Merge pull request #1094 from Infisical/fix-azure-saml-flow

Patch Azure SAML Flow
This commit is contained in:
BlackMagiq
2023-10-18 11:56:45 +01:00
committed by GitHub
6 changed files with 19 additions and 9 deletions
+4 -1
View File
@@ -13,7 +13,10 @@ router.get(
const options = { const options = {
failureRedirect: "/", failureRedirect: "/",
additionalParams: { additionalParams: {
RelayState: req.query.callback_port ?? "" RelayState: JSON.stringify({
spInitiated: true,
callbackPort: req.query.callback_port ?? ""
})
}, },
}; };
passport.authenticate("saml", options)(req, res, next); passport.authenticate("saml", options)(req, res, next);
+4 -2
View File
@@ -312,7 +312,9 @@ const initializePassport = async () => {
} }
if (ssoConfig.authProvider.toString() === AuthMethod.AZURE_SAML.toString()) { if (ssoConfig.authProvider.toString() === AuthMethod.AZURE_SAML.toString()) {
samlConfig.audience = `spn:${ssoConfig.issuer}`; if (req.body.RelayState && JSON.parse(req.body.RelayState).spInitiated) {
samlConfig.audience = `spn:${ssoConfig.issuer}`;
}
} }
req.ssoConfig = ssoConfig; req.ssoConfig = ssoConfig;
@@ -407,7 +409,7 @@ const initializePassport = async () => {
authMethod: req.ssoConfig.authProvider, authMethod: req.ssoConfig.authProvider,
isUserCompleted, isUserCompleted,
...(req.body.RelayState ? { ...(req.body.RelayState ? {
callbackPort: req.body.RelayState as string callbackPort: JSON.parse(req.body.RelayState).callbackPort as string
} : {}) } : {})
}, },
expiresIn: await getJwtProviderAuthLifetime(), expiresIn: await getJwtProviderAuthLifetime(),
+9 -4
View File
@@ -63,12 +63,17 @@ description: "Configure Azure SAML for Infisical SSO"
7. Get IdP values: 7. Get IdP values:
Back in the **Set up Single Sign-On with SAML** screen, copy the **Login URL**, **Azure AD Identifier** and **SAML Certificate** to use when finishing configuring Azure SAML in Infisical. In the **Set up Single Sign-On with SAML** screen, copy the **Login URL** and **SAML Certificate** to use when finishing configuring Azure SAML in Infisical.
Back in Infisical, set **Login URL** and **Azure AD Identifier** from above. Once you've done that, press **Update** to complete the required configuration. ![Azure SAML identity provider values 1](../../../images/sso/azure/idp-values.png)
![Azure SAML identity provider values](../../../images/sso/azure/idp-values.png) In the **Properties** screen, copy the **Application ID** to use when finishing configuring Azure SAML in Infisical.
![Azure SAML paste identity provider values](../../../images/sso/azure/idp-values-2.png)
![Azure SAML identity provider values 2](../../../images/sso/azure/idp-values-2.png)
Back in Infisical, set **Login URL**, **Azure Application ID**, and **SAML Certificate** from above. Once you've done that, press **Update** to complete the required configuration.
![Azure SAML paste identity provider values](../../../images/sso/azure/idp-values-3.png)
<Note> <Note>
When pasting the certificate into Infisical, you'll want to retain `-----BEGIN When pasting the certificate into Infisical, you'll want to retain `-----BEGIN
Binary file not shown.

Before

Width:  |  Height:  |  Size: 521 KiB

After

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.7 MiB

@@ -143,8 +143,8 @@ export const SSOModal = ({
entityId: "Identifier (Entity ID)", entityId: "Identifier (Entity ID)",
entryPoint: "Login URL", entryPoint: "Login URL",
entryPointPlaceholder: "https://login.microsoftonline.com/xxx/saml2", entryPointPlaceholder: "https://login.microsoftonline.com/xxx/saml2",
issuer: "Azure AD Identifier", issuer: "Azure Application ID",
issuerPlaceholder: "https://sts.windows.net/xxx/" issuerPlaceholder: "abc-def-ghi-jkl-mno"
}); });
case AuthProvider.JUMPCLOUD_SAML: case AuthProvider.JUMPCLOUD_SAML:
return ({ return ({