misc: added license checks for oidc sso

This commit is contained in:
Sheen Capadngan
2024-06-18 01:11:57 +08:00
parent 2c237ee277
commit d79ffbe37e
5 changed files with 49 additions and 17 deletions
@@ -27,6 +27,7 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
auditLogStreams: false, auditLogStreams: false,
auditLogStreamLimit: 3, auditLogStreamLimit: 3,
samlSSO: false, samlSSO: false,
oidcSSO: false,
scim: false, scim: false,
ldap: false, ldap: false,
groups: false, groups: false,
@@ -44,6 +44,7 @@ export type TFeatureSet = {
auditLogStreams: false; auditLogStreams: false;
auditLogStreamLimit: 3; auditLogStreamLimit: 3;
samlSSO: false; samlSSO: false;
oidcSSO: false;
scim: false; scim: false;
ldap: false; ldap: false;
groups: false; groups: false;
@@ -196,9 +196,6 @@ export const oidcConfigServiceFactory = ({
} }
); );
// TODO: Sheen update oidc config
// await samlConfigDAL.update({ orgId }, { lastUsed: new Date() });
if (user.email && !user.isEmailVerified) { if (user.email && !user.isEmailVerified) {
const token = await tokenService.createTokenForUser({ const token = await tokenService.createTokenForUser({
type: TokenType.TOKEN_EMAIL_VERIFICATION, type: TokenType.TOKEN_EMAIL_VERIFICATION,
@@ -315,12 +312,20 @@ export const oidcConfigServiceFactory = ({
const org = await orgDAL.findOne({ const org = await orgDAL.findOne({
slug: orgSlug slug: orgSlug
}); });
if (!org) { if (!org) {
throw new BadRequestError({ throw new BadRequestError({
message: "Organization not found" message: "Organization not found"
}); });
} }
const plan = await licenseService.getPlan(org.id);
if (!plan.oidcSSO)
throw new BadRequestError({
message:
"Failed to update OIDC SSO configuration due to plan restriction. Upgrade plan to update SSO configuration."
});
const { permission } = await permissionService.getOrgPermission( const { permission } = await permissionService.getOrgPermission(
actor, actor,
actorId, actorId,
@@ -396,6 +401,13 @@ export const oidcConfigServiceFactory = ({
}); });
} }
const plan = await licenseService.getPlan(org.id);
if (!plan.oidcSSO)
throw new BadRequestError({
message:
"Failed to create OIDC SSO configuration due to plan restriction. Upgrade plan to update SSO configuration."
});
const { permission } = await permissionService.getOrgPermission( const { permission } = await permissionService.getOrgPermission(
actor, actor,
actorId, actorId,
@@ -21,18 +21,19 @@ export type SubscriptionPlan = {
workspacesUsed: number; workspacesUsed: number;
environmentLimit: number; environmentLimit: number;
samlSSO: boolean; samlSSO: boolean;
oidcSSO: boolean;
scim: boolean; scim: boolean;
ldap: boolean; ldap: boolean;
groups: boolean; groups: boolean;
status: status:
| "incomplete" | "incomplete"
| "incomplete_expired" | "incomplete_expired"
| "trialing" | "trialing"
| "active" | "active"
| "past_due" | "past_due"
| "canceled" | "canceled"
| "unpaid" | "unpaid"
| null; | null;
trial_end: number | null; trial_end: number | null;
has_used_trial: boolean; has_used_trial: boolean;
}; };
@@ -1,7 +1,12 @@
import { createNotification } from "@app/components/notifications"; import { createNotification } from "@app/components/notifications";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button, Switch } from "@app/components/v2"; import { Button, Switch, UpgradePlanModal } from "@app/components/v2";
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import {
OrgPermissionActions,
OrgPermissionSubjects,
useOrganization,
useSubscription
} from "@app/context";
import { useGetOIDCConfig } from "@app/hooks/api"; import { useGetOIDCConfig } from "@app/hooks/api";
import { useUpdateOIDCConfig } from "@app/hooks/api/oidcConfig/mutations"; import { useUpdateOIDCConfig } from "@app/hooks/api/oidcConfig/mutations";
import { usePopUp } from "@app/hooks/usePopUp"; import { usePopUp } from "@app/hooks/usePopUp";
@@ -10,17 +15,24 @@ import { OIDCModal } from "./OIDCModal";
export const OrgOIDCSection = (): JSX.Element => { export const OrgOIDCSection = (): JSX.Element => {
const { currentOrg } = useOrganization(); const { currentOrg } = useOrganization();
const { subscription } = useSubscription();
const { data, isLoading } = useGetOIDCConfig(currentOrg?.slug ?? ""); const { data, isLoading } = useGetOIDCConfig(currentOrg?.slug ?? "");
const { mutateAsync } = useUpdateOIDCConfig(); const { mutateAsync } = useUpdateOIDCConfig();
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([ const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
"addOIDC" "addOIDC",
"upgradePlan"
] as const); ] as const);
const handleOIDCToggle = async (value: boolean) => { const handleOIDCToggle = async (value: boolean) => {
try { try {
if (!currentOrg?.id) return; if (!currentOrg?.id) return;
if (!subscription?.oidcSSO) {
handlePopUpOpen("upgradePlan");
return;
}
await mutateAsync({ await mutateAsync({
orgSlug: currentOrg?.slug, orgSlug: currentOrg?.slug,
isActive: value isActive: value
@@ -40,10 +52,10 @@ export const OrgOIDCSection = (): JSX.Element => {
}; };
const addOidcButtonClick = async () => { const addOidcButtonClick = async () => {
try { if (subscription?.oidcSSO && currentOrg) {
handlePopUpOpen("addOIDC"); handlePopUpOpen("addOIDC");
} catch (err) { } else {
console.error(err); handlePopUpOpen("upgradePlan");
} }
}; };
@@ -96,6 +108,11 @@ export const OrgOIDCSection = (): JSX.Element => {
handlePopUpClose={handlePopUpClose} handlePopUpClose={handlePopUpClose}
handlePopUpToggle={handlePopUpToggle} handlePopUpToggle={handlePopUpToggle}
/> />
<UpgradePlanModal
isOpen={popUp.upgradePlan.isOpen}
onOpenChange={(isOpen) => handlePopUpToggle("upgradePlan", isOpen)}
text="You can use OIDC SSO if you switch to Infisical's Pro plan."
/>
</> </>
); );
}; };