From 3c5c6aeca8534bb2a02422ec0f4ff4c4594fbe29 Mon Sep 17 00:00:00 2001 From: = Date: Fri, 11 Apr 2025 23:09:27 +0530 Subject: [PATCH 1/3] feat: updated error message on update org for saml/oidc enforcement --- .../src/ee/services/oidc/oidc-config-dal.ts | 20 +------------ .../services/saml-config/saml-config-dal.ts | 23 +-------------- backend/src/services/org/org-service.ts | 28 ++++++++++++++++--- 3 files changed, 26 insertions(+), 45 deletions(-) diff --git a/backend/src/ee/services/oidc/oidc-config-dal.ts b/backend/src/ee/services/oidc/oidc-config-dal.ts index ffdba2cf7..b9b0a2659 100644 --- a/backend/src/ee/services/oidc/oidc-config-dal.ts +++ b/backend/src/ee/services/oidc/oidc-config-dal.ts @@ -1,6 +1,5 @@ import { TDbClient } from "@app/db"; import { TableName } from "@app/db/schemas"; -import { DatabaseError } from "@app/lib/errors"; import { ormify } from "@app/lib/knex"; export type TOidcConfigDALFactory = ReturnType; @@ -8,22 +7,5 @@ export type TOidcConfigDALFactory = ReturnType; export const oidcConfigDALFactory = (db: TDbClient) => { const oidcCfgOrm = ormify(db, TableName.OidcConfig); - const findEnforceableOidcCfg = async (orgId: string) => { - try { - const oidcCfg = await db - .replicaNode()(TableName.OidcConfig) - .where({ - orgId, - isActive: true - }) - .whereNotNull("lastUsed") - .first(); - - return oidcCfg; - } catch (error) { - throw new DatabaseError({ error, name: "Find org by id" }); - } - }; - - return { ...oidcCfgOrm, findEnforceableOidcCfg }; + return oidcCfgOrm; }; diff --git a/backend/src/ee/services/saml-config/saml-config-dal.ts b/backend/src/ee/services/saml-config/saml-config-dal.ts index aff42230f..c82adcb89 100644 --- a/backend/src/ee/services/saml-config/saml-config-dal.ts +++ b/backend/src/ee/services/saml-config/saml-config-dal.ts @@ -1,6 +1,5 @@ import { TDbClient } from "@app/db"; import { TableName } from "@app/db/schemas"; -import { DatabaseError } from "@app/lib/errors"; import { ormify } from "@app/lib/knex"; export type TSamlConfigDALFactory = ReturnType; @@ -8,25 +7,5 @@ export type TSamlConfigDALFactory = ReturnType; export const samlConfigDALFactory = (db: TDbClient) => { const samlCfgOrm = ormify(db, TableName.SamlConfig); - const findEnforceableSamlCfg = async (orgId: string) => { - try { - const samlCfg = await db - .replicaNode()(TableName.SamlConfig) - .where({ - orgId, - isActive: true - }) - .whereNotNull("lastUsed") - .first(); - - return samlCfg; - } catch (error) { - throw new DatabaseError({ error, name: "Find org by id" }); - } - }; - - return { - ...samlCfgOrm, - findEnforceableSamlCfg - }; + return samlCfgOrm; }; diff --git a/backend/src/services/org/org-service.ts b/backend/src/services/org/org-service.ts index 98b35f68f..455d0ab22 100644 --- a/backend/src/services/org/org-service.ts +++ b/backend/src/services/org/org-service.ts @@ -110,8 +110,8 @@ type TOrgServiceFactoryDep = { projectKeyDAL: Pick; orgMembershipDAL: Pick; incidentContactDAL: TIncidentContactsDALFactory; - samlConfigDAL: Pick; - oidcConfigDAL: Pick; + samlConfigDAL: Pick; + oidcConfigDAL: Pick; smtpService: TSmtpService; tokenService: TAuthTokenServiceFactory; permissionService: TPermissionServiceFactory; @@ -402,13 +402,33 @@ export const orgServiceFactory = ({ } if (authEnforced) { - const samlCfg = await samlConfigDAL.findEnforceableSamlCfg(orgId); - const oidcCfg = await oidcConfigDAL.findEnforceableOidcCfg(orgId); + const samlCfg = await samlConfigDAL.findOne({ + orgId, + isActive: true + }); + const oidcCfg = await oidcConfigDAL.findOne({ + orgId, + isActive: true + }); if (!samlCfg && !oidcCfg) throw new NotFoundError({ message: `SAML or OIDC configuration for organization with ID '${orgId}' not found` }); + + if (samlCfg && !samlCfg.lastUsed) { + throw new BadRequestError({ + message: + "To apply the new SAML auth enforcement, please log in via SAML again. This step is required to enforce SAML-based authentication." + }); + } + + if (oidcCfg && !oidcCfg.lastUsed) { + throw new BadRequestError({ + message: + "To apply the new SAML auth enforcement, please log in via SAML again. This step is required to enforce SAML-based authentication." + }); + } } let defaultMembershipRole: string | undefined; From 7dcd3d24aa354b3dceaf835f36232a2018c3c226 Mon Sep 17 00:00:00 2001 From: = Date: Fri, 11 Apr 2025 23:11:23 +0530 Subject: [PATCH 2/3] feat: corrected oidc message --- backend/src/services/org/org-service.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/src/services/org/org-service.ts b/backend/src/services/org/org-service.ts index 455d0ab22..531673806 100644 --- a/backend/src/services/org/org-service.ts +++ b/backend/src/services/org/org-service.ts @@ -426,7 +426,7 @@ export const orgServiceFactory = ({ if (oidcCfg && !oidcCfg.lastUsed) { throw new BadRequestError({ message: - "To apply the new SAML auth enforcement, please log in via SAML again. This step is required to enforce SAML-based authentication." + "To apply the new OIDC auth enforcement, please log in via OIDC again. This step is required to enforce OIDC-based authentication." }); } } From 80edccc953983b1eac2b67a3391cb7a87282cfe8 Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Sun, 20 Apr 2025 12:06:34 -0400 Subject: [PATCH 3/3] Update org-service.ts --- backend/src/services/org/org-service.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/backend/src/services/org/org-service.ts b/backend/src/services/org/org-service.ts index 531673806..86625d71a 100644 --- a/backend/src/services/org/org-service.ts +++ b/backend/src/services/org/org-service.ts @@ -419,14 +419,14 @@ export const orgServiceFactory = ({ if (samlCfg && !samlCfg.lastUsed) { throw new BadRequestError({ message: - "To apply the new SAML auth enforcement, please log in via SAML again. This step is required to enforce SAML-based authentication." + "To apply the new SAML auth enforcement, please log in via SAML at least once. This step is required to enforce SAML-based authentication." }); } if (oidcCfg && !oidcCfg.lastUsed) { throw new BadRequestError({ message: - "To apply the new OIDC auth enforcement, please log in via OIDC again. This step is required to enforce OIDC-based authentication." + "To apply the new OIDC auth enforcement, please log in via OIDC at least once. This step is required to enforce OIDC-based authentication." }); } }