mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 05:27:48 +00:00
Minor changes to oidc claims and mappings
- Made the claims expanded by default (it looked off when they were closed)
- Moved claims from advanced to geneal tab and kept the mapping in the advanced tab
- Added better description for the tooltip
question: i feel like it would be better to access metadata like: `{{identity.auth.oidc.claim.<...>}}` instead of like how it is now: `{{identity.metadata.auth.oidc.claim.<...>}}`? What do you think
This commit is contained in:
@@ -1,2 +0,0 @@
|
|||||||
DB_CONNECTION_URI=
|
|
||||||
AUDIT_LOGS_DB_CONNECTION_URI=
|
|
||||||
+93
-85
@@ -51,7 +51,7 @@ const schema = z.object({
|
|||||||
key: z.string(),
|
key: z.string(),
|
||||||
value: z.string()
|
value: z.string()
|
||||||
})
|
})
|
||||||
),
|
).default([{ key: "", value: "" }]),
|
||||||
claimMetadataMapping: z
|
claimMetadataMapping: z
|
||||||
.array(
|
.array(
|
||||||
z.object({
|
z.object({
|
||||||
@@ -59,8 +59,7 @@ const schema = z.object({
|
|||||||
value: z.string()
|
value: z.string()
|
||||||
})
|
})
|
||||||
)
|
)
|
||||||
.optional()
|
.default([{ key: "", value: "" }]),
|
||||||
.nullable(),
|
|
||||||
boundSubject: z.string().optional().default("")
|
boundSubject: z.string().optional().default("")
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -105,7 +104,9 @@ export const IdentityOidcAuthForm = ({
|
|||||||
accessTokenTTL: "2592000",
|
accessTokenTTL: "2592000",
|
||||||
accessTokenMaxTTL: "2592000",
|
accessTokenMaxTTL: "2592000",
|
||||||
accessTokenNumUsesLimit: "0",
|
accessTokenNumUsesLimit: "0",
|
||||||
accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]
|
accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }],
|
||||||
|
boundClaims: [{ key: "", value: "" }],
|
||||||
|
claimMetadataMapping: [{ key: "", value: "" }]
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
const {
|
const {
|
||||||
@@ -167,7 +168,7 @@ export const IdentityOidcAuthForm = ({
|
|||||||
caCert: "",
|
caCert: "",
|
||||||
boundIssuer: "",
|
boundIssuer: "",
|
||||||
boundAudiences: "",
|
boundAudiences: "",
|
||||||
boundClaims: [],
|
boundClaims: [{ key: "", value: "" }],
|
||||||
boundSubject: "",
|
boundSubject: "",
|
||||||
accessTokenTTL: "2592000",
|
accessTokenTTL: "2592000",
|
||||||
accessTokenMaxTTL: "2592000",
|
accessTokenMaxTTL: "2592000",
|
||||||
@@ -253,7 +254,7 @@ export const IdentityOidcAuthForm = ({
|
|||||||
<form
|
<form
|
||||||
onSubmit={handleSubmit(onFormSubmit, (fields) => {
|
onSubmit={handleSubmit(onFormSubmit, (fields) => {
|
||||||
setTabValue(
|
setTabValue(
|
||||||
["accessTokenTrustedIps", "caCert", "boundClaims"].includes(Object.keys(fields)[0])
|
["accessTokenTrustedIps", "caCert", "claimMetadataMapping"].includes(Object.keys(fields)[0])
|
||||||
? IdentityFormTab.Advanced
|
? IdentityFormTab.Advanced
|
||||||
: IdentityFormTab.Configuration
|
: IdentityFormTab.Configuration
|
||||||
);
|
);
|
||||||
@@ -343,63 +344,6 @@ export const IdentityOidcAuthForm = ({
|
|||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
<Controller
|
|
||||||
control={control}
|
|
||||||
defaultValue="2592000"
|
|
||||||
name="accessTokenTTL"
|
|
||||||
render={({ field, fieldState: { error } }) => (
|
|
||||||
<FormControl
|
|
||||||
label="Access Token TTL (seconds)"
|
|
||||||
isError={Boolean(error)}
|
|
||||||
errorText={error?.message}
|
|
||||||
>
|
|
||||||
<Input {...field} placeholder="2592000" type="number" min="0" step="1" />
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
/>
|
|
||||||
<Controller
|
|
||||||
control={control}
|
|
||||||
defaultValue="2592000"
|
|
||||||
name="accessTokenMaxTTL"
|
|
||||||
render={({ field, fieldState: { error } }) => (
|
|
||||||
<FormControl
|
|
||||||
label="Access Token Max TTL (seconds)"
|
|
||||||
isError={Boolean(error)}
|
|
||||||
errorText={error?.message}
|
|
||||||
>
|
|
||||||
<Input {...field} placeholder="2592000" type="number" min="0" step="1" />
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
/>
|
|
||||||
<Controller
|
|
||||||
control={control}
|
|
||||||
defaultValue="0"
|
|
||||||
name="accessTokenNumUsesLimit"
|
|
||||||
render={({ field, fieldState: { error } }) => (
|
|
||||||
<FormControl
|
|
||||||
label="Access Token Max Number of Uses"
|
|
||||||
isError={Boolean(error)}
|
|
||||||
errorText={error?.message}
|
|
||||||
>
|
|
||||||
<Input {...field} placeholder="0" type="number" min="0" step="1" />
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
/>
|
|
||||||
</TabPanel>
|
|
||||||
<TabPanel value={IdentityFormTab.Advanced}>
|
|
||||||
<Controller
|
|
||||||
control={control}
|
|
||||||
name="caCert"
|
|
||||||
render={({ field, fieldState: { error } }) => (
|
|
||||||
<FormControl
|
|
||||||
label="CA Certificate"
|
|
||||||
errorText={error?.message}
|
|
||||||
isError={Boolean(error)}
|
|
||||||
>
|
|
||||||
<TextArea {...field} placeholder="-----BEGIN CERTIFICATE----- ..." />
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
/>
|
|
||||||
{boundClaimsFields.map(({ id }, index) => (
|
{boundClaimsFields.map(({ id }, index) => (
|
||||||
<div className="mb-3 flex items-end space-x-2" key={id}>
|
<div className="mb-3 flex items-end space-x-2" key={id}>
|
||||||
<Controller
|
<Controller
|
||||||
@@ -479,6 +423,65 @@ export const IdentityOidcAuthForm = ({
|
|||||||
Add Claims
|
Add Claims
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="2592000"
|
||||||
|
name="accessTokenTTL"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token TTL (seconds)"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="2592000" type="number" min="0" step="1" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="2592000"
|
||||||
|
name="accessTokenMaxTTL"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token Max TTL (seconds)"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="2592000" type="number" min="0" step="1" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="0"
|
||||||
|
name="accessTokenNumUsesLimit"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token Max Number of Uses"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="0" type="number" min="0" step="1" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
</TabPanel>
|
||||||
|
<TabPanel value={IdentityFormTab.Advanced}>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="caCert"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="CA Certificate"
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error)}
|
||||||
|
>
|
||||||
|
<TextArea {...field} placeholder="-----BEGIN CERTIFICATE----- ..." />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
{claimMetadataMappingFields.map(({ id }, index) => (
|
{claimMetadataMappingFields.map(({ id }, index) => (
|
||||||
<div className="mb-3 flex items-end space-x-2" key={id}>
|
<div className="mb-3 flex items-end space-x-2" key={id}>
|
||||||
<Controller
|
<Controller
|
||||||
@@ -488,12 +491,19 @@ export const IdentityOidcAuthForm = ({
|
|||||||
return (
|
return (
|
||||||
<FormControl
|
<FormControl
|
||||||
className="mb-0 flex-grow"
|
className="mb-0 flex-grow"
|
||||||
label={index === 0 ? "Claim Metadata Mapping" : undefined}
|
label={index === 0 ? "Token Claim Mapping" : undefined}
|
||||||
icon={
|
icon={
|
||||||
index === 0 ? (
|
index === 0 ? (
|
||||||
<Tooltip
|
<Tooltip
|
||||||
className="text-center"
|
className="text-center"
|
||||||
content="Map token claims to metadata. This can later be accessed in attribute based permission as identity.metadata.oidc.claims.<>."
|
content={
|
||||||
|
<div className="w-[180px]">
|
||||||
|
<p>Map OIDC token claims to metadata fields</p>
|
||||||
|
<p className="text-sm mt-2">Example:</p>
|
||||||
|
<p className="text-sm mt-1">'role' → 'token.groups'</p>
|
||||||
|
<p className="text-xs text-gray-400 mt-1">Becomes: identity.metadata.oidc.claims.role</p>
|
||||||
|
</div>
|
||||||
|
}
|
||||||
>
|
>
|
||||||
<FontAwesomeIcon icon={faQuestionCircle} size="sm" />
|
<FontAwesomeIcon icon={faQuestionCircle} size="sm" />
|
||||||
</Tooltip>
|
</Tooltip>
|
||||||
@@ -505,7 +515,7 @@ export const IdentityOidcAuthForm = ({
|
|||||||
<Input
|
<Input
|
||||||
value={field.value}
|
value={field.value}
|
||||||
onChange={(e) => field.onChange(e)}
|
onChange={(e) => field.onChange(e)}
|
||||||
placeholder="property"
|
placeholder="Field name"
|
||||||
/>
|
/>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
);
|
);
|
||||||
@@ -524,7 +534,7 @@ export const IdentityOidcAuthForm = ({
|
|||||||
<Input
|
<Input
|
||||||
value={field.value}
|
value={field.value}
|
||||||
onChange={(e) => field.onChange(e)}
|
onChange={(e) => field.onChange(e)}
|
||||||
placeholder="key1.nested-key2"
|
placeholder="Token claim"
|
||||||
/>
|
/>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
);
|
);
|
||||||
@@ -554,9 +564,10 @@ export const IdentityOidcAuthForm = ({
|
|||||||
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
size="xs"
|
size="xs"
|
||||||
>
|
>
|
||||||
Add Mapping
|
Add Token Mapping
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
{accessTokenTrustedIpsFields.map(({ id }, index) => (
|
{accessTokenTrustedIpsFields.map(({ id }, index) => (
|
||||||
<div className="mb-3 flex items-end space-x-2" key={id}>
|
<div className="mb-3 flex items-end space-x-2" key={id}>
|
||||||
<Controller
|
<Controller
|
||||||
@@ -627,24 +638,21 @@ export const IdentityOidcAuthForm = ({
|
|||||||
</div>
|
</div>
|
||||||
</TabPanel>
|
</TabPanel>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
<div className="flex items-center">
|
|
||||||
<Button
|
|
||||||
className="mr-4"
|
|
||||||
size="sm"
|
|
||||||
type="submit"
|
|
||||||
isLoading={isSubmitting}
|
|
||||||
isDisabled={isSubmitting}
|
|
||||||
>
|
|
||||||
{isUpdate ? "Update" : "Add"}
|
|
||||||
</Button>
|
|
||||||
|
|
||||||
<Button
|
<div className="mt-8 flex justify-between">
|
||||||
colorSchema="secondary"
|
<div className="flex items-center">
|
||||||
variant="plain"
|
<Button
|
||||||
onClick={() => handlePopUpToggle("identityAuthMethod", false)}
|
onClick={() => handlePopUpToggle("identityAuthMethod", false)}
|
||||||
>
|
variant="outline_bg"
|
||||||
Cancel
|
className="mr-4"
|
||||||
</Button>
|
isDisabled={isSubmitting}
|
||||||
|
>
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
<Button type="submit" isLoading={isSubmitting}>
|
||||||
|
{isUpdate ? "Update" : "Add"} Auth Method
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</form>
|
</form>
|
||||||
);
|
);
|
||||||
|
|||||||
Reference in New Issue
Block a user