mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat: resolve alignment issue and fixed sanitization to top level
This commit is contained in:
@@ -145,7 +145,7 @@ export const registerSamlRouter = async (server: FastifyZodProvider) => {
|
||||
|
||||
const { isUserCompleted, providerAuthToken } = await server.services.saml.samlLogin({
|
||||
externalId: profile.nameID,
|
||||
email,
|
||||
email: email.toLowerCase(),
|
||||
firstName,
|
||||
lastName: lastName as string,
|
||||
relayState: (req.body as { RelayState?: string }).RelayState,
|
||||
|
||||
@@ -181,7 +181,6 @@ export const oidcConfigServiceFactory = ({
|
||||
manageGroupMemberships
|
||||
}: TOidcLoginDTO) => {
|
||||
const serverCfg = await getServerCfg();
|
||||
const sanitizedEmail = email.trim().toLowerCase();
|
||||
|
||||
if (serverCfg.enabledLoginMethods && !serverCfg.enabledLoginMethods.includes(LoginMethod.OIDC)) {
|
||||
throw new ForbiddenRequestError({
|
||||
@@ -216,7 +215,7 @@ export const oidcConfigServiceFactory = ({
|
||||
await orgMembershipDAL.create(
|
||||
{
|
||||
userId: userAlias.userId,
|
||||
inviteEmail: sanitizedEmail,
|
||||
inviteEmail: email,
|
||||
orgId,
|
||||
role,
|
||||
roleId,
|
||||
@@ -246,7 +245,7 @@ export const oidcConfigServiceFactory = ({
|
||||
// we prioritize getting the most complete user to create the new alias under
|
||||
newUser = await userDAL.findOne(
|
||||
{
|
||||
email: sanitizedEmail,
|
||||
email,
|
||||
isEmailVerified: true
|
||||
},
|
||||
tx
|
||||
@@ -256,7 +255,7 @@ export const oidcConfigServiceFactory = ({
|
||||
// this fetches user entries created via invites
|
||||
newUser = await userDAL.findOne(
|
||||
{
|
||||
username: sanitizedEmail
|
||||
username: email
|
||||
},
|
||||
tx
|
||||
);
|
||||
@@ -274,10 +273,10 @@ export const oidcConfigServiceFactory = ({
|
||||
const uniqueUsername = await normalizeUsername(externalId, userDAL);
|
||||
newUser = await userDAL.create(
|
||||
{
|
||||
email: sanitizedEmail,
|
||||
email,
|
||||
firstName,
|
||||
isEmailVerified: serverCfg.trustOidcEmails,
|
||||
username: serverCfg.trustOidcEmails ? sanitizedEmail : uniqueUsername,
|
||||
username: serverCfg.trustOidcEmails ? email : uniqueUsername,
|
||||
lastName,
|
||||
authMethods: [],
|
||||
isGhost: false
|
||||
@@ -291,7 +290,7 @@ export const oidcConfigServiceFactory = ({
|
||||
userId: newUser.id,
|
||||
aliasType: UserAliasType.OIDC,
|
||||
externalId,
|
||||
emails: sanitizedEmail ? [sanitizedEmail] : [],
|
||||
emails: email ? [email] : [],
|
||||
orgId
|
||||
},
|
||||
tx
|
||||
@@ -311,7 +310,7 @@ export const oidcConfigServiceFactory = ({
|
||||
await orgMembershipDAL.create(
|
||||
{
|
||||
userId: newUser.id,
|
||||
inviteEmail: sanitizedEmail,
|
||||
inviteEmail: email,
|
||||
orgId,
|
||||
role,
|
||||
roleId,
|
||||
@@ -716,7 +715,7 @@ export const oidcConfigServiceFactory = ({
|
||||
}
|
||||
|
||||
oidcLogin({
|
||||
email: claims.email,
|
||||
email: claims.email.toLowerCase(),
|
||||
externalId: claims.sub,
|
||||
firstName: claims.given_name ?? "",
|
||||
lastName: claims.family_name ?? "",
|
||||
|
||||
@@ -266,7 +266,7 @@ export const samlConfigServiceFactory = ({
|
||||
await orgMembershipDAL.create(
|
||||
{
|
||||
userId: userAlias.userId,
|
||||
inviteEmail: email.toLowerCase(),
|
||||
inviteEmail: email,
|
||||
orgId,
|
||||
role,
|
||||
roleId,
|
||||
@@ -324,7 +324,7 @@ export const samlConfigServiceFactory = ({
|
||||
if (serverCfg.trustSamlEmails) {
|
||||
newUser = await userDAL.findOne(
|
||||
{
|
||||
email: email.toLowerCase(),
|
||||
email,
|
||||
isEmailVerified: true
|
||||
},
|
||||
tx
|
||||
@@ -335,8 +335,8 @@ export const samlConfigServiceFactory = ({
|
||||
const uniqueUsername = await normalizeUsername(`${firstName ?? ""}-${lastName ?? ""}`, userDAL);
|
||||
newUser = await userDAL.create(
|
||||
{
|
||||
username: serverCfg.trustSamlEmails ? email.toLowerCase() : uniqueUsername,
|
||||
email: email.toLowerCase(),
|
||||
username: serverCfg.trustSamlEmails ? email : uniqueUsername,
|
||||
email,
|
||||
isEmailVerified: serverCfg.trustSamlEmails,
|
||||
firstName,
|
||||
lastName,
|
||||
@@ -352,7 +352,7 @@ export const samlConfigServiceFactory = ({
|
||||
userId: newUser.id,
|
||||
aliasType: UserAliasType.SAML,
|
||||
externalId,
|
||||
emails: email ? [email.toLowerCase()] : [],
|
||||
emails: email ? [email] : [],
|
||||
orgId
|
||||
},
|
||||
tx
|
||||
@@ -372,7 +372,7 @@ export const samlConfigServiceFactory = ({
|
||||
await orgMembershipDAL.create(
|
||||
{
|
||||
userId: newUser.id,
|
||||
inviteEmail: email.toLowerCase(),
|
||||
inviteEmail: email,
|
||||
orgId,
|
||||
role,
|
||||
roleId,
|
||||
|
||||
@@ -82,9 +82,11 @@ export const SelectOrganizationPage = () => {
|
||||
<b>{duplicateAccounts?.data?.myAccount?.username}</b>.
|
||||
</p>
|
||||
<Alert variant="warning" hideTitle>
|
||||
We've detected multiple accounts using variations of the same email address.
|
||||
Please confirm that this account, {duplicateAccounts?.data?.myAccount?.username}, is
|
||||
the account you wish to retain.
|
||||
<div>
|
||||
We've detected multiple accounts using variations of the same email address.
|
||||
Confirm to retain this account <b>{duplicateAccounts?.data?.myAccount?.username}</b>
|
||||
. Upon confirmation other accounts will be <b>removed</b>.
|
||||
</div>
|
||||
</Alert>
|
||||
</div>
|
||||
<div className="thin-scrollbar flex h-full max-h-60 w-full flex-col items-stretch gap-2 overflow-auto rounded-md">
|
||||
@@ -121,13 +123,13 @@ export const SelectOrganizationPage = () => {
|
||||
<div className="mt-4 flex w-full flex-col">
|
||||
<div className="flex gap-6">
|
||||
<Button
|
||||
className="flex-grow"
|
||||
className="flex-1 flex-grow"
|
||||
isLoading={removeDuplicateEmails.isPending}
|
||||
onClick={() =>
|
||||
removeDuplicateEmails.mutate(undefined, {
|
||||
onSuccess: () => {
|
||||
createNotification({
|
||||
type: "info",
|
||||
type: "success",
|
||||
text: "Removed duplicate accounts"
|
||||
});
|
||||
setRemoveDuplicateLater(true);
|
||||
@@ -140,9 +142,9 @@ export const SelectOrganizationPage = () => {
|
||||
<Button
|
||||
variant="outline_bg"
|
||||
onClick={() => setRemoveDuplicateLater(true)}
|
||||
className="flex-grow"
|
||||
className="flex-1 flex-grow"
|
||||
>
|
||||
Do This Later
|
||||
Ask Again Later?
|
||||
</Button>
|
||||
</div>
|
||||
<Button
|
||||
@@ -152,7 +154,7 @@ export const SelectOrganizationPage = () => {
|
||||
className="mt-4"
|
||||
onClick={handleLogout}
|
||||
>
|
||||
Change account
|
||||
Change Account
|
||||
</Button>
|
||||
</div>
|
||||
</form>
|
||||
|
||||
Reference in New Issue
Block a user