mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 18:27:36 +00:00
Merge pull request #4319 from Infisical/feat/last-logged-auth
feat: adds support for last logged in auth method field
This commit is contained in:
@@ -0,0 +1,65 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
const lastUserLoggedInAuthMethod = await knex.schema.hasColumn(TableName.OrgMembership, "lastLoginAuthMethod");
|
||||||
|
const lastIdentityLoggedInAuthMethod = await knex.schema.hasColumn(
|
||||||
|
TableName.IdentityOrgMembership,
|
||||||
|
"lastLoginAuthMethod"
|
||||||
|
);
|
||||||
|
const lastUserLoggedInTime = await knex.schema.hasColumn(TableName.OrgMembership, "lastLoginTime");
|
||||||
|
const lastIdentityLoggedInTime = await knex.schema.hasColumn(TableName.IdentityOrgMembership, "lastLoginTime");
|
||||||
|
if (!lastUserLoggedInAuthMethod || !lastUserLoggedInTime) {
|
||||||
|
await knex.schema.alterTable(TableName.OrgMembership, (t) => {
|
||||||
|
if (!lastUserLoggedInAuthMethod) {
|
||||||
|
t.string("lastLoginAuthMethod").nullable();
|
||||||
|
}
|
||||||
|
if (!lastUserLoggedInTime) {
|
||||||
|
t.datetime("lastLoginTime").nullable();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!lastIdentityLoggedInAuthMethod || !lastIdentityLoggedInTime) {
|
||||||
|
await knex.schema.alterTable(TableName.IdentityOrgMembership, (t) => {
|
||||||
|
if (!lastIdentityLoggedInAuthMethod) {
|
||||||
|
t.string("lastLoginAuthMethod").nullable();
|
||||||
|
}
|
||||||
|
if (!lastIdentityLoggedInTime) {
|
||||||
|
t.datetime("lastLoginTime").nullable();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
const lastUserLoggedInAuthMethod = await knex.schema.hasColumn(TableName.OrgMembership, "lastLoginAuthMethod");
|
||||||
|
const lastIdentityLoggedInAuthMethod = await knex.schema.hasColumn(
|
||||||
|
TableName.IdentityOrgMembership,
|
||||||
|
"lastLoginAuthMethod"
|
||||||
|
);
|
||||||
|
const lastUserLoggedInTime = await knex.schema.hasColumn(TableName.OrgMembership, "lastLoginTime");
|
||||||
|
const lastIdentityLoggedInTime = await knex.schema.hasColumn(TableName.IdentityOrgMembership, "lastLoginTime");
|
||||||
|
if (lastUserLoggedInAuthMethod || lastUserLoggedInTime) {
|
||||||
|
await knex.schema.alterTable(TableName.OrgMembership, (t) => {
|
||||||
|
if (lastUserLoggedInAuthMethod) {
|
||||||
|
t.dropColumn("lastLoginAuthMethod");
|
||||||
|
}
|
||||||
|
if (lastUserLoggedInTime) {
|
||||||
|
t.dropColumn("lastLoginTime");
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (lastIdentityLoggedInAuthMethod || lastIdentityLoggedInTime) {
|
||||||
|
await knex.schema.alterTable(TableName.IdentityOrgMembership, (t) => {
|
||||||
|
if (lastIdentityLoggedInAuthMethod) {
|
||||||
|
t.dropColumn("lastLoginAuthMethod");
|
||||||
|
}
|
||||||
|
if (lastIdentityLoggedInTime) {
|
||||||
|
t.dropColumn("lastLoginTime");
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -14,7 +14,9 @@ export const IdentityOrgMembershipsSchema = z.object({
|
|||||||
orgId: z.string().uuid(),
|
orgId: z.string().uuid(),
|
||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
updatedAt: z.date(),
|
updatedAt: z.date(),
|
||||||
identityId: z.string().uuid()
|
identityId: z.string().uuid(),
|
||||||
|
lastLoginAuthMethod: z.string().nullable().optional(),
|
||||||
|
lastLoginTime: z.date().nullable().optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TIdentityOrgMemberships = z.infer<typeof IdentityOrgMembershipsSchema>;
|
export type TIdentityOrgMemberships = z.infer<typeof IdentityOrgMembershipsSchema>;
|
||||||
|
|||||||
@@ -19,7 +19,9 @@ export const OrgMembershipsSchema = z.object({
|
|||||||
roleId: z.string().uuid().nullable().optional(),
|
roleId: z.string().uuid().nullable().optional(),
|
||||||
projectFavorites: z.string().array().nullable().optional(),
|
projectFavorites: z.string().array().nullable().optional(),
|
||||||
isActive: z.boolean().default(true),
|
isActive: z.boolean().default(true),
|
||||||
lastInvitedAt: z.date().nullable().optional()
|
lastInvitedAt: z.date().nullable().optional(),
|
||||||
|
lastLoginAuthMethod: z.string().nullable().optional(),
|
||||||
|
lastLoginTime: z.date().nullable().optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TOrgMemberships = z.infer<typeof OrgMembershipsSchema>;
|
export type TOrgMemberships = z.infer<typeof OrgMembershipsSchema>;
|
||||||
|
|||||||
@@ -45,6 +45,8 @@ import { groupServiceFactory } from "@app/ee/services/group/group-service";
|
|||||||
import { userGroupMembershipDALFactory } from "@app/ee/services/group/user-group-membership-dal";
|
import { userGroupMembershipDALFactory } from "@app/ee/services/group/user-group-membership-dal";
|
||||||
import { hsmServiceFactory } from "@app/ee/services/hsm/hsm-service";
|
import { hsmServiceFactory } from "@app/ee/services/hsm/hsm-service";
|
||||||
import { HsmModule } from "@app/ee/services/hsm/hsm-types";
|
import { HsmModule } from "@app/ee/services/hsm/hsm-types";
|
||||||
|
import { identityAuthTemplateDALFactory } from "@app/ee/services/identity-auth-template/identity-auth-template-dal";
|
||||||
|
import { identityAuthTemplateServiceFactory } from "@app/ee/services/identity-auth-template/identity-auth-template-service";
|
||||||
import { identityProjectAdditionalPrivilegeDALFactory } from "@app/ee/services/identity-project-additional-privilege/identity-project-additional-privilege-dal";
|
import { identityProjectAdditionalPrivilegeDALFactory } from "@app/ee/services/identity-project-additional-privilege/identity-project-additional-privilege-dal";
|
||||||
import { identityProjectAdditionalPrivilegeServiceFactory } from "@app/ee/services/identity-project-additional-privilege/identity-project-additional-privilege-service";
|
import { identityProjectAdditionalPrivilegeServiceFactory } from "@app/ee/services/identity-project-additional-privilege/identity-project-additional-privilege-service";
|
||||||
import { identityProjectAdditionalPrivilegeV2ServiceFactory } from "@app/ee/services/identity-project-additional-privilege-v2/identity-project-additional-privilege-v2-service";
|
import { identityProjectAdditionalPrivilegeV2ServiceFactory } from "@app/ee/services/identity-project-additional-privilege-v2/identity-project-additional-privilege-v2-service";
|
||||||
@@ -179,8 +181,6 @@ import { identityAccessTokenDALFactory } from "@app/services/identity-access-tok
|
|||||||
import { identityAccessTokenServiceFactory } from "@app/services/identity-access-token/identity-access-token-service";
|
import { identityAccessTokenServiceFactory } from "@app/services/identity-access-token/identity-access-token-service";
|
||||||
import { identityAliCloudAuthDALFactory } from "@app/services/identity-alicloud-auth/identity-alicloud-auth-dal";
|
import { identityAliCloudAuthDALFactory } from "@app/services/identity-alicloud-auth/identity-alicloud-auth-dal";
|
||||||
import { identityAliCloudAuthServiceFactory } from "@app/services/identity-alicloud-auth/identity-alicloud-auth-service";
|
import { identityAliCloudAuthServiceFactory } from "@app/services/identity-alicloud-auth/identity-alicloud-auth-service";
|
||||||
import { identityAuthTemplateDALFactory } from "@app/ee/services/identity-auth-template/identity-auth-template-dal";
|
|
||||||
import { identityAuthTemplateServiceFactory } from "@app/ee/services/identity-auth-template/identity-auth-template-service";
|
|
||||||
import { identityAwsAuthDALFactory } from "@app/services/identity-aws-auth/identity-aws-auth-dal";
|
import { identityAwsAuthDALFactory } from "@app/services/identity-aws-auth/identity-aws-auth-dal";
|
||||||
import { identityAwsAuthServiceFactory } from "@app/services/identity-aws-auth/identity-aws-auth-service";
|
import { identityAwsAuthServiceFactory } from "@app/services/identity-aws-auth/identity-aws-auth-service";
|
||||||
import { identityAzureAuthDALFactory } from "@app/services/identity-azure-auth/identity-azure-auth-dal";
|
import { identityAzureAuthDALFactory } from "@app/services/identity-azure-auth/identity-azure-auth-dal";
|
||||||
|
|||||||
@@ -148,11 +148,17 @@ export const authLoginServiceFactory = ({
|
|||||||
|
|
||||||
if (organizationId) {
|
if (organizationId) {
|
||||||
const org = await orgDAL.findById(organizationId);
|
const org = await orgDAL.findById(organizationId);
|
||||||
if (org && org.userTokenExpiration) {
|
if (org) {
|
||||||
|
await orgMembershipDAL.update(
|
||||||
|
{ userId: user.id, orgId: org.id },
|
||||||
|
{ lastLoginAuthMethod: authMethod, lastLoginTime: new Date() }
|
||||||
|
);
|
||||||
|
if (org.userTokenExpiration) {
|
||||||
tokenSessionExpiresIn = getMinExpiresIn(cfg.JWT_AUTH_LIFETIME, org.userTokenExpiration);
|
tokenSessionExpiresIn = getMinExpiresIn(cfg.JWT_AUTH_LIFETIME, org.userTokenExpiration);
|
||||||
refreshTokenExpiresIn = org.userTokenExpiration;
|
refreshTokenExpiresIn = org.userTokenExpiration;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
const accessToken = crypto.jwt().sign(
|
const accessToken = crypto.jwt().sign(
|
||||||
{
|
{
|
||||||
|
|||||||
+1
-1
@@ -32,8 +32,8 @@ import {
|
|||||||
keyAlgorithmToAlgCfg
|
keyAlgorithmToAlgCfg
|
||||||
} from "../certificate-authority-fns";
|
} from "../certificate-authority-fns";
|
||||||
import { TCertificateAuthoritySecretDALFactory } from "../certificate-authority-secret-dal";
|
import { TCertificateAuthoritySecretDALFactory } from "../certificate-authority-secret-dal";
|
||||||
import { TIssueCertWithTemplateDTO } from "./internal-certificate-authority-types";
|
|
||||||
import { validateAndMapAltNameType } from "../certificate-authority-validators";
|
import { validateAndMapAltNameType } from "../certificate-authority-validators";
|
||||||
|
import { TIssueCertWithTemplateDTO } from "./internal-certificate-authority-types";
|
||||||
|
|
||||||
type TInternalCertificateAuthorityFnsDeps = {
|
type TInternalCertificateAuthorityFnsDeps = {
|
||||||
certificateAuthorityDAL: Pick<TCertificateAuthorityDALFactory, "findByIdWithAssociatedCa" | "findById">;
|
certificateAuthorityDAL: Pick<TCertificateAuthorityDALFactory, "findByIdWithAssociatedCa" | "findById">;
|
||||||
|
|||||||
+1
-1
@@ -52,6 +52,7 @@ import {
|
|||||||
} from "../certificate-authority-fns";
|
} from "../certificate-authority-fns";
|
||||||
import { TCertificateAuthorityQueueFactory } from "../certificate-authority-queue";
|
import { TCertificateAuthorityQueueFactory } from "../certificate-authority-queue";
|
||||||
import { TCertificateAuthoritySecretDALFactory } from "../certificate-authority-secret-dal";
|
import { TCertificateAuthoritySecretDALFactory } from "../certificate-authority-secret-dal";
|
||||||
|
import { validateAndMapAltNameType } from "../certificate-authority-validators";
|
||||||
import { TInternalCertificateAuthorityDALFactory } from "./internal-certificate-authority-dal";
|
import { TInternalCertificateAuthorityDALFactory } from "./internal-certificate-authority-dal";
|
||||||
import {
|
import {
|
||||||
TCreateCaDTO,
|
TCreateCaDTO,
|
||||||
@@ -68,7 +69,6 @@ import {
|
|||||||
TSignIntermediateDTO,
|
TSignIntermediateDTO,
|
||||||
TUpdateCaDTO
|
TUpdateCaDTO
|
||||||
} from "./internal-certificate-authority-types";
|
} from "./internal-certificate-authority-types";
|
||||||
import { validateAndMapAltNameType } from "../certificate-authority-validators";
|
|
||||||
|
|
||||||
type TInternalCertificateAuthorityServiceFactoryDep = {
|
type TInternalCertificateAuthorityServiceFactoryDep = {
|
||||||
certificateAuthorityDAL: Pick<
|
certificateAuthorityDAL: Pick<
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ type TIdentityAliCloudAuthServiceFactoryDep = {
|
|||||||
TIdentityAliCloudAuthDALFactory,
|
TIdentityAliCloudAuthDALFactory,
|
||||||
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
||||||
>;
|
>;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
};
|
};
|
||||||
@@ -64,6 +64,8 @@ export const identityAliCloudAuthServiceFactory = ({
|
|||||||
identityId: identityAliCloudAuth.identityId
|
identityId: identityAliCloudAuth.identityId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (!identityMembershipOrg) throw new UnauthorizedError({ message: "Identity not attached to a organization" });
|
||||||
|
|
||||||
const requestUrl = new URL("https://sts.aliyuncs.com");
|
const requestUrl = new URL("https://sts.aliyuncs.com");
|
||||||
|
|
||||||
for (const key of Object.keys(params)) {
|
for (const key of Object.keys(params)) {
|
||||||
@@ -87,6 +89,14 @@ export const identityAliCloudAuthServiceFactory = ({
|
|||||||
|
|
||||||
// Generate the token
|
// Generate the token
|
||||||
const identityAccessToken = await identityAliCloudAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityAliCloudAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.ALICLOUD_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityAliCloudAuth.identityId,
|
identityId: identityAliCloudAuth.identityId,
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ import {
|
|||||||
type TIdentityAwsAuthServiceFactoryDep = {
|
type TIdentityAwsAuthServiceFactoryDep = {
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
identityAwsAuthDAL: Pick<TIdentityAwsAuthDALFactory, "findOne" | "transaction" | "create" | "updateById" | "delete">;
|
identityAwsAuthDAL: Pick<TIdentityAwsAuthDALFactory, "findOne" | "transaction" | "create" | "updateById" | "delete">;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
};
|
};
|
||||||
@@ -91,6 +91,7 @@ export const identityAwsAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityAwsAuth.identityId });
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityAwsAuth.identityId });
|
||||||
|
if (!identityMembershipOrg) throw new UnauthorizedError({ message: "Identity not attached to a organization" });
|
||||||
|
|
||||||
const headers: TAwsGetCallerIdentityHeaders = JSON.parse(Buffer.from(iamRequestHeaders, "base64").toString());
|
const headers: TAwsGetCallerIdentityHeaders = JSON.parse(Buffer.from(iamRequestHeaders, "base64").toString());
|
||||||
const body: string = Buffer.from(iamRequestBody, "base64").toString();
|
const body: string = Buffer.from(iamRequestBody, "base64").toString();
|
||||||
@@ -152,6 +153,14 @@ export const identityAwsAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityAwsAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityAwsAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.AWS_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityAwsAuth.identityId,
|
identityId: identityAwsAuth.identityId,
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ type TIdentityAzureAuthServiceFactoryDep = {
|
|||||||
TIdentityAzureAuthDALFactory,
|
TIdentityAzureAuthDALFactory,
|
||||||
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
||||||
>;
|
>;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
@@ -80,6 +80,14 @@ export const identityAzureAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityAzureAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityAzureAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.AZURE_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityAzureAuth.identityId,
|
identityId: identityAzureAuth.identityId,
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ import {
|
|||||||
|
|
||||||
type TIdentityGcpAuthServiceFactoryDep = {
|
type TIdentityGcpAuthServiceFactoryDep = {
|
||||||
identityGcpAuthDAL: Pick<TIdentityGcpAuthDALFactory, "findOne" | "transaction" | "create" | "updateById" | "delete">;
|
identityGcpAuthDAL: Pick<TIdentityGcpAuthDALFactory, "findOne" | "transaction" | "create" | "updateById" | "delete">;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
@@ -119,6 +119,14 @@ export const identityGcpAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityGcpAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityGcpAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.GCP_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityGcpAuth.identityId,
|
identityId: identityGcpAuth.identityId,
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ import {
|
|||||||
|
|
||||||
type TIdentityJwtAuthServiceFactoryDep = {
|
type TIdentityJwtAuthServiceFactoryDep = {
|
||||||
identityJwtAuthDAL: TIdentityJwtAuthDALFactory;
|
identityJwtAuthDAL: TIdentityJwtAuthDALFactory;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
@@ -209,6 +209,14 @@ export const identityJwtAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityJwtAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityJwtAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.JWT_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityJwtAuth.identityId,
|
identityId: identityJwtAuth.identityId,
|
||||||
|
|||||||
@@ -49,7 +49,7 @@ type TIdentityKubernetesAuthServiceFactoryDep = {
|
|||||||
"create" | "findOne" | "transaction" | "updateById" | "delete"
|
"create" | "findOne" | "transaction" | "updateById" | "delete"
|
||||||
>;
|
>;
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "findById">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "findById" | "updateById">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||||
@@ -380,6 +380,14 @@ export const identityKubernetesAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityKubernetesAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityKubernetesAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.KUBERNETES_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityKubernetesAuth.identityId,
|
identityId: identityKubernetesAuth.identityId,
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ type TIdentityLdapAuthServiceFactoryDep = {
|
|||||||
TIdentityLdapAuthDALFactory,
|
TIdentityLdapAuthDALFactory,
|
||||||
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
||||||
>;
|
>;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
kmsService: TKmsServiceFactory;
|
kmsService: TKmsServiceFactory;
|
||||||
@@ -144,6 +144,14 @@ export const identityLdapAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityLdapAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityLdapAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.LDAP_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityLdapAuth.identityId,
|
identityId: identityLdapAuth.identityId,
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ import {
|
|||||||
type TIdentityOciAuthServiceFactoryDep = {
|
type TIdentityOciAuthServiceFactoryDep = {
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
identityOciAuthDAL: Pick<TIdentityOciAuthDALFactory, "findOne" | "transaction" | "create" | "updateById" | "delete">;
|
identityOciAuthDAL: Pick<TIdentityOciAuthDALFactory, "findOne" | "transaction" | "create" | "updateById" | "delete">;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
};
|
};
|
||||||
@@ -57,6 +57,7 @@ export const identityOciAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityOciAuth.identityId });
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityOciAuth.identityId });
|
||||||
|
if (!identityMembershipOrg) throw new UnauthorizedError({ message: "Identity not attached to a organization" });
|
||||||
|
|
||||||
// Validate OCI host format. Ensures that the host is in "identity.<region>.oraclecloud.com" format.
|
// Validate OCI host format. Ensures that the host is in "identity.<region>.oraclecloud.com" format.
|
||||||
if (!headers.host || !new RE2("^identity\\.([a-z]{2}-[a-z]+-[1-9])\\.oraclecloud\\.com$").test(headers.host)) {
|
if (!headers.host || !new RE2("^identity\\.([a-z]{2}-[a-z]+-[1-9])\\.oraclecloud\\.com$").test(headers.host)) {
|
||||||
@@ -91,6 +92,14 @@ export const identityOciAuthServiceFactory = ({
|
|||||||
|
|
||||||
// Generate the token
|
// Generate the token
|
||||||
const identityAccessToken = await identityOciAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityOciAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.OCI_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityOciAuth.identityId,
|
identityId: identityOciAuth.identityId,
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ import {
|
|||||||
|
|
||||||
type TIdentityOidcAuthServiceFactoryDep = {
|
type TIdentityOidcAuthServiceFactoryDep = {
|
||||||
identityOidcAuthDAL: TIdentityOidcAuthDALFactory;
|
identityOidcAuthDAL: TIdentityOidcAuthDALFactory;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
@@ -178,6 +178,14 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityOidcAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityOidcAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.OIDC_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityOidcAuth.identityId,
|
identityId: identityOidcAuth.identityId,
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ type TIdentityTlsCertAuthServiceFactoryDep = {
|
|||||||
TIdentityTlsCertAuthDALFactory,
|
TIdentityTlsCertAuthDALFactory,
|
||||||
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
"findOne" | "transaction" | "create" | "updateById" | "delete"
|
||||||
>;
|
>;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||||
@@ -118,6 +118,14 @@ export const identityTlsCertAuthServiceFactory = ({
|
|||||||
|
|
||||||
// Generate the token
|
// Generate the token
|
||||||
const identityAccessToken = await identityTlsCertAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityTlsCertAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.TLS_CERT_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityTlsCertAuth.identityId,
|
identityId: identityTlsCertAuth.identityId,
|
||||||
|
|||||||
@@ -35,7 +35,7 @@ type TIdentityTokenAuthServiceFactoryDep = {
|
|||||||
TIdentityTokenAuthDALFactory,
|
TIdentityTokenAuthDALFactory,
|
||||||
"transaction" | "create" | "findOne" | "updateById" | "delete"
|
"transaction" | "create" | "findOne" | "updateById" | "delete"
|
||||||
>;
|
>;
|
||||||
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne" | "updateById">;
|
||||||
identityAccessTokenDAL: Pick<
|
identityAccessTokenDAL: Pick<
|
||||||
TIdentityAccessTokenDALFactory,
|
TIdentityAccessTokenDALFactory,
|
||||||
"create" | "find" | "update" | "findById" | "findOne" | "updateById" | "delete"
|
"create" | "find" | "update" | "findById" | "findOne" | "updateById" | "delete"
|
||||||
@@ -345,6 +345,14 @@ export const identityTokenAuthServiceFactory = ({
|
|||||||
const identityTokenAuth = await identityTokenAuthDAL.findOne({ identityId });
|
const identityTokenAuth = await identityTokenAuthDAL.findOne({ identityId });
|
||||||
|
|
||||||
const identityAccessToken = await identityTokenAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityTokenAuthDAL.transaction(async (tx) => {
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.TOKEN_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityTokenAuth.identityId,
|
identityId: identityTokenAuth.identityId,
|
||||||
|
|||||||
@@ -59,6 +59,11 @@ export const identityUaServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityUa.identityId });
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityUa.identityId });
|
||||||
|
if (!identityMembershipOrg) {
|
||||||
|
throw new NotFoundError({
|
||||||
|
message: "No identity with the org membership was found"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
checkIPAgainstBlocklist({
|
checkIPAgainstBlocklist({
|
||||||
ipAddress: ip,
|
ipAddress: ip,
|
||||||
@@ -127,7 +132,14 @@ export const identityUaServiceFactory = ({
|
|||||||
|
|
||||||
const identityAccessToken = await identityUaDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityUaDAL.transaction(async (tx) => {
|
||||||
const uaClientSecretDoc = await identityUaClientSecretDAL.incrementUsage(validClientSecretInfo!.id, tx);
|
const uaClientSecretDoc = await identityUaClientSecretDAL.incrementUsage(validClientSecretInfo!.id, tx);
|
||||||
|
await identityOrgMembershipDAL.updateById(
|
||||||
|
identityMembershipOrg.id,
|
||||||
|
{
|
||||||
|
lastLoginAuthMethod: IdentityAuthMethod.UNIVERSAL_AUTH,
|
||||||
|
lastLoginTime: new Date()
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
const newToken = await identityAccessTokenDAL.create(
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
{
|
{
|
||||||
identityId: identityUa.identityId,
|
identityId: identityUa.identityId,
|
||||||
|
|||||||
@@ -254,6 +254,8 @@ export const identityOrgDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("role").withSchema("paginatedIdentity"),
|
db.ref("role").withSchema("paginatedIdentity"),
|
||||||
db.ref("roleId").withSchema("paginatedIdentity"),
|
db.ref("roleId").withSchema("paginatedIdentity"),
|
||||||
db.ref("orgId").withSchema("paginatedIdentity"),
|
db.ref("orgId").withSchema("paginatedIdentity"),
|
||||||
|
db.ref("lastLoginAuthMethod").withSchema("paginatedIdentity"),
|
||||||
|
db.ref("lastLoginTime").withSchema("paginatedIdentity"),
|
||||||
db.ref("createdAt").withSchema("paginatedIdentity"),
|
db.ref("createdAt").withSchema("paginatedIdentity"),
|
||||||
db.ref("updatedAt").withSchema("paginatedIdentity"),
|
db.ref("updatedAt").withSchema("paginatedIdentity"),
|
||||||
db.ref("identityId").withSchema("paginatedIdentity").as("identityId"),
|
db.ref("identityId").withSchema("paginatedIdentity").as("identityId"),
|
||||||
@@ -319,7 +321,9 @@ export const identityOrgDALFactory = (db: TDbClient) => {
|
|||||||
ldapId,
|
ldapId,
|
||||||
tlsCertId,
|
tlsCertId,
|
||||||
createdAt,
|
createdAt,
|
||||||
updatedAt
|
updatedAt,
|
||||||
|
lastLoginAuthMethod,
|
||||||
|
lastLoginTime
|
||||||
}) => ({
|
}) => ({
|
||||||
role,
|
role,
|
||||||
roleId,
|
roleId,
|
||||||
@@ -328,6 +332,8 @@ export const identityOrgDALFactory = (db: TDbClient) => {
|
|||||||
orgId,
|
orgId,
|
||||||
createdAt,
|
createdAt,
|
||||||
updatedAt,
|
updatedAt,
|
||||||
|
lastLoginAuthMethod,
|
||||||
|
lastLoginTime,
|
||||||
customRole: roleId
|
customRole: roleId
|
||||||
? {
|
? {
|
||||||
id: crId,
|
id: crId,
|
||||||
@@ -497,6 +503,8 @@ export const identityOrgDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("orgId").withSchema(TableName.IdentityOrgMembership),
|
db.ref("orgId").withSchema(TableName.IdentityOrgMembership),
|
||||||
db.ref("createdAt").withSchema(TableName.IdentityOrgMembership),
|
db.ref("createdAt").withSchema(TableName.IdentityOrgMembership),
|
||||||
db.ref("updatedAt").withSchema(TableName.IdentityOrgMembership),
|
db.ref("updatedAt").withSchema(TableName.IdentityOrgMembership),
|
||||||
|
db.ref("lastLoginAuthMethod").withSchema(TableName.IdentityOrgMembership),
|
||||||
|
db.ref("lastLoginTime").withSchema(TableName.IdentityOrgMembership),
|
||||||
db.ref("identityId").withSchema(TableName.IdentityOrgMembership).as("identityId"),
|
db.ref("identityId").withSchema(TableName.IdentityOrgMembership).as("identityId"),
|
||||||
db.ref("name").withSchema(TableName.Identity).as("identityName"),
|
db.ref("name").withSchema(TableName.Identity).as("identityName"),
|
||||||
db.ref("hasDeleteProtection").withSchema(TableName.Identity),
|
db.ref("hasDeleteProtection").withSchema(TableName.Identity),
|
||||||
@@ -576,7 +584,9 @@ export const identityOrgDALFactory = (db: TDbClient) => {
|
|||||||
tokenId,
|
tokenId,
|
||||||
ldapId,
|
ldapId,
|
||||||
createdAt,
|
createdAt,
|
||||||
updatedAt
|
updatedAt,
|
||||||
|
lastLoginTime,
|
||||||
|
lastLoginAuthMethod
|
||||||
}) => ({
|
}) => ({
|
||||||
role,
|
role,
|
||||||
roleId,
|
roleId,
|
||||||
@@ -586,6 +596,8 @@ export const identityOrgDALFactory = (db: TDbClient) => {
|
|||||||
orgId,
|
orgId,
|
||||||
createdAt,
|
createdAt,
|
||||||
updatedAt,
|
updatedAt,
|
||||||
|
lastLoginTime,
|
||||||
|
lastLoginAuthMethod,
|
||||||
customRole: roleId
|
customRole: roleId
|
||||||
? {
|
? {
|
||||||
id: crId,
|
id: crId,
|
||||||
|
|||||||
@@ -32,6 +32,8 @@ export const orgMembershipDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("roleId").withSchema(TableName.OrgMembership),
|
db.ref("roleId").withSchema(TableName.OrgMembership),
|
||||||
db.ref("status").withSchema(TableName.OrgMembership),
|
db.ref("status").withSchema(TableName.OrgMembership),
|
||||||
db.ref("isActive").withSchema(TableName.OrgMembership),
|
db.ref("isActive").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("lastLoginAuthMethod").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("lastLoginTime").withSchema(TableName.OrgMembership),
|
||||||
db.ref("email").withSchema(TableName.Users),
|
db.ref("email").withSchema(TableName.Users),
|
||||||
db.ref("username").withSchema(TableName.Users),
|
db.ref("username").withSchema(TableName.Users),
|
||||||
db.ref("firstName").withSchema(TableName.Users),
|
db.ref("firstName").withSchema(TableName.Users),
|
||||||
@@ -64,7 +66,9 @@ export const orgMembershipDALFactory = (db: TDbClient) => {
|
|||||||
role,
|
role,
|
||||||
status,
|
status,
|
||||||
isActive,
|
isActive,
|
||||||
inviteEmail
|
inviteEmail,
|
||||||
|
lastLoginAuthMethod,
|
||||||
|
lastLoginTime
|
||||||
}) => ({
|
}) => ({
|
||||||
roleId,
|
roleId,
|
||||||
orgId,
|
orgId,
|
||||||
@@ -73,6 +77,8 @@ export const orgMembershipDALFactory = (db: TDbClient) => {
|
|||||||
status,
|
status,
|
||||||
isActive,
|
isActive,
|
||||||
inviteEmail,
|
inviteEmail,
|
||||||
|
lastLoginAuthMethod,
|
||||||
|
lastLoginTime,
|
||||||
user: {
|
user: {
|
||||||
id: userId,
|
id: userId,
|
||||||
email,
|
email,
|
||||||
|
|||||||
@@ -285,6 +285,8 @@ export const orgDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("roleId").withSchema(TableName.OrgMembership),
|
db.ref("roleId").withSchema(TableName.OrgMembership),
|
||||||
db.ref("status").withSchema(TableName.OrgMembership),
|
db.ref("status").withSchema(TableName.OrgMembership),
|
||||||
db.ref("isActive").withSchema(TableName.OrgMembership),
|
db.ref("isActive").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("lastLoginAuthMethod").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("lastLoginTime").withSchema(TableName.OrgMembership),
|
||||||
db.ref("email").withSchema(TableName.Users),
|
db.ref("email").withSchema(TableName.Users),
|
||||||
db.ref("isEmailVerified").withSchema(TableName.Users),
|
db.ref("isEmailVerified").withSchema(TableName.Users),
|
||||||
db.ref("username").withSchema(TableName.Users),
|
db.ref("username").withSchema(TableName.Users),
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
import { faClock, faShield } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { format } from "date-fns";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
lastLoginAuthMethod: string;
|
||||||
|
lastLoginTime: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const LastLoginSection = ({ lastLoginTime, lastLoginAuthMethod }: Props) => (
|
||||||
|
<div>
|
||||||
|
<div className="mb-2 flex items-center gap-2 border-b border-mineshaft-600 pb-1">
|
||||||
|
<div className="font-medium">Last Login</div>
|
||||||
|
</div>
|
||||||
|
<div className="mb-2 flex items-center gap-2 text-sm">
|
||||||
|
<div className="flex items-center justify-center rounded bg-mineshaft-700 p-3">
|
||||||
|
<FontAwesomeIcon icon={faShield} className="h-4 w-4" />
|
||||||
|
</div>
|
||||||
|
<div className="flex flex-col">
|
||||||
|
<div className="text-sm font-medium">Authentication Method</div>
|
||||||
|
<div className="text-sm">{lastLoginAuthMethod}</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div className="flex items-center gap-2 text-sm">
|
||||||
|
<div className="flex items-center justify-center rounded bg-mineshaft-700 p-3">
|
||||||
|
<FontAwesomeIcon icon={faClock} className="h-4 w-4" />
|
||||||
|
</div>
|
||||||
|
<div className="flex flex-col">
|
||||||
|
<div className="text-sm font-medium">Time</div>
|
||||||
|
<div className="text-sm">{format(lastLoginTime, "PPpp")} </div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
export { LastLoginSection } from "./LastLoginSection";
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import { forwardRef } from "react";
|
||||||
import { cva, VariantProps } from "cva";
|
import { cva, VariantProps } from "cva";
|
||||||
import { twMerge } from "tailwind-merge";
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
@@ -24,13 +25,16 @@ const badgeVariants = cva(
|
|||||||
|
|
||||||
export type BadgeProps = VariantProps<typeof badgeVariants> & IProps;
|
export type BadgeProps = VariantProps<typeof badgeVariants> & IProps;
|
||||||
|
|
||||||
export const Badge = ({ children, className, variant, ...props }: BadgeProps) => {
|
export const Badge = forwardRef<HTMLDivElement, BadgeProps>(
|
||||||
|
({ children, className, variant, ...props }, ref) => {
|
||||||
return (
|
return (
|
||||||
<div
|
<div
|
||||||
className={twMerge(badgeVariants({ variant: variant || "primary" }), className)}
|
className={twMerge(badgeVariants({ variant: variant || "primary" }), className)}
|
||||||
{...props}
|
{...props}
|
||||||
|
ref={ref}
|
||||||
>
|
>
|
||||||
{children}
|
{children}
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
};
|
}
|
||||||
|
);
|
||||||
|
|||||||
@@ -41,6 +41,8 @@ export type IdentityMembershipOrg = {
|
|||||||
id: string;
|
id: string;
|
||||||
identity: Identity;
|
identity: Identity;
|
||||||
organization: string;
|
organization: string;
|
||||||
|
lastLoginAuthMethod?: IdentityAuthMethod;
|
||||||
|
lastLoginTime?: string;
|
||||||
metadata: { key: string; value: string; id: string }[];
|
metadata: { key: string; value: string; id: string }[];
|
||||||
role: "admin" | "member" | "viewer" | "no-access" | "custom";
|
role: "admin" | "member" | "viewer" | "no-access" | "custom";
|
||||||
customRole?: TOrgRole;
|
customRole?: TOrgRole;
|
||||||
|
|||||||
@@ -68,6 +68,8 @@ export type OrgUser = {
|
|||||||
deniedPermissions: any[];
|
deniedPermissions: any[];
|
||||||
roleId: string;
|
roleId: string;
|
||||||
isActive: boolean;
|
isActive: boolean;
|
||||||
|
lastLoginAuthMethod?: AuthMethod;
|
||||||
|
lastLoginTime?: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TProjectMembership = {
|
export type TProjectMembership = {
|
||||||
|
|||||||
+38
-4
@@ -7,6 +7,7 @@ import {
|
|||||||
faEdit,
|
faEdit,
|
||||||
faEllipsisV,
|
faEllipsisV,
|
||||||
faFilter,
|
faFilter,
|
||||||
|
faInfoCircle,
|
||||||
faMagnifyingGlass,
|
faMagnifyingGlass,
|
||||||
faServer,
|
faServer,
|
||||||
faTrash
|
faTrash
|
||||||
@@ -16,6 +17,7 @@ import { useNavigate } from "@tanstack/react-router";
|
|||||||
import { twMerge } from "tailwind-merge";
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { LastLoginSection } from "@app/components/organization/LastLoginSection";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import {
|
import {
|
||||||
DropdownMenu,
|
DropdownMenu,
|
||||||
@@ -40,6 +42,7 @@ import {
|
|||||||
Td,
|
Td,
|
||||||
Th,
|
Th,
|
||||||
THead,
|
THead,
|
||||||
|
Tooltip,
|
||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { OrgPermissionIdentityActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionIdentityActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
@@ -49,7 +52,12 @@ import {
|
|||||||
setUserTablePreference
|
setUserTablePreference
|
||||||
} from "@app/helpers/userTablePreferences";
|
} from "@app/helpers/userTablePreferences";
|
||||||
import { usePagination, useResetPageHelper } from "@app/hooks";
|
import { usePagination, useResetPageHelper } from "@app/hooks";
|
||||||
import { useGetOrgRoles, useSearchIdentities, useUpdateIdentity } from "@app/hooks/api";
|
import {
|
||||||
|
identityAuthToNameMap,
|
||||||
|
useGetOrgRoles,
|
||||||
|
useSearchIdentities,
|
||||||
|
useUpdateIdentity
|
||||||
|
} from "@app/hooks/api";
|
||||||
import { OrderByDirection } from "@app/hooks/api/generic/types";
|
import { OrderByDirection } from "@app/hooks/api/generic/types";
|
||||||
import { OrgIdentityOrderBy } from "@app/hooks/api/organization/types";
|
import { OrgIdentityOrderBy } from "@app/hooks/api/organization/types";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
@@ -284,7 +292,14 @@ export const IdentityTable = ({ handlePopUpOpen }: Props) => {
|
|||||||
<TBody>
|
<TBody>
|
||||||
{isPending && <TableSkeleton columns={3} innerKey="org-identities" />}
|
{isPending && <TableSkeleton columns={3} innerKey="org-identities" />}
|
||||||
{!isPending &&
|
{!isPending &&
|
||||||
data?.identities?.map(({ identity: { id, name }, role, customRole }) => {
|
data?.identities?.map(
|
||||||
|
({
|
||||||
|
identity: { id, name },
|
||||||
|
role,
|
||||||
|
customRole,
|
||||||
|
lastLoginAuthMethod,
|
||||||
|
lastLoginTime
|
||||||
|
}) => {
|
||||||
return (
|
return (
|
||||||
<Tr
|
<Tr
|
||||||
className="h-10 cursor-pointer transition-colors duration-100 hover:bg-mineshaft-700"
|
className="h-10 cursor-pointer transition-colors duration-100 hover:bg-mineshaft-700"
|
||||||
@@ -298,7 +313,25 @@ export const IdentityTable = ({ handlePopUpOpen }: Props) => {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
>
|
>
|
||||||
<Td>{name}</Td>
|
<Td className="group">
|
||||||
|
{name}
|
||||||
|
{lastLoginAuthMethod && lastLoginTime && (
|
||||||
|
<Tooltip
|
||||||
|
className="min-w-52 max-w-96 px-3"
|
||||||
|
content={
|
||||||
|
<LastLoginSection
|
||||||
|
lastLoginAuthMethod={identityAuthToNameMap[lastLoginAuthMethod]}
|
||||||
|
lastLoginTime={lastLoginTime}
|
||||||
|
/>
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon
|
||||||
|
icon={faInfoCircle}
|
||||||
|
className="ml-2 text-mineshaft-400 opacity-0 transition-all group-hover:opacity-100"
|
||||||
|
/>
|
||||||
|
</Tooltip>
|
||||||
|
)}
|
||||||
|
</Td>
|
||||||
<Td>
|
<Td>
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={OrgPermissionIdentityActions.Edit}
|
I={OrgPermissionIdentityActions.Edit}
|
||||||
@@ -389,7 +422,8 @@ export const IdentityTable = ({ handlePopUpOpen }: Props) => {
|
|||||||
</Td>
|
</Td>
|
||||||
</Tr>
|
</Tr>
|
||||||
);
|
);
|
||||||
})}
|
}
|
||||||
|
)}
|
||||||
</TBody>
|
</TBody>
|
||||||
</Table>
|
</Table>
|
||||||
{!isPending && data && totalCount > 0 && (
|
{!isPending && data && totalCount > 0 && (
|
||||||
|
|||||||
+32
-2
@@ -7,6 +7,7 @@ import {
|
|||||||
faEdit,
|
faEdit,
|
||||||
faEllipsisV,
|
faEllipsisV,
|
||||||
faFilter,
|
faFilter,
|
||||||
|
faInfoCircle,
|
||||||
faMagnifyingGlass,
|
faMagnifyingGlass,
|
||||||
faSearch,
|
faSearch,
|
||||||
faUsers,
|
faUsers,
|
||||||
@@ -19,6 +20,7 @@ import { useNavigate } from "@tanstack/react-router";
|
|||||||
import { twMerge } from "tailwind-merge";
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { LastLoginSection } from "@app/components/organization/LastLoginSection";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import {
|
import {
|
||||||
Badge,
|
Badge,
|
||||||
@@ -471,7 +473,17 @@ export const OrgMembersTable = ({
|
|||||||
{isLoading && <TableSkeleton columns={5} innerKey="org-members" />}
|
{isLoading && <TableSkeleton columns={5} innerKey="org-members" />}
|
||||||
{!isLoading &&
|
{!isLoading &&
|
||||||
filteredMembersPage.map(
|
filteredMembersPage.map(
|
||||||
({ user: u, inviteEmail, role, roleId, id: orgMembershipId, status, isActive }) => {
|
({
|
||||||
|
user: u,
|
||||||
|
inviteEmail,
|
||||||
|
role,
|
||||||
|
roleId,
|
||||||
|
id: orgMembershipId,
|
||||||
|
status,
|
||||||
|
isActive,
|
||||||
|
lastLoginAuthMethod,
|
||||||
|
lastLoginTime
|
||||||
|
}) => {
|
||||||
const name =
|
const name =
|
||||||
u && u.firstName ? `${u.firstName} ${u.lastName ?? ""}`.trim() : null;
|
u && u.firstName ? `${u.firstName} ${u.lastName ?? ""}`.trim() : null;
|
||||||
const email = u?.email || inviteEmail;
|
const email = u?.email || inviteEmail;
|
||||||
@@ -504,7 +516,9 @@ export const OrgMembersTable = ({
|
|||||||
}}
|
}}
|
||||||
/>
|
/>
|
||||||
</Td>
|
</Td>
|
||||||
<Td className={twMerge("max-w-0", isActive ? "" : "text-mineshaft-400")}>
|
<Td
|
||||||
|
className={twMerge("group max-w-0", isActive ? "" : "text-mineshaft-400")}
|
||||||
|
>
|
||||||
<div className="flex items-center">
|
<div className="flex items-center">
|
||||||
<p className="truncate">
|
<p className="truncate">
|
||||||
{name ?? <span className="text-mineshaft-400">Not Set</span>}
|
{name ?? <span className="text-mineshaft-400">Not Set</span>}
|
||||||
@@ -517,6 +531,22 @@ export const OrgMembersTable = ({
|
|||||||
</Tooltip>
|
</Tooltip>
|
||||||
</Badge>
|
</Badge>
|
||||||
)}
|
)}
|
||||||
|
{lastLoginAuthMethod && lastLoginTime && (
|
||||||
|
<Tooltip
|
||||||
|
className="min-w-52 max-w-96 px-3"
|
||||||
|
content={
|
||||||
|
<LastLoginSection
|
||||||
|
lastLoginAuthMethod={lastLoginAuthMethod}
|
||||||
|
lastLoginTime={lastLoginTime}
|
||||||
|
/>
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon
|
||||||
|
icon={faInfoCircle}
|
||||||
|
className="ml-2 text-mineshaft-400 opacity-0 transition-all group-hover:opacity-100"
|
||||||
|
/>
|
||||||
|
</Tooltip>
|
||||||
|
)}
|
||||||
</div>
|
</div>
|
||||||
</Td>
|
</Td>
|
||||||
<Td className={twMerge("max-w-0", isActive ? "" : "text-mineshaft-400")}>
|
<Td className={twMerge("max-w-0", isActive ? "" : "text-mineshaft-400")}>
|
||||||
|
|||||||
+14
-1
@@ -7,6 +7,7 @@ import {
|
|||||||
faTrash
|
faTrash
|
||||||
} from "@fortawesome/free-solid-svg-icons";
|
} from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { format } from "date-fns";
|
||||||
import { twMerge } from "tailwind-merge";
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
@@ -22,7 +23,7 @@ import {
|
|||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { OrgPermissionIdentityActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionIdentityActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import { useTimedReset } from "@app/hooks";
|
import { useTimedReset } from "@app/hooks";
|
||||||
import { useGetIdentityById } from "@app/hooks/api";
|
import { identityAuthToNameMap, useGetIdentityById } from "@app/hooks/api";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
@@ -138,6 +139,18 @@ export const IdentityDetailsSection = ({ identityId, handlePopUpOpen }: Props) =
|
|||||||
<p className="text-sm font-semibold text-mineshaft-300">Name</p>
|
<p className="text-sm font-semibold text-mineshaft-300">Name</p>
|
||||||
<p className="text-sm text-mineshaft-300">{data.identity.name}</p>
|
<p className="text-sm text-mineshaft-300">{data.identity.name}</p>
|
||||||
</div>
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Last Login Auth Method</p>
|
||||||
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
{data.lastLoginAuthMethod ? identityAuthToNameMap[data.lastLoginAuthMethod] : "-"}
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Last Login Time</p>
|
||||||
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
{data.lastLoginTime ? format(data.lastLoginTime, "PPpp") : "-"}
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
<div className="mb-4">
|
<div className="mb-4">
|
||||||
<p className="text-sm font-semibold text-mineshaft-300">Delete Protection</p>
|
<p className="text-sm font-semibold text-mineshaft-300">Delete Protection</p>
|
||||||
<p className="text-sm text-mineshaft-300">
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ import {
|
|||||||
faPencil
|
faPencil
|
||||||
} from "@fortawesome/free-solid-svg-icons";
|
} from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { format } from "date-fns";
|
||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
@@ -159,6 +160,22 @@ export const UserDetailsSection = ({ membershipId, handlePopUpOpen }: Props) =>
|
|||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Last Login Auth Method</p>
|
||||||
|
<div className="group flex align-top">
|
||||||
|
<p className="break-all text-sm text-mineshaft-300">
|
||||||
|
{membership.lastLoginAuthMethod || "-"}
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Last Login Time</p>
|
||||||
|
<div className="group flex align-top">
|
||||||
|
<p className="break-all text-sm text-mineshaft-300">
|
||||||
|
{membership.lastLoginTime ? format(membership.lastLoginTime, "PPpp") : "-"}
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
<div className="mb-4">
|
<div className="mb-4">
|
||||||
<p className="text-sm font-semibold text-mineshaft-300">Organization Role</p>
|
<p className="text-sm font-semibold text-mineshaft-300">Organization Role</p>
|
||||||
<p className="text-sm text-mineshaft-300">{roleName ?? "-"}</p>
|
<p className="text-sm text-mineshaft-300">{roleName ?? "-"}</p>
|
||||||
|
|||||||
Reference in New Issue
Block a user