CB-2830 send auth provider in auth info (#1263)

* CB-2830 send auth provider in auth info

* CB-1424 feat: provider / configuration logout

* CB-1424 fix: provider logout

Co-authored-by: Aleksey Potsetsuev <wrouds@gmail.com>
This commit is contained in:
Alexander Skoblikov
2022-11-10 20:20:21 +03:00
committed by GitHub
co-authored by Aleksey Potsetsuev
parent 537bfda887
commit bc4677ccde
9 changed files with 119 additions and 143 deletions
@@ -19,7 +19,6 @@ package io.cloudbeaver.model.session;
import io.cloudbeaver.DBWUserIdentity;
import io.cloudbeaver.model.user.WebUser;
import io.cloudbeaver.model.user.WebUserOriginInfo;
import io.cloudbeaver.registry.WebAuthProviderConfiguration;
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.Log;
@@ -41,7 +40,7 @@ public class WebAuthInfo implements SMSessionPrincipal {
private final WebSession session;
private final WebUser user;
private final WebAuthProviderDescriptor authProvider;
private WebAuthProviderConfiguration authProviderConfiguration;
private String authProviderConfigurationId;
private SMSession authSession;
private final OffsetDateTime loginTime;
private final DBWUserIdentity userIdentity;
@@ -101,7 +100,11 @@ public class WebAuthInfo implements SMSessionPrincipal {
@Property
public String getAuthConfiguration() {
return authProviderConfiguration == null ? null : authProviderConfiguration.getId();
return authProviderConfigurationId;
}
public void setAuthProviderConfigurationId(String authProviderConfigurationId) {
this.authProviderConfigurationId = authProviderConfigurationId;
}
public WebUser getUser() {
@@ -116,14 +119,6 @@ public class WebAuthInfo implements SMSessionPrincipal {
return authProvider;
}
public WebAuthProviderConfiguration getAuthProviderConfiguration() {
return authProviderConfiguration;
}
public void setAuthProviderConfiguration(WebAuthProviderConfiguration authProviderConfiguration) {
this.authProviderConfiguration = authProviderConfiguration;
}
public SMSession getAuthSession() {
return authSession;
}
@@ -29,6 +29,7 @@ import io.cloudbeaver.utils.WebAppUtils;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.auth.SMAuthConfigurationReference;
import org.jkiss.dbeaver.model.auth.SMAuthInfo;
import org.jkiss.dbeaver.model.auth.SMAuthProvider;
import org.jkiss.dbeaver.model.auth.SMSession;
@@ -87,8 +88,8 @@ public class WebSessionAuthProcessor {
try {
if (configMode && alreadyLoggedIn) {
for (String providerId : authInfo.getAuthData().keySet()) {
webSession.removeAuthInfo(providerId);
for (SMAuthConfigurationReference authConfiguration : authInfo.getAuthData().keySet()) {
webSession.removeAuthInfo(authConfiguration.getAuthProviderId());
}
}
webSession.updateSMAuthInfo(authInfo);
@@ -102,8 +103,9 @@ public class WebSessionAuthProcessor {
var securityController = webSession.getSecurityController();
Map<String, Object> providerConfig = Collections.emptyMap();
var newAuthInfos = new ArrayList<WebAuthInfo>();
for (Map.Entry<String, Object> entry : authInfo.getAuthData().entrySet()) {
String providerId = entry.getKey();
for (Map.Entry<SMAuthConfigurationReference, Object> entry : authInfo.getAuthData().entrySet()) {
SMAuthConfigurationReference authConfiguration = entry.getKey();
String providerId = authConfiguration.getAuthProviderId();
Map<String, Object> authAttrs = (Map<String, Object>) entry.getValue();
var authProviderDescriptor = getAuthProvider(providerId);
@@ -111,15 +113,13 @@ public class WebSessionAuthProcessor {
SMAuthProviderExternal<?> authProviderExternal = authProviderInstance instanceof SMAuthProviderExternal<?> ?
(SMAuthProviderExternal<?>) authProviderInstance : null;
boolean providerEnabled = isProviderEnabled(providerId);
boolean providerDisabled = !isProviderEnabled(providerId);
if (configMode || webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) {
// 1. Admin can authorize in any providers
// 2. When it authorizes in non-local provider for the first time we force linkUser flag
if (!providerEnabled && webSession.getUser() != null) {
if (providerDisabled && webSession.getUser() != null) {
linkWithActiveUser = true;
}
} else if (!providerEnabled && !webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) {
throw new DBWebException("Authentication provider '" + providerId + "' is disabled");
}
SMSession authSession;
@@ -174,7 +174,9 @@ public class WebSessionAuthProcessor {
authProviderDescriptor,
userIdentity,
authSession,
OffsetDateTime.now());
OffsetDateTime.now()
);
webAuthInfo.setAuthProviderConfigurationId(authConfiguration.getAuthProviderConfigurationId());
webAuthInfo.setMessage("Authenticated with " + authProviderDescriptor.getLabel() + " provider");
if (configMode) {
webAuthInfo.setUserCredentials(authAttrs);
@@ -1037,17 +1037,17 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
if (SMAuthProviderFederated.class.isAssignableFrom(authProviderInstance.getClass())) {
//async auth
var authProviderFederated = (SMAuthProviderFederated) authProviderInstance;
var redirectUrl = buildRedirectLink(
authProviderFederated.getSignInLink(authProviderConfigurationId, Map.of()),
var redirectUrl = buildRedirectLink(authProviderFederated.getSignInLink(authProviderConfigurationId, Map.of()),
authAttemptId);
return SMAuthInfo.inProgress(authAttemptId, redirectUrl, filteredUserCreds);
Map<SMAuthConfigurationReference, Object> authData = Map.of(new SMAuthConfigurationReference(authProviderId,
authProviderConfigurationId), filteredUserCreds);
return SMAuthInfo.inProgress(authAttemptId, redirectUrl, authData);
}
txn.commit();
return finishAuthentication(
SMAuthInfo.inProgress(
authAttemptId,
null,
Map.of(authProviderId, securedUserIdentifyingCredentials)
null, Map.of(new SMAuthConfigurationReference(authProviderId, null), securedUserIdentifyingCredentials)
),
true,
false
@@ -1125,10 +1125,12 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
}
@Override
public void updateAuthStatus(@NotNull String authId,
@NotNull SMAuthStatus authStatus,
@NotNull Map<String, Object> authInfo,
@Nullable String error) throws DBException {
public void updateAuthStatus(
@NotNull String authId,
@NotNull SMAuthStatus authStatus,
@NotNull Map<SMAuthConfigurationReference, Object> authInfo,
@Nullable String error
) throws DBException {
var existAuthInfo = getAuthStatus(authId);
if (existAuthInfo.getAuthStatus() != SMAuthStatus.IN_PROGRESS) {
throw new SMException("Authorization already finished and cannot be updated");
@@ -1137,13 +1139,14 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
updateAuthStatus(authId, authStatus, authInfo, error, authSessionInfo.getSmSessionId());
}
private void updateAuthStatus(@NotNull String authId,
@NotNull SMAuthStatus authStatus,
@NotNull Map<String, Object> authInfo,
@Nullable String error,
@Nullable String smSessionId) throws DBException {
try (Connection dbCon = database.openConnection();
JDBCTransaction txn = new JDBCTransaction(dbCon)) {
private void updateAuthStatus(
@NotNull String authId,
@NotNull SMAuthStatus authStatus,
@NotNull Map<SMAuthConfigurationReference, Object> authInfo,
@Nullable String error,
@Nullable String smSessionId
) throws DBException {
try (Connection dbCon = database.openConnection(); JDBCTransaction txn = new JDBCTransaction(dbCon)) {
try (PreparedStatement dbStat = dbCon.prepareStatement(
"UPDATE CB_AUTH_ATTEMPT SET AUTH_STATUS=?,AUTH_ERROR=?,SESSION_ID=? WHERE AUTH_ID=?")) {
dbStat.setString(1, authStatus.toString());
@@ -1155,20 +1158,29 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
}
}
for (Map.Entry<String, Object> entry : authInfo.entrySet()) {
String providerId = entry.getKey();
for (Map.Entry<SMAuthConfigurationReference, Object> entry : authInfo.entrySet()) {
SMAuthConfigurationReference providerId = entry.getKey();
String authJson = gson.toJson(entry.getValue());
try (PreparedStatement dbStat = dbCon.prepareStatement(
"UPDATE CB_AUTH_ATTEMPT_INFO SET AUTH_STATE=? WHERE AUTH_ID=? AND AUTH_PROVIDER_ID=?")) {
boolean configIdExist = providerId.getAuthProviderConfigurationId() != null;
var sqlBuilder = new StringBuilder();
sqlBuilder.append("UPDATE CB_AUTH_ATTEMPT_INFO SET AUTH_STATE=? ")
.append("WHERE AUTH_ID=? AND AUTH_PROVIDER_ID=? AND ")
.append(configIdExist ? "AUTH_PROVIDER_CONFIGURATION_ID=?" : "AUTH_PROVIDER_CONFIGURATION_ID IS NULL");
try (PreparedStatement dbStat = dbCon.prepareStatement(sqlBuilder.toString())) {
dbStat.setString(1, authJson);
dbStat.setString(2, authId);
dbStat.setString(3, providerId);
dbStat.setString(3, providerId.getAuthProviderId());
if (configIdExist) {
dbStat.setString(4, providerId.getAuthProviderConfigurationId());
}
if (dbStat.executeUpdate() <= 0) {
try (PreparedStatement dbStatIns = dbCon.prepareStatement(
"INSERT INTO CB_AUTH_ATTEMPT_INFO (AUTH_ID,AUTH_PROVIDER_ID,AUTH_STATE) VALUES(?,?,?)")) {
"INSERT INTO CB_AUTH_ATTEMPT_INFO (AUTH_ID,AUTH_PROVIDER_ID,AUTH_PROVIDER_CONFIGURATION_ID,AUTH_STATE) "
+ "VALUES(?,?,?,?)")) {
dbStatIns.setString(1, authId);
dbStatIns.setString(2, providerId);
dbStatIns.setString(3, authJson);
dbStatIns.setString(2, providerId.getAuthProviderId());
dbStatIns.setString(3, providerId.getAuthProviderConfigurationId());
dbStatIns.setString(4, authJson);
dbStatIns.execute();
}
}
@@ -1199,7 +1211,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
smSessionId = dbResult.getString(3);
}
}
Map<String, Object> authData = new LinkedHashMap<>();
Map<SMAuthConfigurationReference, Object> authData = new LinkedHashMap<>();
String redirectUrl = null;
try (PreparedStatement dbStat = dbCon.prepareStatement(
@@ -1217,14 +1229,13 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
WebAuthProviderDescriptor authProviderDescriptor = getAuthProvider(authProviderId);
var authProviderInstance = authProviderDescriptor.getInstance();
if (SMAuthProviderFederated.class.isAssignableFrom(authProviderInstance.getClass())) {
redirectUrl = buildRedirectLink(
((SMAuthProviderFederated) authProviderInstance).getRedirectLink(authProviderConfiguration, Map.of()),
authId
);
redirectUrl = buildRedirectLink(((SMAuthProviderFederated) authProviderInstance).getRedirectLink(
authProviderConfiguration,
Map.of()), authId);
}
}
authData.put(authProviderId, authProviderData);
authData.put(new SMAuthConfigurationReference(authProviderId, authProviderConfiguration), authProviderData);
}
}
}
@@ -1368,7 +1379,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
if (authInfo.getAuthStatus() != SMAuthStatus.IN_PROGRESS) {
throw new SMException("Authorization has already been completed with status: " + authInfo.getAuthStatus());
}
Set<String> authProviderIds = authInfo.getAuthData().keySet();
Set<SMAuthConfigurationReference> authProviderIds = authInfo.getAuthData().keySet();
if (authProviderIds.isEmpty()) {
throw new SMException("Authorization providers are not defined");
}
@@ -1386,20 +1397,19 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
}
String activeUserId = permissions == null ? null : permissions.getUserId();
Map<String, Object> storedUserData = new LinkedHashMap<>();
Map<SMAuthConfigurationReference, Object> storedUserData = new LinkedHashMap<>();
SMTeam[] allTeams = null;
String detectedAuthRole = null;
for (String authProviderId : authProviderIds) {
for (SMAuthConfigurationReference authConfiguration : authProviderIds) {
String authProviderId = authConfiguration.getAuthProviderId();
WebAuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
var userAuthData = (Map<String, Object>) authInfo.getAuthData().get(authProviderId);
var userAuthData = (Map<String, Object>) authInfo.getAuthData().get(authConfiguration);
SMAutoAssign autoAssign = getAutoAssignUserData(authId, authProvider, userAuthData, finishAuthMonitor);
if (autoAssign != null) {
detectedAuthRole = autoAssign.getAuthRole();
}
var userIdFromCreds = findOrCreateExternalUserByCredentials(
authProvider,
authAttemptSessionInfo.getSessionParams(),
var userIdFromCreds = findOrCreateExternalUserByCredentials(authProvider, authAttemptSessionInfo.getSessionParams(),
userAuthData,
finishAuthMonitor,
activeUserId,
@@ -1423,10 +1433,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
if (activeUserId == null) {
activeUserId = userIdFromCreds;
}
storedUserData.put(
authProviderId,
saveSecuredCreds ? userAuthData : filterSecuredUserData(userAuthData, getAuthProvider(authProviderId))
);
storedUserData.put(authConfiguration,
saveSecuredCreds ? userAuthData : filterSecuredUserData(userAuthData, getAuthProvider(authProviderId)));
}
String tokenAuthRole = updateUserAuthRoleIfNeeded(activeUserId, detectedAuthRole);
@@ -2156,4 +2164,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
return activeUserCredentials.getUserId();
}
private boolean isProviderEnabled(@NotNull String providerId) {
WebAuthConfiguration appConfiguration = application.getAuthConfiguration();
return appConfiguration.isAuthProviderEnabled(providerId);
}
}
@@ -15,15 +15,20 @@ import { uuid } from '@cloudbeaver/core-utils';
import { AuthProvidersResource, AuthProviderConfiguration } from './AuthProvidersResource';
import { type ILoginOptions, UserInfoResource } from './UserInfoResource';
export interface IUserAuthConfiguration {
providerId: string;
configuration: AuthProviderConfiguration;
}
@injectable()
export class AuthInfoService {
get userInfo(): UserInfo | null {
return this.userInfoResource.data;
}
get userAuthConfigurations(): AuthProviderConfiguration[] {
get userAuthConfigurations(): IUserAuthConfiguration[] {
const tokens = this.userInfo?.authTokens;
const result: AuthProviderConfiguration[] = [];
const result: IUserAuthConfiguration[] = [];
if (!tokens) {
return result;
@@ -41,7 +46,7 @@ export class AuthInfoService {
);
if (configuration) {
result.push(configuration);
result.push({ providerId: provider.id, configuration });
}
}
}
@@ -158,9 +158,13 @@ UserInfoIncludes
});
}
async logout(): Promise<void> {
if (this.data) {
await this.graphQLService.sdk.authLogout();
async logout(provider?: string, configuration?: string): Promise<void> {
await this.graphQLService.sdk.authLogout({
provider,
configuration,
});
if (!provider || (this.data?.authTokens.length || 0) <= 1) {
this.setData(null);
this.resetIncludes();
}
@@ -1,3 +1,9 @@
query authLogout {
authLogout
query authLogout(
$provider: ID
$configuration: ID
) {
authLogout(
provider: $provider
configuration: $configuration
)
}
+6 -44
View File
@@ -887,7 +887,6 @@ export interface ProjectInfo {
export interface Query {
activeUser?: Maybe<UserInfo>;
allConnections: Array<ConnectionInfo>;
authChangeLocalPassword: Scalars['Boolean'];
authLogin: AuthInfo;
authLogout?: Maybe<Scalars['Boolean']>;
@@ -897,10 +896,6 @@ export interface Query {
configureServer: Scalars['Boolean'];
connectionFolders: Array<ConnectionFolderInfo>;
connectionInfo: ConnectionInfo;
/** @deprecated Field no longer supported */
copyConnectionConfiguration: ConnectionInfo;
/** @deprecated Field no longer supported */
createConnectionConfiguration: ConnectionInfo;
createTeam: AdminTeamInfo;
createUser: AdminUserInfo;
dataTransferAvailableStreamProcessors: Array<DataTransferProcessorInfo>;
@@ -909,8 +904,6 @@ export interface Query {
dataTransferExportDataFromResults: AsyncTaskInfo;
dataTransferRemoveDataFile?: Maybe<Scalars['Boolean']>;
deleteAuthProviderConfiguration: Scalars['Boolean'];
/** @deprecated Field no longer supported */
deleteConnectionConfiguration?: Maybe<Scalars['Boolean']>;
deleteTeam?: Maybe<Scalars['Boolean']>;
deleteUser?: Maybe<Scalars['Boolean']>;
deleteUserMetaParameter: Scalars['Boolean'];
@@ -969,19 +962,11 @@ export interface Query {
sqlParseScript: SqlScriptInfo;
sqlSupportedOperations: Array<DataTypeLogicalOperation>;
templateConnections: Array<ConnectionInfo>;
/** @deprecated Field no longer supported */
updateConnectionConfiguration: ConnectionInfo;
updateTeam: AdminTeamInfo;
userConnections: Array<ConnectionInfo>;
}
export interface QueryAllConnectionsArgs {
id?: InputMaybe<Scalars['ID']>;
projectId: Scalars['ID'];
}
export interface QueryAuthChangeLocalPasswordArgs {
newPassword: Scalars['String'];
oldPassword: Scalars['String'];
@@ -1025,19 +1010,6 @@ export interface QueryConnectionInfoArgs {
}
export interface QueryCopyConnectionConfigurationArgs {
config?: InputMaybe<ConnectionConfig>;
nodePath: Scalars['String'];
projectId: Scalars['ID'];
}
export interface QueryCreateConnectionConfigurationArgs {
config: ConnectionConfig;
projectId: Scalars['ID'];
}
export interface QueryCreateTeamArgs {
description?: InputMaybe<Scalars['String']>;
teamId: Scalars['ID'];
@@ -1079,12 +1051,6 @@ export interface QueryDeleteAuthProviderConfigurationArgs {
}
export interface QueryDeleteConnectionConfigurationArgs {
id: Scalars['ID'];
projectId: Scalars['ID'];
}
export interface QueryDeleteTeamArgs {
teamId: Scalars['ID'];
}
@@ -1372,13 +1338,6 @@ export interface QueryTemplateConnectionsArgs {
}
export interface QueryUpdateConnectionConfigurationArgs {
config: ConnectionConfig;
id: Scalars['ID'];
projectId: Scalars['ID'];
}
export interface QueryUpdateTeamArgs {
description?: InputMaybe<Scalars['String']>;
teamId: Scalars['ID'];
@@ -1711,7 +1670,10 @@ export type AuthLoginQueryVariables = Exact<{
export type AuthLoginQuery = { authInfo: { redirectLink?: string, authId?: string, authStatus: AuthStatus, userTokens?: Array<{ authProvider: string, authConfiguration?: string, loginTime: any, message?: string, origin: { type: string, subType?: string, displayName: string, icon?: string, details?: Array<{ id?: string, displayName?: string, description?: string, category?: string, dataType?: string, defaultValue?: any, validValues?: Array<any>, value?: any, length: ObjectPropertyLength, features: Array<string>, order: number }> } }> } };
export type AuthLogoutQueryVariables = Exact<{ [key: string]: never; }>;
export type AuthLogoutQueryVariables = Exact<{
provider?: InputMaybe<Scalars['ID']>;
configuration?: InputMaybe<Scalars['ID']>;
}>;
export type AuthLogoutQuery = { authLogout?: boolean };
@@ -3178,8 +3140,8 @@ export const AuthLoginDocument = `
}
${AuthTokenFragmentDoc}`;
export const AuthLogoutDocument = `
query authLogout {
authLogout
query authLogout($provider: ID, $configuration: ID) {
authLogout(provider: $provider, configuration: $configuration)
}
`;
export const DeleteAuthProviderConfigurationDocument = `
@@ -9,7 +9,7 @@
import { observable } from 'mobx';
import { AdministrationScreenService } from '@cloudbeaver/core-administration';
import { AppAuthService, AuthInfoService, AuthProviderContext, AuthProviderService, AuthProvidersResource, AUTH_PROVIDER_LOCAL_ID, RequestedProvider, UserInfoResource } from '@cloudbeaver/core-authentication';
import { AppAuthService, AuthInfoService, AuthProviderContext, AuthProviderService, AuthProvidersResource, AUTH_PROVIDER_LOCAL_ID, IUserAuthConfiguration, RequestedProvider, UserInfoResource } from '@cloudbeaver/core-authentication';
import { injectable, Bootstrap } from '@cloudbeaver/core-di';
import type { DialogueStateResult } from '@cloudbeaver/core-dialogs';
import { NotificationService } from '@cloudbeaver/core-events';
@@ -71,25 +71,30 @@ export class AuthenticationService extends Bootstrap {
await this.auth(false, { providerId, linkUser });
}
async logout(): Promise<void> {
async logout(providerId?: string, configurationId?: string): Promise<void> {
const contexts = await this.onLogout.execute('before');
if (ExecutorInterrupter.isInterrupted(contexts)) {
return;
}
if (this.authInfoService.userAuthConfigurations.length > 0) {
const userAuthConfiguration = this.authInfoService.userAuthConfigurations[0];
let userAuthConfiguration: IUserAuthConfiguration | undefined = undefined;
if (userAuthConfiguration.signOutLink) {
this.logoutConfiguration(userAuthConfiguration.id, true);
}
if (providerId) {
userAuthConfiguration = this.authInfoService.userAuthConfigurations
.find(c => c.providerId === providerId && c.configuration.id === configurationId);
} else if (this.authInfoService.userAuthConfigurations.length > 0) {
userAuthConfiguration = this.authInfoService.userAuthConfigurations[0];
}
if (userAuthConfiguration?.configuration.signOutLink) {
this.logoutConfiguration(userAuthConfiguration);
}
try {
await this.userInfoResource.logout();
await this.userInfoResource.logout(providerId, configurationId);
if (!this.administrationScreenService.isConfigurationMode) {
if (!this.administrationScreenService.isConfigurationMode && !providerId) {
this.screenService.navigateToRoot();
}
@@ -99,14 +104,11 @@ export class AuthenticationService extends Bootstrap {
}
}
logoutConfiguration(configurationId: string, full: boolean): void {
const userAuthConfiguration = this.authInfoService.userAuthConfigurations
.find(configuration => configuration.id === configurationId);
if (userAuthConfiguration?.signOutLink) {
const id = `${userAuthConfiguration.id}-sign-out`;
private async logoutConfiguration(configuration: IUserAuthConfiguration): Promise<void> {
if (configuration.configuration.signOutLink) {
const id = `${configuration.configuration.id}-sign-out`;
const popup = this.windowsService.open(id, {
url: userAuthConfiguration.signOutLink,
url: configuration.configuration.signOutLink,
target: id,
width: 600,
height: 700,
@@ -116,18 +118,6 @@ export class AuthenticationService extends Bootstrap {
popup.blur();
window.focus();
}
if (!full) {
let maxTime = 1000 / 100 * 10;
const interval = setInterval(() => {
if (popup?.location.href !== userAuthConfiguration.signOutLink || maxTime === 0) {
this.userInfoResource.markOutdated();
clearInterval(interval);
}
maxTime--;
}, 100);
}
}
}
@@ -95,10 +95,10 @@ export const AuthTokenList = observer<Props>(function AuthTokenList({ user, clas
>
<Cell
before={icon ? <IconOrImage icon={icon} /> : undefined}
after={configuration && (
after={(
<Button
mod={['outlined']}
onClick={() => authenticationService.logoutConfiguration(configuration!.id, false)}
onClick={() => authenticationService.logout(provider.id, configuration?.id)}
>
{translate('authentication_logout')}
</Button>