mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-2830 send auth provider in auth info (#1263)
* CB-2830 send auth provider in auth info * CB-1424 feat: provider / configuration logout * CB-1424 fix: provider logout Co-authored-by: Aleksey Potsetsuev <wrouds@gmail.com>
This commit is contained in:
co-authored by
Aleksey Potsetsuev
parent
537bfda887
commit
bc4677ccde
+6
-11
@@ -19,7 +19,6 @@ package io.cloudbeaver.model.session;
|
||||
import io.cloudbeaver.DBWUserIdentity;
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import io.cloudbeaver.model.user.WebUserOriginInfo;
|
||||
import io.cloudbeaver.registry.WebAuthProviderConfiguration;
|
||||
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
@@ -41,7 +40,7 @@ public class WebAuthInfo implements SMSessionPrincipal {
|
||||
private final WebSession session;
|
||||
private final WebUser user;
|
||||
private final WebAuthProviderDescriptor authProvider;
|
||||
private WebAuthProviderConfiguration authProviderConfiguration;
|
||||
private String authProviderConfigurationId;
|
||||
private SMSession authSession;
|
||||
private final OffsetDateTime loginTime;
|
||||
private final DBWUserIdentity userIdentity;
|
||||
@@ -101,7 +100,11 @@ public class WebAuthInfo implements SMSessionPrincipal {
|
||||
|
||||
@Property
|
||||
public String getAuthConfiguration() {
|
||||
return authProviderConfiguration == null ? null : authProviderConfiguration.getId();
|
||||
return authProviderConfigurationId;
|
||||
}
|
||||
|
||||
public void setAuthProviderConfigurationId(String authProviderConfigurationId) {
|
||||
this.authProviderConfigurationId = authProviderConfigurationId;
|
||||
}
|
||||
|
||||
public WebUser getUser() {
|
||||
@@ -116,14 +119,6 @@ public class WebAuthInfo implements SMSessionPrincipal {
|
||||
return authProvider;
|
||||
}
|
||||
|
||||
public WebAuthProviderConfiguration getAuthProviderConfiguration() {
|
||||
return authProviderConfiguration;
|
||||
}
|
||||
|
||||
public void setAuthProviderConfiguration(WebAuthProviderConfiguration authProviderConfiguration) {
|
||||
this.authProviderConfiguration = authProviderConfiguration;
|
||||
}
|
||||
|
||||
public SMSession getAuthSession() {
|
||||
return authSession;
|
||||
}
|
||||
|
||||
+11
-9
@@ -29,6 +29,7 @@ import io.cloudbeaver.utils.WebAppUtils;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.auth.SMAuthConfigurationReference;
|
||||
import org.jkiss.dbeaver.model.auth.SMAuthInfo;
|
||||
import org.jkiss.dbeaver.model.auth.SMAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.SMSession;
|
||||
@@ -87,8 +88,8 @@ public class WebSessionAuthProcessor {
|
||||
|
||||
try {
|
||||
if (configMode && alreadyLoggedIn) {
|
||||
for (String providerId : authInfo.getAuthData().keySet()) {
|
||||
webSession.removeAuthInfo(providerId);
|
||||
for (SMAuthConfigurationReference authConfiguration : authInfo.getAuthData().keySet()) {
|
||||
webSession.removeAuthInfo(authConfiguration.getAuthProviderId());
|
||||
}
|
||||
}
|
||||
webSession.updateSMAuthInfo(authInfo);
|
||||
@@ -102,8 +103,9 @@ public class WebSessionAuthProcessor {
|
||||
var securityController = webSession.getSecurityController();
|
||||
Map<String, Object> providerConfig = Collections.emptyMap();
|
||||
var newAuthInfos = new ArrayList<WebAuthInfo>();
|
||||
for (Map.Entry<String, Object> entry : authInfo.getAuthData().entrySet()) {
|
||||
String providerId = entry.getKey();
|
||||
for (Map.Entry<SMAuthConfigurationReference, Object> entry : authInfo.getAuthData().entrySet()) {
|
||||
SMAuthConfigurationReference authConfiguration = entry.getKey();
|
||||
String providerId = authConfiguration.getAuthProviderId();
|
||||
Map<String, Object> authAttrs = (Map<String, Object>) entry.getValue();
|
||||
|
||||
var authProviderDescriptor = getAuthProvider(providerId);
|
||||
@@ -111,15 +113,13 @@ public class WebSessionAuthProcessor {
|
||||
SMAuthProviderExternal<?> authProviderExternal = authProviderInstance instanceof SMAuthProviderExternal<?> ?
|
||||
(SMAuthProviderExternal<?>) authProviderInstance : null;
|
||||
|
||||
boolean providerEnabled = isProviderEnabled(providerId);
|
||||
boolean providerDisabled = !isProviderEnabled(providerId);
|
||||
if (configMode || webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) {
|
||||
// 1. Admin can authorize in any providers
|
||||
// 2. When it authorizes in non-local provider for the first time we force linkUser flag
|
||||
if (!providerEnabled && webSession.getUser() != null) {
|
||||
if (providerDisabled && webSession.getUser() != null) {
|
||||
linkWithActiveUser = true;
|
||||
}
|
||||
} else if (!providerEnabled && !webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) {
|
||||
throw new DBWebException("Authentication provider '" + providerId + "' is disabled");
|
||||
}
|
||||
|
||||
SMSession authSession;
|
||||
@@ -174,7 +174,9 @@ public class WebSessionAuthProcessor {
|
||||
authProviderDescriptor,
|
||||
userIdentity,
|
||||
authSession,
|
||||
OffsetDateTime.now());
|
||||
OffsetDateTime.now()
|
||||
);
|
||||
webAuthInfo.setAuthProviderConfigurationId(authConfiguration.getAuthProviderConfigurationId());
|
||||
webAuthInfo.setMessage("Authenticated with " + authProviderDescriptor.getLabel() + " provider");
|
||||
if (configMode) {
|
||||
webAuthInfo.setUserCredentials(authAttrs);
|
||||
|
||||
+53
-41
@@ -1037,17 +1037,17 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
if (SMAuthProviderFederated.class.isAssignableFrom(authProviderInstance.getClass())) {
|
||||
//async auth
|
||||
var authProviderFederated = (SMAuthProviderFederated) authProviderInstance;
|
||||
var redirectUrl = buildRedirectLink(
|
||||
authProviderFederated.getSignInLink(authProviderConfigurationId, Map.of()),
|
||||
var redirectUrl = buildRedirectLink(authProviderFederated.getSignInLink(authProviderConfigurationId, Map.of()),
|
||||
authAttemptId);
|
||||
return SMAuthInfo.inProgress(authAttemptId, redirectUrl, filteredUserCreds);
|
||||
Map<SMAuthConfigurationReference, Object> authData = Map.of(new SMAuthConfigurationReference(authProviderId,
|
||||
authProviderConfigurationId), filteredUserCreds);
|
||||
return SMAuthInfo.inProgress(authAttemptId, redirectUrl, authData);
|
||||
}
|
||||
txn.commit();
|
||||
return finishAuthentication(
|
||||
SMAuthInfo.inProgress(
|
||||
authAttemptId,
|
||||
null,
|
||||
Map.of(authProviderId, securedUserIdentifyingCredentials)
|
||||
null, Map.of(new SMAuthConfigurationReference(authProviderId, null), securedUserIdentifyingCredentials)
|
||||
),
|
||||
true,
|
||||
false
|
||||
@@ -1125,10 +1125,12 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
}
|
||||
|
||||
@Override
|
||||
public void updateAuthStatus(@NotNull String authId,
|
||||
@NotNull SMAuthStatus authStatus,
|
||||
@NotNull Map<String, Object> authInfo,
|
||||
@Nullable String error) throws DBException {
|
||||
public void updateAuthStatus(
|
||||
@NotNull String authId,
|
||||
@NotNull SMAuthStatus authStatus,
|
||||
@NotNull Map<SMAuthConfigurationReference, Object> authInfo,
|
||||
@Nullable String error
|
||||
) throws DBException {
|
||||
var existAuthInfo = getAuthStatus(authId);
|
||||
if (existAuthInfo.getAuthStatus() != SMAuthStatus.IN_PROGRESS) {
|
||||
throw new SMException("Authorization already finished and cannot be updated");
|
||||
@@ -1137,13 +1139,14 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
updateAuthStatus(authId, authStatus, authInfo, error, authSessionInfo.getSmSessionId());
|
||||
}
|
||||
|
||||
private void updateAuthStatus(@NotNull String authId,
|
||||
@NotNull SMAuthStatus authStatus,
|
||||
@NotNull Map<String, Object> authInfo,
|
||||
@Nullable String error,
|
||||
@Nullable String smSessionId) throws DBException {
|
||||
try (Connection dbCon = database.openConnection();
|
||||
JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
private void updateAuthStatus(
|
||||
@NotNull String authId,
|
||||
@NotNull SMAuthStatus authStatus,
|
||||
@NotNull Map<SMAuthConfigurationReference, Object> authInfo,
|
||||
@Nullable String error,
|
||||
@Nullable String smSessionId
|
||||
) throws DBException {
|
||||
try (Connection dbCon = database.openConnection(); JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
"UPDATE CB_AUTH_ATTEMPT SET AUTH_STATUS=?,AUTH_ERROR=?,SESSION_ID=? WHERE AUTH_ID=?")) {
|
||||
dbStat.setString(1, authStatus.toString());
|
||||
@@ -1155,20 +1158,29 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
}
|
||||
}
|
||||
|
||||
for (Map.Entry<String, Object> entry : authInfo.entrySet()) {
|
||||
String providerId = entry.getKey();
|
||||
for (Map.Entry<SMAuthConfigurationReference, Object> entry : authInfo.entrySet()) {
|
||||
SMAuthConfigurationReference providerId = entry.getKey();
|
||||
String authJson = gson.toJson(entry.getValue());
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
"UPDATE CB_AUTH_ATTEMPT_INFO SET AUTH_STATE=? WHERE AUTH_ID=? AND AUTH_PROVIDER_ID=?")) {
|
||||
boolean configIdExist = providerId.getAuthProviderConfigurationId() != null;
|
||||
var sqlBuilder = new StringBuilder();
|
||||
sqlBuilder.append("UPDATE CB_AUTH_ATTEMPT_INFO SET AUTH_STATE=? ")
|
||||
.append("WHERE AUTH_ID=? AND AUTH_PROVIDER_ID=? AND ")
|
||||
.append(configIdExist ? "AUTH_PROVIDER_CONFIGURATION_ID=?" : "AUTH_PROVIDER_CONFIGURATION_ID IS NULL");
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(sqlBuilder.toString())) {
|
||||
dbStat.setString(1, authJson);
|
||||
dbStat.setString(2, authId);
|
||||
dbStat.setString(3, providerId);
|
||||
dbStat.setString(3, providerId.getAuthProviderId());
|
||||
if (configIdExist) {
|
||||
dbStat.setString(4, providerId.getAuthProviderConfigurationId());
|
||||
}
|
||||
if (dbStat.executeUpdate() <= 0) {
|
||||
try (PreparedStatement dbStatIns = dbCon.prepareStatement(
|
||||
"INSERT INTO CB_AUTH_ATTEMPT_INFO (AUTH_ID,AUTH_PROVIDER_ID,AUTH_STATE) VALUES(?,?,?)")) {
|
||||
"INSERT INTO CB_AUTH_ATTEMPT_INFO (AUTH_ID,AUTH_PROVIDER_ID,AUTH_PROVIDER_CONFIGURATION_ID,AUTH_STATE) "
|
||||
+ "VALUES(?,?,?,?)")) {
|
||||
dbStatIns.setString(1, authId);
|
||||
dbStatIns.setString(2, providerId);
|
||||
dbStatIns.setString(3, authJson);
|
||||
dbStatIns.setString(2, providerId.getAuthProviderId());
|
||||
dbStatIns.setString(3, providerId.getAuthProviderConfigurationId());
|
||||
dbStatIns.setString(4, authJson);
|
||||
dbStatIns.execute();
|
||||
}
|
||||
}
|
||||
@@ -1199,7 +1211,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
smSessionId = dbResult.getString(3);
|
||||
}
|
||||
}
|
||||
Map<String, Object> authData = new LinkedHashMap<>();
|
||||
Map<SMAuthConfigurationReference, Object> authData = new LinkedHashMap<>();
|
||||
String redirectUrl = null;
|
||||
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
@@ -1217,14 +1229,13 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
WebAuthProviderDescriptor authProviderDescriptor = getAuthProvider(authProviderId);
|
||||
var authProviderInstance = authProviderDescriptor.getInstance();
|
||||
if (SMAuthProviderFederated.class.isAssignableFrom(authProviderInstance.getClass())) {
|
||||
redirectUrl = buildRedirectLink(
|
||||
((SMAuthProviderFederated) authProviderInstance).getRedirectLink(authProviderConfiguration, Map.of()),
|
||||
authId
|
||||
);
|
||||
redirectUrl = buildRedirectLink(((SMAuthProviderFederated) authProviderInstance).getRedirectLink(
|
||||
authProviderConfiguration,
|
||||
Map.of()), authId);
|
||||
}
|
||||
|
||||
}
|
||||
authData.put(authProviderId, authProviderData);
|
||||
authData.put(new SMAuthConfigurationReference(authProviderId, authProviderConfiguration), authProviderData);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1368,7 +1379,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
if (authInfo.getAuthStatus() != SMAuthStatus.IN_PROGRESS) {
|
||||
throw new SMException("Authorization has already been completed with status: " + authInfo.getAuthStatus());
|
||||
}
|
||||
Set<String> authProviderIds = authInfo.getAuthData().keySet();
|
||||
Set<SMAuthConfigurationReference> authProviderIds = authInfo.getAuthData().keySet();
|
||||
if (authProviderIds.isEmpty()) {
|
||||
throw new SMException("Authorization providers are not defined");
|
||||
}
|
||||
@@ -1386,20 +1397,19 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
}
|
||||
String activeUserId = permissions == null ? null : permissions.getUserId();
|
||||
|
||||
Map<String, Object> storedUserData = new LinkedHashMap<>();
|
||||
Map<SMAuthConfigurationReference, Object> storedUserData = new LinkedHashMap<>();
|
||||
SMTeam[] allTeams = null;
|
||||
String detectedAuthRole = null;
|
||||
for (String authProviderId : authProviderIds) {
|
||||
for (SMAuthConfigurationReference authConfiguration : authProviderIds) {
|
||||
String authProviderId = authConfiguration.getAuthProviderId();
|
||||
WebAuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
|
||||
var userAuthData = (Map<String, Object>) authInfo.getAuthData().get(authProviderId);
|
||||
var userAuthData = (Map<String, Object>) authInfo.getAuthData().get(authConfiguration);
|
||||
SMAutoAssign autoAssign = getAutoAssignUserData(authId, authProvider, userAuthData, finishAuthMonitor);
|
||||
if (autoAssign != null) {
|
||||
detectedAuthRole = autoAssign.getAuthRole();
|
||||
}
|
||||
|
||||
var userIdFromCreds = findOrCreateExternalUserByCredentials(
|
||||
authProvider,
|
||||
authAttemptSessionInfo.getSessionParams(),
|
||||
var userIdFromCreds = findOrCreateExternalUserByCredentials(authProvider, authAttemptSessionInfo.getSessionParams(),
|
||||
userAuthData,
|
||||
finishAuthMonitor,
|
||||
activeUserId,
|
||||
@@ -1423,10 +1433,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
if (activeUserId == null) {
|
||||
activeUserId = userIdFromCreds;
|
||||
}
|
||||
storedUserData.put(
|
||||
authProviderId,
|
||||
saveSecuredCreds ? userAuthData : filterSecuredUserData(userAuthData, getAuthProvider(authProviderId))
|
||||
);
|
||||
storedUserData.put(authConfiguration,
|
||||
saveSecuredCreds ? userAuthData : filterSecuredUserData(userAuthData, getAuthProvider(authProviderId)));
|
||||
}
|
||||
|
||||
String tokenAuthRole = updateUserAuthRoleIfNeeded(activeUserId, detectedAuthRole);
|
||||
@@ -2156,4 +2164,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
return activeUserCredentials.getUserId();
|
||||
}
|
||||
|
||||
private boolean isProviderEnabled(@NotNull String providerId) {
|
||||
WebAuthConfiguration appConfiguration = application.getAuthConfiguration();
|
||||
return appConfiguration.isAuthProviderEnabled(providerId);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -15,15 +15,20 @@ import { uuid } from '@cloudbeaver/core-utils';
|
||||
import { AuthProvidersResource, AuthProviderConfiguration } from './AuthProvidersResource';
|
||||
import { type ILoginOptions, UserInfoResource } from './UserInfoResource';
|
||||
|
||||
export interface IUserAuthConfiguration {
|
||||
providerId: string;
|
||||
configuration: AuthProviderConfiguration;
|
||||
}
|
||||
|
||||
@injectable()
|
||||
export class AuthInfoService {
|
||||
get userInfo(): UserInfo | null {
|
||||
return this.userInfoResource.data;
|
||||
}
|
||||
|
||||
get userAuthConfigurations(): AuthProviderConfiguration[] {
|
||||
get userAuthConfigurations(): IUserAuthConfiguration[] {
|
||||
const tokens = this.userInfo?.authTokens;
|
||||
const result: AuthProviderConfiguration[] = [];
|
||||
const result: IUserAuthConfiguration[] = [];
|
||||
|
||||
if (!tokens) {
|
||||
return result;
|
||||
@@ -41,7 +46,7 @@ export class AuthInfoService {
|
||||
);
|
||||
|
||||
if (configuration) {
|
||||
result.push(configuration);
|
||||
result.push({ providerId: provider.id, configuration });
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -158,9 +158,13 @@ UserInfoIncludes
|
||||
});
|
||||
}
|
||||
|
||||
async logout(): Promise<void> {
|
||||
if (this.data) {
|
||||
await this.graphQLService.sdk.authLogout();
|
||||
async logout(provider?: string, configuration?: string): Promise<void> {
|
||||
await this.graphQLService.sdk.authLogout({
|
||||
provider,
|
||||
configuration,
|
||||
});
|
||||
|
||||
if (!provider || (this.data?.authTokens.length || 0) <= 1) {
|
||||
this.setData(null);
|
||||
this.resetIncludes();
|
||||
}
|
||||
|
||||
@@ -1,3 +1,9 @@
|
||||
query authLogout {
|
||||
authLogout
|
||||
query authLogout(
|
||||
$provider: ID
|
||||
$configuration: ID
|
||||
) {
|
||||
authLogout(
|
||||
provider: $provider
|
||||
configuration: $configuration
|
||||
)
|
||||
}
|
||||
@@ -887,7 +887,6 @@ export interface ProjectInfo {
|
||||
|
||||
export interface Query {
|
||||
activeUser?: Maybe<UserInfo>;
|
||||
allConnections: Array<ConnectionInfo>;
|
||||
authChangeLocalPassword: Scalars['Boolean'];
|
||||
authLogin: AuthInfo;
|
||||
authLogout?: Maybe<Scalars['Boolean']>;
|
||||
@@ -897,10 +896,6 @@ export interface Query {
|
||||
configureServer: Scalars['Boolean'];
|
||||
connectionFolders: Array<ConnectionFolderInfo>;
|
||||
connectionInfo: ConnectionInfo;
|
||||
/** @deprecated Field no longer supported */
|
||||
copyConnectionConfiguration: ConnectionInfo;
|
||||
/** @deprecated Field no longer supported */
|
||||
createConnectionConfiguration: ConnectionInfo;
|
||||
createTeam: AdminTeamInfo;
|
||||
createUser: AdminUserInfo;
|
||||
dataTransferAvailableStreamProcessors: Array<DataTransferProcessorInfo>;
|
||||
@@ -909,8 +904,6 @@ export interface Query {
|
||||
dataTransferExportDataFromResults: AsyncTaskInfo;
|
||||
dataTransferRemoveDataFile?: Maybe<Scalars['Boolean']>;
|
||||
deleteAuthProviderConfiguration: Scalars['Boolean'];
|
||||
/** @deprecated Field no longer supported */
|
||||
deleteConnectionConfiguration?: Maybe<Scalars['Boolean']>;
|
||||
deleteTeam?: Maybe<Scalars['Boolean']>;
|
||||
deleteUser?: Maybe<Scalars['Boolean']>;
|
||||
deleteUserMetaParameter: Scalars['Boolean'];
|
||||
@@ -969,19 +962,11 @@ export interface Query {
|
||||
sqlParseScript: SqlScriptInfo;
|
||||
sqlSupportedOperations: Array<DataTypeLogicalOperation>;
|
||||
templateConnections: Array<ConnectionInfo>;
|
||||
/** @deprecated Field no longer supported */
|
||||
updateConnectionConfiguration: ConnectionInfo;
|
||||
updateTeam: AdminTeamInfo;
|
||||
userConnections: Array<ConnectionInfo>;
|
||||
}
|
||||
|
||||
|
||||
export interface QueryAllConnectionsArgs {
|
||||
id?: InputMaybe<Scalars['ID']>;
|
||||
projectId: Scalars['ID'];
|
||||
}
|
||||
|
||||
|
||||
export interface QueryAuthChangeLocalPasswordArgs {
|
||||
newPassword: Scalars['String'];
|
||||
oldPassword: Scalars['String'];
|
||||
@@ -1025,19 +1010,6 @@ export interface QueryConnectionInfoArgs {
|
||||
}
|
||||
|
||||
|
||||
export interface QueryCopyConnectionConfigurationArgs {
|
||||
config?: InputMaybe<ConnectionConfig>;
|
||||
nodePath: Scalars['String'];
|
||||
projectId: Scalars['ID'];
|
||||
}
|
||||
|
||||
|
||||
export interface QueryCreateConnectionConfigurationArgs {
|
||||
config: ConnectionConfig;
|
||||
projectId: Scalars['ID'];
|
||||
}
|
||||
|
||||
|
||||
export interface QueryCreateTeamArgs {
|
||||
description?: InputMaybe<Scalars['String']>;
|
||||
teamId: Scalars['ID'];
|
||||
@@ -1079,12 +1051,6 @@ export interface QueryDeleteAuthProviderConfigurationArgs {
|
||||
}
|
||||
|
||||
|
||||
export interface QueryDeleteConnectionConfigurationArgs {
|
||||
id: Scalars['ID'];
|
||||
projectId: Scalars['ID'];
|
||||
}
|
||||
|
||||
|
||||
export interface QueryDeleteTeamArgs {
|
||||
teamId: Scalars['ID'];
|
||||
}
|
||||
@@ -1372,13 +1338,6 @@ export interface QueryTemplateConnectionsArgs {
|
||||
}
|
||||
|
||||
|
||||
export interface QueryUpdateConnectionConfigurationArgs {
|
||||
config: ConnectionConfig;
|
||||
id: Scalars['ID'];
|
||||
projectId: Scalars['ID'];
|
||||
}
|
||||
|
||||
|
||||
export interface QueryUpdateTeamArgs {
|
||||
description?: InputMaybe<Scalars['String']>;
|
||||
teamId: Scalars['ID'];
|
||||
@@ -1711,7 +1670,10 @@ export type AuthLoginQueryVariables = Exact<{
|
||||
|
||||
export type AuthLoginQuery = { authInfo: { redirectLink?: string, authId?: string, authStatus: AuthStatus, userTokens?: Array<{ authProvider: string, authConfiguration?: string, loginTime: any, message?: string, origin: { type: string, subType?: string, displayName: string, icon?: string, details?: Array<{ id?: string, displayName?: string, description?: string, category?: string, dataType?: string, defaultValue?: any, validValues?: Array<any>, value?: any, length: ObjectPropertyLength, features: Array<string>, order: number }> } }> } };
|
||||
|
||||
export type AuthLogoutQueryVariables = Exact<{ [key: string]: never; }>;
|
||||
export type AuthLogoutQueryVariables = Exact<{
|
||||
provider?: InputMaybe<Scalars['ID']>;
|
||||
configuration?: InputMaybe<Scalars['ID']>;
|
||||
}>;
|
||||
|
||||
|
||||
export type AuthLogoutQuery = { authLogout?: boolean };
|
||||
@@ -3178,8 +3140,8 @@ export const AuthLoginDocument = `
|
||||
}
|
||||
${AuthTokenFragmentDoc}`;
|
||||
export const AuthLogoutDocument = `
|
||||
query authLogout {
|
||||
authLogout
|
||||
query authLogout($provider: ID, $configuration: ID) {
|
||||
authLogout(provider: $provider, configuration: $configuration)
|
||||
}
|
||||
`;
|
||||
export const DeleteAuthProviderConfigurationDocument = `
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
import { observable } from 'mobx';
|
||||
|
||||
import { AdministrationScreenService } from '@cloudbeaver/core-administration';
|
||||
import { AppAuthService, AuthInfoService, AuthProviderContext, AuthProviderService, AuthProvidersResource, AUTH_PROVIDER_LOCAL_ID, RequestedProvider, UserInfoResource } from '@cloudbeaver/core-authentication';
|
||||
import { AppAuthService, AuthInfoService, AuthProviderContext, AuthProviderService, AuthProvidersResource, AUTH_PROVIDER_LOCAL_ID, IUserAuthConfiguration, RequestedProvider, UserInfoResource } from '@cloudbeaver/core-authentication';
|
||||
import { injectable, Bootstrap } from '@cloudbeaver/core-di';
|
||||
import type { DialogueStateResult } from '@cloudbeaver/core-dialogs';
|
||||
import { NotificationService } from '@cloudbeaver/core-events';
|
||||
@@ -71,25 +71,30 @@ export class AuthenticationService extends Bootstrap {
|
||||
await this.auth(false, { providerId, linkUser });
|
||||
}
|
||||
|
||||
async logout(): Promise<void> {
|
||||
async logout(providerId?: string, configurationId?: string): Promise<void> {
|
||||
const contexts = await this.onLogout.execute('before');
|
||||
|
||||
if (ExecutorInterrupter.isInterrupted(contexts)) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (this.authInfoService.userAuthConfigurations.length > 0) {
|
||||
const userAuthConfiguration = this.authInfoService.userAuthConfigurations[0];
|
||||
let userAuthConfiguration: IUserAuthConfiguration | undefined = undefined;
|
||||
|
||||
if (userAuthConfiguration.signOutLink) {
|
||||
this.logoutConfiguration(userAuthConfiguration.id, true);
|
||||
}
|
||||
if (providerId) {
|
||||
userAuthConfiguration = this.authInfoService.userAuthConfigurations
|
||||
.find(c => c.providerId === providerId && c.configuration.id === configurationId);
|
||||
} else if (this.authInfoService.userAuthConfigurations.length > 0) {
|
||||
userAuthConfiguration = this.authInfoService.userAuthConfigurations[0];
|
||||
}
|
||||
|
||||
if (userAuthConfiguration?.configuration.signOutLink) {
|
||||
this.logoutConfiguration(userAuthConfiguration);
|
||||
}
|
||||
|
||||
try {
|
||||
await this.userInfoResource.logout();
|
||||
await this.userInfoResource.logout(providerId, configurationId);
|
||||
|
||||
if (!this.administrationScreenService.isConfigurationMode) {
|
||||
if (!this.administrationScreenService.isConfigurationMode && !providerId) {
|
||||
this.screenService.navigateToRoot();
|
||||
}
|
||||
|
||||
@@ -99,14 +104,11 @@ export class AuthenticationService extends Bootstrap {
|
||||
}
|
||||
}
|
||||
|
||||
logoutConfiguration(configurationId: string, full: boolean): void {
|
||||
const userAuthConfiguration = this.authInfoService.userAuthConfigurations
|
||||
.find(configuration => configuration.id === configurationId);
|
||||
|
||||
if (userAuthConfiguration?.signOutLink) {
|
||||
const id = `${userAuthConfiguration.id}-sign-out`;
|
||||
private async logoutConfiguration(configuration: IUserAuthConfiguration): Promise<void> {
|
||||
if (configuration.configuration.signOutLink) {
|
||||
const id = `${configuration.configuration.id}-sign-out`;
|
||||
const popup = this.windowsService.open(id, {
|
||||
url: userAuthConfiguration.signOutLink,
|
||||
url: configuration.configuration.signOutLink,
|
||||
target: id,
|
||||
width: 600,
|
||||
height: 700,
|
||||
@@ -116,18 +118,6 @@ export class AuthenticationService extends Bootstrap {
|
||||
popup.blur();
|
||||
window.focus();
|
||||
}
|
||||
|
||||
if (!full) {
|
||||
let maxTime = 1000 / 100 * 10;
|
||||
|
||||
const interval = setInterval(() => {
|
||||
if (popup?.location.href !== userAuthConfiguration.signOutLink || maxTime === 0) {
|
||||
this.userInfoResource.markOutdated();
|
||||
clearInterval(interval);
|
||||
}
|
||||
maxTime--;
|
||||
}, 100);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+2
-2
@@ -95,10 +95,10 @@ export const AuthTokenList = observer<Props>(function AuthTokenList({ user, clas
|
||||
>
|
||||
<Cell
|
||||
before={icon ? <IconOrImage icon={icon} /> : undefined}
|
||||
after={configuration && (
|
||||
after={(
|
||||
<Button
|
||||
mod={['outlined']}
|
||||
onClick={() => authenticationService.logoutConfiguration(configuration!.id, false)}
|
||||
onClick={() => authenticationService.logout(provider.id, configuration?.id)}
|
||||
>
|
||||
{translate('authentication_logout')}
|
||||
</Button>
|
||||
|
||||
Reference in New Issue
Block a user