Merge pull request #16077 from swordqiu/hotfix/qj-invalid-idp-status

fix: better prompt info for user failed auth due to invalid idp status
This commit is contained in:
Zexi Li
2023-03-01 10:11:49 +08:00
committed by GitHub
4 changed files with 20 additions and 10 deletions
+6 -4
View File
@@ -377,13 +377,15 @@ func (h *AuthHandlers) doCredentialLogin(ctx context.Context, req *http.Request,
if httperr.Code == 409 || httperr.Code == 429 {
return nil, err
}
switch httperr.Class {
case "UserNotFound", "WrongPassword":
switch errors.Error(httperr.Class) {
case httperrors.ErrUserNotFound, httperrors.ErrWrongPassword:
return nil, httperrors.NewJsonClientError(httperrors.ErrIncorrectUsernameOrPassword, "incorrect username or password")
case "UserLocked":
case httperrors.ErrUserLocked:
return nil, httperrors.NewJsonClientError(httperrors.ErrUserLocked, "The user has been locked, please contact the administrator")
case "UserDisabled":
case httperrors.ErrUserDisabled:
return nil, httperrors.NewJsonClientError(httperrors.ErrUserDisabled, "The user has been disabled, please contact the administrator")
case httperrors.ErrInvalidIdpStatus:
return nil, httperrors.NewJsonClientError(httperrors.ErrInvalidIdpStatus, "The IDP of user has been disabled or in invalid status")
}
}
return nil, httperrors.NewInvalidCredentialError("invalid credential")
+6 -3
View File
@@ -31,9 +31,10 @@ const (
ErrActionNotFound = errors.Error("ActionNotFoundError")
ErrTenantNotFound = errors.Error("TenantNotFoundError")
ErrServerStatus = errors.Error("ServerStatusError")
ErrInvalidStatus = errors.ErrInvalidStatus
ErrInvalidFormat = errors.ErrInvalidFormat
ErrServerStatus = errors.Error("ServerStatusError")
ErrInvalidStatus = errors.ErrInvalidStatus
ErrInvalidIdpStatus = errors.Error("InvalidIdpStatus")
ErrInvalidFormat = errors.ErrInvalidFormat
ErrInputParameter = errors.Error("InputParameterError")
ErrWeakPassword = errors.Error("WeakPasswordError")
@@ -125,6 +126,8 @@ var (
ErrInvalidStatus: 400,
ErrInvalidFormat: 400,
ErrInvalidIdpStatus: 400,
ErrInputParameter: 400,
ErrWeakPassword: 400,
ErrMissingParameter: 400,
+2 -2
View File
@@ -175,11 +175,11 @@ func authUserByIdentityInternal(ctx context.Context, ident *mcclient.SAuthentica
idp := idpObj.(*models.SIdentityProvider)
if idp.Enabled.IsFalse() {
return nil, errors.Wrap(httperrors.ErrInvalidStatus, "idp disabled")
return nil, errors.Wrap(httperrors.ErrInvalidIdpStatus, "idp disabled")
}
if idp.Status != api.IdentityDriverStatusConnected && idp.Status != api.IdentityDriverStatusDisconnected {
return nil, errors.Wrapf(httperrors.ErrInvalidStatus, "invalid idp status %s", idp.Status)
return nil, errors.Wrapf(httperrors.ErrInvalidIdpStatus, "invalid idp status %s", idp.Status)
}
conf, err := models.GetConfigs(idp, true, nil, nil)
+6 -1
View File
@@ -88,7 +88,12 @@ func authenticateTokensV3(ctx context.Context, w http.ResponseWriter, r *http.Re
switch errors.Cause(err) {
case sqlchemy.ErrDuplicateEntry:
httperrors.ConflictError(ctx, w, "duplicate username")
case httperrors.ErrTooManyAttempts, httperrors.ErrUserNotFound, httperrors.ErrUserDisabled, httperrors.ErrUserLocked, httperrors.ErrWrongPassword:
case httperrors.ErrTooManyAttempts,
httperrors.ErrUserNotFound,
httperrors.ErrUserDisabled,
httperrors.ErrUserLocked,
httperrors.ErrInvalidIdpStatus,
httperrors.ErrWrongPassword:
httperrors.GeneralServerError(ctx, w, err)
default:
httperrors.UnauthorizedError(ctx, w, "unauthorized %s", err)