From 6187f10c072c7b6db7ff9c852ff3952625f26a9c Mon Sep 17 00:00:00 2001 From: Qiu Jian Date: Wed, 1 Mar 2023 00:58:37 +0800 Subject: [PATCH] fix: better prompt info for user failed auth due to invalid idp status --- pkg/apigateway/handler/auth.go | 10 ++++++---- pkg/httperrors/consts.go | 9 ++++++--- pkg/keystone/tokens/auth.go | 4 ++-- pkg/keystone/tokens/handlers.go | 7 ++++++- 4 files changed, 20 insertions(+), 10 deletions(-) diff --git a/pkg/apigateway/handler/auth.go b/pkg/apigateway/handler/auth.go index dd422d8bdd..3511247f42 100644 --- a/pkg/apigateway/handler/auth.go +++ b/pkg/apigateway/handler/auth.go @@ -377,13 +377,15 @@ func (h *AuthHandlers) doCredentialLogin(ctx context.Context, req *http.Request, if httperr.Code == 409 || httperr.Code == 429 { return nil, err } - switch httperr.Class { - case "UserNotFound", "WrongPassword": + switch errors.Error(httperr.Class) { + case httperrors.ErrUserNotFound, httperrors.ErrWrongPassword: return nil, httperrors.NewJsonClientError(httperrors.ErrIncorrectUsernameOrPassword, "incorrect username or password") - case "UserLocked": + case httperrors.ErrUserLocked: return nil, httperrors.NewJsonClientError(httperrors.ErrUserLocked, "The user has been locked, please contact the administrator") - case "UserDisabled": + case httperrors.ErrUserDisabled: return nil, httperrors.NewJsonClientError(httperrors.ErrUserDisabled, "The user has been disabled, please contact the administrator") + case httperrors.ErrInvalidIdpStatus: + return nil, httperrors.NewJsonClientError(httperrors.ErrInvalidIdpStatus, "The IDP of user has been disabled or in invalid status") } } return nil, httperrors.NewInvalidCredentialError("invalid credential") diff --git a/pkg/httperrors/consts.go b/pkg/httperrors/consts.go index ec86d08677..6546e307c8 100644 --- a/pkg/httperrors/consts.go +++ b/pkg/httperrors/consts.go @@ -31,9 +31,10 @@ const ( ErrActionNotFound = errors.Error("ActionNotFoundError") ErrTenantNotFound = errors.Error("TenantNotFoundError") - ErrServerStatus = errors.Error("ServerStatusError") - ErrInvalidStatus = errors.ErrInvalidStatus - ErrInvalidFormat = errors.ErrInvalidFormat + ErrServerStatus = errors.Error("ServerStatusError") + ErrInvalidStatus = errors.ErrInvalidStatus + ErrInvalidIdpStatus = errors.Error("InvalidIdpStatus") + ErrInvalidFormat = errors.ErrInvalidFormat ErrInputParameter = errors.Error("InputParameterError") ErrWeakPassword = errors.Error("WeakPasswordError") @@ -125,6 +126,8 @@ var ( ErrInvalidStatus: 400, ErrInvalidFormat: 400, + ErrInvalidIdpStatus: 400, + ErrInputParameter: 400, ErrWeakPassword: 400, ErrMissingParameter: 400, diff --git a/pkg/keystone/tokens/auth.go b/pkg/keystone/tokens/auth.go index a0775c66b6..1ec1884520 100644 --- a/pkg/keystone/tokens/auth.go +++ b/pkg/keystone/tokens/auth.go @@ -175,11 +175,11 @@ func authUserByIdentityInternal(ctx context.Context, ident *mcclient.SAuthentica idp := idpObj.(*models.SIdentityProvider) if idp.Enabled.IsFalse() { - return nil, errors.Wrap(httperrors.ErrInvalidStatus, "idp disabled") + return nil, errors.Wrap(httperrors.ErrInvalidIdpStatus, "idp disabled") } if idp.Status != api.IdentityDriverStatusConnected && idp.Status != api.IdentityDriverStatusDisconnected { - return nil, errors.Wrapf(httperrors.ErrInvalidStatus, "invalid idp status %s", idp.Status) + return nil, errors.Wrapf(httperrors.ErrInvalidIdpStatus, "invalid idp status %s", idp.Status) } conf, err := models.GetConfigs(idp, true, nil, nil) diff --git a/pkg/keystone/tokens/handlers.go b/pkg/keystone/tokens/handlers.go index 434eeff630..d9bf693cb5 100644 --- a/pkg/keystone/tokens/handlers.go +++ b/pkg/keystone/tokens/handlers.go @@ -88,7 +88,12 @@ func authenticateTokensV3(ctx context.Context, w http.ResponseWriter, r *http.Re switch errors.Cause(err) { case sqlchemy.ErrDuplicateEntry: httperrors.ConflictError(ctx, w, "duplicate username") - case httperrors.ErrTooManyAttempts, httperrors.ErrUserNotFound, httperrors.ErrUserDisabled, httperrors.ErrUserLocked, httperrors.ErrWrongPassword: + case httperrors.ErrTooManyAttempts, + httperrors.ErrUserNotFound, + httperrors.ErrUserDisabled, + httperrors.ErrUserLocked, + httperrors.ErrInvalidIdpStatus, + httperrors.ErrWrongPassword: httperrors.GeneralServerError(ctx, w, err) default: httperrors.UnauthorizedError(ctx, w, "unauthorized %s", err)