From 4b570a55de75ec147f6ee45003b3e1c3aacafa7b Mon Sep 17 00:00:00 2001 From: Michael Wilson Date: Tue, 14 Feb 2023 12:31:43 -0500 Subject: [PATCH] Add SAML query functions to auth preferences. (#21692) * Add SAML query functions to auth preferences and role. Getter functions have been made for the new IdP configuration fields in the AuthPreferences and RoleOptions. * Remove role query, as we can access this in the object. * Make sure the IdP options section won't hit any nil pointer errors. --- api/types/authentication.go | 32 +++++++++++++++++++++++++++----- 1 file changed, 27 insertions(+), 5 deletions(-) diff --git a/api/types/authentication.go b/api/types/authentication.go index b9bae7be8ad..e8149f69516 100644 --- a/api/types/authentication.go +++ b/api/types/authentication.go @@ -117,6 +117,11 @@ type AuthPreference interface { // SetDeviceTrust sets the cluster device trust settings. SetDeviceTrust(*DeviceTrust) + // IsSAMLIdPEnabled returns true if the SAML IdP is enabled. + IsSAMLIdPEnabled() bool + // SetSAMLIdPEnabled sets the SAML IdP to enabled. + SetSAMLIdPEnabled(bool) + // String represents a human readable version of authentication settings. String() string } @@ -407,6 +412,16 @@ func (c *AuthPreferenceV2) SetDeviceTrust(dt *DeviceTrust) { c.Spec.DeviceTrust = dt } +// IsSAMLIdPEnabled returns true if the SAML IdP is enabled. +func (c *AuthPreferenceV2) IsSAMLIdPEnabled() bool { + return c.Spec.IDP.SAML.Enabled.Value +} + +// SetSAMLIdPEnabled sets the SAML IdP to enabled. +func (c *AuthPreferenceV2) SetSAMLIdPEnabled(enabled bool) { + c.Spec.IDP.SAML.Enabled = NewBoolOption(enabled) +} + // setStaticFields sets static resource header and metadata fields. func (c *AuthPreferenceV2) setStaticFields() { c.Kind = KindClusterAuthPreference @@ -552,13 +567,20 @@ func (c *AuthPreferenceV2) CheckAndSetDefaults() error { } } + // Make sure the IdP section is populated. if c.Spec.IDP == nil { + c.Spec.IDP = &IdPOptions{} + } + + // Make sure the SAML section is populated. + if c.Spec.IDP.SAML == nil { + c.Spec.IDP.SAML = &IdPSAMLOptions{} + } + + // Make sure the SAML enabled field is populated. + if c.Spec.IDP.SAML.Enabled == nil { // Enable the IdP by default. - c.Spec.IDP = &IdPOptions{ - SAML: &IdPSAMLOptions{ - Enabled: NewBoolOption(true), - }, - } + c.Spec.IDP.SAML.Enabled = NewBoolOption(true) } return nil