Commit Graph
18 Commits
Author SHA1 Message Date
Steven Martin 74be92adc0 Update msgraph http.Response error message (#59411) 2025-09-22 09:50:37 +00:00
Marek Smoliński 4bafbeeb80 Align msgraph client - switch to fast unmarshal (#59180) 2025-09-17 12:53:18 +00:00
Marek Smoliński 6d5ab75cc0 Add msgraph client iter options forwarding (#59177) 2025-09-17 10:43:01 +00:00
Rafał Cieślak 8d2a37fd56 lib/msgraph: Get token before each retry (#58673)
* Get token before each retry

* Add note about caching to AzureTokenProvider.GetToken
2025-09-17 09:08:58 +00:00
Rafał Cieślak 07ee5ba23c lib/msgraph: Add auth error handling, logging, and Client-Request-Id header (#58661)
* Capture status code in GraphError

* Add comments to GraphError fields

* Parse auth errors returned by AzureTokenProvider

* Update tests to use NewClient

* Add logging to lib/msgraph.Client

* Add client-request-id header

* Fix typos in api/types.ValidateMSGraphEndpoints

* Ignore StatusCode field during unmarshalling

* Check for `authFailedError.RawResponse.Body != nil`

* Move credential verification from e/lib/intune to lib/msgraph

* Remove request logging
2025-09-09 08:48:53 +00:00
Rafał Cieślak 12463985c1 Add variadic opts and managed device methods to lib/msgraph.Client (#58398)
* Add variadic opts to lib/msgraph.Client.iterate

* Add IterateManagedDevicePages

* Add GetManagedDevice to lib/msgraph.Client

* Copy all header values
2025-09-05 09:56:00 +00:00
Sakshyam Shah b09f4887be adds user's transitiveMemberOf group lister to lib/msgraph (#58095)
* set and validate default graph endpoint

* add IterateUsersTransitiveMemberOf method to list user groups

* run make fix-imports

* fix: return on group type error:
- updates test
2025-08-22 01:55:29 +00:00
Zac Bergquist a12def583a Apply remaining modernize changes. (#56037)
This is the last of this series of updates.
2025-06-25 21:25:29 +00:00
rosstimothy 2cced62805 Fix violations of non-constant format strings linter (#51812)
Depends on https://github.com/gravitational/teleport.e/pull/6006.
Now that we are compliant, the ignore rule was removed from the
golangci-lint config to prevent future regressions.
2025-02-04 16:43:35 +00:00
Matt Brock b22f342680 Azure integration command (#47541)
* Initial command to create the managed identity and role

* Adding permissions and applying command params

* Adding graph permissions to the MSI

* Updating parameters

* Adding some details and cleaning up comments

* Fixing go.sum

* Linting

* License

* PR feedback

* Decoupling sync config with an interface for testing

* Tweaks to test mocking

* PR feedback

* Rebase adjustments

* PR feedback

* Switch to empty struct maps instead of bool maps for set representation

* Godocs

* Adding user agent to Azure SDK requests

* Linting
2025-01-16 17:43:20 +00:00
Matt BrockandTiago Silva 47f4498b76 Adding the Azure sync module functions along with new cloud client functionality (#50366)
* Protobuf and configuration for Access Graph Azure Discovery

* Adding the Azure sync module functions along with new cloud client functionality

* Forgot to decouple role definitions fetching function from the fetcher

* Moving reconciliation to the upstream azure sync PR

* Moving reconciliation test to the upstream azure sync PR

* Updating go.sum

* Fixing rebase after protobuf gen

* Nolinting until upstream PRs

* Updating to use existing msgraph client

* Adding protection around nil values

* PR feedback

* Updating principal fetching to incorporate metadata from principal subtypes

* Updating opts to not leak URL parameters

* Conformant package name

* Using variadic options

* PR feedback

* Removing memberOf expansion

* Expanding memberships by calling memberOf on each user

* Also returning expanded principals for improved readability

* Removing ptrToList

* PR feedback

* Rebase go.sum stuff

* Go mod tidy

* Linting

* Linting

* Collecting errors from fetching memberships and using a WithContext error group

* Fixing go.mod

* Update lib/msgraph/paginated.go

Co-authored-by: Tiago Silva <tiago.silva@goteleport.com>

* PR feedback

* e ref update

* e ref update

* Fixing method

* Fetching group members from groups rather than memberships of each principal

* Linting

---------

Co-authored-by: Tiago Silva <tiago.silva@goteleport.com>
2025-01-13 19:27:58 +00:00
Tiago Silva a1cdc9a43d [entraid] parse user's given name and surname (#49496)
To populate the given name and surname traits, we must parse them from
Entra ID responses. This PR parses the given name and surname artifacts
from the json response.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2024-11-27 11:58:57 +00:00
Tiago Silva 903c1ad6f4 [entraid] set all optional claims to avoid weird behavior (#48957)
Entra sometimes sends the OptionClaims when retrieving a certain application if only SAML2Token is set, other times it doesn't return them.

This PR fills all id and access token values so entra doesn't fail to send the optional token value.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2024-11-14 13:13:15 +00:00
Tiago Silva 0ebaf189f8 [entraid] store entra appId in plugin settings (#48754)
* [entraid] store entra `appId` in plugin settings

This PR stores the Entra ID appID of the application used for SSO in Entra ID plugin settings.
This field filled in a best effort scenario and might be empty for old Entra Plugins.
Newly created plugins will make the field mandatory.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>

* handle code review comments

---------

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2024-11-12 10:00:47 +00:00
Tiago Silva 9379fb7a71 [entraid] Expose Application OptionalClaims and Groups AD settings (#48737)
* [entraid] Expose Application `OptionalClaims` and Groups AD settings

This PR exposes Entra ID settings for `OptionalClaims` where applications store the info regarding how the group claim is mapped to SAML properties.

It also exposes the GroupID settings:

- `onPremisesDomainName`
- `onPremisesNetBiosName`
- `onPremisesSamAccountName`

That will be later used compute group claims with the Teleport SAML connector.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>

* handle code review comments

---------

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2024-11-11 15:01:45 +00:00
Tiago Silva e109161776 [entraid] ignore unsuported groups members and parse nested group memberships (#48182)
This PR fixes a typo where the error was incorrectly ignored and caused failures when group membership included other groups and any unsupported kinds.

This PR fixes that by properly returning `unsupportedGroupMember` while also supports parsing groups that are member of other groups.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
2024-10-30 22:46:11 +00:00
Tiago SilvaandMarco Dinis 768a0bd684 [entraid] add setup script for offline clusters. (#47863)
* [entraid] add setup script for offline clusters.

This PR adds a cli configuration for Entra ID where it's possible to default to system credentials instead of relying on OIDC for authentication in EntraID. OIDC is not always a possibility specially when the cluster is private and not internet acessible.

The UX is the following:

```text

Step 1: Run the Setup Script

1. Open **Azure Cloud Shell** (Bash) using **Google Chrome** or **Safari** for the best compatibility.
2. Upload the setup script using the **Upload** button in the Cloud Shell toolbar.
3. Once uploaded, execute the script by running the following command:
   $ bash entraid.sh

**Important Considerations**:
- You must have **Azure privileged administrator permissions** to complete the integration.
- Ensure you're using the **Bash** environment in Cloud Shell.
- During the script execution, you'll be prompted to run 'az login' to authenticate with Azure. **Teleport** does not store or persist your credentials.
- **Mozilla Firefox** users may experience connectivity issues in Azure Cloud Shell; using Chrome or Safari is recommended.

Once the script completes, type 'continue' to proceed, 'exit' to quit: continue

Step 2: Input Tenant ID and Client ID

With the output of Step 1, please copy and paste the following information:
Enter the Tenant ID: 1056b571-0390-4b08-86c8-2edba8d9ae79
Enter the Client ID: 1056b571-0390-4b08-86c8-2edba8d9ae79

Successfully created EntraID plugin "name".
```

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>

* move function to api

* handle code review comments

* Apply suggestions from code review

Co-authored-by: Marco Dinis <marco.dinis@goteleport.com>

* fix url

* enable group claims

* add godoc

* handle code review comments

* fix gomod

---------

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
Co-authored-by: Marco Dinis <marco.dinis@goteleport.com>
2024-10-29 17:51:58 +00:00
Justinas Stankevičius c5a5f8e7a2 Replace MS Graph SDK with an in-house client (#44069)
* Add MS Graph client skeleton

* Complete retry logic

* Add GetID() to GroupMember

* Parse MS Graph API error responses

* Pull out page size into config

* Add missing "patch" methods to client interface

* Move code around

* Factor out roundtrip()

* Fill out remaining methods

* Add godocs and solve lints

* Run gci

* Move godocs to the interface

* Add missing method

* Finish errors_test

* close body in test

* nit

* Add license headers

* Move azureoidc onboarding code to msgraph.Client

* Make AzureTokenProvider public

* Use cmp.Or to shorten config defaults handling

* Address review nits

* Parallelize tests

* nit

* Respect context cancellation in retry logic

* Utilize BlockUntil in tests

* Remove Client interface, make client struct public

* Prefer defaults.HTTPClient to http.DefaultClient

* Iterate entra apps, do not buffer all in memory

* nit

* Set additional timeouts on default HTTP client

* Escape path segments when constructing URLs

* Add a general timeout for default HTTP client
2024-07-17 15:51:39 +00:00