mirror of https://github.com/rancher/ui.git
Fixes requests from review
This commit is contained in:
parent
dfac8fb538
commit
0670441dbc
|
|
@ -79,10 +79,10 @@ const App = Application.extend({
|
|||
'digitalOcean',
|
||||
'endpoint',
|
||||
'github',
|
||||
'google',
|
||||
'globalStore',
|
||||
'intl',
|
||||
'modal',
|
||||
'oauth',
|
||||
'resource-actions',
|
||||
'router',
|
||||
'scope',
|
||||
|
|
|
|||
|
|
@ -11,8 +11,7 @@ const samlProviders = ['ping', 'adfs', 'keycloak', 'okta'];
|
|||
const allowedForwards = ['localhost'];
|
||||
|
||||
export default Route.extend(VerifyAuth, {
|
||||
github: service(),
|
||||
google: service(),
|
||||
oauth: service(),
|
||||
intl: service(),
|
||||
language: service('user-language'),
|
||||
|
||||
|
|
@ -23,8 +22,7 @@ export default Route.extend(VerifyAuth, {
|
|||
},
|
||||
|
||||
model(params/* , transition */) {
|
||||
const github = get(this, 'github');
|
||||
const google = get(this, 'google');
|
||||
const oauth = get(this, 'oauth');
|
||||
const code = get(params, 'code');
|
||||
const forward = get(params, 'forward');
|
||||
|
||||
|
|
@ -41,7 +39,7 @@ export default Route.extend(VerifyAuth, {
|
|||
code
|
||||
});
|
||||
} else {
|
||||
github.login(forward);
|
||||
oauth.login(forward);
|
||||
}
|
||||
} else {
|
||||
return reject(new Error('Invalid forward url'));
|
||||
|
|
@ -51,28 +49,21 @@ export default Route.extend(VerifyAuth, {
|
|||
}
|
||||
|
||||
if ( window.opener && !get(params, 'login') && !get(params, 'errorCode') ) {
|
||||
let openersGithub = window.opener.ls('github');
|
||||
let openersGoogle = window.opener.ls('google');
|
||||
let openersOauth = window.opener.ls('oauth');
|
||||
let openerStore = window.opener.ls('globalStore');
|
||||
let qp = get(params, 'config') || get(params, 'authProvider');
|
||||
let type = `${ qp }Config`;
|
||||
let config = openerStore.getById(type, qp);
|
||||
let gh = get(this, 'github');
|
||||
let go = get(this, 'google');
|
||||
let stateMsg = 'Authorization state did not match, please try again.';
|
||||
let isGithub = get(params, 'config') === 'github'
|
||||
let isGoogle = get(params, 'config') === 'googleoauth'
|
||||
|
||||
if ( get(params, 'config') === 'github' ) {
|
||||
return gh.testConfig(config).then((resp) => {
|
||||
gh.authorize(resp, openersGithub.get('state'));
|
||||
if ( isGithub || isGoogle ) {
|
||||
return oauth.testConfig(config).then((resp) => {
|
||||
oauth.authorize(resp, openersOauth.get('state'));
|
||||
}).catch((err) => {
|
||||
this.send('gotError', err);
|
||||
});
|
||||
} else if ( get(params, 'config') === 'googleoauth') {
|
||||
return go.testConfig(config).then((resp) => {
|
||||
go.authorize(resp, openersGoogle.get('state'));
|
||||
}).catch((err) => {
|
||||
this.send('gotError', err)
|
||||
})
|
||||
} else if ( samlProviders.includes(get(params, 'config')) ) {
|
||||
if ( window.opener.window.onAuthTest ) {
|
||||
reply(null, config);
|
||||
|
|
@ -82,9 +73,7 @@ export default Route.extend(VerifyAuth, {
|
|||
}
|
||||
|
||||
if ( get(params, 'code') ) {
|
||||
const currentOpener = openersGithub.state ? openersGithub : openersGoogle;
|
||||
|
||||
if ( currentOpener.stateMatches(get(params, 'state')) ) {
|
||||
if ( openersOauth.stateMatches(get(params, 'state')) ) {
|
||||
reply(params.error_description, params.code);
|
||||
} else {
|
||||
reply(stateMsg);
|
||||
|
|
@ -99,11 +88,11 @@ export default Route.extend(VerifyAuth, {
|
|||
}
|
||||
}
|
||||
|
||||
if ( code && get(params, 'login') || get(params, 'state').includes('login') ) {
|
||||
let currentProvider = github.stateMatches(get(params, 'state')) ? 'github' : 'googleoauth'
|
||||
if ( code && get(params, 'state').includes('login') ) {
|
||||
const providerType = get(params, 'state').includes('github') ? 'github' : 'googleoauth'
|
||||
|
||||
if ( github.stateMatches(get(params, 'state')) || google.stateMatches(get(params, 'state')) ) {
|
||||
currentProvider = get(this, 'access.providers').findBy('id', currentProvider);
|
||||
if ( oauth.stateMatches(get(params, 'state')) ) {
|
||||
const currentProvider = get(this, 'access.providers').findBy('id', providerType);
|
||||
|
||||
return currentProvider.doAction('login', {
|
||||
code,
|
||||
|
|
|
|||
|
|
@ -18,10 +18,10 @@ const Eng = Engine.extend({
|
|||
'digitalOcean',
|
||||
'endpoint',
|
||||
'github',
|
||||
'google',
|
||||
'globalStore',
|
||||
'intl',
|
||||
'modal',
|
||||
'oauth',
|
||||
'resource-actions',
|
||||
'router',
|
||||
'scope',
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ import C from 'ui/utils/constants';
|
|||
import AuthMixin from 'global-admin/mixins/authentication';
|
||||
|
||||
export default Controller.extend(AuthMixin, {
|
||||
github: service(),
|
||||
oauth: service(),
|
||||
endpoint: service(),
|
||||
access: service(),
|
||||
settings: service(),
|
||||
|
|
@ -58,7 +58,7 @@ export default Controller.extend(AuthMixin, {
|
|||
'allowedPrincipalIds': [],
|
||||
});
|
||||
|
||||
setProperties(get(this, 'github'), {
|
||||
setProperties(get(this, 'oauth'), {
|
||||
hostname: authConfig.get('hostname'),
|
||||
scheme: authConfig.get('scheme'),
|
||||
clientId: authConfig.get('clientId')
|
||||
|
|
@ -66,7 +66,7 @@ export default Controller.extend(AuthMixin, {
|
|||
|
||||
|
||||
set(this, '_boundSucceed', this.authenticationApplied.bind(this));
|
||||
get(this, 'github').test(authConfig, get(this, '_boundSucceed'));
|
||||
get(this, 'oauth').test(authConfig, get(this, '_boundSucceed'));
|
||||
},
|
||||
},
|
||||
enterpriseDidChange: observer('isEnterprise', 'authConfig.hostname', 'secure', function() {
|
||||
|
|
|
|||
|
|
@ -5,7 +5,7 @@ import Controller from '@ember/controller';
|
|||
import AuthMixin from 'global-admin/mixins/authentication';
|
||||
|
||||
export default Controller.extend(AuthMixin, {
|
||||
google: service(),
|
||||
oauth: service(),
|
||||
endpoint: service(),
|
||||
access: service(),
|
||||
settings: service(),
|
||||
|
|
@ -44,7 +44,7 @@ export default Controller.extend(AuthMixin, {
|
|||
});
|
||||
|
||||
set(this, '_boundSucceed', this.authenticationApplied.bind(this));
|
||||
get(this, 'google').test(authConfig, get(this, '_boundSucceed'));
|
||||
get(this, 'oauth').test(authConfig, get(this, '_boundSucceed'));
|
||||
},
|
||||
},
|
||||
|
||||
|
|
|
|||
|
|
@ -1,11 +1,10 @@
|
|||
<section>
|
||||
{{#unless isEnabled}}
|
||||
<div class="banner bg-warning">
|
||||
<div class="banner-icon"><span class="icon icon-alert"></span></div>
|
||||
<div class="banner-message">
|
||||
<p>{{t 'authPage.google.header.disabled.label'}}</p>
|
||||
</div>
|
||||
</div>
|
||||
<BannerMessage
|
||||
@color='bg-warning'
|
||||
@icon='icon-alert'
|
||||
@message={{t 'authPage.google.header.disabled.label'}}
|
||||
/>
|
||||
{{/unless}}
|
||||
{{top-errors errors=errors}}
|
||||
</section>
|
||||
|
|
@ -21,21 +20,21 @@
|
|||
showExpand=false
|
||||
title=(t 'authPage.google.authenticated.header.text')
|
||||
}}
|
||||
<section class="">
|
||||
<div class="clearfix">
|
||||
<div class="pull-right">
|
||||
<button class="btn btn-sm right-divider-btn bg-error" {{action "disable"}}>
|
||||
<section class=''>
|
||||
<div class='clearfix'>
|
||||
<div class='pull-right'>
|
||||
<button class='btn btn-sm right-divider-btn bg-error' {{action 'disable'}}>
|
||||
{{t 'authPage.google.authenticated.disableAccess.disable'}}
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
<hr />
|
||||
<div><b>{{t 'authPage.google.authenticated.header.adminEmail.text'}} </b> <span class="text-muted">{{authConfig.adminEmail}}</span></div>
|
||||
<div><b>{{t 'authPage.google.authenticated.header.adminEmail.text'}} </b> <span class='text-muted'>{{authConfig.adminEmail}}</span></div>
|
||||
</section>
|
||||
{{/accordion-list-item}}
|
||||
|
||||
{{#accordion-list-item
|
||||
classNames="mt-30"
|
||||
classNames='mt-30'
|
||||
detail=(t 'siteAccess.helpText' appName=settings.appName htmlSafe=true)
|
||||
expand=(action expandFn)
|
||||
expandAll=al.expandAll
|
||||
|
|
@ -61,9 +60,9 @@
|
|||
showExpand=false
|
||||
title=(t 'authPage.google.notAuthenticated.header')
|
||||
}}
|
||||
<section class="">
|
||||
<section class=''>
|
||||
<p>
|
||||
<ol class="alphalist ml-40">
|
||||
<ol class='alphalist ml-40'>
|
||||
<li>
|
||||
{{t 'authPage.google.notAuthenticated.ul.li1.text' htmlSafe=true}}
|
||||
<ul>
|
||||
|
|
@ -74,10 +73,25 @@
|
|||
{{t 'authPage.google.notAuthenticated.ul.li2.text'}}
|
||||
<ul>
|
||||
<li>{{t 'authPage.google.notAuthenticated.ul.li2.ul.li1' appName=settings.appName htmlSafe=true}}
|
||||
<span>{{destinationDomain}}{{copy-to-clipboard size='small' clipboardText=destinationUrl htmlSafe=true}}</span>
|
||||
<span>
|
||||
{{destinationDomain}}
|
||||
{{copy-to-clipboard
|
||||
size='small'
|
||||
clipboardText=destinationUrl
|
||||
htmlSafe=true
|
||||
}}
|
||||
</span>
|
||||
</li>
|
||||
<li>
|
||||
<b>{{t 'authPage.google.notAuthenticated.ul.li2.ul.li2' htmlSafe=true}}</b> <span>{{destinationUrl}}{{copy-to-clipboard size='small' clipboardText=destinationUrl htmlSafe=true}}</span>
|
||||
<b>{{t 'authPage.google.notAuthenticated.ul.li2.ul.li2' htmlSafe=true}}</b>
|
||||
<span>
|
||||
{{destinationUrl}}
|
||||
{{copy-to-clipboard
|
||||
size='small'
|
||||
clipboardText=destinationUrl
|
||||
htmlSafe=true
|
||||
}}
|
||||
</span>
|
||||
</li>
|
||||
<li>{{t 'authPage.google.notAuthenticated.ul.li2.ul.li3'}}</li>
|
||||
</ul>
|
||||
|
|
@ -88,10 +102,25 @@
|
|||
<li>{{t 'authPage.google.notAuthenticated.ul.li3.ul.li1'}}
|
||||
</li>
|
||||
<li>
|
||||
<b>{{t 'authPage.google.notAuthenticated.ul.li3.ul.li2' htmlSafe=true}}</b> <span>{{destinationUrl}}{{copy-to-clipboard size='small' clipboardText=destinationUrl htmlSafe=true}}</span>
|
||||
<b>{{t 'authPage.google.notAuthenticated.ul.li3.ul.li2' htmlSafe=true}}</b>
|
||||
<span>
|
||||
{{destinationUrl}}
|
||||
{{copy-to-clipboard
|
||||
size='small'
|
||||
clipboardText=destinationUrl
|
||||
htmlSafe=true
|
||||
}}
|
||||
</span>
|
||||
</li>
|
||||
<li>{{t 'authPage.google.notAuthenticated.ul.li3.ul.li3' htmlSafe=true}}
|
||||
<span>{{redirectURI}}{{copy-to-clipboard size='small' clipboardText=destinationUrl htmlSafe=true}}</span>
|
||||
<span>
|
||||
{{redirectURI}}
|
||||
{{copy-to-clipboard
|
||||
size='small'
|
||||
clipboardText=destinationUrl
|
||||
htmlSafe=true
|
||||
}}
|
||||
</span>
|
||||
</li>
|
||||
<li>{{t 'authPage.google.notAuthenticated.ul.li3.ul.li4'}}</li>
|
||||
</ul>
|
||||
|
|
@ -118,44 +147,53 @@
|
|||
showExpand=false
|
||||
title=(t 'authPage.google.notAuthenticated.form.header' appName=settings.appName)
|
||||
}}
|
||||
<form autcomplete="on">
|
||||
<section class="">
|
||||
<form autcomplete='on'>
|
||||
<section class=''>
|
||||
|
||||
<div class="row">
|
||||
<div class="col span-6">
|
||||
<div class="inline-form">
|
||||
<label class="acc-label pb-5">{{t 'authPage.google.notAuthenticated.form.adminEmail.labelText'}}{{field-required}}</label>
|
||||
{{input type="text" name="username" value=authConfig.adminEmail classNames="form-control"}}
|
||||
<p class="help-block">{{t 'authPage.google.notAuthenticated.form.adminEmail.helperText'}}</p>
|
||||
<div class='row'>
|
||||
<div class='col span-6'>
|
||||
<div class='inline-form'>
|
||||
<label class='acc-label pb-5'>{{t 'authPage.google.notAuthenticated.form.adminEmail.labelText'}}{{field-required}}</label>
|
||||
{{input
|
||||
type='text'
|
||||
name='username'
|
||||
value=authConfig.adminEmail
|
||||
classNames='form-control'
|
||||
}}
|
||||
<p class='help-block'>{{t 'authPage.google.notAuthenticated.form.adminEmail.helperText'}}</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="col span-6">
|
||||
<div class="inline-form">
|
||||
<label class="acc-label pb-5">{{t 'authPage.google.notAuthenticated.form.hostname.labelText'}}{{field-required}}</label>
|
||||
{{input type="text" value=authConfig.hostname classNames="form-control"}}
|
||||
<p class="help-block">{{t 'authPage.google.notAuthenticated.form.hostname.helperText'}}</p>
|
||||
<div class='col span-6'>
|
||||
<div class='inline-form'>
|
||||
<label class='acc-label pb-5'>{{t 'authPage.google.notAuthenticated.form.hostname.labelText'}}{{field-required}}</label>
|
||||
{{input
|
||||
type='text'
|
||||
value=authConfig.hostname
|
||||
classNames='form-control'
|
||||
}}
|
||||
<p class='help-block'>{{t 'authPage.google.notAuthenticated.form.hostname.helperText'}}</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row">
|
||||
<div class="col span-12">
|
||||
<div class='row'>
|
||||
<div class='col span-12'>
|
||||
{{#input-text-file
|
||||
classNames="box"
|
||||
label="authPage.google.notAuthenticated.form.oauthCredential.labelText"
|
||||
classNames='box'
|
||||
label='authPage.google.notAuthenticated.form.oauthCredential.labelText'
|
||||
value=authConfig.oauthCredential
|
||||
accept="text/*, .json"
|
||||
accept='text/*, .json'
|
||||
minHeight=60
|
||||
canChangeName=false
|
||||
nameRequired=true
|
||||
placeholder="authPage.google.notAuthenticated.form.oauthCredential.labelText"
|
||||
placeholder='authPage.google.notAuthenticated.form.oauthCredential.labelText'
|
||||
concealValue=true
|
||||
as |section|
|
||||
}}
|
||||
{{#if (eq section "description")}}
|
||||
<div class="row help">
|
||||
<div class="col span-12 help-block wrap mb-0">
|
||||
{{t "authPage.google.notAuthenticated.form.oauthCredential.helperText" htmlSafe=true}}
|
||||
{{#if (eq section 'description')}}
|
||||
<div class='row help'>
|
||||
<div class='col span-12 help-block wrap mb-0'>
|
||||
{{t 'authPage.google.notAuthenticated.form.oauthCredential.helperText' htmlSafe=true}}
|
||||
</div>
|
||||
</div>
|
||||
{{/if}}
|
||||
|
|
@ -163,24 +201,24 @@
|
|||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row">
|
||||
<div class="col span-12">
|
||||
<div class='row'>
|
||||
<div class='col span-12'>
|
||||
{{#input-text-file
|
||||
classNames="box"
|
||||
label="authPage.google.notAuthenticated.form.serviceAccountCredential.labelText"
|
||||
classNames='box'
|
||||
label='authPage.google.notAuthenticated.form.serviceAccountCredential.labelText'
|
||||
value=authConfig.serviceAccountCredential
|
||||
accept="text/*, .json"
|
||||
accept='text/*, .json'
|
||||
minHeight=60
|
||||
canChangeName=false
|
||||
nameRequired=true
|
||||
placeholder="authPage.google.notAuthenticated.form.serviceAccountCredential.labelText"
|
||||
placeholder='authPage.google.notAuthenticated.form.serviceAccountCredential.labelText'
|
||||
concealValue=true
|
||||
as |section|
|
||||
}}
|
||||
{{#if (eq section "description")}}
|
||||
<div class="row help">
|
||||
<div class="col span-12 help-block wrap mb-0">
|
||||
{{t "authPage.google.notAuthenticated.form.serviceAccountCredential.helperText" htmlSafe=true}}
|
||||
{{#if (eq section 'description')}}
|
||||
<div class='row help'>
|
||||
<div class='col span-12 help-block wrap mb-0'>
|
||||
{{t 'authPage.google.notAuthenticated.form.serviceAccountCredential.helperText' htmlSafe=true}}
|
||||
</div>
|
||||
</div>
|
||||
{{/if}}
|
||||
|
|
@ -188,18 +226,18 @@
|
|||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row text-center">
|
||||
<div class="btn-group">
|
||||
<button class="btn bg-primary" {{action "save"}}>
|
||||
<div class='row text-center'>
|
||||
<div class='btn-group'>
|
||||
<button class='btn bg-primary' {{action 'save'}}>
|
||||
{{#if saving}}
|
||||
<i class="icon icon-spinner icon-spin"></i> {{t 'authPage.google.testAuth.buttonText.post'}}
|
||||
<i class='icon icon-spinner icon-spin'></i> {{t 'authPage.google.testAuth.buttonText.post'}}
|
||||
{{else if doneSaving}}
|
||||
{{t 'generic.saved'}}
|
||||
{{else}}
|
||||
<i class="icon icon-github"></i> {{t 'authPage.google.testAuth.buttonText.pre'}}
|
||||
<i class='icon icon-google'></i> {{t 'authPage.google.testAuth.buttonText.pre'}}
|
||||
{{/if}}
|
||||
</button>
|
||||
<button {{action "cancel"}} class="btn bg-transparent">{{t 'saveCancel.cancel'}}</button>
|
||||
<button {{action 'cancel'}} class='btn bg-transparent'>{{t 'saveCancel.cancel'}}</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
|
|
|||
|
|
@ -2,11 +2,11 @@ import { inject as service } from '@ember/service';
|
|||
import Component from '@ember/component';
|
||||
|
||||
export default Component.extend({
|
||||
github: service(),
|
||||
oauth: service(),
|
||||
|
||||
actions: {
|
||||
authenticate() {
|
||||
this.get('github').login();
|
||||
this.get('oauth').login('github');
|
||||
}
|
||||
}
|
||||
});
|
||||
|
|
|
|||
|
|
@ -2,11 +2,11 @@ import { inject as service } from '@ember/service';
|
|||
import Component from '@ember/component';
|
||||
|
||||
export default Component.extend({
|
||||
google: service(),
|
||||
oauth: service(),
|
||||
|
||||
actions: {
|
||||
authenticate() {
|
||||
this.get('google').login();
|
||||
this.get('oauth').login('googleoauth');
|
||||
}
|
||||
}
|
||||
});
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
<form {{action "authenticate" on="submit"}} class="row pt-10 pb-10">
|
||||
<button disabled={{waiting}} class="btn bg-primary" {{action "authenticate"}}>
|
||||
<i class="icon icon-github"></i> {{t 'loginGoogle.buttonText'}}
|
||||
<i class="icon icon-google"></i> {{t 'loginGoogle.buttonText'}}
|
||||
</button>
|
||||
</form>
|
||||
|
|
|
|||
|
|
@ -3,6 +3,9 @@ import { addQueryParam, addQueryParams, popupWindowOptions } from 'shared/utils/
|
|||
import { get, set } from '@ember/object';
|
||||
import C from 'shared/utils/constants';
|
||||
|
||||
const googleOauthScope = 'openid profile email https://www.googleapis.com/auth/admin.directory.user.readonly https://www.googleapis.com/auth/admin.directory.group.readonly';
|
||||
const githubOauthScope = 'read:org';
|
||||
|
||||
export default Service.extend({
|
||||
access: service(),
|
||||
cookies: service(),
|
||||
|
|
@ -10,11 +13,16 @@ export default Service.extend({
|
|||
globalStore: service(),
|
||||
app: service(),
|
||||
intl: service(),
|
||||
authType: '',
|
||||
|
||||
generateState() {
|
||||
return set(this, 'session.githubState', `${ Math.random() }`);
|
||||
},
|
||||
|
||||
generateLoginStateKey(authType) {
|
||||
return set(this, 'session.githubState', `${ Math.random() }login${ authType }`)
|
||||
},
|
||||
|
||||
stateMatches(actual) {
|
||||
return actual && get(this, 'session.githubState') === actual;
|
||||
},
|
||||
|
|
@ -28,30 +36,40 @@ export default Service.extend({
|
|||
},
|
||||
|
||||
authorize(auth, state) {
|
||||
const url = addQueryParams(get(auth, 'redirectUrl'), {
|
||||
scope: 'read:org',
|
||||
const isGithub = auth.type.includes('github')
|
||||
let url = null;
|
||||
|
||||
|
||||
if (isGithub) {
|
||||
url = addQueryParams(get(auth, 'redirectUrl'), {
|
||||
scope: githubOauthScope,
|
||||
redirect_uri: `${ window.location.origin }/verify-auth`,
|
||||
authProvider: 'github',
|
||||
state,
|
||||
});
|
||||
} else {
|
||||
url = addQueryParams(get(auth, 'redirectUrl'), {
|
||||
scope: googleOauthScope,
|
||||
redirect_uri: `${ window.location.origin }/verify-auth`,
|
||||
state,
|
||||
});
|
||||
}
|
||||
|
||||
return window.location.href = url;
|
||||
},
|
||||
|
||||
login(forwardUrl) {
|
||||
const provider = get(this, 'access.providers').findBy('id', 'github');
|
||||
login(authType, forwardUrl) {
|
||||
const provider = get(this, 'access.providers').findBy('id', authType);
|
||||
const authRedirect = get(provider, 'redirectUrl');
|
||||
let redirect = addQueryParams(`${ window.location.origin }/verify-auth`, {
|
||||
login: true,
|
||||
state: this.generateState(),
|
||||
});
|
||||
let redirect = `${ window.location.origin }/verify-auth`;
|
||||
|
||||
if ( forwardUrl ) {
|
||||
redirect = addQueryParam(redirect, 'forward', forwardUrl);
|
||||
}
|
||||
|
||||
const url = addQueryParams(authRedirect, {
|
||||
scope: 'read:org',
|
||||
let url = addQueryParams(authRedirect, {
|
||||
scope: authType === 'github' ? githubOauthScope : googleOauthScope,
|
||||
state: this.generateLoginStateKey(authType),
|
||||
redirect_uri: redirect,
|
||||
});
|
||||
|
||||
|
|
@ -60,6 +78,7 @@ export default Service.extend({
|
|||
|
||||
test(config, cb) {
|
||||
let responded = false;
|
||||
let configName = config.name;
|
||||
|
||||
window.onAuthTest = (err, code) => {
|
||||
if ( !responded ) {
|
||||
|
|
@ -72,8 +91,7 @@ export default Service.extend({
|
|||
};
|
||||
|
||||
set(this, 'state', this.generateState());
|
||||
|
||||
let url = addQueryParams(`${ window.location.origin }/verify-auth`, { config: 'github', });
|
||||
let url = addQueryParams(`${ window.location.origin }/verify-auth`, { config: configName, });
|
||||
|
||||
const popup = window.open(url, 'rancherAuth', popupWindowOptions());
|
||||
const intl = get(this, 'intl');
|
||||
|
|
@ -105,17 +123,28 @@ export default Service.extend({
|
|||
},
|
||||
|
||||
finishTest(config, code, cb) {
|
||||
const ghConfig = config;
|
||||
const currentConfig = config;
|
||||
let out = null;
|
||||
|
||||
set(ghConfig, 'enabled', true);
|
||||
set(currentConfig, 'enabled', true);
|
||||
|
||||
let out = {
|
||||
if (config.id === 'googleoauth') {
|
||||
out = {
|
||||
code,
|
||||
enabled: true,
|
||||
githubConfig: ghConfig,
|
||||
googleOauthConfig: currentConfig,
|
||||
description: C.SESSION.DESCRIPTION,
|
||||
ttl: C.SESSION.TTL,
|
||||
};
|
||||
} else {
|
||||
out = {
|
||||
code,
|
||||
enabled: true,
|
||||
githubConfig: currentConfig,
|
||||
description: C.SESSION.DESCRIPTION,
|
||||
ttl: C.SESSION.TTL,
|
||||
};
|
||||
}
|
||||
|
||||
const allowedPrincipalIds = get(config, 'allowedPrincipalIds') || [];
|
||||
|
||||
|
|
@ -133,7 +162,7 @@ export default Service.extend({
|
|||
allowedPrincipalIds.pushObject(get(this, 'access.principal.id'));
|
||||
}
|
||||
|
||||
return ghConfig.save().then(() => {
|
||||
return currentConfig.save().then(() => {
|
||||
window.location.href = window.location.href;
|
||||
});
|
||||
})
|
||||
|
|
|
|||
|
|
@ -3,7 +3,8 @@ import { addQueryParam, addQueryParams, popupWindowOptions } from 'shared/utils/
|
|||
import { get, set } from '@ember/object';
|
||||
import C from 'shared/utils/constants';
|
||||
|
||||
const googleOauthScope = 'openid profile email https://www.googleapis.com/auth/admin.directory.user.readonly https://www.googleapis.com/auth/admin.directory.group.readonly'
|
||||
const googleOauthScope = 'openid profile email https://www.googleapis.com/auth/admin.directory.user.readonly https://www.googleapis.com/auth/admin.directory.group.readonly';
|
||||
const githubOauthScope = 'read:org';
|
||||
|
||||
export default Service.extend({
|
||||
access: service(),
|
||||
|
|
@ -12,17 +13,18 @@ export default Service.extend({
|
|||
globalStore: service(),
|
||||
app: service(),
|
||||
intl: service(),
|
||||
authType: '',
|
||||
|
||||
generateState() {
|
||||
return set(this, 'session.googleState', `${ Math.random() }`);
|
||||
return set(this, 'session.githubState', `${ Math.random() }`);
|
||||
},
|
||||
|
||||
generateLoginStateKey() {
|
||||
return set(this, 'session.googleState', `${ Math.random() }login`)
|
||||
generateLoginStateKey(authType) {
|
||||
return set(this, 'session.githubState', `${ Math.random() }login${ authType }`)
|
||||
},
|
||||
|
||||
stateMatches(actual) {
|
||||
return actual && get(this, 'session.googleState') === actual;
|
||||
return actual && get(this, 'session.githubState') === actual;
|
||||
},
|
||||
|
||||
testConfig(config) {
|
||||
|
|
@ -34,18 +36,30 @@ export default Service.extend({
|
|||
},
|
||||
|
||||
authorize(auth, state) {
|
||||
const url = addQueryParams(get(auth, 'redirectUrl'), {
|
||||
const isGithub = auth.type.includes('github')
|
||||
let url = null;
|
||||
|
||||
|
||||
if (isGithub) {
|
||||
url = addQueryParams(get(auth, 'redirectUrl'), {
|
||||
scope: githubOauthScope,
|
||||
redirect_uri: `${ window.location.origin }/verify-auth`,
|
||||
authProvider: 'github',
|
||||
state,
|
||||
});
|
||||
} else {
|
||||
url = addQueryParams(get(auth, 'redirectUrl'), {
|
||||
scope: googleOauthScope,
|
||||
redirect_uri: `${ window.location.origin }/verify-auth`,
|
||||
state,
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
return window.location.href = url;
|
||||
},
|
||||
|
||||
login(forwardUrl) {
|
||||
const provider = get(this, 'access.providers').findBy('id', 'googleoauth');
|
||||
login(authType, forwardUrl) {
|
||||
const provider = get(this, 'access.providers').findBy('id', authType);
|
||||
const authRedirect = get(provider, 'redirectUrl');
|
||||
let redirect = `${ window.location.origin }/verify-auth`;
|
||||
|
||||
|
|
@ -53,9 +67,9 @@ export default Service.extend({
|
|||
redirect = addQueryParam(redirect, 'forward', forwardUrl);
|
||||
}
|
||||
|
||||
const url = addQueryParams(authRedirect, {
|
||||
scope: googleOauthScope,
|
||||
state: this.generateLoginStateKey(),
|
||||
let url = addQueryParams(authRedirect, {
|
||||
scope: authType === 'github' ? githubOauthScope : googleOauthScope,
|
||||
state: this.generateLoginStateKey(authType),
|
||||
redirect_uri: redirect,
|
||||
});
|
||||
|
||||
|
|
@ -64,20 +78,20 @@ export default Service.extend({
|
|||
|
||||
test(config, cb) {
|
||||
let responded = false;
|
||||
let configName = config.name;
|
||||
|
||||
window.onAuthTest = (err, code) => {
|
||||
if ( !responded ) {
|
||||
let googleConfig = config;
|
||||
let ghConfig = config;
|
||||
|
||||
responded = true;
|
||||
|
||||
this.finishTest(googleConfig, code, cb);
|
||||
this.finishTest(ghConfig, code, cb);
|
||||
}
|
||||
};
|
||||
|
||||
set(this, 'state', this.generateState());
|
||||
|
||||
let url = addQueryParams(`${ window.location.origin }/verify-auth`, { config: 'googleoauth', });
|
||||
let url = addQueryParams(`${ window.location.origin }/verify-auth`, { config: configName, });
|
||||
|
||||
const popup = window.open(url, 'rancherAuth', popupWindowOptions());
|
||||
const intl = get(this, 'intl');
|
||||
|
|
@ -90,7 +104,7 @@ export default Service.extend({
|
|||
responded = true;
|
||||
cb({
|
||||
type: 'error',
|
||||
message: intl.t('authPage.google.testAuth.authError')
|
||||
message: intl.t('authPage.github.testAuth.authError')
|
||||
});
|
||||
}
|
||||
} else if (popup === null || typeof (popup) === 'undefined') {
|
||||
|
|
@ -101,7 +115,7 @@ export default Service.extend({
|
|||
|
||||
cb({
|
||||
type: 'error',
|
||||
message: intl.t('authPage.google.testAuth.popupError')
|
||||
message: intl.t('authPage.github.testAuth.popupError')
|
||||
});
|
||||
}
|
||||
}
|
||||
|
|
@ -109,17 +123,28 @@ export default Service.extend({
|
|||
},
|
||||
|
||||
finishTest(config, code, cb) {
|
||||
const goConfig = config;
|
||||
const currentConfig = config;
|
||||
let out = null;
|
||||
|
||||
set(goConfig, 'enabled', true);
|
||||
set(currentConfig, 'enabled', true);
|
||||
|
||||
let out = {
|
||||
if (config.id === 'googleoauth') {
|
||||
out = {
|
||||
code,
|
||||
enabled: true,
|
||||
googleOauthConfig: goConfig,
|
||||
googleOauthConfig: currentConfig,
|
||||
description: C.SESSION.DESCRIPTION,
|
||||
ttl: C.SESSION.TTL,
|
||||
};
|
||||
} else {
|
||||
out = {
|
||||
code,
|
||||
enabled: true,
|
||||
githubConfig: currentConfig,
|
||||
description: C.SESSION.DESCRIPTION,
|
||||
ttl: C.SESSION.TTL,
|
||||
};
|
||||
}
|
||||
|
||||
const allowedPrincipalIds = get(config, 'allowedPrincipalIds') || [];
|
||||
|
||||
|
|
@ -137,7 +162,7 @@ export default Service.extend({
|
|||
allowedPrincipalIds.pushObject(get(this, 'access.principal.id'));
|
||||
}
|
||||
|
||||
return goConfig.save().then(() => {
|
||||
return currentConfig.save().then(() => {
|
||||
window.location.href = window.location.href;
|
||||
});
|
||||
})
|
||||
|
|
@ -145,4 +170,4 @@ export default Service.extend({
|
|||
cb(err);
|
||||
});
|
||||
},
|
||||
})
|
||||
});
|
||||
|
|
@ -220,6 +220,9 @@ var C = {
|
|||
TYPE_OKTA_GROUP: 'okta_group',
|
||||
TYPE_FREEIPA_USER: 'freeipa_user',
|
||||
TYPE_FREEIPA_GROUP: 'freeipa_group',
|
||||
TYPE_GOOGLE_USER: 'google_user',
|
||||
TYPE_GOOGLE_TEAM: 'google_team',
|
||||
TYPE_GOOGLE_ORG: 'google_org',
|
||||
|
||||
PERSON: 'person',
|
||||
TEAM: 'team',
|
||||
|
|
|
|||
|
|
@ -1 +0,0 @@
|
|||
export { default } from 'shared/google/service';
|
||||
|
|
@ -0,0 +1 @@
|
|||
export { default } from 'shared/oauth/service';
|
||||
|
|
@ -1 +1 @@
|
|||
Subproject commit dc7c438544167077ea087bd594921c0d12e7b182
|
||||
Subproject commit 3781f899f1f430fa7af78642e89055d4da2695db
|
||||
Loading…
Reference in New Issue