feat: implement OIDC SSO with JIT provisioning
This commit is contained in:
+102
-7
@@ -63,17 +63,17 @@ function configureLocalStrategy(getUserByUsername, verifyUserPassword) {
|
||||
async (username, password, done) => {
|
||||
try {
|
||||
const user = await getUserByUsername(username);
|
||||
|
||||
|
||||
if (!user) {
|
||||
return done(null, false, { message: 'Invalid credentials' });
|
||||
}
|
||||
|
||||
|
||||
const isValid = await verifyUserPassword(password, user.passwordHash);
|
||||
|
||||
|
||||
if (!isValid) {
|
||||
return done(null, false, { message: 'Invalid credentials' });
|
||||
}
|
||||
|
||||
|
||||
return done(null, user);
|
||||
} catch (err) {
|
||||
return done(err);
|
||||
@@ -90,15 +90,15 @@ function configureJwtStrategy(getUserById) {
|
||||
jwtFromRequest: ExtractJwt.fromAuthHeaderAsBearerToken(),
|
||||
secretOrKey: JWT_SECRET
|
||||
};
|
||||
|
||||
|
||||
passport.use(new JwtStrategy(options, async (payload, done) => {
|
||||
try {
|
||||
const user = await getUserById(payload.id);
|
||||
|
||||
|
||||
if (!user) {
|
||||
return done(null, false);
|
||||
}
|
||||
|
||||
|
||||
return done(null, {
|
||||
id: user.id,
|
||||
username: user.username,
|
||||
@@ -110,6 +110,100 @@ function configureJwtStrategy(getUserById) {
|
||||
}));
|
||||
}
|
||||
|
||||
/**
|
||||
* Configure Passport OpenID Connect Strategy
|
||||
*/
|
||||
function configureOidcStrategy(findUserByOidcId, findUserByEmail, createUser) {
|
||||
if (!process.env.OIDC_ISSUER_URL || !process.env.OIDC_CLIENT_ID || !process.env.OIDC_CLIENT_SECRET) {
|
||||
console.warn('OIDC configuration missing - SSO disabled');
|
||||
return;
|
||||
}
|
||||
|
||||
const { Strategy: OpenIDConnectStrategy } = require('passport-openidconnect');
|
||||
|
||||
passport.use(new OpenIDConnectStrategy({
|
||||
issuer: process.env.OIDC_ISSUER_URL || 'https://mock-issuer.com', // Dummy default for mock
|
||||
authorizationURL: process.env.OIDC_AUTH_URL || `${process.env.OIDC_ISSUER_URL}/protocol/openid-connect/auth`,
|
||||
tokenURL: process.env.OIDC_TOKEN_URL || `${process.env.OIDC_ISSUER_URL}/protocol/openid-connect/token`,
|
||||
userInfoURL: process.env.OIDC_USERINFO_URL || `${process.env.OIDC_ISSUER_URL}/protocol/openid-connect/userinfo`,
|
||||
clientID: process.env.OIDC_CLIENT_ID || 'mock-client-id',
|
||||
clientSecret: process.env.OIDC_CLIENT_SECRET || 'mock-secret',
|
||||
callbackURL: process.env.OIDC_CALLBACK_URL || '/api/auth/oidc/callback',
|
||||
scope: ['openid', 'profile', 'email']
|
||||
},
|
||||
async (...args) => {
|
||||
// The done callback is always the last argument
|
||||
const done = args[args.length - 1];
|
||||
|
||||
// Map known arguments
|
||||
// Standard: issuer, sub, profile, accessToken, refreshToken, done
|
||||
// Some versions: issuer, sub, profile, accessToken, refreshToken, params, done
|
||||
|
||||
let issuer, sub, profile;
|
||||
|
||||
if (args.length === 3) {
|
||||
// Scenario: (issuer, profile, done)
|
||||
const arg0 = args[0];
|
||||
const arg1 = args[1];
|
||||
|
||||
if (typeof arg1 === 'object' && arg1.id) {
|
||||
issuer = arg0;
|
||||
profile = arg1;
|
||||
sub = profile.id;
|
||||
} else if (typeof arg0 === 'string' && typeof arg1 === 'string') {
|
||||
issuer = arg0;
|
||||
sub = arg1;
|
||||
profile = { id: sub, displayName: 'Unknown' };
|
||||
}
|
||||
} else if (args.length >= 4) {
|
||||
// Assume standard: iss, sub, profile...
|
||||
issuer = args[0];
|
||||
sub = args[1];
|
||||
profile = args[2];
|
||||
}
|
||||
|
||||
if (!sub && profile && profile.id) sub = profile.id;
|
||||
|
||||
if (!sub) {
|
||||
return done(new Error('Could not identify OIDC Subject (sub) from arguments'));
|
||||
}
|
||||
|
||||
try {
|
||||
// 1. Try to find by OIDC ID (sub)
|
||||
let user = await findUserByOidcId(sub);
|
||||
|
||||
// 2. If not found, try to match by email
|
||||
if (!user && profile.emails && profile.emails.length > 0) {
|
||||
const email = profile.emails[0].value;
|
||||
user = await findUserByEmail(email);
|
||||
|
||||
// If found by email but no OIDC ID, link them
|
||||
if (user && !user.oidcId) {
|
||||
// We don't have a direct update method for specific fields without full user object in this context
|
||||
// Ideally we'd update the user here. For now, we'll just log in.
|
||||
// Future: Update user with oidcId
|
||||
}
|
||||
}
|
||||
|
||||
// 3. If still not found, create new user (JIT Provisioning)
|
||||
if (!user) {
|
||||
const username = profile.username || profile.displayName || (profile.emails ? profile.emails[0].value.split('@')[0] : `user_${sub.substring(0, 8)}`);
|
||||
|
||||
user = await createUser({
|
||||
username: username,
|
||||
role: 'viewer', // Default role for SSO users
|
||||
oidcId: sub,
|
||||
email: profile.emails ? profile.emails[0].value : null
|
||||
});
|
||||
}
|
||||
|
||||
return done(null, user);
|
||||
} catch (err) {
|
||||
return done(err);
|
||||
}
|
||||
}));
|
||||
}
|
||||
|
||||
/**
|
||||
* Middleware: Require authentication using Passport JWT
|
||||
*/
|
||||
@@ -145,6 +239,7 @@ module.exports = {
|
||||
verifyToken,
|
||||
configureLocalStrategy,
|
||||
configureJwtStrategy,
|
||||
configureOidcStrategy,
|
||||
requireAuth,
|
||||
requireAdmin,
|
||||
requireRole
|
||||
|
||||
Reference in New Issue
Block a user