mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-09-01 21:27:58 +00:00
fix(sso): preserve admin-assigned roles across SSO sign-in (#1862)
* fix(sso): preserve admin-assigned roles across SSO sign-in An SSO/OIDC/LDAP user's role was overwritten by the IdP-derived role on every sign-in, so a role an admin assigned in Settings > Users reverted to the provider default on the next login. Gate role re-sync behind an opt-in sso_role_sync setting (default off), so manual role edits persist unless the operator explicitly enables IdP-authoritative sync. Email continues to sync unconditionally. Adds human-session-only GET/PUT /api/sso/config/role-sync endpoints with a hub-side API-token rejection in the remote proxy, a frontend toggle, a regenerated SSO settings screenshot, and matching docs. Closes #1851 * fix(sso): satisfy CodeQL on role-sync log and test token hashing Route three inline API-token creation blocks through the shared createTestApiToken helper so the sha256 hashing lives in one place, and log the role-sync toggle as a word instead of a raw boolean. No behavior change; resolves the CodeQL js/insecure-hashing and log-injection alerts. * fix(sso): harden role-sync gate, name the toggle, fix screenshot Addresses pre-merge review findings on the SSO role-sync feature: - Make the hub-side SSO config authz guard case-insensitive to match Express routing semantics, closing a case-variant API-token bypass. - Give the IdP role-sync switch an accessible name. - Capture the SSO settings screenshot at desktop size with the scroll area expanded so the role-sync control is fully visible.
This commit is contained in:
@@ -50,6 +50,7 @@ import {
|
||||
} from '../middleware/permissions';
|
||||
import type { PermissionAction } from '../middleware/permissions';
|
||||
import { SETTING_WRITE_PERMISSIONS } from '../routes/settings';
|
||||
import { rejectApiTokenScope } from '../middleware/apiTokenScope';
|
||||
|
||||
/**
|
||||
* Per-request hop timing for the critical hydration GETs, kept off the Request
|
||||
@@ -378,6 +379,18 @@ export function createRemoteProxyMiddleware(): RequestHandler {
|
||||
return;
|
||||
}
|
||||
|
||||
// SSO configuration routes are human-session-only. The destination-side
|
||||
// rejectApiTokenScope cannot detect the original API token because this
|
||||
// proxy replaces incoming credentials with a node-to-node JWT. Reject
|
||||
// API-token-authenticated requests here, covering the /sso/config collection
|
||||
// and all descendant paths (req.path is post-/api strip). Express matches
|
||||
// routes case-insensitively, so this guard must too (the i flag).
|
||||
if (/^\/sso\/config(?:\/|$)/i.test(req.path)) {
|
||||
if (rejectApiTokenScope(req, res, 'API tokens cannot access SSO configuration.')) {
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
const node = NodeRegistry.getInstance().getNode(req.nodeId);
|
||||
if (!node || node.type !== 'remote') {
|
||||
next();
|
||||
|
||||
Reference in New Issue
Block a user