2021-05-16 16:52:27 +00:00
|
|
|
import { OAuthSource, SourcesApi, FlowsApi, UserMatchingModeEnum, OAuthSourceRequest, FlowsInstancesListDesignationEnum } from "authentik-api";
|
2021-04-03 17:26:43 +00:00
|
|
|
import { t } from "@lingui/macro";
|
2021-04-02 13:15:19 +00:00
|
|
|
import { customElement, property } from "lit-element";
|
|
|
|
import { html, TemplateResult } from "lit-html";
|
|
|
|
import { DEFAULT_CONFIG } from "../../../api/Config";
|
|
|
|
import "../../../elements/forms/FormGroup";
|
|
|
|
import "../../../elements/forms/HorizontalFormElement";
|
|
|
|
import { ifDefined } from "lit-html/directives/if-defined";
|
|
|
|
import { until } from "lit-html/directives/until";
|
2021-04-03 22:36:53 +00:00
|
|
|
import { first } from "../../../utils";
|
2021-05-11 09:48:34 +00:00
|
|
|
import { ModelForm } from "../../../elements/forms/ModelForm";
|
2021-04-02 13:15:19 +00:00
|
|
|
|
|
|
|
@customElement("ak-source-oauth-form")
|
2021-05-11 09:48:34 +00:00
|
|
|
export class OAuthSourceForm extends ModelForm<OAuthSource, string> {
|
2021-04-02 13:15:19 +00:00
|
|
|
|
2021-05-11 09:48:34 +00:00
|
|
|
loadInstance(pk: string): Promise<OAuthSource> {
|
2021-05-16 12:43:42 +00:00
|
|
|
return new SourcesApi(DEFAULT_CONFIG).sourcesOauthRetrieve({
|
2021-05-11 09:48:34 +00:00
|
|
|
slug: pk,
|
2021-04-02 13:15:19 +00:00
|
|
|
}).then(source => {
|
2021-04-03 22:36:53 +00:00
|
|
|
this.showUrlOptions = first(source.type?.urlsCustomizable, false);
|
2021-05-11 09:48:34 +00:00
|
|
|
return source;
|
2021-04-02 13:15:19 +00:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2021-04-17 17:16:23 +00:00
|
|
|
@property()
|
|
|
|
modelName?: string;
|
|
|
|
|
2021-04-02 13:15:19 +00:00
|
|
|
@property({type: Boolean})
|
|
|
|
showUrlOptions = false;
|
|
|
|
|
2021-04-17 19:13:33 +00:00
|
|
|
@property({type: Boolean})
|
|
|
|
showRequestTokenURL = false;
|
|
|
|
|
2021-04-02 13:15:19 +00:00
|
|
|
getSuccessMessage(): string {
|
2021-05-11 09:48:34 +00:00
|
|
|
if (this.instance) {
|
2021-04-03 17:26:43 +00:00
|
|
|
return t`Successfully updated source.`;
|
2021-04-02 13:15:19 +00:00
|
|
|
} else {
|
2021-04-03 17:26:43 +00:00
|
|
|
return t`Successfully created source.`;
|
2021-04-02 13:15:19 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
send = (data: OAuthSource): Promise<OAuthSource> => {
|
2021-06-01 21:36:21 +00:00
|
|
|
if (this.instance?.slug) {
|
2021-05-11 11:31:33 +00:00
|
|
|
return new SourcesApi(DEFAULT_CONFIG).sourcesOauthPartialUpdate({
|
2021-05-11 09:48:34 +00:00
|
|
|
slug: this.instance.slug,
|
2021-05-16 16:24:15 +00:00
|
|
|
patchedOAuthSourceRequest: data
|
2021-04-02 13:15:19 +00:00
|
|
|
});
|
|
|
|
} else {
|
|
|
|
return new SourcesApi(DEFAULT_CONFIG).sourcesOauthCreate({
|
2021-05-16 16:24:15 +00:00
|
|
|
oAuthSourceRequest: data as unknown as OAuthSourceRequest
|
2021-04-02 13:15:19 +00:00
|
|
|
});
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
renderUrlOptions(): TemplateResult {
|
|
|
|
if (!this.showUrlOptions) {
|
|
|
|
return html``;
|
|
|
|
}
|
|
|
|
return html`
|
|
|
|
<ak-form-group>
|
|
|
|
<span slot="header">
|
2021-04-03 17:26:43 +00:00
|
|
|
${t`URL settings`}
|
2021-04-02 13:15:19 +00:00
|
|
|
</span>
|
|
|
|
<div slot="body" class="pf-c-form">
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Authorization URL`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="authorizationUrl">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="text" value="${first(this.instance?.authorizationUrl, "")}" class="pf-c-form-control" required>
|
2021-04-03 17:26:43 +00:00
|
|
|
<p class="pf-c-form__helper-text">${t`URL the user is redirect to to consent the authorization.`}</p>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Access token URL`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="accessTokenUrl">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="text" value="${first(this.instance?.accessTokenUrl, "")}" class="pf-c-form-control" required>
|
2021-04-03 17:26:43 +00:00
|
|
|
<p class="pf-c-form__helper-text">${t`URL used by authentik to retrieve tokens.`}</p>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Profile URL`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="profileUrl">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="text" value="${first(this.instance?.profileUrl, "")}" class="pf-c-form-control" required>
|
2021-04-03 17:26:43 +00:00
|
|
|
<p class="pf-c-form__helper-text">${t`URL used by authentik to get user information.`}</p>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
2021-04-17 19:13:33 +00:00
|
|
|
${this.showRequestTokenURL ? html`<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Request token URL`}
|
2021-04-02 13:15:19 +00:00
|
|
|
name="requestTokenUrl">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="text" value="${first(this.instance?.requestTokenUrl, "")}" class="pf-c-form-control">
|
2021-04-03 17:26:43 +00:00
|
|
|
<p class="pf-c-form__helper-text">${t`URL used to request the initial token. This URL is only required for OAuth 1.`}</p>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
2021-04-17 19:13:33 +00:00
|
|
|
` : html``}
|
2021-04-02 13:15:19 +00:00
|
|
|
</div>
|
|
|
|
</ak-form-group>`;
|
|
|
|
}
|
|
|
|
|
|
|
|
renderForm(): TemplateResult {
|
|
|
|
return html`<form class="pf-c-form pf-m-horizontal">
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Name`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="name">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="text" value="${ifDefined(this.instance?.name)}" class="pf-c-form-control" required>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Slug`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="slug">
|
2021-06-08 15:56:35 +00:00
|
|
|
<input type="text" value="${ifDefined(this.instance?.slug)}" class="pf-c-form-control" required>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal name="enabled">
|
|
|
|
<div class="pf-c-check">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="checkbox" class="pf-c-check__input" ?checked=${first(this.instance?.enabled, true)}>
|
2021-04-02 13:15:19 +00:00
|
|
|
<label class="pf-c-check__label">
|
2021-04-03 17:26:43 +00:00
|
|
|
${t`Enabled`}
|
2021-04-02 13:15:19 +00:00
|
|
|
</label>
|
|
|
|
</div>
|
|
|
|
</ak-form-element-horizontal>
|
2021-05-04 10:02:16 +00:00
|
|
|
<ak-form-element-horizontal
|
|
|
|
label=${t`User matching mode`}
|
|
|
|
?required=${true}
|
|
|
|
name="userMatchingMode">
|
|
|
|
<select class="pf-c-form-control">
|
2021-05-16 13:31:13 +00:00
|
|
|
<option value=${UserMatchingModeEnum.Identifier} ?selected=${this.instance?.userMatchingMode === UserMatchingModeEnum.Identifier}>
|
2021-05-04 10:02:16 +00:00
|
|
|
${t`Link users on unique identifier`}
|
|
|
|
</option>
|
2021-05-16 13:31:13 +00:00
|
|
|
<option value=${UserMatchingModeEnum.UsernameLink} ?selected=${this.instance?.userMatchingMode === UserMatchingModeEnum.UsernameLink}>
|
2021-05-04 10:02:16 +00:00
|
|
|
${t`Link to a user with identical email address. Can have security implications when a source doesn't validate email addresses`}
|
|
|
|
</option>
|
2021-05-16 13:31:13 +00:00
|
|
|
<option value=${UserMatchingModeEnum.UsernameDeny} ?selected=${this.instance?.userMatchingMode === UserMatchingModeEnum.UsernameDeny}>
|
2021-05-04 10:02:16 +00:00
|
|
|
${t`Use the user's email address, but deny enrollment when the email address already exists.`}
|
|
|
|
</option>
|
2021-05-16 13:31:13 +00:00
|
|
|
<option value=${UserMatchingModeEnum.EmailLink} ?selected=${this.instance?.userMatchingMode === UserMatchingModeEnum.EmailLink}>
|
2021-05-04 10:02:16 +00:00
|
|
|
${t`Link to a user with identical username address. Can have security implications when a username is used with another source.`}
|
|
|
|
</option>
|
2021-05-16 13:31:13 +00:00
|
|
|
<option value=${UserMatchingModeEnum.EmailDeny} ?selected=${this.instance?.userMatchingMode === UserMatchingModeEnum.EmailDeny}>
|
2021-05-04 10:02:16 +00:00
|
|
|
${t`Use the user's username, but deny enrollment when the username already exists.`}
|
|
|
|
</option>
|
|
|
|
</select>
|
|
|
|
</ak-form-element-horizontal>
|
2021-04-02 13:15:19 +00:00
|
|
|
|
|
|
|
<ak-form-group .expanded=${true}>
|
|
|
|
<span slot="header">
|
2021-04-03 17:26:43 +00:00
|
|
|
${t`Protocol settings`}
|
2021-04-02 13:15:19 +00:00
|
|
|
</span>
|
|
|
|
<div slot="body" class="pf-c-form">
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Consumer key`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="consumerKey">
|
2021-05-11 09:48:34 +00:00
|
|
|
<input type="text" value="${ifDefined(this.instance?.consumerKey)}" class="pf-c-form-control" required>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Consumer secret`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
2021-05-11 09:48:34 +00:00
|
|
|
?writeOnly=${this.instance !== undefined}
|
2021-04-02 13:15:19 +00:00
|
|
|
name="consumerSecret">
|
2021-05-16 16:24:15 +00:00
|
|
|
<input type="text" value="" class="pf-c-form-control" required>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Provider type`}
|
2021-04-02 13:15:19 +00:00
|
|
|
name="providerType">
|
|
|
|
<select class="pf-c-form-control" @change=${(ev: Event) => {
|
|
|
|
const el = (ev.target as HTMLSelectElement);
|
|
|
|
const selected = el.selectedOptions[0];
|
2021-06-01 21:33:59 +00:00
|
|
|
this.showUrlOptions = "data-urls-custom" in selected.attributes;
|
|
|
|
this.showRequestTokenURL = "data-request-token" in selected.attributes;
|
2021-05-11 09:48:34 +00:00
|
|
|
if (!this.instance) {
|
|
|
|
this.instance = {} as OAuthSource;
|
2021-04-17 17:06:56 +00:00
|
|
|
}
|
2021-05-11 09:48:34 +00:00
|
|
|
this.instance.providerType = selected.value;
|
2021-04-02 13:15:19 +00:00
|
|
|
}}>
|
2021-05-16 16:38:19 +00:00
|
|
|
${until(new SourcesApi(DEFAULT_CONFIG).sourcesOauthSourceTypesList().then(types => {
|
2021-04-02 13:15:19 +00:00
|
|
|
return types.map(type => {
|
2021-05-11 09:48:34 +00:00
|
|
|
let selected = this.instance?.providerType === type.slug;
|
2021-06-01 21:16:36 +00:00
|
|
|
const modelSlug = this.modelName?.replace("oauthsource", "").replace("-", "");
|
|
|
|
const typeSlug = type.slug.replace("-", "");
|
2021-05-11 09:48:34 +00:00
|
|
|
if (!this.instance?.pk) {
|
2021-06-01 21:16:36 +00:00
|
|
|
if (modelSlug === typeSlug) {
|
2021-04-17 17:16:23 +00:00
|
|
|
selected = true;
|
2021-06-01 21:33:59 +00:00
|
|
|
this.showUrlOptions = type.urlsCustomizable;
|
|
|
|
this.showRequestTokenURL = type.requestTokenUrl !== null;
|
2021-04-17 17:16:23 +00:00
|
|
|
}
|
|
|
|
}
|
2021-04-17 19:13:33 +00:00
|
|
|
return html`<option
|
|
|
|
?data-urls-custom=${type.urlsCustomizable}
|
|
|
|
?data-request-token=${type.requestTokenUrl}
|
|
|
|
value=${type.slug}
|
|
|
|
?selected=${selected}>
|
|
|
|
${type.name}
|
|
|
|
</option>`;
|
2021-04-02 13:15:19 +00:00
|
|
|
});
|
2021-04-03 22:24:06 +00:00
|
|
|
}), html`<option>${t`Loading...`}</option>`)}
|
2021-04-02 13:15:19 +00:00
|
|
|
</select>
|
|
|
|
</ak-form-element-horizontal>
|
|
|
|
</div>
|
|
|
|
</ak-form-group>
|
|
|
|
${this.renderUrlOptions()}
|
|
|
|
<ak-form-group>
|
|
|
|
<span slot="header">
|
2021-04-03 17:26:43 +00:00
|
|
|
${t`Flow settings`}
|
2021-04-02 13:15:19 +00:00
|
|
|
</span>
|
|
|
|
<div slot="body" class="pf-c-form">
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Authentication flow`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="authenticationFlow">
|
|
|
|
<select class="pf-c-form-control">
|
|
|
|
${until(new FlowsApi(DEFAULT_CONFIG).flowsInstancesList({
|
|
|
|
ordering: "pk",
|
2021-05-16 16:46:04 +00:00
|
|
|
designation: FlowsInstancesListDesignationEnum.Authentication,
|
2021-04-02 13:15:19 +00:00
|
|
|
}).then(flows => {
|
|
|
|
return flows.results.map(flow => {
|
2021-05-11 09:48:34 +00:00
|
|
|
let selected = this.instance?.authenticationFlow === flow.pk;
|
|
|
|
if (!this.instance?.pk && !this.instance?.authenticationFlow && flow.slug === "default-source-authentication") {
|
2021-04-02 13:15:19 +00:00
|
|
|
selected = true;
|
|
|
|
}
|
|
|
|
return html`<option value=${ifDefined(flow.pk)} ?selected=${selected}>${flow.name} (${flow.slug})</option>`;
|
|
|
|
});
|
2021-04-03 22:24:06 +00:00
|
|
|
}), html`<option>${t`Loading...`}</option>`)}
|
2021-04-02 13:15:19 +00:00
|
|
|
</select>
|
2021-04-03 17:26:43 +00:00
|
|
|
<p class="pf-c-form__helper-text">${t`Flow to use when authenticating existing users.`}</p>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal
|
2021-04-03 17:26:43 +00:00
|
|
|
label=${t`Enrollment flow`}
|
2021-04-02 13:15:19 +00:00
|
|
|
?required=${true}
|
|
|
|
name="enrollmentFlow">
|
|
|
|
<select class="pf-c-form-control">
|
|
|
|
${until(new FlowsApi(DEFAULT_CONFIG).flowsInstancesList({
|
|
|
|
ordering: "pk",
|
2021-05-16 16:46:04 +00:00
|
|
|
designation: FlowsInstancesListDesignationEnum.Enrollment,
|
2021-04-02 13:15:19 +00:00
|
|
|
}).then(flows => {
|
|
|
|
return flows.results.map(flow => {
|
2021-05-11 09:48:34 +00:00
|
|
|
let selected = this.instance?.enrollmentFlow === flow.pk;
|
|
|
|
if (!this.instance?.pk && !this.instance?.enrollmentFlow && flow.slug === "default-source-enrollment") {
|
2021-04-02 13:15:19 +00:00
|
|
|
selected = true;
|
|
|
|
}
|
|
|
|
return html`<option value=${ifDefined(flow.pk)} ?selected=${selected}>${flow.name} (${flow.slug})</option>`;
|
|
|
|
});
|
2021-04-03 22:24:06 +00:00
|
|
|
}), html`<option>${t`Loading...`}</option>`)}
|
2021-04-02 13:15:19 +00:00
|
|
|
</select>
|
2021-04-03 17:26:43 +00:00
|
|
|
<p class="pf-c-form__helper-text">${t`Flow to use when enrolling new users.`}</p>
|
2021-04-02 13:15:19 +00:00
|
|
|
</ak-form-element-horizontal>
|
|
|
|
</div>
|
|
|
|
</ak-form-group>
|
|
|
|
</form>`;
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|