* ATH-01-001: resolve path and check start before loading blueprints
This is even less of an issue since 411ef239f6
, since with that commit we only allow files that the listing returns
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-010: fix missing user filter for webauthn device
This prevents an attack that is only possible when an attacker can intercept HTTP traffic and in the case of HTTPS decrypt it.
* ATH-01-008: fix web forms not submitting correctly when pressing enter
When submitting some forms with the Enter key instead of clicking "Confirm"/etc, the form would not get submitted correctly
This would in the worst case is when setting a user's password, where the new password can end up in the URL, but the password was not actually saved to the user.
* ATH-01-004: remove env from admin system endpoint
this endpoint already required admin access, but for debugging the env variables are used very little
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-003 / ATH-01-012: disable htmlLabels in mermaid
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-005: use hmac.compare_digest for secret_key authentication
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-009: migrate impersonation to use API
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-010: rework
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-014: save authenticator validation state in flow context
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
bugfixes
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* ATH-01-012: escape quotation marks
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* add website
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* update release ntoes
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* update with all notes
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
* fix format
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
---------
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
81 lines
3.2 KiB
TypeScript
81 lines
3.2 KiB
TypeScript
import { RenderFlowOption } from "@goauthentik/admin/flows/utils";
|
|
import { DEFAULT_CONFIG } from "@goauthentik/common/api/config";
|
|
import { SentryIgnoredError } from "@goauthentik/common/errors";
|
|
import { Form } from "@goauthentik/elements/forms/Form";
|
|
import "@goauthentik/elements/forms/HorizontalFormElement";
|
|
import "@goauthentik/elements/forms/SearchSelect";
|
|
|
|
import { msg } from "@lit/localize";
|
|
import { TemplateResult, html } from "lit";
|
|
import { customElement } from "lit/decorators.js";
|
|
|
|
import {
|
|
Flow,
|
|
FlowsApi,
|
|
FlowsInstancesListDesignationEnum,
|
|
FlowsInstancesListRequest,
|
|
ProvidersApi,
|
|
SAMLProvider,
|
|
} from "@goauthentik/api";
|
|
|
|
@customElement("ak-provider-saml-import-form")
|
|
export class SAMLProviderImportForm extends Form<SAMLProvider> {
|
|
getSuccessMessage(): string {
|
|
return msg("Successfully imported provider.");
|
|
}
|
|
|
|
async send(data: SAMLProvider): Promise<void> {
|
|
const file = this.getFormFiles()["metadata"];
|
|
if (!file) {
|
|
throw new SentryIgnoredError("No form data");
|
|
}
|
|
return new ProvidersApi(DEFAULT_CONFIG).providersSamlImportMetadataCreate({
|
|
file: file,
|
|
name: data.name,
|
|
authorizationFlow: data.authorizationFlow || "",
|
|
});
|
|
}
|
|
|
|
renderInlineForm(): TemplateResult {
|
|
return html`<ak-form-element-horizontal label=${msg("Name")} ?required=${true} name="name">
|
|
<input type="text" class="pf-c-form-control" required />
|
|
</ak-form-element-horizontal>
|
|
<ak-form-element-horizontal
|
|
label=${msg("Authorization flow")}
|
|
?required=${true}
|
|
name="authorizationFlow"
|
|
>
|
|
<ak-search-select
|
|
.fetchObjects=${async (query?: string): Promise<Flow[]> => {
|
|
const args: FlowsInstancesListRequest = {
|
|
ordering: "slug",
|
|
designation: FlowsInstancesListDesignationEnum.Authorization,
|
|
};
|
|
if (query !== undefined) {
|
|
args.search = query;
|
|
}
|
|
const flows = await new FlowsApi(DEFAULT_CONFIG).flowsInstancesList(args);
|
|
return flows.results;
|
|
}}
|
|
.renderElement=${(flow: Flow): string => {
|
|
return RenderFlowOption(flow);
|
|
}}
|
|
.renderDescription=${(flow: Flow): TemplateResult => {
|
|
return html`${flow.name}`;
|
|
}}
|
|
.value=${(flow: Flow | undefined): string | undefined => {
|
|
return flow?.slug;
|
|
}}
|
|
>
|
|
</ak-search-select>
|
|
<p class="pf-c-form__helper-text">
|
|
${msg("Flow used when authorizing this provider.")}
|
|
</p>
|
|
</ak-form-element-horizontal>
|
|
|
|
<ak-form-element-horizontal label=${msg("Metadata")} name="metadata">
|
|
<input type="file" value="" class="pf-c-form-control" />
|
|
</ak-form-element-horizontal>`;
|
|
}
|
|
}
|