Commit Graph
322 Commits
Author SHA1 Message Date
Nirav Parikh 0d828f1272 Merge pull request #134 from RafayLabs/idp-groups-and-updating-same
Add IdP groups in Identities table
2022-05-17 19:09:43 +05:30
Akshay Gaikwad d26dfa5e55 Fix: go formatting 2022-05-17 13:20:10 +05:30
Akshay Gaikwad 2e4d802995 Fix: Type assertion error on IdPGroups 2022-05-17 13:16:59 +05:30
Abin Simon 5c68a33537 Prevent combining idp and managed groups 2022-05-13 16:24:58 +05:30
Abin Simon ed81980a7f Merge pull request #136 from RafayLabs/oidc-provider-update-secret-issuer
[OIdC Provider] Return client secret on GET requests
2022-05-13 13:50:55 +05:30
Abin Simon f3de101f94 Update User spec to include IDPGroups 2022-05-13 13:37:07 +05:30
Akshay Gaikwad f604768865 [OIdC Provider] Return client secret on GET requests
- Returns client secret on GET request, so that when UI made
modification to OIdC provider, it should be able to send back the
client secret to PUT request.
- Fix issuer url validation when udpate.
2022-05-12 19:15:10 +05:30
Akshay Gaikwad a0424f4000 Modify groupaccount table instead of just policy rules 2022-05-12 18:11:10 +05:30
Abin Simon 51db33f8b9 Merge pull request #133 from RafayLabs/fix-prompt-access
Ignore unnecessary error checks
2022-05-12 18:01:48 +05:30
Akshay Gaikwad 5e7fc110b2 Add IdP groups in Identities table
The idp_groups is list of groups IdP user belongs to that is returning
in the OIdC providers token response. The flow of Idp Group mapping is
as follows:
    OIdC Provider (OP) return custom claim with groups in a token when
    authentication event
        |
    The value of custom claim is mapped to `idp_groups` of identity
    traint using JsonNet mapper.
        |
    On inserting/updating/deleting `identities` table, Postgresql
    sends a pg_notification with
    `PG_OPERATION,IDENTITY_ID,IDENTITY_TRAIN` as a payload.
       |
    The `pkg/service/user.UserService.UpdateIdpUserGroupPolicy` update
    the casbin policies for each notification based on payload received.
2022-05-12 12:32:30 +05:30
akshay196-rafay da1d8c9331 Merge pull request #131 from RafayLabs/oidc-improvements
OIDC Provider improvements
2022-05-12 11:29:13 +05:30
Akshay Gaikwad 243c7645b5 Remove file:// from OIDC urls validation 2022-05-12 11:10:56 +05:30
Abin Simon 7e025813d9 Drop unnecessary error checks 2022-05-11 17:17:36 +05:30
Abin Simon cfccc1f55c Merge pull request #132 from RafayLabs/remote-auth
Add auth service
2022-05-10 10:44:21 +05:30
Abin Simon 5b5d099abd Improve auth service 2022-05-10 09:28:42 +05:30
Abin Simon 34ff1f6e32 Add auth service 2022-05-09 10:13:05 +05:30
Akshay Gaikwad a308b59b07 OIdC Provider: Replace new client secret on Update provider request 2022-05-06 13:00:46 +05:30
Akshay Gaikwad 1f1d04ac29 OIdC Provider: Validate Urls
The mapperUrl, issuerUrl, authUrl and tokenUrl supports file://,
http(s):// and base64:// urls.
2022-05-06 12:31:19 +05:30
Akshay Gaikwad 38a2dd50cd OIdC Provider: Deny duplicate Issuer Url
Duplicate email from different provider applications with same issuer
url cause problems.
2022-05-06 12:09:59 +05:30
Akshay Gaikwad eb0b7d3ef2 Provision to create new oidc provider with same name that of deleted
When we soft delete oidc provider entry which we are doing for delete
provider API endpoint, we cannot create new oidc provider entry with a
same name due to unique constraint violation on name. Applying unique
constraint to name,trash will allow to create new oidc provider entry
with a same name, but fail on deleting that entry because it violates
unique constraint. Hence this commit adds unique constraint
to (id,name) combined.
2022-05-06 11:31:48 +05:30
Abin Simon 721f995db6 Merge pull request #129 from RafayLabs/hasher-upd
removing references to sensitive hash information
2022-05-05 11:11:16 +05:30
niravparikh05 cb485e426e removing references to sensitive hash information 2022-05-03 17:19:10 +05:30
Nirav Parikh a26a54574d Merge pull request #128 from RafayLabs/oidc-updates
fixes to callback url and associate default org admin group to role
2022-05-03 17:09:27 +05:30
niravparikh05 27b2b2f8d9 fixes to callback url and associate default org admin group to role 2022-05-03 13:08:23 +05:30
Nirav Parikh 597be0538e Merge pull request #127 from RafayLabs/synchronizer-udpate
[synchronizer] Run once before start listening for database udpate
2022-05-03 13:05:30 +05:30
Nirav Parikh d0bae84476 Merge pull request #126 from RafayLabs/fix-tests
Fix tests
2022-05-03 13:04:02 +05:30
Akshay Gaikwad 6fda5831ee [synchronizer] Run once before start listening for database udpate
At a time of restarting Kratos pod, we noticed to update the Kratos
config we need modify something in IdP UI to trigger the
synchronizer. Instead this change will run synchronizer initially so
it will update Kratos config with database IdP entries if any.
2022-05-03 12:50:32 +05:30
Abin Simon de8d9d874c Add step to create kind cluster for tests in CI 2022-05-02 15:17:57 +05:30
Abin Simon 7ba4f9e518 Drop broken tests from unused modules
Dropping broken tests releated to namespaces, gitops and relay peering.
2022-05-02 15:16:10 +05:30
Abin Simon e92394080b Fix string formatting in tests 2022-05-02 15:10:37 +05:30
Abin Simon c2142e6abe Fix tests because of missing fiels
--- FAIL: TestAccessorWithNull (0.00s)
    accessor_test.go:66: open testdata/secret.yaml: no such file or directory
--- FAIL: TestAccessorSetRaw (0.00s)
    accessor_test.go:93: open testdata/pod.yaml: no such file or directory
--- FAIL: TestAccessor (0.00s)
    accessor_test.go:128: open testdata/pod.yaml: no such file or directory
2022-05-02 15:10:00 +05:30
Nirav Parikh 31a89543b0 Merge pull request #125 from RafayLabs/no-restart
Fix casbin caching issues
2022-04-29 18:35:46 +05:30
Abin Simon f9ec22a0ba Invalidate casbin cache after every update 2022-04-29 15:10:36 +05:30
Abin Simon 5c7776b12e Set sentry scheme to http if no scheme available 2022-04-29 15:10:19 +05:30
Nirav Parikh df5609f1fa Merge pull request #123 from RafayLabs/oidc-fixes
fixes for oidc config and groups list
2022-04-29 11:18:12 +05:30
niravparikh05 13e78d6b07 fixes for cli auth 2022-04-28 21:35:42 +05:30
niravparikh05 e9b9b2b7f4 fixes for oidc config and groups list 2022-04-27 21:39:24 +05:30
Nirav Parikh 53140574a9 Merge pull request #122 from RafayLabs/synchronizer-omit-trashed
[synchronizer] Omit trash oidc providers in synchronizing
2022-04-27 19:03:18 +05:30
Akshay Gaikwad 4331eed88c [synchronizer] Map provider name to id in kratos confing 2022-04-27 18:33:03 +05:30
Akshay Gaikwad af09d570bf [synchronizer] Omit trash oidc providers in synchronizing 2022-04-27 16:47:03 +05:30
Nirav Parikh d908aef6bf Merge pull request #121 from RafayLabs/few-fixes
fixes for permissions and user group assoc
2022-04-26 21:34:09 +05:30
niravparikh05 33f3d9337b test case to be fixed 2022-04-26 21:31:13 +05:30
niravparikh05 101c005312 fixes for permissions and user group assoc 2022-04-26 19:56:36 +05:30
Nirav Parikh 8e5e36b6cf Merge pull request #115 from RafayLabs/audit-log-final
Audit log
2022-04-26 15:36:22 +05:30
Abin Simon 2dfbc42717 Drop org and partner restriction in relay audit lookup 2022-04-26 15:29:37 +05:30
Abin Simon 426368014b Enable audit info server for use in relay-tail 2022-04-26 15:29:26 +05:30
Abin Simon 3a87a77dca Add trash column to BootstrapAgentTemplate 2022-04-26 15:29:05 +05:30
Abin Simon 9b7dc9a9a0 Use kratos public url in prompt 2022-04-26 13:29:07 +05:30
Abin Simon a68277e295 Fix fetching user in sentry
Previously we were getting the user with quotes around it which caused issues.
2022-04-26 13:28:36 +05:30
Abin Simon abaa8294bc Improve cacheablility of docker builds 2022-04-26 13:28:22 +05:30