* 🛠️ Synchronization of the user with LDAP
* add configuration with LDAP attributes mappings * add defalut company and remove application check since it's not configurable * change error handling, now all the requests are independant
This commit is contained in:
@@ -81,7 +81,7 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"database":{
|
"database":{
|
||||||
"secret":"ab63bb3e90c0271c9a1c06651a7c0967eab8851a7a897766",
|
"secret":"",
|
||||||
"type":"cassandra",
|
"type":"cassandra",
|
||||||
"mongodb":{
|
"mongodb":{
|
||||||
"uri":"mongodb://mongo:27017",
|
"uri":"mongodb://mongo:27017",
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ import {
|
|||||||
RealtimeBaseBusEvent,
|
RealtimeBaseBusEvent,
|
||||||
} from "../../../../core/platform/services/realtime/types";
|
} from "../../../../core/platform/services/realtime/types";
|
||||||
import { ResourceGetResponse } from "../../../../utils/types";
|
import { ResourceGetResponse } from "../../../../utils/types";
|
||||||
import { getInstance } from "../../../user/entities/user";
|
|
||||||
import {
|
import {
|
||||||
ApplicationObject,
|
ApplicationObject,
|
||||||
getApplicationObject,
|
getApplicationObject,
|
||||||
@@ -21,6 +20,7 @@ import {
|
|||||||
ApplicationLoginResponse,
|
ApplicationLoginResponse,
|
||||||
ConfigureRequest,
|
ConfigureRequest,
|
||||||
} from "../types";
|
} from "../types";
|
||||||
|
import { ConsoleHookUser } from "src/services/console/types";
|
||||||
|
|
||||||
export class ApplicationsApiController {
|
export class ApplicationsApiController {
|
||||||
async token(
|
async token(
|
||||||
@@ -175,37 +175,15 @@ export class ApplicationsApiController {
|
|||||||
};
|
};
|
||||||
}>,
|
}>,
|
||||||
): Promise<any> {
|
): Promise<any> {
|
||||||
const email = request.body.email.trim().toLocaleLowerCase();
|
|
||||||
|
|
||||||
if (await gr.services.users.getByEmail(email)) {
|
|
||||||
throw new Error("This email is already used");
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const newUser = getInstance({
|
await gr.services.console.getClient().updateLocalUserFromConsole({
|
||||||
first_name: request.body.first_name,
|
email: request.body.email.trim().toLocaleLowerCase(),
|
||||||
last_name: request.body.last_name,
|
name: request.body.first_name,
|
||||||
email_canonical: email,
|
surname: request.body.last_name,
|
||||||
username_canonical: (email.replace("@", ".") || "").toLocaleLowerCase(),
|
} as ConsoleHookUser);
|
||||||
phone: "",
|
|
||||||
identity_provider: "console",
|
|
||||||
identity_provider_id: email,
|
|
||||||
mail_verified: true,
|
|
||||||
});
|
|
||||||
const user = await gr.services.users.create(newUser);
|
|
||||||
|
|
||||||
const company = await gr.services.companies.getCompany({
|
|
||||||
id: "00000000-0000-4000-0000-000000000000",
|
|
||||||
});
|
|
||||||
|
|
||||||
await gr.services.companies.setUserRole(company.id, user.entity.id, "member");
|
|
||||||
|
|
||||||
await gr.services.users.save(user.entity, {
|
|
||||||
user: { id: user.entity.id, server_request: true },
|
|
||||||
});
|
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
logger.error(err);
|
logger.error(err);
|
||||||
throw new Error("An unknown error occured");
|
throw err;
|
||||||
}
|
}
|
||||||
return {};
|
return {};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -99,12 +99,13 @@ export class ConsoleRemoteClient implements ConsoleServiceClient {
|
|||||||
throw CrudException.badRequest("User not found on Console");
|
throw CrudException.badRequest("User not found on Console");
|
||||||
}
|
}
|
||||||
|
|
||||||
const roles = userDTO.roles.filter(
|
if (userDTO.roles) {
|
||||||
role => role.applications === undefined || role.applications.find(a => a.code === "tdrive"),
|
const roles = userDTO.roles.filter(
|
||||||
);
|
role => role.applications === undefined || role.applications.find(a => a.code === "tdrive"),
|
||||||
|
);
|
||||||
//REMOVE LATER
|
//REMOVE LATER
|
||||||
logger.info(`Roles are: ${roles}.`);
|
logger.info(`Roles are: ${roles}.`);
|
||||||
|
}
|
||||||
|
|
||||||
let user = await gr.services.users.getByConsoleId(userDTO.email);
|
let user = await gr.services.users.getByConsoleId(userDTO.email);
|
||||||
|
|
||||||
@@ -151,7 +152,9 @@ export class ConsoleRemoteClient implements ConsoleServiceClient {
|
|||||||
user.preferences.timezone = coalesce(userDTO.preference.timeZone, user.preferences?.timezone);
|
user.preferences.timezone = coalesce(userDTO.preference.timeZone, user.preferences?.timezone);
|
||||||
}
|
}
|
||||||
|
|
||||||
user.picture = userDTO.avatar.value;
|
if (userDTO.avatar) {
|
||||||
|
user.picture = userDTO.avatar.value;
|
||||||
|
}
|
||||||
|
|
||||||
await gr.services.users.save(user);
|
await gr.services.users.save(user);
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import ldap from "ldapjs";
|
import ldap, { SearchEntry } from "ldapjs";
|
||||||
import axios, { AxiosError } from "axios";
|
import axios, { AxiosError } from "axios";
|
||||||
import dotenv from "dotenv";
|
import dotenv from "dotenv";
|
||||||
|
|
||||||
@@ -119,14 +119,14 @@ client.bind(ldapConfig.bindDN, ldapConfig.bindCredentials, (err) => {
|
|||||||
|
|
||||||
const apiRequests: Promise<any>[] = [];
|
const apiRequests: Promise<any>[] = [];
|
||||||
|
|
||||||
searchRes.on("searchEntry", (entry: any) => {
|
searchRes.on("searchEntry", (entry: SearchEntry) => {
|
||||||
console.log('Receive entry:: ' + JSON.stringify(entry.pojo));
|
console.log('Receive entry:: ' + JSON.stringify(entry.attributes));
|
||||||
|
|
||||||
// Handle each search result entry
|
// Handle each search result entry
|
||||||
const userAttributes: UserAttributes = {
|
const userAttributes: UserAttributes = {
|
||||||
first_name: entry.attributes[0]?.values[0],
|
first_name: entry.attributes.find(a=> a.type == ldapConfig.mappings.firstName)?.vals[0]!,
|
||||||
last_name: entry.attributes[1]?.values[0],
|
last_name: entry.attributes.find(a=> a.type == ldapConfig.mappings.lastName)?.vals[0]!,
|
||||||
email: entry.attributes[2]?.values[0],
|
email: entry.attributes.find(a=> a.type == ldapConfig.mappings.email)?.vals[0]!,
|
||||||
};
|
};
|
||||||
|
|
||||||
if (userAttributes.email) {
|
if (userAttributes.email) {
|
||||||
|
|||||||
Reference in New Issue
Block a user