|
| 1 | +'use strict' |
| 2 | + |
| 3 | +const Router = require('express').Router |
| 4 | +const passport = require('passport') |
| 5 | +const SamlStrategy = require('passport-saml').Strategy |
| 6 | +const config = require('../../../config') |
| 7 | +const models = require('../../../models') |
| 8 | +const logger = require('../../../logger') |
| 9 | +const {urlencodedParser} = require('../../utils') |
| 10 | +const fs = require('fs') |
| 11 | +const intersection = function (array1, array2) { return array1.filter((n) => array2.includes(n)) } |
| 12 | + |
| 13 | +let samlAuth = module.exports = Router() |
| 14 | + |
| 15 | +passport.use(new SamlStrategy({ |
| 16 | + callbackUrl: config.saml.callbackUrl || config.serverurl + '/auth/saml/callback', |
| 17 | + entryPoint: config.saml.idpSsoUrl, |
| 18 | + issuer: config.saml.issuer || config.serverurl, |
| 19 | + cert: fs.readFileSync(config.saml.idpCert, 'utf-8'), |
| 20 | + identifierFormat: config.saml.identifierFormat |
| 21 | +}, function (user, done) { |
| 22 | + // check authorization if needed |
| 23 | + if (config.saml.externalGroups && config.saml.grouptAttribute) { |
| 24 | + var externalGroups = intersection(config.saml.externalGroups, user[config.saml.groupAttribute]) |
| 25 | + if (externalGroups.length > 0) { |
| 26 | + logger.error('saml permission denied: ' + externalGroups.join(', ')) |
| 27 | + return done('Permission denied', null) |
| 28 | + } |
| 29 | + } |
| 30 | + if (config.saml.requiredGroups && config.saml.grouptAttribute) { |
| 31 | + if (intersection(config.saml.requiredGroups, user[config.saml.groupAttribute]).length === 0) { |
| 32 | + logger.error('saml permission denied') |
| 33 | + return done('Permission denied', null) |
| 34 | + } |
| 35 | + } |
| 36 | + // user creation |
| 37 | + var uuid = user[config.saml.attribute.id] || user.nameID |
| 38 | + var profile = { |
| 39 | + provider: 'saml', |
| 40 | + id: 'SAML-' + uuid, |
| 41 | + username: user[config.saml.attribute.username] || user.nameID, |
| 42 | + displayName: user[config.saml.attribute.displayName] || user.nameID, |
| 43 | + emails: user[config.saml.attribute.email] ? [user[config.saml.attribute.email]] : [] |
| 44 | + } |
| 45 | + if (profile.emails.length === 0 && config.saml.identifierFormat === 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress') { |
| 46 | + profile.emails.push(user.nameID) |
| 47 | + } |
| 48 | + var stringifiedProfile = JSON.stringify(profile) |
| 49 | + models.User.findOrCreate({ |
| 50 | + where: { |
| 51 | + profileid: profile.id.toString() |
| 52 | + }, |
| 53 | + defaults: { |
| 54 | + profile: stringifiedProfile |
| 55 | + } |
| 56 | + }).spread(function (user, created) { |
| 57 | + if (user) { |
| 58 | + var needSave = false |
| 59 | + if (user.profile !== stringifiedProfile) { |
| 60 | + user.profile = stringifiedProfile |
| 61 | + needSave = true |
| 62 | + } |
| 63 | + if (needSave) { |
| 64 | + user.save().then(function () { |
| 65 | + if (config.debug) { logger.debug('user login: ' + user.id) } |
| 66 | + return done(null, user) |
| 67 | + }) |
| 68 | + } else { |
| 69 | + if (config.debug) { logger.debug('user login: ' + user.id) } |
| 70 | + return done(null, user) |
| 71 | + } |
| 72 | + } |
| 73 | + }).catch(function (err) { |
| 74 | + logger.error('saml auth failed: ' + err) |
| 75 | + return done(err, null) |
| 76 | + }) |
| 77 | +})) |
| 78 | + |
| 79 | +samlAuth.get('/auth/saml', |
| 80 | + passport.authenticate('saml', { |
| 81 | + successReturnToOrRedirect: config.serverurl + '/', |
| 82 | + failureRedirect: config.serverurl + '/' |
| 83 | + }) |
| 84 | +) |
| 85 | + |
| 86 | +samlAuth.post('/auth/saml/callback', urlencodedParser, |
| 87 | + passport.authenticate('saml', { |
| 88 | + successReturnToOrRedirect: config.serverurl + '/', |
| 89 | + failureRedirect: config.serverurl + '/' |
| 90 | + }) |
| 91 | +) |
| 92 | + |
| 93 | +samlAuth.get('/auth/saml/metadata', function (req, res) { |
| 94 | + res.type('application/xml') |
| 95 | + res.send(passport._strategy('saml').generateServiceProviderMetadata()) |
| 96 | +}) |
0 commit comments