mirror of
https://github.com/fosrl/pangolin.git
synced 2026-08-13 16:00:02 +02:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 501e9226aa |
@@ -77,7 +77,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
- name: Log in to Docker Hub
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: docker.io
|
registry: docker.io
|
||||||
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
||||||
@@ -149,7 +149,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
- name: Log in to Docker Hub
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: docker.io
|
registry: docker.io
|
||||||
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
||||||
@@ -204,7 +204,7 @@ jobs:
|
|||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
- name: Log in to Docker Hub
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: docker.io
|
registry: docker.io
|
||||||
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
||||||
@@ -407,7 +407,7 @@ jobs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
|
|
||||||
- name: Login to GitHub Container Registry (for cosign)
|
- name: Login to GitHub Container Registry (for cosign)
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
username: ${{ github.actor }}
|
username: ${{ github.actor }}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ jobs:
|
|||||||
stale:
|
stale:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@1e223db275d687790206a7acac4d1a11bd6fe629 # v10.4.0
|
- uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 # v11.0.0
|
||||||
with:
|
with:
|
||||||
days-before-stale: 14
|
days-before-stale: 14
|
||||||
days-before-close: 14
|
days-before-close: 14
|
||||||
|
|||||||
+2
-2
@@ -1,5 +1,5 @@
|
|||||||
# FROM node:24-slim AS base
|
# FROM node:24-slim AS base
|
||||||
FROM public.ecr.aws/docker/library/node:26-slim AS base
|
FROM public.ecr.aws/docker/library/node:24-slim AS base
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
@@ -33,7 +33,7 @@ FROM base AS builder
|
|||||||
RUN npm ci --omit=dev
|
RUN npm ci --omit=dev
|
||||||
|
|
||||||
# FROM node:24-slim AS runner
|
# FROM node:24-slim AS runner
|
||||||
FROM public.ecr.aws/docker/library/node:26-slim AS runner
|
FROM public.ecr.aws/docker/library/node:24-slim AS runner
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
FROM node:26-alpine
|
FROM node:24-alpine
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
|||||||
@@ -43,8 +43,6 @@
|
|||||||
"inviteLoginUser": "Please make sure you're logged in as the correct user.",
|
"inviteLoginUser": "Please make sure you're logged in as the correct user.",
|
||||||
"inviteErrorNoUser": "We're sorry, but it looks like the invite you're trying to access is not for a user that exists.",
|
"inviteErrorNoUser": "We're sorry, but it looks like the invite you're trying to access is not for a user that exists.",
|
||||||
"inviteCreateUser": "Please create an account first.",
|
"inviteCreateUser": "Please create an account first.",
|
||||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
|
||||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
|
||||||
"goHome": "Go Home",
|
"goHome": "Go Home",
|
||||||
"inviteLogInOtherUser": "Log In as a Different User",
|
"inviteLogInOtherUser": "Log In as a Different User",
|
||||||
"createAnAccount": "Create an Account",
|
"createAnAccount": "Create an Account",
|
||||||
@@ -1451,11 +1449,8 @@
|
|||||||
"actionSetResourcePincode": "Set Resource Pincode",
|
"actionSetResourcePincode": "Set Resource Pincode",
|
||||||
"actionSetResourceEmailWhitelist": "Set Resource Email Whitelist",
|
"actionSetResourceEmailWhitelist": "Set Resource Email Whitelist",
|
||||||
"actionGetResourceEmailWhitelist": "Get Resource Email Whitelist",
|
"actionGetResourceEmailWhitelist": "Get Resource Email Whitelist",
|
||||||
"actionListResourcePolicies": "List Resource Policies",
|
|
||||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
|
||||||
"actionGetResourcePolicy": "Get Resource Policy",
|
"actionGetResourcePolicy": "Get Resource Policy",
|
||||||
"actionUpdateResourcePolicy": "Update Resource Policy",
|
"actionUpdateResourcePolicy": "Update Resource Policy",
|
||||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
|
||||||
"actionSetResourcePolicyUsers": "Set Resource Policy Users",
|
"actionSetResourcePolicyUsers": "Set Resource Policy Users",
|
||||||
"actionSetResourcePolicyRoles": "Set Resource Policy Roles",
|
"actionSetResourcePolicyRoles": "Set Resource Policy Roles",
|
||||||
"actionSetResourcePolicyPassword": "Set Resource Policy Password",
|
"actionSetResourcePolicyPassword": "Set Resource Policy Password",
|
||||||
|
|||||||
@@ -95,8 +95,7 @@ export const subscriptions = pgTable("subscriptions", {
|
|||||||
billingCycleAnchor: bigint("billingCycleAnchor", { mode: "number" }),
|
billingCycleAnchor: bigint("billingCycleAnchor", { mode: "number" }),
|
||||||
expiresAt: bigint("expiresAt", { mode: "number" }),
|
expiresAt: bigint("expiresAt", { mode: "number" }),
|
||||||
trial: boolean("trial").default(false),
|
trial: boolean("trial").default(false),
|
||||||
type: varchar("type", { length: 50 }), // tier1, tier2, tier3, or license
|
type: varchar("type", { length: 50 }) // tier1, tier2, tier3, or license
|
||||||
override: boolean("override").default(false)
|
|
||||||
});
|
});
|
||||||
|
|
||||||
export const subscriptionItems = pgTable("subscriptionItems", {
|
export const subscriptionItems = pgTable("subscriptionItems", {
|
||||||
|
|||||||
@@ -89,8 +89,7 @@ export const subscriptions = sqliteTable("subscriptions", {
|
|||||||
expiresAt: integer("expiresAt"),
|
expiresAt: integer("expiresAt"),
|
||||||
trial: integer("trial", { mode: "boolean" }).default(false),
|
trial: integer("trial", { mode: "boolean" }).default(false),
|
||||||
billingCycleAnchor: integer("billingCycleAnchor"),
|
billingCycleAnchor: integer("billingCycleAnchor"),
|
||||||
type: text("type"), // tier1, tier2, tier3, or license
|
type: text("type") // tier1, tier2, tier3, or license
|
||||||
override: integer("override", { mode: "boolean" }).default(false)
|
|
||||||
});
|
});
|
||||||
|
|
||||||
export const subscriptionItems = sqliteTable("subscriptionItems", {
|
export const subscriptionItems = sqliteTable("subscriptionItems", {
|
||||||
|
|||||||
@@ -632,6 +632,7 @@ export const ResourcePolicySchema = z.object({
|
|||||||
})
|
})
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
.max(50)
|
||||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||||
.optional()
|
.optional()
|
||||||
.default([]),
|
.default([]),
|
||||||
|
|||||||
@@ -1,9 +1,8 @@
|
|||||||
import { db, idp, idpOrg, Transaction } from "@server/db";
|
import { db, idp, idpOrg, Transaction } from "@server/db";
|
||||||
import { and, eq } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { build } from "@server/build";
|
|
||||||
|
|
||||||
export function isOrgIdentityProviderMode(): boolean {
|
export function isOrgIdentityProviderMode(): boolean {
|
||||||
return build === "saas" || process.env.IDENTITY_PROVIDER_MODE === "org";
|
return process.env.IDENTITY_PROVIDER_MODE === "org";
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -53,15 +53,6 @@ export async function handleSubscriptionDeleted(
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
// If the subscription has been manually overridden, we lock it down
|
|
||||||
// so Stripe can no longer change (or delete) its status locally.
|
|
||||||
if (existingSubscription.override === true) {
|
|
||||||
logger.info(
|
|
||||||
`Subscription ${subscription.id} is locked (override=true). Ignoring deletion event from Stripe.`
|
|
||||||
);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
await db
|
await db
|
||||||
.delete(subscriptions)
|
.delete(subscriptions)
|
||||||
.where(eq(subscriptions.subscriptionId, subscription.id));
|
.where(eq(subscriptions.subscriptionId, subscription.id));
|
||||||
|
|||||||
@@ -68,27 +68,13 @@ export async function handleSubscriptionUpdated(
|
|||||||
const type = getSubType(fullSubscription);
|
const type = getSubType(fullSubscription);
|
||||||
const previousType = existingSubscription.type as SubscriptionType | null;
|
const previousType = existingSubscription.type as SubscriptionType | null;
|
||||||
|
|
||||||
// If the subscription has been manually overridden, we lock the
|
|
||||||
// status down so Stripe webhooks can no longer change it.
|
|
||||||
const isLocked = existingSubscription.override === true;
|
|
||||||
if (isLocked) {
|
|
||||||
logger.info(
|
|
||||||
`Subscription ${subscription.id} is locked (override=true). Ignoring status change from Stripe (would have been ${subscription.status}).`
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const effectiveStatus = isLocked
|
|
||||||
? existingSubscription.status
|
|
||||||
: subscription.status;
|
|
||||||
|
|
||||||
await db
|
await db
|
||||||
.update(subscriptions)
|
.update(subscriptions)
|
||||||
.set({
|
.set({
|
||||||
status: effectiveStatus,
|
status: subscription.status,
|
||||||
canceledAt: isLocked
|
canceledAt: subscription.canceled_at
|
||||||
? existingSubscription.canceledAt
|
? subscription.canceled_at
|
||||||
: subscription.canceled_at
|
: null,
|
||||||
? subscription.canceled_at
|
|
||||||
: null,
|
|
||||||
updatedAt: Math.floor(Date.now() / 1000),
|
updatedAt: Math.floor(Date.now() / 1000),
|
||||||
billingCycleAnchor: subscription.billing_cycle_anchor,
|
billingCycleAnchor: subscription.billing_cycle_anchor,
|
||||||
type: type
|
type: type
|
||||||
@@ -289,23 +275,23 @@ export async function handleSubscriptionUpdated(
|
|||||||
// we only need to handle the limit lifecycle for saas subscriptions not for the licenses
|
// we only need to handle the limit lifecycle for saas subscriptions not for the licenses
|
||||||
await handleSubscriptionLifesycle(
|
await handleSubscriptionLifesycle(
|
||||||
customer.orgId,
|
customer.orgId,
|
||||||
effectiveStatus,
|
subscription.status,
|
||||||
type
|
type
|
||||||
);
|
);
|
||||||
|
|
||||||
// Handle feature lifecycle when subscription is canceled or becomes unpaid
|
// Handle feature lifecycle when subscription is canceled or becomes unpaid
|
||||||
if (
|
if (
|
||||||
effectiveStatus === "canceled" ||
|
subscription.status === "canceled" ||
|
||||||
effectiveStatus === "unpaid" ||
|
subscription.status === "unpaid" ||
|
||||||
effectiveStatus === "incomplete_expired"
|
subscription.status === "incomplete_expired"
|
||||||
) {
|
) {
|
||||||
logger.info(
|
logger.info(
|
||||||
`Subscription ${subscription.id} for org ${customer.orgId} is ${effectiveStatus}, disabling paid features`
|
`Subscription ${subscription.id} for org ${customer.orgId} is ${subscription.status}, disabling paid features`
|
||||||
);
|
);
|
||||||
await handleTierChange(customer.orgId, null, previousType ?? undefined);
|
await handleTierChange(customer.orgId, null, previousType ?? undefined);
|
||||||
}
|
}
|
||||||
} else if (type === "license") {
|
} else if (type === "license") {
|
||||||
if (effectiveStatus === "canceled" || effectiveStatus == "unpaid" || effectiveStatus == "incomplete_expired") {
|
if (subscription.status === "canceled" || subscription.status == "unpaid" || subscription.status == "incomplete_expired") {
|
||||||
try {
|
try {
|
||||||
// WARNING:
|
// WARNING:
|
||||||
// this invalidates ALL OF THE ENTERPRISE LICENSES for this orgId
|
// this invalidates ALL OF THE ENTERPRISE LICENSES for this orgId
|
||||||
|
|||||||
@@ -107,6 +107,7 @@ const createResourcePolicyBodySchema = z.strictObject({
|
|||||||
})
|
})
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
.max(50)
|
||||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||||
.optional()
|
.optional()
|
||||||
.default([]),
|
.default([]),
|
||||||
|
|||||||
@@ -726,8 +726,8 @@ authenticated.post(
|
|||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyUsers),
|
verifyUserHasAction(ActionsEnum.setResourcePolicyUsers),
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyRoles),
|
verifyUserHasAction(ActionsEnum.setResourcePolicyRoles),
|
||||||
logActionAudit(ActionsEnum.setResourcePolicyUsers),
|
logActionAudit(ActionsEnum.setResourcePolicyUsers),
|
||||||
logActionAudit(ActionsEnum.setResourcePolicyRoles),
|
logActionAudit(ActionsEnum.setResourcePolicyRoles),
|
||||||
policy.setResourcePolicyAccessControl
|
policy.setResourcePolicyAccessControl
|
||||||
@@ -742,8 +742,8 @@ authenticated.put(
|
|||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyUsers),
|
verifyUserHasAction(ActionsEnum.setResourcePolicyUsers),
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyRoles),
|
verifyUserHasAction(ActionsEnum.setResourcePolicyRoles),
|
||||||
logActionAudit(ActionsEnum.setResourcePolicyUsers),
|
logActionAudit(ActionsEnum.setResourcePolicyUsers),
|
||||||
logActionAudit(ActionsEnum.setResourcePolicyRoles),
|
logActionAudit(ActionsEnum.setResourcePolicyRoles),
|
||||||
policy.setResourcePolicyAccessControl
|
policy.setResourcePolicyAccessControl
|
||||||
|
|||||||
@@ -19,6 +19,7 @@ const setResourcePolicyWhitelistBodySchema = z.strictObject({
|
|||||||
})
|
})
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
.max(50)
|
||||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -24,6 +24,7 @@ const setResourceWhitelistBodySchema = z.strictObject({
|
|||||||
})
|
})
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
.max(50)
|
||||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ import { calculateUserClientsForOrgs } from "@server/lib/calculateUserClientsFor
|
|||||||
import { build } from "@server/build";
|
import { build } from "@server/build";
|
||||||
import { assignUserToOrg } from "@server/lib/userOrg";
|
import { assignUserToOrg } from "@server/lib/userOrg";
|
||||||
import { isOrgRebuildRateLimited } from "@server/lib/rebuildClientAssociations";
|
import { isOrgRebuildRateLimited } from "@server/lib/rebuildClientAssociations";
|
||||||
import { UserType } from "@server/types/UserTypes";
|
|
||||||
|
|
||||||
const acceptInviteBodySchema = z.strictObject({
|
const acceptInviteBodySchema = z.strictObject({
|
||||||
token: z.string(),
|
token: z.string(),
|
||||||
@@ -67,17 +66,12 @@ export async function acceptInvite(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
const [existingInternalUser] = await db
|
const existingUser = await db
|
||||||
.select()
|
.select()
|
||||||
.from(users)
|
.from(users)
|
||||||
.where(
|
.where(eq(users.email, existingInvite.email))
|
||||||
and(
|
|
||||||
eq(users.email, existingInvite.email),
|
|
||||||
eq(users.type, UserType.Internal)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
.limit(1);
|
.limit(1);
|
||||||
if (!existingInternalUser) {
|
if (!existingUser.length) {
|
||||||
return next(
|
return next(
|
||||||
createHttpError(
|
createHttpError(
|
||||||
HttpCode.BAD_REQUEST,
|
HttpCode.BAD_REQUEST,
|
||||||
@@ -86,8 +80,9 @@ export async function acceptInvite(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
const { user } = await verifySession(req);
|
const { user, session } = await verifySession(req);
|
||||||
|
|
||||||
|
// at this point we know the user exists
|
||||||
if (!user) {
|
if (!user) {
|
||||||
return next(
|
return next(
|
||||||
createHttpError(
|
createHttpError(
|
||||||
@@ -97,7 +92,7 @@ export async function acceptInvite(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (user.email !== existingInvite.email) {
|
if (user && user.email !== existingInvite.email) {
|
||||||
return next(
|
return next(
|
||||||
createHttpError(
|
createHttpError(
|
||||||
HttpCode.BAD_REQUEST,
|
HttpCode.BAD_REQUEST,
|
||||||
@@ -106,15 +101,6 @@ export async function acceptInvite(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (user.type !== UserType.Internal) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invites can only be accepted by internal users."
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (build == "saas") {
|
if (build == "saas") {
|
||||||
const usage = await usageService.getUsage(
|
const usage = await usageService.getUsage(
|
||||||
existingInvite.orgId,
|
existingInvite.orgId,
|
||||||
@@ -209,7 +195,7 @@ export async function acceptInvite(
|
|||||||
await assignUserToOrg(
|
await assignUserToOrg(
|
||||||
org,
|
org,
|
||||||
{
|
{
|
||||||
userId: user.userId,
|
userId: existingUser[0].userId,
|
||||||
orgId: existingInvite.orgId
|
orgId: existingInvite.orgId
|
||||||
},
|
},
|
||||||
inviteRoleIds,
|
inviteRoleIds,
|
||||||
@@ -222,13 +208,13 @@ export async function acceptInvite(
|
|||||||
.where(eq(userInvites.inviteId, inviteId));
|
.where(eq(userInvites.inviteId, inviteId));
|
||||||
|
|
||||||
logger.debug(
|
logger.debug(
|
||||||
`User ${user.userId} accepted invite to org ${existingInvite.orgId}`
|
`User ${existingUser[0].userId} accepted invite to org ${existingInvite.orgId}`
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
calculateUserClientsForOrgs(user.userId).catch((e) => {
|
calculateUserClientsForOrgs(existingUser[0].userId).catch((e) => {
|
||||||
logger.error(
|
logger.error(
|
||||||
`Failed to calculate user clients after accepting invite for user ${user.userId}: ${e}`
|
`Failed to calculate user clients after accepting invite for user ${existingUser[0].userId}: ${e}`
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -20,7 +20,6 @@ import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
|||||||
import { assignUserToOrg } from "@server/lib/userOrg";
|
import { assignUserToOrg } from "@server/lib/userOrg";
|
||||||
import { isLicensedOrSubscribed } from "#dynamic/lib/isLicencedOrSubscribed";
|
import { isLicensedOrSubscribed } from "#dynamic/lib/isLicencedOrSubscribed";
|
||||||
import { isOrgRebuildRateLimited } from "@server/lib/rebuildClientAssociations";
|
import { isOrgRebuildRateLimited } from "@server/lib/rebuildClientAssociations";
|
||||||
import { idpExistsForOrg } from "@server/lib/idp/idpExistsForOrg";
|
|
||||||
|
|
||||||
const paramsSchema = z.strictObject({
|
const paramsSchema = z.strictObject({
|
||||||
orgId: z.string().nonempty()
|
orgId: z.string().nonempty()
|
||||||
@@ -240,16 +239,6 @@ export async function createOrgUser(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
const providerExists = await idpExistsForOrg(idpId, orgId);
|
|
||||||
if (!providerExists) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Identity provider not found in this organization"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const [idpRes] = await db
|
const [idpRes] = await db
|
||||||
.select()
|
.select()
|
||||||
.from(idp)
|
.from(idp)
|
||||||
|
|||||||
@@ -107,7 +107,7 @@ const listUsersSchema = z.strictObject({
|
|||||||
.filter((n) => Number.isInteger(n) && n > 0);
|
.filter((n) => Number.isInteger(n) && n > 0);
|
||||||
const unique = [...new Set(nums)];
|
const unique = [...new Set(nums)];
|
||||||
return unique.length ? unique : undefined;
|
return unique.length ? unique : undefined;
|
||||||
}, z.array(z.number().int().positive()).optional())
|
}, z.array(z.number().int().positive()).max(50).optional())
|
||||||
.openapi({
|
.openapi({
|
||||||
description:
|
description:
|
||||||
"Filter users who have any of these role ids in the organization (repeat query param)"
|
"Filter users who have any of these role ids in the organization (repeat query param)"
|
||||||
|
|||||||
+1
-1
@@ -181,7 +181,7 @@ export default function NetworkingPage() {
|
|||||||
<SettingsSectionDescription>
|
<SettingsSectionDescription>
|
||||||
{t("remoteExitNodeNetworkingDescription")}
|
{t("remoteExitNodeNetworkingDescription")}
|
||||||
<a
|
<a
|
||||||
href="https://docs.pangolin.net/manage/remote-node/backhaul"
|
href="https://docs.pangolin.net/placeholder"
|
||||||
target="_blank"
|
target="_blank"
|
||||||
rel="noopener noreferrer"
|
rel="noopener noreferrer"
|
||||||
className="text-primary hover:underline inline-flex items-center gap-1"
|
className="text-primary hover:underline inline-flex items-center gap-1"
|
||||||
|
|||||||
@@ -38,6 +38,18 @@ import { useEffect, useState } from "react";
|
|||||||
import { useForm } from "react-hook-form";
|
import { useForm } from "react-hook-form";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
|
const accessControlsFormSchema = z.object({
|
||||||
|
username: z.string(),
|
||||||
|
autoProvisioned: z.boolean(),
|
||||||
|
roles: z.array(
|
||||||
|
z.object({
|
||||||
|
id: z.string(),
|
||||||
|
text: z.string(),
|
||||||
|
isAdmin: z.boolean().optional()
|
||||||
|
})
|
||||||
|
)
|
||||||
|
});
|
||||||
|
|
||||||
export default function AccessControlsPage() {
|
export default function AccessControlsPage() {
|
||||||
const { orgUser: user, updateOrgUser } = userOrgUserContext();
|
const { orgUser: user, updateOrgUser } = userOrgUserContext();
|
||||||
const { user: sessionUser } = useUserContext();
|
const { user: sessionUser } = useUserContext();
|
||||||
@@ -57,20 +69,6 @@ export default function AccessControlsPage() {
|
|||||||
(build === "enterprise" && !isPaid) ||
|
(build === "enterprise" && !isPaid) ||
|
||||||
(build === "oss" && !isPaid));
|
(build === "oss" && !isPaid));
|
||||||
|
|
||||||
const accessControlsFormSchema = z.object({
|
|
||||||
username: z.string(),
|
|
||||||
autoProvisioned: z.boolean(),
|
|
||||||
roles: z
|
|
||||||
.array(
|
|
||||||
z.object({
|
|
||||||
id: z.string(),
|
|
||||||
text: z.string(),
|
|
||||||
isAdmin: z.boolean().optional()
|
|
||||||
})
|
|
||||||
)
|
|
||||||
.min(1, { message: t("accessRoleSelectPlease") })
|
|
||||||
});
|
|
||||||
|
|
||||||
const form = useForm({
|
const form = useForm({
|
||||||
resolver: zodResolver(accessControlsFormSchema),
|
resolver: zodResolver(accessControlsFormSchema),
|
||||||
defaultValues: {
|
defaultValues: {
|
||||||
@@ -110,6 +108,15 @@ export default function AccessControlsPage() {
|
|||||||
async function executeSave() {
|
async function executeSave() {
|
||||||
const values = form.getValues();
|
const values = form.getValues();
|
||||||
|
|
||||||
|
if (values.roles.length === 0) {
|
||||||
|
toast({
|
||||||
|
variant: "destructive",
|
||||||
|
title: t("accessRoleRequired"),
|
||||||
|
description: t("accessRoleSelectPlease")
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
setIsSaving(true);
|
setIsSaving(true);
|
||||||
try {
|
try {
|
||||||
const roleIds = values.roles.map((r) => parseInt(r.id, 10));
|
const roleIds = values.roles.map((r) => parseInt(r.id, 10));
|
||||||
@@ -163,6 +170,15 @@ export default function AccessControlsPage() {
|
|||||||
|
|
||||||
const values = form.getValues();
|
const values = form.getValues();
|
||||||
|
|
||||||
|
if (values.roles.length === 0) {
|
||||||
|
toast({
|
||||||
|
variant: "destructive",
|
||||||
|
title: t("accessRoleRequired"),
|
||||||
|
description: t("accessRoleSelectPlease")
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
const willHaveAdminRole = values.roles.some((r) => r.isAdmin === true);
|
const willHaveAdminRole = values.roles.some((r) => r.isAdmin === true);
|
||||||
|
|
||||||
const isRemovingOwnAdmin =
|
const isRemovingOwnAdmin =
|
||||||
|
|||||||
@@ -237,13 +237,10 @@ export default function Page() {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
const useOrgIdps =
|
|
||||||
build === "saas" || env.app.identityProviderMode === "org";
|
|
||||||
|
|
||||||
const res = await api
|
const res = await api
|
||||||
.get<
|
.get<
|
||||||
AxiosResponse<ListIdpsResponse>
|
AxiosResponse<ListIdpsResponse>
|
||||||
>(useOrgIdps ? `/org/${orgId}/idp` : "/idp")
|
>(build === "saas" ? `/org/${orgId}/idp` : "/idp")
|
||||||
.catch((e) => {
|
.catch((e) => {
|
||||||
console.error(e);
|
console.error(e);
|
||||||
toast({
|
toast({
|
||||||
@@ -304,7 +301,8 @@ export default function Page() {
|
|||||||
);
|
);
|
||||||
const [isSubmittingExternal, setIsSubmittingExternal] = useState(false);
|
const [isSubmittingExternal, setIsSubmittingExternal] = useState(false);
|
||||||
|
|
||||||
const loading = isSubmittingInternal || isSubmittingExternal;
|
const loading =
|
||||||
|
isSubmittingInternal || isSubmittingExternal;
|
||||||
|
|
||||||
async function onSubmitInternal() {
|
async function onSubmitInternal() {
|
||||||
const isValid = await internalForm.trigger();
|
const isValid = await internalForm.trigger();
|
||||||
|
|||||||
@@ -193,10 +193,7 @@ export default async function Page(props: {
|
|||||||
redirect={redirectUrl}
|
redirect={redirectUrl}
|
||||||
forceLogin={forceLogin}
|
forceLogin={forceLogin}
|
||||||
defaultUser={defaultUser}
|
defaultUser={defaultUser}
|
||||||
inviteMode={isInvite}
|
lastUsedIdp={lastUsedIdpForSmartLogin}
|
||||||
lastUsedIdp={
|
|
||||||
isInvite ? null : lastUsedIdpForSmartLogin
|
|
||||||
}
|
|
||||||
orgSignIn={
|
orgSignIn={
|
||||||
!isInvite &&
|
!isInvite &&
|
||||||
(build === "saas" ||
|
(build === "saas" ||
|
||||||
@@ -216,7 +213,7 @@ export default async function Page(props: {
|
|||||||
) : (
|
) : (
|
||||||
<DashboardLoginForm
|
<DashboardLoginForm
|
||||||
redirect={redirectUrl}
|
redirect={redirectUrl}
|
||||||
idps={isInvite ? [] : loginIdps}
|
idps={loginIdps}
|
||||||
forceLogin={forceLogin}
|
forceLogin={forceLogin}
|
||||||
showOrgLogin={
|
showOrgLogin={
|
||||||
!isInvite &&
|
!isInvite &&
|
||||||
|
|||||||
@@ -53,7 +53,7 @@ import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
|||||||
import { usePaidStatus } from "@/hooks/usePaidStatus";
|
import { usePaidStatus } from "@/hooks/usePaidStatus";
|
||||||
import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
||||||
import { toUnicode } from "punycode";
|
import { toUnicode } from "punycode";
|
||||||
import { useCallback, useEffect, useMemo, useRef, useState } from "react";
|
import { useCallback, useEffect, useMemo, useState } from "react";
|
||||||
import { useUserContext } from "@app/hooks/useUserContext";
|
import { useUserContext } from "@app/hooks/useUserContext";
|
||||||
|
|
||||||
type AvailableOption = {
|
type AvailableOption = {
|
||||||
@@ -166,19 +166,8 @@ export default function DomainPicker({
|
|||||||
const [selectedProvidedDomain, setSelectedProvidedDomain] =
|
const [selectedProvidedDomain, setSelectedProvidedDomain] =
|
||||||
useState<AvailableOption | null>(null);
|
useState<AvailableOption | null>(null);
|
||||||
|
|
||||||
// Only run the initial base-domain selection once the domains have
|
|
||||||
// loaded. This must not re-run on later `defaultDomainId`/`defaultSubdomain`
|
|
||||||
// changes, because selecting a provided (namespace) domain calls
|
|
||||||
// onDomainChange(null), which the parent form echoes back as
|
|
||||||
// defaultDomainId/defaultSubdomain becoming undefined — re-running this
|
|
||||||
// effect on that change would immediately snap the selector back to the
|
|
||||||
// organization domain, making provided domains unselectable whenever one
|
|
||||||
// was already set.
|
|
||||||
const didSelectInitialDomainRef = useRef(false);
|
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (!loadingDomains && !didSelectInitialDomainRef.current) {
|
if (!loadingDomains) {
|
||||||
didSelectInitialDomainRef.current = true;
|
|
||||||
let domainOptionToSelect: DomainOption | null = null;
|
let domainOptionToSelect: DomainOption | null = null;
|
||||||
if (organizationDomains.length > 0) {
|
if (organizationDomains.length > 0) {
|
||||||
// Select the first organization domain or the one provided from props
|
// Select the first organization domain or the one provided from props
|
||||||
|
|||||||
@@ -44,7 +44,6 @@ export default function InviteStatusCard({
|
|||||||
| "user_does_not_exist"
|
| "user_does_not_exist"
|
||||||
| "not_logged_in"
|
| "not_logged_in"
|
||||||
| "user_limit_exceeded"
|
| "user_limit_exceeded"
|
||||||
| "oidc_not_allowed"
|
|
||||||
>("rejected");
|
>("rejected");
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
@@ -70,12 +69,6 @@ export default function InviteStatusCard({
|
|||||||
function cardType() {
|
function cardType() {
|
||||||
if (error.includes("Invite is not for this user")) {
|
if (error.includes("Invite is not for this user")) {
|
||||||
return "wrong_user";
|
return "wrong_user";
|
||||||
} else if (
|
|
||||||
error.includes(
|
|
||||||
"Invites can only be accepted by internal users."
|
|
||||||
)
|
|
||||||
) {
|
|
||||||
return "oidc_not_allowed";
|
|
||||||
} else if (
|
} else if (
|
||||||
error.includes(
|
error.includes(
|
||||||
"User does not exist. Please create an account first."
|
"User does not exist. Please create an account first."
|
||||||
@@ -173,14 +166,6 @@ export default function InviteStatusCard({
|
|||||||
<p className="text-center">{t("inviteCreateUser")}</p>
|
<p className="text-center">{t("inviteCreateUser")}</p>
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
} else if (type === "oidc_not_allowed") {
|
|
||||||
return (
|
|
||||||
<div>
|
|
||||||
<p className="text-center mb-4">
|
|
||||||
{t("inviteErrorOidcNotAllowed")}
|
|
||||||
</p>
|
|
||||||
</div>
|
|
||||||
);
|
|
||||||
} else if (type === "user_limit_exceeded") {
|
} else if (type === "user_limit_exceeded") {
|
||||||
return (
|
return (
|
||||||
<div>
|
<div>
|
||||||
@@ -214,10 +199,6 @@ export default function InviteStatusCard({
|
|||||||
);
|
);
|
||||||
} else if (type === "user_does_not_exist") {
|
} else if (type === "user_does_not_exist") {
|
||||||
return <Button onClick={goToSignup}>{t("createAnAccount")}</Button>;
|
return <Button onClick={goToSignup}>{t("createAnAccount")}</Button>;
|
||||||
} else if (type === "oidc_not_allowed") {
|
|
||||||
return (
|
|
||||||
<Button onClick={goToLogin}>{t("inviteLogInOtherUser")}</Button>
|
|
||||||
);
|
|
||||||
} else if (type === "user_limit_exceeded") {
|
} else if (type === "user_limit_exceeded") {
|
||||||
return (
|
return (
|
||||||
<Button
|
<Button
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ import {
|
|||||||
InfoSections,
|
InfoSections,
|
||||||
InfoSectionTitle
|
InfoSectionTitle
|
||||||
} from "@app/components/InfoSection";
|
} from "@app/components/InfoSection";
|
||||||
import CopyToClipboard from "@app/components/CopyToClipboard";
|
|
||||||
import { useTranslations } from "next-intl";
|
import { useTranslations } from "next-intl";
|
||||||
|
|
||||||
type OrgInfoCardProps = {};
|
type OrgInfoCardProps = {};
|
||||||
@@ -27,9 +26,7 @@ export default function OrgInfoCard({}: OrgInfoCardProps) {
|
|||||||
</InfoSection>
|
</InfoSection>
|
||||||
<InfoSection>
|
<InfoSection>
|
||||||
<InfoSectionTitle>{t("orgId")}</InfoSectionTitle>
|
<InfoSectionTitle>{t("orgId")}</InfoSectionTitle>
|
||||||
<InfoSectionContent>
|
<InfoSectionContent>{org.org.orgId}</InfoSectionContent>
|
||||||
<CopyToClipboard text={org.org.orgId} />
|
|
||||||
</InfoSectionContent>
|
|
||||||
</InfoSection>
|
</InfoSection>
|
||||||
<InfoSection>
|
<InfoSection>
|
||||||
<InfoSectionTitle>{t("subnet")}</InfoSectionTitle>
|
<InfoSectionTitle>{t("subnet")}</InfoSectionTitle>
|
||||||
|
|||||||
@@ -9,15 +9,17 @@ import {
|
|||||||
FormMessage
|
FormMessage
|
||||||
} from "@app/components/ui/form";
|
} from "@app/components/ui/form";
|
||||||
|
|
||||||
|
import { toast } from "@app/hooks/useToast";
|
||||||
import { useTranslations } from "next-intl";
|
import { useTranslations } from "next-intl";
|
||||||
|
|
||||||
|
import { useRef } from "react";
|
||||||
import type { FieldValues, Path, UseFormReturn } from "react-hook-form";
|
import type { FieldValues, Path, UseFormReturn } from "react-hook-form";
|
||||||
import { RolesSelector, type SelectedRole } from "./roles-selector";
|
import { RolesSelector, type SelectedRole } from "./roles-selector";
|
||||||
|
|
||||||
type OrgRolesTagFieldProps<TFieldValues extends FieldValues> = {
|
type OrgRolesTagFieldProps<TFieldValues extends FieldValues> = {
|
||||||
form: Pick<
|
form: Pick<
|
||||||
UseFormReturn<TFieldValues>,
|
UseFormReturn<TFieldValues>,
|
||||||
"control" | "getValues" | "setValue" | "clearErrors"
|
"control" | "getValues" | "setValue"
|
||||||
>;
|
>;
|
||||||
orgId: string;
|
orgId: string;
|
||||||
/** Field in the form that holds Tag[] (role tags). Default: `"roles"`. */
|
/** Field in the form that holds Tag[] (role tags). Default: `"roles"`. */
|
||||||
@@ -40,6 +42,46 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
|||||||
disabled
|
disabled
|
||||||
}: OrgRolesTagFieldProps<TFieldValues>) {
|
}: OrgRolesTagFieldProps<TFieldValues>) {
|
||||||
const t = useTranslations();
|
const t = useTranslations();
|
||||||
|
const isPopoverOpenRef = useRef(false);
|
||||||
|
const lastValidRolesRef = useRef<SelectedRole[]>(
|
||||||
|
(form.getValues(name) as SelectedRole[]) ?? []
|
||||||
|
);
|
||||||
|
|
||||||
|
function validateRolesSelection() {
|
||||||
|
const current = form.getValues(name) as SelectedRole[];
|
||||||
|
|
||||||
|
if (current.length === 0 && lastValidRolesRef.current.length > 0) {
|
||||||
|
form.setValue(name, lastValidRolesRef.current as never, {
|
||||||
|
shouldDirty: true
|
||||||
|
});
|
||||||
|
toast({
|
||||||
|
variant: "destructive",
|
||||||
|
title: t("accessRoleRequired"),
|
||||||
|
description: t("accessRoleSelectPlease")
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (current.length > 0) {
|
||||||
|
lastValidRolesRef.current = current;
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
function handlePopoverOpenChange(open: boolean) {
|
||||||
|
isPopoverOpenRef.current = open;
|
||||||
|
|
||||||
|
if (open) {
|
||||||
|
const current = form.getValues(name) as SelectedRole[];
|
||||||
|
if (current.length > 0) {
|
||||||
|
lastValidRolesRef.current = current;
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
validateRolesSelection();
|
||||||
|
}
|
||||||
|
|
||||||
function setRoleTags(nextValue: SelectedRole[]) {
|
function setRoleTags(nextValue: SelectedRole[]) {
|
||||||
const prev = form.getValues(name) as SelectedRole[];
|
const prev = form.getValues(name) as SelectedRole[];
|
||||||
@@ -57,14 +99,15 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
|||||||
form.setValue(name, [prev[prev.length - 1]] as never, {
|
form.setValue(name, [prev[prev.length - 1]] as never, {
|
||||||
shouldDirty: true
|
shouldDirty: true
|
||||||
});
|
});
|
||||||
form.clearErrors(name);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
form.setValue(name, next as never, { shouldDirty: true });
|
form.setValue(name, next as never, { shouldDirty: true });
|
||||||
|
|
||||||
if (next.length > 0) {
|
if (next.length > 0 && !isPopoverOpenRef.current) {
|
||||||
form.clearErrors(name);
|
lastValidRolesRef.current = next;
|
||||||
|
} else if (!isPopoverOpenRef.current) {
|
||||||
|
validateRolesSelection();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -74,6 +117,9 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
|||||||
name={name}
|
name={name}
|
||||||
render={({ field }) => {
|
render={({ field }) => {
|
||||||
const selectedRoles = (field.value ?? []) as SelectedRole[];
|
const selectedRoles = (field.value ?? []) as SelectedRole[];
|
||||||
|
if (!isPopoverOpenRef.current && selectedRoles.length > 0) {
|
||||||
|
lastValidRolesRef.current = selectedRoles;
|
||||||
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<FormItem className="flex flex-col items-start">
|
<FormItem className="flex flex-col items-start">
|
||||||
@@ -83,6 +129,7 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
|||||||
orgId={orgId}
|
orgId={orgId}
|
||||||
selectedRoles={selectedRoles}
|
selectedRoles={selectedRoles}
|
||||||
onSelectRoles={setRoleTags}
|
onSelectRoles={setRoleTags}
|
||||||
|
onPopoverOpenChange={handlePopoverOpenChange}
|
||||||
disabled={disabled}
|
disabled={disabled}
|
||||||
/>
|
/>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
|
|||||||
@@ -115,11 +115,8 @@ function getActionsCategories(root: boolean) {
|
|||||||
},
|
},
|
||||||
|
|
||||||
"Resource Policy": {
|
"Resource Policy": {
|
||||||
[t("actionListResourcePolicies")]: "listResourcePolicies",
|
|
||||||
[t("actionCreateResourcePolicy")]: "createResourcePolicy",
|
|
||||||
[t("actionGetResourcePolicy")]: "getResourcePolicy",
|
[t("actionGetResourcePolicy")]: "getResourcePolicy",
|
||||||
[t("actionUpdateResourcePolicy")]: "updateResourcePolicy",
|
[t("actionUpdateResourcePolicy")]: "updateResourcePolicy",
|
||||||
[t("actionDeleteResourcePolicy")]: "deleteResourcePolicy",
|
|
||||||
[t("actionSetResourcePolicyUsers")]: "setResourcePolicyUsers",
|
[t("actionSetResourcePolicyUsers")]: "setResourcePolicyUsers",
|
||||||
[t("actionSetResourcePolicyRoles")]: "setResourcePolicyRoles",
|
[t("actionSetResourcePolicyRoles")]: "setResourcePolicyRoles",
|
||||||
[t("actionSetResourcePolicyPassword")]: "setResourcePolicyPassword",
|
[t("actionSetResourcePolicyPassword")]: "setResourcePolicyPassword",
|
||||||
|
|||||||
@@ -56,7 +56,6 @@ type SmartLoginFormProps = {
|
|||||||
defaultUser?: string;
|
defaultUser?: string;
|
||||||
orgSignIn?: OrgSignInConfig;
|
orgSignIn?: OrgSignInConfig;
|
||||||
lastUsedIdp?: (LoginFormIDP & { orgId?: string }) | null;
|
lastUsedIdp?: (LoginFormIDP & { orgId?: string }) | null;
|
||||||
inviteMode?: boolean;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
type ViewState =
|
type ViewState =
|
||||||
@@ -94,8 +93,7 @@ export default function SmartLoginForm({
|
|||||||
forceLogin,
|
forceLogin,
|
||||||
defaultUser,
|
defaultUser,
|
||||||
orgSignIn,
|
orgSignIn,
|
||||||
lastUsedIdp,
|
lastUsedIdp
|
||||||
inviteMode = false
|
|
||||||
}: SmartLoginFormProps) {
|
}: SmartLoginFormProps) {
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
const { env } = useEnvContext();
|
const { env } = useEnvContext();
|
||||||
@@ -138,10 +136,6 @@ export default function SmartLoginForm({
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
const signupUrl = redirect
|
|
||||||
? `/auth/signup?email=${encodeURIComponent(identifier)}&redirect=${encodeURIComponent(redirect)}&fromSmartLogin=true`
|
|
||||||
: `/auth/signup?email=${encodeURIComponent(identifier)}&fromSmartLogin=true`;
|
|
||||||
|
|
||||||
if (!result.found || result.accounts.length === 0) {
|
if (!result.found || result.accounts.length === 0) {
|
||||||
// No accounts found
|
// No accounts found
|
||||||
if (!isEmail || forceLogin) {
|
if (!isEmail || forceLogin) {
|
||||||
@@ -153,36 +147,13 @@ export default function SmartLoginForm({
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
// Valid email but no accounts and not forceLogin - redirect to signup
|
// Valid email but no accounts and not forceLogin - redirect to signup
|
||||||
|
const signupUrl = redirect
|
||||||
|
? `/auth/signup?email=${encodeURIComponent(identifier)}&redirect=${encodeURIComponent(redirect)}&fromSmartLogin=true`
|
||||||
|
: `/auth/signup?email=${encodeURIComponent(identifier)}&fromSmartLogin=true`;
|
||||||
router.push(signupUrl);
|
router.push(signupUrl);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Invite accept only supports internal (password) accounts
|
|
||||||
if (inviteMode) {
|
|
||||||
const internalAccount = result.accounts.find(
|
|
||||||
(acc) => acc.hasInternalAuth
|
|
||||||
);
|
|
||||||
if (internalAccount) {
|
|
||||||
setViewState({
|
|
||||||
type: "password",
|
|
||||||
identifier,
|
|
||||||
account: internalAccount
|
|
||||||
});
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (isEmail && !forceLogin) {
|
|
||||||
router.push(signupUrl);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
form.setError("identifier", {
|
|
||||||
type: "manual",
|
|
||||||
message: t("inviteLoginInternalOnly")
|
|
||||||
});
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Determine which view to show
|
// Determine which view to show
|
||||||
const account = result.accounts[0]; // Use first account for now
|
const account = result.accounts[0]; // Use first account for now
|
||||||
|
|
||||||
|
|||||||
@@ -15,14 +15,11 @@ import {
|
|||||||
} from "@app/components/ui/popover";
|
} from "@app/components/ui/popover";
|
||||||
import { cn } from "@app/lib/cn";
|
import { cn } from "@app/lib/cn";
|
||||||
import { ListUserOrgsResponse } from "@server/routers/org";
|
import { ListUserOrgsResponse } from "@server/routers/org";
|
||||||
import { Check, ChevronDown, Plus } from "lucide-react";
|
import { Check, ChevronDown, ChevronsUpDown } from "lucide-react";
|
||||||
import { usePathname, useRouter } from "next/navigation";
|
import { usePathname, useRouter } from "next/navigation";
|
||||||
import { useMemo, useState } from "react";
|
import { useMemo, useState } from "react";
|
||||||
import { useTranslations } from "next-intl";
|
import { useTranslations } from "next-intl";
|
||||||
import { Button } from "@app/components/ui/button";
|
import { Button } from "@app/components/ui/button";
|
||||||
import { useEnvContext } from "@app/hooks/useEnvContext";
|
|
||||||
import { useUserContext } from "@app/hooks/useUserContext";
|
|
||||||
import { build } from "@server/build";
|
|
||||||
|
|
||||||
type LauncherOrgSelectorProps = {
|
type LauncherOrgSelectorProps = {
|
||||||
orgId?: string;
|
orgId?: string;
|
||||||
@@ -34,16 +31,9 @@ export function LauncherOrgSelector({ orgId, orgs }: LauncherOrgSelectorProps) {
|
|||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
const pathname = usePathname();
|
const pathname = usePathname();
|
||||||
const t = useTranslations();
|
const t = useTranslations();
|
||||||
const { env } = useEnvContext();
|
|
||||||
const { user } = useUserContext();
|
|
||||||
|
|
||||||
const selectedOrg = orgs?.find((org) => org.orgId === orgId);
|
const selectedOrg = orgs?.find((org) => org.orgId === orgId);
|
||||||
|
|
||||||
let canCreateOrg = !env.flags.disableUserCreateOrg || user.serverAdmin;
|
|
||||||
if (build === "saas" && user.type !== "internal") {
|
|
||||||
canCreateOrg = false;
|
|
||||||
}
|
|
||||||
|
|
||||||
const sortedOrgs = useMemo(() => {
|
const sortedOrgs = useMemo(() => {
|
||||||
if (!orgs?.length) {
|
if (!orgs?.length) {
|
||||||
return orgs ?? [];
|
return orgs ?? [];
|
||||||
@@ -118,22 +108,6 @@ export function LauncherOrgSelector({ orgId, orgs }: LauncherOrgSelectorProps) {
|
|||||||
</CommandGroup>
|
</CommandGroup>
|
||||||
</CommandList>
|
</CommandList>
|
||||||
</Command>
|
</Command>
|
||||||
{canCreateOrg && (
|
|
||||||
<div className="p-2 border-t border-border">
|
|
||||||
<Button
|
|
||||||
variant="ghost"
|
|
||||||
size="sm"
|
|
||||||
className="w-full justify-start h-8 font-normal text-muted-foreground"
|
|
||||||
onClick={() => {
|
|
||||||
setOpen(false);
|
|
||||||
router.push("/setup");
|
|
||||||
}}
|
|
||||||
>
|
|
||||||
<Plus className="h-3.5 w-3.5 mr-2" />
|
|
||||||
{t("setupNewOrg")}
|
|
||||||
</Button>
|
|
||||||
</div>
|
|
||||||
)}
|
|
||||||
</PopoverContent>
|
</PopoverContent>
|
||||||
</Popover>
|
</Popover>
|
||||||
);
|
);
|
||||||
|
|||||||
Reference in New Issue
Block a user