|
| 1 | +import Route from '@ember/routing/route'; |
| 2 | +import { inject as service } from '@ember/service'; |
| 3 | + |
| 4 | +const AUTH = 'vault.cluster.auth'; |
| 5 | +const PROVIDER = 'vault.cluster.identity.oidc-provider'; |
| 6 | + |
| 7 | +export default class VaultClusterIdentityOidcProviderRoute extends Route { |
| 8 | + @service auth; |
| 9 | + @service router; |
| 10 | + |
| 11 | + get win() { |
| 12 | + return this.window || window; |
| 13 | + } |
| 14 | + |
| 15 | + _redirect(url, params) { |
| 16 | + let redir = this._buildUrl(url, params); |
| 17 | + this.win.location.replace(redir); |
| 18 | + } |
| 19 | + |
| 20 | + beforeModel(transition) { |
| 21 | + const currentToken = this.auth.get('currentTokenName'); |
| 22 | + let { redirect_to, ...qp } = transition.to.queryParams; |
| 23 | + console.debug('DEBUG: removing redirect_to', redirect_to); |
| 24 | + if (!currentToken && 'none' === qp.prompt?.toLowerCase()) { |
| 25 | + this._redirect(qp.redirect_uri, { |
| 26 | + state: qp.state, |
| 27 | + error: 'login_required', |
| 28 | + }); |
| 29 | + } else if (!currentToken || 'login' === qp.prompt?.toLowerCase()) { |
| 30 | + if ('login' === qp.prompt?.toLowerCase()) { |
| 31 | + this.auth.deleteCurrentToken(); |
| 32 | + qp.prompt = null; |
| 33 | + } |
| 34 | + let { cluster_name } = this.paramsFor('vault.cluster'); |
| 35 | + let url = this.router.urlFor(transition.to.name, transition.to.params, { queryParams: qp }); |
| 36 | + return this.transitionTo(AUTH, cluster_name, { queryParams: { redirect_to: url } }); |
| 37 | + } |
| 38 | + } |
| 39 | + |
| 40 | + _redirectToAuth(oidcName, queryParams, logout = false) { |
| 41 | + let { cluster_name } = this.paramsFor('vault.cluster'); |
| 42 | + let currentRoute = this.router.urlFor(PROVIDER, oidcName, { queryParams }); |
| 43 | + if (logout) { |
| 44 | + this.auth.deleteCurrentToken(); |
| 45 | + } |
| 46 | + return this.transitionTo(AUTH, cluster_name, { queryParams: { redirect_to: currentRoute } }); |
| 47 | + } |
| 48 | + |
| 49 | + _buildUrl(urlString, params) { |
| 50 | + try { |
| 51 | + let url = new URL(urlString); |
| 52 | + Object.keys(params).forEach(key => { |
| 53 | + if (params[key]) { |
| 54 | + url.searchParams.append(key, params[key]); |
| 55 | + } |
| 56 | + }); |
| 57 | + return url; |
| 58 | + } catch (e) { |
| 59 | + console.debug('DEBUG: parsing url failed for', urlString); |
| 60 | + throw new Error('Invalid URL'); |
| 61 | + } |
| 62 | + } |
| 63 | + |
| 64 | + _handleSuccess(response, baseUrl, state) { |
| 65 | + const { code } = response; |
| 66 | + let redirectUrl = this._buildUrl(baseUrl, { code, state }); |
| 67 | + this.win.location.replace(redirectUrl); |
| 68 | + } |
| 69 | + _handleError(errorResp, baseUrl) { |
| 70 | + let redirectUrl = this._buildUrl(baseUrl, { ...errorResp }); |
| 71 | + this.win.location.replace(redirectUrl); |
| 72 | + } |
| 73 | + |
| 74 | + async model(params) { |
| 75 | + let { oidc_name, ...qp } = params; |
| 76 | + let decodedRedirect = decodeURI(qp.redirect_uri); |
| 77 | + let url = this._buildUrl(`${this.win.origin}/v1/identity/oidc/provider/${oidc_name}/authorize`, qp); |
| 78 | + try { |
| 79 | + const response = await this.auth.ajax(url, 'GET', {}); |
| 80 | + if ('consent' === qp.prompt?.toLowerCase()) { |
| 81 | + return { |
| 82 | + consent: { |
| 83 | + code: response.code, |
| 84 | + redirect: decodedRedirect, |
| 85 | + state: qp.state, |
| 86 | + }, |
| 87 | + }; |
| 88 | + } |
| 89 | + this._handleSuccess(response, decodedRedirect, qp.state); |
| 90 | + } catch (errorRes) { |
| 91 | + let resp = await errorRes.json(); |
| 92 | + let code = resp.error; |
| 93 | + if (code === 'max_age_violation') { |
| 94 | + this._redirectToAuth(oidc_name, qp, true); |
| 95 | + } else if (code === 'invalid_redirect_uri') { |
| 96 | + return { |
| 97 | + error: { |
| 98 | + title: 'Redirect URI mismatch', |
| 99 | + message: |
| 100 | + 'The provided redirect_uri is not in the list of allowed redirect URIs. Please make sure you are sending a valid redirect URI from your application.', |
| 101 | + }, |
| 102 | + }; |
| 103 | + } else if (code === 'invalid_client_id') { |
| 104 | + return { |
| 105 | + error: { |
| 106 | + title: 'Invalid client ID', |
| 107 | + message: 'Your client ID is invalid. Please update your configuration and try again.', |
| 108 | + }, |
| 109 | + }; |
| 110 | + } else { |
| 111 | + this._handleError(resp, decodedRedirect); |
| 112 | + } |
| 113 | + } |
| 114 | + } |
| 115 | +} |
0 commit comments