Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions engine_issue_session.go
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,17 @@ func (e *Engine) IssueSession(ctx context.Context, req *IssueSessionRequest) (*I
req.AppID = req.User.AppID
}

// Resolve the default environment when the caller didn't supply one.
// authsome_sessions.env_id is NOT NULL, so a session minted without an
// env_id fails to persist. SignUp/SignIn already do this; callers that go
// straight through IssueSession (email-verification auto-login, SSO) relied
// on it happening here.
if req.EnvID.IsNil() {
if env, _ := e.GetDefaultEnvironment(ctx, req.AppID); env != nil { //nolint:errcheck // best-effort env lookup
req.EnvID = env.ID
}
}

// MFA gate. When the per-app config sets MFARequired and the
// caller hasn't already verified via the challenge endpoint, the
// gate fires regardless of whether the user has previously
Expand Down
6 changes: 6 additions & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,11 @@ go 1.26.0

require (
github.com/a-h/templ v0.3.1001
github.com/crewjam/saml v0.5.1
github.com/go-webauthn/webauthn v0.15.0
github.com/oschwald/maxminddb-golang v1.13.1
github.com/pquerna/otp v1.5.0
github.com/russellhaering/goxmldsig v1.4.0
github.com/stretchr/testify v1.11.1
github.com/testcontainers/testcontainers-go/modules/postgres v0.42.0
github.com/xraph/chronicle v1.6.0
Expand All @@ -31,6 +33,7 @@ require (

require (
github.com/Oudwins/tailwind-merge-go v0.2.1 // indirect
github.com/beevik/etree v1.5.0 // indirect
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
github.com/dustin/go-humanize v1.0.1 // indirect
github.com/go-openapi/swag/cmdutils v0.28.0 // indirect
Expand All @@ -44,8 +47,11 @@ require (
github.com/go-openapi/swag/stringutils v0.28.0 // indirect
github.com/go-openapi/swag/typeutils v0.28.0 // indirect
github.com/go-openapi/swag/yamlutils v0.28.0 // indirect
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
github.com/hashicorp/go-metrics v0.6.1 // indirect
github.com/jonboulle/clockwork v0.2.2 // indirect
github.com/mattermost/xml-roundtrip-validator v0.1.0 // indirect
github.com/moby/moby/api v1.54.1 // indirect
github.com/moby/moby/client v0.4.0 // indirect
github.com/ncruces/go-strftime v1.0.0 // indirect
Expand Down
25 changes: 25 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,9 @@ github.com/alecthomas/units v0.0.0-20151022065526-2efee857e7cf/go.mod h1:ybxpYRF
github.com/alecthomas/units v0.0.0-20190717042225-c3de453c63f4/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
github.com/armon/go-metrics v0.4.1 h1:hR91U9KYmb6bLBYLQjyM+3j+rcd/UhE+G78SFnF8gJA=
github.com/armon/go-metrics v0.4.1/go.mod h1:E6amYzXo6aW1tqzoZGT755KkbgrJsSdpwZ+3JqfkOG4=
github.com/beevik/etree v1.1.0/go.mod h1:r8Aw8JqVegEf0w2fDnATrX9VpkMcyFeM0FhwO62wh+A=
github.com/beevik/etree v1.5.0 h1:iaQZFSDS+3kYZiGoc9uKeOkUY3nYMXOKLl6KIJxiJWs=
github.com/beevik/etree v1.5.0/go.mod h1:gPNJNaBGVZ9AwsidazFZyygnd+0pAU38N4D+WemwKNs=
github.com/beorn7/perks v0.0.0-20180321164747-3a771d992973/go.mod h1:Dwedo/Wpr24TaqPxmxbtue+5NUziq4I4S80YR8gNf3Q=
github.com/beorn7/perks v1.0.0/go.mod h1:KWe93zE9D1o94FZ5RNwFwVgaQK1VOXiVxmqh+CedLV8=
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
Expand Down Expand Up @@ -50,8 +53,11 @@ github.com/containerd/platforms v0.2.1 h1:zvwtM3rz2YHPQsF2CHYM8+KtB5dvhISiXh5ZpS
github.com/containerd/platforms v0.2.1/go.mod h1:XHCb+2/hzowdiut9rkudds9bE5yJ7npe7dG/wG+uFPw=
github.com/cpuguy83/dockercfg v0.3.2 h1:DlJTyZGBDlXqUZ2Dk2Q3xHs/FtnooJJVaad2S9GKorA=
github.com/cpuguy83/dockercfg v0.3.2/go.mod h1:sugsbF4//dDlL/i+S+rtpIWp+5h0BHJHfjj5/jFyUJc=
github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E=
github.com/creack/pty v1.1.24 h1:bJrF4RRfyJnbTJqzRLHzcGaZK1NeM5kTC9jGgovnR1s=
github.com/creack/pty v1.1.24/go.mod h1:08sCNb52WyoAwi2QDyzUCTgcvVFhUzewun7wtTfvcwE=
github.com/crewjam/saml v0.5.1 h1:g+mfp0CrLuLRZCK793PgJcZeg5dS/0CDwoeAX2zcwNI=
github.com/crewjam/saml v0.5.1/go.mod h1:r0fDkmFe5URDgPrmtH0IYokva6fac3AUdstiPhyEolQ=
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM=
Expand Down Expand Up @@ -152,6 +158,8 @@ github.com/gobwas/ws v1.4.0/go.mod h1:G3gNqMNtPppf5XUz7O4shetPpcZ1VJ7zt18dlUeakr
github.com/gofrs/uuid/v5 v5.3.2 h1:2jfO8j3XgSwlz/wHqemAEugfnTlikAYHhnqQ8Xh4fE0=
github.com/gofrs/uuid/v5 v5.3.2/go.mod h1:CDOjlDMVAtN56jqyRUZh58JT31Tiw7/oQyEXZV+9bD8=
github.com/gogo/protobuf v1.1.1/go.mod h1:r8qH/GZQm5c6nD/R0oafs1akxWv10x8SbQlK7atdtwQ=
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
github.com/golang-jwt/jwt/v5 v5.3.1 h1:kYf81DTWFe7t+1VvL7eS+jKFVWaUnK9cB1qbwn63YCY=
github.com/golang-jwt/jwt/v5 v5.3.1/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE=
github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
Expand Down Expand Up @@ -225,6 +233,8 @@ github.com/jackc/pgx/v5 v5.10.0 h1:VhSvgU2jSli8o3AqIEOTJr7rZwAEUVo4E4XhR94Zfr0=
github.com/jackc/pgx/v5 v5.10.0/go.mod h1:mal1tBGAFfLHvZzaYh77YS/eC6IX9OWbRV1QIIM0Jn4=
github.com/jackc/puddle/v2 v2.2.2 h1:PR8nw+E/1w0GLuRFSmiioY6UooMp6KJv0/61nB7icHo=
github.com/jackc/puddle/v2 v2.2.2/go.mod h1:vriiEXHvEE654aYKXXjOvZM39qJ0q+azkZFrfEOc3H4=
github.com/jonboulle/clockwork v0.2.2 h1:UOGuzwb1PwsrDAObMuhUnj0p5ULPj8V/xJ7Kx9qUBdQ=
github.com/jonboulle/clockwork v0.2.2/go.mod h1:Pkfl5aHPm1nk2H9h0bjmnJD/BcgbGXUBGnn1kMkgxc8=
github.com/json-iterator/go v1.1.6/go.mod h1:+SdeFBvtyEkXs7REEP0seUULqWtbJapLOCVDaaPEHmU=
github.com/json-iterator/go v1.1.9/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM=
Expand All @@ -237,6 +247,8 @@ github.com/klauspost/cpuid/v2 v2.2.10/go.mod h1:hqwkgyIinND0mEev00jJYCxPNVRVXFQe
github.com/konsorten/go-windows-terminal-sequences v1.0.1/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ=
github.com/kr/logfmt v0.0.0-20140226030751-b84e30acd515/go.mod h1:+0opPa2QZZtGFBFZlji/RkVcI2GknAs/DXo4wKdlNEc=
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
github.com/kr/pretty v0.2.1/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI=
github.com/kr/pretty v0.3.0/go.mod h1:640gp4NfQd8pI5XOwp5fnNeVWj67G7CFk/SaSQn7NBk=
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
Expand All @@ -253,6 +265,8 @@ github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 h1:6E+4a0GO5zZEnZ
github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0/go.mod h1:zJYVVT2jmtg6P3p1VtQj7WsuWi/y4VnjVBn7F8KPB3I=
github.com/magiconair/properties v1.8.10 h1:s31yESBquKXCV9a/ScB3ESkOjUYYv+X0rg8SYxI99mE=
github.com/magiconair/properties v1.8.10/go.mod h1:Dhd985XPs7jluiymwWYZ0G4Z61jb3vdS329zhj2hYo0=
github.com/mattermost/xml-roundtrip-validator v0.1.0 h1:RXbVD2UAl7A7nOTR4u7E3ILa4IbtvKBHw64LDsmu9hU=
github.com/mattermost/xml-roundtrip-validator v0.1.0/go.mod h1:qccnGMcpgwcNaBnxqpJpWWUiPNr5H3O8eDgGV9gT5To=
github.com/mattn/go-colorable v0.1.9/go.mod h1:u6P/XSegPjTcexA+o6vUJrdnUu04hMope9wVRipJSqc=
github.com/mattn/go-colorable v0.1.12/go.mod h1:u5H1YNBxpqRaxsYJYSkiCWKzEfiAb1Gb520KVy5xxl4=
github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY=
Expand Down Expand Up @@ -307,6 +321,7 @@ github.com/oschwald/maxminddb-golang v1.13.1 h1:G3wwjdN9JmIK2o/ermkHM+98oX5fS+k5
github.com/oschwald/maxminddb-golang v1.13.1/go.mod h1:K4pgV9N/GcK694KSTmVSDTODk4IsCNThNdTmnaBZ/F8=
github.com/pascaldekloe/goe v0.1.0 h1:cBOtyMzM9HTpWjXfbbunk26uA6nG3a8n06Wieeh0MwY=
github.com/pascaldekloe/goe v0.1.0/go.mod h1:lzWF7FIEvWOWxwDKqyGYQf6ZUaNfKdP144TG7ZOy1lc=
github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA=
github.com/pkg/errors v0.8.0/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/errors v0.8.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
Expand Down Expand Up @@ -351,10 +366,14 @@ github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
github.com/robfig/cron/v3 v3.0.1 h1:WdRxkvbJztn8LMz/QEvLN5sBU+xKpSqwwUO1Pjr4qDs=
github.com/robfig/cron/v3 v3.0.1/go.mod h1:eQICP3HwyT7UooqI/z+Ov+PtYAWygg1TEWWzGIFLtro=
github.com/rogpeppe/go-internal v1.6.1/go.mod h1:xXDCJY+GAPziupqXw64V24skbSoqbTEfhy4qGm1nDQc=
github.com/rogpeppe/go-internal v1.8.0/go.mod h1:WmiCO8CzOY8rg0OYDC4/i/2WRWAB6poM+XZ2dLUbcbE=
github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
github.com/rs/xid v1.6.0 h1:fV591PaemRlL6JfRxGDEPl69wICngIQ3shQtzfy2gxU=
github.com/rs/xid v1.6.0/go.mod h1:7XoLgs4eV+QndskICGsho+ADou8ySMSjJKDIan90Nz0=
github.com/russellhaering/goxmldsig v1.4.0 h1:8UcDh/xGyQiyrW+Fq5t8f+l2DLB1+zlhYzkPUJ7Qhys=
github.com/russellhaering/goxmldsig v1.4.0/go.mod h1:gM4MDENBQf7M+V824SGfyIUVFWydB7n0KkEubVJl+Tw=
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ=
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
github.com/sean-/seed v0.0.0-20170313163322-e2103e2c3529 h1:nn5Wsu0esKSJiIVhscUtVbo7ada43DJhG55ua/hjS5I=
Expand All @@ -374,6 +393,7 @@ github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+Q
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.7.2/go.mod h1:R6va5+xMeoiuVRoj+gSkQ7d3FALtqAAGI1FQKckRals=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
Expand Down Expand Up @@ -555,9 +575,11 @@ google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af h1:+5/Sw3GsDNl
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
gopkg.in/alecthomas/kingpin.v2 v2.2.6/go.mod h1:FMv+mEhP44yOT+4EoQTLFTRgOQ1FBLkstjWtayDeSgw=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk=
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q=
gopkg.in/errgo.v2 v2.1.0/go.mod h1:hNsd1EY+bozCKY1Ytp96fpM3vjJbqLJn88ws8XvfDNI=
gopkg.in/evanphx/json-patch.v4 v4.13.0 h1:czT3CmqEaQ1aanPc5SdlgQrrEIb8w/wwCvWWnfEbYzo=
gopkg.in/evanphx/json-patch.v4 v4.13.0/go.mod h1:p8EYWUEYMpynmqDbY58zCKCFZw8pRWMG4EsWvDvM72M=
gopkg.in/inf.v0 v0.9.1 h1:73M5CoZyi3ZLMOyDlQh031Cx6N9NDJ2Vvfl76EDAgDc=
Expand All @@ -569,8 +591,11 @@ gopkg.in/yaml.v2 v2.2.5/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
gopkg.in/yaml.v2 v2.4.0 h1:D8xgwECY7CYvx+Y2n4sBz93Jn9JRvxdiyyo8CTfuKaY=
gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gotest.tools v2.2.0+incompatible h1:VsBPFP1AI068pPrMxtb/S8Zkgf9xEmTLJjfM+P5UIEo=
gotest.tools v2.2.0+incompatible/go.mod h1:DsYFclhRJ6vuDpmuTbkuFWG+y2sxOXAzmJt81HFBacw=
gotest.tools/v3 v3.5.2 h1:7koQfIKdy+I8UTetycgUqXWSDwpgv193Ka+qRsmBY8Q=
gotest.tools/v3 v3.5.2/go.mod h1:LtdLGcnqToBH83WByAAi/wiwSFCArdFIUV/xxN4pcjA=
k8s.io/api v0.36.3 h1:NxB+05W2UGqXWFXcLO0RB5cnqnUPP5v5sVlaOH0Iz4w=
Expand Down
5 changes: 5 additions & 0 deletions plugins/notification/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,11 @@ type Config struct {
// a ?token= query parameter.
PasswordResetPath string

// SignInPath is the path (relative to BaseURL) of the sign-in page. It is
// used for the login_url in the welcome notification. Defaults to
// "/sign-in".
SignInPath string

// DefaultLocale is the default locale for notifications (e.g. "en").
// If empty, defaults to "en".
DefaultLocale string
Expand Down
5 changes: 4 additions & 1 deletion plugins/notification/plugin.go
Original file line number Diff line number Diff line change
Expand Up @@ -119,6 +119,9 @@ func New(cfg ...Config) *Plugin {
if c.PasswordResetPath == "" {
c.PasswordResetPath = "/reset-password"
}
if c.SignInPath == "" {
c.SignInPath = "/sign-in"
}

// Merge user-provided mappings with defaults.
mappings := DefaultMappings()
Expand Down Expand Up @@ -234,7 +237,7 @@ func (p *Plugin) OnAfterSignUp(ctx context.Context, u *user.User, _ *session.Ses
Data: map[string]any{
"user_name": name,
"app_name": p.config.AppName,
"login_url": p.config.BaseURL + "/login",
"login_url": p.config.BaseURL + p.config.SignInPath,
},
}); err != nil {
p.logger.Warn("notification plugin: failed to send welcome notification",
Expand Down
66 changes: 66 additions & 0 deletions plugins/sso/migrations.go
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,41 @@ ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS client_secret TEXT
},
)

PostgresMigrations.MustRegister(
&migrate.Migration{
Name: "add_saml_fields",
Version: "20240201000003",
Up: func(ctx context.Context, exec migrate.Executor) error {
_, err := exec.Exec(ctx, `
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS idp_metadata_xml TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS idp_sso_url TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS idp_certificate TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS entity_id TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS acs_url TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS sp_certificate TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS sp_private_key TEXT NOT NULL DEFAULT '';
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS sign_requests BOOLEAN NOT NULL DEFAULT FALSE;
ALTER TABLE authsome_sso_connections ADD COLUMN IF NOT EXISTS attribute_mappings TEXT NOT NULL DEFAULT '';
`)
return err
},
Down: func(ctx context.Context, exec migrate.Executor) error {
_, err := exec.Exec(ctx, `
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS idp_metadata_xml;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS idp_sso_url;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS idp_certificate;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS entity_id;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS acs_url;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS sp_certificate;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS sp_private_key;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS sign_requests;
ALTER TABLE authsome_sso_connections DROP COLUMN IF EXISTS attribute_mappings;
`)
return err
},
},
)

// ──────────────────────────────────────────────────
// SQLite migrations
// ──────────────────────────────────────────────────
Expand Down Expand Up @@ -126,4 +161,35 @@ CREATE INDEX IF NOT EXISTS idx_authsome_sso_connections_provider
},
},
)

SqliteMigrations.MustRegister(
&migrate.Migration{
Name: "add_saml_fields",
Version: "20240201000003",
Up: func(ctx context.Context, exec migrate.Executor) error {
// SQLite requires one ADD COLUMN per statement.
cols := []string{
`ALTER TABLE authsome_sso_connections ADD COLUMN idp_metadata_xml TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN idp_sso_url TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN idp_certificate TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN entity_id TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN acs_url TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN sp_certificate TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN sp_private_key TEXT NOT NULL DEFAULT '';`,
`ALTER TABLE authsome_sso_connections ADD COLUMN sign_requests INTEGER NOT NULL DEFAULT 0;`,
`ALTER TABLE authsome_sso_connections ADD COLUMN attribute_mappings TEXT NOT NULL DEFAULT '';`,
}
for _, stmt := range cols {
if _, err := exec.Exec(ctx, stmt); err != nil {
return err
}
}
return nil
},
Down: func(_ context.Context, _ migrate.Executor) error {
// SQLite does not support DROP COLUMN in older versions; best-effort.
return nil
},
},
)
}
60 changes: 60 additions & 0 deletions plugins/sso/org_membership_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
package sso

import (
"context"
"testing"

"github.com/xraph/authsome/id"
"github.com/xraph/authsome/store/memory"
)

// TestEnsureOrgMembership verifies the org-level SSO enrollment: the first SSO
// login into an org-scoped connection adds the user as a member, and repeated
// logins are idempotent (no duplicate membership).
func TestEnsureOrgMembership(t *testing.T) {
mem := memory.New()
p := New()
p.SetStore(mem)

ctx := context.Background()
orgID := id.NewOrgID()
userID := id.NewUserID()

// First SSO login → user is enrolled into the org.
p.ensureOrgMembership(ctx, orgID, userID)

members, err := mem.ListMembers(ctx, orgID)
if err != nil {
t.Fatalf("ListMembers: %v", err)
}
if len(members) != 1 {
t.Fatalf("expected 1 member after enrollment, got %d", len(members))
}
if members[0].UserID != userID {
t.Errorf("member UserID = %s, want %s", members[0].UserID, userID)
}
if members[0].OrgID != orgID {
t.Errorf("member OrgID = %s, want %s", members[0].OrgID, orgID)
}

// Second login for the same user → idempotent, still exactly one member.
p.ensureOrgMembership(ctx, orgID, userID)
members, err = mem.ListMembers(ctx, orgID)
if err != nil {
t.Fatalf("ListMembers (2nd): %v", err)
}
if len(members) != 1 {
t.Fatalf("expected membership to stay idempotent (1), got %d", len(members))
}

// A different user logging in via the same connection is added alongside.
otherUser := id.NewUserID()
p.ensureOrgMembership(ctx, orgID, otherUser)
members, err = mem.ListMembers(ctx, orgID)
if err != nil {
t.Fatalf("ListMembers (3rd): %v", err)
}
if len(members) != 2 {
t.Fatalf("expected 2 members after a second user, got %d", len(members))
}
}
Loading
Loading