mirror of
https://gitlab.com/openstapps/openstapps.git
synced 2026-10-07 18:22:04 +00:00
WIP
This commit is contained in:
@@ -90,12 +90,18 @@ export class AuthHelperService {
|
|||||||
key as keyof SCUserConfiguration;
|
key as keyof SCUserConfiguration;
|
||||||
|
|
||||||
user[userKey] = JSONPath({
|
user[userKey] = JSONPath({
|
||||||
path: this.userConfigurationMap[userKey] as string,
|
path:
|
||||||
|
this.userConfigurationMap[
|
||||||
|
userKey
|
||||||
|
] as string,
|
||||||
json: userInfo,
|
json: userInfo,
|
||||||
})[0];
|
})[0];
|
||||||
}
|
}
|
||||||
|
|
||||||
if (user.givenName && user.familyName) {
|
if (
|
||||||
|
user.givenName &&
|
||||||
|
user.familyName
|
||||||
|
) {
|
||||||
user.name =
|
user.name =
|
||||||
`${user.givenName} ${user.familyName}`;
|
`${user.givenName} ${user.familyName}`;
|
||||||
}
|
}
|
||||||
@@ -103,7 +109,8 @@ export class AuthHelperService {
|
|||||||
return user;
|
return user;
|
||||||
}
|
}
|
||||||
|
|
||||||
public async deleteOriginPath(): Promise<void> {
|
public async deleteOriginPath():
|
||||||
|
Promise<void> {
|
||||||
await this.storageProvider.delete(
|
await this.storageProvider.delete(
|
||||||
AUTH_ORIGIN_PATH,
|
AUTH_ORIGIN_PATH,
|
||||||
);
|
);
|
||||||
@@ -129,9 +136,11 @@ export class AuthHelperService {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public async endBrowserSession(): Promise<void> {
|
public async endBrowserSession():
|
||||||
|
Promise<void> {
|
||||||
const endSessionEndpoint =
|
const endSessionEndpoint =
|
||||||
await this.authService.getEndSessionEndpoint();
|
await this.authService
|
||||||
|
.getEndSessionEndpoint();
|
||||||
|
|
||||||
if (!endSessionEndpoint) {
|
if (!endSessionEndpoint) {
|
||||||
return;
|
return;
|
||||||
@@ -139,25 +148,41 @@ export class AuthHelperService {
|
|||||||
|
|
||||||
const alert =
|
const alert =
|
||||||
await this.alertController.create({
|
await this.alertController.create({
|
||||||
header: this.translateService.instant(
|
header:
|
||||||
|
this.translateService.instant(
|
||||||
`${AUTH_MESSAGE_PREFIX}.log_out_alert.header`,
|
`${AUTH_MESSAGE_PREFIX}.log_out_alert.header`,
|
||||||
),
|
),
|
||||||
message: this.translateService.instant(
|
|
||||||
|
message:
|
||||||
|
this.translateService.instant(
|
||||||
`${AUTH_MESSAGE_PREFIX}.log_out_alert.message`,
|
`${AUTH_MESSAGE_PREFIX}.log_out_alert.message`,
|
||||||
),
|
),
|
||||||
|
|
||||||
buttons: [
|
buttons: [
|
||||||
{
|
{
|
||||||
text:
|
text:
|
||||||
this.translateService.instant('no'),
|
this.translateService.instant(
|
||||||
|
'no',
|
||||||
|
),
|
||||||
|
|
||||||
|
role: 'cancel',
|
||||||
cssClass: 'default',
|
cssClass: 'default',
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
text:
|
text:
|
||||||
this.translateService.instant('yes'),
|
this.translateService.instant(
|
||||||
|
'yes',
|
||||||
|
),
|
||||||
|
|
||||||
role: 'confirm',
|
role: 'confirm',
|
||||||
cssClass: 'preferred',
|
cssClass: 'preferred',
|
||||||
handler: () => {
|
|
||||||
this.browser.open(
|
handler: async () => {
|
||||||
|
/*
|
||||||
|
* Only now, after explicit confirmation,
|
||||||
|
* open the IdP end-session endpoint.
|
||||||
|
*/
|
||||||
|
await this.browser.open(
|
||||||
endSessionEndpoint,
|
endSessionEndpoint,
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -53,7 +53,6 @@ import {
|
|||||||
} from './auth.provider.methods';
|
} from './auth.provider.methods';
|
||||||
import {requestorFactory} from './factories/requestor.factory';
|
import {requestorFactory} from './factories/requestor.factory';
|
||||||
import {storageFactory} from './factories/storage.factory';
|
import {storageFactory} from './factories/storage.factory';
|
||||||
import {SimpleBrowser} from '../../util/browser.factory';
|
|
||||||
|
|
||||||
const TOKEN_RESPONSE_KEY = 'token_response';
|
const TOKEN_RESPONSE_KEY = 'token_response';
|
||||||
const AUTH_EXPIRY_BUFFER = -5 * 60;
|
const AUTH_EXPIRY_BUFFER = -5 * 60;
|
||||||
@@ -184,7 +183,6 @@ export class AuthService {
|
|||||||
constructor(
|
constructor(
|
||||||
private readonly platform: Platform,
|
private readonly platform: Platform,
|
||||||
private readonly configProvider: ConfigProvider,
|
private readonly configProvider: ConfigProvider,
|
||||||
private readonly browser: SimpleBrowser,
|
|
||||||
) {
|
) {
|
||||||
this.storage =
|
this.storage =
|
||||||
storageFactory(platform);
|
storageFactory(platform);
|
||||||
@@ -420,12 +418,9 @@ export class AuthService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public async signOut(
|
public async signOut(
|
||||||
state?: string,
|
_state?: string,
|
||||||
revokeTokens = false,
|
revokeTokens = false,
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
const currentToken =
|
|
||||||
this.tokenSubject.value;
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
if (revokeTokens) {
|
if (revokeTokens) {
|
||||||
await this.revokeTokens();
|
await this.revokeTokens();
|
||||||
@@ -435,23 +430,17 @@ export class AuthService {
|
|||||||
TOKEN_RESPONSE_KEY,
|
TOKEN_RESPONSE_KEY,
|
||||||
);
|
);
|
||||||
|
|
||||||
const endSessionEndpoint =
|
/*
|
||||||
await this.getEndSessionEndpoint();
|
* Local logout only.
|
||||||
|
*
|
||||||
if (
|
* The optional logout from the identity provider is
|
||||||
endSessionEndpoint &&
|
* deliberately handled by AuthHelperService after the
|
||||||
currentToken
|
* confirmation dialog.
|
||||||
) {
|
*/
|
||||||
await this.performEndSessionRequest(
|
this.notify({
|
||||||
endSessionEndpoint,
|
action:
|
||||||
currentToken,
|
AuthActions.SignOutSuccess,
|
||||||
state,
|
});
|
||||||
);
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
await this.internalEndSessionCallback();
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
this.notify({
|
this.notify({
|
||||||
action:
|
action:
|
||||||
@@ -886,43 +875,6 @@ export class AuthService {
|
|||||||
.completeAuthorizationRequestIfPossible();
|
.completeAuthorizationRequestIfPossible();
|
||||||
}
|
}
|
||||||
|
|
||||||
private async performEndSessionRequest(
|
|
||||||
endpoint: string,
|
|
||||||
token: TokenResponse,
|
|
||||||
state?: string,
|
|
||||||
): Promise<void> {
|
|
||||||
const url =
|
|
||||||
new URL(endpoint);
|
|
||||||
|
|
||||||
if (token.idToken) {
|
|
||||||
url.searchParams.set(
|
|
||||||
'id_token_hint',
|
|
||||||
token.idToken,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (
|
|
||||||
this.authConfig
|
|
||||||
.end_session_redirect_url
|
|
||||||
) {
|
|
||||||
url.searchParams.set(
|
|
||||||
'post_logout_redirect_uri',
|
|
||||||
this.authConfig
|
|
||||||
.end_session_redirect_url,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (state) {
|
|
||||||
url.searchParams.set(
|
|
||||||
'state',
|
|
||||||
state,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
await this.browser.open(
|
|
||||||
url.toString(),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
private async internalEndSessionCallback():
|
private async internalEndSessionCallback():
|
||||||
Promise<void> {
|
Promise<void> {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) 2023 StApps
|
* Copyright (C) 2022 StApps
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
* This program is free software: you can redistribute it and/or modify it
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
* under the terms of the GNU General Public License as published by the Free
|
||||||
* Software Foundation, version 3.
|
* Software Foundation, version 3.
|
||||||
@@ -12,12 +12,14 @@
|
|||||||
* You should have received a copy of the GNU General Public License along with
|
* You should have received a copy of the GNU General Public License along with
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
import {Component} from '@angular/core';
|
import {Component} from '@angular/core';
|
||||||
import {AuthHelperService} from '../../auth/auth-helper.service';
|
|
||||||
import {ActivatedRoute} from '@angular/router';
|
import {ActivatedRoute} from '@angular/router';
|
||||||
|
|
||||||
|
import {AuthHelperService} from '../../auth/auth-helper.service';
|
||||||
|
import {AuthService} from '../../auth/auth.service';
|
||||||
import {ScheduleProvider} from '../../calendar/schedule.provider';
|
import {ScheduleProvider} from '../../calendar/schedule.provider';
|
||||||
import {profilePageSections} from '../../../../config/profile-page-sections';
|
import {profilePageSections} from '../../../../config/profile-page-sections';
|
||||||
import {AuthService} from '../../auth/auth.service';
|
|
||||||
|
|
||||||
@Component({
|
@Component({
|
||||||
selector: 'app-home',
|
selector: 'app-home',
|
||||||
@@ -34,23 +36,40 @@ export class ProfilePageComponent {
|
|||||||
readonly scheduleProvider: ScheduleProvider,
|
readonly scheduleProvider: ScheduleProvider,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
async signIn() {
|
async signIn(): Promise<void> {
|
||||||
const originPath = this.activatedRoute.snapshot.queryParamMap.get('origin_path');
|
const originPath =
|
||||||
|
this.activatedRoute.snapshot
|
||||||
|
.queryParamMap
|
||||||
|
.get('origin_path');
|
||||||
|
|
||||||
await (
|
await (
|
||||||
originPath
|
originPath
|
||||||
? this.authHelper.setOriginPath(originPath)
|
? this.authHelper
|
||||||
: this.authHelper.deleteOriginPath()
|
.setOriginPath(originPath)
|
||||||
|
: this.authHelper
|
||||||
|
.deleteOriginPath()
|
||||||
);
|
);
|
||||||
|
|
||||||
await this.authService.signIn();
|
await this.authService.signIn();
|
||||||
}
|
}
|
||||||
|
|
||||||
async signOut() {
|
async signOut(): Promise<void> {
|
||||||
|
/*
|
||||||
|
* First log out locally.
|
||||||
|
*/
|
||||||
await this.authService.signOut();
|
await this.authService.signOut();
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Then ask whether the user also wants to terminate
|
||||||
|
* the session at the identity provider.
|
||||||
|
*
|
||||||
|
* The IdP end-session endpoint is opened only if
|
||||||
|
* the user confirms with "Yes".
|
||||||
|
*/
|
||||||
|
await this.authHelper.endBrowserSession();
|
||||||
}
|
}
|
||||||
|
|
||||||
ionViewWillEnter() {
|
ionViewWillEnter(): void {
|
||||||
void this.authService.loadUserInfo();
|
void this.authService.loadUserInfo();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user