added sso support for auth requests without prompt parameter
This commit is contained in:
parent
2530a2dad6
commit
8c0cd0099c
@ -148,10 +148,11 @@ loginServer = decideLogin
|
|||||||
| not validOIDC = throwError err401 { errBody = "For OIDC, the 'openid' scope and the 'id_token' response type must be given" }
|
| not validOIDC = throwError err401 { errBody = "For OIDC, the 'openid' scope and the 'id_token' response type must be given" }
|
||||||
| Just "none" <- mPrompt = handleSSO
|
| Just "none" <- mPrompt = handleSSO
|
||||||
| Just "login" <- mPrompt = handleLogin
|
| Just "login" <- mPrompt = handleLogin
|
||||||
| Nothing <- mPrompt = handleLogin
|
| Nothing <- mPrompt = if isJust mCreds then handleSSO else handleLogin
|
||||||
| otherwise = throwError err401 { errBody = "Prompt not supported" }
|
| otherwise = throwError err401 { errBody = "Prompt not supported" }
|
||||||
where
|
where
|
||||||
responseType' = readMaybe @ResponseType responseType
|
responseType' = readMaybe @ResponseType responseType
|
||||||
|
mCreds = mCookies >>= lookup "oa2_auth_cookie" . parseCookiesText . encodeUtf8
|
||||||
validOIDC :: Bool
|
validOIDC :: Bool
|
||||||
validOIDC = let scopes' = map (read @(Scope' user)) $ words scopes
|
validOIDC = let scopes' = map (read @(Scope' user)) $ words scopes
|
||||||
in (Left OpenID `elem` scopes') == (responseType' == Just IDToken)
|
in (Left OpenID `elem` scopes') == (responseType' == Just IDToken)
|
||||||
@ -160,8 +161,6 @@ loginServer = decideLogin
|
|||||||
handleSSO = do -- TODO check openid scope
|
handleSSO = do -- TODO check openid scope
|
||||||
liftIO $ putStrLn "login via SSO..."
|
liftIO $ putStrLn "login via SSO..."
|
||||||
unless (read @ResponseType responseType == IDToken) $ throwError err500 { errBody = "Unsupported response type" }
|
unless (read @ResponseType responseType == IDToken) $ throwError err500 { errBody = "Unsupported response type" }
|
||||||
unless (isJust mCookies) $ throwError err500 { errBody = "Missing cookie" }
|
|
||||||
let mCreds = lookup "oa2_auth_cookie" . parseCookiesText . encodeUtf8 $ fromJust mCookies
|
|
||||||
unless (isJust mCreds) $ throwError err500 { errBody = "Missing oauth2 cookie" }
|
unless (isJust mCreds) $ throwError err500 { errBody = "Missing oauth2 cookie" }
|
||||||
url' <- handleCreds @user @userData (fromJust mCreds) scopes client url mState mNonce
|
url' <- handleCreds @user @userData (fromJust mCreds) scopes client url mState mNonce
|
||||||
liftIO $ putStrLn "SSO successful"
|
liftIO $ putStrLn "SSO successful"
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user