Commit Graph

669 Commits

Author SHA1 Message Date
blam 11b7c39fb6 chore: added caching for successful profile retrieval
Signed-off-by: blam <ben@blam.sh>
2021-12-07 10:52:27 +01:00
Patrik Oldsberg 1154ec0017 auth-backend: decorateWithIdentity -> prepareBackstageIdentityResponse + API report fixes
Co-authored-by: blam <ben@blam.sh>
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-12-06 17:23:01 +01:00
Patrik Oldsberg 73c73b71d1 auth: simplify types and reintroduce deprecated BackstageIdentity
Co-authored-by: Fredrik Adelöw <freben@gmail.com>
Co-authored-by: blam <ben@blam.sh>
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-12-06 14:51:40 +01:00
blam e847694fbb chore: rebuild api-report now I fixed some issues
Signed-off-by: blam <ben@blam.sh>
2021-12-03 14:10:00 +01:00
blam e0f5814037 chore: more code review comments
Signed-off-by: blam <ben@blam.sh>
2021-12-03 10:33:05 +01:00
blam a76dacda24 chore: fix up the api reports
Signed-off-by: blam <ben@blam.sh>
2021-12-03 10:24:01 +01:00
blam 388fd9bb7f chore: fixing some code review comments
Signed-off-by: blam <ben@blam.sh>
2021-12-03 10:21:01 +01:00
blam acbb4cedd4 chore: fix derpy merge conflicts
Signed-off-by: blam <ben@blam.sh>
2021-12-03 10:08:04 +01:00
blam 3b39323f26 chore: revert some of the provider changes are they are handled in the OAuthAdapter now
Signed-off-by: blam <ben@blam.sh>
2021-12-02 13:33:47 +01:00
blam 11a90d6a79 chore: revert some of the handling
Signed-off-by: blam <ben@blam.sh>
2021-12-02 13:33:47 +01:00
blam b3ac79d7c2 chore: updated the api-report for auth backend. probably need to make this a bit better.
Signed-off-by: blam <ben@blam.sh>
2021-12-02 13:33:47 +01:00
blam 39645e56ac chore: reworking the auth providers to decorate the identity from the token that is returned from the different providers
Co-authored-by: Johan Haals <johan.haals@gmail.com>
Signed-off-by: blam <ben@blam.sh>
2021-12-02 13:33:47 +01:00
blam 29d0b45c6a chore: fixing issue with multi signin providers
Co-authored-by: Johan Haals <johan.haals@gmail.com>
Co-authored-by: Fredrik Adelöw <freben@gmail.com>
Signed-off-by: blam <ben@blam.sh>
2021-12-02 13:32:35 +01:00
blam 64c3fc492e chore: fix up api-reports and fix the export
Co-authored-by: Johan Haals <johan.haals@gmail.com>
Co-authored-by: Fredrik Adelöw <freben@gmail.com>
Signed-off-by: blam <ben@blam.sh>
2021-12-02 13:32:35 +01:00
Johan Haals 8c337a480f chore: Update types and API reports
Signed-off-by: Johan Haals <johan.haals@gmail.com>
2021-12-02 13:32:35 +01:00
Johan Haals e9471d274c Use BackstageUserIdentity, fix tests
Co-authored-by: blam <ben@blam.sh>
Co-authored-by: Fredrik Adelöw <freben@gmail.com>
Co-authored-by: Patrik Oldsberg <poldsberg@gmail.com>
Signed-off-by: Johan Haals <johan.haals@gmail.com>
2021-12-02 13:32:35 +01:00
Johan Haals 32b0443660 core-plugin-api: Use LegacyUserIdentity helper
Co-authored-by: blam <ben@blam.sh>
Signed-off-by: Johan Haals <johan.haals@gmail.com>
2021-12-02 13:29:27 +01:00
Patrik Oldsberg 6304c8f947 core-plugin-api: Refactor IdentityApi
Co-authored-by: Fredrik Adelöw <freben@gmail.com>
Co-authored-by: Johan Haals <johan.haals@gmail.com>
Co-authored-by: blam <ben@blam.sh>
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-12-02 13:29:27 +01:00
Patrik Oldsberg 019997dd4e Merge pull request #8331 from backstage/rugvip/auth-fin
auth-backend: migrate saml provider to sign-in resolver
2021-12-02 13:03:55 +01:00
Patrik Oldsberg 4bf4111902 auth-backend: migrate saml provider to sign-in resolver
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-12-02 12:06:22 +01:00
Hasan Ozdemir 2c4cda7506 define the profile in oidc provider without using makeProfile function
Signed-off-by: Hasan Ozdemir <21654050+nodify-at@users.noreply.github.com>
2021-12-02 11:31:40 +01:00
Patrik Oldsberg 067ddb7abb auth-backend: switch saml config to use privateKey
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-12-02 01:23:40 +01:00
Hasan Ozdemir 7d50123cd5 add access_type to issuer client to receive a refresh token
Signed-off-by: Hasan Ozdemir <21654050+nodify-at@users.noreply.github.com>
2021-12-02 00:48:28 +01:00
Hasan Ozdemir 36fa32216f Auth handler and sign in resolvers for oidc provider
Signed-off-by: Hasan Ozdemir <21654050+nodify-at@users.noreply.github.com>
2021-12-02 00:48:28 +01:00
Patrik Oldsberg 63f3b46b86 Merge pull request #8160 from adrianbarwicki/patch-1
feat: expose catalog lib in `plugin-auth-backend`
2021-11-26 16:57:20 +01:00
Fredrik Adelöw de1f77b71c Merge pull request #8233 from backstage/freben/less-cross
🧹  Align on usage of `cross-fetch` vs `node-fetch` in frontend vs backend packages
2021-11-26 10:15:50 +01:00
github-actions[bot] ef34f5de7b Version Packages 2021-11-25 12:40:52 +00:00
Fredrik Adelöw b055a6addc Align on usage of cross-fetch vs node-fetch in frontend vs backend packages
Signed-off-by: Fredrik Adelöw <freben@gmail.com>
2021-11-25 13:05:08 +01:00
Adrian Barwicki 7071dce02d feat: expose catalog lib in plugin-auth-backend
We are writing a custom OIDC provider plugin and need to use CatalogIdentityClient class in our provider. It is however not exported and we are not able to use it.

It is not a problem for providers that are committed to backstage repo as they use the local path, e.g https://github.com/backstage/backstage/blob/master/plugins/auth-backend/src/providers/aws-alb/provider.ts#L31 - but only for the ones that are developed locally.

Signed-off-by: Adrian Barwicki <adrianbarwicki@gmail.com>
2021-11-23 15:17:19 +01:00
Patrik Oldsberg 9f9ff42e28 Merge pull request #8193 from backstage/mod/auth-responses
auth-backend: use more standardized error responses
2021-11-22 17:28:52 +01:00
Patrik Oldsberg 9312572360 auth-backend: use more standardized error responses
Co-authored-by: Johan Haals <johan.haals@gmail.com>
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-11-22 13:17:26 +01:00
Otto Sichert b23bc7f9c3 Change default port of backend to 7007 due to MacOS Control Center update
Signed-off-by: Otto Sichert <git@ottosichert.de>
2021-11-18 16:45:57 +01:00
github-actions[bot] 99bf179ccf Version Packages 2021-11-18 11:52:08 +00:00
Zach Falen 7d6ab03ebb update test
Signed-off-by: Zach Falen <zfalen@deloitte.com>
2021-11-12 13:32:48 -07:00
Zach Falen 8a60033962 hotfix for Backstage token generation, prefer .token over .idToken
Signed-off-by: Zach Falen <zfalen@deloitte.com>
2021-11-12 12:53:13 -07:00
github-actions[bot] 3369ade8c0 Version Packages 2021-11-11 11:07:58 +00:00
Patrik Oldsberg e4989dec38 Merge pull request #7924 from backstage/rugvip/audience
auth-backend: add forwarding of the SAML audience option
2021-11-09 18:13:10 +01:00
Patrik Oldsberg 3e0e2f09d5 auth-backend: add forwarding of the SAML audience option
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
2021-11-09 16:25:34 +01:00
Marcus Eide 00af71a8fc Filter out undefined keys from settings
Signed-off-by: Marcus Eide <eide@spotify.com>
2021-11-09 10:42:21 +01:00
github-actions[bot] d66c5f1282 Version Packages 2021-10-28 14:06:43 +00:00
Patrik Oldsberg c9143d2abe Merge pull request #7409 from RoadieHQ/ch3367
Adopt extra field for OAuth state
2021-10-28 16:01:48 +02:00
blam d465f2e0af chore: bump the msw package and remove it from test-utils as it's not even needed
Signed-off-by: blam <ben@blam.sh>
2021-10-26 17:13:49 +02:00
Nicolas Arnold f18755ee49 Using req instead of state
Signed-off-by: Nicolas Arnold <nic@roadie.io>
2021-10-26 10:27:18 +01:00
Johan Haals f1e96dc5b1 chore/cli: Replace msw with setupRequestMockHandlers
Signed-off-by: Johan Haals <johan.haals@gmail.com>
2021-10-26 10:54:47 +02:00
Nicolas Arnold 8c93478a4e Update api docs
Signed-off-by: Nicolas Arnold <nic@roadie.io>
2021-10-22 15:24:19 +01:00
Nicolas Arnold 7714547af5 Fixing types
Signed-off-by: Nicolas Arnold <nic@roadie.io>
2021-10-22 10:40:37 +01:00
Nicolas Arnold f86173221c Add callback to allow users to override state
This is a slightly different implementation. It allows the user to pass in a reference to a callback so that the state
can be set. It was a suggestion from @Rugvip on a discussion we had offline.

The callback is an async function that returns a Promise<string>

Note: due to the way the OAuthAdapter works, this callback must include an env + nonce. Without them, your oauth request will fail.

Signed-off-by: Nicolas Arnold <nic@roadie.io>
2021-10-22 10:33:04 +01:00
Nicolas Arnold 3b767f19c9 Adopt extra field for OAuth state
Currently, the OAuth state is very limited. It only accepts three field:
* env
* nonce
* origin

This does not give the user much flexibility when passing in other fields to the state. Origin is set based on the window location.
Env determined by the running environment of backstage. Nonce, randomly generated every time.

If a user wanted to verify other fields in the state, they would be unable to do so.
For example, let's say you have a GitHub app that serves multiple installations. In order for this to work you need a middle service between github and backstage.
This service needs to programaticaly determine where to redirect the requests to (GitHub apps only allow one redirect url).
Your intermediate service requires you to redirect to other paths on backstage based on the type of request the Github ap
p receives.
By adding in the `extraState` to the Github Provider Options, this can now be achieved. You can set the field to `{'redirect_url': '/some/path/to/redirect/to'}` to complete
 the OAuth flow.

Although this is a very specific use case, I believe this will be useful across all the providers.

Signed-off-by: Nicolas Arnold <nic@roadie.io>
2021-10-22 10:23:44 +01:00
github-actions[bot] bf5090e59d Version Packages 2021-10-21 13:28:13 +00:00
Patrik Oldsberg 803c5550c5 Merge pull request #7568 from backstage/firestore-keystore
auth-backend: Add Firestore as new key-store provider
2021-10-21 14:43:05 +02:00