You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

173 lines
5.1 KiB

  1. const _ = require('lodash')
  2. const fs = require('fs-extra')
  3. const path = require('path')
  4. const graphHelper = require('../../helpers/graph')
  5. /* global WIKI */
  6. module.exports = {
  7. Query: {
  8. async authentication () { return {} }
  9. },
  10. Mutation: {
  11. async authentication () { return {} }
  12. },
  13. AuthenticationQuery: {
  14. /**
  15. * Fetch active authentication strategies
  16. */
  17. async strategies (obj, args, context, info) {
  18. let strategies = await WIKI.models.authentication.getStrategies(args.isEnabled)
  19. strategies = strategies.map(stg => {
  20. const strategyInfo = _.find(WIKI.data.authentication, ['key', stg.key]) || {}
  21. return {
  22. ...strategyInfo,
  23. ...stg,
  24. config: _.sortBy(_.transform(stg.config, (res, value, key) => {
  25. const configData = _.get(strategyInfo.props, key, false)
  26. if (configData) {
  27. res.push({
  28. key,
  29. value: JSON.stringify({
  30. ...configData,
  31. value
  32. })
  33. })
  34. }
  35. }, []), 'key')
  36. }
  37. })
  38. return strategies
  39. }
  40. },
  41. AuthenticationMutation: {
  42. /**
  43. * Perform Login
  44. */
  45. async login (obj, args, context) {
  46. try {
  47. const authResult = await WIKI.models.users.login(args, context)
  48. return {
  49. ...authResult,
  50. responseResult: graphHelper.generateSuccess('Login success')
  51. }
  52. } catch (err) {
  53. // LDAP Debug Flag
  54. if (args.strategy === 'ldap' && WIKI.config.flags.ldapdebug) {
  55. WIKI.logger.warn('LDAP LOGIN ERROR (c1): ', err)
  56. }
  57. return graphHelper.generateError(err)
  58. }
  59. },
  60. /**
  61. * Perform 2FA Login
  62. */
  63. async loginTFA (obj, args, context) {
  64. try {
  65. const authResult = await WIKI.models.users.loginTFA(args, context)
  66. return {
  67. ...authResult,
  68. responseResult: graphHelper.generateSuccess('TFA success')
  69. }
  70. } catch (err) {
  71. return graphHelper.generateError(err)
  72. }
  73. },
  74. /**
  75. * Perform Mandatory Password Change after Login
  76. */
  77. async loginChangePassword (obj, args, context) {
  78. try {
  79. const authResult = await WIKI.models.users.loginChangePassword(args, context)
  80. return {
  81. ...authResult,
  82. responseResult: graphHelper.generateSuccess('Password changed successfully')
  83. }
  84. } catch (err) {
  85. return graphHelper.generateError(err)
  86. }
  87. },
  88. /**
  89. * Register a new account
  90. */
  91. async register (obj, args, context) {
  92. try {
  93. await WIKI.models.users.register({ ...args, verify: true }, context)
  94. return {
  95. responseResult: graphHelper.generateSuccess('Registration success')
  96. }
  97. } catch (err) {
  98. return graphHelper.generateError(err)
  99. }
  100. },
  101. /**
  102. * Update Authentication Strategies
  103. */
  104. async updateStrategies (obj, args, context) {
  105. try {
  106. WIKI.config.auth = {
  107. audience: _.get(args, 'config.audience', WIKI.config.auth.audience),
  108. tokenExpiration: _.get(args, 'config.tokenExpiration', WIKI.config.auth.tokenExpiration),
  109. tokenRenewal: _.get(args, 'config.tokenRenewal', WIKI.config.auth.tokenRenewal)
  110. }
  111. await WIKI.configSvc.saveToDb(['auth'])
  112. for (let str of args.strategies) {
  113. await WIKI.models.authentication.query().patch({
  114. isEnabled: str.isEnabled,
  115. config: _.reduce(str.config, (result, value, key) => {
  116. _.set(result, `${value.key}`, _.get(JSON.parse(value.value), 'v', null))
  117. return result
  118. }, {}),
  119. selfRegistration: str.selfRegistration,
  120. domainWhitelist: { v: str.domainWhitelist },
  121. autoEnrollGroups: { v: str.autoEnrollGroups }
  122. }).where('key', str.key)
  123. }
  124. await WIKI.auth.activateStrategies()
  125. return {
  126. responseResult: graphHelper.generateSuccess('Strategies updated successfully')
  127. }
  128. } catch (err) {
  129. return graphHelper.generateError(err)
  130. }
  131. },
  132. /**
  133. * Generate New Authentication Public / Private Key Certificates
  134. */
  135. async regenerateCertificates (obj, args, context) {
  136. try {
  137. await WIKI.auth.regenerateCertificates()
  138. return {
  139. responseResult: graphHelper.generateSuccess('Certificates have been regenerated successfully.')
  140. }
  141. } catch (err) {
  142. return graphHelper.generateError(err)
  143. }
  144. },
  145. /**
  146. * Reset Guest User
  147. */
  148. async resetGuestUser (obj, args, context) {
  149. try {
  150. await WIKI.auth.resetGuestUser()
  151. return {
  152. responseResult: graphHelper.generateSuccess('Guest user has been reset successfully.')
  153. }
  154. } catch (err) {
  155. return graphHelper.generateError(err)
  156. }
  157. }
  158. },
  159. AuthenticationStrategy: {
  160. icon (ap, args) {
  161. return fs.readFile(path.join(WIKI.ROOTPATH, `assets/svg/auth-icon-${ap.key}.svg`), 'utf8').catch(err => {
  162. if (err.code === 'ENOENT') {
  163. return null
  164. }
  165. throw err
  166. })
  167. }
  168. }
  169. }