Commit Graph
25 Commits
Author SHA1 Message Date
TimshelandGitHub de808c5ad9 Fix Playwright docker (#6206) 2025-08-25 17:59:55 +02:00
TimshelandGitHub 7f386d38ae Fix Playwright test conf and update deps (#6176) 2025-08-14 18:04:14 +02:00
TimshelandGitHub 7fc94516ce Fix link to point to the wiki (#6157) 2025-08-09 22:20:03 +02:00
cff6c2b3af SSO using OpenID Connect (#3899)
* Add SSO functionality using OpenID Connect

Co-authored-by: Pablo Ovelleiro Corral <mail@pablo.tools>
Co-authored-by: Stuart Heap <sheap13@gmail.com>
Co-authored-by: Alex Moore <skiepp@my-dockerfarm.cloud>
Co-authored-by: Brian Munro <brian.alexander.munro@gmail.com>
Co-authored-by: Jacques B. <timshel@github.com>

* Improvements and error handling

* Stop rolling device token

* Add playwright tests

* Activate PKCE by default

* Ensure result order when searching for sso_user

* add SSO_ALLOW_UNKNOWN_EMAIL_VERIFICATION

* Toggle SSO button in scss

* Base64 encode state before sending it to providers

* Prevent disabled User from SSO login

* Review fixes

* Remove unused UserOrganization.invited_by_email

* Split SsoUser::find_by_identifier_or_email

* api::Accounts::verify_password add the policy even if it's ignored

* Disable signups if SSO_ONLY is activated

* Add verifiedDate to organizations::get_org_domain_sso_details

* Review fixes

* Remove OrganizationId guard from get_master_password_policy

* Add wrapper type OIDCCode OIDCState OIDCIdentifier

* Membership::confirm_user_invitations fix and tests

* Allow set-password only if account is unitialized

* Review fixes

* Prevent accepting another user invitation

* Log password change event on SSO account creation

* Unify master password policy resolution

* Upgrade openidconnect to 4.0.0

* Revert "Remove unused UserOrganization.invited_by_email"

This reverts commit 548e19995e141314af98a10d170ea7371f02fab4.

* Process org enrollment in accounts::post_set_password

* Improve tests

* Pass the claim invited_by_email in case it was not in db

* Add Slack configuration hints

* Fix playwright tests

* Skip broken tests

* Add sso identifier in admin user panel

* Remove duplicate expiration check, add a log

* Augment mobile refresh_token validity

* Rauthy configuration hints

* Fix playwright tests

* Playwright upgrade and conf improvement

* Playwright tests improvements

* 2FA email and device creation change

* Fix and improve Playwright tests

* Minor improvements

* Fix enforceOnLogin org policies

* Run playwright sso tests against correct db

* PKCE should now work with Zitadel

* Playwright upgrade maildev to use MailBuffer.expect

* Upgrades playwright tests deps

* Check email_verified in id_token and user_info

* Add sso verified endpoint for v2025.6.0

* Fix playwright tests

* Create a separate sso_client

* Upgrade openidconnect to 4.0.1

* Server settings for login fields toggle

* Use only css for login fields

* Fix playwright test

* Review fix

* More review fix

* Perform same checks when setting kdf

---------

Co-authored-by: Felix Eckhofer <felix@eckhofer.com>
Co-authored-by: Pablo Ovelleiro Corral <mail@pablo.tools>
Co-authored-by: Stuart Heap <sheap13@gmail.com>
Co-authored-by: Alex Moore <skiepp@my-dockerfarm.cloud>
Co-authored-by: Brian Munro <brian.alexander.munro@gmail.com>
Co-authored-by: Jacques B. <timshel@github.com>
Co-authored-by: Timshel <timshel@480s>
2025-08-08 23:22:22 +02:00
TimshelandGitHub a0c76284fd Perform same checks when setting kdf (#6141) 2025-08-07 23:33:27 +02:00
ce70cd2cf4 Hide login form custom fields (#6054)
Co-authored-by: Timshel <timshel@480s>
2025-07-14 22:01:20 +02:00
TimshelandGitHub 0d3f283c37 Fix and improvements to policies (#5923) 2025-06-02 21:47:12 +02:00
TimshelandGitHub a039e227c7 web-client now request email 2fa (#5871) 2025-05-26 20:24:30 +02:00
TimshelandGitHub 602b18fdd6 Remove old client version check (#5874) 2025-05-23 17:24:03 +02:00
TimshelandGitHub bf04c64759 Toggle providers using class (#5832) 2025-05-16 18:54:44 +02:00
TimshelandGitHub 2f1d86b7f1 remove Hide Business scss rules (#5855) 2025-05-16 18:53:01 +02:00
TimshelandGitHub bfe172702a Fix Yubico toggle (#5833) 2025-05-12 19:24:27 +02:00
TimshelandGitHub df42b6d6b0 Fix Yubico toggle (#5833) 2025-05-12 19:24:12 +02:00
TimshelandGitHub 0d16da440d On member invite and edit access_all is not sent anymore (#5673)
* On member invite and edit access_all is not sent anymore

* Use MembershipType ordering for access_all check

Fixes #5711
2025-04-16 17:52:26 +02:00
TimshelandGitHub f960bf59bb Fix invited user registration without SMTP (#5712) 2025-04-04 13:54:28 +02:00
TimshelandGitHub 1dae6093c9 Use subtle to replace deprecated ring::constant_time::verify_slices_are_equal (#5680) 2025-03-15 19:33:17 +01:00
TimshelandGitHub 08183fc999 Add TOTP delete endpoint (#5327) 2024-12-30 16:57:52 +01:00
TimshelandGitHub 248e561b3f Add orgUserHasExistingUser parameters to org invite (#4827) 2024-09-01 15:55:41 +02:00
TimshelandGitHub 65d11a9720 Switch to Whitelisting in .dockerignore (#4856) 2024-08-21 21:59:17 +02:00
TimshelandGitHub 3466a8040e Remove unecessary email normalization (#4840) 2024-08-17 22:48:59 +02:00
TimshelandGitHub f858523d92 Duo: use the formatted db email (#4779) 2024-07-25 20:25:44 +02:00
TimshelandGitHub de66e56b6c Allow to override log level for specific target (#4305) 2024-07-24 16:49:03 +02:00
TimshelandGitHub 9555ac7bb8 Remove compatibility route (#4578) 2024-05-25 15:29:58 +02:00
Jacques BandGitHub 29144b2ce0 Small improvements around email change (#4415) 2024-03-17 19:55:03 +01:00
Jacques BandGitHub 8b66e34415 Return 404 when user public_key is empty (#4271) 2024-01-26 20:34:36 +01:00