mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2025-09-09 18:25:58 +03:00
* Add SSO functionality using OpenID Connect Co-authored-by: Pablo Ovelleiro Corral <mail@pablo.tools> Co-authored-by: Stuart Heap <sheap13@gmail.com> Co-authored-by: Alex Moore <skiepp@my-dockerfarm.cloud> Co-authored-by: Brian Munro <brian.alexander.munro@gmail.com> Co-authored-by: Jacques B. <timshel@github.com> * Improvements and error handling * Stop rolling device token * Add playwright tests * Activate PKCE by default * Ensure result order when searching for sso_user * add SSO_ALLOW_UNKNOWN_EMAIL_VERIFICATION * Toggle SSO button in scss * Base64 encode state before sending it to providers * Prevent disabled User from SSO login * Review fixes * Remove unused UserOrganization.invited_by_email * Split SsoUser::find_by_identifier_or_email * api::Accounts::verify_password add the policy even if it's ignored * Disable signups if SSO_ONLY is activated * Add verifiedDate to organizations::get_org_domain_sso_details * Review fixes * Remove OrganizationId guard from get_master_password_policy * Add wrapper type OIDCCode OIDCState OIDCIdentifier * Membership::confirm_user_invitations fix and tests * Allow set-password only if account is unitialized * Review fixes * Prevent accepting another user invitation * Log password change event on SSO account creation * Unify master password policy resolution * Upgrade openidconnect to 4.0.0 * Revert "Remove unused UserOrganization.invited_by_email" This reverts commit 548e19995e141314af98a10d170ea7371f02fab4. * Process org enrollment in accounts::post_set_password * Improve tests * Pass the claim invited_by_email in case it was not in db * Add Slack configuration hints * Fix playwright tests * Skip broken tests * Add sso identifier in admin user panel * Remove duplicate expiration check, add a log * Augment mobile refresh_token validity * Rauthy configuration hints * Fix playwright tests * Playwright upgrade and conf improvement * Playwright tests improvements * 2FA email and device creation change * Fix and improve Playwright tests * Minor improvements * Fix enforceOnLogin org policies * Run playwright sso tests against correct db * PKCE should now work with Zitadel * Playwright upgrade maildev to use MailBuffer.expect * Upgrades playwright tests deps * Check email_verified in id_token and user_info * Add sso verified endpoint for v2025.6.0 * Fix playwright tests * Create a separate sso_client * Upgrade openidconnect to 4.0.1 * Server settings for login fields toggle * Use only css for login fields * Fix playwright test * Review fix * More review fix * Perform same checks when setting kdf --------- Co-authored-by: Felix Eckhofer <felix@eckhofer.com> Co-authored-by: Pablo Ovelleiro Corral <mail@pablo.tools> Co-authored-by: Stuart Heap <sheap13@gmail.com> Co-authored-by: Alex Moore <skiepp@my-dockerfarm.cloud> Co-authored-by: Brian Munro <brian.alexander.munro@gmail.com> Co-authored-by: Jacques B. <timshel@github.com> Co-authored-by: Timshel <timshel@480s>
101 lines
3.1 KiB
TypeScript
101 lines
3.1 KiB
TypeScript
import { test, expect, type TestInfo } from '@playwright/test';
|
|
import { MailDev } from 'maildev';
|
|
|
|
const utils = require('../global-utils');
|
|
import { createAccount, logUser } from './setups/user';
|
|
import { activateEmail, retrieveEmailCode, disableEmail } from './setups/2fa';
|
|
|
|
let users = utils.loadEnv();
|
|
|
|
let mailserver;
|
|
|
|
test.beforeAll('Setup', async ({ browser }, testInfo: TestInfo) => {
|
|
mailserver = new MailDev({
|
|
port: process.env.MAILDEV_SMTP_PORT,
|
|
web: { port: process.env.MAILDEV_HTTP_PORT },
|
|
})
|
|
|
|
await mailserver.listen();
|
|
|
|
await utils.startVault(browser, testInfo, {
|
|
SMTP_HOST: process.env.MAILDEV_HOST,
|
|
SMTP_FROM: process.env.PW_SMTP_FROM,
|
|
});
|
|
});
|
|
|
|
test.afterAll('Teardown', async ({}) => {
|
|
utils.stopVault();
|
|
if( mailserver ){
|
|
await mailserver.close();
|
|
}
|
|
});
|
|
|
|
test('Account creation', async ({ page }) => {
|
|
const mailBuffer = mailserver.buffer(users.user1.email);
|
|
|
|
await createAccount(test, page, users.user1, mailBuffer);
|
|
|
|
mailBuffer.close();
|
|
});
|
|
|
|
test('Login', async ({ context, page }) => {
|
|
const mailBuffer = mailserver.buffer(users.user1.email);
|
|
|
|
await logUser(test, page, users.user1, mailBuffer);
|
|
|
|
await test.step('verify email', async () => {
|
|
await page.getByText('Verify your account\'s email').click();
|
|
await expect(page.getByText('Verify your account\'s email')).toBeVisible();
|
|
await page.getByRole('button', { name: 'Send email' }).click();
|
|
|
|
await utils.checkNotification(page, 'Check your email inbox for a verification link');
|
|
|
|
const verify = await mailBuffer.expect((m) => m.subject === "Verify Your Email");
|
|
expect(verify.from[0]?.address).toBe(process.env.PW_SMTP_FROM);
|
|
|
|
const page2 = await context.newPage();
|
|
await page2.setContent(verify.html);
|
|
const link = await page2.getByTestId("verify").getAttribute("href");
|
|
await page2.close();
|
|
|
|
await page.goto(link);
|
|
await utils.checkNotification(page, 'Account email verified');
|
|
});
|
|
|
|
mailBuffer.close();
|
|
});
|
|
|
|
test('Activate 2fa', async ({ page }) => {
|
|
const emails = mailserver.buffer(users.user1.email);
|
|
|
|
await logUser(test, page, users.user1);
|
|
|
|
await activateEmail(test, page, users.user1, emails);
|
|
|
|
emails.close();
|
|
});
|
|
|
|
test('2fa', async ({ page }) => {
|
|
const emails = mailserver.buffer(users.user1.email);
|
|
|
|
await test.step('login', async () => {
|
|
await page.goto('/');
|
|
|
|
await page.getByLabel(/Email address/).fill(users.user1.email);
|
|
await page.getByRole('button', { name: 'Continue' }).click();
|
|
await page.getByLabel('Master password').fill(users.user1.password);
|
|
await page.getByRole('button', { name: 'Log in with master password' }).click();
|
|
|
|
await expect(page.getByRole('heading', { name: 'Verify your Identity' })).toBeVisible();
|
|
const code = await retrieveEmailCode(test, page, emails);
|
|
await page.getByLabel(/Verification code/).fill(code);
|
|
await page.getByRole('button', { name: 'Continue' }).click();
|
|
|
|
await expect(page).toHaveTitle(/Vaults/);
|
|
})
|
|
|
|
await disableEmail(test, page, users.user1);
|
|
|
|
emails.close();
|
|
});
|