Merge pull request #770 from michael-pattern/feat/763/per-user_permissions_when_using_oauth

feat: per-user permissions when using oauth
This commit is contained in:
Jan Prochazka
2024-05-09 14:20:12 +02:00
committed by GitHub
3 changed files with 10 additions and 3 deletions

View File

@@ -137,7 +137,7 @@ module.exports = {
return { error: 'Logins not configured' }; return { error: 'Logins not configured' };
} }
const foundLogin = logins.find(x => x.login == login); const foundLogin = logins.find(x => x.login == login);
if (foundLogin && foundLogin.password == password) { if (foundLogin && foundLogin.password && foundLogin.password == password) {
return { return {
accessToken: jwt.sign({ login }, tokenSecret, { expiresIn: getTokenLifetime() }), accessToken: jwt.sign({ login }, tokenSecret, { expiresIn: getTokenLifetime() }),
}; };

View File

@@ -48,7 +48,7 @@ function start() {
if (logins && process.env.BASIC_AUTH) { if (logins && process.env.BASIC_AUTH) {
app.use( app.use(
basicAuth({ basicAuth({
users: _.fromPairs(logins.map(x => [x.login, x.password])), users: _.fromPairs(logins.filter(x => x.password).map(x => [x.login, x.password])),
challenge: true, challenge: true,
realm: 'DbGate Web App', realm: 'DbGate Web App',
}) })

View File

@@ -39,7 +39,7 @@ function getLogins() {
permissions: process.env.PERMISSIONS, permissions: process.env.PERMISSIONS,
}); });
} }
if (process.env.LOGINS) { if (process.env.LOGINS || process.env.OAUTH_PERMISSIONS) {
const logins = _.compact(process.env.LOGINS.split(',').map(x => x.trim())); const logins = _.compact(process.env.LOGINS.split(',').map(x => x.trim()));
for (const login of logins) { for (const login of logins) {
const password = process.env[`LOGIN_PASSWORD_${login}`]; const password = process.env[`LOGIN_PASSWORD_${login}`];
@@ -51,6 +51,13 @@ function getLogins() {
permissions, permissions,
}); });
} }
if (process.env.OAUTH_PERMISSIONS) {
res.push({
login,
password: null,
permissions,
})
}
} }
} }