oidc_server.js 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349
  1. import {addGroupsWithAttributes, addEmail, changeFullname, changeUsername} from './loginHandler';
  2. Oidc = {};
  3. httpCa = false;
  4. if (process.env.OAUTH2_CA_CERT !== undefined) {
  5. try {
  6. const fs = Npm.require('fs');
  7. if (fs.existsSync(process.env.OAUTH2_CA_CERT)) {
  8. httpCa = fs.readFileSync(process.env.OAUTH2_CA_CERT);
  9. }
  10. } catch(e) {
  11. console.log('WARNING: failed loading: ' + process.env.OAUTH2_CA_CERT);
  12. console.log(e);
  13. }
  14. }
  15. var profile = {};
  16. var serviceData = {};
  17. var userinfo = {};
  18. OAuth.registerService('oidc', 2, null, function (query) {
  19. var debug = process.env.DEBUG === 'true';
  20. var token = getToken(query);
  21. if (debug) console.log('XXX: register token:', token);
  22. var accessToken = token.access_token || token.id_token;
  23. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  24. var claimsInAccessToken = (process.env.OAUTH2_ADFS_ENABLED === 'true' ||
  25. process.env.OAUTH2_ADFS_ENABLED === true ||
  26. process.env.OAUTH2_B2C_ENABLED === 'true' ||
  27. process.env.OAUTH2_B2C_ENABLED === true) || false;
  28. if(claimsInAccessToken)
  29. {
  30. // hack when using custom claims in the accessToken. On premise ADFS. And Azure AD B2C.
  31. userinfo = getTokenContent(accessToken);
  32. }
  33. else
  34. {
  35. // normal behaviour, getting the claims from UserInfo endpoint.
  36. userinfo = getUserInfo(accessToken);
  37. }
  38. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  39. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  40. if (debug) console.log('XXX: userinfo:', userinfo);
  41. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  42. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  43. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  44. serviceData.accessToken = accessToken;
  45. serviceData.expiresAt = expiresAt;
  46. // If on Oracle OIM email is empty or null, get info from username
  47. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  48. if (userinfo[process.env.OAUTH2_EMAIL_MAP]) {
  49. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP];
  50. } else {
  51. serviceData.email = userinfo[process.env.OAUTH2_USERNAME_MAP];
  52. }
  53. }
  54. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  55. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  56. }
  57. if (process.env.OAUTH2_B2C_ENABLED === 'true' || process.env.OAUTH2_B2C_ENABLED === true) {
  58. serviceData.email = userinfo["emails"][0];
  59. }
  60. if (accessToken) {
  61. var tokenContent = getTokenContent(accessToken);
  62. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  63. _.extend(serviceData, fields);
  64. }
  65. if (token.refresh_token)
  66. serviceData.refreshToken = token.refresh_token;
  67. if (debug) console.log('XXX: serviceData:', serviceData);
  68. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  69. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  70. if (process.env.OAUTH2_B2C_ENABLED === 'true' || process.env.OAUTH2_B2C_ENABLED === true) {
  71. profile.email = userinfo["emails"][0];
  72. }
  73. if (debug) console.log('XXX: profile:', profile);
  74. //temporarily store data from oidc in user.services.oidc.groups to update groups
  75. serviceData.groups = (userinfo["groups"] && userinfo["wekanGroups"]) ? userinfo["wekanGroups"] : userinfo["groups"];
  76. // groups arriving as array of strings indicate there is no scope set in oidc privider
  77. // to assign teams and keep admin privileges
  78. // data needs to be treated differently.
  79. // use case: in oidc provider no scope is set, hence no group attributes.
  80. // therefore: keep admin privileges for wekan as before
  81. if(Array.isArray(serviceData.groups) && serviceData.groups.length && typeof serviceData.groups[0] === "string" )
  82. {
  83. user = Meteor.users.findOne({'_id': serviceData.id});
  84. serviceData.groups.forEach(function(groupName, i)
  85. {
  86. if(user?.isAdmin && i == 0)
  87. {
  88. // keep information of user.isAdmin since in loginHandler the user will // be updated regarding group admin privileges provided via oidc
  89. serviceData.groups[i] = {"isAdmin": true};
  90. serviceData.groups[i]["displayName"]= groupName;
  91. }
  92. else
  93. {
  94. serviceData.groups[i] = {"displayName": groupName};
  95. }
  96. });
  97. }
  98. // Fix OIDC login loop for integer user ID. Thanks to danielkaiser.
  99. // https://github.com/wekan/wekan/issues/4795
  100. Meteor.call('groupRoutineOnLogin',serviceData, ""+serviceData.id);
  101. Meteor.call('boardRoutineOnLogin',serviceData, ""+serviceData.id);
  102. return {
  103. serviceData: serviceData,
  104. options: { profile: profile }
  105. };
  106. });
  107. var userAgent = "Meteor";
  108. if (Meteor.release) {
  109. userAgent += "/" + Meteor.release;
  110. }
  111. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  112. var getToken = function (query) {
  113. var debug = process.env.DEBUG === 'true';
  114. var config = getConfiguration();
  115. if(config.tokenEndpoint.includes('https://')){
  116. var serverTokenEndpoint = config.tokenEndpoint;
  117. }else{
  118. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  119. }
  120. var requestPermissions = config.requestPermissions;
  121. var response;
  122. try {
  123. var postOptions = {
  124. headers: {
  125. Accept: 'application/json',
  126. "User-Agent": userAgent
  127. },
  128. params: {
  129. code: query.code,
  130. client_id: config.clientId,
  131. client_secret: OAuth.openSecret(config.secret),
  132. redirect_uri: OAuth._redirectUri('oidc', config),
  133. grant_type: 'authorization_code',
  134. state: query.state
  135. }
  136. };
  137. if (httpCa) {
  138. postOptions['npmRequestOptions'] = { ca: httpCa };
  139. }
  140. response = HTTP.post(serverTokenEndpoint, postOptions);
  141. } catch (err) {
  142. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  143. { response: err.response });
  144. }
  145. if (response.data.error) {
  146. // if the http response was a json object with an error attribute
  147. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  148. } else {
  149. if (debug) console.log('XXX: getToken response: ', response.data);
  150. return response.data;
  151. }
  152. };
  153. }
  154. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  155. var getToken = function (query) {
  156. var debug = process.env.DEBUG === 'true';
  157. var config = getConfiguration();
  158. if(config.tokenEndpoint.includes('https://')){
  159. var serverTokenEndpoint = config.tokenEndpoint;
  160. }else{
  161. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  162. }
  163. var requestPermissions = config.requestPermissions;
  164. var response;
  165. // OIM needs basic Authentication token in the header - ClientID + SECRET in base64
  166. var dataToken=null;
  167. var strBasicToken=null;
  168. var strBasicToken64=null;
  169. dataToken = process.env.OAUTH2_CLIENT_ID + ':' + process.env.OAUTH2_SECRET;
  170. strBasicToken = new Buffer(dataToken);
  171. strBasicToken64 = strBasicToken.toString('base64');
  172. // eslint-disable-next-line no-console
  173. if (debug) console.log('Basic Token: ', strBasicToken64);
  174. try {
  175. var postOptions = {
  176. headers: {
  177. Accept: 'application/json',
  178. "User-Agent": userAgent,
  179. "Authorization": "Basic " + strBasicToken64
  180. },
  181. params: {
  182. code: query.code,
  183. client_id: config.clientId,
  184. client_secret: OAuth.openSecret(config.secret),
  185. redirect_uri: OAuth._redirectUri('oidc', config),
  186. grant_type: 'authorization_code',
  187. state: query.state
  188. }
  189. };
  190. if (httpCa) {
  191. postOptions['npmRequestOptions'] = { ca: httpCa };
  192. }
  193. response = HTTP.post(serverTokenEndpoint, postOptions);
  194. } catch (err) {
  195. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  196. { response: err.response });
  197. }
  198. if (response.data.error) {
  199. // if the http response was a json object with an error attribute
  200. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  201. } else {
  202. // eslint-disable-next-line no-console
  203. if (debug) console.log('XXX: getToken response: ', response.data);
  204. return response.data;
  205. }
  206. };
  207. }
  208. var getUserInfo = function (accessToken) {
  209. var debug = process.env.DEBUG === 'true';
  210. var config = getConfiguration();
  211. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  212. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  213. if (config.userinfoEndpoint.includes("https://")) {
  214. var serverUserinfoEndpoint = config.userinfoEndpoint;
  215. } else {
  216. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  217. }
  218. var response;
  219. try {
  220. var getOptions = {
  221. headers: {
  222. "User-Agent": userAgent,
  223. "Authorization": "Bearer " + accessToken
  224. }
  225. };
  226. if (httpCa) {
  227. getOptions['npmRequestOptions'] = { ca: httpCa };
  228. }
  229. response = HTTP.get(serverUserinfoEndpoint, getOptions);
  230. } catch (err) {
  231. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  232. {response: err.response});
  233. }
  234. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  235. return response.data;
  236. };
  237. var getConfiguration = function () {
  238. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  239. if (!config) {
  240. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  241. }
  242. return config;
  243. };
  244. var getTokenContent = function (token) {
  245. var content = null;
  246. if (token) {
  247. try {
  248. var parts = token.split('.');
  249. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  250. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  251. var signature = Buffer.from(parts[2], 'base64');
  252. var signed = parts[0] + '.' + parts[1];
  253. } catch (err) {
  254. this.content = {
  255. exp: 0
  256. };
  257. }
  258. }
  259. return content;
  260. }
  261. Meteor.methods({
  262. 'groupRoutineOnLogin': function(info, userId)
  263. {
  264. check(info, Object);
  265. check(userId, String);
  266. var propagateOidcData = process.env.PROPAGATE_OIDC_DATA || false;
  267. if (propagateOidcData) {
  268. users= Meteor.users;
  269. user = users.findOne({'services.oidc.id': userId});
  270. if(user) {
  271. //updates/creates Groups and user admin privileges accordingly if not undefined
  272. if (info.groups) {
  273. addGroupsWithAttributes(user, info.groups);
  274. }
  275. if(info.email) addEmail(user, info.email);
  276. if(info.fullname) changeFullname(user, info.fullname);
  277. if(info.username) changeUsername(user, info.username);
  278. }
  279. }
  280. }
  281. });
  282. Meteor.methods({
  283. 'boardRoutineOnLogin': function(info, oidcUserId)
  284. {
  285. check(info, Object);
  286. check(oidcUserId, String);
  287. const defaultBoardParams = (process.env.DEFAULT_BOARD_ID || '').split(':');
  288. const defaultBoardId = defaultBoardParams.shift()
  289. if (!defaultBoardId) return
  290. const board = Boards.findOne(defaultBoardId)
  291. const userId = Users.findOne({ 'services.oidc.id': oidcUserId })?._id
  292. const memberIndex = _.pluck(board?.members, 'userId').indexOf(userId);
  293. if(!board || !userId || memberIndex > -1) return
  294. board.addMember(userId)
  295. board.setMemberPermission(
  296. userId,
  297. defaultBoardParams.contains("isAdmin"),
  298. defaultBoardParams.contains("isNoComments"),
  299. defaultBoardParams.contains("isCommentsOnly"),
  300. defaultBoardParams.contains("isWorker")
  301. )
  302. }
  303. });
  304. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  305. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  306. };