authentication.js 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281
  1. const _ = require('lodash')
  2. const fs = require('fs-extra')
  3. const path = require('path')
  4. const graphHelper = require('../../helpers/graph')
  5. /* global WIKI */
  6. module.exports = {
  7. Query: {
  8. /**
  9. * List of API Keys
  10. */
  11. async apiKeys (obj, args, context) {
  12. const keys = await WIKI.models.apiKeys.query().orderBy(['isRevoked', 'name'])
  13. return keys.map(k => ({
  14. id: k.id,
  15. name: k.name,
  16. keyShort: '...' + k.key.substring(k.key.length - 20),
  17. isRevoked: k.isRevoked,
  18. expiration: k.expiration,
  19. createdAt: k.createdAt,
  20. updatedAt: k.updatedAt
  21. }))
  22. },
  23. /**
  24. * Current API State
  25. */
  26. apiState () {
  27. return WIKI.config.api.isEnabled
  28. },
  29. async authStrategies () {
  30. return WIKI.data.authentication.map(stg => ({
  31. ...stg,
  32. isAvailable: stg.isAvailable === true,
  33. props: _.sortBy(_.transform(stg.props, (res, value, key) => {
  34. res.push({
  35. key,
  36. value: JSON.stringify(value)
  37. })
  38. }, []), 'key')
  39. }))
  40. }
  41. // /**
  42. // * Fetch active authentication strategies
  43. // */
  44. // async activeStrategies (obj, args, context, info) {
  45. // let strategies = await WIKI.models.authentication.getStrategies()
  46. // strategies = strategies.map(stg => {
  47. // const strategyInfo = _.find(WIKI.data.authentication, ['key', stg.strategyKey]) || {}
  48. // return {
  49. // ...stg,
  50. // strategy: strategyInfo,
  51. // config: _.sortBy(_.transform(stg.config, (res, value, key) => {
  52. // const configData = _.get(strategyInfo.props, key, false)
  53. // if (configData) {
  54. // res.push({
  55. // key,
  56. // value: JSON.stringify({
  57. // ...configData,
  58. // value
  59. // })
  60. // })
  61. // }
  62. // }, []), 'key')
  63. // }
  64. // })
  65. // return args.enabledOnly ? _.filter(strategies, 'isEnabled') : strategies
  66. // }
  67. },
  68. Mutation: {
  69. /**
  70. * Create New API Key
  71. */
  72. async createApiKey (obj, args, context) {
  73. try {
  74. const key = await WIKI.models.apiKeys.createNewKey(args)
  75. await WIKI.auth.reloadApiKeys()
  76. WIKI.events.outbound.emit('reloadApiKeys')
  77. return {
  78. key,
  79. responseResult: graphHelper.generateSuccess('API Key created successfully')
  80. }
  81. } catch (err) {
  82. return graphHelper.generateError(err)
  83. }
  84. },
  85. /**
  86. * Perform Login
  87. */
  88. async login (obj, args, context) {
  89. try {
  90. const authResult = await WIKI.models.users.login(args, context)
  91. return {
  92. ...authResult,
  93. responseResult: graphHelper.generateSuccess('Login success')
  94. }
  95. } catch (err) {
  96. // LDAP Debug Flag
  97. if (args.strategy === 'ldap' && WIKI.config.flags.ldapdebug) {
  98. WIKI.logger.warn('LDAP LOGIN ERROR (c1): ', err)
  99. }
  100. return graphHelper.generateError(err)
  101. }
  102. },
  103. /**
  104. * Perform 2FA Login
  105. */
  106. async loginTFA (obj, args, context) {
  107. try {
  108. const authResult = await WIKI.models.users.loginTFA(args, context)
  109. return {
  110. ...authResult,
  111. responseResult: graphHelper.generateSuccess('TFA success')
  112. }
  113. } catch (err) {
  114. return graphHelper.generateError(err)
  115. }
  116. },
  117. /**
  118. * Perform Mandatory Password Change after Login
  119. */
  120. async loginChangePassword (obj, args, context) {
  121. try {
  122. const authResult = await WIKI.models.users.loginChangePassword(args, context)
  123. return {
  124. ...authResult,
  125. responseResult: graphHelper.generateSuccess('Password changed successfully')
  126. }
  127. } catch (err) {
  128. return graphHelper.generateError(err)
  129. }
  130. },
  131. /**
  132. * Perform Mandatory Password Change after Login
  133. */
  134. async forgotPassword (obj, args, context) {
  135. try {
  136. await WIKI.models.users.loginForgotPassword(args, context)
  137. return {
  138. responseResult: graphHelper.generateSuccess('Password reset request processed.')
  139. }
  140. } catch (err) {
  141. return graphHelper.generateError(err)
  142. }
  143. },
  144. /**
  145. * Register a new account
  146. */
  147. async register (obj, args, context) {
  148. try {
  149. await WIKI.models.users.register({ ...args, verify: true }, context)
  150. return {
  151. responseResult: graphHelper.generateSuccess('Registration success')
  152. }
  153. } catch (err) {
  154. return graphHelper.generateError(err)
  155. }
  156. },
  157. /**
  158. * Set API state
  159. */
  160. async setApiState (obj, args, context) {
  161. try {
  162. WIKI.config.api.isEnabled = args.enabled
  163. await WIKI.configSvc.saveToDb(['api'])
  164. return {
  165. responseResult: graphHelper.generateSuccess('API State changed successfully')
  166. }
  167. } catch (err) {
  168. return graphHelper.generateError(err)
  169. }
  170. },
  171. /**
  172. * Revoke an API key
  173. */
  174. async revokeApiKey (obj, args, context) {
  175. try {
  176. await WIKI.models.apiKeys.query().findById(args.id).patch({
  177. isRevoked: true
  178. })
  179. await WIKI.auth.reloadApiKeys()
  180. WIKI.events.outbound.emit('reloadApiKeys')
  181. return {
  182. responseResult: graphHelper.generateSuccess('API Key revoked successfully')
  183. }
  184. } catch (err) {
  185. return graphHelper.generateError(err)
  186. }
  187. },
  188. /**
  189. * Update Authentication Strategies
  190. */
  191. async updateAuthStrategies (obj, args, context) {
  192. try {
  193. const previousStrategies = await WIKI.models.authentication.getStrategies()
  194. for (const str of args.strategies) {
  195. const newStr = {
  196. displayName: str.displayName,
  197. order: str.order,
  198. isEnabled: str.isEnabled,
  199. config: _.reduce(str.config, (result, value, key) => {
  200. _.set(result, `${value.key}`, _.get(JSON.parse(value.value), 'v', null))
  201. return result
  202. }, {}),
  203. selfRegistration: str.selfRegistration,
  204. domainWhitelist: { v: str.domainWhitelist },
  205. autoEnrollGroups: { v: str.autoEnrollGroups }
  206. }
  207. if (_.some(previousStrategies, ['key', str.key])) {
  208. await WIKI.models.authentication.query().patch({
  209. key: str.key,
  210. strategyKey: str.strategyKey,
  211. ...newStr
  212. }).where('key', str.key)
  213. } else {
  214. await WIKI.models.authentication.query().insert({
  215. key: str.key,
  216. strategyKey: str.strategyKey,
  217. ...newStr
  218. })
  219. }
  220. }
  221. for (const str of _.differenceBy(previousStrategies, args.strategies, 'key')) {
  222. const hasUsers = await WIKI.models.users.query().count('* as total').where({ providerKey: str.key }).first()
  223. if (_.toSafeInteger(hasUsers.total) > 0) {
  224. throw new Error(`Cannot delete ${str.displayName} as 1 or more users are still using it.`)
  225. } else {
  226. await WIKI.models.authentication.query().delete().where('key', str.key)
  227. }
  228. }
  229. await WIKI.auth.activateStrategies()
  230. WIKI.events.outbound.emit('reloadAuthStrategies')
  231. return {
  232. responseResult: graphHelper.generateSuccess('Strategies updated successfully')
  233. }
  234. } catch (err) {
  235. return graphHelper.generateError(err)
  236. }
  237. },
  238. /**
  239. * Generate New Authentication Public / Private Key Certificates
  240. */
  241. async regenerateCertificates (obj, args, context) {
  242. try {
  243. await WIKI.auth.regenerateCertificates()
  244. return {
  245. responseResult: graphHelper.generateSuccess('Certificates have been regenerated successfully.')
  246. }
  247. } catch (err) {
  248. return graphHelper.generateError(err)
  249. }
  250. },
  251. /**
  252. * Reset Guest User
  253. */
  254. async resetGuestUser (obj, args, context) {
  255. try {
  256. await WIKI.auth.resetGuestUser()
  257. return {
  258. responseResult: graphHelper.generateSuccess('Guest user has been reset successfully.')
  259. }
  260. } catch (err) {
  261. return graphHelper.generateError(err)
  262. }
  263. }
  264. },
  265. AuthenticationStrategy: {
  266. icon (ap, args) {
  267. return fs.readFile(path.join(WIKI.ROOTPATH, `assets/svg/auth-icon-${ap.key}.svg`), 'utf8').catch(err => {
  268. if (err.code === 'ENOENT') {
  269. return null
  270. }
  271. throw err
  272. })
  273. }
  274. }
  275. }