Do not return empty SSO and SMTP settings for non-global-admins (#12180)
#11266 PS: I first attempted a serialization trick by introducing a new `appConfigResponse` and implementing `json.Marshal` to exclude these fields but it was too hacky and hard to maintain moving forward, so I'm bitting the bullet now. Happy to hear other ideas. - [X] Changes file added for user-visible changes in `changes/` or `orbit/changes/`. See [Changes files](https://fleetdm.com/docs/contributing/committing-changes#changes-files) for more information. - ~[ ] Documented any API changes (docs/Using-Fleet/REST-API.md or docs/Contributing/API-for-contributors.md)~ - ~[ ] Documented any permissions changes~ - ~[ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements)~ - ~[ ] Added support on fleet's osquery simulator `cmd/osquery-perf` for new osquery data ingestion features.~ - [X] Added/updated tests - [X] Manual QA for all new/changed functionality - ~For Orbit and Fleet Desktop changes:~ - ~[ ] Manual QA must be performed in the three main OSs, macOS, Windows and Linux.~ - ~[ ] Auto-update manual QA, from released version of component to new version (see [tools/tuf/test](../tools/tuf/test/README.md)).~
This commit is contained in:
@@ -646,10 +646,15 @@ func (svc *Service) InitiateMDMAppleSSOCallback(ctx context.Context, auth fleet.
|
||||
return "", ctxerr.Wrap(ctx, err, "validate request in session")
|
||||
}
|
||||
|
||||
var ssoSettings fleet.SSOSettings
|
||||
if appConfig.SSOSettings != nil {
|
||||
ssoSettings = *appConfig.SSOSettings
|
||||
}
|
||||
|
||||
err = sso.ValidateAudiences(
|
||||
*metadata,
|
||||
auth,
|
||||
appConfig.SSOSettings.EntityID,
|
||||
ssoSettings.EntityID,
|
||||
appConfig.ServerSettings.ServerURL,
|
||||
appConfig.ServerSettings.ServerURL+svc.config.Server.URLPrefix+"/api/v1/fleet/mdm/sso/callback",
|
||||
)
|
||||
|
||||
@@ -34,7 +34,7 @@ func (svc *Service) GetSSOUser(ctx context.Context, auth fleet.Auth) (*fleet.Use
|
||||
|
||||
// If JIT provisioning is disabled, then Fleet does not attempt to change
|
||||
// the role of the existing user.
|
||||
if !config.SSOSettings.EnableJITProvisioning {
|
||||
if config.SSOSettings == nil || !config.SSOSettings.EnableJITProvisioning {
|
||||
return user, nil
|
||||
}
|
||||
|
||||
@@ -75,7 +75,7 @@ func (svc *Service) GetSSOUser(ctx context.Context, auth fleet.Auth) (*fleet.Use
|
||||
}
|
||||
return user, nil
|
||||
case errors.As(err, &nfe):
|
||||
if !config.SSOSettings.EnableJITProvisioning {
|
||||
if config.SSOSettings == nil || !config.SSOSettings.EnableJITProvisioning {
|
||||
return nil, err
|
||||
}
|
||||
default:
|
||||
|
||||
Reference in New Issue
Block a user