Files
fleet/server/service/client_sessions.go
T
Steven PalmesanoandJuan Fernandez 435c6e130b Display instructions needed for SSO-enabled accounts with fleetctl (#46768)
**Related issue:** Resolves #21818

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* The CLI now detects when SSO is enabled on the server and shows a
warning directing users to authenticate with an API token (with guidance
link) instead of email/password.

* **Bug Fixes**
* Authentication error messaging is now SSO-aware, improving guidance
when credential login fails.

* **Tests**
* Added coverage to verify the authentication guidance changes correctly
based on whether SSO is enabled.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Juan Fernandez <juan@fleetdm.com>
2026-06-17 18:19:00 -04:00

78 lines
2.1 KiB
Go

package service
import (
"encoding/json"
"fmt"
"net/http"
"github.com/fleetdm/fleet/v4/server/fleet"
)
// Login attempts to login to the current Fleet instance. If login is successful,
// an auth token is returned.
func (c *Client) Login(email, password string) (string, error) {
params := fleet.LoginRequest{
Email: email,
Password: password,
}
response, err := c.Do("POST", "/api/latest/fleet/login", "", params)
if err != nil {
return "", fmt.Errorf("POST /api/latest/fleet/login: %w", err)
}
defer response.Body.Close()
if response.StatusCode == http.StatusNotFound {
return "", notSetupErr{}
}
if response.StatusCode != http.StatusOK {
return "", fmt.Errorf(
"login received status %d %s",
response.StatusCode,
extractServerErrorText(response.Body),
)
}
var responseBody fleet.LoginResponse
err = json.NewDecoder(response.Body).Decode(&responseBody)
if err != nil {
return "", fmt.Errorf("decode login response: %w", err)
}
if responseBody.Err != nil {
return "", fmt.Errorf("login: %s", responseBody.Err)
}
return responseBody.Token, nil
}
// SSOSettings returns the SSO settings for the current Fleet instance.
// This endpoint is unauthenticated and can be called before login.
func (c *Client) SSOSettings() (*fleet.SessionSSOSettings, error) {
response, err := c.Do("GET", "/api/v1/fleet/sso", "", nil)
if err != nil {
return nil, fmt.Errorf("GET /api/v1/fleet/sso: %w", err)
}
defer response.Body.Close()
if response.StatusCode != http.StatusOK {
return nil, fmt.Errorf("get SSO settings received status %d %s", response.StatusCode, extractServerErrorText(response.Body))
}
var responseBody struct {
Settings *fleet.SessionSSOSettings `json:"settings"`
}
if err := json.NewDecoder(response.Body).Decode(&responseBody); err != nil {
return nil, fmt.Errorf("decode SSO settings response: %w", err)
}
return responseBody.Settings, nil
}
// Logout attempts to logout to the current Fleet instance.
func (c *Client) Logout() error {
verb, path := "POST", "/api/latest/fleet/logout"
var responseBody fleet.LogoutResponse
return c.authenticatedRequest(nil, verb, path, &responseBody)
}