-
Notifications
You must be signed in to change notification settings - Fork 4
[NAE-2241] Anonymous access refactor #316
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: release/7.1.0
Are you sure you want to change the base?
Changes from all commits
9cdebe0
41cc8fb
8babfe3
f0a63a8
ffb3b5e
44be3b6
3949d93
0305882
1b87bfd
9085d7f
2033c19
79c4990
c4c68c8
10b4a24
5db20de
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -6,7 +6,7 @@ import {ProxyAuthenticationService} from './proxyAuthentication.service'; | |
| import {AuthenticationMethodService} from './services/authentication-method.service'; | ||
| import {OverlayModule} from '@angular/cdk/overlay'; | ||
| import {MatProgressSpinnerModule} from '@angular/material/progress-spinner'; | ||
| import {AnonymousAuthenticationInterceptor} from './services/anonymous-authentication-interceptor'; | ||
| // import {AnonymousAuthenticationInterceptor} from './services/anonymous-authentication-interceptor'; | ||
|
|
||
|
|
||
| @NgModule({ | ||
|
|
@@ -22,7 +22,7 @@ import {AnonymousAuthenticationInterceptor} from './services/anonymous-authentic | |
| ], | ||
| providers: [ | ||
| { provide: HTTP_INTERCEPTORS, useClass: AuthenticationInterceptor, multi: true }, | ||
| { provide: HTTP_INTERCEPTORS, useClass: AnonymousAuthenticationInterceptor, multi: true }, | ||
| // { provide: HTTP_INTERCEPTORS, useClass: AnonymousAuthenticationInterceptor, multi: true }, | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. remove |
||
| { provide: AuthenticationMethodService, useClass: ProxyAuthenticationService}, | ||
| // AuthenticationEffects | ||
| ] | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,12 +1,12 @@ | ||
| import {ConfigurationService} from '../configuration/configuration.service'; | ||
| import {NullAuthenticationService} from './services/methods/null-authentication/null-authentication.service'; | ||
| import {BasicAuthenticationService} from './services/methods/basic-authentication/basic-authentication.service'; | ||
| import {HttpClient} from '@angular/common/http'; | ||
| import {HttpClient, HttpHeaders} from '@angular/common/http'; | ||
| import {BasicWithRealmAuthenticationService} from "./services/methods/basic-authentication/basic-with-realm-authentication.service"; | ||
| import {filter, take} from "rxjs/operators"; | ||
| import {UserResource} from "../resources/interface/user-resource"; | ||
| import {Credentials} from "./models/credentials"; | ||
| import {Observable} from 'rxjs'; | ||
| import {Observable, throwError} from 'rxjs'; | ||
| import {Injectable} from "@angular/core"; | ||
| import {AuthenticationMethodService} from "./services/authentication-method.service"; | ||
|
|
||
|
|
@@ -46,6 +46,24 @@ | |
| return this._proxyAuthMethod.login(credentials); | ||
| } | ||
|
|
||
| loginWithApiToken(token: string, realmId?: string): Observable<UserResource> { | ||
| const auth = this._config.get().providers.auth; | ||
| const loginEndpoint = typeof auth.endpoints === 'object' ? auth.endpoints['login'] : undefined; | ||
| const url = auth.address + (loginEndpoint ?? ''); | ||
| if (!loginEndpoint) { | ||
| return throwError(new Error('Login URL is not defined in the config [nae.providers.auth.endpoints.login]')); | ||
|
Check warning on line 54 in projects/netgrif-components-core/src/lib/authentication/proxyAuthentication.service.ts
|
||
| } | ||
| if (!token?.trim()) { | ||
| return throwError(new Error('API token is empty')); | ||
|
Check warning on line 57 in projects/netgrif-components-core/src/lib/authentication/proxyAuthentication.service.ts
|
||
| } | ||
|
|
||
| let headers = new HttpHeaders().set('Authorization', `Bearer ${token.trim()}`); | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
# Inspect repository configuration for insecure authentication endpoints.
rg -n -C 3 '"address"\s*:\s*"http:|sessionBearer|apiToken' nae.json projectsRepository: netgrif/components Length of output: 16802 Sensitive Data Exposure Reachability: External Reject non-HTTPS authentication endpoints.
🤖 Prompt for AI Agents |
||
| if (realmId?.trim()) { | ||
| headers = headers.set('X-Realm-ID', realmId.trim()); | ||
| } | ||
| return this._http.get<UserResource>(url, {headers}); | ||
| } | ||
|
|
||
| logout(): Observable<object> { | ||
| return this._proxyAuthMethod.logout(); | ||
| } | ||
|
|
||
| Original file line number | Diff line number | Diff line change | ||
|---|---|---|---|---|
|
|
@@ -8,9 +8,7 @@ export * from './sign-up/public-api'; | |||
| /* MODULES */ | ||||
| export * from './authentication.module'; | ||||
|
|
||||
| /* SERVICES */ | ||||
| export * from './anonymous/anonymous.service'; | ||||
| export * from './services/anonymous-authentication-interceptor' | ||||
| // export * from './services/anonymous-authentication-interceptor' | ||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🧹 Nitpick | 🔵 Trivial Remove the commented export from the public API surface. Keeping commented exports in a public API file creates dead code and ambiguity. If this export is intentionally retired, delete it outright. 🧹 Suggested cleanup-// export * from './services/anonymous-authentication-interceptor'📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. @renczesstefan remove |
||||
| export * from './services/authentication-interceptor' | ||||
| export * from './proxyAuthentication.service' | ||||
|
|
||||
|
|
||||
This file was deleted.
This file was deleted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🤖 get_repo_knowledge executed:
get_repo_knowledge netgrif/components /tmp/coderabbit-repo-knowledge/netgrif-components-726ffb43Length of output: 844
🏁 Script executed:
Repository: netgrif/components
Length of output: 50375
🏁 Script executed:
Repository: netgrif/components
Length of output: 9097
🏁 Script executed:
Repository: netgrif/components
Length of output: 4674
🏁 Script executed:
Repository: netgrif/components
Length of output: 13095
🏁 Script executed:
Repository: netgrif/components
Length of output: 10352
Sensitive Data Exposure
Reachability: External
Exploitability: Difficult
CWE: CWE-319 — Cleartext Transmission of Sensitive Information
Use HTTPS before enabling API-token login.
apiToken.enabledistrue, whileproviders.auth.addressuses HTTP. The example app sends the query token as anAuthorization: Bearercredential beforeremoveFromUrlruns. Set the auth address to HTTPS, or disable API-token login for HTTP-only configurations.🤖 Prompt for AI Agents