Standardize page width, card layouts; mark SSO users external and read-only
- All pages now wrap their content in <div class="container mt-4">, matching sso-manager-node's width instead of rendering full-bleed inside the fluid shell. - Users and Permissions pages converted from bare <table>s to the same card-grid convention already used on the Groups page. - Users backed by SSO/OIDC login (backing === 'oidc', set by the redis user model's JIT-provisioning path) are now marked "External (SSO)" and their password-change control is hidden; PUT /password/:username also rejects with 403 server-side for such users. Deletion stays allowed. Redis-backend only -- LDAP/PAM deployments have no per-record marker for this today. - app-base.js (byte-identical across the 3 apps): added app.util.revealItem(), wired into the Users/Permissions create flows. - Bumped @simpleworkjs/frontend to ^0.2.7.
This commit is contained in:
+10
-1
@@ -81,11 +81,20 @@ router.put('/password', async function(req, res, next){
|
||||
}
|
||||
});
|
||||
|
||||
// Admin: reset another user's password.
|
||||
// Admin: reset another user's password. Blocked for SSO/OIDC-provisioned
|
||||
// accounts (backing === 'oidc') -- they authenticate through the IdP, not a
|
||||
// local password, so resetting one here would be a no-op at best and a
|
||||
// false sense of control at worst. Only applies to the redis user backend;
|
||||
// LDAP/PAM-backed deployments have no per-record marker for this.
|
||||
router.put('/password/:username', authz.requireAdmin, async function(req, res, next){
|
||||
try{
|
||||
validatePassword(req.body.password);
|
||||
let user = await User.get(req.params.username);
|
||||
if(user.backing === 'oidc'){
|
||||
let e = new Error('Cannot set a password for an SSO-authenticated user.');
|
||||
e.status = 403;
|
||||
throw e;
|
||||
}
|
||||
return res.json({results: await user.setPassword(req.body)});
|
||||
}catch(error){
|
||||
next(error);
|
||||
|
||||
Reference in New Issue
Block a user