Compare commits
14 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 69883836e1 | |||
| 17df21041a | |||
| c19fffe3c9 | |||
| b6abfe8f03 | |||
| 420ccfab3b | |||
| 8ed4505dc0 | |||
| 451054f0c2 | |||
| 3a46680c8b | |||
| 1b0418e42e | |||
| 4e3aa082d3 | |||
| 6cb8b259e2 | |||
| 2532c492f1 | |||
| fdc045e166 | |||
| 0c2f38f0fe |
@@ -4,6 +4,27 @@ All notable changes to this project are documented here. Format loosely
|
||||
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions
|
||||
correspond to git tags (`vX.Y.Z`) and `nodejs/package.json`'s `version`.
|
||||
|
||||
## [1.7.0] - 2026-07-28
|
||||
|
||||
### Fixed
|
||||
- **`formAJAX`'s loading indicator showed literal HTML** ("<div class=..."), not a spinner — it passed raw markup to `app.messages.action`, which HTML-escapes its message by design. Replaced with plain text.
|
||||
- **`POST /api/user/` (create) and `PUT /api/user/password` had no `message` field** in their response, so the success notification rendered empty. Added messages matching every other route's convention.
|
||||
- **The user landing on `/login` with a `?redirect=` had no explanation why** — happens whenever another app's "Log in with SSO" bounces an unauthenticated user through `/oauth/authorize`. Now shows a contextual banner explaining what's happening.
|
||||
|
||||
### Changed
|
||||
- **Directory: tree view is now the only view** (the list/tree toggle is gone) — simpler, one code path.
|
||||
- **Directory: clicking a resource's name opens its detail modal**, not just the pencil/edit icon.
|
||||
|
||||
Found via a fresh production install's feedback — see the [theta-env v1.13.0 release](https://github.com/theta42/theta-env/releases) for the full cross-repo summary.
|
||||
|
||||
## [1.6.3] - 2026-07-28
|
||||
|
||||
### Fixed
|
||||
- **Group membership changes (`PUT`/`DELETE /api/group/:group/:uid`) didn't invalidate the User cache**, so `isServiceAccount` (and anything else derived from `memberOf`) could stay stale for up to 5 minutes after a change. This is what caused a real "lost user" report — the account had landed in `app_sso_service_account` (which `users.ejs`'s People tab filters out entirely) and looked exactly like data loss, though nothing was ever deleted.
|
||||
|
||||
### Added
|
||||
- **A confirmation before adding anyone to `app_sso_service_account`** via the Groups page — that group's whole purpose is to hide an account from the People tab, and there was no guardrail against doing that to a real person by mistake (which is how the bug above happened). Every other group's add-member flow is unchanged.
|
||||
|
||||
## [1.6.2] - 2026-07-28
|
||||
|
||||
### Fixed
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "t42-sso-manager",
|
||||
"version": "1.6.2",
|
||||
"version": "1.7.0",
|
||||
"description": "A very simple LDAP management and SSO system",
|
||||
"author": [
|
||||
{
|
||||
|
||||
@@ -679,13 +679,10 @@ function formAJAX(btn){
|
||||
return false;
|
||||
}
|
||||
|
||||
app.messages.action(
|
||||
`<div class="spinner-border" role="status">
|
||||
<span class="visually-hidden">Loading...</span>
|
||||
</div>`,
|
||||
$form,
|
||||
'info'
|
||||
);
|
||||
// Plain text: app.messages.action HTML-escapes its message (by design,
|
||||
// see @simpleworkjs/frontend), so raw markup like a spinner <div> would
|
||||
// render literally instead of as an element.
|
||||
app.messages.action('Saving…', $form, 'info');
|
||||
|
||||
app.api[method]($form.attr('action'), formData, function(error, data){
|
||||
app.messages.action(data.message, $form, error ? 'danger' : 'success'); //re-populate table
|
||||
|
||||
@@ -82,8 +82,13 @@ router.put('/:group/:uid', async function(req, res, next){
|
||||
|
||||
var group = await Group.get(req.params.group);
|
||||
var user = await User.get(req.params.uid);
|
||||
const results = await group.addMember(user);
|
||||
// Group membership feeds directly into cached-User-derived state
|
||||
// (isServiceAccount, isAdmin, group-gated nav/UI) -- without this,
|
||||
// a membership change here is invisible for up to the cache's TTL.
|
||||
User.clearCache();
|
||||
return res.json({
|
||||
results: await group.addMember(user),
|
||||
results,
|
||||
message: `Added user ${req.params.uid} to ${req.params.group} group.`
|
||||
});
|
||||
}catch(error){
|
||||
@@ -98,8 +103,10 @@ router.delete('/:group/:uid', async function(req, res, next){
|
||||
|
||||
var group = await Group.get(req.params.group);
|
||||
var user = await User.get(req.params.uid);
|
||||
const results = await group.removeMember(user);
|
||||
User.clearCache();
|
||||
return res.json({
|
||||
results: await group.removeMember(user),
|
||||
results,
|
||||
message: `Removed user ${req.params.uid} from ${req.params.group} group.`
|
||||
});
|
||||
}catch(error){
|
||||
|
||||
@@ -49,7 +49,7 @@ router.post('/', async function(req, res, next){
|
||||
}
|
||||
}
|
||||
|
||||
return res.json({results: user});
|
||||
return res.json({results: user, message: `User ${user.uid} created.`});
|
||||
}catch(error){
|
||||
next(error);
|
||||
}
|
||||
@@ -107,7 +107,7 @@ router.put('/password', async function(req, res, next){
|
||||
const verif = await UserVerification.getOrCreate(req.user.uid);
|
||||
await verif.update({ password_must_change: false });
|
||||
User.clearCache();
|
||||
return res.json({results: result});
|
||||
return res.json({results: result, message: 'Password changed.'});
|
||||
}catch(error){
|
||||
next(error);
|
||||
}
|
||||
|
||||
@@ -151,6 +151,32 @@ describe('Groups — member management', () => {
|
||||
const members = Array.isArray(group.member) ? group.member : [group.member];
|
||||
expect(members.some(dn => dn && dn.includes(MEMBER_UID))).toBe(false);
|
||||
});
|
||||
|
||||
// Regression: adding/removing a member here didn't clear User's LRU
|
||||
// cache (ttl 5 minutes), so isServiceAccount -- derived from
|
||||
// app_sso_service_account membership at GET /api/user/:uid time -- could
|
||||
// stay wrong for up to 5 minutes after the group change. In production
|
||||
// this hid a real person's account from the Users page's "People" tab
|
||||
// (it filters out anything with isServiceAccount) for however long the
|
||||
// stale cache entry lived, which looked exactly like the account had
|
||||
// vanished.
|
||||
test('PUT app_sso_service_account/:uid immediately flips isServiceAccount (no stale cache)', async () => {
|
||||
const added = await request(app)
|
||||
.put(`/api/group/app_sso_service_account/${MEMBER_UID}`)
|
||||
.set('auth-token', token);
|
||||
expect(added.status).toBe(200);
|
||||
|
||||
const afterAdd = await request(app).get(`/api/user/${MEMBER_UID}`).set('auth-token', token);
|
||||
expect(afterAdd.body.results.isServiceAccount).toBeTruthy();
|
||||
|
||||
const removed = await request(app)
|
||||
.delete(`/api/group/app_sso_service_account/${MEMBER_UID}`)
|
||||
.set('auth-token', token);
|
||||
expect(removed.status).toBe(200);
|
||||
|
||||
const afterRemove = await request(app).get(`/api/user/${MEMBER_UID}`).set('auth-token', token);
|
||||
expect(afterRemove.body.results.isServiceAccount).toBeFalsy();
|
||||
});
|
||||
});
|
||||
|
||||
describe('Groups — owner management', () => {
|
||||
|
||||
+39
-45
@@ -15,12 +15,6 @@
|
||||
<option value="kind">Kind</option>
|
||||
<option value="env">Environment</option>
|
||||
</select>
|
||||
<div class="btn-group btn-group-sm shadow-sm" role="group">
|
||||
<input type="radio" class="btn-check" name="viewMode" id="view-list" value="list" autocomplete="off" checked onchange="renderTable()">
|
||||
<label class="btn btn-outline-secondary" for="view-list"><i class="fa-solid fa-list"></i></label>
|
||||
<input type="radio" class="btn-check" name="viewMode" id="view-tree" value="tree" autocomplete="off" onchange="renderTable()">
|
||||
<label class="btn btn-outline-secondary" for="view-tree"><i class="fa-solid fa-folder-tree"></i></label>
|
||||
</div>
|
||||
<button class="btn btn-sm btn-primary ms-1 shadow-sm" onclick="openAddModal()">
|
||||
<i class="fas fa-plus"></i> Add Resource
|
||||
</button>
|
||||
@@ -49,7 +43,12 @@
|
||||
{{{indentHtml}}}
|
||||
<span class="badge bg-secondary">{{kind}}{{#metadata.subType}} ({{metadata.subType}}){{/metadata.subType}}</span>
|
||||
</td>
|
||||
<td><strong>{{name}}</strong><br><small class="text-muted">{{slug}}</small></td>
|
||||
<td>
|
||||
<a href="#" class="text-reset text-decoration-none" onclick="openEditModal('{{id}}'); return false;" title="View details">
|
||||
<strong>{{name}}</strong>
|
||||
</a>
|
||||
<br><small class="text-muted">{{slug}}</small>
|
||||
</td>
|
||||
<td>
|
||||
{{#metadata.isProduction}}<span class="badge bg-danger">Prod</span>{{/metadata.isProduction}}
|
||||
{{^metadata.isProduction}}<span class="badge bg-info">Dev</span>{{/metadata.isProduction}}
|
||||
@@ -376,8 +375,7 @@
|
||||
function renderTable() {
|
||||
const filter = $('#search-filter').val().toLowerCase();
|
||||
const sort = $('#sort-by').val();
|
||||
const viewMode = $('input[name="viewMode"]:checked').val();
|
||||
|
||||
|
||||
let filtered = rawResources.filter(r => {
|
||||
if (!filter) return true;
|
||||
return (r.name || '').toLowerCase().includes(filter) ||
|
||||
@@ -402,42 +400,38 @@
|
||||
|
||||
let finalRenderList = [];
|
||||
|
||||
if (viewMode === 'tree') {
|
||||
const map = {};
|
||||
const roots = [];
|
||||
filtered.forEach(r => { map[r.id] = { ...r, children: [] }; });
|
||||
|
||||
filtered.forEach(r => {
|
||||
const node = map[r.id];
|
||||
if (node.parentId && map[node.parentId]) {
|
||||
map[node.parentId].children.push(node);
|
||||
} else {
|
||||
roots.push(node);
|
||||
}
|
||||
});
|
||||
|
||||
const flatten = (nodes, depth) => {
|
||||
nodes.forEach(n => {
|
||||
let indentHtml = '';
|
||||
for(let i = 0; i < depth; i++) {
|
||||
indentHtml += '<span style="display:inline-block; width: 1.5rem;"></span>';
|
||||
}
|
||||
if (depth > 0) {
|
||||
indentHtml += '<i class="fa-solid fa-turn-up fa-rotate-90 text-muted me-2"></i>';
|
||||
}
|
||||
n.indentHtml = indentHtml;
|
||||
finalRenderList.push(n);
|
||||
if (n.children.length > 0) {
|
||||
flatten(n.children, depth + 1);
|
||||
}
|
||||
});
|
||||
};
|
||||
|
||||
flatten(roots, 0);
|
||||
} else {
|
||||
finalRenderList = filtered.map(r => ({ ...r, indentHtml: '' }));
|
||||
}
|
||||
|
||||
const map = {};
|
||||
const roots = [];
|
||||
filtered.forEach(r => { map[r.id] = { ...r, children: [] }; });
|
||||
|
||||
filtered.forEach(r => {
|
||||
const node = map[r.id];
|
||||
if (node.parentId && map[node.parentId]) {
|
||||
map[node.parentId].children.push(node);
|
||||
} else {
|
||||
roots.push(node);
|
||||
}
|
||||
});
|
||||
|
||||
const flatten = (nodes, depth) => {
|
||||
nodes.forEach(n => {
|
||||
let indentHtml = '';
|
||||
for(let i = 0; i < depth; i++) {
|
||||
indentHtml += '<span style="display:inline-block; width: 1.5rem;"></span>';
|
||||
}
|
||||
if (depth > 0) {
|
||||
indentHtml += '<i class="fa-solid fa-turn-up fa-rotate-90 text-muted me-2"></i>';
|
||||
}
|
||||
n.indentHtml = indentHtml;
|
||||
finalRenderList.push(n);
|
||||
if (n.children.length > 0) {
|
||||
flatten(n.children, depth + 1);
|
||||
}
|
||||
});
|
||||
};
|
||||
|
||||
flatten(roots, 0);
|
||||
|
||||
$.scope.resources.empty();
|
||||
for (const r of finalRenderList) {
|
||||
$.scope.resources.push(r);
|
||||
|
||||
+28
-1
@@ -32,6 +32,33 @@
|
||||
return value;
|
||||
}
|
||||
|
||||
// app_sso_service_account is a marker group: membership hides an account
|
||||
// from the Users page's People tab entirely (see users.ejs), which is
|
||||
// exactly right for a non-person account but has silently made a real
|
||||
// person's account look "gone" before (nothing else about it changes).
|
||||
// Everywhere else in this dropdown just fires the PUT directly; only
|
||||
// this one group gets a confirmation first.
|
||||
function addMemberClick(event, groupCN, uid, el){
|
||||
event.preventDefault();
|
||||
const $el = $(el);
|
||||
(async function(){
|
||||
if (groupCN === 'app_sso_service_account') {
|
||||
const ok = await app.messages.confirm(
|
||||
`Mark "${uid}" as a service account? This hides them from the Users page's People tab (Service Accounts tab only) — only do this for a non-person account.`,
|
||||
$el.closest('.card'), 'warning'
|
||||
);
|
||||
if (!ok) return;
|
||||
}
|
||||
try {
|
||||
const data = await app.api.put(`group/${groupCN}/${uid}`, {});
|
||||
await addedUser(data.message, groupCN, uid, $el);
|
||||
} catch(e) {
|
||||
app.messages.action(e.message || 'Failed to add member', $el.closest('.card'), 'danger');
|
||||
}
|
||||
})();
|
||||
return false;
|
||||
}
|
||||
|
||||
async function addedUser(message, group, user, $form){
|
||||
let data = await app.group.get(group);
|
||||
$.scope.groupCard.update('cn', group, processGroup(data.results));
|
||||
@@ -214,7 +241,7 @@
|
||||
</button>
|
||||
<div class="dropdown-menu shadow-lg" aria-labelledby="group_add_member">
|
||||
{{ #toAdd }}{{#.}}
|
||||
<a class="dropdown-item" action="group/{{groupCN}}/{{uid}}" method="put" onclick="formAJAX(this)" evalAJAX="addedUser(data.message, '{{groupCN}}', '{{uid}}', $form);">
|
||||
<a class="dropdown-item" href="#" onclick="return addMemberClick(event, '{{groupCN}}', '{{uid}}', this);">
|
||||
<i class="fa-solid fa-user"></i> {{uid}}
|
||||
</a>
|
||||
{{/.}}{{ /toAdd }}
|
||||
|
||||
@@ -7,6 +7,22 @@
|
||||
}
|
||||
});
|
||||
|
||||
// Landing here with no explanation ("why am I on the SSO login page?") is
|
||||
// exactly what happens when another app's "Log in with SSO" button sends
|
||||
// an unauthenticated user through /oauth/authorize, which bounces them
|
||||
// here with ?redirect=. Tell them what's happening instead of leaving it
|
||||
// a mystery.
|
||||
$(document).ready(function(){
|
||||
var redirect = <%- JSON.stringify(redirect || '') %>;
|
||||
if(redirect){
|
||||
var isOauth = /\/oauth\/authorize/.test(redirect);
|
||||
var message = isOauth
|
||||
? 'Log in to continue — an application is requesting access to your account.'
|
||||
: "Log in to continue to what you were doing — you'll be sent back afterward.";
|
||||
app.messages.action(message, $('.card').first(), 'info');
|
||||
}
|
||||
});
|
||||
|
||||
function setOtpMethod(method) {
|
||||
$('#otpMethodInput').val(method);
|
||||
$('#otpMethodEmail').toggleClass('active', method === 'email').toggleClass('btn-secondary', method === 'email').toggleClass('btn-outline-secondary', method !== 'email');
|
||||
|
||||
Reference in New Issue
Block a user