mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-05 23:34:11 +02:00
Fixed issues identified in PR review
This commit is contained in:
1 parent
4f118e6e08
commit
7a338cfd59
6 files changed
+287
-18
No files matched your search
@@ -20,6 +20,7 @@ import (
|
||||
// with any extra data injected into RawData.
|
||||
type AdditionalInfoProvider interface {
|
||||
FetchAdditionalInfo(ctx context.Context, user goth.User) (goth.User, error)
|
||||
FailLoginOnAdditionalInfoError() bool
|
||||
}
|
||||
|
||||
// GetAdditionalInfoProvider returns an AdditionalInfoProvider for the given
|
||||
@@ -39,8 +40,21 @@ func GetAdditionalInfoProvider(source *Source, gothUser *goth.User) AdditionalIn
|
||||
// This is intentional — the token is issued moments before this
|
||||
// call during the login flow and is guaranteed to be fresh.
|
||||
authenticatedClient := go_oauth2.NewClient(context.Background(), go_oauth2.StaticTokenSource(oauthToken))
|
||||
return google_module.NewClient(authenticatedClient, claimName)
|
||||
return google_module.NewClient(authenticatedClient, claimName, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func isGoogleGroupClaimRequiredForLoginFlow(source *Source) bool {
|
||||
groupClaimName := source.GroupClaimName
|
||||
if groupClaimName == "" {
|
||||
groupClaimName = "groups"
|
||||
}
|
||||
|
||||
// Fail closed only when login itself depends on the group claim.
|
||||
//
|
||||
// Admin/restricted/team sync can preserve the user's previous state when the
|
||||
// group claim is missing, so those options intentionally stay fail-open.
|
||||
return source.RequiredClaimName == groupClaimName
|
||||
}
|
||||
@@ -0,0 +1,62 @@
|
||||
// Copyright 2026 The Gitea Authors. All rights reserved.
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
package oauth2
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func TestIsGoogleGroupClaimRequiredForLoginFlow(t *testing.T) {
|
||||
t.Run("no group-dependent options", func(t *testing.T) {
|
||||
source := &Source{
|
||||
GroupClaimName: "groups",
|
||||
}
|
||||
assert.False(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
|
||||
t.Run("required claim uses group claim", func(t *testing.T) {
|
||||
source := &Source{
|
||||
GroupClaimName: "custom_groups",
|
||||
RequiredClaimName: "custom_groups",
|
||||
}
|
||||
assert.True(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
|
||||
t.Run("required claim uses default groups claim", func(t *testing.T) {
|
||||
source := &Source{
|
||||
RequiredClaimName: "groups",
|
||||
}
|
||||
assert.True(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
|
||||
t.Run("admin group configured", func(t *testing.T) {
|
||||
source := &Source{
|
||||
AdminGroup: "admins@example.com",
|
||||
}
|
||||
assert.False(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
|
||||
t.Run("restricted group configured", func(t *testing.T) {
|
||||
source := &Source{
|
||||
RestrictedGroup: "restricted@example.com",
|
||||
}
|
||||
assert.False(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
|
||||
t.Run("group team mapping configured", func(t *testing.T) {
|
||||
source := &Source{
|
||||
GroupTeamMap: "{\"a\": {\"org\": [\"team\"]}}",
|
||||
}
|
||||
assert.False(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
|
||||
t.Run("group team mapping removal enabled", func(t *testing.T) {
|
||||
source := &Source{
|
||||
GroupTeamMapRemoval: true,
|
||||
}
|
||||
assert.False(t, isGoogleGroupClaimRequiredForLoginFlow(source))
|
||||
})
|
||||
}
|
||||
Reference in new issue
Block a user