use saml config interface instead of generic system configuration (#3551)

This commit is contained in:
Kevin Papst
2022-09-23 13:29:46 +02:00
committed by GitHub
parent b38fc96623
commit bfab6f42d0
8 changed files with 41 additions and 28 deletions

View File

@@ -12,7 +12,7 @@ services:
- [setAuth, ['@App\Saml\SamlAuthFactory']] - [setAuth, ['@App\Saml\SamlAuthFactory']]
App\Saml\Provider\SamlProvider: App\Saml\Provider\SamlProvider:
arguments: ['@App\Repository\UserRepository', '', '@App\Saml\SamlTokenFactory', '@App\Saml\User\SamlUserFactory', '@App\Configuration\SystemConfiguration'] arguments: ['@App\Repository\UserRepository', '', '@App\Saml\SamlTokenFactory', '@App\Saml\User\SamlUserFactory', '@App\Configuration\SamlConfigurationInterface']
App\Saml\Security\SamlAuthenticationSuccessHandler: App\Saml\Security\SamlAuthenticationSuccessHandler:
parent: security.authentication.success_handler parent: security.authentication.success_handler

View File

@@ -9,7 +9,7 @@
namespace App\Controller\Auth; namespace App\Controller\Auth;
use App\Configuration\SystemConfiguration; use App\Configuration\SamlConfigurationInterface;
use App\Saml\SamlAuthFactory; use App\Saml\SamlAuthFactory;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController; use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Request; use Symfony\Component\HttpFoundation\Request;
@@ -23,12 +23,12 @@ use Symfony\Component\Security\Core\Security;
final class SamlController extends AbstractController final class SamlController extends AbstractController
{ {
private $authFactory; private $authFactory;
private $systemConfiguration; private $samlConfiguration;
public function __construct(SamlAuthFactory $authFactory, SystemConfiguration $systemConfiguration) public function __construct(SamlAuthFactory $authFactory, SamlConfigurationInterface $samlConfiguration)
{ {
$this->authFactory = $authFactory; $this->authFactory = $authFactory;
$this->systemConfiguration = $systemConfiguration; $this->samlConfiguration = $samlConfiguration;
} }
/** /**
@@ -36,7 +36,7 @@ final class SamlController extends AbstractController
*/ */
public function loginAction(Request $request) public function loginAction(Request $request)
{ {
if (!$this->systemConfiguration->isSamlActive()) { if (!$this->samlConfiguration->isActivated()) {
throw $this->createNotFoundException('SAML deactivated'); throw $this->createNotFoundException('SAML deactivated');
} }
@@ -67,7 +67,7 @@ final class SamlController extends AbstractController
*/ */
public function metadataAction() public function metadataAction()
{ {
if (!$this->systemConfiguration->isSamlActive()) { if (!$this->samlConfiguration->isActivated()) {
throw $this->createNotFoundException('SAML deactivated'); throw $this->createNotFoundException('SAML deactivated');
} }
@@ -84,7 +84,7 @@ final class SamlController extends AbstractController
*/ */
public function assertionConsumerServiceAction() public function assertionConsumerServiceAction()
{ {
if (!$this->systemConfiguration->isSamlActive()) { if (!$this->samlConfiguration->isActivated()) {
throw $this->createNotFoundException('SAML deactivated'); throw $this->createNotFoundException('SAML deactivated');
} }
@@ -96,7 +96,7 @@ final class SamlController extends AbstractController
*/ */
public function logoutAction() public function logoutAction()
{ {
if (!$this->systemConfiguration->isSamlActive()) { if (!$this->samlConfiguration->isActivated()) {
throw $this->createNotFoundException('SAML deactivated'); throw $this->createNotFoundException('SAML deactivated');
} }

View File

@@ -9,6 +9,7 @@
namespace App\Controller\Security; namespace App\Controller\Security;
use App\Configuration\SamlConfigurationInterface;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController; use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Request; use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\HttpFoundation\Response; use Symfony\Component\HttpFoundation\Response;
@@ -21,10 +22,12 @@ use Symfony\Component\Security\Csrf\CsrfTokenManagerInterface;
final class SecurityController extends AbstractController final class SecurityController extends AbstractController
{ {
private $tokenManager; private $tokenManager;
private $samlConfiguration;
public function __construct(CsrfTokenManagerInterface $tokenManager) public function __construct(CsrfTokenManagerInterface $tokenManager, SamlConfigurationInterface $samlConfiguration)
{ {
$this->tokenManager = $tokenManager; $this->tokenManager = $tokenManager;
$this->samlConfiguration = $samlConfiguration;
} }
/** /**
@@ -67,6 +70,7 @@ final class SecurityController extends AbstractController
'last_username' => $lastUsername, 'last_username' => $lastUsername,
'error' => $error, 'error' => $error,
'csrf_token' => $csrfToken, 'csrf_token' => $csrfToken,
'saml_config' => $this->samlConfiguration,
]); ]);
} }

View File

@@ -9,7 +9,7 @@
namespace App\Saml\Provider; namespace App\Saml\Provider;
use App\Configuration\SystemConfiguration; use App\Configuration\SamlConfigurationInterface;
use App\Entity\User; use App\Entity\User;
use App\Repository\UserRepository; use App\Repository\UserRepository;
use App\Saml\SamlTokenFactory; use App\Saml\SamlTokenFactory;
@@ -29,7 +29,7 @@ final class SamlProvider implements AuthenticationProviderInterface
private $repository; private $repository;
private $configuration; private $configuration;
public function __construct(UserRepository $repository, UserProviderInterface $userProvider, SamlTokenFactory $tokenFactory, SamlUserFactory $userFactory, SystemConfiguration $configuration) public function __construct(UserRepository $repository, UserProviderInterface $userProvider, SamlTokenFactory $tokenFactory, SamlUserFactory $userFactory, SamlConfigurationInterface $configuration)
{ {
$this->repository = $repository; $this->repository = $repository;
$this->userProvider = $userProvider; $this->userProvider = $userProvider;
@@ -74,7 +74,7 @@ final class SamlProvider implements AuthenticationProviderInterface
public function supports(TokenInterface $token) public function supports(TokenInterface $token)
{ {
if (!$this->configuration->isSamlActive()) { if (!$this->configuration->isActivated()) {
return false; return false;
} }

View File

@@ -23,13 +23,13 @@
{% endblock %} {% endblock %}
{% block login_social_auth %} {% block login_social_auth %}
{% if kimai_config.samlActive %} {% if saml_config.isActivated() %}
{% set class = 'btn-primary' %} {% set class = 'btn-primary' %}
{% if kimai_config.loginFormActive %} {% if kimai_config.loginFormActive %}
{% set class = 'btn-google' %} {% set class = 'btn-google' %}
{% endif %} {% endif %}
<a href="{{ path('saml_login') }}" class="btn btn-block {{ class }}"> <a href="{{ path('saml_login') }}" class="btn btn-block {{ class }}">
<span>{{ kimai_config.samlTitle|trans }}</span> <span>{{ saml_config.getTitle()|trans }}</span>
</a> </a>
<br> <br>
{% endif %} {% endif %}

View File

@@ -9,6 +9,7 @@
namespace App\Tests\Controller\Auth; namespace App\Tests\Controller\Auth;
use App\Configuration\SamlConfiguration;
use App\Configuration\SystemConfiguration; use App\Configuration\SystemConfiguration;
use App\Controller\Auth\SamlController; use App\Controller\Auth\SamlController;
use App\Saml\SamlAuthFactory; use App\Saml\SamlAuthFactory;
@@ -53,9 +54,9 @@ class SamlControllerTest extends TestCase
return (new SamlAuthFactoryFactory($this))->create()->create(); return (new SamlAuthFactoryFactory($this))->create()->create();
} }
protected function getSystemConfiguration(bool $activated = true) protected function getSamlConfiguration(bool $activated = true): SamlConfiguration
{ {
return $this->getSystemConfigurationMock($this->getDefaultSettings($activated), []); return new SamlConfiguration($this->getSystemConfigurationMock($this->getDefaultSettings($activated), []));
} }
public function testAssertionConsumerServiceAction() public function testAssertionConsumerServiceAction()
@@ -65,7 +66,7 @@ class SamlControllerTest extends TestCase
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration()); $sut = new SamlController($factory, $this->getSamlConfiguration());
$sut->assertionConsumerServiceAction(); $sut->assertionConsumerServiceAction();
} }
@@ -76,7 +77,7 @@ class SamlControllerTest extends TestCase
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration()); $sut = new SamlController($factory, $this->getSamlConfiguration());
$sut->logoutAction(); $sut->logoutAction();
} }
@@ -111,7 +112,7 @@ EOD;
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$factory->expects($this->once())->method('create')->willReturn($oauth); $factory->expects($this->once())->method('create')->willReturn($oauth);
$sut = new SamlController($factory, $this->getSystemConfiguration()); $sut = new SamlController($factory, $this->getSamlConfiguration());
$result = $sut->metadataAction(); $result = $sut->metadataAction();
self::assertInstanceOf(Response::class, $result); self::assertInstanceOf(Response::class, $result);
@@ -140,7 +141,7 @@ EOD;
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration()); $sut = new SamlController($factory, $this->getSamlConfiguration());
$sut->loginAction($request); $sut->loginAction($request);
} }
@@ -151,7 +152,7 @@ EOD;
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration(false)); $sut = new SamlController($factory, $this->getSamlConfiguration(false));
$sut->loginAction(new Request()); $sut->loginAction(new Request());
} }
@@ -162,7 +163,7 @@ EOD;
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration(false)); $sut = new SamlController($factory, $this->getSamlConfiguration(false));
$sut->metadataAction(); $sut->metadataAction();
} }
@@ -173,7 +174,7 @@ EOD;
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration(false)); $sut = new SamlController($factory, $this->getSamlConfiguration(false));
$sut->logoutAction(); $sut->logoutAction();
} }
@@ -184,7 +185,7 @@ EOD;
$factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock(); $factory = $this->getMockBuilder(SamlAuthFactory::class)->disableOriginalConstructor()->getMock();
$sut = new SamlController($factory, $this->getSystemConfiguration(false)); $sut = new SamlController($factory, $this->getSamlConfiguration(false));
$sut->assertionConsumerServiceAction(); $sut->assertionConsumerServiceAction();
} }
} }

View File

@@ -9,8 +9,11 @@
namespace App\Tests\Controller\Security; namespace App\Tests\Controller\Security;
use App\Configuration\SamlConfiguration;
use App\Configuration\SystemConfiguration;
use App\Controller\Security\SecurityController; use App\Controller\Security\SecurityController;
use App\Entity\User; use App\Entity\User;
use App\Tests\Configuration\TestConfigLoader;
use App\Tests\Controller\ControllerBaseTest; use App\Tests\Controller\ControllerBaseTest;
use Symfony\Component\Security\Csrf\CsrfTokenManagerInterface; use Symfony\Component\Security\Csrf\CsrfTokenManagerInterface;
@@ -119,7 +122,9 @@ class SecurityControllerTest extends ControllerBaseTest
$client = self::createClient(); // just to bootstrap the container $client = self::createClient(); // just to bootstrap the container
$csrf = $this->createMock(CsrfTokenManagerInterface::class); $csrf = $this->createMock(CsrfTokenManagerInterface::class);
$sut = new SecurityController($csrf); $systemConfig = new SystemConfiguration(new TestConfigLoader([]), ['saml' => ['activate' => true]]);
$samlConfig = new SamlConfiguration($systemConfig);
$sut = new SecurityController($csrf, $samlConfig);
$sut->checkAction(); $sut->checkAction();
} }
@@ -130,7 +135,9 @@ class SecurityControllerTest extends ControllerBaseTest
$client = self::createClient(); // just to bootstrap the container $client = self::createClient(); // just to bootstrap the container
$csrf = $this->createMock(CsrfTokenManagerInterface::class); $csrf = $this->createMock(CsrfTokenManagerInterface::class);
$sut = new SecurityController($csrf); $systemConfig = new SystemConfiguration(new TestConfigLoader([]), ['saml' => ['activate' => true]]);
$samlConfig = new SamlConfiguration($systemConfig);
$sut = new SecurityController($csrf, $samlConfig);
$sut->logoutAction(); $sut->logoutAction();
} }
} }

View File

@@ -54,13 +54,14 @@ class SamlProviderTest extends TestCase
} }
$systemConfig = new SystemConfiguration(new TestConfigLoader([]), ['saml' => ['activate' => true]]); $systemConfig = new SystemConfiguration(new TestConfigLoader([]), ['saml' => ['activate' => true]]);
$samlConfig = new SamlConfiguration($systemConfig);
$repository = $this->getMockBuilder(UserRepository::class)->disableOriginalConstructor()->getMock(); $repository = $this->getMockBuilder(UserRepository::class)->disableOriginalConstructor()->getMock();
if ($user !== null) { if ($user !== null) {
$repository->expects($this->once())->method('loadUserByUsername')->willReturn($user); $repository->expects($this->once())->method('loadUserByUsername')->willReturn($user);
} }
$userProvider = new ChainUserProvider([new DoctrineUserProvider($repository)]); $userProvider = new ChainUserProvider([new DoctrineUserProvider($repository)]);
$provider = new SamlProvider($repository, $userProvider, new SamlTokenFactory(), $userFactory, $systemConfig); $provider = new SamlProvider($repository, $userProvider, new SamlTokenFactory(), $userFactory, $samlConfig);
return $provider; return $provider;
} }