OidcSecuritySetting.jsx 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293
  1. /* eslint-disable react/no-danger */
  2. import React from 'react';
  3. import PropTypes from 'prop-types';
  4. import { withTranslation } from 'react-i18next';
  5. import { createSubscribedElement } from '../../UnstatedUtils';
  6. import AppContainer from '../../../services/AppContainer';
  7. import AdminGeneralSecurityContainer from '../../../services/AdminGeneralSecurityContainer';
  8. import AdminOidcSecurityContainer from '../../../services/AdminOidcSecurityContainer';
  9. class OidcSecurityManagement extends React.Component {
  10. render() {
  11. const { t, adminGeneralSecurityContainer, adminOidcSecurityContainer } = this.props;
  12. return (
  13. <React.Fragment>
  14. <h2 className="alert-anchor border-bottom">
  15. { t('security_setting.OAuth.OIDC.name') } { t('security_setting.configuration') }
  16. </h2>
  17. <div className="row mb-5">
  18. <strong className="col-xs-3 text-right">{ t('security_setting.OAuth.OIDC.name') }</strong>
  19. <div className="col-xs-6 text-left">
  20. <div className="checkbox checkbox-success">
  21. <input
  22. id="isOidcEnabled"
  23. type="checkbox"
  24. checked={adminGeneralSecurityContainer.state.isOidcEnabled}
  25. onChange={() => { adminGeneralSecurityContainer.switchIsOidcEnabled() }}
  26. />
  27. <label htmlFor="isOidcEnabled">
  28. { t('security_setting.OAuth.enable_oidc') }
  29. </label>
  30. </div>
  31. </div>
  32. </div>
  33. <div className="row mb-5">
  34. <label className="col-xs-3 text-right">{ t('security_setting.callback_URL') }</label>
  35. <div className="col-xs-6">
  36. <input
  37. className="form-control"
  38. type="text"
  39. value={adminOidcSecurityContainer.state.callbackUrl}
  40. readOnly
  41. />
  42. <p className="help-block small">{ t('security_setting.desc_of_callback_URL', { AuthName: 'OAuth' }) }</p>
  43. {!adminGeneralSecurityContainer.state.appSiteUrl && (
  44. <div className="alert alert-danger">
  45. <i
  46. className="icon-exclamation"
  47. // eslint-disable-next-line max-len
  48. dangerouslySetInnerHTML={{ __html: t('security_setting.alert_siteUrl_is_not_set', { link: `<a href="/admin/app">${t('App settings')}<i class="icon-login"></i></a>` }) }}
  49. />
  50. </div>
  51. )}
  52. </div>
  53. </div>
  54. {adminGeneralSecurityContainer.state.isOidcEnabled && (
  55. <React.Fragment>
  56. <div className="row mb-5">
  57. <label htmlFor="oidcProviderName" className="col-xs-3 text-right">{ t('security_setting.providerName') }</label>
  58. <div className="col-xs-6">
  59. <input
  60. className="form-control"
  61. type="text"
  62. name="oidcProviderName"
  63. value={adminOidcSecurityContainer.state.oidcProviderName}
  64. onChange={e => adminOidcSecurityContainer.changeOidcProviderName(e.target.value)}
  65. />
  66. </div>
  67. </div>
  68. <div className="row mb-5">
  69. <label htmlFor="oidcIssuerHost" className="col-xs-3 text-right">{ t('security_setting.issuerHost') }</label>
  70. <div className="col-xs-6">
  71. <input
  72. className="form-control"
  73. type="text"
  74. name="oidcIssuerHost"
  75. value={adminOidcSecurityContainer.state.oidcIssuerHost}
  76. onChange={e => adminOidcSecurityContainer.changeOidcIssuerHost(e.target.value)}
  77. />
  78. <p className="help-block">
  79. <small dangerouslySetInnerHTML={{ __html: t('security_setting.Use env var if empty', { env: 'OAUTH_OIDC_ISSUER_HOST' }) }} />
  80. </p>
  81. </div>
  82. </div>
  83. <div className="row mb-5">
  84. <label htmlFor="oidcClientId" className="col-xs-3 text-right">{ t('security_setting.clientID') }</label>
  85. <div className="col-xs-6">
  86. <input
  87. className="form-control"
  88. type="text"
  89. name="oidcClientId"
  90. value={adminOidcSecurityContainer.state.oidcClientId}
  91. onChange={e => adminOidcSecurityContainer.changeOidcClientId(e.target.value)}
  92. />
  93. <p className="help-block">
  94. <small dangerouslySetInnerHTML={{ __html: t('security_setting.Use env var if empty', { env: 'OAUTH_OIDC_CLIENT_ID' }) }} />
  95. </p>
  96. </div>
  97. </div>
  98. <div className="row mb-5">
  99. <label htmlFor="oidcClientSecret" className="col-xs-3 text-right">{ t('security_setting.client_secret') }</label>
  100. <div className="col-xs-6">
  101. <input
  102. className="form-control"
  103. type="text"
  104. name="oidcClientSecret"
  105. value={adminOidcSecurityContainer.state.oidcClientSecret}
  106. onChange={e => adminOidcSecurityContainer.changeOidcClientSecret(e.target.value)}
  107. />
  108. <p className="help-block">
  109. <small dangerouslySetInnerHTML={{ __html: t('security_setting.Use env var if empty', { env: 'OAUTH_OIDC_CLIENT_SECRET' }) }} />
  110. </p>
  111. </div>
  112. </div>
  113. <h3 className="alert-anchor border-bottom">
  114. Attribute Mapping ({ t('security_setting.optional') })
  115. </h3>
  116. <div className="row mb-5">
  117. <label htmlFor="oidcAttrMapId" className="col-xs-3 text-right">Identifier</label>
  118. <div className="col-xs-6">
  119. <input
  120. className="form-control"
  121. type="text"
  122. name="oidcAttrMapId"
  123. value={adminOidcSecurityContainer.state.oidcAttrMapId}
  124. onChange={e => adminOidcSecurityContainer.changeOidcAttrMapId(e.target.value)}
  125. />
  126. <p className="help-block">
  127. <small dangerouslySetInnerHTML={{ __html: t('security_setting.OAuth.OIDC.id_detail') }} />
  128. </p>
  129. </div>
  130. </div>
  131. <div className="row mb-5">
  132. <label htmlFor="oidcAttrMapUserName" className="col-xs-3 text-right">{ t('username') }</label>
  133. <div className="col-xs-6">
  134. <input
  135. className="form-control"
  136. type="text"
  137. name="oidcAttrMapUserName"
  138. value={adminOidcSecurityContainer.state.oidcAttrMapUserName}
  139. onChange={e => adminOidcSecurityContainer.changeOidcAttrMapUserName(e.target.value)}
  140. />
  141. <p className="help-block">
  142. <small dangerouslySetInnerHTML={{ __html: t('security_setting.OAuth.OIDC.username_detail') }} />
  143. </p>
  144. </div>
  145. </div>
  146. <div className="row mb-5">
  147. <label htmlFor="oidcAttrMapName" className="col-xs-3 text-right">{ t('Name') }</label>
  148. <div className="col-xs-6">
  149. <input
  150. className="form-control"
  151. type="text"
  152. name="oidcAttrMapName"
  153. value={adminOidcSecurityContainer.state.oidcAttrMapName}
  154. onChange={e => adminOidcSecurityContainer.changeOidcAttrMapName(e.target.value)}
  155. />
  156. <p className="help-block">
  157. <small dangerouslySetInnerHTML={{ __html: t('security_setting.OAuth.OIDC.name_detail') }} />
  158. </p>
  159. </div>
  160. </div>
  161. <div className="row mb-5">
  162. <label htmlFor="oidcAttrMapEmail" className="col-xs-3 text-right">{ t('Email') }</label>
  163. <div className="col-xs-6">
  164. <input
  165. className="form-control"
  166. type="text"
  167. name="oidcAttrMapEmail"
  168. value={adminOidcSecurityContainer.state.oidcAttrMapEmail}
  169. onChange={e => adminOidcSecurityContainer.changeOidcAttrMapEmail(e.target.value)}
  170. />
  171. <p className="help-block">
  172. <small dangerouslySetInnerHTML={{ __html: t('security_setting.OAuth.OIDC.mapping_detail', { target: t('Email') }) }} />
  173. </p>
  174. </div>
  175. </div>
  176. <div className="row mb-5">
  177. <label className="col-xs-3 text-right">{ t('security_setting.callback_URL') }</label>
  178. <div className="col-xs-6">
  179. <input
  180. className="form-control"
  181. type="text"
  182. value={adminOidcSecurityContainer.state.callbackUrl}
  183. readOnly
  184. />
  185. <p className="help-block small">{ t('security_setting.desc_of_callback_URL', { AuthName: 'OAuth' }) }</p>
  186. {!adminGeneralSecurityContainer.state.appSiteUrl && (
  187. <div className="alert alert-danger">
  188. <i
  189. className="icon-exclamation"
  190. // eslint-disable-next-line max-len
  191. dangerouslySetInnerHTML={{ __html: t('security_setting.alert_siteUrl_is_not_set', { link: `<a href="/admin/app">${t('App settings')}<i class="icon-login"></i></a>` }) }}
  192. />
  193. </div>
  194. )}
  195. </div>
  196. </div>
  197. <div className="row mb-3">
  198. <div className="col-xs-offset-3 col-xs-6 text-left">
  199. <div className="checkbox checkbox-success">
  200. <input
  201. id="bindByUserName-oidc"
  202. type="checkbox"
  203. checked={adminOidcSecurityContainer.state.isSameUsernameTreatedAsIdenticalUser}
  204. onChange={() => { adminOidcSecurityContainer.switchIsSameUsernameTreatedAsIdenticalUser() }}
  205. />
  206. <label
  207. htmlFor="bindByUserName-oidc"
  208. dangerouslySetInnerHTML={{ __html: t('security_setting.Treat username matching as identical') }}
  209. />
  210. </div>
  211. <p className="help-block">
  212. <small dangerouslySetInnerHTML={{ __html: t('security_setting.Treat username matching as identical_warn') }} />
  213. </p>
  214. </div>
  215. </div>
  216. <div className="row mb-5">
  217. <div className="col-xs-offset-3 col-xs-6 text-left">
  218. <div className="checkbox checkbox-success">
  219. <input
  220. id="bindByEmail-oidc"
  221. type="checkbox"
  222. checked={adminOidcSecurityContainer.state.isSameEmailTreatedAsIdenticalUser}
  223. onChange={() => { adminOidcSecurityContainer.switchIsSameEmailTreatedAsIdenticalUser() }}
  224. />
  225. <label
  226. htmlFor="bindByEmail-oidc"
  227. dangerouslySetInnerHTML={{ __html: t('security_setting.Treat email matching as identical') }}
  228. />
  229. </div>
  230. <p className="help-block">
  231. <small dangerouslySetInnerHTML={{ __html: t('security_setting.Treat email matching as identical_warn') }} />
  232. </p>
  233. </div>
  234. </div>
  235. </React.Fragment>
  236. )}
  237. <hr />
  238. <div style={{ minHeight: '300px' }}>
  239. <h4>
  240. <i className="icon-question" aria-hidden="true"></i>
  241. <a href="#collapseHelpForOidcOauth" data-toggle="collapse">{ t('security_setting.OAuth.how_to.oidc') }</a>
  242. </h4>
  243. <ol id="collapseHelpForOidcOauth" className="collapse">
  244. <li>{ t('security_setting.OAuth.OIDC.register_1') }</li>
  245. <li>{ t('security_setting.OAuth.OIDC.register_2') }</li>
  246. <li>{ t('security_setting.OAuth.OIDC.register_3') }</li>
  247. </ol>
  248. </div>
  249. </React.Fragment>
  250. );
  251. }
  252. }
  253. OidcSecurityManagement.propTypes = {
  254. t: PropTypes.func.isRequired, // i18next
  255. appContainer: PropTypes.instanceOf(AppContainer).isRequired,
  256. adminGeneralSecurityContainer: PropTypes.instanceOf(AdminGeneralSecurityContainer).isRequired,
  257. adminOidcSecurityContainer: PropTypes.instanceOf(AdminOidcSecurityContainer).isRequired,
  258. };
  259. const OidcSecurityManagementWrapper = (props) => {
  260. return createSubscribedElement(OidcSecurityManagement, props, [AppContainer, AdminGeneralSecurityContainer, AdminOidcSecurityContainer]);
  261. };
  262. export default withTranslation()(OidcSecurityManagementWrapper);