@@ -72,6 +72,7 @@ const (
|
||||
RightsRequestEntityType uint16 = 48
|
||||
StateOfApplicabilityEntityType uint16 = 49
|
||||
StateOfApplicabilityControlEntityType uint16 = 50
|
||||
IdentityProfileEntityType uint16 = 51
|
||||
)
|
||||
|
||||
type EntityInfo struct {
|
||||
@@ -284,6 +285,10 @@ var entityRegistry = map[uint16]EntityInfo{
|
||||
Model: "StateOfApplicabilityControl",
|
||||
Table: "states_of_applicability_controls",
|
||||
},
|
||||
IdentityProfileEntityType: {
|
||||
Model: "IdentityProfile",
|
||||
Table: "iam_identity_profiles",
|
||||
},
|
||||
}
|
||||
|
||||
func EntityTable(entityType uint16) (string, bool) {
|
||||
|
||||
@@ -35,7 +35,6 @@ type (
|
||||
ID gid.GID `db:"id"`
|
||||
EmailAddress mail.Addr `db:"email_address"`
|
||||
HashedPassword []byte `db:"hashed_password"`
|
||||
FullName string `db:"fullname"`
|
||||
EmailAddressVerified bool `db:"email_address_verified"`
|
||||
SAMLSubject *string `db:"saml_subject"`
|
||||
CreatedAt time.Time `db:"created_at"`
|
||||
@@ -66,9 +65,8 @@ SELECT
|
||||
email_address,
|
||||
hashed_password,
|
||||
email_address_verified,
|
||||
fullname,
|
||||
created_at,
|
||||
updated_at
|
||||
created_at,
|
||||
updated_at
|
||||
FROM
|
||||
identities
|
||||
WHERE
|
||||
@@ -143,7 +141,6 @@ SELECT
|
||||
email_address,
|
||||
hashed_password,
|
||||
email_address_verified,
|
||||
fullname,
|
||||
saml_subject,
|
||||
created_at,
|
||||
updated_at
|
||||
@@ -186,8 +183,7 @@ SELECT
|
||||
id,
|
||||
email_address,
|
||||
hashed_password,
|
||||
email_address_verified,
|
||||
fullname,
|
||||
email_address_verified,
|
||||
saml_subject,
|
||||
created_at,
|
||||
updated_at
|
||||
@@ -225,13 +221,12 @@ func (i *Identity) Insert(
|
||||
) error {
|
||||
q := `
|
||||
INSERT INTO
|
||||
identities (id, email_address, hashed_password, email_address_verified, fullname, saml_subject, created_at, updated_at)
|
||||
identities (id, email_address, hashed_password, email_address_verified, saml_subject, created_at, updated_at)
|
||||
VALUES (
|
||||
@identity_id,
|
||||
@email_address,
|
||||
@hashed_password,
|
||||
@email_address_verified,
|
||||
@fullname,
|
||||
@saml_subject,
|
||||
@created_at,
|
||||
@updated_at
|
||||
@@ -242,7 +237,6 @@ VALUES (
|
||||
"identity_id": i.ID,
|
||||
"email_address": i.EmailAddress,
|
||||
"hashed_password": i.HashedPassword,
|
||||
"fullname": i.FullName,
|
||||
"saml_subject": i.SAMLSubject,
|
||||
"created_at": i.CreatedAt,
|
||||
"updated_at": i.UpdatedAt,
|
||||
@@ -273,8 +267,7 @@ SET
|
||||
email_address = @email_address,
|
||||
email_address_verified = @email_address_verified,
|
||||
saml_subject = @saml_subject,
|
||||
fullname = @fullname,
|
||||
hashed_password = @hashed_password,
|
||||
hashed_password = @hashed_password,
|
||||
updated_at = @updated_at
|
||||
WHERE
|
||||
id = @identity_id
|
||||
@@ -286,7 +279,6 @@ WHERE
|
||||
"email_address_verified": i.EmailAddressVerified,
|
||||
"saml_subject": i.SAMLSubject,
|
||||
"updated_at": i.UpdatedAt,
|
||||
"fullname": i.FullName,
|
||||
"hashed_password": i.HashedPassword,
|
||||
}
|
||||
|
||||
@@ -314,7 +306,6 @@ SELECT
|
||||
email_address,
|
||||
hashed_password,
|
||||
email_address_verified,
|
||||
fullname,
|
||||
saml_subject,
|
||||
created_at,
|
||||
updated_at
|
||||
|
||||
293
pkg/coredata/identity_profile.go
Normal file
293
pkg/coredata/identity_profile.go
Normal file
@@ -0,0 +1,293 @@
|
||||
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
|
||||
//
|
||||
// Permission to use, copy, modify, and/or distribute this software for any
|
||||
// purpose with or without fee is hereby granted, provided that the above
|
||||
// copyright notice and this permission notice appear in all copies.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
// PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
package coredata
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"maps"
|
||||
"time"
|
||||
|
||||
"github.com/jackc/pgx/v5"
|
||||
"go.gearno.de/kit/pg"
|
||||
"go.probo.inc/probo/pkg/gid"
|
||||
)
|
||||
|
||||
type (
|
||||
IdentityProfile struct {
|
||||
ID gid.GID `db:"id"`
|
||||
IdentityID gid.GID `db:"identity_id"`
|
||||
MembershipID *gid.GID `db:"membership_id"`
|
||||
FullName string `db:"full_name"`
|
||||
CreatedAt time.Time `db:"created_at"`
|
||||
UpdatedAt time.Time `db:"updated_at"`
|
||||
}
|
||||
|
||||
IdentityProfiles []*IdentityProfile
|
||||
)
|
||||
|
||||
func (p *IdentityProfile) IsDefault() bool {
|
||||
return p.MembershipID == nil
|
||||
}
|
||||
|
||||
// LoadDefaultByIdentityID loads the default profile for an identity (where membership_id is NULL)
|
||||
func (p *IdentityProfile) LoadDefaultByIdentityID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
identityID gid.GID,
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
id,
|
||||
identity_id,
|
||||
membership_id,
|
||||
full_name,
|
||||
created_at,
|
||||
updated_at
|
||||
FROM
|
||||
iam_identity_profiles
|
||||
WHERE
|
||||
tenant_id IS NULL
|
||||
AND identity_id = @identity_id
|
||||
AND membership_id IS NULL
|
||||
LIMIT 1;
|
||||
`
|
||||
|
||||
args := pgx.StrictNamedArgs{"identity_id": identityID}
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query default identity profile: %w", err)
|
||||
}
|
||||
|
||||
profile, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[IdentityProfile])
|
||||
if err != nil {
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return ErrResourceNotFound
|
||||
}
|
||||
|
||||
return fmt.Errorf("cannot collect default identity profile: %w", err)
|
||||
}
|
||||
|
||||
*p = profile
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// LoadByMembershipID loads the profile for a specific membership
|
||||
func (p *IdentityProfile) LoadByMembershipID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
membershipID gid.GID,
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
id,
|
||||
identity_id,
|
||||
membership_id,
|
||||
full_name,
|
||||
created_at,
|
||||
updated_at
|
||||
FROM
|
||||
iam_identity_profiles
|
||||
WHERE
|
||||
%s
|
||||
AND membership_id = @membership_id
|
||||
LIMIT 1;
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{"membership_id": membershipID}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query identity profile: %w", err)
|
||||
}
|
||||
|
||||
profile, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[IdentityProfile])
|
||||
if err != nil {
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return ErrResourceNotFound
|
||||
}
|
||||
|
||||
return fmt.Errorf("cannot collect identity profile: %w", err)
|
||||
}
|
||||
|
||||
*p = profile
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (p *IdentityProfile) LoadByID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
profileID gid.GID,
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
id,
|
||||
identity_id,
|
||||
membership_id,
|
||||
full_name,
|
||||
created_at,
|
||||
updated_at
|
||||
FROM
|
||||
iam_identity_profiles
|
||||
WHERE
|
||||
%s
|
||||
AND id = @profile_id
|
||||
LIMIT 1;
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{"profile_id": profileID}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query identity profile: %w", err)
|
||||
}
|
||||
|
||||
profile, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[IdentityProfile])
|
||||
if err != nil {
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return ErrResourceNotFound
|
||||
}
|
||||
|
||||
return fmt.Errorf("cannot collect identity profile: %w", err)
|
||||
}
|
||||
|
||||
*p = profile
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (p *IdentityProfile) Insert(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
) error {
|
||||
q := `
|
||||
INSERT INTO
|
||||
iam_identity_profiles (
|
||||
tenant_id,
|
||||
id,
|
||||
identity_id,
|
||||
membership_id,
|
||||
full_name,
|
||||
created_at,
|
||||
updated_at
|
||||
)
|
||||
VALUES (
|
||||
@tenant_id,
|
||||
@id,
|
||||
@identity_id,
|
||||
@membership_id,
|
||||
@full_name,
|
||||
@created_at,
|
||||
@updated_at
|
||||
)
|
||||
`
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"tenant_id": p.ID.TenantID().String(),
|
||||
"id": p.ID,
|
||||
"identity_id": p.IdentityID,
|
||||
"membership_id": p.MembershipID,
|
||||
"full_name": p.FullName,
|
||||
"created_at": p.CreatedAt,
|
||||
"updated_at": p.UpdatedAt,
|
||||
}
|
||||
|
||||
_, err := conn.Exec(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert identity profile: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (p *IdentityProfile) Update(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
) error {
|
||||
q := `
|
||||
UPDATE
|
||||
iam_identity_profiles
|
||||
SET
|
||||
full_name = @full_name,
|
||||
updated_at = @updated_at
|
||||
WHERE
|
||||
id = @id
|
||||
AND %s
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"id": p.ID,
|
||||
"full_name": p.FullName,
|
||||
"updated_at": p.UpdatedAt,
|
||||
}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
result, err := conn.Exec(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot update identity profile: %w", err)
|
||||
}
|
||||
|
||||
if result.RowsAffected() == 0 {
|
||||
return ErrResourceNotFound
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (p *IdentityProfile) Delete(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
profileID gid.GID,
|
||||
) error {
|
||||
q := `
|
||||
DELETE FROM
|
||||
iam_identity_profiles
|
||||
WHERE
|
||||
id = @profile_id
|
||||
AND %s
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{"profile_id": profileID}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
result, err := conn.Exec(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot delete identity profile: %w", err)
|
||||
}
|
||||
|
||||
if result.RowsAffected() == 0 {
|
||||
return ErrResourceNotFound
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -189,7 +189,7 @@ SELECT
|
||||
mbr.identity_id,
|
||||
mbr.organization_id,
|
||||
mbr.role,
|
||||
i.fullname as full_name,
|
||||
COALESCE(mp.full_name, dp.full_name, '') as full_name,
|
||||
i.email_address,
|
||||
mbr.created_at,
|
||||
mbr.updated_at
|
||||
@@ -197,6 +197,10 @@ FROM
|
||||
mbr
|
||||
JOIN
|
||||
identities i ON mbr.identity_id = i.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles mp ON mp.membership_id = mbr.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles dp ON dp.identity_id = mbr.identity_id AND dp.membership_id IS NULL
|
||||
`
|
||||
|
||||
query = fmt.Sprintf(query, scope.SQLFragment())
|
||||
@@ -329,7 +333,7 @@ SELECT
|
||||
mbr.identity_id,
|
||||
mbr.organization_id,
|
||||
mbr.role,
|
||||
i.fullname as full_name,
|
||||
COALESCE(mp.full_name, dp.full_name, '') as full_name,
|
||||
i.email_address,
|
||||
mbr.created_at,
|
||||
mbr.updated_at
|
||||
@@ -337,6 +341,10 @@ FROM
|
||||
mbr
|
||||
JOIN
|
||||
identities i ON mbr.identity_id = i.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles mp ON mp.membership_id = mbr.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles dp ON dp.identity_id = mbr.identity_id AND dp.membership_id IS NULL
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
@@ -455,7 +463,7 @@ SELECT
|
||||
mbr.identity_id,
|
||||
mbr.organization_id,
|
||||
mbr.role,
|
||||
i.fullname as full_name,
|
||||
COALESCE(mp.full_name, dp.full_name, '') as full_name,
|
||||
i.email_address,
|
||||
mbr.created_at,
|
||||
mbr.updated_at
|
||||
@@ -463,6 +471,10 @@ FROM
|
||||
mbr
|
||||
JOIN
|
||||
identities i ON mbr.identity_id = i.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles mp ON mp.membership_id = mbr.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles dp ON dp.identity_id = mbr.identity_id AND dp.membership_id IS NULL
|
||||
ORDER BY
|
||||
mbr.created_at DESC
|
||||
`
|
||||
@@ -520,19 +532,23 @@ SELECT
|
||||
created_at,
|
||||
updated_at
|
||||
FROM (
|
||||
SELECT
|
||||
mbr.id,
|
||||
mbr.identity_id,
|
||||
mbr.organization_id,
|
||||
mbr.role,
|
||||
i.fullname as full_name,
|
||||
i.email_address,
|
||||
mbr.created_at,
|
||||
mbr.updated_at
|
||||
FROM
|
||||
mbr
|
||||
JOIN
|
||||
identities i ON mbr.identity_id = i.id
|
||||
SELECT
|
||||
mbr.id,
|
||||
mbr.identity_id,
|
||||
mbr.organization_id,
|
||||
mbr.role,
|
||||
COALESCE(mp.full_name, dp.full_name, '') as full_name,
|
||||
i.email_address,
|
||||
mbr.created_at,
|
||||
mbr.updated_at
|
||||
FROM
|
||||
mbr
|
||||
JOIN
|
||||
identities i ON mbr.identity_id = i.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles mp ON mp.membership_id = mbr.id
|
||||
LEFT JOIN
|
||||
iam_identity_profiles dp ON dp.identity_id = mbr.identity_id AND dp.membership_id IS NULL
|
||||
) AS membership_with_identity
|
||||
WHERE %s
|
||||
`
|
||||
|
||||
12
pkg/coredata/migrations/20251220T140915Z.sql
Normal file
12
pkg/coredata/migrations/20251220T140915Z.sql
Normal file
@@ -0,0 +1,12 @@
|
||||
CREATE TABLE iam_identity_profiles (
|
||||
tenant_id TEXT NOT NULL,
|
||||
id TEXT NOT NULL PRIMARY KEY,
|
||||
identity_id TEXT NOT NULL REFERENCES identities(id) ON DELETE CASCADE,
|
||||
membership_id TEXT REFERENCES iam_memberships(id) ON DELETE CASCADE,
|
||||
full_name TEXT NOT NULL,
|
||||
created_at TIMESTAMPTZ NOT NULL,
|
||||
updated_at TIMESTAMPTZ NOT NULL
|
||||
);
|
||||
|
||||
CREATE UNIQUE INDEX idx_iam_identity_profiles_default ON iam_identity_profiles(identity_id) WHERE membership_id IS NULL;
|
||||
CREATE UNIQUE INDEX idx_iam_identity_profiles_membership ON iam_identity_profiles(membership_id) WHERE membership_id IS NOT NULL;
|
||||
32
pkg/coredata/migrations/20251221T222519Z.sql
Normal file
32
pkg/coredata/migrations/20251221T222519Z.sql
Normal file
@@ -0,0 +1,32 @@
|
||||
INSERT INTO iam_identity_profiles (tenant_id, id, identity_id, membership_id, full_name, created_at, updated_at)
|
||||
SELECT
|
||||
'',
|
||||
generate_gid('\x0000000000000000'::bytea, 51),
|
||||
i.id,
|
||||
NULL,
|
||||
COALESCE(i.fullname, ''),
|
||||
i.created_at,
|
||||
NOW()
|
||||
FROM identities i
|
||||
WHERE NOT EXISTS (
|
||||
SELECT 1 FROM iam_identity_profiles p
|
||||
WHERE p.identity_id = i.id AND p.membership_id IS NULL
|
||||
);
|
||||
|
||||
INSERT INTO iam_identity_profiles (tenant_id, id, identity_id, membership_id, full_name, created_at, updated_at)
|
||||
SELECT
|
||||
m.tenant_id,
|
||||
generate_gid(decode_base64_unpadded(m.tenant_id), 51),
|
||||
m.identity_id,
|
||||
m.id,
|
||||
COALESCE(i.fullname, ''),
|
||||
m.created_at,
|
||||
NOW()
|
||||
FROM iam_memberships m
|
||||
JOIN identities i ON i.id = m.identity_id
|
||||
WHERE NOT EXISTS (
|
||||
SELECT 1 FROM iam_identity_profiles p
|
||||
WHERE p.membership_id = m.id
|
||||
);
|
||||
|
||||
ALTER TABLE identities DROP COLUMN fullname;
|
||||
@@ -125,9 +125,14 @@ func (s AccountService) ChangeEmail(ctx context.Context, identityID gid.GID, req
|
||||
return fmt.Errorf("cannot update identity: %w", err)
|
||||
}
|
||||
|
||||
profile := &coredata.IdentityProfile{}
|
||||
if err := profile.LoadDefaultByIdentityID(ctx, tx, identityID); err != nil {
|
||||
return fmt.Errorf("cannot load default profile: %w", err)
|
||||
}
|
||||
|
||||
subject, textBody, htmlBody, err := emails.RenderConfirmEmail(
|
||||
s.baseURL,
|
||||
identity.FullName,
|
||||
profile.FullName,
|
||||
confirmationUrl,
|
||||
)
|
||||
if err != nil {
|
||||
@@ -135,7 +140,7 @@ func (s AccountService) ChangeEmail(ctx context.Context, identityID gid.GID, req
|
||||
}
|
||||
|
||||
confirmationEmail := coredata.NewEmail(
|
||||
identity.FullName,
|
||||
profile.FullName,
|
||||
identity.EmailAddress,
|
||||
subject,
|
||||
textBody,
|
||||
@@ -714,3 +719,157 @@ func (s AccountService) ListOrganizations(ctx context.Context, identityID gid.GI
|
||||
|
||||
return organizations, nil
|
||||
}
|
||||
|
||||
func (s AccountService) GetProfileForMembership(ctx context.Context, membershipID gid.GID) (*coredata.IdentityProfile, error) {
|
||||
var (
|
||||
scope = coredata.NewScopeFromObjectID(membershipID)
|
||||
profile = &coredata.IdentityProfile{}
|
||||
)
|
||||
|
||||
err := s.pg.WithConn(
|
||||
ctx,
|
||||
func(conn pg.Conn) error {
|
||||
membership := &coredata.Membership{}
|
||||
err := membership.LoadByID(ctx, conn, scope, membershipID)
|
||||
if err != nil {
|
||||
if err == coredata.ErrResourceNotFound {
|
||||
return NewMembershipNotFoundError(membershipID)
|
||||
}
|
||||
|
||||
return fmt.Errorf("cannot load membership: %w", err)
|
||||
}
|
||||
|
||||
err = profile.LoadByMembershipID(ctx, conn, scope, membershipID)
|
||||
if err != nil {
|
||||
if err == coredata.ErrResourceNotFound {
|
||||
return NewProfileNotFoundError(membershipID)
|
||||
}
|
||||
|
||||
return fmt.Errorf("cannot load identity profile: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
},
|
||||
)
|
||||
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return profile, nil
|
||||
}
|
||||
|
||||
func (s AccountService) GetDefaultProfile(ctx context.Context, identityID gid.GID) (*coredata.IdentityProfile, error) {
|
||||
var profile = &coredata.IdentityProfile{}
|
||||
|
||||
err := s.pg.WithConn(
|
||||
ctx,
|
||||
func(conn pg.Conn) error {
|
||||
err := profile.LoadDefaultByIdentityID(ctx, conn, identityID)
|
||||
if err != nil {
|
||||
if err == coredata.ErrResourceNotFound {
|
||||
return NewProfileNotFoundError(identityID)
|
||||
}
|
||||
|
||||
return fmt.Errorf("cannot load default profile: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
},
|
||||
)
|
||||
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return profile, nil
|
||||
}
|
||||
|
||||
type UpdateIdentityProfileRequest struct {
|
||||
MembershipID gid.GID
|
||||
FullName *string
|
||||
}
|
||||
|
||||
func (s AccountService) UpdateIdentityProfile(
|
||||
ctx context.Context,
|
||||
identityID gid.GID,
|
||||
req *UpdateIdentityProfileRequest,
|
||||
) (*coredata.IdentityProfile, error) {
|
||||
// var (
|
||||
// scope = coredata.NewScopeFromObjectID(req.MembershipID)
|
||||
// profile = &coredata.IdentityProfile{}
|
||||
// )
|
||||
|
||||
// err := s.pg.WithTx(
|
||||
// ctx,
|
||||
// func(tx pg.Conn) error {
|
||||
// // First verify the membership belongs to the identity
|
||||
// membership := &coredata.Membership{}
|
||||
// err := membership.LoadByID(ctx, tx, scope, req.MembershipID)
|
||||
// if err != nil {
|
||||
// if err == coredata.ErrResourceNotFound {
|
||||
// return NewMembershipNotFoundError(req.MembershipID)
|
||||
// }
|
||||
|
||||
// return fmt.Errorf("cannot load membership: %w", err)
|
||||
// }
|
||||
|
||||
// if membership.IdentityID != identityID {
|
||||
// return NewMembershipNotFoundError(req.MembershipID)
|
||||
// }
|
||||
|
||||
// // Try to load existing membership profile
|
||||
// err = profile.LoadByMembershipID(ctx, tx, scope, req.MembershipID)
|
||||
// if err != nil && err != coredata.ErrResourceNotFound {
|
||||
// return fmt.Errorf("cannot load identity profile: %w", err)
|
||||
// }
|
||||
|
||||
// now := time.Now()
|
||||
|
||||
// if err == coredata.ErrResourceNotFound {
|
||||
// // Create new membership profile, optionally inheriting from default
|
||||
// tenantID := req.MembershipID.TenantID()
|
||||
// membershipID := req.MembershipID
|
||||
|
||||
// // Try to get default profile to inherit FullName
|
||||
// defaultProfile := &coredata.IdentityProfile{}
|
||||
// defaultFullName := ""
|
||||
// if loadErr := defaultProfile.LoadDefaultByIdentityID(ctx, tx, identityID); loadErr == nil {
|
||||
// defaultFullName = defaultProfile.FullName
|
||||
// }
|
||||
|
||||
// tenantIDStr := tenantID.String()
|
||||
// profile = &coredata.IdentityProfile{
|
||||
// ID: gid.New(tenantID, coredata.IdentityProfileEntityType),
|
||||
// TenantID: &tenantIDStr,
|
||||
// IdentityID: identityID,
|
||||
// MembershipID: &membershipID,
|
||||
// FullName: defaultFullName,
|
||||
// CreatedAt: now,
|
||||
// UpdatedAt: now,
|
||||
// }
|
||||
// }
|
||||
|
||||
// // Apply updates
|
||||
// if req.FullName != nil {
|
||||
// profile.FullName = *req.FullName
|
||||
// }
|
||||
// profile.UpdatedAt = now
|
||||
|
||||
// // Upsert the membership profile
|
||||
// err = profile.UpsertMembership(ctx, tx)
|
||||
// if err != nil {
|
||||
// return fmt.Errorf("cannot upsert identity profile: %w", err)
|
||||
// }
|
||||
|
||||
// return nil
|
||||
// },
|
||||
// )
|
||||
|
||||
// if err != nil {
|
||||
// return nil, err
|
||||
// }
|
||||
|
||||
// return profile, nil
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
@@ -158,7 +158,6 @@ func (s *AuthService) CreateIdentityFromInvitation(
|
||||
EmailAddress: invitation.Email,
|
||||
HashedPassword: hashedPassword,
|
||||
EmailAddressVerified: true,
|
||||
FullName: invitation.FullName,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
@@ -172,6 +171,19 @@ func (s *AuthService) CreateIdentityFromInvitation(
|
||||
return fmt.Errorf("cannot insert identity: %w", err)
|
||||
}
|
||||
|
||||
defaultProfile := &coredata.IdentityProfile{
|
||||
ID: gid.New(gid.NilTenant, coredata.IdentityProfileEntityType),
|
||||
IdentityID: identity.ID,
|
||||
FullName: invitation.FullName,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
|
||||
err = defaultProfile.Insert(ctx, tx)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert default profile: %w", err)
|
||||
}
|
||||
|
||||
session = coredata.NewRootSession(identity.ID, coredata.AuthMethodPassword, s.sessionDuration)
|
||||
err = session.Insert(ctx, tx)
|
||||
if err != nil {
|
||||
@@ -273,9 +285,14 @@ func (s AuthService) SendPasswordResetInstructionByEmail(
|
||||
return fmt.Errorf("cannot load identity: %w", err)
|
||||
}
|
||||
|
||||
profile := &coredata.IdentityProfile{}
|
||||
if err := profile.LoadDefaultByIdentityID(ctx, tx, identity.ID); err != nil {
|
||||
return fmt.Errorf("cannot load default profile: %w", err)
|
||||
}
|
||||
|
||||
subject, textBody, htmlBody, err := emails.RenderPasswordReset(
|
||||
s.baseURL,
|
||||
identity.FullName,
|
||||
profile.FullName,
|
||||
resetPasswordUrl,
|
||||
)
|
||||
if err != nil {
|
||||
@@ -283,7 +300,7 @@ func (s AuthService) SendPasswordResetInstructionByEmail(
|
||||
}
|
||||
|
||||
passwordResetEmail := coredata.NewEmail(
|
||||
identity.FullName,
|
||||
profile.FullName,
|
||||
identity.EmailAddress,
|
||||
subject,
|
||||
textBody,
|
||||
@@ -325,11 +342,18 @@ func (s AuthService) CreateIdentityWithPassword(
|
||||
EmailAddress: req.Email,
|
||||
HashedPassword: hashedPassword,
|
||||
EmailAddressVerified: false,
|
||||
FullName: req.FullName,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
|
||||
defaultProfile = &coredata.IdentityProfile{
|
||||
ID: gid.New(gid.NilTenant, coredata.IdentityProfileEntityType),
|
||||
IdentityID: identity.ID,
|
||||
FullName: req.FullName,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
|
||||
session = coredata.NewRootSession(identity.ID, coredata.AuthMethodPassword, 24*time.Hour*7)
|
||||
)
|
||||
|
||||
@@ -358,7 +382,7 @@ func (s AuthService) CreateIdentityWithPassword(
|
||||
|
||||
subject, textBody, htmlBody, err := emails.RenderConfirmEmail(
|
||||
s.baseURL,
|
||||
identity.FullName,
|
||||
req.FullName,
|
||||
confirmationUrl,
|
||||
)
|
||||
if err != nil {
|
||||
@@ -366,7 +390,7 @@ func (s AuthService) CreateIdentityWithPassword(
|
||||
}
|
||||
|
||||
confirmationEmail := coredata.NewEmail(
|
||||
identity.FullName,
|
||||
req.FullName,
|
||||
identity.EmailAddress,
|
||||
subject,
|
||||
textBody,
|
||||
@@ -385,6 +409,11 @@ func (s AuthService) CreateIdentityWithPassword(
|
||||
return fmt.Errorf("cannot insert identity: %w", err)
|
||||
}
|
||||
|
||||
err = defaultProfile.Insert(ctx, tx)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert default profile: %w", err)
|
||||
}
|
||||
|
||||
if err := confirmationEmail.Insert(ctx, tx); err != nil {
|
||||
return fmt.Errorf("cannot insert email: %w", err)
|
||||
}
|
||||
|
||||
@@ -200,6 +200,16 @@ func (e ErrPersonalAPIKeyNotFound) Error() string {
|
||||
return fmt.Sprintf("personal API key %q not found", e.PersonalAPIKeyID)
|
||||
}
|
||||
|
||||
type ErrProfileNotFound struct{ MembershipID gid.GID }
|
||||
|
||||
func NewProfileNotFoundError(membershipID gid.GID) error {
|
||||
return &ErrProfileNotFound{MembershipID: membershipID}
|
||||
}
|
||||
|
||||
func (e ErrProfileNotFound) Error() string {
|
||||
return fmt.Sprintf("profile for membership %q not found", e.MembershipID)
|
||||
}
|
||||
|
||||
type ErrPersonalAPIKeyExpired struct{ PersonalAPIKeyID gid.GID }
|
||||
|
||||
func NewPersonalAPIKeyExpiredError(personalAPIKeyID gid.GID) error {
|
||||
|
||||
@@ -260,7 +260,6 @@ func (s *Service) HandleAssertion(
|
||||
EmailAddress: email,
|
||||
HashedPassword: nil,
|
||||
EmailAddressVerified: true,
|
||||
FullName: fullname,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
@@ -269,11 +268,23 @@ func (s *Service) HandleAssertion(
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert identity: %w", err)
|
||||
}
|
||||
|
||||
defaultProfile := &coredata.IdentityProfile{
|
||||
ID: gid.New(gid.NilTenant, coredata.IdentityProfileEntityType),
|
||||
IdentityID: identity.ID,
|
||||
FullName: fullname,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
|
||||
err = defaultProfile.Insert(ctx, tx)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert default profile: %w", err)
|
||||
}
|
||||
} else if err != nil {
|
||||
return fmt.Errorf("cannot load identity: %w", err)
|
||||
} else {
|
||||
identity.SAMLSubject = &assertion.Subject.NameID.Value
|
||||
identity.FullName = fullname
|
||||
identity.EmailAddress = email
|
||||
identity.EmailAddressVerified = true
|
||||
identity.UpdatedAt = now
|
||||
@@ -304,6 +315,20 @@ func (s *Service) HandleAssertion(
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert membership: %w", err)
|
||||
}
|
||||
|
||||
membershipProfile := &coredata.IdentityProfile{
|
||||
ID: gid.New(membership.ID.TenantID(), coredata.IdentityProfileEntityType),
|
||||
IdentityID: identity.ID,
|
||||
MembershipID: &membership.ID,
|
||||
FullName: fullname,
|
||||
CreatedAt: now,
|
||||
UpdatedAt: now,
|
||||
}
|
||||
|
||||
err = membershipProfile.Insert(ctx, tx)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert membership profile: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
if role != nil {
|
||||
@@ -316,6 +341,19 @@ func (s *Service) HandleAssertion(
|
||||
}
|
||||
}
|
||||
|
||||
memberProfile := &coredata.IdentityProfile{}
|
||||
err = memberProfile.LoadByMembershipID(ctx, tx, coredata.NewNoScope(), membership.ID)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot load membership profile: %w", err)
|
||||
}
|
||||
|
||||
memberProfile.FullName = fullname
|
||||
memberProfile.UpdatedAt = now
|
||||
err = memberProfile.Update(ctx, tx, coredata.NewNoScope())
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot update membership profile: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
},
|
||||
)
|
||||
|
||||
@@ -138,6 +138,8 @@ type Identity implements Node {
|
||||
createdAt: Datetime!
|
||||
updatedAt: Datetime!
|
||||
|
||||
defaultProfile: IdentityProfile @goField(forceResolver: true) @isViewer
|
||||
|
||||
memberships(
|
||||
first: Int
|
||||
after: CursorKey
|
||||
@@ -168,27 +170,12 @@ type Identity implements Node {
|
||||
last: Int
|
||||
before: CursorKey
|
||||
): PersonalAPIKeyConnection @goField(forceResolver: true) @isViewer
|
||||
|
||||
profileFor(organizationId: ID!): IdentityProfile @isViewer
|
||||
}
|
||||
|
||||
type IdentityProfile implements Node {
|
||||
id: ID!
|
||||
displayName: String!
|
||||
firstName: String
|
||||
lastName: String
|
||||
jobTitle: String
|
||||
department: String
|
||||
phoneNumber: String
|
||||
avatarUrl: String
|
||||
manager: IdentityProfile
|
||||
timezone: String
|
||||
locale: String
|
||||
customAttributes: [CustomAttribute!]!
|
||||
provisionedBy: ProvisioningSource!
|
||||
externalId: String
|
||||
fullName: String!
|
||||
identity: Identity!
|
||||
organization: Organization!
|
||||
createdAt: Datetime!
|
||||
updatedAt: Datetime!
|
||||
}
|
||||
@@ -244,8 +231,8 @@ enum MembershipRole
|
||||
type Membership implements Node {
|
||||
id: ID!
|
||||
createdAt: Datetime!
|
||||
profile: IdentityProfile!
|
||||
identity: Identity @goField(forceResolver: true)
|
||||
profile: IdentityProfile @goField(forceResolver: true) @isViewer
|
||||
organization: Organization @goField(forceResolver: true)
|
||||
role: MembershipRole!
|
||||
permissions: [Permission!]!
|
||||
@@ -382,12 +369,6 @@ enum SAMLEnforcementPolicy
|
||||
)
|
||||
}
|
||||
|
||||
enum AuthMethod {
|
||||
PASSWORD
|
||||
SAML
|
||||
RECOVERY_CODE
|
||||
}
|
||||
|
||||
enum TokenScope {
|
||||
READ_ORGANIZATION
|
||||
WRITE_ORGANIZATION
|
||||
@@ -578,14 +559,7 @@ input AssumeOrganizationSessionInput {
|
||||
|
||||
input UpdateIdentityProfileInput {
|
||||
membershipId: ID!
|
||||
displayName: String
|
||||
firstName: String
|
||||
lastName: String
|
||||
jobTitle: String
|
||||
department: String
|
||||
phoneNumber: String
|
||||
timezone: String
|
||||
locale: String
|
||||
fullName: String
|
||||
}
|
||||
|
||||
input RevokeSessionInput {
|
||||
@@ -750,10 +724,6 @@ type DeactivateAccountPayload {
|
||||
success: Boolean!
|
||||
}
|
||||
|
||||
type DeleteAccountPayload {
|
||||
success: Boolean!
|
||||
}
|
||||
|
||||
type UpdateIdentityProfilePayload {
|
||||
profile: IdentityProfile
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
26
pkg/server/api/connect/v1/types/identity_profile.go
Normal file
26
pkg/server/api/connect/v1/types/identity_profile.go
Normal file
@@ -0,0 +1,26 @@
|
||||
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
|
||||
//
|
||||
// Permission to use, copy, modify, and/or distribute this software for any
|
||||
// purpose with or without fee is hereby granted, provided that the above
|
||||
// copyright notice and this permission notice appear in all copies.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
// PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
package types
|
||||
|
||||
import "go.probo.inc/probo/pkg/coredata"
|
||||
|
||||
func NewIdentityProfile(profile *coredata.IdentityProfile) *IdentityProfile {
|
||||
return &IdentityProfile{
|
||||
ID: profile.ID,
|
||||
FullName: profile.FullName,
|
||||
CreatedAt: profile.CreatedAt,
|
||||
UpdatedAt: profile.UpdatedAt,
|
||||
}
|
||||
}
|
||||
@@ -71,5 +71,8 @@ func NewInvitation(invitation *coredata.Invitation) *Invitation {
|
||||
AcceptedAt: invitation.AcceptedAt,
|
||||
CreatedAt: invitation.CreatedAt,
|
||||
Status: invitation.Status,
|
||||
Organization: &Organization{
|
||||
ID: invitation.OrganizationID,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
@@ -61,9 +61,14 @@ func NewMembershipEdge(membership *coredata.Membership, orderField coredata.Memb
|
||||
|
||||
func NewMembership(membership *coredata.Membership) *Membership {
|
||||
return &Membership{
|
||||
ID: membership.ID,
|
||||
IdentityID: membership.IdentityID,
|
||||
CreatedAt: membership.CreatedAt,
|
||||
ID: membership.ID,
|
||||
CreatedAt: membership.CreatedAt,
|
||||
Identity: &Identity{
|
||||
ID: membership.IdentityID,
|
||||
},
|
||||
Organization: &Organization{
|
||||
ID: membership.OrganizationID,
|
||||
},
|
||||
// Permissions: membership.Permissions,
|
||||
// ProvisionedBy: membership.ProvisionedBy,
|
||||
// Active: membership.Active,
|
||||
|
||||
@@ -61,12 +61,14 @@ func NewSessionEdge(session *coredata.Session, orderField coredata.SessionOrderF
|
||||
|
||||
func NewSession(session *coredata.Session) *Session {
|
||||
return &Session{
|
||||
ID: session.ID,
|
||||
IPAddress: session.IPAddress.String(),
|
||||
IdentityID: session.IdentityID,
|
||||
UserAgent: session.UserAgent,
|
||||
UpdatedAt: session.UpdatedAt,
|
||||
CreatedAt: session.CreatedAt,
|
||||
ExpiresAt: session.ExpiredAt,
|
||||
ID: session.ID,
|
||||
Identity: &Identity{
|
||||
ID: session.IdentityID,
|
||||
},
|
||||
IPAddress: session.IPAddress.String(),
|
||||
UserAgent: session.UserAgent,
|
||||
UpdatedAt: session.UpdatedAt,
|
||||
CreatedAt: session.CreatedAt,
|
||||
ExpiresAt: session.ExpiredAt,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -33,12 +33,6 @@ type AcceptInvitationPayload struct {
|
||||
MembershipEdge *MembershipEdge `json:"membershipEdge"`
|
||||
}
|
||||
|
||||
type AddIPAllowlistEntryInput struct {
|
||||
OrganizationID gid.GID `json:"organizationId"`
|
||||
Cidr string `json:"cidr"`
|
||||
Description *string `json:"description,omitempty"`
|
||||
}
|
||||
|
||||
type Application struct {
|
||||
ID ApplicationID `json:"id"`
|
||||
Name string `json:"name"`
|
||||
@@ -108,28 +102,10 @@ type CreateSAMLConfigurationPayload struct {
|
||||
SamlConfigurationEdge *SAMLConfigurationEdge `json:"samlConfigurationEdge"`
|
||||
}
|
||||
|
||||
type CustomAttribute struct {
|
||||
Key string `json:"key"`
|
||||
Value string `json:"value"`
|
||||
}
|
||||
|
||||
type DeactivateAccountInput struct {
|
||||
Password string `json:"password"`
|
||||
}
|
||||
|
||||
type DeactivateAccountPayload struct {
|
||||
Success bool `json:"success"`
|
||||
}
|
||||
|
||||
type DeleteAccountInput struct {
|
||||
Password string `json:"password"`
|
||||
Confirmation string `json:"confirmation"`
|
||||
}
|
||||
|
||||
type DeleteAccountPayload struct {
|
||||
Success bool `json:"success"`
|
||||
}
|
||||
|
||||
type DeleteInvitationInput struct {
|
||||
OrganizationID gid.GID `json:"organizationId"`
|
||||
InvitationID gid.GID `json:"invitationId"`
|
||||
@@ -178,35 +154,22 @@ type Identity struct {
|
||||
EmailVerified bool `json:"emailVerified"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
UpdatedAt time.Time `json:"updatedAt"`
|
||||
DefaultProfile *IdentityProfile `json:"defaultProfile,omitempty"`
|
||||
Memberships *MembershipConnection `json:"memberships,omitempty"`
|
||||
PendingInvitations *InvitationConnection `json:"pendingInvitations,omitempty"`
|
||||
Sessions *SessionConnection `json:"sessions,omitempty"`
|
||||
PersonalAPIKeys *PersonalAPIKeyConnection `json:"personalAPIKeys,omitempty"`
|
||||
ProfileFor *IdentityProfile `json:"profileFor,omitempty"`
|
||||
}
|
||||
|
||||
func (Identity) IsNode() {}
|
||||
func (this Identity) GetID() gid.GID { return this.ID }
|
||||
|
||||
type IdentityProfile struct {
|
||||
ID gid.GID `json:"id"`
|
||||
DisplayName string `json:"displayName"`
|
||||
FirstName *string `json:"firstName,omitempty"`
|
||||
LastName *string `json:"lastName,omitempty"`
|
||||
JobTitle *string `json:"jobTitle,omitempty"`
|
||||
Department *string `json:"department,omitempty"`
|
||||
PhoneNumber *string `json:"phoneNumber,omitempty"`
|
||||
AvatarURL *string `json:"avatarUrl,omitempty"`
|
||||
Manager *IdentityProfile `json:"manager,omitempty"`
|
||||
Timezone *string `json:"timezone,omitempty"`
|
||||
Locale *string `json:"locale,omitempty"`
|
||||
CustomAttributes []*CustomAttribute `json:"customAttributes"`
|
||||
ProvisionedBy ProvisioningSource `json:"provisionedBy"`
|
||||
ExternalID *string `json:"externalId,omitempty"`
|
||||
Identity *Identity `json:"identity"`
|
||||
Organization *Organization `json:"organization"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
UpdatedAt time.Time `json:"updatedAt"`
|
||||
ID gid.GID `json:"id"`
|
||||
FullName string `json:"fullName"`
|
||||
Identity *Identity `json:"identity"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
UpdatedAt time.Time `json:"updatedAt"`
|
||||
}
|
||||
|
||||
func (IdentityProfile) IsNode() {}
|
||||
@@ -242,18 +205,14 @@ type InviteMemberPayload struct {
|
||||
}
|
||||
|
||||
type Membership struct {
|
||||
ID gid.GID `json:"id"`
|
||||
IdentityID gid.GID `json:"identityId"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
Profile *IdentityProfile `json:"profile"`
|
||||
Identity *Identity `json:"identity,omitempty"`
|
||||
Organization *Organization `json:"organization,omitempty"`
|
||||
Role coredata.MembershipRole `json:"role"`
|
||||
Permissions []*Permission `json:"permissions"`
|
||||
ProvisionedBy ProvisioningSource `json:"provisionedBy"`
|
||||
Active bool `json:"active"`
|
||||
LastSyncedAt *time.Time `json:"lastSyncedAt,omitempty"`
|
||||
LastSession *Session `json:"lastSession,omitempty"`
|
||||
ID gid.GID `json:"id"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
Identity *Identity `json:"identity,omitempty"`
|
||||
Profile *IdentityProfile `json:"profile,omitempty"`
|
||||
Organization *Organization `json:"organization,omitempty"`
|
||||
Role coredata.MembershipRole `json:"role"`
|
||||
Permissions []*Permission `json:"permissions"`
|
||||
LastSession *Session `json:"lastSession,omitempty"`
|
||||
}
|
||||
|
||||
func (Membership) IsNode() {}
|
||||
@@ -346,10 +305,6 @@ type PersonalAPIKeyEdge struct {
|
||||
type Query struct {
|
||||
}
|
||||
|
||||
type RemoveIPAllowlistEntryInput struct {
|
||||
EntryID gid.GID `json:"entryId"`
|
||||
}
|
||||
|
||||
type RemoveMemberInput struct {
|
||||
OrganizationID gid.GID `json:"organizationId"`
|
||||
MembershipID gid.GID `json:"membershipId"`
|
||||
@@ -442,13 +397,13 @@ type SSOAvailability struct {
|
||||
}
|
||||
|
||||
type Session struct {
|
||||
ID gid.GID `json:"id"`
|
||||
IdentityID gid.GID `json:"identityId"`
|
||||
IPAddress string `json:"ipAddress"`
|
||||
UserAgent string `json:"userAgent"`
|
||||
UpdatedAt time.Time `json:"updatedAt"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
ExpiresAt time.Time `json:"expiresAt"`
|
||||
ID gid.GID `json:"id"`
|
||||
Identity *Identity `json:"identity,omitempty"`
|
||||
IPAddress string `json:"ipAddress"`
|
||||
UserAgent string `json:"userAgent"`
|
||||
UpdatedAt time.Time `json:"updatedAt"`
|
||||
CreatedAt time.Time `json:"createdAt"`
|
||||
ExpiresAt time.Time `json:"expiresAt"`
|
||||
}
|
||||
|
||||
func (Session) IsNode() {}
|
||||
@@ -464,20 +419,6 @@ type SessionOrder struct {
|
||||
Field coredata.SessionOrderField `json:"field"`
|
||||
}
|
||||
|
||||
type SessionPolicy struct {
|
||||
MaxSessionDurationHours int `json:"maxSessionDurationHours"`
|
||||
IdleTimeoutMinutes int `json:"idleTimeoutMinutes"`
|
||||
MaxConcurrentSessions *int `json:"maxConcurrentSessions,omitempty"`
|
||||
RequireReauthForSensitiveActions bool `json:"requireReauthForSensitiveActions"`
|
||||
}
|
||||
|
||||
type SessionPolicyInput struct {
|
||||
MaxSessionDurationHours *int `json:"maxSessionDurationHours,omitempty"`
|
||||
IdleTimeoutMinutes *int `json:"idleTimeoutMinutes,omitempty"`
|
||||
MaxConcurrentSessions *int `json:"maxConcurrentSessions,omitempty"`
|
||||
RequireReauthForSensitiveActions *bool `json:"requireReauthForSensitiveActions,omitempty"`
|
||||
}
|
||||
|
||||
type SignInInput struct {
|
||||
Email mail.Addr `json:"email"`
|
||||
Password string `json:"password"`
|
||||
@@ -513,14 +454,7 @@ type SignUpPayload struct {
|
||||
|
||||
type UpdateIdentityProfileInput struct {
|
||||
MembershipID gid.GID `json:"membershipId"`
|
||||
DisplayName *string `json:"displayName,omitempty"`
|
||||
FirstName *string `json:"firstName,omitempty"`
|
||||
LastName *string `json:"lastName,omitempty"`
|
||||
JobTitle *string `json:"jobTitle,omitempty"`
|
||||
Department *string `json:"department,omitempty"`
|
||||
PhoneNumber *string `json:"phoneNumber,omitempty"`
|
||||
Timezone *string `json:"timezone,omitempty"`
|
||||
Locale *string `json:"locale,omitempty"`
|
||||
FullName *string `json:"fullName,omitempty"`
|
||||
}
|
||||
|
||||
type UpdateIdentityProfilePayload struct {
|
||||
@@ -699,63 +633,6 @@ func (e ApplicationID) MarshalJSON() ([]byte, error) {
|
||||
return buf.Bytes(), nil
|
||||
}
|
||||
|
||||
type AuthMethod string
|
||||
|
||||
const (
|
||||
AuthMethodPassword AuthMethod = "PASSWORD"
|
||||
AuthMethodSaml AuthMethod = "SAML"
|
||||
AuthMethodRecoveryCode AuthMethod = "RECOVERY_CODE"
|
||||
)
|
||||
|
||||
var AllAuthMethod = []AuthMethod{
|
||||
AuthMethodPassword,
|
||||
AuthMethodSaml,
|
||||
AuthMethodRecoveryCode,
|
||||
}
|
||||
|
||||
func (e AuthMethod) IsValid() bool {
|
||||
switch e {
|
||||
case AuthMethodPassword, AuthMethodSaml, AuthMethodRecoveryCode:
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func (e AuthMethod) String() string {
|
||||
return string(e)
|
||||
}
|
||||
|
||||
func (e *AuthMethod) UnmarshalGQL(v any) error {
|
||||
str, ok := v.(string)
|
||||
if !ok {
|
||||
return fmt.Errorf("enums must be strings")
|
||||
}
|
||||
|
||||
*e = AuthMethod(str)
|
||||
if !e.IsValid() {
|
||||
return fmt.Errorf("%s is not a valid AuthMethod", str)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (e AuthMethod) MarshalGQL(w io.Writer) {
|
||||
fmt.Fprint(w, strconv.Quote(e.String()))
|
||||
}
|
||||
|
||||
func (e *AuthMethod) UnmarshalJSON(b []byte) error {
|
||||
s, err := strconv.Unquote(string(b))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return e.UnmarshalGQL(s)
|
||||
}
|
||||
|
||||
func (e AuthMethod) MarshalJSON() ([]byte, error) {
|
||||
var buf bytes.Buffer
|
||||
e.MarshalGQL(&buf)
|
||||
return buf.Bytes(), nil
|
||||
}
|
||||
|
||||
type PrincipalType string
|
||||
|
||||
const (
|
||||
@@ -811,63 +688,6 @@ func (e PrincipalType) MarshalJSON() ([]byte, error) {
|
||||
return buf.Bytes(), nil
|
||||
}
|
||||
|
||||
type ProvisioningSource string
|
||||
|
||||
const (
|
||||
ProvisioningSourceManual ProvisioningSource = "MANUAL"
|
||||
ProvisioningSourceInvitation ProvisioningSource = "INVITATION"
|
||||
ProvisioningSourceSaml ProvisioningSource = "SAML"
|
||||
)
|
||||
|
||||
var AllProvisioningSource = []ProvisioningSource{
|
||||
ProvisioningSourceManual,
|
||||
ProvisioningSourceInvitation,
|
||||
ProvisioningSourceSaml,
|
||||
}
|
||||
|
||||
func (e ProvisioningSource) IsValid() bool {
|
||||
switch e {
|
||||
case ProvisioningSourceManual, ProvisioningSourceInvitation, ProvisioningSourceSaml:
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func (e ProvisioningSource) String() string {
|
||||
return string(e)
|
||||
}
|
||||
|
||||
func (e *ProvisioningSource) UnmarshalGQL(v any) error {
|
||||
str, ok := v.(string)
|
||||
if !ok {
|
||||
return fmt.Errorf("enums must be strings")
|
||||
}
|
||||
|
||||
*e = ProvisioningSource(str)
|
||||
if !e.IsValid() {
|
||||
return fmt.Errorf("%s is not a valid ProvisioningSource", str)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (e ProvisioningSource) MarshalGQL(w io.Writer) {
|
||||
fmt.Fprint(w, strconv.Quote(e.String()))
|
||||
}
|
||||
|
||||
func (e *ProvisioningSource) UnmarshalJSON(b []byte) error {
|
||||
s, err := strconv.Unquote(string(b))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return e.UnmarshalGQL(s)
|
||||
}
|
||||
|
||||
func (e ProvisioningSource) MarshalJSON() ([]byte, error) {
|
||||
var buf bytes.Buffer
|
||||
e.MarshalGQL(&buf)
|
||||
return buf.Bytes(), nil
|
||||
}
|
||||
|
||||
type ReauthenticationReason string
|
||||
|
||||
const (
|
||||
|
||||
@@ -24,6 +24,17 @@ import (
|
||||
"go.probo.inc/probo/pkg/server/gqlutils/types/cursor"
|
||||
)
|
||||
|
||||
// DefaultProfile is the resolver for the defaultProfile field.
|
||||
func (r *identityResolver) DefaultProfile(ctx context.Context, obj *types.Identity) (*types.IdentityProfile, error) {
|
||||
profile, err := r.iam.AccountService.GetDefaultProfile(ctx, obj.ID)
|
||||
if err != nil {
|
||||
r.logger.ErrorCtx(ctx, "cannot get default profile", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewIdentityProfile(profile), nil
|
||||
}
|
||||
|
||||
// Memberships is the resolver for the memberships field.
|
||||
func (r *identityResolver) Memberships(ctx context.Context, obj *types.Identity, first *int, after *page.CursorKey, last *int, before *page.CursorKey, orderBy *types.MembershipOrderBy) (*types.MembershipConnection, error) {
|
||||
pageOrderBy := page.OrderBy[coredata.MembershipOrderField]{
|
||||
@@ -41,7 +52,8 @@ func (r *identityResolver) Memberships(ctx context.Context, obj *types.Identity,
|
||||
|
||||
page, err := r.iam.AccountService.ListMemberships(ctx, obj.ID, cursor)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot list memberships: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot list memberships", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewMembershipConnection(page, r, obj.ID), nil
|
||||
@@ -58,7 +70,8 @@ func (r *identityResolver) PendingInvitations(ctx context.Context, obj *types.Id
|
||||
|
||||
page, err := r.iam.AccountService.ListPendingInvitations(ctx, obj.ID, cursor)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot list pending invitations: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot list pending invitations", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewInvitationConnection(page, r, obj.ID, nil), nil
|
||||
@@ -81,7 +94,8 @@ func (r *identityResolver) Sessions(ctx context.Context, obj *types.Identity, fi
|
||||
|
||||
page, err := r.iam.AccountService.ListSessions(ctx, obj.ID, cursor)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot list sessions: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot list sessions", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewSessionConnection(page, r, obj.ID), nil
|
||||
@@ -98,7 +112,8 @@ func (r *identityResolver) PersonalAPIKeys(ctx context.Context, obj *types.Ident
|
||||
|
||||
page, err := r.iam.AccountService.ListPersonalAPIKeys(ctx, obj.ID, cursor)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot list personal api keys: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot list personal api keys", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewPersonalAPIKeyConnection(page, r, obj.ID), nil
|
||||
@@ -108,7 +123,8 @@ func (r *identityResolver) PersonalAPIKeys(ctx context.Context, obj *types.Ident
|
||||
func (r *invitationResolver) Organization(ctx context.Context, obj *types.Invitation) (*types.Organization, error) {
|
||||
organization, err := r.iam.OrganizationService.GetOrganizationForInvitation(ctx, obj.ID)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot get organization for invitation: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot get organization for invitation", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewOrganization(organization), nil
|
||||
@@ -120,31 +136,51 @@ func (r *invitationConnectionResolver) TotalCount(ctx context.Context, obj *type
|
||||
case *organizationResolver:
|
||||
count, err := r.iam.OrganizationService.CountInvitations(ctx, obj.ParentID, obj.Filters)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot count invitations: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot count invitations", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
return &count, nil
|
||||
case *identityResolver:
|
||||
count, err := r.iam.AccountService.CountPendingInvitations(ctx, obj.ParentID)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot count invitations: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot count invitations", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return &count, nil
|
||||
}
|
||||
|
||||
panic(fmt.Errorf("unsupported resolver: %T", obj.Resolver))
|
||||
r.logger.ErrorCtx(ctx, "unsupported resolver", log.Any("resolver", obj.Resolver))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
// Identity is the resolver for the identity field.
|
||||
func (r *membershipResolver) Identity(ctx context.Context, obj *types.Membership) (*types.Identity, error) {
|
||||
identity, err := r.iam.AccountService.GetIdentityForMembership(ctx, obj.ID)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot get identity: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot get identity for membership", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewIdentity(identity), nil
|
||||
}
|
||||
|
||||
// Profile is the resolver for the profile field.
|
||||
func (r *membershipResolver) Profile(ctx context.Context, obj *types.Membership) (*types.IdentityProfile, error) {
|
||||
profile, err := r.iam.AccountService.GetProfileForMembership(ctx, obj.ID)
|
||||
if err != nil {
|
||||
var errProfileNotFound *iam.ErrProfileNotFound
|
||||
if errors.As(err, &errProfileNotFound) {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
r.logger.ErrorCtx(ctx, "cannot get profile for membership", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewIdentityProfile(profile), nil
|
||||
}
|
||||
|
||||
// Organization is the resolver for the organization field.
|
||||
func (r *membershipResolver) Organization(ctx context.Context, obj *types.Membership) (*types.Organization, error) {
|
||||
organization, err := r.iam.OrganizationService.GetOrganizationForMembership(ctx, obj.ID)
|
||||
@@ -517,7 +553,29 @@ func (r *mutationResolver) AssumeOrganizationSession(ctx context.Context, input
|
||||
|
||||
// UpdateIdentityProfile is the resolver for the updateIdentityProfile field.
|
||||
func (r *mutationResolver) UpdateIdentityProfile(ctx context.Context, input types.UpdateIdentityProfileInput) (*types.UpdateIdentityProfilePayload, error) {
|
||||
panic(fmt.Errorf("not implemented: UpdateIdentityProfile - updateIdentityProfile"))
|
||||
identity := IdentityFromContext(ctx)
|
||||
|
||||
profile, err := r.iam.AccountService.UpdateIdentityProfile(
|
||||
ctx,
|
||||
identity.ID,
|
||||
&iam.UpdateIdentityProfileRequest{
|
||||
MembershipID: input.MembershipID,
|
||||
FullName: input.FullName,
|
||||
},
|
||||
)
|
||||
if err != nil {
|
||||
var errMembershipNotFound *iam.ErrMembershipNotFound
|
||||
if errors.As(err, &errMembershipNotFound) {
|
||||
return nil, gqlutils.NotFound(err)
|
||||
}
|
||||
|
||||
r.logger.ErrorCtx(ctx, "cannot update identity profile", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return &types.UpdateIdentityProfilePayload{
|
||||
Profile: types.NewIdentityProfile(profile),
|
||||
}, nil
|
||||
}
|
||||
|
||||
// RevokeSession is the resolver for the revokeSession field.
|
||||
@@ -801,7 +859,8 @@ func (r *mutationResolver) CreateSAMLConfiguration(ctx context.Context, input ty
|
||||
)
|
||||
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot create saml configuration: %w", err))
|
||||
r.logger.ErrorCtx(ctx, "cannot create saml configuration", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return &types.CreateSAMLConfigurationPayload{
|
||||
@@ -1095,6 +1154,17 @@ func (r *sAMLConfigurationConnectionResolver) TotalCount(ctx context.Context, ob
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
// Identity is the resolver for the identity field.
|
||||
func (r *sessionResolver) Identity(ctx context.Context, obj *types.Session) (*types.Identity, error) {
|
||||
identity, err := r.iam.AccountService.GetIdentity(ctx, obj.Identity.ID)
|
||||
if err != nil {
|
||||
r.logger.ErrorCtx(ctx, "cannot get identity for session", log.Error(err))
|
||||
return nil, gqlutils.InternalServerError(ctx)
|
||||
}
|
||||
|
||||
return types.NewIdentity(identity), nil
|
||||
}
|
||||
|
||||
// TotalCount is the resolver for the totalCount field.
|
||||
func (r *sessionConnectionResolver) TotalCount(ctx context.Context, obj *types.SessionConnection) (*int, error) {
|
||||
switch obj.Resolver.(type) {
|
||||
@@ -1150,6 +1220,9 @@ func (r *Resolver) SAMLConfigurationConnection() schema.SAMLConfigurationConnect
|
||||
return &sAMLConfigurationConnectionResolver{r}
|
||||
}
|
||||
|
||||
// Session returns schema.SessionResolver implementation.
|
||||
func (r *Resolver) Session() schema.SessionResolver { return &sessionResolver{r} }
|
||||
|
||||
// SessionConnection returns schema.SessionConnectionResolver implementation.
|
||||
func (r *Resolver) SessionConnection() schema.SessionConnectionResolver {
|
||||
return &sessionConnectionResolver{r}
|
||||
@@ -1165,4 +1238,5 @@ type organizationResolver struct{ *Resolver }
|
||||
type personalAPIKeyConnectionResolver struct{ *Resolver }
|
||||
type queryResolver struct{ *Resolver }
|
||||
type sAMLConfigurationConnectionResolver struct{ *Resolver }
|
||||
type sessionResolver struct{ *Resolver }
|
||||
type sessionConnectionResolver struct{ *Resolver }
|
||||
|
||||
@@ -2167,14 +2167,21 @@ func (r *mutationResolver) ExportFramework(ctx context.Context, input types.Expo
|
||||
prb := r.ProboService(ctx, input.FrameworkID.TenantID())
|
||||
identity := connect_v1.IdentityFromContext(ctx)
|
||||
|
||||
err, exportJobID := prb.Frameworks.RequestExport(
|
||||
// Load default profile to get the full name
|
||||
recipientName := ""
|
||||
profile, err := r.iam.AccountService.GetDefaultProfile(ctx, identity.ID)
|
||||
if err == nil {
|
||||
recipientName = profile.FullName
|
||||
}
|
||||
|
||||
exportErr, exportJobID := prb.Frameworks.RequestExport(
|
||||
ctx,
|
||||
input.FrameworkID,
|
||||
identity.EmailAddress,
|
||||
identity.FullName,
|
||||
recipientName,
|
||||
)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot export framework: %w", err))
|
||||
if exportErr != nil {
|
||||
panic(fmt.Errorf("cannot export framework: %w", exportErr))
|
||||
}
|
||||
|
||||
return &types.ExportFrameworkPayload{
|
||||
@@ -3345,15 +3352,22 @@ func (r *mutationResolver) BulkExportDocuments(ctx context.Context, input types.
|
||||
|
||||
identity := connect_v1.IdentityFromContext(ctx)
|
||||
|
||||
// Load default profile to get the full name
|
||||
recipientName := ""
|
||||
profile, err := r.iam.AccountService.GetDefaultProfile(ctx, identity.ID)
|
||||
if err == nil {
|
||||
recipientName = profile.FullName
|
||||
}
|
||||
|
||||
options := probo.ExportPDFOptions{
|
||||
WithWatermark: input.WithWatermark,
|
||||
WithSignatures: input.WithSignatures,
|
||||
WatermarkEmail: input.WatermarkEmail,
|
||||
}
|
||||
|
||||
documentExport, err := prb.Documents.RequestExport(ctx, input.DocumentIds, identity.EmailAddress, identity.FullName, options)
|
||||
if err != nil {
|
||||
panic(fmt.Errorf("cannot request document export: %w", err))
|
||||
documentExport, exportErr := prb.Documents.RequestExport(ctx, input.DocumentIds, identity.EmailAddress, recipientName, options)
|
||||
if exportErr != nil {
|
||||
panic(fmt.Errorf("cannot request document export: %w", exportErr))
|
||||
}
|
||||
|
||||
return &types.BulkExportDocumentsPayload{
|
||||
|
||||
Reference in New Issue
Block a user