Harden compliance portal auth and TLS
Align console references and OAuth branding with the compliance-page model, and fix certificate cache eviction, portal OAuth handlers, and magic-link edge cases left after the trust-center rename. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -580,6 +580,19 @@ func (s AuthService) SendMagicLink(ctx context.Context, req *SendMagicLinkReques
|
||||
return fmt.Errorf("cannot generate magic link token: %w", err)
|
||||
}
|
||||
|
||||
senderName := magicLinkDefaultSenderName
|
||||
|
||||
if req.OAuth2ClientIDRaw != nil && *req.OAuth2ClientIDRaw != "" {
|
||||
branding, err := s.OAuth2ServerService.ClientBranding(ctx, *req.OAuth2ClientIDRaw)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot load oauth2 client branding: %w", err)
|
||||
}
|
||||
|
||||
if branding != nil {
|
||||
senderName = branding.Name
|
||||
}
|
||||
}
|
||||
|
||||
return s.pg.WithTx(
|
||||
ctx,
|
||||
func(ctx context.Context, tx pg.Tx) error {
|
||||
@@ -596,7 +609,6 @@ func (s AuthService) SendMagicLink(ctx context.Context, req *SendMagicLinkReques
|
||||
|
||||
fullName := req.Email.Username()
|
||||
identity := &coredata.Identity{}
|
||||
senderName := magicLinkDefaultSenderName
|
||||
|
||||
if err := identity.LoadByEmail(ctx, tx, req.Email); err == nil {
|
||||
if identity.FullName != "" {
|
||||
@@ -608,17 +620,6 @@ func (s AuthService) SendMagicLink(ctx context.Context, req *SendMagicLinkReques
|
||||
}
|
||||
}
|
||||
|
||||
if req.OAuth2ClientIDRaw != nil && *req.OAuth2ClientIDRaw != "" {
|
||||
branding, err := s.OAuth2ServerService.ClientBranding(ctx, *req.OAuth2ClientIDRaw)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot load oauth2 client branding: %w", err)
|
||||
}
|
||||
|
||||
if branding != nil {
|
||||
senderName = branding.Name
|
||||
}
|
||||
}
|
||||
|
||||
emailPresenterCfg := emails.DefaultPresenterConfig(s.baseURL)
|
||||
|
||||
if req.MagicLinkBaseURL != nil {
|
||||
|
||||
Reference in New Issue
Block a user