Add configurable invitation token validity
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
@@ -1,4 +1,6 @@
|
||||
probod:
|
||||
auth:
|
||||
invitation-confirmation-token-validity: 3600
|
||||
api:
|
||||
cors:
|
||||
allowed-origins: ["http://localhost:8080", "http://localhost:5173"]
|
||||
|
||||
@@ -21,9 +21,10 @@ import (
|
||||
|
||||
type (
|
||||
authConfig struct {
|
||||
Cookie cookieConfig `json:"cookie"`
|
||||
Password passwordConfig `json:"password"`
|
||||
DisableSignup bool `json:"disable-signup"`
|
||||
Cookie cookieConfig `json:"cookie"`
|
||||
Password passwordConfig `json:"password"`
|
||||
DisableSignup bool `json:"disable-signup"`
|
||||
InvitationConfirmationTokenValidity int `json:"invitation-confirmation-token-validity"`
|
||||
}
|
||||
|
||||
trustAuthConfig struct {
|
||||
|
||||
@@ -99,7 +99,8 @@ func New() *Implm {
|
||||
Duration: 24,
|
||||
Domain: "localhost",
|
||||
},
|
||||
DisableSignup: false,
|
||||
DisableSignup: false,
|
||||
InvitationConfirmationTokenValidity: 3600,
|
||||
},
|
||||
TrustAuth: trustAuthConfig{
|
||||
CookieName: "TCT",
|
||||
@@ -235,6 +236,7 @@ func (impl *Implm) Run(
|
||||
impl.cfg.Auth.Cookie.Secret,
|
||||
impl.cfg.Hostname,
|
||||
impl.cfg.Auth.DisableSignup,
|
||||
time.Duration(impl.cfg.Auth.InvitationConfirmationTokenValidity)*time.Second,
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot create usrmgr service: %w", err)
|
||||
|
||||
@@ -32,11 +32,12 @@ import (
|
||||
|
||||
type (
|
||||
Service struct {
|
||||
pg *pg.Client
|
||||
hp *passwdhash.Profile
|
||||
hostname string
|
||||
tokenSecret string
|
||||
disableSignup bool
|
||||
pg *pg.Client
|
||||
hp *passwdhash.Profile
|
||||
hostname string
|
||||
tokenSecret string
|
||||
disableSignup bool
|
||||
invitationTokenValidity time.Duration
|
||||
}
|
||||
|
||||
ErrInvalidCredentials struct {
|
||||
@@ -168,13 +169,15 @@ func NewService(
|
||||
tokenSecret string,
|
||||
hostname string,
|
||||
disableSignup bool,
|
||||
invitationTokenValidity time.Duration,
|
||||
) (*Service, error) {
|
||||
return &Service{
|
||||
pg: pgClient,
|
||||
hp: hp,
|
||||
hostname: hostname,
|
||||
tokenSecret: tokenSecret,
|
||||
disableSignup: disableSignup,
|
||||
pg: pgClient,
|
||||
hp: hp,
|
||||
hostname: hostname,
|
||||
tokenSecret: tokenSecret,
|
||||
disableSignup: disableSignup,
|
||||
invitationTokenValidity: invitationTokenValidity,
|
||||
}, nil
|
||||
}
|
||||
|
||||
@@ -710,7 +713,7 @@ func (s Service) InviteUser(
|
||||
confirmationToken, err := statelesstoken.NewToken(
|
||||
s.tokenSecret,
|
||||
TokenTypeOrganizationInvitation,
|
||||
12*time.Hour,
|
||||
s.invitationTokenValidity,
|
||||
InvitationData{OrganizationID: organizationID, Email: emailAddress, FullName: fullName},
|
||||
)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user