Auth: Remove Email Lookup from oauth integrations 8.5 (#899)

backport https://github.com/grafana/grafana-private-mirror/pull/894 to 8.5.x
This commit is contained in:
Ieva
2023-06-07 08:12:33 +02:00
committed by Horst Gutmann
parent e4fd9da88e
commit 2b60228f42
2 changed files with 22 additions and 17 deletions
+9 -8
View File
@@ -307,16 +307,17 @@ func (hs *HTTPServer) SyncUser(
connect social.SocialConnector,
) (*models.User, error) {
oauthLogger.Debug("Syncing Grafana user with corresponding OAuth profile")
lookupParams := models.UserLookupParams{}
if hs.Cfg.OAuthAllowInsecureEmailLookup {
lookupParams.Email = &extUser.Email
}
// add/update user in Grafana
cmd := &models.UpsertUserCommand{
ReqContext: ctx,
ExternalUser: extUser,
SignupAllowed: connect.IsSignupAllowed(),
UserLookupParams: models.UserLookupParams{
Email: &extUser.Email,
UserID: nil,
Login: nil,
},
ReqContext: ctx,
ExternalUser: extUser,
SignupAllowed: connect.IsSignupAllowed(),
UserLookupParams: lookupParams,
}
if err := hs.Login.UpsertUser(ctx.Req.Context(), cmd); err != nil {
+13 -9
View File
@@ -288,15 +288,16 @@ type Cfg struct {
DefaultHomeDashboardPath string
// Auth
LoginCookieName string
LoginMaxInactiveLifetime time.Duration
LoginMaxLifetime time.Duration
TokenRotationIntervalMinutes int
SigV4AuthEnabled bool
SigV4VerboseLogging bool
BasicAuthEnabled bool
AdminUser string
AdminPassword string
LoginCookieName string
LoginMaxInactiveLifetime time.Duration
LoginMaxLifetime time.Duration
TokenRotationIntervalMinutes int
SigV4AuthEnabled bool
SigV4VerboseLogging bool
BasicAuthEnabled bool
AdminUser string
AdminPassword string
OAuthAllowInsecureEmailLookup bool
// AWS Plugin Auth
AWSAllowedAuthProviders []string
@@ -1261,6 +1262,9 @@ func readAuthSettings(iniFile *ini.File, cfg *Cfg) (err error) {
} else {
maxLifetimeDaysVal = "30d"
}
cfg.OAuthAllowInsecureEmailLookup = auth.Key("oauth_allow_insecure_email_lookup").MustBool(false)
maxLifetimeDurationVal := valueAsString(auth, "login_maximum_lifetime_duration", maxLifetimeDaysVal)
cfg.LoginMaxLifetime, err = gtime.ParseDuration(maxLifetimeDurationVal)
if err != nil {