diff --git a/pkg/api/login_oauth.go b/pkg/api/login_oauth.go index cb6871508d8..43d0eda269c 100644 --- a/pkg/api/login_oauth.go +++ b/pkg/api/login_oauth.go @@ -307,16 +307,17 @@ func (hs *HTTPServer) SyncUser( connect social.SocialConnector, ) (*models.User, error) { oauthLogger.Debug("Syncing Grafana user with corresponding OAuth profile") + lookupParams := models.UserLookupParams{} + if hs.Cfg.OAuthAllowInsecureEmailLookup { + lookupParams.Email = &extUser.Email + } + // add/update user in Grafana cmd := &models.UpsertUserCommand{ - ReqContext: ctx, - ExternalUser: extUser, - SignupAllowed: connect.IsSignupAllowed(), - UserLookupParams: models.UserLookupParams{ - Email: &extUser.Email, - UserID: nil, - Login: nil, - }, + ReqContext: ctx, + ExternalUser: extUser, + SignupAllowed: connect.IsSignupAllowed(), + UserLookupParams: lookupParams, } if err := hs.Login.UpsertUser(ctx.Req.Context(), cmd); err != nil { diff --git a/pkg/setting/setting.go b/pkg/setting/setting.go index 359ee00919b..d9ad315b72f 100644 --- a/pkg/setting/setting.go +++ b/pkg/setting/setting.go @@ -288,15 +288,16 @@ type Cfg struct { DefaultHomeDashboardPath string // Auth - LoginCookieName string - LoginMaxInactiveLifetime time.Duration - LoginMaxLifetime time.Duration - TokenRotationIntervalMinutes int - SigV4AuthEnabled bool - SigV4VerboseLogging bool - BasicAuthEnabled bool - AdminUser string - AdminPassword string + LoginCookieName string + LoginMaxInactiveLifetime time.Duration + LoginMaxLifetime time.Duration + TokenRotationIntervalMinutes int + SigV4AuthEnabled bool + SigV4VerboseLogging bool + BasicAuthEnabled bool + AdminUser string + AdminPassword string + OAuthAllowInsecureEmailLookup bool // AWS Plugin Auth AWSAllowedAuthProviders []string @@ -1261,6 +1262,9 @@ func readAuthSettings(iniFile *ini.File, cfg *Cfg) (err error) { } else { maxLifetimeDaysVal = "30d" } + + cfg.OAuthAllowInsecureEmailLookup = auth.Key("oauth_allow_insecure_email_lookup").MustBool(false) + maxLifetimeDurationVal := valueAsString(auth, "login_maximum_lifetime_duration", maxLifetimeDaysVal) cfg.LoginMaxLifetime, err = gtime.ParseDuration(maxLifetimeDurationVal) if err != nil {