From e56528194a972620f1844501af8d7c75c1a88303 Mon Sep 17 00:00:00 2001 From: Nawwar Elnarsh Date: Sun, 4 Oct 2026 17:13:49 +0200 Subject: [PATCH] fix(admin): omit installation-only login flags from scoped providers --- web/app/page.tsx | 9 +++++---- web/e2e/navigation.spec.ts | 38 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 43 insertions(+), 4 deletions(-) diff --git a/web/app/page.tsx b/web/app/page.tsx index 754cea7..af1573c 100644 --- a/web/app/page.tsx +++ b/web/app/page.tsx @@ -2902,12 +2902,13 @@ function ProviderSettings({ basePath, scope, setMessage }: { basePath: string; s event.preventDefault(); const target = event.currentTarget; const form = new FormData(target); + const controlLogin = scope === "installation" ? { control_login_enabled: form.get("control_login_enabled") === "on" } : {}; setBusy(kind); try { - if (kind === "google") await api.request("PUT", `${basePath}/auth/providers/google`, { client_id: form.get("client_id"), client_secret: form.get("client_secret"), inheritable: form.get("inheritable") === "on", control_login_enabled: form.get("control_login_enabled") === "on" }); - if (kind === "apple") await api.request("PUT", `${basePath}/auth/providers/apple`, { client_id: form.get("client_id"), team_id: form.get("team_id"), key_id: form.get("key_id"), private_key_pem: form.get("private_key_pem"), inheritable: form.get("inheritable") === "on", control_login_enabled: form.get("control_login_enabled") === "on" }); - if (kind === "microsoft") await api.request("PUT", `${basePath}/auth/providers/microsoft`, { client_id: form.get("client_id"), client_secret: form.get("client_secret"), tenant: form.get("tenant"), inheritable: form.get("inheritable") === "on", control_login_enabled: form.get("control_login_enabled") === "on" }); - if (kind === "facebook" || kind === "linkedin") await api.request("PUT", `${basePath}/auth/providers/${kind}`, { client_id: form.get("client_id"), client_secret: form.get("client_secret"), inheritable: form.get("inheritable") === "on", control_login_enabled: form.get("control_login_enabled") === "on" }); + if (kind === "google") await api.request("PUT", `${basePath}/auth/providers/google`, { client_id: form.get("client_id"), client_secret: form.get("client_secret"), inheritable: form.get("inheritable") === "on", ...controlLogin }); + if (kind === "apple") await api.request("PUT", `${basePath}/auth/providers/apple`, { client_id: form.get("client_id"), team_id: form.get("team_id"), key_id: form.get("key_id"), private_key_pem: form.get("private_key_pem"), inheritable: form.get("inheritable") === "on", ...controlLogin }); + if (kind === "microsoft") await api.request("PUT", `${basePath}/auth/providers/microsoft`, { client_id: form.get("client_id"), client_secret: form.get("client_secret"), tenant: form.get("tenant"), inheritable: form.get("inheritable") === "on", ...controlLogin }); + if (kind === "facebook" || kind === "linkedin") await api.request("PUT", `${basePath}/auth/providers/${kind}`, { client_id: form.get("client_id"), client_secret: form.get("client_secret"), inheritable: form.get("inheritable") === "on", ...controlLogin }); if (kind === "smtp") await api.request("POST", `${basePath}/notification-providers`, { ...smtpProviderInput(form), inheritable: form.get("inheritable") === "on" }); if (kind === "stripe") await api.request("POST", `${basePath}/billing/providers`, { provider: "stripe", secret: form.get("secret"), api_version: "2026-04-22.dahlia", inheritable: form.get("inheritable") === "on" }); if (kind === "storage") await api.request("POST", `${basePath}/storage/providers`, storageProviderInput(form, scope)); diff --git a/web/e2e/navigation.spec.ts b/web/e2e/navigation.spec.ts index 8cd18ea..95a4863 100644 --- a/web/e2e/navigation.spec.ts +++ b/web/e2e/navigation.spec.ts @@ -4,6 +4,44 @@ const org = { id: "01900000-0000-7000-8000-000000000101", name: "Navigation Org" const app = { id: "01900000-0000-7000-8000-000000000102", organization_id: org.id, name: "Navigation App", slug: "nav-app", issuer: "http://localhost:8093/oidc" }; const product = { id: "01900000-0000-7000-8000-000000000103", key: "standard", name: "Standard", version: 1 }; +for (const scope of ["installation", "organization", "application"] as const) { + test(`social provider forms restrict Platform login fields to installation (${scope})`, async ({ page }) => { + await mockAdmin(page); + const context = scope === "installation" ? "platform" : scope; + const contextID = scope === "application" ? `&application_id=${app.id}` : scope === "organization" ? `&organization_id=${org.id}` : ""; + const basePath = scope === "installation" ? "/v1/control/installation" : scope === "organization" ? `/v1/control/organizations/${org.id}` : `/v1/control/applications/${app.id}`; + await page.route("**/auth/providers/*", async (route) => { + expect(route.request().method()).toBe("PUT"); + const provider = new URL(route.request().url()).pathname.split("/").at(-1); + const payload = route.request().postDataJSON(); + expect(new URL(route.request().url()).pathname).toBe(`${basePath}/auth/providers/${provider}`); + if (scope === "installation") expect(payload.control_login_enabled).toBe(provider !== "google"); + else expect(payload).not.toHaveProperty("control_login_enabled"); + await route.fulfill({ contentType: "application/json", body: "{}" }); + }); + await page.goto(`/?context=${context}${contextID}§ion=providers`); + for (const provider of ["Google", "Apple", "Microsoft", "Facebook", "LinkedIn"]) { + await page.getByRole("link", { name: `Configure ${provider}`, exact: true }).click(); + const form = page.locator("form").filter({ has: page.getByRole("button", { name: `Save ${provider}`, exact: true }) }); + await form.locator('[name="client_id"]').fill("test-client-id"); + if (provider === "Apple") { + await form.locator('[name="team_id"]').fill("test-team-id"); + await form.locator('[name="key_id"]').fill("test-key-id"); + await form.locator('[name="private_key_pem"]').fill("test-only-private-key-placeholder"); + } else await form.locator('[name="client_secret"]').fill("test-client-secret"); + const controlLogin = form.locator('[name="control_login_enabled"]'); + if (scope === "installation") { + await expect(controlLogin).toBeVisible(); + if (provider !== "Google") await controlLogin.check(); + } else await expect(controlLogin).toHaveCount(0); + const response = page.waitForResponse((response) => response.request().method() === "PUT" && response.url().endsWith(`/auth/providers/${provider.toLowerCase()}`)); + await form.getByRole("button", { name: `Save ${provider}`, exact: true }).click(); + await response; + await expect(page.locator(".toast-success")).toContainText(`${provider} login provider saved`); + } + }); +} + async function mockAdmin(page: Page) { await page.route("**/v1/**", async (route) => { const path = new URL(route.request().url()).pathname;