UNPKG

@sync-in/server

Version:

The secure, open-source platform for file storage, sharing, collaboration, and sync

301 lines (300 loc) 11.4 kB
/* * Copyright (C) 2012-2025 Johan Legrand <johan.legrand@sync-in.com> * This file is part of Sync-in | The open source file sync and share solution * See the LICENSE file for licensing details */ "use strict"; Object.defineProperty(exports, "__esModule", { value: true }); function _export(target, all) { for(var name in all)Object.defineProperty(target, name, { enumerable: true, get: Object.getOwnPropertyDescriptor(all, name).get }); } _export(exports, { get AuthConfig () { return AuthConfig; }, get AuthMethodLdapAttributesConfig () { return AuthMethodLdapAttributesConfig; }, get AuthMethodLdapConfig () { return AuthMethodLdapConfig; }, get AuthMfaConfig () { return AuthMfaConfig; }, get AuthMfaTotpConfig () { return AuthMfaTotpConfig; }, get AuthTokenAccessConfig () { return AuthTokenAccessConfig; }, get AuthTokenConfig () { return AuthTokenConfig; }, get AuthTokenCsrfConfig () { return AuthTokenCsrfConfig; }, get AuthTokenRefreshConfig () { return AuthTokenRefreshConfig; }, get AuthTokenWSConfig () { return AuthTokenWSConfig; } }); const _classtransformer = require("class-transformer"); const _classvalidator = require("class-validator"); const _shared = require("../common/shared"); const _auth = require("./constants/auth"); const _authldap = require("./constants/auth-ldap"); function _ts_decorate(decorators, target, key, desc) { var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d; if (typeof Reflect === "object" && typeof Reflect.decorate === "function") r = Reflect.decorate(decorators, target, key, desc); else for(var i = decorators.length - 1; i >= 0; i--)if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r; return c > 3 && r && Object.defineProperty(target, key, r), r; } function _ts_metadata(k, v) { if (typeof Reflect === "object" && typeof Reflect.metadata === "function") return Reflect.metadata(k, v); } let AuthMfaTotpConfig = class AuthMfaTotpConfig { constructor(){ this.enabled = true; this.issuer = _shared.SERVER_NAME; } }; _ts_decorate([ (0, _classvalidator.IsBoolean)() ], AuthMfaTotpConfig.prototype, "enabled", void 0); _ts_decorate([ (0, _classvalidator.IsString)() ], AuthMfaTotpConfig.prototype, "issuer", void 0); let AuthMfaConfig = class AuthMfaConfig { constructor(){ this.totp = new AuthMfaTotpConfig(); } }; _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthMfaTotpConfig), _ts_metadata("design:type", typeof AuthMfaTotpConfig === "undefined" ? Object : AuthMfaTotpConfig) ], AuthMfaConfig.prototype, "totp", void 0); let AuthTokenAccessConfig = class AuthTokenAccessConfig { constructor(){ this.// force default name name = _auth.ACCESS_KEY; this.expiration = '30m'; } }; _ts_decorate([ (0, _classtransformer.Exclude)({ toClassOnly: true }) ], AuthTokenAccessConfig.prototype, "name", void 0); _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)(), _ts_metadata("design:type", String) ], AuthTokenAccessConfig.prototype, "secret", void 0); _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)() ], AuthTokenAccessConfig.prototype, "expiration", void 0); let AuthTokenRefreshConfig = class AuthTokenRefreshConfig { constructor(){ this.// force default name name = _auth.REFRESH_KEY; this.expiration = '4h'; } }; _ts_decorate([ (0, _classtransformer.Exclude)({ toClassOnly: true }) ], AuthTokenRefreshConfig.prototype, "name", void 0); _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)(), _ts_metadata("design:type", String) ], AuthTokenRefreshConfig.prototype, "secret", void 0); _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)() ], AuthTokenRefreshConfig.prototype, "expiration", void 0); let AuthTokenCsrfConfig = class AuthTokenCsrfConfig extends AuthTokenRefreshConfig { constructor(...args){ super(...args), this.name = _auth.CSRF_KEY; } }; _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)(), _ts_metadata("design:type", String) ], AuthTokenCsrfConfig.prototype, "name", void 0); let AuthTokenWSConfig = class AuthTokenWSConfig extends AuthTokenRefreshConfig { constructor(...args){ super(...args), this.name = _auth.WS_KEY; } }; _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)(), _ts_metadata("design:type", String) ], AuthTokenWSConfig.prototype, "name", void 0); let AuthTokenConfig = class AuthTokenConfig { }; _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthTokenAccessConfig), _ts_metadata("design:type", typeof AuthTokenAccessConfig === "undefined" ? Object : AuthTokenAccessConfig) ], AuthTokenConfig.prototype, "access", void 0); _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthTokenRefreshConfig), _ts_metadata("design:type", typeof AuthTokenRefreshConfig === "undefined" ? Object : AuthTokenRefreshConfig) ], AuthTokenConfig.prototype, "refresh", void 0); _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthTokenCsrfConfig), _ts_metadata("design:type", typeof AuthTokenCsrfConfig === "undefined" ? Object : AuthTokenCsrfConfig) ], AuthTokenConfig.prototype, "csrf", void 0); _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthTokenWSConfig), _ts_metadata("design:type", typeof AuthTokenWSConfig === "undefined" ? Object : AuthTokenWSConfig) ], AuthTokenConfig.prototype, "ws", void 0); let AuthMethodLdapAttributesConfig = class AuthMethodLdapAttributesConfig { constructor(){ this.login = _authldap.LDAP_LOGIN_ATTR.UID; this.email = _authldap.LDAP_COMMON_ATTR.MAIL; } }; _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), (0, _classtransformer.Transform)(({ value })=>value || _authldap.LDAP_LOGIN_ATTR.UID), (0, _classvalidator.IsEnum)(_authldap.LDAP_LOGIN_ATTR), _ts_metadata("design:type", typeof _authldap.LDAP_LOGIN_ATTR === "undefined" ? Object : _authldap.LDAP_LOGIN_ATTR) ], AuthMethodLdapAttributesConfig.prototype, "login", void 0); _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), (0, _classtransformer.Transform)(({ value })=>value || _authldap.LDAP_COMMON_ATTR.MAIL), _ts_metadata("design:type", String) ], AuthMethodLdapAttributesConfig.prototype, "email", void 0); let AuthMethodLdapConfig = class AuthMethodLdapConfig { constructor(){ this.attributes = new AuthMethodLdapAttributesConfig(); } }; _ts_decorate([ (0, _classtransformer.Transform)(({ value })=>Array.isArray(value) ? value.filter((v)=>Boolean(v)) : value), (0, _classvalidator.ArrayNotEmpty)(), (0, _classvalidator.IsArray)(), (0, _classvalidator.IsString)({ each: true }), _ts_metadata("design:type", Array) ], AuthMethodLdapConfig.prototype, "servers", void 0); _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsNotEmpty)(), _ts_metadata("design:type", String) ], AuthMethodLdapConfig.prototype, "baseDN", void 0); _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), _ts_metadata("design:type", String) ], AuthMethodLdapConfig.prototype, "filter", void 0); _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthMethodLdapAttributesConfig), _ts_metadata("design:type", typeof AuthMethodLdapAttributesConfig === "undefined" ? Object : AuthMethodLdapAttributesConfig) ], AuthMethodLdapConfig.prototype, "attributes", void 0); _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), _ts_metadata("design:type", String) ], AuthMethodLdapConfig.prototype, "adminGroup", void 0); _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), _ts_metadata("design:type", String) ], AuthMethodLdapConfig.prototype, "upnSuffix", void 0); _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), _ts_metadata("design:type", String) ], AuthMethodLdapConfig.prototype, "netbiosName", void 0); let AuthConfig = class AuthConfig { constructor(){ this.method = 'mysql'; this.mfa = new AuthMfaConfig(); this.cookieSameSite = 'strict'; } }; _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsIn)([ 'mysql', 'ldap' ]), _ts_metadata("design:type", String) ], AuthConfig.prototype, "method", void 0); _ts_decorate([ (0, _classvalidator.IsOptional)(), (0, _classvalidator.IsString)(), _ts_metadata("design:type", String) ], AuthConfig.prototype, "encryptionKey", void 0); _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthMfaConfig), _ts_metadata("design:type", typeof AuthMfaConfig === "undefined" ? Object : AuthMfaConfig) ], AuthConfig.prototype, "mfa", void 0); _ts_decorate([ (0, _classvalidator.IsString)(), (0, _classvalidator.IsIn)([ 'lax', 'strict' ]), _ts_metadata("design:type", String) ], AuthConfig.prototype, "cookieSameSite", void 0); _ts_decorate([ (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsNotEmptyObject)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthTokenConfig), _ts_metadata("design:type", typeof AuthTokenConfig === "undefined" ? Object : AuthTokenConfig) ], AuthConfig.prototype, "token", void 0); _ts_decorate([ (0, _classvalidator.ValidateIf)((o)=>o.method === 'ldap'), (0, _classvalidator.IsDefined)(), (0, _classvalidator.IsObject)(), (0, _classvalidator.ValidateNested)(), (0, _classtransformer.Type)(()=>AuthMethodLdapConfig), _ts_metadata("design:type", typeof AuthMethodLdapConfig === "undefined" ? Object : AuthMethodLdapConfig) ], AuthConfig.prototype, "ldap", void 0); //# sourceMappingURL=auth.config.js.map