@sync-in/server
Version:
The secure, open-source platform for file storage, sharing, collaboration, and sync
301 lines (300 loc) • 11.4 kB
JavaScript
/*
* Copyright (C) 2012-2025 Johan Legrand <johan.legrand@sync-in.com>
* This file is part of Sync-in | The open source file sync and share solution
* See the LICENSE file for licensing details
*/ "use strict";
Object.defineProperty(exports, "__esModule", {
value: true
});
function _export(target, all) {
for(var name in all)Object.defineProperty(target, name, {
enumerable: true,
get: Object.getOwnPropertyDescriptor(all, name).get
});
}
_export(exports, {
get AuthConfig () {
return AuthConfig;
},
get AuthMethodLdapAttributesConfig () {
return AuthMethodLdapAttributesConfig;
},
get AuthMethodLdapConfig () {
return AuthMethodLdapConfig;
},
get AuthMfaConfig () {
return AuthMfaConfig;
},
get AuthMfaTotpConfig () {
return AuthMfaTotpConfig;
},
get AuthTokenAccessConfig () {
return AuthTokenAccessConfig;
},
get AuthTokenConfig () {
return AuthTokenConfig;
},
get AuthTokenCsrfConfig () {
return AuthTokenCsrfConfig;
},
get AuthTokenRefreshConfig () {
return AuthTokenRefreshConfig;
},
get AuthTokenWSConfig () {
return AuthTokenWSConfig;
}
});
const _classtransformer = require("class-transformer");
const _classvalidator = require("class-validator");
const _shared = require("../common/shared");
const _auth = require("./constants/auth");
const _authldap = require("./constants/auth-ldap");
function _ts_decorate(decorators, target, key, desc) {
var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d;
if (typeof Reflect === "object" && typeof Reflect.decorate === "function") r = Reflect.decorate(decorators, target, key, desc);
else for(var i = decorators.length - 1; i >= 0; i--)if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r;
return c > 3 && r && Object.defineProperty(target, key, r), r;
}
function _ts_metadata(k, v) {
if (typeof Reflect === "object" && typeof Reflect.metadata === "function") return Reflect.metadata(k, v);
}
let AuthMfaTotpConfig = class AuthMfaTotpConfig {
constructor(){
this.enabled = true;
this.issuer = _shared.SERVER_NAME;
}
};
_ts_decorate([
(0, _classvalidator.IsBoolean)()
], AuthMfaTotpConfig.prototype, "enabled", void 0);
_ts_decorate([
(0, _classvalidator.IsString)()
], AuthMfaTotpConfig.prototype, "issuer", void 0);
let AuthMfaConfig = class AuthMfaConfig {
constructor(){
this.totp = new AuthMfaTotpConfig();
}
};
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthMfaTotpConfig),
_ts_metadata("design:type", typeof AuthMfaTotpConfig === "undefined" ? Object : AuthMfaTotpConfig)
], AuthMfaConfig.prototype, "totp", void 0);
let AuthTokenAccessConfig = class AuthTokenAccessConfig {
constructor(){
this.// force default name
name = _auth.ACCESS_KEY;
this.expiration = '30m';
}
};
_ts_decorate([
(0, _classtransformer.Exclude)({
toClassOnly: true
})
], AuthTokenAccessConfig.prototype, "name", void 0);
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)(),
_ts_metadata("design:type", String)
], AuthTokenAccessConfig.prototype, "secret", void 0);
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)()
], AuthTokenAccessConfig.prototype, "expiration", void 0);
let AuthTokenRefreshConfig = class AuthTokenRefreshConfig {
constructor(){
this.// force default name
name = _auth.REFRESH_KEY;
this.expiration = '4h';
}
};
_ts_decorate([
(0, _classtransformer.Exclude)({
toClassOnly: true
})
], AuthTokenRefreshConfig.prototype, "name", void 0);
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)(),
_ts_metadata("design:type", String)
], AuthTokenRefreshConfig.prototype, "secret", void 0);
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)()
], AuthTokenRefreshConfig.prototype, "expiration", void 0);
let AuthTokenCsrfConfig = class AuthTokenCsrfConfig extends AuthTokenRefreshConfig {
constructor(...args){
super(...args), this.name = _auth.CSRF_KEY;
}
};
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)(),
_ts_metadata("design:type", String)
], AuthTokenCsrfConfig.prototype, "name", void 0);
let AuthTokenWSConfig = class AuthTokenWSConfig extends AuthTokenRefreshConfig {
constructor(...args){
super(...args), this.name = _auth.WS_KEY;
}
};
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)(),
_ts_metadata("design:type", String)
], AuthTokenWSConfig.prototype, "name", void 0);
let AuthTokenConfig = class AuthTokenConfig {
};
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthTokenAccessConfig),
_ts_metadata("design:type", typeof AuthTokenAccessConfig === "undefined" ? Object : AuthTokenAccessConfig)
], AuthTokenConfig.prototype, "access", void 0);
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthTokenRefreshConfig),
_ts_metadata("design:type", typeof AuthTokenRefreshConfig === "undefined" ? Object : AuthTokenRefreshConfig)
], AuthTokenConfig.prototype, "refresh", void 0);
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthTokenCsrfConfig),
_ts_metadata("design:type", typeof AuthTokenCsrfConfig === "undefined" ? Object : AuthTokenCsrfConfig)
], AuthTokenConfig.prototype, "csrf", void 0);
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthTokenWSConfig),
_ts_metadata("design:type", typeof AuthTokenWSConfig === "undefined" ? Object : AuthTokenWSConfig)
], AuthTokenConfig.prototype, "ws", void 0);
let AuthMethodLdapAttributesConfig = class AuthMethodLdapAttributesConfig {
constructor(){
this.login = _authldap.LDAP_LOGIN_ATTR.UID;
this.email = _authldap.LDAP_COMMON_ATTR.MAIL;
}
};
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
(0, _classtransformer.Transform)(({ value })=>value || _authldap.LDAP_LOGIN_ATTR.UID),
(0, _classvalidator.IsEnum)(_authldap.LDAP_LOGIN_ATTR),
_ts_metadata("design:type", typeof _authldap.LDAP_LOGIN_ATTR === "undefined" ? Object : _authldap.LDAP_LOGIN_ATTR)
], AuthMethodLdapAttributesConfig.prototype, "login", void 0);
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
(0, _classtransformer.Transform)(({ value })=>value || _authldap.LDAP_COMMON_ATTR.MAIL),
_ts_metadata("design:type", String)
], AuthMethodLdapAttributesConfig.prototype, "email", void 0);
let AuthMethodLdapConfig = class AuthMethodLdapConfig {
constructor(){
this.attributes = new AuthMethodLdapAttributesConfig();
}
};
_ts_decorate([
(0, _classtransformer.Transform)(({ value })=>Array.isArray(value) ? value.filter((v)=>Boolean(v)) : value),
(0, _classvalidator.ArrayNotEmpty)(),
(0, _classvalidator.IsArray)(),
(0, _classvalidator.IsString)({
each: true
}),
_ts_metadata("design:type", Array)
], AuthMethodLdapConfig.prototype, "servers", void 0);
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsNotEmpty)(),
_ts_metadata("design:type", String)
], AuthMethodLdapConfig.prototype, "baseDN", void 0);
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
_ts_metadata("design:type", String)
], AuthMethodLdapConfig.prototype, "filter", void 0);
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthMethodLdapAttributesConfig),
_ts_metadata("design:type", typeof AuthMethodLdapAttributesConfig === "undefined" ? Object : AuthMethodLdapAttributesConfig)
], AuthMethodLdapConfig.prototype, "attributes", void 0);
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
_ts_metadata("design:type", String)
], AuthMethodLdapConfig.prototype, "adminGroup", void 0);
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
_ts_metadata("design:type", String)
], AuthMethodLdapConfig.prototype, "upnSuffix", void 0);
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
_ts_metadata("design:type", String)
], AuthMethodLdapConfig.prototype, "netbiosName", void 0);
let AuthConfig = class AuthConfig {
constructor(){
this.method = 'mysql';
this.mfa = new AuthMfaConfig();
this.cookieSameSite = 'strict';
}
};
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsIn)([
'mysql',
'ldap'
]),
_ts_metadata("design:type", String)
], AuthConfig.prototype, "method", void 0);
_ts_decorate([
(0, _classvalidator.IsOptional)(),
(0, _classvalidator.IsString)(),
_ts_metadata("design:type", String)
], AuthConfig.prototype, "encryptionKey", void 0);
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthMfaConfig),
_ts_metadata("design:type", typeof AuthMfaConfig === "undefined" ? Object : AuthMfaConfig)
], AuthConfig.prototype, "mfa", void 0);
_ts_decorate([
(0, _classvalidator.IsString)(),
(0, _classvalidator.IsIn)([
'lax',
'strict'
]),
_ts_metadata("design:type", String)
], AuthConfig.prototype, "cookieSameSite", void 0);
_ts_decorate([
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsNotEmptyObject)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthTokenConfig),
_ts_metadata("design:type", typeof AuthTokenConfig === "undefined" ? Object : AuthTokenConfig)
], AuthConfig.prototype, "token", void 0);
_ts_decorate([
(0, _classvalidator.ValidateIf)((o)=>o.method === 'ldap'),
(0, _classvalidator.IsDefined)(),
(0, _classvalidator.IsObject)(),
(0, _classvalidator.ValidateNested)(),
(0, _classtransformer.Type)(()=>AuthMethodLdapConfig),
_ts_metadata("design:type", typeof AuthMethodLdapConfig === "undefined" ? Object : AuthMethodLdapConfig)
], AuthConfig.prototype, "ldap", void 0);
//# sourceMappingURL=auth.config.js.map