Skip to content

Commit 58bb13d

Browse files
committed
fix(auth): serialize domain administration and align SSO validation
1 parent 718c4e7 commit 58bb13d

7 files changed

Lines changed: 398 additions & 73 deletions

File tree

‎apps/docs/openapi-v2-resources.json‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7954,7 +7954,7 @@
79547954
"get": {
79557955
"operationId": "listCredentialMembers",
79567956
"summary": "List Credential Members",
7957-
"description": "List explicit credential grants, including revoked grants, and inherited workspace administrator access. Requires workspace read access. Personal API keys and OAuth tokens can access OAuth or service-account credentials; sessions can also access workspace environment credentials. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:read`.",
7957+
"description": "List explicit credential grants, including revoked grants, and inherited workspace administrator access. Requires workspace read access and the integrations.manage capability. Personal API keys and OAuth tokens can access OAuth or service-account credentials; sessions can also access workspace environment credentials. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:read`.",
79587958
"x-sim-operation": "credentials.members.list",
79597959
"x-oauth-scope": "api:read",
79607960
"tags": ["Credentials"],
@@ -8080,7 +8080,7 @@
80808080
"post": {
80818081
"operationId": "upsertCredentialMember",
80828082
"summary": "Upsert Credential Member",
8083-
"description": "Grant or change an existing workspace member’s credential role. Requires credential administrator access. Revoked grants become active again; inherited administrators cannot be demoted. A new grant returns 201; an existing grant returns 200. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.",
8083+
"description": "Grant or change an existing workspace member’s credential role. Requires credential administrator access and the integrations.manage capability. Revoked grants become active again; inherited administrators cannot be demoted. A new grant returns 201; an existing grant returns 200. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.",
80848084
"x-sim-operation": "credentials.members.upsert",
80858085
"x-oauth-scope": "api:write",
80868086
"tags": ["Credentials"],
@@ -8198,7 +8198,7 @@
81988198
"delete": {
81998199
"operationId": "removeCredentialMember",
82008200
"summary": "Remove Credential Member",
8201-
"description": "Revoke an active explicit credential grant. Requires credential administrator access. Inherited workspace administrators cannot be removed; an absent or already-revoked grant returns 404. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.",
8201+
"description": "Revoke an active explicit credential grant. Requires credential administrator access and the integrations.manage capability. Inherited workspace administrators cannot be removed; an absent or already-revoked grant returns 404. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.",
82028202
"x-sim-operation": "credentials.members.remove",
82038203
"x-oauth-scope": "api:write",
82048204
"tags": ["Credentials"],

‎apps/sim/lib/api/contracts/v2/openapi/credential-members.ts‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ export const credentialMemberOpenApiRoutes = [
1818
applicationOperation: credentialOperations.listMembers,
1919
operationId: 'listCredentialMembers',
2020
summary: 'List Credential Members',
21-
description: `List explicit credential grants, including revoked grants, and inherited workspace administrator access. Requires workspace read access. Personal API keys and OAuth tokens can access OAuth or service-account credentials; sessions can also access workspace environment credentials. ${WORKSPACE_API_KEY_DENIED}`,
21+
description: `List explicit credential grants, including revoked grants, and inherited workspace administrator access. Requires workspace read access and the integrations.manage capability. Personal API keys and OAuth tokens can access OAuth or service-account credentials; sessions can also access workspace environment credentials. ${WORKSPACE_API_KEY_DENIED}`,
2222
tags: ['Credentials'],
2323
errors: RESOURCE_ERRORS,
2424
success: { description: 'List Credential Members result.', headers: RATE_LIMIT_HEADERS },
@@ -34,7 +34,7 @@ export const credentialMemberOpenApiRoutes = [
3434
v2ListCredentialMembersContract.query,
3535
'ListCredentialMembersQuery',
3636
'Query parameters',
37-
'Filters and pagination controls.'
37+
'Workspace scope, sorting, and pagination controls.'
3838
),
3939
response: documentedSchema(
4040
v2ListCredentialMembersContract.response.schema,
@@ -50,7 +50,7 @@ export const credentialMemberOpenApiRoutes = [
5050
applicationOperation: credentialOperations.upsertMember,
5151
operationId: 'upsertCredentialMember',
5252
summary: 'Upsert Credential Member',
53-
description: `Grant or change an existing workspace member’s credential role. Requires credential administrator access. Revoked grants become active again; inherited administrators cannot be demoted. A new grant returns 201; an existing grant returns 200. ${WORKSPACE_API_KEY_DENIED}`,
53+
description: `Grant or change an existing workspace member’s credential role. Requires credential administrator access and the integrations.manage capability. Revoked grants become active again; inherited administrators cannot be demoted. A new grant returns 201; an existing grant returns 200. ${WORKSPACE_API_KEY_DENIED}`,
5454
tags: ['Credentials'],
5555
errors: RESOURCE_ERRORS,
5656
success: { description: 'Upsert Credential Member result.', headers: RATE_LIMIT_HEADERS },
@@ -66,7 +66,7 @@ export const credentialMemberOpenApiRoutes = [
6666
v2UpsertCredentialMemberContract.query,
6767
'UpsertCredentialMemberQuery',
6868
'Query parameters',
69-
'Filters and pagination controls.'
69+
'Workspace containing the credential.'
7070
),
7171
body: documentedSchema(
7272
v2UpsertCredentialMemberContract.body,
@@ -88,7 +88,7 @@ export const credentialMemberOpenApiRoutes = [
8888
applicationOperation: credentialOperations.removeMember,
8989
operationId: 'removeCredentialMember',
9090
summary: 'Remove Credential Member',
91-
description: `Revoke an active explicit credential grant. Requires credential administrator access. Inherited workspace administrators cannot be removed; an absent or already-revoked grant returns 404. ${WORKSPACE_API_KEY_DENIED}`,
91+
description: `Revoke an active explicit credential grant. Requires credential administrator access and the integrations.manage capability. Inherited workspace administrators cannot be removed; an absent or already-revoked grant returns 404. ${WORKSPACE_API_KEY_DENIED}`,
9292
tags: ['Credentials'],
9393
errors: RESOURCE_ERRORS,
9494
success: { description: 'Remove Credential Member result.', headers: RATE_LIMIT_HEADERS },
@@ -104,7 +104,7 @@ export const credentialMemberOpenApiRoutes = [
104104
v2RemoveCredentialMemberContract.query,
105105
'RemoveCredentialMemberQuery',
106106
'Query parameters',
107-
'Filters and pagination controls.'
107+
'Workspace containing the credential.'
108108
),
109109
response: documentedSchema(
110110
v2RemoveCredentialMemberContract.response.schema,

‎apps/sim/lib/api/mcp/generated/v2-operations.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1726,7 +1726,7 @@ export const V2_MCP_OPERATIONS = {
17261726
contract: v2ListCredentialMembersContract,
17271727
summary: 'List Credential Members',
17281728
description:
1729-
'List explicit credential grants, including revoked grants, and inherited workspace administrator access. Requires workspace read access. Personal API keys and OAuth tokens can access OAuth or service-account credentials; sessions can also access workspace environment credentials. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:read`.',
1729+
'List explicit credential grants, including revoked grants, and inherited workspace administrator access. Requires workspace read access and the integrations.manage capability. Personal API keys and OAuth tokens can access OAuth or service-account credentials; sessions can also access workspace environment credentials. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:read`.',
17301730
workspaceKeyUnsupported: true,
17311731
handler: () =>
17321732
import('@/app/api/v2/credentials/[credentialId]/members/route').then((route) => route.GET),
@@ -2344,7 +2344,7 @@ export const V2_MCP_OPERATIONS = {
23442344
contract: v2RemoveCredentialMemberContract,
23452345
summary: 'Remove Credential Member',
23462346
description:
2347-
'Revoke an active explicit credential grant. Requires credential administrator access. Inherited workspace administrators cannot be removed; an absent or already-revoked grant returns 404. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.',
2347+
'Revoke an active explicit credential grant. Requires credential administrator access and the integrations.manage capability. Inherited workspace administrators cannot be removed; an absent or already-revoked grant returns 404. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.',
23482348
workspaceKeyUnsupported: true,
23492349
handler: () =>
23502350
import('@/app/api/v2/credentials/[credentialId]/members/[userId]/route').then(
@@ -2941,7 +2941,7 @@ export const V2_MCP_OPERATIONS = {
29412941
contract: v2UpsertCredentialMemberContract,
29422942
summary: 'Upsert Credential Member',
29432943
description:
2944-
'Grant or change an existing workspace member’s credential role. Requires credential administrator access. Revoked grants become active again; inherited administrators cannot be demoted. A new grant returns 201; an existing grant returns 200. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.',
2944+
'Grant or change an existing workspace member’s credential role. Requires credential administrator access and the integrations.manage capability. Revoked grants become active again; inherited administrators cannot be demoted. A new grant returns 201; an existing grant returns 200. Workspace API keys return `403`; use a personal API key or scoped OAuth token.\n\nOAuth scope: `api:write`.',
29452945
workspaceKeyUnsupported: true,
29462946
handler: () =>
29472947
import('@/app/api/v2/credentials/[credentialId]/members/route').then((route) => route.POST),

‎apps/sim/lib/auth/sso/registration-input.ts‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ import { z } from 'zod'
22

33
const ssoMappingSchema = z
44
.object({
5-
id: z.string().default('sub'),
6-
email: z.string().default('email'),
7-
name: z.string().default('name'),
8-
image: z.string().default('picture'),
5+
id: z.string().min(1).max(255).default('sub'),
6+
email: z.string().min(1).max(255).default('email'),
7+
name: z.string().min(1).max(255).default('name'),
8+
image: z.string().min(1).max(255).default('picture'),
99
})
1010
.default({
1111
id: 'sub',
@@ -16,7 +16,7 @@ const ssoMappingSchema = z
1616

1717
export const ssoRegistrationInputSchema = z.discriminatedUnion('providerType', [
1818
z.object({
19-
providerType: z.literal('oidc').default('oidc'),
19+
providerType: z.literal('oidc'),
2020
providerId: z.string().min(1, 'Provider ID is required').max(255),
2121
issuer: z.string().url('Issuer must be a valid URL'),
2222
domain: z.string().min(1, 'Domain is required'),
@@ -33,7 +33,7 @@ export const ssoRegistrationInputSchema = z.discriminatedUnion('providerType', [
3333
.map((value) => value.trim())
3434
.filter((value) => value !== '')
3535
),
36-
z.array(z.string()),
36+
z.array(z.string().trim().min(1)),
3737
])
3838
.default(['openid', 'profile', 'email']),
3939
pkce: z.boolean().default(true),

0 commit comments

Comments
 (0)