Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions tf/actions/ensureLdapUsersUseLdap.js
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,18 @@ exports.onExecutePostLogin = async (event, api) => {
"jijaIzcZmFCDRtV74scMb9lI87MtYNTA", // mozillians.org Verification Client
];

// Service (bot) identities exempt from LDAP enforcement
// https://bugzilla.mozilla.org/show_bug.cgi?id=2072995
const SERVICE_ACCOUNT_EXEMPTIONS = {
// See also denyRegistrationByEmail.js
// Matrix, IAM-1617
pFf6sBIfp4n3Wcs3F9Q7a9ry8MTrbi2F: [
"taskcluster-accounts+community@mozilla.com",
"taskcluster-accounts+firefoxci@mozilla.com",
"taskcluster-accounts+staging@mozilla.com",
],
};

// The domain strings in this array should always be declared here in lowercase
const MOZILLA_STAFF_DOMAINS = [
"mozilla.com", // Main corp domain
Expand Down Expand Up @@ -120,6 +132,15 @@ exports.onExecutePostLogin = async (event, api) => {

// 'ad' is LDAP - Force LDAP users to log with LDAP here
if (event.connection.strategy !== "ad") {
const email = event.user.email.toLowerCase();
const exemptEmails =
SERVICE_ACCOUNT_EXEMPTIONS[event.client.client_id] || [];
if (event.user.email_verified && exemptEmails.includes(email)) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have yet to see a case where event.user.email_verified has been false.

I did some investigation for bhearsum a while back, that's still in Slack (ref).

My take: if we've exempted an email we probably don't care if it's been verified or not.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My take: if we've exempted an email we probably don't care if it's been verified or not.

My reasoning is mostly: it looks like we want to use these more as an API/username for a bot account, in which case if it can receive email is sort of not important. Other IdPs may rely on that, for granting an account.

console.log(
`Service account ${email} is exempt from LDAP enforcement for client ${event.client.client_id}`
);
return;
}
for (let domain of MOZILLA_STAFF_DOMAINS) {
// we need to sanitize the email address to lowercase before matching so we can catch users with upper/mixed case email addresses
if (event.user.email.toLowerCase().endsWith(domain)) {
Expand Down
Loading