diff --git a/.gitignore b/.gitignore index 5539fbd..5916b60 100644 --- a/.gitignore +++ b/.gitignore @@ -42,3 +42,9 @@ out/ *.log __pycache__/ + +frontend/node_modules/ +frontend/dist/ +frontend/test-results/ +frontend/playwright-report/ +.playwright-cli/ diff --git a/AGENTS.md b/AGENTS.md index ee834b7..66c97b8 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -3,9 +3,13 @@ - 后续修改必须新建分支并提交 PR;未经维护者明确指示,不直接推 main、不自行合并。 - 默认中文维护项目文档、commit、issue 和 PR;代码与上游 API 名称保留英文。 - 项目使用 Java 与 Spring;Native 是交付约束,不是可选优化,不引入 Kotlin。 -- 变更需通过适用的 JVM 测试和 Native 集成测试;未执行的验证明确报告。 +- 日常变更先通过适用的 JVM 测试,不要求每轮执行耗时的 Native 编译与测试;Native 仍为交付目标,在阶段性验收或兼容性风险变化时集中验证。未执行的验证明确报告。 +- 按 DDD 组织 authentication 上下文:领域拥有 User/UserRepository,应用层编排目录认证与读取,基础设施实现 AD 仓储与 Security Provider,Web 仅渲染页面;领域和应用层不依赖 Spring/Servlet/LDAP。 +- 用户仓储复用本次用户 bind 的连接,不新增只读服务账号;连接限于当前用例,不保留密码或连接在 HTTP session 中。 +- 选型演示在真实接入后删除,不将演示入口、状态机、验证码或开关保留为应用功能。 - 只实现当前任务范围。Hydra 负责签发,首轮 AD 负责身份和组,本服务独立于 Ayatori。 -- 不把 LDAP 密码成功当成完整 MFA 成功;所有因素绑定同一主体与认证事务。 +- React 只替换 Spring Security 默认登录 UI;表单认证、SecurityContext、因素状态、会话轮换与退出交给框架,不自建登录状态机。 +- LDAP 密码成功可以建立仅含密码因素的 SecurityContext,但不等于完整 MFA 或 Hydra 授权;受保护操作必须检查所需因素。 - 不提交凭据、MFA secret、生产配置秘密或包含上述内容的测试输出。 - 生产部署配置属于 homelab-infra;本仓库初始化不授权切换现役登录入口。 - 文档区分计划、实现、Native 实测和人类验收,禁止将代码存在当成部署证据。 diff --git a/README.md b/README.md index ea94c8f..a278a2c 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,7 @@ # iam-login 独立 IAM 的登录与认证服务,以 Java、Spring Security 和 GraalVM Native 实现,作为 -Hydra 的 Login/Consent 应用。当前已生成 Spring Initializr 骨架,尚未实现 AD、MFA 与 Hydra 登录链路。 +Hydra 的 Login/Consent 应用。已实现 AD 密码与直接所属组查询,以及等待 MFA 的浏览器页面;MFA 与 Hydra 登录链路仍待实现。 ## 职责与边界 @@ -34,7 +34,8 @@ Hydra 的 Login/Consent 应用。当前已生成 Spring Initializr 骨架,尚 4.1.1 和 Gradle;Spring Security 等库由 Boot BOM 管理,插件版本在 build.gradle 中固定。 Native 使用 GraalVM 25。 -Native 构建与原生二进制上的认证测试是交付要求;JVM 测试通过或 native 编译成功都不 +日常改动先跑 JVM 测试,不要求每轮编译 Native。Native 构建与原生二进制上的认证测试 +留在阶段性验收;JVM 测试通过或 native 编译成功都不 单独构成验收。Keycloak 可作为流程与安全边界参考,不以它采用 Quarkus 作为 native 兼容性证据,不直接引入其服务端 SPI 和模型。 @@ -46,12 +47,14 @@ Native 构建与原生二进制上的认证测试是交付要求;JVM 测试通 [项目初始化](docs/bootstrap.md)。使用 JDK 25 执行: ```sh +npm --prefix frontend ci +npm --prefix frontend run build ./gradlew test testAot ./gradlew bootRun ``` 测试需要可用的 Docker,生成器配置了 Grafana LGTM Testcontainer。 -当前只有默认应用和上下文测试,默认 Spring Security 登录页不是可用的 IAM 登录流程。 +测试覆盖 AD 第一因素、浏览器流程和监控集成。人类登录统一从 `/signin` 进入。 使用 GraalVM 25 验证原生测试与编译: ```sh @@ -63,4 +66,39 @@ Docker 开发使用 `scripts/gradle-in-docker`,默认持久挂载 Gradle 缓 原生应用可用 `python3 scripts/native-smoke.py` 检查启动、默认访问控制和 HTTP 指标。 JVM、AOT、Native 测试及原生应用 HTTP 检查已通过,实测范围与资源数据见 [本地验证结果](docs/bootstrap.md#2026-09-25-本地验证结果)。 -AD、MFA 与 Hydra 认证链路仍待实现与验收。 +新增 AD 路径本轮按维护者要求只进行 JVM 验证,不沿用基线的 Native 验收结论。 +重构前的真实目录密码与属性/直接所属组读取已通过维护者浏览器验收;Spring Data LDAP +版本已通过 JVM 和浏览器回归,真实人类复验待反馈。MFA 与 Hydra 链路仍待实现。 + +## 领域与代码组织 + +当前限界上下文为 `authentication`,使用 DDD 分层,依赖向领域内部收敛: + +```text +interfaces/web → infrastructure/security(principal)+ domain +infrastructure/security → application → domain +infrastructure/ad → application/port + domain +configuration → 装配上述实现 +``` + +- `authentication/domain`:`User`、`UserRepository`;稳定主体与组成员关系属于领域模型,不依赖 Spring、Servlet、LDAP 或持久化注解。 +- `authentication/application`:`VerifyPassword` 用例,编排密码认证与同连接用户仓储查询; + `port` 描述密码认证及其用户仓储会话,不暴露 `DirContext`。 +- `authentication/infrastructure/ad`:AD bind、Spring Data LDAP 用户仓储、LDAP 实体与领域映射。 + 使用同一次用户 bind 的连接,查询结束关闭,不新增服务账号,不保存用户密码。 +- `authentication/infrastructure/security`:Provider 将目录用户转换为仅含密码因素的认证结果。 +- `authentication/interfaces/web`:登录页面与上下文转换;不处理密码 POST、认证会话或退出。 +- `configuration`:Spring 组件装配、安全链、静态资源和 Native hints。 +- `frontend/src`:入口、页面、表单组件和页面数据契约分别维护,只包含真实登录流程。 + +测试覆盖应用用例、AD 仓储和完整 Spring Security 过滤器链,LDAP 夹具集中在测试 `support` 包。 +界面采用 React + Vite,Spring 在 HTML 中内联当前步骤上下文,浏览器原生表单 POST, +表单由 Spring Security `formLogin` 处理,框架维护因素、SecurityContext、会话轮换和退出。 +React 只替换默认登录 UI,不增加前端路由器、模板引擎或 Node 运行服务。 + +## AD 第一因素接入 + +真实入口为 `/signin`,默认关闭且要求 HTTPS。密码验证通过后显示 AD 身份与直接所属组, +保存仅含 `FACTOR_PASSWORD` 的认证结果,停在等待 MFA 状态。待 MFA 页要求十分钟内的密码因素; +其他应用入口暂时全部拒绝,不能凭密码因素接受 Hydra challenge。监控 Basic 认证使用独立无状态安全链。 +配置、组语义、HTTPS 与验收边界见 [AD 接入](docs/ad-login.md)。 diff --git a/build.gradle b/build.gradle index 5680496..2eace16 100644 --- a/build.gradle +++ b/build.gradle @@ -71,3 +71,15 @@ graalvmNative { } } } + +// Vite owns the HTML and hashed assets; only the controller can serve the page shell. +// Build it with `npm ci && npm run build` in frontend/ before invoking Gradle. +tasks.named('processResources') { + inputs.files(fileTree('frontend/dist')) + doFirst { + if (!file('frontend/dist/index.html').exists()) { + throw new GradleException('Missing UI build: run npm ci && npm run build in frontend/') + } + } + from('frontend/dist') { into 'ui' } +} diff --git a/docs/ad-login.md b/docs/ad-login.md new file mode 100644 index 0000000..631cfe0 --- /dev/null +++ b/docs/ad-login.md @@ -0,0 +1,125 @@ +# AD 第一因素接入 + +`/signin` 接收 AD 用户名(sAMAccountName)或本域 UPN,通过 Spring LDAP `ContextSource.getContext` 以用户身份执行 LDAPS bind, +随后由 Spring Data LDAP 仓储复用这条已认证连接查询用户与组。 +不使用额外目录服务账号,不写入 AD,不复制 Authelia 的绑定密码。 + +领域仓储接口为 `UserRepository`,`User` 为领域模型。`VerifyPassword` 应用用例以 +try-with-resources 管理已认证用户仓储会话;基础设施的 `AdUserRepository` 通过 +`SimpleLdapRepository`、`LdapTemplate`、ODM 实现读取与转换,关闭后不可继续查询。 +`AdUserEntry` 的 LDAP 注解不会进入领域对象。 + +成功后重定向到 `/signin/mfa`,显示目录账号、objectGUID、邮箱、直接所属组及组 DN。 +**这是密码因素验收页面,MFA 尚未接入,不是完整登录成功。** Spring Security 保存 +仅含 `FACTOR_PASSWORD` 的认证结果;其余应用请求使用 `denyAll`,不调用 Hydra, +不替换现役 Go/Authelia/Gitea 登录链路。 + +## 目录和组语义 + +- AD 是身份和组权威。objectGUID 按 AD 混合字节序解析为标准 UUID,作为目录稳定键; + 不是已确定的 Hydra `sub`。切换前仍须处理现役 issuer/sub 哈希的主体连续性。 +- 从 `memberOf` 读取直接成员关系,保留原始 DN;CN 保留大小写,不添加 `ROLE_`, + 不把 Spring 的 `FACTOR_PASSWORD` 当作组。结果排序,不做应用专用组改写。 +- 此轮不展开嵌套组、不推导 primaryGroupID,也不宣称与 Authelia 的有效组集合完全一致。 + 遇到 ranged memberOf 或不同 DN 同名 CN 拒绝映射,不静默丢组或合并不同主体。 +- AD bind 执行密码及账号状态检查;基础设施层将禁用、锁定、密码过期等 AD 子码转换为 + 应用层认证失败原因,不向领域层泄露 LDAP/Spring 异常。 + 搜索排除 computer 对象,只接受唯一用户条目和合法 objectGUID/sAMAccountName。 +- 邮箱作为目录属性展示,不声称 `email_verified=true`。 + +## 启用 + +`iam.ad.enabled=true` 时才装配登录 Controller 与浏览器安全链(含 formLogin)。 +未启用时入口由兜底安全链拒绝,匿名 GET 返回 401;不注册密码处理端点。 + +正常 JVM 构建: + +```sh +IAM_DOCKER_USE_SUDO=1 scripts/gradle-in-docker test bootJar +``` + +Gradle 与 npm 缓存默认持久挂载,可用 `IAM_GRADLE_CACHE`、`IAM_NPM_CACHE` 指定目录。 +日常迭代不必每轮跑 Native;新增 AD/JNDI/TLS 路径的原生验收留到阶段性验证。 + +运行时配置(非秘密): + +```yaml +iam: + ad: + enabled: true + url: ldaps://dc1.ad.ddupan.top:636 + domain: ad.ddupan.top + base-dn: DC=ad,DC=ddupan,DC=top +server: + port: 18082 + ssl: + enabled: true + certificate: file:/run/iam/browser.crt + certificate-private-key: file:/run/iam/browser.key + servlet: + session: + cookie: + secure: true + same-site: lax +``` + +证书与私钥使用外部受管文件,不加入仓库。开发验收可使用本机的 Tailscale HTTPS 域名 +及相应证书;用匹配证书的主机名打开,不能用 LAN IP 替代域名后跳过警告。 +部署与证书自动续期归 homelab-infra,此轮本地运行不是生产部署。 + +LDAPS 使用默认 JSSE 信任库并执行服务端域名校验。Samba 当前证书由 OpenBao 内部 CA +签发,需把**公开 CA** 加入运行用 truststore,并通过 JVM 参数指定: + +```sh +java -Djavax.net.ssl.trustStore=/run/iam/truststore \ + -Djavax.net.ssl.trustStorePassword=changeit -jar iam-login.jar +``` + +这里 truststore 仅含公开信任锚,口令不是目录密码。保留所需公共根证书;不得禁用 +LDAP endpoint identification 或用信任所有证书的 socket factory。连接/读取超时为 3/5 秒。 +AD 根范围查询可能返回 DomainDnsZones/ForestDnsZones 等分区 referral;配置为 ignore, +由仓储的 LdapTemplate 忽略 partial result,不使用 throw 打断用户查询,也不 follow 转发用户凭据。 + +浏览器安全链通过 Spring Security `redirectToHttps` 将明文请求重定向至 HTTPS, +重定向前不执行密码验证或退出。默认不信任转发头。若以后由代理终结 TLS, +必须配合仅受信代理可达的后端网络和转发头配置,不能公开一个信任任意 forwarded header +的 HTTP 端口。当前开发验收由应用直接终结 TLS。 + +## 状态与操作 + +React 只渲染登录页面与待 MFA 页面,原生表单 POST 由 Spring Security `formLogin` +接收。`DirectoryAuthenticationProvider` 调用目录用例并返回不含密码的 principal 和 +带签发时间的 `FACTOR_PASSWORD`;目录组只保留在身份快照中,不映射为本服务权限。 +框架负责 CSRF、成功/失败跳转、SecurityContext 持久化、session ID 轮换以及 POST logout。 +`/signin/restart` 是框架 logout 地址;不再维护 LoginTransaction 或另一份浏览器认证状态。 + +待 MFA 页通过框架的 `validDuration` 要求密码因素在十分钟内完成,过期后需要重新认证。 +这不是完整登录会话的过期策略。MFA 与 Hydra 尚未实现,其余应用入口当前拒绝所有访问。 +`/actuator/**` 使用独立无状态 Basic 安全链,人类密码因素不能用于读取监控端点, +监控账号也不能借 Basic 进入人类登录流程。 + +移除原来事务内的两秒提交间隔;它不是有效的账号/IP 限流。此 PoC 仍仅供受控 +LAN/Tailscale 验收,生产发布前需完善入口限流、审计、MFA、Hydra challenge 和恢复策略。 +页面禁止缓存,内联 JSON 转义 HTML 结束标记。错误页面只显示统一消息。 + +基础存活检查使用 `/actuator/health/liveness`。Boot 自动配置的 LDAP 健康项并未连接这里 +按用户 bind 创建的仓储连接,不能把该项当作此认证路径的可用性验证。 + +## 本轮验证边界 + +隔离测试使用真实 TLS、LDAP bind 和搜索,校验正确/错误密码、未知账号、AD 账号状态 +子码、GUID 字节序、组名、错误 TLS 主机名、CSRF、HTTPS、会话轮换、因素过期和密码成功后 +仍不能访问受保护应用入口。UnboundID 的 UPN bind 与 AD 子码由测试拦截器模拟,不能替代 Samba AD。 +测试证书、私钥与账号全为虚构夹具,不用于实际部署。 + +2026-09-27:Spring Security 重构通过 18 项 JVM 测试和 `bootJar` 构建,覆盖 +密码因素的保存与有效期、会话轮换、退出、未完成 MFA 的访问限制,以及监控安全链隔离。 +此前 JVM 使用受信 CA 完成 Samba AD RootDSE 查询。 +浏览器已检查登录表单渲染、真实 CSRF 原生 POST 和失败后清空密码;只使用在访问 AD 前 +即拒绝的合成外域用户名,不尝试猜测人类密码。浏览器回归共 1 项通过,包含移动端布局。 +复现:`IAM_AD_URL=https://验收域名:端口 npm --prefix frontend run test:browser -- ad-login.spec.ts`。 +重构前,维护者已在 HTTPS 页面完成真实密码验证,成功到达待 MFA 页面,并反馈目录标识、邮箱与 +六个直接所属组的查询结果。该验收覆盖 Samba AD 第一因素与属性读取,不表示 MFA、 +嵌套组/主组等价性或 Hydra 登录已完成。Spring Security 重构后的真实人类复验仍待反馈。 +不在聊天、命令行或日志中传递人类密码。 +新增 AD 路径尚未进行 Native 测试,不能复用旧 UI 原型的 Native 结论。 diff --git a/docs/bootstrap.md b/docs/bootstrap.md index ad12073..fdc51b9 100644 --- a/docs/bootstrap.md +++ b/docs/bootstrap.md @@ -126,3 +126,6 @@ Prometheus 注册器中的 CPU 时间计数器并断言数值有效,避免后 这是一次本地 smoke 测量,启动耗时含检查器轮询,RSS 不是峰值或负载预算,ELF 大小不等于 运行镜像大小。未验证 AD、MFA、Hydra、目录就绪或 OTLP 后端数据查询,也尚未接入 CI。 运行报告生成在 `build/reports/native-smoke/result.json`,不提交运行日志或构建产物。 + +手写 Native 补丁位于 `META-INF/native-image/top.ddupan.iam/iam-login-manual/`, +与 Spring AOT 生成的 `iam-login/` 目录分开,避免 `bootJar` 中同名元数据冲突。 diff --git a/docs/native-validation.md b/docs/native-validation.md index 6232430..f65a049 100644 --- a/docs/native-validation.md +++ b/docs/native-validation.md @@ -20,9 +20,15 @@ WebAuthn 集成;TOTP、恢复方式与已有 Authelia MFA 的迁移方式需 - Hydra admin 保持内部访问,业务日志不得包含密码、MFA secret、token 或 challenge。 - 原生二进制与隔离 Hydra 完成授权码链路,再验证现有 Gitea 账号及权限。 +日常迭代以 JVM 测试为准,不要求每轮执行 Native 编译。Native 验证安排在阶段性验收 +或新增反射、JNDI、TLS 等兼容性风险时集中进行;记录尚未覆盖的新路径。 + ## Native 与监控 - CI 构建 Native 产物并对该产物执行集成测试;测试报告区分 JVM 与 Native。 +- 登录 Controller 与安全链使用 `@ConditionalOnProperty(iam.ad.enabled)`;AOT 在构建时 + 决定 bean 是否存在。AD Native 产物必须在 AOT 阶段启用此属性,验证实际入口与兜底链, + 不能假设运行时修改属性会重新装配 bean。本轮只验证 JVM,尚未验收该 Native 路径。 - 最终运行镜像无需 JRE,不允许以回退 JVM 的方式令 Native 验收通过。 - LDAP、MFA、数据库、TLS、JSON 和 Hydra HTTP 客户端全部在 Native 中执行。 - 纳入 Actuator、Micrometer Prometheus 与 OpenTelemetry/分布式追踪;实际发起请求后 diff --git a/frontend/index.html b/frontend/index.html new file mode 100644 index 0000000..4b65779 --- /dev/null +++ b/frontend/index.html @@ -0,0 +1,17 @@ + + + + + + + 登录 · IAM + + +
+ + + + + diff --git a/frontend/package-lock.json b/frontend/package-lock.json new file mode 100644 index 0000000..57bc869 --- /dev/null +++ b/frontend/package-lock.json @@ -0,0 +1,1280 @@ +{ + "name": "iam-login-ui", + "version": "0.0.1", + "lockfileVersion": 3, + "requires": true, + "packages": { + "": { + "name": "iam-login-ui", + "version": "0.0.1", + "dependencies": { + "react": "19.3.0", + "react-dom": "19.3.0" + }, + "devDependencies": { + "@playwright/test": "1.63.0", + "@types/react": "^19.2.0", + "@types/react-dom": "^19.2.0", + "typescript": "7.0.2", + "vite": "8.3.1" + } + }, + "node_modules/@oxc-project/types": { + "version": "0.151.0", + "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.151.0.tgz", + "integrity": "sha512-J1yXrIlNDZVzE3ada310xeAw7nH8yCAyLPuUIsjKatFPmfn5bS1oW+cM+QsGOtVWd5nhSpbwZWx/rue+r5Z+PA==", + "dev": true, + "license": "MIT", + "funding": { + "url": "https://github.com/sponsors/oxc-project" + } + }, + "node_modules/@playwright/test": { + "version": "1.63.0", + "resolved": "https://registry.npmjs.org/@playwright/test/-/test-1.63.0.tgz", + "integrity": "sha512-oxMK4vllB9RK5NQ2l1pq1IfOf2AvnEuj/vYGDj0H2nMtmtZpKtCwt/l00GEO6xjGfpBNAvjovvYdCm50dRQkpQ==", + "dev": true, + "license": "Apache-2.0", + "dependencies": { + "playwright": "1.63.0" + }, + "bin": { + "playwright": "cli.js" + }, + "engines": { + "node": ">=20" + } + }, + "node_modules/@rolldown/binding-android-arm-eabi": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.11.tgz", + "integrity": "sha512-A5kXfGKvKWWZE0TtPrfsvT+q4Y5d1QG8gGUzpYjGydM+fARM9MuX90PrXYXe0XbsDVgyxxNzHo6giCj90bsFNw==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-android-arm64": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.11.tgz", + "integrity": "sha512-z6cTycz+iJ4PVkuL4HHW4DfTfoeU/2nqYYuSOrTmH7yHK5Y0LCOnA03V4ZNxavyVaU1oOqUgIg2klN/s+USGOA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-darwin-arm64": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.11.tgz", + "integrity": "sha512-jShvqNtP6vDC6/A5JOAzbVV+DkgHqhl/ScVCJEbt+TUY6QYz7YnXcrg3sLtFBniro0f/Ld50ZwCWA6f7KYD1nQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-darwin-x64": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.11.tgz", + "integrity": "sha512-f2i2xiNWq1Z1l2++q2fuhZRdLAT3aqxD6vRNm1RAxpUoBcdqNB3C0s1Bt+K+PbEx2F5F4gQp6hqKkphCY/xF9w==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-freebsd-x64": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.11.tgz", + "integrity": "sha512-4Ir5FSOKIAMr4r0kExpt1s3bMgzJU3rA45AYOHtQpls0oNeqcYBKrWMlckrYH4KCfGLfkfn1tN1dmZPMVsdXow==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-arm-gnueabihf": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.11.tgz", + "integrity": "sha512-/gnRDM+39BROzAN/k1OZjDPnDMcZxB/0EUxKjONO5yVkNEvlsoMDrxGNKgZi/ttFriS2gwlDNzB65pvNbFOXIQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-arm64-gnu": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.11.tgz", + "integrity": "sha512-PFaK8HwvAHbaKbBcDNQihjMKYvFnA5hiENx/l5tphTDz1E0WFp32l0A7aq7lyUwGsRw/xSrNIy/gIK4thrSCrw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-arm64-musl": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.11.tgz", + "integrity": "sha512-AskzJUIKRLPxkruR1wLKewGbOw+EYfU/9lOrBFj4AFrEA8hPpKFnODWNu2WLaNs0QNkEb9QIJufmVZZIL/bJlg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-ppc64-gnu": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.11.tgz", + "integrity": "sha512-qlUGAheh2yh8afH7QBgx0PrRHN85hKnNd78x8MeMhXivuevgd8vgf6/CstOzmNKY/lLTHvNTrPy98cLnAugzJw==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-s390x-gnu": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.11.tgz", + "integrity": "sha512-secpEad+0vCbSfn8upFySkDskv+bGPk3THSDS9Y89yc4rb4kzqHp8Dmyd9BkQW4SnhNXBZCl/6CrO//hZahNJQ==", + "cpu": [ + "s390x" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-x64-gnu": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.11.tgz", + "integrity": "sha512-mOVBT3dPpkWm8XBWPmU4bf+U6dYDLeMo/9ojUmis4N0L5uu10qra5vOyngZ7/PSdoE4G9KvRt4bloRxNjLas7A==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-linux-x64-musl": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.11.tgz", + "integrity": "sha512-Is78i9A8Ui4SqcxUwFJ9uMmjDn58IbVTjFWYdQestFEgeuEmHMLGNriXnVJKkwG2YiZjw8cP0zCTyDMdDGtOOg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-openharmony-arm64": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.11.tgz", + "integrity": "sha512-dUCXneZ87INUMyQ0D+C0HrEBNUPNXHaPmU5GTjyKTJEiussw9Kaj5Ln8UztPe4epV/ffvgNBEadksdYhmW6xJA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openharmony" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-win32-arm64-msvc": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.11.tgz", + "integrity": "sha512-jByxb6qfd+bH1xUd0qnfFnb17i9sWBPY2tOavJ0l3tdr3OTu+Kvtm8cd/JV5nFt657b1VqGltxg9olOEfofXWw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/binding-win32-x64-msvc": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.11.tgz", + "integrity": "sha512-/PzKqzAJ03i19oy2ItPvyvaVjOjBCNnfaJs8yvUdGBKmiESgnrJSQ2awd81QzFbbnAmu7YO9ZnJrDCb9VSJPRA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/@rolldown/pluginutils": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/@rolldown/pluginutils/-/pluginutils-1.0.1.tgz", + "integrity": "sha512-2j9bGt5Jh8hj+vPtgzPtl72j0yRxHAyumoo6TNfAjsLB04UtpSvPbPcDcBMxz7n+9CYB0c1GxQFxYRg2jimqGw==", + "dev": true, + "license": "MIT" + }, + "node_modules/@types/react": { + "version": "19.3.0", + "resolved": "https://registry.npmjs.org/@types/react/-/react-19.3.0.tgz", + "integrity": "sha512-N0rFCuH9YoxG9/m61l9MfpJKfmLOVU0em7ipIz6TRgSSkvReLB9vL85GB+yr8Bs5leqpvg96JSwF4ZS1s4viQg==", + "dev": true, + "license": "MIT", + "dependencies": { + "csstype": "^3.2.2" + } + }, + "node_modules/@types/react-dom": { + "version": "19.3.0", + "resolved": "https://registry.npmjs.org/@types/react-dom/-/react-dom-19.3.0.tgz", + "integrity": "sha512-ZI7bU42mZXXKHn/qNLEw2IrbiINU7X5+vfgdixBHkCNpYWXjKgfQ/P+uyGb5CjOLB9UcnTeg3rylQtV2hym44Q==", + "dev": true, + "license": "MIT", + "peerDependencies": { + "@types/react": "^19.3.0" + } + }, + "node_modules/@typescript/typescript-aix-ppc64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-aix-ppc64/-/typescript-aix-ppc64-7.0.2.tgz", + "integrity": "sha512-MTKKkWB7p/0E9xi1d1tHtZ5PiLkGEMIq88pK2CubZjOsLtYTLqhgIgi6zepFa+9GHZ6h05NMCkQxGKiPXMxXtQ==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "aix" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-darwin-arm64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-darwin-arm64/-/typescript-darwin-arm64-7.0.2.tgz", + "integrity": "sha512-gowzar9MwS/aRWp6f3a4KUqzRjAZjOsmGNCM6LcTgXum+dBfgsBVMN+AgvOCCbguXyick6LJhpBszxMebJ8syA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-darwin-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-darwin-x64/-/typescript-darwin-x64-7.0.2.tgz", + "integrity": "sha512-SZ9xZInqApNlNGc9s0W1VSsktYSOe9cFqNOIqmN1Gs8SmkjKZYFt017G4VwPxASInODuAdbTW7sXiFUf893RgA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-freebsd-arm64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-freebsd-arm64/-/typescript-freebsd-arm64-7.0.2.tgz", + "integrity": "sha512-W5NH4y/J0plIIS5b2xvTEkU7JFxyqdMAOgf+Ilhl0vHQXKO5dZoxd+C/jEtq56c4F3wk71RB4BMRQ2XdI+bwYQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-freebsd-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-freebsd-x64/-/typescript-freebsd-x64-7.0.2.tgz", + "integrity": "sha512-UMGDx5sTpzNw3WiPebH7l90IWfJggEd+egHt/q6p7/Cm3zqoV7VxkGXt+3DxPIw8CcmvAB0j3sVVfbhX+M4Tpw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-arm": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-arm/-/typescript-linux-arm-7.0.2.tgz", + "integrity": "sha512-gffT3xPz9sR7j/YJExkyPntrI0P2EP9XbOyWzth2/Gs0RstK+90RBcO0ncXoXy/beYll1SXw846Nf2zdnEz0QQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-arm64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-arm64/-/typescript-linux-arm64-7.0.2.tgz", + "integrity": "sha512-Qh4eU4/y3yDjnfjjyPYihMj5/ODIlmt+Bzu17OI+fiSRDW57QmU5SiN63exPRNJPKUzcc1INa1NXdrJ+MqHjUQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-loong64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-loong64/-/typescript-linux-loong64-7.0.2.tgz", + "integrity": "sha512-uEHck9i8hoAzXPiYRib1O7miOnz23SxIeVl6F4LXox+qov1K35jHcEW6VHKvZI+pyvl7fZEP4MCU5LYvIq1GuQ==", + "cpu": [ + "loong64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-mips64el": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-mips64el/-/typescript-linux-mips64el-7.0.2.tgz", + "integrity": "sha512-R4KvAMnE43W5Qeqb0Ly56O3mWMWIAgsMyz36DCaycd5nbg/9kzm0liw3JocfRqyJY0KPmzFjbswozXyW0DnIYA==", + "cpu": [ + "mips64el" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-ppc64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-ppc64/-/typescript-linux-ppc64-7.0.2.tgz", + "integrity": "sha512-DORx5b3sd/4S7eayxm4FQv+A7CrkUIGRaHiwI8oiHTAI1fAPWhF4J0vAlkC8biAlHSVVwxMQ3tjZ2/DVbnQiiA==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-riscv64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-riscv64/-/typescript-linux-riscv64-7.0.2.tgz", + "integrity": "sha512-wf0jqEDOjrPRnKwYRyyJDRo11KMbvMFrU+q4zqKyChODBzvlkbhNQfKvLxQCcwTpdDaXSHZTVuh0JoCrKCUMHQ==", + "cpu": [ + "riscv64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-s390x": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-s390x/-/typescript-linux-s390x-7.0.2.tgz", + "integrity": "sha512-IkwJc3L7yhytWd/ewjyxNDfOmswCm9GWMJT/ue/dU4aZNbwZeYAetq42VyLmsmSjvoX7z74X6ZaYCtzAr0EuGw==", + "cpu": [ + "s390x" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-linux-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-linux-x64/-/typescript-linux-x64-7.0.2.tgz", + "integrity": "sha512-EYdf2cNg7rgCWJnxCdJ+F3V39O8ihb37eHAu1LK8oAFizgTQbPOK7zHHXbPt8rX24COqODXeI3sIf0fCXG7H/A==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-netbsd-arm64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-netbsd-arm64/-/typescript-netbsd-arm64-7.0.2.tgz", + "integrity": "sha512-+polYF4MF04aPpO5FTkHran9yUQDSXqy5GiSDKpsll5jy3l3+g9QLhpf39T+ePtefhXLOGrLl0QIjkQP6VnelA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "netbsd" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-netbsd-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-netbsd-x64/-/typescript-netbsd-x64-7.0.2.tgz", + "integrity": "sha512-8YIT0EHM/3dq10ZOVF/A7pc/YSMtbcecct4rWtexrnSCHOPcpC2KTLXfTCR6vDpnSiY12heNb1GiN/wu+T/FyA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "netbsd" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-openbsd-arm64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-openbsd-arm64/-/typescript-openbsd-arm64-7.0.2.tgz", + "integrity": "sha512-APT8+ClYnuYm1u9+kgGXoMj2VzWzcymwh2gNSQVySHfkRDGOTVkoWLjCmOQSaO+PoqQ57B0flRp9SA+7GnnkzQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "openbsd" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-openbsd-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-openbsd-x64/-/typescript-openbsd-x64-7.0.2.tgz", + "integrity": "sha512-yX7s+Q0Dln0Dt9tEzZsAjXXR/+ytBM7AlglaqyeMPxQszJ1JhlJdZ6jLA+IzldHtflX81em7lDao1xXu+aRRkg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "openbsd" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-sunos-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-sunos-x64/-/typescript-sunos-x64-7.0.2.tgz", + "integrity": "sha512-dLJDGaLZ1D4HPQn62u1n8mBDkJREwMsAkCdkwd4Ieqw+x3TUyTsqY0YiBCtE6H6OzzgGk3iuZ3vFWRS+E8/d1g==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "sunos" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-win32-arm64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-win32-arm64/-/typescript-win32-arm64-7.0.2.tgz", + "integrity": "sha512-Gyl1Vy6OsWesLzmq+EP0Fb7b4Nid5232AvcA2SFcdYreldpNtYFFofPjnt62y9hQy7VTaZp65ICJjuAQRaVcIQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/@typescript/typescript-win32-x64": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/@typescript/typescript-win32-x64/-/typescript-win32-x64-7.0.2.tgz", + "integrity": "sha512-0BQ3HkAHHlKLSp1qRvf3SUhGpGsDuhB/jgFw75guyqbxJqEaS0Cw/VFO8i2nHglJUzQCRtMMR/IBAKE3ETMC4g==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "Apache-2.0", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=16.20.0" + } + }, + "node_modules/csstype": { + "version": "3.2.3", + "resolved": "https://registry.npmjs.org/csstype/-/csstype-3.2.3.tgz", + "integrity": "sha512-z1HGKcYy2xA8AGQfwrn0PAy+PB7X/GSj3UVJW9qKyn43xWa+gl5nXmU4qqLMRzWVLFC8KusUX8T/0kCiOYpAIQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/detect-libc": { + "version": "2.1.2", + "resolved": "https://registry.npmjs.org/detect-libc/-/detect-libc-2.1.2.tgz", + "integrity": "sha512-Btj2BOOO83o3WyH59e8MgXsxEQVcarkUOpEYrubB0urwnN10yQ364rsiByU11nZlqWYZm05i/of7io4mzihBtQ==", + "dev": true, + "license": "Apache-2.0", + "engines": { + "node": ">=8" + } + }, + "node_modules/fdir": { + "version": "6.5.0", + "resolved": "https://registry.npmjs.org/fdir/-/fdir-6.5.0.tgz", + "integrity": "sha512-tIbYtZbucOs0BRGqPJkshJUYdL+SDH7dVM8gjy+ERp3WAUjLEFJE+02kanyHtwjWOnwrKYBiwAmM0p4kLJAnXg==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=12.0.0" + }, + "peerDependencies": { + "picomatch": "^3 || ^4" + }, + "peerDependenciesMeta": { + "picomatch": { + "optional": true + } + } + }, + "node_modules/fsevents": { + "version": "2.3.3", + "resolved": "https://registry.npmjs.org/fsevents/-/fsevents-2.3.3.tgz", + "integrity": "sha512-5xoDfX+fL7faATnagmWPpbFtwh/R77WmMMqqHGS65C3vvB0YHrgF+B1YmZ3441tMj5n63k0212XNoJwzlhffQw==", + "dev": true, + "hasInstallScript": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^8.16.0 || ^10.6.0 || >=11.0.0" + } + }, + "node_modules/lightningcss": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss/-/lightningcss-1.33.0.tgz", + "integrity": "sha512-WkUDrojuJs0xkgGf2udWxa3yGBRxPtxUkB79i6aCZLRgc7PM8fZe9TosfPDcvEpQZbuFASnHYmRLBLUbmLOIIA==", + "dev": true, + "license": "MPL-2.0", + "dependencies": { + "detect-libc": "^2.0.3" + }, + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + }, + "optionalDependencies": { + "lightningcss-android-arm64": "1.33.0", + "lightningcss-darwin-arm64": "1.33.0", + "lightningcss-darwin-x64": "1.33.0", + "lightningcss-freebsd-x64": "1.33.0", + "lightningcss-linux-arm-gnueabihf": "1.33.0", + "lightningcss-linux-arm64-gnu": "1.33.0", + "lightningcss-linux-arm64-musl": "1.33.0", + "lightningcss-linux-x64-gnu": "1.33.0", + "lightningcss-linux-x64-musl": "1.33.0", + "lightningcss-win32-arm64-msvc": "1.33.0", + "lightningcss-win32-x64-msvc": "1.33.0" + } + }, + "node_modules/lightningcss-android-arm64": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-android-arm64/-/lightningcss-android-arm64-1.33.0.tgz", + "integrity": "sha512-gEpRTalKdosp4Bb8qWtc2iOgE5SeIHlpS1up9bFq2wAyYhl1UdTObYiHe98zEM9SQvSoqQZ1IQD0JNpg3Ml5pg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-darwin-arm64": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-darwin-arm64/-/lightningcss-darwin-arm64-1.33.0.tgz", + "integrity": "sha512-Sciaz8eenNTKn9b3t7+xr0ipTp9YxKQY4npwQ3mrRuL0BAVHBLyZxofhaKBAVtzmtRZ/zTyo0/to4B1uWG/Djg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-darwin-x64": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-darwin-x64/-/lightningcss-darwin-x64-1.33.0.tgz", + "integrity": "sha512-Z5UPAxzrjlWNNyGy6i65cJzzvgJ5D3T6wMvs+gWpY9d7qRhANrxqAp6LhxIgZhWEw18RfJTGcRxjuLIBr+m8XQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-freebsd-x64": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-freebsd-x64/-/lightningcss-freebsd-x64-1.33.0.tgz", + "integrity": "sha512-QQM/Ti/hQajJwCY+RiWuCZ9sdtI/XQk7nDK5vC8kkdwixezOlDgvDx7+RT+QjK6FcFT4MpsuoBnHIo/O3StRRg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-linux-arm-gnueabihf": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-linux-arm-gnueabihf/-/lightningcss-linux-arm-gnueabihf-1.33.0.tgz", + "integrity": "sha512-N7FVBe6iS24MlM6R/4RBTxGhQheZGs7tiQ9U32UtF75NzP5Q7xWPRqLBCKxlRQRk3rY1jCIPLzx7WzOhuUIRLQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-linux-arm64-gnu": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-linux-arm64-gnu/-/lightningcss-linux-arm64-gnu-1.33.0.tgz", + "integrity": "sha512-j2v/itmy4HlNxlc6voKXYgBqNi0Ng2LShg4z7GufpEgs05P+2suBVyi9I6YHq5uoVFx9ETin3eCEhLVyXGQnKg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-linux-arm64-musl": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-linux-arm64-musl/-/lightningcss-linux-arm64-musl-1.33.0.tgz", + "integrity": "sha512-yiO5ROMuYQgXbC60yjZU5CYSFZGKXL0HFATXt9mHJn1+zW55oCtMI9NfcVhYLMFDL7gV7oBPon/EmMMGg2OvtQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-linux-x64-gnu": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-linux-x64-gnu/-/lightningcss-linux-x64-gnu-1.33.0.tgz", + "integrity": "sha512-ar+Ju7LmcN0Jo4FpL4hpFybwNG9/3A/Br5KW2n2jyODg3MEZXaDYADdemoNS+BDNfMgKvylJLj4S5tyRActuAg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-linux-x64-musl": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-linux-x64-musl/-/lightningcss-linux-x64-musl-1.33.0.tgz", + "integrity": "sha512-RYiYbkokw0trfKqqzfF55lginwEPrD3OJDfTuJzFs1MK6iFnDenaz1fqLLtX4ITG3OktJQXOeTaw1awrBAlZPw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-win32-arm64-msvc": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-win32-arm64-msvc/-/lightningcss-win32-arm64-msvc-1.33.0.tgz", + "integrity": "sha512-1K+MPfLSFVpphzpdbfkhlWk6wBrTObBzS2T6db10PNOZgR9GoVsAWzwNyuhUYYbTp23j+4RrncfujZ4uAzXvwA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/lightningcss-win32-x64-msvc": { + "version": "1.33.0", + "resolved": "https://registry.npmjs.org/lightningcss-win32-x64-msvc/-/lightningcss-win32-x64-msvc-1.33.0.tgz", + "integrity": "sha512-OlEICDx/Xl0FqSp4bry8zFnCvGpig3Gl4gCquvYwHuqJKEC1+n9NgDniFvqHGmMv1ZkqDJrDqKKSykTDX+ehuA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MPL-2.0", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">= 12.0.0" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/parcel" + } + }, + "node_modules/nanoid": { + "version": "3.3.19", + "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.19.tgz", + "integrity": "sha512-Y2tUNy4ouw6tq5oDSKeQYGOyhkUBhNOcGV/02KC+6kd9eDGqdZd++mjMiIDilrBYvjEnCYvVtsuHCuP+okSfug==", + "dev": true, + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/ai" + } + ], + "license": "MIT", + "bin": { + "nanoid": "bin/nanoid.cjs" + }, + "engines": { + "node": "^10 || ^12 || ^13.7 || ^14 || >=15.0.1" + } + }, + "node_modules/picocolors": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/picocolors/-/picocolors-1.1.1.tgz", + "integrity": "sha512-xceH2snhtb5M9liqDsmEw56le376mTZkEX/jEb/RxNFyegNul7eNslCXP9FDj/Lcu0X8KEyMceP2ntpaHrDEVA==", + "dev": true, + "license": "ISC" + }, + "node_modules/picomatch": { + "version": "4.0.7", + "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.7.tgz", + "integrity": "sha512-qcJu88Q2IWqJsDD529JKMdwGm/dvInW4HvQnRwiH9JtihJvzGOscDtHE3x1pBKeUOTysQ8kVmLnJ2kJu7yhcGA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=12" + }, + "funding": { + "url": "https://github.com/sponsors/jonschlinkert" + } + }, + "node_modules/playwright": { + "version": "1.63.0", + "resolved": "https://registry.npmjs.org/playwright/-/playwright-1.63.0.tgz", + "integrity": "sha512-+7ziBLidS4NaNCdt57SUDT+wYmmd5fmiQejUic/kb+YsYSCPyOOE9sebzMjNmQrsnNpDJqd4WHvV/8lfKfUDUg==", + "dev": true, + "license": "Apache-2.0", + "dependencies": { + "playwright-core": "1.63.0" + }, + "bin": { + "playwright": "cli.js" + }, + "engines": { + "node": ">=20" + } + }, + "node_modules/playwright-core": { + "version": "1.63.0", + "resolved": "https://registry.npmjs.org/playwright-core/-/playwright-core-1.63.0.tgz", + "integrity": "sha512-rYCsBF/M5HjUch52bbtVONEFjv6Xu8sm8h72dNlR5bzIE1fvC/bxgspzkjSfU+MweEMmPM8KJebG6nnyxo5mCg==", + "dev": true, + "license": "Apache-2.0", + "bin": { + "playwright-core": "cli.js" + }, + "engines": { + "node": ">=20" + } + }, + "node_modules/postcss": { + "version": "8.5.28", + "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.28.tgz", + "integrity": "sha512-RRuzqDtt5Y9h3quz5hWhK+TPnsmVs6WwSU6LkJMeY4HstUEDuYTG8UJSdawMRzmzAtV+KEoG8N3Qg2qLy5vM/A==", + "dev": true, + "funding": [ + { + "type": "opencollective", + "url": "https://opencollective.com/postcss/" + }, + { + "type": "tidelift", + "url": "https://tidelift.com/funding/github/npm/postcss" + }, + { + "type": "github", + "url": "https://github.com/sponsors/ai" + } + ], + "license": "MIT", + "dependencies": { + "nanoid": "^3.3.18", + "picocolors": "^1.1.1", + "source-map-js": "^1.2.1" + }, + "engines": { + "node": "^10 || ^12 || >=14" + } + }, + "node_modules/react": { + "version": "19.3.0", + "resolved": "https://registry.npmjs.org/react/-/react-19.3.0.tgz", + "integrity": "sha512-E8LUcbtBWt20bbl2YoHfx4ZDBdxVTfOKtCZn9cDSJ4l6/nuoApcpIBcj47t2wZoVX8g2ZHuMHbiShgCR1T5Sog==", + "license": "MIT", + "engines": { + "node": ">=0.10.0" + } + }, + "node_modules/react-dom": { + "version": "19.3.0", + "resolved": "https://registry.npmjs.org/react-dom/-/react-dom-19.3.0.tgz", + "integrity": "sha512-JDk8dgif51OjFoDE70+OT9ICyYr+69HlmihNwp1+Nsfbna3t5sIiCa9ZJktDmQ4/1b/rn26hIAR2uYXDMr5r0Q==", + "license": "MIT", + "dependencies": { + "scheduler": "^0.28.0" + }, + "peerDependencies": { + "react": "^19.3.0" + } + }, + "node_modules/rolldown": { + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.11.tgz", + "integrity": "sha512-qpSwIyz0jHQq5qXBTNxFmE6664rJ7O+4TvPFOiOaBSrz8IOHc1koKKSqTM2H6u1UG1+TveuC6vaDHKXFOvb1Kw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@oxc-project/types": "=0.151.0", + "@rolldown/pluginutils": "^1.0.0" + }, + "bin": { + "rolldown": "bin/cli.mjs" + }, + "engines": { + "node": "^20.19.0 || >=22.12.0" + }, + "optionalDependencies": { + "@rolldown/binding-android-arm-eabi": "1.2.11", + "@rolldown/binding-android-arm64": "1.2.11", + "@rolldown/binding-darwin-arm64": "1.2.11", + "@rolldown/binding-darwin-x64": "1.2.11", + "@rolldown/binding-freebsd-x64": "1.2.11", + "@rolldown/binding-linux-arm-gnueabihf": "1.2.11", + "@rolldown/binding-linux-arm64-gnu": "1.2.11", + "@rolldown/binding-linux-arm64-musl": "1.2.11", + "@rolldown/binding-linux-ppc64-gnu": "1.2.11", + "@rolldown/binding-linux-s390x-gnu": "1.2.11", + "@rolldown/binding-linux-x64-gnu": "1.2.11", + "@rolldown/binding-linux-x64-musl": "1.2.11", + "@rolldown/binding-openharmony-arm64": "1.2.11", + "@rolldown/binding-win32-arm64-msvc": "1.2.11", + "@rolldown/binding-win32-x64-msvc": "1.2.11" + } + }, + "node_modules/scheduler": { + "version": "0.28.0", + "resolved": "https://registry.npmjs.org/scheduler/-/scheduler-0.28.0.tgz", + "integrity": "sha512-juorfCmIkIw8tT+p5BXSm6PJjQF/ycEYmKyzURCIt/RaZIhL+PulbQ9Yu2z1HdOJDdqDTlxA1+xKBmHXJsczAw==", + "license": "MIT" + }, + "node_modules/source-map-js": { + "version": "1.2.1", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", + "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "dev": true, + "license": "BSD-3-Clause", + "engines": { + "node": ">=0.10.0" + } + }, + "node_modules/tinyglobby": { + "version": "0.2.17", + "resolved": "https://registry.npmjs.org/tinyglobby/-/tinyglobby-0.2.17.tgz", + "integrity": "sha512-wXR/dYpcqKmfWpEdZjiKJOwCNFndD0DMnrW/cYjVGttEkBfVgcLFHoNrlj47mjOVic9yyNu65alsgF4NQyTa2g==", + "dev": true, + "license": "MIT", + "dependencies": { + "fdir": "^6.5.0", + "picomatch": "^4.0.4" + }, + "engines": { + "node": ">=12.0.0" + }, + "funding": { + "url": "https://github.com/sponsors/SuperchupuDev" + } + }, + "node_modules/typescript": { + "version": "7.0.2", + "resolved": "https://registry.npmjs.org/typescript/-/typescript-7.0.2.tgz", + "integrity": "sha512-8FYau96o3NKOhbjKi/qNvG/W5jhzxkbdm5sj9AbZ/5T5sWqn3hJgLfGx27sRKZWTvyzCP8dLRBTf5tBTSRVUNA==", + "dev": true, + "license": "Apache-2.0", + "bin": { + "tsc": "bin/tsc" + }, + "engines": { + "node": ">=16.20.0" + }, + "optionalDependencies": { + "@typescript/typescript-aix-ppc64": "7.0.2", + "@typescript/typescript-darwin-arm64": "7.0.2", + "@typescript/typescript-darwin-x64": "7.0.2", + "@typescript/typescript-freebsd-arm64": "7.0.2", + "@typescript/typescript-freebsd-x64": "7.0.2", + "@typescript/typescript-linux-arm": "7.0.2", + "@typescript/typescript-linux-arm64": "7.0.2", + "@typescript/typescript-linux-loong64": "7.0.2", + "@typescript/typescript-linux-mips64el": "7.0.2", + "@typescript/typescript-linux-ppc64": "7.0.2", + "@typescript/typescript-linux-riscv64": "7.0.2", + "@typescript/typescript-linux-s390x": "7.0.2", + "@typescript/typescript-linux-x64": "7.0.2", + "@typescript/typescript-netbsd-arm64": "7.0.2", + "@typescript/typescript-netbsd-x64": "7.0.2", + "@typescript/typescript-openbsd-arm64": "7.0.2", + "@typescript/typescript-openbsd-x64": "7.0.2", + "@typescript/typescript-sunos-x64": "7.0.2", + "@typescript/typescript-win32-arm64": "7.0.2", + "@typescript/typescript-win32-x64": "7.0.2" + } + }, + "node_modules/vite": { + "version": "8.3.1", + "resolved": "https://registry.npmjs.org/vite/-/vite-8.3.1.tgz", + "integrity": "sha512-/bvH9E9tmCXRGp2uXY3WbOldqpTwFkbha/8ANaEQ6VkxhH60KyqLwgZq6lG2y+4uT55x9+9eUHMpQ7uGnOCKjA==", + "dev": true, + "license": "MIT", + "dependencies": { + "lightningcss": "^1.33.0", + "picomatch": "^4.0.7", + "postcss": "^8.5.28", + "rolldown": "~1.2.9", + "tinyglobby": "^0.2.17" + }, + "bin": { + "vite": "bin/vite.js" + }, + "engines": { + "node": "^20.19.0 || >=22.12.0" + }, + "funding": { + "url": "https://github.com/vitejs/vite?sponsor=1" + }, + "optionalDependencies": { + "fsevents": "~2.3.3" + }, + "peerDependencies": { + "@types/node": "^20.19.0 || >=22.12.0", + "@vitejs/devtools": "^0.7.1", + "esbuild": "^0.27.0 || ^0.28.0", + "jiti": ">=1.21.0", + "less": "^4.0.0", + "sass": "^1.70.0", + "sass-embedded": "^1.70.0", + "stylus": ">=0.54.8", + "sugarss": "^5.0.0", + "terser": "^5.16.0", + "tsx": "^4.8.1", + "yaml": "^2.4.2" + }, + "peerDependenciesMeta": { + "@types/node": { + "optional": true + }, + "@vitejs/devtools": { + "optional": true + }, + "esbuild": { + "optional": true + }, + "jiti": { + "optional": true + }, + "less": { + "optional": true + }, + "sass": { + "optional": true + }, + "sass-embedded": { + "optional": true + }, + "stylus": { + "optional": true + }, + "sugarss": { + "optional": true + }, + "terser": { + "optional": true + }, + "tsx": { + "optional": true + }, + "yaml": { + "optional": true + } + } + } + } +} diff --git a/frontend/package.json b/frontend/package.json new file mode 100644 index 0000000..ebb6bf4 --- /dev/null +++ b/frontend/package.json @@ -0,0 +1,22 @@ +{ + "name": "iam-login-ui", + "private": true, + "version": "0.0.1", + "type": "module", + "scripts": { + "build": "tsc --noEmit && vite build", + "watch": "vite build --watch", + "test:browser": "playwright test" + }, + "dependencies": { + "react": "19.3.0", + "react-dom": "19.3.0" + }, + "devDependencies": { + "vite": "8.3.1", + "typescript": "7.0.2", + "@types/react": "^19.2.0", + "@types/react-dom": "^19.2.0", + "@playwright/test": "1.63.0" + } +} diff --git a/frontend/playwright.config.ts b/frontend/playwright.config.ts new file mode 100644 index 0000000..586bad4 --- /dev/null +++ b/frontend/playwright.config.ts @@ -0,0 +1,8 @@ +import { defineConfig } from "@playwright/test"; +export default defineConfig({ + testDir: "./tests", + use: { + baseURL: process.env.IAM_AD_URL, + headless: true, + }, +}); diff --git a/frontend/src/components/SubmitForm.tsx b/frontend/src/components/SubmitForm.tsx new file mode 100644 index 0000000..b5eee3a --- /dev/null +++ b/frontend/src/components/SubmitForm.tsx @@ -0,0 +1,23 @@ +import { useState, type ReactNode } from "react"; +import type { CsrfToken } from "../page-context"; + +type Props = { + action: string; + csrf: CsrfToken; + label: string; + children?: ReactNode; +}; + +/** Submit a browser document request; the server owns authentication transitions. */ +export function SubmitForm({ action, csrf, label, children }: Props) { + const [pending, setPending] = useState(false); + return ( +
setPending(true)} aria-busy={pending}> + + {children} + +
+ ); +} diff --git a/frontend/src/main.tsx b/frontend/src/main.tsx new file mode 100644 index 0000000..0125aff --- /dev/null +++ b/frontend/src/main.tsx @@ -0,0 +1,8 @@ +import { createRoot } from "react-dom/client"; +import { readPageContext } from "./page-context"; +import { SignInPage } from "./pages/SignInPage"; +import "./style.css"; + +createRoot(document.getElementById("root")!).render( + , +); diff --git a/frontend/src/page-context.ts b/frontend/src/page-context.ts new file mode 100644 index 0000000..70a0614 --- /dev/null +++ b/frontend/src/page-context.ts @@ -0,0 +1,32 @@ +export type CsrfToken = { name: string; value: string }; + +type PageBase = { + name: string; + error: string; + action: string; + csrf: CsrfToken; +}; + +export type SignInContext = PageBase & ( + | { step: "password" } + | { + step: "mfa-pending"; + identity: { + username: string; + subjectId: string; + email: string; + groups: string[]; + groupDns: string[]; + }; + } +); + +export function readPageContext(): SignInContext { + const data = document.getElementById("login-context")?.textContent; + if (!data) throw new Error("Missing login page context"); + const context: SignInContext = JSON.parse(data); + if (context.step !== "password" && context.step !== "mfa-pending") { + throw new Error("Unknown login step"); + } + return context; +} diff --git a/frontend/src/pages/SignInPage.tsx b/frontend/src/pages/SignInPage.tsx new file mode 100644 index 0000000..f565cdd --- /dev/null +++ b/frontend/src/pages/SignInPage.tsx @@ -0,0 +1,54 @@ +import { SubmitForm } from "../components/SubmitForm"; +import type { SignInContext } from "../page-context"; + +export function SignInPage({ context }: { context: SignInContext }) { + return ( +
+
iam
+
+
AD 登录验证
+

+ {context.step === "password" ? "登录你的账号" : "密码已验证,等待 MFA"} +

+

+ {context.step === "password" + ? "使用 AD 用户名或完整 UPN 登录。" + : `${context.name},目录验证成功。第二因素尚未接入,本次没有完成登录或向应用授权。`} +

+ {context.error &&

{context.error}

} + {context.step === "mfa-pending" && ( +
+
+
账号
{context.identity.username}
+
目录标识
{context.identity.subjectId}
+
邮箱
{context.identity.email || "未设置"}
+
+

直接所属组

+ {context.identity.groups.length + ?
    {context.identity.groups.map(group =>
  • {group}
  • )}
+ :

没有直接所属组。

} +
+ 组 DN +
    {context.identity.groupDns.map(dn =>
  • {dn}
  • )}
+
+

当前仅读取 memberOf,不展开嵌套组,也不包含主组。

+
+ )} + + {context.step === "password" && <> + + + } + +
+
独立 IAM · AD 接入验证
+
+ ); +} diff --git a/frontend/src/style.css b/frontend/src/style.css new file mode 100644 index 0000000..8cb080e --- /dev/null +++ b/frontend/src/style.css @@ -0,0 +1,155 @@ +:root { + font-family: Inter, "Noto Sans SC", system-ui, sans-serif; + color: #182826; + background: #f3f5f1; + font-synthesis: none; + font-size: 16px; +} +* { + box-sizing: border-box; +} +body { + margin: 0; +} +main { + max-width: 520px; + margin: 0 auto; + padding: 40px 20px 28px; +} +header { + margin-bottom: 40px; +} +.brand { + font-size: 32px; + font-weight: 750; + letter-spacing: -2px; + color: #285448; + text-decoration: none; +} +.brand > span:first-child { + font-weight: 400; +} +.card { + background: #fff; + border: 1px solid #dce4dd; + border-radius: 18px; + padding: 36px; + box-shadow: 0 12px 40px #173f2510; +} +.eyebrow { + font-size: 12px; + color: #60746a; + letter-spacing: 2px; +} +h1 { + font-size: 27px; + letter-spacing: -0.5px; + line-height: 1.35; + margin: 0 0 12px; + overflow-wrap: anywhere; +} +.intro { + font-size: 14px; + color: #60716a; + line-height: 1.8; + margin: 0 0 25px; +} +label { + display: block; + font-size: 14px; + font-weight: 600; +} +input:not([type="hidden"]) { + display: block; + width: 100%; + border: 1px solid #bdccc1; + border-radius: 8px; + padding: 13px 14px; + margin: 9px 0 22px; + font: inherit; + color: inherit; + background: #fff; +} +input:focus { + outline: 3px solid #a9cbbc; + outline-offset: 2px; +} +button { + font: inherit; + cursor: pointer; +} +.primary { + width: 100%; + border: 0; + background: #245b47; + color: #fff; + font-weight: 600; + border-radius: 8px; + padding: 13px; +} +.primary:hover { + background: #194734; +} +.primary:disabled { + opacity: 0.65; + cursor: wait; +} +.error { + color: #9e302b; + background: #fff0ed; + padding: 12px; + border-radius: 8px; + font-size: 14px; + line-height: 1.6; +} +footer { + text-align: center; + color: #7c887e; + font-size: 12px; + margin-top: 28px; +} +a:focus-visible, +button:focus-visible { + outline: 3px solid #a9cbbc; + outline-offset: 3px; +} +@media (max-width: 480px) { + main { + padding-top: 24px; + } + header { + margin-bottom: 24px; + } + .card { + padding: 26px 22px; + } +} +@media (prefers-color-scheme: dark) { + :root { + background: #14221c; + color: #edf4ee; + } + .card { + background: #1e3027; + border-color: #344b3d; + } + .brand { + color: #b9ddc8; + } + .intro, + .eyebrow { + color: #acbfb2; + } + input:not([type="hidden"]) { + background: #18271f; + border-color: #526657; + } + .error { + background: #492b29; + color: #ffc3b9; + } +} + +.directory-result { overflow-wrap: anywhere; } +.directory-result dd { margin: 0 0 1rem; } +.directory-result h2 { font-size: 1rem; } diff --git a/frontend/src/vite-env.d.ts b/frontend/src/vite-env.d.ts new file mode 100644 index 0000000..11f02fe --- /dev/null +++ b/frontend/src/vite-env.d.ts @@ -0,0 +1 @@ +/// diff --git a/frontend/tests/ad-login.spec.ts b/frontend/tests/ad-login.spec.ts new file mode 100644 index 0000000..8946864 --- /dev/null +++ b/frontend/tests/ad-login.spec.ts @@ -0,0 +1,31 @@ +import { test, expect } from "@playwright/test"; + +// Explicit opt-in: never submit synthetic credentials to an arbitrary configured directory. +// The external-domain username below must be rejected before any LDAP bind. +test("AD HTTPS page uses native POST and keeps failed credentials out of the response", async ({ page, context }) => { + test.skip(!process.env.IAM_AD_URL, "Set IAM_AD_URL to the HTTPS first-factor PoC"); + const url = new URL("/signin", process.env.IAM_AD_URL!); + expect(url.protocol).toBe("https:"); + const requests: { method: string; type: string; path: string }[] = []; + page.on("request", request => requests.push({ + method: request.method(), type: request.resourceType(), path: new URL(request.url()).pathname, + })); + await page.goto(url.toString()); + await expect(page.getByRole("heading", { name: "登录你的账号" })).toBeVisible(); + await expect(page.locator("form")).toHaveAttribute("method", "post"); + await expect(page.locator("input[name=_csrf]")).toHaveCount(1); + const session = (await context.cookies()).find(cookie => cookie.name === "JSESSIONID"); + expect(session).toMatchObject({ secure: true, httpOnly: true, sameSite: "Lax" }); + await page.getByLabel("用户名", { exact: true }).fill("ui-check@invalid.example"); + await page.getByLabel("密码", { exact: true }).fill("synthetic-ui-check"); + await page.getByRole("button", { name: "继续", exact: true }).click(); + await expect(page.getByRole("alert")).toContainText("无法验证账号"); + await expect(page.getByLabel("密码", { exact: true })).toHaveValue(""); + expect(await page.content()).not.toContain("synthetic-ui-check"); + expect(requests.filter(request => request.method === "POST")).toEqual([ + { method: "POST", type: "document", path: "/signin/password" }, + ]); + expect(requests.filter(request => ["fetch", "xhr"].includes(request.type))).toHaveLength(0); + await page.setViewportSize({ width: 390, height: 844 }); + expect(await page.evaluate(() => document.documentElement.scrollWidth > innerWidth)).toBe(false); +}); diff --git a/frontend/tsconfig.json b/frontend/tsconfig.json new file mode 100644 index 0000000..3164401 --- /dev/null +++ b/frontend/tsconfig.json @@ -0,0 +1,13 @@ +{ + "compilerOptions": { + "target": "ES2022", + "lib": ["ES2022", "DOM", "DOM.Iterable"], + "module": "ESNext", + "moduleResolution": "Bundler", + "jsx": "react-jsx", + "strict": true, + "noEmit": true, + "skipLibCheck": true + }, + "include": ["src"] +} diff --git a/frontend/vite.config.ts b/frontend/vite.config.ts new file mode 100644 index 0000000..bd6b3a0 --- /dev/null +++ b/frontend/vite.config.ts @@ -0,0 +1,6 @@ +import { defineConfig } from "vite"; + +export default defineConfig({ + base: "/", + build: { outDir: "dist", emptyOutDir: true }, +}); diff --git a/scripts/frontend-in-docker b/scripts/frontend-in-docker new file mode 100755 index 0000000..c3358a7 --- /dev/null +++ b/scripts/frontend-in-docker @@ -0,0 +1,16 @@ +#!/usr/bin/env bash +set -euo pipefail +repo_root=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd) +cache_dir=${IAM_NPM_CACHE:-${XDG_CACHE_HOME:-$HOME/.cache}/iam-login/npm} +mkdir -p -- "$cache_dir" +cache_dir=$(cd -- "$cache_dir" && pwd) +docker_cmd=(docker) +if [[ ${IAM_DOCKER_USE_SUDO:-0} == 1 ]]; then + docker_cmd=(sudo -n docker) +fi +exec "${docker_cmd[@]}" run --rm --network host \ + --cpus 2 --memory 1g --user "$(id -u):$(id -g)" \ + -e HOME=/npm -e npm_config_cache=/npm \ + -v "$cache_dir:/npm" -v "$repo_root:/workspace" \ + -w /workspace/frontend node@sha256:d8e448a56fc63242f70026718378bd4b00f8c82e78d20eefb199224a4d8e33d8 \ + sh -c 'npm ci --no-audit --no-fund && npm run build' diff --git a/scripts/gradle-in-docker b/scripts/gradle-in-docker index d681d2f..2f882da 100755 --- a/scripts/gradle-in-docker +++ b/scripts/gradle-in-docker @@ -13,6 +13,8 @@ if (($# == 0)); then set -- test fi +"$repo_root/scripts/frontend-in-docker" + # Linux host networking is needed for Testcontainers' published ports. exec "${docker_cmd[@]}" run --rm --network host \ --cpus "${IAM_BUILD_CPUS:-4}" --memory "${IAM_BUILD_MEMORY:-8g}" \ diff --git a/scripts/native-smoke.py b/scripts/native-smoke.py index f5ef364..25d48c1 100755 --- a/scripts/native-smoke.py +++ b/scripts/native-smoke.py @@ -59,6 +59,8 @@ def main(): def request(path, authenticated=False): headers = {'Accept': 'text/plain' if authenticated and path == '/actuator/prometheus' else 'application/json'} + if path == '/signin': + headers['Accept'] = 'text/html' if authenticated: headers['Authorization'] = f'Basic {basic}' req = urllib.request.Request(base_url + path, headers=headers) @@ -78,6 +80,7 @@ def main(): ready_seconds = time.monotonic() - started assert request('/actuator/prometheus')[0] == 401, 'Anonymous metrics must be rejected' assert request('/')[0] == 401, 'Anonymous application access must be rejected' + assert request('/signin')[0] == 401, 'Sign-in must be disabled without directory configuration' status, before = request('/actuator/prometheus', authenticated=True) assert status == 200, 'Authenticated Prometheus scrape failed' for _ in range(3): diff --git a/src/main/java/top/ddupan/iam/login/authentication/application/VerifyPassword.java b/src/main/java/top/ddupan/iam/login/authentication/application/VerifyPassword.java new file mode 100644 index 0000000..c4363fa --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/application/VerifyPassword.java @@ -0,0 +1,22 @@ +package top.ddupan.iam.login.authentication.application; + +import top.ddupan.iam.login.authentication.application.port.PasswordAuthenticator; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException.Reason; +import top.ddupan.iam.login.authentication.domain.User; + +/** Resolves the user through the same authenticated directory connection. */ +public final class VerifyPassword { + private final PasswordAuthenticator authenticator; + + public VerifyPassword(PasswordAuthenticator authenticator) { + this.authenticator = authenticator; + } + + public User verify(String username, String password) { + try (var session = authenticator.authenticate(username, password)) { + return session.users().findByLoginName(session.loginName()) + .orElseThrow(() -> new PasswordVerificationException(Reason.REJECTED)); + } + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/application/port/AuthenticatedUserSession.java b/src/main/java/top/ddupan/iam/login/authentication/application/port/AuthenticatedUserSession.java new file mode 100644 index 0000000..bc6aee3 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/application/port/AuthenticatedUserSession.java @@ -0,0 +1,10 @@ +package top.ddupan.iam.login.authentication.application.port; + +import top.ddupan.iam.login.authentication.domain.UserRepository; + +/** Uses the authenticated user's connection, without exposing connection or credential objects. */ +public interface AuthenticatedUserSession extends AutoCloseable { + String loginName(); + UserRepository users(); + @Override void close(); +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/application/port/PasswordAuthenticator.java b/src/main/java/top/ddupan/iam/login/authentication/application/port/PasswordAuthenticator.java new file mode 100644 index 0000000..63ee91e --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/application/port/PasswordAuthenticator.java @@ -0,0 +1,6 @@ +package top.ddupan.iam.login.authentication.application.port; + +/** Password authentication opens a short-lived user repository scope. */ +public interface PasswordAuthenticator { + AuthenticatedUserSession authenticate(String username, String password); +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/application/port/PasswordVerificationException.java b/src/main/java/top/ddupan/iam/login/authentication/application/port/PasswordVerificationException.java new file mode 100644 index 0000000..873e36d --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/application/port/PasswordVerificationException.java @@ -0,0 +1,14 @@ +package top.ddupan.iam.login.authentication.application.port; + +/** Adapter failures translated into application vocabulary, without vendor exception details. */ +public final class PasswordVerificationException extends RuntimeException { + public enum Reason { REJECTED, DISABLED, LOCKED, PASSWORD_EXPIRED, ACCOUNT_EXPIRED, UNAVAILABLE } + private final Reason reason; + + public PasswordVerificationException(Reason reason) { + super(reason.name()); + this.reason = reason; + } + + public Reason reason() { return reason; } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/domain/User.java b/src/main/java/top/ddupan/iam/login/authentication/domain/User.java new file mode 100644 index 0000000..73cd327 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/domain/User.java @@ -0,0 +1,48 @@ +package top.ddupan.iam.login.authentication.domain; + +import java.util.List; +import java.util.Objects; + +/** Directory-owned user aggregate. Identity is stable while profile and membership may change. */ +public final class User { + private final UserId id; + private final String username; + private final String displayName; + private final String email; + private final List memberships; + + public User(UserId id, String username, String displayName, String email, List memberships) { + this.id = Objects.requireNonNull(id); + if (username == null || username.isBlank()) throw new IllegalArgumentException("Missing username"); + this.username = username; + this.displayName = Objects.requireNonNull(displayName); + this.email = Objects.requireNonNull(email); + this.memberships = List.copyOf(memberships); + } + + public UserId id() { return id; } + public String username() { return username; } + public String displayName() { return displayName; } + public String email() { return email; } + public List memberships() { return memberships; } + + @Override public boolean equals(Object other) { return other instanceof User user && id.equals(user.id); } + @Override public int hashCode() { return id.hashCode(); } + + public record UserId(String authority, String value) { + public UserId { + if (authority == null || authority.isBlank() || value == null || value.isBlank()) { + throw new IllegalArgumentException("Missing user identifier"); + } + } + } + + /** External group identifiers are opaque to the domain. */ + public record GroupMembership(String name, String externalId) { + public GroupMembership { + if (name == null || name.isBlank() || externalId == null || externalId.isBlank()) { + throw new IllegalArgumentException("Missing group identifier"); + } + } + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/domain/UserRepository.java b/src/main/java/top/ddupan/iam/login/authentication/domain/UserRepository.java new file mode 100644 index 0000000..caea6cb --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/domain/UserRepository.java @@ -0,0 +1,12 @@ +package top.ddupan.iam.login.authentication.domain; + +import java.util.Optional; + +/** Read-only user collection; directory entries and LDAP types never cross this boundary. */ +public interface UserRepository { + Optional findByLoginName(String loginName); + + final class AccessFailure extends RuntimeException { + public AccessFailure() { super("User repository is unavailable or returned an invalid user"); } + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdEntryMapper.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdEntryMapper.java new file mode 100644 index 0000000..029a79f --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdEntryMapper.java @@ -0,0 +1,27 @@ +package top.ddupan.iam.login.authentication.infrastructure.ad; + +import java.util.Locale; +import javax.naming.NamingException; +import org.springframework.LdapDataEntry; +import org.springframework.ldap.odm.core.impl.DefaultObjectDirectoryMapper; +import top.ddupan.iam.login.authentication.domain.UserRepository; + +/** Keep Spring's ODM mapping while refusing silently truncated AD group attributes. */ +final class AdEntryMapper extends DefaultObjectDirectoryMapper { + @Override + public T mapFromLdapDataEntry(LdapDataEntry entry, Class type) { + var ids = entry.getAttributes().getIDs(); + try { + while (ids.hasMore()) { + if (ids.next().toLowerCase(Locale.ROOT).startsWith("memberof;")) { + throw new UserRepository.AccessFailure(); + } + } + } catch (NamingException ex) { + throw new UserRepository.AccessFailure(); + } finally { + try { ids.close(); } catch (NamingException ignored) { } + } + return super.mapFromLdapDataEntry(entry, type); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdPasswordAuthenticator.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdPasswordAuthenticator.java new file mode 100644 index 0000000..fa8c7d7 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdPasswordAuthenticator.java @@ -0,0 +1,91 @@ +package top.ddupan.iam.login.authentication.infrastructure.ad; + +import java.net.URI; +import java.util.Locale; +import java.util.Map; +import java.util.regex.Pattern; +import org.springframework.boot.context.properties.EnableConfigurationProperties; +import org.springframework.data.ldap.repository.support.SimpleLdapRepository; +import org.springframework.ldap.core.LdapTemplate; +import org.springframework.ldap.core.support.LdapContextSource; +import org.springframework.ldap.core.support.SingleContextSource; +import org.springframework.stereotype.Component; +import top.ddupan.iam.login.authentication.application.port.AuthenticatedUserSession; +import top.ddupan.iam.login.authentication.application.port.PasswordAuthenticator; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException.Reason; + +/** Bind authenticates; the scoped Spring Data repository owns all user and membership reads. */ +@Component +@EnableConfigurationProperties(AdProperties.class) +public final class AdPasswordAuthenticator implements PasswordAuthenticator { + private static final Pattern AD_SUBCODE = Pattern.compile("\\bdata\\s+([0-9a-f]+)", Pattern.CASE_INSENSITIVE); + private final AdProperties properties; + private final LdapContextSource contexts; + + public AdPasswordAuthenticator(AdProperties properties) { + this.properties = properties; + if (!properties.enabled()) { contexts = null; return; } + var uri = URI.create(properties.url()); + if (!"ldaps".equals(uri.getScheme()) || uri.getHost() == null || uri.getUserInfo() != null + || uri.getQuery() != null || uri.getFragment() != null + || properties.domain() == null || properties.domain().isBlank() + || properties.baseDn() == null || properties.baseDn().isBlank()) { + throw new IllegalArgumentException("AD requires an LDAPS URL, domain and base DN"); + } + contexts = new LdapContextSource(); + contexts.setUrl(properties.url()); + contexts.setBase(properties.baseDn()); + contexts.setPooled(false); + contexts.setReferral("ignore"); + contexts.setBaseEnvironmentProperties(Map.of( + "com.sun.jndi.ldap.connect.timeout", "3000", + "com.sun.jndi.ldap.read.timeout", "5000", + "java.naming.ldap.attributes.binary", "objectGUID")); + contexts.afterPropertiesSet(); + } + + @Override + public AuthenticatedUserSession authenticate(String username, String password) { + if (contexts == null) throw new PasswordVerificationException(Reason.UNAVAILABLE); + if (username == null || username.isBlank() || username.length() > 256 + || username.contains("\\") || !username.equals(username.strip()) + || (username.contains("@") && !username.toLowerCase(Locale.ROOT) + .endsWith("@" + properties.domain().toLowerCase(Locale.ROOT))) + || password == null || password.isEmpty() || password.length() > 1024) { + throw new PasswordVerificationException(Reason.REJECTED); + } + String principal = username.contains("@") ? username : username + "@" + properties.domain(); + try { + var connection = new SingleContextSource(contexts.getContext(principal, password)); + try { + var mapper = new AdEntryMapper(); + var operations = new LdapTemplate(connection); + operations.setIgnorePartialResultException(true); + operations.setObjectDirectoryMapper(mapper); + var entries = new SimpleLdapRepository<>(operations, mapper, AdUserEntry.class); + return new AdUserRepository(entries, connection, properties.domain(), principal); + } catch (RuntimeException ex) { + connection.destroy(); + throw ex; + } + } catch (org.springframework.ldap.AuthenticationException ex) { + throw new PasswordVerificationException(reason(ex)); + } catch (org.springframework.ldap.NamingException | org.springframework.dao.DataAccessException ex) { + throw new PasswordVerificationException(Reason.UNAVAILABLE); + } + } + + private static Reason reason(org.springframework.ldap.AuthenticationException exception) { + // Translate AD's diagnostic codes; never expose the diagnostic or credentials to the use case. + var matcher = AD_SUBCODE.matcher(exception.getMessage() == null ? "" : exception.getMessage()); + if (!matcher.find()) return Reason.REJECTED; + return switch (matcher.group(1).toLowerCase(Locale.ROOT)) { + case "533" -> Reason.DISABLED; + case "775" -> Reason.LOCKED; + case "532", "773" -> Reason.PASSWORD_EXPIRED; + case "701" -> Reason.ACCOUNT_EXPIRED; + default -> Reason.REJECTED; + }; + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdProperties.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdProperties.java new file mode 100644 index 0000000..b1441d5 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdProperties.java @@ -0,0 +1,6 @@ +package top.ddupan.iam.login.authentication.infrastructure.ad; + +import org.springframework.boot.context.properties.ConfigurationProperties; + +@ConfigurationProperties("iam.ad") +public record AdProperties(boolean enabled, String url, String domain, String baseDn) {} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserEntry.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserEntry.java new file mode 100644 index 0000000..c562425 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserEntry.java @@ -0,0 +1,20 @@ +package top.ddupan.iam.login.authentication.infrastructure.ad; + +import java.util.List; +import javax.naming.Name; +import lombok.Getter; +import org.springframework.ldap.odm.annotations.Attribute; +import org.springframework.ldap.odm.annotations.Entry; +import org.springframework.ldap.odm.annotations.Id; + +/** Persistence representation, deliberately separate from the domain user. */ +@Getter +@Entry(objectClasses = "user") +public final class AdUserEntry { + @Id private Name dn; + @Attribute(name = "objectGUID", type = Attribute.Type.BINARY) private byte[] objectGuid; + @Attribute(name = "sAMAccountName") private String accountName; + @Attribute(name = "displayName") private String displayName; + @Attribute(name = "mail") private String email; + @Attribute(name = "memberOf") private List memberOf; +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserRepository.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserRepository.java new file mode 100644 index 0000000..a7e6765 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserRepository.java @@ -0,0 +1,82 @@ +package top.ddupan.iam.login.authentication.infrastructure.ad; + +import java.nio.ByteBuffer; +import java.nio.ByteOrder; +import java.util.List; +import java.util.Optional; +import java.util.TreeMap; +import java.util.UUID; +import javax.naming.NamingException; +import javax.naming.ldap.LdapName; +import org.springframework.data.ldap.repository.LdapRepository; +import org.springframework.ldap.core.support.SingleContextSource; +import top.ddupan.iam.login.authentication.application.port.AuthenticatedUserSession; +import top.ddupan.iam.login.authentication.domain.User; +import top.ddupan.iam.login.authentication.domain.User.GroupMembership; +import top.ddupan.iam.login.authentication.domain.User.UserId; +import top.ddupan.iam.login.authentication.domain.UserRepository; +import static org.springframework.ldap.query.LdapQueryBuilder.query; + +/** One authenticated connection and one Spring Data repository per use-case scope. */ +final class AdUserRepository implements UserRepository, AuthenticatedUserSession { + private final LdapRepository entries; + private final SingleContextSource connection; + private final String authority; + private final String loginName; + private boolean closed; + + AdUserRepository(LdapRepository entries, SingleContextSource connection, + String authority, String loginName) { + this.entries = entries; + this.connection = connection; + this.authority = authority; + this.loginName = loginName; + } + + @Override + public Optional findByLoginName(String name) { + requireOpen(); + try { + return entries.findOne(query().where("objectClass").is("user") + .and("objectClass").not().is("computer") + .and(query().where("sAMAccountName").is(name).or("userPrincipalName").is(name))) + .map(this::toUser); + } catch (org.springframework.ldap.NamingException | org.springframework.dao.DataAccessException | IllegalArgumentException ex) { + throw new UserRepository.AccessFailure(); + } + } + + private User toUser(AdUserEntry entry) { + var groups = new TreeMap(); + for (String dn : entry.getMemberOf() == null ? List.of() : entry.getMemberOf()) { + try { + var name = new LdapName(dn); + var rdn = name.getRdn(name.size() - 1); + if (!rdn.getType().equalsIgnoreCase("CN")) throw new UserRepository.AccessFailure(); + String cn = rdn.getValue().toString(); + if (groups.putIfAbsent(cn, new GroupMembership(cn, dn)) != null) { + throw new UserRepository.AccessFailure(); + } + } catch (NamingException ex) { throw new UserRepository.AccessFailure(); } + } + return new User(new UserId(authority, guid(entry.getObjectGuid())), entry.getAccountName(), + entry.getDisplayName() == null ? entry.getAccountName() : entry.getDisplayName(), + entry.getEmail() == null ? "" : entry.getEmail(), List.copyOf(groups.values())); + } + + static String guid(byte[] bytes) { + if (bytes == null || bytes.length != 16) throw new UserRepository.AccessFailure(); + var little = ByteBuffer.wrap(bytes).order(ByteOrder.LITTLE_ENDIAN); + long most = Integer.toUnsignedLong(little.getInt()) << 32 + | (long) Short.toUnsignedInt(little.getShort()) << 16 + | Short.toUnsignedInt(little.getShort()); + return new UUID(most, ByteBuffer.wrap(bytes, 8, 8).getLong()).toString(); + } + + @Override public String loginName() { requireOpen(); return loginName; } + @Override public UserRepository users() { requireOpen(); return this; } + private void requireOpen() { if (closed) throw new IllegalStateException("User repository scope is closed"); } + @Override public void close() { + if (!closed) { closed = true; connection.destroy(); } + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryAuthenticationProvider.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryAuthenticationProvider.java new file mode 100644 index 0000000..e177365 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryAuthenticationProvider.java @@ -0,0 +1,44 @@ +package top.ddupan.iam.login.authentication.infrastructure.security; + +import java.util.List; +import org.springframework.security.authentication.AuthenticationProvider; +import org.springframework.security.authentication.BadCredentialsException; +import org.springframework.security.authentication.InternalAuthenticationServiceException; +import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; +import org.springframework.security.core.Authentication; +import org.springframework.security.core.authority.FactorGrantedAuthority; +import top.ddupan.iam.login.authentication.application.VerifyPassword; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.domain.UserRepository; + +/** Bridges directory authentication into Spring Security's form-login lifecycle. */ +public final class DirectoryAuthenticationProvider implements AuthenticationProvider { + private final VerifyPassword passwords; + + public DirectoryAuthenticationProvider(VerifyPassword passwords) { + this.passwords = passwords; + } + + @Override + public Authentication authenticate(Authentication request) { + try { + var user = passwords.verify(request.getName(), + request.getCredentials() instanceof String password ? password : null); + // Directory groups remain profile data, not local application authorities. + return UsernamePasswordAuthenticationToken.authenticated(new DirectoryPrincipal(user), null, + List.of(FactorGrantedAuthority.fromAuthority(FactorGrantedAuthority.PASSWORD_AUTHORITY))); + } catch (PasswordVerificationException ex) { + if (ex.reason() == PasswordVerificationException.Reason.UNAVAILABLE) { + throw new InternalAuthenticationServiceException("Directory unavailable"); + } + throw new BadCredentialsException("Unable to verify credentials"); + } catch (UserRepository.AccessFailure ex) { + throw new InternalAuthenticationServiceException("Directory unavailable"); + } + } + + @Override + public boolean supports(Class authentication) { + return UsernamePasswordAuthenticationToken.class.equals(authentication); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryPrincipal.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryPrincipal.java new file mode 100644 index 0000000..01e1ee4 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryPrincipal.java @@ -0,0 +1,12 @@ +package top.ddupan.iam.login.authentication.infrastructure.security; + +import org.springframework.security.core.AuthenticatedPrincipal; +import top.ddupan.iam.login.authentication.domain.User; + +/** An immutable directory snapshot; never contains credentials or connections. */ +public record DirectoryPrincipal(User user) implements AuthenticatedPrincipal { + @Override + public String getName() { + return user.id().authority() + ":" + user.id().value(); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java new file mode 100644 index 0000000..d057063 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java @@ -0,0 +1,32 @@ +package top.ddupan.iam.login.authentication.interfaces.web; + +import java.io.IOException; +import java.nio.charset.StandardCharsets; +import org.springframework.core.io.ClassPathResource; +import org.springframework.http.MediaType; +import org.springframework.http.ResponseEntity; +import org.springframework.stereotype.Component; +import tools.jackson.databind.json.JsonMapper; + +/** Shared HTML shell; the page context is data, never executable JavaScript. */ +@Component +public class PageRenderer { + private static final String SLOT = "__IAM_PAGE_CONTEXT__"; + private final String shell; + private final JsonMapper json = JsonMapper.builder().build(); + + public PageRenderer() throws IOException { + shell = new ClassPathResource("ui/index.html").getContentAsString(StandardCharsets.UTF_8); + if (shell.indexOf(SLOT) < 0 || shell.indexOf(SLOT) != shell.lastIndexOf(SLOT)) { + throw new IllegalStateException("Expected exactly one UI context slot"); + } + } + + public ResponseEntity render(Object context) { + String safe = json.writeValueAsString(context).replace("<", "\\u003c") + .replace(">", "\\u003e").replace("&", "\\u0026") + .replace("\u2028", "\\u2028").replace("\u2029", "\\u2029"); + return ResponseEntity.ok().header("Cache-Control", "no-store") + .contentType(new MediaType(MediaType.TEXT_HTML, StandardCharsets.UTF_8)).body(shell.replace(SLOT, safe)); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java new file mode 100644 index 0000000..4f889ad --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java @@ -0,0 +1,46 @@ +package top.ddupan.iam.login.authentication.interfaces.web; + +import java.util.Map; +import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty; +import org.springframework.http.MediaType; +import org.springframework.http.ResponseEntity; +import org.springframework.security.core.annotation.AuthenticationPrincipal; +import org.springframework.security.web.csrf.CsrfToken; +import org.springframework.web.bind.annotation.GetMapping; +import org.springframework.web.bind.annotation.RequestParam; +import org.springframework.web.bind.annotation.RestController; +import top.ddupan.iam.login.authentication.domain.User.GroupMembership; +import top.ddupan.iam.login.authentication.infrastructure.security.DirectoryPrincipal; + +/** Renders Spring Security's login pages; form processing belongs to the security filters. */ +@RestController +@ConditionalOnProperty(prefix = "iam.ad", name = "enabled", havingValue = "true") +public class SignInController { + private final PageRenderer renderer; + + public SignInController(PageRenderer renderer) { + this.renderer = renderer; + } + + @GetMapping(value = "/signin", produces = MediaType.TEXT_HTML_VALUE) + ResponseEntity page(@RequestParam(required = false) String error, CsrfToken csrf) { + return renderer.render(Map.of("step", "password", "name", "", + "error", error == null ? "" : "无法验证账号,请检查凭据与账号状态,或稍后重试。", + "action", "/signin/password", "csrf", csrf(csrf))); + } + + @GetMapping(value = "/signin/mfa", produces = MediaType.TEXT_HTML_VALUE) + ResponseEntity pending(@AuthenticationPrincipal DirectoryPrincipal principal, CsrfToken csrf) { + var user = principal.user(); + return renderer.render(Map.of("step", "mfa-pending", "name", user.displayName(), + "error", "", "action", "/signin/restart", "csrf", csrf(csrf), + "identity", Map.of("username", user.username(), "subjectId", user.id().value(), + "email", user.email(), + "groups", user.memberships().stream().map(GroupMembership::name).toList(), + "groupDns", user.memberships().stream().map(GroupMembership::externalId).toList()))); + } + + private static Map csrf(CsrfToken token) { + return Map.of("name", token.getParameterName(), "value", token.getToken()); + } +} diff --git a/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java b/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java new file mode 100644 index 0000000..0c432d2 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java @@ -0,0 +1,32 @@ +package top.ddupan.iam.login.configuration; + +import javax.naming.directory.DirContext; +import javax.naming.ldap.LdapContext; +import org.springframework.aot.hint.RuntimeHints; +import org.springframework.aot.hint.RuntimeHintsRegistrar; +import org.springframework.aot.hint.annotation.RegisterReflectionForBinding; +import org.springframework.context.annotation.ImportRuntimeHints; +import org.springframework.ldap.core.DirContextProxy; +import top.ddupan.iam.login.authentication.infrastructure.ad.AdUserEntry; +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import top.ddupan.iam.login.authentication.application.VerifyPassword; +import top.ddupan.iam.login.authentication.application.port.PasswordAuthenticator; + +/** Composition root: dependencies point inward, framework wiring stays outside the model. */ +@Configuration(proxyBeanMethods = false) +@RegisterReflectionForBinding(AdUserEntry.class) +@ImportRuntimeHints(AuthenticationConfiguration.DirectoryHints.class) +class AuthenticationConfiguration { + @Bean + VerifyPassword verifyPassword(PasswordAuthenticator authenticator) { + return new VerifyPassword(authenticator); + } + static class DirectoryHints implements RuntimeHintsRegistrar { + @Override + public void registerHints(RuntimeHints hints, ClassLoader classLoader) { + hints.proxies().registerJdkProxy(LdapContext.class, DirContextProxy.class); + hints.proxies().registerJdkProxy(DirContext.class, DirContextProxy.class); + } + } +} diff --git a/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java b/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java new file mode 100644 index 0000000..02a543d --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java @@ -0,0 +1,84 @@ +package top.ddupan.iam.login.configuration; + +import java.time.Duration; +import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty; +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.core.annotation.Order; +import org.springframework.http.HttpStatus; +import org.springframework.security.authentication.ProviderManager; +import org.springframework.security.authorization.AuthorizationManagerFactories; +import org.springframework.security.config.Customizer; +import org.springframework.security.config.annotation.web.builders.HttpSecurity; +import org.springframework.security.config.annotation.authorization.EnableMultiFactorAuthentication; +import org.springframework.security.web.SecurityFilterChain; +import org.springframework.security.web.access.intercept.RequestAuthorizationContext; +import org.springframework.security.web.authentication.HttpStatusEntryPoint; +import org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint; +import org.springframework.security.web.servlet.util.matcher.PathPatternRequestMatcher; +import top.ddupan.iam.login.authentication.application.VerifyPassword; +import top.ddupan.iam.login.authentication.infrastructure.security.DirectoryAuthenticationProvider; + +@Configuration(proxyBeanMethods = false) +@EnableMultiFactorAuthentication(authorities = {}) +class SecurityConfiguration { + // Operational Basic authentication is isolated from human first-factor authentication. + @Bean + @Order(1) + SecurityFilterChain management(HttpSecurity http) throws Exception { + return http.securityMatcher("/actuator/**") + .authorizeHttpRequests(auth -> auth + .requestMatchers("/actuator/health/**").permitAll() + .anyRequest().authenticated()) + .securityContext(context -> context.securityContextRepository( + new org.springframework.security.web.context.NullSecurityContextRepository())) + .sessionManagement(session -> session.sessionCreationPolicy( + org.springframework.security.config.http.SessionCreationPolicy.STATELESS)) + .httpBasic(Customizer.withDefaults()) + .build(); + } + + @Bean + @Order(2) + @ConditionalOnProperty(prefix = "iam.ad", name = "enabled", havingValue = "true") + SecurityFilterChain browser(HttpSecurity http, VerifyPassword passwords) throws Exception { + var passwordFactor = AuthorizationManagerFactories.multiFactor() + .requireFactor(factor -> factor.passwordAuthority().validDuration(Duration.ofMinutes(10))) + .build(); + return http.securityMatcher("/signin", "/signin/**", "/assets/**") + .redirectToHttps(Customizer.withDefaults()) + .authenticationManager(new ProviderManager(new DirectoryAuthenticationProvider(passwords))) + .authorizeHttpRequests(auth -> auth + .requestMatchers("/error", "/signin", "/signin/password", "/assets/**").permitAll() + .requestMatchers("/signin/mfa").access(passwordFactor.authenticated()) + // No complete MFA or Hydra acceptance exists yet. Fail closed until those are implemented. + .anyRequest().denyAll()) + .formLogin(form -> form.loginPage("/signin").loginProcessingUrl("/signin/password") + .defaultSuccessUrl("/signin/mfa", true).failureUrl("/signin?error")) + .logout(logout -> logout.logoutUrl("/signin/restart").logoutSuccessUrl("/signin")) + .exceptionHandling(exceptions -> exceptions + .defaultAuthenticationEntryPointFor(new LoginUrlAuthenticationEntryPoint("/signin"), + PathPatternRequestMatcher.withDefaults().matcher("/signin/**")) + .defaultAuthenticationEntryPointFor(new HttpStatusEntryPoint(HttpStatus.UNAUTHORIZED), + org.springframework.security.web.util.matcher.AnyRequestMatcher.INSTANCE)) + .requestCache(cache -> cache.disable()) + .headers(headers -> headers.contentSecurityPolicy(csp -> csp.policyDirectives( + "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; " + + "object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'"))) + .build(); + } + + @Bean + @Order(3) + SecurityFilterChain fallback(HttpSecurity http) throws Exception { + return http.authorizeHttpRequests(auth -> auth + .requestMatchers("/error").permitAll() + .anyRequest().denyAll()) + .exceptionHandling(exceptions -> exceptions + .authenticationEntryPoint(new HttpStatusEntryPoint(HttpStatus.UNAUTHORIZED))) + .requestCache(cache -> cache.disable()) + .logout(logout -> logout.disable()) + .build(); + } + +} diff --git a/src/main/java/top/ddupan/iam/login/configuration/WebConfiguration.java b/src/main/java/top/ddupan/iam/login/configuration/WebConfiguration.java new file mode 100644 index 0000000..3ec3acc --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/configuration/WebConfiguration.java @@ -0,0 +1,28 @@ +package top.ddupan.iam.login.configuration; + +import java.time.Duration; +import org.springframework.aot.hint.RuntimeHints; +import org.springframework.aot.hint.RuntimeHintsRegistrar; +import org.springframework.context.annotation.Configuration; +import org.springframework.context.annotation.ImportRuntimeHints; +import org.springframework.http.CacheControl; +import org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry; +import org.springframework.web.servlet.config.annotation.WebMvcConfigurer; + +@Configuration(proxyBeanMethods = false) +@ImportRuntimeHints(WebConfiguration.Resources.class) +class WebConfiguration implements WebMvcConfigurer { + + @Override + public void addResourceHandlers(ResourceHandlerRegistry registry) { + registry.addResourceHandler("/assets/**").addResourceLocations("classpath:/ui/assets/") + .setCacheControl(CacheControl.maxAge(Duration.ofDays(365)).cachePublic().immutable()); + } + + static class Resources implements RuntimeHintsRegistrar { + @Override + public void registerHints(RuntimeHints hints, ClassLoader classLoader) { + hints.resources().registerPattern("ui/**"); + } + } +} diff --git a/src/main/resources/META-INF/native-image/top.ddupan.iam/iam-login/reachability-metadata.json b/src/main/resources/META-INF/native-image/top.ddupan.iam/iam-login-manual/reachability-metadata.json similarity index 100% rename from src/main/resources/META-INF/native-image/top.ddupan.iam/iam-login/reachability-metadata.json rename to src/main/resources/META-INF/native-image/top.ddupan.iam/iam-login-manual/reachability-metadata.json diff --git a/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java b/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java index 1619289..ddac059 100644 --- a/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java +++ b/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java @@ -10,42 +10,58 @@ import org.springframework.boot.opentelemetry.autoconfigure.logging.otlp.OtlpLog import org.springframework.boot.opentelemetry.autoconfigure.logging.otlp.Transport; import org.springframework.boot.test.context.SpringBootTest; import org.springframework.boot.testcontainers.service.connection.ServiceConnection; +import org.springframework.boot.webmvc.test.autoconfigure.AutoConfigureMockMvc; +import org.springframework.test.web.servlet.MockMvc; import org.testcontainers.grafana.LgtmStackContainer; import org.testcontainers.junit.jupiter.Container; import org.testcontainers.junit.jupiter.Testcontainers; import org.testcontainers.utility.DockerImageName; import static org.assertj.core.api.Assertions.assertThat; +import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.get; +import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.status; @SpringBootTest +@AutoConfigureMockMvc @AutoConfigureMetrics @AutoConfigureTracing @Testcontainers class IamLoginApplicationTests { - // Field-based service connections are recreated by the test context in AOT mode. - @Container - @ServiceConnection - static final LgtmStackContainer grafanaLgtm = new LgtmStackContainer( - DockerImageName.parse(TestcontainersConfiguration.LGTM_IMAGE)); + // Field-based service connections are recreated by the test context in AOT mode. + @Container + @ServiceConnection + static final LgtmStackContainer grafanaLgtm = new LgtmStackContainer( + DockerImageName.parse(TestcontainersConfiguration.LGTM_IMAGE)); - @Autowired - OtlpLoggingConnectionDetails loggingConnectionDetails; + @Autowired + OtlpLoggingConnectionDetails loggingConnectionDetails; - @Autowired - @Qualifier("prometheusMeterRegistry") - MeterRegistry prometheus; + @Autowired + @Qualifier("prometheusMeterRegistry") + MeterRegistry prometheus; - @Test - void processCpuTimeCanBeRead() { - assertThat(prometheus.get("process.cpu.time").functionCounter().count()).isFinite().isNotNegative(); - } + @Autowired + MockMvc mvc; - @Test - void loggingConnectionUsesRunningContainer() { - assertThat(grafanaLgtm.isRunning()).isTrue(); - assertThat(loggingConnectionDetails.getUrl(Transport.HTTP)) - .isEqualTo(grafanaLgtm.getOtlpHttpUrl() + "/v1/logs"); - } + @Test + void signInIsDisabledUntilDirectoryIsConfigured() throws Exception { + mvc.perform(get("/signin").secure(true)).andExpect(status().isUnauthorized()); + mvc.perform(org.springframework.test.web.servlet.request.MockMvcRequestBuilders.post("/signin/password") + .secure(true).with(org.springframework.security.test.web.servlet.request.SecurityMockMvcRequestPostProcessors.csrf())) + .andExpect(status().isUnauthorized()); + } + + @Test + void processCpuTimeCanBeRead() { + assertThat(prometheus.get("process.cpu.time").functionCounter().count()).isFinite().isNotNegative(); + } + + @Test + void loggingConnectionUsesRunningContainer() { + assertThat(grafanaLgtm.isRunning()).isTrue(); + assertThat(loggingConnectionDetails.getUrl(Transport.HTTP)) + .isEqualTo(grafanaLgtm.getOtlpHttpUrl() + "/v1/logs"); + } } diff --git a/src/test/java/top/ddupan/iam/login/authentication/application/VerifyPasswordTests.java b/src/test/java/top/ddupan/iam/login/authentication/application/VerifyPasswordTests.java new file mode 100644 index 0000000..729b91c --- /dev/null +++ b/src/test/java/top/ddupan/iam/login/authentication/application/VerifyPasswordTests.java @@ -0,0 +1,49 @@ +package top.ddupan.iam.login.authentication.application; + +import java.util.List; +import java.util.Optional; +import org.junit.jupiter.api.Test; +import top.ddupan.iam.login.authentication.application.port.AuthenticatedUserSession; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.domain.User; +import top.ddupan.iam.login.authentication.domain.UserRepository; +import static org.assertj.core.api.Assertions.*; + +class VerifyPasswordTests { + static final User ALICE = new User(new User.UserId("directory", "alice-id"), "alice", "Alice", "", List.of()); + + @Test + void readsTheBoundUserAndClosesTheConnection() { + var scope = new Scope(name -> { + assertThat(name).isEqualTo("alice@directory"); + return Optional.of(ALICE); + }); + assertThat(new VerifyPassword((username, password) -> scope).verify("alice", "secret")).isEqualTo(ALICE); + assertThat(scope.closed).isTrue(); + } + + @Test + void missingUserClosesTheConnectionAndRejectsAuthentication() { + var scope = new Scope(name -> Optional.empty()); + assertThatThrownBy(() -> new VerifyPassword((u, p) -> scope).verify("alice", "secret")) + .isInstanceOf(PasswordVerificationException.class); + assertThat(scope.closed).isTrue(); + } + + @Test + void repositoryFailureStillClosesTheConnection() { + var scope = new Scope(name -> { throw new UserRepository.AccessFailure(); }); + assertThatThrownBy(() -> new VerifyPassword((u, p) -> scope).verify("alice", "secret")) + .isInstanceOf(UserRepository.AccessFailure.class); + assertThat(scope.closed).isTrue(); + } + + private static final class Scope implements AuthenticatedUserSession { + private final UserRepository users; + boolean closed; + Scope(UserRepository users) { this.users = users; } + @Override public String loginName() { return "alice@directory"; } + @Override public UserRepository users() { return users; } + @Override public void close() { closed = true; } + } +} diff --git a/src/test/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserRepositoryIntegrationTests.java b/src/test/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserRepositoryIntegrationTests.java new file mode 100644 index 0000000..d51f34a --- /dev/null +++ b/src/test/java/top/ddupan/iam/login/authentication/infrastructure/ad/AdUserRepositoryIntegrationTests.java @@ -0,0 +1,79 @@ +package top.ddupan.iam.login.authentication.infrastructure.ad; + +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException.Reason; +import top.ddupan.iam.login.authentication.domain.User.GroupMembership; +import top.ddupan.iam.login.support.AdDirectoryFixture; +import static org.assertj.core.api.Assertions.*; + +class AdUserRepositoryIntegrationTests { + private static AdDirectoryFixture directory; + private static AdPasswordAuthenticator authenticator; + + @BeforeAll static void start() { + directory = new AdDirectoryFixture(); + authenticator = new AdPasswordAuthenticator(new AdProperties(true, + directory.url(), "example.test", "dc=example,dc=test")); + } + @AfterAll static void close() { directory.close(); } + + @Test + void repositoryUsesTheBoundConnectionAndMapsGuidAndGroupsDespiteReferrals() { + int before = directory.binds.get(); + try (var session = authenticator.authenticate("alice", "fixture-password")) { + var user = session.users().findByLoginName(session.loginName()).orElseThrow(); + assertThat(user.id().value()).isEqualTo("00112233-4455-6677-8899-aabbccddeeff"); + assertThat(user.memberships()).extracting(GroupMembership::name).containsExactly("MixedCase", "gitea-admins"); + assertThat(session.users().findByLoginName("alice")).contains(user); + assertThat(directory.binds.get() - before).isEqualTo(1); + assertThat(directory.searchConnection).isEqualTo(directory.bindConnection); + } + } + + @Test + void closingTheScopePreventsFurtherRepositoryUse() { + var session = authenticator.authenticate("alice@example.test", "fixture-password"); + var users = session.users(); + session.close(); + assertThatThrownBy(() -> users.findByLoginName("alice")).isInstanceOf(IllegalStateException.class); + assertThatThrownBy(session::users).isInstanceOf(IllegalStateException.class); + } + + @Test + void wrongPasswordsUnknownAccountsAndAdAccountStatesAreTranslated() { + rejected("alice", "wrong", Reason.REJECTED); + rejected("unknown", "fixture-password", Reason.REJECTED); + rejected("disabled", "fixture-password", Reason.DISABLED); + rejected("locked", "fixture-password", Reason.LOCKED); + rejected("expired", "fixture-password", Reason.PASSWORD_EXPIRED); + } + + @Test + void emptyPasswordsAndForeignDomainsNeverAttemptBind() { + int before = directory.binds.get(); + rejected("alice", "", Reason.REJECTED); + rejected("alice@other.test", "fixture-password", Reason.REJECTED); + assertThat(directory.binds.get()).isEqualTo(before); + } + + @Test + void rejectsWrongTlsHostnameAndPlainLdapConfiguration() { + var wrongName = new AdPasswordAuthenticator(new AdProperties(true, + directory.mismatchedHostnameUrl(), "example.test", "dc=example,dc=test")); + assertThatThrownBy(() -> wrongName.authenticate("alice", "fixture-password")) + .isInstanceOfSatisfying(PasswordVerificationException.class, + ex -> assertThat(ex.reason()).isEqualTo(Reason.UNAVAILABLE)); + assertThatThrownBy(() -> new AdPasswordAuthenticator(new AdProperties(true, + "ldap://localhost:389", "example.test", "dc=example,dc=test"))) + .isInstanceOf(IllegalArgumentException.class); + } + + private static void rejected(String username, String password, Reason reason) { + assertThatThrownBy(() -> authenticator.authenticate(username, password)) + .isInstanceOfSatisfying(PasswordVerificationException.class, + ex -> assertThat(ex.reason()).isEqualTo(reason)); + } +} diff --git a/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java b/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java new file mode 100644 index 0000000..259608f --- /dev/null +++ b/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java @@ -0,0 +1,165 @@ +package top.ddupan.iam.login.authentication.interfaces.web; + +import top.ddupan.iam.login.support.AdDirectoryFixture; +import org.springframework.aot.hint.RuntimeHints; +import org.springframework.aot.hint.RuntimeHintsRegistrar; +import org.springframework.context.annotation.ImportRuntimeHints; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.Test; +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.boot.test.context.SpringBootTest; +import org.springframework.boot.webmvc.test.autoconfigure.AutoConfigureMockMvc; +import org.springframework.http.MediaType; +import java.time.Instant; +import java.util.List; +import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; +import org.springframework.security.core.authority.FactorGrantedAuthority; +import org.springframework.security.core.context.SecurityContext; +import org.springframework.mock.web.MockHttpSession; +import org.springframework.test.context.DynamicPropertyRegistry; +import org.springframework.test.context.DynamicPropertySource; +import org.springframework.test.web.servlet.MockMvc; +import static org.assertj.core.api.Assertions.*; +import static org.springframework.security.test.web.servlet.request.SecurityMockMvcRequestPostProcessors.csrf; +import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.*; +import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.*; + +/** Real LDAPS sockets and Spring Data LDAP; AD bind/subcode semantics are simulated. */ +@SpringBootTest(properties = {"iam.ad.enabled=true", "iam.ad.domain=example.test", "iam.ad.base-dn=dc=example,dc=test", + "management.otlp.metrics.export.enabled=false", "spring.security.user.name=fixture-monitor", "spring.security.user.password=fixture-monitor-password"}) +@AutoConfigureMockMvc +@org.springframework.boot.micrometer.metrics.test.autoconfigure.AutoConfigureMetrics +@ImportRuntimeHints(SignInIntegrationTests.FixtureHints.class) +class SignInIntegrationTests { + static class FixtureHints implements RuntimeHintsRegistrar { + @Override + public void registerHints(RuntimeHints hints, ClassLoader loader) { + hints.resources().registerPattern("ldap/fixture.p12"); + } + } + + static class Directory { + static final AdDirectoryFixture INSTANCE = new AdDirectoryFixture(); + } + + @DynamicPropertySource + static void directory(DynamicPropertyRegistry registry) { + registry.add("iam.ad.url", () -> Directory.INSTANCE.url()); + } + + @AfterAll + static void close() { Directory.INSTANCE.close(); } + + @Autowired MockMvc mvc; + + @Test + void browserRequiresHttpsCsrfAndOrderedSteps() throws Exception { + mvc.perform(get("/signin")).andExpect(redirectedUrl("https://localhost/signin")); + mvc.perform(get("/signin/mfa").with(https())).andExpect(redirectedUrl("/signin")); + mvc.perform(post("/signin/password").with(https()).param("username", "alice") + .param("password", "fixture-password")).andExpect(status().isForbidden()); + } + + @Test + void successfulPasswordRotatesSessionAndStopsBeforeMfa() throws Exception { + var session = new MockHttpSession(); + mvc.perform(get("/signin").with(https()).session(session)).andExpect(status().isOk()); + String oldId = session.getId(); + mvc.perform(post("/signin/password").with(https()).session(session).with(csrf()) + .param("username", "alice").param("password", "fixture-password")) + .andExpect(redirectedUrl("/signin/mfa")); + assertThat(session.getId()).isNotEqualTo(oldId); + var html = mvc.perform(get("/signin/mfa").with(https()).session(session)) + .andExpect(status().isOk()).andExpect(header().string("Cache-Control", "no-store")) + .andReturn().getResponse().getContentAsString(); + assertThat(html).contains("mfa-pending", "gitea-admins", "\\u003c/script\\u003e") + .doesNotContain("fixture-password", ""), + new com.unboundid.ldap.sdk.Attribute("mail", "alice@example.test"), + new com.unboundid.ldap.sdk.Attribute("objectGUID", GUID), + new com.unboundid.ldap.sdk.Attribute("memberOf", "CN=gitea-admins," + BASE, "CN=MixedCase," + BASE))); + } catch (Exception ex) { throw new ExceptionInInitializerError(ex); } + } + + + public String url() { return "ldaps://localhost:" + ldap.getListenPort(); } + public String mismatchedHostnameUrl() { return "ldaps://127.0.0.1:" + ldap.getListenPort(); } + @Override public void close() { ldap.shutDown(true); SSLContext.setDefault(original); } +} diff --git a/src/test/resources/ldap/README.md b/src/test/resources/ldap/README.md new file mode 100644 index 0000000..fcd46f4 --- /dev/null +++ b/src/test/resources/ldap/README.md @@ -0,0 +1,4 @@ +fixture.p12 是仅用于隔离 LDAPS 测试的自签名证书和测试私钥,口令为 fixture-only。 +仅信任 localhost,不能用于生产。测试账户和密码都是虚构数据。 +测试服务仅绑定 127.0.0.1;JVM/Native 均执行真实 TLS、bind 和搜索,但 AD 的 UPN bind +与禁用/锁定/密码过期子码由拦截器模拟,不代替 Samba AD 人类验收。 diff --git a/src/test/resources/ldap/fixture.p12 b/src/test/resources/ldap/fixture.p12 new file mode 100644 index 0000000..3ca7c0d Binary files /dev/null and b/src/test/resources/ldap/fixture.p12 differ