Try a directory before anything signs in through it
POST /api/directory/test takes a saved directory's id, an address and optionally a password, and answers whether the directory opened, what a recipient lookup of the address finds (account or group, with its aliases, groups and name), and whether the password signs in. A wrong password is told apart from a directory that can't be reached or is set up wrong. It calls the directory itself, below the sign-in path: a test never creates or updates an account, never counts toward the sign-in ban and doesn't depend on which domains use the directory. A password hash a directory returns is never sent back. OIDC directories report their discovered issuer; they take no passwords. For server-level administrators with directory update permission. The console's guided directory setup uses it to test a real person before any domain is switched over.
This commit is contained in:
@@ -120,6 +120,17 @@ impl ManagementApi for Server {
|
||||
jmap::inbuxa::explanation::question(self, &access_token, &subject).await?;
|
||||
Ok(explain_stream(self.clone(), access_token, question, in_flight))
|
||||
}
|
||||
// inbuxa: try a saved directory before anything signs in through it
|
||||
"directory" if is_post && path.get(1).copied() == Some("test") => {
|
||||
let (_in_flight, access_token) = self.authenticate_headers(req, session).await?;
|
||||
jmap::inbuxa::directory_test::assert_allowed(&access_token)?;
|
||||
let request = body
|
||||
.as_deref()
|
||||
.and_then(|body| serde_json::from_slice::<serde_json::Value>(body).ok())
|
||||
.unwrap_or_default();
|
||||
let answer = jmap::inbuxa::directory_test::test(self, &request).await?;
|
||||
Ok(JsonResponse::new(answer).no_cache().into_http_response())
|
||||
}
|
||||
"account" => {
|
||||
// Authenticate request
|
||||
let (_in_flight, access_token) = self.authenticate_headers(req, session).await?;
|
||||
|
||||
Reference in New Issue
Block a user