MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / resolveSso

Function resolveSso

apps/host-selfhost/src/config.ts:230–267  ·  view source on GitHub ↗
()

Source from the content-addressed store, hash-verified

228// would be open registration for anyone with an account at the IdP, bypassing
229// the invite gate entirely.
230const resolveSso = (): SsoConfig | undefined => {
231 const clientId = process.env.EXECUTOR_SSO_CLIENT_ID?.trim();
232 const clientSecret = process.env.EXECUTOR_SSO_CLIENT_SECRET?.trim();
233 if (!clientId && !clientSecret) return undefined;
234 if (!clientId || !clientSecret) {
235 // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: refuse to boot on half-configured SSO credentials
236 throw new Error("EXECUTOR_SSO_CLIENT_ID and EXECUTOR_SSO_CLIENT_SECRET must be set together");
237 }
238 const providerId = process.env.EXECUTOR_SSO_PROVIDER_ID?.trim().toLowerCase() ?? "";
239 if (!PROVIDER_ID_PATTERN.test(providerId)) {
240 // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: refuse to boot on a missing/malformed provider id
241 throw new Error(
242 'EXECUTOR_SSO_PROVIDER_ID is required when SSO is configured (1-48 chars of [a-z0-9-], e.g. "google" or "okta") — it names the provider and its OAuth callback path',
243 );
244 }
245 const discoveryUrl =
246 process.env.EXECUTOR_SSO_DISCOVERY_URL?.trim() || DISCOVERY_PRESETS[providerId];
247 if (!discoveryUrl) {
248 // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: refuse to boot without a way to reach the IdP
249 throw new Error(
250 `EXECUTOR_SSO_DISCOVERY_URL is required for provider ${JSON.stringify(providerId)} (the IdP's …/.well-known/openid-configuration URL)`,
251 );
252 }
253 const allowedDomains = (process.env.EXECUTOR_SSO_ALLOWED_DOMAINS ?? "")
254 .split(",")
255 .map((domain) => domain.trim().replace(/^@/, "").toLowerCase())
256 .filter((domain) => domain.length > 0);
257 if (allowedDomains.length === 0) {
258 // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: SSO sign-in without a domain allowlist is open registration; refuse to boot
259 throw new Error(
260 'EXECUTOR_SSO_ALLOWED_DOMAINS is required when SSO is configured (comma-separated email domains, e.g. "example.com") — it is what gates sign-ups in place of an invite code',
261 );
262 }
263 const providerName =
264 process.env.EXECUTOR_SSO_PROVIDER_NAME?.trim() ||
265 providerId.charAt(0).toUpperCase() + providerId.slice(1);
266 return { providerId, providerName, discoveryUrl, clientId, clientSecret, allowedDomains };
267};
268
269// A malformed value is refused rather than silently ignored: an operator who
270// sets the knob and typos it should find out at boot, not by watching a

Callers 1

loadConfigFunction · 0.85

Calls 1

replaceMethod · 0.65

Tested by

no test coverage detected