Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 11 additions & 1 deletion .github/workflows/brokers-qa.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,14 @@ jobs:
path: ~/.cargo/bin/cargo-cbuild
key: ${{ runner.os }}-cargo-c-${{ hashFiles('authd-oidc-brokers/tools/install-cargo-c') }}

- uses: canonical/desktop-engineering/gh-actions/common/dpkg-install-speedup@main
- name: Install dependencies
Comment thread
adombeck marked this conversation as resolved.
run: |
set -eu
sudo apt-get update
# Headers for the cgo bindings to libfido2 (internal/fido).
sudo apt-get install -y libfido2-dev

- name: Build libhimmelblau
# The code sanity check fails if himmelblau.h does not exist, so we generate it first.
run: go generate --tags withmsentraid ./internal/providers/msentraid/...
Expand Down Expand Up @@ -87,7 +95,9 @@ jobs:
run: |
set -eu
sudo apt-get update
sudo apt-get install -y git-delta
# libfido2-dev provides the headers for the cgo bindings to libfido2
# (internal/fido).
sudo apt-get install -y git-delta libfido2-dev

- name: Install coverage collection dependencies
if: matrix.test == 'coverage'
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/e2e-tests-run.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -233,6 +233,8 @@ jobs:
export E2E_USER="${{ secrets.E2E_MSENTRA_USERNAME }}"
export E2E_PASSWORD="${{ secrets.E2E_MSENTRA_PASSWORD }}"
export TOTP_SECRET="${{ secrets.E2E_MSENTRA_TOTP_SECRET }}"
export AUTHD_MSENTRAID_ISSUER_ID="${{ secrets.E2E_MSENTRA_ISSUER_ID }}"
export AUTHD_MSENTRAID_CLIENT_ID="${{ secrets.E2E_MSENTRA_CLIENT_ID }}"
export AUTHD_MSENTRAID_CLIENT_SECRET="${{ secrets.E2E_MSENTRA_CLIENT_SECRET }}"
elif [ "${{ inputs.broker }}" = "authd-google" ]; then
export E2E_USER="${{ secrets.E2E_GOOGLE_USERNAME }}"
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/tics-run.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ env:
clang-tools
clang
dotnet8
libfido2-dev
libglib2.0-dev
libpam-dev
libpwquality-dev
Expand Down
3 changes: 2 additions & 1 deletion .gitmodules
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
[submodule "authd-oidc-brokers/third_party/libhimmelblau"]
path = authd-oidc-brokers/third_party/libhimmelblau
url = https://gitlab.com/samba-team/libhimmelblau.git
url = https://gitlab.com/nooreldeensalah/libhimmelblau.git
branch = fido-passkeys-mfa
Comment thread
nooreldeenmansour marked this conversation as resolved.
[submodule "e2e-tests/.yarf"]
path = e2e-tests/.yarf
url = https://github.com/adombeck/yarf
4 changes: 2 additions & 2 deletions authd-oidc-brokers/cmd/authd-oidc/daemon/export_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -75,10 +75,10 @@ issuer = %s
client_id = client_id

[flows]
# These tests don't exercise the entra_password flow, and the default
# These tests don't exercise the entra_auth flow, and the default
# (enabled) would fail startup validation under the withmsentraid tag
# because no client_secret or register_device is configured here.
entra_password = false
entra_auth = false
`, providerURL)
err = os.WriteFile(p, []byte(brokerCfg), 0600)
require.NoError(t, err, "Setup: could not create broker configuration for tests")
Expand Down
13 changes: 8 additions & 5 deletions authd-oidc-brokers/conf/variants/msentraid/broker.conf
Original file line number Diff line number Diff line change
Expand Up @@ -105,9 +105,12 @@ client_id = <CLIENT_ID>
## a code).
#device_code = true

## entra_password: When true (default), users can authenticate by entering
## their Microsoft Entra ID password directly, followed by MFA verification.
## entra_auth: When true (default), users can authenticate with the
## Microsoft Entra ID direct-auth flow.
## When the user has enrolled passwordless methods (FIDO2 security keys,
## Microsoft Authenticator, or a Temporary Access Pass), the flow negotiates
## those automatically; otherwise it falls back to password + MFA.
##
## Note: If both flows are disabled, no authentication will be available
## and users will not be able to log in.
#entra_password = true
## Note: If both device_code and entra_auth are disabled, the broker
## considers the configuration invalid and will fail to start.
#entra_auth = true
2 changes: 2 additions & 0 deletions authd-oidc-brokers/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ require (
github.com/golang-jwt/jwt/v5 v5.3.1
github.com/google/uuid v1.6.0
github.com/k0kubun/pp v3.0.1+incompatible
github.com/keys-pub/go-libfido2 v1.5.3
github.com/microsoftgraph/msgraph-sdk-go v1.99.0
github.com/microsoftgraph/msgraph-sdk-go-core v1.4.1
github.com/mitchellh/mapstructure v1.5.0
Expand Down Expand Up @@ -52,6 +53,7 @@ require (
github.com/otiai10/copy v1.14.1 // indirect
github.com/otiai10/mint v1.6.3 // indirect
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
github.com/sagikazarmark/locafero v0.11.0 // indirect
github.com/sirupsen/logrus v1.9.3 // indirect
Expand Down
7 changes: 7 additions & 0 deletions authd-oidc-brokers/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ github.com/k0kubun/colorstring v0.0.0-20150214042306-9440f1994b88 h1:uC1QfSlInpQ
github.com/k0kubun/colorstring v0.0.0-20150214042306-9440f1994b88/go.mod h1:3w7q1U84EfirKl04SVQ/s7nPm1ZPhiXd34z40TNz36k=
github.com/k0kubun/pp v3.0.1+incompatible h1:3tqvf7QgUnZ5tXO6pNAZlrvHgl6DvifjDrd9g2S9Z40=
github.com/k0kubun/pp v3.0.1+incompatible/go.mod h1:GWse8YhT0p8pT4ir3ZgBbfZild3tgzSScAn6HmfYukg=
github.com/keys-pub/go-libfido2 v1.5.3 h1:vtgHxlSB43u6lj0TSuA3VvT6z3E7VI+L1a2hvMFdECk=
github.com/keys-pub/go-libfido2 v1.5.3/go.mod h1:P0V19qHwJNY0htZwZDe9Ilvs/nokGhdFX7faKFyZ6+U=
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
Expand Down Expand Up @@ -80,6 +82,8 @@ github.com/otiai10/mint v1.6.3 h1:87qsV/aw1F5as1eH1zS/yqHY85ANKVMgkDrf9rcxbQs=
github.com/otiai10/mint v1.6.3/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pelletier/go-toml/v2 v2.2.4 h1:mye9XuhQ6gvn5h28+VilKrrPoQVanw5PMw/TB0t5Ec4=
github.com/pelletier/go-toml/v2 v2.2.4/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
Expand Down Expand Up @@ -109,6 +113,7 @@ github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+
github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw=
github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo=
github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
github.com/stretchr/testify v1.5.1/go.mod h1:5W2xD1RspED5o8YsWQXVCued0rvSQ+mT+I5cxcmMvtA=
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU=
Expand Down Expand Up @@ -145,6 +150,7 @@ golang.org/x/net v0.55.0/go.mod h1:L5U2KuzuOe1lY7Z+aWVIKK6qEeJXnXV9yzGA+WCHJww=
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20200317015054-43a5402ce75a/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM=
golang.org/x/sync v0.21.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
Expand Down Expand Up @@ -174,6 +180,7 @@ gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntN
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q=
gopkg.in/ini.v1 v1.67.3 h1:iM9Lhz5MRSGhHVGGwCuzG9KO8PoirCXj/m/qTmOJJQw=
gopkg.in/ini.v1 v1.67.3/go.mod h1:x/cyOwCgZqOkJoDIJ3c1KNHMo10+nLGAhh+kn3Zizss=
gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
29 changes: 19 additions & 10 deletions authd-oidc-brokers/internal/broker/authmodes/consts.go
Original file line number Diff line number Diff line change
Expand Up @@ -16,26 +16,35 @@ const (
// NewPassword is the ID of the new password configuration method.
NewPassword = "newpassword"

// EntraPassword is the ID of the Entra ID password + MFA authentication flow.
EntraPassword = "entra_password"
// EntraAuth is the ID of the Entra ID password/passwordless authentication method.
EntraAuth = "entra_auth"

// EntraMFAWait is the ID of the poll-based MFA follow-up mode.
EntraMFAWait = "entra_mfa_wait"

// EntraMFACode is the ID of the code-entry MFA follow-up mode.
EntraMFACode = "entra_mfa_code"

// EntraAuthFido is the ID of the security-key MFA follow-up mode, which
// performs the WebAuthn assertion with a locally connected FIDO2 device.
EntraAuthFido = "entra_auth_fido"

// EntraAuthFidoPin is the ID of the security-key PIN entry mode, chained
// before EntraAuthFido when the connected device requires a client PIN.
EntraAuthFidoPin = "entra_auth_fido_pin"
)

var (
// Label is a map of auth mode IDs to their display labels.
//nolint:gosec // G101: These are auth mode display labels, not credentials.
Label = map[string]string{
Password: "Local password",
Device: "Device code flow",
DeviceQr: "Device code flow",
NewPassword: "Define your local password",
EntraPassword: "Entra ID password + MFA",
EntraMFAWait: "Waiting for MFA approval",
EntraMFACode: "Enter your MFA code",
Password: "Local password",
Device: "Device code flow",
DeviceQr: "Device code flow",
NewPassword: "Define your local password",
EntraAuth: "Entra ID authentication",
EntraMFAWait: "Waiting for MFA approval",
EntraMFACode: "Enter your MFA code",
EntraAuthFido: "Use your security key",
EntraAuthFidoPin: "Enter your security key PIN",
}
)
Loading
Loading