* add delegatedauthentication to validated server config * dynamic client registration functions * test OP registration functions * add stubbed nativeOidc flow setup in Login * cover more error cases in Login * tidy * test dynamic client registration in Login * comment oidc_static_clients * register oidc inside Login.getFlows * strict fixes * remove unused code * and imports * comments * comments 2 * util functions to get static client id * check static client ids in login flow * remove dead code * OidcRegistrationClientMetadata type * navigate to oidc authorize url * exchange code for token * navigate to oidc authorize url * navigate to oidc authorize url * test * adjust for js-sdk code * login with oidc native flow: messy version * tidy * update test for response_mode query * tidy up some TODOs * use new types * add identityServerUrl to stored params * unit test completeOidcLogin * test tokenlogin * strict * whitespace * tidy * unit test oidc login flow in MatrixChat * strict * tidy * extract success/failure handlers from token login function * typo * use for no homeserver error dialog too * reuse post-token login functions, test * shuffle testing utils around * shuffle testing utils around * i18n * tidy * Update src/Lifecycle.ts Co-authored-by: Richard van der Hoff <1389908+richvdh@users.noreply.github.com> * tidy * comment * update tests for id token validation * move try again responsibility * prettier * add friendly error messages for oidc authorization failures * i18n * update for new translations, tidy --------- Co-authored-by: Richard van der Hoff <1389908+richvdh@users.noreply.github.com>
48 lines
1.6 KiB
TypeScript
48 lines
1.6 KiB
TypeScript
/*
|
|
Copyright 2023 The Matrix.org Foundation C.I.C.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
import { ReactNode } from "react";
|
|
import { OidcError } from "matrix-js-sdk/src/oidc/error";
|
|
|
|
import { _t } from "../../languageHandler";
|
|
|
|
/**
|
|
* Errors thrown by EW during OIDC native flow authentication.
|
|
* Intended to be logged, not read by users.
|
|
*/
|
|
export enum OidcClientError {
|
|
InvalidQueryParameters = "Invalid query parameters for OIDC native login. `code` and `state` are required.",
|
|
}
|
|
|
|
/**
|
|
* Get a friendly translated error message for user consumption
|
|
* based on error encountered during authentication
|
|
* @param error
|
|
* @returns a friendly translated error message for user consumption
|
|
*/
|
|
export const getOidcErrorMessage = (error: Error): string | ReactNode => {
|
|
switch (error.message) {
|
|
case OidcError.MissingOrInvalidStoredState:
|
|
return _t("auth|oidc|missing_or_invalid_stored_state");
|
|
case OidcClientError.InvalidQueryParameters:
|
|
case OidcError.CodeExchangeFailed:
|
|
case OidcError.InvalidBearerTokenResponse:
|
|
case OidcError.InvalidIdToken:
|
|
default:
|
|
return _t("auth|oidc|generic_auth_error");
|
|
}
|
|
};
|