0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-04 10:39:43 +08:00
discourse/lib/validators/enable_sso_validator.rb
Osama Sayegh 17e4bb4109
FIX: Reject DiscourseConnect SSO payloads when secret is blank (#40830)
DiscourseConnect verified SSO payload signatures with whatever
`discourse_connect_secret` was configured, including an empty string, so
an instance with DiscourseConnect enabled but no secret set did not fail
safely.

`DiscourseConnectBase#parse` now fails when the effective secret is
blank, and `EnableSsoValidator` refuses to enable DiscourseConnect
unless a secret of at least 10 characters is set.
2026-06-12 15:17:16 +03:00

39 lines
902 B
Ruby
Vendored

# frozen_string_literal: true
class EnableSsoValidator
def initialize(opts = {})
@opts = opts
end
MIN_SECRET_LENGTH = 10
def valid_value?(val)
return true if val == "f"
if SiteSetting.discourse_connect_url.blank? || secret_too_short? || is_2fa_enforced?
return false
end
true
end
def error_message
if SiteSetting.discourse_connect_url.blank?
return I18n.t("site_settings.errors.discourse_connect_url_is_empty")
end
return I18n.t("site_settings.errors.discourse_connect_secret_is_too_short") if secret_too_short?
if is_2fa_enforced?
I18n.t("site_settings.errors.discourse_connect_cannot_be_enabled_if_second_factor_enforced")
end
end
def is_2fa_enforced?
SiteSetting.enforce_second_factor? != "no"
end
private
def secret_too_short?
SiteSetting.discourse_connect_secret.length < MIN_SECRET_LENGTH
end
end