-import * as express from 'express'
-import { AccessDeniedError } from 'oauth2-server'
+import express from 'express'
+import { AccessDeniedError } from '@node-oauth/oauth2-server'
import { PluginManager } from '@server/lib/plugins/plugin-manager'
-import { ActorModel } from '@server/models/activitypub/actor'
import { MOAuthClient } from '@server/types/models'
import { MOAuthTokenUser } from '@server/types/models/oauth/oauth-token'
import { MUser } from '@server/types/models/user/user'
-import { UserAdminFlag } from '@shared/models/users/user-flag.model'
-import { UserRole } from '@shared/models/users/user-role'
+import { pick } from '@shared/core-utils'
import { logger } from '../../helpers/logger'
import { CONFIG } from '../../initializers/config'
-import { UserModel } from '../../models/account/user'
import { OAuthClientModel } from '../../models/oauth/oauth-client'
import { OAuthTokenModel } from '../../models/oauth/oauth-token'
-import { createUserAccountAndChannelAndPlaylist } from '../user'
+import { UserModel } from '../../models/user/user'
+import { findAvailableLocalActorName } from '../local-actor'
+import { buildUser, createUserAccountAndChannelAndPlaylist } from '../user'
+import { ExternalUser } from './external-auth'
import { TokensCache } from './tokens-cache'
type TokenInfo = {
bypass: boolean
pluginName: string
authName?: string
- user: {
- username: string
- email: string
- displayName: string
- role: UserRole
- }
+ user: ExternalUser
}
async function getAccessToken (bearerToken: string) {
// Then we just go through a regular login process
if (user.pluginAuth !== null) {
// This user does not belong to this plugin, skip it
- if (user.pluginAuth !== bypassLogin.pluginName) return null
+ if (user.pluginAuth !== bypassLogin.pluginName) {
+ logger.info(
+ 'Cannot bypass oauth login by plugin %s because %s has another plugin auth method (%s).',
+ bypassLogin.pluginName, bypassLogin.user.email, user.pluginAuth
+ )
+
+ return null
+ }
checkUserValidityOrThrow(user)
logger.debug('Getting User (username/email: ' + usernameOrEmail + ', password: ******).')
const user = await UserModel.loadByUsernameOrEmail(usernameOrEmail)
+
// If we don't find the user, or if the user belongs to a plugin
if (!user || user.pluginAuth !== null || !password) return null
// ---------------------------------------------------------------------------
-async function createUserFromExternal (pluginAuth: string, options: {
- username: string
- email: string
- role: UserRole
- displayName: string
-}) {
- // Check an actor does not already exists with that name (removed user)
- const actor = await ActorModel.loadLocalByName(options.username)
- if (actor) return null
-
- const userToCreate = new UserModel({
- username: options.username,
+async function createUserFromExternal (pluginAuth: string, userOptions: ExternalUser) {
+ const username = await findAvailableLocalActorName(userOptions.username)
+
+ const userToCreate = buildUser({
+ ...pick(userOptions, [ 'email', 'role', 'adminFlags', 'videoQuota', 'videoQuotaDaily' ]),
+
+ username,
+ emailVerified: null,
password: null,
- email: options.email,
- nsfwPolicy: CONFIG.INSTANCE.DEFAULT_NSFW_POLICY,
- autoPlayVideo: true,
- role: options.role,
- videoQuota: CONFIG.USER.VIDEO_QUOTA,
- videoQuotaDaily: CONFIG.USER.VIDEO_QUOTA_DAILY,
- adminFlags: UserAdminFlag.NONE,
pluginAuth
- }) as MUser
+ })
const { user } = await createUserAccountAndChannelAndPlaylist({
userToCreate,
- userDisplayName: options.displayName
+ userDisplayName: userOptions.displayName
})
return user