* Add domain_id to oauth_provider table and VO
* Add domain-aware methods to OauthProviderDao
* Add domainId parameter to OAuth provider API commands and response
* Add domain support to OAuth2AuthManager
* Add domain-aware OAuth verification
* Add domain support to ListOAuthProvidersCmd and update related tests
* fix domain path issue
* Add domainId support to OAuth provider
* Return domain name and UUID in OAuth provider API responses using ApiDBUtils
* Refactor domain ID resolution in VerifyOAuthCodeAndGetUserCmd to improve code clarity
* Enhance OAuth2 plugin support for domain-level configuration and authentication checks
* Update OAuth2 tests and VerifyOAuthCodeAndGetUserCmdTest
* Add method to find OAuth provider by domain with global fallback
* Update OAuth provider configuration to use 'domain' instead of 'domainid' in columns and details
* Refactor OAuth provider methods to support domain-level queries and enhance user verification
* Add caching for access token retrieval in GithubOAuth2Provider
* Refactor access token checks in GithubOAuth2Provider to use StringUtils for improved readability and consistency
* Refactor null checks to use utility for improved readability and consistency
* Update OAuth2UserAuthenticatorTest to include domainId in user verification method
* Remove unnecessary blank line and unused imports in OAuth provider command classes
* Refactor and cleanup
* Remove unnecessary blank lines
* Enhance RegisterOAuthProviderCmdTest with additional provider mock data
* Remove startup gate from OAuth plugin initialization to support dynamic config toggling
* Add strictScope to ConfigKey to disable global fallback for domain-scoped oauth2.enabled
* Add domain-scoped provider filtering to listOauthProvider and centralize domain resolution in OAuth2AuthManager
* Add External OAuth tab with domain-scoped provider selection to login page
* code cleanup
* test fix
* Handle login page provider visibility
* UI cleanup
* UI Cleanup
* Keep text color consistent
* add unit tests
* Add Multiple-domain OAuth tests
* Refactor as per PR comments
* Use idempotent DDL helpers for oauth_provider schema migration
* Use global config check for global providers and extract oauthEnabled variable
* Make strictScope return null when id is null
* Rename verification methods to use 'verifySecretCodeAndFetchEmail' for consistency
* Refactor domain handling in OAuth2AuthManagerImpl to use DomainService instead of DomainDao
* Enhance domain ID descriptions in OAuth command classes for clarity
* Add domain path handling to OAuth provider commands and improve descriptions
* Update domain path description in VerifyOAuthCodeAndGetUserCmd to clarify behavior with Domain ID
* Replace remove method with expunge in deleteOauthProvider and add corresponding unit test
* Add external login label to Login.vue and update i18n locale handling
* Fix stale value issue in updateConfiguration response handling in ConfigurationValue.vue
* Enhance OAuth login error handling and add unit test for missing parameters
* Add validation to reject enabling OAuth provider when plugin is disabled at domain scope
* Add domain reassignment support to UpdateOAuthProviderCmd and enhance validation in OAuth2AuthManagerImpl
* Add domain ID to OAuth provider arguments in config
* Fix condition for OAuth verification URL handling in router
* Add domain path to OauthProviderResponse and update UI config to display it
* Update config to remove 'secretkey' from columns and details
* Add secretkey to details in config and display in DetailsTab
* Implement normalization of ROOT domain to null for global OAuth provider handling and add corresponding unit tests
* Refactor OAuth plugin domain scope handling to use a centralized method for enabling checks
* Add strict scope handling to ConfigKey and update OAuth2AuthManager usage
* Implement domain removal listener to clean up OAuth providers on domain deletion
* Enhance OAuth tab icons with disabled state styling for better UX
* Add domain-specific provider prompt and update OAuth provider handling
---------
Co-authored-by: Daman Arora <daman.arora@shapeblue.com>
* API modifications for passwordchangerequired
* ui login flow for passwordchangerequired
* add passwordchangerequired in listUsers API response, it will be used in UI to render reset password form
* cleanup redundant LOGIN_SOURCE and limiting apis for first time login
* address copilot comments
* allow enforcing password change for all role types and update reset pwd flow for passwordchangerequired
* address review comments
* add unit tests
* cleanup ispasswordchangerequired from user_view
* address review comments
* 1. Allow enforcing password change while creating user
2. Admin can enforce password change on next login with out resetting password
* address review comment, add unit test
* improve code coverage
* fix pre-commit license issue
* 1. allow enter key to submit change password form
2. hide force password reset for disabled/locked user in ui
* 1. throw exception when force reset password is done for locked/disabled user/account
2. ui validation on current and new password being same
3. allow enforce change password for add user until saml is not enabled
* allow oauth login to skip force password change
* Fix check
* Adds configuration for behaviour, when SAML SSO is disabled for a user
* set default configuration value to false and rename it to enable.login.with.disabled.saml
---------
Co-authored-by: Vitor Hugo Homem Marzarotto <vitor.marzarotto@scclouds.com.br>
Co-authored-by: erikbocks <erik.bock@outlook.com>
This PR aligns the use of terminology, renaming VM / virtual machine references to 'Instance' and also capitalising the terms Templates, Network, Snapshot, User, Account in CloudStack APIs, error and log messages, events, tooltips, etc. Many typos, grammar and spelling mistakes were fixed, also terms like IPv4, VPN, VPC, etc. were properly capitalised. Some error messages were cleaned for better readability. The test cases, expecting some exception strings were adjusted accordingly.
Here is the wiki page, describing the changes in details:
https://cwiki.apache.org/confluence/display/CLOUDSTACK/Object+Naming+and+Title+Case+Convention
---------
Co-authored-by: Manoj Kumar <manojkr.itbhu@gmail.com>
Co-authored-by: Harikrishna <harikrishna.patnala@gmail.com>
* Add UUID field for LDAP configuration
* move db changes to the lastest schema file
* Add ID param to list ldapConf API & delete ldapConf API
* fix ui test
* fix 1 ui test
* fix test
* fix api description
---------
Co-authored-by: dahn <daan@onecht.net>
Dependency name change mockito-inline to mockito-core. Inline is now the default and the last version of mockito-inline released is 5.2.0.
assertj-core in user-authenticators/saml2 pulls in an incompatible version of byte-buddy and required an exclusion. Updating the version of assertj is left for a future PR.
The upgrade requires Java 11+, dropping support for Java 8. CloudStack documentation already says to use Java 11 and does not indicate that java 8 is supported.
Test classes using @RunWith(MockitoJUnitRunner.class) now get run in strict mode. Changes were made to tests where the stubbing intention was clear. In ManagementServerMaintenanceManagerImplTest there are 5 tests where the intention of the test is unclear. Each of the statements now use Mockito.lenient() to avoid the exception. Other cases in the tests follow a similar pattern.
Minor clean up.
Both @Spy and Mockito.spy( should not be used. Favored the annotation.
Both @RunWith(MockitoJUnitRunner.class) and MockitoAnnotations.openMocks(this); should not be used. Favored the annotation.
Unnecessary extends TestCase removed.
@InjectMocks and new in statement unnecessary. Removed new when issue presented.
Some of the Cmd classes like UpdateNetworkCmd have a type tree that includes fields of type Object. This appears to cause issues with injection, requiring that @Mock fields be available. This is where the following fields were added in multiple places:
Object job;
ResponseGenerator _responseGenerator;
Wrong number of parameters for Mockito.when in LibvirtRevertSnapshotCommandWrapperTest.java