Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove Passport #2809

Merged
merged 29 commits into from
Feb 17, 2025
Merged
Show file tree
Hide file tree
Changes from 23 commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
57a00e0
Remove passport
fraxachun Nov 22, 2024
463d7f3
Update packages/api/cms-api/src/auth/services/static-authed-user.auth…
fraxachun Nov 28, 2024
481e411
Merge next
fraxachun Dec 2, 2024
9fdf4f8
Add tests
fraxachun Dec 2, 2024
94602e1
Add tests
fraxachun Dec 2, 2024
3070ae0
Add @nestjs/jwt as peer dependency
fraxachun Dec 2, 2024
c2f7ea5
Add JwtAuthService to demo
fraxachun Dec 2, 2024
12419de
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 2, 2024
41d52ee
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 13, 2024
daab325
Update packages/api/cms-api/src/auth/util/auth-guard.providers.ts
fraxachun Dec 18, 2024
ff8f140
Update packages/api/cms-api/src/auth/services/basic.auth-service.ts
fraxachun Dec 18, 2024
33bf4f0
Merge remote-tracking branch 'origin/remove-passport' into remove-pas…
fraxachun Dec 18, 2024
d1a1b3a
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 18, 2024
8bd18ee
Remove jsonwebtoken dependency
fraxachun Dec 18, 2024
84316fd
Add migration guide
fraxachun Dec 18, 2024
ebf1e7d
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 18, 2024
8326884
Add changeset
fraxachun Dec 18, 2024
6f3f9e3
Fix typo
fraxachun Dec 18, 2024
a39e806
Update docs/docs/migration/migration-from-v7-to-v8.md
fraxachun Dec 19, 2024
7b66355
Add note to migration guide
fraxachun Dec 19, 2024
ae27da5
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 19, 2024
f8e57ec
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 19, 2024
0f52509
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 19, 2024
f864172
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Dec 20, 2024
aa15c4a
Fix docs
fraxachun Dec 20, 2024
2cf4ff2
Merge remote-tracking branch 'origin/next' into remove-passport
fraxachun Feb 6, 2025
9938b0c
Merge branch 'next' into remove-passport
fraxachun Feb 6, 2025
2a237f5
Merge branch 'next' into remove-passport
fraxachun Feb 14, 2025
9a73b06
Remove dependency
fraxachun Feb 14, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/rude-laws-pretend.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"@comet/cms-api": major
---

Replace passport with auth services

See the migration guide to upgrade.
1 change: 1 addition & 0 deletions demo/api/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"@nestjs/common": "^10.4.8",
"@nestjs/core": "^10.4.8",
"@nestjs/graphql": "^12.2.1",
"@nestjs/jwt": "^10.2.0",
"@nestjs/platform-express": "^10.4.8",
"@opentelemetry/api": "^1.9.0",
"@opentelemetry/auto-instrumentations-node": "^0.50.0",
Expand Down
56 changes: 28 additions & 28 deletions demo/api/schema.gql
Original file line number Diff line number Diff line change
Expand Up @@ -2,34 +2,6 @@
# THIS FILE WAS AUTOMATICALLY GENERATED (DO NOT MODIFY)
# ------------------------------------------------------

type UserPermissionsUser {
id: String!
name: String!
email: String!
permissionsCount: Int!
contentScopesCount: Int!
}

type CurrentUserPermission {
permission: String!
contentScopes: [JSONObject!]!
}

"""
The `JSONObject` scalar type represents JSON objects as specified by [ECMA-404](http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf).
"""
scalar JSONObject @specifiedBy(url: "http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf")

type CurrentUser {
id: String!
name: String!
email: String!
permissions: [CurrentUserPermission!]!
impersonated: Boolean
authenticatedUser: UserPermissionsUser
permissionsForScope(scope: JSONObject!): [String!]!
}

type UserPermission {
id: ID!
source: UserPermissionSource!
Expand All @@ -53,6 +25,34 @@ A date-time string at UTC, such as 2019-12-03T09:54:33Z, compliant with the date
"""
scalar DateTime

"""
The `JSONObject` scalar type represents JSON objects as specified by [ECMA-404](http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf).
"""
scalar JSONObject @specifiedBy(url: "http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf")

type UserPermissionsUser {
id: String!
name: String!
email: String!
permissionsCount: Int!
contentScopesCount: Int!
}

type CurrentUserPermission {
permission: String!
contentScopes: [JSONObject!]!
}

type CurrentUser {
id: String!
name: String!
email: String!
permissions: [CurrentUserPermission!]!
impersonated: Boolean
authenticatedUser: UserPermissionsUser
permissionsForScope(scope: JSONObject!): [String!]!
}

type Dependency {
rootId: String!
rootGraphqlObjectType: String!
Expand Down
29 changes: 19 additions & 10 deletions demo/api/src/auth/auth.module.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,14 @@
import { createAuthResolver, createCometAuthGuard, createStaticAuthedUserStrategy, createStaticCredentialsBasicStrategy } from "@comet/cms-api";
import {
CometAuthGuard,
createAuthGuardProviders,
createAuthResolver,
createBasicAuthService,
createJwtAuthService,
createStaticUserAuthService,
} from "@comet/cms-api";
import { DynamicModule, Module } from "@nestjs/common";
import { APP_GUARD } from "@nestjs/core";
import { JwtModule } from "@nestjs/jwt";
import { Config } from "@src/config/config";

import { AccessControlService } from "./access-control.service";
Expand All @@ -15,23 +23,24 @@ export class AuthModule {
return {
module: AuthModule,
providers: [
createStaticCredentialsBasicStrategy({
username: SYSTEM_USER_NAME,
password: config.auth.systemUserPassword,
strategyName: "system-user",
}),
createStaticAuthedUserStrategy({
staticAuthedUser: staticUsers[0],
}),
...createAuthGuardProviders(
createBasicAuthService({
username: SYSTEM_USER_NAME,
password: config.auth.systemUserPassword,
}),
createJwtAuthService({ verifyOptions: { secret: "secret" } }), // for testing purposes, send header "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIyIiwiaWF0IjoxNTE2MjM5MDIyfQ.fG9j2rVOgunoya_njgn9w1t8muFlrpE9ffJ9i8sJYsQ"
createStaticUserAuthService({ staticUser: staticUsers[0] }),
),
createAuthResolver(),
{
provide: APP_GUARD,
useClass: createCometAuthGuard(["system-user", "static-authed-user"]),
useClass: CometAuthGuard,
},
UserService,
AccessControlService,
],
exports: [UserService, AccessControlService],
imports: [JwtModule],
};
}
}
53 changes: 53 additions & 0 deletions docs/docs/migration/migration-from-v7-to-v8.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,8 @@ It automatically installs the new versions of all `@comet` libraries, runs an ES
- Run MUI codemods
- Upgrade MUI X packages to v6
- Upgrade NestJS packages to v10
- Remove passport-dependencies (we don't use passport anymore)
- Add @nestjs/jwt dependencies

</details>

Expand Down Expand Up @@ -126,8 +128,59 @@ The class-validator peer dependency has been bumped to v0.14.0:
npx @comet/upgrade v8/update-class-validator.ts
```

### Remove passport

Remove all passport-dependencies and add @nestjs/jwt

```diff title=api/package.json
{
"dependencies": {
- "@nestjs/passport": "^9.0.0",
- ...other passport dependencies
+ "@nestjs/jwt": "^10.2.0",
}
}
```

:::note Codemod available

```sh
npx @comet/upgrade v8/remove-passport.ts
```

:::

Rename the `strategy`-factories and wrap them in `...createAuthGuardProviders()`:

```diff title=api/src/auth/auth.module.ts
- createStaticCredentialsBasicStrategy({ ... }),
- createAuthProxyJwtStrategy({ ... }),
- createStaticCredentialsBasicStrategy({ ... }),
+ ...createAuthGuardProviders(
+ createBasicAuthService({ ... }),
+ createJwtAuthService({ ... }),
+ createStaticUserAuthService({ ... }),
+ ),
```

:::note The configuration of the AuthServices have changed slightly. Consulting the code completion should help to adapt.

Replace `createAuthResolver` with the class name:

```diff title=api/src/auth/auth.module.ts
- useClass: createCometAuthGuard([...]),
+ useClass: CometAuthGuard,
```

:::note `CometAuthGuard` does not support Passport strategies anymore. Consider rewriting or wrapping into `AuthServiceInterface`. However, you still can use passport strategies in conjunction with the provided `AuthGuard` from `@nestjs/passport`.

Import `JwtModule` from `@nestjs/jwt`:

```diff title=api/src/auth/auth.module.ts
exports: [UserService, AccessControlService],
+ imports: [JwtModule],
```

## Admin

### Stay on same page after changing scope
Expand Down
11 changes: 2 additions & 9 deletions packages/api/cms-api/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@
"@golevelup/nestjs-discovery": "^4.0.2",
"@hapi/accept": "^5.0.2",
"@nestjs/mapped-types": "^2.0.6",
"@nestjs/passport": "^10.0.3",
"@opentelemetry/api": "^1.9.0",
"@types/get-image-colors": "^4.0.0",
"base64url": "^3.0.0",
Expand All @@ -58,18 +57,13 @@
"graphql-scalars": "^1.23.0",
"hasha": "^5.2.2",
"jose": "^5.2.4",
"jsonwebtoken": "^8.5.1",
"jszip": "^3.10.1",
"jwks-rsa": "^3.0.0",
"lodash.isequal": "^4.0.0",
"mime": "^3.0.0",
"mime-db": "^1.0.0",
"multer": "^1.4.4",
"node-fetch": "^2.0.0",
"passport": "^0.6.0",
"passport-custom": "^1.1.1",
"passport-http": "^0.3.0",
"passport-jwt": "^4.0.0",
"pluralize": "^8.0.0",
"probe-image-size": "^7.0.0",
"reflect-metadata": "^0.1.0",
Expand All @@ -92,21 +86,19 @@
"@nestjs/common": "^10.4.8",
"@nestjs/core": "^10.4.8",
"@nestjs/graphql": "^12.2.1",
"@nestjs/jwt": "^10.2.0",
"@nestjs/platform-express": "^10.4.8",
"@nestjs/testing": "^10.4.8",
"@sentry/node": "^7.0.0",
"@types/draft-js": "^0.11.10",
"@types/express": "^4.0.0",
"@types/jest": "^29.5.0",
"@types/jsonwebtoken": "^8.5.9",
"@types/lodash.isequal": "^4.0.0",
"@types/mime": "^2.0.0",
"@types/mime-db": "^1.0.0",
"@types/multer": "^1.4.4",
"@types/node": "^22.0.0",
"@types/node-fetch": "^2.6.2",
"@types/passport-http": "^0.3.9",
"@types/passport-jwt": "^3.0.7",
"@types/pluralize": "^0.0.29",
"@types/probe-image-size": "^7.0.0",
"@types/request-ip": "^0.0.41",
Expand Down Expand Up @@ -136,6 +128,7 @@
"@nestjs/common": "^10.0.0",
"@nestjs/core": "^10.0.0",
"@nestjs/graphql": "^12.0.0",
"@nestjs/jwt": "^10.2.0",
"@nestjs/platform-express": "^10.0.0",
"@sentry/node": "^7.0.0",
"class-validator": "^0.14.0",
Expand Down
56 changes: 28 additions & 28 deletions packages/api/cms-api/schema.gql
Original file line number Diff line number Diff line change
@@ -1,31 +1,3 @@
type UserPermissionsUser {
id: String!
name: String!
email: String!
permissionsCount: Int!
contentScopesCount: Int!
}

type CurrentUserPermission {
permission: String!
contentScopes: [JSONObject!]!
}

"""
The `JSONObject` scalar type represents JSON objects as specified by [ECMA-404](http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf).
"""
scalar JSONObject @specifiedBy(url: "http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf")

type CurrentUser {
id: String!
name: String!
email: String!
permissions: [CurrentUserPermission!]!
impersonated: Boolean
authenticatedUser: UserPermissionsUser
permissionsForScope(scope: JSONObject!): [String!]!
}

type UserPermission {
id: ID!
source: UserPermissionSource!
Expand All @@ -49,6 +21,34 @@ A date-time string at UTC, such as 2019-12-03T09:54:33Z, compliant with the date
"""
scalar DateTime

"""
The `JSONObject` scalar type represents JSON objects as specified by [ECMA-404](http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf).
"""
scalar JSONObject @specifiedBy(url: "http://www.ecma-international.org/publications/files/ECMA-ST/ECMA-404.pdf")

type UserPermissionsUser {
id: String!
name: String!
email: String!
permissionsCount: Int!
contentScopesCount: Int!
}

type CurrentUserPermission {
permission: String!
contentScopes: [JSONObject!]!
}

type CurrentUser {
id: String!
name: String!
email: String!
permissions: [CurrentUserPermission!]!
impersonated: Boolean
authenticatedUser: UserPermissionsUser
permissionsForScope(scope: JSONObject!): [String!]!
}

type Dependency {
rootId: String!
rootGraphqlObjectType: String!
Expand Down
Loading
Loading