Add certificate authentication, in-app setup guides and security audit
Certificate (RFC 7523 client assertion) as an alternative to the client secret: one-click generation of a 3072-bit RSA key pair with a self-signed certificate, .cer download (public part only), own PEM upload with validation, expiry display, encrypted key storage. Both the authorization code exchange and the Graph client-credentials request use the selected method. Step-by-step guides for secret, certificate and the app registration are shown in the settings. Security audit (docs/security-audit.md) and fixes: - Multi-tenant mode ignored the unverified email claim: matching now uses the UPN only, or the email claim when xms_edov is true. - Login starts are rate limited per client (30 per 10 minutes). - Optional trusted proxy header for client IPs (M365_LOGIN_CLIENT_IP_HEADER / filter). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2
This commit is contained in:
parent
966164177d
commit
8766927123
19 changed files with 2515 additions and 644 deletions
|
|
@ -718,3 +718,230 @@
|
|||
.m365-fallback .m365-copy {
|
||||
margin-bottom: 8px;
|
||||
}
|
||||
|
||||
/* Auth method switch */
|
||||
.m365-method {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(2, minmax(0, 1fr));
|
||||
gap: 12px;
|
||||
margin-bottom: 20px;
|
||||
}
|
||||
|
||||
@media (max-width: 782px) {
|
||||
.m365-method {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
}
|
||||
|
||||
.m365-method__option {
|
||||
display: flex;
|
||||
gap: 10px;
|
||||
align-items: flex-start;
|
||||
padding: 14px 16px;
|
||||
border: 1px solid var(--m365-border);
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
background: #fff;
|
||||
}
|
||||
|
||||
.m365-method__option:hover {
|
||||
border-color: #b6d7f2;
|
||||
}
|
||||
|
||||
.m365-method__option.is-selected {
|
||||
border-color: var(--m365-accent);
|
||||
box-shadow: 0 0 0 1px var(--m365-accent);
|
||||
background: #fbfdff;
|
||||
}
|
||||
|
||||
.m365-method__option input {
|
||||
margin-top: 3px;
|
||||
}
|
||||
|
||||
.m365-method__option strong {
|
||||
display: block;
|
||||
font-weight: 600;
|
||||
}
|
||||
|
||||
.m365-method__option em {
|
||||
display: block;
|
||||
font-style: normal;
|
||||
color: var(--m365-muted);
|
||||
margin-top: 2px;
|
||||
font-size: 12px;
|
||||
}
|
||||
|
||||
.m365-method__badge {
|
||||
display: inline-block;
|
||||
margin-left: 6px;
|
||||
padding: 1px 8px;
|
||||
border-radius: 999px;
|
||||
font-size: 11px;
|
||||
font-weight: 600;
|
||||
background: #e6f4ea;
|
||||
color: #1e6b31;
|
||||
vertical-align: middle;
|
||||
}
|
||||
|
||||
.m365-auth-panel {
|
||||
display: none;
|
||||
}
|
||||
|
||||
.m365-auth-panel.is-active {
|
||||
display: block;
|
||||
}
|
||||
|
||||
/* Certificate box */
|
||||
.m365-cert {
|
||||
border: 1px solid var(--m365-border);
|
||||
border-radius: 8px;
|
||||
padding: 16px;
|
||||
background: #fafafa;
|
||||
margin-bottom: 16px;
|
||||
}
|
||||
|
||||
.m365-cert__grid {
|
||||
display: grid;
|
||||
grid-template-columns: max-content minmax(0, 1fr);
|
||||
gap: 6px 16px;
|
||||
font-size: 13px;
|
||||
margin: 8px 0 12px;
|
||||
}
|
||||
|
||||
.m365-cert__grid dt {
|
||||
color: var(--m365-muted);
|
||||
}
|
||||
|
||||
.m365-cert__grid dd {
|
||||
margin: 0;
|
||||
word-break: break-all;
|
||||
}
|
||||
|
||||
.m365-cert__grid code {
|
||||
background: #fff;
|
||||
border: 1px solid var(--m365-border);
|
||||
border-radius: 4px;
|
||||
padding: 2px 6px;
|
||||
font-size: 12px;
|
||||
}
|
||||
|
||||
.m365-cert__actions {
|
||||
display: flex;
|
||||
flex-wrap: wrap;
|
||||
gap: 8px;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
.m365-cert__empty {
|
||||
color: var(--m365-muted);
|
||||
margin: 0 0 12px;
|
||||
}
|
||||
|
||||
.m365-cert__status {
|
||||
display: inline-block;
|
||||
padding: 2px 10px;
|
||||
border-radius: 999px;
|
||||
font-size: 12px;
|
||||
font-weight: 600;
|
||||
}
|
||||
|
||||
.m365-cert__status.is-ok {
|
||||
background: #e6f4ea;
|
||||
color: #1e6b31;
|
||||
}
|
||||
|
||||
.m365-cert__status.is-warn {
|
||||
background: #fcf0e4;
|
||||
color: #8a4b00;
|
||||
}
|
||||
|
||||
.m365-cert__status.is-bad {
|
||||
background: #fcf0f1;
|
||||
color: #8a2424;
|
||||
}
|
||||
|
||||
.m365-field textarea.m365-pem {
|
||||
font-family: Consolas, Monaco, monospace;
|
||||
font-size: 12px;
|
||||
min-height: 120px;
|
||||
}
|
||||
|
||||
/* Guides */
|
||||
.m365-guide {
|
||||
border: 1px solid var(--m365-border);
|
||||
border-radius: 8px;
|
||||
background: #fff;
|
||||
margin-top: 16px;
|
||||
}
|
||||
|
||||
.m365-guide > summary {
|
||||
cursor: pointer;
|
||||
padding: 12px 16px;
|
||||
font-weight: 600;
|
||||
list-style: none;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
}
|
||||
|
||||
.m365-guide > summary::-webkit-details-marker {
|
||||
display: none;
|
||||
}
|
||||
|
||||
.m365-guide > summary::before {
|
||||
content: "▸";
|
||||
color: var(--m365-accent);
|
||||
transition: transform 0.15s ease;
|
||||
}
|
||||
|
||||
.m365-guide[open] > summary::before {
|
||||
transform: rotate(90deg);
|
||||
}
|
||||
|
||||
.m365-guide__body {
|
||||
padding: 0 16px 16px;
|
||||
border-top: 1px solid #f0f0f1;
|
||||
}
|
||||
|
||||
.m365-guide__body ol {
|
||||
margin: 12px 0 0;
|
||||
padding-left: 22px;
|
||||
}
|
||||
|
||||
.m365-guide__body li {
|
||||
margin-bottom: 10px;
|
||||
line-height: 1.55;
|
||||
}
|
||||
|
||||
.m365-guide__body li strong {
|
||||
font-weight: 600;
|
||||
}
|
||||
|
||||
.m365-guide__body code {
|
||||
font-size: 12px;
|
||||
}
|
||||
|
||||
.m365-guide__note {
|
||||
margin: 12px 0 0;
|
||||
padding: 10px 12px;
|
||||
border-radius: 6px;
|
||||
background: #f0f6fc;
|
||||
border: 1px solid #c5d9ed;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.m365-guide__warn {
|
||||
margin: 12px 0 0;
|
||||
padding: 10px 12px;
|
||||
border-radius: 6px;
|
||||
background: #fcf0e4;
|
||||
border: 1px solid #f0c28a;
|
||||
color: #6b3a00;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.m365-warning--strong {
|
||||
background: #fcf0f1;
|
||||
color: #8a2424;
|
||||
border: 1px solid #f0b8bd;
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue