Add certificate authentication, in-app setup guides and security audit

Certificate (RFC 7523 client assertion) as an alternative to the client
secret: one-click generation of a 3072-bit RSA key pair with a
self-signed certificate, .cer download (public part only), own PEM
upload with validation, expiry display, encrypted key storage. Both the
authorization code exchange and the Graph client-credentials request
use the selected method. Step-by-step guides for secret, certificate
and the app registration are shown in the settings.

Security audit (docs/security-audit.md) and fixes:
- Multi-tenant mode ignored the unverified email claim: matching now
  uses the UPN only, or the email claim when xms_edov is true.
- Login starts are rate limited per client (30 per 10 minutes).
- Optional trusted proxy header for client IPs
  (M365_LOGIN_CLIENT_IP_HEADER / filter).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2
This commit is contained in:
friloo 2026-09-22 15:04:32 +00:00
parent 966164177d
commit 8766927123
No known key found for this signature in database
19 changed files with 2515 additions and 644 deletions

View file

@ -129,6 +129,50 @@
$( '#m365-icon-url' ).val( '' ).trigger( 'input' );
} );
/* ---------------- Auth method switch ---------------- */
function applyMethod() {
var method = $( 'input[name$="[auth_method]"]:checked' ).val() || 'secret';
$( '.m365-method__option' ).removeClass( 'is-selected' ).filter( '[data-method="' + method + '"]' ).addClass( 'is-selected' );
$( '.m365-auth-panel' ).removeClass( 'is-active' ).filter( '[data-method="' + method + '"]' ).addClass( 'is-active' );
}
$( 'input[name$="[auth_method]"]' ).on( 'change', applyMethod );
applyMethod();
/* ---------------- Certificate generation ---------------- */
$( '#m365-cert-generate' ).on( 'click', function () {
var $btn = $( this );
var $out = $( '#m365-cert-result' );
if ( $btn.data( 'replace' ) && ! window.confirm( i18n.confirmCert ) ) {
return;
}
$btn.prop( 'disabled', true );
$out.removeClass( 'is-success is-error' ).prop( 'hidden', false ).text( i18n.generating || '…' );
$.post( cfg.ajaxUrl, { action: cfg.certAction, nonce: cfg.nonce, op: 'generate' } ).done( function ( res ) {
if ( res && res.success ) {
$out.addClass( 'is-success' ).text( res.data.message );
window.setTimeout( function () { window.location.reload(); }, 800 );
} else {
$out.addClass( 'is-error' ).text( ( res && res.data && res.data.message ) || i18n.testFailed );
$btn.prop( 'disabled', false );
}
} ).fail( function () {
$out.addClass( 'is-error' ).text( i18n.testFailed );
$btn.prop( 'disabled', false );
} );
} );
$( '#m365-cert-remove' ).on( 'change', function () {
if ( this.checked && ! window.confirm( i18n.confirmCertRemove ) ) {
this.checked = false;
}
} );
$( '#m365-cert-paste-toggle' ).on( 'click', function ( e ) {
e.preventDefault();
$( '#m365-cert-paste' ).prop( 'hidden', function ( i, v ) { return ! v; } );
} );
/* ---------------- Secret visibility ---------------- */
$( '.m365-toggle-secret' ).on( 'click', function () {
var $input = $( '#m365-client-secret' );