Last active
June 23, 2020 15:51
-
-
Save janakamarasena/294f3cba4b597952cf33fcc9f84fe4b9 to your computer and use it in GitHub Desktop.
Blog - account linking scenario 1, advance association script.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| var onLoginRequest = function onLoginRequest(context) { | |
| var fedUser; | |
| executeStep(1, | |
| { | |
| onSuccess: function (context) { | |
| var idpName = context.steps[1].idp; | |
| // Only execute this flow when the user login from the google idp. | |
| // If you want to target all your idps you can use something like | |
| // idpName !== "LOCAL" | |
| if (idpName === "google") { | |
| fedUser = context.currentKnownSubject; | |
| // Check if there is already a user association | |
| var assocUser = getAssociatedLocalUser(fedUser); | |
| if (assocUser == null) { | |
| var claimMap = {}; | |
| claimMap["http://wso2.org/claims/emailaddress"] = fedUser.remoteClaims.email; | |
| // getUniqueUserWithClaimValues(<claims to match the user>, <tenant domain>) | |
| var storedLocalUser = getUniqueUserWithClaimValues(claimMap, "carbon.super"); | |
| if (storedLocalUser !== null) { | |
| // Prompt a screen showing info on the user association | |
| prompt("associationConsentForm", { "email": fedUser.remoteClaims.email }, { | |
| onSuccess: function (context) { | |
| // Get the user decision to associate from the prompt | |
| var decision = context.request.params.decision[0]; | |
| if (decision === "yes") { | |
| // Perform basic authenticaion to confirm account ownership | |
| executeStep(2, | |
| { | |
| onSuccess: function (context) { | |
| // Get the authenticated user from basic authentication step | |
| var authUser = context.steps[2].subject; | |
| // Do any additional validation here | |
| // E.g. Validate whether storedLocalUser that we found is same as the authenticated user | |
| // storedLocalUser.username == authUser.username | |
| // Do the account linking | |
| doAssociationWithLocalUser(fedUser, authUser.username, authUser.tenantDomain, authUser.userStoreDomain); | |
| } | |
| }); | |
| } | |
| } | |
| }); | |
| } | |
| } | |
| } | |
| } | |
| }); | |
| }; |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment