Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions apps/login/src/lib/server/loginname.ts
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
"use server";

import * as Sentry from "@sentry/nextjs";
import { create } from "@zitadel/client";
import { ChecksSchema } from "@zitadel/proto/zitadel/session/v2/session_service_pb";
import { AuthenticationMethodType } from "@zitadel/proto/zitadel/user/v2/user_service_pb";
Expand Down Expand Up @@ -219,20 +220,74 @@ export async function sendLoginname(command: SendLoginnameCommand) {
userLoginSettings?.disableLoginWithPhone
) {
if (user.preferredLoginName !== concatLoginname) {
Sentry.captureMessage("User not found: IDP-only validation failed", {
level: "error",
tags: {
validation_type: "idp_only",
user_id: user.userId,
},
extra: {
preferredLoginName: user.preferredLoginName,
concatLoginname,
commandLoginName: command.loginName,
email: humanUser?.email?.email,
organizationId: command.organization,
disableLoginWithEmail: userLoginSettings?.disableLoginWithEmail,
disableLoginWithPhone: userLoginSettings?.disableLoginWithPhone,
},
});
return { error: "User not found in the system!" };
}
} else if (userLoginSettings?.disableLoginWithEmail) {
if (
user.preferredLoginName !== concatLoginname ||
humanUser?.phone?.phone !== command.loginName
) {
Sentry.captureMessage(
"User not found: email-disabled validation failed",
{
level: "error",
tags: {
validation_type: "email_disabled",
user_id: user.userId,
},
extra: {
preferredLoginName: user.preferredLoginName,
concatLoginname,
commandLoginName: command.loginName,
phone: humanUser?.phone?.phone,
organizationId: command.organization,
disableLoginWithEmail: userLoginSettings?.disableLoginWithEmail,
disableLoginWithPhone: userLoginSettings?.disableLoginWithPhone,
},
},
);
return { error: "User not found in the system!" };
}
} else if (userLoginSettings?.disableLoginWithPhone) {
if (
user.preferredLoginName !== concatLoginname ||
humanUser?.email?.email !== command.loginName
) {
Sentry.captureMessage(
"User not found: phone-disabled validation failed",
{
level: "error",
tags: {
validation_type: "phone_disabled",
user_id: user.userId,
},
extra: {
preferredLoginName: user.preferredLoginName,
concatLoginname,
commandLoginName: command.loginName,
email: humanUser?.email?.email,
organizationId: command.organization,
disableLoginWithEmail: userLoginSettings?.disableLoginWithEmail,
disableLoginWithPhone: userLoginSettings?.disableLoginWithPhone,
},
},
);
return { error: "User not found in the system!" };
}
}
Expand Down
45 changes: 45 additions & 0 deletions apps/login/src/lib/zitadel.ts
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
import * as Sentry from "@sentry/nextjs";
import { Client, create, Duration } from "@zitadel/client";
import { createServerTransport as libCreateServerTransport } from "@zitadel/client/node";
import { makeReqCtx } from "@zitadel/client/v2";
Expand Down Expand Up @@ -856,6 +857,18 @@ export async function searchUsers({
}

if (loginNameResult.result.length > 1) {
Sentry.captureMessage("Multiple users found: loginName search", {
level: "error",
tags: {
search_type: "multiple_users_loginname",
},
extra: {
searchValue,
organizationId,
suffix,
resultCount: loginNameResult.result.length,
},
});
return { error: "Multiple users found" };
}

Expand Down Expand Up @@ -951,13 +964,45 @@ export async function searchUsers({
}

if (emailOrPhoneResult.result.length > 1) {
Sentry.captureMessage("Multiple users found: email/phone search", {
level: "error",
tags: {
search_type: "multiple_users_email_phone",
},
extra: {
searchValue,
organizationId,
suffix,
userId,
resultCount: emailOrPhoneResult.result.length,
disableLoginWithEmail: loginSettings?.disableLoginWithEmail,
disableLoginWithPhone: loginSettings?.disableLoginWithPhone,
},
});
return { error: "Multiple users found." };
}

if (emailOrPhoneResult.result.length == 1) {
return emailOrPhoneResult;
}

Sentry.captureMessage("User not found: searchUsers exhausted all queries", {
level: "error",
tags: {
search_type: "user_search_failed",
},
extra: {
searchValue,
organizationId,
suffix,
userId,
disableLoginWithEmail: loginSettings?.disableLoginWithEmail,
disableLoginWithPhone: loginSettings?.disableLoginWithPhone,
loginNameResultCount: 0,
emailOrPhoneResultCount: emailOrPhoneResult.result.length,
},
});

return { error: "User not found in the system" };
}

Expand Down
Loading