mattermost-mobile/app/utils/intune_errors.ts
Elias Nahum 44eb76bed7
feat(iOS): Add Microsoft Intune MAM integration with multi-server support (#9312)
* refactor: implement custom ExpoImage wrapper for cache control

Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app

* refactor(ios): convert Gekidou to CocoaPods

Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0

* npm audit

* update fastlane

* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection

Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository

* fix tests by mocking @mattermost/intune

* feat: implement Intune MAM integration with comprehensive security enforcement

Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls

* fix alerts when no server database is present

* Unify cache strategy

* fix emit config changed after it was stored in the db

* Handle Mid-Session Enrollment Detection

* fix ADALLogOverrideDisabled missing in Fastfile

* fix flow for initial enrollment

* fix and add unit tests

* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release

* Update intune submodule with addressed feedback

* fix validate-intune-clean workflow

* feat(intune): add comprehensive error handling and SAML+Entra support

Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.

* update i18n

* update intune submodule

* update build-pr token

* fix race condition between server auth and intune enrollment

* fix CI workflow to build with intune

* use deploy key for intune submodule

* set the config directly in the submodule .git

* debug injection

* try setting GIT_SSH_COMMAND

* remove action debug

* fix server url input

* match pod cache with intune hash

* Fastfile and envs

* have workflows check for intune/.git

* have ci cache intune frameworks as well

* update Fastlane to set no-cache to artifacts uploaded

* fix s3 upload

* fix pblist template

* Attempt to remove the cache control for PR uploads to s3

* use hash from commit for S3 path

* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain

* Fix surface errors from intune login

* fix postinstall scripts

* use cacheKey for draft md images

* remove unnecessary double await during test

* Have isMinimumLicenseTier accept valid license sku tier as target

* Add missing Auth error messages

* remove the last period for intune errors in i18n

* do not call unenroll with wipe on manual logout

* Fix tests and Intune error messages

* do not filter any SSO type regardless of which is used for Intune

* fix 412 to not retry

* fix tests, app logs sharing and share_extension avatar cache

* apply setScreenCapturePolicy on license change

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* re-apply screen capture on enrollment

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* use userData from intunr login and prevent getMe

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* Check for Biometrics and Jailbreak as we used to

---------

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
2025-12-10 13:07:28 +02:00

80 lines
2.6 KiB
TypeScript

// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
import {defineMessage, type IntlShape} from 'react-intl';
import {isErrorWithMessage} from '@utils/errors';
// MSAL Error Domain and Codes
const MSAL_ERROR_DOMAIN = 'MSALErrorDomain';
const MSAL_ERROR_CODE_USER_CANCELED = -50005;
// i18n message definitions
const intuneErrorMessages = {
loginCanceled: defineMessage({
id: 'mobile.intune.login.canceled',
defaultMessage: 'Login was canceled. Please try again',
}),
authFailed: defineMessage({
id: 'mobile.intune.login.failed',
defaultMessage: 'Authentication failed. Please try again',
}),
};
/**
* Check if error is an NSError with domain and code
*/
function isNSError(error: unknown): error is {domain: string; code: number; message?: string} {
return (
typeof error === 'object' &&
error !== null &&
'domain' in error &&
'code' in error &&
typeof (error as {domain: unknown}).domain === 'string' &&
typeof (error as {code: unknown}).code === 'number'
);
}
/**
* Check if error is MSAL user cancellation
*/
export function isMSALUserCancellation(error: unknown): boolean {
return isNSError(error) &&
error.domain === MSAL_ERROR_DOMAIN &&
error.code === MSAL_ERROR_CODE_USER_CANCELED;
}
/**
* Map Intune/MSAL error to user-friendly i18n message
* Handles:
* - Server errors (400, 409, 428)
* - MSAL cancellation errors (-50005)
* - Generic MSAL errors
*
* @param error - The error object from nativeEntraLogin
* @param intl - IntlShape for formatting messages
* @returns User-friendly error message
*/
export function getIntuneErrorMessage(error: unknown, intl: IntlShape): string {
// Handle MSAL user cancellation (domain: MSALErrorDomain, code: -50005)
if (isMSALUserCancellation(error)) {
return intl.formatMessage(intuneErrorMessages.loginCanceled);
}
// Handle generic MSAL errors (other MSALErrorDomain codes)
if (isNSError(error) && error.domain === MSAL_ERROR_DOMAIN) {
return intl.formatMessage(intuneErrorMessages.authFailed);
}
// Handle any other error with message
if (isErrorWithMessage(error)) {
// Check for raw MSAL error strings in message
if (error.message.includes(MSAL_ERROR_DOMAIN) || error.message.includes('code:')) {
return intl.formatMessage(intuneErrorMessages.authFailed);
}
return error.message;
}
// Fallback for unknown errors
return intl.formatMessage(intuneErrorMessages.authFailed);
}