mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 13:27:46 +00:00
Fix lint issues
This commit is contained in:
@@ -1,5 +1,6 @@
|
|||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { authRateLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { authRateLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import crypto from "node:crypto";
|
import crypto from "node:crypto";
|
||||||
import jwt from "jsonwebtoken";
|
|
||||||
|
|
||||||
import bcrypt from "bcrypt";
|
import bcrypt from "bcrypt";
|
||||||
|
import jwt from "jsonwebtoken";
|
||||||
import { Knex } from "knex";
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { TAuthTokens, TAuthTokenSessions } from "@app/db/schemas";
|
import { TAuthTokens, TAuthTokenSessions } from "@app/db/schemas";
|
||||||
@@ -101,40 +101,6 @@ export const tokenServiceFactory = ({ tokenDAL, userDAL, orgMembershipDAL }: TAu
|
|||||||
return token;
|
return token;
|
||||||
};
|
};
|
||||||
|
|
||||||
const validateRefreshToken = async (refreshToken?: string) => {
|
|
||||||
const appCfg = getConfig();
|
|
||||||
if (!refreshToken)
|
|
||||||
throw new NotFoundError({
|
|
||||||
name: "AuthTokenNotFound",
|
|
||||||
message: "Failed to find refresh token"
|
|
||||||
});
|
|
||||||
|
|
||||||
const decodedToken = jwt.verify(refreshToken, appCfg.AUTH_SECRET) as AuthModeRefreshJwtTokenPayload;
|
|
||||||
|
|
||||||
if (decodedToken.authTokenType !== AuthTokenType.REFRESH_TOKEN)
|
|
||||||
throw new UnauthorizedError({
|
|
||||||
message: "The token provided is not a refresh token",
|
|
||||||
name: "InvalidToken"
|
|
||||||
});
|
|
||||||
|
|
||||||
const tokenVersion = await getUserTokenSessionById(decodedToken.tokenVersionId, decodedToken.userId);
|
|
||||||
|
|
||||||
if (!tokenVersion)
|
|
||||||
throw new UnauthorizedError({
|
|
||||||
message: "Valid token version not found",
|
|
||||||
name: "InvalidToken"
|
|
||||||
});
|
|
||||||
|
|
||||||
if (decodedToken.refreshVersion !== tokenVersion.refreshVersion) {
|
|
||||||
throw new UnauthorizedError({
|
|
||||||
message: "Token version mismatch",
|
|
||||||
name: "InvalidToken"
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
return { decodedToken, tokenVersion };
|
|
||||||
};
|
|
||||||
|
|
||||||
const validateTokenForUser = async ({
|
const validateTokenForUser = async ({
|
||||||
type,
|
type,
|
||||||
userId,
|
userId,
|
||||||
@@ -185,6 +151,40 @@ export const tokenServiceFactory = ({ tokenDAL, userDAL, orgMembershipDAL }: TAu
|
|||||||
|
|
||||||
const revokeAllMySessions = async (userId: string) => tokenDAL.deleteTokenSession({ userId });
|
const revokeAllMySessions = async (userId: string) => tokenDAL.deleteTokenSession({ userId });
|
||||||
|
|
||||||
|
const validateRefreshToken = async (refreshToken?: string) => {
|
||||||
|
const appCfg = getConfig();
|
||||||
|
if (!refreshToken)
|
||||||
|
throw new NotFoundError({
|
||||||
|
name: "AuthTokenNotFound",
|
||||||
|
message: "Failed to find refresh token"
|
||||||
|
});
|
||||||
|
|
||||||
|
const decodedToken = jwt.verify(refreshToken, appCfg.AUTH_SECRET) as AuthModeRefreshJwtTokenPayload;
|
||||||
|
|
||||||
|
if (decodedToken.authTokenType !== AuthTokenType.REFRESH_TOKEN)
|
||||||
|
throw new UnauthorizedError({
|
||||||
|
message: "The token provided is not a refresh token",
|
||||||
|
name: "InvalidToken"
|
||||||
|
});
|
||||||
|
|
||||||
|
const tokenVersion = await getUserTokenSessionById(decodedToken.tokenVersionId, decodedToken.userId);
|
||||||
|
|
||||||
|
if (!tokenVersion)
|
||||||
|
throw new UnauthorizedError({
|
||||||
|
message: "Valid token version not found",
|
||||||
|
name: "InvalidToken"
|
||||||
|
});
|
||||||
|
|
||||||
|
if (decodedToken.refreshVersion !== tokenVersion.refreshVersion) {
|
||||||
|
throw new UnauthorizedError({
|
||||||
|
message: "Token version mismatch",
|
||||||
|
name: "InvalidToken"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return { decodedToken, tokenVersion };
|
||||||
|
};
|
||||||
|
|
||||||
// to parse jwt identity in inject identity plugin
|
// to parse jwt identity in inject identity plugin
|
||||||
const fnValidateJwtIdentity = async (token: AuthModeJwtTokenPayload) => {
|
const fnValidateJwtIdentity = async (token: AuthModeJwtTokenPayload) => {
|
||||||
const session = await tokenDAL.findOneTokenSession({
|
const session = await tokenDAL.findOneTokenSession({
|
||||||
@@ -218,12 +218,12 @@ export const tokenServiceFactory = ({ tokenDAL, userDAL, orgMembershipDAL }: TAu
|
|||||||
|
|
||||||
return {
|
return {
|
||||||
createTokenForUser,
|
createTokenForUser,
|
||||||
validateRefreshToken,
|
|
||||||
validateTokenForUser,
|
validateTokenForUser,
|
||||||
getUserTokenSession,
|
getUserTokenSession,
|
||||||
clearTokenSessionById,
|
clearTokenSessionById,
|
||||||
getTokenSessionByUser,
|
getTokenSessionByUser,
|
||||||
revokeAllMySessions,
|
revokeAllMySessions,
|
||||||
|
validateRefreshToken,
|
||||||
fnValidateJwtIdentity,
|
fnValidateJwtIdentity,
|
||||||
getUserTokenSessionById
|
getUserTokenSessionById
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ import jwt from "jsonwebtoken";
|
|||||||
|
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { ForbiddenRequestError, UnauthorizedError } from "@app/lib/errors";
|
import { ForbiddenRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||||
|
|
||||||
import { AuthModeProviderJwtTokenPayload, AuthModeProviderSignUpTokenPayload, AuthTokenType } from "./auth-type";
|
import { AuthModeProviderJwtTokenPayload, AuthModeProviderSignUpTokenPayload, AuthTokenType } from "./auth-type";
|
||||||
|
|
||||||
export const validateProviderAuthToken = (providerToken: string, username?: string) => {
|
export const validateProviderAuthToken = (providerToken: string, username?: string) => {
|
||||||
|
|||||||
@@ -1,8 +1,9 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { TDbClient } from "@app/db";
|
import { TDbClient } from "@app/db";
|
||||||
import { TableName } from "@app/db/schemas";
|
import { TableName } from "@app/db/schemas";
|
||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify } from "@app/lib/knex";
|
import { ormify } from "@app/lib/knex";
|
||||||
import { Knex } from "knex";
|
|
||||||
|
|
||||||
export type TKmsRootConfigDALFactory = ReturnType<typeof kmsRootConfigDALFactory>;
|
export type TKmsRootConfigDALFactory = ReturnType<typeof kmsRootConfigDALFactory>;
|
||||||
|
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import { AxiosError } from "axios";
|
|||||||
|
|
||||||
import { apiRequest } from "@app/config/request";
|
import { apiRequest } from "@app/config/request";
|
||||||
import { SessionStorageKeys } from "@app/const";
|
import { SessionStorageKeys } from "@app/const";
|
||||||
|
import { queryClient as qc } from "@app/hooks/api/reactQuery";
|
||||||
|
|
||||||
import { APIKeyDataV2 } from "../apiKeys/types";
|
import { APIKeyDataV2 } from "../apiKeys/types";
|
||||||
import { MfaMethod } from "../auth/types";
|
import { MfaMethod } from "../auth/types";
|
||||||
@@ -24,7 +25,6 @@ import {
|
|||||||
User,
|
User,
|
||||||
UserEnc
|
UserEnc
|
||||||
} from "./types";
|
} from "./types";
|
||||||
import { queryClient } from "@app/hooks/api/reactQuery";
|
|
||||||
|
|
||||||
export const fetchUserDetails = async () => {
|
export const fetchUserDetails = async () => {
|
||||||
const { data } = await apiRequest.get<{ user: User & UserEnc }>("/api/v1/user");
|
const { data } = await apiRequest.get<{ user: User & UserEnc }>("/api/v1/user");
|
||||||
@@ -297,7 +297,7 @@ export const clearSession = (keepQueryClient?: boolean) => {
|
|||||||
sessionStorage.removeItem(SessionStorageKeys.CLI_TERMINAL_TOKEN);
|
sessionStorage.removeItem(SessionStorageKeys.CLI_TERMINAL_TOKEN);
|
||||||
|
|
||||||
if (!keepQueryClient) {
|
if (!keepQueryClient) {
|
||||||
queryClient.clear(); // Clear React Query cache
|
qc.clear(); // Clear React Query cache
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -1,12 +1,11 @@
|
|||||||
import { createFileRoute, redirect } from "@tanstack/react-router";
|
import { createFileRoute, redirect } from "@tanstack/react-router";
|
||||||
|
import { AxiosError } from "axios";
|
||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { ROUTE_PATHS } from "@app/const/routes";
|
import { ROUTE_PATHS } from "@app/const/routes";
|
||||||
import { userKeys } from "@app/hooks/api";
|
import { userKeys } from "@app/hooks/api";
|
||||||
import { authKeys, fetchAuthToken } from "@app/hooks/api/auth/queries";
|
import { authKeys, fetchAuthToken } from "@app/hooks/api/auth/queries";
|
||||||
import { fetchUserDetails } from "@app/hooks/api/users/queries";
|
import { clearSession, fetchUserDetails, logoutUser } from "@app/hooks/api/users/queries";
|
||||||
import { AxiosError } from "axios";
|
|
||||||
import { clearSession, logoutUser } from "@app/hooks/api/users/queries";
|
|
||||||
|
|
||||||
export const Route = createFileRoute("/_authenticate")({
|
export const Route = createFileRoute("/_authenticate")({
|
||||||
beforeLoad: async ({ context, location }) => {
|
beforeLoad: async ({ context, location }) => {
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { createFileRoute } from '@tanstack/react-router'
|
import { createFileRoute } from "@tanstack/react-router";
|
||||||
|
|
||||||
import { NoOrgPage } from './NoOrgPage'
|
import { NoOrgPage } from "./NoOrgPage";
|
||||||
|
|
||||||
export const Route = createFileRoute('/_authenticate/organization/none')({
|
export const Route = createFileRoute("/_authenticate/organization/none")({
|
||||||
component: NoOrgPage,
|
component: NoOrgPage
|
||||||
})
|
});
|
||||||
|
|||||||
@@ -1,9 +1,7 @@
|
|||||||
import { createFileRoute } from '@tanstack/react-router'
|
import { createFileRoute } from "@tanstack/react-router";
|
||||||
|
|
||||||
import { OrganizationLayout } from '@app/layouts/OrganizationLayout'
|
import { OrganizationLayout } from "@app/layouts/OrganizationLayout";
|
||||||
|
|
||||||
export const Route = createFileRoute(
|
export const Route = createFileRoute("/_authenticate/_inject-org-details/_org-layout")({
|
||||||
'/_authenticate/_inject-org-details/_org-layout',
|
component: OrganizationLayout
|
||||||
)({
|
});
|
||||||
component: OrganizationLayout,
|
|
||||||
})
|
|
||||||
|
|||||||
Reference in New Issue
Block a user