mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 22:27:22 +00:00
misc: renamed disable flag + docs
This commit is contained in:
@@ -3,16 +3,16 @@ import { Knex } from "knex";
|
|||||||
import { TableName } from "../schemas";
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
export async function up(knex: Knex): Promise<void> {
|
||||||
const hasSkipBootstrapCertValidationCol = await knex.schema.hasColumn(
|
const hasDisableBootstrapCertValidationCol = await knex.schema.hasColumn(
|
||||||
TableName.CertificateTemplateEstConfig,
|
TableName.CertificateTemplateEstConfig,
|
||||||
"skipBootstrapCertValidation"
|
"disableBootstrapCertValidation"
|
||||||
);
|
);
|
||||||
|
|
||||||
const hasCaChainCol = await knex.schema.hasColumn(TableName.CertificateTemplateEstConfig, "encryptedCaChain");
|
const hasCaChainCol = await knex.schema.hasColumn(TableName.CertificateTemplateEstConfig, "encryptedCaChain");
|
||||||
|
|
||||||
await knex.schema.alterTable(TableName.CertificateTemplateEstConfig, (t) => {
|
await knex.schema.alterTable(TableName.CertificateTemplateEstConfig, (t) => {
|
||||||
if (!hasSkipBootstrapCertValidationCol) {
|
if (!hasDisableBootstrapCertValidationCol) {
|
||||||
t.boolean("skipBootstrapCertValidation").defaultTo(false).notNullable();
|
t.boolean("disableBootstrapCertValidation").defaultTo(false).notNullable();
|
||||||
}
|
}
|
||||||
|
|
||||||
if (hasCaChainCol) {
|
if (hasCaChainCol) {
|
||||||
@@ -22,16 +22,16 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
export async function down(knex: Knex): Promise<void> {
|
||||||
const hasSkipBootstrapCertValidationCol = await knex.schema.hasColumn(
|
const hasDisableBootstrapCertValidationCol = await knex.schema.hasColumn(
|
||||||
TableName.CertificateTemplateEstConfig,
|
TableName.CertificateTemplateEstConfig,
|
||||||
"skipBootstrapCertValidation"
|
"disableBootstrapCertValidation"
|
||||||
);
|
);
|
||||||
|
|
||||||
const hasCaChainCol = await knex.schema.hasColumn(TableName.CertificateTemplateEstConfig, "encryptedCaChain");
|
const hasCaChainCol = await knex.schema.hasColumn(TableName.CertificateTemplateEstConfig, "encryptedCaChain");
|
||||||
|
|
||||||
await knex.schema.alterTable(TableName.CertificateTemplateEstConfig, (t) => {
|
await knex.schema.alterTable(TableName.CertificateTemplateEstConfig, (t) => {
|
||||||
if (hasSkipBootstrapCertValidationCol) {
|
if (hasDisableBootstrapCertValidationCol) {
|
||||||
t.dropColumn("skipBootstrapCertValidation");
|
t.dropColumn("disableBootstrapCertValidation");
|
||||||
}
|
}
|
||||||
|
|
||||||
if (hasCaChainCol) {
|
if (hasCaChainCol) {
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ export const CertificateTemplateEstConfigsSchema = z.object({
|
|||||||
isEnabled: z.boolean(),
|
isEnabled: z.boolean(),
|
||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
updatedAt: z.date(),
|
updatedAt: z.date(),
|
||||||
skipBootstrapCertValidation: z.boolean().default(false)
|
disableBootstrapCertValidation: z.boolean().default(false)
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TCertificateTemplateEstConfigs = z.infer<typeof CertificateTemplateEstConfigsSchema>;
|
export type TCertificateTemplateEstConfigs = z.infer<typeof CertificateTemplateEstConfigsSchema>;
|
||||||
|
|||||||
@@ -171,7 +171,7 @@ export const certificateEstServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!estConfig.skipBootstrapCertValidation) {
|
if (!estConfig.disableBootstrapCertValidation) {
|
||||||
const caCerts = estConfig.caChain
|
const caCerts = estConfig.caChain
|
||||||
.match(/-----BEGIN CERTIFICATE-----[\s\S]+?-----END CERTIFICATE-----/g)
|
.match(/-----BEGIN CERTIFICATE-----[\s\S]+?-----END CERTIFICATE-----/g)
|
||||||
?.map((cert) => {
|
?.map((cert) => {
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ const sanitizedEstConfig = CertificateTemplateEstConfigsSchema.pick({
|
|||||||
id: true,
|
id: true,
|
||||||
certificateTemplateId: true,
|
certificateTemplateId: true,
|
||||||
isEnabled: true,
|
isEnabled: true,
|
||||||
skipBootstrapCertValidation: true
|
disableBootstrapCertValidation: true
|
||||||
});
|
});
|
||||||
|
|
||||||
export const registerCertificateTemplateRouter = async (server: FastifyZodProvider) => {
|
export const registerCertificateTemplateRouter = async (server: FastifyZodProvider) => {
|
||||||
@@ -247,11 +247,11 @@ export const registerCertificateTemplateRouter = async (server: FastifyZodProvid
|
|||||||
caChain: z.string().trim().optional(),
|
caChain: z.string().trim().optional(),
|
||||||
passphrase: z.string().min(1),
|
passphrase: z.string().min(1),
|
||||||
isEnabled: z.boolean().default(true),
|
isEnabled: z.boolean().default(true),
|
||||||
skipBootstrapCertValidation: z.boolean().default(false)
|
disableBootstrapCertValidation: z.boolean().default(false)
|
||||||
})
|
})
|
||||||
.refine(
|
.refine(
|
||||||
({ caChain, skipBootstrapCertValidation }) =>
|
({ caChain, disableBootstrapCertValidation }) =>
|
||||||
skipBootstrapCertValidation || (!skipBootstrapCertValidation && caChain),
|
disableBootstrapCertValidation || (!disableBootstrapCertValidation && caChain),
|
||||||
"CA chain is required"
|
"CA chain is required"
|
||||||
),
|
),
|
||||||
response: {
|
response: {
|
||||||
@@ -299,7 +299,7 @@ export const registerCertificateTemplateRouter = async (server: FastifyZodProvid
|
|||||||
body: z.object({
|
body: z.object({
|
||||||
caChain: z.string().trim().optional(),
|
caChain: z.string().trim().optional(),
|
||||||
passphrase: z.string().min(1).optional(),
|
passphrase: z.string().min(1).optional(),
|
||||||
skipBootstrapCertValidation: z.boolean().optional(),
|
disableBootstrapCertValidation: z.boolean().optional(),
|
||||||
isEnabled: z.boolean().optional()
|
isEnabled: z.boolean().optional()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
|
|||||||
@@ -236,7 +236,7 @@ export const certificateTemplateServiceFactory = ({
|
|||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actor,
|
actor,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
skipBootstrapCertValidation
|
disableBootstrapCertValidation
|
||||||
}: TCreateEstConfigurationDTO) => {
|
}: TCreateEstConfigurationDTO) => {
|
||||||
const plan = await licenseService.getPlan(actorOrgId);
|
const plan = await licenseService.getPlan(actorOrgId);
|
||||||
if (!plan.pkiEst) {
|
if (!plan.pkiEst) {
|
||||||
@@ -305,7 +305,7 @@ export const certificateTemplateServiceFactory = ({
|
|||||||
hashedPassphrase,
|
hashedPassphrase,
|
||||||
encryptedCaChain,
|
encryptedCaChain,
|
||||||
isEnabled,
|
isEnabled,
|
||||||
skipBootstrapCertValidation
|
disableBootstrapCertValidation
|
||||||
});
|
});
|
||||||
|
|
||||||
return { ...estConfig, projectId: certTemplate.projectId };
|
return { ...estConfig, projectId: certTemplate.projectId };
|
||||||
@@ -320,7 +320,7 @@ export const certificateTemplateServiceFactory = ({
|
|||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actor,
|
actor,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
skipBootstrapCertValidation
|
disableBootstrapCertValidation
|
||||||
}: TUpdateEstConfigurationDTO) => {
|
}: TUpdateEstConfigurationDTO) => {
|
||||||
const plan = await licenseService.getPlan(actorOrgId);
|
const plan = await licenseService.getPlan(actorOrgId);
|
||||||
if (!plan.pkiEst) {
|
if (!plan.pkiEst) {
|
||||||
@@ -369,7 +369,7 @@ export const certificateTemplateServiceFactory = ({
|
|||||||
|
|
||||||
const updatedData: TCertificateTemplateEstConfigsUpdate = {
|
const updatedData: TCertificateTemplateEstConfigsUpdate = {
|
||||||
isEnabled,
|
isEnabled,
|
||||||
skipBootstrapCertValidation
|
disableBootstrapCertValidation
|
||||||
};
|
};
|
||||||
|
|
||||||
if (caChain) {
|
if (caChain) {
|
||||||
@@ -468,7 +468,7 @@ export const certificateTemplateServiceFactory = ({
|
|||||||
hashedPassphrase: estConfig.hashedPassphrase,
|
hashedPassphrase: estConfig.hashedPassphrase,
|
||||||
projectId: certTemplate.projectId,
|
projectId: certTemplate.projectId,
|
||||||
orgId: certTemplate.orgId,
|
orgId: certTemplate.orgId,
|
||||||
skipBootstrapCertValidation: estConfig.skipBootstrapCertValidation
|
disableBootstrapCertValidation: estConfig.disableBootstrapCertValidation
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ export type TCreateEstConfigurationDTO = {
|
|||||||
caChain?: string;
|
caChain?: string;
|
||||||
passphrase: string;
|
passphrase: string;
|
||||||
isEnabled: boolean;
|
isEnabled: boolean;
|
||||||
skipBootstrapCertValidation: boolean;
|
disableBootstrapCertValidation: boolean;
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
export type TUpdateEstConfigurationDTO = {
|
export type TUpdateEstConfigurationDTO = {
|
||||||
@@ -45,7 +45,7 @@ export type TUpdateEstConfigurationDTO = {
|
|||||||
caChain?: string;
|
caChain?: string;
|
||||||
passphrase?: string;
|
passphrase?: string;
|
||||||
isEnabled?: boolean;
|
isEnabled?: boolean;
|
||||||
skipBootstrapCertValidation?: boolean;
|
disableBootstrapCertValidation?: boolean;
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
export type TGetEstConfigurationDTO =
|
export type TGetEstConfigurationDTO =
|
||||||
|
|||||||
@@ -35,6 +35,7 @@ These endpoints are exposed on port 8443 under the .well-known/est path e.g.
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
- **Disable Bootstrap Certificate Validation** - Enable this if your devices are not configured with a bootstrap certificate.
|
||||||
- **Certificate Authority Chain** - This is the certificate chain used to validate your devices' manufacturing/pre-installed certificates. This will be used to authenticate your devices with Infisical's EST server.
|
- **Certificate Authority Chain** - This is the certificate chain used to validate your devices' manufacturing/pre-installed certificates. This will be used to authenticate your devices with Infisical's EST server.
|
||||||
- **Passphrase** - This is also used to authenticate your devices with Infisical's EST server. When configuring the clients, use the value defined here as the EST password.
|
- **Passphrase** - This is also used to authenticate your devices with Infisical's EST server. When configuring the clients, use the value defined here as the EST password.
|
||||||
|
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 612 KiB After Width: | Height: | Size: 507 KiB |
@@ -49,7 +49,7 @@ export type TCreateEstConfigDTO = {
|
|||||||
caChain?: string;
|
caChain?: string;
|
||||||
passphrase: string;
|
passphrase: string;
|
||||||
isEnabled: boolean;
|
isEnabled: boolean;
|
||||||
skipBootstrapCertValidation: boolean;
|
disableBootstrapCertValidation: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TUpdateEstConfigDTO = {
|
export type TUpdateEstConfigDTO = {
|
||||||
@@ -57,7 +57,7 @@ export type TUpdateEstConfigDTO = {
|
|||||||
caChain?: string;
|
caChain?: string;
|
||||||
passphrase?: string;
|
passphrase?: string;
|
||||||
isEnabled?: boolean;
|
isEnabled?: boolean;
|
||||||
skipBootstrapCertValidation?: boolean;
|
disableBootstrapCertValidation?: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TEstConfig = {
|
export type TEstConfig = {
|
||||||
@@ -65,5 +65,5 @@ export type TEstConfig = {
|
|||||||
certificateTemplateId: string;
|
certificateTemplateId: string;
|
||||||
caChain: string;
|
caChain: string;
|
||||||
isEnabled: boolean;
|
isEnabled: boolean;
|
||||||
skipBootstrapCertValidation: boolean;
|
disableBootstrapCertValidation: boolean;
|
||||||
};
|
};
|
||||||
|
|||||||
+14
-14
@@ -36,7 +36,7 @@ const schema = z.object({
|
|||||||
caChain: z.string().optional(),
|
caChain: z.string().optional(),
|
||||||
passphrase: z.string().optional(),
|
passphrase: z.string().optional(),
|
||||||
isEnabled: z.boolean(),
|
isEnabled: z.boolean(),
|
||||||
skipBootstrapCertValidation: z.boolean().optional().default(false)
|
disableBootstrapCertValidation: z.boolean().optional().default(false)
|
||||||
});
|
});
|
||||||
|
|
||||||
export type FormData = z.infer<typeof schema>;
|
export type FormData = z.infer<typeof schema>;
|
||||||
@@ -65,26 +65,26 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
|
|||||||
const { mutateAsync: updateEstConfig } = useUpdateEstConfig();
|
const { mutateAsync: updateEstConfig } = useUpdateEstConfig();
|
||||||
const [isPassphraseFocused, setIsPassphraseFocused] = useToggle(false);
|
const [isPassphraseFocused, setIsPassphraseFocused] = useToggle(false);
|
||||||
|
|
||||||
const skipBootstrapCertValidation = watch("skipBootstrapCertValidation");
|
const disableBootstrapCertValidation = watch("disableBootstrapCertValidation");
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (skipBootstrapCertValidation) {
|
if (disableBootstrapCertValidation) {
|
||||||
setValue("caChain", "");
|
setValue("caChain", "");
|
||||||
}
|
}
|
||||||
}, [skipBootstrapCertValidation]);
|
}, [disableBootstrapCertValidation]);
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (data) {
|
if (data) {
|
||||||
reset({
|
reset({
|
||||||
caChain: data.caChain,
|
caChain: data.caChain,
|
||||||
isEnabled: data.isEnabled,
|
isEnabled: data.isEnabled,
|
||||||
skipBootstrapCertValidation: data.skipBootstrapCertValidation
|
disableBootstrapCertValidation: data.disableBootstrapCertValidation
|
||||||
});
|
});
|
||||||
} else {
|
} else {
|
||||||
reset({
|
reset({
|
||||||
caChain: "",
|
caChain: "",
|
||||||
isEnabled: false,
|
isEnabled: false,
|
||||||
skipBootstrapCertValidation: false
|
disableBootstrapCertValidation: false
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}, [data]);
|
}, [data]);
|
||||||
@@ -97,7 +97,7 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
|
|||||||
caChain,
|
caChain,
|
||||||
passphrase,
|
passphrase,
|
||||||
isEnabled,
|
isEnabled,
|
||||||
skipBootstrapCertValidation
|
disableBootstrapCertValidation
|
||||||
});
|
});
|
||||||
} else {
|
} else {
|
||||||
if (!passphrase) {
|
if (!passphrase) {
|
||||||
@@ -110,7 +110,7 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
|
|||||||
caChain,
|
caChain,
|
||||||
passphrase,
|
passphrase,
|
||||||
isEnabled,
|
isEnabled,
|
||||||
skipBootstrapCertValidation
|
disableBootstrapCertValidation
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -167,7 +167,7 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
|
|||||||
)}
|
)}
|
||||||
<Controller
|
<Controller
|
||||||
control={control}
|
control={control}
|
||||||
name="skipBootstrapCertValidation"
|
name="disableBootstrapCertValidation"
|
||||||
render={({ field, fieldState: { error } }) => {
|
render={({ field, fieldState: { error } }) => {
|
||||||
return (
|
return (
|
||||||
<FormControl isError={Boolean(error)} errorText={error?.message}>
|
<FormControl isError={Boolean(error)} errorText={error?.message}>
|
||||||
@@ -176,27 +176,27 @@ export const CertificateTemplateEnrollmentModal = ({ popUp, handlePopUpToggle }:
|
|||||||
onCheckedChange={(value) => field.onChange(value)}
|
onCheckedChange={(value) => field.onChange(value)}
|
||||||
isChecked={field.value}
|
isChecked={field.value}
|
||||||
>
|
>
|
||||||
<p className="ml-1 w-full">Skip Bootstrap Certificate Validation</p>
|
<p className="ml-1 w-full">Disable Bootstrap Certificate Validation</p>
|
||||||
</Switch>
|
</Switch>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
);
|
);
|
||||||
}}
|
}}
|
||||||
/>
|
/>
|
||||||
{!skipBootstrapCertValidation && (
|
{!disableBootstrapCertValidation && (
|
||||||
<Controller
|
<Controller
|
||||||
control={control}
|
control={control}
|
||||||
name="caChain"
|
name="caChain"
|
||||||
disabled={skipBootstrapCertValidation}
|
disabled={disableBootstrapCertValidation}
|
||||||
render={({ field, fieldState: { error } }) => (
|
render={({ field, fieldState: { error } }) => (
|
||||||
<FormControl
|
<FormControl
|
||||||
label="Certificate Authority Chain"
|
label="Certificate Authority Chain"
|
||||||
isError={Boolean(error)}
|
isError={Boolean(error)}
|
||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
isRequired={!skipBootstrapCertValidation}
|
isRequired={!disableBootstrapCertValidation}
|
||||||
>
|
>
|
||||||
<TextArea
|
<TextArea
|
||||||
{...field}
|
{...field}
|
||||||
isDisabled={skipBootstrapCertValidation}
|
isDisabled={disableBootstrapCertValidation}
|
||||||
className="min-h-[15rem] border-none bg-mineshaft-900 text-gray-400"
|
className="min-h-[15rem] border-none bg-mineshaft-900 text-gray-400"
|
||||||
reSize="none"
|
reSize="none"
|
||||||
/>
|
/>
|
||||||
|
|||||||
Reference in New Issue
Block a user