mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 02:27:37 +00:00
Merge pull request #3618 from Infisical/fix-bundle-for-old-certs
This commit is contained in:
@@ -131,8 +131,8 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
|
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
|
||||||
certificateChain: z.string().trim().nullish().describe(CERTIFICATES.GET_CERT.certificateChain),
|
certificateChain: z.string().trim().nullable().describe(CERTIFICATES.GET_CERT.certificateChain),
|
||||||
privateKey: z.string().trim().describe(CERTIFICATES.GET_CERT.privateKey),
|
privateKey: z.string().trim().nullable().describe(CERTIFICATES.GET_CERT.privateKey),
|
||||||
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
|
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -518,7 +518,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
|
certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
|
||||||
certificateChain: z.string().trim().nullish().describe(CERTIFICATES.GET_CERT.certificateChain),
|
certificateChain: z.string().trim().nullable().describe(CERTIFICATES.GET_CERT.certificateChain),
|
||||||
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
|
serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -105,7 +105,7 @@ export const buildCertificateChain = async ({
|
|||||||
kmsService,
|
kmsService,
|
||||||
kmsId
|
kmsId
|
||||||
}: TBuildCertificateChainDTO) => {
|
}: TBuildCertificateChainDTO) => {
|
||||||
if (!encryptedCertificateChain && (!caCert || !caCertChain)) {
|
if (!encryptedCertificateChain && !caCert) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -29,6 +29,7 @@ import {
|
|||||||
TGetCertPrivateKeyDTO,
|
TGetCertPrivateKeyDTO,
|
||||||
TRevokeCertDTO
|
TRevokeCertDTO
|
||||||
} from "./certificate-types";
|
} from "./certificate-types";
|
||||||
|
import { NotFoundError } from "@app/lib/errors";
|
||||||
|
|
||||||
type TCertificateServiceFactoryDep = {
|
type TCertificateServiceFactoryDep = {
|
||||||
certificateDAL: Pick<TCertificateDALFactory, "findOne" | "deleteById" | "update" | "find">;
|
certificateDAL: Pick<TCertificateDALFactory, "findOne" | "deleteById" | "update" | "find">;
|
||||||
@@ -337,18 +338,27 @@ export const certificateServiceFactory = ({
|
|||||||
encryptedCertificateChain: certBody.encryptedCertificateChain || undefined
|
encryptedCertificateChain: certBody.encryptedCertificateChain || undefined
|
||||||
});
|
});
|
||||||
|
|
||||||
const { certPrivateKey } = await getCertificateCredentials({
|
let privateKey: string | null = null;
|
||||||
certId: cert.id,
|
try {
|
||||||
projectId: ca.projectId,
|
const { certPrivateKey } = await getCertificateCredentials({
|
||||||
certificateSecretDAL,
|
certId: cert.id,
|
||||||
projectDAL,
|
projectId: ca.projectId,
|
||||||
kmsService
|
certificateSecretDAL,
|
||||||
});
|
projectDAL,
|
||||||
|
kmsService
|
||||||
|
});
|
||||||
|
privateKey = certPrivateKey;
|
||||||
|
} catch (e) {
|
||||||
|
// Skip NotFound errors but throw all others
|
||||||
|
if (!(e instanceof NotFoundError)) {
|
||||||
|
throw e;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
certificate,
|
certificate,
|
||||||
certificateChain,
|
certificateChain,
|
||||||
privateKey: certPrivateKey,
|
privateKey,
|
||||||
serialNumber,
|
serialNumber,
|
||||||
cert,
|
cert,
|
||||||
ca
|
ca
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ export const useGetCertBundle = (serialNumber: string) => {
|
|||||||
certificate: string;
|
certificate: string;
|
||||||
certificateChain: string;
|
certificateChain: string;
|
||||||
serialNumber: string;
|
serialNumber: string;
|
||||||
privateKey: string;
|
privateKey: string | null;
|
||||||
}>(`/api/v1/pki/certificates/${serialNumber}/bundle`);
|
}>(`/api/v1/pki/certificates/${serialNumber}/bundle`);
|
||||||
return data;
|
return data;
|
||||||
},
|
},
|
||||||
|
|||||||
+2
-2
@@ -35,7 +35,7 @@ export const CertificateCertModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
certificate: string;
|
certificate: string;
|
||||||
certificateChain: string;
|
certificateChain: string;
|
||||||
serialNumber: string;
|
serialNumber: string;
|
||||||
privateKey?: string;
|
privateKey?: string | null;
|
||||||
}
|
}
|
||||||
| undefined = canReadPrivateKey ? bundleData : bodyData;
|
| undefined = canReadPrivateKey ? bundleData : bodyData;
|
||||||
|
|
||||||
@@ -52,7 +52,7 @@ export const CertificateCertModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
serialNumber={data.serialNumber}
|
serialNumber={data.serialNumber}
|
||||||
certificate={data.certificate}
|
certificate={data.certificate}
|
||||||
certificateChain={data.certificateChain}
|
certificateChain={data.certificateChain}
|
||||||
privateKey={data.privateKey}
|
privateKey={data.privateKey || undefined}
|
||||||
/>
|
/>
|
||||||
) : (
|
) : (
|
||||||
<div />
|
<div />
|
||||||
|
|||||||
+2
-2
@@ -1,10 +1,10 @@
|
|||||||
import { useEffect, useState } from "react";
|
import { useEffect, useState } from "react";
|
||||||
|
import axios from "axios";
|
||||||
|
|
||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { Switch } from "@app/components/v2";
|
import { Switch } from "@app/components/v2";
|
||||||
import { useOrganization } from "@app/context";
|
import { useOrganization } from "@app/context";
|
||||||
import { useUpdateOrg } from "@app/hooks/api";
|
import { useUpdateOrg } from "@app/hooks/api";
|
||||||
import axios from "axios";
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
|
||||||
|
|
||||||
export const OrgProductSelectSection = () => {
|
export const OrgProductSelectSection = () => {
|
||||||
const [toggledProducts, setToggledProducts] = useState<{
|
const [toggledProducts, setToggledProducts] = useState<{
|
||||||
|
|||||||
+1
-1
@@ -4,13 +4,13 @@ import { ProjectType, ProjectVersion } from "@app/hooks/api/workspace/types";
|
|||||||
|
|
||||||
import { AuditLogsRetentionSection } from "../AuditLogsRetentionSection";
|
import { AuditLogsRetentionSection } from "../AuditLogsRetentionSection";
|
||||||
import { AutoCapitalizationSection } from "../AutoCapitalizationSection";
|
import { AutoCapitalizationSection } from "../AutoCapitalizationSection";
|
||||||
import { SecretSharingSection } from "../SecretSharingSection";
|
|
||||||
import { BackfillSecretReferenceSecretion } from "../BackfillSecretReferenceSection";
|
import { BackfillSecretReferenceSecretion } from "../BackfillSecretReferenceSection";
|
||||||
import { DeleteProjectProtection } from "../DeleteProjectProtection";
|
import { DeleteProjectProtection } from "../DeleteProjectProtection";
|
||||||
import { DeleteProjectSection } from "../DeleteProjectSection";
|
import { DeleteProjectSection } from "../DeleteProjectSection";
|
||||||
import { EnvironmentSection } from "../EnvironmentSection";
|
import { EnvironmentSection } from "../EnvironmentSection";
|
||||||
import { PointInTimeVersionLimitSection } from "../PointInTimeVersionLimitSection";
|
import { PointInTimeVersionLimitSection } from "../PointInTimeVersionLimitSection";
|
||||||
import { RebuildSecretIndicesSection } from "../RebuildSecretIndicesSection/RebuildSecretIndicesSection";
|
import { RebuildSecretIndicesSection } from "../RebuildSecretIndicesSection/RebuildSecretIndicesSection";
|
||||||
|
import { SecretSharingSection } from "../SecretSharingSection";
|
||||||
import { SecretTagsSection } from "../SecretTagsSection";
|
import { SecretTagsSection } from "../SecretTagsSection";
|
||||||
|
|
||||||
export const ProjectGeneralTab = () => {
|
export const ProjectGeneralTab = () => {
|
||||||
|
|||||||
+2
-1
@@ -1,9 +1,10 @@
|
|||||||
|
import { useState } from "react";
|
||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { ProjectPermissionCan } from "@app/components/permissions";
|
import { ProjectPermissionCan } from "@app/components/permissions";
|
||||||
import { Checkbox } from "@app/components/v2";
|
import { Checkbox } from "@app/components/v2";
|
||||||
import { ProjectPermissionActions, ProjectPermissionSub, useWorkspace } from "@app/context";
|
import { ProjectPermissionActions, ProjectPermissionSub, useWorkspace } from "@app/context";
|
||||||
import { useUpdateProject } from "@app/hooks/api/workspace/queries";
|
import { useUpdateProject } from "@app/hooks/api/workspace/queries";
|
||||||
import { useState } from "react";
|
|
||||||
|
|
||||||
export const SecretSharingSection = () => {
|
export const SecretSharingSection = () => {
|
||||||
const { currentWorkspace } = useWorkspace();
|
const { currentWorkspace } = useWorkspace();
|
||||||
|
|||||||
Reference in New Issue
Block a user