mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 09:26:47 +00:00
misc: addressed comments
This commit is contained in:
@@ -1,6 +1,7 @@
|
|||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||||
import { writeLimit } from "@app/server/config/rateLimiter";
|
import { writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
@@ -38,8 +39,14 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
|||||||
onRequest: (req, _, next) => {
|
onRequest: (req, _, next) => {
|
||||||
const authHeader = req.headers.authorization;
|
const authHeader = req.headers.authorization;
|
||||||
|
|
||||||
if (appCfg.PROXY_AUTH_SECRET && authHeader === `Bearer ${appCfg.PROXY_AUTH_SECRET}`) {
|
if (appCfg.PROXY_AUTH_SECRET && authHeader) {
|
||||||
return next();
|
const expectedHeader = `Bearer ${appCfg.PROXY_AUTH_SECRET}`;
|
||||||
|
if (
|
||||||
|
authHeader.length === expectedHeader.length &&
|
||||||
|
crypto.nativeCrypto.timingSafeEqual(Buffer.from(authHeader), Buffer.from(expectedHeader))
|
||||||
|
) {
|
||||||
|
return next();
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
throw new UnauthorizedError({
|
throw new UnauthorizedError({
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import z from "zod";
|
import z from "zod";
|
||||||
|
|
||||||
import { GatewaysV2Schema } from "@app/db/schemas";
|
import { GatewaysV2Schema } from "@app/db/schemas";
|
||||||
import { writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
@@ -40,6 +40,9 @@ export const registerGatewayV2Router = async (server: FastifyZodProvider) => {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
config: {
|
||||||
|
rateLimit: writeLimit
|
||||||
|
},
|
||||||
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const gateway = await server.services.gatewayV2.registerGateway({
|
const gateway = await server.services.gatewayV2.registerGateway({
|
||||||
@@ -90,6 +93,9 @@ export const registerGatewayV2Router = async (server: FastifyZodProvider) => {
|
|||||||
}).array()
|
}).array()
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const gateways = await server.services.gatewayV2.listGateways({
|
const gateways = await server.services.gatewayV2.listGateways({
|
||||||
|
|||||||
@@ -421,7 +421,8 @@ const cryptographyFactory = () => {
|
|||||||
constants: crypto.constants,
|
constants: crypto.constants,
|
||||||
X509Certificate: crypto.X509Certificate,
|
X509Certificate: crypto.X509Certificate,
|
||||||
KeyObject: crypto.KeyObject,
|
KeyObject: crypto.KeyObject,
|
||||||
Hash: crypto.Hash
|
Hash: crypto.Hash,
|
||||||
|
timingSafeEqual: crypto.timingSafeEqual
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user