diff --git a/backend/src/ee/routes/v1/pki-acme-router.ts b/backend/src/ee/routes/v1/pki-acme-router.ts index 0cb39657d..4794a125a 100644 --- a/backend/src/ee/routes/v1/pki-acme-router.ts +++ b/backend/src/ee/routes/v1/pki-acme-router.ts @@ -371,11 +371,7 @@ export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => { return sendAcmeResponse( res, profileId, - await server.services.pkiAcme.downloadAcmeCertificate({ - profileId, - accountId, - orderId: req.params.orderId - }) + await server.services.pkiAcme.downloadAcmeCertificate({ profileId, accountId, orderId: req.params.orderId }) ); } }); diff --git a/backend/src/ee/services/pki-acme/pki-acme-order-dal.ts b/backend/src/ee/services/pki-acme/pki-acme-order-dal.ts index 2c7ea6aee..78a46b665 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-order-dal.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-order-dal.ts @@ -51,7 +51,7 @@ export const pkiAcmeOrderDALFactory = (db: TDbClient) => { } }; - const findByIdWithAuthorizations = async (id: string, tx?: Knex) => { + const findByAccountAndOrderIdWithAuthorizations = async (accountId: string, orderId: string, tx?: Knex) => { try { const order = await (tx || db)(TableName.PkiAcmeOrder) .join(TableName.PkiAcmeOrderAuth, `${TableName.PkiAcmeOrderAuth}.orderId`, `${TableName.PkiAcmeOrder}.id`) @@ -63,7 +63,8 @@ export const pkiAcmeOrderDALFactory = (db: TDbClient) => { db.ref("identifierValue").withSchema(TableName.PkiAcmeAuth).as("identifierValue"), db.ref("expiresAt").withSchema(TableName.PkiAcmeAuth).as("expiresAt") ) - .where(`${TableName.PkiAcmeOrder}.id`, id) + .where(`${TableName.PkiAcmeOrder}.id`, orderId) + .where(`${TableName.PkiAcmeOrder}.accountId`, accountId) .first(); if (!order) { @@ -88,6 +89,6 @@ export const pkiAcmeOrderDALFactory = (db: TDbClient) => { create, updateById, findById, - findByIdWithAuthorizations + findByAccountAndOrderIdWithAuthorizations }; }; diff --git a/backend/src/ee/services/pki-acme/pki-acme-service.ts b/backend/src/ee/services/pki-acme/pki-acme-service.ts index 49dfb72ef..c68bb3895 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-service.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-service.ts @@ -53,7 +53,7 @@ import { type TPkiAcmeServiceFactoryDep = { certificateProfileDAL: Pick; acmeAccountDAL: Pick; - acmeOrderDAL: Pick; + acmeOrderDAL: Pick; acmeAuthDAL: Pick; acmeOrderAuthDAL: Pick; }; @@ -396,8 +396,8 @@ export const pkiAcmeServiceFactory = ({ accountId: string; orderId: string; }): Promise> => { - const order = await acmeOrderDAL.findByIdWithAuthorizations(orderId); - if (!order || order.accountId !== accountId) { + const order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId); + if (!order) { throw new NotFoundError({ message: "ACME order not found" }); } return { @@ -418,25 +418,45 @@ export const pkiAcmeServiceFactory = ({ orderId: string; payload: TFinalizeAcmeOrderPayload; }): Promise> => { - const profile = await validateAcmeProfile(profileId); + const order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId); + if (!order) { + throw new NotFoundError({ message: "ACME order not found" }); + } const { csr } = payload; // FIXME: Implement ACME finalize order return { status: 200, - body: { - status: "processing", - expires: new Date(Date.now() + 24 * 60 * 60 * 1000).toISOString(), - identifiers: [], - authorizations: [], - finalize: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/orders/${orderId}/finalize`), - certificate: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/orders/${orderId}/certificate`) - }, + body: buildAcmeOrderResource({ profileId, order }), headers: { Location: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/orders/${orderId}`) } }; }; + const downloadAcmeCertificate = async ({ + profileId, + accountId, + orderId + }: { + profileId: string; + accountId: string; + orderId: string; + }): Promise> => { + const order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId); + if (!order) { + throw new NotFoundError({ message: "ACME order not found" }); + } + // FIXME: Implement ACME certificate download + // Return the certificate in PEM format + return { + status: 200, + body: "FIXME-certificate-pem", + headers: { + Location: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/orders/${orderId}/certificate`) + } + }; + }; + const listAcmeOrders = async ({ profileId, accountId @@ -457,25 +477,6 @@ export const pkiAcmeServiceFactory = ({ }; }; - const downloadAcmeCertificate = async ({ - profileId, - orderId - }: { - profileId: string; - orderId: string; - }): Promise> => { - const profile = await validateAcmeProfile(profileId); - // FIXME: Implement ACME certificate download - // Return the certificate in PEM format - return { - status: 200, - body: "FIXME-certificate-pem", - headers: { - Location: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/orders/${orderId}/certificate`) - } - }; - }; - /** -------------------------------------------------------------- * ACME Authorization * -------------------------------------------------------------- */ diff --git a/backend/src/ee/services/pki-acme/pki-acme-types.ts b/backend/src/ee/services/pki-acme/pki-acme-types.ts index 672300f18..8fded06d4 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-types.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-types.ts @@ -123,13 +123,6 @@ export type TPkiAcmeServiceFactory = { orderId: string; payload: TFinalizeAcmeOrderPayload; }) => Promise>; - listAcmeOrders: ({ - profileId, - accountId - }: { - profileId: string; - accountId: string; - }) => Promise>; downloadAcmeCertificate: ({ profileId, accountId, @@ -139,6 +132,13 @@ export type TPkiAcmeServiceFactory = { accountId: string; orderId: string; }) => Promise>; + listAcmeOrders: ({ + profileId, + accountId + }: { + profileId: string; + accountId: string; + }) => Promise>; getAcmeAuthorization: ({ profileId, accountId,