mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 08:27:36 +00:00
update delete client secret to revoke client secret
This commit is contained in:
@@ -101,7 +101,8 @@ export const getMIClientSecrets = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const clientSecretData = await MachineIdentityClientSecret
|
const clientSecretData = await MachineIdentityClientSecret
|
||||||
.find({
|
.find({
|
||||||
machineIdentity: machineMembershipOrg.machineIdentity
|
machineIdentity: machineMembershipOrg.machineIdentity,
|
||||||
|
isClientSecretRevoked: false
|
||||||
})
|
})
|
||||||
.sort({ createdAt: -1 })
|
.sort({ createdAt: -1 })
|
||||||
.limit(5);
|
.limit(5);
|
||||||
@@ -209,7 +210,7 @@ export const createMIClientSecret = async (req: Request, res: Response) => {
|
|||||||
* @param req
|
* @param req
|
||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
export const deleteMIClientSecret = async (req: Request, res: Response) => {
|
export const revokeMIClientSecret = async (req: Request, res: Response) => {
|
||||||
const {
|
const {
|
||||||
params: {
|
params: {
|
||||||
machineId,
|
machineId,
|
||||||
@@ -458,24 +459,24 @@ export const renewAccessToken = async (req: Request, res: Response) => {
|
|||||||
} = await validateRequest(reqValidator.RenewAccessTokenV1, req);
|
} = await validateRequest(reqValidator.RenewAccessTokenV1, req);
|
||||||
|
|
||||||
const decodedToken = <jwt.MachineAccessTokenJwtPayload>(
|
const decodedToken = <jwt.MachineAccessTokenJwtPayload>(
|
||||||
jwt.verify(accessToken, await getAuthSecret())
|
jwt.verify(accessToken, await getAuthSecret())
|
||||||
);
|
);
|
||||||
|
|
||||||
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError();
|
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError();
|
||||||
|
|
||||||
const machineIdentityAccessToken = await IdentityAccessToken.findOne({
|
const machineIdentityAccessToken = await IdentityAccessToken.findOne({
|
||||||
_id: decodedToken.identityAccessTokenId,
|
_id: decodedToken.identityAccessTokenId,
|
||||||
isAccessTokenRevoked: false
|
isAccessTokenRevoked: false
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!machineIdentityAccessToken) throw UnauthorizedRequestError();
|
if (!machineIdentityAccessToken) throw UnauthorizedRequestError();
|
||||||
|
|
||||||
const {
|
const {
|
||||||
accessTokenTTL,
|
accessTokenTTL,
|
||||||
accessTokenLastRenewedAt,
|
accessTokenLastRenewedAt,
|
||||||
accessTokenMaxTTL,
|
accessTokenMaxTTL,
|
||||||
createdAt: accessTokenCreatedAt
|
createdAt: accessTokenCreatedAt
|
||||||
} = machineIdentityAccessToken;
|
} = machineIdentityAccessToken;
|
||||||
|
|
||||||
if (accessTokenTTL === accessTokenMaxTTL) throw UnauthorizedRequestError({
|
if (accessTokenTTL === accessTokenMaxTTL) throw UnauthorizedRequestError({
|
||||||
message: "Failed to renew non-renewable access token"
|
message: "Failed to renew non-renewable access token"
|
||||||
@@ -503,7 +504,7 @@ export const renewAccessToken = async (req: Request, res: Response) => {
|
|||||||
message: "Failed to renew MI access token due to TTL expiration"
|
message: "Failed to renew MI access token due to TTL expiration"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// max ttl checks
|
// max ttl checks
|
||||||
if (accessTokenMaxTTL > 0) {
|
if (accessTokenMaxTTL > 0) {
|
||||||
@@ -513,8 +514,8 @@ export const renewAccessToken = async (req: Request, res: Response) => {
|
|||||||
const expirationDate = new Date(accessTokenCreated.getTime() + ttlInMilliseconds);
|
const expirationDate = new Date(accessTokenCreated.getTime() + ttlInMilliseconds);
|
||||||
|
|
||||||
if (currentDate > expirationDate) throw UnauthorizedRequestError({
|
if (currentDate > expirationDate) throw UnauthorizedRequestError({
|
||||||
message: "Failed to renew MI access token due to Max TTL expiration"
|
message: "Failed to renew MI access token due to Max TTL expiration"
|
||||||
});
|
});
|
||||||
|
|
||||||
const extendToDate = new Date(currentDate.getTime() + accessTokenTTL);
|
const extendToDate = new Date(currentDate.getTime() + accessTokenTTL);
|
||||||
if (extendToDate > expirationDate) throw UnauthorizedRequestError({
|
if (extendToDate > expirationDate) throw UnauthorizedRequestError({
|
||||||
|
|||||||
@@ -20,12 +20,12 @@ router.post(
|
|||||||
machineIdentitiesController.createMIClientSecret
|
machineIdentitiesController.createMIClientSecret
|
||||||
);
|
);
|
||||||
|
|
||||||
router.delete(
|
router.post(
|
||||||
"/:machineId/client-secrets/:clientSecretId",
|
"/:machineId/client-secrets/:clientSecretId/revoke",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT]
|
acceptedAuthModes: [AuthMode.JWT]
|
||||||
}),
|
}),
|
||||||
machineIdentitiesController.deleteMIClientSecret
|
machineIdentitiesController.revokeMIClientSecret
|
||||||
);
|
);
|
||||||
|
|
||||||
router.post(
|
router.post(
|
||||||
|
|||||||
@@ -62,7 +62,7 @@ export const useDeleteMachineIdentityClientSecret = () => {
|
|||||||
machineId:string;
|
machineId:string;
|
||||||
clientSecretId: string;
|
clientSecretId: string;
|
||||||
}) => {
|
}) => {
|
||||||
const { data } = await apiRequest.delete(`/api/v1/machine-identities/${machineId}/client-secrets/${clientSecretId}`);
|
const { data } = await apiRequest.post(`/api/v1/machine-identities/${machineId}/client-secrets/${clientSecretId}/revoke`);
|
||||||
return data;
|
return data;
|
||||||
},
|
},
|
||||||
onSuccess: (_, { machineId }) => {
|
onSuccess: (_, { machineId }) => {
|
||||||
|
|||||||
Reference in New Issue
Block a user