update delete client secret to revoke client secret

This commit is contained in:
Maidul Islam
2023-12-06 18:16:14 -05:00
parent ec5cf97f18
commit 0fb2056b8b
3 changed files with 32 additions and 31 deletions
@@ -101,7 +101,8 @@ export const getMIClientSecrets = async (req: Request, res: Response) => {
const clientSecretData = await MachineIdentityClientSecret
.find({
machineIdentity: machineMembershipOrg.machineIdentity
machineIdentity: machineMembershipOrg.machineIdentity,
isClientSecretRevoked: false
})
.sort({ createdAt: -1 })
.limit(5);
@@ -209,7 +210,7 @@ export const createMIClientSecret = async (req: Request, res: Response) => {
* @param req
* @param res
*/
export const deleteMIClientSecret = async (req: Request, res: Response) => {
export const revokeMIClientSecret = async (req: Request, res: Response) => {
const {
params: {
machineId,
@@ -458,24 +459,24 @@ export const renewAccessToken = async (req: Request, res: Response) => {
} = await validateRequest(reqValidator.RenewAccessTokenV1, req);
const decodedToken = <jwt.MachineAccessTokenJwtPayload>(
jwt.verify(accessToken, await getAuthSecret())
);
jwt.verify(accessToken, await getAuthSecret())
);
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError();
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError();
const machineIdentityAccessToken = await IdentityAccessToken.findOne({
const machineIdentityAccessToken = await IdentityAccessToken.findOne({
_id: decodedToken.identityAccessTokenId,
isAccessTokenRevoked: false
});
if (!machineIdentityAccessToken) throw UnauthorizedRequestError();
if (!machineIdentityAccessToken) throw UnauthorizedRequestError();
const {
accessTokenTTL,
accessTokenLastRenewedAt,
accessTokenMaxTTL,
createdAt: accessTokenCreatedAt
} = machineIdentityAccessToken;
accessTokenTTL,
accessTokenLastRenewedAt,
accessTokenMaxTTL,
createdAt: accessTokenCreatedAt
} = machineIdentityAccessToken;
if (accessTokenTTL === accessTokenMaxTTL) throw UnauthorizedRequestError({
message: "Failed to renew non-renewable access token"
@@ -503,7 +504,7 @@ export const renewAccessToken = async (req: Request, res: Response) => {
message: "Failed to renew MI access token due to TTL expiration"
});
}
}
}
// max ttl checks
if (accessTokenMaxTTL > 0) {
@@ -513,8 +514,8 @@ export const renewAccessToken = async (req: Request, res: Response) => {
const expirationDate = new Date(accessTokenCreated.getTime() + ttlInMilliseconds);
if (currentDate > expirationDate) throw UnauthorizedRequestError({
message: "Failed to renew MI access token due to Max TTL expiration"
});
message: "Failed to renew MI access token due to Max TTL expiration"
});
const extendToDate = new Date(currentDate.getTime() + accessTokenTTL);
if (extendToDate > expirationDate) throw UnauthorizedRequestError({
@@ -20,12 +20,12 @@ router.post(
machineIdentitiesController.createMIClientSecret
);
router.delete(
"/:machineId/client-secrets/:clientSecretId",
router.post(
"/:machineId/client-secrets/:clientSecretId/revoke",
requireAuth({
acceptedAuthModes: [AuthMode.JWT]
}),
machineIdentitiesController.deleteMIClientSecret
machineIdentitiesController.revokeMIClientSecret
);
router.post(
@@ -62,7 +62,7 @@ export const useDeleteMachineIdentityClientSecret = () => {
machineId:string;
clientSecretId: string;
}) => {
const { data } = await apiRequest.delete(`/api/v1/machine-identities/${machineId}/client-secrets/${clientSecretId}`);
const { data } = await apiRequest.post(`/api/v1/machine-identities/${machineId}/client-secrets/${clientSecretId}/revoke`);
return data;
},
onSuccess: (_, { machineId }) => {