mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
Refine eab payload checking logic
This commit is contained in:
@@ -353,11 +353,19 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
kmsId: certificateManagerKmsId
|
kmsId: certificateManagerKmsId
|
||||||
});
|
});
|
||||||
const eabSecret = await kmsDecryptor({ cipherTextBlob: profile.acmeConfig!.encryptedEabSecret! });
|
const eabSecret = await kmsDecryptor({ cipherTextBlob: profile.acmeConfig!.encryptedEabSecret! });
|
||||||
|
let eabPayload: Uint8Array<ArrayBufferLike> | undefined;
|
||||||
|
let eabProtectedHeader: JWSHeaderParameters | undefined;
|
||||||
try {
|
try {
|
||||||
const { payload: eabPayload, protectedHeader: eabProtectedHeader } = await flattenedVerify(
|
const result = await flattenedVerify(externalAccountBinding, eabSecret);
|
||||||
externalAccountBinding,
|
eabPayload = result.payload;
|
||||||
eabSecret
|
eabProtectedHeader = result.protectedHeader;
|
||||||
);
|
} catch (error) {
|
||||||
|
if (error instanceof errors.JWSInvalid) {
|
||||||
|
throw new AcmeMalformedError({ detail: "Invalid external account binding JWS payload" });
|
||||||
|
}
|
||||||
|
logger.error(error, "Unexpected error while verifying EAB JWS payload");
|
||||||
|
throw new AcmeServerInternalError({ detail: "Failed to verify EAB JWS payload" });
|
||||||
|
}
|
||||||
const { alg: eabAlg, kid: eabKid } = eabProtectedHeader!;
|
const { alg: eabAlg, kid: eabKid } = eabProtectedHeader!;
|
||||||
if (!["HS256", "HS384", "HS512"].includes(eabAlg!)) {
|
if (!["HS256", "HS384", "HS512"].includes(eabAlg!)) {
|
||||||
throw new AcmeMalformedError({ detail: "Invalid algorithm for external account binding JWS payload" });
|
throw new AcmeMalformedError({ detail: "Invalid algorithm for external account binding JWS payload" });
|
||||||
@@ -383,16 +391,6 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
message: "External account binding public key thumbprint or algorithm mismatch"
|
message: "External account binding public key thumbprint or algorithm mismatch"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
} catch (error) {
|
|
||||||
if (error instanceof errors.JWSInvalid) {
|
|
||||||
throw new AcmeMalformedError({ detail: "Invalid external account binding JWS payload" });
|
|
||||||
}
|
|
||||||
if (error instanceof AcmeError) {
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
logger.error(error, "Unexpected error while verifying EAB JWS payload");
|
|
||||||
throw new AcmeServerInternalError({ detail: "Failed to verify EAB JWS payload" });
|
|
||||||
}
|
|
||||||
|
|
||||||
const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByProfileIdAndPublicKeyThumbprintAndAlg(
|
const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByProfileIdAndPublicKeyThumbprintAndAlg(
|
||||||
profileId,
|
profileId,
|
||||||
|
|||||||
Reference in New Issue
Block a user