mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 16:27:40 +00:00
Improve external configs schema
This commit is contained in:
@@ -8,6 +8,7 @@ import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
|||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
import { CertStatus } from "@app/services/certificate/certificate-types";
|
import { CertStatus } from "@app/services/certificate/certificate-types";
|
||||||
|
import { ExternalConfigUnionSchema } from "@app/services/certificate-profile/certificate-profile-external-config-schemas";
|
||||||
import { EnrollmentType, IssuerType } from "@app/services/certificate-profile/certificate-profile-types";
|
import { EnrollmentType, IssuerType } from "@app/services/certificate-profile/certificate-profile-types";
|
||||||
|
|
||||||
export const registerCertificateProfilesRouter = async (server: FastifyZodProvider) => {
|
export const registerCertificateProfilesRouter = async (server: FastifyZodProvider) => {
|
||||||
@@ -47,7 +48,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
})
|
})
|
||||||
.optional(),
|
.optional(),
|
||||||
acmeConfig: z.object({}).optional(),
|
acmeConfig: z.object({}).optional(),
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
.refine(
|
.refine(
|
||||||
(data) => {
|
(data) => {
|
||||||
@@ -151,7 +152,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificateProfile: PkiCertificateProfilesSchema.extend({
|
certificateProfile: PkiCertificateProfilesSchema.extend({
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -247,7 +248,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
directoryUrl: z.string()
|
directoryUrl: z.string()
|
||||||
})
|
})
|
||||||
.optional(),
|
.optional(),
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
}).array(),
|
}).array(),
|
||||||
totalCount: z.number()
|
totalCount: z.number()
|
||||||
})
|
})
|
||||||
@@ -293,7 +294,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificateProfile: PkiCertificateProfilesSchema.extend({
|
certificateProfile: PkiCertificateProfilesSchema.extend({
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
}).extend({
|
}).extend({
|
||||||
certificateAuthority: z
|
certificateAuthority: z
|
||||||
.object({
|
.object({
|
||||||
@@ -328,7 +329,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
renewBeforeDays: z.number().optional()
|
renewBeforeDays: z.number().optional()
|
||||||
})
|
})
|
||||||
.optional(),
|
.optional(),
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -377,7 +378,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificateProfile: PkiCertificateProfilesSchema.extend({
|
certificateProfile: PkiCertificateProfilesSchema.extend({
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -433,7 +434,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
renewBeforeDays: z.number().min(1).max(30).optional()
|
renewBeforeDays: z.number().min(1).max(30).optional()
|
||||||
})
|
})
|
||||||
.optional(),
|
.optional(),
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
.refine(
|
.refine(
|
||||||
(data) => {
|
(data) => {
|
||||||
@@ -456,7 +457,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificateProfile: PkiCertificateProfilesSchema.extend({
|
certificateProfile: PkiCertificateProfilesSchema.extend({
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -503,7 +504,7 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificateProfile: PkiCertificateProfilesSchema.extend({
|
certificateProfile: PkiCertificateProfilesSchema.extend({
|
||||||
externalConfigs: z.record(z.unknown()).nullable().optional()
|
externalConfigs: ExternalConfigUnionSchema
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
+50
@@ -0,0 +1,50 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* External configuration schema for Azure AD CS Certificate Authority
|
||||||
|
*/
|
||||||
|
export const AzureAdCsExternalConfigSchema = z.object({
|
||||||
|
template: z
|
||||||
|
.string()
|
||||||
|
.min(1, "Template name is required for Azure AD CS")
|
||||||
|
.describe("Certificate template name for Azure AD CS")
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* External configuration schema for ACME Certificate Authority
|
||||||
|
*/
|
||||||
|
export const AcmeExternalConfigSchema = z.object({});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Map of CA types to their corresponding external configuration schemas
|
||||||
|
*/
|
||||||
|
export const ExternalConfigSchemaMap = {
|
||||||
|
[CaType.AZURE_AD_CS]: AzureAdCsExternalConfigSchema,
|
||||||
|
[CaType.ACME]: AcmeExternalConfigSchema,
|
||||||
|
[CaType.INTERNAL]: z.object({}).optional() // Internal CAs don't use external configs
|
||||||
|
} as const;
|
||||||
|
|
||||||
|
export const createExternalConfigSchema = (caType?: CaType | null) => {
|
||||||
|
if (!caType || caType === CaType.INTERNAL) {
|
||||||
|
return z.object({}).nullable().optional();
|
||||||
|
}
|
||||||
|
|
||||||
|
const schema = ExternalConfigSchemaMap[caType];
|
||||||
|
if (!schema) {
|
||||||
|
return z.object({}).nullable().optional();
|
||||||
|
}
|
||||||
|
|
||||||
|
return schema.nullable().optional();
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Union type of all possible external configuration schemas
|
||||||
|
*/
|
||||||
|
export const ExternalConfigUnionSchema = z
|
||||||
|
.union([AzureAdCsExternalConfigSchema, AcmeExternalConfigSchema, z.object({})])
|
||||||
|
.nullable()
|
||||||
|
.optional();
|
||||||
|
|
||||||
|
export type TExternalConfig = z.infer<typeof ExternalConfigUnionSchema>;
|
||||||
Reference in New Issue
Block a user