mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 05:27:48 +00:00
feat(secret-rotation): Okta Client Secret Rotation
This commit is contained in:
@@ -6,6 +6,7 @@ import { registerAzureClientSecretRotationRouter } from "./azure-client-secret-r
|
|||||||
import { registerLdapPasswordRotationRouter } from "./ldap-password-rotation-router";
|
import { registerLdapPasswordRotationRouter } from "./ldap-password-rotation-router";
|
||||||
import { registerMsSqlCredentialsRotationRouter } from "./mssql-credentials-rotation-router";
|
import { registerMsSqlCredentialsRotationRouter } from "./mssql-credentials-rotation-router";
|
||||||
import { registerMySqlCredentialsRotationRouter } from "./mysql-credentials-rotation-router";
|
import { registerMySqlCredentialsRotationRouter } from "./mysql-credentials-rotation-router";
|
||||||
|
import { registerOktaClientSecretRotationRouter } from "./okta-client-secret-rotation-router";
|
||||||
import { registerOracleDBCredentialsRotationRouter } from "./oracledb-credentials-rotation-router";
|
import { registerOracleDBCredentialsRotationRouter } from "./oracledb-credentials-rotation-router";
|
||||||
import { registerPostgresCredentialsRotationRouter } from "./postgres-credentials-rotation-router";
|
import { registerPostgresCredentialsRotationRouter } from "./postgres-credentials-rotation-router";
|
||||||
|
|
||||||
@@ -22,5 +23,6 @@ export const SECRET_ROTATION_REGISTER_ROUTER_MAP: Record<
|
|||||||
[SecretRotation.Auth0ClientSecret]: registerAuth0ClientSecretRotationRouter,
|
[SecretRotation.Auth0ClientSecret]: registerAuth0ClientSecretRotationRouter,
|
||||||
[SecretRotation.AzureClientSecret]: registerAzureClientSecretRotationRouter,
|
[SecretRotation.AzureClientSecret]: registerAzureClientSecretRotationRouter,
|
||||||
[SecretRotation.AwsIamUserSecret]: registerAwsIamUserSecretRotationRouter,
|
[SecretRotation.AwsIamUserSecret]: registerAwsIamUserSecretRotationRouter,
|
||||||
[SecretRotation.LdapPassword]: registerLdapPasswordRotationRouter
|
[SecretRotation.LdapPassword]: registerLdapPasswordRotationRouter,
|
||||||
|
[SecretRotation.OktaClientSecret]: registerOktaClientSecretRotationRouter
|
||||||
};
|
};
|
||||||
|
|||||||
+19
@@ -0,0 +1,19 @@
|
|||||||
|
import {
|
||||||
|
CreateOktaClientSecretRotationSchema,
|
||||||
|
OktaClientSecretRotationGeneratedCredentialsSchema,
|
||||||
|
OktaClientSecretRotationSchema,
|
||||||
|
UpdateOktaClientSecretRotationSchema
|
||||||
|
} from "@app/ee/services/secret-rotation-v2/okta-client-secret";
|
||||||
|
import { SecretRotation } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-enums";
|
||||||
|
|
||||||
|
import { registerSecretRotationEndpoints } from "./secret-rotation-v2-endpoints";
|
||||||
|
|
||||||
|
export const registerOktaClientSecretRotationRouter = async (server: FastifyZodProvider) =>
|
||||||
|
registerSecretRotationEndpoints({
|
||||||
|
type: SecretRotation.OktaClientSecret,
|
||||||
|
server,
|
||||||
|
responseSchema: OktaClientSecretRotationSchema,
|
||||||
|
createSchema: CreateOktaClientSecretRotationSchema,
|
||||||
|
updateSchema: UpdateOktaClientSecretRotationSchema,
|
||||||
|
generatedCredentialsSchema: OktaClientSecretRotationGeneratedCredentialsSchema
|
||||||
|
});
|
||||||
@@ -7,6 +7,7 @@ import { AzureClientSecretRotationListItemSchema } from "@app/ee/services/secret
|
|||||||
import { LdapPasswordRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/ldap-password";
|
import { LdapPasswordRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/ldap-password";
|
||||||
import { MsSqlCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/mssql-credentials";
|
import { MsSqlCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/mssql-credentials";
|
||||||
import { MySqlCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/mysql-credentials";
|
import { MySqlCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/mysql-credentials";
|
||||||
|
import { OktaClientSecretRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/okta-client-secret";
|
||||||
import { OracleDBCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/oracledb-credentials";
|
import { OracleDBCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/oracledb-credentials";
|
||||||
import { PostgresCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/postgres-credentials";
|
import { PostgresCredentialsRotationListItemSchema } from "@app/ee/services/secret-rotation-v2/postgres-credentials";
|
||||||
import { SecretRotationV2Schema } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-union-schema";
|
import { SecretRotationV2Schema } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-union-schema";
|
||||||
@@ -23,7 +24,8 @@ const SecretRotationV2OptionsSchema = z.discriminatedUnion("type", [
|
|||||||
Auth0ClientSecretRotationListItemSchema,
|
Auth0ClientSecretRotationListItemSchema,
|
||||||
AzureClientSecretRotationListItemSchema,
|
AzureClientSecretRotationListItemSchema,
|
||||||
AwsIamUserSecretRotationListItemSchema,
|
AwsIamUserSecretRotationListItemSchema,
|
||||||
LdapPasswordRotationListItemSchema
|
LdapPasswordRotationListItemSchema,
|
||||||
|
OktaClientSecretRotationListItemSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerSecretRotationV2Router = async (server: FastifyZodProvider) => {
|
export const registerSecretRotationV2Router = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export * from "./okta-client-secret-rotation-constants";
|
||||||
|
export * from "./okta-client-secret-rotation-schemas";
|
||||||
|
export * from "./okta-client-secret-rotation-types";
|
||||||
+15
@@ -0,0 +1,15 @@
|
|||||||
|
import { SecretRotation } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-enums";
|
||||||
|
import { TSecretRotationV2ListItem } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-types";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
|
||||||
|
export const OKTA_CLIENT_SECRET_ROTATION_LIST_OPTION: TSecretRotationV2ListItem = {
|
||||||
|
name: "Okta Client Secret",
|
||||||
|
type: SecretRotation.OktaClientSecret,
|
||||||
|
connection: AppConnection.Okta,
|
||||||
|
template: {
|
||||||
|
secretsMapping: {
|
||||||
|
clientId: "OKTA_CLIENT_ID",
|
||||||
|
clientSecret: "OKTA_CLIENT_SECRET"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
+260
@@ -0,0 +1,260 @@
|
|||||||
|
/* eslint-disable no-await-in-loop */
|
||||||
|
import { AxiosError } from "axios";
|
||||||
|
|
||||||
|
import {
|
||||||
|
TRotationFactory,
|
||||||
|
TRotationFactoryGetSecretsPayload,
|
||||||
|
TRotationFactoryIssueCredentials,
|
||||||
|
TRotationFactoryRevokeCredentials,
|
||||||
|
TRotationFactoryRotateCredentials
|
||||||
|
} from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-types";
|
||||||
|
import { request } from "@app/lib/config/request";
|
||||||
|
import { delay as delayMs } from "@app/lib/delay";
|
||||||
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
import { getOktaInstanceUrl } from "@app/services/app-connection/okta";
|
||||||
|
|
||||||
|
import {
|
||||||
|
TOktaClientSecret,
|
||||||
|
TOktaClientSecretRotationGeneratedCredentials,
|
||||||
|
TOktaClientSecretRotationWithConnection
|
||||||
|
} from "./okta-client-secret-rotation-types";
|
||||||
|
|
||||||
|
type OktaErrorResponse = { errorCode: string; errorSummary: string; errorCauses?: { errorSummary: string }[] };
|
||||||
|
|
||||||
|
const isOktaErrorResponse = (data: unknown): data is OktaErrorResponse => {
|
||||||
|
return (
|
||||||
|
typeof data === "object" &&
|
||||||
|
data !== null &&
|
||||||
|
"errorSummary" in data &&
|
||||||
|
typeof (data as OktaErrorResponse).errorSummary === "string"
|
||||||
|
);
|
||||||
|
};
|
||||||
|
|
||||||
|
const createErrorMessage = (error: unknown) => {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
if (error.response?.data && isOktaErrorResponse(error.response.data)) {
|
||||||
|
const oktaError = error.response.data;
|
||||||
|
if (oktaError.errorCauses && oktaError.errorCauses.length > 0) {
|
||||||
|
return oktaError.errorCauses[0].errorSummary;
|
||||||
|
}
|
||||||
|
return oktaError.errorSummary;
|
||||||
|
}
|
||||||
|
if (error.message) {
|
||||||
|
return error.message;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return "Unknown error";
|
||||||
|
};
|
||||||
|
|
||||||
|
export const oktaClientSecretRotationFactory: TRotationFactory<
|
||||||
|
TOktaClientSecretRotationWithConnection,
|
||||||
|
TOktaClientSecretRotationGeneratedCredentials
|
||||||
|
> = (secretRotation) => {
|
||||||
|
const {
|
||||||
|
connection,
|
||||||
|
parameters: { clientId },
|
||||||
|
secretsMapping
|
||||||
|
} = secretRotation;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Creates a new client secret for the Okta app.
|
||||||
|
*/
|
||||||
|
const $rotateClientSecret = async () => {
|
||||||
|
const instanceUrl = await getOktaInstanceUrl(connection);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const { data } = await request.post<TOktaClientSecret>(
|
||||||
|
`${instanceUrl}/api/v1/apps/${clientId}/credentials/secrets`,
|
||||||
|
{},
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Accept: "application/json",
|
||||||
|
Authorization: `SSWS ${connection.credentials.apiToken}`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!data.client_secret || !data.id) {
|
||||||
|
throw new Error("Invalid response from Okta: missing 'client_secret' or secret 'id'.");
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
clientSecret: data.client_secret,
|
||||||
|
secretId: data.id,
|
||||||
|
clientId
|
||||||
|
};
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (
|
||||||
|
error instanceof AxiosError &&
|
||||||
|
error.response?.data &&
|
||||||
|
isOktaErrorResponse(error.response.data) &&
|
||||||
|
error.response.data.errorCode === "E0000001"
|
||||||
|
) {
|
||||||
|
// Okta has a maximum of 2 secrets per app, thus we must warn the users in case they already have 2
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to add client secret to Okta app ${clientId}: You must have only a single secret for the Okta app prior to creating this secret rotation.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to add client secret to Okta app ${clientId}: ${createErrorMessage(error)}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* List client secrets.
|
||||||
|
*/
|
||||||
|
const $listClientSecrets = async () => {
|
||||||
|
const instanceUrl = await getOktaInstanceUrl(connection);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const { data } = await request.get<TOktaClientSecret[]>(
|
||||||
|
`${instanceUrl}/api/v1/apps/${clientId}/credentials/secrets`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Accept: "application/json",
|
||||||
|
Authorization: `SSWS ${connection.credentials.apiToken}`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return data;
|
||||||
|
} catch (error: unknown) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to list client secrets for Okta app ${clientId}: ${createErrorMessage(error)}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Checks if a credential with the given secretId exists.
|
||||||
|
*/
|
||||||
|
const credentialExists = async (secretId: string): Promise<boolean> => {
|
||||||
|
const instanceUrl = await getOktaInstanceUrl(connection);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const { data } = await request.get<TOktaClientSecret>(
|
||||||
|
`${instanceUrl}/api/v1/apps/${clientId}/credentials/secrets/${secretId}`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Accept: "application/json",
|
||||||
|
Authorization: `SSWS ${connection.credentials.apiToken}`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return data.id === secretId;
|
||||||
|
} catch (_) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes a client secret from the Okta app using its secretId.
|
||||||
|
* First checks if the credential exists before attempting revocation.
|
||||||
|
*/
|
||||||
|
const revokeCredential = async (secretId: string) => {
|
||||||
|
// Check if credential exists before attempting revocation
|
||||||
|
const exists = await credentialExists(secretId);
|
||||||
|
if (!exists) {
|
||||||
|
return; // Credential doesn't exist, nothing to revoke
|
||||||
|
}
|
||||||
|
|
||||||
|
const instanceUrl = await getOktaInstanceUrl(connection);
|
||||||
|
|
||||||
|
try {
|
||||||
|
// First deactivate the secret
|
||||||
|
await request.post(
|
||||||
|
`${instanceUrl}/api/v1/apps/${clientId}/credentials/secrets/${secretId}/lifecycle/deactivate`,
|
||||||
|
undefined,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `SSWS ${connection.credentials.apiToken}`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
// Then delete it
|
||||||
|
await request.delete(`${instanceUrl}/api/v1/apps/${clientId}/credentials/secrets/${secretId}`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `SSWS ${connection.credentials.apiToken}`
|
||||||
|
}
|
||||||
|
});
|
||||||
|
} catch (error: unknown) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to remove client secret with secretId ${secretId} from app ${clientId}: ${createErrorMessage(error)}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Issues a new set of credentials.
|
||||||
|
*/
|
||||||
|
const issueCredentials: TRotationFactoryIssueCredentials<TOktaClientSecretRotationGeneratedCredentials> = async (
|
||||||
|
callback
|
||||||
|
) => {
|
||||||
|
const credentials = await $rotateClientSecret();
|
||||||
|
return callback(credentials);
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes a list of credentials.
|
||||||
|
*/
|
||||||
|
const revokeCredentials: TRotationFactoryRevokeCredentials<TOktaClientSecretRotationGeneratedCredentials> = async (
|
||||||
|
credentials,
|
||||||
|
callback
|
||||||
|
) => {
|
||||||
|
if (!credentials?.length) return callback();
|
||||||
|
|
||||||
|
for (const { secretId } of credentials) {
|
||||||
|
await revokeCredential(secretId);
|
||||||
|
await delayMs(1000);
|
||||||
|
}
|
||||||
|
return callback();
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Rotates credentials by issuing new ones and revoking the old.
|
||||||
|
*/
|
||||||
|
const rotateCredentials: TRotationFactoryRotateCredentials<TOktaClientSecretRotationGeneratedCredentials> = async (
|
||||||
|
oldCredentials,
|
||||||
|
callback,
|
||||||
|
activeCredentials
|
||||||
|
) => {
|
||||||
|
// Since in Okta you can only have a maximum of 2 secrets at a time, we must delete any other secret besides the current one PRIOR to generating the second secret
|
||||||
|
if (oldCredentials?.secretId) {
|
||||||
|
await revokeCredential(oldCredentials.secretId);
|
||||||
|
} else if (activeCredentials) {
|
||||||
|
// On the first rotation oldCredentials won't be set so we must find the second secret manually
|
||||||
|
const secrets = await $listClientSecrets();
|
||||||
|
|
||||||
|
if (secrets.length > 1) {
|
||||||
|
const nonActiveSecret = secrets.find((secret) => secret.id !== activeCredentials.secretId);
|
||||||
|
if (nonActiveSecret) {
|
||||||
|
await revokeCredential(nonActiveSecret.id);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const newCredentials = await $rotateClientSecret();
|
||||||
|
return callback(newCredentials);
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maps the generated credentials into the secret payload format.
|
||||||
|
*/
|
||||||
|
const getSecretsPayload: TRotationFactoryGetSecretsPayload<TOktaClientSecretRotationGeneratedCredentials> = ({
|
||||||
|
clientSecret
|
||||||
|
}) => [
|
||||||
|
{ key: secretsMapping.clientId, value: clientId },
|
||||||
|
{ key: secretsMapping.clientSecret, value: clientSecret }
|
||||||
|
];
|
||||||
|
|
||||||
|
return {
|
||||||
|
issueCredentials,
|
||||||
|
revokeCredentials,
|
||||||
|
rotateCredentials,
|
||||||
|
getSecretsPayload
|
||||||
|
};
|
||||||
|
};
|
||||||
+68
@@ -0,0 +1,68 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { SecretRotation } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-enums";
|
||||||
|
import {
|
||||||
|
BaseCreateSecretRotationSchema,
|
||||||
|
BaseSecretRotationSchema,
|
||||||
|
BaseUpdateSecretRotationSchema
|
||||||
|
} from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-schemas";
|
||||||
|
import { SecretRotations } from "@app/lib/api-docs";
|
||||||
|
import { SecretNameSchema } from "@app/server/lib/schemas";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationGeneratedCredentialsSchema = z
|
||||||
|
.object({
|
||||||
|
clientId: z.string(),
|
||||||
|
clientSecret: z.string(),
|
||||||
|
secretId: z.string()
|
||||||
|
})
|
||||||
|
.array()
|
||||||
|
.min(1)
|
||||||
|
.max(2);
|
||||||
|
|
||||||
|
const OktaClientSecretRotationParametersSchema = z.object({
|
||||||
|
clientId: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Client ID Required")
|
||||||
|
.describe(SecretRotations.PARAMETERS.OKTA_CLIENT_SECRET.clientId)
|
||||||
|
});
|
||||||
|
|
||||||
|
const OktaClientSecretRotationSecretsMappingSchema = z.object({
|
||||||
|
clientId: SecretNameSchema.describe(SecretRotations.SECRETS_MAPPING.OKTA_CLIENT_SECRET.clientId),
|
||||||
|
clientSecret: SecretNameSchema.describe(SecretRotations.SECRETS_MAPPING.OKTA_CLIENT_SECRET.clientSecret)
|
||||||
|
});
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationTemplateSchema = z.object({
|
||||||
|
secretsMapping: z.object({
|
||||||
|
clientId: z.string(),
|
||||||
|
clientSecret: z.string()
|
||||||
|
})
|
||||||
|
});
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationSchema = BaseSecretRotationSchema(SecretRotation.OktaClientSecret).extend({
|
||||||
|
type: z.literal(SecretRotation.OktaClientSecret),
|
||||||
|
parameters: OktaClientSecretRotationParametersSchema,
|
||||||
|
secretsMapping: OktaClientSecretRotationSecretsMappingSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const CreateOktaClientSecretRotationSchema = BaseCreateSecretRotationSchema(
|
||||||
|
SecretRotation.OktaClientSecret
|
||||||
|
).extend({
|
||||||
|
parameters: OktaClientSecretRotationParametersSchema,
|
||||||
|
secretsMapping: OktaClientSecretRotationSecretsMappingSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const UpdateOktaClientSecretRotationSchema = BaseUpdateSecretRotationSchema(
|
||||||
|
SecretRotation.OktaClientSecret
|
||||||
|
).extend({
|
||||||
|
parameters: OktaClientSecretRotationParametersSchema.optional(),
|
||||||
|
secretsMapping: OktaClientSecretRotationSecretsMappingSchema.optional()
|
||||||
|
});
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationListItemSchema = z.object({
|
||||||
|
name: z.literal("Okta Client Secret"),
|
||||||
|
connection: z.literal(AppConnection.Okta),
|
||||||
|
type: z.literal(SecretRotation.OktaClientSecret),
|
||||||
|
template: OktaClientSecretRotationTemplateSchema
|
||||||
|
});
|
||||||
+40
@@ -0,0 +1,40 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TOktaConnection } from "@app/services/app-connection/okta";
|
||||||
|
|
||||||
|
import {
|
||||||
|
CreateOktaClientSecretRotationSchema,
|
||||||
|
OktaClientSecretRotationGeneratedCredentialsSchema,
|
||||||
|
OktaClientSecretRotationListItemSchema,
|
||||||
|
OktaClientSecretRotationSchema
|
||||||
|
} from "./okta-client-secret-rotation-schemas";
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotation = z.infer<typeof OktaClientSecretRotationSchema>;
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationInput = z.infer<typeof CreateOktaClientSecretRotationSchema>;
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationListItem = z.infer<typeof OktaClientSecretRotationListItemSchema>;
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationWithConnection = TOktaClientSecretRotation & {
|
||||||
|
connection: TOktaConnection;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationGeneratedCredentials = z.infer<
|
||||||
|
typeof OktaClientSecretRotationGeneratedCredentialsSchema
|
||||||
|
>;
|
||||||
|
|
||||||
|
export interface TOktaClientSecretRotationParameters {
|
||||||
|
clientId: string;
|
||||||
|
secretId: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface TOktaClientSecretRotationSecretsMapping {
|
||||||
|
clientId: string;
|
||||||
|
clientSecret: string;
|
||||||
|
secretId: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface TOktaClientSecret {
|
||||||
|
id: string;
|
||||||
|
client_secret: string;
|
||||||
|
}
|
||||||
@@ -6,7 +6,8 @@ export enum SecretRotation {
|
|||||||
Auth0ClientSecret = "auth0-client-secret",
|
Auth0ClientSecret = "auth0-client-secret",
|
||||||
AzureClientSecret = "azure-client-secret",
|
AzureClientSecret = "azure-client-secret",
|
||||||
AwsIamUserSecret = "aws-iam-user-secret",
|
AwsIamUserSecret = "aws-iam-user-secret",
|
||||||
LdapPassword = "ldap-password"
|
LdapPassword = "ldap-password",
|
||||||
|
OktaClientSecret = "okta-client-secret"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum SecretRotationStatus {
|
export enum SecretRotationStatus {
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ import { AZURE_CLIENT_SECRET_ROTATION_LIST_OPTION } from "./azure-client-secret"
|
|||||||
import { LDAP_PASSWORD_ROTATION_LIST_OPTION, TLdapPasswordRotation } from "./ldap-password";
|
import { LDAP_PASSWORD_ROTATION_LIST_OPTION, TLdapPasswordRotation } from "./ldap-password";
|
||||||
import { MSSQL_CREDENTIALS_ROTATION_LIST_OPTION } from "./mssql-credentials";
|
import { MSSQL_CREDENTIALS_ROTATION_LIST_OPTION } from "./mssql-credentials";
|
||||||
import { MYSQL_CREDENTIALS_ROTATION_LIST_OPTION } from "./mysql-credentials";
|
import { MYSQL_CREDENTIALS_ROTATION_LIST_OPTION } from "./mysql-credentials";
|
||||||
|
import { OKTA_CLIENT_SECRET_ROTATION_LIST_OPTION } from "./okta-client-secret";
|
||||||
import { ORACLEDB_CREDENTIALS_ROTATION_LIST_OPTION } from "./oracledb-credentials";
|
import { ORACLEDB_CREDENTIALS_ROTATION_LIST_OPTION } from "./oracledb-credentials";
|
||||||
import { POSTGRES_CREDENTIALS_ROTATION_LIST_OPTION } from "./postgres-credentials";
|
import { POSTGRES_CREDENTIALS_ROTATION_LIST_OPTION } from "./postgres-credentials";
|
||||||
import { SecretRotation, SecretRotationStatus } from "./secret-rotation-v2-enums";
|
import { SecretRotation, SecretRotationStatus } from "./secret-rotation-v2-enums";
|
||||||
@@ -30,7 +31,8 @@ const SECRET_ROTATION_LIST_OPTIONS: Record<SecretRotation, TSecretRotationV2List
|
|||||||
[SecretRotation.Auth0ClientSecret]: AUTH0_CLIENT_SECRET_ROTATION_LIST_OPTION,
|
[SecretRotation.Auth0ClientSecret]: AUTH0_CLIENT_SECRET_ROTATION_LIST_OPTION,
|
||||||
[SecretRotation.AzureClientSecret]: AZURE_CLIENT_SECRET_ROTATION_LIST_OPTION,
|
[SecretRotation.AzureClientSecret]: AZURE_CLIENT_SECRET_ROTATION_LIST_OPTION,
|
||||||
[SecretRotation.AwsIamUserSecret]: AWS_IAM_USER_SECRET_ROTATION_LIST_OPTION,
|
[SecretRotation.AwsIamUserSecret]: AWS_IAM_USER_SECRET_ROTATION_LIST_OPTION,
|
||||||
[SecretRotation.LdapPassword]: LDAP_PASSWORD_ROTATION_LIST_OPTION
|
[SecretRotation.LdapPassword]: LDAP_PASSWORD_ROTATION_LIST_OPTION,
|
||||||
|
[SecretRotation.OktaClientSecret]: OKTA_CLIENT_SECRET_ROTATION_LIST_OPTION
|
||||||
};
|
};
|
||||||
|
|
||||||
export const listSecretRotationOptions = () => {
|
export const listSecretRotationOptions = () => {
|
||||||
|
|||||||
@@ -9,7 +9,8 @@ export const SECRET_ROTATION_NAME_MAP: Record<SecretRotation, string> = {
|
|||||||
[SecretRotation.Auth0ClientSecret]: "Auth0 Client Secret",
|
[SecretRotation.Auth0ClientSecret]: "Auth0 Client Secret",
|
||||||
[SecretRotation.AzureClientSecret]: "Azure Client Secret",
|
[SecretRotation.AzureClientSecret]: "Azure Client Secret",
|
||||||
[SecretRotation.AwsIamUserSecret]: "AWS IAM User Secret",
|
[SecretRotation.AwsIamUserSecret]: "AWS IAM User Secret",
|
||||||
[SecretRotation.LdapPassword]: "LDAP Password"
|
[SecretRotation.LdapPassword]: "LDAP Password",
|
||||||
|
[SecretRotation.OktaClientSecret]: "Okta Client Secret"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SECRET_ROTATION_CONNECTION_MAP: Record<SecretRotation, AppConnection> = {
|
export const SECRET_ROTATION_CONNECTION_MAP: Record<SecretRotation, AppConnection> = {
|
||||||
@@ -20,5 +21,6 @@ export const SECRET_ROTATION_CONNECTION_MAP: Record<SecretRotation, AppConnectio
|
|||||||
[SecretRotation.Auth0ClientSecret]: AppConnection.Auth0,
|
[SecretRotation.Auth0ClientSecret]: AppConnection.Auth0,
|
||||||
[SecretRotation.AzureClientSecret]: AppConnection.AzureClientSecrets,
|
[SecretRotation.AzureClientSecret]: AppConnection.AzureClientSecrets,
|
||||||
[SecretRotation.AwsIamUserSecret]: AppConnection.AWS,
|
[SecretRotation.AwsIamUserSecret]: AppConnection.AWS,
|
||||||
[SecretRotation.LdapPassword]: AppConnection.LDAP
|
[SecretRotation.LdapPassword]: AppConnection.LDAP,
|
||||||
|
[SecretRotation.OktaClientSecret]: AppConnection.Okta
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -82,6 +82,7 @@ import { TSecretVersionV2DALFactory } from "@app/services/secret-v2-bridge/secre
|
|||||||
import { TSecretVersionV2TagDALFactory } from "@app/services/secret-v2-bridge/secret-version-tag-dal";
|
import { TSecretVersionV2TagDALFactory } from "@app/services/secret-v2-bridge/secret-version-tag-dal";
|
||||||
|
|
||||||
import { awsIamUserSecretRotationFactory } from "./aws-iam-user-secret/aws-iam-user-secret-rotation-fns";
|
import { awsIamUserSecretRotationFactory } from "./aws-iam-user-secret/aws-iam-user-secret-rotation-fns";
|
||||||
|
import { oktaClientSecretRotationFactory } from "./okta-client-secret/okta-client-secret-rotation-fns";
|
||||||
import { TSecretRotationV2DALFactory } from "./secret-rotation-v2-dal";
|
import { TSecretRotationV2DALFactory } from "./secret-rotation-v2-dal";
|
||||||
|
|
||||||
export type TSecretRotationV2ServiceFactoryDep = {
|
export type TSecretRotationV2ServiceFactoryDep = {
|
||||||
@@ -126,7 +127,8 @@ const SECRET_ROTATION_FACTORY_MAP: Record<SecretRotation, TRotationFactoryImplem
|
|||||||
[SecretRotation.Auth0ClientSecret]: auth0ClientSecretRotationFactory as TRotationFactoryImplementation,
|
[SecretRotation.Auth0ClientSecret]: auth0ClientSecretRotationFactory as TRotationFactoryImplementation,
|
||||||
[SecretRotation.AzureClientSecret]: azureClientSecretRotationFactory as TRotationFactoryImplementation,
|
[SecretRotation.AzureClientSecret]: azureClientSecretRotationFactory as TRotationFactoryImplementation,
|
||||||
[SecretRotation.AwsIamUserSecret]: awsIamUserSecretRotationFactory as TRotationFactoryImplementation,
|
[SecretRotation.AwsIamUserSecret]: awsIamUserSecretRotationFactory as TRotationFactoryImplementation,
|
||||||
[SecretRotation.LdapPassword]: ldapPasswordRotationFactory as TRotationFactoryImplementation
|
[SecretRotation.LdapPassword]: ldapPasswordRotationFactory as TRotationFactoryImplementation,
|
||||||
|
[SecretRotation.OktaClientSecret]: oktaClientSecretRotationFactory as TRotationFactoryImplementation
|
||||||
};
|
};
|
||||||
|
|
||||||
export const secretRotationV2ServiceFactory = ({
|
export const secretRotationV2ServiceFactory = ({
|
||||||
|
|||||||
@@ -45,6 +45,13 @@ import {
|
|||||||
TMySqlCredentialsRotationListItem,
|
TMySqlCredentialsRotationListItem,
|
||||||
TMySqlCredentialsRotationWithConnection
|
TMySqlCredentialsRotationWithConnection
|
||||||
} from "./mysql-credentials";
|
} from "./mysql-credentials";
|
||||||
|
import {
|
||||||
|
TOktaClientSecretRotation,
|
||||||
|
TOktaClientSecretRotationGeneratedCredentials,
|
||||||
|
TOktaClientSecretRotationInput,
|
||||||
|
TOktaClientSecretRotationListItem,
|
||||||
|
TOktaClientSecretRotationWithConnection
|
||||||
|
} from "./okta-client-secret";
|
||||||
import {
|
import {
|
||||||
TOracleDBCredentialsRotation,
|
TOracleDBCredentialsRotation,
|
||||||
TOracleDBCredentialsRotationInput,
|
TOracleDBCredentialsRotationInput,
|
||||||
@@ -68,7 +75,8 @@ export type TSecretRotationV2 =
|
|||||||
| TAuth0ClientSecretRotation
|
| TAuth0ClientSecretRotation
|
||||||
| TAzureClientSecretRotation
|
| TAzureClientSecretRotation
|
||||||
| TLdapPasswordRotation
|
| TLdapPasswordRotation
|
||||||
| TAwsIamUserSecretRotation;
|
| TAwsIamUserSecretRotation
|
||||||
|
| TOktaClientSecretRotation;
|
||||||
|
|
||||||
export type TSecretRotationV2WithConnection =
|
export type TSecretRotationV2WithConnection =
|
||||||
| TPostgresCredentialsRotationWithConnection
|
| TPostgresCredentialsRotationWithConnection
|
||||||
@@ -78,14 +86,16 @@ export type TSecretRotationV2WithConnection =
|
|||||||
| TAuth0ClientSecretRotationWithConnection
|
| TAuth0ClientSecretRotationWithConnection
|
||||||
| TAzureClientSecretRotationWithConnection
|
| TAzureClientSecretRotationWithConnection
|
||||||
| TLdapPasswordRotationWithConnection
|
| TLdapPasswordRotationWithConnection
|
||||||
| TAwsIamUserSecretRotationWithConnection;
|
| TAwsIamUserSecretRotationWithConnection
|
||||||
|
| TOktaClientSecretRotationWithConnection;
|
||||||
|
|
||||||
export type TSecretRotationV2GeneratedCredentials =
|
export type TSecretRotationV2GeneratedCredentials =
|
||||||
| TSqlCredentialsRotationGeneratedCredentials
|
| TSqlCredentialsRotationGeneratedCredentials
|
||||||
| TAuth0ClientSecretRotationGeneratedCredentials
|
| TAuth0ClientSecretRotationGeneratedCredentials
|
||||||
| TAzureClientSecretRotationGeneratedCredentials
|
| TAzureClientSecretRotationGeneratedCredentials
|
||||||
| TLdapPasswordRotationGeneratedCredentials
|
| TLdapPasswordRotationGeneratedCredentials
|
||||||
| TAwsIamUserSecretRotationGeneratedCredentials;
|
| TAwsIamUserSecretRotationGeneratedCredentials
|
||||||
|
| TOktaClientSecretRotationGeneratedCredentials;
|
||||||
|
|
||||||
export type TSecretRotationV2Input =
|
export type TSecretRotationV2Input =
|
||||||
| TPostgresCredentialsRotationInput
|
| TPostgresCredentialsRotationInput
|
||||||
@@ -95,7 +105,8 @@ export type TSecretRotationV2Input =
|
|||||||
| TAuth0ClientSecretRotationInput
|
| TAuth0ClientSecretRotationInput
|
||||||
| TAzureClientSecretRotationInput
|
| TAzureClientSecretRotationInput
|
||||||
| TLdapPasswordRotationInput
|
| TLdapPasswordRotationInput
|
||||||
| TAwsIamUserSecretRotationInput;
|
| TAwsIamUserSecretRotationInput
|
||||||
|
| TOktaClientSecretRotationInput;
|
||||||
|
|
||||||
export type TSecretRotationV2ListItem =
|
export type TSecretRotationV2ListItem =
|
||||||
| TPostgresCredentialsRotationListItem
|
| TPostgresCredentialsRotationListItem
|
||||||
@@ -105,7 +116,8 @@ export type TSecretRotationV2ListItem =
|
|||||||
| TAuth0ClientSecretRotationListItem
|
| TAuth0ClientSecretRotationListItem
|
||||||
| TAzureClientSecretRotationListItem
|
| TAzureClientSecretRotationListItem
|
||||||
| TLdapPasswordRotationListItem
|
| TLdapPasswordRotationListItem
|
||||||
| TAwsIamUserSecretRotationListItem;
|
| TAwsIamUserSecretRotationListItem
|
||||||
|
| TOktaClientSecretRotationListItem;
|
||||||
|
|
||||||
export type TSecretRotationV2TemporaryParameters = TLdapPasswordRotationInput["temporaryParameters"] | undefined;
|
export type TSecretRotationV2TemporaryParameters = TLdapPasswordRotationInput["temporaryParameters"] | undefined;
|
||||||
|
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import { AzureClientSecretRotationSchema } from "@app/ee/services/secret-rotatio
|
|||||||
import { LdapPasswordRotationSchema } from "@app/ee/services/secret-rotation-v2/ldap-password";
|
import { LdapPasswordRotationSchema } from "@app/ee/services/secret-rotation-v2/ldap-password";
|
||||||
import { MsSqlCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/mssql-credentials";
|
import { MsSqlCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/mssql-credentials";
|
||||||
import { MySqlCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/mysql-credentials";
|
import { MySqlCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/mysql-credentials";
|
||||||
|
import { OktaClientSecretRotationSchema } from "@app/ee/services/secret-rotation-v2/okta-client-secret";
|
||||||
import { OracleDBCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/oracledb-credentials";
|
import { OracleDBCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/oracledb-credentials";
|
||||||
import { PostgresCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/postgres-credentials";
|
import { PostgresCredentialsRotationSchema } from "@app/ee/services/secret-rotation-v2/postgres-credentials";
|
||||||
|
|
||||||
@@ -17,5 +18,6 @@ export const SecretRotationV2Schema = z.discriminatedUnion("type", [
|
|||||||
Auth0ClientSecretRotationSchema,
|
Auth0ClientSecretRotationSchema,
|
||||||
AzureClientSecretRotationSchema,
|
AzureClientSecretRotationSchema,
|
||||||
LdapPasswordRotationSchema,
|
LdapPasswordRotationSchema,
|
||||||
AwsIamUserSecretRotationSchema
|
AwsIamUserSecretRotationSchema,
|
||||||
|
OktaClientSecretRotationSchema
|
||||||
]);
|
]);
|
||||||
|
|||||||
@@ -2598,6 +2598,9 @@ export const SecretRotations = {
|
|||||||
AWS_IAM_USER_SECRET: {
|
AWS_IAM_USER_SECRET: {
|
||||||
userName: "The name of the client to rotate credentials for.",
|
userName: "The name of the client to rotate credentials for.",
|
||||||
region: "The AWS region the client is present in."
|
region: "The AWS region the client is present in."
|
||||||
|
},
|
||||||
|
OKTA_CLIENT_SECRET: {
|
||||||
|
clientId: "The ID of the Okta Application to rotate the client secret for."
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
SECRETS_MAPPING: {
|
SECRETS_MAPPING: {
|
||||||
@@ -2620,6 +2623,10 @@ export const SecretRotations = {
|
|||||||
AWS_IAM_USER_SECRET: {
|
AWS_IAM_USER_SECRET: {
|
||||||
accessKeyId: "The name of the secret that the access key ID will be mapped to.",
|
accessKeyId: "The name of the secret that the access key ID will be mapped to.",
|
||||||
secretAccessKey: "The name of the secret that the rotated secret access key will be mapped to."
|
secretAccessKey: "The name of the secret that the rotated secret access key will be mapped to."
|
||||||
|
},
|
||||||
|
OKTA_CLIENT_SECRET: {
|
||||||
|
clientId: "The name of the secret that the client ID will be mapped to.",
|
||||||
|
clientSecret: "The name of the secret that the rotated client secret will be mapped to."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -53,5 +53,5 @@ export const listOktaApps = async (appConnection: TOktaConnection) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
return data.filter((app) => app.status === "ACTIVE");
|
return data.filter((app) => app.status === "ACTIVE" && app.name === "oidc_client");
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -25,4 +25,5 @@ export type TOktaApp = {
|
|||||||
id: string;
|
id: string;
|
||||||
label: string;
|
label: string;
|
||||||
status: "ACTIVE" | "INACTIVE";
|
status: "ACTIVE" | "INACTIVE";
|
||||||
|
name: string; // "oidc_client" or other types
|
||||||
};
|
};
|
||||||
|
|||||||
+38
@@ -0,0 +1,38 @@
|
|||||||
|
import { CredentialDisplay } from "@app/components/secret-rotations-v2/ViewSecretRotationV2GeneratedCredentials/shared/CredentialDisplay";
|
||||||
|
import { TOktaClientSecretRotationGeneratedCredentialsResponse } from "@app/hooks/api/secretRotationsV2/types/okta-client-secret-rotation";
|
||||||
|
|
||||||
|
import { ViewRotationGeneratedCredentialsDisplay } from "./shared";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
generatedCredentialsResponse: TOktaClientSecretRotationGeneratedCredentialsResponse;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const ViewOktaClientSecretRotationGeneratedCredentials = ({
|
||||||
|
generatedCredentialsResponse: { generatedCredentials, activeIndex }
|
||||||
|
}: Props) => {
|
||||||
|
const inactiveIndex = activeIndex === 0 ? 1 : 0;
|
||||||
|
|
||||||
|
const activeCredentials = generatedCredentials[activeIndex];
|
||||||
|
const inactiveCredentials = generatedCredentials[inactiveIndex];
|
||||||
|
|
||||||
|
return (
|
||||||
|
<ViewRotationGeneratedCredentialsDisplay
|
||||||
|
activeCredentials={
|
||||||
|
<>
|
||||||
|
<CredentialDisplay label="Client ID">{activeCredentials?.clientId}</CredentialDisplay>
|
||||||
|
<CredentialDisplay isSensitive label="Client Secret">
|
||||||
|
{activeCredentials?.clientSecret}
|
||||||
|
</CredentialDisplay>
|
||||||
|
</>
|
||||||
|
}
|
||||||
|
inactiveCredentials={
|
||||||
|
<>
|
||||||
|
<CredentialDisplay label="Client ID">{inactiveCredentials?.clientId}</CredentialDisplay>
|
||||||
|
<CredentialDisplay isSensitive label="Client Secret">
|
||||||
|
{inactiveCredentials?.clientSecret}
|
||||||
|
</CredentialDisplay>
|
||||||
|
</>
|
||||||
|
}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
};
|
||||||
+8
@@ -22,6 +22,7 @@ import {
|
|||||||
|
|
||||||
import { ViewSqlCredentialsRotationGeneratedCredentials } from "./shared";
|
import { ViewSqlCredentialsRotationGeneratedCredentials } from "./shared";
|
||||||
import { ViewAwsIamUserSecretRotationGeneratedCredentials } from "./ViewAwsIamUserSecretRotationGeneratedCredentials";
|
import { ViewAwsIamUserSecretRotationGeneratedCredentials } from "./ViewAwsIamUserSecretRotationGeneratedCredentials";
|
||||||
|
import { ViewOktaClientSecretRotationGeneratedCredentials } from "./ViewOktaClientSecretRotationGeneratedCredentials";
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
secretRotation?: TSecretRotationV2;
|
secretRotation?: TSecretRotationV2;
|
||||||
@@ -99,6 +100,13 @@ const Content = ({ secretRotation }: ContentProps) => {
|
|||||||
/>
|
/>
|
||||||
);
|
);
|
||||||
break;
|
break;
|
||||||
|
case SecretRotation.OktaClientSecret:
|
||||||
|
Component = (
|
||||||
|
<ViewOktaClientSecretRotationGeneratedCredentials
|
||||||
|
generatedCredentialsResponse={generatedCredentialsResponse}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error("Unhandled View Generated Credential Rotation Type");
|
throw new Error("Unhandled View Generated Credential Rotation Type");
|
||||||
}
|
}
|
||||||
|
|||||||
+51
@@ -0,0 +1,51 @@
|
|||||||
|
import { Controller, useFormContext } from "react-hook-form";
|
||||||
|
import { SingleValue } from "react-select";
|
||||||
|
|
||||||
|
import { TSecretRotationV2Form } from "@app/components/secret-rotations-v2/forms/schemas";
|
||||||
|
import { FilterableSelect, FormControl } from "@app/components/v2";
|
||||||
|
import { useOktaConnectionListApps } from "@app/hooks/api/appConnections/okta";
|
||||||
|
import { TOktaApp } from "@app/hooks/api/appConnections/okta/types";
|
||||||
|
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationParametersFields = () => {
|
||||||
|
const { control, watch, setValue } = useFormContext<
|
||||||
|
TSecretRotationV2Form & {
|
||||||
|
type: SecretRotation.OktaClientSecret;
|
||||||
|
}
|
||||||
|
>();
|
||||||
|
|
||||||
|
const connectionId = watch("connection.id");
|
||||||
|
|
||||||
|
const { data: apps, isPending: isAppsPending } = useOktaConnectionListApps(connectionId, {
|
||||||
|
enabled: Boolean(connectionId)
|
||||||
|
});
|
||||||
|
|
||||||
|
return (
|
||||||
|
<Controller
|
||||||
|
name="parameters.clientId"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
label="OpenID Connect Application"
|
||||||
|
>
|
||||||
|
<FilterableSelect
|
||||||
|
menuPlacement="top"
|
||||||
|
isLoading={isAppsPending && Boolean(connectionId)}
|
||||||
|
isDisabled={!connectionId}
|
||||||
|
value={apps?.find((app) => app.id === value) ?? null}
|
||||||
|
onChange={(option) => {
|
||||||
|
onChange((option as SingleValue<TOktaApp>)?.id ?? null);
|
||||||
|
setValue("parameters.clientId", (option as SingleValue<TOktaApp>)?.id ?? "");
|
||||||
|
}}
|
||||||
|
options={apps}
|
||||||
|
placeholder="Select an application..."
|
||||||
|
getOptionLabel={(option) => option.label}
|
||||||
|
getOptionValue={(option) => option.id}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
};
|
||||||
+3
-1
@@ -7,6 +7,7 @@ import { Auth0ClientSecretRotationParametersFields } from "./Auth0ClientSecretRo
|
|||||||
import { AwsIamUserSecretRotationParametersFields } from "./AwsIamUserSecretRotationParametersFields";
|
import { AwsIamUserSecretRotationParametersFields } from "./AwsIamUserSecretRotationParametersFields";
|
||||||
import { AzureClientSecretRotationParametersFields } from "./AzureClientSecretRotationParametersFields";
|
import { AzureClientSecretRotationParametersFields } from "./AzureClientSecretRotationParametersFields";
|
||||||
import { LdapPasswordRotationParametersFields } from "./LdapPasswordRotationParametersFields";
|
import { LdapPasswordRotationParametersFields } from "./LdapPasswordRotationParametersFields";
|
||||||
|
import { OktaClientSecretRotationParametersFields } from "./OktaClientSecretRotationParametersFields";
|
||||||
import { SqlCredentialsRotationParametersFields } from "./shared";
|
import { SqlCredentialsRotationParametersFields } from "./shared";
|
||||||
|
|
||||||
const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
||||||
@@ -17,7 +18,8 @@ const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
|||||||
[SecretRotation.Auth0ClientSecret]: Auth0ClientSecretRotationParametersFields,
|
[SecretRotation.Auth0ClientSecret]: Auth0ClientSecretRotationParametersFields,
|
||||||
[SecretRotation.AzureClientSecret]: AzureClientSecretRotationParametersFields,
|
[SecretRotation.AzureClientSecret]: AzureClientSecretRotationParametersFields,
|
||||||
[SecretRotation.LdapPassword]: LdapPasswordRotationParametersFields,
|
[SecretRotation.LdapPassword]: LdapPasswordRotationParametersFields,
|
||||||
[SecretRotation.AwsIamUserSecret]: AwsIamUserSecretRotationParametersFields
|
[SecretRotation.AwsIamUserSecret]: AwsIamUserSecretRotationParametersFields,
|
||||||
|
[SecretRotation.OktaClientSecret]: OktaClientSecretRotationParametersFields
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SecretRotationV2ParametersFields = () => {
|
export const SecretRotationV2ParametersFields = () => {
|
||||||
|
|||||||
+29
@@ -0,0 +1,29 @@
|
|||||||
|
import { useFormContext } from "react-hook-form";
|
||||||
|
|
||||||
|
import { TSecretRotationV2Form } from "@app/components/secret-rotations-v2/forms/schemas";
|
||||||
|
import { GenericFieldLabel } from "@app/components/v2";
|
||||||
|
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
||||||
|
|
||||||
|
import { SecretRotationReviewSection } from "./shared";
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationReviewFields = () => {
|
||||||
|
const { watch } = useFormContext<
|
||||||
|
TSecretRotationV2Form & {
|
||||||
|
type: SecretRotation.OktaClientSecret;
|
||||||
|
}
|
||||||
|
>();
|
||||||
|
|
||||||
|
const [parameters, { clientId, clientSecret }] = watch(["parameters", "secretsMapping"]);
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<SecretRotationReviewSection label="Parameters">
|
||||||
|
<GenericFieldLabel label="App ID">{parameters.clientId}</GenericFieldLabel>
|
||||||
|
</SecretRotationReviewSection>
|
||||||
|
<SecretRotationReviewSection label="Secrets Mapping">
|
||||||
|
<GenericFieldLabel label="Client ID">{clientId}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Client Secret">{clientSecret}</GenericFieldLabel>
|
||||||
|
</SecretRotationReviewSection>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
+3
-1
@@ -10,6 +10,7 @@ import { Auth0ClientSecretRotationReviewFields } from "./Auth0ClientSecretRotati
|
|||||||
import { AwsIamUserSecretRotationReviewFields } from "./AwsIamUserSecretRotationReviewFields";
|
import { AwsIamUserSecretRotationReviewFields } from "./AwsIamUserSecretRotationReviewFields";
|
||||||
import { AzureClientSecretRotationReviewFields } from "./AzureClientSecretRotationReviewFields";
|
import { AzureClientSecretRotationReviewFields } from "./AzureClientSecretRotationReviewFields";
|
||||||
import { LdapPasswordRotationReviewFields } from "./LdapPasswordRotationReviewFields";
|
import { LdapPasswordRotationReviewFields } from "./LdapPasswordRotationReviewFields";
|
||||||
|
import { OktaClientSecretRotationReviewFields } from "./OktaClientSecretRotationReviewFields";
|
||||||
import { SqlCredentialsRotationReviewFields } from "./shared";
|
import { SqlCredentialsRotationReviewFields } from "./shared";
|
||||||
|
|
||||||
const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
||||||
@@ -20,7 +21,8 @@ const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
|||||||
[SecretRotation.Auth0ClientSecret]: Auth0ClientSecretRotationReviewFields,
|
[SecretRotation.Auth0ClientSecret]: Auth0ClientSecretRotationReviewFields,
|
||||||
[SecretRotation.AzureClientSecret]: AzureClientSecretRotationReviewFields,
|
[SecretRotation.AzureClientSecret]: AzureClientSecretRotationReviewFields,
|
||||||
[SecretRotation.LdapPassword]: LdapPasswordRotationReviewFields,
|
[SecretRotation.LdapPassword]: LdapPasswordRotationReviewFields,
|
||||||
[SecretRotation.AwsIamUserSecret]: AwsIamUserSecretRotationReviewFields
|
[SecretRotation.AwsIamUserSecret]: AwsIamUserSecretRotationReviewFields,
|
||||||
|
[SecretRotation.OktaClientSecret]: OktaClientSecretRotationReviewFields
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SecretRotationV2ReviewFields = () => {
|
export const SecretRotationV2ReviewFields = () => {
|
||||||
|
|||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
import { Controller, useFormContext } from "react-hook-form";
|
||||||
|
|
||||||
|
import { TSecretRotationV2Form } from "@app/components/secret-rotations-v2/forms/schemas";
|
||||||
|
import { FormControl, Input } from "@app/components/v2";
|
||||||
|
import { SecretRotation, useSecretRotationV2Option } from "@app/hooks/api/secretRotationsV2";
|
||||||
|
|
||||||
|
import { SecretsMappingTable } from "./shared";
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationSecretsMappingFields = () => {
|
||||||
|
const { control } = useFormContext<
|
||||||
|
TSecretRotationV2Form & {
|
||||||
|
type: SecretRotation.OktaClientSecret;
|
||||||
|
}
|
||||||
|
>();
|
||||||
|
|
||||||
|
const { rotationOption } = useSecretRotationV2Option(SecretRotation.OktaClientSecret);
|
||||||
|
|
||||||
|
const items = [
|
||||||
|
{
|
||||||
|
name: "Client ID",
|
||||||
|
input: (
|
||||||
|
<Controller
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl isError={Boolean(error)} errorText={error?.message}>
|
||||||
|
<Input
|
||||||
|
value={value}
|
||||||
|
onChange={onChange}
|
||||||
|
placeholder={rotationOption?.template.secretsMapping.clientId}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
control={control}
|
||||||
|
name="secretsMapping.clientId"
|
||||||
|
/>
|
||||||
|
)
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Client Secret",
|
||||||
|
input: (
|
||||||
|
<Controller
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl isError={Boolean(error)} errorText={error?.message}>
|
||||||
|
<Input
|
||||||
|
value={value}
|
||||||
|
onChange={onChange}
|
||||||
|
placeholder={rotationOption?.template.secretsMapping.clientSecret}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
control={control}
|
||||||
|
name="secretsMapping.clientSecret"
|
||||||
|
/>
|
||||||
|
)
|
||||||
|
}
|
||||||
|
];
|
||||||
|
|
||||||
|
return <SecretsMappingTable items={items} />;
|
||||||
|
};
|
||||||
+3
-1
@@ -7,6 +7,7 @@ import { Auth0ClientSecretRotationSecretsMappingFields } from "./Auth0ClientSecr
|
|||||||
import { AwsIamUserSecretRotationSecretsMappingFields } from "./AwsIamUserSecretRotationSecretsMappingFields";
|
import { AwsIamUserSecretRotationSecretsMappingFields } from "./AwsIamUserSecretRotationSecretsMappingFields";
|
||||||
import { AzureClientSecretRotationSecretsMappingFields } from "./AzureClientSecretRotationSecretsMappingFields";
|
import { AzureClientSecretRotationSecretsMappingFields } from "./AzureClientSecretRotationSecretsMappingFields";
|
||||||
import { LdapPasswordRotationSecretsMappingFields } from "./LdapPasswordRotationSecretsMappingFields";
|
import { LdapPasswordRotationSecretsMappingFields } from "./LdapPasswordRotationSecretsMappingFields";
|
||||||
|
import { OktaClientSecretRotationSecretsMappingFields } from "./OktaClientSecretRotationSecretsMappingFields";
|
||||||
import { SqlCredentialsRotationSecretsMappingFields } from "./shared";
|
import { SqlCredentialsRotationSecretsMappingFields } from "./shared";
|
||||||
|
|
||||||
const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
||||||
@@ -17,7 +18,8 @@ const COMPONENT_MAP: Record<SecretRotation, React.FC> = {
|
|||||||
[SecretRotation.Auth0ClientSecret]: Auth0ClientSecretRotationSecretsMappingFields,
|
[SecretRotation.Auth0ClientSecret]: Auth0ClientSecretRotationSecretsMappingFields,
|
||||||
[SecretRotation.AzureClientSecret]: AzureClientSecretRotationSecretsMappingFields,
|
[SecretRotation.AzureClientSecret]: AzureClientSecretRotationSecretsMappingFields,
|
||||||
[SecretRotation.LdapPassword]: LdapPasswordRotationSecretsMappingFields,
|
[SecretRotation.LdapPassword]: LdapPasswordRotationSecretsMappingFields,
|
||||||
[SecretRotation.AwsIamUserSecret]: AwsIamUserSecretRotationSecretsMappingFields
|
[SecretRotation.AwsIamUserSecret]: AwsIamUserSecretRotationSecretsMappingFields,
|
||||||
|
[SecretRotation.OktaClientSecret]: OktaClientSecretRotationSecretsMappingFields
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SecretRotationV2SecretsMappingFields = () => {
|
export const SecretRotationV2SecretsMappingFields = () => {
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ import { PostgresCredentialsRotationSchema } from "@app/components/secret-rotati
|
|||||||
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
||||||
import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation";
|
import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation";
|
||||||
|
|
||||||
|
import { OktaClientSecretRotationSchema } from "./okta-client-secret-rotation-schema";
|
||||||
import { OracleDBCredentialsRotationSchema } from "./oracledb-credentials-rotation-schema";
|
import { OracleDBCredentialsRotationSchema } from "./oracledb-credentials-rotation-schema";
|
||||||
|
|
||||||
export const SecretRotationV2FormSchema = (isUpdate: boolean) =>
|
export const SecretRotationV2FormSchema = (isUpdate: boolean) =>
|
||||||
@@ -23,7 +24,8 @@ export const SecretRotationV2FormSchema = (isUpdate: boolean) =>
|
|||||||
MySqlCredentialsRotationSchema,
|
MySqlCredentialsRotationSchema,
|
||||||
OracleDBCredentialsRotationSchema,
|
OracleDBCredentialsRotationSchema,
|
||||||
LdapPasswordRotationSchema,
|
LdapPasswordRotationSchema,
|
||||||
AwsIamUserSecretRotationSchema
|
AwsIamUserSecretRotationSchema,
|
||||||
|
OktaClientSecretRotationSchema
|
||||||
]),
|
]),
|
||||||
z.object({ id: z.string().optional() })
|
z.object({ id: z.string().optional() })
|
||||||
)
|
)
|
||||||
|
|||||||
+17
@@ -0,0 +1,17 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { BaseSecretRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/base-secret-rotation-v2-schema";
|
||||||
|
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
||||||
|
|
||||||
|
export const OktaClientSecretRotationSchema = z
|
||||||
|
.object({
|
||||||
|
type: z.literal(SecretRotation.OktaClientSecret),
|
||||||
|
parameters: z.object({
|
||||||
|
clientId: z.string().trim().min(1, "App ID required")
|
||||||
|
}),
|
||||||
|
secretsMapping: z.object({
|
||||||
|
clientId: z.string().trim().min(1, "Client ID required"),
|
||||||
|
clientSecret: z.string().trim().min(1, "Client Secret required")
|
||||||
|
})
|
||||||
|
})
|
||||||
|
.merge(BaseSecretRotationSchema);
|
||||||
@@ -44,6 +44,11 @@ export const SECRET_ROTATION_MAP: Record<
|
|||||||
name: "AWS IAM User Secret",
|
name: "AWS IAM User Secret",
|
||||||
image: "Amazon Web Services.png",
|
image: "Amazon Web Services.png",
|
||||||
size: 50
|
size: 50
|
||||||
|
},
|
||||||
|
[SecretRotation.OktaClientSecret]: {
|
||||||
|
name: "Okta Client Secret",
|
||||||
|
image: "Okta.png",
|
||||||
|
size: 50
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -55,7 +60,8 @@ export const SECRET_ROTATION_CONNECTION_MAP: Record<SecretRotation, AppConnectio
|
|||||||
[SecretRotation.Auth0ClientSecret]: AppConnection.Auth0,
|
[SecretRotation.Auth0ClientSecret]: AppConnection.Auth0,
|
||||||
[SecretRotation.AzureClientSecret]: AppConnection.AzureClientSecrets,
|
[SecretRotation.AzureClientSecret]: AppConnection.AzureClientSecrets,
|
||||||
[SecretRotation.LdapPassword]: AppConnection.LDAP,
|
[SecretRotation.LdapPassword]: AppConnection.LDAP,
|
||||||
[SecretRotation.AwsIamUserSecret]: AppConnection.AWS
|
[SecretRotation.AwsIamUserSecret]: AppConnection.AWS,
|
||||||
|
[SecretRotation.OktaClientSecret]: AppConnection.Okta
|
||||||
};
|
};
|
||||||
|
|
||||||
// if a rotation can potentially have downtime due to rotating a single credential set this to false
|
// if a rotation can potentially have downtime due to rotating a single credential set this to false
|
||||||
@@ -67,7 +73,8 @@ export const IS_ROTATION_DUAL_CREDENTIALS: Record<SecretRotation, boolean> = {
|
|||||||
[SecretRotation.Auth0ClientSecret]: false,
|
[SecretRotation.Auth0ClientSecret]: false,
|
||||||
[SecretRotation.AzureClientSecret]: true,
|
[SecretRotation.AzureClientSecret]: true,
|
||||||
[SecretRotation.LdapPassword]: false,
|
[SecretRotation.LdapPassword]: false,
|
||||||
[SecretRotation.AwsIamUserSecret]: true
|
[SecretRotation.AwsIamUserSecret]: true,
|
||||||
|
[SecretRotation.OktaClientSecret]: true
|
||||||
};
|
};
|
||||||
|
|
||||||
export const getRotateAtLocal = ({ hours, minutes }: TSecretRotationV2["rotateAtUtc"]) => {
|
export const getRotateAtLocal = ({ hours, minutes }: TSecretRotationV2["rotateAtUtc"]) => {
|
||||||
|
|||||||
@@ -6,7 +6,8 @@ export enum SecretRotation {
|
|||||||
Auth0ClientSecret = "auth0-client-secret",
|
Auth0ClientSecret = "auth0-client-secret",
|
||||||
AzureClientSecret = "azure-client-secret",
|
AzureClientSecret = "azure-client-secret",
|
||||||
LdapPassword = "ldap-password",
|
LdapPassword = "ldap-password",
|
||||||
AwsIamUserSecret = "aws-iam-user-secret"
|
AwsIamUserSecret = "aws-iam-user-secret",
|
||||||
|
OktaClientSecret = "okta-client-secret"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum SecretRotationStatus {
|
export enum SecretRotationStatus {
|
||||||
|
|||||||
@@ -35,6 +35,11 @@ import {
|
|||||||
TMySqlCredentialsRotation,
|
TMySqlCredentialsRotation,
|
||||||
TMySqlCredentialsRotationGeneratedCredentialsResponse
|
TMySqlCredentialsRotationGeneratedCredentialsResponse
|
||||||
} from "./mysql-credentials-rotation";
|
} from "./mysql-credentials-rotation";
|
||||||
|
import {
|
||||||
|
TOktaClientSecretRotation,
|
||||||
|
TOktaClientSecretRotationGeneratedCredentialsResponse,
|
||||||
|
TOktaClientSecretRotationOption
|
||||||
|
} from "./okta-client-secret-rotation";
|
||||||
import {
|
import {
|
||||||
TOracleDBCredentialsRotation,
|
TOracleDBCredentialsRotation,
|
||||||
TOracleDBCredentialsRotationGeneratedCredentialsResponse
|
TOracleDBCredentialsRotationGeneratedCredentialsResponse
|
||||||
@@ -49,6 +54,7 @@ export type TSecretRotationV2 = (
|
|||||||
| TAzureClientSecretRotation
|
| TAzureClientSecretRotation
|
||||||
| TLdapPasswordRotation
|
| TLdapPasswordRotation
|
||||||
| TAwsIamUserSecretRotation
|
| TAwsIamUserSecretRotation
|
||||||
|
| TOktaClientSecretRotation
|
||||||
) & {
|
) & {
|
||||||
secrets: (SecretV3RawSanitized | null)[];
|
secrets: (SecretV3RawSanitized | null)[];
|
||||||
};
|
};
|
||||||
@@ -58,7 +64,8 @@ export type TSecretRotationV2Option =
|
|||||||
| TAuth0ClientSecretRotationOption
|
| TAuth0ClientSecretRotationOption
|
||||||
| TAzureClientSecretRotationOption
|
| TAzureClientSecretRotationOption
|
||||||
| TLdapPasswordRotationOption
|
| TLdapPasswordRotationOption
|
||||||
| TAwsIamUserSecretRotationOption;
|
| TAwsIamUserSecretRotationOption
|
||||||
|
| TOktaClientSecretRotationOption;
|
||||||
|
|
||||||
export type TListSecretRotationV2Options = { secretRotationOptions: TSecretRotationV2Option[] };
|
export type TListSecretRotationV2Options = { secretRotationOptions: TSecretRotationV2Option[] };
|
||||||
|
|
||||||
@@ -72,7 +79,8 @@ export type TViewSecretRotationGeneratedCredentialsResponse =
|
|||||||
| TAuth0ClientSecretRotationGeneratedCredentialsResponse
|
| TAuth0ClientSecretRotationGeneratedCredentialsResponse
|
||||||
| TAzureClientSecretRotationGeneratedCredentialsResponse
|
| TAzureClientSecretRotationGeneratedCredentialsResponse
|
||||||
| TLdapPasswordRotationGeneratedCredentialsResponse
|
| TLdapPasswordRotationGeneratedCredentialsResponse
|
||||||
| TAwsIamUserSecretRotationGeneratedCredentialsResponse;
|
| TAwsIamUserSecretRotationGeneratedCredentialsResponse
|
||||||
|
| TOktaClientSecretRotationGeneratedCredentialsResponse;
|
||||||
|
|
||||||
export type TCreateSecretRotationV2DTO = DiscriminativePick<
|
export type TCreateSecretRotationV2DTO = DiscriminativePick<
|
||||||
TSecretRotationV2,
|
TSecretRotationV2,
|
||||||
@@ -124,6 +132,7 @@ export type TSecretRotationOptionMap = {
|
|||||||
[SecretRotation.AzureClientSecret]: TAzureClientSecretRotationOption;
|
[SecretRotation.AzureClientSecret]: TAzureClientSecretRotationOption;
|
||||||
[SecretRotation.LdapPassword]: TLdapPasswordRotationOption;
|
[SecretRotation.LdapPassword]: TLdapPasswordRotationOption;
|
||||||
[SecretRotation.AwsIamUserSecret]: TAwsIamUserSecretRotationOption;
|
[SecretRotation.AwsIamUserSecret]: TAwsIamUserSecretRotationOption;
|
||||||
|
[SecretRotation.OktaClientSecret]: TOktaClientSecretRotationOption;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TSecretRotationGeneratedCredentialsResponseMap = {
|
export type TSecretRotationGeneratedCredentialsResponseMap = {
|
||||||
@@ -135,4 +144,5 @@ export type TSecretRotationGeneratedCredentialsResponseMap = {
|
|||||||
[SecretRotation.AzureClientSecret]: TAzureClientSecretRotationGeneratedCredentialsResponse;
|
[SecretRotation.AzureClientSecret]: TAzureClientSecretRotationGeneratedCredentialsResponse;
|
||||||
[SecretRotation.LdapPassword]: TLdapPasswordRotationGeneratedCredentialsResponse;
|
[SecretRotation.LdapPassword]: TLdapPasswordRotationGeneratedCredentialsResponse;
|
||||||
[SecretRotation.AwsIamUserSecret]: TAwsIamUserSecretRotationGeneratedCredentialsResponse;
|
[SecretRotation.AwsIamUserSecret]: TAwsIamUserSecretRotationGeneratedCredentialsResponse;
|
||||||
|
[SecretRotation.OktaClientSecret]: TOktaClientSecretRotationGeneratedCredentialsResponse;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,37 @@
|
|||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
||||||
|
import {
|
||||||
|
TSecretRotationV2Base,
|
||||||
|
TSecretRotationV2GeneratedCredentialsResponseBase
|
||||||
|
} from "@app/hooks/api/secretRotationsV2/types/shared";
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotation = TSecretRotationV2Base & {
|
||||||
|
type: SecretRotation.OktaClientSecret;
|
||||||
|
parameters: {
|
||||||
|
clientId: string;
|
||||||
|
};
|
||||||
|
secretsMapping: {
|
||||||
|
clientId: string;
|
||||||
|
clientSecret: string;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationGeneratedCredentials = {
|
||||||
|
clientId: string;
|
||||||
|
clientSecret: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationGeneratedCredentialsResponse =
|
||||||
|
TSecretRotationV2GeneratedCredentialsResponseBase<
|
||||||
|
SecretRotation.OktaClientSecret,
|
||||||
|
TOktaClientSecretRotationGeneratedCredentials
|
||||||
|
>;
|
||||||
|
|
||||||
|
export type TOktaClientSecretRotationOption = {
|
||||||
|
name: string;
|
||||||
|
type: SecretRotation.OktaClientSecret;
|
||||||
|
connection: AppConnection.Okta;
|
||||||
|
template: {
|
||||||
|
secretsMapping: TOktaClientSecretRotation["secretsMapping"];
|
||||||
|
};
|
||||||
|
};
|
||||||
Reference in New Issue
Block a user