mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #481 from quinton11/feat/multi-profile
feat: CLI support for switching between multiple logged in user accounts
This commit is contained in:
@@ -10,9 +10,11 @@ import (
|
||||
|
||||
"errors"
|
||||
"fmt"
|
||||
"net/url"
|
||||
"regexp"
|
||||
|
||||
"github.com/Infisical/infisical-merge/packages/api"
|
||||
"github.com/Infisical/infisical-merge/packages/config"
|
||||
"github.com/Infisical/infisical-merge/packages/crypto"
|
||||
"github.com/Infisical/infisical-merge/packages/models"
|
||||
"github.com/Infisical/infisical-merge/packages/srp"
|
||||
@@ -33,6 +35,10 @@ type params struct {
|
||||
keyLength uint32
|
||||
}
|
||||
|
||||
const ADD_USER = "Add a new account login"
|
||||
const REPLACE_USER = "Override current logged in user"
|
||||
const EXIT_USER_MENU = "Exit"
|
||||
|
||||
// loginCmd represents the login command
|
||||
var loginCmd = &cobra.Command{
|
||||
Use: "login",
|
||||
@@ -49,7 +55,7 @@ var loginCmd = &cobra.Command{
|
||||
}
|
||||
|
||||
if currentLoggedInUserDetails.IsUserLoggedIn && !currentLoggedInUserDetails.LoginExpired && len(currentLoggedInUserDetails.UserCredentials.PrivateKey) != 0 {
|
||||
shouldOverride, err := shouldOverrideLoginPrompt(currentLoggedInUserDetails.UserCredentials.Email)
|
||||
shouldOverride, err := userLoginMenu(currentLoggedInUserDetails.UserCredentials.Email)
|
||||
if err != nil {
|
||||
util.HandleError(err)
|
||||
}
|
||||
@@ -59,6 +65,31 @@ var loginCmd = &cobra.Command{
|
||||
}
|
||||
}
|
||||
|
||||
//override domain
|
||||
domainQuery := true
|
||||
if config.INFISICAL_URL_MANUAL_OVERRIDE != util.INFISICAL_DEFAULT_API_URL {
|
||||
overrideDomain, err := DomainOverridePrompt()
|
||||
if err != nil {
|
||||
util.HandleError(err)
|
||||
}
|
||||
|
||||
//if not override set INFISICAL_URL to exported var
|
||||
//set domainQuery to false
|
||||
if !overrideDomain {
|
||||
domainQuery = false
|
||||
config.INFISICAL_URL = config.INFISICAL_URL_MANUAL_OVERRIDE
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
//prompt user to select domain between Infisical cloud and self hosting
|
||||
if domainQuery {
|
||||
err = askForDomain()
|
||||
if err != nil {
|
||||
util.HandleError(err, "Unable to parse domain url")
|
||||
}
|
||||
}
|
||||
|
||||
email, password, err := askForLoginCredentials()
|
||||
if err != nil {
|
||||
util.HandleError(err, "Unable to parse email and password for authentication")
|
||||
@@ -252,6 +283,77 @@ func init() {
|
||||
rootCmd.AddCommand(loginCmd)
|
||||
}
|
||||
|
||||
func DomainOverridePrompt() (bool, error) {
|
||||
var (
|
||||
PRESET = "Use Domain"
|
||||
OVERRIDE = "Change Domain"
|
||||
)
|
||||
|
||||
options := []string{PRESET, OVERRIDE}
|
||||
optionsPrompt := promptui.Select{
|
||||
Label: fmt.Sprintf("Current INFISICAL_API_URL Domain Override: %s", config.INFISICAL_URL_MANUAL_OVERRIDE),
|
||||
Items: options,
|
||||
Size: 2,
|
||||
}
|
||||
|
||||
_, selectedOption, err := optionsPrompt.Run()
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
return selectedOption == OVERRIDE, err
|
||||
}
|
||||
|
||||
func askForDomain() error {
|
||||
//query user to choose between Infisical cloud or self hosting
|
||||
var (
|
||||
INFISICAL_CLOUD = "Infisical Cloud"
|
||||
SELF_HOSTING = "Self Hosting"
|
||||
)
|
||||
|
||||
options := []string{INFISICAL_CLOUD, SELF_HOSTING}
|
||||
optionsPrompt := promptui.Select{
|
||||
Label: "Select your hosting option",
|
||||
Items: options,
|
||||
Size: 2,
|
||||
}
|
||||
|
||||
_, selectedHostingOption, err := optionsPrompt.Run()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if selectedHostingOption == INFISICAL_CLOUD {
|
||||
//cloud option
|
||||
config.INFISICAL_URL = util.INFISICAL_DEFAULT_API_URL
|
||||
return nil
|
||||
}
|
||||
|
||||
urlValidation := func(input string) error {
|
||||
_, err := url.ParseRequestURI(input)
|
||||
if err != nil {
|
||||
return errors.New("this is an invalid url")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
domainPrompt := promptui.Prompt{
|
||||
Label: "Domain",
|
||||
Validate: urlValidation,
|
||||
Default: "Example - https://my-self-hosted-instance.com/api",
|
||||
}
|
||||
|
||||
domain, err := domainPrompt.Run()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
//set api url
|
||||
config.INFISICAL_URL = domain
|
||||
//return nil
|
||||
return nil
|
||||
}
|
||||
|
||||
func askForLoginCredentials() (email string, password string, err error) {
|
||||
validateEmail := func(input string) error {
|
||||
matched, err := regexp.MatchString("^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\\.[a-zA-Z0-9-.]+$", input)
|
||||
@@ -342,16 +444,18 @@ func getFreshUserCredentials(email string, password string) (*api.GetLoginOneV2R
|
||||
return &loginOneResponseResult, &loginTwoResponseResult, nil
|
||||
}
|
||||
|
||||
func shouldOverrideLoginPrompt(currentLoggedInUserEmail string) (bool, error) {
|
||||
func userLoginMenu(currentLoggedInUserEmail string) (bool, error) {
|
||||
label := fmt.Sprintf("Current logged in user email: %s on domain: %s", currentLoggedInUserEmail, config.INFISICAL_URL)
|
||||
|
||||
prompt := promptui.Select{
|
||||
Label: fmt.Sprintf("There seems to be a user already logged in with the email: %s. Would you like to override that login? Select[Yes/No]", currentLoggedInUserEmail),
|
||||
Items: []string{"No", "Yes"},
|
||||
Label: label,
|
||||
Items: []string{ADD_USER, REPLACE_USER, EXIT_USER_MENU},
|
||||
}
|
||||
_, result, err := prompt.Run()
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
return result == "Yes", err
|
||||
return result != EXIT_USER_MENU, err
|
||||
}
|
||||
|
||||
func generateFromPassword(password string, salt []byte, p *params) (hash []byte, err error) {
|
||||
|
||||
248
cli/packages/cmd/user.go
Normal file
248
cli/packages/cmd/user.go
Normal file
@@ -0,0 +1,248 @@
|
||||
package cmd
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/url"
|
||||
|
||||
"github.com/Infisical/infisical-merge/packages/config"
|
||||
"github.com/Infisical/infisical-merge/packages/models"
|
||||
"github.com/Infisical/infisical-merge/packages/util"
|
||||
"github.com/manifoldco/promptui"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
var userCmd = &cobra.Command{
|
||||
Use: "user",
|
||||
Short: "Used to manage user credentials",
|
||||
DisableFlagsInUseLine: true,
|
||||
Example: "infisical user",
|
||||
Args: cobra.ExactArgs(0),
|
||||
Run: func(cmd *cobra.Command, args []string) {},
|
||||
}
|
||||
|
||||
var switchCmd = &cobra.Command{
|
||||
Use: "switch",
|
||||
Short: "Used to switch between Infisical profiles",
|
||||
DisableFlagsInUseLine: true,
|
||||
Example: "infisical switch",
|
||||
Args: cobra.ExactArgs(0),
|
||||
PreRun: func(cmd *cobra.Command, args []string) {
|
||||
util.RequireLogin()
|
||||
},
|
||||
Run: func(cmd *cobra.Command, args []string) {
|
||||
//get previous logged in profiles
|
||||
loggedInProfiles, err := getLoggedInUsers()
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user switch]: Unable to get logged Profiles")
|
||||
}
|
||||
|
||||
//prompt user
|
||||
profile, err := LoggedInUsersPrompt(loggedInProfiles)
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user switch]: Prompt error")
|
||||
}
|
||||
|
||||
//write to config file
|
||||
configFile, err := util.GetConfigFile()
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user switch]: Unable to get config file")
|
||||
}
|
||||
|
||||
configFile.LoggedInUserEmail = profile
|
||||
|
||||
//set logged in user domain
|
||||
ok := util.ConfigContainsEmail(configFile.LoggedInUsers, profile)
|
||||
|
||||
if !ok {
|
||||
//profile not in loggedInUsers
|
||||
configFile.LoggedInUsers = append(configFile.LoggedInUsers, models.LoggedInUser{
|
||||
Email: profile,
|
||||
Domain: config.INFISICAL_URL,
|
||||
})
|
||||
//set logged in user domain
|
||||
configFile.LoggedInUserDomain = config.INFISICAL_URL
|
||||
|
||||
} else {
|
||||
//exists, set logged in user domain
|
||||
for _, v := range configFile.LoggedInUsers {
|
||||
if profile == v.Email {
|
||||
configFile.LoggedInUserDomain = v.Domain
|
||||
break
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
err = util.WriteConfigFile(&configFile)
|
||||
if err != nil {
|
||||
util.HandleError(err, "")
|
||||
}
|
||||
},
|
||||
}
|
||||
|
||||
var updateCmd = &cobra.Command{
|
||||
Use: "update",
|
||||
Short: "Used to update properties of an Infisical profile",
|
||||
DisableFlagsInUseLine: true,
|
||||
Example: "infisical user update",
|
||||
Args: cobra.ExactArgs(0),
|
||||
Run: func(cmd *cobra.Command, args []string) {},
|
||||
}
|
||||
|
||||
var domainCmd = &cobra.Command{
|
||||
Use: "domain",
|
||||
Short: "Used to update the domain of an Infisical profile",
|
||||
DisableFlagsInUseLine: true,
|
||||
Example: "infisical user update domain",
|
||||
Args: cobra.ExactArgs(0),
|
||||
PreRun: func(cmd *cobra.Command, args []string) {
|
||||
util.RequireLogin()
|
||||
},
|
||||
Run: func(cmd *cobra.Command, args []string) {
|
||||
//prompt for profiles selection
|
||||
loggedInProfiles, err := getLoggedInUsers()
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user update domain]: Unable to get logged Profiles")
|
||||
}
|
||||
|
||||
//prompt user
|
||||
profile, err := LoggedInUsersPrompt(loggedInProfiles)
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user update domain]: Prompt error")
|
||||
}
|
||||
|
||||
domain := ""
|
||||
domainQuery := true
|
||||
if config.INFISICAL_URL_MANUAL_OVERRIDE != util.INFISICAL_DEFAULT_API_URL {
|
||||
|
||||
override, err := DomainOverridePrompt()
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user update domain]: Domain override prompt error")
|
||||
}
|
||||
|
||||
if !override {
|
||||
domainQuery = false
|
||||
domain = config.INFISICAL_URL_MANUAL_OVERRIDE
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
if domainQuery {
|
||||
//prompt to update domain
|
||||
domain, err = NewDomainPrompt()
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user update domain]: Prompt error")
|
||||
}
|
||||
}
|
||||
|
||||
//write to config file
|
||||
configFile, err := util.GetConfigFile()
|
||||
if err != nil {
|
||||
util.HandleError(err, "[infisical user update domain]: Unable to get config file")
|
||||
}
|
||||
|
||||
//check if profile in logged in profiles
|
||||
|
||||
//if not add new profile loggedInUsers
|
||||
//else update profile from loggedinUsers slice
|
||||
ok := util.ConfigContainsEmail(configFile.LoggedInUsers, profile)
|
||||
if !ok {
|
||||
configFile.LoggedInUsers = append(configFile.LoggedInUsers, models.LoggedInUser{
|
||||
Email: profile,
|
||||
Domain: domain,
|
||||
})
|
||||
} else {
|
||||
//exists, set logged in user domain
|
||||
for idx, v := range configFile.LoggedInUsers {
|
||||
if profile == v.Email {
|
||||
configFile.LoggedInUsers[idx].Domain = domain //inplace
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
//check if current loggedinuser is selected profile
|
||||
//if yes set current domain to changed domain
|
||||
if configFile.LoggedInUserEmail == profile {
|
||||
configFile.LoggedInUserDomain = domain
|
||||
}
|
||||
|
||||
err = util.WriteConfigFile(&configFile)
|
||||
if err != nil {
|
||||
util.HandleError(err, "")
|
||||
}
|
||||
|
||||
},
|
||||
}
|
||||
|
||||
func init() {
|
||||
updateCmd.AddCommand(domainCmd)
|
||||
userCmd.AddCommand(updateCmd)
|
||||
userCmd.AddCommand(switchCmd)
|
||||
rootCmd.AddCommand(userCmd)
|
||||
}
|
||||
|
||||
// This returns all logged in user emails from the config file.
|
||||
// If none, it returns the current logged in user in a slice
|
||||
func getLoggedInUsers() ([]string, error) {
|
||||
loggedInProfiles := []string{}
|
||||
|
||||
if util.ConfigFileExists() {
|
||||
configFile, err := util.GetConfigFile()
|
||||
if err != nil {
|
||||
return loggedInProfiles, err
|
||||
}
|
||||
|
||||
//get logged in profiles
|
||||
//
|
||||
if len(configFile.LoggedInUsers) > 0 {
|
||||
for _, v := range configFile.LoggedInUsers {
|
||||
loggedInProfiles = append(loggedInProfiles, v.Email)
|
||||
}
|
||||
} else {
|
||||
|
||||
loggedInProfiles = append(loggedInProfiles, configFile.LoggedInUserEmail)
|
||||
}
|
||||
return loggedInProfiles, nil
|
||||
} else {
|
||||
//empty
|
||||
return loggedInProfiles, errors.New("couldn't retrieve config file")
|
||||
}
|
||||
}
|
||||
|
||||
func NewDomainPrompt() (string, error) {
|
||||
urlValidation := func(input string) error {
|
||||
_, err := url.ParseRequestURI(input)
|
||||
if err != nil {
|
||||
return errors.New("this is an invalid url")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
//else run prompt to enter domain
|
||||
domainPrompt := promptui.Prompt{
|
||||
Label: "New Domain",
|
||||
Validate: urlValidation,
|
||||
Default: "Example - https://my-self-hosted-instance.com/api",
|
||||
}
|
||||
|
||||
domain, err := domainPrompt.Run()
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
return domain, nil
|
||||
}
|
||||
|
||||
func LoggedInUsersPrompt(profiles []string) (string, error) {
|
||||
prompt := promptui.Select{Label: "Which of your Infisical profiles would you like to use",
|
||||
Items: profiles,
|
||||
Size: 7,
|
||||
}
|
||||
|
||||
idx, _, err := prompt.Run()
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
return profiles[idx], nil
|
||||
}
|
||||
@@ -1,3 +1,4 @@
|
||||
package config
|
||||
|
||||
var INFISICAL_URL string
|
||||
var INFISICAL_URL_MANUAL_OVERRIDE string
|
||||
|
||||
@@ -12,8 +12,15 @@ type UserCredentials struct {
|
||||
|
||||
// The file struct for Infisical config file
|
||||
type ConfigFile struct {
|
||||
LoggedInUserEmail string `json:"loggedInUserEmail"`
|
||||
VaultBackendType keyring.BackendType `json:"vaultBackendType"`
|
||||
LoggedInUserEmail string `json:"loggedInUserEmail"`
|
||||
LoggedInUserDomain string `json:"LoggedInUserDomain,omitempty"`
|
||||
VaultBackendType keyring.BackendType `json:"vaultBackendType"`
|
||||
LoggedInUsers []LoggedInUser `json:"loggedInUsers,omitempty"`
|
||||
}
|
||||
|
||||
type LoggedInUser struct {
|
||||
Email string `json:"email"`
|
||||
Domain string `json:"domain"`
|
||||
}
|
||||
|
||||
type SingleEnvironmentVariable struct {
|
||||
|
||||
@@ -23,8 +23,5 @@ func WriteToFile(fileName string, dataToWrite []byte, filePerm os.FileMode) erro
|
||||
|
||||
func CheckIsConnectedToInternet() (ok bool) {
|
||||
_, err := http.Get("http://clients3.google.com/generate_204")
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
return true
|
||||
return err == nil
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/Infisical/infisical-merge/packages/config"
|
||||
"github.com/Infisical/infisical-merge/packages/models"
|
||||
log "github.com/sirupsen/logrus"
|
||||
)
|
||||
@@ -31,9 +32,29 @@ func WriteInitalConfig(userCredentials *models.UserCredentials) error {
|
||||
return fmt.Errorf("writeInitalConfig: unable to write config file because [err=%s]", err)
|
||||
}
|
||||
|
||||
//if profiles exists
|
||||
loggedInUser := models.LoggedInUser{
|
||||
Email: userCredentials.Email,
|
||||
Domain: config.INFISICAL_URL,
|
||||
}
|
||||
//if empty or if email not in loggedinUsers
|
||||
if len(existingConfigFile.LoggedInUsers) == 0 || !ConfigContainsEmail(existingConfigFile.LoggedInUsers, userCredentials.Email) {
|
||||
|
||||
existingConfigFile.LoggedInUsers = append(existingConfigFile.LoggedInUsers, loggedInUser)
|
||||
} else {
|
||||
//if exists update domain of loggedin users
|
||||
for idx, user := range existingConfigFile.LoggedInUsers {
|
||||
if user.Email == userCredentials.Email {
|
||||
existingConfigFile.LoggedInUsers[idx] = loggedInUser
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
configFile := models.ConfigFile{
|
||||
LoggedInUserEmail: userCredentials.Email,
|
||||
VaultBackendType: existingConfigFile.VaultBackendType,
|
||||
LoggedInUserEmail: userCredentials.Email,
|
||||
LoggedInUserDomain: config.INFISICAL_URL,
|
||||
VaultBackendType: existingConfigFile.VaultBackendType,
|
||||
LoggedInUsers: existingConfigFile.LoggedInUsers,
|
||||
}
|
||||
|
||||
configFileMarshalled, err := json.Marshal(configFile)
|
||||
@@ -176,7 +197,7 @@ func GetConfigFile() (models.ConfigFile, error) {
|
||||
return configFile, nil
|
||||
}
|
||||
|
||||
// Write a ConfigFile to disk. Raise error if unable to save the model to ask
|
||||
// Write a ConfigFile to disk. Raise error if unable to save the model to disk
|
||||
func WriteConfigFile(configFile *models.ConfigFile) error {
|
||||
fullConfigFilePath, fullConfigFileDirPath, err := GetFullConfigFilePath()
|
||||
if err != nil {
|
||||
|
||||
@@ -6,6 +6,7 @@ import (
|
||||
|
||||
"github.com/99designs/keyring"
|
||||
"github.com/Infisical/infisical-merge/packages/api"
|
||||
"github.com/Infisical/infisical-merge/packages/config"
|
||||
"github.com/Infisical/infisical-merge/packages/models"
|
||||
"github.com/go-resty/resty/v2"
|
||||
)
|
||||
@@ -87,6 +88,13 @@ func GetCurrentLoggedInUserDetails() (LoggedInUserDetails, error) {
|
||||
SetAuthToken(userCreds.JTWToken).
|
||||
SetHeader("Accept", "application/json")
|
||||
|
||||
config.INFISICAL_URL_MANUAL_OVERRIDE = config.INFISICAL_URL
|
||||
//configFile.LoggedInUserDomain
|
||||
//if not empty set as infisical url
|
||||
if configFile.LoggedInUserDomain != "" {
|
||||
config.INFISICAL_URL = configFile.LoggedInUserDomain
|
||||
}
|
||||
|
||||
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
||||
if !isAuthenticated {
|
||||
return LoggedInUserDetails{
|
||||
|
||||
@@ -9,6 +9,8 @@ import (
|
||||
"os/exec"
|
||||
"path"
|
||||
"strings"
|
||||
|
||||
"github.com/Infisical/infisical-merge/packages/models"
|
||||
)
|
||||
|
||||
type DecodedSymmetricEncryptionDetails = struct {
|
||||
@@ -61,6 +63,16 @@ func IsSecretTypeValid(s string) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
// Checks if the passed in email already exists in the users slice
|
||||
func ConfigContainsEmail(users []models.LoggedInUser, email string) bool {
|
||||
for _, value := range users {
|
||||
if value.Email == email {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func RequireLogin() {
|
||||
currentUserDetails, err := GetCurrentLoggedInUserDetails()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user