mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 20:27:43 +00:00
Complete Azure integration
This commit is contained in:
@@ -17,7 +17,6 @@ const NODE_ENV = process.env.NODE_ENV! || 'production';
|
|||||||
const VERBOSE_ERROR_OUTPUT = process.env.VERBOSE_ERROR_OUTPUT! === 'true' && true;
|
const VERBOSE_ERROR_OUTPUT = process.env.VERBOSE_ERROR_OUTPUT! === 'true' && true;
|
||||||
const LOKI_HOST = process.env.LOKI_HOST || undefined;
|
const LOKI_HOST = process.env.LOKI_HOST || undefined;
|
||||||
const CLIENT_ID_AZURE = process.env.CLIENT_ID_AZURE!;
|
const CLIENT_ID_AZURE = process.env.CLIENT_ID_AZURE!;
|
||||||
const TENANT_ID_AZURE = process.env.TENANT_ID_AZURE!;
|
|
||||||
const CLIENT_ID_HEROKU = process.env.CLIENT_ID_HEROKU!;
|
const CLIENT_ID_HEROKU = process.env.CLIENT_ID_HEROKU!;
|
||||||
const CLIENT_ID_VERCEL = process.env.CLIENT_ID_VERCEL!;
|
const CLIENT_ID_VERCEL = process.env.CLIENT_ID_VERCEL!;
|
||||||
const CLIENT_ID_NETLIFY = process.env.CLIENT_ID_NETLIFY!;
|
const CLIENT_ID_NETLIFY = process.env.CLIENT_ID_NETLIFY!;
|
||||||
@@ -72,7 +71,6 @@ export {
|
|||||||
VERBOSE_ERROR_OUTPUT,
|
VERBOSE_ERROR_OUTPUT,
|
||||||
LOKI_HOST,
|
LOKI_HOST,
|
||||||
CLIENT_ID_AZURE,
|
CLIENT_ID_AZURE,
|
||||||
TENANT_ID_AZURE,
|
|
||||||
CLIENT_ID_HEROKU,
|
CLIENT_ID_HEROKU,
|
||||||
CLIENT_ID_VERCEL,
|
CLIENT_ID_VERCEL,
|
||||||
CLIENT_ID_NETLIFY,
|
CLIENT_ID_NETLIFY,
|
||||||
|
|||||||
@@ -364,8 +364,8 @@ const exchangeCodeGithub = async ({ code }: { code: string }) => {
|
|||||||
* @param {Object} obj1
|
* @param {Object} obj1
|
||||||
* @param {Object} obj1.code - code for code-token exchange
|
* @param {Object} obj1.code - code for code-token exchange
|
||||||
* @returns {Object} obj2
|
* @returns {Object} obj2
|
||||||
* @returns {String} obj2.accessToken - access token for Github API
|
* @returns {String} obj2.accessToken - access token for Gitlab API
|
||||||
* @returns {String} obj2.refreshToken - refresh token for Github API
|
* @returns {String} obj2.refreshToken - refresh token for Gitlab API
|
||||||
* @returns {Date} obj2.accessExpiresAt - date of expiration for access token
|
* @returns {Date} obj2.accessExpiresAt - date of expiration for access token
|
||||||
*/
|
*/
|
||||||
const exchangeCodeGitlab = async ({ code }: { code: string }) => {
|
const exchangeCodeGitlab = async ({ code }: { code: string }) => {
|
||||||
|
|||||||
@@ -195,17 +195,22 @@ const syncSecretsAzureKeyVault = async ({
|
|||||||
*/
|
*/
|
||||||
const paginateAzureKeyVaultSecrets = async (url: string) => {
|
const paginateAzureKeyVaultSecrets = async (url: string) => {
|
||||||
let result: GetAzureKeyVaultSecret[] = [];
|
let result: GetAzureKeyVaultSecret[] = [];
|
||||||
|
try {
|
||||||
while (url) {
|
while (url) {
|
||||||
const res = await request.get(url, {
|
const res = await request.get(url, {
|
||||||
headers: {
|
headers: {
|
||||||
Authorization: `Bearer ${accessToken}`,
|
Authorization: `Bearer ${accessToken}`
|
||||||
'Accept-Encoding': 'application/json'
|
}
|
||||||
}
|
});
|
||||||
});
|
|
||||||
|
result = result.concat(res.data.value);
|
||||||
|
|
||||||
|
url = res.data.nextLink;
|
||||||
|
}
|
||||||
|
|
||||||
result = result.concat(res.data.value);
|
} catch (err) {
|
||||||
url = res.data.nextLink;
|
Sentry.setUser(null);
|
||||||
|
Sentry.captureException(err);
|
||||||
}
|
}
|
||||||
|
|
||||||
return result;
|
return result;
|
||||||
@@ -221,8 +226,7 @@ const syncSecretsAzureKeyVault = async ({
|
|||||||
|
|
||||||
const azureKeyVaultSecret = await request.get(`${getAzureKeyVaultSecret.id}?api-version=7.3`, {
|
const azureKeyVaultSecret = await request.get(`${getAzureKeyVaultSecret.id}?api-version=7.3`, {
|
||||||
headers: {
|
headers: {
|
||||||
'Authorization': `Bearer ${accessToken}`,
|
'Authorization': `Bearer ${accessToken}`
|
||||||
'Accept-Encoding': 'application/json'
|
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -279,8 +283,7 @@ const syncSecretsAzureKeyVault = async ({
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
headers: {
|
headers: {
|
||||||
Authorization: `Bearer ${accessToken}`,
|
Authorization: `Bearer ${accessToken}`
|
||||||
'Accept-Encoding': 'application/json'
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
@@ -291,8 +294,7 @@ const syncSecretsAzureKeyVault = async ({
|
|||||||
deleteSecrets.forEach(async (secret) => {
|
deleteSecrets.forEach(async (secret) => {
|
||||||
await request.delete(`${integration.app}/secrets/${secret.key}?api-version=7.3`, {
|
await request.delete(`${integration.app}/secrets/${secret.key}?api-version=7.3`, {
|
||||||
headers: {
|
headers: {
|
||||||
'Authorization': `Bearer ${accessToken}`,
|
'Authorization': `Bearer ${accessToken}`
|
||||||
'Accept-Encoding': 'application/json'
|
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
import {
|
import {
|
||||||
CLIENT_ID_AZURE,
|
CLIENT_ID_AZURE,
|
||||||
CLIENT_ID_GITLAB,
|
CLIENT_ID_GITLAB
|
||||||
TENANT_ID_AZURE
|
|
||||||
} from '../config';
|
} from '../config';
|
||||||
import {
|
import {
|
||||||
CLIENT_ID_HEROKU,
|
CLIENT_ID_HEROKU,
|
||||||
CLIENT_ID_NETLIFY,
|
CLIENT_ID_NETLIFY,
|
||||||
CLIENT_ID_GITHUB,
|
CLIENT_ID_GITHUB,
|
||||||
CLIENT_SLUG_VERCEL,
|
CLIENT_SLUG_VERCEL
|
||||||
CLIENT_SECRET_GITLAB,
|
|
||||||
} from "../config";
|
} from "../config";
|
||||||
|
|
||||||
// integrations
|
// integrations
|
||||||
@@ -41,7 +39,7 @@ const INTEGRATION_SET = new Set([
|
|||||||
const INTEGRATION_OAUTH2 = "oauth2";
|
const INTEGRATION_OAUTH2 = "oauth2";
|
||||||
|
|
||||||
// integration oauth endpoints
|
// integration oauth endpoints
|
||||||
const INTEGRATION_AZURE_TOKEN_URL = `https://login.microsoftonline.com/${TENANT_ID_AZURE}/oauth2/v2.0/token`;
|
const INTEGRATION_AZURE_TOKEN_URL = `https://login.microsoftonline.com/common/oauth2/v2.0/token`;
|
||||||
const INTEGRATION_HEROKU_TOKEN_URL = 'https://id.heroku.com/oauth/token';
|
const INTEGRATION_HEROKU_TOKEN_URL = 'https://id.heroku.com/oauth/token';
|
||||||
const INTEGRATION_VERCEL_TOKEN_URL =
|
const INTEGRATION_VERCEL_TOKEN_URL =
|
||||||
"https://api.vercel.com/v2/oauth/access_token";
|
"https://api.vercel.com/v2/oauth/access_token";
|
||||||
@@ -99,15 +97,6 @@ const INTEGRATION_OPTIONS = [
|
|||||||
clientId: CLIENT_ID_GITHUB,
|
clientId: CLIENT_ID_GITHUB,
|
||||||
docsLink: ''
|
docsLink: ''
|
||||||
},
|
},
|
||||||
{
|
|
||||||
name: 'GitLab',
|
|
||||||
slug: 'gitlab',
|
|
||||||
image: 'GitLab.png',
|
|
||||||
isAvailable: true,
|
|
||||||
type: 'oauth',
|
|
||||||
clientId: CLIENT_ID_GITLAB,
|
|
||||||
docsLink: ''
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
name: 'Render',
|
name: 'Render',
|
||||||
slug: 'render',
|
slug: 'render',
|
||||||
@@ -144,6 +133,15 @@ const INTEGRATION_OPTIONS = [
|
|||||||
clientId: '',
|
clientId: '',
|
||||||
docsLink: ''
|
docsLink: ''
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: 'Azure Key Vault',
|
||||||
|
slug: 'azure-key-vault',
|
||||||
|
image: 'Microsoft Azure.png',
|
||||||
|
isAvailable: true,
|
||||||
|
type: 'oauth',
|
||||||
|
clientId: CLIENT_ID_AZURE,
|
||||||
|
docsLink: ''
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: 'Circle CI',
|
name: 'Circle CI',
|
||||||
slug: 'circleci',
|
slug: 'circleci',
|
||||||
@@ -153,6 +151,15 @@ const INTEGRATION_OPTIONS = [
|
|||||||
clientId: '',
|
clientId: '',
|
||||||
docsLink: ''
|
docsLink: ''
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: 'GitLab',
|
||||||
|
slug: 'gitlab',
|
||||||
|
image: 'GitLab.png',
|
||||||
|
isAvailable: true,
|
||||||
|
type: 'oauth',
|
||||||
|
clientId: CLIENT_ID_GITLAB,
|
||||||
|
docsLink: ''
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: 'Travis CI',
|
name: 'Travis CI',
|
||||||
slug: 'travisci',
|
slug: 'travisci',
|
||||||
@@ -162,16 +169,6 @@ const INTEGRATION_OPTIONS = [
|
|||||||
clientId: '',
|
clientId: '',
|
||||||
docsLink: ''
|
docsLink: ''
|
||||||
},
|
},
|
||||||
{
|
|
||||||
name: 'Azure Key Vault',
|
|
||||||
slug: 'azure-key-vault',
|
|
||||||
image: 'Microsoft Azure.png',
|
|
||||||
isAvailable: false,
|
|
||||||
type: 'oauth',
|
|
||||||
clientId: CLIENT_ID_AZURE,
|
|
||||||
tenantId: TENANT_ID_AZURE,
|
|
||||||
docsLink: ''
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
name: 'Google Cloud Platform',
|
name: 'Google Cloud Platform',
|
||||||
slug: 'gcp',
|
slug: 'gcp',
|
||||||
|
|||||||
@@ -172,7 +172,7 @@ export default function Integrations() {
|
|||||||
let link = '';
|
let link = '';
|
||||||
switch (integrationOption.slug) {
|
switch (integrationOption.slug) {
|
||||||
case 'azure-key-vault':
|
case 'azure-key-vault':
|
||||||
link = `https://login.microsoftonline.com/${integrationOption.tenantId}/oauth2/v2.0/authorize?client_id=${integrationOption.clientId}&response_type=code&redirect_uri=${window.location.origin}/integrations/azure-key-vault/oauth2/callback&response_mode=query&scope=https://vault.azure.net/.default openid offline_access&state=${state}`;
|
link = `https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=${integrationOption.clientId}&response_type=code&redirect_uri=${window.location.origin}/integrations/azure-key-vault/oauth2/callback&response_mode=query&scope=https://vault.azure.net/.default openid offline_access&state=${state}`;
|
||||||
break;
|
break;
|
||||||
case 'aws-parameter-store':
|
case 'aws-parameter-store':
|
||||||
link = `${window.location.origin}/integrations/aws-parameter-store/authorize`;
|
link = `${window.location.origin}/integrations/aws-parameter-store/authorize`;
|
||||||
|
|||||||
Reference in New Issue
Block a user