mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 12:27:31 +00:00
Fix: Remove org ID from JWT
This commit is contained in:
@@ -121,10 +121,7 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
|
|||||||
switch (authMode) {
|
switch (authMode) {
|
||||||
// May or may not have an orgId. If it doesn't have an org ID, it's likely because the token is from an org that doesn't enforce org-level auth.
|
// May or may not have an orgId. If it doesn't have an org ID, it's likely because the token is from an org that doesn't enforce org-level auth.
|
||||||
case AuthMode.JWT: {
|
case AuthMode.JWT: {
|
||||||
const { user, tokenVersionId, orgId } = await server.services.authToken.fnValidateJwtIdentity(
|
const { user, tokenVersionId, orgId } = await server.services.authToken.fnValidateJwtIdentity(token);
|
||||||
token,
|
|
||||||
req.headers?.["x-infisical-organization-id"]
|
|
||||||
);
|
|
||||||
req.auth = { authMode: AuthMode.JWT, user, userId: user.id, tokenVersionId, actor, orgId };
|
req.auth = { authMode: AuthMode.JWT, user, userId: user.id, tokenVersionId, actor, orgId };
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -264,7 +264,7 @@ export const registerRoutes = async (
|
|||||||
queueService
|
queueService
|
||||||
});
|
});
|
||||||
|
|
||||||
const tokenService = tokenServiceFactory({ tokenDAL: authTokenDAL, userDAL, orgDAL });
|
const tokenService = tokenServiceFactory({ tokenDAL: authTokenDAL, userDAL });
|
||||||
const userService = userServiceFactory({ userDAL });
|
const userService = userServiceFactory({ userDAL });
|
||||||
const loginService = authLoginServiceFactory({ userDAL, smtpService, tokenService });
|
const loginService = authLoginServiceFactory({ userDAL, smtpService, tokenService });
|
||||||
const passwordService = authPaswordServiceFactory({
|
const passwordService = authPaswordServiceFactory({
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import { getConfig } from "@app/lib/config/env";
|
|||||||
import { UnauthorizedError } from "@app/lib/errors";
|
import { UnauthorizedError } from "@app/lib/errors";
|
||||||
|
|
||||||
import { AuthModeJwtTokenPayload } from "../auth/auth-type";
|
import { AuthModeJwtTokenPayload } from "../auth/auth-type";
|
||||||
import { TOrgDALFactory } from "../org/org-dal";
|
|
||||||
import { TUserDALFactory } from "../user/user-dal";
|
import { TUserDALFactory } from "../user/user-dal";
|
||||||
import { TTokenDALFactory } from "./auth-token-dal";
|
import { TTokenDALFactory } from "./auth-token-dal";
|
||||||
import { TCreateTokenForUserDTO, TIssueAuthTokenDTO, TokenType, TValidateTokenForUserDTO } from "./auth-token-types";
|
import { TCreateTokenForUserDTO, TIssueAuthTokenDTO, TokenType, TValidateTokenForUserDTO } from "./auth-token-types";
|
||||||
@@ -15,7 +14,6 @@ import { TCreateTokenForUserDTO, TIssueAuthTokenDTO, TokenType, TValidateTokenFo
|
|||||||
type TAuthTokenServiceFactoryDep = {
|
type TAuthTokenServiceFactoryDep = {
|
||||||
tokenDAL: TTokenDALFactory;
|
tokenDAL: TTokenDALFactory;
|
||||||
userDAL: Pick<TUserDALFactory, "findById">;
|
userDAL: Pick<TUserDALFactory, "findById">;
|
||||||
orgDAL: Pick<TOrgDALFactory, "findMembership">;
|
|
||||||
};
|
};
|
||||||
export type TAuthTokenServiceFactory = ReturnType<typeof tokenServiceFactory>;
|
export type TAuthTokenServiceFactory = ReturnType<typeof tokenServiceFactory>;
|
||||||
|
|
||||||
@@ -56,7 +54,7 @@ export const getTokenConfig = (tokenType: TokenType) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
export const tokenServiceFactory = ({ tokenDAL, userDAL, orgDAL }: TAuthTokenServiceFactoryDep) => {
|
export const tokenServiceFactory = ({ tokenDAL, userDAL }: TAuthTokenServiceFactoryDep) => {
|
||||||
const createTokenForUser = async ({ type, userId, orgId }: TCreateTokenForUserDTO) => {
|
const createTokenForUser = async ({ type, userId, orgId }: TCreateTokenForUserDTO) => {
|
||||||
const { token, ...tkCfg } = getTokenConfig(type);
|
const { token, ...tkCfg } = getTokenConfig(type);
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
@@ -132,7 +130,7 @@ export const tokenServiceFactory = ({ tokenDAL, userDAL, orgDAL }: TAuthTokenSer
|
|||||||
const revokeAllMySessions = async (userId: string) => tokenDAL.deleteTokenSession({ userId });
|
const revokeAllMySessions = async (userId: string) => tokenDAL.deleteTokenSession({ userId });
|
||||||
|
|
||||||
// to parse jwt identity in inject identity plugin
|
// to parse jwt identity in inject identity plugin
|
||||||
const fnValidateJwtIdentity = async (token: AuthModeJwtTokenPayload, organizationIdHeader?: string | string[]) => {
|
const fnValidateJwtIdentity = async (token: AuthModeJwtTokenPayload) => {
|
||||||
const session = await tokenDAL.findOneTokenSession({
|
const session = await tokenDAL.findOneTokenSession({
|
||||||
id: token.tokenVersionId,
|
id: token.tokenVersionId,
|
||||||
userId: token.userId
|
userId: token.userId
|
||||||
@@ -143,22 +141,7 @@ export const tokenServiceFactory = ({ tokenDAL, userDAL, orgDAL }: TAuthTokenSer
|
|||||||
const user = await userDAL.findById(session.userId);
|
const user = await userDAL.findById(session.userId);
|
||||||
if (!user || !user.isAccepted) throw new UnauthorizedError({ name: "Token user not found" });
|
if (!user || !user.isAccepted) throw new UnauthorizedError({ name: "Token user not found" });
|
||||||
|
|
||||||
let orgId = token.organizationId;
|
return { user, tokenVersionId: token.tokenVersionId, orgId: token.organizationId };
|
||||||
if (!token.organizationId && organizationIdHeader) {
|
|
||||||
// If the token doesn't have an organization ID, but an organization ID is provided in the header, we need to check if the user is a member of the organization before concluding the organization ID is valid.
|
|
||||||
const userMembership = (
|
|
||||||
await orgDAL.findMembership({
|
|
||||||
userId: user.id,
|
|
||||||
orgId: organizationIdHeader as string
|
|
||||||
})
|
|
||||||
)[0];
|
|
||||||
|
|
||||||
if (!userMembership) throw new UnauthorizedError({ name: "User not a member of the organization" });
|
|
||||||
|
|
||||||
orgId = userMembership.orgId;
|
|
||||||
}
|
|
||||||
|
|
||||||
return { user, tokenVersionId: token.tokenVersionId, orgId };
|
|
||||||
};
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
|
|||||||
@@ -15,14 +15,8 @@ apiRequest.interceptors.request.use((config) => {
|
|||||||
const mfaTempToken = getMfaTempToken();
|
const mfaTempToken = getMfaTempToken();
|
||||||
const token = getAuthToken();
|
const token = getAuthToken();
|
||||||
const providerAuthToken = SecurityClient.getProviderAuthToken();
|
const providerAuthToken = SecurityClient.getProviderAuthToken();
|
||||||
const organizationId = localStorage.getItem("orgData.id");
|
|
||||||
|
|
||||||
if (config.headers) {
|
if (config.headers) {
|
||||||
if (organizationId) {
|
|
||||||
// eslint-disable-next-line no-param-reassign
|
|
||||||
config.headers["x-infisical-organization-id"] = organizationId;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (signupTempToken) {
|
if (signupTempToken) {
|
||||||
// eslint-disable-next-line no-param-reassign
|
// eslint-disable-next-line no-param-reassign
|
||||||
config.headers.Authorization = `Bearer ${signupTempToken}`;
|
config.headers.Authorization = `Bearer ${signupTempToken}`;
|
||||||
|
|||||||
Reference in New Issue
Block a user