mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Chore: Export Cli login interface
This commit is contained in:
@@ -11,14 +11,14 @@ import SecurityClient from "./SecurityClient";
|
|||||||
// eslint-disable-next-line new-cap
|
// eslint-disable-next-line new-cap
|
||||||
const client = new jsrp.client();
|
const client = new jsrp.client();
|
||||||
|
|
||||||
interface IsCliLoginSuccessful {
|
export interface IsCliLoginSuccessful {
|
||||||
mfaEnabled: boolean;
|
mfaEnabled: boolean;
|
||||||
loginResponse?: {
|
loginResponse?: {
|
||||||
email: string;
|
email: string;
|
||||||
privateKey: string;
|
privateKey: string;
|
||||||
JTWToken: string;
|
JTWToken: string;
|
||||||
};
|
};
|
||||||
success: boolean;
|
success: boolean;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -27,123 +27,117 @@ interface IsCliLoginSuccessful {
|
|||||||
* @param {string} email - email of user to log in
|
* @param {string} email - email of user to log in
|
||||||
* @param {string} password - password of user to log in
|
* @param {string} password - password of user to log in
|
||||||
*/
|
*/
|
||||||
const attemptLogin = async (
|
const attemptLogin = async ({
|
||||||
{
|
email,
|
||||||
email,
|
password,
|
||||||
password,
|
providerAuthToken
|
||||||
providerAuthToken,
|
}: {
|
||||||
}: {
|
email: string;
|
||||||
email: string;
|
password: string;
|
||||||
password: string;
|
providerAuthToken?: string;
|
||||||
providerAuthToken?: string;
|
}): Promise<IsCliLoginSuccessful> => {
|
||||||
}
|
const telemetry = new Telemetry().getInstance();
|
||||||
): Promise<IsCliLoginSuccessful> => {
|
return new Promise((resolve, reject) => {
|
||||||
|
client.init(
|
||||||
|
{
|
||||||
|
username: email,
|
||||||
|
password
|
||||||
|
},
|
||||||
|
async () => {
|
||||||
|
try {
|
||||||
|
const clientPublicKey = client.getPublicKey();
|
||||||
|
const { serverPublicKey, salt } = await login1({
|
||||||
|
email,
|
||||||
|
clientPublicKey,
|
||||||
|
providerAuthToken
|
||||||
|
});
|
||||||
|
|
||||||
const telemetry = new Telemetry().getInstance();
|
client.setSalt(salt);
|
||||||
return new Promise((resolve, reject) => {
|
client.setServerPublicKey(serverPublicKey);
|
||||||
client.init(
|
const clientProof = client.getProof(); // called M1
|
||||||
{
|
|
||||||
username: email,
|
|
||||||
password
|
|
||||||
},
|
|
||||||
async () => {
|
|
||||||
try {
|
|
||||||
const clientPublicKey = client.getPublicKey();
|
|
||||||
const { serverPublicKey, salt } = await login1({
|
|
||||||
email,
|
|
||||||
clientPublicKey,
|
|
||||||
providerAuthToken,
|
|
||||||
});
|
|
||||||
|
|
||||||
client.setSalt(salt);
|
const {
|
||||||
client.setServerPublicKey(serverPublicKey);
|
mfaEnabled,
|
||||||
const clientProof = client.getProof(); // called M1
|
encryptionVersion,
|
||||||
|
protectedKey,
|
||||||
|
protectedKeyIV,
|
||||||
|
protectedKeyTag,
|
||||||
|
token,
|
||||||
|
publicKey,
|
||||||
|
encryptedPrivateKey,
|
||||||
|
iv,
|
||||||
|
tag
|
||||||
|
} = await login2({
|
||||||
|
email,
|
||||||
|
clientProof,
|
||||||
|
providerAuthToken
|
||||||
|
});
|
||||||
|
if (mfaEnabled) {
|
||||||
|
// case: MFA is enabled
|
||||||
|
|
||||||
const {
|
// set temporary (MFA) JWT token
|
||||||
mfaEnabled,
|
SecurityClient.setMfaToken(token);
|
||||||
encryptionVersion,
|
|
||||||
protectedKey,
|
|
||||||
protectedKeyIV,
|
|
||||||
protectedKeyTag,
|
|
||||||
token,
|
|
||||||
publicKey,
|
|
||||||
encryptedPrivateKey,
|
|
||||||
iv,
|
|
||||||
tag
|
|
||||||
} = await login2(
|
|
||||||
{
|
|
||||||
email,
|
|
||||||
clientProof,
|
|
||||||
providerAuthToken,
|
|
||||||
}
|
|
||||||
);
|
|
||||||
if (mfaEnabled) {
|
|
||||||
// case: MFA is enabled
|
|
||||||
|
|
||||||
// set temporary (MFA) JWT token
|
resolve({
|
||||||
SecurityClient.setMfaToken(token);
|
mfaEnabled,
|
||||||
|
success: true
|
||||||
|
});
|
||||||
|
} else if (
|
||||||
|
!mfaEnabled &&
|
||||||
|
encryptionVersion &&
|
||||||
|
encryptedPrivateKey &&
|
||||||
|
iv &&
|
||||||
|
tag &&
|
||||||
|
token
|
||||||
|
) {
|
||||||
|
// case: MFA is not enabled
|
||||||
|
|
||||||
resolve({
|
// unset provider auth token in case it was used
|
||||||
mfaEnabled,
|
SecurityClient.setProviderAuthToken("");
|
||||||
success: true
|
// set JWT token
|
||||||
});
|
SecurityClient.setToken(token);
|
||||||
} else if (
|
|
||||||
!mfaEnabled &&
|
|
||||||
encryptionVersion &&
|
|
||||||
encryptedPrivateKey &&
|
|
||||||
iv &&
|
|
||||||
tag &&
|
|
||||||
token
|
|
||||||
) {
|
|
||||||
// case: MFA is not enabled
|
|
||||||
|
|
||||||
// unset provider auth token in case it was used
|
const privateKey = await KeyService.decryptPrivateKey({
|
||||||
SecurityClient.setProviderAuthToken("");
|
encryptionVersion,
|
||||||
// set JWT token
|
encryptedPrivateKey,
|
||||||
SecurityClient.setToken(token);
|
iv,
|
||||||
|
tag,
|
||||||
|
password,
|
||||||
|
salt,
|
||||||
|
protectedKey,
|
||||||
|
protectedKeyIV,
|
||||||
|
protectedKeyTag
|
||||||
|
});
|
||||||
|
|
||||||
const privateKey = await KeyService.decryptPrivateKey({
|
saveTokenToLocalStorage({
|
||||||
encryptionVersion,
|
publicKey,
|
||||||
encryptedPrivateKey,
|
encryptedPrivateKey,
|
||||||
iv,
|
iv,
|
||||||
tag,
|
tag,
|
||||||
password,
|
privateKey
|
||||||
salt,
|
});
|
||||||
protectedKey,
|
|
||||||
protectedKeyIV,
|
|
||||||
protectedKeyTag
|
|
||||||
});
|
|
||||||
|
|
||||||
saveTokenToLocalStorage({
|
if (email) {
|
||||||
publicKey,
|
telemetry.identify(email, email);
|
||||||
encryptedPrivateKey,
|
telemetry.capture("User Logged In");
|
||||||
iv,
|
|
||||||
tag,
|
|
||||||
privateKey
|
|
||||||
});
|
|
||||||
|
|
||||||
if (email) {
|
|
||||||
telemetry.identify(email, email);
|
|
||||||
telemetry.capture("User Logged In");
|
|
||||||
}
|
|
||||||
|
|
||||||
resolve({
|
|
||||||
mfaEnabled: false,
|
|
||||||
loginResponse: {
|
|
||||||
email,
|
|
||||||
privateKey,
|
|
||||||
JTWToken: token
|
|
||||||
},
|
|
||||||
success: true
|
|
||||||
})
|
|
||||||
|
|
||||||
}
|
|
||||||
} catch (err) {
|
|
||||||
reject(err);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
);
|
|
||||||
});
|
resolve({
|
||||||
|
mfaEnabled: false,
|
||||||
|
loginResponse: {
|
||||||
|
email,
|
||||||
|
privateKey,
|
||||||
|
JTWToken: token
|
||||||
|
},
|
||||||
|
success: true
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
reject(err);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
export default attemptLogin;
|
export default attemptLogin;
|
||||||
|
|||||||
Reference in New Issue
Block a user