mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 20:27:43 +00:00
Audit logs
This commit is contained in:
@@ -78,7 +78,8 @@ export type TCreateAuditLogDTO = {
|
|||||||
| ScimClientActor
|
| ScimClientActor
|
||||||
| PlatformActor
|
| PlatformActor
|
||||||
| UnknownUserActor
|
| UnknownUserActor
|
||||||
| KmipClientActor;
|
| KmipClientActor
|
||||||
|
| AcmeProfileActor;
|
||||||
orgId?: string;
|
orgId?: string;
|
||||||
projectId?: string;
|
projectId?: string;
|
||||||
} & BaseAuthData;
|
} & BaseAuthData;
|
||||||
@@ -574,7 +575,11 @@ export enum EventType {
|
|||||||
APPROVAL_REQUEST_CANCEL = "approval-request-cancel",
|
APPROVAL_REQUEST_CANCEL = "approval-request-cancel",
|
||||||
APPROVAL_REQUEST_GRANT_LIST = "approval-request-grant-list",
|
APPROVAL_REQUEST_GRANT_LIST = "approval-request-grant-list",
|
||||||
APPROVAL_REQUEST_GRANT_GET = "approval-request-grant-get",
|
APPROVAL_REQUEST_GRANT_GET = "approval-request-grant-get",
|
||||||
APPROVAL_REQUEST_GRANT_REVOKE = "approval-request-grant-revoke"
|
APPROVAL_REQUEST_GRANT_REVOKE = "approval-request-grant-revoke",
|
||||||
|
|
||||||
|
// PKI ACME
|
||||||
|
CREATE_ACME_ACCOUNT = "create-acme-account",
|
||||||
|
RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account"
|
||||||
}
|
}
|
||||||
|
|
||||||
export const filterableSecretEvents: EventType[] = [
|
export const filterableSecretEvents: EventType[] = [
|
||||||
@@ -615,6 +620,10 @@ interface KmipClientActorMetadata {
|
|||||||
name: string;
|
name: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface AcmeProfileActorMetadata {
|
||||||
|
profileId: string;
|
||||||
|
}
|
||||||
|
|
||||||
interface UnknownUserActorMetadata {}
|
interface UnknownUserActorMetadata {}
|
||||||
|
|
||||||
export interface UserActor {
|
export interface UserActor {
|
||||||
@@ -652,7 +661,19 @@ export interface ScimClientActor {
|
|||||||
metadata: ScimClientActorMetadata;
|
metadata: ScimClientActorMetadata;
|
||||||
}
|
}
|
||||||
|
|
||||||
export type Actor = UserActor | ServiceActor | IdentityActor | ScimClientActor | PlatformActor | KmipClientActor;
|
export interface AcmeProfileActor {
|
||||||
|
type: ActorType.ACME_PROFILE;
|
||||||
|
metadata: AcmeProfileActorMetadata;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type Actor =
|
||||||
|
| UserActor
|
||||||
|
| ServiceActor
|
||||||
|
| IdentityActor
|
||||||
|
| ScimClientActor
|
||||||
|
| PlatformActor
|
||||||
|
| KmipClientActor
|
||||||
|
| AcmeProfileActor;
|
||||||
|
|
||||||
interface GetSecretsEvent {
|
interface GetSecretsEvent {
|
||||||
type: EventType.GET_SECRETS;
|
type: EventType.GET_SECRETS;
|
||||||
@@ -4368,6 +4389,23 @@ interface ApprovalRequestGrantRevokeEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface CreateAcmeAccountEvent {
|
||||||
|
type: EventType.CREATE_ACME_ACCOUNT;
|
||||||
|
metadata: {
|
||||||
|
accountId: string;
|
||||||
|
publicKeyThumbprint: string;
|
||||||
|
emails?: string[];
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface RetrieveAcmeAccountEvent {
|
||||||
|
type: EventType.RETRIEVE_ACME_ACCOUNT;
|
||||||
|
metadata: {
|
||||||
|
accountId: string;
|
||||||
|
publicKeyThumbprint: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
export type Event =
|
export type Event =
|
||||||
| CreateSubOrganizationEvent
|
| CreateSubOrganizationEvent
|
||||||
| UpdateSubOrganizationEvent
|
| UpdateSubOrganizationEvent
|
||||||
@@ -4768,4 +4806,6 @@ export type Event =
|
|||||||
| ApprovalRequestCancelEvent
|
| ApprovalRequestCancelEvent
|
||||||
| ApprovalRequestGrantListEvent
|
| ApprovalRequestGrantListEvent
|
||||||
| ApprovalRequestGrantGetEvent
|
| ApprovalRequestGrantGetEvent
|
||||||
| ApprovalRequestGrantRevokeEvent;
|
| ApprovalRequestGrantRevokeEvent
|
||||||
|
| CreateAcmeAccountEvent
|
||||||
|
| RetrieveAcmeAccountEvent;
|
||||||
|
|||||||
@@ -47,6 +47,7 @@ import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
|||||||
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
||||||
import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns";
|
import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns";
|
||||||
|
|
||||||
|
import { EventType, TAuditLogServiceFactory } from "../audit-log/audit-log-types";
|
||||||
import { TLicenseServiceFactory } from "../license/license-service";
|
import { TLicenseServiceFactory } from "../license/license-service";
|
||||||
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
|
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
|
||||||
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
||||||
@@ -136,6 +137,7 @@ type TPkiAcmeServiceFactoryDep = {
|
|||||||
certificateTemplateV2Service: Pick<TCertificateTemplateV2ServiceFactory, "validateCertificateRequest">;
|
certificateTemplateV2Service: Pick<TCertificateTemplateV2ServiceFactory, "validateCertificateRequest">;
|
||||||
acmeChallengeService: Pick<TPkiAcmeChallengeServiceFactory, "markChallengeAsReady">;
|
acmeChallengeService: Pick<TPkiAcmeChallengeServiceFactory, "markChallengeAsReady">;
|
||||||
pkiAcmeQueueService: Pick<TPkiAcmeQueueServiceFactory, "queueChallengeValidation">;
|
pkiAcmeQueueService: Pick<TPkiAcmeQueueServiceFactory, "queueChallengeValidation">;
|
||||||
|
auditLogService: Pick<TAuditLogServiceFactory, "createAuditLog">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export const pkiAcmeServiceFactory = ({
|
export const pkiAcmeServiceFactory = ({
|
||||||
@@ -159,7 +161,8 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
certificateV3Service,
|
certificateV3Service,
|
||||||
certificateTemplateV2Service,
|
certificateTemplateV2Service,
|
||||||
acmeChallengeService,
|
acmeChallengeService,
|
||||||
pkiAcmeQueueService
|
pkiAcmeQueueService,
|
||||||
|
auditLogService
|
||||||
}: TPkiAcmeServiceFactoryDep): TPkiAcmeServiceFactory => {
|
}: TPkiAcmeServiceFactoryDep): TPkiAcmeServiceFactory => {
|
||||||
const validateAcmeProfile = async (profileId: string): Promise<TCertificateProfileWithConfigs> => {
|
const validateAcmeProfile = async (profileId: string): Promise<TCertificateProfileWithConfigs> => {
|
||||||
const profile = await certificateProfileDAL.findByIdWithConfigs(profileId);
|
const profile = await certificateProfileDAL.findByIdWithConfigs(profileId);
|
||||||
@@ -446,6 +449,23 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
throw new AcmeExternalAccountRequiredError({ message: "External account binding is required" });
|
throw new AcmeExternalAccountRequiredError({ message: "External account binding is required" });
|
||||||
}
|
}
|
||||||
if (existingAccount) {
|
if (existingAccount) {
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
projectId: profile.projectId,
|
||||||
|
actor: {
|
||||||
|
type: ActorType.ACME_PROFILE,
|
||||||
|
metadata: {
|
||||||
|
profileId: profile.id
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.RETRIEVE_ACME_ACCOUNT,
|
||||||
|
metadata: {
|
||||||
|
accountId: existingAccount.id,
|
||||||
|
publicKeyThumbprint
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
status: 200,
|
status: 200,
|
||||||
body: {
|
body: {
|
||||||
@@ -518,7 +538,25 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
publicKeyThumbprint,
|
publicKeyThumbprint,
|
||||||
emails: contact ?? []
|
emails: contact ?? []
|
||||||
});
|
});
|
||||||
// TODO: create audit log here
|
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
projectId: profile.projectId,
|
||||||
|
actor: {
|
||||||
|
type: ActorType.ACME_PROFILE,
|
||||||
|
metadata: {
|
||||||
|
profileId: profile.id
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.CREATE_ACME_ACCOUNT,
|
||||||
|
metadata: {
|
||||||
|
accountId: newAccount.id,
|
||||||
|
publicKeyThumbprint: newAccount.publicKeyThumbprint,
|
||||||
|
emails: newAccount.emails
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
status: 201,
|
status: 201,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -2332,7 +2332,8 @@ export const registerRoutes = async (
|
|||||||
certificateV3Service,
|
certificateV3Service,
|
||||||
certificateTemplateV2Service,
|
certificateTemplateV2Service,
|
||||||
acmeChallengeService,
|
acmeChallengeService,
|
||||||
pkiAcmeQueueService
|
pkiAcmeQueueService,
|
||||||
|
auditLogService
|
||||||
});
|
});
|
||||||
|
|
||||||
const pkiSubscriberService = pkiSubscriberServiceFactory({
|
const pkiSubscriberService = pkiSubscriberServiceFactory({
|
||||||
|
|||||||
@@ -41,6 +41,7 @@ export enum ActorType { // would extend to AWS, Azure, ...
|
|||||||
IDENTITY = "identity",
|
IDENTITY = "identity",
|
||||||
Machine = "machine",
|
Machine = "machine",
|
||||||
SCIM_CLIENT = "scimClient",
|
SCIM_CLIENT = "scimClient",
|
||||||
|
ACME_PROFILE = "acmeProfile",
|
||||||
ACME_ACCOUNT = "acmeAccount",
|
ACME_ACCOUNT = "acmeAccount",
|
||||||
UNKNOWN_USER = "unknownUser"
|
UNKNOWN_USER = "unknownUser"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user