mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Extract types
This commit is contained in:
@@ -1,8 +1,6 @@
|
||||
/* eslint-disable @typescript-eslint/no-floating-promises */
|
||||
import { z } from "zod";
|
||||
|
||||
import { ApiDocsTags } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import {
|
||||
CreateAcmeAccountResponseSchema,
|
||||
CreateAcmeAccountSchema,
|
||||
@@ -25,8 +23,13 @@ import {
|
||||
RespondToAcmeChallengeResponseSchema,
|
||||
RespondToAcmeChallengeSchema
|
||||
} from "@app/ee/services/pki-acme/pki-acme-schemas";
|
||||
import { ApiDocsTags } from "@app/lib/api-docs";
|
||||
import { getConfig } from "@app/lib/config/env";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
|
||||
export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => {
|
||||
const appCfg = getConfig();
|
||||
|
||||
server.addContentTypeParser("application/jose+json", { parseAs: "string" }, (_, body, done) => {
|
||||
try {
|
||||
const strBody = body instanceof Buffer ? body.toString() : body;
|
||||
@@ -107,11 +110,21 @@ export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => {
|
||||
}
|
||||
},
|
||||
handler: async (req, res) => {
|
||||
// TODO: check nonce here
|
||||
// TODO: check signature here
|
||||
|
||||
const account = await server.services.pkiAcme.createAcmeAccount(req.params.profileId, req.body);
|
||||
// TODO: deal with existing account case here
|
||||
res.code(201);
|
||||
res.header(
|
||||
"Location",
|
||||
`${appCfg.SITE_URL}/api/v1/pki/acme/profiles/${req.params.profileId}/accounts/${account.accountUrl}`
|
||||
);
|
||||
|
||||
// TODO: DRY
|
||||
const nonce = await server.services.pkiAcme.getAcmeNewNonce(req.params.profileId);
|
||||
res.header("Replay-Nonce", nonce);
|
||||
res.header("Cache-Control", "no-store");
|
||||
return account;
|
||||
}
|
||||
});
|
||||
@@ -227,11 +240,7 @@ export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => {
|
||||
}
|
||||
},
|
||||
handler: async (req) => {
|
||||
const order = await server.services.pkiAcme.finalizeAcmeOrder(
|
||||
req.params.profileId,
|
||||
req.params.orderId,
|
||||
req.body.csr
|
||||
);
|
||||
const order = await server.services.pkiAcme.finalizeAcmeOrder(req.params.profileId, req.params.orderId, req.body);
|
||||
return order;
|
||||
}
|
||||
});
|
||||
|
||||
@@ -21,23 +21,26 @@ export const GetAcmeNewNonceSchema = z.object({
|
||||
})
|
||||
});
|
||||
|
||||
// New Account payload schema
|
||||
export const CreateAcmeAccountBodySchema = z.object({
|
||||
contact: z.array(z.string()).optional(),
|
||||
termsOfServiceAgreed: z.boolean().optional(),
|
||||
onlyReturnExisting: z.boolean().optional(),
|
||||
externalAccountBinding: z
|
||||
.object({
|
||||
protected: z.string(),
|
||||
payload: z.string(),
|
||||
signature: z.string()
|
||||
})
|
||||
.optional()
|
||||
});
|
||||
|
||||
// New Account endpoint
|
||||
export const CreateAcmeAccountSchema = z.object({
|
||||
params: z.object({
|
||||
profileId: z.string().uuid()
|
||||
}),
|
||||
body: z.object({
|
||||
contact: z.array(z.string()).optional(),
|
||||
termsOfServiceAgreed: z.boolean().optional(),
|
||||
onlyReturnExisting: z.boolean().optional(),
|
||||
externalAccountBinding: z
|
||||
.object({
|
||||
protected: z.string(),
|
||||
payload: z.string(),
|
||||
signature: z.string()
|
||||
})
|
||||
.optional()
|
||||
})
|
||||
body: CreateAcmeAccountBodySchema
|
||||
});
|
||||
|
||||
export const CreateAcmeAccountResponseSchema = z.object({
|
||||
@@ -47,21 +50,24 @@ export const CreateAcmeAccountResponseSchema = z.object({
|
||||
accountUrl: z.string()
|
||||
});
|
||||
|
||||
// New Order payload schema
|
||||
export const CreateAcmeOrderBodySchema = z.object({
|
||||
identifiers: z.array(
|
||||
z.object({
|
||||
type: z.string(),
|
||||
value: z.string()
|
||||
})
|
||||
),
|
||||
notBefore: z.string().optional(),
|
||||
notAfter: z.string().optional()
|
||||
});
|
||||
|
||||
// New Order endpoint
|
||||
export const CreateAcmeOrderSchema = z.object({
|
||||
params: z.object({
|
||||
profileId: z.string().uuid()
|
||||
}),
|
||||
body: z.object({
|
||||
identifiers: z.array(
|
||||
z.object({
|
||||
type: z.string(),
|
||||
value: z.string()
|
||||
})
|
||||
),
|
||||
notBefore: z.string().optional(),
|
||||
notAfter: z.string().optional()
|
||||
})
|
||||
body: CreateAcmeOrderBodySchema
|
||||
});
|
||||
|
||||
export const CreateAcmeOrderResponseSchema = z.object({
|
||||
@@ -78,15 +84,18 @@ export const CreateAcmeOrderResponseSchema = z.object({
|
||||
certificate: z.string().optional()
|
||||
});
|
||||
|
||||
// Account Deactivation payload schema
|
||||
export const DeactivateAcmeAccountBodySchema = z.object({
|
||||
status: z.literal("deactivated")
|
||||
});
|
||||
|
||||
// Account Deactivation endpoint
|
||||
export const DeactivateAcmeAccountSchema = z.object({
|
||||
params: z.object({
|
||||
profileId: z.string().uuid(),
|
||||
accountId: z.string()
|
||||
}),
|
||||
body: z.object({
|
||||
status: z.literal("deactivated")
|
||||
})
|
||||
body: DeactivateAcmeAccountBodySchema
|
||||
});
|
||||
|
||||
export const DeactivateAcmeAccountResponseSchema = z.object({
|
||||
@@ -127,15 +136,18 @@ export const GetAcmeOrderResponseSchema = z.object({
|
||||
certificate: z.string().optional()
|
||||
});
|
||||
|
||||
// Finalize Order payload schema
|
||||
export const FinalizeAcmeOrderBodySchema = z.object({
|
||||
csr: z.string()
|
||||
});
|
||||
|
||||
// Finalize Order endpoint
|
||||
export const FinalizeAcmeOrderSchema = z.object({
|
||||
params: z.object({
|
||||
profileId: z.string().uuid(),
|
||||
orderId: z.string()
|
||||
}),
|
||||
body: z.object({
|
||||
csr: z.string()
|
||||
})
|
||||
body: FinalizeAcmeOrderBodySchema
|
||||
});
|
||||
|
||||
export const FinalizeAcmeOrderResponseSchema = z.object({
|
||||
|
||||
@@ -4,10 +4,14 @@ import { NotFoundError } from "@app/lib/errors";
|
||||
import { TCertificateProfileDALFactory } from "@app/services/certificate-profile/certificate-profile-dal";
|
||||
|
||||
import {
|
||||
TCreateAcmeAccountPayload,
|
||||
TCreateAcmeAccountResponse,
|
||||
TCreateAcmeOrderPayload,
|
||||
TCreateAcmeOrderResponse,
|
||||
TDeactivateAcmeAccountPayload,
|
||||
TDeactivateAcmeAccountResponse,
|
||||
TDownloadAcmeCertificateDTO,
|
||||
TFinalizeAcmeOrderPayload,
|
||||
TFinalizeAcmeOrderResponse,
|
||||
TGetAcmeAuthorizationResponse,
|
||||
TGetAcmeDirectoryResponse,
|
||||
@@ -49,7 +53,10 @@ export const pkiAcmeServiceFactory = ({ certificateProfileDAL }: TPkiAcmeService
|
||||
return "FIXME-generate-nonce";
|
||||
};
|
||||
|
||||
const createAcmeAccount = async (profileId: string, body: unknown): Promise<TCreateAcmeAccountResponse> => {
|
||||
const createAcmeAccount = async (
|
||||
profileId: string,
|
||||
body: TCreateAcmeAccountPayload
|
||||
): Promise<TCreateAcmeAccountResponse> => {
|
||||
// FIXME: Implement ACME new account registration
|
||||
// Use EAB authentication to find corresponding Infisical machine identity
|
||||
// Check permissions and return account information
|
||||
@@ -63,7 +70,10 @@ export const pkiAcmeServiceFactory = ({ certificateProfileDAL }: TPkiAcmeService
|
||||
};
|
||||
};
|
||||
|
||||
const createAcmeOrder = async (profileId: string, body: unknown): Promise<TCreateAcmeOrderResponse> => {
|
||||
const createAcmeOrder = async (
|
||||
profileId: string,
|
||||
body: TCreateAcmeOrderPayload
|
||||
): Promise<TCreateAcmeOrderResponse> => {
|
||||
// FIXME: Implement ACME new order creation
|
||||
const orderId = "FIXME-order-id";
|
||||
const baseUrl = appCfg.SITE_URL || "";
|
||||
@@ -78,7 +88,8 @@ export const pkiAcmeServiceFactory = ({ certificateProfileDAL }: TPkiAcmeService
|
||||
|
||||
const deactivateAcmeAccount = async (
|
||||
profileId: string,
|
||||
accountId: string
|
||||
accountId: string,
|
||||
body?: TDeactivateAcmeAccountPayload
|
||||
): Promise<TDeactivateAcmeAccountResponse> => {
|
||||
// FIXME: Implement ACME account deactivation
|
||||
return {
|
||||
@@ -108,8 +119,9 @@ export const pkiAcmeServiceFactory = ({ certificateProfileDAL }: TPkiAcmeService
|
||||
const finalizeAcmeOrder = async (
|
||||
profileId: string,
|
||||
orderId: string,
|
||||
csr: string
|
||||
body: TFinalizeAcmeOrderPayload
|
||||
): Promise<TFinalizeAcmeOrderResponse> => {
|
||||
const { csr } = body;
|
||||
// FIXME: Implement ACME finalize order
|
||||
const baseUrl = appCfg.SITE_URL || "";
|
||||
return {
|
||||
|
||||
@@ -1,9 +1,13 @@
|
||||
import { z } from "zod";
|
||||
|
||||
import {
|
||||
CreateAcmeAccountBodySchema,
|
||||
CreateAcmeAccountResponseSchema,
|
||||
CreateAcmeOrderBodySchema,
|
||||
CreateAcmeOrderResponseSchema,
|
||||
DeactivateAcmeAccountBodySchema,
|
||||
DeactivateAcmeAccountResponseSchema,
|
||||
FinalizeAcmeOrderBodySchema,
|
||||
FinalizeAcmeOrderResponseSchema,
|
||||
GetAcmeAuthorizationResponseSchema,
|
||||
GetAcmeDirectoryResponseSchema,
|
||||
@@ -23,15 +27,29 @@ export type TDownloadAcmeCertificateDTO = string;
|
||||
export type TGetAcmeAuthorizationResponse = z.infer<typeof GetAcmeAuthorizationResponseSchema>;
|
||||
export type TRespondToAcmeChallengeResponse = z.infer<typeof RespondToAcmeChallengeResponseSchema>;
|
||||
|
||||
// Payload types
|
||||
export type TCreateAcmeAccountPayload = z.infer<typeof CreateAcmeAccountBodySchema>;
|
||||
export type TCreateAcmeOrderPayload = z.infer<typeof CreateAcmeOrderBodySchema>;
|
||||
export type TDeactivateAcmeAccountPayload = z.infer<typeof DeactivateAcmeAccountBodySchema>;
|
||||
export type TFinalizeAcmeOrderPayload = z.infer<typeof FinalizeAcmeOrderBodySchema>;
|
||||
|
||||
export type TPkiAcmeServiceFactory = {
|
||||
getAcmeDirectory: (profileId: string) => Promise<TGetAcmeDirectoryResponse>;
|
||||
getAcmeNewNonce: (profileId: string) => Promise<string>;
|
||||
createAcmeAccount: (profileId: string, body: unknown) => Promise<TCreateAcmeAccountResponse>;
|
||||
createAcmeOrder: (profileId: string, body: unknown) => Promise<TCreateAcmeOrderResponse>;
|
||||
deactivateAcmeAccount: (profileId: string, accountId: string) => Promise<TDeactivateAcmeAccountResponse>;
|
||||
createAcmeAccount: (profileId: string, body: TCreateAcmeAccountPayload) => Promise<TCreateAcmeAccountResponse>;
|
||||
createAcmeOrder: (profileId: string, body: TCreateAcmeOrderPayload) => Promise<TCreateAcmeOrderResponse>;
|
||||
deactivateAcmeAccount: (
|
||||
profileId: string,
|
||||
accountId: string,
|
||||
body?: TDeactivateAcmeAccountPayload
|
||||
) => Promise<TDeactivateAcmeAccountResponse>;
|
||||
listAcmeOrders: (profileId: string, accountId: string) => Promise<TListAcmeOrdersResponse>;
|
||||
getAcmeOrder: (profileId: string, orderId: string) => Promise<TGetAcmeOrderResponse>;
|
||||
finalizeAcmeOrder: (profileId: string, orderId: string, csr: string) => Promise<TFinalizeAcmeOrderResponse>;
|
||||
finalizeAcmeOrder: (
|
||||
profileId: string,
|
||||
orderId: string,
|
||||
body: TFinalizeAcmeOrderPayload
|
||||
) => Promise<TFinalizeAcmeOrderResponse>;
|
||||
downloadAcmeCertificate: (profileId: string, orderId: string) => Promise<string>;
|
||||
getAcmeAuthorization: (profileId: string, authzId: string) => Promise<TGetAcmeAuthorizationResponse>;
|
||||
respondToAcmeChallenge: (profileId: string, authzId: string) => Promise<TRespondToAcmeChallengeResponse>;
|
||||
|
||||
Reference in New Issue
Block a user