JWT_AUTH_SECRET => AUTH_SECRET

This commit is contained in:
Maidul Islam
2024-01-27 12:40:36 +05:30
committed by Akhil Mohan
parent cec14efe86
commit 30b959babb
12 changed files with 29 additions and 27 deletions
+4 -3
View File
@@ -36,7 +36,7 @@ const envSchema = z
.default("#5VihU%rbXHcHwWwCot5L3vyPsx$7dWYw^iGk!EJg2bC*f$PD$%KCqx^R@#^LSEf"), .default("#5VihU%rbXHcHwWwCot5L3vyPsx$7dWYw^iGk!EJg2bC*f$PD$%KCqx^R@#^LSEf"),
SITE_URL: zpStr(z.string().optional()), SITE_URL: zpStr(z.string().optional()),
// jwt options // jwt options
JWT_AUTH_SECRET: zpStr(z.string()), AUTH_SECRET: zpStr(z.string()).default(process.env.JWT_AUTH_SECRET), // for those still using old JWT_AUTH_SECRET
JWT_AUTH_LIFETIME: zpStr(z.string().default("10d")), JWT_AUTH_LIFETIME: zpStr(z.string().default("10d")),
JWT_SIGNUP_LIFETIME: zpStr(z.string().default("15m")), JWT_SIGNUP_LIFETIME: zpStr(z.string().default("15m")),
JWT_REFRESH_LIFETIME: zpStr(z.string().default("90d")), JWT_REFRESH_LIFETIME: zpStr(z.string().default("90d")),
@@ -49,7 +49,7 @@ const envSchema = z
CLIENT_SECRET_GITHUB_LOGIN: zpStr(z.string().optional()), CLIENT_SECRET_GITHUB_LOGIN: zpStr(z.string().optional()),
CLIENT_ID_GITLAB_LOGIN: zpStr(z.string().optional()), CLIENT_ID_GITLAB_LOGIN: zpStr(z.string().optional()),
CLIENT_SECRET_GITLAB_LOGIN: zpStr(z.string().optional()), CLIENT_SECRET_GITLAB_LOGIN: zpStr(z.string().optional()),
CLIENT_GITLAB_LOGIN_URL: zpStr(z.string().optional().default(GITLAB_URL)), CLIENT_GITLAB_LOGIN_URL: zpStr(z.string().optional().default(process.env.URL_GITLAB_LOGIN ?? GITLAB_URL)), // fallback since URL_GITLAB_LOGIN has been renamed
// integration client secrets // integration client secrets
// heroku // heroku
CLIENT_ID_HEROKU: zpStr(z.string().optional()), CLIENT_ID_HEROKU: zpStr(z.string().optional()),
@@ -73,7 +73,7 @@ const envSchema = z
// azure // azure
CLIENT_ID_AZURE: zpStr(z.string().optional()), CLIENT_ID_AZURE: zpStr(z.string().optional()),
CLIENT_SECRET_AZURE: zpStr(z.string().optional()), CLIENT_SECRET_AZURE: zpStr(z.string().optional()),
// google // gitlab
CLIENT_ID_GITLAB: zpStr(z.string().optional()), CLIENT_ID_GITLAB: zpStr(z.string().optional()),
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()), CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)), URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
@@ -114,6 +114,7 @@ export const initEnvConfig = (logger: Logger) => {
logger.error(parsedEnv.error.issues); logger.error(parsedEnv.error.issues);
process.exit(-1); process.exit(-1);
} }
envCfg = Object.freeze(parsedEnv.data); envCfg = Object.freeze(parsedEnv.data);
return envCfg; return envCfg;
}; };
+6 -5
View File
@@ -14,11 +14,12 @@ const logLevelToSeverityLookup: Record<string, string> = {
// eslint-disable-next-line import/no-mutable-exports // eslint-disable-next-line import/no-mutable-exports
export let logger: Readonly<Logger>; export let logger: Readonly<Logger>;
// akhilmhdh: why this instead of putting it in config right // akhilmhdh:
// reason is to avoid a cyclical condition // The logger is not placed in the main app config to avoid a circular dependency.
// config needs logger to output error when invalid environment is provided // The config requires the logger to display errors when an invalid environment is supplied.
// logger needs config to get aws or other transport cred // On the other hand, the logger needs the config to obtain credentials for AWS or other transports.
// this would make logger independent package // By keeping the logger separate, it becomes an independent package.
const loggerConfig = z.object({ const loggerConfig = z.object({
AWS_CLOUDWATCH_LOG_GROUP_NAME: z.string().default("infisical-log-stream"), AWS_CLOUDWATCH_LOG_GROUP_NAME: z.string().default("infisical-log-stream"),
AWS_CLOUDWATCH_LOG_REGION: z.string().default("us-east-1"), AWS_CLOUDWATCH_LOG_REGION: z.string().default("us-east-1"),
@@ -82,7 +82,7 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
server.decorateRequest("auth", null); server.decorateRequest("auth", null);
server.addHook("onRequest", async (req) => { server.addHook("onRequest", async (req) => {
const appCfg = getConfig(); const appCfg = getConfig();
const { authMode, token, actor } = await extractAuth(req, appCfg.JWT_AUTH_SECRET); const { authMode, token, actor } = await extractAuth(req, appCfg.AUTH_SECRET);
if (!authMode) return; if (!authMode) return;
switch (authMode) { switch (authMode) {
@@ -76,7 +76,7 @@ export const registerAuthRoutes = async (server: FastifyZodProvider) => {
const decodedToken = jwt.verify( const decodedToken = jwt.verify(
refreshToken, refreshToken,
appCfg.JWT_AUTH_SECRET appCfg.AUTH_SECRET
) as AuthModeRefreshJwtTokenPayload; ) as AuthModeRefreshJwtTokenPayload;
if (decodedToken.authTokenType !== AuthTokenType.REFRESH_TOKEN) if (decodedToken.authTokenType !== AuthTokenType.REFRESH_TOKEN)
throw new UnauthorizedError({ message: "Invalid token", name: "Auth token route" }); throw new UnauthorizedError({ message: "Invalid token", name: "Auth token route" });
@@ -98,7 +98,7 @@ export const registerAuthRoutes = async (server: FastifyZodProvider) => {
tokenVersionId: tokenVersion.id, tokenVersionId: tokenVersion.id,
accessVersion: tokenVersion.accessVersion accessVersion: tokenVersion.accessVersion
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ expiresIn: appCfg.JWT_AUTH_LIFETIME } { expiresIn: appCfg.JWT_AUTH_LIFETIME }
); );
@@ -21,7 +21,7 @@ export const registerMfaRouter = async (server: FastifyZodProvider) => {
return res; return res;
} }
const decodedToken = jwt.verify(token, cfg.JWT_AUTH_SECRET) as JwtPayload; const decodedToken = jwt.verify(token, cfg.AUTH_SECRET) as JwtPayload;
if (decodedToken.authTokenType !== AuthTokenType.MFA_TOKEN) if (decodedToken.authTokenType !== AuthTokenType.MFA_TOKEN)
throw new Error("Unauthorized access"); throw new Error("Unauthorized access");
+2 -2
View File
@@ -14,7 +14,7 @@ export const validateProviderAuthToken = (providerToken: string, email: string)
const appCfg = getConfig(); const appCfg = getConfig();
const decodedToken = jwt.verify( const decodedToken = jwt.verify(
providerToken, providerToken,
appCfg.JWT_AUTH_SECRET appCfg.AUTH_SECRET
) as AuthModeProviderJwtTokenPayload; ) as AuthModeProviderJwtTokenPayload;
if (decodedToken.authTokenType !== AuthTokenType.PROVIDER_TOKEN) throw new UnauthorizedError(); if (decodedToken.authTokenType !== AuthTokenType.PROVIDER_TOKEN) throw new UnauthorizedError();
@@ -43,7 +43,7 @@ export const validateSignUpAuthorization = (token: string, userId: string, valid
const decodedToken = jwt.verify( const decodedToken = jwt.verify(
AUTH_TOKEN_VALUE, AUTH_TOKEN_VALUE,
appCfg.JWT_AUTH_SECRET appCfg.AUTH_SECRET
) as AuthModeProviderSignUpTokenPayload; ) as AuthModeProviderSignUpTokenPayload;
if (!validate) return decodedToken; if (!validate) return decodedToken;
@@ -98,7 +98,7 @@ export const authLoginServiceFactory = ({
tokenVersionId: tokenSession.id, tokenVersionId: tokenSession.id,
accessVersion: tokenSession.accessVersion accessVersion: tokenSession.accessVersion
}, },
cfg.JWT_AUTH_SECRET, cfg.AUTH_SECRET,
{ expiresIn: cfg.JWT_AUTH_LIFETIME } { expiresIn: cfg.JWT_AUTH_LIFETIME }
); );
@@ -109,7 +109,7 @@ export const authLoginServiceFactory = ({
tokenVersionId: tokenSession.id, tokenVersionId: tokenSession.id,
refreshVersion: tokenSession.refreshVersion refreshVersion: tokenSession.refreshVersion
}, },
cfg.JWT_AUTH_SECRET, cfg.AUTH_SECRET,
{ expiresIn: cfg.JWT_REFRESH_LIFETIME } { expiresIn: cfg.JWT_REFRESH_LIFETIME }
); );
@@ -178,7 +178,7 @@ export const authLoginServiceFactory = ({
if (userEnc.isMfaEnabled) { if (userEnc.isMfaEnabled) {
const mfaToken = jwt.sign( const mfaToken = jwt.sign(
{ authTokenType: AuthTokenType.MFA_TOKEN, userId: userEnc.userId }, { authTokenType: AuthTokenType.MFA_TOKEN, userId: userEnc.userId },
cfg.JWT_AUTH_SECRET, cfg.AUTH_SECRET,
{ expiresIn: cfg.JWT_MFA_LIFETIME } { expiresIn: cfg.JWT_MFA_LIFETIME }
); );
await sendUserMfaCode(userEnc.userId, userEnc.email); await sendUserMfaCode(userEnc.userId, userEnc.email);
@@ -254,7 +254,7 @@ export const authLoginServiceFactory = ({
} }
: {}) : {})
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ {
expiresIn: appCfg.JWT_PROVIDER_AUTH_LIFETIME expiresIn: appCfg.JWT_PROVIDER_AUTH_LIFETIME
} }
@@ -148,7 +148,7 @@ export const authPaswordServiceFactory = ({
authTokenType: AuthTokenType.SIGNUP_TOKEN, authTokenType: AuthTokenType.SIGNUP_TOKEN,
userId: user.id userId: user.id
}, },
cfg.JWT_AUTH_SECRET, cfg.AUTH_SECRET,
{ expiresIn: cfg.JWT_SIGNUP_LIFETIME } { expiresIn: cfg.JWT_SIGNUP_LIFETIME }
); );
@@ -88,7 +88,7 @@ export const authSignupServiceFactory = ({
authTokenType: AuthTokenType.SIGNUP_TOKEN, authTokenType: AuthTokenType.SIGNUP_TOKEN,
userId: user.id.toString() userId: user.id.toString()
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ expiresIn: appCfg.JWT_SIGNUP_LIFETIME } { expiresIn: appCfg.JWT_SIGNUP_LIFETIME }
); );
@@ -181,7 +181,7 @@ export const authSignupServiceFactory = ({
tokenVersionId: tokenSession.id, tokenVersionId: tokenSession.id,
accessVersion: tokenSession.accessVersion accessVersion: tokenSession.accessVersion
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ expiresIn: appCfg.JWT_AUTH_LIFETIME } { expiresIn: appCfg.JWT_AUTH_LIFETIME }
); );
@@ -192,7 +192,7 @@ export const authSignupServiceFactory = ({
tokenVersionId: tokenSession.id, tokenVersionId: tokenSession.id,
refreshVersion: tokenSession.refreshVersion refreshVersion: tokenSession.refreshVersion
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ expiresIn: appCfg.JWT_REFRESH_LIFETIME } { expiresIn: appCfg.JWT_REFRESH_LIFETIME }
); );
@@ -281,7 +281,7 @@ export const authSignupServiceFactory = ({
tokenVersionId: tokenSession.id, tokenVersionId: tokenSession.id,
accessVersion: tokenSession.accessVersion accessVersion: tokenSession.accessVersion
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ expiresIn: appCfg.JWT_SIGNUP_LIFETIME } { expiresIn: appCfg.JWT_SIGNUP_LIFETIME }
); );
@@ -292,7 +292,7 @@ export const authSignupServiceFactory = ({
tokenVersionId: tokenSession.id, tokenVersionId: tokenSession.id,
refreshVersion: tokenSession.refreshVersion refreshVersion: tokenSession.refreshVersion
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ expiresIn: appCfg.JWT_SIGNUP_LIFETIME } { expiresIn: appCfg.JWT_SIGNUP_LIFETIME }
); );
@@ -88,7 +88,7 @@ export const identityAccessTokenServiceFactory = ({
const renewAccessToken = async ({ accessToken }: TRenewAccessTokenDTO) => { const renewAccessToken = async ({ accessToken }: TRenewAccessTokenDTO) => {
const appCfg = getConfig(); const appCfg = getConfig();
const decodedToken = jwt.verify(accessToken, appCfg.JWT_AUTH_SECRET) as JwtPayload; const decodedToken = jwt.verify(accessToken, appCfg.AUTH_SECRET) as JwtPayload;
if (decodedToken.authTokenType !== AuthTokenType.IDENTITY_ACCESS_TOKEN) if (decodedToken.authTokenType !== AuthTokenType.IDENTITY_ACCESS_TOKEN)
throw new UnauthorizedError(); throw new UnauthorizedError();
@@ -131,7 +131,7 @@ export const identityUaServiceFactory = ({
identityAccessTokenId: identityAccessToken.id, identityAccessTokenId: identityAccessToken.id,
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ {
expiresIn: expiresIn:
identityAccessToken.accessTokenMaxTTL === 0 identityAccessToken.accessTokenMaxTTL === 0
+1 -1
View File
@@ -385,7 +385,7 @@ export const orgServiceFactory = ({
authTokenType: AuthTokenType.SIGNUP_TOKEN, authTokenType: AuthTokenType.SIGNUP_TOKEN,
userId: user.id userId: user.id
}, },
appCfg.JWT_AUTH_SECRET, appCfg.AUTH_SECRET,
{ {
expiresIn: appCfg.JWT_SIGNUP_LIFETIME expiresIn: appCfg.JWT_SIGNUP_LIFETIME
} }