feat: updated frontend to make reviewer jwt optional

This commit is contained in:
=
2025-03-22 01:07:28 +05:30
parent 81b026865c
commit 341b63c61c
3 changed files with 27 additions and 21 deletions
+2 -2
View File
@@ -350,7 +350,7 @@ export type AddIdentityKubernetesAuthDTO = {
organizationId: string; organizationId: string;
identityId: string; identityId: string;
kubernetesHost: string; kubernetesHost: string;
tokenReviewerJwt: string; tokenReviewerJwt?: string;
allowedNamespaces: string; allowedNamespaces: string;
allowedNames: string; allowedNames: string;
allowedAudience: string; allowedAudience: string;
@@ -367,7 +367,7 @@ export type UpdateIdentityKubernetesAuthDTO = {
organizationId: string; organizationId: string;
identityId: string; identityId: string;
kubernetesHost?: string; kubernetesHost?: string;
tokenReviewerJwt?: string; tokenReviewerJwt?: string | null;
allowedNamespaces?: string; allowedNamespaces?: string;
allowedNames?: string; allowedNames?: string;
allowedAudience?: string; allowedAudience?: string;
@@ -31,7 +31,7 @@ import { IdentityFormTab } from "./types";
const schema = z const schema = z
.object({ .object({
kubernetesHost: z.string().min(1), kubernetesHost: z.string().min(1),
tokenReviewerJwt: z.string().min(1), tokenReviewerJwt: z.string().optional(),
allowedNames: z.string(), allowedNames: z.string(),
allowedNamespaces: z.string(), allowedNamespaces: z.string(),
allowedAudience: z.string(), allowedAudience: z.string(),
@@ -166,7 +166,7 @@ export const IdentityKubernetesAuthForm = ({
await updateMutateAsync({ await updateMutateAsync({
organizationId: orgId, organizationId: orgId,
kubernetesHost, kubernetesHost,
tokenReviewerJwt, tokenReviewerJwt: tokenReviewerJwt || null,
allowedNames, allowedNames,
allowedNamespaces, allowedNamespaces,
allowedAudience, allowedAudience,
@@ -182,7 +182,7 @@ export const IdentityKubernetesAuthForm = ({
organizationId: orgId, organizationId: orgId,
identityId, identityId,
kubernetesHost: kubernetesHost || "", kubernetesHost: kubernetesHost || "",
tokenReviewerJwt, tokenReviewerJwt: tokenReviewerJwt || undefined,
allowedNames: allowedNames || "", allowedNames: allowedNames || "",
allowedNamespaces: allowedNamespaces || "", allowedNamespaces: allowedNamespaces || "",
allowedAudience: allowedAudience || "", allowedAudience: allowedAudience || "",
@@ -255,11 +255,11 @@ export const IdentityKubernetesAuthForm = ({
name="tokenReviewerJwt" name="tokenReviewerJwt"
render={({ field, fieldState: { error } }) => ( render={({ field, fieldState: { error } }) => (
<FormControl <FormControl
tooltipClassName="max-w-md"
label="Token Reviewer JWT" label="Token Reviewer JWT"
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
tooltipText="A long-lived service account JWT token for Infisical to access the TokenReview API to validate other service account JWT tokens submitted by applications/pods." tooltipText="Optional JWT token for accessing Kubernetes TokenReview API. If provided, this long-lived token will be used to validate service account tokens during authentication. If omitted, the client's own JWT will be used instead, which requires the client to have the system:auth-delegator ClusterRole binding."
isRequired
> >
<Input {...field} placeholder="" type="password" /> <Input {...field} placeholder="" type="password" />
</FormControl> </FormControl>
@@ -70,20 +70,26 @@ export const ViewIdentityKubernetesAuthContent = ({
{data.kubernetesHost} {data.kubernetesHost}
</IdentityAuthFieldDisplay> </IdentityAuthFieldDisplay>
<IdentityAuthFieldDisplay className="col-span-2" label="Token Reviewer JWT"> <IdentityAuthFieldDisplay className="col-span-2" label="Token Reviewer JWT">
<Tooltip {data.tokenReviewerJwt ? (
side="right" <Tooltip
className="max-w-xl p-2" side="right"
content={ className="max-w-xl p-2"
<p className="break-words rounded bg-mineshaft-600 p-2">{data.tokenReviewerJwt}</p> content={
} <p className="break-words rounded bg-mineshaft-600 p-2">
> {data.tokenReviewerJwt || "Not provided"}
<div className="w-min"> </p>
<Badge className="flex h-5 w-min items-center gap-1.5 whitespace-nowrap bg-mineshaft-400/50 text-bunker-300"> }
<FontAwesomeIcon icon={faEye} /> >
<span>Reveal</span> <div className="w-min">
</Badge> <Badge className="flex h-5 w-min items-center gap-1.5 whitespace-nowrap bg-mineshaft-400/50 text-bunker-300">
</div> <FontAwesomeIcon icon={faEye} />
</Tooltip> <span>Reveal</span>
</Badge>
</div>
</Tooltip>
) : (
<p className="text-base italic leading-4 text-bunker-400">Not set</p>
)}
</IdentityAuthFieldDisplay> </IdentityAuthFieldDisplay>
<IdentityAuthFieldDisplay className="col-span-2" label="Allowed Service Account Names"> <IdentityAuthFieldDisplay className="col-span-2" label="Allowed Service Account Names">
{data.allowedNames {data.allowedNames