mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Populate service token user
This commit is contained in:
@@ -41,7 +41,7 @@ const validateAuthMode = ({
|
|||||||
// case: no auth or X-API-KEY header present
|
// case: no auth or X-API-KEY header present
|
||||||
throw BadRequestError({ message: 'Missing Authorization or X-API-KEY in request header.' });
|
throw BadRequestError({ message: 'Missing Authorization or X-API-KEY in request header.' });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (typeof apiKey === 'string') {
|
if (typeof apiKey === 'string') {
|
||||||
// case: treat request authentication type as via X-API-KEY (i.e. API Key)
|
// case: treat request authentication type as via X-API-KEY (i.e. API Key)
|
||||||
authTokenType = 'apiKey';
|
authTokenType = 'apiKey';
|
||||||
@@ -50,13 +50,13 @@ const validateAuthMode = ({
|
|||||||
|
|
||||||
if (typeof authHeader === 'string') {
|
if (typeof authHeader === 'string') {
|
||||||
// case: treat request authentication type as via Authorization header (i.e. either JWT or service token)
|
// case: treat request authentication type as via Authorization header (i.e. either JWT or service token)
|
||||||
const [tokenType, tokenValue] = <[string, string]>authHeader.split(' ', 2) ?? [null, null]
|
const [tokenType, tokenValue] = <[string, string]>authHeader.split(' ', 2) ?? [null, null]
|
||||||
if (tokenType === null)
|
if (tokenType === null)
|
||||||
throw BadRequestError({ message: `Missing Authorization Header in the request header.` });
|
throw BadRequestError({ message: `Missing Authorization Header in the request header.` });
|
||||||
if (tokenType.toLowerCase() !== 'bearer')
|
if (tokenType.toLowerCase() !== 'bearer')
|
||||||
throw BadRequestError({ message: `The provided authentication type '${tokenType}' is not supported.` });
|
throw BadRequestError({ message: `The provided authentication type '${tokenType}' is not supported.` });
|
||||||
if (tokenValue === null)
|
if (tokenValue === null)
|
||||||
throw BadRequestError({ message: 'Missing Authorization Body in the request header.' });
|
throw BadRequestError({ message: 'Missing Authorization Body in the request header.' });
|
||||||
|
|
||||||
switch (tokenValue.split('.', 1)[0]) {
|
switch (tokenValue.split('.', 1)[0]) {
|
||||||
case 'st':
|
case 'st':
|
||||||
@@ -67,11 +67,11 @@ const validateAuthMode = ({
|
|||||||
}
|
}
|
||||||
authTokenValue = tokenValue;
|
authTokenValue = tokenValue;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!authTokenType || !authTokenValue) throw BadRequestError({ message: 'Missing valid Authorization or X-API-KEY in request header.' });
|
if (!authTokenType || !authTokenValue) throw BadRequestError({ message: 'Missing valid Authorization or X-API-KEY in request header.' });
|
||||||
|
|
||||||
if (!acceptedAuthModes.includes(authTokenType)) throw BadRequestError({ message: 'The provided authentication type is not supported.' });
|
if (!acceptedAuthModes.includes(authTokenType)) throw BadRequestError({ message: 'The provided authentication type is not supported.' });
|
||||||
|
|
||||||
return ({
|
return ({
|
||||||
authTokenType,
|
authTokenType,
|
||||||
authTokenValue
|
authTokenValue
|
||||||
@@ -108,7 +108,7 @@ const getAuthUserPayload = async ({
|
|||||||
message: 'Failed to authenticate JWT token'
|
message: 'Failed to authenticate JWT token'
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
return user;
|
return user;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -130,7 +130,7 @@ const getAuthSTDPayload = async ({
|
|||||||
// TODO: optimize double query
|
// TODO: optimize double query
|
||||||
serviceTokenData = await ServiceTokenData
|
serviceTokenData = await ServiceTokenData
|
||||||
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt');
|
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt');
|
||||||
|
|
||||||
if (!serviceTokenData) {
|
if (!serviceTokenData) {
|
||||||
throw ServiceTokenDataNotFoundError({ message: 'Failed to find service token data' });
|
throw ServiceTokenDataNotFoundError({ message: 'Failed to find service token data' });
|
||||||
} else if (serviceTokenData?.expiresAt && new Date(serviceTokenData.expiresAt) < new Date()) {
|
} else if (serviceTokenData?.expiresAt && new Date(serviceTokenData.expiresAt) < new Date()) {
|
||||||
@@ -148,14 +148,14 @@ const getAuthSTDPayload = async ({
|
|||||||
|
|
||||||
serviceTokenData = await ServiceTokenData
|
serviceTokenData = await ServiceTokenData
|
||||||
.findById(TOKEN_IDENTIFIER)
|
.findById(TOKEN_IDENTIFIER)
|
||||||
.select('+encryptedKey +iv +tag');
|
.select('+encryptedKey +iv +tag').populate('user');
|
||||||
|
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: 'Failed to authenticate service token'
|
message: 'Failed to authenticate service token'
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
return serviceTokenData;
|
return serviceTokenData;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -173,11 +173,11 @@ const getAuthAPIKeyPayload = async ({
|
|||||||
let user;
|
let user;
|
||||||
try {
|
try {
|
||||||
const [_, TOKEN_IDENTIFIER, TOKEN_SECRET] = <[string, string, string]>authTokenValue.split('.', 3);
|
const [_, TOKEN_IDENTIFIER, TOKEN_SECRET] = <[string, string, string]>authTokenValue.split('.', 3);
|
||||||
|
|
||||||
const apiKeyData = await APIKeyData
|
const apiKeyData = await APIKeyData
|
||||||
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt')
|
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt')
|
||||||
.populate('user', '+publicKey');
|
.populate('user', '+publicKey');
|
||||||
|
|
||||||
if (!apiKeyData) {
|
if (!apiKeyData) {
|
||||||
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
|
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
|
||||||
} else if (apiKeyData?.expiresAt && new Date(apiKeyData.expiresAt) < new Date()) {
|
} else if (apiKeyData?.expiresAt && new Date(apiKeyData.expiresAt) < new Date()) {
|
||||||
@@ -192,14 +192,14 @@ const getAuthAPIKeyPayload = async ({
|
|||||||
if (!isMatch) throw UnauthorizedRequestError({
|
if (!isMatch) throw UnauthorizedRequestError({
|
||||||
message: 'Failed to authenticate API key'
|
message: 'Failed to authenticate API key'
|
||||||
});
|
});
|
||||||
|
|
||||||
user = apiKeyData.user;
|
user = apiKeyData.user;
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: 'Failed to authenticate API key'
|
message: 'Failed to authenticate API key'
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
return user;
|
return user;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -292,12 +292,12 @@ const createToken = ({
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
export {
|
export {
|
||||||
validateAuthMode,
|
validateAuthMode,
|
||||||
getAuthUserPayload,
|
getAuthUserPayload,
|
||||||
getAuthSTDPayload,
|
getAuthSTDPayload,
|
||||||
getAuthAPIKeyPayload,
|
getAuthAPIKeyPayload,
|
||||||
createToken,
|
createToken,
|
||||||
issueTokens,
|
issueTokens,
|
||||||
clearTokens
|
clearTokens
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -17,10 +17,10 @@ const requireServiceTokenDataAuth = ({
|
|||||||
|
|
||||||
const serviceTokenData = await ServiceTokenData
|
const serviceTokenData = await ServiceTokenData
|
||||||
.findById(req[location].serviceTokenDataId)
|
.findById(req[location].serviceTokenDataId)
|
||||||
.select('+encryptedKey +iv +tag');
|
.select('+encryptedKey +iv +tag').populate('user');
|
||||||
|
|
||||||
if (!serviceTokenData) {
|
if (!serviceTokenData) {
|
||||||
return next(AccountNotFoundError({message: 'Failed to locate service token data'}));
|
return next(AccountNotFoundError({ message: 'Failed to locate service token data' }));
|
||||||
}
|
}
|
||||||
|
|
||||||
if (req.user) {
|
if (req.user) {
|
||||||
@@ -31,9 +31,9 @@ const requireServiceTokenDataAuth = ({
|
|||||||
acceptedRoles
|
acceptedRoles
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
req.serviceTokenData = serviceTokenData;
|
req.serviceTokenData = serviceTokenData;
|
||||||
|
|
||||||
next();
|
next();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user