From 3841394eb76584630ca0b12783c266a6fc8613e3 Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Sat, 26 Oct 2024 03:18:57 +0800 Subject: [PATCH] misc: migrated existing to new helper --- .../dynamic-secret/dynamic-secret-fns.ts | 4 ++- .../providers/elastic-search.ts | 20 ++------------- .../dynamic-secret/providers/mongo-db.ts | 19 ++------------ .../dynamic-secret/providers/rabbit-mq.ts | 20 ++------------- .../dynamic-secret/providers/redis.ts | 19 ++------------ .../dynamic-secret/providers/sql-database.ts | 25 ++----------------- 6 files changed, 13 insertions(+), 94 deletions(-) diff --git a/backend/src/ee/services/dynamic-secret/dynamic-secret-fns.ts b/backend/src/ee/services/dynamic-secret/dynamic-secret-fns.ts index 1e858c988..04aeb3950 100644 --- a/backend/src/ee/services/dynamic-secret/dynamic-secret-fns.ts +++ b/backend/src/ee/services/dynamic-secret/dynamic-secret-fns.ts @@ -1,8 +1,10 @@ import { getConfig } from "@app/lib/config/env"; import { BadRequestError } from "@app/lib/errors"; +import { getDbConnectionHost } from "@app/lib/knex"; export const verifyHostInputValidity = (host: string) => { const appCfg = getConfig(); + const dbHost = appCfg.DB_HOST || getDbConnectionHost(appCfg.DB_CONNECTION_URI); if ( appCfg.isCloud && @@ -12,7 +14,7 @@ export const verifyHostInputValidity = (host: string) => { ) throw new BadRequestError({ message: "Invalid db host" }); - if (host === "localhost" || host === "127.0.0.1") { + if (host === "localhost" || host === "127.0.0.1" || dbHost === host) { throw new BadRequestError({ message: "Invalid db host" }); } }; diff --git a/backend/src/ee/services/dynamic-secret/providers/elastic-search.ts b/backend/src/ee/services/dynamic-secret/providers/elastic-search.ts index 3247ef21b..bfe0ac443 100644 --- a/backend/src/ee/services/dynamic-secret/providers/elastic-search.ts +++ b/backend/src/ee/services/dynamic-secret/providers/elastic-search.ts @@ -2,10 +2,9 @@ import { Client as ElasticSearchClient } from "@elastic/elasticsearch"; import { customAlphabet } from "nanoid"; import { z } from "zod"; -import { getConfig } from "@app/lib/config/env"; -import { BadRequestError } from "@app/lib/errors"; import { alphaNumericNanoId } from "@app/lib/nanoid"; +import { verifyHostInputValidity } from "../dynamic-secret-fns"; import { DynamicSecretElasticSearchSchema, ElasticSearchAuthTypes, TDynamicProviderFns } from "./models"; const generatePassword = () => { @@ -19,23 +18,8 @@ const generateUsername = () => { export const ElasticSearchProvider = (): TDynamicProviderFns => { const validateProviderInputs = async (inputs: unknown) => { - const appCfg = getConfig(); - const isCloud = Boolean(appCfg.LICENSE_SERVER_KEY); // quick and dirty way to check if its cloud or not - const providerInputs = await DynamicSecretElasticSearchSchema.parseAsync(inputs); - if ( - isCloud && - // localhost - // internal ips - (providerInputs.host === "host.docker.internal" || - providerInputs.host.match(/^10\.\d+\.\d+\.\d+/) || - providerInputs.host.match(/^192\.168\.\d+\.\d+/)) - ) { - throw new BadRequestError({ message: "Invalid db host" }); - } - if (providerInputs.host === "localhost" || providerInputs.host === "127.0.0.1") { - throw new BadRequestError({ message: "Invalid db host" }); - } + verifyHostInputValidity(providerInputs.host); return providerInputs; }; diff --git a/backend/src/ee/services/dynamic-secret/providers/mongo-db.ts b/backend/src/ee/services/dynamic-secret/providers/mongo-db.ts index ea9430846..b824f5aa8 100644 --- a/backend/src/ee/services/dynamic-secret/providers/mongo-db.ts +++ b/backend/src/ee/services/dynamic-secret/providers/mongo-db.ts @@ -2,10 +2,9 @@ import { MongoClient } from "mongodb"; import { customAlphabet } from "nanoid"; import { z } from "zod"; -import { getConfig } from "@app/lib/config/env"; -import { BadRequestError } from "@app/lib/errors"; import { alphaNumericNanoId } from "@app/lib/nanoid"; +import { verifyHostInputValidity } from "../dynamic-secret-fns"; import { DynamicSecretMongoDBSchema, TDynamicProviderFns } from "./models"; const generatePassword = (size = 48) => { @@ -19,22 +18,8 @@ const generateUsername = () => { export const MongoDBProvider = (): TDynamicProviderFns => { const validateProviderInputs = async (inputs: unknown) => { - const appCfg = getConfig(); const providerInputs = await DynamicSecretMongoDBSchema.parseAsync(inputs); - if ( - appCfg.isCloud && - // localhost - // internal ips - (providerInputs.host === "host.docker.internal" || - providerInputs.host.match(/^10\.\d+\.\d+\.\d+/) || - providerInputs.host.match(/^192\.168\.\d+\.\d+/)) - ) - throw new BadRequestError({ message: "Invalid db host" }); - - if (providerInputs.host === "localhost" || providerInputs.host === "127.0.0.1") { - throw new BadRequestError({ message: "Invalid db host" }); - } - + verifyHostInputValidity(providerInputs.host); return providerInputs; }; diff --git a/backend/src/ee/services/dynamic-secret/providers/rabbit-mq.ts b/backend/src/ee/services/dynamic-secret/providers/rabbit-mq.ts index 15492cd2d..00d3b538f 100644 --- a/backend/src/ee/services/dynamic-secret/providers/rabbit-mq.ts +++ b/backend/src/ee/services/dynamic-secret/providers/rabbit-mq.ts @@ -3,12 +3,11 @@ import https from "https"; import { customAlphabet } from "nanoid"; import { z } from "zod"; -import { getConfig } from "@app/lib/config/env"; -import { BadRequestError } from "@app/lib/errors"; import { removeTrailingSlash } from "@app/lib/fn"; import { logger } from "@app/lib/logger"; import { alphaNumericNanoId } from "@app/lib/nanoid"; +import { verifyHostInputValidity } from "../dynamic-secret-fns"; import { DynamicSecretRabbitMqSchema, TDynamicProviderFns } from "./models"; const generatePassword = () => { @@ -79,23 +78,8 @@ async function deleteRabbitMqUser({ axiosInstance, usernameToDelete }: TDeleteRa export const RabbitMqProvider = (): TDynamicProviderFns => { const validateProviderInputs = async (inputs: unknown) => { - const appCfg = getConfig(); - const isCloud = Boolean(appCfg.LICENSE_SERVER_KEY); // quick and dirty way to check if its cloud or not - const providerInputs = await DynamicSecretRabbitMqSchema.parseAsync(inputs); - if ( - isCloud && - // localhost - // internal ips - (providerInputs.host === "host.docker.internal" || - providerInputs.host.match(/^10\.\d+\.\d+\.\d+/) || - providerInputs.host.match(/^192\.168\.\d+\.\d+/)) - ) { - throw new BadRequestError({ message: "Invalid db host" }); - } - if (providerInputs.host === "localhost" || providerInputs.host === "127.0.0.1") { - throw new BadRequestError({ message: "Invalid db host" }); - } + verifyHostInputValidity(providerInputs.host); return providerInputs; }; diff --git a/backend/src/ee/services/dynamic-secret/providers/redis.ts b/backend/src/ee/services/dynamic-secret/providers/redis.ts index 1338e62e3..0e7ae99a0 100644 --- a/backend/src/ee/services/dynamic-secret/providers/redis.ts +++ b/backend/src/ee/services/dynamic-secret/providers/redis.ts @@ -3,11 +3,10 @@ import { Redis } from "ioredis"; import { customAlphabet } from "nanoid"; import { z } from "zod"; -import { getConfig } from "@app/lib/config/env"; import { BadRequestError } from "@app/lib/errors"; -import { getDbConnectionHost } from "@app/lib/knex"; import { alphaNumericNanoId } from "@app/lib/nanoid"; +import { verifyHostInputValidity } from "../dynamic-secret-fns"; import { DynamicSecretRedisDBSchema, TDynamicProviderFns } from "./models"; const generatePassword = () => { @@ -51,22 +50,8 @@ const executeTransactions = async (connection: Redis, commands: string[]): Promi export const RedisDatabaseProvider = (): TDynamicProviderFns => { const validateProviderInputs = async (inputs: unknown) => { - const appCfg = getConfig(); - const isCloud = Boolean(appCfg.LICENSE_SERVER_KEY); // quick and dirty way to check if its cloud or not - const dbHost = appCfg.DB_HOST || getDbConnectionHost(appCfg.DB_CONNECTION_URI); - const providerInputs = await DynamicSecretRedisDBSchema.parseAsync(inputs); - if ( - isCloud && - // localhost - // internal ips - (providerInputs.host === "host.docker.internal" || - providerInputs.host.match(/^10\.\d+\.\d+\.\d+/) || - providerInputs.host.match(/^192\.168\.\d+\.\d+/)) - ) - throw new BadRequestError({ message: "Invalid db host" }); - if (providerInputs.host === "localhost" || providerInputs.host === "127.0.0.1" || dbHost === providerInputs.host) - throw new BadRequestError({ message: "Invalid db host" }); + verifyHostInputValidity(providerInputs.host); return providerInputs; }; diff --git a/backend/src/ee/services/dynamic-secret/providers/sql-database.ts b/backend/src/ee/services/dynamic-secret/providers/sql-database.ts index 6745f573b..6acf23b06 100644 --- a/backend/src/ee/services/dynamic-secret/providers/sql-database.ts +++ b/backend/src/ee/services/dynamic-secret/providers/sql-database.ts @@ -3,11 +3,9 @@ import knex from "knex"; import { customAlphabet } from "nanoid"; import { z } from "zod"; -import { getConfig } from "@app/lib/config/env"; -import { BadRequestError } from "@app/lib/errors"; -import { getDbConnectionHost } from "@app/lib/knex"; import { alphaNumericNanoId } from "@app/lib/nanoid"; +import { verifyHostInputValidity } from "../dynamic-secret-fns"; import { DynamicSecretSqlDBSchema, SqlProviders, TDynamicProviderFns } from "./models"; const EXTERNAL_REQUEST_TIMEOUT = 10 * 1000; @@ -29,27 +27,8 @@ const generateUsername = (provider: SqlProviders) => { export const SqlDatabaseProvider = (): TDynamicProviderFns => { const validateProviderInputs = async (inputs: unknown) => { - const appCfg = getConfig(); - const isCloud = Boolean(appCfg.LICENSE_SERVER_KEY); // quick and dirty way to check if its cloud or not - const dbHost = appCfg.DB_HOST || getDbConnectionHost(appCfg.DB_CONNECTION_URI); - const providerInputs = await DynamicSecretSqlDBSchema.parseAsync(inputs); - if ( - isCloud && - // localhost - // internal ips - (providerInputs.host === "host.docker.internal" || - providerInputs.host.match(/^10\.\d+\.\d+\.\d+/) || - providerInputs.host.match(/^192\.168\.\d+\.\d+/)) - ) - throw new BadRequestError({ message: "Invalid db host" }); - if ( - providerInputs.host === "localhost" || - providerInputs.host === "127.0.0.1" || - // database infisical uses - dbHost === providerInputs.host - ) - throw new BadRequestError({ message: "Invalid db host" }); + verifyHostInputValidity(providerInputs.host); return providerInputs; };