mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 20:27:43 +00:00
feat(app-connections): Hashicorp Vault App Connection
This commit is contained in:
@@ -1857,6 +1857,12 @@ export const AppConnections = {
|
|||||||
WINDMILL: {
|
WINDMILL: {
|
||||||
instanceUrl: "The Windmill instance URL to connect with (defaults to https://app.windmill.dev).",
|
instanceUrl: "The Windmill instance URL to connect with (defaults to https://app.windmill.dev).",
|
||||||
accessToken: "The access token to use to connect with Windmill."
|
accessToken: "The access token to use to connect with Windmill."
|
||||||
|
},
|
||||||
|
HC_VAULT: {
|
||||||
|
instanceUrl: "The Hashicrop Vault instance URL to connect with.",
|
||||||
|
accessToken: "The access token used to connect with Hashicorp Vault.",
|
||||||
|
roleId: "The Role ID used to connect with Hashicorp Vault.",
|
||||||
|
secretId: "The Secret ID used to connect with Hashicorp Vault."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -24,6 +24,10 @@ import {
|
|||||||
} from "@app/services/app-connection/databricks";
|
} from "@app/services/app-connection/databricks";
|
||||||
import { GcpConnectionListItemSchema, SanitizedGcpConnectionSchema } from "@app/services/app-connection/gcp";
|
import { GcpConnectionListItemSchema, SanitizedGcpConnectionSchema } from "@app/services/app-connection/gcp";
|
||||||
import { GitHubConnectionListItemSchema, SanitizedGitHubConnectionSchema } from "@app/services/app-connection/github";
|
import { GitHubConnectionListItemSchema, SanitizedGitHubConnectionSchema } from "@app/services/app-connection/github";
|
||||||
|
import {
|
||||||
|
HCVaultConnectionListItemSchema,
|
||||||
|
SanitizedHCVaultConnectionSchema
|
||||||
|
} from "@app/services/app-connection/hc-vault";
|
||||||
import {
|
import {
|
||||||
HumanitecConnectionListItemSchema,
|
HumanitecConnectionListItemSchema,
|
||||||
SanitizedHumanitecConnectionSchema
|
SanitizedHumanitecConnectionSchema
|
||||||
@@ -59,7 +63,8 @@ const SanitizedAppConnectionSchema = z.union([
|
|||||||
...SanitizedMsSqlConnectionSchema.options,
|
...SanitizedMsSqlConnectionSchema.options,
|
||||||
...SanitizedCamundaConnectionSchema.options,
|
...SanitizedCamundaConnectionSchema.options,
|
||||||
...SanitizedWindmillConnectionSchema.options,
|
...SanitizedWindmillConnectionSchema.options,
|
||||||
...SanitizedAuth0ConnectionSchema.options
|
...SanitizedAuth0ConnectionSchema.options,
|
||||||
|
...SanitizedHCVaultConnectionSchema.options
|
||||||
]);
|
]);
|
||||||
|
|
||||||
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
||||||
@@ -76,7 +81,8 @@ const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
|||||||
MsSqlConnectionListItemSchema,
|
MsSqlConnectionListItemSchema,
|
||||||
CamundaConnectionListItemSchema,
|
CamundaConnectionListItemSchema,
|
||||||
WindmillConnectionListItemSchema,
|
WindmillConnectionListItemSchema,
|
||||||
Auth0ConnectionListItemSchema
|
Auth0ConnectionListItemSchema,
|
||||||
|
HCVaultConnectionListItemSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { readLimit } from "@app/server/config/rateLimiter";
|
||||||
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import {
|
||||||
|
CreateHCVaultConnectionSchema,
|
||||||
|
SanitizedHCVaultConnectionSchema,
|
||||||
|
UpdateHCVaultConnectionSchema
|
||||||
|
} from "@app/services/app-connection/hc-vault";
|
||||||
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
|
import { registerAppConnectionEndpoints } from "./app-connection-endpoints";
|
||||||
|
|
||||||
|
export const registerHCVaultConnectionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
registerAppConnectionEndpoints({
|
||||||
|
app: AppConnection.HCVault,
|
||||||
|
server,
|
||||||
|
sanitizedResponseSchema: SanitizedHCVaultConnectionSchema,
|
||||||
|
createSchema: CreateHCVaultConnectionSchema,
|
||||||
|
updateSchema: UpdateHCVaultConnectionSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
// The following endpoints are for internal Infisical App use only and not part of the public API
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: `/:connectionId/mounts`,
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
params: z.object({
|
||||||
|
connectionId: z.string().uuid()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.string().array()
|
||||||
|
}
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
|
handler: async (req) => {
|
||||||
|
const { connectionId } = req.params;
|
||||||
|
|
||||||
|
const mounts = await server.services.appConnection.hcvault.listMounts(connectionId, req.permission);
|
||||||
|
return mounts;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -8,6 +8,7 @@ import { registerCamundaConnectionRouter } from "./camunda-connection-router";
|
|||||||
import { registerDatabricksConnectionRouter } from "./databricks-connection-router";
|
import { registerDatabricksConnectionRouter } from "./databricks-connection-router";
|
||||||
import { registerGcpConnectionRouter } from "./gcp-connection-router";
|
import { registerGcpConnectionRouter } from "./gcp-connection-router";
|
||||||
import { registerGitHubConnectionRouter } from "./github-connection-router";
|
import { registerGitHubConnectionRouter } from "./github-connection-router";
|
||||||
|
import { registerHCVaultConnectionRouter } from "./hc-vault-connection-router";
|
||||||
import { registerHumanitecConnectionRouter } from "./humanitec-connection-router";
|
import { registerHumanitecConnectionRouter } from "./humanitec-connection-router";
|
||||||
import { registerMsSqlConnectionRouter } from "./mssql-connection-router";
|
import { registerMsSqlConnectionRouter } from "./mssql-connection-router";
|
||||||
import { registerPostgresConnectionRouter } from "./postgres-connection-router";
|
import { registerPostgresConnectionRouter } from "./postgres-connection-router";
|
||||||
@@ -32,5 +33,6 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record<AppConnection, (server:
|
|||||||
[AppConnection.MsSql]: registerMsSqlConnectionRouter,
|
[AppConnection.MsSql]: registerMsSqlConnectionRouter,
|
||||||
[AppConnection.Camunda]: registerCamundaConnectionRouter,
|
[AppConnection.Camunda]: registerCamundaConnectionRouter,
|
||||||
[AppConnection.Windmill]: registerWindmillConnectionRouter,
|
[AppConnection.Windmill]: registerWindmillConnectionRouter,
|
||||||
[AppConnection.Auth0]: registerAuth0ConnectionRouter
|
[AppConnection.Auth0]: registerAuth0ConnectionRouter,
|
||||||
|
[AppConnection.HCVault]: registerHCVaultConnectionRouter
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -12,7 +12,8 @@ export enum AppConnection {
|
|||||||
MsSql = "mssql",
|
MsSql = "mssql",
|
||||||
Camunda = "camunda",
|
Camunda = "camunda",
|
||||||
Windmill = "windmill",
|
Windmill = "windmill",
|
||||||
Auth0 = "auth0"
|
Auth0 = "auth0",
|
||||||
|
HCVault = "hashicorp-vault"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum AWSRegion {
|
export enum AWSRegion {
|
||||||
|
|||||||
@@ -36,6 +36,11 @@ import {
|
|||||||
} from "./databricks";
|
} from "./databricks";
|
||||||
import { GcpConnectionMethod, getGcpConnectionListItem, validateGcpConnectionCredentials } from "./gcp";
|
import { GcpConnectionMethod, getGcpConnectionListItem, validateGcpConnectionCredentials } from "./gcp";
|
||||||
import { getGitHubConnectionListItem, GitHubConnectionMethod, validateGitHubConnectionCredentials } from "./github";
|
import { getGitHubConnectionListItem, GitHubConnectionMethod, validateGitHubConnectionCredentials } from "./github";
|
||||||
|
import {
|
||||||
|
getHCVaultConnectionListItem,
|
||||||
|
HCVaultConnectionMethod,
|
||||||
|
validateHCVaultConnectionCredentials
|
||||||
|
} from "./hc-vault";
|
||||||
import {
|
import {
|
||||||
getHumanitecConnectionListItem,
|
getHumanitecConnectionListItem,
|
||||||
HumanitecConnectionMethod,
|
HumanitecConnectionMethod,
|
||||||
@@ -71,7 +76,8 @@ export const listAppConnectionOptions = () => {
|
|||||||
getMsSqlConnectionListItem(),
|
getMsSqlConnectionListItem(),
|
||||||
getCamundaConnectionListItem(),
|
getCamundaConnectionListItem(),
|
||||||
getWindmillConnectionListItem(),
|
getWindmillConnectionListItem(),
|
||||||
getAuth0ConnectionListItem()
|
getAuth0ConnectionListItem(),
|
||||||
|
getHCVaultConnectionListItem()
|
||||||
].sort((a, b) => a.name.localeCompare(b.name));
|
].sort((a, b) => a.name.localeCompare(b.name));
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -135,7 +141,8 @@ export const validateAppConnectionCredentials = async (
|
|||||||
[AppConnection.Vercel]: validateVercelConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Vercel]: validateVercelConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.TerraformCloud]: validateTerraformCloudConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.TerraformCloud]: validateTerraformCloudConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Auth0]: validateAuth0ConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Auth0]: validateAuth0ConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Windmill]: validateWindmillConnectionCredentials as TAppConnectionCredentialsValidator
|
[AppConnection.Windmill]: validateWindmillConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
|
[AppConnection.HCVault]: validateHCVaultConnectionCredentials as TAppConnectionCredentialsValidator
|
||||||
};
|
};
|
||||||
|
|
||||||
return VALIDATE_APP_CONNECTION_CREDENTIALS_MAP[appConnection.app](appConnection);
|
return VALIDATE_APP_CONNECTION_CREDENTIALS_MAP[appConnection.app](appConnection);
|
||||||
@@ -167,9 +174,12 @@ export const getAppConnectionMethodName = (method: TAppConnection["method"]) =>
|
|||||||
case MsSqlConnectionMethod.UsernameAndPassword:
|
case MsSqlConnectionMethod.UsernameAndPassword:
|
||||||
return "Username & Password";
|
return "Username & Password";
|
||||||
case WindmillConnectionMethod.AccessToken:
|
case WindmillConnectionMethod.AccessToken:
|
||||||
|
case HCVaultConnectionMethod.AccessToken:
|
||||||
return "Access Token";
|
return "Access Token";
|
||||||
case Auth0ConnectionMethod.ClientCredentials:
|
case Auth0ConnectionMethod.ClientCredentials:
|
||||||
return "Client Credentials";
|
return "Client Credentials";
|
||||||
|
case HCVaultConnectionMethod.AppRole:
|
||||||
|
return "App Role";
|
||||||
default:
|
default:
|
||||||
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions
|
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions
|
||||||
throw new Error(`Unhandled App Connection Method: ${method}`);
|
throw new Error(`Unhandled App Connection Method: ${method}`);
|
||||||
@@ -214,5 +224,6 @@ export const TRANSITION_CONNECTION_CREDENTIALS_TO_PLATFORM: Record<
|
|||||||
[AppConnection.Camunda]: platformManagedCredentialsNotSupported,
|
[AppConnection.Camunda]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Vercel]: platformManagedCredentialsNotSupported,
|
[AppConnection.Vercel]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Windmill]: platformManagedCredentialsNotSupported,
|
[AppConnection.Windmill]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Auth0]: platformManagedCredentialsNotSupported
|
[AppConnection.Auth0]: platformManagedCredentialsNotSupported,
|
||||||
|
[AppConnection.HCVault]: platformManagedCredentialsNotSupported
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -41,6 +41,8 @@ import { ValidateGcpConnectionCredentialsSchema } from "./gcp";
|
|||||||
import { gcpConnectionService } from "./gcp/gcp-connection-service";
|
import { gcpConnectionService } from "./gcp/gcp-connection-service";
|
||||||
import { ValidateGitHubConnectionCredentialsSchema } from "./github";
|
import { ValidateGitHubConnectionCredentialsSchema } from "./github";
|
||||||
import { githubConnectionService } from "./github/github-connection-service";
|
import { githubConnectionService } from "./github/github-connection-service";
|
||||||
|
import { ValidateHCVaultConnectionCredentialsSchema } from "./hc-vault";
|
||||||
|
import { hcVaultConnectionService } from "./hc-vault/hc-vault-connection-service";
|
||||||
import { ValidateHumanitecConnectionCredentialsSchema } from "./humanitec";
|
import { ValidateHumanitecConnectionCredentialsSchema } from "./humanitec";
|
||||||
import { humanitecConnectionService } from "./humanitec/humanitec-connection-service";
|
import { humanitecConnectionService } from "./humanitec/humanitec-connection-service";
|
||||||
import { ValidateMsSqlConnectionCredentialsSchema } from "./mssql";
|
import { ValidateMsSqlConnectionCredentialsSchema } from "./mssql";
|
||||||
@@ -74,7 +76,8 @@ const VALIDATE_APP_CONNECTION_CREDENTIALS_MAP: Record<AppConnection, TValidateAp
|
|||||||
[AppConnection.MsSql]: ValidateMsSqlConnectionCredentialsSchema,
|
[AppConnection.MsSql]: ValidateMsSqlConnectionCredentialsSchema,
|
||||||
[AppConnection.Camunda]: ValidateCamundaConnectionCredentialsSchema,
|
[AppConnection.Camunda]: ValidateCamundaConnectionCredentialsSchema,
|
||||||
[AppConnection.Windmill]: ValidateWindmillConnectionCredentialsSchema,
|
[AppConnection.Windmill]: ValidateWindmillConnectionCredentialsSchema,
|
||||||
[AppConnection.Auth0]: ValidateAuth0ConnectionCredentialsSchema
|
[AppConnection.Auth0]: ValidateAuth0ConnectionCredentialsSchema,
|
||||||
|
[AppConnection.HCVault]: ValidateHCVaultConnectionCredentialsSchema
|
||||||
};
|
};
|
||||||
|
|
||||||
export const appConnectionServiceFactory = ({
|
export const appConnectionServiceFactory = ({
|
||||||
@@ -450,6 +453,7 @@ export const appConnectionServiceFactory = ({
|
|||||||
camunda: camundaConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
camunda: camundaConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
vercel: vercelConnectionService(connectAppConnectionById),
|
vercel: vercelConnectionService(connectAppConnectionById),
|
||||||
windmill: windmillConnectionService(connectAppConnectionById),
|
windmill: windmillConnectionService(connectAppConnectionById),
|
||||||
auth0: auth0ConnectionService(connectAppConnectionById, appConnectionDAL, kmsService)
|
auth0: auth0ConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
|
hcvault: hcVaultConnectionService(connectAppConnectionById)
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -51,6 +51,12 @@ import {
|
|||||||
TGitHubConnectionInput,
|
TGitHubConnectionInput,
|
||||||
TValidateGitHubConnectionCredentialsSchema
|
TValidateGitHubConnectionCredentialsSchema
|
||||||
} from "./github";
|
} from "./github";
|
||||||
|
import {
|
||||||
|
THCVaultConnection,
|
||||||
|
THCVaultConnectionConfig,
|
||||||
|
THCVaultConnectionInput,
|
||||||
|
TValidateHCVaultConnectionCredentialsSchema
|
||||||
|
} from "./hc-vault";
|
||||||
import {
|
import {
|
||||||
THumanitecConnection,
|
THumanitecConnection,
|
||||||
THumanitecConnectionConfig,
|
THumanitecConnectionConfig,
|
||||||
@@ -97,6 +103,7 @@ export type TAppConnection = { id: string } & (
|
|||||||
| TCamundaConnection
|
| TCamundaConnection
|
||||||
| TWindmillConnection
|
| TWindmillConnection
|
||||||
| TAuth0Connection
|
| TAuth0Connection
|
||||||
|
| THCVaultConnection
|
||||||
);
|
);
|
||||||
|
|
||||||
export type TAppConnectionRaw = NonNullable<Awaited<ReturnType<TAppConnectionDALFactory["findById"]>>>;
|
export type TAppConnectionRaw = NonNullable<Awaited<ReturnType<TAppConnectionDALFactory["findById"]>>>;
|
||||||
@@ -118,6 +125,7 @@ export type TAppConnectionInput = { id: string } & (
|
|||||||
| TCamundaConnectionInput
|
| TCamundaConnectionInput
|
||||||
| TWindmillConnectionInput
|
| TWindmillConnectionInput
|
||||||
| TAuth0ConnectionInput
|
| TAuth0ConnectionInput
|
||||||
|
| THCVaultConnectionInput
|
||||||
);
|
);
|
||||||
|
|
||||||
export type TSqlConnectionInput = TPostgresConnectionInput | TMsSqlConnectionInput;
|
export type TSqlConnectionInput = TPostgresConnectionInput | TMsSqlConnectionInput;
|
||||||
@@ -144,7 +152,8 @@ export type TAppConnectionConfig =
|
|||||||
| TSqlConnectionConfig
|
| TSqlConnectionConfig
|
||||||
| TCamundaConnectionConfig
|
| TCamundaConnectionConfig
|
||||||
| TWindmillConnectionConfig
|
| TWindmillConnectionConfig
|
||||||
| TAuth0ConnectionConfig;
|
| TAuth0ConnectionConfig
|
||||||
|
| THCVaultConnectionConfig;
|
||||||
|
|
||||||
export type TValidateAppConnectionCredentialsSchema =
|
export type TValidateAppConnectionCredentialsSchema =
|
||||||
| TValidateAwsConnectionCredentialsSchema
|
| TValidateAwsConnectionCredentialsSchema
|
||||||
@@ -160,7 +169,8 @@ export type TValidateAppConnectionCredentialsSchema =
|
|||||||
| TValidateTerraformCloudConnectionCredentialsSchema
|
| TValidateTerraformCloudConnectionCredentialsSchema
|
||||||
| TValidateVercelConnectionCredentialsSchema
|
| TValidateVercelConnectionCredentialsSchema
|
||||||
| TValidateWindmillConnectionCredentialsSchema
|
| TValidateWindmillConnectionCredentialsSchema
|
||||||
| TValidateAuth0ConnectionCredentialsSchema;
|
| TValidateAuth0ConnectionCredentialsSchema
|
||||||
|
| TValidateHCVaultConnectionCredentialsSchema;
|
||||||
|
|
||||||
export type TListAwsConnectionKmsKeys = {
|
export type TListAwsConnectionKmsKeys = {
|
||||||
connectionId: string;
|
connectionId: string;
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export enum HCVaultConnectionMethod {
|
||||||
|
AccessToken = "access-token",
|
||||||
|
AppRole = "app-role"
|
||||||
|
}
|
||||||
@@ -0,0 +1,102 @@
|
|||||||
|
import { AxiosError } from "axios";
|
||||||
|
|
||||||
|
import { request } from "@app/lib/config/request";
|
||||||
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
import { removeTrailingSlash } from "@app/lib/fn";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
|
||||||
|
import { HCVaultConnectionMethod } from "./hc-vault-connection-enums";
|
||||||
|
import {
|
||||||
|
THCVaultConnection,
|
||||||
|
THCVaultConnectionConfig,
|
||||||
|
THCVaultMountResponse,
|
||||||
|
TValidateHCVaultConnectionCredentials
|
||||||
|
} from "./hc-vault-connection-types";
|
||||||
|
|
||||||
|
export const getHCVaultConnectionListItem = () => ({
|
||||||
|
name: "HCVault" as const,
|
||||||
|
app: AppConnection.HCVault as const,
|
||||||
|
methods: Object.values(HCVaultConnectionMethod) as [
|
||||||
|
HCVaultConnectionMethod.AccessToken,
|
||||||
|
HCVaultConnectionMethod.AppRole
|
||||||
|
]
|
||||||
|
});
|
||||||
|
|
||||||
|
type TokenRespData = {
|
||||||
|
auth: {
|
||||||
|
client_token: string;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
export const getHCVaultAccessToken = async (connection: TValidateHCVaultConnectionCredentials) => {
|
||||||
|
// Return access token directly if not using AppRole method
|
||||||
|
if (connection.method !== HCVaultConnectionMethod.AppRole) {
|
||||||
|
return connection.credentials.accessToken;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Generate temporary token for AppRole method
|
||||||
|
try {
|
||||||
|
const { instanceUrl, roleId, secretId } = connection.credentials;
|
||||||
|
const tokenResp = await request.post<TokenRespData>(
|
||||||
|
`${removeTrailingSlash(instanceUrl)}/v1/auth/approle/login`,
|
||||||
|
{ role_id: roleId, secret_id: secretId },
|
||||||
|
{ headers: { "Content-Type": "application/json" } }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (tokenResp.status !== 200) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Unable to validate credentials: Hashicorp Vault responded with a status code of ${tokenResp.status} (${tokenResp.statusText}). Verify credentials and try again.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return tokenResp.data.auth.client_token;
|
||||||
|
} catch (e: unknown) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Unable to validate connection: verify credentials"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const validateHCVaultConnectionCredentials = async (config: THCVaultConnectionConfig) => {
|
||||||
|
const instanceUrl = removeTrailingSlash(config.credentials.instanceUrl);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const accessToken = await getHCVaultAccessToken(config);
|
||||||
|
|
||||||
|
// Verify token
|
||||||
|
await request.get(`${instanceUrl}/v1/auth/token/lookup-self`, {
|
||||||
|
headers: { "X-Vault-Token": accessToken }
|
||||||
|
});
|
||||||
|
|
||||||
|
return config.credentials;
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to validate credentials: ${error.message || "Unknown error"}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Unable to validate connection: verify credentials"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const listHCVaultMounts = async (appConnection: THCVaultConnection) => {
|
||||||
|
const instanceUrl = removeTrailingSlash(appConnection.credentials.instanceUrl);
|
||||||
|
const accessToken = await getHCVaultAccessToken(appConnection);
|
||||||
|
|
||||||
|
const { data } = await request.get<THCVaultMountResponse>(`${instanceUrl}/v1/sys/mounts`, {
|
||||||
|
headers: { "X-Vault-Token": accessToken }
|
||||||
|
});
|
||||||
|
|
||||||
|
const mounts: string[] = [];
|
||||||
|
|
||||||
|
// Filter for "kv" type only
|
||||||
|
Object.entries(data.data).forEach(([path, mount]) => {
|
||||||
|
if (mount.type === "kv") {
|
||||||
|
mounts.push(path);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return mounts;
|
||||||
|
};
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { AppConnections } from "@app/lib/api-docs";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import {
|
||||||
|
BaseAppConnectionSchema,
|
||||||
|
GenericCreateAppConnectionFieldsSchema,
|
||||||
|
GenericUpdateAppConnectionFieldsSchema
|
||||||
|
} from "@app/services/app-connection/app-connection-schemas";
|
||||||
|
|
||||||
|
import { HCVaultConnectionMethod } from "./hc-vault-connection-enums";
|
||||||
|
|
||||||
|
const InstanceUrlSchema = z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Instance URL required")
|
||||||
|
.url("Invalid Instance URL")
|
||||||
|
.describe(AppConnections.CREDENTIALS.HC_VAULT.instanceUrl);
|
||||||
|
|
||||||
|
export const HCVaultConnectionAccessTokenCredentialsSchema = z.object({
|
||||||
|
instanceUrl: InstanceUrlSchema,
|
||||||
|
accessToken: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Access Token required")
|
||||||
|
.describe(AppConnections.CREDENTIALS.HC_VAULT.accessToken)
|
||||||
|
});
|
||||||
|
|
||||||
|
export const HCVaultConnectionAppRoleCredentialsSchema = z.object({
|
||||||
|
instanceUrl: InstanceUrlSchema,
|
||||||
|
roleId: z.string().trim().min(1, "Role ID required").describe(AppConnections.CREDENTIALS.HC_VAULT.roleId),
|
||||||
|
secretId: z.string().trim().min(1, "Secret ID required").describe(AppConnections.CREDENTIALS.HC_VAULT.secretId)
|
||||||
|
});
|
||||||
|
|
||||||
|
const BaseHCVaultConnectionSchema = BaseAppConnectionSchema.extend({ app: z.literal(AppConnection.HCVault) });
|
||||||
|
|
||||||
|
export const HCVaultConnectionSchema = z.intersection(
|
||||||
|
BaseHCVaultConnectionSchema,
|
||||||
|
z.discriminatedUnion("method", [
|
||||||
|
z.object({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AccessToken),
|
||||||
|
credentials: HCVaultConnectionAccessTokenCredentialsSchema
|
||||||
|
}),
|
||||||
|
z.object({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AppRole),
|
||||||
|
credentials: HCVaultConnectionAppRoleCredentialsSchema
|
||||||
|
})
|
||||||
|
])
|
||||||
|
);
|
||||||
|
|
||||||
|
export const SanitizedHCVaultConnectionSchema = z.discriminatedUnion("method", [
|
||||||
|
BaseHCVaultConnectionSchema.extend({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AccessToken),
|
||||||
|
credentials: HCVaultConnectionAccessTokenCredentialsSchema.pick({})
|
||||||
|
}),
|
||||||
|
BaseHCVaultConnectionSchema.extend({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AppRole),
|
||||||
|
credentials: HCVaultConnectionAppRoleCredentialsSchema.pick({})
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
export const ValidateHCVaultConnectionCredentialsSchema = z.discriminatedUnion("method", [
|
||||||
|
z.object({
|
||||||
|
method: z
|
||||||
|
.literal(HCVaultConnectionMethod.AccessToken)
|
||||||
|
.describe(AppConnections.CREATE(AppConnection.HCVault).method),
|
||||||
|
credentials: HCVaultConnectionAccessTokenCredentialsSchema.describe(
|
||||||
|
AppConnections.CREATE(AppConnection.HCVault).credentials
|
||||||
|
)
|
||||||
|
}),
|
||||||
|
z.object({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AppRole).describe(AppConnections.CREATE(AppConnection.HCVault).method),
|
||||||
|
credentials: HCVaultConnectionAppRoleCredentialsSchema.describe(
|
||||||
|
AppConnections.CREATE(AppConnection.HCVault).credentials
|
||||||
|
)
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
export const CreateHCVaultConnectionSchema = ValidateHCVaultConnectionCredentialsSchema.and(
|
||||||
|
GenericCreateAppConnectionFieldsSchema(AppConnection.HCVault)
|
||||||
|
);
|
||||||
|
|
||||||
|
export const UpdateHCVaultConnectionSchema = z
|
||||||
|
.object({
|
||||||
|
credentials: HCVaultConnectionAccessTokenCredentialsSchema.optional().describe(
|
||||||
|
AppConnections.UPDATE(AppConnection.HCVault).credentials
|
||||||
|
)
|
||||||
|
})
|
||||||
|
.and(GenericUpdateAppConnectionFieldsSchema(AppConnection.HCVault));
|
||||||
|
|
||||||
|
export const HCVaultConnectionListItemSchema = z.object({
|
||||||
|
name: z.literal("HCVault"),
|
||||||
|
app: z.literal(AppConnection.HCVault),
|
||||||
|
methods: z.nativeEnum(HCVaultConnectionMethod).array()
|
||||||
|
});
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
import { OrgServiceActor } from "@app/lib/types";
|
||||||
|
|
||||||
|
import { AppConnection } from "../app-connection-enums";
|
||||||
|
import { listHCVaultMounts } from "./hc-vault-connection-fns";
|
||||||
|
import { THCVaultConnection } from "./hc-vault-connection-types";
|
||||||
|
|
||||||
|
type TGetAppConnectionFunc = (
|
||||||
|
app: AppConnection,
|
||||||
|
connectionId: string,
|
||||||
|
actor: OrgServiceActor
|
||||||
|
) => Promise<THCVaultConnection>;
|
||||||
|
|
||||||
|
export const hcVaultConnectionService = (getAppConnection: TGetAppConnectionFunc) => {
|
||||||
|
const listMounts = async (connectionId: string, actor: OrgServiceActor) => {
|
||||||
|
const appConnection = await getAppConnection(AppConnection.HCVault, connectionId, actor);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const mounts = await listHCVaultMounts(appConnection);
|
||||||
|
return mounts;
|
||||||
|
} catch (error) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return {
|
||||||
|
listMounts
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { DiscriminativePick } from "@app/lib/types";
|
||||||
|
|
||||||
|
import { AppConnection } from "../app-connection-enums";
|
||||||
|
import {
|
||||||
|
CreateHCVaultConnectionSchema,
|
||||||
|
HCVaultConnectionSchema,
|
||||||
|
ValidateHCVaultConnectionCredentialsSchema
|
||||||
|
} from "./hc-vault-connection-schemas";
|
||||||
|
|
||||||
|
export type THCVaultConnection = z.infer<typeof HCVaultConnectionSchema>;
|
||||||
|
|
||||||
|
export type THCVaultConnectionInput = z.infer<typeof CreateHCVaultConnectionSchema> & {
|
||||||
|
app: AppConnection.HCVault;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TValidateHCVaultConnectionCredentialsSchema = typeof ValidateHCVaultConnectionCredentialsSchema;
|
||||||
|
|
||||||
|
export type TValidateHCVaultConnectionCredentials = z.infer<typeof ValidateHCVaultConnectionCredentialsSchema>;
|
||||||
|
|
||||||
|
export type THCVaultConnectionConfig = DiscriminativePick<THCVaultConnectionInput, "method" | "app" | "credentials"> & {
|
||||||
|
orgId: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type THCVaultMountResponse = {
|
||||||
|
data: {
|
||||||
|
[key: string]: {
|
||||||
|
type: string; // We're only interested in "kv" types
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export * from "./hc-vault-connection-enums";
|
||||||
|
export * from "./hc-vault-connection-fns";
|
||||||
|
export * from "./hc-vault-connection-schemas";
|
||||||
|
export * from "./hc-vault-connection-types";
|
||||||
@@ -17,7 +17,8 @@ import {
|
|||||||
TAppConnection,
|
TAppConnection,
|
||||||
TerraformCloudConnectionMethod,
|
TerraformCloudConnectionMethod,
|
||||||
VercelConnectionMethod,
|
VercelConnectionMethod,
|
||||||
WindmillConnectionMethod
|
WindmillConnectionMethod,
|
||||||
|
HCVaultConnectionMethod
|
||||||
} from "@app/hooks/api/appConnections/types";
|
} from "@app/hooks/api/appConnections/types";
|
||||||
|
|
||||||
export const APP_CONNECTION_MAP: Record<
|
export const APP_CONNECTION_MAP: Record<
|
||||||
@@ -43,7 +44,8 @@ export const APP_CONNECTION_MAP: Record<
|
|||||||
[AppConnection.MsSql]: { name: "Microsoft SQL Server", image: "MsSql.png" },
|
[AppConnection.MsSql]: { name: "Microsoft SQL Server", image: "MsSql.png" },
|
||||||
[AppConnection.Camunda]: { name: "Camunda", image: "Camunda.png" },
|
[AppConnection.Camunda]: { name: "Camunda", image: "Camunda.png" },
|
||||||
[AppConnection.Windmill]: { name: "Windmill", image: "Windmill.png" },
|
[AppConnection.Windmill]: { name: "Windmill", image: "Windmill.png" },
|
||||||
[AppConnection.Auth0]: { name: "Auth0", image: "Auth0.png", size: 40 }
|
[AppConnection.Auth0]: { name: "Auth0", image: "Auth0.png", size: 40 },
|
||||||
|
[AppConnection.HCVault]: { name: "Hashicorp Vault", image: "Vault.png" }
|
||||||
};
|
};
|
||||||
|
|
||||||
export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => {
|
export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => {
|
||||||
@@ -71,10 +73,13 @@ export const getAppConnectionMethodDetails = (method: TAppConnection["method"])
|
|||||||
case PostgresConnectionMethod.UsernameAndPassword:
|
case PostgresConnectionMethod.UsernameAndPassword:
|
||||||
case MsSqlConnectionMethod.UsernameAndPassword:
|
case MsSqlConnectionMethod.UsernameAndPassword:
|
||||||
return { name: "Username & Password", icon: faLock };
|
return { name: "Username & Password", icon: faLock };
|
||||||
|
case HCVaultConnectionMethod.AccessToken:
|
||||||
case WindmillConnectionMethod.AccessToken:
|
case WindmillConnectionMethod.AccessToken:
|
||||||
return { name: "Access Token", icon: faKey };
|
return { name: "Access Token", icon: faKey };
|
||||||
case Auth0ConnectionMethod.ClientCredentials:
|
case Auth0ConnectionMethod.ClientCredentials:
|
||||||
return { name: "Client Credentials", icon: faServer };
|
return { name: "Client Credentials", icon: faServer };
|
||||||
|
case HCVaultConnectionMethod.AppRole:
|
||||||
|
return { name: "App Role", icon: faUser };
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App Connection Method: ${method}`);
|
throw new Error(`Unhandled App Connection Method: ${method}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,5 +12,6 @@ export enum AppConnection {
|
|||||||
MsSql = "mssql",
|
MsSql = "mssql",
|
||||||
Camunda = "camunda",
|
Camunda = "camunda",
|
||||||
Windmill = "windmill",
|
Windmill = "windmill",
|
||||||
Auth0 = "auth0"
|
Auth0 = "auth0",
|
||||||
|
HCVault = "hashicorp-vault"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
export * from "./queries";
|
||||||
|
export * from "./types";
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
import { useQuery, UseQueryOptions } from "@tanstack/react-query";
|
||||||
|
|
||||||
|
import { apiRequest } from "@app/config/request";
|
||||||
|
|
||||||
|
import { appConnectionKeys } from "../queries";
|
||||||
|
|
||||||
|
const hcVaultConnectionKeys = {
|
||||||
|
all: [...appConnectionKeys.all, "hcvault"] as const,
|
||||||
|
listMounts: (connectionId: string) =>
|
||||||
|
[...hcVaultConnectionKeys.all, "mounts", connectionId] as const
|
||||||
|
};
|
||||||
|
|
||||||
|
export const useHCVaultConnectionListWorkspaces = (
|
||||||
|
connectionId: string,
|
||||||
|
options?: Omit<
|
||||||
|
UseQueryOptions<
|
||||||
|
string[],
|
||||||
|
unknown,
|
||||||
|
string[],
|
||||||
|
ReturnType<typeof hcVaultConnectionKeys.listMounts>
|
||||||
|
>,
|
||||||
|
"queryKey" | "queryFn"
|
||||||
|
>
|
||||||
|
) => {
|
||||||
|
return useQuery({
|
||||||
|
queryKey: hcVaultConnectionKeys.listMounts(connectionId),
|
||||||
|
queryFn: async () => {
|
||||||
|
const { data } = await apiRequest.get<string[]>(
|
||||||
|
`/api/v1/app-connections/hc-vault/${connectionId}/mounts`
|
||||||
|
);
|
||||||
|
|
||||||
|
return data;
|
||||||
|
},
|
||||||
|
...options
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -67,6 +67,10 @@ export type TAuth0ConnectionOption = TAppConnectionOptionBase & {
|
|||||||
app: AppConnection.Auth0;
|
app: AppConnection.Auth0;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export type THCVaultConnectionOption = TAppConnectionOptionBase & {
|
||||||
|
app: AppConnection.HCVault;
|
||||||
|
};
|
||||||
|
|
||||||
export type TAppConnectionOption =
|
export type TAppConnectionOption =
|
||||||
| TAwsConnectionOption
|
| TAwsConnectionOption
|
||||||
| TGitHubConnectionOption
|
| TGitHubConnectionOption
|
||||||
@@ -81,7 +85,8 @@ export type TAppConnectionOption =
|
|||||||
| TMsSqlConnectionOption
|
| TMsSqlConnectionOption
|
||||||
| TCamundaConnectionOption
|
| TCamundaConnectionOption
|
||||||
| TWindmillConnectionOption
|
| TWindmillConnectionOption
|
||||||
| TAuth0ConnectionOption;
|
| TAuth0ConnectionOption
|
||||||
|
| THCVaultConnectionOption;
|
||||||
|
|
||||||
export type TAppConnectionOptionMap = {
|
export type TAppConnectionOptionMap = {
|
||||||
[AppConnection.AWS]: TAwsConnectionOption;
|
[AppConnection.AWS]: TAwsConnectionOption;
|
||||||
@@ -98,4 +103,5 @@ export type TAppConnectionOptionMap = {
|
|||||||
[AppConnection.Camunda]: TCamundaConnectionOption;
|
[AppConnection.Camunda]: TCamundaConnectionOption;
|
||||||
[AppConnection.Windmill]: TWindmillConnectionOption;
|
[AppConnection.Windmill]: TWindmillConnectionOption;
|
||||||
[AppConnection.Auth0]: TAuth0ConnectionOption;
|
[AppConnection.Auth0]: TAuth0ConnectionOption;
|
||||||
|
[AppConnection.HCVault]: THCVaultConnectionOption;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,25 @@
|
|||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import { TRootAppConnection } from "@app/hooks/api/appConnections/types/root-connection";
|
||||||
|
|
||||||
|
export enum HCVaultConnectionMethod {
|
||||||
|
AccessToken = "access-token",
|
||||||
|
AppRole = "app-role"
|
||||||
|
}
|
||||||
|
|
||||||
|
export type THCVaultConnection = TRootAppConnection & { app: AppConnection.HCVault } & (
|
||||||
|
| {
|
||||||
|
method: HCVaultConnectionMethod.AccessToken;
|
||||||
|
credentials: {
|
||||||
|
instanceUrl: string;
|
||||||
|
accessToken: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
method: HCVaultConnectionMethod.AppRole;
|
||||||
|
credentials: {
|
||||||
|
instanceUrl: string;
|
||||||
|
roleId: string;
|
||||||
|
secretId: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
);
|
||||||
@@ -8,6 +8,7 @@ import { TCamundaConnection } from "./camunda-connection";
|
|||||||
import { TDatabricksConnection } from "./databricks-connection";
|
import { TDatabricksConnection } from "./databricks-connection";
|
||||||
import { TGcpConnection } from "./gcp-connection";
|
import { TGcpConnection } from "./gcp-connection";
|
||||||
import { TGitHubConnection } from "./github-connection";
|
import { TGitHubConnection } from "./github-connection";
|
||||||
|
import { THCVaultConnection } from "./hc-vault-connection";
|
||||||
import { THumanitecConnection } from "./humanitec-connection";
|
import { THumanitecConnection } from "./humanitec-connection";
|
||||||
import { TMsSqlConnection } from "./mssql-connection";
|
import { TMsSqlConnection } from "./mssql-connection";
|
||||||
import { TPostgresConnection } from "./postgres-connection";
|
import { TPostgresConnection } from "./postgres-connection";
|
||||||
@@ -29,6 +30,7 @@ export * from "./postgres-connection";
|
|||||||
export * from "./terraform-cloud-connection";
|
export * from "./terraform-cloud-connection";
|
||||||
export * from "./vercel-connection";
|
export * from "./vercel-connection";
|
||||||
export * from "./windmill-connection";
|
export * from "./windmill-connection";
|
||||||
|
export * from "./hc-vault-connection";
|
||||||
|
|
||||||
export type TAppConnection =
|
export type TAppConnection =
|
||||||
| TAwsConnection
|
| TAwsConnection
|
||||||
@@ -44,7 +46,8 @@ export type TAppConnection =
|
|||||||
| TMsSqlConnection
|
| TMsSqlConnection
|
||||||
| TCamundaConnection
|
| TCamundaConnection
|
||||||
| TWindmillConnection
|
| TWindmillConnection
|
||||||
| TAuth0Connection;
|
| TAuth0Connection
|
||||||
|
| THCVaultConnection;
|
||||||
|
|
||||||
export type TAvailableAppConnection = Pick<TAppConnection, "name" | "id">;
|
export type TAvailableAppConnection = Pick<TAppConnection, "name" | "id">;
|
||||||
|
|
||||||
@@ -86,4 +89,5 @@ export type TAppConnectionMap = {
|
|||||||
[AppConnection.Camunda]: TCamundaConnection;
|
[AppConnection.Camunda]: TCamundaConnection;
|
||||||
[AppConnection.Windmill]: TWindmillConnection;
|
[AppConnection.Windmill]: TWindmillConnection;
|
||||||
[AppConnection.Auth0]: TAuth0Connection;
|
[AppConnection.Auth0]: TAuth0Connection;
|
||||||
|
[AppConnection.HCVault]: THCVaultConnection;
|
||||||
};
|
};
|
||||||
|
|||||||
+5
@@ -23,6 +23,7 @@ import { PostgresConnectionForm } from "./PostgresConnectionForm";
|
|||||||
import { TerraformCloudConnectionForm } from "./TerraformCloudConnectionForm";
|
import { TerraformCloudConnectionForm } from "./TerraformCloudConnectionForm";
|
||||||
import { VercelConnectionForm } from "./VercelConnectionForm";
|
import { VercelConnectionForm } from "./VercelConnectionForm";
|
||||||
import { WindmillConnectionForm } from "./WindmillConnectionForm";
|
import { WindmillConnectionForm } from "./WindmillConnectionForm";
|
||||||
|
import { HCVaultConnectionForm } from "./HCVaultConnectionForm";
|
||||||
|
|
||||||
type FormProps = {
|
type FormProps = {
|
||||||
onComplete: (appConnection: TAppConnection) => void;
|
onComplete: (appConnection: TAppConnection) => void;
|
||||||
@@ -89,6 +90,8 @@ const CreateForm = ({ app, onComplete }: CreateFormProps) => {
|
|||||||
return <WindmillConnectionForm onSubmit={onSubmit} />;
|
return <WindmillConnectionForm onSubmit={onSubmit} />;
|
||||||
case AppConnection.Auth0:
|
case AppConnection.Auth0:
|
||||||
return <Auth0ConnectionForm onSubmit={onSubmit} />;
|
return <Auth0ConnectionForm onSubmit={onSubmit} />;
|
||||||
|
case AppConnection.HCVault:
|
||||||
|
return <HCVaultConnectionForm onSubmit={onSubmit} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App ${app}`);
|
throw new Error(`Unhandled App ${app}`);
|
||||||
}
|
}
|
||||||
@@ -153,6 +156,8 @@ const UpdateForm = ({ appConnection, onComplete }: UpdateFormProps) => {
|
|||||||
return <WindmillConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
return <WindmillConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
case AppConnection.Auth0:
|
case AppConnection.Auth0:
|
||||||
return <Auth0ConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
return <Auth0ConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
|
case AppConnection.HCVault:
|
||||||
|
return <HCVaultConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`);
|
throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`);
|
||||||
}
|
}
|
||||||
|
|||||||
+202
@@ -0,0 +1,202 @@
|
|||||||
|
import { Controller, FormProvider, useForm } from "react-hook-form";
|
||||||
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import {
|
||||||
|
Button,
|
||||||
|
FormControl,
|
||||||
|
Input,
|
||||||
|
ModalClose,
|
||||||
|
SecretInput,
|
||||||
|
Select,
|
||||||
|
SelectItem
|
||||||
|
} from "@app/components/v2";
|
||||||
|
import { APP_CONNECTION_MAP, getAppConnectionMethodDetails } from "@app/helpers/appConnections";
|
||||||
|
import { HCVaultConnectionMethod, THCVaultConnection } from "@app/hooks/api/appConnections";
|
||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
|
||||||
|
import {
|
||||||
|
genericAppConnectionFieldsSchema,
|
||||||
|
GenericAppConnectionsFields
|
||||||
|
} from "./GenericAppConnectionFields";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
appConnection?: THCVaultConnection;
|
||||||
|
onSubmit: (formData: FormData) => Promise<void>;
|
||||||
|
};
|
||||||
|
|
||||||
|
const rootSchema = genericAppConnectionFieldsSchema.extend({
|
||||||
|
app: z.literal(AppConnection.HCVault)
|
||||||
|
});
|
||||||
|
|
||||||
|
const InstanceUrlSchema = z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Instance URL required")
|
||||||
|
.url("Invalid Instance URL");
|
||||||
|
const formSchema = z.discriminatedUnion("method", [
|
||||||
|
rootSchema.extend({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AccessToken),
|
||||||
|
credentials: z.object({
|
||||||
|
instanceUrl: InstanceUrlSchema,
|
||||||
|
accessToken: z.string().trim().min(1, "Access Token required")
|
||||||
|
})
|
||||||
|
}),
|
||||||
|
rootSchema.extend({
|
||||||
|
method: z.literal(HCVaultConnectionMethod.AppRole),
|
||||||
|
credentials: z.object({
|
||||||
|
instanceUrl: InstanceUrlSchema,
|
||||||
|
roleId: z.string().trim().min(1, "Role ID required"),
|
||||||
|
secretId: z.string().trim().min(1, "Secret ID required")
|
||||||
|
})
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
type FormData = z.infer<typeof formSchema>;
|
||||||
|
|
||||||
|
export const HCVaultConnectionForm = ({ appConnection, onSubmit }: Props) => {
|
||||||
|
const isUpdate = Boolean(appConnection);
|
||||||
|
|
||||||
|
const form = useForm<FormData>({
|
||||||
|
resolver: zodResolver(formSchema),
|
||||||
|
defaultValues: appConnection ?? {
|
||||||
|
app: AppConnection.HCVault,
|
||||||
|
method: HCVaultConnectionMethod.AppRole
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
const {
|
||||||
|
handleSubmit,
|
||||||
|
control,
|
||||||
|
watch,
|
||||||
|
formState: { isSubmitting, isDirty }
|
||||||
|
} = form;
|
||||||
|
|
||||||
|
const selectedMethod = watch("method");
|
||||||
|
|
||||||
|
return (
|
||||||
|
<FormProvider {...form}>
|
||||||
|
<form onSubmit={handleSubmit(onSubmit)}>
|
||||||
|
{!isUpdate && <GenericAppConnectionsFields />}
|
||||||
|
<Controller
|
||||||
|
name="method"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
tooltipText={`The method you would like to use to connect with ${
|
||||||
|
APP_CONNECTION_MAP[AppConnection.HCVault].name
|
||||||
|
}. This field cannot be changed after creation.`}
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Method"
|
||||||
|
>
|
||||||
|
<Select
|
||||||
|
isDisabled={isUpdate}
|
||||||
|
value={value}
|
||||||
|
onValueChange={(val) => onChange(val)}
|
||||||
|
className="w-full border border-mineshaft-500"
|
||||||
|
position="popper"
|
||||||
|
dropdownContainerClassName="max-w-none"
|
||||||
|
>
|
||||||
|
{Object.values(HCVaultConnectionMethod).map((method) => {
|
||||||
|
return (
|
||||||
|
<SelectItem value={method} key={method}>
|
||||||
|
{getAppConnectionMethodDetails(method).name}{" "}
|
||||||
|
{method === HCVaultConnectionMethod.AppRole ? " (Recommended)" : ""}
|
||||||
|
</SelectItem>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</Select>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
name="credentials.instanceUrl"
|
||||||
|
control={control}
|
||||||
|
shouldUnregister
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Instance URL"
|
||||||
|
tooltipClassName="max-w-sm"
|
||||||
|
tooltipText="The URL at which your Hashicorp Vault instance is hosted."
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="https://vault.mycompany.com" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
{selectedMethod === HCVaultConnectionMethod.AccessToken ? (
|
||||||
|
<Controller
|
||||||
|
name="credentials.accessToken"
|
||||||
|
control={control}
|
||||||
|
shouldUnregister
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Access Token"
|
||||||
|
>
|
||||||
|
<SecretInput
|
||||||
|
{...field}
|
||||||
|
containerClassName="text-gray-400 group-focus-within:!border-primary-400/50 border border-mineshaft-500 bg-mineshaft-900 px-2.5 py-1.5"
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
) : (
|
||||||
|
<>
|
||||||
|
<Controller
|
||||||
|
name="credentials.roleId"
|
||||||
|
control={control}
|
||||||
|
shouldUnregister
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Role ID"
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="00000000-0000-0000-0000-000000000000" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
name="credentials.secretId"
|
||||||
|
control={control}
|
||||||
|
shouldUnregister
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Secret ID"
|
||||||
|
>
|
||||||
|
<SecretInput
|
||||||
|
{...field}
|
||||||
|
containerClassName="text-gray-400 group-focus-within:!border-primary-400/50 border border-mineshaft-500 bg-mineshaft-900 px-2.5 py-1.5"
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
</>
|
||||||
|
)}
|
||||||
|
<div className="mt-8 flex items-center">
|
||||||
|
<Button
|
||||||
|
className="mr-4"
|
||||||
|
size="sm"
|
||||||
|
type="submit"
|
||||||
|
colorSchema="secondary"
|
||||||
|
isLoading={isSubmitting}
|
||||||
|
isDisabled={isSubmitting || !isDirty}
|
||||||
|
>
|
||||||
|
{isUpdate ? "Update Credentials" : "Connect to Hashicorp Vault"}
|
||||||
|
</Button>
|
||||||
|
<ModalClose asChild>
|
||||||
|
<Button colorSchema="secondary" variant="plain">
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
</ModalClose>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
</FormProvider>
|
||||||
|
);
|
||||||
|
};
|
||||||
Reference in New Issue
Block a user