mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
Extract fns
This commit is contained in:
@@ -0,0 +1,17 @@
|
|||||||
|
import { getConfig } from "@app/lib/config/env";
|
||||||
|
import { z } from "zod";
|
||||||
|
import { AcmeMalformedError } from "./pki-acme-errors";
|
||||||
|
|
||||||
|
export const buildUrl = (profileId: string, path: string): string => {
|
||||||
|
const appCfg = getConfig();
|
||||||
|
const baseUrl = appCfg.SITE_URL ?? "";
|
||||||
|
return `${baseUrl}/api/v1/pki/acme/profiles/${profileId}${path}`;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const extractAccountIdFromKid = (kid: string, profileId: string): string => {
|
||||||
|
const kidPrefix = buildUrl(profileId, "/accounts/");
|
||||||
|
if (!kid.startsWith(kidPrefix)) {
|
||||||
|
throw new AcmeMalformedError({ detail: "KID must start with the profile account URL" });
|
||||||
|
}
|
||||||
|
return z.string().uuid().parse(kid.slice(kidPrefix.length));
|
||||||
|
};
|
||||||
@@ -1,6 +1,5 @@
|
|||||||
import { TPkiAcmeAccounts } from "@app/db/schemas/pki-acme-accounts";
|
import { TPkiAcmeAccounts } from "@app/db/schemas/pki-acme-accounts";
|
||||||
import { TPkiAcmeAuths } from "@app/db/schemas/pki-acme-auths";
|
import { TPkiAcmeAuths } from "@app/db/schemas/pki-acme-auths";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
import { BadRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
@@ -39,6 +38,7 @@ import {
|
|||||||
AcmeUnauthorizedError,
|
AcmeUnauthorizedError,
|
||||||
AcmeUnsupportedIdentifierError
|
AcmeUnsupportedIdentifierError
|
||||||
} from "./pki-acme-errors";
|
} from "./pki-acme-errors";
|
||||||
|
import { buildUrl, extractAccountIdFromKid } from "./pki-acme-fns";
|
||||||
import { TPkiAcmeOrderAuthDALFactory } from "./pki-acme-order-auth-dal";
|
import { TPkiAcmeOrderAuthDALFactory } from "./pki-acme-order-auth-dal";
|
||||||
import { TPkiAcmeOrderDALFactory } from "./pki-acme-order-dal";
|
import { TPkiAcmeOrderDALFactory } from "./pki-acme-order-dal";
|
||||||
import {
|
import {
|
||||||
@@ -115,20 +115,6 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
return profile;
|
return profile;
|
||||||
};
|
};
|
||||||
|
|
||||||
const buildUrl = (profileId: string, path: string): string => {
|
|
||||||
const appCfg = getConfig();
|
|
||||||
const baseUrl = appCfg.SITE_URL ?? "";
|
|
||||||
return `${baseUrl}/api/v1/pki/acme/profiles/${profileId}${path}`;
|
|
||||||
};
|
|
||||||
|
|
||||||
const extractAccountIdFromKid = (kid: string, profileId: string): string => {
|
|
||||||
const kidPrefix = buildUrl(profileId, "/accounts/");
|
|
||||||
if (!kid.startsWith(kidPrefix)) {
|
|
||||||
throw new AcmeMalformedError({ detail: "KID must start with the profile account URL" });
|
|
||||||
}
|
|
||||||
return z.string().uuid().parse(kid.slice(kidPrefix.length));
|
|
||||||
};
|
|
||||||
|
|
||||||
const validateJwsPayload = async <
|
const validateJwsPayload = async <
|
||||||
TSchema extends z.ZodSchema<any> | undefined = undefined,
|
TSchema extends z.ZodSchema<any> | undefined = undefined,
|
||||||
T = TSchema extends z.ZodSchema<infer R> ? R : string
|
T = TSchema extends z.ZodSchema<infer R> ? R : string
|
||||||
|
|||||||
Reference in New Issue
Block a user