mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 11:25:58 +00:00
Return eab kid as well
This commit is contained in:
@@ -506,20 +506,21 @@ export const registerCertificateProfilesRouter = async (server: FastifyZodProvid
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
eabKid: z.string(),
|
||||
eabSecret: z.string()
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||
handler: async (req) => {
|
||||
const eabSecret = await server.services.certificateProfile.revealAcmeEabSecret({
|
||||
const { eabKid, eabSecret } = await server.services.certificateProfile.revealAcmeEabSecret({
|
||||
actor: req.permission.type,
|
||||
actorId: req.permission.id,
|
||||
actorAuthMethod: req.permission.authMethod,
|
||||
actorOrgId: req.permission.orgId,
|
||||
profileId: req.params.id
|
||||
});
|
||||
return { eabSecret };
|
||||
return { eabKid, eabSecret };
|
||||
}
|
||||
});
|
||||
};
|
||||
|
||||
@@ -130,7 +130,8 @@ export const certificateProfileDALFactory = (db: TDbClient) => {
|
||||
db.ref("id").withSchema(TableName.PkiApiEnrollmentConfig).as("apiConfigId"),
|
||||
db.ref("autoRenew").withSchema(TableName.PkiApiEnrollmentConfig).as("apiConfigAutoRenew"),
|
||||
db.ref("renewBeforeDays").withSchema(TableName.PkiApiEnrollmentConfig).as("apiConfigRenewBeforeDays"),
|
||||
db.ref("id").withSchema(TableName.PkiAcmeEnrollmentConfig).as("acmeConfigId")
|
||||
db.ref("id").withSchema(TableName.PkiAcmeEnrollmentConfig).as("acmeConfigId"),
|
||||
db.ref("encryptedEabSecret").withSchema(TableName.PkiAcmeEnrollmentConfig).as("acmeConfigEncryptedEabSecret")
|
||||
)
|
||||
.where(`${TableName.PkiCertificateProfile}.id`, id)
|
||||
.first();
|
||||
@@ -158,7 +159,10 @@ export const certificateProfileDALFactory = (db: TDbClient) => {
|
||||
: undefined;
|
||||
|
||||
const acmeConfig = result.acmeConfigId
|
||||
? ({ id: result.acmeConfigId } as TCertificateProfileWithConfigs["acmeConfig"])
|
||||
? ({
|
||||
id: result.acmeConfigId,
|
||||
encryptedEabSecret: result.acmeConfigEncryptedEabSecret
|
||||
} as TCertificateProfileWithConfigs["acmeConfig"])
|
||||
: undefined;
|
||||
|
||||
const certificateAuthority =
|
||||
|
||||
@@ -832,7 +832,7 @@ export const certificateProfileServiceFactory = ({
|
||||
kmsId: certificateManagerKmsId
|
||||
});
|
||||
const eabSecret = await kmsDecryptor({ cipherTextBlob: profile.acmeConfig.encryptedEabSecret });
|
||||
return eabSecret.toString();
|
||||
return { eabKid: profile.id, eabSecret: eabSecret.toString() };
|
||||
};
|
||||
|
||||
return {
|
||||
|
||||
Reference in New Issue
Block a user