mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 19:28:33 +00:00
misc: made project key and data key creation concurrency safe
This commit is contained in:
@@ -134,9 +134,12 @@ export const kmsServiceFactory = ({
|
||||
|
||||
org = await orgDAL.findById(orgId);
|
||||
} else {
|
||||
org = await orgDAL.findById(orgId);
|
||||
if (!org.kmsDefaultKeyId) {
|
||||
const keyId = await orgDAL.transaction(async (tx) => {
|
||||
org = await orgDAL.findById(orgId, tx);
|
||||
if (org.kmsDefaultKeyId) {
|
||||
return org.kmsDefaultKeyId;
|
||||
}
|
||||
|
||||
const key = await generateKmsKey({
|
||||
isReserved: true,
|
||||
orgId: org.id,
|
||||
@@ -151,18 +154,13 @@ export const kmsServiceFactory = ({
|
||||
tx
|
||||
);
|
||||
|
||||
await keyStore.setItemWithExpiry(
|
||||
`${KeyStorePrefixes.WaitUntilReadyKmsOrgKeyCreation}${orgId}`,
|
||||
10,
|
||||
"true"
|
||||
);
|
||||
await keyStore.setItemWithExpiry(`${KeyStorePrefixes.WaitUntilReadyKmsOrgKeyCreation}${orgId}`, 10, "true");
|
||||
|
||||
return key.id;
|
||||
});
|
||||
|
||||
return keyId;
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
await lock?.release();
|
||||
}
|
||||
@@ -192,7 +190,6 @@ export const kmsServiceFactory = ({
|
||||
kmsId: kmsDoc.orgKms.id
|
||||
});
|
||||
|
||||
// fetch encryptedDataKey straight from kmsDoc by joining it in query :D
|
||||
const orgKmsDataKey = await orgKmsDecryptor({
|
||||
cipherTextBlob: kmsDoc.orgKms.encryptedDataKey
|
||||
});
|
||||
@@ -326,9 +323,12 @@ export const kmsServiceFactory = ({
|
||||
|
||||
org = await orgDAL.findById(orgId);
|
||||
} else {
|
||||
org = await orgDAL.findById(orgId);
|
||||
if (!org.kmsEncryptedDataKey) {
|
||||
const orgDataKey = await orgDAL.transaction(async (tx) => {
|
||||
org = await orgDAL.findById(orgId, tx);
|
||||
if (org.kmsEncryptedDataKey) {
|
||||
return;
|
||||
}
|
||||
|
||||
const dataKey = randomSecureBytes();
|
||||
const kmsEncryptor = await encryptWithKmsKey(
|
||||
{
|
||||
@@ -358,6 +358,7 @@ export const kmsServiceFactory = ({
|
||||
return dataKey;
|
||||
});
|
||||
|
||||
if (orgDataKey) {
|
||||
return orgDataKey;
|
||||
}
|
||||
}
|
||||
@@ -401,6 +402,11 @@ export const kmsServiceFactory = ({
|
||||
project = await projectDAL.findById(projectId);
|
||||
} else {
|
||||
const kmsKeyId = await projectDAL.transaction(async (tx) => {
|
||||
project = await projectDAL.findById(projectId, tx);
|
||||
if (project.kmsSecretManagerKeyId) {
|
||||
return project.kmsSecretManagerKeyId;
|
||||
}
|
||||
|
||||
const key = await generateKmsKey({
|
||||
isReserved: true,
|
||||
orgId: project.orgId,
|
||||
@@ -464,6 +470,12 @@ export const kmsServiceFactory = ({
|
||||
|
||||
project = await projectDAL.findById(projectId);
|
||||
} else {
|
||||
const projectDataKey = await projectDAL.transaction(async (tx) => {
|
||||
project = await projectDAL.findById(projectId, tx);
|
||||
if (project.kmsSecretManagerEncryptedDataKey) {
|
||||
return;
|
||||
}
|
||||
|
||||
const dataKey = randomSecureBytes();
|
||||
const kmsEncryptor = await encryptWithKmsKey({
|
||||
kmsId: kmsKeyId
|
||||
@@ -473,9 +485,13 @@ export const kmsServiceFactory = ({
|
||||
plainText: dataKey
|
||||
});
|
||||
|
||||
await projectDAL.updateById(projectId, {
|
||||
await projectDAL.updateById(
|
||||
projectId,
|
||||
{
|
||||
kmsSecretManagerEncryptedDataKey: cipherTextBlob
|
||||
});
|
||||
},
|
||||
tx
|
||||
);
|
||||
|
||||
await keyStore.setItemWithExpiry(
|
||||
`${KeyStorePrefixes.WaitUntilReadyKmsProjectDataKeyCreation}${projectId}`,
|
||||
@@ -483,6 +499,11 @@ export const kmsServiceFactory = ({
|
||||
"true"
|
||||
);
|
||||
return dataKey;
|
||||
});
|
||||
|
||||
if (projectDataKey) {
|
||||
return projectDataKey;
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
await lock?.release();
|
||||
|
||||
Reference in New Issue
Block a user