mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 23:27:14 +00:00
More audit
This commit is contained in:
@@ -49,7 +49,7 @@ import { TWebhookPayloads } from "@app/services/webhook/webhook-types";
|
|||||||
import { WorkflowIntegration } from "@app/services/workflow-integration/workflow-integration-types";
|
import { WorkflowIntegration } from "@app/services/workflow-integration/workflow-integration-types";
|
||||||
|
|
||||||
import { KmipPermission } from "../kmip/kmip-enum";
|
import { KmipPermission } from "../kmip/kmip-enum";
|
||||||
import { AcmeIdentifierType } from "../pki-acme/pki-acme-schemas";
|
import { AcmeChallengeType, AcmeIdentifierType } from "../pki-acme/pki-acme-schemas";
|
||||||
import { ApprovalStatus } from "../secret-approval-request/secret-approval-request-types";
|
import { ApprovalStatus } from "../secret-approval-request/secret-approval-request-types";
|
||||||
|
|
||||||
export type TListProjectAuditLogDTO = {
|
export type TListProjectAuditLogDTO = {
|
||||||
@@ -583,7 +583,9 @@ export enum EventType {
|
|||||||
CREATE_ACME_ACCOUNT = "create-acme-account",
|
CREATE_ACME_ACCOUNT = "create-acme-account",
|
||||||
RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account",
|
RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account",
|
||||||
CREATE_ACME_ORDER = "create-acme-order",
|
CREATE_ACME_ORDER = "create-acme-order",
|
||||||
FINALIZE_ACME_ORDER = "finalize-acme-order"
|
FINALIZE_ACME_ORDER = "finalize-acme-order",
|
||||||
|
DOWNLOAD_ACME_CERTIFICATE = "download-acme-certificate",
|
||||||
|
RESPOND_TO_ACME_CHALLENGE = "respond-to-acme-challenge"
|
||||||
}
|
}
|
||||||
|
|
||||||
export const filterableSecretEvents: EventType[] = [
|
export const filterableSecretEvents: EventType[] = [
|
||||||
@@ -4439,6 +4441,20 @@ interface FinalizeAcmeOrderEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface DownloadAcmeCertificateEvent {
|
||||||
|
type: EventType.DOWNLOAD_ACME_CERTIFICATE;
|
||||||
|
metadata: {
|
||||||
|
orderId: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface RespondToAcmeChallengeEvent {
|
||||||
|
type: EventType.RESPOND_TO_ACME_CHALLENGE;
|
||||||
|
metadata: {
|
||||||
|
challengeId: string;
|
||||||
|
type: AcmeChallengeType;
|
||||||
|
};
|
||||||
|
}
|
||||||
export type Event =
|
export type Event =
|
||||||
| CreateSubOrganizationEvent
|
| CreateSubOrganizationEvent
|
||||||
| UpdateSubOrganizationEvent
|
| UpdateSubOrganizationEvent
|
||||||
@@ -4843,4 +4859,6 @@ export type Event =
|
|||||||
| CreateAcmeAccountEvent
|
| CreateAcmeAccountEvent
|
||||||
| RetrieveAcmeAccountEvent
|
| RetrieveAcmeAccountEvent
|
||||||
| CreateAcmeOrderEvent
|
| CreateAcmeOrderEvent
|
||||||
| FinalizeAcmeOrderEvent;
|
| FinalizeAcmeOrderEvent
|
||||||
|
| DownloadAcmeCertificateEvent
|
||||||
|
| RespondToAcmeChallengeEvent;
|
||||||
|
|||||||
@@ -1005,6 +1005,24 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
|
|
||||||
const certLeaf = certObj.toString("pem").trim().replace("\n", "\r\n");
|
const certLeaf = certObj.toString("pem").trim().replace("\n", "\r\n");
|
||||||
const certChain = certificateChain.trim().replace("\n", "\r\n");
|
const certChain = certificateChain.trim().replace("\n", "\r\n");
|
||||||
|
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
projectId: profile.projectId,
|
||||||
|
actor: {
|
||||||
|
type: ActorType.ACME_ACCOUNT,
|
||||||
|
metadata: {
|
||||||
|
profileId,
|
||||||
|
accountId
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.DOWNLOAD_ACME_CERTIFICATE,
|
||||||
|
metadata: {
|
||||||
|
orderId
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
status: 200,
|
status: 200,
|
||||||
body:
|
body:
|
||||||
@@ -1087,6 +1105,7 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
authzId: string;
|
authzId: string;
|
||||||
challengeId: string;
|
challengeId: string;
|
||||||
}): Promise<TAcmeResponse<TRespondToAcmeChallengeResponse>> => {
|
}): Promise<TAcmeResponse<TRespondToAcmeChallengeResponse>> => {
|
||||||
|
const profile = await validateAcmeProfile(profileId);
|
||||||
const result = await acmeChallengeDAL.findByAccountAuthAndChallengeId(accountId, authzId, challengeId);
|
const result = await acmeChallengeDAL.findByAccountAuthAndChallengeId(accountId, authzId, challengeId);
|
||||||
if (!result) {
|
if (!result) {
|
||||||
throw new NotFoundError({ message: "ACME challenge not found" });
|
throw new NotFoundError({ message: "ACME challenge not found" });
|
||||||
@@ -1094,6 +1113,23 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
await acmeChallengeService.markChallengeAsReady(challengeId);
|
await acmeChallengeService.markChallengeAsReady(challengeId);
|
||||||
await pkiAcmeQueueService.queueChallengeValidation(challengeId);
|
await pkiAcmeQueueService.queueChallengeValidation(challengeId);
|
||||||
const challenge = (await acmeChallengeDAL.findByIdForChallengeValidation(challengeId))!;
|
const challenge = (await acmeChallengeDAL.findByIdForChallengeValidation(challengeId))!;
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
projectId: profile.projectId,
|
||||||
|
actor: {
|
||||||
|
type: ActorType.ACME_ACCOUNT,
|
||||||
|
metadata: {
|
||||||
|
profileId,
|
||||||
|
accountId
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.RESPOND_TO_ACME_CHALLENGE,
|
||||||
|
metadata: {
|
||||||
|
challengeId,
|
||||||
|
type: challenge.type
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
return {
|
return {
|
||||||
status: 200,
|
status: 200,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
Reference in New Issue
Block a user