mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 17:27:40 +00:00
feat: changes on review comments
This commit is contained in:
@@ -5,6 +5,7 @@ import nacl from "tweetnacl";
|
|||||||
import tweetnacl from "tweetnacl-util";
|
import tweetnacl from "tweetnacl-util";
|
||||||
|
|
||||||
import { TUserEncryptionKeys } from "@app/db/schemas";
|
import { TUserEncryptionKeys } from "@app/db/schemas";
|
||||||
|
import { UserEncryption } from "@app/services/user/user-types";
|
||||||
|
|
||||||
import { decryptSymmetric128BitHexKeyUTF8, encryptAsymmetric, encryptSymmetric } from "./encryption";
|
import { decryptSymmetric128BitHexKeyUTF8, encryptAsymmetric, encryptSymmetric } from "./encryption";
|
||||||
|
|
||||||
@@ -115,7 +116,7 @@ export const getUserPrivateKey = async (
|
|||||||
| "encryptionVersion"
|
| "encryptionVersion"
|
||||||
>
|
>
|
||||||
) => {
|
) => {
|
||||||
if (user.encryptionVersion === 1) {
|
if (user.encryptionVersion === UserEncryption.V1) {
|
||||||
return decryptSymmetric128BitHexKeyUTF8({
|
return decryptSymmetric128BitHexKeyUTF8({
|
||||||
ciphertext: user.encryptedPrivateKey,
|
ciphertext: user.encryptedPrivateKey,
|
||||||
iv: user.iv,
|
iv: user.iv,
|
||||||
@@ -123,7 +124,12 @@ export const getUserPrivateKey = async (
|
|||||||
key: password.slice(0, 32).padStart(32 + (password.slice(0, 32).length - new Blob([password]).size), "0")
|
key: password.slice(0, 32).padStart(32 + (password.slice(0, 32).length - new Blob([password]).size), "0")
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
if (user.encryptionVersion === 2 && user.protectedKey && user.protectedKeyIV && user.protectedKeyTag) {
|
if (
|
||||||
|
user.encryptionVersion === UserEncryption.V2 &&
|
||||||
|
user.protectedKey &&
|
||||||
|
user.protectedKeyIV &&
|
||||||
|
user.protectedKeyTag
|
||||||
|
) {
|
||||||
const derivedKey = await argon2.hash(password, {
|
const derivedKey = await argon2.hash(password, {
|
||||||
salt: Buffer.from(user.salt),
|
salt: Buffer.from(user.salt),
|
||||||
memoryCost: 65536,
|
memoryCost: 65536,
|
||||||
|
|||||||
@@ -1,16 +1,16 @@
|
|||||||
import fs from "fs/promises";
|
import fs from "fs/promises";
|
||||||
import path from "path";
|
import path from "path";
|
||||||
|
|
||||||
export const isDisposableEmail = async (email: string | string[]) => {
|
export const isDisposableEmail = async (emails: string | string[]) => {
|
||||||
const disposableEmails = await fs.readFile(path.join(__dirname, "disposable_emails.txt"), "utf8");
|
const disposableEmails = await fs.readFile(path.join(__dirname, "disposable_emails.txt"), "utf8");
|
||||||
if (Array.isArray(email)) {
|
if (Array.isArray(emails)) {
|
||||||
return email.some((el) => {
|
return emails.some((email) => {
|
||||||
const emailDomain = el.split("@")[1];
|
const emailDomain = email.split("@")[1];
|
||||||
return disposableEmails.split("\n").includes(emailDomain);
|
return disposableEmails.split("\n").includes(emailDomain);
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const emailDomain = email.split("@")[1];
|
const emailDomain = emails.split("@")[1];
|
||||||
if (disposableEmails.split("\n").includes(emailDomain)) return true;
|
if (disposableEmails.split("\n").includes(emailDomain)) return true;
|
||||||
return false;
|
return false;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -24,6 +24,7 @@ import { TProjectMembershipDALFactory } from "../project-membership/project-memb
|
|||||||
import { TProjectUserMembershipRoleDALFactory } from "../project-membership/project-user-membership-role-dal";
|
import { TProjectUserMembershipRoleDALFactory } from "../project-membership/project-user-membership-role-dal";
|
||||||
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
|
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
|
||||||
import { TUserDALFactory } from "../user/user-dal";
|
import { TUserDALFactory } from "../user/user-dal";
|
||||||
|
import { UserEncryption } from "../user/user-types";
|
||||||
import { TAuthDALFactory } from "./auth-dal";
|
import { TAuthDALFactory } from "./auth-dal";
|
||||||
import { validateProviderAuthToken, validateSignUpAuthorization } from "./auth-fns";
|
import { validateProviderAuthToken, validateSignUpAuthorization } from "./auth-fns";
|
||||||
import { TCompleteAccountInviteDTO, TCompleteAccountSignupDTO } from "./auth-signup-type";
|
import { TCompleteAccountInviteDTO, TCompleteAccountSignupDTO } from "./auth-signup-type";
|
||||||
@@ -174,7 +175,7 @@ export const authSignupServiceFactory = ({
|
|||||||
encryptedPrivateKey,
|
encryptedPrivateKey,
|
||||||
iv: encryptedPrivateKeyIV,
|
iv: encryptedPrivateKeyIV,
|
||||||
tag: encryptedPrivateKeyTag,
|
tag: encryptedPrivateKeyTag,
|
||||||
encryptionVersion: 2
|
encryptionVersion: UserEncryption.V2
|
||||||
});
|
});
|
||||||
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
|
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
|
||||||
const updateduser = await authDAL.transaction(async (tx) => {
|
const updateduser = await authDAL.transaction(async (tx) => {
|
||||||
@@ -214,7 +215,7 @@ export const authSignupServiceFactory = ({
|
|||||||
userEncKey = await userDAL.upsertUserEncryptionKey(
|
userEncKey = await userDAL.upsertUserEncryptionKey(
|
||||||
us.id,
|
us.id,
|
||||||
{
|
{
|
||||||
encryptionVersion: 2,
|
encryptionVersion: UserEncryption.V2,
|
||||||
protectedKey: encKeys.protectedKey,
|
protectedKey: encKeys.protectedKey,
|
||||||
protectedKeyIV: encKeys.protectedKeyIV,
|
protectedKeyIV: encKeys.protectedKeyIV,
|
||||||
protectedKeyTag: encKeys.protectedKeyTag,
|
protectedKeyTag: encKeys.protectedKeyTag,
|
||||||
@@ -236,7 +237,7 @@ export const authSignupServiceFactory = ({
|
|||||||
userEncKey = await userDAL.upsertUserEncryptionKey(
|
userEncKey = await userDAL.upsertUserEncryptionKey(
|
||||||
us.id,
|
us.id,
|
||||||
{
|
{
|
||||||
encryptionVersion: 2,
|
encryptionVersion: UserEncryption.V2,
|
||||||
salt,
|
salt,
|
||||||
verifier,
|
verifier,
|
||||||
publicKey,
|
publicKey,
|
||||||
@@ -452,7 +453,7 @@ export const authSignupServiceFactory = ({
|
|||||||
userEncKey = await userDAL.upsertUserEncryptionKey(
|
userEncKey = await userDAL.upsertUserEncryptionKey(
|
||||||
us.id,
|
us.id,
|
||||||
{
|
{
|
||||||
encryptionVersion: 2,
|
encryptionVersion: UserEncryption.V2,
|
||||||
salt,
|
salt,
|
||||||
verifier,
|
verifier,
|
||||||
publicKey,
|
publicKey,
|
||||||
|
|||||||
@@ -4,18 +4,14 @@ import { alphaNumericNanoId } from "@app/lib/nanoid";
|
|||||||
import { TUserDALFactory } from "@app/services/user/user-dal";
|
import { TUserDALFactory } from "@app/services/user/user-dal";
|
||||||
|
|
||||||
export const normalizeUsername = async (username: string, userDAL: Pick<TUserDALFactory, "findOne">) => {
|
export const normalizeUsername = async (username: string, userDAL: Pick<TUserDALFactory, "findOne">) => {
|
||||||
let attempt = slugify(`${username}-${alphaNumericNanoId(4)}`);
|
let attempt: string;
|
||||||
|
let user;
|
||||||
|
|
||||||
let user = await userDAL.findOne({ username: attempt });
|
do {
|
||||||
if (!user) return attempt;
|
|
||||||
|
|
||||||
while (true) {
|
|
||||||
attempt = slugify(`${username}-${alphaNumericNanoId(4)}`);
|
attempt = slugify(`${username}-${alphaNumericNanoId(4)}`);
|
||||||
// eslint-disable-next-line no-await-in-loop
|
// eslint-disable-next-line no-await-in-loop
|
||||||
user = await userDAL.findOne({ username: attempt });
|
user = await userDAL.findOne({ username: attempt });
|
||||||
|
} while (user);
|
||||||
|
|
||||||
if (!user) {
|
return attempt;
|
||||||
return attempt;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export enum UserEncryption {
|
||||||
|
V1 = 1,
|
||||||
|
V2 = 2
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user