mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 15:28:25 +00:00
Revise pr based on greptile review
This commit is contained in:
@@ -14,7 +14,7 @@ export const sanitizedSshHost = SshHostsSchema.pick({
|
|||||||
});
|
});
|
||||||
|
|
||||||
export const loginMappingSchema = z.object({
|
export const loginMappingSchema = z.object({
|
||||||
loginUser: z.string().trim(),
|
loginUser: z.string().trim().min(1).max(32),
|
||||||
allowedPrincipals: z.object({
|
allowedPrincipals: z.object({
|
||||||
usernames: z
|
usernames: z
|
||||||
.array(z.string().trim())
|
.array(z.string().trim())
|
||||||
|
|||||||
@@ -1735,6 +1735,15 @@ export const PKI_SUBSCRIBERS = {
|
|||||||
privateKey: "The private key of the issued certificate.",
|
privateKey: "The private key of the issued certificate.",
|
||||||
serialNumber: "The serial number of the issued certificate."
|
serialNumber: "The serial number of the issued certificate."
|
||||||
},
|
},
|
||||||
|
SIGN_CERT: {
|
||||||
|
subscriberName: "The name of the PKI subscriber to sign the certificate for.",
|
||||||
|
projectId: "The ID of the project of the PKI subscriber to sign the certificate for.",
|
||||||
|
csr: "The CSR to be used to sign the certificate.",
|
||||||
|
certificate: "The signed certificate.",
|
||||||
|
issuingCaCertificate: "The certificate of the issuing CA.",
|
||||||
|
certificateChain: "The certificate chain of the signed certificate.",
|
||||||
|
serialNumber: "The serial number of the signed certificate."
|
||||||
|
},
|
||||||
LIST_CERTS: {
|
LIST_CERTS: {
|
||||||
subscriberName: "The name of the PKI subscriber to list the certificates for.",
|
subscriberName: "The name of the PKI subscriber to list the certificates for.",
|
||||||
projectId: "The ID of the project of the PKI subscriber to list the certificates for.",
|
projectId: "The ID of the project of the PKI subscriber to list the certificates for.",
|
||||||
|
|||||||
@@ -361,17 +361,17 @@ export const registerPkiSubscriberRouter = async (server: FastifyZodProvider) =>
|
|||||||
tags: [ApiDocsTags.PkiSubscribers],
|
tags: [ApiDocsTags.PkiSubscribers],
|
||||||
description: "Sign certificate",
|
description: "Sign certificate",
|
||||||
params: z.object({
|
params: z.object({
|
||||||
subscriberName: z.string().describe(PKI_SUBSCRIBERS.ISSUE_CERT.subscriberName)
|
subscriberName: z.string().describe(PKI_SUBSCRIBERS.SIGN_CERT.subscriberName)
|
||||||
}),
|
}),
|
||||||
body: z.object({
|
body: z.object({
|
||||||
projectId: z.string().trim().describe(PKI_SUBSCRIBERS.ISSUE_CERT.projectId),
|
projectId: z.string().trim().describe(PKI_SUBSCRIBERS.SIGN_CERT.projectId),
|
||||||
csr: z.string().trim().min(1)
|
csr: z.string().trim().min(1).max(3000).describe(PKI_SUBSCRIBERS.SIGN_CERT.csr)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
certificate: z.string().trim().describe(PKI_SUBSCRIBERS.ISSUE_CERT.certificate),
|
certificate: z.string().trim().describe(PKI_SUBSCRIBERS.SIGN_CERT.certificate),
|
||||||
issuingCaCertificate: z.string().trim().describe(PKI_SUBSCRIBERS.ISSUE_CERT.issuingCaCertificate),
|
issuingCaCertificate: z.string().trim().describe(PKI_SUBSCRIBERS.SIGN_CERT.issuingCaCertificate),
|
||||||
certificateChain: z.string().trim().describe(PKI_SUBSCRIBERS.ISSUE_CERT.certificateChain),
|
certificateChain: z.string().trim().describe(PKI_SUBSCRIBERS.SIGN_CERT.certificateChain),
|
||||||
serialNumber: z.string().trim().describe(PKI_SUBSCRIBERS.ISSUE_CERT.serialNumber)
|
serialNumber: z.string().trim().describe(PKI_SUBSCRIBERS.ISSUE_CERT.serialNumber)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -412,7 +412,7 @@ export const registerPkiSubscriberRouter = async (server: FastifyZodProvider) =>
|
|||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
certificate: certificate.toString("pem"),
|
certificate,
|
||||||
certificateChain,
|
certificateChain,
|
||||||
issuingCaCertificate,
|
issuingCaCertificate,
|
||||||
serialNumber
|
serialNumber
|
||||||
|
|||||||
@@ -498,6 +498,8 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
rateLimit: readLimit
|
rateLimit: readLimit
|
||||||
},
|
},
|
||||||
schema: {
|
schema: {
|
||||||
|
hide: false,
|
||||||
|
tags: [ApiDocsTags.PkiSubscribers],
|
||||||
params: z.object({
|
params: z.object({
|
||||||
projectId: z.string().trim().describe(PROJECTS.LIST_PKI_SUBSCRIBERS.projectId)
|
projectId: z.string().trim().describe(PROJECTS.LIST_PKI_SUBSCRIBERS.projectId)
|
||||||
}),
|
}),
|
||||||
|
|||||||
@@ -706,7 +706,7 @@ export const pkiSubscriberServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
certificate: leafCert,
|
certificate: leafCert.toString("pem"),
|
||||||
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
|
certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(),
|
||||||
issuingCaCertificate,
|
issuingCaCertificate,
|
||||||
serialNumber,
|
serialNumber,
|
||||||
|
|||||||
@@ -240,7 +240,7 @@ openssl verify -crl_check -CAfile chain.pem -CRLfile crl.pem cert.pem
|
|||||||
```
|
```
|
||||||
|
|
||||||
Note that you can also obtain the CRL from the certificate itself by
|
Note that you can also obtain the CRL from the certificate itself by
|
||||||
referencing the CRL distribution point extension on the certificate itself.
|
referencing the CRL distribution point extension on the certificate.
|
||||||
|
|
||||||
To check a certificate against the CRL distribution point specified within it with OpenSSL, you can use the following command:
|
To check a certificate against the CRL distribution point specified within it with OpenSSL, you can use the following command:
|
||||||
|
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ description: "Learn how to manage PKI subscribers and issue X.509 certificates f
|
|||||||
|
|
||||||
## Concept
|
## Concept
|
||||||
|
|
||||||
In Infisical PKI, subscribers are logical representatiosn of entities such as devices, servers, applications that request and receive certificates from Certificate Authorities (CAs).
|
In Infisical PKI, subscribers are logical representations of entities such as devices, servers, applications that request and receive certificates from Certificate Authorities (CAs).
|
||||||
|
|
||||||
<div align="center">
|
<div align="center">
|
||||||
|
|
||||||
@@ -109,7 +109,7 @@ openssl verify -crl_check -CAfile chain.pem -CRLfile crl.pem cert.pem
|
|||||||
```
|
```
|
||||||
|
|
||||||
Note that you can also obtain the CRL from the certificate itself by
|
Note that you can also obtain the CRL from the certificate itself by
|
||||||
referencing the CRL distribution point extension on the certificate itself.
|
referencing the CRL distribution point extension on the certificate.
|
||||||
|
|
||||||
To check a certificate against the CRL distribution point specified within it with OpenSSL, you can use the following command:
|
To check a certificate against the CRL distribution point specified within it with OpenSSL, you can use the following command:
|
||||||
|
|
||||||
@@ -125,7 +125,7 @@ openssl verify -verbose -crl_check -crl_download -CAfile chain.pem cert.pem
|
|||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="What is the workflow for renewing a certificate?">
|
<Accordion title="What is the workflow for renewing a certificate?">
|
||||||
To renew a certificate, you have to issue a new certificate for the same
|
To renew a certificate, you have to issue a new certificate for the same
|
||||||
subscriber The original certificate will continue to be valid through its
|
subscriber. The original certificate will continue to be valid through its
|
||||||
original TTL unless explicitly revoked.
|
original TTL unless explicitly revoked.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|||||||
+3
-4
@@ -102,8 +102,7 @@ const Page = () => {
|
|||||||
)}
|
)}
|
||||||
onClick={() =>
|
onClick={() =>
|
||||||
handlePopUpOpen("deletePkiSubscriber", {
|
handlePopUpOpen("deletePkiSubscriber", {
|
||||||
subscriberId: data.id,
|
subscriberName: data.name
|
||||||
name: data.name
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
disabled={!isAllowed}
|
disabled={!isAllowed}
|
||||||
@@ -131,14 +130,14 @@ const Page = () => {
|
|||||||
<PkiSubscriberModal popUp={popUp} handlePopUpToggle={handlePopUpToggle} />
|
<PkiSubscriberModal popUp={popUp} handlePopUpToggle={handlePopUpToggle} />
|
||||||
<DeleteActionModal
|
<DeleteActionModal
|
||||||
isOpen={popUp.deletePkiSubscriber.isOpen}
|
isOpen={popUp.deletePkiSubscriber.isOpen}
|
||||||
title={`Are you sure want to remove the PKI subscriber: ${
|
title={`Are you sure you want to remove the PKI subscriber: ${
|
||||||
(popUp?.deletePkiSubscriber?.data as { name: string })?.name || ""
|
(popUp?.deletePkiSubscriber?.data as { name: string })?.name || ""
|
||||||
}?`}
|
}?`}
|
||||||
onChange={(isOpen) => handlePopUpToggle("deletePkiSubscriber", isOpen)}
|
onChange={(isOpen) => handlePopUpToggle("deletePkiSubscriber", isOpen)}
|
||||||
deleteKey="confirm"
|
deleteKey="confirm"
|
||||||
onDeleteApproved={() =>
|
onDeleteApproved={() =>
|
||||||
onRemoveSubscriberSubmit(
|
onRemoveSubscriberSubmit(
|
||||||
(popUp?.deletePkiSubscriber?.data as { subscriberId: string })?.subscriberId
|
(popUp?.deletePkiSubscriber?.data as { subscriberName: string })?.subscriberName
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
/>
|
/>
|
||||||
|
|||||||
+1
-2
@@ -142,10 +142,9 @@ export const PkiSubscriberDetailsSection = ({ subscriberName, handlePopUpOpen }:
|
|||||||
</div>
|
</div>
|
||||||
{canIssuePkiSubscriberCert && (
|
{canIssuePkiSubscriberCert && (
|
||||||
<Button
|
<Button
|
||||||
isDisabled={!canIssuePkiSubscriberCert}
|
|
||||||
className="mt-4 w-full"
|
className="mt-4 w-full"
|
||||||
colorSchema="primary"
|
colorSchema="primary"
|
||||||
type="submit"
|
type="button"
|
||||||
isLoading={isIssuingCert}
|
isLoading={isIssuingCert}
|
||||||
onClick={() => {
|
onClick={() => {
|
||||||
onIssuePkiSubscriberCert();
|
onIssuePkiSubscriberCert();
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ export const PkiSubscribersPage = () => {
|
|||||||
<title>{t("common.head-title", { title: "PKI Subscribers" })}</title>
|
<title>{t("common.head-title", { title: "PKI Subscribers" })}</title>
|
||||||
</Helmet>
|
</Helmet>
|
||||||
<div className="h-full bg-bunker-800">
|
<div className="h-full bg-bunker-800">
|
||||||
<div className="container mx-auto flex flex-col justify-between bg-bunker-800 text-white">
|
<div className="container mx-auto flex flex-col justify-between text-white">
|
||||||
<div className="mx-auto mb-6 w-full max-w-7xl">
|
<div className="mx-auto mb-6 w-full max-w-7xl">
|
||||||
<PageHeader
|
<PageHeader
|
||||||
title="Subscribers"
|
title="Subscribers"
|
||||||
|
|||||||
@@ -165,16 +165,6 @@ export const PkiSubscriberModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
console.log("onFormSubmitArgs: ", {
|
|
||||||
name,
|
|
||||||
caId,
|
|
||||||
commonName,
|
|
||||||
subjectAlternativeNames,
|
|
||||||
ttl,
|
|
||||||
keyUsages,
|
|
||||||
extendedKeyUsages
|
|
||||||
});
|
|
||||||
|
|
||||||
// Check if there is already a different subscriber with the same name
|
// Check if there is already a different subscriber with the same name
|
||||||
const existingNames =
|
const existingNames =
|
||||||
subscribers?.filter((s) => s.id !== pkiSubscriber?.id).map((s) => s.name) || [];
|
subscribers?.filter((s) => s.id !== pkiSubscriber?.id).map((s) => s.name) || [];
|
||||||
|
|||||||
+2
-2
@@ -68,7 +68,7 @@ export const PkiSubscriberSection = () => {
|
|||||||
} catch (err) {
|
} catch (err) {
|
||||||
console.error(err);
|
console.error(err);
|
||||||
createNotification({
|
createNotification({
|
||||||
text: `Failed to ${status === PkiSubscriberStatus.ACTIVE ? "enabled" : "disabled"} subscriber`,
|
text: `Failed to ${status === PkiSubscriberStatus.ACTIVE ? "enable" : "disable"} subscriber`,
|
||||||
type: "error"
|
type: "error"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -123,7 +123,7 @@ export const PkiSubscriberSection = () => {
|
|||||||
<PkiSubscriberModal popUp={popUp} handlePopUpToggle={handlePopUpToggle} />
|
<PkiSubscriberModal popUp={popUp} handlePopUpToggle={handlePopUpToggle} />
|
||||||
<DeleteActionModal
|
<DeleteActionModal
|
||||||
isOpen={popUp.pkiSubscriberStatus.isOpen}
|
isOpen={popUp.pkiSubscriberStatus.isOpen}
|
||||||
title={`Are you sure want to ${isEnabling ? "enable" : "disable"} the subscriber ${subscriberName}?`}
|
title={`Are you sure you want to ${isEnabling ? "enable" : "disable"} the subscriber ${subscriberName}?`}
|
||||||
subTitle={
|
subTitle={
|
||||||
isEnabling
|
isEnabling
|
||||||
? "This action will allow issuing certificates for this subscriber again."
|
? "This action will allow issuing certificates for this subscriber again."
|
||||||
|
|||||||
Reference in New Issue
Block a user