mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 13:28:34 +00:00
addressed requested changes
This commit is contained in:
@@ -2309,7 +2309,7 @@ export const AppConnections = {
|
|||||||
tenantId: "The Tenant ID to use to connect with Azure Client Secrets.",
|
tenantId: "The Tenant ID to use to connect with Azure Client Secrets.",
|
||||||
clientId: "The Client ID to use to connect with Azure Client Secrets.",
|
clientId: "The Client ID to use to connect with Azure Client Secrets.",
|
||||||
clientSecret: "The Client Secret to use to connect with Azure Client Secrets.",
|
clientSecret: "The Client Secret to use to connect with Azure Client Secrets.",
|
||||||
certificate: "The certificate to use to connect with Azure Client Secrets.",
|
certificateBody: "The certificate body in PEM format to use to connect with Azure Client Secrets.",
|
||||||
privateKey:
|
privateKey:
|
||||||
"The private key to use to connect with Azure Client Secrets. This is never transmitted to Azure and is only used to sign the Azure client assertion with."
|
"The private key to use to connect with Azure Client Secrets. This is never transmitted to Azure and is only used to sign the Azure client assertion with."
|
||||||
},
|
},
|
||||||
|
|||||||
+9
-8
@@ -1,6 +1,7 @@
|
|||||||
/* eslint-disable no-case-declarations */
|
/* eslint-disable no-case-declarations */
|
||||||
import { AxiosError, AxiosResponse } from "axios";
|
import { AxiosError, AxiosResponse } from "axios";
|
||||||
import type { KeyObject } from "crypto";
|
import type { KeyObject } from "crypto";
|
||||||
|
import RE2 from "re2";
|
||||||
import { v4 as uuidv4 } from "uuid";
|
import { v4 as uuidv4 } from "uuid";
|
||||||
|
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
@@ -37,9 +38,9 @@ const generateClientAssertion = (
|
|||||||
|
|
||||||
const certBuffer = Buffer.from(
|
const certBuffer = Buffer.from(
|
||||||
certificate
|
certificate
|
||||||
.replace(/-----BEGIN CERTIFICATE-----/, "")
|
.replace(new RE2("-----BEGIN CERTIFICATE-----"), "")
|
||||||
.replace(/-----END CERTIFICATE-----/, "")
|
.replace(new RE2("-----END CERTIFICATE-----"), "")
|
||||||
.replace(/\s/g, ""),
|
.replace(new RE2("\\s", "g"), ""),
|
||||||
"base64"
|
"base64"
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -225,12 +226,12 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
kmsService,
|
kmsService,
|
||||||
encryptedCredentials: appConnection.encryptedCredentials
|
encryptedCredentials: appConnection.encryptedCredentials
|
||||||
})) as TAzureClientSecretsConnectionCertificateCredentials;
|
})) as TAzureClientSecretsConnectionCertificateCredentials;
|
||||||
const { accessToken, expiresAt, clientId, tenantId, certificate, privateKey } = accessTokenCredentials;
|
const { accessToken, expiresAt, clientId, tenantId, certificateBody, privateKey } = accessTokenCredentials;
|
||||||
if (accessToken && expiresAt && expiresAt > currentTime + 300000) {
|
if (accessToken && expiresAt && expiresAt > currentTime + 300000) {
|
||||||
return accessToken;
|
return accessToken;
|
||||||
}
|
}
|
||||||
|
|
||||||
const clientAssertion = generateClientAssertion(clientId, tenantId, privateKey, certificate);
|
const clientAssertion = generateClientAssertion(clientId, tenantId, privateKey, certificateBody);
|
||||||
const { data: clientData } = await request.post<ExchangeCodeAzureResponse>(
|
const { data: clientData } = await request.post<ExchangeCodeAzureResponse>(
|
||||||
IntegrationUrls.AZURE_TOKEN_URL.replace("common", tenantId || "common"),
|
IntegrationUrls.AZURE_TOKEN_URL.replace("common", tenantId || "common"),
|
||||||
new URLSearchParams({
|
new URLSearchParams({
|
||||||
@@ -379,9 +380,9 @@ export const validateAzureClientSecretsConnectionCredentials = async (config: TA
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
case AzureClientSecretsConnectionMethod.Certificate: {
|
case AzureClientSecretsConnectionMethod.Certificate: {
|
||||||
const { tenantId, certificate, privateKey, clientId } = inputCredentials;
|
const { tenantId, certificateBody, privateKey, clientId } = inputCredentials;
|
||||||
try {
|
try {
|
||||||
const clientAssertion = generateClientAssertion(clientId, tenantId, privateKey, certificate);
|
const clientAssertion = generateClientAssertion(clientId, tenantId, privateKey, certificateBody);
|
||||||
|
|
||||||
const tokenEndpoint = `https://login.microsoftonline.com/${tenantId}/oauth2/v2.0/token`;
|
const tokenEndpoint = `https://login.microsoftonline.com/${tenantId}/oauth2/v2.0/token`;
|
||||||
|
|
||||||
@@ -402,7 +403,7 @@ export const validateAzureClientSecretsConnectionCredentials = async (config: TA
|
|||||||
return {
|
return {
|
||||||
tenantId,
|
tenantId,
|
||||||
clientId,
|
clientId,
|
||||||
certificate,
|
certificateBody,
|
||||||
privateKey,
|
privateKey,
|
||||||
accessToken: response.data.access_token,
|
accessToken: response.data.access_token,
|
||||||
expiresAt: Date.now() + response.data.expires_in * 1000
|
expiresAt: Date.now() + response.data.expires_in * 1000
|
||||||
|
|||||||
+4
-4
@@ -61,11 +61,11 @@ export const AzureClientSecretsConnectionCertificateInputCredentialsSchema = z.o
|
|||||||
.trim()
|
.trim()
|
||||||
.min(1, "Client ID required")
|
.min(1, "Client ID required")
|
||||||
.describe(AppConnections.CREDENTIALS.AZURE_CLIENT_SECRETS.clientId),
|
.describe(AppConnections.CREDENTIALS.AZURE_CLIENT_SECRETS.clientId),
|
||||||
certificate: z
|
certificateBody: z
|
||||||
.string()
|
.string()
|
||||||
.trim()
|
.trim()
|
||||||
.min(1, "Certificate required")
|
.min(1, "Certificate body required")
|
||||||
.describe(AppConnections.CREDENTIALS.AZURE_CLIENT_SECRETS.certificate),
|
.describe(AppConnections.CREDENTIALS.AZURE_CLIENT_SECRETS.certificateBody),
|
||||||
privateKey: z
|
privateKey: z
|
||||||
.string()
|
.string()
|
||||||
.trim()
|
.trim()
|
||||||
@@ -84,7 +84,7 @@ export const AzureClientSecretsConnectionClientSecretOutputCredentialsSchema = z
|
|||||||
export const AzureClientSecretsConnectionCertificateOutputCredentialsSchema = z.object({
|
export const AzureClientSecretsConnectionCertificateOutputCredentialsSchema = z.object({
|
||||||
clientId: z.string(),
|
clientId: z.string(),
|
||||||
tenantId: z.string(),
|
tenantId: z.string(),
|
||||||
certificate: z.string(),
|
certificateBody: z.string(),
|
||||||
privateKey: z.string(),
|
privateKey: z.string(),
|
||||||
accessToken: z.string(),
|
accessToken: z.string(),
|
||||||
expiresAt: z.number()
|
expiresAt: z.number()
|
||||||
|
|||||||
@@ -122,7 +122,7 @@ Infisical currently only supports two methods for connecting to Azure, which are
|
|||||||

|

|
||||||
|
|
||||||
<Tip>
|
<Tip>
|
||||||
Keep in mind that you'll need the both the certificate & private key in order to configure the Azure Client Secrets connection within Infisical.
|
Keep in mind that both the certificate and its private key are required to configure the Azure Client Secrets connection in Infisical.
|
||||||
</Tip>
|
</Tip>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
@@ -168,7 +168,7 @@ Infisical currently only supports two methods for connecting to Azure, which are
|
|||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Certificate">
|
<Tab title="Certificate">
|
||||||
<Step title="Create Connection">
|
<Step title="Create Connection">
|
||||||
Fill in the **Tenant ID**, **Client ID**, **Certificate**, and **Private Key** fields with the Directory (Tenant) ID, Application (Client) ID, Certificate and Private Key you obtained in the [previous step](#certificate-authentication).
|
Fill in the **Tenant ID**, **Client ID**, **Certificate (PEM format)**, and **Private Key** fields with the Directory (Tenant) ID, Application (Client) ID, Certificate and Private Key you obtained in the [previous step](#certificate-authentication).
|
||||||
|
|
||||||
<Tip>
|
<Tip>
|
||||||
The private key is never transmitted to Azure, and it is only used to sign the client assertion used to authenticate with Azure.
|
The private key is never transmitted to Azure, and it is only used to sign the client assertion used to authenticate with Azure.
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ export type TAzureClientSecretsConnection = TRootAppConnection & {
|
|||||||
credentials: {
|
credentials: {
|
||||||
clientId: string;
|
clientId: string;
|
||||||
tenantId: string;
|
tenantId: string;
|
||||||
certificate: string;
|
certificateBody: string;
|
||||||
privateKey: string;
|
privateKey: string;
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
+8
-4
@@ -68,7 +68,7 @@ const certificateSchema = baseSchema.extend({
|
|||||||
method: z.literal(AzureClientSecretsConnectionMethod.Certificate),
|
method: z.literal(AzureClientSecretsConnectionMethod.Certificate),
|
||||||
credentials: z.object({
|
credentials: z.object({
|
||||||
clientId: z.string().trim().min(1, "Client ID is required"),
|
clientId: z.string().trim().min(1, "Client ID is required"),
|
||||||
certificate: z.string().trim().min(1, "Certificate is required"),
|
certificateBody: z.string().trim().min(1, "Certificate is required"),
|
||||||
privateKey: z.string().trim().min(1, "Private Key is required"),
|
privateKey: z.string().trim().min(1, "Private Key is required"),
|
||||||
tenantId: z.string().trim().min(1, "Tenant ID is required")
|
tenantId: z.string().trim().min(1, "Tenant ID is required")
|
||||||
})
|
})
|
||||||
@@ -129,7 +129,7 @@ const getDefaultValues = (appConnection?: TAzureClientSecretsConnection): Partia
|
|||||||
credentials: {
|
credentials: {
|
||||||
clientId: credentials.clientId,
|
clientId: credentials.clientId,
|
||||||
tenantId: credentials.tenantId,
|
tenantId: credentials.tenantId,
|
||||||
certificate: "",
|
certificateBody: "",
|
||||||
privateKey: ""
|
privateKey: ""
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
@@ -249,7 +249,11 @@ export const AzureClientSecretsConnectionForm = ({ appConnection, onSubmit, proj
|
|||||||
/>
|
/>
|
||||||
|
|
||||||
<Controller
|
<Controller
|
||||||
name="tenantId"
|
name={
|
||||||
|
selectedMethod === AzureClientSecretsConnectionMethod.OAuth
|
||||||
|
? "tenantId"
|
||||||
|
: "credentials.tenantId"
|
||||||
|
}
|
||||||
control={control}
|
control={control}
|
||||||
render={({ field, fieldState: { error } }) => (
|
render={({ field, fieldState: { error } }) => (
|
||||||
<FormControl
|
<FormControl
|
||||||
@@ -322,7 +326,7 @@ export const AzureClientSecretsConnectionForm = ({ appConnection, onSubmit, proj
|
|||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
<Controller
|
<Controller
|
||||||
name="credentials.certificate"
|
name="credentials.certificateBody"
|
||||||
control={control}
|
control={control}
|
||||||
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
<FormControl
|
<FormControl
|
||||||
|
|||||||
Reference in New Issue
Block a user