mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 15:28:25 +00:00
fix(secret-ref): resolved service token unable to fetch secrets in cli
This commit is contained in:
@@ -181,14 +181,16 @@ type GetServiceTokenDetailsResponse struct {
|
|||||||
ID string `json:"_id"`
|
ID string `json:"_id"`
|
||||||
Name string `json:"name"`
|
Name string `json:"name"`
|
||||||
Workspace string `json:"workspace"`
|
Workspace string `json:"workspace"`
|
||||||
Environment string `json:"environment"`
|
|
||||||
ExpiresAt time.Time `json:"expiresAt"`
|
ExpiresAt time.Time `json:"expiresAt"`
|
||||||
EncryptedKey string `json:"encryptedKey"`
|
EncryptedKey string `json:"encryptedKey"`
|
||||||
Iv string `json:"iv"`
|
Iv string `json:"iv"`
|
||||||
Tag string `json:"tag"`
|
Tag string `json:"tag"`
|
||||||
CreatedAt time.Time `json:"createdAt"`
|
CreatedAt time.Time `json:"createdAt"`
|
||||||
UpdatedAt time.Time `json:"updatedAt"`
|
UpdatedAt time.Time `json:"updatedAt"`
|
||||||
SecretPath string `json:"secretPath"`
|
Scopes []struct {
|
||||||
|
Environment string `json:"environment"`
|
||||||
|
SecretPath string `json:"secretPath"`
|
||||||
|
} `json:"scopes"`
|
||||||
}
|
}
|
||||||
|
|
||||||
type GetAccessibleEnvironmentsRequest struct {
|
type GetAccessibleEnvironmentsRequest struct {
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ import (
|
|||||||
"github.com/rs/zerolog/log"
|
"github.com/rs/zerolog/log"
|
||||||
)
|
)
|
||||||
|
|
||||||
func GetPlainTextSecretsViaServiceToken(fullServiceToken string) ([]models.SingleEnvironmentVariable, api.GetServiceTokenDetailsResponse, error) {
|
func GetPlainTextSecretsViaServiceToken(fullServiceToken string, environment string, secretPath string) ([]models.SingleEnvironmentVariable, api.GetServiceTokenDetailsResponse, error) {
|
||||||
serviceTokenParts := strings.SplitN(fullServiceToken, ".", 4)
|
serviceTokenParts := strings.SplitN(fullServiceToken, ".", 4)
|
||||||
if len(serviceTokenParts) < 4 {
|
if len(serviceTokenParts) < 4 {
|
||||||
return nil, api.GetServiceTokenDetailsResponse{}, fmt.Errorf("invalid service token entered. Please double check your service token and try again")
|
return nil, api.GetServiceTokenDetailsResponse{}, fmt.Errorf("invalid service token entered. Please double check your service token and try again")
|
||||||
@@ -35,10 +35,19 @@ func GetPlainTextSecretsViaServiceToken(fullServiceToken string) ([]models.Singl
|
|||||||
return nil, api.GetServiceTokenDetailsResponse{}, fmt.Errorf("unable to get service token details. [err=%v]", err)
|
return nil, api.GetServiceTokenDetailsResponse{}, fmt.Errorf("unable to get service token details. [err=%v]", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// if multiple scopes are there then user needs to specify which environment and secret path
|
||||||
|
if environment == "" {
|
||||||
|
if len(serviceTokenDetails.Scopes) != 1 {
|
||||||
|
return nil, api.GetServiceTokenDetailsResponse{}, fmt.Errorf("you need to provide the --env for multiple environment scoped token")
|
||||||
|
} else {
|
||||||
|
environment = serviceTokenDetails.Scopes[0].Environment
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
encryptedSecrets, err := api.CallGetSecretsV3(httpClient, api.GetEncryptedSecretsV3Request{
|
encryptedSecrets, err := api.CallGetSecretsV3(httpClient, api.GetEncryptedSecretsV3Request{
|
||||||
WorkspaceId: serviceTokenDetails.Workspace,
|
WorkspaceId: serviceTokenDetails.Workspace,
|
||||||
Environment: serviceTokenDetails.Environment,
|
Environment: environment,
|
||||||
SecretPath: serviceTokenDetails.SecretPath,
|
SecretPath: secretPath,
|
||||||
})
|
})
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -190,11 +199,7 @@ func GetAllEnvironmentVariables(params models.GetAllSecretsParameters) ([]models
|
|||||||
|
|
||||||
} else {
|
} else {
|
||||||
log.Debug().Msg("Trying to fetch secrets using service token")
|
log.Debug().Msg("Trying to fetch secrets using service token")
|
||||||
secretsToReturn, _, errorToReturn = GetPlainTextSecretsViaServiceToken(infisicalToken)
|
secretsToReturn, _, errorToReturn = GetPlainTextSecretsViaServiceToken(infisicalToken, params.Environment, params.SecretsPath)
|
||||||
|
|
||||||
// if serviceTokenDetails.Environment != params.Environment {
|
|
||||||
// PrintErrorMessageAndExit(fmt.Sprintf("Fetch secrets failed: token allows [%s] environment access, not [%s]. Service tokens are environment-specific; no need for --env flag.", params.Environment, serviceTokenDetails.Environment))
|
|
||||||
// }
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return secretsToReturn, errorToReturn
|
return secretsToReturn, errorToReturn
|
||||||
|
|||||||
Reference in New Issue
Block a user