mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 13:28:34 +00:00
review fixes
This commit is contained in:
@@ -1,6 +1,7 @@
|
|||||||
/* eslint-disable @typescript-eslint/no-unsafe-assignment */
|
/* eslint-disable @typescript-eslint/no-unsafe-assignment */
|
||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
|
import RE2 from "re2";
|
||||||
|
|
||||||
import { IdentityAuthMethod } from "@app/db/schemas";
|
import { IdentityAuthMethod } from "@app/db/schemas";
|
||||||
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
||||||
@@ -58,6 +59,13 @@ export const identityOciAuthServiceFactory = ({
|
|||||||
|
|
||||||
await blockLocalAndPrivateIpAddresses(headers.host);
|
await blockLocalAndPrivateIpAddresses(headers.host);
|
||||||
|
|
||||||
|
// Validate OCI host format
|
||||||
|
if (!headers.host || !new RE2("^identity\\.[a-zA-Z0-9-]+\\.oraclecloud\\.com$").test(headers.host)) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Invalid OCI host format. Expected format: identity.<region>.oraclecloud.com"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const { data } = await request.get<TOciGetUserResponse>(`https://${headers.host}/20160918/users/${userOcid}`, {
|
const { data } = await request.get<TOciGetUserResponse>(`https://${headers.host}/20160918/users/${userOcid}`, {
|
||||||
headers
|
headers
|
||||||
});
|
});
|
||||||
@@ -209,7 +217,7 @@ export const identityOciAuthServiceFactory = ({
|
|||||||
|
|
||||||
if (
|
if (
|
||||||
(accessTokenMaxTTL || identityOciAuth.accessTokenMaxTTL) > 0 &&
|
(accessTokenMaxTTL || identityOciAuth.accessTokenMaxTTL) > 0 &&
|
||||||
(accessTokenTTL || identityOciAuth.accessTokenMaxTTL) > (accessTokenMaxTTL || identityOciAuth.accessTokenMaxTTL)
|
(accessTokenTTL || identityOciAuth.accessTokenTTL) > (accessTokenMaxTTL || identityOciAuth.accessTokenMaxTTL)
|
||||||
) {
|
) {
|
||||||
throw new BadRequestError({ message: "Access token TTL cannot be greater than max TTL" });
|
throw new BadRequestError({ message: "Access token TTL cannot be greater than max TTL" });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,13 +1,14 @@
|
|||||||
|
import RE2 from "re2";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
const usernameSchema = z
|
const usernameSchema = z
|
||||||
.string()
|
.string()
|
||||||
.min(1, "Username cannot be empty")
|
.min(1, "Username cannot be empty")
|
||||||
.regex(/^[a-zA-Z0-9._@-]+$/, "Invalid OCI username format");
|
.refine((val) => new RE2("^[a-zA-Z0-9._@-]+$").test(val), "Invalid OCI username format");
|
||||||
|
|
||||||
export const validateUsernames = z
|
export const validateUsernames = z
|
||||||
.string()
|
.string()
|
||||||
.trim()
|
.trim()
|
||||||
|
.max(500, "Input exceeds the maximum limit of 500 characters")
|
||||||
.transform((val) =>
|
.transform((val) =>
|
||||||
val
|
val
|
||||||
.split(",")
|
.split(",")
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ To interact with the Infisical API, you will need to obtain an access token. Fol
|
|||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
|
|
||||||
- The client secret or access token has expired.
|
- The client secret or access token has expired.
|
||||||
- The identity is insufficently permissioned to interact with the resources you wish to access.
|
- The identity is insufficiently permissioned to interact with the resources you wish to access.
|
||||||
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
- You are attempting to access a `/raw` secrets endpoint that requires your project to disable E2EE.
|
||||||
- The client secret/access token is being used from an untrusted IP.
|
- The client secret/access token is being used from an untrusted IP.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|||||||
@@ -280,7 +280,7 @@ In the following steps, we explore how to create and use identities for your app
|
|||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
|
|
||||||
- The access token has expired.
|
- The access token has expired.
|
||||||
- The identity is insufficently permissioned to interact with the resources you wish to access.
|
- The identity is insufficiently permissioned to interact with the resources you wish to access.
|
||||||
- The client access token is being used from an untrusted IP.
|
- The client access token is being used from an untrusted IP.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|||||||
@@ -143,7 +143,7 @@ const requestAsJson = {
|
|||||||
headers: Object.fromEntries(request.headers.entries()),
|
headers: Object.fromEntries(request.headers.entries()),
|
||||||
};
|
};
|
||||||
|
|
||||||
const res = await fetch("https://tunnel.util.lol/api/v1/auth/oci-auth/login", {
|
const res = await fetch("https://app.infisical.com/api/v1/auth/oci-auth/login", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
|
|||||||
@@ -123,7 +123,7 @@ using the Token Auth authentication method.
|
|||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
|
|
||||||
- The access token has expired. If this is the case, you should obtain a new access token or consider extending the token's TTL.
|
- The access token has expired. If this is the case, you should obtain a new access token or consider extending the token's TTL.
|
||||||
- The identity is insufficently permissioned to interact with the resources you wish to access.
|
- The identity is insufficiently permissioned to interact with the resources you wish to access.
|
||||||
- The access token is being used from an untrusted IP.
|
- The access token is being used from an untrusted IP.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="What is access token renewal and TTL/Max TTL?">
|
<Accordion title="What is access token renewal and TTL/Max TTL?">
|
||||||
|
|||||||
@@ -161,7 +161,7 @@ using the Universal Auth authentication method.
|
|||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
|
|
||||||
- The client secret or access token has expired.
|
- The client secret or access token has expired.
|
||||||
- The identity is insufficently permissioned to interact with the resources you wish to access.
|
- The identity is insufficiently permissioned to interact with the resources you wish to access.
|
||||||
- The client secret/access token is being used from an untrusted IP.
|
- The client secret/access token is being used from an untrusted IP.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="What is access token renewal and TTL/Max TTL?">
|
<Accordion title="What is access token renewal and TTL/Max TTL?">
|
||||||
|
|||||||
@@ -184,7 +184,7 @@ In the following steps, we explore the end-to-end workflow for setting up this s
|
|||||||
<Accordion title="Why are my AWS IAM credentials not rotating?">
|
<Accordion title="Why are my AWS IAM credentials not rotating?">
|
||||||
There are a few reasons for why this might happen:
|
There are a few reasons for why this might happen:
|
||||||
- The strategy configuration is invalid (e.g. the managing IAM user's credentials are incorrect, the target AWS region is incorrect, etc.)
|
- The strategy configuration is invalid (e.g. the managing IAM user's credentials are incorrect, the target AWS region is incorrect, etc.)
|
||||||
- The managing IAM user is insufficently permissioned to rotate the credentials of the target IAM user. For instance, you may have setup
|
- The managing IAM user is insufficiently permissioned to rotate the credentials of the target IAM user. For instance, you may have setup
|
||||||
[paths](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) for the managing IAM user and the policy does not have the necessary
|
[paths](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) for the managing IAM user and the policy does not have the necessary
|
||||||
permissions to rotate the credentials.
|
permissions to rotate the credentials.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|||||||
Reference in New Issue
Block a user