mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fixed app connection endpoints
This commit is contained in:
@@ -38,7 +38,7 @@
|
||||
"build:frontend": "npm run build --prefix ../frontend",
|
||||
"start": "node --enable-source-maps dist/main.mjs",
|
||||
"type:check": "tsc --noEmit",
|
||||
"lint:fix": "eslint --fix --ext js,ts ./src",
|
||||
"lint:fix": "node --max-old-space-size=8192 ./node_modules/.bin/eslint --fix --ext js,ts ./src",
|
||||
"lint": "eslint 'src/**/*.ts'",
|
||||
"test:unit": "vitest run -c vitest.unit.config.ts",
|
||||
"test:e2e": "vitest run -c vitest.e2e.config.ts --bail=1",
|
||||
|
||||
@@ -22,8 +22,6 @@ export const registerOCIConnectionRouter = async (server: FastifyZodProvider) =>
|
||||
});
|
||||
|
||||
// The following endpoints are for internal Infisical App use only and not part of the public API
|
||||
|
||||
// TODO(andrey): These may need to be changed
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: `/:connectionId/vaults`,
|
||||
@@ -32,25 +30,29 @@ export const registerOCIConnectionRouter = async (server: FastifyZodProvider) =>
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
connectionId: z.string().uuid(),
|
||||
connectionId: z.string().uuid()
|
||||
}),
|
||||
querystring: z.object({
|
||||
compartmentOcid: z.string().min(1, "Compartment OCID required")
|
||||
}),
|
||||
response: {
|
||||
200: z
|
||||
.object({
|
||||
// TODO(andrey): This may need change
|
||||
id: z.string(),
|
||||
displayName: z.string(),
|
||||
compartmentId: z.string(),
|
||||
timeCreated: z.string(),
|
||||
lifecycleState: z.string()
|
||||
displayName: z.string()
|
||||
})
|
||||
.array()
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const vaults = await server.services.appConnection.oci.listVaults(req.params, req.permission);
|
||||
const { connectionId } = req.params;
|
||||
const { compartmentOcid } = req.query;
|
||||
|
||||
const vaults = await server.services.appConnection.oci.listVaults(
|
||||
{ connectionId, compartmentOcid },
|
||||
req.permission
|
||||
);
|
||||
return vaults;
|
||||
}
|
||||
});
|
||||
@@ -63,14 +65,15 @@ export const registerOCIConnectionRouter = async (server: FastifyZodProvider) =>
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
connectionId: z.string().uuid(),
|
||||
connectionId: z.string().uuid()
|
||||
}),
|
||||
querystring: z.object({
|
||||
compartmentOcid: z.string().min(1, "Compartment OCID required"),
|
||||
vaultOcid: z.string().min(1, "Compartment OCID required")
|
||||
}),
|
||||
response: {
|
||||
200: z
|
||||
.object({
|
||||
// TODO(andrey): This may need change
|
||||
id: z.string(),
|
||||
displayName: z.string()
|
||||
})
|
||||
@@ -79,7 +82,13 @@ export const registerOCIConnectionRouter = async (server: FastifyZodProvider) =>
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const vaults = await server.services.appConnection.oci.listVaultKeys(req.params, req.permission);
|
||||
const { connectionId } = req.params;
|
||||
const { compartmentOcid, vaultOcid } = req.query;
|
||||
|
||||
const vaults = await server.services.appConnection.oci.listVaultKeys(
|
||||
{ connectionId, compartmentOcid, vaultOcid },
|
||||
req.permission
|
||||
);
|
||||
return vaults;
|
||||
}
|
||||
});
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { common, identity, keymanagement } from "oci-sdk";
|
||||
import { common, identity, keymanagement, vault } from "oci-sdk";
|
||||
|
||||
import { request } from "@app/lib/config/request";
|
||||
import { BadRequestError } from "@app/lib/errors";
|
||||
@@ -56,43 +56,24 @@ export const validateOCIConnectionCredentials = async (config: TOCIConnectionCon
|
||||
return config.credentials;
|
||||
};
|
||||
|
||||
// TODO(andrey): This may need to be removed. I don't think the endpoint is right
|
||||
export const listOCIVaults = async (appConnection: TOCIConnection, compartmentOcid: string) => {
|
||||
const provider = await getOCIProvider(appConnection);
|
||||
const signer = new common.DefaultRequestSigner(provider);
|
||||
|
||||
// Create proper type for response
|
||||
interface VaultsResponse {
|
||||
items: Array<{
|
||||
id: string;
|
||||
displayName: string;
|
||||
compartmentId: string;
|
||||
timeCreated: string;
|
||||
lifecycleState: string;
|
||||
}>;
|
||||
}
|
||||
|
||||
const requestParams = await common.composeRequest({
|
||||
method: "GET",
|
||||
baseEndpoint: `https://vaults.${appConnection.credentials.region}.oci.oraclecloud.com`,
|
||||
path: "/20180608/vaults",
|
||||
pathParams: { compartmentId: compartmentOcid },
|
||||
defaultHeaders: {
|
||||
Accept: "application/json"
|
||||
}
|
||||
});
|
||||
await signer.signHttpRequest(requestParams);
|
||||
const resp = await request.get<VaultsResponse>(requestParams.uri, {
|
||||
headers: requestParams.headers as unknown as Record<string, string>
|
||||
const keyManagementClient = new keymanagement.KmsVaultClient({
|
||||
authenticationDetailsProvider: provider
|
||||
});
|
||||
|
||||
return resp.data.items;
|
||||
const vaults = await keyManagementClient.listVaults({
|
||||
compartmentId: compartmentOcid
|
||||
});
|
||||
|
||||
return vaults.items;
|
||||
};
|
||||
|
||||
export const listOCIVaultKeys = async (appConnection: TOCIConnection, compartmentOcid: string, vaultOcid: string) => {
|
||||
const provider = await getOCIProvider(appConnection);
|
||||
|
||||
const vaultIdMatch = vaultOcid.match(/ocid1\.vault\.[^.]+\.([^.]+)/);
|
||||
const vaultIdMatch = vaultOcid.match(/ocid1\.vault\.[^.]+\.[^.]+\.([^.]+)/);
|
||||
if (!vaultIdMatch || !vaultIdMatch[1]) {
|
||||
throw new BadRequestError({
|
||||
message: "Invalid vault OCID format"
|
||||
@@ -103,14 +84,11 @@ export const listOCIVaultKeys = async (appConnection: TOCIConnection, compartmen
|
||||
authenticationDetailsProvider: provider
|
||||
});
|
||||
|
||||
keyManagementClient.endpoint = `https://${vaultIdMatch[1]}-crypto.kms.${appConnection.credentials.region}.oraclecloud.com`;
|
||||
keyManagementClient.endpoint = `https://${vaultIdMatch[1]}-management.kms.${appConnection.credentials.region}.oraclecloud.com`;
|
||||
|
||||
const keys = await keyManagementClient.listKeys({
|
||||
compartmentId: compartmentOcid
|
||||
});
|
||||
|
||||
return keys.items.map((key) => ({
|
||||
id: key.id,
|
||||
displayName: key.displayName
|
||||
}));
|
||||
return keys.items;
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user