mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 05:28:23 +00:00
Fix change password private key removal
This commit is contained in:
@@ -13,8 +13,6 @@ import { deriveArgonKey } from './crypto';
|
|||||||
const clientOldPassword = new jsrp.client();
|
const clientOldPassword = new jsrp.client();
|
||||||
const clientNewPassword = new jsrp.client();
|
const clientNewPassword = new jsrp.client();
|
||||||
|
|
||||||
// TODO: modify this function
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* This function loggs in the user (whether it's right after signup, or a normal login)
|
* This function loggs in the user (whether it's right after signup, or a normal login)
|
||||||
* @param {*} email
|
* @param {*} email
|
||||||
@@ -105,9 +103,8 @@ const changePassword = async (
|
|||||||
secret: Buffer.from(derivedKey.hash)
|
secret: Buffer.from(derivedKey.hash)
|
||||||
});
|
});
|
||||||
|
|
||||||
let res;
|
|
||||||
try {
|
try {
|
||||||
res = await changePassword2({
|
await changePassword2({
|
||||||
clientProof,
|
clientProof,
|
||||||
protectedKey,
|
protectedKey,
|
||||||
protectedKeyIV,
|
protectedKeyIV,
|
||||||
@@ -118,23 +115,19 @@ const changePassword = async (
|
|||||||
salt: result.salt,
|
salt: result.salt,
|
||||||
verifier: result.verifier
|
verifier: result.verifier
|
||||||
});
|
});
|
||||||
|
|
||||||
saveTokenToLocalStorage({
|
saveTokenToLocalStorage({
|
||||||
protectedKey,
|
protectedKey,
|
||||||
protectedKeyIV,
|
protectedKeyIV,
|
||||||
protectedKeyTag,
|
protectedKeyTag,
|
||||||
encryptedPrivateKey,
|
encryptedPrivateKey,
|
||||||
iv: encryptedPrivateKeyIV,
|
iv: encryptedPrivateKeyIV,
|
||||||
tag: encryptedPrivateKeyTag,
|
tag: encryptedPrivateKeyTag
|
||||||
});
|
});
|
||||||
|
|
||||||
if (res && res.status === 400) {
|
setPasswordChanged(true);
|
||||||
setCurrentPasswordError(true);
|
setCurrentPassword('');
|
||||||
} else if (res && res.status === 200) {
|
setNewPassword('');
|
||||||
setPasswordChanged(true);
|
|
||||||
setCurrentPassword('');
|
|
||||||
setNewPassword('');
|
|
||||||
}
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
setCurrentPasswordError(true);
|
setCurrentPasswordError(true);
|
||||||
console.log(error);
|
console.log(error);
|
||||||
|
|||||||
@@ -3,9 +3,9 @@ interface Props {
|
|||||||
protectedKeyIV?: string;
|
protectedKeyIV?: string;
|
||||||
protectedKeyTag?: string;
|
protectedKeyTag?: string;
|
||||||
publicKey?: string;
|
publicKey?: string;
|
||||||
encryptedPrivateKey: string;
|
encryptedPrivateKey?: string;
|
||||||
iv: string;
|
iv?: string;
|
||||||
tag: string;
|
tag?: string;
|
||||||
privateKey?: string;
|
privateKey?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -20,38 +20,46 @@ export const saveTokenToLocalStorage = ({
|
|||||||
privateKey,
|
privateKey,
|
||||||
}: Props) => {
|
}: Props) => {
|
||||||
try {
|
try {
|
||||||
localStorage.removeItem("protectedKey");
|
|
||||||
localStorage.removeItem("protectedKeyIV");
|
|
||||||
localStorage.removeItem("protectedKeyTag");
|
|
||||||
localStorage.removeItem("publicKey");
|
|
||||||
localStorage.removeItem("encryptedPrivateKey");
|
|
||||||
localStorage.removeItem("iv");
|
|
||||||
localStorage.removeItem("tag");
|
|
||||||
localStorage.removeItem("PRIVATE_KEY");
|
|
||||||
|
|
||||||
if (protectedKey) {
|
if (protectedKey) {
|
||||||
|
localStorage.removeItem("protectedKey");
|
||||||
localStorage.setItem("protectedKey", protectedKey);
|
localStorage.setItem("protectedKey", protectedKey);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (protectedKeyIV) {
|
if (protectedKeyIV) {
|
||||||
|
localStorage.removeItem("protectedKeyIV");
|
||||||
localStorage.setItem("protectedKeyIV", protectedKeyIV);
|
localStorage.setItem("protectedKeyIV", protectedKeyIV);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (protectedKeyTag) {
|
if (protectedKeyTag) {
|
||||||
|
localStorage.removeItem("protectedKeyTag");
|
||||||
localStorage.setItem("protectedKeyTag", protectedKeyTag);
|
localStorage.setItem("protectedKeyTag", protectedKeyTag);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (publicKey) {
|
if (publicKey) {
|
||||||
|
localStorage.removeItem("publicKey");
|
||||||
localStorage.setItem("publicKey", publicKey);
|
localStorage.setItem("publicKey", publicKey);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (privateKey) {
|
if (encryptedPrivateKey) {
|
||||||
localStorage.setItem("PRIVATE_KEY", privateKey);
|
localStorage.removeItem("encryptedPrivateKey");
|
||||||
|
localStorage.setItem("encryptedPrivateKey", encryptedPrivateKey);
|
||||||
}
|
}
|
||||||
|
|
||||||
localStorage.setItem("encryptedPrivateKey", encryptedPrivateKey);
|
if (iv) {
|
||||||
localStorage.setItem("iv", iv);
|
localStorage.removeItem("iv");
|
||||||
localStorage.setItem("tag", tag);
|
localStorage.setItem("iv", iv);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (tag) {
|
||||||
|
localStorage.removeItem("tag");
|
||||||
|
localStorage.setItem("tag", tag);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (privateKey) {
|
||||||
|
localStorage.removeItem("PRIVATE_KEY");
|
||||||
|
localStorage.setItem("PRIVATE_KEY", privateKey);
|
||||||
|
}
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
if (err instanceof Error) {
|
if (err instanceof Error) {
|
||||||
throw new Error(
|
throw new Error(
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import SecurityClient from '@app/components/utilities/SecurityClient';
|
import { apiRequest } from "@app/config/request";
|
||||||
|
|
||||||
interface Props {
|
interface Props {
|
||||||
clientProof: string;
|
clientProof: string;
|
||||||
@@ -17,7 +17,7 @@ interface Props {
|
|||||||
* @param {*} clientPublicKey
|
* @param {*} clientPublicKey
|
||||||
* @returns
|
* @returns
|
||||||
*/
|
*/
|
||||||
const changePassword2 = ({
|
const changePassword2 = async ({
|
||||||
clientProof,
|
clientProof,
|
||||||
protectedKey,
|
protectedKey,
|
||||||
protectedKeyIV,
|
protectedKeyIV,
|
||||||
@@ -27,29 +27,20 @@ const changePassword2 = ({
|
|||||||
encryptedPrivateKeyTag,
|
encryptedPrivateKeyTag,
|
||||||
salt,
|
salt,
|
||||||
verifier
|
verifier
|
||||||
}: Props) =>
|
}: Props) => {
|
||||||
SecurityClient.fetchCall('/api/v1/password/change-password', {
|
const { data } = await apiRequest.post('/api/v1/password/change-password', {
|
||||||
method: 'POST',
|
clientProof,
|
||||||
headers: {
|
protectedKey,
|
||||||
'Content-Type': 'application/json'
|
protectedKeyIV,
|
||||||
},
|
protectedKeyTag,
|
||||||
body: JSON.stringify({
|
encryptedPrivateKey,
|
||||||
clientProof,
|
encryptedPrivateKeyIV,
|
||||||
protectedKey,
|
encryptedPrivateKeyTag,
|
||||||
protectedKeyIV,
|
salt,
|
||||||
protectedKeyTag,
|
verifier
|
||||||
encryptedPrivateKey,
|
|
||||||
encryptedPrivateKeyIV,
|
|
||||||
encryptedPrivateKeyTag,
|
|
||||||
salt,
|
|
||||||
verifier
|
|
||||||
})
|
|
||||||
}).then(async (res) => {
|
|
||||||
if (res && res.status === 200) {
|
|
||||||
return res;
|
|
||||||
}
|
|
||||||
console.log('Failed to change the password');
|
|
||||||
return undefined;
|
|
||||||
});
|
});
|
||||||
|
|
||||||
|
return data;
|
||||||
|
}
|
||||||
|
|
||||||
export default changePassword2;
|
export default changePassword2;
|
||||||
|
|||||||
Reference in New Issue
Block a user