mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 06:26:16 +00:00
Merge pull request #773 from Infisical/debug-google-sso
Initialize organization bot upon creating organization
This commit is contained in:
@@ -3,12 +3,100 @@ import { client, getEncryptionKey, getRootEncryptionKey } from "../config";
|
|||||||
import { BotOrg } from "../models";
|
import { BotOrg } from "../models";
|
||||||
import { decryptSymmetric128BitHexKeyUTF8 } from "../utils/crypto";
|
import { decryptSymmetric128BitHexKeyUTF8 } from "../utils/crypto";
|
||||||
import {
|
import {
|
||||||
|
ALGORITHM_AES_256_GCM,
|
||||||
ENCODING_SCHEME_BASE64,
|
ENCODING_SCHEME_BASE64,
|
||||||
ENCODING_SCHEME_UTF8
|
ENCODING_SCHEME_UTF8
|
||||||
} from "../variables";
|
} from "../variables";
|
||||||
import { InternalServerError } from "../utils/errors";
|
import { InternalServerError } from "../utils/errors";
|
||||||
|
import { encryptSymmetric128BitHexKeyUTF8, generateKeyPair } from "../utils/crypto";
|
||||||
|
|
||||||
// TODO: DOCstrings
|
/**
|
||||||
|
* Create a bot with name [name] for organization with id [organizationId]
|
||||||
|
* @param {Object} obj
|
||||||
|
* @param {String} obj.name - name of bot
|
||||||
|
* @param {String} obj.organizationId - id of organization that bot belongs to
|
||||||
|
*/
|
||||||
|
export const createBotOrg = async ({
|
||||||
|
name,
|
||||||
|
organizationId,
|
||||||
|
}: {
|
||||||
|
name: string;
|
||||||
|
organizationId: Types.ObjectId;
|
||||||
|
}) => {
|
||||||
|
const encryptionKey = await getEncryptionKey();
|
||||||
|
const rootEncryptionKey = await getRootEncryptionKey();
|
||||||
|
|
||||||
|
const { publicKey, privateKey } = generateKeyPair();
|
||||||
|
const key = client.createSymmetricKey();
|
||||||
|
|
||||||
|
if (rootEncryptionKey) {
|
||||||
|
const {
|
||||||
|
ciphertext: encryptedPrivateKey,
|
||||||
|
iv: privateKeyIV,
|
||||||
|
tag: privateKeyTag
|
||||||
|
} = client.encryptSymmetric(privateKey, rootEncryptionKey);
|
||||||
|
|
||||||
|
const {
|
||||||
|
ciphertext: encryptedSymmetricKey,
|
||||||
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag
|
||||||
|
} = client.encryptSymmetric(key, rootEncryptionKey);
|
||||||
|
|
||||||
|
return await new BotOrg({
|
||||||
|
name,
|
||||||
|
organization: organizationId,
|
||||||
|
publicKey,
|
||||||
|
encryptedSymmetricKey,
|
||||||
|
symmetricKeyIV,
|
||||||
|
symmetricKeyTag,
|
||||||
|
symmetricKeyAlgorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
symmetricKeyKeyEncoding: ENCODING_SCHEME_BASE64,
|
||||||
|
encryptedPrivateKey,
|
||||||
|
privateKeyIV,
|
||||||
|
privateKeyTag,
|
||||||
|
privateKeyAlgorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
privateKeyKeyEncoding: ENCODING_SCHEME_BASE64
|
||||||
|
}).save();
|
||||||
|
} else if (encryptionKey) {
|
||||||
|
const {
|
||||||
|
ciphertext: encryptedPrivateKey,
|
||||||
|
iv: privateKeyIV,
|
||||||
|
tag: privateKeyTag
|
||||||
|
} = encryptSymmetric128BitHexKeyUTF8({
|
||||||
|
plaintext: privateKey,
|
||||||
|
key: encryptionKey
|
||||||
|
});
|
||||||
|
|
||||||
|
const {
|
||||||
|
ciphertext: encryptedSymmetricKey,
|
||||||
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag
|
||||||
|
} = encryptSymmetric128BitHexKeyUTF8({
|
||||||
|
plaintext: key,
|
||||||
|
key: encryptionKey
|
||||||
|
});
|
||||||
|
|
||||||
|
return await new BotOrg({
|
||||||
|
name,
|
||||||
|
organization: organizationId,
|
||||||
|
publicKey,
|
||||||
|
encryptedSymmetricKey,
|
||||||
|
symmetricKeyIV,
|
||||||
|
symmetricKeyTag,
|
||||||
|
symmetricKeyAlgorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
symmetricKeyKeyEncoding: ENCODING_SCHEME_UTF8,
|
||||||
|
encryptedPrivateKey,
|
||||||
|
privateKeyIV,
|
||||||
|
privateKeyTag,
|
||||||
|
privateKeyAlgorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
privateKeyKeyEncoding: ENCODING_SCHEME_UTF8
|
||||||
|
}).save();
|
||||||
|
}
|
||||||
|
|
||||||
|
throw InternalServerError({
|
||||||
|
message: "Failed to create new organization bot due to missing encryption key",
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
export const getSymmetricKeyHelper = async (organizationId: Types.ObjectId) => {
|
export const getSymmetricKeyHelper = async (organizationId: Types.ObjectId) => {
|
||||||
const rootEncryptionKey = await getRootEncryptionKey();
|
const rootEncryptionKey = await getRootEncryptionKey();
|
||||||
|
|||||||
@@ -14,6 +14,9 @@ import {
|
|||||||
licenseKeyRequest,
|
licenseKeyRequest,
|
||||||
licenseServerKeyRequest,
|
licenseServerKeyRequest,
|
||||||
} from "../config/request";
|
} from "../config/request";
|
||||||
|
import {
|
||||||
|
createBotOrg
|
||||||
|
} from "./botOrg";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create an organization with name [name]
|
* Create an organization with name [name]
|
||||||
@@ -29,6 +32,7 @@ export const createOrganization = async ({
|
|||||||
name: string;
|
name: string;
|
||||||
email: string;
|
email: string;
|
||||||
}) => {
|
}) => {
|
||||||
|
|
||||||
const licenseServerKey = await getLicenseServerKey();
|
const licenseServerKey = await getLicenseServerKey();
|
||||||
let organization;
|
let organization;
|
||||||
|
|
||||||
@@ -52,6 +56,12 @@ export const createOrganization = async ({
|
|||||||
}).save();
|
}).save();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// initialize bot for organization
|
||||||
|
await createBotOrg({
|
||||||
|
name,
|
||||||
|
organizationId: organization._id
|
||||||
|
});
|
||||||
|
|
||||||
return organization;
|
return organization;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -177,7 +177,6 @@ export const backfillBotOrgs = async () => {
|
|||||||
return new BotOrg({
|
return new BotOrg({
|
||||||
name: "Infisical Bot",
|
name: "Infisical Bot",
|
||||||
organization: organizationToAddBot,
|
organization: organizationToAddBot,
|
||||||
isActive: false,
|
|
||||||
publicKey,
|
publicKey,
|
||||||
encryptedSymmetricKey,
|
encryptedSymmetricKey,
|
||||||
symmetricKeyIV,
|
symmetricKeyIV,
|
||||||
@@ -212,7 +211,6 @@ export const backfillBotOrgs = async () => {
|
|||||||
return new BotOrg({
|
return new BotOrg({
|
||||||
name: "Infisical Bot",
|
name: "Infisical Bot",
|
||||||
organization: organizationToAddBot,
|
organization: organizationToAddBot,
|
||||||
isActive: false,
|
|
||||||
publicKey,
|
publicKey,
|
||||||
encryptedSymmetricKey,
|
encryptedSymmetricKey,
|
||||||
symmetricKeyIV,
|
symmetricKeyIV,
|
||||||
|
|||||||
@@ -112,10 +112,6 @@ export const UserInfoSSOStep = ({
|
|||||||
const privateKey = encodeBase64(secretKeyUint8Array);
|
const privateKey = encodeBase64(secretKeyUint8Array);
|
||||||
const publicKey = encodeBase64(publicKeyUint8Array);
|
const publicKey = encodeBase64(publicKeyUint8Array);
|
||||||
localStorage.setItem("PRIVATE_KEY", privateKey);
|
localStorage.setItem("PRIVATE_KEY", privateKey);
|
||||||
|
|
||||||
console.log("make");
|
|
||||||
console.log("email: ", email);
|
|
||||||
console.log("password: ", password);
|
|
||||||
|
|
||||||
client.init(
|
client.init(
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user