mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 02:27:39 +00:00
@@ -7,6 +7,7 @@ import getOrganizationUserProjects from "~/pages/api/organization/GetOrgUserProj
|
|||||||
import { initPostHog } from "../analytics/posthog";
|
import { initPostHog } from "../analytics/posthog";
|
||||||
import pushKeys from "./secrets/pushKeys";
|
import pushKeys from "./secrets/pushKeys";
|
||||||
import { ENV } from "./config";
|
import { ENV } from "./config";
|
||||||
|
import { saveTokenToLocalStorage } from "./saveTokenToLocalStorage";
|
||||||
import SecurityClient from "./SecurityClient";
|
import SecurityClient from "./SecurityClient";
|
||||||
|
|
||||||
const nacl = require("tweetnacl");
|
const nacl = require("tweetnacl");
|
||||||
@@ -40,66 +41,38 @@ const attemptLogin = async (
|
|||||||
async () => {
|
async () => {
|
||||||
const clientPublicKey = client.getPublicKey();
|
const clientPublicKey = client.getPublicKey();
|
||||||
|
|
||||||
let serverPublicKey, salt;
|
const { serverPublicKey, salt } = await login1(email, clientPublicKey);
|
||||||
try {
|
|
||||||
let res = await login1(email, clientPublicKey);
|
|
||||||
res = await res.json();
|
|
||||||
serverPublicKey = res.serverPublicKey;
|
|
||||||
salt = res.salt;
|
|
||||||
} catch (err) {
|
|
||||||
setErrorLogin(true);
|
|
||||||
console.log("Wrong password", err);
|
|
||||||
}
|
|
||||||
|
|
||||||
let response;
|
|
||||||
try {
|
try {
|
||||||
client.setSalt(salt);
|
client.setSalt(salt);
|
||||||
client.setServerPublicKey(serverPublicKey);
|
client.setServerPublicKey(serverPublicKey);
|
||||||
const clientProof = client.getProof(); // called M1
|
const clientProof = client.getProof(); // called M1
|
||||||
response = await login2(email, clientProof);
|
|
||||||
} catch (err) {
|
|
||||||
setErrorLogin(true);
|
|
||||||
console.log("Password verification failed");
|
|
||||||
}
|
|
||||||
|
|
||||||
// if everything works, go the main dashboard page.
|
// if everything works, go the main dashboard page.
|
||||||
try {
|
const { token, publicKey, encryptedPrivateKey, iv, tag } =
|
||||||
if (response.status == "200") {
|
await login2(email, clientProof);
|
||||||
response = await response.json();
|
SecurityClient.setToken(token);
|
||||||
SecurityClient.setToken(response["token"]);
|
|
||||||
const publicKey = response["publicKey"];
|
|
||||||
const encryptedPrivateKey = response["encryptedPrivateKey"];
|
|
||||||
const iv = response["iv"];
|
|
||||||
const tag = response["tag"];
|
|
||||||
|
|
||||||
const PRIVATE_KEY = Aes256Gcm.decrypt(
|
const privateKey = Aes256Gcm.decrypt(
|
||||||
encryptedPrivateKey,
|
encryptedPrivateKey,
|
||||||
iv,
|
iv,
|
||||||
tag,
|
tag,
|
||||||
password
|
password
|
||||||
.slice(0, 32)
|
.slice(0, 32)
|
||||||
.padStart(
|
.padStart(
|
||||||
32 +
|
32 + (password.slice(0, 32).length - new Blob([password]).size),
|
||||||
(password.slice(0, 32).length - new Blob([password]).size),
|
"0"
|
||||||
"0"
|
)
|
||||||
)
|
);
|
||||||
);
|
|
||||||
|
|
||||||
try {
|
saveTokenToLocalStorage({
|
||||||
localStorage.setItem("publicKey", publicKey);
|
token,
|
||||||
localStorage.setItem("encryptedPrivateKey", encryptedPrivateKey);
|
publicKey,
|
||||||
localStorage.setItem("iv", iv);
|
encryptedPrivateKey,
|
||||||
localStorage.setItem("tag", tag);
|
iv,
|
||||||
localStorage.setItem("PRIVATE_KEY", PRIVATE_KEY);
|
tag,
|
||||||
} catch (err) {
|
privateKey,
|
||||||
setErrorLogin(true);
|
});
|
||||||
console.error(
|
|
||||||
"Unable to send the tokens in local storage:" + err.message
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
setErrorLogin(true);
|
|
||||||
}
|
|
||||||
|
|
||||||
const userOrgs = await getOrganizations();
|
const userOrgs = await getOrganizations();
|
||||||
const userOrgsData = userOrgs.map((org) => org._id);
|
const userOrgsData = userOrgs.map((org) => org._id);
|
||||||
@@ -149,7 +122,7 @@ const attemptLogin = async (
|
|||||||
STRIPE_SECRET_KEY: ["sk_test_7348oyho4hfq398HIUOH78", "shared"],
|
STRIPE_SECRET_KEY: ["sk_test_7348oyho4hfq398HIUOH78", "shared"],
|
||||||
},
|
},
|
||||||
workspaceId: projectToLogin,
|
workspaceId: projectToLogin,
|
||||||
env: "Development"
|
env: "Development",
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
try {
|
try {
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
interface Props {
|
||||||
|
publicKey: string;
|
||||||
|
encryptedPrivateKey: string;
|
||||||
|
iv: string;
|
||||||
|
tag: string;
|
||||||
|
privateTag: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export const saveTokenToLocalStorage = ({
|
||||||
|
publicKey,
|
||||||
|
encryptedPrivateKey,
|
||||||
|
iv,
|
||||||
|
tag,
|
||||||
|
privateTag,
|
||||||
|
}: Props) => {
|
||||||
|
try {
|
||||||
|
localStorage.setItem("publicKey", publicKey);
|
||||||
|
localStorage.setItem("encryptedPrivateKey", encryptedPrivateKey);
|
||||||
|
localStorage.setItem("iv", iv);
|
||||||
|
localStorage.setItem("tag", tag);
|
||||||
|
localStorage.setItem("PRIVATE_KEY", privateTag);
|
||||||
|
} catch (err) {
|
||||||
|
if (err instanceof Error) {
|
||||||
|
throw new Error(
|
||||||
|
"Unable to send the tokens in local storage:" + err.message
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -1,20 +0,0 @@
|
|||||||
/**
|
|
||||||
* This is the first step of the login process (pake)
|
|
||||||
* @param {*} email
|
|
||||||
* @param {*} clientPublicKey
|
|
||||||
* @returns
|
|
||||||
*/
|
|
||||||
const login1 = (email, clientPublicKey) => {
|
|
||||||
return fetch("/api/v1/auth/login1", {
|
|
||||||
method: "POST",
|
|
||||||
headers: {
|
|
||||||
"Content-Type": "application/json",
|
|
||||||
},
|
|
||||||
body: JSON.stringify({
|
|
||||||
email: email,
|
|
||||||
clientPublicKey,
|
|
||||||
}),
|
|
||||||
});
|
|
||||||
};
|
|
||||||
|
|
||||||
export default login1;
|
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
interface Login1 {
|
||||||
|
serverPublicKey: string;
|
||||||
|
salt: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* This is the first step of the login process (pake)
|
||||||
|
* @param {*} email
|
||||||
|
* @param {*} clientPublicKey
|
||||||
|
* @returns
|
||||||
|
*/
|
||||||
|
const login1 = async (email: string, clientPublicKey: string) => {
|
||||||
|
const response = await fetch("/api/v1/auth/login1", {
|
||||||
|
method: "POST",
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
},
|
||||||
|
body: JSON.stringify({
|
||||||
|
email: email,
|
||||||
|
clientPublicKey,
|
||||||
|
}),
|
||||||
|
});
|
||||||
|
// need precise error handling about the status code
|
||||||
|
if (response?.status === 200) {
|
||||||
|
const data = (await response.json()) as unknown as Login1;
|
||||||
|
return data;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error("Wrong password");
|
||||||
|
};
|
||||||
|
|
||||||
|
export default login1;
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
/**
|
|
||||||
* This is the second step of the login process
|
|
||||||
* @param {*} email
|
|
||||||
* @param {*} clientPublicKey
|
|
||||||
* @returns
|
|
||||||
*/
|
|
||||||
const login2 = (email, clientProof) => {
|
|
||||||
return fetch("/api/v1/auth/login2", {
|
|
||||||
method: "POST",
|
|
||||||
headers: {
|
|
||||||
"Content-Type": "application/json",
|
|
||||||
},
|
|
||||||
body: JSON.stringify({
|
|
||||||
email: email,
|
|
||||||
clientProof,
|
|
||||||
}),
|
|
||||||
credentials: "include",
|
|
||||||
}).then((res) => {
|
|
||||||
if (res.status == 200) {
|
|
||||||
console.log("User logged in", res);
|
|
||||||
return res;
|
|
||||||
} else {
|
|
||||||
console.log("Failed to log in");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
};
|
|
||||||
|
|
||||||
export default login2;
|
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
interface Login2Response {
|
||||||
|
encryptedPrivateKey: string;
|
||||||
|
iv: string;
|
||||||
|
publicKey: string;
|
||||||
|
tag: string;
|
||||||
|
token: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* This is the second step of the login process
|
||||||
|
* @param {*} email
|
||||||
|
* @param {*} clientPublicKey
|
||||||
|
* @returns
|
||||||
|
*/
|
||||||
|
const login2 = async (email: string, clientProof: string) => {
|
||||||
|
const response = await fetch("/api/v1/auth/login2", {
|
||||||
|
method: "POST",
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
},
|
||||||
|
body: JSON.stringify({
|
||||||
|
email: email,
|
||||||
|
clientProof,
|
||||||
|
}),
|
||||||
|
credentials: "include",
|
||||||
|
});
|
||||||
|
// need precise error handling about the status code
|
||||||
|
if (response.status == 200) {
|
||||||
|
const data = (await response.json()) as unknown as Login2Response;
|
||||||
|
return data;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error("Password verification failed");
|
||||||
|
};
|
||||||
|
|
||||||
|
export default login2;
|
||||||
Reference in New Issue
Block a user