mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
feat: updated by reptile feedback
This commit is contained in:
@@ -183,7 +183,12 @@ export const AwsElastiCacheDatabaseProvider = (): TDynamicProviderFns => {
|
|||||||
} catch (err) {
|
} catch (err) {
|
||||||
const sanitizedErrorMessage = sanitizeString({
|
const sanitizedErrorMessage = sanitizeString({
|
||||||
unsanitizedString: (err as Error)?.message,
|
unsanitizedString: (err as Error)?.message,
|
||||||
tokens: [providerInputs.accessKeyId, providerInputs.secretAccessKey, providerInputs.clusterName]
|
tokens: [
|
||||||
|
providerInputs.accessKeyId,
|
||||||
|
providerInputs.secretAccessKey,
|
||||||
|
providerInputs.clusterName,
|
||||||
|
providerInputs.region
|
||||||
|
]
|
||||||
});
|
});
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Failed to connect with provider: ${sanitizedErrorMessage}`
|
message: `Failed to connect with provider: ${sanitizedErrorMessage}`
|
||||||
|
|||||||
@@ -180,47 +180,49 @@ export const AwsIamProvider = (): TDynamicProviderFns => {
|
|||||||
awsTags.push(...additionalTags);
|
awsTags.push(...additionalTags);
|
||||||
}
|
}
|
||||||
|
|
||||||
const createUserRes = await client.send(
|
try {
|
||||||
new CreateUserCommand({
|
const createUserRes = await client.send(
|
||||||
Path: awsPath,
|
new CreateUserCommand({
|
||||||
PermissionsBoundary: permissionBoundaryPolicyArn || undefined,
|
Path: awsPath,
|
||||||
Tags: awsTags,
|
PermissionsBoundary: permissionBoundaryPolicyArn || undefined,
|
||||||
UserName: username
|
Tags: awsTags,
|
||||||
})
|
UserName: username
|
||||||
);
|
|
||||||
|
|
||||||
if (!createUserRes.User) throw new BadRequestError({ message: "Failed to create AWS IAM User" });
|
|
||||||
if (userGroups) {
|
|
||||||
await Promise.all(
|
|
||||||
userGroups
|
|
||||||
.split(",")
|
|
||||||
.filter(Boolean)
|
|
||||||
.map((group) =>
|
|
||||||
client.send(new AddUserToGroupCommand({ UserName: createUserRes?.User?.UserName, GroupName: group }))
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (policyArns) {
|
|
||||||
await Promise.all(
|
|
||||||
policyArns
|
|
||||||
.split(",")
|
|
||||||
.filter(Boolean)
|
|
||||||
.map((policyArn) =>
|
|
||||||
client.send(new AttachUserPolicyCommand({ UserName: createUserRes?.User?.UserName, PolicyArn: policyArn }))
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (policyDocument) {
|
|
||||||
await client.send(
|
|
||||||
new PutUserPolicyCommand({
|
|
||||||
UserName: createUserRes.User.UserName,
|
|
||||||
PolicyName: `infisical-dynamic-policy-${alphaNumericNanoId(4)}`,
|
|
||||||
PolicyDocument: policyDocument
|
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
if (!createUserRes.User) throw new BadRequestError({ message: "Failed to create AWS IAM User" });
|
||||||
|
if (userGroups) {
|
||||||
|
await Promise.all(
|
||||||
|
userGroups
|
||||||
|
.split(",")
|
||||||
|
.filter(Boolean)
|
||||||
|
.map((group) =>
|
||||||
|
client.send(new AddUserToGroupCommand({ UserName: createUserRes?.User?.UserName, GroupName: group }))
|
||||||
|
)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (policyArns) {
|
||||||
|
await Promise.all(
|
||||||
|
policyArns
|
||||||
|
.split(",")
|
||||||
|
.filter(Boolean)
|
||||||
|
.map((policyArn) =>
|
||||||
|
client.send(
|
||||||
|
new AttachUserPolicyCommand({ UserName: createUserRes?.User?.UserName, PolicyArn: policyArn })
|
||||||
|
)
|
||||||
|
)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (policyDocument) {
|
||||||
|
await client.send(
|
||||||
|
new PutUserPolicyCommand({
|
||||||
|
UserName: createUserRes.User.UserName,
|
||||||
|
PolicyName: `infisical-dynamic-policy-${alphaNumericNanoId(4)}`,
|
||||||
|
PolicyDocument: policyDocument
|
||||||
|
})
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
const createAccessKeyRes = await client.send(
|
const createAccessKeyRes = await client.send(
|
||||||
new CreateAccessKeyCommand({
|
new CreateAccessKeyCommand({
|
||||||
UserName: createUserRes.User.UserName
|
UserName: createUserRes.User.UserName
|
||||||
|
|||||||
@@ -114,12 +114,12 @@ export const AzureEntraIDProvider = (): TDynamicProviderFns & {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const revoke = async (inputs: unknown, entityId: string) => {
|
const revoke = async (inputs: unknown, entityId: string) => {
|
||||||
|
const providerInputs = await validateProviderInputs(inputs);
|
||||||
try {
|
try {
|
||||||
// Creates a new password
|
// Creates a new password
|
||||||
await create({ inputs });
|
await create({ inputs });
|
||||||
return { entityId };
|
return { entityId };
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
const providerInputs = await validateProviderInputs(inputs);
|
|
||||||
const sanitizedErrorMessage = sanitizeString({
|
const sanitizedErrorMessage = sanitizeString({
|
||||||
unsanitizedString: (err as Error)?.message,
|
unsanitizedString: (err as Error)?.message,
|
||||||
tokens: [providerInputs.clientSecret, providerInputs.applicationId, entityId]
|
tokens: [providerInputs.clientSecret, providerInputs.applicationId, entityId]
|
||||||
|
|||||||
@@ -66,11 +66,7 @@ export const ElasticSearchProvider = (): TDynamicProviderFns => {
|
|||||||
const connection = await $getClient(providerInputs);
|
const connection = await $getClient(providerInputs);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const infoResponse = await connection
|
const infoResponse = await connection.info().then(() => true);
|
||||||
.info()
|
|
||||||
.then(() => true)
|
|
||||||
.catch(() => false);
|
|
||||||
|
|
||||||
return infoResponse;
|
return infoResponse;
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
const tokens = [];
|
const tokens = [];
|
||||||
|
|||||||
@@ -216,7 +216,8 @@ export const LdapProvider = (): TDynamicProviderFns => {
|
|||||||
if (providerInputs.credentialType === LdapCredentialType.Static) {
|
if (providerInputs.credentialType === LdapCredentialType.Static) {
|
||||||
const dnRegex = new RE2("^dn:\\s*(.+)", "m");
|
const dnRegex = new RE2("^dn:\\s*(.+)", "m");
|
||||||
const dnMatch = dnRegex.exec(providerInputs.rotationLdif);
|
const dnMatch = dnRegex.exec(providerInputs.rotationLdif);
|
||||||
const username = dnMatch?.[1] || "";
|
const username = dnMatch?.[1];
|
||||||
|
if (!username) throw new BadRequestError({ message: "Username not found from Ldif" });
|
||||||
const password = generatePassword();
|
const password = generatePassword();
|
||||||
|
|
||||||
if (dnMatch) {
|
if (dnMatch) {
|
||||||
|
|||||||
@@ -123,7 +123,12 @@ export const RedisDatabaseProvider = (): TDynamicProviderFns => {
|
|||||||
if (connection) await connection.quit();
|
if (connection) await connection.quit();
|
||||||
const sanitizedErrorMessage = sanitizeString({
|
const sanitizedErrorMessage = sanitizeString({
|
||||||
unsanitizedString: (err as Error)?.message,
|
unsanitizedString: (err as Error)?.message,
|
||||||
tokens: [providerInputs.password || "", providerInputs.username, providerInputs.host]
|
tokens: [
|
||||||
|
providerInputs.password || "",
|
||||||
|
providerInputs.username,
|
||||||
|
providerInputs.host,
|
||||||
|
String(providerInputs.port)
|
||||||
|
]
|
||||||
});
|
});
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Failed to connect with provider: ${sanitizedErrorMessage}`
|
message: `Failed to connect with provider: ${sanitizedErrorMessage}`
|
||||||
|
|||||||
@@ -155,7 +155,7 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
|
|||||||
sqlText: revokeStatement,
|
sqlText: revokeStatement,
|
||||||
complete(err) {
|
complete(err) {
|
||||||
if (err) {
|
if (err) {
|
||||||
return reject();
|
return reject(err);
|
||||||
}
|
}
|
||||||
|
|
||||||
return resolve(true);
|
return resolve(true);
|
||||||
|
|||||||
Reference in New Issue
Block a user