mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 18:28:27 +00:00
misc: added audit logs for kms backup and other minor edits
This commit is contained in:
@@ -281,7 +281,13 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId
|
projectId: req.params.workspaceId
|
||||||
});
|
});
|
||||||
|
|
||||||
// TODO: add audit log
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.GET_PROJECT_KMS_BACKUP
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return backup;
|
return backup;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -144,7 +144,8 @@ export enum EventType {
|
|||||||
UPDATE_KMS = "update-kms",
|
UPDATE_KMS = "update-kms",
|
||||||
DELETE_KMS = "delete-kms",
|
DELETE_KMS = "delete-kms",
|
||||||
GET_KMS = "get-kms",
|
GET_KMS = "get-kms",
|
||||||
UPDATE_PROJECT_KMS = "update-project-kms"
|
UPDATE_PROJECT_KMS = "update-project-kms",
|
||||||
|
GET_PROJECT_KMS_BACKUP = "get-project-kms-backup"
|
||||||
}
|
}
|
||||||
|
|
||||||
interface UserActorMetadata {
|
interface UserActorMetadata {
|
||||||
@@ -1223,6 +1224,10 @@ interface UpdateProjectKmsEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface GetProjectKmsBackupEvent {
|
||||||
|
type: EventType.GET_PROJECT_KMS_BACKUP;
|
||||||
|
}
|
||||||
|
|
||||||
export type Event =
|
export type Event =
|
||||||
| GetSecretsEvent
|
| GetSecretsEvent
|
||||||
| GetSecretEvent
|
| GetSecretEvent
|
||||||
@@ -1329,4 +1334,5 @@ export type Event =
|
|||||||
| UpdateKmsEvent
|
| UpdateKmsEvent
|
||||||
| DeleteKmsEvent
|
| DeleteKmsEvent
|
||||||
| GetKmsEvent
|
| GetKmsEvent
|
||||||
| UpdateProjectKmsEvent;
|
| UpdateProjectKmsEvent
|
||||||
|
| GetProjectKmsBackupEvent;
|
||||||
|
|||||||
@@ -598,8 +598,8 @@ export const kmsServiceFactory = ({
|
|||||||
const kmsEncryptor = await encryptWithKmsKey({ kmsId: kmsKeyIdForEncrypt });
|
const kmsEncryptor = await encryptWithKmsKey({ kmsId: kmsKeyIdForEncrypt });
|
||||||
const { cipherTextBlob: encryptedSecretManagerDataKey } = await kmsEncryptor({ plainText: secretManagerDataKey });
|
const { cipherTextBlob: encryptedSecretManagerDataKey } = await kmsEncryptor({ plainText: secretManagerDataKey });
|
||||||
|
|
||||||
// format: projectId.kmsFunction.kmsId.Base64(encryptedDataKey)
|
// format: version.projectId.kmsFunction.kmsId.Base64(encryptedDataKey)
|
||||||
const secretManagerBackup = `${projectId}.secretManager.${kmsKeyIdForEncrypt}.${encryptedSecretManagerDataKey.toString(
|
const secretManagerBackup = `v1.${projectId}.secretManager.${kmsKeyIdForEncrypt}.${encryptedSecretManagerDataKey.toString(
|
||||||
"base64"
|
"base64"
|
||||||
)}`;
|
)}`;
|
||||||
|
|
||||||
|
|||||||
@@ -713,7 +713,7 @@ export const projectServiceFactory = ({
|
|||||||
const plan = await licenseService.getPlan(actorOrgId);
|
const plan = await licenseService.getPlan(actorOrgId);
|
||||||
if (!plan.externalKms) {
|
if (!plan.externalKms) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Failed to create KMS backup due to plan restriction. Upgrade to the enterprise plan."
|
message: "Failed to get KMS backup due to plan restriction. Upgrade to the enterprise plan."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -79,7 +79,7 @@ export const EncryptionTab = () => {
|
|||||||
|
|
||||||
const { secretManager } = await fetchProjectKmsBackup(currentWorkspace.id);
|
const { secretManager } = await fetchProjectKmsBackup(currentWorkspace.id);
|
||||||
|
|
||||||
const [, kmsFunction] = secretManager.split(".");
|
const [, , kmsFunction] = secretManager.split(".");
|
||||||
const file = secretManager;
|
const file = secretManager;
|
||||||
|
|
||||||
const blob = new Blob([file], { type: "text/plain;charset=utf-8" });
|
const blob = new Blob([file], { type: "text/plain;charset=utf-8" });
|
||||||
|
|||||||
Reference in New Issue
Block a user