diff --git a/backend/src/server/routes/v1/certificate-router.ts b/backend/src/server/routes/v1/certificate-router.ts index 6306d7403..1975a4a44 100644 --- a/backend/src/server/routes/v1/certificate-router.ts +++ b/backend/src/server/routes/v1/certificate-router.ts @@ -484,13 +484,13 @@ export const registerCertRouter = async (server: FastifyZodProvider) => { response: { 200: z.object({ certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate), - certificateChain: z.string().trim().describe(CERTIFICATES.GET_CERT.certificateChain), + certificateChain: z.string().trim().nullable().describe(CERTIFICATES.GET_CERT.certificateChain), serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes) }) } }, handler: async (req) => { - const { certificate, certificateChain, serialNumber, cert, ca } = await server.services.certificate.getCertBody({ + const { certificate, certificateChain, serialNumber, cert } = await server.services.certificate.getCertBody({ serialNumber: req.params.serialNumber, actor: req.permission.type, actorId: req.permission.id, @@ -500,7 +500,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => { await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, - projectId: ca.projectId, + projectId: cert.projectId, event: { type: EventType.DELETE_CERT, metadata: { diff --git a/backend/src/services/certificate-authority/certificate-authority-service.ts b/backend/src/services/certificate-authority/certificate-authority-service.ts index 499a25741..0ab09e7fb 100644 --- a/backend/src/services/certificate-authority/certificate-authority-service.ts +++ b/backend/src/services/certificate-authority/certificate-authority-service.ts @@ -1388,7 +1388,8 @@ export const certificateAuthorityServiceFactory = ({ notBefore: notBeforeDate, notAfter: notAfterDate, keyUsages: selectedKeyUsages, - extendedKeyUsages: selectedExtendedKeyUsages + extendedKeyUsages: selectedExtendedKeyUsages, + projectId: ca.projectId }, tx ); @@ -1422,6 +1423,7 @@ export const certificateAuthorityServiceFactory = ({ kmsService }); + // TODO(andrey): Might need tweaks after other PR merge return { certificate: leafCert.toString("pem"), certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(), @@ -1779,7 +1781,8 @@ export const certificateAuthorityServiceFactory = ({ notBefore: notBeforeDate, notAfter: notAfterDate, keyUsages: selectedKeyUsages, - extendedKeyUsages: selectedExtendedKeyUsages + extendedKeyUsages: selectedExtendedKeyUsages, + projectId: ca.projectId }, tx ); @@ -1813,6 +1816,7 @@ export const certificateAuthorityServiceFactory = ({ kmsService }); + // TODO(andrey): Might need tweaks after other PR merge return { certificate: leafCert, certificateChain: `${issuingCaCertificate}\n${caCertChain}`.trim(), diff --git a/backend/src/services/certificate/certificate-service.ts b/backend/src/services/certificate/certificate-service.ts index 6bd76b2f0..aa5a113f3 100644 --- a/backend/src/services/certificate/certificate-service.ts +++ b/backend/src/services/certificate/certificate-service.ts @@ -174,17 +174,10 @@ export const certificateServiceFactory = ({ const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => { const cert = await certificateDAL.findOne({ serialNumber }); - // TODO(andrey): Remove this later. - if (!cert.caId || !cert.caCertId) { - throw new Error("ERROR"); - } - - const ca = await certificateAuthorityDAL.findById(cert.caId); - const { permission } = await permissionService.getProjectPermission({ actor, actorId, - projectId: ca.projectId, + projectId: cert.projectId, actorAuthMethod, actorOrgId, actionProjectType: ActionProjectType.CertificateManager @@ -195,7 +188,7 @@ export const certificateServiceFactory = ({ const certBody = await certificateBodyDAL.findOne({ certId: cert.id }); const certificateManagerKeyId = await getProjectKmsCertificateKeyId({ - projectId: ca.projectId, + projectId: cert.projectId, projectDAL, kmsService }); @@ -209,20 +202,26 @@ export const certificateServiceFactory = ({ const certObj = new x509.X509Certificate(decryptedCert); - const { caCert, caCertChain } = await getCaCertChain({ - caCertId: cert.caCertId, - certificateAuthorityDAL, - certificateAuthorityCertDAL, - projectDAL, - kmsService - }); + let certificateChain = null; + + // TODO(andrey): Update this after the "store cert chain on cert body" PR gets merged + if (cert.caCertId) { + const { caCert, caCertChain } = await getCaCertChain({ + caCertId: cert.caCertId, + certificateAuthorityDAL, + certificateAuthorityCertDAL, + projectDAL, + kmsService + }); + + certificateChain = `${caCert}\n${caCertChain}`.trim(); + } return { certificate: certObj.toString("pem"), - certificateChain: `${caCert}\n${caCertChain}`.trim(), + certificateChain, serialNumber: certObj.serialNumber, - cert, - ca + cert }; };