mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 19:26:38 +00:00
Revert "add refresh token to cli"
This commit is contained in:
@@ -2,7 +2,6 @@ package api
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
"net/http"
|
|
||||||
|
|
||||||
"github.com/Infisical/infisical-merge/packages/config"
|
"github.com/Infisical/infisical-merge/packages/config"
|
||||||
"github.com/go-resty/resty/v2"
|
"github.com/go-resty/resty/v2"
|
||||||
@@ -180,19 +179,6 @@ func CallLogin2V2(httpClient *resty.Client, request GetLoginTwoV2Request) (GetLo
|
|||||||
SetBody(request).
|
SetBody(request).
|
||||||
Post(fmt.Sprintf("%v/v2/auth/login2", config.INFISICAL_URL))
|
Post(fmt.Sprintf("%v/v2/auth/login2", config.INFISICAL_URL))
|
||||||
|
|
||||||
cookies := response.Cookies()
|
|
||||||
// Find a cookie by name
|
|
||||||
cookieName := "jid"
|
|
||||||
var refreshToken *http.Cookie
|
|
||||||
for _, cookie := range cookies {
|
|
||||||
if cookie.Name == cookieName {
|
|
||||||
refreshToken = cookie
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
loginTwoV2Response.RefreshToken = refreshToken.Value
|
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return GetLoginTwoV2Response{}, fmt.Errorf("CallLogin2V2: Unable to complete api request [err=%s]", err)
|
return GetLoginTwoV2Response{}, fmt.Errorf("CallLogin2V2: Unable to complete api request [err=%s]", err)
|
||||||
}
|
}
|
||||||
@@ -261,26 +247,3 @@ func CallGetAccessibleEnvironments(httpClient *resty.Client, request GetAccessib
|
|||||||
|
|
||||||
return accessibleEnvironmentsResponse, nil
|
return accessibleEnvironmentsResponse, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func CallGetNewAccessTokenWithRefreshToken(httpClient *resty.Client, refreshToken string) (GetNewAccessTokenWithRefreshTokenResponse, error) {
|
|
||||||
var newAccessToken GetNewAccessTokenWithRefreshTokenResponse
|
|
||||||
response, err := httpClient.
|
|
||||||
R().
|
|
||||||
SetResult(&newAccessToken).
|
|
||||||
SetHeader("User-Agent", USER_AGENT).
|
|
||||||
SetCookie(&http.Cookie{
|
|
||||||
Name: "jid",
|
|
||||||
Value: refreshToken,
|
|
||||||
}).
|
|
||||||
Post(fmt.Sprintf("%v/v1/auth/token", config.INFISICAL_URL))
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return GetNewAccessTokenWithRefreshTokenResponse{}, err
|
|
||||||
}
|
|
||||||
|
|
||||||
if response.IsError() {
|
|
||||||
return GetNewAccessTokenWithRefreshTokenResponse{}, fmt.Errorf("CallGetNewAccessTokenWithRefreshToken: Unsuccessful response: [response=%v]", response)
|
|
||||||
}
|
|
||||||
|
|
||||||
return newAccessToken, nil
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -281,7 +281,6 @@ type GetLoginTwoV2Response struct {
|
|||||||
ProtectedKey string `json:"protectedKey"`
|
ProtectedKey string `json:"protectedKey"`
|
||||||
ProtectedKeyIV string `json:"protectedKeyIV"`
|
ProtectedKeyIV string `json:"protectedKeyIV"`
|
||||||
ProtectedKeyTag string `json:"protectedKeyTag"`
|
ProtectedKeyTag string `json:"protectedKeyTag"`
|
||||||
RefreshToken string `json:"RefreshToken"`
|
|
||||||
}
|
}
|
||||||
|
|
||||||
type VerifyMfaTokenRequest struct {
|
type VerifyMfaTokenRequest struct {
|
||||||
@@ -315,7 +314,3 @@ type VerifyMfaTokenErrorResponse struct {
|
|||||||
Application string `json:"application"`
|
Application string `json:"application"`
|
||||||
Extra []interface{} `json:"extra"`
|
Extra []interface{} `json:"extra"`
|
||||||
}
|
}
|
||||||
|
|
||||||
type GetNewAccessTokenWithRefreshTokenResponse struct {
|
|
||||||
Token string `json:"token"`
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ var loginCmd = &cobra.Command{
|
|||||||
|
|
||||||
loginOneResponse, loginTwoResponse, err := getFreshUserCredentials(email, password)
|
loginOneResponse, loginTwoResponse, err := getFreshUserCredentials(email, password)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Warn().Msg("Unable to authenticate with the provided credentials, please ensure your email and password are correct")
|
fmt.Println("Unable to authenticate with the provided credentials, please try again")
|
||||||
log.Debug().Err(err)
|
log.Debug().Err(err)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
@@ -244,10 +244,9 @@ var loginCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
|
|
||||||
userCredentialsToBeStored := &models.UserCredentials{
|
userCredentialsToBeStored := &models.UserCredentials{
|
||||||
Email: email,
|
Email: email,
|
||||||
PrivateKey: string(decryptedPrivateKey),
|
PrivateKey: string(decryptedPrivateKey),
|
||||||
JTWToken: loginTwoResponse.Token,
|
JTWToken: loginTwoResponse.Token,
|
||||||
RefreshToken: loginTwoResponse.RefreshToken,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
err = util.StoreUserCredsInKeyRing(userCredentialsToBeStored)
|
err = util.StoreUserCredsInKeyRing(userCredentialsToBeStored)
|
||||||
@@ -415,7 +414,7 @@ func getFreshUserCredentials(email string, password string) (*api.GetLoginOneV2R
|
|||||||
})
|
})
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, nil, err
|
util.HandleError(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// **** Login 2
|
// **** Login 2
|
||||||
|
|||||||
@@ -5,10 +5,9 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
type UserCredentials struct {
|
type UserCredentials struct {
|
||||||
Email string `json:"email"`
|
Email string `json:"email"`
|
||||||
PrivateKey string `json:"privateKey"`
|
PrivateKey string `json:"privateKey"`
|
||||||
JTWToken string `json:"JTWToken"`
|
JTWToken string `json:"JTWToken"`
|
||||||
RefreshToken string `json:"RefreshToken"`
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// The file struct for Infisical config file
|
// The file struct for Infisical config file
|
||||||
|
|||||||
@@ -9,7 +9,6 @@ import (
|
|||||||
"github.com/Infisical/infisical-merge/packages/config"
|
"github.com/Infisical/infisical-merge/packages/config"
|
||||||
"github.com/Infisical/infisical-merge/packages/models"
|
"github.com/Infisical/infisical-merge/packages/models"
|
||||||
"github.com/go-resty/resty/v2"
|
"github.com/go-resty/resty/v2"
|
||||||
"github.com/rs/zerolog/log"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type LoggedInUserDetails struct {
|
type LoggedInUserDetails struct {
|
||||||
@@ -97,20 +96,6 @@ func GetCurrentLoggedInUserDetails() (LoggedInUserDetails, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
||||||
|
|
||||||
if !isAuthenticated {
|
|
||||||
accessTokenResponse, _ := api.CallGetNewAccessTokenWithRefreshToken(httpClient, userCreds.RefreshToken)
|
|
||||||
if accessTokenResponse.Token != "" {
|
|
||||||
isAuthenticated = true
|
|
||||||
userCreds.JTWToken = accessTokenResponse.Token
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
err = StoreUserCredsInKeyRing(&userCreds)
|
|
||||||
if err != nil {
|
|
||||||
log.Debug().Msg("unable to store your user credentials with new access token")
|
|
||||||
}
|
|
||||||
|
|
||||||
if !isAuthenticated {
|
if !isAuthenticated {
|
||||||
return LoggedInUserDetails{
|
return LoggedInUserDetails{
|
||||||
IsUserLoggedIn: true, // was logged in
|
IsUserLoggedIn: true, // was logged in
|
||||||
|
|||||||
@@ -74,12 +74,23 @@ func ConfigContainsEmail(users []models.LoggedInUser, email string) bool {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func RequireLogin() {
|
func RequireLogin() {
|
||||||
// get the config file that stores the current logged in user email
|
currentUserDetails, err := GetCurrentLoggedInUserDetails()
|
||||||
configFile, _ := GetConfigFile()
|
|
||||||
|
|
||||||
if configFile.LoggedInUserEmail == "" {
|
if err != nil {
|
||||||
|
HandleError(err, "unable to retrieve your login details")
|
||||||
|
}
|
||||||
|
|
||||||
|
if !currentUserDetails.IsUserLoggedIn {
|
||||||
PrintErrorMessageAndExit("You must be logged in to run this command. To login, run [infisical login]")
|
PrintErrorMessageAndExit("You must be logged in to run this command. To login, run [infisical login]")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if currentUserDetails.LoginExpired {
|
||||||
|
PrintErrorMessageAndExit("Your login expired, please login in again. To login, run [infisical login]")
|
||||||
|
}
|
||||||
|
|
||||||
|
if currentUserDetails.UserCredentials.Email == "" && currentUserDetails.UserCredentials.JTWToken == "" && currentUserDetails.UserCredentials.PrivateKey == "" {
|
||||||
|
PrintErrorMessageAndExit("One or more of your login details is empty. Please try logging in again via by running [infisical login]")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func RequireServiceToken() {
|
func RequireServiceToken() {
|
||||||
|
|||||||
Reference in New Issue
Block a user