mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 09:25:59 +00:00
fix: tests failing
This commit is contained in:
@@ -1,6 +1,9 @@
|
|||||||
import { SecretType, TSecrets } from "@app/db/schemas";
|
import { SecretType, TSecrets } from "@app/db/schemas";
|
||||||
import { decryptSecret, encryptSecret, getUserPrivateKey, seedData1 } from "@app/db/seed-data";
|
import { decryptSecret, encryptSecret, getUserPrivateKey, seedData1 } from "@app/db/seed-data";
|
||||||
|
import { initEnvConfig } from "@app/lib/config/env";
|
||||||
import { SymmetricKeySize } from "@app/lib/crypto";
|
import { SymmetricKeySize } from "@app/lib/crypto";
|
||||||
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
|
import { initLogger, logger } from "@app/lib/logger";
|
||||||
|
|
||||||
const createServiceToken = async (
|
const createServiceToken = async (
|
||||||
scopes: { environment: string; secretPath: string }[],
|
scopes: { environment: string; secretPath: string }[],
|
||||||
@@ -24,16 +27,17 @@ const createServiceToken = async (
|
|||||||
});
|
});
|
||||||
const { user: userInfo } = JSON.parse(userInfoRes.payload);
|
const { user: userInfo } = JSON.parse(userInfoRes.payload);
|
||||||
const privateKey = await getUserPrivateKey(seedData1.password, userInfo);
|
const privateKey = await getUserPrivateKey(seedData1.password, userInfo);
|
||||||
const projectKey = testCryptoProvider.encryption().asymmetric().decrypt({
|
|
||||||
|
const projectKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: projectKeyEnc.encryptedKey,
|
ciphertext: projectKeyEnc.encryptedKey,
|
||||||
nonce: projectKeyEnc.nonce,
|
nonce: projectKeyEnc.nonce,
|
||||||
publicKey: projectKeyEnc.sender.publicKey,
|
publicKey: projectKeyEnc.sender.publicKey,
|
||||||
privateKey
|
privateKey
|
||||||
});
|
});
|
||||||
|
|
||||||
const randomBytes = testCryptoProvider.randomBytes(16).toString("hex");
|
const randomBytes = crypto.randomBytes(16).toString("hex");
|
||||||
|
|
||||||
const { ciphertext, iv, tag } = testCryptoProvider.encryption().encryptSymmetric({
|
const { ciphertext, iv, tag } = crypto.encryption().encryptSymmetric({
|
||||||
plaintext: projectKey,
|
plaintext: projectKey,
|
||||||
key: randomBytes,
|
key: randomBytes,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -141,6 +145,9 @@ describe("Service token secret ops", async () => {
|
|||||||
let projectKey = "";
|
let projectKey = "";
|
||||||
let folderId = "";
|
let folderId = "";
|
||||||
beforeAll(async () => {
|
beforeAll(async () => {
|
||||||
|
initLogger();
|
||||||
|
await initEnvConfig(testSuperAdminDAL, logger);
|
||||||
|
|
||||||
serviceToken = await createServiceToken(
|
serviceToken = await createServiceToken(
|
||||||
[{ secretPath: "/**", environment: seedData1.environment.slug }],
|
[{ secretPath: "/**", environment: seedData1.environment.slug }],
|
||||||
["read", "write"]
|
["read", "write"]
|
||||||
@@ -158,7 +165,7 @@ describe("Service token secret ops", async () => {
|
|||||||
const serviceTokenInfo = serviceTokenInfoRes.json();
|
const serviceTokenInfo = serviceTokenInfoRes.json();
|
||||||
const serviceTokenParts = serviceToken.split(".");
|
const serviceTokenParts = serviceToken.split(".");
|
||||||
|
|
||||||
projectKey = testCryptoProvider.encryption().decryptSymmetric({
|
projectKey = crypto.encryption().decryptSymmetric({
|
||||||
key: serviceTokenParts[3],
|
key: serviceTokenParts[3],
|
||||||
tag: serviceTokenInfo.tag,
|
tag: serviceTokenInfo.tag,
|
||||||
ciphertext: serviceTokenInfo.encryptedKey,
|
ciphertext: serviceTokenInfo.encryptedKey,
|
||||||
@@ -557,7 +564,7 @@ describe("Service token fail cases", async () => {
|
|||||||
type: SecretType.Shared,
|
type: SecretType.Shared,
|
||||||
secretPath: "/",
|
secretPath: "/",
|
||||||
// doesn't matter project key because this will fail before that due to read only access
|
// doesn't matter project key because this will fail before that due to read only access
|
||||||
...encryptSecret(testCryptoProvider.randomBytes(16).toString("hex"), "NEW", "value", "")
|
...encryptSecret(crypto.randomBytes(16).toString("hex"), "NEW", "value", "")
|
||||||
},
|
},
|
||||||
headers: {
|
headers: {
|
||||||
authorization: `Bearer ${serviceToken}`
|
authorization: `Bearer ${serviceToken}`
|
||||||
|
|||||||
@@ -1,5 +1,8 @@
|
|||||||
import { SecretType, TSecrets } from "@app/db/schemas";
|
import { SecretType, TSecrets } from "@app/db/schemas";
|
||||||
import { decryptSecret, encryptSecret, getUserPrivateKey, seedData1 } from "@app/db/seed-data";
|
import { decryptSecret, encryptSecret, getUserPrivateKey, seedData1 } from "@app/db/seed-data";
|
||||||
|
import { initEnvConfig } from "@app/lib/config/env";
|
||||||
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
|
import { initLogger, logger } from "@app/lib/logger";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
const createSecret = async (dto: {
|
const createSecret = async (dto: {
|
||||||
@@ -154,6 +157,9 @@ describe("Secret V3 Router", async () => {
|
|||||||
let projectKey = "";
|
let projectKey = "";
|
||||||
let folderId = "";
|
let folderId = "";
|
||||||
beforeAll(async () => {
|
beforeAll(async () => {
|
||||||
|
initLogger();
|
||||||
|
await initEnvConfig(testSuperAdminDAL, logger);
|
||||||
|
|
||||||
const projectKeyRes = await testServer.inject({
|
const projectKeyRes = await testServer.inject({
|
||||||
method: "GET",
|
method: "GET",
|
||||||
url: `/api/v2/workspace/${seedData1.project.id}/encrypted-key`,
|
url: `/api/v2/workspace/${seedData1.project.id}/encrypted-key`,
|
||||||
@@ -172,7 +178,7 @@ describe("Secret V3 Router", async () => {
|
|||||||
});
|
});
|
||||||
const { user: userInfo } = JSON.parse(userInfoRes.payload);
|
const { user: userInfo } = JSON.parse(userInfoRes.payload);
|
||||||
const privateKey = await getUserPrivateKey(seedData1.password, userInfo);
|
const privateKey = await getUserPrivateKey(seedData1.password, userInfo);
|
||||||
projectKey = testCryptoProvider.encryption().asymmetric().decrypt({
|
projectKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: projectKeyEncryptionDetails.encryptedKey,
|
ciphertext: projectKeyEncryptionDetails.encryptedKey,
|
||||||
nonce: projectKeyEncryptionDetails.nonce,
|
nonce: projectKeyEncryptionDetails.nonce,
|
||||||
publicKey: projectKeyEncryptionDetails.sender.publicKey,
|
publicKey: projectKeyEncryptionDetails.sender.publicKey,
|
||||||
@@ -668,7 +674,7 @@ describe.each([{ auth: AuthMode.JWT }, { auth: AuthMode.IDENTITY_ACCESS_TOKEN }]
|
|||||||
const { user: userInfo } = JSON.parse(userInfoRes.payload);
|
const { user: userInfo } = JSON.parse(userInfoRes.payload);
|
||||||
|
|
||||||
const privateKey = await getUserPrivateKey(seedData1.password, userInfo);
|
const privateKey = await getUserPrivateKey(seedData1.password, userInfo);
|
||||||
const projectKey = testCryptoProvider.encryption().asymmetric().decrypt({
|
const projectKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: projectKeyEnc.encryptedKey,
|
ciphertext: projectKeyEnc.encryptedKey,
|
||||||
nonce: projectKeyEnc.nonce,
|
nonce: projectKeyEnc.nonce,
|
||||||
publicKey: projectKeyEnc.sender.publicKey,
|
publicKey: projectKeyEnc.sender.publicKey,
|
||||||
@@ -684,7 +690,7 @@ describe.each([{ auth: AuthMode.JWT }, { auth: AuthMode.IDENTITY_ACCESS_TOKEN }]
|
|||||||
});
|
});
|
||||||
expect(projectBotRes.statusCode).toEqual(200);
|
expect(projectBotRes.statusCode).toEqual(200);
|
||||||
const projectBot = JSON.parse(projectBotRes.payload).bot;
|
const projectBot = JSON.parse(projectBotRes.payload).bot;
|
||||||
const botKey = testCryptoProvider.encryption().asymmetric().encrypt(projectKey, projectBot.publicKey, privateKey);
|
const botKey = crypto.encryption().asymmetric().encrypt(projectKey, projectBot.publicKey, privateKey);
|
||||||
|
|
||||||
// set bot as active
|
// set bot as active
|
||||||
const setBotActive = await testServer.inject({
|
const setBotActive = await testServer.inject({
|
||||||
|
|||||||
@@ -18,7 +18,6 @@ import { keyStoreFactory } from "@app/keystore/keystore";
|
|||||||
import { initializeHsmModule } from "@app/ee/services/hsm/hsm-fns";
|
import { initializeHsmModule } from "@app/ee/services/hsm/hsm-fns";
|
||||||
import { buildRedisFromConfig } from "@app/lib/config/redis";
|
import { buildRedisFromConfig } from "@app/lib/config/redis";
|
||||||
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
|
||||||
|
|
||||||
dotenv.config({ path: path.join(__dirname, "../../.env.test"), debug: true });
|
dotenv.config({ path: path.join(__dirname, "../../.env.test"), debug: true });
|
||||||
export default {
|
export default {
|
||||||
@@ -82,7 +81,7 @@ export default {
|
|||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
globalThis.testServer = server;
|
globalThis.testServer = server;
|
||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
globalThis.testCryptoProvider = crypto;
|
globalThis.testSuperAdminDAL = superAdminDAL;
|
||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
globalThis.jwtAuthToken = jwt.sign(
|
globalThis.jwtAuthToken = jwt.sign(
|
||||||
{
|
{
|
||||||
@@ -111,6 +110,8 @@ export default {
|
|||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
delete globalThis.testServer;
|
delete globalThis.testServer;
|
||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
|
delete globalThis.testSuperAdminDAL;
|
||||||
|
// @ts-expect-error type
|
||||||
delete globalThis.jwtToken;
|
delete globalThis.jwtToken;
|
||||||
// called after all tests with this env have been run
|
// called after all tests with this env have been run
|
||||||
await db.migrate.rollback(
|
await db.migrate.rollback(
|
||||||
|
|||||||
Vendored
+2
-2
@@ -1,8 +1,8 @@
|
|||||||
import { FastifyInstance, RawReplyDefaultExpression, RawRequestDefaultExpression, RawServerDefault } from "fastify";
|
import { FastifyInstance, RawReplyDefaultExpression, RawRequestDefaultExpression, RawServerDefault } from "fastify";
|
||||||
|
|
||||||
import { TCryptographyFactory } from "@app/lib/crypto/cryptography";
|
|
||||||
import { CustomLogger } from "@app/lib/logger/logger";
|
import { CustomLogger } from "@app/lib/logger/logger";
|
||||||
import { ZodTypeProvider } from "@app/server/plugins/fastify-zod";
|
import { ZodTypeProvider } from "@app/server/plugins/fastify-zod";
|
||||||
|
import { TSuperAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
||||||
|
|
||||||
declare global {
|
declare global {
|
||||||
type FastifyZodProvider = FastifyInstance<
|
type FastifyZodProvider = FastifyInstance<
|
||||||
@@ -15,6 +15,6 @@ declare global {
|
|||||||
|
|
||||||
// used only for testing
|
// used only for testing
|
||||||
const testServer: FastifyZodProvider;
|
const testServer: FastifyZodProvider;
|
||||||
const testCryptoProvider: TCryptographyFactory;
|
const testSuperAdminDAL: TSuperAdminDALFactory;
|
||||||
const jwtAuthToken: string;
|
const jwtAuthToken: string;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,11 +3,12 @@ import { Knex } from "knex";
|
|||||||
|
|
||||||
import { chunkArray } from "@app/lib/fn";
|
import { chunkArray } from "@app/lib/fn";
|
||||||
import { selectAllTableCols } from "@app/lib/knex";
|
import { selectAllTableCols } from "@app/lib/knex";
|
||||||
import { logger } from "@app/lib/logger";
|
import { initLogger, logger } from "@app/lib/logger";
|
||||||
|
|
||||||
import { SecretType, TableName } from "../schemas";
|
import { SecretType, TableName } from "../schemas";
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
initLogger();
|
||||||
logger.info("Starting secret version fix migration");
|
logger.info("Starting secret version fix migration");
|
||||||
|
|
||||||
// Get all shared secret IDs first to optimize versions query
|
// Get all shared secret IDs first to optimize versions query
|
||||||
@@ -133,6 +134,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export async function down(): Promise<void> {
|
export async function down(): Promise<void> {
|
||||||
|
initLogger();
|
||||||
logger.info("Rollback not implemented for secret version fix migration");
|
logger.info("Rollback not implemented for secret version fix migration");
|
||||||
// Note: Rolling back this migration would be complex and potentially destructive
|
// Note: Rolling back this migration would be complex and potentially destructive
|
||||||
// as it would require tracking which version entries were added
|
// as it would require tracking which version entries were added
|
||||||
|
|||||||
@@ -348,7 +348,6 @@ export const computeMd5 = (message: string, digest: DigestType = DigestType.Hex)
|
|||||||
};
|
};
|
||||||
|
|
||||||
const cryptographyFactory = () => {
|
const cryptographyFactory = () => {
|
||||||
// placeholder for now
|
|
||||||
let $fipsEnabled = false;
|
let $fipsEnabled = false;
|
||||||
let $isInitialized = false;
|
let $isInitialized = false;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user