improvements: address feedback, feature docs and cert validation with dns rebinding handling

This commit is contained in:
Scott Wilson
2025-04-03 21:17:04 -07:00
parent 577c81be65
commit 715441908b
24 changed files with 708 additions and 306 deletions
@@ -153,6 +153,12 @@ export const secretRotationV2ServiceFactory = ({
tx: Knex;
secretPath: string;
}) => {
if (new Set(secretKeys).size !== secretKeys.length) {
throw new BadRequestError({
message: `Secrets mapping keys must be unique. "${secretKeys.join(", ")}" contains duplicate keys.`
});
}
const conflictingSecrets = await secretV2BridgeDAL.find(
{
$in: {
+1
View File
@@ -59,6 +59,7 @@ const envSchema = z
QUEUE_WORKERS_ENABLED: zodStrBool.default("true"),
HTTPS_ENABLED: zodStrBool,
ROTATION_DEVELOPMENT_MODE: zodStrBool.default("false").optional(),
DB_SSL_REJECT_UNAUTHORIZED: zodStrBool.default("true"),
// smtp options
SMTP_HOST: zpStr(z.string().optional()),
SMTP_IGNORE_TLS: zodStrBool.default("false"),
@@ -5,6 +5,7 @@ import {
TSqlCredentialsRotationGeneratedCredentials,
TSqlCredentialsRotationWithConnection
} from "@app/ee/services/secret-rotation-v2/shared/sql-credentials/sql-credentials-rotation-types";
import { getConfig } from "@app/lib/config/env";
import { BadRequestError, DatabaseError } from "@app/lib/errors";
import { alphaNumericNanoId } from "@app/lib/nanoid";
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
@@ -19,12 +20,16 @@ const SQL_CONNECTION_CLIENT_MAP = {
};
export const getSqlConnectionClient = async (appConnection: Pick<TSqlConnection, "credentials" | "app">) => {
const appCfg = getConfig();
const {
app,
credentials: { host: baseHost, database, port, sslCertificate, password, username }
} = appConnection;
const ssl = sslCertificate ? { rejectUnauthorized: false, ca: sslCertificate } : undefined;
const ssl = sslCertificate
? { rejectUnauthorized: appCfg.DB_SSL_REJECT_UNAUTHORIZED, ca: sslCertificate, servername: baseHost }
: undefined;
const [host] = await verifyHostInputValidity(baseHost);
@@ -43,7 +48,7 @@ export const getSqlConnectionClient = async (appConnection: Pick<TSqlConnection,
options:
app === AppConnection.MsSql
? {
trustServerCertificate: !sslCertificate,
trustServerCertificate: !appCfg.DB_SSL_REJECT_UNAUTHORIZED,
cryptoCredentialsDetails: sslCertificate ? { ca: sslCertificate } : {}
}
: undefined