mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 12:29:26 +00:00
misc: addressed comments
This commit is contained in:
@@ -4,6 +4,7 @@ import { getConfig } from "@app/lib/config/env";
|
||||
import { crypto } from "@app/lib/crypto/cryptography";
|
||||
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||
import { writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
|
||||
@@ -19,7 +20,7 @@ export const registerRelayRouter = async (server: FastifyZodProvider) => {
|
||||
schema: {
|
||||
body: z.object({
|
||||
host: z.string(),
|
||||
name: z.string()
|
||||
name: slugSchema({ min: 1, max: 32, field: "name" })
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -69,7 +70,7 @@ export const registerRelayRouter = async (server: FastifyZodProvider) => {
|
||||
schema: {
|
||||
body: z.object({
|
||||
host: z.string(),
|
||||
name: z.string()
|
||||
name: slugSchema({ min: 1, max: 32, field: "name" })
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
|
||||
@@ -2,6 +2,7 @@ import z from "zod";
|
||||
|
||||
import { GatewaysV2Schema } from "@app/db/schemas";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
|
||||
@@ -20,8 +21,8 @@ export const registerGatewayV2Router = async (server: FastifyZodProvider) => {
|
||||
url: "/",
|
||||
schema: {
|
||||
body: z.object({
|
||||
relayName: z.string(),
|
||||
name: z.string()
|
||||
relayName: slugSchema({ min: 1, max: 32, field: "relayName" }),
|
||||
name: slugSchema({ min: 1, max: 32, field: "name" })
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
import { Knex } from "knex";
|
||||
|
||||
import { TDbClient } from "@app/db";
|
||||
import { GatewaysV2Schema, TableName, TGatewaysV2 } from "@app/db/schemas";
|
||||
import { DatabaseError } from "@app/lib/errors";
|
||||
@@ -10,7 +12,7 @@ export const gatewayV2DalFactory = (db: TDbClient) => {
|
||||
|
||||
const find = async (filter: TFindFilter<TGatewaysV2>, { offset, limit, sort, tx }: TFindOpt<TGatewaysV2> = {}) => {
|
||||
try {
|
||||
const query = (tx || db)(TableName.GatewayV2)
|
||||
const query = (tx || db.replicaNode())(TableName.GatewayV2)
|
||||
// eslint-disable-next-line @typescript-eslint/no-misused-promises
|
||||
.where(buildFindFilter(filter, TableName.GatewayV2))
|
||||
.join(TableName.Identity, `${TableName.Identity}.id`, `${TableName.GatewayV2}.identityId`)
|
||||
@@ -39,5 +41,20 @@ export const gatewayV2DalFactory = (db: TDbClient) => {
|
||||
}
|
||||
};
|
||||
|
||||
return { ...orm, find };
|
||||
const findById = async (id: string, tx?: Knex) => {
|
||||
try {
|
||||
const doc = await (tx || db.replicaNode())(TableName.GatewayV2)
|
||||
.join(TableName.Organization, `${TableName.GatewayV2}.orgId`, `${TableName.Organization}.id`)
|
||||
.where(`${TableName.GatewayV2}.id`, id)
|
||||
.select(selectAllTableCols(TableName.GatewayV2))
|
||||
.select(db.ref("name").withSchema(TableName.Organization).as("orgName"))
|
||||
.first();
|
||||
|
||||
return doc;
|
||||
} catch (error) {
|
||||
throw new DatabaseError({ error, name: `${TableName.GatewayV2}: Find by id` });
|
||||
}
|
||||
};
|
||||
|
||||
return { ...orm, find, findById };
|
||||
};
|
||||
|
||||
@@ -394,6 +394,7 @@ export const gatewayV2ServiceFactory = ({
|
||||
const relayCredentials = await relayService.getCredentialsForClient({
|
||||
relayId: gateway.relayId,
|
||||
orgId: gateway.orgId,
|
||||
orgName: gateway.orgName,
|
||||
gatewayId
|
||||
});
|
||||
|
||||
|
||||
@@ -13,6 +13,7 @@ import {
|
||||
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||
import { KmsDataKey } from "@app/services/kms/kms-types";
|
||||
|
||||
import { verifyHostInputValidity } from "../dynamic-secret/dynamic-secret-fns";
|
||||
import { createSshCert, createSshKeyPair } from "../ssh/ssh-certificate-authority-fns";
|
||||
import { SshCertType } from "../ssh/ssh-certificate-authority-types";
|
||||
import { SshCertKeyAlgorithm } from "../ssh-certificate/ssh-certificate-types";
|
||||
@@ -689,6 +690,7 @@ export const relayServiceFactory = ({
|
||||
const $generateRelayClientCredentials = async ({
|
||||
gatewayId,
|
||||
orgId,
|
||||
orgName,
|
||||
relayPkiClientCaCertificate,
|
||||
relayPkiClientCaPrivateKey,
|
||||
relayPkiServerCaCertificate,
|
||||
@@ -696,6 +698,7 @@ export const relayServiceFactory = ({
|
||||
}: {
|
||||
gatewayId: string;
|
||||
orgId: string;
|
||||
orgName: string;
|
||||
relayPkiClientCaCertificate: Buffer;
|
||||
relayPkiClientCaPrivateKey: Buffer;
|
||||
relayPkiServerCaCertificate: Buffer;
|
||||
@@ -742,7 +745,7 @@ export const relayServiceFactory = ({
|
||||
|
||||
const clientCert = await x509.X509CertificateGenerator.create({
|
||||
serialNumber: clientCertSerialNumber,
|
||||
subject: `O=${orgId},OU=relay-client,CN=${gatewayId}`,
|
||||
subject: `O=${orgName}-${orgId},OU=relay-client,CN=${gatewayId}`,
|
||||
issuer: relayClientCaCert.subject,
|
||||
notAfter: clientCertExpiration,
|
||||
notBefore: clientCertIssuedAt,
|
||||
@@ -833,10 +836,12 @@ export const relayServiceFactory = ({
|
||||
const getCredentialsForClient = async ({
|
||||
relayId,
|
||||
orgId,
|
||||
orgName,
|
||||
gatewayId
|
||||
}: {
|
||||
relayId: string;
|
||||
orgId: string;
|
||||
orgName: string;
|
||||
gatewayId: string;
|
||||
}) => {
|
||||
const relay = await relayDAL.findOne({
|
||||
@@ -849,11 +854,14 @@ export const relayServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
await verifyHostInputValidity(relay.host);
|
||||
|
||||
if (relay.orgId === null) {
|
||||
const instanceCAs = await $getInstanceCAs();
|
||||
const relayCertificateCredentials = await $generateRelayClientCredentials({
|
||||
gatewayId,
|
||||
orgId,
|
||||
orgName,
|
||||
relayPkiClientCaCertificate: instanceCAs.instanceRelayPkiClientCaCertificate,
|
||||
relayPkiClientCaPrivateKey: instanceCAs.instanceRelayPkiClientCaPrivateKey,
|
||||
relayPkiServerCaCertificate: instanceCAs.instanceRelayPkiServerCaCertificate,
|
||||
@@ -870,6 +878,7 @@ export const relayServiceFactory = ({
|
||||
const relayCertificateCredentials = await $generateRelayClientCredentials({
|
||||
gatewayId,
|
||||
orgId,
|
||||
orgName,
|
||||
relayPkiClientCaCertificate: orgCAs.relayPkiClientCaCertificate,
|
||||
relayPkiClientCaPrivateKey: orgCAs.relayPkiClientCaPrivateKey,
|
||||
relayPkiServerCaCertificate: orgCAs.relayPkiServerCaCertificate,
|
||||
@@ -896,6 +905,8 @@ export const relayServiceFactory = ({
|
||||
let relay: TRelays;
|
||||
const isOrgRelay = identityId && orgId;
|
||||
|
||||
await verifyHostInputValidity(host);
|
||||
|
||||
if (isOrgRelay) {
|
||||
relay = await relayDAL.transaction(async (tx) => {
|
||||
const existingRelay = await relayDAL.findOne(
|
||||
@@ -907,9 +918,7 @@ export const relayServiceFactory = ({
|
||||
);
|
||||
|
||||
if (existingRelay && (existingRelay.host !== host || existingRelay.name !== name)) {
|
||||
throw new BadRequestError({
|
||||
message: "Org relay with this machine identity already exists."
|
||||
});
|
||||
return relayDAL.updateById(existingRelay.id, { host, name }, tx);
|
||||
}
|
||||
|
||||
if (!existingRelay) {
|
||||
@@ -937,9 +946,7 @@ export const relayServiceFactory = ({
|
||||
);
|
||||
|
||||
if (existingRelay && existingRelay.host !== host) {
|
||||
throw new BadRequestError({
|
||||
message: "Instance relay with this name already exists with a different host"
|
||||
});
|
||||
return relayDAL.updateById(existingRelay.id, { host }, tx);
|
||||
}
|
||||
|
||||
if (!existingRelay) {
|
||||
|
||||
Reference in New Issue
Block a user