Merge pull request #2792 from Infisical/daniel/dynamic-secret-renewals

fix(dynamic-secrets): renewal 500 error
This commit is contained in:
Daniel Hougaard
2024-11-26 01:52:28 +04:00
committed by GitHub
13 changed files with 44 additions and 33 deletions
@@ -212,7 +212,7 @@ export const AwsElastiCacheDatabaseProvider = (): TDynamicProviderFns => {
}; };
const renew = async (inputs: unknown, entityId: string) => { const renew = async (inputs: unknown, entityId: string) => {
// Do nothing // No renewal necessary
return { entityId }; return { entityId };
}; };
@@ -179,9 +179,8 @@ export const AwsIamProvider = (): TDynamicProviderFns => {
}; };
const renew = async (_inputs: unknown, entityId: string) => { const renew = async (_inputs: unknown, entityId: string) => {
// do nothing // No renewal necessary
const username = entityId; return { entityId };
return { entityId: username };
}; };
return { return {
@@ -55,11 +55,6 @@ export const AzureEntraIDProvider = (): TDynamicProviderFns & {
return data.success; return data.success;
}; };
const renew = async (inputs: unknown, entityId: string) => {
// Do nothing
return { entityId };
};
const create = async (inputs: unknown) => { const create = async (inputs: unknown) => {
const providerInputs = await validateProviderInputs(inputs); const providerInputs = await validateProviderInputs(inputs);
const data = await getToken(providerInputs.tenantId, providerInputs.applicationId, providerInputs.clientSecret); const data = await getToken(providerInputs.tenantId, providerInputs.applicationId, providerInputs.clientSecret);
@@ -127,6 +122,11 @@ export const AzureEntraIDProvider = (): TDynamicProviderFns & {
return users; return users;
}; };
const renew = async (inputs: unknown, entityId: string) => {
// No renewal necessary
return { entityId };
};
return { return {
validateProviderInputs, validateProviderInputs,
validateConnection, validateConnection,
@@ -99,20 +99,24 @@ export const CassandraProvider = (): TDynamicProviderFns => {
const renew = async (inputs: unknown, entityId: string, expireAt: number) => { const renew = async (inputs: unknown, entityId: string, expireAt: number) => {
const providerInputs = await validateProviderInputs(inputs); const providerInputs = await validateProviderInputs(inputs);
if (!providerInputs.renewStatement) return { entityId };
const client = await getClient(providerInputs); const client = await getClient(providerInputs);
const username = entityId;
const expiration = new Date(expireAt).toISOString(); const expiration = new Date(expireAt).toISOString();
const { keyspace } = providerInputs; const { keyspace } = providerInputs;
const renewStatement = handlebars.compile(providerInputs.revocationStatement)({ username, keyspace, expiration }); const renewStatement = handlebars.compile(providerInputs.renewStatement)({
username: entityId,
keyspace,
expiration
});
const queries = renewStatement.toString().split(";").filter(Boolean); const queries = renewStatement.toString().split(";").filter(Boolean);
for (const query of queries) { for await (const query of queries) {
// eslint-disable-next-line
await client.execute(query); await client.execute(query);
} }
await client.shutdown(); await client.shutdown();
return { entityId: username }; return { entityId };
}; };
return { return {
@@ -96,7 +96,7 @@ export const ElasticSearchProvider = (): TDynamicProviderFns => {
}; };
const renew = async (inputs: unknown, entityId: string) => { const renew = async (inputs: unknown, entityId: string) => {
// Do nothing // No renewal necessary
return { entityId }; return { entityId };
}; };
@@ -268,7 +268,7 @@ export const LdapProvider = (): TDynamicProviderFns => {
}; };
const renew = async (inputs: unknown, entityId: string) => { const renew = async (inputs: unknown, entityId: string) => {
// Do nothing // No renewal necessary
return { entityId }; return { entityId };
}; };
@@ -88,6 +88,7 @@ export const MongoDBProvider = (): TDynamicProviderFns => {
}; };
const renew = async (_inputs: unknown, entityId: string) => { const renew = async (_inputs: unknown, entityId: string) => {
// No renewal necessary
return { entityId }; return { entityId };
}; };
@@ -142,7 +142,7 @@ export const RabbitMqProvider = (): TDynamicProviderFns => {
}; };
const renew = async (inputs: unknown, entityId: string) => { const renew = async (inputs: unknown, entityId: string) => {
// Do nothing // No renewal necessary
return { entityId }; return { entityId };
}; };
@@ -141,6 +141,8 @@ export const RedisDatabaseProvider = (): TDynamicProviderFns => {
const renew = async (inputs: unknown, entityId: string, expireAt: number) => { const renew = async (inputs: unknown, entityId: string, expireAt: number) => {
const providerInputs = await validateProviderInputs(inputs); const providerInputs = await validateProviderInputs(inputs);
if (!providerInputs.renewStatement) return { entityId };
const connection = await getClient(providerInputs); const connection = await getClient(providerInputs);
const username = entityId; const username = entityId;
@@ -135,13 +135,15 @@ export const SapHanaProvider = (): TDynamicProviderFns => {
return { entityId: username }; return { entityId: username };
}; };
const renew = async (inputs: unknown, username: string, expireAt: number) => { const renew = async (inputs: unknown, entityId: string, expireAt: number) => {
const providerInputs = await validateProviderInputs(inputs); const providerInputs = await validateProviderInputs(inputs);
if (!providerInputs.renewStatement) return { entityId };
const client = await getClient(providerInputs); const client = await getClient(providerInputs);
try { try {
const expiration = new Date(expireAt).toISOString(); const expiration = new Date(expireAt).toISOString();
const renewStatement = handlebars.compile(providerInputs.renewStatement)({ username, expiration }); const renewStatement = handlebars.compile(providerInputs.renewStatement)({ username: entityId, expiration });
const queries = renewStatement.toString().split(";").filter(Boolean); const queries = renewStatement.toString().split(";").filter(Boolean);
for await (const query of queries) { for await (const query of queries) {
await new Promise((resolve, reject) => { await new Promise((resolve, reject) => {
@@ -161,7 +163,7 @@ export const SapHanaProvider = (): TDynamicProviderFns => {
client.disconnect(); client.disconnect();
} }
return { entityId: username }; return { entityId };
}; };
return { return {
@@ -131,17 +131,16 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
return { entityId: username }; return { entityId: username };
}; };
const renew = async (inputs: unknown, username: string, expireAt: number) => { const renew = async (inputs: unknown, entityId: string, expireAt: number) => {
const providerInputs = await validateProviderInputs(inputs); const providerInputs = await validateProviderInputs(inputs);
if (!providerInputs.renewStatement) return { entityId };
if (!providerInputs.renewStatement) return { entityId: username };
const client = await getClient(providerInputs); const client = await getClient(providerInputs);
try { try {
const expiration = getDaysToExpiry(new Date(expireAt)); const expiration = getDaysToExpiry(new Date(expireAt));
const renewStatement = handlebars.compile(providerInputs.renewStatement)({ const renewStatement = handlebars.compile(providerInputs.renewStatement)({
username, username: entityId,
expiration expiration
}); });
@@ -161,7 +160,7 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
client.destroy(noop); client.destroy(noop);
} }
return { entityId: username }; return { entityId };
}; };
return { return {
@@ -110,13 +110,19 @@ export const SqlDatabaseProvider = (): TDynamicProviderFns => {
const renew = async (inputs: unknown, entityId: string, expireAt: number) => { const renew = async (inputs: unknown, entityId: string, expireAt: number) => {
const providerInputs = await validateProviderInputs(inputs); const providerInputs = await validateProviderInputs(inputs);
if (!providerInputs.renewStatement) return { entityId };
const db = await getClient(providerInputs); const db = await getClient(providerInputs);
const username = entityId;
const expiration = new Date(expireAt).toISOString(); const expiration = new Date(expireAt).toISOString();
const { database } = providerInputs; const { database } = providerInputs;
const renewStatement = handlebars.compile(providerInputs.renewStatement)({ username, expiration, database }); const renewStatement = handlebars.compile(providerInputs.renewStatement)({
username: entityId,
expiration,
database
});
if (renewStatement) { if (renewStatement) {
const queries = renewStatement.toString().split(";").filter(Boolean); const queries = renewStatement.toString().split(";").filter(Boolean);
await db.transaction(async (tx) => { await db.transaction(async (tx) => {
@@ -128,7 +134,7 @@ export const SqlDatabaseProvider = (): TDynamicProviderFns => {
} }
await db.destroy(); await db.destroy();
return { entityId: username }; return { entityId };
}; };
return { return {
@@ -1,7 +1,6 @@
import { authenticator } from "otplib"; import { authenticator } from "otplib";
import { HashAlgorithms } from "otplib/core"; import { HashAlgorithms } from "otplib/core";
import { BadRequestError } from "@app/lib/errors";
import { alphaNumericNanoId } from "@app/lib/nanoid"; import { alphaNumericNanoId } from "@app/lib/nanoid";
import { DynamicSecretTotpSchema, TDynamicProviderFns, TotpConfigType } from "./models"; import { DynamicSecretTotpSchema, TDynamicProviderFns, TotpConfigType } from "./models";
@@ -76,10 +75,9 @@ export const TotpProvider = (): TDynamicProviderFns => {
}; };
// eslint-disable-next-line @typescript-eslint/no-unused-vars // eslint-disable-next-line @typescript-eslint/no-unused-vars
const renew = async (_inputs: unknown, _entityId: string) => { const renew = async (_inputs: unknown, entityId: string) => {
throw new BadRequestError({ // No renewal necessary
message: "Lease renewal is not supported for TOTPs" return { entityId };
});
}; };
return { return {