mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Add option to attach accessId onto integration auth middleware
This commit is contained in:
@@ -151,6 +151,7 @@ export const getIntegrationAuthApps = async (req: Request, res: Response) => {
|
|||||||
const apps = await getApps({
|
const apps = await getApps({
|
||||||
integrationAuth: req.integrationAuth,
|
integrationAuth: req.integrationAuth,
|
||||||
accessToken: req.accessToken,
|
accessToken: req.accessToken,
|
||||||
|
accessId: req.accessId,
|
||||||
...teamId && { teamId }
|
...teamId && { teamId }
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -48,10 +48,12 @@ interface App {
|
|||||||
const getApps = async ({
|
const getApps = async ({
|
||||||
integrationAuth,
|
integrationAuth,
|
||||||
accessToken,
|
accessToken,
|
||||||
|
accessId,
|
||||||
teamId,
|
teamId,
|
||||||
}: {
|
}: {
|
||||||
integrationAuth: IIntegrationAuth;
|
integrationAuth: IIntegrationAuth;
|
||||||
accessToken: string;
|
accessToken: string;
|
||||||
|
accessId?: string;
|
||||||
teamId?: string;
|
teamId?: string;
|
||||||
}) => {
|
}) => {
|
||||||
let apps: App[] = [];
|
let apps: App[] = [];
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ const requireIntegrationAuthorizationAuth = ({
|
|||||||
return async (req: Request, res: Response, next: NextFunction) => {
|
return async (req: Request, res: Response, next: NextFunction) => {
|
||||||
const { integrationAuthId } = req[location];
|
const { integrationAuthId } = req[location];
|
||||||
|
|
||||||
const { integrationAuth, accessToken } = await validateClientForIntegrationAuth({
|
const { integrationAuth, accessToken, accessId } = await validateClientForIntegrationAuth({
|
||||||
authData: req.authData,
|
authData: req.authData,
|
||||||
integrationAuthId: new Types.ObjectId(integrationAuthId),
|
integrationAuthId: new Types.ObjectId(integrationAuthId),
|
||||||
acceptedRoles,
|
acceptedRoles,
|
||||||
@@ -38,6 +38,10 @@ const requireIntegrationAuthorizationAuth = ({
|
|||||||
req.accessToken = accessToken;
|
req.accessToken = accessToken;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (accessId) {
|
||||||
|
req.accessId = accessId;
|
||||||
|
}
|
||||||
|
|
||||||
return next();
|
return next();
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
1
backend/src/types/express/index.d.ts
vendored
1
backend/src/types/express/index.d.ts
vendored
@@ -37,6 +37,7 @@ declare global {
|
|||||||
serviceToken: any;
|
serviceToken: any;
|
||||||
serviceAccount: any;
|
serviceAccount: any;
|
||||||
accessToken: any;
|
accessToken: any;
|
||||||
|
accessId: any;
|
||||||
serviceTokenData: any;
|
serviceTokenData: any;
|
||||||
apiKeyData: any;
|
apiKeyData: any;
|
||||||
query?: any;
|
query?: any;
|
||||||
|
|||||||
@@ -56,11 +56,14 @@ import { validateServiceAccountClientForWorkspace } from './serviceAccount';
|
|||||||
|
|
||||||
if (!integrationAuth) throw IntegrationAuthNotFoundError();
|
if (!integrationAuth) throw IntegrationAuthNotFoundError();
|
||||||
|
|
||||||
let accessToken;
|
let accessToken, accessId;
|
||||||
if (attachAccessToken) {
|
if (attachAccessToken) {
|
||||||
accessToken = (await IntegrationService.getIntegrationAuthAccess({
|
const access = (await IntegrationService.getIntegrationAuthAccess({
|
||||||
integrationAuthId: integrationAuth._id
|
integrationAuthId: integrationAuth._id
|
||||||
})).accessToken;
|
}));
|
||||||
|
|
||||||
|
accessToken = access.accessToken;
|
||||||
|
accessId = access.accessId;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (authData.authMode === AUTH_MODE_JWT && authData.authPayload instanceof User) {
|
if (authData.authMode === AUTH_MODE_JWT && authData.authPayload instanceof User) {
|
||||||
@@ -70,7 +73,7 @@ import { validateServiceAccountClientForWorkspace } from './serviceAccount';
|
|||||||
acceptedRoles
|
acceptedRoles
|
||||||
});
|
});
|
||||||
|
|
||||||
return ({ integrationAuth, accessToken });
|
return ({ integrationAuth, accessToken, accessId });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (authData.authMode === AUTH_MODE_SERVICE_ACCOUNT && authData.authPayload instanceof ServiceAccount) {
|
if (authData.authMode === AUTH_MODE_SERVICE_ACCOUNT && authData.authPayload instanceof ServiceAccount) {
|
||||||
@@ -79,7 +82,7 @@ import { validateServiceAccountClientForWorkspace } from './serviceAccount';
|
|||||||
workspaceId: integrationAuth.workspace._id
|
workspaceId: integrationAuth.workspace._id
|
||||||
});
|
});
|
||||||
|
|
||||||
return ({ integrationAuth, accessToken });
|
return ({ integrationAuth, accessToken, accessId });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (authData.authMode === AUTH_MODE_SERVICE_TOKEN && authData.authPayload instanceof ServiceTokenData) {
|
if (authData.authMode === AUTH_MODE_SERVICE_TOKEN && authData.authPayload instanceof ServiceTokenData) {
|
||||||
@@ -95,7 +98,7 @@ import { validateServiceAccountClientForWorkspace } from './serviceAccount';
|
|||||||
acceptedRoles
|
acceptedRoles
|
||||||
});
|
});
|
||||||
|
|
||||||
return ({ integrationAuth, accessToken });
|
return ({ integrationAuth, accessToken, accessId });
|
||||||
}
|
}
|
||||||
|
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
|
|||||||
Reference in New Issue
Block a user