diff --git a/backend/src/db/migrations/20250430174352_email-case-change.ts b/backend/src/db/migrations/20250430174352_email-case-change.ts new file mode 100644 index 000000000..d6b9b3980 --- /dev/null +++ b/backend/src/db/migrations/20250430174352_email-case-change.ts @@ -0,0 +1,47 @@ +import { Knex } from "knex"; + +import { TableName } from "../schemas"; + +export async function up(knex: Knex): Promise { + const hasEmail = await knex.schema.hasColumn(TableName.Users, "email"); + const hasUsername = await knex.schema.hasColumn(TableName.Users, "username"); + if (hasEmail) { + await knex(TableName.Users) + .where({ isGhost: false }) + .update({ + // @ts-expect-error email assume string this is expected + email: knex.raw("lower(email)") + }); + } + if (hasUsername) { + await knex.schema.raw(` + CREATE INDEX IF NOT EXISTS ${TableName.Users}_lower_username_idx + ON ${TableName.Users} (LOWER(username)) + `); + + const duplicatesSubquery = knex(TableName.Users) + .select(knex.raw("lower(username) as lowercase_username")) + .groupBy("lowercase_username") + .having(knex.raw("count(*)"), ">", 1); + + // Update usernames to lowercase where they won't create duplicates + await knex(TableName.Users) + .where({ isGhost: false }) + .whereRaw("username <> lower(username)") // Only update if not already lowercase + // @ts-expect-error username assume string this is expected + .whereNotIn(knex.raw("lower(username)"), duplicatesSubquery) + .update({ + // @ts-expect-error username assume string this is expected + username: knex.raw("lower(username)") + }); + } +} + +export async function down(knex: Knex): Promise { + const hasUsername = await knex.schema.hasColumn(TableName.Users, "username"); + if (hasUsername) { + await knex.schema.raw(` + DROP INDEX IF EXISTS ${TableName.Users}_lower_username_idx +`); + } +} diff --git a/backend/src/db/migrations/20250516192508_secret-sharing-limits-for-org.ts b/backend/src/db/migrations/20250516192508_secret-sharing-limits-for-org.ts new file mode 100644 index 000000000..f68c1c29b --- /dev/null +++ b/backend/src/db/migrations/20250516192508_secret-sharing-limits-for-org.ts @@ -0,0 +1,35 @@ +import { Knex } from "knex"; + +import { TableName } from "../schemas"; + +export async function up(knex: Knex): Promise { + const hasLifetimeColumn = await knex.schema.hasColumn(TableName.Organization, "maxSharedSecretLifetime"); + const hasViewLimitColumn = await knex.schema.hasColumn(TableName.Organization, "maxSharedSecretViewLimit"); + + if (!hasLifetimeColumn || !hasViewLimitColumn) { + await knex.schema.alterTable(TableName.Organization, (t) => { + if (!hasLifetimeColumn) { + t.integer("maxSharedSecretLifetime").nullable().defaultTo(2592000); // 30 days in seconds + } + if (!hasViewLimitColumn) { + t.integer("maxSharedSecretViewLimit").nullable(); + } + }); + } +} + +export async function down(knex: Knex): Promise { + const hasLifetimeColumn = await knex.schema.hasColumn(TableName.Organization, "maxSharedSecretLifetime"); + const hasViewLimitColumn = await knex.schema.hasColumn(TableName.Organization, "maxSharedSecretViewLimit"); + + if (hasLifetimeColumn || hasViewLimitColumn) { + await knex.schema.alterTable(TableName.Organization, (t) => { + if (hasLifetimeColumn) { + t.dropColumn("maxSharedSecretLifetime"); + } + if (hasViewLimitColumn) { + t.dropColumn("maxSharedSecretViewLimit"); + } + }); + } +} diff --git a/backend/src/db/migrations/20250517002223_secret-share-to-specific-emails.ts b/backend/src/db/migrations/20250517002223_secret-share-to-specific-emails.ts new file mode 100644 index 000000000..6a02ae4eb --- /dev/null +++ b/backend/src/db/migrations/20250517002223_secret-share-to-specific-emails.ts @@ -0,0 +1,43 @@ +import { Knex } from "knex"; + +import { TableName } from "../schemas"; + +export async function up(knex: Knex): Promise { + if (await knex.schema.hasTable(TableName.SecretSharing)) { + const hasEncryptedSalt = await knex.schema.hasColumn(TableName.SecretSharing, "encryptedSalt"); + const hasAuthorizedEmails = await knex.schema.hasColumn(TableName.SecretSharing, "authorizedEmails"); + + if (!hasEncryptedSalt || !hasAuthorizedEmails) { + await knex.schema.alterTable(TableName.SecretSharing, (t) => { + // These two columns are only needed when secrets are shared with a specific list of emails + + if (!hasEncryptedSalt) { + t.binary("encryptedSalt").nullable(); + } + + if (!hasAuthorizedEmails) { + t.json("authorizedEmails").nullable(); + } + }); + } + } +} + +export async function down(knex: Knex): Promise { + if (await knex.schema.hasTable(TableName.SecretSharing)) { + const hasEncryptedSalt = await knex.schema.hasColumn(TableName.SecretSharing, "encryptedSalt"); + const hasAuthorizedEmails = await knex.schema.hasColumn(TableName.SecretSharing, "authorizedEmails"); + + if (hasEncryptedSalt || hasAuthorizedEmails) { + await knex.schema.alterTable(TableName.SecretSharing, (t) => { + if (hasEncryptedSalt) { + t.dropColumn("encryptedSalt"); + } + + if (hasAuthorizedEmails) { + t.dropColumn("authorizedEmails"); + } + }); + } + } +} diff --git a/backend/src/db/schemas/organizations.ts b/backend/src/db/schemas/organizations.ts index 6779d5407..fb0728707 100644 --- a/backend/src/db/schemas/organizations.ts +++ b/backend/src/db/schemas/organizations.ts @@ -34,7 +34,9 @@ export const OrganizationsSchema = z.object({ kmsProductEnabled: z.boolean().default(true).nullable().optional(), sshProductEnabled: z.boolean().default(true).nullable().optional(), scannerProductEnabled: z.boolean().default(true).nullable().optional(), - shareSecretsProductEnabled: z.boolean().default(true).nullable().optional() + shareSecretsProductEnabled: z.boolean().default(true).nullable().optional(), + maxSharedSecretLifetime: z.number().default(2592000).nullable().optional(), + maxSharedSecretViewLimit: z.number().nullable().optional() }); export type TOrganizations = z.infer; diff --git a/backend/src/db/schemas/secret-sharing.ts b/backend/src/db/schemas/secret-sharing.ts index 24ea26677..7de34708c 100644 --- a/backend/src/db/schemas/secret-sharing.ts +++ b/backend/src/db/schemas/secret-sharing.ts @@ -27,7 +27,9 @@ export const SecretSharingSchema = z.object({ password: z.string().nullable().optional(), encryptedSecret: zodBuffer.nullable().optional(), identifier: z.string().nullable().optional(), - type: z.string().default("share") + type: z.string().default("share"), + encryptedSalt: zodBuffer.nullable().optional(), + authorizedEmails: z.unknown().nullable().optional() }); export type TSecretSharing = z.infer; diff --git a/backend/src/ee/routes/v1/saml-router.ts b/backend/src/ee/routes/v1/saml-router.ts index 8648ade7c..c8395d608 100644 --- a/backend/src/ee/routes/v1/saml-router.ts +++ b/backend/src/ee/routes/v1/saml-router.ts @@ -145,7 +145,7 @@ export const registerSamlRouter = async (server: FastifyZodProvider) => { const { isUserCompleted, providerAuthToken } = await server.services.saml.samlLogin({ externalId: profile.nameID, - email, + email: email.toLowerCase(), firstName, lastName: lastName as string, relayState: (req.body as { RelayState?: string }).RelayState, diff --git a/backend/src/ee/services/group/group-dal.ts b/backend/src/ee/services/group/group-dal.ts index 1d33cafd6..801f52fc0 100644 --- a/backend/src/ee/services/group/group-dal.ts +++ b/backend/src/ee/services/group/group-dal.ts @@ -111,9 +111,9 @@ export const groupDALFactory = (db: TDbClient) => { } if (search) { - void query.andWhereRaw(`CONCAT_WS(' ', "firstName", "lastName", "username") ilike ?`, [`%${search}%`]); + void query.andWhereRaw(`CONCAT_WS(' ', "firstName", "lastName", lower("username")) ilike ?`, [`%${search}%`]); } else if (username) { - void query.andWhere(`${TableName.Users}.username`, "ilike", `%${username}%`); + void query.andWhereRaw(`lower("${TableName.Users}"."username") ilike ?`, `%${username}%`); } switch (filter) { diff --git a/backend/src/ee/services/group/group-service.ts b/backend/src/ee/services/group/group-service.ts index b9206771e..cc3125918 100644 --- a/backend/src/ee/services/group/group-service.ts +++ b/backend/src/ee/services/group/group-service.ts @@ -30,7 +30,7 @@ import { import { TUserGroupMembershipDALFactory } from "./user-group-membership-dal"; type TGroupServiceFactoryDep = { - userDAL: Pick; + userDAL: Pick; groupDAL: Pick< TGroupDALFactory, "create" | "findOne" | "update" | "delete" | "findAllGroupPossibleMembers" | "findById" | "transaction" @@ -380,7 +380,10 @@ export const groupServiceFactory = ({ details: { missingPermissions: permissionBoundary.missingPermissions } }); - const user = await userDAL.findOne({ username }); + const usersWithUsername = await userDAL.findUserByUsername(username); + // akhilmhdh: case sensitive email resolution + const user = + usersWithUsername?.length > 1 ? usersWithUsername.find((el) => el.username === username) : usersWithUsername?.[0]; if (!user) throw new NotFoundError({ message: `Failed to find user with username ${username}` }); const users = await addUsersToGroupByUserIds({ @@ -461,7 +464,10 @@ export const groupServiceFactory = ({ details: { missingPermissions: permissionBoundary.missingPermissions } }); - const user = await userDAL.findOne({ username }); + const usersWithUsername = await userDAL.findUserByUsername(username); + // akhilmhdh: case sensitive email resolution + const user = + usersWithUsername?.length > 1 ? usersWithUsername.find((el) => el.username === username) : usersWithUsername?.[0]; if (!user) throw new NotFoundError({ message: `Failed to find user with username ${username}` }); const users = await removeUsersFromGroupByUserIds({ diff --git a/backend/src/ee/services/hsm/hsm-fns.ts b/backend/src/ee/services/hsm/hsm-fns.ts index ef975a371..8eec7ceb7 100644 --- a/backend/src/ee/services/hsm/hsm-fns.ts +++ b/backend/src/ee/services/hsm/hsm-fns.ts @@ -24,9 +24,13 @@ export const initializeHsmModule = (envConfig: Pick response, async (err) => { const originalRequest = (err as AxiosError).config; - + const errStatusCode = Number((err as AxiosError)?.response?.status); + logger.error((err as AxiosError)?.response?.data, "License server call error"); // eslint-disable-next-line - if ((err as AxiosError)?.response?.status === 401 && !(originalRequest as any)._retry) { + if ((errStatusCode === 401 || errStatusCode === 403) && !(originalRequest as any)._retry) { // eslint-disable-next-line (originalRequest as any)._retry = true; // injected diff --git a/backend/src/ee/services/license/license-service.ts b/backend/src/ee/services/license/license-service.ts index cf9818658..f5b1f96ec 100644 --- a/backend/src/ee/services/license/license-service.ts +++ b/backend/src/ee/services/license/license-service.ts @@ -348,8 +348,8 @@ export const licenseServiceFactory = ({ } = await licenseServerCloudApi.request.post( `/api/license-server/v1/customers/${organization.customerId}/billing-details/payment-methods`, { - success_url: `${appCfg.SITE_URL}/dashboard`, - cancel_url: `${appCfg.SITE_URL}/dashboard` + success_url: `${appCfg.SITE_URL}/organization/billing`, + cancel_url: `${appCfg.SITE_URL}/organization/billing` } ); @@ -362,7 +362,7 @@ export const licenseServiceFactory = ({ } = await licenseServerCloudApi.request.post( `/api/license-server/v1/customers/${organization.customerId}/billing-details/billing-portal`, { - return_url: `${appCfg.SITE_URL}/dashboard` + return_url: `${appCfg.SITE_URL}/organization/billing` } ); @@ -379,7 +379,7 @@ export const licenseServiceFactory = ({ message: `Organization with ID '${orgId}' not found` }); } - if (instanceType !== InstanceType.OnPrem && instanceType !== InstanceType.EnterpriseOnPremOffline) { + if (instanceType === InstanceType.Cloud) { const { data } = await licenseServerCloudApi.request.get( `/api/license-server/v1/customers/${organization.customerId}/cloud-plan/billing` ); @@ -407,11 +407,38 @@ export const licenseServiceFactory = ({ message: `Organization with ID '${orgId}' not found` }); } - if (instanceType !== InstanceType.OnPrem && instanceType !== InstanceType.EnterpriseOnPremOffline) { - const { data } = await licenseServerCloudApi.request.get( - `/api/license-server/v1/customers/${organization.customerId}/cloud-plan/table` - ); - return data; + + const orgMembersUsed = await orgDAL.countAllOrgMembers(orgId); + const identityUsed = await identityOrgMembershipDAL.countAllOrgIdentities({ orgId }); + const projects = await projectDAL.find({ orgId }); + const projectCount = projects.length; + + if (instanceType === InstanceType.Cloud) { + const { data } = await licenseServerCloudApi.request.get<{ + head: { name: string }[]; + rows: { name: string; allowed: boolean }[]; + }>(`/api/license-server/v1/customers/${organization.customerId}/cloud-plan/table`); + + const formattedData = { + head: data.head, + rows: data.rows.map((el) => { + let used = "-"; + + if (el.name === BillingPlanRows.MemberLimit.name) { + used = orgMembersUsed.toString(); + } else if (el.name === BillingPlanRows.WorkspaceLimit.name) { + used = projectCount.toString(); + } else if (el.name === BillingPlanRows.IdentityLimit.name) { + used = (identityUsed + orgMembersUsed).toString(); + } + + return { + ...el, + used + }; + }) + }; + return formattedData; } const mappedRows = await Promise.all( @@ -420,14 +447,11 @@ export const licenseServiceFactory = ({ let used = "-"; if (field === BillingPlanRows.MemberLimit.field) { - const orgMemberships = await orgDAL.countAllOrgMembers(orgId); - used = orgMemberships.toString(); + used = orgMembersUsed.toString(); } else if (field === BillingPlanRows.WorkspaceLimit.field) { - const projects = await projectDAL.find({ orgId }); - used = projects.length.toString(); + used = projectCount.toString(); } else if (field === BillingPlanRows.IdentityLimit.field) { - const identities = await identityOrgMembershipDAL.countAllOrgIdentities({ orgId }); - used = identities.toString(); + used = identityUsed.toString(); } return { diff --git a/backend/src/ee/services/oidc/oidc-config-service.ts b/backend/src/ee/services/oidc/oidc-config-service.ts index 6accb69e9..d933835e4 100644 --- a/backend/src/ee/services/oidc/oidc-config-service.ts +++ b/backend/src/ee/services/oidc/oidc-config-service.ts @@ -171,8 +171,8 @@ export const oidcConfigServiceFactory = ({ }; const oidcLogin = async ({ - externalId, email, + externalId, firstName, lastName, orgId, @@ -717,7 +717,7 @@ export const oidcConfigServiceFactory = ({ const groups = typeof claims.groups === "string" ? [claims.groups] : (claims.groups as string[] | undefined); oidcLogin({ - email: claims.email, + email: claims.email.toLowerCase(), externalId: claims.sub, firstName: claims.given_name ?? "", lastName: claims.family_name ?? "", diff --git a/backend/src/ee/services/scim/scim-service.ts b/backend/src/ee/services/scim/scim-service.ts index 84cced88f..4aad13ab8 100644 --- a/backend/src/ee/services/scim/scim-service.ts +++ b/backend/src/ee/services/scim/scim-service.ts @@ -342,7 +342,7 @@ export const scimServiceFactory = ({ orgMembership = await orgMembershipDAL.create( { userId: userAlias.userId, - inviteEmail: email, + inviteEmail: email.toLowerCase(), orgId, role, roleId, @@ -364,7 +364,7 @@ export const scimServiceFactory = ({ if (trustScimEmails) { user = await userDAL.findOne( { - email, + email: email.toLowerCase(), isEmailVerified: true }, tx @@ -379,8 +379,8 @@ export const scimServiceFactory = ({ ); user = await userDAL.create( { - username: trustScimEmails ? email : uniqueUsername, - email, + username: trustScimEmails ? email.toLowerCase() : uniqueUsername, + email: email.toLowerCase(), isEmailVerified: trustScimEmails, firstName, lastName, @@ -396,7 +396,7 @@ export const scimServiceFactory = ({ userId: user.id, aliasType, externalId, - emails: email ? [email] : [], + emails: email ? [email.toLowerCase()] : [], orgId }, tx @@ -418,7 +418,7 @@ export const scimServiceFactory = ({ orgMembership = await orgMembershipDAL.create( { userId: user.id, - inviteEmail: email, + inviteEmail: email.toLowerCase(), orgId, role, roleId, @@ -529,7 +529,7 @@ export const scimServiceFactory = ({ membership.userId, { firstName: scimUser.name.givenName, - email: scimUser.emails[0].value, + email: scimUser.emails[0].value.toLowerCase(), lastName: scimUser.name.familyName, isEmailVerified: hasEmailChanged ? trustScimEmails : undefined }, @@ -606,7 +606,7 @@ export const scimServiceFactory = ({ membership.userId, { firstName, - email, + email: email?.toLowerCase(), lastName, isEmailVerified: org.orgAuthMethod === OrgAuthMethod.OIDC ? serverCfg.trustOidcEmails : serverCfg.trustSamlEmails diff --git a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts index 0fd01b753..07cf97a7e 100644 --- a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts +++ b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts @@ -1,4 +1,4 @@ -import ldap from "ldapjs"; +import ldap, { Client, SearchOptions } from "ldapjs"; import { TRotationFactory, @@ -8,26 +8,73 @@ import { TRotationFactoryRotateCredentials } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-types"; import { logger } from "@app/lib/logger"; +import { DistinguishedNameRegex } from "@app/lib/regex"; import { encryptAppConnectionCredentials } from "@app/services/app-connection/app-connection-fns"; import { getLdapConnectionClient, LdapProvider, TLdapConnection } from "@app/services/app-connection/ldap"; import { generatePassword } from "../shared/utils"; import { + LdapPasswordRotationMethod, TLdapPasswordRotationGeneratedCredentials, + TLdapPasswordRotationInput, TLdapPasswordRotationWithConnection } from "./ldap-password-rotation-types"; const getEncodedPassword = (password: string) => Buffer.from(`"${password}"`, "utf16le"); +const getDN = async (dn: string, client: Client): Promise => { + if (DistinguishedNameRegex.test(dn)) return dn; + + const opts: SearchOptions = { + filter: `(userPrincipalName=${dn})`, + scope: "sub", + attributes: ["dn"] + }; + + const base = dn + .split("@")[1] + .split(".") + .map((dc) => `dc=${dc}`) + .join(","); + + return new Promise((resolve, reject) => { + // Perform the search + client.search(base, opts, (err, res) => { + if (err) { + logger.error(err, "LDAP Failed to get DN"); + reject(new Error(`Provider Resolve DN Error: ${err.message}`)); + } + + let userDn: string | null; + + res.on("searchEntry", (entry) => { + userDn = entry.objectName; + }); + + res.on("error", (error) => { + logger.error(error, "LDAP Failed to get DN"); + reject(new Error(`Provider Resolve DN Error: ${error.message}`)); + }); + + res.on("end", () => { + if (userDn) { + resolve(userDn); + } else { + reject(new Error(`Unable to resolve DN for ${dn}.`)); + } + }); + }); + }); +}; + export const ldapPasswordRotationFactory: TRotationFactory< TLdapPasswordRotationWithConnection, - TLdapPasswordRotationGeneratedCredentials + TLdapPasswordRotationGeneratedCredentials, + TLdapPasswordRotationInput["temporaryParameters"] > = (secretRotation, appConnectionDAL, kmsService) => { - const { - connection, - parameters: { dn, passwordRequirements }, - secretsMapping - } = secretRotation; + const { connection, parameters, secretsMapping, activeIndex } = secretRotation; + + const { dn, passwordRequirements } = parameters; const $verifyCredentials = async (credentials: Pick) => { try { @@ -40,13 +87,21 @@ export const ldapPasswordRotationFactory: TRotationFactory< } }; - const $rotatePassword = async () => { + const $rotatePassword = async (currentPassword?: string) => { const { credentials, orgId } = connection; if (!credentials.url.startsWith("ldaps")) throw new Error("Password Rotation requires an LDAPS connection"); - const client = await getLdapConnectionClient(credentials); - const isPersonalRotation = credentials.dn === dn; + const client = await getLdapConnectionClient( + currentPassword + ? { + ...credentials, + password: currentPassword, + dn + } + : credentials + ); + const isConnectionRotation = credentials.dn === dn; const password = generatePassword(passwordRequirements); @@ -58,8 +113,8 @@ export const ldapPasswordRotationFactory: TRotationFactory< const encodedPassword = getEncodedPassword(password); // service account vs personal password rotation require different changes - if (isPersonalRotation) { - const currentEncodedPassword = getEncodedPassword(credentials.password); + if (isConnectionRotation || currentPassword) { + const currentEncodedPassword = getEncodedPassword(currentPassword || credentials.password); changes = [ new ldap.Change({ @@ -93,8 +148,9 @@ export const ldapPasswordRotationFactory: TRotationFactory< } try { + const userDn = await getDN(dn, client); await new Promise((resolve, reject) => { - client.modify(dn, changes, (err) => { + client.modify(userDn, changes, (err) => { if (err) { logger.error(err, "LDAP Password Rotation Failed"); reject(new Error(`Provider Modify Error: ${err.message}`)); @@ -110,7 +166,7 @@ export const ldapPasswordRotationFactory: TRotationFactory< await $verifyCredentials({ dn, password }); - if (isPersonalRotation) { + if (isConnectionRotation) { const updatedCredentials: TLdapConnection["credentials"] = { ...credentials, password @@ -128,29 +184,41 @@ export const ldapPasswordRotationFactory: TRotationFactory< return { dn, password }; }; - const issueCredentials: TRotationFactoryIssueCredentials = async ( - callback - ) => { - const credentials = await $rotatePassword(); + const issueCredentials: TRotationFactoryIssueCredentials< + TLdapPasswordRotationGeneratedCredentials, + TLdapPasswordRotationInput["temporaryParameters"] + > = async (callback, temporaryParameters) => { + const credentials = await $rotatePassword( + parameters.rotationMethod === LdapPasswordRotationMethod.TargetPrincipal + ? temporaryParameters?.password + : undefined + ); return callback(credentials); }; const revokeCredentials: TRotationFactoryRevokeCredentials = async ( - _, + credentialsToRevoke, callback ) => { + const currentPassword = credentialsToRevoke[activeIndex].password; + // we just rotate to a new password, essentially revoking old credentials - await $rotatePassword(); + await $rotatePassword( + parameters.rotationMethod === LdapPasswordRotationMethod.TargetPrincipal ? currentPassword : undefined + ); return callback(); }; const rotateCredentials: TRotationFactoryRotateCredentials = async ( _, - callback + callback, + activeCredentials ) => { - const credentials = await $rotatePassword(); + const credentials = await $rotatePassword( + parameters.rotationMethod === LdapPasswordRotationMethod.TargetPrincipal ? activeCredentials.password : undefined + ); return callback(credentials); }; diff --git a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-schemas.ts b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-schemas.ts index e99569d9a..741cd3ce1 100644 --- a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-schemas.ts +++ b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-schemas.ts @@ -1,6 +1,6 @@ -import RE2 from "re2"; import { z } from "zod"; +import { LdapPasswordRotationMethod } from "@app/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types"; import { SecretRotation } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-enums"; import { BaseCreateSecretRotationSchema, @@ -9,7 +9,7 @@ import { } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-schemas"; import { PasswordRequirementsSchema } from "@app/ee/services/secret-rotation-v2/shared/general"; import { SecretRotations } from "@app/lib/api-docs"; -import { DistinguishedNameRegex } from "@app/lib/regex"; +import { DistinguishedNameRegex, UserPrincipalNameRegex } from "@app/lib/regex"; import { SecretNameSchema } from "@app/server/lib/schemas"; import { AppConnection } from "@app/services/app-connection/app-connection-enums"; @@ -26,10 +26,16 @@ const LdapPasswordRotationParametersSchema = z.object({ dn: z .string() .trim() - .regex(new RE2(DistinguishedNameRegex), "Invalid DN format, ie; CN=user,OU=users,DC=example,DC=com") - .min(1, "Distinguished Name (DN) Required") + .min(1, "DN/UPN required") + .refine((value) => DistinguishedNameRegex.test(value) || UserPrincipalNameRegex.test(value), { + message: "Invalid DN/UPN format" + }) .describe(SecretRotations.PARAMETERS.LDAP_PASSWORD.dn), - passwordRequirements: PasswordRequirementsSchema.optional() + passwordRequirements: PasswordRequirementsSchema.optional(), + rotationMethod: z + .nativeEnum(LdapPasswordRotationMethod) + .optional() + .describe(SecretRotations.PARAMETERS.LDAP_PASSWORD.rotationMethod) }); const LdapPasswordRotationSecretsMappingSchema = z.object({ @@ -50,10 +56,28 @@ export const LdapPasswordRotationSchema = BaseSecretRotationSchema(SecretRotatio secretsMapping: LdapPasswordRotationSecretsMappingSchema }); -export const CreateLdapPasswordRotationSchema = BaseCreateSecretRotationSchema(SecretRotation.LdapPassword).extend({ - parameters: LdapPasswordRotationParametersSchema, - secretsMapping: LdapPasswordRotationSecretsMappingSchema -}); +export const CreateLdapPasswordRotationSchema = BaseCreateSecretRotationSchema(SecretRotation.LdapPassword) + .extend({ + parameters: LdapPasswordRotationParametersSchema, + secretsMapping: LdapPasswordRotationSecretsMappingSchema, + temporaryParameters: z + .object({ + password: z.string().min(1, "Password required").describe(SecretRotations.PARAMETERS.LDAP_PASSWORD.password) + }) + .optional() + }) + .superRefine((val, ctx) => { + if ( + val.parameters.rotationMethod === LdapPasswordRotationMethod.TargetPrincipal && + !val.temporaryParameters?.password + ) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Password required", + path: ["temporaryParameters", "password"] + }); + } + }); export const UpdateLdapPasswordRotationSchema = BaseUpdateSecretRotationSchema(SecretRotation.LdapPassword).extend({ parameters: LdapPasswordRotationParametersSchema.optional(), diff --git a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types.ts b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types.ts index cb15b0734..86437cac5 100644 --- a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types.ts +++ b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types.ts @@ -9,6 +9,11 @@ import { LdapPasswordRotationSchema } from "./ldap-password-rotation-schemas"; +export enum LdapPasswordRotationMethod { + ConnectionPrincipal = "connection-principal", + TargetPrincipal = "target-principal" +} + export type TLdapPasswordRotation = z.infer; export type TLdapPasswordRotationInput = z.infer; diff --git a/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-fns.ts b/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-fns.ts index a25482c8c..1be7dc802 100644 --- a/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-fns.ts +++ b/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-fns.ts @@ -1,12 +1,13 @@ import { AxiosError } from "axios"; import { getConfig } from "@app/lib/config/env"; +import { BadRequestError } from "@app/lib/errors"; import { KmsDataKey } from "@app/services/kms/kms-types"; import { AUTH0_CLIENT_SECRET_ROTATION_LIST_OPTION } from "./auth0-client-secret"; import { AWS_IAM_USER_SECRET_ROTATION_LIST_OPTION } from "./aws-iam-user-secret"; import { AZURE_CLIENT_SECRET_ROTATION_LIST_OPTION } from "./azure-client-secret"; -import { LDAP_PASSWORD_ROTATION_LIST_OPTION } from "./ldap-password"; +import { LDAP_PASSWORD_ROTATION_LIST_OPTION, TLdapPasswordRotation } from "./ldap-password"; import { MSSQL_CREDENTIALS_ROTATION_LIST_OPTION } from "./mssql-credentials"; import { POSTGRES_CREDENTIALS_ROTATION_LIST_OPTION } from "./postgres-credentials"; import { SecretRotation, SecretRotationStatus } from "./secret-rotation-v2-enums"; @@ -15,7 +16,8 @@ import { TSecretRotationV2, TSecretRotationV2GeneratedCredentials, TSecretRotationV2ListItem, - TSecretRotationV2Raw + TSecretRotationV2Raw, + TUpdateSecretRotationV2DTO } from "./secret-rotation-v2-types"; const SECRET_ROTATION_LIST_OPTIONS: Record = { @@ -228,3 +230,30 @@ export const parseRotationErrorMessage = (err: unknown): string => { ? errorMessage : `${errorMessage.substring(0, MAX_MESSAGE_LENGTH - 3)}...`; }; + +function haveUnequalProperties(obj1: T, obj2: T, properties: (keyof T)[]): boolean { + return properties.some((prop) => obj1[prop] !== obj2[prop]); +} + +export const throwOnImmutableParameterUpdate = ( + updatePayload: TUpdateSecretRotationV2DTO, + secretRotation: TSecretRotationV2Raw +) => { + if (!updatePayload.parameters) return; + + switch (updatePayload.type) { + case SecretRotation.LdapPassword: + if ( + haveUnequalProperties( + updatePayload.parameters as TLdapPasswordRotation["parameters"], + secretRotation.parameters as TLdapPasswordRotation["parameters"], + ["rotationMethod", "dn"] + ) + ) { + throw new BadRequestError({ message: "Cannot update rotation method or DN" }); + } + break; + default: + // do nothing + } +}; diff --git a/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-service.ts b/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-service.ts index 69743f133..352c99b2c 100644 --- a/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-service.ts +++ b/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-service.ts @@ -25,7 +25,8 @@ import { getNextUtcRotationInterval, getSecretRotationRotateSecretJobOptions, listSecretRotationOptions, - parseRotationErrorMessage + parseRotationErrorMessage, + throwOnImmutableParameterUpdate } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-fns"; import { SECRET_ROTATION_CONNECTION_MAP, @@ -46,6 +47,7 @@ import { TSecretRotationV2, TSecretRotationV2GeneratedCredentials, TSecretRotationV2Raw, + TSecretRotationV2TemporaryParameters, TSecretRotationV2WithConnection, TUpdateSecretRotationV2DTO } from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-types"; @@ -112,7 +114,8 @@ const MAX_GENERATED_CREDENTIALS_LENGTH = 2; type TRotationFactoryImplementation = TRotationFactory< TSecretRotationV2WithConnection, - TSecretRotationV2GeneratedCredentials + TSecretRotationV2GeneratedCredentials, + TSecretRotationV2TemporaryParameters >; const SECRET_ROTATION_FACTORY_MAP: Record = { [SecretRotation.PostgresCredentials]: sqlCredentialsRotationFactory as TRotationFactoryImplementation, @@ -400,6 +403,7 @@ export const secretRotationV2ServiceFactory = ({ environment, rotateAtUtc = { hours: 0, minutes: 0 }, secretsMapping, + temporaryParameters, ...payload }: TCreateSecretRotationV2DTO, actor: OrgServiceActor @@ -546,7 +550,7 @@ export const secretRotationV2ServiceFactory = ({ return createdRotation; }); - }); + }, temporaryParameters); await secretV2BridgeDAL.invalidateSecretCacheByProjectId(projectId); await snapshotService.performSnapshot(folder.id); @@ -585,10 +589,7 @@ export const secretRotationV2ServiceFactory = ({ } }; - const updateSecretRotation = async ( - { type, rotationId, ...payload }: TUpdateSecretRotationV2DTO, - actor: OrgServiceActor - ) => { + const updateSecretRotation = async (dto: TUpdateSecretRotationV2DTO, actor: OrgServiceActor) => { const plan = await licenseService.getPlan(actor.orgId); if (!plan.secretRotation) @@ -596,6 +597,8 @@ export const secretRotationV2ServiceFactory = ({ message: "Failed to update secret rotation due to plan restriction. Upgrade plan to update secret rotations." }); + const { type, rotationId, ...payload } = dto; + const secretRotation = await secretRotationV2DAL.findById(rotationId); if (!secretRotation) @@ -603,6 +606,8 @@ export const secretRotationV2ServiceFactory = ({ message: `Could not find ${SECRET_ROTATION_NAME_MAP[type]} Rotation with ID ${rotationId}` }); + throwOnImmutableParameterUpdate(dto, secretRotation); + const { folder, environment, projectId, folderId, connection } = secretRotation; const secretsMapping = secretRotation.secretsMapping as TSecretRotationV2["secretsMapping"]; @@ -877,6 +882,7 @@ export const secretRotationV2ServiceFactory = ({ const inactiveIndex = (activeIndex + 1) % MAX_GENERATED_CREDENTIALS_LENGTH; const inactiveCredentials = generatedCredentials[inactiveIndex]; + const activeCredentials = generatedCredentials[activeIndex]; const rotationFactory = SECRET_ROTATION_FACTORY_MAP[type as SecretRotation]( { @@ -887,73 +893,77 @@ export const secretRotationV2ServiceFactory = ({ kmsService ); - const updatedRotation = await rotationFactory.rotateCredentials(inactiveCredentials, async (newCredentials) => { - const updatedCredentials = [...generatedCredentials]; - updatedCredentials[inactiveIndex] = newCredentials; + const updatedRotation = await rotationFactory.rotateCredentials( + inactiveCredentials, + async (newCredentials) => { + const updatedCredentials = [...generatedCredentials]; + updatedCredentials[inactiveIndex] = newCredentials; - const encryptedUpdatedCredentials = await encryptSecretRotationCredentials({ - projectId, - generatedCredentials: updatedCredentials as TSecretRotationV2GeneratedCredentials, - kmsService - }); - - return secretRotationV2DAL.transaction(async (tx) => { - const secretsPayload = rotationFactory.getSecretsPayload(newCredentials); - - const { encryptor } = await kmsService.createCipherPairWithDataKey({ - type: KmsDataKey.SecretManager, - projectId + const encryptedUpdatedCredentials = await encryptSecretRotationCredentials({ + projectId, + generatedCredentials: updatedCredentials as TSecretRotationV2GeneratedCredentials, + kmsService }); - // update mapped secrets with new credential values - await fnSecretBulkUpdate({ - folderId, - orgId: connection.orgId, - tx, - inputSecrets: secretsPayload.map(({ key, value }) => ({ - filter: { - key, - folderId, - type: SecretType.Shared - }, - data: { - encryptedValue: encryptor({ - plainText: Buffer.from(value) - }).cipherTextBlob, - references: [] - } - })), - secretDAL: secretV2BridgeDAL, - secretVersionDAL: secretVersionV2BridgeDAL, - secretVersionTagDAL: secretVersionTagV2BridgeDAL, - secretTagDAL, - resourceMetadataDAL - }); + return secretRotationV2DAL.transaction(async (tx) => { + const secretsPayload = rotationFactory.getSecretsPayload(newCredentials); - const currentTime = new Date(); + const { encryptor } = await kmsService.createCipherPairWithDataKey({ + type: KmsDataKey.SecretManager, + projectId + }); - return secretRotationV2DAL.updateById( - secretRotation.id, - { - encryptedGeneratedCredentials: encryptedUpdatedCredentials, - activeIndex: inactiveIndex, - isLastRotationManual: isManualRotation, - lastRotatedAt: currentTime, - lastRotationAttemptedAt: currentTime, - nextRotationAt: calculateNextRotationAt({ - ...(secretRotation as TSecretRotationV2), - rotationStatus: SecretRotationStatus.Success, + // update mapped secrets with new credential values + await fnSecretBulkUpdate({ + folderId, + orgId: connection.orgId, + tx, + inputSecrets: secretsPayload.map(({ key, value }) => ({ + filter: { + key, + folderId, + type: SecretType.Shared + }, + data: { + encryptedValue: encryptor({ + plainText: Buffer.from(value) + }).cipherTextBlob, + references: [] + } + })), + secretDAL: secretV2BridgeDAL, + secretVersionDAL: secretVersionV2BridgeDAL, + secretVersionTagDAL: secretVersionTagV2BridgeDAL, + secretTagDAL, + resourceMetadataDAL + }); + + const currentTime = new Date(); + + return secretRotationV2DAL.updateById( + secretRotation.id, + { + encryptedGeneratedCredentials: encryptedUpdatedCredentials, + activeIndex: inactiveIndex, + isLastRotationManual: isManualRotation, lastRotatedAt: currentTime, - isManualRotation - }), - rotationStatus: SecretRotationStatus.Success, - lastRotationJobId: jobId, - encryptedLastRotationMessage: null - }, - tx - ); - }); - }); + lastRotationAttemptedAt: currentTime, + nextRotationAt: calculateNextRotationAt({ + ...(secretRotation as TSecretRotationV2), + rotationStatus: SecretRotationStatus.Success, + lastRotatedAt: currentTime, + isManualRotation + }), + rotationStatus: SecretRotationStatus.Success, + lastRotationJobId: jobId, + encryptedLastRotationMessage: null + }, + tx + ); + }); + }, + activeCredentials + ); await auditLogService.createAuditLog({ ...(auditLogInfo ?? { diff --git a/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-types.ts b/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-types.ts index ab715c406..b72bfba31 100644 --- a/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-types.ts +++ b/backend/src/ee/services/secret-rotation-v2/secret-rotation-v2-types.ts @@ -87,6 +87,8 @@ export type TSecretRotationV2ListItem = | TLdapPasswordRotationListItem | TAwsIamUserSecretRotationListItem; +export type TSecretRotationV2TemporaryParameters = TLdapPasswordRotationInput["temporaryParameters"] | undefined; + export type TSecretRotationV2Raw = NonNullable>>; export type TListSecretRotationsV2ByProjectId = { @@ -120,6 +122,7 @@ export type TCreateSecretRotationV2DTO = Pick< environment: string; isAutoRotationEnabled?: boolean; rotateAtUtc?: TRotateAtUtc; + temporaryParameters?: TSecretRotationV2TemporaryParameters; }; export type TUpdateSecretRotationV2DTO = Partial< @@ -186,8 +189,12 @@ export type TSecretRotationSendNotificationJobPayload = { // transactional behavior. By passing in the rotation mutation, if this mutation fails we can roll back the // third party credential changes (when supported), preventing credentials getting out of sync -export type TRotationFactoryIssueCredentials = ( - callback: (newCredentials: T[number]) => Promise +export type TRotationFactoryIssueCredentials< + T extends TSecretRotationV2GeneratedCredentials, + P extends TSecretRotationV2TemporaryParameters = undefined +> = ( + callback: (newCredentials: T[number]) => Promise, + temporaryParameters?: P ) => Promise; export type TRotationFactoryRevokeCredentials = ( @@ -197,7 +204,8 @@ export type TRotationFactoryRevokeCredentials = ( credentialsToRevoke: T[number] | undefined, - callback: (newCredentials: T[number]) => Promise + callback: (newCredentials: T[number]) => Promise, + activeCredentials: T[number] ) => Promise; export type TRotationFactoryGetSecretsPayload = ( @@ -206,13 +214,14 @@ export type TRotationFactoryGetSecretsPayload = ( secretRotation: T, appConnectionDAL: Pick, kmsService: Pick ) => { - issueCredentials: TRotationFactoryIssueCredentials; + issueCredentials: TRotationFactoryIssueCredentials; revokeCredentials: TRotationFactoryRevokeCredentials; rotateCredentials: TRotationFactoryRotateCredentials; getSecretsPayload: TRotationFactoryGetSecretsPayload; diff --git a/backend/src/lib/api-docs/constants.ts b/backend/src/lib/api-docs/constants.ts index 7b3f89576..537264028 100644 --- a/backend/src/lib/api-docs/constants.ts +++ b/backend/src/lib/api-docs/constants.ts @@ -2126,7 +2126,7 @@ export const AppConnections = { LDAP: { provider: "The type of LDAP provider. Determines provider-specific behaviors.", url: "The LDAP/LDAPS URL to connect to (e.g., 'ldap://domain-or-ip:389' or 'ldaps://domain-or-ip:636').", - dn: "The Distinguished Name (DN) of the principal to bind with (e.g., 'CN=John,CN=Users,DC=example,DC=com').", + dn: "The Distinguished Name (DN) or User Principal Name (UPN) of the principal to bind with (e.g., 'CN=John,CN=Users,DC=example,DC=com').", password: "The password to bind with for authentication.", sslRejectUnauthorized: "Whether or not to reject unauthorized SSL certificates (true/false) when using ldaps://. Set to false only in test environments.", @@ -2371,7 +2371,10 @@ export const SecretRotations = { clientId: "The client ID of the Azure Application to rotate the client secret for." }, LDAP_PASSWORD: { - dn: "The Distinguished Name (DN) of the principal to rotate the password for." + dn: "The Distinguished Name (DN) or User Principal Name (UPN) of the principal to rotate the password for.", + rotationMethod: + 'Whether the rotation should be performed by the LDAP "connection-principal" or the "target-principal" (defaults to \'connection-principal\').', + password: 'The password of the provided principal if "parameters.rotationMethod" is set to "target-principal".' }, GENERAL: { PASSWORD_REQUIREMENTS: { @@ -2405,7 +2408,7 @@ export const SecretRotations = { clientSecret: "The name of the secret that the rotated client secret will be mapped to." }, LDAP_PASSWORD: { - dn: "The name of the secret that the Distinguished Name (DN) of the principal will be mapped to.", + dn: "The name of the secret that the Distinguished Name (DN) or User Principal Name (UPN) of the principal will be mapped to.", password: "The name of the secret that the rotated password will be mapped to." }, AWS_IAM_USER_SECRET: { diff --git a/backend/src/lib/knex/scim.ts b/backend/src/lib/knex/scim.ts index 64f7fc2f6..d522e2f5f 100644 --- a/backend/src/lib/knex/scim.ts +++ b/backend/src/lib/knex/scim.ts @@ -1,6 +1,8 @@ import { Knex } from "knex"; import { Compare, Filter, parse } from "scim2-parse-filter"; +import { TableName } from "@app/db/schemas"; + const appendParentToGroupingOperator = (parentPath: string, filter: Filter) => { if (filter.op !== "[]" && filter.op !== "and" && filter.op !== "or" && filter.op !== "not") { return { ...filter, attrPath: `${parentPath}.${(filter as Compare).attrPath}` }; @@ -27,8 +29,12 @@ const processDynamicQuery = ( const { scimFilterAst, query } = stack.pop()!; switch (scimFilterAst.op) { case "eq": { + let sanitizedValue = scimFilterAst.compValue; const attrPath = getAttributeField(scimFilterAst.attrPath); - if (attrPath) void query.where(attrPath, scimFilterAst.compValue); + if (attrPath === `${TableName.Users}.email` && typeof sanitizedValue === "string") { + sanitizedValue = sanitizedValue.toLowerCase(); + } + if (attrPath) void query.where(attrPath, sanitizedValue); break; } case "pr": { @@ -62,18 +68,30 @@ const processDynamicQuery = ( break; } case "ew": { + let sanitizedValue = scimFilterAst.compValue; const attrPath = getAttributeField(scimFilterAst.attrPath); - if (attrPath) void query.whereILike(attrPath, `%${scimFilterAst.compValue}`); + if (attrPath === `${TableName.Users}.email` && typeof sanitizedValue === "string") { + sanitizedValue = sanitizedValue.toLowerCase(); + } + if (attrPath) void query.whereILike(attrPath, `%${sanitizedValue}`); break; } case "co": { + let sanitizedValue = scimFilterAst.compValue; const attrPath = getAttributeField(scimFilterAst.attrPath); - if (attrPath) void query.whereILike(attrPath, `%${scimFilterAst.compValue}%`); + if (attrPath === `${TableName.Users}.email` && typeof sanitizedValue === "string") { + sanitizedValue = sanitizedValue.toLowerCase(); + } + if (attrPath) void query.whereILike(attrPath, `%${sanitizedValue}%`); break; } case "ne": { + let sanitizedValue = scimFilterAst.compValue; const attrPath = getAttributeField(scimFilterAst.attrPath); - if (attrPath) void query.whereNot(attrPath, "=", scimFilterAst.compValue); + if (attrPath === `${TableName.Users}.email` && typeof sanitizedValue === "string") { + sanitizedValue = sanitizedValue.toLowerCase(); + } + if (attrPath) void query.whereNot(attrPath, "=", sanitizedValue); break; } case "and": { diff --git a/backend/src/lib/regex/index.ts b/backend/src/lib/regex/index.ts index 68ba7671d..be9430669 100644 --- a/backend/src/lib/regex/index.ts +++ b/backend/src/lib/regex/index.ts @@ -1,3 +1,11 @@ +import RE2 from "re2"; + export const DistinguishedNameRegex = // DN format, ie; CN=user,OU=users,DC=example,DC=com - /^(?:(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*)(?:,(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*))*)?$/; + new RE2( + /^(?:(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*)(?:,(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*))*)?$/ + ); + +export const UserPrincipalNameRegex = new RE2(/^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9._-]+\.[a-zA-Z]{2,}$/); + +export const LdapUrlRegex = new RE2(/^ldaps?:\/\//); diff --git a/backend/src/server/routes/index.ts b/backend/src/server/routes/index.ts index 94eee2215..f3b265c7b 100644 --- a/backend/src/server/routes/index.ts +++ b/backend/src/server/routes/index.ts @@ -628,7 +628,6 @@ export const registerRoutes = async ( const userService = userServiceFactory({ userDAL, - userAliasDAL, orgMembershipDAL, tokenService, permissionService, diff --git a/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts b/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts index de7927573..d9ef62087 100644 --- a/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts +++ b/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts @@ -114,10 +114,12 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide CharacterType.Numbers, CharacterType.Colon, CharacterType.Period, - CharacterType.ForwardSlash + CharacterType.ForwardSlash, + CharacterType.Hyphen ])(val), { - message: "Kubernetes host must only contain alphabets, numbers, colons, periods, and forward slashes." + message: + "Kubernetes host must only contain alphabets, numbers, colons, periods, hyphen, and forward slashes." } ), caCert: z.string().trim().default("").describe(KUBERNETES_AUTH.ATTACH.caCert), @@ -234,11 +236,13 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide CharacterType.Numbers, CharacterType.Colon, CharacterType.Period, - CharacterType.ForwardSlash + CharacterType.ForwardSlash, + CharacterType.Hyphen ])(val); }, { - message: "Kubernetes host must only contain alphabets, numbers, colons, periods, and forward slashes." + message: + "Kubernetes host must only contain alphabets, numbers, colons, periods, hyphen, and forward slashes." } ), caCert: z.string().trim().optional().describe(KUBERNETES_AUTH.UPDATE.caCert), diff --git a/backend/src/server/routes/v1/invite-org-router.ts b/backend/src/server/routes/v1/invite-org-router.ts index 501bebdab..77ae0e627 100644 --- a/backend/src/server/routes/v1/invite-org-router.ts +++ b/backend/src/server/routes/v1/invite-org-router.ts @@ -16,7 +16,12 @@ export const registerInviteOrgRouter = async (server: FastifyZodProvider) => { method: "POST", schema: { body: z.object({ - inviteeEmails: z.array(z.string().trim().email()), + inviteeEmails: z + .string() + .trim() + .email() + .array() + .refine((val) => val.every((el) => el === el.toLowerCase()), "Email must be lowercase"), organizationId: z.string().trim(), projects: z .object({ @@ -115,7 +120,11 @@ export const registerInviteOrgRouter = async (server: FastifyZodProvider) => { }, schema: { body: z.object({ - email: z.string().trim().email(), + email: z + .string() + .trim() + .email() + .refine((val) => val === val.toLowerCase(), "Email must be lowercase"), organizationId: z.string().trim(), code: z.string().trim() }), diff --git a/backend/src/server/routes/v1/organization-router.ts b/backend/src/server/routes/v1/organization-router.ts index e14dacebb..c489d685d 100644 --- a/backend/src/server/routes/v1/organization-router.ts +++ b/backend/src/server/routes/v1/organization-router.ts @@ -281,7 +281,18 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => { kmsProductEnabled: z.boolean().optional(), sshProductEnabled: z.boolean().optional(), scannerProductEnabled: z.boolean().optional(), - shareSecretsProductEnabled: z.boolean().optional() + shareSecretsProductEnabled: z.boolean().optional(), + maxSharedSecretLifetime: z + .number() + .min(300, "Max Shared Secret lifetime cannot be under 5 minutes") + .max(2592000, "Max Shared Secret lifetime cannot exceed 30 days") + .optional(), + maxSharedSecretViewLimit: z + .number() + .min(1, "Max Shared Secret view count cannot be lower than 1") + .max(1000, "Max Shared Secret view count cannot exceed 1000") + .nullable() + .optional() }), response: { 200: z.object({ diff --git a/backend/src/server/routes/v1/secret-sharing-router.ts b/backend/src/server/routes/v1/secret-sharing-router.ts index 37c8a052f..e712ee138 100644 --- a/backend/src/server/routes/v1/secret-sharing-router.ts +++ b/backend/src/server/routes/v1/secret-sharing-router.ts @@ -62,7 +62,9 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) => }), body: z.object({ hashedHex: z.string().min(1).optional(), - password: z.string().optional() + password: z.string().optional(), + email: z.string().optional(), + hash: z.string().optional() }), response: { 200: z.object({ @@ -88,7 +90,9 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) => sharedSecretId: req.params.id, hashedHex: req.body.hashedHex, password: req.body.password, - orgId: req.permission?.orgId + orgId: req.permission?.orgId, + email: req.body.email, + hash: req.body.hash }); if (sharedSecret.secret?.orgId) { @@ -151,7 +155,8 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) => secretValue: z.string(), expiresAt: z.string(), expiresAfterViews: z.number().min(1).optional(), - accessType: z.nativeEnum(SecretSharingAccessType).default(SecretSharingAccessType.Organization) + accessType: z.nativeEnum(SecretSharingAccessType).default(SecretSharingAccessType.Organization), + emails: z.string().email().array().max(100).optional() }), response: { 200: z.object({ diff --git a/backend/src/server/routes/v1/user-router.ts b/backend/src/server/routes/v1/user-router.ts index a97f11be4..a0c3592f7 100644 --- a/backend/src/server/routes/v1/user-router.ts +++ b/backend/src/server/routes/v1/user-router.ts @@ -46,6 +46,54 @@ export const registerUserRouter = async (server: FastifyZodProvider) => { } }); + server.route({ + method: "GET", + url: "/duplicate-accounts", + config: { + rateLimit: readLimit + }, + schema: { + response: { + 200: z.object({ + users: UsersSchema.extend({ + isMyAccount: z.boolean(), + organizations: z.object({ name: z.string(), slug: z.string() }).array() + }).array() + }) + } + }, + onRequest: verifyAuth([AuthMode.JWT], { requireOrg: false }), + handler: async (req) => { + if (req.auth.authMode === AuthMode.JWT && req.auth.user.email) { + const users = await server.services.user.getAllMyAccounts(req.auth.user.email, req.permission.id); + return { users }; + } + return { users: [] }; + } + }); + + server.route({ + method: "POST", + url: "/remove-duplicate-accounts", + config: { + rateLimit: writeLimit + }, + schema: { + response: { + 200: z.object({ + message: z.string() + }) + } + }, + onRequest: verifyAuth([AuthMode.JWT], { requireOrg: false }), + handler: async (req) => { + if (req.auth.authMode === AuthMode.JWT && req.auth.user.email) { + await server.services.user.removeMyDuplicateAccounts(req.auth.user.email, req.permission.id); + } + return { message: "Removed all duplicate accounts" }; + } + }); + server.route({ method: "GET", url: "/private-key", diff --git a/backend/src/server/routes/v2/project-membership-router.ts b/backend/src/server/routes/v2/project-membership-router.ts index a1a1cfc96..76f1e9c5e 100644 --- a/backend/src/server/routes/v2/project-membership-router.ts +++ b/backend/src/server/routes/v2/project-membership-router.ts @@ -27,8 +27,19 @@ export const registerProjectMembershipRouter = async (server: FastifyZodProvider projectId: z.string().describe(PROJECT_USERS.INVITE_MEMBER.projectId) }), body: z.object({ - emails: z.string().email().array().default([]).describe(PROJECT_USERS.INVITE_MEMBER.emails), - usernames: z.string().array().default([]).describe(PROJECT_USERS.INVITE_MEMBER.usernames), + emails: z + .string() + .email() + .array() + .default([]) + .describe(PROJECT_USERS.INVITE_MEMBER.emails) + .refine((val) => val.every((el) => el === el.toLowerCase()), "Email must be lowercase"), + usernames: z + .string() + .array() + .default([]) + .describe(PROJECT_USERS.INVITE_MEMBER.usernames) + .refine((val) => val.every((el) => el === el.toLowerCase()), "Username must be lowercase"), roleSlugs: z.string().array().min(1).optional().describe(PROJECT_USERS.INVITE_MEMBER.roleSlugs) }), response: { @@ -92,8 +103,19 @@ export const registerProjectMembershipRouter = async (server: FastifyZodProvider projectId: z.string().describe(PROJECT_USERS.REMOVE_MEMBER.projectId) }), body: z.object({ - emails: z.string().email().array().default([]).describe(PROJECT_USERS.REMOVE_MEMBER.emails), - usernames: z.string().array().default([]).describe(PROJECT_USERS.REMOVE_MEMBER.usernames) + emails: z + .string() + .email() + .array() + .default([]) + .describe(PROJECT_USERS.REMOVE_MEMBER.emails) + .refine((val) => val.every((el) => el === el.toLowerCase()), "Email must be lowercase"), + usernames: z + .string() + .array() + .default([]) + .describe(PROJECT_USERS.REMOVE_MEMBER.usernames) + .refine((val) => val.every((el) => el === el.toLowerCase()), "Username must be lowercase") }), response: { 200: z.object({ diff --git a/backend/src/services/app-connection/ldap/ldap-connection-schemas.ts b/backend/src/services/app-connection/ldap/ldap-connection-schemas.ts index 91884b914..c4c94b4fc 100644 --- a/backend/src/services/app-connection/ldap/ldap-connection-schemas.ts +++ b/backend/src/services/app-connection/ldap/ldap-connection-schemas.ts @@ -1,8 +1,7 @@ -import RE2 from "re2"; import { z } from "zod"; import { AppConnections } from "@app/lib/api-docs"; -import { DistinguishedNameRegex } from "@app/lib/regex"; +import { DistinguishedNameRegex, LdapUrlRegex, UserPrincipalNameRegex } from "@app/lib/regex"; import { AppConnection } from "@app/services/app-connection/app-connection-enums"; import { BaseAppConnectionSchema, @@ -14,17 +13,14 @@ import { LdapConnectionMethod, LdapProvider } from "./ldap-connection-enums"; export const LdapConnectionSimpleBindCredentialsSchema = z.object({ provider: z.nativeEnum(LdapProvider).describe(AppConnections.CREDENTIALS.LDAP.provider), - url: z - .string() - .trim() - .min(1, "URL required") - .regex(new RE2(/^ldaps?:\/\//)) - .describe(AppConnections.CREDENTIALS.LDAP.url), + url: z.string().trim().min(1, "URL required").regex(LdapUrlRegex).describe(AppConnections.CREDENTIALS.LDAP.url), dn: z .string() .trim() - .regex(new RE2(DistinguishedNameRegex), "Invalid DN format, ie; CN=user,OU=users,DC=example,DC=com") - .min(1, "Distinguished Name (DN) required") + .min(1, "DN/UPN required") + .refine((value) => DistinguishedNameRegex.test(value) || UserPrincipalNameRegex.test(value), { + message: "Invalid DN/UPN format" + }) .describe(AppConnections.CREDENTIALS.LDAP.dn), password: z.string().trim().min(1, "Password required").describe(AppConnections.CREDENTIALS.LDAP.password), sslRejectUnauthorized: z.boolean().optional().describe(AppConnections.CREDENTIALS.LDAP.sslRejectUnauthorized), diff --git a/backend/src/services/auth/auth-login-service.ts b/backend/src/services/auth/auth-login-service.ts index fdbd5ccd8..bee85b14c 100644 --- a/backend/src/services/auth/auth-login-service.ts +++ b/backend/src/services/auth/auth-login-service.ts @@ -199,9 +199,12 @@ export const authLoginServiceFactory = ({ providerAuthToken, clientPublicKey }: TLoginGenServerPublicKeyDTO) => { - const userEnc = await userDAL.findUserEncKeyByUsername({ + // akhilmhdh: case sensitive email resolution + const usersByUsername = await userDAL.findUserEncKeyByUsername({ username: email }); + const userEnc = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === email) : usersByUsername?.[0]; const serverCfg = await getServerCfg(); @@ -250,9 +253,12 @@ export const authLoginServiceFactory = ({ }: TLoginClientProofDTO) => { const appCfg = getConfig(); - const userEnc = await userDAL.findUserEncKeyByUsername({ + // akhilmhdh: case sensitive email resolution + const usersByUsername = await userDAL.findUserEncKeyByUsername({ username: email }); + const userEnc = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === email) : usersByUsername?.[0]; if (!userEnc) throw new Error("Failed to find user"); const user = await userDAL.findById(userEnc.userId); const cfg = getConfig(); @@ -649,10 +655,12 @@ export const authLoginServiceFactory = ({ * OAuth2 login for google,github, and other oauth2 provider * */ const oauth2Login = async ({ email, firstName, lastName, authMethod, callbackPort }: TOauthLoginDTO) => { - let user = await userDAL.findUserByUsername(email); + // akhilmhdh: case sensitive email resolution + const usersByUsername = await userDAL.findUserByUsername(email); + let user = usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === email) : usersByUsername?.[0]; const serverCfg = await getServerCfg(); - if (serverCfg.enabledLoginMethods) { + if (serverCfg.enabledLoginMethods && user) { switch (authMethod) { case AuthMethod.GITHUB: { if (!serverCfg.enabledLoginMethods.includes(LoginMethod.GITHUB)) { @@ -715,8 +723,8 @@ export const authLoginServiceFactory = ({ } user = await userDAL.create({ - username: email, - email, + username: email.trim().toLowerCase(), + email: email.trim().toLowerCase(), isEmailVerified: true, firstName, lastName, @@ -814,11 +822,14 @@ export const authLoginServiceFactory = ({ ? decodedProviderToken.orgId : undefined; - const userEnc = await userDAL.findUserEncKeyByUsername({ + // akhilmhdh: case sensitive email resolution + const usersByUsername = await userDAL.findUserEncKeyByUsername({ username: email }); - if (!userEnc) throw new BadRequestError({ message: "Invalid token" }); - if (!userEnc.serverEncryptedPrivateKey) + const userEnc = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === email) : usersByUsername?.[0]; + + if (!userEnc?.serverEncryptedPrivateKey) throw new BadRequestError({ message: "Key handoff incomplete. Please try logging in again." }); const token = await generateUserTokens({ diff --git a/backend/src/services/auth/auth-password-service.ts b/backend/src/services/auth/auth-password-service.ts index 14fb58258..5e2f8c7b3 100644 --- a/backend/src/services/auth/auth-password-service.ts +++ b/backend/src/services/auth/auth-password-service.ts @@ -121,7 +121,10 @@ export const authPaswordServiceFactory = ({ */ const sendPasswordResetEmail = async (email: string) => { const sendEmail = async () => { - const user = await userDAL.findUserByUsername(email); + const users = await userDAL.findUserByUsername(email); + // akhilmhdh: case sensitive email resolution + const user = users?.length > 1 ? users.find((el) => el.username === email) : users?.[0]; + if (!user) throw new BadRequestError({ message: "Failed to find user data" }); if (user && user.isAccepted) { const cfg = getConfig(); @@ -152,7 +155,10 @@ export const authPaswordServiceFactory = ({ * */ const verifyPasswordResetEmail = async (email: string, code: string) => { const cfg = getConfig(); - const user = await userDAL.findUserByUsername(email); + const users = await userDAL.findUserByUsername(email); + // akhilmhdh: case sensitive email resolution + const user = users?.length > 1 ? users.find((el) => el.username === email) : users?.[0]; + if (!user) throw new BadRequestError({ message: "Failed to find user data" }); const userEnc = await userDAL.findUserEncKeyByUserId(user.id); @@ -189,16 +195,15 @@ export const authPaswordServiceFactory = ({ throw new BadRequestError({ message: `User encryption key not found for user with ID '${userId}'` }); } - if (!user.hashedPassword) { - throw new BadRequestError({ message: "Unable to reset password, no password is set" }); - } - if (!user.authMethods?.includes(AuthMethod.EMAIL)) { throw new BadRequestError({ message: "Unable to reset password, no email authentication method is configured" }); } // we check the old password if the user is resetting their password while logged in if (type === ResetPasswordV2Type.LoggedInReset) { + if (!user.hashedPassword) { + throw new BadRequestError({ message: "Unable to change password, no password is set" }); + } if (!oldPassword) { throw new BadRequestError({ message: "Current password is required." }); } diff --git a/backend/src/services/auth/auth-signup-service.ts b/backend/src/services/auth/auth-signup-service.ts index 4d8c98205..7e11f25cb 100644 --- a/backend/src/services/auth/auth-signup-service.ts +++ b/backend/src/services/auth/auth-signup-service.ts @@ -73,18 +73,27 @@ export const authSignupServiceFactory = ({ }: TAuthSignupDep) => { // first step of signup. create user and send email const beginEmailSignupProcess = async (email: string) => { - const isEmailInvalid = await isDisposableEmail(email); + const sanitizedEmail = email.trim().toLowerCase(); + const isEmailInvalid = await isDisposableEmail(sanitizedEmail); if (isEmailInvalid) { throw new Error("Provided a disposable email"); } - let user = await userDAL.findUserByUsername(email); + // akhilmhdh: case sensitive email resolution + const usersByUsername = await userDAL.findUserByUsername(sanitizedEmail); + let user = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === sanitizedEmail) : usersByUsername?.[0]; if (user && user.isAccepted) { // TODO(akhilmhdh-pg): copy as old one. this needs to be changed due to security issues - throw new Error("Failed to send verification code for complete account"); + throw new BadRequestError({ message: "Failed to send verification code for complete account" }); } if (!user) { - user = await userDAL.create({ authMethods: [AuthMethod.EMAIL], username: email, email, isGhost: false }); + user = await userDAL.create({ + authMethods: [AuthMethod.EMAIL], + username: sanitizedEmail, + email: sanitizedEmail, + isGhost: false + }); } if (!user) throw new Error("Failed to create user"); @@ -96,7 +105,7 @@ export const authSignupServiceFactory = ({ await smtpService.sendMail({ template: SmtpTemplates.SignupEmailVerification, subjectLine: "Infisical confirmation code", - recipients: [user.email as string], + recipients: [sanitizedEmail], substitutions: { code: token } @@ -104,11 +113,15 @@ export const authSignupServiceFactory = ({ }; const verifyEmailSignup = async (email: string, code: string) => { - const user = await userDAL.findUserByUsername(email); + const sanitizedEmail = email.trim().toLowerCase(); + const usersByUsername = await userDAL.findUserByUsername(sanitizedEmail); + const user = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === sanitizedEmail) : usersByUsername?.[0]; if (!user || (user && user.isAccepted)) { // TODO(akhilmhdh): copy as old one. this needs to be changed due to security issues throw new Error("Failed to send verification code for complete account"); } + const appCfg = getConfig(); await tokenService.validateTokenForUser({ type: TokenType.TOKEN_EMAIL_CONFIRMATION, @@ -153,12 +166,15 @@ export const authSignupServiceFactory = ({ authorization, useDefaultOrg }: TCompleteAccountSignupDTO) => { + const sanitizedEmail = email.trim().toLowerCase(); const appCfg = getConfig(); const serverCfg = await getServerCfg(); - const user = await userDAL.findOne({ username: email }); + const usersByUsername = await userDAL.findUserByUsername(sanitizedEmail); + const user = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === sanitizedEmail) : usersByUsername?.[0]; if (!user || (user && user.isAccepted)) { - throw new Error("Failed to complete account for complete user"); + throw new BadRequestError({ message: "Failed to complete account for complete user" }); } let organizationId: string | null = null; @@ -315,7 +331,7 @@ export const authSignupServiceFactory = ({ } const updatedMembersips = await orgDAL.updateMembership( - { inviteEmail: email, status: OrgMembershipStatus.Invited }, + { inviteEmail: sanitizedEmail, status: OrgMembershipStatus.Invited }, { userId: user.id, status: OrgMembershipStatus.Accepted } ); const uniqueOrgId = [...new Set(updatedMembersips.map(({ orgId }) => orgId))]; @@ -382,9 +398,9 @@ export const authSignupServiceFactory = ({ * User signup flow when they are invited to join the org * */ const completeAccountInvite = async ({ + email, ip, salt, - email, password, verifier, firstName, @@ -399,7 +415,10 @@ export const authSignupServiceFactory = ({ encryptedPrivateKeyTag, authorization }: TCompleteAccountInviteDTO) => { - const user = await userDAL.findUserByUsername(email); + const sanitizedEmail = email.trim().toLowerCase(); + const usersByUsername = await userDAL.findUserByUsername(sanitizedEmail); + const user = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === sanitizedEmail) : usersByUsername?.[0]; if (!user || (user && user.isAccepted)) { throw new Error("Failed to complete account for complete user"); } @@ -407,7 +426,7 @@ export const authSignupServiceFactory = ({ validateSignUpAuthorization(authorization, user.id); const [orgMembership] = await orgDAL.findMembership({ - inviteEmail: email, + inviteEmail: sanitizedEmail, status: OrgMembershipStatus.Invited }); if (!orgMembership) @@ -454,7 +473,7 @@ export const authSignupServiceFactory = ({ const serverGeneratedPrivateKey = await getUserPrivateKey(serverGeneratedPassword, { ...systemGeneratedUserEncryptionKey }); - const encKeys = await generateUserSrpKeys(email, password, { + const encKeys = await generateUserSrpKeys(sanitizedEmail, password, { publicKey: systemGeneratedUserEncryptionKey.publicKey, privateKey: serverGeneratedPrivateKey }); @@ -505,7 +524,7 @@ export const authSignupServiceFactory = ({ } const updatedMembersips = await orgDAL.updateMembership( - { inviteEmail: email, status: OrgMembershipStatus.Invited }, + { inviteEmail: sanitizedEmail, status: OrgMembershipStatus.Invited }, { userId: us.id, status: OrgMembershipStatus.Accepted }, tx ); diff --git a/backend/src/services/org/org-dal.ts b/backend/src/services/org/org-dal.ts index 54b0e1b0f..32cabf444 100644 --- a/backend/src/services/org/org-dal.ts +++ b/backend/src/services/org/org-dal.ts @@ -206,7 +206,7 @@ export const orgDALFactory = (db: TDbClient) => { .where(`${TableName.OrgMembership}.orgId`, orgId) .count("*") .join(TableName.Users, `${TableName.OrgMembership}.userId`, `${TableName.Users}.id`) - .where({ isGhost: false }) + .where({ isGhost: false, [`${TableName.OrgMembership}.isActive` as "isActive"]: true }) .first(); return parseInt((count as unknown as CountResult).count || "0", 10); diff --git a/backend/src/services/org/org-schema.ts b/backend/src/services/org/org-schema.ts index 39a1680a9..ae82cd1bc 100644 --- a/backend/src/services/org/org-schema.ts +++ b/backend/src/services/org/org-schema.ts @@ -24,5 +24,7 @@ export const sanitizedOrganizationSchema = OrganizationsSchema.pick({ kmsProductEnabled: true, sshProductEnabled: true, scannerProductEnabled: true, - shareSecretsProductEnabled: true + shareSecretsProductEnabled: true, + maxSharedSecretLifetime: true, + maxSharedSecretViewLimit: true }); diff --git a/backend/src/services/org/org-service.ts b/backend/src/services/org/org-service.ts index bcbd9e0e5..bfd24e639 100644 --- a/backend/src/services/org/org-service.ts +++ b/backend/src/services/org/org-service.ts @@ -361,7 +361,9 @@ export const orgServiceFactory = ({ kmsProductEnabled, sshProductEnabled, scannerProductEnabled, - shareSecretsProductEnabled + shareSecretsProductEnabled, + maxSharedSecretLifetime, + maxSharedSecretViewLimit } }: TUpdateOrgDTO) => { const appCfg = getConfig(); @@ -469,7 +471,9 @@ export const orgServiceFactory = ({ kmsProductEnabled, sshProductEnabled, scannerProductEnabled, - shareSecretsProductEnabled + shareSecretsProductEnabled, + maxSharedSecretLifetime, + maxSharedSecretViewLimit }); if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` }); return org; @@ -823,7 +827,11 @@ export const orgServiceFactory = ({ const users: Pick[] = []; for await (const inviteeEmail of inviteeEmails) { - let inviteeUser = await userDAL.findUserByUsername(inviteeEmail, tx); + const usersByUsername = await userDAL.findUserByUsername(inviteeEmail, tx); + let inviteeUser = + usersByUsername?.length > 1 + ? usersByUsername.find((el) => el.username === inviteeEmail) + : usersByUsername?.[0]; // if the user doesn't exist we create the user with the email if (!inviteeUser) { @@ -1235,10 +1243,13 @@ export const orgServiceFactory = ({ * magic link and issue a temporary signup token for user to complete setting up their account */ const verifyUserToOrg = async ({ orgId, email, code }: TVerifyUserToOrgDTO) => { - const user = await userDAL.findUserByUsername(email); + const usersByUsername = await userDAL.findUserByUsername(email); + const user = + usersByUsername?.length > 1 ? usersByUsername.find((el) => el.username === email) : usersByUsername?.[0]; if (!user) { throw new NotFoundError({ message: "User not found" }); } + const [orgMembership] = await orgDAL.findMembership({ [`${TableName.OrgMembership}.userId` as "userId"]: user.id, status: OrgMembershipStatus.Invited, diff --git a/backend/src/services/org/org-types.ts b/backend/src/services/org/org-types.ts index 9625934fb..8b2485ac4 100644 --- a/backend/src/services/org/org-types.ts +++ b/backend/src/services/org/org-types.ts @@ -81,6 +81,8 @@ export type TUpdateOrgDTO = { sshProductEnabled: boolean; scannerProductEnabled: boolean; shareSecretsProductEnabled: boolean; + maxSharedSecretLifetime: number; + maxSharedSecretViewLimit: number | null; }>; } & TOrgPermission; diff --git a/backend/src/services/secret-sharing/secret-sharing-service.ts b/backend/src/services/secret-sharing/secret-sharing-service.ts index 9649be722..702078364 100644 --- a/backend/src/services/secret-sharing/secret-sharing-service.ts +++ b/backend/src/services/secret-sharing/secret-sharing-service.ts @@ -6,6 +6,7 @@ import { TSecretSharing } from "@app/db/schemas"; import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service"; import { getConfig } from "@app/lib/config/env"; import { BadRequestError, ForbiddenRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors"; +import { logger } from "@app/lib/logger"; import { SecretSharingAccessType } from "@app/lib/types"; import { isUuidV4 } from "@app/lib/validator"; @@ -60,7 +61,9 @@ export const secretSharingServiceFactory = ({ } const fiveMins = 5 * 60 * 1000; - if (expiryTime - currentTime < fiveMins) { + + // 1 second buffer + if (expiryTime - currentTime + 1000 < fiveMins) { throw new BadRequestError({ message: "Expiration time cannot be less than 5 mins" }); } }; @@ -76,8 +79,11 @@ export const secretSharingServiceFactory = ({ password, accessType, expiresAt, - expiresAfterViews + expiresAfterViews, + emails }: TCreateSharedSecretDTO) => { + const appCfg = getConfig(); + const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); if (!permission) throw new ForbiddenRequestError({ name: "User is not a part of the specified organization" }); $validateSharedSecretExpiry(expiresAt); @@ -93,7 +99,46 @@ export const secretSharingServiceFactory = ({ throw new BadRequestError({ message: "Shared secret value too long" }); } + // Check lifetime is within org allowance + const expiresAtTimestamp = new Date(expiresAt).getTime(); + const lifetime = expiresAtTimestamp - new Date().getTime(); + + // org.maxSharedSecretLifetime is in seconds + if (org.maxSharedSecretLifetime && lifetime / 1000 > org.maxSharedSecretLifetime) { + throw new BadRequestError({ message: "Secret lifetime exceeds organization limit" }); + } + + // Check max view count is within org allowance + if (org.maxSharedSecretViewLimit && (!expiresAfterViews || expiresAfterViews > org.maxSharedSecretViewLimit)) { + throw new BadRequestError({ message: "Secret max views parameter exceeds organization limit" }); + } + const encryptWithRoot = kmsService.encryptWithRootKey(); + + let salt: string | undefined; + let encryptedSalt: Buffer | undefined; + const orgEmails = []; + + if (emails && emails.length > 0) { + const allOrgMembers = await orgDAL.findAllOrgMembers(orgId); + + // Check to see that all emails are a part of the organization (if enforced) while also collecting a list of emails which are in the org + for (const email of emails) { + if (allOrgMembers.some((v) => v.user.email === email)) { + orgEmails.push(email); + // If the email is not part of the org, but access type / org settings require it + } else if (!org.allowSecretSharingOutsideOrganization || accessType === SecretSharingAccessType.Organization) { + throw new BadRequestError({ + message: "Organization does not allow sharing secrets to members outside of this organization" + }); + } + } + + // Generate salt for signing email hashes (if emails are provided) + salt = crypto.randomBytes(32).toString("hex"); + encryptedSalt = encryptWithRoot(Buffer.from(salt)); + } + const encryptedSecret = encryptWithRoot(Buffer.from(secretValue)); const id = crypto.randomBytes(32).toString("hex"); @@ -112,11 +157,45 @@ export const secretSharingServiceFactory = ({ expiresAfterViews, userId: actorId, orgId, - accessType + accessType, + authorizedEmails: emails && emails.length > 0 ? JSON.stringify(emails) : undefined, + encryptedSalt }); const idToReturn = `${Buffer.from(newSharedSecret.identifier!, "hex").toString("base64url")}`; + // Loop through recipients and send out emails with unique access links + if (emails && salt) { + const user = await userDAL.findById(actorId); + + if (!user) { + throw new NotFoundError({ message: `User with ID '${actorId}' not found` }); + } + + for await (const email of emails) { + try { + const hmac = crypto.createHmac("sha256", salt).update(email); + const hash = hmac.digest("hex"); + + // Only show the username to emails which are part of the organization + const respondentUsername = orgEmails.includes(email) ? user.username : undefined; + + await smtpService.sendMail({ + recipients: [email], + subjectLine: "A secret has been shared with you", + substitutions: { + name, + respondentUsername, + secretRequestUrl: `${appCfg.SITE_URL}/shared/secret/${idToReturn}?email=${encodeURIComponent(email)}&hash=${hash}` + }, + template: SmtpTemplates.SecretRequestCompleted + }); + } catch (e) { + logger.error(e, "Failed to send shared secret URL to a recipient's email."); + } + } + } + return { id: idToReturn }; }; @@ -390,8 +469,15 @@ export const secretSharingServiceFactory = ({ }); }; - /** Get's password-less secret. validates all secret's requested (must be fresh). */ - const getSharedSecretById = async ({ sharedSecretId, hashedHex, orgId, password }: TGetActiveSharedSecretByIdDTO) => { + /** Gets password-less secret. validates all secret's requested (must be fresh). */ + const getSharedSecretById = async ({ + sharedSecretId, + hashedHex, + orgId, + password, + email, + hash + }: TGetActiveSharedSecretByIdDTO) => { const sharedSecret = isUuidV4(sharedSecretId) ? await secretSharingDAL.findOne({ id: sharedSecretId, @@ -438,6 +524,32 @@ export const secretSharingServiceFactory = ({ }); } + const decryptWithRoot = kmsService.decryptWithRootKey(); + + if (sharedSecret.authorizedEmails && sharedSecret.encryptedSalt) { + // Verify both params were passed + if (!email || !hash) { + throw new BadRequestError({ + message: "This secret is email protected. Parameters must include email and hash." + }); + + // Verify that email is authorized to view shared secret + } else if (!(sharedSecret.authorizedEmails as string[]).includes(email)) { + throw new UnauthorizedError({ message: "Email not authorized to view secret" }); + + // Verify that hash matches + } else { + const salt = decryptWithRoot(sharedSecret.encryptedSalt).toString(); + const hmac = crypto.createHmac("sha256", salt).update(email); + const rebuiltHash = hmac.digest("hex"); + + if (rebuiltHash !== hash) { + throw new UnauthorizedError({ message: "Email not authorized to view secret" }); + } + } + } + + // Password checks const isPasswordProtected = Boolean(sharedSecret.password); const hasProvidedPassword = Boolean(password); if (isPasswordProtected) { @@ -452,7 +564,6 @@ export const secretSharingServiceFactory = ({ // If encryptedSecret is set, we know that this secret has been encrypted using KMS, and we can therefore do server-side decryption. let decryptedSecretValue: Buffer | undefined; if (sharedSecret.encryptedSecret) { - const decryptWithRoot = kmsService.decryptWithRootKey(); decryptedSecretValue = decryptWithRoot(sharedSecret.encryptedSecret); } diff --git a/backend/src/services/secret-sharing/secret-sharing-types.ts b/backend/src/services/secret-sharing/secret-sharing-types.ts index 835d70eff..049dbb913 100644 --- a/backend/src/services/secret-sharing/secret-sharing-types.ts +++ b/backend/src/services/secret-sharing/secret-sharing-types.ts @@ -22,6 +22,7 @@ export type TSharedSecretPermission = { accessType?: SecretSharingAccessType; name?: string; password?: string; + emails?: string[]; }; export type TCreatePublicSharedSecretDTO = { @@ -37,6 +38,10 @@ export type TGetActiveSharedSecretByIdDTO = { hashedHex?: string; orgId?: string; password?: string; + + // For secrets shared with specific emails + email?: string; + hash?: string; }; export type TValidateActiveSharedSecretDTO = TGetActiveSharedSecretByIdDTO & { diff --git a/backend/src/services/super-admin/super-admin-service.ts b/backend/src/services/super-admin/super-admin-service.ts index 22fc51d1a..04dfa253b 100644 --- a/backend/src/services/super-admin/super-admin-service.ts +++ b/backend/src/services/super-admin/super-admin-service.ts @@ -257,8 +257,8 @@ export const superAdminServiceFactory = ({ const adminSignUp = async ({ lastName, firstName, - salt, email, + salt, password, verifier, publicKey, @@ -272,7 +272,8 @@ export const superAdminServiceFactory = ({ userAgent }: TAdminSignUpDTO) => { const appCfg = getConfig(); - const existingUser = await userDAL.findOne({ email }); + const sanitizedEmail = email.trim().toLowerCase(); + const existingUser = await userDAL.findOne({ username: sanitizedEmail }); if (existingUser) throw new BadRequestError({ name: "Admin sign up", message: "User already exists" }); const privateKey = await getUserPrivateKey(password, { @@ -292,8 +293,8 @@ export const superAdminServiceFactory = ({ { firstName, lastName, - username: email, - email, + username: sanitizedEmail, + email: sanitizedEmail, superAdmin: true, isGhost: false, isAccepted: true, @@ -348,12 +349,13 @@ export const superAdminServiceFactory = ({ const bootstrapInstance = async ({ email, password, organizationName }: TAdminBootstrapInstanceDTO) => { const appCfg = getConfig(); + const sanitizedEmail = email.trim().toLowerCase(); const serverCfg = await serverCfgDAL.findById(ADMIN_CONFIG_DB_UUID); if (serverCfg?.initialized) { throw new BadRequestError({ message: "Instance has already been set up" }); } - const existingUser = await userDAL.findOne({ email }); + const existingUser = await userDAL.findOne({ email: sanitizedEmail }); if (existingUser) throw new BadRequestError({ name: "Instance initialization", message: "User already exists" }); const userInfo = await userDAL.transaction(async (tx) => { @@ -361,8 +363,8 @@ export const superAdminServiceFactory = ({ { firstName: "Admin", lastName: "User", - username: email, - email, + username: sanitizedEmail, + email: sanitizedEmail, superAdmin: true, isGhost: false, isAccepted: true, @@ -372,7 +374,7 @@ export const superAdminServiceFactory = ({ tx ); const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(password); - const encKeys = await generateUserSrpKeys(email, password); + const encKeys = await generateUserSrpKeys(sanitizedEmail, password); const userEnc = await userDAL.createUserEncryption( { diff --git a/backend/src/services/user/user-dal.ts b/backend/src/services/user/user-dal.ts index eba497f0f..b5a29fc8c 100644 --- a/backend/src/services/user/user-dal.ts +++ b/backend/src/services/user/user-dal.ts @@ -8,16 +8,18 @@ import { TUserEncryptionKeys, TUserEncryptionKeysInsert, TUserEncryptionKeysUpdate, - TUsers + TUsers, + UsersSchema } from "@app/db/schemas"; import { DatabaseError } from "@app/lib/errors"; -import { ormify, selectAllTableCols } from "@app/lib/knex"; +import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex"; export type TUserDALFactory = ReturnType; export const userDALFactory = (db: TDbClient) => { const userOrm = ormify(db, TableName.Users); - const findUserByUsername = async (username: string, tx?: Knex) => userOrm.findOne({ username }, tx); + const findUserByUsername = async (username: string, tx?: Knex) => + (tx || db)(TableName.Users).whereRaw('lower("username") = :username', { username: username.toLowerCase() }); const getUsersByFilter = async ({ limit, @@ -41,7 +43,7 @@ export const userDALFactory = (db: TDbClient) => { .whereILike("email", `%${searchTerm}%`) .orWhereILike("firstName", `%${searchTerm}%`) .orWhereILike("lastName", `%${searchTerm}%`) - .orWhereLike("username", `%${searchTerm}%`); + .orWhereRaw('lower("username") like ?', `%${searchTerm}%`); }); } @@ -65,12 +67,11 @@ export const userDALFactory = (db: TDbClient) => { try { return await db .replicaNode()(TableName.Users) + .whereRaw('lower("username") = :username', { username: username.toLowerCase() }) .where({ - username, isGhost: false }) - .join(TableName.UserEncryptionKey, `${TableName.Users}.id`, `${TableName.UserEncryptionKey}.userId`) - .first(); + .join(TableName.UserEncryptionKey, `${TableName.Users}.id`, `${TableName.UserEncryptionKey}.userId`); } catch (error) { throw new DatabaseError({ error, name: "Find user enc by email" }); } @@ -168,6 +169,38 @@ export const userDALFactory = (db: TDbClient) => { } }; + const findAllMyAccounts = async (email: string) => { + try { + const doc = await db(TableName.Users) + .where({ email }) + .leftJoin(TableName.OrgMembership, `${TableName.OrgMembership}.userId`, `${TableName.Users}.id`) + .leftJoin(TableName.Organization, `${TableName.Organization}.id`, `${TableName.OrgMembership}.orgId`) + .select(selectAllTableCols(TableName.Users)) + .select( + db.ref("name").withSchema(TableName.Organization).as("orgName"), + db.ref("slug").withSchema(TableName.Organization).as("orgSlug") + ); + const formattedDoc = sqlNestRelationships({ + data: doc, + key: "id", + parentMapper: (el) => UsersSchema.parse(el), + childrenMapper: [ + { + key: "orgSlug", + label: "organizations" as const, + mapper: ({ orgSlug, orgName }) => ({ + slug: orgSlug, + name: orgName + }) + } + ] + }); + return formattedDoc; + } catch (error) { + throw new DatabaseError({ error, name: "Upsert user enc key" }); + } + }; + // USER ACTION FUNCTIONS // --------------------- const findOneUserAction = (filter: TUserActionsUpdate, tx?: Knex) => { @@ -200,6 +233,7 @@ export const userDALFactory = (db: TDbClient) => { createUserEncryption, findOneUserAction, createUserAction, - getUsersByFilter + getUsersByFilter, + findAllMyAccounts }; }; diff --git a/backend/src/services/user/user-service.ts b/backend/src/services/user/user-service.ts index 5da5d493c..29f6300d6 100644 --- a/backend/src/services/user/user-service.ts +++ b/backend/src/services/user/user-service.ts @@ -9,7 +9,6 @@ import { TAuthTokenServiceFactory } from "@app/services/auth-token/auth-token-se import { TokenType } from "@app/services/auth-token/auth-token-types"; import { TOrgMembershipDALFactory } from "@app/services/org-membership/org-membership-dal"; import { SmtpTemplates, TSmtpService } from "@app/services/smtp/smtp-service"; -import { TUserAliasDALFactory } from "@app/services/user-alias/user-alias-dal"; import { AuthMethod } from "../auth/auth-type"; import { TGroupProjectDALFactory } from "../group-project/group-project-dal"; @@ -21,7 +20,7 @@ type TUserServiceFactoryDep = { userDAL: Pick< TUserDALFactory, | "find" - | "findOne" + | "findUserByUsername" | "findById" | "transaction" | "updateById" @@ -31,8 +30,8 @@ type TUserServiceFactoryDep = { | "createUserAction" | "findUserEncKeyByUserId" | "delete" + | "findAllMyAccounts" >; - userAliasDAL: Pick; groupProjectDAL: Pick; orgMembershipDAL: Pick; tokenService: Pick; @@ -45,7 +44,6 @@ export type TUserServiceFactory = ReturnType; export const userServiceFactory = ({ userDAL, - userAliasDAL, orgMembershipDAL, projectMembershipDAL, groupProjectDAL, @@ -54,8 +52,11 @@ export const userServiceFactory = ({ permissionService }: TUserServiceFactoryDep) => { const sendEmailVerificationCode = async (username: string) => { - const user = await userDAL.findOne({ username }); + // akhilmhdh: case sensitive email resolution + const users = await userDAL.findUserByUsername(username); + const user = users?.length > 1 ? users.find((el) => el.username === username) : users?.[0]; if (!user) throw new NotFoundError({ name: `User with username '${username}' not found` }); + if (!user.email) throw new BadRequestError({ name: "Failed to send email verification code due to no email on user" }); if (user.isEmailVerified) @@ -77,7 +78,10 @@ export const userServiceFactory = ({ }; const verifyEmailVerificationCode = async (username: string, code: string) => { - const user = await userDAL.findOne({ username }); + // akhilmhdh: case sensitive email resolution + const usersByusername = await userDAL.findUserByUsername(username); + const user = + usersByusername?.length > 1 ? usersByusername.find((el) => el.username === username) : usersByusername?.[0]; if (!user) throw new NotFoundError({ name: `User with username '${username}' not found` }); if (!user.email) throw new BadRequestError({ name: "Failed to verify email verification code due to no email on user" }); @@ -90,84 +94,8 @@ export const userServiceFactory = ({ code }); - const { email } = user; - - await userDAL.transaction(async (tx) => { - await userDAL.updateById( - user.id, - { - isEmailVerified: true - }, - tx - ); - - // check if there are verified users with the same email. - const users = await userDAL.find( - { - email, - isEmailVerified: true - }, - { tx } - ); - - if (users.length > 1) { - // merge users - const mergeUser = users.find((u) => u.id !== user.id); - if (!mergeUser) throw new NotFoundError({ name: "Failed to find merge user" }); - - const mergeUserOrgMembershipSet = new Set( - (await orgMembershipDAL.find({ userId: mergeUser.id }, { tx })).map((m) => m.orgId) - ); - const myOrgMemberships = (await orgMembershipDAL.find({ userId: user.id }, { tx })).filter( - (m) => !mergeUserOrgMembershipSet.has(m.orgId) - ); - - const userAliases = await userAliasDAL.find( - { - userId: user.id - }, - { tx } - ); - await userDAL.deleteById(user.id, tx); - - if (myOrgMemberships.length) { - await orgMembershipDAL.insertMany( - myOrgMemberships.map((orgMembership) => ({ - ...orgMembership, - userId: mergeUser.id - })), - tx - ); - } - - if (userAliases.length) { - await userAliasDAL.insertMany( - userAliases.map((userAlias) => ({ - ...userAlias, - userId: mergeUser.id - })), - tx - ); - } - } else { - await userDAL.delete( - { - email, - isAccepted: false, - isEmailVerified: false - }, - tx - ); - - // update current user's username to [email] - await userDAL.updateById( - user.id, - { - username: email - }, - tx - ); - } + await userDAL.updateById(user.id, { + isEmailVerified: true }); }; @@ -212,6 +140,23 @@ export const userServiceFactory = ({ return updatedUser; }; + const getAllMyAccounts = async (email: string, userId: string) => { + const users = await userDAL.findAllMyAccounts(email); + return users?.map((el) => ({ ...el, isMyAccount: el.id === userId })); + }; + + const removeMyDuplicateAccounts = async (email: string, userId: string) => { + const users = await userDAL.find({ email }); + const duplicatedAccounts = users?.filter((el) => el.id !== userId); + const myAccount = users?.find((el) => el.id === userId); + if (duplicatedAccounts.length && myAccount) { + await userDAL.transaction(async (tx) => { + await userDAL.delete({ $in: { id: duplicatedAccounts?.map((el) => el.id) } }, tx); + await userDAL.updateById(userId, { username: (myAccount.email || myAccount.username).toLowerCase() }, tx); + }); + } + }; + const getMe = async (userId: string) => { const user = await userDAL.findUserEncKeyByUserId(userId); if (!user) throw new NotFoundError({ message: `User with ID '${userId}' not found`, name: "GetMe" }); @@ -313,9 +258,11 @@ export const userServiceFactory = ({ }; const listUserGroups = async ({ username, actorOrgId, actor, actorId, actorAuthMethod }: TListUserGroupsDTO) => { - const user = await userDAL.findOne({ - username - }); + // akhilmhdh: case sensitive email resolution + const usersByusername = await userDAL.findUserByUsername(username); + const user = + usersByusername?.length > 1 ? usersByusername.find((el) => el.username === username) : usersByusername?.[0]; + if (!user) throw new NotFoundError({ name: `User with username '${username}' not found` }); // This makes it so the user can always read information about themselves, but no one else if they don't have the Members Read permission. if (user.id !== actorId) { @@ -346,7 +293,9 @@ export const userServiceFactory = ({ getUserAction, unlockUser, getUserPrivateKey, + getAllMyAccounts, getUserProjectFavorites, + removeMyDuplicateAccounts, updateUserProjectFavorites }; }; diff --git a/cli/packages/cmd/agent.go b/cli/packages/cmd/agent.go index b14fd04e2..445941674 100644 --- a/cli/packages/cmd/agent.go +++ b/cli/packages/cmd/agent.go @@ -884,6 +884,12 @@ func (tm *AgentManager) MonitorSecretChanges(secretTemplate Template, templateId if err != nil { log.Error().Msgf("unable to process template because %v", err) + + // case: if exit-after-auth is true, it should exit the agent once an error on secret fetching occurs with the appropriate exit code (1) + // previous behavior would exit after 25 sec with status code 0, even if this step errors + if tm.exitAfterAuth { + os.Exit(1) + } } else { if (existingEtag != currentEtag) || firstRun { diff --git a/company/handbook/spending-money.mdx b/company/handbook/spending-money.mdx index 1e32aeaf5..864984f10 100644 --- a/company/handbook/spending-money.mdx +++ b/company/handbook/spending-money.mdx @@ -6,9 +6,14 @@ description: "The guide to spending money at Infisical." Fairly frequently, you might run into situations when you need to spend company money. - -Please spend money in a way that you think is in the best interest of the company. - + +# Expensing Meals + +As a perk of working at Infisical, we cover some of your meal expenses. + +HQ team members: meals and unlimited snacks are provided on-site at no cost. + +Remote team members: a food stipend is allocated based on location. # Trivial expenses @@ -18,6 +23,10 @@ This means expenses that are: 1. Non-recurring AND less than $75/month in total. 2. Recurring AND less than $20/month. + +Please spend money in a way that you think is in the best interest of the company. + + ## Saving receipts Make sure you keep copies for all receipts. If you expense something on a company card and cannot provide a receipt, this may be deducted from your pay. diff --git a/docs/documentation/platform/kms/hsm-integration.mdx b/docs/documentation/platform/kms/hsm-integration.mdx index a9ab2c832..33a28305f 100644 --- a/docs/documentation/platform/kms/hsm-integration.mdx +++ b/docs/documentation/platform/kms/hsm-integration.mdx @@ -38,7 +38,7 @@ Enabling HSM encryption has a set of key benefits: ### Requirements - An Infisical instance with a version number that is equal to or greater than `v0.91.0`. - If you are using Docker, your instance must be using the `infisical/infisical-fips` image. -- An HSM device from a provider such as [Thales Luna HSM](https://cpl.thalesgroup.com/encryption/data-protection-on-demand/services/luna-cloud-hsm), [AWS CloudHSM](https://aws.amazon.com/cloudhsm/), or others. +- An HSM device from a provider such as [Thales Luna HSM](https://cpl.thalesgroup.com/encryption/data-protection-on-demand/services/luna-cloud-hsm), [AWS CloudHSM](https://aws.amazon.com/cloudhsm/), [Fortanix HSM](https://www.fortanix.com/platform/data-security-manager), or others. ### FIPS Compliance @@ -53,14 +53,14 @@ For organizations that work with US government agencies, FIPS compliance is almo - To set up HSM encryption, you need to configure an HSM provider and HSM key. The HSM provider is used to connect to the HSM device, and the HSM key is used to encrypt Infisical's KMS keys. We recommend using a Cloud HSM provider such as [Thales Luna HSM](https://cpl.thalesgroup.com/encryption/data-protection-on-demand/services/luna-cloud-hsm) or [AWS CloudHSM](https://aws.amazon.com/cloudhsm/). + To set up HSM encryption, you need to configure an HSM provider and HSM key. The HSM provider is used to connect to the HSM device, and the HSM key is used to encrypt Infisical's KMS keys. We recommend using a Cloud HSM provider such as [Thales Luna HSM](https://cpl.thalesgroup.com/encryption/data-protection-on-demand/services/luna-cloud-hsm), [AWS CloudHSM](https://aws.amazon.com/cloudhsm/), or [Fortanix HSM](https://www.fortanix.com/platform/data-security-manager). You need to follow the instructions provided by the HSM provider to set up the HSM device. Once the HSM device is set up, the HSM device can be used within Infisical. After setting up the HSM from your provider, you will have a set of files that you can use to access the HSM. These files need to be present on the machine where Infisical is running. If you are using containers, you will need to mount the folder where these files are stored as a volume in the container. - The setup process for an HSM device varies depending on the provider. We have created a guide for Thales Luna Cloud HSM, which you can find below. + The setup process for an HSM device varies depending on the provider. We have created guides for Thales Luna Cloud HSM and Fortanix HSM, which you can find below. @@ -255,6 +255,78 @@ For organizations that work with US government agencies, FIPS compliance is almo After following these steps, your Docker setup will be ready to use HSM encryption. + + + + To use Fortanix HSM with Infisical, you need to: + + 1. Create an App in Fortanix: + - Set Interface value to be PKCS#11 + - Select API key as authentication method + - Assign app to a group + + ![Fortanix HSM Setup](/images/platform/kms/hsm/fortanix-hsm-setup.png) + + 2. Take note of the domain (e.g., apac.smartkey.io). You will need this to set up the configuration file for the Fortanix client. + + + + The easiest approach would be to download the `.so` file for Linux directly from the [Fortanix PKCS#11 installation page](https://fortanix.zendesk.com/hc/en-us/sections/4408769080724-PKCS-11). + + Create a configuration file named `pkcs11.conf` with the following content: + + ``` + api_endpoint = "https://apac.smartkey.io" + prevent_duplicate_opaque_objects = true + retry_timeout_millis = 60000 + ``` + + Note: Replace `apac.smartkey.io` with your actual Fortanix domain if different. For more details about the configuration file format and additional options, refer to the [Fortanix PKCS#11 Configuration File Documentation](https://support.fortanix.com/docs/clients-pkcs11-library#511-configuration-file-format). + + + + Create a directory to store the Fortanix library and configuration file: + + ```bash + mkdir -p /etc/fortanix-hsm + ``` + + Copy the downloaded `.so` file and the `pkcs11.conf` file to this directory: + + ```bash + cp /path/to/fortanix_pkcs11_4.37.2554.so /etc/fortanix-hsm/ + cp /path/to/pkcs11.conf /etc/fortanix-hsm/ + ``` + + + + Run Docker with Fortanix HSM by mounting the directory and setting the required environment variables: + + ```bash + docker run -p 80:8080 \ + -v /etc/fortanix-hsm:/etc/fortanix-hsm \ + -e HSM_LIB_PATH="/etc/fortanix-hsm/fortanix_pkcs11_4.37.2554.so" \ # Path to the PKCS#11 library + -e HSM_PIN="MDE3YWUxO..." \ # Your Fortanix app API key used for authentication + -e HSM_SLOT=0 \ # Slot value (arbitrary for Fortanix HSM) + -e HSM_KEY_LABEL="hsm-key-label" \ # Label to identify the encryption key in the HSM + -e FORTANIX_PKCS11_CONFIG_PATH="/etc/fortanix-hsm/pkcs11.conf" \ # Path to Fortanix configuration file + + # The rest are unrelated to HSM setup... + -e ENCRYPTION_KEY="<>" \ + -e AUTH_SECRET="<>" \ + -e DB_CONNECTION_URI="<>" \ + -e REDIS_URL="<>" \ + -e SITE_URL="<>" \ + infisical/infisical-fips: # Replace with the version you want to use + ``` + + + Note: Fortanix HSM integration only works for AMD64 CPU architectures. + + + + After following these steps, your Docker setup will be ready to use Fortanix HSM encryption. + @@ -569,6 +641,173 @@ For organizations that work with US government agencies, FIPS compliance is almo After following these steps, your Kubernetes setup will be ready to use HSM encryption. + + + + First, you need to set up Fortanix HSM by: + + 1. Creating an App in Fortanix: + - Set Interface value to be PKCS#11 + - Select API key as authentication method + - Assign app to a group + + ![Fortanix HSM Setup](/images/platform/kms/hsm/fortanix-hsm-setup.png) + + 2. Take note of the domain (e.g., apac.smartkey.io). You will need this when setting up the configuration file. + + + + Create a directory to store the Fortanix configuration files: + + ```bash + mkdir -p /etc/fortanix-hsm + ``` + + Download the Fortanix PKCS#11 library for Linux from the [Fortanix PKCS#11 installation page](https://fortanix.zendesk.com/hc/en-us/sections/4408769080724-PKCS-11). + + Create a configuration file named `pkcs11.conf` with the following content: + + ``` + api_endpoint = "https://apac.smartkey.io" + prevent_duplicate_opaque_objects = true + retry_timeout_millis = 60000 + ``` + + Note: Replace `apac.smartkey.io` with your actual Fortanix domain if different. + + + + Create a Persistent Volume Claim to store the Fortanix files: + + ```bash + kubectl apply -f - < + + + Update your Kubernetes secret with the Fortanix HSM environment variables: + + ```yaml + apiVersion: v1 + kind: Secret + metadata: + name: infisical-secrets + type: Opaque + stringData: + # ... Other environment variables ... + HSM_LIB_PATH: "/etc/fortanix-hsm/fortanix_pkcs11_4.37.2554.so" # Path to the PKCS#11 library in the container + HSM_PIN: "" # Your Fortanix app API key used for authentication + HSM_SLOT: "0" # Slot value (can be set to 0 for Fortanix HSM as it's arbitrary) + HSM_KEY_LABEL: "hsm-key-label" # Label to identify the encryption key in the HSM + FORTANIX_PKCS11_CONFIG_PATH: "/etc/fortanix-hsm/pkcs11.conf" # Path to Fortanix configuration file + ``` + + Apply the updated secret: + + ```bash + kubectl apply -f ./secret-file-name.yaml + ``` + + + + Update your Helm values to use the FIPS-compliant image and mount the Fortanix HSM files: + + ```yaml + # ... The rest of the values.yaml file ... + + image: + repository: infisical/infisical-fips # Must use "infisical/infisical-fips" + tag: "v0.117.1-postgres" + pullPolicy: IfNotPresent + + extraVolumeMounts: + - name: fortanix-data + mountPath: /etc/fortanix-hsm # The path where Fortanix files will be available + + extraVolumes: + - name: fortanix-data + persistentVolumeClaim: + claimName: fortanix-hsm-pvc + + # ... The rest of the values.yaml file ... + ``` + + + Note: Fortanix HSM integration only works for AMD64 CPU architectures. + + + + + Upgrade the Helm chart with the new values: + + ```bash + helm upgrade --install infisical infisical-helm-charts/infisical-standalone --values /path/to/values.yaml + ``` + + Restart the deployment: + + ```bash + kubectl rollout restart deployment/infisical-infisical + ``` + + + After following these steps, your Kubernetes setup will be ready to use Fortanix HSM encryption. + diff --git a/docs/documentation/platform/organization.mdx b/docs/documentation/platform/organization.mdx index 3a53484fb..6c3b218ab 100644 --- a/docs/documentation/platform/organization.mdx +++ b/docs/documentation/platform/organization.mdx @@ -20,6 +20,7 @@ The **Settings** page lets you manage information about your organization includ - **Slug**: The slug of your organization. - **Default Organization Member Role**: The role assigned to users when joining your organization unless otherwise specified. - **Incident Contacts**: Emails that should be alerted if anything abnormal is detected within the organization. +- **Enabled Products**: Products which are enabled for your organization. This setting strictly affects the sidebar UI; disabling a product does not disable its API or routes. ![organization settings general](../../images/platform/organization/organization-settings-general.png) @@ -43,7 +44,7 @@ In the **Organization Roles** tab, you can edit current or create new custom rol Note that Role-Based Access Management (RBAC) is partly a paid feature. - + Infisical provides immutable roles like `admin`, `member`, etc. at the organization and project level for free. diff --git a/docs/documentation/platform/secret-rotation/ldap-password.mdx b/docs/documentation/platform/secret-rotation/ldap-password.mdx index 103fe4656..feb3a664d 100644 --- a/docs/documentation/platform/secret-rotation/ldap-password.mdx +++ b/docs/documentation/platform/secret-rotation/ldap-password.mdx @@ -28,7 +28,7 @@ description: "Learn how to automatically rotate LDAP passwords." 3. Select the **LDAP Connection** to use and configure the rotation behavior. Then click **Next**. ![Rotation Configuration](/images/secret-rotations-v2/ldap-password/ldap-password-configuration.png) - - **LDAP Connection** - the connection that will perform the rotation of the configured DN's password. + - **LDAP Connection** - the connection that will perform the rotation of the configured principal's password. LDAP Password Rotations require an LDAP Connection that uses ldaps:// protocol. @@ -40,13 +40,20 @@ description: "Learn how to automatically rotate LDAP passwords." - 4. Specify the Distinguished Name (DN) of the principal whose password you want to rotate and configure the password requirements. Then click **Next**. + 4. Configure the required Parameters for your rotation. Then click **Next**. ![Rotation Parameters](/images/secret-rotations-v2/ldap-password/ldap-password-parameters.png) + - **Rotation Method** - The method to use when rotating the target principal's password. + - **Connection Principal** - Infisical will use the LDAP Connection's binding principal to rotate the target principal's password. + - **Target Principal** - Infisical will bind with the target Principal to rotate their own password. + - **DN/UPN** - The Distinguished Name (DN), or User Principal Name (UPN) if supported, of the principal whose password you want to rotate. + - **Password** - The target principal's password (if **Rotation Method** is set to **Target Principal**). + - **Password Requirements** - The constraints to apply when generating new passwords. + 5. Specify the secret names that the client credentials should be mapped to. Then click **Next**. ![Rotation Secrets Mapping](/images/secret-rotations-v2/ldap-password/ldap-password-secrets-mapping.png) - - **DN** - the name of the secret that the principal's Distinguished Name (DN) will be mapped to. + - **DN/UPN** - the name of the secret that the principal's Distinguished Name (DN) or User Principal Name (UPN) will be mapped to. - **Password** - the name of the secret that the rotated password will be mapped to. 6. Give your rotation a name and description (optional). Then click **Next**. @@ -85,6 +92,7 @@ description: "Learn how to automatically rotate LDAP passwords." "minutes": 0 }, "parameters": { + "rotationMethod": "connection-principal", "dn": "CN=John,CN=Users,DC=example,DC=com", "passwordRequirements": { "length": 48, @@ -154,6 +162,7 @@ description: "Learn how to automatically rotate LDAP passwords." "lastRotationMessage": null, "type": "ldap-password", "parameters": { + "rotationMethod": "connection-principal", "dn": "CN=John,CN=Users,DC=example,DC=com", "passwordRequirements": { "length": 48, diff --git a/docs/images/platform/kms/hsm/fortanix-hsm-setup.png b/docs/images/platform/kms/hsm/fortanix-hsm-setup.png new file mode 100644 index 000000000..7465e1296 Binary files /dev/null and b/docs/images/platform/kms/hsm/fortanix-hsm-setup.png differ diff --git a/docs/images/platform/organization/organization-settings-general.png b/docs/images/platform/organization/organization-settings-general.png index affcf32ff..9467b6005 100644 Binary files a/docs/images/platform/organization/organization-settings-general.png and b/docs/images/platform/organization/organization-settings-general.png differ diff --git a/docs/images/secret-rotations-v2/ldap-password/ldap-password-confirm.png b/docs/images/secret-rotations-v2/ldap-password/ldap-password-confirm.png index 1725c4355..707736095 100644 Binary files a/docs/images/secret-rotations-v2/ldap-password/ldap-password-confirm.png and b/docs/images/secret-rotations-v2/ldap-password/ldap-password-confirm.png differ diff --git a/docs/images/secret-rotations-v2/ldap-password/ldap-password-parameters.png b/docs/images/secret-rotations-v2/ldap-password/ldap-password-parameters.png index dfe723b06..8dbfb8ddf 100644 Binary files a/docs/images/secret-rotations-v2/ldap-password/ldap-password-parameters.png and b/docs/images/secret-rotations-v2/ldap-password/ldap-password-parameters.png differ diff --git a/docs/integrations/app-connections/ldap.mdx b/docs/integrations/app-connections/ldap.mdx index 63c4bfed1..db0b596ce 100644 --- a/docs/integrations/app-connections/ldap.mdx +++ b/docs/integrations/app-connections/ldap.mdx @@ -10,7 +10,7 @@ Infisical supports the use of [Simple Binding](https://ldap.com/the-ldap-bind-op You will need the following information to establish an LDAP connection: - **LDAP URL** - The LDAP/LDAPS URL to connect to (e.g., ldap://domain-or-ip:389 or ldaps://domain-or-ip:636) -- **Binding DN** - The Distinguished Name (DN) of the principal to bind with (e.g., 'CN=John,CN=Users,DC=example,DC=com') +- **Binding DN/UPN** - The Distinguished Name (DN), or User Principal Name (UPN) if supported, of the principal to bind with (e.g., 'CN=John,CN=Users,DC=example,DC=com') - **Binding Password** - The password to bind with for authentication - **CA Certificate** - The SSL certificate (PEM format) to use for secure connection when using ldaps:// with a self-signed certificate diff --git a/docs/integrations/platforms/kubernetes-csi.mdx b/docs/integrations/platforms/kubernetes-csi.mdx index 88df9585c..da1d4d019 100644 --- a/docs/integrations/platforms/kubernetes-csi.mdx +++ b/docs/integrations/platforms/kubernetes-csi.mdx @@ -1,6 +1,6 @@ --- title: "Kubernetes CSI" -description: "How to use Infisical to inject secrets directly into Kubernetes pods." +description: "How to use the Infisical Kubernetes CSI provider to inject secrets directly into Kubernetes pods." --- ## Overview @@ -15,9 +15,9 @@ flowchart LR CSP --> CSD(Secrets Store CSI Driver) end - subgraph Application + subgraph Pod CSD --> V(Volume) - V <--> P(Pod) + V <--> P(Application) end ``` diff --git a/docs/integrations/platforms/kubernetes-injector.mdx b/docs/integrations/platforms/kubernetes-injector.mdx new file mode 100644 index 000000000..aacdcfbbb --- /dev/null +++ b/docs/integrations/platforms/kubernetes-injector.mdx @@ -0,0 +1,317 @@ +--- +title: "Kubernetes Agent Injector" +description: "How to use the Infisical Kubernetes Agent Injector to inject secrets directly into Kubernetes pods." +--- + +## Overview + +The Infisical Kubernetes Agent Injector allows you to inject secrets directly into your Kubernetes pods. The Injector will create a [Infisical Agent](/integrations/platforms/infisical-agent) container within your pod that syncs secrets from Infisical into a shared volume mount within your pod. + + +The Infisical Agent Injector will patch and modify your pod's deployment to contain an [Infisical Agent](/integrations/platforms/infisical-agent) container which renders your Infisical secrets into a shared volume mount within your pod. + +The Infisical Agent Injector is built on [Kubernetes Mutating Admission Webhooks](https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers), and will watch for `CREATE` and `UPDATE` events on pods in your cluster. +The injector is namespace-agnostic, and will watch for pods in any namespace, but will only patch pods that have the `org.infisical.com/inject` annotation set to `true`. + + +```mermaid +flowchart LR + subgraph Secrets Management + SS(Infisical) --> INJ(Infisical Injector) + end + + subgraph Pod + INJ --> INIT(Agent Init Container) + INIT --> V(Volume) + V <--> P(Application) + end + +``` + +## Install the Infisical Agent Injector + +To install the Infisical Agent Injector, you will need to install our helm charts using [Helm](https://helm.sh/). + +```bash +helm repo add infisical-helm-charts 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/' +helm repo update +helm install --generate-name infisical-helm-charts/infisical-agent-injector +``` + +After installing the helm chart you can verify that the injector is running and working as intended by checking the logs of the injector pod. +```bash +$ kubectl logs deployment/infisical-agent-injector +2025/05/19 14:20:05 Starting infisical-agent-injector... +2025/05/19 14:20:05 Generating self-signed certificate... +2025/05/19 14:20:06 Creating directory: /tmp/tls +2025/05/19 14:20:06 Writing cert to: /tmp/tls/tls.crt +2025/05/19 14:20:06 Writing key to: /tmp/tls/tls.key +2025/05/19 14:20:06 Starting HTTPS server on port 8585... +2025/05/19 14:20:06 Attempting to update webhook config (attempt 1)... +2025/05/19 14:20:06 Successfully updated webhook configuration with CA bundle +``` + +## Supported annotations + +The Infisical Agent Injector supports the following annotations: + + + The inject annotation is used to enable the injector on a pod. Set the value to `true` and the pod will be patched with an Infisical Agent container on update or create. + + + The inject mode annotation is used to specify the mode to use to inject the secrets into the pod. Currently only `init` mode is supported. + + - `init`: The init method will create an init container for the pod that will render the secrets into a shared volume mount within the pod. The agent init container will run before any other containers in the pod runs, including other init containers. + + + The agent config map annotation is used to specify the name of the config map that contains the configuration for the injector. The config map must be in the same namespace as the pod. + + +## ConfigMap Configuration + +### Supported Fields + +When you are configuring a pod to use the injector, you must create a config map in the same namespace as the pod you want to inject secrets into. +The entire config needs to be of string format and needs to be assigned to the `config.yaml` key in the config map. You can find a full example of the config at the end of this section. + + + The address of your Infisical instance. This field is optional and will default to `https://app.infisical.com` if not provided. + + + + The authentication type to use to connect to Infisical. Currently only the `kubernetes` authentication type is supported. + You can refer to our [Kubernetes Auth](/documentation/platform/identities/kubernetes-auth) documentation for more information on how to create a machine identity for Kubernetes Auth. + Please note that the pod's default service account will be used to authenticate with Infisical. + + + + The ID of the machine identity to use to connect to Infisical. This field is required if the `infisical.auth.type` is set to `kubernetes`. + + + +The templates hold an array of templates that will be rendered and injected into the pod. + + + + The path to inject the secrets into within the pod. + If not specified, this will default to `/shared/infisical-secrets`. If you have multiple templates and don't provide a destination path, the destination paths will default to `/shared/infisical-secrets-1`, `/shared/infisical-secrets-2`, etc. + + + + The content of the template to render. + This will be rendered as a [Go Template](https://pkg.go.dev/text/template) and will have access to the following variables. + It follows the templating format and supports the same functions as the [Infisical Agent](/integrations/platforms/infisical-agent#quick-start-infisical-agent) + + + +### Authentication +The Infisical Agent Injector only supports Machine Identity [Kubernetes Auth](/documentation/platform/identities/kubernetes-auth) authentication at the moment. + +To configure Kubernetes Auth, you need to set the `auth.type` field to `kubernetes` and set the `auth.config.identity-id` to the ID of the machine identity you wish to use for authentication. + +```yaml +auth: + type: "kubernetes" + config: + identity-id: "" +``` + +### Example ConfigMap +```yaml config-map.yaml +apiVersion: v1 +kind: ConfigMap +metadata: + name: demo-config-map +data: + config.yaml: | + infisical: + address: "https://app.infisical.com" + auth: + type: "kubernetes" + config: + identity-id: "" + templates: + - destination-path: "/path/to/save/secrets/file.txt" + template-content: | + {{- with secret "" "dev" "/" }} + {{- range . }} + {{ .Key }}={{ .Value }} + {{- end }} + {{- end }} +``` + +```bash +kubectl apply -f config-map.yaml +``` + +To use the config map in your pod, you will need to add the `org.infisical.com/agent-config-map` annotation to your pod's deployment. The value of the annotation is the name of the config map you created above. +```yaml +apiVersion: v1 +kind: Pod +metadata: + name: demo + labels: + app: demo + annotations: + org.infisical.com/inject: "true" # Set to true for the injector to patch the pod on create/update events + org.infisical.com/inject-mode: "init" # The mode to use to inject the secrets into the pod. Currently only `init` mode is supported. + org.infisical.com/agent-config-map: "name-of-config-map" # The name of the config map that you created above, which contains all the settings for injecting the secrets into the pod +spec: + # ... +``` + + +## Quick Start +In this section we'll walk through a full example of how to inject secrets into a pod using the Infisical Agent Injector. +In this example we'll create a basic nginx deployment and print a Infisical secret called `API_KEY` to the container logs. + +### Create secrets in Infisical +First you'll need to create the secret in Infisical. + +- `API_KEY`: The API key to use for the nginx deployment. + +Once you've created the secret, save your project ID, environment slug, and secret path, as these will be used in the next step. + +### Configuration +To use the injector you must create a config map in the same namespace as the pod you want to inject secrets into. In this example we'll create a config map in the `test-namespace` namespace. + +The agent injector will authenticate with Infisical using a [Kubernetes Auth](/documentation/platform/identities/kubernetes-auth) machine identity. Please follow the [instructions](/documentation/platform/identities/kubernetes-auth) to create a machine identity configured for Kubernetes Auth. +The agent injector will use the service account token of the pod to authenticate with Infisical. + +The `template-content` will be rendered as a [Go Template](https://pkg.go.dev/text/template) and will have access to the following variables. It follows the templating format and supports the same functions as the [Infisical Agent](/integrations/platforms/infisical-agent#quick-start-infisical-agent) +The `destination-path` refers to the path within the pod that the secrets will be injected into. In this case we're injecting the secrets into a file called `/infisical/secrets`. + + +Replace the ``, ``, with your project ID and the environment slug of where you created your secrets in Infisical. Replace `` with the ID of your machine identity configured for Kubernetes Auth. +```yaml config-map.yaml +apiVersion: v1 +kind: ConfigMap +metadata: + name: nginx-infisical-config-map + namespace: test-namespace +data: + config.yaml: | + infisical: + address: "https://app.infisical.com" + auth: + type: "kubernetes" + config: + identity-id: "" + templates: + - destination-path: "/infisical/secrets" + template-content: | + {{- with secret "" "" "/" }} + {{- range . }} + {{ .Key }}={{ .Value }} + {{- end }} + {{- end }} +``` + +Now apply the config map: +```bash +kubectl apply -f config-map.yaml +``` + +### Injecting secrets into your pod + +To inject secrets into your pod, you will need to add the `org.infisical.com/inject: "true"` annotation to your pod's deployment. + +The `org.infisical.com/agent-config-map` annotation will point to the config map we created in the previous step. It's important that the config map is in the same namespace as the pod. + +We are creating a nginx deployment with a PVC to store the database data. + +```yaml nginx.yaml +--- +apiVersion: v1 +kind: Pod +metadata: + name: nginx-pod + namespace: test-namespace + labels: + app: nginx + annotations: + org.infisical.com/inject: "true" + org.infisical.com/inject-mode: "init" + org.infisical.com/agent-config-map: "nginx-infisical-config-map" +spec: + containers: + - name: simple-app-demo + image: nginx:alpine + command: ["/bin/sh", "-c"] + args: + - | + export $(cat /infisical/secrets | xargs) + echo "API_KEY is set to: $API_KEY" + nginx -g "daemon off;" +``` + +### Applying the deployment + +To apply the deployment, you can use the following command: + +```bash +kubectl apply -f nginx.yaml +``` +It may take a few minutes for the pod to be ready and for the Infisical secrets to be injected. You can check the status of the pod by running: + +```bash +kubectl get pods -n test-namespace +``` + +### Verifying the secrets are injected + +To verify the secrets are injected, you can check the pod's logs: + +```bash +$ kubectl exec -it pod/nginx-pod -n test-namespace -- cat /infisical/secrets + +Defaulted container "simple-app-demo" out of: simple-app-demo, infisical-agent-init (init) + +API_KEY=sk_api_... # The secret you created in Infisical +``` + +Additionally you can now check that the `API_KEY` secret is being logged to the nginx container logs: +```bash +$ kubectl logs pod/nginx-pod -n test-namespace +Defaulted container "simple-app-demo" out of: simple-app-demo, infisical-agent-init (init) +API_KEY is set to: sk_api_... # The secret you created in Infisical +``` + + +## Troubleshooting + + + + If the pod is stuck in `Init` state, it means the Agent init container is failing to start or is stuck in a restart loop. + This could be due to a number of reasons, such as the machine identity not having the correct permissions, or trying to fetch secrets from a non-existent project/environment. + + You can check the logs of the infisical init container by running: + ```bash + # For deployments + kubectl logs deployment/your-deployment-name -c infisical-agent-init -n "" + + # For pods + kubectl logs pod/your-pod-name -c infisical-agent-init -n "" + ``` + + You can also check the logs of the pod by running: + ```bash + kubectl logs deployment/postgres-deployment -n test-namespace + ``` + + When checking the logs of the agent init container, you may see something like the following: + ```bash + Starting infisical agent... + 11:10AM INF starting Infisical agent... + 11:10AM INF Infisical instance address set to https://daniel1.tunn.dev + 11:10AM INF template engine started for template 1... + 11:10AM INF attempting to authenticate... + 11:10AM INF new access token saved to file at path '/home/infisical/config/identity-access-token' + 11:10AM ERR unable to process template because template: literalTemplate:1:9: executing "literalTemplate" at : error calling secret: CallGetRawSecretsV3: Unsuccessful response [GET https://daniel1.tunn.dev/api/v3/secrets/raw?environment=dev&expandSecretReferences=true&include_imports=true&secretPath=%2F&workspaceId=3c0d3ff6-165c-4dc9-b52c-ff3ffaedfce311111] [status-code=404] [response={"reqId":"req-ljqNq567jchFrK","statusCode":404,"message":"Project with ID '3c0d3ff6-165c-4dc9-b52c-ff3ffaedfce311111' not found during bot lookup. Are you sure you are using the correct project ID?","error":"NotFound"}] + + echo 'Agent failed with exit code 1' + + exit 1 + Agent failed with exit code 1 + ``` + + In the above error, the project ID was invalid in the config map. + \ No newline at end of file diff --git a/docs/internals/bug-bounty.mdx b/docs/internals/bug-bounty.mdx index e45de05bf..2dc4cd662 100644 --- a/docs/internals/bug-bounty.mdx +++ b/docs/internals/bug-bounty.mdx @@ -10,8 +10,10 @@ We value reports that help identify vulnerabilities that affect the integrity of ### How to Report - Send reports to **security@infisical.com** with clear steps to reproduce, impact, and (if possible) a proof-of-concept. -- We will acknowledge receipt within 3 business days. +- We will acknowledge receipt within 3 business days for reports that are clearly written, technically sound, and plausibly within scope. - We'll provide an initial assessment or next steps within 5 business days. +- **Please note**: We do not respond to spam, auto generated reports, inaccurate claims, or submissions that are clearly out of scope. + ### What's in Scope? diff --git a/docs/mint.json b/docs/mint.json index 20e8ed3b2..c8d98f1c0 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -442,6 +442,7 @@ "integrations/platforms/kubernetes/infisical-dynamic-secret-crd" ] }, + "integrations/platforms/kubernetes-injector", "integrations/platforms/kubernetes-csi", "integrations/platforms/docker-swarm-with-agent", "integrations/platforms/ecs-with-agent" diff --git a/frontend/src/components/secret-rotations-v2/ViewSecretRotationV2GeneratedCredentials/ViewLdapPasswordRotationGeneratedCredentials.tsx b/frontend/src/components/secret-rotations-v2/ViewSecretRotationV2GeneratedCredentials/ViewLdapPasswordRotationGeneratedCredentials.tsx index 238dabea3..9e1476118 100644 --- a/frontend/src/components/secret-rotations-v2/ViewSecretRotationV2GeneratedCredentials/ViewLdapPasswordRotationGeneratedCredentials.tsx +++ b/frontend/src/components/secret-rotations-v2/ViewSecretRotationV2GeneratedCredentials/ViewLdapPasswordRotationGeneratedCredentials.tsx @@ -18,9 +18,7 @@ export const ViewLdapPasswordRotationGeneratedCredentials = ({ - - {activeCredentials?.dn} - + {activeCredentials?.dn} {activeCredentials?.password} @@ -28,9 +26,7 @@ export const ViewLdapPasswordRotationGeneratedCredentials = ({ } inactiveCredentials={ <> - - {inactiveCredentials?.dn} - + {inactiveCredentials?.dn} {inactiveCredentials?.password} diff --git a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2Form.tsx b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2Form.tsx index e1c74b420..d931d9d3c 100644 --- a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2Form.tsx +++ b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2Form.tsx @@ -48,7 +48,8 @@ const FORM_TABS: { name: string; key: string; fields: (keyof TSecretRotationV2Fo "rotateAtUtc" ] }, - { name: "Parameters", key: "parameters", fields: ["parameters"] }, + // @ts-expect-error temporary parameters aren't present on all forms + { name: "Parameters", key: "parameters", fields: ["parameters", "temporaryParameters"] }, { name: "Mappings", key: "secretsMapping", fields: ["secretsMapping"] }, { name: "Details", key: "details", fields: ["name", "description"] }, { name: "Review", key: "review", fields: [] } @@ -75,7 +76,7 @@ export const SecretRotationV2Form = ({ const { rotationOption } = useSecretRotationV2Option(type); const formMethods = useForm({ - resolver: zodResolver(SecretRotationV2FormSchema), + resolver: zodResolver(SecretRotationV2FormSchema(Boolean(secretRotation))), defaultValues: secretRotation ? { ...secretRotation, diff --git a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ParametersFields/LdapPasswordRotationParametersFields.tsx b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ParametersFields/LdapPasswordRotationParametersFields.tsx index 9c9d8329f..243c18369 100644 --- a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ParametersFields/LdapPasswordRotationParametersFields.tsx +++ b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ParametersFields/LdapPasswordRotationParametersFields.tsx @@ -2,40 +2,135 @@ import { Controller, useFormContext } from "react-hook-form"; import { TSecretRotationV2Form } from "@app/components/secret-rotations-v2/forms/schemas"; import { DEFAULT_PASSWORD_REQUIREMENTS } from "@app/components/secret-rotations-v2/forms/schemas/shared"; -import { FormControl, Input } from "@app/components/v2"; +import { FormControl, Input, Select, SelectItem } from "@app/components/v2"; import { SecretRotation } from "@app/hooks/api/secretRotationsV2"; +import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation"; export const LdapPasswordRotationParametersFields = () => { - const { control } = useFormContext< + const { control, watch, setValue } = useFormContext< TSecretRotationV2Form & { type: SecretRotation.LdapPassword; } >(); + const [id, rotationMethod] = watch(["id", "parameters.rotationMethod"]); + const isUpdate = Boolean(id); + return ( <> ( + Determines how the rotation will be performed: +
    +
  • + Connection Principal - The Connection + principal will rotate the target principal's password. +
  • +
  • + Target Principal - The target principal + will rotate their own password. +
  • +
+ + } + tooltipClassName="max-w-sm" errorText={error?.message} - label="Distinguished Name (DN)" + isError={Boolean(error?.message)} + label="Rotation Method" + helperText={ + // eslint-disable-next-line no-nested-ternary + isUpdate + ? "Cannot be updated." + : value === LdapPasswordRotationMethod.ConnectionPrincipal + ? "The connection principal will rotate the target principal's password" + : "The target principal will rotate their own password" + } > - + onValueChange={(val) => { + setValue( + "temporaryParameters", + val === LdapPasswordRotationMethod.TargetPrincipal + ? { + password: "" + } + : undefined + ); + onChange(val); + }} + className="w-full border border-mineshaft-500 capitalize" + position="popper" + dropdownContainerClassName="max-w-none" + > + {Object.values(LdapPasswordRotationMethod).map((method) => { + return ( + + {method.replace("-", " ")} + + ); + })} +
)} /> +
+ ( + + + + )} + /> + {rotationMethod === LdapPasswordRotationMethod.TargetPrincipal && !isUpdate && ( + ( + + + + )} + /> + )} +
Password Requirements
-
+
{ label="Password Length" isError={Boolean(error)} errorText={error?.message} - helperText="The length of the password to generate" + tooltipText="The length of the password to generate" > { label="Digit Count" isError={Boolean(error)} errorText={error?.message} - helperText="Minimum number of digits" + tooltipText="Minimum number of digits" > { label="Lowercase Character Count" isError={Boolean(error)} errorText={error?.message} - helperText="Minimum number of lowercase characters" + tooltipText="Minimum number of lowercase characters" > { label="Uppercase Character Count" isError={Boolean(error)} errorText={error?.message} - helperText="Minimum number of uppercase characters" + tooltipText="Minimum number of uppercase characters" > { label="Symbol Count" isError={Boolean(error)} errorText={error?.message} - helperText="Minimum number of symbols" + tooltipText="Minimum number of symbols" > { label="Allowed Symbols" isError={Boolean(error)} errorText={error?.message} - helperText="Symbols to use in generated password" + tooltipText="Symbols to use in generated password" > { const [parameters, { dn, password }] = watch(["parameters", "secretsMapping"]); + const { passwordRequirements } = parameters; + return ( <> - {parameters.dn} + {parameters.dn} + {passwordRequirements && ( + + {passwordRequirements.length} + + {passwordRequirements.required.digits} + + + {passwordRequirements.required.lowercase} + + + {passwordRequirements.required.uppercase} + + + {passwordRequirements.required.symbols} + + + {passwordRequirements.allowedSymbols} + + + )} - {dn} + {dn} {password} diff --git a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ReviewFields/shared/SecretRotationReviewSection.tsx b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ReviewFields/shared/SecretRotationReviewSection.tsx index 7e2da4a07..fdff4af5c 100644 --- a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ReviewFields/shared/SecretRotationReviewSection.tsx +++ b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2ReviewFields/shared/SecretRotationReviewSection.tsx @@ -1,7 +1,7 @@ import { ReactNode } from "react"; type Props = { - label: "Parameters" | "Secrets Mapping"; + label: "Parameters" | "Secrets Mapping" | "Password Requirements"; children: ReactNode; }; diff --git a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2SecretsMappingFields/LdapPasswordRotationSecretsMappingFields.tsx b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2SecretsMappingFields/LdapPasswordRotationSecretsMappingFields.tsx index 01d2e0d74..0c5c90662 100644 --- a/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2SecretsMappingFields/LdapPasswordRotationSecretsMappingFields.tsx +++ b/frontend/src/components/secret-rotations-v2/forms/SecretRotationV2SecretsMappingFields/LdapPasswordRotationSecretsMappingFields.tsx @@ -17,7 +17,7 @@ export const LdapPasswordRotationSecretsMappingFields = () => { const items = [ { - name: "DN", + name: "DN/UPN", input: ( ( diff --git a/frontend/src/components/secret-rotations-v2/forms/schemas/index.ts b/frontend/src/components/secret-rotations-v2/forms/schemas/index.ts index b0484ae67..b8564801f 100644 --- a/frontend/src/components/secret-rotations-v2/forms/schemas/index.ts +++ b/frontend/src/components/secret-rotations-v2/forms/schemas/index.ts @@ -6,16 +6,36 @@ import { AzureClientSecretRotationSchema } from "@app/components/secret-rotation import { LdapPasswordRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/ldap-password-rotation-schema"; import { MsSqlCredentialsRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/mssql-credentials-rotation-schema"; import { PostgresCredentialsRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/postgres-credentials-rotation-schema"; +import { SecretRotation } from "@app/hooks/api/secretRotationsV2"; +import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation"; -const SecretRotationUnionSchema = z.discriminatedUnion("type", [ - Auth0ClientSecretRotationSchema, - AzureClientSecretRotationSchema, - PostgresCredentialsRotationSchema, - MsSqlCredentialsRotationSchema, - LdapPasswordRotationSchema, - AwsIamUserSecretRotationSchema -]); +export const SecretRotationV2FormSchema = (isUpdate: boolean) => + z + .intersection( + z.discriminatedUnion("type", [ + Auth0ClientSecretRotationSchema, + AzureClientSecretRotationSchema, + PostgresCredentialsRotationSchema, + MsSqlCredentialsRotationSchema, + LdapPasswordRotationSchema, + AwsIamUserSecretRotationSchema + ]), + z.object({ id: z.string().optional() }) + ) + .superRefine((val, ctx) => { + if (val.type !== SecretRotation.LdapPassword || isUpdate) return; -export const SecretRotationV2FormSchema = SecretRotationUnionSchema; + // this has to go on union or breaks discrimination + if ( + val.parameters.rotationMethod === LdapPasswordRotationMethod.TargetPrincipal && + !val.temporaryParameters?.password + ) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Password required", + path: ["temporaryParameters", "password"] + }); + } + }); -export type TSecretRotationV2Form = z.infer; +export type TSecretRotationV2Form = z.infer>; diff --git a/frontend/src/components/secret-rotations-v2/forms/schemas/ldap-password-rotation-schema.ts b/frontend/src/components/secret-rotations-v2/forms/schemas/ldap-password-rotation-schema.ts index e18609f04..58e998ee7 100644 --- a/frontend/src/components/secret-rotations-v2/forms/schemas/ldap-password-rotation-schema.ts +++ b/frontend/src/components/secret-rotations-v2/forms/schemas/ldap-password-rotation-schema.ts @@ -2,8 +2,9 @@ import { z } from "zod"; import { BaseSecretRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/base-secret-rotation-v2-schema"; import { PasswordRequirementsSchema } from "@app/components/secret-rotations-v2/forms/schemas/shared"; -import { DistinguishedNameRegex } from "@app/helpers/string"; +import { DistinguishedNameRegex, UserPrincipalNameRegex } from "@app/helpers/string"; import { SecretRotation } from "@app/hooks/api/secretRotationsV2"; +import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation"; export const LdapPasswordRotationSchema = z .object({ @@ -12,13 +13,24 @@ export const LdapPasswordRotationSchema = z dn: z .string() .trim() - .regex(DistinguishedNameRegex, "Invalid Distinguished Name format") - .min(1, "Distinguished Name (DN) required"), - passwordRequirements: PasswordRequirementsSchema.optional() + .min(1, "DN/UPN required") + .refine( + (value) => DistinguishedNameRegex.test(value) || UserPrincipalNameRegex.test(value), + { + message: "Invalid DN/UPN format" + } + ), + passwordRequirements: PasswordRequirementsSchema.optional(), + rotationMethod: z.nativeEnum(LdapPasswordRotationMethod).optional() }), secretsMapping: z.object({ - dn: z.string().trim().min(1, "Distinguished Name (DN) required"), + dn: z.string().trim().min(1, "DN/UPN required"), password: z.string().trim().min(1, "Password required") - }) + }), + temporaryParameters: z + .object({ + password: z.string().min(1, "Password required") + }) + .optional() }) .merge(BaseSecretRotationSchema); diff --git a/frontend/src/components/secret-rotations-v2/forms/schemas/shared/password-requirements-schema.ts b/frontend/src/components/secret-rotations-v2/forms/schemas/shared/password-requirements-schema.ts index a02852ec8..1bab3b0bd 100644 --- a/frontend/src/components/secret-rotations-v2/forms/schemas/shared/password-requirements-schema.ts +++ b/frontend/src/components/secret-rotations-v2/forms/schemas/shared/password-requirements-schema.ts @@ -1,5 +1,7 @@ import { z } from "zod"; +export type TPasswordRequirements = z.infer; + export const PasswordRequirementsSchema = z .object({ length: z diff --git a/frontend/src/components/v2/Select/Select.tsx b/frontend/src/components/v2/Select/Select.tsx index e0dc90186..a35dc00d2 100644 --- a/frontend/src/components/v2/Select/Select.tsx +++ b/frontend/src/components/v2/Select/Select.tsx @@ -123,6 +123,7 @@ export const SelectItem = forwardRef( return ( { export const DistinguishedNameRegex = /^(?:(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*)(?:,(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*))*)?$/; + +export const UserPrincipalNameRegex = /^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/; diff --git a/frontend/src/hooks/api/organization/queries.tsx b/frontend/src/hooks/api/organization/queries.tsx index 947353162..cd620bb64 100644 --- a/frontend/src/hooks/api/organization/queries.tsx +++ b/frontend/src/hooks/api/organization/queries.tsx @@ -118,7 +118,9 @@ export const useUpdateOrg = () => { kmsProductEnabled, sshProductEnabled, scannerProductEnabled, - shareSecretsProductEnabled + shareSecretsProductEnabled, + maxSharedSecretLifetime, + maxSharedSecretViewLimit }) => { return apiRequest.patch(`/api/v1/organization/${orgId}`, { name, @@ -136,7 +138,9 @@ export const useUpdateOrg = () => { kmsProductEnabled, sshProductEnabled, scannerProductEnabled, - shareSecretsProductEnabled + shareSecretsProductEnabled, + maxSharedSecretLifetime, + maxSharedSecretViewLimit }); }, onSuccess: () => { diff --git a/frontend/src/hooks/api/organization/types.ts b/frontend/src/hooks/api/organization/types.ts index ab015f890..068cfad6d 100644 --- a/frontend/src/hooks/api/organization/types.ts +++ b/frontend/src/hooks/api/organization/types.ts @@ -26,6 +26,8 @@ export type Organization = { sshProductEnabled: boolean; scannerProductEnabled: boolean; shareSecretsProductEnabled: boolean; + maxSharedSecretLifetime: number; + maxSharedSecretViewLimit: number | null; }; export type UpdateOrgDTO = { @@ -46,6 +48,8 @@ export type UpdateOrgDTO = { sshProductEnabled?: boolean; scannerProductEnabled?: boolean; shareSecretsProductEnabled?: boolean; + maxSharedSecretViewLimit?: number | null; + maxSharedSecretLifetime?: number; }; export type BillingDetails = { diff --git a/frontend/src/hooks/api/secretRotationsV2/types/ldap-password-rotation.ts b/frontend/src/hooks/api/secretRotationsV2/types/ldap-password-rotation.ts index b8d2ade2b..42a1116cf 100644 --- a/frontend/src/hooks/api/secretRotationsV2/types/ldap-password-rotation.ts +++ b/frontend/src/hooks/api/secretRotationsV2/types/ldap-password-rotation.ts @@ -1,3 +1,4 @@ +import { TPasswordRequirements } from "@app/components/secret-rotations-v2/forms/schemas/shared"; import { AppConnection } from "@app/hooks/api/appConnections/enums"; import { SecretRotation } from "@app/hooks/api/secretRotationsV2"; import { @@ -5,10 +6,17 @@ import { TSecretRotationV2GeneratedCredentialsResponseBase } from "@app/hooks/api/secretRotationsV2/types/shared"; +export enum LdapPasswordRotationMethod { + ConnectionPrincipal = "connection-principal", + TargetPrincipal = "target-principal" +} + export type TLdapPasswordRotation = TSecretRotationV2Base & { type: SecretRotation.LdapPassword; parameters: { dn: string; + rotationMethod?: LdapPasswordRotationMethod; + passwordRequirements?: TPasswordRequirements; }; secretsMapping: { dn: string; diff --git a/frontend/src/hooks/api/secretSharing/queries.ts b/frontend/src/hooks/api/secretSharing/queries.ts index ace45526a..cfd505ff0 100644 --- a/frontend/src/hooks/api/secretSharing/queries.ts +++ b/frontend/src/hooks/api/secretSharing/queries.ts @@ -11,10 +11,13 @@ export const secretSharingKeys = { allSecretRequests: () => ["secretRequests"] as const, specificSecretRequests: ({ offset, limit }: { offset: number; limit: number }) => [...secretSharingKeys.allSecretRequests(), { offset, limit }] as const, - getSecretById: (arg: { id: string; hashedHex: string | null; password?: string }) => [ - "shared-secret", - arg - ], + getSecretById: (arg: { + id: string; + hashedHex: string | null; + password?: string; + email?: string; + hash?: string; + }) => ["shared-secret", arg], getSecretRequestById: (arg: { id: string }) => ["secret-request", arg] as const }; @@ -70,20 +73,34 @@ export const useGetSecretRequests = ({ export const useGetActiveSharedSecretById = ({ sharedSecretId, hashedHex, - password + password, + email, + hash }: { sharedSecretId: string; hashedHex: string | null; password?: string; + + // For secrets shared to specific emails (optional) + email?: string; + hash?: string; }) => { return useQuery({ - queryKey: secretSharingKeys.getSecretById({ id: sharedSecretId, hashedHex, password }), + queryKey: secretSharingKeys.getSecretById({ + id: sharedSecretId, + hashedHex, + password, + email, + hash + }), queryFn: async () => { const { data } = await apiRequest.post( `/api/v1/secret-sharing/shared/public/${sharedSecretId}`, { ...(hashedHex && { hashedHex }), - password + password, + email, + hash } ); diff --git a/frontend/src/hooks/api/secretSharing/types.ts b/frontend/src/hooks/api/secretSharing/types.ts index ab819cfb6..c35228fab 100644 --- a/frontend/src/hooks/api/secretSharing/types.ts +++ b/frontend/src/hooks/api/secretSharing/types.ts @@ -32,6 +32,7 @@ export type TCreateSharedSecretRequest = { expiresAt: Date; expiresAfterViews?: number; accessType?: SecretSharingAccessType; + emails?: string[]; }; export type TCreateSecretRequestRequestDTO = { diff --git a/frontend/src/hooks/api/users/index.tsx b/frontend/src/hooks/api/users/index.tsx index 0774275f9..715c3532d 100644 --- a/frontend/src/hooks/api/users/index.tsx +++ b/frontend/src/hooks/api/users/index.tsx @@ -1,6 +1,7 @@ export { useAddUserToWsE2EE, useAddUserToWsNonE2EE, + useRemoveMyDuplicateAccounts, useRevokeMySessionById, useSendEmailVerificationCode, useVerifyEmailVerificationCode @@ -14,6 +15,7 @@ export { useDeleteOrgMembership, useGetMyAPIKeys, useGetMyAPIKeysV2, + useGetMyDuplicateAccount, useGetMyIp, useGetMyOrganizationProjects, useGetMySessions, diff --git a/frontend/src/hooks/api/users/mutation.tsx b/frontend/src/hooks/api/users/mutation.tsx index 1b873b31c..ee274ab31 100644 --- a/frontend/src/hooks/api/users/mutation.tsx +++ b/frontend/src/hooks/api/users/mutation.tsx @@ -184,3 +184,12 @@ export const useRevokeMySessionById = () => { } }); }; + +export const useRemoveMyDuplicateAccounts = () => { + return useMutation({ + mutationFn: async () => { + const { data } = await apiRequest.post("/api/v1/user/remove-duplicate-accounts"); + return data; + } + }); +}; diff --git a/frontend/src/hooks/api/users/queries.tsx b/frontend/src/hooks/api/users/queries.tsx index 06cde4d34..ea451db02 100644 --- a/frontend/src/hooks/api/users/queries.tsx +++ b/frontend/src/hooks/api/users/queries.tsx @@ -37,6 +37,33 @@ export const useGetUser = () => queryFn: fetchUserDetails }); +export const fetchUserDuplicateAccounts = async () => { + const { data } = await apiRequest.get<{ + users: Array< + User & { + isMyAccount: boolean; + organizations: { name: string; slug: string }[]; + devices: { + ip: string; + userAgent: string; + }[]; + } + >; + }>("/api/v1/user/duplicate-accounts"); + return data.users; +}; + +export const useGetMyDuplicateAccount = () => + useQuery({ + queryKey: userKeys.getMyDuplicateAccount, + staleTime: 60 * 1000, // 1 min in ms + queryFn: fetchUserDuplicateAccounts, + select: (users) => ({ + duplicateAccounts: users.filter((el) => !el.isMyAccount), + myAccount: users?.find((el) => el.isMyAccount) + }) + }); + export const useDeleteMe = () => { const queryClient = useQueryClient(); diff --git a/frontend/src/hooks/api/users/query-keys.tsx b/frontend/src/hooks/api/users/query-keys.tsx index 34d969b49..aacbb73b9 100644 --- a/frontend/src/hooks/api/users/query-keys.tsx +++ b/frontend/src/hooks/api/users/query-keys.tsx @@ -1,5 +1,6 @@ export const userKeys = { getUser: ["user"] as const, + getMyDuplicateAccount: ["user-duplicate-account"] as const, getPrivateKey: ["user"] as const, userAction: ["user-action"] as const, userProjectFavorites: (orgId: string) => [{ orgId }, "user-project-favorites"] as const, diff --git a/frontend/src/pages/auth/LoginPage/components/PasswordStep/PasswordStep.tsx b/frontend/src/pages/auth/LoginPage/components/PasswordStep/PasswordStep.tsx index 529509b49..91432f9be 100644 --- a/frontend/src/pages/auth/LoginPage/components/PasswordStep/PasswordStep.tsx +++ b/frontend/src/pages/auth/LoginPage/components/PasswordStep/PasswordStep.tsx @@ -18,7 +18,8 @@ import { useToggle } from "@app/hooks"; import { useOauthTokenExchange, useSelectOrganization } from "@app/hooks/api"; import { MfaMethod } from "@app/hooks/api/auth/types"; import { fetchOrganizations } from "@app/hooks/api/organization/queries"; -import { fetchMyPrivateKey } from "@app/hooks/api/users/queries"; +import { fetchMyPrivateKey, fetchUserDuplicateAccounts } from "@app/hooks/api/users/queries"; +import { EmailDuplicationConfirmation } from "@app/pages/auth/SelectOrgPage/EmailDuplicationConfirmation"; import { navigateUserToOrg, useNavigateToSelectOrganization } from "../../Login.utils"; @@ -40,6 +41,7 @@ export const PasswordStep = ({ const [isLoading, setIsLoading] = useState(false); const { t } = useTranslation(); const navigate = useNavigate(); + const [removeDuplicateLater, setRemoveDuplicateLater] = useState(true); const { mutateAsync: selectOrganization } = useSelectOrganization(); const { mutateAsync: oauthTokenExchange } = useOauthTokenExchange(); const [shouldShowMfa, toggleShowMfa] = useToggle(false); @@ -109,6 +111,13 @@ export const PasswordStep = ({ return; } + const userDuplicateAccount = await fetchUserDuplicateAccounts(); + const hasDuplicate = userDuplicateAccount?.length > 1; + if (hasDuplicate) { + setRemoveDuplicateLater(false); + return; + } + await navigateUserToOrg(navigate, organizationId); }; @@ -306,6 +315,18 @@ export const PasswordStep = ({ ); } + if (!removeDuplicateLater) { + return ( + + navigateUserToOrg(navigate, organizationId).catch(() => + createNotification({ text: "Failed to navigate user", type: "error" }) + ) + } + /> + ); + } + if (hasExchangedPrivateKey) { return (
diff --git a/frontend/src/pages/auth/SelectOrgPage/EmailDuplicationConfirmation.tsx b/frontend/src/pages/auth/SelectOrgPage/EmailDuplicationConfirmation.tsx new file mode 100644 index 000000000..0347aee39 --- /dev/null +++ b/frontend/src/pages/auth/SelectOrgPage/EmailDuplicationConfirmation.tsx @@ -0,0 +1,164 @@ +import { useCallback } from "react"; +import { Helmet } from "react-helmet"; +import { useTranslation } from "react-i18next"; +import { faInfoCircle } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { Link, useNavigate } from "@tanstack/react-router"; +import { format } from "date-fns"; + +import { createNotification } from "@app/components/notifications"; +import { Button, DeleteActionModal, Tooltip } from "@app/components/v2"; +import { usePopUp } from "@app/hooks"; +import { + useGetMyDuplicateAccount, + useLogoutUser, + useRemoveMyDuplicateAccounts +} from "@app/hooks/api"; + +type Props = { + onRemoveDuplicateLater: () => void; +}; + +export const EmailDuplicationConfirmation = ({ onRemoveDuplicateLater }: Props) => { + const duplicateAccounts = useGetMyDuplicateAccount(); + const removeDuplicateEmails = useRemoveMyDuplicateAccounts(); + const { t } = useTranslation(); + const navigate = useNavigate(); + const logout = useLogoutUser(true); + const { popUp, handlePopUpToggle } = usePopUp(["removeDuplicateConfirm"] as const); + const handleLogout = useCallback(async () => { + try { + console.log("Logging out..."); + await logout.mutateAsync(); + navigate({ to: "/login" }); + } catch (error) { + console.error(error); + } + }, [logout, navigate]); + + return ( +
+ + {t("common.head-title", { title: t("login.title") })} + + + + + +
+ +
+ Infisical logo +
+ +
+
+

+ Multiple Accounts Detected +

+

+ You're currently logged in as{" "} + {duplicateAccounts?.data?.myAccount?.username}. +

+
+

+ We've detected multiple accounts using variations of the same email address. +

+
+
+
+ Your other accounts +
+
+ {duplicateAccounts?.data?.duplicateAccounts?.map((el) => { + const lastSession = el.devices?.at(-1); + return ( +
+
+
{el.username}
+
+ Last logged in at {format(new Date(el.updatedAt), "Pp")} +
+
+ Organizations: {el?.organizations?.map((i) => i.slug)?.join(",")} +
+
+
+ +
IP: {lastSession?.ip || "-"}
+
User Agent: {lastSession?.userAgent || "-"}
+
+ } + > + + +
+
+ ); + })} +
+
+
+ + +
+ +
+ +
+
+ handlePopUpToggle("removeDuplicateConfirm", isOpen)} + deleteKey="remove" + buttonText="Confirm" + onDeleteApproved={() => + removeDuplicateEmails.mutateAsync(undefined, { + onSuccess: () => { + createNotification({ + type: "success", + text: "Removed duplicate accounts" + }); + onRemoveDuplicateLater(); + } + }) + } + /> +
+ ); +}; diff --git a/frontend/src/pages/auth/SelectOrgPage/SelectOrgPage.tsx b/frontend/src/pages/auth/SelectOrgPage/SelectOrgPage.tsx index 7dddd1a4b..f66be2d4b 100644 --- a/frontend/src/pages/auth/SelectOrgPage/SelectOrgPage.tsx +++ b/frontend/src/pages/auth/SelectOrgPage/SelectOrgPage.tsx @@ -1,33 +1,10 @@ -import { useCallback, useEffect, useState } from "react"; -import { Helmet } from "react-helmet"; -import { useTranslation } from "react-i18next"; -import { faArrowRight } from "@fortawesome/free-solid-svg-icons"; -import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; -import { Link, useNavigate } from "@tanstack/react-router"; -import axios from "axios"; -import { addSeconds, formatISO } from "date-fns"; -import { jwtDecode } from "jwt-decode"; +import { useState } from "react"; -import { Mfa } from "@app/components/auth/Mfa"; -import { createNotification } from "@app/components/notifications"; -import { IsCliLoginSuccessful } from "@app/components/utilities/attemptCliLogin"; -import SecurityClient from "@app/components/utilities/SecurityClient"; -import { Button, Spinner } from "@app/components/v2"; -import { SessionStorageKeys } from "@app/const"; -import { OrgMembershipRole } from "@app/helpers/roles"; -import { useToggle } from "@app/hooks"; -import { - useGetOrganizations, - useGetUser, - useLogoutUser, - useSelectOrganization -} from "@app/hooks/api"; -import { MfaMethod, UserAgentType } from "@app/hooks/api/auth/types"; -import { getAuthToken, isLoggedIn } from "@app/hooks/api/reactQuery"; -import { Organization } from "@app/hooks/api/types"; -import { AuthMethod } from "@app/hooks/api/users/types"; +import { Spinner } from "@app/components/v2"; +import { useGetMyDuplicateAccount } from "@app/hooks/api"; -import { navigateUserToOrg } from "../LoginPage/Login.utils"; +import { EmailDuplicationConfirmation } from "./EmailDuplicationConfirmation"; +import { SelectOrganizationSection } from "./SelectOrgSection"; const LoadingScreen = () => { return ( @@ -39,253 +16,18 @@ const LoadingScreen = () => { }; export const SelectOrganizationPage = () => { - const navigate = useNavigate(); - const { t } = useTranslation(); + const duplicateAccounts = useGetMyDuplicateAccount(); + const [removeDuplicateLater, setRemoveDuplicateLater] = useState(false); - const organizations = useGetOrganizations(); - const selectOrg = useSelectOrganization(); - const { data: user, isPending: userLoading } = useGetUser(); - const [shouldShowMfa, toggleShowMfa] = useToggle(false); - const [requiredMfaMethod, setRequiredMfaMethod] = useState(MfaMethod.EMAIL); - const [isInitialOrgCheckLoading, setIsInitialOrgCheckLoading] = useState(true); - - const [mfaSuccessCallback, setMfaSuccessCallback] = useState<() => void>(() => {}); - - const queryParams = new URLSearchParams(window.location.search); - const orgId = queryParams.get("org_id"); - const callbackPort = queryParams.get("callback_port"); - const isAdminLogin = queryParams.get("is_admin_login") === "true"; - const defaultSelectedOrg = organizations.data?.find((org) => org.id === orgId); - - const logout = useLogoutUser(true); - const handleLogout = useCallback(async () => { - try { - console.log("Logging out..."); - await logout.mutateAsync(); - navigate({ to: "/login" }); - } catch (error) { - console.error(error); - } - }, [logout, navigate]); - - const handleSelectOrganization = useCallback( - async (organization: Organization) => { - const canBypassOrgAuth = - organization.bypassOrgAuthEnabled && - organization.userRole === OrgMembershipRole.Admin && - isAdminLogin; - - if (organization.authEnforced && !canBypassOrgAuth) { - // org has an org-level auth method enabled (e.g. SAML) - // -> logout + redirect to SAML SSO - await logout.mutateAsync(); - let url = ""; - if (organization.orgAuthMethod === AuthMethod.OIDC) { - url = `/api/v1/sso/oidc/login?orgSlug=${organization.slug}${ - callbackPort ? `&callbackPort=${callbackPort}` : "" - }`; - } else { - url = `/api/v1/sso/redirect/saml2/organizations/${organization.slug}`; - - if (callbackPort) { - url += `?callback_port=${callbackPort}`; - } - } - - window.location.href = url; - return; - } - - const { token, isMfaEnabled, mfaMethod } = await selectOrg - .mutateAsync({ - organizationId: organization.id, - userAgent: callbackPort ? UserAgentType.CLI : undefined - }) - .finally(() => setIsInitialOrgCheckLoading(false)); - - if (isMfaEnabled) { - SecurityClient.setMfaToken(token); - if (mfaMethod) { - setRequiredMfaMethod(mfaMethod); - } - toggleShowMfa.on(); - setMfaSuccessCallback(() => () => handleSelectOrganization(organization)); - return; - } - - if (callbackPort) { - const privateKey = localStorage.getItem("PRIVATE_KEY"); - - let error: string | null = null; - - if (!privateKey) error = "Private key not found"; - if (!user?.email) error = "User email not found"; - if (!token) error = "No token found"; - - if (error) { - createNotification({ - text: error, - type: "error" - }); - return; - } - - const payload = { - JTWToken: token, - email: user?.email, - privateKey - } as IsCliLoginSuccessful["loginResponse"]; - - // send request to server endpoint - const instance = axios.create(); - await instance.post(`http://127.0.0.1:${callbackPort}/`, payload).catch(() => { - // if error happens to communicate we set the token with an expiry in sessino storage - // the cli-redirect page has logic to show this to user and ask them to paste it in terminal - sessionStorage.setItem( - SessionStorageKeys.CLI_TERMINAL_TOKEN, - JSON.stringify({ - expiry: formatISO(addSeconds(new Date(), 30)), - data: window.btoa(JSON.stringify(payload)) - }) - ); - }); - navigate({ to: "/cli-redirect" }); - // cli page - } else { - navigateUserToOrg(navigate, organization.id); - } - }, - [selectOrg] - ); - - const handleCliRedirect = useCallback(() => { - const authToken = getAuthToken(); - - if (authToken && !callbackPort) { - const decodedJwt = jwtDecode(authToken) as any; - - if (decodedJwt?.organizationId) { - navigateUserToOrg(navigate, decodedJwt.organizationId); - } - } - - if (!isLoggedIn()) { - navigate({ to: "/login" }); - } - }, []); - - useEffect(() => { - if (callbackPort) { - handleCliRedirect(); - } - }, [navigate]); - - useEffect(() => { - if (organizations.isPending || !organizations.data) return; - - // Case: User has no organizations. - // This can happen if the user was previously a member, but the organization was deleted or the user was removed. - if (organizations.data.length === 0) { - navigate({ to: "/organization/none" }); - } else if (organizations.data.length === 1) { - if (callbackPort) { - handleCliRedirect(); - setIsInitialOrgCheckLoading(false); - } else { - handleSelectOrganization(organizations.data[0]); - } - } else { - setIsInitialOrgCheckLoading(false); - } - }, [organizations.isPending, organizations.data]); - - useEffect(() => { - if (defaultSelectedOrg) { - handleSelectOrganization(defaultSelectedOrg); - } - }, [defaultSelectedOrg]); - - if ( - userLoading || - !user || - ((isInitialOrgCheckLoading || defaultSelectedOrg) && !shouldShowMfa) - ) { + if (duplicateAccounts.isPending) { return ; } - return ( -
- - {t("common.head-title", { title: t("login.title") })} - - - - - - {shouldShowMfa ? ( - - ) : ( -
- -
- Infisical logo -
- -
-
-

- Choose your organization -

+ if (duplicateAccounts.data?.duplicateAccounts?.length && !removeDuplicateLater) { + return ( + setRemoveDuplicateLater(true)} /> + ); + } -
-

- You‘re currently logged in as {user.username} -

-

- Not you?{" "} - -

-
-
-
- {organizations.isPending ? ( - - ) : ( - organizations.data?.map((org) => ( - // eslint-disable-next-line jsx-a11y/click-events-have-key-events, jsx-a11y/no-static-element-interactions -
handleSelectOrganization(org)} - key={org.id} - className="group flex cursor-pointer items-center justify-between rounded-md bg-mineshaft-700 px-4 py-3 capitalize text-gray-200 shadow-md transition-colors hover:bg-mineshaft-600" - > -

{org.name}

- - -
- )) - )} -
-
-
- )} - -
-
- ); + return ; }; diff --git a/frontend/src/pages/auth/SelectOrgPage/SelectOrgSection.tsx b/frontend/src/pages/auth/SelectOrgPage/SelectOrgSection.tsx new file mode 100644 index 000000000..2ca179c87 --- /dev/null +++ b/frontend/src/pages/auth/SelectOrgPage/SelectOrgSection.tsx @@ -0,0 +1,289 @@ +import { useCallback, useEffect, useState } from "react"; +import { Helmet } from "react-helmet"; +import { useTranslation } from "react-i18next"; +import { faArrowRight } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { Link, useNavigate } from "@tanstack/react-router"; +import axios from "axios"; +import { addSeconds, formatISO } from "date-fns"; +import { jwtDecode } from "jwt-decode"; + +import { Mfa } from "@app/components/auth/Mfa"; +import { createNotification } from "@app/components/notifications"; +import { IsCliLoginSuccessful } from "@app/components/utilities/attemptCliLogin"; +import SecurityClient from "@app/components/utilities/SecurityClient"; +import { Button, Spinner } from "@app/components/v2"; +import { SessionStorageKeys } from "@app/const"; +import { OrgMembershipRole } from "@app/helpers/roles"; +import { useToggle } from "@app/hooks"; +import { + useGetOrganizations, + useGetUser, + useLogoutUser, + useSelectOrganization +} from "@app/hooks/api"; +import { MfaMethod, UserAgentType } from "@app/hooks/api/auth/types"; +import { getAuthToken, isLoggedIn } from "@app/hooks/api/reactQuery"; +import { Organization } from "@app/hooks/api/types"; +import { AuthMethod } from "@app/hooks/api/users/types"; + +import { navigateUserToOrg } from "../LoginPage/Login.utils"; + +const LoadingScreen = () => { + return ( +
+ +

Loading, please wait

+
+ ); +}; + +export const SelectOrganizationSection = () => { + const navigate = useNavigate(); + const { t } = useTranslation(); + + const organizations = useGetOrganizations(); + const selectOrg = useSelectOrganization(); + const { data: user, isPending: userLoading } = useGetUser(); + const [shouldShowMfa, toggleShowMfa] = useToggle(false); + const [requiredMfaMethod, setRequiredMfaMethod] = useState(MfaMethod.EMAIL); + const [isInitialOrgCheckLoading, setIsInitialOrgCheckLoading] = useState(true); + + const [mfaSuccessCallback, setMfaSuccessCallback] = useState<() => void>(() => {}); + + const queryParams = new URLSearchParams(window.location.search); + const orgId = queryParams.get("org_id"); + const callbackPort = queryParams.get("callback_port"); + const isAdminLogin = queryParams.get("is_admin_login") === "true"; + const defaultSelectedOrg = organizations.data?.find((org) => org.id === orgId); + + const logout = useLogoutUser(true); + const handleLogout = useCallback(async () => { + try { + console.log("Logging out..."); + await logout.mutateAsync(); + navigate({ to: "/login" }); + } catch (error) { + console.error(error); + } + }, [logout, navigate]); + + const handleSelectOrganization = useCallback( + async (organization: Organization) => { + const canBypassOrgAuth = + organization.bypassOrgAuthEnabled && + organization.userRole === OrgMembershipRole.Admin && + isAdminLogin; + + if (organization.authEnforced && !canBypassOrgAuth) { + // org has an org-level auth method enabled (e.g. SAML) + // -> logout + redirect to SAML SSO + await logout.mutateAsync(); + let url = ""; + if (organization.orgAuthMethod === AuthMethod.OIDC) { + url = `/api/v1/sso/oidc/login?orgSlug=${organization.slug}${ + callbackPort ? `&callbackPort=${callbackPort}` : "" + }`; + } else { + url = `/api/v1/sso/redirect/saml2/organizations/${organization.slug}`; + + if (callbackPort) { + url += `?callback_port=${callbackPort}`; + } + } + + window.location.href = url; + return; + } + + const { token, isMfaEnabled, mfaMethod } = await selectOrg + .mutateAsync({ + organizationId: organization.id, + userAgent: callbackPort ? UserAgentType.CLI : undefined + }) + .finally(() => setIsInitialOrgCheckLoading(false)); + + if (isMfaEnabled) { + SecurityClient.setMfaToken(token); + if (mfaMethod) { + setRequiredMfaMethod(mfaMethod); + } + toggleShowMfa.on(); + setMfaSuccessCallback(() => () => handleSelectOrganization(organization)); + return; + } + + if (callbackPort) { + const privateKey = localStorage.getItem("PRIVATE_KEY"); + + let error: string | null = null; + + if (!privateKey) error = "Private key not found"; + if (!user?.email) error = "User email not found"; + if (!token) error = "No token found"; + + if (error) { + createNotification({ + text: error, + type: "error" + }); + return; + } + + const payload = { + JTWToken: token, + email: user?.email, + privateKey + } as IsCliLoginSuccessful["loginResponse"]; + + // send request to server endpoint + const instance = axios.create(); + await instance.post(`http://127.0.0.1:${callbackPort}/`, payload).catch(() => { + // if error happens to communicate we set the token with an expiry in sessino storage + // the cli-redirect page has logic to show this to user and ask them to paste it in terminal + sessionStorage.setItem( + SessionStorageKeys.CLI_TERMINAL_TOKEN, + JSON.stringify({ + expiry: formatISO(addSeconds(new Date(), 30)), + data: window.btoa(JSON.stringify(payload)) + }) + ); + }); + navigate({ to: "/cli-redirect" }); + // cli page + } else { + navigateUserToOrg(navigate, organization.id); + } + }, + [selectOrg] + ); + + const handleCliRedirect = useCallback(() => { + const authToken = getAuthToken(); + + if (authToken && !callbackPort) { + const decodedJwt = jwtDecode(authToken) as any; + + if (decodedJwt?.organizationId) { + navigateUserToOrg(navigate, decodedJwt.organizationId); + } + } + + if (!isLoggedIn()) { + navigate({ to: "/login" }); + } + }, []); + + useEffect(() => { + if (callbackPort) { + handleCliRedirect(); + } + }, [navigate]); + + useEffect(() => { + if (organizations.isPending || !organizations.data) return; + + // Case: User has no organizations. + // This can happen if the user was previously a member, but the organization was deleted or the user was removed. + if (organizations.data.length === 0) { + navigate({ to: "/organization/none" }); + } else if (organizations.data.length === 1) { + if (callbackPort) { + handleCliRedirect(); + setIsInitialOrgCheckLoading(false); + } else { + handleSelectOrganization(organizations.data[0]); + } + } else { + setIsInitialOrgCheckLoading(false); + } + }, [organizations.isPending, organizations.data]); + + useEffect(() => { + if (defaultSelectedOrg) { + handleSelectOrganization(defaultSelectedOrg); + } + }, [defaultSelectedOrg]); + + if ( + userLoading || + !user || + ((isInitialOrgCheckLoading || defaultSelectedOrg) && !shouldShowMfa) + ) { + return ; + } + + return ( +
+ + {t("common.head-title", { title: t("login.title") })} + + + + + + {shouldShowMfa ? ( + + ) : ( +
+ +
+ Infisical logo +
+ +
+
+

+ Choose your organization +

+
+

+ You‘re currently logged in as {user.username} +

+

+ Not you?{" "} + +

+
+
+
+ {organizations.isPending ? ( + + ) : ( + organizations.data?.map((org) => ( + // eslint-disable-next-line jsx-a11y/click-events-have-key-events, jsx-a11y/no-static-element-interactions +
handleSelectOrganization(org)} + key={org.id} + className="group flex cursor-pointer items-center justify-between rounded-md bg-mineshaft-700 px-4 py-3 capitalize text-gray-200 shadow-md transition-colors hover:bg-mineshaft-600" + > +

{org.name}

+ + +
+ )) + )} +
+
+
+ )} +
+
+ ); +}; diff --git a/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/LdapConnectionForm.tsx b/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/LdapConnectionForm.tsx index 7346f84af..a13a5c184 100644 --- a/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/LdapConnectionForm.tsx +++ b/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/LdapConnectionForm.tsx @@ -19,7 +19,7 @@ import { Tooltip } from "@app/components/v2"; import { APP_CONNECTION_MAP, getAppConnectionMethodDetails } from "@app/helpers/appConnections"; -import { DistinguishedNameRegex } from "@app/helpers/string"; +import { DistinguishedNameRegex, UserPrincipalNameRegex } from "@app/helpers/string"; import { LdapConnectionMethod, LdapConnectionProvider, @@ -55,8 +55,13 @@ const formSchema = z.discriminatedUnion("method", [ dn: z .string() .trim() - .regex(DistinguishedNameRegex, "Invalid Distinguished Name format") - .min(1, "Distinguished Name (DN) required"), + .min(1, "DN/UPN required") + .refine( + (value) => DistinguishedNameRegex.test(value) || UserPrincipalNameRegex.test(value), + { + message: "Invalid DN/UPN format" + } + ), password: z.string().trim().min(1, "Password required"), sslRejectUnauthorized: z.boolean(), sslCertificate: z @@ -223,7 +228,7 @@ export const LdapConnectionForm = ({ appConnection, onSubmit }: Props) => { diff --git a/frontend/src/pages/organization/BillingPage/components/BillingCloudTab/CurrentPlanSection.tsx b/frontend/src/pages/organization/BillingPage/components/BillingCloudTab/CurrentPlanSection.tsx index 1b7e84f2c..5c85f19f7 100644 --- a/frontend/src/pages/organization/BillingPage/components/BillingCloudTab/CurrentPlanSection.tsx +++ b/frontend/src/pages/organization/BillingPage/components/BillingCloudTab/CurrentPlanSection.tsx @@ -1,4 +1,9 @@ -import { faCircleCheck, faCircleXmark, faFileInvoice } from "@fortawesome/free-solid-svg-icons"; +import { + faCircleCheck, + faCircleXmark, + faFileInvoice, + faInfoCircle +} from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { @@ -10,6 +15,7 @@ import { Td, Th, THead, + Tooltip, Tr } from "@app/components/v2"; import { useOrganization } from "@app/context"; @@ -48,9 +54,26 @@ export const CurrentPlanSection = () => { data && data?.rows?.length > 0 && data.rows.map(({ name, allowed, used }) => { + let toolTipText = null; + if (name === "Organization identity limit") { + toolTipText = + "Identity count is calculated by the total number of user identities and machine identities."; + } + return ( - {name} + + {name} + {toolTipText && ( + + + + )} + {displayCell(allowed)} {used} diff --git a/frontend/src/pages/organization/SecretSharingPage/components/ShareSecret/AddShareSecretModal.tsx b/frontend/src/pages/organization/SecretSharingPage/components/ShareSecret/AddShareSecretModal.tsx index 45b974755..a9450993f 100644 --- a/frontend/src/pages/organization/SecretSharingPage/components/ShareSecret/AddShareSecretModal.tsx +++ b/frontend/src/pages/organization/SecretSharingPage/components/ShareSecret/AddShareSecretModal.tsx @@ -30,6 +30,8 @@ export const AddShareSecretModal = ({ popUp, handlePopUpToggle }: Props) => { allowSecretSharingOutsideOrganization={ currentOrg?.allowSecretSharingOutsideOrganization ?? true } + maxSharedSecretLifetime={currentOrg?.maxSharedSecretLifetime} + maxSharedSecretViewLimit={currentOrg?.maxSharedSecretViewLimit} /> diff --git a/frontend/src/pages/organization/SecretSharingSettingsPage/SecretSharingSettingsPage.tsx b/frontend/src/pages/organization/SecretSharingSettingsPage/SecretSharingSettingsPage.tsx index 8ee37f631..ae1aa3772 100644 --- a/frontend/src/pages/organization/SecretSharingSettingsPage/SecretSharingSettingsPage.tsx +++ b/frontend/src/pages/organization/SecretSharingSettingsPage/SecretSharingSettingsPage.tsx @@ -17,11 +17,11 @@ export const SecretSharingSettingsPage = withPermission( return ( <> - {t("common.head-title", { title: t("settings.org.title") })} + {t("common.head-title", { title: "Secret Share Settings" })}
- +
diff --git a/frontend/src/pages/organization/SecretSharingSettingsPage/components/OrgSecretShareLimitSection/OrgSecretShareLimitSection.tsx b/frontend/src/pages/organization/SecretSharingSettingsPage/components/OrgSecretShareLimitSection/OrgSecretShareLimitSection.tsx new file mode 100644 index 000000000..e0d88a082 --- /dev/null +++ b/frontend/src/pages/organization/SecretSharingSettingsPage/components/OrgSecretShareLimitSection/OrgSecretShareLimitSection.tsx @@ -0,0 +1,294 @@ +import { Controller, useForm } from "react-hook-form"; +import { zodResolver } from "@hookform/resolvers/zod"; +import { z } from "zod"; +import { useEffect } from "react"; + +import { createNotification } from "@app/components/notifications"; +import { OrgPermissionCan } from "@app/components/permissions"; +import { Button, FormControl, Input, Select, SelectItem } from "@app/components/v2"; +import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; +import { useUpdateOrg } from "@app/hooks/api"; + +const MAX_SHARED_SECRET_LIFETIME_SECONDS = 30 * 24 * 60 * 60; // 30 days in seconds +const MIN_SHARED_SECRET_LIFETIME_SECONDS = 5 * 60; // 5 minutes in seconds + +// Helper function to convert duration to seconds +const durationToSeconds = (value: number, unit: "m" | "h" | "d"): number => { + switch (unit) { + case "m": + return value * 60; + case "h": + return value * 60 * 60; + case "d": + return value * 60 * 60 * 24; + default: + return 0; + } +}; + +// Helper function to convert seconds to form lifetime value and unit +const getFormLifetimeFromSeconds = ( + totalSeconds: number | null | undefined +): { maxLifetimeValue: number; maxLifetimeUnit: "m" | "h" | "d" } => { + const DEFAULT_LIFETIME_VALUE = 30; + const DEFAULT_LIFETIME_UNIT = "d" as "m" | "h" | "d"; + + if (totalSeconds == null || totalSeconds <= 0) { + return { + maxLifetimeValue: DEFAULT_LIFETIME_VALUE, + maxLifetimeUnit: DEFAULT_LIFETIME_UNIT + }; + } + + const secondsInDay = 24 * 60 * 60; + const secondsInHour = 60 * 60; + const secondsInMinute = 60; + + if (totalSeconds % secondsInDay === 0) { + const value = totalSeconds / secondsInDay; + if (value >= 1) return { maxLifetimeValue: value, maxLifetimeUnit: "d" }; + } + + if (totalSeconds % secondsInHour === 0) { + const value = totalSeconds / secondsInHour; + if (value >= 1) return { maxLifetimeValue: value, maxLifetimeUnit: "h" }; + } + + if (totalSeconds % secondsInMinute === 0) { + const value = totalSeconds / secondsInMinute; + if (value >= 1) return { maxLifetimeValue: value, maxLifetimeUnit: "m" }; + } + + return { + maxLifetimeValue: DEFAULT_LIFETIME_VALUE, + maxLifetimeUnit: DEFAULT_LIFETIME_UNIT + }; +}; + +const formSchema = z + .object({ + maxLifetimeValue: z.number().min(1, "Value must be at least 1"), + maxLifetimeUnit: z.enum(["m", "h", "d"], { + invalid_type_error: "Please select a valid time unit" + }), + maxViewLimit: z.string() + }) + .superRefine((data, ctx) => { + const { maxLifetimeValue, maxLifetimeUnit } = data; + + const durationInSeconds = durationToSeconds(maxLifetimeValue, maxLifetimeUnit); + + // Check max limit + if (durationInSeconds > MAX_SHARED_SECRET_LIFETIME_SECONDS) { + let message = "Duration exceeds maximum allowed limit"; + + if (maxLifetimeUnit === "m") { + message = `Maximum allowed minutes is ${MAX_SHARED_SECRET_LIFETIME_SECONDS / 60} (30 days)`; + } else if (maxLifetimeUnit === "h") { + message = `Maximum allowed hours is ${MAX_SHARED_SECRET_LIFETIME_SECONDS / (60 * 60)} (30 days)`; + } else if (maxLifetimeUnit === "d") { + message = `Maximum allowed days is ${MAX_SHARED_SECRET_LIFETIME_SECONDS / (24 * 60 * 60)}`; + } + + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message, + path: ["maxLifetimeValue"] + }); + } + + // Check min limit + if (durationInSeconds < MIN_SHARED_SECRET_LIFETIME_SECONDS) { + const message = `Duration must be at least ${MIN_SHARED_SECRET_LIFETIME_SECONDS / 60} minutes`; // 5 minutes + + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message, + path: ["maxLifetimeValue"] + }); + } + }); + +type TForm = z.infer; + +const viewLimitOptions = [ + { label: "1", value: 1 }, + { label: "Unlimited", value: -1 } +]; + +export const OrgSecretShareLimitSection = () => { + const { mutateAsync } = useUpdateOrg(); + const { currentOrg } = useOrganization(); + + const getDefaultFormValues = () => { + const initialLifetime = getFormLifetimeFromSeconds(currentOrg?.maxSharedSecretLifetime); + return { + maxLifetimeValue: initialLifetime.maxLifetimeValue, + maxLifetimeUnit: initialLifetime.maxLifetimeUnit, + maxViewLimit: currentOrg?.maxSharedSecretViewLimit?.toString() || "-1" + }; + }; + + const { + control, + formState: { isSubmitting, isDirty }, + handleSubmit, + reset + } = useForm({ + resolver: zodResolver(formSchema), + defaultValues: getDefaultFormValues() + }); + + useEffect(() => { + if (currentOrg) { + reset(getDefaultFormValues()); + } + }, [currentOrg, reset]); + + const handleFormSubmit = async (formData: TForm) => { + try { + const maxSharedSecretLifetimeSeconds = durationToSeconds( + formData.maxLifetimeValue, + formData.maxLifetimeUnit + ); + + await mutateAsync({ + orgId: currentOrg.id, + maxSharedSecretViewLimit: + formData.maxViewLimit === "-1" ? null : Number(formData.maxViewLimit), + maxSharedSecretLifetime: maxSharedSecretLifetimeSeconds + }); + + createNotification({ + text: "Successfully updated secret share limits", + type: "success" + }); + + reset(formData); + } catch { + createNotification({ + text: "Failed to update secret share limits", + type: "error" + }); + } + }; + + // Units for the dropdown with readable labels + const timeUnits = [ + { value: "m", label: "Minutes" }, + { value: "h", label: "Hours" }, + { value: "d", label: "Days" } + ]; + + return ( +
+
+

Secret Share Limits

+
+

+ These settings establish the maximum limits for all Shared Secret parameters within this + organization. Shared secrets cannot be created with values exceeding these limits. +

+ + {(isAllowed) => ( +
+
+ ( + + { + const val = e.target.value; + field.onChange(val === "" ? "" : parseInt(val, 10)); + }} + disabled={!isAllowed} + /> + + )} + /> + ( + + + + )} + /> +
+
+ ( + + + + )} + /> +
+ +
+ )} +
+
+ ); +}; diff --git a/frontend/src/pages/organization/SecretSharingSettingsPage/components/OrgSecretShareLimitSection/index.tsx b/frontend/src/pages/organization/SecretSharingSettingsPage/components/OrgSecretShareLimitSection/index.tsx new file mode 100644 index 000000000..1e83c4be8 --- /dev/null +++ b/frontend/src/pages/organization/SecretSharingSettingsPage/components/OrgSecretShareLimitSection/index.tsx @@ -0,0 +1 @@ +export { OrgSecretShareLimitSection } from "./OrgSecretShareLimitSection"; diff --git a/frontend/src/pages/organization/SecretSharingSettingsPage/components/SecretSharingSettingsGeneralTab/SecretSharingSettingsGeneralTab.tsx b/frontend/src/pages/organization/SecretSharingSettingsPage/components/SecretSharingSettingsGeneralTab/SecretSharingSettingsGeneralTab.tsx index ede3d9fc8..ba849507d 100644 --- a/frontend/src/pages/organization/SecretSharingSettingsPage/components/SecretSharingSettingsGeneralTab/SecretSharingSettingsGeneralTab.tsx +++ b/frontend/src/pages/organization/SecretSharingSettingsPage/components/SecretSharingSettingsGeneralTab/SecretSharingSettingsGeneralTab.tsx @@ -1,9 +1,11 @@ +import { OrgSecretShareLimitSection } from "../OrgSecretShareLimitSection"; import { SecretSharingAllowShareToAnyone } from "../SecretSharingAllowShareToAnyone"; export const SecretSharingSettingsGeneralTab = () => { return (
+
); }; diff --git a/frontend/src/pages/organization/SettingsPage/components/OrgProductSelectSection/OrgProductSelectSection.tsx b/frontend/src/pages/organization/SettingsPage/components/OrgProductSelectSection/OrgProductSelectSection.tsx index b649a7ac0..e9267d897 100644 --- a/frontend/src/pages/organization/SettingsPage/components/OrgProductSelectSection/OrgProductSelectSection.tsx +++ b/frontend/src/pages/organization/SettingsPage/components/OrgProductSelectSection/OrgProductSelectSection.tsx @@ -80,7 +80,7 @@ export const OrgProductSelectSection = () => { return (
-

Organization Products

+

Enabled Products

Select which products are available for your organization.

diff --git a/frontend/src/pages/organization/SettingsPage/components/OrgSecurityTab/OrgUserAccessTokenLimitSection.tsx b/frontend/src/pages/organization/SettingsPage/components/OrgSecurityTab/OrgUserAccessTokenLimitSection.tsx index bc020d3a1..58a91e90e 100644 --- a/frontend/src/pages/organization/SettingsPage/components/OrgSecurityTab/OrgUserAccessTokenLimitSection.tsx +++ b/frontend/src/pages/organization/SettingsPage/components/OrgSecurityTab/OrgUserAccessTokenLimitSection.tsx @@ -96,61 +96,59 @@ export const OrgUserAccessTokenLimitSection = () => { {(isAllowed) => (
-
-
- ( - + ( + + field.onChange(parseInt(e.target.value, 10))} + disabled={!isAllowed} + /> + + )} + /> + + ( + + field.onChange(parseInt(e.target.value, 10))} - disabled={!isAllowed} - /> - - )} - /> -
-
- ( - - - - )} - /> -
+ {timeUnits.map(({ value, label }) => ( + +
{label}
+
+ ))} + + + )} + />
diff --git a/frontend/src/pages/public/ShareSecretPage/components/ShareSecretForm.tsx b/frontend/src/pages/public/ShareSecretPage/components/ShareSecretForm.tsx index a2228e46b..e347f1482 100644 --- a/frontend/src/pages/public/ShareSecretPage/components/ShareSecretForm.tsx +++ b/frontend/src/pages/public/ShareSecretPage/components/ShareSecretForm.tsx @@ -6,7 +6,19 @@ import { zodResolver } from "@hookform/resolvers/zod"; import { z } from "zod"; import { createNotification } from "@app/components/notifications"; -import { Button, FormControl, IconButton, Input, Select, SelectItem } from "@app/components/v2"; +import { + Accordion, + AccordionContent, + AccordionItem, + AccordionTrigger, + Button, + FormControl, + IconButton, + Input, + Select, + SelectItem, + Switch +} from "@app/components/v2"; import { useTimedReset } from "@app/hooks"; import { useCreatePublicSharedSecret, useCreateSharedSecret } from "@app/hooks/api"; import { SecretSharingAccessType } from "@app/hooks/api/secretSharing"; @@ -33,7 +45,24 @@ const schema = z.object({ secret: z.string().min(1), expiresIn: z.string(), viewLimit: z.string(), - accessType: z.nativeEnum(SecretSharingAccessType).optional() + accessType: z.nativeEnum(SecretSharingAccessType).optional(), + emails: z + .string() + .optional() + .refine( + (val) => { + if (!val) return true; + const emails = val + .split(",") + .map((email) => email.trim()) + .filter((email) => email !== ""); + if (emails.length > 100) return false; + return emails.every((email) => z.string().email().safeParse(email).success); + }, + { + message: "Must be a comma-separated list of valid emails (max 100) or empty." + } + ) }); export type FormData = z.infer; @@ -42,14 +71,18 @@ type Props = { isPublic: boolean; // whether or not this is a public (non-authenticated) secret sharing form value?: string; allowSecretSharingOutsideOrganization?: boolean; + maxSharedSecretLifetime?: number; + maxSharedSecretViewLimit?: number | null; }; export const ShareSecretForm = ({ isPublic, value, - allowSecretSharingOutsideOrganization = true + allowSecretSharingOutsideOrganization = true, + maxSharedSecretLifetime, + maxSharedSecretViewLimit }: Props) => { - const [secretLink, setSecretLink] = useState(""); + const [secretLink, setSecretLink] = useState(null); const [, isCopyingSecret, setCopyTextSecret] = useTimedReset({ initialState: "Copy to clipboard" }); @@ -58,6 +91,15 @@ export const ShareSecretForm = ({ const privateSharedSecretCreator = useCreateSharedSecret(); const createSharedSecret = isPublic ? publicSharedSecretCreator : privateSharedSecretCreator; + // Note: maxSharedSecretLifetime is in seconds + const filteredExpiresInOptions = maxSharedSecretLifetime + ? expiresInOptions.filter((v) => v.value / 1000 <= maxSharedSecretLifetime) + : expiresInOptions; + + const filteredViewLimitOptions = maxSharedSecretViewLimit + ? viewLimitOptions.filter((v) => v.value > 0 && v.value <= maxSharedSecretViewLimit) + : viewLimitOptions; + const { control, reset, @@ -66,7 +108,10 @@ export const ShareSecretForm = ({ } = useForm({ resolver: zodResolver(schema), defaultValues: { - secret: value || "" + secret: value || "", + viewLimit: filteredViewLimitOptions[filteredViewLimitOptions.length - 1].value.toString(), + expiresIn: + filteredExpiresInOptions[Math.min(filteredExpiresInOptions.length - 1, 2)].value.toString() } }); @@ -76,32 +121,45 @@ export const ShareSecretForm = ({ secret, expiresIn, viewLimit, - accessType + accessType, + emails }: FormData) => { try { const expiresAt = new Date(new Date().getTime() + Number(expiresIn)); + const processedEmails = emails ? emails.split(",").map((e) => e.trim()) : undefined; + const { id } = await createSharedSecret.mutateAsync({ name, password, secretValue: secret, expiresAt, expiresAfterViews: viewLimit === "-1" ? undefined : Number(viewLimit), - accessType + accessType, + emails: processedEmails }); - const link = `${window.location.origin}/shared/secret/${id}`; + if (processedEmails && processedEmails.length > 0) { + setSecretLink(""); + createNotification({ + text: `Shared secret link emailed to ${processedEmails.length} user(s).`, + type: "success" + }); + } else { + const link = `${window.location.origin}/shared/secret/${id}`; + + setSecretLink(link); + + navigator.clipboard.writeText(link); + setCopyTextSecret("secret"); + + createNotification({ + text: "Shared secret link copied to clipboard.", + type: "success" + }); + } - setSecretLink(link); reset(); - - navigator.clipboard.writeText(link); - setCopyTextSecret("secret"); - - createNotification({ - text: "Shared secret link copied to clipboard.", - type: "success" - }); } catch (error) { console.error(error); createNotification({ @@ -111,152 +169,256 @@ export const ShareSecretForm = ({ } }; - const hasSecretLink = Boolean(secretLink); - - return !hasSecretLink ? ( - - {!isPublic && ( + if (secretLink === null) + return ( + + {!isPublic && ( + ( + + + + )} + /> + )} ( - )} /> - )} - ( - -