Merge pull request #3111 from Infisical/daniel/minor-improvements

fix: minor improvements
This commit is contained in:
Daniel Hougaard
2025-02-12 20:37:37 +04:00
committed by GitHub
7 changed files with 127 additions and 96 deletions
@@ -31,7 +31,7 @@ export async function up(knex: Knex): Promise<void> {
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const projectEncryptionRingBuffer = const projectEncryptionRingBuffer =
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const webhooks = await knex(TableName.Webhook) const webhooks = await knex(TableName.Webhook)
.where({}) .where({})
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.Webhook}.envId`) .join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.Webhook}.envId`)
.select( .select(
@@ -53,10 +53,13 @@ export async function up(knex: Knex): Promise<void> {
webhooks.map(async (el) => { webhooks.map(async (el) => {
let projectKmsService = projectEncryptionRingBuffer.getItem(el.projectId); let projectKmsService = projectEncryptionRingBuffer.getItem(el.projectId);
if (!projectKmsService) { if (!projectKmsService) {
projectKmsService = await kmsService.createCipherPairWithDataKey({ projectKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.SecretManager, {
projectId: el.projectId type: KmsDataKey.SecretManager,
}, knex); projectId: el.projectId
},
knex
);
projectEncryptionRingBuffer.push(el.projectId, projectKmsService); projectEncryptionRingBuffer.push(el.projectId, projectKmsService);
} }
@@ -46,10 +46,13 @@ export async function up(knex: Knex): Promise<void> {
dynamicSecretRootCredentials.map(async ({ projectId, ...el }) => { dynamicSecretRootCredentials.map(async ({ projectId, ...el }) => {
let projectKmsService = projectEncryptionRingBuffer.getItem(projectId); let projectKmsService = projectEncryptionRingBuffer.getItem(projectId);
if (!projectKmsService) { if (!projectKmsService) {
projectKmsService = await kmsService.createCipherPairWithDataKey({ projectKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.SecretManager, {
projectId type: KmsDataKey.SecretManager,
}, knex); projectId
},
knex
);
projectEncryptionRingBuffer.push(projectId, projectKmsService); projectEncryptionRingBuffer.push(projectId, projectKmsService);
} }
@@ -39,10 +39,13 @@ export async function up(knex: Knex): Promise<void> {
secretRotations.map(async ({ projectId, ...el }) => { secretRotations.map(async ({ projectId, ...el }) => {
let projectKmsService = projectEncryptionRingBuffer.getItem(projectId); let projectKmsService = projectEncryptionRingBuffer.getItem(projectId);
if (!projectKmsService) { if (!projectKmsService) {
projectKmsService = await kmsService.createCipherPairWithDataKey({ projectKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.SecretManager, {
projectId type: KmsDataKey.SecretManager,
}, knex); projectId
},
knex
);
projectEncryptionRingBuffer.push(projectId, projectKmsService); projectEncryptionRingBuffer.push(projectId, projectKmsService);
} }
@@ -76,77 +76,87 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
) )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId"); .orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedIdentityKubernetesConfigs = []; const updatedIdentityKubernetesConfigs = [];
for (const { encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el } of identityKubernetesConfigs) { for await (const {
let orgKmsService = orgEncryptionRingBuffer.getItem(orgId); encryptedSymmetricKey,
symmetricKeyKeyEncoding,
if (!orgKmsService) { symmetricKeyTag,
orgKmsService = await kmsService.createCipherPairWithDataKey({ symmetricKeyIV,
orgId,
...el
} of identityKubernetesConfigs) {
let orgKmsService = orgEncryptionRingBuffer.getItem(orgId);
if (!orgKmsService) {
orgKmsService = await kmsService.createCipherPairWithDataKey(
{
type: KmsDataKey.Organization, type: KmsDataKey.Organization,
orgId orgId
}, knex); },
orgEncryptionRingBuffer.push(orgId, orgKmsService); knex
} );
orgEncryptionRingBuffer.push(orgId, orgKmsService);
const key = infisicalSymmetricDecrypt({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
});
const decryptedTokenReviewerJwt =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.tokenReviewerJwtIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.tokenReviewerJwtTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedTokenReviewerJwt
})
: "";
const decryptedCertificate =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCaCert && el.caCertIV && el.caCertTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.caCertIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.caCertTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedCaCert
})
: "";
const encryptedKubernetesTokenReviewerJwt = orgKmsService.encryptor({
plainText: Buffer.from(decryptedTokenReviewerJwt)
}).cipherTextBlob;
const encryptedKubernetesCaCertificate = orgKmsService.encryptor({
plainText: Buffer.from(decryptedCertificate)
}).cipherTextBlob;
updatedIdentityKubernetesConfigs.push({
...el,
accessTokenTrustedIps: JSON.stringify(el.accessTokenTrustedIps),
encryptedKubernetesCaCertificate,
encryptedKubernetesTokenReviewerJwt
});
} }
const key = infisicalSymmetricDecrypt({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
});
const decryptedTokenReviewerJwt =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.tokenReviewerJwtIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.tokenReviewerJwtTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedTokenReviewerJwt
})
: "";
const decryptedCertificate =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCaCert && el.caCertIV && el.caCertTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.caCertIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.caCertTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedCaCert
})
: "";
const encryptedKubernetesTokenReviewerJwt = orgKmsService.encryptor({
plainText: Buffer.from(decryptedTokenReviewerJwt)
}).cipherTextBlob;
const encryptedKubernetesCaCertificate = orgKmsService.encryptor({
plainText: Buffer.from(decryptedCertificate)
}).cipherTextBlob;
updatedIdentityKubernetesConfigs.push({
...el,
accessTokenTrustedIps: JSON.stringify(el.accessTokenTrustedIps),
encryptedKubernetesCaCertificate,
encryptedKubernetesTokenReviewerJwt
});
}
for (let i = 0; i < updatedIdentityKubernetesConfigs.length; i += BATCH_SIZE) { for (let i = 0; i < updatedIdentityKubernetesConfigs.length; i += BATCH_SIZE) {
// eslint-disable-next-line no-await-in-loop // eslint-disable-next-line no-await-in-loop
await knex(TableName.IdentityKubernetesAuth) await knex(TableName.IdentityKubernetesAuth)
@@ -62,10 +62,13 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el }) => { async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el }) => {
let orgKmsService = orgEncryptionRingBuffer.getItem(orgId); let orgKmsService = orgEncryptionRingBuffer.getItem(orgId);
if (!orgKmsService) { if (!orgKmsService) {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.Organization, {
orgId type: KmsDataKey.Organization,
}, knex); orgId
},
knex
);
orgEncryptionRingBuffer.push(orgId, orgKmsService); orgEncryptionRingBuffer.push(orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
@@ -49,10 +49,13 @@ const reencryptSamlConfig = async (knex: Knex) => {
async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, ...el }) => { async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, ...el }) => {
let orgKmsService = orgEncryptionRingBuffer.getItem(el.orgId); let orgKmsService = orgEncryptionRingBuffer.getItem(el.orgId);
if (!orgKmsService) { if (!orgKmsService) {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.Organization, {
orgId: el.orgId type: KmsDataKey.Organization,
}, knex); orgId: el.orgId
},
knex
);
orgEncryptionRingBuffer.push(el.orgId, orgKmsService); orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
@@ -204,10 +207,13 @@ const reencryptLdapConfig = async (knex: Knex) => {
async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, ...el }) => { async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, ...el }) => {
let orgKmsService = orgEncryptionRingBuffer.getItem(el.orgId); let orgKmsService = orgEncryptionRingBuffer.getItem(el.orgId);
if (!orgKmsService) { if (!orgKmsService) {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.Organization, {
orgId: el.orgId type: KmsDataKey.Organization,
}, knex); orgId: el.orgId
},
knex
);
orgEncryptionRingBuffer.push(el.orgId, orgKmsService); orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
@@ -353,10 +359,13 @@ const reencryptOidcConfig = async (knex: Knex) => {
async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, ...el }) => { async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, ...el }) => {
let orgKmsService = orgEncryptionRingBuffer.getItem(el.orgId); let orgKmsService = orgEncryptionRingBuffer.getItem(el.orgId);
if (!orgKmsService) { if (!orgKmsService) {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey(
type: KmsDataKey.Organization, {
orgId: el.orgId type: KmsDataKey.Organization,
}, knex); orgId: el.orgId
},
knex
);
orgEncryptionRingBuffer.push(el.orgId, orgKmsService); orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
+1 -1
View File
@@ -111,7 +111,7 @@ export const groupDALFactory = (db: TDbClient) => {
} }
if (search) { if (search) {
void query.andWhereRaw(`CONCAT_WS(' ', "firstName", "lastName", "username") ilike '%${search}%'`); // void query.andWhereRaw(`CONCAT_WS(' ', "firstName", "lastName", "username") ilike '%${search}%'`);
} else if (username) { } else if (username) {
void query.andWhere(`${TableName.Users}.username`, "ilike", `%${username}%`); void query.andWhere(`${TableName.Users}.username`, "ilike", `%${username}%`);
} }