Update identity-kubernetes-auth-service.ts

This commit is contained in:
Daniel Hougaard
2024-10-02 13:39:15 +04:00
parent e6e1ed7ca9
commit 7b64288019
@@ -1,5 +1,5 @@
import { ForbiddenError } from "@casl/ability"; import { ForbiddenError } from "@casl/ability";
import axios from "axios"; import axios, { AxiosError } from "axios";
import https from "https"; import https from "https";
import jwt from "jsonwebtoken"; import jwt from "jsonwebtoken";
@@ -107,32 +107,54 @@ export const identityKubernetesAuthServiceFactory = ({
}); });
} }
const { data }: { data: TCreateTokenReviewResponse } = await axios.post( const { data } = await axios
`${identityKubernetesAuth.kubernetesHost}/apis/authentication.k8s.io/v1/tokenreviews`, .post<TCreateTokenReviewResponse>(
{ `${identityKubernetesAuth.kubernetesHost}/apis/authentication.k8s.io/v1/tokenreviews`,
apiVersion: "authentication.k8s.io/v1", {
kind: "TokenReview", apiVersion: "authentication.k8s.io/v1",
spec: { kind: "TokenReview",
token: serviceAccountJwt spec: {
} token: serviceAccountJwt
}, }
{
headers: {
"Content-Type": "application/json",
Authorization: `Bearer ${tokenReviewerJwt}`
}, },
httpsAgent: new https.Agent({ {
ca: caCert, headers: {
rejectUnauthorized: !!caCert "Content-Type": "application/json",
}) Authorization: `Bearer ${tokenReviewerJwt}`
} },
);
if ("error" in data.status) throw new UnauthorizedError({ message: data.status.error }); // if ca cert, rejectUnauthorized: true
httpsAgent: new https.Agent({
ca: caCert,
rejectUnauthorized: !!caCert
})
}
)
.catch((err) => {
if (err instanceof AxiosError) {
if (err.response) {
const { message } = err?.response?.data as unknown as { message?: string };
if (message) {
throw new UnauthorizedError({
message,
name: "KubernetesTokenReviewRequestError"
});
}
}
}
throw err;
});
if ("error" in data.status)
throw new UnauthorizedError({ message: data.status.error, name: "KubernetesTokenReviewError" });
// check the response to determine if the token is valid // check the response to determine if the token is valid
if (!(data.status && data.status.authenticated)) if (!(data.status && data.status.authenticated))
throw new UnauthorizedError({ message: "Kubernetes token not authenticated" }); throw new UnauthorizedError({
message: "Kubernetes token not authenticated",
name: "KubernetesTokenReviewError"
});
const { namespace: targetNamespace, name: targetName } = extractK8sUsername(data.status.user.username); const { namespace: targetNamespace, name: targetName } = extractK8sUsername(data.status.user.username);