mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 22:27:48 +00:00
Update identity-kubernetes-auth-service.ts
This commit is contained in:
@@ -1,5 +1,5 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
import axios from "axios";
|
import axios, { AxiosError } from "axios";
|
||||||
import https from "https";
|
import https from "https";
|
||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
|
|
||||||
@@ -107,32 +107,54 @@ export const identityKubernetesAuthServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const { data }: { data: TCreateTokenReviewResponse } = await axios.post(
|
const { data } = await axios
|
||||||
`${identityKubernetesAuth.kubernetesHost}/apis/authentication.k8s.io/v1/tokenreviews`,
|
.post<TCreateTokenReviewResponse>(
|
||||||
{
|
`${identityKubernetesAuth.kubernetesHost}/apis/authentication.k8s.io/v1/tokenreviews`,
|
||||||
apiVersion: "authentication.k8s.io/v1",
|
{
|
||||||
kind: "TokenReview",
|
apiVersion: "authentication.k8s.io/v1",
|
||||||
spec: {
|
kind: "TokenReview",
|
||||||
token: serviceAccountJwt
|
spec: {
|
||||||
}
|
token: serviceAccountJwt
|
||||||
},
|
}
|
||||||
{
|
|
||||||
headers: {
|
|
||||||
"Content-Type": "application/json",
|
|
||||||
Authorization: `Bearer ${tokenReviewerJwt}`
|
|
||||||
},
|
},
|
||||||
httpsAgent: new https.Agent({
|
{
|
||||||
ca: caCert,
|
headers: {
|
||||||
rejectUnauthorized: !!caCert
|
"Content-Type": "application/json",
|
||||||
})
|
Authorization: `Bearer ${tokenReviewerJwt}`
|
||||||
}
|
},
|
||||||
);
|
|
||||||
|
|
||||||
if ("error" in data.status) throw new UnauthorizedError({ message: data.status.error });
|
// if ca cert, rejectUnauthorized: true
|
||||||
|
httpsAgent: new https.Agent({
|
||||||
|
ca: caCert,
|
||||||
|
rejectUnauthorized: !!caCert
|
||||||
|
})
|
||||||
|
}
|
||||||
|
)
|
||||||
|
.catch((err) => {
|
||||||
|
if (err instanceof AxiosError) {
|
||||||
|
if (err.response) {
|
||||||
|
const { message } = err?.response?.data as unknown as { message?: string };
|
||||||
|
|
||||||
|
if (message) {
|
||||||
|
throw new UnauthorizedError({
|
||||||
|
message,
|
||||||
|
name: "KubernetesTokenReviewRequestError"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
throw err;
|
||||||
|
});
|
||||||
|
|
||||||
|
if ("error" in data.status)
|
||||||
|
throw new UnauthorizedError({ message: data.status.error, name: "KubernetesTokenReviewError" });
|
||||||
|
|
||||||
// check the response to determine if the token is valid
|
// check the response to determine if the token is valid
|
||||||
if (!(data.status && data.status.authenticated))
|
if (!(data.status && data.status.authenticated))
|
||||||
throw new UnauthorizedError({ message: "Kubernetes token not authenticated" });
|
throw new UnauthorizedError({
|
||||||
|
message: "Kubernetes token not authenticated",
|
||||||
|
name: "KubernetesTokenReviewError"
|
||||||
|
});
|
||||||
|
|
||||||
const { namespace: targetNamespace, name: targetName } = extractK8sUsername(data.status.user.username);
|
const { namespace: targetNamespace, name: targetName } = extractK8sUsername(data.status.user.username);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user