mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 07:27:58 +00:00
improvement: address feedback
This commit is contained in:
@@ -182,9 +182,9 @@ export const DynamicSecretSnowflakeSchema = z.object({
|
|||||||
orgId: z.string().trim().min(1),
|
orgId: z.string().trim().min(1),
|
||||||
username: z.string().trim().min(1),
|
username: z.string().trim().min(1),
|
||||||
password: z.string().trim().min(1),
|
password: z.string().trim().min(1),
|
||||||
creationStatement: z.string().trim(),
|
creationStatement: z.string().trim().min(1),
|
||||||
revocationStatement: z.string().trim(),
|
revocationStatement: z.string().trim().min(1),
|
||||||
renewStatement: z.string().trim()
|
renewStatement: z.string().trim().optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
export const AzureEntraIDSchema = z.object({
|
export const AzureEntraIDSchema = z.object({
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import { customAlphabet } from "nanoid";
|
|||||||
import snowflake from "snowflake-sdk";
|
import snowflake from "snowflake-sdk";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
|
|
||||||
import { DynamicSecretSnowflakeSchema, TDynamicProviderFns } from "./models";
|
import { DynamicSecretSnowflakeSchema, TDynamicProviderFns } from "./models";
|
||||||
@@ -41,15 +42,7 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
|
|||||||
application: "Infisical"
|
application: "Infisical"
|
||||||
});
|
});
|
||||||
|
|
||||||
await new Promise((resolve, reject) => {
|
await client.connectAsync(noop);
|
||||||
client.connect((err) => {
|
|
||||||
if (err) {
|
|
||||||
return reject(err);
|
|
||||||
}
|
|
||||||
|
|
||||||
return resolve(true);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
return client;
|
return client;
|
||||||
};
|
};
|
||||||
@@ -58,9 +51,20 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
|
|||||||
const providerInputs = await validateProviderInputs(inputs);
|
const providerInputs = await validateProviderInputs(inputs);
|
||||||
const client = await getClient(providerInputs);
|
const client = await getClient(providerInputs);
|
||||||
|
|
||||||
const isValidConnection = await client.isValidAsync();
|
let isValidConnection: boolean;
|
||||||
|
|
||||||
client.destroy(noop);
|
try {
|
||||||
|
isValidConnection = await Promise.race([
|
||||||
|
client.isValidAsync(),
|
||||||
|
new Promise((resolve) => {
|
||||||
|
setTimeout(resolve, 10000);
|
||||||
|
}).then(() => {
|
||||||
|
throw new BadRequestError({ message: "Unable to establish connection - verify credentials" });
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
} finally {
|
||||||
|
client.destroy(noop);
|
||||||
|
}
|
||||||
|
|
||||||
return isValidConnection;
|
return isValidConnection;
|
||||||
};
|
};
|
||||||
@@ -72,15 +76,15 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
|
|||||||
|
|
||||||
const username = generateUsername();
|
const username = generateUsername();
|
||||||
const password = generatePassword();
|
const password = generatePassword();
|
||||||
const expiration = getDaysToExpiry(new Date(expireAt));
|
|
||||||
|
|
||||||
const creationStatement = handlebars.compile(providerInputs.creationStatement, { noEscape: true })({
|
|
||||||
username,
|
|
||||||
password,
|
|
||||||
expiration
|
|
||||||
});
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
const expiration = getDaysToExpiry(new Date(expireAt));
|
||||||
|
const creationStatement = handlebars.compile(providerInputs.creationStatement, { noEscape: true })({
|
||||||
|
username,
|
||||||
|
password,
|
||||||
|
expiration
|
||||||
|
});
|
||||||
|
|
||||||
await new Promise((resolve, reject) => {
|
await new Promise((resolve, reject) => {
|
||||||
client.execute({
|
client.execute({
|
||||||
sqlText: creationStatement,
|
sqlText: creationStatement,
|
||||||
@@ -105,9 +109,9 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
|
|||||||
|
|
||||||
const client = await getClient(providerInputs);
|
const client = await getClient(providerInputs);
|
||||||
|
|
||||||
const revokeStatement = handlebars.compile(providerInputs.revocationStatement)({ username });
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
const revokeStatement = handlebars.compile(providerInputs.revocationStatement)({ username });
|
||||||
|
|
||||||
await new Promise((resolve, reject) => {
|
await new Promise((resolve, reject) => {
|
||||||
client.execute({
|
client.execute({
|
||||||
sqlText: revokeStatement,
|
sqlText: revokeStatement,
|
||||||
@@ -132,14 +136,13 @@ export const SnowflakeProvider = (): TDynamicProviderFns => {
|
|||||||
|
|
||||||
const client = await getClient(providerInputs);
|
const client = await getClient(providerInputs);
|
||||||
|
|
||||||
const expiration = getDaysToExpiry(new Date(expireAt));
|
|
||||||
|
|
||||||
const renewStatement = handlebars.compile(providerInputs.renewStatement)({
|
|
||||||
username,
|
|
||||||
expiration
|
|
||||||
});
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
const expiration = getDaysToExpiry(new Date(expireAt));
|
||||||
|
const renewStatement = handlebars.compile(providerInputs.renewStatement)({
|
||||||
|
username,
|
||||||
|
expiration
|
||||||
|
});
|
||||||
|
|
||||||
await new Promise((resolve, reject) => {
|
await new Promise((resolve, reject) => {
|
||||||
client.execute({
|
client.execute({
|
||||||
sqlText: renewStatement,
|
sqlText: renewStatement,
|
||||||
|
|||||||
@@ -226,7 +226,7 @@ export type TDynamicSecretProvider =
|
|||||||
password: string;
|
password: string;
|
||||||
creationStatement: string;
|
creationStatement: string;
|
||||||
revocationStatement: string;
|
revocationStatement: string;
|
||||||
renewStatement: string;
|
renewStatement?: string;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
export type TCreateDynamicSecretDTO = {
|
export type TCreateDynamicSecretDTO = {
|
||||||
|
|||||||
+7
-3
@@ -29,7 +29,7 @@ const formSchema = z.object({
|
|||||||
password: z.string().trim().min(1),
|
password: z.string().trim().min(1),
|
||||||
creationStatement: z.string().trim().min(1),
|
creationStatement: z.string().trim().min(1),
|
||||||
revocationStatement: z.string().trim().min(1),
|
revocationStatement: z.string().trim().min(1),
|
||||||
renewStatement: z.string().trim().min(1)
|
renewStatement: z.string().trim().optional()
|
||||||
}),
|
}),
|
||||||
defaultTTL: z.string().superRefine((val, ctx) => {
|
defaultTTL: z.string().superRefine((val, ctx) => {
|
||||||
const valMs = ms(val);
|
const valMs = ms(val);
|
||||||
@@ -51,7 +51,11 @@ const formSchema = z.object({
|
|||||||
if (valMs > 24 * 60 * 60 * 1000)
|
if (valMs > 24 * 60 * 60 * 1000)
|
||||||
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than a day" });
|
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than a day" });
|
||||||
}),
|
}),
|
||||||
name: z.string().refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
name: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1)
|
||||||
|
.refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
||||||
});
|
});
|
||||||
type TForm = z.infer<typeof formSchema>;
|
type TForm = z.infer<typeof formSchema>;
|
||||||
|
|
||||||
@@ -105,7 +109,7 @@ export const SnowflakeInputForm = ({
|
|||||||
} catch (err) {
|
} catch (err) {
|
||||||
createNotification({
|
createNotification({
|
||||||
type: "error",
|
type: "error",
|
||||||
text: "Failed to create dynamic secret"
|
text: err instanceof Error ? err.message : "Failed to create dynamic secret"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
+9
-5
@@ -28,9 +28,9 @@ const formSchema = z.object({
|
|||||||
orgId: z.string().min(1),
|
orgId: z.string().min(1),
|
||||||
username: z.string().min(1),
|
username: z.string().min(1),
|
||||||
password: z.string().min(1),
|
password: z.string().min(1),
|
||||||
creationStatement: z.string().min(1),
|
creationStatement: z.string().trim().min(1),
|
||||||
revocationStatement: z.string().min(1),
|
revocationStatement: z.string().trim().min(1),
|
||||||
renewStatement: z.string().optional()
|
renewStatement: z.string().trim().optional()
|
||||||
})
|
})
|
||||||
.partial(),
|
.partial(),
|
||||||
defaultTTL: z.string().superRefine((val, ctx) => {
|
defaultTTL: z.string().superRefine((val, ctx) => {
|
||||||
@@ -53,7 +53,11 @@ const formSchema = z.object({
|
|||||||
if (valMs > 24 * 60 * 60 * 1000)
|
if (valMs > 24 * 60 * 60 * 1000)
|
||||||
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than a day" });
|
ctx.addIssue({ code: z.ZodIssueCode.custom, message: "TTL must be less than a day" });
|
||||||
}),
|
}),
|
||||||
newName: z.string().refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
newName: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1)
|
||||||
|
.refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
||||||
});
|
});
|
||||||
type TForm = z.infer<typeof formSchema>;
|
type TForm = z.infer<typeof formSchema>;
|
||||||
|
|
||||||
@@ -114,7 +118,7 @@ export const EditDynamicSecretSnowflakeForm = ({
|
|||||||
} catch (err) {
|
} catch (err) {
|
||||||
createNotification({
|
createNotification({
|
||||||
type: "error",
|
type: "error",
|
||||||
text: "Failed to update dynamic secret"
|
text: err instanceof Error ? err.message : "Failed to create dynamic secret"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user