update a few endpoints to not rely on CA

This commit is contained in:
x
2025-04-30 13:39:50 -04:00
parent 4d847ab2cb
commit 7f836ed9bc
2 changed files with 23 additions and 31 deletions
@@ -37,7 +37,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
} }
}, },
handler: async (req) => { handler: async (req) => {
const { cert, ca } = await server.services.certificate.getCert({ const { cert } = await server.services.certificate.getCert({
serialNumber: req.params.serialNumber, serialNumber: req.params.serialNumber,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
@@ -47,7 +47,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
await server.services.auditLog.createAuditLog({ await server.services.auditLog.createAuditLog({
...req.auditLogInfo, ...req.auditLogInfo,
projectId: ca.projectId, projectId: cert.projectId,
event: { event: {
type: EventType.GET_CERT, type: EventType.GET_CERT,
metadata: { metadata: {
@@ -440,7 +440,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
} }
}, },
handler: async (req) => { handler: async (req) => {
const { deletedCert, ca } = await server.services.certificate.deleteCert({ const { deletedCert } = await server.services.certificate.deleteCert({
serialNumber: req.params.serialNumber, serialNumber: req.params.serialNumber,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
@@ -450,7 +450,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
await server.services.auditLog.createAuditLog({ await server.services.auditLog.createAuditLog({
...req.auditLogInfo, ...req.auditLogInfo,
projectId: ca.projectId, projectId: deletedCert.projectId,
event: { event: {
type: EventType.DELETE_CERT, type: EventType.DELETE_CERT,
metadata: { metadata: {
@@ -67,16 +67,10 @@ export const certificateServiceFactory = ({
const getCert = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertDTO) => { const getCert = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertDTO) => {
const cert = await certificateDAL.findOne({ serialNumber }); const cert = await certificateDAL.findOne({ serialNumber });
let ca;
if (cert.caId) {
ca = await certificateAuthorityDAL.findById(cert.caId);
}
const { permission } = await permissionService.getProjectPermission({ const { permission } = await permissionService.getProjectPermission({
actor, actor,
actorId, actorId,
projectId: ca.projectId, projectId: cert.projectId,
actorAuthMethod, actorAuthMethod,
actorOrgId, actorOrgId,
actionProjectType: ActionProjectType.CertificateManager actionProjectType: ActionProjectType.CertificateManager
@@ -85,8 +79,7 @@ export const certificateServiceFactory = ({
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Certificates); ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Certificates);
return { return {
cert, cert
ca
}; };
}; };
@@ -95,12 +88,11 @@ export const certificateServiceFactory = ({
*/ */
const deleteCert = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TDeleteCertDTO) => { const deleteCert = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TDeleteCertDTO) => {
const cert = await certificateDAL.findOne({ serialNumber }); const cert = await certificateDAL.findOne({ serialNumber });
const ca = await certificateAuthorityDAL.findById(cert.caId);
const { permission } = await permissionService.getProjectPermission({ const { permission } = await permissionService.getProjectPermission({
actor, actor,
actorId, actorId,
projectId: ca.projectId, projectId: cert.projectId,
actorAuthMethod, actorAuthMethod,
actorOrgId, actorOrgId,
actionProjectType: ActionProjectType.CertificateManager actionProjectType: ActionProjectType.CertificateManager
@@ -111,8 +103,7 @@ export const certificateServiceFactory = ({
const deletedCert = await certificateDAL.deleteById(cert.id); const deletedCert = await certificateDAL.deleteById(cert.id);
return { return {
deletedCert, deletedCert
ca
}; };
}; };
@@ -130,6 +121,11 @@ export const certificateServiceFactory = ({
actorOrgId actorOrgId
}: TRevokeCertDTO) => { }: TRevokeCertDTO) => {
const cert = await certificateDAL.findOne({ serialNumber }); const cert = await certificateDAL.findOne({ serialNumber });
if (!cert.caId) {
throw new Error("Cannot revoke external certificates");
}
const ca = await certificateAuthorityDAL.findById(cert.caId); const ca = await certificateAuthorityDAL.findById(cert.caId);
const { permission } = await permissionService.getProjectPermission({ const { permission } = await permissionService.getProjectPermission({
@@ -177,6 +173,12 @@ export const certificateServiceFactory = ({
*/ */
const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => { const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => {
const cert = await certificateDAL.findOne({ serialNumber }); const cert = await certificateDAL.findOne({ serialNumber });
// TODO(andrey): Remove this later.
if (!cert.caId || !cert.caCertId) {
throw new Error("ERROR");
}
const ca = await certificateAuthorityDAL.findById(cert.caId); const ca = await certificateAuthorityDAL.findById(cert.caId);
const { permission } = await permissionService.getProjectPermission({ const { permission } = await permissionService.getProjectPermission({
@@ -327,17 +329,6 @@ export const certificateServiceFactory = ({
plainText: Buffer.from(certificatePem) plainText: Buffer.from(certificatePem)
}); });
let encryptedCertificateChain: undefined | Buffer;
if (chainPem) {
const { cipherTextBlob } = await kmsEncryptor({
plainText: Buffer.from(chainPem)
});
encryptedCertificateChain = cipherTextBlob;
}
console.log(friendlyName, commonName, altNames, serialNumber, notBefore, notAfter);
// Store in database
await certificateDAL.transaction(async (tx) => { await certificateDAL.transaction(async (tx) => {
const cert = await certificateDAL.create( const cert = await certificateDAL.create(
{ {
@@ -347,7 +338,9 @@ export const certificateServiceFactory = ({
altNames, altNames,
serialNumber, serialNumber,
notBefore, notBefore,
notAfter notAfter,
projectId
// TODO(andrey): Add keyUsages and extendedKeyUsages
// keyUsages, // keyUsages,
// extendedKeyUsages // extendedKeyUsages
}, },
@@ -357,8 +350,7 @@ export const certificateServiceFactory = ({
await certificateBodyDAL.create( await certificateBodyDAL.create(
{ {
certId: cert.id, certId: cert.id,
encryptedCertificate, encryptedCertificate
encryptedCertificateChain
}, },
tx tx
); );