mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 19:28:58 +00:00
update a few endpoints to not rely on CA
This commit is contained in:
@@ -37,7 +37,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
||||
}
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { cert, ca } = await server.services.certificate.getCert({
|
||||
const { cert } = await server.services.certificate.getCert({
|
||||
serialNumber: req.params.serialNumber,
|
||||
actor: req.permission.type,
|
||||
actorId: req.permission.id,
|
||||
@@ -47,7 +47,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
projectId: ca.projectId,
|
||||
projectId: cert.projectId,
|
||||
event: {
|
||||
type: EventType.GET_CERT,
|
||||
metadata: {
|
||||
@@ -440,7 +440,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
||||
}
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { deletedCert, ca } = await server.services.certificate.deleteCert({
|
||||
const { deletedCert } = await server.services.certificate.deleteCert({
|
||||
serialNumber: req.params.serialNumber,
|
||||
actor: req.permission.type,
|
||||
actorId: req.permission.id,
|
||||
@@ -450,7 +450,7 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
projectId: ca.projectId,
|
||||
projectId: deletedCert.projectId,
|
||||
event: {
|
||||
type: EventType.DELETE_CERT,
|
||||
metadata: {
|
||||
|
||||
@@ -67,16 +67,10 @@ export const certificateServiceFactory = ({
|
||||
const getCert = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertDTO) => {
|
||||
const cert = await certificateDAL.findOne({ serialNumber });
|
||||
|
||||
let ca;
|
||||
|
||||
if (cert.caId) {
|
||||
ca = await certificateAuthorityDAL.findById(cert.caId);
|
||||
}
|
||||
|
||||
const { permission } = await permissionService.getProjectPermission({
|
||||
actor,
|
||||
actorId,
|
||||
projectId: ca.projectId,
|
||||
projectId: cert.projectId,
|
||||
actorAuthMethod,
|
||||
actorOrgId,
|
||||
actionProjectType: ActionProjectType.CertificateManager
|
||||
@@ -85,8 +79,7 @@ export const certificateServiceFactory = ({
|
||||
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Certificates);
|
||||
|
||||
return {
|
||||
cert,
|
||||
ca
|
||||
cert
|
||||
};
|
||||
};
|
||||
|
||||
@@ -95,12 +88,11 @@ export const certificateServiceFactory = ({
|
||||
*/
|
||||
const deleteCert = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TDeleteCertDTO) => {
|
||||
const cert = await certificateDAL.findOne({ serialNumber });
|
||||
const ca = await certificateAuthorityDAL.findById(cert.caId);
|
||||
|
||||
const { permission } = await permissionService.getProjectPermission({
|
||||
actor,
|
||||
actorId,
|
||||
projectId: ca.projectId,
|
||||
projectId: cert.projectId,
|
||||
actorAuthMethod,
|
||||
actorOrgId,
|
||||
actionProjectType: ActionProjectType.CertificateManager
|
||||
@@ -111,8 +103,7 @@ export const certificateServiceFactory = ({
|
||||
const deletedCert = await certificateDAL.deleteById(cert.id);
|
||||
|
||||
return {
|
||||
deletedCert,
|
||||
ca
|
||||
deletedCert
|
||||
};
|
||||
};
|
||||
|
||||
@@ -130,6 +121,11 @@ export const certificateServiceFactory = ({
|
||||
actorOrgId
|
||||
}: TRevokeCertDTO) => {
|
||||
const cert = await certificateDAL.findOne({ serialNumber });
|
||||
|
||||
if (!cert.caId) {
|
||||
throw new Error("Cannot revoke external certificates");
|
||||
}
|
||||
|
||||
const ca = await certificateAuthorityDAL.findById(cert.caId);
|
||||
|
||||
const { permission } = await permissionService.getProjectPermission({
|
||||
@@ -177,6 +173,12 @@ export const certificateServiceFactory = ({
|
||||
*/
|
||||
const getCertBody = async ({ serialNumber, actorId, actorAuthMethod, actor, actorOrgId }: TGetCertBodyDTO) => {
|
||||
const cert = await certificateDAL.findOne({ serialNumber });
|
||||
|
||||
// TODO(andrey): Remove this later.
|
||||
if (!cert.caId || !cert.caCertId) {
|
||||
throw new Error("ERROR");
|
||||
}
|
||||
|
||||
const ca = await certificateAuthorityDAL.findById(cert.caId);
|
||||
|
||||
const { permission } = await permissionService.getProjectPermission({
|
||||
@@ -327,17 +329,6 @@ export const certificateServiceFactory = ({
|
||||
plainText: Buffer.from(certificatePem)
|
||||
});
|
||||
|
||||
let encryptedCertificateChain: undefined | Buffer;
|
||||
if (chainPem) {
|
||||
const { cipherTextBlob } = await kmsEncryptor({
|
||||
plainText: Buffer.from(chainPem)
|
||||
});
|
||||
encryptedCertificateChain = cipherTextBlob;
|
||||
}
|
||||
|
||||
console.log(friendlyName, commonName, altNames, serialNumber, notBefore, notAfter);
|
||||
|
||||
// Store in database
|
||||
await certificateDAL.transaction(async (tx) => {
|
||||
const cert = await certificateDAL.create(
|
||||
{
|
||||
@@ -347,7 +338,9 @@ export const certificateServiceFactory = ({
|
||||
altNames,
|
||||
serialNumber,
|
||||
notBefore,
|
||||
notAfter
|
||||
notAfter,
|
||||
projectId
|
||||
// TODO(andrey): Add keyUsages and extendedKeyUsages
|
||||
// keyUsages,
|
||||
// extendedKeyUsages
|
||||
},
|
||||
@@ -357,8 +350,7 @@ export const certificateServiceFactory = ({
|
||||
await certificateBodyDAL.create(
|
||||
{
|
||||
certId: cert.id,
|
||||
encryptedCertificate,
|
||||
encryptedCertificateChain
|
||||
encryptedCertificate
|
||||
},
|
||||
tx
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user