Merge pull request #2396 from Infisical/daniel/cli-stale-session

fix: stale session after logging into CLI
This commit is contained in:
Maidul Islam
2024-09-10 08:27:16 -04:00
committed by GitHub
6 changed files with 25 additions and 14 deletions
+1 -1
View File
@@ -468,7 +468,7 @@ export const registerRoutes = async (
projectMembershipDAL projectMembershipDAL
}); });
const loginService = authLoginServiceFactory({ userDAL, smtpService, tokenService, orgDAL, tokenDAL: authTokenDAL }); const loginService = authLoginServiceFactory({ userDAL, smtpService, tokenService, orgDAL });
const passwordService = authPaswordServiceFactory({ const passwordService = authPaswordServiceFactory({
tokenService, tokenService,
smtpService, smtpService,
+3 -2
View File
@@ -42,7 +42,8 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
}, },
schema: { schema: {
body: z.object({ body: z.object({
organizationId: z.string().trim() organizationId: z.string().trim(),
userAgent: z.enum(["cli"]).optional()
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -53,7 +54,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
handler: async (req, res) => { handler: async (req, res) => {
const cfg = getConfig(); const cfg = getConfig();
const tokens = await server.services.login.selectOrganization({ const tokens = await server.services.login.selectOrganization({
userAgent: req.headers["user-agent"], userAgent: req.body.userAgent ?? req.headers["user-agent"],
authJwtToken: req.headers.authorization, authJwtToken: req.headers.authorization,
organizationId: req.body.organizationId, organizationId: req.body.organizationId,
ipAddress: req.realIp ipAddress: req.realIp
@@ -12,7 +12,6 @@ import { BadRequestError, DatabaseError, UnauthorizedError } from "@app/lib/erro
import { logger } from "@app/lib/logger"; import { logger } from "@app/lib/logger";
import { getServerCfg } from "@app/services/super-admin/super-admin-service"; import { getServerCfg } from "@app/services/super-admin/super-admin-service";
import { TTokenDALFactory } from "../auth-token/auth-token-dal";
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service"; import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
import { TokenType } from "../auth-token/auth-token-types"; import { TokenType } from "../auth-token/auth-token-types";
import { TOrgDALFactory } from "../org/org-dal"; import { TOrgDALFactory } from "../org/org-dal";
@@ -34,7 +33,6 @@ type TAuthLoginServiceFactoryDep = {
orgDAL: TOrgDALFactory; orgDAL: TOrgDALFactory;
tokenService: TAuthTokenServiceFactory; tokenService: TAuthTokenServiceFactory;
smtpService: TSmtpService; smtpService: TSmtpService;
tokenDAL: TTokenDALFactory;
}; };
export type TAuthLoginFactory = ReturnType<typeof authLoginServiceFactory>; export type TAuthLoginFactory = ReturnType<typeof authLoginServiceFactory>;
@@ -42,8 +40,7 @@ export const authLoginServiceFactory = ({
userDAL, userDAL,
tokenService, tokenService,
smtpService, smtpService,
orgDAL, orgDAL
tokenDAL
}: TAuthLoginServiceFactoryDep) => { }: TAuthLoginServiceFactoryDep) => {
/* /*
* Private * Private
@@ -376,8 +373,6 @@ export const authLoginServiceFactory = ({
}); });
} }
await tokenDAL.incrementTokenSessionVersion(user.id, decodedToken.tokenVersionId);
const tokens = await generateUserTokens({ const tokens = await generateUserTokens({
authMethod: decodedToken.authMethod, authMethod: decodedToken.authMethod,
user, user,
+11 -4
View File
@@ -24,6 +24,7 @@ import {
SRP1DTO, SRP1DTO,
SRPR1Res, SRPR1Res,
TOauthTokenExchangeDTO, TOauthTokenExchangeDTO,
UserAgentType,
VerifyMfaTokenDTO, VerifyMfaTokenDTO,
VerifyMfaTokenRes, VerifyMfaTokenRes,
VerifySignupInviteDTO VerifySignupInviteDTO
@@ -60,7 +61,10 @@ export const useLogin1 = () => {
}); });
}; };
export const selectOrganization = async (data: { organizationId: string }) => { export const selectOrganization = async (data: {
organizationId: string;
userAgent?: UserAgentType;
}) => {
const { data: res } = await apiRequest.post<{ token: string }>( const { data: res } = await apiRequest.post<{ token: string }>(
"/api/v3/auth/select-organization", "/api/v3/auth/select-organization",
data data
@@ -71,11 +75,14 @@ export const selectOrganization = async (data: { organizationId: string }) => {
export const useSelectOrganization = () => { export const useSelectOrganization = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async (details: { organizationId: string }) => { mutationFn: async (details: { organizationId: string; userAgent?: UserAgentType }) => {
const data = await selectOrganization(details); const data = await selectOrganization(details);
SecurityClient.setToken(data.token); // If a custom user agent is set, then this session is meant for another consuming application, not the web application.
SecurityClient.setProviderAuthToken(""); if (!details.userAgent) {
SecurityClient.setToken(data.token);
SecurityClient.setProviderAuthToken("");
}
return data; return data;
}, },
+4
View File
@@ -145,3 +145,7 @@ export type IssueBackupPrivateKeyDTO = {
export type GetBackupEncryptedPrivateKeyDTO = { export type GetBackupEncryptedPrivateKeyDTO = {
verificationToken: string; verificationToken: string;
}; };
export enum UserAgentType {
CLI = "cli"
}
@@ -16,6 +16,7 @@ import { Button, Spinner } from "@app/components/v2";
import { SessionStorageKeys } from "@app/const"; import { SessionStorageKeys } from "@app/const";
import { useUser } from "@app/context"; import { useUser } from "@app/context";
import { useGetOrganizations, useLogoutUser, useSelectOrganization } from "@app/hooks/api"; import { useGetOrganizations, useLogoutUser, useSelectOrganization } from "@app/hooks/api";
import { UserAgentType } from "@app/hooks/api/auth/types";
import { Organization } from "@app/hooks/api/types"; import { Organization } from "@app/hooks/api/types";
import { getAuthToken, isLoggedIn } from "@app/reactQuery"; import { getAuthToken, isLoggedIn } from "@app/reactQuery";
import { navigateUserToOrg } from "@app/views/Login/Login.utils"; import { navigateUserToOrg } from "@app/views/Login/Login.utils";
@@ -68,7 +69,10 @@ export default function LoginPage() {
return; return;
} }
const { token } = await selectOrg.mutateAsync({ organizationId: organization.id }); const { token } = await selectOrg.mutateAsync({
organizationId: organization.id,
userAgent: callbackPort ? UserAgentType.CLI : undefined
});
if (callbackPort) { if (callbackPort) {
const privateKey = localStorage.getItem("PRIVATE_KEY"); const privateKey = localStorage.getItem("PRIVATE_KEY");