mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
Merge pull request #2396 from Infisical/daniel/cli-stale-session
fix: stale session after logging into CLI
This commit is contained in:
@@ -468,7 +468,7 @@ export const registerRoutes = async (
|
|||||||
projectMembershipDAL
|
projectMembershipDAL
|
||||||
});
|
});
|
||||||
|
|
||||||
const loginService = authLoginServiceFactory({ userDAL, smtpService, tokenService, orgDAL, tokenDAL: authTokenDAL });
|
const loginService = authLoginServiceFactory({ userDAL, smtpService, tokenService, orgDAL });
|
||||||
const passwordService = authPaswordServiceFactory({
|
const passwordService = authPaswordServiceFactory({
|
||||||
tokenService,
|
tokenService,
|
||||||
smtpService,
|
smtpService,
|
||||||
|
|||||||
@@ -42,7 +42,8 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
},
|
},
|
||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
organizationId: z.string().trim()
|
organizationId: z.string().trim(),
|
||||||
|
userAgent: z.enum(["cli"]).optional()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -53,7 +54,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
handler: async (req, res) => {
|
handler: async (req, res) => {
|
||||||
const cfg = getConfig();
|
const cfg = getConfig();
|
||||||
const tokens = await server.services.login.selectOrganization({
|
const tokens = await server.services.login.selectOrganization({
|
||||||
userAgent: req.headers["user-agent"],
|
userAgent: req.body.userAgent ?? req.headers["user-agent"],
|
||||||
authJwtToken: req.headers.authorization,
|
authJwtToken: req.headers.authorization,
|
||||||
organizationId: req.body.organizationId,
|
organizationId: req.body.organizationId,
|
||||||
ipAddress: req.realIp
|
ipAddress: req.realIp
|
||||||
|
|||||||
@@ -12,7 +12,6 @@ import { BadRequestError, DatabaseError, UnauthorizedError } from "@app/lib/erro
|
|||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
import { getServerCfg } from "@app/services/super-admin/super-admin-service";
|
import { getServerCfg } from "@app/services/super-admin/super-admin-service";
|
||||||
|
|
||||||
import { TTokenDALFactory } from "../auth-token/auth-token-dal";
|
|
||||||
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
|
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
|
||||||
import { TokenType } from "../auth-token/auth-token-types";
|
import { TokenType } from "../auth-token/auth-token-types";
|
||||||
import { TOrgDALFactory } from "../org/org-dal";
|
import { TOrgDALFactory } from "../org/org-dal";
|
||||||
@@ -34,7 +33,6 @@ type TAuthLoginServiceFactoryDep = {
|
|||||||
orgDAL: TOrgDALFactory;
|
orgDAL: TOrgDALFactory;
|
||||||
tokenService: TAuthTokenServiceFactory;
|
tokenService: TAuthTokenServiceFactory;
|
||||||
smtpService: TSmtpService;
|
smtpService: TSmtpService;
|
||||||
tokenDAL: TTokenDALFactory;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TAuthLoginFactory = ReturnType<typeof authLoginServiceFactory>;
|
export type TAuthLoginFactory = ReturnType<typeof authLoginServiceFactory>;
|
||||||
@@ -42,8 +40,7 @@ export const authLoginServiceFactory = ({
|
|||||||
userDAL,
|
userDAL,
|
||||||
tokenService,
|
tokenService,
|
||||||
smtpService,
|
smtpService,
|
||||||
orgDAL,
|
orgDAL
|
||||||
tokenDAL
|
|
||||||
}: TAuthLoginServiceFactoryDep) => {
|
}: TAuthLoginServiceFactoryDep) => {
|
||||||
/*
|
/*
|
||||||
* Private
|
* Private
|
||||||
@@ -376,8 +373,6 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
await tokenDAL.incrementTokenSessionVersion(user.id, decodedToken.tokenVersionId);
|
|
||||||
|
|
||||||
const tokens = await generateUserTokens({
|
const tokens = await generateUserTokens({
|
||||||
authMethod: decodedToken.authMethod,
|
authMethod: decodedToken.authMethod,
|
||||||
user,
|
user,
|
||||||
|
|||||||
@@ -24,6 +24,7 @@ import {
|
|||||||
SRP1DTO,
|
SRP1DTO,
|
||||||
SRPR1Res,
|
SRPR1Res,
|
||||||
TOauthTokenExchangeDTO,
|
TOauthTokenExchangeDTO,
|
||||||
|
UserAgentType,
|
||||||
VerifyMfaTokenDTO,
|
VerifyMfaTokenDTO,
|
||||||
VerifyMfaTokenRes,
|
VerifyMfaTokenRes,
|
||||||
VerifySignupInviteDTO
|
VerifySignupInviteDTO
|
||||||
@@ -60,7 +61,10 @@ export const useLogin1 = () => {
|
|||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
export const selectOrganization = async (data: { organizationId: string }) => {
|
export const selectOrganization = async (data: {
|
||||||
|
organizationId: string;
|
||||||
|
userAgent?: UserAgentType;
|
||||||
|
}) => {
|
||||||
const { data: res } = await apiRequest.post<{ token: string }>(
|
const { data: res } = await apiRequest.post<{ token: string }>(
|
||||||
"/api/v3/auth/select-organization",
|
"/api/v3/auth/select-organization",
|
||||||
data
|
data
|
||||||
@@ -71,11 +75,14 @@ export const selectOrganization = async (data: { organizationId: string }) => {
|
|||||||
export const useSelectOrganization = () => {
|
export const useSelectOrganization = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
return useMutation({
|
return useMutation({
|
||||||
mutationFn: async (details: { organizationId: string }) => {
|
mutationFn: async (details: { organizationId: string; userAgent?: UserAgentType }) => {
|
||||||
const data = await selectOrganization(details);
|
const data = await selectOrganization(details);
|
||||||
|
|
||||||
SecurityClient.setToken(data.token);
|
// If a custom user agent is set, then this session is meant for another consuming application, not the web application.
|
||||||
SecurityClient.setProviderAuthToken("");
|
if (!details.userAgent) {
|
||||||
|
SecurityClient.setToken(data.token);
|
||||||
|
SecurityClient.setProviderAuthToken("");
|
||||||
|
}
|
||||||
|
|
||||||
return data;
|
return data;
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -145,3 +145,7 @@ export type IssueBackupPrivateKeyDTO = {
|
|||||||
export type GetBackupEncryptedPrivateKeyDTO = {
|
export type GetBackupEncryptedPrivateKeyDTO = {
|
||||||
verificationToken: string;
|
verificationToken: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export enum UserAgentType {
|
||||||
|
CLI = "cli"
|
||||||
|
}
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ import { Button, Spinner } from "@app/components/v2";
|
|||||||
import { SessionStorageKeys } from "@app/const";
|
import { SessionStorageKeys } from "@app/const";
|
||||||
import { useUser } from "@app/context";
|
import { useUser } from "@app/context";
|
||||||
import { useGetOrganizations, useLogoutUser, useSelectOrganization } from "@app/hooks/api";
|
import { useGetOrganizations, useLogoutUser, useSelectOrganization } from "@app/hooks/api";
|
||||||
|
import { UserAgentType } from "@app/hooks/api/auth/types";
|
||||||
import { Organization } from "@app/hooks/api/types";
|
import { Organization } from "@app/hooks/api/types";
|
||||||
import { getAuthToken, isLoggedIn } from "@app/reactQuery";
|
import { getAuthToken, isLoggedIn } from "@app/reactQuery";
|
||||||
import { navigateUserToOrg } from "@app/views/Login/Login.utils";
|
import { navigateUserToOrg } from "@app/views/Login/Login.utils";
|
||||||
@@ -68,7 +69,10 @@ export default function LoginPage() {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
const { token } = await selectOrg.mutateAsync({ organizationId: organization.id });
|
const { token } = await selectOrg.mutateAsync({
|
||||||
|
organizationId: organization.id,
|
||||||
|
userAgent: callbackPort ? UserAgentType.CLI : undefined
|
||||||
|
});
|
||||||
|
|
||||||
if (callbackPort) {
|
if (callbackPort) {
|
||||||
const privateKey = localStorage.getItem("PRIVATE_KEY");
|
const privateKey = localStorage.getItem("PRIVATE_KEY");
|
||||||
|
|||||||
Reference in New Issue
Block a user