mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 07:26:45 +00:00
Split requireBlindIndicesEnabled, E2EEOff, requireIPAllowlistCheck away from requireWorkspaceAuth
This commit is contained in:
@@ -14,6 +14,9 @@ import requireServiceAccountAuth from "./requireServiceAccountAuth";
|
|||||||
import requireServiceAccountWorkspacePermissionAuth from "./requireServiceAccountWorkspacePermissionAuth";
|
import requireServiceAccountWorkspacePermissionAuth from "./requireServiceAccountWorkspacePermissionAuth";
|
||||||
import requireSecretAuth from "./requireSecretAuth";
|
import requireSecretAuth from "./requireSecretAuth";
|
||||||
import requireSecretsAuth from "./requireSecretsAuth";
|
import requireSecretsAuth from "./requireSecretsAuth";
|
||||||
|
import requireBlindIndicesEnabled from "./requireBlindIndicesEnabled";
|
||||||
|
import requireE2EEOff from "./requireE2EEOff";
|
||||||
|
import requireIPAllowlistCheck from "./requireIPAllowlistCheck";
|
||||||
import validateRequest from "./validateRequest";
|
import validateRequest from "./validateRequest";
|
||||||
|
|
||||||
export {
|
export {
|
||||||
@@ -33,5 +36,8 @@ export {
|
|||||||
requireServiceAccountWorkspacePermissionAuth,
|
requireServiceAccountWorkspacePermissionAuth,
|
||||||
requireSecretAuth,
|
requireSecretAuth,
|
||||||
requireSecretsAuth,
|
requireSecretsAuth,
|
||||||
|
requireBlindIndicesEnabled,
|
||||||
|
requireE2EEOff,
|
||||||
|
requireIPAllowlistCheck,
|
||||||
validateRequest,
|
validateRequest,
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
import { NextFunction, Request, Response } from "express";
|
||||||
|
import { Types } from "mongoose";
|
||||||
|
import { SecretBlindIndexData } from "../models";
|
||||||
|
import { UnauthorizedRequestError } from "../utils/errors";
|
||||||
|
|
||||||
|
type req = "params" | "body" | "query";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validate if workspace with [workspaceId] has blind indices enabled
|
||||||
|
* @param {Object} obj
|
||||||
|
* @param {String} obj.locationWorkspaceId - location of [workspaceId] on request (e.g. params, body) for parsing
|
||||||
|
* @returns
|
||||||
|
*/
|
||||||
|
const requireBlindIndicesEnabled = ({
|
||||||
|
locationWorkspaceId
|
||||||
|
}: {
|
||||||
|
locationWorkspaceId: req;
|
||||||
|
}) => {
|
||||||
|
return async (req: Request, res: Response, next: NextFunction) => {
|
||||||
|
const workspaceId = req[locationWorkspaceId]?.workspaceId;
|
||||||
|
|
||||||
|
const secretBlindIndexData = await SecretBlindIndexData.exists({
|
||||||
|
workspace: new Types.ObjectId(workspaceId)
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!secretBlindIndexData) throw UnauthorizedRequestError({
|
||||||
|
message: "Failed workspace authorization due to blind indices not being enabled"
|
||||||
|
});
|
||||||
|
|
||||||
|
return next();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export default requireBlindIndicesEnabled;
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
import { NextFunction, Request, Response } from "express";
|
||||||
|
import { BadRequestError } from "../utils/errors";
|
||||||
|
import { BotService } from "../services";
|
||||||
|
|
||||||
|
type req = "params" | "body" | "query";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validate if workspace with [workspaceId] has E2EE off/disabled
|
||||||
|
* @param {Object} obj
|
||||||
|
* @param {String} obj.locationWorkspaceId - location of [workspaceId] on request (e.g. params, body) for parsing
|
||||||
|
* @returns
|
||||||
|
*/
|
||||||
|
const requireE2EEOff = ({
|
||||||
|
locationWorkspaceId
|
||||||
|
}: {
|
||||||
|
locationWorkspaceId: req;
|
||||||
|
}) => {
|
||||||
|
return async (req: Request, _: Response, next: NextFunction) => {
|
||||||
|
const workspaceId = req[locationWorkspaceId]?.workspaceId;
|
||||||
|
|
||||||
|
const isWorkspaceE2EE = await BotService.getIsWorkspaceE2EE(workspaceId);
|
||||||
|
|
||||||
|
if (isWorkspaceE2EE) throw BadRequestError({
|
||||||
|
message: "Failed workspace authorization due to end-to-end encryption not being disabled"
|
||||||
|
});
|
||||||
|
|
||||||
|
return next();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export default requireE2EEOff;
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
import net from "net";
|
||||||
|
import { NextFunction, Request, Response } from "express";
|
||||||
|
import { UnauthorizedRequestError } from "../utils/errors";
|
||||||
|
import { extractIPDetails } from "../utils/ip";
|
||||||
|
import { ActorType, TrustedIP } from "../ee/models";
|
||||||
|
|
||||||
|
type req = "params" | "body" | "query";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validate if workspace with [workspaceId] has E2EE off/disabled
|
||||||
|
* @param {Object} obj
|
||||||
|
* @param {String} obj.locationWorkspaceId - location of [workspaceId] on request (e.g. params, body) for parsing
|
||||||
|
* @returns
|
||||||
|
*/
|
||||||
|
const requireIPAllowlistCheck = ({
|
||||||
|
locationWorkspaceId
|
||||||
|
}: {
|
||||||
|
locationWorkspaceId: req;
|
||||||
|
}) => {
|
||||||
|
return async (req: Request, _: Response, next: NextFunction) => {
|
||||||
|
const workspaceId = req[locationWorkspaceId]?.workspaceId;
|
||||||
|
|
||||||
|
if (req.authData.actor.type === ActorType.SERVICE) {
|
||||||
|
const trustedIps = await TrustedIP.find({
|
||||||
|
workspace: workspaceId
|
||||||
|
});
|
||||||
|
|
||||||
|
if (trustedIps.length > 0) {
|
||||||
|
// case: check the IP address of the inbound request against trusted IPs
|
||||||
|
|
||||||
|
const blockList = new net.BlockList();
|
||||||
|
|
||||||
|
for (const trustedIp of trustedIps) {
|
||||||
|
if (trustedIp.prefix !== undefined) {
|
||||||
|
blockList.addSubnet(trustedIp.ipAddress, trustedIp.prefix, trustedIp.type);
|
||||||
|
} else {
|
||||||
|
blockList.addAddress(trustedIp.ipAddress, trustedIp.type);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const { type } = extractIPDetails(req.authData.ipAddress);
|
||||||
|
const check = blockList.check(req.authData.ipAddress, type);
|
||||||
|
|
||||||
|
if (!check)
|
||||||
|
throw UnauthorizedRequestError({
|
||||||
|
message: "Failed workspace authorization"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return next();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export default requireIPAllowlistCheck;
|
||||||
@@ -9,24 +9,18 @@ type req = "params" | "body" | "query";
|
|||||||
* on request params.
|
* on request params.
|
||||||
* @param {Object} obj
|
* @param {Object} obj
|
||||||
* @param {String[]} obj.acceptedRoles - accepted workspace roles for JWT auth
|
* @param {String[]} obj.acceptedRoles - accepted workspace roles for JWT auth
|
||||||
* @param {String[]} obj.location - location of [workspaceId] on request (e.g. params, body) for parsing
|
* @param {String} obj.locationWorkspaceId - location of [workspaceId] on request (e.g. params, body) for parsing
|
||||||
*/
|
*/
|
||||||
const requireWorkspaceAuth = ({
|
const requireWorkspaceAuth = ({
|
||||||
acceptedRoles,
|
acceptedRoles,
|
||||||
locationWorkspaceId,
|
locationWorkspaceId,
|
||||||
locationEnvironment = undefined,
|
locationEnvironment = undefined,
|
||||||
requiredPermissions = [],
|
requiredPermissions = [],
|
||||||
requireBlindIndicesEnabled = false,
|
|
||||||
requireE2EEOff = false,
|
|
||||||
checkIPAllowlist = false
|
|
||||||
}: {
|
}: {
|
||||||
acceptedRoles: Array<"admin" | "member">;
|
acceptedRoles: Array<"admin" | "member">;
|
||||||
locationWorkspaceId: req;
|
locationWorkspaceId: req;
|
||||||
locationEnvironment?: req | undefined;
|
locationEnvironment?: req | undefined;
|
||||||
requiredPermissions?: string[];
|
requiredPermissions?: string[];
|
||||||
requireBlindIndicesEnabled?: boolean;
|
|
||||||
requireE2EEOff?: boolean;
|
|
||||||
checkIPAllowlist?: boolean;
|
|
||||||
}) => {
|
}) => {
|
||||||
return async (req: Request, res: Response, next: NextFunction) => {
|
return async (req: Request, res: Response, next: NextFunction) => {
|
||||||
const workspaceId = req[locationWorkspaceId]?.workspaceId;
|
const workspaceId = req[locationWorkspaceId]?.workspaceId;
|
||||||
@@ -38,10 +32,7 @@ const requireWorkspaceAuth = ({
|
|||||||
workspaceId: new Types.ObjectId(workspaceId),
|
workspaceId: new Types.ObjectId(workspaceId),
|
||||||
environment,
|
environment,
|
||||||
acceptedRoles,
|
acceptedRoles,
|
||||||
requiredPermissions,
|
requiredPermissions
|
||||||
requireBlindIndicesEnabled,
|
|
||||||
requireE2EEOff,
|
|
||||||
checkIPAllowlist
|
|
||||||
});
|
});
|
||||||
|
|
||||||
if (membership) {
|
if (membership) {
|
||||||
|
|||||||
@@ -1,6 +1,12 @@
|
|||||||
import express from "express";
|
import express from "express";
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
import { requireAuth, requireWorkspaceAuth, validateRequest } from "../../middleware";
|
import {
|
||||||
|
requireAuth,
|
||||||
|
requireBlindIndicesEnabled,
|
||||||
|
requireE2EEOff,
|
||||||
|
requireWorkspaceAuth,
|
||||||
|
validateRequest
|
||||||
|
} from "../../middleware";
|
||||||
import { body, param, query } from "express-validator";
|
import { body, param, query } from "express-validator";
|
||||||
import { secretsController } from "../../controllers/v3";
|
import { secretsController } from "../../controllers/v3";
|
||||||
import {
|
import {
|
||||||
@@ -21,8 +27,6 @@ router.get(
|
|||||||
secretsController.getSecretsRaw
|
secretsController.getSecretsRaw
|
||||||
);
|
);
|
||||||
|
|
||||||
// TODO(akhilmhdh): tony please split the requireWorkspaceAuth to multiple middlewares
|
|
||||||
// IP checking into another one
|
|
||||||
router.get(
|
router.get(
|
||||||
"/raw/:secretName",
|
"/raw/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
@@ -32,10 +36,13 @@ router.get(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "query",
|
locationWorkspaceId: "query",
|
||||||
locationEnvironment: "query",
|
locationEnvironment: "query",
|
||||||
requiredPermissions: [PERMISSION_READ_SECRETS],
|
requiredPermissions: [PERMISSION_READ_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: true,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "query"
|
||||||
|
}),
|
||||||
|
requireE2EEOff({
|
||||||
|
locationWorkspaceId: "query"
|
||||||
}),
|
}),
|
||||||
secretsController.getSecretByNameRaw
|
secretsController.getSecretByNameRaw
|
||||||
);
|
);
|
||||||
@@ -49,10 +56,13 @@ router.post(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "body",
|
locationWorkspaceId: "body",
|
||||||
locationEnvironment: "body",
|
locationEnvironment: "body",
|
||||||
requiredPermissions: [PERMISSION_WRITE_SECRETS],
|
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: true,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "body"
|
||||||
|
}),
|
||||||
|
requireE2EEOff({
|
||||||
|
locationWorkspaceId: "body"
|
||||||
}),
|
}),
|
||||||
secretsController.createSecretRaw
|
secretsController.createSecretRaw
|
||||||
);
|
);
|
||||||
@@ -66,10 +76,13 @@ router.patch(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "body",
|
locationWorkspaceId: "body",
|
||||||
locationEnvironment: "body",
|
locationEnvironment: "body",
|
||||||
requiredPermissions: [PERMISSION_WRITE_SECRETS],
|
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: true,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "body"
|
||||||
|
}),
|
||||||
|
requireE2EEOff({
|
||||||
|
locationWorkspaceId: "body"
|
||||||
}),
|
}),
|
||||||
secretsController.updateSecretByNameRaw
|
secretsController.updateSecretByNameRaw
|
||||||
);
|
);
|
||||||
@@ -83,10 +96,13 @@ router.delete(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "body",
|
locationWorkspaceId: "body",
|
||||||
locationEnvironment: "body",
|
locationEnvironment: "body",
|
||||||
requiredPermissions: [PERMISSION_WRITE_SECRETS],
|
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: true,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "body"
|
||||||
|
}),
|
||||||
|
requireE2EEOff({
|
||||||
|
locationWorkspaceId: "body"
|
||||||
}),
|
}),
|
||||||
secretsController.deleteSecretByNameRaw
|
secretsController.deleteSecretByNameRaw
|
||||||
);
|
);
|
||||||
@@ -105,10 +121,10 @@ router.get(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "query",
|
locationWorkspaceId: "query",
|
||||||
locationEnvironment: "query",
|
locationEnvironment: "query",
|
||||||
requiredPermissions: [PERMISSION_READ_SECRETS],
|
requiredPermissions: [PERMISSION_READ_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: false,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "query"
|
||||||
}),
|
}),
|
||||||
secretsController.getSecrets
|
secretsController.getSecrets
|
||||||
);
|
);
|
||||||
@@ -122,10 +138,10 @@ router.post(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "body",
|
locationWorkspaceId: "body",
|
||||||
locationEnvironment: "body",
|
locationEnvironment: "body",
|
||||||
requiredPermissions: [PERMISSION_WRITE_SECRETS],
|
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: false,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "body"
|
||||||
}),
|
}),
|
||||||
secretsController.createSecret
|
secretsController.createSecret
|
||||||
);
|
);
|
||||||
@@ -139,9 +155,10 @@ router.get(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "query",
|
locationWorkspaceId: "query",
|
||||||
locationEnvironment: "query",
|
locationEnvironment: "query",
|
||||||
requiredPermissions: [PERMISSION_READ_SECRETS],
|
requiredPermissions: [PERMISSION_READ_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
checkIPAllowlist: false
|
requireBlindIndicesEnabled({
|
||||||
|
locationWorkspaceId: "query"
|
||||||
}),
|
}),
|
||||||
secretsController.getSecretByName
|
secretsController.getSecretByName
|
||||||
);
|
);
|
||||||
@@ -155,10 +172,10 @@ router.patch(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "body",
|
locationWorkspaceId: "body",
|
||||||
locationEnvironment: "body",
|
locationEnvironment: "body",
|
||||||
requiredPermissions: [PERMISSION_WRITE_SECRETS],
|
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: false,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "body"
|
||||||
}),
|
}),
|
||||||
secretsController.updateSecretByName
|
secretsController.updateSecretByName
|
||||||
);
|
);
|
||||||
@@ -178,10 +195,10 @@ router.delete(
|
|||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
locationWorkspaceId: "body",
|
locationWorkspaceId: "body",
|
||||||
locationEnvironment: "body",
|
locationEnvironment: "body",
|
||||||
requiredPermissions: [PERMISSION_WRITE_SECRETS],
|
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||||
requireBlindIndicesEnabled: true,
|
}),
|
||||||
requireE2EEOff: false,
|
requireBlindIndicesEnabled({
|
||||||
checkIPAllowlist: false
|
locationWorkspaceId: "body"
|
||||||
}),
|
}),
|
||||||
secretsController.deleteSecretByName
|
secretsController.deleteSecretByName
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -1,13 +1,10 @@
|
|||||||
import net from "net";
|
|
||||||
import { Types } from "mongoose";
|
import { Types } from "mongoose";
|
||||||
import { IServiceTokenData, IUser, SecretBlindIndexData, Workspace } from "../models";
|
import { IServiceTokenData, IUser, Workspace } from "../models";
|
||||||
import { ActorType, TrustedIP } from "../ee/models";
|
import { ActorType } from "../ee/models";
|
||||||
import { validateUserClientForWorkspace } from "./user";
|
import { validateUserClientForWorkspace } from "./user";
|
||||||
import { validateServiceTokenDataClientForWorkspace } from "./serviceTokenData";
|
import { validateServiceTokenDataClientForWorkspace } from "./serviceTokenData";
|
||||||
import { BadRequestError, UnauthorizedRequestError, WorkspaceNotFoundError } from "../utils/errors";
|
import { WorkspaceNotFoundError } from "../utils/errors";
|
||||||
import { BotService } from "../services";
|
|
||||||
import { AuthData } from "../interfaces/middleware";
|
import { AuthData } from "../interfaces/middleware";
|
||||||
import { extractIPDetails } from "../utils/ip";
|
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
import { EventType, UserAgentType } from "../ee/models";
|
import { EventType, UserAgentType } from "../ee/models";
|
||||||
|
|
||||||
@@ -26,50 +23,19 @@ export const validateClientForWorkspace = async ({
|
|||||||
workspaceId,
|
workspaceId,
|
||||||
environment,
|
environment,
|
||||||
acceptedRoles,
|
acceptedRoles,
|
||||||
requiredPermissions,
|
requiredPermissions
|
||||||
requireBlindIndicesEnabled,
|
|
||||||
requireE2EEOff,
|
|
||||||
checkIPAllowlist
|
|
||||||
}: {
|
}: {
|
||||||
authData: AuthData;
|
authData: AuthData;
|
||||||
workspaceId: Types.ObjectId;
|
workspaceId: Types.ObjectId;
|
||||||
environment?: string;
|
environment?: string;
|
||||||
acceptedRoles: Array<"admin" | "member">;
|
acceptedRoles: Array<"admin" | "member">;
|
||||||
requiredPermissions?: string[];
|
requiredPermissions?: string[];
|
||||||
requireBlindIndicesEnabled: boolean;
|
|
||||||
requireE2EEOff: boolean;
|
|
||||||
checkIPAllowlist: boolean;
|
|
||||||
}) => {
|
}) => {
|
||||||
const workspace = await Workspace.findById(workspaceId);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
|
|
||||||
if (!workspace)
|
if (!workspace) throw WorkspaceNotFoundError({
|
||||||
throw WorkspaceNotFoundError({
|
message: "Failed to find workspace"
|
||||||
message: "Failed to find workspace"
|
});
|
||||||
});
|
|
||||||
|
|
||||||
if (requireBlindIndicesEnabled) {
|
|
||||||
// case: blind indices are not enabled for secrets in this workspace
|
|
||||||
// (i.e. workspace was created before blind indices were introduced
|
|
||||||
// and no admin has enabled it)
|
|
||||||
|
|
||||||
const secretBlindIndexData = await SecretBlindIndexData.exists({
|
|
||||||
workspace: new Types.ObjectId(workspaceId)
|
|
||||||
});
|
|
||||||
|
|
||||||
if (!secretBlindIndexData)
|
|
||||||
throw UnauthorizedRequestError({
|
|
||||||
message: "Failed workspace authorization due to blind indices not being enabled"
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (requireE2EEOff) {
|
|
||||||
const isWorkspaceE2EE = await BotService.getIsWorkspaceE2EE(workspaceId);
|
|
||||||
|
|
||||||
if (isWorkspaceE2EE)
|
|
||||||
throw BadRequestError({
|
|
||||||
message: "Failed workspace authorization due to end-to-end encryption not being disabled"
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
let membership;
|
let membership;
|
||||||
switch (authData.actor.type) {
|
switch (authData.actor.type) {
|
||||||
@@ -84,34 +50,6 @@ export const validateClientForWorkspace = async ({
|
|||||||
|
|
||||||
return { membership, workspace };
|
return { membership, workspace };
|
||||||
case ActorType.SERVICE:
|
case ActorType.SERVICE:
|
||||||
if (checkIPAllowlist) {
|
|
||||||
const trustedIps = await TrustedIP.find({
|
|
||||||
workspace: workspaceId
|
|
||||||
});
|
|
||||||
|
|
||||||
if (trustedIps.length > 0) {
|
|
||||||
// case: check the IP address of the inbound request against trusted IPs
|
|
||||||
|
|
||||||
const blockList = new net.BlockList();
|
|
||||||
|
|
||||||
for (const trustedIp of trustedIps) {
|
|
||||||
if (trustedIp.prefix !== undefined) {
|
|
||||||
blockList.addSubnet(trustedIp.ipAddress, trustedIp.prefix, trustedIp.type);
|
|
||||||
} else {
|
|
||||||
blockList.addAddress(trustedIp.ipAddress, trustedIp.type);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
const { type } = extractIPDetails(authData.ipAddress);
|
|
||||||
const check = blockList.check(authData.ipAddress, type);
|
|
||||||
|
|
||||||
if (!check)
|
|
||||||
throw UnauthorizedRequestError({
|
|
||||||
message: "Failed workspace authorization"
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
await validateServiceTokenDataClientForWorkspace({
|
await validateServiceTokenDataClientForWorkspace({
|
||||||
serviceTokenData: authData.authPayload as IServiceTokenData,
|
serviceTokenData: authData.authPayload as IServiceTokenData,
|
||||||
workspaceId,
|
workspaceId,
|
||||||
|
|||||||
Reference in New Issue
Block a user