Merge pull request #2093 from Infisical/doc/add-native-auth-to-docs

doc: added native auths to api reference
This commit is contained in:
BlackMagiq
2024-07-11 09:46:26 +07:00
committed by GitHub
41 changed files with 569 additions and 137 deletions
+204 -8
View File
@@ -70,13 +70,13 @@ export const UNIVERSAL_AUTH = {
"The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses." "The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses."
}, },
RETRIEVE: { RETRIEVE: {
identityId: "The ID of the identity to retrieve." identityId: "The ID of the identity to retrieve the auth method for."
}, },
REVOKE: { REVOKE: {
identityId: "The ID of the identity to revoke." identityId: "The ID of the identity to revoke the auth method for."
}, },
UPDATE: { UPDATE: {
identityId: "The ID of the identity to update.", identityId: "The ID of the identity to update the auth method for.",
clientSecretTrustedIps: "The new list of IPs or CIDR ranges that the Client Secret can be used from.", clientSecretTrustedIps: "The new list of IPs or CIDR ranges that the Client Secret can be used from.",
accessTokenTrustedIps: "The new list of IPs or CIDR ranges that access tokens can be used from.", accessTokenTrustedIps: "The new list of IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The new lifetime for an access token in seconds.", accessTokenTTL: "The new lifetime for an access token in seconds.",
@@ -119,32 +119,228 @@ export const AWS_AUTH = {
"The base64-encoded body of the signed request. Most likely, the base64-encoding of Action=GetCallerIdentity&Version=2011-06-15.", "The base64-encoded body of the signed request. Most likely, the base64-encoding of Action=GetCallerIdentity&Version=2011-06-15.",
iamRequestHeaders: "The base64-encoded headers of the sts:GetCallerIdentity signed request." iamRequestHeaders: "The base64-encoded headers of the sts:GetCallerIdentity signed request."
}, },
ATTACH: {
identityId: "The ID of the identity to attach the configuration onto.",
allowedPrincipalArns:
"The comma-separated list of trusted IAM principal ARNs that are allowed to authenticate with Infisical.",
allowedAccountIds:
"The comma-separated list of trusted AWS account IDs that are allowed to authenticate with Infisical.",
accessTokenTTL: "The lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The maximum lifetime for an acccess token in seconds.",
stsEndpoint: "The endpoint URL for the AWS STS API.",
accessTokenNumUsesLimit: "The maximum number of times that an access token can be used.",
accessTokenTrustedIps: "The IPs or CIDR ranges that access tokens can be used from."
},
UPDATE: {
identityId: "The ID of the identity to update the auth method for.",
allowedPrincipalArns:
"The new comma-separated list of trusted IAM principal ARNs that are allowed to authenticate with Infisical.",
allowedAccountIds:
"The new comma-separated list of trusted AWS account IDs that are allowed to authenticate with Infisical.",
accessTokenTTL: "The new lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The new maximum lifetime for an acccess token in seconds.",
stsEndpoint: "The new endpoint URL for the AWS STS API.",
accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used.",
accessTokenTrustedIps: "The new IPs or CIDR ranges that access tokens can be used from."
},
RETRIEVE: {
identityId: "The ID of the identity to retrieve the auth method for."
},
REVOKE: { REVOKE: {
identityId: "The ID of the identity to revoke." identityId: "The ID of the identity to revoke the auth method for."
} }
} as const; } as const;
export const AZURE_AUTH = { export const AZURE_AUTH = {
LOGIN: {
identityId: "The ID of the identity to login."
},
ATTACH: {
identityId: "The ID of the identity to attach the configuration onto.",
tenantId: "The tenant ID for the Azure AD organization.",
resource: "The resource URL for the application registered in Azure AD.",
allowedServicePrincipalIds:
"The comma-separated list of Azure AD service principal IDs that are allowed to authenticate with Infisical.",
accessTokenTrustedIps: "The IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The maximum number of times that an access token can be used."
},
UPDATE: {
identityId: "The ID of the identity to update the auth method for.",
tenantId: "The new tenant ID for the Azure AD organization.",
resource: "The new resource URL for the application registered in Azure AD.",
allowedServicePrincipalIds:
"The new comma-separated list of Azure AD service principal IDs that are allowed to authenticate with Infisical.",
accessTokenTrustedIps: "The new IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The new lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The new maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used."
},
RETRIEVE: {
identityId: "The ID of the identity to retrieve the auth method for."
},
REVOKE: { REVOKE: {
identityId: "The ID of the identity to revoke." identityId: "The ID of the identity to revoke the auth method for."
} }
} as const; } as const;
export const GCP_AUTH = { export const GCP_AUTH = {
LOGIN: {
identityId: "The ID of the identity to login."
},
ATTACH: {
identityId: "The ID of the identity to attach the configuration onto.",
allowedServiceAccounts:
"The comma-separated list of trusted service account emails corresponding to the GCE resource(s) allowed to authenticate with Infisical.",
allowedProjects:
"The comma-separated list of trusted GCP projects that the GCE instance must belong to authenticate with Infisical.",
allowedZones:
"The comma-separated list of trusted zones that the GCE instances must belong to authenticate with Infisical.",
accessTokenTrustedIps: "The IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The maximum number of times that an access token can be used."
},
UPDATE: {
identityId: "The ID of the identity to update the auth method for.",
allowedServiceAccounts:
"The new comma-separated list of trusted service account emails corresponding to the GCE resource(s) allowed to authenticate with Infisical.",
allowedProjects:
"The new comma-separated list of trusted GCP projects that the GCE instance must belong to authenticate with Infisical.",
allowedZones:
"The new comma-separated list of trusted zones that the GCE instances must belong to authenticate with Infisical.",
accessTokenTrustedIps: "The new IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The new lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The new maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used."
},
RETRIEVE: {
identityId: "The ID of the identity to retrieve the auth method for."
},
REVOKE: { REVOKE: {
identityId: "The ID of the identity to revoke." identityId: "The ID of the identity to revoke the auth method for."
} }
} as const; } as const;
export const KUBERNETES_AUTH = { export const KUBERNETES_AUTH = {
LOGIN: {
identityId: "The ID of the identity to login."
},
ATTACH: {
identityId: "The ID of the identity to attach the configuration onto.",
kubernetesHost: "The host string, host:port pair, or URL to the base of the Kubernetes API server.",
caCert: "The PEM-encoded CA cert for the Kubernetes API server.",
tokenReviewerJwt:
"The long-lived service account JWT token for Infisical to access the TokenReview API to validate other service account JWT tokens submitted by applications/pods.",
allowedNamespaces:
"The comma-separated list of trusted namespaces that service accounts must belong to authenticate with Infisical.",
allowedNames: "The comma-separated list of trusted service account names that can authenticate with Infisical.",
allowedAudience:
"The optional audience claim that the service account JWT token must have to authenticate with Infisical.",
accessTokenTrustedIps: "The IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The maximum number of times that an access token can be used."
},
UPDATE: {
identityId: "The ID of the identity to update the auth method for.",
kubernetesHost: "The new host string, host:port pair, or URL to the base of the Kubernetes API server.",
caCert: "The new PEM-encoded CA cert for the Kubernetes API server.",
tokenReviewerJwt:
"The new long-lived service account JWT token for Infisical to access the TokenReview API to validate other service account JWT tokens submitted by applications/pods.",
allowedNamespaces:
"The new comma-separated list of trusted namespaces that service accounts must belong to authenticate with Infisical.",
allowedNames: "The new comma-separated list of trusted service account names that can authenticate with Infisical.",
allowedAudience:
"The new optional audience claim that the service account JWT token must have to authenticate with Infisical.",
accessTokenTrustedIps: "The new IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The new lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The new maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used."
},
RETRIEVE: {
identityId: "The ID of the identity to retrieve the auth method for."
},
REVOKE: { REVOKE: {
identityId: "The ID of the identity to revoke." identityId: "The ID of the identity to revoke the auth method for."
}
} as const;
export const TOKEN_AUTH = {
ATTACH: {
identityId: "The ID of the identity to attach the configuration onto.",
accessTokenTrustedIps: "The IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The maximum number of times that an access token can be used."
},
UPDATE: {
identityId: "The ID of the identity to update the auth method for.",
accessTokenTrustedIps: "The new IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The new lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The new maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used."
},
RETRIEVE: {
identityId: "The ID of the identity to retrieve the auth method for."
},
REVOKE: {
identityId: "The ID of the identity to revoke the auth method for."
},
GET_TOKENS: {
identityId: "The ID of the identity to list token metadata for.",
offset: "The offset to start from. If you enter 10, it will start from the 10th token.",
limit: "The number of tokens to return"
},
CREATE_TOKEN: {
identityId: "The ID of the identity to create the token for.",
name: "The name of the token to create"
},
UPDATE_TOKEN: {
tokenId: "The ID of the token to update metadata for",
name: "The name of the token to update to"
},
REVOKE_TOKEN: {
tokenId: "The ID of the token to revoke"
} }
} as const; } as const;
export const OIDC_AUTH = { export const OIDC_AUTH = {
LOGIN: {
identityId: "The ID of the identity to login."
},
ATTACH: {
identityId: "The ID of the identity to attach the configuration onto.",
oidcDiscoveryUrl: "The URL used to retrieve the OpenID Connect configuration from the identity provider.",
caCert: "The PEM-encoded CA cert for establishing secure communication with the Identity Provider endpoints.",
boundIssuer: "The unique identifier of the identity provider issuing the JWT.",
boundAudiences: "The list of intended recipients.",
boundClaims: "The attributes that should be present in the JWT for it to be valid.",
boundSubject: "The expected principal that is the subject of the JWT.",
accessTokenTrustedIps: "The IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The maximum number of times that an access token can be used."
},
UPDATE: {
identityId: "The ID of the identity to update the auth method for.",
oidcDiscoveryUrl: "The new URL used to retrieve the OpenID Connect configuration from the identity provider.",
caCert: "The new PEM-encoded CA cert for establishing secure communication with the Identity Provider endpoints.",
boundIssuer: "The new unique identifier of the identity provider issuing the JWT.",
boundAudiences: "The new list of intended recipients.",
boundClaims: "The new attributes that should be present in the JWT for it to be valid.",
boundSubject: "The new expected principal that is the subject of the JWT.",
accessTokenTrustedIps: "The new IPs or CIDR ranges that access tokens can be used from.",
accessTokenTTL: "The new lifetime for an acccess token in seconds.",
accessTokenMaxTTL: "The new maximum lifetime for an acccess token in seconds.",
accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used."
},
RETRIEVE: {
identityId: "The ID of the identity to retrieve the auth method for."
},
REVOKE: { REVOKE: {
identityId: "The ID of the identity to revoke." identityId: "The ID of the identity to revoke the auth method for."
} }
} as const; } as const;
@@ -77,19 +77,25 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(AWS_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z.object({
stsEndpoint: z.string().trim().min(1).default("https://sts.amazonaws.com/"), stsEndpoint: z
allowedPrincipalArns: validatePrincipalArns, .string()
allowedAccountIds: validateAccountIds, .trim()
.min(1)
.default("https://sts.amazonaws.com/")
.describe(AWS_AUTH.ATTACH.stsEndpoint),
allowedPrincipalArns: validatePrincipalArns.describe(AWS_AUTH.ATTACH.allowedPrincipalArns),
allowedAccountIds: validateAccountIds.describe(AWS_AUTH.ATTACH.allowedAccountIds),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(AWS_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -97,15 +103,17 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(AWS_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0) .describe(AWS_AUTH.ATTACH.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(AWS_AUTH.ATTACH.accessTokenNumUsesLimit)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -160,21 +168,22 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(AWS_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z.object({
stsEndpoint: z.string().trim().min(1).optional(), stsEndpoint: z.string().trim().min(1).optional().describe(AWS_AUTH.UPDATE.stsEndpoint),
allowedPrincipalArns: validatePrincipalArns, allowedPrincipalArns: validatePrincipalArns.describe(AWS_AUTH.UPDATE.allowedPrincipalArns),
allowedAccountIds: validateAccountIds, allowedAccountIds: validateAccountIds.describe(AWS_AUTH.UPDATE.allowedAccountIds),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.optional(), .optional()
accessTokenTTL: z.number().int().min(0).optional(), .describe(AWS_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional(), accessTokenTTL: z.number().int().min(0).optional().describe(AWS_AUTH.UPDATE.accessTokenTTL),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(AWS_AUTH.UPDATE.accessTokenNumUsesLimit),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
@@ -182,6 +191,7 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.optional() .optional()
.describe(AWS_AUTH.UPDATE.accessTokenMaxTTL)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -236,7 +246,7 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(AWS_AUTH.RETRIEVE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -19,7 +19,7 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
schema: { schema: {
description: "Login with Azure Auth", description: "Login with Azure Auth",
body: z.object({ body: z.object({
identityId: z.string(), identityId: z.string().describe(AZURE_AUTH.LOGIN.identityId),
jwt: z.string() jwt: z.string()
}), }),
response: { response: {
@@ -72,19 +72,20 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(AZURE_AUTH.LOGIN.identityId)
}), }),
body: z.object({ body: z.object({
tenantId: z.string().trim(), tenantId: z.string().trim().describe(AZURE_AUTH.ATTACH.tenantId),
resource: z.string().trim(), resource: z.string().trim().describe(AZURE_AUTH.ATTACH.resource),
allowedServicePrincipalIds: validateAzureAuthField, allowedServicePrincipalIds: validateAzureAuthField.describe(AZURE_AUTH.ATTACH.allowedServicePrincipalIds),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(AZURE_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -92,15 +93,17 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(AZURE_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0) .describe(AZURE_AUTH.ATTACH.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(AZURE_AUTH.ATTACH.accessTokenNumUsesLimit)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -154,21 +157,24 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(AZURE_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z.object({
tenantId: z.string().trim().optional(), tenantId: z.string().trim().optional().describe(AZURE_AUTH.UPDATE.tenantId),
resource: z.string().trim().optional(), resource: z.string().trim().optional().describe(AZURE_AUTH.UPDATE.resource),
allowedServicePrincipalIds: validateAzureAuthField.optional(), allowedServicePrincipalIds: validateAzureAuthField
.optional()
.describe(AZURE_AUTH.UPDATE.allowedServicePrincipalIds),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.optional(), .optional()
accessTokenTTL: z.number().int().min(0).optional(), .describe(AZURE_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional(), accessTokenTTL: z.number().int().min(0).optional().describe(AZURE_AUTH.UPDATE.accessTokenTTL),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(AZURE_AUTH.UPDATE.accessTokenNumUsesLimit),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
@@ -176,6 +182,7 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.optional() .optional()
.describe(AZURE_AUTH.UPDATE.accessTokenMaxTTL)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -229,7 +236,7 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(AZURE_AUTH.RETRIEVE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -19,7 +19,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
schema: { schema: {
description: "Login with GCP Auth", description: "Login with GCP Auth",
body: z.object({ body: z.object({
identityId: z.string(), identityId: z.string().describe(GCP_AUTH.LOGIN.identityId),
jwt: z.string() jwt: z.string()
}), }),
response: { response: {
@@ -72,20 +72,21 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(GCP_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z.object({
type: z.enum(["iam", "gce"]), type: z.enum(["iam", "gce"]),
allowedServiceAccounts: validateGcpAuthField, allowedServiceAccounts: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedServiceAccounts),
allowedProjects: validateGcpAuthField, allowedProjects: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedProjects),
allowedZones: validateGcpAuthField, allowedZones: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedZones),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(GCP_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -93,15 +94,17 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(GCP_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0) .describe(GCP_AUTH.ATTACH.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(GCP_AUTH.ATTACH.accessTokenNumUsesLimit)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -157,22 +160,23 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(GCP_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z.object({
type: z.enum(["iam", "gce"]).optional(), type: z.enum(["iam", "gce"]).optional(),
allowedServiceAccounts: validateGcpAuthField.optional(), allowedServiceAccounts: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedServiceAccounts),
allowedProjects: validateGcpAuthField.optional(), allowedProjects: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedProjects),
allowedZones: validateGcpAuthField.optional(), allowedZones: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedZones),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.optional(), .optional()
accessTokenTTL: z.number().int().min(0).optional(), .describe(GCP_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional(), accessTokenTTL: z.number().int().min(0).optional().describe(GCP_AUTH.UPDATE.accessTokenTTL),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(GCP_AUTH.UPDATE.accessTokenNumUsesLimit),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
@@ -180,6 +184,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.optional() .optional()
.describe(GCP_AUTH.UPDATE.accessTokenMaxTTL)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -235,7 +240,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(GCP_AUTH.RETRIEVE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -30,7 +30,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
schema: { schema: {
description: "Login with Kubernetes Auth", description: "Login with Kubernetes Auth",
body: z.object({ body: z.object({
identityId: z.string().trim(), identityId: z.string().trim().describe(KUBERNETES_AUTH.LOGIN.identityId),
jwt: z.string().trim() jwt: z.string().trim()
}), }),
response: { response: {
@@ -85,22 +85,23 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(KUBERNETES_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z.object({
kubernetesHost: z.string().trim().min(1), kubernetesHost: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.kubernetesHost),
caCert: z.string().trim().default(""), caCert: z.string().trim().default("").describe(KUBERNETES_AUTH.ATTACH.caCert),
tokenReviewerJwt: z.string().trim().min(1), tokenReviewerJwt: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.tokenReviewerJwt),
allowedNamespaces: z.string(), // TODO: validation allowedNamespaces: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNamespaces), // TODO: validation
allowedNames: z.string(), allowedNames: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNames),
allowedAudience: z.string(), allowedAudience: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedAudience),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(KUBERNETES_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -108,15 +109,22 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(KUBERNETES_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0) .describe(KUBERNETES_AUTH.ATTACH.accessTokenMaxTTL),
accessTokenNumUsesLimit: z
.number()
.int()
.min(0)
.default(0)
.describe(KUBERNETES_AUTH.ATTACH.accessTokenNumUsesLimit)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -171,24 +179,30 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(KUBERNETES_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z.object({
kubernetesHost: z.string().trim().min(1).optional(), kubernetesHost: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.kubernetesHost),
caCert: z.string().trim().optional(), caCert: z.string().trim().optional().describe(KUBERNETES_AUTH.UPDATE.caCert),
tokenReviewerJwt: z.string().trim().min(1).optional(), tokenReviewerJwt: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.tokenReviewerJwt),
allowedNamespaces: z.string().optional(), // TODO: validation allowedNamespaces: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNamespaces), // TODO: validation
allowedNames: z.string().optional(), allowedNames: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNames),
allowedAudience: z.string().optional(), allowedAudience: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedAudience),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.optional(), .optional()
accessTokenTTL: z.number().int().min(0).optional(), .describe(KUBERNETES_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional(), accessTokenTTL: z.number().int().min(0).optional().describe(KUBERNETES_AUTH.UPDATE.accessTokenTTL),
accessTokenNumUsesLimit: z
.number()
.int()
.min(0)
.optional()
.describe(KUBERNETES_AUTH.UPDATE.accessTokenNumUsesLimit),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
@@ -196,6 +210,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.optional() .optional()
.describe(KUBERNETES_AUTH.UPDATE.accessTokenMaxTTL)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -250,7 +265,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(KUBERNETES_AUTH.RETRIEVE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -30,7 +30,7 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
schema: { schema: {
description: "Login with OIDC Auth", description: "Login with OIDC Auth",
body: z.object({ body: z.object({
identityId: z.string().trim(), identityId: z.string().trim().describe(OIDC_AUTH.LOGIN.identityId),
jwt: z.string().trim() jwt: z.string().trim()
}), }),
response: { response: {
@@ -85,16 +85,23 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(OIDC_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z.object({
oidcDiscoveryUrl: z.string().url().min(1).describe(OIDC_AUTH.ATTACH.oidcDiscoveryUrl),
caCert: z.string().trim().default("").describe(OIDC_AUTH.ATTACH.caCert),
boundIssuer: z.string().min(1).describe(OIDC_AUTH.ATTACH.boundIssuer),
boundAudiences: validateOidcAuthAudiencesField.describe(OIDC_AUTH.ATTACH.boundAudiences),
boundClaims: validateOidcBoundClaimsField.describe(OIDC_AUTH.ATTACH.boundClaims),
boundSubject: z.string().optional().default("").describe(OIDC_AUTH.ATTACH.boundSubject),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(OIDC_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -102,21 +109,17 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(OIDC_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0), .describe(OIDC_AUTH.ATTACH.accessTokenMaxTTL),
oidcDiscoveryUrl: z.string().url().min(1), accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(OIDC_AUTH.ATTACH.accessTokenNumUsesLimit)
caCert: z.string().trim().default(""),
boundIssuer: z.string().min(1),
boundAudiences: validateOidcAuthAudiencesField,
boundClaims: validateOidcBoundClaimsField,
boundSubject: z.string().optional().default("")
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -176,17 +179,24 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(OIDC_AUTH.UPDATE.identityId)
}), }),
body: z body: z
.object({ .object({
oidcDiscoveryUrl: z.string().url().min(1).describe(OIDC_AUTH.UPDATE.oidcDiscoveryUrl),
caCert: z.string().trim().default("").describe(OIDC_AUTH.UPDATE.caCert),
boundIssuer: z.string().min(1).describe(OIDC_AUTH.UPDATE.boundIssuer),
boundAudiences: validateOidcAuthAudiencesField.describe(OIDC_AUTH.UPDATE.boundAudiences),
boundClaims: validateOidcBoundClaimsField.describe(OIDC_AUTH.UPDATE.boundClaims),
boundSubject: z.string().optional().default("").describe(OIDC_AUTH.UPDATE.boundSubject),
accessTokenTrustedIps: z accessTokenTrustedIps: z
.object({ .object({
ipAddress: z.string().trim() ipAddress: z.string().trim()
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(OIDC_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -194,21 +204,18 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(OIDC_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0), .describe(OIDC_AUTH.UPDATE.accessTokenMaxTTL),
oidcDiscoveryUrl: z.string().url().min(1),
caCert: z.string().trim().default(""), accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(OIDC_AUTH.UPDATE.accessTokenNumUsesLimit)
boundIssuer: z.string().min(1),
boundAudiences: validateOidcAuthAudiencesField,
boundClaims: validateOidcBoundClaimsField,
boundSubject: z.string().optional().default("")
}) })
.partial(), .partial(),
response: { response: {
@@ -267,7 +274,7 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(OIDC_AUTH.RETRIEVE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -2,6 +2,7 @@ import { z } from "zod";
import { IdentityAccessTokensSchema, IdentityTokenAuthsSchema } from "@app/db/schemas"; import { IdentityAccessTokensSchema, IdentityTokenAuthsSchema } from "@app/db/schemas";
import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { EventType } from "@app/ee/services/audit-log/audit-log-types";
import { TOKEN_AUTH } from "@app/lib/api-docs";
import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
import { AuthMode } from "@app/services/auth/auth-type"; import { AuthMode } from "@app/services/auth/auth-type";
@@ -23,7 +24,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(TOKEN_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z.object({
accessTokenTrustedIps: z accessTokenTrustedIps: z
@@ -32,7 +33,8 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
}) })
.array() .array()
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(TOKEN_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
@@ -40,15 +42,17 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number" message: "accessTokenTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
.describe(TOKEN_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.refine((value) => value !== 0, { .refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.default(2592000), .default(2592000)
accessTokenNumUsesLimit: z.number().int().min(0).default(0) .describe(TOKEN_AUTH.ATTACH.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(TOKEN_AUTH.ATTACH.accessTokenNumUsesLimit)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -102,7 +106,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string().trim() identityId: z.string().trim().describe(TOKEN_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z.object({
accessTokenTrustedIps: z accessTokenTrustedIps: z
@@ -111,9 +115,10 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
}) })
.array() .array()
.min(1) .min(1)
.optional(), .optional()
accessTokenTTL: z.number().int().min(0).optional(), .describe(TOKEN_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional(), accessTokenTTL: z.number().int().min(0).optional().describe(TOKEN_AUTH.UPDATE.accessTokenTTL),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(TOKEN_AUTH.UPDATE.accessTokenNumUsesLimit),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
@@ -121,6 +126,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
message: "accessTokenMaxTTL must have a non zero number" message: "accessTokenMaxTTL must have a non zero number"
}) })
.optional() .optional()
.describe(TOKEN_AUTH.UPDATE.accessTokenMaxTTL)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -174,7 +180,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(TOKEN_AUTH.RETRIEVE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -221,7 +227,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(TOKEN_AUTH.REVOKE.identityId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -253,15 +259,6 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
} }
}); });
// proposed
// update token by id: PATCH /token-auth/tokens/:tokenId
// revoke token by id: POST /token-auth/tokens/:tokenId/revoke
// current
// revoke token by id: POST /token/revoke-by-id
// token-auth/identities/:identityId/tokens
server.route({ server.route({
method: "POST", method: "POST",
url: "/token-auth/identities/:identityId/tokens", url: "/token-auth/identities/:identityId/tokens",
@@ -270,17 +267,17 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
}, },
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
description: "Create token for identity with Token Auth configured", description: "Create token for identity with Token Auth",
security: [ security: [
{ {
bearerAuth: [] bearerAuth: []
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(TOKEN_AUTH.CREATE_TOKEN.identityId)
}), }),
body: z.object({ body: z.object({
name: z.string().optional() name: z.string().optional().describe(TOKEN_AUTH.CREATE_TOKEN.name)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -331,18 +328,18 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
}, },
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
description: "Get tokens for identity with Token Auth configured", description: "Get tokens for identity with Token Auth",
security: [ security: [
{ {
bearerAuth: [] bearerAuth: []
} }
], ],
params: z.object({ params: z.object({
identityId: z.string() identityId: z.string().describe(TOKEN_AUTH.GET_TOKENS.identityId)
}), }),
querystring: z.object({ querystring: z.object({
offset: z.coerce.number().min(0).max(100).default(0), offset: z.coerce.number().min(0).max(100).default(0).describe(TOKEN_AUTH.GET_TOKENS.offset),
limit: z.coerce.number().min(1).max(100).default(20) limit: z.coerce.number().min(1).max(100).default(20).describe(TOKEN_AUTH.GET_TOKENS.limit)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -383,17 +380,17 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
}, },
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
description: "Update token for identity with Token Auth configured", description: "Update token for identity with Token Auth",
security: [ security: [
{ {
bearerAuth: [] bearerAuth: []
} }
], ],
params: z.object({ params: z.object({
tokenId: z.string() tokenId: z.string().describe(TOKEN_AUTH.UPDATE_TOKEN.tokenId)
}), }),
body: z.object({ body: z.object({
name: z.string().optional() name: z.string().optional().describe(TOKEN_AUTH.UPDATE_TOKEN.name)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -436,14 +433,14 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
}, },
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
description: "Revoke token for identity with Token Auth configured", description: "Revoke token for identity with Token Auth",
security: [ security: [
{ {
bearerAuth: [] bearerAuth: []
} }
], ],
params: z.object({ params: z.object({
tokenId: z.string() tokenId: z.string().describe(TOKEN_AUTH.REVOKE_TOKEN.tokenId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -0,0 +1,4 @@
---
title: "Attach"
openapi: "POST /api/v1/auth/aws-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Login"
openapi: "POST /api/v1/auth/aws-auth/login"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/auth/aws-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "DELETE /api/v1/auth/aws-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/auth/aws-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Attach"
openapi: "POST /api/v1/auth/azure-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Login"
openapi: "POST /api/v1/auth/azure-auth/login"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/auth/azure-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "DELETE /api/v1/auth/azure-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/auth/azure-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Attach"
openapi: "POST /api/v1/auth/gcp-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Login"
openapi: "POST /api/v1/auth/gcp-auth/login"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/auth/gcp-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "DELETE /api/v1/auth/gcp-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/auth/gcp-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Attach"
openapi: "POST /api/v1/auth/kubernetes-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Login"
openapi: "POST /api/v1/auth/kubernetes-auth/login"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/auth/kubernetes-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "DELETE /api/v1/auth/kubernetes-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/auth/kubernetes-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Attach"
openapi: "POST /api/v1/auth/oidc-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Login"
openapi: "POST /api/v1/auth/oidc-auth/login"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/auth/oidc-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "DELETE /api/v1/auth/oidc-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/auth/oidc-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Attach"
openapi: "POST /api/v1/auth/token-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Create Token"
openapi: "POST /api/v1/auth/token-auth/identities/{identityId}/tokens"
---
@@ -0,0 +1,4 @@
---
title: "Get Tokens"
openapi: "GET /api/v1/auth/token-auth/identities/{identityId}/tokens"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/auth/token-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke Token"
openapi: "POST /api/v1/auth/token-auth/tokens/{tokenId}/revoke"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "DELETE /api/v1/auth/token-auth/identities/{identityId}"
---
@@ -0,0 +1,4 @@
---
title: "Update Token"
openapi: "PATCH /api/v1/auth/token-auth/tokens/{tokenId}"
---
@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/auth/token-auth/identities/{identityId}"
---
+63
View File
@@ -428,6 +428,19 @@
"api-reference/endpoints/identities/list" "api-reference/endpoints/identities/list"
] ]
}, },
{
"group": "Token Auth",
"pages": [
"api-reference/endpoints/token-auth/attach",
"api-reference/endpoints/token-auth/retrieve",
"api-reference/endpoints/token-auth/update",
"api-reference/endpoints/token-auth/revoke",
"api-reference/endpoints/token-auth/get-tokens",
"api-reference/endpoints/token-auth/create-token",
"api-reference/endpoints/token-auth/update-token",
"api-reference/endpoints/token-auth/revoke-token"
]
},
{ {
"group": "Universal Auth", "group": "Universal Auth",
"pages": [ "pages": [
@@ -444,6 +457,56 @@
"api-reference/endpoints/universal-auth/revoke-access-token" "api-reference/endpoints/universal-auth/revoke-access-token"
] ]
}, },
{
"group": "GCP Auth",
"pages": [
"api-reference/endpoints/gcp-auth/login",
"api-reference/endpoints/gcp-auth/attach",
"api-reference/endpoints/gcp-auth/retrieve",
"api-reference/endpoints/gcp-auth/update",
"api-reference/endpoints/gcp-auth/revoke"
]
},
{
"group": "AWS Auth",
"pages": [
"api-reference/endpoints/aws-auth/login",
"api-reference/endpoints/aws-auth/attach",
"api-reference/endpoints/aws-auth/retrieve",
"api-reference/endpoints/aws-auth/update",
"api-reference/endpoints/aws-auth/revoke"
]
},
{
"group": "Azure Auth",
"pages": [
"api-reference/endpoints/azure-auth/login",
"api-reference/endpoints/azure-auth/attach",
"api-reference/endpoints/azure-auth/retrieve",
"api-reference/endpoints/azure-auth/update",
"api-reference/endpoints/azure-auth/revoke"
]
},
{
"group": "Kubernetes Auth",
"pages": [
"api-reference/endpoints/kubernetes-auth/login",
"api-reference/endpoints/kubernetes-auth/attach",
"api-reference/endpoints/kubernetes-auth/retrieve",
"api-reference/endpoints/kubernetes-auth/update",
"api-reference/endpoints/kubernetes-auth/revoke"
]
},
{
"group": "OIDC Auth",
"pages": [
"api-reference/endpoints/oidc-auth/login",
"api-reference/endpoints/oidc-auth/attach",
"api-reference/endpoints/oidc-auth/retrieve",
"api-reference/endpoints/oidc-auth/update",
"api-reference/endpoints/oidc-auth/revoke"
]
},
{ {
"group": "Organizations", "group": "Organizations",
"pages": [ "pages": [