mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 06:26:27 +00:00
Merge pull request #4479 from Infisical/feat/validate-dns
feat: removed internal ip transformation
This commit is contained in:
@@ -30,7 +30,7 @@ const generateUsername = (usernameTemplate?: string | null, identity?: { name: s
|
|||||||
export const CassandraProvider = (): TDynamicProviderFns => {
|
export const CassandraProvider = (): TDynamicProviderFns => {
|
||||||
const validateProviderInputs = async (inputs: unknown) => {
|
const validateProviderInputs = async (inputs: unknown) => {
|
||||||
const providerInputs = await DynamicSecretCassandraSchema.parseAsync(inputs);
|
const providerInputs = await DynamicSecretCassandraSchema.parseAsync(inputs);
|
||||||
const hostIps = await Promise.all(
|
await Promise.all(
|
||||||
providerInputs.host
|
providerInputs.host
|
||||||
.split(",")
|
.split(",")
|
||||||
.filter(Boolean)
|
.filter(Boolean)
|
||||||
@@ -48,10 +48,10 @@ export const CassandraProvider = (): TDynamicProviderFns => {
|
|||||||
allowedExpressions: (val) => ["username"].includes(val)
|
allowedExpressions: (val) => ["username"].includes(val)
|
||||||
});
|
});
|
||||||
|
|
||||||
return { ...providerInputs, hostIps };
|
return { ...providerInputs };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretCassandraSchema> & { hostIps: string[] }) => {
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretCassandraSchema>) => {
|
||||||
const sslOptions = providerInputs.ca ? { rejectUnauthorized: false, ca: providerInputs.ca } : undefined;
|
const sslOptions = providerInputs.ca ? { rejectUnauthorized: false, ca: providerInputs.ca } : undefined;
|
||||||
const client = new cassandra.Client({
|
const client = new cassandra.Client({
|
||||||
sslOptions,
|
sslOptions,
|
||||||
@@ -64,7 +64,7 @@ export const CassandraProvider = (): TDynamicProviderFns => {
|
|||||||
},
|
},
|
||||||
keyspace: providerInputs.keyspace,
|
keyspace: providerInputs.keyspace,
|
||||||
localDataCenter: providerInputs?.localDataCenter,
|
localDataCenter: providerInputs?.localDataCenter,
|
||||||
contactPoints: providerInputs.hostIps
|
contactPoints: providerInputs.host.split(",")
|
||||||
});
|
});
|
||||||
return client;
|
return client;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -28,14 +28,14 @@ const generateUsername = (usernameTemplate?: string | null, identity?: { name: s
|
|||||||
export const ElasticSearchProvider = (): TDynamicProviderFns => {
|
export const ElasticSearchProvider = (): TDynamicProviderFns => {
|
||||||
const validateProviderInputs = async (inputs: unknown) => {
|
const validateProviderInputs = async (inputs: unknown) => {
|
||||||
const providerInputs = await DynamicSecretElasticSearchSchema.parseAsync(inputs);
|
const providerInputs = await DynamicSecretElasticSearchSchema.parseAsync(inputs);
|
||||||
const [hostIp] = await verifyHostInputValidity(providerInputs.host);
|
await verifyHostInputValidity(providerInputs.host);
|
||||||
return { ...providerInputs, hostIp };
|
return { ...providerInputs };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretElasticSearchSchema> & { hostIp: string }) => {
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretElasticSearchSchema>) => {
|
||||||
const connection = new ElasticSearchClient({
|
const connection = new ElasticSearchClient({
|
||||||
node: {
|
node: {
|
||||||
url: new URL(`${providerInputs.hostIp}:${providerInputs.port}`),
|
url: new URL(`${providerInputs.host}:${providerInputs.port}`),
|
||||||
...(providerInputs.ca && {
|
...(providerInputs.ca && {
|
||||||
ssl: {
|
ssl: {
|
||||||
rejectUnauthorized: false,
|
rejectUnauthorized: false,
|
||||||
|
|||||||
@@ -28,15 +28,15 @@ const generateUsername = (usernameTemplate?: string | null, identity?: { name: s
|
|||||||
export const MongoDBProvider = (): TDynamicProviderFns => {
|
export const MongoDBProvider = (): TDynamicProviderFns => {
|
||||||
const validateProviderInputs = async (inputs: unknown) => {
|
const validateProviderInputs = async (inputs: unknown) => {
|
||||||
const providerInputs = await DynamicSecretMongoDBSchema.parseAsync(inputs);
|
const providerInputs = await DynamicSecretMongoDBSchema.parseAsync(inputs);
|
||||||
const [hostIp] = await verifyHostInputValidity(providerInputs.host);
|
await verifyHostInputValidity(providerInputs.host);
|
||||||
return { ...providerInputs, hostIp };
|
return { ...providerInputs };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretMongoDBSchema> & { hostIp: string }) => {
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretMongoDBSchema>) => {
|
||||||
const isSrv = !providerInputs.port;
|
const isSrv = !providerInputs.port;
|
||||||
const uri = isSrv
|
const uri = isSrv
|
||||||
? `mongodb+srv://${providerInputs.hostIp}`
|
? `mongodb+srv://${providerInputs.host}`
|
||||||
: `mongodb://${providerInputs.hostIp}:${providerInputs.port}`;
|
: `mongodb://${providerInputs.host}:${providerInputs.port}`;
|
||||||
|
|
||||||
const client = new MongoClient(uri, {
|
const client = new MongoClient(uri, {
|
||||||
auth: {
|
auth: {
|
||||||
|
|||||||
@@ -87,13 +87,13 @@ async function deleteRabbitMqUser({ axiosInstance, usernameToDelete }: TDeleteRa
|
|||||||
export const RabbitMqProvider = (): TDynamicProviderFns => {
|
export const RabbitMqProvider = (): TDynamicProviderFns => {
|
||||||
const validateProviderInputs = async (inputs: unknown) => {
|
const validateProviderInputs = async (inputs: unknown) => {
|
||||||
const providerInputs = await DynamicSecretRabbitMqSchema.parseAsync(inputs);
|
const providerInputs = await DynamicSecretRabbitMqSchema.parseAsync(inputs);
|
||||||
const [hostIp] = await verifyHostInputValidity(providerInputs.host);
|
await verifyHostInputValidity(providerInputs.host);
|
||||||
return { ...providerInputs, hostIp };
|
return { ...providerInputs };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretRabbitMqSchema> & { hostIp: string }) => {
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretRabbitMqSchema>) => {
|
||||||
const axiosInstance = axios.create({
|
const axiosInstance = axios.create({
|
||||||
baseURL: `${providerInputs.hostIp}:${providerInputs.port}/api`,
|
baseURL: `${providerInputs.host}:${providerInputs.port}/api`,
|
||||||
auth: {
|
auth: {
|
||||||
username: providerInputs.username,
|
username: providerInputs.username,
|
||||||
password: providerInputs.password
|
password: providerInputs.password
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ export const SapAseProvider = (): TDynamicProviderFns => {
|
|||||||
const validateProviderInputs = async (inputs: unknown) => {
|
const validateProviderInputs = async (inputs: unknown) => {
|
||||||
const providerInputs = await DynamicSecretSapAseSchema.parseAsync(inputs);
|
const providerInputs = await DynamicSecretSapAseSchema.parseAsync(inputs);
|
||||||
|
|
||||||
const [hostIp] = await verifyHostInputValidity(providerInputs.host);
|
await verifyHostInputValidity(providerInputs.host);
|
||||||
validateHandlebarTemplate("SAP ASE creation", providerInputs.creationStatement, {
|
validateHandlebarTemplate("SAP ASE creation", providerInputs.creationStatement, {
|
||||||
allowedExpressions: (val) => ["username", "password"].includes(val)
|
allowedExpressions: (val) => ["username", "password"].includes(val)
|
||||||
});
|
});
|
||||||
@@ -45,16 +45,13 @@ export const SapAseProvider = (): TDynamicProviderFns => {
|
|||||||
allowedExpressions: (val) => ["username"].includes(val)
|
allowedExpressions: (val) => ["username"].includes(val)
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
return { ...providerInputs, hostIp };
|
return { ...providerInputs };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretSapAseSchema>, useMaster?: boolean) => {
|
||||||
providerInputs: z.infer<typeof DynamicSecretSapAseSchema> & { hostIp: string },
|
|
||||||
useMaster?: boolean
|
|
||||||
) => {
|
|
||||||
const connectionString =
|
const connectionString =
|
||||||
`DRIVER={FreeTDS};` +
|
`DRIVER={FreeTDS};` +
|
||||||
`SERVER=${providerInputs.hostIp};` +
|
`SERVER=${providerInputs.host};` +
|
||||||
`PORT=${providerInputs.port};` +
|
`PORT=${providerInputs.port};` +
|
||||||
`DATABASE=${useMaster ? "master" : providerInputs.database};` +
|
`DATABASE=${useMaster ? "master" : providerInputs.database};` +
|
||||||
`UID=${providerInputs.username};` +
|
`UID=${providerInputs.username};` +
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ export const SapHanaProvider = (): TDynamicProviderFns => {
|
|||||||
const validateProviderInputs = async (inputs: unknown) => {
|
const validateProviderInputs = async (inputs: unknown) => {
|
||||||
const providerInputs = await DynamicSecretSapHanaSchema.parseAsync(inputs);
|
const providerInputs = await DynamicSecretSapHanaSchema.parseAsync(inputs);
|
||||||
|
|
||||||
const [hostIp] = await verifyHostInputValidity(providerInputs.host);
|
await verifyHostInputValidity(providerInputs.host);
|
||||||
validateHandlebarTemplate("SAP Hana creation", providerInputs.creationStatement, {
|
validateHandlebarTemplate("SAP Hana creation", providerInputs.creationStatement, {
|
||||||
allowedExpressions: (val) => ["username", "password", "expiration"].includes(val)
|
allowedExpressions: (val) => ["username", "password", "expiration"].includes(val)
|
||||||
});
|
});
|
||||||
@@ -49,12 +49,12 @@ export const SapHanaProvider = (): TDynamicProviderFns => {
|
|||||||
validateHandlebarTemplate("SAP Hana revoke", providerInputs.revocationStatement, {
|
validateHandlebarTemplate("SAP Hana revoke", providerInputs.revocationStatement, {
|
||||||
allowedExpressions: (val) => ["username"].includes(val)
|
allowedExpressions: (val) => ["username"].includes(val)
|
||||||
});
|
});
|
||||||
return { ...providerInputs, hostIp };
|
return { ...providerInputs };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretSapHanaSchema> & { hostIp: string }) => {
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretSapHanaSchema>) => {
|
||||||
const client = hdb.createClient({
|
const client = hdb.createClient({
|
||||||
host: providerInputs.hostIp,
|
host: providerInputs.host,
|
||||||
port: providerInputs.port,
|
port: providerInputs.port,
|
||||||
user: providerInputs.username,
|
user: providerInputs.username,
|
||||||
password: providerInputs.password,
|
password: providerInputs.password,
|
||||||
|
|||||||
@@ -150,8 +150,10 @@ export const SqlDatabaseProvider = ({ gatewayService }: TSqlDatabaseProviderDTO)
|
|||||||
return { ...providerInputs, hostIp };
|
return { ...providerInputs, hostIp };
|
||||||
};
|
};
|
||||||
|
|
||||||
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretSqlDBSchema>) => {
|
const $getClient = async (providerInputs: z.infer<typeof DynamicSecretSqlDBSchema> & { hostIp: string }) => {
|
||||||
const ssl = providerInputs.ca ? { rejectUnauthorized: false, ca: providerInputs.ca } : undefined;
|
const ssl = providerInputs.ca
|
||||||
|
? { rejectUnauthorized: false, ca: providerInputs.ca, servername: providerInputs.host }
|
||||||
|
: undefined;
|
||||||
const isMsSQLClient = providerInputs.client === SqlProviders.MsSQL;
|
const isMsSQLClient = providerInputs.client === SqlProviders.MsSQL;
|
||||||
|
|
||||||
const db = knex({
|
const db = knex({
|
||||||
@@ -159,7 +161,7 @@ export const SqlDatabaseProvider = ({ gatewayService }: TSqlDatabaseProviderDTO)
|
|||||||
connection: {
|
connection: {
|
||||||
database: providerInputs.database,
|
database: providerInputs.database,
|
||||||
port: providerInputs.port,
|
port: providerInputs.port,
|
||||||
host: providerInputs.host,
|
host: providerInputs.client === SqlProviders.Postgres ? providerInputs.hostIp : providerInputs.host,
|
||||||
user: providerInputs.username,
|
user: providerInputs.username,
|
||||||
password: providerInputs.password,
|
password: providerInputs.password,
|
||||||
ssl,
|
ssl,
|
||||||
@@ -209,8 +211,8 @@ export const SqlDatabaseProvider = ({ gatewayService }: TSqlDatabaseProviderDTO)
|
|||||||
const validateConnection = async (inputs: unknown) => {
|
const validateConnection = async (inputs: unknown) => {
|
||||||
const providerInputs = await validateProviderInputs(inputs);
|
const providerInputs = await validateProviderInputs(inputs);
|
||||||
let isConnected = false;
|
let isConnected = false;
|
||||||
const gatewayCallback = async (host = providerInputs.hostIp, port = providerInputs.port) => {
|
const gatewayCallback = async (host = providerInputs.host, port = providerInputs.port) => {
|
||||||
const db = await $getClient({ ...providerInputs, port, host });
|
const db = await $getClient({ ...providerInputs, port, host, hostIp: providerInputs.hostIp });
|
||||||
// oracle needs from keyword
|
// oracle needs from keyword
|
||||||
const testStatement = providerInputs.client === SqlProviders.Oracle ? "SELECT 1 FROM DUAL" : "SELECT 1";
|
const testStatement = providerInputs.client === SqlProviders.Oracle ? "SELECT 1 FROM DUAL" : "SELECT 1";
|
||||||
|
|
||||||
|
|||||||
@@ -56,7 +56,7 @@ const getConnectionConfig = ({
|
|||||||
? {
|
? {
|
||||||
rejectUnauthorized: sslRejectUnauthorized,
|
rejectUnauthorized: sslRejectUnauthorized,
|
||||||
ca: sslCertificate,
|
ca: sslCertificate,
|
||||||
servername: host
|
serverName: host
|
||||||
}
|
}
|
||||||
: false
|
: false
|
||||||
};
|
};
|
||||||
@@ -90,7 +90,7 @@ export const getSqlConnectionClient = async (appConnection: Pick<TSqlConnection,
|
|||||||
connection: {
|
connection: {
|
||||||
database,
|
database,
|
||||||
port,
|
port,
|
||||||
host,
|
host: app === AppConnection.Postgres ? host : baseHost,
|
||||||
user: username,
|
user: username,
|
||||||
password,
|
password,
|
||||||
connectionTimeoutMillis: EXTERNAL_REQUEST_TIMEOUT,
|
connectionTimeoutMillis: EXTERNAL_REQUEST_TIMEOUT,
|
||||||
@@ -135,7 +135,7 @@ export const executeWithPotentialGateway = async <T>(
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
protocol: GatewayProxyProtocol.Tcp,
|
protocol: GatewayProxyProtocol.Tcp,
|
||||||
targetHost,
|
targetHost: app === AppConnection.Postgres ? targetHost : credentials.host,
|
||||||
targetPort: credentials.port,
|
targetPort: credentials.port,
|
||||||
relayHost,
|
relayHost,
|
||||||
relayPort: Number(relayPort),
|
relayPort: Number(relayPort),
|
||||||
|
|||||||
Reference in New Issue
Block a user