mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 11:27:32 +00:00
misc: removed mfa from existing login
This commit is contained in:
@@ -280,10 +280,6 @@ export const registerSsoRouter = async (server: FastifyZodProvider) => {
|
|||||||
providerAuthToken: req.body.providerAuthToken
|
providerAuthToken: req.body.providerAuthToken
|
||||||
});
|
});
|
||||||
|
|
||||||
if (data.isMfaEnabled) {
|
|
||||||
return { mfaEnabled: true, token: data.token } as const; // for discriminated union
|
|
||||||
}
|
|
||||||
|
|
||||||
void res.setCookie("jid", data.token.refresh, {
|
void res.setCookie("jid", data.token.refresh, {
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
path: "/",
|
path: "/",
|
||||||
|
|||||||
@@ -47,7 +47,8 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
token: z.string()
|
token: z.string(),
|
||||||
|
isMfaEnabled: z.boolean()
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -60,6 +61,13 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
ipAddress: req.realIp
|
ipAddress: req.realIp
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (tokens.isMfaEnabled) {
|
||||||
|
return {
|
||||||
|
token: tokens.mfa as string,
|
||||||
|
isMfaEnabled: true
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
void res.setCookie("jid", tokens.refresh, {
|
void res.setCookie("jid", tokens.refresh, {
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
path: "/",
|
path: "/",
|
||||||
@@ -67,7 +75,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
secure: cfg.HTTPS_ENABLED
|
secure: cfg.HTTPS_ENABLED
|
||||||
});
|
});
|
||||||
|
|
||||||
return { token: tokens.access };
|
return { token: tokens.access, isMfaEnabled: false };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -86,21 +94,18 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
password: z.string().optional()
|
password: z.string().optional()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.discriminatedUnion("mfaEnabled", [
|
200: z.object({
|
||||||
z.object({ mfaEnabled: z.literal(true), token: z.string() }),
|
mfaEnabled: z.literal(false),
|
||||||
z.object({
|
encryptionVersion: z.number().default(1).nullable().optional(),
|
||||||
mfaEnabled: z.literal(false),
|
protectedKey: z.string().nullable(),
|
||||||
encryptionVersion: z.number().default(1).nullable().optional(),
|
protectedKeyIV: z.string().nullable(),
|
||||||
protectedKey: z.string().nullable(),
|
protectedKeyTag: z.string().nullable(),
|
||||||
protectedKeyIV: z.string().nullable(),
|
publicKey: z.string(),
|
||||||
protectedKeyTag: z.string().nullable(),
|
encryptedPrivateKey: z.string(),
|
||||||
publicKey: z.string(),
|
iv: z.string(),
|
||||||
encryptedPrivateKey: z.string(),
|
tag: z.string(),
|
||||||
iv: z.string(),
|
token: z.string()
|
||||||
tag: z.string(),
|
})
|
||||||
token: z.string()
|
|
||||||
})
|
|
||||||
])
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
handler: async (req, res) => {
|
handler: async (req, res) => {
|
||||||
@@ -118,10 +123,6 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
password: req.body.password
|
password: req.body.password
|
||||||
});
|
});
|
||||||
|
|
||||||
if (data.isMfaEnabled) {
|
|
||||||
return { mfaEnabled: true, token: data.token } as const; // for discriminated union
|
|
||||||
}
|
|
||||||
|
|
||||||
void res.setCookie("jid", data.token.refresh, {
|
void res.setCookie("jid", data.token.refresh, {
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
path: "/",
|
path: "/",
|
||||||
|
|||||||
@@ -298,30 +298,6 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// send multi factor auth token if they it enabled
|
|
||||||
if (userEnc.isMfaEnabled && userEnc.email) {
|
|
||||||
enforceUserLockStatus(Boolean(user.isLocked), user.temporaryLockDateEnd);
|
|
||||||
|
|
||||||
const mfaToken = jwt.sign(
|
|
||||||
{
|
|
||||||
authMethod,
|
|
||||||
authTokenType: AuthTokenType.MFA_TOKEN,
|
|
||||||
userId: userEnc.userId
|
|
||||||
},
|
|
||||||
cfg.AUTH_SECRET,
|
|
||||||
{
|
|
||||||
expiresIn: cfg.JWT_MFA_LIFETIME
|
|
||||||
}
|
|
||||||
);
|
|
||||||
|
|
||||||
await sendUserMfaCode({
|
|
||||||
userId: userEnc.userId,
|
|
||||||
email: userEnc.email
|
|
||||||
});
|
|
||||||
|
|
||||||
return { isMfaEnabled: true, token: mfaToken } as const;
|
|
||||||
}
|
|
||||||
|
|
||||||
const token = await generateUserTokens({
|
const token = await generateUserTokens({
|
||||||
user: {
|
user: {
|
||||||
...userEnc,
|
...userEnc,
|
||||||
@@ -333,7 +309,7 @@ export const authLoginServiceFactory = ({
|
|||||||
organizationId
|
organizationId
|
||||||
});
|
});
|
||||||
|
|
||||||
return { token, isMfaEnabled: false, user: userEnc } as const;
|
return { token, user: userEnc } as const;
|
||||||
};
|
};
|
||||||
|
|
||||||
const selectOrganization = async ({
|
const selectOrganization = async ({
|
||||||
@@ -373,6 +349,30 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// send multi factor auth token if they it enabled
|
||||||
|
if (user.isMfaEnabled && user.email) {
|
||||||
|
enforceUserLockStatus(Boolean(user.isLocked), user.temporaryLockDateEnd);
|
||||||
|
|
||||||
|
const mfaToken = jwt.sign(
|
||||||
|
{
|
||||||
|
authMethod: decodedToken.authMethod,
|
||||||
|
authTokenType: AuthTokenType.MFA_TOKEN,
|
||||||
|
userId: user.id
|
||||||
|
},
|
||||||
|
cfg.AUTH_SECRET,
|
||||||
|
{
|
||||||
|
expiresIn: cfg.JWT_MFA_LIFETIME
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
await sendUserMfaCode({
|
||||||
|
userId: user.id,
|
||||||
|
email: user.email
|
||||||
|
});
|
||||||
|
|
||||||
|
return { isMfaEnabled: true, mfa: mfaToken } as const;
|
||||||
|
}
|
||||||
|
|
||||||
const tokens = await generateUserTokens({
|
const tokens = await generateUserTokens({
|
||||||
authMethod: decodedToken.authMethod,
|
authMethod: decodedToken.authMethod,
|
||||||
user,
|
user,
|
||||||
@@ -381,7 +381,10 @@ export const authLoginServiceFactory = ({
|
|||||||
organizationId
|
organizationId
|
||||||
});
|
});
|
||||||
|
|
||||||
return tokens;
|
return {
|
||||||
|
...tokens,
|
||||||
|
isMfaEnabled: false
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -629,7 +632,6 @@ export const authLoginServiceFactory = ({
|
|||||||
const oauth2TokenExchange = async ({ userAgent, ip, providerAuthToken, email }: TOauthTokenExchangeDTO) => {
|
const oauth2TokenExchange = async ({ userAgent, ip, providerAuthToken, email }: TOauthTokenExchangeDTO) => {
|
||||||
const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email);
|
const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email);
|
||||||
|
|
||||||
const appCfg = getConfig();
|
|
||||||
const { authMethod, userName } = decodedProviderToken;
|
const { authMethod, userName } = decodedProviderToken;
|
||||||
if (!userName) throw new BadRequestError({ message: "Missing user name" });
|
if (!userName) throw new BadRequestError({ message: "Missing user name" });
|
||||||
const organizationId =
|
const organizationId =
|
||||||
@@ -644,29 +646,6 @@ export const authLoginServiceFactory = ({
|
|||||||
if (!userEnc) throw new BadRequestError({ message: "Invalid token" });
|
if (!userEnc) throw new BadRequestError({ message: "Invalid token" });
|
||||||
if (!userEnc.serverEncryptedPrivateKey)
|
if (!userEnc.serverEncryptedPrivateKey)
|
||||||
throw new BadRequestError({ message: "Key handoff incomplete. Please try logging in again." });
|
throw new BadRequestError({ message: "Key handoff incomplete. Please try logging in again." });
|
||||||
// send multi factor auth token if they it enabled
|
|
||||||
if (userEnc.isMfaEnabled && userEnc.email) {
|
|
||||||
enforceUserLockStatus(Boolean(userEnc.isLocked), userEnc.temporaryLockDateEnd);
|
|
||||||
|
|
||||||
const mfaToken = jwt.sign(
|
|
||||||
{
|
|
||||||
authMethod,
|
|
||||||
authTokenType: AuthTokenType.MFA_TOKEN,
|
|
||||||
userId: userEnc.userId
|
|
||||||
},
|
|
||||||
appCfg.AUTH_SECRET,
|
|
||||||
{
|
|
||||||
expiresIn: appCfg.JWT_MFA_LIFETIME
|
|
||||||
}
|
|
||||||
);
|
|
||||||
|
|
||||||
await sendUserMfaCode({
|
|
||||||
userId: userEnc.userId,
|
|
||||||
email: userEnc.email
|
|
||||||
});
|
|
||||||
|
|
||||||
return { isMfaEnabled: true, token: mfaToken } as const;
|
|
||||||
}
|
|
||||||
|
|
||||||
const token = await generateUserTokens({
|
const token = await generateUserTokens({
|
||||||
user: { ...userEnc, id: userEnc.userId },
|
user: { ...userEnc, id: userEnc.userId },
|
||||||
|
|||||||
@@ -65,7 +65,7 @@ export const selectOrganization = async (data: {
|
|||||||
organizationId: string;
|
organizationId: string;
|
||||||
userAgent?: UserAgentType;
|
userAgent?: UserAgentType;
|
||||||
}) => {
|
}) => {
|
||||||
const { data: res } = await apiRequest.post<{ token: string }>(
|
const { data: res } = await apiRequest.post<{ token: string; isMfaEnabled: boolean }>(
|
||||||
"/api/v3/auth/select-organization",
|
"/api/v3/auth/select-organization",
|
||||||
data
|
data
|
||||||
);
|
);
|
||||||
|
|||||||
Reference in New Issue
Block a user