mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 09:28:28 +00:00
resolved error handling issue with requireAuth middleware
This commit is contained in:
@@ -166,7 +166,6 @@ const main = async () => {
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
// await createTestUserForDevelopment();
|
|
||||||
setUpHealthEndpoint(server);
|
setUpHealthEndpoint(server);
|
||||||
|
|
||||||
server.on("close", async () => {
|
server.on("close", async () => {
|
||||||
|
|||||||
@@ -42,58 +42,61 @@ const requireAuth = ({
|
|||||||
acceptedAuthModes: string[];
|
acceptedAuthModes: string[];
|
||||||
}) => {
|
}) => {
|
||||||
return async (req: Request, res: Response, next: NextFunction) => {
|
return async (req: Request, res: Response, next: NextFunction) => {
|
||||||
|
|
||||||
// validate auth token against accepted auth modes [acceptedAuthModes]
|
// validate auth token against accepted auth modes [acceptedAuthModes]
|
||||||
// and return token type [authTokenType] and value [authTokenValue]
|
// and return token type [authTokenType] and value [authTokenValue]
|
||||||
|
try {
|
||||||
const { authMode, authTokenValue } = validateAuthMode({
|
const { authMode, authTokenValue } = validateAuthMode({
|
||||||
headers: req.headers,
|
headers: req.headers,
|
||||||
acceptedAuthModes
|
acceptedAuthModes
|
||||||
});
|
});
|
||||||
|
|
||||||
let authPayload: IUser | IServiceAccount | IServiceTokenData;
|
let authPayload: IUser | IServiceAccount | IServiceTokenData;
|
||||||
switch (authMode) {
|
switch (authMode) {
|
||||||
case AUTH_MODE_SERVICE_ACCOUNT:
|
case AUTH_MODE_SERVICE_ACCOUNT:
|
||||||
authPayload = await getAuthSAAKPayload({
|
authPayload = await getAuthSAAKPayload({
|
||||||
authTokenValue
|
authTokenValue
|
||||||
});
|
});
|
||||||
req.serviceAccount = authPayload;
|
req.serviceAccount = authPayload;
|
||||||
break;
|
break;
|
||||||
case AUTH_MODE_SERVICE_TOKEN:
|
case AUTH_MODE_SERVICE_TOKEN:
|
||||||
authPayload = await getAuthSTDPayload({
|
authPayload = await getAuthSTDPayload({
|
||||||
authTokenValue
|
authTokenValue
|
||||||
});
|
});
|
||||||
req.serviceTokenData = authPayload;
|
req.serviceTokenData = authPayload;
|
||||||
break;
|
break;
|
||||||
case AUTH_MODE_API_KEY:
|
case AUTH_MODE_API_KEY:
|
||||||
authPayload = await getAuthAPIKeyPayload({
|
authPayload = await getAuthAPIKeyPayload({
|
||||||
authTokenValue
|
authTokenValue
|
||||||
});
|
});
|
||||||
req.user = authPayload;
|
req.user = authPayload;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
authPayload = await getAuthUserPayload({
|
authPayload = await getAuthUserPayload({
|
||||||
authTokenValue
|
authTokenValue
|
||||||
});
|
});
|
||||||
req.user = authPayload;
|
req.user = authPayload;
|
||||||
break;
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
req.requestData = {
|
||||||
|
...req.params,
|
||||||
|
...req.query,
|
||||||
|
...req.body,
|
||||||
|
}
|
||||||
|
|
||||||
|
req.authData = {
|
||||||
|
authMode,
|
||||||
|
authPayload, // User, ServiceAccount, ServiceTokenData
|
||||||
|
authChannel: getChannelFromUserAgent(req.headers['user-agent']),
|
||||||
|
authIP: req.ip,
|
||||||
|
authUserAgent: req.headers['user-agent'] ?? 'other'
|
||||||
|
}
|
||||||
|
|
||||||
|
return next();
|
||||||
|
} catch (err) {
|
||||||
|
return next(err);
|
||||||
}
|
}
|
||||||
|
|
||||||
req.requestData = {
|
|
||||||
...req.params,
|
|
||||||
...req.query,
|
|
||||||
...req.body,
|
|
||||||
}
|
|
||||||
|
|
||||||
req.authData = {
|
|
||||||
authMode,
|
|
||||||
authPayload, // User, ServiceAccount, ServiceTokenData
|
|
||||||
authChannel: getChannelFromUserAgent(req.headers['user-agent']),
|
|
||||||
authIP: req.ip,
|
|
||||||
authUserAgent: req.headers['user-agent'] ?? 'other'
|
|
||||||
}
|
|
||||||
|
|
||||||
return next();
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -9,21 +9,22 @@ const { patchRouterParam } = require('../patchAsyncRoutes');
|
|||||||
import {
|
import {
|
||||||
validateEncryptionKeysConfig
|
validateEncryptionKeysConfig
|
||||||
} from './validateConfig';
|
} from './validateConfig';
|
||||||
import {
|
import {
|
||||||
backfillSecretVersions,
|
backfillSecretVersions,
|
||||||
backfillBots,
|
backfillBots,
|
||||||
backfillSecretBlindIndexData,
|
backfillSecretBlindIndexData,
|
||||||
backfillEncryptionMetadata
|
backfillEncryptionMetadata
|
||||||
} from './backfillData';
|
} from './backfillData';
|
||||||
import {
|
import {
|
||||||
reencryptBotPrivateKeys,
|
reencryptBotPrivateKeys,
|
||||||
reencryptSecretBlindIndexDataSalts
|
reencryptSecretBlindIndexDataSalts
|
||||||
} from './reencryptData';
|
} from './reencryptData';
|
||||||
import {
|
import {
|
||||||
getNodeEnv,
|
getNodeEnv,
|
||||||
getMongoURL,
|
getMongoURL,
|
||||||
getSentryDSN
|
getSentryDSN
|
||||||
} from '../../config';
|
} from '../../config';
|
||||||
|
import { initializePassport } from '../auth';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Prepare Infisical upon startup. This includes tasks like:
|
* Prepare Infisical upon startup. This includes tasks like:
|
||||||
@@ -42,13 +43,14 @@ export const setup = async () => {
|
|||||||
|
|
||||||
// initializing SMTP configuration
|
// initializing SMTP configuration
|
||||||
setTransporter(await initSmtp());
|
setTransporter(await initSmtp());
|
||||||
|
|
||||||
// initializing global feature set
|
// initializing global feature set
|
||||||
await EELicenseService.initGlobalFeatureSet();
|
await EELicenseService.initGlobalFeatureSet();
|
||||||
|
|
||||||
// initializing the database connection
|
// initializing the database connection
|
||||||
await DatabaseService.initDatabase(await getMongoURL());
|
await DatabaseService.initDatabase(await getMongoURL());
|
||||||
|
await initializePassport();
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* NOTE: the order in this setup function is critical.
|
* NOTE: the order in this setup function is critical.
|
||||||
* It is important to backfill data before performing any re-encryption functionality.
|
* It is important to backfill data before performing any re-encryption functionality.
|
||||||
@@ -59,7 +61,7 @@ export const setup = async () => {
|
|||||||
await backfillBots();
|
await backfillBots();
|
||||||
await backfillSecretBlindIndexData();
|
await backfillSecretBlindIndexData();
|
||||||
await backfillEncryptionMetadata();
|
await backfillEncryptionMetadata();
|
||||||
|
|
||||||
// re-encrypt any data previously encrypted under server hex 128-bit ENCRYPTION_KEY
|
// re-encrypt any data previously encrypted under server hex 128-bit ENCRYPTION_KEY
|
||||||
// to base64 256-bit ROOT_ENCRYPTION_KEY
|
// to base64 256-bit ROOT_ENCRYPTION_KEY
|
||||||
await reencryptBotPrivateKeys();
|
await reencryptBotPrivateKeys();
|
||||||
|
|||||||
Reference in New Issue
Block a user