mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 22:27:48 +00:00
Refactor
This commit is contained in:
@@ -319,13 +319,19 @@ export const AcmeCertificateAuthorityFns = ({
|
|||||||
|
|
||||||
const orderCertificate = async ({
|
const orderCertificate = async ({
|
||||||
caId,
|
caId,
|
||||||
|
subscriberId,
|
||||||
commonName,
|
commonName,
|
||||||
altNames
|
altNames,
|
||||||
|
keyUsages,
|
||||||
|
extendedKeyUsages
|
||||||
}: {
|
}: {
|
||||||
caId: string;
|
caId: string;
|
||||||
|
subscriberId?: string;
|
||||||
commonName: string;
|
commonName: string;
|
||||||
altNames?: string[];
|
altNames?: string[];
|
||||||
}): Promise<string> => {
|
keyUsages?: CertKeyUsage[];
|
||||||
|
extendedKeyUsages?: CertExtendedKeyUsage[];
|
||||||
|
}) => {
|
||||||
const ca = await certificateAuthorityDAL.findByIdWithAssociatedCa(caId);
|
const ca = await certificateAuthorityDAL.findByIdWithAssociatedCa(caId);
|
||||||
if (!ca.externalCa || ca.externalCa.type !== CaType.ACME) {
|
if (!ca.externalCa || ca.externalCa.type !== CaType.ACME) {
|
||||||
throw new BadRequestError({ message: "CA is not an ACME CA" });
|
throw new BadRequestError({ message: "CA is not an ACME CA" });
|
||||||
@@ -498,20 +504,20 @@ export const AcmeCertificateAuthorityFns = ({
|
|||||||
plainText: Buffer.from(skLeaf)
|
plainText: Buffer.from(skLeaf)
|
||||||
});
|
});
|
||||||
|
|
||||||
await certificateDAL.transaction(async (tx) => {
|
return certificateDAL.transaction(async (tx) => {
|
||||||
const cert = await certificateDAL.create(
|
const cert = await certificateDAL.create(
|
||||||
{
|
{
|
||||||
caId: ca.id,
|
caId: ca.id,
|
||||||
pkiSubscriberId: subscriber.id,
|
pkiSubscriberId: subscriberId,
|
||||||
status: CertStatus.ACTIVE,
|
status: CertStatus.ACTIVE,
|
||||||
friendlyName: subscriber.commonName,
|
friendlyName: commonName,
|
||||||
commonName: subscriber.commonName,
|
commonName,
|
||||||
altNames: subscriber.subjectAlternativeNames.join(","),
|
altNames: altNames?.join(","),
|
||||||
serialNumber: certObj.serialNumber,
|
serialNumber: certObj.serialNumber,
|
||||||
notBefore: certObj.notBefore,
|
notBefore: certObj.notBefore,
|
||||||
notAfter: certObj.notAfter,
|
notAfter: certObj.notAfter,
|
||||||
keyUsages: subscriber.keyUsages as CertKeyUsage[],
|
keyUsages: keyUsages,
|
||||||
extendedKeyUsages: subscriber.extendedKeyUsages as CertExtendedKeyUsage[],
|
extendedKeyUsages: extendedKeyUsages,
|
||||||
projectId: ca.projectId
|
projectId: ca.projectId
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
@@ -533,26 +539,32 @@ export const AcmeCertificateAuthorityFns = ({
|
|||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
});
|
|
||||||
|
|
||||||
await triggerAutoSyncForSubscriber(subscriber.id, { pkiSyncDAL, pkiSyncQueue });
|
return cert;
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
const orderCertificateForAcmeProfile = async (profileId: string, commonName: string): Promise<string> => {
|
const orderSubscriberCertificate = async (subscriberId: string) => {
|
||||||
const profile = await certificateProfileDAL.findByIdWithConfigs(profileId);
|
const subscriber = await pkiSubscriberDAL.findById(subscriberId);
|
||||||
if (!profile) {
|
if (!subscriber.caId) {
|
||||||
throw new NotFoundError({ message: "Certificate profile not found" });
|
throw new BadRequestError({ message: "Subscriber does not have a CA" });
|
||||||
}
|
|
||||||
if (profile.enrollmentType !== EnrollmentType.ACME) {
|
|
||||||
throw new NotFoundError({ message: "Certificate profile is not configured for ACME enrollment" });
|
|
||||||
}
|
}
|
||||||
|
await orderCertificate({
|
||||||
|
caId: subscriber.caId,
|
||||||
|
subscriberId: subscriber.id,
|
||||||
|
commonName: subscriber.commonName,
|
||||||
|
altNames: subscriber.subjectAlternativeNames,
|
||||||
|
keyUsages: subscriber.keyUsages as CertKeyUsage[],
|
||||||
|
extendedKeyUsages: subscriber.extendedKeyUsages as CertExtendedKeyUsage[]
|
||||||
|
});
|
||||||
|
await triggerAutoSyncForSubscriber(subscriber.id, { pkiSyncDAL, pkiSyncQueue });
|
||||||
};
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
createCertificateAuthority,
|
createCertificateAuthority,
|
||||||
updateCertificateAuthority,
|
updateCertificateAuthority,
|
||||||
listCertificateAuthorities,
|
listCertificateAuthorities,
|
||||||
orderSubscriberCertificate,
|
orderCertificate,
|
||||||
orderCertificateForAcmeProfile
|
orderSubscriberCertificate
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user