diff --git a/backend/package-lock.json b/backend/package-lock.json index f22fd0b7b..c6ac0b147 100644 --- a/backend/package-lock.json +++ b/backend/package-lock.json @@ -25,6 +25,7 @@ "@fastify/multipart": "8.3.1", "@fastify/passport": "^2.4.0", "@fastify/rate-limit": "^9.0.0", + "@fastify/reply-from": "^9.8.0", "@fastify/request-context": "^5.1.0", "@fastify/session": "^10.7.0", "@fastify/static": "^7.0.4", @@ -8044,6 +8045,42 @@ "toad-cache": "^3.3.0" } }, + "node_modules/@fastify/reply-from": { + "version": "9.8.0", + "resolved": "https://registry.npmjs.org/@fastify/reply-from/-/reply-from-9.8.0.tgz", + "integrity": "sha512-bPNVaFhEeNI0Lyl6404YZaPFokudCplidE3QoOcr78yOy6H9sYw97p5KPYvY/NJNUHfFtvxOaSAHnK+YSiv/Mg==", + "license": "MIT", + "dependencies": { + "@fastify/error": "^3.0.0", + "end-of-stream": "^1.4.4", + "fast-content-type-parse": "^1.1.0", + "fast-querystring": "^1.0.0", + "fastify-plugin": "^4.0.0", + "toad-cache": "^3.7.0", + "undici": "^5.19.1" + } + }, + "node_modules/@fastify/reply-from/node_modules/@fastify/busboy": { + "version": "2.1.1", + "resolved": "https://registry.npmjs.org/@fastify/busboy/-/busboy-2.1.1.tgz", + "integrity": "sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA==", + "license": "MIT", + "engines": { + "node": ">=14" + } + }, + "node_modules/@fastify/reply-from/node_modules/undici": { + "version": "5.29.0", + "resolved": "https://registry.npmjs.org/undici/-/undici-5.29.0.tgz", + "integrity": "sha512-raqeBD6NQK4SkWhQzeYKd1KmIG6dllBOTt55Rmkt4HtI9mwdWtJljnrXjAFUBLTSN67HWrOIZ3EPF4kjUw80Bg==", + "license": "MIT", + "dependencies": { + "@fastify/busboy": "^2.0.0" + }, + "engines": { + "node": ">=14.0" + } + }, "node_modules/@fastify/request-context": { "version": "5.1.0", "resolved": "https://registry.npmjs.org/@fastify/request-context/-/request-context-5.1.0.tgz", @@ -29330,9 +29367,10 @@ } }, "node_modules/toad-cache": { - "version": "3.3.0", - "resolved": "https://registry.npmjs.org/toad-cache/-/toad-cache-3.3.0.tgz", - "integrity": "sha512-3oDzcogWGHZdkwrHyvJVpPjA7oNzY6ENOV3PsWJY9XYPZ6INo94Yd47s5may1U+nleBPwDhrRiTPMIvKaa3MQg==", + "version": "3.7.0", + "resolved": "https://registry.npmjs.org/toad-cache/-/toad-cache-3.7.0.tgz", + "integrity": "sha512-/m8M+2BJUpoJdgAHoG+baCwBT+tf2VraSfkBgl0Y00qIWt41DJ8R5B8nsEw0I58YwF5IZH6z24/2TobDKnqSWw==", + "license": "MIT", "engines": { "node": ">=12" } diff --git a/backend/package.json b/backend/package.json index aaef9f567..0c8464eaf 100644 --- a/backend/package.json +++ b/backend/package.json @@ -145,6 +145,7 @@ "@fastify/multipart": "8.3.1", "@fastify/passport": "^2.4.0", "@fastify/rate-limit": "^9.0.0", + "@fastify/reply-from": "^9.8.0", "@fastify/request-context": "^5.1.0", "@fastify/session": "^10.7.0", "@fastify/static": "^7.0.4", diff --git a/backend/src/@types/fastify.d.ts b/backend/src/@types/fastify.d.ts index 47973cc09..60bcf7348 100644 --- a/backend/src/@types/fastify.d.ts +++ b/backend/src/@types/fastify.d.ts @@ -162,6 +162,7 @@ declare module "fastify" { }; // identity injection. depending on which kinda of token the information is filled in auth auth: TAuthMode; + shouldForwardWritesToPrimaryInstance: boolean; permission: { authMethod: ActorAuthMethod; type: ActorType; diff --git a/backend/src/lib/config/env.ts b/backend/src/lib/config/env.ts index 586a69655..7416baa59 100644 --- a/backend/src/lib/config/env.ts +++ b/backend/src/lib/config/env.ts @@ -218,6 +218,8 @@ const envSchema = z ), PARAMS_FOLDER_SECRET_DETECTION_ENTROPY: z.coerce.number().optional().default(3.7), + INFISICAL_PRIMARY_INSTANCE_URL: zpStr(z.string().optional()), + // HSM HSM_LIB_PATH: zpStr(z.string().optional()), HSM_PIN: zpStr(z.string().optional()), diff --git a/backend/src/server/plugins/auth/inject-identity.ts b/backend/src/server/plugins/auth/inject-identity.ts index 97c62b545..2f128dda1 100644 --- a/backend/src/server/plugins/auth/inject-identity.ts +++ b/backend/src/server/plugins/auth/inject-identity.ts @@ -107,110 +107,117 @@ export const extractAuth = async (req: FastifyRequest, jwtSecret: string) => { }; // ! Important: You can only 100% count on the `req.permission.orgId` field being present when the auth method is Identity Access Token (Machine Identity). -export const injectIdentity = fp(async (server: FastifyZodProvider) => { - server.decorateRequest("auth", null); - server.addHook("onRequest", async (req) => { - const appCfg = getConfig(); +export const injectIdentity = fp( + async (server: FastifyZodProvider, opt: { shouldForwardWritesToPrimaryInstance?: boolean }) => { + server.decorateRequest("auth", null); + server.decorateRequest("shouldForwardWritesToPrimaryInstance", Boolean(opt.shouldForwardWritesToPrimaryInstance)); + server.addHook("onRequest", async (req) => { + const appCfg = getConfig(); - if (req.url.includes(".well-known/est") || req.url.includes("/api/v3/auth/")) { - return; - } - - // Authentication is handled on a route-level here. - if (req.url.includes("/api/v1/workflow-integrations/microsoft-teams/message-endpoint")) { - return; - } - - const { authMode, token, actor } = await extractAuth(req, appCfg.AUTH_SECRET); - - if (!authMode) return; - - switch (authMode) { - case AuthMode.JWT: { - const { user, tokenVersionId, orgId } = await server.services.authToken.fnValidateJwtIdentity(token); - requestContext.set("orgId", orgId); - req.auth = { - authMode: AuthMode.JWT, - user, - userId: user.id, - tokenVersionId, - actor, - orgId: orgId as string, - authMethod: token.authMethod, - isMfaVerified: token.isMfaVerified, - token - }; - break; + if (opt.shouldForwardWritesToPrimaryInstance && req.method !== "GET") { + return; } - case AuthMode.IDENTITY_ACCESS_TOKEN: { - const identity = await server.services.identityAccessToken.fnValidateIdentityAccessToken(token, req.realIp); - const serverCfg = await getServerCfg(); - requestContext.set("orgId", identity.orgId); - req.auth = { - authMode: AuthMode.IDENTITY_ACCESS_TOKEN, - actor, - orgId: identity.orgId, - identityId: identity.identityId, - identityName: identity.name, - authMethod: null, - isInstanceAdmin: serverCfg?.adminIdentityIds?.includes(identity.identityId), - token - }; - if (token?.identityAuth?.oidc) { - requestContext.set("identityAuthInfo", { - identityId: identity.identityId, - oidc: token?.identityAuth?.oidc - }); + + if (req.url.includes(".well-known/est") || req.url.includes("/api/v3/auth/")) { + return; + } + + // Authentication is handled on a route-level here. + if (req.url.includes("/api/v1/workflow-integrations/microsoft-teams/message-endpoint")) { + return; + } + + const { authMode, token, actor } = await extractAuth(req, appCfg.AUTH_SECRET); + + if (!authMode) return; + + switch (authMode) { + case AuthMode.JWT: { + const { user, tokenVersionId, orgId } = await server.services.authToken.fnValidateJwtIdentity(token); + requestContext.set("orgId", orgId); + req.auth = { + authMode: AuthMode.JWT, + user, + userId: user.id, + tokenVersionId, + actor, + orgId: orgId as string, + authMethod: token.authMethod, + isMfaVerified: token.isMfaVerified, + token + }; + break; } - if (token?.identityAuth?.kubernetes) { - requestContext.set("identityAuthInfo", { + case AuthMode.IDENTITY_ACCESS_TOKEN: { + const identity = await server.services.identityAccessToken.fnValidateIdentityAccessToken(token, req.realIp); + const serverCfg = await getServerCfg(); + requestContext.set("orgId", identity.orgId); + req.auth = { + authMode: AuthMode.IDENTITY_ACCESS_TOKEN, + actor, + orgId: identity.orgId, identityId: identity.identityId, - kubernetes: token?.identityAuth?.kubernetes - }); + identityName: identity.name, + authMethod: null, + isInstanceAdmin: serverCfg?.adminIdentityIds?.includes(identity.identityId), + token + }; + if (token?.identityAuth?.oidc) { + requestContext.set("identityAuthInfo", { + identityId: identity.identityId, + oidc: token?.identityAuth?.oidc + }); + } + if (token?.identityAuth?.kubernetes) { + requestContext.set("identityAuthInfo", { + identityId: identity.identityId, + kubernetes: token?.identityAuth?.kubernetes + }); + } + if (token?.identityAuth?.aws) { + requestContext.set("identityAuthInfo", { + identityId: identity.identityId, + aws: token?.identityAuth?.aws + }); + } + break; } - if (token?.identityAuth?.aws) { - requestContext.set("identityAuthInfo", { - identityId: identity.identityId, - aws: token?.identityAuth?.aws - }); + case AuthMode.SERVICE_TOKEN: { + const serviceToken = await server.services.serviceToken.fnValidateServiceToken(token); + requestContext.set("orgId", serviceToken.orgId); + req.auth = { + orgId: serviceToken.orgId, + authMode: AuthMode.SERVICE_TOKEN as const, + serviceToken, + serviceTokenId: serviceToken.id, + actor, + authMethod: null, + token + }; + break; } - break; + case AuthMode.API_KEY: { + const user = await server.services.apiKey.fnValidateApiKey(token as string); + req.auth = { + authMode: AuthMode.API_KEY as const, + userId: user.id, + actor, + user, + orgId: "API_KEY", // We set the orgId to an arbitrary value, since we can't link an API key to a specific org. We have to deprecate API keys soon! + authMethod: null, + token: token as string + }; + break; + } + case AuthMode.SCIM_TOKEN: { + const { orgId, scimTokenId } = await server.services.scim.fnValidateScimToken(token); + requestContext.set("orgId", orgId); + req.auth = { authMode: AuthMode.SCIM_TOKEN, actor, scimTokenId, orgId, authMethod: null }; + break; + } + default: + throw new BadRequestError({ message: "Invalid token strategy provided" }); } - case AuthMode.SERVICE_TOKEN: { - const serviceToken = await server.services.serviceToken.fnValidateServiceToken(token); - requestContext.set("orgId", serviceToken.orgId); - req.auth = { - orgId: serviceToken.orgId, - authMode: AuthMode.SERVICE_TOKEN as const, - serviceToken, - serviceTokenId: serviceToken.id, - actor, - authMethod: null, - token - }; - break; - } - case AuthMode.API_KEY: { - const user = await server.services.apiKey.fnValidateApiKey(token as string); - req.auth = { - authMode: AuthMode.API_KEY as const, - userId: user.id, - actor, - user, - orgId: "API_KEY", // We set the orgId to an arbitrary value, since we can't link an API key to a specific org. We have to deprecate API keys soon! - authMethod: null, - token: token as string - }; - break; - } - case AuthMode.SCIM_TOKEN: { - const { orgId, scimTokenId } = await server.services.scim.fnValidateScimToken(token); - requestContext.set("orgId", orgId); - req.auth = { authMode: AuthMode.SCIM_TOKEN, actor, scimTokenId, orgId, authMethod: null }; - break; - } - default: - throw new BadRequestError({ message: "Invalid token strategy provided" }); - } - }); -}); + }); + } +); diff --git a/backend/src/server/plugins/auth/verify-auth.ts b/backend/src/server/plugins/auth/verify-auth.ts index 44ea069dc..c63199769 100644 --- a/backend/src/server/plugins/auth/verify-auth.ts +++ b/backend/src/server/plugins/auth/verify-auth.ts @@ -10,6 +10,10 @@ interface TAuthOptions { export const verifyAuth = (authStrategies: AuthMode[], options: TAuthOptions = { requireOrg: true }) => (req: T, _res: FastifyReply, done: HookHandlerDoneFunction) => { + if (req.shouldForwardWritesToPrimaryInstance && req.method !== "GET") { + return done(); + } + if (!Array.isArray(authStrategies)) throw new Error("Auth strategy must be array"); if (!req.auth) throw new UnauthorizedError({ message: "Token missing" }); diff --git a/backend/src/server/plugins/primary-forwarding-mode.ts b/backend/src/server/plugins/primary-forwarding-mode.ts new file mode 100644 index 000000000..611806a6b --- /dev/null +++ b/backend/src/server/plugins/primary-forwarding-mode.ts @@ -0,0 +1,14 @@ +import replyFrom from "@fastify/reply-from"; +import fp from "fastify-plugin"; + +export const forwardWritesToPrimary = fp(async (server, opt: { primaryUrl: string }) => { + await server.register(replyFrom, { + base: opt.primaryUrl + }); + + server.addHook("preValidation", async (request, reply) => { + if (request.url.startsWith("/api") && ["POST", "PUT", "DELETE", "PATCH"].includes(request.method)) { + return reply.from(request.url); + } + }); +}); diff --git a/backend/src/server/routes/index.ts b/backend/src/server/routes/index.ts index 9af4f6ade..24294b46a 100644 --- a/backend/src/server/routes/index.ts +++ b/backend/src/server/routes/index.ts @@ -312,6 +312,7 @@ import { injectAssumePrivilege } from "../plugins/auth/inject-assume-privilege"; import { injectIdentity } from "../plugins/auth/inject-identity"; import { injectPermission } from "../plugins/auth/inject-permission"; import { injectRateLimits } from "../plugins/inject-rate-limits"; +import { forwardWritesToPrimary } from "../plugins/primary-forwarding-mode"; import { registerV1Routes } from "./v1"; import { initializeOauthConfigSync } from "./v1/sso-router"; import { registerV2Routes } from "./v2"; @@ -2146,8 +2147,14 @@ export const registerRoutes = async ( user: userDAL, kmipClient: kmipClientDAL }); + const shouldForwardWritesToPrimaryInstance = Boolean(envConfig.INFISICAL_PRIMARY_INSTANCE_URL); + if (shouldForwardWritesToPrimaryInstance) { + logger.info(`Infisical primary instance is configured: ${envConfig.INFISICAL_PRIMARY_INSTANCE_URL}`); - await server.register(injectIdentity, { userDAL, serviceTokenDAL }); + await server.register(forwardWritesToPrimary, { primaryUrl: envConfig.INFISICAL_PRIMARY_INSTANCE_URL as string }); + } + + await server.register(injectIdentity, { shouldForwardWritesToPrimaryInstance }); await server.register(injectAssumePrivilege); await server.register(injectPermission); await server.register(injectRateLimits);