Merge pull request #3029 from akhilmhdh/feat/min-ttl

Resolved ttl and max ttl to be zero
This commit is contained in:
Akhil Mohan
2025-01-28 12:00:28 +05:30
committed by GitHub
24 changed files with 541 additions and 527 deletions
@@ -79,44 +79,44 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
params: z.object({ params: z.object({
identityId: z.string().trim().describe(AWS_AUTH.ATTACH.identityId) identityId: z.string().trim().describe(AWS_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z
stsEndpoint: z .object({
.string() stsEndpoint: z
.trim() .string()
.min(1) .trim()
.default("https://sts.amazonaws.com/") .min(1)
.describe(AWS_AUTH.ATTACH.stsEndpoint), .default("https://sts.amazonaws.com/")
allowedPrincipalArns: validatePrincipalArns.describe(AWS_AUTH.ATTACH.allowedPrincipalArns), .describe(AWS_AUTH.ATTACH.stsEndpoint),
allowedAccountIds: validateAccountIds.describe(AWS_AUTH.ATTACH.allowedAccountIds), allowedPrincipalArns: validatePrincipalArns.describe(AWS_AUTH.ATTACH.allowedPrincipalArns),
accessTokenTrustedIps: z allowedAccountIds: validateAccountIds.describe(AWS_AUTH.ATTACH.allowedAccountIds),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(AWS_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(AWS_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(AWS_AUTH.ATTACH.accessTokenTTL),
.default(2592000) accessTokenMaxTTL: z
.describe(AWS_AUTH.ATTACH.accessTokenTTL), .number()
accessTokenMaxTTL: z .int()
.number() .min(1)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(AWS_AUTH.ATTACH.accessTokenMaxTTL),
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(AWS_AUTH.ATTACH.accessTokenNumUsesLimit)
}) })
.default(2592000) .refine(
.describe(AWS_AUTH.ATTACH.accessTokenMaxTTL), (val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(AWS_AUTH.ATTACH.accessTokenNumUsesLimit) "Access Token TTL cannot be greater than Access Token Max TTL."
}), ),
response: { response: {
200: z.object({ 200: z.object({
identityAwsAuth: IdentityAwsAuthsSchema identityAwsAuth: IdentityAwsAuthsSchema
@@ -172,30 +172,33 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
params: z.object({ params: z.object({
identityId: z.string().describe(AWS_AUTH.UPDATE.identityId) identityId: z.string().describe(AWS_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z
stsEndpoint: z.string().trim().min(1).optional().describe(AWS_AUTH.UPDATE.stsEndpoint), .object({
allowedPrincipalArns: validatePrincipalArns.describe(AWS_AUTH.UPDATE.allowedPrincipalArns), stsEndpoint: z.string().trim().min(1).optional().describe(AWS_AUTH.UPDATE.stsEndpoint),
allowedAccountIds: validateAccountIds.describe(AWS_AUTH.UPDATE.allowedAccountIds), allowedPrincipalArns: validatePrincipalArns.describe(AWS_AUTH.UPDATE.allowedPrincipalArns),
accessTokenTrustedIps: z allowedAccountIds: validateAccountIds.describe(AWS_AUTH.UPDATE.allowedAccountIds),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(AWS_AUTH.UPDATE.accessTokenTrustedIps), .optional()
accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(AWS_AUTH.UPDATE.accessTokenTTL), .describe(AWS_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(AWS_AUTH.UPDATE.accessTokenNumUsesLimit), accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(AWS_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(AWS_AUTH.UPDATE.accessTokenNumUsesLimit),
.number() accessTokenMaxTTL: z
.int() .number()
.max(315360000) .int()
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenMaxTTL must have a non zero number" .min(0)
}) .optional()
.optional() .describe(AWS_AUTH.UPDATE.accessTokenMaxTTL)
.describe(AWS_AUTH.UPDATE.accessTokenMaxTTL) })
}), .refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityAwsAuth: IdentityAwsAuthsSchema identityAwsAuth: IdentityAwsAuthsSchema
@@ -76,39 +76,44 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
params: z.object({ params: z.object({
identityId: z.string().trim().describe(AZURE_AUTH.LOGIN.identityId) identityId: z.string().trim().describe(AZURE_AUTH.LOGIN.identityId)
}), }),
body: z.object({ body: z
tenantId: z.string().trim().describe(AZURE_AUTH.ATTACH.tenantId), .object({
resource: z.string().trim().describe(AZURE_AUTH.ATTACH.resource), tenantId: z.string().trim().describe(AZURE_AUTH.ATTACH.tenantId),
allowedServicePrincipalIds: validateAzureAuthField.describe(AZURE_AUTH.ATTACH.allowedServicePrincipalIds), resource: z.string().trim().describe(AZURE_AUTH.ATTACH.resource),
accessTokenTrustedIps: z allowedServicePrincipalIds: validateAzureAuthField.describe(AZURE_AUTH.ATTACH.allowedServicePrincipalIds),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(AZURE_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(AZURE_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(AZURE_AUTH.ATTACH.accessTokenTTL),
.default(2592000) accessTokenMaxTTL: z
.describe(AZURE_AUTH.ATTACH.accessTokenTTL), .number()
accessTokenMaxTTL: z .int()
.number() .min(0)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(AZURE_AUTH.ATTACH.accessTokenMaxTTL),
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z
}) .number()
.default(2592000) .int()
.describe(AZURE_AUTH.ATTACH.accessTokenMaxTTL), .min(0)
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(AZURE_AUTH.ATTACH.accessTokenNumUsesLimit) .default(0)
}), .describe(AZURE_AUTH.ATTACH.accessTokenNumUsesLimit)
})
.refine(
(val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityAzureAuth: IdentityAzureAuthsSchema identityAzureAuth: IdentityAzureAuthsSchema
@@ -163,32 +168,40 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
params: z.object({ params: z.object({
identityId: z.string().trim().describe(AZURE_AUTH.UPDATE.identityId) identityId: z.string().trim().describe(AZURE_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z
tenantId: z.string().trim().optional().describe(AZURE_AUTH.UPDATE.tenantId), .object({
resource: z.string().trim().optional().describe(AZURE_AUTH.UPDATE.resource), tenantId: z.string().trim().optional().describe(AZURE_AUTH.UPDATE.tenantId),
allowedServicePrincipalIds: validateAzureAuthField resource: z.string().trim().optional().describe(AZURE_AUTH.UPDATE.resource),
.optional() allowedServicePrincipalIds: validateAzureAuthField
.describe(AZURE_AUTH.UPDATE.allowedServicePrincipalIds), .optional()
accessTokenTrustedIps: z .describe(AZURE_AUTH.UPDATE.allowedServicePrincipalIds),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(AZURE_AUTH.UPDATE.accessTokenTrustedIps), .optional()
accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(AZURE_AUTH.UPDATE.accessTokenTTL), .describe(AZURE_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(AZURE_AUTH.UPDATE.accessTokenNumUsesLimit), accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(AZURE_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenNumUsesLimit: z
.number() .number()
.int() .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .optional()
message: "accessTokenMaxTTL must have a non zero number" .describe(AZURE_AUTH.UPDATE.accessTokenNumUsesLimit),
}) accessTokenMaxTTL: z
.optional() .number()
.describe(AZURE_AUTH.UPDATE.accessTokenMaxTTL) .int()
}), .max(315360000)
.min(0)
.optional()
.describe(AZURE_AUTH.UPDATE.accessTokenMaxTTL)
})
.refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityAzureAuth: IdentityAzureAuthsSchema identityAzureAuth: IdentityAzureAuthsSchema
@@ -74,40 +74,40 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
params: z.object({ params: z.object({
identityId: z.string().trim().describe(GCP_AUTH.ATTACH.identityId) identityId: z.string().trim().describe(GCP_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z
type: z.enum(["iam", "gce"]), .object({
allowedServiceAccounts: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedServiceAccounts), type: z.enum(["iam", "gce"]),
allowedProjects: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedProjects), allowedServiceAccounts: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedServiceAccounts),
allowedZones: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedZones), allowedProjects: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedProjects),
accessTokenTrustedIps: z allowedZones: validateGcpAuthField.describe(GCP_AUTH.ATTACH.allowedZones),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(GCP_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(GCP_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(GCP_AUTH.ATTACH.accessTokenTTL),
.default(2592000) accessTokenMaxTTL: z
.describe(GCP_AUTH.ATTACH.accessTokenTTL), .number()
accessTokenMaxTTL: z .int()
.number() .min(0)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(GCP_AUTH.ATTACH.accessTokenMaxTTL),
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(GCP_AUTH.ATTACH.accessTokenNumUsesLimit)
}) })
.default(2592000) .refine(
.describe(GCP_AUTH.ATTACH.accessTokenMaxTTL), (val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(GCP_AUTH.ATTACH.accessTokenNumUsesLimit) "Access Token TTL cannot be greater than Access Token Max TTL."
}), ),
response: { response: {
200: z.object({ 200: z.object({
identityGcpAuth: IdentityGcpAuthsSchema identityGcpAuth: IdentityGcpAuthsSchema
@@ -164,31 +164,34 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
params: z.object({ params: z.object({
identityId: z.string().trim().describe(GCP_AUTH.UPDATE.identityId) identityId: z.string().trim().describe(GCP_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z
type: z.enum(["iam", "gce"]).optional(), .object({
allowedServiceAccounts: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedServiceAccounts), type: z.enum(["iam", "gce"]).optional(),
allowedProjects: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedProjects), allowedServiceAccounts: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedServiceAccounts),
allowedZones: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedZones), allowedProjects: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedProjects),
accessTokenTrustedIps: z allowedZones: validateGcpAuthField.optional().describe(GCP_AUTH.UPDATE.allowedZones),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(GCP_AUTH.UPDATE.accessTokenTrustedIps), .optional()
accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(GCP_AUTH.UPDATE.accessTokenTTL), .describe(GCP_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(GCP_AUTH.UPDATE.accessTokenNumUsesLimit), accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(GCP_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(GCP_AUTH.UPDATE.accessTokenNumUsesLimit),
.number() accessTokenMaxTTL: z
.int() .number()
.max(315360000) .int()
.refine((value) => value !== 0, { .min(0)
message: "accessTokenMaxTTL must have a non zero number" .max(315360000)
}) .optional()
.optional() .describe(GCP_AUTH.UPDATE.accessTokenMaxTTL)
.describe(GCP_AUTH.UPDATE.accessTokenMaxTTL) })
}), .refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityGcpAuth: IdentityGcpAuthsSchema identityGcpAuth: IdentityGcpAuthsSchema
@@ -34,23 +34,12 @@ const CreateBaseSchema = z.object({
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(JWT_AUTH.ATTACH.accessTokenTrustedIps), .describe(JWT_AUTH.ATTACH.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z.number().int().min(0).max(315360000).default(2592000).describe(JWT_AUTH.ATTACH.accessTokenTTL),
.number()
.int()
.min(1)
.max(315360000)
.refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number"
})
.default(2592000)
.describe(JWT_AUTH.ATTACH.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.min(0)
.max(315360000) .max(315360000)
.refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number"
})
.default(2592000) .default(2592000)
.describe(JWT_AUTH.ATTACH.accessTokenMaxTTL), .describe(JWT_AUTH.ATTACH.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(JWT_AUTH.ATTACH.accessTokenNumUsesLimit) accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(JWT_AUTH.ATTACH.accessTokenNumUsesLimit)
@@ -70,23 +59,12 @@ const UpdateBaseSchema = z
.min(1) .min(1)
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
.describe(JWT_AUTH.UPDATE.accessTokenTrustedIps), .describe(JWT_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenTTL: z accessTokenTTL: z.number().int().min(0).max(315360000).default(2592000).describe(JWT_AUTH.UPDATE.accessTokenTTL),
.number()
.int()
.min(1)
.max(315360000)
.refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number"
})
.default(2592000)
.describe(JWT_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.min(0)
.max(315360000) .max(315360000)
.refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number"
})
.default(2592000) .default(2592000)
.describe(JWT_AUTH.UPDATE.accessTokenMaxTTL), .describe(JWT_AUTH.UPDATE.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(JWT_AUTH.UPDATE.accessTokenNumUsesLimit) accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(JWT_AUTH.UPDATE.accessTokenNumUsesLimit)
@@ -87,47 +87,47 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
params: z.object({ params: z.object({
identityId: z.string().trim().describe(KUBERNETES_AUTH.ATTACH.identityId) identityId: z.string().trim().describe(KUBERNETES_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z
kubernetesHost: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.kubernetesHost), .object({
caCert: z.string().trim().default("").describe(KUBERNETES_AUTH.ATTACH.caCert), kubernetesHost: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.kubernetesHost),
tokenReviewerJwt: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.tokenReviewerJwt), caCert: z.string().trim().default("").describe(KUBERNETES_AUTH.ATTACH.caCert),
allowedNamespaces: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNamespaces), // TODO: validation tokenReviewerJwt: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.tokenReviewerJwt),
allowedNames: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNames), allowedNamespaces: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNamespaces), // TODO: validation
allowedAudience: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedAudience), allowedNames: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNames),
accessTokenTrustedIps: z allowedAudience: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedAudience),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(KUBERNETES_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(KUBERNETES_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(KUBERNETES_AUTH.ATTACH.accessTokenTTL),
.default(2592000) accessTokenMaxTTL: z
.describe(KUBERNETES_AUTH.ATTACH.accessTokenTTL), .number()
accessTokenMaxTTL: z .int()
.number() .min(0)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(KUBERNETES_AUTH.ATTACH.accessTokenMaxTTL),
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z
}) .number()
.default(2592000) .int()
.describe(KUBERNETES_AUTH.ATTACH.accessTokenMaxTTL), .min(0)
accessTokenNumUsesLimit: z .default(0)
.number() .describe(KUBERNETES_AUTH.ATTACH.accessTokenNumUsesLimit)
.int() })
.min(0) .refine(
.default(0) (val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
.describe(KUBERNETES_AUTH.ATTACH.accessTokenNumUsesLimit) "Access Token TTL cannot be greater than Access Token Max TTL."
}), ),
response: { response: {
200: z.object({ 200: z.object({
identityKubernetesAuth: IdentityKubernetesAuthResponseSchema identityKubernetesAuth: IdentityKubernetesAuthResponseSchema
@@ -183,44 +183,47 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
params: z.object({ params: z.object({
identityId: z.string().describe(KUBERNETES_AUTH.UPDATE.identityId) identityId: z.string().describe(KUBERNETES_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z
kubernetesHost: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.kubernetesHost), .object({
caCert: z.string().trim().optional().describe(KUBERNETES_AUTH.UPDATE.caCert), kubernetesHost: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.kubernetesHost),
tokenReviewerJwt: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.tokenReviewerJwt), caCert: z.string().trim().optional().describe(KUBERNETES_AUTH.UPDATE.caCert),
allowedNamespaces: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNamespaces), // TODO: validation tokenReviewerJwt: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.tokenReviewerJwt),
allowedNames: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNames), allowedNamespaces: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNamespaces), // TODO: validation
allowedAudience: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedAudience), allowedNames: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNames),
accessTokenTrustedIps: z allowedAudience: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedAudience),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(KUBERNETES_AUTH.UPDATE.accessTokenTrustedIps), .optional()
accessTokenTTL: z .describe(KUBERNETES_AUTH.UPDATE.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(0) .int()
.max(315360000) .min(0)
.optional() .max(315360000)
.describe(KUBERNETES_AUTH.UPDATE.accessTokenTTL), .optional()
accessTokenNumUsesLimit: z .describe(KUBERNETES_AUTH.UPDATE.accessTokenTTL),
.number() accessTokenNumUsesLimit: z
.int() .number()
.min(0) .int()
.optional() .min(0)
.describe(KUBERNETES_AUTH.UPDATE.accessTokenNumUsesLimit), .optional()
accessTokenMaxTTL: z .describe(KUBERNETES_AUTH.UPDATE.accessTokenNumUsesLimit),
.number() accessTokenMaxTTL: z
.int() .number()
.max(315360000) .int()
.refine((value) => value !== 0, { .min(0)
message: "accessTokenMaxTTL must have a non zero number" .max(315360000)
}) .optional()
.optional() .describe(KUBERNETES_AUTH.UPDATE.accessTokenMaxTTL)
.describe(KUBERNETES_AUTH.UPDATE.accessTokenMaxTTL) })
}), .refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityKubernetesAuth: IdentityKubernetesAuthResponseSchema identityKubernetesAuth: IdentityKubernetesAuthResponseSchema
@@ -87,42 +87,42 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
params: z.object({ params: z.object({
identityId: z.string().trim().describe(OIDC_AUTH.ATTACH.identityId) identityId: z.string().trim().describe(OIDC_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z
oidcDiscoveryUrl: z.string().url().min(1).describe(OIDC_AUTH.ATTACH.oidcDiscoveryUrl), .object({
caCert: z.string().trim().default("").describe(OIDC_AUTH.ATTACH.caCert), oidcDiscoveryUrl: z.string().url().min(1).describe(OIDC_AUTH.ATTACH.oidcDiscoveryUrl),
boundIssuer: z.string().min(1).describe(OIDC_AUTH.ATTACH.boundIssuer), caCert: z.string().trim().default("").describe(OIDC_AUTH.ATTACH.caCert),
boundAudiences: validateOidcAuthAudiencesField.describe(OIDC_AUTH.ATTACH.boundAudiences), boundIssuer: z.string().min(1).describe(OIDC_AUTH.ATTACH.boundIssuer),
boundClaims: validateOidcBoundClaimsField.describe(OIDC_AUTH.ATTACH.boundClaims), boundAudiences: validateOidcAuthAudiencesField.describe(OIDC_AUTH.ATTACH.boundAudiences),
boundSubject: z.string().optional().default("").describe(OIDC_AUTH.ATTACH.boundSubject), boundClaims: validateOidcBoundClaimsField.describe(OIDC_AUTH.ATTACH.boundClaims),
accessTokenTrustedIps: z boundSubject: z.string().optional().default("").describe(OIDC_AUTH.ATTACH.boundSubject),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(OIDC_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(OIDC_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(OIDC_AUTH.ATTACH.accessTokenTTL),
.default(2592000) accessTokenMaxTTL: z
.describe(OIDC_AUTH.ATTACH.accessTokenTTL), .number()
accessTokenMaxTTL: z .int()
.number() .min(0)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(OIDC_AUTH.ATTACH.accessTokenMaxTTL),
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(OIDC_AUTH.ATTACH.accessTokenNumUsesLimit)
}) })
.default(2592000) .refine(
.describe(OIDC_AUTH.ATTACH.accessTokenMaxTTL), (val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(OIDC_AUTH.ATTACH.accessTokenNumUsesLimit) "Access Token TTL cannot be greater than Access Token Max TTL."
}), ),
response: { response: {
200: z.object({ 200: z.object({
identityOidcAuth: IdentityOidcAuthResponseSchema identityOidcAuth: IdentityOidcAuthResponseSchema
@@ -202,26 +202,24 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
accessTokenTTL: z accessTokenTTL: z
.number() .number()
.int() .int()
.min(1) .min(0)
.max(315360000) .max(315360000)
.refine((value) => value !== 0, {
message: "accessTokenTTL must have a non zero number"
})
.default(2592000) .default(2592000)
.describe(OIDC_AUTH.UPDATE.accessTokenTTL), .describe(OIDC_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenMaxTTL: z
.number() .number()
.int() .int()
.min(0)
.max(315360000) .max(315360000)
.refine((value) => value !== 0, {
message: "accessTokenMaxTTL must have a non zero number"
})
.default(2592000) .default(2592000)
.describe(OIDC_AUTH.UPDATE.accessTokenMaxTTL), .describe(OIDC_AUTH.UPDATE.accessTokenMaxTTL),
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(OIDC_AUTH.UPDATE.accessTokenNumUsesLimit) accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(OIDC_AUTH.UPDATE.accessTokenNumUsesLimit)
}) })
.partial(), .partial()
.refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityOidcAuth: IdentityOidcAuthResponseSchema identityOidcAuth: IdentityOidcAuthResponseSchema
@@ -26,36 +26,41 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
params: z.object({ params: z.object({
identityId: z.string().trim().describe(TOKEN_AUTH.ATTACH.identityId) identityId: z.string().trim().describe(TOKEN_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z
accessTokenTrustedIps: z .object({
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(TOKEN_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(TOKEN_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(TOKEN_AUTH.ATTACH.accessTokenTTL),
.default(2592000) accessTokenMaxTTL: z
.describe(TOKEN_AUTH.ATTACH.accessTokenTTL), .number()
accessTokenMaxTTL: z .int()
.number() .min(0)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(TOKEN_AUTH.ATTACH.accessTokenMaxTTL),
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z
}) .number()
.default(2592000) .int()
.describe(TOKEN_AUTH.ATTACH.accessTokenMaxTTL), .min(0)
accessTokenNumUsesLimit: z.number().int().min(0).default(0).describe(TOKEN_AUTH.ATTACH.accessTokenNumUsesLimit) .default(0)
}), .describe(TOKEN_AUTH.ATTACH.accessTokenNumUsesLimit)
})
.refine(
(val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityTokenAuth: IdentityTokenAuthsSchema identityTokenAuth: IdentityTokenAuthsSchema
@@ -110,27 +115,35 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
params: z.object({ params: z.object({
identityId: z.string().trim().describe(TOKEN_AUTH.UPDATE.identityId) identityId: z.string().trim().describe(TOKEN_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z
accessTokenTrustedIps: z .object({
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(TOKEN_AUTH.UPDATE.accessTokenTrustedIps), .optional()
accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(TOKEN_AUTH.UPDATE.accessTokenTTL), .describe(TOKEN_AUTH.UPDATE.accessTokenTrustedIps),
accessTokenNumUsesLimit: z.number().int().min(0).optional().describe(TOKEN_AUTH.UPDATE.accessTokenNumUsesLimit), accessTokenTTL: z.number().int().min(0).max(315360000).optional().describe(TOKEN_AUTH.UPDATE.accessTokenTTL),
accessTokenMaxTTL: z accessTokenNumUsesLimit: z
.number() .number()
.int() .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .optional()
message: "accessTokenMaxTTL must have a non zero number" .describe(TOKEN_AUTH.UPDATE.accessTokenNumUsesLimit),
}) accessTokenMaxTTL: z
.optional() .number()
.describe(TOKEN_AUTH.UPDATE.accessTokenMaxTTL) .int()
}), .min(0)
.max(315360000)
.optional()
.describe(TOKEN_AUTH.UPDATE.accessTokenMaxTTL)
})
.refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityTokenAuth: IdentityTokenAuthsSchema identityTokenAuth: IdentityTokenAuthsSchema
@@ -86,49 +86,49 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => {
params: z.object({ params: z.object({
identityId: z.string().trim().describe(UNIVERSAL_AUTH.ATTACH.identityId) identityId: z.string().trim().describe(UNIVERSAL_AUTH.ATTACH.identityId)
}), }),
body: z.object({ body: z
clientSecretTrustedIps: z .object({
.object({ clientSecretTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(UNIVERSAL_AUTH.ATTACH.clientSecretTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTrustedIps: z .describe(UNIVERSAL_AUTH.ATTACH.clientSecretTrustedIps),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]) .min(1)
.describe(UNIVERSAL_AUTH.ATTACH.accessTokenTrustedIps), .default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }])
accessTokenTTL: z .describe(UNIVERSAL_AUTH.ATTACH.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(1) .int()
.max(315360000) .min(0)
.refine((value) => value !== 0, { .max(315360000)
message: "accessTokenTTL must have a non zero number" .default(2592000)
}) .describe(UNIVERSAL_AUTH.ATTACH.accessTokenTTL), // 30 days
.default(2592000) accessTokenMaxTTL: z
.describe(UNIVERSAL_AUTH.ATTACH.accessTokenTTL), // 30 days .number()
accessTokenMaxTTL: z .int()
.number() .min(0)
.int() .max(315360000)
.max(315360000) .default(2592000)
.refine((value) => value !== 0, { .describe(UNIVERSAL_AUTH.ATTACH.accessTokenMaxTTL), // 30 days
message: "accessTokenMaxTTL must have a non zero number" accessTokenNumUsesLimit: z
}) .number()
.default(2592000) .int()
.describe(UNIVERSAL_AUTH.ATTACH.accessTokenMaxTTL), // 30 days .min(0)
accessTokenNumUsesLimit: z .default(0)
.number() .describe(UNIVERSAL_AUTH.ATTACH.accessTokenNumUsesLimit)
.int() })
.min(0) .refine(
.default(0) (val) => val.accessTokenTTL <= val.accessTokenMaxTTL,
.describe(UNIVERSAL_AUTH.ATTACH.accessTokenNumUsesLimit) "Access Token TTL cannot be greater than Access Token Max TTL."
}), ),
response: { response: {
200: z.object({ 200: z.object({
identityUniversalAuth: IdentityUniversalAuthsSchema identityUniversalAuth: IdentityUniversalAuthsSchema
@@ -181,46 +181,49 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => {
params: z.object({ params: z.object({
identityId: z.string().describe(UNIVERSAL_AUTH.UPDATE.identityId) identityId: z.string().describe(UNIVERSAL_AUTH.UPDATE.identityId)
}), }),
body: z.object({ body: z
clientSecretTrustedIps: z .object({
.object({ clientSecretTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(UNIVERSAL_AUTH.UPDATE.clientSecretTrustedIps), .optional()
accessTokenTrustedIps: z .describe(UNIVERSAL_AUTH.UPDATE.clientSecretTrustedIps),
.object({ accessTokenTrustedIps: z
ipAddress: z.string().trim() .object({
}) ipAddress: z.string().trim()
.array() })
.min(1) .array()
.optional() .min(1)
.describe(UNIVERSAL_AUTH.UPDATE.accessTokenTrustedIps), .optional()
accessTokenTTL: z .describe(UNIVERSAL_AUTH.UPDATE.accessTokenTrustedIps),
.number() accessTokenTTL: z
.int() .number()
.min(0) .int()
.max(315360000) .min(0)
.optional() .max(315360000)
.describe(UNIVERSAL_AUTH.UPDATE.accessTokenTTL), .optional()
accessTokenNumUsesLimit: z .describe(UNIVERSAL_AUTH.UPDATE.accessTokenTTL),
.number() accessTokenNumUsesLimit: z
.int() .number()
.min(0) .int()
.optional() .min(0)
.describe(UNIVERSAL_AUTH.UPDATE.accessTokenNumUsesLimit), .optional()
accessTokenMaxTTL: z .describe(UNIVERSAL_AUTH.UPDATE.accessTokenNumUsesLimit),
.number() accessTokenMaxTTL: z
.int() .number()
.max(315360000) .int()
.refine((value) => value !== 0, { .min(0)
message: "accessTokenMaxTTL must have a non zero number" .max(315360000)
}) .optional()
.optional() .describe(UNIVERSAL_AUTH.UPDATE.accessTokenMaxTTL)
.describe(UNIVERSAL_AUTH.UPDATE.accessTokenMaxTTL) })
}), .refine(
(val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true),
"Access Token TTL cannot be greater than Access Token Max TTL."
),
response: { response: {
200: z.object({ 200: z.object({
identityUniversalAuth: IdentityUniversalAuthsSchema identityUniversalAuth: IdentityUniversalAuthsSchema
@@ -126,12 +126,12 @@ export const identityAwsAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityAwsAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityAwsAuth, identityAccessToken, identityMembershipOrg };
@@ -99,12 +99,12 @@ export const identityAzureAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityAzureAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityAzureAuth, identityAccessToken, identityMembershipOrg };
@@ -138,12 +138,12 @@ export const identityGcpAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityGcpAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityGcpAuth, identityAccessToken, identityMembershipOrg };
@@ -212,12 +212,12 @@ export const identityJwtAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityJwtAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityJwtAuth, identityAccessToken, identityMembershipOrg };
@@ -229,12 +229,12 @@ export const identityKubernetesAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityKubernetesAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityKubernetesAuth, identityAccessToken, identityMembershipOrg };
@@ -194,12 +194,12 @@ export const identityOidcAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityOidcAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityOidcAuth, identityAccessToken, identityMembershipOrg };
@@ -328,12 +328,12 @@ export const identityTokenAuthServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityTokenAuth, identityAccessToken, identityMembershipOrg }; return { accessToken, identityTokenAuth, identityAccessToken, identityMembershipOrg };
@@ -129,12 +129,12 @@ export const identityUaServiceFactory = ({
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
{ // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
expiresIn: Number(identityAccessToken.accessTokenTTL) === 0
Number(identityAccessToken.accessTokenMaxTTL) === 0 ? undefined
? undefined : {
: Number(identityAccessToken.accessTokenMaxTTL) expiresIn: Number(identityAccessToken.accessTokenTTL)
} }
); );
return { accessToken, identityUa, validClientSecretInfo, identityAccessToken, identityMembershipOrg }; return { accessToken, identityUa, validClientSecretInfo, identityAccessToken, identityMembershipOrg };
@@ -259,7 +259,7 @@ export const IdentityAwsAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -273,7 +273,7 @@ export const IdentityAwsAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -255,7 +255,7 @@ export const IdentityAzureAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -269,7 +269,7 @@ export const IdentityAzureAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -294,7 +294,7 @@ export const IdentityGcpAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -308,7 +308,7 @@ export const IdentityGcpAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -563,7 +563,7 @@ export const IdentityJwtAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -577,7 +577,7 @@ export const IdentityJwtAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -305,7 +305,7 @@ export const IdentityKubernetesAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -320,7 +320,7 @@ export const IdentityKubernetesAuthForm = ({
errorText={error?.message} errorText={error?.message}
tooltipText="The maximum lifetime for an access token in seconds. This value will be referenced at renewal time." tooltipText="The maximum lifetime for an access token in seconds. This value will be referenced at renewal time."
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -323,7 +323,7 @@ export const IdentityOidcAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -337,7 +337,7 @@ export const IdentityOidcAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -192,7 +192,7 @@ export const IdentityTokenAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -206,7 +206,7 @@ export const IdentityTokenAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />
@@ -224,7 +224,7 @@ export const IdentityUniversalAuthForm = ({
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
> >
<Input {...field} placeholder="2592000" type="number" min="1" step="1" /> <Input {...field} placeholder="2592000" type="number" min="0" step="1" />
</FormControl> </FormControl>
)} )}
/> />