From 96cb47319283b6e2a527ae880310b77771460c3b Mon Sep 17 00:00:00 2001 From: Fang-Pen Lin Date: Wed, 29 Oct 2025 18:25:26 -0700 Subject: [PATCH] Fix new order resp --- .../ee/services/pki-acme/pki-acme-service.ts | 36 +++++++++---------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/backend/src/ee/services/pki-acme/pki-acme-service.ts b/backend/src/ee/services/pki-acme/pki-acme-service.ts index bcb3f07c7..f6400e181 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-service.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-service.ts @@ -208,6 +208,7 @@ export const pkiAcmeServiceFactory = ({ payload: TCreateAcmeAccountPayload; }): Promise> => { const profile = await validateAcmeProfile(profileId); + // TODO: ensure unique account per public key const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByPublicKey(profileId, alg, jwk); if (onlyReturnExisting && !existingAccount) { throw new AcmeAccountDoesNotExistError({ message: "ACME account not found" }); @@ -272,14 +273,17 @@ export const pkiAcmeServiceFactory = ({ payload.identifiers.map(async (identifier) => { if (identifier.type === AcmeIdentifierType.DNS) { // TODO: reuse existing authorizations for this identifier if they exist - return await acmeAuthDAL.create({ - accountId: account.id, - status: AcmeAuthStatus.Pending, - identifierType: identifier.type, - identifierValue: identifier.value, - // TODO: read config from the profile to get the expiration time instead - expiresAt: new Date(Date.now() + 24 * 60 * 60 * 1000) - }); + return await acmeAuthDAL.create( + { + accountId: account.id, + status: AcmeAuthStatus.Pending, + identifierType: identifier.type, + identifierValue: identifier.value, + // TODO: read config from the profile to get the expiration time instead + expiresAt: new Date(Date.now() + 24 * 60 * 60 * 1000) + }, + tx + ); } else { throw new AcmeMalformedError({ detail: "Only DNS identifiers are supported" }); } @@ -290,7 +294,8 @@ export const pkiAcmeServiceFactory = ({ authorizations.map((auth) => ({ orderId: createdOrder.id, authId: auth.id - })) + })), + tx ); return { ...createdOrder, authorizations, account }; }); @@ -301,18 +306,13 @@ export const pkiAcmeServiceFactory = ({ status: "pending", // TODO: read config from the profile to get the expiration time instead expires: new Date(Date.now() + 24 * 60 * 60 * 1000).toISOString(), - identifiers: order.authorizations.map((auth) => ({ + identifiers: order.authorizations.map((auth: TPkiAcmeAuths) => ({ type: auth.identifierType, value: auth.identifierValue })), - authorizations: order.authorizations.map((auth) => ({ - id: auth.id, - status: auth.status, - identifier: { - type: auth.identifierType, - value: auth.identifierValue - } - })), + authorizations: order.authorizations.map((auth: TPkiAcmeAuths) => + buildUrl(`/api/v1/pki/acme/profiles/${order.account.profileId}/authorizations/${auth.id}`) + ), finalize: buildUrl(`/api/v1/pki/acme/profiles/${order.account.profileId}/orders/${order.id}/finalize`) }, headers: {