Fix new order resp

This commit is contained in:
Fang-Pen Lin
2025-11-07 09:18:30 -08:00
parent c6981671af
commit 96cb473192
@@ -208,6 +208,7 @@ export const pkiAcmeServiceFactory = ({
payload: TCreateAcmeAccountPayload; payload: TCreateAcmeAccountPayload;
}): Promise<TAcmeResponse<TCreateAcmeAccountResponse>> => { }): Promise<TAcmeResponse<TCreateAcmeAccountResponse>> => {
const profile = await validateAcmeProfile(profileId); const profile = await validateAcmeProfile(profileId);
// TODO: ensure unique account per public key
const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByPublicKey(profileId, alg, jwk); const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByPublicKey(profileId, alg, jwk);
if (onlyReturnExisting && !existingAccount) { if (onlyReturnExisting && !existingAccount) {
throw new AcmeAccountDoesNotExistError({ message: "ACME account not found" }); throw new AcmeAccountDoesNotExistError({ message: "ACME account not found" });
@@ -272,14 +273,17 @@ export const pkiAcmeServiceFactory = ({
payload.identifiers.map(async (identifier) => { payload.identifiers.map(async (identifier) => {
if (identifier.type === AcmeIdentifierType.DNS) { if (identifier.type === AcmeIdentifierType.DNS) {
// TODO: reuse existing authorizations for this identifier if they exist // TODO: reuse existing authorizations for this identifier if they exist
return await acmeAuthDAL.create({ return await acmeAuthDAL.create(
accountId: account.id, {
status: AcmeAuthStatus.Pending, accountId: account.id,
identifierType: identifier.type, status: AcmeAuthStatus.Pending,
identifierValue: identifier.value, identifierType: identifier.type,
// TODO: read config from the profile to get the expiration time instead identifierValue: identifier.value,
expiresAt: new Date(Date.now() + 24 * 60 * 60 * 1000) // TODO: read config from the profile to get the expiration time instead
}); expiresAt: new Date(Date.now() + 24 * 60 * 60 * 1000)
},
tx
);
} else { } else {
throw new AcmeMalformedError({ detail: "Only DNS identifiers are supported" }); throw new AcmeMalformedError({ detail: "Only DNS identifiers are supported" });
} }
@@ -290,7 +294,8 @@ export const pkiAcmeServiceFactory = ({
authorizations.map((auth) => ({ authorizations.map((auth) => ({
orderId: createdOrder.id, orderId: createdOrder.id,
authId: auth.id authId: auth.id
})) })),
tx
); );
return { ...createdOrder, authorizations, account }; return { ...createdOrder, authorizations, account };
}); });
@@ -301,18 +306,13 @@ export const pkiAcmeServiceFactory = ({
status: "pending", status: "pending",
// TODO: read config from the profile to get the expiration time instead // TODO: read config from the profile to get the expiration time instead
expires: new Date(Date.now() + 24 * 60 * 60 * 1000).toISOString(), expires: new Date(Date.now() + 24 * 60 * 60 * 1000).toISOString(),
identifiers: order.authorizations.map((auth) => ({ identifiers: order.authorizations.map((auth: TPkiAcmeAuths) => ({
type: auth.identifierType, type: auth.identifierType,
value: auth.identifierValue value: auth.identifierValue
})), })),
authorizations: order.authorizations.map((auth) => ({ authorizations: order.authorizations.map((auth: TPkiAcmeAuths) =>
id: auth.id, buildUrl(`/api/v1/pki/acme/profiles/${order.account.profileId}/authorizations/${auth.id}`)
status: auth.status, ),
identifier: {
type: auth.identifierType,
value: auth.identifierValue
}
})),
finalize: buildUrl(`/api/v1/pki/acme/profiles/${order.account.profileId}/orders/${order.id}/finalize`) finalize: buildUrl(`/api/v1/pki/acme/profiles/${order.account.profileId}/orders/${order.id}/finalize`)
}, },
headers: { headers: {