Add no access role, replace ST V3 refs with machine

This commit is contained in:
Tuan Dang
2023-11-27 09:59:15 +07:00
parent 63df0dba64
commit 99c41bb63b
21 changed files with 69 additions and 65 deletions

View File

@@ -25,7 +25,7 @@ declare module "jsonwebtoken" {
userId: string;
refreshVersion?: number;
}
export interface ServiceRefreshTokenJwtPayload extends jwt.JwtPayload {
export interface MachineRefreshTokenJwtPayload extends jwt.JwtPayload {
serviceTokenDataId: string;
authTokenType: string;
tokenVersion: number;

View File

@@ -99,7 +99,7 @@ const checkSecretsPermission = async ({
});
return { authVerifier: () => true };
}
case ActorType.SERVICE_V3: {
case ActorType.MACHINE: {
const { permission } = await getAuthDataProjectPermissions({
authData,
workspaceId: new Types.ObjectId(workspaceId)

View File

@@ -17,10 +17,10 @@ import {
FolderVersion,
IPType,
ISecretVersion,
MachineActor,
SecretSnapshot,
SecretVersion,
ServiceActor,
ServiceActorV3,
TFolderRootVersionSchema,
TrustedIP,
UserActor
@@ -757,12 +757,12 @@ export const getWorkspaceAuditLogActorFilterOpts = async (req: Request, res: Res
}
}));
const serviceV3Actors: ServiceActorV3[] = (
const serviceV3Actors: MachineActor[] = (
await MachineIdentity.find({
workspace: new Types.ObjectId(workspaceId)
})
).map((machineIdentity) => ({
type: ActorType.SERVICE_V3,
type: ActorType.MACHINE,
metadata: {
serviceId: machineIdentity._id.toString(),
name: machineIdentity.name

View File

@@ -44,11 +44,11 @@ import { ForbiddenError } from "@casl/ability";
}
} = await validateRequest(reqValidator.RefreshTokenV3, req);
const decodedToken = <jwt.ServiceRefreshTokenJwtPayload>(
const decodedToken = <jwt.MachineRefreshTokenJwtPayload>(
jwt.verify(refreshToken, await getAuthSecret())
);
if (decodedToken.authTokenType !== AuthTokenType.SERVICE_REFRESH_TOKEN) throw UnauthorizedRequestError();
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_REFRESH_TOKEN) throw UnauthorizedRequestError();
let machineIdentity = await MachineIdentity.findOne({
_id: new Types.ObjectId(decodedToken.serviceTokenDataId),
@@ -92,7 +92,7 @@ import { ForbiddenError } from "@casl/ability";
response.refreshToken = createToken({
payload: {
serviceTokenDataId: machineIdentity._id.toString(),
authTokenType: AuthTokenType.SERVICE_REFRESH_TOKEN,
authTokenType: AuthTokenType.MACHINE_REFRESH_TOKEN,
tokenVersion: machineIdentity.tokenVersion
},
secret: await getAuthSecret()
@@ -101,8 +101,8 @@ import { ForbiddenError } from "@casl/ability";
response.accessToken = createToken({
payload: {
serviceTokenDataId: machineIdentity._id.toString(), // TODO: fix this
authTokenType: AuthTokenType.SERVICE_ACCESS_TOKEN,
_id: machineIdentity._id.toString(), // TODO: fix this
authTokenType: AuthTokenType.MACHINE_ACCESS_TOKEN,
tokenVersion: machineIdentity.tokenVersion
},
expiresIn: machineIdentity.accessTokenTTL,
@@ -226,8 +226,8 @@ export const createMachineIdentity = async (req: Request, res: Response) => {
const refreshToken = createToken({
payload: {
serviceTokenDataId: machineIdentity._id.toString(), // TODO: update
authTokenType: AuthTokenType.SERVICE_REFRESH_TOKEN,
_id: machineIdentity._id.toString(),
authTokenType: AuthTokenType.MACHINE_REFRESH_TOKEN,
tokenVersion: machineIdentity.tokenVersion
},
secret: await getAuthSecret()

View File

@@ -1,8 +1,7 @@
export enum ActorType {
USER = "user",
SERVICE = "service",
SERVICE_V3 = "service-v3",
// Machine = "machine"
MACHINE = "machine"
}
export enum UserAgentType {

View File

@@ -11,6 +11,11 @@ interface ServiceActorMetadata {
name: string;
}
interface MachineActorMetadata {
machineId: string;
name: string;
}
export interface UserActor {
type: ActorType.USER;
metadata: UserActorMetadata;
@@ -21,16 +26,16 @@ export interface ServiceActor {
metadata: ServiceActorMetadata;
}
export interface ServiceActorV3 {
type: ActorType.SERVICE_V3;
metadata: ServiceActorMetadata;
export interface MachineActor {
type: ActorType.MACHINE;
metadata: MachineActorMetadata;
}
// export interface MachineActor {
// type: ActorType.Machine;
// }
export type Actor = UserActor | ServiceActor | ServiceActorV3;
export type Actor = UserActor | ServiceActor | MachineActor;
interface GetSecretsEvent {
type: EventType.GET_SECRETS;

View File

@@ -310,7 +310,7 @@ export const getAuthDataProjectPermissions = async ({
role = "viewer";
break;
}
case ActorType.SERVICE_V3: {
case ActorType.MACHINE: {
const machineMembership = await MachineMembership.findOne({
machineIdentity: authData.authPayload._id,
workspace: workspaceId

View File

@@ -1,6 +1,6 @@
import { Types } from "mongoose";
import { IMachineIdentity, IServiceTokenData, IUser } from "../../models";
import { ServiceActor, ServiceActorV3, UserActor, UserAgentType } from "../../ee/models";
import { MachineActor, ServiceActor, UserActor, UserAgentType } from "../../ee/models";
interface BaseAuthData {
ipAddress: string;
@@ -15,7 +15,7 @@ export interface UserAuthData extends BaseAuthData {
}
export interface MachineIdentityAuthData extends BaseAuthData {
actor: ServiceActorV3;
actor: MachineActor;
authPayload: IMachineIdentity;
}

View File

@@ -50,7 +50,7 @@ const requireAuth = ({
case AuthMode.SERVICE_TOKEN:
req.serviceTokenData = authData.authPayload;
break;
case AuthMode.SERVICE_ACCESS_TOKEN:
case AuthMode.MACHINE_ACCESS_TOKEN:
req.serviceTokenData = authData.authPayload;
break;
case AuthMode.API_KEY:

View File

@@ -7,7 +7,7 @@ import { AuthMode } from "../../variables";
router.get(
"/raw",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
secretsController.getSecretsRaw
);
@@ -15,7 +15,7 @@ router.get(
router.get(
"/raw/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "query"
@@ -29,7 +29,7 @@ router.get(
router.post(
"/raw/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "body"
@@ -43,7 +43,7 @@ router.post(
router.patch(
"/raw/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "body"
@@ -57,7 +57,7 @@ router.patch(
router.delete(
"/raw/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "body"
@@ -71,7 +71,7 @@ router.delete(
router.get(
"/",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "query"
@@ -116,7 +116,7 @@ router.delete(
router.post(
"/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "body"
@@ -127,7 +127,7 @@ router.post(
router.get(
"/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "query"
@@ -138,7 +138,7 @@ router.get(
router.patch(
"/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "body"
@@ -149,7 +149,7 @@ router.patch(
router.delete(
"/:secretName",
requireAuth({
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
}),
requireBlindIndicesEnabled({
locationWorkspaceId: "body"

View File

@@ -12,14 +12,14 @@ interface ValidateMachineIdentityParams {
export const validateMachineIdentity = async ({
authTokenValue
}: ValidateMachineIdentityParams) => {
const decodedToken = <jwt.ServiceRefreshTokenJwtPayload>(
const decodedToken = <jwt.MachineRefreshTokenJwtPayload>(
jwt.verify(authTokenValue, await getAuthSecret())
);
if (decodedToken.authTokenType !== AuthTokenType.SERVICE_ACCESS_TOKEN) throw UnauthorizedRequestError();
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError();
const machineIdentity = await MachineIdentity.findOne({
_id: new Types.ObjectId(decodedToken.serviceTokenDataId),
_id: new Types.ObjectId(decodedToken._id),
isActive: true
});

View File

@@ -36,7 +36,7 @@ interface GetAuthDataParams {
* - SERVICE_TOKEN
* - API_KEY
* - JWT
* - SERVICE_ACCESS_TOKEN (from machine identity)
* - MACHINE_ACCESS_TOKEN (from machine identity)
* - API_KEY_V2
* @param {Object} params
* @param {Object.<string, (string|string[]|undefined)>} params.headers - The HTTP request headers, usually from Express's `req.headers`.
@@ -77,8 +77,8 @@ export const extractAuthMode = async ({
return { authMode: AuthMode.JWT, authTokenValue };
case AuthTokenType.API_KEY:
return { authMode: AuthMode.API_KEY_V2, authTokenValue };
case AuthTokenType.SERVICE_ACCESS_TOKEN:
return { authMode: AuthMode.SERVICE_ACCESS_TOKEN, authTokenValue };
case AuthTokenType.MACHINE_ACCESS_TOKEN:
return { authMode: AuthMode.MACHINE_ACCESS_TOKEN, authTokenValue };
default:
throw UnauthorizedRequestError({
message: "Failed to authenticate unknown authentication method"
@@ -115,20 +115,20 @@ export const getAuthData = async ({
userAgentType
}
}
case AuthMode.SERVICE_ACCESS_TOKEN: {
const serviceTokenData = await validateMachineIdentity({
case AuthMode.MACHINE_ACCESS_TOKEN: {
const machineIdentity = await validateMachineIdentity({
authTokenValue
});
return {
actor: {
type: ActorType.SERVICE_V3,
type: ActorType.MACHINE,
metadata: {
serviceId: serviceTokenData._id.toString(),
name: serviceTokenData.name
machineId: machineIdentity._id.toString(),
name: machineIdentity.name
}
},
authPayload: serviceTokenData,
authPayload: machineIdentity,
ipAddress,
userAgent,
userAgentType

View File

@@ -58,9 +58,9 @@ const validateClientForIntegrationAuth = async ({
throw UnauthorizedRequestError({
message: "Failed service token authorization for integration authorization"
});
case ActorType.SERVICE_V3:
case ActorType.MACHINE:
throw UnauthorizedRequestError({
message: "Failed service token authorization for integration authorization"
message: "Failed machine authorization for integration authorization"
});
}
};

View File

@@ -1,5 +1,5 @@
import { z } from "zod";
import { MEMBER } from "../variables";
import { NO_ACCESS } from "../variables";
export const RefreshTokenV3 = z.object({
body: z.object({
@@ -11,8 +11,8 @@ export const CreateMachineIdentityV3 = z.object({
body: z.object({
name: z.string().trim(),
organizationId: z.string().trim(),
role: z.string().trim().min(1).default(MEMBER),
trustedIps: z // TODO: provide default
role: z.string().trim().min(1).default(NO_ACCESS),
trustedIps: z
.object({
ipAddress: z.string().trim(),
})

View File

@@ -46,9 +46,9 @@ export const validateClientForOrganization = async ({
throw UnauthorizedRequestError({
message: "Failed service token authorization for organization"
});
case ActorType.SERVICE_V3:
case ActorType.MACHINE:
throw UnauthorizedRequestError({
message: "Failed service token authorization for organization"
message: "Failed machine authorization for organization"
});
}
};

View File

@@ -8,7 +8,7 @@ import { AuthData } from "../interfaces/middleware";
import { z } from "zod";
import { EventType, UserAgentType } from "../ee/models";
import { UnauthorizedRequestError } from "../utils/errors";
import { MEMBER } from "../variables";
import { NO_ACCESS } from "../variables";
/**
* Validate authenticated clients for workspace with id [workspaceId] based
@@ -60,9 +60,9 @@ export const validateClientForWorkspace = async ({
requiredPermissions
});
return { membership, workspace };
case ActorType.SERVICE_V3:
case ActorType.MACHINE:
throw UnauthorizedRequestError({
message: "Failed service token authorization for organization"
message: "Failed machine authorization for organization"
});
}
};
@@ -286,7 +286,7 @@ export const AddWorkspaceServiceMemberV2 = z.object({
machineId: z.string().trim()
}),
body: z.object({
role: z.string().trim().min(1).default(MEMBER),
role: z.string().trim().min(1).default(NO_ACCESS),
})
});

View File

@@ -7,14 +7,14 @@ export enum AuthTokenType {
MFA_TOKEN = "mfaToken", // TODO: remove in favor of claim
PROVIDER_TOKEN = "providerToken", // TODO: remove in favor of claim
API_KEY = "apiKey",
SERVICE_ACCESS_TOKEN = "serviceAccessToken",
SERVICE_REFRESH_TOKEN = "serviceRefreshToken"
MACHINE_ACCESS_TOKEN = "machineAccessToken",
MACHINE_REFRESH_TOKEN = "machineRefreshToken"
}
export enum AuthMode {
JWT = "jwt",
SERVICE_TOKEN = "serviceToken",
SERVICE_ACCESS_TOKEN = "serviceAccessToken",
MACHINE_ACCESS_TOKEN = "machineAccessToken",
API_KEY = "apiKey",
API_KEY_V2 = "apiKeyV2"
}

View File

@@ -1,7 +1,7 @@
export enum ActorType {
USER = "user",
SERVICE = "service",
SERVICE_V3 = "service-v3"
MACHINE = "machine"
}
export enum UserAgentType {

View File

@@ -20,12 +20,12 @@ export interface ServiceActor {
metadata: ServiceActorMetadata;
}
export interface ServiceActorV3 {
type: ActorType.SERVICE_V3;
export interface MachineActor {
type: ActorType.MACHINE;
metadata: ServiceActorMetadata;
}
export type Actor = UserActor | ServiceActor | ServiceActorV3;
export type Actor = UserActor | ServiceActor | MachineActor;
interface GetSecretsEvent {
type: EventType.GET_SECRETS;

View File

@@ -50,11 +50,11 @@ export const LogsFilter = ({ control, reset }: Props) => {
{actor.metadata.name}
</SelectItem>
);
case ActorType.SERVICE_V3:
case ActorType.MACHINE:
return (
<SelectItem
value={`${actor.type}-${actor.metadata.serviceId}`}
key={`service-actor-v3-filter-${actor.metadata.serviceId}`}
key={`machine-filter-${actor.metadata.serviceId}`}
>
{actor.metadata.name}
</SelectItem>

View File

@@ -29,7 +29,7 @@ export const LogsTableRow = ({
<p>Service token</p>
</Td>
);
case ActorType.SERVICE_V3:
case ActorType.MACHINE:
return (
<Td>
<p>{`${actor.metadata.name}`}</p>