diff --git a/backend/src/controllers/v1/authController.ts b/backend/src/controllers/v1/authController.ts index 428c1bda0..75f2fe604 100644 --- a/backend/src/controllers/v1/authController.ts +++ b/backend/src/controllers/v1/authController.ts @@ -25,7 +25,7 @@ declare module "jsonwebtoken" { userId: string; refreshVersion?: number; } - export interface ServiceRefreshTokenJwtPayload extends jwt.JwtPayload { + export interface MachineRefreshTokenJwtPayload extends jwt.JwtPayload { serviceTokenDataId: string; authTokenType: string; tokenVersion: number; diff --git a/backend/src/controllers/v3/secretsController.ts b/backend/src/controllers/v3/secretsController.ts index 1c691088a..e379ffc00 100644 --- a/backend/src/controllers/v3/secretsController.ts +++ b/backend/src/controllers/v3/secretsController.ts @@ -99,7 +99,7 @@ const checkSecretsPermission = async ({ }); return { authVerifier: () => true }; } - case ActorType.SERVICE_V3: { + case ActorType.MACHINE: { const { permission } = await getAuthDataProjectPermissions({ authData, workspaceId: new Types.ObjectId(workspaceId) diff --git a/backend/src/ee/controllers/v1/workspaceController.ts b/backend/src/ee/controllers/v1/workspaceController.ts index 68d8c541b..2b11c3674 100644 --- a/backend/src/ee/controllers/v1/workspaceController.ts +++ b/backend/src/ee/controllers/v1/workspaceController.ts @@ -17,10 +17,10 @@ import { FolderVersion, IPType, ISecretVersion, + MachineActor, SecretSnapshot, SecretVersion, ServiceActor, - ServiceActorV3, TFolderRootVersionSchema, TrustedIP, UserActor @@ -757,12 +757,12 @@ export const getWorkspaceAuditLogActorFilterOpts = async (req: Request, res: Res } })); - const serviceV3Actors: ServiceActorV3[] = ( + const serviceV3Actors: MachineActor[] = ( await MachineIdentity.find({ workspace: new Types.ObjectId(workspaceId) }) ).map((machineIdentity) => ({ - type: ActorType.SERVICE_V3, + type: ActorType.MACHINE, metadata: { serviceId: machineIdentity._id.toString(), name: machineIdentity.name diff --git a/backend/src/ee/controllers/v3/machineIdentityController.ts b/backend/src/ee/controllers/v3/machineIdentityController.ts index 07b093fe2..a422aa9c3 100644 --- a/backend/src/ee/controllers/v3/machineIdentityController.ts +++ b/backend/src/ee/controllers/v3/machineIdentityController.ts @@ -44,11 +44,11 @@ import { ForbiddenError } from "@casl/ability"; } } = await validateRequest(reqValidator.RefreshTokenV3, req); - const decodedToken = ( + const decodedToken = ( jwt.verify(refreshToken, await getAuthSecret()) ); - if (decodedToken.authTokenType !== AuthTokenType.SERVICE_REFRESH_TOKEN) throw UnauthorizedRequestError(); + if (decodedToken.authTokenType !== AuthTokenType.MACHINE_REFRESH_TOKEN) throw UnauthorizedRequestError(); let machineIdentity = await MachineIdentity.findOne({ _id: new Types.ObjectId(decodedToken.serviceTokenDataId), @@ -92,7 +92,7 @@ import { ForbiddenError } from "@casl/ability"; response.refreshToken = createToken({ payload: { serviceTokenDataId: machineIdentity._id.toString(), - authTokenType: AuthTokenType.SERVICE_REFRESH_TOKEN, + authTokenType: AuthTokenType.MACHINE_REFRESH_TOKEN, tokenVersion: machineIdentity.tokenVersion }, secret: await getAuthSecret() @@ -101,8 +101,8 @@ import { ForbiddenError } from "@casl/ability"; response.accessToken = createToken({ payload: { - serviceTokenDataId: machineIdentity._id.toString(), // TODO: fix this - authTokenType: AuthTokenType.SERVICE_ACCESS_TOKEN, + _id: machineIdentity._id.toString(), // TODO: fix this + authTokenType: AuthTokenType.MACHINE_ACCESS_TOKEN, tokenVersion: machineIdentity.tokenVersion }, expiresIn: machineIdentity.accessTokenTTL, @@ -226,8 +226,8 @@ export const createMachineIdentity = async (req: Request, res: Response) => { const refreshToken = createToken({ payload: { - serviceTokenDataId: machineIdentity._id.toString(), // TODO: update - authTokenType: AuthTokenType.SERVICE_REFRESH_TOKEN, + _id: machineIdentity._id.toString(), + authTokenType: AuthTokenType.MACHINE_REFRESH_TOKEN, tokenVersion: machineIdentity.tokenVersion }, secret: await getAuthSecret() diff --git a/backend/src/ee/models/auditLog/enums.ts b/backend/src/ee/models/auditLog/enums.ts index 08c0c2ff7..629c13dc2 100644 --- a/backend/src/ee/models/auditLog/enums.ts +++ b/backend/src/ee/models/auditLog/enums.ts @@ -1,8 +1,7 @@ export enum ActorType { USER = "user", SERVICE = "service", - SERVICE_V3 = "service-v3", - // Machine = "machine" + MACHINE = "machine" } export enum UserAgentType { diff --git a/backend/src/ee/models/auditLog/types.ts b/backend/src/ee/models/auditLog/types.ts index bd79b5bec..542feee7b 100644 --- a/backend/src/ee/models/auditLog/types.ts +++ b/backend/src/ee/models/auditLog/types.ts @@ -11,6 +11,11 @@ interface ServiceActorMetadata { name: string; } +interface MachineActorMetadata { + machineId: string; + name: string; +} + export interface UserActor { type: ActorType.USER; metadata: UserActorMetadata; @@ -21,16 +26,16 @@ export interface ServiceActor { metadata: ServiceActorMetadata; } -export interface ServiceActorV3 { - type: ActorType.SERVICE_V3; - metadata: ServiceActorMetadata; +export interface MachineActor { + type: ActorType.MACHINE; + metadata: MachineActorMetadata; } // export interface MachineActor { // type: ActorType.Machine; // } -export type Actor = UserActor | ServiceActor | ServiceActorV3; +export type Actor = UserActor | ServiceActor | MachineActor; interface GetSecretsEvent { type: EventType.GET_SECRETS; diff --git a/backend/src/ee/services/ProjectRoleService.ts b/backend/src/ee/services/ProjectRoleService.ts index 225f72534..0b368c9a0 100644 --- a/backend/src/ee/services/ProjectRoleService.ts +++ b/backend/src/ee/services/ProjectRoleService.ts @@ -310,7 +310,7 @@ export const getAuthDataProjectPermissions = async ({ role = "viewer"; break; } - case ActorType.SERVICE_V3: { + case ActorType.MACHINE: { const machineMembership = await MachineMembership.findOne({ machineIdentity: authData.authPayload._id, workspace: workspaceId diff --git a/backend/src/interfaces/middleware/index.ts b/backend/src/interfaces/middleware/index.ts index 3bccaa20e..8f72c6668 100644 --- a/backend/src/interfaces/middleware/index.ts +++ b/backend/src/interfaces/middleware/index.ts @@ -1,6 +1,6 @@ import { Types } from "mongoose"; import { IMachineIdentity, IServiceTokenData, IUser } from "../../models"; -import { ServiceActor, ServiceActorV3, UserActor, UserAgentType } from "../../ee/models"; +import { MachineActor, ServiceActor, UserActor, UserAgentType } from "../../ee/models"; interface BaseAuthData { ipAddress: string; @@ -15,7 +15,7 @@ export interface UserAuthData extends BaseAuthData { } export interface MachineIdentityAuthData extends BaseAuthData { - actor: ServiceActorV3; + actor: MachineActor; authPayload: IMachineIdentity; } diff --git a/backend/src/middleware/requireAuth.ts b/backend/src/middleware/requireAuth.ts index 929d22fea..07dc93a38 100644 --- a/backend/src/middleware/requireAuth.ts +++ b/backend/src/middleware/requireAuth.ts @@ -50,7 +50,7 @@ const requireAuth = ({ case AuthMode.SERVICE_TOKEN: req.serviceTokenData = authData.authPayload; break; - case AuthMode.SERVICE_ACCESS_TOKEN: + case AuthMode.MACHINE_ACCESS_TOKEN: req.serviceTokenData = authData.authPayload; break; case AuthMode.API_KEY: diff --git a/backend/src/routes/v3/secrets.ts b/backend/src/routes/v3/secrets.ts index 81e0cb4c0..d19445258 100644 --- a/backend/src/routes/v3/secrets.ts +++ b/backend/src/routes/v3/secrets.ts @@ -7,7 +7,7 @@ import { AuthMode } from "../../variables"; router.get( "/raw", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), secretsController.getSecretsRaw ); @@ -15,7 +15,7 @@ router.get( router.get( "/raw/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "query" @@ -29,7 +29,7 @@ router.get( router.post( "/raw/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "body" @@ -43,7 +43,7 @@ router.post( router.patch( "/raw/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "body" @@ -57,7 +57,7 @@ router.patch( router.delete( "/raw/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "body" @@ -71,7 +71,7 @@ router.delete( router.get( "/", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "query" @@ -116,7 +116,7 @@ router.delete( router.post( "/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "body" @@ -127,7 +127,7 @@ router.post( router.get( "/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "query" @@ -138,7 +138,7 @@ router.get( router.patch( "/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "body" @@ -149,7 +149,7 @@ router.patch( router.delete( "/:secretName", requireAuth({ - acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN] + acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN] }), requireBlindIndicesEnabled({ locationWorkspaceId: "body" diff --git a/backend/src/utils/authn/authModeValidators/machineIdentity.ts b/backend/src/utils/authn/authModeValidators/machineIdentity.ts index effb657ae..bdd1f823b 100644 --- a/backend/src/utils/authn/authModeValidators/machineIdentity.ts +++ b/backend/src/utils/authn/authModeValidators/machineIdentity.ts @@ -12,14 +12,14 @@ interface ValidateMachineIdentityParams { export const validateMachineIdentity = async ({ authTokenValue }: ValidateMachineIdentityParams) => { - const decodedToken = ( + const decodedToken = ( jwt.verify(authTokenValue, await getAuthSecret()) ); - if (decodedToken.authTokenType !== AuthTokenType.SERVICE_ACCESS_TOKEN) throw UnauthorizedRequestError(); + if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError(); const machineIdentity = await MachineIdentity.findOne({ - _id: new Types.ObjectId(decodedToken.serviceTokenDataId), + _id: new Types.ObjectId(decodedToken._id), isActive: true }); diff --git a/backend/src/utils/authn/helpers/index.ts b/backend/src/utils/authn/helpers/index.ts index 1ae7449b4..54a58ae33 100644 --- a/backend/src/utils/authn/helpers/index.ts +++ b/backend/src/utils/authn/helpers/index.ts @@ -36,7 +36,7 @@ interface GetAuthDataParams { * - SERVICE_TOKEN * - API_KEY * - JWT - * - SERVICE_ACCESS_TOKEN (from machine identity) + * - MACHINE_ACCESS_TOKEN (from machine identity) * - API_KEY_V2 * @param {Object} params * @param {Object.} params.headers - The HTTP request headers, usually from Express's `req.headers`. @@ -77,8 +77,8 @@ export const extractAuthMode = async ({ return { authMode: AuthMode.JWT, authTokenValue }; case AuthTokenType.API_KEY: return { authMode: AuthMode.API_KEY_V2, authTokenValue }; - case AuthTokenType.SERVICE_ACCESS_TOKEN: - return { authMode: AuthMode.SERVICE_ACCESS_TOKEN, authTokenValue }; + case AuthTokenType.MACHINE_ACCESS_TOKEN: + return { authMode: AuthMode.MACHINE_ACCESS_TOKEN, authTokenValue }; default: throw UnauthorizedRequestError({ message: "Failed to authenticate unknown authentication method" @@ -115,20 +115,20 @@ export const getAuthData = async ({ userAgentType } } - case AuthMode.SERVICE_ACCESS_TOKEN: { - const serviceTokenData = await validateMachineIdentity({ + case AuthMode.MACHINE_ACCESS_TOKEN: { + const machineIdentity = await validateMachineIdentity({ authTokenValue }); return { actor: { - type: ActorType.SERVICE_V3, + type: ActorType.MACHINE, metadata: { - serviceId: serviceTokenData._id.toString(), - name: serviceTokenData.name + machineId: machineIdentity._id.toString(), + name: machineIdentity.name } }, - authPayload: serviceTokenData, + authPayload: machineIdentity, ipAddress, userAgent, userAgentType diff --git a/backend/src/validation/integrationAuth.ts b/backend/src/validation/integrationAuth.ts index 3eb51d833..d4a6b42a5 100644 --- a/backend/src/validation/integrationAuth.ts +++ b/backend/src/validation/integrationAuth.ts @@ -58,9 +58,9 @@ const validateClientForIntegrationAuth = async ({ throw UnauthorizedRequestError({ message: "Failed service token authorization for integration authorization" }); - case ActorType.SERVICE_V3: + case ActorType.MACHINE: throw UnauthorizedRequestError({ - message: "Failed service token authorization for integration authorization" + message: "Failed machine authorization for integration authorization" }); } }; diff --git a/backend/src/validation/machineIdentity.ts b/backend/src/validation/machineIdentity.ts index 32be61c99..15af09f14 100644 --- a/backend/src/validation/machineIdentity.ts +++ b/backend/src/validation/machineIdentity.ts @@ -1,5 +1,5 @@ import { z } from "zod"; -import { MEMBER } from "../variables"; +import { NO_ACCESS } from "../variables"; export const RefreshTokenV3 = z.object({ body: z.object({ @@ -11,8 +11,8 @@ export const CreateMachineIdentityV3 = z.object({ body: z.object({ name: z.string().trim(), organizationId: z.string().trim(), - role: z.string().trim().min(1).default(MEMBER), - trustedIps: z // TODO: provide default + role: z.string().trim().min(1).default(NO_ACCESS), + trustedIps: z .object({ ipAddress: z.string().trim(), }) diff --git a/backend/src/validation/organization.ts b/backend/src/validation/organization.ts index aab05e97a..20e2f1567 100644 --- a/backend/src/validation/organization.ts +++ b/backend/src/validation/organization.ts @@ -46,9 +46,9 @@ export const validateClientForOrganization = async ({ throw UnauthorizedRequestError({ message: "Failed service token authorization for organization" }); - case ActorType.SERVICE_V3: + case ActorType.MACHINE: throw UnauthorizedRequestError({ - message: "Failed service token authorization for organization" + message: "Failed machine authorization for organization" }); } }; diff --git a/backend/src/validation/workspace.ts b/backend/src/validation/workspace.ts index b7d3b56ba..3eaffd187 100644 --- a/backend/src/validation/workspace.ts +++ b/backend/src/validation/workspace.ts @@ -8,7 +8,7 @@ import { AuthData } from "../interfaces/middleware"; import { z } from "zod"; import { EventType, UserAgentType } from "../ee/models"; import { UnauthorizedRequestError } from "../utils/errors"; -import { MEMBER } from "../variables"; +import { NO_ACCESS } from "../variables"; /** * Validate authenticated clients for workspace with id [workspaceId] based @@ -60,9 +60,9 @@ export const validateClientForWorkspace = async ({ requiredPermissions }); return { membership, workspace }; - case ActorType.SERVICE_V3: + case ActorType.MACHINE: throw UnauthorizedRequestError({ - message: "Failed service token authorization for organization" + message: "Failed machine authorization for organization" }); } }; @@ -286,7 +286,7 @@ export const AddWorkspaceServiceMemberV2 = z.object({ machineId: z.string().trim() }), body: z.object({ - role: z.string().trim().min(1).default(MEMBER), + role: z.string().trim().min(1).default(NO_ACCESS), }) }); diff --git a/backend/src/variables/authentication.ts b/backend/src/variables/authentication.ts index bdad84ff6..c474eb309 100644 --- a/backend/src/variables/authentication.ts +++ b/backend/src/variables/authentication.ts @@ -7,14 +7,14 @@ export enum AuthTokenType { MFA_TOKEN = "mfaToken", // TODO: remove in favor of claim PROVIDER_TOKEN = "providerToken", // TODO: remove in favor of claim API_KEY = "apiKey", - SERVICE_ACCESS_TOKEN = "serviceAccessToken", - SERVICE_REFRESH_TOKEN = "serviceRefreshToken" + MACHINE_ACCESS_TOKEN = "machineAccessToken", + MACHINE_REFRESH_TOKEN = "machineRefreshToken" } export enum AuthMode { JWT = "jwt", SERVICE_TOKEN = "serviceToken", - SERVICE_ACCESS_TOKEN = "serviceAccessToken", + MACHINE_ACCESS_TOKEN = "machineAccessToken", API_KEY = "apiKey", API_KEY_V2 = "apiKeyV2" } diff --git a/frontend/src/hooks/api/auditLogs/enums.tsx b/frontend/src/hooks/api/auditLogs/enums.tsx index 0be03e452..9aefd34a1 100644 --- a/frontend/src/hooks/api/auditLogs/enums.tsx +++ b/frontend/src/hooks/api/auditLogs/enums.tsx @@ -1,7 +1,7 @@ export enum ActorType { USER = "user", SERVICE = "service", - SERVICE_V3 = "service-v3" + MACHINE = "machine" } export enum UserAgentType { diff --git a/frontend/src/hooks/api/auditLogs/types.tsx b/frontend/src/hooks/api/auditLogs/types.tsx index ff6dceffc..56826a273 100644 --- a/frontend/src/hooks/api/auditLogs/types.tsx +++ b/frontend/src/hooks/api/auditLogs/types.tsx @@ -20,12 +20,12 @@ export interface ServiceActor { metadata: ServiceActorMetadata; } -export interface ServiceActorV3 { - type: ActorType.SERVICE_V3; +export interface MachineActor { + type: ActorType.MACHINE; metadata: ServiceActorMetadata; } -export type Actor = UserActor | ServiceActor | ServiceActorV3; +export type Actor = UserActor | ServiceActor | MachineActor; interface GetSecretsEvent { type: EventType.GET_SECRETS; diff --git a/frontend/src/views/Project/AuditLogsPage/components/LogsFilter.tsx b/frontend/src/views/Project/AuditLogsPage/components/LogsFilter.tsx index b48cce4e3..c7f39cd97 100644 --- a/frontend/src/views/Project/AuditLogsPage/components/LogsFilter.tsx +++ b/frontend/src/views/Project/AuditLogsPage/components/LogsFilter.tsx @@ -50,11 +50,11 @@ export const LogsFilter = ({ control, reset }: Props) => { {actor.metadata.name} ); - case ActorType.SERVICE_V3: + case ActorType.MACHINE: return ( {actor.metadata.name} diff --git a/frontend/src/views/Project/AuditLogsPage/components/LogsTableRow.tsx b/frontend/src/views/Project/AuditLogsPage/components/LogsTableRow.tsx index e28e55306..57440f2a5 100644 --- a/frontend/src/views/Project/AuditLogsPage/components/LogsTableRow.tsx +++ b/frontend/src/views/Project/AuditLogsPage/components/LogsTableRow.tsx @@ -29,7 +29,7 @@ export const LogsTableRow = ({

Service token

); - case ActorType.SERVICE_V3: + case ActorType.MACHINE: return (

{`${actor.metadata.name}`}