mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 19:26:07 +00:00
Add no access role, replace ST V3 refs with machine
This commit is contained in:
@@ -25,7 +25,7 @@ declare module "jsonwebtoken" {
|
|||||||
userId: string;
|
userId: string;
|
||||||
refreshVersion?: number;
|
refreshVersion?: number;
|
||||||
}
|
}
|
||||||
export interface ServiceRefreshTokenJwtPayload extends jwt.JwtPayload {
|
export interface MachineRefreshTokenJwtPayload extends jwt.JwtPayload {
|
||||||
serviceTokenDataId: string;
|
serviceTokenDataId: string;
|
||||||
authTokenType: string;
|
authTokenType: string;
|
||||||
tokenVersion: number;
|
tokenVersion: number;
|
||||||
|
|||||||
@@ -99,7 +99,7 @@ const checkSecretsPermission = async ({
|
|||||||
});
|
});
|
||||||
return { authVerifier: () => true };
|
return { authVerifier: () => true };
|
||||||
}
|
}
|
||||||
case ActorType.SERVICE_V3: {
|
case ActorType.MACHINE: {
|
||||||
const { permission } = await getAuthDataProjectPermissions({
|
const { permission } = await getAuthDataProjectPermissions({
|
||||||
authData,
|
authData,
|
||||||
workspaceId: new Types.ObjectId(workspaceId)
|
workspaceId: new Types.ObjectId(workspaceId)
|
||||||
|
|||||||
@@ -17,10 +17,10 @@ import {
|
|||||||
FolderVersion,
|
FolderVersion,
|
||||||
IPType,
|
IPType,
|
||||||
ISecretVersion,
|
ISecretVersion,
|
||||||
|
MachineActor,
|
||||||
SecretSnapshot,
|
SecretSnapshot,
|
||||||
SecretVersion,
|
SecretVersion,
|
||||||
ServiceActor,
|
ServiceActor,
|
||||||
ServiceActorV3,
|
|
||||||
TFolderRootVersionSchema,
|
TFolderRootVersionSchema,
|
||||||
TrustedIP,
|
TrustedIP,
|
||||||
UserActor
|
UserActor
|
||||||
@@ -757,12 +757,12 @@ export const getWorkspaceAuditLogActorFilterOpts = async (req: Request, res: Res
|
|||||||
}
|
}
|
||||||
}));
|
}));
|
||||||
|
|
||||||
const serviceV3Actors: ServiceActorV3[] = (
|
const serviceV3Actors: MachineActor[] = (
|
||||||
await MachineIdentity.find({
|
await MachineIdentity.find({
|
||||||
workspace: new Types.ObjectId(workspaceId)
|
workspace: new Types.ObjectId(workspaceId)
|
||||||
})
|
})
|
||||||
).map((machineIdentity) => ({
|
).map((machineIdentity) => ({
|
||||||
type: ActorType.SERVICE_V3,
|
type: ActorType.MACHINE,
|
||||||
metadata: {
|
metadata: {
|
||||||
serviceId: machineIdentity._id.toString(),
|
serviceId: machineIdentity._id.toString(),
|
||||||
name: machineIdentity.name
|
name: machineIdentity.name
|
||||||
|
|||||||
@@ -44,11 +44,11 @@ import { ForbiddenError } from "@casl/ability";
|
|||||||
}
|
}
|
||||||
} = await validateRequest(reqValidator.RefreshTokenV3, req);
|
} = await validateRequest(reqValidator.RefreshTokenV3, req);
|
||||||
|
|
||||||
const decodedToken = <jwt.ServiceRefreshTokenJwtPayload>(
|
const decodedToken = <jwt.MachineRefreshTokenJwtPayload>(
|
||||||
jwt.verify(refreshToken, await getAuthSecret())
|
jwt.verify(refreshToken, await getAuthSecret())
|
||||||
);
|
);
|
||||||
|
|
||||||
if (decodedToken.authTokenType !== AuthTokenType.SERVICE_REFRESH_TOKEN) throw UnauthorizedRequestError();
|
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_REFRESH_TOKEN) throw UnauthorizedRequestError();
|
||||||
|
|
||||||
let machineIdentity = await MachineIdentity.findOne({
|
let machineIdentity = await MachineIdentity.findOne({
|
||||||
_id: new Types.ObjectId(decodedToken.serviceTokenDataId),
|
_id: new Types.ObjectId(decodedToken.serviceTokenDataId),
|
||||||
@@ -92,7 +92,7 @@ import { ForbiddenError } from "@casl/ability";
|
|||||||
response.refreshToken = createToken({
|
response.refreshToken = createToken({
|
||||||
payload: {
|
payload: {
|
||||||
serviceTokenDataId: machineIdentity._id.toString(),
|
serviceTokenDataId: machineIdentity._id.toString(),
|
||||||
authTokenType: AuthTokenType.SERVICE_REFRESH_TOKEN,
|
authTokenType: AuthTokenType.MACHINE_REFRESH_TOKEN,
|
||||||
tokenVersion: machineIdentity.tokenVersion
|
tokenVersion: machineIdentity.tokenVersion
|
||||||
},
|
},
|
||||||
secret: await getAuthSecret()
|
secret: await getAuthSecret()
|
||||||
@@ -101,8 +101,8 @@ import { ForbiddenError } from "@casl/ability";
|
|||||||
|
|
||||||
response.accessToken = createToken({
|
response.accessToken = createToken({
|
||||||
payload: {
|
payload: {
|
||||||
serviceTokenDataId: machineIdentity._id.toString(), // TODO: fix this
|
_id: machineIdentity._id.toString(), // TODO: fix this
|
||||||
authTokenType: AuthTokenType.SERVICE_ACCESS_TOKEN,
|
authTokenType: AuthTokenType.MACHINE_ACCESS_TOKEN,
|
||||||
tokenVersion: machineIdentity.tokenVersion
|
tokenVersion: machineIdentity.tokenVersion
|
||||||
},
|
},
|
||||||
expiresIn: machineIdentity.accessTokenTTL,
|
expiresIn: machineIdentity.accessTokenTTL,
|
||||||
@@ -226,8 +226,8 @@ export const createMachineIdentity = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const refreshToken = createToken({
|
const refreshToken = createToken({
|
||||||
payload: {
|
payload: {
|
||||||
serviceTokenDataId: machineIdentity._id.toString(), // TODO: update
|
_id: machineIdentity._id.toString(),
|
||||||
authTokenType: AuthTokenType.SERVICE_REFRESH_TOKEN,
|
authTokenType: AuthTokenType.MACHINE_REFRESH_TOKEN,
|
||||||
tokenVersion: machineIdentity.tokenVersion
|
tokenVersion: machineIdentity.tokenVersion
|
||||||
},
|
},
|
||||||
secret: await getAuthSecret()
|
secret: await getAuthSecret()
|
||||||
|
|||||||
@@ -1,8 +1,7 @@
|
|||||||
export enum ActorType {
|
export enum ActorType {
|
||||||
USER = "user",
|
USER = "user",
|
||||||
SERVICE = "service",
|
SERVICE = "service",
|
||||||
SERVICE_V3 = "service-v3",
|
MACHINE = "machine"
|
||||||
// Machine = "machine"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum UserAgentType {
|
export enum UserAgentType {
|
||||||
|
|||||||
@@ -11,6 +11,11 @@ interface ServiceActorMetadata {
|
|||||||
name: string;
|
name: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface MachineActorMetadata {
|
||||||
|
machineId: string;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
|
|
||||||
export interface UserActor {
|
export interface UserActor {
|
||||||
type: ActorType.USER;
|
type: ActorType.USER;
|
||||||
metadata: UserActorMetadata;
|
metadata: UserActorMetadata;
|
||||||
@@ -21,16 +26,16 @@ export interface ServiceActor {
|
|||||||
metadata: ServiceActorMetadata;
|
metadata: ServiceActorMetadata;
|
||||||
}
|
}
|
||||||
|
|
||||||
export interface ServiceActorV3 {
|
export interface MachineActor {
|
||||||
type: ActorType.SERVICE_V3;
|
type: ActorType.MACHINE;
|
||||||
metadata: ServiceActorMetadata;
|
metadata: MachineActorMetadata;
|
||||||
}
|
}
|
||||||
|
|
||||||
// export interface MachineActor {
|
// export interface MachineActor {
|
||||||
// type: ActorType.Machine;
|
// type: ActorType.Machine;
|
||||||
// }
|
// }
|
||||||
|
|
||||||
export type Actor = UserActor | ServiceActor | ServiceActorV3;
|
export type Actor = UserActor | ServiceActor | MachineActor;
|
||||||
|
|
||||||
interface GetSecretsEvent {
|
interface GetSecretsEvent {
|
||||||
type: EventType.GET_SECRETS;
|
type: EventType.GET_SECRETS;
|
||||||
|
|||||||
@@ -310,7 +310,7 @@ export const getAuthDataProjectPermissions = async ({
|
|||||||
role = "viewer";
|
role = "viewer";
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case ActorType.SERVICE_V3: {
|
case ActorType.MACHINE: {
|
||||||
const machineMembership = await MachineMembership.findOne({
|
const machineMembership = await MachineMembership.findOne({
|
||||||
machineIdentity: authData.authPayload._id,
|
machineIdentity: authData.authPayload._id,
|
||||||
workspace: workspaceId
|
workspace: workspaceId
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import { Types } from "mongoose";
|
import { Types } from "mongoose";
|
||||||
import { IMachineIdentity, IServiceTokenData, IUser } from "../../models";
|
import { IMachineIdentity, IServiceTokenData, IUser } from "../../models";
|
||||||
import { ServiceActor, ServiceActorV3, UserActor, UserAgentType } from "../../ee/models";
|
import { MachineActor, ServiceActor, UserActor, UserAgentType } from "../../ee/models";
|
||||||
|
|
||||||
interface BaseAuthData {
|
interface BaseAuthData {
|
||||||
ipAddress: string;
|
ipAddress: string;
|
||||||
@@ -15,7 +15,7 @@ export interface UserAuthData extends BaseAuthData {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export interface MachineIdentityAuthData extends BaseAuthData {
|
export interface MachineIdentityAuthData extends BaseAuthData {
|
||||||
actor: ServiceActorV3;
|
actor: MachineActor;
|
||||||
authPayload: IMachineIdentity;
|
authPayload: IMachineIdentity;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ const requireAuth = ({
|
|||||||
case AuthMode.SERVICE_TOKEN:
|
case AuthMode.SERVICE_TOKEN:
|
||||||
req.serviceTokenData = authData.authPayload;
|
req.serviceTokenData = authData.authPayload;
|
||||||
break;
|
break;
|
||||||
case AuthMode.SERVICE_ACCESS_TOKEN:
|
case AuthMode.MACHINE_ACCESS_TOKEN:
|
||||||
req.serviceTokenData = authData.authPayload;
|
req.serviceTokenData = authData.authPayload;
|
||||||
break;
|
break;
|
||||||
case AuthMode.API_KEY:
|
case AuthMode.API_KEY:
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ import { AuthMode } from "../../variables";
|
|||||||
router.get(
|
router.get(
|
||||||
"/raw",
|
"/raw",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
secretsController.getSecretsRaw
|
secretsController.getSecretsRaw
|
||||||
);
|
);
|
||||||
@@ -15,7 +15,7 @@ router.get(
|
|||||||
router.get(
|
router.get(
|
||||||
"/raw/:secretName",
|
"/raw/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "query"
|
locationWorkspaceId: "query"
|
||||||
@@ -29,7 +29,7 @@ router.get(
|
|||||||
router.post(
|
router.post(
|
||||||
"/raw/:secretName",
|
"/raw/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "body"
|
locationWorkspaceId: "body"
|
||||||
@@ -43,7 +43,7 @@ router.post(
|
|||||||
router.patch(
|
router.patch(
|
||||||
"/raw/:secretName",
|
"/raw/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "body"
|
locationWorkspaceId: "body"
|
||||||
@@ -57,7 +57,7 @@ router.patch(
|
|||||||
router.delete(
|
router.delete(
|
||||||
"/raw/:secretName",
|
"/raw/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "body"
|
locationWorkspaceId: "body"
|
||||||
@@ -71,7 +71,7 @@ router.delete(
|
|||||||
router.get(
|
router.get(
|
||||||
"/",
|
"/",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "query"
|
locationWorkspaceId: "query"
|
||||||
@@ -116,7 +116,7 @@ router.delete(
|
|||||||
router.post(
|
router.post(
|
||||||
"/:secretName",
|
"/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "body"
|
locationWorkspaceId: "body"
|
||||||
@@ -127,7 +127,7 @@ router.post(
|
|||||||
router.get(
|
router.get(
|
||||||
"/:secretName",
|
"/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "query"
|
locationWorkspaceId: "query"
|
||||||
@@ -138,7 +138,7 @@ router.get(
|
|||||||
router.patch(
|
router.patch(
|
||||||
"/:secretName",
|
"/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "body"
|
locationWorkspaceId: "body"
|
||||||
@@ -149,7 +149,7 @@ router.patch(
|
|||||||
router.delete(
|
router.delete(
|
||||||
"/:secretName",
|
"/:secretName",
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.SERVICE_ACCESS_TOKEN]
|
acceptedAuthModes: [AuthMode.JWT, AuthMode.API_KEY, AuthMode.API_KEY_V2, AuthMode.SERVICE_TOKEN, AuthMode.MACHINE_ACCESS_TOKEN]
|
||||||
}),
|
}),
|
||||||
requireBlindIndicesEnabled({
|
requireBlindIndicesEnabled({
|
||||||
locationWorkspaceId: "body"
|
locationWorkspaceId: "body"
|
||||||
|
|||||||
@@ -12,14 +12,14 @@ interface ValidateMachineIdentityParams {
|
|||||||
export const validateMachineIdentity = async ({
|
export const validateMachineIdentity = async ({
|
||||||
authTokenValue
|
authTokenValue
|
||||||
}: ValidateMachineIdentityParams) => {
|
}: ValidateMachineIdentityParams) => {
|
||||||
const decodedToken = <jwt.ServiceRefreshTokenJwtPayload>(
|
const decodedToken = <jwt.MachineRefreshTokenJwtPayload>(
|
||||||
jwt.verify(authTokenValue, await getAuthSecret())
|
jwt.verify(authTokenValue, await getAuthSecret())
|
||||||
);
|
);
|
||||||
|
|
||||||
if (decodedToken.authTokenType !== AuthTokenType.SERVICE_ACCESS_TOKEN) throw UnauthorizedRequestError();
|
if (decodedToken.authTokenType !== AuthTokenType.MACHINE_ACCESS_TOKEN) throw UnauthorizedRequestError();
|
||||||
|
|
||||||
const machineIdentity = await MachineIdentity.findOne({
|
const machineIdentity = await MachineIdentity.findOne({
|
||||||
_id: new Types.ObjectId(decodedToken.serviceTokenDataId),
|
_id: new Types.ObjectId(decodedToken._id),
|
||||||
isActive: true
|
isActive: true
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ interface GetAuthDataParams {
|
|||||||
* - SERVICE_TOKEN
|
* - SERVICE_TOKEN
|
||||||
* - API_KEY
|
* - API_KEY
|
||||||
* - JWT
|
* - JWT
|
||||||
* - SERVICE_ACCESS_TOKEN (from machine identity)
|
* - MACHINE_ACCESS_TOKEN (from machine identity)
|
||||||
* - API_KEY_V2
|
* - API_KEY_V2
|
||||||
* @param {Object} params
|
* @param {Object} params
|
||||||
* @param {Object.<string, (string|string[]|undefined)>} params.headers - The HTTP request headers, usually from Express's `req.headers`.
|
* @param {Object.<string, (string|string[]|undefined)>} params.headers - The HTTP request headers, usually from Express's `req.headers`.
|
||||||
@@ -77,8 +77,8 @@ export const extractAuthMode = async ({
|
|||||||
return { authMode: AuthMode.JWT, authTokenValue };
|
return { authMode: AuthMode.JWT, authTokenValue };
|
||||||
case AuthTokenType.API_KEY:
|
case AuthTokenType.API_KEY:
|
||||||
return { authMode: AuthMode.API_KEY_V2, authTokenValue };
|
return { authMode: AuthMode.API_KEY_V2, authTokenValue };
|
||||||
case AuthTokenType.SERVICE_ACCESS_TOKEN:
|
case AuthTokenType.MACHINE_ACCESS_TOKEN:
|
||||||
return { authMode: AuthMode.SERVICE_ACCESS_TOKEN, authTokenValue };
|
return { authMode: AuthMode.MACHINE_ACCESS_TOKEN, authTokenValue };
|
||||||
default:
|
default:
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: "Failed to authenticate unknown authentication method"
|
message: "Failed to authenticate unknown authentication method"
|
||||||
@@ -115,20 +115,20 @@ export const getAuthData = async ({
|
|||||||
userAgentType
|
userAgentType
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
case AuthMode.SERVICE_ACCESS_TOKEN: {
|
case AuthMode.MACHINE_ACCESS_TOKEN: {
|
||||||
const serviceTokenData = await validateMachineIdentity({
|
const machineIdentity = await validateMachineIdentity({
|
||||||
authTokenValue
|
authTokenValue
|
||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
actor: {
|
actor: {
|
||||||
type: ActorType.SERVICE_V3,
|
type: ActorType.MACHINE,
|
||||||
metadata: {
|
metadata: {
|
||||||
serviceId: serviceTokenData._id.toString(),
|
machineId: machineIdentity._id.toString(),
|
||||||
name: serviceTokenData.name
|
name: machineIdentity.name
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
authPayload: serviceTokenData,
|
authPayload: machineIdentity,
|
||||||
ipAddress,
|
ipAddress,
|
||||||
userAgent,
|
userAgent,
|
||||||
userAgentType
|
userAgentType
|
||||||
|
|||||||
@@ -58,9 +58,9 @@ const validateClientForIntegrationAuth = async ({
|
|||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: "Failed service token authorization for integration authorization"
|
message: "Failed service token authorization for integration authorization"
|
||||||
});
|
});
|
||||||
case ActorType.SERVICE_V3:
|
case ActorType.MACHINE:
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: "Failed service token authorization for integration authorization"
|
message: "Failed machine authorization for integration authorization"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
import { MEMBER } from "../variables";
|
import { NO_ACCESS } from "../variables";
|
||||||
|
|
||||||
export const RefreshTokenV3 = z.object({
|
export const RefreshTokenV3 = z.object({
|
||||||
body: z.object({
|
body: z.object({
|
||||||
@@ -11,8 +11,8 @@ export const CreateMachineIdentityV3 = z.object({
|
|||||||
body: z.object({
|
body: z.object({
|
||||||
name: z.string().trim(),
|
name: z.string().trim(),
|
||||||
organizationId: z.string().trim(),
|
organizationId: z.string().trim(),
|
||||||
role: z.string().trim().min(1).default(MEMBER),
|
role: z.string().trim().min(1).default(NO_ACCESS),
|
||||||
trustedIps: z // TODO: provide default
|
trustedIps: z
|
||||||
.object({
|
.object({
|
||||||
ipAddress: z.string().trim(),
|
ipAddress: z.string().trim(),
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -46,9 +46,9 @@ export const validateClientForOrganization = async ({
|
|||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: "Failed service token authorization for organization"
|
message: "Failed service token authorization for organization"
|
||||||
});
|
});
|
||||||
case ActorType.SERVICE_V3:
|
case ActorType.MACHINE:
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: "Failed service token authorization for organization"
|
message: "Failed machine authorization for organization"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { AuthData } from "../interfaces/middleware";
|
|||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
import { EventType, UserAgentType } from "../ee/models";
|
import { EventType, UserAgentType } from "../ee/models";
|
||||||
import { UnauthorizedRequestError } from "../utils/errors";
|
import { UnauthorizedRequestError } from "../utils/errors";
|
||||||
import { MEMBER } from "../variables";
|
import { NO_ACCESS } from "../variables";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Validate authenticated clients for workspace with id [workspaceId] based
|
* Validate authenticated clients for workspace with id [workspaceId] based
|
||||||
@@ -60,9 +60,9 @@ export const validateClientForWorkspace = async ({
|
|||||||
requiredPermissions
|
requiredPermissions
|
||||||
});
|
});
|
||||||
return { membership, workspace };
|
return { membership, workspace };
|
||||||
case ActorType.SERVICE_V3:
|
case ActorType.MACHINE:
|
||||||
throw UnauthorizedRequestError({
|
throw UnauthorizedRequestError({
|
||||||
message: "Failed service token authorization for organization"
|
message: "Failed machine authorization for organization"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
@@ -286,7 +286,7 @@ export const AddWorkspaceServiceMemberV2 = z.object({
|
|||||||
machineId: z.string().trim()
|
machineId: z.string().trim()
|
||||||
}),
|
}),
|
||||||
body: z.object({
|
body: z.object({
|
||||||
role: z.string().trim().min(1).default(MEMBER),
|
role: z.string().trim().min(1).default(NO_ACCESS),
|
||||||
})
|
})
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -7,14 +7,14 @@ export enum AuthTokenType {
|
|||||||
MFA_TOKEN = "mfaToken", // TODO: remove in favor of claim
|
MFA_TOKEN = "mfaToken", // TODO: remove in favor of claim
|
||||||
PROVIDER_TOKEN = "providerToken", // TODO: remove in favor of claim
|
PROVIDER_TOKEN = "providerToken", // TODO: remove in favor of claim
|
||||||
API_KEY = "apiKey",
|
API_KEY = "apiKey",
|
||||||
SERVICE_ACCESS_TOKEN = "serviceAccessToken",
|
MACHINE_ACCESS_TOKEN = "machineAccessToken",
|
||||||
SERVICE_REFRESH_TOKEN = "serviceRefreshToken"
|
MACHINE_REFRESH_TOKEN = "machineRefreshToken"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum AuthMode {
|
export enum AuthMode {
|
||||||
JWT = "jwt",
|
JWT = "jwt",
|
||||||
SERVICE_TOKEN = "serviceToken",
|
SERVICE_TOKEN = "serviceToken",
|
||||||
SERVICE_ACCESS_TOKEN = "serviceAccessToken",
|
MACHINE_ACCESS_TOKEN = "machineAccessToken",
|
||||||
API_KEY = "apiKey",
|
API_KEY = "apiKey",
|
||||||
API_KEY_V2 = "apiKeyV2"
|
API_KEY_V2 = "apiKeyV2"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
export enum ActorType {
|
export enum ActorType {
|
||||||
USER = "user",
|
USER = "user",
|
||||||
SERVICE = "service",
|
SERVICE = "service",
|
||||||
SERVICE_V3 = "service-v3"
|
MACHINE = "machine"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum UserAgentType {
|
export enum UserAgentType {
|
||||||
|
|||||||
@@ -20,12 +20,12 @@ export interface ServiceActor {
|
|||||||
metadata: ServiceActorMetadata;
|
metadata: ServiceActorMetadata;
|
||||||
}
|
}
|
||||||
|
|
||||||
export interface ServiceActorV3 {
|
export interface MachineActor {
|
||||||
type: ActorType.SERVICE_V3;
|
type: ActorType.MACHINE;
|
||||||
metadata: ServiceActorMetadata;
|
metadata: ServiceActorMetadata;
|
||||||
}
|
}
|
||||||
|
|
||||||
export type Actor = UserActor | ServiceActor | ServiceActorV3;
|
export type Actor = UserActor | ServiceActor | MachineActor;
|
||||||
|
|
||||||
interface GetSecretsEvent {
|
interface GetSecretsEvent {
|
||||||
type: EventType.GET_SECRETS;
|
type: EventType.GET_SECRETS;
|
||||||
|
|||||||
@@ -50,11 +50,11 @@ export const LogsFilter = ({ control, reset }: Props) => {
|
|||||||
{actor.metadata.name}
|
{actor.metadata.name}
|
||||||
</SelectItem>
|
</SelectItem>
|
||||||
);
|
);
|
||||||
case ActorType.SERVICE_V3:
|
case ActorType.MACHINE:
|
||||||
return (
|
return (
|
||||||
<SelectItem
|
<SelectItem
|
||||||
value={`${actor.type}-${actor.metadata.serviceId}`}
|
value={`${actor.type}-${actor.metadata.serviceId}`}
|
||||||
key={`service-actor-v3-filter-${actor.metadata.serviceId}`}
|
key={`machine-filter-${actor.metadata.serviceId}`}
|
||||||
>
|
>
|
||||||
{actor.metadata.name}
|
{actor.metadata.name}
|
||||||
</SelectItem>
|
</SelectItem>
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ export const LogsTableRow = ({
|
|||||||
<p>Service token</p>
|
<p>Service token</p>
|
||||||
</Td>
|
</Td>
|
||||||
);
|
);
|
||||||
case ActorType.SERVICE_V3:
|
case ActorType.MACHINE:
|
||||||
return (
|
return (
|
||||||
<Td>
|
<Td>
|
||||||
<p>{`${actor.metadata.name}`}</p>
|
<p>{`${actor.metadata.name}`}</p>
|
||||||
|
|||||||
Reference in New Issue
Block a user