mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 16:28:11 +00:00
Review fixes
This commit is contained in:
@@ -33,8 +33,8 @@ export const GithubProvider = (): TDynamicProviderFns => {
|
|||||||
|
|
||||||
const nowInSeconds = Math.floor(Date.now() / 1000);
|
const nowInSeconds = Math.floor(Date.now() / 1000);
|
||||||
const jwtPayload = {
|
const jwtPayload = {
|
||||||
iat: nowInSeconds - 60,
|
iat: nowInSeconds - 5,
|
||||||
exp: nowInSeconds + 10 * 60 - 60,
|
exp: nowInSeconds + 60,
|
||||||
iss: String(appId)
|
iss: String(appId)
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -110,9 +110,12 @@ export const GithubProvider = (): TDynamicProviderFns => {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
const revoke = async (_inputs: unknown, entityId: string) => {
|
const revoke = async () => {
|
||||||
// GitHub installation access tokens cannot be revoked.
|
// GitHub installation tokens cannot be revoked.
|
||||||
return { entityId };
|
throw new BadRequestError({
|
||||||
|
message:
|
||||||
|
"Github dynamic secret does not support revocation because GitHub itself cannot revoke installation tokens"
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
const renew = async () => {
|
const renew = async () => {
|
||||||
|
|||||||
@@ -1,23 +1,15 @@
|
|||||||
---
|
---
|
||||||
title: "Github"
|
title: "GitHub"
|
||||||
description: "Learn how to dynamically generate Github app tokens."
|
description: "Learn how to dynamically generate GitHub App tokens."
|
||||||
---
|
---
|
||||||
|
|
||||||
The Infisical Github dynamic secret allows you to generate short-lived tokens for a Github app on demand based on service account permissions.
|
The Infisical GitHub dynamic secret allows you to generate short-lived tokens for a GitHub App on demand based on service account permissions.
|
||||||
|
|
||||||
<Warning>
|
## Setup GitHub App
|
||||||
Github app tokens cannot be revoked. As such, revoking a token on Infisical does not invalidate the Github token; it remains active until it expires.
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
<Warning>
|
|
||||||
Github app tokens are fixed to a TTL of 1 hour.
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
## Setup Github App
|
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Create an application on GitHub">
|
<Step title="Create an application on GitHub">
|
||||||
Navigate to [GitHub app settings](https://github.com/settings/apps) and click **New GitHub App**.
|
Navigate to [GitHub App settings](https://github.com/settings/apps) and click **New GitHub App**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@@ -26,9 +18,9 @@ The Infisical Github dynamic secret allows you to generate short-lived tokens fo
|
|||||||
Disable webhook by unchecking the Active checkbox.
|
Disable webhook by unchecking the Active checkbox.
|
||||||

|

|
||||||
|
|
||||||
Configure the app's permissions to grant the necessary access for the dynamic secret's short-lived tokens.
|
Configure the app's permissions to grant the necessary access for the dynamic secret's short-lived tokens based on your use case.
|
||||||
|
|
||||||
Create the Github application.
|
Create the GitHub Application.
|
||||||

|

|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
@@ -37,7 +29,7 @@ The Infisical Github dynamic secret allows you to generate short-lived tokens fo
|
|||||||
</Note>
|
</Note>
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Save app credentials">
|
<Step title="Save app credentials">
|
||||||
Copy the **App ID** and generate a new **Private Key** for your Github application.
|
Copy the **App ID** and generate a new **Private Key** for your GitHub Application.
|
||||||

|

|
||||||
|
|
||||||
Save these for later steps.
|
Save these for later steps.
|
||||||
@@ -53,7 +45,7 @@ The Infisical Github dynamic secret allows you to generate short-lived tokens fo
|
|||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
## Set up Dynamic Secrets with Github
|
## Set up Dynamic Secrets with GitHub
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Open Secret Overview Dashboard">
|
<Step title="Open Secret Overview Dashboard">
|
||||||
@@ -62,7 +54,7 @@ The Infisical Github dynamic secret allows you to generate short-lived tokens fo
|
|||||||
<Step title="Click on the 'Add Dynamic Secret' button">
|
<Step title="Click on the 'Add Dynamic Secret' button">
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Select 'Github'">
|
<Step title="Select 'GitHub'">
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Provide the inputs for dynamic secret parameters">
|
<Step title="Provide the inputs for dynamic secret parameters">
|
||||||
@@ -110,11 +102,11 @@ This will allow you to see the expiration time of the lease or delete a lease be
|
|||||||

|

|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Github app tokens cannot be revoked. As such, revoking a token on Infisical does not invalidate the Github token; it remains active until it expires.
|
GitHub App tokens cannot be revoked. As such, revoking a token on Infisical does not invalidate the GitHub token; it remains active until it expires.
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
## Renew Leases
|
## Renew Leases
|
||||||
|
|
||||||
<Warning>
|
<Note>
|
||||||
Github app tokens cannot be renewed because they are fixed to a lifetime of 1 hour.
|
GitHub App tokens cannot be renewed because they are fixed to a lifetime of 1 hour.
|
||||||
</Warning>
|
</Note>
|
||||||
|
|||||||
+1
-1
@@ -148,7 +148,7 @@ const DYNAMIC_SECRET_LIST = [
|
|||||||
{
|
{
|
||||||
icon: <FontAwesomeIcon icon={faGithub} size="lg" />,
|
icon: <FontAwesomeIcon icon={faGithub} size="lg" />,
|
||||||
provider: DynamicSecretProviders.Github,
|
provider: DynamicSecretProviders.Github,
|
||||||
title: "Github"
|
title: "GitHub"
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user