mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 20:26:44 +00:00
Finish preliminary AWS IAM Auth method
This commit is contained in:
@@ -1,5 +1,6 @@
|
|||||||
import { IdentityAuthMethod } from "./enums";
|
import { IdentityAuthMethod } from "./enums";
|
||||||
|
|
||||||
export const identityAuthToNameMap: { [I in IdentityAuthMethod]: string } = {
|
export const identityAuthToNameMap: { [I in IdentityAuthMethod]: string } = {
|
||||||
[IdentityAuthMethod.UNIVERSAL_AUTH]: "Universal Auth"
|
[IdentityAuthMethod.UNIVERSAL_AUTH]: "Universal Auth",
|
||||||
|
[IdentityAuthMethod.AWS_IAM_AUTH]: "AWS IAM Auth"
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
export enum IdentityAuthMethod {
|
export enum IdentityAuthMethod {
|
||||||
UNIVERSAL_AUTH = "universal-auth"
|
UNIVERSAL_AUTH = "universal-auth",
|
||||||
|
AWS_IAM_AUTH = "aws-iam-auth"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,12 +1,16 @@
|
|||||||
export { identityAuthToNameMap } from "./constants";
|
export { identityAuthToNameMap } from "./constants";
|
||||||
export { IdentityAuthMethod } from "./enums";
|
export { IdentityAuthMethod } from "./enums";
|
||||||
export {
|
export {
|
||||||
|
useAddIdentityAwsIamAuth,
|
||||||
useAddIdentityUniversalAuth,
|
useAddIdentityUniversalAuth,
|
||||||
useCreateIdentity,
|
useCreateIdentity,
|
||||||
useCreateIdentityUniversalAuthClientSecret,
|
useCreateIdentityUniversalAuthClientSecret,
|
||||||
useDeleteIdentity,
|
useDeleteIdentity,
|
||||||
useRevokeIdentityUniversalAuthClientSecret,
|
useRevokeIdentityUniversalAuthClientSecret,
|
||||||
useUpdateIdentity,
|
useUpdateIdentity,
|
||||||
useUpdateIdentityUniversalAuth
|
useUpdateIdentityAwsIamAuth,
|
||||||
} from "./mutations";
|
useUpdateIdentityUniversalAuth} from "./mutations";
|
||||||
export { useGetIdentityUniversalAuth, useGetIdentityUniversalAuthClientSecrets } from "./queries";
|
export {
|
||||||
|
useGetIdentityAwsIamAuth,
|
||||||
|
useGetIdentityUniversalAuth,
|
||||||
|
useGetIdentityUniversalAuthClientSecrets} from "./queries";
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import { apiRequest } from "@app/config/request";
|
|||||||
import { organizationKeys } from "../organization/queries";
|
import { organizationKeys } from "../organization/queries";
|
||||||
import { identitiesKeys } from "./queries";
|
import { identitiesKeys } from "./queries";
|
||||||
import {
|
import {
|
||||||
|
AddIdentityAwsIamAuthDTO,
|
||||||
AddIdentityUniversalAuthDTO,
|
AddIdentityUniversalAuthDTO,
|
||||||
ClientSecretData,
|
ClientSecretData,
|
||||||
CreateIdentityDTO,
|
CreateIdentityDTO,
|
||||||
@@ -13,10 +14,11 @@ import {
|
|||||||
DeleteIdentityDTO,
|
DeleteIdentityDTO,
|
||||||
DeleteIdentityUniversalAuthClientSecretDTO,
|
DeleteIdentityUniversalAuthClientSecretDTO,
|
||||||
Identity,
|
Identity,
|
||||||
|
IdentityAwsIamAuth,
|
||||||
IdentityUniversalAuth,
|
IdentityUniversalAuth,
|
||||||
|
UpdateIdentityAwsIamAuthDTO,
|
||||||
UpdateIdentityDTO,
|
UpdateIdentityDTO,
|
||||||
UpdateIdentityUniversalAuthDTO
|
UpdateIdentityUniversalAuthDTO} from "./types";
|
||||||
} from "./types";
|
|
||||||
|
|
||||||
export const useCreateIdentity = () => {
|
export const useCreateIdentity = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
@@ -169,3 +171,74 @@ export const useRevokeIdentityUniversalAuthClientSecret = () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export const useAddIdentityAwsIamAuth = () => {
|
||||||
|
const queryClient = useQueryClient();
|
||||||
|
return useMutation<IdentityAwsIamAuth, {}, AddIdentityAwsIamAuthDTO>({
|
||||||
|
mutationFn: async ({
|
||||||
|
identityId,
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps
|
||||||
|
}) => {
|
||||||
|
const {
|
||||||
|
data: { identityAwsIamAuth }
|
||||||
|
} = await apiRequest.post<{ identityAwsIamAuth: IdentityAwsIamAuth }>(
|
||||||
|
`/api/v1/auth/aws-iam-auth/identities/${identityId}`,
|
||||||
|
{
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return identityAwsIamAuth;
|
||||||
|
},
|
||||||
|
onSuccess: (_, { organizationId }) => {
|
||||||
|
queryClient.invalidateQueries(organizationKeys.getOrgIdentityMemberships(organizationId));
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
|
export const useUpdateIdentityAwsIamAuth = () => {
|
||||||
|
const queryClient = useQueryClient();
|
||||||
|
return useMutation<IdentityAwsIamAuth, {}, UpdateIdentityAwsIamAuthDTO>({
|
||||||
|
mutationFn: async ({
|
||||||
|
identityId,
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps
|
||||||
|
}) => {
|
||||||
|
const {
|
||||||
|
data: { identityAwsIamAuth }
|
||||||
|
} = await apiRequest.patch<{ identityAwsIamAuth: IdentityAwsIamAuth }>(
|
||||||
|
`/api/v1/auth/aws-iam-auth/identities/${identityId}`,
|
||||||
|
{
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps
|
||||||
|
}
|
||||||
|
);
|
||||||
|
return identityAwsIamAuth;
|
||||||
|
},
|
||||||
|
onSuccess: (_, { organizationId }) => {
|
||||||
|
queryClient.invalidateQueries(organizationKeys.getOrgIdentityMemberships(organizationId));
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|||||||
@@ -2,27 +2,26 @@ import { useQuery } from "@tanstack/react-query";
|
|||||||
|
|
||||||
import { apiRequest } from "@app/config/request";
|
import { apiRequest } from "@app/config/request";
|
||||||
|
|
||||||
import { ClientSecretData, IdentityUniversalAuth } from "./types";
|
import { ClientSecretData, IdentityAwsIamAuth,IdentityUniversalAuth } from "./types";
|
||||||
|
|
||||||
export const identitiesKeys = {
|
export const identitiesKeys = {
|
||||||
getIdentityUniversalAuth: (identityId: string) =>
|
getIdentityUniversalAuth: (identityId: string) =>
|
||||||
[{ identityId }, "identity-universal-auth"] as const,
|
[{ identityId }, "identity-universal-auth"] as const,
|
||||||
getIdentityUniversalAuthClientSecrets: (identityId: string) =>
|
getIdentityUniversalAuthClientSecrets: (identityId: string) =>
|
||||||
[{ identityId }, "identity-universal-auth-client-secrets"] as const
|
[{ identityId }, "identity-universal-auth-client-secrets"] as const,
|
||||||
|
getIdentityAwsIamAuth: (identityId: string) => [{ identityId }, "identity-aws-iam-auth"] as const
|
||||||
};
|
};
|
||||||
|
|
||||||
export const useGetIdentityUniversalAuth = (identityId: string) => {
|
export const useGetIdentityUniversalAuth = (identityId: string) => {
|
||||||
return useQuery({
|
return useQuery({
|
||||||
|
enabled: Boolean(identityId),
|
||||||
queryKey: identitiesKeys.getIdentityUniversalAuth(identityId),
|
queryKey: identitiesKeys.getIdentityUniversalAuth(identityId),
|
||||||
queryFn: async () => {
|
queryFn: async () => {
|
||||||
if (identityId === "") throw new Error("Identity ID is required");
|
|
||||||
|
|
||||||
const {
|
const {
|
||||||
data: { identityUniversalAuth }
|
data: { identityUniversalAuth }
|
||||||
} = await apiRequest.get<{ identityUniversalAuth: IdentityUniversalAuth }>(
|
} = await apiRequest.get<{ identityUniversalAuth: IdentityUniversalAuth }>(
|
||||||
`/api/v1/auth/universal-auth/identities/${identityId}`
|
`/api/v1/auth/universal-auth/identities/${identityId}`
|
||||||
);
|
);
|
||||||
|
|
||||||
return identityUniversalAuth;
|
return identityUniversalAuth;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -30,17 +29,30 @@ export const useGetIdentityUniversalAuth = (identityId: string) => {
|
|||||||
|
|
||||||
export const useGetIdentityUniversalAuthClientSecrets = (identityId: string) => {
|
export const useGetIdentityUniversalAuthClientSecrets = (identityId: string) => {
|
||||||
return useQuery({
|
return useQuery({
|
||||||
|
enabled: Boolean(identityId),
|
||||||
queryKey: identitiesKeys.getIdentityUniversalAuthClientSecrets(identityId),
|
queryKey: identitiesKeys.getIdentityUniversalAuthClientSecrets(identityId),
|
||||||
queryFn: async () => {
|
queryFn: async () => {
|
||||||
if (identityId === "") return [];
|
|
||||||
|
|
||||||
const {
|
const {
|
||||||
data: { clientSecretData }
|
data: { clientSecretData }
|
||||||
} = await apiRequest.get<{ clientSecretData: ClientSecretData[] }>(
|
} = await apiRequest.get<{ clientSecretData: ClientSecretData[] }>(
|
||||||
`/api/v1/auth/universal-auth/identities/${identityId}/client-secrets`
|
`/api/v1/auth/universal-auth/identities/${identityId}/client-secrets`
|
||||||
);
|
);
|
||||||
|
|
||||||
return clientSecretData;
|
return clientSecretData;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export const useGetIdentityAwsIamAuth = (identityId: string) => {
|
||||||
|
return useQuery({
|
||||||
|
enabled: Boolean(identityId),
|
||||||
|
queryKey: identitiesKeys.getIdentityAwsIamAuth(identityId),
|
||||||
|
queryFn: async () => {
|
||||||
|
const {
|
||||||
|
data: { identityAwsIamAuth }
|
||||||
|
} = await apiRequest.get<{ identityAwsIamAuth: IdentityAwsIamAuth }>(
|
||||||
|
`/api/v1/auth/aws-iam-auth/identities/${identityId}`
|
||||||
|
);
|
||||||
|
return identityAwsIamAuth;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|||||||
@@ -38,19 +38,19 @@ export type IdentityMembership = {
|
|||||||
customRoleSlug: string;
|
customRoleSlug: string;
|
||||||
} & (
|
} & (
|
||||||
| {
|
| {
|
||||||
isTemporary: false;
|
isTemporary: false;
|
||||||
temporaryRange: null;
|
temporaryRange: null;
|
||||||
temporaryMode: null;
|
temporaryMode: null;
|
||||||
temporaryAccessEndTime: null;
|
temporaryAccessEndTime: null;
|
||||||
temporaryAccessStartTime: null;
|
temporaryAccessStartTime: null;
|
||||||
}
|
}
|
||||||
| {
|
| {
|
||||||
isTemporary: true;
|
isTemporary: true;
|
||||||
temporaryRange: string;
|
temporaryRange: string;
|
||||||
temporaryMode: string;
|
temporaryMode: string;
|
||||||
temporaryAccessEndTime: string;
|
temporaryAccessEndTime: string;
|
||||||
temporaryAccessStartTime: string;
|
temporaryAccessStartTime: string;
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
>;
|
>;
|
||||||
createdAt: string;
|
createdAt: string;
|
||||||
@@ -113,6 +113,45 @@ export type UpdateIdentityUniversalAuthDTO = {
|
|||||||
}[];
|
}[];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export type IdentityAwsIamAuth = {
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint: string;
|
||||||
|
allowedPrincipalArns: string;
|
||||||
|
allowedAccountIds: string;
|
||||||
|
accessTokenTTL: number;
|
||||||
|
accessTokenMaxTTL: number;
|
||||||
|
accessTokenNumUsesLimit: number;
|
||||||
|
accessTokenTrustedIps: IdentityTrustedIp[];
|
||||||
|
};
|
||||||
|
|
||||||
|
export type AddIdentityAwsIamAuthDTO = {
|
||||||
|
organizationId: string;
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint: string;
|
||||||
|
allowedPrincipalArns: string;
|
||||||
|
allowedAccountIds: string;
|
||||||
|
accessTokenTTL: number;
|
||||||
|
accessTokenMaxTTL: number;
|
||||||
|
accessTokenNumUsesLimit: number;
|
||||||
|
accessTokenTrustedIps: {
|
||||||
|
ipAddress: string;
|
||||||
|
}[];
|
||||||
|
};
|
||||||
|
|
||||||
|
export type UpdateIdentityAwsIamAuthDTO = {
|
||||||
|
organizationId: string;
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint?: string;
|
||||||
|
allowedPrincipalArns?: string;
|
||||||
|
allowedAccountIds?: string;
|
||||||
|
accessTokenTTL?: number;
|
||||||
|
accessTokenMaxTTL?: number;
|
||||||
|
accessTokenNumUsesLimit?: number;
|
||||||
|
accessTokenTrustedIps?: {
|
||||||
|
ipAddress: string;
|
||||||
|
}[];
|
||||||
|
};
|
||||||
|
|
||||||
export type CreateIdentityUniversalAuthClientSecretDTO = {
|
export type CreateIdentityUniversalAuthClientSecretDTO = {
|
||||||
identityId: string;
|
identityId: string;
|
||||||
description?: string;
|
description?: string;
|
||||||
|
|||||||
+46
-15
@@ -1,3 +1,4 @@
|
|||||||
|
import { useEffect } from "react";
|
||||||
import { Controller, useForm } from "react-hook-form";
|
import { Controller, useForm } from "react-hook-form";
|
||||||
import { yupResolver } from "@hookform/resolvers/yup";
|
import { yupResolver } from "@hookform/resolvers/yup";
|
||||||
import * as yup from "yup";
|
import * as yup from "yup";
|
||||||
@@ -13,6 +14,7 @@ import {
|
|||||||
import { IdentityAuthMethod } from "@app/hooks/api/identities";
|
import { IdentityAuthMethod } from "@app/hooks/api/identities";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
|
import { IdentityAwsIamAuthForm } from "./IdentityAwsIamAuthForm";
|
||||||
import { IdentityUniversalAuthForm } from "./IdentityUniversalAuthForm";
|
import { IdentityUniversalAuthForm } from "./IdentityUniversalAuthForm";
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
@@ -24,22 +26,25 @@ type Props = {
|
|||||||
) => void;
|
) => void;
|
||||||
};
|
};
|
||||||
|
|
||||||
const identityAuthMethods = [{ label: "Universal Auth", value: IdentityAuthMethod.UNIVERSAL_AUTH }];
|
const identityAuthMethods = [
|
||||||
|
{ label: "Universal Auth", value: IdentityAuthMethod.UNIVERSAL_AUTH },
|
||||||
|
{ label: "AWS IAM Auth", value: IdentityAuthMethod.AWS_IAM_AUTH }
|
||||||
|
];
|
||||||
|
|
||||||
const schema = yup
|
const schema = yup
|
||||||
.object({
|
.object({
|
||||||
authMethod: yup.string().required("Auth method is required") // TODO: better enforcement here
|
authMethod: yup.string().required("Auth method is required")
|
||||||
})
|
})
|
||||||
.required();
|
.required();
|
||||||
|
|
||||||
export type FormData = yup.InferType<typeof schema>;
|
export type FormData = yup.InferType<typeof schema>;
|
||||||
|
|
||||||
export const IdentityAuthMethodModal = ({ popUp, handlePopUpOpen, handlePopUpToggle }: Props) => {
|
export const IdentityAuthMethodModal = ({ popUp, handlePopUpOpen, handlePopUpToggle }: Props) => {
|
||||||
const {
|
const { control, watch, setValue } = useForm<FormData>({
|
||||||
control
|
resolver: yupResolver(schema),
|
||||||
// watch,
|
defaultValues: {
|
||||||
} = useForm<FormData>({
|
authMethod: IdentityAuthMethod.UNIVERSAL_AUTH
|
||||||
resolver: yupResolver(schema)
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
const identityAuthMethodData = popUp?.identityAuthMethod?.data as {
|
const identityAuthMethodData = popUp?.identityAuthMethod?.data as {
|
||||||
@@ -48,16 +53,41 @@ export const IdentityAuthMethodModal = ({ popUp, handlePopUpOpen, handlePopUpTog
|
|||||||
authMethod?: IdentityAuthMethod;
|
authMethod?: IdentityAuthMethod;
|
||||||
};
|
};
|
||||||
|
|
||||||
// const authMethod = watch("authMethod");
|
useEffect(() => {
|
||||||
|
if (identityAuthMethodData?.authMethod) {
|
||||||
|
setValue("authMethod", identityAuthMethodData.authMethod);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
setValue("authMethod", IdentityAuthMethod.UNIVERSAL_AUTH);
|
||||||
|
}, [identityAuthMethodData?.authMethod]);
|
||||||
|
|
||||||
|
const authMethod = watch("authMethod");
|
||||||
|
|
||||||
const renderIdentityAuthForm = () => {
|
const renderIdentityAuthForm = () => {
|
||||||
return (
|
switch (identityAuthMethodData?.authMethod ?? authMethod) {
|
||||||
<IdentityUniversalAuthForm
|
case IdentityAuthMethod.AWS_IAM_AUTH: {
|
||||||
handlePopUpOpen={handlePopUpOpen}
|
return (
|
||||||
handlePopUpToggle={handlePopUpToggle}
|
<IdentityAwsIamAuthForm
|
||||||
identityAuthMethodData={identityAuthMethodData}
|
handlePopUpOpen={handlePopUpOpen}
|
||||||
/>
|
handlePopUpToggle={handlePopUpToggle}
|
||||||
);
|
identityAuthMethodData={identityAuthMethodData}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
case IdentityAuthMethod.UNIVERSAL_AUTH: {
|
||||||
|
return (
|
||||||
|
<IdentityUniversalAuthForm
|
||||||
|
handlePopUpOpen={handlePopUpOpen}
|
||||||
|
handlePopUpToggle={handlePopUpToggle}
|
||||||
|
identityAuthMethodData={identityAuthMethodData}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
default: {
|
||||||
|
return <div />;
|
||||||
|
}
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
@@ -83,6 +113,7 @@ export const IdentityAuthMethodModal = ({ popUp, handlePopUpOpen, handlePopUpTog
|
|||||||
{...field}
|
{...field}
|
||||||
onValueChange={(e) => onChange(e)}
|
onValueChange={(e) => onChange(e)}
|
||||||
className="w-full"
|
className="w-full"
|
||||||
|
isDisabled={!!identityAuthMethodData?.authMethod}
|
||||||
>
|
>
|
||||||
{identityAuthMethods.map(({ label, value }) => (
|
{identityAuthMethods.map(({ label, value }) => (
|
||||||
<SelectItem value={String(value || "")} key={label}>
|
<SelectItem value={String(value || "")} key={label}>
|
||||||
|
|||||||
+348
@@ -0,0 +1,348 @@
|
|||||||
|
import { useEffect } from "react";
|
||||||
|
import { Controller, useFieldArray, useForm } from "react-hook-form";
|
||||||
|
import { faPlus, faXmark } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { yupResolver } from "@hookform/resolvers/yup";
|
||||||
|
import * as yup from "yup";
|
||||||
|
|
||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { Button, FormControl, IconButton, Input } from "@app/components/v2";
|
||||||
|
import { useOrganization, useSubscription } from "@app/context";
|
||||||
|
import {
|
||||||
|
useAddIdentityAwsIamAuth,
|
||||||
|
useGetIdentityAwsIamAuth,
|
||||||
|
useUpdateIdentityAwsIamAuth
|
||||||
|
} from "@app/hooks/api";
|
||||||
|
import { IdentityAuthMethod } from "@app/hooks/api/identities";
|
||||||
|
import { IdentityTrustedIp } from "@app/hooks/api/identities/types";
|
||||||
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
|
const schema = yup
|
||||||
|
.object({
|
||||||
|
stsEndpoint: yup.string(),
|
||||||
|
allowedPrincipalArns: yup.string(),
|
||||||
|
allowedAccountIds: yup.string(),
|
||||||
|
accessTokenTTL: yup.string().required("Access Token TTL is required"),
|
||||||
|
accessTokenMaxTTL: yup.string().required("Access Max Token TTL is required"),
|
||||||
|
accessTokenNumUsesLimit: yup.string().required("Access Token Max Number of Uses is required"),
|
||||||
|
accessTokenTrustedIps: yup
|
||||||
|
.array(
|
||||||
|
yup.object({
|
||||||
|
ipAddress: yup.string().max(50).required().label("IP Address")
|
||||||
|
})
|
||||||
|
)
|
||||||
|
.min(1)
|
||||||
|
.required()
|
||||||
|
.label("Access Token Trusted IP")
|
||||||
|
})
|
||||||
|
.required();
|
||||||
|
|
||||||
|
export type FormData = yup.InferType<typeof schema>;
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
handlePopUpOpen: (popUpName: keyof UsePopUpState<["upgradePlan"]>) => void;
|
||||||
|
handlePopUpToggle: (
|
||||||
|
popUpName: keyof UsePopUpState<["identityAuthMethod"]>,
|
||||||
|
state?: boolean
|
||||||
|
) => void;
|
||||||
|
identityAuthMethodData: {
|
||||||
|
identityId: string;
|
||||||
|
name: string;
|
||||||
|
authMethod?: IdentityAuthMethod;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
export const IdentityAwsIamAuthForm = ({
|
||||||
|
handlePopUpOpen,
|
||||||
|
handlePopUpToggle,
|
||||||
|
identityAuthMethodData
|
||||||
|
}: Props) => {
|
||||||
|
const { currentOrg } = useOrganization();
|
||||||
|
const orgId = currentOrg?.id || "";
|
||||||
|
const { subscription } = useSubscription();
|
||||||
|
|
||||||
|
const { mutateAsync: addMutateAsync } = useAddIdentityAwsIamAuth();
|
||||||
|
const { mutateAsync: updateMutateAsync } = useUpdateIdentityAwsIamAuth();
|
||||||
|
|
||||||
|
const { data } = useGetIdentityAwsIamAuth(identityAuthMethodData?.identityId ?? "");
|
||||||
|
|
||||||
|
const {
|
||||||
|
control,
|
||||||
|
handleSubmit,
|
||||||
|
reset,
|
||||||
|
formState: { isSubmitting }
|
||||||
|
} = useForm<FormData>({
|
||||||
|
resolver: yupResolver(schema),
|
||||||
|
defaultValues: {
|
||||||
|
stsEndpoint: "https://sts.amazonaws.com/",
|
||||||
|
allowedPrincipalArns: "",
|
||||||
|
allowedAccountIds: "",
|
||||||
|
accessTokenTTL: "2592000",
|
||||||
|
accessTokenMaxTTL: "2592000",
|
||||||
|
accessTokenNumUsesLimit: "0",
|
||||||
|
accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
const {
|
||||||
|
fields: accessTokenTrustedIpsFields,
|
||||||
|
append: appendAccessTokenTrustedIp,
|
||||||
|
remove: removeAccessTokenTrustedIp
|
||||||
|
} = useFieldArray({ control, name: "accessTokenTrustedIps" });
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (data) {
|
||||||
|
reset({
|
||||||
|
stsEndpoint: data.stsEndpoint,
|
||||||
|
allowedPrincipalArns: data.allowedPrincipalArns,
|
||||||
|
allowedAccountIds: data.allowedAccountIds,
|
||||||
|
accessTokenTTL: String(data.accessTokenTTL),
|
||||||
|
accessTokenMaxTTL: String(data.accessTokenMaxTTL),
|
||||||
|
accessTokenNumUsesLimit: String(data.accessTokenNumUsesLimit),
|
||||||
|
accessTokenTrustedIps: data.accessTokenTrustedIps.map(
|
||||||
|
({ ipAddress, prefix }: IdentityTrustedIp) => {
|
||||||
|
return {
|
||||||
|
ipAddress: `${ipAddress}${prefix !== undefined ? `/${prefix}` : ""}`
|
||||||
|
};
|
||||||
|
}
|
||||||
|
)
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
reset({
|
||||||
|
stsEndpoint: "https://sts.amazonaws.com/",
|
||||||
|
allowedPrincipalArns: "",
|
||||||
|
allowedAccountIds: "",
|
||||||
|
accessTokenTTL: "2592000",
|
||||||
|
accessTokenMaxTTL: "2592000",
|
||||||
|
accessTokenNumUsesLimit: "0",
|
||||||
|
accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}, [data]);
|
||||||
|
|
||||||
|
const onFormSubmit = async ({
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
stsEndpoint,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps
|
||||||
|
}: FormData) => {
|
||||||
|
try {
|
||||||
|
if (!identityAuthMethodData) return;
|
||||||
|
|
||||||
|
if (data) {
|
||||||
|
await updateMutateAsync({
|
||||||
|
organizationId: orgId,
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
identityId: identityAuthMethodData.identityId,
|
||||||
|
accessTokenTTL: Number(accessTokenTTL),
|
||||||
|
accessTokenMaxTTL: Number(accessTokenMaxTTL),
|
||||||
|
accessTokenNumUsesLimit: Number(accessTokenNumUsesLimit),
|
||||||
|
accessTokenTrustedIps
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
await addMutateAsync({
|
||||||
|
organizationId: orgId,
|
||||||
|
identityId: identityAuthMethodData.identityId,
|
||||||
|
stsEndpoint: stsEndpoint || "",
|
||||||
|
allowedPrincipalArns: allowedPrincipalArns || "",
|
||||||
|
allowedAccountIds: allowedAccountIds || "",
|
||||||
|
accessTokenTTL: Number(accessTokenTTL),
|
||||||
|
accessTokenMaxTTL: Number(accessTokenMaxTTL),
|
||||||
|
accessTokenNumUsesLimit: Number(accessTokenNumUsesLimit),
|
||||||
|
accessTokenTrustedIps
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
handlePopUpToggle("identityAuthMethod", false);
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text: `Successfully ${
|
||||||
|
identityAuthMethodData?.authMethod ? "updated" : "configured"
|
||||||
|
} auth method`,
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
|
||||||
|
reset();
|
||||||
|
} catch (err) {
|
||||||
|
createNotification({
|
||||||
|
text: `Failed to ${identityAuthMethodData?.authMethod ? "update" : "configure"} identity`,
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return (
|
||||||
|
<form onSubmit={handleSubmit(onFormSubmit)}>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="2592000"
|
||||||
|
name="allowedPrincipalArns"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl label="Allowed ARNs" isError={Boolean(error)} errorText={error?.message}>
|
||||||
|
<Input
|
||||||
|
{...field}
|
||||||
|
placeholder="arn:aws:iam::123456789012:role/MyRoleName, arn:aws:iam::123456789012:user/MyUserName..."
|
||||||
|
type="text"
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="allowedAccountIds"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Allowed Account IDs"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="123456789012, ..." />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="https://sts.amazonaws.com/"
|
||||||
|
name="stsEndpoint"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl label="STS Endpoint" isError={Boolean(error)} errorText={error?.message}>
|
||||||
|
<Input {...field} placeholder="https://sts.amazonaws.com/" type="text" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="2592000"
|
||||||
|
name="accessTokenTTL"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token TTL (seconds)"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="2592000" type="number" min="1" step="1" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="2592000"
|
||||||
|
name="accessTokenMaxTTL"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token Max TTL (seconds)"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="2592000" type="number" min="1" step="1" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue="0"
|
||||||
|
name="accessTokenNumUsesLimit"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token Max Number of Uses"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="0" type="number" min="0" step="1" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
{accessTokenTrustedIpsFields.map(({ id }, index) => (
|
||||||
|
<div className="mb-3 flex items-end space-x-2" key={id}>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name={`accessTokenTrustedIps.${index}.ipAddress`}
|
||||||
|
defaultValue="0.0.0.0/0"
|
||||||
|
render={({ field, fieldState: { error } }) => {
|
||||||
|
return (
|
||||||
|
<FormControl
|
||||||
|
className="mb-0 flex-grow"
|
||||||
|
label={index === 0 ? "Access Token Trusted IPs" : undefined}
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input
|
||||||
|
value={field.value}
|
||||||
|
onChange={(e) => {
|
||||||
|
if (subscription?.ipAllowlisting) {
|
||||||
|
field.onChange(e);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
}}
|
||||||
|
placeholder="123.456.789.0"
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
);
|
||||||
|
}}
|
||||||
|
/>
|
||||||
|
<IconButton
|
||||||
|
onClick={() => {
|
||||||
|
if (subscription?.ipAllowlisting) {
|
||||||
|
removeAccessTokenTrustedIp(index);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
}}
|
||||||
|
size="lg"
|
||||||
|
colorSchema="danger"
|
||||||
|
variant="plain"
|
||||||
|
ariaLabel="update"
|
||||||
|
className="p-3"
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={faXmark} />
|
||||||
|
</IconButton>
|
||||||
|
</div>
|
||||||
|
))}
|
||||||
|
<div className="my-4 ml-1">
|
||||||
|
<Button
|
||||||
|
variant="outline_bg"
|
||||||
|
onClick={() => {
|
||||||
|
if (subscription?.ipAllowlisting) {
|
||||||
|
appendAccessTokenTrustedIp({
|
||||||
|
ipAddress: "0.0.0.0/0"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
}}
|
||||||
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
|
size="xs"
|
||||||
|
>
|
||||||
|
Add IP Address
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
<div className="flex items-center">
|
||||||
|
<Button
|
||||||
|
className="mr-4"
|
||||||
|
size="sm"
|
||||||
|
type="submit"
|
||||||
|
isLoading={isSubmitting}
|
||||||
|
isDisabled={isSubmitting}
|
||||||
|
>
|
||||||
|
{identityAuthMethodData?.authMethod ? "Update" : "Configure"}
|
||||||
|
</Button>
|
||||||
|
<Button
|
||||||
|
colorSchema="secondary"
|
||||||
|
variant="plain"
|
||||||
|
onClick={() => handlePopUpToggle("identityAuthMethod", false)}
|
||||||
|
>
|
||||||
|
{identityAuthMethodData?.authMethod ? "Cancel" : "Skip"}
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
);
|
||||||
|
};
|
||||||
+23
-22
@@ -15,7 +15,10 @@ import {
|
|||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { useOrganization } from "@app/context";
|
import { useOrganization } from "@app/context";
|
||||||
import { useCreateIdentity, useGetOrgRoles, useUpdateIdentity } from "@app/hooks/api";
|
import { useCreateIdentity, useGetOrgRoles, useUpdateIdentity } from "@app/hooks/api";
|
||||||
import { IdentityAuthMethod, useAddIdentityUniversalAuth } from "@app/hooks/api/identities";
|
import {
|
||||||
|
IdentityAuthMethod
|
||||||
|
// useAddIdentityUniversalAuth
|
||||||
|
} from "@app/hooks/api/identities";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
const schema = yup
|
const schema = yup
|
||||||
@@ -40,9 +43,7 @@ type Props = {
|
|||||||
handlePopUpToggle: (popUpName: keyof UsePopUpState<["identity"]>, state?: boolean) => void;
|
handlePopUpToggle: (popUpName: keyof UsePopUpState<["identity"]>, state?: boolean) => void;
|
||||||
};
|
};
|
||||||
|
|
||||||
export const IdentityModal = ({ popUp, /* handlePopUpOpen, */ handlePopUpToggle }: Props) => {
|
export const IdentityModal = ({ popUp, handlePopUpOpen, handlePopUpToggle }: Props) => {
|
||||||
|
|
||||||
|
|
||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
|
|
||||||
@@ -50,7 +51,7 @@ export const IdentityModal = ({ popUp, /* handlePopUpOpen, */ handlePopUpToggle
|
|||||||
|
|
||||||
const { mutateAsync: createMutateAsync } = useCreateIdentity();
|
const { mutateAsync: createMutateAsync } = useCreateIdentity();
|
||||||
const { mutateAsync: updateMutateAsync } = useUpdateIdentity();
|
const { mutateAsync: updateMutateAsync } = useUpdateIdentity();
|
||||||
const { mutateAsync: addMutateAsync } = useAddIdentityUniversalAuth();
|
// const { mutateAsync: addMutateAsync } = useAddIdentityUniversalAuth();
|
||||||
|
|
||||||
const {
|
const {
|
||||||
control,
|
control,
|
||||||
@@ -113,31 +114,31 @@ export const IdentityModal = ({ popUp, /* handlePopUpOpen, */ handlePopUpToggle
|
|||||||
// create
|
// create
|
||||||
|
|
||||||
const {
|
const {
|
||||||
id: createdId
|
id: createdId,
|
||||||
// name: createdName,
|
name: createdName,
|
||||||
// authMethod
|
authMethod
|
||||||
} = await createMutateAsync({
|
} = await createMutateAsync({
|
||||||
name,
|
name,
|
||||||
role: role || undefined,
|
role: role || undefined,
|
||||||
organizationId: orgId
|
organizationId: orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
await addMutateAsync({
|
// await addMutateAsync({
|
||||||
organizationId: orgId,
|
// organizationId: orgId,
|
||||||
identityId: createdId,
|
// identityId: createdId,
|
||||||
clientSecretTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }],
|
// clientSecretTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }],
|
||||||
accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }],
|
// accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }],
|
||||||
accessTokenTTL: 2592000,
|
// accessTokenTTL: 2592000,
|
||||||
accessTokenMaxTTL: 2592000,
|
// accessTokenMaxTTL: 2592000,
|
||||||
accessTokenNumUsesLimit: 0
|
// accessTokenNumUsesLimit: 0
|
||||||
});
|
// });
|
||||||
|
|
||||||
handlePopUpToggle("identity", false);
|
handlePopUpToggle("identity", false);
|
||||||
// handlePopUpOpen("identityAuthMethod", {
|
handlePopUpOpen("identityAuthMethod", {
|
||||||
// identityId: createdId,
|
identityId: createdId,
|
||||||
// name: createdName,
|
name: createdName,
|
||||||
// authMethod
|
authMethod
|
||||||
// });
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
createNotification({
|
createNotification({
|
||||||
|
|||||||
-3
@@ -23,8 +23,6 @@ import { useGetIdentityMembershipOrgs, useGetOrgRoles, useUpdateIdentity } from
|
|||||||
import { IdentityAuthMethod, identityAuthToNameMap } from "@app/hooks/api/identities";
|
import { IdentityAuthMethod, identityAuthToNameMap } from "@app/hooks/api/identities";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
// TODO: some kind of map
|
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
handlePopUpOpen: (
|
handlePopUpOpen: (
|
||||||
popUpName: keyof UsePopUpState<
|
popUpName: keyof UsePopUpState<
|
||||||
@@ -44,7 +42,6 @@ type Props = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
export const IdentityTable = ({ handlePopUpOpen }: Props) => {
|
export const IdentityTable = ({ handlePopUpOpen }: Props) => {
|
||||||
|
|
||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
|
|
||||||
|
|||||||
+1
-2
@@ -63,7 +63,6 @@ export const IdentityUniversalAuthForm = ({
|
|||||||
handlePopUpToggle,
|
handlePopUpToggle,
|
||||||
identityAuthMethodData
|
identityAuthMethodData
|
||||||
}: Props) => {
|
}: Props) => {
|
||||||
|
|
||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
const { subscription } = useSubscription();
|
const { subscription } = useSubscription();
|
||||||
@@ -384,7 +383,7 @@ export const IdentityUniversalAuthForm = ({
|
|||||||
variant="plain"
|
variant="plain"
|
||||||
onClick={() => handlePopUpToggle("identityAuthMethod", false)}
|
onClick={() => handlePopUpToggle("identityAuthMethod", false)}
|
||||||
>
|
>
|
||||||
Cancel
|
{identityAuthMethodData?.authMethod ? "Cancel" : "Skip"}
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
</form>
|
</form>
|
||||||
|
|||||||
Reference in New Issue
Block a user