mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 21:27:10 +00:00
Merge pull request #3700 from akhilmhdh/fix/gateway-dns-resolve
feat: resolved gateway verify issue and validation check
This commit is contained in:
@@ -11,6 +11,8 @@ export const verifyHostInputValidity = async (host: string, isGateway = false) =
|
|||||||
|
|
||||||
if (appCfg.isDevelopmentMode) return [host];
|
if (appCfg.isDevelopmentMode) return [host];
|
||||||
|
|
||||||
|
if (isGateway) return [host];
|
||||||
|
|
||||||
const reservedHosts = [appCfg.DB_HOST || getDbConnectionHost(appCfg.DB_CONNECTION_URI)].concat(
|
const reservedHosts = [appCfg.DB_HOST || getDbConnectionHost(appCfg.DB_CONNECTION_URI)].concat(
|
||||||
(appCfg.DB_READ_REPLICAS || []).map((el) => getDbConnectionHost(el.DB_CONNECTION_URI)),
|
(appCfg.DB_READ_REPLICAS || []).map((el) => getDbConnectionHost(el.DB_CONNECTION_URI)),
|
||||||
getDbConnectionHost(appCfg.REDIS_URL),
|
getDbConnectionHost(appCfg.REDIS_URL),
|
||||||
@@ -58,7 +60,7 @@ export const verifyHostInputValidity = async (host: string, isGateway = false) =
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!isGateway && !(appCfg.DYNAMIC_SECRET_ALLOW_INTERNAL_IP || appCfg.ALLOW_INTERNAL_IP_CONNECTIONS)) {
|
if (!(appCfg.DYNAMIC_SECRET_ALLOW_INTERNAL_IP || appCfg.ALLOW_INTERNAL_IP_CONNECTIONS)) {
|
||||||
const isInternalIp = inputHostIps.some((el) => isPrivateIp(el));
|
const isInternalIp = inputHostIps.some((el) => isPrivateIp(el));
|
||||||
if (isInternalIp) throw new BadRequestError({ message: "Invalid db host" });
|
if (isInternalIp) throw new BadRequestError({ message: "Invalid db host" });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -116,7 +116,7 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
const create = async (inputs: unknown, expireAt: number) => {
|
const create = async ({ inputs, expireAt }: { inputs: unknown; expireAt: number }) => {
|
||||||
const providerInputs = await validateProviderInputs(inputs);
|
const providerInputs = await validateProviderInputs(inputs);
|
||||||
|
|
||||||
const tokenRequestCallback = async (host: string, port: number) => {
|
const tokenRequestCallback = async (host: string, port: number) => {
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ const createQuicConnection = async (
|
|||||||
if (!certs || certs.length === 0) return quic.native.CryptoError.CertificateRequired;
|
if (!certs || certs.length === 0) return quic.native.CryptoError.CertificateRequired;
|
||||||
const serverCertificate = new crypto.X509Certificate(Buffer.from(certs[0]));
|
const serverCertificate = new crypto.X509Certificate(Buffer.from(certs[0]));
|
||||||
const caCertificate = new crypto.X509Certificate(tlsOptions.ca);
|
const caCertificate = new crypto.X509Certificate(tlsOptions.ca);
|
||||||
const isValidServerCertificate = serverCertificate.checkIssued(caCertificate);
|
const isValidServerCertificate = serverCertificate.verify(caCertificate.publicKey);
|
||||||
if (!isValidServerCertificate) return quic.native.CryptoError.BadCertificate;
|
if (!isValidServerCertificate) return quic.native.CryptoError.BadCertificate;
|
||||||
|
|
||||||
const subjectDetails = parseSubjectDetails(serverCertificate.subject);
|
const subjectDetails = parseSubjectDetails(serverCertificate.subject);
|
||||||
|
|||||||
Reference in New Issue
Block a user