Fix bug on azure revokeCredentials and limit expiration to 5 years

This commit is contained in:
carlosmonastyrski
2025-04-30 18:16:48 -03:00
parent d0a642a63a
commit a01a9f3f77
@@ -1,3 +1,4 @@
/* eslint-disable no-await-in-loop */
import { AxiosError } from "axios"; import { AxiosError } from "axios";
import { import {
@@ -18,6 +19,11 @@ import { getAzureConnectionAccessToken } from "@app/services/app-connection/azur
const GRAPH_API_BASE = "https://graph.microsoft.com/v1.0"; const GRAPH_API_BASE = "https://graph.microsoft.com/v1.0";
const sleep = async () =>
new Promise((resolve) => {
setTimeout(resolve, 1000);
});
export const azureClientSecretRotationFactory: TRotationFactory< export const azureClientSecretRotationFactory: TRotationFactory<
TAzureClientSecretRotationWithConnection, TAzureClientSecretRotationWithConnection,
TAzureClientSecretRotationGeneratedCredentials TAzureClientSecretRotationGeneratedCredentials
@@ -41,13 +47,16 @@ export const azureClientSecretRotationFactory: TRotationFactory<
"0" "0"
)}-${now.getFullYear()}`; )}-${now.getFullYear()}`;
const endDateTime = new Date();
endDateTime.setFullYear(now.getFullYear() + 5);
try { try {
const { data } = await request.post<AzureAddPasswordResponse>( const { data } = await request.post<AzureAddPasswordResponse>(
endpoint, endpoint,
{ {
passwordCredential: { passwordCredential: {
displayName: `Infisical Rotated Secret (${formattedDate})`, displayName: `Infisical Rotated Secret (${formattedDate})`,
endDateTime: "2299-12-31T23:59:59Z" // effectively no expiration endDateTime: endDateTime.toISOString()
} }
}, },
{ {
@@ -130,7 +139,10 @@ export const azureClientSecretRotationFactory: TRotationFactory<
) => { ) => {
if (!credentials?.length) return callback(); if (!credentials?.length) return callback();
await Promise.all(credentials.map(({ keyId }) => revokeCredential(keyId))); for (const { keyId } of credentials) {
await revokeCredential(keyId);
await sleep();
}
return callback(); return callback();
}; };