mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 16:27:40 +00:00
Fix merge conflicts
This commit is contained in:
@@ -80,19 +80,10 @@ export const login1 = async (req: Request, res: Response) => {
|
|||||||
export const login2 = async (req: Request, res: Response) => {
|
export const login2 = async (req: Request, res: Response) => {
|
||||||
if (!req.headers['user-agent']) throw InternalServerError({ message: 'User-Agent header is required' });
|
if (!req.headers['user-agent']) throw InternalServerError({ message: 'User-Agent header is required' });
|
||||||
|
|
||||||
<<<<<<< HEAD
|
|
||||||
if (!req.headers['user-agent']) throw InternalServerError({ message: 'User-Agent header is required' });
|
|
||||||
|
|
||||||
const { email, clientProof } = req.body;
|
|
||||||
const user = await User.findOne({
|
|
||||||
email
|
|
||||||
}).select('+salt +verifier +encryptionVersion +protectedKey +protectedKeyIV +protectedKeyTag +publicKey +encryptedPrivateKey +iv +tag +devices');
|
|
||||||
=======
|
|
||||||
const { email, clientProof } = req.body;
|
const { email, clientProof } = req.body;
|
||||||
const user = await User.findOne({
|
const user = await User.findOne({
|
||||||
email
|
email
|
||||||
}).select('+salt +verifier +encryptionVersion +protectedKey +protectedKeyIV +protectedKeyTag +publicKey +encryptedPrivateKey +iv +tag');
|
}).select('+salt +verifier +encryptionVersion +protectedKey +protectedKeyIV +protectedKeyTag +publicKey +encryptedPrivateKey +iv +tag +devices');
|
||||||
>>>>>>> origin/main
|
|
||||||
|
|
||||||
if (!user) throw new Error('Failed to find user');
|
if (!user) throw new Error('Failed to find user');
|
||||||
|
|
||||||
@@ -102,73 +93,6 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
return BadRequestError(Error("Failed to find login details for SRP"))
|
return BadRequestError(Error("Failed to find login details for SRP"))
|
||||||
}
|
}
|
||||||
|
|
||||||
<<<<<<< HEAD
|
|
||||||
const server = new jsrp.server();
|
|
||||||
server.init(
|
|
||||||
{
|
|
||||||
salt: user.salt,
|
|
||||||
verifier: user.verifier,
|
|
||||||
b: loginSRPDetail.serverBInt
|
|
||||||
},
|
|
||||||
async () => {
|
|
||||||
server.setClientPublicKey(loginSRPDetail.clientPublicKey);
|
|
||||||
|
|
||||||
// compare server and client shared keys
|
|
||||||
if (server.checkClientProof(clientProof)) {
|
|
||||||
|
|
||||||
if (user.isMfaEnabled) {
|
|
||||||
// case: user has MFA enabled
|
|
||||||
|
|
||||||
// generate temporary MFA token
|
|
||||||
const token = createToken({
|
|
||||||
payload: {
|
|
||||||
userId: user._id.toString()
|
|
||||||
},
|
|
||||||
expiresIn: await getJwtMfaLifetime(),
|
|
||||||
secret: await getJwtMfaSecret()
|
|
||||||
});
|
|
||||||
|
|
||||||
const code = await TokenService.createToken({
|
|
||||||
type: TOKEN_EMAIL_MFA,
|
|
||||||
email
|
|
||||||
});
|
|
||||||
|
|
||||||
// send MFA code [code] to [email]
|
|
||||||
await sendMail({
|
|
||||||
template: 'emailMfa.handlebars',
|
|
||||||
subjectLine: 'Infisical MFA code',
|
|
||||||
recipients: [email],
|
|
||||||
substitutions: {
|
|
||||||
code
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
return res.status(200).send({
|
|
||||||
mfaEnabled: true,
|
|
||||||
token
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
await checkUserDevice({
|
|
||||||
user,
|
|
||||||
ip: req.realIP,
|
|
||||||
userAgent: req.headers['user-agent'] ?? ''
|
|
||||||
});
|
|
||||||
|
|
||||||
// issue tokens
|
|
||||||
const tokens = await issueAuthTokens({
|
|
||||||
userId: user._id,
|
|
||||||
ip: req.realIP,
|
|
||||||
userAgent: req.headers['user-agent'] ?? ''
|
|
||||||
});
|
|
||||||
|
|
||||||
// store (refresh) token in httpOnly cookie
|
|
||||||
res.cookie('jid', tokens.refreshToken, {
|
|
||||||
httpOnly: true,
|
|
||||||
path: '/',
|
|
||||||
sameSite: 'strict',
|
|
||||||
secure: await getHttpsEnabled()
|
|
||||||
=======
|
|
||||||
const server = new jsrp.server();
|
const server = new jsrp.server();
|
||||||
server.init(
|
server.init(
|
||||||
{
|
{
|
||||||
@@ -181,7 +105,6 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
// compare server and client shared keys
|
// compare server and client shared keys
|
||||||
if (server.checkClientProof(clientProof)) {
|
if (server.checkClientProof(clientProof)) {
|
||||||
|
|
||||||
if (user.isMfaEnabled) {
|
if (user.isMfaEnabled) {
|
||||||
// case: user has MFA enabled
|
// case: user has MFA enabled
|
||||||
|
|
||||||
@@ -197,7 +120,6 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
const code = await TokenService.createToken({
|
const code = await TokenService.createToken({
|
||||||
type: TOKEN_EMAIL_MFA,
|
type: TOKEN_EMAIL_MFA,
|
||||||
email
|
email
|
||||||
>>>>>>> origin/main
|
|
||||||
});
|
});
|
||||||
|
|
||||||
// send MFA code [code] to [email]
|
// send MFA code [code] to [email]
|
||||||
@@ -210,28 +132,24 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
<<<<<<< HEAD
|
|
||||||
loginAction && await EELogService.createLog({
|
|
||||||
userId: user._id,
|
|
||||||
actions: [loginAction],
|
|
||||||
channel: getChannelFromUserAgent(req.headers['user-agent']),
|
|
||||||
ipAddress: req.realIP
|
|
||||||
=======
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
mfaEnabled: true,
|
mfaEnabled: true,
|
||||||
token
|
token
|
||||||
>>>>>>> origin/main
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
await checkUserDevice({
|
await checkUserDevice({
|
||||||
user,
|
user,
|
||||||
ip: req.ip,
|
ip: req.realIP,
|
||||||
userAgent: req.headers['user-agent'] ?? ''
|
userAgent: req.headers['user-agent'] ?? ''
|
||||||
});
|
});
|
||||||
|
|
||||||
// issue tokens
|
// issue tokens
|
||||||
const tokens = await issueAuthTokens({ userId: user._id.toString() });
|
const tokens = await issueAuthTokens({
|
||||||
|
userId: user._id,
|
||||||
|
ip: req.realIP,
|
||||||
|
userAgent: req.headers['user-agent'] ?? ''
|
||||||
|
});
|
||||||
|
|
||||||
// store (refresh) token in httpOnly cookie
|
// store (refresh) token in httpOnly cookie
|
||||||
res.cookie('jid', tokens.refreshToken, {
|
res.cookie('jid', tokens.refreshToken, {
|
||||||
@@ -241,7 +159,7 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
secure: await getHttpsEnabled()
|
secure: await getHttpsEnabled()
|
||||||
});
|
});
|
||||||
|
|
||||||
// case: user does not have MFA enablgged
|
// case: user does not have MFA enabled
|
||||||
// return (access) token in response
|
// return (access) token in response
|
||||||
|
|
||||||
interface ResponseData {
|
interface ResponseData {
|
||||||
|
|||||||
@@ -112,19 +112,12 @@ export const completeAccountSignup = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
<<<<<<< HEAD
|
|
||||||
// issue tokens
|
|
||||||
const tokens = await issueAuthTokens({
|
|
||||||
userId: user._id,
|
|
||||||
ip: req.realIP,
|
|
||||||
userAgent: req.headers['user-agent'] ?? ''
|
|
||||||
});
|
|
||||||
=======
|
|
||||||
// issue tokens
|
// issue tokens
|
||||||
const tokens = await issueAuthTokens({
|
const tokens = await issueAuthTokens({
|
||||||
userId: user._id.toString()
|
userId: user._id,
|
||||||
|
ip: req.realIP,
|
||||||
|
userAgent: req.headers['user-agent'] ?? ''
|
||||||
});
|
});
|
||||||
>>>>>>> origin/main
|
|
||||||
|
|
||||||
token = tokens.token;
|
token = tokens.token;
|
||||||
|
|
||||||
@@ -244,19 +237,12 @@ export const completeAccountInvite = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
<<<<<<< HEAD
|
|
||||||
// issue tokens
|
|
||||||
const tokens = await issueAuthTokens({
|
|
||||||
userId: user._id,
|
|
||||||
ip: req.realIP,
|
|
||||||
userAgent: req.headers['user-agent'] ?? ''
|
|
||||||
});
|
|
||||||
=======
|
|
||||||
// issue tokens
|
// issue tokens
|
||||||
const tokens = await issueAuthTokens({
|
const tokens = await issueAuthTokens({
|
||||||
userId: user._id.toString()
|
userId: user._id,
|
||||||
|
ip: req.realIP,
|
||||||
|
userAgent: req.headers['user-agent'] ?? ''
|
||||||
});
|
});
|
||||||
>>>>>>> origin/main
|
|
||||||
|
|
||||||
token = tokens.token;
|
token = tokens.token;
|
||||||
|
|
||||||
|
|||||||
@@ -46,68 +46,6 @@ interface V2PushSecret {
|
|||||||
*/
|
*/
|
||||||
export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
|
export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
|
||||||
// upload (encrypted) secrets to workspace with id [workspaceId]
|
// upload (encrypted) secrets to workspace with id [workspaceId]
|
||||||
<<<<<<< HEAD
|
|
||||||
try {
|
|
||||||
const postHogClient = await TelemetryService.getPostHogClient();
|
|
||||||
let { secrets }: { secrets: V2PushSecret[] } = req.body;
|
|
||||||
const { keys, environment, channel } = req.body;
|
|
||||||
const { workspaceId } = req.params;
|
|
||||||
|
|
||||||
// validate environment
|
|
||||||
const workspaceEnvs = req.membership.workspace.environments;
|
|
||||||
if (!workspaceEnvs.find(({ slug }: { slug: string }) => slug === environment)) {
|
|
||||||
throw new Error('Failed to validate environment');
|
|
||||||
}
|
|
||||||
|
|
||||||
// sanitize secrets
|
|
||||||
secrets = secrets.filter(
|
|
||||||
(s: V2PushSecret) => s.secretKeyCiphertext !== '' && s.secretValueCiphertext !== ''
|
|
||||||
);
|
|
||||||
|
|
||||||
await push({
|
|
||||||
userId: req.user._id,
|
|
||||||
workspaceId,
|
|
||||||
environment,
|
|
||||||
secrets,
|
|
||||||
channel: channel ? channel : 'cli',
|
|
||||||
ipAddress: req.realIP
|
|
||||||
});
|
|
||||||
|
|
||||||
await pushKeys({
|
|
||||||
userId: req.user._id,
|
|
||||||
workspaceId,
|
|
||||||
keys
|
|
||||||
});
|
|
||||||
|
|
||||||
if (postHogClient) {
|
|
||||||
postHogClient.capture({
|
|
||||||
event: 'secrets pushed',
|
|
||||||
distinctId: req.user.email,
|
|
||||||
properties: {
|
|
||||||
numberOfSecrets: secrets.length,
|
|
||||||
environment,
|
|
||||||
workspaceId,
|
|
||||||
channel: channel ? channel : 'cli'
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
// trigger event - push secrets
|
|
||||||
EventService.handleEvent({
|
|
||||||
event: eventPushSecrets({
|
|
||||||
workspaceId: new Types.ObjectId(workspaceId),
|
|
||||||
environment
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
} catch (err) {
|
|
||||||
Sentry.setUser({ email: req.user.email });
|
|
||||||
Sentry.captureException(err);
|
|
||||||
return res.status(400).send({
|
|
||||||
message: 'Failed to upload workspace secrets'
|
|
||||||
});
|
|
||||||
}
|
|
||||||
=======
|
|
||||||
const postHogClient = await TelemetryService.getPostHogClient();
|
const postHogClient = await TelemetryService.getPostHogClient();
|
||||||
let { secrets }: { secrets: V2PushSecret[] } = req.body;
|
let { secrets }: { secrets: V2PushSecret[] } = req.body;
|
||||||
const { keys, environment, channel } = req.body;
|
const { keys, environment, channel } = req.body;
|
||||||
@@ -130,7 +68,7 @@ export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
|
|||||||
environment,
|
environment,
|
||||||
secrets,
|
secrets,
|
||||||
channel: channel ? channel : 'cli',
|
channel: channel ? channel : 'cli',
|
||||||
ipAddress: req.ip
|
ipAddress: req.realIP
|
||||||
});
|
});
|
||||||
|
|
||||||
await pushKeys({
|
await pushKeys({
|
||||||
@@ -159,7 +97,6 @@ export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
|
|||||||
environment
|
environment
|
||||||
})
|
})
|
||||||
});
|
});
|
||||||
>>>>>>> origin/main
|
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
message: 'Successfully uploaded workspace secrets'
|
message: 'Successfully uploaded workspace secrets'
|
||||||
@@ -174,59 +111,7 @@ export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
|
|||||||
* @returns
|
* @returns
|
||||||
*/
|
*/
|
||||||
export const pullSecrets = async (req: Request, res: Response) => {
|
export const pullSecrets = async (req: Request, res: Response) => {
|
||||||
<<<<<<< HEAD
|
|
||||||
let secrets;
|
let secrets;
|
||||||
try {
|
|
||||||
const postHogClient = await TelemetryService.getPostHogClient();
|
|
||||||
const environment: string = req.query.environment as string;
|
|
||||||
const channel: string = req.query.channel as string;
|
|
||||||
const { workspaceId } = req.params;
|
|
||||||
|
|
||||||
let userId;
|
|
||||||
if (req.user) {
|
|
||||||
userId = req.user._id.toString();
|
|
||||||
} else if (req.serviceTokenData) {
|
|
||||||
userId = req.serviceTokenData.user.toString();
|
|
||||||
}
|
|
||||||
// validate environment
|
|
||||||
const workspaceEnvs = req.membership.workspace.environments;
|
|
||||||
if (!workspaceEnvs.find(({ slug }: { slug: string }) => slug === environment)) {
|
|
||||||
throw new Error('Failed to validate environment');
|
|
||||||
}
|
|
||||||
|
|
||||||
secrets = await pull({
|
|
||||||
userId,
|
|
||||||
workspaceId,
|
|
||||||
environment,
|
|
||||||
channel: channel ? channel : 'cli',
|
|
||||||
ipAddress: req.realIP
|
|
||||||
});
|
|
||||||
|
|
||||||
if (channel !== 'cli') {
|
|
||||||
secrets = reformatPullSecrets({ secrets });
|
|
||||||
}
|
|
||||||
|
|
||||||
if (postHogClient) {
|
|
||||||
// capture secrets pushed event in production
|
|
||||||
postHogClient.capture({
|
|
||||||
distinctId: req.user.email,
|
|
||||||
event: 'secrets pulled',
|
|
||||||
properties: {
|
|
||||||
numberOfSecrets: secrets.length,
|
|
||||||
environment,
|
|
||||||
workspaceId,
|
|
||||||
channel: channel ? channel : 'cli'
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
} catch (err) {
|
|
||||||
Sentry.setUser({ email: req.user.email });
|
|
||||||
Sentry.captureException(err);
|
|
||||||
return res.status(400).send({
|
|
||||||
message: 'Failed to pull workspace secrets'
|
|
||||||
});
|
|
||||||
}
|
|
||||||
=======
|
|
||||||
const postHogClient = await TelemetryService.getPostHogClient();
|
const postHogClient = await TelemetryService.getPostHogClient();
|
||||||
const environment: string = req.query.environment as string;
|
const environment: string = req.query.environment as string;
|
||||||
const channel: string = req.query.channel as string;
|
const channel: string = req.query.channel as string;
|
||||||
@@ -244,17 +129,16 @@ export const pullSecrets = async (req: Request, res: Response) => {
|
|||||||
throw new Error('Failed to validate environment');
|
throw new Error('Failed to validate environment');
|
||||||
}
|
}
|
||||||
|
|
||||||
let secrets = await pull({
|
secrets = await pull({
|
||||||
userId,
|
userId,
|
||||||
workspaceId,
|
workspaceId,
|
||||||
environment,
|
environment,
|
||||||
channel: channel ? channel : 'cli',
|
channel: channel ? channel : 'cli',
|
||||||
ipAddress: req.ip
|
ipAddress: req.realIP
|
||||||
});
|
});
|
||||||
|
|
||||||
if (channel !== 'cli') {
|
if (channel !== 'cli') {
|
||||||
// FIX: Fix this any
|
secrets = reformatPullSecrets({ secrets });
|
||||||
secrets = reformatPullSecrets({ secrets }) as any;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (postHogClient) {
|
if (postHogClient) {
|
||||||
@@ -270,7 +154,6 @@ export const pullSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
>>>>>>> origin/main
|
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
secrets
|
secrets
|
||||||
|
|||||||
Reference in New Issue
Block a user