mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Keep public key as a jwk json obj instead
This commit is contained in:
@@ -54,8 +54,8 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
// Multi-value emails array
|
// Multi-value emails array
|
||||||
t.specificType("emails", "text[]").notNullable();
|
t.specificType("emails", "text[]").notNullable();
|
||||||
|
|
||||||
// Public key (PEM format)
|
// Public key (JWK format)
|
||||||
t.text("publicKey").notNullable();
|
t.jsonb("publicKey").notNullable();
|
||||||
|
|
||||||
t.timestamps(true, true, true);
|
t.timestamps(true, true, true);
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ export const PkiAcmeAccountsSchema = z.object({
|
|||||||
id: z.string().uuid(),
|
id: z.string().uuid(),
|
||||||
profileId: z.string().uuid(),
|
profileId: z.string().uuid(),
|
||||||
emails: z.string().array(),
|
emails: z.string().array(),
|
||||||
publicKey: z.string(),
|
publicKey: z.unknown(),
|
||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
updatedAt: z.date()
|
updatedAt: z.date()
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -20,12 +20,14 @@ import {
|
|||||||
GetAcmeOrderSchema,
|
GetAcmeOrderSchema,
|
||||||
ListAcmeOrdersResponseSchema,
|
ListAcmeOrdersResponseSchema,
|
||||||
ListAcmeOrdersSchema,
|
ListAcmeOrdersSchema,
|
||||||
|
RawJwsPayloadSchema,
|
||||||
RespondToAcmeChallengeResponseSchema,
|
RespondToAcmeChallengeResponseSchema,
|
||||||
RespondToAcmeChallengeSchema
|
RespondToAcmeChallengeSchema
|
||||||
} from "@app/ee/services/pki-acme/pki-acme-schemas";
|
} from "@app/ee/services/pki-acme/pki-acme-schemas";
|
||||||
import { ApiDocsTags } from "@app/lib/api-docs";
|
import { ApiDocsTags } from "@app/lib/api-docs";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
|
import { TRawJwsPayload } from "@app/ee/services/pki-acme/pki-acme-types";
|
||||||
|
|
||||||
export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => {
|
export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
@@ -104,16 +106,22 @@ export const registerPkiAcmeRouter = async (server: FastifyZodProvider) => {
|
|||||||
hide: false,
|
hide: false,
|
||||||
tags: [ApiDocsTags.PkiAcme],
|
tags: [ApiDocsTags.PkiAcme],
|
||||||
description: "ACME New Account - register a new account or find existing one",
|
description: "ACME New Account - register a new account or find existing one",
|
||||||
...CreateAcmeAccountSchema.shape,
|
...RawJwsPayloadSchema.shape,
|
||||||
response: {
|
response: {
|
||||||
201: CreateAcmeAccountResponseSchema
|
201: CreateAcmeAccountResponseSchema
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
handler: async (req, res) => {
|
handler: async (req, res) => {
|
||||||
// TODO: check nonce here
|
// TODO: check nonce here
|
||||||
// TODO: check signature here
|
const { payload, protectedHeader, jwk } = await server.services.pkiAcme.validateCreateAcmeAccountJwsPayload(
|
||||||
|
req.body as TRawJwsPayload
|
||||||
|
);
|
||||||
|
|
||||||
const account = await server.services.pkiAcme.createAcmeAccount(req.params.profileId, req.body);
|
const account = await server.services.pkiAcme.createAcmeAccount(
|
||||||
|
req.params.profileId,
|
||||||
|
jwk,
|
||||||
|
payload as TCreateAcmeAccountPayload
|
||||||
|
);
|
||||||
// TODO: deal with existing account case here
|
// TODO: deal with existing account case here
|
||||||
res.code(201);
|
res.code(201);
|
||||||
res.header(
|
res.header(
|
||||||
|
|||||||
Reference in New Issue
Block a user