docs, grammar fixes, frontend tweak
@@ -97,7 +97,7 @@ export const registerSshCertificateTemplateRouter = async (server: FastifyZodPro
|
|||||||
allowCustomKeyIds: z.boolean().describe(SSH_CERTIFICATE_TEMPLATES.CREATE.allowCustomKeyIds)
|
allowCustomKeyIds: z.boolean().describe(SSH_CERTIFICATE_TEMPLATES.CREATE.allowCustomKeyIds)
|
||||||
})
|
})
|
||||||
.refine((data) => ms(data.maxTTL) >= ms(data.ttl), {
|
.refine((data) => ms(data.maxTTL) >= ms(data.ttl), {
|
||||||
message: "Max TLL must be greater than or equal to TTL",
|
message: "Max TTL must be greater than or equal to TTL",
|
||||||
path: ["maxTTL"]
|
path: ["maxTTL"]
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import { getConfig } from "@app/lib/config/env";
|
|||||||
import { request } from "@app/lib/config/request";
|
import { request } from "@app/lib/config/request";
|
||||||
import { BadRequestError, NotFoundError, PermissionBoundaryError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError, PermissionBoundaryError, UnauthorizedError } from "@app/lib/errors";
|
||||||
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
||||||
|
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
||||||
|
|
||||||
import { ActorType, AuthTokenType } from "../auth/auth-type";
|
import { ActorType, AuthTokenType } from "../auth/auth-type";
|
||||||
import { TIdentityOrgDALFactory } from "../identity/identity-org-dal";
|
import { TIdentityOrgDALFactory } from "../identity/identity-org-dal";
|
||||||
@@ -29,7 +30,6 @@ import {
|
|||||||
TRevokeOciAuthDTO,
|
TRevokeOciAuthDTO,
|
||||||
TUpdateOciAuthDTO
|
TUpdateOciAuthDTO
|
||||||
} from "./identity-oci-auth-types";
|
} from "./identity-oci-auth-types";
|
||||||
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
|
||||||
|
|
||||||
type TIdentityOciAuthServiceFactoryDep = {
|
type TIdentityOciAuthServiceFactoryDep = {
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Attach"
|
||||||
|
openapi: "POST /api/v1/auth/oci-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Login"
|
||||||
|
openapi: "POST /api/v1/auth/oci-auth/login"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Retrieve"
|
||||||
|
openapi: "GET /api/v1/auth/oci-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Revoke"
|
||||||
|
openapi: "DELETE /api/v1/auth/oci-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Update"
|
||||||
|
openapi: "PATCH /api/v1/auth/oci-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -85,7 +85,7 @@ In this brief, we'll explore how to fetch a secret back from a project on [Infis
|
|||||||
Next, we can use the access token to authenticate with the [Infisical API](/api-reference/overview/introduction) to read/write secrets
|
Next, we can use the access token to authenticate with the [Infisical API](/api-reference/overview/introduction) to read/write secrets
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -311,7 +311,7 @@ access the Infisical API using the AWS Auth authentication method.
|
|||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -173,7 +173,7 @@ access the Infisical API using the Azure Auth authentication method.
|
|||||||
We recommend using one of Infisical's clients like SDKs or the Infisical Agent to authenticate with Infisical using Azure Auth as they handle the authentication process including retrieving the client access token.
|
We recommend using one of Infisical's clients like SDKs or the Infisical Agent to authenticate with Infisical using Azure Auth as they handle the authentication process including retrieving the client access token.
|
||||||
</Tip>
|
</Tip>
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
a new access token should be obtained by performing another login operation.
|
a new access token should be obtained by performing another login operation.
|
||||||
|
|||||||
@@ -168,7 +168,7 @@ access the Infisical API using the GCP ID Token authentication method.
|
|||||||
We recommend using one of Infisical's clients like SDKs or the Infisical Agent to authenticate with Infisical using GCP IAM Auth as they handle the authentication process including generating the signed JWT token.
|
We recommend using one of Infisical's clients like SDKs or the Infisical Agent to authenticate with Infisical using GCP IAM Auth as they handle the authentication process including generating the signed JWT token.
|
||||||
</Tip>
|
</Tip>
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
a new access token should be obtained by performing another login operation.
|
a new access token should be obtained by performing another login operation.
|
||||||
@@ -352,7 +352,7 @@ access the Infisical API using the GCP IAM authentication method.
|
|||||||
We recommend using one of Infisical's clients like SDKs or the Infisical Agent to authenticate with Infisical using GCP IAM Auth as they handle the authentication process including generating the signed JWT token.
|
We recommend using one of Infisical's clients like SDKs or the Infisical Agent to authenticate with Infisical using GCP IAM Auth as they handle the authentication process including generating the signed JWT token.
|
||||||
</Tip>
|
</Tip>
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
a new access token should be obtained by performing another login operation.
|
a new access token should be obtained by performing another login operation.
|
||||||
|
|||||||
@@ -257,7 +257,7 @@ In the following steps, we explore how to create and use identities for your app
|
|||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
|
|
||||||
If an identity access token exceeds its max ttl, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token exceeds its max ttl, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -0,0 +1,163 @@
|
|||||||
|
---
|
||||||
|
title: OCI Auth
|
||||||
|
description: "Learn how to authenticate with Infisical using OCI user accounts."
|
||||||
|
---
|
||||||
|
|
||||||
|
**OCI Auth** is an OCI-native authentication method that verifies Oracle Cloud Infrastructure users through signature validation, allowing secure access to Infisical resources.
|
||||||
|
|
||||||
|
## Diagram
|
||||||
|
|
||||||
|
The following sequence diagram illustrates the OCI Auth workflow for authenticating OCI users with Infisical.
|
||||||
|
|
||||||
|
```mermaid
|
||||||
|
sequenceDiagram
|
||||||
|
participant Client
|
||||||
|
participant Infisical
|
||||||
|
participant OCI
|
||||||
|
|
||||||
|
Note over Client,Client: Step 1: Sign user identity request
|
||||||
|
|
||||||
|
Note over Client,Infisical: Step 2: Login Operation
|
||||||
|
Client->>Infisical: Send signed request details to /api/v1/auth/oci-auth/login
|
||||||
|
|
||||||
|
Note over Infisical,OCI: Step 3: Request verification
|
||||||
|
Infisical->>OCI: Forward signed request
|
||||||
|
OCI-->>Infisical: Return user details
|
||||||
|
|
||||||
|
Note over Infisical: Step 4: Identity property validation
|
||||||
|
Infisical->>Client: Return short-lived access token
|
||||||
|
|
||||||
|
Note over Client,Infisical: Step 5: Access Infisical API with token
|
||||||
|
Client->>Infisical: Make authenticated requests using the short-lived access token
|
||||||
|
```
|
||||||
|
|
||||||
|
## Concept
|
||||||
|
|
||||||
|
At a high level, Infisical authenticates an OCI user by verifying its identity and checking that it meets specific requirements (e.g., its username is authorized) at the `/api/v1/auth/oci-auth/login` endpoint. If successful,
|
||||||
|
then Infisical returns a short-lived access token that can be used to make authenticated requests to the Infisical API.
|
||||||
|
|
||||||
|
To be more specific:
|
||||||
|
1. The client [signs](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm) a `/20160918/users/{userId}` request using an OCI user's [private key](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/apisigningkey.htm#Required_Keys_and_OCIDs); this is done using the [OCI SDK](https://infisical.com/docs/documentation/platform/identities/oci-auth#accessing-the-infisical-api-with-the-identity) or API.
|
||||||
|
2. The client sends the signed request's headers and their user OCID to Infisical at the `/api/v1/auth/oci-auth/login` endpoint.
|
||||||
|
3. Infisical reconstructs the request and sends it to OCI via the [Get User](https://docs.oracle.com/en/engineered-systems/private-cloud-appliance/3.0-latest/ceapi/op-20160918-users-user_id-get.html) endpoint for verification and obtains the identity associated with the OCI user.
|
||||||
|
4. Infisical checks the user's properties against set criteria such as **Allowed Usernames**.
|
||||||
|
5. If all checks pass, Infisical returns a short-lived access token that the client can use to make authenticated requests to the Infisical API.
|
||||||
|
|
||||||
|
## Guide
|
||||||
|
|
||||||
|
In the following steps, we explore how to create and use identities for your workloads and applications on OCI to
|
||||||
|
access the Infisical API using the OCI request signing authentication method.
|
||||||
|
|
||||||
|
### Creating an identity
|
||||||
|
|
||||||
|
To create an identity, head to your Organization Settings > Access Control > [Identities](https://app.infisical.com/organization/access-management?selectedTab=identities) and press **Create identity**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
When creating an identity, you specify an organization-level [role](/documentation/platform/role-based-access-controls) for it to assume; you can configure roles in Organization Settings > Access Control > [Organization Roles](https://app.infisical.com/organization/access-management?selectedTab=roles).
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Input some details for your new identity:
|
||||||
|
- **Name (required):** A friendly name for the identity.
|
||||||
|
- **Role (required):** A role from the [**Organization Roles**](https://app.infisical.com/organization/access-management?selectedTab=roles) tab for the identity to assume. The organization role assigned will determine what organization-level resources this identity can have access to.
|
||||||
|
|
||||||
|
Once you've created an identity, you'll be redirected to a page where you can manage the identity.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Since the identity has been configured with [Universal Auth](https://infisical.com/docs/documentation/platform/identities/universal-auth) by default, you should reconfigure it to use OCI Auth instead. To do this, click the cog next to **Universal Auth** and then select **Delete** in the options dropdown.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Now create a new OCI Auth Method.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Here's some information about each field:
|
||||||
|
- **Allowed Usernames:** A comma-separated list of trusted OCI users that are allowed to authenticate with Infisical.
|
||||||
|
- **Access Token TTL (default is `2592000` equivalent to 30 days):** The lifetime for an access token in seconds. This value will be referenced at renewal time.
|
||||||
|
- **Access Token Max TTL (default is `2592000` equivalent to 30 days):** The maximum lifetime for an access token in seconds. This value will be referenced at renewal time.
|
||||||
|
- **Access Token Max Number of Uses (default is `0`):** The maximum number of times that an access token can be used; a value of `0` implies an infinite number of uses.
|
||||||
|
- **Access Token Trusted IPs:** The IPs or CIDR ranges that access tokens can be used from. By default, each token is given the `0.0.0.0/0`, allowing usage from any network address.
|
||||||
|
|
||||||
|
### Adding an identity to a project
|
||||||
|
|
||||||
|
In order to allow an identity to access project-level resources such as secrets, you must add it to the relevant projects.
|
||||||
|
|
||||||
|
To do this, head over to the project you want to add the identity to and navigate to Project Settings > Access Control > Machine Identities and press **Add Identity**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Select the identity you want to add to the project and the project-level role you want it to assume. The project role given to the identity will determine what project-level resources this identity can access.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
### Accessing the Infisical API with the identity
|
||||||
|
|
||||||
|
To access the Infisical API as the identity, you need to construct a signed [Get User](https://docs.oracle.com/en/engineered-systems/private-cloud-appliance/3.0-latest/ceapi/op-20160918-users-user_id-get.html) request using [OCI Signature v1](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm#Request_Signatures) and then make a request to the `/api/v1/auth/oci-auth/login` endpoint passing the signed header data and user OCID.
|
||||||
|
|
||||||
|
Below is an example of how you can authenticate with Infisical using the `oci-sdk` for NodeJS.
|
||||||
|
|
||||||
|
```typescript
|
||||||
|
import { common } from "oci-sdk";
|
||||||
|
|
||||||
|
// Change these credentials to match your OCI user
|
||||||
|
const tenancyId = "ocid1.tenancy.oc1..example";
|
||||||
|
const userId = "ocid1.user.oc1..example";
|
||||||
|
const fingerprint = "00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00";
|
||||||
|
const region = "us-ashburn-1";
|
||||||
|
const privateKey = "..."; // Must be PEM format
|
||||||
|
|
||||||
|
const provider = new common.SimpleAuthenticationDetailsProvider(
|
||||||
|
tenancyId,
|
||||||
|
userId,
|
||||||
|
fingerprint,
|
||||||
|
privateKey,
|
||||||
|
null,
|
||||||
|
common.Region.fromRegionId(region),
|
||||||
|
);
|
||||||
|
|
||||||
|
// Build request
|
||||||
|
const headers = new Headers({
|
||||||
|
host: `identity.${region}.oraclecloud.com`,
|
||||||
|
});
|
||||||
|
|
||||||
|
const request: common.HttpRequest = {
|
||||||
|
method: "GET",
|
||||||
|
uri: `/20160918/users/${userId}`,
|
||||||
|
headers,
|
||||||
|
body: null,
|
||||||
|
};
|
||||||
|
|
||||||
|
// Sign request
|
||||||
|
const signer = new common.DefaultRequestSigner(provider);
|
||||||
|
await signer.signHttpRequest(request);
|
||||||
|
|
||||||
|
// Forward signed request to Infisical
|
||||||
|
const requestAsJson = {
|
||||||
|
identityId: "2dd11664-68e3-471d-b366-907206ab1bff",
|
||||||
|
userOcid: userId,
|
||||||
|
headers: Object.fromEntries(request.headers.entries()),
|
||||||
|
};
|
||||||
|
|
||||||
|
const res = await fetch("https://tunnel.util.lol/api/v1/auth/oci-auth/login", {
|
||||||
|
method: "POST",
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
},
|
||||||
|
body: JSON.stringify(requestAsJson),
|
||||||
|
});
|
||||||
|
|
||||||
|
const json = await res.json();
|
||||||
|
|
||||||
|
console.log("Infisical Response:", json);
|
||||||
|
```
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation; the default TTL is `7200` seconds, which can be adjusted.
|
||||||
|
|
||||||
|
If an identity access token expires, it can no longer access the Infisical API. A new access token should be obtained by performing another login operation.
|
||||||
|
</Note>
|
||||||
@@ -163,7 +163,7 @@ In the following steps, we explore how to create and use identities to access th
|
|||||||
}
|
}
|
||||||
```
|
```
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -159,7 +159,7 @@ In the following steps, we explore how to create and use identities to access th
|
|||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -159,7 +159,7 @@ In the following steps, we explore how to create and use identities to access th
|
|||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted.
|
the default TTL is `7200` seconds which can be adjusted.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -106,7 +106,7 @@ using the Token Auth authentication method.
|
|||||||
to authenticate with the [Infisical API](/api-reference/overview/introduction).
|
to authenticate with the [Infisical API](/api-reference/overview/introduction).
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted in the Token Auth configuration.
|
the default TTL is `7200` seconds which can be adjusted in the Token Auth configuration.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
@@ -144,7 +144,7 @@ using the Universal Auth authentication method.
|
|||||||
Next, you can use the access token to authenticate with the [Infisical API](/api-reference/overview/introduction)
|
Next, you can use the access token to authenticate with the [Infisical API](/api-reference/overview/introduction)
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Each identity access token has a time-to-live (TLL) which you can infer from the response of the login operation;
|
Each identity access token has a time-to-live (TTL) which you can infer from the response of the login operation;
|
||||||
the default TTL is `7200` seconds which can be adjusted in the Universal Auth configuration.
|
the default TTL is `7200` seconds which can be adjusted in the Universal Auth configuration.
|
||||||
|
|
||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
|
|||||||
|
After Width: | Height: | Size: 674 KiB |
|
Before Width: | Height: | Size: 410 KiB After Width: | Height: | Size: 590 KiB |
|
Before Width: | Height: | Size: 656 KiB After Width: | Height: | Size: 1.0 MiB |
|
Before Width: | Height: | Size: 534 KiB After Width: | Height: | Size: 666 KiB |
|
Before Width: | Height: | Size: 549 KiB After Width: | Height: | Size: 1.1 MiB |
|
After Width: | Height: | Size: 1.1 MiB |
|
Before Width: | Height: | Size: 414 KiB After Width: | Height: | Size: 579 KiB |
|
Before Width: | Height: | Size: 645 KiB After Width: | Height: | Size: 1.0 MiB |
@@ -299,14 +299,14 @@
|
|||||||
{
|
{
|
||||||
"group": "Machine Identities",
|
"group": "Machine Identities",
|
||||||
"pages": [
|
"pages": [
|
||||||
|
"documentation/platform/identities/aws-auth",
|
||||||
|
"documentation/platform/identities/azure-auth",
|
||||||
|
"documentation/platform/identities/gcp-auth",
|
||||||
|
"documentation/platform/identities/jwt-auth",
|
||||||
|
"documentation/platform/identities/kubernetes-auth",
|
||||||
|
"documentation/platform/identities/oci-auth",
|
||||||
"documentation/platform/identities/token-auth",
|
"documentation/platform/identities/token-auth",
|
||||||
"documentation/platform/identities/universal-auth",
|
"documentation/platform/identities/universal-auth",
|
||||||
"documentation/platform/identities/kubernetes-auth",
|
|
||||||
"documentation/platform/identities/gcp-auth",
|
|
||||||
"documentation/platform/identities/azure-auth",
|
|
||||||
"documentation/platform/identities/aws-auth",
|
|
||||||
"documentation/platform/identities/jwt-auth",
|
|
||||||
|
|
||||||
{
|
{
|
||||||
"group": "OIDC Auth",
|
"group": "OIDC Auth",
|
||||||
"pages": [
|
"pages": [
|
||||||
@@ -695,6 +695,16 @@
|
|||||||
"api-reference/endpoints/aws-auth/revoke"
|
"api-reference/endpoints/aws-auth/revoke"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"group": "OCI Auth",
|
||||||
|
"pages": [
|
||||||
|
"api-reference/endpoints/oci-auth/login",
|
||||||
|
"api-reference/endpoints/oci-auth/attach",
|
||||||
|
"api-reference/endpoints/oci-auth/retrieve",
|
||||||
|
"api-reference/endpoints/oci-auth/update",
|
||||||
|
"api-reference/endpoints/oci-auth/revoke"
|
||||||
|
]
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"group": "Azure Auth",
|
"group": "Azure Auth",
|
||||||
"pages": [
|
"pages": [
|
||||||
|
|||||||
@@ -47,10 +47,10 @@ export const ViewIdentityOciAuthContent = ({
|
|||||||
onEdit={() => handlePopUpOpen("identityAuthMethod")}
|
onEdit={() => handlePopUpOpen("identityAuthMethod")}
|
||||||
onDelete={onDelete}
|
onDelete={onDelete}
|
||||||
>
|
>
|
||||||
<IdentityAuthFieldDisplay label="Access Token TLL (seconds)">
|
<IdentityAuthFieldDisplay label="Access Token TTL (seconds)">
|
||||||
{data.accessTokenTTL}
|
{data.accessTokenTTL}
|
||||||
</IdentityAuthFieldDisplay>
|
</IdentityAuthFieldDisplay>
|
||||||
<IdentityAuthFieldDisplay label="Access Token Max TLL (seconds)">
|
<IdentityAuthFieldDisplay label="Access Token Max TTL (seconds)">
|
||||||
{data.accessTokenMaxTTL}
|
{data.accessTokenMaxTTL}
|
||||||
</IdentityAuthFieldDisplay>
|
</IdentityAuthFieldDisplay>
|
||||||
<IdentityAuthFieldDisplay label="Access Token Max Number of Uses">
|
<IdentityAuthFieldDisplay label="Access Token Max Number of Uses">
|
||||||
|
|||||||
@@ -61,7 +61,7 @@ const schema = z
|
|||||||
allowCustomKeyIds: z.boolean().optional().default(false)
|
allowCustomKeyIds: z.boolean().optional().default(false)
|
||||||
})
|
})
|
||||||
.refine((data) => ms(data.maxTTL) >= ms(data.ttl), {
|
.refine((data) => ms(data.maxTTL) >= ms(data.ttl), {
|
||||||
message: "Max TLL must be greater than or equal to TTL",
|
message: "Max TTL must be greater than or equal to TTL",
|
||||||
path: ["maxTTL"]
|
path: ["maxTTL"]
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||