mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 01:26:20 +00:00
feat: applied hashed password change in change-password route
This commit is contained in:
@@ -51,7 +51,8 @@ export const registerPasswordRouter = async (server: FastifyZodProvider) => {
|
|||||||
encryptedPrivateKeyIV: z.string().trim(),
|
encryptedPrivateKeyIV: z.string().trim(),
|
||||||
encryptedPrivateKeyTag: z.string().trim(),
|
encryptedPrivateKeyTag: z.string().trim(),
|
||||||
salt: z.string().trim(),
|
salt: z.string().trim(),
|
||||||
verifier: z.string().trim()
|
verifier: z.string().trim(),
|
||||||
|
password: z.string().trim()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
|
|||||||
@@ -20,11 +20,20 @@ export const registerUserRouter = async (server: FastifyZodProvider) => {
|
|||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
user: UsersSchema.merge(
|
user: UsersSchema.merge(
|
||||||
UserEncryptionKeysSchema.omit({
|
UserEncryptionKeysSchema.pick({
|
||||||
|
clientPublicKey: true,
|
||||||
|
serverPrivateKey: true,
|
||||||
|
encryptionVersion: true,
|
||||||
|
protectedKey: true,
|
||||||
|
protectedKeyIV: true,
|
||||||
|
protectedKeyTag: true,
|
||||||
|
publicKey: true,
|
||||||
|
encryptedPrivateKey: true,
|
||||||
|
iv: true,
|
||||||
|
tag: true,
|
||||||
|
salt: true,
|
||||||
verifier: true,
|
verifier: true,
|
||||||
serverEncryptedPrivateKey: true,
|
userId: true
|
||||||
serverEncryptedPrivateKeyIV: true,
|
|
||||||
serverEncryptedPrivateKeyTag: true
|
|
||||||
})
|
})
|
||||||
)
|
)
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -255,7 +255,23 @@ export const registerUserRouter = async (server: FastifyZodProvider) => {
|
|||||||
description: "Retrieve the current user on the request",
|
description: "Retrieve the current user on the request",
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
user: UsersSchema.merge(UserEncryptionKeysSchema.omit({ verifier: true }))
|
user: UsersSchema.merge(
|
||||||
|
UserEncryptionKeysSchema.pick({
|
||||||
|
clientPublicKey: true,
|
||||||
|
serverPrivateKey: true,
|
||||||
|
encryptionVersion: true,
|
||||||
|
protectedKey: true,
|
||||||
|
protectedKeyIV: true,
|
||||||
|
protectedKeyTag: true,
|
||||||
|
publicKey: true,
|
||||||
|
encryptedPrivateKey: true,
|
||||||
|
iv: true,
|
||||||
|
tag: true,
|
||||||
|
salt: true,
|
||||||
|
verifier: true,
|
||||||
|
userId: true
|
||||||
|
})
|
||||||
|
)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import bcrypt from "bcrypt";
|
||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
|
|
||||||
import { SecretEncryptionAlgo, SecretKeyEncoding } from "@app/db/schemas";
|
import { SecretEncryptionAlgo, SecretKeyEncoding } from "@app/db/schemas";
|
||||||
@@ -57,7 +58,8 @@ export const authPaswordServiceFactory = ({
|
|||||||
encryptedPrivateKeyTag,
|
encryptedPrivateKeyTag,
|
||||||
salt,
|
salt,
|
||||||
verifier,
|
verifier,
|
||||||
tokenVersionId
|
tokenVersionId,
|
||||||
|
password
|
||||||
}: TChangePasswordDTO) => {
|
}: TChangePasswordDTO) => {
|
||||||
const userEnc = await userDAL.findUserEncKeyByUserId(userId);
|
const userEnc = await userDAL.findUserEncKeyByUserId(userId);
|
||||||
if (!userEnc) throw new Error("Failed to find user");
|
if (!userEnc) throw new Error("Failed to find user");
|
||||||
@@ -76,6 +78,8 @@ export const authPaswordServiceFactory = ({
|
|||||||
);
|
);
|
||||||
if (!isValidClientProof) throw new Error("Failed to authenticate. Try again?");
|
if (!isValidClientProof) throw new Error("Failed to authenticate. Try again?");
|
||||||
|
|
||||||
|
const appCfg = getConfig();
|
||||||
|
const hashedPassword = await bcrypt.hash(password, appCfg.BCRYPT_SALT_ROUND);
|
||||||
await userDAL.updateUserEncryptionByUserId(userId, {
|
await userDAL.updateUserEncryptionByUserId(userId, {
|
||||||
encryptionVersion: 2,
|
encryptionVersion: 2,
|
||||||
protectedKey,
|
protectedKey,
|
||||||
@@ -87,7 +91,8 @@ export const authPaswordServiceFactory = ({
|
|||||||
salt,
|
salt,
|
||||||
verifier,
|
verifier,
|
||||||
serverPrivateKey: null,
|
serverPrivateKey: null,
|
||||||
clientPublicKey: null
|
clientPublicKey: null,
|
||||||
|
password: hashedPassword
|
||||||
});
|
});
|
||||||
|
|
||||||
if (tokenVersionId) {
|
if (tokenVersionId) {
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ export type TChangePasswordDTO = {
|
|||||||
salt: string;
|
salt: string;
|
||||||
verifier: string;
|
verifier: string;
|
||||||
tokenVersionId?: string;
|
tokenVersionId?: string;
|
||||||
|
password: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TResetPasswordViaBackupKeyDTO = {
|
export type TResetPasswordViaBackupKeyDTO = {
|
||||||
|
|||||||
Generated
+726
-205
File diff suppressed because it is too large
Load Diff
@@ -72,6 +72,7 @@ const attemptChangePassword = ({ email, currentPassword, newPassword }: Params):
|
|||||||
});
|
});
|
||||||
|
|
||||||
await changePassword({
|
await changePassword({
|
||||||
|
password: newPassword,
|
||||||
clientProof,
|
clientProof,
|
||||||
protectedKey,
|
protectedKey,
|
||||||
protectedKeyIV,
|
protectedKeyIV,
|
||||||
|
|||||||
@@ -108,6 +108,7 @@ export type VerifySignupInviteDTO = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
export type ChangePasswordDTO = {
|
export type ChangePasswordDTO = {
|
||||||
|
password: string;
|
||||||
clientProof: string;
|
clientProof: string;
|
||||||
protectedKey: string;
|
protectedKey: string;
|
||||||
protectedKeyIV: string;
|
protectedKeyIV: string;
|
||||||
|
|||||||
Reference in New Issue
Block a user