mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 02:26:19 +00:00
feat: added totp support for cli
This commit is contained in:
@@ -138,6 +138,7 @@ type GetOrganizationsResponse struct {
|
|||||||
type SelectOrganizationResponse struct {
|
type SelectOrganizationResponse struct {
|
||||||
Token string `json:"token"`
|
Token string `json:"token"`
|
||||||
MfaEnabled bool `json:"isMfaEnabled"`
|
MfaEnabled bool `json:"isMfaEnabled"`
|
||||||
|
MfaMethod string `json:"mfaMethod"`
|
||||||
}
|
}
|
||||||
|
|
||||||
type SelectOrganizationRequest struct {
|
type SelectOrganizationRequest struct {
|
||||||
@@ -260,8 +261,9 @@ type GetLoginTwoV2Response struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type VerifyMfaTokenRequest struct {
|
type VerifyMfaTokenRequest struct {
|
||||||
Email string `json:"email"`
|
Email string `json:"email"`
|
||||||
MFAToken string `json:"mfaToken"`
|
MFAToken string `json:"mfaToken"`
|
||||||
|
MFAMethod string `json:"mfaMethod"`
|
||||||
}
|
}
|
||||||
|
|
||||||
type VerifyMfaTokenResponse struct {
|
type VerifyMfaTokenResponse struct {
|
||||||
|
|||||||
@@ -79,13 +79,14 @@ var initCmd = &cobra.Command{
|
|||||||
if tokenResponse.MfaEnabled {
|
if tokenResponse.MfaEnabled {
|
||||||
i := 1
|
i := 1
|
||||||
for i < 6 {
|
for i < 6 {
|
||||||
mfaVerifyCode := askForMFACode()
|
mfaVerifyCode := askForMFACode(tokenResponse.MfaMethod)
|
||||||
|
|
||||||
httpClient := resty.New()
|
httpClient := resty.New()
|
||||||
httpClient.SetAuthToken(tokenResponse.Token)
|
httpClient.SetAuthToken(tokenResponse.Token)
|
||||||
verifyMFAresponse, mfaErrorResponse, requestError := api.CallVerifyMfaToken(httpClient, api.VerifyMfaTokenRequest{
|
verifyMFAresponse, mfaErrorResponse, requestError := api.CallVerifyMfaToken(httpClient, api.VerifyMfaTokenRequest{
|
||||||
Email: userCreds.UserCredentials.Email,
|
Email: userCreds.UserCredentials.Email,
|
||||||
MFAToken: mfaVerifyCode,
|
MFAToken: mfaVerifyCode,
|
||||||
|
MFAMethod: tokenResponse.MfaMethod,
|
||||||
})
|
})
|
||||||
if requestError != nil {
|
if requestError != nil {
|
||||||
util.HandleError(err)
|
util.HandleError(err)
|
||||||
@@ -99,7 +100,7 @@ var initCmd = &cobra.Command{
|
|||||||
break
|
break
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if mfaErrorResponse.Context.Code == "mfa_expired" {
|
if mfaErrorResponse.Context.Code == "mfa_expired" {
|
||||||
util.PrintErrorMessageAndExit("Your 2FA verification code has expired, please try logging in again")
|
util.PrintErrorMessageAndExit("Your 2FA verification code has expired, please try logging in again")
|
||||||
break
|
break
|
||||||
|
|||||||
@@ -343,7 +343,7 @@ func cliDefaultLogin(userCredentialsToBeStored *models.UserCredentials) {
|
|||||||
if loginTwoResponse.MfaEnabled {
|
if loginTwoResponse.MfaEnabled {
|
||||||
i := 1
|
i := 1
|
||||||
for i < 6 {
|
for i < 6 {
|
||||||
mfaVerifyCode := askForMFACode()
|
mfaVerifyCode := askForMFACode("email")
|
||||||
|
|
||||||
httpClient := resty.New()
|
httpClient := resty.New()
|
||||||
httpClient.SetAuthToken(loginTwoResponse.Token)
|
httpClient.SetAuthToken(loginTwoResponse.Token)
|
||||||
@@ -756,13 +756,14 @@ func GetJwtTokenWithOrganizationId(oldJwtToken string, email string) string {
|
|||||||
if selectedOrgRes.MfaEnabled {
|
if selectedOrgRes.MfaEnabled {
|
||||||
i := 1
|
i := 1
|
||||||
for i < 6 {
|
for i < 6 {
|
||||||
mfaVerifyCode := askForMFACode()
|
mfaVerifyCode := askForMFACode(selectedOrgRes.MfaMethod)
|
||||||
|
|
||||||
httpClient := resty.New()
|
httpClient := resty.New()
|
||||||
httpClient.SetAuthToken(selectedOrgRes.Token)
|
httpClient.SetAuthToken(selectedOrgRes.Token)
|
||||||
verifyMFAresponse, mfaErrorResponse, requestError := api.CallVerifyMfaToken(httpClient, api.VerifyMfaTokenRequest{
|
verifyMFAresponse, mfaErrorResponse, requestError := api.CallVerifyMfaToken(httpClient, api.VerifyMfaTokenRequest{
|
||||||
Email: email,
|
Email: email,
|
||||||
MFAToken: mfaVerifyCode,
|
MFAToken: mfaVerifyCode,
|
||||||
|
MFAMethod: selectedOrgRes.MfaMethod,
|
||||||
})
|
})
|
||||||
if requestError != nil {
|
if requestError != nil {
|
||||||
util.HandleError(err)
|
util.HandleError(err)
|
||||||
@@ -817,9 +818,15 @@ func generateFromPassword(password string, salt []byte, p *params) (hash []byte,
|
|||||||
return hash, nil
|
return hash, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func askForMFACode() string {
|
func askForMFACode(mfaMethod string) string {
|
||||||
|
var label string
|
||||||
|
if mfaMethod == "totp" {
|
||||||
|
label = "Enter the verification code from your mobile authenticator app or use a recovery code"
|
||||||
|
} else {
|
||||||
|
label = "Enter the 2FA verification code sent to your email"
|
||||||
|
}
|
||||||
mfaCodePromptUI := promptui.Prompt{
|
mfaCodePromptUI := promptui.Prompt{
|
||||||
Label: "Enter the 2FA verification code sent to your email",
|
Label: label,
|
||||||
}
|
}
|
||||||
|
|
||||||
mfaVerifyCode, err := mfaCodePromptUI.Run()
|
mfaVerifyCode, err := mfaCodePromptUI.Run()
|
||||||
|
|||||||
Reference in New Issue
Block a user