mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 15:28:25 +00:00
Merge pull request #1286 from Infisical/identities-ipv6
Add IPv6 consideration to default universal auth IP allowlist
This commit is contained in:
@@ -550,7 +550,7 @@ export const attachIdentityUniversalAuth = async (req: Request, res: Response) =
|
|||||||
|
|
||||||
// validate trusted ips
|
// validate trusted ips
|
||||||
const reformattedClientSecretTrustedIps = clientSecretTrustedIps.map((clientSecretTrustedIp) => {
|
const reformattedClientSecretTrustedIps = clientSecretTrustedIps.map((clientSecretTrustedIp) => {
|
||||||
if (!plan.ipAllowlisting && clientSecretTrustedIp.ipAddress !== "0.0.0.0/0") return res.status(400).send({
|
if (!plan.ipAllowlisting && (clientSecretTrustedIp.ipAddress !== "0.0.0.0/0" && clientSecretTrustedIp.ipAddress !== "::/0")) return res.status(400).send({
|
||||||
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -564,7 +564,7 @@ export const attachIdentityUniversalAuth = async (req: Request, res: Response) =
|
|||||||
});
|
});
|
||||||
|
|
||||||
const reformattedAccessTokenTrustedIps = accessTokenTrustedIps.map((accessTokenTrustedIp) => {
|
const reformattedAccessTokenTrustedIps = accessTokenTrustedIps.map((accessTokenTrustedIp) => {
|
||||||
if (!plan.ipAllowlisting && accessTokenTrustedIp.ipAddress !== "0.0.0.0/0") return res.status(400).send({
|
if (!plan.ipAllowlisting && (accessTokenTrustedIp.ipAddress !== "0.0.0.0/0" && accessTokenTrustedIp.ipAddress !== "::/0")) return res.status(400).send({
|
||||||
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -750,7 +750,7 @@ export const updateIdentityUniversalAuth = async (req: Request, res: Response) =
|
|||||||
let reformattedClientSecretTrustedIps;
|
let reformattedClientSecretTrustedIps;
|
||||||
if (clientSecretTrustedIps) {
|
if (clientSecretTrustedIps) {
|
||||||
reformattedClientSecretTrustedIps = clientSecretTrustedIps.map((clientSecretTrustedIp) => {
|
reformattedClientSecretTrustedIps = clientSecretTrustedIps.map((clientSecretTrustedIp) => {
|
||||||
if (!plan.ipAllowlisting && clientSecretTrustedIp.ipAddress !== "0.0.0.0/0") return res.status(400).send({
|
if (!plan.ipAllowlisting && (clientSecretTrustedIp.ipAddress !== "0.0.0.0/0" && clientSecretTrustedIp.ipAddress !== "::/0")) return res.status(400).send({
|
||||||
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -767,7 +767,7 @@ export const updateIdentityUniversalAuth = async (req: Request, res: Response) =
|
|||||||
let reformattedAccessTokenTrustedIps;
|
let reformattedAccessTokenTrustedIps;
|
||||||
if (accessTokenTrustedIps) {
|
if (accessTokenTrustedIps) {
|
||||||
reformattedAccessTokenTrustedIps = accessTokenTrustedIps.map((accessTokenTrustedIp) => {
|
reformattedAccessTokenTrustedIps = accessTokenTrustedIps.map((accessTokenTrustedIp) => {
|
||||||
if (!plan.ipAllowlisting && accessTokenTrustedIp.ipAddress !== "0.0.0.0/0") return res.status(400).send({
|
if (!plan.ipAllowlisting && (accessTokenTrustedIp.ipAddress !== "0.0.0.0/0" && accessTokenTrustedIp.ipAddress !== "::/0")) return res.status(400).send({
|
||||||
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
message: "Failed to add IP access range to service token due to plan restriction. Upgrade plan to add IP access range."
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -108,14 +108,14 @@ export const AddUniversalAuthToIdentityV1 = z.object({
|
|||||||
})
|
})
|
||||||
.array()
|
.array()
|
||||||
.min(1)
|
.min(1)
|
||||||
.default([{ ipAddress: "0.0.0.0/0" }]),
|
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]),
|
||||||
accessTokenTrustedIps: z
|
accessTokenTrustedIps: z
|
||||||
.object({
|
.object({
|
||||||
ipAddress: z.string().trim(),
|
ipAddress: z.string().trim(),
|
||||||
})
|
})
|
||||||
.array()
|
.array()
|
||||||
.min(1)
|
.min(1)
|
||||||
.default([{ ipAddress: "0.0.0.0/0" }]),
|
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]),
|
||||||
accessTokenTTL: z.number().int().min(1).refine(value => value !== 0, {
|
accessTokenTTL: z.number().int().min(1).refine(value => value !== 0, {
|
||||||
message: "accessTokenTTL must have a non zero number",
|
message: "accessTokenTTL must have a non zero number",
|
||||||
}).default(2592000),
|
}).default(2592000),
|
||||||
|
|||||||
+16
-12
@@ -91,12 +91,14 @@ export const IdentityUniversalAuthForm = ({
|
|||||||
accessTokenTTL: "2592000",
|
accessTokenTTL: "2592000",
|
||||||
accessTokenMaxTTL: "2592000",
|
accessTokenMaxTTL: "2592000",
|
||||||
accessTokenNumUsesLimit: "0",
|
accessTokenNumUsesLimit: "0",
|
||||||
clientSecretTrustedIps: [{
|
clientSecretTrustedIps: [
|
||||||
ipAddress: "0.0.0.0/0"
|
{ ipAddress: "0.0.0.0/0" },
|
||||||
}],
|
{ ipAddress: "::/0" }
|
||||||
accessTokenTrustedIps: [{
|
],
|
||||||
ipAddress: "0.0.0.0/0"
|
accessTokenTrustedIps: [
|
||||||
}],
|
{ ipAddress: "0.0.0.0/0" },
|
||||||
|
{ ipAddress: "::/0" }
|
||||||
|
],
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -139,12 +141,14 @@ export const IdentityUniversalAuthForm = ({
|
|||||||
accessTokenTTL: "2592000",
|
accessTokenTTL: "2592000",
|
||||||
accessTokenMaxTTL: "2592000",
|
accessTokenMaxTTL: "2592000",
|
||||||
accessTokenNumUsesLimit: "0",
|
accessTokenNumUsesLimit: "0",
|
||||||
clientSecretTrustedIps: [{
|
clientSecretTrustedIps: [
|
||||||
ipAddress: "0.0.0.0/0"
|
{ ipAddress: "0.0.0.0/0" },
|
||||||
}],
|
{ ipAddress: "::/0" }
|
||||||
accessTokenTrustedIps: [{
|
],
|
||||||
ipAddress: "0.0.0.0/0"
|
accessTokenTrustedIps: [
|
||||||
}]
|
{ ipAddress: "0.0.0.0/0" },
|
||||||
|
{ ipAddress: "::/0" }
|
||||||
|
]
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}, [data]);
|
}, [data]);
|
||||||
|
|||||||
Reference in New Issue
Block a user