mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 19:26:19 +00:00
misc: updated cli interactive to support mfa in org select
This commit is contained in:
@@ -137,6 +137,7 @@ type GetOrganizationsResponse struct {
|
|||||||
|
|
||||||
type SelectOrganizationResponse struct {
|
type SelectOrganizationResponse struct {
|
||||||
Token string `json:"token"`
|
Token string `json:"token"`
|
||||||
|
MfaEnabled bool `json:"isMfaEnabled"`
|
||||||
}
|
}
|
||||||
|
|
||||||
type SelectOrganizationRequest struct {
|
type SelectOrganizationRequest struct {
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ package cmd
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
"github.com/Infisical/infisical-merge/packages/api"
|
"github.com/Infisical/infisical-merge/packages/api"
|
||||||
"github.com/Infisical/infisical-merge/packages/models"
|
"github.com/Infisical/infisical-merge/packages/models"
|
||||||
@@ -75,6 +76,42 @@ var initCmd = &cobra.Command{
|
|||||||
selectedOrganization := organizations[index]
|
selectedOrganization := organizations[index]
|
||||||
|
|
||||||
tokenResponse, err := api.CallSelectOrganization(httpClient, api.SelectOrganizationRequest{OrganizationId: selectedOrganization.ID})
|
tokenResponse, err := api.CallSelectOrganization(httpClient, api.SelectOrganizationRequest{OrganizationId: selectedOrganization.ID})
|
||||||
|
if tokenResponse.MfaEnabled {
|
||||||
|
i := 1
|
||||||
|
for i < 6 {
|
||||||
|
mfaVerifyCode := askForMFACode()
|
||||||
|
|
||||||
|
httpClient := resty.New()
|
||||||
|
httpClient.SetAuthToken(tokenResponse.Token)
|
||||||
|
verifyMFAresponse, mfaErrorResponse, requestError := api.CallVerifyMfaToken(httpClient, api.VerifyMfaTokenRequest{
|
||||||
|
Email: userCreds.UserCredentials.Email,
|
||||||
|
MFAToken: mfaVerifyCode,
|
||||||
|
})
|
||||||
|
if requestError != nil {
|
||||||
|
util.HandleError(err)
|
||||||
|
break
|
||||||
|
} else if mfaErrorResponse != nil {
|
||||||
|
if mfaErrorResponse.Context.Code == "mfa_invalid" {
|
||||||
|
msg := fmt.Sprintf("Incorrect, verification code. You have %v attempts left", 5-i)
|
||||||
|
fmt.Println(msg)
|
||||||
|
if i == 5 {
|
||||||
|
util.PrintErrorMessageAndExit("No tries left, please try again in a bit")
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if mfaErrorResponse.Context.Code == "mfa_expired" {
|
||||||
|
util.PrintErrorMessageAndExit("Your 2FA verification code has expired, please try logging in again")
|
||||||
|
break
|
||||||
|
}
|
||||||
|
i++
|
||||||
|
} else {
|
||||||
|
httpClient.SetAuthToken(verifyMFAresponse.Token)
|
||||||
|
tokenResponse, err = api.CallSelectOrganization(httpClient, api.SelectOrganizationRequest{OrganizationId: selectedOrganization.ID})
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to select organization")
|
util.HandleError(err, "Unable to select organization")
|
||||||
|
|||||||
@@ -477,7 +477,7 @@ func cliDefaultLogin(userCredentialsToBeStored *models.UserCredentials) {
|
|||||||
util.PrintErrorMessageAndExit("We were unable to fetch required details to complete your login. Run with -d to see more info")
|
util.PrintErrorMessageAndExit("We were unable to fetch required details to complete your login. Run with -d to see more info")
|
||||||
}
|
}
|
||||||
// Login is successful so ask user to choose organization
|
// Login is successful so ask user to choose organization
|
||||||
newJwtToken := GetJwtTokenWithOrganizationId(loginTwoResponse.Token)
|
newJwtToken := GetJwtTokenWithOrganizationId(loginTwoResponse.Token, email)
|
||||||
|
|
||||||
//updating usercredentials
|
//updating usercredentials
|
||||||
userCredentialsToBeStored.Email = email
|
userCredentialsToBeStored.Email = email
|
||||||
@@ -710,7 +710,7 @@ func getFreshUserCredentials(email string, password string) (*api.GetLoginOneV2R
|
|||||||
return &loginOneResponseResult, &loginTwoResponseResult, nil
|
return &loginOneResponseResult, &loginTwoResponseResult, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func GetJwtTokenWithOrganizationId(oldJwtToken string) string {
|
func GetJwtTokenWithOrganizationId(oldJwtToken string, email string) string {
|
||||||
log.Debug().Msg(fmt.Sprint("GetJwtTokenWithOrganizationId: ", "oldJwtToken", oldJwtToken))
|
log.Debug().Msg(fmt.Sprint("GetJwtTokenWithOrganizationId: ", "oldJwtToken", oldJwtToken))
|
||||||
|
|
||||||
httpClient := resty.New()
|
httpClient := resty.New()
|
||||||
@@ -739,11 +739,51 @@ func GetJwtTokenWithOrganizationId(oldJwtToken string) string {
|
|||||||
selectedOrganization := organizations[index]
|
selectedOrganization := organizations[index]
|
||||||
|
|
||||||
selectedOrgRes, err := api.CallSelectOrganization(httpClient, api.SelectOrganizationRequest{OrganizationId: selectedOrganization.ID})
|
selectedOrgRes, err := api.CallSelectOrganization(httpClient, api.SelectOrganizationRequest{OrganizationId: selectedOrganization.ID})
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err)
|
util.HandleError(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if selectedOrgRes.MfaEnabled {
|
||||||
|
i := 1
|
||||||
|
for i < 6 {
|
||||||
|
mfaVerifyCode := askForMFACode()
|
||||||
|
|
||||||
|
httpClient := resty.New()
|
||||||
|
httpClient.SetAuthToken(selectedOrgRes.Token)
|
||||||
|
verifyMFAresponse, mfaErrorResponse, requestError := api.CallVerifyMfaToken(httpClient, api.VerifyMfaTokenRequest{
|
||||||
|
Email: email,
|
||||||
|
MFAToken: mfaVerifyCode,
|
||||||
|
})
|
||||||
|
if requestError != nil {
|
||||||
|
util.HandleError(err)
|
||||||
|
break
|
||||||
|
} else if mfaErrorResponse != nil {
|
||||||
|
if mfaErrorResponse.Context.Code == "mfa_invalid" {
|
||||||
|
msg := fmt.Sprintf("Incorrect, verification code. You have %v attempts left", 5-i)
|
||||||
|
fmt.Println(msg)
|
||||||
|
if i == 5 {
|
||||||
|
util.PrintErrorMessageAndExit("No tries left, please try again in a bit")
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if mfaErrorResponse.Context.Code == "mfa_expired" {
|
||||||
|
util.PrintErrorMessageAndExit("Your 2FA verification code has expired, please try logging in again")
|
||||||
|
break
|
||||||
|
}
|
||||||
|
i++
|
||||||
|
} else {
|
||||||
|
httpClient.SetAuthToken(verifyMFAresponse.Token)
|
||||||
|
selectedOrgRes, err = api.CallSelectOrganization(httpClient, api.SelectOrganizationRequest{OrganizationId: selectedOrganization.ID})
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
util.HandleError(err, "Unable to select organization")
|
||||||
|
}
|
||||||
|
|
||||||
return selectedOrgRes.Token
|
return selectedOrgRes.Token
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user