Keep db update

This commit is contained in:
Fang-Pen Lin
2025-11-07 09:19:52 -08:00
parent e5db20d062
commit bba265d21e
2 changed files with 17 additions and 8 deletions
@@ -85,11 +85,11 @@ export async function up(knex: Knex): Promise<void> {
t.timestamp("expiresAt").notNullable(); t.timestamp("expiresAt").notNullable();
t.string("csr").nullable(); t.text("csr").nullable();
t.string("certificate").nullable(); t.text("certificate").nullable();
t.string("certificateChain").nullable(); t.text("certificateChain").nullable();
t.string("error").nullable(); t.text("error").nullable();
// Order status // Order status
t.string("status").notNullable(); // pending, ready, processing, valid, invalid t.string("status").notNullable(); // pending, ready, processing, valid, invalid
@@ -508,7 +508,7 @@ export const pkiAcmeServiceFactory = ({
throw new NotFoundError({ message: "ACME order not found" }); throw new NotFoundError({ message: "ACME order not found" });
} }
if (order.status === AcmeOrderStatus.Ready) { if (order.status === AcmeOrderStatus.Ready) {
order = await acmeOrderDAL.transaction(async (tx) => { const { order: updatedOrder, error } = await acmeOrderDAL.transaction(async (tx) => {
const order = (await acmeOrderDAL.findByIdForFinalization(orderId, tx))!; const order = (await acmeOrderDAL.findByIdForFinalization(orderId, tx))!;
// TODO: ideally, this should be doen with onRequest: verifyAuth([AuthMode.ACME_JWS_SIGNATURE]), instead // TODO: ideally, this should be doen with onRequest: verifyAuth([AuthMode.ACME_JWS_SIGNATURE]), instead
const { ownerOrgId: actorOrgId } = (await certificateProfileDAL.findByIdWithOwnerOrgId(profileId, tx))!; const { ownerOrgId: actorOrgId } = (await certificateProfileDAL.findByIdWithOwnerOrgId(profileId, tx))!;
@@ -521,6 +521,7 @@ export const pkiAcmeServiceFactory = ({
const { csr } = payload; const { csr } = payload;
// TODO: validate the CSR and return badCSR error if it's invalid // TODO: validate the CSR and return badCSR error if it's invalid
// TODO: this should be the same transaction? // TODO: this should be the same transaction?
let error: Error | undefined;
try { try {
const { certificate, certificateChain, certificateId } = const { certificate, certificateChain, certificateId } =
await certificateV3Service.signCertificateFromProfile({ await certificateV3Service.signCertificateFromProfile({
@@ -562,12 +563,20 @@ export const pkiAcmeServiceFactory = ({
// TODO: log the error // TODO: log the error
// TODO: audit log the error // TODO: audit log the error
if (error instanceof BadRequestError) { if (error instanceof BadRequestError) {
throw new AcmeBadCSRError({ detail: `Invalid CSR: ${error.message}` }); error = new AcmeBadCSRError({ detail: `Invalid CSR: ${error.message}` });
} else {
error = new AcmeServerInternalError({ detail: "Failed to sign certificate" });
} }
throw new AcmeServerInternalError({ detail: "Failed to sign certificate" });
} }
return await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId, tx); return {
order: (await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId, tx))!,
error
};
}); });
if (error) {
throw error;
}
order = updatedOrder;
} else if (order.status !== AcmeOrderStatus.Valid) { } else if (order.status !== AcmeOrderStatus.Valid) {
throw new AcmeOrderNotReadyError({ message: "ACME order is not ready" }); throw new AcmeOrderNotReadyError({ message: "ACME order is not ready" });
} }