mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 18:26:16 +00:00
misc: addressed review comments
This commit is contained in:
Vendored
+1
@@ -99,6 +99,7 @@ import {
|
|||||||
TIdentityGcpAuthsInsert,
|
TIdentityGcpAuthsInsert,
|
||||||
TIdentityGcpAuthsUpdate,
|
TIdentityGcpAuthsUpdate,
|
||||||
TIdentityJwtAuths,
|
TIdentityJwtAuths,
|
||||||
|
TIdentityJwtAuthsInsert,
|
||||||
TIdentityJwtAuthsUpdate,
|
TIdentityJwtAuthsUpdate,
|
||||||
TIdentityKubernetesAuths,
|
TIdentityKubernetesAuths,
|
||||||
TIdentityKubernetesAuthsInsert,
|
TIdentityKubernetesAuthsInsert,
|
||||||
|
|||||||
@@ -94,17 +94,17 @@ const UpdateBaseSchema = z
|
|||||||
.partial();
|
.partial();
|
||||||
|
|
||||||
const JwksConfigurationSchema = z.object({
|
const JwksConfigurationSchema = z.object({
|
||||||
configurationType: z.literal(JwtConfigurationType.JWKS),
|
configurationType: z.literal(JwtConfigurationType.JWKS).describe(JWT_AUTH.ATTACH.configurationType),
|
||||||
jwksUrl: z.string().trim().url(),
|
jwksUrl: z.string().trim().url().describe(JWT_AUTH.ATTACH.jwksUrl),
|
||||||
jwksCaCert: z.string().trim().default(""),
|
jwksCaCert: z.string().trim().default("").describe(JWT_AUTH.ATTACH.jwksCaCert),
|
||||||
publicKeys: z.string().array().optional().default([])
|
publicKeys: z.string().array().optional().default([]).describe(JWT_AUTH.ATTACH.publicKeys)
|
||||||
});
|
});
|
||||||
|
|
||||||
const StaticConfigurationSchema = z.object({
|
const StaticConfigurationSchema = z.object({
|
||||||
configurationType: z.literal(JwtConfigurationType.STATIC),
|
configurationType: z.literal(JwtConfigurationType.STATIC).describe(JWT_AUTH.ATTACH.configurationType),
|
||||||
jwksUrl: z.string().trim().optional().default(""),
|
jwksUrl: z.string().trim().optional().default("").describe(JWT_AUTH.ATTACH.jwksUrl),
|
||||||
jwksCaCert: z.string().trim().optional().default(""),
|
jwksCaCert: z.string().trim().optional().default("").describe(JWT_AUTH.ATTACH.jwksCaCert),
|
||||||
publicKeys: z.string().min(1).array().min(1)
|
publicKeys: z.string().min(1).array().min(1).describe(JWT_AUTH.ATTACH.publicKeys)
|
||||||
});
|
});
|
||||||
|
|
||||||
export const registerIdentityJwtAuthRouter = async (server: FastifyZodProvider) => {
|
export const registerIdentityJwtAuthRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -1,4 +1,9 @@
|
|||||||
import picomatch from "picomatch";
|
import picomatch from "picomatch";
|
||||||
|
|
||||||
export const doesFieldValueMatchJwtPolicy = (fieldValue: string, policyValue: string) =>
|
export const doesFieldValueMatchJwtPolicy = (fieldValue: string | boolean, policyValue: string) => {
|
||||||
policyValue === fieldValue || picomatch.isMatch(fieldValue, policyValue);
|
if (typeof fieldValue === "boolean") {
|
||||||
|
return fieldValue === (policyValue === "true");
|
||||||
|
}
|
||||||
|
|
||||||
|
return policyValue === fieldValue || picomatch.isMatch(fieldValue, policyValue);
|
||||||
|
};
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ export const identityJwtAuthServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
let tokenData: Record<string, string> = {};
|
let tokenData: Record<string, string | boolean> = {};
|
||||||
|
|
||||||
if (identityJwtAuth.configurationType === JwtConfigurationType.JWKS) {
|
if (identityJwtAuth.configurationType === JwtConfigurationType.JWKS) {
|
||||||
const decryptedJwksCaCert = orgDataKeyDecryptor({
|
const decryptedJwksCaCert = orgDataKeyDecryptor({
|
||||||
@@ -127,13 +127,7 @@ export const identityJwtAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (identityJwtAuth.boundIssuer) {
|
if (identityJwtAuth.boundIssuer) {
|
||||||
if (!tokenData.iss) {
|
if (tokenData.iss !== identityJwtAuth.boundIssuer) {
|
||||||
throw new UnauthorizedError({
|
|
||||||
message: "Access denied: token has no issuer field"
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!doesFieldValueMatchJwtPolicy(tokenData.iss, identityJwtAuth.boundIssuer)) {
|
|
||||||
throw new ForbiddenRequestError({
|
throw new ForbiddenRequestError({
|
||||||
message: "Access denied: issuer mismatch"
|
message: "Access denied: issuer mismatch"
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Attach"
|
||||||
|
openapi: "POST /api/v1/auth/jwt-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Login"
|
||||||
|
openapi: "POST /api/v1/auth/jwt-auth/login"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Retrieve"
|
||||||
|
openapi: "GET /api/v1/auth/jwt-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Revoke"
|
||||||
|
openapi: "DELETE /api/v1/auth/jwt-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Update"
|
||||||
|
openapi: "PATCH /api/v1/auth/jwt-auth/identities/{identityId}"
|
||||||
|
---
|
||||||
@@ -583,6 +583,16 @@
|
|||||||
"api-reference/endpoints/oidc-auth/revoke"
|
"api-reference/endpoints/oidc-auth/revoke"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"group": "JWT Auth",
|
||||||
|
"pages": [
|
||||||
|
"api-reference/endpoints/jwt-auth/login",
|
||||||
|
"api-reference/endpoints/jwt-auth/attach",
|
||||||
|
"api-reference/endpoints/jwt-auth/retrieve",
|
||||||
|
"api-reference/endpoints/jwt-auth/update",
|
||||||
|
"api-reference/endpoints/jwt-auth/revoke"
|
||||||
|
]
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"group": "Groups",
|
"group": "Groups",
|
||||||
"pages": [
|
"pages": [
|
||||||
|
|||||||
Reference in New Issue
Block a user