mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 20:27:12 +00:00
Merge pull request #4250 from Infisical/fix/oracle-db-rotation-failing
fix: potential fix for oracle db rotation failing
This commit is contained in:
+23
-6
@@ -7,12 +7,13 @@ import {
|
|||||||
TRotationFactoryRevokeCredentials,
|
TRotationFactoryRevokeCredentials,
|
||||||
TRotationFactoryRotateCredentials
|
TRotationFactoryRotateCredentials
|
||||||
} from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-types";
|
} from "@app/ee/services/secret-rotation-v2/secret-rotation-v2-types";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
import {
|
import {
|
||||||
executeWithPotentialGateway,
|
executeWithPotentialGateway,
|
||||||
SQL_CONNECTION_ALTER_LOGIN_STATEMENT
|
SQL_CONNECTION_ALTER_LOGIN_STATEMENT
|
||||||
} from "@app/services/app-connection/shared/sql";
|
} from "@app/services/app-connection/shared/sql";
|
||||||
|
|
||||||
import { generatePassword } from "../utils";
|
import { DEFAULT_PASSWORD_REQUIREMENTS, generatePassword } from "../utils";
|
||||||
import {
|
import {
|
||||||
TSqlCredentialsRotationGeneratedCredentials,
|
TSqlCredentialsRotationGeneratedCredentials,
|
||||||
TSqlCredentialsRotationWithConnection
|
TSqlCredentialsRotationWithConnection
|
||||||
@@ -32,6 +33,11 @@ const redactPasswords = (e: unknown, credentials: TSqlCredentialsRotationGenerat
|
|||||||
return redactedMessage;
|
return redactedMessage;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const ORACLE_PASSWORD_REQUIREMENTS = {
|
||||||
|
...DEFAULT_PASSWORD_REQUIREMENTS,
|
||||||
|
length: 30
|
||||||
|
};
|
||||||
|
|
||||||
export const sqlCredentialsRotationFactory: TRotationFactory<
|
export const sqlCredentialsRotationFactory: TRotationFactory<
|
||||||
TSqlCredentialsRotationWithConnection,
|
TSqlCredentialsRotationWithConnection,
|
||||||
TSqlCredentialsRotationGeneratedCredentials
|
TSqlCredentialsRotationGeneratedCredentials
|
||||||
@@ -43,6 +49,9 @@ export const sqlCredentialsRotationFactory: TRotationFactory<
|
|||||||
secretsMapping
|
secretsMapping
|
||||||
} = secretRotation;
|
} = secretRotation;
|
||||||
|
|
||||||
|
const passwordRequirement =
|
||||||
|
connection.app === AppConnection.OracleDB ? ORACLE_PASSWORD_REQUIREMENTS : DEFAULT_PASSWORD_REQUIREMENTS;
|
||||||
|
|
||||||
const executeOperation = <T>(
|
const executeOperation = <T>(
|
||||||
operation: (client: Knex) => Promise<T>,
|
operation: (client: Knex) => Promise<T>,
|
||||||
credentialsOverride?: TSqlCredentialsRotationGeneratedCredentials[number]
|
credentialsOverride?: TSqlCredentialsRotationGeneratedCredentials[number]
|
||||||
@@ -65,7 +74,7 @@ export const sqlCredentialsRotationFactory: TRotationFactory<
|
|||||||
const $validateCredentials = async (credentials: TSqlCredentialsRotationGeneratedCredentials[number]) => {
|
const $validateCredentials = async (credentials: TSqlCredentialsRotationGeneratedCredentials[number]) => {
|
||||||
try {
|
try {
|
||||||
await executeOperation(async (client) => {
|
await executeOperation(async (client) => {
|
||||||
await client.raw("SELECT 1");
|
await client.raw(connection.app === AppConnection.OracleDB ? `SELECT 1 FROM DUAL` : `Select 1`);
|
||||||
}, credentials);
|
}, credentials);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new Error(redactPasswords(error, [credentials]));
|
throw new Error(redactPasswords(error, [credentials]));
|
||||||
@@ -75,11 +84,13 @@ export const sqlCredentialsRotationFactory: TRotationFactory<
|
|||||||
const issueCredentials: TRotationFactoryIssueCredentials<TSqlCredentialsRotationGeneratedCredentials> = async (
|
const issueCredentials: TRotationFactoryIssueCredentials<TSqlCredentialsRotationGeneratedCredentials> = async (
|
||||||
callback
|
callback
|
||||||
) => {
|
) => {
|
||||||
|
// For SQL, since we get existing users, we change both their passwords
|
||||||
|
// on issue to invalidate their existing passwords
|
||||||
// For SQL, since we get existing users, we change both their passwords
|
// For SQL, since we get existing users, we change both their passwords
|
||||||
// on issue to invalidate their existing passwords
|
// on issue to invalidate their existing passwords
|
||||||
const credentialsSet = [
|
const credentialsSet = [
|
||||||
{ username: username1, password: generatePassword() },
|
{ username: username1, password: generatePassword(passwordRequirement) },
|
||||||
{ username: username2, password: generatePassword() }
|
{ username: username2, password: generatePassword(passwordRequirement) }
|
||||||
];
|
];
|
||||||
|
|
||||||
try {
|
try {
|
||||||
@@ -105,7 +116,10 @@ export const sqlCredentialsRotationFactory: TRotationFactory<
|
|||||||
credentialsToRevoke,
|
credentialsToRevoke,
|
||||||
callback
|
callback
|
||||||
) => {
|
) => {
|
||||||
const revokedCredentials = credentialsToRevoke.map(({ username }) => ({ username, password: generatePassword() }));
|
const revokedCredentials = credentialsToRevoke.map(({ username }) => ({
|
||||||
|
username,
|
||||||
|
password: generatePassword(passwordRequirement)
|
||||||
|
}));
|
||||||
|
|
||||||
try {
|
try {
|
||||||
await executeOperation(async (client) => {
|
await executeOperation(async (client) => {
|
||||||
@@ -128,7 +142,10 @@ export const sqlCredentialsRotationFactory: TRotationFactory<
|
|||||||
callback
|
callback
|
||||||
) => {
|
) => {
|
||||||
// generate new password for the next active user
|
// generate new password for the next active user
|
||||||
const credentials = { username: activeIndex === 0 ? username2 : username1, password: generatePassword() };
|
const credentials = {
|
||||||
|
username: activeIndex === 0 ? username2 : username1,
|
||||||
|
password: generatePassword(passwordRequirement)
|
||||||
|
};
|
||||||
|
|
||||||
try {
|
try {
|
||||||
await executeOperation(async (client) => {
|
await executeOperation(async (client) => {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ type TPasswordRequirements = {
|
|||||||
allowedSymbols?: string;
|
allowedSymbols?: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
const DEFAULT_PASSWORD_REQUIREMENTS: TPasswordRequirements = {
|
export const DEFAULT_PASSWORD_REQUIREMENTS: TPasswordRequirements = {
|
||||||
length: 48,
|
length: 48,
|
||||||
required: {
|
required: {
|
||||||
lowercase: 1,
|
lowercase: 1,
|
||||||
|
|||||||
Reference in New Issue
Block a user