Merge remote-tracking branch 'origin' into improve-service-accounts

This commit is contained in:
Tuan Dang
2023-04-11 23:58:52 +03:00
5 changed files with 27 additions and 35 deletions
+1 -1
View File
@@ -13,7 +13,7 @@ export const getJwtServiceSecret = () => infisical.get('JWT_SERVICE_SECRET')!;
export const getJwtSignupLifetime = () => infisical.get('JWT_SIGNUP_LIFETIME')! || '15m'; export const getJwtSignupLifetime = () => infisical.get('JWT_SIGNUP_LIFETIME')! || '15m';
export const getJwtSignupSecret = () => infisical.get('JWT_SIGNUP_SECRET')!; export const getJwtSignupSecret = () => infisical.get('JWT_SIGNUP_SECRET')!;
export const getMongoURL = () => infisical.get('MONGO_URL')!; export const getMongoURL = () => infisical.get('MONGO_URL')!;
export const getNodeEnv = () => infisical.get('NODE_ENV')!; export const getNodeEnv = () => infisical.get('NODE_ENV')! || 'production';
export const getVerboseErrorOutput = () => infisical.get('VERBOSE_ERROR_OUTPUT')! === 'true' && true; export const getVerboseErrorOutput = () => infisical.get('VERBOSE_ERROR_OUTPUT')! === 'true' && true;
export const getLokiHost = () => infisical.get('LOKI_HOST')!; export const getLokiHost = () => infisical.get('LOKI_HOST')!;
export const getClientIdAzure = () => infisical.get('CLIENT_ID_AZURE')!; export const getClientIdAzure = () => infisical.get('CLIENT_ID_AZURE')!;
@@ -608,7 +608,7 @@ export const getSecrets = async (req: Request, res: Response) => {
if (hasWriteOnlyAccess) { if (hasWriteOnlyAccess) {
// (i.e. you don't get values to decrypt since you can only write) // (i.e. you don't get values to decrypt since you can only write)
secrets = await Secret.find(secretQuery).select("secretKeyCiphertext secretKeyIV secretKeyTag") secrets = await Secret.find(secretQuery).select("secretKeyCiphertext secretKeyIV secretKeyTag").populate("tags")
} else { } else {
secrets = await Secret.find(secretQuery).populate("tags") secrets = await Secret.find(secretQuery).populate("tags")
} }
@@ -625,7 +625,7 @@ export const getSecrets = async (req: Request, res: Response) => {
}, },
...(tagIds.length > 0 ? { tags: { $in: tagIds } } : {}), ...(tagIds.length > 0 ? { tags: { $in: tagIds } } : {}),
type: SECRET_SHARED type: SECRET_SHARED
}); }).populate("tags");
} }
const channel = getChannelFromUserAgent(req.headers['user-agent']) const channel = getChannelFromUserAgent(req.headers['user-agent'])
+2 -2
View File
@@ -157,7 +157,7 @@ const getAuthSTDPayload = async ({
}, { }, {
new: true new: true
}) })
.select('+encryptedKey +iv +tag'); .select('+encryptedKey +iv +tag').populate('user');
if (!serviceTokenData) throw ServiceTokenDataNotFoundError({ message: 'Failed to find service token data' }); if (!serviceTokenData) throw ServiceTokenDataNotFoundError({ message: 'Failed to find service token data' });
@@ -208,7 +208,7 @@ const getAuthAPIKeyPayload = async ({
let apiKeyData = await APIKeyData let apiKeyData = await APIKeyData
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt') .findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt')
.populate<{user: IUser}>('user', '+publicKey'); .populate<{ user: IUser }>('user', '+publicKey');
if (!apiKeyData) { if (!apiKeyData) {
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' }); throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
+4 -13
View File
@@ -230,19 +230,10 @@ type GetEncryptedSecretsV2Response struct {
} }
type GetServiceTokenDetailsResponse struct { type GetServiceTokenDetailsResponse struct {
ID string `json:"_id"` ID string `json:"_id"`
Name string `json:"name"` Name string `json:"name"`
Workspace string `json:"workspace"` Workspace string `json:"workspace"`
Environment string `json:"environment"` Environment string `json:"environment"`
User struct {
ID string `json:"_id"`
Email string `json:"email"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
V int `json:"__v"`
FirstName string `json:"firstName"`
LastName string `json:"lastName"`
} `json:"user"`
ExpiresAt time.Time `json:"expiresAt"` ExpiresAt time.Time `json:"expiresAt"`
EncryptedKey string `json:"encryptedKey"` EncryptedKey string `json:"encryptedKey"`
Iv string `json:"iv"` Iv string `json:"iv"`
+1
View File
@@ -28,6 +28,7 @@ Self-hosted Infisical allows you to maintain your sensitive information within y
</Tab> </Tab>
<Tab title="Helm Kubernetes"> <Tab title="Helm Kubernetes">
<Note>This deployment option is highly available</Note> <Note>This deployment option is highly available</Note>
<iframe width="560" height="315" src="https://www.youtube.com/embed/ugJZSCcZaV8" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
**Prerequisites** **Prerequisites**
- You have understanding of [Kubernetes](https://kubernetes.io/) - You have understanding of [Kubernetes](https://kubernetes.io/)