mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
Merge remote-tracking branch 'origin' into improve-service-accounts
This commit is contained in:
@@ -13,7 +13,7 @@ export const getJwtServiceSecret = () => infisical.get('JWT_SERVICE_SECRET')!;
|
|||||||
export const getJwtSignupLifetime = () => infisical.get('JWT_SIGNUP_LIFETIME')! || '15m';
|
export const getJwtSignupLifetime = () => infisical.get('JWT_SIGNUP_LIFETIME')! || '15m';
|
||||||
export const getJwtSignupSecret = () => infisical.get('JWT_SIGNUP_SECRET')!;
|
export const getJwtSignupSecret = () => infisical.get('JWT_SIGNUP_SECRET')!;
|
||||||
export const getMongoURL = () => infisical.get('MONGO_URL')!;
|
export const getMongoURL = () => infisical.get('MONGO_URL')!;
|
||||||
export const getNodeEnv = () => infisical.get('NODE_ENV')!;
|
export const getNodeEnv = () => infisical.get('NODE_ENV')! || 'production';
|
||||||
export const getVerboseErrorOutput = () => infisical.get('VERBOSE_ERROR_OUTPUT')! === 'true' && true;
|
export const getVerboseErrorOutput = () => infisical.get('VERBOSE_ERROR_OUTPUT')! === 'true' && true;
|
||||||
export const getLokiHost = () => infisical.get('LOKI_HOST')!;
|
export const getLokiHost = () => infisical.get('LOKI_HOST')!;
|
||||||
export const getClientIdAzure = () => infisical.get('CLIENT_ID_AZURE')!;
|
export const getClientIdAzure = () => infisical.get('CLIENT_ID_AZURE')!;
|
||||||
|
|||||||
@@ -560,9 +560,9 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
return tag ? tag.id : null;
|
return tag ? tag.id : null;
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
let secrets: ISecret[] = [];
|
let secrets: ISecret[] = [];
|
||||||
|
|
||||||
if (req.user) {
|
if (req.user) {
|
||||||
// case: client authorization is via JWT
|
// case: client authorization is via JWT
|
||||||
|
|
||||||
@@ -578,12 +578,12 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
let secretQuery: any;
|
let secretQuery: any;
|
||||||
if (tagNamesList != undefined && tagNamesList.length != 0) {
|
if (tagNamesList != undefined && tagNamesList.length != 0) {
|
||||||
const workspaceFromDB = await Tag.find({ workspace: workspaceId })
|
const workspaceFromDB = await Tag.find({ workspace: workspaceId })
|
||||||
|
|
||||||
const tagIds = _.map(tagNamesList, (tagName) => {
|
const tagIds = _.map(tagNamesList, (tagName) => {
|
||||||
const tag = _.find(workspaceFromDB, { slug: tagName });
|
const tag = _.find(workspaceFromDB, { slug: tagName });
|
||||||
return tag ? tag.id : null;
|
return tag ? tag.id : null;
|
||||||
});
|
});
|
||||||
|
|
||||||
secretQuery = {
|
secretQuery = {
|
||||||
workspace: workspaceId,
|
workspace: workspaceId,
|
||||||
environment,
|
environment,
|
||||||
@@ -608,15 +608,15 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
if (hasWriteOnlyAccess) {
|
if (hasWriteOnlyAccess) {
|
||||||
// (i.e. you don't get values to decrypt since you can only write)
|
// (i.e. you don't get values to decrypt since you can only write)
|
||||||
secrets = await Secret.find(secretQuery).select("secretKeyCiphertext secretKeyIV secretKeyTag")
|
secrets = await Secret.find(secretQuery).select("secretKeyCiphertext secretKeyIV secretKeyTag").populate("tags")
|
||||||
} else {
|
} else {
|
||||||
secrets = await Secret.find(secretQuery).populate("tags")
|
secrets = await Secret.find(secretQuery).populate("tags")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (req.serviceAccount || req.serviceTokenData) {
|
if (req.serviceAccount || req.serviceTokenData) {
|
||||||
// case: client authorization is either via service account or service token
|
// case: client authorization is either via service account or service token
|
||||||
|
|
||||||
secrets = await Secret.find({
|
secrets = await Secret.find({
|
||||||
workspace: new Types.ObjectId(workspaceId),
|
workspace: new Types.ObjectId(workspaceId),
|
||||||
environment,
|
environment,
|
||||||
@@ -625,7 +625,7 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
},
|
},
|
||||||
...(tagIds.length > 0 ? { tags: { $in: tagIds } } : {}),
|
...(tagIds.length > 0 ? { tags: { $in: tagIds } } : {}),
|
||||||
type: SECRET_SHARED
|
type: SECRET_SHARED
|
||||||
});
|
}).populate("tags");
|
||||||
}
|
}
|
||||||
|
|
||||||
const channel = getChannelFromUserAgent(req.headers['user-agent'])
|
const channel = getChannelFromUserAgent(req.headers['user-agent'])
|
||||||
@@ -638,7 +638,7 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
workspaceId: new Types.ObjectId(workspaceId as string),
|
workspaceId: new Types.ObjectId(workspaceId as string),
|
||||||
secretIds: secrets.map((n: any) => n._id)
|
secretIds: secrets.map((n: any) => n._id)
|
||||||
});
|
});
|
||||||
|
|
||||||
readAction && await EELogService.createLog({
|
readAction && await EELogService.createLog({
|
||||||
userId: req.user?._id,
|
userId: req.user?._id,
|
||||||
serviceAccountId: req.serviceAccount?._id,
|
serviceAccountId: req.serviceAccount?._id,
|
||||||
@@ -952,7 +952,7 @@ export const deleteSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
*/
|
*/
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
message: 'delete secrets!!'
|
message: 'delete secrets!!'
|
||||||
});
|
});
|
||||||
|
|||||||
+11
-11
@@ -148,7 +148,7 @@ const getAuthSTDPayload = async ({
|
|||||||
if (!isMatch) throw UnauthorizedRequestError({
|
if (!isMatch) throw UnauthorizedRequestError({
|
||||||
message: 'Failed to authenticate service token'
|
message: 'Failed to authenticate service token'
|
||||||
});
|
});
|
||||||
|
|
||||||
serviceTokenData = await ServiceTokenData
|
serviceTokenData = await ServiceTokenData
|
||||||
.findOneAndUpdate({
|
.findOneAndUpdate({
|
||||||
_id: new Types.ObjectId(TOKEN_IDENTIFIER)
|
_id: new Types.ObjectId(TOKEN_IDENTIFIER)
|
||||||
@@ -157,8 +157,8 @@ const getAuthSTDPayload = async ({
|
|||||||
}, {
|
}, {
|
||||||
new: true
|
new: true
|
||||||
})
|
})
|
||||||
.select('+encryptedKey +iv +tag');
|
.select('+encryptedKey +iv +tag').populate('user');
|
||||||
|
|
||||||
if (!serviceTokenData) throw ServiceTokenDataNotFoundError({ message: 'Failed to find service token data' });
|
if (!serviceTokenData) throw ServiceTokenDataNotFoundError({ message: 'Failed to find service token data' });
|
||||||
|
|
||||||
return serviceTokenData;
|
return serviceTokenData;
|
||||||
@@ -176,20 +176,20 @@ const getAuthSAAKPayload = async ({
|
|||||||
authTokenValue: string;
|
authTokenValue: string;
|
||||||
}) => {
|
}) => {
|
||||||
const [_, TOKEN_IDENTIFIER, TOKEN_SECRET] = <[string, string, string]>authTokenValue.split('.', 3);
|
const [_, TOKEN_IDENTIFIER, TOKEN_SECRET] = <[string, string, string]>authTokenValue.split('.', 3);
|
||||||
|
|
||||||
const serviceAccount = await ServiceAccount.findById(
|
const serviceAccount = await ServiceAccount.findById(
|
||||||
Buffer.from(TOKEN_IDENTIFIER, 'base64').toString('hex')
|
Buffer.from(TOKEN_IDENTIFIER, 'base64').toString('hex')
|
||||||
).select('+secretHash');
|
).select('+secretHash');
|
||||||
|
|
||||||
if (!serviceAccount) {
|
if (!serviceAccount) {
|
||||||
throw ServiceAccountNotFoundError({ message: 'Failed to find service account' });
|
throw ServiceAccountNotFoundError({ message: 'Failed to find service account' });
|
||||||
}
|
}
|
||||||
|
|
||||||
const result = await bcrypt.compare(TOKEN_SECRET, serviceAccount.secretHash);
|
const result = await bcrypt.compare(TOKEN_SECRET, serviceAccount.secretHash);
|
||||||
if (!result) throw UnauthorizedRequestError({
|
if (!result) throw UnauthorizedRequestError({
|
||||||
message: 'Failed to authenticate service account access key'
|
message: 'Failed to authenticate service account access key'
|
||||||
});
|
});
|
||||||
|
|
||||||
return serviceAccount;
|
return serviceAccount;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -208,7 +208,7 @@ const getAuthAPIKeyPayload = async ({
|
|||||||
|
|
||||||
let apiKeyData = await APIKeyData
|
let apiKeyData = await APIKeyData
|
||||||
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt')
|
.findById(TOKEN_IDENTIFIER, '+secretHash +expiresAt')
|
||||||
.populate<{user: IUser}>('user', '+publicKey');
|
.populate<{ user: IUser }>('user', '+publicKey');
|
||||||
|
|
||||||
if (!apiKeyData) {
|
if (!apiKeyData) {
|
||||||
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
|
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
|
||||||
@@ -232,13 +232,13 @@ const getAuthAPIKeyPayload = async ({
|
|||||||
}, {
|
}, {
|
||||||
new: true
|
new: true
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!apiKeyData) {
|
if (!apiKeyData) {
|
||||||
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
|
throw APIKeyDataNotFoundError({ message: 'Failed to find API key data' });
|
||||||
}
|
}
|
||||||
|
|
||||||
const user = await User.findById(apiKeyData.user).select('+publicKey');
|
const user = await User.findById(apiKeyData.user).select('+publicKey');
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
throw AccountNotFoundError({
|
throw AccountNotFoundError({
|
||||||
message: 'Failed to find user'
|
message: 'Failed to find user'
|
||||||
|
|||||||
@@ -230,19 +230,10 @@ type GetEncryptedSecretsV2Response struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type GetServiceTokenDetailsResponse struct {
|
type GetServiceTokenDetailsResponse struct {
|
||||||
ID string `json:"_id"`
|
ID string `json:"_id"`
|
||||||
Name string `json:"name"`
|
Name string `json:"name"`
|
||||||
Workspace string `json:"workspace"`
|
Workspace string `json:"workspace"`
|
||||||
Environment string `json:"environment"`
|
Environment string `json:"environment"`
|
||||||
User struct {
|
|
||||||
ID string `json:"_id"`
|
|
||||||
Email string `json:"email"`
|
|
||||||
CreatedAt time.Time `json:"createdAt"`
|
|
||||||
UpdatedAt time.Time `json:"updatedAt"`
|
|
||||||
V int `json:"__v"`
|
|
||||||
FirstName string `json:"firstName"`
|
|
||||||
LastName string `json:"lastName"`
|
|
||||||
} `json:"user"`
|
|
||||||
ExpiresAt time.Time `json:"expiresAt"`
|
ExpiresAt time.Time `json:"expiresAt"`
|
||||||
EncryptedKey string `json:"encryptedKey"`
|
EncryptedKey string `json:"encryptedKey"`
|
||||||
Iv string `json:"iv"`
|
Iv string `json:"iv"`
|
||||||
|
|||||||
@@ -28,6 +28,7 @@ Self-hosted Infisical allows you to maintain your sensitive information within y
|
|||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Helm Kubernetes">
|
<Tab title="Helm Kubernetes">
|
||||||
<Note>This deployment option is highly available</Note>
|
<Note>This deployment option is highly available</Note>
|
||||||
|
<iframe width="560" height="315" src="https://www.youtube.com/embed/ugJZSCcZaV8" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
|
||||||
|
|
||||||
**Prerequisites**
|
**Prerequisites**
|
||||||
- You have understanding of [Kubernetes](https://kubernetes.io/)
|
- You have understanding of [Kubernetes](https://kubernetes.io/)
|
||||||
|
|||||||
Reference in New Issue
Block a user