mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
misc: addressed review comments
This commit is contained in:
@@ -5,45 +5,49 @@ import { WebhookType } from "@app/services/webhook/webhook-types";
|
|||||||
import { TableName } from "../schemas";
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
export async function up(knex: Knex): Promise<void> {
|
||||||
const hasEncryptedURL = await knex.schema.hasColumn(TableName.Webhook, "encryptedUrl");
|
const hasUrlCipherText = await knex.schema.hasColumn(TableName.Webhook, "urlCipherText");
|
||||||
const hasUrlIV = await knex.schema.hasColumn(TableName.Webhook, "urlIV");
|
const hasUrlIV = await knex.schema.hasColumn(TableName.Webhook, "urlIV");
|
||||||
const hasUrlTag = await knex.schema.hasColumn(TableName.Webhook, "urlTag");
|
const hasUrlTag = await knex.schema.hasColumn(TableName.Webhook, "urlTag");
|
||||||
const hasType = await knex.schema.hasColumn(TableName.Webhook, "type");
|
const hasType = await knex.schema.hasColumn(TableName.Webhook, "type");
|
||||||
|
|
||||||
await knex.schema.alterTable(TableName.Webhook, (tb) => {
|
if (await knex.schema.hasTable(TableName.Webhook)) {
|
||||||
if (!hasEncryptedURL) {
|
await knex.schema.alterTable(TableName.Webhook, (tb) => {
|
||||||
tb.text("encryptedUrl");
|
if (!hasUrlCipherText) {
|
||||||
}
|
tb.text("urlCipherText");
|
||||||
if (!hasUrlIV) {
|
}
|
||||||
tb.string("urlIV");
|
if (!hasUrlIV) {
|
||||||
}
|
tb.string("urlIV");
|
||||||
if (!hasUrlTag) {
|
}
|
||||||
tb.string("urlTag");
|
if (!hasUrlTag) {
|
||||||
}
|
tb.string("urlTag");
|
||||||
if (!hasType) {
|
}
|
||||||
tb.string("type").defaultTo(WebhookType.GENERAL);
|
if (!hasType) {
|
||||||
}
|
tb.string("type").defaultTo(WebhookType.GENERAL);
|
||||||
});
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
export async function down(knex: Knex): Promise<void> {
|
||||||
const hasEncryptedURL = await knex.schema.hasColumn(TableName.Webhook, "encryptedUrl");
|
const hasUrlCipherText = await knex.schema.hasColumn(TableName.Webhook, "urlCipherText");
|
||||||
const hasUrlIV = await knex.schema.hasColumn(TableName.Webhook, "urlIV");
|
const hasUrlIV = await knex.schema.hasColumn(TableName.Webhook, "urlIV");
|
||||||
const hasUrlTag = await knex.schema.hasColumn(TableName.Webhook, "urlTag");
|
const hasUrlTag = await knex.schema.hasColumn(TableName.Webhook, "urlTag");
|
||||||
const hasType = await knex.schema.hasColumn(TableName.Webhook, "type");
|
const hasType = await knex.schema.hasColumn(TableName.Webhook, "type");
|
||||||
|
|
||||||
await knex.schema.alterTable(TableName.Webhook, (t) => {
|
if (await knex.schema.hasTable(TableName.Webhook)) {
|
||||||
if (hasEncryptedURL) {
|
await knex.schema.alterTable(TableName.Webhook, (t) => {
|
||||||
t.dropColumn("encryptedUrl");
|
if (hasUrlCipherText) {
|
||||||
}
|
t.dropColumn("urlCipherText");
|
||||||
if (hasUrlIV) {
|
}
|
||||||
t.dropColumn("urlIV");
|
if (hasUrlIV) {
|
||||||
}
|
t.dropColumn("urlIV");
|
||||||
if (hasUrlTag) {
|
}
|
||||||
t.dropColumn("urlTag");
|
if (hasUrlTag) {
|
||||||
}
|
t.dropColumn("urlTag");
|
||||||
if (hasType) {
|
}
|
||||||
t.dropColumn("type");
|
if (hasType) {
|
||||||
}
|
t.dropColumn("type");
|
||||||
});
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ export const WebhooksSchema = z.object({
|
|||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
updatedAt: z.date(),
|
updatedAt: z.date(),
|
||||||
envId: z.string().uuid(),
|
envId: z.string().uuid(),
|
||||||
encryptedUrl: z.string().nullable().optional(),
|
urlCipherText: z.string().nullable().optional(),
|
||||||
urlIV: z.string().nullable().optional(),
|
urlIV: z.string().nullable().optional(),
|
||||||
urlTag: z.string().nullable().optional(),
|
urlTag: z.string().nullable().optional(),
|
||||||
type: z.string().default("general").nullable().optional()
|
type: z.string().default("general").nullable().optional()
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ export const sanitizedWebhookSchema = WebhooksSchema.omit({
|
|||||||
tag: true,
|
tag: true,
|
||||||
algorithm: true,
|
algorithm: true,
|
||||||
keyEncoding: true,
|
keyEncoding: true,
|
||||||
encryptedUrl: true,
|
urlCipherText: true,
|
||||||
urlIV: true,
|
urlIV: true,
|
||||||
urlTag: true
|
urlTag: true
|
||||||
}).merge(
|
}).merge(
|
||||||
|
|||||||
@@ -4,9 +4,8 @@ import { AxiosError } from "axios";
|
|||||||
import picomatch from "picomatch";
|
import picomatch from "picomatch";
|
||||||
|
|
||||||
import { SecretKeyEncoding, TWebhooks } from "@app/db/schemas";
|
import { SecretKeyEncoding, TWebhooks } from "@app/db/schemas";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
|
||||||
import { request } from "@app/lib/config/request";
|
import { request } from "@app/lib/config/request";
|
||||||
import { decryptSymmetric, decryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
import { infisicalSymmetricDecrypt } from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
|
||||||
@@ -17,53 +16,27 @@ import { WebhookType } from "./webhook-types";
|
|||||||
const WEBHOOK_TRIGGER_TIMEOUT = 15 * 1000;
|
const WEBHOOK_TRIGGER_TIMEOUT = 15 * 1000;
|
||||||
|
|
||||||
export const decryptWebhookDetails = (webhook: TWebhooks) => {
|
export const decryptWebhookDetails = (webhook: TWebhooks) => {
|
||||||
const appCfg = getConfig();
|
const { keyEncoding, iv, encryptedSecretKey, tag, urlCipherText, urlIV, urlTag, url } = webhook;
|
||||||
const { keyEncoding, iv, encryptedSecretKey, tag, encryptedUrl, urlIV, urlTag, url } = webhook;
|
|
||||||
|
|
||||||
const encryptionKey = appCfg.ENCRYPTION_KEY;
|
|
||||||
const rootEncryptionKey = appCfg.ROOT_ENCRYPTION_KEY;
|
|
||||||
|
|
||||||
let decryptedSecretKey = "";
|
let decryptedSecretKey = "";
|
||||||
let decryptedUrl = url;
|
let decryptedUrl = url;
|
||||||
|
|
||||||
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
if (encryptedSecretKey) {
|
||||||
// case: encoding scheme is base64
|
decryptedSecretKey = infisicalSymmetricDecrypt({
|
||||||
if (encryptedSecretKey) {
|
keyEncoding: keyEncoding as SecretKeyEncoding,
|
||||||
decryptedSecretKey = decryptSymmetric({
|
ciphertext: encryptedSecretKey,
|
||||||
ciphertext: encryptedSecretKey,
|
iv: iv as string,
|
||||||
iv: iv as string,
|
tag: tag as string
|
||||||
tag: tag as string,
|
});
|
||||||
key: rootEncryptionKey
|
}
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (encryptedUrl) {
|
if (urlCipherText) {
|
||||||
decryptedUrl = decryptSymmetric({
|
decryptedUrl = infisicalSymmetricDecrypt({
|
||||||
ciphertext: encryptedUrl,
|
keyEncoding: keyEncoding as SecretKeyEncoding,
|
||||||
iv: urlIV as string,
|
ciphertext: urlCipherText,
|
||||||
tag: urlTag as string,
|
iv: urlIV as string,
|
||||||
key: rootEncryptionKey
|
tag: urlTag as string
|
||||||
});
|
});
|
||||||
}
|
|
||||||
} else if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
|
||||||
// case: encoding scheme is utf8
|
|
||||||
if (encryptedSecretKey) {
|
|
||||||
decryptedSecretKey = decryptSymmetric128BitHexKeyUTF8({
|
|
||||||
ciphertext: encryptedSecretKey,
|
|
||||||
iv: iv as string,
|
|
||||||
tag: tag as string,
|
|
||||||
key: encryptionKey
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (encryptedUrl) {
|
|
||||||
decryptedUrl = decryptSymmetric128BitHexKeyUTF8({
|
|
||||||
ciphertext: encryptedUrl,
|
|
||||||
iv: urlIV as string,
|
|
||||||
tag: urlTag as string,
|
|
||||||
key: encryptionKey
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
@@ -109,17 +82,17 @@ export const getWebhookPayload = (
|
|||||||
{
|
{
|
||||||
title: "Workspace ID",
|
title: "Workspace ID",
|
||||||
value: workspaceId,
|
value: workspaceId,
|
||||||
short: true
|
short: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
title: "Environment",
|
title: "Environment",
|
||||||
value: environment,
|
value: environment,
|
||||||
short: true
|
short: false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
title: "Secret Path",
|
title: "Secret Path",
|
||||||
value: secretPath,
|
value: secretPath,
|
||||||
short: true
|
short: false
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,10 +1,9 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
|
||||||
import { SecretEncryptionAlgo, SecretKeyEncoding, TWebhooksInsert } from "@app/db/schemas";
|
import { TWebhooksInsert } from "@app/db/schemas";
|
||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||||
import { encryptSymmetric, encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
|
||||||
import { TProjectEnvDALFactory } from "../project-env/project-env-dal";
|
import { TProjectEnvDALFactory } from "../project-env/project-env-dal";
|
||||||
@@ -39,10 +38,6 @@ export const webhookServiceFactory = ({ webhookDAL, projectEnvDAL, permissionSer
|
|||||||
webhookSecretKey,
|
webhookSecretKey,
|
||||||
type
|
type
|
||||||
}: TCreateWebhookDTO) => {
|
}: TCreateWebhookDTO) => {
|
||||||
const appCfg = getConfig();
|
|
||||||
const encryptionKey = appCfg.ENCRYPTION_KEY;
|
|
||||||
const rootEncryptionKey = appCfg.ROOT_ENCRYPTION_KEY;
|
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission(
|
const { permission } = await permissionService.getProjectPermission(
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -63,37 +58,21 @@ export const webhookServiceFactory = ({ webhookDAL, projectEnvDAL, permissionSer
|
|||||||
};
|
};
|
||||||
|
|
||||||
if (webhookSecretKey) {
|
if (webhookSecretKey) {
|
||||||
if (rootEncryptionKey) {
|
const { ciphertext, iv, tag, algorithm, encoding } = infisicalSymmetricEncypt(webhookSecretKey);
|
||||||
const { ciphertext, iv, tag } = encryptSymmetric(webhookSecretKey, rootEncryptionKey);
|
insertDoc.encryptedSecretKey = ciphertext;
|
||||||
insertDoc.encryptedSecretKey = ciphertext;
|
insertDoc.iv = iv;
|
||||||
insertDoc.iv = iv;
|
insertDoc.tag = tag;
|
||||||
insertDoc.tag = tag;
|
insertDoc.algorithm = algorithm;
|
||||||
insertDoc.algorithm = SecretEncryptionAlgo.AES_256_GCM;
|
insertDoc.keyEncoding = encoding;
|
||||||
insertDoc.keyEncoding = SecretKeyEncoding.BASE64;
|
|
||||||
} else if (encryptionKey) {
|
|
||||||
const { ciphertext, iv, tag } = encryptSymmetric128BitHexKeyUTF8(webhookSecretKey, encryptionKey);
|
|
||||||
insertDoc.encryptedSecretKey = ciphertext;
|
|
||||||
insertDoc.iv = iv;
|
|
||||||
insertDoc.tag = tag;
|
|
||||||
insertDoc.algorithm = SecretEncryptionAlgo.AES_256_GCM;
|
|
||||||
insertDoc.keyEncoding = SecretKeyEncoding.UTF8;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (rootEncryptionKey) {
|
if (webhookUrl) {
|
||||||
const { ciphertext, iv, tag } = encryptSymmetric(webhookUrl, rootEncryptionKey);
|
const { ciphertext, iv, tag, algorithm, encoding } = infisicalSymmetricEncypt(webhookUrl);
|
||||||
insertDoc.encryptedUrl = ciphertext;
|
insertDoc.urlCipherText = ciphertext;
|
||||||
insertDoc.urlIV = iv;
|
insertDoc.urlIV = iv;
|
||||||
insertDoc.urlTag = tag;
|
insertDoc.urlTag = tag;
|
||||||
insertDoc.algorithm = SecretEncryptionAlgo.AES_256_GCM;
|
insertDoc.algorithm = algorithm;
|
||||||
insertDoc.keyEncoding = SecretKeyEncoding.BASE64;
|
insertDoc.keyEncoding = encoding;
|
||||||
} else if (encryptionKey) {
|
|
||||||
const { ciphertext, iv, tag } = encryptSymmetric128BitHexKeyUTF8(webhookUrl, encryptionKey);
|
|
||||||
insertDoc.encryptedUrl = ciphertext;
|
|
||||||
insertDoc.urlIV = iv;
|
|
||||||
insertDoc.urlTag = tag;
|
|
||||||
insertDoc.algorithm = SecretEncryptionAlgo.AES_256_GCM;
|
|
||||||
insertDoc.keyEncoding = SecretKeyEncoding.UTF8;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
const webhook = await webhookDAL.create(insertDoc);
|
const webhook = await webhookDAL.create(insertDoc);
|
||||||
|
|||||||
@@ -1,5 +1,11 @@
|
|||||||
|
export enum WebhookType {
|
||||||
|
GENERAL = "general",
|
||||||
|
SLACK = "slack"
|
||||||
|
}
|
||||||
|
|
||||||
export type TWebhook = {
|
export type TWebhook = {
|
||||||
id: string;
|
id: string;
|
||||||
|
type: WebhookType;
|
||||||
projectId: string;
|
projectId: string;
|
||||||
environment: {
|
environment: {
|
||||||
slug: string;
|
slug: string;
|
||||||
@@ -22,6 +28,7 @@ export type TCreateWebhookDto = {
|
|||||||
webhookUrl: string;
|
webhookUrl: string;
|
||||||
webhookSecretKey?: string;
|
webhookSecretKey?: string;
|
||||||
secretPath: string;
|
secretPath: string;
|
||||||
|
type: WebhookType;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TUpdateWebhookDto = {
|
export type TUpdateWebhookDto = {
|
||||||
|
|||||||
@@ -14,11 +14,7 @@ import {
|
|||||||
SelectItem
|
SelectItem
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { SecretPathInput } from "@app/components/v2/SecretPathInput";
|
import { SecretPathInput } from "@app/components/v2/SecretPathInput";
|
||||||
|
import { WebhookType } from "@app/hooks/api/webhooks/types";
|
||||||
enum WebhookType {
|
|
||||||
GENERAL = "general",
|
|
||||||
SLACK = "slack"
|
|
||||||
}
|
|
||||||
|
|
||||||
const formSchema = z
|
const formSchema = z
|
||||||
.object({
|
.object({
|
||||||
@@ -116,7 +112,6 @@ export const AddWebhookForm = ({
|
|||||||
<Controller
|
<Controller
|
||||||
control={control}
|
control={control}
|
||||||
name="type"
|
name="type"
|
||||||
defaultValue={WebhookType.GENERAL}
|
|
||||||
render={({ field: { onChange, ...field }, fieldState: { error } }) => (
|
render={({ field: { onChange, ...field }, fieldState: { error } }) => (
|
||||||
<FormControl
|
<FormControl
|
||||||
label="Type"
|
label="Type"
|
||||||
|
|||||||
Reference in New Issue
Block a user