mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 01:25:47 +00:00
fix(server): updated secret rotation to pick on db host in validation
This commit is contained in:
+2
-1
@@ -9,6 +9,7 @@ import jmespath from "jmespath";
|
|||||||
import knex from "knex";
|
import knex from "knex";
|
||||||
|
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
|
import { getDbConnectionHost } from "@app/lib/knex";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
|
|
||||||
import { TAssignOp, TDbProviderClients, TDirectAssignOp, THttpProviderFunction } from "../templates/types";
|
import { TAssignOp, TDbProviderClients, TDirectAssignOp, THttpProviderFunction } from "../templates/types";
|
||||||
@@ -89,7 +90,7 @@ export const secretRotationDbFn = async ({
|
|||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
|
|
||||||
const ssl = ca ? { rejectUnauthorized: false, ca } : undefined;
|
const ssl = ca ? { rejectUnauthorized: false, ca } : undefined;
|
||||||
if (host === "localhost" || host === "127.0.0.1" || appCfg.DB_CONNECTION_URI.includes(host))
|
if (host === "localhost" || host === "127.0.0.1" || getDbConnectionHost(appCfg.DB_CONNECTION_URI) === host)
|
||||||
throw new Error("Invalid db host");
|
throw new Error("Invalid db host");
|
||||||
|
|
||||||
const db = knex({
|
const db = knex({
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
import { URL } from "url"; // Import the URL class
|
||||||
|
|
||||||
|
export const getDbConnectionHost = (urlString: string) => {
|
||||||
|
try {
|
||||||
|
const url = new URL(urlString);
|
||||||
|
// Split hostname and port (if provided)
|
||||||
|
return url.hostname.split(":")[0];
|
||||||
|
} catch (error) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -4,6 +4,7 @@ import { Tables } from "knex/types/tables";
|
|||||||
|
|
||||||
import { DatabaseError } from "../errors";
|
import { DatabaseError } from "../errors";
|
||||||
|
|
||||||
|
export * from "./connection";
|
||||||
export * from "./join";
|
export * from "./join";
|
||||||
export * from "./select";
|
export * from "./select";
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user