mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 07:27:58 +00:00
Address PR comments for Azure Client Secret Rotation
This commit is contained in:
+2
-6
@@ -153,12 +153,8 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
|||||||
* Maps the generated credentials into the secret payload format.
|
* Maps the generated credentials into the secret payload format.
|
||||||
*/
|
*/
|
||||||
const getSecretsPayload: TRotationFactoryGetSecretsPayload<TAzureClientSecretRotationGeneratedCredentials> = ({
|
const getSecretsPayload: TRotationFactoryGetSecretsPayload<TAzureClientSecretRotationGeneratedCredentials> = ({
|
||||||
clientSecret,
|
clientSecret
|
||||||
clientId
|
}) => [{ key: secretsMapping.clientSecret, value: clientSecret }];
|
||||||
}) => [
|
|
||||||
{ key: secretsMapping.clientSecret, value: clientSecret },
|
|
||||||
{ key: secretsMapping.clientId, value: clientId }
|
|
||||||
];
|
|
||||||
|
|
||||||
return {
|
return {
|
||||||
issueCredentials,
|
issueCredentials,
|
||||||
|
|||||||
+1
-8
@@ -31,8 +31,6 @@ export const getAzureClientSecretsConnectionListItem = () => {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
const EXPIRATION_TIME = 300000;
|
|
||||||
|
|
||||||
export const getAzureConnectionAccessToken = async (
|
export const getAzureConnectionAccessToken = async (
|
||||||
connectionId: string,
|
connectionId: string,
|
||||||
appConnectionDAL: Pick<TAppConnectionDALFactory, "findById" | "updateById">,
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "findById" | "updateById">,
|
||||||
@@ -63,14 +61,9 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
encryptedCredentials: appConnection.encryptedCredentials
|
encryptedCredentials: appConnection.encryptedCredentials
|
||||||
})) as TAzureClientSecretsConnectionCredentials;
|
})) as TAzureClientSecretsConnectionCredentials;
|
||||||
|
|
||||||
const { expiresAt, refreshToken } = credentials;
|
const { refreshToken } = credentials;
|
||||||
const currentTime = Date.now();
|
const currentTime = Date.now();
|
||||||
|
|
||||||
// get new token if expired or less than 5 minutes until expiry
|
|
||||||
if (currentTime < expiresAt - EXPIRATION_TIME) {
|
|
||||||
return credentials.accessToken;
|
|
||||||
}
|
|
||||||
|
|
||||||
const { data } = await request.post<ExchangeCodeAzureResponse>(
|
const { data } = await request.post<ExchangeCodeAzureResponse>(
|
||||||
IntegrationUrls.AZURE_TOKEN_URL.replace("common", credentials.tenantId || "common"),
|
IntegrationUrls.AZURE_TOKEN_URL.replace("common", credentials.tenantId || "common"),
|
||||||
new URLSearchParams({
|
new URLSearchParams({
|
||||||
|
|||||||
@@ -36,13 +36,19 @@ Infisical currently only supports one method for connecting to Azure, which is O
|
|||||||
|
|
||||||
#### Azure Client Secrets permissions
|
#### Azure Client Secrets permissions
|
||||||
|
|
||||||
Set the API permissions of the Azure application to include the following Azure Client Secrets permissions:
|
Set the API permissions of the Azure application to include the following permissions:
|
||||||
- Microsoft Graph
|
- Microsoft Graph
|
||||||
- `Application.ReadWrite.All`
|
- `Application.ReadWrite.All`
|
||||||
|
- `Application.ReadWrite.OwnedBy`
|
||||||
|
- `Application.ReadWrite.All` (Delegated)
|
||||||
|
- `Directory.ReadWrite.All` (Delegated)
|
||||||
|
- `User.Read` (Delegated)
|
||||||
- Azure App Configuration
|
- Azure App Configuration
|
||||||
- `KeyValue.Delete`
|
- `KeyValue.Delete` (Delegated)
|
||||||
- `KeyValue.Read`
|
- `KeyValue.Read` (Delegated)
|
||||||
- `KeyValue.Write`
|
- `KeyValue.Write` (Delegated)
|
||||||
|
- Access Key Vault
|
||||||
|
- `user_impersonation` (Delegated)
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -19,7 +19,7 @@ export const ViewAzureClientSecretRotationGeneratedCredentials = ({
|
|||||||
<ViewRotationGeneratedCredentialsDisplay
|
<ViewRotationGeneratedCredentialsDisplay
|
||||||
activeCredentials={
|
activeCredentials={
|
||||||
<>
|
<>
|
||||||
<CredentialDisplay label="Client ID">{activeCredentials?.clientId}</CredentialDisplay>
|
<CredentialDisplay label="Secret ID">{activeCredentials?.clientId}</CredentialDisplay>
|
||||||
<CredentialDisplay isSensitive label="Client Secret">
|
<CredentialDisplay isSensitive label="Client Secret">
|
||||||
{activeCredentials?.clientSecret}
|
{activeCredentials?.clientSecret}
|
||||||
</CredentialDisplay>
|
</CredentialDisplay>
|
||||||
@@ -27,7 +27,7 @@ export const ViewAzureClientSecretRotationGeneratedCredentials = ({
|
|||||||
}
|
}
|
||||||
inactiveCredentials={
|
inactiveCredentials={
|
||||||
<>
|
<>
|
||||||
<CredentialDisplay label="Client ID">{inactiveCredentials?.clientId}</CredentialDisplay>
|
<CredentialDisplay label="Secret ID">{inactiveCredentials?.clientId}</CredentialDisplay>
|
||||||
<CredentialDisplay isSensitive label="Client Secret">
|
<CredentialDisplay isSensitive label="Client Secret">
|
||||||
{inactiveCredentials?.clientSecret}
|
{inactiveCredentials?.clientSecret}
|
||||||
</CredentialDisplay>
|
</CredentialDisplay>
|
||||||
|
|||||||
+5
-2
@@ -38,8 +38,11 @@ export const AzureClientSecretRotationParametersFields = () => {
|
|||||||
content={
|
content={
|
||||||
<>
|
<>
|
||||||
Ensure that your connection has the{" "}
|
Ensure that your connection has the{" "}
|
||||||
<span className="font-semibold">Application.ReadWrite.All</span> permission and
|
<span className="font-semibold">
|
||||||
the application exists in Azure.
|
Application.ReadWrite.All, Directory.ReadWrite.All,
|
||||||
|
Application.ReadWrite.OwnedBy, user_impersonation and User.Read
|
||||||
|
</span>{" "}
|
||||||
|
permissions and the application exists in Azure.
|
||||||
</>
|
</>
|
||||||
}
|
}
|
||||||
>
|
>
|
||||||
|
|||||||
-18
@@ -16,24 +16,6 @@ export const AzureClientSecretRotationSecretsMappingFields = () => {
|
|||||||
const { rotationOption } = useSecretRotationV2Option(SecretRotation.AzureClientSecret);
|
const { rotationOption } = useSecretRotationV2Option(SecretRotation.AzureClientSecret);
|
||||||
|
|
||||||
const items = [
|
const items = [
|
||||||
{
|
|
||||||
name: "Client ID",
|
|
||||||
input: (
|
|
||||||
<Controller
|
|
||||||
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
|
||||||
<FormControl isError={Boolean(error)} errorText={error?.message}>
|
|
||||||
<Input
|
|
||||||
value={value}
|
|
||||||
onChange={onChange}
|
|
||||||
placeholder={rotationOption?.template.secretsMapping.clientId}
|
|
||||||
/>
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
control={control}
|
|
||||||
name="secretsMapping.clientId"
|
|
||||||
/>
|
|
||||||
)
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
name: "Client Secret",
|
name: "Client Secret",
|
||||||
input: (
|
input: (
|
||||||
|
|||||||
Reference in New Issue
Block a user