mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Change Azure Client Secret Rotation to show app client id
This commit is contained in:
@@ -24,7 +24,7 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
> = (secretRotation, appConnectionDAL, kmsService) => {
|
||||
const {
|
||||
connection,
|
||||
parameters: { appId },
|
||||
parameters: { appId, clientId: clientIdParam },
|
||||
secretsMapping
|
||||
} = secretRotation;
|
||||
|
||||
@@ -64,7 +64,8 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
|
||||
return {
|
||||
clientSecret: data.secretText,
|
||||
clientId: data.keyId
|
||||
keyId: data.keyId,
|
||||
clientId: clientIdParam
|
||||
};
|
||||
} catch (error: unknown) {
|
||||
if (error instanceof AxiosError) {
|
||||
@@ -81,14 +82,14 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
/**
|
||||
* Revokes a client secret from the Azure app using its keyId.
|
||||
*/
|
||||
const revokeCredential = async (clientId: string) => {
|
||||
const revokeCredential = async (keyId: string) => {
|
||||
const accessToken = await getAzureConnectionAccessToken(connection.id, appConnectionDAL, kmsService);
|
||||
const endpoint = `${GRAPH_API_BASE}/applications/${appId}/removePassword`;
|
||||
|
||||
try {
|
||||
await request.post(
|
||||
endpoint,
|
||||
{ keyId: clientId },
|
||||
{ keyId },
|
||||
{
|
||||
headers: {
|
||||
Authorization: `Bearer ${accessToken}`,
|
||||
@@ -99,7 +100,7 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
} catch (error: unknown) {
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to remove client secret with keyId ${clientId} from app ${appId}: ${
|
||||
message: `Failed to remove client secret with keyId ${keyId} from app ${appId}: ${
|
||||
error.message || "Unknown error"
|
||||
}`
|
||||
});
|
||||
@@ -129,7 +130,7 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
) => {
|
||||
if (!credentials?.length) return callback();
|
||||
|
||||
await Promise.all(credentials.map(({ clientId }) => revokeCredential(clientId)));
|
||||
await Promise.all(credentials.map(({ keyId }) => revokeCredential(keyId)));
|
||||
return callback();
|
||||
};
|
||||
|
||||
@@ -141,9 +142,8 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
callback
|
||||
) => {
|
||||
const newCredentials = await $rotateClientSecret();
|
||||
|
||||
if (oldCredentials?.clientId) {
|
||||
await revokeCredential(oldCredentials.clientId);
|
||||
if (oldCredentials?.keyId) {
|
||||
await revokeCredential(oldCredentials.keyId);
|
||||
}
|
||||
|
||||
return callback(newCredentials);
|
||||
@@ -154,7 +154,10 @@ export const azureClientSecretRotationFactory: TRotationFactory<
|
||||
*/
|
||||
const getSecretsPayload: TRotationFactoryGetSecretsPayload<TAzureClientSecretRotationGeneratedCredentials> = ({
|
||||
clientSecret
|
||||
}) => [{ key: secretsMapping.clientSecret, value: clientSecret }];
|
||||
}) => [
|
||||
{ key: secretsMapping.clientSecret, value: clientSecret },
|
||||
{ key: secretsMapping.clientId, value: clientIdParam }
|
||||
];
|
||||
|
||||
return {
|
||||
issueCredentials,
|
||||
|
||||
@@ -13,7 +13,8 @@ import { AppConnection } from "@app/services/app-connection/app-connection-enums
|
||||
export const AzureClientSecretRotationGeneratedCredentialsSchema = z
|
||||
.object({
|
||||
clientId: z.string(),
|
||||
clientSecret: z.string()
|
||||
clientSecret: z.string(),
|
||||
keyId: z.string()
|
||||
})
|
||||
.array()
|
||||
.min(1)
|
||||
@@ -21,7 +22,8 @@ export const AzureClientSecretRotationGeneratedCredentialsSchema = z
|
||||
|
||||
const AzureClientSecretRotationParametersSchema = z.object({
|
||||
appId: z.string().trim().min(1, "App ID Required").describe(SecretRotations.PARAMETERS.AZURE_CLIENT_SECRET.appId),
|
||||
appName: z.string().trim().describe(SecretRotations.PARAMETERS.AZURE_CLIENT_SECRET.appName).optional()
|
||||
appName: z.string().trim().describe(SecretRotations.PARAMETERS.AZURE_CLIENT_SECRET.appName).optional(),
|
||||
clientId: z.string().trim().describe(SecretRotations.PARAMETERS.AZURE_CLIENT_SECRET.clientId)
|
||||
});
|
||||
|
||||
const AzureClientSecretRotationSecretsMappingSchema = z.object({
|
||||
|
||||
@@ -2089,7 +2089,8 @@ export const SecretRotations = {
|
||||
},
|
||||
AZURE_CLIENT_SECRET: {
|
||||
appId: "The ID of the Azure Application to rotate the client secret for.",
|
||||
appName: "The name of the Azure Application to rotate the client secret for."
|
||||
appName: "The name of the Azure Application to rotate the client secret for.",
|
||||
clientId: "The client ID of the Azure Application to rotate the client secret for."
|
||||
},
|
||||
LDAP_PASSWORD: {
|
||||
dn: "The Distinguished Name (DN) of the principal to rotate the password for."
|
||||
|
||||
Reference in New Issue
Block a user