mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 08:28:22 +00:00
Merge pull request #4251 from Infisical/fix/azureOAuthSeparateEnvVars
Separate Azure OAuth env vars to different env variables for each app connection
This commit is contained in:
+11
-2
@@ -123,8 +123,17 @@ INF_APP_CONNECTION_GITHUB_RADAR_APP_WEBHOOK_SECRET=
|
|||||||
INF_APP_CONNECTION_GCP_SERVICE_ACCOUNT_CREDENTIAL=
|
INF_APP_CONNECTION_GCP_SERVICE_ACCOUNT_CREDENTIAL=
|
||||||
|
|
||||||
# azure app connection
|
# azure app connection
|
||||||
INF_APP_CONNECTION_AZURE_CLIENT_ID=
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID=
|
||||||
INF_APP_CONNECTION_AZURE_CLIENT_SECRET=
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET=
|
||||||
|
|
||||||
|
INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID=
|
||||||
|
INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET=
|
||||||
|
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID=
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET=
|
||||||
|
|
||||||
|
INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID=
|
||||||
|
INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET=
|
||||||
|
|
||||||
# datadog
|
# datadog
|
||||||
SHOULD_USE_DATADOG_TRACER=
|
SHOULD_USE_DATADOG_TRACER=
|
||||||
|
|||||||
@@ -261,10 +261,26 @@ const envSchema = z
|
|||||||
// gcp app
|
// gcp app
|
||||||
INF_APP_CONNECTION_GCP_SERVICE_ACCOUNT_CREDENTIAL: zpStr(z.string().optional()),
|
INF_APP_CONNECTION_GCP_SERVICE_ACCOUNT_CREDENTIAL: zpStr(z.string().optional()),
|
||||||
|
|
||||||
// azure app
|
// Legacy Single Multi Purpose Azure App Connection
|
||||||
INF_APP_CONNECTION_AZURE_CLIENT_ID: zpStr(z.string().optional()),
|
INF_APP_CONNECTION_AZURE_CLIENT_ID: zpStr(z.string().optional()),
|
||||||
INF_APP_CONNECTION_AZURE_CLIENT_SECRET: zpStr(z.string().optional()),
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRET: zpStr(z.string().optional()),
|
||||||
|
|
||||||
|
// Azure App Configuration App Connection
|
||||||
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID: zpStr(z.string().optional()),
|
||||||
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET: zpStr(z.string().optional()),
|
||||||
|
|
||||||
|
// Azure Key Vault App Connection
|
||||||
|
INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID: zpStr(z.string().optional()),
|
||||||
|
INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET: zpStr(z.string().optional()),
|
||||||
|
|
||||||
|
// Azure Client Secrets App Connection
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID: zpStr(z.string().optional()),
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET: zpStr(z.string().optional()),
|
||||||
|
|
||||||
|
// Azure DevOps App Connection
|
||||||
|
INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID: zpStr(z.string().optional()),
|
||||||
|
INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET: zpStr(z.string().optional()),
|
||||||
|
|
||||||
// datadog
|
// datadog
|
||||||
SHOULD_USE_DATADOG_TRACER: zodStrBool.default("false"),
|
SHOULD_USE_DATADOG_TRACER: zodStrBool.default("false"),
|
||||||
DATADOG_PROFILING_ENABLED: zodStrBool.default("false"),
|
DATADOG_PROFILING_ENABLED: zodStrBool.default("false"),
|
||||||
@@ -341,7 +357,23 @@ const envSchema = z
|
|||||||
isHsmConfigured:
|
isHsmConfigured:
|
||||||
Boolean(data.HSM_LIB_PATH) && Boolean(data.HSM_PIN) && Boolean(data.HSM_KEY_LABEL) && data.HSM_SLOT !== undefined,
|
Boolean(data.HSM_LIB_PATH) && Boolean(data.HSM_PIN) && Boolean(data.HSM_KEY_LABEL) && data.HSM_SLOT !== undefined,
|
||||||
samlDefaultOrgSlug: data.DEFAULT_SAML_ORG_SLUG,
|
samlDefaultOrgSlug: data.DEFAULT_SAML_ORG_SLUG,
|
||||||
SECRET_SCANNING_ORG_WHITELIST: data.SECRET_SCANNING_ORG_WHITELIST?.split(",")
|
SECRET_SCANNING_ORG_WHITELIST: data.SECRET_SCANNING_ORG_WHITELIST?.split(","),
|
||||||
|
INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID || data.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
||||||
|
INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET || data.INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID || data.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET || data.INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
||||||
|
INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID || data.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
||||||
|
INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET || data.INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
||||||
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID || data.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
||||||
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET:
|
||||||
|
data.INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET || data.INF_APP_CONNECTION_AZURE_CLIENT_SECRET
|
||||||
}));
|
}));
|
||||||
|
|
||||||
export type TEnvConfig = Readonly<z.infer<typeof envSchema>>;
|
export type TEnvConfig = Readonly<z.infer<typeof envSchema>>;
|
||||||
@@ -451,15 +483,54 @@ export const overwriteSchema: {
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
azure: {
|
azureAppConfiguration: {
|
||||||
name: "Azure",
|
name: "Azure App Configuration",
|
||||||
fields: [
|
fields: [
|
||||||
{
|
{
|
||||||
key: "INF_APP_CONNECTION_AZURE_CLIENT_ID",
|
key: "INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID",
|
||||||
description: "The Application (Client) ID of your Azure application."
|
description: "The Application (Client) ID of your Azure application."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
key: "INF_APP_CONNECTION_AZURE_CLIENT_SECRET",
|
key: "INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET",
|
||||||
|
description: "The Client Secret of your Azure application."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
azureKeyVault: {
|
||||||
|
name: "Azure Key Vault",
|
||||||
|
fields: [
|
||||||
|
{
|
||||||
|
key: "INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID",
|
||||||
|
description: "The Application (Client) ID of your Azure application."
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET",
|
||||||
|
description: "The Client Secret of your Azure application."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
azureClientSecrets: {
|
||||||
|
name: "Azure Client Secrets",
|
||||||
|
fields: [
|
||||||
|
{
|
||||||
|
key: "INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID",
|
||||||
|
description: "The Application (Client) ID of your Azure application."
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET",
|
||||||
|
description: "The Client Secret of your Azure application."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
azureDevOps: {
|
||||||
|
name: "Azure DevOps",
|
||||||
|
fields: [
|
||||||
|
{
|
||||||
|
key: "INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID",
|
||||||
|
description: "The Application (Client) ID of your Azure application."
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET",
|
||||||
description: "The Client Secret of your Azure application."
|
description: "The Client Secret of your Azure application."
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
+13
-6
@@ -14,13 +14,13 @@ import {
|
|||||||
} from "./azure-app-configuration-connection-types";
|
} from "./azure-app-configuration-connection-types";
|
||||||
|
|
||||||
export const getAzureAppConfigurationConnectionListItem = () => {
|
export const getAzureAppConfigurationConnectionListItem = () => {
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID } = getConfig();
|
||||||
|
|
||||||
return {
|
return {
|
||||||
name: "Azure App Configuration" as const,
|
name: "Azure App Configuration" as const,
|
||||||
app: AppConnection.AzureAppConfiguration as const,
|
app: AppConnection.AzureAppConfiguration as const,
|
||||||
methods: Object.values(AzureAppConfigurationConnectionMethod) as [AzureAppConfigurationConnectionMethod.OAuth],
|
methods: Object.values(AzureAppConfigurationConnectionMethod) as [AzureAppConfigurationConnectionMethod.OAuth],
|
||||||
oauthClientId: INF_APP_CONNECTION_AZURE_CLIENT_ID
|
oauthClientId: INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -29,9 +29,16 @@ export const validateAzureAppConfigurationConnectionCredentials = async (
|
|||||||
) => {
|
) => {
|
||||||
const { credentials: inputCredentials, method } = config;
|
const { credentials: inputCredentials, method } = config;
|
||||||
|
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID, INF_APP_CONNECTION_AZURE_CLIENT_SECRET, SITE_URL } = getConfig();
|
const {
|
||||||
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID,
|
||||||
|
INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET,
|
||||||
|
SITE_URL
|
||||||
|
} = getConfig();
|
||||||
|
|
||||||
if (!INF_APP_CONNECTION_AZURE_CLIENT_ID || !INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (
|
||||||
|
!INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID ||
|
||||||
|
!INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET
|
||||||
|
) {
|
||||||
throw new InternalServerError({
|
throw new InternalServerError({
|
||||||
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -47,8 +54,8 @@ export const validateAzureAppConfigurationConnectionCredentials = async (
|
|||||||
grant_type: "authorization_code",
|
grant_type: "authorization_code",
|
||||||
code: inputCredentials.code,
|
code: inputCredentials.code,
|
||||||
scope: `openid offline_access https://azconfig.io/.default`,
|
scope: `openid offline_access https://azconfig.io/.default`,
|
||||||
client_id: INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID,
|
||||||
client_secret: INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET,
|
||||||
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|||||||
+19
-9
@@ -23,7 +23,7 @@ import {
|
|||||||
} from "./azure-client-secrets-connection-types";
|
} from "./azure-client-secrets-connection-types";
|
||||||
|
|
||||||
export const getAzureClientSecretsConnectionListItem = () => {
|
export const getAzureClientSecretsConnectionListItem = () => {
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID } = getConfig();
|
||||||
|
|
||||||
return {
|
return {
|
||||||
name: "Azure Client Secrets" as const,
|
name: "Azure Client Secrets" as const,
|
||||||
@@ -32,7 +32,7 @@ export const getAzureClientSecretsConnectionListItem = () => {
|
|||||||
AzureClientSecretsConnectionMethod.OAuth,
|
AzureClientSecretsConnectionMethod.OAuth,
|
||||||
AzureClientSecretsConnectionMethod.ClientSecret
|
AzureClientSecretsConnectionMethod.ClientSecret
|
||||||
],
|
],
|
||||||
oauthClientId: INF_APP_CONNECTION_AZURE_CLIENT_ID
|
oauthClientId: INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -64,7 +64,10 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
const currentTime = Date.now();
|
const currentTime = Date.now();
|
||||||
switch (appConnection.method) {
|
switch (appConnection.method) {
|
||||||
case AzureClientSecretsConnectionMethod.OAuth:
|
case AzureClientSecretsConnectionMethod.OAuth:
|
||||||
if (!appCfg.INF_APP_CONNECTION_AZURE_CLIENT_ID || !appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (
|
||||||
|
!appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID ||
|
||||||
|
!appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET
|
||||||
|
) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Azure OAuth environment variables have not been configured`
|
message: `Azure OAuth environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -74,8 +77,8 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
new URLSearchParams({
|
new URLSearchParams({
|
||||||
grant_type: "refresh_token",
|
grant_type: "refresh_token",
|
||||||
scope: `openid offline_access https://graph.microsoft.com/.default`,
|
scope: `openid offline_access https://graph.microsoft.com/.default`,
|
||||||
client_id: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID,
|
||||||
client_secret: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET,
|
||||||
refresh_token: refreshToken
|
refresh_token: refreshToken
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
@@ -142,7 +145,11 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
export const validateAzureClientSecretsConnectionCredentials = async (config: TAzureClientSecretsConnectionConfig) => {
|
export const validateAzureClientSecretsConnectionCredentials = async (config: TAzureClientSecretsConnectionConfig) => {
|
||||||
const { credentials: inputCredentials, method } = config;
|
const { credentials: inputCredentials, method } = config;
|
||||||
|
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID, INF_APP_CONNECTION_AZURE_CLIENT_SECRET, SITE_URL } = getConfig();
|
const {
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID,
|
||||||
|
INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET,
|
||||||
|
SITE_URL
|
||||||
|
} = getConfig();
|
||||||
|
|
||||||
switch (method) {
|
switch (method) {
|
||||||
case AzureClientSecretsConnectionMethod.OAuth:
|
case AzureClientSecretsConnectionMethod.OAuth:
|
||||||
@@ -150,7 +157,10 @@ export const validateAzureClientSecretsConnectionCredentials = async (config: TA
|
|||||||
throw new InternalServerError({ message: "SITE_URL env var is required to complete Azure OAuth flow" });
|
throw new InternalServerError({ message: "SITE_URL env var is required to complete Azure OAuth flow" });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!INF_APP_CONNECTION_AZURE_CLIENT_ID || !INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (
|
||||||
|
!INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID ||
|
||||||
|
!INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET
|
||||||
|
) {
|
||||||
throw new InternalServerError({
|
throw new InternalServerError({
|
||||||
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -166,8 +176,8 @@ export const validateAzureClientSecretsConnectionCredentials = async (config: TA
|
|||||||
grant_type: "authorization_code",
|
grant_type: "authorization_code",
|
||||||
code: inputCredentials.code,
|
code: inputCredentials.code,
|
||||||
scope: `openid offline_access https://graph.microsoft.com/.default`,
|
scope: `openid offline_access https://graph.microsoft.com/.default`,
|
||||||
client_id: INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID,
|
||||||
client_secret: INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET,
|
||||||
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ import {
|
|||||||
} from "./azure-devops-types";
|
} from "./azure-devops-types";
|
||||||
|
|
||||||
export const getAzureDevopsConnectionListItem = () => {
|
export const getAzureDevopsConnectionListItem = () => {
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID } = getConfig();
|
||||||
|
|
||||||
return {
|
return {
|
||||||
name: "Azure DevOps" as const,
|
name: "Azure DevOps" as const,
|
||||||
@@ -32,7 +32,7 @@ export const getAzureDevopsConnectionListItem = () => {
|
|||||||
AzureDevOpsConnectionMethod.OAuth,
|
AzureDevOpsConnectionMethod.OAuth,
|
||||||
AzureDevOpsConnectionMethod.AccessToken
|
AzureDevOpsConnectionMethod.AccessToken
|
||||||
],
|
],
|
||||||
oauthClientId: INF_APP_CONNECTION_AZURE_CLIENT_ID
|
oauthClientId: INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -63,7 +63,7 @@ export const getAzureDevopsConnection = async (
|
|||||||
switch (appConnection.method) {
|
switch (appConnection.method) {
|
||||||
case AzureDevOpsConnectionMethod.OAuth:
|
case AzureDevOpsConnectionMethod.OAuth:
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
if (!appCfg.INF_APP_CONNECTION_AZURE_CLIENT_ID || !appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (!appCfg.INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID || !appCfg.INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Azure environment variables have not been configured`
|
message: `Azure environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -81,8 +81,8 @@ export const getAzureDevopsConnection = async (
|
|||||||
new URLSearchParams({
|
new URLSearchParams({
|
||||||
grant_type: "refresh_token",
|
grant_type: "refresh_token",
|
||||||
scope: `https://app.vssps.visualstudio.com/.default`,
|
scope: `https://app.vssps.visualstudio.com/.default`,
|
||||||
client_id: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: appCfg.INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID,
|
||||||
client_secret: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: appCfg.INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET,
|
||||||
refresh_token: refreshToken
|
refresh_token: refreshToken
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
@@ -119,7 +119,8 @@ export const getAzureDevopsConnection = async (
|
|||||||
export const validateAzureDevOpsConnectionCredentials = async (config: TAzureDevOpsConnectionConfig) => {
|
export const validateAzureDevOpsConnectionCredentials = async (config: TAzureDevOpsConnectionConfig) => {
|
||||||
const { credentials: inputCredentials, method } = config;
|
const { credentials: inputCredentials, method } = config;
|
||||||
|
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID, INF_APP_CONNECTION_AZURE_CLIENT_SECRET, SITE_URL } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID, INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET, SITE_URL } =
|
||||||
|
getConfig();
|
||||||
|
|
||||||
switch (method) {
|
switch (method) {
|
||||||
case AzureDevOpsConnectionMethod.OAuth:
|
case AzureDevOpsConnectionMethod.OAuth:
|
||||||
@@ -127,7 +128,7 @@ export const validateAzureDevOpsConnectionCredentials = async (config: TAzureDev
|
|||||||
throw new InternalServerError({ message: "SITE_URL env var is required to complete Azure OAuth flow" });
|
throw new InternalServerError({ message: "SITE_URL env var is required to complete Azure OAuth flow" });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!INF_APP_CONNECTION_AZURE_CLIENT_ID || !INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (!INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID || !INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET) {
|
||||||
throw new InternalServerError({
|
throw new InternalServerError({
|
||||||
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -144,8 +145,8 @@ export const validateAzureDevOpsConnectionCredentials = async (config: TAzureDev
|
|||||||
grant_type: "authorization_code",
|
grant_type: "authorization_code",
|
||||||
code: oauthCredentials.code,
|
code: oauthCredentials.code,
|
||||||
scope: `https://app.vssps.visualstudio.com/.default`,
|
scope: `https://app.vssps.visualstudio.com/.default`,
|
||||||
client_id: INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID,
|
||||||
client_secret: INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET,
|
||||||
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|||||||
+13
-9
@@ -26,7 +26,10 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">
|
||||||
) => {
|
) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
if (!appCfg.INF_APP_CONNECTION_AZURE_CLIENT_ID || !appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (
|
||||||
|
!appCfg.INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID ||
|
||||||
|
!appCfg.INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET
|
||||||
|
) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Azure environment variables have not been configured`
|
message: `Azure environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -57,8 +60,8 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
new URLSearchParams({
|
new URLSearchParams({
|
||||||
grant_type: "refresh_token",
|
grant_type: "refresh_token",
|
||||||
scope: `openid offline_access`,
|
scope: `openid offline_access`,
|
||||||
client_id: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: appCfg.INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID,
|
||||||
client_secret: appCfg.INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: appCfg.INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET,
|
||||||
refresh_token: credentials.refreshToken
|
refresh_token: credentials.refreshToken
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
@@ -92,22 +95,23 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
};
|
};
|
||||||
|
|
||||||
export const getAzureKeyVaultConnectionListItem = () => {
|
export const getAzureKeyVaultConnectionListItem = () => {
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID } = getConfig();
|
||||||
|
|
||||||
return {
|
return {
|
||||||
name: "Azure Key Vault" as const,
|
name: "Azure Key Vault" as const,
|
||||||
app: AppConnection.AzureKeyVault as const,
|
app: AppConnection.AzureKeyVault as const,
|
||||||
methods: Object.values(AzureKeyVaultConnectionMethod) as [AzureKeyVaultConnectionMethod.OAuth],
|
methods: Object.values(AzureKeyVaultConnectionMethod) as [AzureKeyVaultConnectionMethod.OAuth],
|
||||||
oauthClientId: INF_APP_CONNECTION_AZURE_CLIENT_ID
|
oauthClientId: INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
export const validateAzureKeyVaultConnectionCredentials = async (config: TAzureKeyVaultConnectionConfig) => {
|
export const validateAzureKeyVaultConnectionCredentials = async (config: TAzureKeyVaultConnectionConfig) => {
|
||||||
const { credentials: inputCredentials, method } = config;
|
const { credentials: inputCredentials, method } = config;
|
||||||
|
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID, INF_APP_CONNECTION_AZURE_CLIENT_SECRET, SITE_URL } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID, INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET, SITE_URL } =
|
||||||
|
getConfig();
|
||||||
|
|
||||||
if (!INF_APP_CONNECTION_AZURE_CLIENT_ID || !INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (!INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID || !INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET) {
|
||||||
throw new InternalServerError({
|
throw new InternalServerError({
|
||||||
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
||||||
});
|
});
|
||||||
@@ -123,8 +127,8 @@ export const validateAzureKeyVaultConnectionCredentials = async (config: TAzureK
|
|||||||
grant_type: "authorization_code",
|
grant_type: "authorization_code",
|
||||||
code: inputCredentials.code,
|
code: inputCredentials.code,
|
||||||
scope: `openid offline_access https://vault.azure.net/.default`,
|
scope: `openid offline_access https://vault.azure.net/.default`,
|
||||||
client_id: INF_APP_CONNECTION_AZURE_CLIENT_ID,
|
client_id: INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID,
|
||||||
client_secret: INF_APP_CONNECTION_AZURE_CLIENT_SECRET,
|
client_secret: INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET,
|
||||||
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
redirect_uri: `${SITE_URL}/organization/app-connections/azure/oauth/callback`
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -50,8 +50,8 @@ Infisical currently only supports one method for connecting to Azure, which is O
|
|||||||
|
|
||||||
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
||||||
|
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_APP_CONFIGURATION_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the Azure App Configuration connection.
|
Once added, restart your Infisical instance and use the Azure App Configuration connection.
|
||||||
</Step>
|
</Step>
|
||||||
|
|||||||
@@ -57,8 +57,8 @@ Infisical currently only supports one method for connecting to Azure, which is O
|
|||||||
|
|
||||||
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
||||||
|
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_CLIENT_SECRETS_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the Azure Client Secrets connection.
|
Once added, restart your Infisical instance and use the Azure Client Secrets connection.
|
||||||
</Step>
|
</Step>
|
||||||
|
|||||||
@@ -56,8 +56,8 @@ Infisical currently supports two methods for connecting to Azure DevOps, which a
|
|||||||
|
|
||||||
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
||||||
|
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_DEVOPS_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the Azure Client Secrets connection.
|
Once added, restart your Infisical instance and use the Azure Client Secrets connection.
|
||||||
</Step>
|
</Step>
|
||||||
|
|||||||
@@ -49,8 +49,8 @@ Infisical currently only supports one method for connecting to Azure, which is O
|
|||||||
|
|
||||||
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
Back in your Infisical instance, add two new environment variables for the credentials of your Azure application.
|
||||||
|
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_ID`: The **Application (Client) ID** of your Azure application.
|
||||||
- `INF_APP_CONNECTION_AZURE_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
- `INF_APP_CONNECTION_AZURE_KEY_VAULT_CLIENT_SECRET`: The **Client Secret** of your Azure application.
|
||||||
|
|
||||||
Once added, restart your Infisical instance and use the Azure Key Vault connection.
|
Once added, restart your Infisical instance and use the Azure Key Vault connection.
|
||||||
</Step>
|
</Step>
|
||||||
|
|||||||
Reference in New Issue
Block a user