Return existing even if onlyReturnExisting is not set to ture while creating the new one

This commit is contained in:
Fang-Pen Lin
2025-11-20 09:38:08 -08:00
parent b50f03d4fb
commit d341dd0fb7
@@ -291,6 +291,7 @@ export const pkiAcmeServiceFactory = ({
url, url,
rawJwsPayload, rawJwsPayload,
getJWK: async (protectedHeader) => { getJWK: async (protectedHeader) => {
// get jwk instead of kid
if (!protectedHeader.kid) { if (!protectedHeader.kid) {
throw new AcmeMalformedError({ message: "KID is required in the protected header" }); throw new AcmeMalformedError({ message: "KID is required in the protected header" });
} }
@@ -394,16 +395,15 @@ export const pkiAcmeServiceFactory = ({
const profile = await validateAcmeProfile(profileId); const profile = await validateAcmeProfile(profileId);
const publicKeyThumbprint = await calculateJwkThumbprint(jwk, "sha256"); const publicKeyThumbprint = await calculateJwkThumbprint(jwk, "sha256");
const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByProfileIdAndPublicKeyThumbprintAndAlg(
profileId,
alg,
publicKeyThumbprint
);
if (onlyReturnExisting) { if (onlyReturnExisting) {
const existingAccount: TPkiAcmeAccounts | null = await acmeAccountDAL.findByProfileIdAndPublicKeyThumbprintAndAlg(
profileId,
alg,
publicKeyThumbprint
);
if (!existingAccount) { if (!existingAccount) {
throw new AcmeAccountDoesNotExistError({ message: "ACME account not found" }); throw new AcmeAccountDoesNotExistError({ message: "ACME account not found" });
} }
// With the same public key, we found an existing account, just return it
return { return {
status: 200, status: 200,
body: { body: {
@@ -433,6 +433,20 @@ export const pkiAcmeServiceFactory = ({
if (!externalAccountBinding) { if (!externalAccountBinding) {
throw new AcmeExternalAccountRequiredError({ message: "External account binding is required" }); throw new AcmeExternalAccountRequiredError({ message: "External account binding is required" });
} }
if (existingAccount) {
return {
status: 200,
body: {
status: "valid",
contact: existingAccount.emails,
orders: buildUrl(profile.id, `/accounts/${existingAccount.id}/orders`)
},
headers: {
Location: buildUrl(profile.id, `/accounts/${existingAccount.id}`),
Link: `<${buildUrl(profile.id, "/directory")}>;rel="index"`
}
};
}
const certificateManagerKmsId = await getProjectKmsCertificateKeyId({ const certificateManagerKmsId = await getProjectKmsCertificateKeyId({
projectId: profile.projectId, projectId: profile.projectId,