mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat: improved api desc, added ping check before accepting stream
This commit is contained in:
@@ -1,10 +1,13 @@
|
||||
import { ForbiddenError } from "@casl/ability";
|
||||
import { RawAxiosRequestHeaders } from "axios";
|
||||
|
||||
import { SecretKeyEncoding } from "@app/db/schemas";
|
||||
import { request } from "@app/lib/config/request";
|
||||
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||
import { BadRequestError } from "@app/lib/errors";
|
||||
import { validateLocalIps } from "@app/lib/validator";
|
||||
|
||||
import { AUDIT_LOG_STREAM_TIMEOUT } from "../audit-log/audit-log-queue";
|
||||
import { TLicenseServiceFactory } from "../license/license-service";
|
||||
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
|
||||
import { TPermissionServiceFactory } from "../permission/permission-service";
|
||||
@@ -57,6 +60,21 @@ export const auditLogStreamServiceFactory = ({
|
||||
"Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams."
|
||||
});
|
||||
}
|
||||
|
||||
// testing connection first
|
||||
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
|
||||
if (token) headers.Authorization = `Bearer ${token}`;
|
||||
await request.post(
|
||||
url,
|
||||
{ ping: "ok" },
|
||||
{
|
||||
headers,
|
||||
// request timeout
|
||||
timeout: AUDIT_LOG_STREAM_TIMEOUT,
|
||||
// connection timeout
|
||||
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
|
||||
}
|
||||
);
|
||||
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
|
||||
const logStream = await auditLogStreamDAL.create({
|
||||
orgId: actorOrgId,
|
||||
@@ -99,6 +117,22 @@ export const auditLogStreamServiceFactory = ({
|
||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
||||
|
||||
if (url) validateLocalIps(url);
|
||||
|
||||
// testing connection first
|
||||
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
|
||||
if (token) headers.Authorization = `Bearer ${token}`;
|
||||
await request.post(
|
||||
url || logStream.url,
|
||||
{ ping: "ok" },
|
||||
{
|
||||
headers,
|
||||
// request timeout
|
||||
timeout: AUDIT_LOG_STREAM_TIMEOUT,
|
||||
// connection timeout
|
||||
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
|
||||
}
|
||||
);
|
||||
|
||||
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
|
||||
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
|
||||
url,
|
||||
|
||||
@@ -24,7 +24,7 @@ export type TAuditLogQueueServiceFactory = ReturnType<typeof auditLogQueueServic
|
||||
|
||||
// keep this timeout 5s it must be fast because else the queue will take time to finish
|
||||
// audit log is a crowded queue thus needs to be fast
|
||||
const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
|
||||
export const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
|
||||
export const auditLogQueueServiceFactory = ({
|
||||
auditLogDAL,
|
||||
queueService,
|
||||
|
||||
@@ -22,9 +22,9 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
|
||||
rbac: false,
|
||||
customRateLimits: false,
|
||||
customAlerts: false,
|
||||
auditLogs: false,
|
||||
auditLogsRetentionDays: 0,
|
||||
auditLogStreams: false,
|
||||
auditLogs: true,
|
||||
auditLogsRetentionDays: 3,
|
||||
auditLogStreams: true,
|
||||
auditLogStreamLimit: 3,
|
||||
samlSSO: false,
|
||||
scim: false,
|
||||
|
||||
@@ -617,12 +617,12 @@ export const INTEGRATION = {
|
||||
|
||||
export const AUDIT_LOG_STREAMS = {
|
||||
CREATE: {
|
||||
url: "The socket URL to push logs to.",
|
||||
token: "Authentication token from the logging provider"
|
||||
url: "The HTTP URL to push logs to.",
|
||||
token: "Authentication token for the external provider used for identification."
|
||||
},
|
||||
UPDATE: {
|
||||
id: "The ID of the audit log stream to update.",
|
||||
url: "The socket URL to push logs to.",
|
||||
url: "The HTTP URL to push logs to.",
|
||||
token: "Authentication token for the external provider used for identification."
|
||||
},
|
||||
DELETE: {
|
||||
|
||||
@@ -64,7 +64,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
|
||||
const handleFormSubmit = async ({ token, url }: TForm) => {
|
||||
if (isSubmitting) return;
|
||||
if (isEdit) {
|
||||
handleAuditLogStreamEdit({ token, url });
|
||||
await handleAuditLogStreamEdit({ token, url });
|
||||
return;
|
||||
}
|
||||
try {
|
||||
@@ -102,7 +102,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
|
||||
control={control}
|
||||
name="url"
|
||||
render={({ field, fieldState: { error } }) => (
|
||||
<FormControl label="URL" isError={Boolean(error?.message)} errorText={error?.message} helperText="The endpoint where Infisical logs should be sent to">
|
||||
<FormControl label="Endpoint URL" isError={Boolean(error?.message)} errorText={error?.message}>
|
||||
<Input {...field} />
|
||||
</FormControl>
|
||||
)}
|
||||
@@ -118,7 +118,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
|
||||
errorText={error?.message}
|
||||
helperText="The bearer token used to authenticate with the logging provider endpoint"
|
||||
>
|
||||
<Input {...field} />
|
||||
<Input {...field} type="password" />
|
||||
</FormControl>
|
||||
)}
|
||||
/>
|
||||
|
||||
Reference in New Issue
Block a user