feat: improved api desc, added ping check before accepting stream

This commit is contained in:
Akhil Mohan
2024-05-03 00:21:49 +05:30
parent 387c899193
commit d650fd68c0
5 changed files with 44 additions and 10 deletions

View File

@@ -1,10 +1,13 @@
import { ForbiddenError } from "@casl/ability";
import { RawAxiosRequestHeaders } from "axios";
import { SecretKeyEncoding } from "@app/db/schemas";
import { request } from "@app/lib/config/request";
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
import { BadRequestError } from "@app/lib/errors";
import { validateLocalIps } from "@app/lib/validator";
import { AUDIT_LOG_STREAM_TIMEOUT } from "../audit-log/audit-log-queue";
import { TLicenseServiceFactory } from "../license/license-service";
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
import { TPermissionServiceFactory } from "../permission/permission-service";
@@ -57,6 +60,21 @@ export const auditLogStreamServiceFactory = ({
"Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams."
});
}
// testing connection first
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
if (token) headers.Authorization = `Bearer ${token}`;
await request.post(
url,
{ ping: "ok" },
{
headers,
// request timeout
timeout: AUDIT_LOG_STREAM_TIMEOUT,
// connection timeout
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
}
);
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
const logStream = await auditLogStreamDAL.create({
orgId: actorOrgId,
@@ -99,6 +117,22 @@ export const auditLogStreamServiceFactory = ({
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
if (url) validateLocalIps(url);
// testing connection first
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
if (token) headers.Authorization = `Bearer ${token}`;
await request.post(
url || logStream.url,
{ ping: "ok" },
{
headers,
// request timeout
timeout: AUDIT_LOG_STREAM_TIMEOUT,
// connection timeout
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
}
);
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
url,

View File

@@ -24,7 +24,7 @@ export type TAuditLogQueueServiceFactory = ReturnType<typeof auditLogQueueServic
// keep this timeout 5s it must be fast because else the queue will take time to finish
// audit log is a crowded queue thus needs to be fast
const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
export const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
export const auditLogQueueServiceFactory = ({
auditLogDAL,
queueService,

View File

@@ -22,9 +22,9 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
rbac: false,
customRateLimits: false,
customAlerts: false,
auditLogs: false,
auditLogsRetentionDays: 0,
auditLogStreams: false,
auditLogs: true,
auditLogsRetentionDays: 3,
auditLogStreams: true,
auditLogStreamLimit: 3,
samlSSO: false,
scim: false,

View File

@@ -617,12 +617,12 @@ export const INTEGRATION = {
export const AUDIT_LOG_STREAMS = {
CREATE: {
url: "The socket URL to push logs to.",
token: "Authentication token from the logging provider"
url: "The HTTP URL to push logs to.",
token: "Authentication token for the external provider used for identification."
},
UPDATE: {
id: "The ID of the audit log stream to update.",
url: "The socket URL to push logs to.",
url: "The HTTP URL to push logs to.",
token: "Authentication token for the external provider used for identification."
},
DELETE: {

View File

@@ -64,7 +64,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
const handleFormSubmit = async ({ token, url }: TForm) => {
if (isSubmitting) return;
if (isEdit) {
handleAuditLogStreamEdit({ token, url });
await handleAuditLogStreamEdit({ token, url });
return;
}
try {
@@ -102,7 +102,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
control={control}
name="url"
render={({ field, fieldState: { error } }) => (
<FormControl label="URL" isError={Boolean(error?.message)} errorText={error?.message} helperText="The endpoint where Infisical logs should be sent to">
<FormControl label="Endpoint URL" isError={Boolean(error?.message)} errorText={error?.message}>
<Input {...field} />
</FormControl>
)}
@@ -118,7 +118,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
errorText={error?.message}
helperText="The bearer token used to authenticate with the logging provider endpoint"
>
<Input {...field} />
<Input {...field} type="password" />
</FormControl>
)}
/>