feat: improved api desc, added ping check before accepting stream

This commit is contained in:
Akhil Mohan
2024-05-03 00:23:59 +05:30
parent 387c899193
commit d650fd68c0
5 changed files with 44 additions and 10 deletions
@@ -1,10 +1,13 @@
import { ForbiddenError } from "@casl/ability"; import { ForbiddenError } from "@casl/ability";
import { RawAxiosRequestHeaders } from "axios";
import { SecretKeyEncoding } from "@app/db/schemas"; import { SecretKeyEncoding } from "@app/db/schemas";
import { request } from "@app/lib/config/request";
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption"; import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
import { BadRequestError } from "@app/lib/errors"; import { BadRequestError } from "@app/lib/errors";
import { validateLocalIps } from "@app/lib/validator"; import { validateLocalIps } from "@app/lib/validator";
import { AUDIT_LOG_STREAM_TIMEOUT } from "../audit-log/audit-log-queue";
import { TLicenseServiceFactory } from "../license/license-service"; import { TLicenseServiceFactory } from "../license/license-service";
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission"; import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
import { TPermissionServiceFactory } from "../permission/permission-service"; import { TPermissionServiceFactory } from "../permission/permission-service";
@@ -57,6 +60,21 @@ export const auditLogStreamServiceFactory = ({
"Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams." "Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams."
}); });
} }
// testing connection first
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
if (token) headers.Authorization = `Bearer ${token}`;
await request.post(
url,
{ ping: "ok" },
{
headers,
// request timeout
timeout: AUDIT_LOG_STREAM_TIMEOUT,
// connection timeout
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
}
);
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined; const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
const logStream = await auditLogStreamDAL.create({ const logStream = await auditLogStreamDAL.create({
orgId: actorOrgId, orgId: actorOrgId,
@@ -99,6 +117,22 @@ export const auditLogStreamServiceFactory = ({
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
if (url) validateLocalIps(url); if (url) validateLocalIps(url);
// testing connection first
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
if (token) headers.Authorization = `Bearer ${token}`;
await request.post(
url || logStream.url,
{ ping: "ok" },
{
headers,
// request timeout
timeout: AUDIT_LOG_STREAM_TIMEOUT,
// connection timeout
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
}
);
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined; const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
const updatedLogStream = await auditLogStreamDAL.updateById(id, { const updatedLogStream = await auditLogStreamDAL.updateById(id, {
url, url,
@@ -24,7 +24,7 @@ export type TAuditLogQueueServiceFactory = ReturnType<typeof auditLogQueueServic
// keep this timeout 5s it must be fast because else the queue will take time to finish // keep this timeout 5s it must be fast because else the queue will take time to finish
// audit log is a crowded queue thus needs to be fast // audit log is a crowded queue thus needs to be fast
const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000; export const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
export const auditLogQueueServiceFactory = ({ export const auditLogQueueServiceFactory = ({
auditLogDAL, auditLogDAL,
queueService, queueService,
@@ -22,9 +22,9 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
rbac: false, rbac: false,
customRateLimits: false, customRateLimits: false,
customAlerts: false, customAlerts: false,
auditLogs: false, auditLogs: true,
auditLogsRetentionDays: 0, auditLogsRetentionDays: 3,
auditLogStreams: false, auditLogStreams: true,
auditLogStreamLimit: 3, auditLogStreamLimit: 3,
samlSSO: false, samlSSO: false,
scim: false, scim: false,
+3 -3
View File
@@ -617,12 +617,12 @@ export const INTEGRATION = {
export const AUDIT_LOG_STREAMS = { export const AUDIT_LOG_STREAMS = {
CREATE: { CREATE: {
url: "The socket URL to push logs to.", url: "The HTTP URL to push logs to.",
token: "Authentication token from the logging provider" token: "Authentication token for the external provider used for identification."
}, },
UPDATE: { UPDATE: {
id: "The ID of the audit log stream to update.", id: "The ID of the audit log stream to update.",
url: "The socket URL to push logs to.", url: "The HTTP URL to push logs to.",
token: "Authentication token for the external provider used for identification." token: "Authentication token for the external provider used for identification."
}, },
DELETE: { DELETE: {
@@ -64,7 +64,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
const handleFormSubmit = async ({ token, url }: TForm) => { const handleFormSubmit = async ({ token, url }: TForm) => {
if (isSubmitting) return; if (isSubmitting) return;
if (isEdit) { if (isEdit) {
handleAuditLogStreamEdit({ token, url }); await handleAuditLogStreamEdit({ token, url });
return; return;
} }
try { try {
@@ -102,7 +102,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
control={control} control={control}
name="url" name="url"
render={({ field, fieldState: { error } }) => ( render={({ field, fieldState: { error } }) => (
<FormControl label="URL" isError={Boolean(error?.message)} errorText={error?.message} helperText="The endpoint where Infisical logs should be sent to"> <FormControl label="Endpoint URL" isError={Boolean(error?.message)} errorText={error?.message}>
<Input {...field} /> <Input {...field} />
</FormControl> </FormControl>
)} )}
@@ -118,7 +118,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
errorText={error?.message} errorText={error?.message}
helperText="The bearer token used to authenticate with the logging provider endpoint" helperText="The bearer token used to authenticate with the logging provider endpoint"
> >
<Input {...field} /> <Input {...field} type="password" />
</FormControl> </FormControl>
)} )}
/> />