mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 17:26:36 +00:00
feat: improved api desc, added ping check before accepting stream
This commit is contained in:
@@ -1,10 +1,13 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
import { RawAxiosRequestHeaders } from "axios";
|
||||||
|
|
||||||
import { SecretKeyEncoding } from "@app/db/schemas";
|
import { SecretKeyEncoding } from "@app/db/schemas";
|
||||||
|
import { request } from "@app/lib/config/request";
|
||||||
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { validateLocalIps } from "@app/lib/validator";
|
import { validateLocalIps } from "@app/lib/validator";
|
||||||
|
|
||||||
|
import { AUDIT_LOG_STREAM_TIMEOUT } from "../audit-log/audit-log-queue";
|
||||||
import { TLicenseServiceFactory } from "../license/license-service";
|
import { TLicenseServiceFactory } from "../license/license-service";
|
||||||
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
|
||||||
import { TPermissionServiceFactory } from "../permission/permission-service";
|
import { TPermissionServiceFactory } from "../permission/permission-service";
|
||||||
@@ -57,6 +60,21 @@ export const auditLogStreamServiceFactory = ({
|
|||||||
"Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams."
|
"Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// testing connection first
|
||||||
|
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
|
||||||
|
if (token) headers.Authorization = `Bearer ${token}`;
|
||||||
|
await request.post(
|
||||||
|
url,
|
||||||
|
{ ping: "ok" },
|
||||||
|
{
|
||||||
|
headers,
|
||||||
|
// request timeout
|
||||||
|
timeout: AUDIT_LOG_STREAM_TIMEOUT,
|
||||||
|
// connection timeout
|
||||||
|
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
|
||||||
|
}
|
||||||
|
);
|
||||||
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
|
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
|
||||||
const logStream = await auditLogStreamDAL.create({
|
const logStream = await auditLogStreamDAL.create({
|
||||||
orgId: actorOrgId,
|
orgId: actorOrgId,
|
||||||
@@ -99,6 +117,22 @@ export const auditLogStreamServiceFactory = ({
|
|||||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
||||||
|
|
||||||
if (url) validateLocalIps(url);
|
if (url) validateLocalIps(url);
|
||||||
|
|
||||||
|
// testing connection first
|
||||||
|
const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" };
|
||||||
|
if (token) headers.Authorization = `Bearer ${token}`;
|
||||||
|
await request.post(
|
||||||
|
url || logStream.url,
|
||||||
|
{ ping: "ok" },
|
||||||
|
{
|
||||||
|
headers,
|
||||||
|
// request timeout
|
||||||
|
timeout: AUDIT_LOG_STREAM_TIMEOUT,
|
||||||
|
// connection timeout
|
||||||
|
signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT)
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
|
const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined;
|
||||||
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
|
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
|
||||||
url,
|
url,
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ export type TAuditLogQueueServiceFactory = ReturnType<typeof auditLogQueueServic
|
|||||||
|
|
||||||
// keep this timeout 5s it must be fast because else the queue will take time to finish
|
// keep this timeout 5s it must be fast because else the queue will take time to finish
|
||||||
// audit log is a crowded queue thus needs to be fast
|
// audit log is a crowded queue thus needs to be fast
|
||||||
const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
|
export const AUDIT_LOG_STREAM_TIMEOUT = 5 * 1000;
|
||||||
export const auditLogQueueServiceFactory = ({
|
export const auditLogQueueServiceFactory = ({
|
||||||
auditLogDAL,
|
auditLogDAL,
|
||||||
queueService,
|
queueService,
|
||||||
|
|||||||
@@ -22,9 +22,9 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
|
|||||||
rbac: false,
|
rbac: false,
|
||||||
customRateLimits: false,
|
customRateLimits: false,
|
||||||
customAlerts: false,
|
customAlerts: false,
|
||||||
auditLogs: false,
|
auditLogs: true,
|
||||||
auditLogsRetentionDays: 0,
|
auditLogsRetentionDays: 3,
|
||||||
auditLogStreams: false,
|
auditLogStreams: true,
|
||||||
auditLogStreamLimit: 3,
|
auditLogStreamLimit: 3,
|
||||||
samlSSO: false,
|
samlSSO: false,
|
||||||
scim: false,
|
scim: false,
|
||||||
|
|||||||
@@ -617,12 +617,12 @@ export const INTEGRATION = {
|
|||||||
|
|
||||||
export const AUDIT_LOG_STREAMS = {
|
export const AUDIT_LOG_STREAMS = {
|
||||||
CREATE: {
|
CREATE: {
|
||||||
url: "The socket URL to push logs to.",
|
url: "The HTTP URL to push logs to.",
|
||||||
token: "Authentication token from the logging provider"
|
token: "Authentication token for the external provider used for identification."
|
||||||
},
|
},
|
||||||
UPDATE: {
|
UPDATE: {
|
||||||
id: "The ID of the audit log stream to update.",
|
id: "The ID of the audit log stream to update.",
|
||||||
url: "The socket URL to push logs to.",
|
url: "The HTTP URL to push logs to.",
|
||||||
token: "Authentication token for the external provider used for identification."
|
token: "Authentication token for the external provider used for identification."
|
||||||
},
|
},
|
||||||
DELETE: {
|
DELETE: {
|
||||||
|
|||||||
+3
-3
@@ -64,7 +64,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
|
|||||||
const handleFormSubmit = async ({ token, url }: TForm) => {
|
const handleFormSubmit = async ({ token, url }: TForm) => {
|
||||||
if (isSubmitting) return;
|
if (isSubmitting) return;
|
||||||
if (isEdit) {
|
if (isEdit) {
|
||||||
handleAuditLogStreamEdit({ token, url });
|
await handleAuditLogStreamEdit({ token, url });
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
try {
|
try {
|
||||||
@@ -102,7 +102,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
|
|||||||
control={control}
|
control={control}
|
||||||
name="url"
|
name="url"
|
||||||
render={({ field, fieldState: { error } }) => (
|
render={({ field, fieldState: { error } }) => (
|
||||||
<FormControl label="URL" isError={Boolean(error?.message)} errorText={error?.message} helperText="The endpoint where Infisical logs should be sent to">
|
<FormControl label="Endpoint URL" isError={Boolean(error?.message)} errorText={error?.message}>
|
||||||
<Input {...field} />
|
<Input {...field} />
|
||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
@@ -118,7 +118,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => {
|
|||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
helperText="The bearer token used to authenticate with the logging provider endpoint"
|
helperText="The bearer token used to authenticate with the logging provider endpoint"
|
||||||
>
|
>
|
||||||
<Input {...field} />
|
<Input {...field} type="password" />
|
||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
|
|||||||
Reference in New Issue
Block a user