mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 17:27:40 +00:00
feat: made the function shared one
This commit is contained in:
@@ -34,22 +34,7 @@ export const secretSharingServiceFactory = ({
|
|||||||
orgDAL,
|
orgDAL,
|
||||||
kmsService
|
kmsService
|
||||||
}: TSecretSharingServiceFactoryDep) => {
|
}: TSecretSharingServiceFactoryDep) => {
|
||||||
const createSharedSecret = async ({
|
const $validateSharedSecretExpiry = (expiresAt: string) => {
|
||||||
actor,
|
|
||||||
actorId,
|
|
||||||
orgId,
|
|
||||||
actorAuthMethod,
|
|
||||||
actorOrgId,
|
|
||||||
secretValue,
|
|
||||||
name,
|
|
||||||
password,
|
|
||||||
accessType,
|
|
||||||
expiresAt,
|
|
||||||
expiresAfterViews
|
|
||||||
}: TCreateSharedSecretDTO) => {
|
|
||||||
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
|
|
||||||
if (!permission) throw new ForbiddenRequestError({ name: "User is not a part of the specified organization" });
|
|
||||||
|
|
||||||
if (new Date(expiresAt) < new Date()) {
|
if (new Date(expiresAt) < new Date()) {
|
||||||
throw new BadRequestError({ message: "Expiration date cannot be in the past" });
|
throw new BadRequestError({ message: "Expiration date cannot be in the past" });
|
||||||
}
|
}
|
||||||
@@ -66,6 +51,24 @@ export const secretSharingServiceFactory = ({
|
|||||||
if (expiryTime - currentTime < fiveMins) {
|
if (expiryTime - currentTime < fiveMins) {
|
||||||
throw new BadRequestError({ message: "Expiration time cannot be less than 5 mins" });
|
throw new BadRequestError({ message: "Expiration time cannot be less than 5 mins" });
|
||||||
}
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const createSharedSecret = async ({
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
orgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId,
|
||||||
|
secretValue,
|
||||||
|
name,
|
||||||
|
password,
|
||||||
|
accessType,
|
||||||
|
expiresAt,
|
||||||
|
expiresAfterViews
|
||||||
|
}: TCreateSharedSecretDTO) => {
|
||||||
|
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
|
||||||
|
if (!permission) throw new ForbiddenRequestError({ name: "User is not a part of the specified organization" });
|
||||||
|
$validateSharedSecretExpiry(expiresAt);
|
||||||
|
|
||||||
if (secretValue.length > 10_000) {
|
if (secretValue.length > 10_000) {
|
||||||
throw new BadRequestError({ message: "Shared secret value too long" });
|
throw new BadRequestError({ message: "Shared secret value too long" });
|
||||||
@@ -105,22 +108,7 @@ export const secretSharingServiceFactory = ({
|
|||||||
expiresAfterViews,
|
expiresAfterViews,
|
||||||
accessType
|
accessType
|
||||||
}: TCreatePublicSharedSecretDTO) => {
|
}: TCreatePublicSharedSecretDTO) => {
|
||||||
if (new Date(expiresAt) < new Date()) {
|
$validateSharedSecretExpiry(expiresAt);
|
||||||
throw new BadRequestError({ message: "Expiration date cannot be in the past" });
|
|
||||||
}
|
|
||||||
|
|
||||||
// Limit Expiry Time to 1 month
|
|
||||||
const expiryTime = new Date(expiresAt).getTime();
|
|
||||||
const currentTime = new Date().getTime();
|
|
||||||
const thirtyDays = 30 * 24 * 60 * 60 * 1000;
|
|
||||||
if (expiryTime - currentTime > thirtyDays) {
|
|
||||||
throw new BadRequestError({ message: "Expiration date cannot exceed more than 30 days" });
|
|
||||||
}
|
|
||||||
|
|
||||||
const fiveMins = 5 * 60 * 1000;
|
|
||||||
if (expiryTime - currentTime < fiveMins) {
|
|
||||||
throw new BadRequestError({ message: "Expiration time cannot be less than 5 mins" });
|
|
||||||
}
|
|
||||||
|
|
||||||
const encryptWithRoot = kmsService.encryptWithRootKey();
|
const encryptWithRoot = kmsService.encryptWithRootKey();
|
||||||
const encryptedSecret = encryptWithRoot(Buffer.from(secretValue));
|
const encryptedSecret = encryptWithRoot(Buffer.from(secretValue));
|
||||||
|
|||||||
Reference in New Issue
Block a user