mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 14:27:59 +00:00
Merge pull request #400 from Infisical/snyk-fix-0ab98e0c00b32ecebcd11cb2298f542f
[Snyk] Security upgrade styled-components from 5.3.5 to 5.3.7
This commit is contained in:
@@ -50,6 +50,7 @@ const STRIPE_SECRET_KEY = process.env.STRIPE_SECRET_KEY!;
|
|||||||
const STRIPE_WEBHOOK_SECRET = process.env.STRIPE_WEBHOOK_SECRET!;
|
const STRIPE_WEBHOOK_SECRET = process.env.STRIPE_WEBHOOK_SECRET!;
|
||||||
const TELEMETRY_ENABLED = process.env.TELEMETRY_ENABLED! !== 'false' && true;
|
const TELEMETRY_ENABLED = process.env.TELEMETRY_ENABLED! !== 'false' && true;
|
||||||
const LICENSE_KEY = process.env.LICENSE_KEY!;
|
const LICENSE_KEY = process.env.LICENSE_KEY!;
|
||||||
|
const SMTP_CONFIGURED = SMTP_HOST == '' || SMTP_HOST == undefined ? false : true
|
||||||
|
|
||||||
export {
|
export {
|
||||||
PORT,
|
PORT,
|
||||||
@@ -101,5 +102,6 @@ export {
|
|||||||
STRIPE_SECRET_KEY,
|
STRIPE_SECRET_KEY,
|
||||||
STRIPE_WEBHOOK_SECRET,
|
STRIPE_WEBHOOK_SECRET,
|
||||||
TELEMETRY_ENABLED,
|
TELEMETRY_ENABLED,
|
||||||
LICENSE_KEY
|
LICENSE_KEY,
|
||||||
|
SMTP_CONFIGURED
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { Request, Response } from 'express';
|
import { Request, Response } from 'express';
|
||||||
import * as Sentry from '@sentry/node';
|
import * as Sentry from '@sentry/node';
|
||||||
import { User } from '../../models';
|
import { User } from '../../models';
|
||||||
import { JWT_SIGNUP_LIFETIME, JWT_SIGNUP_SECRET, INVITE_ONLY_SIGNUP } from '../../config';
|
import { JWT_SIGNUP_LIFETIME, JWT_SIGNUP_SECRET, INVITE_ONLY_SIGNUP, SMTP_CONFIGURED } from '../../config';
|
||||||
import {
|
import {
|
||||||
sendEmailVerification,
|
sendEmailVerification,
|
||||||
checkEmailVerification,
|
checkEmailVerification,
|
||||||
@@ -20,7 +20,6 @@ export const beginEmailSignup = async (req: Request, res: Response) => {
|
|||||||
let email: string;
|
let email: string;
|
||||||
try {
|
try {
|
||||||
email = req.body.email;
|
email = req.body.email;
|
||||||
|
|
||||||
if (INVITE_ONLY_SIGNUP) {
|
if (INVITE_ONLY_SIGNUP) {
|
||||||
// Only one user can create an account without being invited. The rest need to be invited in order to make an account
|
// Only one user can create an account without being invited. The rest need to be invited in order to make an account
|
||||||
const userCount = await User.countDocuments({})
|
const userCount = await User.countDocuments({})
|
||||||
@@ -75,10 +74,12 @@ export const verifyEmailSignup = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// verify email
|
// verify email
|
||||||
await checkEmailVerification({
|
if (SMTP_CONFIGURED) {
|
||||||
email,
|
await checkEmailVerification({
|
||||||
code
|
email,
|
||||||
});
|
code
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
user = await new User({
|
user = await new User({
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ import { EELogService } from '../../ee/services';
|
|||||||
import {
|
import {
|
||||||
NODE_ENV,
|
NODE_ENV,
|
||||||
JWT_MFA_LIFETIME,
|
JWT_MFA_LIFETIME,
|
||||||
JWT_MFA_SECRET
|
JWT_MFA_SECRET,
|
||||||
} from '../../config';
|
} from '../../config';
|
||||||
import { BadRequestError, InternalServerError } from '../../utils/errors';
|
import { BadRequestError, InternalServerError } from '../../utils/errors';
|
||||||
import {
|
import {
|
||||||
@@ -89,7 +89,7 @@ export const login1 = async (req: Request, res: Response) => {
|
|||||||
*/
|
*/
|
||||||
export const login2 = async (req: Request, res: Response) => {
|
export const login2 = async (req: Request, res: Response) => {
|
||||||
try {
|
try {
|
||||||
|
|
||||||
if (!req.headers['user-agent']) throw InternalServerError({ message: 'User-Agent header is required' });
|
if (!req.headers['user-agent']) throw InternalServerError({ message: 'User-Agent header is required' });
|
||||||
|
|
||||||
const { email, clientProof } = req.body;
|
const { email, clientProof } = req.body;
|
||||||
@@ -129,12 +129,12 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
expiresIn: JWT_MFA_LIFETIME,
|
expiresIn: JWT_MFA_LIFETIME,
|
||||||
secret: JWT_MFA_SECRET
|
secret: JWT_MFA_SECRET
|
||||||
});
|
});
|
||||||
|
|
||||||
const code = await TokenService.createToken({
|
const code = await TokenService.createToken({
|
||||||
type: TOKEN_EMAIL_MFA,
|
type: TOKEN_EMAIL_MFA,
|
||||||
email
|
email
|
||||||
});
|
});
|
||||||
|
|
||||||
// send MFA code [code] to [email]
|
// send MFA code [code] to [email]
|
||||||
await sendMail({
|
await sendMail({
|
||||||
template: 'emailMfa.handlebars',
|
template: 'emailMfa.handlebars',
|
||||||
@@ -144,13 +144,13 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
code
|
code
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
mfaEnabled: true,
|
mfaEnabled: true,
|
||||||
token
|
token
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
await checkUserDevice({
|
await checkUserDevice({
|
||||||
user,
|
user,
|
||||||
ip: req.ip,
|
ip: req.ip,
|
||||||
@@ -183,7 +183,7 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
iv?: string;
|
iv?: string;
|
||||||
tag?: string;
|
tag?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
const response: ResponseData = {
|
const response: ResponseData = {
|
||||||
mfaEnabled: false,
|
mfaEnabled: false,
|
||||||
encryptionVersion: user.encryptionVersion,
|
encryptionVersion: user.encryptionVersion,
|
||||||
@@ -193,7 +193,7 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
iv: user.iv,
|
iv: user.iv,
|
||||||
tag: user.tag
|
tag: user.tag
|
||||||
}
|
}
|
||||||
|
|
||||||
if (
|
if (
|
||||||
user?.protectedKey &&
|
user?.protectedKey &&
|
||||||
user?.protectedKeyIV &&
|
user?.protectedKeyIV &&
|
||||||
@@ -208,14 +208,14 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
name: ACTION_LOGIN,
|
name: ACTION_LOGIN,
|
||||||
userId: user._id
|
userId: user._id
|
||||||
});
|
});
|
||||||
|
|
||||||
loginAction && await EELogService.createLog({
|
loginAction && await EELogService.createLog({
|
||||||
userId: user._id,
|
userId: user._id,
|
||||||
actions: [loginAction],
|
actions: [loginAction],
|
||||||
channel: getChannelFromUserAgent(req.headers['user-agent']),
|
channel: getChannelFromUserAgent(req.headers['user-agent']),
|
||||||
ipAddress: req.ip
|
ipAddress: req.ip
|
||||||
});
|
});
|
||||||
|
|
||||||
return res.status(200).send(response);
|
return res.status(200).send(response);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -246,7 +246,7 @@ export const sendMfaToken = async (req: Request, res: Response) => {
|
|||||||
type: TOKEN_EMAIL_MFA,
|
type: TOKEN_EMAIL_MFA,
|
||||||
email
|
email
|
||||||
});
|
});
|
||||||
|
|
||||||
// send MFA code [code] to [email]
|
// send MFA code [code] to [email]
|
||||||
await sendMail({
|
await sendMail({
|
||||||
template: 'emailMfa.handlebars',
|
template: 'emailMfa.handlebars',
|
||||||
@@ -261,9 +261,9 @@ export const sendMfaToken = async (req: Request, res: Response) => {
|
|||||||
Sentry.captureException(err);
|
Sentry.captureException(err);
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
message: 'Failed to send MFA code'
|
message: 'Failed to send MFA code'
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
message: 'Successfully sent new MFA code'
|
message: 'Successfully sent new MFA code'
|
||||||
});
|
});
|
||||||
@@ -276,76 +276,76 @@ export const sendMfaToken = async (req: Request, res: Response) => {
|
|||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
export const verifyMfaToken = async (req: Request, res: Response) => {
|
export const verifyMfaToken = async (req: Request, res: Response) => {
|
||||||
const { email, mfaToken } = req.body;
|
const { email, mfaToken } = req.body;
|
||||||
|
|
||||||
await TokenService.validateToken({
|
await TokenService.validateToken({
|
||||||
type: TOKEN_EMAIL_MFA,
|
type: TOKEN_EMAIL_MFA,
|
||||||
email,
|
email,
|
||||||
token: mfaToken
|
token: mfaToken
|
||||||
});
|
});
|
||||||
|
|
||||||
const user = await User.findOne({
|
const user = await User.findOne({
|
||||||
email
|
email
|
||||||
}).select('+salt +verifier +encryptionVersion +protectedKey +protectedKeyIV +protectedKeyTag +publicKey +encryptedPrivateKey +iv +tag');
|
}).select('+salt +verifier +encryptionVersion +protectedKey +protectedKeyIV +protectedKeyTag +publicKey +encryptedPrivateKey +iv +tag');
|
||||||
|
|
||||||
if (!user) throw new Error('Failed to find user');
|
if (!user) throw new Error('Failed to find user');
|
||||||
|
|
||||||
await checkUserDevice({
|
await checkUserDevice({
|
||||||
user,
|
user,
|
||||||
ip: req.ip,
|
ip: req.ip,
|
||||||
userAgent: req.headers['user-agent'] ?? ''
|
userAgent: req.headers['user-agent'] ?? ''
|
||||||
});
|
});
|
||||||
|
|
||||||
// issue tokens
|
// issue tokens
|
||||||
const tokens = await issueAuthTokens({ userId: user._id.toString() });
|
const tokens = await issueAuthTokens({ userId: user._id.toString() });
|
||||||
|
|
||||||
// store (refresh) token in httpOnly cookie
|
// store (refresh) token in httpOnly cookie
|
||||||
res.cookie('jid', tokens.refreshToken, {
|
res.cookie('jid', tokens.refreshToken, {
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
path: '/',
|
path: '/',
|
||||||
sameSite: 'strict',
|
sameSite: 'strict',
|
||||||
secure: NODE_ENV === 'production' ? true : false
|
secure: NODE_ENV === 'production' ? true : false
|
||||||
});
|
});
|
||||||
|
|
||||||
interface VerifyMfaTokenRes {
|
|
||||||
encryptionVersion: number;
|
|
||||||
protectedKey?: string;
|
|
||||||
protectedKeyIV?: string;
|
|
||||||
protectedKeyTag?: string;
|
|
||||||
token: string;
|
|
||||||
publicKey: string;
|
|
||||||
encryptedPrivateKey: string;
|
|
||||||
iv: string;
|
|
||||||
tag: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
const resObj: VerifyMfaTokenRes = {
|
interface VerifyMfaTokenRes {
|
||||||
encryptionVersion: user.encryptionVersion,
|
encryptionVersion: number;
|
||||||
token: tokens.token,
|
protectedKey?: string;
|
||||||
publicKey: user.publicKey as string,
|
protectedKeyIV?: string;
|
||||||
encryptedPrivateKey: user.encryptedPrivateKey as string,
|
protectedKeyTag?: string;
|
||||||
iv: user.iv as string,
|
token: string;
|
||||||
tag: user.tag as string
|
publicKey: string;
|
||||||
}
|
encryptedPrivateKey: string;
|
||||||
|
iv: string;
|
||||||
if (user?.protectedKey && user?.protectedKeyIV && user?.protectedKeyTag) {
|
tag: string;
|
||||||
resObj.protectedKey = user.protectedKey;
|
}
|
||||||
resObj.protectedKeyIV = user.protectedKeyIV;
|
|
||||||
resObj.protectedKeyTag = user.protectedKeyTag;
|
|
||||||
}
|
|
||||||
|
|
||||||
const loginAction = await EELogService.createAction({
|
const resObj: VerifyMfaTokenRes = {
|
||||||
name: ACTION_LOGIN,
|
encryptionVersion: user.encryptionVersion,
|
||||||
userId: user._id
|
token: tokens.token,
|
||||||
});
|
publicKey: user.publicKey as string,
|
||||||
|
encryptedPrivateKey: user.encryptedPrivateKey as string,
|
||||||
loginAction && await EELogService.createLog({
|
iv: user.iv as string,
|
||||||
userId: user._id,
|
tag: user.tag as string
|
||||||
actions: [loginAction],
|
}
|
||||||
channel: getChannelFromUserAgent(req.headers['user-agent']),
|
|
||||||
ipAddress: req.ip
|
|
||||||
});
|
|
||||||
|
|
||||||
return res.status(200).send(resObj);
|
if (user?.protectedKey && user?.protectedKeyIV && user?.protectedKeyTag) {
|
||||||
|
resObj.protectedKey = user.protectedKey;
|
||||||
|
resObj.protectedKeyIV = user.protectedKeyIV;
|
||||||
|
resObj.protectedKeyTag = user.protectedKeyTag;
|
||||||
|
}
|
||||||
|
|
||||||
|
const loginAction = await EELogService.createAction({
|
||||||
|
name: ACTION_LOGIN,
|
||||||
|
userId: user._id
|
||||||
|
});
|
||||||
|
|
||||||
|
loginAction && await EELogService.createLog({
|
||||||
|
userId: user._id,
|
||||||
|
actions: [loginAction],
|
||||||
|
channel: getChannelFromUserAgent(req.headers['user-agent']),
|
||||||
|
ipAddress: req.ip
|
||||||
|
});
|
||||||
|
|
||||||
|
return res.status(200).send(resObj);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ import fs from 'fs';
|
|||||||
import path from 'path';
|
import path from 'path';
|
||||||
import handlebars from 'handlebars';
|
import handlebars from 'handlebars';
|
||||||
import nodemailer from 'nodemailer';
|
import nodemailer from 'nodemailer';
|
||||||
import { SMTP_FROM_NAME, SMTP_FROM_ADDRESS } from '../config';
|
import { SMTP_FROM_NAME, SMTP_FROM_ADDRESS, SMTP_CONFIGURED } from '../config';
|
||||||
import * as Sentry from '@sentry/node';
|
import * as Sentry from '@sentry/node';
|
||||||
|
|
||||||
let smtpTransporter: nodemailer.Transporter;
|
let smtpTransporter: nodemailer.Transporter;
|
||||||
@@ -25,23 +25,25 @@ const sendMail = async ({
|
|||||||
recipients: string[];
|
recipients: string[];
|
||||||
substitutions: any;
|
substitutions: any;
|
||||||
}) => {
|
}) => {
|
||||||
try {
|
if (SMTP_CONFIGURED) {
|
||||||
const html = fs.readFileSync(
|
try {
|
||||||
path.resolve(__dirname, '../templates/' + template),
|
const html = fs.readFileSync(
|
||||||
'utf8'
|
path.resolve(__dirname, '../templates/' + template),
|
||||||
);
|
'utf8'
|
||||||
const temp = handlebars.compile(html);
|
);
|
||||||
const htmlToSend = temp(substitutions);
|
const temp = handlebars.compile(html);
|
||||||
|
const htmlToSend = temp(substitutions);
|
||||||
|
|
||||||
await smtpTransporter.sendMail({
|
await smtpTransporter.sendMail({
|
||||||
from: `"${SMTP_FROM_NAME}" <${SMTP_FROM_ADDRESS}>`,
|
from: `"${SMTP_FROM_NAME}" <${SMTP_FROM_ADDRESS}>`,
|
||||||
to: recipients.join(', '),
|
to: recipients.join(', '),
|
||||||
subject: subjectLine,
|
subject: subjectLine,
|
||||||
html: htmlToSend
|
html: htmlToSend
|
||||||
});
|
});
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
Sentry.setUser(null);
|
Sentry.setUser(null);
|
||||||
Sentry.captureException(err);
|
Sentry.captureException(err);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Generated
+8
-9
@@ -1,5 +1,5 @@
|
|||||||
{
|
{
|
||||||
"name": "frontend",
|
"name": "npm-proj-1677883018530-0.7603125731052582NtcmfK",
|
||||||
"lockfileVersion": 2,
|
"lockfileVersion": 2,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
@@ -66,7 +66,7 @@
|
|||||||
"react-table": "^7.8.0",
|
"react-table": "^7.8.0",
|
||||||
"set-cookie-parser": "^2.5.1",
|
"set-cookie-parser": "^2.5.1",
|
||||||
"sharp": "^0.31.2",
|
"sharp": "^0.31.2",
|
||||||
"styled-components": "^5.3.5",
|
"styled-components": "^5.3.7",
|
||||||
"tailwind-merge": "^1.8.1",
|
"tailwind-merge": "^1.8.1",
|
||||||
"tweetnacl": "^1.0.3",
|
"tweetnacl": "^1.0.3",
|
||||||
"tweetnacl-util": "^0.15.1",
|
"tweetnacl-util": "^0.15.1",
|
||||||
@@ -20245,10 +20245,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/styled-components": {
|
"node_modules/styled-components": {
|
||||||
"version": "5.3.5",
|
"version": "5.3.7",
|
||||||
"resolved": "https://registry.npmjs.org/styled-components/-/styled-components-5.3.5.tgz",
|
"resolved": "https://registry.npmjs.org/styled-components/-/styled-components-5.3.7.tgz",
|
||||||
"integrity": "sha512-ndETJ9RKaaL6q41B69WudeqLzOpY1A/ET/glXkNZ2T7dPjPqpPCXXQjDFYZWwNnE5co0wX+gTCqx9mfxTmSIPg==",
|
"integrity": "sha512-JL1b4A79OGqav4TxkrNsuuQfy6ZnrpyQx6hBDQ3Hd3JyuR2IQuVNBpF+FCEWFNZpN5hj+fhkaEVWteVJ18f0tw==",
|
||||||
"hasInstallScript": true,
|
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@babel/helper-module-imports": "^7.0.0",
|
"@babel/helper-module-imports": "^7.0.0",
|
||||||
"@babel/traverse": "^7.4.5",
|
"@babel/traverse": "^7.4.5",
|
||||||
@@ -37001,9 +37000,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"styled-components": {
|
"styled-components": {
|
||||||
"version": "5.3.5",
|
"version": "5.3.7",
|
||||||
"resolved": "https://registry.npmjs.org/styled-components/-/styled-components-5.3.5.tgz",
|
"resolved": "https://registry.npmjs.org/styled-components/-/styled-components-5.3.7.tgz",
|
||||||
"integrity": "sha512-ndETJ9RKaaL6q41B69WudeqLzOpY1A/ET/glXkNZ2T7dPjPqpPCXXQjDFYZWwNnE5co0wX+gTCqx9mfxTmSIPg==",
|
"integrity": "sha512-JL1b4A79OGqav4TxkrNsuuQfy6ZnrpyQx6hBDQ3Hd3JyuR2IQuVNBpF+FCEWFNZpN5hj+fhkaEVWteVJ18f0tw==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"@babel/helper-module-imports": "^7.0.0",
|
"@babel/helper-module-imports": "^7.0.0",
|
||||||
"@babel/traverse": "^7.4.5",
|
"@babel/traverse": "^7.4.5",
|
||||||
|
|||||||
@@ -73,7 +73,7 @@
|
|||||||
"react-table": "^7.8.0",
|
"react-table": "^7.8.0",
|
||||||
"set-cookie-parser": "^2.5.1",
|
"set-cookie-parser": "^2.5.1",
|
||||||
"sharp": "^0.31.2",
|
"sharp": "^0.31.2",
|
||||||
"styled-components": "^5.3.5",
|
"styled-components": "^5.3.7",
|
||||||
"tailwind-merge": "^1.8.1",
|
"tailwind-merge": "^1.8.1",
|
||||||
"tweetnacl": "^1.0.3",
|
"tweetnacl": "^1.0.3",
|
||||||
"tweetnacl-util": "^0.15.1",
|
"tweetnacl-util": "^0.15.1",
|
||||||
|
|||||||
Reference in New Issue
Block a user