mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #3236 from akhilmhdh/fix/renew-token
Resolved renew token not renewing
This commit is contained in:
@@ -78,9 +78,7 @@ export const identityAccessTokenServiceFactory = ({
|
|||||||
const renewAccessToken = async ({ accessToken }: TRenewAccessTokenDTO) => {
|
const renewAccessToken = async ({ accessToken }: TRenewAccessTokenDTO) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
|
|
||||||
const decodedToken = jwt.verify(accessToken, appCfg.AUTH_SECRET) as JwtPayload & {
|
const decodedToken = jwt.verify(accessToken, appCfg.AUTH_SECRET) as TIdentityAccessTokenJwtPayload;
|
||||||
identityAccessTokenId: string;
|
|
||||||
};
|
|
||||||
if (decodedToken.authTokenType !== AuthTokenType.IDENTITY_ACCESS_TOKEN) {
|
if (decodedToken.authTokenType !== AuthTokenType.IDENTITY_ACCESS_TOKEN) {
|
||||||
throw new BadRequestError({ message: "Only identity access tokens can be renewed" });
|
throw new BadRequestError({ message: "Only identity access tokens can be renewed" });
|
||||||
}
|
}
|
||||||
@@ -127,7 +125,23 @@ export const identityAccessTokenServiceFactory = ({
|
|||||||
accessTokenLastRenewedAt: new Date()
|
accessTokenLastRenewedAt: new Date()
|
||||||
});
|
});
|
||||||
|
|
||||||
return { accessToken, identityAccessToken: updatedIdentityAccessToken };
|
const renewedToken = jwt.sign(
|
||||||
|
{
|
||||||
|
identityId: decodedToken.identityId,
|
||||||
|
clientSecretId: decodedToken.clientSecretId,
|
||||||
|
identityAccessTokenId: decodedToken.identityAccessTokenId,
|
||||||
|
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
|
||||||
|
} as TIdentityAccessTokenJwtPayload,
|
||||||
|
appCfg.AUTH_SECRET,
|
||||||
|
// akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
|
||||||
|
Number(identityAccessToken.accessTokenTTL) === 0
|
||||||
|
? undefined
|
||||||
|
: {
|
||||||
|
expiresIn: Number(identityAccessToken.accessTokenTTL)
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return { accessToken: renewedToken, identityAccessToken: updatedIdentityAccessToken };
|
||||||
};
|
};
|
||||||
|
|
||||||
const revokeAccessToken = async (accessToken: string) => {
|
const revokeAccessToken = async (accessToken: string) => {
|
||||||
|
|||||||
Reference in New Issue
Block a user