mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 05:28:29 +00:00
feat(infisical-pg): fixed some bugs on org invite missing auth method
This commit is contained in:
@@ -245,7 +245,8 @@ export const registerRoutes = async (
|
|||||||
const superAdminService = superAdminServiceFactory({
|
const superAdminService = superAdminServiceFactory({
|
||||||
userDal,
|
userDal,
|
||||||
authService: loginService,
|
authService: loginService,
|
||||||
serverCfgDal: superAdminDal
|
serverCfgDal: superAdminDal,
|
||||||
|
orgService
|
||||||
});
|
});
|
||||||
const apiKeyService = apiKeyServiceFactory({ apiKeyDal, userDal });
|
const apiKeyService = apiKeyServiceFactory({ apiKeyDal, userDal });
|
||||||
|
|
||||||
|
|||||||
@@ -118,4 +118,35 @@ export const registerPasswordRouter = async (server: FastifyZodProvider) => {
|
|||||||
return { message: "Successfully updated backup private key", backupPrivateKey };
|
return { message: "Successfully updated backup private key", backupPrivateKey };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
method: "POST",
|
||||||
|
url: "/password-reset",
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
|
schema: {
|
||||||
|
body: z.object({
|
||||||
|
protectedKey: z.string().trim(),
|
||||||
|
protectedKeyIV: z.string().trim(),
|
||||||
|
protectedKeyTag: z.string().trim(),
|
||||||
|
encryptedPrivateKey: z.string().trim(),
|
||||||
|
encryptedPrivateKeyIV: z.string().trim(),
|
||||||
|
encryptedPrivateKeyTag: z.string().trim(),
|
||||||
|
salt: z.string().trim(),
|
||||||
|
verifier: z.string().trim()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
message: z.string()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
await server.services.password.resetPasswordByBackupKey({
|
||||||
|
...req.body,
|
||||||
|
userId: req.permission.id
|
||||||
|
});
|
||||||
|
|
||||||
|
return { message: "Successfully updated backup private key" };
|
||||||
|
}
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -157,19 +157,17 @@ export const authPaswordServiceFactory = ({
|
|||||||
/*
|
/*
|
||||||
* Reset password of a user via backup key
|
* Reset password of a user via backup key
|
||||||
* */
|
* */
|
||||||
const resetPasswordByBackupKey = async (
|
const resetPasswordByBackupKey = async ({
|
||||||
userId: string,
|
encryptedPrivateKey,
|
||||||
{
|
protectedKeyTag,
|
||||||
encryptedPrivateKey,
|
protectedKey,
|
||||||
protectedKeyTag,
|
protectedKeyIV,
|
||||||
protectedKey,
|
salt,
|
||||||
protectedKeyIV,
|
verifier,
|
||||||
salt,
|
encryptedPrivateKeyIV,
|
||||||
verifier,
|
encryptedPrivateKeyTag,
|
||||||
encryptedPrivateKeyIV,
|
userId
|
||||||
encryptedPrivateKeyTag
|
}: TResetPasswordViaBackupKeyDTO) => {
|
||||||
}: TResetPasswordViaBackupKeyDTO
|
|
||||||
) => {
|
|
||||||
await userDal.updateUserEncryptionByUserId(userId, {
|
await userDal.updateUserEncryptionByUserId(userId, {
|
||||||
encryptionVersion: 2,
|
encryptionVersion: 2,
|
||||||
protectedKey,
|
protectedKey,
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ import { generateSymmetricKey, infisicalSymmetricEncypt } from "@app/lib/crypto/
|
|||||||
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||||
import { isDisposableEmail } from "@app/lib/validator";
|
import { isDisposableEmail } from "@app/lib/validator";
|
||||||
|
|
||||||
import { AuthTokenType } from "../auth/auth-type";
|
import { AuthMethod, AuthTokenType } from "../auth/auth-type";
|
||||||
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
|
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
|
||||||
import { TokenType } from "../auth-token/auth-token-types";
|
import { TokenType } from "../auth-token/auth-token-types";
|
||||||
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
|
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
|
||||||
@@ -284,14 +284,24 @@ export const orgServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
// not invited before
|
// not invited before
|
||||||
const user = await userDal.create({ email: inviteeEmail, isAccepted: false });
|
const user = await userDal.create(
|
||||||
await orgDal.createMembership({
|
{
|
||||||
inviteEmail: inviteeEmail,
|
email: inviteeEmail,
|
||||||
orgId,
|
isAccepted: false,
|
||||||
userId: user.id,
|
authMethods: [AuthMethod.EMAIL]
|
||||||
role: OrgMembershipRole.Member,
|
},
|
||||||
status: OrgMembershipStatus.Invited
|
tx
|
||||||
});
|
);
|
||||||
|
await orgDal.createMembership(
|
||||||
|
{
|
||||||
|
inviteEmail: inviteeEmail,
|
||||||
|
orgId,
|
||||||
|
userId: user.id,
|
||||||
|
role: OrgMembershipRole.Member,
|
||||||
|
status: OrgMembershipStatus.Invited
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
return user;
|
return user;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -5,11 +5,14 @@ import { TAuthLoginFactory } from "../auth/auth-login-service";
|
|||||||
import { TUserDalFactory } from "../user/user-dal";
|
import { TUserDalFactory } from "../user/user-dal";
|
||||||
import { TSuperAdminDalFactory } from "./super-admin-dal";
|
import { TSuperAdminDalFactory } from "./super-admin-dal";
|
||||||
import { TAdminSignUpDTO } from "./super-admin-types";
|
import { TAdminSignUpDTO } from "./super-admin-types";
|
||||||
|
import { TOrgServiceFactory } from "../org/org-service";
|
||||||
|
import { AuthMethod } from "../auth/auth-type";
|
||||||
|
|
||||||
type TSuperAdminServiceFactoryDep = {
|
type TSuperAdminServiceFactoryDep = {
|
||||||
serverCfgDal: TSuperAdminDalFactory;
|
serverCfgDal: TSuperAdminDalFactory;
|
||||||
userDal: TUserDalFactory;
|
userDal: TUserDalFactory;
|
||||||
authService: Pick<TAuthLoginFactory, "generateUserTokens">;
|
authService: Pick<TAuthLoginFactory, "generateUserTokens">;
|
||||||
|
orgService: Pick<TOrgServiceFactory, "createOrganization">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TSuperAdminServiceFactory = ReturnType<typeof superAdminServiceFactory>;
|
export type TSuperAdminServiceFactory = ReturnType<typeof superAdminServiceFactory>;
|
||||||
@@ -17,7 +20,8 @@ export type TSuperAdminServiceFactory = ReturnType<typeof superAdminServiceFacto
|
|||||||
export const superAdminServiceFactory = ({
|
export const superAdminServiceFactory = ({
|
||||||
serverCfgDal,
|
serverCfgDal,
|
||||||
userDal,
|
userDal,
|
||||||
authService
|
authService,
|
||||||
|
orgService
|
||||||
}: TSuperAdminServiceFactoryDep) => {
|
}: TSuperAdminServiceFactoryDep) => {
|
||||||
let serverCfg: TSuperAdmin;
|
let serverCfg: TSuperAdmin;
|
||||||
|
|
||||||
@@ -70,7 +74,8 @@ export const superAdminServiceFactory = ({
|
|||||||
lastName,
|
lastName,
|
||||||
email,
|
email,
|
||||||
superAdmin: true,
|
superAdmin: true,
|
||||||
isAccepted: true
|
isAccepted: true,
|
||||||
|
authMethods: [AuthMethod.EMAIL]
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
@@ -92,6 +97,7 @@ export const superAdminServiceFactory = ({
|
|||||||
);
|
);
|
||||||
return { user: newUser, enc: userEnc };
|
return { user: newUser, enc: userEnc };
|
||||||
});
|
});
|
||||||
|
await orgService.createOrganization(userInfo.user.id, userInfo.user.email, "Admin Org");
|
||||||
|
|
||||||
await updateServerCfg({ initialized: true });
|
await updateServerCfg({ initialized: true });
|
||||||
const token = await authService.generateUserTokens(userInfo.user, ip, userAgent);
|
const token = await authService.generateUserTokens(userInfo.user, ip, userAgent);
|
||||||
|
|||||||
Reference in New Issue
Block a user