Update envars to new node SDK format

This commit is contained in:
Tuan Dang
2023-04-22 16:20:33 +03:00
parent 3846c42c00
commit e1bf31b371
44 changed files with 223 additions and 229 deletions
+55 -54
View File
@@ -1,64 +1,65 @@
import infisical from 'infisical-node'; import infisical from 'infisical-node';
export const getPort = () => infisical.get('PORT')! || 4000;
export const getInviteOnlySignup = () => infisical.get('INVITE_ONLY_SIGNUP')! == undefined ? false : infisical.get('INVITE_ONLY_SIGNUP'); export const getPort = async () => await infisical.get('PORT')! || 4000;
export const getEncryptionKey = () => infisical.get('ENCRYPTION_KEY')!; export const getInviteOnlySignup = async () => await infisical.get('INVITE_ONLY_SIGNUP')! == undefined ? false : await infisical.get('INVITE_ONLY_SIGNUP');
export const getSaltRounds = () => parseInt(infisical.get('SALT_ROUNDS')!) || 10; export const getEncryptionKey = async () => await infisical.get('ENCRYPTION_KEY')!;
export const getJwtAuthLifetime = () => infisical.get('JWT_AUTH_LIFETIME')! || '10d'; export const getSaltRounds = async () => parseInt(await infisical.get('SALT_ROUNDS')!) || 10;
export const getJwtAuthSecret = () => infisical.get('JWT_AUTH_SECRET')!; export const getJwtAuthLifetime = async () => await infisical.get('JWT_AUTH_LIFETIME')! || '10d';
export const getJwtMfaLifetime = () => infisical.get('JWT_MFA_LIFETIME')! || '5m'; export const getJwtAuthSecret = async () => await infisical.get('JWT_AUTH_SECRET')!;
export const getJwtMfaSecret = () => infisical.get('JWT_MFA_LIFETIME')! || '5m'; export const getJwtMfaLifetime = async () => await infisical.get('JWT_MFA_LIFETIME')! || '5m';
export const getJwtRefreshLifetime = () => infisical.get('JWT_REFRESH_LIFETIME')! || '90d'; export const getJwtMfaSecret = async () => await infisical.get('JWT_MFA_LIFETIME')! || '5m';
export const getJwtRefreshSecret = () => infisical.get('JWT_REFRESH_SECRET')!; export const getJwtRefreshLifetime = async () => await infisical.get('JWT_REFRESH_LIFETIME')! || '90d';
export const getJwtServiceSecret = () => infisical.get('JWT_SERVICE_SECRET')!; export const getJwtRefreshSecret = async () => await infisical.get('JWT_REFRESH_SECRET')!;
export const getJwtSignupLifetime = () => infisical.get('JWT_SIGNUP_LIFETIME')! || '15m'; export const getJwtServiceSecret = async () => await infisical.get('JWT_SERVICE_SECRET')!;
export const getJwtSignupSecret = () => infisical.get('JWT_SIGNUP_SECRET')!; export const getJwtSignupLifetime = async () => await infisical.get('JWT_SIGNUP_LIFETIME')! || '15m';
export const getMongoURL = () => infisical.get('MONGO_URL')!; export const getJwtSignupSecret = async () => await infisical.get('JWT_SIGNUP_SECRET')!;
export const getNodeEnv = () => infisical.get('NODE_ENV')! || 'production'; export const getMongoURL = async () => await infisical.get('MONGO_URL')!;
export const getVerboseErrorOutput = () => infisical.get('VERBOSE_ERROR_OUTPUT')! === 'true' && true; export const getNodeEnv = async () => await infisical.get('NODE_ENV')! || 'production';
export const getLokiHost = () => infisical.get('LOKI_HOST')!; export const getVerboseErrorOutput = async () => await infisical.get('VERBOSE_ERROR_OUTPUT')! === 'true' && true;
export const getClientIdAzure = () => infisical.get('CLIENT_ID_AZURE')!; export const getLokiHost = async () => await infisical.get('LOKI_HOST')!;
export const getClientIdHeroku = () => infisical.get('CLIENT_ID_HEROKU')!; export const getClientIdAzure = async () => await infisical.get('CLIENT_ID_AZURE')!;
export const getClientIdVercel = () => infisical.get('CLIENT_ID_VERCEL')!; export const getClientIdHeroku = async () => await infisical.get('CLIENT_ID_HEROKU')!;
export const getClientIdNetlify = () => infisical.get('CLIENT_ID_NETLIFY')!; export const getClientIdVercel = async () => await infisical.get('CLIENT_ID_VERCEL')!;
export const getClientIdGitHub = () => infisical.get('CLIENT_ID_GITHUB')!; export const getClientIdNetlify = async () => await infisical.get('CLIENT_ID_NETLIFY')!;
export const getClientIdGitLab = () => infisical.get('CLIENT_ID_GITLAB')!; export const getClientIdGitHub = async () => await infisical.get('CLIENT_ID_GITHUB')!;
export const getClientSecretAzure = () => infisical.get('CLIENT_SECRET_AZURE')!; export const getClientIdGitLab = async () => await infisical.get('CLIENT_ID_GITLAB')!;
export const getClientSecretHeroku = () => infisical.get('CLIENT_SECRET_HEROKU')!; export const getClientSecretAzure = async () => await infisical.get('CLIENT_SECRET_AZURE')!;
export const getClientSecretVercel = () => infisical.get('CLIENT_SECRET_VERCEL')!; export const getClientSecretHeroku = async () => await infisical.get('CLIENT_SECRET_HEROKU')!;
export const getClientSecretNetlify = () => infisical.get('CLIENT_SECRET_NETLIFY')!; export const getClientSecretVercel = async () => await infisical.get('CLIENT_SECRET_VERCEL')!;
export const getClientSecretGitHub = () => infisical.get('CLIENT_SECRET_GITHUB')!; export const getClientSecretNetlify = async () => await infisical.get('CLIENT_SECRET_NETLIFY')!;
export const getClientSecretGitLab = () => infisical.get('CLIENT_SECRET_GITLAB')!; export const getClientSecretGitHub = async () => await infisical.get('CLIENT_SECRET_GITHUB')!;
export const getClientSlugVercel = () => infisical.get('CLIENT_SLUG_VERCEL')!; export const getClientSecretGitLab = async () => await infisical.get('CLIENT_SECRET_GITLAB')!;
export const getPostHogHost = () => infisical.get('POSTHOG_HOST')! || 'https://app.posthog.com'; export const getClientSlugVercel = async () => await infisical.get('CLIENT_SLUG_VERCEL')!;
export const getPostHogProjectApiKey = () => infisical.get('POSTHOG_PROJECT_API_KEY')! || 'phc_nSin8j5q2zdhpFDI1ETmFNUIuTG4DwKVyIigrY10XiE'; export const getPostHogHost = async () => await infisical.get('POSTHOG_HOST')! || 'https://app.posthog.com';
export const getSentryDSN = () => infisical.get('SENTRY_DSN')!; export const getPostHogProjectApiKey = async () => await infisical.get('POSTHOG_PROJECT_API_KEY')! || 'phc_nSin8j5q2zdhpFDI1ETmFNUIuTG4DwKVyIigrY10XiE';
export const getSiteURL = () => infisical.get('SITE_URL')!; export const getSentryDSN = async () => await infisical.get('SENTRY_DSN')!;
export const getSmtpHost = () => infisical.get('SMTP_HOST')!; export const getSiteURL = async () => await infisical.get('SITE_URL')!;
export const getSmtpSecure = () => infisical.get('SMTP_SECURE')! === 'true' || false; export const getSmtpHost = async () => await infisical.get('SMTP_HOST')!;
export const getSmtpPort = () => parseInt(infisical.get('SMTP_PORT')!) || 587; export const getSmtpSecure = async () => await infisical.get('SMTP_SECURE')! === 'true' || false;
export const getSmtpUsername = () => infisical.get('SMTP_USERNAME')!; export const getSmtpPort = async () => parseInt(await infisical.get('SMTP_PORT')!) || 587;
export const getSmtpPassword = () => infisical.get('SMTP_PASSWORD')!; export const getSmtpUsername = async () => await infisical.get('SMTP_USERNAME')!;
export const getSmtpFromAddress = () => infisical.get('SMTP_FROM_ADDRESS')!; export const getSmtpPassword = async () => await infisical.get('SMTP_PASSWORD')!;
export const getSmtpFromName = () => infisical.get('SMTP_FROM_NAME')! || 'Infisical'; export const getSmtpFromAddress = async () => await infisical.get('SMTP_FROM_ADDRESS')!;
export const getStripeProductStarter = () => infisical.get('STRIPE_PRODUCT_STARTER')!; export const getSmtpFromName = async () => await infisical.get('SMTP_FROM_NAME')! || 'Infisical';
export const getStripeProductPro = () => infisical.get('STRIPE_PRODUCT_PRO')!; export const getStripeProductStarter = async () => await infisical.get('STRIPE_PRODUCT_STARTER')!;
export const getStripeProductTeam = () => infisical.get('STRIPE_PRODUCT_TEAM')!; export const getStripeProductPro = async () => await infisical.get('STRIPE_PRODUCT_PRO')!;
export const getStripePublishableKey = () => infisical.get('STRIPE_PUBLISHABLE_KEY')!; export const getStripeProductTeam = async () => await infisical.get('STRIPE_PRODUCT_TEAM')!;
export const getStripeSecretKey = () => infisical.get('STRIPE_SECRET_KEY')!; export const getStripePublishableKey = async () => await infisical.get('STRIPE_PUBLISHABLE_KEY')!;
export const getStripeWebhookSecret = () => infisical.get('STRIPE_WEBHOOK_SECRET')!; export const getStripeSecretKey = async () => await infisical.get('STRIPE_SECRET_KEY')!;
export const getTelemetryEnabled = () => infisical.get('TELEMETRY_ENABLED')! !== 'false' && true; export const getStripeWebhookSecret = async () => await infisical.get('STRIPE_WEBHOOK_SECRET')!;
export const getLoopsApiKey = () => infisical.get('LOOPS_API_KEY')!; export const getTelemetryEnabled = async () => await infisical.get('TELEMETRY_ENABLED')! !== 'false' && true;
export const getSmtpConfigured = () => infisical.get('SMTP_HOST') == '' || infisical.get('SMTP_HOST') == undefined ? false : true export const getLoopsApiKey = async () => await infisical.get('LOOPS_API_KEY')!;
export const getHttpsEnabled = () => { export const getSmtpConfigured = async () => await infisical.get('SMTP_HOST') == '' || await infisical.get('SMTP_HOST') == undefined ? false : true
if (getNodeEnv() != "production") { export const getHttpsEnabled = async () => {
if ((await getNodeEnv()) != "production") {
// no https for anything other than prod // no https for anything other than prod
return false return false
} }
if (infisical.get('HTTPS_ENABLED') == undefined || infisical.get('HTTPS_ENABLED') == "") { if ((await infisical.get('HTTPS_ENABLED')) == undefined || (await infisical.get('HTTPS_ENABLED')) == "") {
// default when no value present // default when no value present
return true return true
} }
return infisical.get('HTTPS_ENABLED') === 'true' && true return (await infisical.get('HTTPS_ENABLED')) === 'true' && true
} }
+5 -5
View File
@@ -126,7 +126,7 @@ export const login2 = async (req: Request, res: Response) => {
httpOnly: true, httpOnly: true,
path: '/', path: '/',
sameSite: 'strict', sameSite: 'strict',
secure: getHttpsEnabled() secure: await getHttpsEnabled()
}); });
const loginAction = await EELogService.createAction({ const loginAction = await EELogService.createAction({
@@ -182,7 +182,7 @@ export const logout = async (req: Request, res: Response) => {
httpOnly: true, httpOnly: true,
path: '/', path: '/',
sameSite: 'strict', sameSite: 'strict',
secure: getHttpsEnabled() as boolean secure: (await getHttpsEnabled()) as boolean
}); });
const logoutAction = await EELogService.createAction({ const logoutAction = await EELogService.createAction({
@@ -237,7 +237,7 @@ export const getNewToken = async (req: Request, res: Response) => {
} }
const decodedToken = <jwt.UserIDJwtPayload>( const decodedToken = <jwt.UserIDJwtPayload>(
jwt.verify(refreshToken, getJwtRefreshSecret()) jwt.verify(refreshToken, await getJwtRefreshSecret())
); );
const user = await User.findOne({ const user = await User.findOne({
@@ -252,8 +252,8 @@ export const getNewToken = async (req: Request, res: Response) => {
payload: { payload: {
userId: decodedToken.userId userId: decodedToken.userId
}, },
expiresIn: getJwtAuthLifetime(), expiresIn: await getJwtAuthLifetime(),
secret: getJwtAuthSecret() secret: await getJwtAuthSecret()
}); });
return res.status(200).send({ return res.status(200).send({
@@ -44,7 +44,7 @@ export const getIntegrationAuth = async (req: Request, res: Response) => {
} }
export const getIntegrationOptions = async (req: Request, res: Response) => { export const getIntegrationOptions = async (req: Request, res: Response) => {
const INTEGRATION_OPTIONS = getIntegrationOptionsFunc(); const INTEGRATION_OPTIONS = await getIntegrationOptionsFunc();
return res.status(200).send({ return res.status(200).send({
integrationOptions: INTEGRATION_OPTIONS, integrationOptions: INTEGRATION_OPTIONS,
@@ -215,7 +215,7 @@ export const inviteUserToWorkspace = async (req: Request, res: Response) => {
inviterFirstName: req.user.firstName, inviterFirstName: req.user.firstName,
inviterEmail: req.user.email, inviterEmail: req.user.email,
workspaceName: req.membership.workspace.name, workspaceName: req.membership.workspace.name,
callback_url: getSiteURL() + '/login' callback_url: (await getSiteURL()) + '/login'
} }
}); });
} catch (err) { } catch (err) {
@@ -180,11 +180,11 @@ export const inviteUserToOrganization = async (req: Request, res: Response) => {
organizationName: organization.name, organizationName: organization.name,
email: inviteeEmail, email: inviteeEmail,
token, token,
callback_url: getSiteURL() + '/signupinvite' callback_url: (await getSiteURL()) + '/signupinvite'
} }
}); });
if (!getSmtpConfigured()) { if (!(await getSmtpConfigured())) {
completeInviteLink = `${siteUrl + '/signupinvite'}?token=${token}&to=${inviteeEmail}` completeInviteLink = `${siteUrl + '/signupinvite'}?token=${token}&to=${inviteeEmail}`
} }
} }
@@ -257,8 +257,8 @@ export const verifyUserToOrganization = async (req: Request, res: Response) => {
payload: { payload: {
userId: user._id.toString() userId: user._id.toString()
}, },
expiresIn: getJwtSignupLifetime(), expiresIn: await getJwtSignupLifetime(),
secret: getJwtSignupSecret() secret: await getJwtSignupSecret()
}); });
} catch (err) { } catch (err) {
Sentry.setUser(null); Sentry.setUser(null);
@@ -317,7 +317,7 @@ export const createOrganizationPortalSession = async (
) => { ) => {
let session; let session;
try { try {
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
@@ -333,13 +333,13 @@ export const createOrganizationPortalSession = async (
customer: req.membershipOrg.organization.customerId, customer: req.membershipOrg.organization.customerId,
mode: 'setup', mode: 'setup',
payment_method_types: ['card'], payment_method_types: ['card'],
success_url: getSiteURL() + '/dashboard', success_url: (await getSiteURL()) + '/dashboard',
cancel_url: getSiteURL() + '/dashboard' cancel_url: (await getSiteURL()) + '/dashboard'
}); });
} else { } else {
session = await stripe.billingPortal.sessions.create({ session = await stripe.billingPortal.sessions.create({
customer: req.membershipOrg.organization.customerId, customer: req.membershipOrg.organization.customerId,
return_url: getSiteURL() + '/dashboard' return_url: (await getSiteURL()) + '/dashboard'
}); });
} }
@@ -365,7 +365,7 @@ export const getOrganizationSubscriptions = async (
) => { ) => {
let subscriptions; let subscriptions;
try { try {
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
@@ -44,7 +44,7 @@ export const emailPasswordReset = async (req: Request, res: Response) => {
substitutions: { substitutions: {
email, email,
token, token,
callback_url: getSiteURL() + '/password-reset' callback_url: (await getSiteURL()) + '/password-reset'
} }
}); });
} catch (err) { } catch (err) {
@@ -91,8 +91,8 @@ export const emailPasswordResetVerify = async (req: Request, res: Response) => {
payload: { payload: {
userId: user._id.toString() userId: user._id.toString()
}, },
expiresIn: getJwtSignupLifetime(), expiresIn: await getJwtSignupLifetime(),
secret: getJwtSignupSecret() secret: await getJwtSignupSecret()
}); });
} catch (err) { } catch (err) {
Sentry.setUser(null); Sentry.setUser(null);
@@ -39,7 +39,7 @@ export const pushSecrets = async (req: Request, res: Response) => {
// upload (encrypted) secrets to workspace with id [workspaceId] // upload (encrypted) secrets to workspace with id [workspaceId]
try { try {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
let { secrets }: { secrets: PushSecret[] } = req.body; let { secrets }: { secrets: PushSecret[] } = req.body;
const { keys, environment, channel } = req.body; const { keys, environment, channel } = req.body;
const { workspaceId } = req.params; const { workspaceId } = req.params;
@@ -114,7 +114,7 @@ export const pullSecrets = async (req: Request, res: Response) => {
let secrets; let secrets;
let key; let key;
try { try {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const environment: string = req.query.environment as string; const environment: string = req.query.environment as string;
const channel: string = req.query.channel as string; const channel: string = req.query.channel as string;
const { workspaceId } = req.params; const { workspaceId } = req.params;
@@ -183,7 +183,7 @@ export const pullSecretsServiceToken = async (req: Request, res: Response) => {
let secrets; let secrets;
let key; let key;
try { try {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const environment: string = req.query.environment as string; const environment: string = req.query.environment as string;
const channel: string = req.query.channel as string; const channel: string = req.query.channel as string;
const { workspaceId } = req.params; const { workspaceId } = req.params;
@@ -61,7 +61,7 @@ export const createServiceToken = async (req: Request, res: Response) => {
workspaceId workspaceId
}, },
expiresIn: expiresIn, expiresIn: expiresIn,
secret: getJwtServiceSecret() secret: await getJwtServiceSecret()
}); });
} catch (err) { } catch (err) {
return res.status(400).send({ return res.status(400).send({
@@ -21,7 +21,7 @@ export const beginEmailSignup = async (req: Request, res: Response) => {
try { try {
email = req.body.email; email = req.body.email;
if (getInviteOnlySignup()) { if (await getInviteOnlySignup()) {
// Only one user can create an account without being invited. The rest need to be invited in order to make an account // Only one user can create an account without being invited. The rest need to be invited in order to make an account
const userCount = await User.countDocuments({}) const userCount = await User.countDocuments({})
if (userCount != 0) { if (userCount != 0) {
@@ -75,7 +75,7 @@ export const verifyEmailSignup = async (req: Request, res: Response) => {
} }
// verify email // verify email
if (getSmtpConfigured()) { if (await getSmtpConfigured()) {
await checkEmailVerification({ await checkEmailVerification({
email, email,
code code
@@ -93,8 +93,8 @@ export const verifyEmailSignup = async (req: Request, res: Response) => {
payload: { payload: {
userId: user._id.toString() userId: user._id.toString()
}, },
expiresIn: getJwtSignupLifetime(), expiresIn: await getJwtSignupLifetime(),
secret: getJwtSignupSecret() secret: await getJwtSignupSecret()
}); });
} catch (err) { } catch (err) {
Sentry.setUser(null); Sentry.setUser(null);
@@ -13,7 +13,7 @@ export const handleWebhook = async (req: Request, res: Response) => {
let event; let event;
try { try {
// check request for valid stripe signature // check request for valid stripe signature
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
@@ -21,7 +21,7 @@ export const handleWebhook = async (req: Request, res: Response) => {
event = stripe.webhooks.constructEvent( event = stripe.webhooks.constructEvent(
req.body, req.body,
sig, sig,
getStripeWebhookSecret() await getStripeWebhookSecret()
); );
} catch (err) { } catch (err) {
Sentry.setUser({ email: req.user.email }); Sentry.setUser({ email: req.user.email });
@@ -43,7 +43,7 @@ export const createAPIKeyData = async (req: Request, res: Response) => {
const { name, expiresIn } = req.body; const { name, expiresIn } = req.body;
const secret = crypto.randomBytes(16).toString('hex'); const secret = crypto.randomBytes(16).toString('hex');
const secretHash = await bcrypt.hash(secret, getSaltRounds()); const secretHash = await bcrypt.hash(secret, await getSaltRounds());
const expiresAt = new Date(); const expiresAt = new Date();
expiresAt.setSeconds(expiresAt.getSeconds() + expiresIn); expiresAt.setSeconds(expiresAt.getSeconds() + expiresIn);
+4 -4
View File
@@ -124,8 +124,8 @@ export const login2 = async (req: Request, res: Response) => {
payload: { payload: {
userId: user._id.toString() userId: user._id.toString()
}, },
expiresIn: getJwtMfaLifetime(), expiresIn: await getJwtMfaLifetime(),
secret: getJwtMfaSecret() secret: await getJwtMfaSecret()
}); });
const code = await TokenService.createToken({ const code = await TokenService.createToken({
@@ -163,7 +163,7 @@ export const login2 = async (req: Request, res: Response) => {
httpOnly: true, httpOnly: true,
path: '/', path: '/',
sameSite: 'strict', sameSite: 'strict',
secure: getHttpsEnabled() secure: await getHttpsEnabled()
}); });
// case: user does not have MFA enablgged // case: user does not have MFA enablgged
@@ -302,7 +302,7 @@ export const verifyMfaToken = async (req: Request, res: Response) => {
httpOnly: true, httpOnly: true,
path: '/', path: '/',
sameSite: 'strict', sameSite: 'strict',
secure: getHttpsEnabled() secure: await getHttpsEnabled()
}); });
interface VerifyMfaTokenRes { interface VerifyMfaTokenRes {
@@ -17,7 +17,7 @@ import { AccountNotFoundError } from '../../utils/errors';
* @param res * @param res
*/ */
export const createSecret = async (req: Request, res: Response) => { export const createSecret = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const secretToCreate: CreateSecretRequestBody = req.body.secret; const secretToCreate: CreateSecretRequestBody = req.body.secret;
const { workspaceId, environment } = req.params const { workspaceId, environment } = req.params
const sanitizedSecret: SanitizedSecretForCreate = { const sanitizedSecret: SanitizedSecretForCreate = {
@@ -70,7 +70,7 @@ export const createSecret = async (req: Request, res: Response) => {
* @param res * @param res
*/ */
export const createSecrets = async (req: Request, res: Response) => { export const createSecrets = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const secretsToCreate: CreateSecretRequestBody[] = req.body.secrets; const secretsToCreate: CreateSecretRequestBody[] = req.body.secrets;
const { workspaceId, environment } = req.params const { workspaceId, environment } = req.params
const sanitizedSecretesToCreate: SanitizedSecretForCreate[] = [] const sanitizedSecretesToCreate: SanitizedSecretForCreate[] = []
@@ -132,7 +132,7 @@ export const createSecrets = async (req: Request, res: Response) => {
* @param res * @param res
*/ */
export const deleteSecrets = async (req: Request, res: Response) => { export const deleteSecrets = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const { workspaceId, environmentName } = req.params const { workspaceId, environmentName } = req.params
const secretIdsToDelete: string[] = req.body.secretIds const secretIdsToDelete: string[] = req.body.secretIds
@@ -186,7 +186,7 @@ export const deleteSecrets = async (req: Request, res: Response) => {
* @param res * @param res
*/ */
export const deleteSecret = async (req: Request, res: Response) => { export const deleteSecret = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
await Secret.findByIdAndDelete(req._secret._id) await Secret.findByIdAndDelete(req._secret._id)
if (postHogClient) { if (postHogClient) {
@@ -215,7 +215,7 @@ export const deleteSecret = async (req: Request, res: Response) => {
* @returns * @returns
*/ */
export const updateSecrets = async (req: Request, res: Response) => { export const updateSecrets = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const { workspaceId, environmentName } = req.params const { workspaceId, environmentName } = req.params
const secretsModificationsRequested: ModifySecretRequestBody[] = req.body.secrets; const secretsModificationsRequested: ModifySecretRequestBody[] = req.body.secrets;
const [secretIdsUserCanModifyError, secretIdsUserCanModify] = await to(Secret.find({ workspace: workspaceId, environment: environmentName }, { _id: 1 }).then()) const [secretIdsUserCanModifyError, secretIdsUserCanModify] = await to(Secret.find({ workspace: workspaceId, environment: environmentName }, { _id: 1 }).then())
@@ -283,7 +283,7 @@ export const updateSecrets = async (req: Request, res: Response) => {
* @returns * @returns
*/ */
export const updateSecret = async (req: Request, res: Response) => { export const updateSecret = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const { workspaceId, environmentName } = req.params const { workspaceId, environmentName } = req.params
const secretModificationsRequested: ModifySecretRequestBody = req.body.secret; const secretModificationsRequested: ModifySecretRequestBody = req.body.secret;
@@ -337,7 +337,7 @@ export const updateSecret = async (req: Request, res: Response) => {
* @returns * @returns
*/ */
export const getSecrets = async (req: Request, res: Response) => { export const getSecrets = async (req: Request, res: Response) => {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const { environment } = req.query; const { environment } = req.query;
const { workspaceId } = req.params; const { workspaceId } = req.params;
@@ -35,7 +35,7 @@ import {
export const batchSecrets = async (req: Request, res: Response) => { export const batchSecrets = async (req: Request, res: Response) => {
const channel = getChannelFromUserAgent(req.headers['user-agent']); const channel = getChannelFromUserAgent(req.headers['user-agent']);
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const { const {
workspaceId, workspaceId,
@@ -508,7 +508,7 @@ export const createSecrets = async (req: Request, res: Response) => {
workspaceId: new Types.ObjectId(workspaceId) workspaceId: new Types.ObjectId(workspaceId)
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
event: 'secrets added', event: 'secrets added',
@@ -683,7 +683,7 @@ export const getSecrets = async (req: Request, res: Response) => {
ipAddress: req.ip ipAddress: req.ip
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
event: 'secrets pulled', event: 'secrets pulled',
@@ -905,7 +905,7 @@ export const updateSecrets = async (req: Request, res: Response) => {
workspaceId: new Types.ObjectId(key) workspaceId: new Types.ObjectId(key)
}) })
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
event: 'secrets modified', event: 'secrets modified',
@@ -1039,7 +1039,7 @@ export const deleteSecrets = async (req: Request, res: Response) => {
workspaceId: new Types.ObjectId(key) workspaceId: new Types.ObjectId(key)
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
event: 'secrets deleted', event: 'secrets deleted',
@@ -72,7 +72,7 @@ export const createServiceAccount = async (req: Request, res: Response) => {
} }
const secret = crypto.randomBytes(16).toString('base64'); const secret = crypto.randomBytes(16).toString('base64');
const secretHash = await bcrypt.hash(secret, getSaltRounds()); const secretHash = await bcrypt.hash(secret, await getSaltRounds());
// create service account // create service account
const serviceAccount = await new ServiceAccount({ const serviceAccount = await new ServiceAccount({
@@ -84,7 +84,7 @@ export const createServiceTokenData = async (req: Request, res: Response) => {
} = req.body; } = req.body;
const secret = crypto.randomBytes(16).toString('hex'); const secret = crypto.randomBytes(16).toString('hex');
const secretHash = await bcrypt.hash(secret, getSaltRounds()); const secretHash = await bcrypt.hash(secret, await getSaltRounds());
let expiresAt; let expiresAt;
if (expiresIn) { if (expiresIn) {
@@ -108,7 +108,7 @@ export const completeAccountSignup = async (req: Request, res: Response) => {
token = tokens.token; token = tokens.token;
// sending a welcome email to new users // sending a welcome email to new users
if (getLoopsApiKey()) { if (await getLoopsApiKey()) {
await request.post("https://app.loops.so/api/v1/events/send", { await request.post("https://app.loops.so/api/v1/events/send", {
"email": email, "email": email,
"eventName": "Sign Up", "eventName": "Sign Up",
@@ -117,7 +117,7 @@ export const completeAccountSignup = async (req: Request, res: Response) => {
}, { }, {
headers: { headers: {
"Accept": "application/json", "Accept": "application/json",
"Authorization": "Bearer " + getLoopsApiKey() "Authorization": "Bearer " + (await getLoopsApiKey())
}, },
}); });
} }
@@ -127,7 +127,7 @@ export const completeAccountSignup = async (req: Request, res: Response) => {
httpOnly: true, httpOnly: true,
path: '/', path: '/',
sameSite: 'strict', sameSite: 'strict',
secure: getHttpsEnabled() secure: await getHttpsEnabled()
}); });
} catch (err) { } catch (err) {
Sentry.setUser(null); Sentry.setUser(null);
@@ -232,7 +232,7 @@ export const completeAccountInvite = async (req: Request, res: Response) => {
httpOnly: true, httpOnly: true,
path: '/', path: '/',
sameSite: 'strict', sameSite: 'strict',
secure: getHttpsEnabled() secure: await getHttpsEnabled()
}); });
} catch (err) { } catch (err) {
Sentry.setUser(null); Sentry.setUser(null);
@@ -48,7 +48,7 @@ interface V2PushSecret {
export const pushWorkspaceSecrets = async (req: Request, res: Response) => { export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
// upload (encrypted) secrets to workspace with id [workspaceId] // upload (encrypted) secrets to workspace with id [workspaceId]
try { try {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
let { secrets }: { secrets: V2PushSecret[] } = req.body; let { secrets }: { secrets: V2PushSecret[] } = req.body;
const { keys, environment, channel } = req.body; const { keys, environment, channel } = req.body;
const { workspaceId } = req.params; const { workspaceId } = req.params;
@@ -123,7 +123,7 @@ export const pushWorkspaceSecrets = async (req: Request, res: Response) => {
export const pullSecrets = async (req: Request, res: Response) => { export const pullSecrets = async (req: Request, res: Response) => {
let secrets; let secrets;
try { try {
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
const environment: string = req.query.environment as string; const environment: string = req.query.environment as string;
const channel: string = req.query.channel as string; const channel: string = req.query.channel as string;
const { workspaceId } = req.params; const { workspaceId } = req.params;
@@ -12,7 +12,7 @@ import { getStripeSecretKey, getStripeWebhookSecret } from '../../../config';
export const handleWebhook = async (req: Request, res: Response) => { export const handleWebhook = async (req: Request, res: Response) => {
let event; let event;
try { try {
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
@@ -21,7 +21,7 @@ export const handleWebhook = async (req: Request, res: Response) => {
event = stripe.webhooks.constructEvent( event = stripe.webhooks.constructEvent(
req.body, req.body,
sig, sig,
getStripeWebhookSecret() await getStripeWebhookSecret()
); );
} catch (err) { } catch (err) {
Sentry.setUser({ email: req.user.email }); Sentry.setUser({ email: req.user.email });
+5 -5
View File
@@ -104,7 +104,7 @@ const getAuthUserPayload = async ({
authTokenValue: string; authTokenValue: string;
}) => { }) => {
const decodedToken = <jwt.UserIDJwtPayload>( const decodedToken = <jwt.UserIDJwtPayload>(
jwt.verify(authTokenValue, getJwtAuthSecret()) jwt.verify(authTokenValue, await getJwtAuthSecret())
); );
const user = await User.findOne({ const user = await User.findOne({
@@ -263,16 +263,16 @@ const issueAuthTokens = async ({ userId }: { userId: string }) => {
payload: { payload: {
userId userId
}, },
expiresIn: getJwtAuthLifetime(), expiresIn: await getJwtAuthLifetime(),
secret: getJwtAuthSecret() secret: await getJwtAuthSecret()
}); });
const refreshToken = createToken({ const refreshToken = createToken({
payload: { payload: {
userId userId
}, },
expiresIn: getJwtRefreshLifetime(), expiresIn: await getJwtRefreshLifetime(),
secret: getJwtRefreshSecret() secret: await getJwtRefreshSecret()
}); });
return { return {
+2 -2
View File
@@ -119,7 +119,7 @@ const createBot = async ({
const { publicKey, privateKey } = generateKeyPair(); const { publicKey, privateKey } = generateKeyPair();
const { ciphertext, iv, tag } = encryptSymmetric({ const { ciphertext, iv, tag } = encryptSymmetric({
plaintext: privateKey, plaintext: privateKey,
key: getEncryptionKey() key: await getEncryptionKey()
}); });
bot = await new Bot({ bot = await new Bot({
@@ -216,7 +216,7 @@ const getKey = async ({ workspaceId }: { workspaceId: Types.ObjectId }) => {
ciphertext: bot.encryptedPrivateKey, ciphertext: bot.encryptedPrivateKey,
iv: bot.iv, iv: bot.iv,
tag: bot.tag, tag: bot.tag,
key: getEncryptionKey() key: await getEncryptionKey()
}); });
key = decryptAsymmetric({ key = decryptAsymmetric({
+2 -2
View File
@@ -20,12 +20,12 @@ const initDatabaseHelper = async ({
// allow empty strings to pass the required validator // allow empty strings to pass the required validator
mongoose.Schema.Types.String.checkRequired(v => typeof v === 'string'); mongoose.Schema.Types.String.checkRequired(v => typeof v === 'string');
getLogger("database").info("Database connection established"); (await getLogger("database")).info("Database connection established");
await EESecretService.initSecretVersioning(); await EESecretService.initSecretVersioning();
await SecretService.initSecretBlindIndexDataHelper(); await SecretService.initSecretBlindIndexDataHelper();
} catch (err) { } catch (err) {
getLogger("database").error(`Unable to establish Database connection due to the error.\n${err}`); (await getLogger("database")).error(`Unable to establish Database connection due to the error.\n${err}`);
} }
return mongoose.connection; return mongoose.connection;
+2 -2
View File
@@ -25,7 +25,7 @@ const sendMail = async ({
recipients: string[]; recipients: string[];
substitutions: any; substitutions: any;
}) => { }) => {
if (getSmtpConfigured()) { if (await getSmtpConfigured()) {
try { try {
const html = fs.readFileSync( const html = fs.readFileSync(
path.resolve(__dirname, '../templates/' + template), path.resolve(__dirname, '../templates/' + template),
@@ -35,7 +35,7 @@ const sendMail = async ({
const htmlToSend = temp(substitutions); const htmlToSend = temp(substitutions);
await smtpTransporter.sendMail({ await smtpTransporter.sendMail({
from: `"${getSmtpFromName()}" <${getSmtpFromAddress()}>`, from: `"${await getSmtpFromName()}" <${await getSmtpFromAddress()}>`,
to: recipients.join(', '), to: recipients.join(', '),
subject: subjectLine, subject: subjectLine,
html: htmlToSend html: htmlToSend
+7 -7
View File
@@ -123,11 +123,11 @@ const createOrganization = async ({
let organization; let organization;
try { try {
// register stripe account // register stripe account
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
if (getStripeSecretKey()) { if (await getStripeSecretKey()) {
const customer = await stripe.customers.create({ const customer = await stripe.customers.create({
email, email,
description: name description: name
@@ -177,14 +177,14 @@ const initSubscriptionOrg = async ({
if (organization) { if (organization) {
if (organization.customerId) { if (organization.customerId) {
// initialize starter subscription with quantity of 0 // initialize starter subscription with quantity of 0
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
const productToPriceMap = { const productToPriceMap = {
starter: getStripeProductStarter(), starter: await getStripeProductStarter(),
team: getStripeProductTeam(), team: await getStripeProductTeam(),
pro: getStripeProductPro() pro: await getStripeProductPro()
}; };
stripeSubscription = await stripe.subscriptions.create({ stripeSubscription = await stripe.subscriptions.create({
@@ -239,7 +239,7 @@ const updateSubscriptionOrgQuantity = async ({
status: ACCEPTED status: ACCEPTED
}); });
const stripe = new Stripe(getStripeSecretKey(), { const stripe = new Stripe(await getStripeSecretKey(), {
apiVersion: '2022-08-01' apiVersion: '2022-08-01'
}); });
+9 -9
View File
@@ -242,7 +242,7 @@ const initSecretBlindIndexDataHelper = async () => {
tag: saltTag tag: saltTag
} = encryptSymmetric({ } = encryptSymmetric({
plaintext: salt, plaintext: salt,
key: getEncryptionKey() key: await getEncryptionKey()
}); });
const secretBlindIndexData = new SecretBlindIndexData({ const secretBlindIndexData = new SecretBlindIndexData({
@@ -280,7 +280,7 @@ const createSecretBlindIndexDataHelper = async ({
tag: saltTag tag: saltTag
} = encryptSymmetric({ } = encryptSymmetric({
plaintext: salt, plaintext: salt,
key: getEncryptionKey() key: await getEncryptionKey()
}); });
const secretBlindIndexData = await new SecretBlindIndexData({ const secretBlindIndexData = await new SecretBlindIndexData({
@@ -316,7 +316,7 @@ const getSecretBlindIndexSaltHelper = async ({
ciphertext: secretBlindIndexData.encryptedSaltCiphertext, ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
iv: secretBlindIndexData.saltIV, iv: secretBlindIndexData.saltIV,
tag: secretBlindIndexData.saltTag, tag: secretBlindIndexData.saltTag,
key: getEncryptionKey() key: await getEncryptionKey()
}); });
return salt; return salt;
@@ -378,7 +378,7 @@ const generateSecretBlindIndexHelper = async ({
ciphertext: secretBlindIndexData.encryptedSaltCiphertext, ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
iv: secretBlindIndexData.saltIV, iv: secretBlindIndexData.saltIV,
tag: secretBlindIndexData.saltTag, tag: secretBlindIndexData.saltTag,
key: getEncryptionKey() key: await getEncryptionKey()
}); });
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({ const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
@@ -508,7 +508,7 @@ const createSecretHelper = async ({
workspaceId workspaceId
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
@@ -578,7 +578,7 @@ const getSecretsHelper = async ({
ipAddress: authData.authIP ipAddress: authData.authIP
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
@@ -660,7 +660,7 @@ const getSecretHelper = async ({
ipAddress: authData.authIP ipAddress: authData.authIP
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
@@ -798,7 +798,7 @@ const updateSecretHelper = async ({
workspaceId workspaceId
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
@@ -905,7 +905,7 @@ const deleteSecretHelper = async ({
workspaceId workspaceId
}); });
const postHogClient = TelemetryService.getPostHogClient(); const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) { if (postHogClient) {
postHogClient.capture({ postHogClient.capture({
+1 -1
View File
@@ -84,7 +84,7 @@ const createTokenHelper = async ({
const query: TokenDataQuery = { type }; const query: TokenDataQuery = { type };
const update: TokenDataUpdate = { const update: TokenDataUpdate = {
type, type,
tokenHash: await bcrypt.hash(token, getSaltRounds()), tokenHash: await bcrypt.hash(token, await getSaltRounds()),
expiresAt expiresAt
} }
-1
View File
@@ -28,7 +28,6 @@ import {
AUTH_MODE_SERVICE_TOKEN, AUTH_MODE_SERVICE_TOKEN,
AUTH_MODE_API_KEY AUTH_MODE_API_KEY
} from '../variables'; } from '../variables';
import { getEncryptionKey } from '../config';
import { encryptSymmetric } from '../utils/crypto'; import { encryptSymmetric } from '../utils/crypto';
import { SecretService } from '../services'; import { SecretService } from '../services';
+13 -15
View File
@@ -79,22 +79,20 @@ import {
} from './config'; } from './config';
const main = async () => { const main = async () => {
if (process.env.INFISICAL_TOKEN != "" || process.env.INFISICAL_TOKEN != undefined) { infisical.connect({
await infisical.connect({ token: process.env.INFISICAL_TOKEN!
token: process.env.INFISICAL_TOKEN! });
});
}
TelemetryService.logTelemetryMessage(); TelemetryService.logTelemetryMessage();
setTransporter(initSmtp()); setTransporter(await initSmtp());
await DatabaseService.initDatabase(getMongoURL()); await DatabaseService.initDatabase(await getMongoURL());
if (getNodeEnv() !== 'test') { if ((await getNodeEnv()) !== 'test') {
Sentry.init({ Sentry.init({
dsn: getSentryDSN(), dsn: await getSentryDSN(),
tracesSampleRate: 1.0, tracesSampleRate: 1.0,
debug: getNodeEnv() === 'production' ? false : true, debug: await getNodeEnv() === 'production' ? false : true,
environment: getNodeEnv() environment: await getNodeEnv()
}); });
} }
@@ -106,13 +104,13 @@ const main = async () => {
app.use( app.use(
cors({ cors({
credentials: true, credentials: true,
origin: getSiteURL() origin: await getSiteURL()
}) })
); );
app.use(requestIp.mw()); app.use(requestIp.mw());
if (getNodeEnv() === 'production') { if ((await getNodeEnv()) === 'production') {
// enable app-wide rate-limiting + helmet security // enable app-wide rate-limiting + helmet security
// in production // in production
app.disable('x-powered-by'); app.disable('x-powered-by');
@@ -177,8 +175,8 @@ const main = async () => {
app.use(requestErrorHandler) app.use(requestErrorHandler)
const server = app.listen(getPort(), () => { const server = app.listen(await getPort(), async () => {
getLogger("backend-main").info(`Server started listening at port ${getPort()}`) (await getLogger("backend-main")).info(`Server started listening at port ${await getPort()}`)
}); });
await createTestUserForDevelopment(); await createTestUserForDevelopment();
+16 -16
View File
@@ -159,9 +159,9 @@ const exchangeCodeAzure = async ({
grant_type: 'authorization_code', grant_type: 'authorization_code',
code: code, code: code,
scope: 'https://vault.azure.net/.default openid offline_access', scope: 'https://vault.azure.net/.default openid offline_access',
client_id: getClientIdAzure(), client_id: await getClientIdAzure(),
client_secret: getClientSecretAzure(), client_secret: await getClientSecretAzure(),
redirect_uri: `${getSiteURL()}/integrations/azure-key-vault/oauth2/callback` redirect_uri: `${await getSiteURL()}/integrations/azure-key-vault/oauth2/callback`
} as any) } as any)
)).data; )).data;
@@ -204,7 +204,7 @@ const exchangeCodeHeroku = async ({
new URLSearchParams({ new URLSearchParams({
grant_type: 'authorization_code', grant_type: 'authorization_code',
code: code, code: code,
client_secret: getClientSecretHeroku() client_secret: await getClientSecretHeroku()
} as any) } as any)
)).data; )).data;
@@ -242,9 +242,9 @@ const exchangeCodeVercel = async ({ code }: { code: string }) => {
INTEGRATION_VERCEL_TOKEN_URL, INTEGRATION_VERCEL_TOKEN_URL,
new URLSearchParams({ new URLSearchParams({
code: code, code: code,
client_id: getClientIdVercel(), client_id: await getClientIdVercel(),
client_secret: getClientSecretVercel(), client_secret: await getClientSecretVercel(),
redirect_uri: `${getSiteURL()}/integrations/vercel/oauth2/callback` redirect_uri: `${await getSiteURL()}/integrations/vercel/oauth2/callback`
} as any) } as any)
) )
).data; ).data;
@@ -282,9 +282,9 @@ const exchangeCodeNetlify = async ({ code }: { code: string }) => {
new URLSearchParams({ new URLSearchParams({
grant_type: 'authorization_code', grant_type: 'authorization_code',
code: code, code: code,
client_id: getClientIdNetlify(), client_id: await getClientIdNetlify(),
client_secret: getClientSecretNetlify(), client_secret: await getClientSecretNetlify(),
redirect_uri: `${getSiteURL()}/integrations/netlify/oauth2/callback` redirect_uri: `${await getSiteURL()}/integrations/netlify/oauth2/callback`
} as any) } as any)
) )
).data; ).data;
@@ -333,10 +333,10 @@ const exchangeCodeGithub = async ({ code }: { code: string }) => {
res = ( res = (
await request.get(INTEGRATION_GITHUB_TOKEN_URL, { await request.get(INTEGRATION_GITHUB_TOKEN_URL, {
params: { params: {
client_id: getClientIdGitHub(), client_id: await getClientIdGitHub(),
client_secret: getClientSecretGitHub(), client_secret: await getClientSecretGitHub(),
code: code, code: code,
redirect_uri: `${getSiteURL()}/integrations/github/oauth2/callback` redirect_uri: `${await getSiteURL()}/integrations/github/oauth2/callback`
}, },
headers: { headers: {
'Accept': 'application/json', 'Accept': 'application/json',
@@ -379,9 +379,9 @@ const exchangeCodeGitlab = async ({ code }: { code: string }) => {
new URLSearchParams({ new URLSearchParams({
grant_type: 'authorization_code', grant_type: 'authorization_code',
code: code, code: code,
client_id: getClientIdGitLab(), client_id: await getClientIdGitLab(),
client_secret: getClientSecretGitLab(), client_secret: await getClientSecretGitLab(),
redirect_uri: `${getSiteURL()}/integrations/gitlab/oauth2/callback` redirect_uri: `${await getSiteURL()}/integrations/gitlab/oauth2/callback`
} as any), } as any),
{ {
headers: { headers: {
+6 -6
View File
@@ -133,11 +133,11 @@ const exchangeRefreshAzure = async ({
const { data }: { data: RefreshTokenAzureResponse } = await request.post( const { data }: { data: RefreshTokenAzureResponse } = await request.post(
INTEGRATION_AZURE_TOKEN_URL, INTEGRATION_AZURE_TOKEN_URL,
new URLSearchParams({ new URLSearchParams({
client_id: getClientIdAzure(), client_id: await getClientIdAzure(),
scope: 'openid offline_access', scope: 'openid offline_access',
refresh_token: refreshToken, refresh_token: refreshToken,
grant_type: 'refresh_token', grant_type: 'refresh_token',
client_secret: getClientSecretAzure() client_secret: await getClientSecretAzure()
} as any) } as any)
); );
@@ -180,7 +180,7 @@ const exchangeRefreshHeroku = async ({
new URLSearchParams({ new URLSearchParams({
grant_type: 'refresh_token', grant_type: 'refresh_token',
refresh_token: refreshToken, refresh_token: refreshToken,
client_secret: getClientSecretHeroku() client_secret: await getClientSecretHeroku()
} as any) } as any)
); );
@@ -223,9 +223,9 @@ const exchangeRefreshGitLab = async ({
new URLSearchParams({ new URLSearchParams({
grant_type: 'refresh_token', grant_type: 'refresh_token',
refresh_token: refreshToken, refresh_token: refreshToken,
client_id: getClientIdGitLab, client_id: await getClientIdGitLab,
client_secret: getClientSecretGitLab(), client_secret: await getClientSecretGitLab(),
redirect_uri: `${getSiteURL()}/integrations/gitlab/oauth2/callback` redirect_uri: `${await getSiteURL()}/integrations/gitlab/oauth2/callback`
} as any), } as any),
{ {
headers: { headers: {
@@ -5,9 +5,9 @@ import { getLogger } from "../utils/logger";
import RequestError, { LogLevel } from "../utils/requestError"; import RequestError, { LogLevel } from "../utils/requestError";
import { getNodeEnv } from '../config'; import { getNodeEnv } from '../config';
export const requestErrorHandler: ErrorRequestHandler = (error: RequestError | Error, req, res, next) => { export const requestErrorHandler: ErrorRequestHandler = async (error: RequestError | Error, req, res, next) => {
if (res.headersSent) return next(); if (res.headersSent) return next();
if (getNodeEnv() !== "production") { if ((await getNodeEnv()) !== "production") {
/* eslint-disable no-console */ /* eslint-disable no-console */
console.log(error) console.log(error)
/* eslint-enable no-console */ /* eslint-enable no-console */
@@ -15,8 +15,8 @@ export const requestErrorHandler: ErrorRequestHandler = (error: RequestError | E
//TODO: Find better way to type check for error. In current setting you need to cast type to get the functions and variables from RequestError //TODO: Find better way to type check for error. In current setting you need to cast type to get the functions and variables from RequestError
if (!(error instanceof RequestError)) { if (!(error instanceof RequestError)) {
error = InternalServerError({ context: { exception: error.message }, stack: error.stack }) error = InternalServerError({ context: { exception: error.message }, stack: error.stack });
getLogger('backend-main').log((<RequestError>error).levelName.toLowerCase(), (<RequestError>error).message) (await getLogger('backend-main')).log((<RequestError>error).levelName.toLowerCase(), (<RequestError>error).message)
} }
//* Set Sentry user identification if req.user is populated //* Set Sentry user identification if req.user is populated
+1 -1
View File
@@ -26,7 +26,7 @@ const requireMfaAuth = async (
if(AUTH_TOKEN_VALUE === null) return next(BadRequestError({message: 'Missing Authorization Body in the request header'})) if(AUTH_TOKEN_VALUE === null) return next(BadRequestError({message: 'Missing Authorization Body in the request header'}))
const decodedToken = <jwt.UserIDJwtPayload>( const decodedToken = <jwt.UserIDJwtPayload>(
jwt.verify(AUTH_TOKEN_VALUE, getJwtMfaSecret()) jwt.verify(AUTH_TOKEN_VALUE, await getJwtMfaSecret())
); );
const user = await User.findOne({ const user = await User.findOne({
@@ -33,7 +33,7 @@ const requireServiceTokenAuth = async (
if(AUTH_TOKEN_VALUE === null) return next(BadRequestError({message: 'Missing Authorization Body in the request header'})) if(AUTH_TOKEN_VALUE === null) return next(BadRequestError({message: 'Missing Authorization Body in the request header'}))
const decodedToken = <jwt.UserIDJwtPayload>( const decodedToken = <jwt.UserIDJwtPayload>(
jwt.verify(AUTH_TOKEN_VALUE, getJwtServiceSecret()) jwt.verify(AUTH_TOKEN_VALUE, await getJwtServiceSecret())
); );
const serviceToken = await ServiceToken.findOne({ const serviceToken = await ServiceToken.findOne({
+1 -1
View File
@@ -27,7 +27,7 @@ const requireSignupAuth = async (
if(AUTH_TOKEN_VALUE === null) return next(BadRequestError({message: 'Missing Authorization Body in the request header'})) if(AUTH_TOKEN_VALUE === null) return next(BadRequestError({message: 'Missing Authorization Body in the request header'}))
const decodedToken = <jwt.UserIDJwtPayload>( const decodedToken = <jwt.UserIDJwtPayload>(
jwt.verify(AUTH_TOKEN_VALUE, getJwtSignupSecret()) jwt.verify(AUTH_TOKEN_VALUE, await getJwtSignupSecret())
); );
const user = await User.findOne({ const user = await User.findOne({
+2 -2
View File
@@ -5,11 +5,11 @@ const router = express.Router();
router.get( router.get(
'/status', '/status',
(req: Request, res: Response) => { async (req: Request, res: Response) => {
res.status(200).json({ res.status(200).json({
date: new Date(), date: new Date(),
message: 'Ok', message: 'Ok',
emailConfigured: getSmtpConfigured() emailConfigured: await getSmtpConfigured()
}) })
} }
); );
-2
View File
@@ -1,5 +1,3 @@
import mongoose from 'mongoose';
import { getLogger } from '../utils/logger';
import { import {
initDatabaseHelper, initDatabaseHelper,
closeDatabaseHelper closeDatabaseHelper
+7 -7
View File
@@ -24,9 +24,9 @@ class Telemetry {
/** /**
* Logs telemetry enable/disable notice. * Logs telemetry enable/disable notice.
*/ */
static logTelemetryMessage = () => { static logTelemetryMessage = async () => {
if(!getTelemetryEnabled()){ if(!(await getTelemetryEnabled())){
getLogger("backend-main").info([ (await getLogger("backend-main")).info([
"", "",
"To improve, Infisical collects telemetry data about general usage.", "To improve, Infisical collects telemetry data about general usage.",
"This helps us understand how the product is doing and guide our product development to create the best possible platform; it also helps us demonstrate growth as we support Infisical as open-source software.", "This helps us understand how the product is doing and guide our product development to create the best possible platform; it also helps us demonstrate growth as we support Infisical as open-source software.",
@@ -39,12 +39,12 @@ class Telemetry {
* Return an instance of the PostHog client initialized. * Return an instance of the PostHog client initialized.
* @returns * @returns
*/ */
static getPostHogClient = () => { static getPostHogClient = async () => {
let postHogClient: any; let postHogClient: any;
if (getNodeEnv() === 'production' && getTelemetryEnabled()) { if ((await getNodeEnv()) === 'production' && (await getTelemetryEnabled())) {
// case: enable opt-out telemetry in production // case: enable opt-out telemetry in production
postHogClient = new PostHog(getPostHogProjectApiKey(), { postHogClient = new PostHog(await getPostHogProjectApiKey(), {
host: getPostHogHost() host: await getPostHogHost()
}); });
} }
+2 -2
View File
@@ -3,8 +3,8 @@ import { createTerminus } from '@godaddy/terminus';
import { getLogger } from '../utils/logger'; import { getLogger } from '../utils/logger';
export const setUpHealthEndpoint = <T>(server: T) => { export const setUpHealthEndpoint = <T>(server: T) => {
const onSignal = () => { const onSignal = async () => {
getLogger('backend-main').info('Server is starting clean-up'); (await getLogger('backend-main')).info('Server is starting clean-up');
return Promise.all([ return Promise.all([
new Promise((resolve) => { new Promise((resolve) => {
if (mongoose.connection && mongoose.connection.readyState == 1) { if (mongoose.connection && mongoose.connection.readyState == 1) {
+11 -11
View File
@@ -15,21 +15,21 @@ import {
getSmtpPort getSmtpPort
} from '../config'; } from '../config';
export const initSmtp = () => { export const initSmtp = async () => {
const mailOpts: SMTPConnection.Options = { const mailOpts: SMTPConnection.Options = {
host: getSmtpHost(), host: await getSmtpHost(),
port: getSmtpPort() port: await getSmtpPort()
}; };
if (getSmtpUsername() && getSmtpPassword()) { if ((await getSmtpUsername()) && (await getSmtpPassword())) {
mailOpts.auth = { mailOpts.auth = {
user: getSmtpUsername(), user: await getSmtpUsername(),
pass: getSmtpPassword() pass: await getSmtpPassword()
}; };
} }
if (getSmtpSecure() ? getSmtpSecure() : false) { if ((await getSmtpSecure()) ? (await getSmtpSecure()) : false) {
switch (getSmtpHost()) { switch (await getSmtpHost()) {
case SMTP_HOST_SENDGRID: case SMTP_HOST_SENDGRID:
mailOpts.requireTLS = true; mailOpts.requireTLS = true;
break; break;
@@ -52,7 +52,7 @@ export const initSmtp = () => {
} }
break; break;
default: default:
if (getSmtpHost().includes('amazonaws.com')) { if ((await getSmtpHost()).includes('amazonaws.com')) {
mailOpts.tls = { mailOpts.tls = {
ciphers: 'TLSv1.2' ciphers: 'TLSv1.2'
} }
@@ -70,10 +70,10 @@ export const initSmtp = () => {
Sentry.setUser(null); Sentry.setUser(null);
Sentry.captureMessage('SMTP - Successfully connected'); Sentry.captureMessage('SMTP - Successfully connected');
}) })
.catch((err) => { .catch(async (err) => {
Sentry.setUser(null); Sentry.setUser(null);
Sentry.captureException( Sentry.captureException(
`SMTP - Failed to connect to ${getSmtpHost()}:${getSmtpPort()} \n\t${err}` `SMTP - Failed to connect to ${await getSmtpHost()}:${await getSmtpPort()} \n\t${err}`
); );
}); });
+1 -1
View File
@@ -19,7 +19,7 @@ export const testWorkspaceKeyId = "63cf48f0225e6955acec5eff"
export const plainTextWorkspaceKey = "543fef8224813a46230b0a50a46c5fb2" export const plainTextWorkspaceKey = "543fef8224813a46230b0a50a46c5fb2"
export const createTestUserForDevelopment = async () => { export const createTestUserForDevelopment = async () => {
if (getNodeEnv() === "development" || getNodeEnv() === "test") { if ((await getNodeEnv()) === "development" || (await getNodeEnv()) === "test") {
const testUser = { const testUser = {
_id: testUserId, _id: testUserId,
email: testUserEmail, email: testUserEmail,
+10 -12
View File
@@ -12,7 +12,7 @@ const logFormat = (prefix: string) => combine(
printf((info) => `${info.timestamp} ${info.label} ${info.level}: ${info.message}`) printf((info) => `${info.timestamp} ${info.label} ${info.level}: ${info.message}`)
); );
const createLoggerWithLabel = (level: string, label: string) => { const createLoggerWithLabel = async (level: string, label: string) => {
const _level = level.toLowerCase() || 'info' const _level = level.toLowerCase() || 'info'
//* Always add Console output to transports //* Always add Console output to transports
const _transports: any[] = [ const _transports: any[] = [
@@ -25,10 +25,10 @@ const createLoggerWithLabel = (level: string, label: string) => {
}) })
] ]
//* Add LokiTransport if it's enabled //* Add LokiTransport if it's enabled
if(getLokiHost() !== undefined){ if((await getLokiHost()) !== undefined){
_transports.push( _transports.push(
new LokiTransport({ new LokiTransport({
host: getLokiHost(), host: await getLokiHost(),
handleExceptions: true, handleExceptions: true,
handleRejections: true, handleRejections: true,
batching: true, batching: true,
@@ -40,7 +40,7 @@ const createLoggerWithLabel = (level: string, label: string) => {
labels: { labels: {
app: process.env.npm_package_name, app: process.env.npm_package_name,
version: process.env.npm_package_version, version: process.env.npm_package_version,
environment: getNodeEnv() environment: await getNodeEnv()
}, },
onConnectionError: (err: Error)=> console.error('Connection error while connecting to Loki Server.\n', err) onConnectionError: (err: Error)=> console.error('Connection error while connecting to Loki Server.\n', err)
}) })
@@ -58,12 +58,10 @@ const createLoggerWithLabel = (level: string, label: string) => {
}); });
} }
const DEFAULT_LOGGERS = { export const getLogger = async (loggerName: 'backend-main' | 'database') => {
"backend-main": createLoggerWithLabel('info', '[IFSC:backend-main]'), const logger = {
"database": createLoggerWithLabel('info', '[IFSC:database]'), "backend-main": await createLoggerWithLabel('info', '[IFSC:backend-main]'),
} "database": await createLoggerWithLabel('info', '[IFSC:database]'),
type LoggerNames = keyof typeof DEFAULT_LOGGERS }
return logger[loggerName]
export const getLogger = (loggerName: LoggerNames) => {
return DEFAULT_LOGGERS[loggerName]
} }
+2 -2
View File
@@ -81,13 +81,13 @@ export default class RequestError extends Error{
return obj return obj
} }
public format(req: Request){ public async format(req: Request){
let _context = Object.assign({ let _context = Object.assign({
stacktrace: this.stacktrace stacktrace: this.stacktrace
}, this.context) }, this.context)
//* Omit sensitive information from context that can leak internal workings of this program if user is not developer //* Omit sensitive information from context that can leak internal workings of this program if user is not developer
if(!getVerboseErrorOutput()){ if(!(await getVerboseErrorOutput())){
_context = this._omit(_context, [ _context = this._omit(_context, [
'stacktrace', 'stacktrace',
'exception', 'exception',
+7 -7
View File
@@ -61,7 +61,7 @@ const INTEGRATION_CIRCLECI_API_URL = "https://circleci.com/api";
const INTEGRATION_TRAVISCI_API_URL = "https://api.travis-ci.com"; const INTEGRATION_TRAVISCI_API_URL = "https://api.travis-ci.com";
const INTEGRATION_SUPABASE_API_URL = 'https://api.supabase.com'; const INTEGRATION_SUPABASE_API_URL = 'https://api.supabase.com';
const getIntegrationOptions = () => { const getIntegrationOptions = async () => {
const INTEGRATION_OPTIONS = [ const INTEGRATION_OPTIONS = [
{ {
name: 'Heroku', name: 'Heroku',
@@ -69,7 +69,7 @@ const getIntegrationOptions = () => {
image: 'Heroku.png', image: 'Heroku.png',
isAvailable: true, isAvailable: true,
type: 'oauth', type: 'oauth',
clientId: getClientIdHeroku(), clientId: await getClientIdHeroku(),
docsLink: '' docsLink: ''
}, },
{ {
@@ -79,7 +79,7 @@ const getIntegrationOptions = () => {
isAvailable: true, isAvailable: true,
type: 'oauth', type: 'oauth',
clientId: '', clientId: '',
clientSlug: getClientSlugVercel(), clientSlug: await getClientSlugVercel(),
docsLink: '' docsLink: ''
}, },
{ {
@@ -88,7 +88,7 @@ const getIntegrationOptions = () => {
image: 'Netlify.png', image: 'Netlify.png',
isAvailable: true, isAvailable: true,
type: 'oauth', type: 'oauth',
clientId: getClientIdNetlify(), clientId: await getClientIdNetlify(),
docsLink: '' docsLink: ''
}, },
{ {
@@ -97,7 +97,7 @@ const getIntegrationOptions = () => {
image: 'GitHub.png', image: 'GitHub.png',
isAvailable: true, isAvailable: true,
type: 'oauth', type: 'oauth',
clientId: getClientIdGitHub(), clientId: await getClientIdGitHub(),
docsLink: '' docsLink: ''
}, },
{ {
@@ -151,7 +151,7 @@ const getIntegrationOptions = () => {
image: 'Microsoft Azure.png', image: 'Microsoft Azure.png',
isAvailable: true, isAvailable: true,
type: 'oauth', type: 'oauth',
clientId: getClientIdAzure(), clientId: await getClientIdAzure(),
docsLink: '' docsLink: ''
}, },
{ {
@@ -169,7 +169,7 @@ const getIntegrationOptions = () => {
image: 'GitLab.png', image: 'GitLab.png',
isAvailable: true, isAvailable: true,
type: 'custom', type: 'custom',
clientId: getClientIdGitLab(), clientId: await getClientIdGitLab(),
docsLink: '' docsLink: ''
}, },
{ {