mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 00:27:35 +00:00
Implement getting auth
This commit is contained in:
@@ -17,7 +17,7 @@ export const pkiAcmeAuthDALFactory = (db: TDbClient) => {
|
|||||||
.select(
|
.select(
|
||||||
selectAllTableCols(TableName.PkiAcmeAuth),
|
selectAllTableCols(TableName.PkiAcmeAuth),
|
||||||
db.ref("id").withSchema(TableName.PkiAcmeChallenge).as("challengeId"),
|
db.ref("id").withSchema(TableName.PkiAcmeChallenge).as("challengeId"),
|
||||||
db.ref("token").withSchema(TableName.PkiAcmeChallenge).as("challengeToken"),
|
db.ref("type").withSchema(TableName.PkiAcmeChallenge).as("challengeType"),
|
||||||
db.ref("status").withSchema(TableName.PkiAcmeChallenge).as("challengeStatus")
|
db.ref("status").withSchema(TableName.PkiAcmeChallenge).as("challengeStatus")
|
||||||
)
|
)
|
||||||
.where(`${TableName.PkiAcmeAuth}.accountId`, accountId)
|
.where(`${TableName.PkiAcmeAuth}.accountId`, accountId)
|
||||||
@@ -34,9 +34,9 @@ export const pkiAcmeAuthDALFactory = (db: TDbClient) => {
|
|||||||
{
|
{
|
||||||
key: "challengeId",
|
key: "challengeId",
|
||||||
label: "challenges" as const,
|
label: "challenges" as const,
|
||||||
mapper: ({ challengeId, challengeToken, challengeStatus }) => ({
|
mapper: ({ challengeId, challengeType, challengeStatus }) => ({
|
||||||
id: challengeId,
|
id: challengeId,
|
||||||
token: challengeToken,
|
type: challengeType,
|
||||||
status: challengeStatus
|
status: challengeStatus
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -49,12 +49,13 @@ import {
|
|||||||
TRawJwsPayload,
|
TRawJwsPayload,
|
||||||
TRespondToAcmeChallengeResponse
|
TRespondToAcmeChallengeResponse
|
||||||
} from "./pki-acme-types";
|
} from "./pki-acme-types";
|
||||||
|
import { TPkiAcmeChallenges } from "@app/db/schemas";
|
||||||
|
|
||||||
type TPkiAcmeServiceFactoryDep = {
|
type TPkiAcmeServiceFactoryDep = {
|
||||||
certificateProfileDAL: Pick<TCertificateProfileDALFactory, "findById">;
|
certificateProfileDAL: Pick<TCertificateProfileDALFactory, "findById">;
|
||||||
acmeAccountDAL: Pick<TPkiAcmeAccountDALFactory, "findByProjectIdAndAccountId" | "findByPublicKey" | "create">;
|
acmeAccountDAL: Pick<TPkiAcmeAccountDALFactory, "findByProjectIdAndAccountId" | "findByPublicKey" | "create">;
|
||||||
acmeOrderDAL: Pick<TPkiAcmeOrderDALFactory, "create" | "transaction" | "findByAccountAndOrderIdWithAuthorizations">;
|
acmeOrderDAL: Pick<TPkiAcmeOrderDALFactory, "create" | "transaction" | "findByAccountAndOrderIdWithAuthorizations">;
|
||||||
acmeAuthDAL: Pick<TPkiAcmeAuthDALFactory, "create" | "findById">;
|
acmeAuthDAL: Pick<TPkiAcmeAuthDALFactory, "create" | "findByAccountIdAndAuthIdWithChallenges">;
|
||||||
acmeOrderAuthDAL: Pick<TPkiAcmeOrderAuthDALFactory, "insertMany">;
|
acmeOrderAuthDAL: Pick<TPkiAcmeOrderAuthDALFactory, "insertMany">;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -514,8 +515,8 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
accountId: string;
|
accountId: string;
|
||||||
authzId: string;
|
authzId: string;
|
||||||
}): Promise<TAcmeResponse<TGetAcmeAuthorizationResponse>> => {
|
}): Promise<TAcmeResponse<TGetAcmeAuthorizationResponse>> => {
|
||||||
const auth = await acmeAuthDAL.findById(authzId);
|
const auth = await acmeAuthDAL.findByAccountIdAndAuthIdWithChallenges(accountId, authzId);
|
||||||
if (!auth || auth.accountId !== accountId) {
|
if (!auth) {
|
||||||
throw new NotFoundError({ message: "ACME authorization not found" });
|
throw new NotFoundError({ message: "ACME authorization not found" });
|
||||||
}
|
}
|
||||||
return {
|
return {
|
||||||
@@ -527,15 +528,16 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
type: auth.identifierType,
|
type: auth.identifierType,
|
||||||
value: auth.identifierValue
|
value: auth.identifierValue
|
||||||
},
|
},
|
||||||
challenges: [
|
challenges: auth.challenges.map((challenge: TPkiAcmeChallenges) => {
|
||||||
// TODO: fixme
|
return {
|
||||||
{
|
type: challenge.type,
|
||||||
type: "http-01",
|
url: buildUrl(
|
||||||
url: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/authorizations/${authzId}/challenges/http-01`),
|
`/api/v1/pki/acme/profiles/${profileId}/authorizations/${authzId}/challenges/${challenge.id}`
|
||||||
status: "pending",
|
),
|
||||||
|
status: challenge.status,
|
||||||
token: auth.token
|
token: auth.token
|
||||||
}
|
};
|
||||||
]
|
})
|
||||||
},
|
},
|
||||||
headers: {
|
headers: {
|
||||||
Location: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/authorizations/${authzId}`)
|
Location: buildUrl(`/api/v1/pki/acme/profiles/${profileId}/authorizations/${authzId}`)
|
||||||
|
|||||||
Reference in New Issue
Block a user