mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 09:28:06 +00:00
feat(api): added revoke access token endpoint
This commit is contained in:
@@ -89,6 +89,9 @@ export const UNIVERSAL_AUTH = {
|
|||||||
},
|
},
|
||||||
RENEW_ACCESS_TOKEN: {
|
RENEW_ACCESS_TOKEN: {
|
||||||
accessToken: "The access token to renew."
|
accessToken: "The access token to renew."
|
||||||
|
},
|
||||||
|
REVOKE_ACCESS_TOKEN: {
|
||||||
|
accessToken: "The access token to revoke."
|
||||||
}
|
}
|
||||||
} as const;
|
} as const;
|
||||||
|
|
||||||
|
|||||||
@@ -36,4 +36,29 @@ export const registerIdentityAccessTokenRouter = async (server: FastifyZodProvid
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
url: "/token/revoke",
|
||||||
|
method: "POST",
|
||||||
|
config: {
|
||||||
|
rateLimit: writeLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
description: "Revoke access token",
|
||||||
|
body: z.object({
|
||||||
|
accessToken: z.string().trim().describe(UNIVERSAL_AUTH.REVOKE_ACCESS_TOKEN.accessToken)
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
message: z.string()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
await server.services.identityAccessToken.revokeAccessToken(req.body.accessToken);
|
||||||
|
return {
|
||||||
|
message: "Successfully revoked access token"
|
||||||
|
};
|
||||||
|
}
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -106,6 +106,24 @@ export const identityAccessTokenServiceFactory = ({
|
|||||||
return { accessToken, identityAccessToken: updatedIdentityAccessToken };
|
return { accessToken, identityAccessToken: updatedIdentityAccessToken };
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const revokeAccessToken = async (accessToken: string) => {
|
||||||
|
const appCfg = getConfig();
|
||||||
|
|
||||||
|
const decodedToken = jwt.verify(accessToken, appCfg.AUTH_SECRET) as JwtPayload & {
|
||||||
|
identityAccessTokenId: string;
|
||||||
|
};
|
||||||
|
if (decodedToken.authTokenType !== AuthTokenType.IDENTITY_ACCESS_TOKEN) throw new UnauthorizedError();
|
||||||
|
|
||||||
|
const identityAccessToken = await identityAccessTokenDAL.findOne({
|
||||||
|
[`${TableName.IdentityAccessToken}.id` as "id"]: decodedToken.identityAccessTokenId,
|
||||||
|
isAccessTokenRevoked: false
|
||||||
|
});
|
||||||
|
if (!identityAccessToken) throw new UnauthorizedError();
|
||||||
|
|
||||||
|
const revokedToken = await identityAccessTokenDAL.deleteById(identityAccessToken.id);
|
||||||
|
return { revokedToken };
|
||||||
|
};
|
||||||
|
|
||||||
const fnValidateIdentityAccessToken = async (token: TIdentityAccessTokenJwtPayload, ipAddress?: string) => {
|
const fnValidateIdentityAccessToken = async (token: TIdentityAccessTokenJwtPayload, ipAddress?: string) => {
|
||||||
const identityAccessToken = await identityAccessTokenDAL.findOne({
|
const identityAccessToken = await identityAccessTokenDAL.findOne({
|
||||||
[`${TableName.IdentityAccessToken}.id` as "id"]: token.identityAccessTokenId,
|
[`${TableName.IdentityAccessToken}.id` as "id"]: token.identityAccessTokenId,
|
||||||
@@ -132,5 +150,5 @@ export const identityAccessTokenServiceFactory = ({
|
|||||||
return { ...identityAccessToken, orgId: identityOrgMembership.orgId };
|
return { ...identityAccessToken, orgId: identityOrgMembership.orgId };
|
||||||
};
|
};
|
||||||
|
|
||||||
return { renewAccessToken, fnValidateIdentityAccessToken };
|
return { renewAccessToken, revokeAccessToken, fnValidateIdentityAccessToken };
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user