mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 19:28:16 +00:00
rephrase comment and error message
This commit is contained in:
@@ -554,11 +554,16 @@ export const authLoginServiceFactory = ({
|
|||||||
return { isUserCompleted, providerAuthToken };
|
return { isUserCompleted, providerAuthToken };
|
||||||
};
|
};
|
||||||
|
|
||||||
// to login users with oauth2 token used for private key handoff
|
/**
|
||||||
// The provider token will be given back to client to send back infisical access token
|
* Handles OAuth2 token exchange for user login with private key handoff.
|
||||||
// why not directly sending access token?
|
*
|
||||||
// 1. To keep the logic change easier from SRP oauth to simple oauth
|
* The process involves exchanging a provider's authorization token for an Infisical access token.
|
||||||
// 2. I don't want to attach access token to url as it may get logged the provider token has very short life span
|
* The provider token is returned to the client, who then sends it back to obtain the Infisical access token.
|
||||||
|
*
|
||||||
|
* This approach is used instead of directly sending the access token for the following reasons:
|
||||||
|
* 1. To facilitate easier logic changes from SRP OAuth to simple OAuth.
|
||||||
|
* 2. To avoid attaching the access token to the URL, which could be logged. The provider token has a very short lifespan, reducing security risks.
|
||||||
|
*/
|
||||||
const oauth2TokenExchange = async ({ userAgent, ip, providerAuthToken, email }: TOauthTokenExchangeDTO) => {
|
const oauth2TokenExchange = async ({ userAgent, ip, providerAuthToken, email }: TOauthTokenExchangeDTO) => {
|
||||||
const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email);
|
const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email);
|
||||||
|
|
||||||
@@ -575,7 +580,7 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
if (!userEnc) throw new BadRequestError({ message: "Invalid token" });
|
if (!userEnc) throw new BadRequestError({ message: "Invalid token" });
|
||||||
if (!userEnc.serverEncryptedPrivateKey)
|
if (!userEnc.serverEncryptedPrivateKey)
|
||||||
throw new BadRequestError({ message: "Private key handoff needs to be done" });
|
throw new BadRequestError({ message: "Key handoff incomplete. Please try logging in again." });
|
||||||
// send multi factor auth token if they it enabled
|
// send multi factor auth token if they it enabled
|
||||||
if (userEnc.isMfaEnabled && userEnc.email) {
|
if (userEnc.isMfaEnabled && userEnc.email) {
|
||||||
enforceUserLockStatus(Boolean(userEnc.isLocked), userEnc.temporaryLockDateEnd);
|
enforceUserLockStatus(Boolean(userEnc.isLocked), userEnc.temporaryLockDateEnd);
|
||||||
|
|||||||
Reference in New Issue
Block a user