mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat: hashpassword and add validation endpoint
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
import { z } from "zod";
|
||||
import bcrypt from "bcrypt"
|
||||
|
||||
import { SecretSharingSchema } from "@app/db/schemas";
|
||||
import { SecretSharingAccessType } from "@app/lib/types";
|
||||
@@ -94,6 +95,49 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "POST",
|
||||
url: "/public/:id/validate",
|
||||
config: {
|
||||
rateLimit: publicEndpointLimit
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
id: z.string().uuid()
|
||||
}),
|
||||
body: z.object({
|
||||
password: z.string().min(1),
|
||||
hashedHex: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
isValid: z.boolean()
|
||||
})
|
||||
}
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { id } = req.params;
|
||||
const { password, hashedHex } = req.body;
|
||||
|
||||
const sharedSecret = await req.server.services.secretSharing.getActiveSharedSecretById({
|
||||
sharedSecretId: id,
|
||||
hashedHex,
|
||||
orgId: req.permission?.orgId
|
||||
});
|
||||
|
||||
if (!sharedSecret) {
|
||||
return { isValid: false };
|
||||
}
|
||||
|
||||
if (sharedSecret.password) {
|
||||
const isMatch = await bcrypt.compare(password, sharedSecret.password);
|
||||
return { isValid: isMatch };
|
||||
}
|
||||
|
||||
return { isValid: false };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "POST",
|
||||
url: "/public",
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
import bcrypt from "bcrypt";
|
||||
|
||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||
import { BadRequestError, ForbiddenRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
|
||||
import { SecretSharingAccessType } from "@app/lib/types";
|
||||
@@ -61,9 +63,10 @@ export const secretSharingServiceFactory = ({
|
||||
throw new BadRequestError({ message: "Shared secret value too long" });
|
||||
}
|
||||
|
||||
const hashedPassword = password ? await bcrypt.hash(password, 10) : null;
|
||||
const newSharedSecret = await secretSharingDAL.create({
|
||||
name,
|
||||
password,
|
||||
password: hashedPassword,
|
||||
encryptedValue,
|
||||
hashedHex,
|
||||
iv,
|
||||
|
||||
Reference in New Issue
Block a user