diff --git a/backend/src/server/routes/v1/secret-sharing-router.ts b/backend/src/server/routes/v1/secret-sharing-router.ts index 95fe4e54b..7a5361049 100644 --- a/backend/src/server/routes/v1/secret-sharing-router.ts +++ b/backend/src/server/routes/v1/secret-sharing-router.ts @@ -1,4 +1,5 @@ import { z } from "zod"; +import bcrypt from "bcrypt" import { SecretSharingSchema } from "@app/db/schemas"; import { SecretSharingAccessType } from "@app/lib/types"; @@ -94,6 +95,49 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) => } }); + server.route({ + method: "POST", + url: "/public/:id/validate", + config: { + rateLimit: publicEndpointLimit + }, + schema: { + params: z.object({ + id: z.string().uuid() + }), + body: z.object({ + password: z.string().min(1), + hashedHex: z.string() + }), + response: { + 200: z.object({ + isValid: z.boolean() + }) + } + }, + handler: async (req) => { + const { id } = req.params; + const { password, hashedHex } = req.body; + + const sharedSecret = await req.server.services.secretSharing.getActiveSharedSecretById({ + sharedSecretId: id, + hashedHex, + orgId: req.permission?.orgId + }); + + if (!sharedSecret) { + return { isValid: false }; + } + + if (sharedSecret.password) { + const isMatch = await bcrypt.compare(password, sharedSecret.password); + return { isValid: isMatch }; + } + + return { isValid: false }; + } + }); + server.route({ method: "POST", url: "/public", diff --git a/backend/src/services/secret-sharing/secret-sharing-service.ts b/backend/src/services/secret-sharing/secret-sharing-service.ts index 71ce43de4..73a1bb6e8 100644 --- a/backend/src/services/secret-sharing/secret-sharing-service.ts +++ b/backend/src/services/secret-sharing/secret-sharing-service.ts @@ -1,3 +1,5 @@ +import bcrypt from "bcrypt"; + import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service"; import { BadRequestError, ForbiddenRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors"; import { SecretSharingAccessType } from "@app/lib/types"; @@ -61,9 +63,10 @@ export const secretSharingServiceFactory = ({ throw new BadRequestError({ message: "Shared secret value too long" }); } + const hashedPassword = password ? await bcrypt.hash(password, 10) : null; const newSharedSecret = await secretSharingDAL.create({ name, - password, + password: hashedPassword, encryptedValue, hashedHex, iv,