mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 00:27:30 +00:00
Handle errors
This commit is contained in:
@@ -18,7 +18,8 @@ export const PkiAcmeOrdersSchema = z.object({
|
|||||||
updatedAt: z.date(),
|
updatedAt: z.date(),
|
||||||
csr: z.string().nullable().optional(),
|
csr: z.string().nullable().optional(),
|
||||||
certificate: z.string().nullable().optional(),
|
certificate: z.string().nullable().optional(),
|
||||||
certificateChain: z.string().nullable().optional()
|
certificateChain: z.string().nullable().optional(),
|
||||||
|
error: z.string().nullable().optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TPkiAcmeOrders = z.infer<typeof PkiAcmeOrdersSchema>;
|
export type TPkiAcmeOrders = z.infer<typeof PkiAcmeOrdersSchema>;
|
||||||
|
|||||||
@@ -528,3 +528,24 @@ export class AcmeOrderNotReadyError extends AcmeError {
|
|||||||
this.name = "AcmeOrderNotReadyError";
|
this.name = "AcmeOrderNotReadyError";
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export class AcmeBadCSRError extends AcmeError {
|
||||||
|
constructor({
|
||||||
|
detail = "The CSR is unacceptable",
|
||||||
|
error,
|
||||||
|
message
|
||||||
|
}: {
|
||||||
|
detail?: string;
|
||||||
|
error?: unknown;
|
||||||
|
message?: string;
|
||||||
|
} = {}) {
|
||||||
|
super({
|
||||||
|
type: AcmeErrorType.BadCsr,
|
||||||
|
detail,
|
||||||
|
status: 400,
|
||||||
|
error,
|
||||||
|
message
|
||||||
|
});
|
||||||
|
this.name = "AcmeBadCSRError";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ import { TPkiAcmeAccounts } from "@app/db/schemas/pki-acme-accounts";
|
|||||||
import { TPkiAcmeAuths } from "@app/db/schemas/pki-acme-auths";
|
import { TPkiAcmeAuths } from "@app/db/schemas/pki-acme-auths";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
import { NotFoundError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
import { TCertificateProfileDALFactory } from "@app/services/certificate-profile/certificate-profile-dal";
|
import { TCertificateProfileDALFactory } from "@app/services/certificate-profile/certificate-profile-dal";
|
||||||
|
|
||||||
@@ -25,6 +25,7 @@ import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
|||||||
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
|
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
|
||||||
import {
|
import {
|
||||||
AcmeAccountDoesNotExistError,
|
AcmeAccountDoesNotExistError,
|
||||||
|
AcmeBadCSRError,
|
||||||
AcmeBadPublicKeyError,
|
AcmeBadPublicKeyError,
|
||||||
AcmeError,
|
AcmeError,
|
||||||
AcmeMalformedError,
|
AcmeMalformedError,
|
||||||
@@ -520,32 +521,51 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
const { csr } = payload;
|
const { csr } = payload;
|
||||||
// TODO: validate the CSR and return badCSR error if it's invalid
|
// TODO: validate the CSR and return badCSR error if it's invalid
|
||||||
// TODO: this should be the same transaction?
|
// TODO: this should be the same transaction?
|
||||||
const { certificate, certificateChain, certificateId } = await certificateV3Service.signCertificateFromProfile({
|
try {
|
||||||
actor: ActorType.ACME_ACCOUNT,
|
const { certificate, certificateChain, certificateId } =
|
||||||
actorId: accountId,
|
await certificateV3Service.signCertificateFromProfile({
|
||||||
actorAuthMethod: null,
|
actor: ActorType.ACME_ACCOUNT,
|
||||||
actorOrgId,
|
actorId: accountId,
|
||||||
profileId,
|
actorAuthMethod: null,
|
||||||
csr,
|
actorOrgId,
|
||||||
notBefore: order.notBefore ? new Date(order.notBefore) : undefined,
|
profileId,
|
||||||
notAfter: order.notAfter ? new Date(order.notAfter) : undefined,
|
csr,
|
||||||
validity: {
|
notBefore: order.notBefore ? new Date(order.notBefore) : undefined,
|
||||||
// TODO: read config from the profile to get the expiration time instead
|
notAfter: order.notAfter ? new Date(order.notAfter) : undefined,
|
||||||
ttl: (24 * 60 * 60 * 1000).toString()
|
validity: {
|
||||||
},
|
// TODO: read config from the profile to get the expiration time instead
|
||||||
enrollmentType: EnrollmentType.ACME
|
ttl: (24 * 60 * 60 * 1000).toString()
|
||||||
});
|
},
|
||||||
// TODO: associate the certificate with the order
|
enrollmentType: EnrollmentType.ACME
|
||||||
await acmeOrderDAL.updateById(
|
});
|
||||||
orderId,
|
// TODO: associate the certificate with the order
|
||||||
{
|
await acmeOrderDAL.updateById(
|
||||||
status: AcmeOrderStatus.Valid,
|
orderId,
|
||||||
csr,
|
{
|
||||||
certificateChain,
|
status: AcmeOrderStatus.Valid,
|
||||||
certificate
|
csr,
|
||||||
},
|
certificateChain,
|
||||||
tx
|
certificate
|
||||||
);
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
} catch (error) {
|
||||||
|
await acmeOrderDAL.updateById(
|
||||||
|
orderId,
|
||||||
|
{
|
||||||
|
csr,
|
||||||
|
status: AcmeOrderStatus.Invalid,
|
||||||
|
error: error instanceof Error ? error.message : "Unknown error"
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
// TODO: log the error
|
||||||
|
// TODO: audit log the error
|
||||||
|
if (error instanceof BadRequestError) {
|
||||||
|
throw new AcmeBadCSRError({ detail: `Invalid CSR: ${error.message}` });
|
||||||
|
}
|
||||||
|
throw new AcmeServerInternalError({ detail: "Failed to sign certificate" });
|
||||||
|
}
|
||||||
return await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId, tx);
|
return await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId, tx);
|
||||||
});
|
});
|
||||||
} else if (order.status !== AcmeOrderStatus.Valid) {
|
} else if (order.status !== AcmeOrderStatus.Valid) {
|
||||||
|
|||||||
@@ -74,7 +74,7 @@ export const certificateProfileDALFactory = (db: TDbClient) => {
|
|||||||
.join(TableName.Project, `${TableName.PkiCertificateProfile}.projectId`, `${TableName.Project}.id`)
|
.join(TableName.Project, `${TableName.PkiCertificateProfile}.projectId`, `${TableName.Project}.id`)
|
||||||
.select(selectAllTableCols(TableName.PkiCertificateProfile))
|
.select(selectAllTableCols(TableName.PkiCertificateProfile))
|
||||||
.select(db.ref("orgId").withSchema(TableName.Project).as("ownerOrgId"))
|
.select(db.ref("orgId").withSchema(TableName.Project).as("ownerOrgId"))
|
||||||
.where({ id })
|
.where(`${TableName.PkiCertificateProfile}.id`, id)
|
||||||
.first()) as (TCertificateProfile & { ownerOrgId: string }) | undefined;
|
.first()) as (TCertificateProfile & { ownerOrgId: string }) | undefined;
|
||||||
return certificateProfile;
|
return certificateProfile;
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
Reference in New Issue
Block a user