Return directory url

This commit is contained in:
Fang-Pen Lin
2025-11-07 09:20:22 -08:00
parent c928b6abf7
commit e931d1936f
2 changed files with 15 additions and 4 deletions
@@ -31,6 +31,7 @@ import {
TCertificateProfileWithConfigs TCertificateProfileWithConfigs
} from "./certificate-profile-types"; } from "./certificate-profile-types";
import { TAcmeEnrollmentConfigDALFactory } from "../enrollment-config/acme-enrollment-config-dal"; import { TAcmeEnrollmentConfigDALFactory } from "../enrollment-config/acme-enrollment-config-dal";
import { buildUrl } from "@app/ee/services/pki-acme/pki-acme-fns";
const generateAndEncryptAcmeEabSecret = async ( const generateAndEncryptAcmeEabSecret = async (
projectId: string, projectId: string,
@@ -484,6 +485,12 @@ export const certificateProfileServiceFactory = ({
profile.estConfig.caChain = ""; profile.estConfig.caChain = "";
} }
} }
if (profile.enrollmentType === EnrollmentType.ACME && profile.acmeConfig) {
profile.acmeConfig.directoryUrl = buildUrl(profile.id, "/directory");
if (profile.acmeConfig.encryptedEabSecret) {
profile.acmeConfig.encryptedEabSecret = undefined;
}
}
return { return {
...profile, ...profile,
@@ -619,7 +626,11 @@ export const certificateProfileServiceFactory = ({
const result: TCertificateProfileWithConfigs = { const result: TCertificateProfileWithConfigs = {
...converted, ...converted,
estConfig: decryptedEstConfig, estConfig: decryptedEstConfig,
apiConfig: profileWithConfigs.apiConfig apiConfig: profileWithConfigs.apiConfig,
acmeConfig:
profile.enrollmentType === EnrollmentType.ACME
? { id: profile.id, directoryUrl: buildUrl(profile.id, "/directory") }
: undefined
}; };
return result; return result;
@@ -831,7 +842,7 @@ export const certificateProfileServiceFactory = ({
const kmsDecryptor = await kmsService.decryptWithKmsKey({ const kmsDecryptor = await kmsService.decryptWithKmsKey({
kmsId: certificateManagerKmsId kmsId: certificateManagerKmsId
}); });
const eabSecret = await kmsDecryptor({ cipherTextBlob: profile.acmeConfig.encryptedEabSecret }); const eabSecret = await kmsDecryptor({ cipherTextBlob: profile.acmeConfig.encryptedEabSecret! });
return { eabKid: profile.id, eabSecret: eabSecret.toString("base64url") }; return { eabKid: profile.id, eabSecret: eabSecret.toString("base64url") };
}; };
@@ -58,9 +58,9 @@ export type TCertificateProfileWithConfigs = TCertificateProfile & {
}; };
acmeConfig?: { acmeConfig?: {
id: string; id: string;
encryptedEabSecret: Buffer; directoryUrl: string;
encryptedEabSecret?: Buffer;
}; };
metrics?: TCertificateProfileMetrics;
}; };
export interface TCertificateProfileCertificate { export interface TCertificateProfileCertificate {