mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 05:26:11 +00:00
Merge pull request #5036 from Infisical/fix/external-kms-credentials-hash-calc
fix: credentials hash calculation in external kms
This commit is contained in:
@@ -11,6 +11,7 @@ import {
|
|||||||
} from "@app/ee/services/external-kms/providers/model";
|
} from "@app/ee/services/external-kms/providers/model";
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
import { deterministicStringify } from "@app/lib/fn/object";
|
||||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
@@ -88,9 +89,11 @@ export const registerExternalKmsEndpoints = <
|
|||||||
...rest
|
...rest
|
||||||
} = externalKms;
|
} = externalKms;
|
||||||
|
|
||||||
|
const credentialsToHash = deterministicStringify(configuration.credential);
|
||||||
|
|
||||||
const credentialsHash = crypto.nativeCrypto
|
const credentialsHash = crypto.nativeCrypto
|
||||||
.createHash("sha256")
|
.createHash("sha256")
|
||||||
.update(externalKmsData.encryptedProviderInputs)
|
.update(Buffer.from(credentialsToHash))
|
||||||
.digest("hex");
|
.digest("hex");
|
||||||
return { ...rest, externalKms: { ...externalKmsData, configuration, credentialsHash } };
|
return { ...rest, externalKms: { ...externalKmsData, configuration, credentialsHash } };
|
||||||
}
|
}
|
||||||
@@ -153,9 +156,12 @@ export const registerExternalKmsEndpoints = <
|
|||||||
external: { providerInput: externalKmsConfiguration, ...externalKmsData },
|
external: { providerInput: externalKmsConfiguration, ...externalKmsData },
|
||||||
...rest
|
...rest
|
||||||
} = externalKms;
|
} = externalKms;
|
||||||
|
|
||||||
|
const credentialsToHash = deterministicStringify(externalKmsConfiguration.credential);
|
||||||
|
|
||||||
const credentialsHash = crypto.nativeCrypto
|
const credentialsHash = crypto.nativeCrypto
|
||||||
.createHash("sha256")
|
.createHash("sha256")
|
||||||
.update(externalKmsData.encryptedProviderInputs)
|
.update(Buffer.from(credentialsToHash))
|
||||||
.digest("hex");
|
.digest("hex");
|
||||||
return { ...rest, externalKms: { ...externalKmsData, configuration: externalKmsConfiguration, credentialsHash } };
|
return { ...rest, externalKms: { ...externalKmsData, configuration: externalKmsConfiguration, credentialsHash } };
|
||||||
}
|
}
|
||||||
@@ -222,9 +228,12 @@ export const registerExternalKmsEndpoints = <
|
|||||||
external: { providerInput: externalKmsConfiguration, ...externalKmsData },
|
external: { providerInput: externalKmsConfiguration, ...externalKmsData },
|
||||||
...rest
|
...rest
|
||||||
} = externalKms;
|
} = externalKms;
|
||||||
|
|
||||||
|
const credentialsToHash = deterministicStringify(externalKmsConfiguration.credential);
|
||||||
|
|
||||||
const credentialsHash = crypto.nativeCrypto
|
const credentialsHash = crypto.nativeCrypto
|
||||||
.createHash("sha256")
|
.createHash("sha256")
|
||||||
.update(externalKmsData.encryptedProviderInputs)
|
.update(Buffer.from(credentialsToHash))
|
||||||
.digest("hex");
|
.digest("hex");
|
||||||
return { ...rest, externalKms: { ...externalKmsData, configuration: externalKmsConfiguration, credentialsHash } };
|
return { ...rest, externalKms: { ...externalKmsData, configuration: externalKmsConfiguration, credentialsHash } };
|
||||||
}
|
}
|
||||||
@@ -277,9 +286,12 @@ export const registerExternalKmsEndpoints = <
|
|||||||
external: { providerInput: configuration, ...externalKmsData },
|
external: { providerInput: configuration, ...externalKmsData },
|
||||||
...rest
|
...rest
|
||||||
} = externalKms;
|
} = externalKms;
|
||||||
|
|
||||||
|
const credentialsToHash = deterministicStringify(configuration.credential);
|
||||||
|
|
||||||
const credentialsHash = crypto.nativeCrypto
|
const credentialsHash = crypto.nativeCrypto
|
||||||
.createHash("sha256")
|
.createHash("sha256")
|
||||||
.update(externalKmsData.encryptedProviderInputs)
|
.update(Buffer.from(credentialsToHash))
|
||||||
.digest("hex");
|
.digest("hex");
|
||||||
|
|
||||||
return { ...rest, externalKms: { ...externalKmsData, configuration, credentialsHash } };
|
return { ...rest, externalKms: { ...externalKmsData, configuration, credentialsHash } };
|
||||||
|
|||||||
@@ -380,6 +380,7 @@ export const externalKmsServiceFactory = ({
|
|||||||
|
|
||||||
const findById = async ({ actor, actorId, actorOrgId, actorAuthMethod, id: kmsId }: TGetExternalKmsByIdDTO) => {
|
const findById = async ({ actor, actorId, actorOrgId, actorAuthMethod, id: kmsId }: TGetExternalKmsByIdDTO) => {
|
||||||
const kmsDoc = await kmsDAL.findById(kmsId);
|
const kmsDoc = await kmsDAL.findById(kmsId);
|
||||||
|
if (!kmsDoc) throw new NotFoundError({ message: `Could not find KMS with ID '${kmsId}'` });
|
||||||
const { permission } = await permissionService.getOrgPermission({
|
const { permission } = await permissionService.getOrgPermission({
|
||||||
scope: OrganizationActionScope.Any,
|
scope: OrganizationActionScope.Any,
|
||||||
actor,
|
actor,
|
||||||
|
|||||||
@@ -103,3 +103,34 @@ export const deepEqualSkipFields = (obj1: unknown, obj2: unknown, skipFields: st
|
|||||||
|
|
||||||
return deepEqual(filtered1, filtered2);
|
return deepEqual(filtered1, filtered2);
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export const deterministicStringify = (value: unknown): string => {
|
||||||
|
if (value === null || value === undefined) {
|
||||||
|
return JSON.stringify(value);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (typeof value === "string" || typeof value === "number" || typeof value === "boolean") {
|
||||||
|
return JSON.stringify(value);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Array.isArray(value)) {
|
||||||
|
const items = value.map((item) => deterministicStringify(item));
|
||||||
|
return `[${items.join(",")}]`;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (typeof value === "object") {
|
||||||
|
const sortedKeys = Object.keys(value).sort();
|
||||||
|
const sortedObj: Record<string, unknown> = {};
|
||||||
|
for (const key of sortedKeys) {
|
||||||
|
const val = (value as Record<string, unknown>)[key];
|
||||||
|
if (typeof val === "object" && val !== null) {
|
||||||
|
sortedObj[key] = JSON.parse(deterministicStringify(val));
|
||||||
|
} else {
|
||||||
|
sortedObj[key] = val;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return JSON.stringify(sortedObj);
|
||||||
|
}
|
||||||
|
|
||||||
|
return JSON.stringify(value);
|
||||||
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user