misc: addressed greptile comments 1

This commit is contained in:
Sheen Capadngan
2025-09-03 21:18:34 +08:00
parent e30cb9d767
commit ec39f84719
7 changed files with 33 additions and 12 deletions
+12 -1
View File
@@ -65,7 +65,18 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
name: z.string() name: z.string()
}), }),
response: { response: {
200: z.any() 200: z.object({
pki: z.object({
serverCertificate: z.string(),
serverPrivateKey: z.string(),
clientCertificateChain: z.string()
}),
ssh: z.object({
serverCertificate: z.string(),
serverPrivateKey: z.string(),
clientCAPublicKey: z.string()
})
})
} }
}, },
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
+3 -1
View File
@@ -1,3 +1,5 @@
export const INSTANCE_PROXY_PREFIX = "infisical-";
export const isInstanceProxy = (proxyName: string) => { export const isInstanceProxy = (proxyName: string) => {
return proxyName.startsWith("infisical-"); return proxyName.startsWith(INSTANCE_PROXY_PREFIX);
}; };
@@ -405,7 +405,7 @@ export const proxyServiceFactory = ({
format: "der", format: "der",
type: "pkcs8" type: "pkcs8"
}); });
const orgProxyClientCaPrivateKey = await crypto.nativeCrypto.subtle.importKey( const orgProxyCaPrivateKey = await crypto.nativeCrypto.subtle.importKey(
"pkcs8", "pkcs8",
orgProxyCaSkObj.export({ format: "der", type: "pkcs8" }), orgProxyCaSkObj.export({ format: "der", type: "pkcs8" }),
alg, alg,
@@ -425,7 +425,7 @@ export const proxyServiceFactory = ({
issuer: orgProxyCaCert.subject, issuer: orgProxyCaCert.subject,
notBefore: orgProxyClientCaIssuedAt, notBefore: orgProxyClientCaIssuedAt,
notAfter: orgProxyClientCaExpiration, notAfter: orgProxyClientCaExpiration,
signingKey: orgProxyClientCaPrivateKey, signingKey: orgProxyCaPrivateKey,
publicKey: orgProxyClientCaKeys.publicKey, publicKey: orgProxyClientCaKeys.publicKey,
signingAlgorithm: alg, signingAlgorithm: alg,
extensions: [ extensions: [
@@ -460,7 +460,7 @@ export const proxyServiceFactory = ({
issuer: orgProxyCaCert.subject, issuer: orgProxyCaCert.subject,
notBefore: orgProxyServerCaIssuedAt, notBefore: orgProxyServerCaIssuedAt,
notAfter: orgProxyServerCaExpiration, notAfter: orgProxyServerCaExpiration,
signingKey: orgProxyClientCaPrivateKey, signingKey: orgProxyCaPrivateKey,
publicKey: orgProxyServerCaKeys.publicKey, publicKey: orgProxyServerCaKeys.publicKey,
signingAlgorithm: alg, signingAlgorithm: alg,
extensions: [ extensions: [
+5 -3
View File
@@ -3,6 +3,7 @@ import tls from "node:tls";
import https from "https"; import https from "https";
import { verifyHostInputValidity } from "@app/ee/services/dynamic-secret/dynamic-secret-fns";
import { splitPemChain } from "@app/services/certificate/certificate-fns"; import { splitPemChain } from "@app/services/certificate/certificate-fns";
import { BadRequestError } from "../errors"; import { BadRequestError } from "../errors";
@@ -27,12 +28,13 @@ const createProxyConnection = async ({
clientPrivateKey: string; clientPrivateKey: string;
serverCertificateChain: string; serverCertificateChain: string;
}): Promise<net.Socket> => { }): Promise<net.Socket> => {
const [host, portStr] = proxyIp.split(":"); const [targetHost] = await verifyHostInputValidity(proxyIp);
const port = parseInt(portStr, 10) || 443; const [, portStr] = proxyIp.split(":");
const port = parseInt(portStr, 10) || 8443;
const serverCAs = splitPemChain(serverCertificateChain); const serverCAs = splitPemChain(serverCertificateChain);
const tlsOptions: tls.ConnectionOptions = { const tlsOptions: tls.ConnectionOptions = {
host, host: targetHost,
port, port,
cert: clientCertificate, cert: clientCertificate,
key: clientPrivateKey, key: clientPrivateKey,
@@ -121,7 +121,8 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
return; return;
} }
if (req.url.includes("/api/v1/proxies/register-instance-proxy")) { // Authentication is handled on a route-level
if (req.url === "/api/v1/proxies/register-instance-proxy") {
return; return;
} }
@@ -3,6 +3,7 @@ import https from "https";
import { verifyHostInputValidity } from "@app/ee/services/dynamic-secret/dynamic-secret-fns"; import { verifyHostInputValidity } from "@app/ee/services/dynamic-secret/dynamic-secret-fns";
import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service"; import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service";
import { TGatewayV2ServiceFactory } from "@app/ee/services/gateway-v2/gateway-v2-service";
import { request } from "@app/lib/config/request"; import { request } from "@app/lib/config/request";
import { BadRequestError } from "@app/lib/errors"; import { BadRequestError } from "@app/lib/errors";
import { removeTrailingSlash } from "@app/lib/fn"; import { removeTrailingSlash } from "@app/lib/fn";
@@ -144,7 +145,9 @@ export const getHCVaultAccessToken = async (
export const validateHCVaultConnectionCredentials = async ( export const validateHCVaultConnectionCredentials = async (
connection: THCVaultConnection, connection: THCVaultConnection,
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId"> gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">,
// eslint-disable-next-line @typescript-eslint/no-unused-vars
_gatewayV2Service: Pick<TGatewayV2ServiceFactory, "getPlatformConnectionDetailsByGatewayId">
) => { ) => {
const instanceUrl = await getHCVaultInstanceUrl(connection); const instanceUrl = await getHCVaultInstanceUrl(connection);
+4 -2
View File
@@ -12,8 +12,10 @@ export const gatewaysQueryKeys = {
queryOptions({ queryOptions({
queryKey: gatewaysQueryKeys.listKey(), queryKey: gatewaysQueryKeys.listKey(),
queryFn: async () => { queryFn: async () => {
const { data } = await apiRequest.get<{ gateways: TGateway[] }>("/api/v1/gateways"); const [{ data }, { data: dataV2 }] = await Promise.all([
const { data: dataV2 } = await apiRequest.get<TGatewayV2[]>("/api/v2/gateways"); apiRequest.get<{ gateways: TGateway[] }>("/api/v1/gateways"),
apiRequest.get<TGatewayV2[]>("/api/v2/gateways")
]);
return [ return [
...data.gateways.map((g) => ({ ...data.gateways.map((g) => ({