mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 09:26:47 +00:00
misc: addressed greptile comments 1
This commit is contained in:
@@ -65,7 +65,18 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
|||||||
name: z.string()
|
name: z.string()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.any()
|
200: z.object({
|
||||||
|
pki: z.object({
|
||||||
|
serverCertificate: z.string(),
|
||||||
|
serverPrivateKey: z.string(),
|
||||||
|
clientCertificateChain: z.string()
|
||||||
|
}),
|
||||||
|
ssh: z.object({
|
||||||
|
serverCertificate: z.string(),
|
||||||
|
serverPrivateKey: z.string(),
|
||||||
|
clientCAPublicKey: z.string()
|
||||||
|
})
|
||||||
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
export const INSTANCE_PROXY_PREFIX = "infisical-";
|
||||||
|
|
||||||
export const isInstanceProxy = (proxyName: string) => {
|
export const isInstanceProxy = (proxyName: string) => {
|
||||||
return proxyName.startsWith("infisical-");
|
return proxyName.startsWith(INSTANCE_PROXY_PREFIX);
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -405,7 +405,7 @@ export const proxyServiceFactory = ({
|
|||||||
format: "der",
|
format: "der",
|
||||||
type: "pkcs8"
|
type: "pkcs8"
|
||||||
});
|
});
|
||||||
const orgProxyClientCaPrivateKey = await crypto.nativeCrypto.subtle.importKey(
|
const orgProxyCaPrivateKey = await crypto.nativeCrypto.subtle.importKey(
|
||||||
"pkcs8",
|
"pkcs8",
|
||||||
orgProxyCaSkObj.export({ format: "der", type: "pkcs8" }),
|
orgProxyCaSkObj.export({ format: "der", type: "pkcs8" }),
|
||||||
alg,
|
alg,
|
||||||
@@ -425,7 +425,7 @@ export const proxyServiceFactory = ({
|
|||||||
issuer: orgProxyCaCert.subject,
|
issuer: orgProxyCaCert.subject,
|
||||||
notBefore: orgProxyClientCaIssuedAt,
|
notBefore: orgProxyClientCaIssuedAt,
|
||||||
notAfter: orgProxyClientCaExpiration,
|
notAfter: orgProxyClientCaExpiration,
|
||||||
signingKey: orgProxyClientCaPrivateKey,
|
signingKey: orgProxyCaPrivateKey,
|
||||||
publicKey: orgProxyClientCaKeys.publicKey,
|
publicKey: orgProxyClientCaKeys.publicKey,
|
||||||
signingAlgorithm: alg,
|
signingAlgorithm: alg,
|
||||||
extensions: [
|
extensions: [
|
||||||
@@ -460,7 +460,7 @@ export const proxyServiceFactory = ({
|
|||||||
issuer: orgProxyCaCert.subject,
|
issuer: orgProxyCaCert.subject,
|
||||||
notBefore: orgProxyServerCaIssuedAt,
|
notBefore: orgProxyServerCaIssuedAt,
|
||||||
notAfter: orgProxyServerCaExpiration,
|
notAfter: orgProxyServerCaExpiration,
|
||||||
signingKey: orgProxyClientCaPrivateKey,
|
signingKey: orgProxyCaPrivateKey,
|
||||||
publicKey: orgProxyServerCaKeys.publicKey,
|
publicKey: orgProxyServerCaKeys.publicKey,
|
||||||
signingAlgorithm: alg,
|
signingAlgorithm: alg,
|
||||||
extensions: [
|
extensions: [
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import tls from "node:tls";
|
|||||||
|
|
||||||
import https from "https";
|
import https from "https";
|
||||||
|
|
||||||
|
import { verifyHostInputValidity } from "@app/ee/services/dynamic-secret/dynamic-secret-fns";
|
||||||
import { splitPemChain } from "@app/services/certificate/certificate-fns";
|
import { splitPemChain } from "@app/services/certificate/certificate-fns";
|
||||||
|
|
||||||
import { BadRequestError } from "../errors";
|
import { BadRequestError } from "../errors";
|
||||||
@@ -27,12 +28,13 @@ const createProxyConnection = async ({
|
|||||||
clientPrivateKey: string;
|
clientPrivateKey: string;
|
||||||
serverCertificateChain: string;
|
serverCertificateChain: string;
|
||||||
}): Promise<net.Socket> => {
|
}): Promise<net.Socket> => {
|
||||||
const [host, portStr] = proxyIp.split(":");
|
const [targetHost] = await verifyHostInputValidity(proxyIp);
|
||||||
const port = parseInt(portStr, 10) || 443;
|
const [, portStr] = proxyIp.split(":");
|
||||||
|
const port = parseInt(portStr, 10) || 8443;
|
||||||
|
|
||||||
const serverCAs = splitPemChain(serverCertificateChain);
|
const serverCAs = splitPemChain(serverCertificateChain);
|
||||||
const tlsOptions: tls.ConnectionOptions = {
|
const tlsOptions: tls.ConnectionOptions = {
|
||||||
host,
|
host: targetHost,
|
||||||
port,
|
port,
|
||||||
cert: clientCertificate,
|
cert: clientCertificate,
|
||||||
key: clientPrivateKey,
|
key: clientPrivateKey,
|
||||||
|
|||||||
@@ -121,7 +121,8 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (req.url.includes("/api/v1/proxies/register-instance-proxy")) {
|
// Authentication is handled on a route-level
|
||||||
|
if (req.url === "/api/v1/proxies/register-instance-proxy") {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import https from "https";
|
|||||||
|
|
||||||
import { verifyHostInputValidity } from "@app/ee/services/dynamic-secret/dynamic-secret-fns";
|
import { verifyHostInputValidity } from "@app/ee/services/dynamic-secret/dynamic-secret-fns";
|
||||||
import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service";
|
import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service";
|
||||||
|
import { TGatewayV2ServiceFactory } from "@app/ee/services/gateway-v2/gateway-v2-service";
|
||||||
import { request } from "@app/lib/config/request";
|
import { request } from "@app/lib/config/request";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { removeTrailingSlash } from "@app/lib/fn";
|
import { removeTrailingSlash } from "@app/lib/fn";
|
||||||
@@ -144,7 +145,9 @@ export const getHCVaultAccessToken = async (
|
|||||||
|
|
||||||
export const validateHCVaultConnectionCredentials = async (
|
export const validateHCVaultConnectionCredentials = async (
|
||||||
connection: THCVaultConnection,
|
connection: THCVaultConnection,
|
||||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">
|
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/no-unused-vars
|
||||||
|
_gatewayV2Service: Pick<TGatewayV2ServiceFactory, "getPlatformConnectionDetailsByGatewayId">
|
||||||
) => {
|
) => {
|
||||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||||
|
|
||||||
|
|||||||
@@ -12,8 +12,10 @@ export const gatewaysQueryKeys = {
|
|||||||
queryOptions({
|
queryOptions({
|
||||||
queryKey: gatewaysQueryKeys.listKey(),
|
queryKey: gatewaysQueryKeys.listKey(),
|
||||||
queryFn: async () => {
|
queryFn: async () => {
|
||||||
const { data } = await apiRequest.get<{ gateways: TGateway[] }>("/api/v1/gateways");
|
const [{ data }, { data: dataV2 }] = await Promise.all([
|
||||||
const { data: dataV2 } = await apiRequest.get<TGatewayV2[]>("/api/v2/gateways");
|
apiRequest.get<{ gateways: TGateway[] }>("/api/v1/gateways"),
|
||||||
|
apiRequest.get<TGatewayV2[]>("/api/v2/gateways")
|
||||||
|
]);
|
||||||
|
|
||||||
return [
|
return [
|
||||||
...data.gateways.map((g) => ({
|
...data.gateways.map((g) => ({
|
||||||
|
|||||||
Reference in New Issue
Block a user