mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 01:26:20 +00:00
Merge pull request #3830 from Infisical/revert-cli-refresh
Revert CLI refresh PR
This commit is contained in:
@@ -101,9 +101,9 @@ const envSchema = z
|
|||||||
LOOPS_API_KEY: zpStr(z.string().optional()),
|
LOOPS_API_KEY: zpStr(z.string().optional()),
|
||||||
// jwt options
|
// jwt options
|
||||||
AUTH_SECRET: zpStr(z.string()).default(process.env.JWT_AUTH_SECRET), // for those still using old JWT_AUTH_SECRET
|
AUTH_SECRET: zpStr(z.string()).default(process.env.JWT_AUTH_SECRET), // for those still using old JWT_AUTH_SECRET
|
||||||
JWT_AUTH_LIFETIME: zpStr(z.string().default("1d")),
|
JWT_AUTH_LIFETIME: zpStr(z.string().default("10d")),
|
||||||
JWT_SIGNUP_LIFETIME: zpStr(z.string().default("15m")),
|
JWT_SIGNUP_LIFETIME: zpStr(z.string().default("15m")),
|
||||||
JWT_REFRESH_LIFETIME: zpStr(z.string().default("14d")),
|
JWT_REFRESH_LIFETIME: zpStr(z.string().default("90d")),
|
||||||
JWT_INVITE_LIFETIME: zpStr(z.string().default("1d")),
|
JWT_INVITE_LIFETIME: zpStr(z.string().default("1d")),
|
||||||
JWT_MFA_LIFETIME: zpStr(z.string().default("5m")),
|
JWT_MFA_LIFETIME: zpStr(z.string().default("5m")),
|
||||||
JWT_PROVIDER_AUTH_LIFETIME: zpStr(z.string().default("15m")),
|
JWT_PROVIDER_AUTH_LIFETIME: zpStr(z.string().default("15m")),
|
||||||
|
|||||||
@@ -107,7 +107,7 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
|
|||||||
server.addHook("onRequest", async (req) => {
|
server.addHook("onRequest", async (req) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
|
|
||||||
if (req.url.includes(".well-known/est") || req.url.includes("/api/v3/auth/") || req.url === "/api/v1/auth/token") {
|
if (req.url.includes(".well-known/est") || req.url.includes("/api/v3/auth/")) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -50,8 +50,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
200: z.object({
|
200: z.object({
|
||||||
token: z.string(),
|
token: z.string(),
|
||||||
isMfaEnabled: z.boolean(),
|
isMfaEnabled: z.boolean(),
|
||||||
mfaMethod: z.string().optional(),
|
mfaMethod: z.string().optional()
|
||||||
RefreshToken: z.string().optional()
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -102,7 +101,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
maxAge: 0
|
maxAge: 0
|
||||||
});
|
});
|
||||||
|
|
||||||
return { token: tokens.access, isMfaEnabled: false, RefreshToken: tokens.refresh };
|
return { token: tokens.access, isMfaEnabled: false };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -130,8 +129,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
encryptedPrivateKey: z.string(),
|
encryptedPrivateKey: z.string(),
|
||||||
iv: z.string(),
|
iv: z.string(),
|
||||||
tag: z.string(),
|
tag: z.string(),
|
||||||
token: z.string(),
|
token: z.string()
|
||||||
RefreshToken: z.string().optional()
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -174,8 +172,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
tag: data.user.tag,
|
tag: data.user.tag,
|
||||||
protectedKey: data.user.protectedKey || null,
|
protectedKey: data.user.protectedKey || null,
|
||||||
protectedKeyIV: data.user.protectedKeyIV || null,
|
protectedKeyIV: data.user.protectedKeyIV || null,
|
||||||
protectedKeyTag: data.user.protectedKeyTag || null,
|
protectedKeyTag: data.user.protectedKeyTag || null
|
||||||
RefreshToken: data.token.refresh
|
|
||||||
} as const;
|
} as const;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ type LoginTwoRequest struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type LoginTwoResponse struct {
|
type LoginTwoResponse struct {
|
||||||
JWTToken string `json:"token"`
|
JTWToken string `json:"token"`
|
||||||
RefreshToken string `json:"refreshToken"`
|
RefreshToken string `json:"refreshToken"`
|
||||||
PublicKey string `json:"publicKey"`
|
PublicKey string `json:"publicKey"`
|
||||||
EncryptedPrivateKey string `json:"encryptedPrivateKey"`
|
EncryptedPrivateKey string `json:"encryptedPrivateKey"`
|
||||||
|
|||||||
@@ -87,7 +87,7 @@ func getDynamicSecretList(cmd *cobra.Command, args []string) {
|
|||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
|
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(infisicalToken)
|
httpClient.SetAuthToken(infisicalToken)
|
||||||
@@ -211,7 +211,7 @@ func createDynamicSecretLeaseByName(cmd *cobra.Command, args []string) {
|
|||||||
if loggedInUserDetails.LoginExpired {
|
if loggedInUserDetails.LoginExpired {
|
||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(infisicalToken)
|
httpClient.SetAuthToken(infisicalToken)
|
||||||
@@ -363,7 +363,7 @@ func renewDynamicSecretLeaseByName(cmd *cobra.Command, args []string) {
|
|||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
|
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(infisicalToken)
|
httpClient.SetAuthToken(infisicalToken)
|
||||||
@@ -478,7 +478,7 @@ func revokeDynamicSecretLeaseByName(cmd *cobra.Command, args []string) {
|
|||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
|
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(infisicalToken)
|
httpClient.SetAuthToken(infisicalToken)
|
||||||
@@ -592,7 +592,7 @@ func listDynamicSecretLeaseByName(cmd *cobra.Command, args []string) {
|
|||||||
if loggedInUserDetails.LoginExpired {
|
if loggedInUserDetails.LoginExpired {
|
||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(infisicalToken)
|
httpClient.SetAuthToken(infisicalToken)
|
||||||
|
|||||||
@@ -115,7 +115,7 @@ var exportCmd = &cobra.Command{
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err)
|
util.HandleError(err)
|
||||||
}
|
}
|
||||||
accessToken = loggedInUserDetails.UserCredentials.JWTToken
|
accessToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
processedTemplate, err := ProcessTemplate(1, templatePath, nil, accessToken, "", &newEtag, dynamicSecretLeases)
|
processedTemplate, err := ProcessTemplate(1, templatePath, nil, accessToken, "", &newEtag, dynamicSecretLeases)
|
||||||
|
|||||||
@@ -53,7 +53,7 @@ var initCmd = &cobra.Command{
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to get resty client with custom headers")
|
util.HandleError(err, "Unable to get resty client with custom headers")
|
||||||
}
|
}
|
||||||
httpClient.SetAuthToken(userCreds.UserCredentials.JWTToken)
|
httpClient.SetAuthToken(userCreds.UserCredentials.JTWToken)
|
||||||
|
|
||||||
organizationResponse, err := api.CallGetAllOrganizations(httpClient)
|
organizationResponse, err := api.CallGetAllOrganizations(httpClient)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -124,7 +124,7 @@ var initCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
|
|
||||||
// set the config jwt token to the new token
|
// set the config jwt token to the new token
|
||||||
userCreds.UserCredentials.JWTToken = tokenResponse.Token
|
userCreds.UserCredentials.JTWToken = tokenResponse.Token
|
||||||
err = util.StoreUserCredsInKeyRing(&userCreds.UserCredentials)
|
err = util.StoreUserCredsInKeyRing(&userCreds.UserCredentials)
|
||||||
httpClient.SetAuthToken(tokenResponse.Token)
|
httpClient.SetAuthToken(tokenResponse.Token)
|
||||||
|
|
||||||
|
|||||||
@@ -111,7 +111,7 @@ var loginCmd = &cobra.Command{
|
|||||||
infisicalClient := infisicalSdk.NewInfisicalClient(context.Background(), infisicalSdk.Config{
|
infisicalClient := infisicalSdk.NewInfisicalClient(context.Background(), infisicalSdk.Config{
|
||||||
SiteUrl: config.INFISICAL_URL,
|
SiteUrl: config.INFISICAL_URL,
|
||||||
UserAgent: api.USER_AGENT,
|
UserAgent: api.USER_AGENT,
|
||||||
AutoTokenRefresh: true,
|
AutoTokenRefresh: false,
|
||||||
CustomHeaders: customHeaders,
|
CustomHeaders: customHeaders,
|
||||||
})
|
})
|
||||||
|
|
||||||
@@ -437,8 +437,7 @@ func cliDefaultLogin(userCredentialsToBeStored *models.UserCredentials) {
|
|||||||
//updating usercredentials
|
//updating usercredentials
|
||||||
userCredentialsToBeStored.Email = email
|
userCredentialsToBeStored.Email = email
|
||||||
userCredentialsToBeStored.PrivateKey = string(decryptedPrivateKey)
|
userCredentialsToBeStored.PrivateKey = string(decryptedPrivateKey)
|
||||||
userCredentialsToBeStored.JWTToken = newJwtToken
|
userCredentialsToBeStored.JTWToken = newJwtToken
|
||||||
userCredentialsToBeStored.RefreshToken = loginTwoResponse.RefreshToken
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
@@ -863,7 +862,7 @@ func askToPasteJwtToken(success chan models.UserCredentials, failure chan error)
|
|||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
|
|
||||||
// verify JWT
|
// verify JTW
|
||||||
httpClient, err := util.GetRestyClientWithCustomHeaders()
|
httpClient, err := util.GetRestyClientWithCustomHeaders()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
failure <- err
|
failure <- err
|
||||||
@@ -872,7 +871,7 @@ func askToPasteJwtToken(success chan models.UserCredentials, failure chan error)
|
|||||||
}
|
}
|
||||||
|
|
||||||
httpClient.
|
httpClient.
|
||||||
SetAuthToken(userCredentials.JWTToken).
|
SetAuthToken(userCredentials.JTWToken).
|
||||||
SetHeader("Accept", "application/json")
|
SetHeader("Accept", "application/json")
|
||||||
|
|
||||||
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
||||||
|
|||||||
@@ -245,7 +245,7 @@ var secretsSetCmd = &cobra.Command{
|
|||||||
|
|
||||||
secretOperations, err = util.SetRawSecrets(processedArgs, secretType, environmentName, secretsPath, projectId, &models.TokenDetails{
|
secretOperations, err = util.SetRawSecrets(processedArgs, secretType, environmentName, secretsPath, projectId, &models.TokenDetails{
|
||||||
Type: "",
|
Type: "",
|
||||||
Token: loggedInUserDetails.UserCredentials.JWTToken,
|
Token: loggedInUserDetails.UserCredentials.JTWToken,
|
||||||
}, file)
|
}, file)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -330,7 +330,7 @@ var secretsDeleteCmd = &cobra.Command{
|
|||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(loggedInUserDetails.UserCredentials.JWTToken)
|
httpClient.SetAuthToken(loggedInUserDetails.UserCredentials.JTWToken)
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, secretName := range args {
|
for _, secretName := range args {
|
||||||
|
|||||||
@@ -186,7 +186,7 @@ func issueCredentials(cmd *cobra.Command, args []string) {
|
|||||||
if loggedInUserDetails.LoginExpired {
|
if loggedInUserDetails.LoginExpired {
|
||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
certificateTemplateId, err := cmd.Flags().GetString("certificateTemplateId")
|
certificateTemplateId, err := cmd.Flags().GetString("certificateTemplateId")
|
||||||
@@ -419,7 +419,7 @@ func signKey(cmd *cobra.Command, args []string) {
|
|||||||
if loggedInUserDetails.LoginExpired {
|
if loggedInUserDetails.LoginExpired {
|
||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
certificateTemplateId, err := cmd.Flags().GetString("certificateTemplateId")
|
certificateTemplateId, err := cmd.Flags().GetString("certificateTemplateId")
|
||||||
@@ -628,7 +628,7 @@ func sshConnect(cmd *cobra.Command, args []string) {
|
|||||||
if loggedInUserDetails.LoginExpired {
|
if loggedInUserDetails.LoginExpired {
|
||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
writeHostCaToFile, err := cmd.Flags().GetBool("write-host-ca-to-file")
|
writeHostCaToFile, err := cmd.Flags().GetBool("write-host-ca-to-file")
|
||||||
@@ -881,7 +881,7 @@ func sshAddHost(cmd *cobra.Command, args []string) {
|
|||||||
if loggedInUserDetails.LoginExpired {
|
if loggedInUserDetails.LoginExpired {
|
||||||
loggedInUserDetails = util.EstablishUserLoginSession()
|
loggedInUserDetails = util.EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
infisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
infisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
projectId, err := cmd.Flags().GetString("projectId")
|
projectId, err := cmd.Flags().GetString("projectId")
|
||||||
|
|||||||
@@ -115,7 +115,7 @@ var tokensCreateCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
workspaceKey, err := util.GetPlainTextWorkspaceKey(loggedInUserDetails.UserCredentials.JWTToken, loggedInUserDetails.UserCredentials.PrivateKey, workspaceId)
|
workspaceKey, err := util.GetPlainTextWorkspaceKey(loggedInUserDetails.UserCredentials.JTWToken, loggedInUserDetails.UserCredentials.PrivateKey, workspaceId)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to get workspace key needed to create service token")
|
util.HandleError(err, "Unable to get workspace key needed to create service token")
|
||||||
}
|
}
|
||||||
@@ -140,7 +140,7 @@ var tokensCreateCmd = &cobra.Command{
|
|||||||
util.HandleError(err, "Unable to get resty client with custom headers")
|
util.HandleError(err, "Unable to get resty client with custom headers")
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(loggedInUserDetails.UserCredentials.JWTToken).
|
httpClient.SetAuthToken(loggedInUserDetails.UserCredentials.JTWToken).
|
||||||
SetHeader("Accept", "application/json")
|
SetHeader("Accept", "application/json")
|
||||||
|
|
||||||
createServiceTokenResponse, err := api.CallCreateServiceToken(httpClient, api.CreateServiceTokenRequest{
|
createServiceTokenResponse, err := api.CallCreateServiceToken(httpClient, api.CreateServiceTokenRequest{
|
||||||
|
|||||||
@@ -118,7 +118,7 @@ var userGetTokenCmd = &cobra.Command{
|
|||||||
util.HandleError(err, "[infisical user get token]: Unable to get logged in user token")
|
util.HandleError(err, "[infisical user get token]: Unable to get logged in user token")
|
||||||
}
|
}
|
||||||
|
|
||||||
tokenParts := strings.Split(loggedInUserDetails.UserCredentials.JWTToken, ".")
|
tokenParts := strings.Split(loggedInUserDetails.UserCredentials.JTWToken, ".")
|
||||||
if len(tokenParts) != 3 {
|
if len(tokenParts) != 3 {
|
||||||
util.HandleError(errors.New("invalid token format"), "[infisical user get token]: Invalid token format")
|
util.HandleError(errors.New("invalid token format"), "[infisical user get token]: Invalid token format")
|
||||||
}
|
}
|
||||||
@@ -136,7 +136,7 @@ var userGetTokenCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
|
|
||||||
fmt.Println("Session ID:", tokenPayload.TokenVersionId)
|
fmt.Println("Session ID:", tokenPayload.TokenVersionId)
|
||||||
fmt.Println("Token:", loggedInUserDetails.UserCredentials.JWTToken)
|
fmt.Println("Token:", loggedInUserDetails.UserCredentials.JTWToken)
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import "time"
|
|||||||
type UserCredentials struct {
|
type UserCredentials struct {
|
||||||
Email string `json:"email"`
|
Email string `json:"email"`
|
||||||
PrivateKey string `json:"privateKey"`
|
PrivateKey string `json:"privateKey"`
|
||||||
JWTToken string `json:"JTWToken"`
|
JTWToken string `json:"JTWToken"`
|
||||||
RefreshToken string `json:"RefreshToken"`
|
RefreshToken string `json:"RefreshToken"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -9,7 +9,6 @@ import (
|
|||||||
"github.com/Infisical/infisical-merge/packages/api"
|
"github.com/Infisical/infisical-merge/packages/api"
|
||||||
"github.com/Infisical/infisical-merge/packages/config"
|
"github.com/Infisical/infisical-merge/packages/config"
|
||||||
"github.com/Infisical/infisical-merge/packages/models"
|
"github.com/Infisical/infisical-merge/packages/models"
|
||||||
"github.com/rs/zerolog/log"
|
|
||||||
"github.com/zalando/go-keyring"
|
"github.com/zalando/go-keyring"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -91,22 +90,23 @@ func GetCurrentLoggedInUserDetails(setConfigVariables bool) (LoggedInUserDetails
|
|||||||
}
|
}
|
||||||
|
|
||||||
httpClient.
|
httpClient.
|
||||||
SetAuthToken(userCreds.JWTToken).
|
SetAuthToken(userCreds.JTWToken).
|
||||||
SetHeader("Accept", "application/json")
|
SetHeader("Accept", "application/json")
|
||||||
|
|
||||||
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
isAuthenticated := api.CallIsAuthenticated(httpClient)
|
||||||
if !isAuthenticated {
|
// TODO: add refresh token
|
||||||
accessTokenResponse, refreshErr := api.CallGetNewAccessTokenWithRefreshToken(httpClient, userCreds.RefreshToken)
|
// if !isAuthenticated {
|
||||||
if refreshErr == nil && accessTokenResponse.Token != "" {
|
// accessTokenResponse, err := api.CallGetNewAccessTokenWithRefreshToken(httpClient, userCreds.RefreshToken)
|
||||||
isAuthenticated = true
|
// if err == nil && accessTokenResponse.Token != "" {
|
||||||
userCreds.JWTToken = accessTokenResponse.Token
|
// isAuthenticated = true
|
||||||
}
|
// userCreds.JTWToken = accessTokenResponse.Token
|
||||||
}
|
// }
|
||||||
|
// }
|
||||||
|
|
||||||
err = StoreUserCredsInKeyRing(&userCreds)
|
// err = StoreUserCredsInKeyRing(&userCreds)
|
||||||
if err != nil {
|
// if err != nil {
|
||||||
log.Debug().Msg("unable to store your user credentials with new access token")
|
// log.Debug().Msg("unable to store your user credentials with new access token")
|
||||||
}
|
// }
|
||||||
|
|
||||||
if !isAuthenticated {
|
if !isAuthenticated {
|
||||||
return LoggedInUserDetails{
|
return LoggedInUserDetails{
|
||||||
|
|||||||
@@ -35,7 +35,7 @@ func GetAllFolders(params models.GetAllFoldersParameters) ([]models.SingleFolder
|
|||||||
params.WorkspaceId = workspaceFile.WorkspaceId
|
params.WorkspaceId = workspaceFile.WorkspaceId
|
||||||
}
|
}
|
||||||
|
|
||||||
folders, err := GetFoldersViaJWT(loggedInUserDetails.UserCredentials.JWTToken, params.WorkspaceId, params.Environment, params.FoldersPath)
|
folders, err := GetFoldersViaJTW(loggedInUserDetails.UserCredentials.JTWToken, params.WorkspaceId, params.Environment, params.FoldersPath)
|
||||||
folderErr = err
|
folderErr = err
|
||||||
foldersToReturn = folders
|
foldersToReturn = folders
|
||||||
} else if params.InfisicalToken != "" {
|
} else if params.InfisicalToken != "" {
|
||||||
@@ -60,14 +60,14 @@ func GetAllFolders(params models.GetAllFoldersParameters) ([]models.SingleFolder
|
|||||||
return foldersToReturn, folderErr
|
return foldersToReturn, folderErr
|
||||||
}
|
}
|
||||||
|
|
||||||
func GetFoldersViaJWT(JWTToken string, workspaceId string, environmentName string, foldersPath string) ([]models.SingleFolder, error) {
|
func GetFoldersViaJTW(JTWToken string, workspaceId string, environmentName string, foldersPath string) ([]models.SingleFolder, error) {
|
||||||
// set up resty client
|
// set up resty client
|
||||||
httpClient, err := GetRestyClientWithCustomHeaders()
|
httpClient, err := GetRestyClientWithCustomHeaders()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
httpClient.SetAuthToken(JWTToken).
|
httpClient.SetAuthToken(JTWToken).
|
||||||
SetHeader("Accept", "application/json")
|
SetHeader("Accept", "application/json")
|
||||||
|
|
||||||
getFoldersRequest := api.GetFoldersV1Request{
|
getFoldersRequest := api.GetFoldersV1Request{
|
||||||
@@ -194,7 +194,7 @@ func CreateFolder(params models.CreateFolderParameters) (models.SingleFolder, er
|
|||||||
loggedInUserDetails = EstablishUserLoginSession()
|
loggedInUserDetails = EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
|
|
||||||
params.InfisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
params.InfisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
// set up resty client
|
// set up resty client
|
||||||
@@ -243,7 +243,7 @@ func DeleteFolder(params models.DeleteFolderParameters) ([]models.SingleFolder,
|
|||||||
loggedInUserDetails = EstablishUserLoginSession()
|
loggedInUserDetails = EstablishUserLoginSession()
|
||||||
}
|
}
|
||||||
|
|
||||||
params.InfisicalToken = loggedInUserDetails.UserCredentials.JWTToken
|
params.InfisicalToken = loggedInUserDetails.UserCredentials.JTWToken
|
||||||
}
|
}
|
||||||
|
|
||||||
// set up resty client
|
// set up resty client
|
||||||
|
|||||||
@@ -302,9 +302,9 @@ func GetAllEnvironmentVariables(params models.GetAllSecretsParameters, projectCo
|
|||||||
params.WorkspaceId = infisicalDotJson.WorkspaceId
|
params.WorkspaceId = infisicalDotJson.WorkspaceId
|
||||||
}
|
}
|
||||||
|
|
||||||
res, err := GetPlainTextSecretsV3(loggedInUserDetails.UserCredentials.JWTToken, params.WorkspaceId,
|
res, err := GetPlainTextSecretsV3(loggedInUserDetails.UserCredentials.JTWToken, params.WorkspaceId,
|
||||||
params.Environment, params.SecretsPath, params.IncludeImport, params.Recursive, params.TagSlugs, true)
|
params.Environment, params.SecretsPath, params.IncludeImport, params.Recursive, params.TagSlugs, true)
|
||||||
log.Debug().Msgf("GetAllEnvironmentVariables: Trying to fetch secrets JWT token [err=%s]", err)
|
log.Debug().Msgf("GetAllEnvironmentVariables: Trying to fetch secrets JTW token [err=%s]", err)
|
||||||
|
|
||||||
if err == nil {
|
if err == nil {
|
||||||
backupEncryptionKey, err := GetBackupEncryptionKey()
|
backupEncryptionKey, err := GetBackupEncryptionKey()
|
||||||
|
|||||||
@@ -73,7 +73,6 @@ export const selectOrganization = async (data: {
|
|||||||
}) => {
|
}) => {
|
||||||
const { data: res } = await apiRequest.post<{
|
const { data: res } = await apiRequest.post<{
|
||||||
token: string;
|
token: string;
|
||||||
RefreshToken: string;
|
|
||||||
isMfaEnabled: boolean;
|
isMfaEnabled: boolean;
|
||||||
mfaMethod?: MfaMethod;
|
mfaMethod?: MfaMethod;
|
||||||
}>("/api/v3/auth/select-organization", data);
|
}>("/api/v3/auth/select-organization", data);
|
||||||
|
|||||||
@@ -76,9 +76,7 @@ export const PasswordStep = ({
|
|||||||
// case: organization ID is present from the provider auth token -- select the org and use the new jwt token in the CLI, then navigate to the org
|
// case: organization ID is present from the provider auth token -- select the org and use the new jwt token in the CLI, then navigate to the org
|
||||||
if (organizationId) {
|
if (organizationId) {
|
||||||
const finishWithOrgWorkflow = async () => {
|
const finishWithOrgWorkflow = async () => {
|
||||||
const { token, isMfaEnabled, mfaMethod, RefreshToken } = await selectOrganization({
|
const { token, isMfaEnabled, mfaMethod } = await selectOrganization({ organizationId });
|
||||||
organizationId
|
|
||||||
});
|
|
||||||
|
|
||||||
if (isMfaEnabled) {
|
if (isMfaEnabled) {
|
||||||
SecurityClient.setMfaToken(token);
|
SecurityClient.setMfaToken(token);
|
||||||
@@ -96,11 +94,10 @@ export const PasswordStep = ({
|
|||||||
const payload = {
|
const payload = {
|
||||||
privateKey,
|
privateKey,
|
||||||
email,
|
email,
|
||||||
JTWToken: token,
|
JTWToken: token
|
||||||
RefreshToken
|
|
||||||
};
|
};
|
||||||
await instance.post(cliUrl, payload).catch(() => {
|
await instance.post(cliUrl, payload).catch(() => {
|
||||||
// if error happens to communicate we set the token with an expiry in session storage
|
// if error happens to communicate we set the token with an expiry in sessino storage
|
||||||
// the cli-redirect page has logic to show this to user and ask them to paste it in terminal
|
// the cli-redirect page has logic to show this to user and ask them to paste it in terminal
|
||||||
sessionStorage.setItem(
|
sessionStorage.setItem(
|
||||||
SessionStorageKeys.CLI_TERMINAL_TOKEN,
|
SessionStorageKeys.CLI_TERMINAL_TOKEN,
|
||||||
@@ -190,7 +187,7 @@ export const PasswordStep = ({
|
|||||||
// case: organization ID is present from the provider auth token -- select the org and use the new jwt token in the CLI, then navigate to the org
|
// case: organization ID is present from the provider auth token -- select the org and use the new jwt token in the CLI, then navigate to the org
|
||||||
if (organizationId) {
|
if (organizationId) {
|
||||||
const finishWithOrgWorkflow = async () => {
|
const finishWithOrgWorkflow = async () => {
|
||||||
const { token, isMfaEnabled, mfaMethod, RefreshToken } = await selectOrganization({
|
const { token, isMfaEnabled, mfaMethod } = await selectOrganization({
|
||||||
organizationId
|
organizationId
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -209,11 +206,10 @@ export const PasswordStep = ({
|
|||||||
const instance = axios.create();
|
const instance = axios.create();
|
||||||
const payload = {
|
const payload = {
|
||||||
...isCliLoginSuccessful.loginResponse,
|
...isCliLoginSuccessful.loginResponse,
|
||||||
JTWToken: token,
|
JTWToken: token
|
||||||
RefreshToken
|
|
||||||
};
|
};
|
||||||
await instance.post(cliUrl, payload).catch(() => {
|
await instance.post(cliUrl, payload).catch(() => {
|
||||||
// if error happens to communicate we set the token with an expiry in session storage
|
// if error happens to communicate we set the token with an expiry in sessino storage
|
||||||
// the cli-redirect page has logic to show this to user and ask them to paste it in terminal
|
// the cli-redirect page has logic to show this to user and ask them to paste it in terminal
|
||||||
sessionStorage.setItem(
|
sessionStorage.setItem(
|
||||||
SessionStorageKeys.CLI_TERMINAL_TOKEN,
|
SessionStorageKeys.CLI_TERMINAL_TOKEN,
|
||||||
|
|||||||
@@ -112,7 +112,7 @@ export const SelectOrganizationSection = () => {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
const { token, isMfaEnabled, mfaMethod, RefreshToken } = await selectOrg
|
const { token, isMfaEnabled, mfaMethod } = await selectOrg
|
||||||
.mutateAsync({
|
.mutateAsync({
|
||||||
organizationId: organization.id,
|
organizationId: organization.id,
|
||||||
userAgent: callbackPort ? UserAgentType.CLI : undefined
|
userAgent: callbackPort ? UserAgentType.CLI : undefined
|
||||||
@@ -151,14 +151,13 @@ export const SelectOrganizationSection = () => {
|
|||||||
const payload = {
|
const payload = {
|
||||||
JTWToken: token,
|
JTWToken: token,
|
||||||
email: user?.email,
|
email: user?.email,
|
||||||
privateKey,
|
privateKey
|
||||||
RefreshToken
|
|
||||||
} as IsCliLoginSuccessful["loginResponse"];
|
} as IsCliLoginSuccessful["loginResponse"];
|
||||||
|
|
||||||
// send request to server endpoint
|
// send request to server endpoint
|
||||||
const instance = axios.create();
|
const instance = axios.create();
|
||||||
await instance.post(`http://127.0.0.1:${callbackPort}/`, payload).catch(() => {
|
await instance.post(`http://127.0.0.1:${callbackPort}/`, payload).catch(() => {
|
||||||
// if error happens to communicate we set the token with an expiry in session storage
|
// if error happens to communicate we set the token with an expiry in sessino storage
|
||||||
// the cli-redirect page has logic to show this to user and ask them to paste it in terminal
|
// the cli-redirect page has logic to show this to user and ask them to paste it in terminal
|
||||||
sessionStorage.setItem(
|
sessionStorage.setItem(
|
||||||
SessionStorageKeys.CLI_TERMINAL_TOKEN,
|
SessionStorageKeys.CLI_TERMINAL_TOKEN,
|
||||||
|
|||||||
Reference in New Issue
Block a user