mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 22:26:15 +00:00
PR fix suggestions
This commit is contained in:
+1
-1
@@ -20,7 +20,7 @@ export const AzureClientSecretRotationGeneratedCredentialsSchema = z
|
|||||||
.max(2);
|
.max(2);
|
||||||
|
|
||||||
const AzureClientSecretRotationParametersSchema = z.object({
|
const AzureClientSecretRotationParametersSchema = z.object({
|
||||||
appId: z.string().trim().min(1, "Client ID Required").describe(SecretRotations.PARAMETERS.AZURE_CLIENT_SECRET.appId),
|
appId: z.string().trim().min(1, "App ID Required").describe(SecretRotations.PARAMETERS.AZURE_CLIENT_SECRET.appId),
|
||||||
appName: z
|
appName: z
|
||||||
.string()
|
.string()
|
||||||
.trim()
|
.trim()
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ import { AppConnection } from "@app/services/app-connection/app-connection-enums
|
|||||||
|
|
||||||
export const SECRET_ROTATION_NAME_MAP: Record<SecretRotation, string> = {
|
export const SECRET_ROTATION_NAME_MAP: Record<SecretRotation, string> = {
|
||||||
[SecretRotation.PostgresCredentials]: "PostgreSQL Credentials",
|
[SecretRotation.PostgresCredentials]: "PostgreSQL Credentials",
|
||||||
[SecretRotation.MsSqlCredentials]: "Microsoft SQL Sever Credentials",
|
[SecretRotation.MsSqlCredentials]: "Microsoft SQL Server Credentials",
|
||||||
[SecretRotation.Auth0ClientSecret]: "Auth0 Client Secret",
|
[SecretRotation.Auth0ClientSecret]: "Auth0 Client Secret",
|
||||||
[SecretRotation.AzureClientSecret]: "Azure Client Secret"
|
[SecretRotation.AzureClientSecret]: "Azure Client Secret"
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record<AppConnection, (server:
|
|||||||
[AppConnection.GCP]: registerGcpConnectionRouter,
|
[AppConnection.GCP]: registerGcpConnectionRouter,
|
||||||
[AppConnection.AzureKeyVault]: registerAzureKeyVaultConnectionRouter,
|
[AppConnection.AzureKeyVault]: registerAzureKeyVaultConnectionRouter,
|
||||||
[AppConnection.AzureAppConfiguration]: registerAzureAppConfigurationConnectionRouter,
|
[AppConnection.AzureAppConfiguration]: registerAzureAppConfigurationConnectionRouter,
|
||||||
|
[AppConnection.AzureClientSecrets]: registerAzureClientSecretsConnectionRouter,
|
||||||
[AppConnection.Databricks]: registerDatabricksConnectionRouter,
|
[AppConnection.Databricks]: registerDatabricksConnectionRouter,
|
||||||
[AppConnection.Humanitec]: registerHumanitecConnectionRouter,
|
[AppConnection.Humanitec]: registerHumanitecConnectionRouter,
|
||||||
[AppConnection.TerraformCloud]: registerTerraformCloudConnectionRouter,
|
[AppConnection.TerraformCloud]: registerTerraformCloudConnectionRouter,
|
||||||
@@ -32,7 +33,6 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record<AppConnection, (server:
|
|||||||
[AppConnection.Postgres]: registerPostgresConnectionRouter,
|
[AppConnection.Postgres]: registerPostgresConnectionRouter,
|
||||||
[AppConnection.MsSql]: registerMsSqlConnectionRouter,
|
[AppConnection.MsSql]: registerMsSqlConnectionRouter,
|
||||||
[AppConnection.Camunda]: registerCamundaConnectionRouter,
|
[AppConnection.Camunda]: registerCamundaConnectionRouter,
|
||||||
[AppConnection.AzureClientSecrets]: registerAzureClientSecretsConnectionRouter,
|
|
||||||
[AppConnection.Windmill]: registerWindmillConnectionRouter,
|
[AppConnection.Windmill]: registerWindmillConnectionRouter,
|
||||||
[AppConnection.Auth0]: registerAuth0ConnectionRouter
|
[AppConnection.Auth0]: registerAuth0ConnectionRouter
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -134,6 +134,8 @@ export const validateAppConnectionCredentials = async (
|
|||||||
[AppConnection.AzureKeyVault]: validateAzureKeyVaultConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.AzureKeyVault]: validateAzureKeyVaultConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.AzureAppConfiguration]:
|
[AppConnection.AzureAppConfiguration]:
|
||||||
validateAzureAppConfigurationConnectionCredentials as TAppConnectionCredentialsValidator,
|
validateAzureAppConfigurationConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
|
[AppConnection.AzureClientSecrets]:
|
||||||
|
validateAzureClientSecretsConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Humanitec]: validateHumanitecConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Humanitec]: validateHumanitecConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Postgres]: validateSqlConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Postgres]: validateSqlConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.MsSql]: validateSqlConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.MsSql]: validateSqlConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
@@ -141,8 +143,6 @@ export const validateAppConnectionCredentials = async (
|
|||||||
[AppConnection.Vercel]: validateVercelConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Vercel]: validateVercelConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.TerraformCloud]: validateTerraformCloudConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.TerraformCloud]: validateTerraformCloudConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Auth0]: validateAuth0ConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Auth0]: validateAuth0ConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.AzureClientSecrets]:
|
|
||||||
validateAzureClientSecretsConnectionCredentials as TAppConnectionCredentialsValidator,
|
|
||||||
[AppConnection.Windmill]: validateWindmillConnectionCredentials as TAppConnectionCredentialsValidator
|
[AppConnection.Windmill]: validateWindmillConnectionCredentials as TAppConnectionCredentialsValidator
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -452,8 +452,8 @@ export const appConnectionServiceFactory = ({
|
|||||||
terraformCloud: terraformCloudConnectionService(connectAppConnectionById),
|
terraformCloud: terraformCloudConnectionService(connectAppConnectionById),
|
||||||
camunda: camundaConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
camunda: camundaConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
vercel: vercelConnectionService(connectAppConnectionById),
|
vercel: vercelConnectionService(connectAppConnectionById),
|
||||||
auth0: auth0ConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
|
||||||
azureClientSecrets: azureClientSecretsConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
azureClientSecrets: azureClientSecretsConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
|
auth0: auth0ConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
windmill: windmillConnectionService(connectAppConnectionById)
|
windmill: windmillConnectionService(connectAppConnectionById)
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -145,12 +145,12 @@ export type TAppConnectionConfig =
|
|||||||
| TGcpConnectionConfig
|
| TGcpConnectionConfig
|
||||||
| TAzureKeyVaultConnectionConfig
|
| TAzureKeyVaultConnectionConfig
|
||||||
| TAzureAppConfigurationConnectionConfig
|
| TAzureAppConfigurationConnectionConfig
|
||||||
|
| TAzureClientSecretsConnectionConfig
|
||||||
| TDatabricksConnectionConfig
|
| TDatabricksConnectionConfig
|
||||||
| THumanitecConnectionConfig
|
| THumanitecConnectionConfig
|
||||||
| TTerraformCloudConnectionConfig
|
| TTerraformCloudConnectionConfig
|
||||||
| TSqlConnectionConfig
|
| TSqlConnectionConfig
|
||||||
| TCamundaConnectionConfig
|
| TCamundaConnectionConfig
|
||||||
| TAzureClientSecretsConnectionConfig
|
|
||||||
| TVercelConnectionConfig
|
| TVercelConnectionConfig
|
||||||
| TWindmillConnectionConfig
|
| TWindmillConnectionConfig
|
||||||
| TAuth0ConnectionConfig;
|
| TAuth0ConnectionConfig;
|
||||||
@@ -161,6 +161,7 @@ export type TValidateAppConnectionCredentialsSchema =
|
|||||||
| TValidateGcpConnectionCredentialsSchema
|
| TValidateGcpConnectionCredentialsSchema
|
||||||
| TValidateAzureKeyVaultConnectionCredentialsSchema
|
| TValidateAzureKeyVaultConnectionCredentialsSchema
|
||||||
| TValidateAzureAppConfigurationConnectionCredentialsSchema
|
| TValidateAzureAppConfigurationConnectionCredentialsSchema
|
||||||
|
| TValidateAzureClientSecretsConnectionCredentialsSchema
|
||||||
| TValidateDatabricksConnectionCredentialsSchema
|
| TValidateDatabricksConnectionCredentialsSchema
|
||||||
| TValidateHumanitecConnectionCredentialsSchema
|
| TValidateHumanitecConnectionCredentialsSchema
|
||||||
| TValidatePostgresConnectionCredentialsSchema
|
| TValidatePostgresConnectionCredentialsSchema
|
||||||
@@ -168,7 +169,6 @@ export type TValidateAppConnectionCredentialsSchema =
|
|||||||
| TValidateCamundaConnectionCredentialsSchema
|
| TValidateCamundaConnectionCredentialsSchema
|
||||||
| TValidateVercelConnectionCredentialsSchema
|
| TValidateVercelConnectionCredentialsSchema
|
||||||
| TValidateTerraformCloudConnectionCredentialsSchema
|
| TValidateTerraformCloudConnectionCredentialsSchema
|
||||||
| TValidateAzureClientSecretsConnectionCredentialsSchema
|
|
||||||
| TValidateWindmillConnectionCredentialsSchema
|
| TValidateWindmillConnectionCredentialsSchema
|
||||||
| TValidateAuth0ConnectionCredentialsSchema;
|
| TValidateAuth0ConnectionCredentialsSchema;
|
||||||
|
|
||||||
|
|||||||
+9
-2
@@ -31,6 +31,8 @@ export const getAzureClientSecretsConnectionListItem = () => {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const EXPIRATION_TIME = 300000;
|
||||||
|
|
||||||
export const getAzureConnectionAccessToken = async (
|
export const getAzureConnectionAccessToken = async (
|
||||||
connectionId: string,
|
connectionId: string,
|
||||||
appConnectionDAL: Pick<TAppConnectionDALFactory, "findById" | "updateById">,
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "findById" | "updateById">,
|
||||||
@@ -62,9 +64,10 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
})) as TAzureClientSecretsConnectionCredentials;
|
})) as TAzureClientSecretsConnectionCredentials;
|
||||||
|
|
||||||
const { expiresAt, refreshToken } = credentials;
|
const { expiresAt, refreshToken } = credentials;
|
||||||
|
const currentTime = Date.now();
|
||||||
|
|
||||||
// get new token if expired or less than 5 minutes until expiry
|
// get new token if expired or less than 5 minutes until expiry
|
||||||
if (Date.now() < expiresAt - 300000) {
|
if (currentTime < expiresAt - EXPIRATION_TIME) {
|
||||||
return credentials.accessToken;
|
return credentials.accessToken;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -82,7 +85,7 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
const updatedCredentials = {
|
const updatedCredentials = {
|
||||||
...credentials,
|
...credentials,
|
||||||
accessToken: data.access_token,
|
accessToken: data.access_token,
|
||||||
expiresAt: Date.now() + data.expires_in * 1000,
|
expiresAt: currentTime + data.expires_in * 1000,
|
||||||
refreshToken: data.refresh_token
|
refreshToken: data.refresh_token
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -102,6 +105,10 @@ export const validateAzureClientSecretsConnectionCredentials = async (config: TA
|
|||||||
|
|
||||||
const { INF_APP_CONNECTION_AZURE_CLIENT_ID, INF_APP_CONNECTION_AZURE_CLIENT_SECRET, SITE_URL } = getConfig();
|
const { INF_APP_CONNECTION_AZURE_CLIENT_ID, INF_APP_CONNECTION_AZURE_CLIENT_SECRET, SITE_URL } = getConfig();
|
||||||
|
|
||||||
|
if (!SITE_URL) {
|
||||||
|
throw new InternalServerError({ message: "SITE_URL env var is required to complete Azure OAuth flow" });
|
||||||
|
}
|
||||||
|
|
||||||
if (!INF_APP_CONNECTION_AZURE_CLIENT_ID || !INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
if (!INF_APP_CONNECTION_AZURE_CLIENT_ID || !INF_APP_CONNECTION_AZURE_CLIENT_SECRET) {
|
||||||
throw new InternalServerError({
|
throw new InternalServerError({
|
||||||
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
message: `Azure ${getAppConnectionMethodName(method)} environment variables have not been configured`
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
import z from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { DiscriminativePick } from "@app/lib/types";
|
import { DiscriminativePick } from "@app/lib/types";
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -43,7 +43,7 @@ export const getAzureConnectionAccessToken = async (
|
|||||||
appConnection.app !== AppConnection.AzureAppConfiguration &&
|
appConnection.app !== AppConnection.AzureAppConfiguration &&
|
||||||
appConnection.app !== AppConnection.AzureClientSecrets
|
appConnection.app !== AppConnection.AzureClientSecrets
|
||||||
) {
|
) {
|
||||||
throw new BadRequestError({ message: `Connection with ID '${connectionId}' is not an Azure Key Vault connection` });
|
throw new BadRequestError({ message: `Connection with ID '${connectionId}' is not a valid Azure connection` });
|
||||||
}
|
}
|
||||||
|
|
||||||
const credentials = (await decryptAppConnectionCredentials({
|
const credentials = (await decryptAppConnectionCredentials({
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: "Azure Client Secrets Connection"
|
title: "Azure Client Secrets Connection"
|
||||||
description: "Learn how to configure a Azure Client Secrets Connection for Infisical."
|
description: "Learn how to configure an Azure Client Secrets Connection for Infisical."
|
||||||
---
|
---
|
||||||
|
|
||||||
Infisical currently only supports one method for connecting to Azure, which is OAuth.
|
Infisical currently only supports one method for connecting to Azure, which is OAuth.
|
||||||
@@ -32,7 +32,7 @@ Infisical currently only supports one method for connecting to Azure, which is O
|
|||||||
</Step>
|
</Step>
|
||||||
<Step title="Assign API permissions to the application">
|
<Step title="Assign API permissions to the application">
|
||||||
|
|
||||||
For the Azure Connection to work with Client Secrets, you need to assign multiple permissions to the application.
|
For the Azure Connection to work with Client Secrets, you need to assign the following permission to the application.
|
||||||
|
|
||||||
#### Azure Client Secrets permissions
|
#### Azure Client Secrets permissions
|
||||||
|
|
||||||
@@ -81,10 +81,10 @@ Infisical currently only supports one method for connecting to Azure, which is O
|
|||||||
</Step>
|
</Step>
|
||||||
<Step title="Grant Access">
|
<Step title="Grant Access">
|
||||||
You will then be redirected to Azure to grant Infisical access to your Azure account. Once granted,
|
You will then be redirected to Azure to grant Infisical access to your Azure account. Once granted,
|
||||||
you will redirect you back to Infisical's App Connections page. 
|
Authorization](/images/app-connections/azure/grant-access.png)
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Connection Created">
|
<Step title="Connection Created">
|
||||||
Your **Azure Client Secrets Connection** is now available for use. 
|
Your **Azure Client Secrets Connection** is now available for use. 
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
+1
@@ -43,6 +43,7 @@ export const AzureClientSecretRotationSecretsMappingFields = () => {
|
|||||||
<Input
|
<Input
|
||||||
value={value}
|
value={value}
|
||||||
onChange={onChange}
|
onChange={onChange}
|
||||||
|
type="password"
|
||||||
placeholder={rotationOption?.template.secretsMapping.clientSecret}
|
placeholder={rotationOption?.template.secretsMapping.clientSecret}
|
||||||
/>
|
/>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
|
|||||||
@@ -6,10 +6,10 @@ import { MsSqlCredentialsRotationSchema } from "@app/components/secret-rotations
|
|||||||
import { PostgresCredentialsRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/postgres-credentials-rotation-schema";
|
import { PostgresCredentialsRotationSchema } from "@app/components/secret-rotations-v2/forms/schemas/postgres-credentials-rotation-schema";
|
||||||
|
|
||||||
const SecretRotationUnionSchema = z.discriminatedUnion("type", [
|
const SecretRotationUnionSchema = z.discriminatedUnion("type", [
|
||||||
PostgresCredentialsRotationSchema,
|
|
||||||
MsSqlCredentialsRotationSchema,
|
|
||||||
Auth0ClientSecretRotationSchema,
|
Auth0ClientSecretRotationSchema,
|
||||||
AzureClientSecretRotationSchema
|
AzureClientSecretRotationSchema,
|
||||||
|
PostgresCredentialsRotationSchema,
|
||||||
|
MsSqlCredentialsRotationSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const SecretRotationV2FormSchema = SecretRotationUnionSchema;
|
export const SecretRotationV2FormSchema = SecretRotationUnionSchema;
|
||||||
|
|||||||
@@ -80,6 +80,7 @@ export type TAppConnectionMap = {
|
|||||||
[AppConnection.GCP]: TGcpConnection;
|
[AppConnection.GCP]: TGcpConnection;
|
||||||
[AppConnection.AzureKeyVault]: TAzureKeyVaultConnection;
|
[AppConnection.AzureKeyVault]: TAzureKeyVaultConnection;
|
||||||
[AppConnection.AzureAppConfiguration]: TAzureAppConfigurationConnection;
|
[AppConnection.AzureAppConfiguration]: TAzureAppConfigurationConnection;
|
||||||
|
[AppConnection.AzureClientSecrets]: TAzureClientSecretsConnection;
|
||||||
[AppConnection.Databricks]: TDatabricksConnection;
|
[AppConnection.Databricks]: TDatabricksConnection;
|
||||||
[AppConnection.Humanitec]: THumanitecConnection;
|
[AppConnection.Humanitec]: THumanitecConnection;
|
||||||
[AppConnection.TerraformCloud]: TTerraformCloudConnection;
|
[AppConnection.TerraformCloud]: TTerraformCloudConnection;
|
||||||
@@ -87,7 +88,6 @@ export type TAppConnectionMap = {
|
|||||||
[AppConnection.Postgres]: TPostgresConnection;
|
[AppConnection.Postgres]: TPostgresConnection;
|
||||||
[AppConnection.MsSql]: TMsSqlConnection;
|
[AppConnection.MsSql]: TMsSqlConnection;
|
||||||
[AppConnection.Camunda]: TCamundaConnection;
|
[AppConnection.Camunda]: TCamundaConnection;
|
||||||
[AppConnection.AzureClientSecrets]: TAzureClientSecretsConnection;
|
|
||||||
[AppConnection.Windmill]: TWindmillConnection;
|
[AppConnection.Windmill]: TWindmillConnection;
|
||||||
[AppConnection.Auth0]: TAuth0Connection;
|
[AppConnection.Auth0]: TAuth0Connection;
|
||||||
};
|
};
|
||||||
|
|||||||
+1
-9
@@ -83,15 +83,7 @@ export const AzureClientSecretsConnectionForm = ({ appConnection }: Props) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
let isMissingConfig: boolean;
|
const isMissingConfig = !oauthClientId;
|
||||||
|
|
||||||
switch (selectedMethod) {
|
|
||||||
case AzureClientSecretsConnectionMethod.OAuth:
|
|
||||||
isMissingConfig = !oauthClientId;
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
throw new Error(`Unhandled Azure Connection method: ${selectedMethod}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
const methodDetails = getAppConnectionMethodDetails(selectedMethod);
|
const methodDetails = getAppConnectionMethodDetails(selectedMethod);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user