fix: addressed rabbit findings

This commit is contained in:
Sheen Capadngan
2025-02-19 17:16:02 +08:00
parent 1db8c9ea29
commit f0e6bcef9b
14 changed files with 38 additions and 29 deletions
@@ -236,7 +236,7 @@ export const registerKmipOperationRouter = async (server: FastifyZodProvider) =>
}, },
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
handler: async (req) => { handler: async (req) => {
const object = await server.services.kmipOperation.deleteOp({ const object = await server.services.kmipOperation.destroy({
...req.kmipUser, ...req.kmipUser,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
@@ -255,7 +255,7 @@ export const registerKmipOperationRouter = async (server: FastifyZodProvider) =>
} }
}, },
event: { event: {
type: EventType.KMIP_OPERATION_DELETE, type: EventType.KMIP_OPERATION_DESTROY,
metadata: { metadata: {
id: object.id id: object.id
} }
+8
View File
@@ -61,6 +61,8 @@ export const registerKmipRouter = async (server: FastifyZodProvider) => {
} }
} }
}); });
return kmipClient;
} }
}); });
@@ -107,6 +109,8 @@ export const registerKmipRouter = async (server: FastifyZodProvider) => {
} }
} }
}); });
return kmipClient;
} }
}); });
@@ -145,6 +149,8 @@ export const registerKmipRouter = async (server: FastifyZodProvider) => {
} }
} }
}); });
return kmipClient;
} }
}); });
@@ -183,6 +189,8 @@ export const registerKmipRouter = async (server: FastifyZodProvider) => {
} }
} }
}); });
return kmipClient;
} }
}); });
@@ -275,7 +275,7 @@ export enum EventType {
KMIP_OPERATION_CREATE = "kmip-operation-create", KMIP_OPERATION_CREATE = "kmip-operation-create",
KMIP_OPERATION_GET = "kmip-operation-get", KMIP_OPERATION_GET = "kmip-operation-get",
KMIP_OPERATION_DELETE = "kmip-operation-delete", KMIP_OPERATION_DESTROY = "kmip-operation-destroy",
KMIP_OPERATION_GET_ATTRIBUTES = "kmip-operation-get-attributes", KMIP_OPERATION_GET_ATTRIBUTES = "kmip-operation-get-attributes",
KMIP_OPERATION_ACTIVATE = "kmip-operation-activate", KMIP_OPERATION_ACTIVATE = "kmip-operation-activate",
KMIP_OPERATION_REVOKE = "kmip-operation-revoke", KMIP_OPERATION_REVOKE = "kmip-operation-revoke",
@@ -2178,8 +2178,8 @@ interface KmipOperationGetEvent {
}; };
} }
interface KmipOperationDeleteEvent { interface KmipOperationDestroyEvent {
type: EventType.KMIP_OPERATION_DELETE; type: EventType.KMIP_OPERATION_DESTROY;
metadata: { metadata: {
id: string; id: string;
}; };
@@ -2457,7 +2457,7 @@ export type Event =
| GetKmipEvent | GetKmipEvent
| RegisterKmipServerEvent | RegisterKmipServerEvent
| KmipOperationGetEvent | KmipOperationGetEvent
| KmipOperationDeleteEvent | KmipOperationDestroyEvent
| KmipOperationCreateEvent | KmipOperationCreateEvent
| KmipOperationGetAttributesEvent | KmipOperationGetAttributesEvent
| KmipOperationActivateEvent | KmipOperationActivateEvent
+1 -1
View File
@@ -6,6 +6,6 @@ export enum KmipPermission {
GetAttributes = "get-attributes", GetAttributes = "get-attributes",
Activate = "activate", Activate = "activate",
Revoke = "revoke", Revoke = "revoke",
Delete = "delete", Destroy = "destroy",
Register = "register" Register = "register"
} }
@@ -11,7 +11,7 @@ import { TKmipClientDALFactory } from "./kmip-client-dal";
import { KmipPermission } from "./kmip-enum"; import { KmipPermission } from "./kmip-enum";
import { import {
TKmipCreateDTO, TKmipCreateDTO,
TKmipDeleteDTO, TKmipDestroyDTO,
TKmipGetAttributesDTO, TKmipGetAttributesDTO,
TKmipGetDTO, TKmipGetDTO,
TKmipLocateDTO, TKmipLocateDTO,
@@ -76,7 +76,7 @@ export const kmipOperationServiceFactory = ({
return kmsKey; return kmsKey;
}; };
const deleteOp = async ({ projectId, id, clientId, actor, actorId, actorOrgId, actorAuthMethod }: TKmipDeleteDTO) => { const destroy = async ({ projectId, id, clientId, actor, actorId, actorOrgId, actorAuthMethod }: TKmipDestroyDTO) => {
const { permission } = await permissionService.getOrgPermission( const { permission } = await permissionService.getOrgPermission(
actor, actor,
actorId, actorId,
@@ -92,9 +92,9 @@ export const kmipOperationServiceFactory = ({
projectId projectId
}); });
if (!kmipClient.permissions?.includes(KmipPermission.Delete)) { if (!kmipClient.permissions?.includes(KmipPermission.Destroy)) {
throw new ForbiddenRequestError({ throw new ForbiddenRequestError({
message: "Client does not have sufficient permission to perform KMIP delete" message: "Client does not have sufficient permission to perform KMIP destroy"
}); });
} }
@@ -108,13 +108,19 @@ export const kmipOperationServiceFactory = ({
} }
if (key.isReserved) { if (key.isReserved) {
throw new BadRequestError({ message: "Cannot delete reserved keys" }); throw new BadRequestError({ message: "Cannot destroy reserved keys" });
} }
const completeKeyDetails = await kmsDAL.findByIdWithAssociatedKms(id); const completeKeyDetails = await kmsDAL.findByIdWithAssociatedKms(id);
if (!completeKeyDetails.internalKms) { if (!completeKeyDetails.internalKms) {
throw new BadRequestError({ throw new BadRequestError({
message: "Cannot delete external keys" message: "Cannot destroy external keys"
});
}
if (!completeKeyDetails.isDisabled) {
throw new BadRequestError({
message: "Cannot destroy active keys"
}); });
} }
@@ -408,7 +414,7 @@ export const kmipOperationServiceFactory = ({
get, get,
activate, activate,
getAttributes, getAttributes,
deleteOp, destroy,
revoke, revoke,
locate, locate,
register register
+1 -1
View File
@@ -60,7 +60,7 @@ export type TKmipGetAttributesDTO = {
id: string; id: string;
} & KmipOperationBaseDTO; } & KmipOperationBaseDTO;
export type TKmipDeleteDTO = { export type TKmipDestroyDTO = {
id: string; id: string;
} & KmipOperationBaseDTO; } & KmipOperationBaseDTO;
+1 -1
View File
@@ -11,7 +11,7 @@ require (
github.com/gitleaks/go-gitdiff v0.8.0 github.com/gitleaks/go-gitdiff v0.8.0
github.com/h2non/filetype v1.1.3 github.com/h2non/filetype v1.1.3
github.com/infisical/go-sdk v0.4.8 github.com/infisical/go-sdk v0.4.8
github.com/infisical/infisical-kmip v0.3.3 github.com/infisical/infisical-kmip v0.3.4
github.com/mattn/go-isatty v0.0.20 github.com/mattn/go-isatty v0.0.20
github.com/muesli/ansi v0.0.0-20221106050444-61f0cd9a192a github.com/muesli/ansi v0.0.0-20221106050444-61f0cd9a192a
github.com/muesli/mango-cobra v1.2.0 github.com/muesli/mango-cobra v1.2.0
+2 -2
View File
@@ -273,8 +273,8 @@ github.com/inconshreveable/mousetrap v1.0.1 h1:U3uMjPSQEBMNp1lFxmllqCPM6P5u/Xq7P
github.com/inconshreveable/mousetrap v1.0.1/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/inconshreveable/mousetrap v1.0.1/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
github.com/infisical/go-sdk v0.4.8 h1:aphRnaauC5//PkP1ZbY9RSK2RiT1LjPS5o4CbX0x5OQ= github.com/infisical/go-sdk v0.4.8 h1:aphRnaauC5//PkP1ZbY9RSK2RiT1LjPS5o4CbX0x5OQ=
github.com/infisical/go-sdk v0.4.8/go.mod h1:bMO9xSaBeXkDBhTIM4FkkREAfw2V8mv5Bm7lvo4+uDk= github.com/infisical/go-sdk v0.4.8/go.mod h1:bMO9xSaBeXkDBhTIM4FkkREAfw2V8mv5Bm7lvo4+uDk=
github.com/infisical/infisical-kmip v0.3.3 h1:RNOlUsuYy81kS0yrT2n9O54VMo8NoiqLAgw5ZgYAxEo= github.com/infisical/infisical-kmip v0.3.4 h1:X7wsW/vnqrTAtilYyuz+xFtkUu025wD5Yfk2u/LbniQ=
github.com/infisical/infisical-kmip v0.3.3/go.mod h1:bO1M4YtKyutNg1bREPmlyZspC5duSR7hyQ3lPmLzrIs= github.com/infisical/infisical-kmip v0.3.4/go.mod h1:bO1M4YtKyutNg1bREPmlyZspC5duSR7hyQ3lPmLzrIs=
github.com/jedib0t/go-pretty v4.3.0+incompatible h1:CGs8AVhEKg/n9YbUenWmNStRW2PHJzaeDodcfvRAbIo= github.com/jedib0t/go-pretty v4.3.0+incompatible h1:CGs8AVhEKg/n9YbUenWmNStRW2PHJzaeDodcfvRAbIo=
github.com/jedib0t/go-pretty v4.3.0+incompatible/go.mod h1:XemHduiw8R651AF9Pt4FwCTKeG3oo7hrHJAoznj9nag= github.com/jedib0t/go-pretty v4.3.0+incompatible/go.mod h1:XemHduiw8R651AF9Pt4FwCTKeG3oo7hrHJAoznj9nag=
github.com/json-iterator/go v1.1.11/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4= github.com/json-iterator/go v1.1.11/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
-4
View File
@@ -78,10 +78,6 @@ func startKmipServer(cmd *cobra.Command, args []string) {
util.HandleError(err, "Unable to parse flag") util.HandleError(err, "Unable to parse flag")
} }
if hostnamesOrIps == "" {
util.PrintErrorMessageAndExit("missing value for field hostnames-or-ips")
}
kmip.StartServer(kmip.ServerConfig{ kmip.StartServer(kmip.ServerConfig{
Addr: addr, Addr: addr,
InfisicalBaseAPIURL: config.INFISICAL_URL, InfisicalBaseAPIURL: config.INFISICAL_URL,
+1 -2
View File
@@ -18,8 +18,7 @@ export const adminQueryKeys = {
serverConfig: () => ["server-config"] as const, serverConfig: () => ["server-config"] as const,
getUsers: (filters: AdminGetUsersFilters) => [adminStandaloneKeys.getUsers, { filters }] as const, getUsers: (filters: AdminGetUsersFilters) => [adminStandaloneKeys.getUsers, { filters }] as const,
getAdminSlackConfig: () => ["admin-slack-config"] as const, getAdminSlackConfig: () => ["admin-slack-config"] as const,
getServerEncryptionStrategies: () => ["server-encryption-strategies"] as const, getServerEncryptionStrategies: () => ["server-encryption-strategies"] as const
getInstanceKmip: () => ["instance-kmip"] as const
}; };
export const fetchServerConfig = async () => { export const fetchServerConfig = async () => {
@@ -133,7 +133,7 @@ export const eventToNameMap: { [K in EventType]: string } = {
[EventType.REGISTER_KMIP_SERVER]: "Register KMIP server", [EventType.REGISTER_KMIP_SERVER]: "Register KMIP server",
[EventType.KMIP_OPERATION_CREATE]: "KMIP operation create", [EventType.KMIP_OPERATION_CREATE]: "KMIP operation create",
[EventType.KMIP_OPERATION_GET]: "KMIP operation get", [EventType.KMIP_OPERATION_GET]: "KMIP operation get",
[EventType.KMIP_OPERATION_DELETE]: "KMIP operation delete", [EventType.KMIP_OPERATION_DESTROY]: "KMIP operation destroy",
[EventType.KMIP_OPERATION_GET_ATTRIBUTES]: "KMIP operation get attributes", [EventType.KMIP_OPERATION_GET_ATTRIBUTES]: "KMIP operation get attributes",
[EventType.KMIP_OPERATION_ACTIVATE]: "KMIP operation activate", [EventType.KMIP_OPERATION_ACTIVATE]: "KMIP operation activate",
[EventType.KMIP_OPERATION_REVOKE]: "KMIP operation revoke", [EventType.KMIP_OPERATION_REVOKE]: "KMIP operation revoke",
+1 -1
View File
@@ -145,7 +145,7 @@ export enum EventType {
REGISTER_KMIP_SERVER = "register-kmip-server", REGISTER_KMIP_SERVER = "register-kmip-server",
KMIP_OPERATION_CREATE = "kmip-operation-create", KMIP_OPERATION_CREATE = "kmip-operation-create",
KMIP_OPERATION_GET = "kmip-operation-get", KMIP_OPERATION_GET = "kmip-operation-get",
KMIP_OPERATION_DELETE = "kmip-operation-delete", KMIP_OPERATION_DESTROY = "kmip-operation-destroy",
KMIP_OPERATION_GET_ATTRIBUTES = "kmip-operation-get-attributes", KMIP_OPERATION_GET_ATTRIBUTES = "kmip-operation-get-attributes",
KMIP_OPERATION_ACTIVATE = "kmip-operation-activate", KMIP_OPERATION_ACTIVATE = "kmip-operation-activate",
KMIP_OPERATION_REVOKE = "kmip-operation-revoke", KMIP_OPERATION_REVOKE = "kmip-operation-revoke",
+1 -1
View File
@@ -9,7 +9,7 @@ export enum KmipPermission {
GetAttributes = "get-attributes", GetAttributes = "get-attributes",
Activate = "activate", Activate = "activate",
Revoke = "revoke", Revoke = "revoke",
Delete = "delete", Destroy = "destroy",
Register = "register" Register = "register"
} }
@@ -22,7 +22,7 @@ const KMIP_PERMISSIONS_OPTIONS = [
{ value: KmipPermission.Create, label: "Create" }, { value: KmipPermission.Create, label: "Create" },
{ value: KmipPermission.Get, label: "Get" }, { value: KmipPermission.Get, label: "Get" },
{ value: KmipPermission.Locate, label: "Locate" }, { value: KmipPermission.Locate, label: "Locate" },
{ value: KmipPermission.Delete, label: "Delete" }, { value: KmipPermission.Destroy, label: "Destroy" },
{ value: KmipPermission.Activate, label: "Activate" }, { value: KmipPermission.Activate, label: "Activate" },
{ value: KmipPermission.Revoke, label: "Revoke" }, { value: KmipPermission.Revoke, label: "Revoke" },
{ value: KmipPermission.GetAttributes, label: "Get Attributes" }, { value: KmipPermission.GetAttributes, label: "Get Attributes" },
@@ -37,7 +37,7 @@ const formSchema = z.object({
[KmipPermission.Create]: z.boolean().optional(), [KmipPermission.Create]: z.boolean().optional(),
[KmipPermission.Get]: z.boolean().optional(), [KmipPermission.Get]: z.boolean().optional(),
[KmipPermission.Locate]: z.boolean().optional(), [KmipPermission.Locate]: z.boolean().optional(),
[KmipPermission.Delete]: z.boolean().optional(), [KmipPermission.Destroy]: z.boolean().optional(),
[KmipPermission.Activate]: z.boolean().optional(), [KmipPermission.Activate]: z.boolean().optional(),
[KmipPermission.GetAttributes]: z.boolean().optional(), [KmipPermission.GetAttributes]: z.boolean().optional(),
[KmipPermission.Revoke]: z.boolean().optional(), [KmipPermission.Revoke]: z.boolean().optional(),