mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
Fix project seed (seeds old projects that can be upgraded)
This commit is contained in:
@@ -1,3 +1,4 @@
|
|||||||
|
/* eslint-disable import/no-mutable-exports */
|
||||||
import crypto from "node:crypto";
|
import crypto from "node:crypto";
|
||||||
|
|
||||||
import argon2, { argon2id } from "argon2";
|
import argon2, { argon2id } from "argon2";
|
||||||
@@ -15,9 +16,12 @@ import {
|
|||||||
|
|
||||||
import { TSecrets, TUserEncryptionKeys } from "./schemas";
|
import { TSecrets, TUserEncryptionKeys } from "./schemas";
|
||||||
|
|
||||||
|
export let userPrivateKey: string | undefined;
|
||||||
|
export let userPublicKey: string | undefined;
|
||||||
|
|
||||||
export const seedData1 = {
|
export const seedData1 = {
|
||||||
id: "3dafd81d-4388-432b-a4c5-f735616868c1",
|
id: "3dafd81d-4388-432b-a4c5-f735616868c1",
|
||||||
email: "[email protected]",
|
email: process.env.TEST_USER_EMAIL || "[email protected]",
|
||||||
password: process.env.TEST_USER_PASSWORD || "testInfisical@1",
|
password: process.env.TEST_USER_PASSWORD || "testInfisical@1",
|
||||||
organization: {
|
organization: {
|
||||||
id: "180870b7-f464-4740-8ffe-9d11c9245ea7",
|
id: "180870b7-f464-4740-8ffe-9d11c9245ea7",
|
||||||
@@ -42,6 +46,12 @@ export const seedData1 = {
|
|||||||
},
|
},
|
||||||
token: {
|
token: {
|
||||||
id: "a9dfafba-a3b7-42e3-8618-91abb702fd36"
|
id: "a9dfafba-a3b7-42e3-8618-91abb702fd36"
|
||||||
|
},
|
||||||
|
|
||||||
|
// We set these values during user creation, and later re-use them during project seeding.
|
||||||
|
encryptionKeys: {
|
||||||
|
publicKey: "",
|
||||||
|
privateKey: ""
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -3,9 +3,12 @@
|
|||||||
|
|
||||||
import { Knex } from "knex";
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
// eslint-disable-next-line @typescript-eslint/no-unused-vars
|
||||||
|
import { generateUserSrpKeys } from "@app/lib/crypto/srp";
|
||||||
|
|
||||||
import { AuthMethod } from "../../services/auth/auth-type";
|
import { AuthMethod } from "../../services/auth/auth-type";
|
||||||
import { TableName } from "../schemas";
|
import { TableName } from "../schemas";
|
||||||
import { generateUserSrpKeys, seedData1 } from "../seed-data";
|
import { seedData1 } from "../seed-data";
|
||||||
|
|
||||||
export async function seed(knex: Knex): Promise<void> {
|
export async function seed(knex: Knex): Promise<void> {
|
||||||
// Deletes ALL existing entries
|
// Deletes ALL existing entries
|
||||||
@@ -34,7 +37,7 @@ export async function seed(knex: Knex): Promise<void> {
|
|||||||
])
|
])
|
||||||
.returning("*");
|
.returning("*");
|
||||||
|
|
||||||
const encKeys = await generateUserSrpKeys(seedData1.password);
|
const encKeys = await generateUserSrpKeys(seedData1.email, seedData1.password);
|
||||||
// password: testInfisical@1
|
// password: testInfisical@1
|
||||||
await knex(TableName.UserEncryptionKey).insert([
|
await knex(TableName.UserEncryptionKey).insert([
|
||||||
{
|
{
|
||||||
@@ -64,4 +67,9 @@ export async function seed(knex: Knex): Promise<void> {
|
|||||||
refreshVersion: 1,
|
refreshVersion: 1,
|
||||||
lastUsed: new Date()
|
lastUsed: new Date()
|
||||||
});
|
});
|
||||||
|
|
||||||
|
seedData1.encryptionKeys = {
|
||||||
|
publicKey: encKeys.publicKey,
|
||||||
|
privateKey: encKeys.plainPrivateKey
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,7 +2,9 @@ import crypto from "node:crypto";
|
|||||||
|
|
||||||
import { Knex } from "knex";
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
import { getConfig, initEnvConfig } from "@app/lib/config/env";
|
||||||
|
import { createSecretBlindIndex, encryptAsymmetric, encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
||||||
|
import { initLogger } from "@app/lib/logger";
|
||||||
|
|
||||||
import { OrgMembershipRole, SecretEncryptionAlgo, SecretKeyEncoding, TableName } from "../schemas";
|
import { OrgMembershipRole, SecretEncryptionAlgo, SecretKeyEncoding, TableName } from "../schemas";
|
||||||
import { buildUserProjectKey, getUserPrivateKey, seedData1 } from "../seed-data";
|
import { buildUserProjectKey, getUserPrivateKey, seedData1 } from "../seed-data";
|
||||||
@@ -14,6 +16,8 @@ export const DEFAULT_PROJECT_ENVS = [
|
|||||||
];
|
];
|
||||||
|
|
||||||
export async function seed(knex: Knex): Promise<void> {
|
export async function seed(knex: Knex): Promise<void> {
|
||||||
|
initEnvConfig(await initLogger());
|
||||||
|
const appCfg = getConfig();
|
||||||
// Deletes ALL existing entries
|
// Deletes ALL existing entries
|
||||||
await knex(TableName.Project).del();
|
await knex(TableName.Project).del();
|
||||||
await knex(TableName.Environment).del();
|
await knex(TableName.Environment).del();
|
||||||
@@ -24,12 +28,40 @@ export async function seed(knex: Knex): Promise<void> {
|
|||||||
name: seedData1.project.name,
|
name: seedData1.project.name,
|
||||||
orgId: seedData1.organization.id,
|
orgId: seedData1.organization.id,
|
||||||
slug: "first-project",
|
slug: "first-project",
|
||||||
// eslint-disable-next-line
|
// @ts-expect-error exluded type id needs to be inserted here to keep it testable
|
||||||
// @ts-ignore
|
id: seedData1.project.id,
|
||||||
id: seedData1.project.id
|
version: "v1"
|
||||||
})
|
})
|
||||||
.returning("*");
|
.returning("*");
|
||||||
|
|
||||||
|
const blindIndex = createSecretBlindIndex(appCfg.ROOT_ENCRYPTION_KEY, appCfg.ENCRYPTION_KEY);
|
||||||
|
|
||||||
|
await knex(TableName.SecretBlindIndex).insert({
|
||||||
|
projectId: project.id,
|
||||||
|
algorithm: blindIndex.algorithm,
|
||||||
|
keyEncoding: blindIndex.keyEncoding,
|
||||||
|
saltIV: blindIndex.iv,
|
||||||
|
encryptedSaltCipherText: blindIndex.ciphertext,
|
||||||
|
saltTag: blindIndex.tag
|
||||||
|
});
|
||||||
|
|
||||||
|
const randomBytes = crypto.randomBytes(16).toString("hex"); // Project key
|
||||||
|
// const encKeys = await generateUserSrpKeys(seedData1.email, seedData1.password); // User keys
|
||||||
|
|
||||||
|
const { ciphertext: encryptedProjectKey, nonce: encryptedProjectKeyIv } = encryptAsymmetric(
|
||||||
|
randomBytes,
|
||||||
|
seedData1.encryptionKeys.publicKey,
|
||||||
|
seedData1.encryptionKeys.privateKey
|
||||||
|
);
|
||||||
|
|
||||||
|
await knex(TableName.ProjectKeys).insert({
|
||||||
|
projectId: project.id,
|
||||||
|
senderId: seedData1.id,
|
||||||
|
receiverId: seedData1.id,
|
||||||
|
encryptedKey: encryptedProjectKey,
|
||||||
|
nonce: encryptedProjectKeyIv
|
||||||
|
});
|
||||||
|
|
||||||
await knex(TableName.ProjectMembership).insert({
|
await knex(TableName.ProjectMembership).insert({
|
||||||
projectId: project.id,
|
projectId: project.id,
|
||||||
role: OrgMembershipRole.Admin,
|
role: OrgMembershipRole.Admin,
|
||||||
|
|||||||
Reference in New Issue
Block a user