mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 10:28:50 +00:00
requested changes
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
/* eslint-disable @typescript-eslint/ban-ts-comment */
|
||||
import { Knex } from "knex";
|
||||
|
||||
import { TableName } from "../schemas";
|
||||
|
||||
export async function up(knex: Knex): Promise<void> {
|
||||
if (await knex.schema.hasTable(TableName.SecretSharing)) {
|
||||
await knex.schema.alterTable(TableName.SecretSharing, (t) => {
|
||||
// Add a new column
|
||||
t.string("new_id", 36).nullable();
|
||||
});
|
||||
|
||||
// Copy data from old column to new column
|
||||
await knex(TableName.SecretSharing).update({
|
||||
// @ts-ignore
|
||||
new_id: knex.raw("id::text")
|
||||
});
|
||||
|
||||
await knex.schema.alterTable(TableName.SecretSharing, (t) => {
|
||||
// Make the new column not nullable
|
||||
t.string("new_id", 36).notNullable().alter();
|
||||
|
||||
// Drop the old primary key
|
||||
t.dropPrimary();
|
||||
|
||||
// Drop the old id column
|
||||
t.dropColumn("id");
|
||||
|
||||
// Rename the new column to 'id'
|
||||
t.renameColumn("new_id", "id");
|
||||
|
||||
// Set the new column as primary key
|
||||
t.primary(["id"]);
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
export async function down(knex: Knex): Promise<void> {
|
||||
if (await knex.schema.hasTable(TableName.SecretSharing)) {
|
||||
await knex.schema.alterTable(TableName.SecretSharing, (t) => {
|
||||
// Add a new UUID column
|
||||
t.uuid("new_id").nullable();
|
||||
});
|
||||
|
||||
// Copy data from string id to UUID, ensuring valid UUID format
|
||||
await knex(TableName.SecretSharing).update({
|
||||
// @ts-ignore
|
||||
new_id: knex.raw("id::uuid")
|
||||
});
|
||||
|
||||
await knex.schema.alterTable(TableName.SecretSharing, (t) => {
|
||||
// Make the new column not nullable
|
||||
t.uuid("new_id").notNullable().alter();
|
||||
|
||||
// Drop the old primary key
|
||||
t.dropPrimary();
|
||||
|
||||
// Drop the old id column
|
||||
t.dropColumn("id");
|
||||
|
||||
// Rename the new column to 'id'
|
||||
t.renameColumn("new_id", "id");
|
||||
|
||||
// Set the new column as primary key
|
||||
t.primary(["id"]);
|
||||
});
|
||||
}
|
||||
}
|
||||
@@ -10,7 +10,6 @@ import { zodBuffer } from "@app/lib/zod";
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const SecretSharingSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
encryptedValue: z.string().nullable().optional(),
|
||||
iv: z.string().nullable().optional(),
|
||||
tag: z.string().nullable().optional(),
|
||||
@@ -25,7 +24,8 @@ export const SecretSharingSchema = z.object({
|
||||
name: z.string().nullable().optional(),
|
||||
lastViewedAt: z.date().nullable().optional(),
|
||||
password: z.string().nullable().optional(),
|
||||
encryptedSecret: zodBuffer.nullable().optional()
|
||||
encryptedSecret: zodBuffer.nullable().optional(),
|
||||
id: z.string()
|
||||
});
|
||||
|
||||
export type TSecretSharing = z.infer<typeof SecretSharingSchema>;
|
||||
|
||||
@@ -55,7 +55,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
id: z.string().uuid()
|
||||
id: z.string()
|
||||
}),
|
||||
body: z.object({
|
||||
hashedHex: z.string().min(1),
|
||||
@@ -107,8 +107,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
id: z.string().uuid(),
|
||||
hashedHex: z.string()
|
||||
id: z.string()
|
||||
})
|
||||
}
|
||||
},
|
||||
@@ -117,7 +116,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
...req.body,
|
||||
accessType: SecretSharingAccessType.Anyone
|
||||
});
|
||||
return { id: sharedSecret.id, hashedHex: sharedSecret.hashedHex };
|
||||
return { id: sharedSecret.id };
|
||||
}
|
||||
});
|
||||
|
||||
@@ -138,8 +137,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
id: z.string().uuid(),
|
||||
hashedHex: z.string()
|
||||
id: z.string()
|
||||
})
|
||||
}
|
||||
},
|
||||
@@ -153,7 +151,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
actorOrgId: req.permission.orgId,
|
||||
...req.body
|
||||
});
|
||||
return { id: sharedSecret.id, hashedHex: sharedSecret.hashedHex };
|
||||
return { id: sharedSecret.id };
|
||||
}
|
||||
});
|
||||
|
||||
@@ -165,7 +163,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
sharedSecretId: z.string().uuid()
|
||||
sharedSecretId: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: SecretSharingSchema
|
||||
|
||||
@@ -82,11 +82,21 @@ export const secretSharingDALFactory = (db: TDbClient) => {
|
||||
}
|
||||
};
|
||||
|
||||
const create = async (data: Omit<TSecretSharing, "createdAt" | "updatedAt">, tx?: Knex) => {
|
||||
try {
|
||||
const [res] = await (tx || db)(TableName.SecretSharing).insert(data).returning("*");
|
||||
return res;
|
||||
} catch (error) {
|
||||
throw new DatabaseError({ error, name: "Create Shared Secret" });
|
||||
}
|
||||
};
|
||||
|
||||
return {
|
||||
...sharedSecretOrm,
|
||||
countAllUserOrgSharedSecrets,
|
||||
pruneExpiredSharedSecrets,
|
||||
softDeleteById,
|
||||
findActiveSharedSecrets
|
||||
findActiveSharedSecrets,
|
||||
create
|
||||
};
|
||||
};
|
||||
|
||||
@@ -68,10 +68,15 @@ export const secretSharingServiceFactory = ({
|
||||
const encryptWithRoot = kmsService.encryptWithRootKey();
|
||||
|
||||
const encryptedSecret = encryptWithRoot(Buffer.from(secretValue));
|
||||
const hashedHex = crypto.createHash("sha256").update(secretValue).digest("hex").substring(0, 13);
|
||||
|
||||
// This will be 36 characters long, due to encoding it to base64.
|
||||
const id = crypto.randomBytes(27).toString("base64url");
|
||||
|
||||
const hashedHex = crypto.createHash("sha256").update(id).digest("base64").substring(0, 13);
|
||||
const hashedPassword = password ? await bcrypt.hash(password, 10) : null;
|
||||
|
||||
const newSharedSecret = await secretSharingDAL.create({
|
||||
id,
|
||||
iv: null,
|
||||
tag: null,
|
||||
encryptedValue: null,
|
||||
@@ -86,7 +91,7 @@ export const secretSharingServiceFactory = ({
|
||||
accessType
|
||||
});
|
||||
|
||||
return { id: newSharedSecret.id, hashedHex: newSharedSecret.hashedHex };
|
||||
return { id: `${newSharedSecret.id}${hashedHex}` };
|
||||
};
|
||||
|
||||
const createPublicSharedSecret = async ({
|
||||
@@ -116,10 +121,12 @@ export const secretSharingServiceFactory = ({
|
||||
const encryptWithRoot = kmsService.encryptWithRootKey();
|
||||
const encryptedSecret = encryptWithRoot(Buffer.from(secretValue));
|
||||
|
||||
const hashedHex = crypto.createHash("sha256").update(secretValue).digest("hex").substring(0, 13);
|
||||
const id = crypto.randomBytes(27).toString("base64url");
|
||||
const hashedHex = crypto.createHash("sha256").update(id).digest("hex").substring(0, 13);
|
||||
const hashedPassword = password ? await bcrypt.hash(password, 10) : null;
|
||||
|
||||
const newSharedSecret = await secretSharingDAL.create({
|
||||
id,
|
||||
encryptedValue: null,
|
||||
iv: null,
|
||||
tag: null,
|
||||
@@ -132,7 +139,7 @@ export const secretSharingServiceFactory = ({
|
||||
accessType
|
||||
});
|
||||
|
||||
return { id: newSharedSecret.id, hashedHex: newSharedSecret.hashedHex };
|
||||
return { id: `${newSharedSecret.id}${hashedHex}` };
|
||||
};
|
||||
|
||||
const getSharedSecrets = async ({
|
||||
|
||||
Reference in New Issue
Block a user