mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 03:26:12 +00:00
add max ttl to renew and login api responses
This commit is contained in:
@@ -4,27 +4,27 @@ import jwt from "jsonwebtoken";
|
|||||||
import crypto from "crypto";
|
import crypto from "crypto";
|
||||||
import bcrypt from "bcrypt";
|
import bcrypt from "bcrypt";
|
||||||
import {
|
import {
|
||||||
IIdentity,
|
IIdentity,
|
||||||
IIdentityTrustedIp,
|
IIdentityTrustedIp,
|
||||||
IIdentityUniversalAuthClientSecret,
|
IIdentityUniversalAuthClientSecret,
|
||||||
Identity,
|
Identity,
|
||||||
IdentityAccessToken,
|
IdentityAccessToken,
|
||||||
IdentityAuthMethod,
|
IdentityAuthMethod,
|
||||||
IdentityMembershipOrg,
|
IdentityMembershipOrg,
|
||||||
IdentityUniversalAuth,
|
IdentityUniversalAuth,
|
||||||
IdentityUniversalAuthClientSecret,
|
IdentityUniversalAuthClientSecret,
|
||||||
} from "../../models";
|
} from "../../models";
|
||||||
import { createToken } from "../../helpers/auth";
|
import { createToken } from "../../helpers/auth";
|
||||||
import { AuthTokenType } from "../../variables";
|
import { AuthTokenType } from "../../variables";
|
||||||
import {
|
import {
|
||||||
BadRequestError,
|
BadRequestError,
|
||||||
ForbiddenRequestError,
|
ForbiddenRequestError,
|
||||||
ResourceNotFoundError,
|
ResourceNotFoundError,
|
||||||
UnauthorizedRequestError
|
UnauthorizedRequestError
|
||||||
} from "../../utils/errors";
|
} from "../../utils/errors";
|
||||||
import {
|
import {
|
||||||
getAuthSecret,
|
getAuthSecret,
|
||||||
getSaltRounds
|
getSaltRounds
|
||||||
} from "../../config";
|
} from "../../config";
|
||||||
import { ActorType, EventType, IRole } from "../../ee/models";
|
import { ActorType, EventType, IRole } from "../../ee/models";
|
||||||
import { validateRequest } from "../../helpers/validation";
|
import { validateRequest } from "../../helpers/validation";
|
||||||
@@ -33,11 +33,11 @@ import { checkIPAgainstBlocklist, extractIPDetails, isValidIpOrCidr } from "../.
|
|||||||
import { getUserAgentType } from "../../utils/posthog";
|
import { getUserAgentType } from "../../utils/posthog";
|
||||||
import { EEAuditLogService, EELicenseService } from "../../ee/services";
|
import { EEAuditLogService, EELicenseService } from "../../ee/services";
|
||||||
import {
|
import {
|
||||||
OrgPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
getAuthDataOrgPermissions,
|
getAuthDataOrgPermissions,
|
||||||
getOrgRolePermissions,
|
getOrgRolePermissions,
|
||||||
isAtLeastAsPrivilegedOrg
|
isAtLeastAsPrivilegedOrg
|
||||||
} from "../../ee/services/RoleService";
|
} from "../../ee/services/RoleService";
|
||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
|
||||||
@@ -86,9 +86,6 @@ export const renewAccessToken = async (req: Request, res: Response) => {
|
|||||||
createdAt: accessTokenCreatedAt
|
createdAt: accessTokenCreatedAt
|
||||||
} = identityAccessToken;
|
} = identityAccessToken;
|
||||||
|
|
||||||
if (accessTokenTTL === accessTokenMaxTTL) throw UnauthorizedRequestError({
|
|
||||||
message: "Failed to renew non-renewable access token"
|
|
||||||
});
|
|
||||||
|
|
||||||
// ttl check
|
// ttl check
|
||||||
if (accessTokenTTL > 0) {
|
if (accessTokenTTL > 0) {
|
||||||
@@ -141,6 +138,7 @@ export const renewAccessToken = async (req: Request, res: Response) => {
|
|||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
accessToken,
|
accessToken,
|
||||||
expiresIn: identityAccessToken.accessTokenTTL,
|
expiresIn: identityAccessToken.accessTokenTTL,
|
||||||
|
accessTokenMaxTTL: identityAccessToken.accessTokenMaxTTL,
|
||||||
tokenType: "Bearer"
|
tokenType: "Bearer"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -237,16 +235,16 @@ export const loginIdentityUniversalAuth = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
// increment usage count by 1
|
// increment usage count by 1
|
||||||
await IdentityUniversalAuthClientSecret
|
await IdentityUniversalAuthClientSecret
|
||||||
.findByIdAndUpdate(
|
.findByIdAndUpdate(
|
||||||
validatedClientSecretDatum._id,
|
validatedClientSecretDatum._id,
|
||||||
{
|
{
|
||||||
clientSecretLastUsedAt: new Date(),
|
clientSecretLastUsedAt: new Date(),
|
||||||
$inc: { clientSecretNumUses: 1 }
|
$inc: { clientSecretNumUses: 1 }
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
new: true
|
new: true
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
const identityAccessToken = await new IdentityAccessToken({
|
const identityAccessToken = await new IdentityAccessToken({
|
||||||
identity: identityUniversalAuth.identity,
|
identity: identityUniversalAuth.identity,
|
||||||
@@ -300,7 +298,8 @@ export const loginIdentityUniversalAuth = async (req: Request, res: Response) =>
|
|||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
accessToken,
|
accessToken,
|
||||||
expiresIn: identityUniversalAuth.accessTokenTTL,
|
expiresIn: identityUniversalAuth.accessTokenTTL,
|
||||||
tokenType: "Bearer"
|
accessTokenMaxTTL: identityUniversalAuth.accessTokenMaxTTL,
|
||||||
|
tokenType: "Bearer",
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user