mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 23:29:05 +00:00
misc: added max keys to try limit
This commit is contained in:
@@ -23,6 +23,7 @@ import {
|
|||||||
UnauthorizedError
|
UnauthorizedError
|
||||||
} from "@app/lib/errors";
|
} from "@app/lib/errors";
|
||||||
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
import { AuthAttemptAuthMethod, AuthAttemptAuthResult, authAttemptCounter } from "@app/lib/telemetry/metrics";
|
import { AuthAttemptAuthMethod, AuthAttemptAuthResult, authAttemptCounter } from "@app/lib/telemetry/metrics";
|
||||||
import { getValueByDot } from "@app/lib/template/dot-access";
|
import { getValueByDot } from "@app/lib/template/dot-access";
|
||||||
|
|
||||||
@@ -145,6 +146,10 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
// If kid is not provided, try all available signing keys
|
// If kid is not provided, try all available signing keys
|
||||||
|
logger.warn(
|
||||||
|
`OIDC login without KID header [identityId=${identityOidcAuth.identityId}] [orgId=${org.id}] [ip=${requestContext.get("ip")}]`
|
||||||
|
);
|
||||||
|
|
||||||
let allSigningKeys;
|
let allSigningKeys;
|
||||||
try {
|
try {
|
||||||
allSigningKeys = await client.getSigningKeys();
|
allSigningKeys = await client.getSigningKeys();
|
||||||
@@ -160,6 +165,14 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Limit the number of keys to try to prevent abuse
|
||||||
|
const MAX_KEYS_TO_TRY = 10;
|
||||||
|
if (allSigningKeys.length > MAX_KEYS_TO_TRY) {
|
||||||
|
throw new UnauthorizedError({
|
||||||
|
message: `Access denied: OIDC provider has ${allSigningKeys.length} signing keys. Tokens must include 'kid' header when provider has more than ${MAX_KEYS_TO_TRY} keys.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
let lastError: Error | null = null;
|
let lastError: Error | null = null;
|
||||||
let verified = false;
|
let verified = false;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user