mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
misc: finalized error codes for oidc login
This commit is contained in:
@@ -18,7 +18,7 @@ import {
|
|||||||
infisicalSymmetricDecrypt,
|
infisicalSymmetricDecrypt,
|
||||||
infisicalSymmetricEncypt
|
infisicalSymmetricEncypt
|
||||||
} from "@app/lib/crypto/encryption";
|
} from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError, ForbiddenRequestError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, ForbiddenRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
|
||||||
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
||||||
|
|
||||||
import { ActorType, AuthTokenType } from "../auth/auth-type";
|
import { ActorType, AuthTokenType } from "../auth/auth-type";
|
||||||
@@ -68,12 +68,12 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
identityId: identityOidcAuth.identityId
|
identityId: identityOidcAuth.identityId
|
||||||
});
|
});
|
||||||
if (!identityMembershipOrg) {
|
if (!identityMembershipOrg) {
|
||||||
throw new BadRequestError({ message: "Failed to find identity" });
|
throw new NotFoundError({ message: "Failed to find identity in organization" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const orgBot = await orgBotDAL.findOne({ orgId: identityMembershipOrg.orgId });
|
const orgBot = await orgBotDAL.findOne({ orgId: identityMembershipOrg.orgId });
|
||||||
if (!orgBot) {
|
if (!orgBot) {
|
||||||
throw new BadRequestError({ message: "Org bot not found", name: "OrgBotNotFound" });
|
throw new NotFoundError({ message: "Org bot not found", name: "OrgBotNotFound" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const key = infisicalSymmetricDecrypt({
|
const key = infisicalSymmetricDecrypt({
|
||||||
@@ -106,7 +106,7 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
|
|
||||||
const decodedToken = jwt.decode(oidcJwt, { complete: true });
|
const decodedToken = jwt.decode(oidcJwt, { complete: true });
|
||||||
if (!decodedToken) {
|
if (!decodedToken) {
|
||||||
throw new BadRequestError({
|
throw new UnauthorizedError({
|
||||||
message: "Invalid JWT"
|
message: "Invalid JWT"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -119,13 +119,24 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
const { kid } = decodedToken.header;
|
const { kid } = decodedToken.header;
|
||||||
const oidcSigningKey = await client.getSigningKey(kid);
|
const oidcSigningKey = await client.getSigningKey(kid);
|
||||||
|
|
||||||
const tokenData = jwt.verify(oidcJwt, oidcSigningKey.getPublicKey(), {
|
let tokenData: Record<string, string>;
|
||||||
issuer: identityOidcAuth.boundIssuer
|
try {
|
||||||
}) as Record<string, string>;
|
tokenData = jwt.verify(oidcJwt, oidcSigningKey.getPublicKey(), {
|
||||||
|
issuer: identityOidcAuth.boundIssuer
|
||||||
|
}) as Record<string, string>;
|
||||||
|
} catch (error) {
|
||||||
|
if (error instanceof jwt.JsonWebTokenError) {
|
||||||
|
throw new UnauthorizedError({
|
||||||
|
message: `Access denied: ${error.message}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
throw error;
|
||||||
|
}
|
||||||
|
|
||||||
if (identityOidcAuth.boundSubject) {
|
if (identityOidcAuth.boundSubject) {
|
||||||
if (!doesFieldValueMatchOidcPolicy(tokenData.sub, identityOidcAuth.boundSubject)) {
|
if (!doesFieldValueMatchOidcPolicy(tokenData.sub, identityOidcAuth.boundSubject)) {
|
||||||
throw new ForbiddenRequestError({
|
throw new UnauthorizedError({
|
||||||
message: "Access denied: OIDC subject not allowed."
|
message: "Access denied: OIDC subject not allowed."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -137,7 +148,7 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
.split(", ")
|
.split(", ")
|
||||||
.some((policyValue) => doesFieldValueMatchOidcPolicy(tokenData.aud, policyValue))
|
.some((policyValue) => doesFieldValueMatchOidcPolicy(tokenData.aud, policyValue))
|
||||||
) {
|
) {
|
||||||
throw new ForbiddenRequestError({
|
throw new UnauthorizedError({
|
||||||
message: "Access denied: OIDC audience not allowed."
|
message: "Access denied: OIDC audience not allowed."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -150,7 +161,7 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
if (
|
if (
|
||||||
!claimValue.split(", ").some((claimEntry) => doesFieldValueMatchOidcPolicy(tokenData[claimKey], claimEntry))
|
!claimValue.split(", ").some((claimEntry) => doesFieldValueMatchOidcPolicy(tokenData[claimKey], claimEntry))
|
||||||
) {
|
) {
|
||||||
throw new ForbiddenRequestError({
|
throw new UnauthorizedError({
|
||||||
message: "Access denied: OIDC claim not allowed."
|
message: "Access denied: OIDC claim not allowed."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user