Merge pull request #4502 from Infisical/improve-lockout

feat(ua-login): improve lock error message & disable lock when lockout is disabled
This commit is contained in:
x032205
2025-09-08 20:42:10 -04:00
committed by GitHub

View File

@@ -84,18 +84,20 @@ export const identityUaServiceFactory = ({
const LOCKOUT_KEY = `lockout:identity:${identityUa.identityId}:${IdentityAuthMethod.UNIVERSAL_AUTH}:${clientId}`; const LOCKOUT_KEY = `lockout:identity:${identityUa.identityId}:${IdentityAuthMethod.UNIVERSAL_AUTH}:${clientId}`;
let lock: Awaited<ReturnType<typeof keyStore.acquireLock>>; let lock: Awaited<ReturnType<typeof keyStore.acquireLock>> | undefined;
try { if (identityUa.lockoutEnabled) {
lock = await keyStore.acquireLock([KeyStorePrefixes.IdentityLockoutLock(LOCKOUT_KEY)], 500, { try {
retryCount: 3, lock = await keyStore.acquireLock([KeyStorePrefixes.IdentityLockoutLock(LOCKOUT_KEY)], 500, {
retryDelay: 300, retryCount: 3,
retryJitter: 100 retryDelay: 300,
}); retryJitter: 100
} catch (e) { });
logger.info( } catch (e) {
`identity login failed to acquire lock [identityId=${identityUa.identityId}] [authMethod=${IdentityAuthMethod.UNIVERSAL_AUTH}]` logger.info(
); `identity login failed to acquire lock [identityId=${identityUa.identityId}] [authMethod=${IdentityAuthMethod.UNIVERSAL_AUTH}]`
throw new RateLimitError({ message: "Rate limit exceeded" }); );
throw new RateLimitError({ message: "Failed to acquire lock: rate limit exceeded" });
}
} }
try { try {
@@ -257,7 +259,7 @@ export const identityUaServiceFactory = ({
...accessTokenTTLParams ...accessTokenTTLParams
}; };
} finally { } finally {
await lock.release(); if (lock) await lock.release();
} }
}; };