mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 16:27:40 +00:00
fix: error -> BadRequestError
This commit is contained in:
@@ -3,6 +3,7 @@ import { AssumeRoleCommand, STSClient } from "@aws-sdk/client-sts";
|
|||||||
|
|
||||||
import { CustomAWSHasher } from "@app/lib/aws/hashing";
|
import { CustomAWSHasher } from "@app/lib/aws/hashing";
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
|
||||||
import { ExternalKmsAwsSchema, KmsAwsCredentialType, TExternalKmsAwsSchema, TExternalKmsProviderFns } from "./model";
|
import { ExternalKmsAwsSchema, KmsAwsCredentialType, TExternalKmsAwsSchema, TExternalKmsProviderFns } from "./model";
|
||||||
|
|
||||||
@@ -22,7 +23,7 @@ const getAwsKmsClient = async (providerInputs: TExternalKmsAwsSchema) => {
|
|||||||
});
|
});
|
||||||
const response = await stsClient.send(command);
|
const response = await stsClient.send(command);
|
||||||
if (!response.Credentials?.AccessKeyId || !response.Credentials?.SecretAccessKey)
|
if (!response.Credentials?.AccessKeyId || !response.Credentials?.SecretAccessKey)
|
||||||
throw new Error("Failed to assume role");
|
throw new BadRequestError({ message: "Failed to assume role" });
|
||||||
|
|
||||||
const kmsClient = new KMSClient({
|
const kmsClient = new KMSClient({
|
||||||
region: providerInputs.awsRegion,
|
region: providerInputs.awsRegion,
|
||||||
@@ -67,7 +68,7 @@ export const AwsKmsProviderFactory = async ({ inputs }: AwsKmsProviderArgs): Pro
|
|||||||
const command = new CreateKeyCommand({ Tags: [{ TagKey: "author", TagValue: "infisical" }] });
|
const command = new CreateKeyCommand({ Tags: [{ TagKey: "author", TagValue: "infisical" }] });
|
||||||
const kmsKey = await awsClient.send(command);
|
const kmsKey = await awsClient.send(command);
|
||||||
|
|
||||||
if (!kmsKey.KeyMetadata?.KeyId) throw new Error("Failed to generate kms key");
|
if (!kmsKey.KeyMetadata?.KeyId) throw new BadRequestError({ message: "Failed to generate kms key" });
|
||||||
|
|
||||||
const updatedProviderInputs = await ExternalKmsAwsSchema.parseAsync({
|
const updatedProviderInputs = await ExternalKmsAwsSchema.parseAsync({
|
||||||
...providerInputs,
|
...providerInputs,
|
||||||
|
|||||||
@@ -253,7 +253,7 @@ export const kmsServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (!org.kmsDefaultKeyId) {
|
if (!org.kmsDefaultKeyId) {
|
||||||
throw new Error("Invalid organization KMS");
|
throw new BadRequestError({ message: "Invalid organization KMS" });
|
||||||
}
|
}
|
||||||
|
|
||||||
return org.kmsDefaultKeyId;
|
return org.kmsDefaultKeyId;
|
||||||
@@ -292,7 +292,7 @@ export const kmsServiceFactory = ({
|
|||||||
let externalKms: TExternalKmsProviderFns;
|
let externalKms: TExternalKmsProviderFns;
|
||||||
|
|
||||||
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
|
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
|
||||||
throw new Error("Invalid organization KMS");
|
throw new BadRequestError({ message: "Invalid organization KMS" });
|
||||||
}
|
}
|
||||||
|
|
||||||
// The idea is external kms connection info is encrypted by an org default KMS
|
// The idea is external kms connection info is encrypted by an org default KMS
|
||||||
@@ -338,7 +338,7 @@ export const kmsServiceFactory = ({
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
default:
|
default:
|
||||||
throw new Error("Invalid KMS provider.");
|
throw new BadRequestError({ message: "Invalid KMS provider." });
|
||||||
}
|
}
|
||||||
|
|
||||||
return async ({ cipherTextBlob }: Pick<TDecryptWithKmsDTO, "cipherTextBlob">) => {
|
return async ({ cipherTextBlob }: Pick<TDecryptWithKmsDTO, "cipherTextBlob">) => {
|
||||||
@@ -509,7 +509,7 @@ export const kmsServiceFactory = ({
|
|||||||
if (kmsDoc.externalKms) {
|
if (kmsDoc.externalKms) {
|
||||||
let externalKms: TExternalKmsProviderFns;
|
let externalKms: TExternalKmsProviderFns;
|
||||||
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
|
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
|
||||||
throw new Error("Invalid organization KMS");
|
throw new BadRequestError({ message: "Invalid organization KMS" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const orgKmsDecryptor = await decryptWithKmsKey({
|
const orgKmsDecryptor = await decryptWithKmsKey({
|
||||||
@@ -550,7 +550,7 @@ export const kmsServiceFactory = ({
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
default:
|
default:
|
||||||
throw new Error("Invalid KMS provider.");
|
throw new BadRequestError({ message: "Invalid KMS provider." });
|
||||||
}
|
}
|
||||||
|
|
||||||
return async ({ plainText }: Pick<TEncryptWithKmsDTO, "plainText">) => {
|
return async ({ plainText }: Pick<TEncryptWithKmsDTO, "plainText">) => {
|
||||||
@@ -651,7 +651,7 @@ export const kmsServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (!org.kmsEncryptedDataKey) {
|
if (!org.kmsEncryptedDataKey) {
|
||||||
throw new Error("Invalid organization KMS");
|
throw new BadRequestError({ message: "Invalid organization KMS" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const kmsDecryptor = await decryptWithKmsKey({
|
const kmsDecryptor = await decryptWithKmsKey({
|
||||||
@@ -723,7 +723,7 @@ export const kmsServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (!project.kmsSecretManagerKeyId) {
|
if (!project.kmsSecretManagerKeyId) {
|
||||||
throw new Error("Missing project KMS key ID");
|
throw new BadRequestError({ message: "Missing project KMS key ID" });
|
||||||
}
|
}
|
||||||
|
|
||||||
return project.kmsSecretManagerKeyId;
|
return project.kmsSecretManagerKeyId;
|
||||||
@@ -832,9 +832,10 @@ export const kmsServiceFactory = ({
|
|||||||
|
|
||||||
const isBase64 = !envConfig.ENCRYPTION_KEY;
|
const isBase64 = !envConfig.ENCRYPTION_KEY;
|
||||||
if (!encryptionKey)
|
if (!encryptionKey)
|
||||||
throw new Error(
|
throw new BadRequestError({
|
||||||
"Root encryption key not found for KMS service. Did you set the ENCRYPTION_KEY or ROOT_ENCRYPTION_KEY environment variables?"
|
message:
|
||||||
);
|
"Root encryption key not found for KMS service. Did you set the ENCRYPTION_KEY or ROOT_ENCRYPTION_KEY environment variables?"
|
||||||
|
});
|
||||||
|
|
||||||
const encryptionKeyBuffer = Buffer.from(encryptionKey, isBase64 ? "base64" : "utf8");
|
const encryptionKeyBuffer = Buffer.from(encryptionKey, isBase64 ? "base64" : "utf8");
|
||||||
|
|
||||||
@@ -846,7 +847,9 @@ export const kmsServiceFactory = ({
|
|||||||
if (kmsRootConfig.encryptionStrategy === RootKeyEncryptionStrategy.HSM) {
|
if (kmsRootConfig.encryptionStrategy === RootKeyEncryptionStrategy.HSM) {
|
||||||
const hsmIsActive = await hsmService.isActive();
|
const hsmIsActive = await hsmService.isActive();
|
||||||
if (!hsmIsActive) {
|
if (!hsmIsActive) {
|
||||||
throw new Error("Unable to decrypt root KMS key. HSM service is inactive. Did you configure the HSM?");
|
throw new BadRequestError({
|
||||||
|
message: "Unable to decrypt root KMS key. HSM service is inactive. Did you configure the HSM?"
|
||||||
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const decryptedKey = await hsmService.decrypt(kmsRootConfig.encryptedRootKey);
|
const decryptedKey = await hsmService.decrypt(kmsRootConfig.encryptedRootKey);
|
||||||
@@ -861,14 +864,16 @@ export const kmsServiceFactory = ({
|
|||||||
return cipher.decrypt(kmsRootConfig.encryptedRootKey, encryptionKeyBuffer);
|
return cipher.decrypt(kmsRootConfig.encryptedRootKey, encryptionKeyBuffer);
|
||||||
}
|
}
|
||||||
|
|
||||||
throw new Error(`Invalid root key encryption strategy: ${kmsRootConfig.encryptionStrategy}`);
|
throw new BadRequestError({ message: `Invalid root key encryption strategy: ${kmsRootConfig.encryptionStrategy}` });
|
||||||
};
|
};
|
||||||
|
|
||||||
const $encryptRootKey = async (plainKeyBuffer: Buffer, strategy: RootKeyEncryptionStrategy) => {
|
const $encryptRootKey = async (plainKeyBuffer: Buffer, strategy: RootKeyEncryptionStrategy) => {
|
||||||
if (strategy === RootKeyEncryptionStrategy.HSM) {
|
if (strategy === RootKeyEncryptionStrategy.HSM) {
|
||||||
const hsmIsActive = await hsmService.isActive();
|
const hsmIsActive = await hsmService.isActive();
|
||||||
if (!hsmIsActive) {
|
if (!hsmIsActive) {
|
||||||
throw new Error("Unable to encrypt root KMS key. HSM service is inactive. Did you configure the HSM?");
|
throw new BadRequestError({
|
||||||
|
message: "Unable to encrypt root KMS key. HSM service is inactive. Did you configure the HSM?"
|
||||||
|
});
|
||||||
}
|
}
|
||||||
const encrypted = await hsmService.encrypt(plainKeyBuffer);
|
const encrypted = await hsmService.encrypt(plainKeyBuffer);
|
||||||
return encrypted;
|
return encrypted;
|
||||||
@@ -882,7 +887,7 @@ export const kmsServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions
|
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions
|
||||||
throw new Error(`Invalid root key encryption strategy: ${strategy}`);
|
throw new BadRequestError({ message: `Invalid root key encryption strategy: ${strategy}` });
|
||||||
};
|
};
|
||||||
|
|
||||||
// by keeping the decrypted data key in inner scope
|
// by keeping the decrypted data key in inner scope
|
||||||
@@ -1130,7 +1135,7 @@ export const kmsServiceFactory = ({
|
|||||||
|
|
||||||
if (!encryptedRootKey) {
|
if (!encryptedRootKey) {
|
||||||
logger.error("KMS: Failed to re-encrypt ROOT Key with selected strategy");
|
logger.error("KMS: Failed to re-encrypt ROOT Key with selected strategy");
|
||||||
throw new Error("Failed to re-encrypt ROOT Key with selected strategy");
|
throw new BadRequestError({ message: "Failed to re-encrypt ROOT Key with selected strategy" });
|
||||||
}
|
}
|
||||||
|
|
||||||
await kmsRootConfigDAL.updateById(KMS_ROOT_CONFIG_UUID, {
|
await kmsRootConfigDAL.updateById(KMS_ROOT_CONFIG_UUID, {
|
||||||
|
|||||||
Reference in New Issue
Block a user