fix: error -> BadRequestError

This commit is contained in:
Piyush Gupta
2025-12-04 02:21:32 +05:30
parent 313fc3f761
commit fef8d53428
2 changed files with 23 additions and 17 deletions
@@ -3,6 +3,7 @@ import { AssumeRoleCommand, STSClient } from "@aws-sdk/client-sts";
import { CustomAWSHasher } from "@app/lib/aws/hashing"; import { CustomAWSHasher } from "@app/lib/aws/hashing";
import { crypto } from "@app/lib/crypto/cryptography"; import { crypto } from "@app/lib/crypto/cryptography";
import { BadRequestError } from "@app/lib/errors";
import { ExternalKmsAwsSchema, KmsAwsCredentialType, TExternalKmsAwsSchema, TExternalKmsProviderFns } from "./model"; import { ExternalKmsAwsSchema, KmsAwsCredentialType, TExternalKmsAwsSchema, TExternalKmsProviderFns } from "./model";
@@ -22,7 +23,7 @@ const getAwsKmsClient = async (providerInputs: TExternalKmsAwsSchema) => {
}); });
const response = await stsClient.send(command); const response = await stsClient.send(command);
if (!response.Credentials?.AccessKeyId || !response.Credentials?.SecretAccessKey) if (!response.Credentials?.AccessKeyId || !response.Credentials?.SecretAccessKey)
throw new Error("Failed to assume role"); throw new BadRequestError({ message: "Failed to assume role" });
const kmsClient = new KMSClient({ const kmsClient = new KMSClient({
region: providerInputs.awsRegion, region: providerInputs.awsRegion,
@@ -67,7 +68,7 @@ export const AwsKmsProviderFactory = async ({ inputs }: AwsKmsProviderArgs): Pro
const command = new CreateKeyCommand({ Tags: [{ TagKey: "author", TagValue: "infisical" }] }); const command = new CreateKeyCommand({ Tags: [{ TagKey: "author", TagValue: "infisical" }] });
const kmsKey = await awsClient.send(command); const kmsKey = await awsClient.send(command);
if (!kmsKey.KeyMetadata?.KeyId) throw new Error("Failed to generate kms key"); if (!kmsKey.KeyMetadata?.KeyId) throw new BadRequestError({ message: "Failed to generate kms key" });
const updatedProviderInputs = await ExternalKmsAwsSchema.parseAsync({ const updatedProviderInputs = await ExternalKmsAwsSchema.parseAsync({
...providerInputs, ...providerInputs,
+20 -15
View File
@@ -253,7 +253,7 @@ export const kmsServiceFactory = ({
} }
if (!org.kmsDefaultKeyId) { if (!org.kmsDefaultKeyId) {
throw new Error("Invalid organization KMS"); throw new BadRequestError({ message: "Invalid organization KMS" });
} }
return org.kmsDefaultKeyId; return org.kmsDefaultKeyId;
@@ -292,7 +292,7 @@ export const kmsServiceFactory = ({
let externalKms: TExternalKmsProviderFns; let externalKms: TExternalKmsProviderFns;
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) { if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
throw new Error("Invalid organization KMS"); throw new BadRequestError({ message: "Invalid organization KMS" });
} }
// The idea is external kms connection info is encrypted by an org default KMS // The idea is external kms connection info is encrypted by an org default KMS
@@ -338,7 +338,7 @@ export const kmsServiceFactory = ({
break; break;
} }
default: default:
throw new Error("Invalid KMS provider."); throw new BadRequestError({ message: "Invalid KMS provider." });
} }
return async ({ cipherTextBlob }: Pick<TDecryptWithKmsDTO, "cipherTextBlob">) => { return async ({ cipherTextBlob }: Pick<TDecryptWithKmsDTO, "cipherTextBlob">) => {
@@ -509,7 +509,7 @@ export const kmsServiceFactory = ({
if (kmsDoc.externalKms) { if (kmsDoc.externalKms) {
let externalKms: TExternalKmsProviderFns; let externalKms: TExternalKmsProviderFns;
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) { if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
throw new Error("Invalid organization KMS"); throw new BadRequestError({ message: "Invalid organization KMS" });
} }
const orgKmsDecryptor = await decryptWithKmsKey({ const orgKmsDecryptor = await decryptWithKmsKey({
@@ -550,7 +550,7 @@ export const kmsServiceFactory = ({
break; break;
} }
default: default:
throw new Error("Invalid KMS provider."); throw new BadRequestError({ message: "Invalid KMS provider." });
} }
return async ({ plainText }: Pick<TEncryptWithKmsDTO, "plainText">) => { return async ({ plainText }: Pick<TEncryptWithKmsDTO, "plainText">) => {
@@ -651,7 +651,7 @@ export const kmsServiceFactory = ({
} }
if (!org.kmsEncryptedDataKey) { if (!org.kmsEncryptedDataKey) {
throw new Error("Invalid organization KMS"); throw new BadRequestError({ message: "Invalid organization KMS" });
} }
const kmsDecryptor = await decryptWithKmsKey({ const kmsDecryptor = await decryptWithKmsKey({
@@ -723,7 +723,7 @@ export const kmsServiceFactory = ({
} }
if (!project.kmsSecretManagerKeyId) { if (!project.kmsSecretManagerKeyId) {
throw new Error("Missing project KMS key ID"); throw new BadRequestError({ message: "Missing project KMS key ID" });
} }
return project.kmsSecretManagerKeyId; return project.kmsSecretManagerKeyId;
@@ -832,9 +832,10 @@ export const kmsServiceFactory = ({
const isBase64 = !envConfig.ENCRYPTION_KEY; const isBase64 = !envConfig.ENCRYPTION_KEY;
if (!encryptionKey) if (!encryptionKey)
throw new Error( throw new BadRequestError({
"Root encryption key not found for KMS service. Did you set the ENCRYPTION_KEY or ROOT_ENCRYPTION_KEY environment variables?" message:
); "Root encryption key not found for KMS service. Did you set the ENCRYPTION_KEY or ROOT_ENCRYPTION_KEY environment variables?"
});
const encryptionKeyBuffer = Buffer.from(encryptionKey, isBase64 ? "base64" : "utf8"); const encryptionKeyBuffer = Buffer.from(encryptionKey, isBase64 ? "base64" : "utf8");
@@ -846,7 +847,9 @@ export const kmsServiceFactory = ({
if (kmsRootConfig.encryptionStrategy === RootKeyEncryptionStrategy.HSM) { if (kmsRootConfig.encryptionStrategy === RootKeyEncryptionStrategy.HSM) {
const hsmIsActive = await hsmService.isActive(); const hsmIsActive = await hsmService.isActive();
if (!hsmIsActive) { if (!hsmIsActive) {
throw new Error("Unable to decrypt root KMS key. HSM service is inactive. Did you configure the HSM?"); throw new BadRequestError({
message: "Unable to decrypt root KMS key. HSM service is inactive. Did you configure the HSM?"
});
} }
const decryptedKey = await hsmService.decrypt(kmsRootConfig.encryptedRootKey); const decryptedKey = await hsmService.decrypt(kmsRootConfig.encryptedRootKey);
@@ -861,14 +864,16 @@ export const kmsServiceFactory = ({
return cipher.decrypt(kmsRootConfig.encryptedRootKey, encryptionKeyBuffer); return cipher.decrypt(kmsRootConfig.encryptedRootKey, encryptionKeyBuffer);
} }
throw new Error(`Invalid root key encryption strategy: ${kmsRootConfig.encryptionStrategy}`); throw new BadRequestError({ message: `Invalid root key encryption strategy: ${kmsRootConfig.encryptionStrategy}` });
}; };
const $encryptRootKey = async (plainKeyBuffer: Buffer, strategy: RootKeyEncryptionStrategy) => { const $encryptRootKey = async (plainKeyBuffer: Buffer, strategy: RootKeyEncryptionStrategy) => {
if (strategy === RootKeyEncryptionStrategy.HSM) { if (strategy === RootKeyEncryptionStrategy.HSM) {
const hsmIsActive = await hsmService.isActive(); const hsmIsActive = await hsmService.isActive();
if (!hsmIsActive) { if (!hsmIsActive) {
throw new Error("Unable to encrypt root KMS key. HSM service is inactive. Did you configure the HSM?"); throw new BadRequestError({
message: "Unable to encrypt root KMS key. HSM service is inactive. Did you configure the HSM?"
});
} }
const encrypted = await hsmService.encrypt(plainKeyBuffer); const encrypted = await hsmService.encrypt(plainKeyBuffer);
return encrypted; return encrypted;
@@ -882,7 +887,7 @@ export const kmsServiceFactory = ({
} }
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions // eslint-disable-next-line @typescript-eslint/restrict-template-expressions
throw new Error(`Invalid root key encryption strategy: ${strategy}`); throw new BadRequestError({ message: `Invalid root key encryption strategy: ${strategy}` });
}; };
// by keeping the decrypted data key in inner scope // by keeping the decrypted data key in inner scope
@@ -1130,7 +1135,7 @@ export const kmsServiceFactory = ({
if (!encryptedRootKey) { if (!encryptedRootKey) {
logger.error("KMS: Failed to re-encrypt ROOT Key with selected strategy"); logger.error("KMS: Failed to re-encrypt ROOT Key with selected strategy");
throw new Error("Failed to re-encrypt ROOT Key with selected strategy"); throw new BadRequestError({ message: "Failed to re-encrypt ROOT Key with selected strategy" });
} }
await kmsRootConfigDAL.updateById(KMS_ROOT_CONFIG_UUID, { await kmsRootConfigDAL.updateById(KMS_ROOT_CONFIG_UUID, {