Files
documenso/packages/lib/server-only/cert/cert-status.ts
T
Catalin Pit cbb1cf7bef fix: default unset signing transport to local (#3309)
`/api/health` and `/api/certificate-status` reported the cert as
available when `NEXT_PRIVATE_SIGNING_TRANSPORT` was unset, even though
sealing defaults to the local P12 and fails if it is missing,
unreadable, or expired.
2026-09-04 08:17:42 +10:00

38 lines
1.1 KiB
TypeScript

import { X509Certificate } from 'node:crypto';
import { createLocalSigner } from '@documenso/signing/transports/local';
import { NEXT_PRIVATE_SIGNING_TRANSPORT } from '../../constants/app';
/**
* Whether the local P12 opens with the configured passphrase and is in date.
* Skips AIA so this stays offline. gcloud-hsm and csc always report available.
*/
export const getCertificateStatus = async () => {
const transport = NEXT_PRIVATE_SIGNING_TRANSPORT();
// Cannot inspect a remote HSM or CSC provider from this process.
if (transport === 'gcloud-hsm' || transport === 'csc') {
return { isAvailable: true };
}
// Anything else (typo, leftover `http`) would throw at seal time.
if (transport !== 'local') {
return { isAvailable: false };
}
try {
const signer = await createLocalSigner({ buildChain: false });
const certificate = new X509Certificate(Buffer.from(signer.certificate));
const now = new Date();
const isWithinValidityPeriod = new Date(certificate.validFrom) <= now && now <= new Date(certificate.validTo);
return { isAvailable: isWithinValidityPeriod };
} catch {
return { isAvailable: false };
}
};