mirror of
https://github.com/documenso/documenso.git
synced 2026-10-03 10:13:52 +10:00
`/api/health` and `/api/certificate-status` reported the cert as available when `NEXT_PRIVATE_SIGNING_TRANSPORT` was unset, even though sealing defaults to the local P12 and fails if it is missing, unreadable, or expired.
38 lines
1.1 KiB
TypeScript
38 lines
1.1 KiB
TypeScript
import { X509Certificate } from 'node:crypto';
|
|
|
|
import { createLocalSigner } from '@documenso/signing/transports/local';
|
|
|
|
import { NEXT_PRIVATE_SIGNING_TRANSPORT } from '../../constants/app';
|
|
|
|
/**
|
|
* Whether the local P12 opens with the configured passphrase and is in date.
|
|
* Skips AIA so this stays offline. gcloud-hsm and csc always report available.
|
|
*/
|
|
export const getCertificateStatus = async () => {
|
|
const transport = NEXT_PRIVATE_SIGNING_TRANSPORT();
|
|
|
|
// Cannot inspect a remote HSM or CSC provider from this process.
|
|
if (transport === 'gcloud-hsm' || transport === 'csc') {
|
|
return { isAvailable: true };
|
|
}
|
|
|
|
// Anything else (typo, leftover `http`) would throw at seal time.
|
|
if (transport !== 'local') {
|
|
return { isAvailable: false };
|
|
}
|
|
|
|
try {
|
|
const signer = await createLocalSigner({ buildChain: false });
|
|
|
|
const certificate = new X509Certificate(Buffer.from(signer.certificate));
|
|
|
|
const now = new Date();
|
|
|
|
const isWithinValidityPeriod = new Date(certificate.validFrom) <= now && now <= new Date(certificate.validTo);
|
|
|
|
return { isAvailable: isWithinValidityPeriod };
|
|
} catch {
|
|
return { isAvailable: false };
|
|
}
|
|
};
|