feat(invite-link): re-structure invite-link-client to use and expose new invite link api - #1274
Conversation
🔍 SDK Breaking Change DetectionSDK Version:
Breaking change detection uses the build of the SDK from this branch, including any incompatibities pre-existing on or merged into this branch. Check the workflow logs to confirm. |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #1274 +/- ##
==========================================
+ Coverage 85.79% 85.82% +0.02%
==========================================
Files 487 491 +4
Lines 69999 70676 +677
==========================================
+ Hits 60059 60660 +601
- Misses 9940 10016 +76 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
70c1a5d to
1d26aa5
Compare
🤖 Bitwarden Claude Code ReviewOverall Assessment: APPROVE Reviewed the restructuring of Code Review DetailsNo blocking findings. Notes (informational, no action required):
|
1d26aa5 to
2c2359e
Compare
2c2359e to
568a6e6
Compare
568a6e6 to
52bfcc5
Compare
52bfcc5 to
ffb720b
Compare
ffb720b to
3b20922
Compare
3b20922 to
c05b283
Compare
…new invite link api
…expose new invite link api
8d255c0 to
21d0b51
Compare
| export const TEST_INVITE_SECRET = | ||
| "oSpRu_AENo_n11TqiLIryrJKaEPbQVjbdd6r4reyqUU" as unknown as InviteSecret; |
There was a problem hiding this comment.
Exposed secret in crates/bitwarden-wasm-internal/integration-tests/tests/org-fixtures.ts - low severity
Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
Reply @AikidoSec ignore: [REASON] to ignore this issue.
More Info
There was a problem hiding this comment.
✅ Based on your feedback, we ignored this issue because of the following reason:
Test vector
| "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwunODXi0Bv17ZDioko6yqGls/2lJVsT1Wab98TW2RMWaWiyqnhNqKSDvuVAmQ5/XBKJzlBnpVx3nfT/soDI4CrbUh5wOSYypzcVhymcRZ9PmNMa3u6ib2iSPr36UXawqTgw2cS6TG30TmtEM0PLCLcsfNUnD2reAlnBpgqlaHR/n1slbIH7Qn7Hy7MC5ElyRc7h3cm92l7K2d1rfCoyX+/xZ/cf4JOY2rGPYx106wR+IBt6SivdBsBYuFNS1BjTlXELJlJsOKcxgXXWbFV9BzJUe2DlYSq7PuIKCd4yYm8mDmDa5m3wFtXAr4CHTVxwOdtA/0x7ZLgKc2O++7a9S6QIDAQAB"; | ||
|
|
||
| export const TEST_INVITE = | ||
| '{"sealed_invite_data":"g1hHpQEDA3gjYXBwbGljYXRpb24veC5iaXR3YXJkZW4uY2Jvci1wYWRkZWQEUOeB/QFwHUwsvdEq0eCp5Us6AAE4gQI6AAE4gAKhBUx0ff7FDlj8cQzQvL1Yy97w7gc4TFOvBS/whCehNcW04jWGFaeNliHZyBRoIhKTHcKP1lJTYEh5ykybxh7ktkuznHCwv3Mz3jQ6Y7fdfINkGpvDo6EL8psW0dXu0BWAoJu1c2IvKFwSlz4fsHwCHCX8a+i2EagdSC1yfOlFqA9Iu6OxX9nEABCQ17GVsa+JanExuT/8W/BKgTZGgp9ptGz98i0hOVLSBbIkOABDNs3ONmxilICzf9jipZsGFjwWpBXJgjAiK5qDHnlYTe6/ASdjvywwbiJjnwr+","invite_key_sealed_invite_data_cek":"g1g+pgE6AAEReQMYZQRQeHT1pCPgaB9CYG+Rb8scAjoAARVcUOeB/QFwHUwsvdEq0eCp5Us6AAE4gQM6AAE4gAKhBVgYnr1DARLvnvtw1bsYXa2gueder+FZz2D4WE1gkmCx7GnYs+54fw+OeTJhutaOhz9gd7lwfRj5V0tGlP3yNdOUxLyyBDN/+L1qQzjbo3Utm17Wfl1ZrVbBZcFsQzue0/Zq0Lk8+/h+cA==","invite_secret_sealed_invite_key":"hFgopQEDAxhlOgABFVxQeHT1pCPgaB9CYG+Rb8scAjoAATiBBjoAATiAAaEFTB07pVNo3oYWy0o/XlhUQA/hxa3AsrA2OnLDQE8ffqZ/J29CXGv3YbPqOgIEXWPWOKEo9SZW+TbhBi6q3Wf0EewTdeWADozr80J79rJTxTfXKS2yNCmT+fjIjJcI0ov8HpnlgYNAogEpM1ggvtgywem/2QA8V1q/wgKtv6Rk1jLDpbZrbvE5+efMGkL2","invite_key_sealed_organization_key":"g1hKpQE6AAEReQN4ImFwcGxpY2F0aW9uL3guYml0d2FyZGVuLmxlZ2FjeS1rZXkEUHh09aQj4GgfQmBvkW/LHAI6AAE4gQM6AAE4gAKhBVgYQ5qCc8T8brREcCQFDzA2QhqjeTjoHtl2WFBuAdHlH509FDCxbqgjPUM56nEXVawZFQSpotSWXQsCYAz/MUce7LREwgkUZ5f3x9y4CpkvNTPkmEGTw675emwwpR05x6gJ0aL/UoyoF4bSpw==","organization_key_sealed_invite_key":"2.YnutjO6dOLfu/FzUXmdpaw==|nQnSQSO5EjB/sq6aMEK3bcEY9PQdLTBmelj1ftsMP7tiWUeoS6RTLKzg4kv8qggUgx+xh+XjBxULwdYJeV3k+pChTrnTRogClph2m3N9RtQ=|/dsbX2NfWpSVFPTHa5HQxBT7b9EdlwVlEgjJzyq3SvA="}' as unknown as Invite; |
There was a problem hiding this comment.
Exposed secret in crates/bitwarden-wasm-internal/integration-tests/tests/org-fixtures.ts - low severity
Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
Reply @AikidoSec ignore: [REASON] to ignore this issue.
More Info
There was a problem hiding this comment.
✅ Based on your feedback, we ignored this issue because of the following reason:
Test vector
dereknance
left a comment
There was a problem hiding this comment.
✅ Platform: crates/bitwarden-wasm-internal/integration-tests/tests/
| supports_confirmation: response.supports_confirmation.unwrap_or(false), | ||
| creation_date: require!(response.creation_date) | ||
| .parse() | ||
| .map_err(|_| MissingFieldError("creation_date"))?, |
There was a problem hiding this comment.
❓ Isn't this more like malformed ?
There was a problem hiding this comment.
@eliykat Would you mind taking a look? Since this is nit I merged since this is VFO work with a tight deadline. / it lives in your code.
There was a problem hiding this comment.
🎨❓ Do we think its worth also moving the delete functionality into the SDK for consistency? There are no crypto operations on it currently, so it doesn't have to. But it would be nice to have all the CRUD operations live in the SDK client. It would make invite link completely portable across clients if we so desired. Perhaps a follow up?
…: re-structure invite-link-client to use and expose new invite link api (bitwarden/sdk-internal#1274)
https://bitwarden.atlassian.net/browse/PM-40307
Re-structure the invite link clients to use the new cryptographic api for the invite, and to expose the new API. HTTP requests are moved into the SDK. Two are left open for AC to move as a follow-up once they are implemented.