Files
Chris Arderne a81ad4949c feat(database,rbac): add multiple environment API key foundations (#4388)
Adds the storage model and authorization contracts needed for multiple
environment API keys. Credentials are represented by hashed values,
revocation and expiration state, and persisted effective scopes.

The built-in authorization fallback exposes full-access policy
preparation, while optional authorization extensions can supply
additional presets and task-aware scope generation. This change does not
create, display, or authenticate additional keys.
2026-07-29 16:24:00 +00:00

52 lines
1.5 KiB
TypeScript

import { createHash } from "node:crypto";
import type { RuntimeEnvironmentType } from "@trigger.dev/database";
import { customAlphabet } from "nanoid";
const apiKeyId = customAlphabet(
"1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ",
24
);
export function hashApiKey(apiKey: string): string {
return createHash("sha256").update(apiKey, "utf8").digest("hex");
}
function generatedApiKey(apiKey: string) {
return {
apiKey,
keyHash: hashApiKey(apiKey),
lastFour: apiKey.slice(-4),
};
}
export function generateRootApiKey(environmentType: RuntimeEnvironmentType) {
// Root keys intentionally use the same 24-character entropy as additional keys.
return generatedApiKey(`${apiKeyPrefix(environmentType)}${apiKeyId()}`);
}
export function generateAdditionalApiKey(environmentType: RuntimeEnvironmentType) {
return generatedApiKey(`${apiKeyPrefix(environmentType)}sk_${apiKeyId()}`);
}
export function apiKeyPrefix(environmentType: RuntimeEnvironmentType): string {
switch (environmentType) {
case "DEVELOPMENT":
return "tr_dev_";
case "STAGING":
return "tr_stg_";
case "PRODUCTION":
return "tr_prod_";
case "PREVIEW":
return "tr_preview_";
}
}
export function obfuscateApiKey(
environmentType: RuntimeEnvironmentType,
lastFour: string,
kind: "root" | "additional" = "root"
): string {
const discriminator = kind === "additional" ? "sk_" : "";
return `${apiKeyPrefix(environmentType)}${discriminator}••••••••${lastFour}`;
}