Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
53 changes: 51 additions & 2 deletions packages/backend/src/connectors/engines/soap.engine.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import { Injectable, Logger } from '@nestjs/common';
import axios from 'axios';
import * as soap from 'soap';
import * as crypto from 'crypto';
import { XMLParser } from 'fast-xml-parser';
import { assertSafeOutboundUrl } from '../../common/ssrf.util';

Expand Down Expand Up @@ -81,6 +82,8 @@ export class SoapEngine {
targetNamespace,
soapParams,
paramOrder,
config.authType,
config.authConfig,
);

// Build headers
Expand Down Expand Up @@ -161,6 +164,8 @@ export class SoapEngine {
targetNamespace: string,
params: Record<string, unknown>,
paramOrder: string[] = [],
authType?: string,
authConfig?: Record<string, unknown>,
): string {
const ns = targetNamespace || 'http://tempuri.org/';

Expand All @@ -174,9 +179,11 @@ export class SoapEngine {
.map((key) => ` <tns:${key}>${this.escapeXml(String(params[key]))}</tns:${key}>`)
.join('\n');

const headerXml = this.buildHeaderXml(authType, authConfig);

return `<?xml version="1.0" encoding="utf-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:tns="${ns}">
<soapenv:Header/>
${headerXml}
<soapenv:Body>
<tns:${operationName}>
${paramXml}
Expand All @@ -185,6 +192,48 @@ ${paramXml}
</soapenv:Envelope>`;
}

private buildHeaderXml(
authType?: string,
authConfig?: Record<string, unknown>,
): string {
if (authType === 'WS_SECURITY' && authConfig) {
const username = this.escapeXml(String(authConfig.username ?? ''));
const password = String(authConfig.password ?? '');
const passwordType = authConfig.passwordType || 'PasswordText';

let passwordElement = '';
let nonceElement = '';
let createdElement = '';

if (passwordType === 'PasswordDigest') {
const created = new Date().toISOString();
const nonceBytes = crypto.randomBytes(16);
const nonceBase64 = nonceBytes.toString('base64');
const hash = crypto
.createHash('sha1')
.update(Buffer.concat([nonceBytes, Buffer.from(created, 'utf8'), Buffer.from(password, 'utf8')]))
.digest('base64');

passwordElement = ` <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">${hash}</wsse:Password>`;
nonceElement = `\n <wsse:Nonce EncodingType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary">${nonceBase64}</wsse:Nonce>`;
createdElement = `\n <wsu:Created xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">${created}</wsu:Created>`;
} else {
passwordElement = ` <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">${this.escapeXml(password)}</wsse:Password>`;
}

return `<soapenv:Header>
<wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
<wsse:UsernameToken>
<wsse:Username>${username}</wsse:Username>
${passwordElement}${nonceElement}${createdElement}
</wsse:UsernameToken>
</wsse:Security>
</soapenv:Header>`;
}

return '<soapenv:Header/>';
}

private escapeXml(str: string): string {
return str
.replace(/&/g, '&amp;')
Expand Down Expand Up @@ -366,4 +415,4 @@ ${paramXml}
}
return result;
}
}
}
Loading