Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 0 additions & 9 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -14,10 +14,6 @@ SAFE_ENABLED="false"
# DOES NOT NEED TO BE SET WHEN DEVELOPING LOCALLY
NETWORK_CONTRACT_ADDRESS="0x0000000000000000000000000000000000000000"

# Required for safe control
BSCSCAN_API_KEY=
ETHERSCAN_API_KEY=

# The endpoint of the reputation oracle.
REPUTATION_ORACLE_ENDPOINT="http://localhost:3001/reputation/local"

Expand All @@ -35,10 +31,8 @@ GOOGLE_TAG_MANAGER_ID=
# pinata connection detail from https://app.pinata.cloud/developers/api-keys
# Only needed for production
PINATA_API_KEY=
PINATA_API_SECRET=

# Needed for currency conversion. For testing, see: https://support.coingecko.com/hc/en-us/articles/21880397454233
COINGECKO_API_KEY=
COINGECKO_API_URL=
POSTHOG_KEY=
POSTHOG_HOST=
Expand All @@ -53,8 +47,5 @@ MAGICBELL_API_KEY=
# Used to set a local key so that in development you only recieve notifications from your current dev env
MAGICBELL_DEV_KEY=

# Needed for Arbitrary transaction feature
ARBISCAN_API_KEY=

# Needed so that we have a wallet provided by Dynamic.xyz
DYNAMIC_ENV_ID=
2 changes: 1 addition & 1 deletion amplify/backend/api/colonycdapp/parameters.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,5 +3,5 @@
"DynamoDBBillingMode": "PAY_PER_REQUEST",
"DynamoDBEnableServerSideEncryption": false,
"DynamoDBEnablePointInTimeRecovery": "true",
"APIKeyExpirationEpoch": 0
"CreateAPIKey": 0
}
8 changes: 8 additions & 0 deletions amplify/backend/api/colonycdapp/schema/schema.graphql
Original file line number Diff line number Diff line change
Expand Up @@ -1111,6 +1111,14 @@ type Query {
"""
getUserNotificationsHMAC: String
@function(name: "getUserNotificationsHMAC-${env}")
getClientSecrets: ClientSecrets
@function(name: "getClientSecrets-${env}")
}

type ClientSecrets {
pinataApiSecret: String
coinGeckoApiKey: String
arbiscanApiKey: String
}

"""
Expand Down
14 changes: 14 additions & 0 deletions amplify/backend/backend-config.json
Original file line number Diff line number Diff line change
Expand Up @@ -192,6 +192,20 @@
"providerPlugin": "awscloudformation",
"service": "Lambda"
},
"getClientSecrets": {
"build": true,
"dependsOn": [
{
"attributes": [
"Arn"
],
"category": "function",
"resourceName": "colonycdappSSMAccess"
}
],
"providerPlugin": "awscloudformation",
"service": "Lambda"
},
"getUserNotificationsHMAC": {
"build": true,
"providerPlugin": "awscloudformation",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@ const ParamNames = {
appsyncApiKey: `%2Famplify%2Fcdapp%2F${ENV}%2FAWS_APPSYNC_API_KEY`,
bnbRpcEndpoint: `%2Famplify%2Fcdapp%2F${ENV}%2FBNB_RPC_ENDPOINT`,
ethRpcEndpoint: `%2Famplify%2Fcdapp%2F${ENV}%2FETH_RPC_ENDPOINT`,
bscscanApiKey: `%2Famplify%2Fcdapp%2F${ENV}%2FBSCSCAN_API_KEY`,
etherscanApiKey: `%2Famplify%2Fcdapp%2F${ENV}%2FETHERSCAN_API_KEY`,
bridgeXYZApiKey: `%2Famplify%2Fcdapp%2F${ENV}%2FBRIDGEXYZ_API_KEY`,
bridgeXYZApiUrl: `%2Famplify%2Fcdapp%2F${ENV}%2FBRIDGEXYZ_API_URL`,
Expand All @@ -21,6 +20,8 @@ const ParamNames = {
magicbellApiSecret: `%2Famplify%2Fcdapp%2F${ENV}%2FMAGICBELL_API_SECRET`,
coinGeckoApiUrl: `%2Famplify%2Fcdapp%2F${ENV}%2FCOINGECKO_API_URL`,
coinGeckoApiKey: `%2Famplify%2Fcdapp%2F${ENV}%2FCOINGECKO_API_KEY`,
pinataApiSecret: `%2Famplify%2Fcdapp%2F${ENV}%2FPINATA_API_SECRET`,
arbiscanApiKey: `%2Famplify%2Fcdapp%2F${ENV}%2FARBISCAN_API_KEY`,
};

const getParam = async (paramName) => {
Expand Down
3 changes: 3 additions & 0 deletions amplify/backend/function/getClientSecrets/.env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
PINATA_API_SECRET=
COINGECKO_API_KEY=
ARBISCAN_API_KEY=
6 changes: 6 additions & 0 deletions amplify/backend/function/getClientSecrets/amplify.state
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
{
"pluginId": "amplify-nodejs-function-runtime-provider",
"functionRuntime": "nodejs",
"useLegacyBuild": true,
"defaultEditorFile": "src/index.js"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
[
{
"Action": [],
"Resource": []
}
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"lambdaLayers": [
{
"type": "ProjectLayer",
"resourceName": "colonycdappSSMAccess",
"env": "qa",
"version": "Always choose latest version",
"isLatestVersionSelected": true
},
{
"type": "ExternalLayer",
"arn": "arn:aws:lambda:eu-west-2:133256977650:layer:AWS-Parameters-and-Secrets-Lambda-Extension:4"
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,231 @@
{
"AWSTemplateFormatVersion": "2010-09-09",
"Description": "{\"createdOn\":\"Linux\",\"createdBy\":\"Amplify\",\"createdWith\":\"12.12.4\",\"stackType\":\"function-Lambda\",\"metadata\":{}}",
"Parameters": {
"CloudWatchRule": {
"Type": "String",
"Default": "NONE",
"Description": " Schedule Expression"
},
"deploymentBucketName": {
"Type": "String"
},
"env": {
"Type": "String"
},
"s3Key": {
"Type": "String"
},
"functioncolonycdappSSMAccessArn": {
"Type": "String",
"Default": "functioncolonycdappSSMAccessArn"
}
},
"Conditions": {
"ShouldNotCreateEnvResources": {
"Fn::Equals": [
{
"Ref": "env"
},
"NONE"
]
}
},
"Resources": {
"LambdaFunction": {
"Type": "AWS::Lambda::Function",
"Metadata": {
"aws:asset:path": "./src",
"aws:asset:property": "Code"
},
"Properties": {
"Code": {
"S3Bucket": {
"Ref": "deploymentBucketName"
},
"S3Key": {
"Ref": "s3Key"
}
},
"Handler": "index.handler",
"FunctionName": {
"Fn::If": [
"ShouldNotCreateEnvResources",
"getClientSecrets",
{
"Fn::Join": [
"",
[
"getClientSecrets",
"-",
{
"Ref": "env"
}
]
]
}
]
},
"Environment": {
"Variables": {
"ENV": {
"Ref": "env"
},
"REGION": {
"Ref": "AWS::Region"
}
}
},
"Role": {
"Fn::GetAtt": [
"LambdaExecutionRole",
"Arn"
]
},
"Runtime": "nodejs20.x",
"Layers": [
{
"Ref": "functioncolonycdappSSMAccessArn"
},
"arn:aws:lambda:eu-west-2:133256977650:layer:AWS-Parameters-and-Secrets-Lambda-Extension:4"
],
"Timeout": 60
}
},
"LambdaExecutionRole": {
"Type": "AWS::IAM::Role",
"Properties": {
"RoleName": {
"Fn::If": [
"ShouldNotCreateEnvResources",
"colonycdappLambdaRoleGetClientSecrets",
{
"Fn::Join": [
"",
[
"colonycdappLambdaRoleGetClientSecrets",
"-",
{
"Ref": "env"
}
]
]
}
]
},
"AssumeRolePolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": [
"lambda.amazonaws.com"
]
},
"Action": [
"sts:AssumeRole"
]
}
]
}
}
},
"lambdaexecutionpolicy": {
"DependsOn": [
"LambdaExecutionRole"
],
"Type": "AWS::IAM::Policy",
"Properties": {
"PolicyName": "lambda-execution-policy",
"Roles": [
{
"Ref": "LambdaExecutionRole"
}
],
"PolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": {
"Fn::Sub": [
"arn:aws:logs:${region}:${account}:log-group:/aws/lambda/${lambda}:log-stream:*",
{
"region": {
"Ref": "AWS::Region"
},
"account": {
"Ref": "AWS::AccountId"
},
"lambda": {
"Ref": "LambdaFunction"
}
}
]
}
},
{
"Effect": "Allow",
"Action": [
"ssm:GetParameter",
"kms:Decrypt"
],
"Resource": {
"Fn::Sub": [
"arn:aws:ssm:${region}:${account}:parameter/*",
{
"region": {
"Ref": "AWS::Region"
},
"account": {
"Ref": "AWS::AccountId"
}
}
]
}
}
]
}
}
}
},
"Outputs": {
"Name": {
"Value": {
"Ref": "LambdaFunction"
}
},
"Arn": {
"Value": {
"Fn::GetAtt": [
"LambdaFunction",
"Arn"
]
}
},
"Region": {
"Value": {
"Ref": "AWS::Region"
}
},
"LambdaExecutionRole": {
"Value": {
"Ref": "LambdaExecutionRole"
}
},
"LambdaExecutionRoleArn": {
"Value": {
"Fn::GetAtt": [
"LambdaExecutionRole",
"Arn"
]
}
}
}
}
34 changes: 34 additions & 0 deletions amplify/backend/function/getClientSecrets/src/index.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
let pinataApiSecret = process.env.PINATA_API_SECRET;
let coinGeckoApiKey = process.env.COINGECKO_API_KEY;
let arbiscanApiKey = process.env.ARBISCAN_API_KEY;

const setEnvVariables = async () => {
const ENV = process.env.ENV;

if (ENV === 'qa' || ENV === 'prod') {
const { getParams } = require('/opt/nodejs/getParams');
[pinataApiSecret, coinGeckoApiKey, arbiscanApiKey] = await getParams([
'pinataApiSecret',
'coinGeckoApiKey',
'arbiscanApiKey',
]);
}
};

exports.handler = async (event) => {
try {
await setEnvVariables();
} catch (err) {
throw new Error('Unable to set environment variables. Reason:', err);
}

if (!event.request.headers['x-wallet-address']) {
return null;
}

return {
pinataApiSecret,
coinGeckoApiKey,
arbiscanApiKey,
};
};
Loading
Loading