mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 06:27:40 +00:00
feat(infisical-pg): completed audit log migrator
This commit is contained in:
@@ -5,7 +5,8 @@
|
|||||||
"main": "index.js",
|
"main": "index.js",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"migration": "tsx src/index.ts",
|
"migration": "tsx src/index.ts",
|
||||||
"rollback": "tsx src/rollback.ts"
|
"rollback": "tsx src/rollback.ts",
|
||||||
|
"migrate:audit-log": "tsx src/audit-log-migrator.ts"
|
||||||
},
|
},
|
||||||
"author": "",
|
"author": "",
|
||||||
"license": "ISC",
|
"license": "ISC",
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
+32
-21
@@ -78,6 +78,26 @@ const getFolderVersionKey = (folderId: string, version: number) =>
|
|||||||
`${folderId}:${version}`;
|
`${folderId}:${version}`;
|
||||||
|
|
||||||
const projectKv = kdb.sublevel(TableName.Project);
|
const projectKv = kdb.sublevel(TableName.Project);
|
||||||
|
const envPKv = kdb.sublevel(TableName.Environment);
|
||||||
|
|
||||||
|
export const getEnvId = (workspace: string, environment: string) => {
|
||||||
|
const envKv = envPKv.sublevel(workspace);
|
||||||
|
return envKv.get(environment);
|
||||||
|
};
|
||||||
|
export const getFolderKv = (workspace: string, environment: string) => {
|
||||||
|
const envKv = envPKv.sublevel(workspace);
|
||||||
|
return envKv.sublevel(environment);
|
||||||
|
};
|
||||||
|
|
||||||
|
const checkIfFolderIsDangling = async (
|
||||||
|
projectId: string,
|
||||||
|
env_slug: string,
|
||||||
|
folderId: string,
|
||||||
|
) => {
|
||||||
|
const kv = getFolderKv(projectId, truncateAndSlugify(env_slug));
|
||||||
|
const result = await kv.get(`${folderId}:dead`).catch(() => null);
|
||||||
|
return Boolean(result);
|
||||||
|
};
|
||||||
|
|
||||||
const migrationCheckPointsKv = kdb.sublevel("CHECK-POINTS");
|
const migrationCheckPointsKv = kdb.sublevel("CHECK-POINTS");
|
||||||
|
|
||||||
@@ -104,7 +124,7 @@ export const groupBy = <T, Key extends string | number | symbol>(
|
|||||||
{} as Record<Key, T[]>,
|
{} as Record<Key, T[]>,
|
||||||
);
|
);
|
||||||
|
|
||||||
const migrateCollection = async <
|
export const migrateCollection = async <
|
||||||
T extends {},
|
T extends {},
|
||||||
K extends keyof Tables,
|
K extends keyof Tables,
|
||||||
R extends (keyof Tables[K]["base"])[] = [],
|
R extends (keyof Tables[K]["base"])[] = [],
|
||||||
@@ -567,26 +587,6 @@ const main = async () => {
|
|||||||
console.log(
|
console.log(
|
||||||
"Migrating environments from Mongo Project -> Pg Environment Table",
|
"Migrating environments from Mongo Project -> Pg Environment Table",
|
||||||
);
|
);
|
||||||
const envPKv = kdb.sublevel(TableName.Environment);
|
|
||||||
|
|
||||||
const getEnvId = (workspace: string, environment: string) => {
|
|
||||||
const envKv = envPKv.sublevel(workspace);
|
|
||||||
return envKv.get(environment);
|
|
||||||
};
|
|
||||||
const getFolderKv = (workspace: string, environment: string) => {
|
|
||||||
const envKv = envPKv.sublevel(workspace);
|
|
||||||
return envKv.sublevel(environment);
|
|
||||||
};
|
|
||||||
|
|
||||||
const checkIfFolderIsDangling = async (
|
|
||||||
projectId: string,
|
|
||||||
env_slug: string,
|
|
||||||
folderId: string,
|
|
||||||
) => {
|
|
||||||
const kv = getFolderKv(projectId, truncateAndSlugify(env_slug));
|
|
||||||
const result = await kv.get(`${folderId}:dead`).catch(() => null);
|
|
||||||
return Boolean(result);
|
|
||||||
};
|
|
||||||
|
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
@@ -665,6 +665,7 @@ const main = async () => {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const projectKeyKv = kdb.sublevel(TableName.ProjectKeys);
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
mongooseCollection: Key,
|
mongooseCollection: Key,
|
||||||
@@ -680,6 +681,7 @@ const main = async () => {
|
|||||||
if (!projectKvRes) return;
|
if (!projectKvRes) return;
|
||||||
|
|
||||||
const id = uuidV4();
|
const id = uuidV4();
|
||||||
|
await projectKeyKv.put(doc._id.toString(), id);
|
||||||
|
|
||||||
const senderId = await userKv
|
const senderId = await userKv
|
||||||
.get(doc.sender.toString())
|
.get(doc.sender.toString())
|
||||||
@@ -889,6 +891,7 @@ const main = async () => {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const secretImportKv = kdb.sublevel(TableName.SecretImport);
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
mongooseCollection: SecretImport,
|
mongooseCollection: SecretImport,
|
||||||
@@ -1337,6 +1340,7 @@ const main = async () => {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const integrationKv = kdb.sublevel(TableName.Integration);
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
mongooseCollection: Integration,
|
mongooseCollection: Integration,
|
||||||
@@ -1357,6 +1361,7 @@ const main = async () => {
|
|||||||
const integrationAuthId = await integrationAuthKv.get(
|
const integrationAuthId = await integrationAuthKv.get(
|
||||||
doc.integrationAuth.toString(),
|
doc.integrationAuth.toString(),
|
||||||
);
|
);
|
||||||
|
await integrationKv.put(doc._id.toString(), id);
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id,
|
id,
|
||||||
@@ -1418,6 +1423,7 @@ const main = async () => {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const webhookKv = kdb.sublevel(TableName.Webhook);
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
mongooseCollection: Webhook,
|
mongooseCollection: Webhook,
|
||||||
@@ -1435,6 +1441,7 @@ const main = async () => {
|
|||||||
doc.workspace.toString(),
|
doc.workspace.toString(),
|
||||||
truncateAndSlugify(doc.environment),
|
truncateAndSlugify(doc.environment),
|
||||||
);
|
);
|
||||||
|
await webhookKv.put(doc._id.toString(), id);
|
||||||
return {
|
return {
|
||||||
id,
|
id,
|
||||||
iv: doc.iv,
|
iv: doc.iv,
|
||||||
@@ -1533,6 +1540,7 @@ const main = async () => {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const identityAccessTokenKv = kdb.sublevel(TableName.IdentityAccessToken);
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
mongooseCollection: IdentityAccessToken,
|
mongooseCollection: IdentityAccessToken,
|
||||||
@@ -1540,6 +1548,7 @@ const main = async () => {
|
|||||||
returnKeys: ["id"],
|
returnKeys: ["id"],
|
||||||
preProcessing: async (doc) => {
|
preProcessing: async (doc) => {
|
||||||
const id = uuidV4();
|
const id = uuidV4();
|
||||||
|
await identityAccessTokenKv.put(doc._id.toString(), id);
|
||||||
const identityUAClientSecretId = doc?.identityUniversalAuthClientSecret
|
const identityUAClientSecretId = doc?.identityUniversalAuthClientSecret
|
||||||
? await identityUaClientSecKv.get(
|
? await identityUaClientSecKv.get(
|
||||||
doc.identityUniversalAuthClientSecret.toString(),
|
doc.identityUniversalAuthClientSecret.toString(),
|
||||||
@@ -1953,6 +1962,7 @@ const main = async () => {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const trustedIpKv = kdb.sublevel(TableName.TrustedIps);
|
||||||
await migrateCollection({
|
await migrateCollection({
|
||||||
db,
|
db,
|
||||||
mongooseCollection: TrustedIP,
|
mongooseCollection: TrustedIP,
|
||||||
@@ -1965,6 +1975,7 @@ const main = async () => {
|
|||||||
.get(doc.workspace.toString())
|
.get(doc.workspace.toString())
|
||||||
.catch(() => null);
|
.catch(() => null);
|
||||||
if (!projectKvRes) return;
|
if (!projectKvRes) return;
|
||||||
|
await trustedIpKv.put(doc._id.toString(), id);
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id,
|
id,
|
||||||
|
|||||||
@@ -19,52 +19,52 @@ const auditLogSchema = new Schema<IAuditLog>(
|
|||||||
type: {
|
type: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: ActorType,
|
enum: ActorType,
|
||||||
required: true
|
required: true,
|
||||||
},
|
},
|
||||||
metadata: {
|
metadata: {
|
||||||
type: Schema.Types.Mixed
|
type: Schema.Types.Mixed,
|
||||||
}
|
},
|
||||||
},
|
},
|
||||||
organization: {
|
organization: {
|
||||||
type: Schema.Types.ObjectId,
|
type: Schema.Types.ObjectId,
|
||||||
required: false
|
required: false,
|
||||||
},
|
},
|
||||||
workspace: {
|
workspace: {
|
||||||
type: Schema.Types.ObjectId,
|
type: Schema.Types.ObjectId,
|
||||||
required: false,
|
required: false,
|
||||||
index: true
|
index: true,
|
||||||
},
|
},
|
||||||
ipAddress: {
|
ipAddress: {
|
||||||
type: String,
|
type: String,
|
||||||
required: true
|
required: true,
|
||||||
},
|
},
|
||||||
event: {
|
event: {
|
||||||
type: {
|
type: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: EventType,
|
enum: EventType,
|
||||||
required: true
|
required: true,
|
||||||
},
|
},
|
||||||
metadata: {
|
metadata: {
|
||||||
type: Schema.Types.Mixed
|
type: Schema.Types.Mixed,
|
||||||
}
|
},
|
||||||
},
|
},
|
||||||
userAgent: {
|
userAgent: {
|
||||||
type: String,
|
type: String,
|
||||||
required: true
|
required: true,
|
||||||
},
|
},
|
||||||
userAgentType: {
|
userAgentType: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: UserAgentType,
|
enum: UserAgentType,
|
||||||
required: true
|
required: true,
|
||||||
},
|
},
|
||||||
expiresAt: {
|
expiresAt: {
|
||||||
type: Date,
|
type: Date,
|
||||||
expires: 0
|
expires: 0,
|
||||||
}
|
},
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
timestamps: true
|
timestamps: true,
|
||||||
}
|
},
|
||||||
);
|
);
|
||||||
|
|
||||||
export const AuditLog = model<IAuditLog>("AuditLog", auditLogSchema);
|
export const AuditLog = model<IAuditLog>("AuditLog", auditLogSchema);
|
||||||
|
|||||||
Reference in New Issue
Block a user