From 37a10d14353433bb0ef655327f849d8a1707c2e4 Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Wed, 2 Jul 2025 04:13:58 +0800 Subject: [PATCH 1/7] misc: updated sidebar name --- frontend/src/layouts/AdminLayout/Sidebar.tsx | 2 +- frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/frontend/src/layouts/AdminLayout/Sidebar.tsx b/frontend/src/layouts/AdminLayout/Sidebar.tsx index db6384e68..61441c1ed 100644 --- a/frontend/src/layouts/AdminLayout/Sidebar.tsx +++ b/frontend/src/layouts/AdminLayout/Sidebar.tsx @@ -43,7 +43,7 @@ const generalTabs = [ link: "/admin/caching" }, { - label: "Environment", + label: "Environment Variables", icon: "unlock", link: "/admin/environment" } diff --git a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx index ea4467131..908270748 100644 --- a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx +++ b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx @@ -17,7 +17,7 @@ export const EnvironmentPage = () => {
From aea61bae381609907be9c84f54d923e1a91e4725 Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Wed, 2 Jul 2025 04:17:52 +0800 Subject: [PATCH 2/7] misc: label updates --- frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx | 2 +- .../admin/EnvironmentPage/components/EnvironmentPageForm.tsx | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx index 908270748..000dd1f0d 100644 --- a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx +++ b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx @@ -16,7 +16,7 @@ export const EnvironmentPage = () => {
diff --git a/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx b/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx index 2a629bf95..5897d8474 100644 --- a/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx +++ b/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx @@ -224,7 +224,7 @@ export const EnvironmentPageForm = () => { isLoading={isSubmitting} isDisabled={isSubmitting || !isDirty} > - Save Overrides + Save
From 38c9242e5b1b29c710335080c61d2303483c322d Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Wed, 2 Jul 2025 04:45:53 +0800 Subject: [PATCH 3/7] misc: add plain support for user get token in CLI --- cli/packages/cmd/user.go | 16 ++++++++++++-- docs/cli/commands/user.mdx | 43 ++++++++++++++++++++++++++++---------- 2 files changed, 46 insertions(+), 13 deletions(-) diff --git a/cli/packages/cmd/user.go b/cli/packages/cmd/user.go index 6c7d54d46..3b0970403 100644 --- a/cli/packages/cmd/user.go +++ b/cli/packages/cmd/user.go @@ -114,6 +114,11 @@ var userGetTokenCmd = &cobra.Command{ loggedInUserDetails = util.EstablishUserLoginSession() } + plain, err := cmd.Flags().GetBool("plain") + if err != nil { + util.HandleError(err, "[infisical user get token]: Unable to get plain flag") + } + if err != nil { util.HandleError(err, "[infisical user get token]: Unable to get logged in user token") } @@ -135,8 +140,12 @@ var userGetTokenCmd = &cobra.Command{ util.HandleError(err, "[infisical user get token]: Unable to parse token payload") } - fmt.Println("Session ID:", tokenPayload.TokenVersionId) - fmt.Println("Token:", loggedInUserDetails.UserCredentials.JTWToken) + if plain { + fmt.Println(loggedInUserDetails.UserCredentials.JTWToken) + } else { + fmt.Println("Session ID:", tokenPayload.TokenVersionId) + fmt.Println("Token:", loggedInUserDetails.UserCredentials.JTWToken) + } }, } @@ -240,7 +249,10 @@ var domainCmd = &cobra.Command{ func init() { updateCmd.AddCommand(domainCmd) userCmd.AddCommand(updateCmd) + + userGetTokenCmd.Flags().Bool("plain", false, "print token without formatting") userGetCmd.AddCommand(userGetTokenCmd) + userCmd.AddCommand(userGetCmd) userCmd.AddCommand(switchCmd) rootCmd.AddCommand(userCmd) diff --git a/docs/cli/commands/user.mdx b/docs/cli/commands/user.mdx index 43a6111e1..108b1f23b 100644 --- a/docs/cli/commands/user.mdx +++ b/docs/cli/commands/user.mdx @@ -35,19 +35,40 @@ infisical user update domain Use this command to get your current Infisical access token and session information. This command requires you to be logged in. - The command will display: +The command will display: - - Your session ID - - Your full JWT access token +- Your session ID +- Your full JWT access token - ```bash - infisical user get token - ``` +```bash +infisical user get token +``` - Example output: +Example output: + +```bash +Session ID: abc123-xyz-456 +Token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... +``` + +### Flags + + + Output only the JWT token without formatting (no session ID) + + Default value: `false` + + ```bash + # Example + infisical user get token --plain + ``` + + Example output: + + ```bash + eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... + ``` + + - ```bash - Session ID: abc123-xyz-456 - Token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... - ``` From cada75bd0c92330f3d1de1b6a6c1a74457243bc2 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard Date: Wed, 2 Jul 2025 01:29:49 +0400 Subject: [PATCH 4/7] Delete mint.json --- docs/mint.json | 2241 ------------------------------------------------ 1 file changed, 2241 deletions(-) delete mode 100644 docs/mint.json diff --git a/docs/mint.json b/docs/mint.json deleted file mode 100644 index 2dcb233d3..000000000 --- a/docs/mint.json +++ /dev/null @@ -1,2241 +0,0 @@ -{ - "name": "Infisical", - "openapi": "https://app.infisical.com/api/docs/json", - "logo": { - "dark": "/logo/dark.svg", - "light": "/logo/light.svg", - "href": "https://infisical.com" - }, - "favicon": "/favicon.png", - "colors": { - "primary": "#26272b", - "light": "#97b31d", - "dark": "#A1B659", - "ultraLight": "#E7F256", - "ultraDark": "#8D9F4C", - "background": { - "light": "#ffffff", - "dark": "#0D1117" - }, - "anchors": { - "from": "#000000", - "to": "#707174" - } - }, - "modeToggle": { - "default": "light", - "isHidden": true - }, - "feedback": { - "suggestEdit": true, - "raiseIssue": true, - "thumbsRating": true - }, - "api": { - "baseUrl": ["https://app.infisical.com", "http://localhost:8080"] - }, - "topbarLinks": [ - { - "name": "Log In", - "url": "https://app.infisical.com/login" - } - ], - "topbarCtaButton": { - "name": "Start for Free", - "url": "https://app.infisical.com/signup" - }, - "tabs": [ - { - "name": "Integrations", - "url": "integrations" - }, - { - "name": "CLI", - "url": "cli" - }, - { - "name": "API Reference", - "url": "api-reference" - }, - { - "name": "SDKs", - "url": "sdks" - }, - { - "name": "Changelog", - "url": "changelog" - } - ], - "navigation": [ - { - "group": "Getting Started", - "pages": [ - "documentation/getting-started/introduction", - { - "group": "Quickstart", - "pages": ["documentation/guides/local-development"] - }, - { - "group": "Guides", - "pages": [ - "documentation/guides/introduction", - "documentation/guides/node", - "documentation/guides/python", - "documentation/guides/nextjs-vercel", - "documentation/guides/microsoft-power-apps", - "documentation/guides/organization-structure" - ] - }, - { - "group": "Setup", - "pages": ["documentation/setup/networking"] - } - ] - }, - { - "group": "Platform", - "pages": [ - "documentation/platform/organization", - "documentation/platform/project", - "documentation/platform/folder", - { - "group": "Secrets", - "pages": [ - "documentation/platform/secret-versioning", - "documentation/platform/pit-recovery", - "documentation/platform/secret-reference", - "documentation/platform/webhooks" - ] - }, - { - "group": "Internal PKI", - "pages": [ - "documentation/platform/pki/overview", - "documentation/platform/pki/private-ca", - "documentation/platform/pki/external-ca", - "documentation/platform/pki/subscribers", - "documentation/platform/pki/certificates", - "documentation/platform/pki/acme-ca", - "documentation/platform/pki/est", - "documentation/platform/pki/alerting", - { - "group": "Integrations", - "pages": [ - "documentation/platform/pki/pki-issuer", - "documentation/platform/pki/integration-guides/gloo-mesh" - ] - } - ] - }, - { - "group": "Infisical SSH", - "pages": [ - "documentation/platform/ssh/overview", - "documentation/platform/ssh/host-groups" - ] - }, - { - "group": "Key Management (KMS)", - "pages": [ - "documentation/platform/kms/overview", - "documentation/platform/kms/hsm-integration", - "documentation/platform/kms/kubernetes-encryption", - "documentation/platform/kms/kmip" - ] - }, - { - "group": "KMS Configuration", - "pages": [ - "documentation/platform/kms-configuration/overview", - "documentation/platform/kms-configuration/aws-kms", - "documentation/platform/kms-configuration/aws-hsm", - "documentation/platform/kms-configuration/gcp-kms" - ] - }, - { - "group": "Identities", - "pages": [ - "documentation/platform/identities/overview", - "documentation/platform/identities/user-identities", - "documentation/platform/identities/machine-identities" - ] - }, - { - "group": "Access Control", - "pages": [ - "documentation/platform/access-controls/overview", - "documentation/platform/access-controls/role-based-access-controls", - { - "group": "Attribute based access controls", - "pages": [ - "documentation/platform/access-controls/abac/overview", - "documentation/platform/access-controls/abac/managing-user-metadata", - "documentation/platform/access-controls/abac/managing-machine-identity-attributes" - ] - }, - "documentation/platform/access-controls/additional-privileges", - "documentation/platform/access-controls/temporary-access", - "documentation/platform/access-controls/assume-privilege", - "documentation/platform/access-controls/access-requests", - "documentation/platform/access-controls/project-access-requests", - "documentation/platform/pr-workflows", - "documentation/platform/groups" - ] - }, - { - "group": "Audit Logs", - "pages": [ - "documentation/platform/audit-logs", - "documentation/platform/audit-log-streams/audit-log-streams", - "documentation/platform/audit-log-streams/audit-log-streams-with-fluentbit" - ] - }, - { - "group": "Secret Rotation", - "pages": [ - "documentation/platform/secret-rotation/overview", - "documentation/platform/secret-rotation/auth0-client-secret", - "documentation/platform/secret-rotation/aws-iam-user-secret", - "documentation/platform/secret-rotation/azure-client-secret", - "documentation/platform/secret-rotation/ldap-password", - "documentation/platform/secret-rotation/mssql-credentials", - "documentation/platform/secret-rotation/mysql-credentials", - "documentation/platform/secret-rotation/oracledb-credentials", - "documentation/platform/secret-rotation/postgres-credentials" - ] - }, - { - "group": "Dynamic Secrets", - "pages": [ - "documentation/platform/dynamic-secrets/overview", - "documentation/platform/dynamic-secrets/aws-elasticache", - "documentation/platform/dynamic-secrets/aws-iam", - "documentation/platform/dynamic-secrets/azure-entra-id", - "documentation/platform/dynamic-secrets/cassandra", - "documentation/platform/dynamic-secrets/elastic-search", - "documentation/platform/dynamic-secrets/gcp-iam", - "documentation/platform/dynamic-secrets/ldap", - "documentation/platform/dynamic-secrets/mongo-atlas", - "documentation/platform/dynamic-secrets/mongo-db", - "documentation/platform/dynamic-secrets/mssql", - "documentation/platform/dynamic-secrets/mysql", - "documentation/platform/dynamic-secrets/oracle", - "documentation/platform/dynamic-secrets/postgresql", - "documentation/platform/dynamic-secrets/rabbit-mq", - "documentation/platform/dynamic-secrets/redis", - "documentation/platform/dynamic-secrets/sap-ase", - "documentation/platform/dynamic-secrets/sap-hana", - "documentation/platform/dynamic-secrets/snowflake", - "documentation/platform/dynamic-secrets/totp", - "documentation/platform/dynamic-secrets/kubernetes", - "documentation/platform/dynamic-secrets/vertica" - ] - }, - { - "group": "Gateway", - "pages": [ - "documentation/platform/gateways/overview", - "documentation/platform/gateways/gateway-security", - "documentation/platform/gateways/networking" - ] - }, - "documentation/platform/project-templates", - { - "group": "Workflow Integrations", - "pages": [ - "documentation/platform/workflow-integrations/slack-integration", - "documentation/platform/workflow-integrations/microsoft-teams-integration" - ] - }, - { - "group": "Admin Consoles", - "pages": [ - "documentation/platform/admin-panel/overview", - "documentation/platform/admin-panel/server-admin", - "documentation/platform/admin-panel/org-admin-console" - ] - }, - "documentation/platform/secret-sharing", - { - "group": "Secret Scanning", - "pages": [ - "documentation/platform/secret-scanning/overview", - "documentation/platform/secret-scanning/github" - ] - } - ] - }, - { - "group": "Authentication Methods", - "pages": [ - { - "group": "User Authentication", - "pages": [ - "documentation/platform/auth-methods/email-password", - { - "group": "SSO", - "pages": [ - "documentation/platform/sso/overview", - "documentation/platform/sso/google", - "documentation/platform/sso/github", - "documentation/platform/sso/gitlab", - "documentation/platform/sso/okta", - "documentation/platform/sso/azure", - "documentation/platform/sso/jumpcloud", - "documentation/platform/sso/keycloak-saml", - "documentation/platform/sso/google-saml", - "documentation/platform/sso/auth0-saml", - { - "group": "OIDC", - "pages": [ - { - "group": "Keycloak OIDC", - "pages": [ - "documentation/platform/sso/keycloak-oidc/overview", - "documentation/platform/sso/keycloak-oidc/group-membership-mapping" - ] - }, - "documentation/platform/sso/auth0-oidc", - { - "group": "General OIDC", - "pages": [ - "documentation/platform/sso/general-oidc/overview", - "documentation/platform/sso/general-oidc/group-membership-mapping" - ] - } - ] - } - ] - }, - { - "group": "LDAP", - "pages": [ - "documentation/platform/ldap/overview", - "documentation/platform/ldap/jumpcloud", - "documentation/platform/ldap/general" - ] - }, - { - "group": "SCIM", - "pages": [ - "documentation/platform/scim/overview", - "documentation/platform/scim/okta", - "documentation/platform/scim/azure", - "documentation/platform/scim/jumpcloud", - "documentation/platform/scim/group-mappings" - ] - } - ] - }, - - { - "group": "Machine Identities", - "pages": [ - "documentation/platform/identities/alicloud-auth", - "documentation/platform/identities/aws-auth", - "documentation/platform/identities/azure-auth", - "documentation/platform/identities/gcp-auth", - "documentation/platform/identities/jwt-auth", - "documentation/platform/identities/kubernetes-auth", - "documentation/platform/identities/oci-auth", - "documentation/platform/identities/token-auth", - "documentation/platform/identities/universal-auth", - { - "group": "OIDC Auth", - "pages": [ - "documentation/platform/identities/oidc-auth/general", - "documentation/platform/identities/oidc-auth/azure", - "documentation/platform/identities/oidc-auth/github", - "documentation/platform/identities/oidc-auth/circleci", - "documentation/platform/identities/oidc-auth/gitlab", - "documentation/platform/identities/oidc-auth/terraform-cloud", - "documentation/platform/identities/oidc-auth/spire" - ] - }, - - { - "group": "LDAP Auth", - "pages": [ - "documentation/platform/identities/ldap-auth/general", - "documentation/platform/identities/ldap-auth/jumpcloud" - ] - } - ] - }, - "documentation/platform/token", - "documentation/platform/mfa", - "documentation/platform/github-org-sync" - ] - }, - { - "group": "Self-host Infisical", - "pages": [ - "self-hosting/overview", - { - "group": "Installation methods", - "pages": [ - "self-hosting/deployment-options/standalone-infisical", - "self-hosting/deployment-options/docker-swarm", - "self-hosting/deployment-options/docker-compose", - "self-hosting/deployment-options/kubernetes-helm" - ] - }, - { - "group": "Linux Package", - "pages": [ - "self-hosting/deployment-options/native/linux-package/installation", - "self-hosting/deployment-options/native/linux-package/commands-configuration", - "self-hosting/deployment-options/linux-upgrade" - ] - }, - "self-hosting/guides/upgrading-infisical", - "self-hosting/configuration/envars", - "self-hosting/configuration/requirements", - { - "group": "Guides", - "pages": [ - "self-hosting/guides/mongo-to-postgres", - "self-hosting/guides/custom-certificates", - "self-hosting/guides/automated-bootstrapping", - "self-hosting/guides/production-hardening" - ] - }, - { - "group": "Reference architectures", - "pages": [ - "self-hosting/reference-architectures/aws-ecs", - "self-hosting/reference-architectures/linux-deployment-ha", - "self-hosting/reference-architectures/on-prem-k8s-ha", - "self-hosting/reference-architectures/google-cloud-run" - ] - }, - "self-hosting/ee", - "self-hosting/faq" - ] - }, - { - "group": "Command line", - "pages": [ - "cli/overview", - "cli/usage", - { - "group": "Core commands", - "pages": [ - "cli/commands/login", - "cli/commands/init", - "cli/commands/run", - "cli/commands/secrets", - "cli/commands/dynamic-secrets", - "cli/commands/ssh", - "cli/commands/gateway", - "cli/commands/bootstrap", - "cli/commands/export", - "cli/commands/token", - "cli/commands/service-token", - "cli/commands/vault", - "cli/commands/user", - "cli/commands/reset", - { - "group": "infisical scan", - "pages": [ - "cli/commands/scan", - "cli/commands/scan-git-changes", - "cli/commands/scan-install" - ] - } - ] - }, - "cli/scanning-overview", - "cli/project-config", - "cli/faq" - ] - }, - { - "group": "Infrastructure Integrations", - "pages": [ - "integrations/platforms/ansible", - "integrations/platforms/apache-airflow", - { - "group": "Container orchestrators", - "pages": [ - { - "group": "Kubernetes", - "pages": [ - "integrations/platforms/kubernetes/overview", - "integrations/platforms/kubernetes/infisical-secret-crd", - "integrations/platforms/kubernetes/infisical-push-secret-crd", - "integrations/platforms/kubernetes/infisical-dynamic-secret-crd" - ] - }, - "integrations/platforms/kubernetes-injector", - "integrations/platforms/kubernetes-csi", - "integrations/platforms/docker-swarm-with-agent", - "integrations/platforms/ecs-with-agent" - ] - }, - { - "group": "Docker", - "pages": [ - "integrations/platforms/docker-intro", - "integrations/platforms/docker", - "integrations/platforms/docker-pass-envs", - "integrations/platforms/docker-compose" - ] - }, - "integrations/platforms/infisical-agent", - "integrations/frameworks/packer", - "integrations/frameworks/pulumi", - "integrations/frameworks/terraform" - ] - }, - { - "group": "App Connections", - "pages": [ - "integrations/app-connections/overview", - { - "group": "Connections", - "pages": [ - "integrations/app-connections/1password", - "integrations/app-connections/auth0", - "integrations/app-connections/aws", - "integrations/app-connections/azure-app-configuration", - "integrations/app-connections/azure-client-secrets", - "integrations/app-connections/azure-devops", - "integrations/app-connections/azure-key-vault", - "integrations/app-connections/camunda", - "integrations/app-connections/databricks", - "integrations/app-connections/flyio", - "integrations/app-connections/gcp", - "integrations/app-connections/github", - "integrations/app-connections/github-radar", - "integrations/app-connections/gitlab", - "integrations/app-connections/hashicorp-vault", - "integrations/app-connections/heroku", - "integrations/app-connections/humanitec", - "integrations/app-connections/ldap", - "integrations/app-connections/mssql", - "integrations/app-connections/mysql", - "integrations/app-connections/oci", - "integrations/app-connections/oracledb", - "integrations/app-connections/postgres", - "integrations/app-connections/render", - "integrations/app-connections/teamcity", - "integrations/app-connections/terraform-cloud", - "integrations/app-connections/vercel", - "integrations/app-connections/windmill" - ] - } - ] - }, - { - "group": "Secret Syncs", - "pages": [ - "integrations/secret-syncs/overview", - { - "group": "Syncs", - "pages": [ - "integrations/secret-syncs/1password", - "integrations/secret-syncs/aws-parameter-store", - "integrations/secret-syncs/aws-secrets-manager", - "integrations/secret-syncs/azure-app-configuration", - "integrations/secret-syncs/azure-devops", - "integrations/secret-syncs/azure-key-vault", - "integrations/secret-syncs/camunda", - "integrations/secret-syncs/databricks", - "integrations/secret-syncs/flyio", - "integrations/secret-syncs/gcp-secret-manager", - "integrations/secret-syncs/github", - "integrations/secret-syncs/gitlab", - "integrations/secret-syncs/hashicorp-vault", - "integrations/secret-syncs/heroku", - "integrations/secret-syncs/humanitec", - "integrations/secret-syncs/oci-vault", - "integrations/secret-syncs/render", - "integrations/secret-syncs/teamcity", - "integrations/secret-syncs/terraform-cloud", - "integrations/secret-syncs/vercel", - "integrations/secret-syncs/windmill" - ] - } - ] - }, - { - "group": "Native Integrations", - "pages": [ - { - "group": "AWS", - "pages": [ - "integrations/cloud/aws-parameter-store", - "integrations/cloud/aws-secret-manager", - "integrations/cloud/aws-amplify" - ] - }, - "integrations/cloud/vercel", - "integrations/cloud/azure-key-vault", - "integrations/cloud/azure-app-configuration", - "integrations/cloud/azure-devops", - "integrations/cloud/gcp-secret-manager", - { - "group": "Cloudflare", - "pages": [ - "integrations/cloud/cloudflare-pages", - "integrations/cloud/cloudflare-workers" - ] - }, - "integrations/cloud/terraform-cloud", - "integrations/cloud/databricks", - { - "group": "View more", - "pages": [ - "integrations/cloud/digital-ocean-app-platform", - "integrations/cloud/heroku", - "integrations/cloud/netlify", - "integrations/cloud/railway", - "integrations/cloud/flyio", - "integrations/cloud/render", - "integrations/cloud/laravel-forge", - "integrations/cloud/supabase", - "integrations/cloud/northflank", - "integrations/cloud/hasura-cloud", - "integrations/cloud/qovery", - "integrations/cloud/hashicorp-vault", - "integrations/cloud/cloud-66", - "integrations/cloud/windmill" - ] - } - ] - }, - { - "group": "CI/CD Integrations", - "pages": [ - "integrations/cicd/jenkins", - "integrations/cicd/githubactions", - "integrations/cicd/gitlab", - "integrations/cicd/bitbucket", - "integrations/cloud/teamcity", - { - "group": "View more", - "pages": [ - "integrations/cicd/circleci", - "integrations/cicd/travisci", - "integrations/cicd/rundeck", - "integrations/cicd/codefresh", - "integrations/cloud/checkly", - "integrations/cicd/octopus-deploy" - ] - } - ] - }, - { - "group": "Framework Integrations", - "pages": [ - "integrations/frameworks/spring-boot-maven", - "integrations/frameworks/react", - "integrations/frameworks/vue", - "integrations/frameworks/express", - { - "group": "View more", - "pages": [ - "integrations/frameworks/nextjs", - "integrations/frameworks/nestjs", - "integrations/frameworks/sveltekit", - "integrations/frameworks/nuxt", - "integrations/frameworks/gatsby", - "integrations/frameworks/remix", - "integrations/frameworks/vite", - "integrations/frameworks/fiber", - "integrations/frameworks/django", - "integrations/frameworks/flask", - "integrations/frameworks/laravel", - "integrations/frameworks/rails", - "integrations/frameworks/dotnet", - "integrations/platforms/pm2", - "integrations/frameworks/ab-initio" - ] - } - ] - }, - { - "group": "Build Tool Integrations", - "pages": ["integrations/build-tools/gradle"] - }, - { - "group": "Others", - "pages": ["integrations/external/backstage"] - }, - { - "group": "", - "pages": ["sdks/overview"] - }, - { - "group": "SDK's", - "pages": [ - "sdks/languages/node", - "sdks/languages/python", - "sdks/languages/java", - "sdks/languages/csharp", - "sdks/languages/go", - "sdks/languages/ruby" - ] - }, - { - "group": "Overview", - "pages": [ - "api-reference/overview/introduction", - "api-reference/overview/authentication", - { - "group": "Examples", - "pages": ["api-reference/overview/examples/integration"] - } - ] - }, - { - "group": "Endpoints", - "pages": [ - { - "group": "Identities", - "pages": [ - "api-reference/endpoints/identities/create", - "api-reference/endpoints/identities/update", - "api-reference/endpoints/identities/delete", - "api-reference/endpoints/identities/get-by-id", - "api-reference/endpoints/identities/list", - "api-reference/endpoints/identities/search" - ] - }, - { - "group": "Token Auth", - "pages": [ - "api-reference/endpoints/token-auth/attach", - "api-reference/endpoints/token-auth/retrieve", - "api-reference/endpoints/token-auth/update", - "api-reference/endpoints/token-auth/revoke", - "api-reference/endpoints/token-auth/get-tokens", - "api-reference/endpoints/token-auth/create-token", - "api-reference/endpoints/token-auth/update-token", - "api-reference/endpoints/token-auth/revoke-token" - ] - }, - { - "group": "Universal Auth", - "pages": [ - "api-reference/endpoints/universal-auth/login", - "api-reference/endpoints/universal-auth/attach", - "api-reference/endpoints/universal-auth/retrieve", - "api-reference/endpoints/universal-auth/update", - "api-reference/endpoints/universal-auth/revoke", - "api-reference/endpoints/universal-auth/create-client-secret", - "api-reference/endpoints/universal-auth/list-client-secrets", - "api-reference/endpoints/universal-auth/revoke-client-secret", - "api-reference/endpoints/universal-auth/get-client-secret-by-id", - "api-reference/endpoints/universal-auth/renew-access-token", - "api-reference/endpoints/universal-auth/revoke-access-token" - ] - }, - { - "group": "GCP Auth", - "pages": [ - "api-reference/endpoints/gcp-auth/login", - "api-reference/endpoints/gcp-auth/attach", - "api-reference/endpoints/gcp-auth/retrieve", - "api-reference/endpoints/gcp-auth/update", - "api-reference/endpoints/gcp-auth/revoke" - ] - }, - { - "group": "Alibaba Cloud Auth", - "pages": [ - "api-reference/endpoints/alicloud-auth/login", - "api-reference/endpoints/alicloud-auth/attach", - "api-reference/endpoints/alicloud-auth/retrieve", - "api-reference/endpoints/alicloud-auth/update", - "api-reference/endpoints/alicloud-auth/revoke" - ] - }, - { - "group": "AWS Auth", - "pages": [ - "api-reference/endpoints/aws-auth/login", - "api-reference/endpoints/aws-auth/attach", - "api-reference/endpoints/aws-auth/retrieve", - "api-reference/endpoints/aws-auth/update", - "api-reference/endpoints/aws-auth/revoke" - ] - }, - { - "group": "OCI Auth", - "pages": [ - "api-reference/endpoints/oci-auth/login", - "api-reference/endpoints/oci-auth/attach", - "api-reference/endpoints/oci-auth/retrieve", - "api-reference/endpoints/oci-auth/update", - "api-reference/endpoints/oci-auth/revoke" - ] - }, - { - "group": "Azure Auth", - "pages": [ - "api-reference/endpoints/azure-auth/login", - "api-reference/endpoints/azure-auth/attach", - "api-reference/endpoints/azure-auth/retrieve", - "api-reference/endpoints/azure-auth/update", - "api-reference/endpoints/azure-auth/revoke" - ] - }, - { - "group": "Kubernetes Auth", - "pages": [ - "api-reference/endpoints/kubernetes-auth/login", - "api-reference/endpoints/kubernetes-auth/attach", - "api-reference/endpoints/kubernetes-auth/retrieve", - "api-reference/endpoints/kubernetes-auth/update", - "api-reference/endpoints/kubernetes-auth/revoke" - ] - }, - { - "group": "OIDC Auth", - "pages": [ - "api-reference/endpoints/oidc-auth/login", - "api-reference/endpoints/oidc-auth/attach", - "api-reference/endpoints/oidc-auth/retrieve", - "api-reference/endpoints/oidc-auth/update", - "api-reference/endpoints/oidc-auth/revoke" - ] - }, - { - "group": "JWT Auth", - "pages": [ - "api-reference/endpoints/jwt-auth/login", - "api-reference/endpoints/jwt-auth/attach", - "api-reference/endpoints/jwt-auth/retrieve", - "api-reference/endpoints/jwt-auth/update", - "api-reference/endpoints/jwt-auth/revoke" - ] - }, - { - "group": "LDAP Auth", - "pages": [ - "api-reference/endpoints/ldap-auth/login", - "api-reference/endpoints/ldap-auth/attach", - "api-reference/endpoints/ldap-auth/retrieve", - "api-reference/endpoints/ldap-auth/update", - "api-reference/endpoints/ldap-auth/revoke" - ] - }, - { - "group": "Groups", - "pages": [ - "api-reference/endpoints/groups/create", - "api-reference/endpoints/groups/update", - "api-reference/endpoints/groups/delete", - "api-reference/endpoints/groups/get", - "api-reference/endpoints/groups/get-by-id", - "api-reference/endpoints/groups/add-group-user", - "api-reference/endpoints/groups/remove-group-user", - "api-reference/endpoints/groups/list-group-users" - ] - }, - { - "group": "Organizations", - "pages": [ - "api-reference/endpoints/organizations/memberships", - "api-reference/endpoints/organizations/update-membership", - "api-reference/endpoints/organizations/delete-membership", - "api-reference/endpoints/organizations/list-identity-memberships", - "api-reference/endpoints/organizations/workspaces" - ] - }, - { - "group": "Projects", - "pages": [ - "api-reference/endpoints/workspaces/create-workspace", - "api-reference/endpoints/workspaces/delete-workspace", - "api-reference/endpoints/workspaces/get-workspace", - "api-reference/endpoints/workspaces/update-workspace", - "api-reference/endpoints/workspaces/secret-snapshots" - ] - }, - { - "group": "Project Users", - "pages": [ - "api-reference/endpoints/project-users/invite-member-to-workspace", - "api-reference/endpoints/project-users/remove-member-from-workspace", - "api-reference/endpoints/project-users/memberships", - "api-reference/endpoints/project-users/get-by-username", - "api-reference/endpoints/project-users/update-membership" - ] - }, - { - "group": "Project Groups", - "pages": [ - "api-reference/endpoints/project-groups/create", - "api-reference/endpoints/project-groups/delete", - "api-reference/endpoints/project-groups/get-by-id", - "api-reference/endpoints/project-groups/list", - "api-reference/endpoints/project-groups/update" - ] - }, - { - "group": "Project Identities", - "pages": [ - "api-reference/endpoints/project-identities/add-identity-membership", - "api-reference/endpoints/project-identities/list-identity-memberships", - "api-reference/endpoints/project-identities/get-by-id", - "api-reference/endpoints/project-identities/update-identity-membership", - "api-reference/endpoints/project-identities/delete-identity-membership" - ] - }, - { - "group": "Project Roles", - "pages": [ - "api-reference/endpoints/project-roles/create", - "api-reference/endpoints/project-roles/update", - "api-reference/endpoints/project-roles/delete", - "api-reference/endpoints/project-roles/get-by-slug", - "api-reference/endpoints/project-roles/list" - ] - }, - { - "group": "Project Templates", - "pages": [ - "api-reference/endpoints/project-templates/create", - "api-reference/endpoints/project-templates/update", - "api-reference/endpoints/project-templates/delete", - "api-reference/endpoints/project-templates/get-by-id", - "api-reference/endpoints/project-templates/list" - ] - }, - { - "group": "Environments", - "pages": [ - "api-reference/endpoints/environments/create", - "api-reference/endpoints/environments/update", - "api-reference/endpoints/environments/delete" - ] - }, - { - "group": "Folders", - "pages": [ - "api-reference/endpoints/folders/list", - "api-reference/endpoints/folders/get-by-id", - "api-reference/endpoints/folders/create", - "api-reference/endpoints/folders/update", - "api-reference/endpoints/folders/delete" - ] - }, - { - "group": "Secret Tags", - "pages": [ - "api-reference/endpoints/secret-tags/list", - "api-reference/endpoints/secret-tags/get-by-id", - "api-reference/endpoints/secret-tags/get-by-slug", - "api-reference/endpoints/secret-tags/create", - "api-reference/endpoints/secret-tags/update", - "api-reference/endpoints/secret-tags/delete" - ] - }, - { - "group": "Secrets", - "pages": [ - "api-reference/endpoints/secrets/list", - "api-reference/endpoints/secrets/create", - "api-reference/endpoints/secrets/read", - "api-reference/endpoints/secrets/update", - "api-reference/endpoints/secrets/delete", - "api-reference/endpoints/secrets/create-many", - "api-reference/endpoints/secrets/update-many", - "api-reference/endpoints/secrets/delete-many", - "api-reference/endpoints/secrets/attach-tags", - "api-reference/endpoints/secrets/detach-tags" - ] - }, - { - "group": "Dynamic Secrets", - "pages": [ - { - "group": "Kubernetes", - "pages": [ - "api-reference/endpoints/dynamic-secrets/kubernetes/create-lease" - ] - }, - "api-reference/endpoints/dynamic-secrets/create", - "api-reference/endpoints/dynamic-secrets/update", - "api-reference/endpoints/dynamic-secrets/delete", - "api-reference/endpoints/dynamic-secrets/get", - "api-reference/endpoints/dynamic-secrets/list", - "api-reference/endpoints/dynamic-secrets/list-leases", - "api-reference/endpoints/dynamic-secrets/create-lease", - "api-reference/endpoints/dynamic-secrets/delete-lease", - "api-reference/endpoints/dynamic-secrets/renew-lease", - "api-reference/endpoints/dynamic-secrets/get-lease" - ] - }, - { - "group": "Secret Imports", - "pages": [ - "api-reference/endpoints/secret-imports/list", - "api-reference/endpoints/secret-imports/create", - "api-reference/endpoints/secret-imports/update", - "api-reference/endpoints/secret-imports/delete" - ] - }, - { - "group": "Secret Rotations", - "pages": [ - "api-reference/endpoints/secret-rotations/list", - "api-reference/endpoints/secret-rotations/options", - { - "group": "Auth0 Client Secret", - "pages": [ - "api-reference/endpoints/secret-rotations/auth0-client-secret/create", - "api-reference/endpoints/secret-rotations/auth0-client-secret/delete", - "api-reference/endpoints/secret-rotations/auth0-client-secret/get-by-id", - "api-reference/endpoints/secret-rotations/auth0-client-secret/get-by-name", - "api-reference/endpoints/secret-rotations/auth0-client-secret/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/auth0-client-secret/list", - "api-reference/endpoints/secret-rotations/auth0-client-secret/rotate-secrets", - "api-reference/endpoints/secret-rotations/auth0-client-secret/update" - ] - }, - { - "group": "AWS IAM User Secret", - "pages": [ - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/create", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/delete", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/get-by-id", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/get-by-name", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/list", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/rotate-secrets", - "api-reference/endpoints/secret-rotations/aws-iam-user-secret/update" - ] - }, - { - "group": "Azure Client Secret", - "pages": [ - "api-reference/endpoints/secret-rotations/azure-client-secret/create", - "api-reference/endpoints/secret-rotations/azure-client-secret/delete", - "api-reference/endpoints/secret-rotations/azure-client-secret/get-by-id", - "api-reference/endpoints/secret-rotations/azure-client-secret/get-by-name", - "api-reference/endpoints/secret-rotations/azure-client-secret/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/azure-client-secret/list", - "api-reference/endpoints/secret-rotations/azure-client-secret/rotate-secrets", - "api-reference/endpoints/secret-rotations/azure-client-secret/update" - ] - }, - { - "group": "LDAP Password", - "pages": [ - "api-reference/endpoints/secret-rotations/ldap-password/create", - "api-reference/endpoints/secret-rotations/ldap-password/delete", - "api-reference/endpoints/secret-rotations/ldap-password/get-by-id", - "api-reference/endpoints/secret-rotations/ldap-password/get-by-name", - "api-reference/endpoints/secret-rotations/ldap-password/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/ldap-password/list", - "api-reference/endpoints/secret-rotations/ldap-password/rotate-secrets", - "api-reference/endpoints/secret-rotations/ldap-password/update" - ] - }, - { - "group": "Microsoft SQL Server Credentials", - "pages": [ - "api-reference/endpoints/secret-rotations/mssql-credentials/create", - "api-reference/endpoints/secret-rotations/mssql-credentials/delete", - "api-reference/endpoints/secret-rotations/mssql-credentials/get-by-id", - "api-reference/endpoints/secret-rotations/mssql-credentials/get-by-name", - "api-reference/endpoints/secret-rotations/mssql-credentials/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/mssql-credentials/list", - "api-reference/endpoints/secret-rotations/mssql-credentials/rotate-secrets", - "api-reference/endpoints/secret-rotations/mssql-credentials/update" - ] - }, - { - "group": "MySQL Credentials", - "pages": [ - "api-reference/endpoints/secret-rotations/mysql-credentials/create", - "api-reference/endpoints/secret-rotations/mysql-credentials/delete", - "api-reference/endpoints/secret-rotations/mysql-credentials/get-by-id", - "api-reference/endpoints/secret-rotations/mysql-credentials/get-by-name", - "api-reference/endpoints/secret-rotations/mysql-credentials/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/mysql-credentials/list", - "api-reference/endpoints/secret-rotations/mysql-credentials/rotate-secrets", - "api-reference/endpoints/secret-rotations/mysql-credentials/update" - ] - }, - { - "group": "OracleDB Credentials", - "pages": [ - "api-reference/endpoints/secret-rotations/oracledb-credentials/create", - "api-reference/endpoints/secret-rotations/oracledb-credentials/delete", - "api-reference/endpoints/secret-rotations/oracledb-credentials/get-by-id", - "api-reference/endpoints/secret-rotations/oracledb-credentials/get-by-name", - "api-reference/endpoints/secret-rotations/oracledb-credentials/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/oracledb-credentials/list", - "api-reference/endpoints/secret-rotations/oracledb-credentials/rotate-secrets", - "api-reference/endpoints/secret-rotations/oracledb-credentials/update" - ] - }, - { - "group": "PostgreSQL Credentials", - "pages": [ - "api-reference/endpoints/secret-rotations/postgres-credentials/create", - "api-reference/endpoints/secret-rotations/postgres-credentials/delete", - "api-reference/endpoints/secret-rotations/postgres-credentials/get-by-id", - "api-reference/endpoints/secret-rotations/postgres-credentials/get-by-name", - "api-reference/endpoints/secret-rotations/postgres-credentials/get-generated-credentials-by-id", - "api-reference/endpoints/secret-rotations/postgres-credentials/list", - "api-reference/endpoints/secret-rotations/postgres-credentials/rotate-secrets", - "api-reference/endpoints/secret-rotations/postgres-credentials/update" - ] - } - ] - }, - { - "group": "Secret Scanning", - "pages": [ - { - "group": "Data Sources", - "pages": [ - "api-reference/endpoints/secret-scanning/data-sources/list", - "api-reference/endpoints/secret-scanning/data-sources/options", - { - "group": "GitHub", - "pages": [ - "api-reference/endpoints/secret-scanning/data-sources/github/list", - "api-reference/endpoints/secret-scanning/data-sources/github/get-by-id", - "api-reference/endpoints/secret-scanning/data-sources/github/get-by-name", - "api-reference/endpoints/secret-scanning/data-sources/github/list-resources", - "api-reference/endpoints/secret-scanning/data-sources/github/list-scans", - "api-reference/endpoints/secret-scanning/data-sources/github/create", - "api-reference/endpoints/secret-scanning/data-sources/github/update", - "api-reference/endpoints/secret-scanning/data-sources/github/delete", - "api-reference/endpoints/secret-scanning/data-sources/github/scan", - "api-reference/endpoints/secret-scanning/data-sources/github/scan-resource" - ] - } - ] - }, - { - "group": "Findings", - "pages": [ - "api-reference/endpoints/secret-scanning/findings/list", - "api-reference/endpoints/secret-scanning/findings/update" - ] - }, - { - "group": "Configuration", - "pages": [ - "api-reference/endpoints/secret-scanning/config/get-by-project-id", - "api-reference/endpoints/secret-scanning/config/update" - ] - } - ] - }, - { - "group": "Identity Specific Privilege", - "pages": [ - { - "group": "V1 (Legacy)", - "pages": [ - "api-reference/endpoints/identity-specific-privilege/v1/create-permanent", - "api-reference/endpoints/identity-specific-privilege/v1/create-temporary", - "api-reference/endpoints/identity-specific-privilege/v1/update", - "api-reference/endpoints/identity-specific-privilege/v1/delete", - "api-reference/endpoints/identity-specific-privilege/v1/find-by-slug", - "api-reference/endpoints/identity-specific-privilege/v1/list" - ] - }, - { - "group": "V2", - "pages": [ - "api-reference/endpoints/identity-specific-privilege/v2/create", - "api-reference/endpoints/identity-specific-privilege/v2/update", - "api-reference/endpoints/identity-specific-privilege/v2/delete", - "api-reference/endpoints/identity-specific-privilege/v2/list", - "api-reference/endpoints/identity-specific-privilege/v2/find-by-id", - "api-reference/endpoints/identity-specific-privilege/v2/find-by-slug" - ] - } - ] - }, - { - "group": "App Connections", - "pages": [ - "api-reference/endpoints/app-connections/list", - "api-reference/endpoints/app-connections/options", - { - "group": "1Password", - "pages": [ - "api-reference/endpoints/app-connections/1password/list", - "api-reference/endpoints/app-connections/1password/available", - "api-reference/endpoints/app-connections/1password/get-by-id", - "api-reference/endpoints/app-connections/1password/get-by-name", - "api-reference/endpoints/app-connections/1password/create", - "api-reference/endpoints/app-connections/1password/update", - "api-reference/endpoints/app-connections/1password/delete" - ] - }, - { - "group": "Auth0", - "pages": [ - "api-reference/endpoints/app-connections/auth0/list", - "api-reference/endpoints/app-connections/auth0/available", - "api-reference/endpoints/app-connections/auth0/get-by-id", - "api-reference/endpoints/app-connections/auth0/get-by-name", - "api-reference/endpoints/app-connections/auth0/create", - "api-reference/endpoints/app-connections/auth0/update", - "api-reference/endpoints/app-connections/auth0/delete" - ] - }, - { - "group": "AWS", - "pages": [ - "api-reference/endpoints/app-connections/aws/list", - "api-reference/endpoints/app-connections/aws/available", - "api-reference/endpoints/app-connections/aws/get-by-id", - "api-reference/endpoints/app-connections/aws/get-by-name", - "api-reference/endpoints/app-connections/aws/create", - "api-reference/endpoints/app-connections/aws/update", - "api-reference/endpoints/app-connections/aws/delete" - ] - }, - { - "group": "Azure App Configuration", - "pages": [ - "api-reference/endpoints/app-connections/azure-app-configuration/list", - "api-reference/endpoints/app-connections/azure-app-configuration/available", - "api-reference/endpoints/app-connections/azure-app-configuration/get-by-id", - "api-reference/endpoints/app-connections/azure-app-configuration/get-by-name", - "api-reference/endpoints/app-connections/azure-app-configuration/create", - "api-reference/endpoints/app-connections/azure-app-configuration/update", - "api-reference/endpoints/app-connections/azure-app-configuration/delete" - ] - }, - { - "group": "Azure Client Secret", - "pages": [ - "api-reference/endpoints/app-connections/azure-client-secret/list", - "api-reference/endpoints/app-connections/azure-client-secret/available", - "api-reference/endpoints/app-connections/azure-client-secret/get-by-id", - "api-reference/endpoints/app-connections/azure-client-secret/get-by-name", - "api-reference/endpoints/app-connections/azure-client-secret/create", - "api-reference/endpoints/app-connections/azure-client-secret/update", - "api-reference/endpoints/app-connections/azure-client-secret/delete" - ] - }, - { - "group": "Azure DevOps", - "pages": [ - "api-reference/endpoints/app-connections/azure-devops/list", - "api-reference/endpoints/app-connections/azure-devops/available", - "api-reference/endpoints/app-connections/azure-devops/get-by-id", - "api-reference/endpoints/app-connections/azure-devops/get-by-name", - "api-reference/endpoints/app-connections/azure-devops/create", - "api-reference/endpoints/app-connections/azure-devops/update", - "api-reference/endpoints/app-connections/azure-devops/delete" - ] - }, - { - "group": "Azure Key Vault", - "pages": [ - "api-reference/endpoints/app-connections/azure-key-vault/list", - "api-reference/endpoints/app-connections/azure-key-vault/available", - "api-reference/endpoints/app-connections/azure-key-vault/get-by-id", - "api-reference/endpoints/app-connections/azure-key-vault/get-by-name", - "api-reference/endpoints/app-connections/azure-key-vault/create", - "api-reference/endpoints/app-connections/azure-key-vault/update", - "api-reference/endpoints/app-connections/azure-key-vault/delete" - ] - }, - { - "group": "Camunda", - "pages": [ - "api-reference/endpoints/app-connections/camunda/list", - "api-reference/endpoints/app-connections/camunda/available", - "api-reference/endpoints/app-connections/camunda/get-by-id", - "api-reference/endpoints/app-connections/camunda/get-by-name", - "api-reference/endpoints/app-connections/camunda/create", - "api-reference/endpoints/app-connections/camunda/update", - "api-reference/endpoints/app-connections/camunda/delete" - ] - }, - { - "group": "Databricks", - "pages": [ - "api-reference/endpoints/app-connections/databricks/list", - "api-reference/endpoints/app-connections/databricks/available", - "api-reference/endpoints/app-connections/databricks/get-by-id", - "api-reference/endpoints/app-connections/databricks/get-by-name", - "api-reference/endpoints/app-connections/databricks/create", - "api-reference/endpoints/app-connections/databricks/update", - "api-reference/endpoints/app-connections/databricks/delete" - ] - }, - { - "group": "Fly.io", - "pages": [ - "api-reference/endpoints/app-connections/flyio/list", - "api-reference/endpoints/app-connections/flyio/available", - "api-reference/endpoints/app-connections/flyio/get-by-id", - "api-reference/endpoints/app-connections/flyio/get-by-name", - "api-reference/endpoints/app-connections/flyio/create", - "api-reference/endpoints/app-connections/flyio/update", - "api-reference/endpoints/app-connections/flyio/delete" - ] - }, - { - "group": "GCP", - "pages": [ - "api-reference/endpoints/app-connections/gcp/list", - "api-reference/endpoints/app-connections/gcp/available", - "api-reference/endpoints/app-connections/gcp/get-by-id", - "api-reference/endpoints/app-connections/gcp/get-by-name", - "api-reference/endpoints/app-connections/gcp/create", - "api-reference/endpoints/app-connections/gcp/update", - "api-reference/endpoints/app-connections/gcp/delete" - ] - }, - { - "group": "GitHub", - "pages": [ - "api-reference/endpoints/app-connections/github/list", - "api-reference/endpoints/app-connections/github/available", - "api-reference/endpoints/app-connections/github/get-by-id", - "api-reference/endpoints/app-connections/github/get-by-name", - "api-reference/endpoints/app-connections/github/create", - "api-reference/endpoints/app-connections/github/update", - "api-reference/endpoints/app-connections/github/delete" - ] - }, - { - "group": "GitLab", - "pages": [ - "api-reference/endpoints/app-connections/gitlab/list", - "api-reference/endpoints/app-connections/gitlab/available", - "api-reference/endpoints/app-connections/gitlab/get-by-id", - "api-reference/endpoints/app-connections/gitlab/get-by-name", - "api-reference/endpoints/app-connections/gitlab/create", - "api-reference/endpoints/app-connections/gitlab/update", - "api-reference/endpoints/app-connections/gitlab/delete" - ] - }, - { - "group": "GitHub Radar", - "pages": [ - "api-reference/endpoints/app-connections/github-radar/list", - "api-reference/endpoints/app-connections/github-radar/available", - "api-reference/endpoints/app-connections/github-radar/get-by-id", - "api-reference/endpoints/app-connections/github-radar/get-by-name", - "api-reference/endpoints/app-connections/github-radar/create", - "api-reference/endpoints/app-connections/github-radar/update", - "api-reference/endpoints/app-connections/github-radar/delete" - ] - }, - { - "group": "Hashicorp Vault", - "pages": [ - "api-reference/endpoints/app-connections/hashicorp-vault/list", - "api-reference/endpoints/app-connections/hashicorp-vault/available", - "api-reference/endpoints/app-connections/hashicorp-vault/get-by-id", - "api-reference/endpoints/app-connections/hashicorp-vault/get-by-name", - "api-reference/endpoints/app-connections/hashicorp-vault/create", - "api-reference/endpoints/app-connections/hashicorp-vault/update", - "api-reference/endpoints/app-connections/hashicorp-vault/delete" - ] - }, - { - "group": "Heroku", - "pages": [ - "api-reference/endpoints/app-connections/heroku/list", - "api-reference/endpoints/app-connections/heroku/available", - "api-reference/endpoints/app-connections/heroku/get-by-id", - "api-reference/endpoints/app-connections/heroku/get-by-name", - "api-reference/endpoints/app-connections/heroku/create", - "api-reference/endpoints/app-connections/heroku/update", - "api-reference/endpoints/app-connections/heroku/delete" - ] - }, - { - "group": "Humanitec", - "pages": [ - "api-reference/endpoints/app-connections/humanitec/list", - "api-reference/endpoints/app-connections/humanitec/available", - "api-reference/endpoints/app-connections/humanitec/get-by-id", - "api-reference/endpoints/app-connections/humanitec/get-by-name", - "api-reference/endpoints/app-connections/humanitec/create", - "api-reference/endpoints/app-connections/humanitec/update", - "api-reference/endpoints/app-connections/humanitec/delete" - ] - }, - { - "group": "LDAP", - "pages": [ - "api-reference/endpoints/app-connections/ldap/list", - "api-reference/endpoints/app-connections/ldap/available", - "api-reference/endpoints/app-connections/ldap/get-by-id", - "api-reference/endpoints/app-connections/ldap/get-by-name", - "api-reference/endpoints/app-connections/ldap/create", - "api-reference/endpoints/app-connections/ldap/update", - "api-reference/endpoints/app-connections/ldap/delete" - ] - }, - { - "group": "Microsoft SQL Server", - "pages": [ - "api-reference/endpoints/app-connections/mssql/list", - "api-reference/endpoints/app-connections/mssql/available", - "api-reference/endpoints/app-connections/mssql/get-by-id", - "api-reference/endpoints/app-connections/mssql/get-by-name", - "api-reference/endpoints/app-connections/mssql/create", - "api-reference/endpoints/app-connections/mssql/update", - "api-reference/endpoints/app-connections/mssql/delete" - ] - }, - { - "group": "MySQL", - "pages": [ - "api-reference/endpoints/app-connections/mysql/list", - "api-reference/endpoints/app-connections/mysql/available", - "api-reference/endpoints/app-connections/mysql/get-by-id", - "api-reference/endpoints/app-connections/mysql/get-by-name", - "api-reference/endpoints/app-connections/mysql/create", - "api-reference/endpoints/app-connections/mysql/update", - "api-reference/endpoints/app-connections/mysql/delete" - ] - }, - { - "group": "OCI", - "pages": [ - "api-reference/endpoints/app-connections/oci/list", - "api-reference/endpoints/app-connections/oci/available", - "api-reference/endpoints/app-connections/oci/get-by-id", - "api-reference/endpoints/app-connections/oci/get-by-name", - "api-reference/endpoints/app-connections/oci/create", - "api-reference/endpoints/app-connections/oci/update", - "api-reference/endpoints/app-connections/oci/delete" - ] - }, - { - "group": "OracleDB", - "pages": [ - "api-reference/endpoints/app-connections/oracledb/list", - "api-reference/endpoints/app-connections/oracledb/available", - "api-reference/endpoints/app-connections/oracledb/get-by-id", - "api-reference/endpoints/app-connections/oracledb/get-by-name", - "api-reference/endpoints/app-connections/oracledb/create", - "api-reference/endpoints/app-connections/oracledb/update", - "api-reference/endpoints/app-connections/oracledb/delete" - ] - }, - { - "group": "PostgreSQL", - "pages": [ - "api-reference/endpoints/app-connections/postgres/list", - "api-reference/endpoints/app-connections/postgres/available", - "api-reference/endpoints/app-connections/postgres/get-by-id", - "api-reference/endpoints/app-connections/postgres/get-by-name", - "api-reference/endpoints/app-connections/postgres/create", - "api-reference/endpoints/app-connections/postgres/update", - "api-reference/endpoints/app-connections/postgres/delete" - ] - }, - { - "group": "Render", - "pages": [ - "api-reference/endpoints/app-connections/render/list", - "api-reference/endpoints/app-connections/render/available", - "api-reference/endpoints/app-connections/render/get-by-id", - "api-reference/endpoints/app-connections/render/get-by-name", - "api-reference/endpoints/app-connections/render/create", - "api-reference/endpoints/app-connections/render/update", - "api-reference/endpoints/app-connections/render/delete" - ] - }, - { - "group": "TeamCity", - "pages": [ - "api-reference/endpoints/app-connections/teamcity/list", - "api-reference/endpoints/app-connections/teamcity/available", - "api-reference/endpoints/app-connections/teamcity/get-by-id", - "api-reference/endpoints/app-connections/teamcity/get-by-name", - "api-reference/endpoints/app-connections/teamcity/create", - "api-reference/endpoints/app-connections/teamcity/update", - "api-reference/endpoints/app-connections/teamcity/delete" - ] - }, - { - "group": "Terraform Cloud", - "pages": [ - "api-reference/endpoints/app-connections/terraform-cloud/list", - "api-reference/endpoints/app-connections/terraform-cloud/available", - "api-reference/endpoints/app-connections/terraform-cloud/get-by-id", - "api-reference/endpoints/app-connections/terraform-cloud/get-by-name", - "api-reference/endpoints/app-connections/terraform-cloud/create", - "api-reference/endpoints/app-connections/terraform-cloud/update", - "api-reference/endpoints/app-connections/terraform-cloud/delete" - ] - }, - { - "group": "Vercel", - "pages": [ - "api-reference/endpoints/app-connections/vercel/list", - "api-reference/endpoints/app-connections/vercel/available", - "api-reference/endpoints/app-connections/vercel/get-by-id", - "api-reference/endpoints/app-connections/vercel/get-by-name", - "api-reference/endpoints/app-connections/vercel/create", - "api-reference/endpoints/app-connections/vercel/update", - "api-reference/endpoints/app-connections/vercel/delete" - ] - }, - { - "group": "Windmill", - "pages": [ - "api-reference/endpoints/app-connections/windmill/list", - "api-reference/endpoints/app-connections/windmill/available", - "api-reference/endpoints/app-connections/windmill/get-by-id", - "api-reference/endpoints/app-connections/windmill/get-by-name", - "api-reference/endpoints/app-connections/windmill/create", - "api-reference/endpoints/app-connections/windmill/update", - "api-reference/endpoints/app-connections/windmill/delete" - ] - } - ] - }, - { - "group": "Secret Syncs", - "pages": [ - "api-reference/endpoints/secret-syncs/list", - "api-reference/endpoints/secret-syncs/options", - { - "group": "1Password", - "pages": [ - "api-reference/endpoints/secret-syncs/1password/list", - "api-reference/endpoints/secret-syncs/1password/get-by-id", - "api-reference/endpoints/secret-syncs/1password/get-by-name", - "api-reference/endpoints/secret-syncs/1password/create", - "api-reference/endpoints/secret-syncs/1password/update", - "api-reference/endpoints/secret-syncs/1password/delete", - "api-reference/endpoints/secret-syncs/1password/sync-secrets", - "api-reference/endpoints/secret-syncs/1password/import-secrets", - "api-reference/endpoints/secret-syncs/1password/remove-secrets" - ] - }, - { - "group": "AWS Parameter Store", - "pages": [ - "api-reference/endpoints/secret-syncs/aws-parameter-store/list", - "api-reference/endpoints/secret-syncs/aws-parameter-store/get-by-id", - "api-reference/endpoints/secret-syncs/aws-parameter-store/get-by-name", - "api-reference/endpoints/secret-syncs/aws-parameter-store/create", - "api-reference/endpoints/secret-syncs/aws-parameter-store/update", - "api-reference/endpoints/secret-syncs/aws-parameter-store/delete", - "api-reference/endpoints/secret-syncs/aws-parameter-store/sync-secrets", - "api-reference/endpoints/secret-syncs/aws-parameter-store/import-secrets", - "api-reference/endpoints/secret-syncs/aws-parameter-store/remove-secrets" - ] - }, - { - "group": "AWS Secrets Manager", - "pages": [ - "api-reference/endpoints/secret-syncs/aws-secrets-manager/list", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/get-by-id", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/get-by-name", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/create", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/update", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/delete", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/sync-secrets", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/import-secrets", - "api-reference/endpoints/secret-syncs/aws-secrets-manager/remove-secrets" - ] - }, - { - "group": "Azure App Configuration", - "pages": [ - "api-reference/endpoints/secret-syncs/azure-app-configuration/list", - "api-reference/endpoints/secret-syncs/azure-app-configuration/get-by-id", - "api-reference/endpoints/secret-syncs/azure-app-configuration/get-by-name", - "api-reference/endpoints/secret-syncs/azure-app-configuration/create", - "api-reference/endpoints/secret-syncs/azure-app-configuration/update", - "api-reference/endpoints/secret-syncs/azure-app-configuration/delete", - "api-reference/endpoints/secret-syncs/azure-app-configuration/sync-secrets", - "api-reference/endpoints/secret-syncs/azure-app-configuration/import-secrets", - "api-reference/endpoints/secret-syncs/azure-app-configuration/remove-secrets" - ] - }, - { - "group": "Azure DevOps", - "pages": [ - "api-reference/endpoints/secret-syncs/azure-devops/list", - "api-reference/endpoints/secret-syncs/azure-devops/get-by-id", - "api-reference/endpoints/secret-syncs/azure-devops/get-by-name", - "api-reference/endpoints/secret-syncs/azure-devops/create", - "api-reference/endpoints/secret-syncs/azure-devops/update", - "api-reference/endpoints/secret-syncs/azure-devops/delete", - "api-reference/endpoints/secret-syncs/azure-devops/sync-secrets", - "api-reference/endpoints/secret-syncs/azure-devops/import-secrets", - "api-reference/endpoints/secret-syncs/azure-devops/remove-secrets" - ] - }, - { - "group": "Azure Key Vault", - "pages": [ - "api-reference/endpoints/secret-syncs/azure-key-vault/list", - "api-reference/endpoints/secret-syncs/azure-key-vault/get-by-id", - "api-reference/endpoints/secret-syncs/azure-key-vault/get-by-name", - "api-reference/endpoints/secret-syncs/azure-key-vault/create", - "api-reference/endpoints/secret-syncs/azure-key-vault/update", - "api-reference/endpoints/secret-syncs/azure-key-vault/delete", - "api-reference/endpoints/secret-syncs/azure-key-vault/sync-secrets", - "api-reference/endpoints/secret-syncs/azure-key-vault/import-secrets", - "api-reference/endpoints/secret-syncs/azure-key-vault/remove-secrets" - ] - }, - { - "group": "Camunda", - "pages": [ - "api-reference/endpoints/secret-syncs/camunda/list", - "api-reference/endpoints/secret-syncs/camunda/get-by-id", - "api-reference/endpoints/secret-syncs/camunda/get-by-name", - "api-reference/endpoints/secret-syncs/camunda/create", - "api-reference/endpoints/secret-syncs/camunda/update", - "api-reference/endpoints/secret-syncs/camunda/delete", - "api-reference/endpoints/secret-syncs/camunda/sync-secrets", - "api-reference/endpoints/secret-syncs/camunda/remove-secrets" - ] - }, - { - "group": "Databricks", - "pages": [ - "api-reference/endpoints/secret-syncs/databricks/list", - "api-reference/endpoints/secret-syncs/databricks/get-by-id", - "api-reference/endpoints/secret-syncs/databricks/get-by-name", - "api-reference/endpoints/secret-syncs/databricks/create", - "api-reference/endpoints/secret-syncs/databricks/update", - "api-reference/endpoints/secret-syncs/databricks/delete", - "api-reference/endpoints/secret-syncs/databricks/sync-secrets", - "api-reference/endpoints/secret-syncs/databricks/remove-secrets" - ] - }, - { - "group": "Fly.io", - "pages": [ - "api-reference/endpoints/secret-syncs/flyio/list", - "api-reference/endpoints/secret-syncs/flyio/get-by-id", - "api-reference/endpoints/secret-syncs/flyio/get-by-name", - "api-reference/endpoints/secret-syncs/flyio/create", - "api-reference/endpoints/secret-syncs/flyio/update", - "api-reference/endpoints/secret-syncs/flyio/delete", - "api-reference/endpoints/secret-syncs/flyio/sync-secrets", - "api-reference/endpoints/secret-syncs/flyio/remove-secrets" - ] - }, - { - "group": "GCP Secret Manager", - "pages": [ - "api-reference/endpoints/secret-syncs/gcp-secret-manager/list", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/get-by-id", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/get-by-name", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/create", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/update", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/delete", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/sync-secrets", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/import-secrets", - "api-reference/endpoints/secret-syncs/gcp-secret-manager/remove-secrets" - ] - }, - { - "group": "GitHub", - "pages": [ - "api-reference/endpoints/secret-syncs/github/list", - "api-reference/endpoints/secret-syncs/github/get-by-id", - "api-reference/endpoints/secret-syncs/github/get-by-name", - "api-reference/endpoints/secret-syncs/github/create", - "api-reference/endpoints/secret-syncs/github/update", - "api-reference/endpoints/secret-syncs/github/delete", - "api-reference/endpoints/secret-syncs/github/sync-secrets", - "api-reference/endpoints/secret-syncs/github/remove-secrets" - ] - }, - { - "group": "GitLab", - "pages": [ - "api-reference/endpoints/secret-syncs/gitlab/list", - "api-reference/endpoints/secret-syncs/gitlab/get-by-id", - "api-reference/endpoints/secret-syncs/gitlab/get-by-name", - "api-reference/endpoints/secret-syncs/gitlab/create", - "api-reference/endpoints/secret-syncs/gitlab/update", - "api-reference/endpoints/secret-syncs/gitlab/delete", - "api-reference/endpoints/secret-syncs/gitlab/sync-secrets", - "api-reference/endpoints/secret-syncs/gitlab/remove-secrets" - ] - }, - { - "group": "Hashicorp Vault", - "pages": [ - "api-reference/endpoints/secret-syncs/hashicorp-vault/list", - "api-reference/endpoints/secret-syncs/hashicorp-vault/get-by-id", - "api-reference/endpoints/secret-syncs/hashicorp-vault/get-by-name", - "api-reference/endpoints/secret-syncs/hashicorp-vault/create", - "api-reference/endpoints/secret-syncs/hashicorp-vault/update", - "api-reference/endpoints/secret-syncs/hashicorp-vault/delete", - "api-reference/endpoints/secret-syncs/hashicorp-vault/sync-secrets", - "api-reference/endpoints/secret-syncs/hashicorp-vault/import-secrets", - "api-reference/endpoints/secret-syncs/hashicorp-vault/remove-secrets" - ] - }, - { - "group": "Heroku", - "pages": [ - "api-reference/endpoints/secret-syncs/heroku/list", - "api-reference/endpoints/secret-syncs/heroku/get-by-id", - "api-reference/endpoints/secret-syncs/heroku/get-by-name", - "api-reference/endpoints/secret-syncs/heroku/create", - "api-reference/endpoints/secret-syncs/heroku/update", - "api-reference/endpoints/secret-syncs/heroku/delete", - "api-reference/endpoints/secret-syncs/heroku/sync-secrets", - "api-reference/endpoints/secret-syncs/heroku/remove-secrets" - ] - }, - { - "group": "Humanitec", - "pages": [ - "api-reference/endpoints/secret-syncs/humanitec/list", - "api-reference/endpoints/secret-syncs/humanitec/get-by-id", - "api-reference/endpoints/secret-syncs/humanitec/get-by-name", - "api-reference/endpoints/secret-syncs/humanitec/create", - "api-reference/endpoints/secret-syncs/humanitec/update", - "api-reference/endpoints/secret-syncs/humanitec/delete", - "api-reference/endpoints/secret-syncs/humanitec/sync-secrets", - "api-reference/endpoints/secret-syncs/humanitec/remove-secrets" - ] - }, - { - "group": "OCI", - "pages": [ - "api-reference/endpoints/secret-syncs/oci-vault/list", - "api-reference/endpoints/secret-syncs/oci-vault/get-by-id", - "api-reference/endpoints/secret-syncs/oci-vault/get-by-name", - "api-reference/endpoints/secret-syncs/oci-vault/create", - "api-reference/endpoints/secret-syncs/oci-vault/update", - "api-reference/endpoints/secret-syncs/oci-vault/delete", - "api-reference/endpoints/secret-syncs/oci-vault/sync-secrets", - "api-reference/endpoints/secret-syncs/oci-vault/import-secrets", - "api-reference/endpoints/secret-syncs/oci-vault/remove-secrets" - ] - }, - { - "group": "Render", - "pages": [ - "api-reference/endpoints/secret-syncs/render/list", - "api-reference/endpoints/secret-syncs/render/get-by-id", - "api-reference/endpoints/secret-syncs/render/get-by-name", - "api-reference/endpoints/secret-syncs/render/create", - "api-reference/endpoints/secret-syncs/render/update", - "api-reference/endpoints/secret-syncs/render/delete", - "api-reference/endpoints/secret-syncs/render/sync-secrets", - "api-reference/endpoints/secret-syncs/render/import-secrets", - "api-reference/endpoints/secret-syncs/render/remove-secrets" - ] - }, - { - "group": "TeamCity", - "pages": [ - "api-reference/endpoints/secret-syncs/teamcity/list", - "api-reference/endpoints/secret-syncs/teamcity/get-by-id", - "api-reference/endpoints/secret-syncs/teamcity/get-by-name", - "api-reference/endpoints/secret-syncs/teamcity/create", - "api-reference/endpoints/secret-syncs/teamcity/update", - "api-reference/endpoints/secret-syncs/teamcity/delete", - "api-reference/endpoints/secret-syncs/teamcity/sync-secrets", - "api-reference/endpoints/secret-syncs/teamcity/import-secrets", - "api-reference/endpoints/secret-syncs/teamcity/remove-secrets" - ] - }, - { - "group": "Terraform Cloud", - "pages": [ - "api-reference/endpoints/secret-syncs/terraform-cloud/list", - "api-reference/endpoints/secret-syncs/terraform-cloud/get-by-id", - "api-reference/endpoints/secret-syncs/terraform-cloud/get-by-name", - "api-reference/endpoints/secret-syncs/terraform-cloud/create", - "api-reference/endpoints/secret-syncs/terraform-cloud/update", - "api-reference/endpoints/secret-syncs/terraform-cloud/delete", - "api-reference/endpoints/secret-syncs/terraform-cloud/sync-secrets", - "api-reference/endpoints/secret-syncs/terraform-cloud/remove-secrets" - ] - }, - { - "group": "Vercel", - "pages": [ - "api-reference/endpoints/secret-syncs/vercel/list", - "api-reference/endpoints/secret-syncs/vercel/get-by-id", - "api-reference/endpoints/secret-syncs/vercel/get-by-name", - "api-reference/endpoints/secret-syncs/vercel/create", - "api-reference/endpoints/secret-syncs/vercel/update", - "api-reference/endpoints/secret-syncs/vercel/delete", - "api-reference/endpoints/secret-syncs/vercel/sync-secrets", - "api-reference/endpoints/secret-syncs/vercel/import-secrets", - "api-reference/endpoints/secret-syncs/vercel/remove-secrets" - ] - }, - { - "group": "Windmill", - "pages": [ - "api-reference/endpoints/secret-syncs/windmill/list", - "api-reference/endpoints/secret-syncs/windmill/get-by-id", - "api-reference/endpoints/secret-syncs/windmill/get-by-name", - "api-reference/endpoints/secret-syncs/windmill/create", - "api-reference/endpoints/secret-syncs/windmill/update", - "api-reference/endpoints/secret-syncs/windmill/delete", - "api-reference/endpoints/secret-syncs/windmill/sync-secrets", - "api-reference/endpoints/secret-syncs/windmill/import-secrets", - "api-reference/endpoints/secret-syncs/windmill/remove-secrets" - ] - } - ] - }, - { - "group": "Integrations", - "pages": [ - "api-reference/endpoints/integrations/create-auth", - "api-reference/endpoints/integrations/list-auth", - "api-reference/endpoints/integrations/find-auth", - "api-reference/endpoints/integrations/delete-auth", - "api-reference/endpoints/integrations/delete-auth-by-id", - "api-reference/endpoints/integrations/create", - "api-reference/endpoints/integrations/update", - "api-reference/endpoints/integrations/delete", - "api-reference/endpoints/integrations/list-project-integrations" - ] - }, - { - "group": "Service Tokens", - "pages": ["api-reference/endpoints/service-tokens/get"] - }, - { - "group": "Audit Logs", - "pages": ["api-reference/endpoints/audit-logs/export-audit-log"] - } - ] - }, - { - "group": "Infisical PKI", - "pages": [ - { - "group": "Subscribers", - "pages": [ - "api-reference/endpoints/pki/subscribers/list-certs", - "api-reference/endpoints/pki/subscribers/create", - "api-reference/endpoints/pki/subscribers/read", - "api-reference/endpoints/pki/subscribers/update", - "api-reference/endpoints/pki/subscribers/delete", - "api-reference/endpoints/pki/subscribers/issue-cert", - "api-reference/endpoints/pki/subscribers/sign-cert", - "api-reference/endpoints/pki/subscribers/order-cert", - "api-reference/endpoints/pki/subscribers/get-latest-cert-bundle" - ] - }, - { - "group": "Certificate Authorities", - "pages": [ - { - "group": "ACME", - "pages": [ - "api-reference/endpoints/certificate-authorities/acme/list", - "api-reference/endpoints/certificate-authorities/acme/create", - "api-reference/endpoints/certificate-authorities/acme/read", - "api-reference/endpoints/certificate-authorities/acme/update", - "api-reference/endpoints/certificate-authorities/acme/delete" - ] - }, - { - "group": "Internal", - "pages": [ - "api-reference/endpoints/certificate-authorities/internal/list", - "api-reference/endpoints/certificate-authorities/internal/create", - "api-reference/endpoints/certificate-authorities/internal/read", - "api-reference/endpoints/certificate-authorities/internal/update", - "api-reference/endpoints/certificate-authorities/internal/delete" - ] - }, - "api-reference/endpoints/certificate-authorities/list", - "api-reference/endpoints/certificate-authorities/create", - "api-reference/endpoints/certificate-authorities/read", - "api-reference/endpoints/certificate-authorities/update", - "api-reference/endpoints/certificate-authorities/delete", - "api-reference/endpoints/certificate-authorities/renew", - "api-reference/endpoints/certificate-authorities/list-ca-certs", - "api-reference/endpoints/certificate-authorities/csr", - "api-reference/endpoints/certificate-authorities/cert", - "api-reference/endpoints/certificate-authorities/sign-intermediate", - "api-reference/endpoints/certificate-authorities/import-cert", - "api-reference/endpoints/certificate-authorities/issue-cert", - "api-reference/endpoints/certificate-authorities/sign-cert", - "api-reference/endpoints/certificate-authorities/crl" - ] - }, - { - "group": "Certificates", - "pages": [ - "api-reference/endpoints/certificates/list", - "api-reference/endpoints/certificates/read", - "api-reference/endpoints/certificates/revoke", - "api-reference/endpoints/certificates/delete", - "api-reference/endpoints/certificates/cert-body", - "api-reference/endpoints/certificates/bundle", - "api-reference/endpoints/certificates/private-key", - "api-reference/endpoints/certificates/issue-certificate", - "api-reference/endpoints/certificates/sign-certificate" - ] - }, - { - "group": "Certificate Templates", - "pages": [ - "api-reference/endpoints/certificate-templates/create", - "api-reference/endpoints/certificate-templates/update", - "api-reference/endpoints/certificate-templates/get-by-id", - "api-reference/endpoints/certificate-templates/delete" - ] - }, - { - "group": "Certificate Collections", - "pages": [ - "api-reference/endpoints/pki-collections/create", - "api-reference/endpoints/pki-collections/read", - "api-reference/endpoints/pki-collections/update", - "api-reference/endpoints/pki-collections/delete", - "api-reference/endpoints/pki-collections/add-item", - "api-reference/endpoints/pki-collections/list-items", - "api-reference/endpoints/pki-collections/delete-item" - ] - }, - { - "group": "PKI Alerting", - "pages": [ - "api-reference/endpoints/pki-alerts/create", - "api-reference/endpoints/pki-alerts/read", - "api-reference/endpoints/pki-alerts/update", - "api-reference/endpoints/pki-alerts/delete" - ] - } - ] - }, - { - "group": "Infisical SSH", - "pages": [ - { - "group": "Hosts", - "pages": [ - "api-reference/endpoints/ssh/hosts/list-my", - "api-reference/endpoints/ssh/hosts/list", - "api-reference/endpoints/ssh/hosts/create", - "api-reference/endpoints/ssh/hosts/read", - "api-reference/endpoints/ssh/hosts/update", - "api-reference/endpoints/ssh/hosts/delete", - "api-reference/endpoints/ssh/hosts/issue-host-cert", - "api-reference/endpoints/ssh/hosts/issue-user-cert", - "api-reference/endpoints/ssh/hosts/read-user-ca-pk", - "api-reference/endpoints/ssh/hosts/read-host-ca-pk" - ] - }, - { - "group": "Host Groups", - "pages": [ - "api-reference/endpoints/ssh/groups/list", - "api-reference/endpoints/ssh/groups/create", - "api-reference/endpoints/ssh/groups/read", - "api-reference/endpoints/ssh/groups/update", - "api-reference/endpoints/ssh/groups/delete", - "api-reference/endpoints/ssh/groups/add-host", - "api-reference/endpoints/ssh/groups/list-hosts", - "api-reference/endpoints/ssh/groups/remove-host" - ] - }, - { - "group": "Certificates", - "pages": [ - "api-reference/endpoints/ssh/certificates/issue-credentials", - "api-reference/endpoints/ssh/certificates/sign-key" - ] - }, - { - "group": "Certificate Authorities", - "pages": [ - "api-reference/endpoints/ssh/ca/list", - "api-reference/endpoints/ssh/ca/create", - "api-reference/endpoints/ssh/ca/read", - "api-reference/endpoints/ssh/ca/update", - "api-reference/endpoints/ssh/ca/delete", - "api-reference/endpoints/ssh/ca/public-key", - "api-reference/endpoints/ssh/ca/list-certificate-templates" - ] - }, - { - "group": "Certificate Templates", - "pages": [ - "api-reference/endpoints/ssh/certificate-templates/list", - "api-reference/endpoints/ssh/certificate-templates/create", - "api-reference/endpoints/ssh/certificate-templates/read", - "api-reference/endpoints/ssh/certificate-templates/update", - "api-reference/endpoints/ssh/certificate-templates/delete" - ] - } - ] - }, - { - "group": "Infisical KMS", - "pages": [ - { - "group": "Keys", - "pages": [ - "api-reference/endpoints/kms/keys/list", - "api-reference/endpoints/kms/keys/get-by-id", - "api-reference/endpoints/kms/keys/get-by-name", - "api-reference/endpoints/kms/keys/create", - "api-reference/endpoints/kms/keys/update", - "api-reference/endpoints/kms/keys/delete" - ] - }, - { - "group": "Encryption", - "pages": [ - "api-reference/endpoints/kms/encryption/encrypt", - "api-reference/endpoints/kms/encryption/decrypt" - ] - }, - { - "group": "Signing", - "pages": [ - "api-reference/endpoints/kms/signing/sign", - "api-reference/endpoints/kms/signing/verify", - "api-reference/endpoints/kms/signing/public-key", - "api-reference/endpoints/kms/signing/signing-algorithms" - ] - } - ] - }, - { - "group": "Internals", - "pages": [ - "internals/overview", - { - "group": "Permissions", - "pages": [ - "internals/permissions/overview", - "internals/permissions/project-permissions", - "internals/permissions/organization-permissions", - "internals/permissions/migration" - ] - }, - "internals/components", - "internals/security", - "internals/service-tokens" - ] - }, - { - "group": "", - "pages": ["changelog/overview"] - }, - { - "group": "Contributing", - "pages": [ - { - "group": "Getting Started", - "pages": [ - "contributing/getting-started/overview", - "contributing/getting-started/code-of-conduct", - "contributing/getting-started/pull-requests", - "contributing/getting-started/faq" - ] - }, - { - "group": "Contributing to platform", - "pages": [ - "contributing/platform/developing", - "contributing/platform/backend/how-to-create-a-feature", - "contributing/platform/backend/folder-structure" - ] - }, - { - "group": "Contributing to SDK", - "pages": ["contributing/sdk/developing"] - } - ] - } - ], - "analytics": { - "koala": { - "publicApiKey": "pk_b50d7184e0e39ddd5cdb43cf6abeadd9b97d" - } - }, - "footer": { - "socials": { - "x": "https://www.twitter.com/infisical/", - "linkedin": "https://www.linkedin.com/company/infisical/", - "github": "https://github.com/Infisical/infisical-cli", - "slack": "https://infisical.com/slack" - }, - "links": [ - { - "title": "PRODUCT", - "links": [ - { - "label": "Secret Management", - "url": "https://infisical.com/" - }, - { - "label": "Secret Scanning", - "url": "https://infisical.com/radar" - }, - { - "label": "Share Secrets", - "url": "https://app.infisical.com/share-secret" - }, - { - "label": "Pricing", - "url": "https://infisical.com/pricing" - }, - { - "label": "Security", - "url": "https://infisical.com/docs/internals/security" - }, - { - "label": "Blog", - "url": "https://infisical.com/blog" - }, - { - "label": "Infisical vs Vault", - "url": "https://infisical.com/infisical-vs-hashicorp-vault" - }, - { - "label": "Forum", - "url": "https://questions.infisical.com/" - } - ] - }, - { - "title": "USE CASES", - "links": [ - { - "label": "Infisical Agent", - "url": "https://infisical.com/docs/documentation/getting-started/introduction" - }, - { - "label": "Kubernetes", - "url": "https://infisical.com/docs/integrations/platforms/kubernetes" - }, - { - "label": "Dynamic Secrets", - "url": "https://infisical.com/docs/documentation/platform/dynamic-secrets/overview" - }, - { - "label": "Terraform", - "url": "https://infisical.com/docs/integrations/frameworks/terraform" - }, - { - "label": "Ansible", - "url": "https://infisical.com/docs/integrations/platforms/ansible" - }, - { - "label": "Jenkins", - "url": "https://infisical.com/docs/integrations/cicd/jenkins" - }, - { - "label": "Docker", - "url": "https://infisical.com/docs/integrations/platforms/docker-intro" - }, - { - "label": "AWS ECS", - "url": "https://infisical.com/docs/integrations/platforms/ecs-with-agent" - }, - { - "label": "GitLab", - "url": "https://infisical.com/docs/integrations/cicd/gitlab" - }, - { - "label": "GitHub", - "url": "https://infisical.com/docs/integrations/cicd/githubactions" - }, - { - "label": "SDK", - "url": "https://infisical.com/docs/sdks/overview" - } - ] - }, - { - "title": "DEVELOPERS", - "links": [ - { - "label": "Changelog", - "url": "https://www.infisical.com/docs/changelog" - }, - { - "label": "Status", - "url": "https://status.infisical.com/" - }, - { - "label": "Feedback & Requests", - "url": "https://github.com/Infisical/infisical/issues" - }, - { - "label": "Trust of Center", - "url": "https://app.vanta.com/infisical.com/trust/hoop8cr78cuarxo9sztvs" - }, - { - "label": "Open Source Friends", - "url": "https://infisical.com/infisical-friends" - }, - { - "label": "How to contribute", - "url": "https://www.infisical.com/infisical-heroes" - } - ] - }, - { - "title": "OTHERS", - "links": [ - { - "label": "Customers", - "url": "https://infisical.com/customers/traba" - }, - { - "label": "Company Handbook", - "url": "https://infisical.com/wiki/handbook/overview" - }, - { - "label": "Careers", - "url": "https://infisical.com/careers" - }, - { - "label": "Terms of Service", - "url": "https://infisical.com/terms" - }, - { - "label": "Privacy Policy", - "url": "https://infisical.com/privacy" - }, - { - "label": "Subprocessors", - "url": "https://infisical.com/subprocessors" - }, - { - "label": "SLA", - "url": "https://infisical.com/sla" - }, - { - "label": "Team Email", - "url": "mailto:team@infisical.com" - }, - { - "label": "Sales", - "url": "mailto:sales@infisical.com" - }, - { - "label": "Support", - "url": "https://infisical.com/slack" - } - ] - } - ] - } -} From e5c7aba745e0ecaf3ba43ce8f4bd2a22e83193a7 Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Tue, 1 Jul 2025 17:42:33 -0400 Subject: [PATCH 5/7] Revert "misc: updated sidebar name" --- frontend/src/layouts/AdminLayout/Sidebar.tsx | 2 +- frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx | 4 ++-- .../admin/EnvironmentPage/components/EnvironmentPageForm.tsx | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/frontend/src/layouts/AdminLayout/Sidebar.tsx b/frontend/src/layouts/AdminLayout/Sidebar.tsx index 61441c1ed..db6384e68 100644 --- a/frontend/src/layouts/AdminLayout/Sidebar.tsx +++ b/frontend/src/layouts/AdminLayout/Sidebar.tsx @@ -43,7 +43,7 @@ const generalTabs = [ link: "/admin/caching" }, { - label: "Environment Variables", + label: "Environment", icon: "unlock", link: "/admin/environment" } diff --git a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx index 000dd1f0d..ea4467131 100644 --- a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx +++ b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx @@ -16,8 +16,8 @@ export const EnvironmentPage = () => {
diff --git a/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx b/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx index 5897d8474..2a629bf95 100644 --- a/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx +++ b/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx @@ -224,7 +224,7 @@ export const EnvironmentPageForm = () => { isLoading={isSubmitting} isDisabled={isSubmitting || !isDirty} > - Save + Save Overrides
From 325d277021f4a0eb23857745e5cfadec302cd75e Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Tue, 1 Jul 2025 17:43:38 -0400 Subject: [PATCH 6/7] Revert "feat(super-admin): Environment Overrides" --- .../20250627010508_env-overrides.ts | 21 -- backend/src/db/schemas/super-admin.ts | 3 +- backend/src/lib/config/env.ts | 111 +------- backend/src/server/routes/index.ts | 4 - backend/src/server/routes/v1/admin-router.ts | 47 +--- .../super-admin/super-admin-service.ts | 81 +----- .../services/super-admin/super-admin-types.ts | 9 - .../v2/HighlightText/HighlightText.tsx | 42 --- .../src/components/v2/HighlightText/index.tsx | 1 - frontend/src/hooks/api/admin/queries.ts | 14 +- frontend/src/hooks/api/admin/types.ts | 9 - frontend/src/layouts/AdminLayout/Sidebar.tsx | 5 - .../admin/EnvironmentPage/EnvironmentPage.tsx | 27 -- .../components/EnvironmentPageForm.tsx | 245 ------------------ .../admin/EnvironmentPage/components/index.ts | 1 - .../src/pages/admin/EnvironmentPage/route.tsx | 25 -- frontend/src/routeTree.gen.ts | 27 -- frontend/src/routes.ts | 1 - 18 files changed, 9 insertions(+), 664 deletions(-) delete mode 100644 backend/src/db/migrations/20250627010508_env-overrides.ts delete mode 100644 frontend/src/components/v2/HighlightText/HighlightText.tsx delete mode 100644 frontend/src/components/v2/HighlightText/index.tsx delete mode 100644 frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx delete mode 100644 frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx delete mode 100644 frontend/src/pages/admin/EnvironmentPage/components/index.ts delete mode 100644 frontend/src/pages/admin/EnvironmentPage/route.tsx diff --git a/backend/src/db/migrations/20250627010508_env-overrides.ts b/backend/src/db/migrations/20250627010508_env-overrides.ts deleted file mode 100644 index 535360a80..000000000 --- a/backend/src/db/migrations/20250627010508_env-overrides.ts +++ /dev/null @@ -1,21 +0,0 @@ -import { Knex } from "knex"; - -import { TableName } from "../schemas"; - -export async function up(knex: Knex): Promise { - const hasColumn = await knex.schema.hasColumn(TableName.SuperAdmin, "encryptedEnvOverrides"); - if (!hasColumn) { - await knex.schema.alterTable(TableName.SuperAdmin, (t) => { - t.binary("encryptedEnvOverrides").nullable(); - }); - } -} - -export async function down(knex: Knex): Promise { - const hasColumn = await knex.schema.hasColumn(TableName.SuperAdmin, "encryptedEnvOverrides"); - if (hasColumn) { - await knex.schema.alterTable(TableName.SuperAdmin, (t) => { - t.dropColumn("encryptedEnvOverrides"); - }); - } -} diff --git a/backend/src/db/schemas/super-admin.ts b/backend/src/db/schemas/super-admin.ts index b5e160096..de4975b20 100644 --- a/backend/src/db/schemas/super-admin.ts +++ b/backend/src/db/schemas/super-admin.ts @@ -34,8 +34,7 @@ export const SuperAdminSchema = z.object({ encryptedGitHubAppConnectionClientSecret: zodBuffer.nullable().optional(), encryptedGitHubAppConnectionSlug: zodBuffer.nullable().optional(), encryptedGitHubAppConnectionId: zodBuffer.nullable().optional(), - encryptedGitHubAppConnectionPrivateKey: zodBuffer.nullable().optional(), - encryptedEnvOverrides: zodBuffer.nullable().optional() + encryptedGitHubAppConnectionPrivateKey: zodBuffer.nullable().optional() }); export type TSuperAdmin = z.infer; diff --git a/backend/src/lib/config/env.ts b/backend/src/lib/config/env.ts index 2523c763c..8db5c16c4 100644 --- a/backend/src/lib/config/env.ts +++ b/backend/src/lib/config/env.ts @@ -2,7 +2,6 @@ import { z } from "zod"; import { QueueWorkerProfile } from "@app/lib/types"; -import { BadRequestError } from "../errors"; import { removeTrailingSlash } from "../fn"; import { CustomLogger } from "../logger/logger"; import { zpStr } from "../zod"; @@ -342,11 +341,8 @@ const envSchema = z export type TEnvConfig = Readonly>; let envCfg: TEnvConfig; -let originalEnvConfig: TEnvConfig; export const getConfig = () => envCfg; -export const getOriginalConfig = () => originalEnvConfig; - // cannot import singleton logger directly as it needs config to load various transport export const initEnvConfig = (logger?: CustomLogger) => { const parsedEnv = envSchema.safeParse(process.env); @@ -356,115 +352,10 @@ export const initEnvConfig = (logger?: CustomLogger) => { process.exit(-1); } - const config = Object.freeze(parsedEnv.data); - envCfg = config; - - if (!originalEnvConfig) { - originalEnvConfig = config; - } - + envCfg = Object.freeze(parsedEnv.data); return envCfg; }; -// A list of environment variables that can be overwritten -export const overwriteSchema: { - [key: string]: { - name: string; - fields: { key: keyof TEnvConfig; description?: string }[]; - }; -} = { - azure: { - name: "Azure", - fields: [ - { - key: "INF_APP_CONNECTION_AZURE_CLIENT_ID", - description: "The Application (Client) ID of your Azure application." - }, - { - key: "INF_APP_CONNECTION_AZURE_CLIENT_SECRET", - description: "The Client Secret of your Azure application." - } - ] - }, - google_sso: { - name: "Google SSO", - fields: [ - { - key: "CLIENT_ID_GOOGLE_LOGIN", - description: "The Client ID of your GCP OAuth2 application." - }, - { - key: "CLIENT_SECRET_GOOGLE_LOGIN", - description: "The Client Secret of your GCP OAuth2 application." - } - ] - }, - github_sso: { - name: "GitHub SSO", - fields: [ - { - key: "CLIENT_ID_GITHUB_LOGIN", - description: "The Client ID of your GitHub OAuth application." - }, - { - key: "CLIENT_SECRET_GITHUB_LOGIN", - description: "The Client Secret of your GitHub OAuth application." - } - ] - }, - gitlab_sso: { - name: "GitLab SSO", - fields: [ - { - key: "CLIENT_ID_GITLAB_LOGIN", - description: "The Client ID of your GitLab application." - }, - { - key: "CLIENT_SECRET_GITLAB_LOGIN", - description: "The Secret of your GitLab application." - }, - { - key: "CLIENT_GITLAB_LOGIN_URL", - description: - "The URL of your self-hosted instance of GitLab where the OAuth application is registered. If no URL is passed in, this will default to https://gitlab.com." - } - ] - } -}; - -export const overridableKeys = new Set( - Object.values(overwriteSchema).flatMap(({ fields }) => fields.map(({ key }) => key)) -); - -export const validateOverrides = (config: Record) => { - const allowedOverrides = Object.fromEntries( - Object.entries(config).filter(([key]) => overridableKeys.has(key as keyof z.input)) - ); - - const tempEnv: Record = { ...process.env, ...allowedOverrides }; - const parsedResult = envSchema.safeParse(tempEnv); - - if (!parsedResult.success) { - const errorDetails = parsedResult.error.issues - .map((issue) => `Key: "${issue.path.join(".")}", Error: ${issue.message}`) - .join("\n"); - throw new BadRequestError({ message: errorDetails }); - } -}; - -export const overrideEnvConfig = (config: Record) => { - const allowedOverrides = Object.fromEntries( - Object.entries(config).filter(([key]) => overridableKeys.has(key as keyof z.input)) - ); - - const tempEnv: Record = { ...process.env, ...allowedOverrides }; - const parsedResult = envSchema.safeParse(tempEnv); - - if (parsedResult.success) { - envCfg = Object.freeze(parsedResult.data); - } -}; - export const formatSmtpConfig = () => { const tlsOptions: { rejectUnauthorized: boolean; diff --git a/backend/src/server/routes/index.ts b/backend/src/server/routes/index.ts index 401eeaf94..aeef89838 100644 --- a/backend/src/server/routes/index.ts +++ b/backend/src/server/routes/index.ts @@ -2045,10 +2045,6 @@ export const registerRoutes = async ( cronJobs.push(adminIntegrationsSyncJob); } } - const configSyncJob = await superAdminService.initializeEnvConfigSync(); - if (configSyncJob) { - cronJobs.push(configSyncJob); - } server.decorate("store", { user: userDAL, diff --git a/backend/src/server/routes/v1/admin-router.ts b/backend/src/server/routes/v1/admin-router.ts index 81e911621..a21587db1 100644 --- a/backend/src/server/routes/v1/admin-router.ts +++ b/backend/src/server/routes/v1/admin-router.ts @@ -8,7 +8,7 @@ import { SuperAdminSchema, UsersSchema } from "@app/db/schemas"; -import { getConfig, overridableKeys } from "@app/lib/config/env"; +import { getConfig } from "@app/lib/config/env"; import { BadRequestError } from "@app/lib/errors"; import { invalidateCacheLimit, readLimit, writeLimit } from "@app/server/config/rateLimiter"; import { getTelemetryDistinctId } from "@app/server/lib/telemetry"; @@ -42,8 +42,7 @@ export const registerAdminRouter = async (server: FastifyZodProvider) => { encryptedGitHubAppConnectionClientSecret: true, encryptedGitHubAppConnectionSlug: true, encryptedGitHubAppConnectionId: true, - encryptedGitHubAppConnectionPrivateKey: true, - encryptedEnvOverrides: true + encryptedGitHubAppConnectionPrivateKey: true }).extend({ isMigrationModeOn: z.boolean(), defaultAuthOrgSlug: z.string().nullable(), @@ -111,14 +110,11 @@ export const registerAdminRouter = async (server: FastifyZodProvider) => { .refine((content) => DOMPurify.sanitize(content) === content, { message: "Page frame content contains unsafe HTML." }) - .optional(), - envOverrides: z.record(z.enum(Array.from(overridableKeys) as [string, ...string[]]), z.string()).optional() + .optional() }), response: { 200: z.object({ - config: SuperAdminSchema.omit({ - encryptedEnvOverrides: true - }).extend({ + config: SuperAdminSchema.extend({ defaultAuthOrgSlug: z.string().nullable() }) }) @@ -385,41 +381,6 @@ export const registerAdminRouter = async (server: FastifyZodProvider) => { } }); - server.route({ - method: "GET", - url: "/env-overrides", - config: { - rateLimit: readLimit - }, - schema: { - response: { - 200: z.record( - z.string(), - z.object({ - name: z.string(), - fields: z - .object({ - key: z.string(), - value: z.string(), - hasEnvEntry: z.boolean(), - description: z.string().optional() - }) - .array() - }) - ) - } - }, - onRequest: (req, res, done) => { - verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN])(req, res, () => { - verifySuperAdmin(req, res, done); - }); - }, - handler: async () => { - const envOverrides = await server.services.superAdmin.getEnvOverridesOrganized(); - return envOverrides; - } - }); - server.route({ method: "DELETE", url: "/user-management/users/:userId", diff --git a/backend/src/services/super-admin/super-admin-service.ts b/backend/src/services/super-admin/super-admin-service.ts index 2ca7a0c33..8a0d4dd14 100644 --- a/backend/src/services/super-admin/super-admin-service.ts +++ b/backend/src/services/super-admin/super-admin-service.ts @@ -5,13 +5,7 @@ import jwt from "jsonwebtoken"; import { IdentityAuthMethod, OrgMembershipRole, TSuperAdmin, TSuperAdminUpdate } from "@app/db/schemas"; import { TLicenseServiceFactory } from "@app/ee/services/license/license-service"; import { PgSqlLock, TKeyStoreFactory } from "@app/keystore/keystore"; -import { - getConfig, - getOriginalConfig, - overrideEnvConfig, - overwriteSchema, - validateOverrides -} from "@app/lib/config/env"; +import { getConfig } from "@app/lib/config/env"; import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption"; import { generateUserSrpKeys, getUserPrivateKey } from "@app/lib/crypto/srp"; import { BadRequestError, NotFoundError } from "@app/lib/errors"; @@ -39,7 +33,6 @@ import { TInvalidateCacheQueueFactory } from "./invalidate-cache-queue"; import { TSuperAdminDALFactory } from "./super-admin-dal"; import { CacheType, - EnvOverrides, LoginMethod, TAdminBootstrapInstanceDTO, TAdminGetIdentitiesDTO, @@ -241,45 +234,6 @@ export const superAdminServiceFactory = ({ adminIntegrationsConfig = config; }; - const getEnvOverrides = async () => { - const serverCfg = await serverCfgDAL.findById(ADMIN_CONFIG_DB_UUID); - - if (!serverCfg || !serverCfg.encryptedEnvOverrides) { - return {}; - } - - const decrypt = kmsService.decryptWithRootKey(); - - const overrides = JSON.parse(decrypt(serverCfg.encryptedEnvOverrides).toString()) as Record; - - return overrides; - }; - - const getEnvOverridesOrganized = async (): Promise => { - const overrides = await getEnvOverrides(); - const ogConfig = getOriginalConfig(); - - return Object.fromEntries( - Object.entries(overwriteSchema).map(([groupKey, groupDef]) => [ - groupKey, - { - name: groupDef.name, - fields: groupDef.fields.map(({ key, description }) => ({ - key, - description, - value: overrides[key] || "", - hasEnvEntry: !!(ogConfig as unknown as Record)[key] - })) - } - ]) - ); - }; - - const $syncEnvConfig = async () => { - const config = await getEnvOverrides(); - overrideEnvConfig(config); - }; - const updateServerCfg = async ( data: TSuperAdminUpdate & { slackClientId?: string; @@ -292,7 +246,6 @@ export const superAdminServiceFactory = ({ gitHubAppConnectionSlug?: string; gitHubAppConnectionId?: string; gitHubAppConnectionPrivateKey?: string; - envOverrides?: Record; }, userId: string ) => { @@ -421,17 +374,6 @@ export const superAdminServiceFactory = ({ gitHubAppConnectionSettingsUpdated = true; } - let envOverridesUpdated = false; - if (data.envOverrides !== undefined) { - // Verify input format - validateOverrides(data.envOverrides); - - const encryptedEnvOverrides = encryptWithRoot(Buffer.from(JSON.stringify(data.envOverrides))); - updatedData.encryptedEnvOverrides = encryptedEnvOverrides; - updatedData.envOverrides = undefined; - envOverridesUpdated = true; - } - const updatedServerCfg = await serverCfgDAL.updateById(ADMIN_CONFIG_DB_UUID, updatedData); await keyStore.setItemWithExpiry(ADMIN_CONFIG_KEY, ADMIN_CONFIG_KEY_EXP, JSON.stringify(updatedServerCfg)); @@ -440,10 +382,6 @@ export const superAdminServiceFactory = ({ await $syncAdminIntegrationConfig(); } - if (envOverridesUpdated) { - await $syncEnvConfig(); - } - if ( updatedServerCfg.encryptedMicrosoftTeamsAppId && updatedServerCfg.encryptedMicrosoftTeamsClientSecret && @@ -876,18 +814,6 @@ export const superAdminServiceFactory = ({ return job; }; - const initializeEnvConfigSync = async () => { - logger.info("Setting up background sync process for environment overrides"); - - await $syncEnvConfig(); - - // sync every 5 minutes - const job = new CronJob("*/5 * * * *", $syncEnvConfig); - job.start(); - - return job; - }; - return { initServerCfg, updateServerCfg, @@ -907,9 +833,6 @@ export const superAdminServiceFactory = ({ getOrganizations, deleteOrganization, deleteOrganizationMembership, - initializeAdminIntegrationConfigSync, - initializeEnvConfigSync, - getEnvOverrides, - getEnvOverridesOrganized + initializeAdminIntegrationConfigSync }; }; diff --git a/backend/src/services/super-admin/super-admin-types.ts b/backend/src/services/super-admin/super-admin-types.ts index b57a015a4..205c59f2c 100644 --- a/backend/src/services/super-admin/super-admin-types.ts +++ b/backend/src/services/super-admin/super-admin-types.ts @@ -1,5 +1,3 @@ -import { TEnvConfig } from "@app/lib/config/env"; - export type TAdminSignUpDTO = { email: string; password: string; @@ -76,10 +74,3 @@ export type TAdminIntegrationConfig = { privateKey: string; }; }; - -export interface EnvOverrides { - [key: string]: { - name: string; - fields: { key: keyof TEnvConfig; value: string; hasEnvEntry: boolean; description?: string }[]; - }; -} diff --git a/frontend/src/components/v2/HighlightText/HighlightText.tsx b/frontend/src/components/v2/HighlightText/HighlightText.tsx deleted file mode 100644 index 3ce7c8f19..000000000 --- a/frontend/src/components/v2/HighlightText/HighlightText.tsx +++ /dev/null @@ -1,42 +0,0 @@ -export const HighlightText = ({ - text, - highlight, - highlightClassName -}: { - text: string | undefined | null; - highlight: string; - highlightClassName?: string; -}) => { - if (!text) return null; - const searchTerm = highlight.toLowerCase().trim(); - - if (!searchTerm) return {text}; - - const parts: React.ReactNode[] = []; - let lastIndex = 0; - - const escapedSearchTerm = searchTerm.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"); - const regex = new RegExp(escapedSearchTerm, "gi"); - - text.replace(regex, (match: string, offset: number) => { - if (offset > lastIndex) { - parts.push({text.substring(lastIndex, offset)}); - } - - parts.push( - - {match} - - ); - - lastIndex = offset + match.length; - - return match; - }); - - if (lastIndex < text.length) { - parts.push({text.substring(lastIndex)}); - } - - return parts; -}; diff --git a/frontend/src/components/v2/HighlightText/index.tsx b/frontend/src/components/v2/HighlightText/index.tsx deleted file mode 100644 index a2ff1b504..000000000 --- a/frontend/src/components/v2/HighlightText/index.tsx +++ /dev/null @@ -1 +0,0 @@ -export { HighlightText } from "./HighlightText"; diff --git a/frontend/src/hooks/api/admin/queries.ts b/frontend/src/hooks/api/admin/queries.ts index 871c7288c..c628df955 100644 --- a/frontend/src/hooks/api/admin/queries.ts +++ b/frontend/src/hooks/api/admin/queries.ts @@ -10,7 +10,6 @@ import { AdminGetUsersFilters, AdminIntegrationsConfig, OrganizationWithProjects, - TGetEnvOverrides, TGetInvalidatingCacheStatus, TGetServerRootKmsEncryptionDetails, TServerConfig @@ -32,8 +31,7 @@ export const adminQueryKeys = { getAdminSlackConfig: () => ["admin-slack-config"] as const, getServerEncryptionStrategies: () => ["server-encryption-strategies"] as const, getInvalidateCache: () => ["admin-invalidate-cache"] as const, - getAdminIntegrationsConfig: () => ["admin-integrations-config"] as const, - getEnvOverrides: () => ["env-overrides"] as const + getAdminIntegrationsConfig: () => ["admin-integrations-config"] as const }; export const fetchServerConfig = async () => { @@ -165,13 +163,3 @@ export const useGetInvalidatingCacheStatus = (enabled = true) => { refetchInterval: (data) => (data ? 3000 : false) }); }; - -export const useGetEnvOverrides = () => { - return useQuery({ - queryKey: adminQueryKeys.getEnvOverrides(), - queryFn: async () => { - const { data } = await apiRequest.get("/api/v1/admin/env-overrides"); - return data; - } - }); -}; diff --git a/frontend/src/hooks/api/admin/types.ts b/frontend/src/hooks/api/admin/types.ts index 4580c6581..c5d92b9da 100644 --- a/frontend/src/hooks/api/admin/types.ts +++ b/frontend/src/hooks/api/admin/types.ts @@ -48,7 +48,6 @@ export type TServerConfig = { authConsentContent?: string; pageFrameContent?: string; invalidatingCache: boolean; - envOverrides?: Record; }; export type TUpdateServerConfigDTO = { @@ -62,7 +61,6 @@ export type TUpdateServerConfigDTO = { gitHubAppConnectionSlug?: string; gitHubAppConnectionId?: string; gitHubAppConnectionPrivateKey?: string; - envOverrides?: Record; } & Partial; export type TCreateAdminUserDTO = { @@ -140,10 +138,3 @@ export type TInvalidateCacheDTO = { export type TGetInvalidatingCacheStatus = { invalidating: boolean; }; - -export interface TGetEnvOverrides { - [key: string]: { - name: string; - fields: { key: string; value: string; hasEnvEntry: boolean; description?: string }[]; - }; -} diff --git a/frontend/src/layouts/AdminLayout/Sidebar.tsx b/frontend/src/layouts/AdminLayout/Sidebar.tsx index db6384e68..ea938394b 100644 --- a/frontend/src/layouts/AdminLayout/Sidebar.tsx +++ b/frontend/src/layouts/AdminLayout/Sidebar.tsx @@ -41,11 +41,6 @@ const generalTabs = [ label: "Caching", icon: "note", link: "/admin/caching" - }, - { - label: "Environment", - icon: "unlock", - link: "/admin/environment" } ]; diff --git a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx b/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx deleted file mode 100644 index ea4467131..000000000 --- a/frontend/src/pages/admin/EnvironmentPage/EnvironmentPage.tsx +++ /dev/null @@ -1,27 +0,0 @@ -import { Helmet } from "react-helmet"; -import { useTranslation } from "react-i18next"; - -import { PageHeader } from "@app/components/v2"; - -import { EnvironmentPageForm } from "./components"; - -export const EnvironmentPage = () => { - const { t } = useTranslation(); - - return ( -
- - {t("common.head-title", { title: "Admin" })} - -
-
- - -
-
-
- ); -}; diff --git a/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx b/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx deleted file mode 100644 index 2a629bf95..000000000 --- a/frontend/src/pages/admin/EnvironmentPage/components/EnvironmentPageForm.tsx +++ /dev/null @@ -1,245 +0,0 @@ -import { useCallback, useEffect, useMemo, useState } from "react"; -import { Control, Controller, useForm, useWatch } from "react-hook-form"; -import { - faChevronRight, - faExclamationTriangle, - faMagnifyingGlass -} from "@fortawesome/free-solid-svg-icons"; -import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; -import { zodResolver } from "@hookform/resolvers/zod"; -import { z } from "zod"; - -import { createNotification } from "@app/components/notifications"; -import { Button, FormControl, Input, SecretInput, Tooltip } from "@app/components/v2"; -import { HighlightText } from "@app/components/v2/HighlightText"; -import { useGetEnvOverrides, useUpdateServerConfig } from "@app/hooks/api"; - -type TForm = Record; - -export const GroupContainer = ({ - group, - control, - search -}: { - group: { - fields: { - key: string; - value: string; - hasEnvEntry: boolean; - description?: string; - }[]; - name: string; - }; - control: Control; - search: string; -}) => { - const [open, setOpen] = useState(false); - - return ( -
-
setOpen((o) => !o)} - onKeyDown={(e) => { - if (e.key === "Enter") { - setOpen((o) => !o); - } - }} - > - - -
{group.name}
-
- - {(open || search) && ( -
- {group.fields.map((field) => ( -
-
- - - - - - -
- -
- {field.hasEnvEntry && ( - - - - )} - - ( - - - - )} - /> -
-
- ))} -
- )} -
- ); -}; - -export const EnvironmentPageForm = () => { - const { data: envOverrides } = useGetEnvOverrides(); - const { mutateAsync: updateServerConfig } = useUpdateServerConfig(); - const [search, setSearch] = useState(""); - - const allFields = useMemo(() => { - if (!envOverrides) return []; - return Object.values(envOverrides).flatMap((group) => group.fields); - }, [envOverrides]); - - const formSchema = useMemo(() => { - return z.object(Object.fromEntries(allFields.map((field) => [field.key, z.string()]))); - }, [allFields]); - - const defaultValues = useMemo(() => { - const values: Record = {}; - allFields.forEach((field) => { - values[field.key] = field.value ?? ""; - }); - return values; - }, [allFields]); - - const { - control, - handleSubmit, - reset, - formState: { isSubmitting, isDirty } - } = useForm({ - resolver: zodResolver(formSchema), - defaultValues - }); - - const formValues = useWatch({ control }); - - const filteredData = useMemo(() => { - if (!envOverrides) return []; - - const searchTerm = search.toLowerCase().trim(); - if (!searchTerm) { - return Object.values(envOverrides); - } - - return Object.values(envOverrides) - .map((group) => { - const filteredFields = group.fields.filter( - (field) => - field.key.toLowerCase().includes(searchTerm) || - (field.description ?? "").toLowerCase().includes(searchTerm) - ); - - if (filteredFields.length > 0) { - return { ...group, fields: filteredFields }; - } - return null; - }) - .filter(Boolean); - }, [search, formValues, envOverrides]); - - useEffect(() => { - reset(defaultValues); - }, [defaultValues, reset]); - - const onSubmit = useCallback( - async (formData: TForm) => { - try { - const filteredFormData = Object.fromEntries( - Object.entries(formData).filter(([, value]) => value !== "") - ); - await updateServerConfig({ - envOverrides: filteredFormData - }); - - createNotification({ - type: "success", - text: "Environment overrides updated successfully. It can take up to 5 minutes to take effect." - }); - - reset(formData); - } catch (error) { - const errorMessage = - (error as any)?.response?.data?.message || - (error as any)?.message || - "An unknown error occurred"; - createNotification({ - type: "error", - title: "Failed to update environment overrides", - text: errorMessage - }); - } - }, - [reset, updateServerConfig] - ); - - return ( -
-
-
-
-

Overrides

-
-

Override specific environment variables.

-
- -
- -
-
- setSearch(e.target.value)} - leftIcon={} - placeholder="Search for keys, descriptions, and values..." - className="flex-1" - /> -
- {filteredData.map((group) => ( - - ))} -
- - ); -}; diff --git a/frontend/src/pages/admin/EnvironmentPage/components/index.ts b/frontend/src/pages/admin/EnvironmentPage/components/index.ts deleted file mode 100644 index 44b82c206..000000000 --- a/frontend/src/pages/admin/EnvironmentPage/components/index.ts +++ /dev/null @@ -1 +0,0 @@ -export { EnvironmentPageForm } from "./EnvironmentPageForm"; diff --git a/frontend/src/pages/admin/EnvironmentPage/route.tsx b/frontend/src/pages/admin/EnvironmentPage/route.tsx deleted file mode 100644 index 0b28b44cb..000000000 --- a/frontend/src/pages/admin/EnvironmentPage/route.tsx +++ /dev/null @@ -1,25 +0,0 @@ -import { createFileRoute, linkOptions } from "@tanstack/react-router"; - -import { EnvironmentPage } from "./EnvironmentPage"; - -export const Route = createFileRoute( - "/_authenticate/_inject-org-details/admin/_admin-layout/environment" -)({ - component: EnvironmentPage, - beforeLoad: async () => { - return { - breadcrumbs: [ - { - label: "Admin", - link: linkOptions({ to: "/admin" }) - }, - { - label: "Environment", - link: linkOptions({ - to: "/admin/environment" - }) - } - ] - }; - } -}); diff --git a/frontend/src/routeTree.gen.ts b/frontend/src/routeTree.gen.ts index 02a3e30d9..a2aa9548b 100644 --- a/frontend/src/routeTree.gen.ts +++ b/frontend/src/routeTree.gen.ts @@ -43,7 +43,6 @@ import { Route as authProviderSuccessPageRouteImport } from './pages/auth/Provid import { Route as authProviderErrorPageRouteImport } from './pages/auth/ProviderErrorPage/route' import { Route as userPersonalSettingsPageRouteImport } from './pages/user/PersonalSettingsPage/route' import { Route as adminIntegrationsPageRouteImport } from './pages/admin/IntegrationsPage/route' -import { Route as adminEnvironmentPageRouteImport } from './pages/admin/EnvironmentPage/route' import { Route as adminEncryptionPageRouteImport } from './pages/admin/EncryptionPage/route' import { Route as adminCachingPageRouteImport } from './pages/admin/CachingPage/route' import { Route as adminAuthenticationPageRouteImport } from './pages/admin/AuthenticationPage/route' @@ -608,12 +607,6 @@ const adminIntegrationsPageRouteRoute = adminIntegrationsPageRouteImport.update( } as any, ) -const adminEnvironmentPageRouteRoute = adminEnvironmentPageRouteImport.update({ - id: '/environment', - path: '/environment', - getParentRoute: () => adminLayoutRoute, -} as any) - const adminEncryptionPageRouteRoute = adminEncryptionPageRouteImport.update({ id: '/encryption', path: '/encryption', @@ -2360,13 +2353,6 @@ declare module '@tanstack/react-router' { preLoaderRoute: typeof adminEncryptionPageRouteImport parentRoute: typeof adminLayoutImport } - '/_authenticate/_inject-org-details/admin/_admin-layout/environment': { - id: '/_authenticate/_inject-org-details/admin/_admin-layout/environment' - path: '/environment' - fullPath: '/admin/environment' - preLoaderRoute: typeof adminEnvironmentPageRouteImport - parentRoute: typeof adminLayoutImport - } '/_authenticate/_inject-org-details/admin/_admin-layout/integrations': { id: '/_authenticate/_inject-org-details/admin/_admin-layout/integrations' path: '/integrations' @@ -4498,7 +4484,6 @@ interface adminLayoutRouteChildren { adminAuthenticationPageRouteRoute: typeof adminAuthenticationPageRouteRoute adminCachingPageRouteRoute: typeof adminCachingPageRouteRoute adminEncryptionPageRouteRoute: typeof adminEncryptionPageRouteRoute - adminEnvironmentPageRouteRoute: typeof adminEnvironmentPageRouteRoute adminIntegrationsPageRouteRoute: typeof adminIntegrationsPageRouteRoute adminMachineIdentitiesResourcesPageRouteRoute: typeof adminMachineIdentitiesResourcesPageRouteRoute adminOrganizationResourcesPageRouteRoute: typeof adminOrganizationResourcesPageRouteRoute @@ -4510,7 +4495,6 @@ const adminLayoutRouteChildren: adminLayoutRouteChildren = { adminAuthenticationPageRouteRoute: adminAuthenticationPageRouteRoute, adminCachingPageRouteRoute: adminCachingPageRouteRoute, adminEncryptionPageRouteRoute: adminEncryptionPageRouteRoute, - adminEnvironmentPageRouteRoute: adminEnvironmentPageRouteRoute, adminIntegrationsPageRouteRoute: adminIntegrationsPageRouteRoute, adminMachineIdentitiesResourcesPageRouteRoute: adminMachineIdentitiesResourcesPageRouteRoute, @@ -4713,7 +4697,6 @@ export interface FileRoutesByFullPath { '/admin/authentication': typeof adminAuthenticationPageRouteRoute '/admin/caching': typeof adminCachingPageRouteRoute '/admin/encryption': typeof adminEncryptionPageRouteRoute - '/admin/environment': typeof adminEnvironmentPageRouteRoute '/admin/integrations': typeof adminIntegrationsPageRouteRoute '/cert-manager/$projectId': typeof certManagerLayoutRouteWithChildren '/kms/$projectId': typeof kmsLayoutRouteWithChildren @@ -4935,7 +4918,6 @@ export interface FileRoutesByTo { '/admin/authentication': typeof adminAuthenticationPageRouteRoute '/admin/caching': typeof adminCachingPageRouteRoute '/admin/encryption': typeof adminEncryptionPageRouteRoute - '/admin/environment': typeof adminEnvironmentPageRouteRoute '/admin/integrations': typeof adminIntegrationsPageRouteRoute '/cert-manager/$projectId': typeof certManagerLayoutRouteWithChildren '/kms/$projectId': typeof kmsLayoutRouteWithChildren @@ -5157,7 +5139,6 @@ export interface FileRoutesById { '/_authenticate/_inject-org-details/admin/_admin-layout/authentication': typeof adminAuthenticationPageRouteRoute '/_authenticate/_inject-org-details/admin/_admin-layout/caching': typeof adminCachingPageRouteRoute '/_authenticate/_inject-org-details/admin/_admin-layout/encryption': typeof adminEncryptionPageRouteRoute - '/_authenticate/_inject-org-details/admin/_admin-layout/environment': typeof adminEnvironmentPageRouteRoute '/_authenticate/_inject-org-details/admin/_admin-layout/integrations': typeof adminIntegrationsPageRouteRoute '/_authenticate/_inject-org-details/_org-layout/cert-manager/$projectId': typeof AuthenticateInjectOrgDetailsOrgLayoutCertManagerProjectIdRouteWithChildren '/_authenticate/_inject-org-details/_org-layout/kms/$projectId': typeof AuthenticateInjectOrgDetailsOrgLayoutKmsProjectIdRouteWithChildren @@ -5390,7 +5371,6 @@ export interface FileRouteTypes { | '/admin/authentication' | '/admin/caching' | '/admin/encryption' - | '/admin/environment' | '/admin/integrations' | '/cert-manager/$projectId' | '/kms/$projectId' @@ -5611,7 +5591,6 @@ export interface FileRouteTypes { | '/admin/authentication' | '/admin/caching' | '/admin/encryption' - | '/admin/environment' | '/admin/integrations' | '/cert-manager/$projectId' | '/kms/$projectId' @@ -5831,7 +5810,6 @@ export interface FileRouteTypes { | '/_authenticate/_inject-org-details/admin/_admin-layout/authentication' | '/_authenticate/_inject-org-details/admin/_admin-layout/caching' | '/_authenticate/_inject-org-details/admin/_admin-layout/encryption' - | '/_authenticate/_inject-org-details/admin/_admin-layout/environment' | '/_authenticate/_inject-org-details/admin/_admin-layout/integrations' | '/_authenticate/_inject-org-details/_org-layout/cert-manager/$projectId' | '/_authenticate/_inject-org-details/_org-layout/kms/$projectId' @@ -6289,7 +6267,6 @@ export const routeTree = rootRoute "/_authenticate/_inject-org-details/admin/_admin-layout/authentication", "/_authenticate/_inject-org-details/admin/_admin-layout/caching", "/_authenticate/_inject-org-details/admin/_admin-layout/encryption", - "/_authenticate/_inject-org-details/admin/_admin-layout/environment", "/_authenticate/_inject-org-details/admin/_admin-layout/integrations", "/_authenticate/_inject-org-details/admin/_admin-layout/resources/machine-identities", "/_authenticate/_inject-org-details/admin/_admin-layout/resources/organizations", @@ -6332,10 +6309,6 @@ export const routeTree = rootRoute "filePath": "admin/EncryptionPage/route.tsx", "parent": "/_authenticate/_inject-org-details/admin/_admin-layout" }, - "/_authenticate/_inject-org-details/admin/_admin-layout/environment": { - "filePath": "admin/EnvironmentPage/route.tsx", - "parent": "/_authenticate/_inject-org-details/admin/_admin-layout" - }, "/_authenticate/_inject-org-details/admin/_admin-layout/integrations": { "filePath": "admin/IntegrationsPage/route.tsx", "parent": "/_authenticate/_inject-org-details/admin/_admin-layout" diff --git a/frontend/src/routes.ts b/frontend/src/routes.ts index 973e36fff..4937e7226 100644 --- a/frontend/src/routes.ts +++ b/frontend/src/routes.ts @@ -8,7 +8,6 @@ const adminRoute = route("/admin", [ index("admin/GeneralPage/route.tsx"), route("/encryption", "admin/EncryptionPage/route.tsx"), route("/authentication", "admin/AuthenticationPage/route.tsx"), - route("/environment", "admin/EnvironmentPage/route.tsx"), route("/integrations", "admin/IntegrationsPage/route.tsx"), route("/caching", "admin/CachingPage/route.tsx"), route("/resources/organizations", "admin/OrganizationResourcesPage/route.tsx"), From 28a27daf29734c25361c248ccf22531bccaca4d5 Mon Sep 17 00:00:00 2001 From: Carlos Monastyrski Date: Tue, 1 Jul 2025 19:55:38 -0300 Subject: [PATCH 7/7] feat(change-approvals): block folder deletion if there is at least one secret protected by a policy --- backend/src/server/routes/index.ts | 4 +- .../secret-folder/secret-folder-service.ts | 72 ++++++++++++++++++- 2 files changed, 73 insertions(+), 3 deletions(-) diff --git a/backend/src/server/routes/index.ts b/backend/src/server/routes/index.ts index 401eeaf94..b28c0759d 100644 --- a/backend/src/server/routes/index.ts +++ b/backend/src/server/routes/index.ts @@ -1189,7 +1189,9 @@ export const registerRoutes = async ( projectEnvDAL, snapshotService, projectDAL, - folderCommitService + folderCommitService, + secretApprovalPolicyService, + secretV2BridgeDAL }); const secretImportService = secretImportServiceFactory({ diff --git a/backend/src/services/secret-folder/secret-folder-service.ts b/backend/src/services/secret-folder/secret-folder-service.ts index da29c0f36..850cfeb61 100644 --- a/backend/src/services/secret-folder/secret-folder-service.ts +++ b/backend/src/services/secret-folder/secret-folder-service.ts @@ -2,9 +2,10 @@ import { ForbiddenError, subject } from "@casl/ability"; import path from "path"; import { v4 as uuidv4, validate as uuidValidate } from "uuid"; -import { ActionProjectType, TSecretFoldersInsert } from "@app/db/schemas"; +import { ActionProjectType, TSecretFolders, TSecretFoldersInsert } from "@app/db/schemas"; import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types"; import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission"; +import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service"; import { TSecretSnapshotServiceFactory } from "@app/ee/services/secret-snapshot/secret-snapshot-service"; import { PgSqlLock } from "@app/keystore/keystore"; import { BadRequestError, NotFoundError } from "@app/lib/errors"; @@ -14,6 +15,7 @@ import { buildFolderPath } from "@app/services/secret-folder/secret-folder-fns"; import { ChangeType, CommitType, TFolderCommitServiceFactory } from "../folder-commit/folder-commit-service"; import { TProjectDALFactory } from "../project/project-dal"; import { TProjectEnvDALFactory } from "../project-env/project-env-dal"; +import { TSecretV2BridgeDALFactory } from "../secret-v2-bridge/secret-v2-bridge-dal"; import { TSecretFolderDALFactory } from "./secret-folder-dal"; import { TCreateFolderDTO, @@ -34,6 +36,8 @@ type TSecretFolderServiceFactoryDep = { folderVersionDAL: Pick; folderCommitService: Pick; projectDAL: Pick; + secretApprovalPolicyService: Pick; + secretV2BridgeDAL: Pick; }; export type TSecretFolderServiceFactory = ReturnType; @@ -45,7 +49,9 @@ export const secretFolderServiceFactory = ({ projectEnvDAL, folderVersionDAL, folderCommitService, - projectDAL + projectDAL, + secretApprovalPolicyService, + secretV2BridgeDAL }: TSecretFolderServiceFactoryDep) => { const createFolder = async ({ projectId, @@ -464,6 +470,66 @@ export const secretFolderServiceFactory = ({ return { folder: newFolder, old: folder }; }; + const $checkFolderPolicy = async ({ + projectId, + environment, + parentId + }: { + projectId: string; + environment: string; + parentId: string; + }) => { + // get environment root folder (as it's needed to get all folders under it) + const rootFolder = await folderDAL.findBySecretPath(projectId, environment, "/"); + if (!rootFolder) throw new NotFoundError({ message: `Root folder not found` }); + // get all folders under environment root folder + const folderPaths = await folderDAL.findByEnvsDeep({ parentIds: [rootFolder.id] }); + + // create a map of folders by parent id + const normalizeKey = (key: string | null | undefined): string => key ?? "root"; + const folderMap = new Map(); + for (const folder of folderPaths) { + if (!folderMap.has(normalizeKey(folder.parentId))) { + folderMap.set(normalizeKey(folder.parentId), []); + } + folderMap.get(normalizeKey(folder.parentId))?.push(folder); + } + + // Recursively collect all folders under the given parentId + const collectDescendants = ( + id: string + ): (TSecretFolders & { path: string; depth: number; environment: string })[] => { + const children = folderMap.get(normalizeKey(id)) || []; + return [...children, ...children.flatMap((child) => collectDescendants(child.id))]; + }; + + const foldersUnderParent = collectDescendants(parentId); + + const folderPolicyPaths = foldersUnderParent.map((folder) => ({ + path: folder.path, + id: folder.id + })); + + // get secrets under the given folders + const secrets = await secretV2BridgeDAL.findByFolderIds({ folderIds: folderPolicyPaths.map((p) => p.id) }); + for await (const folderPolicyPath of folderPolicyPaths) { + // eslint-disable-next-line no-continue + if (!secrets.some((s) => s.folderId === folderPolicyPath.id)) continue; + const policy = await secretApprovalPolicyService.getSecretApprovalPolicy( + projectId, + environment, + folderPolicyPath.path + ); + // if there is a policy and there are secrets under the given folder, throw error + if (policy) { + throw new BadRequestError({ + message: `You cannot delete the selected folder because it contains one or more secrets that are protected by the change policy "${policy.name}" at folder path "${folderPolicyPath.path}". Please remove the secrets at folder path "${folderPolicyPath.path}" and try again.`, + name: "DeleteFolderProtectedByPolicy" + }); + } + } + }; + const deleteFolder = async ({ projectId, actor, @@ -498,6 +564,8 @@ export const secretFolderServiceFactory = ({ message: `Folder with path '${secretPath}' in environment with slug '${environment}' not found` }); + await $checkFolderPolicy({ projectId, environment, parentId: parentFolder.id }); + const [doc] = await folderDAL.delete( { envId: env.id,