mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fix: greptile review comments
This commit is contained in:
@@ -3,14 +3,20 @@ import { Knex } from "knex";
|
||||
import { TableName } from "../schemas";
|
||||
|
||||
export async function up(knex: Knex): Promise<void> {
|
||||
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
||||
t.uuid("scopeOrgId").notNullable();
|
||||
t.foreign("scopeOrgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
|
||||
});
|
||||
const hasScopeOrgIdColumn = await knex.schema.hasColumn(TableName.IdentityAccessToken, "scopeOrgId");
|
||||
if (!hasScopeOrgIdColumn) {
|
||||
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
||||
t.uuid("scopeOrgId");
|
||||
t.foreign("scopeOrgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
export async function down(knex: Knex): Promise<void> {
|
||||
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
||||
t.dropColumn("scopeOrgId");
|
||||
});
|
||||
const hasScopeOrgIdColumn = await knex.schema.hasColumn(TableName.IdentityAccessToken, "scopeOrgId");
|
||||
if (hasScopeOrgIdColumn) {
|
||||
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
||||
t.dropColumn("scopeOrgId");
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
@@ -56,12 +56,12 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => {
|
||||
identity,
|
||||
accessTokenTTL,
|
||||
accessTokenMaxTTL
|
||||
} = await server.services.identityUa.login(
|
||||
req.body.clientId,
|
||||
req.body.clientSecret,
|
||||
req.realIp,
|
||||
req.body.subOrganizationName
|
||||
);
|
||||
} = await server.services.identityUa.login({
|
||||
clientId: req.body.clientId,
|
||||
clientSecret: req.body.clientSecret,
|
||||
ip: req.realIp,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -748,6 +748,33 @@ export const authLoginServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
if (!subOrg.rootOrgId) {
|
||||
throw new BadRequestError({
|
||||
message: "Invalid sub-organization"
|
||||
});
|
||||
}
|
||||
|
||||
const rootOrg = await orgDAL.findById(subOrg.rootOrgId);
|
||||
|
||||
if (!rootOrg) {
|
||||
throw new BadRequestError({
|
||||
message: "Invalid root organization"
|
||||
});
|
||||
}
|
||||
|
||||
const rootOrgMembership = await membershipUserDAL.findOne({
|
||||
actorUserId: user.id,
|
||||
scopeOrgId: rootOrg.id,
|
||||
scope: AccessScope.Organization,
|
||||
status: OrgMembershipStatus.Accepted
|
||||
});
|
||||
|
||||
if (!rootOrgMembership) {
|
||||
throw new ForbiddenRequestError({
|
||||
message: "User does not have access to the root organization"
|
||||
});
|
||||
}
|
||||
|
||||
const subOrgmembershipRole = await membershipRoleDAL.findOne({ membershipId: userSubOrgMembership.id });
|
||||
|
||||
// Check if authEnforced is true and the current auth method is not an enforced method
|
||||
@@ -816,7 +843,7 @@ export const authLoginServiceFactory = ({
|
||||
user,
|
||||
userAgent,
|
||||
ip: ipAddress,
|
||||
...(subOrg.rootOrgId && { organizationId: subOrg.rootOrgId }),
|
||||
organizationId: rootOrg.id,
|
||||
subOrganizationId,
|
||||
isMfaVerified: decodedToken.isMfaVerified,
|
||||
mfaMethod: decodedToken.mfaMethod
|
||||
|
||||
@@ -90,7 +90,7 @@ export const identityAliCloudAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -129,7 +129,7 @@ export const identityAwsAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -86,7 +86,7 @@ export const identityAzureAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -82,7 +82,7 @@ export const identityGcpAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -96,7 +96,7 @@ export const identityJwtAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -208,7 +208,7 @@ export const identityKubernetesAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -177,7 +177,7 @@ export const identityLdapAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -86,7 +86,7 @@ export const identityOciAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -97,7 +97,7 @@ export const identityOidcAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -95,7 +95,7 @@ export const identityTlsCertAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -515,7 +515,7 @@ export const identityTokenAuthServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
@@ -93,7 +93,7 @@ export const identityUaServiceFactory = ({
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || "" : org.id;
|
||||
|
||||
// Resolve sub-organization if specified
|
||||
let scopeOrgId = rootOrgId;
|
||||
@@ -101,7 +101,7 @@ export const identityUaServiceFactory = ({
|
||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||
|
||||
if (subOrg) {
|
||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
||||
if (subOrg.rootOrgId === rootOrgId) {
|
||||
// Verify identity has membership in the sub-organization
|
||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
|
||||
Reference in New Issue
Block a user