mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 21:27:31 +00:00
fix: greptile review comments
This commit is contained in:
+13
-7
@@ -3,14 +3,20 @@ import { Knex } from "knex";
|
|||||||
import { TableName } from "../schemas";
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
export async function up(knex: Knex): Promise<void> {
|
||||||
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
const hasScopeOrgIdColumn = await knex.schema.hasColumn(TableName.IdentityAccessToken, "scopeOrgId");
|
||||||
t.uuid("scopeOrgId").notNullable();
|
if (!hasScopeOrgIdColumn) {
|
||||||
t.foreign("scopeOrgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
|
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
||||||
});
|
t.uuid("scopeOrgId");
|
||||||
|
t.foreign("scopeOrgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
export async function down(knex: Knex): Promise<void> {
|
||||||
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
const hasScopeOrgIdColumn = await knex.schema.hasColumn(TableName.IdentityAccessToken, "scopeOrgId");
|
||||||
t.dropColumn("scopeOrgId");
|
if (hasScopeOrgIdColumn) {
|
||||||
});
|
await knex.schema.alterTable(TableName.IdentityAccessToken, (t) => {
|
||||||
|
t.dropColumn("scopeOrgId");
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -56,12 +56,12 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => {
|
|||||||
identity,
|
identity,
|
||||||
accessTokenTTL,
|
accessTokenTTL,
|
||||||
accessTokenMaxTTL
|
accessTokenMaxTTL
|
||||||
} = await server.services.identityUa.login(
|
} = await server.services.identityUa.login({
|
||||||
req.body.clientId,
|
clientId: req.body.clientId,
|
||||||
req.body.clientSecret,
|
clientSecret: req.body.clientSecret,
|
||||||
req.realIp,
|
ip: req.realIp,
|
||||||
req.body.subOrganizationName
|
subOrganizationName: req.body.subOrganizationName
|
||||||
);
|
});
|
||||||
|
|
||||||
await server.services.auditLog.createAuditLog({
|
await server.services.auditLog.createAuditLog({
|
||||||
...req.auditLogInfo,
|
...req.auditLogInfo,
|
||||||
|
|||||||
@@ -748,6 +748,33 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!subOrg.rootOrgId) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Invalid sub-organization"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const rootOrg = await orgDAL.findById(subOrg.rootOrgId);
|
||||||
|
|
||||||
|
if (!rootOrg) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Invalid root organization"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const rootOrgMembership = await membershipUserDAL.findOne({
|
||||||
|
actorUserId: user.id,
|
||||||
|
scopeOrgId: rootOrg.id,
|
||||||
|
scope: AccessScope.Organization,
|
||||||
|
status: OrgMembershipStatus.Accepted
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!rootOrgMembership) {
|
||||||
|
throw new ForbiddenRequestError({
|
||||||
|
message: "User does not have access to the root organization"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const subOrgmembershipRole = await membershipRoleDAL.findOne({ membershipId: userSubOrgMembership.id });
|
const subOrgmembershipRole = await membershipRoleDAL.findOne({ membershipId: userSubOrgMembership.id });
|
||||||
|
|
||||||
// Check if authEnforced is true and the current auth method is not an enforced method
|
// Check if authEnforced is true and the current auth method is not an enforced method
|
||||||
@@ -816,7 +843,7 @@ export const authLoginServiceFactory = ({
|
|||||||
user,
|
user,
|
||||||
userAgent,
|
userAgent,
|
||||||
ip: ipAddress,
|
ip: ipAddress,
|
||||||
...(subOrg.rootOrgId && { organizationId: subOrg.rootOrgId }),
|
organizationId: rootOrg.id,
|
||||||
subOrganizationId,
|
subOrganizationId,
|
||||||
isMfaVerified: decodedToken.isMfaVerified,
|
isMfaVerified: decodedToken.isMfaVerified,
|
||||||
mfaMethod: decodedToken.mfaMethod
|
mfaMethod: decodedToken.mfaMethod
|
||||||
|
|||||||
@@ -90,7 +90,7 @@ export const identityAliCloudAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -129,7 +129,7 @@ export const identityAwsAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -86,7 +86,7 @@ export const identityAzureAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -82,7 +82,7 @@ export const identityGcpAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -96,7 +96,7 @@ export const identityJwtAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -208,7 +208,7 @@ export const identityKubernetesAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -177,7 +177,7 @@ export const identityLdapAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -86,7 +86,7 @@ export const identityOciAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -95,7 +95,7 @@ export const identityTlsCertAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -515,7 +515,7 @@ export const identityTokenAuthServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
@@ -93,7 +93,7 @@ export const identityUaServiceFactory = ({
|
|||||||
const org = await orgDAL.findById(identity.orgId);
|
const org = await orgDAL.findById(identity.orgId);
|
||||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||||
|
|
||||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
const rootOrgId = isSubOrg ? org.rootOrgId || "" : org.id;
|
||||||
|
|
||||||
// Resolve sub-organization if specified
|
// Resolve sub-organization if specified
|
||||||
let scopeOrgId = rootOrgId;
|
let scopeOrgId = rootOrgId;
|
||||||
@@ -101,7 +101,7 @@ export const identityUaServiceFactory = ({
|
|||||||
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
const subOrg = await orgDAL.findOne({ slug: subOrganizationName });
|
||||||
|
|
||||||
if (subOrg) {
|
if (subOrg) {
|
||||||
if (!isSubOrg || (isSubOrg && subOrg.rootOrgId === rootOrgId)) {
|
if (subOrg.rootOrgId === rootOrgId) {
|
||||||
// Verify identity has membership in the sub-organization
|
// Verify identity has membership in the sub-organization
|
||||||
const subOrgMembership = await membershipIdentityDAL.findOne({
|
const subOrgMembership = await membershipIdentityDAL.findOne({
|
||||||
scope: AccessScope.Organization,
|
scope: AccessScope.Organization,
|
||||||
|
|||||||
Reference in New Issue
Block a user