mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 21:27:31 +00:00
fix: resolved infinite recursion cases
This commit is contained in:
@@ -991,11 +991,16 @@ const recursivelyExpandSecret = async (
|
|||||||
expandedSec: Record<string, string>,
|
expandedSec: Record<string, string>,
|
||||||
interpolatedSec: Record<string, string>,
|
interpolatedSec: Record<string, string>,
|
||||||
fetchCrossEnv: (env: string, secPath: string[], secKey: string) => Promise<string>,
|
fetchCrossEnv: (env: string, secPath: string[], secKey: string) => Promise<string>,
|
||||||
|
recursionChainBreaker: Record<string, boolean>,
|
||||||
key: string
|
key: string
|
||||||
) => {
|
) => {
|
||||||
if (expandedSec?.[key]) {
|
if (expandedSec?.[key]) {
|
||||||
return expandedSec[key];
|
return expandedSec[key];
|
||||||
}
|
}
|
||||||
|
if (recursionChainBreaker?.[key]) {
|
||||||
|
return "";
|
||||||
|
}
|
||||||
|
recursionChainBreaker[key] = true;
|
||||||
|
|
||||||
let interpolatedValue = interpolatedSec[key];
|
let interpolatedValue = interpolatedSec[key];
|
||||||
if (!interpolatedValue) {
|
if (!interpolatedValue) {
|
||||||
@@ -1013,12 +1018,13 @@ const recursivelyExpandSecret = async (
|
|||||||
expandedSec,
|
expandedSec,
|
||||||
interpolatedSec,
|
interpolatedSec,
|
||||||
fetchCrossEnv,
|
fetchCrossEnv,
|
||||||
|
recursionChainBreaker,
|
||||||
interpolationKey
|
interpolationKey
|
||||||
);
|
);
|
||||||
if (val) {
|
if (val) {
|
||||||
interpolatedValue = interpolatedValue.replace(interpolationSyntax, val);
|
interpolatedValue = interpolatedValue.replaceAll(interpolationSyntax, val);
|
||||||
}
|
}
|
||||||
return;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (entities.length > 1) {
|
if (entities.length > 1) {
|
||||||
@@ -1027,11 +1033,12 @@ const recursivelyExpandSecret = async (
|
|||||||
const secRefKey = entities[entities.length - 1];
|
const secRefKey = entities[entities.length - 1];
|
||||||
|
|
||||||
const val = await fetchCrossEnv(secRefEnv, secRefPath, secRefKey);
|
const val = await fetchCrossEnv(secRefEnv, secRefPath, secRefKey);
|
||||||
interpolatedValue = interpolatedValue.replace(interpolationSyntax, val);
|
interpolatedValue = interpolatedValue.replaceAll(interpolationSyntax, val);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
expandedSec[key] = interpolatedValue;
|
||||||
return interpolatedValue;
|
return interpolatedValue;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -1057,17 +1064,21 @@ export const expandSecrets = async (
|
|||||||
for (const key of Object.keys(secrets)) {
|
for (const key of Object.keys(secrets)) {
|
||||||
if (expandedSec?.[key]) {
|
if (expandedSec?.[key]) {
|
||||||
secrets[key].value = expandedSec[key];
|
secrets[key].value = expandedSec[key];
|
||||||
return;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// this is to avoid recursion loop. So the graph should be direct graph rather than cyclic
|
||||||
|
// so for any recursion building if there is an entity two times same key meaning it will be looped
|
||||||
|
const recursionChainBreaker: Record<string, boolean> = {};
|
||||||
const expandedVal = await recursivelyExpandSecret(
|
const expandedVal = await recursivelyExpandSecret(
|
||||||
expandedSec,
|
expandedSec,
|
||||||
interpolatedSec,
|
interpolatedSec,
|
||||||
crossSecEnvFetch,
|
crossSecEnvFetch,
|
||||||
|
recursionChainBreaker,
|
||||||
key
|
key
|
||||||
);
|
);
|
||||||
|
|
||||||
secrets[key].value = expandedVal || "";
|
secrets[key].value = expandedVal;
|
||||||
}
|
}
|
||||||
|
|
||||||
return secrets;
|
return secrets;
|
||||||
|
|||||||
@@ -59,9 +59,11 @@ import _ from "lodash";
|
|||||||
import sodium from "libsodium-wrappers";
|
import sodium from "libsodium-wrappers";
|
||||||
import { standardRequest } from "../config/request";
|
import { standardRequest } from "../config/request";
|
||||||
|
|
||||||
const getSecretKeyValuePair = (secrets: Record<string, { value: string; comment?: string }>) =>
|
const getSecretKeyValuePair = (
|
||||||
|
secrets: Record<string, { value: string; comment?: string } | null>
|
||||||
|
) =>
|
||||||
Object.keys(secrets).reduce<Record<string, string>>((prev, key) => {
|
Object.keys(secrets).reduce<Record<string, string>>((prev, key) => {
|
||||||
prev[key] = secrets[key].value;
|
if (secrets[key]) prev[key] = secrets[key]?.value || "";
|
||||||
return prev;
|
return prev;
|
||||||
}, {});
|
}, {});
|
||||||
|
|
||||||
@@ -667,7 +669,7 @@ const syncSecretsHeroku = async ({
|
|||||||
accessToken
|
accessToken
|
||||||
}: {
|
}: {
|
||||||
integration: IIntegration;
|
integration: IIntegration;
|
||||||
secrets: Record<string, { value: string; comment?: string }>;
|
secrets: Record<string, { value: string; comment?: string } | null>;
|
||||||
accessToken: string;
|
accessToken: string;
|
||||||
}) => {
|
}) => {
|
||||||
const herokuSecrets = (
|
const herokuSecrets = (
|
||||||
@@ -682,7 +684,7 @@ const syncSecretsHeroku = async ({
|
|||||||
|
|
||||||
Object.keys(herokuSecrets).forEach((key) => {
|
Object.keys(herokuSecrets).forEach((key) => {
|
||||||
if (!(key in secrets)) {
|
if (!(key in secrets)) {
|
||||||
delete secrets[key];
|
secrets[key] = null;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
+4
-13
@@ -1,9 +1,7 @@
|
|||||||
{
|
{
|
||||||
"compilerOptions": {
|
"compilerOptions": {
|
||||||
"target": "es2016",
|
"target": "es2016",
|
||||||
"lib": [
|
"lib": ["es6", "es2021"],
|
||||||
"es6"
|
|
||||||
],
|
|
||||||
"module": "commonjs",
|
"module": "commonjs",
|
||||||
"rootDir": "src",
|
"rootDir": "src",
|
||||||
"resolveJsonModule": true,
|
"resolveJsonModule": true,
|
||||||
@@ -15,15 +13,8 @@
|
|||||||
"strict": true,
|
"strict": true,
|
||||||
"noImplicitAny": true,
|
"noImplicitAny": true,
|
||||||
"skipLibCheck": true,
|
"skipLibCheck": true,
|
||||||
"typeRoots": [
|
"typeRoots": ["./src/types", "./node_modules/@types"]
|
||||||
"./src/types",
|
|
||||||
"./node_modules/@types"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
"include": [
|
"include": ["src/**/*"],
|
||||||
"src/**/*"
|
"exclude": ["node_modules"]
|
||||||
],
|
|
||||||
"exclude": [
|
|
||||||
"node_modules"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user