mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 22:26:07 +00:00
improvement: allow all users to reject their own access requests
This commit is contained in:
@@ -354,11 +354,17 @@ export const accessApprovalRequestServiceFactory = ({
|
|||||||
status === ApprovalStatus.APPROVED;
|
status === ApprovalStatus.APPROVED;
|
||||||
|
|
||||||
const isApprover = policy.approvers.find((approver) => approver.userId === actorId);
|
const isApprover = policy.approvers.find((approver) => approver.userId === actorId);
|
||||||
// If user is (not an approver OR cant self approve) AND can't bypass policy
|
|
||||||
if ((!isApprover || (!policy.allowedSelfApprovals && isSelfApproval)) && cannotBypassUnderSoftEnforcement) {
|
const isSelfRejection = isSelfApproval && status === ApprovalStatus.REJECTED;
|
||||||
throw new BadRequestError({
|
|
||||||
message: "Failed to review access approval request. Users are not authorized to review their own request."
|
// users can always reject (cancel) their own requests
|
||||||
});
|
if (!isSelfRejection) {
|
||||||
|
// If user is (not an approver OR cant self approve) AND can't bypass policy
|
||||||
|
if ((!isApprover || (!policy.allowedSelfApprovals && isSelfApproval)) && cannotBypassUnderSoftEnforcement) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Failed to review access approval request. Users are not authorized to review their own request."
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (
|
if (
|
||||||
@@ -414,7 +420,7 @@ export const accessApprovalRequestServiceFactory = ({
|
|||||||
);
|
);
|
||||||
|
|
||||||
// Only throw if actor is not the approver and not bypassing
|
// Only throw if actor is not the approver and not bypassing
|
||||||
if (!isApproverOfTheSequence && !isBreakGlassApprovalAttempt) {
|
if (!isApproverOfTheSequence && !isBreakGlassApprovalAttempt && !isSelfRejection) {
|
||||||
throw new BadRequestError({ message: "You are not a reviewer in this step" });
|
throw new BadRequestError({ message: "You are not a reviewer in this step" });
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+6
-8
@@ -255,6 +255,11 @@ export const ReviewAccessRequestModal = ({
|
|||||||
return "You are not the reviewer in this step.";
|
return "You are not the reviewer in this step.";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// users can always reject (cancel) their own request
|
||||||
|
const isRejectionDisabled = request.isRequestedByCurrentUser
|
||||||
|
? false
|
||||||
|
: !(request.isApprover && request.isSelfApproveAllowed) && !bypassApproval;
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<Modal isOpen={isOpen} onOpenChange={onOpenChange}>
|
<Modal isOpen={isOpen} onOpenChange={onOpenChange}>
|
||||||
<ModalContent
|
<ModalContent
|
||||||
@@ -489,14 +494,7 @@ export const ReviewAccessRequestModal = ({
|
|||||||
</Button>
|
</Button>
|
||||||
<Button
|
<Button
|
||||||
isLoading={isLoading === "rejected"}
|
isLoading={isLoading === "rejected"}
|
||||||
isDisabled={
|
isDisabled={!!isLoading || isRejectionDisabled}
|
||||||
!!isLoading ||
|
|
||||||
(!(
|
|
||||||
request.isApprover &&
|
|
||||||
(!request.isRequestedByCurrentUser || request.isSelfApproveAllowed)
|
|
||||||
) &&
|
|
||||||
!bypassApproval)
|
|
||||||
}
|
|
||||||
onClick={() => handleReview("rejected")}
|
onClick={() => handleReview("rejected")}
|
||||||
className="mt-4 border-transparent bg-transparent text-mineshaft-200 hover:border-red hover:bg-red/20 hover:text-mineshaft-200"
|
className="mt-4 border-transparent bg-transparent text-mineshaft-200 hover:border-red hover:bg-red/20 hover:text-mineshaft-200"
|
||||||
size="sm"
|
size="sm"
|
||||||
|
|||||||
Reference in New Issue
Block a user