mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 02:27:39 +00:00
add role deduplication logic
This commit is contained in:
@@ -696,6 +696,9 @@ export const backfillPermission = async () => {
|
|||||||
.populate<{ workspace: IWorkspace }>("workspace")
|
.populate<{ workspace: IWorkspace }>("workspace")
|
||||||
.lean();
|
.lean();
|
||||||
|
|
||||||
|
// group memberships that need the same permission set
|
||||||
|
const roleMap = new Map<string, { membershipIds: string[], permissions: any[], organizationId: string, workspaceId: string }>();
|
||||||
|
|
||||||
for (const membership of memberships) {
|
for (const membership of memberships) {
|
||||||
// get permissions of members except secret permission
|
// get permissions of members except secret permission
|
||||||
const customPermissions = memberProjectPermissions.rules.filter(
|
const customPermissions = memberProjectPermissions.rules.filter(
|
||||||
@@ -711,16 +714,17 @@ export const backfillPermission = async () => {
|
|||||||
if (ability === "read") secretAccessRule[environmentSlug].read = false;
|
if (ability === "read") secretAccessRule[environmentSlug].read = false;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const secretPermissions: any = [];
|
||||||
Object.entries(secretAccessRule).forEach(([envSlug, { read, write }]) => {
|
Object.entries(secretAccessRule).forEach(([envSlug, { read, write }]) => {
|
||||||
if (read) {
|
if (read) {
|
||||||
customPermissions.push({
|
secretPermissions.push({
|
||||||
subject: ProjectPermissionSub.Secrets,
|
subject: ProjectPermissionSub.Secrets,
|
||||||
action: ProjectPermissionActions.Read,
|
action: ProjectPermissionActions.Read,
|
||||||
conditions: { environment: envSlug }
|
conditions: { environment: envSlug }
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
if (write) {
|
if (write) {
|
||||||
customPermissions.push(
|
secretPermissions.push(
|
||||||
{
|
{
|
||||||
subject: ProjectPermissionSub.Secrets,
|
subject: ProjectPermissionSub.Secrets,
|
||||||
action: ProjectPermissionActions.Edit,
|
action: ProjectPermissionActions.Edit,
|
||||||
@@ -740,23 +744,44 @@ export const backfillPermission = async () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const key = `${JSON.stringify(secretPermissions)}-${membership.workspace.organization.toString()}-${membership.workspace._id.toString()}`; // group roles that have same permission with in the same org and workspace
|
||||||
|
const value = roleMap.get(key);
|
||||||
|
if (value) {
|
||||||
|
value.membershipIds.push(membership._id.toString());
|
||||||
|
value.organizationId = membership.workspace.organization.toString()
|
||||||
|
value.workspaceId = membership.workspace._id.toString()
|
||||||
|
} else {
|
||||||
|
roleMap.set(key, { membershipIds: [membership._id.toString()], permissions: [...customPermissions, ...secretPermissions], organizationId: membership.workspace.organization.toString(), workspaceId: membership.workspace._id.toString() });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const [key, value] of roleMap.entries()) {
|
||||||
|
const { membershipIds, permissions, workspaceId, organizationId } = value
|
||||||
|
|
||||||
const role = new Role({
|
const role = new Role({
|
||||||
name: "Migrated Role",
|
name: "Migrated Role",
|
||||||
organization: membership.workspace.organization,
|
organization: organizationId,
|
||||||
workspace: membership.workspace._id,
|
workspace: workspaceId,
|
||||||
|
description: "This role was auto generated by Infisical with the release of our new permission system",
|
||||||
isOrgRole: false,
|
isOrgRole: false,
|
||||||
slug: `custom-role-${crypto.randomBytes(3).toString("hex")}`,
|
slug: `custom-role-${crypto.randomBytes(3).toString("hex")}`,
|
||||||
permissions: customPermissions
|
permissions: permissions
|
||||||
});
|
});
|
||||||
|
|
||||||
await role.save();
|
await role.save();
|
||||||
await Membership.findByIdAndUpdate(membership._id, {
|
|
||||||
$set: {
|
for (const id of membershipIds) {
|
||||||
role: CUSTOM,
|
await Membership.findByIdAndUpdate(id, { // document db doesn't support update many so we must loop
|
||||||
customRole: role
|
$set: {
|
||||||
}
|
role: CUSTOM,
|
||||||
});
|
customRole: role
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
console.log("Backfill: Finished converting old denied permission in workspace to viewers");
|
||||||
|
|
||||||
await MembershipOrg.updateMany(
|
await MembershipOrg.updateMany(
|
||||||
{
|
{
|
||||||
role: OWNER
|
role: OWNER
|
||||||
@@ -767,5 +792,6 @@ export const backfillPermission = async () => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
console.log("Backfill: Finishing converting old denied permission in workspace to viewers");
|
|
||||||
|
console.log("Backfill: Finished converting owner role to member");
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user