feat: added project id mapping logic for cert and kms

This commit is contained in:
=
2024-12-13 21:38:42 +05:30
parent a857375cc1
commit 0fd8274ff0
10 changed files with 169 additions and 23 deletions
+8
View File
@@ -202,6 +202,9 @@ import {
TProjectSlackConfigs, TProjectSlackConfigs,
TProjectSlackConfigsInsert, TProjectSlackConfigsInsert,
TProjectSlackConfigsUpdate, TProjectSlackConfigsUpdate,
TProjectSplitBackfillIds,
TProjectSplitBackfillIdsInsert,
TProjectSplitBackfillIdsUpdate,
TProjectsUpdate, TProjectsUpdate,
TProjectTemplates, TProjectTemplates,
TProjectTemplatesInsert, TProjectTemplatesInsert,
@@ -838,5 +841,10 @@ declare module "knex/types/tables" {
TProjectTemplatesUpdate TProjectTemplatesUpdate
>; >;
[TableName.TotpConfig]: KnexOriginal.CompositeTableType<TTotpConfigs, TTotpConfigsInsert, TTotpConfigsUpdate>; [TableName.TotpConfig]: KnexOriginal.CompositeTableType<TTotpConfigs, TTotpConfigsInsert, TTotpConfigsUpdate>;
[TableName.ProjectSplitBackfillIds]: KnexOriginal.CompositeTableType<
TProjectSplitBackfillIds,
TProjectSplitBackfillIdsInsert,
TProjectSplitBackfillIdsUpdate
>;
} }
} }
+1
View File
@@ -65,6 +65,7 @@ export * from "./project-keys";
export * from "./project-memberships"; export * from "./project-memberships";
export * from "./project-roles"; export * from "./project-roles";
export * from "./project-slack-configs"; export * from "./project-slack-configs";
export * from "./project-split-backfill-ids";
export * from "./project-templates"; export * from "./project-templates";
export * from "./project-user-additional-privilege"; export * from "./project-user-additional-privilege";
export * from "./project-user-membership-roles"; export * from "./project-user-membership-roles";
@@ -0,0 +1,21 @@
// Code generated by automation script, DO NOT EDIT.
// Automated by pulling database and generating zod schema
// To update. Just run npm run generate:schema
// Written by akhilmhdh.
import { z } from "zod";
import { TImmutableDBKeys } from "./models";
export const ProjectSplitBackfillIdsSchema = z.object({
id: z.string().uuid(),
sourceProjectId: z.string(),
destinationProjectType: z.string(),
destinationProjectId: z.string()
});
export type TProjectSplitBackfillIds = z.infer<typeof ProjectSplitBackfillIdsSchema>;
export type TProjectSplitBackfillIdsInsert = Omit<z.input<typeof ProjectSplitBackfillIdsSchema>, TImmutableDBKeys>;
export type TProjectSplitBackfillIdsUpdate = Partial<
Omit<z.input<typeof ProjectSplitBackfillIdsSchema>, TImmutableDBKeys>
>;
+6 -3
View File
@@ -757,7 +757,8 @@ export const registerRoutes = async (
pkiAlertDAL, pkiAlertDAL,
pkiCollectionDAL, pkiCollectionDAL,
permissionService, permissionService,
smtpService smtpService,
projectDAL
}); });
const pkiCollectionService = pkiCollectionServiceFactory({ const pkiCollectionService = pkiCollectionServiceFactory({
@@ -765,7 +766,8 @@ export const registerRoutes = async (
pkiCollectionItemDAL, pkiCollectionItemDAL,
certificateAuthorityDAL, certificateAuthorityDAL,
certificateDAL, certificateDAL,
permissionService permissionService,
projectDAL
}); });
const projectTemplateService = projectTemplateServiceFactory({ const projectTemplateService = projectTemplateServiceFactory({
@@ -1273,7 +1275,8 @@ export const registerRoutes = async (
const cmekService = cmekServiceFactory({ const cmekService = cmekServiceFactory({
kmsDAL, kmsDAL,
kmsService, kmsService,
permissionService permissionService,
projectDAL
}); });
const externalMigrationQueue = externalMigrationQueueFactory({ const externalMigrationQueue = externalMigrationQueueFactory({
@@ -77,7 +77,10 @@ type TCertificateAuthorityServiceFactoryDep = {
certificateBodyDAL: Pick<TCertificateBodyDALFactory, "create">; certificateBodyDAL: Pick<TCertificateBodyDALFactory, "create">;
pkiCollectionDAL: Pick<TPkiCollectionDALFactory, "findById">; pkiCollectionDAL: Pick<TPkiCollectionDALFactory, "findById">;
pkiCollectionItemDAL: Pick<TPkiCollectionItemDALFactory, "create">; pkiCollectionItemDAL: Pick<TPkiCollectionItemDALFactory, "create">;
projectDAL: Pick<TProjectDALFactory, "findProjectBySlug" | "findOne" | "updateById" | "findById" | "transaction">; projectDAL: Pick<
TProjectDALFactory,
"findProjectBySlug" | "findOne" | "updateById" | "findById" | "transaction" | "getProjectFromSplitId"
>;
kmsService: Pick<TKmsServiceFactory, "generateKmsKey" | "encryptWithKmsKey" | "decryptWithKmsKey">; kmsService: Pick<TKmsServiceFactory, "generateKmsKey" | "encryptWithKmsKey" | "decryptWithKmsKey">;
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">; permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
}; };
@@ -123,11 +126,20 @@ export const certificateAuthorityServiceFactory = ({
}: TCreateCaDTO) => { }: TCreateCaDTO) => {
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId); const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
if (!project) throw new NotFoundError({ message: `Project with slug '${projectSlug}' not found` }); if (!project) throw new NotFoundError({ message: `Project with slug '${projectSlug}' not found` });
let projectId = project.id;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission( const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
project.id, projectId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
); );
@@ -162,7 +174,7 @@ export const certificateAuthorityServiceFactory = ({
const ca = await certificateAuthorityDAL.create( const ca = await certificateAuthorityDAL.create(
{ {
projectId: project.id, projectId,
type, type,
organization, organization,
ou, ou,
@@ -186,7 +198,7 @@ export const certificateAuthorityServiceFactory = ({
); );
const certificateManagerKmsId = await getProjectKmsCertificateKeyId({ const certificateManagerKmsId = await getProjectKmsCertificateKeyId({
projectId: project.id, projectId,
projectDAL, projectDAL,
kmsService kmsService
}); });
+21 -3
View File
@@ -15,16 +15,25 @@ import {
import { TKmsKeyDALFactory } from "@app/services/kms/kms-key-dal"; import { TKmsKeyDALFactory } from "@app/services/kms/kms-key-dal";
import { TKmsServiceFactory } from "@app/services/kms/kms-service"; import { TKmsServiceFactory } from "@app/services/kms/kms-service";
import { TProjectDALFactory } from "../project/project-dal";
type TCmekServiceFactoryDep = { type TCmekServiceFactoryDep = {
kmsService: TKmsServiceFactory; kmsService: TKmsServiceFactory;
kmsDAL: TKmsKeyDALFactory; kmsDAL: TKmsKeyDALFactory;
permissionService: TPermissionServiceFactory; permissionService: TPermissionServiceFactory;
projectDAL: Pick<TProjectDALFactory, "getProjectFromSplitId">;
}; };
export type TCmekServiceFactory = ReturnType<typeof cmekServiceFactory>; export type TCmekServiceFactory = ReturnType<typeof cmekServiceFactory>;
export const cmekServiceFactory = ({ kmsService, kmsDAL, permissionService }: TCmekServiceFactoryDep) => { export const cmekServiceFactory = ({ kmsService, kmsDAL, permissionService, projectDAL }: TCmekServiceFactoryDep) => {
const createCmek = async ({ projectId, ...dto }: TCreateCmekDTO, actor: OrgServiceActor) => { const createCmek = async ({ projectId: preSplitProjectId, ...dto }: TCreateCmekDTO, actor: OrgServiceActor) => {
let projectId = preSplitProjectId;
const cmekProjectFromSplit = await projectDAL.getProjectFromSplitId(projectId, ProjectType.Cmek);
if (cmekProjectFromSplit) {
projectId = cmekProjectFromSplit.id;
}
const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission( const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission(
actor.type, actor.type,
actor.id, actor.id,
@@ -90,7 +99,16 @@ export const cmekServiceFactory = ({ kmsService, kmsDAL, permissionService }: TC
return cmek; return cmek;
}; };
const listCmeksByProjectId = async ({ projectId, ...filters }: TListCmeksByProjectIdDTO, actor: OrgServiceActor) => { const listCmeksByProjectId = async (
{ projectId: preSplitProjectId, ...filters }: TListCmeksByProjectIdDTO,
actor: OrgServiceActor
) => {
let projectId = preSplitProjectId;
const cmekProjectFromSplit = await projectDAL.getProjectFromSplitId(preSplitProjectId, ProjectType.Cmek);
if (cmekProjectFromSplit) {
projectId = cmekProjectFromSplit.id;
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor.type, actor.type,
actor.id, actor.id,
@@ -9,6 +9,7 @@ import { TPkiCollectionDALFactory } from "@app/services/pki-collection/pki-colle
import { pkiItemTypeToNameMap } from "@app/services/pki-collection/pki-collection-types"; import { pkiItemTypeToNameMap } from "@app/services/pki-collection/pki-collection-types";
import { SmtpTemplates, TSmtpService } from "@app/services/smtp/smtp-service"; import { SmtpTemplates, TSmtpService } from "@app/services/smtp/smtp-service";
import { TProjectDALFactory } from "../project/project-dal";
import { TPkiAlertDALFactory } from "./pki-alert-dal"; import { TPkiAlertDALFactory } from "./pki-alert-dal";
import { TCreateAlertDTO, TDeleteAlertDTO, TGetAlertByIdDTO, TUpdateAlertDTO } from "./pki-alert-types"; import { TCreateAlertDTO, TDeleteAlertDTO, TGetAlertByIdDTO, TUpdateAlertDTO } from "./pki-alert-types";
@@ -20,6 +21,7 @@ type TPkiAlertServiceFactoryDep = {
pkiCollectionDAL: Pick<TPkiCollectionDALFactory, "findById">; pkiCollectionDAL: Pick<TPkiCollectionDALFactory, "findById">;
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">; permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
smtpService: Pick<TSmtpService, "sendMail">; smtpService: Pick<TSmtpService, "sendMail">;
projectDAL: Pick<TProjectDALFactory, "getProjectFromSplitId">;
}; };
export type TPkiAlertServiceFactory = ReturnType<typeof pkiAlertServiceFactory>; export type TPkiAlertServiceFactory = ReturnType<typeof pkiAlertServiceFactory>;
@@ -28,7 +30,8 @@ export const pkiAlertServiceFactory = ({
pkiAlertDAL, pkiAlertDAL,
pkiCollectionDAL, pkiCollectionDAL,
permissionService, permissionService,
smtpService smtpService,
projectDAL
}: TPkiAlertServiceFactoryDep) => { }: TPkiAlertServiceFactoryDep) => {
const sendPkiItemExpiryNotices = async () => { const sendPkiItemExpiryNotices = async () => {
const allAlertItems = await pkiAlertDAL.getExpiringPkiCollectionItemsForAlerting(); const allAlertItems = await pkiAlertDAL.getExpiringPkiCollectionItemsForAlerting();
@@ -64,7 +67,7 @@ export const pkiAlertServiceFactory = ({
}; };
const createPkiAlert = async ({ const createPkiAlert = async ({
projectId, projectId: preSplitProjectId,
name, name,
pkiCollectionId, pkiCollectionId,
alertBeforeDays, alertBeforeDays,
@@ -74,6 +77,15 @@ export const pkiAlertServiceFactory = ({
actor, actor,
actorOrgId actorOrgId
}: TCreateAlertDTO) => { }: TCreateAlertDTO) => {
let projectId = preSplitProjectId;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission( const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
@@ -7,6 +7,7 @@ import { BadRequestError, NotFoundError } from "@app/lib/errors";
import { TCertificateDALFactory } from "@app/services/certificate/certificate-dal"; import { TCertificateDALFactory } from "@app/services/certificate/certificate-dal";
import { TCertificateAuthorityDALFactory } from "@app/services/certificate-authority/certificate-authority-dal"; import { TCertificateAuthorityDALFactory } from "@app/services/certificate-authority/certificate-authority-dal";
import { TProjectDALFactory } from "../project/project-dal";
import { TPkiCollectionDALFactory } from "./pki-collection-dal"; import { TPkiCollectionDALFactory } from "./pki-collection-dal";
import { transformPkiCollectionItem } from "./pki-collection-fns"; import { transformPkiCollectionItem } from "./pki-collection-fns";
import { TPkiCollectionItemDALFactory } from "./pki-collection-item-dal"; import { TPkiCollectionItemDALFactory } from "./pki-collection-item-dal";
@@ -30,6 +31,7 @@ type TPkiCollectionServiceFactoryDep = {
certificateAuthorityDAL: Pick<TCertificateAuthorityDALFactory, "find" | "findOne">; certificateAuthorityDAL: Pick<TCertificateAuthorityDALFactory, "find" | "findOne">;
certificateDAL: Pick<TCertificateDALFactory, "find">; certificateDAL: Pick<TCertificateDALFactory, "find">;
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">; permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
projectDAL: Pick<TProjectDALFactory, "getProjectFromSplitId">;
}; };
export type TPkiCollectionServiceFactory = ReturnType<typeof pkiCollectionServiceFactory>; export type TPkiCollectionServiceFactory = ReturnType<typeof pkiCollectionServiceFactory>;
@@ -39,17 +41,27 @@ export const pkiCollectionServiceFactory = ({
pkiCollectionItemDAL, pkiCollectionItemDAL,
certificateAuthorityDAL, certificateAuthorityDAL,
certificateDAL, certificateDAL,
permissionService permissionService,
projectDAL
}: TPkiCollectionServiceFactoryDep) => { }: TPkiCollectionServiceFactoryDep) => {
const createPkiCollection = async ({ const createPkiCollection = async ({
name, name,
description, description,
projectId, projectId: preSplitProjectId,
actorId, actorId,
actorAuthMethod, actorAuthMethod,
actor, actor,
actorOrgId actorOrgId
}: TCreatePkiCollectionDTO) => { }: TCreatePkiCollectionDTO) => {
let projectId = preSplitProjectId;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission( const { permission, ForbidOnInvalidProjectType } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
+18 -1
View File
@@ -336,6 +336,22 @@ export const projectDALFactory = (db: TDbClient) => {
}; };
}; };
const getProjectFromSplitId = async (projectId: string, projectType: ProjectType) => {
try {
const project = await db(TableName.ProjectSplitBackfillIds)
.where({
sourceProjectId: projectId,
destinationProjectType: projectType
})
.join(TableName.Project, `${TableName.Project}.id`, `${TableName.ProjectSplitBackfillIds}.destinationProjectId`)
.select(selectAllTableCols(TableName.Project))
.first();
return project;
} catch (error) {
throw new DatabaseError({ error, name: `Failed to find split project with id ${projectId}` });
}
};
return { return {
...projectOrm, ...projectOrm,
findAllProjects, findAllProjects,
@@ -346,6 +362,7 @@ export const projectDALFactory = (db: TDbClient) => {
findProjectByFilter, findProjectByFilter,
findProjectBySlug, findProjectBySlug,
findProjectWithOrg, findProjectWithOrg,
checkProjectUpgradeStatus checkProjectUpgradeStatus,
getProjectFromSplitId
}; };
}; };
@@ -688,11 +688,19 @@ export const projectServiceFactory = ({
actor actor
}: TListProjectCasDTO) => { }: TListProjectCasDTO) => {
const project = await projectDAL.findProjectByFilter(filter); const project = await projectDAL.findProjectByFilter(filter);
let projectId = project.id;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
project.id, projectId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
); );
@@ -704,7 +712,7 @@ export const projectServiceFactory = ({
const cas = await certificateAuthorityDAL.find( const cas = await certificateAuthorityDAL.find(
{ {
projectId: project.id, projectId,
...(status && { status }), ...(status && { status }),
...(friendlyName && { friendlyName }), ...(friendlyName && { friendlyName }),
...(commonName && { commonName }) ...(commonName && { commonName })
@@ -730,18 +738,26 @@ export const projectServiceFactory = ({
actor actor
}: TListProjectCertsDTO) => { }: TListProjectCertsDTO) => {
const project = await projectDAL.findProjectByFilter(filter); const project = await projectDAL.findProjectByFilter(filter);
let projectId = project.id;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
project.id, projectId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
); );
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Certificates); ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Certificates);
const cas = await certificateAuthorityDAL.find({ projectId: project.id }); const cas = await certificateAuthorityDAL.find({ projectId });
const certificates = await certificateDAL.find( const certificates = await certificateDAL.find(
{ {
@@ -755,7 +771,7 @@ export const projectServiceFactory = ({
); );
const count = await certificateDAL.countCertificatesInProject({ const count = await certificateDAL.countCertificatesInProject({
projectId: project.id, projectId,
friendlyName, friendlyName,
commonName commonName
}); });
@@ -770,12 +786,21 @@ export const projectServiceFactory = ({
* Return list of (PKI) alerts configured for project * Return list of (PKI) alerts configured for project
*/ */
const listProjectAlerts = async ({ const listProjectAlerts = async ({
projectId, projectId: preSplitProjectId,
actor, actor,
actorId, actorId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
}: TListProjectAlertsDTO) => { }: TListProjectAlertsDTO) => {
let projectId = preSplitProjectId;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
@@ -797,12 +822,20 @@ export const projectServiceFactory = ({
* Return list of PKI collections for project * Return list of PKI collections for project
*/ */
const listProjectPkiCollections = async ({ const listProjectPkiCollections = async ({
projectId, projectId: preSplitProjectId,
actor, actor,
actorId, actorId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
}: TListProjectAlertsDTO) => { }: TListProjectAlertsDTO) => {
let projectId = preSplitProjectId;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,
@@ -824,12 +857,21 @@ export const projectServiceFactory = ({
* Return list of certificate templates for project * Return list of certificate templates for project
*/ */
const listProjectCertificateTemplates = async ({ const listProjectCertificateTemplates = async ({
projectId, projectId: preSplitProjectId,
actorId, actorId,
actorOrgId, actorOrgId,
actorAuthMethod, actorAuthMethod,
actor actor
}: TListProjectCertificateTemplatesDTO) => { }: TListProjectCertificateTemplatesDTO) => {
let projectId = preSplitProjectId;
const certManagerProjectFromSplit = await projectDAL.getProjectFromSplitId(
projectId,
ProjectType.CertificateManager
);
if (certManagerProjectFromSplit) {
projectId = certManagerProjectFromSplit.id;
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
actorId, actorId,