mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 13:27:46 +00:00
feat: added support for personal secrets creation via CLI
This commit is contained in:
@@ -170,6 +170,11 @@ var secretsSetCmd = &cobra.Command{
|
|||||||
util.HandleError(err, "Unable to get your local config details")
|
util.HandleError(err, "Unable to get your local config details")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
secretType, err := cmd.Flags().GetString("type")
|
||||||
|
if err != nil || (secretType != util.SECRET_TYPE_SHARED && secretType != util.SECRET_TYPE_PERSONAL) {
|
||||||
|
util.HandleError(err, "Unable to parse secret type")
|
||||||
|
}
|
||||||
|
|
||||||
loggedInUserDetails, err := util.GetCurrentLoggedInUserDetails()
|
loggedInUserDetails, err := util.GetCurrentLoggedInUserDetails()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to authenticate")
|
util.HandleError(err, "Unable to authenticate")
|
||||||
@@ -179,6 +184,7 @@ var secretsSetCmd = &cobra.Command{
|
|||||||
util.PrintErrorMessageAndExit("Your login session has expired, please run [infisical login] and try again")
|
util.PrintErrorMessageAndExit("Your login session has expired, please run [infisical login] and try again")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
httpClient := resty.New().
|
httpClient := resty.New().
|
||||||
SetAuthToken(loggedInUserDetails.UserCredentials.JTWToken).
|
SetAuthToken(loggedInUserDetails.UserCredentials.JTWToken).
|
||||||
SetHeader("Accept", "application/json")
|
SetHeader("Accept", "application/json")
|
||||||
@@ -224,6 +230,7 @@ var secretsSetCmd = &cobra.Command{
|
|||||||
secretOperations := []SecretSetOperation{}
|
secretOperations := []SecretSetOperation{}
|
||||||
|
|
||||||
secretByKey := getSecretsByKeys(secrets)
|
secretByKey := getSecretsByKeys(secrets)
|
||||||
|
personalSecretByKey := getPersonalSecretsByKeys(secrets)
|
||||||
|
|
||||||
for _, arg := range args {
|
for _, arg := range args {
|
||||||
splitKeyValueFromArg := strings.SplitN(arg, "=", 2)
|
splitKeyValueFromArg := strings.SplitN(arg, "=", 2)
|
||||||
@@ -251,7 +258,16 @@ var secretsSetCmd = &cobra.Command{
|
|||||||
util.HandleError(err, "unable to encrypt your secrets")
|
util.HandleError(err, "unable to encrypt your secrets")
|
||||||
}
|
}
|
||||||
|
|
||||||
if existingSecret, ok := secretByKey[key]; ok {
|
var existingSecret models.SingleEnvironmentVariable
|
||||||
|
var doesSecretExist bool
|
||||||
|
|
||||||
|
if secretType == util.SECRET_TYPE_SHARED {
|
||||||
|
existingSecret, doesSecretExist = secretByKey[key]
|
||||||
|
} else {
|
||||||
|
existingSecret, doesSecretExist = personalSecretByKey[key]
|
||||||
|
}
|
||||||
|
|
||||||
|
if doesSecretExist {
|
||||||
// case: secret exists in project so it needs to be modified
|
// case: secret exists in project so it needs to be modified
|
||||||
encryptedSecretDetails := api.Secret{
|
encryptedSecretDetails := api.Secret{
|
||||||
ID: existingSecret.ID,
|
ID: existingSecret.ID,
|
||||||
@@ -291,7 +307,7 @@ var secretsSetCmd = &cobra.Command{
|
|||||||
SecretValueIV: base64.StdEncoding.EncodeToString(encryptedValue.Nonce),
|
SecretValueIV: base64.StdEncoding.EncodeToString(encryptedValue.Nonce),
|
||||||
SecretValueTag: base64.StdEncoding.EncodeToString(encryptedValue.AuthTag),
|
SecretValueTag: base64.StdEncoding.EncodeToString(encryptedValue.AuthTag),
|
||||||
SecretValueHash: hashedValue,
|
SecretValueHash: hashedValue,
|
||||||
Type: util.SECRET_TYPE_SHARED,
|
Type: secretType,
|
||||||
PlainTextKey: key,
|
PlainTextKey: key,
|
||||||
}
|
}
|
||||||
secretsToCreate = append(secretsToCreate, encryptedSecretDetails)
|
secretsToCreate = append(secretsToCreate, encryptedSecretDetails)
|
||||||
@@ -764,6 +780,19 @@ func getSecretsByKeys(secrets []models.SingleEnvironmentVariable) map[string]mod
|
|||||||
return secretMapByName
|
return secretMapByName
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func getPersonalSecretsByKeys(secrets []models.SingleEnvironmentVariable) map[string]models.SingleEnvironmentVariable {
|
||||||
|
secretMapByName := make(map[string]models.SingleEnvironmentVariable, len(secrets))
|
||||||
|
|
||||||
|
for _, secret := range secrets {
|
||||||
|
if secret.Type == util.SECRET_TYPE_PERSONAL {
|
||||||
|
secretMapByName[secret.Key] = secret
|
||||||
|
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return secretMapByName
|
||||||
|
}
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
secretsGenerateExampleEnvCmd.Flags().String("token", "", "Fetch secrets using the Infisical Token")
|
secretsGenerateExampleEnvCmd.Flags().String("token", "", "Fetch secrets using the Infisical Token")
|
||||||
secretsGenerateExampleEnvCmd.Flags().String("projectId", "", "manually set the projectId to fetch folders from for machine identity")
|
secretsGenerateExampleEnvCmd.Flags().String("projectId", "", "manually set the projectId to fetch folders from for machine identity")
|
||||||
@@ -781,6 +810,7 @@ func init() {
|
|||||||
secretsCmd.Flags().Bool("secret-overriding", true, "Prioritizes personal secrets, if any, with the same name over shared secrets")
|
secretsCmd.Flags().Bool("secret-overriding", true, "Prioritizes personal secrets, if any, with the same name over shared secrets")
|
||||||
secretsCmd.AddCommand(secretsSetCmd)
|
secretsCmd.AddCommand(secretsSetCmd)
|
||||||
secretsSetCmd.Flags().String("path", "/", "set secrets within a folder path")
|
secretsSetCmd.Flags().String("path", "/", "set secrets within a folder path")
|
||||||
|
secretsSetCmd.Flags().String("type", util.SECRET_TYPE_SHARED, "the type of secret to create: personal or shared")
|
||||||
|
|
||||||
// Only supports logged in users (JWT auth)
|
// Only supports logged in users (JWT auth)
|
||||||
secretsSetCmd.PersistentPreRun = func(cmd *cobra.Command, args []string) {
|
secretsSetCmd.PersistentPreRun = func(cmd *cobra.Command, args []string) {
|
||||||
|
|||||||
@@ -153,6 +153,16 @@ $ infisical secrets set STRIPE_API_KEY=sjdgwkeudyjwe DOMAIN=example.com HASH=jeb
|
|||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="--type">
|
||||||
|
Used to select the type of secret to create. This could be either personal or shared (defaults to shared)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Example
|
||||||
|
infisical secrets set DOMAIN=example.com --type=personal
|
||||||
|
```
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="infisical secrets delete">
|
<Accordion title="infisical secrets delete">
|
||||||
|
|||||||
Reference in New Issue
Block a user