mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 02:25:48 +00:00
Refactor secret permission validation in InfisicalSecretInput and improve tooltip styling in CreateSecretForm components
This commit is contained in:
@@ -389,30 +389,26 @@ export const InfisicalSecretInput = forwardRef<HTMLTextAreaElement, Props>(
|
||||
|
||||
const secretPath = segment === environmentSlug ? "/" : folderPath;
|
||||
|
||||
const canReadSecretValue = hasSecretReadValueOrDescribePermission(
|
||||
permission,
|
||||
ProjectPermissionSecretActions.ReadValue,
|
||||
{
|
||||
environment: environmentSlug,
|
||||
secretPath,
|
||||
secretName: secretName ?? "*",
|
||||
secretTags: ["*"]
|
||||
// Only validate secret permission, users can always view environments and folders
|
||||
if (segment === secretName) {
|
||||
const canReadSecretValue = hasSecretReadValueOrDescribePermission(
|
||||
permission,
|
||||
ProjectPermissionSecretActions.ReadValue,
|
||||
{
|
||||
environment: environmentSlug,
|
||||
secretPath,
|
||||
secretName: secretName ?? "*",
|
||||
secretTags: ["*"]
|
||||
}
|
||||
);
|
||||
|
||||
if (!canReadSecretValue) {
|
||||
createNotification({
|
||||
text: "You do not have permission to access this secret",
|
||||
type: "error"
|
||||
});
|
||||
return;
|
||||
}
|
||||
);
|
||||
|
||||
let resourceName = "secret";
|
||||
if (segment === environmentSlug) {
|
||||
resourceName = "environment";
|
||||
} else if (segment !== secretName && folderPath.includes(segment)) {
|
||||
resourceName = "folder";
|
||||
}
|
||||
|
||||
if (!canReadSecretValue) {
|
||||
createNotification({
|
||||
text: `You do not have permission to access this ${resourceName}`,
|
||||
type: "error"
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
navigate({
|
||||
|
||||
Reference in New Issue
Block a user