Refactor secret permission validation in InfisicalSecretInput and improve tooltip styling in CreateSecretForm components

This commit is contained in:
Victor Santos
2025-11-10 14:50:57 -03:00
parent 7c4e3bf698
commit 2083e9102f
4 changed files with 50 additions and 51 deletions
@@ -389,30 +389,26 @@ export const InfisicalSecretInput = forwardRef<HTMLTextAreaElement, Props>(
const secretPath = segment === environmentSlug ? "/" : folderPath; const secretPath = segment === environmentSlug ? "/" : folderPath;
const canReadSecretValue = hasSecretReadValueOrDescribePermission( // Only validate secret permission, users can always view environments and folders
permission, if (segment === secretName) {
ProjectPermissionSecretActions.ReadValue, const canReadSecretValue = hasSecretReadValueOrDescribePermission(
{ permission,
environment: environmentSlug, ProjectPermissionSecretActions.ReadValue,
secretPath, {
secretName: secretName ?? "*", environment: environmentSlug,
secretTags: ["*"] secretPath,
secretName: secretName ?? "*",
secretTags: ["*"]
}
);
if (!canReadSecretValue) {
createNotification({
text: "You do not have permission to access this secret",
type: "error"
});
return;
} }
);
let resourceName = "secret";
if (segment === environmentSlug) {
resourceName = "environment";
} else if (segment !== secretName && folderPath.includes(segment)) {
resourceName = "folder";
}
if (!canReadSecretValue) {
createNotification({
text: `You do not have permission to access this ${resourceName}`,
type: "error"
});
return;
} }
navigate({ navigate({
@@ -252,15 +252,15 @@ export const CreateSecretForm = ({ secretPath = "/", onClose }: Props) => {
tooltipText={ tooltipText={
<div> <div>
You can add references to other secrets using the format{" "} You can add references to other secrets using the format{" "}
<code> <code className="rounded-sm bg-mineshaft-600 px-1 py-0.5">
&#36;{"{"}secret_name{"}"} &#36;{"{"}secret_name{"}"}
</code> </code>
<br /> <br />
<br /> <br />
You can go to the referenced secret by holding the{" "} You can go to the referenced secret by holding the{" "}
<code className="rounded-sm bg-mineshaft-600 p-0.5">Cmd</code> (Mac) or{" "} <code className="rounded-sm bg-mineshaft-600 px-1 py-0.5">Cmd</code> (Mac) or{" "}
<code className="rounded-sm bg-mineshaft-600 p-0.5">Ctrl</code> (Windows/Linux) key <code className="rounded-sm bg-mineshaft-600 px-1 py-0.5">Ctrl</code>{" "}
and clicking on the secret name. (Windows/Linux) key and clicking on the secret name.
</div> </div>
} }
tooltipClassName="max-w-md" tooltipClassName="max-w-md"
@@ -219,17 +219,19 @@ const Page = () => {
ProjectPermissionSub.Commits ProjectPermissionSub.Commits
); );
const defaultIncludeFilters = {
[RowType.Folder]: routerQueryParams.filterBy?.includes(RowType.Folder) || false,
[RowType.Import]: routerQueryParams.filterBy?.includes(RowType.Import) || false,
[RowType.DynamicSecret]: routerQueryParams.filterBy?.includes(RowType.DynamicSecret) || false,
[RowType.Secret]: routerQueryParams.filterBy?.includes(RowType.Secret) || false,
[RowType.SecretRotation]: routerQueryParams.filterBy?.includes(RowType.SecretRotation) || false
};
const defaultFilterState = { const defaultFilterState = {
tags: {}, tags: {},
searchFilter: (routerQueryParams.search as string) || "", searchFilter: (routerQueryParams.search as string) || "",
// these should always be on by default for the UI, they will be disabled for the query below based off permissions // these should always be on by default for the UI, they will be disabled for the query below based off permissions
include: { include: defaultIncludeFilters
[RowType.Folder]: false,
[RowType.Import]: false,
[RowType.DynamicSecret]: false,
[RowType.Secret]: false,
[RowType.SecretRotation]: false
}
}; };
const [filter, setFilter] = useState<Filter>(defaultFilterState); const [filter, setFilter] = useState<Filter>(defaultFilterState);
@@ -529,6 +531,19 @@ const Page = () => {
[navigate] [navigate]
); );
const handleClearFilters = useCallback(() => {
setFilter(defaultFilterState);
setDebouncedSearchFilter("");
navigate({
search: (prev) => ({
...prev,
search: "",
tags: "",
filterBy: ""
})
});
}, [navigate]);
const handleSearchChange = useCallback( const handleSearchChange = useCallback(
(searchFilter: string) => { (searchFilter: string) => {
setFilter((state) => ({ ...state, searchFilter })); setFilter((state) => ({ ...state, searchFilter }));
@@ -882,19 +897,7 @@ const Page = () => {
isPITEnabled={isPITEnabled} isPITEnabled={isPITEnabled}
hasPathPolicies={hasPathPolicies} hasPathPolicies={hasPathPolicies}
onRequestAccess={(params) => handlePopUpOpen("requestAccess", params)} onRequestAccess={(params) => handlePopUpOpen("requestAccess", params)}
onClearFilters={() => onClearFilters={handleClearFilters}
setFilter((prev) => ({
...prev,
tags: {},
include: {
secret: false,
import: false,
dynamic: false,
rotation: false,
folder: false
}
}))
}
/> />
<div <div
ref={tableRef} ref={tableRef}
@@ -200,15 +200,15 @@ export const CreateSecretForm = ({
tooltipText={ tooltipText={
<div> <div>
You can add references to other secrets using the format{" "} You can add references to other secrets using the format{" "}
<code> <code className="rounded-sm bg-mineshaft-600 px-1 py-0.5">
&#36;{"{"}secret_name{"}"} &#36;{"{"}secret_name{"}"}
</code> </code>
<br /> <br />
<br /> <br />
You can go to the referenced secret by holding the{" "} You can go to the referenced secret by holding the{" "}
<code className="rounded-sm bg-mineshaft-600 p-0.5">Cmd</code> (Mac) or{" "} <code className="rounded-sm bg-mineshaft-600 px-1 py-0.5">Cmd</code> (Mac) or{" "}
<code className="rounded-sm bg-mineshaft-600 p-0.5">Ctrl</code> (Windows/Linux) key <code className="rounded-sm bg-mineshaft-600 px-1 py-0.5">Ctrl</code>{" "}
and clicking on the secret name. (Windows/Linux) key and clicking on the secret name.
</div> </div>
} }
tooltipClassName="max-w-md" tooltipClassName="max-w-md"