mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 20:28:16 +00:00
fix(server): duplicate secret deletion made possible
This commit is contained in:
@@ -7,7 +7,7 @@ import { TSecretSnapshotServiceFactory } from "@app/ee/services/secret-snapshot/
|
|||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { buildSecretBlindIndexFromName, encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
import { buildSecretBlindIndexFromName, encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { groupBy, pick } from "@app/lib/fn";
|
import { groupBy, pick, unique } from "@app/lib/fn";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
|
||||||
import { ActorType } from "../auth/auth-type";
|
import { ActorType } from "../auth/auth-type";
|
||||||
@@ -242,10 +242,18 @@ export const secretServiceFactory = ({
|
|||||||
|
|
||||||
if (isNew) {
|
if (isNew) {
|
||||||
if (secrets.length) throw new BadRequestError({ message: "Secret already exist" });
|
if (secrets.length) throw new BadRequestError({ message: "Secret already exist" });
|
||||||
} else if (secrets.length !== inputSecrets.length)
|
} else {
|
||||||
throw new BadRequestError({
|
const secretKeysInDB = unique(secrets, (el) => el.secretBlindIndex as string).map(
|
||||||
message: `Secret not found: blind index ${JSON.stringify(keyName2BlindIndex)}`
|
(el) => blindIndex2KeyName[el.secretBlindIndex as string]
|
||||||
});
|
);
|
||||||
|
const hasUnknownSecretsProvided = secretKeysInDB.length !== inputSecrets.length;
|
||||||
|
if (hasUnknownSecretsProvided) {
|
||||||
|
const keysMissingInDB = Object.keys(keyName2BlindIndex).filter((key) => !secretKeysInDB.includes(key));
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Secret not found: blind index ${keysMissingInDB.join(",")}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
return { blindIndex2KeyName, keyName2BlindIndex, secrets };
|
return { blindIndex2KeyName, keyName2BlindIndex, secrets };
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user