mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 06:27:40 +00:00
fix: general access accessible only from private creation
This commit is contained in:
@@ -95,8 +95,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
|||||||
tag: z.string(),
|
tag: z.string(),
|
||||||
hashedHex: z.string(),
|
hashedHex: z.string(),
|
||||||
expiresAt: z.string(),
|
expiresAt: z.string(),
|
||||||
expiresAfterViews: z.number(),
|
expiresAfterViews: z.number()
|
||||||
accessType: z.nativeEnum(SecretSharingAccessType).default(SecretSharingAccessType.Organization)
|
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -105,7 +104,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const { encryptedValue, iv, tag, hashedHex, expiresAt, expiresAfterViews, accessType } = req.body;
|
const { encryptedValue, iv, tag, hashedHex, expiresAt, expiresAfterViews } = req.body;
|
||||||
const sharedSecret = await req.server.services.secretSharing.createPublicSharedSecret({
|
const sharedSecret = await req.server.services.secretSharing.createPublicSharedSecret({
|
||||||
encryptedValue,
|
encryptedValue,
|
||||||
iv,
|
iv,
|
||||||
@@ -113,7 +112,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
|
|||||||
hashedHex,
|
hashedHex,
|
||||||
expiresAt: new Date(expiresAt),
|
expiresAt: new Date(expiresAt),
|
||||||
expiresAfterViews,
|
expiresAfterViews,
|
||||||
accessType
|
accessType: SecretSharingAccessType.Anyone
|
||||||
});
|
});
|
||||||
return { id: sharedSecret.id };
|
return { id: sharedSecret.id };
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import crypto from "crypto";
|
import crypto from "crypto";
|
||||||
|
|
||||||
|
import { useEffect, useRef } from "react";
|
||||||
import { Controller } from "react-hook-form";
|
import { Controller } from "react-hook-form";
|
||||||
import { AxiosError } from "axios";
|
import { AxiosError } from "axios";
|
||||||
import * as yup from "yup";
|
import * as yup from "yup";
|
||||||
@@ -36,6 +37,14 @@ export const AddShareSecretForm = ({
|
|||||||
setNewSharedSecret: (value: string) => void;
|
setNewSharedSecret: (value: string) => void;
|
||||||
isInputDisabled?: boolean;
|
isInputDisabled?: boolean;
|
||||||
}) => {
|
}) => {
|
||||||
|
const isMounted = useRef(true);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
return () => {
|
||||||
|
isMounted.current = false;
|
||||||
|
};
|
||||||
|
}, []);
|
||||||
|
|
||||||
const publicSharedSecretCreator = useCreatePublicSharedSecret();
|
const publicSharedSecretCreator = useCreatePublicSharedSecret();
|
||||||
const privateSharedSecretCreator = useCreateSharedSecret();
|
const privateSharedSecretCreator = useCreateSharedSecret();
|
||||||
const createSharedSecret = isPublic ? publicSharedSecretCreator : privateSharedSecretCreator;
|
const createSharedSecret = isPublic ? publicSharedSecretCreator : privateSharedSecretCreator;
|
||||||
@@ -94,16 +103,18 @@ export const AddShareSecretForm = ({
|
|||||||
expiresAfterViews: expiresAfterSingleView ? 1 : 1000,
|
expiresAfterViews: expiresAfterSingleView ? 1 : 1000,
|
||||||
accessType: accessType as SecretSharingAccessType
|
accessType: accessType as SecretSharingAccessType
|
||||||
});
|
});
|
||||||
setNewSharedSecret(
|
|
||||||
`${window.location.origin}/shared/secret/${id}?key=${encodeURIComponent(
|
|
||||||
hashedHex
|
|
||||||
)}-${encodeURIComponent(key)}`
|
|
||||||
);
|
|
||||||
|
|
||||||
createNotification({
|
if (isMounted.current) {
|
||||||
text: "Successfully created a shared secret",
|
setNewSharedSecret(
|
||||||
type: "success"
|
`${window.location.origin}/shared/secret/${id}?key=${encodeURIComponent(
|
||||||
});
|
hashedHex
|
||||||
|
)}-${encodeURIComponent(key)}`
|
||||||
|
);
|
||||||
|
createNotification({
|
||||||
|
text: "Successfully created a shared secret",
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
}
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
console.error(err);
|
console.error(err);
|
||||||
const axiosError = err as AxiosError;
|
const axiosError = err as AxiosError;
|
||||||
@@ -146,7 +157,7 @@ export const AddShareSecretForm = ({
|
|||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<div className="flex w-full flex-col md:flex-row justify-strech">
|
<div className="flex w-full flex-col md:flex-row justify-stretch">
|
||||||
<div className="flex justify-start">
|
<div className="flex justify-start">
|
||||||
<div className="flex justify-start">
|
<div className="flex justify-start">
|
||||||
<div className="flex w-full justify-center pr-2">
|
<div className="flex w-full justify-center pr-2">
|
||||||
@@ -230,23 +241,25 @@ export const AddShareSecretForm = ({
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<Controller
|
{!isPublic && (
|
||||||
control={control}
|
<Controller
|
||||||
name="accessType"
|
control={control}
|
||||||
defaultValue="organization"
|
name="accessType"
|
||||||
render={({ field: { onChange, ...field } }) => (
|
defaultValue="organization"
|
||||||
<FormControl label="General Access">
|
render={({ field: { onChange, ...field } }) => (
|
||||||
<Select
|
<FormControl label="General Access">
|
||||||
{...field}
|
<Select
|
||||||
onValueChange={(e) => onChange(e)}
|
{...field}
|
||||||
>
|
onValueChange={(e) => onChange(e)}
|
||||||
<SelectItem value="organization">People within your organization</SelectItem>
|
>
|
||||||
<SelectItem value="anyone">Anyone</SelectItem>
|
<SelectItem value="organization">People within your organization</SelectItem>
|
||||||
</Select>
|
<SelectItem value="anyone">Anyone</SelectItem>
|
||||||
</FormControl>
|
</Select>
|
||||||
)}
|
</FormControl>
|
||||||
/>
|
)}
|
||||||
<div className={`flex items-center space-x-4 mt-6 ${!inModal && "justify-start pt-2"}`}>
|
/>
|
||||||
|
)}
|
||||||
|
<div className={`flex items-center space-x-4 pt-2 ${!inModal && ""}`}>
|
||||||
<Button className="mr-0" type="submit" isDisabled={isSubmitting} isLoading={isSubmitting}>
|
<Button className="mr-0" type="submit" isDisabled={isSubmitting} isLoading={isSubmitting}>
|
||||||
{inModal ? "Create" : "Share Secret"}
|
{inModal ? "Create" : "Share Secret"}
|
||||||
</Button>
|
</Button>
|
||||||
|
|||||||
Reference in New Issue
Block a user