mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 08:27:36 +00:00
filter secrets by tags
This commit is contained in:
@@ -18,6 +18,8 @@ import { postHogClient } from '../../services';
|
|||||||
import { getChannelFromUserAgent } from '../../utils/posthog';
|
import { getChannelFromUserAgent } from '../../utils/posthog';
|
||||||
import { ABILITY_READ, ABILITY_WRITE } from '../../variables/organization';
|
import { ABILITY_READ, ABILITY_WRITE } from '../../variables/organization';
|
||||||
import { userHasNoAbility, userHasWorkspaceAccess, userHasWriteOnlyAbility } from '../../ee/helpers/checkMembershipPermissions';
|
import { userHasNoAbility, userHasWorkspaceAccess, userHasWriteOnlyAbility } from '../../ee/helpers/checkMembershipPermissions';
|
||||||
|
import Tag from '../../models/tag';
|
||||||
|
import _ from 'lodash';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create secret(s) for workspace with id [workspaceId] and environment [environment]
|
* Create secret(s) for workspace with id [workspaceId] and environment [environment]
|
||||||
@@ -284,7 +286,10 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
*/
|
*/
|
||||||
const { workspaceId, environment } = req.query;
|
|
||||||
|
|
||||||
|
const { workspaceId, environment, tagSlugs } = req.query;
|
||||||
|
const tagNamesList = typeof tagSlugs === 'string' ? tagSlugs.split(',') : [];
|
||||||
|
|
||||||
let userId = "" // used for getting personal secrets for user
|
let userId = "" // used for getting personal secrets for user
|
||||||
let userEmail = "" // used for posthog
|
let userEmail = "" // used for posthog
|
||||||
@@ -308,31 +313,42 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
let secrets: any
|
let secrets: any
|
||||||
if (hasWriteOnlyAccess) {
|
let secretQuery: any
|
||||||
secrets = await Secret.find(
|
|
||||||
{
|
if (tagNamesList != undefined && tagNamesList.length != 0) {
|
||||||
workspace: workspaceId,
|
const workspaceFromDB = await Tag.find({ workspace: workspaceId })
|
||||||
environment,
|
|
||||||
$or: [
|
const tagIds = _.map(tagNamesList, (tagName) => {
|
||||||
{ user: userId },
|
const tag = _.find(workspaceFromDB, { slug: tagName });
|
||||||
{ user: { $exists: false } }
|
return tag ? tag.id : null;
|
||||||
],
|
});
|
||||||
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
|
|
||||||
}
|
secretQuery = {
|
||||||
)
|
workspace: workspaceId,
|
||||||
.select("secretKeyCiphertext secretKeyIV secretKeyTag")
|
environment,
|
||||||
|
$or: [
|
||||||
|
{ user: userId },
|
||||||
|
{ user: { $exists: false } }
|
||||||
|
],
|
||||||
|
tags: { $in: tagIds },
|
||||||
|
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
secrets = await Secret.find(
|
secretQuery = {
|
||||||
{
|
workspace: workspaceId,
|
||||||
workspace: workspaceId,
|
environment,
|
||||||
environment,
|
$or: [
|
||||||
$or: [
|
{ user: userId },
|
||||||
{ user: userId },
|
{ user: { $exists: false } }
|
||||||
{ user: { $exists: false } }
|
],
|
||||||
],
|
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
|
||||||
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
|
}
|
||||||
}
|
}
|
||||||
).populate("tags")
|
|
||||||
|
if (hasWriteOnlyAccess) {
|
||||||
|
secrets = await Secret.find(secretQuery).select("secretKeyCiphertext secretKeyIV secretKeyTag")
|
||||||
|
} else {
|
||||||
|
secrets = await Secret.find(secretQuery).populate("tags")
|
||||||
}
|
}
|
||||||
|
|
||||||
const channel = getChannelFromUserAgent(req.headers['user-agent'])
|
const channel = getChannelFromUserAgent(req.headers['user-agent'])
|
||||||
|
|||||||
@@ -74,6 +74,7 @@ router.get(
|
|||||||
'/',
|
'/',
|
||||||
query('workspaceId').exists().trim(),
|
query('workspaceId').exists().trim(),
|
||||||
query('environment').exists().trim(),
|
query('environment').exists().trim(),
|
||||||
|
query('tagSlugs'),
|
||||||
validateRequest,
|
validateRequest,
|
||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: ['jwt', 'apiKey', 'serviceToken']
|
acceptedAuthModes: ['jwt', 'apiKey', 'serviceToken']
|
||||||
|
|||||||
Reference in New Issue
Block a user