filter secrets by tags

This commit is contained in:
Maidul Islam
2023-02-13 20:51:43 -08:00
parent 3f9f2ef238
commit 23ea6fd4f9
2 changed files with 42 additions and 25 deletions
+41 -25
View File
@@ -18,6 +18,8 @@ import { postHogClient } from '../../services';
import { getChannelFromUserAgent } from '../../utils/posthog'; import { getChannelFromUserAgent } from '../../utils/posthog';
import { ABILITY_READ, ABILITY_WRITE } from '../../variables/organization'; import { ABILITY_READ, ABILITY_WRITE } from '../../variables/organization';
import { userHasNoAbility, userHasWorkspaceAccess, userHasWriteOnlyAbility } from '../../ee/helpers/checkMembershipPermissions'; import { userHasNoAbility, userHasWorkspaceAccess, userHasWriteOnlyAbility } from '../../ee/helpers/checkMembershipPermissions';
import Tag from '../../models/tag';
import _ from 'lodash';
/** /**
* Create secret(s) for workspace with id [workspaceId] and environment [environment] * Create secret(s) for workspace with id [workspaceId] and environment [environment]
@@ -284,7 +286,10 @@ export const getSecrets = async (req: Request, res: Response) => {
} }
} }
*/ */
const { workspaceId, environment } = req.query;
const { workspaceId, environment, tagSlugs } = req.query;
const tagNamesList = typeof tagSlugs === 'string' ? tagSlugs.split(',') : [];
let userId = "" // used for getting personal secrets for user let userId = "" // used for getting personal secrets for user
let userEmail = "" // used for posthog let userEmail = "" // used for posthog
@@ -308,31 +313,42 @@ export const getSecrets = async (req: Request, res: Response) => {
} }
} }
let secrets: any let secrets: any
if (hasWriteOnlyAccess) { let secretQuery: any
secrets = await Secret.find(
{ if (tagNamesList != undefined && tagNamesList.length != 0) {
workspace: workspaceId, const workspaceFromDB = await Tag.find({ workspace: workspaceId })
environment,
$or: [ const tagIds = _.map(tagNamesList, (tagName) => {
{ user: userId }, const tag = _.find(workspaceFromDB, { slug: tagName });
{ user: { $exists: false } } return tag ? tag.id : null;
], });
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
} secretQuery = {
) workspace: workspaceId,
.select("secretKeyCiphertext secretKeyIV secretKeyTag") environment,
$or: [
{ user: userId },
{ user: { $exists: false } }
],
tags: { $in: tagIds },
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
}
} else { } else {
secrets = await Secret.find( secretQuery = {
{ workspace: workspaceId,
workspace: workspaceId, environment,
environment, $or: [
$or: [ { user: userId },
{ user: userId }, { user: { $exists: false } }
{ user: { $exists: false } } ],
], type: { $in: [SECRET_SHARED, SECRET_PERSONAL] }
type: { $in: [SECRET_SHARED, SECRET_PERSONAL] } }
} }
).populate("tags")
if (hasWriteOnlyAccess) {
secrets = await Secret.find(secretQuery).select("secretKeyCiphertext secretKeyIV secretKeyTag")
} else {
secrets = await Secret.find(secretQuery).populate("tags")
} }
const channel = getChannelFromUserAgent(req.headers['user-agent']) const channel = getChannelFromUserAgent(req.headers['user-agent'])
+1
View File
@@ -74,6 +74,7 @@ router.get(
'/', '/',
query('workspaceId').exists().trim(), query('workspaceId').exists().trim(),
query('environment').exists().trim(), query('environment').exists().trim(),
query('tagSlugs'),
validateRequest, validateRequest,
requireAuth({ requireAuth({
acceptedAuthModes: ['jwt', 'apiKey', 'serviceToken'] acceptedAuthModes: ['jwt', 'apiKey', 'serviceToken']