mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 21:27:31 +00:00
feat: more patchy patch
This commit is contained in:
@@ -372,14 +372,12 @@ export const githubOrgSyncServiceFactory = ({
|
|||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
const memberships = await membershipGroupDAL.insertMany(
|
const memberships = await membershipGroupDAL.insertMany(
|
||||||
newGroups.map(
|
newGroups.map((el) => ({
|
||||||
(el) => ({
|
actorGroupId: el.id,
|
||||||
actorGroupId: el.id,
|
scope: AccessScope.Organization,
|
||||||
scope: AccessScope.Organization,
|
scopeOrgId: orgId
|
||||||
scopeOrgId: orgId
|
})),
|
||||||
}),
|
tx
|
||||||
tx
|
|
||||||
)
|
|
||||||
);
|
);
|
||||||
|
|
||||||
await membershipRoleDAL.insertMany(
|
await membershipRoleDAL.insertMany(
|
||||||
@@ -717,14 +715,12 @@ export const githubOrgSyncServiceFactory = ({
|
|||||||
);
|
);
|
||||||
|
|
||||||
const memberships = await membershipGroupDAL.insertMany(
|
const memberships = await membershipGroupDAL.insertMany(
|
||||||
newGroups.map(
|
newGroups.map((el) => ({
|
||||||
(el) => ({
|
actorGroupId: el.id,
|
||||||
actorGroupId: el.id,
|
scope: AccessScope.Organization,
|
||||||
scope: AccessScope.Organization,
|
scopeOrgId: orgPermission.orgId
|
||||||
scopeOrgId: orgPermission.orgId
|
})),
|
||||||
}),
|
tx
|
||||||
tx
|
|
||||||
)
|
|
||||||
);
|
);
|
||||||
|
|
||||||
await membershipRoleDAL.insertMany(
|
await membershipRoleDAL.insertMany(
|
||||||
|
|||||||
@@ -467,7 +467,7 @@ export const ldapConfigServiceFactory = ({
|
|||||||
|
|
||||||
const [orgMembership] = await orgDAL.findMembership(
|
const [orgMembership] = await orgDAL.findMembership(
|
||||||
{
|
{
|
||||||
[`${TableName.Membership}.actorUserId` as "actorUserId"]: userAlias.userId,
|
[`${TableName.Membership}.actorUserId` as "actorUserId"]: newUserAlias.userId,
|
||||||
[`${TableName.Membership}.scopeOrgId` as "scopeOrgId"]: orgId,
|
[`${TableName.Membership}.scopeOrgId` as "scopeOrgId"]: orgId,
|
||||||
[`${TableName.Membership}.scope` as "scope"]: AccessScope.Organization
|
[`${TableName.Membership}.scope` as "scope"]: AccessScope.Organization
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -229,7 +229,9 @@ export const OrgPermissionSchema = z.discriminatedUnion("subject", [
|
|||||||
}),
|
}),
|
||||||
z.object({
|
z.object({
|
||||||
subject: z.literal(OrgPermissionSubjects.Billing).describe("The entity this permission pertains to."),
|
subject: z.literal(OrgPermissionSubjects.Billing).describe("The entity this permission pertains to."),
|
||||||
action: CASL_ACTION_SCHEMA_NATIVE_ENUM(OrgPermissionActions).describe("Describe what action an entity can take.")
|
action: CASL_ACTION_SCHEMA_NATIVE_ENUM(OrgPermissionBillingActions).describe(
|
||||||
|
"Describe what action an entity can take."
|
||||||
|
)
|
||||||
}),
|
}),
|
||||||
z.object({
|
z.object({
|
||||||
subject: z.literal(OrgPermissionSubjects.Identity).describe("The entity this permission pertains to."),
|
subject: z.literal(OrgPermissionSubjects.Identity).describe("The entity this permission pertains to."),
|
||||||
|
|||||||
+17
-5
@@ -52,10 +52,14 @@ export const newProjectAdditionalPrivilegesFactory = ({
|
|||||||
async (dto) => {
|
async (dto) => {
|
||||||
const scope = getScopeField(dto.scopeData);
|
const scope = getScopeField(dto.scopeData);
|
||||||
|
|
||||||
const { permission } = await $getPermission(dto.permission, scope.value);
|
|
||||||
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member);
|
|
||||||
|
|
||||||
const { actorType } = dto.data;
|
const { actorType } = dto.data;
|
||||||
|
const { permission } = await $getPermission(dto.permission, scope.value);
|
||||||
|
const permissionSet =
|
||||||
|
actorType === ActorType.USER
|
||||||
|
? ([ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member] as const)
|
||||||
|
: ([ProjectPermissionIdentityActions.Edit, ProjectPermissionSub.Identity] as const);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(...permissionSet);
|
||||||
|
|
||||||
const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId);
|
const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId);
|
||||||
const { permission: targetUserPermission, memberships } = await $getPermission(
|
const { permission: targetUserPermission, memberships } = await $getPermission(
|
||||||
{ ...dto.permission, type: actorType, id: dto.data.actorId },
|
{ ...dto.permission, type: actorType, id: dto.data.actorId },
|
||||||
@@ -98,7 +102,11 @@ export const newProjectAdditionalPrivilegesFactory = ({
|
|||||||
const { actorType } = dto.selector;
|
const { actorType } = dto.selector;
|
||||||
|
|
||||||
const { permission } = await $getPermission(dto.permission, scope.value);
|
const { permission } = await $getPermission(dto.permission, scope.value);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member);
|
const permissionSet =
|
||||||
|
actorType === ActorType.USER
|
||||||
|
? ([ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member] as const)
|
||||||
|
: ([ProjectPermissionIdentityActions.Edit, ProjectPermissionSub.Identity] as const);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(...permissionSet);
|
||||||
|
|
||||||
const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId);
|
const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId);
|
||||||
const { permission: targetUserPermission, memberships } = await $getPermission(
|
const { permission: targetUserPermission, memberships } = await $getPermission(
|
||||||
@@ -142,7 +150,11 @@ export const newProjectAdditionalPrivilegesFactory = ({
|
|||||||
const { actorType } = dto.selector;
|
const { actorType } = dto.selector;
|
||||||
|
|
||||||
const { permission } = await $getPermission(dto.permission, scope.value);
|
const { permission } = await $getPermission(dto.permission, scope.value);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member);
|
const permissionSet =
|
||||||
|
actorType === ActorType.USER
|
||||||
|
? ([ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member] as const)
|
||||||
|
: ([ProjectPermissionIdentityActions.Edit, ProjectPermissionSub.Identity] as const);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(...permissionSet);
|
||||||
|
|
||||||
const membership = await membershipDAL.findOne({
|
const membership = await membershipDAL.findOne({
|
||||||
scopeOrgId: dto.permission.orgId,
|
scopeOrgId: dto.permission.orgId,
|
||||||
|
|||||||
Reference in New Issue
Block a user