mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 16:27:40 +00:00
verify project membership for bypassers
This commit is contained in:
@@ -280,6 +280,8 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (bypasserUserIds.length) {
|
if (bypasserUserIds.length) {
|
||||||
|
await verifyProjectUserMembership(bypasserUserIds, project.orgId, project.id);
|
||||||
|
|
||||||
await accessApprovalPolicyBypasserDAL.insertMany(
|
await accessApprovalPolicyBypasserDAL.insertMany(
|
||||||
bypasserUserIds.map((userId) => ({
|
bypasserUserIds.map((userId) => ({
|
||||||
bypasserUserId: userId,
|
bypasserUserId: userId,
|
||||||
@@ -443,11 +445,6 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
bypasserUserIds = [...new Set(bypasserUserIds.concat(bypasserUsers.map((user) => user.id)))];
|
bypasserUserIds = [...new Set(bypasserUserIds.concat(bypasserUsers.map((user) => user.id)))];
|
||||||
}
|
}
|
||||||
|
|
||||||
// Validate user bypassers
|
|
||||||
if (bypasserUserIds.length > 0) {
|
|
||||||
await verifyProjectUserMembership(bypasserUserIds, actorOrgId, accessApprovalPolicy.projectId);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Validate group bypassers
|
// Validate group bypassers
|
||||||
if (groupBypassers.length > 0) {
|
if (groupBypassers.length > 0) {
|
||||||
const orgGroups = await groupDAL.find({
|
const orgGroups = await groupDAL.find({
|
||||||
@@ -555,6 +552,8 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
await accessApprovalPolicyBypasserDAL.delete({ policyId: doc.id }, tx);
|
await accessApprovalPolicyBypasserDAL.delete({ policyId: doc.id }, tx);
|
||||||
|
|
||||||
if (bypasserUserIds.length) {
|
if (bypasserUserIds.length) {
|
||||||
|
await verifyProjectUserMembership(bypasserUserIds, actorOrgId, accessApprovalPolicy.projectId);
|
||||||
|
|
||||||
await accessApprovalPolicyBypasserDAL.insertMany(
|
await accessApprovalPolicyBypasserDAL.insertMany(
|
||||||
bypasserUserIds.map((userId) => ({
|
bypasserUserIds.map((userId) => ({
|
||||||
bypasserUserId: userId,
|
bypasserUserId: userId,
|
||||||
|
|||||||
@@ -271,6 +271,8 @@ export const secretApprovalPolicyServiceFactory = ({
|
|||||||
);
|
);
|
||||||
|
|
||||||
if (bypasserUserIds.length) {
|
if (bypasserUserIds.length) {
|
||||||
|
await verifyProjectUserMembership(bypasserUserIds, actorOrgId, projectId);
|
||||||
|
|
||||||
await secretApprovalPolicyBypasserDAL.insertMany(
|
await secretApprovalPolicyBypasserDAL.insertMany(
|
||||||
bypasserUserIds.map((userId) => ({
|
bypasserUserIds.map((userId) => ({
|
||||||
bypasserUserId: userId,
|
bypasserUserId: userId,
|
||||||
@@ -481,6 +483,8 @@ export const secretApprovalPolicyServiceFactory = ({
|
|||||||
await secretApprovalPolicyBypasserDAL.delete({ policyId: doc.id }, tx);
|
await secretApprovalPolicyBypasserDAL.delete({ policyId: doc.id }, tx);
|
||||||
|
|
||||||
if (bypasserUserIds.length) {
|
if (bypasserUserIds.length) {
|
||||||
|
await verifyProjectUserMembership(bypasserUserIds, actorOrgId, secretApprovalPolicy.projectId);
|
||||||
|
|
||||||
await secretApprovalPolicyBypasserDAL.insertMany(
|
await secretApprovalPolicyBypasserDAL.insertMany(
|
||||||
bypasserUserIds.map((userId) => ({
|
bypasserUserIds.map((userId) => ({
|
||||||
bypasserUserId: userId,
|
bypasserUserId: userId,
|
||||||
|
|||||||
Reference in New Issue
Block a user