mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 19:26:38 +00:00
improvements: address change requests
This commit is contained in:
@@ -237,7 +237,7 @@ export const registerDynamicSecretRouter = async (server: FastifyZodProvider) =>
|
|||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const dynamicSecretCfgs = await server.services.dynamicSecret.list({
|
const dynamicSecretCfgs = await server.services.dynamicSecret.listDynamicSecretsByEnv({
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ export const dynamicSecretDALFactory = (db: TDbClient) => {
|
|||||||
const orm = ormify(db, TableName.DynamicSecret);
|
const orm = ormify(db, TableName.DynamicSecret);
|
||||||
|
|
||||||
// find dynamic secrets for multiple environments (folder IDs are cross env, thus need to rank for pagination)
|
// find dynamic secrets for multiple environments (folder IDs are cross env, thus need to rank for pagination)
|
||||||
const findMultiEnv = async (
|
const listDynamicSecretsByFolderIds = async (
|
||||||
{
|
{
|
||||||
folderIds,
|
folderIds,
|
||||||
search,
|
search,
|
||||||
@@ -44,11 +44,7 @@ export const dynamicSecretDALFactory = (db: TDbClient) => {
|
|||||||
.select(
|
.select(
|
||||||
selectAllTableCols(TableName.DynamicSecret),
|
selectAllTableCols(TableName.DynamicSecret),
|
||||||
db.ref("slug").withSchema(TableName.Environment).as("environment"),
|
db.ref("slug").withSchema(TableName.Environment).as("environment"),
|
||||||
db.raw(
|
db.raw(`DENSE_RANK() OVER (ORDER BY ${TableName.DynamicSecret}."name" ${orderDirection}) as rank`)
|
||||||
`DENSE_RANK() OVER (ORDER BY ${TableName.DynamicSecret}."name" ${
|
|
||||||
orderDirection ?? OrderByDirection.ASC
|
|
||||||
}) as rank`
|
|
||||||
)
|
|
||||||
)
|
)
|
||||||
.orderBy(`${TableName.DynamicSecret}.${orderBy}`, orderDirection);
|
.orderBy(`${TableName.DynamicSecret}.${orderBy}`, orderDirection);
|
||||||
|
|
||||||
@@ -70,5 +66,5 @@ export const dynamicSecretDALFactory = (db: TDbClient) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
return { ...orm, findMultiEnv };
|
return { ...orm, listDynamicSecretsByFolderIds };
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import { TLicenseServiceFactory } from "@app/ee/services/license/license-service
|
|||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
||||||
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { OrderByDirection } from "@app/lib/types";
|
import { OrderByDirection } from "@app/lib/types";
|
||||||
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
||||||
import { TSecretFolderDALFactory } from "@app/services/secret-folder/secret-folder-dal";
|
import { TSecretFolderDALFactory } from "@app/services/secret-folder/secret-folder-dal";
|
||||||
@@ -18,7 +18,9 @@ import {
|
|||||||
TCreateDynamicSecretDTO,
|
TCreateDynamicSecretDTO,
|
||||||
TDeleteDynamicSecretDTO,
|
TDeleteDynamicSecretDTO,
|
||||||
TDetailsDynamicSecretDTO,
|
TDetailsDynamicSecretDTO,
|
||||||
|
TGetDynamicSecretsCountDTO,
|
||||||
TListDynamicSecretsDTO,
|
TListDynamicSecretsDTO,
|
||||||
|
TListDynamicSecretsMultiEnvDTO,
|
||||||
TUpdateDynamicSecretDTO
|
TUpdateDynamicSecretDTO
|
||||||
} from "./dynamic-secret-types";
|
} from "./dynamic-secret-types";
|
||||||
import { DynamicSecretProviders, TDynamicProviderFns } from "./providers/models";
|
import { DynamicSecretProviders, TDynamicProviderFns } from "./providers/models";
|
||||||
@@ -307,21 +309,11 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorId,
|
actorId,
|
||||||
actor,
|
actor,
|
||||||
projectSlug,
|
projectId,
|
||||||
path,
|
path,
|
||||||
environmentSlugs,
|
environmentSlugs,
|
||||||
search,
|
search
|
||||||
...params
|
}: TListDynamicSecretsMultiEnvDTO) => {
|
||||||
}: Omit<TListDynamicSecretsDTO, "environmentSlug"> & { environmentSlugs: string[] }) => {
|
|
||||||
let { projectId } = params;
|
|
||||||
|
|
||||||
if (!projectId) {
|
|
||||||
if (!projectSlug) throw new BadRequestError({ message: "Project ID or slug required" });
|
|
||||||
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
|
||||||
if (!project) throw new BadRequestError({ message: "Project not found" });
|
|
||||||
projectId = project.id;
|
|
||||||
}
|
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission(
|
const { permission } = await permissionService.getProjectPermission(
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -350,26 +342,16 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
};
|
};
|
||||||
|
|
||||||
// get dynamic secret count for a single env
|
// get dynamic secret count for a single env
|
||||||
const getCount = async ({
|
const getDynamicSecretCount = async ({
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorId,
|
actorId,
|
||||||
actor,
|
actor,
|
||||||
projectSlug,
|
|
||||||
path,
|
path,
|
||||||
environmentSlug,
|
environmentSlug,
|
||||||
search,
|
search,
|
||||||
...params
|
projectId
|
||||||
}: TListDynamicSecretsDTO) => {
|
}: TGetDynamicSecretsCountDTO) => {
|
||||||
let { projectId } = params;
|
|
||||||
|
|
||||||
if (!projectId) {
|
|
||||||
if (!projectSlug) throw new BadRequestError({ message: "Project ID or slug required" });
|
|
||||||
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
|
||||||
if (!project) throw new BadRequestError({ message: "Project not found" });
|
|
||||||
projectId = project.id;
|
|
||||||
}
|
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission(
|
const { permission } = await permissionService.getProjectPermission(
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -392,7 +374,7 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
return Number(dynamicSecretCfg[0]?.count ?? 0);
|
return Number(dynamicSecretCfg[0]?.count ?? 0);
|
||||||
};
|
};
|
||||||
|
|
||||||
const list = async ({
|
const listDynamicSecretsByEnv = async ({
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -443,25 +425,16 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
};
|
};
|
||||||
|
|
||||||
// get dynamic secrets for multiple envs
|
// get dynamic secrets for multiple envs
|
||||||
const listMultiEnv = async ({
|
const listDynamicSecretsByFolderIds = async ({
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorId,
|
actorId,
|
||||||
actor,
|
actor,
|
||||||
projectSlug,
|
|
||||||
path,
|
path,
|
||||||
environmentSlugs,
|
environmentSlugs,
|
||||||
|
projectId,
|
||||||
...params
|
...params
|
||||||
}: Omit<TListDynamicSecretsDTO, "environmentSlug"> & { environmentSlugs: string[] }) => {
|
}: TListDynamicSecretsMultiEnvDTO) => {
|
||||||
let { projectId } = params;
|
|
||||||
|
|
||||||
if (!projectId) {
|
|
||||||
if (!projectSlug) throw new BadRequestError({ message: "Project ID or slug required" });
|
|
||||||
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
|
||||||
if (!project) throw new NotFoundError({ message: "Project not found" });
|
|
||||||
projectId = project.id;
|
|
||||||
}
|
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission(
|
const { permission } = await permissionService.getProjectPermission(
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -481,7 +454,7 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
const folders = await folderDAL.findBySecretPathMultiEnv(projectId, environmentSlugs, path);
|
const folders = await folderDAL.findBySecretPathMultiEnv(projectId, environmentSlugs, path);
|
||||||
if (!folders.length) throw new BadRequestError({ message: "Folders not found" });
|
if (!folders.length) throw new BadRequestError({ message: "Folders not found" });
|
||||||
|
|
||||||
const dynamicSecretCfg = await dynamicSecretDAL.findMultiEnv({
|
const dynamicSecretCfg = await dynamicSecretDAL.listDynamicSecretsByFolderIds({
|
||||||
folderIds: folders.map((folder) => folder.id),
|
folderIds: folders.map((folder) => folder.id),
|
||||||
...params
|
...params
|
||||||
});
|
});
|
||||||
@@ -494,9 +467,9 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
updateByName,
|
updateByName,
|
||||||
deleteByName,
|
deleteByName,
|
||||||
getDetails,
|
getDetails,
|
||||||
list,
|
listDynamicSecretsByEnv,
|
||||||
listMultiEnv,
|
listDynamicSecretsByFolderIds,
|
||||||
getCount,
|
getDynamicSecretCount,
|
||||||
getCountMultiEnv
|
getCountMultiEnv
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -59,3 +59,12 @@ export type TListDynamicSecretsDTO = {
|
|||||||
orderDirection?: OrderByDirection;
|
orderDirection?: OrderByDirection;
|
||||||
search?: string;
|
search?: string;
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
export type TListDynamicSecretsMultiEnvDTO = Omit<
|
||||||
|
TListDynamicSecretsDTO,
|
||||||
|
"projectId" | "environmentSlug" | "projectSlug"
|
||||||
|
> & { projectId: string; environmentSlugs: string[] };
|
||||||
|
|
||||||
|
export type TGetDynamicSecretsCountDTO = Omit<TListDynamicSecretsDTO, "projectSlug" | "projectId"> & {
|
||||||
|
projectId: string;
|
||||||
|
};
|
||||||
|
|||||||
@@ -126,7 +126,9 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => {
|
|||||||
|
|
||||||
let folders: Awaited<ReturnType<typeof server.services.folder.getFoldersMultiEnv>> | undefined;
|
let folders: Awaited<ReturnType<typeof server.services.folder.getFoldersMultiEnv>> | undefined;
|
||||||
let secrets: Awaited<ReturnType<typeof server.services.secret.getSecretsRawMultiEnv>> | undefined;
|
let secrets: Awaited<ReturnType<typeof server.services.secret.getSecretsRawMultiEnv>> | undefined;
|
||||||
let dynamicSecrets: Awaited<ReturnType<typeof server.services.dynamicSecret.listMultiEnv>> | undefined;
|
let dynamicSecrets:
|
||||||
|
| Awaited<ReturnType<typeof server.services.dynamicSecret.listDynamicSecretsByFolderIds>>
|
||||||
|
| undefined;
|
||||||
|
|
||||||
let totalFolderCount: number | undefined;
|
let totalFolderCount: number | undefined;
|
||||||
let totalDynamicSecretCount: number | undefined;
|
let totalDynamicSecretCount: number | undefined;
|
||||||
@@ -185,7 +187,7 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
if (remainingLimit > 0 && totalDynamicSecretCount > adjustedOffset) {
|
if (remainingLimit > 0 && totalDynamicSecretCount > adjustedOffset) {
|
||||||
dynamicSecrets = await server.services.dynamicSecret.listMultiEnv({
|
dynamicSecrets = await server.services.dynamicSecret.listDynamicSecretsByFolderIds({
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
@@ -408,7 +410,7 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => {
|
|||||||
let imports: Awaited<ReturnType<typeof server.services.secretImport.getImports>> | undefined;
|
let imports: Awaited<ReturnType<typeof server.services.secretImport.getImports>> | undefined;
|
||||||
let folders: Awaited<ReturnType<typeof server.services.folder.getFolders>> | undefined;
|
let folders: Awaited<ReturnType<typeof server.services.folder.getFolders>> | undefined;
|
||||||
let secrets: Awaited<ReturnType<typeof server.services.secret.getSecretsRaw>>["secrets"] | undefined;
|
let secrets: Awaited<ReturnType<typeof server.services.secret.getSecretsRaw>>["secrets"] | undefined;
|
||||||
let dynamicSecrets: Awaited<ReturnType<typeof server.services.dynamicSecret.list>> | undefined;
|
let dynamicSecrets: Awaited<ReturnType<typeof server.services.dynamicSecret.listDynamicSecretsByEnv>> | undefined;
|
||||||
|
|
||||||
let totalImportCount: number | undefined;
|
let totalImportCount: number | undefined;
|
||||||
let totalFolderCount: number | undefined;
|
let totalFolderCount: number | undefined;
|
||||||
@@ -497,7 +499,7 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (includeDynamicSecrets) {
|
if (includeDynamicSecrets) {
|
||||||
totalDynamicSecretCount = await server.services.dynamicSecret.getCount({
|
totalDynamicSecretCount = await server.services.dynamicSecret.getDynamicSecretCount({
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
@@ -509,7 +511,7 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
if (remainingLimit > 0 && totalDynamicSecretCount > adjustedOffset) {
|
if (remainingLimit > 0 && totalDynamicSecretCount > adjustedOffset) {
|
||||||
dynamicSecrets = await server.services.dynamicSecret.list({
|
dynamicSecrets = await server.services.dynamicSecret.listDynamicSecretsByEnv({
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
|
|||||||
Reference in New Issue
Block a user