mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 21:28:18 +00:00
feat: add slug validator for sub org creation
This commit is contained in:
@@ -6,6 +6,7 @@ import { ApiDocsTags, SUB_ORGANIZATIONS } from "@app/lib/api-docs";
|
|||||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
import { GenericResourceNameSchema } from "@app/server/lib/schemas";
|
||||||
|
|
||||||
const sanitiziedSubOrganizationSchema = OrganizationsSchema.pick({
|
const sanitiziedSubOrganizationSchema = OrganizationsSchema.pick({
|
||||||
id: true,
|
id: true,
|
||||||
@@ -32,7 +33,7 @@ export const registerSubOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
body: z.object({
|
body: z.object({
|
||||||
name: z.string().trim().describe(SUB_ORGANIZATIONS.CREATE.name)
|
name: GenericResourceNameSchema.describe(SUB_ORGANIZATIONS.CREATE.name)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -40,7 +41,7 @@ export const registerSubOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const { organization } = await server.services.subOrganization.createSubOrg({
|
const { organization } = await server.services.subOrganization.createSubOrg({
|
||||||
name: req.body.name,
|
name: req.body.name,
|
||||||
@@ -100,7 +101,7 @@ export const registerSubOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const { organizations } = await server.services.subOrganization.listSubOrgs({
|
const { organizations } = await server.services.subOrganization.listSubOrgs({
|
||||||
permissionActor: {
|
permissionActor: {
|
||||||
|
|||||||
@@ -47,13 +47,21 @@ export const subOrgServiceFactory = ({
|
|||||||
const orgLicensePlan = await licenseService.getPlan(permissionActor.rootOrgId);
|
const orgLicensePlan = await licenseService.getPlan(permissionActor.rootOrgId);
|
||||||
if (!orgLicensePlan.subOrganization) {
|
if (!orgLicensePlan.subOrganization) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Child organization creation failed. Please upgrade your instance to Infisical's Enterprise plan."
|
message: "Sub-organization creation failed. Please upgrade your instance to Infisical's Enterprise plan."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const existingSubOrg = await orgDAL.find({
|
||||||
|
parentOrgId: permissionActor.orgId,
|
||||||
|
name
|
||||||
|
});
|
||||||
|
if (existingSubOrg) {
|
||||||
|
throw new BadRequestError({ message: `Sub-organization with name ${name} already exists` });
|
||||||
|
}
|
||||||
|
|
||||||
const organization = await orgDAL.transaction(async (tx) => {
|
const organization = await orgDAL.transaction(async (tx) => {
|
||||||
const org = await orgDAL.create(
|
const org = await orgDAL.create(
|
||||||
{ name, slug: name, rootOrgId: permissionActor.orgId, parentOrgId: permissionActor.orgId },
|
{ name, slug: name, rootOrgId: permissionActor.rootOrgId, parentOrgId: permissionActor.orgId },
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
const membership = await membershipDAL.create(
|
const membership = await membershipDAL.create(
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import { BadRequestError } from "@app/lib/errors";
|
|||||||
import { ActorType, AuthMethod, AuthMode, AuthModeJwtTokenPayload, AuthTokenType } from "@app/services/auth/auth-type";
|
import { ActorType, AuthMethod, AuthMode, AuthModeJwtTokenPayload, AuthTokenType } from "@app/services/auth/auth-type";
|
||||||
import { TIdentityAccessTokenJwtPayload } from "@app/services/identity-access-token/identity-access-token-types";
|
import { TIdentityAccessTokenJwtPayload } from "@app/services/identity-access-token/identity-access-token-types";
|
||||||
import { getServerCfg } from "@app/services/super-admin/super-admin-service";
|
import { getServerCfg } from "@app/services/super-admin/super-admin-service";
|
||||||
|
import { GenericResourceNameSchema } from "@app/server/lib/schemas";
|
||||||
|
|
||||||
export type TAuthMode =
|
export type TAuthMode =
|
||||||
| {
|
| {
|
||||||
@@ -147,6 +148,9 @@ export const injectIdentity = fp(
|
|||||||
if (!authMode) return;
|
if (!authMode) return;
|
||||||
|
|
||||||
const subOrganizationSelector = req.headers?.["x-infisical-org"] as string | undefined;
|
const subOrganizationSelector = req.headers?.["x-infisical-org"] as string | undefined;
|
||||||
|
if (subOrganizationSelector) {
|
||||||
|
await GenericResourceNameSchema.parseAsync(subOrganizationSelector);
|
||||||
|
}
|
||||||
|
|
||||||
switch (authMode) {
|
switch (authMode) {
|
||||||
case AuthMode.JWT: {
|
case AuthMode.JWT: {
|
||||||
|
|||||||
+1
-2
@@ -26,8 +26,7 @@ export const NewSubOrganizationForm = ({ onClose }: ContentProps) => {
|
|||||||
formState: { isSubmitting }
|
formState: { isSubmitting }
|
||||||
} = useForm({
|
} = useForm({
|
||||||
defaultValues: {
|
defaultValues: {
|
||||||
name: "",
|
name: ""
|
||||||
invitees: []
|
|
||||||
},
|
},
|
||||||
resolver: zodResolver(AddOrgSchema)
|
resolver: zodResolver(AddOrgSchema)
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user