mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 04:27:29 +00:00
add permission check for target env/path for imports
This commit is contained in:
committed by
Akhil Mohan
parent
627c8711dc
commit
33c3c5ecc5
@@ -48,11 +48,19 @@ export const secretImportServiceFactory = ({
|
|||||||
path
|
path
|
||||||
}: TCreateSecretImportDTO) => {
|
}: TCreateSecretImportDTO) => {
|
||||||
const { permission } = await permissionService.getProjectPermission(actor, actorId, projectId);
|
const { permission } = await permissionService.getProjectPermission(actor, actorId, projectId);
|
||||||
|
|
||||||
|
// check if user has permission to import into destination path
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionActions.Create,
|
ProjectPermissionActions.Create,
|
||||||
subject(ProjectPermissionSub.Secrets, { environment, secretPath: path })
|
subject(ProjectPermissionSub.Secrets, { environment, secretPath: path })
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// check if user has permission to import from target path
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
|
ProjectPermissionActions.Create,
|
||||||
|
subject(ProjectPermissionSub.Secrets, { environment: data.environment, secretPath: data.path })
|
||||||
|
);
|
||||||
|
|
||||||
const folder = await folderDal.findBySecretPath(projectId, environment, path);
|
const folder = await folderDal.findBySecretPath(projectId, environment, path);
|
||||||
if (!folder) throw new BadRequestError({ message: "Folder not found", name: "Create import" });
|
if (!folder) throw new BadRequestError({ message: "Folder not found", name: "Create import" });
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user