mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
Fix race condition on identity/group membership check
This commit is contained in:
@@ -93,15 +93,6 @@ export const membershipGroupServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const scopeDatabaseFields = factory.getScopeDatabaseFields(dto.scopeData);
|
const scopeDatabaseFields = factory.getScopeDatabaseFields(dto.scopeData);
|
||||||
const existingMembership = await membershipGroupDAL.findOne({
|
|
||||||
scope: scopeData.scope,
|
|
||||||
...scopeDatabaseFields,
|
|
||||||
actorGroupId: dto.data.groupId
|
|
||||||
});
|
|
||||||
if (existingMembership)
|
|
||||||
throw new BadRequestError({
|
|
||||||
message: "Group is already a member"
|
|
||||||
});
|
|
||||||
|
|
||||||
await factory.onCreateMembershipGroupGuard(dto);
|
await factory.onCreateMembershipGroupGuard(dto);
|
||||||
|
|
||||||
@@ -122,6 +113,19 @@ export const membershipGroupServiceFactory = ({
|
|||||||
const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug);
|
const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug);
|
||||||
|
|
||||||
const membership = await membershipGroupDAL.transaction(async (tx) => {
|
const membership = await membershipGroupDAL.transaction(async (tx) => {
|
||||||
|
const existingMembership = await membershipGroupDAL.findOne(
|
||||||
|
{
|
||||||
|
scope: scopeData.scope,
|
||||||
|
...scopeDatabaseFields,
|
||||||
|
actorGroupId: dto.data.groupId
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
if (existingMembership)
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Group is already a member"
|
||||||
|
});
|
||||||
|
|
||||||
const doc = await membershipGroupDAL.create(
|
const doc = await membershipGroupDAL.create(
|
||||||
{
|
{
|
||||||
scope: scopeData.scope,
|
scope: scopeData.scope,
|
||||||
|
|||||||
@@ -102,19 +102,22 @@ export const membershipIdentityServiceFactory = ({
|
|||||||
throw new NotFoundError({ message: "One or more custom roles not found" });
|
throw new NotFoundError({ message: "One or more custom roles not found" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const existingMembership = await membershipIdentityDAL.findOne({
|
const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug);
|
||||||
|
|
||||||
|
const membership = await membershipIdentityDAL.transaction(async (tx) => {
|
||||||
|
const existingMembership = await membershipIdentityDAL.findOne(
|
||||||
|
{
|
||||||
scope: scopeData.scope,
|
scope: scopeData.scope,
|
||||||
...scopeDatabaseFields,
|
...scopeDatabaseFields,
|
||||||
actorIdentityId: dto.data.identityId
|
actorIdentityId: dto.data.identityId
|
||||||
});
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
if (existingMembership)
|
if (existingMembership)
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Identity is already a member"
|
message: "Identity is already a member"
|
||||||
});
|
});
|
||||||
|
|
||||||
const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug);
|
|
||||||
|
|
||||||
const membership = await membershipIdentityDAL.transaction(async (tx) => {
|
|
||||||
const doc = await membershipIdentityDAL.create(
|
const doc = await membershipIdentityDAL.create(
|
||||||
{
|
{
|
||||||
scope: scopeData.scope,
|
scope: scopeData.scope,
|
||||||
|
|||||||
Reference in New Issue
Block a user