mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
Merge pull request #1819 from akhilmhdh/feat/hide-secret-scanner
feat: added secret-scanning disable option
This commit is contained in:
@@ -90,15 +90,17 @@ export const secretScanningServiceFactory = ({
|
|||||||
const {
|
const {
|
||||||
data: { repositories }
|
data: { repositories }
|
||||||
} = await octokit.apps.listReposAccessibleToInstallation();
|
} = await octokit.apps.listReposAccessibleToInstallation();
|
||||||
await Promise.all(
|
if (!appCfg.DISABLE_SECRET_SCANNING) {
|
||||||
repositories.map(({ id, full_name }) =>
|
await Promise.all(
|
||||||
secretScanningQueue.startFullRepoScan({
|
repositories.map(({ id, full_name }) =>
|
||||||
organizationId: session.orgId,
|
secretScanningQueue.startFullRepoScan({
|
||||||
installationId,
|
organizationId: session.orgId,
|
||||||
repository: { id, fullName: full_name }
|
installationId,
|
||||||
})
|
repository: { id, fullName: full_name }
|
||||||
)
|
})
|
||||||
);
|
)
|
||||||
|
);
|
||||||
|
}
|
||||||
return { installatedApp };
|
return { installatedApp };
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -151,6 +153,7 @@ export const secretScanningServiceFactory = ({
|
|||||||
};
|
};
|
||||||
|
|
||||||
const handleRepoPushEvent = async (payload: WebhookEventMap["push"]) => {
|
const handleRepoPushEvent = async (payload: WebhookEventMap["push"]) => {
|
||||||
|
const appCfg = getConfig();
|
||||||
const { commits, repository, installation, pusher } = payload;
|
const { commits, repository, installation, pusher } = payload;
|
||||||
if (!commits || !repository || !installation || !pusher) {
|
if (!commits || !repository || !installation || !pusher) {
|
||||||
return;
|
return;
|
||||||
@@ -161,13 +164,15 @@ export const secretScanningServiceFactory = ({
|
|||||||
});
|
});
|
||||||
if (!installationLink) return;
|
if (!installationLink) return;
|
||||||
|
|
||||||
await secretScanningQueue.startPushEventScan({
|
if (!appCfg.DISABLE_SECRET_SCANNING) {
|
||||||
commits,
|
await secretScanningQueue.startPushEventScan({
|
||||||
pusher: { name: pusher.name, email: pusher.email },
|
commits,
|
||||||
repository: { fullName: repository.full_name, id: repository.id },
|
pusher: { name: pusher.name, email: pusher.email },
|
||||||
organizationId: installationLink.orgId,
|
repository: { fullName: repository.full_name, id: repository.id },
|
||||||
installationId: String(installation?.id)
|
organizationId: installationLink.orgId,
|
||||||
});
|
installationId: String(installation?.id)
|
||||||
|
});
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
const handleRepoDeleteEvent = async (installationId: string, repositoryIds: string[]) => {
|
const handleRepoDeleteEvent = async (installationId: string, repositoryIds: string[]) => {
|
||||||
|
|||||||
@@ -13,6 +13,10 @@ const zodStrBool = z
|
|||||||
const envSchema = z
|
const envSchema = z
|
||||||
.object({
|
.object({
|
||||||
PORT: z.coerce.number().default(4000),
|
PORT: z.coerce.number().default(4000),
|
||||||
|
DISABLE_SECRET_SCANNING: z
|
||||||
|
.enum(["true", "false"])
|
||||||
|
.default("false")
|
||||||
|
.transform((el) => el === "true"),
|
||||||
REDIS_URL: zpStr(z.string()),
|
REDIS_URL: zpStr(z.string()),
|
||||||
HOST: zpStr(z.string().default("localhost")),
|
HOST: zpStr(z.string().default("localhost")),
|
||||||
DB_CONNECTION_URI: zpStr(z.string().describe("Postgres database connection string")).default(
|
DB_CONNECTION_URI: zpStr(z.string().describe("Postgres database connection string")).default(
|
||||||
|
|||||||
@@ -20,16 +20,23 @@ export const registerAdminRouter = async (server: FastifyZodProvider) => {
|
|||||||
schema: {
|
schema: {
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
config: SuperAdminSchema.omit({ createdAt: true, updatedAt: true }).merge(
|
config: SuperAdminSchema.omit({ createdAt: true, updatedAt: true }).extend({
|
||||||
z.object({ isMigrationModeOn: z.boolean() })
|
isMigrationModeOn: z.boolean(),
|
||||||
)
|
isSecretScanningDisabled: z.boolean()
|
||||||
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
handler: async () => {
|
handler: async () => {
|
||||||
const config = await getServerCfg();
|
const config = await getServerCfg();
|
||||||
const serverEnvs = getConfig();
|
const serverEnvs = getConfig();
|
||||||
return { config: { ...config, isMigrationModeOn: serverEnvs.MAINTENANCE_MODE } };
|
return {
|
||||||
|
config: {
|
||||||
|
...config,
|
||||||
|
isMigrationModeOn: serverEnvs.MAINTENANCE_MODE,
|
||||||
|
isSecretScanningDisabled: serverEnvs.DISABLE_SECRET_SCANNING
|
||||||
|
}
|
||||||
|
};
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
import { ReactNode } from "react";
|
||||||
|
import { faWarning, IconDefinition } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
icon?: IconDefinition;
|
||||||
|
title: string;
|
||||||
|
children: ReactNode;
|
||||||
|
className?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const NoticeBanner = ({ icon = faWarning, title, children, className }: Props) => (
|
||||||
|
<div
|
||||||
|
className={twMerge(
|
||||||
|
"flex w-full flex-row items-center rounded-md border border-primary-600/70 bg-primary/[.07] p-4 text-base text-white",
|
||||||
|
className
|
||||||
|
)}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={icon} className="pr-6 text-4xl text-white/80" />
|
||||||
|
<div className="flex w-full flex-col text-sm">
|
||||||
|
<div className="mb-2 text-lg font-semibold">{title}</div>
|
||||||
|
<div>{children}</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
export { NoticeBanner } from "./NoticeBanner";
|
||||||
@@ -17,6 +17,7 @@ export * from "./IconButton";
|
|||||||
export * from "./Input";
|
export * from "./Input";
|
||||||
export * from "./Menu";
|
export * from "./Menu";
|
||||||
export * from "./Modal";
|
export * from "./Modal";
|
||||||
|
export * from "./NoticeBanner";
|
||||||
export * from "./Pagination";
|
export * from "./Pagination";
|
||||||
export * from "./Popoverv2";
|
export * from "./Popoverv2";
|
||||||
export * from "./SecretInput";
|
export * from "./SecretInput";
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ export type TServerConfig = {
|
|||||||
isMigrationModeOn?: boolean;
|
isMigrationModeOn?: boolean;
|
||||||
trustSamlEmails: boolean;
|
trustSamlEmails: boolean;
|
||||||
trustLdapEmails: boolean;
|
trustLdapEmails: boolean;
|
||||||
|
isSecretScanningDisabled: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TCreateAdminUserDTO = {
|
export type TCreateAdminUserDTO = {
|
||||||
|
|||||||
@@ -3,8 +3,8 @@ import Head from "next/head";
|
|||||||
import { useRouter } from "next/router";
|
import { useRouter } from "next/router";
|
||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button } from "@app/components/v2";
|
import { Button, NoticeBanner } from "@app/components/v2";
|
||||||
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useServerConfig } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { SecretScanningLogsTable } from "@app/views/SecretScanning/components";
|
import { SecretScanningLogsTable } from "@app/views/SecretScanning/components";
|
||||||
|
|
||||||
@@ -17,6 +17,7 @@ const SecretScanning = withPermission(
|
|||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
const queryParams = router.query;
|
const queryParams = router.query;
|
||||||
const [integrationEnabled, setIntegrationStatus] = useState(false);
|
const [integrationEnabled, setIntegrationStatus] = useState(false);
|
||||||
|
const { config } = useServerConfig();
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
const linkInstallation = async () => {
|
const linkInstallation = async () => {
|
||||||
@@ -69,6 +70,11 @@ const SecretScanning = withPermission(
|
|||||||
<div className="mb-6 text-lg text-mineshaft-300">
|
<div className="mb-6 text-lg text-mineshaft-300">
|
||||||
Automatically monitor your GitHub activity and prevent secret leaks
|
Automatically monitor your GitHub activity and prevent secret leaks
|
||||||
</div>
|
</div>
|
||||||
|
{config.isSecretScanningDisabled && (
|
||||||
|
<NoticeBanner title="Secret scanning is in maintenance" className="mb-4">
|
||||||
|
We are working on improving the performance of secret scanning due to increased usage.
|
||||||
|
</NoticeBanner>
|
||||||
|
)}
|
||||||
<div className="relative mb-6 flex justify-between rounded-md border border-mineshaft-600 bg-mineshaft-800 p-6">
|
<div className="relative mb-6 flex justify-between rounded-md border border-mineshaft-600 bg-mineshaft-800 p-6">
|
||||||
<div className="flex flex-col items-start">
|
<div className="flex flex-col items-start">
|
||||||
<div className="mb-1 flex flex-row">
|
<div className="mb-1 flex flex-row">
|
||||||
@@ -110,7 +116,7 @@ const SecretScanning = withPermission(
|
|||||||
colorSchema="primary"
|
colorSchema="primary"
|
||||||
onClick={generateNewIntegrationSession}
|
onClick={generateNewIntegrationSession}
|
||||||
className="h-min py-2"
|
className="h-min py-2"
|
||||||
isDisabled={!isAllowed}
|
isDisabled={!isAllowed || config.isSecretScanningDisabled}
|
||||||
>
|
>
|
||||||
Integrate with GitHub
|
Integrate with GitHub
|
||||||
</Button>
|
</Button>
|
||||||
|
|||||||
Reference in New Issue
Block a user