feat(rbac): put back condition matcher for workspace permission check and added migration function

This commit is contained in:
Akhil Mohan
2023-09-08 21:22:36 +05:30
parent c91a93ef2a
commit 38c044f9a7
4 changed files with 38 additions and 29 deletions
+29 -14
View File
@@ -3,13 +3,7 @@ import crypto from "crypto";
import { Types } from "mongoose"; import { Types } from "mongoose";
import { encryptSymmetric128BitHexKeyUTF8 } from "../crypto"; import { encryptSymmetric128BitHexKeyUTF8 } from "../crypto";
import { EESecretService } from "../../ee/services"; import { EESecretService } from "../../ee/services";
import { import { IPType, ISecretVersion, SecretSnapshot, SecretVersion, TrustedIP } from "../../ee/models";
IPType,
ISecretVersion,
SecretSnapshot,
SecretVersion,
TrustedIP
} from "../../ee/models";
import { import {
AuthMethod, AuthMethod,
BackupPrivateKey, BackupPrivateKey,
@@ -18,6 +12,7 @@ import {
ISecret, ISecret,
Integration, Integration,
IntegrationAuth, IntegrationAuth,
Membership,
Organization, Organization,
Secret, Secret,
SecretBlindIndexData, SecretBlindIndexData,
@@ -30,7 +25,9 @@ import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
import { import {
ALGORITHM_AES_256_GCM, ALGORITHM_AES_256_GCM,
ENCODING_SCHEME_BASE64, ENCODING_SCHEME_BASE64,
ENCODING_SCHEME_UTF8 ENCODING_SCHEME_UTF8,
MEMBER,
VIEWER
} from "../../variables"; } from "../../variables";
import { InternalServerError } from "../errors"; import { InternalServerError } from "../errors";
@@ -582,7 +579,7 @@ export const backfillTrustedIps = async () => {
filter: { filter: {
workspace: Types.ObjectId; workspace: Types.ObjectId;
ipAddress: string; ipAddress: string;
}, };
update: { update: {
workspace: Types.ObjectId; workspace: Types.ObjectId;
ipAddress: string; ipAddress: string;
@@ -590,9 +587,9 @@ export const backfillTrustedIps = async () => {
prefix: number; prefix: number;
isActive: boolean; isActive: boolean;
comment: string; comment: string;
}, };
upsert: boolean; upsert: boolean;
} };
}[] = []; }[] = [];
workspaceIdsToAddTrustedIp.forEach((workspaceId) => { workspaceIdsToAddTrustedIp.forEach((workspaceId) => {
@@ -638,7 +635,7 @@ export const backfillTrustedIps = async () => {
await TrustedIP.bulkWrite(operations); await TrustedIP.bulkWrite(operations);
console.log("Backfill: Trusted IPs complete"); console.log("Backfill: Trusted IPs complete");
} }
} };
export const backfillUserAuthMethods = async () => { export const backfillUserAuthMethods = async () => {
await User.updateMany( await User.updateMany(
@@ -655,7 +652,6 @@ export const backfillUserAuthMethods = async () => {
} }
); );
const documentsToUpdate = await User.find({ const documentsToUpdate = await User.find({
authProvider: { $exists: true }, authProvider: { $exists: true },
authMethods: { $exists: false } authMethods: { $exists: false }
@@ -676,4 +672,23 @@ export const backfillUserAuthMethods = async () => {
} }
); );
} }
} };
export const backfillPermission = async () => {
await Membership.updateMany(
{
deniedPermissions: {
$exists: true
},
role: MEMBER
},
[
{
$set: {
role: VIEWER
}
}
]
);
console.log("Backfill: Finishing converting old denied permission in workspace to viewers");
};
+7 -8
View File
@@ -11,6 +11,7 @@ import {
backfillBots, backfillBots,
backfillEncryptionMetadata, backfillEncryptionMetadata,
backfillIntegration, backfillIntegration,
backfillPermission,
backfillSecretBlindIndexData, backfillSecretBlindIndexData,
backfillSecretFolders, backfillSecretFolders,
backfillSecretVersions, backfillSecretVersions,
@@ -24,12 +25,7 @@ import {
reencryptBotPrivateKeys, reencryptBotPrivateKeys,
reencryptSecretBlindIndexDataSalts reencryptSecretBlindIndexDataSalts
} from "./reencryptData"; } from "./reencryptData";
import { import { getMongoURL, getNodeEnv, getRedisUrl, getSentryDSN } from "../../config";
getMongoURL,
getNodeEnv,
getRedisUrl,
getSentryDSN
} from "../../config";
import { initializePassport } from "../auth"; import { initializePassport } from "../auth";
/** /**
@@ -43,8 +39,10 @@ import { initializePassport } from "../auth";
* - Re-encrypting data * - Re-encrypting data
*/ */
export const setup = async () => { export const setup = async () => {
if (await getRedisUrl() === undefined || await getRedisUrl() === "") { if ((await getRedisUrl()) === undefined || (await getRedisUrl()) === "") {
console.error("WARNING: Redis is not yet configured. Infisical may not function as expected without it.") console.error(
"WARNING: Redis is not yet configured. Infisical may not function as expected without it."
);
} }
await validateEncryptionKeysConfig(); await validateEncryptionKeysConfig();
@@ -86,6 +84,7 @@ export const setup = async () => {
await backfillServiceTokenMultiScope(); await backfillServiceTokenMultiScope();
await backfillTrustedIps(); await backfillTrustedIps();
await backfillUserAuthMethods(); await backfillUserAuthMethods();
await backfillPermission();
// re-encrypt any data previously encrypted under server hex 128-bit ENCRYPTION_KEY // re-encrypt any data previously encrypted under server hex 128-bit ENCRYPTION_KEY
// to base64 256-bit ROOT_ENCRYPTION_KEY // to base64 256-bit ROOT_ENCRYPTION_KEY
+1 -6
View File
@@ -28,11 +28,6 @@ const glob: JsInterpreter<FieldCondition<string>> = (node, object, context) => {
const secretPath = context.get(object, node.field); const secretPath = context.get(object, node.field);
const permissionSecretGlobPath = node.value; const permissionSecretGlobPath = node.value;
if (!secretPath) return false; if (!secretPath) return false;
// console.log(
// secretPath,
// picomatch.isMatch(secretPath, permissionSecretGlobPath, { strictSlashes: false }),
// permissionSecretGlobPath
// );
return picomatch.isMatch(secretPath, permissionSecretGlobPath, { strictSlashes: false }); return picomatch.isMatch(secretPath, permissionSecretGlobPath, { strictSlashes: false });
}; };
@@ -102,7 +97,7 @@ export const useGetUserProjectPermissions = ({ workspaceId }: TGetUserProjectPer
enabled: Boolean(workspaceId), enabled: Boolean(workspaceId),
select: (data) => { select: (data) => {
const rule = unpackRules<RawRuleOf<MongoAbility<ProjectPermissionSet>>>(data); const rule = unpackRules<RawRuleOf<MongoAbility<ProjectPermissionSet>>>(data);
const ability = createMongoAbility<ProjectPermissionSet>(rule); const ability = createMongoAbility<ProjectPermissionSet>(rule, { conditionsMatcher });
return ability; return ability;
} }
}); });
@@ -81,7 +81,7 @@ export const SecretOverviewPage = () => {
const workspaceId = currentWorkspace?._id as string; const workspaceId = currentWorkspace?._id as string;
const { data: latestFileKey } = useGetUserWsKey(workspaceId); const { data: latestFileKey } = useGetUserWsKey(workspaceId);
const [searchFilter, setSearchFilter] = useState(""); const [searchFilter, setSearchFilter] = useState("");
const secretPath = router.query?.secretPath as string; const secretPath = (router.query?.secretPath as string) || "/";
const permission = useProjectPermission(); const permission = useProjectPermission();
useEffect(() => { useEffect(() => {