mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-02 18:25:45 +00:00
feat(rbac): put back condition matcher for workspace permission check and added migration function
This commit is contained in:
@@ -3,13 +3,7 @@ import crypto from "crypto";
|
|||||||
import { Types } from "mongoose";
|
import { Types } from "mongoose";
|
||||||
import { encryptSymmetric128BitHexKeyUTF8 } from "../crypto";
|
import { encryptSymmetric128BitHexKeyUTF8 } from "../crypto";
|
||||||
import { EESecretService } from "../../ee/services";
|
import { EESecretService } from "../../ee/services";
|
||||||
import {
|
import { IPType, ISecretVersion, SecretSnapshot, SecretVersion, TrustedIP } from "../../ee/models";
|
||||||
IPType,
|
|
||||||
ISecretVersion,
|
|
||||||
SecretSnapshot,
|
|
||||||
SecretVersion,
|
|
||||||
TrustedIP
|
|
||||||
} from "../../ee/models";
|
|
||||||
import {
|
import {
|
||||||
AuthMethod,
|
AuthMethod,
|
||||||
BackupPrivateKey,
|
BackupPrivateKey,
|
||||||
@@ -18,6 +12,7 @@ import {
|
|||||||
ISecret,
|
ISecret,
|
||||||
Integration,
|
Integration,
|
||||||
IntegrationAuth,
|
IntegrationAuth,
|
||||||
|
Membership,
|
||||||
Organization,
|
Organization,
|
||||||
Secret,
|
Secret,
|
||||||
SecretBlindIndexData,
|
SecretBlindIndexData,
|
||||||
@@ -30,7 +25,9 @@ import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
|
|||||||
import {
|
import {
|
||||||
ALGORITHM_AES_256_GCM,
|
ALGORITHM_AES_256_GCM,
|
||||||
ENCODING_SCHEME_BASE64,
|
ENCODING_SCHEME_BASE64,
|
||||||
ENCODING_SCHEME_UTF8
|
ENCODING_SCHEME_UTF8,
|
||||||
|
MEMBER,
|
||||||
|
VIEWER
|
||||||
} from "../../variables";
|
} from "../../variables";
|
||||||
import { InternalServerError } from "../errors";
|
import { InternalServerError } from "../errors";
|
||||||
|
|
||||||
@@ -582,7 +579,7 @@ export const backfillTrustedIps = async () => {
|
|||||||
filter: {
|
filter: {
|
||||||
workspace: Types.ObjectId;
|
workspace: Types.ObjectId;
|
||||||
ipAddress: string;
|
ipAddress: string;
|
||||||
},
|
};
|
||||||
update: {
|
update: {
|
||||||
workspace: Types.ObjectId;
|
workspace: Types.ObjectId;
|
||||||
ipAddress: string;
|
ipAddress: string;
|
||||||
@@ -590,9 +587,9 @@ export const backfillTrustedIps = async () => {
|
|||||||
prefix: number;
|
prefix: number;
|
||||||
isActive: boolean;
|
isActive: boolean;
|
||||||
comment: string;
|
comment: string;
|
||||||
},
|
};
|
||||||
upsert: boolean;
|
upsert: boolean;
|
||||||
}
|
};
|
||||||
}[] = [];
|
}[] = [];
|
||||||
|
|
||||||
workspaceIdsToAddTrustedIp.forEach((workspaceId) => {
|
workspaceIdsToAddTrustedIp.forEach((workspaceId) => {
|
||||||
@@ -638,7 +635,7 @@ export const backfillTrustedIps = async () => {
|
|||||||
await TrustedIP.bulkWrite(operations);
|
await TrustedIP.bulkWrite(operations);
|
||||||
console.log("Backfill: Trusted IPs complete");
|
console.log("Backfill: Trusted IPs complete");
|
||||||
}
|
}
|
||||||
}
|
};
|
||||||
|
|
||||||
export const backfillUserAuthMethods = async () => {
|
export const backfillUserAuthMethods = async () => {
|
||||||
await User.updateMany(
|
await User.updateMany(
|
||||||
@@ -655,7 +652,6 @@ export const backfillUserAuthMethods = async () => {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|
||||||
const documentsToUpdate = await User.find({
|
const documentsToUpdate = await User.find({
|
||||||
authProvider: { $exists: true },
|
authProvider: { $exists: true },
|
||||||
authMethods: { $exists: false }
|
authMethods: { $exists: false }
|
||||||
@@ -676,4 +672,23 @@ export const backfillUserAuthMethods = async () => {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
};
|
||||||
|
|
||||||
|
export const backfillPermission = async () => {
|
||||||
|
await Membership.updateMany(
|
||||||
|
{
|
||||||
|
deniedPermissions: {
|
||||||
|
$exists: true
|
||||||
|
},
|
||||||
|
role: MEMBER
|
||||||
|
},
|
||||||
|
[
|
||||||
|
{
|
||||||
|
$set: {
|
||||||
|
role: VIEWER
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
);
|
||||||
|
console.log("Backfill: Finishing converting old denied permission in workspace to viewers");
|
||||||
|
};
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import {
|
|||||||
backfillBots,
|
backfillBots,
|
||||||
backfillEncryptionMetadata,
|
backfillEncryptionMetadata,
|
||||||
backfillIntegration,
|
backfillIntegration,
|
||||||
|
backfillPermission,
|
||||||
backfillSecretBlindIndexData,
|
backfillSecretBlindIndexData,
|
||||||
backfillSecretFolders,
|
backfillSecretFolders,
|
||||||
backfillSecretVersions,
|
backfillSecretVersions,
|
||||||
@@ -24,12 +25,7 @@ import {
|
|||||||
reencryptBotPrivateKeys,
|
reencryptBotPrivateKeys,
|
||||||
reencryptSecretBlindIndexDataSalts
|
reencryptSecretBlindIndexDataSalts
|
||||||
} from "./reencryptData";
|
} from "./reencryptData";
|
||||||
import {
|
import { getMongoURL, getNodeEnv, getRedisUrl, getSentryDSN } from "../../config";
|
||||||
getMongoURL,
|
|
||||||
getNodeEnv,
|
|
||||||
getRedisUrl,
|
|
||||||
getSentryDSN
|
|
||||||
} from "../../config";
|
|
||||||
import { initializePassport } from "../auth";
|
import { initializePassport } from "../auth";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -43,8 +39,10 @@ import { initializePassport } from "../auth";
|
|||||||
* - Re-encrypting data
|
* - Re-encrypting data
|
||||||
*/
|
*/
|
||||||
export const setup = async () => {
|
export const setup = async () => {
|
||||||
if (await getRedisUrl() === undefined || await getRedisUrl() === "") {
|
if ((await getRedisUrl()) === undefined || (await getRedisUrl()) === "") {
|
||||||
console.error("WARNING: Redis is not yet configured. Infisical may not function as expected without it.")
|
console.error(
|
||||||
|
"WARNING: Redis is not yet configured. Infisical may not function as expected without it."
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
await validateEncryptionKeysConfig();
|
await validateEncryptionKeysConfig();
|
||||||
@@ -86,6 +84,7 @@ export const setup = async () => {
|
|||||||
await backfillServiceTokenMultiScope();
|
await backfillServiceTokenMultiScope();
|
||||||
await backfillTrustedIps();
|
await backfillTrustedIps();
|
||||||
await backfillUserAuthMethods();
|
await backfillUserAuthMethods();
|
||||||
|
await backfillPermission();
|
||||||
|
|
||||||
// re-encrypt any data previously encrypted under server hex 128-bit ENCRYPTION_KEY
|
// re-encrypt any data previously encrypted under server hex 128-bit ENCRYPTION_KEY
|
||||||
// to base64 256-bit ROOT_ENCRYPTION_KEY
|
// to base64 256-bit ROOT_ENCRYPTION_KEY
|
||||||
|
|||||||
@@ -28,11 +28,6 @@ const glob: JsInterpreter<FieldCondition<string>> = (node, object, context) => {
|
|||||||
const secretPath = context.get(object, node.field);
|
const secretPath = context.get(object, node.field);
|
||||||
const permissionSecretGlobPath = node.value;
|
const permissionSecretGlobPath = node.value;
|
||||||
if (!secretPath) return false;
|
if (!secretPath) return false;
|
||||||
// console.log(
|
|
||||||
// secretPath,
|
|
||||||
// picomatch.isMatch(secretPath, permissionSecretGlobPath, { strictSlashes: false }),
|
|
||||||
// permissionSecretGlobPath
|
|
||||||
// );
|
|
||||||
return picomatch.isMatch(secretPath, permissionSecretGlobPath, { strictSlashes: false });
|
return picomatch.isMatch(secretPath, permissionSecretGlobPath, { strictSlashes: false });
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -102,7 +97,7 @@ export const useGetUserProjectPermissions = ({ workspaceId }: TGetUserProjectPer
|
|||||||
enabled: Boolean(workspaceId),
|
enabled: Boolean(workspaceId),
|
||||||
select: (data) => {
|
select: (data) => {
|
||||||
const rule = unpackRules<RawRuleOf<MongoAbility<ProjectPermissionSet>>>(data);
|
const rule = unpackRules<RawRuleOf<MongoAbility<ProjectPermissionSet>>>(data);
|
||||||
const ability = createMongoAbility<ProjectPermissionSet>(rule);
|
const ability = createMongoAbility<ProjectPermissionSet>(rule, { conditionsMatcher });
|
||||||
return ability;
|
return ability;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -81,7 +81,7 @@ export const SecretOverviewPage = () => {
|
|||||||
const workspaceId = currentWorkspace?._id as string;
|
const workspaceId = currentWorkspace?._id as string;
|
||||||
const { data: latestFileKey } = useGetUserWsKey(workspaceId);
|
const { data: latestFileKey } = useGetUserWsKey(workspaceId);
|
||||||
const [searchFilter, setSearchFilter] = useState("");
|
const [searchFilter, setSearchFilter] = useState("");
|
||||||
const secretPath = router.query?.secretPath as string;
|
const secretPath = (router.query?.secretPath as string) || "/";
|
||||||
const permission = useProjectPermission();
|
const permission = useProjectPermission();
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
|
|||||||
Reference in New Issue
Block a user