mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 22:27:22 +00:00
Merge pull request #1680 from Infisical/daniel/recursive-max-depth
Fix: Hard limit on recursive secret fetching
This commit is contained in:
@@ -221,7 +221,8 @@ export const SECRETS = {
|
|||||||
|
|
||||||
export const RAW_SECRETS = {
|
export const RAW_SECRETS = {
|
||||||
LIST: {
|
LIST: {
|
||||||
recursive: "Whether or not to fetch all secrets from the specified base path, and all of its subdirectories.",
|
recursive:
|
||||||
|
"Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.",
|
||||||
workspaceId: "The ID of the project to list secrets from.",
|
workspaceId: "The ID of the project to list secrets from.",
|
||||||
workspaceSlug: "The slug of the project to list secrets from. This parameter is only usable by machine identities.",
|
workspaceSlug: "The slug of the project to list secrets from. This parameter is only usable by machine identities.",
|
||||||
environment: "The slug of the environment to list secrets from.",
|
environment: "The slug of the environment to list secrets from.",
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ import {
|
|||||||
} from "@app/lib/crypto";
|
} from "@app/lib/crypto";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { groupBy, unique } from "@app/lib/fn";
|
import { groupBy, unique } from "@app/lib/fn";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
|
||||||
import { ActorAuthMethod, ActorType } from "../auth/auth-type";
|
import { ActorAuthMethod, ActorType } from "../auth/auth-type";
|
||||||
import { getBotKeyFnFactory } from "../project-bot/project-bot-fns";
|
import { getBotKeyFnFactory } from "../project-bot/project-bot-fns";
|
||||||
@@ -92,7 +93,8 @@ const buildHierarchy = (folders: TSecretFolders[]): FolderMap => {
|
|||||||
const generatePaths = (
|
const generatePaths = (
|
||||||
map: FolderMap,
|
map: FolderMap,
|
||||||
parentId: string = "null",
|
parentId: string = "null",
|
||||||
basePath: string = ""
|
basePath: string = "",
|
||||||
|
currentDepth: number = 0
|
||||||
): { path: string; folderId: string }[] => {
|
): { path: string; folderId: string }[] => {
|
||||||
const children = map[parentId || "null"] || [];
|
const children = map[parentId || "null"] || [];
|
||||||
let paths: { path: string; folderId: string }[] = [];
|
let paths: { path: string; folderId: string }[] = [];
|
||||||
@@ -105,13 +107,20 @@ const generatePaths = (
|
|||||||
// eslint-disable-next-line no-nested-ternary
|
// eslint-disable-next-line no-nested-ternary
|
||||||
const currPath = basePath === "" ? (isRootFolder ? "/" : `/${child.name}`) : `${basePath}/${child.name}`;
|
const currPath = basePath === "" ? (isRootFolder ? "/" : `/${child.name}`) : `${basePath}/${child.name}`;
|
||||||
|
|
||||||
|
// Add the current path
|
||||||
paths.push({
|
paths.push({
|
||||||
path: currPath,
|
path: currPath,
|
||||||
folderId: child.id
|
folderId: child.id
|
||||||
}); // Add the current path
|
});
|
||||||
|
|
||||||
// Recursively generate paths for children, passing down the formatted pathh
|
// We make sure that the recursion depth doesn't exceed 20.
|
||||||
const childPaths = generatePaths(map, child.id, currPath);
|
// We do this to create "circuit break", basically to ensure that we can't encounter any potential memory leaks.
|
||||||
|
if (currentDepth >= 20) {
|
||||||
|
logger.info(`generatePaths: Recursion depth exceeded 20, breaking out of recursion [map=${JSON.stringify(map)}]`);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
// Recursively generate paths for children, passing down the formatted path
|
||||||
|
const childPaths = generatePaths(map, child.id, currPath, currentDepth + 1);
|
||||||
paths = paths.concat(
|
paths = paths.concat(
|
||||||
childPaths.map((p) => ({
|
childPaths.map((p) => ({
|
||||||
path: p.path,
|
path: p.path,
|
||||||
|
|||||||
Reference in New Issue
Block a user