diff --git a/backend/src/server/routes/v3/secret-router.ts b/backend/src/server/routes/v3/secret-router.ts index 70b20f79d..564ff262f 100644 --- a/backend/src/server/routes/v3/secret-router.ts +++ b/backend/src/server/routes/v3/secret-router.ts @@ -560,24 +560,14 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => { onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]), handler: async (req) => { let { workspaceId } = req.body; - if (req.permission.type === ActorType.IDENTITY && req.body.projectSlug && !workspaceId) { - const workspace = await server.services.project.getAProject({ - filter: { - type: ProjectFilterType.SLUG, - orgId: req.permission.orgId, - slug: req.body.projectSlug - }, - actorId: req.permission.id, - actorAuthMethod: req.permission.authMethod, - actor: req.permission.type, - actorOrgId: req.permission.orgId - }); - - if (!workspace) throw new NotFoundError({ message: `No project found with slug ${req.body.projectSlug}` }); - - workspaceId = workspace.id; - } - if (!workspaceId) throw new BadRequestError({ message: "You must provide workspaceId or projectSlug" }); + workspaceId = await server.services.project.extractProjectIdFromSlug({ + projectSlug: req.body.projectSlug, + projectId: req.body.workspaceId, + actorId: req.permission.id, + actorAuthMethod: req.permission.authMethod, + actor: req.permission.type, + actorOrgId: req.permission.orgId + }); const secretOperation = await server.services.secret.createSecretRaw({ actorId: req.permission.id, @@ -702,24 +692,14 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => { onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]), handler: async (req) => { let { workspaceId } = req.body; - if (req.permission.type === ActorType.IDENTITY && req.body.projectSlug && !workspaceId) { - const workspace = await server.services.project.getAProject({ - filter: { - type: ProjectFilterType.SLUG, - orgId: req.permission.orgId, - slug: req.body.projectSlug - }, - actorId: req.permission.id, - actorAuthMethod: req.permission.authMethod, - actor: req.permission.type, - actorOrgId: req.permission.orgId - }); - - if (!workspace) throw new NotFoundError({ message: `No project found with slug ${req.body.projectSlug}` }); - - workspaceId = workspace.id; - } - if (!workspaceId) throw new BadRequestError({ message: "You must provide workspaceId or projectSlug" }); + workspaceId = await server.services.project.extractProjectIdFromSlug({ + projectSlug: req.body.projectSlug, + projectId: req.body.workspaceId, + actorId: req.permission.id, + actorAuthMethod: req.permission.authMethod, + actor: req.permission.type, + actorOrgId: req.permission.orgId + }); const secretOperation = await server.services.secret.updateSecretRaw({ actorId: req.permission.id, @@ -824,24 +804,14 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => { onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]), handler: async (req) => { let { workspaceId } = req.body; - if (req.permission.type === ActorType.IDENTITY && req.body.projectSlug && !workspaceId) { - const workspace = await server.services.project.getAProject({ - filter: { - type: ProjectFilterType.SLUG, - orgId: req.permission.orgId, - slug: req.body.projectSlug - }, - actorId: req.permission.id, - actorAuthMethod: req.permission.authMethod, - actor: req.permission.type, - actorOrgId: req.permission.orgId - }); - - if (!workspace) throw new NotFoundError({ message: `No project found with slug ${req.body.projectSlug}` }); - - workspaceId = workspace.id; - } - if (!workspaceId) throw new BadRequestError({ message: "You must provide workspaceId or projectSlug" }); + workspaceId = await server.services.project.extractProjectIdFromSlug({ + projectSlug: req.body.projectSlug, + projectId: req.body.workspaceId, + actorId: req.permission.id, + actorAuthMethod: req.permission.authMethod, + actor: req.permission.type, + actorOrgId: req.permission.orgId + }); const secretOperation = await server.services.secret.deleteSecretRaw({ actorId: req.permission.id, diff --git a/backend/src/services/project/project-service.ts b/backend/src/services/project/project-service.ts index 4650c474d..29774fcc8 100644 --- a/backend/src/services/project/project-service.ts +++ b/backend/src/services/project/project-service.ts @@ -42,7 +42,7 @@ import { TProjectPermission } from "@app/lib/types"; import { TQueueServiceFactory } from "@app/queue"; import { TPkiSubscriberDALFactory } from "@app/services/pki-subscriber/pki-subscriber-dal"; -import { ActorType } from "../auth/auth-type"; +import { ActorAuthMethod, ActorType } from "../auth/auth-type"; import { TCertificateDALFactory } from "../certificate/certificate-dal"; import { TCertificateAuthorityDALFactory } from "../certificate-authority/certificate-authority-dal"; import { expandInternalCa } from "../certificate-authority/certificate-authority-fns"; @@ -82,6 +82,7 @@ import { assignWorkspaceKeysToMembers, bootstrapSshProject, createProjectKey } f import { TProjectQueueFactory } from "./project-queue"; import { TProjectSshConfigDALFactory } from "./project-ssh-config-dal"; import { + ProjectFilterType, TCreateProjectDTO, TDeleteProjectDTO, TDeleteProjectWorkflowIntegration, @@ -866,6 +867,39 @@ export const projectServiceFactory = ({ }); }; + const extractProjectIdFromSlug = async ({ + projectSlug, + projectId, + actorId, + actorAuthMethod, + actor, + actorOrgId + }: { + projectSlug?: string; + projectId?: string; + actorId: string; + actorAuthMethod: ActorAuthMethod; + actor: ActorType; + actorOrgId: string; + }) => { + if (projectId) return projectId; + if (!projectSlug) throw new BadRequestError({ message: "You must provide projectSlug or workspaceId" }); + const project = await getAProject({ + filter: { + type: ProjectFilterType.SLUG, + orgId: actorOrgId, + slug: projectSlug + }, + actorId, + actorAuthMethod, + actor, + actorOrgId + }); + + if (!project) throw new NotFoundError({ message: `No project found with slug ${projectSlug}` }); + return project.id; + }; + const getProjectUpgradeStatus = async ({ projectId, actor, @@ -2006,6 +2040,7 @@ export const projectServiceFactory = ({ getProjectSshConfig, updateProjectSshConfig, requestProjectAccess, - searchProjects + searchProjects, + extractProjectIdFromSlug }; };