mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 06:28:11 +00:00
feat(rbac): changed the action names for org
This commit is contained in:
@@ -19,7 +19,7 @@ import {
|
|||||||
import { validateUserEmail } from "../../validation";
|
import { validateUserEmail } from "../../validation";
|
||||||
import { validateRequest } from "../../helpers/validation";
|
import { validateRequest } from "../../helpers/validation";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../services/RoleService";
|
} from "../../services/RoleService";
|
||||||
@@ -50,7 +50,7 @@ export const deleteMembershipOrg = async (req: Request, _res: Response) => {
|
|||||||
membershipOrgToDelete.organization.toString()
|
membershipOrgToDelete.organization.toString()
|
||||||
);
|
);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Delete,
|
OrgPermissionActions.Delete,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -98,7 +98,7 @@ export const inviteUserToOrganization = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -14,9 +14,8 @@ import { licenseServerKeyRequest } from "../../config/request";
|
|||||||
import { validateRequest } from "../../helpers/validation";
|
import { validateRequest } from "../../helpers/validation";
|
||||||
import * as reqValidator from "../../validation/organization";
|
import * as reqValidator from "../../validation/organization";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
WorkspacePermissionActions,
|
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../services/RoleService";
|
} from "../../services/RoleService";
|
||||||
import { OrganizationNotFoundError } from "../../utils/errors";
|
import { OrganizationNotFoundError } from "../../utils/errors";
|
||||||
@@ -104,7 +103,7 @@ export const getOrganizationMembers = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -130,7 +129,7 @@ export const getOrganizationWorkspaces = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
WorkspacePermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Workspace
|
OrgPermissionSubjects.Workspace
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -172,7 +171,7 @@ export const changeOrganizationName = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.Settings
|
OrgPermissionSubjects.Settings
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -207,7 +206,7 @@ export const getOrganizationIncidentContacts = async (req: Request, res: Respons
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.IncidentAccount
|
OrgPermissionSubjects.IncidentAccount
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -234,7 +233,7 @@ export const addOrganizationIncidentContact = async (req: Request, res: Response
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.IncidentAccount
|
OrgPermissionSubjects.IncidentAccount
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -263,7 +262,7 @@ export const deleteOrganizationIncidentContact = async (req: Request, res: Respo
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Delete,
|
OrgPermissionActions.Delete,
|
||||||
OrgPermissionSubjects.IncidentAccount
|
OrgPermissionSubjects.IncidentAccount
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -292,7 +291,7 @@ export const createOrganizationPortalSession = async (req: Request, res: Respons
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -356,11 +355,11 @@ export const getOrganizationMembersAndTheirWorkspaces = async (req: Request, res
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
WorkspacePermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Workspace
|
OrgPermissionSubjects.Workspace
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ import { Request, Response } from "express";
|
|||||||
import { BadRequestError } from "../../utils/errors";
|
import { BadRequestError } from "../../utils/errors";
|
||||||
import Role from "../../models/role";
|
import Role from "../../models/role";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
adminPermissions,
|
adminPermissions,
|
||||||
getUserOrgPermissions,
|
getUserOrgPermissions,
|
||||||
@@ -30,7 +30,7 @@ export const createRole = async (req: Request, res: Response) => {
|
|||||||
} = await validateRequest(CreateRoleSchema, req);
|
} = await validateRequest(CreateRoleSchema, req);
|
||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user.id, orgId);
|
const { permission } = await getUserOrgPermissions(req.user.id, orgId);
|
||||||
if (permission.cannot(GeneralPermissionActions.Create, OrgPermissionSubjects.Role)) {
|
if (permission.cannot(OrgPermissionActions.Create, OrgPermissionSubjects.Role)) {
|
||||||
throw BadRequestError({ message: "User doesn't have the permission." });
|
throw BadRequestError({ message: "User doesn't have the permission." });
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -68,7 +68,7 @@ export const updateRole = async (req: Request, res: Response) => {
|
|||||||
const isOrgRole = !workspaceId; // if workspaceid is provided then its a workspace rule
|
const isOrgRole = !workspaceId; // if workspaceid is provided then its a workspace rule
|
||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user.id, orgId);
|
const { permission } = await getUserOrgPermissions(req.user.id, orgId);
|
||||||
if (permission.cannot(GeneralPermissionActions.Edit, OrgPermissionSubjects.Role)) {
|
if (permission.cannot(OrgPermissionActions.Edit, OrgPermissionSubjects.Role)) {
|
||||||
throw BadRequestError({ message: "User doesn't have the permission." });
|
throw BadRequestError({ message: "User doesn't have the permission." });
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -112,7 +112,7 @@ export const deleteRole = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user.id, role.organization.toString());
|
const { permission } = await getUserOrgPermissions(req.user.id, role.organization.toString());
|
||||||
if (permission.cannot(GeneralPermissionActions.Delete, OrgPermissionSubjects.Role)) {
|
if (permission.cannot(OrgPermissionActions.Delete, OrgPermissionSubjects.Role)) {
|
||||||
throw BadRequestError({ message: "User doesn't have the permission." });
|
throw BadRequestError({ message: "User doesn't have the permission." });
|
||||||
}
|
}
|
||||||
await Role.findByIdAndDelete(role.id);
|
await Role.findByIdAndDelete(role.id);
|
||||||
@@ -132,7 +132,7 @@ export const getRoles = async (req: Request, res: Response) => {
|
|||||||
const isOrgRole = !workspaceId;
|
const isOrgRole = !workspaceId;
|
||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user.id, orgId);
|
const { permission } = await getUserOrgPermissions(req.user.id, orgId);
|
||||||
if (permission.cannot(GeneralPermissionActions.Read, OrgPermissionSubjects.Role)) {
|
if (permission.cannot(OrgPermissionActions.Read, OrgPermissionSubjects.Role)) {
|
||||||
throw BadRequestError({ message: "User doesn't have the permission." });
|
throw BadRequestError({ message: "User doesn't have the permission." });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ import { Organization } from "../../models";
|
|||||||
import { validateRequest } from "../../helpers/validation";
|
import { validateRequest } from "../../helpers/validation";
|
||||||
import * as reqValidator from "../../validation/secretScanning";
|
import * as reqValidator from "../../validation/secretScanning";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../services/RoleService";
|
} from "../../services/RoleService";
|
||||||
@@ -33,7 +33,7 @@ export const createInstallationSession = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.SecretScanning
|
OrgPermissionSubjects.SecretScanning
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -69,7 +69,7 @@ export const linkInstallationToOrganization = async (req: Request, res: Response
|
|||||||
installationSession.organization.toString()
|
installationSession.organization.toString()
|
||||||
);
|
);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.SecretScanning
|
OrgPermissionSubjects.SecretScanning
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -131,7 +131,7 @@ export const getRisksForOrganization = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.SecretScanning
|
OrgPermissionSubjects.SecretScanning
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -151,7 +151,7 @@ export const updateRisksStatus = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.SecretScanning
|
OrgPermissionSubjects.SecretScanning
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -15,8 +15,8 @@ import { addMemberships } from "../../helpers/membership";
|
|||||||
import { ADMIN } from "../../variables";
|
import { ADMIN } from "../../variables";
|
||||||
import { OrganizationNotFoundError } from "../../utils/errors";
|
import { OrganizationNotFoundError } from "../../utils/errors";
|
||||||
import {
|
import {
|
||||||
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
WorkspacePermissionActions,
|
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../services/RoleService";
|
} from "../../services/RoleService";
|
||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
@@ -146,7 +146,7 @@ export const createWorkspace = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
WorkspacePermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.Workspace
|
OrgPermissionSubjects.Workspace
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -9,9 +9,8 @@ import { CUSTOM } from "../../variables";
|
|||||||
import * as reqValidator from "../../validation/organization";
|
import * as reqValidator from "../../validation/organization";
|
||||||
import { validateRequest } from "../../helpers/validation";
|
import { validateRequest } from "../../helpers/validation";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
WorkspacePermissionActions,
|
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../services/RoleService";
|
} from "../../services/RoleService";
|
||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
@@ -61,7 +60,7 @@ export const getOrganizationMemberships = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -139,7 +138,7 @@ export const updateOrganizationMembership = async (req: Request, res: Response)
|
|||||||
} = await validateRequest(reqValidator.UpdateOrgMemberv2, req);
|
} = await validateRequest(reqValidator.UpdateOrgMemberv2, req);
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -220,7 +219,7 @@ export const deleteOrganizationMembership = async (req: Request, res: Response)
|
|||||||
} = await validateRequest(reqValidator.DeleteOrgMemberv2, req);
|
} = await validateRequest(reqValidator.DeleteOrgMemberv2, req);
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Delete,
|
OrgPermissionActions.Delete,
|
||||||
OrgPermissionSubjects.Member
|
OrgPermissionSubjects.Member
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -284,7 +283,7 @@ export const getOrganizationWorkspaces = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
WorkspacePermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Workspace
|
OrgPermissionSubjects.Workspace
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ import { EELicenseService } from "../../services";
|
|||||||
import { validateRequest } from "../../../helpers/validation";
|
import { validateRequest } from "../../../helpers/validation";
|
||||||
import * as reqValidator from "../../../validation/organization";
|
import * as reqValidator from "../../../validation/organization";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../../services/RoleService";
|
} from "../../../services/RoleService";
|
||||||
@@ -22,7 +22,7 @@ export const getOrganizationPlansTable = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -44,7 +44,7 @@ export const getOrganizationPlan = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -72,11 +72,11 @@ export const startOrganizationTrial = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -118,7 +118,7 @@ export const getOrganizationPlanBillingInfo = async (req: Request, res: Response
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -151,7 +151,7 @@ export const getOrganizationPlanTable = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -178,7 +178,7 @@ export const getOrganizationBillingDetails = async (req: Request, res: Response)
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -206,7 +206,7 @@ export const updateOrganizationBillingDetails = async (req: Request, res: Respon
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -240,7 +240,7 @@ export const getOrganizationPmtMethods = async (req: Request, res: Response) =>
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -273,7 +273,7 @@ export const addOrganizationPmtMethod = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -314,7 +314,7 @@ export const deleteOrganizationPmtMethod = async (req: Request, res: Response) =
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Delete,
|
OrgPermissionActions.Delete,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -344,7 +344,7 @@ export const getOrganizationTaxIds = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -377,7 +377,7 @@ export const addOrganizationTaxId = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -414,7 +414,7 @@ export const deleteOrganizationTaxId = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Delete,
|
OrgPermissionActions.Delete,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -447,7 +447,7 @@ export const getOrganizationInvoices = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -482,7 +482,7 @@ export const getOrganizationLicenses = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Billing
|
OrgPermissionSubjects.Billing
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ import { EELicenseService } from "../../services";
|
|||||||
import * as reqValidator from "../../../validation/sso";
|
import * as reqValidator from "../../../validation/sso";
|
||||||
import { validateRequest } from "../../../helpers/validation";
|
import { validateRequest } from "../../../helpers/validation";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
getUserOrgPermissions
|
getUserOrgPermissions
|
||||||
} from "../../../services/RoleService";
|
} from "../../../services/RoleService";
|
||||||
@@ -49,7 +49,7 @@ export const getSSOConfig = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Read,
|
OrgPermissionActions.Read,
|
||||||
OrgPermissionSubjects.Sso
|
OrgPermissionSubjects.Sso
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -73,7 +73,7 @@ export const updateSSOConfig = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Edit,
|
OrgPermissionActions.Edit,
|
||||||
OrgPermissionSubjects.Sso
|
OrgPermissionSubjects.Sso
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -208,7 +208,7 @@ export const createSSOConfig = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
GeneralPermissionActions.Create,
|
OrgPermissionActions.Create,
|
||||||
OrgPermissionSubjects.Sso
|
OrgPermissionSubjects.Sso
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -4,18 +4,13 @@ import { IRole } from "../models/role";
|
|||||||
import { BadRequestError, UnauthorizedRequestError } from "../utils/errors";
|
import { BadRequestError, UnauthorizedRequestError } from "../utils/errors";
|
||||||
import { ACCEPTED } from "../variables";
|
import { ACCEPTED } from "../variables";
|
||||||
|
|
||||||
export enum GeneralPermissionActions {
|
export enum OrgPermissionActions {
|
||||||
Read = "read",
|
Read = "read",
|
||||||
Create = "create",
|
Create = "create",
|
||||||
Edit = "edit",
|
Edit = "edit",
|
||||||
Delete = "delete"
|
Delete = "delete"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum WorkspacePermissionActions {
|
|
||||||
Read = "read",
|
|
||||||
Create = "create"
|
|
||||||
}
|
|
||||||
|
|
||||||
export enum OrgPermissionSubjects {
|
export enum OrgPermissionSubjects {
|
||||||
Workspace = "workspace",
|
Workspace = "workspace",
|
||||||
Role = "role",
|
Role = "role",
|
||||||
@@ -28,55 +23,56 @@ export enum OrgPermissionSubjects {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export type OrgPermissionSet =
|
export type OrgPermissionSet =
|
||||||
| [WorkspacePermissionActions, OrgPermissionSubjects.Workspace]
|
| [OrgPermissionActions.Read, OrgPermissionSubjects.Workspace]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Role]
|
| [OrgPermissionActions.Create, OrgPermissionSubjects.Workspace]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Member]
|
| [OrgPermissionActions, OrgPermissionSubjects.Role]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Settings]
|
| [OrgPermissionActions, OrgPermissionSubjects.Member]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.IncidentAccount]
|
| [OrgPermissionActions, OrgPermissionSubjects.Settings]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Sso]
|
| [OrgPermissionActions, OrgPermissionSubjects.IncidentAccount]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.SecretScanning]
|
| [OrgPermissionActions, OrgPermissionSubjects.Sso]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Billing];
|
| [OrgPermissionActions, OrgPermissionSubjects.SecretScanning]
|
||||||
|
| [OrgPermissionActions, OrgPermissionSubjects.Billing];
|
||||||
|
|
||||||
const buildAdminPermission = () => {
|
const buildAdminPermission = () => {
|
||||||
const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility);
|
const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility);
|
||||||
// ws permissions
|
// ws permissions
|
||||||
can(WorkspacePermissionActions.Read, OrgPermissionSubjects.Workspace);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Workspace);
|
||||||
can(WorkspacePermissionActions.Create, OrgPermissionSubjects.Workspace);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Workspace);
|
||||||
// role permission
|
// role permission
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Role);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Role);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Role);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Role);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.Role);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Role);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.Role);
|
||||||
|
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Member);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Member);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Member);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Member);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Member);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.Member);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Member);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.Member);
|
||||||
|
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.SecretScanning);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.SecretScanning);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.SecretScanning);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.SecretScanning);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.SecretScanning);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.SecretScanning);
|
||||||
|
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Settings);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Settings);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Settings);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Settings);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Settings);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.Settings);
|
||||||
|
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.IncidentAccount);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.IncidentAccount);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.IncidentAccount);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.IncidentAccount);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.IncidentAccount);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.IncidentAccount);
|
||||||
|
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Sso);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Sso);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Sso);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Sso);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Sso);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.Sso);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Sso);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.Sso);
|
||||||
|
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Billing);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Billing);
|
||||||
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Billing);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Billing);
|
||||||
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Billing);
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.Billing);
|
||||||
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Billing);
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.Billing);
|
||||||
|
|
||||||
return build();
|
return build();
|
||||||
};
|
};
|
||||||
@@ -86,15 +82,15 @@ export const adminPermissions = buildAdminPermission();
|
|||||||
const buildMemberPermission = () => {
|
const buildMemberPermission = () => {
|
||||||
const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility);
|
const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility);
|
||||||
|
|
||||||
can(WorkspacePermissionActions.Read, OrgPermissionSubjects.Workspace);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Workspace);
|
||||||
can(WorkspacePermissionActions.Create, OrgPermissionSubjects.Workspace);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Workspace);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Member);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Member);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Role);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Settings);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Settings);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Billing);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Billing);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Sso);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Sso);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
|
||||||
can(GeneralPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
|
||||||
|
|
||||||
return build();
|
return build();
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
export { OrgPermissionProvider, useOrgPermission } from "./OrgPermissionContext";
|
export { OrgPermissionProvider, useOrgPermission } from "./OrgPermissionContext";
|
||||||
export type { TOrgPermission } from "./types";
|
export type { TOrgPermission } from "./types";
|
||||||
export { GeneralPermissionActions,OrgPermissionSubjects } from "./types";
|
export { OrgPermissionActions, OrgPermissionSubjects } from "./types";
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import { MongoAbility } from "@casl/ability";
|
import { MongoAbility } from "@casl/ability";
|
||||||
|
|
||||||
export enum GeneralPermissionActions {
|
export enum OrgPermissionActions {
|
||||||
Read = "read",
|
Read = "read",
|
||||||
Create = "create",
|
Create = "create",
|
||||||
Edit = "edit",
|
Edit = "edit",
|
||||||
@@ -19,14 +19,14 @@ export enum OrgPermissionSubjects {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export type OrgPermissionSet =
|
export type OrgPermissionSet =
|
||||||
| [GeneralPermissionActions.Create, OrgPermissionSubjects.Workspace]
|
| [OrgPermissionActions.Create, OrgPermissionSubjects.Workspace]
|
||||||
| [GeneralPermissionActions.Read, OrgPermissionSubjects.Workspace]
|
| [OrgPermissionActions.Read, OrgPermissionSubjects.Workspace]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Role]
|
| [OrgPermissionActions, OrgPermissionSubjects.Role]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Member]
|
| [OrgPermissionActions, OrgPermissionSubjects.Member]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Settings]
|
| [OrgPermissionActions, OrgPermissionSubjects.Settings]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.IncidentAccount]
|
| [OrgPermissionActions, OrgPermissionSubjects.IncidentAccount]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Sso]
|
| [OrgPermissionActions, OrgPermissionSubjects.Sso]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.SecretScanning]
|
| [OrgPermissionActions, OrgPermissionSubjects.SecretScanning]
|
||||||
| [GeneralPermissionActions, OrgPermissionSubjects.Billing];
|
| [OrgPermissionActions, OrgPermissionSubjects.Billing];
|
||||||
|
|
||||||
export type TOrgPermission = MongoAbility<OrgPermissionSet>;
|
export type TOrgPermission = MongoAbility<OrgPermissionSet>;
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ export { AuthProvider } from "./AuthContext";
|
|||||||
export { OrgProvider, useOrganization } from "./OrganizationContext";
|
export { OrgProvider, useOrganization } from "./OrganizationContext";
|
||||||
export type { TOrgPermission } from "./OrgPermissionContext";
|
export type { TOrgPermission } from "./OrgPermissionContext";
|
||||||
export {
|
export {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionProvider,
|
OrgPermissionProvider,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
useOrgPermission
|
useOrgPermission
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { useTranslation } from "react-i18next";
|
import { useTranslation } from "react-i18next";
|
||||||
import Head from "next/head";
|
import Head from "next/head";
|
||||||
|
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, TOrgPermission } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, TOrgPermission } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { BillingSettingsPage } from "@app/views/Settings/BillingSettingsPage";
|
import { BillingSettingsPage } from "@app/views/Settings/BillingSettingsPage";
|
||||||
|
|
||||||
@@ -20,7 +20,7 @@ const SettingsBilling = withPermission<{}, TOrgPermission>(
|
|||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
{ action: GeneralPermissionActions.Delete, subject: OrgPermissionSubjects.Billing }
|
{ action: OrgPermissionActions.Delete, subject: OrgPermissionSubjects.Billing }
|
||||||
);
|
);
|
||||||
|
|
||||||
Object.assign(SettingsBilling, { requireAuth: true });
|
Object.assign(SettingsBilling, { requireAuth: true });
|
||||||
|
|||||||
@@ -16,8 +16,8 @@ import {
|
|||||||
faArrowUpRightFromSquare,
|
faArrowUpRightFromSquare,
|
||||||
faCheck,
|
faCheck,
|
||||||
faCheckCircle,
|
faCheckCircle,
|
||||||
faExclamationCircle,
|
|
||||||
faClipboard,
|
faClipboard,
|
||||||
|
faExclamationCircle,
|
||||||
faHandPeace,
|
faHandPeace,
|
||||||
faMagnifyingGlass,
|
faMagnifyingGlass,
|
||||||
faNetworkWired,
|
faNetworkWired,
|
||||||
@@ -43,9 +43,8 @@ import {
|
|||||||
Skeleton,
|
Skeleton,
|
||||||
UpgradePlanModal
|
UpgradePlanModal
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { useFetchServerStatus } from "@app/hooks/api/serverDetails";
|
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
useSubscription,
|
useSubscription,
|
||||||
useUser,
|
useUser,
|
||||||
@@ -59,6 +58,7 @@ import {
|
|||||||
useRegisterUserAction,
|
useRegisterUserAction,
|
||||||
useUploadWsKey
|
useUploadWsKey
|
||||||
} from "@app/hooks/api";
|
} from "@app/hooks/api";
|
||||||
|
import { useFetchServerStatus } from "@app/hooks/api/serverDetails";
|
||||||
import { usePopUp } from "@app/hooks/usePopUp";
|
import { usePopUp } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
import { encryptAssymmetric } from "../../../../components/utilities/cryptography/crypto";
|
import { encryptAssymmetric } from "../../../../components/utilities/cryptography/crypto";
|
||||||
@@ -473,82 +473,81 @@ const OrganizationPage = withPermission(
|
|||||||
const { createNotification } = useNotificationContext();
|
const { createNotification } = useNotificationContext();
|
||||||
const addWsUser = useAddUserToWs();
|
const addWsUser = useAddUserToWs();
|
||||||
|
|
||||||
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
||||||
"addNewWs",
|
"addNewWs",
|
||||||
"upgradePlan"
|
"upgradePlan"
|
||||||
] as const);
|
] as const);
|
||||||
const {
|
const {
|
||||||
control,
|
control,
|
||||||
formState: { isSubmitting },
|
formState: { isSubmitting },
|
||||||
reset,
|
reset,
|
||||||
handleSubmit
|
handleSubmit
|
||||||
} = useForm<TAddProjectFormData>({
|
} = useForm<TAddProjectFormData>({
|
||||||
resolver: yupResolver(formSchema)
|
resolver: yupResolver(formSchema)
|
||||||
});
|
});
|
||||||
|
|
||||||
const [hasUserClickedSlack, setHasUserClickedSlack] = useState(false);
|
const [hasUserClickedSlack, setHasUserClickedSlack] = useState(false);
|
||||||
const [hasUserClickedIntro, setHasUserClickedIntro] = useState(false);
|
const [hasUserClickedIntro, setHasUserClickedIntro] = useState(false);
|
||||||
const [hasUserPushedSecrets, setHasUserPushedSecrets] = useState(false);
|
const [hasUserPushedSecrets, setHasUserPushedSecrets] = useState(false);
|
||||||
const [usersInOrg, setUsersInOrg] = useState(false);
|
const [usersInOrg, setUsersInOrg] = useState(false);
|
||||||
const [searchFilter, setSearchFilter] = useState("");
|
const [searchFilter, setSearchFilter] = useState("");
|
||||||
const createWs = useCreateWorkspace();
|
const createWs = useCreateWorkspace();
|
||||||
const { user } = useUser();
|
const { user } = useUser();
|
||||||
const uploadWsKey = useUploadWsKey();
|
const uploadWsKey = useUploadWsKey();
|
||||||
const { data: serverDetails } = useFetchServerStatus();
|
const { data: serverDetails } = useFetchServerStatus();
|
||||||
|
|
||||||
|
|
||||||
const onCreateProject = async ({ name, addMembers }: TAddProjectFormData) => {
|
const onCreateProject = async ({ name, addMembers }: TAddProjectFormData) => {
|
||||||
// type check
|
// type check
|
||||||
if (!currentOrg) return;
|
if (!currentOrg) return;
|
||||||
try {
|
try {
|
||||||
const {
|
const {
|
||||||
data: {
|
data: {
|
||||||
workspace: { _id: newWorkspaceId }
|
workspace: { _id: newWorkspaceId }
|
||||||
}
|
}
|
||||||
} = await createWs.mutateAsync({
|
} = await createWs.mutateAsync({
|
||||||
organizationId: currentOrg,
|
organizationId: currentOrg,
|
||||||
workspaceName: name
|
workspaceName: name
|
||||||
});
|
|
||||||
|
|
||||||
const randomBytes = crypto.randomBytes(16).toString("hex");
|
|
||||||
const PRIVATE_KEY = String(localStorage.getItem("PRIVATE_KEY"));
|
|
||||||
const { ciphertext, nonce } = encryptAssymmetric({
|
|
||||||
plaintext: randomBytes,
|
|
||||||
publicKey: user.publicKey,
|
|
||||||
privateKey: PRIVATE_KEY
|
|
||||||
});
|
|
||||||
|
|
||||||
await uploadWsKey.mutateAsync({
|
|
||||||
encryptedKey: ciphertext,
|
|
||||||
nonce,
|
|
||||||
userId: user?._id,
|
|
||||||
workspaceId: newWorkspaceId
|
|
||||||
});
|
|
||||||
|
|
||||||
if (addMembers) {
|
|
||||||
// not using hooks because need at this point only
|
|
||||||
const orgUsers = await fetchOrgUsers(currentOrg);
|
|
||||||
orgUsers.forEach(({ status, user: orgUser }) => {
|
|
||||||
// skip if status of org user is not accepted
|
|
||||||
// this orgUser is the person who created the ws
|
|
||||||
if (status !== "accepted" || user.email === orgUser.email) return;
|
|
||||||
addWsUser.mutate({ email: orgUser.email, workspaceId: newWorkspaceId });
|
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const randomBytes = crypto.randomBytes(16).toString("hex");
|
||||||
|
const PRIVATE_KEY = String(localStorage.getItem("PRIVATE_KEY"));
|
||||||
|
const { ciphertext, nonce } = encryptAssymmetric({
|
||||||
|
plaintext: randomBytes,
|
||||||
|
publicKey: user.publicKey,
|
||||||
|
privateKey: PRIVATE_KEY
|
||||||
|
});
|
||||||
|
|
||||||
|
await uploadWsKey.mutateAsync({
|
||||||
|
encryptedKey: ciphertext,
|
||||||
|
nonce,
|
||||||
|
userId: user?._id,
|
||||||
|
workspaceId: newWorkspaceId
|
||||||
|
});
|
||||||
|
|
||||||
|
if (addMembers) {
|
||||||
|
// not using hooks because need at this point only
|
||||||
|
const orgUsers = await fetchOrgUsers(currentOrg);
|
||||||
|
orgUsers.forEach(({ status, user: orgUser }) => {
|
||||||
|
// skip if status of org user is not accepted
|
||||||
|
// this orgUser is the person who created the ws
|
||||||
|
if (status !== "accepted" || user.email === orgUser.email) return;
|
||||||
|
addWsUser.mutate({ email: orgUser.email, workspaceId: newWorkspaceId });
|
||||||
|
});
|
||||||
|
}
|
||||||
|
createNotification({ text: "Workspace created", type: "success" });
|
||||||
|
handlePopUpClose("addNewWs");
|
||||||
|
router.push(`/project/${newWorkspaceId}/secrets/overview`);
|
||||||
|
} catch (err) {
|
||||||
|
console.error(err);
|
||||||
|
createNotification({ text: "Failed to create workspace", type: "error" });
|
||||||
}
|
}
|
||||||
createNotification({ text: "Workspace created", type: "success" });
|
};
|
||||||
handlePopUpClose("addNewWs");
|
|
||||||
router.push(`/project/${newWorkspaceId}/secrets/overview`);
|
|
||||||
} catch (err) {
|
|
||||||
console.error(err);
|
|
||||||
createNotification({ text: "Failed to create workspace", type: "error" });
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
const { subscription } = useSubscription();
|
const { subscription } = useSubscription();
|
||||||
|
|
||||||
const isAddingProjectsAllowed = subscription?.workspaceLimit
|
const isAddingProjectsAllowed = subscription?.workspaceLimit
|
||||||
? subscription.workspacesUsed < subscription.workspaceLimit
|
? subscription.workspacesUsed < subscription.workspaceLimit
|
||||||
: true;
|
: true;
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
onboardingCheck({
|
onboardingCheck({
|
||||||
@@ -567,18 +566,28 @@ const OrganizationPage = withPermission(
|
|||||||
<title>{t("common.head-title", { title: t("settings.members.title") })}</title>
|
<title>{t("common.head-title", { title: t("settings.members.title") })}</title>
|
||||||
<link rel="icon" href="/infisical.ico" />
|
<link rel="icon" href="/infisical.ico" />
|
||||||
</Head>
|
</Head>
|
||||||
{!serverDetails?.redisConfigured && <div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl">
|
{!serverDetails?.redisConfigured && (
|
||||||
<p className="mr-4 mb-4 font-semibold text-white">Announcements</p>
|
<div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl">
|
||||||
<div className="w-full border border-blue-400/70 rounded-md bg-blue-900/70 p-2 text-base text-mineshaft-100 flex items-center">
|
<p className="mr-4 mb-4 font-semibold text-white">Announcements</p>
|
||||||
<FontAwesomeIcon icon={faExclamationCircle} className="text-2xl mr-4 p-4 text-mineshaft-50"/>
|
<div className="w-full border border-blue-400/70 rounded-md bg-blue-900/70 p-2 text-base text-mineshaft-100 flex items-center">
|
||||||
Attention: Updated versions of Infisical now require Redis for full functionality. Learn how to configure it
|
<FontAwesomeIcon
|
||||||
<Link href="https://infisical.com/docs/self-hosting/configuration/redis" target="_blank">
|
icon={faExclamationCircle}
|
||||||
<span className="pl-1 text-white underline underline-offset-2 hover:decoration-blue-400 hover:text-blue-200 duration-100 cursor-pointer">
|
className="text-2xl mr-4 p-4 text-mineshaft-50"
|
||||||
here
|
/>
|
||||||
</span>
|
Attention: Updated versions of Infisical now require Redis for full functionality.
|
||||||
</Link>.
|
Learn how to configure it
|
||||||
|
<Link
|
||||||
|
href="https://infisical.com/docs/self-hosting/configuration/redis"
|
||||||
|
target="_blank"
|
||||||
|
>
|
||||||
|
<span className="pl-1 text-white underline underline-offset-2 hover:decoration-blue-400 hover:text-blue-200 duration-100 cursor-pointer">
|
||||||
|
here
|
||||||
|
</span>
|
||||||
|
</Link>
|
||||||
|
.
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>}
|
)}
|
||||||
<div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl">
|
<div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl">
|
||||||
<p className="mr-4 font-semibold text-white">Projects</p>
|
<p className="mr-4 font-semibold text-white">Projects</p>
|
||||||
<div className="mt-6 flex w-full flex-row">
|
<div className="mt-6 flex w-full flex-row">
|
||||||
@@ -589,10 +598,7 @@ const OrganizationPage = withPermission(
|
|||||||
onChange={(e) => setSearchFilter(e.target.value)}
|
onChange={(e) => setSearchFilter(e.target.value)}
|
||||||
leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />}
|
leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />}
|
||||||
/>
|
/>
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan I={OrgPermissionActions.Create} an={OrgPermissionSubjects.Workspace}>
|
||||||
I={GeneralPermissionActions.Create}
|
|
||||||
an={OrgPermissionSubjects.Workspace}
|
|
||||||
>
|
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
isDisabled={!isAllowed}
|
isDisabled={!isAllowed}
|
||||||
@@ -877,7 +883,7 @@ const OrganizationPage = withPermission(
|
|||||||
);
|
);
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
action: GeneralPermissionActions.Read,
|
action: OrgPermissionActions.Read,
|
||||||
subject: OrgPermissionSubjects.Workspace
|
subject: OrgPermissionSubjects.Workspace
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
|
|||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button } from "@app/components/v2";
|
import { Button } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { SecretScanningLogsTable } from "@app/views/SecretScanning/components";
|
import { SecretScanningLogsTable } from "@app/views/SecretScanning/components";
|
||||||
|
|
||||||
@@ -101,7 +101,7 @@ const SecretScanning = withPermission(
|
|||||||
) : (
|
) : (
|
||||||
<div className="flex items-center h-[3.25rem]">
|
<div className="flex items-center h-[3.25rem]">
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Create}
|
I={OrgPermissionActions.Create}
|
||||||
a={OrgPermissionSubjects.SecretScanning}
|
a={OrgPermissionSubjects.SecretScanning}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
@@ -125,7 +125,7 @@ const SecretScanning = withPermission(
|
|||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.SecretScanning }
|
{ action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.SecretScanning }
|
||||||
);
|
);
|
||||||
|
|
||||||
Object.assign(SecretScanning, { requireAuth: true });
|
Object.assign(SecretScanning, { requireAuth: true });
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ import { useTranslation } from "react-i18next";
|
|||||||
import { motion } from "framer-motion";
|
import { motion } from "framer-motion";
|
||||||
|
|
||||||
import { Tab, TabList, TabPanel, Tabs } from "@app/components/v2";
|
import { Tab, TabList, TabPanel, Tabs } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { useGetRoles } from "@app/hooks/api";
|
import { useGetRoles } from "@app/hooks/api";
|
||||||
import { TRole } from "@app/hooks/api/roles/types";
|
import { TRole } from "@app/hooks/api/roles/types";
|
||||||
@@ -59,5 +59,5 @@ export const MembersPage = withPermission(
|
|||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.Member }
|
{ action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Member }
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ import {
|
|||||||
UpgradePlanModal
|
UpgradePlanModal
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
useOrganization,
|
useOrganization,
|
||||||
useSubscription,
|
useSubscription,
|
||||||
@@ -305,7 +305,7 @@ export const OrgMembersTable = ({ roles = [] }: Props) => {
|
|||||||
placeholder="Search members..."
|
placeholder="Search members..."
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Member}>
|
<OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Member}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
isDisabled={!isAllowed}
|
isDisabled={!isAllowed}
|
||||||
@@ -359,7 +359,7 @@ export const OrgMembersTable = ({ roles = [] }: Props) => {
|
|||||||
<Td>{email}</Td>
|
<Td>{email}</Td>
|
||||||
<Td>
|
<Td>
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Edit}
|
I={OrgPermissionActions.Edit}
|
||||||
a={OrgPermissionSubjects.Member}
|
a={OrgPermissionSubjects.Member}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
@@ -453,7 +453,7 @@ export const OrgMembersTable = ({ roles = [] }: Props) => {
|
|||||||
<Td>
|
<Td>
|
||||||
{userId !== u?._id && (
|
{userId !== u?._id && (
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Delete}
|
I={OrgPermissionActions.Delete}
|
||||||
a={OrgPermissionSubjects.Member}
|
a={OrgPermissionSubjects.Member}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { useEffect, useState } from "react";
|
import { useEffect, useState } from "react";
|
||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import updateRiskStatus, { RiskStatus } from "@app/pages/api/secret-scanning/updateRiskStatus";
|
import updateRiskStatus, { RiskStatus } from "@app/pages/api/secret-scanning/updateRiskStatus";
|
||||||
|
|
||||||
export const RiskStatusSelection = ({
|
export const RiskStatusSelection = ({
|
||||||
@@ -26,7 +26,7 @@ export const RiskStatusSelection = ({
|
|||||||
}, [selectedRiskStatus]);
|
}, [selectedRiskStatus]);
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.SecretScanning}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.SecretScanning}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<select
|
<select
|
||||||
disabled={!isAllowed}
|
disabled={!isAllowed}
|
||||||
|
|||||||
+3
-3
@@ -1,7 +1,7 @@
|
|||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button } from "@app/components/v2";
|
import { Button } from "@app/components/v2";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
useOrganization,
|
useOrganization,
|
||||||
useSubscription
|
useSubscription
|
||||||
@@ -81,7 +81,7 @@ export const PreviewSection = () => {
|
|||||||
Unlimited members, projects, RBAC, smart alerts, and so much more
|
Unlimited members, projects, RBAC, smart alerts, and so much more
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Billing}>
|
<OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Billing}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
onClick={() => handleUpgradeBtnClick()}
|
onClick={() => handleUpgradeBtnClick()}
|
||||||
@@ -103,7 +103,7 @@ export const PreviewSection = () => {
|
|||||||
subscription.status === "trialing" ? "(Trial)" : ""
|
subscription.status === "trialing" ? "(Trial)" : ""
|
||||||
}`}
|
}`}
|
||||||
</p>
|
</p>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
|
|||||||
+2
-2
@@ -6,7 +6,7 @@ import * as yup from "yup";
|
|||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button, FormControl, Input } from "@app/components/v2";
|
import { Button, FormControl, Input } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api";
|
import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api";
|
||||||
|
|
||||||
const schema = yup
|
const schema = yup
|
||||||
@@ -75,7 +75,7 @@ export const CompanyNameSection = () => {
|
|||||||
name="name"
|
name="name"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
type="submit"
|
type="submit"
|
||||||
|
|||||||
+2
-2
@@ -6,7 +6,7 @@ import * as yup from "yup";
|
|||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button, FormControl, Input } from "@app/components/v2";
|
import { Button, FormControl, Input } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api";
|
import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api";
|
||||||
|
|
||||||
const schema = yup
|
const schema = yup
|
||||||
@@ -76,7 +76,7 @@ export const InvoiceEmailSection = () => {
|
|||||||
name="email"
|
name="email"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
type="submit"
|
type="submit"
|
||||||
|
|||||||
+2
-2
@@ -3,7 +3,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
|||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button } from "@app/components/v2";
|
import { Button } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { useAddOrgPmtMethod } from "@app/hooks/api";
|
import { useAddOrgPmtMethod } from "@app/hooks/api";
|
||||||
|
|
||||||
import { PmtMethodsTable } from "./PmtMethodsTable";
|
import { PmtMethodsTable } from "./PmtMethodsTable";
|
||||||
@@ -27,7 +27,7 @@ export const PmtMethodsSection = () => {
|
|||||||
<div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600">
|
<div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600">
|
||||||
<div className="flex items-center mb-8">
|
<div className="flex items-center mb-8">
|
||||||
<h2 className="text-xl font-semibold flex-1 text-white">Payment methods</h2>
|
<h2 className="text-xl font-semibold flex-1 text-white">Payment methods</h2>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Billing}>
|
<OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Billing}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
onClick={handleAddPmtMethodBtnClick}
|
onClick={handleAddPmtMethodBtnClick}
|
||||||
|
|||||||
+2
-2
@@ -14,7 +14,7 @@ import {
|
|||||||
THead,
|
THead,
|
||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { useDeleteOrgPmtMethod, useGetOrgPmtMethods } from "@app/hooks/api";
|
import { useDeleteOrgPmtMethod, useGetOrgPmtMethods } from "@app/hooks/api";
|
||||||
|
|
||||||
export const PmtMethodsTable = () => {
|
export const PmtMethodsTable = () => {
|
||||||
@@ -54,7 +54,7 @@ export const PmtMethodsTable = () => {
|
|||||||
<Td>{`${exp_month}/${exp_year}`}</Td>
|
<Td>{`${exp_month}/${exp_year}`}</Td>
|
||||||
<Td>
|
<Td>
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Delete}
|
I={OrgPermissionActions.Delete}
|
||||||
a={OrgPermissionSubjects.Billing}
|
a={OrgPermissionSubjects.Billing}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
|
|||||||
+2
-2
@@ -3,7 +3,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
|||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button } from "@app/components/v2";
|
import { Button } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import { usePopUp } from "@app/hooks/usePopUp";
|
import { usePopUp } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
import { TaxIDModal } from "./TaxIDModal";
|
import { TaxIDModal } from "./TaxIDModal";
|
||||||
@@ -18,7 +18,7 @@ export const TaxIDSection = () => {
|
|||||||
<div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600">
|
<div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600">
|
||||||
<div className="flex items-center mb-8">
|
<div className="flex items-center mb-8">
|
||||||
<h2 className="text-xl font-semibold flex-1 text-white">Tax ID</h2>
|
<h2 className="text-xl font-semibold flex-1 text-white">Tax ID</h2>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
onClick={() => handlePopUpOpen("addTaxID")}
|
onClick={() => handlePopUpOpen("addTaxID")}
|
||||||
|
|||||||
+2
-2
@@ -14,7 +14,7 @@ import {
|
|||||||
THead,
|
THead,
|
||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { useDeleteOrgTaxId, useGetOrgTaxIds } from "@app/hooks/api";
|
import { useDeleteOrgTaxId, useGetOrgTaxIds } from "@app/hooks/api";
|
||||||
|
|
||||||
const taxIDTypeLabelMap: { [key: string]: string } = {
|
const taxIDTypeLabelMap: { [key: string]: string } = {
|
||||||
@@ -103,7 +103,7 @@ export const TaxIDTable = () => {
|
|||||||
<Td>{value}</Td>
|
<Td>{value}</Td>
|
||||||
<Td>
|
<Td>
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Delete}
|
I={OrgPermissionActions.Delete}
|
||||||
a={OrgPermissionSubjects.Billing}
|
a={OrgPermissionSubjects.Billing}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
|
|||||||
+2
-2
@@ -1,7 +1,7 @@
|
|||||||
import { Fragment } from "react";
|
import { Fragment } from "react";
|
||||||
import { Tab } from "@headlessui/react";
|
import { Tab } from "@headlessui/react";
|
||||||
|
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
|
|
||||||
import { BillingCloudTab } from "../BillingCloudTab";
|
import { BillingCloudTab } from "../BillingCloudTab";
|
||||||
@@ -53,5 +53,5 @@ export const BillingTabGroup = withPermission(
|
|||||||
</Tab.Group>
|
</Tab.Group>
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.Billing }
|
{ action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Billing }
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
|
|
||||||
import { OrgSSOSection } from "./OrgSSOSection";
|
import { OrgSSOSection } from "./OrgSSOSection";
|
||||||
@@ -11,5 +11,5 @@ export const OrgAuthTab = withPermission(
|
|||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.Sso }
|
{ action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Sso }
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import { useNotificationContext } from "@app/components/context/Notifications/No
|
|||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button, Switch, UpgradePlanModal } from "@app/components/v2";
|
import { Button, Switch, UpgradePlanModal } from "@app/components/v2";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
useOrganization,
|
useOrganization,
|
||||||
useSubscription
|
useSubscription
|
||||||
@@ -86,7 +86,7 @@ export const OrgSSOSection = (): JSX.Element => {
|
|||||||
<div className="flex items-center mb-8">
|
<div className="flex items-center mb-8">
|
||||||
<h2 className="text-xl font-semibold flex-1 text-white">SAML SSO Configuration</h2>
|
<h2 className="text-xl font-semibold flex-1 text-white">SAML SSO Configuration</h2>
|
||||||
{!isLoading && (
|
{!isLoading && (
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Sso}>
|
<OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Sso}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
onClick={addSSOBtnClick}
|
onClick={addSSOBtnClick}
|
||||||
@@ -102,7 +102,7 @@ export const OrgSSOSection = (): JSX.Element => {
|
|||||||
</div>
|
</div>
|
||||||
{data && (
|
{data && (
|
||||||
<div className="mb-4">
|
<div className="mb-4">
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Switch
|
<Switch
|
||||||
id="enable-saml-sso"
|
id="enable-saml-sso"
|
||||||
|
|||||||
+3
-3
@@ -4,7 +4,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
|||||||
|
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button } from "@app/components/v2";
|
import { Button } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
|
|
||||||
@@ -25,7 +25,7 @@ export const OrgIncidentContactsSection = withPermission(
|
|||||||
{t("section.incident.incident-contacts")}
|
{t("section.incident.incident-contacts")}
|
||||||
</p>
|
</p>
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Create}
|
I={OrgPermissionActions.Create}
|
||||||
a={OrgPermissionSubjects.IncidentAccount}
|
a={OrgPermissionSubjects.IncidentAccount}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
@@ -50,5 +50,5 @@ export const OrgIncidentContactsSection = withPermission(
|
|||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
},
|
},
|
||||||
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.IncidentAccount }
|
{ action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.IncidentAccount }
|
||||||
);
|
);
|
||||||
|
|||||||
+2
-2
@@ -18,7 +18,7 @@ import {
|
|||||||
THead,
|
THead,
|
||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
import { useDeleteIncidentContact, useGetOrgIncidentContact } from "@app/hooks/api";
|
import { useDeleteIncidentContact, useGetOrgIncidentContact } from "@app/hooks/api";
|
||||||
|
|
||||||
@@ -85,7 +85,7 @@ export const OrgIncidentContactsTable = () => {
|
|||||||
<Td className="w-full">{email}</Td>
|
<Td className="w-full">{email}</Td>
|
||||||
<Td className="mr-4">
|
<Td className="mr-4">
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={GeneralPermissionActions.Delete}
|
I={OrgPermissionActions.Delete}
|
||||||
an={OrgPermissionSubjects.IncidentAccount}
|
an={OrgPermissionSubjects.IncidentAccount}
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
|
|||||||
+3
-3
@@ -6,7 +6,7 @@ import * as yup from "yup";
|
|||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import { Button, FormControl, Input } from "@app/components/v2";
|
import { Button, FormControl, Input } from "@app/components/v2";
|
||||||
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { useRenameOrg } from "@app/hooks/api";
|
import { useRenameOrg } from "@app/hooks/api";
|
||||||
|
|
||||||
@@ -68,7 +68,7 @@ export const OrgNameChangeSection = withPermission(
|
|||||||
name="name"
|
name="name"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Settings}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Settings}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
isLoading={isLoading}
|
isLoading={isLoading}
|
||||||
@@ -85,7 +85,7 @@ export const OrgNameChangeSection = withPermission(
|
|||||||
);
|
);
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
action: GeneralPermissionActions.Read,
|
action: OrgPermissionActions.Read,
|
||||||
subject: OrgPermissionSubjects.Settings,
|
subject: OrgPermissionSubjects.Settings,
|
||||||
containerClassName: "mb-4"
|
containerClassName: "mb-4"
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-2
@@ -35,7 +35,7 @@ import {
|
|||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import {
|
import {
|
||||||
GeneralPermissionActions,
|
OrgPermissionActions,
|
||||||
OrgPermissionSubjects,
|
OrgPermissionSubjects,
|
||||||
useOrganization,
|
useOrganization,
|
||||||
useWorkspace
|
useWorkspace
|
||||||
@@ -382,7 +382,7 @@ export const OrgServiceAccountsTable = withPermission(
|
|||||||
);
|
);
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
action: GeneralPermissionActions.Read,
|
action: OrgPermissionActions.Read,
|
||||||
subject: OrgPermissionSubjects.Settings,
|
subject: OrgPermissionSubjects.Settings,
|
||||||
containerClassName: "mb-4"
|
containerClassName: "mb-4"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user