feat(rbac): changed the action names for org

This commit is contained in:
Akhil Mohan
2023-09-08 21:22:36 +05:30
parent ea9e638d03
commit 4b0bc238fc
32 changed files with 252 additions and 252 deletions
@@ -19,7 +19,7 @@ import {
import { validateUserEmail } from "../../validation"; import { validateUserEmail } from "../../validation";
import { validateRequest } from "../../helpers/validation"; import { validateRequest } from "../../helpers/validation";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
getUserOrgPermissions getUserOrgPermissions
} from "../../services/RoleService"; } from "../../services/RoleService";
@@ -50,7 +50,7 @@ export const deleteMembershipOrg = async (req: Request, _res: Response) => {
membershipOrgToDelete.organization.toString() membershipOrgToDelete.organization.toString()
); );
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Delete, OrgPermissionActions.Delete,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
@@ -98,7 +98,7 @@ export const inviteUserToOrganization = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
@@ -14,9 +14,8 @@ import { licenseServerKeyRequest } from "../../config/request";
import { validateRequest } from "../../helpers/validation"; import { validateRequest } from "../../helpers/validation";
import * as reqValidator from "../../validation/organization"; import * as reqValidator from "../../validation/organization";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
WorkspacePermissionActions,
getUserOrgPermissions getUserOrgPermissions
} from "../../services/RoleService"; } from "../../services/RoleService";
import { OrganizationNotFoundError } from "../../utils/errors"; import { OrganizationNotFoundError } from "../../utils/errors";
@@ -104,7 +103,7 @@ export const getOrganizationMembers = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
@@ -130,7 +129,7 @@ export const getOrganizationWorkspaces = async (req: Request, res: Response) =>
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
WorkspacePermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Workspace OrgPermissionSubjects.Workspace
); );
@@ -172,7 +171,7 @@ export const changeOrganizationName = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.Settings OrgPermissionSubjects.Settings
); );
@@ -207,7 +206,7 @@ export const getOrganizationIncidentContacts = async (req: Request, res: Respons
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.IncidentAccount OrgPermissionSubjects.IncidentAccount
); );
@@ -234,7 +233,7 @@ export const addOrganizationIncidentContact = async (req: Request, res: Response
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.IncidentAccount OrgPermissionSubjects.IncidentAccount
); );
@@ -263,7 +262,7 @@ export const deleteOrganizationIncidentContact = async (req: Request, res: Respo
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Delete, OrgPermissionActions.Delete,
OrgPermissionSubjects.IncidentAccount OrgPermissionSubjects.IncidentAccount
); );
@@ -292,7 +291,7 @@ export const createOrganizationPortalSession = async (req: Request, res: Respons
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -356,11 +355,11 @@ export const getOrganizationMembersAndTheirWorkspaces = async (req: Request, res
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
WorkspacePermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Workspace OrgPermissionSubjects.Workspace
); );
+5 -5
View File
@@ -2,7 +2,7 @@ import { Request, Response } from "express";
import { BadRequestError } from "../../utils/errors"; import { BadRequestError } from "../../utils/errors";
import Role from "../../models/role"; import Role from "../../models/role";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
adminPermissions, adminPermissions,
getUserOrgPermissions, getUserOrgPermissions,
@@ -30,7 +30,7 @@ export const createRole = async (req: Request, res: Response) => {
} = await validateRequest(CreateRoleSchema, req); } = await validateRequest(CreateRoleSchema, req);
const { permission } = await getUserOrgPermissions(req.user.id, orgId); const { permission } = await getUserOrgPermissions(req.user.id, orgId);
if (permission.cannot(GeneralPermissionActions.Create, OrgPermissionSubjects.Role)) { if (permission.cannot(OrgPermissionActions.Create, OrgPermissionSubjects.Role)) {
throw BadRequestError({ message: "User doesn't have the permission." }); throw BadRequestError({ message: "User doesn't have the permission." });
} }
@@ -68,7 +68,7 @@ export const updateRole = async (req: Request, res: Response) => {
const isOrgRole = !workspaceId; // if workspaceid is provided then its a workspace rule const isOrgRole = !workspaceId; // if workspaceid is provided then its a workspace rule
const { permission } = await getUserOrgPermissions(req.user.id, orgId); const { permission } = await getUserOrgPermissions(req.user.id, orgId);
if (permission.cannot(GeneralPermissionActions.Edit, OrgPermissionSubjects.Role)) { if (permission.cannot(OrgPermissionActions.Edit, OrgPermissionSubjects.Role)) {
throw BadRequestError({ message: "User doesn't have the permission." }); throw BadRequestError({ message: "User doesn't have the permission." });
} }
@@ -112,7 +112,7 @@ export const deleteRole = async (req: Request, res: Response) => {
} }
const { permission } = await getUserOrgPermissions(req.user.id, role.organization.toString()); const { permission } = await getUserOrgPermissions(req.user.id, role.organization.toString());
if (permission.cannot(GeneralPermissionActions.Delete, OrgPermissionSubjects.Role)) { if (permission.cannot(OrgPermissionActions.Delete, OrgPermissionSubjects.Role)) {
throw BadRequestError({ message: "User doesn't have the permission." }); throw BadRequestError({ message: "User doesn't have the permission." });
} }
await Role.findByIdAndDelete(role.id); await Role.findByIdAndDelete(role.id);
@@ -132,7 +132,7 @@ export const getRoles = async (req: Request, res: Response) => {
const isOrgRole = !workspaceId; const isOrgRole = !workspaceId;
const { permission } = await getUserOrgPermissions(req.user.id, orgId); const { permission } = await getUserOrgPermissions(req.user.id, orgId);
if (permission.cannot(GeneralPermissionActions.Read, OrgPermissionSubjects.Role)) { if (permission.cannot(OrgPermissionActions.Read, OrgPermissionSubjects.Role)) {
throw BadRequestError({ message: "User doesn't have the permission." }); throw BadRequestError({ message: "User doesn't have the permission." });
} }
@@ -12,7 +12,7 @@ import { Organization } from "../../models";
import { validateRequest } from "../../helpers/validation"; import { validateRequest } from "../../helpers/validation";
import * as reqValidator from "../../validation/secretScanning"; import * as reqValidator from "../../validation/secretScanning";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
getUserOrgPermissions getUserOrgPermissions
} from "../../services/RoleService"; } from "../../services/RoleService";
@@ -33,7 +33,7 @@ export const createInstallationSession = async (req: Request, res: Response) =>
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.SecretScanning OrgPermissionSubjects.SecretScanning
); );
@@ -69,7 +69,7 @@ export const linkInstallationToOrganization = async (req: Request, res: Response
installationSession.organization.toString() installationSession.organization.toString()
); );
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.SecretScanning OrgPermissionSubjects.SecretScanning
); );
@@ -131,7 +131,7 @@ export const getRisksForOrganization = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.SecretScanning OrgPermissionSubjects.SecretScanning
); );
@@ -151,7 +151,7 @@ export const updateRisksStatus = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.SecretScanning OrgPermissionSubjects.SecretScanning
); );
@@ -15,8 +15,8 @@ import { addMemberships } from "../../helpers/membership";
import { ADMIN } from "../../variables"; import { ADMIN } from "../../variables";
import { OrganizationNotFoundError } from "../../utils/errors"; import { OrganizationNotFoundError } from "../../utils/errors";
import { import {
OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
WorkspacePermissionActions,
getUserOrgPermissions getUserOrgPermissions
} from "../../services/RoleService"; } from "../../services/RoleService";
import { ForbiddenError } from "@casl/ability"; import { ForbiddenError } from "@casl/ability";
@@ -146,7 +146,7 @@ export const createWorkspace = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
WorkspacePermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.Workspace OrgPermissionSubjects.Workspace
); );
@@ -9,9 +9,8 @@ import { CUSTOM } from "../../variables";
import * as reqValidator from "../../validation/organization"; import * as reqValidator from "../../validation/organization";
import { validateRequest } from "../../helpers/validation"; import { validateRequest } from "../../helpers/validation";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
WorkspacePermissionActions,
getUserOrgPermissions getUserOrgPermissions
} from "../../services/RoleService"; } from "../../services/RoleService";
import { ForbiddenError } from "@casl/ability"; import { ForbiddenError } from "@casl/ability";
@@ -61,7 +60,7 @@ export const getOrganizationMemberships = async (req: Request, res: Response) =>
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
@@ -139,7 +138,7 @@ export const updateOrganizationMembership = async (req: Request, res: Response)
} = await validateRequest(reqValidator.UpdateOrgMemberv2, req); } = await validateRequest(reqValidator.UpdateOrgMemberv2, req);
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
@@ -220,7 +219,7 @@ export const deleteOrganizationMembership = async (req: Request, res: Response)
} = await validateRequest(reqValidator.DeleteOrgMemberv2, req); } = await validateRequest(reqValidator.DeleteOrgMemberv2, req);
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Delete, OrgPermissionActions.Delete,
OrgPermissionSubjects.Member OrgPermissionSubjects.Member
); );
@@ -284,7 +283,7 @@ export const getOrganizationWorkspaces = async (req: Request, res: Response) =>
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
WorkspacePermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Workspace OrgPermissionSubjects.Workspace
); );
@@ -6,7 +6,7 @@ import { EELicenseService } from "../../services";
import { validateRequest } from "../../../helpers/validation"; import { validateRequest } from "../../../helpers/validation";
import * as reqValidator from "../../../validation/organization"; import * as reqValidator from "../../../validation/organization";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
getUserOrgPermissions getUserOrgPermissions
} from "../../../services/RoleService"; } from "../../../services/RoleService";
@@ -22,7 +22,7 @@ export const getOrganizationPlansTable = async (req: Request, res: Response) =>
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -44,7 +44,7 @@ export const getOrganizationPlan = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -72,11 +72,11 @@ export const startOrganizationTrial = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -118,7 +118,7 @@ export const getOrganizationPlanBillingInfo = async (req: Request, res: Response
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -151,7 +151,7 @@ export const getOrganizationPlanTable = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -178,7 +178,7 @@ export const getOrganizationBillingDetails = async (req: Request, res: Response)
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -206,7 +206,7 @@ export const updateOrganizationBillingDetails = async (req: Request, res: Respon
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -240,7 +240,7 @@ export const getOrganizationPmtMethods = async (req: Request, res: Response) =>
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -273,7 +273,7 @@ export const addOrganizationPmtMethod = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -314,7 +314,7 @@ export const deleteOrganizationPmtMethod = async (req: Request, res: Response) =
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Delete, OrgPermissionActions.Delete,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -344,7 +344,7 @@ export const getOrganizationTaxIds = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -377,7 +377,7 @@ export const addOrganizationTaxId = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -414,7 +414,7 @@ export const deleteOrganizationTaxId = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Delete, OrgPermissionActions.Delete,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -447,7 +447,7 @@ export const getOrganizationInvoices = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -482,7 +482,7 @@ export const getOrganizationLicenses = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Billing OrgPermissionSubjects.Billing
); );
@@ -11,7 +11,7 @@ import { EELicenseService } from "../../services";
import * as reqValidator from "../../../validation/sso"; import * as reqValidator from "../../../validation/sso";
import { validateRequest } from "../../../helpers/validation"; import { validateRequest } from "../../../helpers/validation";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
getUserOrgPermissions getUserOrgPermissions
} from "../../../services/RoleService"; } from "../../../services/RoleService";
@@ -49,7 +49,7 @@ export const getSSOConfig = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Read, OrgPermissionActions.Read,
OrgPermissionSubjects.Sso OrgPermissionSubjects.Sso
); );
@@ -73,7 +73,7 @@ export const updateSSOConfig = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Edit, OrgPermissionActions.Edit,
OrgPermissionSubjects.Sso OrgPermissionSubjects.Sso
); );
@@ -208,7 +208,7 @@ export const createSSOConfig = async (req: Request, res: Response) => {
const { permission } = await getUserOrgPermissions(req.user._id, organizationId); const { permission } = await getUserOrgPermissions(req.user._id, organizationId);
ForbiddenError.from(permission).throwUnlessCan( ForbiddenError.from(permission).throwUnlessCan(
GeneralPermissionActions.Create, OrgPermissionActions.Create,
OrgPermissionSubjects.Sso OrgPermissionSubjects.Sso
); );
+49 -53
View File
@@ -4,18 +4,13 @@ import { IRole } from "../models/role";
import { BadRequestError, UnauthorizedRequestError } from "../utils/errors"; import { BadRequestError, UnauthorizedRequestError } from "../utils/errors";
import { ACCEPTED } from "../variables"; import { ACCEPTED } from "../variables";
export enum GeneralPermissionActions { export enum OrgPermissionActions {
Read = "read", Read = "read",
Create = "create", Create = "create",
Edit = "edit", Edit = "edit",
Delete = "delete" Delete = "delete"
} }
export enum WorkspacePermissionActions {
Read = "read",
Create = "create"
}
export enum OrgPermissionSubjects { export enum OrgPermissionSubjects {
Workspace = "workspace", Workspace = "workspace",
Role = "role", Role = "role",
@@ -28,55 +23,56 @@ export enum OrgPermissionSubjects {
} }
export type OrgPermissionSet = export type OrgPermissionSet =
| [WorkspacePermissionActions, OrgPermissionSubjects.Workspace] | [OrgPermissionActions.Read, OrgPermissionSubjects.Workspace]
| [GeneralPermissionActions, OrgPermissionSubjects.Role] | [OrgPermissionActions.Create, OrgPermissionSubjects.Workspace]
| [GeneralPermissionActions, OrgPermissionSubjects.Member] | [OrgPermissionActions, OrgPermissionSubjects.Role]
| [GeneralPermissionActions, OrgPermissionSubjects.Settings] | [OrgPermissionActions, OrgPermissionSubjects.Member]
| [GeneralPermissionActions, OrgPermissionSubjects.IncidentAccount] | [OrgPermissionActions, OrgPermissionSubjects.Settings]
| [GeneralPermissionActions, OrgPermissionSubjects.Sso] | [OrgPermissionActions, OrgPermissionSubjects.IncidentAccount]
| [GeneralPermissionActions, OrgPermissionSubjects.SecretScanning] | [OrgPermissionActions, OrgPermissionSubjects.Sso]
| [GeneralPermissionActions, OrgPermissionSubjects.Billing]; | [OrgPermissionActions, OrgPermissionSubjects.SecretScanning]
| [OrgPermissionActions, OrgPermissionSubjects.Billing];
const buildAdminPermission = () => { const buildAdminPermission = () => {
const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility); const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility);
// ws permissions // ws permissions
can(WorkspacePermissionActions.Read, OrgPermissionSubjects.Workspace); can(OrgPermissionActions.Read, OrgPermissionSubjects.Workspace);
can(WorkspacePermissionActions.Create, OrgPermissionSubjects.Workspace); can(OrgPermissionActions.Create, OrgPermissionSubjects.Workspace);
// role permission // role permission
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Role); can(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Role); can(OrgPermissionActions.Create, OrgPermissionSubjects.Role);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Role); can(OrgPermissionActions.Edit, OrgPermissionSubjects.Role);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Role); can(OrgPermissionActions.Delete, OrgPermissionSubjects.Role);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Member); can(OrgPermissionActions.Read, OrgPermissionSubjects.Member);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Member); can(OrgPermissionActions.Create, OrgPermissionSubjects.Member);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Member); can(OrgPermissionActions.Edit, OrgPermissionSubjects.Member);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Member); can(OrgPermissionActions.Delete, OrgPermissionSubjects.Member);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.SecretScanning); can(OrgPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.SecretScanning); can(OrgPermissionActions.Create, OrgPermissionSubjects.SecretScanning);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.SecretScanning); can(OrgPermissionActions.Edit, OrgPermissionSubjects.SecretScanning);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.SecretScanning); can(OrgPermissionActions.Delete, OrgPermissionSubjects.SecretScanning);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Settings); can(OrgPermissionActions.Read, OrgPermissionSubjects.Settings);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Settings); can(OrgPermissionActions.Create, OrgPermissionSubjects.Settings);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Settings); can(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Settings); can(OrgPermissionActions.Delete, OrgPermissionSubjects.Settings);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.IncidentAccount); can(OrgPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.IncidentAccount); can(OrgPermissionActions.Create, OrgPermissionSubjects.IncidentAccount);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.IncidentAccount); can(OrgPermissionActions.Edit, OrgPermissionSubjects.IncidentAccount);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.IncidentAccount); can(OrgPermissionActions.Delete, OrgPermissionSubjects.IncidentAccount);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Sso); can(OrgPermissionActions.Read, OrgPermissionSubjects.Sso);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Sso); can(OrgPermissionActions.Create, OrgPermissionSubjects.Sso);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Sso); can(OrgPermissionActions.Edit, OrgPermissionSubjects.Sso);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Sso); can(OrgPermissionActions.Delete, OrgPermissionSubjects.Sso);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Billing); can(OrgPermissionActions.Read, OrgPermissionSubjects.Billing);
can(GeneralPermissionActions.Create, OrgPermissionSubjects.Billing); can(OrgPermissionActions.Create, OrgPermissionSubjects.Billing);
can(GeneralPermissionActions.Edit, OrgPermissionSubjects.Billing); can(OrgPermissionActions.Edit, OrgPermissionSubjects.Billing);
can(GeneralPermissionActions.Delete, OrgPermissionSubjects.Billing); can(OrgPermissionActions.Delete, OrgPermissionSubjects.Billing);
return build(); return build();
}; };
@@ -86,15 +82,15 @@ export const adminPermissions = buildAdminPermission();
const buildMemberPermission = () => { const buildMemberPermission = () => {
const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility); const { can, build } = new AbilityBuilder<MongoAbility<OrgPermissionSet>>(createMongoAbility);
can(WorkspacePermissionActions.Read, OrgPermissionSubjects.Workspace); can(OrgPermissionActions.Read, OrgPermissionSubjects.Workspace);
can(WorkspacePermissionActions.Create, OrgPermissionSubjects.Workspace); can(OrgPermissionActions.Create, OrgPermissionSubjects.Workspace);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Member); can(OrgPermissionActions.Read, OrgPermissionSubjects.Member);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Role); can(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Settings); can(OrgPermissionActions.Read, OrgPermissionSubjects.Settings);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Billing); can(OrgPermissionActions.Read, OrgPermissionSubjects.Billing);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.Sso); can(OrgPermissionActions.Read, OrgPermissionSubjects.Sso);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.IncidentAccount); can(OrgPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
can(GeneralPermissionActions.Read, OrgPermissionSubjects.SecretScanning); can(OrgPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
return build(); return build();
}; };
@@ -1,3 +1,3 @@
export { OrgPermissionProvider, useOrgPermission } from "./OrgPermissionContext"; export { OrgPermissionProvider, useOrgPermission } from "./OrgPermissionContext";
export type { TOrgPermission } from "./types"; export type { TOrgPermission } from "./types";
export { GeneralPermissionActions,OrgPermissionSubjects } from "./types"; export { OrgPermissionActions, OrgPermissionSubjects } from "./types";
@@ -1,6 +1,6 @@
import { MongoAbility } from "@casl/ability"; import { MongoAbility } from "@casl/ability";
export enum GeneralPermissionActions { export enum OrgPermissionActions {
Read = "read", Read = "read",
Create = "create", Create = "create",
Edit = "edit", Edit = "edit",
@@ -19,14 +19,14 @@ export enum OrgPermissionSubjects {
} }
export type OrgPermissionSet = export type OrgPermissionSet =
| [GeneralPermissionActions.Create, OrgPermissionSubjects.Workspace] | [OrgPermissionActions.Create, OrgPermissionSubjects.Workspace]
| [GeneralPermissionActions.Read, OrgPermissionSubjects.Workspace] | [OrgPermissionActions.Read, OrgPermissionSubjects.Workspace]
| [GeneralPermissionActions, OrgPermissionSubjects.Role] | [OrgPermissionActions, OrgPermissionSubjects.Role]
| [GeneralPermissionActions, OrgPermissionSubjects.Member] | [OrgPermissionActions, OrgPermissionSubjects.Member]
| [GeneralPermissionActions, OrgPermissionSubjects.Settings] | [OrgPermissionActions, OrgPermissionSubjects.Settings]
| [GeneralPermissionActions, OrgPermissionSubjects.IncidentAccount] | [OrgPermissionActions, OrgPermissionSubjects.IncidentAccount]
| [GeneralPermissionActions, OrgPermissionSubjects.Sso] | [OrgPermissionActions, OrgPermissionSubjects.Sso]
| [GeneralPermissionActions, OrgPermissionSubjects.SecretScanning] | [OrgPermissionActions, OrgPermissionSubjects.SecretScanning]
| [GeneralPermissionActions, OrgPermissionSubjects.Billing]; | [OrgPermissionActions, OrgPermissionSubjects.Billing];
export type TOrgPermission = MongoAbility<OrgPermissionSet>; export type TOrgPermission = MongoAbility<OrgPermissionSet>;
+1 -1
View File
@@ -2,7 +2,7 @@ export { AuthProvider } from "./AuthContext";
export { OrgProvider, useOrganization } from "./OrganizationContext"; export { OrgProvider, useOrganization } from "./OrganizationContext";
export type { TOrgPermission } from "./OrgPermissionContext"; export type { TOrgPermission } from "./OrgPermissionContext";
export { export {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionProvider, OrgPermissionProvider,
OrgPermissionSubjects, OrgPermissionSubjects,
useOrgPermission useOrgPermission
@@ -1,7 +1,7 @@
import { useTranslation } from "react-i18next"; import { useTranslation } from "react-i18next";
import Head from "next/head"; import Head from "next/head";
import { GeneralPermissionActions, OrgPermissionSubjects, TOrgPermission } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, TOrgPermission } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { BillingSettingsPage } from "@app/views/Settings/BillingSettingsPage"; import { BillingSettingsPage } from "@app/views/Settings/BillingSettingsPage";
@@ -20,7 +20,7 @@ const SettingsBilling = withPermission<{}, TOrgPermission>(
</div> </div>
); );
}, },
{ action: GeneralPermissionActions.Delete, subject: OrgPermissionSubjects.Billing } { action: OrgPermissionActions.Delete, subject: OrgPermissionSubjects.Billing }
); );
Object.assign(SettingsBilling, { requireAuth: true }); Object.assign(SettingsBilling, { requireAuth: true });
+95 -89
View File
@@ -16,8 +16,8 @@ import {
faArrowUpRightFromSquare, faArrowUpRightFromSquare,
faCheck, faCheck,
faCheckCircle, faCheckCircle,
faExclamationCircle,
faClipboard, faClipboard,
faExclamationCircle,
faHandPeace, faHandPeace,
faMagnifyingGlass, faMagnifyingGlass,
faNetworkWired, faNetworkWired,
@@ -43,9 +43,8 @@ import {
Skeleton, Skeleton,
UpgradePlanModal UpgradePlanModal
} from "@app/components/v2"; } from "@app/components/v2";
import { useFetchServerStatus } from "@app/hooks/api/serverDetails";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
useSubscription, useSubscription,
useUser, useUser,
@@ -59,6 +58,7 @@ import {
useRegisterUserAction, useRegisterUserAction,
useUploadWsKey useUploadWsKey
} from "@app/hooks/api"; } from "@app/hooks/api";
import { useFetchServerStatus } from "@app/hooks/api/serverDetails";
import { usePopUp } from "@app/hooks/usePopUp"; import { usePopUp } from "@app/hooks/usePopUp";
import { encryptAssymmetric } from "../../../../components/utilities/cryptography/crypto"; import { encryptAssymmetric } from "../../../../components/utilities/cryptography/crypto";
@@ -473,82 +473,81 @@ const OrganizationPage = withPermission(
const { createNotification } = useNotificationContext(); const { createNotification } = useNotificationContext();
const addWsUser = useAddUserToWs(); const addWsUser = useAddUserToWs();
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([ const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
"addNewWs", "addNewWs",
"upgradePlan" "upgradePlan"
] as const); ] as const);
const { const {
control, control,
formState: { isSubmitting }, formState: { isSubmitting },
reset, reset,
handleSubmit handleSubmit
} = useForm<TAddProjectFormData>({ } = useForm<TAddProjectFormData>({
resolver: yupResolver(formSchema) resolver: yupResolver(formSchema)
}); });
const [hasUserClickedSlack, setHasUserClickedSlack] = useState(false); const [hasUserClickedSlack, setHasUserClickedSlack] = useState(false);
const [hasUserClickedIntro, setHasUserClickedIntro] = useState(false); const [hasUserClickedIntro, setHasUserClickedIntro] = useState(false);
const [hasUserPushedSecrets, setHasUserPushedSecrets] = useState(false); const [hasUserPushedSecrets, setHasUserPushedSecrets] = useState(false);
const [usersInOrg, setUsersInOrg] = useState(false); const [usersInOrg, setUsersInOrg] = useState(false);
const [searchFilter, setSearchFilter] = useState(""); const [searchFilter, setSearchFilter] = useState("");
const createWs = useCreateWorkspace(); const createWs = useCreateWorkspace();
const { user } = useUser(); const { user } = useUser();
const uploadWsKey = useUploadWsKey(); const uploadWsKey = useUploadWsKey();
const { data: serverDetails } = useFetchServerStatus(); const { data: serverDetails } = useFetchServerStatus();
const onCreateProject = async ({ name, addMembers }: TAddProjectFormData) => { const onCreateProject = async ({ name, addMembers }: TAddProjectFormData) => {
// type check // type check
if (!currentOrg) return; if (!currentOrg) return;
try { try {
const { const {
data: { data: {
workspace: { _id: newWorkspaceId } workspace: { _id: newWorkspaceId }
} }
} = await createWs.mutateAsync({ } = await createWs.mutateAsync({
organizationId: currentOrg, organizationId: currentOrg,
workspaceName: name workspaceName: name
});
const randomBytes = crypto.randomBytes(16).toString("hex");
const PRIVATE_KEY = String(localStorage.getItem("PRIVATE_KEY"));
const { ciphertext, nonce } = encryptAssymmetric({
plaintext: randomBytes,
publicKey: user.publicKey,
privateKey: PRIVATE_KEY
});
await uploadWsKey.mutateAsync({
encryptedKey: ciphertext,
nonce,
userId: user?._id,
workspaceId: newWorkspaceId
});
if (addMembers) {
// not using hooks because need at this point only
const orgUsers = await fetchOrgUsers(currentOrg);
orgUsers.forEach(({ status, user: orgUser }) => {
// skip if status of org user is not accepted
// this orgUser is the person who created the ws
if (status !== "accepted" || user.email === orgUser.email) return;
addWsUser.mutate({ email: orgUser.email, workspaceId: newWorkspaceId });
}); });
const randomBytes = crypto.randomBytes(16).toString("hex");
const PRIVATE_KEY = String(localStorage.getItem("PRIVATE_KEY"));
const { ciphertext, nonce } = encryptAssymmetric({
plaintext: randomBytes,
publicKey: user.publicKey,
privateKey: PRIVATE_KEY
});
await uploadWsKey.mutateAsync({
encryptedKey: ciphertext,
nonce,
userId: user?._id,
workspaceId: newWorkspaceId
});
if (addMembers) {
// not using hooks because need at this point only
const orgUsers = await fetchOrgUsers(currentOrg);
orgUsers.forEach(({ status, user: orgUser }) => {
// skip if status of org user is not accepted
// this orgUser is the person who created the ws
if (status !== "accepted" || user.email === orgUser.email) return;
addWsUser.mutate({ email: orgUser.email, workspaceId: newWorkspaceId });
});
}
createNotification({ text: "Workspace created", type: "success" });
handlePopUpClose("addNewWs");
router.push(`/project/${newWorkspaceId}/secrets/overview`);
} catch (err) {
console.error(err);
createNotification({ text: "Failed to create workspace", type: "error" });
} }
createNotification({ text: "Workspace created", type: "success" }); };
handlePopUpClose("addNewWs");
router.push(`/project/${newWorkspaceId}/secrets/overview`);
} catch (err) {
console.error(err);
createNotification({ text: "Failed to create workspace", type: "error" });
}
};
const { subscription } = useSubscription(); const { subscription } = useSubscription();
const isAddingProjectsAllowed = subscription?.workspaceLimit const isAddingProjectsAllowed = subscription?.workspaceLimit
? subscription.workspacesUsed < subscription.workspaceLimit ? subscription.workspacesUsed < subscription.workspaceLimit
: true; : true;
useEffect(() => { useEffect(() => {
onboardingCheck({ onboardingCheck({
@@ -567,18 +566,28 @@ const OrganizationPage = withPermission(
<title>{t("common.head-title", { title: t("settings.members.title") })}</title> <title>{t("common.head-title", { title: t("settings.members.title") })}</title>
<link rel="icon" href="/infisical.ico" /> <link rel="icon" href="/infisical.ico" />
</Head> </Head>
{!serverDetails?.redisConfigured && <div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl"> {!serverDetails?.redisConfigured && (
<p className="mr-4 mb-4 font-semibold text-white">Announcements</p> <div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl">
<div className="w-full border border-blue-400/70 rounded-md bg-blue-900/70 p-2 text-base text-mineshaft-100 flex items-center"> <p className="mr-4 mb-4 font-semibold text-white">Announcements</p>
<FontAwesomeIcon icon={faExclamationCircle} className="text-2xl mr-4 p-4 text-mineshaft-50"/> <div className="w-full border border-blue-400/70 rounded-md bg-blue-900/70 p-2 text-base text-mineshaft-100 flex items-center">
Attention: Updated versions of Infisical now require Redis for full functionality. Learn how to configure it <FontAwesomeIcon
<Link href="https://infisical.com/docs/self-hosting/configuration/redis" target="_blank"> icon={faExclamationCircle}
<span className="pl-1 text-white underline underline-offset-2 hover:decoration-blue-400 hover:text-blue-200 duration-100 cursor-pointer"> className="text-2xl mr-4 p-4 text-mineshaft-50"
here />
</span> Attention: Updated versions of Infisical now require Redis for full functionality.
</Link>. Learn how to configure it
<Link
href="https://infisical.com/docs/self-hosting/configuration/redis"
target="_blank"
>
<span className="pl-1 text-white underline underline-offset-2 hover:decoration-blue-400 hover:text-blue-200 duration-100 cursor-pointer">
here
</span>
</Link>
.
</div>
</div> </div>
</div>} )}
<div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl"> <div className="mb-4 flex flex-col items-start justify-start px-6 py-6 pb-0 text-3xl">
<p className="mr-4 font-semibold text-white">Projects</p> <p className="mr-4 font-semibold text-white">Projects</p>
<div className="mt-6 flex w-full flex-row"> <div className="mt-6 flex w-full flex-row">
@@ -589,10 +598,7 @@ const OrganizationPage = withPermission(
onChange={(e) => setSearchFilter(e.target.value)} onChange={(e) => setSearchFilter(e.target.value)}
leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />} leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />}
/> />
<OrgPermissionCan <OrgPermissionCan I={OrgPermissionActions.Create} an={OrgPermissionSubjects.Workspace}>
I={GeneralPermissionActions.Create}
an={OrgPermissionSubjects.Workspace}
>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
isDisabled={!isAllowed} isDisabled={!isAllowed}
@@ -877,7 +883,7 @@ const OrganizationPage = withPermission(
); );
}, },
{ {
action: GeneralPermissionActions.Read, action: OrgPermissionActions.Read,
subject: OrgPermissionSubjects.Workspace subject: OrgPermissionSubjects.Workspace
} }
); );
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button } from "@app/components/v2"; import { Button } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { SecretScanningLogsTable } from "@app/views/SecretScanning/components"; import { SecretScanningLogsTable } from "@app/views/SecretScanning/components";
@@ -101,7 +101,7 @@ const SecretScanning = withPermission(
) : ( ) : (
<div className="flex items-center h-[3.25rem]"> <div className="flex items-center h-[3.25rem]">
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Create} I={OrgPermissionActions.Create}
a={OrgPermissionSubjects.SecretScanning} a={OrgPermissionSubjects.SecretScanning}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -125,7 +125,7 @@ const SecretScanning = withPermission(
</div> </div>
); );
}, },
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.SecretScanning } { action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.SecretScanning }
); );
Object.assign(SecretScanning, { requireAuth: true }); Object.assign(SecretScanning, { requireAuth: true });
@@ -3,7 +3,7 @@ import { useTranslation } from "react-i18next";
import { motion } from "framer-motion"; import { motion } from "framer-motion";
import { Tab, TabList, TabPanel, Tabs } from "@app/components/v2"; import { Tab, TabList, TabPanel, Tabs } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { useGetRoles } from "@app/hooks/api"; import { useGetRoles } from "@app/hooks/api";
import { TRole } from "@app/hooks/api/roles/types"; import { TRole } from "@app/hooks/api/roles/types";
@@ -59,5 +59,5 @@ export const MembersPage = withPermission(
</div> </div>
); );
}, },
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.Member } { action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Member }
); );
@@ -43,7 +43,7 @@ import {
UpgradePlanModal UpgradePlanModal
} from "@app/components/v2"; } from "@app/components/v2";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
useOrganization, useOrganization,
useSubscription, useSubscription,
@@ -305,7 +305,7 @@ export const OrgMembersTable = ({ roles = [] }: Props) => {
placeholder="Search members..." placeholder="Search members..."
/> />
</div> </div>
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Member}> <OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Member}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
isDisabled={!isAllowed} isDisabled={!isAllowed}
@@ -359,7 +359,7 @@ export const OrgMembersTable = ({ roles = [] }: Props) => {
<Td>{email}</Td> <Td>{email}</Td>
<Td> <Td>
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Edit} I={OrgPermissionActions.Edit}
a={OrgPermissionSubjects.Member} a={OrgPermissionSubjects.Member}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -453,7 +453,7 @@ export const OrgMembersTable = ({ roles = [] }: Props) => {
<Td> <Td>
{userId !== u?._id && ( {userId !== u?._id && (
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Delete} I={OrgPermissionActions.Delete}
a={OrgPermissionSubjects.Member} a={OrgPermissionSubjects.Member}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -1,7 +1,7 @@
import { useEffect, useState } from "react"; import { useEffect, useState } from "react";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
import updateRiskStatus, { RiskStatus } from "@app/pages/api/secret-scanning/updateRiskStatus"; import updateRiskStatus, { RiskStatus } from "@app/pages/api/secret-scanning/updateRiskStatus";
export const RiskStatusSelection = ({ export const RiskStatusSelection = ({
@@ -26,7 +26,7 @@ export const RiskStatusSelection = ({
}, [selectedRiskStatus]); }, [selectedRiskStatus]);
return ( return (
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.SecretScanning}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.SecretScanning}>
{(isAllowed) => ( {(isAllowed) => (
<select <select
disabled={!isAllowed} disabled={!isAllowed}
@@ -1,7 +1,7 @@
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button } from "@app/components/v2"; import { Button } from "@app/components/v2";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
useOrganization, useOrganization,
useSubscription useSubscription
@@ -81,7 +81,7 @@ export const PreviewSection = () => {
Unlimited members, projects, RBAC, smart alerts, and so much more Unlimited members, projects, RBAC, smart alerts, and so much more
</p> </p>
</div> </div>
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Billing}> <OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Billing}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
onClick={() => handleUpgradeBtnClick()} onClick={() => handleUpgradeBtnClick()}
@@ -103,7 +103,7 @@ export const PreviewSection = () => {
subscription.status === "trialing" ? "(Trial)" : "" subscription.status === "trialing" ? "(Trial)" : ""
}`} }`}
</p> </p>
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
{(isAllowed) => ( {(isAllowed) => (
<button <button
type="button" type="button"
@@ -6,7 +6,7 @@ import * as yup from "yup";
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider"; import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button, FormControl, Input } from "@app/components/v2"; import { Button, FormControl, Input } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api"; import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api";
const schema = yup const schema = yup
@@ -75,7 +75,7 @@ export const CompanyNameSection = () => {
name="name" name="name"
/> />
</div> </div>
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
type="submit" type="submit"
@@ -6,7 +6,7 @@ import * as yup from "yup";
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider"; import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button, FormControl, Input } from "@app/components/v2"; import { Button, FormControl, Input } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api"; import { useGetOrgBillingDetails, useUpdateOrgBillingDetails } from "@app/hooks/api";
const schema = yup const schema = yup
@@ -76,7 +76,7 @@ export const InvoiceEmailSection = () => {
name="email" name="email"
/> />
</div> </div>
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
type="submit" type="submit"
@@ -3,7 +3,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button } from "@app/components/v2"; import { Button } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { useAddOrgPmtMethod } from "@app/hooks/api"; import { useAddOrgPmtMethod } from "@app/hooks/api";
import { PmtMethodsTable } from "./PmtMethodsTable"; import { PmtMethodsTable } from "./PmtMethodsTable";
@@ -27,7 +27,7 @@ export const PmtMethodsSection = () => {
<div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600"> <div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600">
<div className="flex items-center mb-8"> <div className="flex items-center mb-8">
<h2 className="text-xl font-semibold flex-1 text-white">Payment methods</h2> <h2 className="text-xl font-semibold flex-1 text-white">Payment methods</h2>
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Billing}> <OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Billing}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
onClick={handleAddPmtMethodBtnClick} onClick={handleAddPmtMethodBtnClick}
@@ -14,7 +14,7 @@ import {
THead, THead,
Tr Tr
} from "@app/components/v2"; } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { useDeleteOrgPmtMethod, useGetOrgPmtMethods } from "@app/hooks/api"; import { useDeleteOrgPmtMethod, useGetOrgPmtMethods } from "@app/hooks/api";
export const PmtMethodsTable = () => { export const PmtMethodsTable = () => {
@@ -54,7 +54,7 @@ export const PmtMethodsTable = () => {
<Td>{`${exp_month}/${exp_year}`}</Td> <Td>{`${exp_month}/${exp_year}`}</Td>
<Td> <Td>
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Delete} I={OrgPermissionActions.Delete}
a={OrgPermissionSubjects.Billing} a={OrgPermissionSubjects.Billing}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -3,7 +3,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button } from "@app/components/v2"; import { Button } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
import { usePopUp } from "@app/hooks/usePopUp"; import { usePopUp } from "@app/hooks/usePopUp";
import { TaxIDModal } from "./TaxIDModal"; import { TaxIDModal } from "./TaxIDModal";
@@ -18,7 +18,7 @@ export const TaxIDSection = () => {
<div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600"> <div className="p-4 bg-mineshaft-900 mb-6 rounded-lg border border-mineshaft-600">
<div className="flex items-center mb-8"> <div className="flex items-center mb-8">
<h2 className="text-xl font-semibold flex-1 text-white">Tax ID</h2> <h2 className="text-xl font-semibold flex-1 text-white">Tax ID</h2>
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Billing}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Billing}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
onClick={() => handlePopUpOpen("addTaxID")} onClick={() => handlePopUpOpen("addTaxID")}
@@ -14,7 +14,7 @@ import {
THead, THead,
Tr Tr
} from "@app/components/v2"; } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { useDeleteOrgTaxId, useGetOrgTaxIds } from "@app/hooks/api"; import { useDeleteOrgTaxId, useGetOrgTaxIds } from "@app/hooks/api";
const taxIDTypeLabelMap: { [key: string]: string } = { const taxIDTypeLabelMap: { [key: string]: string } = {
@@ -103,7 +103,7 @@ export const TaxIDTable = () => {
<Td>{value}</Td> <Td>{value}</Td>
<Td> <Td>
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Delete} I={OrgPermissionActions.Delete}
a={OrgPermissionSubjects.Billing} a={OrgPermissionSubjects.Billing}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -1,7 +1,7 @@
import { Fragment } from "react"; import { Fragment } from "react";
import { Tab } from "@headlessui/react"; import { Tab } from "@headlessui/react";
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { BillingCloudTab } from "../BillingCloudTab"; import { BillingCloudTab } from "../BillingCloudTab";
@@ -53,5 +53,5 @@ export const BillingTabGroup = withPermission(
</Tab.Group> </Tab.Group>
); );
}, },
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.Billing } { action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Billing }
); );
@@ -1,4 +1,4 @@
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { OrgSSOSection } from "./OrgSSOSection"; import { OrgSSOSection } from "./OrgSSOSection";
@@ -11,5 +11,5 @@ export const OrgAuthTab = withPermission(
</div> </div>
); );
}, },
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.Sso } { action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Sso }
); );
@@ -5,7 +5,7 @@ import { useNotificationContext } from "@app/components/context/Notifications/No
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button, Switch, UpgradePlanModal } from "@app/components/v2"; import { Button, Switch, UpgradePlanModal } from "@app/components/v2";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
useOrganization, useOrganization,
useSubscription useSubscription
@@ -86,7 +86,7 @@ export const OrgSSOSection = (): JSX.Element => {
<div className="flex items-center mb-8"> <div className="flex items-center mb-8">
<h2 className="text-xl font-semibold flex-1 text-white">SAML SSO Configuration</h2> <h2 className="text-xl font-semibold flex-1 text-white">SAML SSO Configuration</h2>
{!isLoading && ( {!isLoading && (
<OrgPermissionCan I={GeneralPermissionActions.Create} a={OrgPermissionSubjects.Sso}> <OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Sso}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
onClick={addSSOBtnClick} onClick={addSSOBtnClick}
@@ -102,7 +102,7 @@ export const OrgSSOSection = (): JSX.Element => {
</div> </div>
{data && ( {data && (
<div className="mb-4"> <div className="mb-4">
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Sso}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
{(isAllowed) => ( {(isAllowed) => (
<Switch <Switch
id="enable-saml-sso" id="enable-saml-sso"
@@ -4,7 +4,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button } from "@app/components/v2"; import { Button } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { usePopUp } from "@app/hooks"; import { usePopUp } from "@app/hooks";
@@ -25,7 +25,7 @@ export const OrgIncidentContactsSection = withPermission(
{t("section.incident.incident-contacts")} {t("section.incident.incident-contacts")}
</p> </p>
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Create} I={OrgPermissionActions.Create}
a={OrgPermissionSubjects.IncidentAccount} a={OrgPermissionSubjects.IncidentAccount}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -50,5 +50,5 @@ export const OrgIncidentContactsSection = withPermission(
</div> </div>
); );
}, },
{ action: GeneralPermissionActions.Read, subject: OrgPermissionSubjects.IncidentAccount } { action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.IncidentAccount }
); );
@@ -18,7 +18,7 @@ import {
THead, THead,
Tr Tr
} from "@app/components/v2"; } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { usePopUp } from "@app/hooks"; import { usePopUp } from "@app/hooks";
import { useDeleteIncidentContact, useGetOrgIncidentContact } from "@app/hooks/api"; import { useDeleteIncidentContact, useGetOrgIncidentContact } from "@app/hooks/api";
@@ -85,7 +85,7 @@ export const OrgIncidentContactsTable = () => {
<Td className="w-full">{email}</Td> <Td className="w-full">{email}</Td>
<Td className="mr-4"> <Td className="mr-4">
<OrgPermissionCan <OrgPermissionCan
I={GeneralPermissionActions.Delete} I={OrgPermissionActions.Delete}
an={OrgPermissionSubjects.IncidentAccount} an={OrgPermissionSubjects.IncidentAccount}
> >
{(isAllowed) => ( {(isAllowed) => (
@@ -6,7 +6,7 @@ import * as yup from "yup";
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider"; import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
import { OrgPermissionCan } from "@app/components/permissions"; import { OrgPermissionCan } from "@app/components/permissions";
import { Button, FormControl, Input } from "@app/components/v2"; import { Button, FormControl, Input } from "@app/components/v2";
import { GeneralPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context"; import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
import { withPermission } from "@app/hoc"; import { withPermission } from "@app/hoc";
import { useRenameOrg } from "@app/hooks/api"; import { useRenameOrg } from "@app/hooks/api";
@@ -68,7 +68,7 @@ export const OrgNameChangeSection = withPermission(
name="name" name="name"
/> />
</div> </div>
<OrgPermissionCan I={GeneralPermissionActions.Edit} a={OrgPermissionSubjects.Settings}> <OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Settings}>
{(isAllowed) => ( {(isAllowed) => (
<Button <Button
isLoading={isLoading} isLoading={isLoading}
@@ -85,7 +85,7 @@ export const OrgNameChangeSection = withPermission(
); );
}, },
{ {
action: GeneralPermissionActions.Read, action: OrgPermissionActions.Read,
subject: OrgPermissionSubjects.Settings, subject: OrgPermissionSubjects.Settings,
containerClassName: "mb-4" containerClassName: "mb-4"
} }
@@ -35,7 +35,7 @@ import {
Tr Tr
} from "@app/components/v2"; } from "@app/components/v2";
import { import {
GeneralPermissionActions, OrgPermissionActions,
OrgPermissionSubjects, OrgPermissionSubjects,
useOrganization, useOrganization,
useWorkspace useWorkspace
@@ -382,7 +382,7 @@ export const OrgServiceAccountsTable = withPermission(
); );
}, },
{ {
action: GeneralPermissionActions.Read, action: OrgPermissionActions.Read,
subject: OrgPermissionSubjects.Settings, subject: OrgPermissionSubjects.Settings,
containerClassName: "mb-4" containerClassName: "mb-4"
} }