mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 18:27:36 +00:00
fix: moved away from keystore since its not needed
This commit is contained in:
@@ -7,7 +7,11 @@ import {
|
|||||||
TScanFullRepoEventPayload,
|
TScanFullRepoEventPayload,
|
||||||
TScanPushEventPayload
|
TScanPushEventPayload
|
||||||
} from "@app/ee/services/secret-scanning/secret-scanning-queue/secret-scanning-queue-types";
|
} from "@app/ee/services/secret-scanning/secret-scanning-queue/secret-scanning-queue-types";
|
||||||
import { TIntegrationSyncPayload, TSyncSecretsDTO } from "@app/services/secret/secret-types";
|
import {
|
||||||
|
TFailedIntegrationSyncEmailsPayload,
|
||||||
|
TIntegrationSyncPayload,
|
||||||
|
TSyncSecretsDTO
|
||||||
|
} from "@app/services/secret/secret-types";
|
||||||
|
|
||||||
export enum QueueName {
|
export enum QueueName {
|
||||||
SecretRotation = "secret-rotation",
|
SecretRotation = "secret-rotation",
|
||||||
@@ -107,11 +111,7 @@ export type TQueueJobTypes = {
|
|||||||
}
|
}
|
||||||
| {
|
| {
|
||||||
name: QueueJobs.SendFailedIntegrationSyncEmails;
|
name: QueueJobs.SendFailedIntegrationSyncEmails;
|
||||||
payload: {
|
payload: TFailedIntegrationSyncEmailsPayload;
|
||||||
projectId: string;
|
|
||||||
environmentSlug: string;
|
|
||||||
secretPath: string;
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
[QueueName.SecretFullRepoScan]: {
|
[QueueName.SecretFullRepoScan]: {
|
||||||
name: QueueJobs.SecretScan;
|
name: QueueJobs.SecretScan;
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ import { TSnapshotSecretV2DALFactory } from "@app/ee/services/secret-snapshot/sn
|
|||||||
import { KeyStorePrefixes, KeyStoreTtls, TKeyStoreFactory } from "@app/keystore/keystore";
|
import { KeyStorePrefixes, KeyStoreTtls, TKeyStoreFactory } from "@app/keystore/keystore";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { decryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
import { decryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
|
||||||
import { applyJitter, daysToMillisecond, secondsToMillis } from "@app/lib/dates";
|
import { daysToMillisecond, secondsToMillis } from "@app/lib/dates";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { getTimeDifferenceInSeconds, groupBy, isSamePath, unique } from "@app/lib/fn";
|
import { getTimeDifferenceInSeconds, groupBy, isSamePath, unique } from "@app/lib/fn";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
@@ -55,7 +55,6 @@ import { fnTriggerWebhook } from "../webhook/webhook-fns";
|
|||||||
import { TSecretDALFactory } from "./secret-dal";
|
import { TSecretDALFactory } from "./secret-dal";
|
||||||
import { interpolateSecrets } from "./secret-fns";
|
import { interpolateSecrets } from "./secret-fns";
|
||||||
import {
|
import {
|
||||||
FailedIntegrationSyncEmailsPayloadSchema,
|
|
||||||
TCreateSecretReminderDTO,
|
TCreateSecretReminderDTO,
|
||||||
TFailedIntegrationSyncEmailsPayload,
|
TFailedIntegrationSyncEmailsPayload,
|
||||||
THandleReminderDTO,
|
THandleReminderDTO,
|
||||||
@@ -519,35 +518,16 @@ export const secretQueueFactory = ({
|
|||||||
};
|
};
|
||||||
|
|
||||||
const sendFailedIntegrationSyncEmails = async (payload: TFailedIntegrationSyncEmailsPayload) => {
|
const sendFailedIntegrationSyncEmails = async (payload: TFailedIntegrationSyncEmailsPayload) => {
|
||||||
const key = KeyStorePrefixes.SendFailedIntegrationSyncEmails(
|
const appCfg = getConfig();
|
||||||
payload.projectId,
|
if (!appCfg.isSmtpConfigured) return;
|
||||||
payload.secretPath,
|
|
||||||
payload.environmentSlug
|
|
||||||
);
|
|
||||||
|
|
||||||
await keyStore.setItemWithExpiry(
|
await queueService.queue(QueueName.IntegrationSync, QueueJobs.SendFailedIntegrationSyncEmails, payload, {
|
||||||
key,
|
jobId: `send-failed-integration-sync-emails-${payload.projectId}-${payload.secretPath}-${payload.environmentSlug}`,
|
||||||
KeyStoreTtls.SendFailedIntegrationSyncEmailsInSeconds,
|
delay: 1_000 * 60, // 1 minute
|
||||||
JSON.stringify(payload)
|
|
||||||
);
|
removeOnFail: true,
|
||||||
await queueService.queue(
|
removeOnComplete: true
|
||||||
QueueName.IntegrationSync,
|
});
|
||||||
QueueJobs.SendFailedIntegrationSyncEmails,
|
|
||||||
{
|
|
||||||
secretPath: payload.secretPath,
|
|
||||||
projectId: payload.projectId,
|
|
||||||
environmentSlug: payload.environmentSlug
|
|
||||||
},
|
|
||||||
{
|
|
||||||
delay: applyJitter(
|
|
||||||
secondsToMillis(KeyStoreTtls.SendFailedIntegrationSyncEmailsInSeconds / 2),
|
|
||||||
secondsToMillis(10)
|
|
||||||
),
|
|
||||||
jobId: key,
|
|
||||||
removeOnFail: true,
|
|
||||||
removeOnComplete: true
|
|
||||||
}
|
|
||||||
);
|
|
||||||
};
|
};
|
||||||
|
|
||||||
queueService.start(QueueName.SecretSync, async (job) => {
|
queueService.start(QueueName.SecretSync, async (job) => {
|
||||||
@@ -598,36 +578,16 @@ export const secretQueueFactory = ({
|
|||||||
if (job.name === QueueJobs.SendFailedIntegrationSyncEmails) {
|
if (job.name === QueueJobs.SendFailedIntegrationSyncEmails) {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
|
|
||||||
// If smtp is not configured, we can return early
|
const jobPayload = job.data as TFailedIntegrationSyncEmailsPayload;
|
||||||
if (!appCfg.isSmtpConfigured) return;
|
|
||||||
|
|
||||||
const jobPayload = job.data as Pick<
|
const projectMembers = await projectMembershipDAL.findAllProjectMembers(jobPayload.projectId);
|
||||||
TFailedIntegrationSyncEmailsPayload,
|
const project = await projectDAL.findById(jobPayload.projectId);
|
||||||
"projectId" | "secretPath" | "environmentSlug"
|
|
||||||
>;
|
|
||||||
|
|
||||||
const failedIntegrationsDetails = await keyStore.getItem(
|
|
||||||
KeyStorePrefixes.SendFailedIntegrationSyncEmails(
|
|
||||||
jobPayload.projectId,
|
|
||||||
jobPayload.secretPath,
|
|
||||||
jobPayload.environmentSlug
|
|
||||||
)
|
|
||||||
);
|
|
||||||
|
|
||||||
if (!failedIntegrationsDetails) return;
|
|
||||||
|
|
||||||
const failedSyncKeyStore = FailedIntegrationSyncEmailsPayloadSchema.parse(JSON.parse(failedIntegrationsDetails));
|
|
||||||
|
|
||||||
const projectMembers = await projectMembershipDAL.findAllProjectMembers(failedSyncKeyStore.projectId);
|
|
||||||
const project = await projectDAL.findById(failedSyncKeyStore.projectId);
|
|
||||||
|
|
||||||
// Only send emails to admins, and if its a manual trigger, only send it to the person who triggered it (if actor is admin as well)
|
// Only send emails to admins, and if its a manual trigger, only send it to the person who triggered it (if actor is admin as well)
|
||||||
const filteredProjectMembers = projectMembers
|
const filteredProjectMembers = projectMembers
|
||||||
.filter((member) => member.roles.some((role) => role.role === ProjectMembershipRole.Admin))
|
.filter((member) => member.roles.some((role) => role.role === ProjectMembershipRole.Admin))
|
||||||
.filter((member) =>
|
.filter((member) =>
|
||||||
failedSyncKeyStore.manuallyTriggeredByUserId
|
jobPayload.manuallyTriggeredByUserId ? member.userId === jobPayload.manuallyTriggeredByUserId : true
|
||||||
? member.userId === failedSyncKeyStore.manuallyTriggeredByUserId
|
|
||||||
: true
|
|
||||||
);
|
);
|
||||||
|
|
||||||
await smtpService.sendMail({
|
await smtpService.sendMail({
|
||||||
@@ -635,10 +595,10 @@ export const secretQueueFactory = ({
|
|||||||
template: SmtpTemplates.IntegrationSyncFailed,
|
template: SmtpTemplates.IntegrationSyncFailed,
|
||||||
subjectLine: `Integration Sync Failed`,
|
subjectLine: `Integration Sync Failed`,
|
||||||
substitutions: {
|
substitutions: {
|
||||||
syncMessage: failedSyncKeyStore.count === 1 ? failedSyncKeyStore.syncMessage : undefined, // We are only displaying the sync message if its a singular integration, so we can just grab the first one in the array.
|
syncMessage: jobPayload.count === 1 ? jobPayload.syncMessage : undefined, // We are only displaying the sync message if its a singular integration, so we can just grab the first one in the array.
|
||||||
secretPath: failedSyncKeyStore.secretPath,
|
secretPath: jobPayload.secretPath,
|
||||||
environment: failedSyncKeyStore.environmentName,
|
environment: jobPayload.environmentName,
|
||||||
count: failedSyncKeyStore.count,
|
count: jobPayload.count,
|
||||||
projectName: project.name,
|
projectName: project.name,
|
||||||
integrationUrl: `${appCfg.SITE_URL}/integrations/${project.id}`
|
integrationUrl: `${appCfg.SITE_URL}/integrations/${project.id}`
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user