mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 17:29:00 +00:00
ca relation removal migration
This commit is contained in:
@@ -1,16 +0,0 @@
|
|||||||
import { Knex } from "knex";
|
|
||||||
|
|
||||||
import { TableName } from "../schemas";
|
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
|
||||||
if (await knex.schema.hasTable(TableName.Certificate)) {
|
|
||||||
await knex.schema.alterTable(TableName.Certificate, (t) => {
|
|
||||||
t.uuid("caId").nullable().alter();
|
|
||||||
t.uuid("caCertId").nullable().alter();
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function down(): Promise<void> {
|
|
||||||
// Altering back to nullable will fail
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
if (await knex.schema.hasTable(TableName.Certificate)) {
|
||||||
|
await knex.schema.alterTable(TableName.Certificate, (t) => {
|
||||||
|
t.uuid("caId").nullable().alter();
|
||||||
|
t.uuid("caCertId").nullable().alter();
|
||||||
|
});
|
||||||
|
|
||||||
|
const hasProjectIdColumn = await knex.schema.hasColumn(TableName.Certificate, "projectId");
|
||||||
|
if (!hasProjectIdColumn) {
|
||||||
|
await knex.transaction(async (trx) => {
|
||||||
|
await trx.schema.alterTable(TableName.Certificate, (t) => {
|
||||||
|
t.string("projectId", 36).nullable();
|
||||||
|
t.foreign("projectId").references("id").inTable(TableName.Project).onDelete("CASCADE");
|
||||||
|
});
|
||||||
|
|
||||||
|
await trx.raw(`
|
||||||
|
UPDATE "${TableName.Certificate}" cert
|
||||||
|
SET "projectId" = ca."projectId"
|
||||||
|
FROM "${TableName.CertificateAuthority}" ca
|
||||||
|
WHERE cert."caId" = ca.id
|
||||||
|
`);
|
||||||
|
|
||||||
|
await trx.schema.alterTable(TableName.Certificate, (t) => {
|
||||||
|
t.string("projectId").notNullable().alter();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
if (await knex.schema.hasTable(TableName.Certificate)) {
|
||||||
|
if (await knex.schema.hasColumn(TableName.Certificate, "projectId")) {
|
||||||
|
await knex.schema.alterTable(TableName.Certificate, (t) => {
|
||||||
|
t.dropForeign("projectId");
|
||||||
|
t.dropColumn("projectId");
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Altering back to notNullable for caId and caCertId will fail
|
||||||
|
}
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
import { Knex } from "knex";
|
|
||||||
|
|
||||||
import { TableName } from "../schemas";
|
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
|
||||||
if (await knex.schema.hasTable(TableName.CertificateBody)) {
|
|
||||||
await knex.schema.alterTable(TableName.CertificateBody, (t) => {
|
|
||||||
t.binary("encryptedCertificateChain").nullable();
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!(await knex.schema.hasTable(TableName.CertificateSecret))) {
|
|
||||||
await knex.schema.createTable(TableName.CertificateSecret, (t) => {
|
|
||||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
|
||||||
t.timestamps(true, true, true);
|
|
||||||
t.uuid("certId").notNullable().unique();
|
|
||||||
t.foreign("certId").references("id").inTable(TableName.Certificate).onDelete("CASCADE");
|
|
||||||
t.binary("encryptedPrivateKey").notNullable();
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
|
||||||
if (await knex.schema.hasTable(TableName.CertificateSecret)) {
|
|
||||||
await knex.schema.dropTable(TableName.CertificateSecret);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (await knex.schema.hasTable(TableName.CertificateBody)) {
|
|
||||||
await knex.schema.alterTable(TableName.CertificateBody, (t) => {
|
|
||||||
t.dropColumn("encryptedCertificateChain");
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
import { Knex } from "knex";
|
|
||||||
|
|
||||||
import { TableName } from "../schemas";
|
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
|
||||||
if (await knex.schema.hasTable(TableName.Certificate)) {
|
|
||||||
await knex.schema.alterTable(TableName.Certificate, (t) => {
|
|
||||||
t.uuid("projectId").notNullable();
|
|
||||||
t.foreign("projectId").references("id").inTable(TableName.Certificate).onDelete("CASCADE");
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
|
||||||
// .. tbd
|
|
||||||
}
|
|
||||||
@@ -14,8 +14,7 @@ export const CertificateBodiesSchema = z.object({
|
|||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
updatedAt: z.date(),
|
updatedAt: z.date(),
|
||||||
certId: z.string().uuid(),
|
certId: z.string().uuid(),
|
||||||
encryptedCertificate: zodBuffer,
|
encryptedCertificate: zodBuffer
|
||||||
encryptedCertificateChain: zodBuffer.nullable().optional()
|
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TCertificateBodies = z.infer<typeof CertificateBodiesSchema>;
|
export type TCertificateBodies = z.infer<typeof CertificateBodiesSchema>;
|
||||||
|
|||||||
@@ -24,7 +24,8 @@ export const CertificatesSchema = z.object({
|
|||||||
caCertId: z.string().uuid().nullable().optional(),
|
caCertId: z.string().uuid().nullable().optional(),
|
||||||
certificateTemplateId: z.string().uuid().nullable().optional(),
|
certificateTemplateId: z.string().uuid().nullable().optional(),
|
||||||
keyUsages: z.string().array().nullable().optional(),
|
keyUsages: z.string().array().nullable().optional(),
|
||||||
extendedKeyUsages: z.string().array().nullable().optional()
|
extendedKeyUsages: z.string().array().nullable().optional(),
|
||||||
|
projectId: z.string()
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TCertificates = z.infer<typeof CertificatesSchema>;
|
export type TCertificates = z.infer<typeof CertificatesSchema>;
|
||||||
|
|||||||
Reference in New Issue
Block a user