mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 00:27:35 +00:00
misc: added license checks for external kms management
This commit is contained in:
@@ -6,6 +6,7 @@ import { alphaNumericNanoId } from "@app/lib/nanoid";
|
|||||||
import { TKmsKeyDALFactory } from "@app/services/kms/kms-key-dal";
|
import { TKmsKeyDALFactory } from "@app/services/kms/kms-key-dal";
|
||||||
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||||
|
|
||||||
|
import { TLicenseServiceFactory } from "../license/license-service";
|
||||||
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
|
import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission";
|
||||||
import { TPermissionServiceFactory } from "../permission/permission-service";
|
import { TPermissionServiceFactory } from "../permission/permission-service";
|
||||||
import { TExternalKmsDALFactory } from "./external-kms-dal";
|
import { TExternalKmsDALFactory } from "./external-kms-dal";
|
||||||
@@ -28,6 +29,7 @@ type TExternalKmsServiceFactoryDep = {
|
|||||||
>;
|
>;
|
||||||
kmsDAL: Pick<TKmsKeyDALFactory, "create" | "updateById" | "findById" | "deleteById" | "findOne">;
|
kmsDAL: Pick<TKmsKeyDALFactory, "create" | "updateById" | "findById" | "deleteById" | "findOne">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TExternalKmsServiceFactory = ReturnType<typeof externalKmsServiceFactory>;
|
export type TExternalKmsServiceFactory = ReturnType<typeof externalKmsServiceFactory>;
|
||||||
@@ -35,6 +37,7 @@ export type TExternalKmsServiceFactory = ReturnType<typeof externalKmsServiceFac
|
|||||||
export const externalKmsServiceFactory = ({
|
export const externalKmsServiceFactory = ({
|
||||||
externalKmsDAL,
|
externalKmsDAL,
|
||||||
permissionService,
|
permissionService,
|
||||||
|
licenseService,
|
||||||
kmsService,
|
kmsService,
|
||||||
kmsDAL
|
kmsDAL
|
||||||
}: TExternalKmsServiceFactoryDep) => {
|
}: TExternalKmsServiceFactoryDep) => {
|
||||||
@@ -56,6 +59,13 @@ export const externalKmsServiceFactory = ({
|
|||||||
);
|
);
|
||||||
|
|
||||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Create, OrgPermissionSubjects.Kms);
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Create, OrgPermissionSubjects.Kms);
|
||||||
|
const plan = await licenseService.getPlan(actorOrgId);
|
||||||
|
if (!plan.externalKms) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Failed to create external KMS due to plan restriction. Upgrade to the Enterprise plan."
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const kmsSlug = slug ? slugify(slug) : slugify(alphaNumericNanoId(8).toLowerCase());
|
const kmsSlug = slug ? slugify(slug) : slugify(alphaNumericNanoId(8).toLowerCase());
|
||||||
|
|
||||||
let sanitizedProviderInput = "";
|
let sanitizedProviderInput = "";
|
||||||
@@ -127,6 +137,14 @@ export const externalKmsServiceFactory = ({
|
|||||||
actorOrgId
|
actorOrgId
|
||||||
);
|
);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Kms);
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Kms);
|
||||||
|
|
||||||
|
const plan = await licenseService.getPlan(kmsDoc.orgId);
|
||||||
|
if (!plan.externalKms) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Failed to update external KMS due to plan restriction. Upgrade to the Enterprise plan."
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const kmsSlug = slug ? slugify(slug) : undefined;
|
const kmsSlug = slug ? slugify(slug) : undefined;
|
||||||
|
|
||||||
const externalKmsDoc = await externalKmsDAL.findOne({ kmsKeyId: kmsDoc.id });
|
const externalKmsDoc = await externalKmsDAL.findOne({ kmsKeyId: kmsDoc.id });
|
||||||
|
|||||||
@@ -39,7 +39,8 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
|
|||||||
secretApproval: false,
|
secretApproval: false,
|
||||||
secretRotation: true,
|
secretRotation: true,
|
||||||
caCrl: false,
|
caCrl: false,
|
||||||
instanceUserManagement: false
|
instanceUserManagement: false,
|
||||||
|
externalKms: false
|
||||||
});
|
});
|
||||||
|
|
||||||
export const setupLicenceRequestWithStore = (baseURL: string, refreshUrl: string, licenseKey: string) => {
|
export const setupLicenceRequestWithStore = (baseURL: string, refreshUrl: string, licenseKey: string) => {
|
||||||
|
|||||||
@@ -57,6 +57,7 @@ export type TFeatureSet = {
|
|||||||
secretRotation: true;
|
secretRotation: true;
|
||||||
caCrl: false;
|
caCrl: false;
|
||||||
instanceUserManagement: false;
|
instanceUserManagement: false;
|
||||||
|
externalKms: false;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TOrgPlansTableDTO = {
|
export type TOrgPlansTableDTO = {
|
||||||
|
|||||||
@@ -316,7 +316,8 @@ export const registerRoutes = async (
|
|||||||
kmsDAL,
|
kmsDAL,
|
||||||
kmsService,
|
kmsService,
|
||||||
permissionService,
|
permissionService,
|
||||||
externalKmsDAL
|
externalKmsDAL,
|
||||||
|
licenseService
|
||||||
});
|
});
|
||||||
|
|
||||||
const trustedIpService = trustedIpServiceFactory({
|
const trustedIpService = trustedIpServiceFactory({
|
||||||
|
|||||||
@@ -40,4 +40,5 @@ export type SubscriptionPlan = {
|
|||||||
has_used_trial: boolean;
|
has_used_trial: boolean;
|
||||||
caCrl: boolean;
|
caCrl: boolean;
|
||||||
instanceUserManagement: boolean;
|
instanceUserManagement: boolean;
|
||||||
|
externalKms: boolean;
|
||||||
};
|
};
|
||||||
|
|||||||
+16
-6
@@ -22,7 +22,12 @@ import {
|
|||||||
Tr,
|
Tr,
|
||||||
UpgradePlanModal
|
UpgradePlanModal
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
import {
|
||||||
|
OrgPermissionActions,
|
||||||
|
OrgPermissionSubjects,
|
||||||
|
useOrganization,
|
||||||
|
useSubscription
|
||||||
|
} from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
import { useGetExternalKmsList, useRemoveExternalKms } from "@app/hooks/api";
|
import { useGetExternalKmsList, useRemoveExternalKms } from "@app/hooks/api";
|
||||||
@@ -34,6 +39,7 @@ import { UpdateExternalKmsForm } from "./UpdateExternalKmsForm";
|
|||||||
export const OrgEncryptionTab = withPermission(
|
export const OrgEncryptionTab = withPermission(
|
||||||
() => {
|
() => {
|
||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
|
const { subscription } = useSubscription();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp([
|
const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp([
|
||||||
"upgradePlan",
|
"upgradePlan",
|
||||||
@@ -73,12 +79,11 @@ export const OrgEncryptionTab = withPermission(
|
|||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
onClick={() => {
|
onClick={() => {
|
||||||
|
if (subscription && !subscription?.externalKms) {
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
return;
|
||||||
|
}
|
||||||
handlePopUpOpen("addExternalKms");
|
handlePopUpOpen("addExternalKms");
|
||||||
// if (subscription && !subscription?.auditLogStreams) {
|
|
||||||
// handlePopUpOpen("upgradePlan");
|
|
||||||
// return;
|
|
||||||
// }
|
|
||||||
// handlePopUpOpen("auditLogStreamForm");
|
|
||||||
}}
|
}}
|
||||||
isDisabled={!isAllowed}
|
isDisabled={!isAllowed}
|
||||||
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
@@ -138,6 +143,11 @@ export const OrgEncryptionTab = withPermission(
|
|||||||
)}
|
)}
|
||||||
onClick={(e) => {
|
onClick={(e) => {
|
||||||
e.stopPropagation();
|
e.stopPropagation();
|
||||||
|
if (subscription && !subscription?.externalKms) {
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
handlePopUpOpen("editExternalKms", {
|
handlePopUpOpen("editExternalKms", {
|
||||||
kmsId: kms.id
|
kmsId: kms.id
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user