mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 10:27:26 +00:00
feat: checkpoint before disaster strikes
This commit is contained in:
+3
-3
@@ -1,15 +1,15 @@
|
|||||||
import { TDbClient } from "@app/db";
|
import { TDbClient } from "@app/db";
|
||||||
import { TableName } from "@app/db/schemas";
|
import { TableName } from "@app/db/schemas";
|
||||||
import { ormify } from "@app/lib/knex";
|
import { ormify, TOrmify } from "@app/lib/knex";
|
||||||
|
|
||||||
export type TAccessApprovalPolicyApproverDALFactory = ReturnType<typeof accessApprovalPolicyApproverDALFactory>;
|
export type TAccessApprovalPolicyApproverDALFactory = TOrmify<TableName.AccessApprovalPolicyApprover>;
|
||||||
|
|
||||||
export const accessApprovalPolicyApproverDALFactory = (db: TDbClient) => {
|
export const accessApprovalPolicyApproverDALFactory = (db: TDbClient) => {
|
||||||
const accessApprovalPolicyApproverOrm = ormify(db, TableName.AccessApprovalPolicyApprover);
|
const accessApprovalPolicyApproverOrm = ormify(db, TableName.AccessApprovalPolicyApprover);
|
||||||
return { ...accessApprovalPolicyApproverOrm };
|
return { ...accessApprovalPolicyApproverOrm };
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TAccessApprovalPolicyBypasserDALFactory = ReturnType<typeof accessApprovalPolicyBypasserDALFactory>;
|
export type TAccessApprovalPolicyBypasserDALFactory = TOrmify<TableName.AccessApprovalPolicyBypasser>;
|
||||||
|
|
||||||
export const accessApprovalPolicyBypasserDALFactory = (db: TDbClient) => {
|
export const accessApprovalPolicyBypasserDALFactory = (db: TDbClient) => {
|
||||||
const accessApprovalPolicyBypasserOrm = ormify(db, TableName.AccessApprovalPolicyBypasser);
|
const accessApprovalPolicyBypasserOrm = ormify(db, TableName.AccessApprovalPolicyBypasser);
|
||||||
|
|||||||
@@ -3,13 +3,363 @@ import { Knex } from "knex";
|
|||||||
import { TDbClient } from "@app/db";
|
import { TDbClient } from "@app/db";
|
||||||
import { AccessApprovalPoliciesSchema, TableName, TAccessApprovalPolicies, TUsers } from "@app/db/schemas";
|
import { AccessApprovalPoliciesSchema, TableName, TAccessApprovalPolicies, TUsers } from "@app/db/schemas";
|
||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { buildFindFilter, ormify, selectAllTableCols, sqlNestRelationships, TFindFilter } from "@app/lib/knex";
|
import { buildFindFilter, ormify, selectAllTableCols, sqlNestRelationships, TFindFilter, TOrmify } from "@app/lib/knex";
|
||||||
|
|
||||||
import { ApproverType, BypasserType } from "./access-approval-policy-types";
|
import {
|
||||||
|
ApproverType,
|
||||||
|
BypasserType,
|
||||||
|
TCreateAccessApprovalPolicy,
|
||||||
|
TDeleteAccessApprovalPolicy,
|
||||||
|
TGetAccessApprovalPolicyByIdDTO,
|
||||||
|
TGetAccessPolicyCountByEnvironmentDTO,
|
||||||
|
TListAccessApprovalPoliciesDTO,
|
||||||
|
TUpdateAccessApprovalPolicy
|
||||||
|
} from "./access-approval-policy-types";
|
||||||
|
|
||||||
export type TAccessApprovalPolicyDALFactory = ReturnType<typeof accessApprovalPolicyDALFactory>;
|
export interface TAccessApprovalPolicyDALFactory
|
||||||
|
extends Omit<TOrmify<TableName.AccessApprovalPolicy>, "findById" | "find"> {
|
||||||
|
find: (
|
||||||
|
filter: TFindFilter<
|
||||||
|
TAccessApprovalPolicies & {
|
||||||
|
projectId: string;
|
||||||
|
}
|
||||||
|
>,
|
||||||
|
customFilter?: {
|
||||||
|
policyId?: string;
|
||||||
|
},
|
||||||
|
tx?: Knex
|
||||||
|
) => Promise<
|
||||||
|
{
|
||||||
|
approvers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType.User;
|
||||||
|
name: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType.Group;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
bypassers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType.User;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType.Group;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
}[]
|
||||||
|
>;
|
||||||
|
findById: (
|
||||||
|
policyId: string,
|
||||||
|
tx?: Knex
|
||||||
|
) => Promise<
|
||||||
|
| {
|
||||||
|
approvers: {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
}
|
||||||
|
| undefined
|
||||||
|
>;
|
||||||
|
softDeleteById: (
|
||||||
|
policyId: string,
|
||||||
|
tx?: Knex
|
||||||
|
) => Promise<{
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
}>;
|
||||||
|
findLastValidPolicy: (
|
||||||
|
{
|
||||||
|
envId,
|
||||||
|
secretPath
|
||||||
|
}: {
|
||||||
|
envId: string;
|
||||||
|
secretPath: string;
|
||||||
|
},
|
||||||
|
tx?: Knex
|
||||||
|
) => Promise<
|
||||||
|
| {
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
}
|
||||||
|
| undefined
|
||||||
|
>;
|
||||||
|
}
|
||||||
|
|
||||||
export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
export interface TAccessApprovalPolicyServiceFactory {
|
||||||
|
getAccessPolicyCountByEnvSlug: ({
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
projectSlug,
|
||||||
|
actorId,
|
||||||
|
envSlug
|
||||||
|
}: TGetAccessPolicyCountByEnvironmentDTO) => Promise<{
|
||||||
|
count: number;
|
||||||
|
}>;
|
||||||
|
createAccessApprovalPolicy: ({
|
||||||
|
name,
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
actorOrgId,
|
||||||
|
secretPath,
|
||||||
|
actorAuthMethod,
|
||||||
|
approvals,
|
||||||
|
approvers,
|
||||||
|
bypassers,
|
||||||
|
projectSlug,
|
||||||
|
environment,
|
||||||
|
enforcementLevel,
|
||||||
|
allowedSelfApprovals,
|
||||||
|
approvalsRequired
|
||||||
|
}: TCreateAccessApprovalPolicy) => Promise<{
|
||||||
|
environment: {
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
projectId: string;
|
||||||
|
slug: string;
|
||||||
|
position: number;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
}>;
|
||||||
|
deleteAccessApprovalPolicy: ({
|
||||||
|
policyId,
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
}: TDeleteAccessApprovalPolicy) => Promise<{
|
||||||
|
approvers: {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
}>;
|
||||||
|
updateAccessApprovalPolicy: ({
|
||||||
|
policyId,
|
||||||
|
approvers,
|
||||||
|
bypassers,
|
||||||
|
secretPath,
|
||||||
|
name,
|
||||||
|
actorId,
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
approvals,
|
||||||
|
enforcementLevel,
|
||||||
|
allowedSelfApprovals,
|
||||||
|
approvalsRequired
|
||||||
|
}: TUpdateAccessApprovalPolicy) => Promise<{
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
}>;
|
||||||
|
getAccessApprovalPolicyByProjectSlug: ({
|
||||||
|
actorId,
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
projectSlug
|
||||||
|
}: TListAccessApprovalPoliciesDTO) => Promise<
|
||||||
|
{
|
||||||
|
approvers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType;
|
||||||
|
name: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
bypassers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
}[]
|
||||||
|
>;
|
||||||
|
getAccessApprovalPolicyById: ({
|
||||||
|
actorId,
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
policyId
|
||||||
|
}: TGetAccessApprovalPolicyByIdDTO) => Promise<{
|
||||||
|
approvers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType.User;
|
||||||
|
name: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType.Group;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
bypassers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType.User;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType.Group;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
}>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export const accessApprovalPolicyDALFactory = (db: TDbClient): TAccessApprovalPolicyDALFactory => {
|
||||||
const accessApprovalPolicyOrm = ormify(db, TableName.AccessApprovalPolicy);
|
const accessApprovalPolicyOrm = ormify(db, TableName.AccessApprovalPolicy);
|
||||||
|
|
||||||
const accessApprovalPolicyFindQuery = async (
|
const accessApprovalPolicyFindQuery = async (
|
||||||
@@ -61,7 +411,7 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
return result;
|
return result;
|
||||||
};
|
};
|
||||||
|
|
||||||
const findById = async (policyId: string, tx?: Knex) => {
|
const findById: TAccessApprovalPolicyDALFactory["findById"] = async (policyId, tx) => {
|
||||||
try {
|
try {
|
||||||
const doc = await accessApprovalPolicyFindQuery(tx || db.replicaNode(), {
|
const doc = await accessApprovalPolicyFindQuery(tx || db.replicaNode(), {
|
||||||
[`${TableName.AccessApprovalPolicy}.id` as "id"]: policyId
|
[`${TableName.AccessApprovalPolicy}.id` as "id"]: policyId
|
||||||
@@ -112,13 +462,7 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
const find = async (
|
const find: TAccessApprovalPolicyDALFactory["find"] = async (filter, customFilter, tx) => {
|
||||||
filter: TFindFilter<TAccessApprovalPolicies & { projectId: string }>,
|
|
||||||
customFilter?: {
|
|
||||||
policyId?: string;
|
|
||||||
},
|
|
||||||
tx?: Knex
|
|
||||||
) => {
|
|
||||||
try {
|
try {
|
||||||
const docs = await accessApprovalPolicyFindQuery(tx || db.replicaNode(), filter, customFilter);
|
const docs = await accessApprovalPolicyFindQuery(tx || db.replicaNode(), filter, customFilter);
|
||||||
|
|
||||||
@@ -141,7 +485,7 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
label: "approvers" as const,
|
label: "approvers" as const,
|
||||||
mapper: ({ approverUserId: id, approverUsername, approverSequence, approvalsRequired }) => ({
|
mapper: ({ approverUserId: id, approverUsername, approverSequence, approvalsRequired }) => ({
|
||||||
id,
|
id,
|
||||||
type: ApproverType.User,
|
type: ApproverType.User as const,
|
||||||
name: approverUsername,
|
name: approverUsername,
|
||||||
sequence: approverSequence,
|
sequence: approverSequence,
|
||||||
approvalsRequired
|
approvalsRequired
|
||||||
@@ -152,7 +496,7 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
label: "approvers" as const,
|
label: "approvers" as const,
|
||||||
mapper: ({ approverGroupId: id, approverSequence, approvalsRequired }) => ({
|
mapper: ({ approverGroupId: id, approverSequence, approvalsRequired }) => ({
|
||||||
id,
|
id,
|
||||||
type: ApproverType.Group,
|
type: ApproverType.Group as const,
|
||||||
sequence: approverSequence,
|
sequence: approverSequence,
|
||||||
approvalsRequired
|
approvalsRequired
|
||||||
})
|
})
|
||||||
@@ -162,7 +506,7 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
label: "bypassers" as const,
|
label: "bypassers" as const,
|
||||||
mapper: ({ bypasserUserId: id, bypasserUsername }) => ({
|
mapper: ({ bypasserUserId: id, bypasserUsername }) => ({
|
||||||
id,
|
id,
|
||||||
type: BypasserType.User,
|
type: BypasserType.User as const,
|
||||||
name: bypasserUsername
|
name: bypasserUsername
|
||||||
})
|
})
|
||||||
},
|
},
|
||||||
@@ -171,7 +515,7 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
label: "bypassers" as const,
|
label: "bypassers" as const,
|
||||||
mapper: ({ bypasserGroupId: id }) => ({
|
mapper: ({ bypasserGroupId: id }) => ({
|
||||||
id,
|
id,
|
||||||
type: BypasserType.Group
|
type: BypasserType.Group as const
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
@@ -186,12 +530,15 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
const softDeleteById = async (policyId: string, tx?: Knex) => {
|
const softDeleteById: TAccessApprovalPolicyDALFactory["softDeleteById"] = async (policyId, tx) => {
|
||||||
const softDeletedPolicy = await accessApprovalPolicyOrm.updateById(policyId, { deletedAt: new Date() }, tx);
|
const softDeletedPolicy = await accessApprovalPolicyOrm.updateById(policyId, { deletedAt: new Date() }, tx);
|
||||||
return softDeletedPolicy;
|
return softDeletedPolicy;
|
||||||
};
|
};
|
||||||
|
|
||||||
const findLastValidPolicy = async ({ envId, secretPath }: { envId: string; secretPath: string }, tx?: Knex) => {
|
const findLastValidPolicy: TAccessApprovalPolicyDALFactory["findLastValidPolicy"] = async (
|
||||||
|
{ envId, secretPath },
|
||||||
|
tx
|
||||||
|
) => {
|
||||||
try {
|
try {
|
||||||
const result = await (tx || db.replicaNode())(TableName.AccessApprovalPolicy)
|
const result = await (tx || db.replicaNode())(TableName.AccessApprovalPolicy)
|
||||||
.where(
|
.where(
|
||||||
|
|||||||
@@ -24,9 +24,8 @@ import { TAccessApprovalPolicyDALFactory } from "./access-approval-policy-dal";
|
|||||||
import {
|
import {
|
||||||
ApproverType,
|
ApproverType,
|
||||||
BypasserType,
|
BypasserType,
|
||||||
TCreateAccessApprovalPolicy,
|
TAccessApprovalPolicyServiceFactory,
|
||||||
TDeleteAccessApprovalPolicy,
|
TDeleteAccessApprovalPolicy,
|
||||||
TGetAccessApprovalPolicyByIdDTO,
|
|
||||||
TGetAccessPolicyCountByEnvironmentDTO,
|
TGetAccessPolicyCountByEnvironmentDTO,
|
||||||
TListAccessApprovalPoliciesDTO,
|
TListAccessApprovalPoliciesDTO,
|
||||||
TUpdateAccessApprovalPolicy
|
TUpdateAccessApprovalPolicy
|
||||||
@@ -48,8 +47,6 @@ type TAccessApprovalPolicyServiceFactoryDep = {
|
|||||||
orgMembershipDAL: Pick<TOrgMembershipDALFactory, "find">;
|
orgMembershipDAL: Pick<TOrgMembershipDALFactory, "find">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TAccessApprovalPolicyServiceFactory = ReturnType<typeof accessApprovalPolicyServiceFactory>;
|
|
||||||
|
|
||||||
export const accessApprovalPolicyServiceFactory = ({
|
export const accessApprovalPolicyServiceFactory = ({
|
||||||
accessApprovalPolicyDAL,
|
accessApprovalPolicyDAL,
|
||||||
accessApprovalPolicyApproverDAL,
|
accessApprovalPolicyApproverDAL,
|
||||||
@@ -63,8 +60,8 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
additionalPrivilegeDAL,
|
additionalPrivilegeDAL,
|
||||||
accessApprovalRequestReviewerDAL,
|
accessApprovalRequestReviewerDAL,
|
||||||
orgMembershipDAL
|
orgMembershipDAL
|
||||||
}: TAccessApprovalPolicyServiceFactoryDep) => {
|
}: TAccessApprovalPolicyServiceFactoryDep): TAccessApprovalPolicyServiceFactory => {
|
||||||
const createAccessApprovalPolicy = async ({
|
const createAccessApprovalPolicy: TAccessApprovalPolicyServiceFactory["createAccessApprovalPolicy"] = async ({
|
||||||
name,
|
name,
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -79,7 +76,7 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
enforcementLevel,
|
enforcementLevel,
|
||||||
allowedSelfApprovals,
|
allowedSelfApprovals,
|
||||||
approvalsRequired
|
approvalsRequired
|
||||||
}: TCreateAccessApprovalPolicy) => {
|
}) => {
|
||||||
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
||||||
if (!project) throw new NotFoundError({ message: `Project with slug '${projectSlug}' not found` });
|
if (!project) throw new NotFoundError({ message: `Project with slug '${projectSlug}' not found` });
|
||||||
|
|
||||||
@@ -240,31 +237,26 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
return { ...accessApproval, environment: env, projectId: project.id };
|
return { ...accessApproval, environment: env, projectId: project.id };
|
||||||
};
|
};
|
||||||
|
|
||||||
const getAccessApprovalPolicyByProjectSlug = async ({
|
const getAccessApprovalPolicyByProjectSlug: TAccessApprovalPolicyServiceFactory["getAccessApprovalPolicyByProjectSlug"] =
|
||||||
actorId,
|
async ({ actorId, actor, actorOrgId, actorAuthMethod, projectSlug }: TListAccessApprovalPoliciesDTO) => {
|
||||||
actor,
|
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
||||||
actorOrgId,
|
if (!project) throw new NotFoundError({ message: `Project with slug '${projectSlug}' not found` });
|
||||||
actorAuthMethod,
|
|
||||||
projectSlug
|
|
||||||
}: TListAccessApprovalPoliciesDTO) => {
|
|
||||||
const project = await projectDAL.findProjectBySlug(projectSlug, actorOrgId);
|
|
||||||
if (!project) throw new NotFoundError({ message: `Project with slug '${projectSlug}' not found` });
|
|
||||||
|
|
||||||
// Anyone in the project should be able to get the policies.
|
// Anyone in the project should be able to get the policies.
|
||||||
await permissionService.getProjectPermission({
|
await permissionService.getProjectPermission({
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
projectId: project.id,
|
projectId: project.id,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actionProjectType: ActionProjectType.SecretManager
|
actionProjectType: ActionProjectType.SecretManager
|
||||||
});
|
});
|
||||||
|
|
||||||
const accessApprovalPolicies = await accessApprovalPolicyDAL.find({ projectId: project.id, deletedAt: null });
|
const accessApprovalPolicies = await accessApprovalPolicyDAL.find({ projectId: project.id, deletedAt: null });
|
||||||
return accessApprovalPolicies;
|
return accessApprovalPolicies;
|
||||||
};
|
};
|
||||||
|
|
||||||
const updateAccessApprovalPolicy = async ({
|
const updateAccessApprovalPolicy: TAccessApprovalPolicyServiceFactory["updateAccessApprovalPolicy"] = async ({
|
||||||
policyId,
|
policyId,
|
||||||
approvers,
|
approvers,
|
||||||
bypassers,
|
bypassers,
|
||||||
@@ -483,6 +475,7 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
|
|
||||||
return doc;
|
return doc;
|
||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
...updatedPolicy,
|
...updatedPolicy,
|
||||||
environment: accessApprovalPolicy.environment,
|
environment: accessApprovalPolicy.environment,
|
||||||
@@ -490,7 +483,7 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
const deleteAccessApprovalPolicy = async ({
|
const deleteAccessApprovalPolicy: TAccessApprovalPolicyServiceFactory["deleteAccessApprovalPolicy"] = async ({
|
||||||
policyId,
|
policyId,
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -539,7 +532,7 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
return policy;
|
return policy;
|
||||||
};
|
};
|
||||||
|
|
||||||
const getAccessPolicyCountByEnvSlug = async ({
|
const getAccessPolicyCountByEnvSlug: TAccessApprovalPolicyServiceFactory["getAccessPolicyCountByEnvSlug"] = async ({
|
||||||
actor,
|
actor,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
@@ -576,13 +569,13 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
return { count: policies.length };
|
return { count: policies.length };
|
||||||
};
|
};
|
||||||
|
|
||||||
const getAccessApprovalPolicyById = async ({
|
const getAccessApprovalPolicyById: TAccessApprovalPolicyServiceFactory["getAccessApprovalPolicyById"] = async ({
|
||||||
actorId,
|
actorId,
|
||||||
actor,
|
actor,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
policyId
|
policyId
|
||||||
}: TGetAccessApprovalPolicyByIdDTO) => {
|
}) => {
|
||||||
const [policy] = await accessApprovalPolicyDAL.find({}, { policyId });
|
const [policy] = await accessApprovalPolicyDAL.find({}, { policyId });
|
||||||
|
|
||||||
if (!policy) {
|
if (!policy) {
|
||||||
|
|||||||
@@ -76,3 +76,217 @@ export type TGetAccessApprovalPolicyByIdDTO = {
|
|||||||
export type TListAccessApprovalPoliciesDTO = {
|
export type TListAccessApprovalPoliciesDTO = {
|
||||||
projectSlug: string;
|
projectSlug: string;
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
export interface TAccessApprovalPolicyServiceFactory {
|
||||||
|
getAccessPolicyCountByEnvSlug: ({
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
projectSlug,
|
||||||
|
actorId,
|
||||||
|
envSlug
|
||||||
|
}: TGetAccessPolicyCountByEnvironmentDTO) => Promise<{
|
||||||
|
count: number;
|
||||||
|
}>;
|
||||||
|
createAccessApprovalPolicy: ({
|
||||||
|
name,
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
actorOrgId,
|
||||||
|
secretPath,
|
||||||
|
actorAuthMethod,
|
||||||
|
approvals,
|
||||||
|
approvers,
|
||||||
|
bypassers,
|
||||||
|
projectSlug,
|
||||||
|
environment,
|
||||||
|
enforcementLevel,
|
||||||
|
allowedSelfApprovals,
|
||||||
|
approvalsRequired
|
||||||
|
}: TCreateAccessApprovalPolicy) => Promise<{
|
||||||
|
environment: {
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
projectId: string;
|
||||||
|
slug: string;
|
||||||
|
position: number;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
}>;
|
||||||
|
deleteAccessApprovalPolicy: ({
|
||||||
|
policyId,
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
}: TDeleteAccessApprovalPolicy) => Promise<{
|
||||||
|
approvers: {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
}>;
|
||||||
|
updateAccessApprovalPolicy: ({
|
||||||
|
policyId,
|
||||||
|
approvers,
|
||||||
|
bypassers,
|
||||||
|
secretPath,
|
||||||
|
name,
|
||||||
|
actorId,
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
approvals,
|
||||||
|
enforcementLevel,
|
||||||
|
allowedSelfApprovals,
|
||||||
|
approvalsRequired
|
||||||
|
}: TUpdateAccessApprovalPolicy) => Promise<{
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
}>;
|
||||||
|
getAccessApprovalPolicyByProjectSlug: ({
|
||||||
|
actorId,
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
projectSlug
|
||||||
|
}: TListAccessApprovalPoliciesDTO) => Promise<
|
||||||
|
{
|
||||||
|
approvers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType;
|
||||||
|
name: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
bypassers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
}[]
|
||||||
|
>;
|
||||||
|
getAccessApprovalPolicyById: ({
|
||||||
|
actorId,
|
||||||
|
actor,
|
||||||
|
actorOrgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
policyId
|
||||||
|
}: TGetAccessApprovalPolicyByIdDTO) => Promise<{
|
||||||
|
approvers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType.User;
|
||||||
|
name: string;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: ApproverType.Group;
|
||||||
|
sequence: number | null | undefined;
|
||||||
|
approvalsRequired: number | null | undefined;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
createdAt: Date;
|
||||||
|
updatedAt: Date;
|
||||||
|
approvals: number;
|
||||||
|
envId: string;
|
||||||
|
enforcementLevel: string;
|
||||||
|
allowedSelfApprovals: boolean;
|
||||||
|
secretPath?: string | null | undefined;
|
||||||
|
deletedAt?: Date | null | undefined;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
projectId: string;
|
||||||
|
bypassers: (
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType.User;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
id: string | null | undefined;
|
||||||
|
type: BypasserType.Group;
|
||||||
|
}
|
||||||
|
)[];
|
||||||
|
}>;
|
||||||
|
}
|
||||||
|
|||||||
@@ -91,7 +91,7 @@ export const pkiTemplatesDALFactory = (db: TDbClient) => {
|
|||||||
void query.orderBy(sort.map(([column, order, nulls]) => ({ column: column as string, order, nulls })));
|
void query.orderBy(sort.map(([column, order, nulls]) => ({ column: column as string, order, nulls })));
|
||||||
}
|
}
|
||||||
|
|
||||||
const res = await query;
|
const res = (await query) as Array<Awaited<typeof query>[0] & { count: string }>;
|
||||||
return res.map((el) => ({ ...el, ca: { id: el.caId, name: el.caName } }));
|
return res.map((el) => ({ ...el, ca: { id: el.caId, name: el.caName } }));
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new DatabaseError({ error, name: "Find one" });
|
throw new DatabaseError({ error, name: "Find one" });
|
||||||
|
|||||||
@@ -561,7 +561,7 @@ const formatMultiValueEnv = (val?: string) => {
|
|||||||
return `"${val.replaceAll("\n", "\\n")}"`;
|
return `"${val.replaceAll("\n", "\\n")}"`;
|
||||||
};
|
};
|
||||||
|
|
||||||
type TSecretReferenceTraceNode = {
|
export type TSecretReferenceTraceNode = {
|
||||||
key: string;
|
key: string;
|
||||||
value?: string;
|
value?: string;
|
||||||
environment: string;
|
environment: string;
|
||||||
|
|||||||
Reference in New Issue
Block a user