mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 08:28:52 +00:00
improvement: skip edit/delete permissions for personal secrets
This commit is contained in:
@@ -478,6 +478,7 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
secret = sharedSecretToModify;
|
secret = sharedSecretToModify;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (secret.type !== SecretType.Personal)
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionSecretActions.Edit,
|
ProjectPermissionSecretActions.Edit,
|
||||||
subject(ProjectPermissionSub.Secrets, {
|
subject(ProjectPermissionSub.Secrets, {
|
||||||
@@ -497,6 +498,7 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
const tagsToCheck = inputSecret.tagIds ? newTags : secret.tags;
|
const tagsToCheck = inputSecret.tagIds ? newTags : secret.tags;
|
||||||
|
|
||||||
// now check with new ids
|
// now check with new ids
|
||||||
|
if (secret.type !== SecretType.Personal)
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionSecretActions.Edit,
|
ProjectPermissionSecretActions.Edit,
|
||||||
subject(ProjectPermissionSub.Secrets, {
|
subject(ProjectPermissionSub.Secrets, {
|
||||||
@@ -706,6 +708,8 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
})
|
})
|
||||||
});
|
});
|
||||||
if (!secretToDelete) throw new NotFoundError({ message: "Secret not found" });
|
if (!secretToDelete) throw new NotFoundError({ message: "Secret not found" });
|
||||||
|
|
||||||
|
if (secretToDelete.type !== SecretType.Personal)
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionSecretActions.Delete,
|
ProjectPermissionSecretActions.Delete,
|
||||||
subject(ProjectPermissionSub.Secrets, {
|
subject(ProjectPermissionSub.Secrets, {
|
||||||
|
|||||||
+1
-2
@@ -515,7 +515,6 @@ export const SecretItem = memo(
|
|||||||
isErrorLoadingValue={isErrorFetchingSecretValue}
|
isErrorLoadingValue={isErrorFetchingSecretValue}
|
||||||
key="value-overriden"
|
key="value-overriden"
|
||||||
isVisible={isVisible}
|
isVisible={isVisible}
|
||||||
isReadOnly={isReadOnly}
|
|
||||||
{...field}
|
{...field}
|
||||||
onFocus={() => {
|
onFocus={() => {
|
||||||
if (secret.idOverride) setIsFieldFocused.on();
|
if (secret.idOverride) setIsFieldFocused.on();
|
||||||
@@ -718,7 +717,7 @@ export const SecretItem = memo(
|
|||||||
</DropdownMenuContent>
|
</DropdownMenuContent>
|
||||||
</DropdownMenu>
|
</DropdownMenu>
|
||||||
<ProjectPermissionCan
|
<ProjectPermissionCan
|
||||||
I={ProjectPermissionActions.Edit}
|
I={ProjectPermissionActions.Create}
|
||||||
a={subject(ProjectPermissionSub.Secrets, {
|
a={subject(ProjectPermissionSub.Secrets, {
|
||||||
environment,
|
environment,
|
||||||
secretPath,
|
secretPath,
|
||||||
|
|||||||
Reference in New Issue
Block a user