feat: changed expand secret factory to iterative solution

This commit is contained in:
=
2024-08-30 10:52:46 +05:30
parent 8f461bf50c
commit 55b36b033e
@@ -409,64 +409,60 @@ export const expandSecretReferencesFactory = ({
return secretCache[cacheKey][secretKey] || ""; return secretCache[cacheKey][secretKey] || "";
}; };
const recursivelyExpandSecret = async ({ const recursivelyExpandSecret = async (dto: { value?: string; secretPath: string; environment: string }) => {
value,
secretPath,
environment,
depth = 1
}: {
value?: string;
secretPath: string;
environment: string;
depth?: number;
}) => {
if (!value) return ""; if (!value) return "";
if (depth > MAX_SECRET_REFERENCE_DEPTH) return "";
const stack = [{ ...dto, depth: 0 }];
let expandedValue = dto.value;
while (stack.length) {
const { value, secretPath, environment, depth } = stack.pop()!;
// eslint-disable-next-line
if (depth > MAX_SECRET_REFERENCE_DEPTH) continue;
const refs = value.match(INTERPOLATION_SYNTAX_REG); const refs = value.match(INTERPOLATION_SYNTAX_REG);
let expandedValue = value;
if (refs) { if (refs) {
for (const interpolationSyntax of refs) { for (const interpolationSyntax of refs) {
const interpolationKey = interpolationSyntax.slice(2, interpolationSyntax.length - 1); const interpolationKey = interpolationSyntax.slice(2, interpolationSyntax.length - 1);
const entities = interpolationKey.trim().split("."); const entities = interpolationKey.trim().split(".");
// eslint-disable-next-line
if (!entities.length) continue;
if (entities.length === 1) { if (entities.length === 1) {
const [secretKey] = entities; const [secretKey] = entities;
// eslint-disable-next-line // eslint-disable-next-line
let referenceValue = await fetchSecret(environment, secretPath, secretKey); const referedValue = await fetchSecret(environment, secretPath, secretKey);
if (INTERPOLATION_SYNTAX_REG.test(referenceValue)) { const cacheKey = getCacheUniqueKey(environment, secretPath);
// eslint-disable-next-line secretCache[cacheKey][secretKey] = referedValue;
referenceValue = await recursivelyExpandSecret({ if (INTERPOLATION_SYNTAX_REG.test(referedValue)) {
environment, stack.push({
value: referedValue,
secretPath, secretPath,
value: referenceValue, environment,
depth: depth + 1 depth: depth + 1
}); });
} }
const cacheKey = getCacheUniqueKey(environment, secretPath); expandedValue = expandedValue.replaceAll(interpolationSyntax, referedValue);
secretCache[cacheKey][secretKey] = referenceValue; } else {
expandedValue = expandedValue.replaceAll(interpolationSyntax, referenceValue);
}
if (entities.length > 1) {
const secretReferenceEnvironment = entities[0]; const secretReferenceEnvironment = entities[0];
const secretReferencePath = path.join("/", ...entities.slice(1, entities.length - 1)); const secretReferencePath = path.join("/", ...entities.slice(1, entities.length - 1));
const secretReferenceKey = entities[entities.length - 1]; const secretReferenceKey = entities[entities.length - 1];
// eslint-disable-next-line // eslint-disable-next-line
let referenceValue = await fetchSecret(secretReferenceEnvironment, secretReferencePath, secretReferenceKey); let referedValue = await fetchSecret(secretReferenceEnvironment, secretReferencePath, secretReferenceKey);
if (INTERPOLATION_SYNTAX_REG.test(referenceValue)) { const cacheKey = getCacheUniqueKey(secretReferenceEnvironment, secretReferencePath);
// eslint-disable-next-line secretCache[cacheKey][secretReferenceKey] = referedValue;
referenceValue = await recursivelyExpandSecret({ if (INTERPOLATION_SYNTAX_REG.test(referedValue)) {
environment: secretReferenceEnvironment, stack.push({
value: referedValue,
secretPath: secretReferencePath, secretPath: secretReferencePath,
value: referenceValue, environment: secretReferenceEnvironment,
depth: depth + 1 depth: depth + 1
}); });
} }
const cacheKey = getCacheUniqueKey(secretReferenceEnvironment, secretReferencePath);
secretCache[cacheKey][secretReferenceKey] = referenceValue; expandedValue = expandedValue.replaceAll(interpolationSyntax, referedValue);
expandedValue = expandedValue.replaceAll(interpolationSyntax, referenceValue); }
} }
} }
} }