mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 22:28:15 +00:00
fix: further improve inconsistencies
This commit is contained in:
@@ -4,7 +4,7 @@ import { z } from "zod";
|
|||||||
import { SecretApprovalRequestsSchema, SecretsSchema, SecretType, ServiceTokenScopes } from "@app/db/schemas";
|
import { SecretApprovalRequestsSchema, SecretsSchema, SecretType, ServiceTokenScopes } from "@app/db/schemas";
|
||||||
import { EventType, UserAgentType } from "@app/ee/services/audit-log/audit-log-types";
|
import { EventType, UserAgentType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
import { ApiDocsTags, RAW_SECRETS, SECRETS } from "@app/lib/api-docs";
|
import { ApiDocsTags, RAW_SECRETS, SECRETS } from "@app/lib/api-docs";
|
||||||
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { removeTrailingSlash } from "@app/lib/fn";
|
import { removeTrailingSlash } from "@app/lib/fn";
|
||||||
import { secretsLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { secretsLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { BaseSecretNameSchema, SecretNameSchema } from "@app/server/lib/schemas";
|
import { BaseSecretNameSchema, SecretNameSchema } from "@app/server/lib/schemas";
|
||||||
@@ -12,7 +12,6 @@ import { getTelemetryDistinctId } from "@app/server/lib/telemetry";
|
|||||||
import { getUserAgentType } from "@app/server/plugins/audit-log";
|
import { getUserAgentType } from "@app/server/plugins/audit-log";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { ActorType, AuthMode } from "@app/services/auth/auth-type";
|
import { ActorType, AuthMode } from "@app/services/auth/auth-type";
|
||||||
import { ProjectFilterType } from "@app/services/project/project-types";
|
|
||||||
import { ResourceMetadataSchema } from "@app/services/resource-metadata/resource-metadata-schema";
|
import { ResourceMetadataSchema } from "@app/services/resource-metadata/resource-metadata-schema";
|
||||||
import { SecretOperations, SecretProtectionType } from "@app/services/secret/secret-types";
|
import { SecretOperations, SecretProtectionType } from "@app/services/secret/secret-types";
|
||||||
import { SecretUpdateMode } from "@app/services/secret-v2-bridge/secret-v2-bridge-types";
|
import { SecretUpdateMode } from "@app/services/secret-v2-bridge/secret-v2-bridge-types";
|
||||||
@@ -286,22 +285,17 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
environment = scope[0].environment;
|
environment = scope[0].environment;
|
||||||
workspaceId = req.auth.serviceToken.projectId;
|
workspaceId = req.auth.serviceToken.projectId;
|
||||||
}
|
}
|
||||||
} else if (req.permission.type === ActorType.IDENTITY && req.query.workspaceSlug && !workspaceId) {
|
} else {
|
||||||
const workspace = await server.services.project.getAProject({
|
const projectId = await server.services.project.extractProjectIdFromSlug({
|
||||||
filter: {
|
projectSlug: req.query.workspaceSlug,
|
||||||
type: ProjectFilterType.SLUG,
|
projectId: workspaceId,
|
||||||
orgId: req.permission.orgId,
|
|
||||||
slug: req.query.workspaceSlug
|
|
||||||
},
|
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!workspace) throw new NotFoundError({ message: `No project found with slug ${req.query.workspaceSlug}` });
|
workspaceId = projectId;
|
||||||
|
|
||||||
workspaceId = workspace.id;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!workspaceId || !environment) throw new BadRequestError({ message: "Missing workspace id or environment" });
|
if (!workspaceId || !environment) throw new BadRequestError({ message: "Missing workspace id or environment" });
|
||||||
@@ -442,11 +436,23 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
environment = scope[0].environment;
|
environment = scope[0].environment;
|
||||||
workspaceId = req.auth.serviceToken.projectId;
|
workspaceId = req.auth.serviceToken.projectId;
|
||||||
}
|
}
|
||||||
|
} else {
|
||||||
|
const projectId = await server.services.project.extractProjectIdFromSlug({
|
||||||
|
projectSlug: workspaceSlug,
|
||||||
|
projectId: workspaceId,
|
||||||
|
actorId: req.permission.id,
|
||||||
|
actorAuthMethod: req.permission.authMethod,
|
||||||
|
actor: req.permission.type,
|
||||||
|
actorOrgId: req.permission.orgId
|
||||||
|
});
|
||||||
|
|
||||||
|
workspaceId = projectId;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!environment) throw new BadRequestError({ message: "Missing environment" });
|
if (!environment) throw new BadRequestError({ message: "Missing environment" });
|
||||||
if (!workspaceId && !workspaceSlug)
|
if (!workspaceId) {
|
||||||
throw new BadRequestError({ message: "You must provide workspaceSlug or workspaceId" });
|
throw new BadRequestError({ message: "You must provide workspaceSlug or workspaceId" });
|
||||||
|
}
|
||||||
|
|
||||||
const secret = await server.services.secret.getSecretByNameRaw({
|
const secret = await server.services.secret.getSecretByNameRaw({
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
@@ -457,7 +463,6 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
environment,
|
environment,
|
||||||
projectId: workspaceId,
|
projectId: workspaceId,
|
||||||
viewSecretValue: req.query.viewSecretValue,
|
viewSecretValue: req.query.viewSecretValue,
|
||||||
projectSlug: workspaceSlug,
|
|
||||||
path: secretPath,
|
path: secretPath,
|
||||||
secretName: req.params.secretName,
|
secretName: req.params.secretName,
|
||||||
type: req.query.type,
|
type: req.query.type,
|
||||||
@@ -559,7 +564,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const workspaceId = await server.services.project.extractProjectIdFromSlug({
|
const projectId = await server.services.project.extractProjectIdFromSlug({
|
||||||
projectSlug: req.body.projectSlug,
|
projectSlug: req.body.projectSlug,
|
||||||
projectId: req.body.workspaceId,
|
projectId: req.body.workspaceId,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
@@ -574,7 +579,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
environment: req.body.environment,
|
environment: req.body.environment,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
secretPath: req.body.secretPath,
|
secretPath: req.body.secretPath,
|
||||||
secretName: req.params.secretName,
|
secretName: req.params.secretName,
|
||||||
type: req.body.type,
|
type: req.body.type,
|
||||||
@@ -592,7 +597,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
|
|
||||||
const { secret } = secretOperation;
|
const { secret } = secretOperation;
|
||||||
await server.services.auditLog.createAuditLog({
|
await server.services.auditLog.createAuditLog({
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
...req.auditLogInfo,
|
...req.auditLogInfo,
|
||||||
event: {
|
event: {
|
||||||
type: EventType.CREATE_SECRET,
|
type: EventType.CREATE_SECRET,
|
||||||
@@ -612,7 +617,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
distinctId: getTelemetryDistinctId(req),
|
distinctId: getTelemetryDistinctId(req),
|
||||||
properties: {
|
properties: {
|
||||||
numberOfSecrets: 1,
|
numberOfSecrets: 1,
|
||||||
workspaceId,
|
workspaceId: projectId,
|
||||||
environment: req.body.environment,
|
environment: req.body.environment,
|
||||||
secretPath: req.body.secretPath,
|
secretPath: req.body.secretPath,
|
||||||
channel: getUserAgentType(req.headers["user-agent"]),
|
channel: getUserAgentType(req.headers["user-agent"]),
|
||||||
@@ -690,7 +695,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const workspaceId = await server.services.project.extractProjectIdFromSlug({
|
const projectId = await server.services.project.extractProjectIdFromSlug({
|
||||||
projectSlug: req.body.projectSlug,
|
projectSlug: req.body.projectSlug,
|
||||||
projectId: req.body.workspaceId,
|
projectId: req.body.workspaceId,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
@@ -705,7 +710,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
environment: req.body.environment,
|
environment: req.body.environment,
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
secretPath: req.body.secretPath,
|
secretPath: req.body.secretPath,
|
||||||
secretName: req.params.secretName,
|
secretName: req.params.secretName,
|
||||||
type: req.body.type,
|
type: req.body.type,
|
||||||
@@ -727,7 +732,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
const { secret } = secretOperation;
|
const { secret } = secretOperation;
|
||||||
|
|
||||||
await server.services.auditLog.createAuditLog({
|
await server.services.auditLog.createAuditLog({
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
...req.auditLogInfo,
|
...req.auditLogInfo,
|
||||||
event: {
|
event: {
|
||||||
type: EventType.UPDATE_SECRET,
|
type: EventType.UPDATE_SECRET,
|
||||||
@@ -747,7 +752,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
distinctId: getTelemetryDistinctId(req),
|
distinctId: getTelemetryDistinctId(req),
|
||||||
properties: {
|
properties: {
|
||||||
numberOfSecrets: 1,
|
numberOfSecrets: 1,
|
||||||
workspaceId,
|
workspaceId: projectId,
|
||||||
environment: req.body.environment,
|
environment: req.body.environment,
|
||||||
secretPath: req.body.secretPath,
|
secretPath: req.body.secretPath,
|
||||||
channel: getUserAgentType(req.headers["user-agent"]),
|
channel: getUserAgentType(req.headers["user-agent"]),
|
||||||
@@ -801,7 +806,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.SERVICE_TOKEN, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const workspaceId = await server.services.project.extractProjectIdFromSlug({
|
const projectId = await server.services.project.extractProjectIdFromSlug({
|
||||||
projectSlug: req.body.projectSlug,
|
projectSlug: req.body.projectSlug,
|
||||||
projectId: req.body.workspaceId,
|
projectId: req.body.workspaceId,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
@@ -816,7 +821,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
environment: req.body.environment,
|
environment: req.body.environment,
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
secretPath: req.body.secretPath,
|
secretPath: req.body.secretPath,
|
||||||
secretName: req.params.secretName,
|
secretName: req.params.secretName,
|
||||||
type: req.body.type
|
type: req.body.type
|
||||||
@@ -828,7 +833,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
const { secret } = secretOperation;
|
const { secret } = secretOperation;
|
||||||
|
|
||||||
await server.services.auditLog.createAuditLog({
|
await server.services.auditLog.createAuditLog({
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
...req.auditLogInfo,
|
...req.auditLogInfo,
|
||||||
event: {
|
event: {
|
||||||
type: EventType.DELETE_SECRET,
|
type: EventType.DELETE_SECRET,
|
||||||
@@ -847,7 +852,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
distinctId: getTelemetryDistinctId(req),
|
distinctId: getTelemetryDistinctId(req),
|
||||||
properties: {
|
properties: {
|
||||||
numberOfSecrets: 1,
|
numberOfSecrets: 1,
|
||||||
workspaceId,
|
workspaceId: projectId,
|
||||||
environment: req.body.environment,
|
environment: req.body.environment,
|
||||||
secretPath: req.body.secretPath,
|
secretPath: req.body.secretPath,
|
||||||
channel: getUserAgentType(req.headers["user-agent"]),
|
channel: getUserAgentType(req.headers["user-agent"]),
|
||||||
|
|||||||
@@ -1543,9 +1543,8 @@ export const secretServiceFactory = ({
|
|||||||
actor,
|
actor,
|
||||||
environment,
|
environment,
|
||||||
viewSecretValue,
|
viewSecretValue,
|
||||||
projectId: workspaceId,
|
projectId,
|
||||||
expandSecretReferences,
|
expandSecretReferences,
|
||||||
projectSlug,
|
|
||||||
actorId,
|
actorId,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
@@ -1553,7 +1552,6 @@ export const secretServiceFactory = ({
|
|||||||
includeImports,
|
includeImports,
|
||||||
version
|
version
|
||||||
}: TGetASecretRawDTO) => {
|
}: TGetASecretRawDTO) => {
|
||||||
const projectId = workspaceId || (await projectDAL.findProjectBySlug(projectSlug as string, actorOrgId)).id;
|
|
||||||
const { botKey, shouldUseSecretV2Bridge } = await projectBotService.getBotKey(projectId);
|
const { botKey, shouldUseSecretV2Bridge } = await projectBotService.getBotKey(projectId);
|
||||||
if (shouldUseSecretV2Bridge) {
|
if (shouldUseSecretV2Bridge) {
|
||||||
const secret = await secretV2BridgeService.getSecretByName({
|
const secret = await secretV2BridgeService.getSecretByName({
|
||||||
|
|||||||
@@ -229,8 +229,7 @@ export type TGetASecretRawDTO = {
|
|||||||
type: "shared" | "personal";
|
type: "shared" | "personal";
|
||||||
includeImports?: boolean;
|
includeImports?: boolean;
|
||||||
version?: number;
|
version?: number;
|
||||||
projectSlug?: string;
|
projectId: string;
|
||||||
projectId?: string;
|
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
export type TGetASecretByIdRawDTO = {
|
export type TGetASecretByIdRawDTO = {
|
||||||
|
|||||||
Reference in New Issue
Block a user