feat(access-request): fix deleted policy interfering with the newest and valid policy and fix for default values on the creation form

This commit is contained in:
carlosmonastyrski
2025-05-29 17:43:47 -03:00
parent fe237fbf4a
commit 5af39b1a40
3 changed files with 28 additions and 5 deletions
@@ -144,5 +144,28 @@ export const accessApprovalPolicyDALFactory = (db: TDbClient) => {
return softDeletedPolicy; return softDeletedPolicy;
}; };
return { ...accessApprovalPolicyOrm, find, findById, softDeleteById }; const findLastValidPolicy = async ({ envId, secretPath }: { envId: string; secretPath: string }, tx?: Knex) => {
try {
const result = await (tx || db.replicaNode())(TableName.AccessApprovalPolicy)
.where(
// eslint-disable-next-line @typescript-eslint/no-misused-promises
buildFindFilter(
{
envId,
secretPath
},
TableName.AccessApprovalPolicy
)
)
.orderBy("deletedAt", "desc")
.orderByRaw(`"deletedAt" IS NULL`)
.first();
return result;
} catch (error) {
throw new DatabaseError({ error, name: "FindLastValidPolicy" });
}
};
return { ...accessApprovalPolicyOrm, find, findById, softDeleteById, findLastValidPolicy };
}; };
@@ -57,7 +57,7 @@ type TSecretApprovalRequestServiceFactoryDep = {
| "findOne" | "findOne"
| "getCount" | "getCount"
>; >;
accessApprovalPolicyDAL: Pick<TAccessApprovalPolicyDALFactory, "findOne" | "find">; accessApprovalPolicyDAL: Pick<TAccessApprovalPolicyDALFactory, "findOne" | "find" | "findLastValidPolicy">;
accessApprovalRequestReviewerDAL: Pick< accessApprovalRequestReviewerDAL: Pick<
TAccessApprovalRequestReviewerDALFactory, TAccessApprovalRequestReviewerDALFactory,
"create" | "find" | "findOne" | "transaction" "create" | "find" | "findOne" | "transaction"
@@ -132,7 +132,7 @@ export const accessApprovalRequestServiceFactory = ({
if (!environment) throw new NotFoundError({ message: `Environment with slug '${envSlug}' not found` }); if (!environment) throw new NotFoundError({ message: `Environment with slug '${envSlug}' not found` });
const policy = await accessApprovalPolicyDAL.findOne({ const policy = await accessApprovalPolicyDAL.findLastValidPolicy({
envId: environment.id, envId: environment.id,
secretPath secretPath
}); });
@@ -45,7 +45,7 @@ const formSchema = z
environment: z.object({ slug: z.string(), name: z.string() }), environment: z.object({ slug: z.string(), name: z.string() }),
name: z.string().optional(), name: z.string().optional(),
secretPath: z.string().optional(), secretPath: z.string().optional(),
approvals: z.number().min(1), approvals: z.number().min(1).default(1),
userApprovers: z userApprovers: z
.object({ type: z.literal(ApproverType.User), id: z.string() }) .object({ type: z.literal(ApproverType.User), id: z.string() })
.array() .array()
@@ -55,7 +55,7 @@ const formSchema = z
.array() .array()
.default([]), .default([]),
policyType: z.nativeEnum(PolicyType), policyType: z.nativeEnum(PolicyType),
enforcementLevel: z.nativeEnum(EnforcementLevel), enforcementLevel: z.nativeEnum(EnforcementLevel).default(EnforcementLevel.Hard),
allowedSelfApprovals: z.boolean().default(true) allowedSelfApprovals: z.boolean().default(true)
}) })
.superRefine((data, ctx) => { .superRefine((data, ctx) => {