From 5bb8756c67bc9fb40001903532716adda9278071 Mon Sep 17 00:00:00 2001 From: x032205 Date: Fri, 9 May 2025 01:49:34 -0400 Subject: [PATCH] only list compartments which the user is authorized to 'use vaults' in --- .../app-connection/oci/oci-connection-fns.ts | 22 ++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/backend/src/services/app-connection/oci/oci-connection-fns.ts b/backend/src/services/app-connection/oci/oci-connection-fns.ts index 153e58c98..c93a668d4 100644 --- a/backend/src/services/app-connection/oci/oci-connection-fns.ts +++ b/backend/src/services/app-connection/oci/oci-connection-fns.ts @@ -59,6 +59,9 @@ export const listOCICompartments = async (appConnection: TOCIConnection) => { const provider = await getOCIProvider(appConnection); const identityClient = new identity.IdentityClient({ authenticationDetailsProvider: provider }); + const keyManagementClient = new keymanagement.KmsVaultClient({ + authenticationDetailsProvider: provider + }); const rootCompartment = await identityClient .getTenancy({ @@ -77,7 +80,24 @@ export const listOCICompartments = async (appConnection: TOCIConnection) => { lifecycleState: identity.models.Compartment.LifecycleState.Active }); - return [rootCompartment, ...compartments.items]; + const allCompartments = [rootCompartment, ...compartments.items]; + const filteredCompartments = []; + + for await (const compartment of allCompartments) { + try { + // Check if user can list vaults in this compartment + await keyManagementClient.listVaults({ + compartmentId: compartment.id, + limit: 1 + }); + + filteredCompartments.push(compartment); + } catch (error) { + // Do nothing + } + } + + return filteredCompartments; }; export const listOCIVaults = async (appConnection: TOCIConnection, compartmentOcid: string) => {