feat: added secret expand option in secrets get API

This commit is contained in:
Sheen Capadngan
2024-05-04 14:42:22 +08:00
parent 87b571d6ff
commit 61ae0e2fc7
4 changed files with 69 additions and 10 deletions
+1
View File
@@ -272,6 +272,7 @@ export const SECRETS = {
export const RAW_SECRETS = { export const RAW_SECRETS = {
LIST: { LIST: {
expand: "Whether or not to expand secret references",
recursive: recursive:
"Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.", "Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.",
workspaceId: "The ID of the project to list secrets from.", workspaceId: "The ID of the project to list secrets from.",
@@ -166,6 +166,11 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
workspaceSlug: z.string().trim().optional().describe(RAW_SECRETS.LIST.workspaceSlug), workspaceSlug: z.string().trim().optional().describe(RAW_SECRETS.LIST.workspaceSlug),
environment: z.string().trim().optional().describe(RAW_SECRETS.LIST.environment), environment: z.string().trim().optional().describe(RAW_SECRETS.LIST.environment),
secretPath: z.string().trim().default("/").transform(removeTrailingSlash).describe(RAW_SECRETS.LIST.secretPath), secretPath: z.string().trim().default("/").transform(removeTrailingSlash).describe(RAW_SECRETS.LIST.secretPath),
expand: z
.enum(["true", "false"])
.default("false")
.transform((value) => value === "true")
.describe(RAW_SECRETS.LIST.expand),
recursive: z recursive: z
.enum(["true", "false"]) .enum(["true", "false"])
.default("false") .default("false")
@@ -233,6 +238,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
actor: req.permission.type, actor: req.permission.type,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
environment, environment,
expand: req.query.expand,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
projectId: workspaceId, projectId: workspaceId,
path: secretPath, path: secretPath,
+61 -10
View File
@@ -27,6 +27,7 @@ import {
fnSecretBlindIndexCheck, fnSecretBlindIndexCheck,
fnSecretBulkInsert, fnSecretBulkInsert,
fnSecretBulkUpdate, fnSecretBulkUpdate,
interpolateSecrets,
recursivelyGetSecretPaths recursivelyGetSecretPaths
} from "./secret-fns"; } from "./secret-fns";
import { TSecretQueueFactory } from "./secret-queue"; import { TSecretQueueFactory } from "./secret-queue";
@@ -885,6 +886,7 @@ export const secretServiceFactory = ({
actorAuthMethod, actorAuthMethod,
environment, environment,
includeImports, includeImports,
expand,
recursive recursive
}: TGetSecretsRawDTO) => { }: TGetSecretsRawDTO) => {
const botKey = await projectBotService.getBotKey(projectId); const botKey = await projectBotService.getBotKey(projectId);
@@ -902,17 +904,66 @@ export const secretServiceFactory = ({
recursive recursive
}); });
return { const decryptedSecrets = secrets.map((el) => decryptSecretRaw(el, botKey));
secrets: secrets.map((el) => decryptSecretRaw(el, botKey)), const decryptedImports = (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({
imports: (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({ ...el,
...el, secrets: importedSecrets.map((sec) =>
secrets: importedSecrets.map((sec) => decryptSecretRaw(
decryptSecretRaw( { ...sec, environment: el.environment, workspace: projectId, secretPath: el.secretPath },
{ ...sec, environment: el.environment, workspace: projectId, secretPath: el.secretPath }, botKey
botKey
)
) )
})) )
}));
if (expand) {
const expandSecrets = interpolateSecrets({
folderDAL,
projectId,
secretDAL,
secretEncKey: botKey
});
const batchSecretsExpand = async (
secretBatch: {
secretKey: string;
secretValue: string;
secretComment?: string;
}[]
) => {
const secretRecord: Record<
string,
{
value: string;
comment?: string;
skipMultilineEncoding?: boolean;
}
> = {};
secretBatch.forEach((decryptedSecret) => {
secretRecord[decryptedSecret.secretKey] = {
value: decryptedSecret.secretValue,
comment: decryptedSecret.secretComment
};
});
await expandSecrets(secretRecord);
secretBatch.forEach((decryptedSecret, index) => {
// eslint-disable-next-line no-param-reassign
secretBatch[index].secretValue = secretRecord[decryptedSecret.secretKey].value;
});
};
// expand secrets
await batchSecretsExpand(decryptedSecrets);
// expand imports by batch
await Promise.all(decryptedImports.map((decryptedImport) => batchSecretsExpand(decryptedImport.secrets)));
}
return {
secrets: decryptedSecrets,
imports: decryptedImports
}; };
}; };
@@ -138,6 +138,7 @@ export type TDeleteBulkSecretDTO = {
} & TProjectPermission; } & TProjectPermission;
export type TGetSecretsRawDTO = { export type TGetSecretsRawDTO = {
expand?: boolean;
path: string; path: string;
environment: string; environment: string;
includeImports?: boolean; includeImports?: boolean;