mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 18:27:36 +00:00
feat(infisical-pg): fixed v3 raw endpoint auto filling based on service token data single scoped
This commit is contained in:
@@ -1,13 +1,16 @@
|
|||||||
|
import picomatch from "picomatch";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import {
|
import {
|
||||||
SecretApprovalRequestsSchema,
|
SecretApprovalRequestsSchema,
|
||||||
SecretsSchema,
|
SecretsSchema,
|
||||||
SecretTagsSchema,
|
SecretTagsSchema,
|
||||||
SecretType
|
SecretType,
|
||||||
|
ServiceTokenScopes,
|
||||||
} from "@app/db/schemas";
|
} from "@app/db/schemas";
|
||||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
import { CommitType } from "@app/ee/services/secret-approval-request/secret-approval-request-types";
|
import { CommitType } from "@app/ee/services/secret-approval-request/secret-approval-request-types";
|
||||||
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { ActorType, AuthMode } from "@app/services/auth/auth-type";
|
import { ActorType, AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
@@ -19,8 +22,8 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
querystring: z.object({
|
querystring: z.object({
|
||||||
workspaceId: z.string().trim(),
|
workspaceId: z.string().trim().optional(),
|
||||||
environment: z.string().trim(),
|
environment: z.string().trim().optional(),
|
||||||
secretPath: z.string().trim().default("/"),
|
secretPath: z.string().trim().default("/"),
|
||||||
include_imports: z
|
include_imports: z
|
||||||
.enum(["true", "false"])
|
.enum(["true", "false"])
|
||||||
@@ -53,12 +56,26 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
AuthMode.IDENTITY_ACCESS_TOKEN
|
AuthMode.IDENTITY_ACCESS_TOKEN
|
||||||
]),
|
]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
|
// just for delivery hero usecase
|
||||||
|
let {secretPath,environment,workspaceId} = req.query;
|
||||||
|
if(req.auth.actor === ActorType.SERVICE){
|
||||||
|
const scope = ServiceTokenScopes.parse(req.auth.serviceToken.scopes);
|
||||||
|
const isSingleScope = scope.length === 1;
|
||||||
|
if(isSingleScope && !picomatch.scan(scope[0].secretPath).isGlob){
|
||||||
|
secretPath = scope[0].secretPath;
|
||||||
|
environment = scope[0].environment;
|
||||||
|
workspaceId = req.auth.serviceToken.projectId;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if(!workspaceId || !environment) throw new BadRequestError({message:"Missing workspace id or environment"})
|
||||||
|
|
||||||
const { secrets, imports } = await server.services.secret.getSecretsRaw({
|
const { secrets, imports } = await server.services.secret.getSecretsRaw({
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
environment: req.query.environment,
|
environment,
|
||||||
projectId: req.query.workspaceId,
|
projectId: workspaceId as string,
|
||||||
path: req.query.secretPath,
|
path: secretPath,
|
||||||
includeImports: req.query.include_imports
|
includeImports: req.query.include_imports
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -68,7 +85,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
event: {
|
event: {
|
||||||
type: EventType.GET_SECRETS,
|
type: EventType.GET_SECRETS,
|
||||||
metadata: {
|
metadata: {
|
||||||
environment: req.query.environment,
|
environment,
|
||||||
secretPath: req.query.secretPath,
|
secretPath: req.query.secretPath,
|
||||||
numberOfSecrets: secrets.length
|
numberOfSecrets: secrets.length
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user