mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 20:26:17 +00:00
feat: fixed missing secret folder and import permission in service token
This commit is contained in:
@@ -694,31 +694,35 @@ export const buildServiceTokenProjectPermission = (
|
|||||||
const canRead = permission.includes("read");
|
const canRead = permission.includes("read");
|
||||||
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
|
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
|
||||||
scopes.forEach(({ secretPath, environment }) => {
|
scopes.forEach(({ secretPath, environment }) => {
|
||||||
if (canWrite) {
|
[ProjectPermissionSub.Secrets, ProjectPermissionSub.SecretImports, ProjectPermissionSub.SecretFolders].forEach(
|
||||||
// TODO: @Akhi
|
(subject) => {
|
||||||
// @ts-expect-error type
|
if (canWrite) {
|
||||||
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Secrets, {
|
// TODO: @Akhi
|
||||||
secretPath: { $glob: secretPath },
|
// @ts-expect-error type
|
||||||
environment
|
can(ProjectPermissionActions.Edit, subject, {
|
||||||
});
|
secretPath: { $glob: secretPath },
|
||||||
// @ts-expect-error type
|
environment
|
||||||
can(ProjectPermissionActions.Create, ProjectPermissionSub.Secrets, {
|
});
|
||||||
secretPath: { $glob: secretPath },
|
// @ts-expect-error type
|
||||||
environment
|
can(ProjectPermissionActions.Create, subject, {
|
||||||
});
|
secretPath: { $glob: secretPath },
|
||||||
// @ts-expect-error type
|
environment
|
||||||
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Secrets, {
|
});
|
||||||
secretPath: { $glob: secretPath },
|
// @ts-expect-error type
|
||||||
environment
|
can(ProjectPermissionActions.Delete, subject, {
|
||||||
});
|
secretPath: { $glob: secretPath },
|
||||||
}
|
environment
|
||||||
if (canRead) {
|
});
|
||||||
// @ts-expect-error type
|
}
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Secrets, {
|
if (canRead) {
|
||||||
secretPath: { $glob: secretPath },
|
// @ts-expect-error type
|
||||||
environment
|
can(ProjectPermissionActions.Read, subject, {
|
||||||
});
|
secretPath: { $glob: secretPath },
|
||||||
}
|
environment
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
return build({ conditionsMatcher });
|
return build({ conditionsMatcher });
|
||||||
|
|||||||
Reference in New Issue
Block a user