mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 13:27:46 +00:00
Fix missing membership from SAML mapped groups
This commit is contained in:
@@ -0,0 +1,45 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { AccessScope, TableName } from "../schemas";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
const hasGroupsTable = await knex.schema.hasTable(TableName.Groups);
|
||||||
|
const hasMembershipTable = await knex.schema.hasTable(TableName.Membership);
|
||||||
|
|
||||||
|
if (!hasGroupsTable || !hasMembershipTable) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const groupsWithoutMembership = await knex
|
||||||
|
.select(`${TableName.Groups}.id`, `${TableName.Groups}.orgId`)
|
||||||
|
.from(TableName.Groups)
|
||||||
|
.leftJoin(TableName.Membership, function joinGroupMembership() {
|
||||||
|
this.on(`${TableName.Groups}.id`, "=", `${TableName.Membership}.actorGroupId`);
|
||||||
|
})
|
||||||
|
.whereNull(`${TableName.Membership}.actorGroupId`);
|
||||||
|
|
||||||
|
if (groupsWithoutMembership.length > 0) {
|
||||||
|
const membershipInserts = groupsWithoutMembership.map((group) => ({
|
||||||
|
actorGroupId: group.id,
|
||||||
|
scope: AccessScope.Organization,
|
||||||
|
scopeOrgId: group.orgId,
|
||||||
|
isActive: true
|
||||||
|
}));
|
||||||
|
|
||||||
|
await knex(TableName.Membership).insert(membershipInserts);
|
||||||
|
}
|
||||||
|
|
||||||
|
await knex.schema.alterTable(TableName.Membership, (t) => {
|
||||||
|
t.check(
|
||||||
|
`("actorUserId" IS NOT NULL OR "actorIdentityId" IS NOT NULL OR "actorGroupId" IS NOT NULL)`,
|
||||||
|
undefined,
|
||||||
|
"at_least_one_actor"
|
||||||
|
);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
await knex.schema.alterTable(TableName.Membership, (t) => {
|
||||||
|
t.dropChecks("at_least_one_actor");
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -84,7 +84,7 @@ type TSamlConfigServiceFactoryDep = {
|
|||||||
projectDAL: Pick<TProjectDALFactory, "findById" | "findProjectGhostUser">;
|
projectDAL: Pick<TProjectDALFactory, "findById" | "findProjectGhostUser">;
|
||||||
projectBotDAL: Pick<TProjectBotDALFactory, "findOne">;
|
projectBotDAL: Pick<TProjectBotDALFactory, "findOne">;
|
||||||
projectKeyDAL: Pick<TProjectKeyDALFactory, "find" | "delete" | "findLatestProjectKey" | "insertMany">;
|
projectKeyDAL: Pick<TProjectKeyDALFactory, "find" | "delete" | "findLatestProjectKey" | "insertMany">;
|
||||||
membershipGroupDAL: Pick<TMembershipGroupDALFactory, "find">;
|
membershipGroupDAL: Pick<TMembershipGroupDALFactory, "find" | "create">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export const samlConfigServiceFactory = ({
|
export const samlConfigServiceFactory = ({
|
||||||
@@ -183,6 +183,14 @@ export const samlConfigServiceFactory = ({
|
|||||||
transaction
|
transaction
|
||||||
);
|
);
|
||||||
orgGroupsMap.set(groupName, newGroup);
|
orgGroupsMap.set(groupName, newGroup);
|
||||||
|
await membershipGroupDAL.create(
|
||||||
|
{
|
||||||
|
actorGroupId: newGroup.id,
|
||||||
|
scope: AccessScope.Organization,
|
||||||
|
scopeOrgId: orgId
|
||||||
|
},
|
||||||
|
transaction
|
||||||
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user