mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 11:27:32 +00:00
Disallow service token creation based on permission
This commit is contained in:
@@ -8,6 +8,8 @@ import {
|
|||||||
import {
|
import {
|
||||||
SALT_ROUNDS
|
SALT_ROUNDS
|
||||||
} from '../../config';
|
} from '../../config';
|
||||||
|
import { userHasWorkspaceAccess } from '../../ee/helpers/checkMembershipPermissions';
|
||||||
|
import { ABILITY_READ } from '../../variables/organization';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Return service token data associated with service token on request
|
* Return service token data associated with service token on request
|
||||||
@@ -37,6 +39,11 @@ export const createServiceTokenData = async (req: Request, res: Response) => {
|
|||||||
expiresIn
|
expiresIn
|
||||||
} = req.body;
|
} = req.body;
|
||||||
|
|
||||||
|
const hasAccess = await userHasWorkspaceAccess(req.user, workspaceId, environment, ABILITY_READ)
|
||||||
|
if (!hasAccess) {
|
||||||
|
throw UnauthorizedRequestError({ message: "You do not have the necessary permission(s) perform this action" })
|
||||||
|
}
|
||||||
|
|
||||||
const secret = crypto.randomBytes(16).toString('hex');
|
const secret = crypto.randomBytes(16).toString('hex');
|
||||||
const secretHash = await bcrypt.hash(secret, SALT_ROUNDS);
|
const secretHash = await bcrypt.hash(secret, SALT_ROUNDS);
|
||||||
|
|
||||||
@@ -100,4 +107,8 @@ export const deleteServiceTokenData = async (req: Request, res: Response) => {
|
|||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
serviceTokenData
|
serviceTokenData
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function UnauthorizedRequestError(arg0: { message: string; }) {
|
||||||
|
throw new Error('Function not implemented.');
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user