Disallow service token creation based on permission

This commit is contained in:
Maidul Islam
2023-01-31 09:24:55 -08:00
parent cb080b356c
commit 6711979445
@@ -8,6 +8,8 @@ import {
import { import {
SALT_ROUNDS SALT_ROUNDS
} from '../../config'; } from '../../config';
import { userHasWorkspaceAccess } from '../../ee/helpers/checkMembershipPermissions';
import { ABILITY_READ } from '../../variables/organization';
/** /**
* Return service token data associated with service token on request * Return service token data associated with service token on request
@@ -37,6 +39,11 @@ export const createServiceTokenData = async (req: Request, res: Response) => {
expiresIn expiresIn
} = req.body; } = req.body;
const hasAccess = await userHasWorkspaceAccess(req.user, workspaceId, environment, ABILITY_READ)
if (!hasAccess) {
throw UnauthorizedRequestError({ message: "You do not have the necessary permission(s) perform this action" })
}
const secret = crypto.randomBytes(16).toString('hex'); const secret = crypto.randomBytes(16).toString('hex');
const secretHash = await bcrypt.hash(secret, SALT_ROUNDS); const secretHash = await bcrypt.hash(secret, SALT_ROUNDS);
@@ -100,4 +107,8 @@ export const deleteServiceTokenData = async (req: Request, res: Response) => {
return res.status(200).send({ return res.status(200).send({
serviceTokenData serviceTokenData
}); });
} }
function UnauthorizedRequestError(arg0: { message: string; }) {
throw new Error('Function not implemented.');
}