mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 14:28:23 +00:00
Merge pull request #2865 from Infisical/daniel/fix-reminder-cleanup
fix(secret-reminders): proper cleanup on deleted resources
This commit is contained in:
@@ -22,8 +22,10 @@ export const mockQueue = (): TQueueServiceFactory => {
|
|||||||
listen: (name, event) => {
|
listen: (name, event) => {
|
||||||
events[name] = event;
|
events[name] = event;
|
||||||
},
|
},
|
||||||
|
getRepeatableJobs: async () => [],
|
||||||
clearQueue: async () => {},
|
clearQueue: async () => {},
|
||||||
stopJobById: async () => {},
|
stopJobById: async () => {},
|
||||||
stopRepeatableJobByJobId: async () => true
|
stopRepeatableJobByJobId: async () => true,
|
||||||
|
stopRepeatableJobByKey: async () => true
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -20,11 +20,12 @@ export const withTransaction = <K extends object>(db: Knex, dal: K) => ({
|
|||||||
|
|
||||||
export type TFindFilter<R extends object = object> = Partial<R> & {
|
export type TFindFilter<R extends object = object> = Partial<R> & {
|
||||||
$in?: Partial<{ [k in keyof R]: R[k][] }>;
|
$in?: Partial<{ [k in keyof R]: R[k][] }>;
|
||||||
|
$notNull?: Array<keyof R>;
|
||||||
$search?: Partial<{ [k in keyof R]: R[k] }>;
|
$search?: Partial<{ [k in keyof R]: R[k] }>;
|
||||||
$complex?: TKnexDynamicOperator<R>;
|
$complex?: TKnexDynamicOperator<R>;
|
||||||
};
|
};
|
||||||
export const buildFindFilter =
|
export const buildFindFilter =
|
||||||
<R extends object = object>({ $in, $search, $complex, ...filter }: TFindFilter<R>) =>
|
<R extends object = object>({ $in, $notNull, $search, $complex, ...filter }: TFindFilter<R>) =>
|
||||||
(bd: Knex.QueryBuilder<R, R>) => {
|
(bd: Knex.QueryBuilder<R, R>) => {
|
||||||
void bd.where(filter);
|
void bd.where(filter);
|
||||||
if ($in) {
|
if ($in) {
|
||||||
@@ -34,6 +35,13 @@ export const buildFindFilter =
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if ($notNull?.length) {
|
||||||
|
$notNull.forEach((key) => {
|
||||||
|
void bd.whereNotNull(key as never);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
if ($search) {
|
if ($search) {
|
||||||
Object.entries($search).forEach(([key, val]) => {
|
Object.entries($search).forEach(([key, val]) => {
|
||||||
if (val) {
|
if (val) {
|
||||||
|
|||||||
@@ -317,6 +317,13 @@ export const queueServiceFactory = (
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const getRepeatableJobs = (name: QueueName, startOffset?: number, endOffset?: number) => {
|
||||||
|
const q = queueContainer[name];
|
||||||
|
if (!q) throw new Error(`Queue '${name}' not initialized`);
|
||||||
|
|
||||||
|
return q.getRepeatableJobs(startOffset, endOffset);
|
||||||
|
};
|
||||||
|
|
||||||
const stopRepeatableJobByJobId = async <T extends QueueName>(name: T, jobId: string) => {
|
const stopRepeatableJobByJobId = async <T extends QueueName>(name: T, jobId: string) => {
|
||||||
const q = queueContainer[name];
|
const q = queueContainer[name];
|
||||||
const job = await q.getJob(jobId);
|
const job = await q.getJob(jobId);
|
||||||
@@ -326,6 +333,11 @@ export const queueServiceFactory = (
|
|||||||
return q.removeRepeatableByKey(job.repeatJobKey);
|
return q.removeRepeatableByKey(job.repeatJobKey);
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const stopRepeatableJobByKey = async <T extends QueueName>(name: T, repeatJobKey: string) => {
|
||||||
|
const q = queueContainer[name];
|
||||||
|
return q.removeRepeatableByKey(repeatJobKey);
|
||||||
|
};
|
||||||
|
|
||||||
const stopJobById = async <T extends QueueName>(name: T, jobId: string) => {
|
const stopJobById = async <T extends QueueName>(name: T, jobId: string) => {
|
||||||
const q = queueContainer[name];
|
const q = queueContainer[name];
|
||||||
const job = await q.getJob(jobId);
|
const job = await q.getJob(jobId);
|
||||||
@@ -349,8 +361,10 @@ export const queueServiceFactory = (
|
|||||||
shutdown,
|
shutdown,
|
||||||
stopRepeatableJob,
|
stopRepeatableJob,
|
||||||
stopRepeatableJobByJobId,
|
stopRepeatableJobByJobId,
|
||||||
|
stopRepeatableJobByKey,
|
||||||
clearQueue,
|
clearQueue,
|
||||||
stopJobById,
|
stopJobById,
|
||||||
|
getRepeatableJobs,
|
||||||
startPg,
|
startPg,
|
||||||
queuePg
|
queuePg
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -538,7 +538,11 @@ export const registerRoutes = async (
|
|||||||
|
|
||||||
const orgService = orgServiceFactory({
|
const orgService = orgServiceFactory({
|
||||||
userAliasDAL,
|
userAliasDAL,
|
||||||
|
queueService,
|
||||||
identityMetadataDAL,
|
identityMetadataDAL,
|
||||||
|
secretDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
|
folderDAL,
|
||||||
licenseService,
|
licenseService,
|
||||||
samlConfigDAL,
|
samlConfigDAL,
|
||||||
orgRoleDAL,
|
orgRoleDAL,
|
||||||
@@ -559,6 +563,7 @@ export const registerRoutes = async (
|
|||||||
groupDAL,
|
groupDAL,
|
||||||
orgBotDAL,
|
orgBotDAL,
|
||||||
oidcConfigDAL,
|
oidcConfigDAL,
|
||||||
|
loginService,
|
||||||
projectBotService
|
projectBotService
|
||||||
});
|
});
|
||||||
const signupService = authSignupServiceFactory({
|
const signupService = authSignupServiceFactory({
|
||||||
@@ -776,10 +781,58 @@ export const registerRoutes = async (
|
|||||||
projectTemplateDAL
|
projectTemplateDAL
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const integrationAuthService = integrationAuthServiceFactory({
|
||||||
|
integrationAuthDAL,
|
||||||
|
integrationDAL,
|
||||||
|
permissionService,
|
||||||
|
projectBotService,
|
||||||
|
kmsService
|
||||||
|
});
|
||||||
|
|
||||||
|
const secretQueueService = secretQueueFactory({
|
||||||
|
keyStore,
|
||||||
|
queueService,
|
||||||
|
secretDAL,
|
||||||
|
folderDAL,
|
||||||
|
integrationAuthService,
|
||||||
|
projectBotService,
|
||||||
|
integrationDAL,
|
||||||
|
secretImportDAL,
|
||||||
|
projectEnvDAL,
|
||||||
|
webhookDAL,
|
||||||
|
orgDAL,
|
||||||
|
auditLogService,
|
||||||
|
userDAL,
|
||||||
|
projectMembershipDAL,
|
||||||
|
smtpService,
|
||||||
|
projectDAL,
|
||||||
|
projectBotDAL,
|
||||||
|
secretVersionDAL,
|
||||||
|
secretBlindIndexDAL,
|
||||||
|
secretTagDAL,
|
||||||
|
secretVersionTagDAL,
|
||||||
|
kmsService,
|
||||||
|
secretVersionV2BridgeDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
|
secretVersionTagV2BridgeDAL,
|
||||||
|
secretRotationDAL,
|
||||||
|
integrationAuthDAL,
|
||||||
|
snapshotDAL,
|
||||||
|
snapshotSecretV2BridgeDAL,
|
||||||
|
secretApprovalRequestDAL,
|
||||||
|
projectKeyDAL,
|
||||||
|
projectUserMembershipRoleDAL,
|
||||||
|
orgService
|
||||||
|
});
|
||||||
|
|
||||||
const projectService = projectServiceFactory({
|
const projectService = projectServiceFactory({
|
||||||
permissionService,
|
permissionService,
|
||||||
projectDAL,
|
projectDAL,
|
||||||
|
secretDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
|
queueService,
|
||||||
projectQueue: projectQueueService,
|
projectQueue: projectQueueService,
|
||||||
|
projectBotService,
|
||||||
identityProjectDAL,
|
identityProjectDAL,
|
||||||
identityOrgMembershipDAL,
|
identityOrgMembershipDAL,
|
||||||
projectKeyDAL,
|
projectKeyDAL,
|
||||||
@@ -859,48 +912,6 @@ export const registerRoutes = async (
|
|||||||
projectDAL
|
projectDAL
|
||||||
});
|
});
|
||||||
|
|
||||||
const integrationAuthService = integrationAuthServiceFactory({
|
|
||||||
integrationAuthDAL,
|
|
||||||
integrationDAL,
|
|
||||||
permissionService,
|
|
||||||
projectBotService,
|
|
||||||
kmsService
|
|
||||||
});
|
|
||||||
const secretQueueService = secretQueueFactory({
|
|
||||||
keyStore,
|
|
||||||
queueService,
|
|
||||||
secretDAL,
|
|
||||||
folderDAL,
|
|
||||||
integrationAuthService,
|
|
||||||
projectBotService,
|
|
||||||
integrationDAL,
|
|
||||||
secretImportDAL,
|
|
||||||
projectEnvDAL,
|
|
||||||
webhookDAL,
|
|
||||||
orgDAL,
|
|
||||||
auditLogService,
|
|
||||||
userDAL,
|
|
||||||
projectMembershipDAL,
|
|
||||||
smtpService,
|
|
||||||
projectDAL,
|
|
||||||
projectBotDAL,
|
|
||||||
secretVersionDAL,
|
|
||||||
secretBlindIndexDAL,
|
|
||||||
secretTagDAL,
|
|
||||||
secretVersionTagDAL,
|
|
||||||
kmsService,
|
|
||||||
secretVersionV2BridgeDAL,
|
|
||||||
secretV2BridgeDAL,
|
|
||||||
secretVersionTagV2BridgeDAL,
|
|
||||||
secretRotationDAL,
|
|
||||||
integrationAuthDAL,
|
|
||||||
snapshotDAL,
|
|
||||||
snapshotSecretV2BridgeDAL,
|
|
||||||
secretApprovalRequestDAL,
|
|
||||||
projectKeyDAL,
|
|
||||||
projectUserMembershipRoleDAL,
|
|
||||||
orgService
|
|
||||||
});
|
|
||||||
const secretImportService = secretImportServiceFactory({
|
const secretImportService = secretImportServiceFactory({
|
||||||
licenseService,
|
licenseService,
|
||||||
projectBotService,
|
projectBotService,
|
||||||
@@ -1229,6 +1240,7 @@ export const registerRoutes = async (
|
|||||||
auditLogDAL,
|
auditLogDAL,
|
||||||
queueService,
|
queueService,
|
||||||
secretVersionDAL,
|
secretVersionDAL,
|
||||||
|
secretDAL,
|
||||||
secretFolderVersionDAL: folderVersionDAL,
|
secretFolderVersionDAL: folderVersionDAL,
|
||||||
snapshotDAL,
|
snapshotDAL,
|
||||||
identityAccessTokenDAL,
|
identityAccessTokenDAL,
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ import {
|
|||||||
UsersSchema
|
UsersSchema
|
||||||
} from "@app/db/schemas";
|
} from "@app/db/schemas";
|
||||||
import { ORGANIZATIONS } from "@app/lib/api-docs";
|
import { ORGANIZATIONS } from "@app/lib/api-docs";
|
||||||
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { ActorType, AuthMode } from "@app/services/auth/auth-type";
|
import { ActorType, AuthMode } from "@app/services/auth/auth-type";
|
||||||
@@ -363,21 +364,35 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
organization: OrganizationsSchema
|
organization: OrganizationsSchema,
|
||||||
|
accessToken: z.string()
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY]),
|
||||||
handler: async (req) => {
|
handler: async (req, res) => {
|
||||||
if (req.auth.actor !== ActorType.USER) return;
|
if (req.auth.actor !== ActorType.USER) return;
|
||||||
|
|
||||||
const organization = await server.services.org.deleteOrganizationById(
|
const cfg = getConfig();
|
||||||
req.permission.id,
|
|
||||||
req.params.organizationId,
|
const { organization, tokens } = await server.services.org.deleteOrganizationById({
|
||||||
req.permission.authMethod,
|
userId: req.permission.id,
|
||||||
req.permission.orgId
|
orgId: req.params.organizationId,
|
||||||
);
|
actorAuthMethod: req.permission.authMethod,
|
||||||
return { organization };
|
actorOrgId: req.permission.orgId,
|
||||||
|
authorizationHeader: req.headers.authorization,
|
||||||
|
userAgentHeader: req.headers["user-agent"],
|
||||||
|
ipAddress: req.realIp
|
||||||
|
});
|
||||||
|
|
||||||
|
void res.setCookie("jid", tokens.refreshToken, {
|
||||||
|
httpOnly: true,
|
||||||
|
path: "/",
|
||||||
|
sameSite: "strict",
|
||||||
|
secure: cfg.HTTPS_ENABLED
|
||||||
|
});
|
||||||
|
|
||||||
|
return { organization, accessToken: tokens.accessToken };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -12,9 +12,12 @@ export type TTokenDALFactory = ReturnType<typeof tokenDALFactory>;
|
|||||||
export const tokenDALFactory = (db: TDbClient) => {
|
export const tokenDALFactory = (db: TDbClient) => {
|
||||||
const authOrm = ormify(db, TableName.AuthTokens);
|
const authOrm = ormify(db, TableName.AuthTokens);
|
||||||
|
|
||||||
const findOneTokenSession = async (filter: Partial<TAuthTokenSessions>): Promise<TAuthTokenSessions | undefined> => {
|
const findOneTokenSession = async (
|
||||||
|
filter: Partial<TAuthTokenSessions>,
|
||||||
|
tx?: Knex
|
||||||
|
): Promise<TAuthTokenSessions | undefined> => {
|
||||||
try {
|
try {
|
||||||
const doc = await db.replicaNode()(TableName.AuthTokenSession).where(filter).first();
|
const doc = await (tx || db.replicaNode())(TableName.AuthTokenSession).where(filter).first();
|
||||||
return doc;
|
return doc;
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new DatabaseError({ error, name: "FindOneTokenSession" });
|
throw new DatabaseError({ error, name: "FindOneTokenSession" });
|
||||||
@@ -54,10 +57,11 @@ export const tokenDALFactory = (db: TDbClient) => {
|
|||||||
const insertTokenSession = async (
|
const insertTokenSession = async (
|
||||||
userId: string,
|
userId: string,
|
||||||
ip: string,
|
ip: string,
|
||||||
userAgent: string
|
userAgent: string,
|
||||||
|
tx?: Knex
|
||||||
): Promise<TAuthTokenSessions | undefined> => {
|
): Promise<TAuthTokenSessions | undefined> => {
|
||||||
try {
|
try {
|
||||||
const [session] = await db(TableName.AuthTokenSession)
|
const [session] = await (tx || db)(TableName.AuthTokenSession)
|
||||||
.insert({
|
.insert({
|
||||||
userId,
|
userId,
|
||||||
ip,
|
ip,
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import crypto from "node:crypto";
|
import crypto from "node:crypto";
|
||||||
|
|
||||||
import bcrypt from "bcrypt";
|
import bcrypt from "bcrypt";
|
||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { TAuthTokens, TAuthTokenSessions } from "@app/db/schemas";
|
import { TAuthTokens, TAuthTokenSessions } from "@app/db/schemas";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
@@ -123,14 +124,13 @@ export const tokenServiceFactory = ({ tokenDAL, userDAL, orgMembershipDAL }: TAu
|
|||||||
return deletedToken?.[0];
|
return deletedToken?.[0];
|
||||||
};
|
};
|
||||||
|
|
||||||
const getUserTokenSession = async ({
|
const getUserTokenSession = async (
|
||||||
userId,
|
{ userId, ip, userAgent }: TIssueAuthTokenDTO,
|
||||||
ip,
|
tx?: Knex
|
||||||
userAgent
|
): Promise<TAuthTokenSessions | undefined> => {
|
||||||
}: TIssueAuthTokenDTO): Promise<TAuthTokenSessions | undefined> => {
|
let session = await tokenDAL.findOneTokenSession({ userId, ip, userAgent }, tx);
|
||||||
let session = await tokenDAL.findOneTokenSession({ userId, ip, userAgent });
|
|
||||||
if (!session) {
|
if (!session) {
|
||||||
session = await tokenDAL.insertTokenSession(userId, ip, userAgent);
|
session = await tokenDAL.insertTokenSession(userId, ip, userAgent, tx);
|
||||||
}
|
}
|
||||||
return session;
|
return session;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import bcrypt from "bcrypt";
|
import bcrypt from "bcrypt";
|
||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { TUsers, UserDeviceSchema } from "@app/db/schemas";
|
import { TUsers, UserDeviceSchema } from "@app/db/schemas";
|
||||||
import { isAuthMethodSaml } from "@app/ee/services/permission/permission-fns";
|
import { isAuthMethodSaml } from "@app/ee/services/permission/permission-fns";
|
||||||
@@ -50,13 +51,13 @@ export const authLoginServiceFactory = ({
|
|||||||
* Not exported. This is to update user device list
|
* Not exported. This is to update user device list
|
||||||
* If new device is found. Will be saved and a mail will be send
|
* If new device is found. Will be saved and a mail will be send
|
||||||
*/
|
*/
|
||||||
const updateUserDeviceSession = async (user: TUsers, ip: string, userAgent: string) => {
|
const updateUserDeviceSession = async (user: TUsers, ip: string, userAgent: string, tx?: Knex) => {
|
||||||
const devices = await UserDeviceSchema.parseAsync(user.devices || []);
|
const devices = await UserDeviceSchema.parseAsync(user.devices || []);
|
||||||
const isDeviceSeen = devices.some((device) => device.ip === ip && device.userAgent === userAgent);
|
const isDeviceSeen = devices.some((device) => device.ip === ip && device.userAgent === userAgent);
|
||||||
|
|
||||||
if (!isDeviceSeen) {
|
if (!isDeviceSeen) {
|
||||||
const newDeviceList = devices.concat([{ ip, userAgent }]);
|
const newDeviceList = devices.concat([{ ip, userAgent }]);
|
||||||
await userDAL.updateById(user.id, { devices: JSON.stringify(newDeviceList) });
|
await userDAL.updateById(user.id, { devices: JSON.stringify(newDeviceList) }, tx);
|
||||||
if (user.email) {
|
if (user.email) {
|
||||||
await smtpService.sendMail({
|
await smtpService.sendMail({
|
||||||
template: SmtpTemplates.NewDeviceJoin,
|
template: SmtpTemplates.NewDeviceJoin,
|
||||||
@@ -97,7 +98,8 @@ export const authLoginServiceFactory = ({
|
|||||||
* Check user device and send mail if new device
|
* Check user device and send mail if new device
|
||||||
* generate the auth and refresh token. fn shared by mfa verification and login verification with mfa disabled
|
* generate the auth and refresh token. fn shared by mfa verification and login verification with mfa disabled
|
||||||
*/
|
*/
|
||||||
const generateUserTokens = async ({
|
const generateUserTokens = async (
|
||||||
|
{
|
||||||
user,
|
user,
|
||||||
ip,
|
ip,
|
||||||
userAgent,
|
userAgent,
|
||||||
@@ -113,14 +115,19 @@ export const authLoginServiceFactory = ({
|
|||||||
authMethod: AuthMethod;
|
authMethod: AuthMethod;
|
||||||
isMfaVerified?: boolean;
|
isMfaVerified?: boolean;
|
||||||
mfaMethod?: MfaMethod;
|
mfaMethod?: MfaMethod;
|
||||||
}) => {
|
},
|
||||||
|
tx?: Knex
|
||||||
|
) => {
|
||||||
const cfg = getConfig();
|
const cfg = getConfig();
|
||||||
await updateUserDeviceSession(user, ip, userAgent);
|
await updateUserDeviceSession(user, ip, userAgent, tx);
|
||||||
const tokenSession = await tokenService.getUserTokenSession({
|
const tokenSession = await tokenService.getUserTokenSession(
|
||||||
|
{
|
||||||
userAgent,
|
userAgent,
|
||||||
ip,
|
ip,
|
||||||
userId: user.id
|
userId: user.id
|
||||||
});
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
if (!tokenSession) throw new Error("Failed to create token");
|
if (!tokenSession) throw new Error("Failed to create token");
|
||||||
|
|
||||||
const accessToken = jwt.sign(
|
const accessToken = jwt.sign(
|
||||||
|
|||||||
@@ -31,11 +31,13 @@ import { BadRequestError, ForbiddenRequestError, NotFoundError, UnauthorizedErro
|
|||||||
import { groupBy } from "@app/lib/fn";
|
import { groupBy } from "@app/lib/fn";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
import { isDisposableEmail } from "@app/lib/validator";
|
import { isDisposableEmail } from "@app/lib/validator";
|
||||||
|
import { TQueueServiceFactory } from "@app/queue";
|
||||||
import { getDefaultOrgMembershipRoleForUpdateOrg } from "@app/services/org/org-role-fns";
|
import { getDefaultOrgMembershipRoleForUpdateOrg } from "@app/services/org/org-role-fns";
|
||||||
import { TOrgMembershipDALFactory } from "@app/services/org-membership/org-membership-dal";
|
import { TOrgMembershipDALFactory } from "@app/services/org-membership/org-membership-dal";
|
||||||
import { TUserAliasDALFactory } from "@app/services/user-alias/user-alias-dal";
|
import { TUserAliasDALFactory } from "@app/services/user-alias/user-alias-dal";
|
||||||
|
|
||||||
import { ActorAuthMethod, ActorType, AuthMethod, AuthTokenType } from "../auth/auth-type";
|
import { TAuthLoginFactory } from "../auth/auth-login-service";
|
||||||
|
import { ActorAuthMethod, ActorType, AuthMethod, AuthModeJwtTokenPayload, AuthTokenType } from "../auth/auth-type";
|
||||||
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
|
import { TAuthTokenServiceFactory } from "../auth-token/auth-token-service";
|
||||||
import { TokenType } from "../auth-token/auth-token-types";
|
import { TokenType } from "../auth-token/auth-token-types";
|
||||||
import { TIdentityMetadataDALFactory } from "../identity/identity-metadata-dal";
|
import { TIdentityMetadataDALFactory } from "../identity/identity-metadata-dal";
|
||||||
@@ -47,6 +49,10 @@ import { TProjectKeyDALFactory } from "../project-key/project-key-dal";
|
|||||||
import { TProjectMembershipDALFactory } from "../project-membership/project-membership-dal";
|
import { TProjectMembershipDALFactory } from "../project-membership/project-membership-dal";
|
||||||
import { TProjectUserMembershipRoleDALFactory } from "../project-membership/project-user-membership-role-dal";
|
import { TProjectUserMembershipRoleDALFactory } from "../project-membership/project-user-membership-role-dal";
|
||||||
import { TProjectRoleDALFactory } from "../project-role/project-role-dal";
|
import { TProjectRoleDALFactory } from "../project-role/project-role-dal";
|
||||||
|
import { TSecretDALFactory } from "../secret/secret-dal";
|
||||||
|
import { fnDeleteProjectSecretReminders } from "../secret/secret-fns";
|
||||||
|
import { TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
||||||
|
import { TSecretV2BridgeDALFactory } from "../secret-v2-bridge/secret-v2-bridge-dal";
|
||||||
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
|
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
|
||||||
import { TUserDALFactory } from "../user/user-dal";
|
import { TUserDALFactory } from "../user/user-dal";
|
||||||
import { TIncidentContactsDALFactory } from "./incident-contacts-dal";
|
import { TIncidentContactsDALFactory } from "./incident-contacts-dal";
|
||||||
@@ -69,6 +75,9 @@ import {
|
|||||||
|
|
||||||
type TOrgServiceFactoryDep = {
|
type TOrgServiceFactoryDep = {
|
||||||
userAliasDAL: Pick<TUserAliasDALFactory, "delete">;
|
userAliasDAL: Pick<TUserAliasDALFactory, "delete">;
|
||||||
|
secretDAL: Pick<TSecretDALFactory, "find">;
|
||||||
|
secretV2BridgeDAL: Pick<TSecretV2BridgeDALFactory, "find">;
|
||||||
|
folderDAL: Pick<TSecretFolderDALFactory, "findByProjectId">;
|
||||||
orgDAL: TOrgDALFactory;
|
orgDAL: TOrgDALFactory;
|
||||||
orgBotDAL: TOrgBotDALFactory;
|
orgBotDAL: TOrgBotDALFactory;
|
||||||
orgRoleDAL: TOrgRoleDALFactory;
|
orgRoleDAL: TOrgRoleDALFactory;
|
||||||
@@ -97,6 +106,8 @@ type TOrgServiceFactoryDep = {
|
|||||||
projectBotDAL: Pick<TProjectBotDALFactory, "findOne" | "updateById">;
|
projectBotDAL: Pick<TProjectBotDALFactory, "findOne" | "updateById">;
|
||||||
projectUserMembershipRoleDAL: Pick<TProjectUserMembershipRoleDALFactory, "insertMany" | "create">;
|
projectUserMembershipRoleDAL: Pick<TProjectUserMembershipRoleDALFactory, "insertMany" | "create">;
|
||||||
projectBotService: Pick<TProjectBotServiceFactory, "getBotKey">;
|
projectBotService: Pick<TProjectBotServiceFactory, "getBotKey">;
|
||||||
|
queueService: Pick<TQueueServiceFactory, "stopRepeatableJob">;
|
||||||
|
loginService: Pick<TAuthLoginFactory, "generateUserTokens">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TOrgServiceFactory = ReturnType<typeof orgServiceFactory>;
|
export type TOrgServiceFactory = ReturnType<typeof orgServiceFactory>;
|
||||||
@@ -104,6 +115,9 @@ export type TOrgServiceFactory = ReturnType<typeof orgServiceFactory>;
|
|||||||
export const orgServiceFactory = ({
|
export const orgServiceFactory = ({
|
||||||
userAliasDAL,
|
userAliasDAL,
|
||||||
orgDAL,
|
orgDAL,
|
||||||
|
secretDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
|
folderDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
groupDAL,
|
groupDAL,
|
||||||
orgRoleDAL,
|
orgRoleDAL,
|
||||||
@@ -124,7 +138,9 @@ export const orgServiceFactory = ({
|
|||||||
projectBotDAL,
|
projectBotDAL,
|
||||||
projectUserMembershipRoleDAL,
|
projectUserMembershipRoleDAL,
|
||||||
identityMetadataDAL,
|
identityMetadataDAL,
|
||||||
projectBotService
|
projectBotService,
|
||||||
|
queueService,
|
||||||
|
loginService
|
||||||
}: TOrgServiceFactoryDep) => {
|
}: TOrgServiceFactoryDep) => {
|
||||||
/*
|
/*
|
||||||
* Get organization details by the organization id
|
* Get organization details by the organization id
|
||||||
@@ -419,24 +435,88 @@ export const orgServiceFactory = ({
|
|||||||
/*
|
/*
|
||||||
* Delete organization by id
|
* Delete organization by id
|
||||||
* */
|
* */
|
||||||
const deleteOrganizationById = async (
|
const deleteOrganizationById = async ({
|
||||||
userId: string,
|
userId,
|
||||||
orgId: string,
|
authorizationHeader,
|
||||||
actorAuthMethod: ActorAuthMethod,
|
userAgentHeader,
|
||||||
actorOrgId: string | undefined
|
ipAddress,
|
||||||
) => {
|
orgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
}: {
|
||||||
|
userId: string;
|
||||||
|
authorizationHeader?: string;
|
||||||
|
userAgentHeader?: string;
|
||||||
|
ipAddress: string;
|
||||||
|
orgId: string;
|
||||||
|
actorAuthMethod: ActorAuthMethod;
|
||||||
|
actorOrgId: string | undefined;
|
||||||
|
}) => {
|
||||||
const { membership } = await permissionService.getUserOrgPermission(userId, orgId, actorAuthMethod, actorOrgId);
|
const { membership } = await permissionService.getUserOrgPermission(userId, orgId, actorAuthMethod, actorOrgId);
|
||||||
if ((membership.role as OrgMembershipRole) !== OrgMembershipRole.Admin)
|
if ((membership.role as OrgMembershipRole) !== OrgMembershipRole.Admin) {
|
||||||
throw new ForbiddenRequestError({
|
throw new ForbiddenRequestError({
|
||||||
name: "DeleteOrganizationById",
|
name: "DeleteOrganizationById",
|
||||||
message: "Insufficient privileges"
|
message: "Insufficient privileges"
|
||||||
});
|
});
|
||||||
|
|
||||||
const organization = await orgDAL.deleteById(orgId);
|
|
||||||
if (organization.customerId) {
|
|
||||||
await licenseService.removeOrgCustomer(organization.customerId);
|
|
||||||
}
|
}
|
||||||
return organization;
|
|
||||||
|
if (!authorizationHeader) {
|
||||||
|
throw new UnauthorizedError({ name: "Authorization header not set on request." });
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!userAgentHeader) {
|
||||||
|
throw new BadRequestError({ name: "User agent not set on request." });
|
||||||
|
}
|
||||||
|
|
||||||
|
const cfg = getConfig();
|
||||||
|
const authToken = authorizationHeader.replace("Bearer ", "");
|
||||||
|
|
||||||
|
const decodedToken = jwt.verify(authToken, cfg.AUTH_SECRET) as AuthModeJwtTokenPayload;
|
||||||
|
if (!decodedToken.authMethod) throw new UnauthorizedError({ name: "Auth method not found on existing token" });
|
||||||
|
|
||||||
|
const response = await orgDAL.transaction(async (tx) => {
|
||||||
|
const projects = await projectDAL.find({ orgId }, { tx });
|
||||||
|
|
||||||
|
for await (const project of projects) {
|
||||||
|
await fnDeleteProjectSecretReminders(project.id, {
|
||||||
|
secretDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
|
queueService,
|
||||||
|
projectBotService,
|
||||||
|
folderDAL
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const deletedOrg = await orgDAL.deleteById(orgId, tx);
|
||||||
|
|
||||||
|
if (deletedOrg.customerId) {
|
||||||
|
await licenseService.removeOrgCustomer(deletedOrg.customerId);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Generate new tokens without the organization ID present
|
||||||
|
const user = await userDAL.findById(userId, tx);
|
||||||
|
const { access: accessToken, refresh: refreshToken } = await loginService.generateUserTokens(
|
||||||
|
{
|
||||||
|
user,
|
||||||
|
authMethod: decodedToken.authMethod,
|
||||||
|
ip: ipAddress,
|
||||||
|
userAgent: userAgentHeader,
|
||||||
|
isMfaVerified: decodedToken.isMfaVerified,
|
||||||
|
mfaMethod: decodedToken.mfaMethod
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
|
||||||
|
return {
|
||||||
|
organization: deletedOrg,
|
||||||
|
tokens: {
|
||||||
|
accessToken,
|
||||||
|
refreshToken
|
||||||
|
}
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
return response;
|
||||||
};
|
};
|
||||||
/*
|
/*
|
||||||
* Org membership management
|
* Org membership management
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import { BadRequestError, ForbiddenRequestError, NotFoundError } from "@app/lib/
|
|||||||
import { groupBy } from "@app/lib/fn";
|
import { groupBy } from "@app/lib/fn";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
import { TProjectPermission } from "@app/lib/types";
|
import { TProjectPermission } from "@app/lib/types";
|
||||||
|
import { TQueueServiceFactory } from "@app/queue";
|
||||||
|
|
||||||
import { ActorType } from "../auth/auth-type";
|
import { ActorType } from "../auth/auth-type";
|
||||||
import { TCertificateDALFactory } from "../certificate/certificate-dal";
|
import { TCertificateDALFactory } from "../certificate/certificate-dal";
|
||||||
@@ -28,13 +29,17 @@ import { TOrgServiceFactory } from "../org/org-service";
|
|||||||
import { TPkiAlertDALFactory } from "../pki-alert/pki-alert-dal";
|
import { TPkiAlertDALFactory } from "../pki-alert/pki-alert-dal";
|
||||||
import { TPkiCollectionDALFactory } from "../pki-collection/pki-collection-dal";
|
import { TPkiCollectionDALFactory } from "../pki-collection/pki-collection-dal";
|
||||||
import { TProjectBotDALFactory } from "../project-bot/project-bot-dal";
|
import { TProjectBotDALFactory } from "../project-bot/project-bot-dal";
|
||||||
|
import { TProjectBotServiceFactory } from "../project-bot/project-bot-service";
|
||||||
import { TProjectEnvDALFactory } from "../project-env/project-env-dal";
|
import { TProjectEnvDALFactory } from "../project-env/project-env-dal";
|
||||||
import { TProjectKeyDALFactory } from "../project-key/project-key-dal";
|
import { TProjectKeyDALFactory } from "../project-key/project-key-dal";
|
||||||
import { TProjectMembershipDALFactory } from "../project-membership/project-membership-dal";
|
import { TProjectMembershipDALFactory } from "../project-membership/project-membership-dal";
|
||||||
import { TProjectUserMembershipRoleDALFactory } from "../project-membership/project-user-membership-role-dal";
|
import { TProjectUserMembershipRoleDALFactory } from "../project-membership/project-user-membership-role-dal";
|
||||||
import { TProjectRoleDALFactory } from "../project-role/project-role-dal";
|
import { TProjectRoleDALFactory } from "../project-role/project-role-dal";
|
||||||
import { getPredefinedRoles } from "../project-role/project-role-fns";
|
import { getPredefinedRoles } from "../project-role/project-role-fns";
|
||||||
|
import { TSecretDALFactory } from "../secret/secret-dal";
|
||||||
|
import { fnDeleteProjectSecretReminders } from "../secret/secret-fns";
|
||||||
import { ROOT_FOLDER_NAME, TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
import { ROOT_FOLDER_NAME, TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
||||||
|
import { TSecretV2BridgeDALFactory } from "../secret-v2-bridge/secret-v2-bridge-dal";
|
||||||
import { TProjectSlackConfigDALFactory } from "../slack/project-slack-config-dal";
|
import { TProjectSlackConfigDALFactory } from "../slack/project-slack-config-dal";
|
||||||
import { TSlackIntegrationDALFactory } from "../slack/slack-integration-dal";
|
import { TSlackIntegrationDALFactory } from "../slack/slack-integration-dal";
|
||||||
import { TUserDALFactory } from "../user/user-dal";
|
import { TUserDALFactory } from "../user/user-dal";
|
||||||
@@ -74,7 +79,10 @@ type TProjectServiceFactoryDep = {
|
|||||||
projectDAL: TProjectDALFactory;
|
projectDAL: TProjectDALFactory;
|
||||||
projectQueue: TProjectQueueFactory;
|
projectQueue: TProjectQueueFactory;
|
||||||
userDAL: TUserDALFactory;
|
userDAL: TUserDALFactory;
|
||||||
folderDAL: TSecretFolderDALFactory;
|
projectBotService: Pick<TProjectBotServiceFactory, "getBotKey">;
|
||||||
|
folderDAL: Pick<TSecretFolderDALFactory, "insertMany" | "findByProjectId">;
|
||||||
|
secretDAL: Pick<TSecretDALFactory, "find">;
|
||||||
|
secretV2BridgeDAL: Pick<TSecretV2BridgeDALFactory, "find">;
|
||||||
projectEnvDAL: Pick<TProjectEnvDALFactory, "insertMany" | "find">;
|
projectEnvDAL: Pick<TProjectEnvDALFactory, "insertMany" | "find">;
|
||||||
identityOrgMembershipDAL: TIdentityOrgDALFactory;
|
identityOrgMembershipDAL: TIdentityOrgDALFactory;
|
||||||
identityProjectDAL: TIdentityProjectDALFactory;
|
identityProjectDAL: TIdentityProjectDALFactory;
|
||||||
@@ -92,6 +100,8 @@ type TProjectServiceFactoryDep = {
|
|||||||
permissionService: TPermissionServiceFactory;
|
permissionService: TPermissionServiceFactory;
|
||||||
orgService: Pick<TOrgServiceFactory, "addGhostUser">;
|
orgService: Pick<TOrgServiceFactory, "addGhostUser">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
|
queueService: Pick<TQueueServiceFactory, "stopRepeatableJob">;
|
||||||
|
|
||||||
orgDAL: Pick<TOrgDALFactory, "findOne">;
|
orgDAL: Pick<TOrgDALFactory, "findOne">;
|
||||||
keyStore: Pick<TKeyStoreFactory, "deleteItem">;
|
keyStore: Pick<TKeyStoreFactory, "deleteItem">;
|
||||||
projectBotDAL: Pick<TProjectBotDALFactory, "create">;
|
projectBotDAL: Pick<TProjectBotDALFactory, "create">;
|
||||||
@@ -112,9 +122,13 @@ export type TProjectServiceFactory = ReturnType<typeof projectServiceFactory>;
|
|||||||
|
|
||||||
export const projectServiceFactory = ({
|
export const projectServiceFactory = ({
|
||||||
projectDAL,
|
projectDAL,
|
||||||
|
secretDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
projectQueue,
|
projectQueue,
|
||||||
projectKeyDAL,
|
projectKeyDAL,
|
||||||
permissionService,
|
permissionService,
|
||||||
|
queueService,
|
||||||
|
projectBotService,
|
||||||
orgDAL,
|
orgDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
folderDAL,
|
folderDAL,
|
||||||
@@ -424,6 +438,14 @@ export const projectServiceFactory = ({
|
|||||||
await userDAL.deleteById(projectGhostUser.id, tx);
|
await userDAL.deleteById(projectGhostUser.id, tx);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
await fnDeleteProjectSecretReminders(project.id, {
|
||||||
|
secretDAL,
|
||||||
|
secretV2BridgeDAL,
|
||||||
|
queueService,
|
||||||
|
projectBotService,
|
||||||
|
folderDAL
|
||||||
|
});
|
||||||
|
|
||||||
return delProject;
|
return delProject;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import { QueueJobs, QueueName, TQueueServiceFactory } from "@app/queue";
|
|||||||
|
|
||||||
import { TIdentityAccessTokenDALFactory } from "../identity-access-token/identity-access-token-dal";
|
import { TIdentityAccessTokenDALFactory } from "../identity-access-token/identity-access-token-dal";
|
||||||
import { TIdentityUaClientSecretDALFactory } from "../identity-ua/identity-ua-client-secret-dal";
|
import { TIdentityUaClientSecretDALFactory } from "../identity-ua/identity-ua-client-secret-dal";
|
||||||
|
import { TSecretDALFactory } from "../secret/secret-dal";
|
||||||
import { TSecretVersionDALFactory } from "../secret/secret-version-dal";
|
import { TSecretVersionDALFactory } from "../secret/secret-version-dal";
|
||||||
import { TSecretFolderVersionDALFactory } from "../secret-folder/secret-folder-version-dal";
|
import { TSecretFolderVersionDALFactory } from "../secret-folder/secret-folder-version-dal";
|
||||||
import { TSecretSharingDALFactory } from "../secret-sharing/secret-sharing-dal";
|
import { TSecretSharingDALFactory } from "../secret-sharing/secret-sharing-dal";
|
||||||
@@ -16,6 +17,7 @@ type TDailyResourceCleanUpQueueServiceFactoryDep = {
|
|||||||
identityUniversalAuthClientSecretDAL: Pick<TIdentityUaClientSecretDALFactory, "removeExpiredClientSecrets">;
|
identityUniversalAuthClientSecretDAL: Pick<TIdentityUaClientSecretDALFactory, "removeExpiredClientSecrets">;
|
||||||
secretVersionDAL: Pick<TSecretVersionDALFactory, "pruneExcessVersions">;
|
secretVersionDAL: Pick<TSecretVersionDALFactory, "pruneExcessVersions">;
|
||||||
secretVersionV2DAL: Pick<TSecretVersionV2DALFactory, "pruneExcessVersions">;
|
secretVersionV2DAL: Pick<TSecretVersionV2DALFactory, "pruneExcessVersions">;
|
||||||
|
secretDAL: Pick<TSecretDALFactory, "pruneSecretReminders">;
|
||||||
secretFolderVersionDAL: Pick<TSecretFolderVersionDALFactory, "pruneExcessVersions">;
|
secretFolderVersionDAL: Pick<TSecretFolderVersionDALFactory, "pruneExcessVersions">;
|
||||||
snapshotDAL: Pick<TSnapshotDALFactory, "pruneExcessSnapshots">;
|
snapshotDAL: Pick<TSnapshotDALFactory, "pruneExcessSnapshots">;
|
||||||
secretSharingDAL: Pick<TSecretSharingDALFactory, "pruneExpiredSharedSecrets">;
|
secretSharingDAL: Pick<TSecretSharingDALFactory, "pruneExpiredSharedSecrets">;
|
||||||
@@ -30,6 +32,7 @@ export const dailyResourceCleanUpQueueServiceFactory = ({
|
|||||||
snapshotDAL,
|
snapshotDAL,
|
||||||
secretVersionDAL,
|
secretVersionDAL,
|
||||||
secretFolderVersionDAL,
|
secretFolderVersionDAL,
|
||||||
|
secretDAL,
|
||||||
identityAccessTokenDAL,
|
identityAccessTokenDAL,
|
||||||
secretSharingDAL,
|
secretSharingDAL,
|
||||||
secretVersionV2DAL,
|
secretVersionV2DAL,
|
||||||
@@ -37,6 +40,7 @@ export const dailyResourceCleanUpQueueServiceFactory = ({
|
|||||||
}: TDailyResourceCleanUpQueueServiceFactoryDep) => {
|
}: TDailyResourceCleanUpQueueServiceFactoryDep) => {
|
||||||
queueService.start(QueueName.DailyResourceCleanUp, async () => {
|
queueService.start(QueueName.DailyResourceCleanUp, async () => {
|
||||||
logger.info(`${QueueName.DailyResourceCleanUp}: queue task started`);
|
logger.info(`${QueueName.DailyResourceCleanUp}: queue task started`);
|
||||||
|
await secretDAL.pruneSecretReminders(queueService);
|
||||||
await auditLogDAL.pruneAuditLog();
|
await auditLogDAL.pruneAuditLog();
|
||||||
await identityAccessTokenDAL.removeExpiredTokens();
|
await identityAccessTokenDAL.removeExpiredTokens();
|
||||||
await identityUniversalAuthClientSecretDAL.removeExpiredClientSecrets();
|
await identityUniversalAuthClientSecretDAL.removeExpiredClientSecrets();
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ import { TDbClient } from "@app/db";
|
|||||||
import { SecretsSchema, SecretType, TableName, TSecrets, TSecretsUpdate } from "@app/db/schemas";
|
import { SecretsSchema, SecretType, TableName, TSecrets, TSecretsUpdate } from "@app/db/schemas";
|
||||||
import { BadRequestError, DatabaseError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError, DatabaseError, NotFoundError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
|
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName, TQueueServiceFactory } from "@app/queue";
|
||||||
|
|
||||||
export type TSecretDALFactory = ReturnType<typeof secretDALFactory>;
|
export type TSecretDALFactory = ReturnType<typeof secretDALFactory>;
|
||||||
|
|
||||||
@@ -339,6 +341,94 @@ export const secretDALFactory = (db: TDbClient) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const pruneSecretReminders = async (queueService: TQueueServiceFactory) => {
|
||||||
|
const REMINDER_PRUNE_BATCH_SIZE = 5_000;
|
||||||
|
const MAX_RETRY_ON_FAILURE = 3;
|
||||||
|
let numberOfRetryOnFailure = 0;
|
||||||
|
let deletedReminderCount = 0;
|
||||||
|
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: secret reminders started`);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const repeatableJobs = await queueService.getRepeatableJobs(QueueName.SecretReminder);
|
||||||
|
const reminderJobs = repeatableJobs
|
||||||
|
.map((job) => ({ secretId: job.id?.replace("reminder-", "") as string, jobKey: job.key }))
|
||||||
|
.filter(Boolean);
|
||||||
|
|
||||||
|
if (reminderJobs.length === 0) {
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: no reminder jobs found`);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (let offset = 0; offset < reminderJobs.length; offset += REMINDER_PRUNE_BATCH_SIZE) {
|
||||||
|
try {
|
||||||
|
const batchIds = reminderJobs.slice(offset, offset + REMINDER_PRUNE_BATCH_SIZE).map((r) => r.secretId);
|
||||||
|
|
||||||
|
const payload = {
|
||||||
|
$in: {
|
||||||
|
id: batchIds
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const opts = {
|
||||||
|
limit: REMINDER_PRUNE_BATCH_SIZE
|
||||||
|
};
|
||||||
|
|
||||||
|
// Find existing secrets with pagination
|
||||||
|
// eslint-disable-next-line no-await-in-loop
|
||||||
|
const [secrets, secretsV2] = await Promise.all([
|
||||||
|
ormify(db, TableName.Secret).find(payload, opts),
|
||||||
|
ormify(db, TableName.SecretV2).find(payload, opts)
|
||||||
|
]);
|
||||||
|
|
||||||
|
const foundSecretIds = new Set([
|
||||||
|
...secrets.map((secret) => secret.id),
|
||||||
|
...secretsV2.map((secret) => secret.id)
|
||||||
|
]);
|
||||||
|
|
||||||
|
// Find IDs that don't exist in either table
|
||||||
|
const secretIdsNotFound = batchIds.filter((secretId) => !foundSecretIds.has(secretId));
|
||||||
|
|
||||||
|
// Delete reminders for non-existent secrets
|
||||||
|
for (const secretId of secretIdsNotFound) {
|
||||||
|
const jobKey = reminderJobs.find((r) => r.secretId === secretId)?.jobKey;
|
||||||
|
|
||||||
|
if (jobKey) {
|
||||||
|
// eslint-disable-next-line no-await-in-loop
|
||||||
|
await queueService.stopRepeatableJobByKey(QueueName.SecretReminder, jobKey);
|
||||||
|
deletedReminderCount += 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
numberOfRetryOnFailure = 0;
|
||||||
|
} catch (error) {
|
||||||
|
numberOfRetryOnFailure += 1;
|
||||||
|
logger.error(error, `Failed to process batch at offset ${offset}`);
|
||||||
|
|
||||||
|
if (numberOfRetryOnFailure >= MAX_RETRY_ON_FAILURE) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Retry the current batch
|
||||||
|
offset -= REMINDER_PRUNE_BATCH_SIZE;
|
||||||
|
|
||||||
|
// eslint-disable-next-line no-promise-executor-return, @typescript-eslint/no-loop-func, no-await-in-loop
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 500 * numberOfRetryOnFailure));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Small delay between batches
|
||||||
|
// eslint-disable-next-line no-promise-executor-return, @typescript-eslint/no-loop-func, no-await-in-loop
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 10));
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
logger.error(error, "Failed to complete secret reminder pruning");
|
||||||
|
} finally {
|
||||||
|
logger.info(
|
||||||
|
`${QueueName.DailyResourceCleanUp}: secret reminders completed. Deleted ${deletedReminderCount} reminders`
|
||||||
|
);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
...secretOrm,
|
...secretOrm,
|
||||||
update,
|
update,
|
||||||
@@ -352,6 +442,7 @@ export const secretDALFactory = (db: TDbClient) => {
|
|||||||
findByBlindIndexes,
|
findByBlindIndexes,
|
||||||
upsertSecretReferences,
|
upsertSecretReferences,
|
||||||
findReferencedSecretReferences,
|
findReferencedSecretReferences,
|
||||||
findAllProjectSecretValues
|
findAllProjectSecretValues,
|
||||||
|
pruneSecretReminders
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -19,9 +19,11 @@ import {
|
|||||||
decryptSymmetric128BitHexKeyUTF8,
|
decryptSymmetric128BitHexKeyUTF8,
|
||||||
encryptSymmetric128BitHexKeyUTF8
|
encryptSymmetric128BitHexKeyUTF8
|
||||||
} from "@app/lib/crypto";
|
} from "@app/lib/crypto";
|
||||||
|
import { daysToMillisecond, secondsToMillis } from "@app/lib/dates";
|
||||||
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
||||||
import { groupBy, unique } from "@app/lib/fn";
|
import { groupBy, unique } from "@app/lib/fn";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueJobs, QueueName, TQueueServiceFactory } from "@app/queue";
|
||||||
import {
|
import {
|
||||||
fnSecretBulkInsert as fnSecretV2BridgeBulkInsert,
|
fnSecretBulkInsert as fnSecretV2BridgeBulkInsert,
|
||||||
fnSecretBulkUpdate as fnSecretV2BridgeBulkUpdate,
|
fnSecretBulkUpdate as fnSecretV2BridgeBulkUpdate,
|
||||||
@@ -31,8 +33,10 @@ import {
|
|||||||
import { ActorAuthMethod, ActorType } from "../auth/auth-type";
|
import { ActorAuthMethod, ActorType } from "../auth/auth-type";
|
||||||
import { KmsDataKey } from "../kms/kms-types";
|
import { KmsDataKey } from "../kms/kms-types";
|
||||||
import { getBotKeyFnFactory } from "../project-bot/project-bot-fns";
|
import { getBotKeyFnFactory } from "../project-bot/project-bot-fns";
|
||||||
|
import { TProjectBotServiceFactory } from "../project-bot/project-bot-service";
|
||||||
import { TProjectEnvDALFactory } from "../project-env/project-env-dal";
|
import { TProjectEnvDALFactory } from "../project-env/project-env-dal";
|
||||||
import { TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
import { TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
||||||
|
import { TSecretV2BridgeDALFactory } from "../secret-v2-bridge/secret-v2-bridge-dal";
|
||||||
import { TSecretDALFactory } from "./secret-dal";
|
import { TSecretDALFactory } from "./secret-dal";
|
||||||
import {
|
import {
|
||||||
TCreateManySecretsRawFn,
|
TCreateManySecretsRawFn,
|
||||||
@@ -1138,3 +1142,49 @@ export const decryptSecretWithBot = (
|
|||||||
secretComment
|
secretComment
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
type TFnDeleteProjectSecretReminders = {
|
||||||
|
secretDAL: Pick<TSecretDALFactory, "find">;
|
||||||
|
secretV2BridgeDAL: Pick<TSecretV2BridgeDALFactory, "find">;
|
||||||
|
queueService: Pick<TQueueServiceFactory, "stopRepeatableJob">;
|
||||||
|
projectBotService: Pick<TProjectBotServiceFactory, "getBotKey">;
|
||||||
|
folderDAL: Pick<TSecretFolderDALFactory, "findByProjectId">;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const fnDeleteProjectSecretReminders = async (
|
||||||
|
projectId: string,
|
||||||
|
{ secretDAL, secretV2BridgeDAL, queueService, projectBotService, folderDAL }: TFnDeleteProjectSecretReminders
|
||||||
|
) => {
|
||||||
|
const projectFolders = await folderDAL.findByProjectId(projectId);
|
||||||
|
const { shouldUseSecretV2Bridge } = await projectBotService.getBotKey(projectId, false);
|
||||||
|
|
||||||
|
const projectSecrets = shouldUseSecretV2Bridge
|
||||||
|
? await secretV2BridgeDAL.find({
|
||||||
|
$in: { folderId: projectFolders.map((folder) => folder.id) },
|
||||||
|
$notNull: ["reminderRepeatDays"]
|
||||||
|
})
|
||||||
|
: await secretDAL.find({
|
||||||
|
$in: { folderId: projectFolders.map((folder) => folder.id) },
|
||||||
|
$notNull: ["secretReminderRepeatDays"]
|
||||||
|
});
|
||||||
|
|
||||||
|
const appCfg = getConfig();
|
||||||
|
for await (const secret of projectSecrets) {
|
||||||
|
const repeatDays = shouldUseSecretV2Bridge
|
||||||
|
? (secret as { reminderRepeatDays: number }).reminderRepeatDays
|
||||||
|
: (secret as { secretReminderRepeatDays: number }).secretReminderRepeatDays;
|
||||||
|
|
||||||
|
// We're using the queue service directly to get around conflicting imports.
|
||||||
|
if (repeatDays) {
|
||||||
|
await queueService.stopRepeatableJob(
|
||||||
|
QueueName.SecretReminder,
|
||||||
|
QueueJobs.SecretReminder,
|
||||||
|
{
|
||||||
|
// on prod it this will be in days, in development this will be second
|
||||||
|
every: appCfg.NODE_ENV === "development" ? secondsToMillis(repeatDays) : daysToMillisecond(repeatDays)
|
||||||
|
},
|
||||||
|
`reminder-${secret.id}`
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|||||||
@@ -248,7 +248,9 @@ export const secretQueueFactory = ({
|
|||||||
? secondsToMillis(newSecret.secretReminderRepeatDays)
|
? secondsToMillis(newSecret.secretReminderRepeatDays)
|
||||||
: daysToMillisecond(newSecret.secretReminderRepeatDays),
|
: daysToMillisecond(newSecret.secretReminderRepeatDays),
|
||||||
immediately: true
|
immediately: true
|
||||||
}
|
},
|
||||||
|
removeOnComplete: true,
|
||||||
|
removeOnFail: true
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
|
|||||||
@@ -491,8 +491,8 @@ export const secretServiceFactory = ({
|
|||||||
secretDAL
|
secretDAL
|
||||||
});
|
});
|
||||||
|
|
||||||
const deletedSecret = await secretDAL.transaction(async (tx) =>
|
const deletedSecret = await secretDAL.transaction(async (tx) => {
|
||||||
fnSecretBulkDelete({
|
const secrets = await fnSecretBulkDelete({
|
||||||
projectId,
|
projectId,
|
||||||
folderId,
|
folderId,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -505,8 +505,19 @@ export const secretServiceFactory = ({
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
tx
|
tx
|
||||||
})
|
});
|
||||||
);
|
|
||||||
|
for await (const secret of secrets) {
|
||||||
|
if (secret.secretReminderRepeatDays !== null && secret.secretReminderRepeatDays !== undefined) {
|
||||||
|
await secretQueueService.removeSecretReminder({
|
||||||
|
repeatDays: secret.secretReminderRepeatDays,
|
||||||
|
secretId: secret.id
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return secrets;
|
||||||
|
});
|
||||||
|
|
||||||
if (inputSecret.type === SecretType.Shared) {
|
if (inputSecret.type === SecretType.Shared) {
|
||||||
await snapshotService.performSnapshot(folderId);
|
await snapshotService.performSnapshot(folderId);
|
||||||
@@ -971,8 +982,8 @@ export const secretServiceFactory = ({
|
|||||||
secretDAL
|
secretDAL
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretsDeleted = await secretDAL.transaction(async (tx) =>
|
const secretsDeleted = await secretDAL.transaction(async (tx) => {
|
||||||
fnSecretBulkDelete({
|
const secrets = await fnSecretBulkDelete({
|
||||||
secretDAL,
|
secretDAL,
|
||||||
secretQueueService,
|
secretQueueService,
|
||||||
inputSecrets: inputSecrets.map(({ type, secretName }) => ({
|
inputSecrets: inputSecrets.map(({ type, secretName }) => ({
|
||||||
@@ -983,8 +994,19 @@ export const secretServiceFactory = ({
|
|||||||
folderId,
|
folderId,
|
||||||
actorId,
|
actorId,
|
||||||
tx
|
tx
|
||||||
})
|
});
|
||||||
);
|
|
||||||
|
for await (const secret of secrets) {
|
||||||
|
if (secret.secretReminderRepeatDays !== null && secret.secretReminderRepeatDays !== undefined) {
|
||||||
|
await secretQueueService.removeSecretReminder({
|
||||||
|
repeatDays: secret.secretReminderRepeatDays,
|
||||||
|
secretId: secret.id
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return secrets;
|
||||||
|
});
|
||||||
|
|
||||||
await snapshotService.performSnapshot(folderId);
|
await snapshotService.performSnapshot(folderId);
|
||||||
await secretQueueService.syncSecrets({
|
await secretQueueService.syncSecrets({
|
||||||
|
|||||||
@@ -77,11 +77,16 @@ export const selectOrganization = async (data: {
|
|||||||
export const useSelectOrganization = () => {
|
export const useSelectOrganization = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
return useMutation({
|
return useMutation({
|
||||||
mutationFn: async (details: { organizationId: string; userAgent?: UserAgentType }) => {
|
mutationFn: async (details: {
|
||||||
|
organizationId: string;
|
||||||
|
userAgent?: UserAgentType;
|
||||||
|
forceSetCredentials?: boolean;
|
||||||
|
}) => {
|
||||||
const data = await selectOrganization(details);
|
const data = await selectOrganization(details);
|
||||||
|
|
||||||
// If a custom user agent is set, then this session is meant for another consuming application, not the web application.
|
// If a custom user agent is set, then this session is meant for another consuming application, not the web application.
|
||||||
if (!details.userAgent && !data.isMfaEnabled) {
|
if ((!details.userAgent && !data.isMfaEnabled) || details.forceSetCredentials) {
|
||||||
|
localStorage.setItem("orgData.id", details.organizationId);
|
||||||
SecurityClient.setToken(data.token);
|
SecurityClient.setToken(data.token);
|
||||||
SecurityClient.setProviderAuthToken("");
|
SecurityClient.setProviderAuthToken("");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { useMutation, useQuery, useQueryClient, UseQueryOptions } from "@tanstack/react-query";
|
import { useMutation, useQuery, useQueryClient, UseQueryOptions } from "@tanstack/react-query";
|
||||||
|
|
||||||
|
import SecurityClient from "@app/components/utilities/SecurityClient";
|
||||||
import { apiRequest } from "@app/config/request";
|
import { apiRequest } from "@app/config/request";
|
||||||
import { OrderByDirection } from "@app/hooks/api/generic/types";
|
import { OrderByDirection } from "@app/hooks/api/generic/types";
|
||||||
|
|
||||||
@@ -67,7 +68,7 @@ export const useCreateOrg = (options: { invalidate: boolean } = { invalidate: tr
|
|||||||
mutationFn: async ({ name }: { name: string }) => {
|
mutationFn: async ({ name }: { name: string }) => {
|
||||||
const {
|
const {
|
||||||
data: { organization }
|
data: { organization }
|
||||||
} = await apiRequest.post("/api/v2/organizations", {
|
} = await apiRequest.post<{ organization: { id: string } }>("/api/v2/organizations", {
|
||||||
name
|
name
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -437,10 +438,13 @@ export const useDeleteOrgById = () => {
|
|||||||
return useMutation({
|
return useMutation({
|
||||||
mutationFn: async ({ organizationId }: { organizationId: string }) => {
|
mutationFn: async ({ organizationId }: { organizationId: string }) => {
|
||||||
const {
|
const {
|
||||||
data: { organization }
|
data: { organization, accessToken }
|
||||||
} = await apiRequest.delete<{ organization: Organization }>(
|
} = await apiRequest.delete<{ organization: Organization; accessToken: string }>(
|
||||||
`/api/v2/organizations/${organizationId}`
|
`/api/v2/organizations/${organizationId}`
|
||||||
);
|
);
|
||||||
|
SecurityClient.setToken(accessToken);
|
||||||
|
localStorage.removeItem("orgData.id");
|
||||||
|
|
||||||
return organization;
|
return organization;
|
||||||
},
|
},
|
||||||
onSuccess(_, dto) {
|
onSuccess(_, dto) {
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ import { ProjectType } from "@app/hooks/api/workspace/types";
|
|||||||
import { queryClient } from "@app/reactQuery";
|
import { queryClient } from "@app/reactQuery";
|
||||||
|
|
||||||
export const navigateUserToOrg = async (router: NextRouter, organizationId?: string) => {
|
export const navigateUserToOrg = async (router: NextRouter, organizationId?: string) => {
|
||||||
const userOrgs = await fetchOrganizations();
|
const userOrgs = await fetchOrganizations().catch(() => []);
|
||||||
|
|
||||||
const nonAuthEnforcedOrgs = userOrgs.filter((org) => !org.authEnforced);
|
const nonAuthEnforcedOrgs = userOrgs.filter((org) => !org.authEnforced);
|
||||||
|
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ import z from "zod";
|
|||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { Button, FormControl, Input, Modal, ModalContent } from "@app/components/v2";
|
import { Button, FormControl, Input, Modal, ModalContent } from "@app/components/v2";
|
||||||
import { useCreateOrg, useSelectOrganization } from "@app/hooks/api";
|
import { useCreateOrg, useGetOrganizations, useSelectOrganization } from "@app/hooks/api";
|
||||||
import { ProjectType } from "@app/hooks/api/workspace/types";
|
import { ProjectType } from "@app/hooks/api/workspace/types";
|
||||||
|
|
||||||
const schema = z
|
const schema = z
|
||||||
@@ -23,9 +23,10 @@ interface CreateOrgModalProps {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export const CreateOrgModal: FC<CreateOrgModalProps> = ({ isOpen, onClose }) => {
|
export const CreateOrgModal: FC<CreateOrgModalProps> = ({ isOpen, onClose }) => {
|
||||||
|
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
|
|
||||||
|
const { refetch: refetchOrganizations } = useGetOrganizations();
|
||||||
|
|
||||||
const {
|
const {
|
||||||
control,
|
control,
|
||||||
handleSubmit,
|
handleSubmit,
|
||||||
@@ -50,19 +51,21 @@ export const CreateOrgModal: FC<CreateOrgModalProps> = ({ isOpen, onClose }) =>
|
|||||||
});
|
});
|
||||||
|
|
||||||
await selectOrg({
|
await selectOrg({
|
||||||
organizationId: organization.id
|
organizationId: organization.id,
|
||||||
|
forceSetCredentials: true
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await refetchOrganizations();
|
||||||
|
|
||||||
createNotification({
|
createNotification({
|
||||||
text: "Successfully created organization",
|
text: "Successfully created organization",
|
||||||
type: "success"
|
type: "success"
|
||||||
});
|
});
|
||||||
|
|
||||||
if (router.isReady) router.push(`/org/${organization.id}/${ProjectType.SecretManager}/overview`);
|
if (router.isReady)
|
||||||
|
router.push(`/org/${organization.id}/${ProjectType.SecretManager}/overview`);
|
||||||
else window.location.href = `/org/${organization.id}/${ProjectType.SecretManager}/overview`;
|
else window.location.href = `/org/${organization.id}/${ProjectType.SecretManager}/overview`;
|
||||||
|
|
||||||
localStorage.setItem("orgData.id", organization.id);
|
|
||||||
|
|
||||||
reset();
|
reset();
|
||||||
onClose();
|
onClose();
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
|
|||||||
Reference in New Issue
Block a user