mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 16:27:46 +00:00
Merge pull request #1834 from Infisical/patch-update-project-identity
patch project identity update
This commit is contained in:
@@ -82,6 +82,7 @@ export const identityProjectServiceFactory = ({
|
|||||||
role,
|
role,
|
||||||
project.id
|
project.id
|
||||||
);
|
);
|
||||||
|
|
||||||
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
|
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
if (!hasPriviledge)
|
if (!hasPriviledge)
|
||||||
throw new ForbiddenRequestError({
|
throw new ForbiddenRequestError({
|
||||||
@@ -135,16 +136,18 @@ export const identityProjectServiceFactory = ({
|
|||||||
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
|
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
const { permission: identityRolePermission } = await permissionService.getProjectPermission(
|
for await (const { role: requestedRoleChange } of roles) {
|
||||||
ActorType.IDENTITY,
|
const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
|
||||||
projectIdentity.identityId,
|
requestedRoleChange,
|
||||||
projectIdentity.projectId,
|
projectId
|
||||||
actorAuthMethod,
|
);
|
||||||
actorOrgId
|
|
||||||
);
|
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, identityRolePermission);
|
|
||||||
if (!hasRequiredPriviledges)
|
if (!hasRequiredPriviledges) {
|
||||||
throw new ForbiddenRequestError({ message: "Failed to delete more privileged identity" });
|
throw new ForbiddenRequestError({ message: "Failed to change to a more privileged role" });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// validate custom roles input
|
// validate custom roles input
|
||||||
const customInputRoles = roles.filter(
|
const customInputRoles = roles.filter(
|
||||||
|
|||||||
Reference in New Issue
Block a user