feat: added kms deletion on project deletion and removed e2ee blind index upgrade banner

This commit is contained in:
=
2024-07-25 22:24:52 +05:30
parent e210a6a24f
commit 6e7997b1bd
6 changed files with 15 additions and 43 deletions

View File

@@ -102,6 +102,13 @@ export const kmsServiceFactory = ({
return doc;
};
const deleteInternalKms = async (kmsId: string, orgId: string, tx?: Knex) => {
const kms = await kmsDAL.findByIdWithAssociatedKms(kmsId, tx);
if (kms.isExternal) return;
if (kms.orgId !== orgId) throw new BadRequestError({ message: "KMS doesn't belong to organization" });
return kmsDAL.deleteById(kmsId, tx);
};
/*
* Simple encryption service function to do all the encryption tasks in infisical
* This can be even later exposed directly as api for encryption as function
@@ -794,6 +801,7 @@ export const kmsServiceFactory = ({
return {
startService,
generateKmsKey,
deleteInternalKms,
encryptWithKmsKey,
decryptWithKmsKey,
encryptWithInputKey,

View File

@@ -81,6 +81,7 @@ type TProjectServiceFactoryDep = {
| "loadProjectKeyBackup"
| "getKmsById"
| "getProjectSecretManagerKmsKeyId"
| "deleteInternalKms"
>;
};
@@ -337,7 +338,12 @@ export const projectServiceFactory = ({
const deletedProject = await projectDAL.transaction(async (tx) => {
const delProject = await projectDAL.deleteById(project.id, tx);
const projectGhostUser = await projectMembershipDAL.findProjectGhostUser(project.id, tx).catch(() => null);
if (delProject.kmsCertificateKeyId) {
await kmsService.deleteInternalKms(delProject.kmsCertificateKeyId, delProject.orgId, tx);
}
if (delProject.kmsSecretManagerKeyId) {
await kmsService.deleteInternalKms(delProject.kmsSecretManagerKeyId, delProject.orgId, tx);
}
// Delete the org membership for the ghost user if it's found.
if (projectGhostUser) {
await userDAL.deleteById(projectGhostUser.id, tx);