mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
Merge branch 'main' into removing-sentry-logs
This commit is contained in:
@@ -13,13 +13,20 @@ import {
|
|||||||
*/
|
*/
|
||||||
export const getSecretSnapshot = async (req: Request, res: Response) => {
|
export const getSecretSnapshot = async (req: Request, res: Response) => {
|
||||||
const { secretSnapshotId } = req.params;
|
const { secretSnapshotId } = req.params;
|
||||||
|
|
||||||
const secretSnapshot = await SecretSnapshot.findById(secretSnapshotId)
|
const secretSnapshot = await SecretSnapshot.findById(secretSnapshotId)
|
||||||
.lean()
|
.lean()
|
||||||
.populate<{ secretVersions: ISecretVersion[] }>("secretVersions")
|
.populate<{ secretVersions: ISecretVersion[] }>({
|
||||||
|
path: 'secretVersions',
|
||||||
|
populate: {
|
||||||
|
path: 'tags',
|
||||||
|
model: 'Tag'
|
||||||
|
}
|
||||||
|
})
|
||||||
.populate<{ folderVersion: TFolderRootVersionSchema }>("folderVersion");
|
.populate<{ folderVersion: TFolderRootVersionSchema }>("folderVersion");
|
||||||
|
|
||||||
if (!secretSnapshot) throw new Error("Failed to find secret snapshot");
|
if (!secretSnapshot) throw new Error("Failed to find secret snapshot");
|
||||||
|
|
||||||
const folderId = secretSnapshot.folderId;
|
const folderId = secretSnapshot.folderId;
|
||||||
// to show only the folder required secrets
|
// to show only the folder required secrets
|
||||||
secretSnapshot.secretVersions = secretSnapshot.secretVersions.filter(
|
secretSnapshot.secretVersions = secretSnapshot.secretVersions.filter(
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ export interface ISecretVersion {
|
|||||||
keyEncoding: "utf8" | "base64";
|
keyEncoding: "utf8" | "base64";
|
||||||
createdAt: string;
|
createdAt: string;
|
||||||
folder?: string;
|
folder?: string;
|
||||||
|
tags?: string[];
|
||||||
}
|
}
|
||||||
|
|
||||||
const secretVersionSchema = new Schema<ISecretVersion>(
|
const secretVersionSchema = new Schema<ISecretVersion>(
|
||||||
@@ -112,6 +113,11 @@ const secretVersionSchema = new Schema<ISecretVersion>(
|
|||||||
type: String,
|
type: String,
|
||||||
required: true,
|
required: true,
|
||||||
},
|
},
|
||||||
|
tags: {
|
||||||
|
ref: 'Tag',
|
||||||
|
type: [Schema.Types.ObjectId],
|
||||||
|
default: []
|
||||||
|
},
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
timestamps: true,
|
timestamps: true,
|
||||||
|
|||||||
@@ -185,26 +185,56 @@ const generateSecretBlindIndexHelper = async ({
|
|||||||
workspaceId: Types.ObjectId;
|
workspaceId: Types.ObjectId;
|
||||||
}) => {
|
}) => {
|
||||||
// check if workspace blind index data exists
|
// check if workspace blind index data exists
|
||||||
|
const encryptionKey = await getEncryptionKey();
|
||||||
|
const rootEncryptionKey = await getRootEncryptionKey();
|
||||||
|
|
||||||
const secretBlindIndexData = await SecretBlindIndexData.findOne({
|
const secretBlindIndexData = await SecretBlindIndexData.findOne({
|
||||||
workspace: workspaceId,
|
workspace: workspaceId,
|
||||||
});
|
}).select('+algorithm +keyEncoding');
|
||||||
|
|
||||||
if (!secretBlindIndexData) throw SecretBlindIndexDataNotFoundError();
|
if (!secretBlindIndexData) throw SecretBlindIndexDataNotFoundError();
|
||||||
|
|
||||||
// decrypt workspace salt
|
let salt;
|
||||||
const salt = decryptSymmetric128BitHexKeyUTF8({
|
if (
|
||||||
ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
|
rootEncryptionKey &&
|
||||||
iv: secretBlindIndexData.saltIV,
|
secretBlindIndexData.keyEncoding === ENCODING_SCHEME_BASE64
|
||||||
tag: secretBlindIndexData.saltTag,
|
) {
|
||||||
key: await getEncryptionKey(),
|
salt = client.decryptSymmetric(
|
||||||
});
|
secretBlindIndexData.encryptedSaltCiphertext,
|
||||||
|
rootEncryptionKey,
|
||||||
|
secretBlindIndexData.saltIV,
|
||||||
|
secretBlindIndexData.saltTag
|
||||||
|
);
|
||||||
|
|
||||||
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
|
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
|
||||||
secretName,
|
secretName,
|
||||||
salt,
|
salt,
|
||||||
});
|
});
|
||||||
|
|
||||||
return secretBlindIndex;
|
return secretBlindIndex;
|
||||||
|
} else if (
|
||||||
|
encryptionKey &&
|
||||||
|
secretBlindIndexData.keyEncoding === ENCODING_SCHEME_UTF8
|
||||||
|
) {
|
||||||
|
// decrypt workspace salt
|
||||||
|
salt = decryptSymmetric128BitHexKeyUTF8({
|
||||||
|
ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
|
||||||
|
iv: secretBlindIndexData.saltIV,
|
||||||
|
tag: secretBlindIndexData.saltTag,
|
||||||
|
key: encryptionKey,
|
||||||
|
});
|
||||||
|
|
||||||
|
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
|
||||||
|
secretName,
|
||||||
|
salt,
|
||||||
|
});
|
||||||
|
|
||||||
|
return secretBlindIndex;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw InternalServerError({
|
||||||
|
message: 'Failed to generate secret blind index'
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -335,6 +335,33 @@ export const backfillSecretFolders = async () => {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
|
await SecretVersion.updateMany(
|
||||||
|
{
|
||||||
|
folder: {
|
||||||
|
$exists: false,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
$set: {
|
||||||
|
folder: "root",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
// Back fill because tags were missing in secret versions
|
||||||
|
await SecretVersion.updateMany(
|
||||||
|
{
|
||||||
|
tags: {
|
||||||
|
$exists: false,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
$set: {
|
||||||
|
tags: [],
|
||||||
|
},
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
let secretSnapshots = await SecretSnapshot.find({
|
let secretSnapshots = await SecretSnapshot.find({
|
||||||
environment: {
|
environment: {
|
||||||
$exists: false,
|
$exists: false,
|
||||||
@@ -352,12 +379,15 @@ export const backfillSecretFolders = async () => {
|
|||||||
groupSnapByEnv[secVer.environment].push(secVer);
|
groupSnapByEnv[secVer.environment].push(secVer);
|
||||||
});
|
});
|
||||||
|
|
||||||
const newSnapshots = Object.keys(groupSnapByEnv).map((snapEnv) => ({
|
const newSnapshots = Object.keys(groupSnapByEnv).map((snapEnv) => {
|
||||||
...secSnapshot.toObject({ virtuals: false }),
|
const secretIdsOfEnvGroup = groupSnapByEnv[snapEnv] ? groupSnapByEnv[snapEnv].map(secretVersion => secretVersion._id) : []
|
||||||
_id: new Types.ObjectId(),
|
return {
|
||||||
environment: snapEnv,
|
...secSnapshot.toObject({ virtuals: false }),
|
||||||
secretVersions: groupSnapByEnv[snapEnv],
|
_id: new Types.ObjectId(),
|
||||||
}));
|
environment: snapEnv,
|
||||||
|
secretVersions: secretIdsOfEnvGroup,
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
await SecretSnapshot.insertMany(newSnapshots);
|
await SecretSnapshot.insertMany(newSnapshots);
|
||||||
await secSnapshot.delete();
|
await secSnapshot.delete();
|
||||||
|
|||||||
@@ -51,7 +51,6 @@ export const validateClientForWorkspace = async ({
|
|||||||
requiredPermissions?: string[];
|
requiredPermissions?: string[];
|
||||||
requireBlindIndicesEnabled: boolean;
|
requireBlindIndicesEnabled: boolean;
|
||||||
}) => {
|
}) => {
|
||||||
|
|
||||||
const workspace = await Workspace.findById(workspaceId);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
|
|
||||||
if (!workspace) throw WorkspaceNotFoundError({
|
if (!workspace) throw WorkspaceNotFoundError({
|
||||||
|
|||||||
Reference in New Issue
Block a user