mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 11:27:07 +00:00
Allow getting bot, but not creating
This commit is contained in:
@@ -27,16 +27,6 @@ export const registerProjectBotRouter = async (server: FastifyZodProvider) => {
|
|||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT]),
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const project = await server.services.project.getAProject({
|
|
||||||
actorId: req.permission.id,
|
|
||||||
actor: req.permission.type,
|
|
||||||
projectId: req.params.projectId
|
|
||||||
});
|
|
||||||
|
|
||||||
if (project.version === "v2") {
|
|
||||||
throw new BadRequestError({ message: "Failed to find bot, project has E2EE disabled" });
|
|
||||||
}
|
|
||||||
|
|
||||||
const bot = await server.services.projectBot.findBotByProjectId({
|
const bot = await server.services.projectBot.findBotByProjectId({
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
|
|||||||
@@ -1,23 +1,29 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
|
||||||
import { SecretKeyEncoding } from "@app/db/schemas";
|
import { ProjectVersion, SecretKeyEncoding } from "@app/db/schemas";
|
||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
||||||
import { decryptAsymmetric, generateAsymmetricKeyPair } from "@app/lib/crypto";
|
import { decryptAsymmetric, generateAsymmetricKeyPair } from "@app/lib/crypto";
|
||||||
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
|
||||||
|
import { TProjectDALFactory } from "../project/project-dal";
|
||||||
import { TProjectBotDALFactory } from "./project-bot-dal";
|
import { TProjectBotDALFactory } from "./project-bot-dal";
|
||||||
import { TFindBotByProjectIdDTO, TGetPrivateKeyDTO, TSetActiveStateDTO } from "./project-bot-types";
|
import { TFindBotByProjectIdDTO, TGetPrivateKeyDTO, TSetActiveStateDTO } from "./project-bot-types";
|
||||||
|
|
||||||
type TProjectBotServiceFactoryDep = {
|
type TProjectBotServiceFactoryDep = {
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
|
||||||
|
projectDAL: Pick<TProjectDALFactory, "findById">;
|
||||||
projectBotDAL: TProjectBotDALFactory;
|
projectBotDAL: TProjectBotDALFactory;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TProjectBotServiceFactory = ReturnType<typeof projectBotServiceFactory>;
|
export type TProjectBotServiceFactory = ReturnType<typeof projectBotServiceFactory>;
|
||||||
|
|
||||||
export const projectBotServiceFactory = ({ projectBotDAL, permissionService }: TProjectBotServiceFactoryDep) => {
|
export const projectBotServiceFactory = ({
|
||||||
|
projectBotDAL,
|
||||||
|
projectDAL,
|
||||||
|
permissionService
|
||||||
|
}: TProjectBotServiceFactoryDep) => {
|
||||||
const getBotPrivateKey = ({ bot }: TGetPrivateKeyDTO) =>
|
const getBotPrivateKey = ({ bot }: TGetPrivateKeyDTO) =>
|
||||||
infisicalSymmetricDecrypt({
|
infisicalSymmetricDecrypt({
|
||||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||||
@@ -63,6 +69,12 @@ export const projectBotServiceFactory = ({ projectBotDAL, permissionService }: T
|
|||||||
|
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = infisicalSymmetricEncypt(keys.privateKey);
|
const { iv, tag, ciphertext, encoding, algorithm } = infisicalSymmetricEncypt(keys.privateKey);
|
||||||
|
|
||||||
|
const project = await projectDAL.findById(projectId, tx);
|
||||||
|
|
||||||
|
if (project.version === ProjectVersion.V2) {
|
||||||
|
throw new BadRequestError({ message: "Failed to create bot, project is upgraded." });
|
||||||
|
}
|
||||||
|
|
||||||
return projectBotDAL.create(
|
return projectBotDAL.create(
|
||||||
{
|
{
|
||||||
name: "Infisical Bot",
|
name: "Infisical Bot",
|
||||||
|
|||||||
Reference in New Issue
Block a user