misc: addressed review comments

This commit is contained in:
Sheen Capadngan
2025-04-15 22:42:38 +08:00
parent f33a777fae
commit 71c55d5a53
4 changed files with 23 additions and 12 deletions
@@ -31,7 +31,7 @@ import {
type TDynamicSecretLeaseServiceFactoryDep = { type TDynamicSecretLeaseServiceFactoryDep = {
dynamicSecretLeaseDAL: TDynamicSecretLeaseDALFactory; dynamicSecretLeaseDAL: TDynamicSecretLeaseDALFactory;
dynamicSecretDAL: Pick<TDynamicSecretDALFactory, "findOne" | "findOneWithMetadata">; dynamicSecretDAL: Pick<TDynamicSecretDALFactory, "findOne">;
dynamicSecretProviders: Record<DynamicSecretProviders, TDynamicProviderFns>; dynamicSecretProviders: Record<DynamicSecretProviders, TDynamicProviderFns>;
dynamicSecretQueueService: TDynamicSecretLeaseQueueServiceFactory; dynamicSecretQueueService: TDynamicSecretLeaseQueueServiceFactory;
licenseService: Pick<TLicenseServiceFactory, "getPlan">; licenseService: Pick<TLicenseServiceFactory, "getPlan">;
@@ -92,7 +92,7 @@ export const dynamicSecretLeaseServiceFactory = ({
message: `Folder with path '${path}' in environment with slug '${environmentSlug}' not found` message: `Folder with path '${path}' in environment with slug '${environmentSlug}' not found`
}); });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ name, folderId: folder.id }); const dynamicSecretCfg = await dynamicSecretDAL.findOne({ name, folderId: folder.id });
if (!dynamicSecretCfg) if (!dynamicSecretCfg)
throw new NotFoundError({ throw new NotFoundError({
message: `Dynamic secret with name '${name}' in folder with path '${path}' not found` message: `Dynamic secret with name '${name}' in folder with path '${path}' not found`
@@ -188,7 +188,7 @@ export const dynamicSecretLeaseServiceFactory = ({
throw new NotFoundError({ message: `Dynamic secret lease with ID '${leaseId}' not found` }); throw new NotFoundError({ message: `Dynamic secret lease with ID '${leaseId}' not found` });
} }
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ const dynamicSecretCfg = await dynamicSecretDAL.findOne({
id: dynamicSecretLease.dynamicSecretId, id: dynamicSecretLease.dynamicSecretId,
folderId: folder.id folderId: folder.id
}); });
@@ -274,7 +274,7 @@ export const dynamicSecretLeaseServiceFactory = ({
if (!dynamicSecretLease || dynamicSecretLease.dynamicSecret.folderId !== folder.id) if (!dynamicSecretLease || dynamicSecretLease.dynamicSecret.folderId !== folder.id)
throw new NotFoundError({ message: `Dynamic secret lease with ID '${leaseId}' not found` }); throw new NotFoundError({ message: `Dynamic secret lease with ID '${leaseId}' not found` });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ const dynamicSecretCfg = await dynamicSecretDAL.findOne({
id: dynamicSecretLease.dynamicSecretId, id: dynamicSecretLease.dynamicSecretId,
folderId: folder.id folderId: folder.id
}); });
@@ -349,7 +349,7 @@ export const dynamicSecretLeaseServiceFactory = ({
message: `Folder with path '${path}' in environment with slug '${environmentSlug}' not found` message: `Folder with path '${path}' in environment with slug '${environmentSlug}' not found`
}); });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ name, folderId: folder.id }); const dynamicSecretCfg = await dynamicSecretDAL.findOne({ name, folderId: folder.id });
if (!dynamicSecretCfg) if (!dynamicSecretCfg)
throw new NotFoundError({ throw new NotFoundError({
message: `Dynamic secret with name '${name}' in folder with path '${path}' not found` message: `Dynamic secret with name '${name}' in folder with path '${path}' not found`
@@ -398,7 +398,7 @@ export const dynamicSecretLeaseServiceFactory = ({
if (!dynamicSecretLease) if (!dynamicSecretLease)
throw new NotFoundError({ message: `Dynamic secret lease with ID '${leaseId}' not found` }); throw new NotFoundError({ message: `Dynamic secret lease with ID '${leaseId}' not found` });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ const dynamicSecretCfg = await dynamicSecretDAL.findOne({
id: dynamicSecretLease.dynamicSecretId, id: dynamicSecretLease.dynamicSecretId,
folderId: folder.id folderId: folder.id
}); });
@@ -20,7 +20,7 @@ export type TDynamicSecretDALFactory = ReturnType<typeof dynamicSecretDALFactory
export const dynamicSecretDALFactory = (db: TDbClient) => { export const dynamicSecretDALFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.DynamicSecret); const orm = ormify(db, TableName.DynamicSecret);
const findOneWithMetadata = async (filter: TFindFilter<TDynamicSecrets>, tx?: Knex) => { const findOne = async (filter: TFindFilter<TDynamicSecrets>, tx?: Knex) => {
const query = (tx || db.replicaNode())(TableName.DynamicSecret) const query = (tx || db.replicaNode())(TableName.DynamicSecret)
.leftJoin( .leftJoin(
TableName.ResourceMetadata, TableName.ResourceMetadata,
@@ -178,5 +178,5 @@ export const dynamicSecretDALFactory = (db: TDbClient) => {
} }
}; };
return { ...orm, listDynamicSecretsByFolderIds, findOneWithMetadata, findWithMetadata }; return { ...orm, listDynamicSecretsByFolderIds, findOne, findWithMetadata };
}; };
@@ -209,7 +209,7 @@ export const dynamicSecretServiceFactory = ({
if (!folder) if (!folder)
throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` }); throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ name, folderId: folder.id }); const dynamicSecretCfg = await dynamicSecretDAL.findOne({ name, folderId: folder.id });
if (!dynamicSecretCfg) { if (!dynamicSecretCfg) {
throw new NotFoundError({ throw new NotFoundError({
message: `Dynamic secret with name '${name}' in folder '${folder.path}' not found` message: `Dynamic secret with name '${name}' in folder '${folder.path}' not found`
@@ -225,6 +225,17 @@ export const dynamicSecretServiceFactory = ({
}) })
); );
if (metadata) {
ForbiddenError.from(permission).throwUnlessCan(
ProjectPermissionDynamicSecretActions.EditRootCredential,
subject(ProjectPermissionSub.DynamicSecrets, {
environment: environmentSlug,
secretPath: path,
metadata
})
);
}
if (newName) { if (newName) {
const existingDynamicSecret = await dynamicSecretDAL.findOne({ name: newName, folderId: folder.id }); const existingDynamicSecret = await dynamicSecretDAL.findOne({ name: newName, folderId: folder.id });
if (existingDynamicSecret) if (existingDynamicSecret)
@@ -332,7 +343,7 @@ export const dynamicSecretServiceFactory = ({
if (!folder) if (!folder)
throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` }); throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ name, folderId: folder.id }); const dynamicSecretCfg = await dynamicSecretDAL.findOne({ name, folderId: folder.id });
if (!dynamicSecretCfg) { if (!dynamicSecretCfg) {
throw new NotFoundError({ message: `Dynamic secret with name '${name}' in folder '${folder.path}' not found` }); throw new NotFoundError({ message: `Dynamic secret with name '${name}' in folder '${folder.path}' not found` });
} }
@@ -398,7 +409,7 @@ export const dynamicSecretServiceFactory = ({
if (!folder) if (!folder)
throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` }); throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` });
const dynamicSecretCfg = await dynamicSecretDAL.findOneWithMetadata({ name, folderId: folder.id }); const dynamicSecretCfg = await dynamicSecretDAL.findOne({ name, folderId: folder.id });
if (!dynamicSecretCfg) { if (!dynamicSecretCfg) {
throw new NotFoundError({ message: `Dynamic secret with name '${name} in folder '${path}' not found` }); throw new NotFoundError({ message: `Dynamic secret with name '${name} in folder '${path}' not found` });
} }
@@ -529,7 +529,7 @@ const Page = () => {
isProtectedBranch={isProtectedBranch} isProtectedBranch={isProtectedBranch}
/> />
)} )}
{canReadSecret && <SecretNoAccessListView count={noAccessSecretCount} />} {noAccessSecretCount > 0 && <SecretNoAccessListView count={noAccessSecretCount} />}
{!canReadSecret && {!canReadSecret &&
!canReadDynamicSecret && !canReadDynamicSecret &&
!canReadSecretImports && !canReadSecretImports &&