mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 01:27:41 +00:00
patch project identity update
This commit is contained in:
@@ -38,6 +38,7 @@ module.exports = {
|
|||||||
"@typescript-eslint/no-empty-function": "off",
|
"@typescript-eslint/no-empty-function": "off",
|
||||||
"@typescript-eslint/no-unsafe-enum-comparison": "off",
|
"@typescript-eslint/no-unsafe-enum-comparison": "off",
|
||||||
"no-void": "off",
|
"no-void": "off",
|
||||||
|
"no-await-in-loop": "off",
|
||||||
"consistent-return": "off", // my style
|
"consistent-return": "off", // my style
|
||||||
"import/order": "off", // for simple-import-order
|
"import/order": "off", // for simple-import-order
|
||||||
"import/prefer-default-export": "off", // why
|
"import/prefer-default-export": "off", // why
|
||||||
|
|||||||
@@ -82,6 +82,7 @@ export const identityProjectServiceFactory = ({
|
|||||||
role,
|
role,
|
||||||
project.id
|
project.id
|
||||||
);
|
);
|
||||||
|
|
||||||
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
|
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
if (!hasPriviledge)
|
if (!hasPriviledge)
|
||||||
throw new ForbiddenRequestError({
|
throw new ForbiddenRequestError({
|
||||||
@@ -135,16 +136,18 @@ export const identityProjectServiceFactory = ({
|
|||||||
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
|
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
const { permission: identityRolePermission } = await permissionService.getProjectPermission(
|
for (const { role: requestedRoleChange } of roles) {
|
||||||
ActorType.IDENTITY,
|
const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
|
||||||
projectIdentity.identityId,
|
requestedRoleChange,
|
||||||
projectIdentity.projectId,
|
projectId
|
||||||
actorAuthMethod,
|
);
|
||||||
actorOrgId
|
|
||||||
);
|
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, identityRolePermission);
|
|
||||||
if (!hasRequiredPriviledges)
|
if (!hasRequiredPriviledges) {
|
||||||
throw new ForbiddenRequestError({ message: "Failed to delete more privileged identity" });
|
throw new ForbiddenRequestError({ message: "Failed to change to a more privileged role" });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// validate custom roles input
|
// validate custom roles input
|
||||||
const customInputRoles = roles.filter(
|
const customInputRoles = roles.filter(
|
||||||
|
|||||||
Reference in New Issue
Block a user