mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 22:26:41 +00:00
Merge pull request #4861 from Infisical/ENG-3984
feat(roles): add transparent error message when attempting to delete a role that is used by a membership
This commit is contained in:
@@ -643,7 +643,8 @@ export const registerRoutes = async (
|
|||||||
projectDAL,
|
projectDAL,
|
||||||
identityDAL,
|
identityDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
externalGroupOrgRoleMappingDAL
|
externalGroupOrgRoleMappingDAL,
|
||||||
|
membershipRoleDAL
|
||||||
});
|
});
|
||||||
const additionalPrivilegeService = additionalPrivilegeServiceFactory({
|
const additionalPrivilegeService = additionalPrivilegeServiceFactory({
|
||||||
additionalPrivilegeDAL,
|
additionalPrivilegeDAL,
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import { TPermissionServiceFactory } from "@app/ee/services/permission/permissio
|
|||||||
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
||||||
import { validateHandlebarTemplate } from "@app/lib/template/validate-handlebars";
|
import { validateHandlebarTemplate } from "@app/lib/template/validate-handlebars";
|
||||||
import { UnpackedPermissionSchema, unpackPermissions } from "@app/server/routes/sanitizedSchema/permission";
|
import { UnpackedPermissionSchema, unpackPermissions } from "@app/server/routes/sanitizedSchema/permission";
|
||||||
|
import { TMembershipRoleDALFactory } from "@app/services/membership/membership-role-dal";
|
||||||
|
|
||||||
import { ActorType } from "../auth/auth-type";
|
import { ActorType } from "../auth/auth-type";
|
||||||
import { TExternalGroupOrgRoleMappingDALFactory } from "../external-group-org-role-mapping/external-group-org-role-mapping-dal";
|
import { TExternalGroupOrgRoleMappingDALFactory } from "../external-group-org-role-mapping/external-group-org-role-mapping-dal";
|
||||||
@@ -33,6 +34,7 @@ type TRoleServiceFactoryDep = {
|
|||||||
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission" | "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission" | "getOrgPermission">;
|
||||||
projectDAL: Pick<TProjectDALFactory, "findById">;
|
projectDAL: Pick<TProjectDALFactory, "findById">;
|
||||||
externalGroupOrgRoleMappingDAL: Pick<TExternalGroupOrgRoleMappingDALFactory, "findOne">;
|
externalGroupOrgRoleMappingDAL: Pick<TExternalGroupOrgRoleMappingDALFactory, "findOne">;
|
||||||
|
membershipRoleDAL: Pick<TMembershipRoleDALFactory, "find">;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TRoleServiceFactory = ReturnType<typeof roleServiceFactory>;
|
export type TRoleServiceFactory = ReturnType<typeof roleServiceFactory>;
|
||||||
@@ -43,7 +45,8 @@ export const roleServiceFactory = ({
|
|||||||
projectDAL,
|
projectDAL,
|
||||||
identityDAL,
|
identityDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
externalGroupOrgRoleMappingDAL
|
externalGroupOrgRoleMappingDAL,
|
||||||
|
membershipRoleDAL
|
||||||
}: TRoleServiceFactoryDep) => {
|
}: TRoleServiceFactoryDep) => {
|
||||||
const orgRoleFactory = newOrgRoleFactory({
|
const orgRoleFactory = newOrgRoleFactory({
|
||||||
permissionService,
|
permissionService,
|
||||||
@@ -137,6 +140,23 @@ export const roleServiceFactory = ({
|
|||||||
});
|
});
|
||||||
if (!existingRole) throw new NotFoundError({ message: `Role with ${dto.selector.id} not found` });
|
if (!existingRole) throw new NotFoundError({ message: `Role with ${dto.selector.id} not found` });
|
||||||
|
|
||||||
|
const [roleUsageData] = await membershipRoleDAL.find(
|
||||||
|
{
|
||||||
|
customRoleId: dto.selector.id
|
||||||
|
},
|
||||||
|
{ count: true }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (roleUsageData) {
|
||||||
|
const count = Number.parseInt(roleUsageData.count, 10);
|
||||||
|
if (count > 0) {
|
||||||
|
const plural = count > 1 ? "s" : "";
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Role is assigned to ${count} identity membership${plural}. Re-assign membership role${plural} to delete this role.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
const [role] = await roleDAL.delete({
|
const [role] = await roleDAL.delete({
|
||||||
id: existingRole.id,
|
id: existingRole.id,
|
||||||
[scope.key]: scope.value
|
[scope.key]: scope.value
|
||||||
|
|||||||
Reference in New Issue
Block a user