mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 10:28:50 +00:00
Merge pull request #977 from akhilmhdh:feat/permission-patch-2
feat(rbac): removed owner role and changed member permissions
This commit is contained in:
@@ -8,7 +8,7 @@ import {
|
|||||||
} from "../../models";
|
} from "../../models";
|
||||||
import { createOrganization as create } from "../../helpers/organization";
|
import { createOrganization as create } from "../../helpers/organization";
|
||||||
import { addMembershipsOrg } from "../../helpers/membershipOrg";
|
import { addMembershipsOrg } from "../../helpers/membershipOrg";
|
||||||
import { ACCEPTED, OWNER } from "../../variables";
|
import { ACCEPTED, ADMIN } from "../../variables";
|
||||||
import { getLicenseServerUrl, getSiteURL } from "../../config";
|
import { getLicenseServerUrl, getSiteURL } from "../../config";
|
||||||
import { licenseServerKeyRequest } from "../../config/request";
|
import { licenseServerKeyRequest } from "../../config/request";
|
||||||
import { validateRequest } from "../../helpers/validation";
|
import { validateRequest } from "../../helpers/validation";
|
||||||
@@ -55,7 +55,7 @@ export const createOrganization = async (req: Request, res: Response) => {
|
|||||||
await addMembershipsOrg({
|
await addMembershipsOrg({
|
||||||
userIds: [req.user._id.toString()],
|
userIds: [req.user._id.toString()],
|
||||||
organizationId: organization._id.toString(),
|
organizationId: organization._id.toString(),
|
||||||
roles: [OWNER],
|
roles: [ADMIN],
|
||||||
statuses: [ACCEPTED]
|
statuses: [ACCEPTED]
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -55,6 +55,9 @@ export const getSecretsRaw = async (req: Request, res: Response) => {
|
|||||||
secretPath = getFolderWithPathFromId(folder.nodes, folderId).folderPath;
|
secretPath = getFolderWithPathFromId(folder.nodes, folderId).folderPath;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!environment || !workspaceId)
|
||||||
|
throw BadRequestError({ message: "Missing environment or workspace id" });
|
||||||
|
|
||||||
let permissionCheckFn: (env: string, secPath: string) => boolean; // used to pass as callback function to import secret
|
let permissionCheckFn: (env: string, secPath: string) => boolean; // used to pass as callback function to import secret
|
||||||
if (req.user?._id) {
|
if (req.user?._id) {
|
||||||
const { permission } = await getUserProjectPermissions(req.user._id, workspaceId);
|
const { permission } = await getUserProjectPermissions(req.user._id, workspaceId);
|
||||||
|
|||||||
@@ -171,18 +171,6 @@ export const getRoles = async (req: Request, res: Response) => {
|
|||||||
const customRoles = await Role.find({ organization: orgId, isOrgRole, workspace: workspaceId });
|
const customRoles = await Role.find({ organization: orgId, isOrgRole, workspace: workspaceId });
|
||||||
// as this is shared between org and workspace switch the rule set based on it
|
// as this is shared between org and workspace switch the rule set based on it
|
||||||
const roles = [
|
const roles = [
|
||||||
// owner is only in org level role
|
|
||||||
...(isOrgRole
|
|
||||||
? [
|
|
||||||
{
|
|
||||||
_id: "owner",
|
|
||||||
name: "Owner",
|
|
||||||
slug: "owner",
|
|
||||||
description: "Complete administration access over the organization.",
|
|
||||||
permissions: adminPermissions.rules
|
|
||||||
}
|
|
||||||
]
|
|
||||||
: []),
|
|
||||||
{
|
{
|
||||||
_id: "admin",
|
_id: "admin",
|
||||||
name: "Admin",
|
name: "Admin",
|
||||||
@@ -192,7 +180,7 @@ export const getRoles = async (req: Request, res: Response) => {
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
_id: "member",
|
_id: "member",
|
||||||
name: "Member",
|
name: isOrgRole ? "Member" : "Developer",
|
||||||
slug: "member",
|
slug: "member",
|
||||||
description: "Non-administrative role in an organization",
|
description: "Non-administrative role in an organization",
|
||||||
permissions: isOrgRole ? memberPermissions.rules : memberProjectPermissions.rules
|
permissions: isOrgRole ? memberPermissions.rules : memberProjectPermissions.rules
|
||||||
|
|||||||
@@ -1,6 +1,14 @@
|
|||||||
import { Request, Response } from "express";
|
import { Request, Response } from "express";
|
||||||
import { PipelineStage, Types } from "mongoose";
|
import { PipelineStage, Types } from "mongoose";
|
||||||
import { Folder, Membership, Secret, ServiceTokenData, TFolderSchema, User } from "../../../models";
|
import {
|
||||||
|
Folder,
|
||||||
|
Membership,
|
||||||
|
Secret,
|
||||||
|
ServiceTokenData,
|
||||||
|
TFolderSchema,
|
||||||
|
User,
|
||||||
|
Workspace
|
||||||
|
} from "../../../models";
|
||||||
import {
|
import {
|
||||||
ActorType,
|
ActorType,
|
||||||
AuditLog,
|
AuditLog,
|
||||||
@@ -41,6 +49,7 @@ import {
|
|||||||
getUserProjectPermissions
|
getUserProjectPermissions
|
||||||
} from "../../services/ProjectRoleService";
|
} from "../../services/ProjectRoleService";
|
||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
import { BadRequestError } from "../../../utils/errors";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Return secret snapshots for workspace with id [workspaceId]
|
* Return secret snapshots for workspace with id [workspaceId]
|
||||||
@@ -781,7 +790,10 @@ export const addWorkspaceTrustedIp = async (req: Request, res: Response) => {
|
|||||||
ProjectPermissionSub.IpAllowList
|
ProjectPermissionSub.IpAllowList
|
||||||
);
|
);
|
||||||
|
|
||||||
const plan = await EELicenseService.getPlan(req.workspace.organization);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
|
if (!workspace) throw BadRequestError({ message: "Workspace not found" });
|
||||||
|
|
||||||
|
const plan = await EELicenseService.getPlan(workspace.organization);
|
||||||
|
|
||||||
if (!plan.ipAllowlisting)
|
if (!plan.ipAllowlisting)
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
@@ -844,7 +856,10 @@ export const updateWorkspaceTrustedIp = async (req: Request, res: Response) => {
|
|||||||
ProjectPermissionSub.IpAllowList
|
ProjectPermissionSub.IpAllowList
|
||||||
);
|
);
|
||||||
|
|
||||||
const plan = await EELicenseService.getPlan(req.workspace.organization);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
|
if (!workspace) throw BadRequestError({ message: "Workspace not found" });
|
||||||
|
|
||||||
|
const plan = await EELicenseService.getPlan(workspace.organization);
|
||||||
|
|
||||||
if (!plan.ipAllowlisting)
|
if (!plan.ipAllowlisting)
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
@@ -933,7 +948,10 @@ export const deleteWorkspaceTrustedIp = async (req: Request, res: Response) => {
|
|||||||
ProjectPermissionSub.IpAllowList
|
ProjectPermissionSub.IpAllowList
|
||||||
);
|
);
|
||||||
|
|
||||||
const plan = await EELicenseService.getPlan(req.workspace.organization);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
|
if (!workspace) throw BadRequestError({ message: "Workspace not found" });
|
||||||
|
|
||||||
|
const plan = await EELicenseService.getPlan(workspace.organization);
|
||||||
|
|
||||||
if (!plan.ipAllowlisting)
|
if (!plan.ipAllowlisting)
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
|
|||||||
@@ -158,13 +158,39 @@ const buildMemberPermission = () => {
|
|||||||
can(ProjectPermissionActions.Create, ProjectPermissionSub.SecretRollback);
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.SecretRollback);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Member);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Member);
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Role);
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Member);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Integrations);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Integrations);
|
||||||
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Integrations);
|
||||||
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Integrations);
|
||||||
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Integrations);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Webhooks);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Webhooks);
|
||||||
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Webhooks);
|
||||||
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Webhooks);
|
||||||
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Webhooks);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.ServiceTokens);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.ServiceTokens);
|
||||||
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.ServiceTokens);
|
||||||
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.ServiceTokens);
|
||||||
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.ServiceTokens);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Settings);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Settings);
|
||||||
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Settings);
|
||||||
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Settings);
|
||||||
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Settings);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Environments);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Environments);
|
||||||
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Environments);
|
||||||
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Environments);
|
||||||
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Environments);
|
||||||
|
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Tags);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Tags);
|
||||||
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Tags);
|
||||||
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Tags);
|
||||||
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Tags);
|
||||||
|
|
||||||
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Role);
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.AuditLogs);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.AuditLogs);
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.IpAllowList);
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.IpAllowList);
|
||||||
|
|
||||||
|
|||||||
@@ -86,12 +86,17 @@ const buildMemberPermission = () => {
|
|||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.Workspace);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Workspace);
|
||||||
can(OrgPermissionActions.Create, OrgPermissionSubjects.Workspace);
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Workspace);
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.Member);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Member);
|
||||||
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.Member);
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.Settings);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Settings);
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.Billing);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Billing);
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.Sso);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.Sso);
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.IncidentAccount);
|
||||||
|
|
||||||
can(OrgPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
|
can(OrgPermissionActions.Read, OrgPermissionSubjects.SecretScanning);
|
||||||
|
can(OrgPermissionActions.Create, OrgPermissionSubjects.SecretScanning);
|
||||||
|
can(OrgPermissionActions.Edit, OrgPermissionSubjects.SecretScanning);
|
||||||
|
can(OrgPermissionActions.Delete, OrgPermissionSubjects.SecretScanning);
|
||||||
|
|
||||||
return build({ conditionsMatcher });
|
return build({ conditionsMatcher });
|
||||||
};
|
};
|
||||||
@@ -114,8 +119,7 @@ export const getUserOrgPermissions = async (userId: string, orgId: string) => {
|
|||||||
throw UnauthorizedRequestError({ message: "User doesn't belong to organization" });
|
throw UnauthorizedRequestError({ message: "User doesn't belong to organization" });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (membership.role === "admin" || membership.role === "owner")
|
if (membership.role === "admin") return { permission: adminPermissions, membership };
|
||||||
return { permission: adminPermissions, membership };
|
|
||||||
|
|
||||||
if (membership.role === "member") return { permission: memberPermissions, membership };
|
if (membership.role === "member") return { permission: memberPermissions, membership };
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { IUser } from "../models";
|
import { IUser } from "../models";
|
||||||
import { createOrganization } from "./organization";
|
import { createOrganization } from "./organization";
|
||||||
import { addMembershipsOrg } from "./membershipOrg";
|
import { addMembershipsOrg } from "./membershipOrg";
|
||||||
import { ACCEPTED, OWNER } from "../variables";
|
import { ACCEPTED, ADMIN } from "../variables";
|
||||||
import { sendMail } from "../helpers/nodemailer";
|
import { sendMail } from "../helpers/nodemailer";
|
||||||
import { TokenService } from "../services";
|
import { TokenService } from "../services";
|
||||||
import { TOKEN_EMAIL_CONFIRMATION } from "../variables";
|
import { TOKEN_EMAIL_CONFIRMATION } from "../variables";
|
||||||
@@ -14,10 +14,10 @@ import { TOKEN_EMAIL_CONFIRMATION } from "../variables";
|
|||||||
* @returns {Boolean} success - whether or not operation was successful
|
* @returns {Boolean} success - whether or not operation was successful
|
||||||
*/
|
*/
|
||||||
export const sendEmailVerification = async ({ email }: { email: string }) => {
|
export const sendEmailVerification = async ({ email }: { email: string }) => {
|
||||||
const token = await TokenService.createToken({
|
const token = await TokenService.createToken({
|
||||||
type: TOKEN_EMAIL_CONFIRMATION,
|
type: TOKEN_EMAIL_CONFIRMATION,
|
||||||
email,
|
email
|
||||||
});
|
});
|
||||||
|
|
||||||
// send mail
|
// send mail
|
||||||
await sendMail({
|
await sendMail({
|
||||||
@@ -25,8 +25,8 @@ export const sendEmailVerification = async ({ email }: { email: string }) => {
|
|||||||
subjectLine: "Infisical confirmation code",
|
subjectLine: "Infisical confirmation code",
|
||||||
recipients: [email],
|
recipients: [email],
|
||||||
substitutions: {
|
substitutions: {
|
||||||
code: token,
|
code: token
|
||||||
},
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -36,17 +36,11 @@ export const sendEmailVerification = async ({ email }: { email: string }) => {
|
|||||||
* @param {String} obj.email - emai
|
* @param {String} obj.email - emai
|
||||||
* @param {String} obj.code - code that was sent to [email]
|
* @param {String} obj.code - code that was sent to [email]
|
||||||
*/
|
*/
|
||||||
export const checkEmailVerification = async ({
|
export const checkEmailVerification = async ({ email, code }: { email: string; code: string }) => {
|
||||||
email,
|
|
||||||
code,
|
|
||||||
}: {
|
|
||||||
email: string;
|
|
||||||
code: string;
|
|
||||||
}) => {
|
|
||||||
await TokenService.validateToken({
|
await TokenService.validateToken({
|
||||||
type: TOKEN_EMAIL_CONFIRMATION,
|
type: TOKEN_EMAIL_CONFIRMATION,
|
||||||
email,
|
email,
|
||||||
token: code,
|
token: code
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -58,27 +52,27 @@ export const checkEmailVerification = async ({
|
|||||||
* @param {IUser} obj.user - user who we are initializing for
|
* @param {IUser} obj.user - user who we are initializing for
|
||||||
*/
|
*/
|
||||||
export const initializeDefaultOrg = async ({
|
export const initializeDefaultOrg = async ({
|
||||||
organizationName,
|
organizationName,
|
||||||
user,
|
user
|
||||||
}: {
|
}: {
|
||||||
organizationName: string;
|
organizationName: string;
|
||||||
user: IUser;
|
user: IUser;
|
||||||
}) => {
|
}) => {
|
||||||
try {
|
try {
|
||||||
// create organization with user as owner and initialize a free
|
// create organization with user as owner and initialize a free
|
||||||
// subscription
|
// subscription
|
||||||
const organization = await createOrganization({
|
const organization = await createOrganization({
|
||||||
email: user.email,
|
email: user.email,
|
||||||
name: organizationName,
|
name: organizationName
|
||||||
});
|
});
|
||||||
|
|
||||||
await addMembershipsOrg({
|
await addMembershipsOrg({
|
||||||
userIds: [user._id.toString()],
|
userIds: [user._id.toString()],
|
||||||
organizationId: organization._id.toString(),
|
organizationId: organization._id.toString(),
|
||||||
roles: [OWNER],
|
roles: [ADMIN],
|
||||||
statuses: [ACCEPTED],
|
statuses: [ACCEPTED]
|
||||||
});
|
});
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
throw new Error(`Failed to initialize default organization and workspace [err=${err}]`);
|
throw new Error(`Failed to initialize default organization and workspace [err=${err}]`);
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
import { Document, Schema, Types, model } from "mongoose";
|
import { Document, Schema, Types, model } from "mongoose";
|
||||||
import { ACCEPTED, ADMIN, CUSTOM, INVITED, MEMBER, OWNER } from "../variables";
|
import { ACCEPTED, ADMIN, CUSTOM, INVITED, MEMBER } from "../variables";
|
||||||
|
|
||||||
export interface IMembershipOrg extends Document {
|
export interface IMembershipOrg extends Document {
|
||||||
_id: Types.ObjectId;
|
_id: Types.ObjectId;
|
||||||
@@ -26,7 +26,7 @@ const membershipOrgSchema = new Schema(
|
|||||||
},
|
},
|
||||||
role: {
|
role: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: [OWNER, ADMIN, MEMBER, CUSTOM],
|
enum: [ADMIN, MEMBER, CUSTOM],
|
||||||
required: true
|
required: true
|
||||||
},
|
},
|
||||||
status: {
|
status: {
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ import TelemetryService from "../../services/TelemetryService";
|
|||||||
import { sendMail } from "../../helpers";
|
import { sendMail } from "../../helpers";
|
||||||
import GitRisks from "../../ee/models/gitRisks";
|
import GitRisks from "../../ee/models/gitRisks";
|
||||||
import { MembershipOrg, User } from "../../models";
|
import { MembershipOrg, User } from "../../models";
|
||||||
import { ADMIN, OWNER } from "../../variables";
|
import { ADMIN } from "../../variables";
|
||||||
import { convertKeysToLowercase, scanFullRepoContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
import { convertKeysToLowercase, scanFullRepoContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
||||||
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
||||||
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
||||||
@@ -13,7 +13,7 @@ export const githubFullRepositorySecretScan = new Queue("github-full-repository-
|
|||||||
|
|
||||||
type TScanPushEventQueueDetails = {
|
type TScanPushEventQueueDetails = {
|
||||||
organizationId: string,
|
organizationId: string,
|
||||||
installationId: number,
|
installationId: number,
|
||||||
repository: {
|
repository: {
|
||||||
id: number,
|
id: number,
|
||||||
fullName: string,
|
fullName: string,
|
||||||
@@ -24,22 +24,22 @@ githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback
|
|||||||
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
|
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
|
||||||
try {
|
try {
|
||||||
const octokit = new ProbotOctokit({
|
const octokit = new ProbotOctokit({
|
||||||
auth: {
|
auth: {
|
||||||
appId: await getSecretScanningGitAppId(),
|
appId: await getSecretScanningGitAppId(),
|
||||||
privateKey: await getSecretScanningPrivateKey(),
|
privateKey: await getSecretScanningPrivateKey(),
|
||||||
installationId: installationId
|
installationId: installationId
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
const findings : SecretMatch[] = await scanFullRepoContentAndGetFindings(octokit, installationId, repository.fullName)
|
const findings: SecretMatch[] = await scanFullRepoContentAndGetFindings(octokit, installationId, repository.fullName)
|
||||||
for (const finding of findings) {
|
for (const finding of findings) {
|
||||||
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint},
|
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint },
|
||||||
{
|
{
|
||||||
...convertKeysToLowercase(finding),
|
...convertKeysToLowercase(finding),
|
||||||
installationId: installationId,
|
installationId: installationId,
|
||||||
organization: organizationId,
|
organization: organizationId,
|
||||||
repositoryFullName: repository.fullName,
|
repositoryFullName: repository.fullName,
|
||||||
repositoryId: repository.id
|
repositoryId: repository.id
|
||||||
}, {
|
}, {
|
||||||
upsert: true
|
upsert: true
|
||||||
}).lean()
|
}).lean()
|
||||||
}
|
}
|
||||||
@@ -47,10 +47,7 @@ githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback
|
|||||||
// get emails of admins
|
// get emails of admins
|
||||||
const adminsOfWork = await MembershipOrg.find({
|
const adminsOfWork = await MembershipOrg.find({
|
||||||
organization: organizationId,
|
organization: organizationId,
|
||||||
$or: [
|
role: ADMIN,
|
||||||
{ role: OWNER },
|
|
||||||
{ role: ADMIN }
|
|
||||||
]
|
|
||||||
}).lean()
|
}).lean()
|
||||||
|
|
||||||
const userEmails = await User.find({
|
const userEmails = await User.find({
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import TelemetryService from "../../services/TelemetryService";
|
|||||||
import { sendMail } from "../../helpers";
|
import { sendMail } from "../../helpers";
|
||||||
import GitRisks from "../../ee/models/gitRisks";
|
import GitRisks from "../../ee/models/gitRisks";
|
||||||
import { MembershipOrg, User } from "../../models";
|
import { MembershipOrg, User } from "../../models";
|
||||||
import { ADMIN, OWNER } from "../../variables";
|
import { ADMIN } from "../../variables";
|
||||||
import { convertKeysToLowercase, scanContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
import { convertKeysToLowercase, scanContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
||||||
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
||||||
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
||||||
@@ -88,10 +88,7 @@ githubPushEventSecretScan.process(async (job: Job, done: Queue.DoneCallback) =>
|
|||||||
// get emails of admins
|
// get emails of admins
|
||||||
const adminsOfWork = await MembershipOrg.find({
|
const adminsOfWork = await MembershipOrg.find({
|
||||||
organization: organizationId,
|
organization: organizationId,
|
||||||
$or: [
|
role: ADMIN
|
||||||
{ role: OWNER },
|
|
||||||
{ role: ADMIN }
|
|
||||||
]
|
|
||||||
}).lean()
|
}).lean()
|
||||||
|
|
||||||
const userEmails = await User.find({
|
const userEmails = await User.find({
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ import {
|
|||||||
requireAuth,
|
requireAuth,
|
||||||
requireOrganizationAuth
|
requireOrganizationAuth
|
||||||
} from "../../middleware";
|
} from "../../middleware";
|
||||||
import { ACCEPTED, ADMIN, AuthMode, OWNER } from "../../variables";
|
import { ACCEPTED, ADMIN, AuthMode } from "../../variables";
|
||||||
import { organizationsController } from "../../controllers/v2";
|
import { organizationsController } from "../../controllers/v2";
|
||||||
|
|
||||||
// TODO: /POST to create membership
|
// TODO: /POST to create membership
|
||||||
@@ -48,7 +48,7 @@ router.get(
|
|||||||
acceptedAuthModes: [AuthMode.JWT]
|
acceptedAuthModes: [AuthMode.JWT]
|
||||||
}),
|
}),
|
||||||
requireOrganizationAuth({
|
requireOrganizationAuth({
|
||||||
acceptedRoles: [OWNER, ADMIN],
|
acceptedRoles: [ADMIN],
|
||||||
acceptedStatuses: [ACCEPTED]
|
acceptedStatuses: [ACCEPTED]
|
||||||
}),
|
}),
|
||||||
organizationsController.getOrganizationServiceAccounts
|
organizationsController.getOrganizationServiceAccounts
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ import {
|
|||||||
Integration,
|
Integration,
|
||||||
IntegrationAuth,
|
IntegrationAuth,
|
||||||
Membership,
|
Membership,
|
||||||
|
MembershipOrg,
|
||||||
Organization,
|
Organization,
|
||||||
Secret,
|
Secret,
|
||||||
SecretBlindIndexData,
|
SecretBlindIndexData,
|
||||||
@@ -23,12 +24,15 @@ import {
|
|||||||
import { generateKeyPair } from "../../utils/crypto";
|
import { generateKeyPair } from "../../utils/crypto";
|
||||||
import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
|
import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
|
||||||
import {
|
import {
|
||||||
|
ADMIN,
|
||||||
ALGORITHM_AES_256_GCM,
|
ALGORITHM_AES_256_GCM,
|
||||||
ENCODING_SCHEME_BASE64,
|
ENCODING_SCHEME_BASE64,
|
||||||
ENCODING_SCHEME_UTF8,
|
ENCODING_SCHEME_UTF8,
|
||||||
MEMBER,
|
MEMBER,
|
||||||
|
OWNER,
|
||||||
VIEWER
|
VIEWER
|
||||||
} from "../../variables";
|
} from "../../variables";
|
||||||
|
|
||||||
import { InternalServerError } from "../errors";
|
import { InternalServerError } from "../errors";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -691,5 +695,16 @@ export const backfillPermission = async () => {
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
);
|
);
|
||||||
|
|
||||||
|
await MembershipOrg.updateMany(
|
||||||
|
{
|
||||||
|
role: OWNER
|
||||||
|
},
|
||||||
|
{
|
||||||
|
$set: {
|
||||||
|
role: ADMIN
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
console.log("Backfill: Finishing converting old denied permission in workspace to viewers");
|
console.log("Backfill: Finishing converting old denied permission in workspace to viewers");
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -225,8 +225,8 @@ export const GetSecretsV2 = z.object({
|
|||||||
|
|
||||||
export const GetSecretsRawV3 = z.object({
|
export const GetSecretsRawV3 = z.object({
|
||||||
query: z.object({
|
query: z.object({
|
||||||
workspaceId: z.string().trim(),
|
workspaceId: z.string().trim().optional(),
|
||||||
environment: z.string().trim(),
|
environment: z.string().trim().optional(),
|
||||||
secretPath: z.string().trim().default("/"),
|
secretPath: z.string().trim().default("/"),
|
||||||
folderId: z.string().trim().optional(),
|
folderId: z.string().trim().optional(),
|
||||||
include_imports: z
|
include_imports: z
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
// membership roles
|
// membership roles
|
||||||
export const OWNER = "owner";
|
export const OWNER = "owner"; // depreciated
|
||||||
export const ADMIN = "admin";
|
export const ADMIN = "admin";
|
||||||
export const MEMBER = "member";
|
export const MEMBER = "member";
|
||||||
export const VIEWER = "viewer";
|
export const VIEWER = "viewer";
|
||||||
|
|||||||
@@ -16,14 +16,6 @@ export const ProjectPermissionProvider = ({ children }: Props): JSX.Element => {
|
|||||||
const workspaceId = currentWorkspace?._id || "";
|
const workspaceId = currentWorkspace?._id || "";
|
||||||
const { data: permission, isLoading } = useGetUserProjectPermissions({ workspaceId });
|
const { data: permission, isLoading } = useGetUserProjectPermissions({ workspaceId });
|
||||||
|
|
||||||
if (!permission && currentWorkspace) {
|
|
||||||
return (
|
|
||||||
<div className="flex items-center justify-center w-screen h-screen bg-bunker-800">
|
|
||||||
Failed to load user permissions
|
|
||||||
</div>
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
if ((isLoading && currentWorkspace) || isWsLoading) {
|
if ((isLoading && currentWorkspace) || isWsLoading) {
|
||||||
return (
|
return (
|
||||||
<div className="flex items-center justify-center w-screen h-screen bg-bunker-800">
|
<div className="flex items-center justify-center w-screen h-screen bg-bunker-800">
|
||||||
@@ -37,6 +29,14 @@ export const ProjectPermissionProvider = ({ children }: Props): JSX.Element => {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!permission && currentWorkspace) {
|
||||||
|
return (
|
||||||
|
<div className="flex items-center justify-center w-screen h-screen bg-bunker-800">
|
||||||
|
Failed to load user permissions
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<ProjectPermissionContext.Provider value={permission!}>
|
<ProjectPermissionContext.Provider value={permission!}>
|
||||||
{children}
|
{children}
|
||||||
|
|||||||
@@ -138,7 +138,6 @@ export const AppLayout = ({ children }: LayoutProps) => {
|
|||||||
|
|
||||||
const { t } = useTranslation();
|
const { t } = useTranslation();
|
||||||
|
|
||||||
|
|
||||||
const logout = useLogoutUser();
|
const logout = useLogoutUser();
|
||||||
const logOutUser = async () => {
|
const logOutUser = async () => {
|
||||||
try {
|
try {
|
||||||
@@ -488,7 +487,7 @@ export const AppLayout = ({ children }: LayoutProps) => {
|
|||||||
</MenuItem>
|
</MenuItem>
|
||||||
</a>
|
</a>
|
||||||
</Link>
|
</Link>
|
||||||
<Link href={`/project/${currentWorkspace?._id}/audit-logs`} passHref>
|
{/* <Link href={`/project/${currentWorkspace?._id}/audit-logs`} passHref>
|
||||||
<a>
|
<a>
|
||||||
<MenuItem
|
<MenuItem
|
||||||
isSelected={
|
isSelected={
|
||||||
@@ -499,30 +498,7 @@ export const AppLayout = ({ children }: LayoutProps) => {
|
|||||||
Audit Logs
|
Audit Logs
|
||||||
</MenuItem>
|
</MenuItem>
|
||||||
</a>
|
</a>
|
||||||
</Link>
|
|
||||||
{/* <Link href={`/project/${currentWorkspace?._id}/logs`} passHref>
|
|
||||||
<a>
|
|
||||||
<MenuItem
|
|
||||||
isSelected={
|
|
||||||
router.asPath === `/project/${currentWorkspace?._id}/logs`
|
|
||||||
}
|
|
||||||
icon="system-outline-168-view-headline"
|
|
||||||
>
|
|
||||||
Audit Logs
|
|
||||||
</MenuItem>
|
|
||||||
</a>
|
|
||||||
</Link> */}
|
</Link> */}
|
||||||
{/* <Link href={`/project/${currentWorkspace?._id}/secret-scanning`} passHref>
|
|
||||||
<a>
|
|
||||||
<MenuItem
|
|
||||||
isSelected={router.asPath === `/project/${currentWorkspace?._id}/secret-scanning`}
|
|
||||||
// icon={<FontAwesomeIcon icon={faFileLines} size="lg" />}
|
|
||||||
icon="system-outline-82-extension"
|
|
||||||
>
|
|
||||||
Audit Logs
|
|
||||||
</MenuItem>
|
|
||||||
</a>
|
|
||||||
</Link> */}
|
|
||||||
<Link href={`/project/${currentWorkspace?._id}/settings`} passHref>
|
<Link href={`/project/${currentWorkspace?._id}/settings`} passHref>
|
||||||
<a>
|
<a>
|
||||||
<MenuItem
|
<MenuItem
|
||||||
|
|||||||
@@ -1,6 +1,10 @@
|
|||||||
@tailwind base;
|
@tailwind base;
|
||||||
@tailwind components;
|
@tailwind components;
|
||||||
|
|
||||||
|
html {
|
||||||
|
@apply overflow-hidden;
|
||||||
|
}
|
||||||
|
|
||||||
.rdp-day,
|
.rdp-day,
|
||||||
.rdp-nav_button {
|
.rdp-nav_button {
|
||||||
@apply rounded-md hover:text-mineshaft-500;
|
@apply rounded-md hover:text-mineshaft-500;
|
||||||
|
|||||||
@@ -85,7 +85,13 @@ export const IntegrationsPage = withProjectPermission(
|
|||||||
// details: so onsuccessfully deleting an integration auth, immediately integration list is refeteched
|
// details: so onsuccessfully deleting an integration auth, immediately integration list is refeteched
|
||||||
// After the refetch is completed check if its empty. Then set bot active and reset the submit hook
|
// After the refetch is completed check if its empty. Then set bot active and reset the submit hook
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (isDeleteIntegrationAuthSuccess && !isIntegrationFetching && !integrations?.length) {
|
if (
|
||||||
|
isDeleteIntegrationAuthSuccess &&
|
||||||
|
!isIntegrationFetching &&
|
||||||
|
!isIntegrationAuthLoading &&
|
||||||
|
!integrations?.length &&
|
||||||
|
!integrationAuths?.length
|
||||||
|
) {
|
||||||
if (bot?._id)
|
if (bot?._id)
|
||||||
updateBotActiveStatusSync({
|
updateBotActiveStatusSync({
|
||||||
isActive: false,
|
isActive: false,
|
||||||
@@ -94,7 +100,13 @@ export const IntegrationsPage = withProjectPermission(
|
|||||||
});
|
});
|
||||||
resetDeleteIntegrationAuth();
|
resetDeleteIntegrationAuth();
|
||||||
}
|
}
|
||||||
}, [isIntegrationFetching, isDeleteIntegrationAuthSuccess, integrations?.length]);
|
}, [
|
||||||
|
isIntegrationFetching,
|
||||||
|
isDeleteIntegrationAuthSuccess,
|
||||||
|
isIntegrationAuthLoading,
|
||||||
|
integrationAuths?.length,
|
||||||
|
integrations?.length
|
||||||
|
]);
|
||||||
|
|
||||||
const handleProviderIntegration = async (provider: string) => {
|
const handleProviderIntegration = async (provider: string) => {
|
||||||
const selectedCloudIntegration = cloudIntegrations?.find(({ slug }) => provider === slug);
|
const selectedCloudIntegration = cloudIntegrations?.find(({ slug }) => provider === slug);
|
||||||
|
|||||||
-10
@@ -1,4 +1,3 @@
|
|||||||
import { useState } from "react";
|
|
||||||
import { useForm } from "react-hook-form";
|
import { useForm } from "react-hook-form";
|
||||||
import {
|
import {
|
||||||
faArrowLeft,
|
faArrowLeft,
|
||||||
@@ -80,7 +79,6 @@ const SIMPLE_PERMISSION_OPTIONS = [
|
|||||||
] as const;
|
] as const;
|
||||||
|
|
||||||
export const OrgRoleModifySection = ({ role, onGoBack }: Props) => {
|
export const OrgRoleModifySection = ({ role, onGoBack }: Props) => {
|
||||||
const [searchPermission, setSearchPermission] = useState("");
|
|
||||||
const { subscription } = useSubscription();
|
const { subscription } = useSubscription();
|
||||||
const { popUp, handlePopUpToggle, handlePopUpOpen } = usePopUp(["upgradePlan"] as const);
|
const { popUp, handlePopUpToggle, handlePopUpOpen } = usePopUp(["upgradePlan"] as const);
|
||||||
|
|
||||||
@@ -196,14 +194,6 @@ export const OrgRoleModifySection = ({ role, onGoBack }: Props) => {
|
|||||||
<div>
|
<div>
|
||||||
<h2 className="text-xl font-medium">Add Permission</h2>
|
<h2 className="text-xl font-medium">Add Permission</h2>
|
||||||
</div>
|
</div>
|
||||||
<div className="flex-1 max-w-md">
|
|
||||||
<Input
|
|
||||||
value={searchPermission}
|
|
||||||
onChange={(e) => setSearchPermission(e.target.value)}
|
|
||||||
leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />}
|
|
||||||
placeholder="Search permissions..."
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
</div>
|
</div>
|
||||||
<div className="">
|
<div className="">
|
||||||
<WorkspacePermission
|
<WorkspacePermission
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { useCallback, useMemo, useState } from "react";
|
import { useCallback, useMemo, useState } from "react";
|
||||||
import { Controller, useForm } from "react-hook-form";
|
import { Controller, useForm } from "react-hook-form";
|
||||||
import { useTranslation } from "react-i18next";
|
import { useTranslation } from "react-i18next";
|
||||||
|
import Link from "next/link";
|
||||||
import { faMagnifyingGlass, faPlus, faTrash, faUsers } from "@fortawesome/free-solid-svg-icons";
|
import { faMagnifyingGlass, faPlus, faTrash, faUsers } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
import { zodResolver } from "@hookform/resolvers/zod";
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
@@ -359,48 +360,57 @@ export const MemberListTab = ({ roles = [], isRolesLoading }: Props) => {
|
|||||||
title={t("section.members.add-dialog.add-member-to-project") as string}
|
title={t("section.members.add-dialog.add-member-to-project") as string}
|
||||||
subTitle={t("section.members.add-dialog.user-will-email")}
|
subTitle={t("section.members.add-dialog.user-will-email")}
|
||||||
>
|
>
|
||||||
<form onSubmit={handleSubmit(onAddMember)}>
|
{filteredOrgUsers.length ? (
|
||||||
<Controller
|
<form onSubmit={handleSubmit(onAddMember)}>
|
||||||
control={control}
|
<Controller
|
||||||
defaultValue={filteredOrgUsers?.[0]?.user?.email}
|
control={control}
|
||||||
name="email"
|
defaultValue={filteredOrgUsers?.[0]?.user?.email}
|
||||||
render={({ field, fieldState: { error } }) => (
|
name="email"
|
||||||
<FormControl label="Email" isError={Boolean(error)} errorText={error?.message}>
|
render={({ field, fieldState: { error } }) => (
|
||||||
<Select
|
<FormControl label="Email" isError={Boolean(error)} errorText={error?.message}>
|
||||||
position="popper"
|
<Select
|
||||||
className="w-full"
|
position="popper"
|
||||||
defaultValue={filteredOrgUsers?.[0]?.user?.email}
|
className="w-full"
|
||||||
value={field.value}
|
defaultValue={filteredOrgUsers?.[0]?.user?.email}
|
||||||
onValueChange={field.onChange}
|
value={field.value}
|
||||||
>
|
onValueChange={field.onChange}
|
||||||
{filteredOrgUsers.map(({ _id: orgUserId, user: u }) => (
|
>
|
||||||
<SelectItem value={u?.email} key={`org-membership-join-${orgUserId}`}>
|
{filteredOrgUsers.map(({ _id: orgUserId, user: u }) => (
|
||||||
{u?.email}
|
<SelectItem value={u?.email} key={`org-membership-join-${orgUserId}`}>
|
||||||
</SelectItem>
|
{u?.email}
|
||||||
))}
|
</SelectItem>
|
||||||
</Select>
|
))}
|
||||||
</FormControl>
|
</Select>
|
||||||
)}
|
</FormControl>
|
||||||
/>
|
)}
|
||||||
<div className="mt-8 flex items-center">
|
/>
|
||||||
<Button
|
<div className="mt-8 flex items-center">
|
||||||
className="mr-4"
|
<Button
|
||||||
size="sm"
|
className="mr-4"
|
||||||
type="submit"
|
size="sm"
|
||||||
isLoading={isSubmitting}
|
type="submit"
|
||||||
isDisabled={isSubmitting}
|
isLoading={isSubmitting}
|
||||||
>
|
isDisabled={isSubmitting}
|
||||||
Add Member
|
>
|
||||||
</Button>
|
Add Member
|
||||||
<Button
|
</Button>
|
||||||
colorSchema="secondary"
|
<Button
|
||||||
variant="plain"
|
colorSchema="secondary"
|
||||||
onClick={() => handlePopUpClose("addMember")}
|
variant="plain"
|
||||||
>
|
onClick={() => handlePopUpClose("addMember")}
|
||||||
Cancel
|
>
|
||||||
</Button>
|
Cancel
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
) : (
|
||||||
|
<div className="flex flex-col space-y-4">
|
||||||
|
<div>All the users in your organization are already invited.</div>
|
||||||
|
<Link href={`/org/${currentWorkspace?.organization}/members`}>
|
||||||
|
<Button variant="outline_bg">Add users to organization</Button>
|
||||||
|
</Link>
|
||||||
</div>
|
</div>
|
||||||
</form>
|
)}
|
||||||
</ModalContent>
|
</ModalContent>
|
||||||
</Modal>
|
</Modal>
|
||||||
<DeleteActionModal
|
<DeleteActionModal
|
||||||
|
|||||||
-19
@@ -1,14 +1,11 @@
|
|||||||
import { useState } from "react";
|
|
||||||
import { useForm } from "react-hook-form";
|
import { useForm } from "react-hook-form";
|
||||||
import { faElementor } from "@fortawesome/free-brands-svg-icons";
|
import { faElementor } from "@fortawesome/free-brands-svg-icons";
|
||||||
import {
|
import {
|
||||||
faAnchorLock,
|
faAnchorLock,
|
||||||
faArrowLeft,
|
faArrowLeft,
|
||||||
faBook,
|
|
||||||
faCog,
|
faCog,
|
||||||
faKey,
|
faKey,
|
||||||
faLock,
|
faLock,
|
||||||
faMagnifyingGlass,
|
|
||||||
faNetworkWired,
|
faNetworkWired,
|
||||||
faPuzzlePiece,
|
faPuzzlePiece,
|
||||||
faTags,
|
faTags,
|
||||||
@@ -85,12 +82,6 @@ const SINGLE_PERMISSION_LIST = [
|
|||||||
icon: faTags,
|
icon: faTags,
|
||||||
formName: "tags"
|
formName: "tags"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
title: "Audit Logs",
|
|
||||||
subtitle: "Audit log management control",
|
|
||||||
icon: faBook,
|
|
||||||
formName: "audit-logs"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
title: "IP Allowlist",
|
title: "IP Allowlist",
|
||||||
subtitle: "IP allowlist management control",
|
subtitle: "IP allowlist management control",
|
||||||
@@ -105,8 +96,6 @@ type Props = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
export const ProjectRoleModifySection = ({ role, onGoBack }: Props) => {
|
export const ProjectRoleModifySection = ({ role, onGoBack }: Props) => {
|
||||||
const [searchPermission, setSearchPermission] = useState("");
|
|
||||||
|
|
||||||
const { popUp, handlePopUpToggle, handlePopUpOpen } = usePopUp(["upgradePlan"] as const);
|
const { popUp, handlePopUpToggle, handlePopUpOpen } = usePopUp(["upgradePlan"] as const);
|
||||||
|
|
||||||
const isNonEditable = ["admin", "member", "viewer"].includes(role?.slug || "");
|
const isNonEditable = ["admin", "member", "viewer"].includes(role?.slug || "");
|
||||||
@@ -226,14 +215,6 @@ export const ProjectRoleModifySection = ({ role, onGoBack }: Props) => {
|
|||||||
<div>
|
<div>
|
||||||
<h2 className="text-xl font-medium">Add Permission</h2>
|
<h2 className="text-xl font-medium">Add Permission</h2>
|
||||||
</div>
|
</div>
|
||||||
<div className="flex-1 max-w-md">
|
|
||||||
<Input
|
|
||||||
value={searchPermission}
|
|
||||||
onChange={(e) => setSearchPermission(e.target.value)}
|
|
||||||
leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />}
|
|
||||||
placeholder="Search permissions..."
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
</div>
|
</div>
|
||||||
<div>
|
<div>
|
||||||
<MultiEnvProjectPermission
|
<MultiEnvProjectPermission
|
||||||
|
|||||||
+17
-1
@@ -44,6 +44,22 @@ const PERMISSIONS = [
|
|||||||
{ action: "delete", label: "Remove" }
|
{ action: "delete", label: "Remove" }
|
||||||
] as const;
|
] as const;
|
||||||
|
|
||||||
|
const MEMBERS_PERMISSIONS = [
|
||||||
|
{ action: "read", label: "View all members" },
|
||||||
|
{ action: "create", label: "Invite members" },
|
||||||
|
{ action: "edit", label: "Edit members" },
|
||||||
|
{ action: "delete", label: "Remove members" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
const getPermissionList = (option: Props["formName"]) => {
|
||||||
|
switch (option) {
|
||||||
|
case "member":
|
||||||
|
return MEMBERS_PERMISSIONS;
|
||||||
|
default:
|
||||||
|
return PERMISSIONS;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
export const SingleProjectPermission = ({
|
export const SingleProjectPermission = ({
|
||||||
isNonEditable,
|
isNonEditable,
|
||||||
setValue,
|
setValue,
|
||||||
@@ -148,7 +164,7 @@ export const SingleProjectPermission = ({
|
|||||||
className="overflow-hidden grid gap-8 grid-flow-col auto-cols-min"
|
className="overflow-hidden grid gap-8 grid-flow-col auto-cols-min"
|
||||||
>
|
>
|
||||||
{isCustom &&
|
{isCustom &&
|
||||||
PERMISSIONS.map(({ action, label }) => (
|
getPermissionList(formName).map(({ action, label }) => (
|
||||||
<Controller
|
<Controller
|
||||||
name={`permissions.${formName}.${action}`}
|
name={`permissions.${formName}.${action}`}
|
||||||
key={`permissions.${formName}.${action}`}
|
key={`permissions.${formName}.${action}`}
|
||||||
|
|||||||
Reference in New Issue
Block a user