mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 08:27:36 +00:00
permission check
This commit is contained in:
@@ -6,9 +6,11 @@ import { useNavigate } from "@tanstack/react-router";
|
|||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { ROUTE_PATHS } from "@app/const/routes";
|
import { ROUTE_PATHS } from "@app/const/routes";
|
||||||
import { useProject } from "@app/context";
|
import { useProject, useProjectPermission } from "@app/context";
|
||||||
|
import { ProjectPermissionSecretActions } from "@app/context/ProjectPermissionContext/types";
|
||||||
import { useDebounce, useToggle } from "@app/hooks";
|
import { useDebounce, useToggle } from "@app/hooks";
|
||||||
import { useGetProjectFolders, useGetProjectSecrets } from "@app/hooks/api";
|
import { useGetProjectFolders, useGetProjectSecrets } from "@app/hooks/api";
|
||||||
|
import { hasSecretReadValueOrDescribePermission } from "@app/lib/fn/permission";
|
||||||
|
|
||||||
import { SecretInput } from "../SecretInput";
|
import { SecretInput } from "../SecretInput";
|
||||||
|
|
||||||
@@ -84,6 +86,7 @@ export const InfisicalSecretInput = forwardRef<HTMLTextAreaElement, Props>(
|
|||||||
const { currentProject } = useProject();
|
const { currentProject } = useProject();
|
||||||
const projectId = currentProject?.id || "";
|
const projectId = currentProject?.id || "";
|
||||||
const navigate = useNavigate({ from: ROUTE_PATHS.SecretManager.SecretDashboardPage.path });
|
const navigate = useNavigate({ from: ROUTE_PATHS.SecretManager.SecretDashboardPage.path });
|
||||||
|
const { permission } = useProjectPermission();
|
||||||
|
|
||||||
const [debouncedValue] = useDebounce(value, 100);
|
const [debouncedValue] = useDebounce(value, 100);
|
||||||
|
|
||||||
@@ -330,6 +333,30 @@ export const InfisicalSecretInput = forwardRef<HTMLTextAreaElement, Props>(
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (allSegments.length === 1) {
|
if (allSegments.length === 1) {
|
||||||
|
const canReadSecretValue = hasSecretReadValueOrDescribePermission(
|
||||||
|
permission,
|
||||||
|
ProjectPermissionSecretActions.ReadValue,
|
||||||
|
{
|
||||||
|
environment: propEnvironment ?? "",
|
||||||
|
secretPath: propSecretPath ?? "/",
|
||||||
|
secretName: segment,
|
||||||
|
secretTags: []
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
console.log("canReadSecretValue", canReadSecretValue);
|
||||||
|
console.log("propEnvironment", propEnvironment);
|
||||||
|
console.log("propSecretPath", propSecretPath);
|
||||||
|
console.log("segment", segment);
|
||||||
|
|
||||||
|
if (!canReadSecretValue) {
|
||||||
|
createNotification({
|
||||||
|
text: "You do not have permission to access this secret",
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
navigate({
|
navigate({
|
||||||
search: (prev) => ({
|
search: (prev) => ({
|
||||||
...prev,
|
...prev,
|
||||||
@@ -365,6 +392,32 @@ export const InfisicalSecretInput = forwardRef<HTMLTextAreaElement, Props>(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const secretPath = segment === environmentSlug ? "/" : folderPath;
|
||||||
|
|
||||||
|
const canReadSecretValue = hasSecretReadValueOrDescribePermission(
|
||||||
|
permission,
|
||||||
|
ProjectPermissionSecretActions.ReadValue,
|
||||||
|
{
|
||||||
|
environment: environmentSlug,
|
||||||
|
secretPath,
|
||||||
|
secretName: secretName ?? "",
|
||||||
|
secretTags: []
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
console.log("canReadSecretValue", canReadSecretValue);
|
||||||
|
console.log("environmentSlug", environmentSlug);
|
||||||
|
console.log("secretPath", secretPath);
|
||||||
|
console.log("secretName", secretName);
|
||||||
|
|
||||||
|
if (!canReadSecretValue) {
|
||||||
|
createNotification({
|
||||||
|
text: "You do not have permission to access this secret",
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
navigate({
|
navigate({
|
||||||
to: ROUTE_PATHS.SecretManager.SecretDashboardPage.path,
|
to: ROUTE_PATHS.SecretManager.SecretDashboardPage.path,
|
||||||
params: {
|
params: {
|
||||||
|
|||||||
Reference in New Issue
Block a user