Address PR comments

This commit is contained in:
Carlos Monastyrski
2025-09-10 00:20:00 -03:00
parent 9a17cd6af0
commit 7f03f2cf1d
2 changed files with 75 additions and 47 deletions
@@ -148,7 +148,7 @@ export const secretV2BridgeServiceFactory = ({
keyStore, keyStore,
reminderService reminderService
}: TSecretV2BridgeServiceFactoryDep) => { }: TSecretV2BridgeServiceFactoryDep) => {
const validateSecretReferences = async ( const $validateSecretReferences = async (
projectId: string, projectId: string,
permission: MongoAbility<ProjectPermissionSet>, permission: MongoAbility<ProjectPermissionSet>,
references: ReturnType<typeof getAllSecretReferences>["nestedReferences"], references: ReturnType<typeof getAllSecretReferences>["nestedReferences"],
@@ -177,16 +177,30 @@ export const secretV2BridgeServiceFactory = ({
); );
const referencesFolderGroupByPath = groupBy(referredFolders.filter(Boolean), (i) => `${i?.envId}-${i?.path}`); const referencesFolderGroupByPath = groupBy(referredFolders.filter(Boolean), (i) => `${i?.envId}-${i?.path}`);
// Find only references that have valid folders (don't throw for missing paths)
const validReferences = references.filter((el) => {
const folderId =
referencesFolderGroupByPath[`${referencesEnvironmentGroupBySlug[el.environment][0].id}-${el.secretPath}`]?.[0]
?.id;
return folderId;
});
if (validReferences.length === 0) return;
const referredSecrets = await secretDAL.find( const referredSecrets = await secretDAL.find(
{ {
$complex: { $complex: {
operator: "or", operator: "or",
value: references.map((el) => { value: validReferences
const folderId = .map((el) => {
const folderGroup =
referencesFolderGroupByPath[ referencesFolderGroupByPath[
`${referencesEnvironmentGroupBySlug[el.environment][0].id}-${el.secretPath}` `${referencesEnvironmentGroupBySlug[el.environment][0].id}-${el.secretPath}`
][0]?.id; ];
if (!folderId) throw new BadRequestError({ message: `Referenced path ${el.secretPath} doesn't exist` }); if (!folderGroup || !folderGroup[0]) return null;
const folderId = folderGroup[0].id;
return { return {
operator: "and", operator: "and",
@@ -204,31 +218,30 @@ export const secretV2BridgeServiceFactory = ({
] ]
}; };
}) })
.filter((query) => query !== null) as Array<{
operator: "and";
value: Array<{
operator: "eq";
field: "folderId" | "key";
value: string;
}>;
}>
} }
}, },
{ tx } { tx }
); );
if ( // Only check permissions for secrets that actually exist
referredSecrets.length !== referredSecrets.forEach((secret) => {
new Set(references.map(({ secretKey, secretPath, environment }) => `${secretKey}.${secretPath}.${environment}`)) const reference = validReferences.find((ref) => ref.secretKey === secret.key);
.size // only count unique references if (reference) {
)
throw new BadRequestError({
message: `Referenced secret(s) not found: ${diff(
references.map((el) => el.secretKey),
referredSecrets.map((el) => el.key)
).join(",")}`
});
const referredSecretsGroupBySecretKey = groupBy(referredSecrets, (i) => i.key);
references.forEach((el) => {
throwIfMissingSecretReadValueOrDescribePermission(permission, ProjectPermissionSecretActions.DescribeSecret, { throwIfMissingSecretReadValueOrDescribePermission(permission, ProjectPermissionSecretActions.DescribeSecret, {
environment: el.environment, environment: reference.environment,
secretPath: el.secretPath, secretPath: reference.secretPath,
secretName: el.secretKey, secretName: reference.secretKey,
secretTags: referredSecretsGroupBySecretKey[el.secretKey][0]?.tags?.map((i) => i.slug) secretTags: secret.tags?.map((i) => i.slug)
}); });
}
}); });
return referredSecrets; return referredSecrets;
@@ -312,7 +325,12 @@ export const secretV2BridgeServiceFactory = ({
project.secretDetectionIgnoreValues || [] project.secretDetectionIgnoreValues || []
); );
const { nestedReferences } = getAllSecretReferences(inputSecret.secretValue); const { nestedReferences, localReferences } = getAllSecretReferences(inputSecret.secretValue);
const allSecretReferences = nestedReferences.concat(
localReferences.map((el) => ({ secretKey: el, secretPath, environment }))
);
await $validateSecretReferences(projectId, permission, allSecretReferences);
const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({ const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager, type: KmsDataKey.SecretManager,
@@ -541,6 +559,14 @@ export const secretV2BridgeServiceFactory = ({
); );
} }
if (secretValue) {
const { nestedReferences, localReferences } = getAllSecretReferences(secretValue);
const allSecretReferences = nestedReferences.concat(
localReferences.map((el) => ({ secretKey: el, secretPath, environment }))
);
await $validateSecretReferences(projectId, permission, allSecretReferences);
}
const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({ const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager, type: KmsDataKey.SecretManager,
projectId projectId
@@ -1673,6 +1699,7 @@ export const secretV2BridgeServiceFactory = ({
}); });
} }
}); });
await $validateSecretReferences(projectId, permission, secretReferences);
const { encryptor: secretManagerEncryptor, decryptor: secretManagerDecryptor } = const { encryptor: secretManagerEncryptor, decryptor: secretManagerDecryptor } =
await kmsService.createCipherPairWithDataKey({ type: KmsDataKey.SecretManager, projectId }); await kmsService.createCipherPairWithDataKey({ type: KmsDataKey.SecretManager, projectId });
@@ -1986,6 +2013,7 @@ export const secretV2BridgeServiceFactory = ({
}); });
} }
}); });
await $validateSecretReferences(projectId, permission, secretReferences, tx);
const project = await projectDAL.findById(projectId); const project = await projectDAL.findById(projectId);
await scanSecretPolicyViolations( await scanSecretPolicyViolations(
@@ -3136,6 +3164,6 @@ export const secretV2BridgeServiceFactory = ({
getAccessibleSecrets, getAccessibleSecrets,
getSecretVersionsByIds, getSecretVersionsByIds,
findSecretIdsByFolderIdAndKeys, findSecretIdsByFolderIdAndKeys,
validateSecretReferences $validateSecretReferences
}; };
}; };
@@ -28,11 +28,11 @@ const syntaxHighlight = (
return ( return (
<span <span
className={`ph-no-capture ${isInvalid ? "text-red-500" : "text-yellow"}`} className={`ph-no-capture ${isInvalid ? "" : "text-yellow"}`}
key={`secret-value-${i + 1}`} key={`secret-value-${i + 1}`}
> >
&#36;&#123; &#36;&#123;
<span className={`ph-no-capture ${isInvalid ? "text-red-300/80" : "text-yellow-200/80"}`}> <span className={`ph-no-capture ${isInvalid ? "" : "text-yellow-200/80"}`}>
{referenceContent} {referenceContent}
</span> </span>
&#125; &#125;