mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 19:28:33 +00:00
Update db schema for ssh login mappings
This commit is contained in:
Vendored
+15
-7
@@ -359,9 +359,12 @@ import {
|
|||||||
TSshCertificateTemplates,
|
TSshCertificateTemplates,
|
||||||
TSshCertificateTemplatesInsert,
|
TSshCertificateTemplatesInsert,
|
||||||
TSshCertificateTemplatesUpdate,
|
TSshCertificateTemplatesUpdate,
|
||||||
TSshHostLoginMappings,
|
TSshHostLoginUserMappings,
|
||||||
TSshHostLoginMappingsInsert,
|
TSshHostLoginUserMappingsInsert,
|
||||||
TSshHostLoginMappingsUpdate,
|
TSshHostLoginUserMappingsUpdate,
|
||||||
|
TSshHostLoginUsers,
|
||||||
|
TSshHostLoginUsersInsert,
|
||||||
|
TSshHostLoginUsersUpdate,
|
||||||
TSshHosts,
|
TSshHosts,
|
||||||
TSshHostsInsert,
|
TSshHostsInsert,
|
||||||
TSshHostsUpdate,
|
TSshHostsUpdate,
|
||||||
@@ -454,10 +457,15 @@ declare module "knex/types/tables" {
|
|||||||
TSshCertificateBodiesInsert,
|
TSshCertificateBodiesInsert,
|
||||||
TSshCertificateBodiesUpdate
|
TSshCertificateBodiesUpdate
|
||||||
>;
|
>;
|
||||||
[TableName.SshHostLoginMapping]: KnexOriginal.CompositeTableType<
|
[TableName.SshHostLoginUser]: KnexOriginal.CompositeTableType<
|
||||||
TSshHostLoginMappings,
|
TSshHostLoginUsers,
|
||||||
TSshHostLoginMappingsInsert,
|
TSshHostLoginUsersInsert,
|
||||||
TSshHostLoginMappingsUpdate
|
TSshHostLoginUsersUpdate
|
||||||
|
>;
|
||||||
|
[TableName.SshHostLoginUserMapping]: KnexOriginal.CompositeTableType<
|
||||||
|
TSshHostLoginUserMappings,
|
||||||
|
TSshHostLoginUserMappingsInsert,
|
||||||
|
TSshHostLoginUserMappingsUpdate
|
||||||
>;
|
>;
|
||||||
[TableName.CertificateAuthority]: KnexOriginal.CompositeTableType<
|
[TableName.CertificateAuthority]: KnexOriginal.CompositeTableType<
|
||||||
TCertificateAuthorities,
|
TCertificateAuthorities,
|
||||||
|
|||||||
@@ -22,16 +22,27 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
await createOnUpdateTrigger(knex, TableName.SshHost);
|
await createOnUpdateTrigger(knex, TableName.SshHost);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!(await knex.schema.hasTable(TableName.SshHostLoginMapping))) {
|
if (!(await knex.schema.hasTable(TableName.SshHostLoginUser))) {
|
||||||
await knex.schema.createTable(TableName.SshHostLoginMapping, (t) => {
|
await knex.schema.createTable(TableName.SshHostLoginUser, (t) => {
|
||||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||||
t.timestamps(true, true, true);
|
t.timestamps(true, true, true);
|
||||||
t.uuid("sshHostId").notNullable();
|
t.uuid("sshHostId").notNullable();
|
||||||
t.foreign("sshHostId").references("id").inTable(TableName.SshHost).onDelete("CASCADE");
|
t.foreign("sshHostId").references("id").inTable(TableName.SshHost).onDelete("CASCADE");
|
||||||
t.string("loginUser").notNullable();
|
t.string("loginUser").notNullable(); // e.g. ubuntu, root, ec2-user, ...
|
||||||
t.specificType("allowedPrincipals", "text[]").notNullable();
|
|
||||||
});
|
});
|
||||||
await createOnUpdateTrigger(knex, TableName.SshHostLoginMapping);
|
await createOnUpdateTrigger(knex, TableName.SshHostLoginUser);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!(await knex.schema.hasTable(TableName.SshHostLoginUserMapping))) {
|
||||||
|
await knex.schema.createTable(TableName.SshHostLoginUserMapping, (t) => {
|
||||||
|
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||||
|
t.timestamps(true, true, true);
|
||||||
|
t.uuid("sshHostLoginUserId").notNullable();
|
||||||
|
t.foreign("sshHostLoginUserId").references("id").inTable(TableName.SshHostLoginUser).onDelete("CASCADE");
|
||||||
|
t.uuid("userId").nullable();
|
||||||
|
t.foreign("userId").references("id").inTable(TableName.Users).onDelete("CASCADE");
|
||||||
|
});
|
||||||
|
await createOnUpdateTrigger(knex, TableName.SshHostLoginUserMapping);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!(await knex.schema.hasTable(TableName.ProjectSshConfig))) {
|
if (!(await knex.schema.hasTable(TableName.ProjectSshConfig))) {
|
||||||
@@ -62,11 +73,11 @@ export async function down(knex: Knex): Promise<void> {
|
|||||||
await knex.schema.dropTableIfExists(TableName.ProjectSshConfig);
|
await knex.schema.dropTableIfExists(TableName.ProjectSshConfig);
|
||||||
await dropOnUpdateTrigger(knex, TableName.ProjectSshConfig);
|
await dropOnUpdateTrigger(knex, TableName.ProjectSshConfig);
|
||||||
|
|
||||||
await knex.schema.dropTableIfExists(TableName.SshHostLoginMapping);
|
await knex.schema.dropTableIfExists(TableName.SshHostLoginUserMapping);
|
||||||
await dropOnUpdateTrigger(knex, TableName.SshHostLoginMapping);
|
await dropOnUpdateTrigger(knex, TableName.SshHostLoginUserMapping);
|
||||||
|
|
||||||
await knex.schema.dropTableIfExists(TableName.SshHost);
|
await knex.schema.dropTableIfExists(TableName.SshHostLoginUser);
|
||||||
await dropOnUpdateTrigger(knex, TableName.SshHost);
|
await dropOnUpdateTrigger(knex, TableName.SshHostLoginUser);
|
||||||
|
|
||||||
const hasColumn = await knex.schema.hasColumn(TableName.SshCertificate, "sshHostId");
|
const hasColumn = await knex.schema.hasColumn(TableName.SshCertificate, "sshHostId");
|
||||||
if (hasColumn) {
|
if (hasColumn) {
|
||||||
@@ -74,4 +85,7 @@ export async function down(knex: Knex): Promise<void> {
|
|||||||
t.dropColumn("sshHostId");
|
t.dropColumn("sshHostId");
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
await knex.schema.dropTableIfExists(TableName.SshHost);
|
||||||
|
await dropOnUpdateTrigger(knex, TableName.SshHost);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -121,7 +121,8 @@ export * from "./ssh-certificate-authority-secrets";
|
|||||||
export * from "./ssh-certificate-bodies";
|
export * from "./ssh-certificate-bodies";
|
||||||
export * from "./ssh-certificate-templates";
|
export * from "./ssh-certificate-templates";
|
||||||
export * from "./ssh-certificates";
|
export * from "./ssh-certificates";
|
||||||
export * from "./ssh-host-login-mappings";
|
export * from "./ssh-host-login-user-mappings";
|
||||||
|
export * from "./ssh-host-login-users";
|
||||||
export * from "./ssh-hosts";
|
export * from "./ssh-hosts";
|
||||||
export * from "./super-admin";
|
export * from "./super-admin";
|
||||||
export * from "./totp-configs";
|
export * from "./totp-configs";
|
||||||
|
|||||||
@@ -3,7 +3,8 @@ import { z } from "zod";
|
|||||||
export enum TableName {
|
export enum TableName {
|
||||||
Users = "users",
|
Users = "users",
|
||||||
SshHost = "ssh_hosts",
|
SshHost = "ssh_hosts",
|
||||||
SshHostLoginMapping = "ssh_host_login_mappings",
|
SshHostLoginUser = "ssh_host_login_users",
|
||||||
|
SshHostLoginUserMapping = "ssh_host_login_user_mappings",
|
||||||
SshCertificateAuthority = "ssh_certificate_authorities",
|
SshCertificateAuthority = "ssh_certificate_authorities",
|
||||||
SshCertificateAuthoritySecret = "ssh_certificate_authority_secrets",
|
SshCertificateAuthoritySecret = "ssh_certificate_authority_secrets",
|
||||||
SshCertificateTemplate = "ssh_certificate_templates",
|
SshCertificateTemplate = "ssh_certificate_templates",
|
||||||
|
|||||||
@@ -1,21 +0,0 @@
|
|||||||
// Code generated by automation script, DO NOT EDIT.
|
|
||||||
// Automated by pulling database and generating zod schema
|
|
||||||
// To update. Just run npm run generate:schema
|
|
||||||
// Written by akhilmhdh.
|
|
||||||
|
|
||||||
import { z } from "zod";
|
|
||||||
|
|
||||||
import { TImmutableDBKeys } from "./models";
|
|
||||||
|
|
||||||
export const SshHostLoginMappingsSchema = z.object({
|
|
||||||
id: z.string().uuid(),
|
|
||||||
createdAt: z.date(),
|
|
||||||
updatedAt: z.date(),
|
|
||||||
sshHostId: z.string().uuid(),
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.string().array()
|
|
||||||
});
|
|
||||||
|
|
||||||
export type TSshHostLoginMappings = z.infer<typeof SshHostLoginMappingsSchema>;
|
|
||||||
export type TSshHostLoginMappingsInsert = Omit<z.input<typeof SshHostLoginMappingsSchema>, TImmutableDBKeys>;
|
|
||||||
export type TSshHostLoginMappingsUpdate = Partial<Omit<z.input<typeof SshHostLoginMappingsSchema>, TImmutableDBKeys>>;
|
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
// Code generated by automation script, DO NOT EDIT.
|
||||||
|
// Automated by pulling database and generating zod schema
|
||||||
|
// To update. Just run npm run generate:schema
|
||||||
|
// Written by akhilmhdh.
|
||||||
|
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TImmutableDBKeys } from "./models";
|
||||||
|
|
||||||
|
export const SshHostLoginUserMappingsSchema = z.object({
|
||||||
|
id: z.string().uuid(),
|
||||||
|
createdAt: z.date(),
|
||||||
|
updatedAt: z.date(),
|
||||||
|
sshHostLoginUserId: z.string().uuid(),
|
||||||
|
userId: z.string().uuid().nullable().optional()
|
||||||
|
});
|
||||||
|
|
||||||
|
export type TSshHostLoginUserMappings = z.infer<typeof SshHostLoginUserMappingsSchema>;
|
||||||
|
export type TSshHostLoginUserMappingsInsert = Omit<z.input<typeof SshHostLoginUserMappingsSchema>, TImmutableDBKeys>;
|
||||||
|
export type TSshHostLoginUserMappingsUpdate = Partial<
|
||||||
|
Omit<z.input<typeof SshHostLoginUserMappingsSchema>, TImmutableDBKeys>
|
||||||
|
>;
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
// Code generated by automation script, DO NOT EDIT.
|
||||||
|
// Automated by pulling database and generating zod schema
|
||||||
|
// To update. Just run npm run generate:schema
|
||||||
|
// Written by akhilmhdh.
|
||||||
|
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TImmutableDBKeys } from "./models";
|
||||||
|
|
||||||
|
export const SshHostLoginUsersSchema = z.object({
|
||||||
|
id: z.string().uuid(),
|
||||||
|
createdAt: z.date(),
|
||||||
|
updatedAt: z.date(),
|
||||||
|
sshHostId: z.string().uuid(),
|
||||||
|
loginUser: z.string()
|
||||||
|
});
|
||||||
|
|
||||||
|
export type TSshHostLoginUsers = z.infer<typeof SshHostLoginUsersSchema>;
|
||||||
|
export type TSshHostLoginUsersInsert = Omit<z.input<typeof SshHostLoginUsersSchema>, TImmutableDBKeys>;
|
||||||
|
export type TSshHostLoginUsersUpdate = Partial<Omit<z.input<typeof SshHostLoginUsersSchema>, TImmutableDBKeys>>;
|
||||||
@@ -2,7 +2,7 @@ import { z } from "zod";
|
|||||||
|
|
||||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
import { SshCertKeyAlgorithm } from "@app/ee/services/ssh-certificate/ssh-certificate-types";
|
import { SshCertKeyAlgorithm } from "@app/ee/services/ssh-certificate/ssh-certificate-types";
|
||||||
import { sanitizedSshHost } from "@app/ee/services/ssh-host/ssh-host-schema";
|
import { loginMappingSchema, sanitizedSshHost } from "@app/ee/services/ssh-host/ssh-host-schema";
|
||||||
import { isValidHostname } from "@app/ee/services/ssh-host/ssh-host-validators";
|
import { isValidHostname } from "@app/ee/services/ssh-host/ssh-host-validators";
|
||||||
import { SSH_HOSTS } from "@app/lib/api-docs";
|
import { SSH_HOSTS } from "@app/lib/api-docs";
|
||||||
import { ms } from "@app/lib/ms";
|
import { ms } from "@app/lib/ms";
|
||||||
@@ -23,17 +23,12 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
|
|||||||
response: {
|
response: {
|
||||||
200: z.array(
|
200: z.array(
|
||||||
sanitizedSshHost.extend({
|
sanitizedSshHost.extend({
|
||||||
loginMappings: z.array(
|
loginMappings: z.array(loginMappingSchema)
|
||||||
z.object({
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.array(z.string())
|
|
||||||
})
|
|
||||||
)
|
|
||||||
})
|
})
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const hosts = await server.services.sshHost.listSshHosts({
|
const hosts = await server.services.sshHost.listSshHosts({
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
@@ -41,7 +36,6 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
|
|||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
// TODO: consider adding audit log
|
|
||||||
|
|
||||||
return hosts;
|
return hosts;
|
||||||
}
|
}
|
||||||
@@ -59,12 +53,7 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
|
|||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: sanitizedSshHost.extend({
|
200: sanitizedSshHost.extend({
|
||||||
loginMappings: z.array(
|
loginMappings: z.array(loginMappingSchema)
|
||||||
z.object({
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.array(z.string())
|
|
||||||
})
|
|
||||||
)
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -121,25 +110,13 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
|
|||||||
.refine((val) => ms(val) > 0, "TTL must be a positive number")
|
.refine((val) => ms(val) > 0, "TTL must be a positive number")
|
||||||
.default("1y")
|
.default("1y")
|
||||||
.describe(SSH_HOSTS.CREATE.hostCertTtl),
|
.describe(SSH_HOSTS.CREATE.hostCertTtl),
|
||||||
loginMappings: z
|
loginMappings: z.array(loginMappingSchema).default([]).describe(SSH_HOSTS.CREATE.loginMappings),
|
||||||
.object({
|
|
||||||
loginUser: z.string().trim().describe(SSH_HOSTS.CREATE.loginUser), // TODO: reinforce validation
|
|
||||||
allowedPrincipals: z.array(z.string().trim()).describe(SSH_HOSTS.CREATE.allowedPrincipals) // TODO: reinforce validation
|
|
||||||
})
|
|
||||||
.array()
|
|
||||||
.default([])
|
|
||||||
.describe(SSH_HOSTS.CREATE.loginMappings),
|
|
||||||
userSshCaId: z.string().describe(SSH_HOSTS.CREATE.userSshCaId).optional(),
|
userSshCaId: z.string().describe(SSH_HOSTS.CREATE.userSshCaId).optional(),
|
||||||
hostSshCaId: z.string().describe(SSH_HOSTS.CREATE.hostSshCaId).optional()
|
hostSshCaId: z.string().describe(SSH_HOSTS.CREATE.hostSshCaId).optional()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: sanitizedSshHost.extend({
|
200: sanitizedSshHost.extend({
|
||||||
loginMappings: z.array(
|
loginMappings: z.array(loginMappingSchema)
|
||||||
z.object({
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.array(z.string())
|
|
||||||
})
|
|
||||||
)
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -205,23 +182,11 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
|
|||||||
.refine((val) => ms(val) > 0, "TTL must be a positive number")
|
.refine((val) => ms(val) > 0, "TTL must be a positive number")
|
||||||
.optional()
|
.optional()
|
||||||
.describe(SSH_HOSTS.UPDATE.hostCertTtl),
|
.describe(SSH_HOSTS.UPDATE.hostCertTtl),
|
||||||
loginMappings: z
|
loginMappings: z.array(loginMappingSchema).optional().describe(SSH_HOSTS.CREATE.loginMappings)
|
||||||
.object({
|
|
||||||
loginUser: z.string().trim().describe(SSH_HOSTS.CREATE.loginUser),
|
|
||||||
allowedPrincipals: z.array(z.string().trim()).describe(SSH_HOSTS.CREATE.allowedPrincipals)
|
|
||||||
})
|
|
||||||
.array()
|
|
||||||
.optional()
|
|
||||||
.describe(SSH_HOSTS.CREATE.loginMappings)
|
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: sanitizedSshHost.extend({
|
200: sanitizedSshHost.extend({
|
||||||
loginMappings: z.array(
|
loginMappings: z.array(loginMappingSchema)
|
||||||
z.object({
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.array(z.string())
|
|
||||||
})
|
|
||||||
)
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -268,12 +233,7 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
|
|||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: sanitizedSshHost.extend({
|
200: sanitizedSshHost.extend({
|
||||||
loginMappings: z.array(
|
loginMappings: z.array(loginMappingSchema)
|
||||||
z.object({
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.array(z.string())
|
|
||||||
})
|
|
||||||
)
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -1470,7 +1470,9 @@ interface CreateSshHost {
|
|||||||
hostCertTtl: string;
|
hostCertTtl: string;
|
||||||
loginMappings: {
|
loginMappings: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
userSshCaId: string;
|
userSshCaId: string;
|
||||||
hostSshCaId: string;
|
hostSshCaId: string;
|
||||||
@@ -1486,7 +1488,9 @@ interface UpdateSshHost {
|
|||||||
hostCertTtl?: string;
|
hostCertTtl?: string;
|
||||||
loginMappings?: {
|
loginMappings?: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
userSshCaId?: string;
|
userSshCaId?: string;
|
||||||
hostSshCaId?: string;
|
hostSshCaId?: string;
|
||||||
|
|||||||
@@ -11,52 +11,49 @@ export type TSshHostDALFactory = ReturnType<typeof sshHostDALFactory>;
|
|||||||
export const sshHostDALFactory = (db: TDbClient) => {
|
export const sshHostDALFactory = (db: TDbClient) => {
|
||||||
const sshHostOrm = ormify(db, TableName.SshHost);
|
const sshHostOrm = ormify(db, TableName.SshHost);
|
||||||
|
|
||||||
const findSshHostsWithPrincipalsAcrossProjects = async (projectIds: string[], principals: string[], tx?: Knex) => {
|
const findSshHostsWithPrincipalsAcrossProjects = async (projectIds: string[], userId: string, tx?: Knex) => {
|
||||||
try {
|
try {
|
||||||
const matchingSshHosts = await (tx || db.replicaNode())(TableName.SshHost)
|
const user = await (tx || db.replicaNode())(TableName.Users).where({ id: userId }).select("username").first();
|
||||||
|
|
||||||
|
if (!user) {
|
||||||
|
throw new DatabaseError({ name: `${TableName.Users}: UserNotFound`, error: new Error("User not found") });
|
||||||
|
}
|
||||||
|
|
||||||
|
const rows = await (tx || db.replicaNode())(TableName.SshHost)
|
||||||
|
.leftJoin(TableName.SshHostLoginUser, `${TableName.SshHost}.id`, `${TableName.SshHostLoginUser}.sshHostId`)
|
||||||
.leftJoin(
|
.leftJoin(
|
||||||
TableName.SshHostLoginMapping,
|
TableName.SshHostLoginUserMapping,
|
||||||
`${TableName.SshHost}.id`,
|
`${TableName.SshHostLoginUser}.id`,
|
||||||
`${TableName.SshHostLoginMapping}.sshHostId`
|
`${TableName.SshHostLoginUserMapping}.sshHostLoginUserId`
|
||||||
)
|
)
|
||||||
.whereIn(`${TableName.SshHost}.projectId`, projectIds)
|
.whereIn(`${TableName.SshHost}.projectId`, projectIds)
|
||||||
.whereRaw(`"${TableName.SshHostLoginMapping}"."allowedPrincipals" && ?::text[]`, [principals])
|
.andWhere(`${TableName.SshHostLoginUserMapping}.userId`, userId)
|
||||||
.select(
|
.select(
|
||||||
db.ref("id").withSchema(TableName.SshHost).as("sshHostId"),
|
db.ref("id").withSchema(TableName.SshHost).as("sshHostId"),
|
||||||
db.ref("projectId").withSchema(TableName.SshHost),
|
db.ref("projectId").withSchema(TableName.SshHost),
|
||||||
db.ref("hostname").withSchema(TableName.SshHost),
|
db.ref("hostname").withSchema(TableName.SshHost),
|
||||||
db.ref("userCertTtl").withSchema(TableName.SshHost),
|
db.ref("userCertTtl").withSchema(TableName.SshHost),
|
||||||
db.ref("hostCertTtl").withSchema(TableName.SshHost),
|
db.ref("hostCertTtl").withSchema(TableName.SshHost),
|
||||||
db.ref("loginUser").withSchema(TableName.SshHostLoginMapping),
|
db.ref("loginUser").withSchema(TableName.SshHostLoginUser),
|
||||||
db.ref("allowedPrincipals").withSchema(TableName.SshHostLoginMapping),
|
db.ref("username").withSchema(TableName.Users),
|
||||||
|
db.ref("userId").withSchema(TableName.SshHostLoginUserMapping),
|
||||||
db.ref("userSshCaId").withSchema(TableName.SshHost),
|
db.ref("userSshCaId").withSchema(TableName.SshHost),
|
||||||
db.ref("hostSshCaId").withSchema(TableName.SshHost)
|
db.ref("hostSshCaId").withSchema(TableName.SshHost)
|
||||||
)
|
)
|
||||||
.orderBy(`${TableName.SshHost}.updatedAt`, "desc");
|
.orderBy(`${TableName.SshHost}.updatedAt`, "desc");
|
||||||
|
|
||||||
const grouped = groupBy(matchingSshHosts, (r) => r.sshHostId);
|
const grouped = groupBy(rows, (r) => r.sshHostId);
|
||||||
return Object.values(grouped).map((hostRows) => {
|
return Object.values(grouped).map((hostRows) => {
|
||||||
const { sshHostId, hostname, userCertTtl, hostCertTtl, userSshCaId, hostSshCaId, projectId } = hostRows[0];
|
const { sshHostId, hostname, userCertTtl, hostCertTtl, userSshCaId, hostSshCaId, projectId } = hostRows[0];
|
||||||
|
|
||||||
const loginMappingGrouped = groupBy(
|
const loginMappingGrouped = groupBy(hostRows, (r) => r.loginUser);
|
||||||
hostRows.filter((r) => r.loginUser),
|
|
||||||
(r) => r.loginUser
|
|
||||||
);
|
|
||||||
|
|
||||||
const loginMappings = Object.entries(loginMappingGrouped)
|
const loginMappings = Object.entries(loginMappingGrouped).map(([loginUser]) => ({
|
||||||
.map(([loginUser, entries]) => {
|
loginUser,
|
||||||
const filteredPrincipals = unique(entries.flatMap((entry) => entry.allowedPrincipals ?? [])).filter(
|
allowedPrincipals: {
|
||||||
(principal) => principals.includes(principal)
|
usernames: [user.username]
|
||||||
);
|
}
|
||||||
|
}));
|
||||||
if (filteredPrincipals.length === 0) return null;
|
|
||||||
|
|
||||||
return {
|
|
||||||
loginUser,
|
|
||||||
allowedPrincipals: filteredPrincipals
|
|
||||||
};
|
|
||||||
})
|
|
||||||
.filter(Boolean) as { loginUser: string; allowedPrincipals: string[] }[];
|
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id: sshHostId,
|
id: sshHostId,
|
||||||
@@ -77,11 +74,13 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
const findSshHostsWithLoginMappings = async (projectId: string, tx?: Knex) => {
|
const findSshHostsWithLoginMappings = async (projectId: string, tx?: Knex) => {
|
||||||
try {
|
try {
|
||||||
const rows = await (tx || db.replicaNode())(TableName.SshHost)
|
const rows = await (tx || db.replicaNode())(TableName.SshHost)
|
||||||
|
.leftJoin(TableName.SshHostLoginUser, `${TableName.SshHost}.id`, `${TableName.SshHostLoginUser}.sshHostId`)
|
||||||
.leftJoin(
|
.leftJoin(
|
||||||
TableName.SshHostLoginMapping,
|
TableName.SshHostLoginUserMapping,
|
||||||
`${TableName.SshHost}.id`,
|
`${TableName.SshHostLoginUser}.id`,
|
||||||
`${TableName.SshHostLoginMapping}.sshHostId`
|
`${TableName.SshHostLoginUserMapping}.sshHostLoginUserId`
|
||||||
)
|
)
|
||||||
|
.leftJoin(TableName.Users, `${TableName.SshHostLoginUserMapping}.userId`, `${TableName.Users}.id`)
|
||||||
.where(`${TableName.SshHost}.projectId`, projectId)
|
.where(`${TableName.SshHost}.projectId`, projectId)
|
||||||
.select(
|
.select(
|
||||||
db.ref("id").withSchema(TableName.SshHost).as("sshHostId"),
|
db.ref("id").withSchema(TableName.SshHost).as("sshHostId"),
|
||||||
@@ -89,8 +88,9 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("hostname").withSchema(TableName.SshHost),
|
db.ref("hostname").withSchema(TableName.SshHost),
|
||||||
db.ref("userCertTtl").withSchema(TableName.SshHost),
|
db.ref("userCertTtl").withSchema(TableName.SshHost),
|
||||||
db.ref("hostCertTtl").withSchema(TableName.SshHost),
|
db.ref("hostCertTtl").withSchema(TableName.SshHost),
|
||||||
db.ref("loginUser").withSchema(TableName.SshHostLoginMapping),
|
db.ref("loginUser").withSchema(TableName.SshHostLoginUser),
|
||||||
db.ref("allowedPrincipals").withSchema(TableName.SshHostLoginMapping),
|
db.ref("username").withSchema(TableName.Users),
|
||||||
|
db.ref("userId").withSchema(TableName.SshHostLoginUserMapping),
|
||||||
db.ref("userSshCaId").withSchema(TableName.SshHost),
|
db.ref("userSshCaId").withSchema(TableName.SshHost),
|
||||||
db.ref("hostSshCaId").withSchema(TableName.SshHost)
|
db.ref("hostSshCaId").withSchema(TableName.SshHost)
|
||||||
)
|
)
|
||||||
@@ -107,13 +107,15 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
|
|
||||||
const loginMappings = Object.entries(loginMappingGrouped).map(([loginUser, entries]) => ({
|
const loginMappings = Object.entries(loginMappingGrouped).map(([loginUser, entries]) => ({
|
||||||
loginUser,
|
loginUser,
|
||||||
allowedPrincipals: unique(entries.flatMap((entry) => entry.allowedPrincipals ?? []))
|
allowedPrincipals: {
|
||||||
|
usernames: unique(entries.map((e) => e.username)).filter(Boolean)
|
||||||
|
}
|
||||||
}));
|
}));
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id: sshHostId,
|
id: sshHostId,
|
||||||
projectId,
|
|
||||||
hostname,
|
hostname,
|
||||||
|
projectId,
|
||||||
userCertTtl,
|
userCertTtl,
|
||||||
hostCertTtl,
|
hostCertTtl,
|
||||||
loginMappings,
|
loginMappings,
|
||||||
@@ -129,11 +131,13 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
const findSshHostByIdWithLoginMappings = async (sshHostId: string, tx?: Knex) => {
|
const findSshHostByIdWithLoginMappings = async (sshHostId: string, tx?: Knex) => {
|
||||||
try {
|
try {
|
||||||
const rows = await (tx || db.replicaNode())(TableName.SshHost)
|
const rows = await (tx || db.replicaNode())(TableName.SshHost)
|
||||||
|
.leftJoin(TableName.SshHostLoginUser, `${TableName.SshHost}.id`, `${TableName.SshHostLoginUser}.sshHostId`)
|
||||||
.leftJoin(
|
.leftJoin(
|
||||||
TableName.SshHostLoginMapping,
|
TableName.SshHostLoginUserMapping,
|
||||||
`${TableName.SshHost}.id`,
|
`${TableName.SshHostLoginUser}.id`,
|
||||||
`${TableName.SshHostLoginMapping}.sshHostId`
|
`${TableName.SshHostLoginUserMapping}.sshHostLoginUserId`
|
||||||
)
|
)
|
||||||
|
.leftJoin(TableName.Users, `${TableName.SshHostLoginUserMapping}.userId`, `${TableName.Users}.id`)
|
||||||
.where(`${TableName.SshHost}.id`, sshHostId)
|
.where(`${TableName.SshHost}.id`, sshHostId)
|
||||||
.select(
|
.select(
|
||||||
db.ref("id").withSchema(TableName.SshHost).as("sshHostId"),
|
db.ref("id").withSchema(TableName.SshHost).as("sshHostId"),
|
||||||
@@ -141,8 +145,9 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("hostname").withSchema(TableName.SshHost),
|
db.ref("hostname").withSchema(TableName.SshHost),
|
||||||
db.ref("userCertTtl").withSchema(TableName.SshHost),
|
db.ref("userCertTtl").withSchema(TableName.SshHost),
|
||||||
db.ref("hostCertTtl").withSchema(TableName.SshHost),
|
db.ref("hostCertTtl").withSchema(TableName.SshHost),
|
||||||
db.ref("loginUser").withSchema(TableName.SshHostLoginMapping),
|
db.ref("loginUser").withSchema(TableName.SshHostLoginUser),
|
||||||
db.ref("allowedPrincipals").withSchema(TableName.SshHostLoginMapping),
|
db.ref("username").withSchema(TableName.Users),
|
||||||
|
db.ref("userId").withSchema(TableName.SshHostLoginUserMapping),
|
||||||
db.ref("userSshCaId").withSchema(TableName.SshHost),
|
db.ref("userSshCaId").withSchema(TableName.SshHost),
|
||||||
db.ref("hostSshCaId").withSchema(TableName.SshHost)
|
db.ref("hostSshCaId").withSchema(TableName.SshHost)
|
||||||
);
|
);
|
||||||
@@ -158,7 +163,9 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
|
|
||||||
const loginMappings = Object.entries(loginMappingGrouped).map(([loginUser, entries]) => ({
|
const loginMappings = Object.entries(loginMappingGrouped).map(([loginUser, entries]) => ({
|
||||||
loginUser,
|
loginUser,
|
||||||
allowedPrincipals: unique(entries.flatMap((entry) => entry.allowedPrincipals ?? []))
|
allowedPrincipals: {
|
||||||
|
usernames: unique(entries.map((e) => e.username)).filter(Boolean)
|
||||||
|
}
|
||||||
}));
|
}));
|
||||||
|
|
||||||
return {
|
return {
|
||||||
@@ -178,8 +185,8 @@ export const sshHostDALFactory = (db: TDbClient) => {
|
|||||||
|
|
||||||
return {
|
return {
|
||||||
...sshHostOrm,
|
...sshHostOrm,
|
||||||
findSshHostsWithPrincipalsAcrossProjects,
|
|
||||||
findSshHostsWithLoginMappings,
|
findSshHostsWithLoginMappings,
|
||||||
|
findSshHostsWithPrincipalsAcrossProjects,
|
||||||
findSshHostByIdWithLoginMappings
|
findSshHostByIdWithLoginMappings
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,10 +0,0 @@
|
|||||||
import { TDbClient } from "@app/db";
|
|
||||||
import { TableName } from "@app/db/schemas";
|
|
||||||
import { ormify } from "@app/lib/knex";
|
|
||||||
|
|
||||||
export type TSshHostLoginMappingDALFactory = ReturnType<typeof sshHostLoginMappingDALFactory>;
|
|
||||||
|
|
||||||
export const sshHostLoginMappingDALFactory = (db: TDbClient) => {
|
|
||||||
const sshHostLoginMappingOrm = ormify(db, TableName.SshHostLoginMapping);
|
|
||||||
return sshHostLoginMappingOrm;
|
|
||||||
};
|
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
import { TDbClient } from "@app/db";
|
||||||
|
import { TableName } from "@app/db/schemas";
|
||||||
|
import { ormify } from "@app/lib/knex";
|
||||||
|
|
||||||
|
export type TSshHostLoginUserMappingDALFactory = ReturnType<typeof sshHostLoginUserMappingDALFactory>;
|
||||||
|
|
||||||
|
export const sshHostLoginUserMappingDALFactory = (db: TDbClient) => {
|
||||||
|
const sshHostLoginUserMappingOrm = ormify(db, TableName.SshHostLoginUserMapping);
|
||||||
|
return sshHostLoginUserMappingOrm;
|
||||||
|
};
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
import { SshHostsSchema } from "@app/db/schemas";
|
import { SshHostsSchema } from "@app/db/schemas";
|
||||||
|
|
||||||
export const sanitizedSshHost = SshHostsSchema.pick({
|
export const sanitizedSshHost = SshHostsSchema.pick({
|
||||||
@@ -9,3 +11,10 @@ export const sanitizedSshHost = SshHostsSchema.pick({
|
|||||||
userSshCaId: true,
|
userSshCaId: true,
|
||||||
hostSshCaId: true
|
hostSshCaId: true
|
||||||
});
|
});
|
||||||
|
|
||||||
|
export const loginMappingSchema = z.object({
|
||||||
|
loginUser: z.string(),
|
||||||
|
allowedPrincipals: z.object({
|
||||||
|
usernames: z.array(z.string())
|
||||||
|
})
|
||||||
|
});
|
||||||
|
|||||||
@@ -9,8 +9,10 @@ import { TSshCertificateBodyDALFactory } from "@app/ee/services/ssh-certificate/
|
|||||||
import { TSshCertificateDALFactory } from "@app/ee/services/ssh-certificate/ssh-certificate-dal";
|
import { TSshCertificateDALFactory } from "@app/ee/services/ssh-certificate/ssh-certificate-dal";
|
||||||
import { SshCertKeyAlgorithm } from "@app/ee/services/ssh-certificate/ssh-certificate-types";
|
import { SshCertKeyAlgorithm } from "@app/ee/services/ssh-certificate/ssh-certificate-types";
|
||||||
import { TSshHostDALFactory } from "@app/ee/services/ssh-host/ssh-host-dal";
|
import { TSshHostDALFactory } from "@app/ee/services/ssh-host/ssh-host-dal";
|
||||||
import { TSshHostLoginMappingDALFactory } from "@app/ee/services/ssh-host/ssh-host-login-mapping-dal";
|
import { TSshHostLoginUserMappingDALFactory } from "@app/ee/services/ssh-host/ssh-host-login-user-mapping-dal";
|
||||||
|
import { TSshHostLoginUserDALFactory } from "@app/ee/services/ssh-host/ssh-login-user-dal";
|
||||||
import { BadRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
|
||||||
|
import { ActorType } from "@app/services/auth/auth-type";
|
||||||
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||||
import { KmsDataKey } from "@app/services/kms/kms-types";
|
import { KmsDataKey } from "@app/services/kms/kms-types";
|
||||||
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
||||||
@@ -34,8 +36,8 @@ import {
|
|||||||
TUpdateSshHostDTO
|
TUpdateSshHostDTO
|
||||||
} from "./ssh-host-types";
|
} from "./ssh-host-types";
|
||||||
|
|
||||||
type TSshCertificateAuthorityServiceFactoryDep = {
|
type TSshHostServiceFactoryDep = {
|
||||||
userDAL: Pick<TUserDALFactory, "findById">;
|
userDAL: Pick<TUserDALFactory, "findById" | "find">;
|
||||||
projectDAL: Pick<TProjectDALFactory, "find">;
|
projectDAL: Pick<TProjectDALFactory, "find">;
|
||||||
projectSshConfigDAL: Pick<TProjectSshConfigDALFactory, "findOne">;
|
projectSshConfigDAL: Pick<TProjectSshConfigDALFactory, "findOne">;
|
||||||
sshCertificateAuthorityDAL: Pick<TSshCertificateAuthorityDALFactory, "findById">;
|
sshCertificateAuthorityDAL: Pick<TSshCertificateAuthorityDALFactory, "findById">;
|
||||||
@@ -53,11 +55,9 @@ type TSshCertificateAuthorityServiceFactoryDep = {
|
|||||||
| "findSshHostByIdWithLoginMappings"
|
| "findSshHostByIdWithLoginMappings"
|
||||||
| "findSshHostsWithPrincipalsAcrossProjects"
|
| "findSshHostsWithPrincipalsAcrossProjects"
|
||||||
>;
|
>;
|
||||||
sshHostLoginMappingDAL: Pick<
|
sshHostLoginUserDAL: TSshHostLoginUserDALFactory;
|
||||||
TSshHostLoginMappingDALFactory,
|
sshHostLoginUserMappingDAL: TSshHostLoginUserMappingDALFactory;
|
||||||
"transaction" | "create" | "findById" | "updateById" | "deleteById" | "findOne" | "insertMany" | "delete"
|
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission" | "getUserProjectPermission">;
|
||||||
>;
|
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
|
|
||||||
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -72,26 +72,26 @@ export const sshHostServiceFactory = ({
|
|||||||
sshCertificateDAL,
|
sshCertificateDAL,
|
||||||
sshCertificateBodyDAL,
|
sshCertificateBodyDAL,
|
||||||
sshHostDAL,
|
sshHostDAL,
|
||||||
sshHostLoginMappingDAL,
|
sshHostLoginUserMappingDAL,
|
||||||
|
sshHostLoginUserDAL,
|
||||||
permissionService,
|
permissionService,
|
||||||
kmsService
|
kmsService
|
||||||
}: TSshCertificateAuthorityServiceFactoryDep) => {
|
}: TSshHostServiceFactoryDep) => {
|
||||||
/**
|
/**
|
||||||
* Return list of all SSH hosts that a user can issue user SSH certificates for
|
* Return list of all SSH hosts that a user can issue user SSH certificates for
|
||||||
* (i.e. is able to access / connect to) across all SSH projects in the organization
|
* (i.e. is able to access / connect to) across all SSH projects in the organization
|
||||||
*/
|
*/
|
||||||
const listSshHosts = async ({ actorId, actorAuthMethod, actor, actorOrgId }: TListSshHostsDTO) => {
|
const listSshHosts = async ({ actorId, actorAuthMethod, actor, actorOrgId }: TListSshHostsDTO) => {
|
||||||
|
if (actor !== ActorType.USER) {
|
||||||
|
// (dangtony98): only support user for now
|
||||||
|
throw new BadRequestError({ message: `Actor type ${actor} not supported` });
|
||||||
|
}
|
||||||
|
|
||||||
const sshProjects = await projectDAL.find({
|
const sshProjects = await projectDAL.find({
|
||||||
orgId: actorOrgId,
|
orgId: actorOrgId,
|
||||||
type: ProjectType.SSH
|
type: ProjectType.SSH
|
||||||
});
|
});
|
||||||
|
|
||||||
const principals = await convertActorToPrincipals({
|
|
||||||
actor,
|
|
||||||
actorId,
|
|
||||||
userDAL
|
|
||||||
});
|
|
||||||
|
|
||||||
const allowedHosts = [];
|
const allowedHosts = [];
|
||||||
|
|
||||||
for await (const project of sshProjects) {
|
for await (const project of sshProjects) {
|
||||||
@@ -105,7 +105,7 @@ export const sshHostServiceFactory = ({
|
|||||||
actionProjectType: ActionProjectType.SSH
|
actionProjectType: ActionProjectType.SSH
|
||||||
});
|
});
|
||||||
|
|
||||||
const projectHosts = await sshHostDAL.findSshHostsWithPrincipalsAcrossProjects([project.id], principals);
|
const projectHosts = await sshHostDAL.findSshHostsWithPrincipalsAcrossProjects([project.id], actorId); // TODO: consider fn rename
|
||||||
|
|
||||||
allowedHosts.push(...projectHosts);
|
allowedHosts.push(...projectHosts);
|
||||||
} catch {
|
} catch {
|
||||||
@@ -208,15 +208,51 @@ export const sshHostServiceFactory = ({
|
|||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
|
|
||||||
await sshHostLoginMappingDAL.insertMany(
|
await sshHostLoginUserDAL.insertMany(
|
||||||
loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
loginMappings.map(({ loginUser }) => ({
|
||||||
sshHostId: host.id,
|
sshHostId: host.id,
|
||||||
loginUser,
|
loginUser
|
||||||
allowedPrincipals
|
|
||||||
})),
|
})),
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
|
|
||||||
|
for await (const { loginUser, allowedPrincipals } of loginMappings) {
|
||||||
|
const sshHostLoginUser = await sshHostLoginUserDAL.create(
|
||||||
|
{
|
||||||
|
sshHostId: host.id,
|
||||||
|
loginUser
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
|
||||||
|
const users = await userDAL.find(
|
||||||
|
{
|
||||||
|
$in: {
|
||||||
|
username: allowedPrincipals.usernames
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{ tx }
|
||||||
|
);
|
||||||
|
|
||||||
|
for await (const user of users) {
|
||||||
|
await permissionService.getUserProjectPermission({
|
||||||
|
userId: user.id,
|
||||||
|
projectId,
|
||||||
|
authMethod: actorAuthMethod,
|
||||||
|
userOrgId: actorOrgId,
|
||||||
|
actionProjectType: ActionProjectType.SSH
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
await sshHostLoginUserMappingDAL.insertMany(
|
||||||
|
users.map((user) => ({
|
||||||
|
sshHostLoginUserId: sshHostLoginUser.id,
|
||||||
|
userId: user.id
|
||||||
|
})),
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
const newSshHostWithLoginMappings = await sshHostDAL.findSshHostByIdWithLoginMappings(host.id, tx);
|
const newSshHostWithLoginMappings = await sshHostDAL.findSshHostByIdWithLoginMappings(host.id, tx);
|
||||||
if (!newSshHostWithLoginMappings) {
|
if (!newSshHostWithLoginMappings) {
|
||||||
throw new NotFoundError({ message: `SSH host with ID '${host.id}' not found` });
|
throw new NotFoundError({ message: `SSH host with ID '${host.id}' not found` });
|
||||||
@@ -270,16 +306,58 @@ export const sshHostServiceFactory = ({
|
|||||||
);
|
);
|
||||||
|
|
||||||
if (loginMappings) {
|
if (loginMappings) {
|
||||||
await sshHostLoginMappingDAL.delete({ sshHostId }, tx);
|
await sshHostLoginUserDAL.delete({ sshHostId: host.id }, tx);
|
||||||
if (loginMappings.length) {
|
if (loginMappings.length) {
|
||||||
await sshHostLoginMappingDAL.insertMany(
|
for await (const { loginUser, allowedPrincipals } of loginMappings) {
|
||||||
loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
const sshHostLoginUser = await sshHostLoginUserDAL.create(
|
||||||
sshHostId: host.id,
|
{
|
||||||
loginUser,
|
sshHostId: host.id,
|
||||||
allowedPrincipals
|
loginUser
|
||||||
})),
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
|
|
||||||
|
if (allowedPrincipals.usernames.length === 0) {
|
||||||
|
continue; // or maybe insert no mappings and just skip validation
|
||||||
|
}
|
||||||
|
|
||||||
|
const users = await userDAL.find(
|
||||||
|
{
|
||||||
|
$in: {
|
||||||
|
username: allowedPrincipals.usernames
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{ tx }
|
||||||
|
);
|
||||||
|
|
||||||
|
const foundUsernames = new Set(users.map((u) => u.username));
|
||||||
|
|
||||||
|
for (const uname of allowedPrincipals.usernames) {
|
||||||
|
if (!foundUsernames.has(uname)) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Invalid username: ${uname}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
for await (const user of users) {
|
||||||
|
await permissionService.getUserProjectPermission({
|
||||||
|
userId: user.id,
|
||||||
|
projectId: host.projectId,
|
||||||
|
authMethod: actorAuthMethod,
|
||||||
|
userOrgId: actorOrgId,
|
||||||
|
actionProjectType: ActionProjectType.SSH
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
await sshHostLoginUserMappingDAL.insertMany(
|
||||||
|
users.map((user) => ({
|
||||||
|
sshHostLoginUserId: sshHostLoginUser.id,
|
||||||
|
userId: user.id
|
||||||
|
})),
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -314,10 +392,7 @@ export const sshHostServiceFactory = ({
|
|||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|
||||||
await sshHostDAL.transaction(async (tx) => {
|
await sshHostDAL.deleteById(sshHostId);
|
||||||
await sshHostLoginMappingDAL.delete({ sshHostId }, tx);
|
|
||||||
await sshHostDAL.deleteById(sshHostId, tx);
|
|
||||||
});
|
|
||||||
|
|
||||||
return host;
|
return host;
|
||||||
};
|
};
|
||||||
@@ -379,7 +454,9 @@ export const sshHostServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
const mapping = host.loginMappings.find(
|
const mapping = host.loginMappings.find(
|
||||||
(m) => m.loginUser === loginUser && m.allowedPrincipals.some((allowed) => internalPrincipals.includes(allowed))
|
(m) =>
|
||||||
|
m.loginUser === loginUser &&
|
||||||
|
m.allowedPrincipals.usernames.some((allowed) => internalPrincipals.includes(allowed))
|
||||||
);
|
);
|
||||||
|
|
||||||
if (!mapping) {
|
if (!mapping) {
|
||||||
|
|||||||
@@ -8,7 +8,9 @@ export type TCreateSshHostDTO = {
|
|||||||
hostCertTtl: string;
|
hostCertTtl: string;
|
||||||
loginMappings: {
|
loginMappings: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
userSshCaId?: string;
|
userSshCaId?: string;
|
||||||
hostSshCaId?: string;
|
hostSshCaId?: string;
|
||||||
@@ -21,7 +23,9 @@ export type TUpdateSshHostDTO = {
|
|||||||
hostCertTtl?: string;
|
hostCertTtl?: string;
|
||||||
loginMappings?: {
|
loginMappings?: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
import { TDbClient } from "@app/db";
|
||||||
|
import { TableName } from "@app/db/schemas";
|
||||||
|
import { ormify } from "@app/lib/knex";
|
||||||
|
|
||||||
|
export type TSshHostLoginUserDALFactory = ReturnType<typeof sshHostLoginUserDALFactory>;
|
||||||
|
|
||||||
|
export const sshHostLoginUserDALFactory = (db: TDbClient) => {
|
||||||
|
const sshHostLoginUserOrm = ormify(db, TableName.SshHostLoginUser);
|
||||||
|
return sshHostLoginUserOrm;
|
||||||
|
};
|
||||||
@@ -94,8 +94,9 @@ import { sshCertificateDALFactory } from "@app/ee/services/ssh-certificate/ssh-c
|
|||||||
import { sshCertificateTemplateDALFactory } from "@app/ee/services/ssh-certificate-template/ssh-certificate-template-dal";
|
import { sshCertificateTemplateDALFactory } from "@app/ee/services/ssh-certificate-template/ssh-certificate-template-dal";
|
||||||
import { sshCertificateTemplateServiceFactory } from "@app/ee/services/ssh-certificate-template/ssh-certificate-template-service";
|
import { sshCertificateTemplateServiceFactory } from "@app/ee/services/ssh-certificate-template/ssh-certificate-template-service";
|
||||||
import { sshHostDALFactory } from "@app/ee/services/ssh-host/ssh-host-dal";
|
import { sshHostDALFactory } from "@app/ee/services/ssh-host/ssh-host-dal";
|
||||||
import { sshHostLoginMappingDALFactory } from "@app/ee/services/ssh-host/ssh-host-login-mapping-dal";
|
import { sshHostLoginUserMappingDALFactory } from "@app/ee/services/ssh-host/ssh-host-login-user-mapping-dal";
|
||||||
import { sshHostServiceFactory } from "@app/ee/services/ssh-host/ssh-host-service";
|
import { sshHostServiceFactory } from "@app/ee/services/ssh-host/ssh-host-service";
|
||||||
|
import { sshHostLoginUserDALFactory } from "@app/ee/services/ssh-host/ssh-login-user-dal";
|
||||||
import { trustedIpDALFactory } from "@app/ee/services/trusted-ip/trusted-ip-dal";
|
import { trustedIpDALFactory } from "@app/ee/services/trusted-ip/trusted-ip-dal";
|
||||||
import { trustedIpServiceFactory } from "@app/ee/services/trusted-ip/trusted-ip-service";
|
import { trustedIpServiceFactory } from "@app/ee/services/trusted-ip/trusted-ip-service";
|
||||||
import { TKeyStoreFactory } from "@app/keystore/keystore";
|
import { TKeyStoreFactory } from "@app/keystore/keystore";
|
||||||
@@ -388,7 +389,8 @@ export const registerRoutes = async (
|
|||||||
const sshCertificateAuthoritySecretDAL = sshCertificateAuthoritySecretDALFactory(db);
|
const sshCertificateAuthoritySecretDAL = sshCertificateAuthoritySecretDALFactory(db);
|
||||||
const sshCertificateTemplateDAL = sshCertificateTemplateDALFactory(db);
|
const sshCertificateTemplateDAL = sshCertificateTemplateDALFactory(db);
|
||||||
const sshHostDAL = sshHostDALFactory(db);
|
const sshHostDAL = sshHostDALFactory(db);
|
||||||
const sshHostLoginMappingDAL = sshHostLoginMappingDALFactory(db);
|
const sshHostLoginUserDAL = sshHostLoginUserDALFactory(db);
|
||||||
|
const sshHostLoginUserMappingDAL = sshHostLoginUserMappingDALFactory(db);
|
||||||
|
|
||||||
const kmsDAL = kmskeyDALFactory(db);
|
const kmsDAL = kmskeyDALFactory(db);
|
||||||
const internalKmsDAL = internalKmsDALFactory(db);
|
const internalKmsDAL = internalKmsDALFactory(db);
|
||||||
@@ -806,7 +808,8 @@ export const registerRoutes = async (
|
|||||||
sshCertificateDAL,
|
sshCertificateDAL,
|
||||||
sshCertificateBodyDAL,
|
sshCertificateBodyDAL,
|
||||||
sshHostDAL,
|
sshHostDAL,
|
||||||
sshHostLoginMappingDAL,
|
sshHostLoginUserDAL,
|
||||||
|
sshHostLoginUserMappingDAL,
|
||||||
permissionService,
|
permissionService,
|
||||||
kmsService
|
kmsService
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ import { InfisicalProjectTemplate } from "@app/ee/services/project-template/proj
|
|||||||
import { sanitizedSshCa } from "@app/ee/services/ssh/ssh-certificate-authority-schema";
|
import { sanitizedSshCa } from "@app/ee/services/ssh/ssh-certificate-authority-schema";
|
||||||
import { sanitizedSshCertificate } from "@app/ee/services/ssh-certificate/ssh-certificate-schema";
|
import { sanitizedSshCertificate } from "@app/ee/services/ssh-certificate/ssh-certificate-schema";
|
||||||
import { sanitizedSshCertificateTemplate } from "@app/ee/services/ssh-certificate-template/ssh-certificate-template-schema";
|
import { sanitizedSshCertificateTemplate } from "@app/ee/services/ssh-certificate-template/ssh-certificate-template-schema";
|
||||||
import { sanitizedSshHost } from "@app/ee/services/ssh-host/ssh-host-schema";
|
import { loginMappingSchema, sanitizedSshHost } from "@app/ee/services/ssh-host/ssh-host-schema";
|
||||||
import { PROJECTS } from "@app/lib/api-docs";
|
import { PROJECTS } from "@app/lib/api-docs";
|
||||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { slugSchema } from "@app/server/lib/schemas";
|
import { slugSchema } from "@app/server/lib/schemas";
|
||||||
@@ -616,12 +616,7 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
200: z.object({
|
200: z.object({
|
||||||
hosts: z.array(
|
hosts: z.array(
|
||||||
sanitizedSshHost.extend({
|
sanitizedSshHost.extend({
|
||||||
loginMappings: z.array(
|
loginMappings: z.array(loginMappingSchema)
|
||||||
z.object({
|
|
||||||
loginUser: z.string(),
|
|
||||||
allowedPrincipals: z.array(z.string())
|
|
||||||
})
|
|
||||||
)
|
|
||||||
})
|
})
|
||||||
)
|
)
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -6,7 +6,9 @@ export type TSshHost = {
|
|||||||
hostCertTtl: string;
|
hostCertTtl: string;
|
||||||
loginMappings: {
|
loginMappings: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -17,7 +19,9 @@ export type TCreateSshHostDTO = {
|
|||||||
hostCertTtl?: string;
|
hostCertTtl?: string;
|
||||||
loginMappings: {
|
loginMappings: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -28,7 +32,9 @@ export type TUpdateSshHostDTO = {
|
|||||||
hostCertTtl?: string;
|
hostCertTtl?: string;
|
||||||
loginMappings?: {
|
loginMappings?: {
|
||||||
loginUser: string;
|
loginUser: string;
|
||||||
allowedPrincipals: string[];
|
allowedPrincipals: {
|
||||||
|
usernames: string[];
|
||||||
|
};
|
||||||
}[];
|
}[];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -1,9 +1,8 @@
|
|||||||
import { useEffect } from "react";
|
import { useEffect, useState } from "react";
|
||||||
import { Controller, useFieldArray, useForm } from "react-hook-form";
|
import { Controller, useFieldArray, useForm } from "react-hook-form";
|
||||||
import { faPlus, faTrash } from "@fortawesome/free-solid-svg-icons";
|
import { faChevronDown, faChevronRight, faPlus, faTrash } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
import { zodResolver } from "@hookform/resolvers/zod";
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
import { useNavigate } from "@tanstack/react-router";
|
|
||||||
import ms from "ms";
|
import ms from "ms";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
@@ -15,10 +14,17 @@ import {
|
|||||||
IconButton,
|
IconButton,
|
||||||
Input,
|
Input,
|
||||||
Modal,
|
Modal,
|
||||||
ModalContent
|
ModalContent,
|
||||||
|
Select,
|
||||||
|
SelectItem
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { useWorkspace } from "@app/context";
|
import { useWorkspace } from "@app/context";
|
||||||
import { useCreateSshHost, useGetSshHostById, useUpdateSshHost } from "@app/hooks/api";
|
import {
|
||||||
|
useCreateSshHost,
|
||||||
|
useGetSshHostById,
|
||||||
|
useGetWorkspaceUsers,
|
||||||
|
useUpdateSshHost
|
||||||
|
} from "@app/hooks/api";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
@@ -40,7 +46,7 @@ const schema = z
|
|||||||
loginMappings: z
|
loginMappings: z
|
||||||
.object({
|
.object({
|
||||||
loginUser: z.string().trim().min(1),
|
loginUser: z.string().trim().min(1),
|
||||||
allowedPrincipals: z.string().trim().min(1)
|
allowedPrincipals: z.array(z.string().trim()).default([])
|
||||||
})
|
})
|
||||||
.array()
|
.array()
|
||||||
.default([])
|
.default([])
|
||||||
@@ -50,9 +56,11 @@ const schema = z
|
|||||||
export type FormData = z.infer<typeof schema>;
|
export type FormData = z.infer<typeof schema>;
|
||||||
|
|
||||||
export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
||||||
const navigate = useNavigate();
|
|
||||||
const { currentWorkspace } = useWorkspace();
|
const { currentWorkspace } = useWorkspace();
|
||||||
const projectId = currentWorkspace?.id || "";
|
const projectId = currentWorkspace?.id || "";
|
||||||
|
const { data: members = [] } = useGetWorkspaceUsers(projectId);
|
||||||
|
const [expandedMappings, setExpandedMappings] = useState<Record<number, boolean>>({});
|
||||||
|
|
||||||
const { data: sshHost } = useGetSshHostById(
|
const { data: sshHost } = useGetSshHostById(
|
||||||
(popUp?.sshHost?.data as { sshHostId: string })?.sshHostId || ""
|
(popUp?.sshHost?.data as { sshHostId: string })?.sshHostId || ""
|
||||||
);
|
);
|
||||||
@@ -64,6 +72,8 @@ export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
control,
|
control,
|
||||||
handleSubmit,
|
handleSubmit,
|
||||||
reset,
|
reset,
|
||||||
|
getValues,
|
||||||
|
setValue,
|
||||||
formState: { isSubmitting }
|
formState: { isSubmitting }
|
||||||
} = useForm<FormData>({
|
} = useForm<FormData>({
|
||||||
resolver: zodResolver(schema),
|
resolver: zodResolver(schema),
|
||||||
@@ -86,9 +96,13 @@ export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
userCertTtl: sshHost.userCertTtl,
|
userCertTtl: sshHost.userCertTtl,
|
||||||
loginMappings: sshHost.loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
loginMappings: sshHost.loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
||||||
loginUser,
|
loginUser,
|
||||||
allowedPrincipals: allowedPrincipals.join(",")
|
allowedPrincipals: allowedPrincipals.usernames
|
||||||
}))
|
}))
|
||||||
});
|
});
|
||||||
|
|
||||||
|
setExpandedMappings(
|
||||||
|
Object.fromEntries(sshHost.loginMappings.map((_, index) => [index, false]))
|
||||||
|
);
|
||||||
} else {
|
} else {
|
||||||
reset({
|
reset({
|
||||||
hostname: "",
|
hostname: "",
|
||||||
@@ -109,7 +123,9 @@ export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
userCertTtl,
|
userCertTtl,
|
||||||
loginMappings: loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
loginMappings: loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
||||||
loginUser,
|
loginUser,
|
||||||
allowedPrincipals: allowedPrincipals.split(",")
|
allowedPrincipals: {
|
||||||
|
usernames: allowedPrincipals
|
||||||
|
}
|
||||||
}))
|
}))
|
||||||
});
|
});
|
||||||
} else {
|
} else {
|
||||||
@@ -119,17 +135,11 @@ export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
userCertTtl,
|
userCertTtl,
|
||||||
loginMappings: loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
loginMappings: loginMappings.map(({ loginUser, allowedPrincipals }) => ({
|
||||||
loginUser,
|
loginUser,
|
||||||
allowedPrincipals: allowedPrincipals.split(",")
|
allowedPrincipals: {
|
||||||
|
usernames: allowedPrincipals
|
||||||
|
}
|
||||||
}))
|
}))
|
||||||
});
|
});
|
||||||
|
|
||||||
// navigate({
|
|
||||||
// to: `/${ProjectType.SSH}/$projectId/ca/$caId` as const,
|
|
||||||
// params: {
|
|
||||||
// projectId,
|
|
||||||
// caId: newCaId
|
|
||||||
// }
|
|
||||||
// });
|
|
||||||
}
|
}
|
||||||
|
|
||||||
reset();
|
reset();
|
||||||
@@ -148,6 +158,13 @@ export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const toggleMapping = (index: number) => {
|
||||||
|
setExpandedMappings((prev) => ({
|
||||||
|
...prev,
|
||||||
|
[index]: !prev[index]
|
||||||
|
}));
|
||||||
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<Modal
|
<Modal
|
||||||
isOpen={popUp?.sshHost?.isOpen}
|
isOpen={popUp?.sshHost?.isOpen}
|
||||||
@@ -193,69 +210,182 @@ export const SshHostModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
<div>
|
<div className="mb-4 flex items-center justify-between">
|
||||||
<FormLabel label="Login Mappings" />
|
<FormLabel label="Login Mappings" />
|
||||||
</div>
|
|
||||||
<div className="mb-3 flex flex-col space-y-2">
|
|
||||||
{loginMappingsFormFields.fields.map(({ id: metadataFieldId }, i) => (
|
|
||||||
<div key={metadataFieldId} className="flex items-end space-x-2">
|
|
||||||
<div className="flex-grow">
|
|
||||||
{i === 0 && <span className="text-xs text-mineshaft-400">Login User</span>}
|
|
||||||
<Controller
|
|
||||||
control={control}
|
|
||||||
name={`loginMappings.${i}.loginUser`}
|
|
||||||
render={({ field, fieldState: { error } }) => (
|
|
||||||
<FormControl
|
|
||||||
isError={Boolean(error?.message)}
|
|
||||||
errorText={error?.message}
|
|
||||||
className="mb-0"
|
|
||||||
>
|
|
||||||
<Input {...field} placeholder="ec2-user" />
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<div className="flex-grow">
|
|
||||||
{i === 0 && (
|
|
||||||
<FormLabel label="Allowed Principals" className="text-xs text-mineshaft-400" />
|
|
||||||
)}
|
|
||||||
<Controller
|
|
||||||
control={control}
|
|
||||||
name={`loginMappings.${i}.allowedPrincipals`}
|
|
||||||
render={({ field, fieldState: { error } }) => (
|
|
||||||
<FormControl
|
|
||||||
isError={Boolean(error?.message)}
|
|
||||||
errorText={error?.message}
|
|
||||||
className="mb-0"
|
|
||||||
>
|
|
||||||
<Input {...field} placeholder="[email protected], [email protected]" />
|
|
||||||
</FormControl>
|
|
||||||
)}
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<IconButton
|
|
||||||
ariaLabel="delete key"
|
|
||||||
className="bottom-0.5 h-9"
|
|
||||||
variant="outline_bg"
|
|
||||||
onClick={() => loginMappingsFormFields.remove(i)}
|
|
||||||
>
|
|
||||||
<FontAwesomeIcon icon={faTrash} />
|
|
||||||
</IconButton>
|
|
||||||
</div>
|
|
||||||
))}
|
|
||||||
</div>
|
|
||||||
<div className="mt-2 flex justify-end">
|
|
||||||
<Button
|
<Button
|
||||||
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
size="xs"
|
size="xs"
|
||||||
variant="outline_bg"
|
variant="outline_bg"
|
||||||
onClick={() =>
|
onClick={() => {
|
||||||
loginMappingsFormFields.append({ loginUser: "", allowedPrincipals: "" })
|
const newIndex = loginMappingsFormFields.fields.length;
|
||||||
}
|
loginMappingsFormFields.append({ loginUser: "", allowedPrincipals: [""] });
|
||||||
|
setExpandedMappings((prev) => ({
|
||||||
|
...prev,
|
||||||
|
[newIndex]: true
|
||||||
|
}));
|
||||||
|
}}
|
||||||
>
|
>
|
||||||
Add Login Mapping
|
Add Login Mapping
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
|
<div className="mb-4 flex flex-col space-y-4">
|
||||||
|
{loginMappingsFormFields.fields.map(({ id: metadataFieldId }, i) => (
|
||||||
|
<div
|
||||||
|
key={metadataFieldId}
|
||||||
|
className="flex flex-col space-y-2 rounded-md border border-mineshaft-600 p-4"
|
||||||
|
>
|
||||||
|
<div className="mb-2 flex items-center justify-between">
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
className="flex cursor-pointer items-center py-1 text-sm text-mineshaft-200"
|
||||||
|
onClick={() => toggleMapping(i)}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon
|
||||||
|
icon={expandedMappings[i] ? faChevronDown : faChevronRight}
|
||||||
|
className="mr-4"
|
||||||
|
size="sm"
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name={`loginMappings.${i}.loginUser`}
|
||||||
|
render={({ field }) => (
|
||||||
|
<span className="text-sm font-medium leading-tight">
|
||||||
|
{field.value || "New Login Mapping"}
|
||||||
|
</span>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
</button>
|
||||||
|
<IconButton
|
||||||
|
ariaLabel="delete login mapping"
|
||||||
|
variant="plain"
|
||||||
|
onClick={() => loginMappingsFormFields.remove(i)}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={faTrash} />
|
||||||
|
</IconButton>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{expandedMappings[i] && (
|
||||||
|
<>
|
||||||
|
<div>
|
||||||
|
<span className="text-xs text-mineshaft-400">Login User</span>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name={`loginMappings.${i}.loginUser`}
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
errorText={error?.message}
|
||||||
|
className="mb-0"
|
||||||
|
>
|
||||||
|
<Input
|
||||||
|
{...field}
|
||||||
|
placeholder="ec2-user"
|
||||||
|
onChange={(e) => {
|
||||||
|
const newValue = e.target.value;
|
||||||
|
const loginMappings = getValues("loginMappings");
|
||||||
|
const isDuplicate = loginMappings.some(
|
||||||
|
(mapping, index) => index !== i && mapping.loginUser === newValue
|
||||||
|
);
|
||||||
|
|
||||||
|
if (isDuplicate) {
|
||||||
|
createNotification({
|
||||||
|
text: "This login user already exists",
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
field.onChange(e);
|
||||||
|
}}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
<div className="flex flex-col space-y-2">
|
||||||
|
<div className="mb-2 mt-4 flex items-center justify-between">
|
||||||
|
<FormLabel
|
||||||
|
label="Allowed Principals"
|
||||||
|
className="text-xs text-mineshaft-400"
|
||||||
|
/>
|
||||||
|
<Button
|
||||||
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
|
size="xs"
|
||||||
|
variant="outline_bg"
|
||||||
|
onClick={() => {
|
||||||
|
const current = getValues(`loginMappings.${i}.allowedPrincipals`) ?? [];
|
||||||
|
setValue(`loginMappings.${i}.allowedPrincipals`, [...current, ""]);
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
Add Principal
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name={`loginMappings.${i}.allowedPrincipals`}
|
||||||
|
render={({ field: { value = [], onChange }, fieldState: { error } }) => (
|
||||||
|
<div className="flex flex-col space-y-2">
|
||||||
|
{(value.length === 0 ? [""] : value).map(
|
||||||
|
(principal: string, principalIndex: number) => (
|
||||||
|
<div
|
||||||
|
key={`${metadataFieldId}-principal-${principal}`}
|
||||||
|
className="flex items-center space-x-2"
|
||||||
|
>
|
||||||
|
<div className="flex-1">
|
||||||
|
<Select
|
||||||
|
value={principal}
|
||||||
|
onValueChange={(newValue) => {
|
||||||
|
if (value.includes(newValue)) {
|
||||||
|
createNotification({
|
||||||
|
text: "This principal is already added",
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const newPrincipals = [...value];
|
||||||
|
newPrincipals[principalIndex] = newValue;
|
||||||
|
onChange(newPrincipals);
|
||||||
|
}}
|
||||||
|
placeholder="Select a member"
|
||||||
|
className="w-full"
|
||||||
|
>
|
||||||
|
{members.map((member) => (
|
||||||
|
<SelectItem
|
||||||
|
key={member.user.id}
|
||||||
|
value={member.user.username}
|
||||||
|
>
|
||||||
|
{member.user.username}
|
||||||
|
</SelectItem>
|
||||||
|
))}
|
||||||
|
</Select>
|
||||||
|
</div>
|
||||||
|
<IconButton
|
||||||
|
size="sm"
|
||||||
|
ariaLabel="delete principal"
|
||||||
|
variant="plain"
|
||||||
|
className="h-9"
|
||||||
|
onClick={() => {
|
||||||
|
const newPrincipals = value.filter(
|
||||||
|
(_, idx) => idx !== principalIndex
|
||||||
|
);
|
||||||
|
onChange(newPrincipals);
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={faTrash} />
|
||||||
|
</IconButton>
|
||||||
|
</div>
|
||||||
|
)
|
||||||
|
)}
|
||||||
|
{error && <span className="text-sm text-red-500">{error.message}</span>}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
</>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
))}
|
||||||
|
</div>
|
||||||
<div className="flex items-center">
|
<div className="flex items-center">
|
||||||
<Button
|
<Button
|
||||||
className="mr-4"
|
className="mr-4"
|
||||||
|
|||||||
@@ -91,9 +91,9 @@ export const SshHostsTable = ({ handlePopUpOpen }: Props) => {
|
|||||||
host.loginMappings.map(({ loginUser, allowedPrincipals }) => (
|
host.loginMappings.map(({ loginUser, allowedPrincipals }) => (
|
||||||
<div key={`${host.id}-${loginUser}`} className="mb-2">
|
<div key={`${host.id}-${loginUser}`} className="mb-2">
|
||||||
<div className="text-mineshaft-200">{loginUser}</div>
|
<div className="text-mineshaft-200">{loginUser}</div>
|
||||||
{allowedPrincipals.map((principal) => (
|
{allowedPrincipals.usernames.map((username) => (
|
||||||
<div key={principal} className="ml-4">
|
<div key={`${host.id}-${loginUser}-${username}`} className="ml-4">
|
||||||
└─ {principal}
|
└─ {username}
|
||||||
</div>
|
</div>
|
||||||
))}
|
))}
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
Reference in New Issue
Block a user