mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
adjustment: made secret-deletion opt in
This commit is contained in:
@@ -674,7 +674,8 @@ export const INTEGRATION = {
|
|||||||
secretGCPLabel: "The label for GCP secrets.",
|
secretGCPLabel: "The label for GCP secrets.",
|
||||||
secretAWSTag: "The tags for AWS secrets.",
|
secretAWSTag: "The tags for AWS secrets.",
|
||||||
kmsKeyId: "The ID of the encryption key from AWS KMS.",
|
kmsKeyId: "The ID of the encryption key from AWS KMS.",
|
||||||
shouldDisableDelete: "The flag to disable deletion of secrets in AWS Parameter Store."
|
shouldDisableDelete: "The flag to disable deletion of secrets in AWS Parameter Store.",
|
||||||
|
shouldEnableDelete: "The flag to enable deletion of secrets"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
UPDATE: {
|
UPDATE: {
|
||||||
|
|||||||
@@ -73,7 +73,8 @@ export const registerIntegrationRouter = async (server: FastifyZodProvider) => {
|
|||||||
.optional()
|
.optional()
|
||||||
.describe(INTEGRATION.CREATE.metadata.secretAWSTag),
|
.describe(INTEGRATION.CREATE.metadata.secretAWSTag),
|
||||||
kmsKeyId: z.string().optional().describe(INTEGRATION.CREATE.metadata.kmsKeyId),
|
kmsKeyId: z.string().optional().describe(INTEGRATION.CREATE.metadata.kmsKeyId),
|
||||||
shouldDisableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldDisableDelete)
|
shouldDisableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldDisableDelete),
|
||||||
|
shouldEnableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldEnableDelete)
|
||||||
})
|
})
|
||||||
.default({})
|
.default({})
|
||||||
}),
|
}),
|
||||||
|
|||||||
@@ -1364,7 +1364,7 @@ const syncSecretsGitHub = async ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const metadata = z.record(z.any()).parse(integration.metadata);
|
const metadata = z.record(z.any()).parse(integration.metadata);
|
||||||
if (!metadata.shouldDisableDelete) {
|
if (metadata.shouldEnableDelete) {
|
||||||
for await (const encryptedSecret of encryptedSecrets) {
|
for await (const encryptedSecret of encryptedSecrets) {
|
||||||
if (
|
if (
|
||||||
!(encryptedSecret.name in secrets) &&
|
!(encryptedSecret.name in secrets) &&
|
||||||
|
|||||||
@@ -29,6 +29,7 @@ export type TCreateIntegrationDTO = {
|
|||||||
}[];
|
}[];
|
||||||
kmsKeyId?: string;
|
kmsKeyId?: string;
|
||||||
shouldDisableDelete?: boolean;
|
shouldDisableDelete?: boolean;
|
||||||
|
shouldEnableDelete?: boolean;
|
||||||
};
|
};
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
@@ -54,6 +55,7 @@ export type TUpdateIntegrationDTO = {
|
|||||||
}[];
|
}[];
|
||||||
kmsKeyId?: string;
|
kmsKeyId?: string;
|
||||||
shouldDisableDelete?: boolean;
|
shouldDisableDelete?: boolean;
|
||||||
|
shouldEnableDelete?: boolean;
|
||||||
};
|
};
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
|||||||
@@ -73,6 +73,7 @@ export const useCreateIntegration = () => {
|
|||||||
}[];
|
}[];
|
||||||
kmsKeyId?: string;
|
kmsKeyId?: string;
|
||||||
shouldDisableDelete?: boolean;
|
shouldDisableDelete?: boolean;
|
||||||
|
shouldEnableDelete?: boolean;
|
||||||
};
|
};
|
||||||
}) => {
|
}) => {
|
||||||
const {
|
const {
|
||||||
|
|||||||
@@ -60,7 +60,7 @@ const schema = yup.object({
|
|||||||
selectedSourceEnvironment: yup.string().trim().required("Project Environment is required"),
|
selectedSourceEnvironment: yup.string().trim().required("Project Environment is required"),
|
||||||
secretPath: yup.string().trim().required("Secrets Path is required"),
|
secretPath: yup.string().trim().required("Secrets Path is required"),
|
||||||
secretSuffix: yup.string().trim().optional(),
|
secretSuffix: yup.string().trim().optional(),
|
||||||
shouldDisableDelete: yup.boolean().optional(),
|
shouldEnableDelete: yup.boolean().optional(),
|
||||||
scope: yup.mixed<TargetEnv>().oneOf(targetEnv.slice()).required(),
|
scope: yup.mixed<TargetEnv>().oneOf(targetEnv.slice()).required(),
|
||||||
|
|
||||||
repoIds: yup.mixed().when("scope", {
|
repoIds: yup.mixed().when("scope", {
|
||||||
@@ -121,7 +121,7 @@ export default function GitHubCreateIntegrationPage() {
|
|||||||
secretPath: "/",
|
secretPath: "/",
|
||||||
scope: "github-repo",
|
scope: "github-repo",
|
||||||
repoIds: [],
|
repoIds: [],
|
||||||
shouldDisableDelete: false
|
shouldEnableDelete: false
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -179,7 +179,7 @@ export default function GitHubCreateIntegrationPage() {
|
|||||||
owner: targetApp.owner, // repo owner
|
owner: targetApp.owner, // repo owner
|
||||||
metadata: {
|
metadata: {
|
||||||
secretSuffix: data.secretSuffix,
|
secretSuffix: data.secretSuffix,
|
||||||
shouldDisableDelete: data.shouldDisableDelete
|
shouldEnableDelete: data.shouldEnableDelete
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
})
|
})
|
||||||
@@ -197,7 +197,7 @@ export default function GitHubCreateIntegrationPage() {
|
|||||||
owner: integrationAuthOrgs?.find((e) => e.orgId === data.orgId)?.name,
|
owner: integrationAuthOrgs?.find((e) => e.orgId === data.orgId)?.name,
|
||||||
metadata: {
|
metadata: {
|
||||||
secretSuffix: data.secretSuffix,
|
secretSuffix: data.secretSuffix,
|
||||||
shouldDisableDelete: data.shouldDisableDelete
|
shouldEnableDelete: data.shouldEnableDelete
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
break;
|
break;
|
||||||
@@ -215,7 +215,7 @@ export default function GitHubCreateIntegrationPage() {
|
|||||||
targetEnvironmentId: data.envId,
|
targetEnvironmentId: data.envId,
|
||||||
metadata: {
|
metadata: {
|
||||||
secretSuffix: data.secretSuffix,
|
secretSuffix: data.secretSuffix,
|
||||||
shouldDisableDelete: data.shouldDisableDelete
|
shouldEnableDelete: data.shouldEnableDelete
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
break;
|
break;
|
||||||
@@ -553,14 +553,14 @@ export default function GitHubCreateIntegrationPage() {
|
|||||||
<div className="ml-1 mb-5">
|
<div className="ml-1 mb-5">
|
||||||
<Controller
|
<Controller
|
||||||
control={control}
|
control={control}
|
||||||
name="shouldDisableDelete"
|
name="shouldEnableDelete"
|
||||||
render={({ field: { onChange, value } }) => (
|
render={({ field: { onChange, value } }) => (
|
||||||
<Switch
|
<Switch
|
||||||
id="delete-github-option"
|
id="delete-github-option"
|
||||||
onCheckedChange={(isChecked) => onChange(isChecked)}
|
onCheckedChange={(isChecked) => onChange(isChecked)}
|
||||||
isChecked={value}
|
isChecked={value}
|
||||||
>
|
>
|
||||||
Disable secrets deletion on Github
|
Delete secrets not in Infisical
|
||||||
</Switch>
|
</Switch>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
|
|||||||
Reference in New Issue
Block a user