diff --git a/backend/src/db/migrations/20250815022242_identity-lockouts.ts b/backend/src/db/migrations/20250815022242_identity-lockouts.ts new file mode 100644 index 000000000..d25ee4f47 --- /dev/null +++ b/backend/src/db/migrations/20250815022242_identity-lockouts.ts @@ -0,0 +1,57 @@ +import { Knex } from "knex"; + +import { TableName } from "../schemas"; + +export async function up(knex: Knex): Promise { + if (await knex.schema.hasTable(TableName.IdentityUniversalAuth)) { + const hasLockoutEnabled = await knex.schema.hasColumn(TableName.IdentityUniversalAuth, "lockoutEnabled"); + const hasLockoutThreshold = await knex.schema.hasColumn(TableName.IdentityUniversalAuth, "lockoutThreshold"); + const hasLockoutDuration = await knex.schema.hasColumn(TableName.IdentityUniversalAuth, "lockoutDurationSeconds"); + const hasLockoutCounterReset = await knex.schema.hasColumn( + TableName.IdentityUniversalAuth, + "lockoutCounterResetSeconds" + ); + + await knex.schema.alterTable(TableName.IdentityUniversalAuth, (t) => { + if (!hasLockoutEnabled) { + t.boolean("lockoutEnabled").notNullable().defaultTo(true); + } + if (!hasLockoutThreshold) { + t.integer("lockoutThreshold").notNullable().defaultTo(3); + } + if (!hasLockoutDuration) { + t.integer("lockoutDurationSeconds").notNullable().defaultTo(300); // 5 minutes + } + if (!hasLockoutCounterReset) { + t.integer("lockoutCounterResetSeconds").notNullable().defaultTo(30); // 30 seconds + } + }); + } +} + +export async function down(knex: Knex): Promise { + if (await knex.schema.hasTable(TableName.IdentityUniversalAuth)) { + const hasLockoutEnabled = await knex.schema.hasColumn(TableName.IdentityUniversalAuth, "lockoutEnabled"); + const hasLockoutThreshold = await knex.schema.hasColumn(TableName.IdentityUniversalAuth, "lockoutThreshold"); + const hasLockoutDuration = await knex.schema.hasColumn(TableName.IdentityUniversalAuth, "lockoutDurationSeconds"); + const hasLockoutCounterReset = await knex.schema.hasColumn( + TableName.IdentityUniversalAuth, + "lockoutCounterResetSeconds" + ); + + await knex.schema.alterTable(TableName.IdentityUniversalAuth, (t) => { + if (hasLockoutEnabled) { + t.dropColumn("lockoutEnabled"); + } + if (hasLockoutThreshold) { + t.dropColumn("lockoutThreshold"); + } + if (hasLockoutDuration) { + t.dropColumn("lockoutDurationSeconds"); + } + if (hasLockoutCounterReset) { + t.dropColumn("lockoutCounterResetSeconds"); + } + }); + } +} diff --git a/backend/src/db/schemas/identity-universal-auths.ts b/backend/src/db/schemas/identity-universal-auths.ts index da27b4a55..29e8314aa 100644 --- a/backend/src/db/schemas/identity-universal-auths.ts +++ b/backend/src/db/schemas/identity-universal-auths.ts @@ -18,7 +18,11 @@ export const IdentityUniversalAuthsSchema = z.object({ createdAt: z.date(), updatedAt: z.date(), identityId: z.string().uuid(), - accessTokenPeriod: z.coerce.number().default(0) + accessTokenPeriod: z.coerce.number().default(0), + lockoutEnabled: z.boolean().default(true), + lockoutThreshold: z.number().default(3), + lockoutDurationSeconds: z.number().default(300), + lockoutCounterResetSeconds: z.number().default(30) }); export type TIdentityUniversalAuths = z.infer; diff --git a/backend/src/ee/services/audit-log/audit-log-service.ts b/backend/src/ee/services/audit-log/audit-log-service.ts index 06186d54b..ece5edaf9 100644 --- a/backend/src/ee/services/audit-log/audit-log-service.ts +++ b/backend/src/ee/services/audit-log/audit-log-service.ts @@ -6,9 +6,9 @@ import { getConfig } from "@app/lib/config/env"; import { BadRequestError } from "@app/lib/errors"; import { ActorType } from "@app/services/auth/auth-type"; -import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission"; +import { OrgPermissionAuditLogsActions, OrgPermissionSubjects } from "../permission/org-permission"; import { TPermissionServiceFactory } from "../permission/permission-service-types"; -import { ProjectPermissionActions, ProjectPermissionSub } from "../permission/project-permission"; +import { ProjectPermissionAuditLogsActions, ProjectPermissionSub } from "../permission/project-permission"; import { TAuditLogDALFactory } from "./audit-log-dal"; import { TAuditLogQueueServiceFactory } from "./audit-log-queue"; import { EventType, TAuditLogServiceFactory } from "./audit-log-types"; @@ -41,7 +41,10 @@ export const auditLogServiceFactory = ({ actorOrgId, actionProjectType: ActionProjectType.Any }); - ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.AuditLogs); + ForbiddenError.from(permission).throwUnlessCan( + ProjectPermissionAuditLogsActions.Read, + ProjectPermissionSub.AuditLogs + ); } else { // Organization-wide logs const { permission } = await permissionService.getOrgPermission( @@ -52,7 +55,10 @@ export const auditLogServiceFactory = ({ actorOrgId ); - ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.AuditLogs); + ForbiddenError.from(permission).throwUnlessCan( + OrgPermissionAuditLogsActions.Read, + OrgPermissionSubjects.AuditLogs + ); } // If project ID is not provided, then we need to return all the audit logs for the organization itself. diff --git a/backend/src/ee/services/audit-log/audit-log-types.ts b/backend/src/ee/services/audit-log/audit-log-types.ts index 818c46446..10c84cc4a 100644 --- a/backend/src/ee/services/audit-log/audit-log-types.ts +++ b/backend/src/ee/services/audit-log/audit-log-types.ts @@ -198,6 +198,7 @@ export enum EventType { CREATE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "create-identity-universal-auth-client-secret", REVOKE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "revoke-identity-universal-auth-client-secret", + CLEAR_IDENTITY_UNIVERSAL_AUTH_LOCKOUTS = "clear-identity-universal-auth-lockouts", GET_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRETS = "get-identity-universal-auth-client-secret", GET_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET_BY_ID = "get-identity-universal-auth-client-secret-by-id", @@ -867,6 +868,10 @@ interface AddIdentityUniversalAuthEvent { accessTokenMaxTTL: number; accessTokenNumUsesLimit: number; accessTokenTrustedIps: Array; + lockoutEnabled: boolean; + lockoutThreshold: number; + lockoutDurationSeconds: number; + lockoutCounterResetSeconds: number; }; } @@ -879,6 +884,10 @@ interface UpdateIdentityUniversalAuthEvent { accessTokenMaxTTL?: number; accessTokenNumUsesLimit?: number; accessTokenTrustedIps?: Array; + lockoutEnabled?: boolean; + lockoutThreshold?: number; + lockoutDurationSeconds?: number; + lockoutCounterResetSeconds?: number; }; } @@ -1038,6 +1047,13 @@ interface RevokeIdentityUniversalAuthClientSecretEvent { }; } +interface ClearIdentityUniversalAuthLockoutsEvent { + type: EventType.CLEAR_IDENTITY_UNIVERSAL_AUTH_LOCKOUTS; + metadata: { + identityId: string; + }; +} + interface LoginIdentityGcpAuthEvent { type: EventType.LOGIN_IDENTITY_GCP_AUTH; metadata: { @@ -3500,6 +3516,7 @@ export type Event = | GetIdentityUniversalAuthClientSecretsEvent | GetIdentityUniversalAuthClientSecretByIdEvent | RevokeIdentityUniversalAuthClientSecretEvent + | ClearIdentityUniversalAuthLockoutsEvent | LoginIdentityGcpAuthEvent | AddIdentityGcpAuthEvent | DeleteIdentityGcpAuthEvent diff --git a/backend/src/ee/services/permission/default-roles.ts b/backend/src/ee/services/permission/default-roles.ts index 349130d8e..9329c3c7f 100644 --- a/backend/src/ee/services/permission/default-roles.ts +++ b/backend/src/ee/services/permission/default-roles.ts @@ -2,6 +2,7 @@ import { AbilityBuilder, createMongoAbility, MongoAbility } from "@casl/ability" import { ProjectPermissionActions, + ProjectPermissionAuditLogsActions, ProjectPermissionCertificateActions, ProjectPermissionCmekActions, ProjectPermissionCommitsActions, @@ -394,7 +395,7 @@ const buildMemberPermissionRules = () => { ); can([ProjectPermissionActions.Read], ProjectPermissionSub.Role); - can([ProjectPermissionActions.Read], ProjectPermissionSub.AuditLogs); + can([ProjectPermissionAuditLogsActions.Read], ProjectPermissionSub.AuditLogs); can([ProjectPermissionActions.Read], ProjectPermissionSub.IpAllowList); // double check if all CRUD are needed for CA and Certificates @@ -502,7 +503,7 @@ const buildViewerPermissionRules = () => { can(ProjectPermissionActions.Read, ProjectPermissionSub.Settings); can(ProjectPermissionActions.Read, ProjectPermissionSub.Environments); can(ProjectPermissionActions.Read, ProjectPermissionSub.Tags); - can(ProjectPermissionActions.Read, ProjectPermissionSub.AuditLogs); + can(ProjectPermissionAuditLogsActions.Read, ProjectPermissionSub.AuditLogs); can(ProjectPermissionActions.Read, ProjectPermissionSub.IpAllowList); can(ProjectPermissionActions.Read, ProjectPermissionSub.CertificateAuthorities); can(ProjectPermissionCertificateActions.Read, ProjectPermissionSub.Certificates); diff --git a/backend/src/ee/services/permission/org-permission.ts b/backend/src/ee/services/permission/org-permission.ts index 2436dae2a..d0b1ca3dd 100644 --- a/backend/src/ee/services/permission/org-permission.ts +++ b/backend/src/ee/services/permission/org-permission.ts @@ -23,6 +23,10 @@ export enum OrgPermissionAppConnectionActions { Connect = "connect" } +export enum OrgPermissionAuditLogsActions { + Read = "read" +} + export enum OrgPermissionKmipActions { Proxy = "proxy", Setup = "setup" @@ -125,7 +129,7 @@ export type OrgPermissionSet = | [OrgPermissionBillingActions, OrgPermissionSubjects.Billing] | [OrgPermissionIdentityActions, OrgPermissionSubjects.Identity] | [OrgPermissionActions, OrgPermissionSubjects.Kms] - | [OrgPermissionActions, OrgPermissionSubjects.AuditLogs] + | [OrgPermissionAuditLogsActions, OrgPermissionSubjects.AuditLogs] | [OrgPermissionActions, OrgPermissionSubjects.ProjectTemplates] | [OrgPermissionGatewayActions, OrgPermissionSubjects.Gateway] | [ @@ -214,7 +218,9 @@ export const OrgPermissionSchema = z.discriminatedUnion("subject", [ }), z.object({ subject: z.literal(OrgPermissionSubjects.AuditLogs).describe("The entity this permission pertains to."), - action: CASL_ACTION_SCHEMA_NATIVE_ENUM(OrgPermissionActions).describe("Describe what action an entity can take.") + action: CASL_ACTION_SCHEMA_NATIVE_ENUM(OrgPermissionAuditLogsActions).describe( + "Describe what action an entity can take." + ) }), z.object({ subject: z.literal(OrgPermissionSubjects.ProjectTemplates).describe("The entity this permission pertains to."), @@ -340,10 +346,7 @@ const buildAdminPermission = () => { can(OrgPermissionActions.Edit, OrgPermissionSubjects.Kms); can(OrgPermissionActions.Delete, OrgPermissionSubjects.Kms); - can(OrgPermissionActions.Read, OrgPermissionSubjects.AuditLogs); - can(OrgPermissionActions.Create, OrgPermissionSubjects.AuditLogs); - can(OrgPermissionActions.Edit, OrgPermissionSubjects.AuditLogs); - can(OrgPermissionActions.Delete, OrgPermissionSubjects.AuditLogs); + can(OrgPermissionAuditLogsActions.Read, OrgPermissionSubjects.AuditLogs); can(OrgPermissionActions.Read, OrgPermissionSubjects.ProjectTemplates); can(OrgPermissionActions.Create, OrgPermissionSubjects.ProjectTemplates); @@ -416,7 +419,7 @@ const buildMemberPermission = () => { can(OrgPermissionIdentityActions.Edit, OrgPermissionSubjects.Identity); can(OrgPermissionIdentityActions.Delete, OrgPermissionSubjects.Identity); - can(OrgPermissionActions.Read, OrgPermissionSubjects.AuditLogs); + can(OrgPermissionAuditLogsActions.Read, OrgPermissionSubjects.AuditLogs); can(OrgPermissionAppConnectionActions.Connect, OrgPermissionSubjects.AppConnections); can(OrgPermissionGatewayActions.ListGateways, OrgPermissionSubjects.Gateway); diff --git a/backend/src/ee/services/permission/project-permission.ts b/backend/src/ee/services/permission/project-permission.ts index ab8fea5df..20b4344d3 100644 --- a/backend/src/ee/services/permission/project-permission.ts +++ b/backend/src/ee/services/permission/project-permission.ts @@ -164,6 +164,10 @@ export enum ProjectPermissionSecretEventActions { SubscribeImportMutations = "subscribe-on-import-mutations" } +export enum ProjectPermissionAuditLogsActions { + Read = "read" +} + export enum ProjectPermissionSub { Role = "role", Member = "member", @@ -304,7 +308,7 @@ export type ProjectPermissionSet = | [ProjectPermissionGroupActions, ProjectPermissionSub.Groups] | [ProjectPermissionActions, ProjectPermissionSub.Integrations] | [ProjectPermissionActions, ProjectPermissionSub.Webhooks] - | [ProjectPermissionActions, ProjectPermissionSub.AuditLogs] + | [ProjectPermissionAuditLogsActions, ProjectPermissionSub.AuditLogs] | [ProjectPermissionActions, ProjectPermissionSub.Environments] | [ProjectPermissionActions, ProjectPermissionSub.IpAllowList] | [ProjectPermissionActions, ProjectPermissionSub.Settings] @@ -645,7 +649,7 @@ const GeneralPermissionSchema = [ }), z.object({ subject: z.literal(ProjectPermissionSub.AuditLogs).describe("The entity this permission pertains to."), - action: CASL_ACTION_SCHEMA_NATIVE_ENUM(ProjectPermissionActions).describe( + action: CASL_ACTION_SCHEMA_NATIVE_ENUM(ProjectPermissionAuditLogsActions).describe( "Describe what action an entity can take." ) }), diff --git a/backend/src/keystore/keystore.ts b/backend/src/keystore/keystore.ts index 26aff767e..3f7b8dc9f 100644 --- a/backend/src/keystore/keystore.ts +++ b/backend/src/keystore/keystore.ts @@ -13,7 +13,8 @@ export const PgSqlLock = { SecretRotationV2Creation: (folderId: string) => pgAdvisoryLockHashText(`secret-rotation-v2-creation:${folderId}`), CreateProject: (orgId: string) => pgAdvisoryLockHashText(`create-project:${orgId}`), CreateFolder: (envId: string, projectId: string) => pgAdvisoryLockHashText(`create-folder:${envId}-${projectId}`), - SshInit: (projectId: string) => pgAdvisoryLockHashText(`ssh-bootstrap:${projectId}`) + SshInit: (projectId: string) => pgAdvisoryLockHashText(`ssh-bootstrap:${projectId}`), + IdentityLogin: (identityId: string, nonce: string) => pgAdvisoryLockHashText(`identity-login:${identityId}:${nonce}`) } as const; // all the key prefixes used must be set here to avoid conflict diff --git a/backend/src/lib/api-docs/constants.ts b/backend/src/lib/api-docs/constants.ts index 47f5ca5cd..d61694d8f 100644 --- a/backend/src/lib/api-docs/constants.ts +++ b/backend/src/lib/api-docs/constants.ts @@ -166,7 +166,12 @@ export const UNIVERSAL_AUTH = { accessTokenNumUsesLimit: "The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses.", accessTokenPeriod: - "The period for an access token in seconds. This value will be referenced at renewal time. Default value is 0." + "The period for an access token in seconds. This value will be referenced at renewal time. Default value is 0.", + lockoutEnabled: "Whether the lockout feature is enabled.", + lockoutThreshold: "The amount of times login must fail before locking the identity auth method.", + lockoutDurationSeconds: "How long an identity auth method lockout lasts.", + lockoutCounterResetSeconds: + "How long to wait from the most recent failed login until resetting the lockout counter." }, RETRIEVE: { identityId: "The ID of the identity to retrieve the auth method for." @@ -181,7 +186,12 @@ export const UNIVERSAL_AUTH = { accessTokenTTL: "The new lifetime for an access token in seconds.", accessTokenMaxTTL: "The new maximum lifetime for an access token in seconds.", accessTokenNumUsesLimit: "The new maximum number of times that an access token can be used.", - accessTokenPeriod: "The new period for an access token in seconds." + accessTokenPeriod: "The new period for an access token in seconds.", + lockoutEnabled: "Whether the lockout feature is enabled.", + lockoutThreshold: "The amount of times login must fail before locking the identity auth method.", + lockoutDurationSeconds: "How long an identity auth method lockout lasts.", + lockoutCounterResetSeconds: + "How long to wait from the most recent failed login until resetting the lockout counter." }, CREATE_CLIENT_SECRET: { identityId: "The ID of the identity to create a client secret for.", @@ -201,6 +211,9 @@ export const UNIVERSAL_AUTH = { identityId: "The ID of the identity to revoke the client secret from.", clientSecretId: "The ID of the client secret to revoke." }, + CLEAR_CLIENT_LOCKOUTS: { + identityId: "The ID of the identity to clear the client lockouts from." + }, RENEW_ACCESS_TOKEN: { accessToken: "The access token to renew." }, @@ -2148,7 +2161,9 @@ export const CertificateAuthorities = { directoryUrl: `The directory URL for the ACME Certificate Authority.`, accountEmail: `The email address for the ACME Certificate Authority.`, provider: `The DNS provider for the ACME Certificate Authority.`, - hostedZoneId: `The hosted zone ID for the ACME Certificate Authority.` + hostedZoneId: `The hosted zone ID for the ACME Certificate Authority.`, + eabKid: `The External Account Binding (EAB) Key ID for the ACME Certificate Authority. Required if the ACME provider uses EAB.`, + eabHmacKey: `The External Account Binding (EAB) HMAC key for the ACME Certificate Authority. Required if the ACME provider uses EAB.` }, INTERNAL: { type: "The type of CA to create.", diff --git a/backend/src/server/routes/index.ts b/backend/src/server/routes/index.ts index 17b94312e..88ab64847 100644 --- a/backend/src/server/routes/index.ts +++ b/backend/src/server/routes/index.ts @@ -1464,7 +1464,8 @@ export const registerRoutes = async ( identityOrgMembershipDAL, identityProjectDAL, licenseService, - identityMetadataDAL + identityMetadataDAL, + keyStore }); const identityAuthTemplateService = identityAuthTemplateServiceFactory({ @@ -1518,7 +1519,8 @@ export const registerRoutes = async ( identityAccessTokenDAL, identityUaClientSecretDAL, identityUaDAL, - licenseService + licenseService, + keyStore }); const identityKubernetesAuthService = identityKubernetesAuthServiceFactory({ @@ -1752,7 +1754,8 @@ export const registerRoutes = async ( const migrationService = externalMigrationServiceFactory({ externalMigrationQueue, userDAL, - permissionService + permissionService, + gatewayService }); const externalGroupOrgRoleMappingService = externalGroupOrgRoleMappingServiceFactory({ diff --git a/backend/src/server/routes/v1/dashboard-router.ts b/backend/src/server/routes/v1/dashboard-router.ts index 48d536c14..a54bd5ccf 100644 --- a/backend/src/server/routes/v1/dashboard-router.ts +++ b/backend/src/server/routes/v1/dashboard-router.ts @@ -703,6 +703,9 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => { // prevent older projects from accessing endpoint if (!shouldUseSecretV2Bridge) throw new BadRequestError({ message: "Project version not supported" }); + // verify folder exists and user has project permission + await server.services.folder.getFolderByPath({ projectId, environment, secretPath }, req.permission); + const tags = req.query.tags?.split(",") ?? []; let remainingLimit = limit; diff --git a/backend/src/server/routes/v1/identity-router.ts b/backend/src/server/routes/v1/identity-router.ts index 9acd515c4..65b9448c5 100644 --- a/backend/src/server/routes/v1/identity-router.ts +++ b/backend/src/server/routes/v1/identity-router.ts @@ -250,7 +250,8 @@ export const registerIdentityRouter = async (server: FastifyZodProvider) => { description: true }).optional(), identity: IdentitiesSchema.pick({ name: true, id: true, hasDeleteProtection: true }).extend({ - authMethods: z.array(z.string()) + authMethods: z.array(z.string()), + activeLockoutAuthMethods: z.array(z.string()) }) }) }) diff --git a/backend/src/server/routes/v1/identity-universal-auth-router.ts b/backend/src/server/routes/v1/identity-universal-auth-router.ts index 09fffbff8..6d911a88e 100644 --- a/backend/src/server/routes/v1/identity-universal-auth-router.ts +++ b/backend/src/server/routes/v1/identity-universal-auth-router.ts @@ -137,7 +137,21 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { .min(0) .default(0) .describe(UNIVERSAL_AUTH.ATTACH.accessTokenNumUsesLimit), - accessTokenPeriod: z.number().int().min(0).default(0).describe(UNIVERSAL_AUTH.ATTACH.accessTokenPeriod) + accessTokenPeriod: z.number().int().min(0).default(0).describe(UNIVERSAL_AUTH.ATTACH.accessTokenPeriod), + lockoutEnabled: z.boolean().default(true).describe(UNIVERSAL_AUTH.ATTACH.lockoutEnabled), + lockoutThreshold: z.number().min(1).max(30).default(3).describe(UNIVERSAL_AUTH.ATTACH.lockoutThreshold), + lockoutDurationSeconds: z + .number() + .min(30) + .max(86400) + .default(300) + .describe(UNIVERSAL_AUTH.ATTACH.lockoutDurationSeconds), + lockoutCounterResetSeconds: z + .number() + .min(5) + .max(3600) + .default(30) + .describe(UNIVERSAL_AUTH.ATTACH.lockoutCounterResetSeconds) }) .refine( (val) => val.accessTokenTTL <= val.accessTokenMaxTTL, @@ -171,7 +185,11 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { accessTokenMaxTTL: identityUniversalAuth.accessTokenMaxTTL, accessTokenTrustedIps: identityUniversalAuth.accessTokenTrustedIps as TIdentityTrustedIp[], clientSecretTrustedIps: identityUniversalAuth.clientSecretTrustedIps as TIdentityTrustedIp[], - accessTokenNumUsesLimit: identityUniversalAuth.accessTokenNumUsesLimit + accessTokenNumUsesLimit: identityUniversalAuth.accessTokenNumUsesLimit, + lockoutEnabled: identityUniversalAuth.lockoutEnabled, + lockoutThreshold: identityUniversalAuth.lockoutThreshold, + lockoutDurationSeconds: identityUniversalAuth.lockoutDurationSeconds, + lockoutCounterResetSeconds: identityUniversalAuth.lockoutCounterResetSeconds } } }); @@ -243,7 +261,21 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { .min(0) .max(315360000) .optional() - .describe(UNIVERSAL_AUTH.UPDATE.accessTokenPeriod) + .describe(UNIVERSAL_AUTH.UPDATE.accessTokenPeriod), + lockoutEnabled: z.boolean().optional().describe(UNIVERSAL_AUTH.UPDATE.lockoutEnabled), + lockoutThreshold: z.number().min(1).max(30).optional().describe(UNIVERSAL_AUTH.UPDATE.lockoutThreshold), + lockoutDurationSeconds: z + .number() + .min(30) + .max(86400) + .optional() + .describe(UNIVERSAL_AUTH.UPDATE.lockoutDurationSeconds), + lockoutCounterResetSeconds: z + .number() + .min(5) + .max(3600) + .optional() + .describe(UNIVERSAL_AUTH.UPDATE.lockoutCounterResetSeconds) }) .refine( (val) => (val.accessTokenMaxTTL && val.accessTokenTTL ? val.accessTokenTTL <= val.accessTokenMaxTTL : true), @@ -276,7 +308,11 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { accessTokenMaxTTL: identityUniversalAuth.accessTokenMaxTTL, accessTokenTrustedIps: identityUniversalAuth.accessTokenTrustedIps as TIdentityTrustedIp[], clientSecretTrustedIps: identityUniversalAuth.clientSecretTrustedIps as TIdentityTrustedIp[], - accessTokenNumUsesLimit: identityUniversalAuth.accessTokenNumUsesLimit + accessTokenNumUsesLimit: identityUniversalAuth.accessTokenNumUsesLimit, + lockoutEnabled: identityUniversalAuth.lockoutEnabled, + lockoutThreshold: identityUniversalAuth.lockoutThreshold, + lockoutDurationSeconds: identityUniversalAuth.lockoutDurationSeconds, + lockoutCounterResetSeconds: identityUniversalAuth.lockoutCounterResetSeconds } } }); @@ -594,4 +630,53 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { return { clientSecretData }; } }); + + server.route({ + method: "POST", + url: "/universal-auth/identities/:identityId/clear-lockouts", + config: { + rateLimit: writeLimit + }, + onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), + schema: { + hide: false, + tags: [ApiDocsTags.UniversalAuth], + description: "Clear Universal Auth Lockouts for identity", + security: [ + { + bearerAuth: [] + } + ], + params: z.object({ + identityId: z.string().describe(UNIVERSAL_AUTH.CLEAR_CLIENT_LOCKOUTS.identityId) + }), + response: { + 200: z.object({ + deleted: z.number() + }) + } + }, + handler: async (req) => { + const clearLockoutsData = await server.services.identityUa.clearUniversalAuthLockouts({ + actor: req.permission.type, + actorId: req.permission.id, + actorAuthMethod: req.permission.authMethod, + actorOrgId: req.permission.orgId, + identityId: req.params.identityId + }); + + await server.services.auditLog.createAuditLog({ + ...req.auditLogInfo, + orgId: clearLockoutsData.orgId, + event: { + type: EventType.CLEAR_IDENTITY_UNIVERSAL_AUTH_LOCKOUTS, + metadata: { + identityId: clearLockoutsData.identityId + } + } + }); + + return clearLockoutsData; + } + }); }; diff --git a/backend/src/server/routes/v3/external-migration-router.ts b/backend/src/server/routes/v3/external-migration-router.ts index 4325692da..259a97ddb 100644 --- a/backend/src/server/routes/v3/external-migration-router.ts +++ b/backend/src/server/routes/v3/external-migration-router.ts @@ -66,7 +66,8 @@ export const registerExternalMigrationRouter = async (server: FastifyZodProvider vaultAccessToken: z.string(), vaultNamespace: z.string().trim().optional(), vaultUrl: z.string(), - mappingType: z.nativeEnum(VaultMappingType) + mappingType: z.nativeEnum(VaultMappingType), + gatewayId: z.string().optional() }) }, onRequest: verifyAuth([AuthMode.JWT]), diff --git a/backend/src/server/routes/v3/secret-router.ts b/backend/src/server/routes/v3/secret-router.ts index 55fc094b7..ce0d4f188 100644 --- a/backend/src/server/routes/v3/secret-router.ts +++ b/backend/src/server/routes/v3/secret-router.ts @@ -419,6 +419,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => { 200: z.object({ secret: secretRawSchema.extend({ secretValueHidden: z.boolean(), + secretPath: z.string(), tags: SanitizedTagSchema.array().optional(), secretMetadata: ResourceMetadataSchema.optional() }) diff --git a/backend/src/services/auth/auth-login-service.ts b/backend/src/services/auth/auth-login-service.ts index e3afb754a..0e5ed2ad9 100644 --- a/backend/src/services/auth/auth-login-service.ts +++ b/backend/src/services/auth/auth-login-service.ts @@ -453,10 +453,14 @@ export const authLoginServiceFactory = ({ const selectedOrg = await orgDAL.findById(organizationId); - // Check if authEnforced is true, if that's the case, throw an error - if (selectedOrg.authEnforced) { + // Check if authEnforced is true and the current auth method is not an enforced method + if ( + selectedOrg.authEnforced && + !isAuthMethodSaml(decodedToken.authMethod) && + decodedToken.authMethod !== AuthMethod.OIDC + ) { throw new BadRequestError({ - message: "Authentication is required by your organization before you can log in." + message: "Login with the auth method required by your organization." }); } diff --git a/backend/src/services/certificate-authority/acme/acme-certificate-authority-fns.ts b/backend/src/services/certificate-authority/acme/acme-certificate-authority-fns.ts index 86beadffe..830378ca8 100644 --- a/backend/src/services/certificate-authority/acme/acme-certificate-authority-fns.ts +++ b/backend/src/services/certificate-authority/acme/acme-certificate-authority-fns.ts @@ -64,6 +64,8 @@ type DBConfigurationColumn = { directoryUrl: string; accountEmail: string; hostedZoneId: string; + eabKid?: string; + eabHmacKey?: string; }; export const castDbEntryToAcmeCertificateAuthority = ( @@ -89,7 +91,9 @@ export const castDbEntryToAcmeCertificateAuthority = ( hostedZoneId: dbConfigurationCol.hostedZoneId }, directoryUrl: dbConfigurationCol.directoryUrl, - accountEmail: dbConfigurationCol.accountEmail + accountEmail: dbConfigurationCol.accountEmail, + eabKid: dbConfigurationCol.eabKid, + eabHmacKey: dbConfigurationCol.eabHmacKey }, status: ca.status as CaStatus }; @@ -128,7 +132,7 @@ export const AcmeCertificateAuthorityFns = ({ }); } - const { dnsAppConnectionId, directoryUrl, accountEmail, dnsProviderConfig } = configuration; + const { dnsAppConnectionId, directoryUrl, accountEmail, dnsProviderConfig, eabKid, eabHmacKey } = configuration; const appConnection = await appConnectionDAL.findById(dnsAppConnectionId); if (!appConnection) { @@ -171,7 +175,9 @@ export const AcmeCertificateAuthorityFns = ({ directoryUrl, accountEmail, dnsProvider: dnsProviderConfig.provider, - hostedZoneId: dnsProviderConfig.hostedZoneId + hostedZoneId: dnsProviderConfig.hostedZoneId, + eabKid, + eabHmacKey } }, tx @@ -214,7 +220,7 @@ export const AcmeCertificateAuthorityFns = ({ }) => { const updatedCa = await certificateAuthorityDAL.transaction(async (tx) => { if (configuration) { - const { dnsAppConnectionId, directoryUrl, accountEmail, dnsProviderConfig } = configuration; + const { dnsAppConnectionId, directoryUrl, accountEmail, dnsProviderConfig, eabKid, eabHmacKey } = configuration; const appConnection = await appConnectionDAL.findById(dnsAppConnectionId); if (!appConnection) { @@ -254,7 +260,9 @@ export const AcmeCertificateAuthorityFns = ({ directoryUrl, accountEmail, dnsProvider: dnsProviderConfig.provider, - hostedZoneId: dnsProviderConfig.hostedZoneId + hostedZoneId: dnsProviderConfig.hostedZoneId, + eabKid, + eabHmacKey } }, tx @@ -354,10 +362,19 @@ export const AcmeCertificateAuthorityFns = ({ await blockLocalAndPrivateIpAddresses(acmeCa.configuration.directoryUrl); - const acmeClient = new acme.Client({ + const acmeClientOptions: acme.ClientOptions = { directoryUrl: acmeCa.configuration.directoryUrl, accountKey - }); + }; + + if (acmeCa.configuration.eabKid && acmeCa.configuration.eabHmacKey) { + acmeClientOptions.externalAccountBinding = { + kid: acmeCa.configuration.eabKid, + hmacKey: acmeCa.configuration.eabHmacKey + }; + } + + const acmeClient = new acme.Client(acmeClientOptions); const alg = keyAlgorithmToAlgCfg(CertKeyAlgorithm.RSA_2048); diff --git a/backend/src/services/certificate-authority/acme/acme-certificate-authority-schemas.ts b/backend/src/services/certificate-authority/acme/acme-certificate-authority-schemas.ts index 56b3118cf..70b0cb0e1 100644 --- a/backend/src/services/certificate-authority/acme/acme-certificate-authority-schemas.ts +++ b/backend/src/services/certificate-authority/acme/acme-certificate-authority-schemas.ts @@ -18,7 +18,9 @@ export const AcmeCertificateAuthorityConfigurationSchema = z.object({ hostedZoneId: z.string().trim().min(1).describe(CertificateAuthorities.CONFIGURATIONS.ACME.hostedZoneId) }), directoryUrl: z.string().url().trim().min(1).describe(CertificateAuthorities.CONFIGURATIONS.ACME.directoryUrl), - accountEmail: z.string().trim().min(1).describe(CertificateAuthorities.CONFIGURATIONS.ACME.accountEmail) + accountEmail: z.string().trim().min(1).describe(CertificateAuthorities.CONFIGURATIONS.ACME.accountEmail), + eabKid: z.string().trim().max(64).optional().describe(CertificateAuthorities.CONFIGURATIONS.ACME.eabKid), + eabHmacKey: z.string().trim().max(512).optional().describe(CertificateAuthorities.CONFIGURATIONS.ACME.eabHmacKey) }); export const AcmeCertificateAuthorityCredentialsSchema = z.object({ diff --git a/backend/src/services/external-migration/external-migration-fns/vault.ts b/backend/src/services/external-migration/external-migration-fns/vault.ts index 1ebd56a80..f5f57aa1b 100644 --- a/backend/src/services/external-migration/external-migration-fns/vault.ts +++ b/backend/src/services/external-migration/external-migration-fns/vault.ts @@ -1,12 +1,21 @@ +import https from "node:https"; + import axios, { AxiosInstance } from "axios"; import { v4 as uuidv4 } from "uuid"; +import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service"; import { BadRequestError } from "@app/lib/errors"; +import { GatewayProxyProtocol, withGatewayProxy } from "@app/lib/gateway"; import { logger } from "@app/lib/logger"; import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator"; import { InfisicalImportData, VaultMappingType } from "../external-migration-types"; +enum KvVersion { + V1 = "1", + V2 = "2" +} + type VaultData = { namespace: string; mount: string; @@ -14,7 +23,42 @@ type VaultData = { secretData: Record; }; -const vaultFactory = () => { +const vaultFactory = (gatewayService: Pick) => { + const $gatewayProxyWrapper = async ( + inputs: { + gatewayId: string; + targetHost?: string; + targetPort?: number; + }, + gatewayCallback: (host: string, port: number, httpsAgent?: https.Agent) => Promise + ): Promise => { + const relayDetails = await gatewayService.fnGetGatewayClientTlsByGatewayId(inputs.gatewayId); + const [relayHost, relayPort] = relayDetails.relayAddress.split(":"); + + const callbackResult = await withGatewayProxy( + async (port, httpsAgent) => { + const res = await gatewayCallback("http://localhost", port, httpsAgent); + return res; + }, + { + protocol: GatewayProxyProtocol.Http, + targetHost: inputs.targetHost, + targetPort: inputs.targetPort, + relayHost, + relayPort: Number(relayPort), + identityId: relayDetails.identityId, + orgId: relayDetails.orgId, + tlsOptions: { + ca: relayDetails.certChain, + cert: relayDetails.certificate, + key: relayDetails.privateKey.toString() + } + } + ); + + return callbackResult; + }; + const getMounts = async (request: AxiosInstance) => { const response = await request .get<{ @@ -31,11 +75,24 @@ const vaultFactory = () => { const getPaths = async ( request: AxiosInstance, - { mountPath, secretPath = "" }: { mountPath: string; secretPath?: string } + { mountPath, secretPath = "" }: { mountPath: string; secretPath?: string }, + kvVersion: KvVersion ) => { try { - // For KV v2: /v1/{mount}/metadata/{path}?list=true - const path = secretPath ? `${mountPath}/metadata/${secretPath}` : `${mountPath}/metadata`; + if (kvVersion === KvVersion.V2) { + // For KV v2: /v1/{mount}/metadata/{path}?list=true + const path = secretPath ? `${mountPath}/metadata/${secretPath}` : `${mountPath}/metadata`; + const response = await request.get<{ + data: { + keys: string[]; + }; + }>(`/v1/${path}?list=true`); + + return response.data.data.keys; + } + + // kv version v1: /v1/{mount}?list=true + const path = secretPath ? `${mountPath}/${secretPath}` : mountPath; const response = await request.get<{ data: { keys: string[]; @@ -56,21 +113,42 @@ const vaultFactory = () => { const getSecrets = async ( request: AxiosInstance, - { mountPath, secretPath }: { mountPath: string; secretPath: string } + { mountPath, secretPath }: { mountPath: string; secretPath: string }, + kvVersion: KvVersion ) => { - // For KV v2: /v1/{mount}/data/{path} + if (kvVersion === KvVersion.V2) { + // For KV v2: /v1/{mount}/data/{path} + const response = await request + .get<{ + data: { + data: Record; // KV v2 has nested data structure + metadata: { + created_time: string; + deletion_time: string; + destroyed: boolean; + version: number; + }; + }; + }>(`/v1/${mountPath}/data/${secretPath}`) + .catch((err) => { + if (axios.isAxiosError(err)) { + logger.error(err.response?.data, "External migration: Failed to get Vault secret"); + } + throw err; + }); + + return response.data.data.data; + } + + // kv version v1 + const response = await request .get<{ - data: { - data: Record; // KV v2 has nested data structure - metadata: { - created_time: string; - deletion_time: string; - destroyed: boolean; - version: number; - }; - }; - }>(`/v1/${mountPath}/data/${secretPath}`) + data: Record; // KV v1 has flat data structure + lease_duration: number; + lease_id: string; + renewable: boolean; + }>(`/v1/${mountPath}/${secretPath}`) .catch((err) => { if (axios.isAxiosError(err)) { logger.error(err.response?.data, "External migration: Failed to get Vault secret"); @@ -78,7 +156,7 @@ const vaultFactory = () => { throw err; }); - return response.data.data.data; + return response.data.data; }; // helper function to check if a mount is KV v2 (will be useful if we add support for Vault KV v1) @@ -89,9 +167,10 @@ const vaultFactory = () => { const recursivelyGetAllPaths = async ( request: AxiosInstance, mountPath: string, + kvVersion: KvVersion, currentPath: string = "" ): Promise => { - const paths = await getPaths(request, { mountPath, secretPath: currentPath }); + const paths = await getPaths(request, { mountPath, secretPath: currentPath }, kvVersion); if (paths === null || paths.length === 0) { return []; @@ -105,7 +184,7 @@ const vaultFactory = () => { if (path.endsWith("/")) { // it's a folder so we recurse into it - const subSecrets = await recursivelyGetAllPaths(request, mountPath, fullItemPath); + const subSecrets = await recursivelyGetAllPaths(request, mountPath, kvVersion, fullItemPath); allSecrets.push(...subSecrets); } else { // it's a secret so we add it to our results @@ -119,60 +198,93 @@ const vaultFactory = () => { async function collectVaultData({ baseUrl, namespace, - accessToken + accessToken, + gatewayId }: { baseUrl: string; namespace?: string; accessToken: string; + gatewayId?: string; }): Promise { - const request = axios.create({ - baseURL: baseUrl, - headers: { - "X-Vault-Token": accessToken, - ...(namespace ? { "X-Vault-Namespace": namespace } : {}) + const getData = async (host: string, port?: number, httpsAgent?: https.Agent) => { + const allData: VaultData[] = []; + + const request = axios.create({ + baseURL: port ? `${host}:${port}` : host, + headers: { + "X-Vault-Token": accessToken, + ...(namespace ? { "X-Vault-Namespace": namespace } : {}) + }, + httpsAgent + }); + + // Get all mounts in this namespace + const mounts = await getMounts(request); + + for (const mount of Object.keys(mounts)) { + if (!mount.endsWith("/")) { + delete mounts[mount]; + } } - }); - const allData: VaultData[] = []; + for await (const [mountPath, mountInfo] of Object.entries(mounts)) { + // skip non-KV mounts + if (!mountInfo.type.startsWith("kv")) { + // eslint-disable-next-line no-continue + continue; + } - // Get all mounts in this namespace - const mounts = await getMounts(request); + const kvVersion = mountInfo.options?.version === "2" ? KvVersion.V2 : KvVersion.V1; - for (const mount of Object.keys(mounts)) { - if (!mount.endsWith("/")) { - delete mounts[mount]; + // get all paths in this mount + const paths = await recursivelyGetAllPaths(request, `${mountPath.replace(/\/$/, "")}`, kvVersion); + + const cleanMountPath = mountPath.replace(/\/$/, ""); + + for await (const secretPath of paths) { + // get the actual secret data + const secretData = await getSecrets( + request, + { + mountPath: cleanMountPath, + secretPath: secretPath.replace(`${cleanMountPath}/`, "") + }, + kvVersion + ); + + allData.push({ + namespace: namespace || "", + mount: mountPath.replace(/\/$/, ""), + path: secretPath.replace(`${cleanMountPath}/`, ""), + secretData + }); + } } + + return allData; + }; + + let data; + + if (gatewayId) { + const url = new URL(baseUrl); + + const { port, protocol, hostname } = url; + const cleanedProtocol = protocol.slice(0, -1); + + data = await $gatewayProxyWrapper( + { + gatewayId, + targetHost: `${cleanedProtocol}://${hostname}`, + targetPort: port ? Number(port) : 8200 // 8200, default port for Vault self-hosted/dedicated + }, + getData + ); + } else { + data = await getData(baseUrl); } - for await (const [mountPath, mountInfo] of Object.entries(mounts)) { - // skip non-KV mounts - if (!mountInfo.type.startsWith("kv")) { - // eslint-disable-next-line no-continue - continue; - } - - // get all paths in this mount - const paths = await recursivelyGetAllPaths(request, `${mountPath.replace(/\/$/, "")}`); - - const cleanMountPath = mountPath.replace(/\/$/, ""); - - for await (const secretPath of paths) { - // get the actual secret data - const secretData = await getSecrets(request, { - mountPath: cleanMountPath, - secretPath: secretPath.replace(`${cleanMountPath}/`, "") - }); - - allData.push({ - namespace: namespace || "", - mount: mountPath.replace(/\/$/, ""), - path: secretPath.replace(`${cleanMountPath}/`, ""), - secretData - }); - } - } - - return allData; + return data; } return { @@ -296,17 +408,22 @@ export const transformToInfisicalFormatNamespaceToProjects = ( }; }; -export const importVaultDataFn = async ({ - vaultAccessToken, - vaultNamespace, - vaultUrl, - mappingType -}: { - vaultAccessToken: string; - vaultNamespace?: string; - vaultUrl: string; - mappingType: VaultMappingType; -}) => { +export const importVaultDataFn = async ( + { + vaultAccessToken, + vaultNamespace, + vaultUrl, + mappingType, + gatewayId + }: { + vaultAccessToken: string; + vaultNamespace?: string; + vaultUrl: string; + mappingType: VaultMappingType; + gatewayId?: string; + }, + { gatewayService }: { gatewayService: Pick } +) => { await blockLocalAndPrivateIpAddresses(vaultUrl); if (mappingType === VaultMappingType.Namespace && !vaultNamespace) { @@ -315,12 +432,13 @@ export const importVaultDataFn = async ({ }); } - const vaultApi = vaultFactory(); + const vaultApi = vaultFactory(gatewayService); const vaultData = await vaultApi.collectVaultData({ accessToken: vaultAccessToken, baseUrl: vaultUrl, - namespace: vaultNamespace + namespace: vaultNamespace, + gatewayId }); const infisicalData = transformToInfisicalFormatNamespaceToProjects(vaultData, mappingType); diff --git a/backend/src/services/external-migration/external-migration-service.ts b/backend/src/services/external-migration/external-migration-service.ts index 3bbb88f5b..f1047d0ee 100644 --- a/backend/src/services/external-migration/external-migration-service.ts +++ b/backend/src/services/external-migration/external-migration-service.ts @@ -1,4 +1,5 @@ import { OrgMembershipRole } from "@app/db/schemas"; +import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service"; import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types"; import { crypto } from "@app/lib/crypto/cryptography"; import { BadRequestError, ForbiddenRequestError } from "@app/lib/errors"; @@ -12,6 +13,7 @@ type TExternalMigrationServiceFactoryDep = { permissionService: TPermissionServiceFactory; externalMigrationQueue: TExternalMigrationQueueFactory; userDAL: Pick; + gatewayService: Pick; }; export type TExternalMigrationServiceFactory = ReturnType; @@ -19,7 +21,8 @@ export type TExternalMigrationServiceFactory = ReturnType { const importEnvKeyData = async ({ decryptionKey, @@ -72,6 +75,7 @@ export const externalMigrationServiceFactory = ({ vaultNamespace, mappingType, vaultUrl, + gatewayId, actor, actorId, actorOrgId, @@ -91,12 +95,18 @@ export const externalMigrationServiceFactory = ({ const user = await userDAL.findById(actorId); - const vaultData = await importVaultDataFn({ - vaultAccessToken, - vaultNamespace, - vaultUrl, - mappingType - }); + const vaultData = await importVaultDataFn( + { + vaultAccessToken, + vaultNamespace, + vaultUrl, + mappingType, + gatewayId + }, + { + gatewayService + } + ); const stringifiedJson = JSON.stringify({ data: vaultData, diff --git a/backend/src/services/external-migration/external-migration-types.ts b/backend/src/services/external-migration/external-migration-types.ts index 7c0d4c9ea..ac8ff44e2 100644 --- a/backend/src/services/external-migration/external-migration-types.ts +++ b/backend/src/services/external-migration/external-migration-types.ts @@ -31,6 +31,7 @@ export type TImportVaultDataDTO = { vaultNamespace?: string; mappingType: VaultMappingType; vaultUrl: string; + gatewayId?: string; } & Omit; export type TImportInfisicalDataCreate = { diff --git a/backend/src/services/identity-ua/identity-ua-service.ts b/backend/src/services/identity-ua/identity-ua-service.ts index cd7211b5c..307628039 100644 --- a/backend/src/services/identity-ua/identity-ua-service.ts +++ b/backend/src/services/identity-ua/identity-ua-service.ts @@ -8,6 +8,7 @@ import { validatePrivilegeChangeOperation } from "@app/ee/services/permission/permission-fns"; import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types"; +import { TKeyStoreFactory } from "@app/keystore/keystore"; import { getConfig } from "@app/lib/config/env"; import { crypto } from "@app/lib/crypto/cryptography"; import { BadRequestError, NotFoundError, PermissionBoundaryError, UnauthorizedError } from "@app/lib/errors"; @@ -22,6 +23,7 @@ import { TIdentityUaClientSecretDALFactory } from "./identity-ua-client-secret-d import { TIdentityUaDALFactory } from "./identity-ua-dal"; import { TAttachUaDTO, + TClearUaLockoutsDTO, TCreateUaClientSecretDTO, TGetUaClientSecretsDTO, TGetUaDTO, @@ -38,17 +40,24 @@ type TIdentityUaServiceFactoryDep = { identityOrgMembershipDAL: TIdentityOrgDALFactory; permissionService: Pick; licenseService: Pick; + keyStore: Pick; }; export type TIdentityUaServiceFactory = ReturnType; +// type LockoutObject = { +// lockedOut: boolean; +// failedAttempts: number; +// }; + export const identityUaServiceFactory = ({ identityUaDAL, identityUaClientSecretDAL, identityAccessTokenDAL, identityOrgMembershipDAL, permissionService, - licenseService + licenseService, + keyStore }: TIdentityUaServiceFactoryDep) => { const login = async (clientId: string, clientSecret: string, ip: string) => { const identityUa = await identityUaDAL.findOne({ clientId }); @@ -196,7 +205,11 @@ export const identityUaServiceFactory = ({ actor, actorOrgId, isActorSuperAdmin, - accessTokenPeriod + accessTokenPeriod, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }: TAttachUaDTO) => { await validateIdentityUpdateForSuperAdminPrivileges(identityId, isActorSuperAdmin); @@ -266,7 +279,11 @@ export const identityUaServiceFactory = ({ accessTokenTTL, accessTokenNumUsesLimit, accessTokenTrustedIps: JSON.stringify(reformattedAccessTokenTrustedIps), - accessTokenPeriod + accessTokenPeriod, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }, tx ); @@ -286,7 +303,11 @@ export const identityUaServiceFactory = ({ actorId, actorAuthMethod, actor, - actorOrgId + actorOrgId, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }: TUpdateUaDTO) => { const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); @@ -362,7 +383,11 @@ export const identityUaServiceFactory = ({ accessTokenPeriod, accessTokenTrustedIps: reformattedAccessTokenTrustedIps ? JSON.stringify(reformattedAccessTokenTrustedIps) - : undefined + : undefined, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }); return { ...updatedUaAuth, orgId: identityMembershipOrg.orgId }; }; @@ -713,6 +738,38 @@ export const identityUaServiceFactory = ({ return { ...updatedClientSecret, identityId, orgId: identityMembershipOrg.orgId }; }; + const clearUniversalAuthLockouts = async ({ + identityId, + actorId, + actor, + actorOrgId, + actorAuthMethod + }: TClearUaLockoutsDTO) => { + const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId }); + if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); + + if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.UNIVERSAL_AUTH)) { + throw new BadRequestError({ + message: "The identity does not have universal auth" + }); + } + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + identityMembershipOrg.orgId, + actorAuthMethod, + actorOrgId + ); + ForbiddenError.from(permission).throwUnlessCan(OrgPermissionIdentityActions.Edit, OrgPermissionSubjects.Identity); + + const deleted = await keyStore.deleteItems({ + pattern: `lockout:identity:${identityId}:${IdentityAuthMethod.UNIVERSAL_AUTH}:*` + }); + + return { deleted, identityId, orgId: identityMembershipOrg.orgId }; + }; + return { login, attachUniversalAuth, @@ -722,6 +779,7 @@ export const identityUaServiceFactory = ({ createUniversalAuthClientSecret, getUniversalAuthClientSecrets, revokeUniversalAuthClientSecret, - getUniversalAuthClientSecretById + getUniversalAuthClientSecretById, + clearUniversalAuthLockouts }; }; diff --git a/backend/src/services/identity-ua/identity-ua-types.ts b/backend/src/services/identity-ua/identity-ua-types.ts index f7938e0f7..8e7644b58 100644 --- a/backend/src/services/identity-ua/identity-ua-types.ts +++ b/backend/src/services/identity-ua/identity-ua-types.ts @@ -9,6 +9,10 @@ export type TAttachUaDTO = { clientSecretTrustedIps: { ipAddress: string }[]; accessTokenTrustedIps: { ipAddress: string }[]; isActorSuperAdmin?: boolean; + lockoutEnabled: boolean; + lockoutThreshold: number; + lockoutDurationSeconds: number; + lockoutCounterResetSeconds: number; } & Omit; export type TUpdateUaDTO = { @@ -19,6 +23,10 @@ export type TUpdateUaDTO = { accessTokenPeriod?: number; clientSecretTrustedIps?: { ipAddress: string }[]; accessTokenTrustedIps?: { ipAddress: string }[]; + lockoutEnabled?: boolean; + lockoutThreshold?: number; + lockoutDurationSeconds?: number; + lockoutCounterResetSeconds?: number; } & Omit; export type TGetUaDTO = { @@ -45,6 +53,10 @@ export type TRevokeUaClientSecretDTO = { clientSecretId: string; } & Omit; +export type TClearUaLockoutsDTO = { + identityId: string; +} & Omit; + export type TGetUniversalAuthClientSecretByIdDTO = { identityId: string; clientSecretId: string; diff --git a/backend/src/services/identity/identity-service.ts b/backend/src/services/identity/identity-service.ts index 7c76520b3..969d00331 100644 --- a/backend/src/services/identity/identity-service.ts +++ b/backend/src/services/identity/identity-service.ts @@ -8,6 +8,7 @@ import { validatePrivilegeChangeOperation } from "@app/ee/services/permission/permission-fns"; import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types"; +import { TKeyStoreFactory } from "@app/keystore/keystore"; import { BadRequestError, NotFoundError, PermissionBoundaryError } from "@app/lib/errors"; import { TIdentityProjectDALFactory } from "@app/services/identity-project/identity-project-dal"; @@ -32,6 +33,7 @@ type TIdentityServiceFactoryDep = { identityProjectDAL: Pick; permissionService: Pick; licenseService: Pick; + keyStore: Pick; }; export type TIdentityServiceFactory = ReturnType; @@ -42,7 +44,8 @@ export const identityServiceFactory = ({ identityOrgMembershipDAL, identityProjectDAL, permissionService, - licenseService + licenseService, + keyStore }: TIdentityServiceFactoryDep) => { const createIdentity = async ({ name, @@ -255,7 +258,20 @@ export const identityServiceFactory = ({ ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionIdentityActions.Read, OrgPermissionSubjects.Identity); - return identity; + const activeLockouts = await keyStore.getKeysByPattern(`lockout:identity:${id}:*`); + + const activeLockoutAuthMethods = new Set(); + activeLockouts.forEach((key) => { + const parts = key.split(":"); + if (parts.length > 3) { + activeLockoutAuthMethods.add(parts[3]); + } + }); + + return { + ...identity, + identity: { ...identity.identity, activeLockoutAuthMethods: Array.from(activeLockoutAuthMethods) } + }; }; const deleteIdentity = async ({ diff --git a/backend/src/services/secret-folder/secret-folder-service.ts b/backend/src/services/secret-folder/secret-folder-service.ts index 90cc25710..c5eb0adde 100644 --- a/backend/src/services/secret-folder/secret-folder-service.ts +++ b/backend/src/services/secret-folder/secret-folder-service.ts @@ -30,6 +30,7 @@ import { TDeleteFolderDTO, TDeleteManyFoldersDTO, TGetFolderByIdDTO, + TGetFolderByPathDTO, TGetFolderDTO, TGetFoldersDeepByEnvsDTO, TUpdateFolderDTO, @@ -1398,6 +1399,31 @@ export const secretFolderServiceFactory = ({ }; }; + const getFolderByPath = async ( + { projectId, environment, secretPath }: TGetFolderByPathDTO, + actor: OrgServiceActor + ) => { + // folder check is allowed to be read by anyone + // permission is to check if user has access + await permissionService.getProjectPermission({ + actor: actor.type, + actorId: actor.id, + projectId, + actorAuthMethod: actor.authMethod, + actorOrgId: actor.orgId, + actionProjectType: ActionProjectType.SecretManager + }); + + const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath); + + if (!folder) + throw new NotFoundError({ + message: `Could not find folder with path "${secretPath}" in environment "${environment}" for project with ID "${projectId}"` + }); + + return folder; + }; + return { createFolder, updateFolder, @@ -1405,6 +1431,7 @@ export const secretFolderServiceFactory = ({ deleteFolder, getFolders, getFolderById, + getFolderByPath, getProjectFolderCount, getFoldersMultiEnv, getFoldersDeepByEnvs, diff --git a/backend/src/services/secret-folder/secret-folder-types.ts b/backend/src/services/secret-folder/secret-folder-types.ts index ae8e2c5dc..eed815da5 100644 --- a/backend/src/services/secret-folder/secret-folder-types.ts +++ b/backend/src/services/secret-folder/secret-folder-types.ts @@ -91,3 +91,9 @@ export type TDeleteManyFoldersDTO = { idOrName: string; }>; }; + +export type TGetFolderByPathDTO = { + projectId: string; + environment: string; + secretPath: string; +}; diff --git a/docs/changelog/overview.mdx b/docs/changelog/overview.mdx index 11a058019..7d8282727 100644 --- a/docs/changelog/overview.mdx +++ b/docs/changelog/overview.mdx @@ -26,7 +26,7 @@ The changelog below reflects new product developments and updates on a monthly b - Revamped UI for Access Controls, Access Tree, Policies, and Approval Workflows. - Released [TLS Certificate Authentication method](https://infisical.com/docs/documentation/platform/identities/tls-cert-auth). - Added ability to copy session tokens in the Infisical Dashboard. -- Expanded resource support for [Infisical Terraform Provider](https://infisical.com/docs/integrations/frameworks/terraform). +- Expanded resource support for [Infisical Terraform Provider](https://registry.terraform.io/providers/Infisical/infisical/latest/docs). ## May 2025 @@ -62,7 +62,7 @@ The changelog below reflects new product developments and updates on a monthly b ## March 2025 - Released [Infisical Gateway](https://infisical.com/docs/documentation/platform/gateways/overview) for secure access to private resources without needing direct inbound connections to private networks. -- Enhanced [Terraform](https://infisical.com/docs/integrations/frameworks/terraform#terraform) capabilities with token authentication, ability to import existing Infisical secrets as resources, and support for project templates. +- Enhanced [Terraform](https://registry.terraform.io/providers/Infisical/infisical/latest/docs) capabilities with token authentication, ability to import existing Infisical secrets as resources, and support for project templates. - Self-hosted improvements: Usage and billing visibility for enabled features, ability to delete users, and support for multiple super admins. - UI and UX updates: Improved secret import interface on the overview page, password reset without backup PDF. - CLI enhancements: Various improvements including multiline secret support and ability to pass headers. @@ -93,7 +93,7 @@ The changelog below reflects new product developments and updates on a monthly b - Added support for OIDC group mapping in [Keycloak](https://infisical.com/docs/documentation/platform/sso/keycloak-oidc/overview), enabling automatic mapping of Keycloak groups to Infisical for role-based access control. - Enhanced [Kubernetes operator](https://infisical.com/docs/integrations/platforms/kubernetes/overview#kubernetes-operator) with namespaced group support, bi-directional secret sync (push to Infisical), [dynamic secrets](https://infisical.com/docs/documentation/platform/dynamic-secrets/overview#dynamic-secrets) capabilities, and support for multiple operator instances. - Restructured navigation with dedicated sections for Secrets Management, [Certificate Management (PKI)](https://infisical.com/docs/documentation/platform/pki/overview), [Key Management (KMS)](https://infisical.com/docs/documentation/platform/kms/overview#key-management-service-kms), and [SSH Key Management](https://infisical.com/docs/documentation/platform/ssh). -- Added [ephemeral Terraform resource](https://infisical.com/docs/integrations/frameworks/terraform#terraform-provider) support and improved secret sync architecture. +- Added [ephemeral Terraform resource](https://registry.terraform.io/providers/Infisical/infisical/latest/docs) support and improved secret sync architecture. - Released [.NET provider](https://github.com/Infisical/infisical-dotnet-configuration) with first-party Azure authentication support and Azure CLI integration. - Implemented secret Access Visibility allowing users to view all entities with access to specific secrets in the secret side panel. - Added secret filtering by metadata and SSH assigned certificates (Version 1). @@ -212,7 +212,7 @@ The changelog below reflects new product developments and updates on a monthly b - Completed Postgres migration initiative with restructed Fastify-based backend. - Reduced size of Infisical Node.js SDK by ≈90%. - Added secret fallback support to all SDK's. -- Added Machine Identity support to [Terraform Provider](https://github.com/Infisical/terraform-provider-infisical). +- Added Machine Identity support to [Terraform Provider](https://registry.terraform.io/providers/Infisical/infisical/latest/docs). - Released [.NET SDK](https://infisical.com/docs/sdks/languages/csharp). - Added symmetric encryption support to all SDK's. - Fixed secret reminders bug, where reminders were not being updated correctly. @@ -276,7 +276,7 @@ The changelog below reflects new product developments and updates on a monthly b ## June 2023 -- Released the [Terraform Provider](https://infisical.com/docs/integrations/frameworks/terraform#5-run-terraform). +- Released the [Terraform Provider](https://registry.terraform.io/providers/Infisical/infisical/latest/docs). - Updated the usage and billing page. Added the free trial for the professional tier. - Added native integrations with [Checkly](https://infisical.com/docs/integrations/cloud/checkly), [Hashicorp Vault](https://infisical.com/docs/integrations/cloud/hashicorp-vault), and [Cloudflare Pages](https://infisical.com/docs/integrations/cloud/cloudflare-pages). - Completed a penetration test with a `very good` result. diff --git a/docs/contributing/getting-started/overview.mdx b/docs/contributing/getting-started/overview.mdx index 79bd97c95..35912fc8c 100644 --- a/docs/contributing/getting-started/overview.mdx +++ b/docs/contributing/getting-started/overview.mdx @@ -10,7 +10,7 @@ should approach the development and contribution process. Infisical has two major code-bases. One for the platform code, and one for SDKs. The contribution process has some key differences between the two, so we've split the documentation into two sections: - The [Infisical Platform](https://github.com/Infisical/infisical), the Infisical platform itself. -- The [Infisical SDK](https://github.com/Infisical/sdk), the official Infisical client SDKs. +- The [Infisical SDK](https://infisical.com/docs/sdks/overview), the official Infisical client SDKs. diff --git a/docs/contributing/sdk/developing.mdx b/docs/contributing/sdk/developing.mdx deleted file mode 100644 index 82fd28be8..000000000 --- a/docs/contributing/sdk/developing.mdx +++ /dev/null @@ -1,408 +0,0 @@ ---- -title: "Local development" -description: "This guide will help you contribute to the Infisical SDK." ---- - -## Fork and clone the repo - -[Fork](https://docs.github.com/en/get-started/quickstart/fork-a-repo) the [repository](https://github.com/Infisical/sdk) to your own GitHub account and then [clone](https://docs.github.com/en/repositories/creating-and-managing-repositories/cloning-a-repository) it to your local device. - -Once, you've done that, create a new branch: - -```console -git checkout -b MY_BRANCH_NAME -``` - -## Set up environment variables - -Start by creating a .env file at the root of the Infisical directory then copy the contents of the file below into the .env file. - - - ```env - # This is required for running tests locally. - # Rename this file to ".env" and fill in the values below. - - # Please make sure that the machine identity has access to the project you are testing in. - # https://infisical.com/docs/documentation/platform/identities/universal-auth - INFISICAL_UNIVERSAL_CLIENT_ID=MACHINE_IDENTITY_CLIENT_ID - INFISICAL_UNIVERSAL_CLIENT_SECRET=MACHINE_IDENTITY_CLIENT_SECRET - - # The ID of the Infisical project where we will create the test secrets. - # NOTE: The project must have a dev environment. (This is created by default when you create a project.) - INFISICAL_PROJECT_ID=INFISICAL_TEST_PROJECT_ID - - # The Infisical site URL. If you are testing with a local Infisical instance, then this should be set to "http://localhost:8080". - INFISICAL_SITE_URL=https://app.infisical.com - -```` - - - - The above values are required for running tests locally. Before opening a pull request, make sure to run `cargo test` to ensure that all tests pass. - - - -## Guidelines - -### Predictable and consistent -When adding new functionality (such as new functions), it's very important that the functionality is added to _all_ the SDK's. This is to ensure that the SDK's are predictable and consistent across all languages. If you are adding new functionality, please make sure to add it to all the SDK's. - -### Handling errors -Error handling is very important when writing SDK's. We want to make sure that the SDK's are easy to use, and that the user gets a good understanding of what went wrong when something fails. When adding new functionality, please make sure to add proper error handling. [Read more about error handling here](#error-handling). - -### Tests -If you add new functionality or modify existing functionality, please write tests thats properly cover the new functionality. You can run tests locally by running `cargo test` from the root directory. You must always run tests before opening a pull request. - -### Code style -Please follow the default rust styling guide when writing code for the base SDK. [Read more about rust code style here](https://doc.rust-lang.org/nightly/style-guide/#the-default-rust-style). - - -## Prerequisites for contributing - -### Understanding the terms - -In the guide we use some terms that might be unfamiliar to you. Here's a quick explanation of the terms we use: -- **Base SDK**: The base SDK is the SDK that all other SDK's are built on top of. The base SDK is written in Rust, and is responsible for executing commands and parsing the input and output to and from JSON. -- **Commands**: Commands are what's being sent from the target language to the command handler. The command handler uses the command to execute the corresponding function in the base SDK. Commands are in reality just a JSON string that tells the command handler what function to execute, and what input to use. -- **Command handler**: The command handler is the part of the base SDK that takes care of executing commands. It also takes care of parsing the input and output to and from JSON. -- **Target language**: The target language refers to the actual SDK code. For example, the [Node.js SDK](https://www.npmjs.com/package/@infisical/sdk) is a "target language", and so is the [Python SDK](https://pypi.org/project/infisical-python/). - - -### Understanding the execution flow -After the target language SDK is initiated, it uses language-specific bindings to interact with the base SDK. -These bindings are instantiated, setting up the interface for command execution. A client within the command handler is created, which issues commands to the base SDK. -When a command is executed, it is first validated. If valid, the command handler locates the corresponding command to perform. If the command executes successfully, the command handler returns the output to the target language SDK, where it is parsed and returned to the user. -If the command handler fails to validate the input, an error will be returned to the target language SDK. - - - - - - - - -### Rust knowledge - -Contributing to the SDK requires intermediate to advanced knowledge of Rust concepts such as lifetimes, traits, generics, and async/await _(futures)_, and more. - -### Rust setup -The base SDK is written in rust. Therefore you must have rustc and cargo installed. You can install rustc and cargo by following the instructions [here](https://www.rust-lang.org/tools/install). - -You shouldn't have to use the rust cross compilation toolchain, as all compilation is done through a collection of Github Actions. However. If you need to test cross compilation, please do so with Github Actions. - -### Tests -If you add new functionality or modify existing functionality, please write tests thats properly cover the new functionality. You can run tests locally by running `cargo test` from the root directory. - -### Language-specific crates -The language-specific crates should ideally never have to be modified, as they are simply a wrapper for the `infisical-json` crate, which executes "commands" from the base SDK. If you need to create a new target-language specific crate, please try to create native bindings for the target language. Some languages don't have direct support for native bindings (Java as an example). In those cases we can use the C bindings (`crates/infisical-c`) in the target language. - - - - -## Generate types -Having almost seemless type safety from the base SDK to the target language is critical, as writing types for each language has a lot of drawbacks such as duplicated code, and lots of overhead trying to keep the types up-to-date and in sync across a large collection of languages. Therefore we decided to use [QuickType](https://quicktype.io/) and [Serde](https://serde.rs/) to help us generate types for each language. In our Rust base SDK (`crates/infisical`), we define all the inputs/outputs. - -If you are interested in reading about QuickType works under the hood, you can [read more here](http://blog.quicktype.io/under-the-hood/). - -This is an example of a type defined in Rust (both input and output). For this to become a generated type, you'll need to add it to our schema generator. More on that further down. -```rust -use schemars::JsonSchema; -use serde::{Deserialize, Serialize}; - -#[derive(Serialize, Deserialize, Debug, JsonSchema)] -#[serde(rename_all = "camelCase")] -// Input: -pub struct CreateSecretOptions { - pub environment: String, // environment - pub secret_comment: Option, // secretComment - pub path: Option, // secretPath - pub secret_value: String, // secretValue - pub skip_multiline_encoding: Option, // skipMultilineEncoding - pub r#type: Option, // shared / personal - pub project_id: String, // workspaceId - pub secret_name: String, // secretName (PASSED AS PARAMETER IN REQUEST) -} - -// Output: -#[derive(Serialize, Deserialize, Debug, JsonSchema)] -#[serde(rename_all = "camelCase")] -pub struct CreateSecretResponse { - pub secret: Secret, // "Secret" is defined elsewhere. -} -```` - -### Adding input types to the schema generator - -You will _only_ have to define outputs in our schema generator, then QuickType will take care of the rest behind the scenes. You can find the Rust crate that takes care of type generation here: `crates/sdk-schemas/src/main.rs`. - -Simply add the output _(also called response)_, to the `write_schema_for_response!` macro. This will let QuickType know that it should generate types for the given structs. The main function will look something like this: - -```rust -fn main() -> Result<()> { - // Input types for new Client - write_schema_for!(infisical_json::client::ClientSettings); - // Input types for Client::run_command - write_schema_for!(infisical_json::command::Command); - - // Output types for Client::run_command - // Only add structs which are direct results of SDK commands. - write_schema_for_response! { - infisical::manager::secrets::GetSecretResponse, - infisical::manager::secrets::ListSecretsResponse, - infisical::manager::secrets::UpdateSecretResponse, - infisical::manager::secrets::DeleteSecretResponse, - infisical::manager::secrets::CreateSecretResponse, // <-- This is the output from the above example! - infisical::auth::AccessTokenSuccessResponse - }; - - Ok(()) -} -``` - -### Generating the types for the target language - -Once you've added the output to the schema generator, you can generate the types for the target language by running the following command from the root directory: - -```console -$ npm install -$ npm run schemas -``` - -If you change any of the structs defined in the base SDK, you will need to run this script to re-generate the types. - -This command will run the `schemas.ts` file found in the `support/scripts` folder. If you are adding a new language, it's important that you add the language to the code. - -This is an example of how how we generate types for Node.js: - -```ts -const ts = await quicktype({ - inputData, - lang: "typescript", - rendererOptions: {} -}); -await ensureDir("./languages/node/src/infisical_client"); -writeToFile("./languages/node/src/infisical_client/schemas.ts", ts.lines); -``` - -## Building bindings -We've tried to streamline the building process as much as possible. So you shouldn't have to worry much about building bindings, as it should just be a few commands. - -### Node.js -Building bindings for Node.js is very straight foward. The command below will generate NAPI bindings for Node.js, and move the bindings to the correct folder. We use [NAPI-RS](https://napi.rs/) to generate the bindings. - -```console -$ cd languages/node -$ npm run build -``` - -### Python -To generate and use python bindings you will need to run the following commands. -The Python SDK is located inside the crates folder. This is a limitation of the maturin tool, forcing us to structure the project in this way. - -```console -$ pip install -U pip maturin -$ cd crates/infisical-py -$ python3 -m venv .venv -$ source .venv/bin/activate -$ maturin develop -``` - - - After running the commands above, it's very important that you rename the generated .so file to `infisical_py.so`. After renaming it you also need to move it into the root of the `crates/infisical-py` folder. - - -### Java -Java uses the C bindings to interact with the base SDK. To build and use the C bindings in Java, please follow the instructions below. - -```console -$ cd crates/infisical-c -$ cargo build --release -$ cd ../../languages/java -``` - - After generating the C bindings, the generated .so or .dll has been created in the `/target` directory at the root of the project. - You have to manually move the generated file into the `languages/java/src/main/resources` directory. - - -## Error handling - -### Error handling in the base SDK - -The base SDK should never panic. If an error occurs, we should return a `Result` with an error message. We have a custom Result type defined in the `error.rs` file in the base SDK. - -All our errors are defined in an enum called `Error`. The `Error` enum is defined in the `error.rs` file in the base SDK. The `Error` enum is used in the `Result` type, which is used as the return type for all functions in the base SDK. - -```rust -#[derive(Debug, Error)] -pub enum Error { - // Secret not found - #[error("Secret with name '{}' not found.", .secret_name)] - SecretNotFound { secret_name: String }, - - // .. other errors - - // Errors that are not specific to the base SDK. - #[error(transparent)] - Reqwest(#[from] reqwest::Error), - #[error(transparent)] - Serde(#[from] serde_json::Error), - #[error(transparent)] - Io(#[from] std::io::Error), -} -``` - -### Returning an error - -You can find many examples of how we return errors in the SDK code. A relevant example is for creating secrets, which can be found in `crates/infisical/src/api/secrets/create_secret.rs`. When the error happened due to a request error to our API, we have an API error handler. This prevents duplicate code and keeps error handling consistent across the SDK. You can find the api error handler in the `error.rs` file. - -### Error handling in the target language SDK's. - -All data sent to the target language SDK has the same format. The format is an object with 3 fields: `success (boolean)`, `data (could be anything or nothing)`, and `errorMessage (string or null)`. - -The `success` field is used to determine if the request was successful or not. The `data` field is used to return data from the SDK. The `errorMessage` field is used to return an error message if the request was not successful. - -This means that if the success if false or if the error message is not null, something went wrong and we should throw an error on the target-language level, with the error message. - -## Command handler - -### What is the command handler - -The command handler (the `infisical-json` crate), takes care of executing commands sent from the target language. It also takes care of parsing the input and output to and from JSON. The command handler is the only part of the base SDK that should be aware of JSON. The rest of the base SDK should be completely unaware of JSON, and only work with the Rust structs defined in the base SDK. - -The command handler exposes a function called `run_command`, which is what we use in the target language to execute commands. The function takes a json string as input, and returns a json string as output. We use helper functions generated by QuickType to convert the input and output to and from JSON. - -### Creating new SDK methods - -Creating new commands is necessary when adding new methods to the SDK's. Defining a new command is a 3-step process in most cases. - -#### 1. Define the input and output structs - -Earlier in this guide, we defined the input and output structs for the `CreateSecret` command. We will use that as an example here as well. - -#### 2. Creating the method in the base SDK - -The first step is to create the method in the base SDK. This step will be different depending on what method you are adding. In this example we're going to assume you're adding a function for creating a new secret. - -After you created the function for creating the secret, you'll need need to add it to the ClientSecrets implementation. We do it this way to keep the code organized and easy to read. The ClientSecrets struct is located in the `crates/infisical/src/manager/secrets.rs` file. - -```rust -pub struct ClientSecrets<'a> { - pub(crate) client: &'a mut crate::Client, -} - -impl<'a> ClientSecrets<'a> { - pub async fn create(&mut self, input: &CreateSecretOptions) -> Result { - create_secret(self.client, input).await // <-- This is the function you created! - } -} - -impl<'a> Client { - pub fn secrets(&'a mut self) -> ClientSecrets<'a> { - ClientSecrets { client: self } - } -} -``` - -#### 3. Define a new command - -We define new commands in the `crates/infisical-json/src/command.rs` file. The `Command` enum is what we use to define new commands. - -In the codesnippet below we define a new command called `CreateSecret`. The `CreateSecret` command takes a `CreateSecretOptions` struct as input. We don't have to define the output, because QuickType's converter helps us with figuring out the return type for each command. - -````rust -```rust -use schemars::JsonSchema; -use serde::{Deserialize, Serialize}; - -#[derive(Serialize, Deserialize, JsonSchema, Debug)] -#[serde(rename_all = "camelCase", deny_unknown_fields)] -pub enum Command { - GetSecret(GetSecretOptions), - ListSecrets(ListSecretsOptions), - CreateSecret(CreateSecretOptions), // <-- The new command! - UpdateSecret(UpdateSecretOptions), - DeleteSecret(DeleteSecretOptions), -} -```` - -#### 4. Add the command to the command handler - -After defining the command, we need to add it to the command handler itself. This takes place in the `crates/infisical-json/src/client.rs` file. The `run_command` function is what we use to execute commands. - -In the Client implementation we try to parse the JSON string into a `Command` enum. If the parsing is successful, we match the command and execute the corresponding function. - -```rust -match cmd { - Command::GetSecret(req) => self.0.secrets().get(&req).await.into_string(), - Command::ListSecrets(req) => self.0.secrets().list(&req).await.into_string(), - Command::UpdateSecret(req) => self.0.secrets().update(&req).await.into_string(), - Command::DeleteSecret(req) => self.0.secrets().delete(&req).await.into_string(), - - // This is the new command: - Command::CreateSecret(req) => self.0.secrets().create(&req).await.into_string(), -} -``` - -#### 5. Implementing the new command in the target language SDK's - -We did it! We've now added a new command to the base SDK. The last step is to implement the new command in the target language SDK's. The process is a little different from language to language, but in this example we're going to assume that we're adding a new command to the Node.js SDK. - -First you'll need to generate the new type schemas, we added a new command, input struct, and output struct. [Read more about generating types here](#generating-the-types-for-the-target-language). - -Secondly you need to build the new node bindings so we can use the new functionality in the Node.js SDK. You can do this by running the following command from the `languages/node` directory: - -```console -$ npm install -$ npm run build -``` - -The build command will execute a build script in the `infisical-napi` crate, and move the generated bindings to the appropriate folder. - -After building the new bindings, you can access the new functionality in the Node.js SDK source. - -```ts -// 'binding' is a js file that makes it easier to access the methods in the bindings. (it's auto generated when running npm run build) -import * as rust from "../../binding"; -// We can import the newly generated types from the schemas.ts file. (Generated with QuickType!) -import type { CreateSecretOptions, CreateSecretResponse } from "./schemas"; -// This is the QuickType converter that we use to create commands with! It takes care of all JSON parsing and serialization. -import { Convert, ClientSettings } from "./schemas"; - -export class InfisicalClient { - #client: rust.Client; - - constructor(settings: ClientSettings) { - const settingsJson = settings == null ? null : Convert.clientSettingsToJson(settings); - this.#client = new rust.InfisicalClient(settingsJson); - } - - // ... getSecret - // ... listSecrets - // ... updateSecret - // ... deleteSecret - - async createSecret(options: CreateSecretOptions): Promise { - // The runCommand will return a JSON string, which we can parse into a CreateSecretResponse. - const command = await this.#client.runCommand( - Convert.commandToJson({ - createSecret: options - }) - ); - const response = Convert.toResponseForCreateSecretResponse(command); // <-- This is the QuickType converter in action! - - // If the response is not successful or the data is null, we throw an error. - if (!response.success || response.data == null) { - throw new Error(response.errorMessage ?? "Something went wrong"); - } - - // To make it easier to work with the response, we return the secret directly. - return response.data.secret; - } -} -``` - -And that's it! We've now added a new command to the base SDK, and implemented it in the Node.js SDK. The process is very similar for all other languages, but the code will look a little different. - -## Conclusion - -The SDK has a lot of moving parts, and it can be a little overwhelming at first. But once you get the hang of it, it's actually quite simple. If you have any questions, feel free to reach out to us on [Slack](https://infisical.com/slack), or [open an issue](https://github.com/Infisical/sdk/issues) on GitHub. diff --git a/docs/docs.json b/docs/docs.json index 6eadf70b8..336828000 100644 --- a/docs/docs.json +++ b/docs/docs.json @@ -368,10 +368,6 @@ "contributing/platform/backend/how-to-create-a-feature", "contributing/platform/backend/folder-structure" ] - }, - { - "group": "Contributing to SDK", - "pages": ["contributing/sdk/developing"] } ] } @@ -2564,7 +2560,7 @@ }, { "label": "Terraform", - "href": "https://infisical.com/docs/integrations/frameworks/terraform" + "href": "https://registry.terraform.io/providers/Infisical/infisical/latest/docs" }, { "label": "Ansible", diff --git a/docs/documentation/platform/external-migrations/vault.mdx b/docs/documentation/platform/external-migrations/vault.mdx index ef139e8e4..8254e104f 100644 --- a/docs/documentation/platform/external-migrations/vault.mdx +++ b/docs/documentation/platform/external-migrations/vault.mdx @@ -8,12 +8,12 @@ description: "Learn how to migrate secrets from Vault to Infisical." Migrating from Vault Self-Hosted or Dedicated Vault is a straight forward process with our inbuilt migration option. In order to migrate from Vault, you'll need to provide Infisical an access token to your Vault instance. -Currently the Vault migration only supports migrating secrets from the KV v2 secrets engine. If you're using a different secrets engine, please open an issue on our [GitHub repository](https://github.com/infisical/infisical/issues). +Currently the Vault migration only supports migrating secrets from the KV V2 and V1 secrets engine. If you're using a different secrets engine, please open an issue on our [GitHub repository](https://github.com/infisical/infisical/issues). ### Prerequisites -- A Vault instance with the KV v2 secrets engine enabled. +- A Vault instance with the KV secret engine enabled. - An access token to your Vault instance. diff --git a/docs/documentation/platform/pki/acme-ca.mdx b/docs/documentation/platform/pki/acme-ca.mdx index 8b1fa10db..bf130da9e 100644 --- a/docs/documentation/platform/pki/acme-ca.mdx +++ b/docs/documentation/platform/pki/acme-ca.mdx @@ -147,6 +147,8 @@ In the following steps, we explore how to set up ACME Certificate Authority inte - **Directory URL**: Enter the ACME v2 directory URL for your chosen CA provider (e.g., `https://acme-v02.api.letsencrypt.org/directory` for Let's Encrypt). - **Account Email**: Email address to associate with your ACME account. This email will receive important notifications about your certificates. - **Enable Direct Issuance**: Toggle on to allow direct certificate issuance without requiring subscribers. + - **EAB Key Identifier (KID)**: (Optional) The Key Identifier (KID) provided by your ACME CA for External Account Binding (EAB). This is required by some ACME providers (e.g., ZeroSSL, DigiCert) to link your ACME account to an external account you've pre-registered with them. + - **EAB HMAC Key**: (Optional) The HMAC Key provided by your ACME CA for External Account Binding (EAB). This key is used in conjunction with the KID to prove ownership of the external account during ACME account registration. Finally, press **Create** to register the ACME CA with Infisical. @@ -277,6 +279,19 @@ Let's Encrypt is a free, automated, and open Certificate Authority that provides Always test your ACME integration using Let's Encrypt's staging environment first. This allows you to verify your DNS configuration and certificate issuance process without consuming your production rate limits. +## Example: DigiCert Integration + +DigiCert is a leading commercial Certificate Authority providing a wide range of trusted SSL/TLS certificates. Infisical can integrate with [DigiCert's ACME](https://docs.digicert.com/en/certcentral/certificate-tools/certificate-lifecycle-automation-guides/third-party-acme-integration/request-and-manage-certificates-with-acme.html) service to automate the provisioning and management of these certificates. + +- **Directory URL**: `https://acme.digicert.com/v2/acme/directory` +- **External Account Binding (EAB)**: Required. You will need a Key Identifier (KID) and HMAC Key from your DigiCert account to register the ACME CA in Infisical. +- **Certificate Validity**: Typically 90 days, with automatic renewal through Infisical. +- **Trusted By**: All major browsers and operating systems. + + + When integrating with DigiCert ACME, ensure you have obtained the necessary External Account Binding (EAB) Key Identifier (KID) and HMAC Key from your DigiCert account. + + ## FAQ diff --git a/docs/documentation/platform/secrets-mgmt/concepts/secrets-delivery.mdx b/docs/documentation/platform/secrets-mgmt/concepts/secrets-delivery.mdx index 7ad11948c..df3885055 100644 --- a/docs/documentation/platform/secrets-mgmt/concepts/secrets-delivery.mdx +++ b/docs/documentation/platform/secrets-mgmt/concepts/secrets-delivery.mdx @@ -22,7 +22,7 @@ The table below provides a quick overview of which delivery method may be suitab | Kubernetes (file-based, with rotation) | [Kubernetes CSI Provider](/integrations/platforms/kubernetes-csi) | Mounted files | Uses CSI driver to mount secrets as files with automatic rotation | | Image builds (VMs or containers) | [Packer Plugin](/integrations/frameworks/packer) | Env vars or files | Inject secrets at image build time | | Ansible automation | [Ansible Collection](/integrations/platforms/ansible) | Variables | Runtime secret fetching in playbooks using lookup plugin | -| Terraform / Pulumi | [Terraform Provider](/integrations/frameworks/terraform), [Pulumi](/integrations/frameworks/pulumi) | Inputs / ephemeral resources | Use ephemeral for security; avoids storing secrets in state | +| Terraform / Pulumi | [Terraform Provider](https://registry.terraform.io/providers/Infisical/infisical/latest/docs), [Pulumi](/integrations/frameworks/pulumi) | Inputs / ephemeral resources | Use ephemeral for security; avoids storing secrets in state | | Third-party platforms (GitHub, AWS, etc.) | [Secret Syncs](/integrations/secret-syncs/overview) | Preloaded secrets | Push secrets to platforms that can't fetch directly from Infisical | From here, you can explore the delivery method that best matches your environment: @@ -90,7 +90,7 @@ This is useful when external systems require secrets to be available ahead of ti Infisical integrates with common IaC and automation tools to help you securely inject secrets into your infrastructure provisioning workflows: -- [Terraform](/integrations/frameworks/terraform): Use the official Infisical Terraform provider to fetch secrets either as ephemeral resources (never written to state files) or as traditional data sources. Ideal for managing cloud infrastructure while keeping secrets secure and version-safe. +- [Terraform](https://registry.terraform.io/providers/Infisical/infisical/latest/docs): Use the official Infisical Terraform provider to fetch secrets either as ephemeral resources (never written to state files) or as traditional data sources. Ideal for managing cloud infrastructure while keeping secrets secure and version-safe. - [Pulumi](/integrations/frameworks/pulumi): Integrate Infisical into Pulumi projects using the Terraform Bridge, allowing you to fetch and manage secrets in TypeScript, Go, Python, or C# — without changing your existing workflows. - [Ansible](/integrations/platforms/ansible): Retrieve secrets from Infisical at runtime using the official Ansible Collection and lookup plugin. Works well for dynamic configuration during playbook execution. - [Packer](/integrations/frameworks/packer): Inject secrets into VM or container images at build time using the Infisical Packer Plugin — useful for provisioning base images that require secure configuration values. diff --git a/docs/images/platform/pki/ca/external-ca/create-external-ca-form.png b/docs/images/platform/pki/ca/external-ca/create-external-ca-form.png index ef572bfa7..bc32c23f6 100644 Binary files a/docs/images/platform/pki/ca/external-ca/create-external-ca-form.png and b/docs/images/platform/pki/ca/external-ca/create-external-ca-form.png differ diff --git a/docs/integrations/frameworks/pulumi.mdx b/docs/integrations/frameworks/pulumi.mdx index 11a8e0cb7..c2dbdb103 100644 --- a/docs/integrations/frameworks/pulumi.mdx +++ b/docs/integrations/frameworks/pulumi.mdx @@ -7,7 +7,7 @@ Infisical can be integrated with Pulumi by leveraging Pulumi’s [Terraform Brid which allows Terraform providers to be used seamlessly within Pulumi projects. This enables infrastructure and platform teams to manage Infisical secrets and resources using Pulumi’s familiar programming languages (including TypeScript, Python, Go, and C#), without any change to existing workflows. -The Terraform Bridge wraps the [Infisical Terraform provider](/integrations/frameworks/terraform) and exposes its resources (such as `infisical_secret`, `infisical_project`, and `infisical_service_token`) +The Terraform Bridge wraps the [Infisical Terraform provider](https://registry.terraform.io/providers/Infisical/infisical/latest/docs) and exposes its resources (such as `infisical_secret`, `infisical_project`, and `infisical_service_token`) in a Pulumi-compatible interface. This makes it easy to integrate secret management directly into Pulumi-based IaC pipelines, ensuring secrets stay in sync with the rest of your cloud infrastructure. Authentication is handled through the same methods as Terraform: using environment variables such as `INFISICAL_TOKEN` and `INFISICAL_SITE_URL`. diff --git a/docs/integrations/frameworks/terraform.mdx b/docs/integrations/frameworks/terraform.mdx index 898a77b00..313132d0b 100644 --- a/docs/integrations/frameworks/terraform.mdx +++ b/docs/integrations/frameworks/terraform.mdx @@ -1,8 +1,9 @@ --- title: "Terraform" description: "Learn how to fetch secrets from Infisical with Terraform using both traditional data sources and ephemeral resources" +url: "https://registry.terraform.io/providers/Infisical/infisical/latest/docs" --- - +{/* This guide demonstrates how to use Infisical to manage secrets in your Terraform infrastructure code, supporting both traditional data sources and ephemeral resources for enhanced security. It uses: - Infisical (you can use [Infisical Cloud](https://app.infisical.com) or a [self-hosted instance of Infisical](https://infisical.com/docs/self-hosting/overview)) to store your secrets @@ -234,4 +235,4 @@ For detailed instructions on setting up OIDC authentication with GitHub Actions, See also: - [Machine Identity setup guide](/documentation/platform/identities/machine-identities) - [Terraform Provider Registry](https://registry.terraform.io/providers/Infisical/infisical/latest/docs) -- [GitOps Best Practices](https://www.infisical.com/blog/gitops-best-practices) +- [GitOps Best Practices](https://www.infisical.com/blog/gitops-best-practices) */} diff --git a/docs/integrations/overview.mdx b/docs/integrations/overview.mdx index 5dc06daed..ed7d47b30 100644 --- a/docs/integrations/overview.mdx +++ b/docs/integrations/overview.mdx @@ -7,55 +7,55 @@ Integrations allow environment variables to be synced from Infisical into your l Missing an integration? [Throw in a request](https://github.com/Infisical/infisical/issues). -| Integration | Type | Status | -| -------------------------------------------------------------- | ---------------------- | ----------- | -| [Docker](/integrations/platforms/docker) | Platform | Available | -| [Docker-Compose](/integrations/platforms/docker-compose) | Platform | Available | -| [Kubernetes](/integrations/platforms/kubernetes) | Platform | Available | -| [Terraform](/integrations/frameworks/terraform) | Infrastructure as code | Available | -| [PM2](/integrations/platforms/pm2) | Platform | Available | -| [Heroku](/integrations/cloud/heroku) | Cloud | Available | -| [Vercel](/integrations/cloud/vercel) | Cloud | Available | -| [Netlify](/integrations/cloud/netlify) | Cloud | Available | -| [Render](/integrations/cloud/render) | Cloud | Available | -| [Laravel Forge](/integrations/cloud/laravel-forge) | Cloud | Available | -| [Railway](/integrations/cloud/railway) | Cloud | Available | -| [Terraform Cloud](/integrations/cloud/terraform-cloud) | Cloud | Available | -| [TeamCity](/integrations/cloud/teamcity) | Cloud | Available | -| [Fly.io](/integrations/cloud/flyio) | Cloud | Available | -| [Supabase](/integrations/cloud/supabase) | Cloud | Available | -| [Northflank](/integrations/cloud/northflank) | Cloud | Available | -| [Cloudflare Pages](/integrations/cloud/cloudflare-pages) | Cloud | Available | -| [Cloudflare Workers](/integrations/cloud/cloudflare-workers) | Cloud | Available | -| [Checkly](/integrations/cloud/checkly) | Cloud | Available | -| [Qovery](/integrations/cloud/qovery) | Cloud | Available | -| [HashiCorp Vault](/integrations/cloud/hashicorp-vault) | Cloud | Available | -| [AWS Parameter Store](/integrations/cloud/aws-parameter-store) | Cloud | Available | -| [AWS Secrets Manager](/integrations/cloud/aws-secret-manager) | Cloud | Available | -| [Azure Key Vault](/integrations/cloud/azure-key-vault) | Cloud | Available | -| [GCP Secret Manager](/integrations/cloud/gcp-secret-manager) | Cloud | Available | -| [Windmill](/integrations/cloud/windmill) | Cloud | Available | -| [Bitbucket](/integrations/cicd/bitbucket) | CI/CD | Available | -| [Codefresh](/integrations/cicd/codefresh) | CI/CD | Available | -| [GitHub Actions](/integrations/cicd/githubactions) | CI/CD | Available | -| [GitLab](/integrations/cicd/gitlab) | CI/CD | Available | -| [CircleCI](/integrations/cicd/circleci) | CI/CD | Available | -| [Travis CI](/integrations/cicd/travisci) | CI/CD | Available | -| [Rundeck](/integrations/cicd/rundeck) | CI/CD | Available | -| [Octopus Deploy](/integrations/cicd/octopus-deploy) | CI/CD | Available | -| [React](/integrations/frameworks/react) | Framework | Available | -| [Vue](/integrations/frameworks/vue) | Framework | Available | -| [Express](/integrations/frameworks/express) | Framework | Available | -| [Next.js](/integrations/frameworks/nextjs) | Framework | Available | -| [NestJS](/integrations/frameworks/nestjs) | Framework | Available | -| [SvelteKit](/integrations/frameworks/sveltekit) | Framework | Available | -| [Nuxt](/integrations/frameworks/nuxt) | Framework | Available | -| [Gatsby](/integrations/frameworks/gatsby) | Framework | Available | -| [Remix](/integrations/frameworks/remix) | Framework | Available | -| [Vite](/integrations/frameworks/vite) | Framework | Available | -| [Fiber](/integrations/frameworks/fiber) | Framework | Available | -| [Django](/integrations/frameworks/django) | Framework | Available | -| [Flask](/integrations/frameworks/flask) | Framework | Available | -| [Laravel](/integrations/frameworks/laravel) | Framework | Available | -| [Ruby on Rails](/integrations/frameworks/rails) | Framework | Available | -| Jenkins | CI/CD | Available | +| Integration | Type | Status | +| ------------------------------------------------------------------------------------- | ---------------------- | ---------------------------------- | +| [Docker](/integrations/platforms/docker) | Platform | Available | +| [Docker-Compose](/integrations/platforms/docker-compose) | Platform | Available | +| [Kubernetes](/integrations/platforms/kubernetes) | Platform | Available | +| [Terraform](https://registry.terraform.io/providers/Infisical/infisical/latest/docs) | Infrastructure as code | Available | +| [PM2](/integrations/platforms/pm2) | Platform | Available | +| [Heroku](/integrations/cloud/heroku) | Cloud | Available | +| [Vercel](/integrations/cloud/vercel) | Cloud | Available | +| [Netlify](/integrations/cloud/netlify) | Cloud | Available | +| [Render](/integrations/cloud/render) | Cloud | Available | +| [Laravel Forge](/integrations/cloud/laravel-forge) | Cloud | Available | +| [Railway](/integrations/cloud/railway) | Cloud | Available | +| [Terraform Cloud](/integrations/cloud/terraform-cloud) | Cloud | Available | +| [TeamCity](/integrations/cloud/teamcity) | Cloud | Available | +| [Fly.io](/integrations/cloud/flyio) | Cloud | Available | +| [Supabase](/integrations/cloud/supabase) | Cloud | Available | +| [Northflank](/integrations/cloud/northflank) | Cloud | Available | +| [Cloudflare Pages](/integrations/cloud/cloudflare-pages) | Cloud | Available | +| [Cloudflare Workers](/integrations/cloud/cloudflare-workers) | Cloud | Available | +| [Checkly](/integrations/cloud/checkly) | Cloud | Available | +| [Qovery](/integrations/cloud/qovery) | Cloud | Available | +| [HashiCorp Vault](/integrations/cloud/hashicorp-vault) | Cloud | Available | +| [AWS Parameter Store](/integrations/cloud/aws-parameter-store) | Cloud | Available | +| [AWS Secrets Manager](/integrations/cloud/aws-secret-manager) | Cloud | Available | +| [Azure Key Vault](/integrations/cloud/azure-key-vault) | Cloud | Available | +| [GCP Secret Manager](/integrations/cloud/gcp-secret-manager) | Cloud | Available | +| [Windmill](/integrations/cloud/windmill) | Cloud | Available | +| [Bitbucket](/integrations/cicd/bitbucket) | CI/CD | Available | +| [Codefresh](/integrations/cicd/codefresh) | CI/CD | Available | +| [GitHub Actions](/integrations/cicd/githubactions) | CI/CD | Available | +| [GitLab](/integrations/cicd/gitlab) | CI/CD | Available | +| [CircleCI](/integrations/cicd/circleci) | CI/CD | Available | +| [Travis CI](/integrations/cicd/travisci) | CI/CD | Available | +| [Rundeck](/integrations/cicd/rundeck) | CI/CD | Available | +| [Octopus Deploy](/integrations/cicd/octopus-deploy) | CI/CD | Available | +| [React](/integrations/frameworks/react) | Framework | Available | +| [Vue](/integrations/frameworks/vue) | Framework | Available | +| [Express](/integrations/frameworks/express) | Framework | Available | +| [Next.js](/integrations/frameworks/nextjs) | Framework | Available | +| [NestJS](/integrations/frameworks/nestjs) | Framework | Available | +| [SvelteKit](/integrations/frameworks/sveltekit) | Framework | Available | +| [Nuxt](/integrations/frameworks/nuxt) | Framework | Available | +| [Gatsby](/integrations/frameworks/gatsby) | Framework | Available | +| [Remix](/integrations/frameworks/remix) | Framework | Available | +| [Vite](/integrations/frameworks/vite) | Framework | Available | +| [Fiber](/integrations/frameworks/fiber) | Framework | Available | +| [Django](/integrations/frameworks/django) | Framework | Available | +| [Flask](/integrations/frameworks/flask) | Framework | Available | +| [Laravel](/integrations/frameworks/laravel) | Framework | Available | +| [Ruby on Rails](/integrations/frameworks/rails) | Framework | Available | +| Jenkins | CI/CD | Available | diff --git a/frontend/public/images/integrations/EnvKey.png b/frontend/public/images/integrations/EnvKey.png new file mode 100644 index 000000000..bf1ce03ed Binary files /dev/null and b/frontend/public/images/integrations/EnvKey.png differ diff --git a/frontend/src/components/projects/NewProjectModal.tsx b/frontend/src/components/projects/NewProjectModal.tsx index fa3ae2c70..1bbe9f6f1 100644 --- a/frontend/src/components/projects/NewProjectModal.tsx +++ b/frontend/src/components/projects/NewProjectModal.tsx @@ -153,7 +153,7 @@ const NewProjectForm = ({ onOpenChange }: NewProjectFormProps) => { reset(); onOpenChange(false); navigate({ - to: getProjectHomePage(project.type), + to: getProjectHomePage(project.type, project.environments), params: { projectId: project.id } }); } catch (err) { diff --git a/frontend/src/components/v2/Button/Button.tsx b/frontend/src/components/v2/Button/Button.tsx index 2daa76930..179a55714 100644 --- a/frontend/src/components/v2/Button/Button.tsx +++ b/frontend/src/components/v2/Button/Button.tsx @@ -204,7 +204,7 @@ export const Button = forwardRef( {leftIcon && (
(
-
{title}
+
{title}
{children}
diff --git a/frontend/src/components/v2/FilterableSelect/FilterableSelect.tsx b/frontend/src/components/v2/FilterableSelect/FilterableSelect.tsx index 47a5acd56..7ab8b0f3c 100644 --- a/frontend/src/components/v2/FilterableSelect/FilterableSelect.tsx +++ b/frontend/src/components/v2/FilterableSelect/FilterableSelect.tsx @@ -67,7 +67,7 @@ export const FilterableSelect = ({ }), menuPortal: (provided) => ({ ...provided, - zIndex: 9999 + zIndex: 99999 }) }} tabSelectsValue={tabSelectsValue} diff --git a/frontend/src/components/v2/SecretInput/SecretInput.tsx b/frontend/src/components/v2/SecretInput/SecretInput.tsx index 6f3f4283a..747af73d5 100644 --- a/frontend/src/components/v2/SecretInput/SecretInput.tsx +++ b/frontend/src/components/v2/SecretInput/SecretInput.tsx @@ -6,20 +6,12 @@ import { useToggle } from "@app/hooks"; import { HIDDEN_SECRET_VALUE } from "@app/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretItem"; const REGEX = /(\${([a-zA-Z0-9-_.]+)})/g; -const replaceContentWithDot = (str: string) => { - let finalStr = ""; - for (let i = 0; i < str.length; i += 1) { - const char = str.at(i); - finalStr += char === "\n" ? "\n" : "*"; - } - return finalStr; -}; const syntaxHighlight = (content?: string | null, isVisible?: boolean, isImport?: boolean) => { if (isImport && !content) return "IMPORTED"; if (content === "") return "EMPTY"; if (!content) return "EMPTY"; - if (!isVisible) return replaceContentWithDot(content); + if (!isVisible) return HIDDEN_SECRET_VALUE; let skipNext = false; const formattedContent = content.split(REGEX).flatMap((el, i) => { diff --git a/frontend/src/components/v2/Table/Table.tsx b/frontend/src/components/v2/Table/Table.tsx index cc180ffb6..b8ca27dc1 100644 --- a/frontend/src/components/v2/Table/Table.tsx +++ b/frontend/src/components/v2/Table/Table.tsx @@ -1,4 +1,4 @@ -import { DetailedHTMLProps, HTMLAttributes, ReactNode, TdHTMLAttributes } from "react"; +import { DetailedHTMLProps, forwardRef, HTMLAttributes, ReactNode, TdHTMLAttributes } from "react"; import { twMerge } from "tailwind-merge"; import { Skeleton } from "../Skeleton"; @@ -9,22 +9,20 @@ export type TableContainerProps = { className?: string; } & DetailedHTMLProps, HTMLDivElement>; -export const TableContainer = ({ - children, - className, - isRounded = true, - ...props -}: TableContainerProps): JSX.Element => ( -
- {children} -
+export const TableContainer = forwardRef( + ({ children, className, isRounded = true, ...props }, ref): JSX.Element => ( +
+ {children} +
+ ) ); // main parent table diff --git a/frontend/src/context/OrgPermissionContext/index.tsx b/frontend/src/context/OrgPermissionContext/index.tsx index fccd53935..f3bc0195d 100644 --- a/frontend/src/context/OrgPermissionContext/index.tsx +++ b/frontend/src/context/OrgPermissionContext/index.tsx @@ -2,6 +2,7 @@ export { useOrgPermission } from "./OrgPermissionContext"; export type { TOrgPermission } from "./types"; export { OrgPermissionActions, + OrgPermissionAuditLogsActions, OrgPermissionBillingActions, OrgPermissionGroupActions, OrgPermissionIdentityActions, diff --git a/frontend/src/context/OrgPermissionContext/types.ts b/frontend/src/context/OrgPermissionContext/types.ts index 50e147aa0..74d5293e6 100644 --- a/frontend/src/context/OrgPermissionContext/types.ts +++ b/frontend/src/context/OrgPermissionContext/types.ts @@ -71,6 +71,10 @@ export enum OrgPermissionAppConnectionActions { Connect = "connect" } +export enum OrgPermissionAuditLogsActions { + Read = "read" +} + export enum OrgPermissionKmipActions { Proxy = "proxy", Setup = "setup" @@ -118,7 +122,7 @@ export type OrgPermissionSet = | [OrgPermissionBillingActions, OrgPermissionSubjects.Billing] | [OrgPermissionActions, OrgPermissionSubjects.Kms] | [OrgPermissionAdminConsoleAction, OrgPermissionSubjects.AdminConsole] - | [OrgPermissionActions, OrgPermissionSubjects.AuditLogs] + | [OrgPermissionAuditLogsActions, OrgPermissionSubjects.AuditLogs] | [OrgPermissionActions, OrgPermissionSubjects.ProjectTemplates] | [OrgPermissionAppConnectionActions, OrgPermissionSubjects.AppConnections] | [OrgPermissionIdentityActions, OrgPermissionSubjects.Identity] diff --git a/frontend/src/context/ProjectPermissionContext/index.tsx b/frontend/src/context/ProjectPermissionContext/index.tsx index f564ac74e..a1669e18f 100644 --- a/frontend/src/context/ProjectPermissionContext/index.tsx +++ b/frontend/src/context/ProjectPermissionContext/index.tsx @@ -2,6 +2,7 @@ export { useProjectPermission } from "./ProjectPermissionContext"; export type { ProjectPermissionSet, TProjectPermission } from "./types"; export { ProjectPermissionActions, + ProjectPermissionAuditLogsActions, ProjectPermissionCertificateActions, ProjectPermissionCmekActions, ProjectPermissionDynamicSecretActions, diff --git a/frontend/src/context/ProjectPermissionContext/types.ts b/frontend/src/context/ProjectPermissionContext/types.ts index dad72cada..acfab612f 100644 --- a/frontend/src/context/ProjectPermissionContext/types.ts +++ b/frontend/src/context/ProjectPermissionContext/types.ts @@ -150,6 +150,10 @@ export enum ProjectPermissionSecretEventActions { SubscribeImportMutations = "subscribe-on-import-mutations" } +export enum ProjectPermissionAuditLogsActions { + Read = "read" +} + export enum PermissionConditionOperators { $IN = "$in", $ALL = "$all", @@ -365,7 +369,7 @@ export type ProjectPermissionSet = | [ProjectPermissionActions, ProjectPermissionSub.Groups] | [ProjectPermissionActions, ProjectPermissionSub.Integrations] | [ProjectPermissionActions, ProjectPermissionSub.Webhooks] - | [ProjectPermissionActions, ProjectPermissionSub.AuditLogs] + | [ProjectPermissionAuditLogsActions, ProjectPermissionSub.AuditLogs] | [ProjectPermissionActions, ProjectPermissionSub.Environments] | [ProjectPermissionActions, ProjectPermissionSub.IpAllowList] | [ProjectPermissionActions, ProjectPermissionSub.Settings] diff --git a/frontend/src/context/index.tsx b/frontend/src/context/index.tsx index 833956d77..bfb504664 100644 --- a/frontend/src/context/index.tsx +++ b/frontend/src/context/index.tsx @@ -2,6 +2,7 @@ export { useOrganization } from "./OrganizationContext"; export type { TOrgPermission } from "./OrgPermissionContext"; export { OrgPermissionActions, + OrgPermissionAuditLogsActions, OrgPermissionBillingActions, OrgPermissionGroupActions, OrgPermissionIdentityActions, @@ -11,6 +12,7 @@ export { export type { TProjectPermission } from "./ProjectPermissionContext"; export { ProjectPermissionActions, + ProjectPermissionAuditLogsActions, ProjectPermissionCertificateActions, ProjectPermissionCmekActions, ProjectPermissionDynamicSecretActions, diff --git a/frontend/src/helpers/datetime.ts b/frontend/src/helpers/datetime.ts index 6e0fb8e48..d8a5e90c6 100644 --- a/frontend/src/helpers/datetime.ts +++ b/frontend/src/helpers/datetime.ts @@ -22,3 +22,62 @@ export const formatDateTime = ({ } return format(date, dateFormat); }; + +// Helper function to convert seconds to value and unit +export const getObjectFromSeconds = ( + totalSeconds: number, + activeUnits?: Array<"s" | "m" | "h" | "d" | "w" | "y"> +): { value: number; unit: "s" | "m" | "h" | "d" | "w" | "y" } => { + const SECONDS_IN_MINUTE = 60; + const SECONDS_IN_HOUR = SECONDS_IN_MINUTE * 60; + const SECONDS_IN_DAY = SECONDS_IN_HOUR * 24; + const SECONDS_IN_WEEK = SECONDS_IN_DAY * 7; + const SECONDS_IN_YEAR = SECONDS_IN_DAY * 365; + + const activeUnitsSet = activeUnits ? new Set(activeUnits) : null; + + const isUnitActive = (unit: "s" | "m" | "h" | "d" | "w" | "y"): boolean => { + return activeUnitsSet ? activeUnitsSet.has(unit) : true; + }; + + if ( + isUnitActive("y") && + totalSeconds >= SECONDS_IN_YEAR && + totalSeconds % SECONDS_IN_YEAR === 0 + ) { + return { value: totalSeconds / SECONDS_IN_YEAR, unit: "y" }; + } + + if ( + isUnitActive("w") && + totalSeconds >= SECONDS_IN_WEEK && + totalSeconds % SECONDS_IN_WEEK === 0 + ) { + return { value: totalSeconds / SECONDS_IN_WEEK, unit: "w" }; + } + + if (isUnitActive("d") && totalSeconds >= SECONDS_IN_DAY && totalSeconds % SECONDS_IN_DAY === 0) { + return { value: totalSeconds / SECONDS_IN_DAY, unit: "d" }; + } + + if ( + isUnitActive("h") && + totalSeconds >= SECONDS_IN_HOUR && + totalSeconds % SECONDS_IN_HOUR === 0 + ) { + return { value: totalSeconds / SECONDS_IN_HOUR, unit: "h" }; + } + + if ( + isUnitActive("m") && + totalSeconds >= SECONDS_IN_MINUTE && + totalSeconds % SECONDS_IN_MINUTE === 0 + ) { + return { value: totalSeconds / SECONDS_IN_MINUTE, unit: "m" }; + } + + return { + value: totalSeconds, + unit: "s" + }; +}; diff --git a/frontend/src/helpers/project.ts b/frontend/src/helpers/project.ts index 3b04b263d..7c9185556 100644 --- a/frontend/src/helpers/project.ts +++ b/frontend/src/helpers/project.ts @@ -1,6 +1,6 @@ import { apiRequest } from "@app/config/request"; import { createWorkspace } from "@app/hooks/api/workspace/queries"; -import { ProjectType } from "@app/hooks/api/workspace/types"; +import { ProjectType, WorkspaceEnv } from "@app/hooks/api/workspace/types"; const secretsToBeAdded = [ { @@ -72,12 +72,14 @@ export const getProjectBaseURL = (type: ProjectType) => { } }; -export const getProjectHomePage = (type: ProjectType) => { +// @ts-expect-error akhilmhdh: will remove this later +// eslint-disable-next-line @typescript-eslint/no-unused-vars +export const getProjectHomePage = (type: ProjectType, environments: WorkspaceEnv[]) => { switch (type) { case ProjectType.SecretManager: - return "/projects/secret-management/$projectId/overview"; + return "/projects/secret-management/$projectId/overview" as const; case ProjectType.CertificateManager: - return "/projects/cert-management/$projectId/subscribers"; + return "/projects/cert-management/$projectId/subscribers" as const; case ProjectType.SecretScanning: return `/projects/${type}/$projectId/data-sources` as const; default: diff --git a/frontend/src/hooks/api/auditLogs/constants.tsx b/frontend/src/hooks/api/auditLogs/constants.tsx index 696f5745f..186a8e539 100644 --- a/frontend/src/hooks/api/auditLogs/constants.tsx +++ b/frontend/src/hooks/api/auditLogs/constants.tsx @@ -40,6 +40,7 @@ export const eventToNameMap: { [K in EventType]: string } = { [EventType.GET_IDENTITY_UNIVERSAL_AUTH]: "Get universal auth", [EventType.CREATE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET]: "Create universal auth client secret", [EventType.REVOKE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET]: "Revoke universal auth client secret", + [EventType.CLEAR_IDENTITY_UNIVERSAL_AUTH_LOCKOUTS]: "Clear universal auth lockouts", [EventType.GET_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRETS]: "Get universal auth client secrets", [EventType.CREATE_ENVIRONMENT]: "Create environment", [EventType.UPDATE_ENVIRONMENT]: "Update environment", diff --git a/frontend/src/hooks/api/auditLogs/enums.tsx b/frontend/src/hooks/api/auditLogs/enums.tsx index 159a61808..4fe8948dd 100644 --- a/frontend/src/hooks/api/auditLogs/enums.tsx +++ b/frontend/src/hooks/api/auditLogs/enums.tsx @@ -46,6 +46,7 @@ export enum EventType { GET_IDENTITY_UNIVERSAL_AUTH = "get-identity-universal-auth", CREATE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "create-identity-universal-auth-client-secret", REVOKE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "revoke-identity-universal-auth-client-secret", + CLEAR_IDENTITY_UNIVERSAL_AUTH_LOCKOUTS = "clear-identity-universal-auth-lockouts", GET_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRETS = "get-identity-universal-auth-client-secret", LOGIN_IDENTITY_LDAP_AUTH = "login-identity-ldap-auth", diff --git a/frontend/src/hooks/api/auditLogs/types.tsx b/frontend/src/hooks/api/auditLogs/types.tsx index 0b9e201fe..1ca819e60 100644 --- a/frontend/src/hooks/api/auditLogs/types.tsx +++ b/frontend/src/hooks/api/auditLogs/types.tsx @@ -326,6 +326,14 @@ interface RevokeIdentityUniversalAuthClientSecretEvent { }; } +interface ClearIdentityUniversalAuthLockoutsEvent { + type: EventType.CLEAR_IDENTITY_UNIVERSAL_AUTH_LOCKOUTS; + metadata: { + identityId: string; + clientSecretId: string; + }; +} + interface CreateEnvironmentEvent { type: EventType.CREATE_ENVIRONMENT; metadata: { @@ -892,6 +900,7 @@ export type Event = | CreateIdentityUniversalAuthClientSecretEvent | GetIdentityUniversalAuthClientSecretsEvent | RevokeIdentityUniversalAuthClientSecretEvent + | ClearIdentityUniversalAuthLockoutsEvent | CreateEnvironmentEvent | UpdateEnvironmentEvent | DeleteEnvironmentEvent diff --git a/frontend/src/hooks/api/ca/types.ts b/frontend/src/hooks/api/ca/types.ts index 8dd874a75..336688ca4 100644 --- a/frontend/src/hooks/api/ca/types.ts +++ b/frontend/src/hooks/api/ca/types.ts @@ -16,6 +16,8 @@ export type TAcmeCertificateAuthority = { }; directoryUrl: string; accountEmail: string; + eabKid?: string; + eabHmacKey?: string; }; }; diff --git a/frontend/src/hooks/api/dashboard/queries.tsx b/frontend/src/hooks/api/dashboard/queries.tsx index e748e3e5b..fde3a5ee3 100644 --- a/frontend/src/hooks/api/dashboard/queries.tsx +++ b/frontend/src/hooks/api/dashboard/queries.tsx @@ -1,5 +1,6 @@ import { useCallback } from "react"; import { useQuery, UseQueryOptions } from "@tanstack/react-query"; +import { AxiosError } from "axios"; import { apiRequest } from "@app/config/request"; import { @@ -273,6 +274,12 @@ export const useGetProjectSecretsDetails = ( ...options, // wait for all values to be available enabled: Boolean(projectId) && (options?.enabled ?? true), + retry: (count, error) => { + // don't retry 404s + if (error instanceof AxiosError && error.status === 404) return false; + + return count <= 5; + }, queryKey: dashboardKeys.getProjectSecretsDetails({ secretPath, search, diff --git a/frontend/src/hooks/api/dashboard/types.ts b/frontend/src/hooks/api/dashboard/types.ts index 78c56394f..fbd5107cd 100644 --- a/frontend/src/hooks/api/dashboard/types.ts +++ b/frontend/src/hooks/api/dashboard/types.ts @@ -72,7 +72,7 @@ export type DashboardProjectSecretsOverview = Omit< DashboardProjectSecretsOverviewResponse, "secrets" | "secretRotations" > & { - secrets?: SecretV3RawSanitized[]; + secrets?: (SecretV3RawSanitized & { sourceEnv?: string })[]; secretRotations?: (TSecretRotationV2 & { secrets: (SecretV3RawSanitized | null)[]; })[]; diff --git a/frontend/src/hooks/api/identities/mutations.tsx b/frontend/src/hooks/api/identities/mutations.tsx index c01f1aa85..5189f187c 100644 --- a/frontend/src/hooks/api/identities/mutations.tsx +++ b/frontend/src/hooks/api/identities/mutations.tsx @@ -18,6 +18,7 @@ import { AddIdentityTlsCertAuthDTO, AddIdentityTokenAuthDTO, AddIdentityUniversalAuthDTO, + ClearIdentityUniversalAuthLockoutsDTO, ClientSecretData, CreateIdentityDTO, CreateIdentityUniversalAuthClientSecretDTO, @@ -148,7 +149,11 @@ export const useAddIdentityUniversalAuth = () => { accessTokenTTL, accessTokenMaxTTL, accessTokenNumUsesLimit, - accessTokenTrustedIps + accessTokenTrustedIps, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }) => { const { data: { identityUniversalAuth } @@ -157,7 +162,11 @@ export const useAddIdentityUniversalAuth = () => { accessTokenTTL, accessTokenMaxTTL, accessTokenNumUsesLimit, - accessTokenTrustedIps + accessTokenTrustedIps, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }); return identityUniversalAuth; }, @@ -183,7 +192,11 @@ export const useUpdateIdentityUniversalAuth = () => { accessTokenMaxTTL, accessTokenNumUsesLimit, accessTokenTrustedIps, - accessTokenPeriod + accessTokenPeriod, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }) => { const { data: { identityUniversalAuth } @@ -193,7 +206,11 @@ export const useUpdateIdentityUniversalAuth = () => { accessTokenMaxTTL, accessTokenNumUsesLimit, accessTokenTrustedIps, - accessTokenPeriod + accessTokenPeriod, + lockoutEnabled, + lockoutThreshold, + lockoutDurationSeconds, + lockoutCounterResetSeconds }); return identityUniversalAuth; }, @@ -275,6 +292,25 @@ export const useRevokeIdentityUniversalAuthClientSecret = () => { }); }; +export const useClearIdentityUniversalAuthLockouts = () => { + const queryClient = useQueryClient(); + return useMutation({ + mutationFn: async ({ identityId }) => { + const { + data: { deleted } + } = await apiRequest.post<{ deleted: number }>( + `/api/v1/auth/universal-auth/identities/${identityId}/clear-lockouts` + ); + return deleted; + }, + onSuccess: (_, { identityId }) => { + queryClient.invalidateQueries({ + queryKey: identitiesKeys.getIdentityUniversalAuth(identityId) + }); + } + }); +}; + export const useAddIdentityGcpAuth = () => { const queryClient = useQueryClient(); return useMutation({ diff --git a/frontend/src/hooks/api/identities/types.ts b/frontend/src/hooks/api/identities/types.ts index 7098ce244..36f9eae4e 100644 --- a/frontend/src/hooks/api/identities/types.ts +++ b/frontend/src/hooks/api/identities/types.ts @@ -16,6 +16,7 @@ export type Identity = { name: string; hasDeleteProtection: boolean; authMethods: IdentityAuthMethod[]; + activeLockoutAuthMethods: IdentityAuthMethod[]; createdAt: string; updatedAt: string; isInstanceAdmin?: boolean; @@ -113,6 +114,10 @@ export type IdentityUniversalAuth = { accessTokenNumUsesLimit: number; accessTokenTrustedIps: IdentityTrustedIp[]; accessTokenPeriod: number; + lockoutEnabled: boolean; + lockoutThreshold: number; + lockoutDurationSeconds: number; + lockoutCounterResetSeconds: number; }; export type AddIdentityUniversalAuthDTO = { @@ -128,6 +133,10 @@ export type AddIdentityUniversalAuthDTO = { accessTokenTrustedIps: { ipAddress: string; }[]; + lockoutEnabled: boolean; + lockoutThreshold: number; + lockoutDurationSeconds: number; + lockoutCounterResetSeconds: number; }; export type UpdateIdentityUniversalAuthDTO = { @@ -143,6 +152,10 @@ export type UpdateIdentityUniversalAuthDTO = { accessTokenTrustedIps?: { ipAddress: string; }[]; + lockoutEnabled?: boolean; + lockoutThreshold?: number; + lockoutDurationSeconds?: number; + lockoutCounterResetSeconds?: number; }; export type DeleteIdentityUniversalAuthDTO = { @@ -558,6 +571,10 @@ export type DeleteIdentityUniversalAuthClientSecretDTO = { clientSecretId: string; }; +export type ClearIdentityUniversalAuthLockoutsDTO = { + identityId: string; +}; + export type IdentityTokenAuth = { identityId: string; accessTokenTTL: number; diff --git a/frontend/src/hooks/api/migration/mutations.tsx b/frontend/src/hooks/api/migration/mutations.tsx index 529d5c463..182797954 100644 --- a/frontend/src/hooks/api/migration/mutations.tsx +++ b/frontend/src/hooks/api/migration/mutations.tsx @@ -46,18 +46,21 @@ export const useImportVault = () => { vaultAccessToken, vaultNamespace, vaultUrl, - mappingType + mappingType, + gatewayId }: { vaultAccessToken: string; vaultNamespace?: string; vaultUrl: string; mappingType: string; + gatewayId?: string; }) => { await apiRequest.post("/api/v3/external-migration/vault/", { vaultAccessToken, vaultNamespace, vaultUrl, - mappingType + mappingType, + gatewayId }); } }); diff --git a/frontend/src/hooks/api/workspace/queries.tsx b/frontend/src/hooks/api/workspace/queries.tsx index 7a0e3d2e2..3c7a6d30c 100644 --- a/frontend/src/hooks/api/workspace/queries.tsx +++ b/frontend/src/hooks/api/workspace/queries.tsx @@ -47,7 +47,8 @@ import { UpdateEnvironmentDTO, UpdatePitVersionLimitDTO, UpdateProjectDTO, - Workspace + Workspace, + WorkspaceEnv } from "./types"; export const fetchWorkspaceById = async (workspaceId: string) => { @@ -396,12 +397,16 @@ export const useDeleteWorkspace = () => { export const useCreateWsEnvironment = () => { const queryClient = useQueryClient(); - return useMutation({ - mutationFn: ({ workspaceId, name, slug }) => { - return apiRequest.post(`/api/v1/workspace/${workspaceId}/environments`, { - name, - slug - }); + return useMutation({ + mutationFn: async ({ workspaceId, name, slug }) => { + const { data } = await apiRequest.post<{ environment: WorkspaceEnv }>( + `/api/v1/workspace/${workspaceId}/environments`, + { + name, + slug + } + ); + return data.environment; }, onSuccess: () => { queryClient.invalidateQueries({ diff --git a/frontend/src/hooks/useResizableColWidth.tsx b/frontend/src/hooks/useResizableColWidth.tsx index f2ad80625..6af269217 100644 --- a/frontend/src/hooks/useResizableColWidth.tsx +++ b/frontend/src/hooks/useResizableColWidth.tsx @@ -1,12 +1,13 @@ -import { MouseEvent, useCallback, useEffect, useRef, useState } from "react"; +import { MouseEvent, RefObject, useCallback, useEffect, useRef, useState } from "react"; type Params = { minWidth: number; maxWidth: number; initialWidth: number; + ref: RefObject; }; -export const useResizableColWidth = ({ minWidth, maxWidth, initialWidth }: Params) => { +export const useResizableColWidth = ({ minWidth, maxWidth, initialWidth, ref }: Params) => { const [colWidth, setColWidth] = useState(initialWidth); const [isResizing, setIsResizing] = useState(false); const startX = useRef(0); @@ -63,6 +64,28 @@ export const useResizableColWidth = ({ minWidth, maxWidth, initialWidth }: Param }; }, [isResizing, handleMouseMove, handleMouseUp]); + useEffect(() => { + const element = ref?.current; + if (!element) return; + + const handleResize = () => { + if (colWidth > maxWidth) { + setColWidth(Math.max(maxWidth, minWidth)); + } else if (ref.current?.clientWidth && colWidth > ref.current.clientWidth * 0.9) { + // this else is a fallback to ensure col is always visible + setColWidth(initialWidth); + } + }; + + const resizeObserver = new ResizeObserver(handleResize); + resizeObserver.observe(element); + + // eslint-disable-next-line consistent-return + return () => { + resizeObserver.disconnect(); + }; + }, [ref, maxWidth, colWidth]); + return { colWidth, handleMouseDown, diff --git a/frontend/src/hooks/utils/secrets-overview.tsx b/frontend/src/hooks/utils/secrets-overview.tsx index e136df3f2..d77b41f5f 100644 --- a/frontend/src/hooks/utils/secrets-overview.tsx +++ b/frontend/src/hooks/utils/secrets-overview.tsx @@ -130,7 +130,11 @@ export const useSecretOverview = (secrets: DashboardProjectSecretsOverview["secr const getEnvSecretKeyCount = useCallback( (env: string) => { - return secrets?.filter((secret) => secret.env === env).length ?? 0; + return ( + secrets?.filter((secret) => + secret.sourceEnv ? secret.sourceEnv === env : secret.env === env + ).length ?? 0 + ); }, [secrets] ); diff --git a/frontend/src/layouts/ProjectLayout/components/AssumePrivilegeModeBanner/AssumePrivilegeModeBanner.tsx b/frontend/src/layouts/ProjectLayout/components/AssumePrivilegeModeBanner/AssumePrivilegeModeBanner.tsx index 2b4fcff80..995083ee7 100644 --- a/frontend/src/layouts/ProjectLayout/components/AssumePrivilegeModeBanner/AssumePrivilegeModeBanner.tsx +++ b/frontend/src/layouts/ProjectLayout/components/AssumePrivilegeModeBanner/AssumePrivilegeModeBanner.tsx @@ -36,7 +36,10 @@ export const AssumePrivilegeModeBanner = () => { }, { onSuccess: () => { - const url = getProjectHomePage(currentWorkspace.type); + const url = getProjectHomePage( + currentWorkspace.type, + currentWorkspace.environments + ); window.location.href = url.replace("$projectId", currentWorkspace.id); } } diff --git a/frontend/src/layouts/ProjectLayout/components/ProjectSelect/ProjectSelect.tsx b/frontend/src/layouts/ProjectLayout/components/ProjectSelect/ProjectSelect.tsx index b66717a5c..ebc28a227 100644 --- a/frontend/src/layouts/ProjectLayout/components/ProjectSelect/ProjectSelect.tsx +++ b/frontend/src/layouts/ProjectLayout/components/ProjectSelect/ProjectSelect.tsx @@ -101,7 +101,7 @@ export const ProjectSelect = () => {
{ // to reproduce change this back to router.push and switch between two projects with different env count // look into this on dashboard revamp const url = linkOptions({ - to: getProjectHomePage(workspace.type), + to: getProjectHomePage(workspace.type, workspace.environments), params: { projectId: workspace.id } diff --git a/frontend/src/layouts/SecretManagerLayout/SecretManagerLayout.tsx b/frontend/src/layouts/SecretManagerLayout/SecretManagerLayout.tsx index ad31d9017..0584e8e9c 100644 --- a/frontend/src/layouts/SecretManagerLayout/SecretManagerLayout.tsx +++ b/frontend/src/layouts/SecretManagerLayout/SecretManagerLayout.tsx @@ -11,7 +11,7 @@ import { faVault } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; -import { Link, Outlet } from "@tanstack/react-router"; +import { Link, Outlet, useLocation } from "@tanstack/react-router"; import { motion } from "framer-motion"; import { Badge, Lottie, Menu, MenuGroup, MenuItem } from "@app/components/v2"; @@ -31,6 +31,7 @@ export const SecretManagerLayout = () => { const { t } = useTranslation(); const workspaceId = currentWorkspace?.id || ""; const projectSlug = currentWorkspace?.slug || ""; + const location = useLocation(); const { data: secretApprovalReqCount } = useGetSecretApprovalRequestCount({ workspaceId @@ -73,11 +74,21 @@ export const SecretManagerLayout = () => { {({ isActive }) => ( - +
diff --git a/frontend/src/pages/cert-manager/CertificateAuthoritiesPage/components/ExternalCaModal.tsx b/frontend/src/pages/cert-manager/CertificateAuthoritiesPage/components/ExternalCaModal.tsx index 8b0a88bd0..68757f549 100644 --- a/frontend/src/pages/cert-manager/CertificateAuthoritiesPage/components/ExternalCaModal.tsx +++ b/frontend/src/pages/cert-manager/CertificateAuthoritiesPage/components/ExternalCaModal.tsx @@ -42,6 +42,17 @@ import { import { UsePopUpState } from "@app/hooks/usePopUp"; import { slugSchema } from "@app/lib/schemas"; +const REQUIRED_EAB_DIRECTORIES = [ + "https://acme.digicert.com/v2/acme/directory", + "https://acme.zerossl.com/v2/DV90", + "https://acme.ssl.com/sslcom-dv-rsa", + "https://acme.ssl.com/sslcom-dv-ecc", + "https://dv.acme-v02.api.pki.goog/directory", + "https://acme.sectigo.com/v2/OV", + "https://acme.sectigo.com/v2/EV", + "https://acme.cisco.com/ACMEv2/directory" +]; + const baseSchema = z.object({ type: z.nativeEnum(CaType), name: slugSchema({ @@ -51,18 +62,39 @@ const baseSchema = z.object({ status: z.nativeEnum(CaStatus) }); -const acmeConfigurationSchema = z.object({ - dnsAppConnection: z.object({ - id: z.string(), - name: z.string() - }), - dnsProviderConfig: z.object({ - provider: z.nativeEnum(AcmeDnsProvider), - hostedZoneId: z.string() - }), - directoryUrl: z.string(), - accountEmail: z.string() -}); +const acmeConfigurationSchema = z + .object({ + dnsAppConnection: z.object({ + id: z.string(), + name: z.string() + }), + dnsProviderConfig: z.object({ + provider: z.nativeEnum(AcmeDnsProvider), + hostedZoneId: z.string() + }), + directoryUrl: z.string(), + accountEmail: z.string(), + eabKid: z.string().optional(), + eabHmacKey: z.string().optional() + }) + .superRefine((data, ctx) => { + if (REQUIRED_EAB_DIRECTORIES.includes(data.directoryUrl)) { + if (!data.eabKid || data.eabKid.trim() === "") { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "EAB Key Identifier (KID) is required for this directory URL", + path: ["eabKid"] + }); + } + if (!data.eabHmacKey || data.eabHmacKey.trim() === "") { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "EAB HMAC Key is required for this directory URL", + path: ["eabHmacKey"] + }); + } + } + }); const azureAdCsConfigurationSchema = z.object({ azureAdcsConnection: z.object({ @@ -122,6 +154,10 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { caType === CaType.ACME && configuration && "dnsProviderConfig" in configuration ? configuration.dnsProviderConfig.provider : undefined; + const directoryUrl = + caType === CaType.ACME && configuration && "directoryUrl" in configuration + ? configuration.directoryUrl + : undefined; useEffect(() => { const initialType = (popUp?.ca?.data as { type: CaType })?.type; @@ -155,7 +191,9 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { hostedZoneId: "" }, directoryUrl: "", - accountEmail: "" + accountEmail: "", + eabKid: "", + eabHmacKey: "" } }); } @@ -178,13 +216,10 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { }); const availableConnections: TAvailableAppConnection[] = useMemo(() => { - if (caType === CaType.ACME) { - return [...(availableRoute53Connections || []), ...(availableCloudflareConnections || [])]; - } if (caType === CaType.AZURE_AD_CS) { return availableAzureConnections || []; } - return []; + return [...(availableRoute53Connections || []), ...(availableCloudflareConnections || [])]; }, [ caType, availableRoute53Connections, @@ -192,7 +227,8 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { availableAzureConnections ]); - const isPending = isRoute53Pending || isCloudflarePending || isAzurePending; + const isPending = + isRoute53Pending || isCloudflarePending || (isAzurePending && caType === CaType.AZURE_AD_CS); const dnsAppConnection = caType === CaType.ACME && configuration && "dnsAppConnection" in configuration @@ -227,7 +263,9 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { hostedZoneId: ca.configuration.dnsProviderConfig.hostedZoneId }, directoryUrl: ca.configuration.directoryUrl, - accountEmail: ca.configuration.accountEmail + accountEmail: ca.configuration.accountEmail, + eabKid: ca.configuration.eabKid, + eabHmacKey: ca.configuration.eabHmacKey } }); } else if (ca.type === CaType.AZURE_AD_CS && availableConnections?.length) { @@ -268,7 +306,9 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { dnsProviderConfig: formConfiguration.dnsProviderConfig, directoryUrl: formConfiguration.directoryUrl, accountEmail: formConfiguration.accountEmail, - dnsAppConnectionId: formConfiguration.dnsAppConnection.id + dnsAppConnectionId: formConfiguration.dnsAppConnection.id, + eabKid: formConfiguration.eabKid, + eabHmacKey: formConfiguration.eabHmacKey }; } else if (type === CaType.AZURE_AD_CS && "azureAdcsConnection" in formConfiguration) { configPayload = { @@ -499,6 +539,44 @@ export const ExternalCaModal = ({ popUp, handlePopUpToggle }: Props) => { )} /> + ( + + + + )} + /> + ( + + + + )} + /> )} {caType === CaType.AZURE_AD_CS && ( diff --git a/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityModal.tsx b/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityModal.tsx index 829b55674..4c7fd69cc 100644 --- a/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityModal.tsx +++ b/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityModal.tsx @@ -148,7 +148,11 @@ export const IdentityModal = ({ popUp, handlePopUpToggle }: Props) => { accessTokenTTL: 2592000, accessTokenMaxTTL: 2592000, accessTokenNumUsesLimit: 0, - accessTokenPeriod: 0 + accessTokenPeriod: 0, + lockoutEnabled: true, + lockoutThreshold: 3, + lockoutDurationSeconds: 300, + lockoutCounterResetSeconds: 30 }); handlePopUpToggle("identity", false); diff --git a/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityUniversalAuthForm.tsx b/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityUniversalAuthForm.tsx index e14acd869..2489be7be 100644 --- a/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityUniversalAuthForm.tsx +++ b/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityUniversalAuthForm.tsx @@ -3,6 +3,7 @@ import { Controller, useFieldArray, useForm } from "react-hook-form"; import { faPlus, faXmark } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { zodResolver } from "@hookform/resolvers/zod"; +import ms from "ms"; import { z } from "zod"; import { createNotification } from "@app/components/notifications"; @@ -11,12 +12,16 @@ import { FormControl, IconButton, Input, + Select, + SelectItem, + Switch, Tab, TabList, TabPanel, Tabs } from "@app/components/v2"; import { useOrganization, useSubscription } from "@app/context"; +import { getObjectFromSeconds } from "@app/helpers/datetime"; import { useAddIdentityUniversalAuth, useGetIdentityUniversalAuth, @@ -60,9 +65,79 @@ const schema = z ipAddress: z.string().max(50) }) .array() - .min(1) + .min(1), + lockoutEnabled: z.boolean().default(true), + lockoutThreshold: z + .string() + .refine( + (value) => Number(value) <= 30 && Number(value) >= 1, + "Lockout threshold must be between 1 and 30" + ), + lockoutDurationValue: z.string(), + lockoutDurationUnit: z.enum(["s", "m", "h", "d"], { + invalid_type_error: "Please select a valid time unit" + }), + lockoutCounterResetValue: z.string(), + lockoutCounterResetUnit: z.enum(["s", "m", "h"], { + invalid_type_error: "Please select a valid time unit" + }) }) - .required(); + .required() + .superRefine((data, ctx) => { + const { + lockoutDurationValue, + lockoutCounterResetValue, + lockoutDurationUnit, + lockoutCounterResetUnit, + lockoutEnabled + } = data; + + if (!lockoutEnabled) return; + + let isAnyParseError = false; + + const parsedLockoutDuration = parseInt(lockoutDurationValue, 10); + if (Number.isNaN(parsedLockoutDuration)) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Lockout duration must be a number", + path: ["lockoutDurationValue"] + }); + isAnyParseError = true; + } + + const parsedLockoutCounterReset = parseInt(lockoutCounterResetValue, 10); + if (Number.isNaN(parsedLockoutCounterReset)) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Lockout counter reset must be a number", + path: ["lockoutCounterResetValue"] + }); + isAnyParseError = true; + } + + if (isAnyParseError) return; + + const lockoutDurationInSeconds = ms(`${parsedLockoutDuration}${lockoutDurationUnit}`) / 1000; + const lockoutCounterResetInSeconds = + ms(`${parsedLockoutCounterReset}${lockoutCounterResetUnit}`) / 1000; + + if (lockoutDurationInSeconds > 86400 || lockoutDurationInSeconds < 30) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Lockout duration must be between 30 seconds and 1 day", + path: ["lockoutDurationValue"] + }); + } + + if (lockoutCounterResetInSeconds > 3600 || lockoutCounterResetInSeconds < 5) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Lockout counter reset must be between 5 seconds and 1 hour", + path: ["lockoutCounterResetValue"] + }); + } + }); export type FormData = z.infer; @@ -107,12 +182,25 @@ export const IdentityUniversalAuthForm = ({ accessTokenNumUsesLimit: "0", clientSecretTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }], accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }], - accessTokenPeriod: "0" + accessTokenPeriod: "0", + lockoutEnabled: true, + lockoutThreshold: "3", + lockoutDurationValue: "5", + lockoutDurationUnit: "m", + lockoutCounterResetValue: "30", + lockoutCounterResetUnit: "s" } }); const accessTokenPeriodValue = Number(watch("accessTokenPeriod")); + const lockoutEnabledWatch = watch("lockoutEnabled"); + const lockoutThresholdWatch = watch("lockoutThreshold"); + const lockoutDurationValueWatch = watch("lockoutDurationValue"); + const lockoutDurationUnitWatch = watch("lockoutDurationUnit"); + const lockoutCounterResetValueWatch = watch("lockoutCounterResetValue"); + const lockoutCounterResetUnitWatch = watch("lockoutCounterResetUnit"); + const { fields: clientSecretTrustedIpsFields, append: appendClientSecretTrustedIp, @@ -126,6 +214,9 @@ export const IdentityUniversalAuthForm = ({ useEffect(() => { if (data) { + const lockoutDurationObj = getObjectFromSeconds(data.lockoutDurationSeconds); + const lockoutCounterResetObj = getObjectFromSeconds(data.lockoutCounterResetSeconds); + reset({ accessTokenTTL: String(data.accessTokenTTL), accessTokenMaxTTL: String(data.accessTokenMaxTTL), @@ -144,7 +235,13 @@ export const IdentityUniversalAuthForm = ({ ipAddress: `${ipAddress}${prefix !== undefined ? `/${prefix}` : ""}` }; } - ) + ), + lockoutEnabled: data.lockoutEnabled, + lockoutThreshold: String(data.lockoutThreshold), + lockoutDurationValue: String(lockoutDurationObj.value), + lockoutDurationUnit: lockoutDurationObj.unit as "s" | "m" | "h" | "d", + lockoutCounterResetValue: String(lockoutCounterResetObj.value), + lockoutCounterResetUnit: lockoutCounterResetObj.unit as "s" | "m" | "h" }); } else { reset({ @@ -153,7 +250,13 @@ export const IdentityUniversalAuthForm = ({ accessTokenNumUsesLimit: "0", accessTokenPeriod: "0", clientSecretTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }], - accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }] + accessTokenTrustedIps: [{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }], + lockoutEnabled: true, + lockoutThreshold: "3", + lockoutDurationValue: "5", + lockoutDurationUnit: "m", + lockoutCounterResetValue: "30", + lockoutCounterResetUnit: "s" }); } }, [data]); @@ -164,11 +267,21 @@ export const IdentityUniversalAuthForm = ({ accessTokenNumUsesLimit, clientSecretTrustedIps, accessTokenTrustedIps, - accessTokenPeriod + accessTokenPeriod, + lockoutEnabled, + lockoutThreshold, + lockoutDurationValue, + lockoutDurationUnit, + lockoutCounterResetValue, + lockoutCounterResetUnit }: FormData) => { try { if (!identityId) return; + const lockoutDurationSeconds = ms(`${lockoutDurationValue}${lockoutDurationUnit}`) / 1000; + const lockoutCounterResetSeconds = + ms(`${lockoutCounterResetValue}${lockoutCounterResetUnit}`) / 1000; + if (data) { // update universal auth configuration await updateMutateAsync({ @@ -179,7 +292,11 @@ export const IdentityUniversalAuthForm = ({ accessTokenMaxTTL: Number(accessTokenMaxTTL), accessTokenNumUsesLimit: Number(accessTokenNumUsesLimit), accessTokenTrustedIps, - accessTokenPeriod: Number(accessTokenPeriod) + accessTokenPeriod: Number(accessTokenPeriod), + lockoutEnabled, + lockoutThreshold: Number(lockoutThreshold), + lockoutDurationSeconds, + lockoutCounterResetSeconds }); } else { // create new universal auth configuration @@ -192,7 +309,11 @@ export const IdentityUniversalAuthForm = ({ accessTokenMaxTTL: Number(accessTokenMaxTTL), accessTokenNumUsesLimit: Number(accessTokenNumUsesLimit), accessTokenTrustedIps, - accessTokenPeriod: Number(accessTokenPeriod) + accessTokenPeriod: Number(accessTokenPeriod), + lockoutEnabled, + lockoutThreshold: Number(lockoutThreshold), + lockoutDurationSeconds: Number(lockoutDurationSeconds), + lockoutCounterResetSeconds: Number(lockoutCounterResetSeconds) }); } @@ -217,16 +338,31 @@ export const IdentityUniversalAuthForm = ({ return (
{ - setTabValue( - ["accessTokenTrustedIps", "clientSecretTrustedIps"].includes(Object.keys(fields)[0]) - ? IdentityFormTab.Advanced - : IdentityFormTab.Configuration - ); + const firstErrorField = Object.keys(fields)[0]; + let tab = IdentityFormTab.Configuration; + + if (["accessTokenTrustedIps", "clientSecretTrustedIps"].includes(firstErrorField)) { + tab = IdentityFormTab.Advanced; + } else if ( + [ + "lockoutEnabled", + "lockoutThreshold", + "lockoutDurationValue", + "lockoutDurationUnit", + "lockoutCounterResetValue", + "lockoutCounterResetUnit" + ].includes(firstErrorField) + ) { + tab = IdentityFormTab.Lockout; + } + + setTabValue(tab); })} > setTabValue(value as IdentityFormTab)}> Configuration + Lockout Advanced @@ -296,6 +432,187 @@ export const IdentityUniversalAuthForm = ({ )} /> + +
+ { + return ( + + + Lockout + + + ); + }} + /> +
+ { + return ( + + + + ); + }} + /> +
+ { + return ( + + + + ); + }} + /> + ( + + + + )} + /> +
+
+ { + return ( + + + + ); + }} + /> + ( + + + + )} + /> +
+
+
+
+ {clientSecretTrustedIpsFields.map(({ id }, index) => (
diff --git a/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/types/index.ts b/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/types/index.ts index 56e82f7af..f1c7015c4 100644 --- a/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/types/index.ts +++ b/frontend/src/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/types/index.ts @@ -1,4 +1,5 @@ export enum IdentityFormTab { Advanced = "advanced", + Lockout = "lockout", Configuration = "configuration" } diff --git a/frontend/src/pages/organization/AuditLogsPage/components/LogsSection.tsx b/frontend/src/pages/organization/AuditLogsPage/components/LogsSection.tsx index e938aed7d..5bbb42d32 100644 --- a/frontend/src/pages/organization/AuditLogsPage/components/LogsSection.tsx +++ b/frontend/src/pages/organization/AuditLogsPage/components/LogsSection.tsx @@ -4,9 +4,15 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import ms from "ms"; import { UpgradePlanModal } from "@app/components/license/UpgradePlanModal"; -import { OrgPermissionActions, OrgPermissionSubjects, useSubscription } from "@app/context"; +import { + OrgPermissionAuditLogsActions, + OrgPermissionSubjects, + ProjectPermissionAuditLogsActions, + ProjectPermissionSub, + useSubscription +} from "@app/context"; import { Timezone } from "@app/helpers/datetime"; -import { withPermission } from "@app/hoc"; +import { withPermission, withProjectPermission } from "@app/hoc"; import { Workspace } from "@app/hooks/api/workspace/types"; import { usePopUp } from "@app/hooks/usePopUp"; @@ -28,153 +34,173 @@ type Props = { project?: Workspace; }; -export const LogsSection = withPermission( - ({ presets, refetchInterval, showFilters = true, pageView = false, project }: Props) => { - const { subscription } = useSubscription(); +const LogsSectionComponent = ({ + presets, + refetchInterval, + showFilters = true, + pageView = false, + project +}: Props) => { + const { subscription } = useSubscription(); + const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp(["upgradePlan"] as const); + const [logFilter, setLogFilter] = useState({ + eventType: presets?.eventType || [], + actor: presets?.actorId, + eventMetadata: presets?.eventMetadata + }); + const [timezone, setTimezone] = useState(Timezone.Local); - const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp(["upgradePlan"] as const); - const [logFilter, setLogFilter] = useState({ - eventType: presets?.eventType || [], - actor: presets?.actorId, - eventMetadata: presets?.eventMetadata - }); - const [timezone, setTimezone] = useState(Timezone.Local); + const [dateFilter, setDateFilter] = useState( + presets?.endDate || presets?.startDate + ? { + type: AuditLogDateFilterType.Absolute, + startDate: presets?.startDate || new Date(Number(new Date()) - ms("1h")), + endDate: presets?.endDate || new Date() + } + : { + startDate: new Date(Number(new Date()) - ms("1h")), + endDate: new Date(), + type: AuditLogDateFilterType.Relative, + relativeModeValue: "1h" + } + ); - const [dateFilter, setDateFilter] = useState( - presets?.endDate || presets?.startDate - ? { - type: AuditLogDateFilterType.Absolute, - startDate: presets?.startDate || new Date(Number(new Date()) - ms("1h")), - endDate: presets?.endDate || new Date() - } - : { - startDate: new Date(Number(new Date()) - ms("1h")), - endDate: new Date(), - type: AuditLogDateFilterType.Relative, - relativeModeValue: "1h" - } - ); - - useEffect(() => { - if (subscription && !subscription.auditLogs) { - handlePopUpOpen("upgradePlan"); - } - }, [subscription]); - - if (pageView) - return ( -
-
-
-
-

Audit History

- -
- - Docs - -
-
-
-
-
- {showFilters && ( - - )} - {showFilters && ( - - )} -
-
-
- - { - handlePopUpToggle("upgradePlan", isOpen); - }} - text="You can use audit logs if you switch to a paid Infisical plan." - /> -
-
- ); + useEffect(() => { + if (subscription && !subscription.auditLogs) { + handlePopUpOpen("upgradePlan"); + } + }, [subscription]); + if (pageView) return ( -
-
- {showFilters && ( - - )} - {showFilters && ( - - )} +
+
+
+
+

Audit History

+ +
+ + Docs + +
+
+
+
+
+ {showFilters && ( + + )} + {showFilters && ( + + )} +
+
+
+ + { + handlePopUpToggle("upgradePlan", isOpen); + }} + text="You can use audit logs if you switch to a paid Infisical plan." + />
- - { - handlePopUpToggle("upgradePlan", isOpen); - }} - text="You can use audit logs if you switch to a paid Infisical plan." - />
); - }, - { action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.AuditLogs } -); + + return ( +
+
+ {showFilters && ( + + )} + {showFilters && ( + + )} +
+ + { + handlePopUpToggle("upgradePlan", isOpen); + }} + text="You can use audit logs if you switch to a paid Infisical plan." + /> +
+ ); +}; + +export const LogsSection = (props: Props) => { + const { project } = props; + + if (project) { + const ProjectLogsSectionWithPermission = withProjectPermission(LogsSectionComponent, { + action: ProjectPermissionAuditLogsActions.Read, + subject: ProjectPermissionSub.AuditLogs + }); + return ; + } + + const OrgLogsSectionWithPermission = withPermission(LogsSectionComponent, { + action: OrgPermissionAuditLogsActions.Read, + subject: OrgPermissionSubjects.AuditLogs + }); + return ; +}; diff --git a/frontend/src/pages/organization/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx b/frontend/src/pages/organization/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx index d4de5f1c4..446e54885 100644 --- a/frontend/src/pages/organization/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx +++ b/frontend/src/pages/organization/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx @@ -115,8 +115,10 @@ const Page = () => { handlePopUpToggle("viewAuthMethod", isOpen)} - authMethod={popUp.viewAuthMethod.data} + authMethod={popUp.viewAuthMethod.data?.authMethod} + lockedOut={popUp.viewAuthMethod.data?.lockedOut || false} identityId={identityId} + onResetAllLockouts={popUp.viewAuthMethod.data?.refetchIdentity} />
); diff --git a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/IdentityAuthenticationSection/IdentityAuthenticationSection.tsx b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/IdentityAuthenticationSection/IdentityAuthenticationSection.tsx index 467fc7dcc..a1051afb8 100644 --- a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/IdentityAuthenticationSection/IdentityAuthenticationSection.tsx +++ b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/IdentityAuthenticationSection/IdentityAuthenticationSection.tsx @@ -1,8 +1,8 @@ -import { faCog, faPlus } from "@fortawesome/free-solid-svg-icons"; +import { faCog, faLock, faPlus } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { OrgPermissionCan } from "@app/components/permissions"; -import { Button } from "@app/components/v2"; +import { Button, Tooltip } from "@app/components/v2"; import { OrgPermissionIdentityActions, OrgPermissionSubjects } from "@app/context"; import { IdentityAuthMethod, identityAuthToNameMap, useGetIdentityById } from "@app/hooks/api"; import { UsePopUpState } from "@app/hooks/usePopUp"; @@ -16,7 +16,7 @@ type Props = { }; export const IdentityAuthenticationSection = ({ identityId, handlePopUpOpen }: Props) => { - const { data } = useGetIdentityById(identityId); + const { data, refetch } = useGetIdentityById(identityId); return data ? (
@@ -28,12 +28,25 @@ export const IdentityAuthenticationSection = ({ identityId, handlePopUpOpen }: P {data.identity.authMethods.map((authMethod) => ( ))}
diff --git a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityAuthModal.tsx b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityAuthModal.tsx index ca0a5e6f3..f95a20789 100644 --- a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityAuthModal.tsx +++ b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityAuthModal.tsx @@ -37,9 +37,11 @@ import { ViewIdentityUniversalAuthContent } from "./ViewIdentityUniversalAuthCon type Props = { identityId: string; authMethod?: IdentityAuthMethod; + lockedOut: boolean; isOpen: boolean; onOpenChange: (isOpen: boolean) => void; onDeleteAuthMethod: () => void; + onResetAllLockouts: () => void; }; type TRevokeOptions = { @@ -50,8 +52,13 @@ type TRevokeOptions = { export const Content = ({ identityId, authMethod, - onDeleteAuthMethod -}: Pick) => { + lockedOut, + onDeleteAuthMethod, + onResetAllLockouts +}: Pick< + Props, + "authMethod" | "lockedOut" | "identityId" | "onDeleteAuthMethod" | "onResetAllLockouts" +>) => { const { currentOrg } = useOrganization(); const orgId = currentOrg?.id || ""; @@ -159,9 +166,11 @@ export const Content = ({ ) => { if (!identityId || !authMethod) return null; @@ -194,7 +205,9 @@ export const ViewIdentityAuthModal = ({ onOpenChange(false)} + onResetAllLockouts={() => onResetAllLockouts()} /> diff --git a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityUniversalAuthContent.tsx b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityUniversalAuthContent.tsx index ce6415171..b05a873ce 100644 --- a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityUniversalAuthContent.tsx +++ b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/ViewIdentityUniversalAuthContent.tsx @@ -1,9 +1,15 @@ +import { useState } from "react"; import { faBan, faCheck, faCopy } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import ms from "ms"; -import { EmptyState, IconButton, Spinner, Tooltip } from "@app/components/v2"; +import { createNotification } from "@app/components/notifications"; +import { OrgPermissionCan } from "@app/components/permissions"; +import { Button, EmptyState, IconButton, Spinner, Tooltip } from "@app/components/v2"; +import { OrgPermissionIdentityActions, OrgPermissionSubjects } from "@app/context"; import { useTimedReset } from "@app/hooks"; import { + useClearIdentityUniversalAuthLockouts, useGetIdentityUniversalAuth, useGetIdentityUniversalAuthClientSecrets } from "@app/hooks/api"; @@ -19,16 +25,40 @@ export const ViewIdentityUniversalAuthContent = ({ handlePopUpToggle, handlePopUpOpen, onDelete, - popUp + popUp, + lockedOut, + onResetAllLockouts }: ViewAuthMethodProps) => { const { data, isPending } = useGetIdentityUniversalAuth(identityId); const { data: clientSecrets = [], isPending: clientSecretsPending } = useGetIdentityUniversalAuthClientSecrets(identityId); + const { mutateAsync: clearLockoutsFn, isPending: isClearLockoutsPending } = + useClearIdentityUniversalAuthLockouts(); + + const [lockedOutState, setLockedOutState] = useState(lockedOut); const [copyTextClientId, isCopyingClientId, setCopyTextClientId] = useTimedReset({ initialState: "Copy Client ID to clipboard" }); + async function clearLockouts() { + try { + const deleted = await clearLockoutsFn({ identityId }); + createNotification({ + text: `Successfully cleared ${deleted} lockout${deleted === 1 ? "" : "s"}`, + type: "success" + }); + setLockedOutState(false); + onResetAllLockouts(); + } catch (error) { + console.error(error); + createNotification({ + text: "Failed to clear lockouts. Please try again.", + type: "error" + }); + } + } + if (isPending || clientSecretsPending) { return (
@@ -85,6 +115,41 @@ export const ViewIdentityUniversalAuthContent = ({ {data.clientSecretTrustedIps.map((ip) => ip.ipAddress).join(", ")} + + {data.lockoutEnabled ? "Enabled" : "Disabled"} + + {data.lockoutEnabled && ( + <> +
+ Lockout Options + + {(isAllowed) => ( + + )} + +
+ + {data.lockoutThreshold} + + + {ms(data.lockoutDurationSeconds * 1000, { long: true })} + + + {ms(data.lockoutCounterResetSeconds * 1000, { long: true })} + + + )}
Client ID diff --git a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/types/index.ts b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/types/index.ts index 7673f5d6b..da31a233c 100644 --- a/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/types/index.ts +++ b/frontend/src/pages/organization/IdentityDetailsByIDPage/components/ViewIdentityAuthModal/types/index.ts @@ -9,4 +9,6 @@ export type ViewAuthMethodProps = { state?: boolean ) => void; popUp: UsePopUpState<["revokeAuthMethod", "upgradePlan", "identityAuthMethod"]>; + lockedOut: boolean; + onResetAllLockouts: () => void; }; diff --git a/frontend/src/pages/organization/ProjectsPage/components/AllProjectView.tsx b/frontend/src/pages/organization/ProjectsPage/components/AllProjectView.tsx index a9f613584..7b066a099 100644 --- a/frontend/src/pages/organization/ProjectsPage/components/AllProjectView.tsx +++ b/frontend/src/pages/organization/ProjectsPage/components/AllProjectView.tsx @@ -48,7 +48,7 @@ import { useRequestProjectAccess, useSearchProjects } from "@app/hooks/api"; -import { ProjectType, Workspace } from "@app/hooks/api/workspace/types"; +import { ProjectType, Workspace, WorkspaceEnv } from "@app/hooks/api/workspace/types"; import { ProjectListToggle, ProjectListView @@ -152,13 +152,17 @@ export const AllProjectView = ({ type: projectTypeFilter }); - const handleAccessProject = async (type: ProjectType, projectId: string) => { + const handleAccessProject = async ( + type: ProjectType, + projectId: string, + environments: WorkspaceEnv[] + ) => { try { await orgAdminAccessProject.mutateAsync({ projectId }); await navigate({ - to: getProjectHomePage(type), + to: getProjectHomePage(type, environments), params: { projectId } @@ -315,7 +319,7 @@ export const AllProjectView = ({ onKeyDown={(evt) => { if (evt.key === "Enter" && workspace.isMember) { navigate({ - to: getProjectHomePage(workspace.type), + to: getProjectHomePage(workspace.type, workspace.environments), params: { projectId: workspace.id } @@ -325,7 +329,7 @@ export const AllProjectView = ({ onClick={() => { if (workspace.isMember) { navigate({ - to: getProjectHomePage(workspace.type), + to: getProjectHomePage(workspace.type, workspace.environments), params: { projectId: workspace.id } @@ -371,7 +375,7 @@ export const AllProjectView = ({ onClick={(e) => { e.stopPropagation(); e.preventDefault(); - handleAccessProject(workspace.type, workspace.id); + handleAccessProject(workspace.type, workspace.id, workspace.environments); }} disabled={ orgAdminAccessProject.variables?.projectId === workspace.id && diff --git a/frontend/src/pages/organization/ProjectsPage/components/MyProjectView.tsx b/frontend/src/pages/organization/ProjectsPage/components/MyProjectView.tsx index 8606aeb89..d63099273 100644 --- a/frontend/src/pages/organization/ProjectsPage/components/MyProjectView.tsx +++ b/frontend/src/pages/organization/ProjectsPage/components/MyProjectView.tsx @@ -193,7 +193,7 @@ export const MyProjectView = ({
{ navigate({ - to: getProjectHomePage(workspace.type), + to: getProjectHomePage(workspace.type, workspace.environments), params: { projectId: workspace.id } @@ -247,7 +247,7 @@ export const MyProjectView = ({
{ navigate({ - to: getProjectHomePage(workspace.type), + to: getProjectHomePage(workspace.type, workspace.environments), params: { projectId: workspace.id } diff --git a/frontend/src/pages/organization/RoleByIDPage/components/OrgRoleModifySection.utils.ts b/frontend/src/pages/organization/RoleByIDPage/components/OrgRoleModifySection.utils.ts index 275b73fd0..03b86f2ab 100644 --- a/frontend/src/pages/organization/RoleByIDPage/components/OrgRoleModifySection.utils.ts +++ b/frontend/src/pages/organization/RoleByIDPage/components/OrgRoleModifySection.utils.ts @@ -5,6 +5,7 @@ import { OrgPermissionSubjects } from "@app/context"; import { OrgGatewayPermissionActions, OrgPermissionAppConnectionActions, + OrgPermissionAuditLogsActions, OrgPermissionBillingActions, OrgPermissionGroupActions, OrgPermissionIdentityActions, @@ -23,6 +24,12 @@ const generalPermissionSchema = z }) .optional(); +const auditLogsPermissionSchema = z + .object({ + [OrgPermissionAuditLogsActions.Read]: z.boolean().optional() + }) + .optional(); + const billingPermissionSchema = z .object({ [OrgPermissionBillingActions.Read]: z.boolean().optional(), @@ -121,7 +128,7 @@ export const formSchema = z.object({ }) .optional(), - "audit-logs": generalPermissionSchema, + "audit-logs": auditLogsPermissionSchema, member: generalPermissionSchema, groups: groupPermissionSchema, role: generalPermissionSchema, diff --git a/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/OrgPermissionAuditLogsRow.tsx b/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/OrgPermissionAuditLogsRow.tsx new file mode 100644 index 000000000..b86ae91d4 --- /dev/null +++ b/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/OrgPermissionAuditLogsRow.tsx @@ -0,0 +1,145 @@ +import { useEffect, useMemo } from "react"; +import { Control, Controller, UseFormSetValue, useWatch } from "react-hook-form"; +import { faChevronDown, faChevronRight } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; + +import { createNotification } from "@app/components/notifications"; +import { Checkbox, Select, SelectItem, Td, Tr } from "@app/components/v2"; +import { OrgPermissionAuditLogsActions } from "@app/context/OrgPermissionContext/types"; +import { useToggle } from "@app/hooks"; + +import { TFormSchema } from "../OrgRoleModifySection.utils"; + +type Props = { + isEditable: boolean; + setValue: UseFormSetValue; + control: Control; +}; + +enum Permission { + NoAccess = "no-access", + Custom = "custom" +} + +const PERMISSION_ACTIONS = [ + { + action: OrgPermissionAuditLogsActions.Read, + label: "Read" + } +] as const; + +export const OrgPermissionAuditLogsRow = ({ isEditable, control, setValue }: Props) => { + const [isRowExpanded, setIsRowExpanded] = useToggle(); + const [isCustom, setIsCustom] = useToggle(); + + const rule = useWatch({ + control, + name: "permissions.audit-logs" + }); + + const selectedPermissionCategory = useMemo(() => { + const actions = Object.keys(rule || {}) as Array; + const score = actions.map((key) => (rule?.[key] ? 1 : 0)).reduce((a, b) => a + b, 0 as number); + + if (isCustom) return Permission.Custom; + if (score === 0) return Permission.NoAccess; + + return Permission.Custom; + }, [rule, isCustom]); + + useEffect(() => { + if (selectedPermissionCategory === Permission.Custom) setIsCustom.on(); + else setIsCustom.off(); + }, [selectedPermissionCategory]); + + useEffect(() => { + const isRowCustom = selectedPermissionCategory === Permission.Custom; + if (isRowCustom) { + setIsRowExpanded.on(); + } + }, []); + + const handlePermissionChange = (val: Permission) => { + if (!val) return; + if (val === Permission.Custom) { + setIsRowExpanded.on(); + setIsCustom.on(); + return; + } + setIsCustom.off(); + + switch (val) { + case Permission.NoAccess: + default: + setValue( + "permissions.audit-logs", + { + [OrgPermissionAuditLogsActions.Read]: false + }, + { shouldDirty: true } + ); + } + }; + + return ( + <> + setIsRowExpanded.toggle()} + > + + + + Audit Logs + + + + + {isRowExpanded && ( + + +
+ {PERMISSION_ACTIONS.map(({ action, label }) => { + return ( + ( + { + if (!isEditable) { + createNotification({ + type: "error", + text: "Failed to update default role" + }); + return; + } + field.onChange(e); + }} + id={`permissions.audit-logs.${action}`} + > + {label} + + )} + /> + ); + })} +
+ + + )} + + ); +}; diff --git a/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionRow.tsx b/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionRow.tsx index e0702b201..0254e8240 100644 --- a/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionRow.tsx +++ b/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionRow.tsx @@ -71,6 +71,7 @@ type Props = { | "gateway" | "secret-share" | "billing" + | "audit-logs" | "machine-identity-auth-template" >; setValue: UseFormSetValue; diff --git a/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionsSection.tsx b/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionsSection.tsx index 6fd848f56..3b606cbb1 100644 --- a/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionsSection.tsx +++ b/frontend/src/pages/organization/RoleByIDPage/components/RolePermissionsSection/RolePermissionsSection.tsx @@ -16,6 +16,7 @@ import { TFormSchema } from "../OrgRoleModifySection.utils"; import { OrgPermissionAdminConsoleRow } from "./OrgPermissionAdminConsoleRow"; +import { OrgPermissionAuditLogsRow } from "./OrgPermissionAuditLogsRow"; import { OrgPermissionBillingRow } from "./OrgPermissionBillingRow"; import { OrgGatewayPermissionRow } from "./OrgPermissionGatewayRow"; import { OrgPermissionGroupRow } from "./OrgPermissionGroupRow"; @@ -39,10 +40,6 @@ const SIMPLE_PERMISSION_OPTIONS = [ title: "Incident Contacts", formName: "incident-contact" }, - { - title: "Audit Logs", - formName: "audit-logs" - }, { title: "Organization Profile", formName: "settings" @@ -166,6 +163,11 @@ export const RolePermissionsSection = ({ roleId }: Props) => { /> ); })} + { - switch (unit) { - case "m": - return value * 60; - case "h": - return value * 60 * 60; - case "d": - return value * 60 * 60 * 24; - default: - return 0; - } -}; - -// Helper function to convert seconds to form lifetime value and unit -const getFormLifetimeFromSeconds = ( - totalSeconds: number | null | undefined -): { maxLifetimeValue: number; maxLifetimeUnit: "m" | "h" | "d" } => { - const DEFAULT_LIFETIME_VALUE = 30; - const DEFAULT_LIFETIME_UNIT = "d" as "m" | "h" | "d"; - - if (totalSeconds == null || totalSeconds <= 0) { - return { - maxLifetimeValue: DEFAULT_LIFETIME_VALUE, - maxLifetimeUnit: DEFAULT_LIFETIME_UNIT - }; - } - - const secondsInDay = 24 * 60 * 60; - const secondsInHour = 60 * 60; - const secondsInMinute = 60; - - if (totalSeconds % secondsInDay === 0) { - const value = totalSeconds / secondsInDay; - if (value >= 1) return { maxLifetimeValue: value, maxLifetimeUnit: "d" }; - } - - if (totalSeconds % secondsInHour === 0) { - const value = totalSeconds / secondsInHour; - if (value >= 1) return { maxLifetimeValue: value, maxLifetimeUnit: "h" }; - } - - if (totalSeconds % secondsInMinute === 0) { - const value = totalSeconds / secondsInMinute; - if (value >= 1) return { maxLifetimeValue: value, maxLifetimeUnit: "m" }; - } - - return { - maxLifetimeValue: DEFAULT_LIFETIME_VALUE, - maxLifetimeUnit: DEFAULT_LIFETIME_UNIT - }; -}; - const formSchema = z .object({ maxLifetimeValue: z.number().min(1, "Value must be at least 1"), @@ -77,34 +26,20 @@ const formSchema = z .superRefine((data, ctx) => { const { maxLifetimeValue, maxLifetimeUnit } = data; - const durationInSeconds = durationToSeconds(maxLifetimeValue, maxLifetimeUnit); + const durationInSeconds = ms(`${maxLifetimeValue}${maxLifetimeUnit}`) / 1000; - // Check max limit if (durationInSeconds > MAX_SHARED_SECRET_LIFETIME_SECONDS) { - let message = "Duration exceeds maximum allowed limit"; - - if (maxLifetimeUnit === "m") { - message = `Maximum allowed minutes is ${MAX_SHARED_SECRET_LIFETIME_SECONDS / 60} (30 days)`; - } else if (maxLifetimeUnit === "h") { - message = `Maximum allowed hours is ${MAX_SHARED_SECRET_LIFETIME_SECONDS / (60 * 60)} (30 days)`; - } else if (maxLifetimeUnit === "d") { - message = `Maximum allowed days is ${MAX_SHARED_SECRET_LIFETIME_SECONDS / (24 * 60 * 60)}`; - } - ctx.addIssue({ code: z.ZodIssueCode.custom, - message, + message: "Duration exceeds a maximum of 30 days", path: ["maxLifetimeValue"] }); } - // Check min limit if (durationInSeconds < MIN_SHARED_SECRET_LIFETIME_SECONDS) { - const message = `Duration must be at least ${MIN_SHARED_SECRET_LIFETIME_SECONDS / 60} minutes`; // 5 minutes - ctx.addIssue({ code: z.ZodIssueCode.custom, - message, + message: "Duration must be at least 5 minutes", path: ["maxLifetimeValue"] }); } @@ -122,10 +57,14 @@ export const OrgSecretShareLimitSection = () => { const { currentOrg } = useOrganization(); const getDefaultFormValues = () => { - const initialLifetime = getFormLifetimeFromSeconds(currentOrg?.maxSharedSecretLifetime); + const initialLifetime = getObjectFromSeconds(currentOrg?.maxSharedSecretLifetime, [ + "m", + "h", + "d" + ]); return { - maxLifetimeValue: initialLifetime.maxLifetimeValue, - maxLifetimeUnit: initialLifetime.maxLifetimeUnit, + maxLifetimeValue: initialLifetime.value, + maxLifetimeUnit: initialLifetime.unit as "m" | "h" | "d", maxViewLimit: currentOrg?.maxSharedSecretViewLimit?.toString() || "1", shouldLimitView: Boolean(currentOrg?.maxSharedSecretViewLimit) }; @@ -152,10 +91,8 @@ export const OrgSecretShareLimitSection = () => { const handleFormSubmit = async (formData: TForm) => { try { - const maxSharedSecretLifetimeSeconds = durationToSeconds( - formData.maxLifetimeValue, - formData.maxLifetimeUnit - ); + const maxSharedSecretLifetimeSeconds = + ms(`${formData.maxLifetimeValue}${formData.maxLifetimeUnit}`) / 1000; await mutateAsync({ orgId: currentOrg.id, diff --git a/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/SelectImportFromPlatformModal.tsx b/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/SelectImportFromPlatformModal.tsx index 6da5a44c9..cd39d8678 100644 --- a/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/SelectImportFromPlatformModal.tsx +++ b/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/SelectImportFromPlatformModal.tsx @@ -1,6 +1,4 @@ import { useState } from "react"; -import { faKey, faVault } from "@fortawesome/free-solid-svg-icons"; -import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { AnimatePresence, motion } from "framer-motion"; import { Modal, ModalContent } from "@app/components/v2"; @@ -20,14 +18,16 @@ enum WizardSteps { const PLATFORM_LIST = [ { - icon: faKey, + image: "/images/integrations/EnvKey.png", platform: "env-key", - title: "Env Key" + title: "EnvKey", + size: 34 }, { - icon: faVault, + image: "/images/integrations/Vault.png", platform: "vault", - title: "Vault" + title: "HCP Vault", + size: 40 } ] as const; @@ -67,7 +67,7 @@ export const SelectImportFromPlatformModal = ({ isOpen, onToggle }: Props) => { {PLATFORM_LIST.map((platform, idx) => (
{ @@ -81,7 +81,11 @@ export const SelectImportFromPlatformModal = ({ isOpen, onToggle }: Props) => { } }} > - + {`${platform.title}
{platform.title}
))} diff --git a/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/VaultPlatformModal.tsx b/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/VaultPlatformModal.tsx index 02ab5df1b..137e765d2 100644 --- a/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/VaultPlatformModal.tsx +++ b/frontend/src/pages/organization/SettingsPage/components/ExternalMigrationsTab/components/VaultPlatformModal.tsx @@ -2,12 +2,19 @@ import { Controller, useForm } from "react-hook-form"; import { faQuestionCircle } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { zodResolver } from "@hookform/resolvers/zod"; +import { useQuery } from "@tanstack/react-query"; import { twMerge } from "tailwind-merge"; import { z } from "zod"; import { createNotification } from "@app/components/notifications"; -import { Button, FormControl, Input, Tooltip } from "@app/components/v2"; +import { OrgPermissionCan } from "@app/components/permissions"; +import { Button, FormControl, Input, Select, SelectItem, Tooltip } from "@app/components/v2"; import { NoticeBannerV2 } from "@app/components/v2/NoticeBannerV2/NoticeBannerV2"; +import { + OrgGatewayPermissionActions, + OrgPermissionSubjects +} from "@app/context/OrgPermissionContext/types"; +import { gatewaysQueryKeys } from "@app/hooks/api"; import { useImportVault } from "@app/hooks/api/migration/mutations"; type Props = { @@ -62,36 +69,32 @@ const MAPPING_TYPE_MENU_ITEMS = [ export const VaultPlatformModal = ({ onClose }: Props) => { const formSchema = z.object({ vaultUrl: z.string().min(1), + gatewayId: z.string().optional(), vaultNamespace: z.string().trim().optional(), vaultAccessToken: z.string().min(1), mappingType: z.nativeEnum(VaultMappingType).default(VaultMappingType.KeyVault) }); type TFormData = z.infer; + const { data: gateways, isPending: isGatewayLoading } = useQuery(gatewaysQueryKeys.list()); const { mutateAsync: importVault } = useImportVault(); const { control, handleSubmit, reset, - formState: { isLoading, isDirty, isSubmitting, isValid, errors } + formState: { isLoading, isDirty, isSubmitting, isValid } } = useForm({ resolver: zodResolver(formSchema) }); - console.log({ - isSubmitting, - isLoading, - isValid, - errors - }); - const onSubmit = async (data: TFormData) => { await importVault({ vaultAccessToken: data.vaultAccessToken, vaultNamespace: data.vaultNamespace, vaultUrl: data.vaultUrl, - mappingType: data.mappingType + mappingType: data.mappingType, + ...(data.gatewayId && { gatewayId: data.gatewayId }) }); createNotification({ title: "Import started", @@ -110,11 +113,70 @@ export const VaultPlatformModal = ({ onClose }: Props) => { The Vault migration currently supports importing static secrets from Vault Dedicated/Self-Hosted.
- Currently only KV Secret Engine V2 is supported for Vault migrations. + Currently only KV Secret Engine is supported for Vault migrations.

+
+ + {(isAllowed) => ( + ( + + +
+ +
+
+
+ )} + /> + )} +
+
+ { text: "User privilege assumption has started" }); - const url = getProjectHomePage(currentWorkspace.type); + const url = getProjectHomePage(currentWorkspace.type, currentWorkspace.environments); window.location.href = url.replace("$projectId", currentWorkspace.id); } } diff --git a/frontend/src/pages/project/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx b/frontend/src/pages/project/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx index 19d6c4acc..e1da4edab 100644 --- a/frontend/src/pages/project/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx +++ b/frontend/src/pages/project/IdentityDetailsByIDPage/IdentityDetailsByIDPage.tsx @@ -67,7 +67,7 @@ const Page = () => { type: "success", text: "Identity privilege assumption has started" }); - const url = getProjectHomePage(currentWorkspace.type); + const url = getProjectHomePage(currentWorkspace.type, currentWorkspace.environments); window.location.href = url.replace("$projectId", currentWorkspace.id); } } diff --git a/frontend/src/pages/project/MemberDetailsByIDPage/MemberDetailsByIDPage.tsx b/frontend/src/pages/project/MemberDetailsByIDPage/MemberDetailsByIDPage.tsx index 7bac32f75..7fadf2cb9 100644 --- a/frontend/src/pages/project/MemberDetailsByIDPage/MemberDetailsByIDPage.tsx +++ b/frontend/src/pages/project/MemberDetailsByIDPage/MemberDetailsByIDPage.tsx @@ -72,7 +72,7 @@ export const Page = () => { text: "User privilege assumption has started" }); - const url = getProjectHomePage(currentWorkspace.type); + const url = getProjectHomePage(currentWorkspace.type, currentWorkspace.environments); window.location.href = url.replace("$projectId", currentWorkspace.id); } } diff --git a/frontend/src/pages/project/RoleDetailsBySlugPage/components/ProjectRoleModifySection.utils.tsx b/frontend/src/pages/project/RoleDetailsBySlugPage/components/ProjectRoleModifySection.utils.tsx index 9ebc903a5..856275374 100644 --- a/frontend/src/pages/project/RoleDetailsBySlugPage/components/ProjectRoleModifySection.utils.tsx +++ b/frontend/src/pages/project/RoleDetailsBySlugPage/components/ProjectRoleModifySection.utils.tsx @@ -12,6 +12,7 @@ import { } from "@app/context"; import { PermissionConditionOperators, + ProjectPermissionAuditLogsActions, ProjectPermissionCommitsActions, ProjectPermissionDynamicSecretActions, ProjectPermissionGroupActions, @@ -41,6 +42,10 @@ const GeneralPolicyActionSchema = z.object({ create: z.boolean().optional() }); +const AuditLogsPolicyActionSchema = z.object({ + [ProjectPermissionAuditLogsActions.Read]: z.boolean().optional() +}); + const CertificatePolicyActionSchema = z.object({ [ProjectPermissionCertificateActions.Create]: z.boolean().optional(), [ProjectPermissionCertificateActions.Delete]: z.boolean().optional(), @@ -316,7 +321,7 @@ export const projectRoleFormSchema = z.object({ [ProjectPermissionSub.ServiceTokens]: GeneralPolicyActionSchema.array().default([]), [ProjectPermissionSub.Settings]: GeneralPolicyActionSchema.array().default([]), [ProjectPermissionSub.Environments]: GeneralPolicyActionSchema.array().default([]), - [ProjectPermissionSub.AuditLogs]: GeneralPolicyActionSchema.array().default([]), + [ProjectPermissionSub.AuditLogs]: AuditLogsPolicyActionSchema.array().default([]), [ProjectPermissionSub.IpAllowList]: GeneralPolicyActionSchema.array().default([]), [ProjectPermissionSub.CertificateAuthorities]: GeneralPolicyActionSchema.array().default([]), [ProjectPermissionSub.Certificates]: CertificatePolicyActionSchema.array().default([]), @@ -1324,12 +1329,7 @@ export const PROJECT_PERMISSION_OBJECT: TProjectPermissionObject = { }, [ProjectPermissionSub.AuditLogs]: { title: "Audit Logs", - actions: [ - { label: "Read", value: "read" }, - { label: "Create", value: "create" }, - { label: "Modify", value: "edit" }, - { label: "Remove", value: "delete" } - ] + actions: [{ label: "Read", value: ProjectPermissionAuditLogsActions.Read }] }, [ProjectPermissionSub.IpAllowList]: { title: "IP Allowlist", @@ -1721,7 +1721,7 @@ const projectManagerTemplate = ( permissions: [ { subject: ProjectPermissionSub.AuditLogs, - actions: Object.values(ProjectPermissionActions) + actions: Object.values(ProjectPermissionAuditLogsActions) }, { subject: ProjectPermissionSub.Groups, diff --git a/frontend/src/pages/secret-manager/IntegrationsDetailsByIDPage/components/IntegrationAuditLogsSection.tsx b/frontend/src/pages/secret-manager/IntegrationsDetailsByIDPage/components/IntegrationAuditLogsSection.tsx index b4ecd1e0e..c27b1bb08 100644 --- a/frontend/src/pages/secret-manager/IntegrationsDetailsByIDPage/components/IntegrationAuditLogsSection.tsx +++ b/frontend/src/pages/secret-manager/IntegrationsDetailsByIDPage/components/IntegrationAuditLogsSection.tsx @@ -1,7 +1,7 @@ import { Link } from "@tanstack/react-router"; import { EmptyState } from "@app/components/v2"; -import { useSubscription } from "@app/context"; +import { useSubscription, useWorkspace } from "@app/context"; import { EventType } from "@app/hooks/api/auditLogs/enums"; import { TIntegrationWithEnv } from "@app/hooks/api/integrations/types"; import { LogsSection } from "@app/pages/organization/AuditLogsPage/components/LogsSection"; @@ -15,6 +15,7 @@ type Props = { export const IntegrationAuditLogsSection = ({ integration }: Props) => { const { subscription } = useSubscription(); + const { currentWorkspace } = useWorkspace(); const auditLogsRetentionDays = subscription?.auditLogsRetentionDays ?? 30; @@ -30,6 +31,7 @@ export const IntegrationAuditLogsSection = ({ integration }: Props) => { { const { permission } = useProjectPermission(); const { mutateAsync: createCommit } = useCreateCommit(); - const tableRef = useRef(null); + const tableRef = useRef(null); const [isVisible, setIsVisible] = useState(false); const { isBatchMode, pendingChanges } = useBatchMode(); @@ -249,7 +252,8 @@ const Page = () => { const { data, isPending: isDetailsLoading, - isFetching: isDetailsFetching + isFetching: isDetailsFetching, + isFetched } = useGetProjectSecretsDetails({ environment, projectId: workspaceId, @@ -270,6 +274,18 @@ const Page = () => { tags: filter.tags }); + useEffect(() => { + // if switching tabs in a folder path that doesn't exist in a separate env we navigate to the root + if (!data && isFetched) { + navigate({ + search: (prev) => ({ + ...prev, + secretPath: "/" + }) + }); + } + }, [data, isFetched]); + const { imports, folders, @@ -491,7 +507,8 @@ const Page = () => { minWidth: 100, maxWidth: tableRef.current ? tableRef.current.clientWidth - 148 // ensure value column can't collapse completely - : 800 + : 800, + ref: tableRef }); useEffect(() => { @@ -710,12 +727,18 @@ const Page = () => { const mergedSecrets = getMergedSecretsWithPending(); const mergedFolders = getMergedFoldersWithPending(); + + if (!(currentWorkspace?.version === ProjectVersion.V3)) + return ( +
+ +
+ ); + return (
env.slug === environment)?.name ?? environment - } + title="Secrets Management" description={

Inject your secrets using @@ -759,6 +782,8 @@ const Page = () => { } /> + + {!isRollbackMode ? ( <> { workspaceId={workspaceId} secretPath={secretPath} onNavigateToFolder={handleResetFilter} + canNavigate={isFetched} /> )} {canReadDynamicSecret && Boolean(dynamicSecrets?.length) && ( diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/CompareEnvironments.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/CompareEnvironments.tsx new file mode 100644 index 000000000..c3570bf5a --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/CompareEnvironments.tsx @@ -0,0 +1,595 @@ +import { useCallback, useEffect, useRef, useState } from "react"; +import { MultiValue } from "react-select"; +import { + faArrowDown, + faArrowUp, + faCheckCircle, + faFilter, + faFingerprint, + faFolder, + faKey, + faRotate, + faSearch, + faWarning +} from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { twMerge } from "tailwind-merge"; + +import { + Badge, + Button, + DropdownMenu, + DropdownMenuContent, + DropdownMenuItem, + DropdownMenuLabel, + DropdownMenuTrigger, + EmptyState, + FilterableSelect, + FormLabel, + IconButton, + Input, + Lottie, + Pagination, + Table, + TableContainer, + TBody, + Th, + THead, + Tooltip, + Tr +} from "@app/components/v2"; +import { useWorkspace } from "@app/context"; +import { + getUserTablePreference, + PreferenceKey, + setUserTablePreference +} from "@app/helpers/userTablePreferences"; +import { useDebounce, usePagination, useResetPageHelper } from "@app/hooks"; +import { useGetImportedSecretsAllEnvs } from "@app/hooks/api"; +import { useGetProjectSecretsOverview } from "@app/hooks/api/dashboard"; +import { DashboardSecretsOrderBy } from "@app/hooks/api/dashboard/types"; +import { OrderByDirection } from "@app/hooks/api/generic/types"; +import { WorkspaceEnv } from "@app/hooks/api/workspace/types"; +import { useResizableColWidth } from "@app/hooks/useResizableColWidth"; +import { + useDynamicSecretOverview, + useFolderOverview, + useSecretOverview, + useSecretRotationOverview +} from "@app/hooks/utils"; +import { SecretTableResourceCount } from "@app/pages/secret-manager/OverviewPage/components/SecretTableResourceCount"; + +import { DynamicSecretRow } from "./components/DynamicSecretRow"; +import { FolderRow } from "./components/FolderRow"; +import { SecretRotationRow } from "./components/SecretRotationRow"; +import { SecretNoAccessRow, SecretRow } from "./components/SecretRow"; + +type Props = { + secretPath: string; +}; + +enum RowType { + Folder = "folder", + DynamicSecret = "dynamic", + Secret = "secret", + SecretRotation = "rotation" +} + +type Filter = { + [key in RowType]: boolean; +}; + +const DEFAULT_FILTER_STATE = { + [RowType.Folder]: false, + [RowType.DynamicSecret]: false, + [RowType.Secret]: false, + [RowType.SecretRotation]: false +}; + +const COL_WIDTH_OFFSET = 220; + +export const CompareEnvironments = ({ secretPath }: Props) => { + const { currentWorkspace } = useWorkspace(); + const compareEnvironmentsKey = `compare-environments-${currentWorkspace.id}`; + + const [selectedEnvironments, setSelectedEnvironments] = useState(() => { + try { + const storedEnvironments = JSON.parse(localStorage.getItem(compareEnvironmentsKey) ?? "[]"); + + if (Array.isArray(storedEnvironments) && storedEnvironments.length > 0) { + const potentialEnvs: string[] = []; + storedEnvironments.forEach((env) => { + if (typeof env === "string") { + potentialEnvs.push(env); + } + }); + + return currentWorkspace.environments.filter((env) => potentialEnvs.includes(env.id)); + } + } catch { + // do nothing and proceed + } + return currentWorkspace.environments.slice(0, 2); + }); + + const [filter, setFilter] = useState(DEFAULT_FILTER_STATE); + + const { + offset, + limit, + orderDirection, + setOrderDirection, + setPage, + perPage, + page, + setPerPage, + orderBy + } = usePagination(DashboardSecretsOrderBy.Name, { + initPerPage: getUserTablePreference("secretCompareTable", PreferenceKey.PerPage, 50) + }); + + const handlePerPageChange = (newPerPage: number) => { + setPerPage(newPerPage); + setUserTablePreference("secretCompareTable", PreferenceKey.PerPage, newPerPage); + }; + + const workspaceId = currentWorkspace.id; + const [searchFilter, setSearchFilter] = useState(""); + const [debouncedSearchFilter] = useDebounce(searchFilter); + const [debouncedSelectedEnvironments] = useDebounce(selectedEnvironments); + + useEffect(() => { + localStorage.setItem( + compareEnvironmentsKey, + JSON.stringify(selectedEnvironments.map((env) => env.id)) + ); + }, [debouncedSelectedEnvironments]); + + const { + secretImports, + isImportedSecretPresentInEnv, + getImportedSecretByKey, + getEnvImportedSecretKeyCount + } = useGetImportedSecretsAllEnvs({ + projectId: workspaceId, + path: secretPath, + environments: (currentWorkspace.environments || []).map(({ slug }) => slug) + }); + + const compareEnvironments = selectedEnvironments.length + ? selectedEnvironments + : currentWorkspace.environments; + + const isFilteredByResources = Object.values(filter).some(Boolean); + const { isPending: isOverviewLoading, data: overview } = useGetProjectSecretsOverview( + { + projectId: workspaceId, + environments: compareEnvironments.map((env) => env.slug), + secretPath, + orderDirection, + orderBy, + includeFolders: isFilteredByResources ? filter.folder : true, + includeDynamicSecrets: isFilteredByResources ? filter.dynamic : true, + includeSecrets: isFilteredByResources ? filter.secret : true, + includeImports: true, + includeSecretRotations: isFilteredByResources ? filter.rotation : true, + search: debouncedSearchFilter, + limit, + offset + }, + { enabled: Boolean(compareEnvironments.length) } + ); + + const { + secrets, + folders, + dynamicSecrets, + secretRotations, + totalFolderCount, + totalSecretCount, + totalDynamicSecretCount, + totalSecretRotationCount, + totalCount = 0, + totalUniqueFoldersInPage, + totalUniqueSecretsInPage, + totalUniqueSecretImportsInPage, + totalUniqueDynamicSecretsInPage, + totalUniqueSecretRotationsInPage + } = overview ?? {}; + + const secretImportsShaped = secretImports + ?.flatMap(({ data }) => data) + .filter(Boolean) + .flatMap((item) => item?.secrets || []); + + const handleIsImportedSecretPresentInEnv = (envSlug: string, secretName: string) => { + if (secrets?.some((s) => s.key === secretName && s.env === envSlug)) { + return false; + } + if (secretImportsShaped.some((s) => s.key === secretName && s.sourceEnv === envSlug)) { + return true; + } + return isImportedSecretPresentInEnv(envSlug, secretName); + }; + + useResetPageHelper({ + totalCount, + offset, + setPage + }); + + const { folderNamesAndDescriptions, isFolderPresentInEnv } = useFolderOverview(folders); + + const { dynamicSecretNames, isDynamicSecretPresentInEnv } = + useDynamicSecretOverview(dynamicSecrets); + + const { secretRotationNames, isSecretRotationPresentInEnv, getSecretRotationByName } = + useSecretRotationOverview(secretRotations); + + const { secKeys, getEnvSecretKeyCount } = useSecretOverview( + secrets?.concat(secretImportsShaped) || [] + ); + + const getSecretByKey = useCallback( + (env: string, key: string) => { + const sec = secrets?.find((s) => s.env === env && s.key === key); + return sec; + }, + [secrets] + ); + + const [tableWidth, setTableWidth] = useState(0); + const tableRef = useRef(null); + + const { handleMouseDown, isResizing, colWidth } = useResizableColWidth({ + initialWidth: 320, + minWidth: 160, + maxWidth: tableRef.current + ? tableRef.current.clientWidth - COL_WIDTH_OFFSET // ensure value column can't collapse completely + : 800, + ref: tableRef + }); + + const handleToggleRowType = useCallback( + (rowType: RowType) => + setFilter((state) => { + return { + ...state, + [rowType]: !state[rowType] + }; + }), + [] + ); + + const isTableEmpty = totalCount === 0; + + const isTableFiltered = isFilteredByResources; + + useEffect(() => { + const element = tableRef.current; + if (!element) return; + + const handleResize = () => { + setTableWidth(element.clientWidth - 1); + }; + + const resizeObserver = new ResizeObserver(handleResize); + resizeObserver.observe(element); + + // eslint-disable-next-line consistent-return + return () => { + resizeObserver.disconnect(); + }; + }, [tableRef]); + + return ( + // scott: this is reverse to fix z-indexing bug of dropdown with sticky table cols; couldn't resolve with flex-col +

+ {!isOverviewLoading && totalCount > 0 && ( + + } + className="rounded-b-lg border border-solid border-mineshaft-500 bg-mineshaft-700" + count={totalCount} + page={page} + perPage={perPage} + onChangePage={(newPage) => setPage(newPage)} + onChangePerPage={handlePerPageChange} + /> + )} +
+ + {/* eslint-disable-next-line no-nested-ternary */} + {isOverviewLoading ? ( +
+ +
+ ) : isTableEmpty ? ( + + ) : ( + + + + + {compareEnvironments?.map(({ name, slug }, index) => { + const envSecKeyCount = getEnvSecretKeyCount(slug); + const importedSecKeyCount = getEnvImportedSecretKeyCount(slug); + const missingKeyCount = secKeys.length - envSecKeyCount - importedSecKeyCount; + + return ( + + ); + })} + + + + {folderNamesAndDescriptions.map(({ name: folderName }, index) => ( + + ))} + {dynamicSecretNames.map((dynamicSecretName, index) => ( + + ))} + {secretRotationNames.map((secretRotationName, index) => ( + + ))} + {secKeys.map((key, index) => ( + + ))} + totalCount ? totalCount % perPage : perPage) - + (totalUniqueFoldersInPage || 0) - + (totalUniqueDynamicSecretsInPage || 0) - + (totalUniqueSecretsInPage || 0) - + (totalUniqueSecretImportsInPage || 0) - + (totalUniqueSecretRotationsInPage || 0), + 0 + )} + /> + +
+
+
+
+
+
+
+ Name + + setOrderDirection((prev) => + prev === OrderByDirection.ASC + ? OrderByDirection.DESC + : OrderByDirection.ASC + ) + } + > + + +
+
+
+
+ {name} + {missingKeyCount > 0 && ( + + {missingKeyCount} secret{missingKeyCount > 1 ? "s" : ""} missing + compared to other environments on this page + + } + > + + + {missingKeyCount} + + + )} +
+
+ )} +
+
+
+ setSearchFilter(e.target.value)} + className="h-full flex-1" + placeholder="Search by resource name..." + leftIcon={} + containerClassName="h-10" + /> + {isTableFiltered && ( + + )} + {compareEnvironments.length > 0 && ( + + + + + + Filter by Resource + { + e.preventDefault(); + handleToggleRowType(RowType.Folder); + }} + icon={filter[RowType.Folder] && } + iconPos="right" + > +
+ + Folders +
+
+ { + e.preventDefault(); + handleToggleRowType(RowType.DynamicSecret); + }} + icon={filter[RowType.DynamicSecret] && } + iconPos="right" + > +
+ + Dynamic Secrets +
+
+ { + e.preventDefault(); + handleToggleRowType(RowType.SecretRotation); + }} + icon={filter[RowType.SecretRotation] && } + iconPos="right" + > +
+ + Secret Rotations +
+
+ { + e.preventDefault(); + handleToggleRowType(RowType.Secret); + }} + icon={filter[RowType.Secret] && } + iconPos="right" + > +
+ + Secrets +
+
+
+
+ )} +
+
+ + { + const selected = value as MultiValue; + + setSelectedEnvironments((selected as WorkspaceEnv[]) ?? []); + }} + placeholder="Leave blank to compare all environments" + options={currentWorkspace.environments} + getOptionValue={(option) => option.slug} + getOptionLabel={(option) => option.name} + isMulti + /> +
+
+ ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/DynamicSecretRow/DynamicSecretRow.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/DynamicSecretRow/DynamicSecretRow.tsx new file mode 100644 index 000000000..16de6533b --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/DynamicSecretRow/DynamicSecretRow.tsx @@ -0,0 +1,41 @@ +import { faFingerprint } from "@fortawesome/free-solid-svg-icons"; + +import { Tr } from "@app/components/v2"; + +import { EnvironmentStatusCell, ResourceNameCell } from "../shared"; + +type Props = { + dynamicSecretName: string; + environments: { name: string; slug: string }[]; + isDynamicSecretInEnv: (name: string, env: string) => boolean; + colWidth: number; +}; + +export const DynamicSecretRow = ({ + dynamicSecretName, + environments = [], + isDynamicSecretInEnv, + colWidth +}: Props) => { + return ( + + + {environments.map(({ slug }, i) => { + const isPresent = isDynamicSecretInEnv(dynamicSecretName, slug); + + return ( + + ); + })} + + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/DynamicSecretRow/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/DynamicSecretRow/index.tsx new file mode 100644 index 000000000..5c7bf445a --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/DynamicSecretRow/index.tsx @@ -0,0 +1 @@ +export { DynamicSecretRow } from "./DynamicSecretRow"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/FolderRow/FolderRow.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/FolderRow/FolderRow.tsx new file mode 100644 index 000000000..a3d672e13 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/FolderRow/FolderRow.tsx @@ -0,0 +1,41 @@ +import { faFolder } from "@fortawesome/free-solid-svg-icons"; + +import { Tr } from "@app/components/v2"; + +import { EnvironmentStatusCell, ResourceNameCell } from "../shared"; + +type Props = { + folderName: string; + environments: { name: string; slug: string }[]; + isFolderPresentInEnv: (name: string, env: string) => boolean; + colWidth: number; +}; + +export const FolderRow = ({ + folderName, + environments = [], + isFolderPresentInEnv, + colWidth +}: Props) => { + return ( + + + {environments.map(({ slug }, i) => { + const isPresent = isFolderPresentInEnv(folderName, slug); + + return ( + + ); + })} + + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/FolderRow/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/FolderRow/index.tsx new file mode 100644 index 000000000..171b2e596 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/FolderRow/index.tsx @@ -0,0 +1 @@ +export { FolderRow } from "./FolderRow"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRotationRow/SecretRotationRow.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRotationRow/SecretRotationRow.tsx new file mode 100644 index 000000000..d5c938e9b --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRotationRow/SecretRotationRow.tsx @@ -0,0 +1,179 @@ +import { faEye, faEyeSlash, faInfoCircle, faRotate } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { twMerge } from "tailwind-merge"; + +import { IconButton, TableContainer, Tag, Td, Tooltip, Tr } from "@app/components/v2"; +import { Blur } from "@app/components/v2/Blur"; +import { InfisicalSecretInput } from "@app/components/v2/InfisicalSecretInput"; +import { SECRET_ROTATION_MAP } from "@app/helpers/secretRotationsV2"; +import { useToggle } from "@app/hooks"; +import { TSecretRotationV2 } from "@app/hooks/api/secretRotationsV2"; + +import { EnvironmentStatusCell, ResourceNameCell } from "../shared"; + +type Props = { + secretRotationName: string; + environments: { name: string; slug: string }[]; + isSecretRotationInEnv: (name: string, env: string) => boolean; + getSecretRotationByName: (slug: string, name: string) => TSecretRotationV2 | undefined; + colWidth: number; + tableWidth: number; +}; + +export const SecretRotationRow = ({ + secretRotationName, + environments = [], + isSecretRotationInEnv, + colWidth, + getSecretRotationByName, + tableWidth +}: Props) => { + const [isExpanded, setIsExpanded] = useToggle(false); + const [isSecretVisible, setIsSecretVisible] = useToggle(); + + const totalCols = environments.length + 1; // secret key row + + return ( + <> + + + {environments.map(({ slug }, i) => { + const isPresent = isSecretRotationInEnv(secretRotationName, slug); + + return ( + + ); + })} + + {isExpanded && + environments.map(({ name: envName, slug }) => { + const secretRotation = getSecretRotationByName(slug, secretRotationName); + + if (!secretRotation) return null; + + const { type, secrets, description } = secretRotation; + + const { name: rotationType, image } = SECRET_ROTATION_MAP[type]; + + return ( + + +
+
+
+
+ {envName} + + {`${rotationType} + {rotationType} + + {description && ( + + + + )} +
+
+ + setIsSecretVisible.toggle()} + > + + + +
+ + + + {secrets.map((secret, index) => { + return ( + + + + + + + ); + })} + +
+
+ + {secret?.key ?? "********"} + +
+
+ {/* eslint-disable-next-line no-nested-ternary */} + {!secret ? ( +
********
+ ) : secret.secretValueHidden ? ( + + ) : ( + {}} + /> + )} +
+
+
+ + + ); + })} + + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRotationRow/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRotationRow/index.tsx new file mode 100644 index 000000000..a0b2fcfa7 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRotationRow/index.tsx @@ -0,0 +1 @@ +export { SecretRotationRow } from "./SecretRotationRow"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/EnvironmentSecretRow.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/EnvironmentSecretRow.tsx new file mode 100644 index 000000000..87db191f6 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/EnvironmentSecretRow.tsx @@ -0,0 +1,49 @@ +import { faEyeSlash } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; + +import { Tooltip } from "@app/components/v2"; +import { InfisicalSecretInput } from "@app/components/v2/InfisicalSecretInput"; + +type Props = { + defaultValue?: string | null; + isOverride?: boolean; + isVisible?: boolean; + isImportedSecret: boolean; + environment: string; + secretValueHidden: boolean; + secretPath: string; +}; + +export const EnvironmentSecretRow = ({ + defaultValue, + isOverride, + isImportedSecret, + secretValueHidden, + environment, + secretPath, + isVisible +}: Props) => { + return ( +
+ {secretValueHidden && !isOverride && ( + + + + )} +
+ {}} + isReadOnly + value={defaultValue as string} + key="secret-input" + isVisible={isVisible && !secretValueHidden} + secretPath={secretPath} + environment={environment} + isImport={isImportedSecret} + defaultValue={secretValueHidden ? "" : undefined} + canEditButNotView={secretValueHidden && !isOverride} + /> +
+
+ ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/SecretNoAccessRow.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/SecretNoAccessRow.tsx new file mode 100644 index 000000000..075726d1b --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/SecretNoAccessRow.tsx @@ -0,0 +1,44 @@ +import { faLock } from "@fortawesome/free-solid-svg-icons"; + +import { Tr } from "@app/components/v2"; +import { Blur } from "@app/components/v2/Blur"; + +import { EnvironmentStatusCell, ResourceNameCell } from "../shared"; + +type Props = { + environments: { name: string; slug: string }[]; + count: number; + colWidth: number; +}; + +export const SecretNoAccessRow = ({ environments = [], count, colWidth }: Props) => { + return ( + <> + {Array.from(Array(count)).map((_, j) => ( + + } + iconClassName="text-bunker-400" + icon={faLock} + colWidth={colWidth} + tooltipContent="You do not have permission to view this secret" + /> + {environments.map(({ slug }, i) => { + return ( + + ); + })} + + ))} + + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/SecretRow.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/SecretRow.tsx new file mode 100644 index 000000000..095b50356 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/SecretRow.tsx @@ -0,0 +1,231 @@ +import { subject } from "@casl/ability"; +import { + faCodeBranch, + faEye, + faEyeSlash, + faFileImport, + faKey, + faRotate +} from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; + +import { IconButton, TableContainer, Td, Tooltip, Tr } from "@app/components/v2"; +import { useProjectPermission } from "@app/context"; +import { + ProjectPermissionSecretActions, + ProjectPermissionSub +} from "@app/context/ProjectPermissionContext/types"; +import { useToggle } from "@app/hooks"; +import { SecretV3RawSanitized } from "@app/hooks/api/secrets/types"; +import { WorkspaceEnv } from "@app/hooks/api/types"; +import { HIDDEN_SECRET_VALUE } from "@app/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretItem"; + +import { EnvironmentStatus, EnvironmentStatusCell, ResourceNameCell } from "../shared"; +import { EnvironmentSecretRow } from "./EnvironmentSecretRow"; + +type Props = { + secretKey: string; + secretPath: string; + environments: { name: string; slug: string }[]; + getSecretByKey: (slug: string, key: string) => SecretV3RawSanitized | undefined; + isImportedSecretPresentInEnv: (env: string, secretName: string) => boolean; + getImportedSecretByKey: ( + env: string, + secretName: string + ) => { secret?: SecretV3RawSanitized; environmentInfo?: WorkspaceEnv } | undefined; + colWidth: number; + tableWidth: number; +}; + +export const SecretRow = ({ + secretKey, + environments = [], + secretPath, + getSecretByKey, + isImportedSecretPresentInEnv, + getImportedSecretByKey, + colWidth, + tableWidth +}: Props) => { + const [isFormExpanded, setIsFormExpanded] = useToggle(); + const totalCols = environments.length + 1; // secret key row + const [isSecretVisible, setIsSecretVisible] = useToggle(); + + const { permission } = useProjectPermission(); + + const getDefaultValue = ( + secret: SecretV3RawSanitized | undefined, + importedSecret: { secret?: SecretV3RawSanitized } | undefined + ) => { + const canEditSecretValue = permission.can( + ProjectPermissionSecretActions.Edit, + subject(ProjectPermissionSub.Secrets, { + environment: secret?.env || "", + secretPath: secret?.path || "", + secretName: secret?.key || "", + secretTags: ["*"] + }) + ); + + if (secret?.secretValueHidden && !secret?.valueOverride) { + return canEditSecretValue ? HIDDEN_SECRET_VALUE : ""; + } + return secret?.valueOverride || secret?.value || importedSecret?.secret?.value || ""; + }; + + return ( + <> + setIsFormExpanded.toggle()} + className="group border-mineshaft-500" + > + + {environments.map(({ slug }, i) => { + const secret = getSecretByKey(slug, secretKey); + + const isSecretImported = isImportedSecretPresentInEnv(slug, secretKey); + + const isSecretPresent = Boolean(secret); + const isSecretEmpty = secret?.value === ""; + + let status: EnvironmentStatus; + + if (isSecretEmpty) { + status = "empty"; + } else if (isSecretPresent) { + status = "present"; + } else if (isSecretImported) { + status = "imported"; + } else { + status = "missing"; + } + + return ( + + ); + })} + + {isFormExpanded && ( + + +
+ + + + + + +
+ + setIsSecretVisible.toggle()} + > + + + +
+ + + + {environments.map(({ name, slug }) => { + const secret = getSecretByKey(slug, secretKey); + + const isImportedSecret = isImportedSecretPresentInEnv(slug, secretKey); + const importedSecret = getImportedSecretByKey(slug, secretKey); + + return ( + + + + + ); + })} + +
+ Environment + + Value +
+
+ {name} + {isImportedSecret && ( + + + + )} + {secret?.isRotatedSecret && ( + + + + )} + {secret?.valueOverride && ( + + + + )} +
+
+ +
+
+
+ + + )} + + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/index.tsx new file mode 100644 index 000000000..a1e4a3d51 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/SecretRow/index.tsx @@ -0,0 +1,2 @@ +export { SecretNoAccessRow } from "./SecretNoAccessRow"; +export { SecretRow } from "./SecretRow"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/EnvironmentStatusCell.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/EnvironmentStatusCell.tsx new file mode 100644 index 000000000..fa5d2f8bb --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/EnvironmentStatusCell.tsx @@ -0,0 +1,75 @@ +import { IconDefinition } from "@fortawesome/free-brands-svg-icons"; +import { faCircle } from "@fortawesome/free-regular-svg-icons"; +import { faBan, faCheck, faFileImport, faXmark } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { twMerge } from "tailwind-merge"; + +import { Td, Tooltip } from "@app/components/v2"; + +export type EnvironmentStatus = "present" | "missing" | "empty" | "imported" | "no-access"; + +type Props = { + isLast: boolean; + status: EnvironmentStatus; +}; + +export const EnvironmentStatusCell = ({ isLast, status }: Props) => { + let tooltipContent: string; + let icon: IconDefinition; + let iconClassName: string; + + switch (status) { + case "present": + tooltipContent = "Present in environment"; + icon = faCheck; + iconClassName = "h-3 w-3"; + break; + case "missing": + tooltipContent = "Missing from environment"; + icon = faXmark; + iconClassName = "h-3.5 w-3.5"; + break; + case "empty": + tooltipContent = "Empty value in environment"; + icon = faCircle; + iconClassName = "h-3 w-3"; + break; + case "imported": + tooltipContent = "Imported into environment"; + icon = faFileImport; + iconClassName = "h-3 w-3"; + break; + case "no-access": + tooltipContent = "You do not have permission to view this secret"; + icon = faBan; + iconClassName = "h-3 w-3"; + break; + default: + throw new Error(`Unhandled environment status: ${status as string}`); + } + + return ( + +
+
+ + + +
+
+ + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/ResourceNameCell.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/ResourceNameCell.tsx new file mode 100644 index 000000000..079b563d5 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/ResourceNameCell.tsx @@ -0,0 +1,47 @@ +import { ReactElement } from "react"; +import { IconDefinition } from "@fortawesome/free-brands-svg-icons"; +import { faAngleDown } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; + +import { Td, Tooltip } from "@app/components/v2"; + +type Props = { + isRowExpanded?: boolean; + label: ReactElement | string; + icon: IconDefinition; + iconClassName?: string; + colWidth: number; + tooltipContent?: string; +}; + +export const ResourceNameCell = ({ + isRowExpanded, + label, + icon, + iconClassName, + colWidth, + tooltipContent +}: Props) => { + return ( + + +
+
+ +
+ {typeof label === "string" ? {label} : label} +
+
+ + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/index.ts b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/index.ts new file mode 100644 index 000000000..c8bd53cbe --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/components/shared/index.ts @@ -0,0 +1,2 @@ +export * from "./EnvironmentStatusCell"; +export * from "./ResourceNameCell"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/index.tsx new file mode 100644 index 000000000..f5c997972 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/CompareEnvironments/index.tsx @@ -0,0 +1 @@ +export * from "./CompareEnvironments"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/EnvironmentTabs/EnvironmentTabs.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/EnvironmentTabs/EnvironmentTabs.tsx new file mode 100644 index 000000000..66fd3a878 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/EnvironmentTabs/EnvironmentTabs.tsx @@ -0,0 +1,242 @@ +import { useState } from "react"; +import { faArrowRightArrowLeft, faEllipsisH, faPlus } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { useQueryClient } from "@tanstack/react-query"; +import { useNavigate, useParams } from "@tanstack/react-router"; + +import { UpgradePlanModal } from "@app/components/license/UpgradePlanModal"; +import { ProjectPermissionCan } from "@app/components/permissions"; +import { + Button, + DropdownMenu, + DropdownMenuContent, + DropdownMenuItem, + DropdownMenuLabel, + DropdownMenuTrigger, + Modal, + ModalContent, + Tab, + TabList, + Tabs, + Tooltip +} from "@app/components/v2"; +import { ROUTE_PATHS } from "@app/const/routes"; +import { + ProjectPermissionActions, + ProjectPermissionSub, + useSubscription, + useWorkspace +} from "@app/context"; +import { usePopUp } from "@app/hooks"; +import { workspaceKeys } from "@app/hooks/api"; +import { WorkspaceEnv } from "@app/hooks/api/workspace/types"; +import { AddEnvironmentModal } from "@app/pages/secret-manager/SettingsPage/components/EnvironmentSection/AddEnvironmentModal"; + +import { CompareEnvironments } from "../CompareEnvironments"; + +const COMPARE_ENVIRONMENT_TAB = "__COMPARE_ENVIRONMENT_TAB__"; +const ADD_ENVIRONMENT_TAB = "__ADD_ENVIRONMENT_TAB__"; +const VIEW_MORE_ENVIRONMENT_TAB = "__VIEW_MORE_ENVIRONMENT_TAB__"; + +type Props = { + secretPath: string; +}; + +const TABS_TO_SHOW = 5; + +export const EnvironmentTabs = ({ secretPath }: Props) => { + const { currentWorkspace } = useWorkspace(); + const currentEnv = useParams({ + from: ROUTE_PATHS.SecretManager.SecretDashboardPage.id, + select: (el) => el.envSlug + }); + + const { subscription } = useSubscription(); + + const isMoreEnvironmentsAllowed = + subscription?.environmentLimit && currentWorkspace?.environments + ? currentWorkspace.environments.length < subscription.environmentLimit + : true; + + const [isNavigating, setIsNavigating] = useState(false); + + const navigate = useNavigate(); + + const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp([ + "compareEnvironments", + "createEnvironment", + "upgradePlan" + ] as const); + + const selectedIndex = currentWorkspace.environments.findIndex((env) => env.slug === currentEnv); + + let tabEnvironments: WorkspaceEnv[]; + let dropdownEnvironments: WorkspaceEnv[]; + + if (selectedIndex < TABS_TO_SHOW) { + tabEnvironments = currentWorkspace.environments.slice(0, TABS_TO_SHOW); + dropdownEnvironments = currentWorkspace.environments.slice(TABS_TO_SHOW); + } else { + tabEnvironments = [ + ...currentWorkspace.environments.slice(0, TABS_TO_SHOW - 1), + currentWorkspace.environments[selectedIndex] + ]; + dropdownEnvironments = currentWorkspace.environments + .slice(TABS_TO_SHOW - 1) + .filter((env) => env.slug !== currentEnv); + } + + const queryClient = useQueryClient(); + + const handleSelect = async (envSlug: string) => { + if (isNavigating) return; + + setIsNavigating(true); + await navigate({ + to: ROUTE_PATHS.SecretManager.SecretDashboardPage.path, + params: { + envSlug, + projectId: currentWorkspace.id + }, + search: (prev) => prev + }); + setIsNavigating(false); + }; + + const handleAddEnvironment = () => { + if (isMoreEnvironmentsAllowed) { + handlePopUpOpen("createEnvironment"); + } else { + handlePopUpOpen("upgradePlan"); + } + }; + + return ( + <> + { + if (value === COMPARE_ENVIRONMENT_TAB) { + handlePopUpOpen("compareEnvironments"); + return; + } + + if (value === ADD_ENVIRONMENT_TAB) { + handleAddEnvironment(); + return; + } + + handleSelect(value); + }} + defaultValue="environment-tabs" + > + + {tabEnvironments.map((environment) => ( + +

{environment.name}

+
+ ))} + {dropdownEnvironments.length ? ( + + + + +
+ +
+
+
+
+ + Environments +
+ {dropdownEnvironments.map((environment) => ( + { + e.stopPropagation(); + handleSelect(environment.slug); + }} + > + {environment.name} + + ))} +
+
+ + {(isAllowed) => ( + + + + )} + + + + ) : ( + + +
+ +
+
+
+ )} + {currentWorkspace.environments.length > 1 && ( + +
+ + Compare Environments +
+
+ )} + + + handlePopUpToggle("compareEnvironments", isOpen)} + > + + + + + handlePopUpToggle("upgradePlan", isOpen)} + text="You can add custom environments if you switch to Infisical's Team plan." + /> + handlePopUpToggle("createEnvironment", isOpen)} + onComplete={async (env) => { + await queryClient.refetchQueries({ + queryKey: workspaceKeys.getWorkspaceById(currentWorkspace.id) + }); + handleSelect(env.slug); + }} + /> + + ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/EnvironmentTabs/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/EnvironmentTabs/index.tsx new file mode 100644 index 000000000..76be6609b --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/EnvironmentTabs/index.tsx @@ -0,0 +1 @@ +export * from "./EnvironmentTabs"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderBreadCrumbs/FolderBreadCrumbs.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderBreadCrumbs/FolderBreadCrumbs.tsx new file mode 100644 index 000000000..a2169fa5a --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderBreadCrumbs/FolderBreadCrumbs.tsx @@ -0,0 +1,52 @@ +import { faFolderOpen } from "@fortawesome/free-solid-svg-icons"; +import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; +import { useNavigate } from "@tanstack/react-router"; + +type Props = { + secretPath: string; +}; + +export const FolderBreadCrumbs = ({ secretPath = "/" }: Props) => { + const navigate = useNavigate({ + from: "/projects/secret-management/$projectId/secrets/$envSlug" + }); + + const onFolderCrumbClick = (index: number) => { + const newSecPath = `/${secretPath.split("/").filter(Boolean).slice(0, index).join("/")}`; + if (secretPath === newSecPath) return; + navigate({ + search: (prev) => ({ ...prev, secretPath: newSecPath }) + }); + }; + + return ( +
+
onFolderCrumbClick(0)} + onKeyDown={() => null} + role="button" + tabIndex={0} + > + +
+ {(secretPath || "") + .split("/") + .filter(Boolean) + .map((path, index, arr) => ( +
onFolderCrumbClick(index + 1)} + onKeyDown={() => null} + role="button" + tabIndex={0} + > + {path} +
+ ))} +
+ ); +}; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderBreadCrumbs/index.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderBreadCrumbs/index.tsx new file mode 100644 index 000000000..8224cdb25 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderBreadCrumbs/index.tsx @@ -0,0 +1 @@ +export { FolderBreadCrumbs } from "./FolderBreadCrumbs"; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderListView/FolderListView.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderListView/FolderListView.tsx index 9b8c9ccaa..fd65bc639 100644 --- a/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderListView/FolderListView.tsx +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/FolderListView/FolderListView.tsx @@ -36,6 +36,7 @@ type Props = { workspaceId: string; secretPath?: string; onNavigateToFolder: (path: string) => void; + canNavigate: boolean; }; export const FolderListView = ({ @@ -43,7 +44,8 @@ export const FolderListView = ({ environment, workspaceId, secretPath = "/", - onNavigateToFolder + onNavigateToFolder, + canNavigate }: Props) => { const { popUp, handlePopUpToggle, handlePopUpOpen, handlePopUpClose } = usePopUp([ "updateFolder", @@ -190,7 +192,7 @@ export const FolderListView = ({ }; const handleFolderClick = (name: string, isPending?: boolean) => { - if (isPending) { + if (isPending || !canNavigate) { return; } const path = `${secretPathQueryparam === "/" ? "" : secretPathQueryparam}/${name}`; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretItem.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretItem.tsx index 77bec882c..2a4f54c82 100644 --- a/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretItem.tsx +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretItem.tsx @@ -56,7 +56,7 @@ import { import { CollapsibleSecretImports } from "./CollapsibleSecretImports"; import { useBatchModeActions } from "../../SecretMainPage.store"; -export const HIDDEN_SECRET_VALUE = "******"; +export const HIDDEN_SECRET_VALUE = "*****************************"; export const HIDDEN_SECRET_VALUE_API_MASK = ""; type Props = { diff --git a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncAuditLogsSection.tsx b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncAuditLogsSection.tsx index ddb618708..58c00db6f 100644 --- a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncAuditLogsSection.tsx +++ b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncAuditLogsSection.tsx @@ -2,7 +2,7 @@ import { faFingerprint } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { Link } from "@tanstack/react-router"; -import { useSubscription } from "@app/context"; +import { useSubscription, useWorkspace } from "@app/context"; import { EventType } from "@app/hooks/api/auditLogs/enums"; import { TSecretSync } from "@app/hooks/api/secretSyncs"; import { LogsSection } from "@app/pages/organization/AuditLogsPage/components/LogsSection"; @@ -19,6 +19,7 @@ type Props = { export const SecretSyncAuditLogsSection = ({ secretSync }: Props) => { const { subscription } = useSubscription(); + const { currentWorkspace } = useWorkspace(); const auditLogsRetentionDays = subscription?.auditLogsRetentionDays ?? 30; @@ -36,6 +37,7 @@ export const SecretSyncAuditLogsSection = ({ secretSync }: Props) => { ; - handlePopUpClose: (popUpName: keyof UsePopUpState<["createEnv"]>) => void; - handlePopUpToggle: (popUpName: keyof UsePopUpState<["createEnv"]>, state?: boolean) => void; + isOpen: boolean; + onOpenChange: (isOpen: boolean) => void; + onComplete?: (environment: WorkspaceEnv) => void; }; const schema = z.object({ @@ -24,10 +24,14 @@ const schema = z.object({ export type FormData = z.infer; -export const AddEnvironmentModal = ({ popUp, handlePopUpClose, handlePopUpToggle }: Props) => { +type ContentProps = { + onComplete: (environment: WorkspaceEnv) => void; +}; + +const Content = ({ onComplete }: ContentProps) => { const { currentWorkspace } = useWorkspace(); const { mutateAsync, isPending } = useCreateWsEnvironment(); - const { control, handleSubmit, reset } = useForm({ + const { control, handleSubmit } = useForm({ resolver: zodResolver(schema) }); @@ -35,7 +39,7 @@ export const AddEnvironmentModal = ({ popUp, handlePopUpClose, handlePopUpToggle try { if (!currentWorkspace?.id) return; - await mutateAsync({ + const env = await mutateAsync({ workspaceId: currentWorkspace.id, name: environmentName, slug: environmentSlug @@ -46,7 +50,7 @@ export const AddEnvironmentModal = ({ popUp, handlePopUpClose, handlePopUpToggle type: "success" }); - handlePopUpClose("createEnv"); + onComplete(env); } catch (err) { console.error(err); createNotification({ @@ -57,64 +61,62 @@ export const AddEnvironmentModal = ({ popUp, handlePopUpClose, handlePopUpToggle }; return ( - { - handlePopUpToggle("createEnv", isOpen); - reset(); - }} - > - - - ( - - - - )} - /> - ( - - - - )} - /> -
- + + ( + + + + )} + /> + ( + + + + )} + /> +
+ + + + +
+ + ); +}; - -
- +export const AddEnvironmentModal = ({ onComplete, ...props }: Props) => { + return ( + + + { + if (onComplete) onComplete(env); + props.onOpenChange(false); + }} + /> ); diff --git a/frontend/src/pages/secret-manager/SettingsPage/components/EnvironmentSection/EnvironmentSection.tsx b/frontend/src/pages/secret-manager/SettingsPage/components/EnvironmentSection/EnvironmentSection.tsx index 323fe2640..34acf0c7b 100644 --- a/frontend/src/pages/secret-manager/SettingsPage/components/EnvironmentSection/EnvironmentSection.tsx +++ b/frontend/src/pages/secret-manager/SettingsPage/components/EnvironmentSection/EnvironmentSection.tsx @@ -103,9 +103,8 @@ export const EnvironmentSection = () => { )} handlePopUpToggle("createEnv", isOpen)} />