mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 11:27:47 +00:00
feat(infisical-pg): resolved import secret breaking cli backward compatiability
This commit is contained in:
@@ -250,7 +250,8 @@ export const registerSecretImportRouter = async (server: FastifyZodProvider) =>
|
|||||||
secrets: z
|
secrets: z
|
||||||
.object({
|
.object({
|
||||||
secretPath: z.string(),
|
secretPath: z.string(),
|
||||||
environment: z.object({
|
environment: z.string(),
|
||||||
|
environmentInfo: z.object({
|
||||||
id: z.string(),
|
id: z.string(),
|
||||||
name: z.string(),
|
name: z.string(),
|
||||||
slug: z.string()
|
slug: z.string()
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ import {
|
|||||||
SecretsSchema,
|
SecretsSchema,
|
||||||
SecretTagsSchema,
|
SecretTagsSchema,
|
||||||
SecretType,
|
SecretType,
|
||||||
ServiceTokenScopes,
|
ServiceTokenScopes
|
||||||
} from "@app/db/schemas";
|
} from "@app/db/schemas";
|
||||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
import { CommitType } from "@app/ee/services/secret-approval-request/secret-approval-request-types";
|
import { CommitType } from "@app/ee/services/secret-approval-request/secret-approval-request-types";
|
||||||
@@ -36,11 +36,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
imports: z
|
imports: z
|
||||||
.object({
|
.object({
|
||||||
secretPath: z.string(),
|
secretPath: z.string(),
|
||||||
environment: z.object({
|
environment: z.string(),
|
||||||
id: z.string(),
|
|
||||||
name: z.string(),
|
|
||||||
slug: z.string()
|
|
||||||
}),
|
|
||||||
folderId: z.string().optional(),
|
folderId: z.string().optional(),
|
||||||
secrets: secretRawSchema.array()
|
secrets: secretRawSchema.array()
|
||||||
})
|
})
|
||||||
@@ -57,23 +53,24 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
]),
|
]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
// just for delivery hero usecase
|
// just for delivery hero usecase
|
||||||
let {secretPath,environment,workspaceId} = req.query;
|
let { secretPath, environment, workspaceId } = req.query;
|
||||||
if(req.auth.actor === ActorType.SERVICE){
|
if (req.auth.actor === ActorType.SERVICE) {
|
||||||
const scope = ServiceTokenScopes.parse(req.auth.serviceToken.scopes);
|
const scope = ServiceTokenScopes.parse(req.auth.serviceToken.scopes);
|
||||||
const isSingleScope = scope.length === 1;
|
const isSingleScope = scope.length === 1;
|
||||||
if(isSingleScope && !picomatch.scan(scope[0].secretPath).isGlob){
|
if (isSingleScope && !picomatch.scan(scope[0].secretPath).isGlob) {
|
||||||
secretPath = scope[0].secretPath;
|
secretPath = scope[0].secretPath;
|
||||||
environment = scope[0].environment;
|
environment = scope[0].environment;
|
||||||
workspaceId = req.auth.serviceToken.projectId;
|
workspaceId = req.auth.serviceToken.projectId;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if(!workspaceId || !environment) throw new BadRequestError({message:"Missing workspace id or environment"})
|
if (!workspaceId || !environment)
|
||||||
|
throw new BadRequestError({ message: "Missing workspace id or environment" });
|
||||||
|
|
||||||
const { secrets, imports } = await server.services.secret.getSecretsRaw({
|
const { secrets, imports } = await server.services.secret.getSecretsRaw({
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
environment,
|
environment,
|
||||||
projectId: workspaceId as string,
|
projectId: workspaceId as string,
|
||||||
path: secretPath,
|
path: secretPath,
|
||||||
includeImports: req.query.include_imports
|
includeImports: req.query.include_imports
|
||||||
@@ -360,11 +357,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
imports: z
|
imports: z
|
||||||
.object({
|
.object({
|
||||||
secretPath: z.string(),
|
secretPath: z.string(),
|
||||||
environment: z.object({
|
environment: z.string(),
|
||||||
id: z.string(),
|
|
||||||
name: z.string(),
|
|
||||||
slug: z.string()
|
|
||||||
}),
|
|
||||||
folderId: z.string().optional(),
|
folderId: z.string().optional(),
|
||||||
secrets: SecretsSchema.omit({ secretBlindIndex: true }).array()
|
secrets: SecretsSchema.omit({ secretBlindIndex: true }).array()
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -33,7 +33,8 @@ export const fnSecretsFromImports = async ({
|
|||||||
const importedSecsGroupByFolderId = groupBy(importedSecrets, (i) => i.folderId);
|
const importedSecsGroupByFolderId = groupBy(importedSecrets, (i) => i.folderId);
|
||||||
return allowedImports.map(({ importPath, importEnv }, i) => ({
|
return allowedImports.map(({ importPath, importEnv }, i) => ({
|
||||||
secretPath: importPath,
|
secretPath: importPath,
|
||||||
environment: importEnv,
|
environment: importEnv.slug,
|
||||||
|
environmentInfo: importEnv,
|
||||||
folderId: importedFolders?.[i]?.id,
|
folderId: importedFolders?.[i]?.id,
|
||||||
secrets: importedFolders?.[i]?.id
|
secrets: importedFolders?.[i]?.id
|
||||||
? importedSecsGroupByFolderId[importedFolders?.[i]?.id as string]
|
? importedSecsGroupByFolderId[importedFolders?.[i]?.id as string]
|
||||||
|
|||||||
@@ -585,7 +585,7 @@ export const secretServiceFactory = ({
|
|||||||
return {
|
return {
|
||||||
...importedSecrets[i].secrets[j],
|
...importedSecrets[i].secrets[j],
|
||||||
workspace: projectId,
|
workspace: projectId,
|
||||||
environment: importedSecrets[i].environment.slug
|
environment: importedSecrets[i].environment
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -825,10 +825,7 @@ export const secretServiceFactory = ({
|
|||||||
imports: (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({
|
imports: (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({
|
||||||
...el,
|
...el,
|
||||||
secrets: importedSecrets.map((sec) =>
|
secrets: importedSecrets.map((sec) =>
|
||||||
decryptSecretRaw(
|
decryptSecretRaw({ ...sec, environment: el.environment, workspace: projectId }, botKey)
|
||||||
{ ...sec, environment: el.environment.slug, workspace: projectId },
|
|
||||||
botKey
|
|
||||||
)
|
|
||||||
)
|
)
|
||||||
}))
|
}))
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -118,6 +118,7 @@ export const useGetImportedSecrets = ({
|
|||||||
return data.map((el) => ({
|
return data.map((el) => ({
|
||||||
environment: el.environment,
|
environment: el.environment,
|
||||||
secretPath: el.secretPath,
|
secretPath: el.secretPath,
|
||||||
|
environmentInfo: el.environmentInfo,
|
||||||
folderId: el.folderId,
|
folderId: el.folderId,
|
||||||
secrets: el.secrets.map((encSecret) => {
|
secrets: el.secrets.map((encSecret) => {
|
||||||
const secretKey = decryptSymmetric({
|
const secretKey = decryptSymmetric({
|
||||||
|
|||||||
@@ -13,7 +13,8 @@ export type TSecretImport = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
export type TImportedSecrets = {
|
export type TImportedSecrets = {
|
||||||
environment: WorkspaceEnv;
|
environment: string;
|
||||||
|
environmentInfo: WorkspaceEnv;
|
||||||
secretPath: string;
|
secretPath: string;
|
||||||
folderId: string;
|
folderId: string;
|
||||||
secrets: EncryptedSecret[];
|
secrets: EncryptedSecret[];
|
||||||
|
|||||||
+6
-15
@@ -14,7 +14,6 @@ import { arrayMove, SortableContext, verticalListSortingStrategy } from "@dnd-ki
|
|||||||
|
|
||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
import { DeleteActionModal } from "@app/components/v2";
|
import { DeleteActionModal } from "@app/components/v2";
|
||||||
import { useWorkspace } from "@app/context";
|
|
||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
import { useDeleteSecretImport, useUpdateSecretImport } from "@app/hooks/api";
|
import { useDeleteSecretImport, useUpdateSecretImport } from "@app/hooks/api";
|
||||||
import { TSecretImport } from "@app/hooks/api/secretImports/types";
|
import { TSecretImport } from "@app/hooks/api/secretImports/types";
|
||||||
@@ -25,7 +24,7 @@ import { SecretImportItem } from "./SecretImportItem";
|
|||||||
const SECRET_IN_DASHBOARD = "Present In Dashboard";
|
const SECRET_IN_DASHBOARD = "Present In Dashboard";
|
||||||
|
|
||||||
type TImportedSecrets = Array<{
|
type TImportedSecrets = Array<{
|
||||||
environment: WorkspaceEnv;
|
environmentInfo: WorkspaceEnv;
|
||||||
secretPath: string;
|
secretPath: string;
|
||||||
folderId: string;
|
folderId: string;
|
||||||
secrets: DecryptedSecret[];
|
secrets: DecryptedSecret[];
|
||||||
@@ -35,27 +34,22 @@ export const computeImportedSecretRows = (
|
|||||||
importedSecEnv: string,
|
importedSecEnv: string,
|
||||||
importedSecPath: string,
|
importedSecPath: string,
|
||||||
importSecrets: TImportedSecrets = [],
|
importSecrets: TImportedSecrets = [],
|
||||||
secrets: DecryptedSecret[] = [],
|
secrets: DecryptedSecret[] = []
|
||||||
environments: { name: string; slug: string }[] = []
|
|
||||||
) => {
|
) => {
|
||||||
const importedSecIndex = importSecrets.findIndex(
|
const importedSecIndex = importSecrets.findIndex(
|
||||||
({ secretPath, environment }) =>
|
({ secretPath, environmentInfo }) =>
|
||||||
secretPath === importedSecPath && importedSecEnv === environment.slug
|
secretPath === importedSecPath && importedSecEnv === environmentInfo.slug
|
||||||
);
|
);
|
||||||
if (importedSecIndex === -1) return [];
|
if (importedSecIndex === -1) return [];
|
||||||
|
|
||||||
const importedSec = importSecrets[importedSecIndex];
|
const importedSec = importSecrets[importedSecIndex];
|
||||||
|
|
||||||
const overridenSec: Record<string, { env: string; secretPath: string }> = {};
|
const overridenSec: Record<string, { env: string; secretPath: string }> = {};
|
||||||
const envSlug2Name: Record<string, string> = {};
|
|
||||||
environments.forEach((el) => {
|
|
||||||
envSlug2Name[el.slug] = el.name;
|
|
||||||
});
|
|
||||||
|
|
||||||
for (let i = importedSecIndex + 1; i < importSecrets.length; i += 1) {
|
for (let i = importedSecIndex + 1; i < importSecrets.length; i += 1) {
|
||||||
importSecrets[i].secrets.forEach((el) => {
|
importSecrets[i].secrets.forEach((el) => {
|
||||||
overridenSec[el.key] = {
|
overridenSec[el.key] = {
|
||||||
env: envSlug2Name?.[importSecrets[i].environment.slug] || "unknown",
|
env: importSecrets[i].environmentInfo.name,
|
||||||
secretPath: importSecrets[i].secretPath
|
secretPath: importSecrets[i].secretPath
|
||||||
};
|
};
|
||||||
});
|
});
|
||||||
@@ -96,9 +90,7 @@ export const SecretImportListView = ({
|
|||||||
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
||||||
"deleteSecretImport"
|
"deleteSecretImport"
|
||||||
] as const);
|
] as const);
|
||||||
const { currentWorkspace } = useWorkspace();
|
|
||||||
const { createNotification } = useNotificationContext();
|
const { createNotification } = useNotificationContext();
|
||||||
const environments = currentWorkspace?.environments || [];
|
|
||||||
const sensors = useSensors(
|
const sensors = useSensors(
|
||||||
useSensor(MouseSensor, {}),
|
useSensor(MouseSensor, {}),
|
||||||
useSensor(TouchSensor, {}),
|
useSensor(TouchSensor, {}),
|
||||||
@@ -179,8 +171,7 @@ export const SecretImportListView = ({
|
|||||||
importEnv.slug,
|
importEnv.slug,
|
||||||
importPath,
|
importPath,
|
||||||
importedSecrets,
|
importedSecrets,
|
||||||
secrets,
|
secrets
|
||||||
environments
|
|
||||||
)}
|
)}
|
||||||
secretPath={secretPath}
|
secretPath={secretPath}
|
||||||
environment={environment}
|
environment={environment}
|
||||||
|
|||||||
Reference in New Issue
Block a user