Draft refactor core secrets fn into reusable factories

This commit is contained in:
Tuan Dang
2024-03-08 09:06:03 -08:00
parent 0b98feea50
commit 8ac7a29893
5 changed files with 177 additions and 143 deletions
@@ -32,7 +32,10 @@ import { TSecretFolderDALFactory } from "@app/services/secret-folder/secret-fold
import { TSecretTagDALFactory } from "@app/services/secret-tag/secret-tag-dal"; import { TSecretTagDALFactory } from "@app/services/secret-tag/secret-tag-dal";
import { TIntegrationDALFactory } from "../integration/integration-dal"; import { TIntegrationDALFactory } from "../integration/integration-dal";
import { createManySecretsRawHelper, updateManySecretsRawHelper } from "../secret/secret-fns"; import {
createManySecretsRawHelper
// updateManySecretsRawHelper
} from "../secret/secret-fns";
import { Integrations, IntegrationSyncBehavior, IntegrationUrls } from "./integration-list"; import { Integrations, IntegrationSyncBehavior, IntegrationUrls } from "./integration-list";
const getSecretKeyValuePair = (secrets: Record<string, { value: string | null; comment?: string } | null>) => const getSecretKeyValuePair = (secrets: Record<string, { value: string | null; comment?: string } | null>) =>
@@ -589,7 +592,6 @@ const syncSecretsAWSSecretManager = async ({
/** /**
* Sync/push [secrets] to Heroku app named [integration.app] * Sync/push [secrets] to Heroku app named [integration.app]
* server.services...
*/ */
const syncSecretsHeroku = async ({ const syncSecretsHeroku = async ({
projectDAL, projectDAL,
@@ -609,7 +611,7 @@ const syncSecretsHeroku = async ({
accessToken accessToken
}: { }: {
projectDAL: TProjectDALFactory; projectDAL: TProjectDALFactory;
integrationDAL: TIntegrationDALFactory; integrationDAL: Pick<TIntegrationDALFactory, "updateById">;
secretDAL: TSecretDALFactory; secretDAL: TSecretDALFactory;
secretVersionDAL: TSecretVersionDALFactory; secretVersionDAL: TSecretVersionDALFactory;
secretBlindIndexDAL: TSecretBlindIndexDALFactory; secretBlindIndexDAL: TSecretBlindIndexDALFactory;
@@ -696,27 +698,27 @@ const syncSecretsHeroku = async ({
}); });
} }
if (Object.keys(secretsToUpdate).length) { // if (Object.keys(secretsToUpdate).length) {
await updateManySecretsRawHelper({ // await updateManySecretsRawHelper({
projectId, // projectId,
environment, // environment,
path: secretPath, // path: secretPath,
secrets: Object.keys(secretsToUpdate).map((key) => ({ // secrets: Object.keys(secretsToUpdate).map((key) => ({
secretName: key, // secretName: key,
secretValue: secretsToUpdate[key], // secretValue: secretsToUpdate[key],
type: SecretType.Shared, // type: SecretType.Shared,
secretComment: "" // secretComment: ""
})), // })),
botKey, // TODO: consider getting botKey inside this fn // botKey, // TODO: consider getting botKey inside this fn
projectDAL, // projectDAL,
secretDAL, // secretDAL,
secretVersionDAL, // secretVersionDAL,
secretBlindIndexDAL, // secretBlindIndexDAL,
secretTagDAL, // secretTagDAL,
secretVersionTagDAL, // secretVersionTagDAL,
folderDAL // folderDAL
}); // });
} // }
await request.patch( await request.patch(
`${IntegrationUrls.HEROKU_API_URL}/apps/${integration.app}/config-vars`, `${IntegrationUrls.HEROKU_API_URL}/apps/${integration.app}/config-vars`,
@@ -3071,7 +3073,7 @@ export const syncIntegrationSecrets = async ({
appendices appendices
}: { }: {
projectDAL: TProjectDALFactory; projectDAL: TProjectDALFactory;
integrationDAL: TIntegrationDALFactory; integrationDAL: Pick<TIntegrationDALFactory, "updateById">;
secretDAL: TSecretDALFactory; secretDAL: TSecretDALFactory;
secretVersionDAL: TSecretVersionDALFactory; secretVersionDAL: TSecretVersionDALFactory;
secretBlindIndexDAL: TSecretBlindIndexDALFactory; secretBlindIndexDAL: TSecretBlindIndexDALFactory;
+26 -10
View File
@@ -25,7 +25,8 @@ import {
TFnSecretBlindIndexCheck, TFnSecretBlindIndexCheck,
TFnSecretBulkInsert, TFnSecretBulkInsert,
TFnSecretBulkUpdate, TFnSecretBulkUpdate,
TUpdateManySecretsRawHelper TUpdateManySecretsRawFn,
TUpdateManySecretsRawFnFactory
} from "./secret-types"; } from "./secret-types";
export const generateSecretBlindIndexBySalt = async (secretName: string, secretBlindIndexDoc: TSecretBlindIndexes) => { export const generateSecretBlindIndexBySalt = async (secretName: string, secretBlindIndexDoc: TSecretBlindIndexes) => {
@@ -500,13 +501,15 @@ export const createManySecretsRawHelper = async ({
return newSecrets; return newSecrets;
}; };
export const updateManySecretsRawHelper = async ({ // TOOD: potentially convert raw stuff
projectId,
environment, // updateManySecretsRawFnFactory
path: secretPath,
secrets, // updateManySecretsRawHelper
userId,
botKey, // TODO: consider getting botKey inside this fn export const updateManySecretsRawFnFactory = async ({
// TODO: refactor
botKey,
projectDAL, projectDAL,
secretDAL, secretDAL,
secretVersionDAL, secretVersionDAL,
@@ -514,7 +517,16 @@ export const updateManySecretsRawHelper = async ({
secretTagDAL, secretTagDAL,
secretVersionTagDAL, secretVersionTagDAL,
folderDAL folderDAL
}: TUpdateManySecretsRawHelper) => { }: TUpdateManySecretsRawFnFactory) => {
const updateManySecretsRawFn = async ({
projectId,
environment,
path: secretPath,
secrets, // accept instead ciphertext secrets
userId
}: TUpdateManySecretsRawFn) => {
// TODO: fetch botKey from here
await projectDAL.checkProjectUpgradeStatus(projectId); await projectDAL.checkProjectUpgradeStatus(projectId);
const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath); const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath);
@@ -557,7 +569,8 @@ export const updateManySecretsRawHelper = async ({
message: "Failed to update personal secret override for no corresponding shared secret" message: "Failed to update personal secret override for no corresponding shared secret"
}); });
if (secret.newSecretName) throw new BadRequestError({ message: "Personal secret cannot change the key name" }); if (secret.newSecretName)
throw new BadRequestError({ message: "Personal secret cannot change the key name" });
} }
const tags = secret.tags ? await secretTagDAL.findManyTagsById(projectId, secret.tags) : []; const tags = secret.tags ? await secretTagDAL.findManyTagsById(projectId, secret.tags) : [];
@@ -624,4 +637,7 @@ export const updateManySecretsRawHelper = async ({
); );
return updatedSecrets; return updatedSecrets;
};
return updateManySecretsRawFn;
}; };
+14 -1
View File
@@ -29,6 +29,8 @@ import { TSecretDALFactory } from "./secret-dal";
import { interpolateSecrets } from "./secret-fns"; import { interpolateSecrets } from "./secret-fns";
import { TCreateSecretReminderDTO, THandleReminderDTO, TRemoveSecretReminderDTO } from "./secret-types"; import { TCreateSecretReminderDTO, THandleReminderDTO, TRemoveSecretReminderDTO } from "./secret-types";
// import { updateManySecretsRawFnFactory } from "@app/services/secret/secret-fns";
export type TSecretQueueFactory = ReturnType<typeof secretQueueFactory>; export type TSecretQueueFactory = ReturnType<typeof secretQueueFactory>;
type TSecretQueueFactoryDep = { type TSecretQueueFactoryDep = {
@@ -318,6 +320,17 @@ export const secretQueueFactory = ({
}); });
} }
// const updateManySecretsRawFn = updateManySecretsRawFnFactory({
// botKey, // can move this out
// projectDAL,
// secretDAL,
// secretVersionDAL,
// secretBlindIndexDAL,
// secretTagDAL,
// secretVersionTagDAL,
// folderDAL
// });
await syncIntegrationSecrets({ await syncIntegrationSecrets({
projectDAL, projectDAL,
integrationDAL, integrationDAL,
@@ -328,7 +341,7 @@ export const secretQueueFactory = ({
secretVersionTagDAL, secretVersionTagDAL,
folderDAL, folderDAL,
botKey, botKey,
projectId, projectId, // service
environment, environment,
secretPath, secretPath,
integration, integration,
+13 -10
View File
@@ -274,7 +274,18 @@ export type TCreateManySecretsRawHelper = {
folderDAL: TSecretFolderDALFactory; folderDAL: TSecretFolderDALFactory;
}; };
export type TUpdateManySecretsRawHelper = { export type TUpdateManySecretsRawFnFactory = {
botKey: string;
projectDAL: TProjectDALFactory;
secretDAL: TSecretDALFactory;
secretVersionDAL: TSecretVersionDALFactory;
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
secretTagDAL: TSecretTagDALFactory;
secretVersionTagDAL: TSecretVersionTagDALFactory;
folderDAL: TSecretFolderDALFactory;
};
export type TUpdateManySecretsRawFn = {
projectId: string; projectId: string;
environment: string; environment: string;
path: string; path: string;
@@ -292,13 +303,5 @@ export type TUpdateManySecretsRawHelper = {
source?: string; source?: string;
}; };
}[]; }[];
userId?: string; // only relevant for personal secret(s) userId?: string;
botKey: string;
projectDAL: TProjectDALFactory;
secretDAL: TSecretDALFactory;
secretVersionDAL: TSecretVersionDALFactory;
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
secretTagDAL: TSecretTagDALFactory;
secretVersionTagDAL: TSecretVersionTagDALFactory;
folderDAL: TSecretFolderDALFactory;
}; };