mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 19:28:33 +00:00
Draft refactor core secrets fn into reusable factories
This commit is contained in:
@@ -32,7 +32,10 @@ import { TSecretFolderDALFactory } from "@app/services/secret-folder/secret-fold
|
|||||||
import { TSecretTagDALFactory } from "@app/services/secret-tag/secret-tag-dal";
|
import { TSecretTagDALFactory } from "@app/services/secret-tag/secret-tag-dal";
|
||||||
|
|
||||||
import { TIntegrationDALFactory } from "../integration/integration-dal";
|
import { TIntegrationDALFactory } from "../integration/integration-dal";
|
||||||
import { createManySecretsRawHelper, updateManySecretsRawHelper } from "../secret/secret-fns";
|
import {
|
||||||
|
createManySecretsRawHelper
|
||||||
|
// updateManySecretsRawHelper
|
||||||
|
} from "../secret/secret-fns";
|
||||||
import { Integrations, IntegrationSyncBehavior, IntegrationUrls } from "./integration-list";
|
import { Integrations, IntegrationSyncBehavior, IntegrationUrls } from "./integration-list";
|
||||||
|
|
||||||
const getSecretKeyValuePair = (secrets: Record<string, { value: string | null; comment?: string } | null>) =>
|
const getSecretKeyValuePair = (secrets: Record<string, { value: string | null; comment?: string } | null>) =>
|
||||||
@@ -589,7 +592,6 @@ const syncSecretsAWSSecretManager = async ({
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Sync/push [secrets] to Heroku app named [integration.app]
|
* Sync/push [secrets] to Heroku app named [integration.app]
|
||||||
* server.services...
|
|
||||||
*/
|
*/
|
||||||
const syncSecretsHeroku = async ({
|
const syncSecretsHeroku = async ({
|
||||||
projectDAL,
|
projectDAL,
|
||||||
@@ -609,7 +611,7 @@ const syncSecretsHeroku = async ({
|
|||||||
accessToken
|
accessToken
|
||||||
}: {
|
}: {
|
||||||
projectDAL: TProjectDALFactory;
|
projectDAL: TProjectDALFactory;
|
||||||
integrationDAL: TIntegrationDALFactory;
|
integrationDAL: Pick<TIntegrationDALFactory, "updateById">;
|
||||||
secretDAL: TSecretDALFactory;
|
secretDAL: TSecretDALFactory;
|
||||||
secretVersionDAL: TSecretVersionDALFactory;
|
secretVersionDAL: TSecretVersionDALFactory;
|
||||||
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
|
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
|
||||||
@@ -696,27 +698,27 @@ const syncSecretsHeroku = async ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
if (Object.keys(secretsToUpdate).length) {
|
// if (Object.keys(secretsToUpdate).length) {
|
||||||
await updateManySecretsRawHelper({
|
// await updateManySecretsRawHelper({
|
||||||
projectId,
|
// projectId,
|
||||||
environment,
|
// environment,
|
||||||
path: secretPath,
|
// path: secretPath,
|
||||||
secrets: Object.keys(secretsToUpdate).map((key) => ({
|
// secrets: Object.keys(secretsToUpdate).map((key) => ({
|
||||||
secretName: key,
|
// secretName: key,
|
||||||
secretValue: secretsToUpdate[key],
|
// secretValue: secretsToUpdate[key],
|
||||||
type: SecretType.Shared,
|
// type: SecretType.Shared,
|
||||||
secretComment: ""
|
// secretComment: ""
|
||||||
})),
|
// })),
|
||||||
botKey, // TODO: consider getting botKey inside this fn
|
// botKey, // TODO: consider getting botKey inside this fn
|
||||||
projectDAL,
|
// projectDAL,
|
||||||
secretDAL,
|
// secretDAL,
|
||||||
secretVersionDAL,
|
// secretVersionDAL,
|
||||||
secretBlindIndexDAL,
|
// secretBlindIndexDAL,
|
||||||
secretTagDAL,
|
// secretTagDAL,
|
||||||
secretVersionTagDAL,
|
// secretVersionTagDAL,
|
||||||
folderDAL
|
// folderDAL
|
||||||
});
|
// });
|
||||||
}
|
// }
|
||||||
|
|
||||||
await request.patch(
|
await request.patch(
|
||||||
`${IntegrationUrls.HEROKU_API_URL}/apps/${integration.app}/config-vars`,
|
`${IntegrationUrls.HEROKU_API_URL}/apps/${integration.app}/config-vars`,
|
||||||
@@ -3071,7 +3073,7 @@ export const syncIntegrationSecrets = async ({
|
|||||||
appendices
|
appendices
|
||||||
}: {
|
}: {
|
||||||
projectDAL: TProjectDALFactory;
|
projectDAL: TProjectDALFactory;
|
||||||
integrationDAL: TIntegrationDALFactory;
|
integrationDAL: Pick<TIntegrationDALFactory, "updateById">;
|
||||||
secretDAL: TSecretDALFactory;
|
secretDAL: TSecretDALFactory;
|
||||||
secretVersionDAL: TSecretVersionDALFactory;
|
secretVersionDAL: TSecretVersionDALFactory;
|
||||||
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
|
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
|
||||||
|
|||||||
@@ -25,7 +25,8 @@ import {
|
|||||||
TFnSecretBlindIndexCheck,
|
TFnSecretBlindIndexCheck,
|
||||||
TFnSecretBulkInsert,
|
TFnSecretBulkInsert,
|
||||||
TFnSecretBulkUpdate,
|
TFnSecretBulkUpdate,
|
||||||
TUpdateManySecretsRawHelper
|
TUpdateManySecretsRawFn,
|
||||||
|
TUpdateManySecretsRawFnFactory
|
||||||
} from "./secret-types";
|
} from "./secret-types";
|
||||||
|
|
||||||
export const generateSecretBlindIndexBySalt = async (secretName: string, secretBlindIndexDoc: TSecretBlindIndexes) => {
|
export const generateSecretBlindIndexBySalt = async (secretName: string, secretBlindIndexDoc: TSecretBlindIndexes) => {
|
||||||
@@ -500,13 +501,15 @@ export const createManySecretsRawHelper = async ({
|
|||||||
return newSecrets;
|
return newSecrets;
|
||||||
};
|
};
|
||||||
|
|
||||||
export const updateManySecretsRawHelper = async ({
|
// TOOD: potentially convert raw stuff
|
||||||
projectId,
|
|
||||||
environment,
|
// updateManySecretsRawFnFactory
|
||||||
path: secretPath,
|
|
||||||
secrets,
|
// updateManySecretsRawHelper
|
||||||
userId,
|
|
||||||
botKey, // TODO: consider getting botKey inside this fn
|
export const updateManySecretsRawFnFactory = async ({
|
||||||
|
// TODO: refactor
|
||||||
|
botKey,
|
||||||
projectDAL,
|
projectDAL,
|
||||||
secretDAL,
|
secretDAL,
|
||||||
secretVersionDAL,
|
secretVersionDAL,
|
||||||
@@ -514,7 +517,16 @@ export const updateManySecretsRawHelper = async ({
|
|||||||
secretTagDAL,
|
secretTagDAL,
|
||||||
secretVersionTagDAL,
|
secretVersionTagDAL,
|
||||||
folderDAL
|
folderDAL
|
||||||
}: TUpdateManySecretsRawHelper) => {
|
}: TUpdateManySecretsRawFnFactory) => {
|
||||||
|
const updateManySecretsRawFn = async ({
|
||||||
|
projectId,
|
||||||
|
environment,
|
||||||
|
path: secretPath,
|
||||||
|
secrets, // accept instead ciphertext secrets
|
||||||
|
userId
|
||||||
|
}: TUpdateManySecretsRawFn) => {
|
||||||
|
// TODO: fetch botKey from here
|
||||||
|
|
||||||
await projectDAL.checkProjectUpgradeStatus(projectId);
|
await projectDAL.checkProjectUpgradeStatus(projectId);
|
||||||
|
|
||||||
const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath);
|
const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath);
|
||||||
@@ -557,7 +569,8 @@ export const updateManySecretsRawHelper = async ({
|
|||||||
message: "Failed to update personal secret override for no corresponding shared secret"
|
message: "Failed to update personal secret override for no corresponding shared secret"
|
||||||
});
|
});
|
||||||
|
|
||||||
if (secret.newSecretName) throw new BadRequestError({ message: "Personal secret cannot change the key name" });
|
if (secret.newSecretName)
|
||||||
|
throw new BadRequestError({ message: "Personal secret cannot change the key name" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const tags = secret.tags ? await secretTagDAL.findManyTagsById(projectId, secret.tags) : [];
|
const tags = secret.tags ? await secretTagDAL.findManyTagsById(projectId, secret.tags) : [];
|
||||||
@@ -624,4 +637,7 @@ export const updateManySecretsRawHelper = async ({
|
|||||||
);
|
);
|
||||||
|
|
||||||
return updatedSecrets;
|
return updatedSecrets;
|
||||||
|
};
|
||||||
|
|
||||||
|
return updateManySecretsRawFn;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -29,6 +29,8 @@ import { TSecretDALFactory } from "./secret-dal";
|
|||||||
import { interpolateSecrets } from "./secret-fns";
|
import { interpolateSecrets } from "./secret-fns";
|
||||||
import { TCreateSecretReminderDTO, THandleReminderDTO, TRemoveSecretReminderDTO } from "./secret-types";
|
import { TCreateSecretReminderDTO, THandleReminderDTO, TRemoveSecretReminderDTO } from "./secret-types";
|
||||||
|
|
||||||
|
// import { updateManySecretsRawFnFactory } from "@app/services/secret/secret-fns";
|
||||||
|
|
||||||
export type TSecretQueueFactory = ReturnType<typeof secretQueueFactory>;
|
export type TSecretQueueFactory = ReturnType<typeof secretQueueFactory>;
|
||||||
|
|
||||||
type TSecretQueueFactoryDep = {
|
type TSecretQueueFactoryDep = {
|
||||||
@@ -318,6 +320,17 @@ export const secretQueueFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// const updateManySecretsRawFn = updateManySecretsRawFnFactory({
|
||||||
|
// botKey, // can move this out
|
||||||
|
// projectDAL,
|
||||||
|
// secretDAL,
|
||||||
|
// secretVersionDAL,
|
||||||
|
// secretBlindIndexDAL,
|
||||||
|
// secretTagDAL,
|
||||||
|
// secretVersionTagDAL,
|
||||||
|
// folderDAL
|
||||||
|
// });
|
||||||
|
|
||||||
await syncIntegrationSecrets({
|
await syncIntegrationSecrets({
|
||||||
projectDAL,
|
projectDAL,
|
||||||
integrationDAL,
|
integrationDAL,
|
||||||
@@ -328,7 +341,7 @@ export const secretQueueFactory = ({
|
|||||||
secretVersionTagDAL,
|
secretVersionTagDAL,
|
||||||
folderDAL,
|
folderDAL,
|
||||||
botKey,
|
botKey,
|
||||||
projectId,
|
projectId, // service
|
||||||
environment,
|
environment,
|
||||||
secretPath,
|
secretPath,
|
||||||
integration,
|
integration,
|
||||||
|
|||||||
@@ -274,7 +274,18 @@ export type TCreateManySecretsRawHelper = {
|
|||||||
folderDAL: TSecretFolderDALFactory;
|
folderDAL: TSecretFolderDALFactory;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TUpdateManySecretsRawHelper = {
|
export type TUpdateManySecretsRawFnFactory = {
|
||||||
|
botKey: string;
|
||||||
|
projectDAL: TProjectDALFactory;
|
||||||
|
secretDAL: TSecretDALFactory;
|
||||||
|
secretVersionDAL: TSecretVersionDALFactory;
|
||||||
|
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
|
||||||
|
secretTagDAL: TSecretTagDALFactory;
|
||||||
|
secretVersionTagDAL: TSecretVersionTagDALFactory;
|
||||||
|
folderDAL: TSecretFolderDALFactory;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TUpdateManySecretsRawFn = {
|
||||||
projectId: string;
|
projectId: string;
|
||||||
environment: string;
|
environment: string;
|
||||||
path: string;
|
path: string;
|
||||||
@@ -292,13 +303,5 @@ export type TUpdateManySecretsRawHelper = {
|
|||||||
source?: string;
|
source?: string;
|
||||||
};
|
};
|
||||||
}[];
|
}[];
|
||||||
userId?: string; // only relevant for personal secret(s)
|
userId?: string;
|
||||||
botKey: string;
|
|
||||||
projectDAL: TProjectDALFactory;
|
|
||||||
secretDAL: TSecretDALFactory;
|
|
||||||
secretVersionDAL: TSecretVersionDALFactory;
|
|
||||||
secretBlindIndexDAL: TSecretBlindIndexDALFactory;
|
|
||||||
secretTagDAL: TSecretTagDALFactory;
|
|
||||||
secretVersionTagDAL: TSecretVersionTagDALFactory;
|
|
||||||
folderDAL: TSecretFolderDALFactory;
|
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user