diff --git a/backend/src/ee/routes/v1/group-router.ts b/backend/src/ee/routes/v1/group-router.ts index 628d5e696..766ac3d93 100644 --- a/backend/src/ee/routes/v1/group-router.ts +++ b/backend/src/ee/routes/v1/group-router.ts @@ -12,7 +12,7 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { onRequest: verifyAuth([AuthMode.JWT]), schema: { body: z.object({ - organizationId: z.string().trim(), + // TODO: update on frontend to not send organizationId name: z.string().trim().min(1), slug: z .string() @@ -32,7 +32,6 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { const group = await server.services.group.createGroup({ actor: req.permission.type, actorId: req.permission.id, - orgId: req.body.organizationId, actorAuthMethod: req.permission.authMethod, actorOrgId: req.permission.orgId, ...req.body @@ -72,7 +71,6 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { currentSlug: req.params.currentSlug, actor: req.permission.type, actorId: req.permission.id, - orgId: req.permission.orgId, // note actorAuthMethod: req.permission.authMethod, actorOrgId: req.permission.orgId, ...req.body @@ -99,7 +97,6 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { groupSlug: req.params.groupSlug, actor: req.permission.type, actorId: req.permission.id, - orgId: req.permission.orgId, // note actorAuthMethod: req.permission.authMethod, actorOrgId: req.permission.orgId }); @@ -137,7 +134,6 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { groupSlug: req.params.slug, actor: req.permission.type, actorId: req.permission.id, - orgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, actorOrgId: req.permission.orgId }); @@ -170,7 +166,6 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { username: req.params.username, actor: req.permission.type, actorId: req.permission.id, - orgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, actorOrgId: req.permission.orgId }); @@ -204,7 +199,6 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => { username: req.params.username, actor: req.permission.type, actorId: req.permission.id, - orgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, actorOrgId: req.permission.orgId }); diff --git a/backend/src/ee/services/group/group-service.ts b/backend/src/ee/services/group/group-service.ts index fa2ba75c5..920c6d549 100644 --- a/backend/src/ee/services/group/group-service.ts +++ b/backend/src/ee/services/group/group-service.ts @@ -57,20 +57,19 @@ export const groupServiceFactory = ({ permissionService, licenseService }: TGroupServiceFactoryDep) => { - const createGroup = async ({ - name, - slug, - role, - actor, - actorId, - orgId, - actorAuthMethod, - actorOrgId - }: TCreateGroupDTO) => { - const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); + const createGroup = async ({ name, slug, role, actor, actorId, actorAuthMethod, actorOrgId }: TCreateGroupDTO) => { + if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + actorOrgId, + actorAuthMethod, + actorOrgId + ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Create, OrgPermissionSubjects.Groups); - const plan = await licenseService.getPlan(orgId); + const plan = await licenseService.getPlan(actorOrgId); if (!plan.groups) throw new BadRequestError({ message: "Failed to create group due to plan restriction. Upgrade plan to create group." @@ -78,7 +77,7 @@ export const groupServiceFactory = ({ const { permission: rolePermission, role: customRole } = await permissionService.getOrgPermissionByRole( role, - orgId + actorOrgId ); const isCustomRole = Boolean(customRole); const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, rolePermission); @@ -87,7 +86,7 @@ export const groupServiceFactory = ({ const group = await groupDAL.create({ name, slug: slug || slugify(`${name}-${alphaNumericNanoId(4)}`), - orgId, + orgId: actorOrgId, role: isCustomRole ? OrgMembershipRole.Custom : role, roleId: customRole?.id }); @@ -102,20 +101,27 @@ export const groupServiceFactory = ({ role, actor, actorId, - orgId, actorAuthMethod, actorOrgId }: TUpdateGroupDTO) => { - const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); + if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + actorOrgId, + actorAuthMethod, + actorOrgId + ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Groups); - const plan = await licenseService.getPlan(orgId); + const plan = await licenseService.getPlan(actorOrgId); if (!plan.groups) throw new BadRequestError({ message: "Failed to update group due to plan restrictio Upgrade plan to update group." }); - const group = await groupDAL.findOne({ orgId, slug: currentSlug }); + const group = await groupDAL.findOne({ orgId: actorOrgId, slug: currentSlug }); if (!group) throw new BadRequestError({ message: `Failed to find group with slug ${currentSlug}` }); let customRole: TOrgRoles | undefined; @@ -134,7 +140,7 @@ export const groupServiceFactory = ({ const [updatedGroup] = await groupDAL.update( { - orgId, + orgId: actorOrgId, slug: currentSlug }, { @@ -152,11 +158,19 @@ export const groupServiceFactory = ({ return updatedGroup; }; - const deleteGroup = async ({ groupSlug, actor, actorId, orgId, actorAuthMethod, actorOrgId }: TDeleteGroupDTO) => { - const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); + const deleteGroup = async ({ groupSlug, actor, actorId, actorAuthMethod, actorOrgId }: TDeleteGroupDTO) => { + if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + actorOrgId, + actorAuthMethod, + actorOrgId + ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Delete, OrgPermissionSubjects.Groups); - const plan = await licenseService.getPlan(orgId); + const plan = await licenseService.getPlan(actorOrgId); if (!plan.groups) throw new BadRequestError({ @@ -164,7 +178,7 @@ export const groupServiceFactory = ({ }); const [group] = await groupDAL.delete({ - orgId, + orgId: actorOrgId, slug: groupSlug }); @@ -175,15 +189,22 @@ export const groupServiceFactory = ({ groupSlug, actor, actorId, - orgId, actorAuthMethod, actorOrgId }: TGetGroupUserMembershipsDTO) => { - const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); + if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + actorOrgId, + actorAuthMethod, + actorOrgId + ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Groups); const group = await groupDAL.findOne({ - orgId, + orgId: actorOrgId, slug: groupSlug }); @@ -201,16 +222,23 @@ export const groupServiceFactory = ({ username, actor, actorId, - orgId, actorAuthMethod, actorOrgId }: TCreateGroupUserMembershipDTO) => { - const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); + if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + actorOrgId, + actorAuthMethod, + actorOrgId + ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Groups); // check if group with slug exists const group = await groupDAL.findOne({ - orgId, + orgId: actorOrgId, slug: groupSlug }); @@ -219,7 +247,7 @@ export const groupServiceFactory = ({ message: `Failed to find group with slug ${groupSlug}` }); - const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, orgId); + const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, actorOrgId); // check if user has broader or equal to privileges than group const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, groupRolePermission); @@ -250,7 +278,7 @@ export const groupServiceFactory = ({ // check if user is even part of the organization const existingUserOrgMembership = await orgDAL.findMembership({ userId: user.userId, - orgId + orgId: actorOrgId }); if (!existingUserOrgMembership) @@ -338,16 +366,23 @@ export const groupServiceFactory = ({ username, actor, actorId, - orgId, actorAuthMethod, actorOrgId }: TDeleteGroupUserMembershipDTO) => { - const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); + if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); + + const { permission } = await permissionService.getOrgPermission( + actor, + actorId, + actorOrgId, + actorAuthMethod, + actorOrgId + ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Groups); // check if group with slug exists const group = await groupDAL.findOne({ - orgId, + orgId: actorOrgId, slug: groupSlug }); @@ -356,7 +391,7 @@ export const groupServiceFactory = ({ message: `Failed to find group with slug ${groupSlug}` }); - const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, orgId); + const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, actorOrgId); // check if user has broader or equal to privileges than group const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, groupRolePermission); diff --git a/backend/src/ee/services/ldap-config/ldap-config-service.ts b/backend/src/ee/services/ldap-config/ldap-config-service.ts index 0316052cd..76e2d40ce 100644 --- a/backend/src/ee/services/ldap-config/ldap-config-service.ts +++ b/backend/src/ee/services/ldap-config/ldap-config-service.ts @@ -12,7 +12,6 @@ import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption"; import { BadRequestError } from "@app/lib/errors"; -import { TOrgPermission } from "@app/lib/types"; import { AuthMethod, AuthTokenType } from "@app/services/auth/auth-type"; import { TOrgBotDALFactory } from "@app/services/org/org-bot-dal"; import { TOrgDALFactory } from "@app/services/org/org-dal"; @@ -24,7 +23,7 @@ import { TLicenseServiceFactory } from "../license/license-service"; import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission"; import { TPermissionServiceFactory } from "../permission/permission-service"; import { TLdapConfigDALFactory } from "./ldap-config-dal"; -import { TCreateLdapCfgDTO, TLdapLoginDTO, TUpdateLdapCfgDTO } from "./ldap-config-types"; +import { TCreateLdapCfgDTO, TGetLdapCfgDTO, TLdapLoginDTO, TUpdateLdapCfgDTO } from "./ldap-config-types"; type TLdapConfigServiceFactoryDep = { ldapConfigDAL: TLdapConfigDALFactory; @@ -282,7 +281,7 @@ export const ldapConfigServiceFactory = ({ orgId, actorAuthMethod, actorOrgId - }: TOrgPermission) => { + }: TGetLdapCfgDTO) => { const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Ldap); return getLdapCfg({ diff --git a/backend/src/ee/services/ldap-config/ldap-config-types.ts b/backend/src/ee/services/ldap-config/ldap-config-types.ts index 025ce7781..4e261f9e9 100644 --- a/backend/src/ee/services/ldap-config/ldap-config-types.ts +++ b/backend/src/ee/services/ldap-config/ldap-config-types.ts @@ -1,6 +1,7 @@ import { TOrgPermission } from "@app/lib/types"; export type TCreateLdapCfgDTO = { + orgId: string; isActive: boolean; url: string; bindDN: string; @@ -9,7 +10,9 @@ export type TCreateLdapCfgDTO = { caCert: string; } & TOrgPermission; -export type TUpdateLdapCfgDTO = Partial<{ +export type TUpdateLdapCfgDTO = { + orgId: string; +} & Partial<{ isActive: boolean; url: string; bindDN: string; @@ -19,6 +22,10 @@ export type TUpdateLdapCfgDTO = Partial<{ }> & TOrgPermission; +export type TGetLdapCfgDTO = { + orgId: string; +} & TOrgPermission; + export type TLdapLoginDTO = { externalId: string; username: string; diff --git a/backend/src/lib/types/index.ts b/backend/src/lib/types/index.ts index 7d26a5e5d..a586cfd3e 100644 --- a/backend/src/lib/types/index.ts +++ b/backend/src/lib/types/index.ts @@ -3,7 +3,6 @@ import { ActorAuthMethod, ActorType } from "@app/services/auth/auth-type"; export type TOrgPermission = { actor: ActorType; actorId: string; - orgId: string; actorAuthMethod: ActorAuthMethod; actorOrgId: string | undefined; }; diff --git a/frontend/src/hooks/api/groups/mutations.tsx b/frontend/src/hooks/api/groups/mutations.tsx index 1412e679e..ccf167b51 100644 --- a/frontend/src/hooks/api/groups/mutations.tsx +++ b/frontend/src/hooks/api/groups/mutations.tsx @@ -12,7 +12,6 @@ export const useCreateGroup = () => { mutationFn: async ({ name, slug, - organizationId, role }: { name: string; @@ -25,7 +24,6 @@ export const useCreateGroup = () => { } = await apiRequest.post("/api/v1/groups", { name, slug, - organizationId, role });