From 8e0b4254b14cd8b27715fd6ddae37461129dd9ec Mon Sep 17 00:00:00 2001 From: lemmyMwaura Date: Thu, 8 Aug 2024 09:56:18 +0300 Subject: [PATCH] refactor: fix lint issues and refactor code --- .../server/routes/v1/secret-sharing-router.ts | 6 ++--- .../secret-sharing/secret-sharing-service.ts | 22 +++++++++++-------- .../secret-sharing/secret-sharing-types.ts | 2 -- 3 files changed, 16 insertions(+), 14 deletions(-) diff --git a/backend/src/server/routes/v1/secret-sharing-router.ts b/backend/src/server/routes/v1/secret-sharing-router.ts index 21bcf013c..00b0fb9b3 100644 --- a/backend/src/server/routes/v1/secret-sharing-router.ts +++ b/backend/src/server/routes/v1/secret-sharing-router.ts @@ -74,13 +74,13 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) => } }, handler: async (req) => { - const sharedSecret = await req.server.services.secretSharing.getActiveSharedSecretById({ + const sharedSecret = await req.server.services.secretSharing.getPasswordlessSecretByID({ sharedSecretId: req.params.id, hashedHex: req.query.hashedHex, orgId: req.permission?.orgId }); - if (!sharedSecret || sharedSecret.password) return undefined; + if (!sharedSecret) return undefined; return { encryptedValue: sharedSecret.encryptedValue, @@ -125,7 +125,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) => const { id } = req.params; const { password, hashedHex } = req.body; - const sharedSecret = await req.server.services.secretSharing.validateSecretPassword({ + const sharedSecret = await req.server.services.secretSharing.getValidatedSecretByID({ sharedSecretId: id, hashedHex, orgId: req.permission?.orgId, diff --git a/backend/src/services/secret-sharing/secret-sharing-service.ts b/backend/src/services/secret-sharing/secret-sharing-service.ts index 08dbdc91f..e7e6d4c16 100644 --- a/backend/src/services/secret-sharing/secret-sharing-service.ts +++ b/backend/src/services/secret-sharing/secret-sharing-service.ts @@ -9,11 +9,11 @@ import { UnauthorizedError } from "@app/lib/errors"; import { SecretSharingAccessType } from "@app/lib/types"; +import { TSecretSharing } from "@app/db/schemas"; import { TOrgDALFactory } from "../org/org-dal"; import { TSecretSharingDALFactory } from "./secret-sharing-dal"; import { - SharedSecretWithDate, TCreatePublicSharedSecretDTO, TCreateSharedSecretDTO, TDeleteSharedSecretDTO, @@ -170,7 +170,7 @@ export const secretSharingServiceFactory = ({ }; /** Checks if secret is expired and throws error if true */ - const checkIfExpired = async (sharedSecret: SharedSecretWithDate, sharedSecretId: string) => { + const checkIfSecretIsExpired = async (sharedSecret: TSecretSharing, sharedSecretId: string) => { const { expiresAt, expiresAfterViews } = sharedSecret; if (expiresAt !== null && expiresAt < new Date()) { @@ -190,7 +190,7 @@ export const secretSharingServiceFactory = ({ } }; - const decrementSecretViewCount = async (sharedSecret: SharedSecretWithDate, sharedSecretId: string) => { + const decrementSecretViewCount = async (sharedSecret: TSecretSharing, sharedSecretId: string) => { const { expiresAfterViews } = sharedSecret; if (expiresAfterViews) { @@ -203,7 +203,8 @@ export const secretSharingServiceFactory = ({ }); }; - const getActiveSharedSecretById = async ({ sharedSecretId, hashedHex, orgId }: TGetActiveSharedSecretByIdDTO) => { + /** Get's passwordless secret. validates all secret's requested (must be fresh). */ + const getPasswordlessSecretByID = async ({ sharedSecretId, hashedHex, orgId }: TGetActiveSharedSecretByIdDTO) => { const sharedSecret = await secretSharingDAL.findOne({ id: sharedSecretId, hashedHex @@ -220,7 +221,9 @@ export const secretSharingServiceFactory = ({ if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId) throw new UnauthorizedError(); - await checkIfExpired(sharedSecret, sharedSecretId); + // all secrets pass through here, meaning we check if its expired first and then check if it needs verification + // or can be safely sent to the client. + await checkIfSecretIsExpired(sharedSecret, sharedSecretId); if (sharedSecret.password !== null) return undefined; @@ -236,7 +239,8 @@ export const secretSharingServiceFactory = ({ }; }; - const validateSecretPassword = async ({ + /** Get's the requested secret if password passed is valid */ + const getValidatedSecretByID = async ({ sharedSecretId, hashedHex, orgId, @@ -266,7 +270,7 @@ export const secretSharingServiceFactory = ({ const isMatch = await bcrypt.compare(password, sharedSecret.password as string); if (!isMatch) return undefined; - // we reduce the view count when we are sure the password matches. + // reduce the view count when the password matches (will be returned to the client). await decrementSecretViewCount(sharedSecret, sharedSecretId); return { @@ -291,7 +295,7 @@ export const secretSharingServiceFactory = ({ createPublicSharedSecret, getSharedSecrets, deleteSharedSecretById, - getActiveSharedSecretById, - validateSecretPassword + getPasswordlessSecretByID, + getValidatedSecretByID }; }; diff --git a/backend/src/services/secret-sharing/secret-sharing-types.ts b/backend/src/services/secret-sharing/secret-sharing-types.ts index 6720a7bee..e96a68e64 100644 --- a/backend/src/services/secret-sharing/secret-sharing-types.ts +++ b/backend/src/services/secret-sharing/secret-sharing-types.ts @@ -41,8 +41,6 @@ export type TValidateActiveSharedSecretDTO = TGetActiveSharedSecretByIdDTO & { export type TCreateSharedSecretDTO = TSharedSecretPermission & TCreatePublicSharedSecretDTO; -export type SharedSecretWithDate = Omit & { expiresAt: Date }; - export type TDeleteSharedSecretDTO = { sharedSecretId: string; } & TSharedSecretPermission;