diff --git a/backend/src/ee/services/saml-config/saml-config-service.ts b/backend/src/ee/services/saml-config/saml-config-service.ts index 578ab469c..0a46597b8 100644 --- a/backend/src/ee/services/saml-config/saml-config-service.ts +++ b/backend/src/ee/services/saml-config/saml-config-service.ts @@ -410,7 +410,7 @@ export const samlConfigServiceFactory = ({ } await licenseService.updateSubscriptionOrgMemberCount(organization.id); - const isUserCompleted = Boolean(user.isAccepted); + const isUserCompleted = Boolean(user.isAccepted && user.isEmailVerified); const userEnc = await userDAL.findUserEncKeyByUserId(user.id); const providerAuthToken = crypto.jwt().sign( { diff --git a/backend/src/lib/api-docs/constants.ts b/backend/src/lib/api-docs/constants.ts index 2d5d24e55..584f480ad 100644 --- a/backend/src/lib/api-docs/constants.ts +++ b/backend/src/lib/api-docs/constants.ts @@ -2285,6 +2285,10 @@ export const AppConnections = { }, CHECKLY: { apiKey: "The API key used to authenticate with Checkly." + }, + SUPABASE: { + accessKey: "The Key used to access Supabase.", + instanceUrl: "The URL used to access Supabase." } } }; @@ -2494,6 +2498,10 @@ export const SecretSyncs = { }, CHECKLY: { accountId: "The ID of the Checkly account to sync secrets to." + }, + SUPABASE: { + projectId: "The ID of the Supabase project to sync secrets to.", + projectName: "The name of the Supabase project to sync secrets to." } } }; diff --git a/backend/src/server/lib/cookie.ts b/backend/src/server/lib/cookie.ts new file mode 100644 index 000000000..323bf4be9 --- /dev/null +++ b/backend/src/server/lib/cookie.ts @@ -0,0 +1,43 @@ +import { FastifyReply } from "fastify"; + +import { getConfig } from "@app/lib/config/env"; +import { logger } from "@app/lib/logger"; + +/** + * `aod` (Auth Origin Domain) cookie is used to store the origin domain of the application when user was last authenticated. + * This is useful for determining the target domain for authentication redirects, especially in cloud deployments. + * It is set only in cloud mode to ensure that the cookie is shared across subdomains. + */ +export function addAuthOriginDomainCookie(res: FastifyReply) { + try { + const appCfg = getConfig(); + + // Only set the cookie if the app is running in cloud mode + if (!appCfg.isCloud) return; + + const siteUrl = appCfg.SITE_URL!; + let domain: string; + + const { hostname } = new URL(siteUrl); + + const parts = hostname.split("."); + + if (parts.length >= 2) { + // For `app.infisical.com` => `.infisical.com` + domain = `.${parts.slice(-2).join(".")}`; + } else { + // If somehow only "example", fallback to itself + domain = `.${hostname}`; + } + + void res.setCookie("aod", siteUrl, { + domain, + path: "/", + sameSite: "strict", + httpOnly: false, + secure: appCfg.HTTPS_ENABLED + }); + } catch (error) { + logger.error(error, "Failed to set auth origin domain cookie"); + } +} diff --git a/backend/src/server/routes/v1/admin-router.ts b/backend/src/server/routes/v1/admin-router.ts index 2e31077a7..6cc50dc5c 100644 --- a/backend/src/server/routes/v1/admin-router.ts +++ b/backend/src/server/routes/v1/admin-router.ts @@ -12,6 +12,7 @@ import { getConfig, overridableKeys } from "@app/lib/config/env"; import { crypto } from "@app/lib/crypto/cryptography"; import { BadRequestError } from "@app/lib/errors"; import { invalidateCacheLimit, readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { addAuthOriginDomainCookie } from "@app/server/lib/cookie"; import { getTelemetryDistinctId } from "@app/server/lib/telemetry"; import { verifySuperAdmin } from "@app/server/plugins/auth/superAdmin"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; @@ -593,6 +594,8 @@ export const registerAdminRouter = async (server: FastifyZodProvider) => { secure: appCfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + return { message: "Successfully set up admin account", user: user.user, diff --git a/backend/src/server/routes/v1/app-connection-routers/app-connection-router.ts b/backend/src/server/routes/v1/app-connection-routers/app-connection-router.ts index 62d4ab979..7c1b52edd 100644 --- a/backend/src/server/routes/v1/app-connection-routers/app-connection-router.ts +++ b/backend/src/server/routes/v1/app-connection-routers/app-connection-router.ts @@ -83,6 +83,10 @@ import { RenderConnectionListItemSchema, SanitizedRenderConnectionSchema } from "@app/services/app-connection/render/render-connection-schema"; +import { + SanitizedSupabaseConnectionSchema, + SupabaseConnectionListItemSchema +} from "@app/services/app-connection/supabase"; import { SanitizedTeamCityConnectionSchema, TeamCityConnectionListItemSchema @@ -133,7 +137,8 @@ const SanitizedAppConnectionSchema = z.union([ ...SanitizedBitbucketConnectionSchema.options, ...SanitizedZabbixConnectionSchema.options, ...SanitizedRailwayConnectionSchema.options, - ...SanitizedChecklyConnectionSchema.options + ...SanitizedChecklyConnectionSchema.options, + ...SanitizedSupabaseConnectionSchema.options ]); const AppConnectionOptionsSchema = z.discriminatedUnion("app", [ @@ -169,7 +174,8 @@ const AppConnectionOptionsSchema = z.discriminatedUnion("app", [ BitbucketConnectionListItemSchema, ZabbixConnectionListItemSchema, RailwayConnectionListItemSchema, - ChecklyConnectionListItemSchema + ChecklyConnectionListItemSchema, + SupabaseConnectionListItemSchema ]); export const registerAppConnectionRouter = async (server: FastifyZodProvider) => { diff --git a/backend/src/server/routes/v1/app-connection-routers/index.ts b/backend/src/server/routes/v1/app-connection-routers/index.ts index 67a420cb7..287a406f6 100644 --- a/backend/src/server/routes/v1/app-connection-routers/index.ts +++ b/backend/src/server/routes/v1/app-connection-routers/index.ts @@ -28,6 +28,7 @@ import { registerMySqlConnectionRouter } from "./mysql-connection-router"; import { registerPostgresConnectionRouter } from "./postgres-connection-router"; import { registerRailwayConnectionRouter } from "./railway-connection-router"; import { registerRenderConnectionRouter } from "./render-connection-router"; +import { registerSupabaseConnectionRouter } from "./supabase-connection-router"; import { registerTeamCityConnectionRouter } from "./teamcity-connection-router"; import { registerTerraformCloudConnectionRouter } from "./terraform-cloud-router"; import { registerVercelConnectionRouter } from "./vercel-connection-router"; @@ -70,5 +71,6 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record { + registerAppConnectionEndpoints({ + app: AppConnection.Supabase, + server, + sanitizedResponseSchema: SanitizedSupabaseConnectionSchema, + createSchema: CreateSupabaseConnectionSchema, + updateSchema: UpdateSupabaseConnectionSchema + }); + + // The below endpoints are not exposed and for Infisical App use + server.route({ + method: "GET", + url: `/:connectionId/projects`, + config: { + rateLimit: readLimit + }, + schema: { + params: z.object({ + connectionId: z.string().uuid() + }), + response: { + 200: z.object({ + projects: z + .object({ + name: z.string(), + id: z.string() + }) + .array() + }) + } + }, + onRequest: verifyAuth([AuthMode.JWT]), + handler: async (req) => { + const { connectionId } = req.params; + + const projects = await server.services.appConnection.supabase.listProjects(connectionId, req.permission); + + return { projects }; + } + }); +}; diff --git a/backend/src/server/routes/v1/auth-router.ts b/backend/src/server/routes/v1/auth-router.ts index e7c06ff51..a91548285 100644 --- a/backend/src/server/routes/v1/auth-router.ts +++ b/backend/src/server/routes/v1/auth-router.ts @@ -42,6 +42,14 @@ export const registerAuthRoutes = async (server: FastifyZodProvider) => { maxAge: 0 }); + void res.cookie("aod", "", { + httpOnly: false, + path: "/", + sameSite: "lax", + secure: appCfg.HTTPS_ENABLED, + maxAge: 0 + }); + return { message: "Successfully logged out" }; } }); diff --git a/backend/src/server/routes/v1/identity-oci-auth-router.ts b/backend/src/server/routes/v1/identity-oci-auth-router.ts index de9866c85..e529f300b 100644 --- a/backend/src/server/routes/v1/identity-oci-auth-router.ts +++ b/backend/src/server/routes/v1/identity-oci-auth-router.ts @@ -28,7 +28,17 @@ export const registerIdentityOciAuthRouter = async (server: FastifyZodProvider) .object({ authorization: z.string(), host: z.string(), - "x-date": z.string() + "x-date": z.string().optional(), + date: z.string().optional() + }) + .superRefine((val, ctx) => { + if (!val.date && !val["x-date"]) { + ctx.addIssue({ + code: z.ZodIssueCode.custom, + message: "Either date or x-date must be provided", + path: ["headers", "date"] + }); + } }) .describe(OCI_AUTH.LOGIN.headers) }), diff --git a/backend/src/server/routes/v1/secret-sync-routers/index.ts b/backend/src/server/routes/v1/secret-sync-routers/index.ts index 67b865d31..8e8f696b7 100644 --- a/backend/src/server/routes/v1/secret-sync-routers/index.ts +++ b/backend/src/server/routes/v1/secret-sync-routers/index.ts @@ -21,6 +21,7 @@ import { registerHerokuSyncRouter } from "./heroku-sync-router"; import { registerHumanitecSyncRouter } from "./humanitec-sync-router"; import { registerRailwaySyncRouter } from "./railway-sync-router"; import { registerRenderSyncRouter } from "./render-sync-router"; +import { registerSupabaseSyncRouter } from "./supabase-sync-router"; import { registerTeamCitySyncRouter } from "./teamcity-sync-router"; import { registerTerraformCloudSyncRouter } from "./terraform-cloud-sync-router"; import { registerVercelSyncRouter } from "./vercel-sync-router"; @@ -53,7 +54,7 @@ export const SECRET_SYNC_REGISTER_ROUTER_MAP: Record { diff --git a/backend/src/server/routes/v1/secret-sync-routers/supabase-sync-router.ts b/backend/src/server/routes/v1/secret-sync-routers/supabase-sync-router.ts new file mode 100644 index 000000000..c4343f283 --- /dev/null +++ b/backend/src/server/routes/v1/secret-sync-routers/supabase-sync-router.ts @@ -0,0 +1,17 @@ +import { SecretSync } from "@app/services/secret-sync/secret-sync-enums"; +import { + CreateSupabaseSyncSchema, + SupabaseSyncSchema, + UpdateSupabaseSyncSchema +} from "@app/services/secret-sync/supabase"; + +import { registerSyncSecretsEndpoints } from "./secret-sync-endpoints"; + +export const registerSupabaseSyncRouter = async (server: FastifyZodProvider) => + registerSyncSecretsEndpoints({ + destination: SecretSync.Supabase, + server, + responseSchema: SupabaseSyncSchema, + createSchema: CreateSupabaseSyncSchema, + updateSchema: UpdateSupabaseSyncSchema + }); diff --git a/backend/src/server/routes/v1/sso-router.ts b/backend/src/server/routes/v1/sso-router.ts index 5e2518362..0aec39f3e 100644 --- a/backend/src/server/routes/v1/sso-router.ts +++ b/backend/src/server/routes/v1/sso-router.ts @@ -22,6 +22,7 @@ import { logger } from "@app/lib/logger"; import { ms } from "@app/lib/ms"; import { fetchGithubEmails, fetchGithubUser } from "@app/lib/requests/github"; import { authRateLimit } from "@app/server/config/rateLimiter"; +import { addAuthOriginDomainCookie } from "@app/server/lib/cookie"; import { AuthMethod } from "@app/services/auth/auth-type"; import { OrgAuthMethod } from "@app/services/org/org-types"; import { getServerCfg } from "@app/services/super-admin/super-admin-service"; @@ -475,6 +476,8 @@ export const registerSsoRouter = async (server: FastifyZodProvider) => { secure: appCfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + return { encryptionVersion: data.user.encryptionVersion, token: data.token.access, diff --git a/backend/src/server/routes/v2/mfa-router.ts b/backend/src/server/routes/v2/mfa-router.ts index bdb609432..59a3943f7 100644 --- a/backend/src/server/routes/v2/mfa-router.ts +++ b/backend/src/server/routes/v2/mfa-router.ts @@ -4,6 +4,7 @@ import { getConfig } from "@app/lib/config/env"; import { crypto } from "@app/lib/crypto"; import { BadRequestError, NotFoundError } from "@app/lib/errors"; import { mfaRateLimit } from "@app/server/config/rateLimiter"; +import { addAuthOriginDomainCookie } from "@app/server/lib/cookie"; import { AuthModeMfaJwtTokenPayload, AuthTokenType, MfaMethod } from "@app/services/auth/auth-type"; export const registerMfaRouter = async (server: FastifyZodProvider) => { @@ -131,6 +132,8 @@ export const registerMfaRouter = async (server: FastifyZodProvider) => { secure: appCfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + return { ...user, token: token.access, diff --git a/backend/src/server/routes/v2/organization-router.ts b/backend/src/server/routes/v2/organization-router.ts index fd60316db..c17200a30 100644 --- a/backend/src/server/routes/v2/organization-router.ts +++ b/backend/src/server/routes/v2/organization-router.ts @@ -10,6 +10,7 @@ import { import { ApiDocsTags, ORGANIZATIONS } from "@app/lib/api-docs"; import { getConfig } from "@app/lib/config/env"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { addAuthOriginDomainCookie } from "@app/server/lib/cookie"; import { GenericResourceNameSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { ActorType, AuthMode } from "@app/services/auth/auth-type"; @@ -396,6 +397,8 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => { secure: cfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + return { organization, accessToken: tokens.accessToken }; } }); diff --git a/backend/src/server/routes/v3/login-router.ts b/backend/src/server/routes/v3/login-router.ts index 91df68e16..3a8510f34 100644 --- a/backend/src/server/routes/v3/login-router.ts +++ b/backend/src/server/routes/v3/login-router.ts @@ -3,6 +3,7 @@ import { z } from "zod"; import { INFISICAL_PROVIDER_GITHUB_ACCESS_TOKEN } from "@app/lib/config/const"; import { getConfig } from "@app/lib/config/env"; import { authRateLimit } from "@app/server/config/rateLimiter"; +import { addAuthOriginDomainCookie } from "@app/server/lib/cookie"; export const registerLoginRouter = async (server: FastifyZodProvider) => { server.route({ @@ -93,6 +94,8 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => { secure: cfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + void res.cookie("infisical-project-assume-privileges", "", { httpOnly: true, path: "/", @@ -155,6 +158,8 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => { secure: appCfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + void res.cookie("infisical-project-assume-privileges", "", { httpOnly: true, path: "/", diff --git a/backend/src/server/routes/v3/signup-router.ts b/backend/src/server/routes/v3/signup-router.ts index 393b598cf..391c459a2 100644 --- a/backend/src/server/routes/v3/signup-router.ts +++ b/backend/src/server/routes/v3/signup-router.ts @@ -4,6 +4,7 @@ import { UsersSchema } from "@app/db/schemas"; import { getConfig } from "@app/lib/config/env"; import { ForbiddenRequestError } from "@app/lib/errors"; import { authRateLimit, smtpRateLimit } from "@app/server/config/rateLimiter"; +import { addAuthOriginDomainCookie } from "@app/server/lib/cookie"; import { GenericResourceNameSchema } from "@app/server/lib/schemas"; import { getServerCfg } from "@app/services/super-admin/super-admin-service"; import { PostHogEventTypes } from "@app/services/telemetry/telemetry-types"; @@ -170,6 +171,8 @@ export const registerSignupRouter = async (server: FastifyZodProvider) => { secure: appCfg.HTTPS_ENABLED }); + addAuthOriginDomainCookie(res); + return { message: "Successfully set up account", user, token: accessToken, organizationId }; } }); @@ -239,6 +242,8 @@ export const registerSignupRouter = async (server: FastifyZodProvider) => { }); // TODO(akhilmhdh-pg): add telemetry service + addAuthOriginDomainCookie(res); + return { message: "Successfully set up account", user, token: accessToken }; } }); diff --git a/backend/src/services/app-connection/1password/1password-connection-fns.ts b/backend/src/services/app-connection/1password/1password-connection-fns.ts index d8a18576f..44f3757b2 100644 --- a/backend/src/services/app-connection/1password/1password-connection-fns.ts +++ b/backend/src/services/app-connection/1password/1password-connection-fns.ts @@ -31,12 +31,16 @@ export const validateOnePassConnectionCredentials = async (config: TOnePassConne const { apiToken } = config.credentials; try { - await request.get(`${instanceUrl}/v1/vaults`, { + const res = await request.get(`${instanceUrl}/v1/vaults`, { headers: { Authorization: `Bearer ${apiToken}`, Accept: "application/json" } }); + + if (!Array.isArray(res.data)) { + throw new AxiosError("Invalid response from 1Password API"); + } } catch (error: unknown) { if (error instanceof AxiosError) { throw new BadRequestError({ diff --git a/backend/src/services/app-connection/app-connection-enums.ts b/backend/src/services/app-connection/app-connection-enums.ts index e47ff08a9..233ce0ea8 100644 --- a/backend/src/services/app-connection/app-connection-enums.ts +++ b/backend/src/services/app-connection/app-connection-enums.ts @@ -31,7 +31,8 @@ export enum AppConnection { Zabbix = "zabbix", Railway = "railway", Bitbucket = "bitbucket", - Checkly = "checkly" + Checkly = "checkly", + Supabase = "supabase" } export enum AWSRegion { diff --git a/backend/src/services/app-connection/app-connection-fns.ts b/backend/src/services/app-connection/app-connection-fns.ts index c75745edb..10bab521e 100644 --- a/backend/src/services/app-connection/app-connection-fns.ts +++ b/backend/src/services/app-connection/app-connection-fns.ts @@ -95,6 +95,11 @@ import { getPostgresConnectionListItem, PostgresConnectionMethod } from "./postg import { getRailwayConnectionListItem, validateRailwayConnectionCredentials } from "./railway"; import { RenderConnectionMethod } from "./render/render-connection-enums"; import { getRenderConnectionListItem, validateRenderConnectionCredentials } from "./render/render-connection-fns"; +import { + getSupabaseConnectionListItem, + SupabaseConnectionMethod, + validateSupabaseConnectionCredentials +} from "./supabase"; import { getTeamCityConnectionListItem, TeamCityConnectionMethod, @@ -148,7 +153,8 @@ export const listAppConnectionOptions = () => { getZabbixConnectionListItem(), getRailwayConnectionListItem(), getBitbucketConnectionListItem(), - getChecklyConnectionListItem() + getChecklyConnectionListItem(), + getSupabaseConnectionListItem() ].sort((a, b) => a.name.localeCompare(b.name)); }; @@ -232,7 +238,8 @@ export const validateAppConnectionCredentials = async ( [AppConnection.Zabbix]: validateZabbixConnectionCredentials as TAppConnectionCredentialsValidator, [AppConnection.Railway]: validateRailwayConnectionCredentials as TAppConnectionCredentialsValidator, [AppConnection.Bitbucket]: validateBitbucketConnectionCredentials as TAppConnectionCredentialsValidator, - [AppConnection.Checkly]: validateChecklyConnectionCredentials as TAppConnectionCredentialsValidator + [AppConnection.Checkly]: validateChecklyConnectionCredentials as TAppConnectionCredentialsValidator, + [AppConnection.Supabase]: validateSupabaseConnectionCredentials as TAppConnectionCredentialsValidator }; return VALIDATE_APP_CONNECTION_CREDENTIALS_MAP[appConnection.app](appConnection); @@ -292,6 +299,8 @@ export const getAppConnectionMethodName = (method: TAppConnection["method"]) => case RenderConnectionMethod.ApiKey: case ChecklyConnectionMethod.ApiKey: return "API Key"; + case SupabaseConnectionMethod.AccessToken: + return "Access Token"; default: // eslint-disable-next-line @typescript-eslint/restrict-template-expressions throw new Error(`Unhandled App Connection Method: ${method}`); @@ -355,7 +364,8 @@ export const TRANSITION_CONNECTION_CREDENTIALS_TO_PLATFORM: Record< [AppConnection.Zabbix]: platformManagedCredentialsNotSupported, [AppConnection.Railway]: platformManagedCredentialsNotSupported, [AppConnection.Bitbucket]: platformManagedCredentialsNotSupported, - [AppConnection.Checkly]: platformManagedCredentialsNotSupported + [AppConnection.Checkly]: platformManagedCredentialsNotSupported, + [AppConnection.Supabase]: platformManagedCredentialsNotSupported }; export const enterpriseAppCheck = async ( diff --git a/backend/src/services/app-connection/app-connection-maps.ts b/backend/src/services/app-connection/app-connection-maps.ts index 519a4e5ea..8a85020d8 100644 --- a/backend/src/services/app-connection/app-connection-maps.ts +++ b/backend/src/services/app-connection/app-connection-maps.ts @@ -33,7 +33,8 @@ export const APP_CONNECTION_NAME_MAP: Record = { [AppConnection.Zabbix]: "Zabbix", [AppConnection.Railway]: "Railway", [AppConnection.Bitbucket]: "Bitbucket", - [AppConnection.Checkly]: "Checkly" + [AppConnection.Checkly]: "Checkly", + [AppConnection.Supabase]: "Supabase" }; export const APP_CONNECTION_PLAN_MAP: Record = { @@ -69,5 +70,6 @@ export const APP_CONNECTION_PLAN_MAP: Record>>; @@ -264,6 +271,7 @@ export type TAppConnectionInput = { id: string } & ( | TZabbixConnectionInput | TRailwayConnectionInput | TChecklyConnectionInput + | TSupabaseConnectionInput ); export type TSqlConnectionInput = @@ -311,7 +319,8 @@ export type TAppConnectionConfig = | TBitbucketConnectionConfig | TZabbixConnectionConfig | TRailwayConnectionConfig - | TChecklyConnectionConfig; + | TChecklyConnectionConfig + | TSupabaseConnectionConfig; export type TValidateAppConnectionCredentialsSchema = | TValidateAwsConnectionCredentialsSchema @@ -346,7 +355,8 @@ export type TValidateAppConnectionCredentialsSchema = | TValidateBitbucketConnectionCredentialsSchema | TValidateZabbixConnectionCredentialsSchema | TValidateRailwayConnectionCredentialsSchema - | TValidateChecklyConnectionCredentialsSchema; + | TValidateChecklyConnectionCredentialsSchema + | TValidateSupabaseConnectionCredentialsSchema; export type TListAwsConnectionKmsKeys = { connectionId: string; diff --git a/backend/src/services/app-connection/github-radar/github-radar-connection-fns.ts b/backend/src/services/app-connection/github-radar/github-radar-connection-fns.ts index 84d7a1ce1..fba852a0a 100644 --- a/backend/src/services/app-connection/github-radar/github-radar-connection-fns.ts +++ b/backend/src/services/app-connection/github-radar/github-radar-connection-fns.ts @@ -9,6 +9,7 @@ import { getAppConnectionMethodName } from "@app/services/app-connection/app-con import { IntegrationUrls } from "@app/services/integration-auth/integration-list"; import { AppConnection } from "../app-connection-enums"; +import { GithubTokenRespData, isGithubErrorResponse } from "../github/github-connection-fns"; import { GitHubRadarConnectionMethod } from "./github-radar-connection-enums"; import { TGitHubRadarConnection, @@ -71,13 +72,6 @@ export const listGitHubRadarRepositories = async (appConnection: TGitHubRadarCon return repositories; }; -type TokenRespData = { - access_token: string; - scope: string; - token_type: string; - error?: string; -}; - export const validateGitHubRadarConnectionCredentials = async (config: TGitHubRadarConnectionConfig) => { const { credentials, method } = config; @@ -93,10 +87,10 @@ export const validateGitHubRadarConnectionCredentials = async (config: TGitHubRa }); } - let tokenResp: AxiosResponse; + let tokenResp: AxiosResponse; try { - tokenResp = await request.get("https://github.com/login/oauth/access_token", { + tokenResp = await request.get("https://github.com/login/oauth/access_token", { params: { client_id: INF_APP_CONNECTION_GITHUB_RADAR_APP_CLIENT_ID, client_secret: INF_APP_CONNECTION_GITHUB_RADAR_APP_CLIENT_SECRET, @@ -108,19 +102,27 @@ export const validateGitHubRadarConnectionCredentials = async (config: TGitHubRa "Accept-Encoding": "application/json" } }); + + if (isGithubErrorResponse(tokenResp?.data)) { + throw new BadRequestError({ + message: `Unable to validate credentials: GitHub responded with an error: ${tokenResp.data.error} - ${tokenResp.data.error_description}` + }); + } } catch (e: unknown) { + if (e instanceof BadRequestError) { + throw e; + } + throw new BadRequestError({ message: `Unable to validate connection: verify credentials` }); } - if (tokenResp.status !== 200) { - throw new BadRequestError({ - message: `Unable to validate credentials: GitHub responded with a status code of ${tokenResp.status} (${tokenResp.statusText}). Verify credentials and try again.` - }); - } - if (method === GitHubRadarConnectionMethod.App) { + if (!tokenResp.data.access_token) { + throw new InternalServerError({ message: `Missing access token: ${tokenResp.data.error}` }); + } + const installationsResp = await request.get<{ installations: { id: number; @@ -149,10 +151,6 @@ export const validateGitHubRadarConnectionCredentials = async (config: TGitHubRa } } - if (!tokenResp.data.access_token) { - throw new InternalServerError({ message: `Missing access token: ${tokenResp.data.error}` }); - } - switch (method) { case GitHubRadarConnectionMethod.App: return { diff --git a/backend/src/services/app-connection/github/github-connection-fns.ts b/backend/src/services/app-connection/github/github-connection-fns.ts index d8c98e832..360923e19 100644 --- a/backend/src/services/app-connection/github/github-connection-fns.ts +++ b/backend/src/services/app-connection/github/github-connection-fns.ts @@ -144,13 +144,21 @@ export const getGitHubEnvironments = async (appConnection: TGitHubConnection, ow } }; -type TokenRespData = { - access_token: string; +export type GithubTokenRespData = { + access_token?: string; scope: string; token_type: string; error?: string; }; +export function isGithubErrorResponse(data: GithubTokenRespData): data is GithubTokenRespData & { + error: string; + error_description: string; + error_uri: string; +} { + return "error" in data; +} + export const validateGitHubConnectionCredentials = async (config: TGitHubConnectionConfig) => { const { credentials, method } = config; @@ -183,10 +191,10 @@ export const validateGitHubConnectionCredentials = async (config: TGitHubConnect }); } - let tokenResp: AxiosResponse; + let tokenResp: AxiosResponse; try { - tokenResp = await request.get("https://github.com/login/oauth/access_token", { + tokenResp = await request.get("https://github.com/login/oauth/access_token", { params: { client_id: clientId, client_secret: clientSecret, @@ -198,7 +206,17 @@ export const validateGitHubConnectionCredentials = async (config: TGitHubConnect "Accept-Encoding": "application/json" } }); + + if (isGithubErrorResponse(tokenResp?.data)) { + throw new BadRequestError({ + message: `Unable to validate credentials: GitHub responded with an error: ${tokenResp.data.error} - ${tokenResp.data.error_description}` + }); + } } catch (e: unknown) { + if (e instanceof BadRequestError) { + throw e; + } + throw new BadRequestError({ message: `Unable to validate connection: verify credentials` }); @@ -211,6 +229,10 @@ export const validateGitHubConnectionCredentials = async (config: TGitHubConnect } if (method === GitHubConnectionMethod.App) { + if (!tokenResp.data.access_token) { + throw new InternalServerError({ message: `Missing access token: ${tokenResp.data.error}` }); + } + const installationsResp = await request.get<{ installations: { id: number; @@ -239,10 +261,6 @@ export const validateGitHubConnectionCredentials = async (config: TGitHubConnect } } - if (!tokenResp.data.access_token) { - throw new InternalServerError({ message: `Missing access token: ${tokenResp.data.error}` }); - } - switch (method) { case GitHubConnectionMethod.App: return { diff --git a/backend/src/services/app-connection/supabase/index.ts b/backend/src/services/app-connection/supabase/index.ts new file mode 100644 index 000000000..509204769 --- /dev/null +++ b/backend/src/services/app-connection/supabase/index.ts @@ -0,0 +1,4 @@ +export * from "./supabase-connection-constants"; +export * from "./supabase-connection-fns"; +export * from "./supabase-connection-schemas"; +export * from "./supabase-connection-types"; diff --git a/backend/src/services/app-connection/supabase/supabase-connection-constants.ts b/backend/src/services/app-connection/supabase/supabase-connection-constants.ts new file mode 100644 index 000000000..18ca669b1 --- /dev/null +++ b/backend/src/services/app-connection/supabase/supabase-connection-constants.ts @@ -0,0 +1,3 @@ +export enum SupabaseConnectionMethod { + AccessToken = "access-token" +} diff --git a/backend/src/services/app-connection/supabase/supabase-connection-fns.ts b/backend/src/services/app-connection/supabase/supabase-connection-fns.ts new file mode 100644 index 000000000..579bb5269 --- /dev/null +++ b/backend/src/services/app-connection/supabase/supabase-connection-fns.ts @@ -0,0 +1,58 @@ +/* eslint-disable no-await-in-loop */ +import { AxiosError } from "axios"; + +import { BadRequestError } from "@app/lib/errors"; +import { AppConnection } from "@app/services/app-connection/app-connection-enums"; + +import { SupabaseConnectionMethod } from "./supabase-connection-constants"; +import { SupabasePublicAPI } from "./supabase-connection-public-client"; +import { TSupabaseConnection, TSupabaseConnectionConfig } from "./supabase-connection-types"; + +export const getSupabaseConnectionListItem = () => { + return { + name: "Supabase" as const, + app: AppConnection.Supabase as const, + methods: Object.values(SupabaseConnectionMethod) + }; +}; + +export const validateSupabaseConnectionCredentials = async (config: TSupabaseConnectionConfig) => { + const { credentials } = config; + + try { + await SupabasePublicAPI.healthcheck(config); + } catch (error: unknown) { + if (error instanceof AxiosError) { + throw new BadRequestError({ + message: `Failed to validate credentials: ${error.message || "Unknown error"}` + }); + } + + throw new BadRequestError({ + message: "Unable to validate connection - verify credentials" + }); + } + + return credentials; +}; + +export const listProjects = async (appConnection: TSupabaseConnection) => { + try { + return await SupabasePublicAPI.getProjects(appConnection); + } catch (error: unknown) { + if (error instanceof AxiosError) { + throw new BadRequestError({ + message: `Failed to list projects: ${error.message || "Unknown error"}` + }); + } + + if (error instanceof BadRequestError) { + throw error; + } + + throw new BadRequestError({ + message: "Unable to list projects", + error + }); + } +}; diff --git a/backend/src/services/app-connection/supabase/supabase-connection-public-client.ts b/backend/src/services/app-connection/supabase/supabase-connection-public-client.ts new file mode 100644 index 000000000..3aae50b96 --- /dev/null +++ b/backend/src/services/app-connection/supabase/supabase-connection-public-client.ts @@ -0,0 +1,133 @@ +/* eslint-disable no-await-in-loop */ +/* eslint-disable class-methods-use-this */ +import { AxiosInstance, AxiosRequestConfig, AxiosResponse, HttpStatusCode } from "axios"; + +import { createRequestClient } from "@app/lib/config/request"; +import { delay } from "@app/lib/delay"; +import { removeTrailingSlash } from "@app/lib/fn"; +import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator"; + +import { SupabaseConnectionMethod } from "./supabase-connection-constants"; +import { TSupabaseConnectionConfig, TSupabaseProject, TSupabaseSecret } from "./supabase-connection-types"; + +export const getSupabaseInstanceUrl = async (config: TSupabaseConnectionConfig) => { + const instanceUrl = config.credentials.instanceUrl + ? removeTrailingSlash(config.credentials.instanceUrl) + : "https://api.supabase.com"; + + await blockLocalAndPrivateIpAddresses(instanceUrl); + + return instanceUrl; +}; + +export function getSupabaseAuthHeaders(connection: TSupabaseConnectionConfig): Record { + switch (connection.method) { + case SupabaseConnectionMethod.AccessToken: + return { + Authorization: `Bearer ${connection.credentials.accessKey}` + }; + default: + throw new Error(`Unsupported Supabase connection method`); + } +} + +export function getSupabaseRatelimiter(response: AxiosResponse): { + maxAttempts: number; + isRatelimited: boolean; + wait: () => Promise; +} { + const wait = () => { + return delay(60 * 1000); + }; + + return { + isRatelimited: response.status === HttpStatusCode.TooManyRequests, + wait, + maxAttempts: 3 + }; +} + +class SupabasePublicClient { + private client: AxiosInstance; + + constructor() { + this.client = createRequestClient({ + headers: { + "Content-Type": "application/json" + } + }); + } + + async send( + connection: TSupabaseConnectionConfig, + config: AxiosRequestConfig, + retryAttempt = 0 + ): Promise { + const response = await this.client.request({ + ...config, + baseURL: await getSupabaseInstanceUrl(connection), + validateStatus: (status) => (status >= 200 && status < 300) || status === HttpStatusCode.TooManyRequests, + headers: getSupabaseAuthHeaders(connection) + }); + + const limiter = getSupabaseRatelimiter(response); + + if (limiter.isRatelimited && retryAttempt <= limiter.maxAttempts) { + await limiter.wait(); + return this.send(connection, config, retryAttempt + 1); + } + + return response.data; + } + + async healthcheck(connection: TSupabaseConnectionConfig) { + switch (connection.method) { + case SupabaseConnectionMethod.AccessToken: + return void (await this.getProjects(connection)); + default: + throw new Error(`Unsupported Supabase connection method`); + } + } + + async getVariables(connection: TSupabaseConnectionConfig, projectRef: string) { + const res = await this.send(connection, { + method: "GET", + url: `/v1/projects/${projectRef}/secrets` + }); + + return res; + } + + // Supabase does not support updating variables directly + // Instead, just call create again with the same key and it will overwrite the existing variable + async createVariables(connection: TSupabaseConnectionConfig, projectRef: string, ...variables: TSupabaseSecret[]) { + const res = await this.send(connection, { + method: "POST", + url: `/v1/projects/${projectRef}/secrets`, + data: variables + }); + + return res; + } + + async deleteVariables(connection: TSupabaseConnectionConfig, projectRef: string, ...variables: string[]) { + const res = await this.send(connection, { + method: "DELETE", + url: `/v1/projects/${projectRef}/secrets`, + data: variables + }); + + return res; + } + + async getProjects(connection: TSupabaseConnectionConfig) { + const res = await this.send(connection, { + method: "GET", + url: `/v1/projects` + }); + + return res; + } +} + +export const SupabasePublicAPI = new SupabasePublicClient(); diff --git a/backend/src/services/app-connection/supabase/supabase-connection-schemas.ts b/backend/src/services/app-connection/supabase/supabase-connection-schemas.ts new file mode 100644 index 000000000..9a06b6554 --- /dev/null +++ b/backend/src/services/app-connection/supabase/supabase-connection-schemas.ts @@ -0,0 +1,70 @@ +import z from "zod"; + +import { AppConnections } from "@app/lib/api-docs"; +import { AppConnection } from "@app/services/app-connection/app-connection-enums"; +import { + BaseAppConnectionSchema, + GenericCreateAppConnectionFieldsSchema, + GenericUpdateAppConnectionFieldsSchema +} from "@app/services/app-connection/app-connection-schemas"; + +import { SupabaseConnectionMethod } from "./supabase-connection-constants"; + +export const SupabaseConnectionMethodSchema = z + .nativeEnum(SupabaseConnectionMethod) + .describe(AppConnections.CREATE(AppConnection.Supabase).method); + +export const SupabaseConnectionAccessTokenCredentialsSchema = z.object({ + accessKey: z + .string() + .trim() + .min(1, "Access Key required") + .max(255) + .describe(AppConnections.CREDENTIALS.SUPABASE.accessKey), + instanceUrl: z.string().trim().url().max(255).describe(AppConnections.CREDENTIALS.SUPABASE.instanceUrl).optional() +}); + +const BaseSupabaseConnectionSchema = BaseAppConnectionSchema.extend({ + app: z.literal(AppConnection.Supabase) +}); + +export const SupabaseConnectionSchema = BaseSupabaseConnectionSchema.extend({ + method: SupabaseConnectionMethodSchema, + credentials: SupabaseConnectionAccessTokenCredentialsSchema +}); + +export const SanitizedSupabaseConnectionSchema = z.discriminatedUnion("method", [ + BaseSupabaseConnectionSchema.extend({ + method: SupabaseConnectionMethodSchema, + credentials: SupabaseConnectionAccessTokenCredentialsSchema.pick({ + instanceUrl: true + }) + }) +]); + +export const ValidateSupabaseConnectionCredentialsSchema = z.discriminatedUnion("method", [ + z.object({ + method: SupabaseConnectionMethodSchema, + credentials: SupabaseConnectionAccessTokenCredentialsSchema.describe( + AppConnections.CREATE(AppConnection.Supabase).credentials + ) + }) +]); + +export const CreateSupabaseConnectionSchema = ValidateSupabaseConnectionCredentialsSchema.and( + GenericCreateAppConnectionFieldsSchema(AppConnection.Supabase) +); + +export const UpdateSupabaseConnectionSchema = z + .object({ + credentials: SupabaseConnectionAccessTokenCredentialsSchema.optional().describe( + AppConnections.UPDATE(AppConnection.Supabase).credentials + ) + }) + .and(GenericUpdateAppConnectionFieldsSchema(AppConnection.Supabase)); + +export const SupabaseConnectionListItemSchema = z.object({ + name: z.literal("Supabase"), + app: z.literal(AppConnection.Supabase), + methods: z.nativeEnum(SupabaseConnectionMethod).array() +}); diff --git a/backend/src/services/app-connection/supabase/supabase-connection-service.ts b/backend/src/services/app-connection/supabase/supabase-connection-service.ts new file mode 100644 index 000000000..11cff2b8a --- /dev/null +++ b/backend/src/services/app-connection/supabase/supabase-connection-service.ts @@ -0,0 +1,30 @@ +import { logger } from "@app/lib/logger"; +import { OrgServiceActor } from "@app/lib/types"; + +import { AppConnection } from "../app-connection-enums"; +import { listProjects as getSupabaseProjects } from "./supabase-connection-fns"; +import { TSupabaseConnection } from "./supabase-connection-types"; + +type TGetAppConnectionFunc = ( + app: AppConnection, + connectionId: string, + actor: OrgServiceActor +) => Promise; + +export const supabaseConnectionService = (getAppConnection: TGetAppConnectionFunc) => { + const listProjects = async (connectionId: string, actor: OrgServiceActor) => { + const appConnection = await getAppConnection(AppConnection.Supabase, connectionId, actor); + try { + const projects = await getSupabaseProjects(appConnection); + + return projects ?? []; + } catch (error) { + logger.error(error, "Failed to establish connection with Supabase"); + return []; + } + }; + + return { + listProjects + }; +}; diff --git a/backend/src/services/app-connection/supabase/supabase-connection-types.ts b/backend/src/services/app-connection/supabase/supabase-connection-types.ts new file mode 100644 index 000000000..8bf810c1d --- /dev/null +++ b/backend/src/services/app-connection/supabase/supabase-connection-types.ts @@ -0,0 +1,44 @@ +import z from "zod"; + +import { DiscriminativePick } from "@app/lib/types"; + +import { AppConnection } from "../app-connection-enums"; +import { + CreateSupabaseConnectionSchema, + SupabaseConnectionSchema, + ValidateSupabaseConnectionCredentialsSchema +} from "./supabase-connection-schemas"; + +export type TSupabaseConnection = z.infer; + +export type TSupabaseConnectionInput = z.infer & { + app: AppConnection.Supabase; +}; + +export type TValidateSupabaseConnectionCredentialsSchema = typeof ValidateSupabaseConnectionCredentialsSchema; + +export type TSupabaseConnectionConfig = DiscriminativePick & { + orgId: string; +}; + +export type TSupabaseProject = { + id: string; + organization_id: string; + name: string; + region: string; + created_at: Date; + status: string; + database: TSupabaseDatabase; +}; + +type TSupabaseDatabase = { + host: string; + version: string; + postgres_engine: string; + release_channel: string; +}; + +export type TSupabaseSecret = { + name: string; + value: string; +}; diff --git a/backend/src/services/certificate-authority/certificate-authority-dal.ts b/backend/src/services/certificate-authority/certificate-authority-dal.ts index d5a45ce50..352675441 100644 --- a/backend/src/services/certificate-authority/certificate-authority-dal.ts +++ b/backend/src/services/certificate-authority/certificate-authority-dal.ts @@ -218,7 +218,7 @@ export const certificateAuthorityDALFactory = (db: TDbClient) => { }; const findWithAssociatedCa = async ( - filter: Parameters<(typeof caOrm)["find"]>[0] & { dn?: string; type?: string }, + filter: Parameters<(typeof caOrm)["find"]>[0] & { dn?: string; type?: string; serialNumber?: string }, { offset, limit, sort = [["createdAt", "desc"]] }: TFindOpt = {}, tx?: Knex ) => { diff --git a/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts b/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts index 6668c806c..80201eab6 100644 --- a/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts +++ b/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts @@ -1068,11 +1068,11 @@ export const internalCertificateAuthorityServiceFactory = ({ throw new BadRequestError({ message: "Invalid certificate chain" }); const parentCertObj = chainItems[1]; - const parentCertSubject = parentCertObj.subject; + const parentSerialNumber = parentCertObj.serialNumber; const [parentCa] = await certificateAuthorityDAL.findWithAssociatedCa({ [`${TableName.CertificateAuthority}.projectId` as "projectId"]: ca.projectId, - [`${TableName.InternalCertificateAuthority}.dn` as "dn"]: parentCertSubject + [`${TableName.InternalCertificateAuthority}.serialNumber` as "serialNumber"]: parentSerialNumber }); const certificateManagerKmsId = await getProjectKmsCertificateKeyId({ diff --git a/backend/src/services/identity-oci-auth/identity-oci-auth-types.ts b/backend/src/services/identity-oci-auth/identity-oci-auth-types.ts index c7a131bde..8eb33a866 100644 --- a/backend/src/services/identity-oci-auth/identity-oci-auth-types.ts +++ b/backend/src/services/identity-oci-auth/identity-oci-auth-types.ts @@ -6,7 +6,8 @@ export type TLoginOciAuthDTO = { headers: { authorization: string; host: string; - "x-date": string; + "x-date"?: string; + date?: string; }; }; diff --git a/backend/src/services/secret-import/secret-import-fns.ts b/backend/src/services/secret-import/secret-import-fns.ts index c68033911..6aa73465d 100644 --- a/backend/src/services/secret-import/secret-import-fns.ts +++ b/backend/src/services/secret-import/secret-import-fns.ts @@ -174,6 +174,7 @@ export const fnSecretsV2FromImports = async ({ skipMultilineEncoding?: boolean | null; secretPath: string; environment: string; + secretKey: string; }) => Promise; hasSecretAccess: (environment: string, secretPath: string, secretName: string, secretTagSlugs: string[]) => boolean; }) => { @@ -293,7 +294,8 @@ export const fnSecretsV2FromImports = async ({ value: decryptedSecret.secretValue, secretPath: processedImport.secretPath, environment: processedImport.environment, - skipMultilineEncoding: decryptedSecret.skipMultilineEncoding + skipMultilineEncoding: decryptedSecret.skipMultilineEncoding, + secretKey: decryptedSecret.secretKey }); // eslint-disable-next-line no-param-reassign processedImport.secrets[index].secretValue = expandedSecretValue || ""; diff --git a/backend/src/services/secret-sync/render/render-sync-fns.ts b/backend/src/services/secret-sync/render/render-sync-fns.ts index 8a9039e2e..9140136a0 100644 --- a/backend/src/services/secret-sync/render/render-sync-fns.ts +++ b/backend/src/services/secret-sync/render/render-sync-fns.ts @@ -1,4 +1,6 @@ /* eslint-disable no-await-in-loop */ +import { isAxiosError } from "axios"; + import { request } from "@app/lib/config/request"; import { IntegrationUrls } from "@app/services/integration-auth/integration-list"; import { matchesSchema } from "@app/services/secret-sync/secret-sync-fns"; @@ -71,7 +73,7 @@ const putEnvironmentSecret = async (secretSync: TRenderSyncWithCredentials, secr ); }; -const deleteEnvironmentSecret = async (secretSync: TRenderSyncWithCredentials, secret: TRenderSecret) => { +const deleteEnvironmentSecret = async (secretSync: TRenderSyncWithCredentials, secret: Pick) => { const { destinationConfig, connection: { @@ -79,15 +81,24 @@ const deleteEnvironmentSecret = async (secretSync: TRenderSyncWithCredentials, s } } = secretSync; - await request.delete( - `${IntegrationUrls.RENDER_API_URL}/v1/services/${destinationConfig.serviceId}/env-vars/${secret.key}`, - { - headers: { - Authorization: `Bearer ${apiKey}`, - Accept: "application/json" + try { + await request.delete( + `${IntegrationUrls.RENDER_API_URL}/v1/services/${destinationConfig.serviceId}/env-vars/${secret.key}`, + { + headers: { + Authorization: `Bearer ${apiKey}`, + Accept: "application/json" + } } + ); + } catch (error) { + if (isAxiosError(error) && error.response?.status === 404) { + // If the secret does not exist, we can ignore this error + return; } - ); + + throw error; + } }; const sleep = async () => @@ -99,6 +110,11 @@ export const RenderSyncFns = { syncSecrets: async (secretSync: TRenderSyncWithCredentials, secretMap: TSecretMap) => { const renderSecrets = await getRenderEnvironmentSecrets(secretSync); for await (const key of Object.keys(secretMap)) { + // If value is empty skip it as render does not allow empty variables + if (secretMap[key].value === "") { + // eslint-disable-next-line no-continue + continue; + } await putEnvironmentSecret(secretSync, secretMap, key); await sleep(); } diff --git a/backend/src/services/secret-sync/secret-sync-enums.ts b/backend/src/services/secret-sync/secret-sync-enums.ts index 7e377ee13..8d08e4d82 100644 --- a/backend/src/services/secret-sync/secret-sync-enums.ts +++ b/backend/src/services/secret-sync/secret-sync-enums.ts @@ -22,7 +22,7 @@ export enum SecretSync { GitLab = "gitlab", CloudflarePages = "cloudflare-pages", CloudflareWorkers = "cloudflare-workers", - + Supabase = "supabase", Zabbix = "zabbix", Railway = "railway", Checkly = "checkly" diff --git a/backend/src/services/secret-sync/secret-sync-fns.ts b/backend/src/services/secret-sync/secret-sync-fns.ts index a755c97b7..3daa9232f 100644 --- a/backend/src/services/secret-sync/secret-sync-fns.ts +++ b/backend/src/services/secret-sync/secret-sync-fns.ts @@ -46,6 +46,7 @@ import { RAILWAY_SYNC_LIST_OPTION } from "./railway/railway-sync-constants"; import { RailwaySyncFns } from "./railway/railway-sync-fns"; import { RENDER_SYNC_LIST_OPTION, RenderSyncFns } from "./render"; import { SECRET_SYNC_PLAN_MAP } from "./secret-sync-maps"; +import { SUPABASE_SYNC_LIST_OPTION, SupabaseSyncFns } from "./supabase"; import { TEAMCITY_SYNC_LIST_OPTION, TeamCitySyncFns } from "./teamcity"; import { TERRAFORM_CLOUD_SYNC_LIST_OPTION, TerraformCloudSyncFns } from "./terraform-cloud"; import { VERCEL_SYNC_LIST_OPTION, VercelSyncFns } from "./vercel"; @@ -76,7 +77,7 @@ const SECRET_SYNC_LIST_OPTIONS: Record = { [SecretSync.GitLab]: GITLAB_SYNC_LIST_OPTION, [SecretSync.CloudflarePages]: CLOUDFLARE_PAGES_SYNC_LIST_OPTION, [SecretSync.CloudflareWorkers]: CLOUDFLARE_WORKERS_SYNC_LIST_OPTION, - + [SecretSync.Supabase]: SUPABASE_SYNC_LIST_OPTION, [SecretSync.Zabbix]: ZABBIX_SYNC_LIST_OPTION, [SecretSync.Railway]: RAILWAY_SYNC_LIST_OPTION, [SecretSync.Checkly]: CHECKLY_SYNC_LIST_OPTION @@ -255,6 +256,8 @@ export const SecretSyncFns = { return RailwaySyncFns.syncSecrets(secretSync, schemaSecretMap); case SecretSync.Checkly: return ChecklySyncFns.syncSecrets(secretSync, schemaSecretMap); + case SecretSync.Supabase: + return SupabaseSyncFns.syncSecrets(secretSync, schemaSecretMap); default: throw new Error( `Unhandled sync destination for sync secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}` @@ -359,6 +362,9 @@ export const SecretSyncFns = { case SecretSync.Checkly: secretMap = await ChecklySyncFns.getSecrets(secretSync); break; + case SecretSync.Supabase: + secretMap = await SupabaseSyncFns.getSecrets(secretSync); + break; default: throw new Error( `Unhandled sync destination for get secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}` @@ -444,6 +450,8 @@ export const SecretSyncFns = { return RailwaySyncFns.removeSecrets(secretSync, schemaSecretMap); case SecretSync.Checkly: return ChecklySyncFns.removeSecrets(secretSync, schemaSecretMap); + case SecretSync.Supabase: + return SupabaseSyncFns.removeSecrets(secretSync, schemaSecretMap); default: throw new Error( `Unhandled sync destination for remove secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}` diff --git a/backend/src/services/secret-sync/secret-sync-maps.ts b/backend/src/services/secret-sync/secret-sync-maps.ts index a83418d15..a8a017480 100644 --- a/backend/src/services/secret-sync/secret-sync-maps.ts +++ b/backend/src/services/secret-sync/secret-sync-maps.ts @@ -25,7 +25,7 @@ export const SECRET_SYNC_NAME_MAP: Record = { [SecretSync.GitLab]: "GitLab", [SecretSync.CloudflarePages]: "Cloudflare Pages", [SecretSync.CloudflareWorkers]: "Cloudflare Workers", - + [SecretSync.Supabase]: "Supabase", [SecretSync.Zabbix]: "Zabbix", [SecretSync.Railway]: "Railway", [SecretSync.Checkly]: "Checkly" @@ -55,7 +55,7 @@ export const SECRET_SYNC_CONNECTION_MAP: Record = { [SecretSync.GitLab]: AppConnection.GitLab, [SecretSync.CloudflarePages]: AppConnection.Cloudflare, [SecretSync.CloudflareWorkers]: AppConnection.Cloudflare, - + [SecretSync.Supabase]: AppConnection.Supabase, [SecretSync.Zabbix]: AppConnection.Zabbix, [SecretSync.Railway]: AppConnection.Railway, [SecretSync.Checkly]: AppConnection.Checkly @@ -85,7 +85,7 @@ export const SECRET_SYNC_PLAN_MAP: Record = { [SecretSync.GitLab]: SecretSyncPlanType.Regular, [SecretSync.CloudflarePages]: SecretSyncPlanType.Regular, [SecretSync.CloudflareWorkers]: SecretSyncPlanType.Regular, - + [SecretSync.Supabase]: SecretSyncPlanType.Regular, [SecretSync.Zabbix]: SecretSyncPlanType.Regular, [SecretSync.Railway]: SecretSyncPlanType.Regular, [SecretSync.Checkly]: SecretSyncPlanType.Regular diff --git a/backend/src/services/secret-sync/secret-sync-queue.ts b/backend/src/services/secret-sync/secret-sync-queue.ts index 2acba91e5..8f5a2e806 100644 --- a/backend/src/services/secret-sync/secret-sync-queue.ts +++ b/backend/src/services/secret-sync/secret-sync-queue.ts @@ -231,7 +231,8 @@ export const secretSyncQueueFactory = ({ environment: environment.slug, secretPath: folder.path, skipMultilineEncoding: secret.skipMultilineEncoding, - value: secretValue + value: secretValue, + secretKey }); secretMap[secretKey] = { value: expandedSecretValue || "" }; diff --git a/backend/src/services/secret-sync/secret-sync-types.ts b/backend/src/services/secret-sync/secret-sync-types.ts index 3fcef9493..2c8753d66 100644 --- a/backend/src/services/secret-sync/secret-sync-types.ts +++ b/backend/src/services/secret-sync/secret-sync-types.ts @@ -118,6 +118,12 @@ import { TRenderSyncListItem, TRenderSyncWithCredentials } from "./render/render-sync-types"; +import { + TSupabaseSync, + TSupabaseSyncInput, + TSupabaseSyncListItem, + TSupabaseSyncWithCredentials +} from "./supabase/supabase-sync-types"; import { TTeamCitySync, TTeamCitySyncInput, @@ -159,7 +165,8 @@ export type TSecretSync = | TCloudflareWorkersSync | TZabbixSync | TRailwaySync - | TChecklySync; + | TChecklySync + | TSupabaseSync; export type TSecretSyncWithCredentials = | TAwsParameterStoreSyncWithCredentials @@ -187,7 +194,8 @@ export type TSecretSyncWithCredentials = | TCloudflareWorkersSyncWithCredentials | TZabbixSyncWithCredentials | TRailwaySyncWithCredentials - | TChecklySyncWithCredentials; + | TChecklySyncWithCredentials + | TSupabaseSyncWithCredentials; export type TSecretSyncInput = | TAwsParameterStoreSyncInput @@ -215,7 +223,8 @@ export type TSecretSyncInput = | TCloudflareWorkersSyncInput | TZabbixSyncInput | TRailwaySyncInput - | TChecklySyncInput; + | TChecklySyncInput + | TSupabaseSyncInput; export type TSecretSyncListItem = | TAwsParameterStoreSyncListItem @@ -243,7 +252,8 @@ export type TSecretSyncListItem = | TCloudflareWorkersSyncListItem | TZabbixSyncListItem | TRailwaySyncListItem - | TChecklySyncListItem; + | TChecklySyncListItem + | TSupabaseSyncListItem; export type TSyncOptionsConfig = { canImportSecrets: boolean; diff --git a/backend/src/services/secret-sync/supabase/index.ts b/backend/src/services/secret-sync/supabase/index.ts new file mode 100644 index 000000000..0e1292f35 --- /dev/null +++ b/backend/src/services/secret-sync/supabase/index.ts @@ -0,0 +1,4 @@ +export * from "./supabase-sync-constants"; +export * from "./supabase-sync-fns"; +export * from "./supabase-sync-schemas"; +export * from "./supabase-sync-types"; diff --git a/backend/src/services/secret-sync/supabase/supabase-sync-constants.ts b/backend/src/services/secret-sync/supabase/supabase-sync-constants.ts new file mode 100644 index 000000000..319fcc82e --- /dev/null +++ b/backend/src/services/secret-sync/supabase/supabase-sync-constants.ts @@ -0,0 +1,10 @@ +import { AppConnection } from "@app/services/app-connection/app-connection-enums"; +import { SecretSync } from "@app/services/secret-sync/secret-sync-enums"; +import { TSecretSyncListItem } from "@app/services/secret-sync/secret-sync-types"; + +export const SUPABASE_SYNC_LIST_OPTION: TSecretSyncListItem = { + name: "Supabase", + destination: SecretSync.Supabase, + connection: AppConnection.Supabase, + canImportSecrets: false +}; diff --git a/backend/src/services/secret-sync/supabase/supabase-sync-fns.ts b/backend/src/services/secret-sync/supabase/supabase-sync-fns.ts new file mode 100644 index 000000000..b8106a0ae --- /dev/null +++ b/backend/src/services/secret-sync/supabase/supabase-sync-fns.ts @@ -0,0 +1,102 @@ +/* eslint-disable no-continue */ +/* eslint-disable @typescript-eslint/no-unsafe-member-access */ +/* eslint-disable @typescript-eslint/no-unsafe-assignment */ + +import { chunkArray } from "@app/lib/fn"; +import { TSupabaseSecret } from "@app/services/app-connection/supabase"; +import { SupabasePublicAPI } from "@app/services/app-connection/supabase/supabase-connection-public-client"; +import { matchesSchema } from "@app/services/secret-sync/secret-sync-fns"; + +import { SecretSyncError } from "../secret-sync-errors"; +import { SECRET_SYNC_NAME_MAP } from "../secret-sync-maps"; +import { TSecretMap } from "../secret-sync-types"; +import { TSupabaseSyncWithCredentials } from "./supabase-sync-types"; + +const SUPABASE_INTERNAL_SECRETS = ["SUPABASE_URL", "SUPABASE_ANON_KEY", "SUPABASE_SERVICE_ROLE_KEY", "SUPABASE_DB_URL"]; + +export const SupabaseSyncFns = { + async getSecrets(secretSync: TSupabaseSyncWithCredentials) { + throw new Error(`${SECRET_SYNC_NAME_MAP[secretSync.destination]} does not support importing secrets.`); + }, + + async syncSecrets(secretSync: TSupabaseSyncWithCredentials, secretMap: TSecretMap) { + const { + environment, + syncOptions: { disableSecretDeletion, keySchema } + } = secretSync; + const config = secretSync.destinationConfig; + + const variables = await SupabasePublicAPI.getVariables(secretSync.connection, config.projectId); + + const supabaseSecrets = new Map(variables!.map((variable) => [variable.name, variable])); + + const toCreate: TSupabaseSecret[] = []; + + for (const key of Object.keys(secretMap)) { + const variable: TSupabaseSecret = { name: key, value: secretMap[key].value ?? "" }; + toCreate.push(variable); + } + + for await (const batch of chunkArray(toCreate, 100)) { + try { + await SupabasePublicAPI.createVariables(secretSync.connection, config.projectId, ...batch); + } catch (error) { + throw new SecretSyncError({ + error, + secretKey: batch[0].name // Use the first key in the batch for error reporting + }); + } + } + + if (disableSecretDeletion) return; + + const toDelete: string[] = []; + + for (const key of supabaseSecrets.keys()) { + // eslint-disable-next-line no-continue + if (!matchesSchema(key, environment?.slug || "", keySchema) || SUPABASE_INTERNAL_SECRETS.includes(key)) continue; + + if (!secretMap[key]) { + toDelete.push(key); + } + } + + for await (const batch of chunkArray(toDelete, 100)) { + try { + await SupabasePublicAPI.deleteVariables(secretSync.connection, config.projectId, ...batch); + } catch (error) { + throw new SecretSyncError({ + error, + secretKey: batch[0] // Use the first key in the batch for error reporting + }); + } + } + }, + + async removeSecrets(secretSync: TSupabaseSyncWithCredentials, secretMap: TSecretMap) { + const config = secretSync.destinationConfig; + + const variables = await SupabasePublicAPI.getVariables(secretSync.connection, config.projectId); + + const supabaseSecrets = new Map(variables!.map((variable) => [variable.name, variable])); + + const toDelete: string[] = []; + + for (const key of supabaseSecrets.keys()) { + if (SUPABASE_INTERNAL_SECRETS.includes(key) || !(key in secretMap)) continue; + + toDelete.push(key); + } + + for await (const batch of chunkArray(toDelete, 100)) { + try { + await SupabasePublicAPI.deleteVariables(secretSync.connection, config.projectId, ...batch); + } catch (error) { + throw new SecretSyncError({ + error, + secretKey: batch[0] // Use the first key in the batch for error reporting + }); + } + } + } +}; diff --git a/backend/src/services/secret-sync/supabase/supabase-sync-schemas.ts b/backend/src/services/secret-sync/supabase/supabase-sync-schemas.ts new file mode 100644 index 000000000..633b40dab --- /dev/null +++ b/backend/src/services/secret-sync/supabase/supabase-sync-schemas.ts @@ -0,0 +1,43 @@ +import { z } from "zod"; + +import { AppConnection } from "@app/services/app-connection/app-connection-enums"; +import { SecretSync } from "@app/services/secret-sync/secret-sync-enums"; +import { + BaseSecretSyncSchema, + GenericCreateSecretSyncFieldsSchema, + GenericUpdateSecretSyncFieldsSchema +} from "@app/services/secret-sync/secret-sync-schemas"; +import { TSyncOptionsConfig } from "@app/services/secret-sync/secret-sync-types"; + +const SupabaseSyncDestinationConfigSchema = z.object({ + projectId: z.string().max(255).min(1, "Project ID is required"), + projectName: z.string().max(255).min(1, "Project Name is required") +}); + +const SupabaseSyncOptionsConfig: TSyncOptionsConfig = { canImportSecrets: false }; + +export const SupabaseSyncSchema = BaseSecretSyncSchema(SecretSync.Supabase, SupabaseSyncOptionsConfig).extend({ + destination: z.literal(SecretSync.Supabase), + destinationConfig: SupabaseSyncDestinationConfigSchema +}); + +export const CreateSupabaseSyncSchema = GenericCreateSecretSyncFieldsSchema( + SecretSync.Supabase, + SupabaseSyncOptionsConfig +).extend({ + destinationConfig: SupabaseSyncDestinationConfigSchema +}); + +export const UpdateSupabaseSyncSchema = GenericUpdateSecretSyncFieldsSchema( + SecretSync.Supabase, + SupabaseSyncOptionsConfig +).extend({ + destinationConfig: SupabaseSyncDestinationConfigSchema.optional() +}); + +export const SupabaseSyncListItemSchema = z.object({ + name: z.literal("Supabase"), + connection: z.literal(AppConnection.Supabase), + destination: z.literal(SecretSync.Supabase), + canImportSecrets: z.literal(false) +}); diff --git a/backend/src/services/secret-sync/supabase/supabase-sync-types.ts b/backend/src/services/secret-sync/supabase/supabase-sync-types.ts new file mode 100644 index 000000000..a222748a8 --- /dev/null +++ b/backend/src/services/secret-sync/supabase/supabase-sync-types.ts @@ -0,0 +1,21 @@ +import z from "zod"; + +import { TSupabaseConnection } from "@app/services/app-connection/supabase"; + +import { CreateSupabaseSyncSchema, SupabaseSyncListItemSchema, SupabaseSyncSchema } from "./supabase-sync-schemas"; + +export type TSupabaseSyncListItem = z.infer; + +export type TSupabaseSync = z.infer; + +export type TSupabaseSyncInput = z.infer; + +export type TSupabaseSyncWithCredentials = TSupabaseSync & { + connection: TSupabaseConnection; +}; + +export type TSupabaseVariablesGraphResponse = { + data: { + variables: Record; + }; +}; diff --git a/backend/src/services/secret-v2-bridge/secret-v2-bridge-fns.ts b/backend/src/services/secret-v2-bridge/secret-v2-bridge-fns.ts index 3cab7ec3c..7402d3106 100644 --- a/backend/src/services/secret-v2-bridge/secret-v2-bridge-fns.ts +++ b/backend/src/services/secret-v2-bridge/secret-v2-bridge-fns.ts @@ -629,6 +629,7 @@ export const expandSecretReferencesFactory = ({ secretPath: string; environment: string; shouldStackTrace?: boolean; + secretKey: string; }) => { const stackTrace = { ...dto, key: "root", children: [] } as TSecretReferenceTraceNode; @@ -671,7 +672,7 @@ export const expandSecretReferencesFactory = ({ const referredValue = await fetchSecret(environment, secretPath, secretKey); if (!canExpandValue(environment, secretPath, secretKey, referredValue.tags)) throw new ForbiddenRequestError({ - message: `You are attempting to reference secret named ${secretKey} from environment ${environment} in path ${secretPath} which you do not have access to read value on.` + message: `You do not have permission to read secret '${secretKey}' in environment '${environment}' at path '${secretPath}', which is referenced by secret '${dto.secretKey}' in environment '${dto.environment}' at path '${dto.secretPath}'.` }); const cacheKey = getCacheUniqueKey(environment, secretPath); @@ -690,7 +691,7 @@ export const expandSecretReferencesFactory = ({ const referedValue = await fetchSecret(secretReferenceEnvironment, secretReferencePath, secretReferenceKey); if (!canExpandValue(secretReferenceEnvironment, secretReferencePath, secretReferenceKey, referedValue.tags)) throw new ForbiddenRequestError({ - message: `You are attempting to reference secret named ${secretReferenceKey} from environment ${secretReferenceEnvironment} in path ${secretReferencePath} which you do not have access to read value on.` + message: `You do not have permission to read secret '${secretReferenceKey}' in environment '${secretReferenceEnvironment}' at path '${secretReferencePath}', which is referenced by secret '${dto.secretKey}' in environment '${dto.environment}' at path '${dto.secretPath}'.` }); const cacheKey = getCacheUniqueKey(secretReferenceEnvironment, secretReferencePath); @@ -707,6 +708,7 @@ export const expandSecretReferencesFactory = ({ secretPath: referencedSecretPath, environment: referencedSecretEnvironmentSlug, depth: depth + 1, + secretKey: referencedSecretKey, trace }; @@ -741,6 +743,7 @@ export const expandSecretReferencesFactory = ({ skipMultilineEncoding?: boolean | null; secretPath: string; environment: string; + secretKey: string; }) => { if (!inputSecret.value) return inputSecret.value; @@ -756,6 +759,7 @@ export const expandSecretReferencesFactory = ({ value?: string; secretPath: string; environment: string; + secretKey: string; }) => { const { stackTrace, expandedValue } = await recursivelyExpandSecret({ ...inputSecret, shouldStackTrace: true }); return { stackTrace, expandedValue }; diff --git a/backend/src/services/secret-v2-bridge/secret-v2-bridge-service.ts b/backend/src/services/secret-v2-bridge/secret-v2-bridge-service.ts index 5baed1d32..8f082df03 100644 --- a/backend/src/services/secret-v2-bridge/secret-v2-bridge-service.ts +++ b/backend/src/services/secret-v2-bridge/secret-v2-bridge-service.ts @@ -1105,7 +1105,7 @@ export const secretV2BridgeServiceFactory = ({ if (shouldExpandSecretReferences) { const secretsGroupByPath = groupBy(decryptedSecrets, (i) => i.secretPath); - await Promise.allSettled( + const settledPromises = await Promise.allSettled( Object.keys(secretsGroupByPath).map((groupedPath) => Promise.allSettled( secretsGroupByPath[groupedPath].map(async (decryptedSecret, index) => { @@ -1113,7 +1113,8 @@ export const secretV2BridgeServiceFactory = ({ value: decryptedSecret.secretValue, secretPath: groupedPath, environment, - skipMultilineEncoding: decryptedSecret.skipMultilineEncoding + skipMultilineEncoding: decryptedSecret.skipMultilineEncoding, + secretKey: decryptedSecret.secretKey }); // eslint-disable-next-line no-param-reassign secretsGroupByPath[groupedPath][index].secretValue = expandedSecretValue || ""; @@ -1121,6 +1122,35 @@ export const secretV2BridgeServiceFactory = ({ ) ) ); + const errors: { path: string; error: string }[] = []; + + settledPromises.forEach((outerResult: PromiseSettledResult[]>, outerIndex) => { + const groupedPath = Object.keys(secretsGroupByPath)[outerIndex]; + + if (outerResult.status === "rejected") { + errors.push({ + path: groupedPath, + error: `Failed to process secret group: ${outerResult.reason}` + }); + } else { + // Check inner promise results + outerResult.value.forEach((innerResult: PromiseSettledResult) => { + if (innerResult.status === "rejected") { + const reason = innerResult.reason as ForbiddenRequestError; + errors.push({ + path: groupedPath, + error: reason.message + }); + } + }); + } + }); + if (errors.length > 0) { + throw new ForbiddenRequestError({ + message: "Failed to expand one or more secret references", + details: errors.map((err) => err.error) + }); + } } if (!includeImports) { @@ -1424,7 +1454,8 @@ export const secretV2BridgeServiceFactory = ({ environment, secretPath: path, value: secretValue, - skipMultilineEncoding: secret.skipMultilineEncoding + skipMultilineEncoding: secret.skipMultilineEncoding, + secretKey: secret.key }); secretValue = expandedSecretValue || ""; @@ -2748,7 +2779,8 @@ export const secretV2BridgeServiceFactory = ({ const { expandedValue, stackTrace } = await getExpandedSecretStackTrace({ environment, secretPath, - value: decryptedSecretValue + value: decryptedSecretValue, + secretKey: secretName }); return { tree: stackTrace, value: expandedValue }; diff --git a/backend/src/services/secret/secret-queue.ts b/backend/src/services/secret/secret-queue.ts index 8fcaa6e34..b178aa8e1 100644 --- a/backend/src/services/secret/secret-queue.ts +++ b/backend/src/services/secret/secret-queue.ts @@ -426,7 +426,8 @@ export const secretQueueFactory = ({ environment: dto.environment, secretPath: dto.secretPath, skipMultilineEncoding: secret.skipMultilineEncoding, - value: secretValue + value: secretValue, + secretKey }); content[secretKey] = { value: expandedSecretValue || "" }; diff --git a/company/documentation/engineering/how-to-write-design-doc.mdx b/company/documentation/engineering/how-to-write-design-doc.mdx index 753f884b0..0c6128824 100644 --- a/company/documentation/engineering/how-to-write-design-doc.mdx +++ b/company/documentation/engineering/how-to-write-design-doc.mdx @@ -33,6 +33,7 @@ Every feature/problem is unique, but your design docs should generally include t - A high-level summary of the problem and proposed solution. Keep it brief (max 3 paragraphs). 3. **Context** - Explain the problem's background, why it's important to solve now, and any constraints (e.g., technical, sales, or timeline-related). What do we get out of solving this problem? (needed to close a deal, scale, performance, etc.). + - Consider whether this feature has notable sales implications (e.g., affects pricing, customer commitments, go-to-market strategy, or competitive positioning) that would require Sales team input and approval. 4. **Solution** - Provide a big-picture explanation of the solution, followed by detailed technical architecture. @@ -76,3 +77,11 @@ Before sharing your design docs with others, review your design doc as if you we - Ask a relevant engineer(s) to review your document. Their role is to identify blind spots, challenge assumptions, and ensure everything is clear. Once you and the reviewer are on the same page on the approach, update the document with any missing details they brought up. 4. **Team Review and Feedback** - Invite the relevant engineers to a design doc review meeting and give them 10-15 minutes to read through the document. After everyone has had a chance to review it, open the floor up for discussion. Address any feedback or concerns raised during this meeting. If significant points were overlooked during your initial planning, you may need to revisit the drawing board. Your goal is to think about the feature holistically and minimize the need for drastic changes to your design doc later on. +5. **Sales Approval (When Applicable)** + - If your design document has notable sales implications, get explicit approval from the Sales team before proceeding to implementation. This includes features that: + - Affect pricing models or billing structures + - Impact customer commitments or contractual obligations + - Change core product functionality that's actively being sold + - Introduce new capabilities that could affect competitive positioning + - Modify user experience in ways that could impact customer acquisition or retention + - Share the design document with the Sales team to ensure alignment between the proposed technical approach and sales strategy, pricing models, and market positioning. diff --git a/docs/api-reference/endpoints/app-connections/supabase/available.mdx b/docs/api-reference/endpoints/app-connections/supabase/available.mdx new file mode 100644 index 000000000..136a56749 --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/available.mdx @@ -0,0 +1,4 @@ +--- +title: "Available" +openapi: "GET /api/v1/app-connections/supabase/available" +--- diff --git a/docs/api-reference/endpoints/app-connections/supabase/create.mdx b/docs/api-reference/endpoints/app-connections/supabase/create.mdx new file mode 100644 index 000000000..4b9717d98 --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/create.mdx @@ -0,0 +1,8 @@ +--- +title: "Create" +openapi: "POST /api/v1/app-connections/supabase" +--- + + + Check out the configuration docs for [Supabase Connections](/integrations/app-connections/supabase) to learn how to obtain the required credentials. + diff --git a/docs/api-reference/endpoints/app-connections/supabase/delete.mdx b/docs/api-reference/endpoints/app-connections/supabase/delete.mdx new file mode 100644 index 000000000..f116f5dd7 --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/delete.mdx @@ -0,0 +1,4 @@ +--- +title: "Delete" +openapi: "DELETE /api/v1/app-connections/supabase/{connectionId}" +--- diff --git a/docs/api-reference/endpoints/app-connections/supabase/get-by-id.mdx b/docs/api-reference/endpoints/app-connections/supabase/get-by-id.mdx new file mode 100644 index 000000000..007a100fe --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/get-by-id.mdx @@ -0,0 +1,4 @@ +--- +title: "Get by ID" +openapi: "GET /api/v1/app-connections/supabase/{connectionId}" +--- diff --git a/docs/api-reference/endpoints/app-connections/supabase/get-by-name.mdx b/docs/api-reference/endpoints/app-connections/supabase/get-by-name.mdx new file mode 100644 index 000000000..3c968cc76 --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/get-by-name.mdx @@ -0,0 +1,4 @@ +--- +title: "Get by Name" +openapi: "GET /api/v1/app-connections/supabase/connection-name/{connectionName}" +--- diff --git a/docs/api-reference/endpoints/app-connections/supabase/list.mdx b/docs/api-reference/endpoints/app-connections/supabase/list.mdx new file mode 100644 index 000000000..ff6155541 --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/list.mdx @@ -0,0 +1,4 @@ +--- +title: "List" +openapi: "GET /api/v1/app-connections/supabase" +--- diff --git a/docs/api-reference/endpoints/app-connections/supabase/update.mdx b/docs/api-reference/endpoints/app-connections/supabase/update.mdx new file mode 100644 index 000000000..693378fb7 --- /dev/null +++ b/docs/api-reference/endpoints/app-connections/supabase/update.mdx @@ -0,0 +1,8 @@ +--- +title: "Update" +openapi: "PATCH /api/v1/app-connections/supabase/{connectionId}" +--- + + + Check out the configuration docs for [Supabase Connections](/integrations/app-connections/supabase) to learn how to obtain the required credentials. + diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/create.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/create.mdx new file mode 100644 index 000000000..573b3506e --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/create.mdx @@ -0,0 +1,4 @@ +--- +title: "Create" +openapi: "POST /api/v1/secret-syncs/supabase" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/delete.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/delete.mdx new file mode 100644 index 000000000..24d05f117 --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/delete.mdx @@ -0,0 +1,4 @@ +--- +title: "Delete" +openapi: "DELETE /api/v1/secret-syncs/supabase/{syncId}" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/get-by-id.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/get-by-id.mdx new file mode 100644 index 000000000..0dc7f3353 --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/get-by-id.mdx @@ -0,0 +1,4 @@ +--- +title: "Get by ID" +openapi: "GET /api/v1/secret-syncs/supabase/{syncId}" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/get-by-name.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/get-by-name.mdx new file mode 100644 index 000000000..3f8770130 --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/get-by-name.mdx @@ -0,0 +1,4 @@ +--- +title: "Get by Name" +openapi: "GET /api/v1/secret-syncs/supabase/sync-name/{syncName}" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/list.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/list.mdx new file mode 100644 index 000000000..2d4749419 --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/list.mdx @@ -0,0 +1,4 @@ +--- +title: "List" +openapi: "GET /api/v1/secret-syncs/supabase" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/remove-secrets.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/remove-secrets.mdx new file mode 100644 index 000000000..fdfb3a44e --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/remove-secrets.mdx @@ -0,0 +1,4 @@ +--- +title: "Remove Secrets" +openapi: "POST /api/v1/secret-syncs/supabase/{syncId}/remove-secrets" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/sync-secrets.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/sync-secrets.mdx new file mode 100644 index 000000000..5e17b1ca4 --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/sync-secrets.mdx @@ -0,0 +1,4 @@ +--- +title: "Sync Secrets" +openapi: "POST /api/v1/secret-syncs/supabase/{syncId}/sync-secrets" +--- diff --git a/docs/api-reference/endpoints/secret-syncs/supabase/update.mdx b/docs/api-reference/endpoints/secret-syncs/supabase/update.mdx new file mode 100644 index 000000000..a05d17959 --- /dev/null +++ b/docs/api-reference/endpoints/secret-syncs/supabase/update.mdx @@ -0,0 +1,4 @@ +--- +title: "Update" +openapi: "PATCH /api/v1/secret-syncs/supabase/{syncId}" +--- diff --git a/docs/api-reference/endpoints/tls-cert-auth/login.mdx b/docs/api-reference/endpoints/tls-cert-auth/login.mdx index 0069ef1b7..b93f4c40a 100644 --- a/docs/api-reference/endpoints/tls-cert-auth/login.mdx +++ b/docs/api-reference/endpoints/tls-cert-auth/login.mdx @@ -2,3 +2,8 @@ title: "Login" openapi: "POST /api/v1/auth/tls-cert-auth/login" --- + + + Infisical US/EU and dedicated instances are deployed with AWS ALB. TLS Certificate Auth must flow through our ALB mTLS pass-through in order to authenticate. + When you are authenticating with TLS Certificate Auth, you must use the port `8443` instead of the default `443`. Example: `https://app.infisical.com:8443/api/v1/auth/tls-cert-auth/login` + \ No newline at end of file diff --git a/docs/cli/commands/export.mdx b/docs/cli/commands/export.mdx index 6711903ec..b1dcb5d32 100644 --- a/docs/cli/commands/export.mdx +++ b/docs/cli/commands/export.mdx @@ -9,7 +9,7 @@ infisical export [options] ## Description -Export environment variables from the platform into a file format. +Export environment variables from the platform into a file format. By default, output is sent to stdout (standard output), but you can use the `--output-file` flag to save directly to a file. ## Subcommands & flags @@ -21,18 +21,19 @@ $ infisical export # Export variables to a .env file infisical export > .env +infisical export --output-file=./.env # Export variables to a .env file (with export keyword) infisical export --format=dotenv-export > .env - -# Export variables to a CSV file -infisical export --format=csv > secrets.csv +infisical export --format=dotenv-export --output-file=./.env # Export variables to a JSON file infisical export --format=json > secrets.json +infisical export --format=json --output-file=./secrets.json # Export variables to a YAML file infisical export --format=yaml > secrets.yaml +infisical export --format=yaml --output-file=./secrets.yaml # Render secrets using a custom template file infisical export --template= @@ -73,6 +74,34 @@ infisical export --template= ### flags + + The path to write the output file to. Can be a full file path, directory, or filename. + + ```bash + # Export to specific file + infisical export --format=json --output-file=./secrets.json + + # Export to directory (uses default filename based on format) + infisical export --format=yaml --output-file=./ + ``` + + **When `--output-file` is specified:** + - Secrets are saved directly to the specified file + - A success message is displayed showing the file path + - For directories: adds default filename `secrets.{format}` (e.g., `secrets.json`, `secrets.yaml`) + - For dotenv formats in directories: uses `.env` as the filename + + **When `--output-file` is NOT specified (default behavior):** + - Output is sent to stdout (standard output) + - You can use shell redirection like `infisical export > secrets.json` + - Maintains backwards compatibility with existing scripts + + + If you're using shell redirection and your token expires, re-authentication will fail because the prompt can't display properly due to the redirection. + + + + The `--template` flag specifies the path to the template file used for rendering secrets. When using templates, you can omit the other format flags. @@ -94,6 +123,7 @@ infisical export --template= ``` + Used to set the environment that secrets are pulled from. @@ -162,7 +192,7 @@ infisical export --template= ```bash # Example - infisical run --tags=tag1,tag2,tag3 -- npm run dev + infisical export --tags=tag1,tag2,tag3 --env=dev ``` Note: you must reference the tag by its slug name not its fully qualified name. Go to project settings to view all tag slugs. @@ -171,4 +201,4 @@ infisical export --template= - + \ No newline at end of file diff --git a/docs/docs.json b/docs/docs.json index fd75a8cde..a32453c89 100644 --- a/docs/docs.json +++ b/docs/docs.json @@ -78,10 +78,7 @@ }, { "group": "Infisical SSH", - "pages": [ - "documentation/platform/ssh/overview", - "documentation/platform/ssh/host-groups" - ] + "pages": ["documentation/platform/ssh/overview", "documentation/platform/ssh/host-groups"] }, { "group": "Key Management (KMS)", @@ -378,10 +375,7 @@ }, { "group": "Architecture", - "pages": [ - "internals/architecture/components", - "internals/architecture/cloud" - ] + "pages": ["internals/architecture/components", "internals/architecture/cloud"] }, "internals/security", "internals/service-tokens" @@ -491,6 +485,7 @@ "integrations/app-connections/postgres", "integrations/app-connections/railway", "integrations/app-connections/render", + "integrations/app-connections/supabase", "integrations/app-connections/teamcity", "integrations/app-connections/terraform-cloud", "integrations/app-connections/vercel", @@ -528,6 +523,7 @@ "integrations/secret-syncs/oci-vault", "integrations/secret-syncs/railway", "integrations/secret-syncs/render", + "integrations/secret-syncs/supabase", "integrations/secret-syncs/teamcity", "integrations/secret-syncs/terraform-cloud", "integrations/secret-syncs/vercel", @@ -555,10 +551,7 @@ "integrations/cloud/gcp-secret-manager", { "group": "Cloudflare", - "pages": [ - "integrations/cloud/cloudflare-pages", - "integrations/cloud/cloudflare-workers" - ] + "pages": ["integrations/cloud/cloudflare-pages", "integrations/cloud/cloudflare-workers"] }, "integrations/cloud/terraform-cloud", "integrations/cloud/databricks", @@ -670,11 +663,7 @@ "cli/commands/reset", { "group": "infisical scan", - "pages": [ - "cli/commands/scan", - "cli/commands/scan-git-changes", - "cli/commands/scan-install" - ] + "pages": ["cli/commands/scan", "cli/commands/scan-git-changes", "cli/commands/scan-install"] } ] }, @@ -998,9 +987,7 @@ "pages": [ { "group": "Kubernetes", - "pages": [ - "api-reference/endpoints/dynamic-secrets/kubernetes/create-lease" - ] + "pages": ["api-reference/endpoints/dynamic-secrets/kubernetes/create-lease"] }, "api-reference/endpoints/dynamic-secrets/create", "api-reference/endpoints/dynamic-secrets/update", @@ -1557,6 +1544,18 @@ "api-reference/endpoints/app-connections/render/delete" ] }, + { + "group": "Supabase", + "pages": [ + "api-reference/endpoints/app-connections/supabase/list", + "api-reference/endpoints/app-connections/supabase/available", + "api-reference/endpoints/app-connections/supabase/get-by-id", + "api-reference/endpoints/app-connections/supabase/get-by-name", + "api-reference/endpoints/app-connections/supabase/create", + "api-reference/endpoints/app-connections/supabase/update", + "api-reference/endpoints/app-connections/supabase/delete" + ] + }, { "group": "TeamCity", "pages": [ @@ -1908,6 +1907,19 @@ "api-reference/endpoints/secret-syncs/render/remove-secrets" ] }, + { + "group": "Supabase", + "pages": [ + "api-reference/endpoints/secret-syncs/supabase/list", + "api-reference/endpoints/secret-syncs/supabase/get-by-id", + "api-reference/endpoints/secret-syncs/supabase/get-by-name", + "api-reference/endpoints/secret-syncs/supabase/create", + "api-reference/endpoints/secret-syncs/supabase/update", + "api-reference/endpoints/secret-syncs/supabase/delete", + "api-reference/endpoints/secret-syncs/supabase/sync-secrets", + "api-reference/endpoints/secret-syncs/supabase/remove-secrets" + ] + }, { "group": "TeamCity", "pages": [ diff --git a/docs/documentation/platform/identities/tls-cert-auth.mdx b/docs/documentation/platform/identities/tls-cert-auth.mdx index e11d0c06e..0ecb60b99 100644 --- a/docs/documentation/platform/identities/tls-cert-auth.mdx +++ b/docs/documentation/platform/identities/tls-cert-auth.mdx @@ -42,10 +42,14 @@ To be more specific: Most of the time, the Infisical server will be behind a load balancer or proxy. To propagate the TLS certificate from the load balancer to the instance, you can configure the TLS to send the client certificate as a header - that is set as an [environment - variable](/self-hosting/configuration/envars#param-identity-tls-cert-auth-client-certificate-header-key). + that is set as an [environment variable](/self-hosting/configuration/envars#param-identity-tls-cert-auth-client-certificate-header-key). + + Infisical US/EU and dedicated instances are deployed with AWS ALB. TLS Certificate Auth must flow through our ALB mTLS pass-through in order to authenticate. + When you are authenticating with TLS Certificate Auth, you must use the port `8443` instead of the default `443`. Example: `https://app.infisical.com:8443/api/v1/auth/tls-cert-auth/login` + + ## Guide In the following steps, we explore how to create and use identities for your workloads and applications on TLS Certificate to @@ -123,7 +127,7 @@ try { const clientCertificate = fs.readFileSync("client-cert.pem", "utf8"); const clientKeyCertificate = fs.readFileSync("client-key.pem", "utf8"); - const infisicalUrl = "https://app.infisical.com"; // or your self-hosted Infisical URL + const infisicalUrl = "https://app.infisical.com:8443"; // or your self-hosted Infisical URL const identityId = ""; // Create HTTPS agent with client certificate and key diff --git a/docs/images/app-connections/supabase/app-connection-api-keys.png b/docs/images/app-connections/supabase/app-connection-api-keys.png new file mode 100644 index 000000000..f37c1f306 Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-api-keys.png differ diff --git a/docs/images/app-connections/supabase/app-connection-create-api-key.png b/docs/images/app-connections/supabase/app-connection-create-api-key.png new file mode 100644 index 000000000..c860ba17f Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-create-api-key.png differ diff --git a/docs/images/app-connections/supabase/app-connection-create-form.png b/docs/images/app-connections/supabase/app-connection-create-form.png new file mode 100644 index 000000000..3633dc21e Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-create-form.png differ diff --git a/docs/images/app-connections/supabase/app-connection-form.png b/docs/images/app-connections/supabase/app-connection-form.png new file mode 100644 index 000000000..c1b550147 Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-form.png differ diff --git a/docs/images/app-connections/supabase/app-connection-generated.png b/docs/images/app-connections/supabase/app-connection-generated.png new file mode 100644 index 000000000..c494abc7a Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-generated.png differ diff --git a/docs/images/app-connections/supabase/app-connection-key-generated.png b/docs/images/app-connections/supabase/app-connection-key-generated.png new file mode 100644 index 000000000..0732cd37b Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-key-generated.png differ diff --git a/docs/images/app-connections/supabase/app-connection-option.png b/docs/images/app-connections/supabase/app-connection-option.png new file mode 100644 index 000000000..68c29876c Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-option.png differ diff --git a/docs/images/app-connections/supabase/app-connection-user-settings.png b/docs/images/app-connections/supabase/app-connection-user-settings.png new file mode 100644 index 000000000..fcd280b91 Binary files /dev/null and b/docs/images/app-connections/supabase/app-connection-user-settings.png differ diff --git a/docs/images/secret-syncs/supabase/select-option.png b/docs/images/secret-syncs/supabase/select-option.png new file mode 100644 index 000000000..863bba0ca Binary files /dev/null and b/docs/images/secret-syncs/supabase/select-option.png differ diff --git a/docs/images/secret-syncs/supabase/sync-created.png b/docs/images/secret-syncs/supabase/sync-created.png new file mode 100644 index 000000000..118c499de Binary files /dev/null and b/docs/images/secret-syncs/supabase/sync-created.png differ diff --git a/docs/images/secret-syncs/supabase/sync-destination.png b/docs/images/secret-syncs/supabase/sync-destination.png new file mode 100644 index 000000000..3f9c6680d Binary files /dev/null and b/docs/images/secret-syncs/supabase/sync-destination.png differ diff --git a/docs/images/secret-syncs/supabase/sync-details.png b/docs/images/secret-syncs/supabase/sync-details.png new file mode 100644 index 000000000..79ef5d610 Binary files /dev/null and b/docs/images/secret-syncs/supabase/sync-details.png differ diff --git a/docs/images/secret-syncs/supabase/sync-options.png b/docs/images/secret-syncs/supabase/sync-options.png new file mode 100644 index 000000000..f6b400138 Binary files /dev/null and b/docs/images/secret-syncs/supabase/sync-options.png differ diff --git a/docs/images/secret-syncs/supabase/sync-review.png b/docs/images/secret-syncs/supabase/sync-review.png new file mode 100644 index 000000000..c3b6adde8 Binary files /dev/null and b/docs/images/secret-syncs/supabase/sync-review.png differ diff --git a/docs/images/secret-syncs/supabase/sync-source.png b/docs/images/secret-syncs/supabase/sync-source.png new file mode 100644 index 000000000..b7bbf5de8 Binary files /dev/null and b/docs/images/secret-syncs/supabase/sync-source.png differ diff --git a/docs/integrations/app-connections/postgres.mdx b/docs/integrations/app-connections/postgres.mdx index 1a6ca5969..239608905 100644 --- a/docs/integrations/app-connections/postgres.mdx +++ b/docs/integrations/app-connections/postgres.mdx @@ -30,14 +30,14 @@ Infisical supports connecting to PostgreSQL using a database role. -- enable permissions to alter login credentials ALTER ROLE infisical_role WITH CREATEROLE; ``` - - For each user whose password will be rotated, you must grant that specific user role to your admin user with the ADMIN option: + + In some configurations, the role performing the rotation must be explicitly granted access to manage each user. To do this, grant the user's role to the rotation role with: ```SQL -- grant each user role to admin user for password rotation - GRANT TO WITH ADMIN OPTION; + GRANT TO WITH ADMIN OPTION; ``` - Replace `` with each specific username whose credentials will be rotated, and `` with the role that will perform the rotation. - + Replace `` with each specific username whose credentials will be rotated, and `` with the role that will perform the rotation. + diff --git a/docs/integrations/app-connections/supabase.mdx b/docs/integrations/app-connections/supabase.mdx new file mode 100644 index 000000000..9716b1526 --- /dev/null +++ b/docs/integrations/app-connections/supabase.mdx @@ -0,0 +1,107 @@ +--- +title: "Supabase Connection" +description: "Learn how to configure a Supabase Connection for Infisical." +--- + +Infisical supports the use of [Personal Access Tokens](https://supabase.com/dashboard/account/tokens) to connect with Supabase. + +## Create a Supabase Personal Access Token + + + + ![Account Preferences](/images/app-connections/supabase/app-connection-user-settings.png) + + + ![Settings Page](/images/app-connections/supabase/app-connection-api-keys.png) + + + ![Access Tokens Page](/images/app-connections/supabase/app-connection-create-api-key.png) + + + Provide a descriptive name for the token. + + ![Enter Name](/images/app-connections/supabase/app-connection-create-form.png) + + + + ![Create Token](/images/app-connections/supabase/app-connection-key-generated.png) + + + +## Create a Supabase Connection in Infisical + + + + + + In your Infisical dashboard, go to **Organization Settings** and open the [**App Connections**](https://app.infisical.com/organization/app-connections) tab. + + ![App Connections Tab](/images/app-connections/general/add-connection.png) + + + Click **+ Add Connection** and choose **Supabase Connection** from the list of integrations. + + ![Select Supabase Connection](/images/app-connections/supabase/app-connection-option.png) + + + Complete the form by providing: + - A descriptive name for the connection + - An optional description + - Supabase instance URL (e.g., `https://your-domain.com` or `https://api.supabase.com`) + - The Access Token value from the previous step + + ![Supabase Connection Modal](/images/app-connections/supabase/app-connection-form.png) + + + After submitting the form, your **Supabase Connection** will be successfully created and ready to use with your Infisical projects. + + ![Supabase Connection Created](/images/app-connections/supabase/app-connection-generated.png) + + + + + + + To create a Supabase Connection via API, send a request to the [Create Supabase Connection](/api-reference/endpoints/app-connections/supabase/create) endpoint. + + ### Sample request + + ```bash Request + curl --request POST \ + --url https://app.infisical.com/api/v1/app-connections/supabase \ + --header 'Content-Type: application/json' \ + --data '{ + "name": "my-supabase-connection", + "method": "access-token", + "credentials": { + "accessToken": "[Access Token]", + "instanceUrl": "https://api.supabase.com" + } + }' + ``` + + ### Sample response + + ```bash Response + { + "appConnection": { + "id": "e5d18aca-86f7-4026-a95e-efb8aeb0d8e6", + "name": "my-supabase-connection", + "description": null, + "version": 1, + "orgId": "6f03caa1-a5de-43ce-b127-95a145d3464c", + "createdAt": "2025-04-23T19:46:34.831Z", + "updatedAt": "2025-04-23T19:46:34.831Z", + "isPlatformManagedCredentials": false, + "credentialsHash": "7c2d371dec195f82a6a0d5b41c970a229cfcaf88e894a5b6395e2dbd0280661f", + "app": "supabase", + "method": "access-token", + "credentials": { + "instanceUrl": "https://api.supabase.com" + } + } + } + ``` + + + diff --git a/docs/integrations/secret-syncs/supabase.mdx b/docs/integrations/secret-syncs/supabase.mdx new file mode 100644 index 000000000..f43dcfbbe --- /dev/null +++ b/docs/integrations/secret-syncs/supabase.mdx @@ -0,0 +1,163 @@ +--- +title: "Supabase Sync" +description: "Learn how to configure a Supabase Sync for Infisical." +--- + +**Prerequisites:** + +- Create a [Supabase Connection](/integrations/app-connections/supabase) + + + + + + Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button. + + ![Secret Syncs Tab](/images/secret-syncs/general/secret-sync-tab.png) + + + ![Select Supabase](/images/secret-syncs/supabase/select-option.png) + + + Configure the **Source** from where secrets should be retrieved, then click **Next**. + + ![Configure Source](/images/secret-syncs/supabase/sync-source.png) + + - **Environment**: The project environment to retrieve secrets from. + - **Secret Path**: The folder path to retrieve secrets from. + + + If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports). + + + + Configure the **Destination** to where secrets should be deployed, then click **Next**. + + ![Configure Destination](/images/secret-syncs/supabase/sync-destination.png) + + - **Supabase Connection**: The Supabase Connection to authenticate with. + - **Project**: The Supabase project to sync secrets to. + + + Configure the **Sync Options** to specify how secrets should be synced, then click **Next**. + + ![Configure Options](/images/secret-syncs/supabase/sync-options.png) + + - **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync. + - **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical. + + Supabase does not support importing secrets. + + - **Key Schema**: Template that determines how secret names are transformed when syncing, using `{{secretKey}}` as a placeholder for the original secret name and `{{environment}}` for the environment. + + We highly recommend using a Key Schema to ensure that Infisical only manages the specific keys you intend, keeping everything else untouched. + + - **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only. + - **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical. + + + Configure the **Details** of your Supabase Sync, then click **Next**. + + ![Configure Details](/images/secret-syncs/supabase/sync-details.png) + + - **Name**: The name of your sync. Must be slug-friendly. + - **Description**: An optional description for your sync. + + + Review your Supabase Sync configuration, then click **Create Sync**. + + ![Review Configuration](/images/secret-syncs/supabase/sync-review.png) + + + If enabled, your Supabase Sync will begin syncing your secrets to the destination endpoint. + + ![Sync Created](/images/secret-syncs/supabase/sync-created.png) + + + + + To create a **Supabase Sync**, make an API request to the [Create Supabase Sync](/api-reference/endpoints/secret-syncs/supabase/create) API endpoint. + + ### Sample request + + ```bash Request + curl --request POST \ + --url https://app.infisical.com/api/v1/secret-syncs/supabase \ + --header 'Content-Type: application/json' \ + --data '{ + "name": "my-supabase-sync", + "projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "description": "an example sync", + "connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "environment": "dev", + "secretPath": "/my-secrets", + "isEnabled": true, + "syncOptions": { + "initialSyncBehavior": "overwrite-destination", + "autoSyncEnabled": true, + "disableSecretDeletion": false + }, + "destinationConfig": { + "projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "projectName": "Example Project" + } + }' + ``` + + ### Sample response + + ```bash Response + { + "secretSync": { + "id": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "name": "my-supabase-sync", + "description": "an example sync", + "isEnabled": true, + "version": 1, + "folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "createdAt": "2023-11-07T05:31:56Z", + "updatedAt": "2023-11-07T05:31:56Z", + "syncStatus": "succeeded", + "lastSyncJobId": "123", + "lastSyncMessage": null, + "lastSyncedAt": "2023-11-07T05:31:56Z", + "importStatus": null, + "lastImportJobId": null, + "lastImportMessage": null, + "lastImportedAt": null, + "removeStatus": null, + "lastRemoveJobId": null, + "lastRemoveMessage": null, + "lastRemovedAt": null, + "syncOptions": { + "initialSyncBehavior": "overwrite-destination", + "autoSyncEnabled": true, + "disableSecretDeletion": false + }, + "projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "connection": { + "app": "supabase", + "name": "my-supabase-connection", + "id": "3c90c3cc-0d44-4b50-8888-8dd25736052a" + }, + "environment": { + "slug": "dev", + "name": "Development", + "id": "3c90c3cc-0d44-4b50-8888-8dd25736052a" + }, + "folder": { + "id": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "path": "/my-secrets" + }, + "destination": "supabase", + "destinationConfig": { + "projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a", + "projectName": "Example Project" + } + } + } + ``` + + + diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SecretSyncDestinationFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SecretSyncDestinationFields.tsx index 7ac57bbd9..09cf2caec 100644 --- a/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SecretSyncDestinationFields.tsx +++ b/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SecretSyncDestinationFields.tsx @@ -24,6 +24,7 @@ import { HumanitecSyncFields } from "./HumanitecSyncFields"; import { OCIVaultSyncFields } from "./OCIVaultSyncFields"; import { RailwaySyncFields } from "./RailwaySyncFields"; import { RenderSyncFields } from "./RenderSyncFields"; +import { SupabaseSyncFields } from "./SupabaseSyncFields"; import { TeamCitySyncFields } from "./TeamCitySyncFields"; import { TerraformCloudSyncFields } from "./TerraformCloudSyncFields"; import { VercelSyncFields } from "./VercelSyncFields"; @@ -88,6 +89,8 @@ export const SecretSyncDestinationFields = () => { return ; case SecretSync.Checkly: return ; + case SecretSync.Supabase: + return ; default: throw new Error(`Unhandled Destination Config Field: ${destination}`); } diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SupabaseSyncFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SupabaseSyncFields.tsx new file mode 100644 index 000000000..7d698c002 --- /dev/null +++ b/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/SupabaseSyncFields.tsx @@ -0,0 +1,65 @@ +import { Controller, useFormContext, useWatch } from "react-hook-form"; +import { SingleValue } from "react-select"; + +import { SecretSyncConnectionField } from "@app/components/secret-syncs/forms/SecretSyncConnectionField"; +import { FilterableSelect, FormControl } from "@app/components/v2"; +import { + TSupabaseProject, + useSupabaseConnectionListProjects +} from "@app/hooks/api/appConnections/supabase"; +import { SecretSync } from "@app/hooks/api/secretSyncs"; + +import { TSecretSyncForm } from "../schemas"; + +export const SupabaseSyncFields = () => { + const { control, setValue } = useFormContext< + TSecretSyncForm & { destination: SecretSync.Supabase } + >(); + + const connectionId = useWatch({ name: "connection.id", control }); + + const { data: projects = [], isPending: isProjectsLoading } = useSupabaseConnectionListProjects( + connectionId, + { + enabled: Boolean(connectionId) + } + ); + + return ( + <> + { + setValue("destinationConfig.projectName", ""); + setValue("destinationConfig.projectId", ""); + }} + /> + ( + + p.id === value) ?? null} + onChange={(option) => { + const v = option as SingleValue; + onChange(v?.id ?? null); + setValue("destinationConfig.projectName", v?.name ?? ""); + }} + options={projects} + placeholder="Select project..." + getOptionLabel={(option) => option.name} + getOptionValue={(option) => option.id} + /> + + )} + /> + + ); +}; diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/SecretSyncOptionsFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/SecretSyncOptionsFields.tsx index 5c1da3b37..eaf66a053 100644 --- a/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/SecretSyncOptionsFields.tsx +++ b/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/SecretSyncOptionsFields.tsx @@ -62,6 +62,7 @@ export const SecretSyncOptionsFields = ({ hideInitialSync }: Props) => { case SecretSync.Zabbix: case SecretSync.Railway: case SecretSync.Checkly: + case SecretSync.Supabase: AdditionalSyncOptionsFieldsComponent = null; break; default: diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SecretSyncReviewFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SecretSyncReviewFields.tsx index a4e1c5b5d..d09f58a2e 100644 --- a/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SecretSyncReviewFields.tsx +++ b/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SecretSyncReviewFields.tsx @@ -34,6 +34,7 @@ import { OCIVaultSyncReviewFields } from "./OCIVaultSyncReviewFields"; import { OnePassSyncReviewFields } from "./OnePassSyncReviewFields"; import { RailwaySyncReviewFields } from "./RailwaySyncReviewFields"; import { RenderSyncReviewFields } from "./RenderSyncReviewFields"; +import { SupabaseSyncReviewFields } from "./SupabaseSyncReviewFields"; import { TeamCitySyncReviewFields } from "./TeamCitySyncReviewFields"; import { TerraformCloudSyncReviewFields } from "./TerraformCloudSyncReviewFields"; import { VercelSyncReviewFields } from "./VercelSyncReviewFields"; @@ -140,6 +141,9 @@ export const SecretSyncReviewFields = () => { case SecretSync.Checkly: DestinationFieldsComponent = ; break; + case SecretSync.Supabase: + DestinationFieldsComponent = ; + break; default: throw new Error(`Unhandled Destination Review Fields: ${destination}`); } diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SupabaseSyncReviewFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SupabaseSyncReviewFields.tsx new file mode 100644 index 000000000..332359743 --- /dev/null +++ b/frontend/src/components/secret-syncs/forms/SecretSyncReviewFields/SupabaseSyncReviewFields.tsx @@ -0,0 +1,12 @@ +import { useFormContext } from "react-hook-form"; + +import { TSecretSyncForm } from "@app/components/secret-syncs/forms/schemas"; +import { GenericFieldLabel } from "@app/components/v2"; +import { SecretSync } from "@app/hooks/api/secretSyncs"; + +export const SupabaseSyncReviewFields = () => { + const { watch } = useFormContext(); + const projectName = watch("destinationConfig.projectName"); + + return {projectName}; +}; diff --git a/frontend/src/components/secret-syncs/forms/schemas/secret-sync-schema.ts b/frontend/src/components/secret-syncs/forms/schemas/secret-sync-schema.ts index 94a2f41ad..83c334f71 100644 --- a/frontend/src/components/secret-syncs/forms/schemas/secret-sync-schema.ts +++ b/frontend/src/components/secret-syncs/forms/schemas/secret-sync-schema.ts @@ -21,6 +21,7 @@ import { HumanitecSyncDestinationSchema } from "./humanitec-sync-destination-sch import { OCIVaultSyncDestinationSchema } from "./oci-vault-sync-destination-schema"; import { RailwaySyncDestinationSchema } from "./railway-sync-destination-schema"; import { RenderSyncDestinationSchema } from "./render-sync-destination-schema"; +import { SupabaseSyncDestinationSchema } from "./supabase-sync-destination-schema"; import { TeamCitySyncDestinationSchema } from "./teamcity-sync-destination-schema"; import { TerraformCloudSyncDestinationSchema } from "./terraform-cloud-destination-schema"; import { VercelSyncDestinationSchema } from "./vercel-sync-destination-schema"; @@ -51,7 +52,7 @@ const SecretSyncUnionSchema = z.discriminatedUnion("destination", [ GitlabSyncDestinationSchema, CloudflarePagesSyncDestinationSchema, CloudflareWorkersSyncDestinationSchema, - + SupabaseSyncDestinationSchema, ZabbixSyncDestinationSchema, RailwaySyncDestinationSchema, ChecklySyncDestinationSchema diff --git a/frontend/src/components/secret-syncs/forms/schemas/supabase-sync-destination-schema.ts b/frontend/src/components/secret-syncs/forms/schemas/supabase-sync-destination-schema.ts new file mode 100644 index 000000000..3cbb49775 --- /dev/null +++ b/frontend/src/components/secret-syncs/forms/schemas/supabase-sync-destination-schema.ts @@ -0,0 +1,14 @@ +import { z } from "zod"; + +import { BaseSecretSyncSchema } from "@app/components/secret-syncs/forms/schemas/base-secret-sync-schema"; +import { SecretSync } from "@app/hooks/api/secretSyncs"; + +export const SupabaseSyncDestinationSchema = BaseSecretSyncSchema().merge( + z.object({ + destination: z.literal(SecretSync.Supabase), + destinationConfig: z.object({ + projectId: z.string().max(255).min(1, "Project ID is required"), + projectName: z.string().max(255).min(1, "Project Name is required") + }) + }) +); diff --git a/frontend/src/helpers/appConnections.ts b/frontend/src/helpers/appConnections.ts index 229b77bf5..996483904 100644 --- a/frontend/src/helpers/appConnections.ts +++ b/frontend/src/helpers/appConnections.ts @@ -46,6 +46,7 @@ import { HerokuConnectionMethod } from "@app/hooks/api/appConnections/types/hero import { OCIConnectionMethod } from "@app/hooks/api/appConnections/types/oci-connection"; import { RailwayConnectionMethod } from "@app/hooks/api/appConnections/types/railway-connection"; import { RenderConnectionMethod } from "@app/hooks/api/appConnections/types/render-connection"; +import { SupabaseConnectionMethod } from "@app/hooks/api/appConnections/types/supabase-connection"; export const APP_CONNECTION_MAP: Record< AppConnection, @@ -96,7 +97,8 @@ export const APP_CONNECTION_MAP: Record< [AppConnection.Zabbix]: { name: "Zabbix", image: "Zabbix.png" }, [AppConnection.Railway]: { name: "Railway", image: "Railway.png" }, [AppConnection.Bitbucket]: { name: "Bitbucket", image: "Bitbucket.png" }, - [AppConnection.Checkly]: { name: "Checkly", image: "Checkly.png" } + [AppConnection.Checkly]: { name: "Checkly", image: "Checkly.png" }, + [AppConnection.Supabase]: { name: "Supabase", image: "Supabase.png" } }; export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => { @@ -151,6 +153,7 @@ export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) case HerokuConnectionMethod.AuthToken: return { name: "Auth Token", icon: faKey }; case RailwayConnectionMethod.AccountToken: + case SupabaseConnectionMethod.AccessToken: return { name: "Account Token", icon: faKey }; case RailwayConnectionMethod.TeamToken: return { name: "Team Token", icon: faKey }; diff --git a/frontend/src/helpers/secretSyncs.ts b/frontend/src/helpers/secretSyncs.ts index b81e7d85a..29b4f2f73 100644 --- a/frontend/src/helpers/secretSyncs.ts +++ b/frontend/src/helpers/secretSyncs.ts @@ -97,6 +97,10 @@ export const SECRET_SYNC_MAP: Record = { [SecretSync.GitLab]: AppConnection.Gitlab, [SecretSync.CloudflarePages]: AppConnection.Cloudflare, [SecretSync.CloudflareWorkers]: AppConnection.Cloudflare, - + [SecretSync.Supabase]: AppConnection.Supabase, [SecretSync.Zabbix]: AppConnection.Zabbix, [SecretSync.Railway]: AppConnection.Railway, [SecretSync.Checkly]: AppConnection.Checkly diff --git a/frontend/src/hooks/api/appConnections/enums.ts b/frontend/src/hooks/api/appConnections/enums.ts index 4364be5e4..965675bc7 100644 --- a/frontend/src/hooks/api/appConnections/enums.ts +++ b/frontend/src/hooks/api/appConnections/enums.ts @@ -31,5 +31,6 @@ export enum AppConnection { Bitbucket = "bitbucket", Zabbix = "zabbix", Railway = "railway", - Checkly = "checkly" + Checkly = "checkly", + Supabase = "supabase" } diff --git a/frontend/src/hooks/api/appConnections/supabase/index.ts b/frontend/src/hooks/api/appConnections/supabase/index.ts new file mode 100644 index 000000000..2c1906d36 --- /dev/null +++ b/frontend/src/hooks/api/appConnections/supabase/index.ts @@ -0,0 +1,2 @@ +export * from "./queries"; +export * from "./types"; diff --git a/frontend/src/hooks/api/appConnections/supabase/queries.tsx b/frontend/src/hooks/api/appConnections/supabase/queries.tsx new file mode 100644 index 000000000..488e8b01a --- /dev/null +++ b/frontend/src/hooks/api/appConnections/supabase/queries.tsx @@ -0,0 +1,37 @@ +import { useQuery, UseQueryOptions } from "@tanstack/react-query"; + +import { apiRequest } from "@app/config/request"; +import { appConnectionKeys } from "@app/hooks/api/appConnections"; + +import { TSupabaseProject } from "./types"; + +const supabaseConnectionKeys = { + all: [...appConnectionKeys.all, "supabase"] as const, + listProjects: (connectionId: string) => + [...supabaseConnectionKeys.all, "workspace-scopes", connectionId] as const +}; + +export const useSupabaseConnectionListProjects = ( + connectionId: string, + options?: Omit< + UseQueryOptions< + TSupabaseProject[], + unknown, + TSupabaseProject[], + ReturnType + >, + "queryKey" | "queryFn" + > +) => { + return useQuery({ + queryKey: supabaseConnectionKeys.listProjects(connectionId), + queryFn: async () => { + const { data } = await apiRequest.get<{ projects: TSupabaseProject[] }>( + `/api/v1/app-connections/supabase/${connectionId}/projects` + ); + + return data.projects; + }, + ...options + }); +}; diff --git a/frontend/src/hooks/api/appConnections/supabase/types.ts b/frontend/src/hooks/api/appConnections/supabase/types.ts new file mode 100644 index 000000000..fae012644 --- /dev/null +++ b/frontend/src/hooks/api/appConnections/supabase/types.ts @@ -0,0 +1,4 @@ +export type TSupabaseProject = { + id: string; + name: string; +}; diff --git a/frontend/src/hooks/api/appConnections/types/app-options.ts b/frontend/src/hooks/api/appConnections/types/app-options.ts index 8c2ec2fe1..b6b00a615 100644 --- a/frontend/src/hooks/api/appConnections/types/app-options.ts +++ b/frontend/src/hooks/api/appConnections/types/app-options.ts @@ -148,6 +148,10 @@ export type TChecklyConnectionOption = TAppConnectionOptionBase & { app: AppConnection.Checkly; }; +export type TSupabaseConnectionOption = TAppConnectionOptionBase & { + app: AppConnection.Supabase; +}; + export type TAppConnectionOption = | TAwsConnectionOption | TGitHubConnectionOption @@ -215,4 +219,5 @@ export type TAppConnectionOptionMap = { [AppConnection.Zabbix]: TZabbixConnectionOption; [AppConnection.Railway]: TRailwayConnectionOption; [AppConnection.Checkly]: TChecklyConnectionOption; + [AppConnection.Supabase]: TSupabaseConnectionOption; }; diff --git a/frontend/src/hooks/api/appConnections/types/index.ts b/frontend/src/hooks/api/appConnections/types/index.ts index 31a97d2f3..e177fa2ab 100644 --- a/frontend/src/hooks/api/appConnections/types/index.ts +++ b/frontend/src/hooks/api/appConnections/types/index.ts @@ -28,6 +28,7 @@ import { TOracleDBConnection } from "./oracledb-connection"; import { TPostgresConnection } from "./postgres-connection"; import { TRailwayConnection } from "./railway-connection"; import { TRenderConnection } from "./render-connection"; +import { TSupabaseConnection } from "./supabase-connection"; import { TTeamCityConnection } from "./teamcity-connection"; import { TTerraformCloudConnection } from "./terraform-cloud-connection"; import { TVercelConnection } from "./vercel-connection"; @@ -99,7 +100,8 @@ export type TAppConnection = | TBitbucketConnection | TZabbixConnection | TRailwayConnection - | TChecklyConnection; + | TChecklyConnection + | TSupabaseConnection; export type TAvailableAppConnection = Pick; @@ -160,4 +162,5 @@ export type TAppConnectionMap = { [AppConnection.Zabbix]: TZabbixConnection; [AppConnection.Railway]: TRailwayConnection; [AppConnection.Checkly]: TChecklyConnection; + [AppConnection.Supabase]: TSupabaseConnection; }; diff --git a/frontend/src/hooks/api/appConnections/types/supabase-connection.ts b/frontend/src/hooks/api/appConnections/types/supabase-connection.ts new file mode 100644 index 000000000..014554535 --- /dev/null +++ b/frontend/src/hooks/api/appConnections/types/supabase-connection.ts @@ -0,0 +1,15 @@ +import { AppConnection } from "@app/hooks/api/appConnections/enums"; +import { TRootAppConnection } from "@app/hooks/api/appConnections/types/root-connection"; + +export enum SupabaseConnectionMethod { + AccessToken = "access-token" +} + +export type TSupabaseConnection = TRootAppConnection & { + app: AppConnection.Supabase; + method: SupabaseConnectionMethod.AccessToken; + credentials: { + instanceUrl?: string; + accessKey: string; + }; +}; diff --git a/frontend/src/hooks/api/secretSyncs/enums.ts b/frontend/src/hooks/api/secretSyncs/enums.ts index 79f174d4c..dfba4bf4b 100644 --- a/frontend/src/hooks/api/secretSyncs/enums.ts +++ b/frontend/src/hooks/api/secretSyncs/enums.ts @@ -22,7 +22,7 @@ export enum SecretSync { GitLab = "gitlab", CloudflarePages = "cloudflare-pages", CloudflareWorkers = "cloudflare-workers", - + Supabase = "supabase", Zabbix = "zabbix", Railway = "railway", Checkly = "checkly" diff --git a/frontend/src/hooks/api/secretSyncs/types/index.ts b/frontend/src/hooks/api/secretSyncs/types/index.ts index e0c6de742..df02872ad 100644 --- a/frontend/src/hooks/api/secretSyncs/types/index.ts +++ b/frontend/src/hooks/api/secretSyncs/types/index.ts @@ -22,6 +22,7 @@ import { THerokuSync } from "./heroku-sync"; import { THumanitecSync } from "./humanitec-sync"; import { TOCIVaultSync } from "./oci-vault-sync"; import { TRailwaySync } from "./railway-sync"; +import { TSupabaseSync } from "./supabase"; import { TTeamCitySync } from "./teamcity-sync"; import { TTerraformCloudSync } from "./terraform-cloud-sync"; import { TVercelSync } from "./vercel-sync"; @@ -61,7 +62,8 @@ export type TSecretSync = | TCloudflareWorkersSync | TZabbixSync | TRailwaySync - | TChecklySync; + | TChecklySync + | TSupabaseSync; export type TListSecretSyncs = { secretSyncs: TSecretSync[] }; diff --git a/frontend/src/hooks/api/secretSyncs/types/supabase.ts b/frontend/src/hooks/api/secretSyncs/types/supabase.ts new file mode 100644 index 000000000..e38e264c3 --- /dev/null +++ b/frontend/src/hooks/api/secretSyncs/types/supabase.ts @@ -0,0 +1,17 @@ +/* eslint-disable @typescript-eslint/no-empty-object-type */ +import { AppConnection } from "@app/hooks/api/appConnections/enums"; +import { SecretSync } from "@app/hooks/api/secretSyncs"; +import { TRootSecretSync } from "@app/hooks/api/secretSyncs/types/root-sync"; + +export type TSupabaseSync = TRootSecretSync & { + destination: SecretSync.Supabase; + destinationConfig: { + projectId: string; + projectName: string; + }; + connection: { + app: AppConnection.Supabase; + name: string; + id: string; + }; +}; diff --git a/frontend/src/hooks/api/subscriptions/types.ts b/frontend/src/hooks/api/subscriptions/types.ts index dad9e11fa..87a02231f 100644 --- a/frontend/src/hooks/api/subscriptions/types.ts +++ b/frontend/src/hooks/api/subscriptions/types.ts @@ -17,8 +17,8 @@ export type SubscriptionPlan = { rbac: boolean; secretVersioning: boolean; slug: string; - secretApproval: string; - secretRotation: string; + secretApproval: boolean; + secretRotation: boolean; tier: number; workspaceLimit: number; workspacesUsed: number; diff --git a/frontend/src/hooks/usePathAccessPolicies.tsx b/frontend/src/hooks/usePathAccessPolicies.tsx new file mode 100644 index 000000000..463e9638d --- /dev/null +++ b/frontend/src/hooks/usePathAccessPolicies.tsx @@ -0,0 +1,60 @@ +import { useMemo } from "react"; + +import { useSubscription, useWorkspace } from "@app/context"; +import { useGetAccessApprovalPolicies } from "@app/hooks/api"; + +const matchesPath = (folderPath: string, pattern: string) => { + const normalizedPath = folderPath === "/" ? "/" : folderPath.replace(/\/$/, ""); + const normalizedPattern = pattern === "/" ? "/" : pattern.replace(/\/$/, ""); + + if (normalizedPath === normalizedPattern) { + return true; + } + + if (normalizedPattern.endsWith("/**")) { + const basePattern = normalizedPattern.slice(0, -3); // Remove "/**" + + // Handle root wildcard "/**" + if (basePattern === "") { + return true; + } + + // Check if path starts with the base pattern + if (normalizedPath === basePattern) { + return true; + } + + // Check if path is a subdirectory of the base pattern + return normalizedPath.startsWith(`${basePattern}/`); + } + + return false; +}; + +type Params = { + secretPath: string; + environment: string; +}; + +export const usePathAccessPolicies = ({ secretPath, environment }: Params) => { + const { currentWorkspace } = useWorkspace(); + const { subscription } = useSubscription(); + const { data: policies } = useGetAccessApprovalPolicies({ + projectSlug: currentWorkspace.slug, + options: { + enabled: subscription.secretApproval + } + }); + + return useMemo(() => { + const pathPolicies = policies?.filter( + (policy) => + policy.environment.slug === environment && matchesPath(secretPath, policy.secretPath) + ); + + return { + hasPathPolicies: subscription.secretApproval && Boolean(pathPolicies?.length), + pathPolicies + }; + }, [secretPath, environment, policies, subscription.secretApproval]); +}; diff --git a/frontend/src/pages/cert-manager/AlertingPage/components/PkiAlertModal.tsx b/frontend/src/pages/cert-manager/AlertingPage/components/PkiAlertModal.tsx index 048c951ea..04fafa0b2 100644 --- a/frontend/src/pages/cert-manager/AlertingPage/components/PkiAlertModal.tsx +++ b/frontend/src/pages/cert-manager/AlertingPage/components/PkiAlertModal.tsx @@ -31,10 +31,10 @@ enum TimeUnit { const schema = z.object({ name: z.string().trim().min(1), - pkiCollectionId: z.string(), - alertBefore: z.string(), + pkiCollectionId: z.string().min(1), + alertBefore: z.string().min(1), alertUnit: z.nativeEnum(TimeUnit), - emails: z.string().trim() + emails: z.string().trim().min(1) }); const convertToDays = (unit: TimeUnit, value: number) => { diff --git a/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/AppConnectionForm.tsx b/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/AppConnectionForm.tsx index b06d445b4..45a774780 100644 --- a/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/AppConnectionForm.tsx +++ b/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/AppConnectionForm.tsx @@ -37,6 +37,7 @@ import { OracleDBConnectionForm } from "./OracleDBConnectionForm"; import { PostgresConnectionForm } from "./PostgresConnectionForm"; import { RailwayConnectionForm } from "./RailwayConnectionForm"; import { RenderConnectionForm } from "./RenderConnectionForm"; +import { SupabaseConnectionForm } from "./SupabaseConnectionForm"; import { TeamCityConnectionForm } from "./TeamCityConnectionForm"; import { TerraformCloudConnectionForm } from "./TerraformCloudConnectionForm"; import { VercelConnectionForm } from "./VercelConnectionForm"; @@ -146,6 +147,8 @@ const CreateForm = ({ app, onComplete }: CreateFormProps) => { return ; case AppConnection.Checkly: return ; + case AppConnection.Supabase: + return ; default: throw new Error(`Unhandled App ${app}`); } @@ -248,6 +251,8 @@ const UpdateForm = ({ appConnection, onComplete }: UpdateFormProps) => { return ; case AppConnection.Checkly: return ; + case AppConnection.Supabase: + return ; default: throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`); } diff --git a/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/SupabaseConnectionForm.tsx b/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/SupabaseConnectionForm.tsx new file mode 100644 index 000000000..af2ddfced --- /dev/null +++ b/frontend/src/pages/organization/AppConnections/AppConnectionsPage/components/AppConnectionForm/SupabaseConnectionForm.tsx @@ -0,0 +1,159 @@ +import { Controller, FormProvider, useForm } from "react-hook-form"; +import { zodResolver } from "@hookform/resolvers/zod"; +import { z } from "zod"; + +import { + Button, + FormControl, + Input, + ModalClose, + SecretInput, + Select, + SelectItem +} from "@app/components/v2"; +import { APP_CONNECTION_MAP, getAppConnectionMethodDetails } from "@app/helpers/appConnections"; +import { AppConnection } from "@app/hooks/api/appConnections/enums"; +import { + SupabaseConnectionMethod, + TSupabaseConnection +} from "@app/hooks/api/appConnections/types/supabase-connection"; + +import { + genericAppConnectionFieldsSchema, + GenericAppConnectionsFields +} from "./GenericAppConnectionFields"; + +type Props = { + appConnection?: TSupabaseConnection; + onSubmit: (formData: FormData) => void; +}; + +const rootSchema = genericAppConnectionFieldsSchema.extend({ + app: z.literal(AppConnection.Supabase) +}); + +const formSchema = z.discriminatedUnion("method", [ + rootSchema.extend({ + method: z.literal(SupabaseConnectionMethod.AccessToken), + credentials: z.object({ + accessKey: z.string().trim().min(1, "Access Key required"), + instanceUrl: z.string().url().optional() + }) + }) +]); + +type FormData = z.infer; + +export const SupabaseConnectionForm = ({ appConnection, onSubmit }: Props) => { + const isUpdate = Boolean(appConnection); + + const form = useForm({ + resolver: zodResolver(formSchema), + defaultValues: appConnection ?? { + app: AppConnection.Supabase, + method: SupabaseConnectionMethod.AccessToken + } + }); + + const { + handleSubmit, + control, + formState: { isSubmitting, isDirty } + } = form; + + return ( + +
+ {!isUpdate && } + ( + + onChange(e.target.value)} + placeholder="https://api.supabase.com" + /> + + )} + /> + ( + + + + )} + /> + ( + + onChange(e.target.value)} + /> + + )} + /> + +
+ + + + +
+ +
+ ); +}; diff --git a/frontend/src/pages/project/AccessControlPage/components/MembersTab/components/MemberRoleForm/SpecificPrivilegeSection.tsx b/frontend/src/pages/project/AccessControlPage/components/MembersTab/components/MemberRoleForm/SpecificPrivilegeSection.tsx index 86b7d7633..51a83c6e0 100644 --- a/frontend/src/pages/project/AccessControlPage/components/MembersTab/components/MemberRoleForm/SpecificPrivilegeSection.tsx +++ b/frontend/src/pages/project/AccessControlPage/components/MembersTab/components/MemberRoleForm/SpecificPrivilegeSection.tsx @@ -79,10 +79,14 @@ type TSecretPermissionForm = z.infer; export const SpecificPrivilegeSecretForm = ({ privilege, policies, - onClose + onClose, + selectedActions = [], + secretPath: initialSecretPath }: { privilege?: TProjectUserPrivilege; policies?: TAccessApprovalPolicy[]; + selectedActions?: ProjectPermissionActions[]; + secretPath?: string; onClose?: () => void; }) => { const { currentWorkspace } = useWorkspace(); @@ -126,10 +130,11 @@ export const SpecificPrivilegeSecretForm = ({ } : { environmentSlug: currentWorkspace.environments?.[0]?.slug, - read: false, - edit: false, - create: false, - delete: false, + secretPath: initialSecretPath, + read: selectedActions.includes(ProjectPermissionActions.Read), + edit: selectedActions.includes(ProjectPermissionActions.Edit), + create: selectedActions.includes(ProjectPermissionActions.Create), + delete: selectedActions.includes(ProjectPermissionActions.Delete), temporaryAccess: { isTemporary: false } @@ -281,6 +286,8 @@ export const SpecificPrivilegeSecretForm = ({ isDisabled={isMemberEditDisabled} className="w-full bg-mineshaft-900 hover:bg-mineshaft-800" onValueChange={(e) => onChange(e)} + position="popper" + dropdownContainerClassName="max-w-none" > {currentWorkspace?.environments?.map(({ slug, id, name }) => ( @@ -309,6 +316,8 @@ export const SpecificPrivilegeSecretForm = ({ className="w-full hover:bg-mineshaft-800" placeholder="Select a secret path" onValueChange={(e) => field.onChange(e)} + position="popper" + dropdownContainerClassName="max-w-none" > {selectablePaths.map((path) => ( @@ -636,6 +645,7 @@ export const SpecificPrivilegeSecretForm = ({ {!!policies && ( )} diff --git a/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SecretSyncDestinationCol.tsx b/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SecretSyncDestinationCol.tsx index 54ee79fe7..0a41b2c4b 100644 --- a/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SecretSyncDestinationCol.tsx +++ b/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SecretSyncDestinationCol.tsx @@ -21,6 +21,7 @@ import { HumanitecSyncDestinationCol } from "./HumanitecSyncDestinationCol"; import { OCIVaultSyncDestinationCol } from "./OCIVaultSyncDestinationCol"; import { RailwaySyncDestinationCol } from "./RailwaySyncDestinationCol"; import { RenderSyncDestinationCol } from "./RenderSyncDestinationCol"; +import { SupabaseSyncDestinationCol } from "./SupabaseSyncDestinationCol"; import { TeamCitySyncDestinationCol } from "./TeamCitySyncDestinationCol"; import { TerraformCloudSyncDestinationCol } from "./TerraformCloudSyncDestinationCol"; import { VercelSyncDestinationCol } from "./VercelSyncDestinationCol"; @@ -85,6 +86,8 @@ export const SecretSyncDestinationCol = ({ secretSync }: Props) => { return ; case SecretSync.Checkly: return ; + case SecretSync.Supabase: + return ; default: throw new Error( `Unhandled Secret Sync Destination Col: ${(secretSync as TSecretSync).destination}` diff --git a/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SupabaseSyncDestinationCol.tsx b/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SupabaseSyncDestinationCol.tsx new file mode 100644 index 000000000..9558c3b39 --- /dev/null +++ b/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/SecretSyncDestinationCol/SupabaseSyncDestinationCol.tsx @@ -0,0 +1,14 @@ +import { TSupabaseSync } from "@app/hooks/api/secretSyncs/types/supabase"; + +import { getSecretSyncDestinationColValues } from "../helpers"; +import { SecretSyncTableCell } from "../SecretSyncTableCell"; + +type Props = { + secretSync: TSupabaseSync; +}; + +export const SupabaseSyncDestinationCol = ({ secretSync }: Props) => { + const { primaryText, secondaryText } = getSecretSyncDestinationColValues(secretSync); + + return ; +}; diff --git a/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/helpers/index.ts b/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/helpers/index.ts index bc4bd28f5..a4a7e5480 100644 --- a/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/helpers/index.ts +++ b/frontend/src/pages/secret-manager/IntegrationsListPage/components/SecretSyncsTab/SecretSyncTable/helpers/index.ts @@ -170,6 +170,10 @@ export const getSecretSyncDestinationColValues = (secretSync: TSecretSync) => { primaryText = destinationConfig.accountName; secondaryText = "Checkly Account"; break; + case SecretSync.Supabase: + primaryText = destinationConfig.projectName; + secondaryText = "Supabase Project"; + break; default: throw new Error(`Unhandled Destination Col Values ${destination}`); } diff --git a/frontend/src/pages/secret-manager/SecretApprovalsPage/components/AccessApprovalRequest/components/RequestAccessModal.tsx b/frontend/src/pages/secret-manager/SecretApprovalsPage/components/AccessApprovalRequest/components/RequestAccessModal.tsx index b337f4e69..0da633155 100644 --- a/frontend/src/pages/secret-manager/SecretApprovalsPage/components/AccessApprovalRequest/components/RequestAccessModal.tsx +++ b/frontend/src/pages/secret-manager/SecretApprovalsPage/components/AccessApprovalRequest/components/RequestAccessModal.tsx @@ -1,15 +1,19 @@ import { Modal, ModalContent } from "@app/components/v2"; +import { ProjectPermissionActions } from "@app/context"; import { TAccessApprovalPolicy } from "@app/hooks/api/types"; import { SpecificPrivilegeSecretForm } from "@app/pages/project/AccessControlPage/components/MembersTab/components/MemberRoleForm/SpecificPrivilegeSection"; export const RequestAccessModal = ({ isOpen, onOpenChange, - policies + policies, + ...props }: { isOpen: boolean; onOpenChange: (isOpen: boolean) => void; policies: TAccessApprovalPolicy[]; + selectedActions?: ProjectPermissionActions[]; + secretPath?: string; }) => { return ( @@ -18,7 +22,11 @@ export const RequestAccessModal = ({ title="Request Access" subTitle="Request access to any secrets and resources based on the predefined policies." > - onOpenChange(false)} policies={policies} /> + onOpenChange(false)} + policies={policies} + {...props} + /> ); diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/SecretDashboardPage.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/SecretDashboardPage.tsx index 7326876da..92f0c2d00 100644 --- a/frontend/src/pages/secret-manager/SecretDashboardPage/SecretDashboardPage.tsx +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/SecretDashboardPage.tsx @@ -3,7 +3,7 @@ import { useCallback, useEffect, useMemo, useState } from "react"; import { Helmet } from "react-helmet"; import { useTranslation } from "react-i18next"; import { subject } from "@casl/ability"; -import { faArrowDown, faArrowUp } from "@fortawesome/free-solid-svg-icons"; +import { faArrowDown, faArrowUp, faInfoCircle } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { useNavigate, useParams, useSearch } from "@tanstack/react-router"; import { twMerge } from "tailwind-merge"; @@ -11,10 +11,12 @@ import { twMerge } from "tailwind-merge"; import { createNotification } from "@app/components/notifications"; import { PermissionDeniedBanner } from "@app/components/permissions"; import { + Button, Checkbox, ContentLoader, Modal, ModalContent, + PageHeader, Pagination, Tooltip } from "@app/components/v2"; @@ -50,7 +52,9 @@ import { OrderByDirection } from "@app/hooks/api/generic/types"; import { PendingAction } from "@app/hooks/api/secretFolders/types"; import { useCreateCommit } from "@app/hooks/api/secrets/mutations"; import { SecretV3RawSanitized } from "@app/hooks/api/types"; +import { usePathAccessPolicies } from "@app/hooks/usePathAccessPolicies"; import { hasSecretReadValueOrDescribePermission } from "@app/lib/fn/permission"; +import { RequestAccessModal } from "@app/pages/secret-manager/SecretApprovalsPage/components/AccessApprovalRequest/components/RequestAccessModal"; import { SecretRotationListView } from "@app/pages/secret-manager/SecretDashboardPage/components/SecretRotationListView"; import { SecretTableResourceCount } from "../OverviewPage/components/SecretTableResourceCount"; @@ -125,7 +129,10 @@ const Page = () => { const [snapshotId, setSnapshotId] = useState(null); const isRollbackMode = Boolean(snapshotId); - const { popUp, handlePopUpClose, handlePopUpToggle } = usePopUp(["snapshots"] as const); + const { popUp, handlePopUpClose, handlePopUpToggle, handlePopUpOpen } = usePopUp([ + "snapshots", + "requestAccess" + ] as const); // env slug const workspaceId = currentWorkspace?.id || ""; @@ -149,6 +156,26 @@ const Page = () => { } ); + const canEditSecrets = permission.can( + ProjectPermissionSecretActions.Edit, + subject(ProjectPermissionSub.Secrets, { + environment, + secretPath, + secretName: "*", + secretTags: ["*"] + }) + ); + + const canDeleteSecrets = permission.can( + ProjectPermissionSecretActions.Delete, + subject(ProjectPermissionSub.Secrets, { + environment, + secretPath, + secretName: "*", + secretTags: ["*"] + }) + ); + const canReadSecretValue = hasSecretReadValueOrDescribePermission( permission, ProjectPermissionSecretActions.ReadValue, @@ -274,6 +301,8 @@ const Page = () => { permission.can(ProjectPermissionActions.Read, ProjectPermissionSub.Tags) ? workspaceId : "" ); + const { pathPolicies, hasPathPolicies } = usePathAccessPolicies({ secretPath, environment }); + const { data: boardPolicy } = useGetSecretApprovalPolicyOfABoard({ workspaceId, environment, @@ -666,6 +695,52 @@ const Page = () => { const mergedFolders = getMergedFoldersWithPending(); return (
+ env.slug === environment)?.name ?? environment + } + description={ +

+ Inject your secrets using + + Infisical CLI + + , + + Infisical API + + , + + Infisical SDKs + + , and + + more + + . +

+ } + /> {!isRollbackMode ? ( <> @@ -689,8 +764,15 @@ const Page = () => { importedBy={importedBy} usedBySecretSyncs={usedBySecretSyncs} isPITEnabled={isPITEnabled} + hasPathPolicies={hasPathPolicies} + onRequestAccess={(params) => handlePopUpOpen("requestAccess", params)} /> -
+
{isNotEmpty && (
{
Value
)} + {hasPathPolicies && + // eslint-disable-next-line no-nested-ternary + (!canReadSecret ? ( +
+
+ + You do not have permission to read secrets in this folder +
+ +
+ ) : !canEditSecrets || !canDeleteSecrets ? ( +
+
+ + + You do not have permission to {!canEditSecrets ? "edit" : ""} + {!canEditSecrets && !canDeleteSecrets ? " or " : ""} + {!canDeleteSecrets ? "delete" : ""} secrets in this folder + +
+ +
+ ) : null)} + {canReadSecretImports && Boolean(imports?.length) && ( { /> + {!!pathPolicies && ( + { + handlePopUpClose("requestAccess"); + }} + selectedActions={popUp.requestAccess.data} + secretPath={pathPolicies?.[0]?.secretPath} + /> + )} void; + hasPathPolicies: boolean; }; export const ActionBar = ({ @@ -152,7 +157,9 @@ export const ActionBar = ({ protectedBranchPolicyName, importedBy, isPITEnabled = false, - usedBySecretSyncs + usedBySecretSyncs, + onRequestAccess, + hasPathPolicies }: Props) => { const { handlePopUpOpen, handlePopUpToggle, handlePopUpClose, popUp } = usePopUp([ "addFolder", @@ -164,7 +171,8 @@ export const ActionBar = ({ "misc", "upgradePlan", "replicateFolder", - "confirmUpload" + "confirmUpload", + "requestAccess" ] as const); const isProtectedBranch = Boolean(protectedBranchPolicyName); const { subscription } = useSubscription(); @@ -186,6 +194,7 @@ export const ActionBar = ({ const isMultiSelectActive = Boolean(Object.keys(selectedSecrets).length); const { currentWorkspace } = useWorkspace(); + const { permission } = useProjectPermission(); const handleFolderCreate = async (folderName: string, description: string | null) => { try { @@ -835,27 +844,50 @@ export const ActionBar = ({
- - {(isAllowed) => ( - - )} - + {hasPathPolicies ? ( + + ) : ( + + {(isAllowed) => ( + + )} + + )} handlePopUpToggle("misc", isOpen)} @@ -1194,6 +1226,27 @@ export const ActionBar = ({ )} + handlePopUpToggle("requestAccess", open)} + > + +

You do not have permission to perform this action.

+

Request access to perform this action in this folder.

+
+ + + + + + +
+
+
); }; diff --git a/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretDropzone/SecretDropzone.tsx b/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretDropzone/SecretDropzone.tsx index b0f61dc89..92df89cae 100644 --- a/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretDropzone/SecretDropzone.tsx +++ b/frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretDropzone/SecretDropzone.tsx @@ -262,7 +262,7 @@ export const SecretDropzone = ({ className={twMerge( "relative mx-0.5 mb-4 mt-4 flex cursor-pointer items-center justify-center rounded-md bg-mineshaft-900 px-2 py-4 text-sm text-mineshaft-200 opacity-60 outline-dashed outline-2 outline-chicago-600 duration-200 hover:opacity-100", isDragActive && "opacity-100", - !isSmaller && "mx-auto w-full max-w-3xl flex-col space-y-4 py-20", + !isSmaller && "mx-auto mt-40 w-full max-w-3xl flex-col space-y-4 py-20", isLoading && "bg-bunker-800" )} > diff --git a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SecretSyncDestinatonSection.tsx b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SecretSyncDestinatonSection.tsx index 68e6f4325..e7230e815 100644 --- a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SecretSyncDestinatonSection.tsx +++ b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SecretSyncDestinatonSection.tsx @@ -32,6 +32,7 @@ import { HumanitecSyncDestinationSection } from "./HumanitecSyncDestinationSecti import { OCIVaultSyncDestinationSection } from "./OCIVaultSyncDestinationSection"; import { RailwaySyncDestinationSection } from "./RailwaySyncDestinationSection"; import { RenderSyncDestinationSection } from "./RenderSyncDestinationSection"; +import { SupabaseSyncDestinationSection } from "./SupabaseSyncDestinationSection"; import { TeamCitySyncDestinationSection } from "./TeamCitySyncDestinationSection"; import { TerraformCloudSyncDestinationSection } from "./TerraformCloudSyncDestinationSection"; import { VercelSyncDestinationSection } from "./VercelSyncDestinationSection"; @@ -130,6 +131,9 @@ export const SecretSyncDestinationSection = ({ secretSync, onEditDestination }: case SecretSync.Checkly: DestinationComponents = ; break; + case SecretSync.Supabase: + DestinationComponents = ; + break; default: throw new Error(`Unhandled Destination Section components: ${destination}`); } diff --git a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SupabaseSyncDestinationSection.tsx b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SupabaseSyncDestinationSection.tsx new file mode 100644 index 000000000..baa771a03 --- /dev/null +++ b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/SupabaseSyncDestinationSection.tsx @@ -0,0 +1,12 @@ +import { GenericFieldLabel } from "@app/components/secret-syncs"; +import { TSupabaseSync } from "@app/hooks/api/secretSyncs/types/supabase"; + +type Props = { + secretSync: TSupabaseSync; +}; + +export const SupabaseSyncDestinationSection = ({ secretSync }: Props) => { + const { destinationConfig } = secretSync; + + return {destinationConfig.projectName}; +}; diff --git a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncOptionsSection/SecretSyncOptionsSection.tsx b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncOptionsSection/SecretSyncOptionsSection.tsx index 456425f5c..3cc70ebcb 100644 --- a/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncOptionsSection/SecretSyncOptionsSection.tsx +++ b/frontend/src/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncOptionsSection/SecretSyncOptionsSection.tsx @@ -63,6 +63,7 @@ export const SecretSyncOptionsSection = ({ secretSync, onEditOptions }: Props) = case SecretSync.CloudflareWorkers: case SecretSync.Zabbix: case SecretSync.Railway: + case SecretSync.Supabase: case SecretSync.Checkly: AdditionalSyncOptionsComponent = null; break; diff --git a/nginx/default.dev.conf b/nginx/default.dev.conf index 2dd32049b..f1de1790c 100644 --- a/nginx/default.dev.conf +++ b/nginx/default.dev.conf @@ -14,7 +14,7 @@ server { proxy_pass http://backend:4000; proxy_redirect off; - proxy_cookie_path / "/; HttpOnly; SameSite=strict"; + proxy_cookie_path / "/; SameSite=strict"; } location /runtime-ui-env.js {