mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 22:27:48 +00:00
misc: added as least as privileged check to update
This commit is contained in:
@@ -256,6 +256,19 @@ export const groupProjectServiceFactory = ({
|
|||||||
const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
|
const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
|
||||||
if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` });
|
if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` });
|
||||||
|
|
||||||
|
for await (const { role: requestedRoleChange } of roles) {
|
||||||
|
const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
|
||||||
|
requestedRoleChange,
|
||||||
|
project.id
|
||||||
|
);
|
||||||
|
|
||||||
|
const hasRequiredPrivileges = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
|
|
||||||
|
if (!hasRequiredPrivileges) {
|
||||||
|
throw new ForbiddenRequestError({ message: "Failed to assign group to a more privileged role" });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// validate custom roles input
|
// validate custom roles input
|
||||||
const customInputRoles = roles.filter(
|
const customInputRoles = roles.filter(
|
||||||
({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole)
|
({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole)
|
||||||
|
|||||||
Reference in New Issue
Block a user