feat: completed switch in metadata and resolved ts errors in backend

This commit is contained in:
=
2025-11-13 12:52:38 +05:30
parent c63327e56e
commit 974f3923d0
15 changed files with 65 additions and 69 deletions
@@ -204,9 +204,7 @@ export const permissionDALFactory = (db: TDbClient): TPermissionDALFactory => {
.on(`${TableName.IdentityMetadata}.userId`, db.raw("?", [actorId])) .on(`${TableName.IdentityMetadata}.userId`, db.raw("?", [actorId]))
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`); .andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
} else if (actorType === ActorType.IDENTITY) { } else if (actorType === ActorType.IDENTITY) {
void queryBuilder void queryBuilder.on(`${TableName.IdentityMetadata}.identityId`, db.raw("?", [actorId]));
.on(`${TableName.IdentityMetadata}.identityId`, db.raw("?", [actorId]))
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
} }
}) })
.where(`${TableName.Membership}.scopeOrgId`, scopeData.orgId) .where(`${TableName.Membership}.scopeOrgId`, scopeData.orgId)
@@ -667,9 +665,7 @@ export const permissionDALFactory = (db: TDbClient): TPermissionDALFactory => {
}) })
.join(TableName.Identity, `${TableName.Identity}.id`, `${TableName.Membership}.actorIdentityId`) .join(TableName.Identity, `${TableName.Identity}.id`, `${TableName.Membership}.actorIdentityId`)
.leftJoin(TableName.IdentityMetadata, (queryBuilder) => { .leftJoin(TableName.IdentityMetadata, (queryBuilder) => {
void queryBuilder void queryBuilder.on(`${TableName.Membership}.actorIdentityId`, `${TableName.IdentityMetadata}.identityId`);
.on(`${TableName.Membership}.actorIdentityId`, `${TableName.IdentityMetadata}.identityId`)
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
}) })
.where(`${TableName.Membership}.scopeOrgId`, orgId) .where(`${TableName.Membership}.scopeOrgId`, orgId)
.whereNotNull(`${TableName.Membership}.actorIdentityId`) .whereNotNull(`${TableName.Membership}.actorIdentityId`)
@@ -200,7 +200,7 @@ export const identityAliCloudAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -280,7 +280,7 @@ export const identityAliCloudAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -350,7 +350,7 @@ export const identityAliCloudAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -389,7 +389,7 @@ export const identityAliCloudAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.ALICLOUD_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.ALICLOUD_AUTH)) {
@@ -286,7 +286,7 @@ export const identityAwsAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -370,7 +370,7 @@ export const identityAwsAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -441,7 +441,7 @@ export const identityAwsAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -480,7 +480,7 @@ export const identityAwsAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AWS_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AWS_AUTH)) {
@@ -192,7 +192,7 @@ export const identityAzureAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -275,7 +275,7 @@ export const identityAzureAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AZURE_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AZURE_AUTH)) {
@@ -348,7 +348,7 @@ export const identityAzureAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AZURE_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AZURE_AUTH)) {
@@ -387,7 +387,7 @@ export const identityAzureAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AZURE_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.AZURE_AUTH)) {
@@ -232,7 +232,7 @@ export const identityGcpAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -317,7 +317,7 @@ export const identityGcpAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -392,7 +392,7 @@ export const identityGcpAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -432,7 +432,7 @@ export const identityGcpAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -309,7 +309,7 @@ export const identityJwtAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.JWT_AUTH)) { if (identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.JWT_AUTH)) {
@@ -416,7 +416,7 @@ export const identityJwtAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -524,7 +524,7 @@ export const identityJwtAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -576,7 +576,7 @@ export const identityJwtAuthServiceFactory = ({
if (!identityMembershipOrg) { if (!identityMembershipOrg) {
throw new NotFoundError({ message: "Failed to find identity" }); throw new NotFoundError({ message: "Failed to find identity" });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -549,7 +549,7 @@ export const identityKubernetesAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -679,7 +679,7 @@ export const identityKubernetesAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -831,7 +831,7 @@ export const identityKubernetesAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -897,7 +897,7 @@ export const identityKubernetesAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -276,7 +276,7 @@ export const identityLdapAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -451,7 +451,7 @@ export const identityLdapAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -618,7 +618,7 @@ export const identityLdapAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -669,7 +669,7 @@ export const identityLdapAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.LDAP_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.LDAP_AUTH)) {
@@ -203,7 +203,7 @@ export const identityOciAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -285,7 +285,7 @@ export const identityOciAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -355,7 +355,7 @@ export const identityOciAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -394,7 +394,7 @@ export const identityOciAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.OCI_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.OCI_AUTH)) {
@@ -366,7 +366,7 @@ export const identityOidcAuthServiceFactory = ({
if (!identityMembershipOrg) { if (!identityMembershipOrg) {
throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.OIDC_AUTH)) { if (identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.OIDC_AUTH)) {
@@ -462,7 +462,7 @@ export const identityOidcAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -555,7 +555,7 @@ export const identityOidcAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -600,7 +600,7 @@ export const identityOidcAuthServiceFactory = ({
if (!identityMembershipOrg) { if (!identityMembershipOrg) {
throw new NotFoundError({ message: "Failed to find identity" }); throw new NotFoundError({ message: "Failed to find identity" });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -223,7 +223,7 @@ export const identityTlsCertAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -309,7 +309,7 @@ export const identityTlsCertAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -392,7 +392,7 @@ export const identityTlsCertAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -440,7 +440,7 @@ export const identityTlsCertAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.TLS_CERT_AUTH)) { if (!identityMembershipOrg.identity.authMethods.includes(IdentityAuthMethod.TLS_CERT_AUTH)) {
@@ -87,7 +87,7 @@ export const identityTokenAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -167,7 +167,7 @@ export const identityTokenAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -239,7 +239,7 @@ export const identityTokenAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -282,7 +282,7 @@ export const identityTokenAuthServiceFactory = ({
identityId identityId
}); });
if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` }); if (!identityMembershipOrg) throw new NotFoundError({ message: `Failed to find identity with ID ${identityId}` });
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -343,7 +343,7 @@ export const identityUaServiceFactory = ({
message: "Failed to add universal auth to already configured identity" message: "Failed to add universal auth to already configured identity"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -456,7 +456,7 @@ export const identityUaServiceFactory = ({
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -550,7 +550,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -587,7 +587,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
const { permission } = await permissionService.getOrgPermission({ const { permission } = await permissionService.getOrgPermission({
@@ -658,7 +658,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -744,7 +744,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -818,7 +818,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -890,7 +890,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -967,7 +967,7 @@ export const identityUaServiceFactory = ({
message: "The identity does not have universal auth" message: "The identity does not have universal auth"
}); });
} }
if (identityMembershipOrg.identity.identityOrgId !== actorOrgId) { if (identityMembershipOrg.identity.orgId !== actorOrgId) {
throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" }); throw new ForbiddenRequestError({ message: "Sub organization not authorized to access this identity" });
} }
@@ -142,7 +142,7 @@ export const identityServiceFactory = ({
if (metadata && metadata.length) { if (metadata && metadata.length) {
const rowsToInsert = metadata.map(({ key, value }) => ({ const rowsToInsert = metadata.map(({ key, value }) => ({
identityId: newIdentity.id, identityId: newIdentity.id,
orgId, orgId: newIdentity.orgId,
key, key,
value value
})); }));
@@ -243,13 +243,13 @@ export const identityServiceFactory = ({
value: string; value: string;
}> = []; }> = [];
if (metadata) { if (metadata && identityDetails.orgId === actorOrgId) {
await identityMetadataDAL.delete({ orgId: identityOrgMembership.scopeOrgId, identityId: id }, tx); await identityMetadataDAL.delete({ orgId: newIdentity.orgId, identityId: id }, tx);
if (metadata.length) { if (metadata.length) {
const rowsToInsert = metadata.map(({ key, value }) => ({ const rowsToInsert = metadata.map(({ key, value }) => ({
identityId: newIdentity.id, identityId: newIdentity.id,
orgId: identityOrgMembership.scopeOrgId, orgId: newIdentity.orgId,
key, key,
value value
})); }));
@@ -340,7 +340,7 @@ export const identityServiceFactory = ({
if (identityOrgMembership.identity.hasDeleteProtection) if (identityOrgMembership.identity.hasDeleteProtection)
throw new BadRequestError({ message: "Identity has delete protection" }); throw new BadRequestError({ message: "Identity has delete protection" });
if (identityOrgMembership.identity.identityOrgId === actorOrgId) { if (identityOrgMembership.identity.orgId === actorOrgId) {
const deletedIdentity = await identityDAL.deleteById(id); const deletedIdentity = await identityDAL.deleteById(id);
await licenseService.updateSubscriptionOrgMemberCount(identityOrgMembership.scopeOrgId); await licenseService.updateSubscriptionOrgMemberCount(identityOrgMembership.scopeOrgId);
return { ...deletedIdentity, orgId: identityOrgMembership.scopeOrgId }; return { ...deletedIdentity, orgId: identityOrgMembership.scopeOrgId };
@@ -115,7 +115,7 @@ export const identityServiceFactory = ({
if (data.metadata && data.metadata.length) { if (data.metadata && data.metadata.length) {
const rowsToInsert = data.metadata.map(({ key, value }) => ({ const rowsToInsert = data.metadata.map(({ key, value }) => ({
identityId: newIdentity.id, identityId: newIdentity.id,
orgId: dto.permission.orgId, orgId: newIdentity.orgId,
key, key,
value value
})); }));
@@ -148,7 +148,7 @@ export const identityServiceFactory = ({
throw new NotFoundError({ message: `Identity with id ${dto.selector.identityId} not found` }); throw new NotFoundError({ message: `Identity with id ${dto.selector.identityId} not found` });
const identity = await identityDAL.transaction(async (tx) => { const identity = await identityDAL.transaction(async (tx) => {
const newIdentity = const updatedIdentity =
data?.name || data?.hasDeleteProtection data?.name || data?.hasDeleteProtection
? await identityDAL.updateById( ? await identityDAL.updateById(
dto.selector.identityId, dto.selector.identityId,
@@ -168,8 +168,8 @@ export const identityServiceFactory = ({
if (data.metadata.length) { if (data.metadata.length) {
const rowsToInsert = data.metadata.map(({ key, value }) => ({ const rowsToInsert = data.metadata.map(({ key, value }) => ({
identityId: newIdentity.id, identityId: updatedIdentity.id,
orgId: dto.permission.orgId, orgId: updatedIdentity.orgId,
key, key,
value value
})); }));
@@ -179,7 +179,7 @@ export const identityServiceFactory = ({
} }
return { return {
...newIdentity, ...updatedIdentity,
metadata: insertedMetadata metadata: insertedMetadata
}; };
}); });