Minor fixes on policies multi env migration

This commit is contained in:
Carlos Monastyrski
2025-07-25 01:37:25 -03:00
parent b05ea8a69a
commit 99e8bdef58
3 changed files with 32 additions and 25 deletions
@@ -12,11 +12,13 @@ export async function up(knex: Knex): Promise<void> {
t.uuid("policyId").notNullable(); t.uuid("policyId").notNullable();
t.foreign("policyId").references("id").inTable(TableName.AccessApprovalPolicy).onDelete("CASCADE"); t.foreign("policyId").references("id").inTable(TableName.AccessApprovalPolicy).onDelete("CASCADE");
t.uuid("envId").notNullable(); t.uuid("envId").notNullable();
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("CASCADE"); t.foreign("envId").references("id").inTable(TableName.Environment);
t.timestamps(true, true, true); t.timestamps(true, true, true);
t.unique(["policyId", "envId"]); t.unique(["policyId", "envId"]);
}); });
await createOnUpdateTrigger(knex, TableName.AccessApprovalPolicyEnvironment);
const existingAccessApprovalPolicies = await knex(TableName.AccessApprovalPolicy) const existingAccessApprovalPolicies = await knex(TableName.AccessApprovalPolicy)
.select(selectAllTableCols(TableName.AccessApprovalPolicy)) .select(selectAllTableCols(TableName.AccessApprovalPolicy))
.whereNotNull(`${TableName.AccessApprovalPolicy}.envId`); .whereNotNull(`${TableName.AccessApprovalPolicy}.envId`);
@@ -36,11 +38,13 @@ export async function up(knex: Knex): Promise<void> {
t.uuid("policyId").notNullable(); t.uuid("policyId").notNullable();
t.foreign("policyId").references("id").inTable(TableName.SecretApprovalPolicy).onDelete("CASCADE"); t.foreign("policyId").references("id").inTable(TableName.SecretApprovalPolicy).onDelete("CASCADE");
t.uuid("envId").notNullable(); t.uuid("envId").notNullable();
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("CASCADE"); t.foreign("envId").references("id").inTable(TableName.Environment);
t.timestamps(true, true, true); t.timestamps(true, true, true);
t.unique(["policyId", "envId"]); t.unique(["policyId", "envId"]);
}); });
await createOnUpdateTrigger(knex, TableName.SecretApprovalPolicyEnvironment);
const existingSecretApprovalPolicies = await knex(TableName.SecretApprovalPolicy) const existingSecretApprovalPolicies = await knex(TableName.SecretApprovalPolicy)
.select(selectAllTableCols(TableName.SecretApprovalPolicy)) .select(selectAllTableCols(TableName.SecretApprovalPolicy))
.whereNotNull(`${TableName.SecretApprovalPolicy}.envId`); .whereNotNull(`${TableName.SecretApprovalPolicy}.envId`);
@@ -68,9 +72,6 @@ export async function up(knex: Knex): Promise<void> {
// Add the new foreign key constraint with ON DELETE SET NULL // Add the new foreign key constraint with ON DELETE SET NULL
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("SET NULL"); t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("SET NULL");
}); });
await createOnUpdateTrigger(knex, TableName.AccessApprovalPolicyEnvironment);
await createOnUpdateTrigger(knex, TableName.SecretApprovalPolicyEnvironment);
} }
export async function down(knex: Knex): Promise<void> { export async function down(knex: Knex): Promise<void> {
@@ -354,16 +354,19 @@ export const accessApprovalPolicyServiceFactory = ({
envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: accessApprovalPolicy.projectId }); envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: accessApprovalPolicy.projectId });
} }
if ( for (const env of envs) {
await $policyExists({ if (
envIds: envs.map((env) => env.id), // eslint-disable-next-line no-await-in-loop
secretPath: secretPath || accessApprovalPolicy.secretPath, await $policyExists({
policyId: accessApprovalPolicy.id envId: env.id,
}) secretPath: secretPath || accessApprovalPolicy.secretPath,
) { policyId: accessApprovalPolicy.id
throw new BadRequestError({ })
message: `A policy for secret path '${secretPath}' already exists` ) {
}); throw new BadRequestError({
message: `A policy for secret path '${secretPath || accessApprovalPolicy.secretPath}' already exists in environment '${env.slug}'`
});
}
} }
const { permission } = await permissionService.getProjectPermission({ const { permission } = await permissionService.getProjectPermission({
@@ -315,16 +315,19 @@ export const secretApprovalPolicyServiceFactory = ({
) { ) {
envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: secretApprovalPolicy.projectId }); envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: secretApprovalPolicy.projectId });
} }
if ( for (const env of envs) {
await $policyExists({ if (
envIds: envs.map((env) => env.id), // eslint-disable-next-line no-await-in-loop
secretPath: secretPath || secretApprovalPolicy.secretPath, await $policyExists({
policyId: secretApprovalPolicy.id envId: env.id,
}) secretPath: secretPath || secretApprovalPolicy.secretPath,
) { policyId: secretApprovalPolicy.id
throw new BadRequestError({ })
message: `A policy for secret path '${secretPath}' already exists` ) {
}); throw new BadRequestError({
message: `A policy for secret path '${secretPath || secretApprovalPolicy.secretPath}' already exists in environment '${env.slug}'`
});
}
} }
const { permission } = await permissionService.getProjectPermission({ const { permission } = await permissionService.getProjectPermission({