mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 14:26:25 +00:00
Minor fixes on policies multi env migration
This commit is contained in:
@@ -12,11 +12,13 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
t.uuid("policyId").notNullable();
|
t.uuid("policyId").notNullable();
|
||||||
t.foreign("policyId").references("id").inTable(TableName.AccessApprovalPolicy).onDelete("CASCADE");
|
t.foreign("policyId").references("id").inTable(TableName.AccessApprovalPolicy).onDelete("CASCADE");
|
||||||
t.uuid("envId").notNullable();
|
t.uuid("envId").notNullable();
|
||||||
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("CASCADE");
|
t.foreign("envId").references("id").inTable(TableName.Environment);
|
||||||
t.timestamps(true, true, true);
|
t.timestamps(true, true, true);
|
||||||
t.unique(["policyId", "envId"]);
|
t.unique(["policyId", "envId"]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await createOnUpdateTrigger(knex, TableName.AccessApprovalPolicyEnvironment);
|
||||||
|
|
||||||
const existingAccessApprovalPolicies = await knex(TableName.AccessApprovalPolicy)
|
const existingAccessApprovalPolicies = await knex(TableName.AccessApprovalPolicy)
|
||||||
.select(selectAllTableCols(TableName.AccessApprovalPolicy))
|
.select(selectAllTableCols(TableName.AccessApprovalPolicy))
|
||||||
.whereNotNull(`${TableName.AccessApprovalPolicy}.envId`);
|
.whereNotNull(`${TableName.AccessApprovalPolicy}.envId`);
|
||||||
@@ -36,11 +38,13 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
t.uuid("policyId").notNullable();
|
t.uuid("policyId").notNullable();
|
||||||
t.foreign("policyId").references("id").inTable(TableName.SecretApprovalPolicy).onDelete("CASCADE");
|
t.foreign("policyId").references("id").inTable(TableName.SecretApprovalPolicy).onDelete("CASCADE");
|
||||||
t.uuid("envId").notNullable();
|
t.uuid("envId").notNullable();
|
||||||
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("CASCADE");
|
t.foreign("envId").references("id").inTable(TableName.Environment);
|
||||||
t.timestamps(true, true, true);
|
t.timestamps(true, true, true);
|
||||||
t.unique(["policyId", "envId"]);
|
t.unique(["policyId", "envId"]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await createOnUpdateTrigger(knex, TableName.SecretApprovalPolicyEnvironment);
|
||||||
|
|
||||||
const existingSecretApprovalPolicies = await knex(TableName.SecretApprovalPolicy)
|
const existingSecretApprovalPolicies = await knex(TableName.SecretApprovalPolicy)
|
||||||
.select(selectAllTableCols(TableName.SecretApprovalPolicy))
|
.select(selectAllTableCols(TableName.SecretApprovalPolicy))
|
||||||
.whereNotNull(`${TableName.SecretApprovalPolicy}.envId`);
|
.whereNotNull(`${TableName.SecretApprovalPolicy}.envId`);
|
||||||
@@ -68,9 +72,6 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
// Add the new foreign key constraint with ON DELETE SET NULL
|
// Add the new foreign key constraint with ON DELETE SET NULL
|
||||||
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("SET NULL");
|
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("SET NULL");
|
||||||
});
|
});
|
||||||
|
|
||||||
await createOnUpdateTrigger(knex, TableName.AccessApprovalPolicyEnvironment);
|
|
||||||
await createOnUpdateTrigger(knex, TableName.SecretApprovalPolicyEnvironment);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
|||||||
@@ -354,16 +354,19 @@ export const accessApprovalPolicyServiceFactory = ({
|
|||||||
envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: accessApprovalPolicy.projectId });
|
envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: accessApprovalPolicy.projectId });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (
|
for (const env of envs) {
|
||||||
await $policyExists({
|
if (
|
||||||
envIds: envs.map((env) => env.id),
|
// eslint-disable-next-line no-await-in-loop
|
||||||
secretPath: secretPath || accessApprovalPolicy.secretPath,
|
await $policyExists({
|
||||||
policyId: accessApprovalPolicy.id
|
envId: env.id,
|
||||||
})
|
secretPath: secretPath || accessApprovalPolicy.secretPath,
|
||||||
) {
|
policyId: accessApprovalPolicy.id
|
||||||
throw new BadRequestError({
|
})
|
||||||
message: `A policy for secret path '${secretPath}' already exists`
|
) {
|
||||||
});
|
throw new BadRequestError({
|
||||||
|
message: `A policy for secret path '${secretPath || accessApprovalPolicy.secretPath}' already exists in environment '${env.slug}'`
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission({
|
const { permission } = await permissionService.getProjectPermission({
|
||||||
|
|||||||
@@ -315,16 +315,19 @@ export const secretApprovalPolicyServiceFactory = ({
|
|||||||
) {
|
) {
|
||||||
envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: secretApprovalPolicy.projectId });
|
envs = await projectEnvDAL.find({ $in: { slug: environments }, projectId: secretApprovalPolicy.projectId });
|
||||||
}
|
}
|
||||||
if (
|
for (const env of envs) {
|
||||||
await $policyExists({
|
if (
|
||||||
envIds: envs.map((env) => env.id),
|
// eslint-disable-next-line no-await-in-loop
|
||||||
secretPath: secretPath || secretApprovalPolicy.secretPath,
|
await $policyExists({
|
||||||
policyId: secretApprovalPolicy.id
|
envId: env.id,
|
||||||
})
|
secretPath: secretPath || secretApprovalPolicy.secretPath,
|
||||||
) {
|
policyId: secretApprovalPolicy.id
|
||||||
throw new BadRequestError({
|
})
|
||||||
message: `A policy for secret path '${secretPath}' already exists`
|
) {
|
||||||
});
|
throw new BadRequestError({
|
||||||
|
message: `A policy for secret path '${secretPath || secretApprovalPolicy.secretPath}' already exists in environment '${env.slug}'`
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const { permission } = await permissionService.getProjectPermission({
|
const { permission } = await permissionService.getProjectPermission({
|
||||||
|
|||||||
Reference in New Issue
Block a user