mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 23:28:25 +00:00
Merge remote-tracking branch 'origin' into azure-auth
This commit is contained in:
@@ -82,6 +82,7 @@ export const identityProjectServiceFactory = ({
|
|||||||
role,
|
role,
|
||||||
project.id
|
project.id
|
||||||
);
|
);
|
||||||
|
|
||||||
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
|
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
if (!hasPriviledge)
|
if (!hasPriviledge)
|
||||||
throw new ForbiddenRequestError({
|
throw new ForbiddenRequestError({
|
||||||
@@ -135,16 +136,18 @@ export const identityProjectServiceFactory = ({
|
|||||||
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
|
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
const { permission: identityRolePermission } = await permissionService.getProjectPermission(
|
for await (const { role: requestedRoleChange } of roles) {
|
||||||
ActorType.IDENTITY,
|
const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
|
||||||
projectIdentity.identityId,
|
requestedRoleChange,
|
||||||
projectIdentity.projectId,
|
projectId
|
||||||
actorAuthMethod,
|
);
|
||||||
actorOrgId
|
|
||||||
);
|
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, rolePermission);
|
||||||
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, identityRolePermission);
|
|
||||||
if (!hasRequiredPriviledges)
|
if (!hasRequiredPriviledges) {
|
||||||
throw new ForbiddenRequestError({ message: "Failed to delete more privileged identity" });
|
throw new ForbiddenRequestError({ message: "Failed to change to a more privileged role" });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// validate custom roles input
|
// validate custom roles input
|
||||||
const customInputRoles = roles.filter(
|
const customInputRoles = roles.filter(
|
||||||
|
|||||||
@@ -353,7 +353,7 @@ export const interpolateSecrets = ({ projectId, secretEncKey, secretDAL, folderD
|
|||||||
};
|
};
|
||||||
|
|
||||||
export const decryptSecretRaw = (
|
export const decryptSecretRaw = (
|
||||||
secret: TSecrets & { workspace: string; environment: string; secretPath?: string },
|
secret: TSecrets & { workspace: string; environment: string; secretPath: string },
|
||||||
key: string
|
key: string
|
||||||
) => {
|
) => {
|
||||||
const secretKey = decryptSymmetric128BitHexKeyUTF8({
|
const secretKey = decryptSymmetric128BitHexKeyUTF8({
|
||||||
@@ -520,7 +520,8 @@ export const fnSecretBulkInsert = async ({
|
|||||||
inputSecrets.map(({ references = [], secretBlindIndex }) => ({
|
inputSecrets.map(({ references = [], secretBlindIndex }) => ({
|
||||||
secretId: newSecretGroupByBlindIndex[secretBlindIndex as string][0].id,
|
secretId: newSecretGroupByBlindIndex[secretBlindIndex as string][0].id,
|
||||||
references
|
references
|
||||||
}))
|
})),
|
||||||
|
tx
|
||||||
);
|
);
|
||||||
if (newSecretTags.length) {
|
if (newSecretTags.length) {
|
||||||
const secTags = await secretTagDAL.saveTagsToSecret(newSecretTags, tx);
|
const secTags = await secretTagDAL.saveTagsToSecret(newSecretTags, tx);
|
||||||
@@ -565,7 +566,8 @@ export const fnSecretBulkUpdate = async ({
|
|||||||
.map(({ data: { references = [] } }, i) => ({
|
.map(({ data: { references = [] } }, i) => ({
|
||||||
secretId: newSecrets[i].id,
|
secretId: newSecrets[i].id,
|
||||||
references
|
references
|
||||||
}))
|
})),
|
||||||
|
tx
|
||||||
);
|
);
|
||||||
const secsUpdatedTag = inputSecrets.flatMap(({ data: { tags } }, i) =>
|
const secsUpdatedTag = inputSecrets.flatMap(({ data: { tags } }, i) =>
|
||||||
tags !== undefined ? { tags, secretId: newSecrets[i].id } : []
|
tags !== undefined ? { tags, secretId: newSecrets[i].id } : []
|
||||||
|
|||||||
@@ -285,7 +285,7 @@ export const secretServiceFactory = ({
|
|||||||
await snapshotService.performSnapshot(folderId);
|
await snapshotService.performSnapshot(folderId);
|
||||||
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
|
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
|
||||||
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot
|
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot
|
||||||
return { ...secret[0], environment, workspace: projectId, tags };
|
return { ...secret[0], environment, workspace: projectId, tags, secretPath: path };
|
||||||
};
|
};
|
||||||
|
|
||||||
const updateSecret = async ({
|
const updateSecret = async ({
|
||||||
@@ -415,7 +415,7 @@ export const secretServiceFactory = ({
|
|||||||
await snapshotService.performSnapshot(folderId);
|
await snapshotService.performSnapshot(folderId);
|
||||||
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
|
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
|
||||||
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot
|
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot
|
||||||
return { ...updatedSecret[0], workspace: projectId, environment };
|
return { ...updatedSecret[0], workspace: projectId, environment, secretPath: path };
|
||||||
};
|
};
|
||||||
|
|
||||||
const deleteSecret = async ({
|
const deleteSecret = async ({
|
||||||
@@ -484,7 +484,7 @@ export const secretServiceFactory = ({
|
|||||||
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
|
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
|
||||||
|
|
||||||
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot
|
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot
|
||||||
return { ...deletedSecret[0], _id: deletedSecret[0].id, workspace: projectId, environment };
|
return { ...deletedSecret[0], _id: deletedSecret[0].id, workspace: projectId, environment, secretPath: path };
|
||||||
};
|
};
|
||||||
|
|
||||||
const getSecrets = async ({
|
const getSecrets = async ({
|
||||||
@@ -681,7 +681,8 @@ export const secretServiceFactory = ({
|
|||||||
return {
|
return {
|
||||||
...importedSecrets[i].secrets[j],
|
...importedSecrets[i].secrets[j],
|
||||||
workspace: projectId,
|
workspace: projectId,
|
||||||
environment: importedSecrets[i].environment
|
environment: importedSecrets[i].environment,
|
||||||
|
secretPath: importedSecrets[i].secretPath
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -689,7 +690,7 @@ export const secretServiceFactory = ({
|
|||||||
}
|
}
|
||||||
if (!secret) throw new BadRequestError({ message: "Secret not found" });
|
if (!secret) throw new BadRequestError({ message: "Secret not found" });
|
||||||
|
|
||||||
return { ...secret, workspace: projectId, environment };
|
return { ...secret, workspace: projectId, environment, secretPath: path };
|
||||||
};
|
};
|
||||||
|
|
||||||
const createManySecret = async ({
|
const createManySecret = async ({
|
||||||
@@ -980,34 +981,40 @@ export const secretServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
const batchSecretsExpand = async (
|
const batchSecretsExpand = async (
|
||||||
secretBatch: {
|
secretBatch: { secretKey: string; secretValue: string; secretComment?: string; secretPath: string }[]
|
||||||
secretKey: string;
|
|
||||||
secretValue: string;
|
|
||||||
secretComment?: string;
|
|
||||||
}[]
|
|
||||||
) => {
|
) => {
|
||||||
const secretRecord: Record<
|
// Group secrets by secretPath
|
||||||
string,
|
const secretsByPath: Record<string, { secretKey: string; secretValue: string; secretComment?: string }[]> = {};
|
||||||
{
|
|
||||||
value: string;
|
secretBatch.forEach((secret) => {
|
||||||
comment?: string;
|
if (!secretsByPath[secret.secretPath]) {
|
||||||
skipMultilineEncoding?: boolean;
|
secretsByPath[secret.secretPath] = [];
|
||||||
}
|
}
|
||||||
> = {};
|
secretsByPath[secret.secretPath].push(secret);
|
||||||
|
|
||||||
secretBatch.forEach((decryptedSecret) => {
|
|
||||||
secretRecord[decryptedSecret.secretKey] = {
|
|
||||||
value: decryptedSecret.secretValue,
|
|
||||||
comment: decryptedSecret.secretComment
|
|
||||||
};
|
|
||||||
});
|
});
|
||||||
|
|
||||||
await expandSecrets(secretRecord);
|
// Expand secrets for each group
|
||||||
|
for (const secPath in secretsByPath) {
|
||||||
|
if (!Object.hasOwn(secretsByPath, path)) {
|
||||||
|
// eslint-disable-next-line no-continue
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
secretBatch.forEach((decryptedSecret, index) => {
|
const secretRecord: Record<string, { value: string; comment?: string; skipMultilineEncoding?: boolean }> = {};
|
||||||
// eslint-disable-next-line no-param-reassign
|
secretsByPath[secPath].forEach((decryptedSecret) => {
|
||||||
secretBatch[index].secretValue = secretRecord[decryptedSecret.secretKey].value;
|
secretRecord[decryptedSecret.secretKey] = {
|
||||||
});
|
value: decryptedSecret.secretValue,
|
||||||
|
comment: decryptedSecret.secretComment
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
await expandSecrets(secretRecord);
|
||||||
|
|
||||||
|
secretsByPath[secPath].forEach((decryptedSecret) => {
|
||||||
|
// eslint-disable-next-line no-param-reassign
|
||||||
|
decryptedSecret.secretValue = secretRecord[decryptedSecret.secretKey].value;
|
||||||
|
});
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
// expand secrets
|
// expand secrets
|
||||||
@@ -1055,6 +1062,7 @@ export const secretServiceFactory = ({
|
|||||||
includeImports,
|
includeImports,
|
||||||
version
|
version
|
||||||
});
|
});
|
||||||
|
|
||||||
return decryptSecretRaw(secret, botKey);
|
return decryptSecretRaw(secret, botKey);
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -1227,7 +1235,9 @@ export const secretServiceFactory = ({
|
|||||||
await snapshotService.performSnapshot(secrets[0].folderId);
|
await snapshotService.performSnapshot(secrets[0].folderId);
|
||||||
await secretQueueService.syncSecrets({ secretPath, projectId, environment });
|
await secretQueueService.syncSecrets({ secretPath, projectId, environment });
|
||||||
|
|
||||||
return secrets.map((secret) => decryptSecretRaw({ ...secret, workspace: projectId, environment }, botKey));
|
return secrets.map((secret) =>
|
||||||
|
decryptSecretRaw({ ...secret, workspace: projectId, environment, secretPath }, botKey)
|
||||||
|
);
|
||||||
};
|
};
|
||||||
|
|
||||||
const updateManySecretsRaw = async ({
|
const updateManySecretsRaw = async ({
|
||||||
@@ -1279,7 +1289,9 @@ export const secretServiceFactory = ({
|
|||||||
await snapshotService.performSnapshot(secrets[0].folderId);
|
await snapshotService.performSnapshot(secrets[0].folderId);
|
||||||
await secretQueueService.syncSecrets({ secretPath, projectId, environment });
|
await secretQueueService.syncSecrets({ secretPath, projectId, environment });
|
||||||
|
|
||||||
return secrets.map((secret) => decryptSecretRaw({ ...secret, workspace: projectId, environment }, botKey));
|
return secrets.map((secret) =>
|
||||||
|
decryptSecretRaw({ ...secret, workspace: projectId, environment, secretPath }, botKey)
|
||||||
|
);
|
||||||
};
|
};
|
||||||
|
|
||||||
const deleteManySecretsRaw = async ({
|
const deleteManySecretsRaw = async ({
|
||||||
@@ -1313,7 +1325,9 @@ export const secretServiceFactory = ({
|
|||||||
await snapshotService.performSnapshot(secrets[0].folderId);
|
await snapshotService.performSnapshot(secrets[0].folderId);
|
||||||
await secretQueueService.syncSecrets({ secretPath, projectId, environment });
|
await secretQueueService.syncSecrets({ secretPath, projectId, environment });
|
||||||
|
|
||||||
return secrets.map((secret) => decryptSecretRaw({ ...secret, workspace: projectId, environment }, botKey));
|
return secrets.map((secret) =>
|
||||||
|
decryptSecretRaw({ ...secret, workspace: projectId, environment, secretPath }, botKey)
|
||||||
|
);
|
||||||
};
|
};
|
||||||
|
|
||||||
const getSecretVersions = async ({
|
const getSecretVersions = async ({
|
||||||
@@ -1582,7 +1596,8 @@ export const secretServiceFactory = ({
|
|||||||
key: botKey
|
key: botKey
|
||||||
})
|
})
|
||||||
)
|
)
|
||||||
}))
|
})),
|
||||||
|
tx
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user