Merge remote-tracking branch 'origin' into azure-auth

This commit is contained in:
Tuan Dang
2024-05-15 23:23:50 -07:00
3 changed files with 65 additions and 45 deletions
@@ -82,6 +82,7 @@ export const identityProjectServiceFactory = ({
role, role,
project.id project.id
); );
const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission); const hasPriviledge = isAtLeastAsPrivileged(permission, rolePermission);
if (!hasPriviledge) if (!hasPriviledge)
throw new ForbiddenRequestError({ throw new ForbiddenRequestError({
@@ -135,16 +136,18 @@ export const identityProjectServiceFactory = ({
message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}` message: `Identity with id ${identityId} doesn't exists in project with id ${projectId}`
}); });
const { permission: identityRolePermission } = await permissionService.getProjectPermission( for await (const { role: requestedRoleChange } of roles) {
ActorType.IDENTITY, const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
projectIdentity.identityId, requestedRoleChange,
projectIdentity.projectId, projectId
actorAuthMethod, );
actorOrgId
); const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, rolePermission);
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, identityRolePermission);
if (!hasRequiredPriviledges) if (!hasRequiredPriviledges) {
throw new ForbiddenRequestError({ message: "Failed to delete more privileged identity" }); throw new ForbiddenRequestError({ message: "Failed to change to a more privileged role" });
}
}
// validate custom roles input // validate custom roles input
const customInputRoles = roles.filter( const customInputRoles = roles.filter(
+5 -3
View File
@@ -353,7 +353,7 @@ export const interpolateSecrets = ({ projectId, secretEncKey, secretDAL, folderD
}; };
export const decryptSecretRaw = ( export const decryptSecretRaw = (
secret: TSecrets & { workspace: string; environment: string; secretPath?: string }, secret: TSecrets & { workspace: string; environment: string; secretPath: string },
key: string key: string
) => { ) => {
const secretKey = decryptSymmetric128BitHexKeyUTF8({ const secretKey = decryptSymmetric128BitHexKeyUTF8({
@@ -520,7 +520,8 @@ export const fnSecretBulkInsert = async ({
inputSecrets.map(({ references = [], secretBlindIndex }) => ({ inputSecrets.map(({ references = [], secretBlindIndex }) => ({
secretId: newSecretGroupByBlindIndex[secretBlindIndex as string][0].id, secretId: newSecretGroupByBlindIndex[secretBlindIndex as string][0].id,
references references
})) })),
tx
); );
if (newSecretTags.length) { if (newSecretTags.length) {
const secTags = await secretTagDAL.saveTagsToSecret(newSecretTags, tx); const secTags = await secretTagDAL.saveTagsToSecret(newSecretTags, tx);
@@ -565,7 +566,8 @@ export const fnSecretBulkUpdate = async ({
.map(({ data: { references = [] } }, i) => ({ .map(({ data: { references = [] } }, i) => ({
secretId: newSecrets[i].id, secretId: newSecrets[i].id,
references references
})) })),
tx
); );
const secsUpdatedTag = inputSecrets.flatMap(({ data: { tags } }, i) => const secsUpdatedTag = inputSecrets.flatMap(({ data: { tags } }, i) =>
tags !== undefined ? { tags, secretId: newSecrets[i].id } : [] tags !== undefined ? { tags, secretId: newSecrets[i].id } : []
+47 -32
View File
@@ -285,7 +285,7 @@ export const secretServiceFactory = ({
await snapshotService.performSnapshot(folderId); await snapshotService.performSnapshot(folderId);
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment }); await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot // TODO(akhilmhdh-pg): licence check, posthog service and snapshot
return { ...secret[0], environment, workspace: projectId, tags }; return { ...secret[0], environment, workspace: projectId, tags, secretPath: path };
}; };
const updateSecret = async ({ const updateSecret = async ({
@@ -415,7 +415,7 @@ export const secretServiceFactory = ({
await snapshotService.performSnapshot(folderId); await snapshotService.performSnapshot(folderId);
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment }); await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot // TODO(akhilmhdh-pg): licence check, posthog service and snapshot
return { ...updatedSecret[0], workspace: projectId, environment }; return { ...updatedSecret[0], workspace: projectId, environment, secretPath: path };
}; };
const deleteSecret = async ({ const deleteSecret = async ({
@@ -484,7 +484,7 @@ export const secretServiceFactory = ({
await secretQueueService.syncSecrets({ secretPath: path, projectId, environment }); await secretQueueService.syncSecrets({ secretPath: path, projectId, environment });
// TODO(akhilmhdh-pg): licence check, posthog service and snapshot // TODO(akhilmhdh-pg): licence check, posthog service and snapshot
return { ...deletedSecret[0], _id: deletedSecret[0].id, workspace: projectId, environment }; return { ...deletedSecret[0], _id: deletedSecret[0].id, workspace: projectId, environment, secretPath: path };
}; };
const getSecrets = async ({ const getSecrets = async ({
@@ -681,7 +681,8 @@ export const secretServiceFactory = ({
return { return {
...importedSecrets[i].secrets[j], ...importedSecrets[i].secrets[j],
workspace: projectId, workspace: projectId,
environment: importedSecrets[i].environment environment: importedSecrets[i].environment,
secretPath: importedSecrets[i].secretPath
}; };
} }
} }
@@ -689,7 +690,7 @@ export const secretServiceFactory = ({
} }
if (!secret) throw new BadRequestError({ message: "Secret not found" }); if (!secret) throw new BadRequestError({ message: "Secret not found" });
return { ...secret, workspace: projectId, environment }; return { ...secret, workspace: projectId, environment, secretPath: path };
}; };
const createManySecret = async ({ const createManySecret = async ({
@@ -980,34 +981,40 @@ export const secretServiceFactory = ({
}); });
const batchSecretsExpand = async ( const batchSecretsExpand = async (
secretBatch: { secretBatch: { secretKey: string; secretValue: string; secretComment?: string; secretPath: string }[]
secretKey: string;
secretValue: string;
secretComment?: string;
}[]
) => { ) => {
const secretRecord: Record< // Group secrets by secretPath
string, const secretsByPath: Record<string, { secretKey: string; secretValue: string; secretComment?: string }[]> = {};
{
value: string; secretBatch.forEach((secret) => {
comment?: string; if (!secretsByPath[secret.secretPath]) {
skipMultilineEncoding?: boolean; secretsByPath[secret.secretPath] = [];
} }
> = {}; secretsByPath[secret.secretPath].push(secret);
secretBatch.forEach((decryptedSecret) => {
secretRecord[decryptedSecret.secretKey] = {
value: decryptedSecret.secretValue,
comment: decryptedSecret.secretComment
};
}); });
await expandSecrets(secretRecord); // Expand secrets for each group
for (const secPath in secretsByPath) {
if (!Object.hasOwn(secretsByPath, path)) {
// eslint-disable-next-line no-continue
continue;
}
secretBatch.forEach((decryptedSecret, index) => { const secretRecord: Record<string, { value: string; comment?: string; skipMultilineEncoding?: boolean }> = {};
// eslint-disable-next-line no-param-reassign secretsByPath[secPath].forEach((decryptedSecret) => {
secretBatch[index].secretValue = secretRecord[decryptedSecret.secretKey].value; secretRecord[decryptedSecret.secretKey] = {
}); value: decryptedSecret.secretValue,
comment: decryptedSecret.secretComment
};
});
await expandSecrets(secretRecord);
secretsByPath[secPath].forEach((decryptedSecret) => {
// eslint-disable-next-line no-param-reassign
decryptedSecret.secretValue = secretRecord[decryptedSecret.secretKey].value;
});
}
}; };
// expand secrets // expand secrets
@@ -1055,6 +1062,7 @@ export const secretServiceFactory = ({
includeImports, includeImports,
version version
}); });
return decryptSecretRaw(secret, botKey); return decryptSecretRaw(secret, botKey);
}; };
@@ -1227,7 +1235,9 @@ export const secretServiceFactory = ({
await snapshotService.performSnapshot(secrets[0].folderId); await snapshotService.performSnapshot(secrets[0].folderId);
await secretQueueService.syncSecrets({ secretPath, projectId, environment }); await secretQueueService.syncSecrets({ secretPath, projectId, environment });
return secrets.map((secret) => decryptSecretRaw({ ...secret, workspace: projectId, environment }, botKey)); return secrets.map((secret) =>
decryptSecretRaw({ ...secret, workspace: projectId, environment, secretPath }, botKey)
);
}; };
const updateManySecretsRaw = async ({ const updateManySecretsRaw = async ({
@@ -1279,7 +1289,9 @@ export const secretServiceFactory = ({
await snapshotService.performSnapshot(secrets[0].folderId); await snapshotService.performSnapshot(secrets[0].folderId);
await secretQueueService.syncSecrets({ secretPath, projectId, environment }); await secretQueueService.syncSecrets({ secretPath, projectId, environment });
return secrets.map((secret) => decryptSecretRaw({ ...secret, workspace: projectId, environment }, botKey)); return secrets.map((secret) =>
decryptSecretRaw({ ...secret, workspace: projectId, environment, secretPath }, botKey)
);
}; };
const deleteManySecretsRaw = async ({ const deleteManySecretsRaw = async ({
@@ -1313,7 +1325,9 @@ export const secretServiceFactory = ({
await snapshotService.performSnapshot(secrets[0].folderId); await snapshotService.performSnapshot(secrets[0].folderId);
await secretQueueService.syncSecrets({ secretPath, projectId, environment }); await secretQueueService.syncSecrets({ secretPath, projectId, environment });
return secrets.map((secret) => decryptSecretRaw({ ...secret, workspace: projectId, environment }, botKey)); return secrets.map((secret) =>
decryptSecretRaw({ ...secret, workspace: projectId, environment, secretPath }, botKey)
);
}; };
const getSecretVersions = async ({ const getSecretVersions = async ({
@@ -1582,7 +1596,8 @@ export const secretServiceFactory = ({
key: botKey key: botKey
}) })
) )
})) })),
tx
); );
}); });