Merge pull request #1239 from Infisical/workspace-key-log

add workspace id and receiver to getWorkspaceKey error
This commit is contained in:
Maidul Islam
2023-12-13 11:28:14 -05:00
committed by GitHub
@@ -1,10 +1,10 @@
import { Request, Response } from "express"; import { Request, Response } from "express";
import { Types } from "mongoose"; import { Types } from "mongoose";
import { import {
IIdentity, IIdentity,
IdentityMembership, IdentityMembership,
IdentityMembershipOrg, IdentityMembershipOrg,
Key, Key,
Membership, Membership,
ServiceTokenData, ServiceTokenData,
Workspace Workspace
@@ -182,11 +182,11 @@ export const getWorkspaceKey = async (req: Request, res: Response) => {
"apiKeyAuth": [] "apiKeyAuth": []
}] }]
#swagger.parameters['workspaceId'] = { #swagger.parameters['workspaceId'] = {
"description": "ID of project", "description": "ID of project",
"required": true, "required": true,
"type": "string" "type": "string"
} }
#swagger.responses[200] = { #swagger.responses[200] = {
content: { content: {
@@ -211,7 +211,7 @@ export const getWorkspaceKey = async (req: Request, res: Response) => {
receiver: req.user._id receiver: req.user._id
}).populate("sender", "+publicKey"); }).populate("sender", "+publicKey");
if (!key) throw new Error("Failed to find workspace key"); if (!key) throw new Error(`getWorkspaceKey: Failed to find workspace key [workspaceId=${workspaceId}] [receiver=${req.user._id}]`);
await EEAuditLogService.createAuditLog( await EEAuditLogService.createAuditLog(
req.authData, req.authData,
@@ -256,26 +256,26 @@ export const getWorkspaceMemberships = async (req: Request, res: Response) => {
"apiKeyAuth": [] "apiKeyAuth": []
}] }]
#swagger.parameters['workspaceId'] = { #swagger.parameters['workspaceId'] = {
"description": "ID of project", "description": "ID of project",
"required": true, "required": true,
"type": "string" "type": "string"
} }
#swagger.responses[200] = { #swagger.responses[200] = {
content: { content: {
"application/json": { "application/json": {
"schema": { "schema": {
"type": "object", "type": "object",
"properties": { "properties": {
"memberships": { "memberships": {
"type": "array", "type": "array",
"items": { "items": {
$ref: "#/components/schemas/Membership" $ref: "#/components/schemas/Membership"
}, },
"description": "Memberships of project" "description": "Memberships of project"
} }
} }
} }
} }
} }
@@ -319,19 +319,19 @@ export const updateWorkspaceMembership = async (req: Request, res: Response) =>
"apiKeyAuth": [] "apiKeyAuth": []
}] }]
#swagger.parameters['workspaceId'] = { #swagger.parameters['workspaceId'] = {
"description": "ID of project", "description": "ID of project",
"required": true, "required": true,
"type": "string" "type": "string"
} }
#swagger.parameters['membershipId'] = { #swagger.parameters['membershipId'] = {
"description": "ID of project membership to update", "description": "ID of project membership to update",
"required": true, "required": true,
"type": "string" "type": "string"
} }
#swagger.requestBody = { #swagger.requestBody = {
"required": true, "required": true,
"content": { "content": {
"application/json": { "application/json": {
@@ -352,13 +352,13 @@ export const updateWorkspaceMembership = async (req: Request, res: Response) =>
content: { content: {
"application/json": { "application/json": {
"schema": { "schema": {
"type": "object", "type": "object",
"properties": { "properties": {
"membership": { "membership": {
$ref: "#/components/schemas/Membership", $ref: "#/components/schemas/Membership",
"description": "Updated membership" "description": "Updated membership"
} }
} }
} }
} }
} }
@@ -409,29 +409,29 @@ export const deleteWorkspaceMembership = async (req: Request, res: Response) =>
"apiKeyAuth": [] "apiKeyAuth": []
}] }]
#swagger.parameters['workspaceId'] = { #swagger.parameters['workspaceId'] = {
"description": "ID of project", "description": "ID of project",
"required": true, "required": true,
"type": "string" "type": "string"
} }
#swagger.parameters['membershipId'] = { #swagger.parameters['membershipId'] = {
"description": "ID of project membership to delete", "description": "ID of project membership to delete",
"required": true, "required": true,
"type": "string" "type": "string"
} }
#swagger.responses[200] = { #swagger.responses[200] = {
content: { content: {
"application/json": { "application/json": {
"schema": { "schema": {
"type": "object", "type": "object",
"properties": { "properties": {
"membership": { "membership": {
$ref: "#/components/schemas/Membership", $ref: "#/components/schemas/Membership",
"description": "Deleted membership" "description": "Deleted membership"
} }
} }
} }
} }
} }
@@ -511,14 +511,14 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
* @param req * @param req
* @param res * @param res
*/ */
export const addIdentityToWorkspace = async (req: Request, res: Response) => { export const addIdentityToWorkspace = async (req: Request, res: Response) => {
const { const {
params: { workspaceId, identityId }, params: { workspaceId, identityId },
body: { body: {
role role
} }
} = await validateRequest(reqValidator.AddIdentityToWorkspaceV2, req); } = await validateRequest(reqValidator.AddIdentityToWorkspaceV2, req);
const { permission } = await getAuthDataProjectPermissions({ const { permission } = await getAuthDataProjectPermissions({
authData: req.authData, authData: req.authData,
workspaceId: new Types.ObjectId(workspaceId) workspaceId: new Types.ObjectId(workspaceId)
@@ -538,7 +538,7 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
message: `Identity with id ${identityId} already exists in project with id ${workspaceId}` message: `Identity with id ${identityId} already exists in project with id ${workspaceId}`
}); });
const workspace = await Workspace.findById(workspaceId); const workspace = await Workspace.findById(workspaceId);
if (!workspace) throw ResourceNotFoundError(); if (!workspace) throw ResourceNotFoundError();
@@ -550,16 +550,16 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
if (!identityMembershipOrg) throw ResourceNotFoundError({ if (!identityMembershipOrg) throw ResourceNotFoundError({
message: `Failed to find identity with id ${identityId}` message: `Failed to find identity with id ${identityId}`
}); });
if (!identityMembershipOrg.organization.equals(workspace.organization)) throw BadRequestError({ if (!identityMembershipOrg.organization.equals(workspace.organization)) throw BadRequestError({
message: "Failed to add identity to project in another organization" message: "Failed to add identity to project in another organization"
}); });
const rolePermission = await getWorkspaceRolePermissions(role, workspaceId); const rolePermission = await getWorkspaceRolePermissions(role, workspaceId);
const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission); const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission);
if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({ if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({
message: "Failed to add identity to project with more privileged role" message: "Failed to add identity to project with more privileged role"
}); });
let customRole; let customRole;
@@ -571,18 +571,18 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
isOrgRole: false, isOrgRole: false,
workspace: new Types.ObjectId(workspaceId) workspace: new Types.ObjectId(workspaceId)
}); });
if (!customRole) throw BadRequestError({ message: "Role not found" }); if (!customRole) throw BadRequestError({ message: "Role not found" });
} }
} }
identityMembership = await new IdentityMembership({ identityMembership = await new IdentityMembership({
identity: identityMembershipOrg.identity, identity: identityMembershipOrg.identity,
workspace: new Types.ObjectId(workspaceId), workspace: new Types.ObjectId(workspaceId),
role: customRole ? CUSTOM : role, role: customRole ? CUSTOM : role,
customRole customRole
}).save(); }).save();
return res.status(200).send({ return res.status(200).send({
identityMembership identityMembership
}); });
@@ -594,14 +594,14 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
* @param req * @param req
* @param res * @param res
*/ */
export const updateIdentityWorkspaceRole = async (req: Request, res: Response) => { export const updateIdentityWorkspaceRole = async (req: Request, res: Response) => {
const { const {
params: { workspaceId, identityId }, params: { workspaceId, identityId },
body: { body: {
role role
} }
} = await validateRequest(reqValidator.UpdateIdentityWorkspaceRoleV2, req); } = await validateRequest(reqValidator.UpdateIdentityWorkspaceRoleV2, req);
const { permission } = await getAuthDataProjectPermissions({ const { permission } = await getAuthDataProjectPermissions({
authData: req.authData, authData: req.authData,
workspaceId: new Types.ObjectId(workspaceId) workspaceId: new Types.ObjectId(workspaceId)
@@ -611,7 +611,7 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
ProjectPermissionActions.Edit, ProjectPermissionActions.Edit,
ProjectPermissionSub.Identity ProjectPermissionSub.Identity
); );
let identityMembership = await IdentityMembership let identityMembership = await IdentityMembership
.findOne({ .findOne({
identity: new Types.ObjectId(identityId), identity: new Types.ObjectId(identityId),
@@ -625,21 +625,21 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
if (!identityMembership) throw BadRequestError({ if (!identityMembership) throw BadRequestError({
message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}` message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}`
}); });
const identityRolePermission = await getWorkspaceRolePermissions( const identityRolePermission = await getWorkspaceRolePermissions(
identityMembership?.customRole?.slug ?? identityMembership.role, identityMembership?.customRole?.slug ?? identityMembership.role,
identityMembership.workspace.toString() identityMembership.workspace.toString()
); );
const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission); const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission);
if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({ if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({
message: "Failed to update role of more privileged identity" message: "Failed to update role of more privileged identity"
}); });
const rolePermission = await getWorkspaceRolePermissions(role, workspaceId); const rolePermission = await getWorkspaceRolePermissions(role, workspaceId);
const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission); const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission);
if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({ if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({
message: "Failed to update identity to a more privileged role" message: "Failed to update identity to a more privileged role"
}); });
let customRole; let customRole;
@@ -651,11 +651,11 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
isOrgRole: false, isOrgRole: false,
workspace: new Types.ObjectId(workspaceId) workspace: new Types.ObjectId(workspaceId)
}); });
if (!customRole) throw BadRequestError({ message: "Role not found" }); if (!customRole) throw BadRequestError({ message: "Role not found" });
} }
} }
identityMembership = await IdentityMembership.findOneAndUpdate( identityMembership = await IdentityMembership.findOneAndUpdate(
{ {
identity: identityMembership.identity._id, identity: identityMembership.identity._id,
@@ -681,11 +681,11 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
* @param req * @param req
* @param res * @param res
*/ */
export const deleteIdentityFromWorkspace = async (req: Request, res: Response) => { export const deleteIdentityFromWorkspace = async (req: Request, res: Response) => {
const { const {
params: { workspaceId, identityId } params: { workspaceId, identityId }
} = await validateRequest(reqValidator.DeleteIdentityFromWorkspaceV2, req); } = await validateRequest(reqValidator.DeleteIdentityFromWorkspaceV2, req);
const { permission } = await getAuthDataProjectPermissions({ const { permission } = await getAuthDataProjectPermissions({
authData: req.authData, authData: req.authData,
workspaceId: new Types.ObjectId(workspaceId) workspaceId: new Types.ObjectId(workspaceId)
@@ -695,7 +695,7 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
ProjectPermissionActions.Delete, ProjectPermissionActions.Delete,
ProjectPermissionSub.Identity ProjectPermissionSub.Identity
); );
const identityMembership = await IdentityMembership const identityMembership = await IdentityMembership
.findOne({ .findOne({
identity: new Types.ObjectId(identityId), identity: new Types.ObjectId(identityId),
@@ -705,20 +705,20 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
identity: IIdentity, identity: IIdentity,
customRole: IRole customRole: IRole
}>("identity customRole"); }>("identity customRole");
if (!identityMembership) throw ResourceNotFoundError({ if (!identityMembership) throw ResourceNotFoundError({
message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}` message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}`
}); });
const identityRolePermission = await getWorkspaceRolePermissions( const identityRolePermission = await getWorkspaceRolePermissions(
identityMembership?.customRole?.slug ?? identityMembership.role, identityMembership?.customRole?.slug ?? identityMembership.role,
identityMembership.workspace.toString() identityMembership.workspace.toString()
); );
const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission); const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission);
if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({ if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({
message: "Failed to remove more privileged identity from project" message: "Failed to remove more privileged identity from project"
}); });
await IdentityMembership.findByIdAndDelete(identityMembership._id); await IdentityMembership.findByIdAndDelete(identityMembership._id);
return res.status(200).send({ return res.status(200).send({
@@ -732,11 +732,11 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
* @param res * @param res
* @returns * @returns
*/ */
export const getWorkspaceIdentityMemberships = async (req: Request, res: Response) => { export const getWorkspaceIdentityMemberships = async (req: Request, res: Response) => {
const { const {
params: { workspaceId } params: { workspaceId }
} = await validateRequest(reqValidator.GetWorkspaceIdentityMembersV2, req); } = await validateRequest(reqValidator.GetWorkspaceIdentityMembersV2, req);
const { permission } = await getAuthDataProjectPermissions({ const { permission } = await getAuthDataProjectPermissions({
authData: req.authData, authData: req.authData,
workspaceId: new Types.ObjectId(workspaceId) workspaceId: new Types.ObjectId(workspaceId)