mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 15:26:35 +00:00
Merge pull request #1239 from Infisical/workspace-key-log
add workspace id and receiver to getWorkspaceKey error
This commit is contained in:
@@ -1,10 +1,10 @@
|
|||||||
import { Request, Response } from "express";
|
import { Request, Response } from "express";
|
||||||
import { Types } from "mongoose";
|
import { Types } from "mongoose";
|
||||||
import {
|
import {
|
||||||
IIdentity,
|
IIdentity,
|
||||||
IdentityMembership,
|
IdentityMembership,
|
||||||
IdentityMembershipOrg,
|
IdentityMembershipOrg,
|
||||||
Key,
|
Key,
|
||||||
Membership,
|
Membership,
|
||||||
ServiceTokenData,
|
ServiceTokenData,
|
||||||
Workspace
|
Workspace
|
||||||
@@ -182,11 +182,11 @@ export const getWorkspaceKey = async (req: Request, res: Response) => {
|
|||||||
"apiKeyAuth": []
|
"apiKeyAuth": []
|
||||||
}]
|
}]
|
||||||
|
|
||||||
#swagger.parameters['workspaceId'] = {
|
#swagger.parameters['workspaceId'] = {
|
||||||
"description": "ID of project",
|
"description": "ID of project",
|
||||||
"required": true,
|
"required": true,
|
||||||
"type": "string"
|
"type": "string"
|
||||||
}
|
}
|
||||||
|
|
||||||
#swagger.responses[200] = {
|
#swagger.responses[200] = {
|
||||||
content: {
|
content: {
|
||||||
@@ -211,7 +211,7 @@ export const getWorkspaceKey = async (req: Request, res: Response) => {
|
|||||||
receiver: req.user._id
|
receiver: req.user._id
|
||||||
}).populate("sender", "+publicKey");
|
}).populate("sender", "+publicKey");
|
||||||
|
|
||||||
if (!key) throw new Error("Failed to find workspace key");
|
if (!key) throw new Error(`getWorkspaceKey: Failed to find workspace key [workspaceId=${workspaceId}] [receiver=${req.user._id}]`);
|
||||||
|
|
||||||
await EEAuditLogService.createAuditLog(
|
await EEAuditLogService.createAuditLog(
|
||||||
req.authData,
|
req.authData,
|
||||||
@@ -256,26 +256,26 @@ export const getWorkspaceMemberships = async (req: Request, res: Response) => {
|
|||||||
"apiKeyAuth": []
|
"apiKeyAuth": []
|
||||||
}]
|
}]
|
||||||
|
|
||||||
#swagger.parameters['workspaceId'] = {
|
#swagger.parameters['workspaceId'] = {
|
||||||
"description": "ID of project",
|
"description": "ID of project",
|
||||||
"required": true,
|
"required": true,
|
||||||
"type": "string"
|
"type": "string"
|
||||||
}
|
}
|
||||||
|
|
||||||
#swagger.responses[200] = {
|
#swagger.responses[200] = {
|
||||||
content: {
|
content: {
|
||||||
"application/json": {
|
"application/json": {
|
||||||
"schema": {
|
"schema": {
|
||||||
"type": "object",
|
"type": "object",
|
||||||
"properties": {
|
"properties": {
|
||||||
"memberships": {
|
"memberships": {
|
||||||
"type": "array",
|
"type": "array",
|
||||||
"items": {
|
"items": {
|
||||||
$ref: "#/components/schemas/Membership"
|
$ref: "#/components/schemas/Membership"
|
||||||
},
|
},
|
||||||
"description": "Memberships of project"
|
"description": "Memberships of project"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -319,19 +319,19 @@ export const updateWorkspaceMembership = async (req: Request, res: Response) =>
|
|||||||
"apiKeyAuth": []
|
"apiKeyAuth": []
|
||||||
}]
|
}]
|
||||||
|
|
||||||
#swagger.parameters['workspaceId'] = {
|
#swagger.parameters['workspaceId'] = {
|
||||||
"description": "ID of project",
|
"description": "ID of project",
|
||||||
"required": true,
|
"required": true,
|
||||||
"type": "string"
|
"type": "string"
|
||||||
}
|
}
|
||||||
|
|
||||||
#swagger.parameters['membershipId'] = {
|
#swagger.parameters['membershipId'] = {
|
||||||
"description": "ID of project membership to update",
|
"description": "ID of project membership to update",
|
||||||
"required": true,
|
"required": true,
|
||||||
"type": "string"
|
"type": "string"
|
||||||
}
|
}
|
||||||
|
|
||||||
#swagger.requestBody = {
|
#swagger.requestBody = {
|
||||||
"required": true,
|
"required": true,
|
||||||
"content": {
|
"content": {
|
||||||
"application/json": {
|
"application/json": {
|
||||||
@@ -352,13 +352,13 @@ export const updateWorkspaceMembership = async (req: Request, res: Response) =>
|
|||||||
content: {
|
content: {
|
||||||
"application/json": {
|
"application/json": {
|
||||||
"schema": {
|
"schema": {
|
||||||
"type": "object",
|
"type": "object",
|
||||||
"properties": {
|
"properties": {
|
||||||
"membership": {
|
"membership": {
|
||||||
$ref: "#/components/schemas/Membership",
|
$ref: "#/components/schemas/Membership",
|
||||||
"description": "Updated membership"
|
"description": "Updated membership"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -409,29 +409,29 @@ export const deleteWorkspaceMembership = async (req: Request, res: Response) =>
|
|||||||
"apiKeyAuth": []
|
"apiKeyAuth": []
|
||||||
}]
|
}]
|
||||||
|
|
||||||
#swagger.parameters['workspaceId'] = {
|
#swagger.parameters['workspaceId'] = {
|
||||||
"description": "ID of project",
|
"description": "ID of project",
|
||||||
"required": true,
|
"required": true,
|
||||||
"type": "string"
|
"type": "string"
|
||||||
}
|
}
|
||||||
|
|
||||||
#swagger.parameters['membershipId'] = {
|
#swagger.parameters['membershipId'] = {
|
||||||
"description": "ID of project membership to delete",
|
"description": "ID of project membership to delete",
|
||||||
"required": true,
|
"required": true,
|
||||||
"type": "string"
|
"type": "string"
|
||||||
}
|
}
|
||||||
|
|
||||||
#swagger.responses[200] = {
|
#swagger.responses[200] = {
|
||||||
content: {
|
content: {
|
||||||
"application/json": {
|
"application/json": {
|
||||||
"schema": {
|
"schema": {
|
||||||
"type": "object",
|
"type": "object",
|
||||||
"properties": {
|
"properties": {
|
||||||
"membership": {
|
"membership": {
|
||||||
$ref: "#/components/schemas/Membership",
|
$ref: "#/components/schemas/Membership",
|
||||||
"description": "Deleted membership"
|
"description": "Deleted membership"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -511,14 +511,14 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
* @param req
|
* @param req
|
||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
export const addIdentityToWorkspace = async (req: Request, res: Response) => {
|
export const addIdentityToWorkspace = async (req: Request, res: Response) => {
|
||||||
const {
|
const {
|
||||||
params: { workspaceId, identityId },
|
params: { workspaceId, identityId },
|
||||||
body: {
|
body: {
|
||||||
role
|
role
|
||||||
}
|
}
|
||||||
} = await validateRequest(reqValidator.AddIdentityToWorkspaceV2, req);
|
} = await validateRequest(reqValidator.AddIdentityToWorkspaceV2, req);
|
||||||
|
|
||||||
const { permission } = await getAuthDataProjectPermissions({
|
const { permission } = await getAuthDataProjectPermissions({
|
||||||
authData: req.authData,
|
authData: req.authData,
|
||||||
workspaceId: new Types.ObjectId(workspaceId)
|
workspaceId: new Types.ObjectId(workspaceId)
|
||||||
@@ -538,7 +538,7 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
message: `Identity with id ${identityId} already exists in project with id ${workspaceId}`
|
message: `Identity with id ${identityId} already exists in project with id ${workspaceId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
||||||
const workspace = await Workspace.findById(workspaceId);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
if (!workspace) throw ResourceNotFoundError();
|
if (!workspace) throw ResourceNotFoundError();
|
||||||
|
|
||||||
@@ -550,16 +550,16 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
if (!identityMembershipOrg) throw ResourceNotFoundError({
|
if (!identityMembershipOrg) throw ResourceNotFoundError({
|
||||||
message: `Failed to find identity with id ${identityId}`
|
message: `Failed to find identity with id ${identityId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!identityMembershipOrg.organization.equals(workspace.organization)) throw BadRequestError({
|
if (!identityMembershipOrg.organization.equals(workspace.organization)) throw BadRequestError({
|
||||||
message: "Failed to add identity to project in another organization"
|
message: "Failed to add identity to project in another organization"
|
||||||
});
|
});
|
||||||
|
|
||||||
const rolePermission = await getWorkspaceRolePermissions(role, workspaceId);
|
const rolePermission = await getWorkspaceRolePermissions(role, workspaceId);
|
||||||
const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission);
|
const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission);
|
||||||
|
|
||||||
if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({
|
if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({
|
||||||
message: "Failed to add identity to project with more privileged role"
|
message: "Failed to add identity to project with more privileged role"
|
||||||
});
|
});
|
||||||
|
|
||||||
let customRole;
|
let customRole;
|
||||||
@@ -571,18 +571,18 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
isOrgRole: false,
|
isOrgRole: false,
|
||||||
workspace: new Types.ObjectId(workspaceId)
|
workspace: new Types.ObjectId(workspaceId)
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!customRole) throw BadRequestError({ message: "Role not found" });
|
if (!customRole) throw BadRequestError({ message: "Role not found" });
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
identityMembership = await new IdentityMembership({
|
identityMembership = await new IdentityMembership({
|
||||||
identity: identityMembershipOrg.identity,
|
identity: identityMembershipOrg.identity,
|
||||||
workspace: new Types.ObjectId(workspaceId),
|
workspace: new Types.ObjectId(workspaceId),
|
||||||
role: customRole ? CUSTOM : role,
|
role: customRole ? CUSTOM : role,
|
||||||
customRole
|
customRole
|
||||||
}).save();
|
}).save();
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
identityMembership
|
identityMembership
|
||||||
});
|
});
|
||||||
@@ -594,14 +594,14 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
* @param req
|
* @param req
|
||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
export const updateIdentityWorkspaceRole = async (req: Request, res: Response) => {
|
export const updateIdentityWorkspaceRole = async (req: Request, res: Response) => {
|
||||||
const {
|
const {
|
||||||
params: { workspaceId, identityId },
|
params: { workspaceId, identityId },
|
||||||
body: {
|
body: {
|
||||||
role
|
role
|
||||||
}
|
}
|
||||||
} = await validateRequest(reqValidator.UpdateIdentityWorkspaceRoleV2, req);
|
} = await validateRequest(reqValidator.UpdateIdentityWorkspaceRoleV2, req);
|
||||||
|
|
||||||
const { permission } = await getAuthDataProjectPermissions({
|
const { permission } = await getAuthDataProjectPermissions({
|
||||||
authData: req.authData,
|
authData: req.authData,
|
||||||
workspaceId: new Types.ObjectId(workspaceId)
|
workspaceId: new Types.ObjectId(workspaceId)
|
||||||
@@ -611,7 +611,7 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
ProjectPermissionActions.Edit,
|
ProjectPermissionActions.Edit,
|
||||||
ProjectPermissionSub.Identity
|
ProjectPermissionSub.Identity
|
||||||
);
|
);
|
||||||
|
|
||||||
let identityMembership = await IdentityMembership
|
let identityMembership = await IdentityMembership
|
||||||
.findOne({
|
.findOne({
|
||||||
identity: new Types.ObjectId(identityId),
|
identity: new Types.ObjectId(identityId),
|
||||||
@@ -625,21 +625,21 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
if (!identityMembership) throw BadRequestError({
|
if (!identityMembership) throw BadRequestError({
|
||||||
message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}`
|
message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
const identityRolePermission = await getWorkspaceRolePermissions(
|
const identityRolePermission = await getWorkspaceRolePermissions(
|
||||||
identityMembership?.customRole?.slug ?? identityMembership.role,
|
identityMembership?.customRole?.slug ?? identityMembership.role,
|
||||||
identityMembership.workspace.toString()
|
identityMembership.workspace.toString()
|
||||||
);
|
);
|
||||||
const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission);
|
const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission);
|
||||||
if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({
|
if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({
|
||||||
message: "Failed to update role of more privileged identity"
|
message: "Failed to update role of more privileged identity"
|
||||||
});
|
});
|
||||||
|
|
||||||
const rolePermission = await getWorkspaceRolePermissions(role, workspaceId);
|
const rolePermission = await getWorkspaceRolePermissions(role, workspaceId);
|
||||||
const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission);
|
const isAsPrivilegedAsIntendedRole = isAtLeastAsPrivilegedWorkspace(permission, rolePermission);
|
||||||
|
|
||||||
if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({
|
if (!isAsPrivilegedAsIntendedRole) throw ForbiddenRequestError({
|
||||||
message: "Failed to update identity to a more privileged role"
|
message: "Failed to update identity to a more privileged role"
|
||||||
});
|
});
|
||||||
|
|
||||||
let customRole;
|
let customRole;
|
||||||
@@ -651,11 +651,11 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
isOrgRole: false,
|
isOrgRole: false,
|
||||||
workspace: new Types.ObjectId(workspaceId)
|
workspace: new Types.ObjectId(workspaceId)
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!customRole) throw BadRequestError({ message: "Role not found" });
|
if (!customRole) throw BadRequestError({ message: "Role not found" });
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
identityMembership = await IdentityMembership.findOneAndUpdate(
|
identityMembership = await IdentityMembership.findOneAndUpdate(
|
||||||
{
|
{
|
||||||
identity: identityMembership.identity._id,
|
identity: identityMembership.identity._id,
|
||||||
@@ -681,11 +681,11 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
* @param req
|
* @param req
|
||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
export const deleteIdentityFromWorkspace = async (req: Request, res: Response) => {
|
export const deleteIdentityFromWorkspace = async (req: Request, res: Response) => {
|
||||||
const {
|
const {
|
||||||
params: { workspaceId, identityId }
|
params: { workspaceId, identityId }
|
||||||
} = await validateRequest(reqValidator.DeleteIdentityFromWorkspaceV2, req);
|
} = await validateRequest(reqValidator.DeleteIdentityFromWorkspaceV2, req);
|
||||||
|
|
||||||
const { permission } = await getAuthDataProjectPermissions({
|
const { permission } = await getAuthDataProjectPermissions({
|
||||||
authData: req.authData,
|
authData: req.authData,
|
||||||
workspaceId: new Types.ObjectId(workspaceId)
|
workspaceId: new Types.ObjectId(workspaceId)
|
||||||
@@ -695,7 +695,7 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
ProjectPermissionActions.Delete,
|
ProjectPermissionActions.Delete,
|
||||||
ProjectPermissionSub.Identity
|
ProjectPermissionSub.Identity
|
||||||
);
|
);
|
||||||
|
|
||||||
const identityMembership = await IdentityMembership
|
const identityMembership = await IdentityMembership
|
||||||
.findOne({
|
.findOne({
|
||||||
identity: new Types.ObjectId(identityId),
|
identity: new Types.ObjectId(identityId),
|
||||||
@@ -705,20 +705,20 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
identity: IIdentity,
|
identity: IIdentity,
|
||||||
customRole: IRole
|
customRole: IRole
|
||||||
}>("identity customRole");
|
}>("identity customRole");
|
||||||
|
|
||||||
if (!identityMembership) throw ResourceNotFoundError({
|
if (!identityMembership) throw ResourceNotFoundError({
|
||||||
message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}`
|
message: `Identity with id ${identityId} does not exist in project with id ${workspaceId}`
|
||||||
});
|
});
|
||||||
|
|
||||||
const identityRolePermission = await getWorkspaceRolePermissions(
|
const identityRolePermission = await getWorkspaceRolePermissions(
|
||||||
identityMembership?.customRole?.slug ?? identityMembership.role,
|
identityMembership?.customRole?.slug ?? identityMembership.role,
|
||||||
identityMembership.workspace.toString()
|
identityMembership.workspace.toString()
|
||||||
);
|
);
|
||||||
const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission);
|
const isAsPrivilegedAsIdentity = isAtLeastAsPrivilegedWorkspace(permission, identityRolePermission);
|
||||||
if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({
|
if (!isAsPrivilegedAsIdentity) throw ForbiddenRequestError({
|
||||||
message: "Failed to remove more privileged identity from project"
|
message: "Failed to remove more privileged identity from project"
|
||||||
});
|
});
|
||||||
|
|
||||||
await IdentityMembership.findByIdAndDelete(identityMembership._id);
|
await IdentityMembership.findByIdAndDelete(identityMembership._id);
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
@@ -732,11 +732,11 @@ export const toggleAutoCapitalization = async (req: Request, res: Response) => {
|
|||||||
* @param res
|
* @param res
|
||||||
* @returns
|
* @returns
|
||||||
*/
|
*/
|
||||||
export const getWorkspaceIdentityMemberships = async (req: Request, res: Response) => {
|
export const getWorkspaceIdentityMemberships = async (req: Request, res: Response) => {
|
||||||
const {
|
const {
|
||||||
params: { workspaceId }
|
params: { workspaceId }
|
||||||
} = await validateRequest(reqValidator.GetWorkspaceIdentityMembersV2, req);
|
} = await validateRequest(reqValidator.GetWorkspaceIdentityMembersV2, req);
|
||||||
|
|
||||||
const { permission } = await getAuthDataProjectPermissions({
|
const { permission } = await getAuthDataProjectPermissions({
|
||||||
authData: req.authData,
|
authData: req.authData,
|
||||||
workspaceId: new Types.ObjectId(workspaceId)
|
workspaceId: new Types.ObjectId(workspaceId)
|
||||||
|
|||||||
Reference in New Issue
Block a user