Patch secret-override mechanism with versioning/snapshots

This commit is contained in:
Tuan Dang
2022-12-24 20:01:33 -05:00
parent 9bbf380741
commit 9c769853b4
+14 -21
View File
@@ -57,17 +57,17 @@ const pushSecrets = async ({
workspaceId, workspaceId,
environment environment
}); });
const oldSecretsObj: any = oldSecrets.reduce((accumulator, s: any) => { const oldSecretsObj: any = oldSecrets.reduce((accumulator, s: any) =>
return { ...accumulator, [s.secretKeyHash]: s }; ({ ...accumulator, [`${s.type}-${s.secretKeyHash}`]: s })
}, {}); , {});
const newSecretsObj = secrets.reduce((accumulator, s) => { const newSecretsObj = secrets.reduce((accumulator, s) =>
return { ...accumulator, [s.hashKey]: s }; ({ ...accumulator, [`${s.type}-${s.hashKey}`]: s })
}, {}); , {});
// handle deleting secrets // handle deleting secrets
const toDelete = oldSecrets const toDelete = oldSecrets
.filter( .filter(
(s: ISecret) => !(s.secretKeyHash in newSecretsObj) (s: ISecret) => !(`${s.type}-${s.secretKeyHash}` in newSecretsObj)
) )
.map((s) => s._id); .map((s) => s._id);
if (toDelete.length > 0) { if (toDelete.length > 0) {
@@ -87,16 +87,11 @@ const pushSecrets = async ({
// handle modifying secrets where type or value changed // handle modifying secrets where type or value changed
const toUpdate = secrets const toUpdate = secrets
.filter((s) => { .filter((s) => {
if (s.hashKey in oldSecretsObj) { if (`${s.type}-${s.hashKey}` in oldSecretsObj) {
if (s.hashValue !== oldSecretsObj[s.hashKey].secretValueHash) { if (s.hashValue !== oldSecretsObj[`${s.type}-${s.hashKey}`].secretValueHash) {
// case: filter secrets where value changed // case: filter secrets where value changed
return true; return true;
} }
if (s.type !== oldSecretsObj[s.hashKey].type) {
// case: filter secrets where type changed
return true;
}
} }
return false; return false;
@@ -122,8 +117,7 @@ const pushSecrets = async ({
return { return {
updateOne: { updateOne: {
filter: { filter: {
workspace: workspaceId, _id: oldSecretsObj[`${s.type}-${s.hashKey}`]._id
_id: oldSecretsObj[s.hashKey]._id
}, },
update update
} }
@@ -132,6 +126,7 @@ const pushSecrets = async ({
await Secret.bulkWrite(operations as any); await Secret.bulkWrite(operations as any);
await SecretVersion.insertMany( await SecretVersion.insertMany(
toUpdate.map(({ toUpdate.map(({
type,
ciphertextKey, ciphertextKey,
ivKey, ivKey,
tagKey, tagKey,
@@ -141,8 +136,8 @@ const pushSecrets = async ({
tagValue, tagValue,
hashValue hashValue
}) => ({ }) => ({
secret: oldSecretsObj[hashKey]._id, secret: oldSecretsObj[`${type}-${hashKey}`]._id,
version: oldSecretsObj[hashKey].version + 1, version: oldSecretsObj[`${type}-${hashKey}`].version + 1,
isDeleted: false, isDeleted: false,
secretKeyCiphertext: ciphertextKey, secretKeyCiphertext: ciphertextKey,
secretKeyIV: ivKey, secretKeyIV: ivKey,
@@ -156,7 +151,7 @@ const pushSecrets = async ({
); );
// handle adding new secrets // handle adding new secrets
const toAdd = secrets.filter((s) => !(s.hashKey in oldSecretsObj)); const toAdd = secrets.filter((s) => !(`${s.type}-${s.hashKey}` in oldSecretsObj));
if (toAdd.length > 0) { if (toAdd.length > 0) {
// add secrets // add secrets
@@ -214,8 +209,6 @@ const pushSecrets = async ({
await takeSecretSnapshotHelper({ await takeSecretSnapshotHelper({
workspaceId workspaceId
}); });
// TODO: in the future add secret snapshot to capture entire
// state of project at this point in time
} catch (err) { } catch (err) {
Sentry.setUser(null); Sentry.setUser(null);
Sentry.captureException(err); Sentry.captureException(err);