mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 00:27:30 +00:00
feat: more review comments
This commit is contained in:
@@ -189,7 +189,7 @@ export const userGroupMembershipDALFactory = (db: TDbClient) => {
|
|||||||
const docs = await db
|
const docs = await db
|
||||||
.replicaNode()(TableName.UserGroupMembership)
|
.replicaNode()(TableName.UserGroupMembership)
|
||||||
.join(TableName.Groups, `${TableName.UserGroupMembership}.groupId`, `${TableName.Groups}.id`)
|
.join(TableName.Groups, `${TableName.UserGroupMembership}.groupId`, `${TableName.Groups}.id`)
|
||||||
.join(TableName.Membership, `${TableName.UserGroupMembership}.userId`, `${TableName.Membership}.actorGroupId`)
|
.join(TableName.Membership, `${TableName.UserGroupMembership}.userId`, `${TableName.Membership}.actorUserId`)
|
||||||
.join(TableName.Users, `${TableName.UserGroupMembership}.userId`, `${TableName.Users}.id`)
|
.join(TableName.Users, `${TableName.UserGroupMembership}.userId`, `${TableName.Users}.id`)
|
||||||
.where(`${TableName.Groups}.id`, groupId)
|
.where(`${TableName.Groups}.id`, groupId)
|
||||||
.where(`${TableName.Membership}.scope`, AccessScope.Organization)
|
.where(`${TableName.Membership}.scope`, AccessScope.Organization)
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import { TDbClient } from "@app/db";
|
|||||||
import {
|
import {
|
||||||
AccessScope,
|
AccessScope,
|
||||||
AccessScopeData,
|
AccessScopeData,
|
||||||
IdentityProjectMembershipRoleSchema,
|
MembershipRolesSchema,
|
||||||
MembershipsSchema,
|
MembershipsSchema,
|
||||||
TableName,
|
TableName,
|
||||||
TMemberships,
|
TMemberships,
|
||||||
@@ -95,7 +95,6 @@ export interface TPermissionDALFactory {
|
|||||||
updatedAt: Date;
|
updatedAt: Date;
|
||||||
isTemporary: boolean;
|
isTemporary: boolean;
|
||||||
role: string;
|
role: string;
|
||||||
projectMembershipId: string;
|
|
||||||
temporaryRange?: string | null | undefined;
|
temporaryRange?: string | null | undefined;
|
||||||
permissions?: unknown;
|
permissions?: unknown;
|
||||||
customRoleId?: string | null | undefined;
|
customRoleId?: string | null | undefined;
|
||||||
@@ -382,7 +381,7 @@ export const permissionDALFactory = (db: TDbClient): TPermissionDALFactory => {
|
|||||||
}
|
}
|
||||||
})
|
})
|
||||||
.select(
|
.select(
|
||||||
db.ref("id").withSchema(TableName.GroupProjectMembership).as("membershipId"),
|
db.ref("id").withSchema(TableName.Membership).as("membershipId"),
|
||||||
db.ref("id").withSchema(TableName.Groups).as("groupId"),
|
db.ref("id").withSchema(TableName.Groups).as("groupId"),
|
||||||
db.ref("name").withSchema(TableName.Groups).as("groupName"),
|
db.ref("name").withSchema(TableName.Groups).as("groupName"),
|
||||||
db.ref("slug").withSchema("groupCustomRoles").as("groupProjectMembershipRoleCustomRoleSlug"),
|
db.ref("slug").withSchema("groupCustomRoles").as("groupProjectMembershipRoleCustomRoleSlug"),
|
||||||
@@ -474,6 +473,7 @@ export const permissionDALFactory = (db: TDbClient): TPermissionDALFactory => {
|
|||||||
const docs = await db
|
const docs = await db
|
||||||
.replicaNode()(TableName.Users)
|
.replicaNode()(TableName.Users)
|
||||||
.where("isGhost", "=", false)
|
.where("isGhost", "=", false)
|
||||||
|
.join(TableName.Membership, `${TableName.Users}.id`, `${TableName.Membership}.actorUserId`)
|
||||||
.join(TableName.MembershipRole, `${TableName.Membership}.id`, `${TableName.MembershipRole}.membershipId`)
|
.join(TableName.MembershipRole, `${TableName.Membership}.id`, `${TableName.MembershipRole}.membershipId`)
|
||||||
.leftJoin(TableName.Role, `${TableName.MembershipRole}.customRoleId`, `${TableName.Role}.id`)
|
.leftJoin(TableName.Role, `${TableName.MembershipRole}.customRoleId`, `${TableName.Role}.id`)
|
||||||
.leftJoin(TableName.AdditionalPrivilege, (qb) => {
|
.leftJoin(TableName.AdditionalPrivilege, (qb) => {
|
||||||
@@ -661,12 +661,14 @@ export const permissionDALFactory = (db: TDbClient): TPermissionDALFactory => {
|
|||||||
`${TableName.AdditionalPrivilege}.orgId`
|
`${TableName.AdditionalPrivilege}.orgId`
|
||||||
);
|
);
|
||||||
})
|
})
|
||||||
|
.join(TableName.Identity, `${TableName.Identity}.id`, `${TableName.Membership}.actorIdentityId`)
|
||||||
.leftJoin(TableName.IdentityMetadata, (queryBuilder) => {
|
.leftJoin(TableName.IdentityMetadata, (queryBuilder) => {
|
||||||
void queryBuilder
|
void queryBuilder
|
||||||
.on(`${TableName.Membership}.actorIdentityId`, `${TableName.IdentityMetadata}.identityId`)
|
.on(`${TableName.Membership}.actorIdentityId`, `${TableName.IdentityMetadata}.identityId`)
|
||||||
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
|
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
|
||||||
})
|
})
|
||||||
.where(`${TableName.Membership}.scopeOrgId`, orgId)
|
.where(`${TableName.Membership}.scopeOrgId`, orgId)
|
||||||
|
.whereNotNull(`${TableName.Membership}.actorIdentityId`)
|
||||||
.where(`${TableName.Membership}.scope`, AccessScope.Project)
|
.where(`${TableName.Membership}.scope`, AccessScope.Project)
|
||||||
.where(`${TableName.Membership}.scopeProjectId`, projectId)
|
.where(`${TableName.Membership}.scopeProjectId`, projectId)
|
||||||
.select(selectAllTableCols(TableName.MembershipRole))
|
.select(selectAllTableCols(TableName.MembershipRole))
|
||||||
@@ -715,7 +717,7 @@ export const permissionDALFactory = (db: TDbClient): TPermissionDALFactory => {
|
|||||||
key: "id",
|
key: "id",
|
||||||
label: "roles" as const,
|
label: "roles" as const,
|
||||||
mapper: (data) =>
|
mapper: (data) =>
|
||||||
IdentityProjectMembershipRoleSchema.extend({
|
MembershipRolesSchema.extend({
|
||||||
permissions: z.unknown(),
|
permissions: z.unknown(),
|
||||||
customRoleSlug: z.string().optional().nullable()
|
customRoleSlug: z.string().optional().nullable()
|
||||||
}).parse(data)
|
}).parse(data)
|
||||||
|
|||||||
@@ -383,7 +383,6 @@ export const registerIdentityProjectRouter = async (server: FastifyZodProvider)
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
// TODO(simp): look into how to handle projects
|
|
||||||
server.route({
|
server.route({
|
||||||
method: "GET",
|
method: "GET",
|
||||||
url: "/identity-memberships/:identityMembershipId",
|
url: "/identity-memberships/:identityMembershipId",
|
||||||
|
|||||||
@@ -265,7 +265,7 @@ export const membershipGroupServiceFactory = ({
|
|||||||
|
|
||||||
if (existingMembership.actorGroupId === dto.permission.id)
|
if (existingMembership.actorGroupId === dto.permission.id)
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "You can't delete you own membership"
|
message: "You can't delete your own membership"
|
||||||
});
|
});
|
||||||
|
|
||||||
const membershipDoc = await membershipGroupDAL.transaction(async (tx) => {
|
const membershipDoc = await membershipGroupDAL.transaction(async (tx) => {
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ export const newOrgMembershipGroupFactory = ({
|
|||||||
|
|
||||||
const onCreateMembershipGroupGuard: TMembershipGroupScopeFactory["onCreateMembershipGroupGuard"] = async () => {
|
const onCreateMembershipGroupGuard: TMembershipGroupScopeFactory["onCreateMembershipGroupGuard"] = async () => {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Organizatin membership cannot be created for groups"
|
message: "Organization membership cannot be created for groups"
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -84,7 +84,7 @@ export const newOrgMembershipGroupFactory = ({
|
|||||||
|
|
||||||
const onDeleteMembershipGroupGuard: TMembershipGroupScopeFactory["onDeleteMembershipGroupGuard"] = async () => {
|
const onDeleteMembershipGroupGuard: TMembershipGroupScopeFactory["onDeleteMembershipGroupGuard"] = async () => {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Organizatin membership cannot be created for organization scoped group"
|
message: "Organization membership cannot be created for organization scoped group"
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -41,7 +41,7 @@ export const membershipIdentityDALFactory = (db: TDbClient) => {
|
|||||||
.leftJoin(TableName.Role, `${TableName.MembershipRole}.customRoleId`, `${TableName.Role}.id`)
|
.leftJoin(TableName.Role, `${TableName.MembershipRole}.customRoleId`, `${TableName.Role}.id`)
|
||||||
.leftJoin(TableName.IdentityMetadata, (queryBuilder) => {
|
.leftJoin(TableName.IdentityMetadata, (queryBuilder) => {
|
||||||
void queryBuilder
|
void queryBuilder
|
||||||
.on(`${TableName.Membership}.actorIdentityId`, `${TableName.IdentityMetadata}.userId`)
|
.on(`${TableName.Membership}.actorIdentityId`, `${TableName.IdentityMetadata}.identityId`)
|
||||||
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
|
.andOn(`${TableName.Membership}.scopeOrgId`, `${TableName.IdentityMetadata}.orgId`);
|
||||||
})
|
})
|
||||||
.where(`${TableName.Membership}.scopeOrgId`, scopeData.orgId)
|
.where(`${TableName.Membership}.scopeOrgId`, scopeData.orgId)
|
||||||
|
|||||||
@@ -272,7 +272,7 @@ export const membershipIdentityServiceFactory = ({
|
|||||||
|
|
||||||
if (existingMembership.actorIdentityId === dto.permission.id)
|
if (existingMembership.actorIdentityId === dto.permission.id)
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "You can't delete you own membership"
|
message: "You can't delete your own membership"
|
||||||
});
|
});
|
||||||
|
|
||||||
const membershipDoc = await membershipIdentityDAL.transaction(async (tx) => {
|
const membershipDoc = await membershipIdentityDAL.transaction(async (tx) => {
|
||||||
|
|||||||
@@ -41,7 +41,7 @@ export const newOrgMembershipIdentityFactory = ({
|
|||||||
const onCreateMembershipIdentityGuard: TMembershipIdentityScopeFactory["onCreateMembershipIdentityGuard"] =
|
const onCreateMembershipIdentityGuard: TMembershipIdentityScopeFactory["onCreateMembershipIdentityGuard"] =
|
||||||
async () => {
|
async () => {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Organizatin membership cannot be created for organization scoped identity"
|
message: "Organization membership cannot be created for organization scoped identity"
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -88,7 +88,7 @@ export const newOrgMembershipIdentityFactory = ({
|
|||||||
const onDeleteMembershipIdentityGuard: TMembershipIdentityScopeFactory["onDeleteMembershipIdentityGuard"] =
|
const onDeleteMembershipIdentityGuard: TMembershipIdentityScopeFactory["onDeleteMembershipIdentityGuard"] =
|
||||||
async () => {
|
async () => {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Organizatin membership cannot be created for organization scoped identity"
|
message: "Organization membership cannot be created for organization scoped identity"
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -398,7 +398,7 @@ export const membershipUserServiceFactory = ({
|
|||||||
|
|
||||||
if (existingMembership.actorUserId === dto.permission.id)
|
if (existingMembership.actorUserId === dto.permission.id)
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "You can't delete you own membership"
|
message: "You can't delete your own membership"
|
||||||
});
|
});
|
||||||
|
|
||||||
const membershipDoc = await membershipUserDAL.transaction(async (tx) => {
|
const membershipDoc = await membershipUserDAL.transaction(async (tx) => {
|
||||||
|
|||||||
@@ -762,7 +762,7 @@ export const orgServiceFactory = ({
|
|||||||
throw new NotFoundError({ message: `Organization membership with ID ${membershipId} not found` });
|
throw new NotFoundError({ message: `Organization membership with ID ${membershipId} not found` });
|
||||||
if (foundMembership.scopeOrgId !== orgId)
|
if (foundMembership.scopeOrgId !== orgId)
|
||||||
throw new UnauthorizedError({ message: "Updated org member doesn't belong to the organization" });
|
throw new UnauthorizedError({ message: "Updated org member doesn't belong to the organization" });
|
||||||
if (foundMembership.scopeOrgId === userId)
|
if (foundMembership.actorUserId === userId)
|
||||||
throw new UnauthorizedError({ message: "Cannot update own organization membership" });
|
throw new UnauthorizedError({ message: "Cannot update own organization membership" });
|
||||||
|
|
||||||
const isCustomRole = !Object.values(OrgMembershipRole).includes(role as OrgMembershipRole);
|
const isCustomRole = !Object.values(OrgMembershipRole).includes(role as OrgMembershipRole);
|
||||||
|
|||||||
@@ -106,6 +106,8 @@ export const projectMembershipDALFactory = (db: TDbClient) => {
|
|||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
id: userId,
|
id: userId,
|
||||||
|
// akhilmhdh: if we do user encryption based join this would fail for scim user who haven't logged in yet
|
||||||
|
// public key is not used anymore as well
|
||||||
publicKey: "",
|
publicKey: "",
|
||||||
isGhost,
|
isGhost,
|
||||||
isOrgMembershipActive: isActive
|
isOrgMembershipActive: isActive
|
||||||
@@ -249,7 +251,17 @@ export const projectMembershipDALFactory = (db: TDbClient) => {
|
|||||||
id,
|
id,
|
||||||
userId,
|
userId,
|
||||||
projectId,
|
projectId,
|
||||||
user: { email, username, firstName, lastName, id: userId, isGhost, publicKey: "" },
|
user: {
|
||||||
|
email,
|
||||||
|
username,
|
||||||
|
firstName,
|
||||||
|
lastName,
|
||||||
|
id: userId,
|
||||||
|
isGhost,
|
||||||
|
// akhilmhdh: if we do user encryption based join this would fail for scim user who haven't logged in yet
|
||||||
|
// public key is not used anymore as well
|
||||||
|
publicKey: ""
|
||||||
|
},
|
||||||
project: {
|
project: {
|
||||||
id: projectId,
|
id: projectId,
|
||||||
name: projectName,
|
name: projectName,
|
||||||
|
|||||||
@@ -15,7 +15,6 @@ import { isCustomOrgRole } from "@app/services/org/org-role-fns";
|
|||||||
|
|
||||||
import { TRoleScopeFactory } from "../role-types";
|
import { TRoleScopeFactory } from "../role-types";
|
||||||
|
|
||||||
// TODO(simp): missing external group checking
|
|
||||||
type TOrgRoleScopeFactoryDep = {
|
type TOrgRoleScopeFactoryDep = {
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
externalGroupOrgRoleMappingDAL: Pick<TExternalGroupOrgRoleMappingDALFactory, "findOne">;
|
externalGroupOrgRoleMappingDAL: Pick<TExternalGroupOrgRoleMappingDALFactory, "findOne">;
|
||||||
|
|||||||
@@ -2395,8 +2395,8 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
projectId: folder.projectId,
|
projectId: folder.projectId,
|
||||||
secretVersions: secretVersionsFilter,
|
secretVersions: secretVersionsFilter,
|
||||||
findOpt: {
|
findOpt: {
|
||||||
offset,
|
|
||||||
limit,
|
limit,
|
||||||
|
offset,
|
||||||
sort: [["createdAt", "desc"]]
|
sort: [["createdAt", "desc"]]
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -221,7 +221,7 @@ export const secretVersionV2BridgeDALFactory = (db: TDbClient) => {
|
|||||||
})
|
})
|
||||||
.orWhere((qb) => {
|
.orWhere((qb) => {
|
||||||
void qb.where(`${TableName.SecretVersionV2}.secretId`, secretId);
|
void qb.where(`${TableName.SecretVersionV2}.secretId`, secretId);
|
||||||
void qb.whereNull(`${TableName.Membership}.actorProjectId`);
|
void qb.whereNull(`${TableName.Membership}.scopeProjectId`);
|
||||||
if (secretVersions?.length) void qb.whereIn(`${TableName.SecretVersionV2}.version`, secretVersions);
|
if (secretVersions?.length) void qb.whereIn(`${TableName.SecretVersionV2}.version`, secretVersions);
|
||||||
})
|
})
|
||||||
.select(
|
.select(
|
||||||
|
|||||||
+1
-1
@@ -272,7 +272,7 @@ export const IdentityAuthTemplatesTable = ({ handlePopUpOpen }: Props) => {
|
|||||||
/>
|
/>
|
||||||
)}
|
)}
|
||||||
{!subscription.machineIdentityAuthTemplates && (
|
{!subscription.machineIdentityAuthTemplates && (
|
||||||
<EmptyState title="This feature is not yet activated for your license." icon={faBan} />
|
<EmptyState title="This feature is not been activated for your license." icon={faBan} />
|
||||||
)}
|
)}
|
||||||
{!isPending && templates.length === 0 && (
|
{!isPending && templates.length === 0 && (
|
||||||
<EmptyState
|
<EmptyState
|
||||||
|
|||||||
Reference in New Issue
Block a user