mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Refactor EE secret versioning/snapshot access
This commit is contained in:
@@ -1,4 +1,3 @@
|
|||||||
|
|
||||||
import { patchRouterParam } from './utils/patchAsyncRoutes';
|
import { patchRouterParam } from './utils/patchAsyncRoutes';
|
||||||
import express from 'express';
|
import express from 'express';
|
||||||
import helmet from 'helmet';
|
import helmet from 'helmet';
|
||||||
@@ -7,7 +6,7 @@ import cookieParser from 'cookie-parser';
|
|||||||
import dotenv from 'dotenv';
|
import dotenv from 'dotenv';
|
||||||
|
|
||||||
dotenv.config();
|
dotenv.config();
|
||||||
import { PORT, NODE_ENV, SITE_URL } from './config';
|
import { PORT, NODE_ENV, SITE_URL, LICENSE_KEY } from './config';
|
||||||
import { apiLimiter } from './helpers/rateLimiter';
|
import { apiLimiter } from './helpers/rateLimiter';
|
||||||
|
|
||||||
import {
|
import {
|
||||||
|
|||||||
@@ -3,7 +3,9 @@ import {
|
|||||||
Secret
|
Secret
|
||||||
} from '../../models';
|
} from '../../models';
|
||||||
import {
|
import {
|
||||||
SecretSnapshot
|
SecretSnapshot,
|
||||||
|
SecretVersion,
|
||||||
|
ISecretVersion
|
||||||
} from '../models';
|
} from '../models';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -52,6 +54,21 @@ import {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const addSecretVersionsHelper = async ({
|
||||||
|
secretVersions
|
||||||
|
}: {
|
||||||
|
secretVersions: ISecretVersion[]
|
||||||
|
}) => {
|
||||||
|
try {
|
||||||
|
await SecretVersion.insertMany(secretVersions);
|
||||||
|
} catch (err) {
|
||||||
|
Sentry.setUser(null);
|
||||||
|
Sentry.captureException(err);
|
||||||
|
throw new Error('Failed to add secret versions');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
export {
|
export {
|
||||||
takeSecretSnapshotHelper
|
takeSecretSnapshotHelper,
|
||||||
|
addSecretVersionsHelper
|
||||||
}
|
}
|
||||||
@@ -3,5 +3,7 @@ import SecretVersion, { ISecretVersion } from "./secretVersion";
|
|||||||
|
|
||||||
export {
|
export {
|
||||||
SecretSnapshot,
|
SecretSnapshot,
|
||||||
SecretVersion
|
ISecretSnapshot,
|
||||||
|
SecretVersion,
|
||||||
|
ISecretVersion
|
||||||
}
|
}
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
import { Schema, model, Types } from 'mongoose';
|
import { Schema, model, Types } from 'mongoose';
|
||||||
|
|
||||||
export interface ISecretVersion {
|
export interface ISecretVersion {
|
||||||
_id: Types.ObjectId;
|
_id?: Types.ObjectId;
|
||||||
secret: Types.ObjectId;
|
secret: Types.ObjectId;
|
||||||
version: number;
|
version: number;
|
||||||
isDeleted: boolean;
|
isDeleted: boolean;
|
||||||
|
|||||||
@@ -1,22 +1,19 @@
|
|||||||
|
import { LICENSE_KEY } from '../../config';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Class to handle Enterprise Edition license actions
|
* Class to handle Enterprise Edition license actions
|
||||||
*/
|
*/
|
||||||
class EELicenseService {
|
class EELicenseService {
|
||||||
/**
|
|
||||||
* Check if license key [licenseKey] corresponds to a
|
private readonly _isLicenseValid: boolean;
|
||||||
* valid Infisical Enterprise Edition license.
|
|
||||||
* @param {Object} obj
|
constructor(licenseKey: string) {
|
||||||
* @param {Object} obj.licenseKey
|
this._isLicenseValid = true;
|
||||||
* @returns {Boolean}
|
}
|
||||||
*/
|
|
||||||
static async checkLicense({
|
public get isLicenseValid(): boolean {
|
||||||
licenseKey
|
return this._isLicenseValid;
|
||||||
}: {
|
|
||||||
licenseKey: string;
|
|
||||||
}) {
|
|
||||||
// TODO
|
|
||||||
return true;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export default EELicenseService;
|
export default new EELicenseService(LICENSE_KEY);
|
||||||
@@ -1,4 +1,8 @@
|
|||||||
import { takeSecretSnapshotHelper } from '../helpers/secret';
|
import { ISecretVersion } from '../models';
|
||||||
|
import {
|
||||||
|
takeSecretSnapshotHelper,
|
||||||
|
addSecretVersionsHelper
|
||||||
|
} from '../helpers/secret';
|
||||||
import EELicenseService from './EELicenseService';
|
import EELicenseService from './EELicenseService';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -21,9 +25,25 @@ class EESecretService {
|
|||||||
licenseKey: string;
|
licenseKey: string;
|
||||||
workspaceId: string;
|
workspaceId: string;
|
||||||
}) {
|
}) {
|
||||||
EELicenseService.checkLicense({ licenseKey });
|
if (!EELicenseService.isLicenseValid) return;
|
||||||
await takeSecretSnapshotHelper({ workspaceId });
|
await takeSecretSnapshotHelper({ workspaceId });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Adds secret versions [secretVersions] to the SecretVersion collection.
|
||||||
|
* @param {Object} obj
|
||||||
|
* @param {SecretVersion} obj.secretVersions
|
||||||
|
*/
|
||||||
|
static async addSecretVersions({
|
||||||
|
secretVersions
|
||||||
|
}: {
|
||||||
|
secretVersions: ISecretVersion[];
|
||||||
|
}) {
|
||||||
|
if (!EELicenseService.isLicenseValid) return;
|
||||||
|
await addSecretVersionsHelper({
|
||||||
|
secretVersions
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export default EESecretService;
|
export default EESecretService;
|
||||||
@@ -130,8 +130,10 @@ const pushSecrets = async ({
|
|||||||
};
|
};
|
||||||
});
|
});
|
||||||
await Secret.bulkWrite(operations as any);
|
await Secret.bulkWrite(operations as any);
|
||||||
await SecretVersion.insertMany(
|
|
||||||
toUpdate.map(({
|
// (EE) add secret versions for updated secrets
|
||||||
|
await EESecretService.addSecretVersions({
|
||||||
|
secretVersions: toUpdate.map(({
|
||||||
type,
|
type,
|
||||||
ciphertextKey,
|
ciphertextKey,
|
||||||
ivKey,
|
ivKey,
|
||||||
@@ -153,8 +155,8 @@ const pushSecrets = async ({
|
|||||||
secretValueIV: ivValue,
|
secretValueIV: ivValue,
|
||||||
secretValueTag: tagValue,
|
secretValueTag: tagValue,
|
||||||
secretValueHash: hashValue
|
secretValueHash: hashValue
|
||||||
}))
|
}))
|
||||||
);
|
});
|
||||||
|
|
||||||
// handle adding new secrets
|
// handle adding new secrets
|
||||||
const toAdd = secrets.filter((s) => !(`${s.type}-${s.hashKey}` in oldSecretsObj));
|
const toAdd = secrets.filter((s) => !(`${s.type}-${s.hashKey}` in oldSecretsObj));
|
||||||
@@ -185,8 +187,9 @@ const pushSecrets = async ({
|
|||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|
||||||
await SecretVersion.insertMany(
|
// (EE) add secret versions for new secrets
|
||||||
newSecrets.map(({
|
EESecretService.addSecretVersions({
|
||||||
|
secretVersions: newSecrets.map(({
|
||||||
_id,
|
_id,
|
||||||
secretKeyCiphertext,
|
secretKeyCiphertext,
|
||||||
secretKeyIV,
|
secretKeyIV,
|
||||||
@@ -209,7 +212,7 @@ const pushSecrets = async ({
|
|||||||
secretValueTag,
|
secretValueTag,
|
||||||
secretValueHash
|
secretValueHash
|
||||||
}))
|
}))
|
||||||
);
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// (EE) take a secret snapshot
|
// (EE) take a secret snapshot
|
||||||
|
|||||||
Reference in New Issue
Block a user