Merge pull request #1493 from akhilmhdh/fix/dup-sec-del

fix(server): duplicate secret deletion made possible
This commit is contained in:
Maidul Islam
2024-02-29 14:16:44 -05:00
committed by GitHub
+20 -11
View File
@@ -7,7 +7,7 @@ import { TSecretSnapshotServiceFactory } from "@app/ee/services/secret-snapshot/
import { getConfig } from "@app/lib/config/env"; import { getConfig } from "@app/lib/config/env";
import { buildSecretBlindIndexFromName, encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto"; import { buildSecretBlindIndexFromName, encryptSymmetric128BitHexKeyUTF8 } from "@app/lib/crypto";
import { BadRequestError } from "@app/lib/errors"; import { BadRequestError } from "@app/lib/errors";
import { groupBy, pick } from "@app/lib/fn"; import { groupBy, pick, unique } from "@app/lib/fn";
import { logger } from "@app/lib/logger"; import { logger } from "@app/lib/logger";
import { ActorType } from "../auth/auth-type"; import { ActorType } from "../auth/auth-type";
@@ -202,12 +202,13 @@ export const secretServiceFactory = ({
return deletedSecrets; return deletedSecrets;
}; };
// this is a utility function for secret modification /**
// this will check given secret name blind index exist or not * Checks and handles secrets using a blind index method.
// if its a created secret set isNew to true * The function generates mappings between secret names and their blind indexes, validates user IDs for personal secrets, and retrieves secrets from the database based on their blind indexes.
// thus if these blindindex exist it will throw an error * For new secrets (isNew = true), it ensures they don't already exist in the database.
// vice versa when u need to check for updated secret * For existing secrets, it verifies their presence in the database.
// this will also return the blind index grouped by secretName * If discrepancies are found, errors are thrown. The function returns mappings and the fetched secrets.
*/
const fnSecretBlindIndexCheck = async ({ const fnSecretBlindIndexCheck = async ({
inputSecrets, inputSecrets,
folderId, folderId,
@@ -242,10 +243,18 @@ export const secretServiceFactory = ({
if (isNew) { if (isNew) {
if (secrets.length) throw new BadRequestError({ message: "Secret already exist" }); if (secrets.length) throw new BadRequestError({ message: "Secret already exist" });
} else if (secrets.length !== inputSecrets.length) } else {
throw new BadRequestError({ const secretKeysInDB = unique(secrets, (el) => el.secretBlindIndex as string).map(
message: `Secret not found: blind index ${JSON.stringify(keyName2BlindIndex)}` (el) => blindIndex2KeyName[el.secretBlindIndex as string]
}); );
const hasUnknownSecretsProvided = secretKeysInDB.length !== inputSecrets.length;
if (hasUnknownSecretsProvided) {
const keysMissingInDB = Object.keys(keyName2BlindIndex).filter((key) => !secretKeysInDB.includes(key));
throw new BadRequestError({
message: `Secret not found: blind index ${keysMissingInDB.join(",")}`
});
}
}
return { blindIndex2KeyName, keyName2BlindIndex, secrets }; return { blindIndex2KeyName, keyName2BlindIndex, secrets };
}; };