mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 10:26:00 +00:00
Feat: Request Access (migrations)
This commit is contained in:
@@ -10,6 +10,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
t.string("name").notNullable();
|
t.string("name").notNullable();
|
||||||
t.integer("approvals").defaultTo(1).notNullable();
|
t.integer("approvals").defaultTo(1).notNullable();
|
||||||
t.uuid("envId").notNullable();
|
t.uuid("envId").notNullable();
|
||||||
|
t.string("secretPath");
|
||||||
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("CASCADE");
|
t.foreign("envId").references("id").inTable(TableName.Environment).onDelete("CASCADE");
|
||||||
t.timestamps(true, true, true);
|
t.timestamps(true, true, true);
|
||||||
});
|
});
|
||||||
@@ -31,8 +32,8 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
export async function down(knex: Knex): Promise<void> {
|
||||||
await knex.schema.dropTableIfExists(TableName.AccessApprovalPolicy);
|
|
||||||
await knex.schema.dropTableIfExists(TableName.AccessApprovalPolicyApprover);
|
await knex.schema.dropTableIfExists(TableName.AccessApprovalPolicyApprover);
|
||||||
|
await knex.schema.dropTableIfExists(TableName.AccessApprovalPolicy);
|
||||||
await dropOnUpdateTrigger(knex, TableName.AccessApprovalPolicy);
|
await dropOnUpdateTrigger(knex, TableName.AccessApprovalPolicy);
|
||||||
await dropOnUpdateTrigger(knex, TableName.AccessApprovalPolicyApprover);
|
await dropOnUpdateTrigger(knex, TableName.AccessApprovalPolicyApprover);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { TableName } from "../schemas";
|
||||||
|
import { createOnUpdateTrigger, dropOnUpdateTrigger } from "../utils";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
if (!(await knex.schema.hasTable(TableName.AccessApprovalRequest))) {
|
||||||
|
await knex.schema.createTable(TableName.AccessApprovalRequest, (t) => {
|
||||||
|
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||||
|
|
||||||
|
t.uuid("policyId").notNullable();
|
||||||
|
t.foreign("policyId").references("id").inTable(TableName.AccessApprovalPolicy).onDelete("CASCADE");
|
||||||
|
|
||||||
|
t.uuid("privilegeId").nullable();
|
||||||
|
t.foreign("privilegeId").references("id").inTable(TableName.ProjectUserAdditionalPrivilege).onDelete("CASCADE");
|
||||||
|
|
||||||
|
t.uuid("requestedBy").notNullable();
|
||||||
|
t.foreign("requestedBy").references("id").inTable(TableName.ProjectMembership).onDelete("CASCADE");
|
||||||
|
|
||||||
|
// We use these values to create the actual privilege at a later point in time.
|
||||||
|
t.boolean("isTemporary").notNullable();
|
||||||
|
t.string("temporaryRange").nullable();
|
||||||
|
|
||||||
|
t.jsonb("permissions").notNullable();
|
||||||
|
|
||||||
|
t.timestamps(true, true, true);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
await createOnUpdateTrigger(knex, TableName.AccessApprovalRequest);
|
||||||
|
|
||||||
|
if (!(await knex.schema.hasTable(TableName.AccessApprovalRequestReviewer))) {
|
||||||
|
await knex.schema.createTable(TableName.AccessApprovalRequestReviewer, (t) => {
|
||||||
|
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||||
|
t.uuid("member").notNullable();
|
||||||
|
t.foreign("member").references("id").inTable(TableName.ProjectMembership).onDelete("CASCADE");
|
||||||
|
t.string("status").notNullable();
|
||||||
|
t.uuid("requestId").notNullable();
|
||||||
|
t.foreign("requestId").references("id").inTable(TableName.AccessApprovalRequest).onDelete("CASCADE");
|
||||||
|
t.timestamps(true, true, true);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
await createOnUpdateTrigger(knex, TableName.AccessApprovalRequestReviewer);
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
await knex.schema.dropTableIfExists(TableName.AccessApprovalRequestReviewer);
|
||||||
|
await knex.schema.dropTableIfExists(TableName.AccessApprovalRequest);
|
||||||
|
|
||||||
|
await dropOnUpdateTrigger(knex, TableName.AccessApprovalRequestReviewer);
|
||||||
|
await dropOnUpdateTrigger(knex, TableName.AccessApprovalRequest);
|
||||||
|
}
|
||||||
@@ -12,6 +12,7 @@ export const AccessApprovalPoliciesSchema = z.object({
|
|||||||
name: z.string(),
|
name: z.string(),
|
||||||
approvals: z.number().default(1),
|
approvals: z.number().default(1),
|
||||||
envId: z.string().uuid(),
|
envId: z.string().uuid(),
|
||||||
|
secretPath: z.string().nullable().optional(),
|
||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
updatedAt: z.date()
|
updatedAt: z.date()
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
// Code generated by automation script, DO NOT EDIT.
|
||||||
|
// Automated by pulling database and generating zod schema
|
||||||
|
// To update. Just run npm run generate:schema
|
||||||
|
// Written by akhilmhdh.
|
||||||
|
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TImmutableDBKeys } from "./models";
|
||||||
|
|
||||||
|
export const AccessApprovalRequestsReviewersSchema = z.object({
|
||||||
|
id: z.string().uuid(),
|
||||||
|
member: z.string().uuid(),
|
||||||
|
status: z.string(),
|
||||||
|
requestId: z.string().uuid(),
|
||||||
|
createdAt: z.date(),
|
||||||
|
updatedAt: z.date()
|
||||||
|
});
|
||||||
|
|
||||||
|
export type TAccessApprovalRequestsReviewers = z.infer<typeof AccessApprovalRequestsReviewersSchema>;
|
||||||
|
export type TAccessApprovalRequestsReviewersInsert = Omit<
|
||||||
|
z.input<typeof AccessApprovalRequestsReviewersSchema>,
|
||||||
|
TImmutableDBKeys
|
||||||
|
>;
|
||||||
|
export type TAccessApprovalRequestsReviewersUpdate = Partial<
|
||||||
|
Omit<z.input<typeof AccessApprovalRequestsReviewersSchema>, TImmutableDBKeys>
|
||||||
|
>;
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
// Code generated by automation script, DO NOT EDIT.
|
||||||
|
// Automated by pulling database and generating zod schema
|
||||||
|
// To update. Just run npm run generate:schema
|
||||||
|
// Written by akhilmhdh.
|
||||||
|
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TImmutableDBKeys } from "./models";
|
||||||
|
|
||||||
|
export const AccessApprovalRequestsSchema = z.object({
|
||||||
|
id: z.string().uuid(),
|
||||||
|
policyId: z.string().uuid(),
|
||||||
|
privilegeId: z.string().uuid().nullable().optional(),
|
||||||
|
requestedBy: z.string().uuid(),
|
||||||
|
isTemporary: z.boolean(),
|
||||||
|
temporaryRange: z.string().nullable().optional(),
|
||||||
|
permissions: z.unknown(),
|
||||||
|
createdAt: z.date(),
|
||||||
|
updatedAt: z.date()
|
||||||
|
});
|
||||||
|
|
||||||
|
export type TAccessApprovalRequests = z.infer<typeof AccessApprovalRequestsSchema>;
|
||||||
|
export type TAccessApprovalRequestsInsert = Omit<z.input<typeof AccessApprovalRequestsSchema>, TImmutableDBKeys>;
|
||||||
|
export type TAccessApprovalRequestsUpdate = Partial<
|
||||||
|
Omit<z.input<typeof AccessApprovalRequestsSchema>, TImmutableDBKeys>
|
||||||
|
>;
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
export * from "./access-approval-policies";
|
export * from "./access-approval-policies";
|
||||||
export * from "./access-approval-policies-approvers";
|
export * from "./access-approval-policies-approvers";
|
||||||
|
export * from "./access-approval-requests";
|
||||||
|
export * from "./access-approval-requests-reviewers";
|
||||||
export * from "./api-keys";
|
export * from "./api-keys";
|
||||||
export * from "./audit-log-streams";
|
export * from "./audit-log-streams";
|
||||||
export * from "./audit-logs";
|
export * from "./audit-logs";
|
||||||
|
|||||||
Reference in New Issue
Block a user