Merge pull request #3846 from Infisical/daniel/multiple-folders

fix(folders): duplicate folders
This commit is contained in:
Daniel Hougaard
2025-06-24 19:04:26 +04:00
committed by GitHub
2 changed files with 64 additions and 20 deletions
+2 -1
View File
@@ -11,7 +11,8 @@ export const PgSqlLock = {
OrgGatewayRootCaInit: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-root-ca:${orgId}`), OrgGatewayRootCaInit: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-root-ca:${orgId}`),
OrgGatewayCertExchange: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-cert-exchange:${orgId}`), OrgGatewayCertExchange: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-cert-exchange:${orgId}`),
SecretRotationV2Creation: (folderId: string) => pgAdvisoryLockHashText(`secret-rotation-v2-creation:${folderId}`), SecretRotationV2Creation: (folderId: string) => pgAdvisoryLockHashText(`secret-rotation-v2-creation:${folderId}`),
CreateProject: (orgId: string) => pgAdvisoryLockHashText(`create-project:${orgId}`) CreateProject: (orgId: string) => pgAdvisoryLockHashText(`create-project:${orgId}`),
CreateFolder: (envId: string, projectId: string) => pgAdvisoryLockHashText(`create-folder:${envId}-${projectId}`)
} as const; } as const;
// all the key prefixes used must be set here to avoid conflict // all the key prefixes used must be set here to avoid conflict
@@ -6,6 +6,7 @@ import { ActionProjectType, TSecretFoldersInsert } from "@app/db/schemas";
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types"; import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types";
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission"; import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
import { TSecretSnapshotServiceFactory } from "@app/ee/services/secret-snapshot/secret-snapshot-service"; import { TSecretSnapshotServiceFactory } from "@app/ee/services/secret-snapshot/secret-snapshot-service";
import { PgSqlLock } from "@app/keystore/keystore";
import { BadRequestError, NotFoundError } from "@app/lib/errors"; import { BadRequestError, NotFoundError } from "@app/lib/errors";
import { OrderByDirection, OrgServiceActor } from "@app/lib/types"; import { OrderByDirection, OrgServiceActor } from "@app/lib/types";
import { buildFolderPath } from "@app/services/secret-folder/secret-folder-fns"; import { buildFolderPath } from "@app/services/secret-folder/secret-folder-fns";
@@ -83,36 +84,75 @@ export const secretFolderServiceFactory = ({
// that is this request must be idempotent // that is this request must be idempotent
// so we do a tricky move. we try to find the to be created folder path if that is exactly match return that // so we do a tricky move. we try to find the to be created folder path if that is exactly match return that
// else we get some path before that then we will start creating remaining folder // else we get some path before that then we will start creating remaining folder
await tx.raw("SELECT pg_advisory_xact_lock(?)", [PgSqlLock.CreateFolder(env.id, env.projectId)]);
const pathWithFolder = path.join(secretPath, name); const pathWithFolder = path.join(secretPath, name);
const parentFolder = await folderDAL.findClosestFolder(projectId, environment, pathWithFolder, tx); const parentFolder = await folderDAL.findClosestFolder(projectId, environment, pathWithFolder, tx);
// no folder found is not possible root should be their
if (!parentFolder) { if (!parentFolder) {
throw new NotFoundError({ throw new NotFoundError({
message: `Folder with path '${pathWithFolder}' in environment with slug '${environment}' not found` message: `Parent folder for path '${pathWithFolder}' not found`
}); });
} }
// exact folder
if (parentFolder.path === pathWithFolder) return parentFolder;
let parentFolderId = parentFolder.id; // check if the exact folder already exists
const existingFolder = await folderDAL.findOne(
{
envId: env.id,
parentId: parentFolder.id,
name,
isReserved: false
},
tx
);
if (existingFolder) {
return existingFolder;
}
// exact folder case
if (parentFolder.path === pathWithFolder) {
return parentFolder;
}
let currentParentId = parentFolder.id;
// build the full path we need by processing each segment
if (parentFolder.path !== secretPath) { if (parentFolder.path !== secretPath) {
// this is upsert folder in a path const missingSegments = secretPath.substring(parentFolder.path.length).split("/").filter(Boolean);
// we are not taking snapshots of this because
// snapshot will be removed from automatic for all commits to user click or cron based const newFolders: TSecretFoldersInsert[] = [];
const missingSegment = secretPath.substring(parentFolder.path.length).split("/").filter(Boolean);
if (missingSegment.length) { // process each segment sequentially
const newFolders: Array<TSecretFoldersInsert & { id: string }> = missingSegment.map((segment) => { for await (const segment of missingSegments) {
const existingSegment = await folderDAL.findOne(
{
name: segment,
parentId: currentParentId,
envId: env.id,
isReserved: false
},
tx
);
if (existingSegment) {
// use existing folder and update the path / parent
currentParentId = existingSegment.id;
} else {
const newFolder = { const newFolder = {
name: segment, name: segment,
parentId: parentFolderId, parentId: currentParentId,
id: uuidv4(), id: uuidv4(),
envId: env.id, envId: env.id,
version: 1 version: 1
}; };
parentFolderId = newFolder.id;
return newFolder; currentParentId = newFolder.id;
}); newFolders.push(newFolder);
parentFolderId = newFolders.at(-1)?.id as string; }
}
if (newFolders.length) {
const docs = await folderDAL.insertMany(newFolders, tx); const docs = await folderDAL.insertMany(newFolders, tx);
const folderVersions = await folderVersionDAL.insertMany( const folderVersions = await folderVersionDAL.insertMany(
docs.map((doc) => ({ docs.map((doc) => ({
@@ -133,7 +173,7 @@ export const secretFolderServiceFactory = ({
} }
}, },
message: "Folder created", message: "Folder created",
folderId: parentFolderId, folderId: currentParentId,
changes: folderVersions.map((fv) => ({ changes: folderVersions.map((fv) => ({
type: CommitType.ADD, type: CommitType.ADD,
folderVersionId: fv.id folderVersionId: fv.id
@@ -145,9 +185,10 @@ export const secretFolderServiceFactory = ({
} }
const doc = await folderDAL.create( const doc = await folderDAL.create(
{ name, envId: env.id, version: 1, parentId: parentFolderId, description }, { name, envId: env.id, version: 1, parentId: currentParentId, description },
tx tx
); );
const folderVersion = await folderVersionDAL.create( const folderVersion = await folderVersionDAL.create(
{ {
name: doc.name, name: doc.name,
@@ -158,6 +199,7 @@ export const secretFolderServiceFactory = ({
}, },
tx tx
); );
await folderCommitService.createCommit( await folderCommitService.createCommit(
{ {
actor: { actor: {
@@ -167,7 +209,7 @@ export const secretFolderServiceFactory = ({
} }
}, },
message: "Folder created", message: "Folder created",
folderId: parentFolderId, folderId: doc.id,
changes: [ changes: [
{ {
type: CommitType.ADD, type: CommitType.ADD,
@@ -177,6 +219,7 @@ export const secretFolderServiceFactory = ({
}, },
tx tx
); );
return doc; return doc;
}); });