mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
improvements: remove secret permission checks from secret syncs
This commit is contained in:
@@ -2,10 +2,8 @@ import { ForbiddenError, subject } from "@casl/ability";
|
|||||||
|
|
||||||
import { ActionProjectType } from "@app/db/schemas";
|
import { ActionProjectType } from "@app/db/schemas";
|
||||||
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
||||||
import { throwIfMissingSecretReadValueOrDescribePermission } from "@app/ee/services/permission/permission-fns";
|
|
||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types";
|
||||||
import {
|
import {
|
||||||
ProjectPermissionSecretActions,
|
|
||||||
ProjectPermissionSecretSyncActions,
|
ProjectPermissionSecretSyncActions,
|
||||||
ProjectPermissionSub
|
ProjectPermissionSub
|
||||||
} from "@app/ee/services/permission/project-permission";
|
} from "@app/ee/services/permission/project-permission";
|
||||||
@@ -248,15 +246,6 @@ export const secretSyncServiceFactory = ({
|
|||||||
subject(ProjectPermissionSub.SecretSyncs, { environment, secretPath })
|
subject(ProjectPermissionSub.SecretSyncs, { environment, secretPath })
|
||||||
);
|
);
|
||||||
|
|
||||||
throwIfMissingSecretReadValueOrDescribePermission(
|
|
||||||
projectPermission,
|
|
||||||
ProjectPermissionSecretActions.DescribeSecret,
|
|
||||||
{
|
|
||||||
environment,
|
|
||||||
secretPath
|
|
||||||
}
|
|
||||||
);
|
|
||||||
|
|
||||||
const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath);
|
const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath);
|
||||||
|
|
||||||
if (!folder)
|
if (!folder)
|
||||||
@@ -375,11 +364,6 @@ export const secretSyncServiceFactory = ({
|
|||||||
if (!updatedEnvironment || !updatedSecretPath)
|
if (!updatedEnvironment || !updatedSecretPath)
|
||||||
throw new BadRequestError({ message: "Must specify both source environment and secret path" });
|
throw new BadRequestError({ message: "Must specify both source environment and secret path" });
|
||||||
|
|
||||||
throwIfMissingSecretReadValueOrDescribePermission(permission, ProjectPermissionSecretActions.DescribeSecret, {
|
|
||||||
environment: updatedEnvironment,
|
|
||||||
secretPath: updatedSecretPath
|
|
||||||
});
|
|
||||||
|
|
||||||
const newFolder = await folderDAL.findBySecretPath(secretSync.projectId, updatedEnvironment, updatedSecretPath);
|
const newFolder = await folderDAL.findBySecretPath(secretSync.projectId, updatedEnvironment, updatedSecretPath);
|
||||||
|
|
||||||
if (!newFolder)
|
if (!newFolder)
|
||||||
|
|||||||
Reference in New Issue
Block a user