fix: tests and missing tags permission check

This commit is contained in:
Daniel Hougaard
2025-03-11 00:09:00 +04:00
parent 46ce46b5a0
commit a8fc0e540a
3 changed files with 15 additions and 13 deletions
+1
View File
@@ -71,6 +71,7 @@
"migrate:org": "tsx ./scripts/migrate-organization.ts", "migrate:org": "tsx ./scripts/migrate-organization.ts",
"seed:new": "tsx ./scripts/create-seed-file.ts", "seed:new": "tsx ./scripts/create-seed-file.ts",
"seed": "knex --knexfile ./dist/db/knexfile.ts --client pg seed:run", "seed": "knex --knexfile ./dist/db/knexfile.ts --client pg seed:run",
"seed-dev": "knex --knexfile ./src/db/knexfile.ts --client pg seed:run",
"db:reset": "npm run migration:rollback -- --all && npm run migration:latest" "db:reset": "npm run migration:rollback -- --all && npm run migration:latest"
}, },
"keywords": [], "keywords": [],
@@ -1,5 +1,5 @@
/* eslint-disable no-nested-ternary */ /* eslint-disable no-nested-ternary */
import { ForbiddenError, MongoAbility, subject } from "@casl/ability"; import { ForbiddenError, MongoAbility, PureAbility, subject } from "@casl/ability";
import { z } from "zod"; import { z } from "zod";
import { TOrganizations } from "@app/db/schemas"; import { TOrganizations } from "@app/db/schemas";
@@ -15,7 +15,7 @@ import {
} from "./project-permission"; } from "./project-permission";
export function CheckForbiddenErrorSecretsSubject( export function CheckForbiddenErrorSecretsSubject(
permission: MongoAbility<ProjectPermissionSet>, permission: MongoAbility<ProjectPermissionSet> | PureAbility,
action: Extract< action: Extract<
ProjectPermissionSecretActions, ProjectPermissionSecretActions,
ProjectPermissionSecretActions.ReadValue | ProjectPermissionSecretActions.DescribeSecret ProjectPermissionSecretActions.ReadValue | ProjectPermissionSecretActions.DescribeSecret
@@ -1,4 +1,4 @@
import { ForbiddenError, PureAbility, subject } from "@casl/ability"; import { ForbiddenError, MongoAbility, subject } from "@casl/ability";
import { Knex } from "knex"; import { Knex } from "knex";
import { z } from "zod"; import { z } from "zod";
@@ -15,6 +15,7 @@ import { TPermissionServiceFactory } from "@app/ee/services/permission/permissio
import { import {
ProjectPermissionActions, ProjectPermissionActions,
ProjectPermissionSecretActions, ProjectPermissionSecretActions,
ProjectPermissionSet,
ProjectPermissionSub ProjectPermissionSub
} from "@app/ee/services/permission/project-permission"; } from "@app/ee/services/permission/project-permission";
import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service"; import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service";
@@ -123,7 +124,7 @@ export const secretV2BridgeServiceFactory = ({
}: TSecretV2BridgeServiceFactoryDep) => { }: TSecretV2BridgeServiceFactoryDep) => {
const $validateSecretReferences = async ( const $validateSecretReferences = async (
projectId: string, projectId: string,
permission: PureAbility, permission: MongoAbility<ProjectPermissionSet>,
references: ReturnType<typeof getAllSecretReferences>["nestedReferences"], references: ReturnType<typeof getAllSecretReferences>["nestedReferences"],
tx?: Knex tx?: Knex
) => { ) => {
@@ -131,6 +132,7 @@ export const secretV2BridgeServiceFactory = ({
const uniqueReferenceEnvironmentSlugs = Array.from(new Set(references.map((el) => el.environment))); const uniqueReferenceEnvironmentSlugs = Array.from(new Set(references.map((el) => el.environment)));
const referencesEnvironments = await projectEnvDAL.findBySlugs(projectId, uniqueReferenceEnvironmentSlugs, tx); const referencesEnvironments = await projectEnvDAL.findBySlugs(projectId, uniqueReferenceEnvironmentSlugs, tx);
if (referencesEnvironments.length !== uniqueReferenceEnvironmentSlugs.length) if (referencesEnvironments.length !== uniqueReferenceEnvironmentSlugs.length)
throw new BadRequestError({ throw new BadRequestError({
message: `Referenced environment not found. Missing ${diff( message: `Referenced environment not found. Missing ${diff(
@@ -147,6 +149,7 @@ export const secretV2BridgeServiceFactory = ({
})), })),
tx tx
); );
const referencesFolderGroupByPath = groupBy(referredFolders.filter(Boolean), (i) => `${i?.envId}-${i?.path}`); const referencesFolderGroupByPath = groupBy(referredFolders.filter(Boolean), (i) => `${i?.envId}-${i?.path}`);
const referredSecrets = await secretDAL.find( const referredSecrets = await secretDAL.find(
{ {
@@ -194,15 +197,12 @@ export const secretV2BridgeServiceFactory = ({
const referredSecretsGroupBySecretKey = groupBy(referredSecrets, (i) => i.key); const referredSecretsGroupBySecretKey = groupBy(referredSecrets, (i) => i.key);
references.forEach((el) => { references.forEach((el) => {
ForbiddenError.from(permission).throwUnlessCan( CheckForbiddenErrorSecretsSubject(permission, ProjectPermissionSecretActions.ReadValue, {
ProjectPermissionActions.Read, environment: el.environment,
subject(ProjectPermissionSub.Secrets, { secretPath: el.secretPath,
environment: el.environment, secretName: el.secretKey,
secretPath: el.secretPath, secretTags: referredSecretsGroupBySecretKey[el.secretKey][0]?.tags?.map((i) => i.slug)
secretName: el.secretKey, });
tags: referredSecretsGroupBySecretKey[el.secretKey][0]?.tags?.map((i) => i.slug)
})
);
}); });
return referredSecrets; return referredSecrets;
@@ -277,6 +277,7 @@ export const secretV2BridgeServiceFactory = ({
const allSecretReferences = nestedReferences.concat( const allSecretReferences = nestedReferences.concat(
localReferences.map((el) => ({ secretKey: el, secretPath, environment })) localReferences.map((el) => ({ secretKey: el, secretPath, environment }))
); );
await $validateSecretReferences(projectId, permission, allSecretReferences); await $validateSecretReferences(projectId, permission, allSecretReferences);
const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({ const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({