mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 01:26:43 +00:00
fix: tests and missing tags permission check
This commit is contained in:
@@ -71,6 +71,7 @@
|
|||||||
"migrate:org": "tsx ./scripts/migrate-organization.ts",
|
"migrate:org": "tsx ./scripts/migrate-organization.ts",
|
||||||
"seed:new": "tsx ./scripts/create-seed-file.ts",
|
"seed:new": "tsx ./scripts/create-seed-file.ts",
|
||||||
"seed": "knex --knexfile ./dist/db/knexfile.ts --client pg seed:run",
|
"seed": "knex --knexfile ./dist/db/knexfile.ts --client pg seed:run",
|
||||||
|
"seed-dev": "knex --knexfile ./src/db/knexfile.ts --client pg seed:run",
|
||||||
"db:reset": "npm run migration:rollback -- --all && npm run migration:latest"
|
"db:reset": "npm run migration:rollback -- --all && npm run migration:latest"
|
||||||
},
|
},
|
||||||
"keywords": [],
|
"keywords": [],
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* eslint-disable no-nested-ternary */
|
/* eslint-disable no-nested-ternary */
|
||||||
import { ForbiddenError, MongoAbility, subject } from "@casl/ability";
|
import { ForbiddenError, MongoAbility, PureAbility, subject } from "@casl/ability";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { TOrganizations } from "@app/db/schemas";
|
import { TOrganizations } from "@app/db/schemas";
|
||||||
@@ -15,7 +15,7 @@ import {
|
|||||||
} from "./project-permission";
|
} from "./project-permission";
|
||||||
|
|
||||||
export function CheckForbiddenErrorSecretsSubject(
|
export function CheckForbiddenErrorSecretsSubject(
|
||||||
permission: MongoAbility<ProjectPermissionSet>,
|
permission: MongoAbility<ProjectPermissionSet> | PureAbility,
|
||||||
action: Extract<
|
action: Extract<
|
||||||
ProjectPermissionSecretActions,
|
ProjectPermissionSecretActions,
|
||||||
ProjectPermissionSecretActions.ReadValue | ProjectPermissionSecretActions.DescribeSecret
|
ProjectPermissionSecretActions.ReadValue | ProjectPermissionSecretActions.DescribeSecret
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { ForbiddenError, PureAbility, subject } from "@casl/ability";
|
import { ForbiddenError, MongoAbility, subject } from "@casl/ability";
|
||||||
import { Knex } from "knex";
|
import { Knex } from "knex";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
@@ -15,6 +15,7 @@ import { TPermissionServiceFactory } from "@app/ee/services/permission/permissio
|
|||||||
import {
|
import {
|
||||||
ProjectPermissionActions,
|
ProjectPermissionActions,
|
||||||
ProjectPermissionSecretActions,
|
ProjectPermissionSecretActions,
|
||||||
|
ProjectPermissionSet,
|
||||||
ProjectPermissionSub
|
ProjectPermissionSub
|
||||||
} from "@app/ee/services/permission/project-permission";
|
} from "@app/ee/services/permission/project-permission";
|
||||||
import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service";
|
import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service";
|
||||||
@@ -123,7 +124,7 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
}: TSecretV2BridgeServiceFactoryDep) => {
|
}: TSecretV2BridgeServiceFactoryDep) => {
|
||||||
const $validateSecretReferences = async (
|
const $validateSecretReferences = async (
|
||||||
projectId: string,
|
projectId: string,
|
||||||
permission: PureAbility,
|
permission: MongoAbility<ProjectPermissionSet>,
|
||||||
references: ReturnType<typeof getAllSecretReferences>["nestedReferences"],
|
references: ReturnType<typeof getAllSecretReferences>["nestedReferences"],
|
||||||
tx?: Knex
|
tx?: Knex
|
||||||
) => {
|
) => {
|
||||||
@@ -131,6 +132,7 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
|
|
||||||
const uniqueReferenceEnvironmentSlugs = Array.from(new Set(references.map((el) => el.environment)));
|
const uniqueReferenceEnvironmentSlugs = Array.from(new Set(references.map((el) => el.environment)));
|
||||||
const referencesEnvironments = await projectEnvDAL.findBySlugs(projectId, uniqueReferenceEnvironmentSlugs, tx);
|
const referencesEnvironments = await projectEnvDAL.findBySlugs(projectId, uniqueReferenceEnvironmentSlugs, tx);
|
||||||
|
|
||||||
if (referencesEnvironments.length !== uniqueReferenceEnvironmentSlugs.length)
|
if (referencesEnvironments.length !== uniqueReferenceEnvironmentSlugs.length)
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Referenced environment not found. Missing ${diff(
|
message: `Referenced environment not found. Missing ${diff(
|
||||||
@@ -147,6 +149,7 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
})),
|
})),
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
|
|
||||||
const referencesFolderGroupByPath = groupBy(referredFolders.filter(Boolean), (i) => `${i?.envId}-${i?.path}`);
|
const referencesFolderGroupByPath = groupBy(referredFolders.filter(Boolean), (i) => `${i?.envId}-${i?.path}`);
|
||||||
const referredSecrets = await secretDAL.find(
|
const referredSecrets = await secretDAL.find(
|
||||||
{
|
{
|
||||||
@@ -194,15 +197,12 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
|
|
||||||
const referredSecretsGroupBySecretKey = groupBy(referredSecrets, (i) => i.key);
|
const referredSecretsGroupBySecretKey = groupBy(referredSecrets, (i) => i.key);
|
||||||
references.forEach((el) => {
|
references.forEach((el) => {
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
CheckForbiddenErrorSecretsSubject(permission, ProjectPermissionSecretActions.ReadValue, {
|
||||||
ProjectPermissionActions.Read,
|
environment: el.environment,
|
||||||
subject(ProjectPermissionSub.Secrets, {
|
secretPath: el.secretPath,
|
||||||
environment: el.environment,
|
secretName: el.secretKey,
|
||||||
secretPath: el.secretPath,
|
secretTags: referredSecretsGroupBySecretKey[el.secretKey][0]?.tags?.map((i) => i.slug)
|
||||||
secretName: el.secretKey,
|
});
|
||||||
tags: referredSecretsGroupBySecretKey[el.secretKey][0]?.tags?.map((i) => i.slug)
|
|
||||||
})
|
|
||||||
);
|
|
||||||
});
|
});
|
||||||
|
|
||||||
return referredSecrets;
|
return referredSecrets;
|
||||||
@@ -277,6 +277,7 @@ export const secretV2BridgeServiceFactory = ({
|
|||||||
const allSecretReferences = nestedReferences.concat(
|
const allSecretReferences = nestedReferences.concat(
|
||||||
localReferences.map((el) => ({ secretKey: el, secretPath, environment }))
|
localReferences.map((el) => ({ secretKey: el, secretPath, environment }))
|
||||||
);
|
);
|
||||||
|
|
||||||
await $validateSecretReferences(projectId, permission, allSecretReferences);
|
await $validateSecretReferences(projectId, permission, allSecretReferences);
|
||||||
|
|
||||||
const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({
|
const { encryptor: secretManagerEncryptor } = await kmsService.createCipherPairWithDataKey({
|
||||||
|
|||||||
Reference in New Issue
Block a user