mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 07:26:45 +00:00
fix: allow apps which have write access
This commit is contained in:
@@ -785,41 +785,82 @@ const getAppsWindmill = async ({ accessToken }: { accessToken: string }) => {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
// make calls for each app to check user is admin for that app or not
|
//check for write access of secrets in windmill workspaces
|
||||||
const authCheckForApps = async (data: any) => {
|
const writeAccessCheck = data.map(async (app: any) => {
|
||||||
const allAppResponse = data.map(async (app: any) => {
|
try {
|
||||||
return standardRequest.get(
|
const userPath = "u/user/variable";
|
||||||
`${INTEGRATION_WINDMILL_API_URL}/w/${app.id}/users/whoami`,
|
const folderPath = "f/folder/variable";
|
||||||
|
|
||||||
|
const { data: writeUser } = await standardRequest.post(
|
||||||
|
`${INTEGRATION_WINDMILL_API_URL}/w/${app.id}/variables/create`,
|
||||||
|
{
|
||||||
|
path: userPath,
|
||||||
|
value: "variable",
|
||||||
|
is_secret: true,
|
||||||
|
description: "variable description"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
headers: {
|
headers: {
|
||||||
Authorization: `Bearer ${accessToken}`,
|
Authorization: `Bearer ${accessToken}`,
|
||||||
"Accept-Encoding": "application/json",
|
"Accept-Encoding": "application/json",
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
)
|
);
|
||||||
.then((response: any) => {
|
|
||||||
const modifiedData = { ...response.data };
|
|
||||||
modifiedData.appName = app.name;
|
|
||||||
return modifiedData;
|
|
||||||
})
|
|
||||||
.catch((error: any) => {
|
|
||||||
return undefined;
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
const appPromiseResponses = await Promise.all(allAppResponse)
|
const { data: writeFolder } = await standardRequest.post(
|
||||||
const filteredAppResponses = appPromiseResponses.filter((authRes: any) => (authRes !== undefined) && (authRes.is_admin));
|
`${INTEGRATION_WINDMILL_API_URL}/w/${app.id}/variables/create`,
|
||||||
|
{
|
||||||
return filteredAppResponses;
|
path: folderPath,
|
||||||
}
|
value: "variable",
|
||||||
|
is_secret: true,
|
||||||
|
description: "variable description"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
// is write access is allowed then delete the created secrets from workspace
|
||||||
|
if (writeUser && writeFolder) {
|
||||||
|
await standardRequest.delete(
|
||||||
|
`${INTEGRATION_WINDMILL_API_URL}/w/${app.id}/variables/delete/${userPath}`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
// get apps that user(auth token) is authorized for
|
await standardRequest.delete(
|
||||||
const authorizedApps = await authCheckForApps(data);
|
`${INTEGRATION_WINDMILL_API_URL}/w/${app.id}/variables/delete/${folderPath}`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
const apps = authorizedApps.map((a: any) => {
|
return app;
|
||||||
|
} else {
|
||||||
|
return { error: "cannot write secret" };
|
||||||
|
}
|
||||||
|
} catch (err: any) {
|
||||||
|
return { error: err.message };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
const appsWriteResponses = await Promise.all(writeAccessCheck);
|
||||||
|
const appsWithWriteAccess = appsWriteResponses.filter((appRes: any) => !appRes.error);
|
||||||
|
|
||||||
|
const apps = appsWithWriteAccess.map((a: any) => {
|
||||||
return {
|
return {
|
||||||
name: a.appName,
|
name: a.name,
|
||||||
appId: a.workspace_id,
|
appId: a.id,
|
||||||
};
|
};
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -114,7 +114,7 @@ export default function WindmillCreateIntegrationPage() {
|
|||||||
placeholder="Provide a path, default is /"
|
placeholder="Provide a path, default is /"
|
||||||
/>
|
/>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
<FormControl label="Windmill Workspace (Admin)" className="mt-4">
|
<FormControl label="Windmill Workspace (Write Access)" className="mt-4">
|
||||||
<Select
|
<Select
|
||||||
value={targetApp}
|
value={targetApp}
|
||||||
onValueChange={(val) => setTargetApp(val)}
|
onValueChange={(val) => setTargetApp(val)}
|
||||||
|
|||||||
Reference in New Issue
Block a user