mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 00:26:24 +00:00
feat: updated api description and changed slug to privilege slug
This commit is contained in:
@@ -102,7 +102,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
// disallow empty string
|
// disallow empty string
|
||||||
slug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.slug),
|
privilegeSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.slug),
|
||||||
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.identityId),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.identityId),
|
||||||
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.projectSlug),
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.projectSlug),
|
||||||
data: z
|
data: z
|
||||||
@@ -146,17 +146,19 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const { isPackedPermission, ...data } = req.body.data;
|
const { isPackedPermission, ...updatedInfo } = req.body.data;
|
||||||
const privilege = await server.services.identityProjectAdditionalPrivilege.updateBySlug({
|
const privilege = await server.services.identityProjectAdditionalPrivilege.updateBySlug({
|
||||||
actorId: req.permission.id,
|
actorId: req.permission.id,
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
...req.body,
|
slug: req.body.privilegeSlug,
|
||||||
|
identityId: req.body.identityId,
|
||||||
|
projectSlug: req.body.projectSlug,
|
||||||
data: {
|
data: {
|
||||||
...data,
|
...updatedInfo,
|
||||||
permissions: data?.permissions
|
permissions: updatedInfo?.permissions
|
||||||
? JSON.stringify(isPackedPermission ? data?.permissions : packRules(data.permissions))
|
? JSON.stringify(isPackedPermission ? updatedInfo?.permissions : packRules(updatedInfo.permissions))
|
||||||
: undefined
|
: undefined
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -169,7 +171,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
method: "DELETE",
|
method: "DELETE",
|
||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
slug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.slug),
|
privilegeSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.slug),
|
||||||
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.identityId),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.identityId),
|
||||||
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.projectSlug)
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.projectSlug)
|
||||||
}),
|
}),
|
||||||
@@ -186,18 +188,20 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
...req.body
|
slug: req.body.privilegeSlug,
|
||||||
|
identityId: req.body.identityId,
|
||||||
|
projectSlug: req.body.projectSlug
|
||||||
});
|
});
|
||||||
return { privilege };
|
return { privilege };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
server.route({
|
server.route({
|
||||||
url: "/:slug",
|
url: "/:privilegeSlug",
|
||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
slug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.slug)
|
privilegeSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.slug)
|
||||||
}),
|
}),
|
||||||
querystring: z.object({
|
querystring: z.object({
|
||||||
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.identityId),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.identityId),
|
||||||
@@ -216,7 +220,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
slug: req.params.slug,
|
slug: req.params.privilegeSlug,
|
||||||
...req.query
|
...req.query
|
||||||
});
|
});
|
||||||
return { privilege };
|
return { privilege };
|
||||||
|
|||||||
@@ -400,7 +400,7 @@ export const SECRET_TAGS = {
|
|||||||
|
|
||||||
export const IDENTITY_ADDITIONAL_PRIVILEGE = {
|
export const IDENTITY_ADDITIONAL_PRIVILEGE = {
|
||||||
CREATE: {
|
CREATE: {
|
||||||
projectSlug: "The slug of the project of the dynamic secret in.",
|
projectSlug: "The slug of the project of the identity in.",
|
||||||
identityId: "The ID of the identity to delete.",
|
identityId: "The ID of the identity to delete.",
|
||||||
slug: "The slug of the privilege to create.",
|
slug: "The slug of the privilege to create.",
|
||||||
permissions:
|
permissions:
|
||||||
@@ -412,12 +412,16 @@ export const IDENTITY_ADDITIONAL_PRIVILEGE = {
|
|||||||
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
||||||
},
|
},
|
||||||
UPDATE: {
|
UPDATE: {
|
||||||
projectSlug: "The slug of the project of the dynamic secret in.",
|
projectSlug: "The slug of the project of the identity in.",
|
||||||
identityId: "The ID of the identity to delete.",
|
identityId: "The ID of the identity to update.",
|
||||||
slug: "The slug of the privilege to create.",
|
slug: "The slug of the privilege to update.",
|
||||||
newSlug: "The new slug of the privilege to create.",
|
newSlug: "The new slug of the privilege to update.",
|
||||||
permissions:
|
permissions: `The permission object for the privilege.
|
||||||
"The permission object for the privilege. Refer https://casl.js.org/v6/en/guide/define-rules#the-shape-of-raw-rule to understand the shape",
|
Example unpacked permission shape
|
||||||
|
1. [["read", "secrets", {environment: "dev", secretPath: {$glob: "/"}}]]
|
||||||
|
2. [["read", "secrets", {environment: "dev"}], ["create", "secrets", {environment: "dev"}]]
|
||||||
|
2. [["read", "secrets", {environment: "dev"}]]
|
||||||
|
`,
|
||||||
isPackPermission: "Whether the server should pack(compact) the permission object.",
|
isPackPermission: "Whether the server should pack(compact) the permission object.",
|
||||||
isTemporary: "Whether the privilege is temporary.",
|
isTemporary: "Whether the privilege is temporary.",
|
||||||
temporaryMode: "Type of temporary access given. Types: relative",
|
temporaryMode: "Type of temporary access given. Types: relative",
|
||||||
@@ -425,18 +429,18 @@ export const IDENTITY_ADDITIONAL_PRIVILEGE = {
|
|||||||
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
||||||
},
|
},
|
||||||
DELETE: {
|
DELETE: {
|
||||||
projectSlug: "The slug of the project of the dynamic secret in.",
|
projectSlug: "The slug of the project of the identity in.",
|
||||||
identityId: "The ID of the identity to delete.",
|
identityId: "The ID of the identity to delete.",
|
||||||
slug: "The slug of the privilege to create."
|
slug: "The slug of the privilege to delete."
|
||||||
},
|
},
|
||||||
GET_BY_SLUG: {
|
GET_BY_SLUG: {
|
||||||
projectSlug: "The slug of the project of the dynamic secret in.",
|
projectSlug: "The slug of the project of the identity in.",
|
||||||
identityId: "The ID of the identity to delete.",
|
identityId: "The ID of the identity to list.",
|
||||||
slug: "The slug of the privilege to create."
|
slug: "The slug of the privilege."
|
||||||
},
|
},
|
||||||
LIST: {
|
LIST: {
|
||||||
projectSlug: "The slug of the project of the dynamic secret in.",
|
projectSlug: "The slug of the project of the identity in.",
|
||||||
identityId: "The ID of the identity to delete.",
|
identityId: "The ID of the identity to list.",
|
||||||
unpacked: "Whether the system should send the permissions as unpacked"
|
unpacked: "Whether the system should send the permissions as unpacked"
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -35,9 +35,9 @@ export const useUpdateIdentityProjectAdditionalPrivilege = () => {
|
|||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation<TIdentityProjectPrivilege, {}, TUpdateIdentityProjectPrivlegeDTO>({
|
return useMutation<TIdentityProjectPrivilege, {}, TUpdateIdentityProjectPrivlegeDTO>({
|
||||||
mutationFn: async ({ slug, projectSlug, identityId, data }) => {
|
mutationFn: async ({ privilegeSlug, projectSlug, identityId, data }) => {
|
||||||
const { data: res } = await apiRequest.patch("/api/v1/additional-privilege/identity", {
|
const { data: res } = await apiRequest.patch("/api/v1/additional-privilege/identity", {
|
||||||
slug,
|
privilegeSlug,
|
||||||
projectSlug,
|
projectSlug,
|
||||||
identityId,
|
identityId,
|
||||||
data: {
|
data: {
|
||||||
@@ -60,12 +60,12 @@ export const useDeleteIdentityProjectAdditionalPrivilege = () => {
|
|||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation<TIdentityProjectPrivilege, {}, TDeleteIdentityProjectPrivilegeDTO>({
|
return useMutation<TIdentityProjectPrivilege, {}, TDeleteIdentityProjectPrivilegeDTO>({
|
||||||
mutationFn: async ({ identityId, projectSlug, slug }) => {
|
mutationFn: async ({ identityId, projectSlug, privilegeSlug }) => {
|
||||||
const { data } = await apiRequest.delete("/api/v1/additional-privilege/identity", {
|
const { data } = await apiRequest.delete("/api/v1/additional-privilege/identity", {
|
||||||
data: {
|
data: {
|
||||||
identityId,
|
identityId,
|
||||||
projectSlug,
|
projectSlug,
|
||||||
slug
|
privilegeSlug
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
return data.privilege;
|
return data.privilege;
|
||||||
|
|||||||
@@ -11,13 +11,13 @@ import {
|
|||||||
} from "./types";
|
} from "./types";
|
||||||
|
|
||||||
export const identitiyProjectPrivilegeKeys = {
|
export const identitiyProjectPrivilegeKeys = {
|
||||||
details: ({ identityId, slug, projectSlug }: TGetIdentityProjectPrivilegeDetails) =>
|
details: ({ identityId, privilegeSlug, projectSlug }: TGetIdentityProjectPrivilegeDetails) =>
|
||||||
[
|
[
|
||||||
"identity-user-privilege",
|
"identity-user-privilege",
|
||||||
{
|
{
|
||||||
identityId,
|
identityId,
|
||||||
projectSlug,
|
projectSlug,
|
||||||
slug
|
privilegeSlug
|
||||||
}
|
}
|
||||||
] as const,
|
] as const,
|
||||||
list: ({ projectSlug, identityId }: TListIdentityProjectPrivileges) =>
|
list: ({ projectSlug, identityId }: TListIdentityProjectPrivileges) =>
|
||||||
@@ -27,17 +27,17 @@ export const identitiyProjectPrivilegeKeys = {
|
|||||||
export const useGetIdentityProjectPrivilegeDetails = ({
|
export const useGetIdentityProjectPrivilegeDetails = ({
|
||||||
projectSlug,
|
projectSlug,
|
||||||
identityId,
|
identityId,
|
||||||
slug
|
privilegeSlug
|
||||||
}: TGetIdentityProjectPrivilegeDetails) => {
|
}: TGetIdentityProjectPrivilegeDetails) => {
|
||||||
return useQuery({
|
return useQuery({
|
||||||
enabled: Boolean(projectSlug && identityId && slug),
|
enabled: Boolean(projectSlug && identityId && privilegeSlug),
|
||||||
queryKey: identitiyProjectPrivilegeKeys.details({ projectSlug, slug, identityId }),
|
queryKey: identitiyProjectPrivilegeKeys.details({ projectSlug, privilegeSlug, identityId }),
|
||||||
queryFn: async () => {
|
queryFn: async () => {
|
||||||
const {
|
const {
|
||||||
data: { privilege }
|
data: { privilege }
|
||||||
} = await apiRequest.get<{
|
} = await apiRequest.get<{
|
||||||
privilege: Omit<TIdentityProjectPrivilege, "permissions"> & { permissions: unknown };
|
privilege: Omit<TIdentityProjectPrivilege, "permissions"> & { permissions: unknown };
|
||||||
}>(`/api/v1/additional-privilege/identity/${slug}`, {
|
}>(`/api/v1/additional-privilege/identity/${privilegeSlug}`, {
|
||||||
params: {
|
params: {
|
||||||
identityId,
|
identityId,
|
||||||
projectSlug
|
projectSlug
|
||||||
|
|||||||
@@ -42,14 +42,14 @@ export type TCreateIdentityProjectPrivilegeDTO = {
|
|||||||
export type TUpdateIdentityProjectPrivlegeDTO = {
|
export type TUpdateIdentityProjectPrivlegeDTO = {
|
||||||
projectSlug: string;
|
projectSlug: string;
|
||||||
identityId: string;
|
identityId: string;
|
||||||
slug: string;
|
privilegeSlug: string;
|
||||||
data: Partial<Omit<TCreateIdentityProjectPrivilegeDTO, "projectMembershipId" | "projectId">>;
|
data: Partial<Omit<TCreateIdentityProjectPrivilegeDTO, "projectMembershipId" | "projectId">>;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TDeleteIdentityProjectPrivilegeDTO = {
|
export type TDeleteIdentityProjectPrivilegeDTO = {
|
||||||
projectSlug: string;
|
projectSlug: string;
|
||||||
identityId: string;
|
identityId: string;
|
||||||
slug: string;
|
privilegeSlug: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TListIdentityUserPrivileges = {
|
export type TListIdentityUserPrivileges = {
|
||||||
@@ -60,5 +60,5 @@ export type TListIdentityUserPrivileges = {
|
|||||||
export type TGetIdentityProejctPrivilegeDetails = {
|
export type TGetIdentityProejctPrivilegeDetails = {
|
||||||
projectSlug: string;
|
projectSlug: string;
|
||||||
identityId: string;
|
identityId: string;
|
||||||
slug: string;
|
privilegeSlug: string;
|
||||||
};
|
};
|
||||||
|
|||||||
+2
-2
@@ -144,7 +144,7 @@ const SpecificPrivilegeSecretForm = ({
|
|||||||
conditions
|
conditions
|
||||||
}))
|
}))
|
||||||
},
|
},
|
||||||
slug: privilege.slug,
|
privilegeSlug: privilege.slug,
|
||||||
identityId,
|
identityId,
|
||||||
projectSlug
|
projectSlug
|
||||||
});
|
});
|
||||||
@@ -165,7 +165,7 @@ const SpecificPrivilegeSecretForm = ({
|
|||||||
try {
|
try {
|
||||||
await deleteIdentityPrivilege.mutateAsync({
|
await deleteIdentityPrivilege.mutateAsync({
|
||||||
identityId,
|
identityId,
|
||||||
slug: privilege.slug,
|
privilegeSlug: privilege.slug,
|
||||||
projectSlug
|
projectSlug
|
||||||
});
|
});
|
||||||
createNotification({
|
createNotification({
|
||||||
|
|||||||
Reference in New Issue
Block a user