diff --git a/backend/src/server/routes/v1/secret-sharing-router.ts b/backend/src/server/routes/v1/secret-sharing-router.ts
index 5fedfd5a0..de1bfe968 100644
--- a/backend/src/server/routes/v1/secret-sharing-router.ts
+++ b/backend/src/server/routes/v1/secret-sharing-router.ts
@@ -80,7 +80,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
orgId: req.permission?.orgId
});
- // only return secret if it exists and has no password set
+ // return undefined if it does not exist, has password set or has no more views allowed.
if (!sharedSecret || sharedSecret.password) return undefined;
return {
diff --git a/backend/src/services/secret-sharing/secret-sharing-service.ts b/backend/src/services/secret-sharing/secret-sharing-service.ts
index 14a11a65e..b37f8a771 100644
--- a/backend/src/services/secret-sharing/secret-sharing-service.ts
+++ b/backend/src/services/secret-sharing/secret-sharing-service.ts
@@ -179,10 +179,12 @@ export const secretSharingServiceFactory = ({
if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId)
throw new UnauthorizedError();
- if (sharedSecret.password) return undefined;
+ await checkIfExpired(sharedSecret, sharedSecretId);
+
+ if (sharedSecret.password !== null) return undefined;
- // we only update the view count when secret has no password, when password is set view count is updated when we validate the password.
- manageSecretViewCount(sharedSecret, sharedSecretId);
+ // decrement when we are sure the user will view secret.
+ await decrementSecretViewCount(sharedSecret, sharedSecretId);
return {
...sharedSecret,
@@ -215,13 +217,11 @@ export const secretSharingServiceFactory = ({
if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId)
throw new UnauthorizedError();
- if (!sharedSecret.password) return undefined;
-
const isMatch = await bcrypt.compare(password, sharedSecret.password);
- if (!isMatch) return undefined;
+ if (!isMatch) return undefined
- // reduce view count when we are sure the password matches.
- manageSecretViewCount(sharedSecret, sharedSecretId)
+ // we reduce the view count when we are sure the password matches.
+ await decrementSecretViewCount(sharedSecret, sharedSecretId);
return {
...sharedSecret,
@@ -240,7 +240,8 @@ export const secretSharingServiceFactory = ({
return deletedSharedSecret;
};
- const manageSecretViewCount = async (sharedSecret: any, sharedSecretId: string) => {
+ /** Checks if secret is expired and throws error if true */
+ const checkIfExpired = async (sharedSecret: any, sharedSecretId: string) => {
const { expiresAt, expiresAfterViews } = sharedSecret;
if (expiresAt !== null && expiresAt < new Date()) {
@@ -258,6 +259,10 @@ export const secretSharingServiceFactory = ({
message: "Access denied: Secret has expired by view count"
});
}
+ }
+
+ const decrementSecretViewCount = async (sharedSecret: any, sharedSecretId: string) => {
+ const { expiresAfterViews } = sharedSecret;
if (expiresAfterViews) {
// decrement view count if view count expiry set
diff --git a/frontend/src/hooks/api/secretSharing/queries.ts b/frontend/src/hooks/api/secretSharing/queries.ts
index b697b92b4..acf091e5b 100644
--- a/frontend/src/hooks/api/secretSharing/queries.ts
+++ b/frontend/src/hooks/api/secretSharing/queries.ts
@@ -2,7 +2,7 @@ import { useQuery } from "@tanstack/react-query";
import { apiRequest } from "@app/config/request";
-import { TSharedSecret, TViewSharedSecretResponse, ValidateSecretPassword } from "./types";
+import { TSharedSecret, TViewSharedSecretResponse } from "./types";
export const secretSharingKeys = {
allSharedSecrets: () => ["sharedSecrets"] as const,
@@ -77,7 +77,7 @@ export const fetchSecretIfPasswordIsValid = async (
hashedHex: string,
password: string,
) => {
- const { data } = await apiRequest.post