Add supabase docs, modify integration docs wording, check integration middleware

This commit is contained in:
Tuan Dang
2023-04-14 14:08:09 +03:00
parent d824305fd6
commit b21a8b4574
29 changed files with 73 additions and 45 deletions
+1 -1
View File
@@ -72,7 +72,7 @@ interface Update {
if (!integration) throw IntegrationNotFoundError(); if (!integration) throw IntegrationNotFoundError();
const integrationAuth = await IntegrationAuth const integrationAuth = await IntegrationAuth
.findById(integrationId) .findById(integration.integrationAuth)
.select( .select(
'+refreshCiphertext +refreshIV +refreshTag +accessCiphertext +accessIV +accessTag +accessExpiresAt' '+refreshCiphertext +refreshIV +refreshTag +accessCiphertext +accessIV +accessTag +accessExpiresAt'
); );
+12 -7
View File
@@ -34,19 +34,21 @@ import { validateServiceAccountClientForWorkspace } from '../helpers/serviceAcco
*/ */
const validateClientForIntegrationAuth = async ({ const validateClientForIntegrationAuth = async ({
authData, authData,
integrationId, integrationAuthId,
acceptedRoles acceptedRoles,
attachAccessToken
}: { }: {
authData: { authData: {
authMode: string; authMode: string;
authPayload: IUser | IServiceAccount | IServiceTokenData; authPayload: IUser | IServiceAccount | IServiceTokenData;
}; };
integrationId: Types.ObjectId; integrationAuthId: Types.ObjectId;
acceptedRoles: Array<'admin' | 'member'>; acceptedRoles: Array<'admin' | 'member'>;
attachAccessToken?: boolean;
}) => { }) => {
const integrationAuth = await IntegrationAuth const integrationAuth = await IntegrationAuth
.findById(integrationId) .findById(integrationAuthId)
.populate<{ workspace: IWorkspace }>('workspace') .populate<{ workspace: IWorkspace }>('workspace')
.select( .select(
'+refreshCiphertext +refreshIV +refreshTag +accessCiphertext +accessIV +accessTag +accessExpiresAt' '+refreshCiphertext +refreshIV +refreshTag +accessCiphertext +accessIV +accessTag +accessExpiresAt'
@@ -54,9 +56,12 @@ import { validateServiceAccountClientForWorkspace } from '../helpers/serviceAcco
if (!integrationAuth) throw IntegrationAuthNotFoundError(); if (!integrationAuth) throw IntegrationAuthNotFoundError();
const accessToken = (await IntegrationService.getIntegrationAuthAccess({ let accessToken;
integrationAuthId: integrationAuth._id if (attachAccessToken) {
})).accessToken; accessToken = (await IntegrationService.getIntegrationAuthAccess({
integrationAuthId: integrationAuth._id
})).accessToken;
}
if (authData.authMode === AUTH_MODE_JWT && authData.authPayload instanceof User) { if (authData.authMode === AUTH_MODE_JWT && authData.authPayload instanceof User) {
await validateUserClientForWorkspace({ await validateUserClientForWorkspace({
@@ -18,8 +18,6 @@ const requireIntegrationAuth = ({
acceptedRoles: Array<'admin' | 'member'>; acceptedRoles: Array<'admin' | 'member'>;
}) => { }) => {
return async (req: Request, res: Response, next: NextFunction) => { return async (req: Request, res: Response, next: NextFunction) => {
// integration authorization middleware
const { integrationId } = req.params; const { integrationId } = req.params;
const { integration, accessToken } = await validateClientForIntegration({ const { integration, accessToken } = await validateClientForIntegration({
@@ -30,8 +30,9 @@ const requireIntegrationAuthorizationAuth = ({
const { integrationAuth, accessToken } = await validateClientForIntegrationAuth({ const { integrationAuth, accessToken } = await validateClientForIntegrationAuth({
authData: req.authData, authData: req.authData,
integrationId: new Types.ObjectId(integrationAuthId), integrationAuthId: new Types.ObjectId(integrationAuthId),
acceptedRoles acceptedRoles,
attachAccessToken
}); });
if (integrationAuth) { if (integrationAuth) {
@@ -30,15 +30,15 @@ const requireMembershipAuth = ({
res: Response, res: Response,
next: NextFunction next: NextFunction
) => { ) => {
const { membershipId } = req[locationMembershipId]; const { membershipId } = req[locationMembershipId];
req.targetMembership = await validateClientForMembership({ req.targetMembership = await validateClientForMembership({
authData: req.authData, authData: req.authData,
membershipId: new Types.ObjectId(membershipId), membershipId: new Types.ObjectId(membershipId),
acceptedRoles acceptedRoles
}); });
return next(); return next();
} }
} }
Binary file not shown.

After

Width:  |  Height:  |  Size: 504 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 538 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 505 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 564 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 382 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.1 MiB

After

Width:  |  Height:  |  Size: 1.1 MiB

+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "CircleCI" title: "CircleCI"
description: "How to automatically sync secrets from Infisical into your CircleCI project." description: "How to sync secrets from Infisical to CircleCI"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "GitHub Actions" title: "GitHub Actions"
description: "How to automatically sync secrets from Infisical into your GitHub Actions." description: "How to sync secrets from Infisical to GitHub Actions"
--- ---
<Warning> <Warning>
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "GitLab" title: "GitLab"
description: "How to automatically sync secrets from Infisical into GitLab." description: "How to sync secrets from Infisical to GitLab"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Travis CI" title: "Travis CI"
description: "How to automatically sync secrets from Infisical to your Travis CI repository." description: "How to sync secrets from Infisical to Travis CI"
--- ---
Prerequisites: Prerequisites:
@@ -1,6 +1,6 @@
--- ---
title: "AWS Parameter Store" title: "AWS Parameter Store"
description: "How to automatically sync secrets from Infisical to your AWS Parameter Store." description: "How to sync secrets from Infisical to AWS Parameter Store"
--- ---
Prerequisites: Prerequisites:
@@ -1,6 +1,6 @@
--- ---
title: "AWS Secret Manager" title: "AWS Secret Manager"
description: "How to automatically sync secrets from Infisical to your AWS Secret Manager." description: "How to sync secrets from Infisical to AWS Secret Manager"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Azure Key Vault" title: "Azure Key Vault"
description: "How to automatically sync secrets from Infisical into your Azure Key Vault." description: "How to sync secrets from Infisical to Azure Key Vault"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Fly.io" title: "Fly.io"
description: "How to automatically sync secrets from Infisical into your Fly.io project." description: "How to sync secrets from Infisical to Fly.io"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Heroku" title: "Heroku"
description: "How to automatically sync secrets from Infisical into your Heroku project." description: "How to sync secrets from Infisical to Heroku"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Netlify" title: "Netlify"
description: "How to automatically sync secrets from Infisical into your Netlify project." description: "How to sync secrets from Infisical to Netlify"
--- ---
<Warning> <Warning>
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Railway" title: "Railway"
description: "How to automatically sync secrets from Infisical into your Railway projects and services" description: "How to sync secrets from Infisical to Railway"
--- ---
Prerequisites: Prerequisites:
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Render" title: "Render"
description: "How to automatically sync secrets from Infisical into your Render project." description: "How to sync secrets from Infisical to Render"
--- ---
Prerequisites: Prerequisites:
+28 -4
View File
@@ -1,20 +1,44 @@
--- ---
title: "Supabase" title: "Supabase"
description: "How to automatically sync secrets from Infisical into your Supabase project." description: "How to sync secrets from Infisical to Supabase"
--- ---
<Note>
The Supabase integration is useful if your Supabase project uses sensitive-information such as [environment variables in edge functions](https://supabase.com/docs/guides/functions/secrets).
Synced envars can be accessed in edge functions using Deno's built-in handler: `Deno.env.get(MY_SECRET_NAME)`.
</Note>
Prerequisites: Prerequisites:
- Have an account and project set up at [Supabase](https://supabase.com/)
- Set up and add envars to [Infisical Cloud](https://app.infisical.com) - Set up and add envars to [Infisical Cloud](https://app.infisical.com)
Note somewhere that envars will be accessible in edge functions etc.
## Navigate to your project's integrations tab ## Navigate to your project's integrations tab
![integrations](../../images/integrations.png) ![integrations](../../images/integrations.png)
## Enter your Supabase API ## Enter your Supabase Access Token
Obtain a Supabase Access Token in your Supabase [Account > Access Tokens](https://app.supabase.com/account/tokens).
![integrations supabase dashboard](../../images/integrations-supabase-dashboard.png)
![integrations supabase token](../../images/integrations-supabase-token.png)
Press on the Supabase tile and input your Supabase Access Token to grant Infisical access to your Supabase account.
![integrations supabase authorization](../../images/integrations-supabase-authorization.png)
<Info>
If this is your project's first cloud integration, then you'll have to grant
Infisical access to your project's environment variables. Although this step
breaks E2EE, it's necessary for Infisical to sync the environment variables to
the cloud platform.
</Info>
## Start integration ## Start integration
Select which Infisical environment secrets you want to sync to which Supabase project. Lastly, press create integration to start syncing secrets to Supabase.
![integrations supabase create](../../images/integrations-supabase-create.png)
![integrations supabase](../../images/integrations-supabase.png)
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: "Vercel" title: "Vercel"
description: "How to automatically sync secrets from Infisical into your Vercel project." description: "How to sync secrets from Infisical to Vercel"
--- ---
Prerequisites: Prerequisites:
+2 -2
View File
@@ -18,9 +18,9 @@ Missing an integration? Throw in a [request](https://github.com/Infisical/infisi
| [Vercel](/integrations/cloud/vercel) | Cloud | Available | | [Vercel](/integrations/cloud/vercel) | Cloud | Available |
| [Netlify](/integrations/cloud/netlify) | Cloud | Available | | [Netlify](/integrations/cloud/netlify) | Cloud | Available |
| [Render](/integrations/cloud/render) | Cloud | Available | | [Render](/integrations/cloud/render) | Cloud | Available |
| [Railway](/integrations/cloud/railway) | Cloud | Available | | [Railway](/integrations/cloud/railway) | Cloud | Available |
| [Fly.io](/integrations/cloud/flyio) | Cloud | Available | | [Fly.io](/integrations/cloud/flyio) | Cloud | Available |
| [Supabase](/integrations/cloud/flyio) | Cloud | Available | | [Supabase](/integrations/cloud/supabase) | Cloud | Available |
| [AWS Parameter Store](/integrations/cloud/aws-parameter-store) | Cloud | Available | | [AWS Parameter Store](/integrations/cloud/aws-parameter-store) | Cloud | Available |
| [AWS Secret Manager](/integrations/cloud/aws-secret-manager) | Cloud | Available | | [AWS Secret Manager](/integrations/cloud/aws-secret-manager) | Cloud | Available |
| [Azure Key Vault](/integrations/cloud/azure-key-vault) | Cloud | Available | | [Azure Key Vault](/integrations/cloud/azure-key-vault) | Cloud | Available |
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
title: 'Kubernetes' title: 'Kubernetes'
description: "This page explains how to use Infisical to inject secrets into Kubernetes clusters." description: "How to use Infisical to inject secrets into Kubernetes clusters."
--- ---
![title](../../images/k8-diagram.png) ![title](../../images/k8-diagram.png)
+1
View File
@@ -151,6 +151,7 @@
"integrations/cloud/render", "integrations/cloud/render",
"integrations/cloud/railway", "integrations/cloud/railway",
"integrations/cloud/flyio", "integrations/cloud/flyio",
"integrations/cloud/supabase",
"integrations/cloud/azure-key-vault", "integrations/cloud/azure-key-vault",
"integrations/cicd/githubactions", "integrations/cicd/githubactions",
"integrations/cicd/gitlab", "integrations/cicd/gitlab",
@@ -19,7 +19,6 @@ const deleteIntegration = ({ integrationId }: Props) =>
if (res && res.status === 200) { if (res && res.status === 200) {
return (await res.json()).integration; return (await res.json()).integration;
} }
console.log('Failed to delete an integration');
return undefined; return undefined;
}); });