diff --git a/backend/src/ee/routes/v1/identity-project-additional-privilege-router.ts b/backend/src/ee/routes/v1/identity-project-additional-privilege-router.ts index f08dfde1e..1a1c92146 100644 --- a/backend/src/ee/routes/v1/identity-project-additional-privilege-router.ts +++ b/backend/src/ee/routes/v1/identity-project-additional-privilege-router.ts @@ -31,11 +31,11 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F .min(1) .max(60) .trim() - .default(slugify(alphaNumericNanoId(12))) .refine((val) => val.toLowerCase() === val, "Must be lowercase") .refine((v) => slugify(v) === v, { message: "Slug must be a valid slug" }) + .optional() .describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug), permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions) }), @@ -53,6 +53,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F actorOrgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, ...req.body, + slug: req.body.slug ? slugify(req.body.slug) : slugify(alphaNumericNanoId(12)), isTemporary: false, permissions: JSON.stringify(packRules(req.body.permissions)) }); @@ -78,11 +79,11 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F .min(1) .max(60) .trim() - .default(slugify(alphaNumericNanoId(12))) .refine((val) => val.toLowerCase() === val, "Must be lowercase") .refine((v) => slugify(v) === v, { message: "Slug must be a valid slug" }) + .optional() .describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug), permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions), temporaryMode: z @@ -111,6 +112,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F actorOrgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, ...req.body, + slug: req.body.slug ? slugify(req.body.slug) : slugify(alphaNumericNanoId(12)), isTemporary: true, permissions: JSON.stringify(packRules(req.body.permissions)) }); diff --git a/backend/src/ee/routes/v1/user-additional-privilege-router.ts b/backend/src/ee/routes/v1/user-additional-privilege-router.ts index 9b6bfb6fb..3db812c79 100644 --- a/backend/src/ee/routes/v1/user-additional-privilege-router.ts +++ b/backend/src/ee/routes/v1/user-additional-privilege-router.ts @@ -21,11 +21,11 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr .min(1) .max(60) .trim() - .default(slugify(alphaNumericNanoId(12))) .refine((v) => v.toLowerCase() === v, "Slug must be lowercase") .refine((v) => slugify(v) === v, { message: "Slug must be a valid slug" }) + .optional() .describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug), permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions) }), @@ -43,6 +43,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr actorOrgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, ...req.body, + slug: req.body.slug ? slugify(req.body.slug) : slugify(alphaNumericNanoId(12)), isTemporary: false, permissions: JSON.stringify(req.body.permissions) }); @@ -61,11 +62,11 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr .min(1) .max(60) .trim() - .default(`privilege-${slugify(alphaNumericNanoId(12))}`) .refine((v) => v.toLowerCase() === v, "Slug must be lowercase") .refine((v) => slugify(v) === v, { message: "Slug must be a valid slug" }) + .optional() .describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug), permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions), temporaryMode: z @@ -94,6 +95,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr actorOrgId: req.permission.orgId, actorAuthMethod: req.permission.authMethod, ...req.body, + slug: req.body.slug ? slugify(req.body.slug) : `privilege-${slugify(alphaNumericNanoId(12))}`, isTemporary: true, permissions: JSON.stringify(req.body.permissions) }); diff --git a/docs/documentation/platform/access-controls/access-requests.mdx b/docs/documentation/platform/access-controls/access-requests.mdx index e8a52b0e4..45c155ab4 100644 --- a/docs/documentation/platform/access-controls/access-requests.mdx +++ b/docs/documentation/platform/access-controls/access-requests.mdx @@ -3,11 +3,20 @@ title: "Access Requests" description: "Learn how to request access to sensitive resources in Infisical." --- -In certain situations, developers need to expand their access to certain new project or a sensitive environment. For those use cases, it is helpful to utilize Infisical's **Access Requests** functionality. +In certain situations, developers need to expand their access to a certain new project or a sensitive environment. For those use cases, it is helpful to utilize Infisical's **Access Requests** functionality. This functionality works in the following way: -1. A project administrator sets up a policy that assigns access managers to a certain sensitive folder or environment. -2. When a developer requests access to one of such sensitive resources, corresponding access managers get an email notification about it. -3. An access manager can approve or deny the access request as well as specify the duration of access in the case of approval. -4. As soon as the request is approved, developer is able to access the sought resources. +1. A project administrator sets up a policy that assigns access managers (also known as eligible approvers) to a certain sensitive folder or environment. +![Create Access Request Policy Modal](/images/platform/access-controls/create-access-request-policy.png) +![Access Request Policies](/images/platform/access-controls/access-request-policies.png) + +2. When a developer requests access to one of such sensitive resources, the request is visible in the dashboard, and the corresponding eligible approvers get an email notification about it. +![Access Request Create](/images/platform/access-controls/request-access.png) +![Access Request Dashboard](/images/platform/access-controls/access-requests-pending.png) + +3. An eligible approver can approve or reject the access request. +![Access Request Review](/images/platform/access-controls/review-access-request.png) + +4. As soon as the request is approved, developer is able to access the sought resources. +![Access Request Dashboard](/images/platform/access-controls/access-requests-completed.png) diff --git a/docs/images/platform/access-controls/access-request-policies.png b/docs/images/platform/access-controls/access-request-policies.png new file mode 100644 index 000000000..d7ea4829c Binary files /dev/null and b/docs/images/platform/access-controls/access-request-policies.png differ diff --git a/docs/images/platform/access-controls/access-requests-completed.png b/docs/images/platform/access-controls/access-requests-completed.png new file mode 100644 index 000000000..a2a167f78 Binary files /dev/null and b/docs/images/platform/access-controls/access-requests-completed.png differ diff --git a/docs/images/platform/access-controls/access-requests-pending.png b/docs/images/platform/access-controls/access-requests-pending.png new file mode 100644 index 000000000..d75f669e2 Binary files /dev/null and b/docs/images/platform/access-controls/access-requests-pending.png differ diff --git a/docs/images/platform/access-controls/create-access-request-policy.png b/docs/images/platform/access-controls/create-access-request-policy.png new file mode 100644 index 000000000..6593fd733 Binary files /dev/null and b/docs/images/platform/access-controls/create-access-request-policy.png differ diff --git a/docs/images/platform/access-controls/request-access.png b/docs/images/platform/access-controls/request-access.png new file mode 100644 index 000000000..63c76dbd5 Binary files /dev/null and b/docs/images/platform/access-controls/request-access.png differ diff --git a/docs/images/platform/access-controls/review-access-request.png b/docs/images/platform/access-controls/review-access-request.png new file mode 100644 index 000000000..8376f9691 Binary files /dev/null and b/docs/images/platform/access-controls/review-access-request.png differ diff --git a/docs/integrations/platforms/infisical-agent.mdx b/docs/integrations/platforms/infisical-agent.mdx index 3b0bd0bb1..1516ae045 100644 --- a/docs/integrations/platforms/infisical-agent.mdx +++ b/docs/integrations/platforms/infisical-agent.mdx @@ -52,7 +52,7 @@ While specifying an authentication method is mandatory to start the agent, confi | `sinks[].config.path` | The file path where the access token should be stored for each sink in the list. | | `templates[].source-path` | The path to the template file that should be used to render secrets. | | `templates[].destination-path` | The path where the rendered secrets from the source template will be saved to. | -| `templates[].config.polling-interval` | How frequently to check for secret changes. Default: `60s` (optional) | +| `templates[].config.polling-interval` | How frequently to check for secret changes. Default: `5 minutes` (optional) | | `templates[].config.execute.command` | The command to execute when secret change is detected (optional) | | `templates[].config.execute.timeout` | How long in seconds to wait for command to execute before timing out (optional) |