Merge main

This commit is contained in:
Tuan Dang
2024-04-04 12:24:28 -07:00
parent 175ce865aa
commit b3a9661755
10 changed files with 22 additions and 9 deletions
@@ -31,11 +31,11 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
.min(1) .min(1)
.max(60) .max(60)
.trim() .trim()
.default(slugify(alphaNumericNanoId(12)))
.refine((val) => val.toLowerCase() === val, "Must be lowercase") .refine((val) => val.toLowerCase() === val, "Must be lowercase")
.refine((v) => slugify(v) === v, { .refine((v) => slugify(v) === v, {
message: "Slug must be a valid slug" message: "Slug must be a valid slug"
}) })
.optional()
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug), .describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug),
permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions) permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions)
}), }),
@@ -53,6 +53,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
...req.body, ...req.body,
slug: req.body.slug ? slugify(req.body.slug) : slugify(alphaNumericNanoId(12)),
isTemporary: false, isTemporary: false,
permissions: JSON.stringify(packRules(req.body.permissions)) permissions: JSON.stringify(packRules(req.body.permissions))
}); });
@@ -78,11 +79,11 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
.min(1) .min(1)
.max(60) .max(60)
.trim() .trim()
.default(slugify(alphaNumericNanoId(12)))
.refine((val) => val.toLowerCase() === val, "Must be lowercase") .refine((val) => val.toLowerCase() === val, "Must be lowercase")
.refine((v) => slugify(v) === v, { .refine((v) => slugify(v) === v, {
message: "Slug must be a valid slug" message: "Slug must be a valid slug"
}) })
.optional()
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug), .describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug),
permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions), permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions),
temporaryMode: z temporaryMode: z
@@ -111,6 +112,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
...req.body, ...req.body,
slug: req.body.slug ? slugify(req.body.slug) : slugify(alphaNumericNanoId(12)),
isTemporary: true, isTemporary: true,
permissions: JSON.stringify(packRules(req.body.permissions)) permissions: JSON.stringify(packRules(req.body.permissions))
}); });
@@ -21,11 +21,11 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
.min(1) .min(1)
.max(60) .max(60)
.trim() .trim()
.default(slugify(alphaNumericNanoId(12)))
.refine((v) => v.toLowerCase() === v, "Slug must be lowercase") .refine((v) => v.toLowerCase() === v, "Slug must be lowercase")
.refine((v) => slugify(v) === v, { .refine((v) => slugify(v) === v, {
message: "Slug must be a valid slug" message: "Slug must be a valid slug"
}) })
.optional()
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug), .describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug),
permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions) permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions)
}), }),
@@ -43,6 +43,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
...req.body, ...req.body,
slug: req.body.slug ? slugify(req.body.slug) : slugify(alphaNumericNanoId(12)),
isTemporary: false, isTemporary: false,
permissions: JSON.stringify(req.body.permissions) permissions: JSON.stringify(req.body.permissions)
}); });
@@ -61,11 +62,11 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
.min(1) .min(1)
.max(60) .max(60)
.trim() .trim()
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
.refine((v) => v.toLowerCase() === v, "Slug must be lowercase") .refine((v) => v.toLowerCase() === v, "Slug must be lowercase")
.refine((v) => slugify(v) === v, { .refine((v) => slugify(v) === v, {
message: "Slug must be a valid slug" message: "Slug must be a valid slug"
}) })
.optional()
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug), .describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug),
permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions), permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions),
temporaryMode: z temporaryMode: z
@@ -94,6 +95,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
...req.body, ...req.body,
slug: req.body.slug ? slugify(req.body.slug) : `privilege-${slugify(alphaNumericNanoId(12))}`,
isTemporary: true, isTemporary: true,
permissions: JSON.stringify(req.body.permissions) permissions: JSON.stringify(req.body.permissions)
}); });
@@ -3,11 +3,20 @@ title: "Access Requests"
description: "Learn how to request access to sensitive resources in Infisical." description: "Learn how to request access to sensitive resources in Infisical."
--- ---
In certain situations, developers need to expand their access to certain new project or a sensitive environment. For those use cases, it is helpful to utilize Infisical's **Access Requests** functionality. In certain situations, developers need to expand their access to a certain new project or a sensitive environment. For those use cases, it is helpful to utilize Infisical's **Access Requests** functionality.
This functionality works in the following way: This functionality works in the following way:
1. A project administrator sets up a policy that assigns access managers to a certain sensitive folder or environment. 1. A project administrator sets up a policy that assigns access managers (also known as eligible approvers) to a certain sensitive folder or environment.
2. When a developer requests access to one of such sensitive resources, corresponding access managers get an email notification about it. ![Create Access Request Policy Modal](/images/platform/access-controls/create-access-request-policy.png)
3. An access manager can approve or deny the access request as well as specify the duration of access in the case of approval. ![Access Request Policies](/images/platform/access-controls/access-request-policies.png)
2. When a developer requests access to one of such sensitive resources, the request is visible in the dashboard, and the corresponding eligible approvers get an email notification about it.
![Access Request Create](/images/platform/access-controls/request-access.png)
![Access Request Dashboard](/images/platform/access-controls/access-requests-pending.png)
3. An eligible approver can approve or reject the access request.
![Access Request Review](/images/platform/access-controls/review-access-request.png)
4. As soon as the request is approved, developer is able to access the sought resources. 4. As soon as the request is approved, developer is able to access the sought resources.
![Access Request Dashboard](/images/platform/access-controls/access-requests-completed.png)
Binary file not shown.

After

Width:  |  Height:  |  Size: 79 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 108 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 132 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 96 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 123 KiB

@@ -52,7 +52,7 @@ While specifying an authentication method is mandatory to start the agent, confi
| `sinks[].config.path` | The file path where the access token should be stored for each sink in the list. | | `sinks[].config.path` | The file path where the access token should be stored for each sink in the list. |
| `templates[].source-path` | The path to the template file that should be used to render secrets. | | `templates[].source-path` | The path to the template file that should be used to render secrets. |
| `templates[].destination-path` | The path where the rendered secrets from the source template will be saved to. | | `templates[].destination-path` | The path where the rendered secrets from the source template will be saved to. |
| `templates[].config.polling-interval` | How frequently to check for secret changes. Default: `60s` (optional) | | `templates[].config.polling-interval` | How frequently to check for secret changes. Default: `5 minutes` (optional) |
| `templates[].config.execute.command` | The command to execute when secret change is detected (optional) | | `templates[].config.execute.command` | The command to execute when secret change is detected (optional) |
| `templates[].config.execute.timeout` | How long in seconds to wait for command to execute before timing out (optional) | | `templates[].config.execute.timeout` | How long in seconds to wait for command to execute before timing out (optional) |