Merge pull request #1781 from Infisical/feature/added-secret-expand-in-raw-secret-get

feat: added secret expand option in secrets get API
This commit is contained in:
Maidul Islam
2024-05-04 22:09:12 -04:00
committed by GitHub
4 changed files with 69 additions and 10 deletions

View File

@@ -272,6 +272,7 @@ export const SECRETS = {
export const RAW_SECRETS = { export const RAW_SECRETS = {
LIST: { LIST: {
expand: "Whether or not to expand secret references",
recursive: recursive:
"Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.", "Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.",
workspaceId: "The ID of the project to list secrets from.", workspaceId: "The ID of the project to list secrets from.",

View File

@@ -166,6 +166,11 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
workspaceSlug: z.string().trim().optional().describe(RAW_SECRETS.LIST.workspaceSlug), workspaceSlug: z.string().trim().optional().describe(RAW_SECRETS.LIST.workspaceSlug),
environment: z.string().trim().optional().describe(RAW_SECRETS.LIST.environment), environment: z.string().trim().optional().describe(RAW_SECRETS.LIST.environment),
secretPath: z.string().trim().default("/").transform(removeTrailingSlash).describe(RAW_SECRETS.LIST.secretPath), secretPath: z.string().trim().default("/").transform(removeTrailingSlash).describe(RAW_SECRETS.LIST.secretPath),
expandSecretReferences: z
.enum(["true", "false"])
.default("false")
.transform((value) => value === "true")
.describe(RAW_SECRETS.LIST.expand),
recursive: z recursive: z
.enum(["true", "false"]) .enum(["true", "false"])
.default("false") .default("false")
@@ -233,6 +238,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
actor: req.permission.type, actor: req.permission.type,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
environment, environment,
expandSecretReferences: req.query.expandSecretReferences,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
projectId: workspaceId, projectId: workspaceId,
path: secretPath, path: secretPath,

View File

@@ -27,6 +27,7 @@ import {
fnSecretBlindIndexCheck, fnSecretBlindIndexCheck,
fnSecretBulkInsert, fnSecretBulkInsert,
fnSecretBulkUpdate, fnSecretBulkUpdate,
interpolateSecrets,
recursivelyGetSecretPaths recursivelyGetSecretPaths
} from "./secret-fns"; } from "./secret-fns";
import { TSecretQueueFactory } from "./secret-queue"; import { TSecretQueueFactory } from "./secret-queue";
@@ -885,6 +886,7 @@ export const secretServiceFactory = ({
actorAuthMethod, actorAuthMethod,
environment, environment,
includeImports, includeImports,
expandSecretReferences,
recursive recursive
}: TGetSecretsRawDTO) => { }: TGetSecretsRawDTO) => {
const botKey = await projectBotService.getBotKey(projectId); const botKey = await projectBotService.getBotKey(projectId);
@@ -902,17 +904,66 @@ export const secretServiceFactory = ({
recursive recursive
}); });
return { const decryptedSecrets = secrets.map((el) => decryptSecretRaw(el, botKey));
secrets: secrets.map((el) => decryptSecretRaw(el, botKey)), const decryptedImports = (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({
imports: (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({ ...el,
...el, secrets: importedSecrets.map((sec) =>
secrets: importedSecrets.map((sec) => decryptSecretRaw(
decryptSecretRaw( { ...sec, environment: el.environment, workspace: projectId, secretPath: el.secretPath },
{ ...sec, environment: el.environment, workspace: projectId, secretPath: el.secretPath }, botKey
botKey
)
) )
})) )
}));
if (expandSecretReferences) {
const expandSecrets = interpolateSecrets({
folderDAL,
projectId,
secretDAL,
secretEncKey: botKey
});
const batchSecretsExpand = async (
secretBatch: {
secretKey: string;
secretValue: string;
secretComment?: string;
}[]
) => {
const secretRecord: Record<
string,
{
value: string;
comment?: string;
skipMultilineEncoding?: boolean;
}
> = {};
secretBatch.forEach((decryptedSecret) => {
secretRecord[decryptedSecret.secretKey] = {
value: decryptedSecret.secretValue,
comment: decryptedSecret.secretComment
};
});
await expandSecrets(secretRecord);
secretBatch.forEach((decryptedSecret, index) => {
// eslint-disable-next-line no-param-reassign
secretBatch[index].secretValue = secretRecord[decryptedSecret.secretKey].value;
});
};
// expand secrets
await batchSecretsExpand(decryptedSecrets);
// expand imports by batch
await Promise.all(decryptedImports.map((decryptedImport) => batchSecretsExpand(decryptedImport.secrets)));
}
return {
secrets: decryptedSecrets,
imports: decryptedImports
}; };
}; };

View File

@@ -138,6 +138,7 @@ export type TDeleteBulkSecretDTO = {
} & TProjectPermission; } & TProjectPermission;
export type TGetSecretsRawDTO = { export type TGetSecretsRawDTO = {
expandSecretReferences?: boolean;
path: string; path: string;
environment: string; environment: string;
includeImports?: boolean; includeImports?: boolean;