mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #1781 from Infisical/feature/added-secret-expand-in-raw-secret-get
feat: added secret expand option in secrets get API
This commit is contained in:
@@ -272,6 +272,7 @@ export const SECRETS = {
|
|||||||
|
|
||||||
export const RAW_SECRETS = {
|
export const RAW_SECRETS = {
|
||||||
LIST: {
|
LIST: {
|
||||||
|
expand: "Whether or not to expand secret references",
|
||||||
recursive:
|
recursive:
|
||||||
"Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.",
|
"Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.",
|
||||||
workspaceId: "The ID of the project to list secrets from.",
|
workspaceId: "The ID of the project to list secrets from.",
|
||||||
|
|||||||
@@ -166,6 +166,11 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
workspaceSlug: z.string().trim().optional().describe(RAW_SECRETS.LIST.workspaceSlug),
|
workspaceSlug: z.string().trim().optional().describe(RAW_SECRETS.LIST.workspaceSlug),
|
||||||
environment: z.string().trim().optional().describe(RAW_SECRETS.LIST.environment),
|
environment: z.string().trim().optional().describe(RAW_SECRETS.LIST.environment),
|
||||||
secretPath: z.string().trim().default("/").transform(removeTrailingSlash).describe(RAW_SECRETS.LIST.secretPath),
|
secretPath: z.string().trim().default("/").transform(removeTrailingSlash).describe(RAW_SECRETS.LIST.secretPath),
|
||||||
|
expandSecretReferences: z
|
||||||
|
.enum(["true", "false"])
|
||||||
|
.default("false")
|
||||||
|
.transform((value) => value === "true")
|
||||||
|
.describe(RAW_SECRETS.LIST.expand),
|
||||||
recursive: z
|
recursive: z
|
||||||
.enum(["true", "false"])
|
.enum(["true", "false"])
|
||||||
.default("false")
|
.default("false")
|
||||||
@@ -233,6 +238,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId,
|
actorOrgId: req.permission.orgId,
|
||||||
environment,
|
environment,
|
||||||
|
expandSecretReferences: req.query.expandSecretReferences,
|
||||||
actorAuthMethod: req.permission.authMethod,
|
actorAuthMethod: req.permission.authMethod,
|
||||||
projectId: workspaceId,
|
projectId: workspaceId,
|
||||||
path: secretPath,
|
path: secretPath,
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ import {
|
|||||||
fnSecretBlindIndexCheck,
|
fnSecretBlindIndexCheck,
|
||||||
fnSecretBulkInsert,
|
fnSecretBulkInsert,
|
||||||
fnSecretBulkUpdate,
|
fnSecretBulkUpdate,
|
||||||
|
interpolateSecrets,
|
||||||
recursivelyGetSecretPaths
|
recursivelyGetSecretPaths
|
||||||
} from "./secret-fns";
|
} from "./secret-fns";
|
||||||
import { TSecretQueueFactory } from "./secret-queue";
|
import { TSecretQueueFactory } from "./secret-queue";
|
||||||
@@ -885,6 +886,7 @@ export const secretServiceFactory = ({
|
|||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
environment,
|
environment,
|
||||||
includeImports,
|
includeImports,
|
||||||
|
expandSecretReferences,
|
||||||
recursive
|
recursive
|
||||||
}: TGetSecretsRawDTO) => {
|
}: TGetSecretsRawDTO) => {
|
||||||
const botKey = await projectBotService.getBotKey(projectId);
|
const botKey = await projectBotService.getBotKey(projectId);
|
||||||
@@ -902,17 +904,66 @@ export const secretServiceFactory = ({
|
|||||||
recursive
|
recursive
|
||||||
});
|
});
|
||||||
|
|
||||||
return {
|
const decryptedSecrets = secrets.map((el) => decryptSecretRaw(el, botKey));
|
||||||
secrets: secrets.map((el) => decryptSecretRaw(el, botKey)),
|
const decryptedImports = (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({
|
||||||
imports: (imports || [])?.map(({ secrets: importedSecrets, ...el }) => ({
|
...el,
|
||||||
...el,
|
secrets: importedSecrets.map((sec) =>
|
||||||
secrets: importedSecrets.map((sec) =>
|
decryptSecretRaw(
|
||||||
decryptSecretRaw(
|
{ ...sec, environment: el.environment, workspace: projectId, secretPath: el.secretPath },
|
||||||
{ ...sec, environment: el.environment, workspace: projectId, secretPath: el.secretPath },
|
botKey
|
||||||
botKey
|
|
||||||
)
|
|
||||||
)
|
)
|
||||||
}))
|
)
|
||||||
|
}));
|
||||||
|
|
||||||
|
if (expandSecretReferences) {
|
||||||
|
const expandSecrets = interpolateSecrets({
|
||||||
|
folderDAL,
|
||||||
|
projectId,
|
||||||
|
secretDAL,
|
||||||
|
secretEncKey: botKey
|
||||||
|
});
|
||||||
|
|
||||||
|
const batchSecretsExpand = async (
|
||||||
|
secretBatch: {
|
||||||
|
secretKey: string;
|
||||||
|
secretValue: string;
|
||||||
|
secretComment?: string;
|
||||||
|
}[]
|
||||||
|
) => {
|
||||||
|
const secretRecord: Record<
|
||||||
|
string,
|
||||||
|
{
|
||||||
|
value: string;
|
||||||
|
comment?: string;
|
||||||
|
skipMultilineEncoding?: boolean;
|
||||||
|
}
|
||||||
|
> = {};
|
||||||
|
|
||||||
|
secretBatch.forEach((decryptedSecret) => {
|
||||||
|
secretRecord[decryptedSecret.secretKey] = {
|
||||||
|
value: decryptedSecret.secretValue,
|
||||||
|
comment: decryptedSecret.secretComment
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
await expandSecrets(secretRecord);
|
||||||
|
|
||||||
|
secretBatch.forEach((decryptedSecret, index) => {
|
||||||
|
// eslint-disable-next-line no-param-reassign
|
||||||
|
secretBatch[index].secretValue = secretRecord[decryptedSecret.secretKey].value;
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
|
// expand secrets
|
||||||
|
await batchSecretsExpand(decryptedSecrets);
|
||||||
|
|
||||||
|
// expand imports by batch
|
||||||
|
await Promise.all(decryptedImports.map((decryptedImport) => batchSecretsExpand(decryptedImport.secrets)));
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
secrets: decryptedSecrets,
|
||||||
|
imports: decryptedImports
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -138,6 +138,7 @@ export type TDeleteBulkSecretDTO = {
|
|||||||
} & TProjectPermission;
|
} & TProjectPermission;
|
||||||
|
|
||||||
export type TGetSecretsRawDTO = {
|
export type TGetSecretsRawDTO = {
|
||||||
|
expandSecretReferences?: boolean;
|
||||||
path: string;
|
path: string;
|
||||||
environment: string;
|
environment: string;
|
||||||
includeImports?: boolean;
|
includeImports?: boolean;
|
||||||
|
|||||||
Reference in New Issue
Block a user