mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 13:27:22 +00:00
Merge pull request #3246 from Infisical/disable-delete-sync-option
Feature: Disable Secret Deletion Sync Option
This commit is contained in:
@@ -1727,7 +1727,8 @@ export const SecretSyncs = {
|
|||||||
SYNC_OPTIONS: (destination: SecretSync) => {
|
SYNC_OPTIONS: (destination: SecretSync) => {
|
||||||
const destinationName = SECRET_SYNC_NAME_MAP[destination];
|
const destinationName = SECRET_SYNC_NAME_MAP[destination];
|
||||||
return {
|
return {
|
||||||
initialSyncBehavior: `Specify how Infisical should resolve the initial sync to the ${destinationName} destination.`
|
initialSyncBehavior: `Specify how Infisical should resolve the initial sync to the ${destinationName} destination.`,
|
||||||
|
disableSecretDeletion: `Enable this flag to prevent removal of secrets from the ${destinationName} destination when syncing.`
|
||||||
};
|
};
|
||||||
},
|
},
|
||||||
ADDITIONAL_SYNC_OPTIONS: {
|
ADDITIONAL_SYNC_OPTIONS: {
|
||||||
|
|||||||
@@ -382,6 +382,8 @@ export const AwsParameterStoreSyncFns = {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
const parametersToDelete: AWS.SSM.Parameter[] = [];
|
const parametersToDelete: AWS.SSM.Parameter[] = [];
|
||||||
|
|
||||||
for (const entry of Object.entries(awsParameterStoreSecretsRecord)) {
|
for (const entry of Object.entries(awsParameterStoreSecretsRecord)) {
|
||||||
|
|||||||
@@ -396,6 +396,8 @@ export const AwsSecretsManagerSyncFns = {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
for await (const secretKey of Object.keys(awsSecretsRecord)) {
|
for await (const secretKey of Object.keys(awsSecretsRecord)) {
|
||||||
if (!(secretKey in secretMap) || !secretMap[secretKey].value) {
|
if (!(secretKey in secretMap) || !secretMap[secretKey].value) {
|
||||||
try {
|
try {
|
||||||
|
|||||||
+2
@@ -136,6 +136,8 @@ export const azureAppConfigurationSyncFactory = ({
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (secretSync.syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
for await (const key of Object.keys(azureAppConfigSecrets)) {
|
for await (const key of Object.keys(azureAppConfigSecrets)) {
|
||||||
const azureSecret = azureAppConfigSecrets[key];
|
const azureSecret = azureAppConfigSecrets[key];
|
||||||
if (
|
if (
|
||||||
|
|||||||
@@ -189,6 +189,8 @@ export const azureKeyVaultSyncFactory = ({ kmsService, appConnectionDAL }: TAzur
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (secretSync.syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
for await (const deleteSecretKey of deleteSecrets.filter(
|
for await (const deleteSecretKey of deleteSecrets.filter(
|
||||||
(secret) => !setSecrets.find((setSecret) => setSecret.key === secret)
|
(secret) => !setSecrets.find((setSecret) => setSecret.key === secret)
|
||||||
)) {
|
)) {
|
||||||
|
|||||||
@@ -112,6 +112,8 @@ export const databricksSyncFactory = ({ kmsService, appConnectionDAL }: TDatabri
|
|||||||
accessToken
|
accessToken
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (secretSync.syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
for await (const secret of databricksSecretKeys) {
|
for await (const secret of databricksSecretKeys) {
|
||||||
if (!(secret.key in secretMap)) {
|
if (!(secret.key in secretMap)) {
|
||||||
await deleteDatabricksSecrets({
|
await deleteDatabricksSecrets({
|
||||||
|
|||||||
@@ -155,6 +155,9 @@ export const GcpSyncFns = {
|
|||||||
for await (const key of Object.keys(gcpSecrets)) {
|
for await (const key of Object.keys(gcpSecrets)) {
|
||||||
try {
|
try {
|
||||||
if (!(key in secretMap) || !secretMap[key].value) {
|
if (!(key in secretMap) || !secretMap[key].value) {
|
||||||
|
// eslint-disable-next-line no-continue
|
||||||
|
if (secretSync.syncOptions.disableSecretDeletion) continue;
|
||||||
|
|
||||||
// case: delete secret
|
// case: delete secret
|
||||||
await request.delete(
|
await request.delete(
|
||||||
`${IntegrationUrls.GCP_SECRET_MANAGER_URL}/v1/projects/${destinationConfig.projectId}/secrets/${key}`,
|
`${IntegrationUrls.GCP_SECRET_MANAGER_URL}/v1/projects/${destinationConfig.projectId}/secrets/${key}`,
|
||||||
|
|||||||
@@ -192,12 +192,6 @@ export const GithubSyncFns = {
|
|||||||
|
|
||||||
const publicKey = await getPublicKey(client, secretSync);
|
const publicKey = await getPublicKey(client, secretSync);
|
||||||
|
|
||||||
for await (const encryptedSecret of encryptedSecrets) {
|
|
||||||
if (!(encryptedSecret.name in secretMap)) {
|
|
||||||
await deleteSecret(client, secretSync, encryptedSecret);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
await sodium.ready.then(async () => {
|
await sodium.ready.then(async () => {
|
||||||
for await (const key of Object.keys(secretMap)) {
|
for await (const key of Object.keys(secretMap)) {
|
||||||
// convert secret & base64 key to Uint8Array.
|
// convert secret & base64 key to Uint8Array.
|
||||||
@@ -224,6 +218,14 @@ export const GithubSyncFns = {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (secretSync.syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
|
for await (const encryptedSecret of encryptedSecrets) {
|
||||||
|
if (!(encryptedSecret.name in secretMap)) {
|
||||||
|
await deleteSecret(client, secretSync, encryptedSecret);
|
||||||
|
}
|
||||||
|
}
|
||||||
},
|
},
|
||||||
getSecrets: async (secretSync: TGitHubSyncWithCredentials) => {
|
getSecrets: async (secretSync: TGitHubSyncWithCredentials) => {
|
||||||
throw new Error(`${SECRET_SYNC_NAME_MAP[secretSync.destination]} does not support importing secrets.`);
|
throw new Error(`${SECRET_SYNC_NAME_MAP[secretSync.destination]} does not support importing secrets.`);
|
||||||
|
|||||||
@@ -196,6 +196,8 @@ export const HumanitecSyncFns = {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (secretSync.syncOptions.disableSecretDeletion) return;
|
||||||
|
|
||||||
for await (const humanitecSecret of humanitecSecrets) {
|
for await (const humanitecSecret of humanitecSecrets) {
|
||||||
if (!secretMap[humanitecSecret.key]) {
|
if (!secretMap[humanitecSecret.key]) {
|
||||||
await deleteSecret(secretSync, humanitecSecret);
|
await deleteSecret(secretSync, humanitecSecret);
|
||||||
|
|||||||
@@ -23,7 +23,8 @@ const BaseSyncOptionsSchema = <T extends AnyZodObject | undefined = undefined>({
|
|||||||
initialSyncBehavior: (canImportSecrets
|
initialSyncBehavior: (canImportSecrets
|
||||||
? z.nativeEnum(SecretSyncInitialSyncBehavior)
|
? z.nativeEnum(SecretSyncInitialSyncBehavior)
|
||||||
: z.literal(SecretSyncInitialSyncBehavior.OverwriteDestination)
|
: z.literal(SecretSyncInitialSyncBehavior.OverwriteDestination)
|
||||||
).describe(SecretSyncs.SYNC_OPTIONS(destination).initialSyncBehavior)
|
).describe(SecretSyncs.SYNC_OPTIONS(destination).initialSyncBehavior),
|
||||||
|
disableSecretDeletion: z.boolean().optional().describe(SecretSyncs.SYNC_OPTIONS(destination).disableSecretDeletion)
|
||||||
});
|
});
|
||||||
|
|
||||||
const schema = merge ? baseSchema.merge(merge) : baseSchema;
|
const schema = merge ? baseSchema.merge(merge) : baseSchema;
|
||||||
|
|||||||
@@ -43,8 +43,11 @@ description: "Learn how to configure an AWS Parameter Store Sync for Infisical."
|
|||||||
- **KMS Key**: The AWS KMS key ID or alias to encrypt parameters with.
|
- **KMS Key**: The AWS KMS key ID or alias to encrypt parameters with.
|
||||||
- **Tags**: Optional resource tags to add to parameters synced by Infisical.
|
- **Tags**: Optional resource tags to add to parameters synced by Infisical.
|
||||||
- **Sync Secret Metadata as Resource Tags**: If enabled, metadata attached to secrets will be added as resource tags to parameters synced by Infisical.
|
- **Sync Secret Metadata as Resource Tags**: If enabled, metadata attached to secrets will be added as resource tags to parameters synced by Infisical.
|
||||||
<Note>Manually configured tags from the **Tags** field will take precedence over secret metadata when tag keys conflict.</Note>
|
<Note>
|
||||||
|
Manually configured tags from the **Tags** field will take precedence over secret metadata when tag keys conflict.
|
||||||
|
</Note>
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your Parameter Store Sync, then click **Next**.
|
6. Configure the **Details** of your Parameter Store Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -46,7 +46,11 @@ description: "Learn how to configure an AWS Secrets Manager Sync for Infisical."
|
|||||||
- **KMS Key**: The AWS KMS key ID or alias to encrypt secrets with.
|
- **KMS Key**: The AWS KMS key ID or alias to encrypt secrets with.
|
||||||
- **Tags**: Optional tags to add to secrets synced by Infisical.
|
- **Tags**: Optional tags to add to secrets synced by Infisical.
|
||||||
- **Sync Secret Metadata as Tags**: If enabled, metadata attached to secrets will be added as tags to secrets synced by Infisical.
|
- **Sync Secret Metadata as Tags**: If enabled, metadata attached to secrets will be added as tags to secrets synced by Infisical.
|
||||||
|
<Note>
|
||||||
|
Manually configured tags from the **Tags** field will take precedence over secret metadata when tag keys conflict.
|
||||||
|
</Note>
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your Secrets Manager Sync, then click **Next**.
|
6. Configure the **Details** of your Secrets Manager Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -6,7 +6,7 @@ description: "Learn how to configure an Azure App Configuration Sync for Infisic
|
|||||||
**Prerequisites:**
|
**Prerequisites:**
|
||||||
|
|
||||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||||
- Create a [Azure Connection](/integrations/app-connections/azure), configured for Azure App Configuration.
|
- Create an [Azure App Configuration Connection](/integrations/app-connections/azure-app-configuration)
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
The Azure App Configuration Secret Sync requires the following permissions to be set on the user / service principal
|
The Azure App Configuration Secret Sync requires the following permissions to be set on the user / service principal
|
||||||
@@ -50,6 +50,7 @@ description: "Learn how to configure an Azure App Configuration Sync for Infisic
|
|||||||
- **Import Secrets (Prioritize Azure App Configuration)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Secrets Manager over Infisical when keys conflict.
|
- **Import Secrets (Prioritize Azure App Configuration)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Secrets Manager over Infisical when keys conflict.
|
||||||
|
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your Azure App Configuration Sync, then click **Next**.
|
6. Configure the **Details** of your Azure App Configuration Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -6,7 +6,7 @@ description: "Learn how to configure a Azure Key Vault Sync for Infisical."
|
|||||||
**Prerequisites:**
|
**Prerequisites:**
|
||||||
|
|
||||||
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||||
- Create a [Azure Connection](/integrations/app-connections/azure), configured for Azure Key Vault.
|
- Create an [Azure Key Vault Connection](/integrations/app-connections/azure-key-vault)
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
The Azure Key Vault Secret Sync requires the following secrets permissions to be set on the user / service principal
|
The Azure Key Vault Secret Sync requires the following secrets permissions to be set on the user / service principal
|
||||||
@@ -52,6 +52,7 @@ description: "Learn how to configure a Azure Key Vault Sync for Infisical."
|
|||||||
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over Secrets Manager when keys conflict.
|
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over Secrets Manager when keys conflict.
|
||||||
- **Import Secrets (Prioritize Azure Key Vault)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Secrets Manager over Infisical when keys conflict.
|
- **Import Secrets (Prioritize Azure Key Vault)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Secrets Manager over Infisical when keys conflict.
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your Azure Key Vault Sync, then click **Next**.
|
6. Configure the **Details** of your Azure Key Vault Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -47,6 +47,7 @@ description: "Learn how to configure a Databricks Sync for Infisical."
|
|||||||
Databricks does not support importing secrets.
|
Databricks does not support importing secrets.
|
||||||
</Note>
|
</Note>
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your Databricks Sync, then click **Next**.
|
6. Configure the **Details** of your Databricks Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -43,6 +43,7 @@ description: "Learn how to configure a GCP Secret Manager Sync for Infisical."
|
|||||||
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over GCP Secret Manager when keys conflict.
|
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over GCP Secret Manager when keys conflict.
|
||||||
- **Import Secrets (Prioritize GCP Secret Manager)**: Imports secrets from the destination endpoint before syncing, prioritizing values from GCP Secret Manager over Infisical when keys conflict.
|
- **Import Secrets (Prioritize GCP Secret Manager)**: Imports secrets from the destination endpoint before syncing, prioritizing values from GCP Secret Manager over Infisical when keys conflict.
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your GCP Secret Manager Sync, then click **Next**.
|
6. Configure the **Details** of your GCP Secret Manager Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -63,6 +63,7 @@ description: "Learn how to configure a GitHub Sync for Infisical."
|
|||||||
GitHub does not support importing secrets.
|
GitHub does not support importing secrets.
|
||||||
</Note>
|
</Note>
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your GitHub Sync, then click **Next**.
|
6. Configure the **Details** of your GitHub Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
@@ -56,6 +56,7 @@ description: "Learn how to configure a Humanitec Sync for Infisical."
|
|||||||
Humanitec does not support importing secrets.
|
Humanitec does not support importing secrets.
|
||||||
</Note>
|
</Note>
|
||||||
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
6. Configure the **Details** of your Humanitec Sync, then click **Next**.
|
6. Configure the **Details** of your Humanitec Sync, then click **Next**.
|
||||||

|

|
||||||
|
|||||||
+40
-2
@@ -1,9 +1,9 @@
|
|||||||
import { ReactNode } from "react";
|
import { ReactNode } from "react";
|
||||||
import { Controller, useFormContext } from "react-hook-form";
|
import { Controller, useFormContext } from "react-hook-form";
|
||||||
import { faTriangleExclamation } from "@fortawesome/free-solid-svg-icons";
|
import { faQuestionCircle, faTriangleExclamation } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
import { FormControl, Select, SelectItem } from "@app/components/v2";
|
import { FormControl, Select, SelectItem, Switch, Tooltip } from "@app/components/v2";
|
||||||
import { SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP, SECRET_SYNC_MAP } from "@app/helpers/secretSyncs";
|
import { SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP, SECRET_SYNC_MAP } from "@app/helpers/secretSyncs";
|
||||||
import { SecretSync, useSecretSyncOption } from "@app/hooks/api/secretSyncs";
|
import { SecretSync, useSecretSyncOption } from "@app/hooks/api/secretSyncs";
|
||||||
|
|
||||||
@@ -116,6 +116,44 @@ export const SecretSyncOptionsFields = ({ hideInitialSync }: Props) => {
|
|||||||
</>
|
</>
|
||||||
)}
|
)}
|
||||||
{AdditionalSyncOptionsFieldsComponent}
|
{AdditionalSyncOptionsFieldsComponent}
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="syncOptions.disableSecretDeletion"
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => {
|
||||||
|
return (
|
||||||
|
<FormControl isError={Boolean(error)} errorText={error?.message}>
|
||||||
|
<Switch
|
||||||
|
className="bg-mineshaft-400/80 shadow-inner data-[state=checked]:bg-green/80"
|
||||||
|
id="auto-sync-enabled"
|
||||||
|
thumbClassName="bg-mineshaft-800"
|
||||||
|
onCheckedChange={onChange}
|
||||||
|
isChecked={value}
|
||||||
|
>
|
||||||
|
<p className="w-[11rem]">
|
||||||
|
Disable Secret Deletion{" "}
|
||||||
|
<Tooltip
|
||||||
|
className="max-w-md"
|
||||||
|
content={
|
||||||
|
<>
|
||||||
|
<p>
|
||||||
|
When enabled, Infisical will <span className="font-semibold">not</span>{" "}
|
||||||
|
remove secrets from the destination during a sync.
|
||||||
|
</p>
|
||||||
|
<p className="mt-4">
|
||||||
|
Enable this option if you intend to manage some secrets manually outside
|
||||||
|
of Infisical.
|
||||||
|
</p>
|
||||||
|
</>
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={faQuestionCircle} size="sm" className="ml-1" />
|
||||||
|
</Tooltip>
|
||||||
|
</p>
|
||||||
|
</Switch>
|
||||||
|
</FormControl>
|
||||||
|
);
|
||||||
|
}}
|
||||||
|
/>
|
||||||
{/* <Controller
|
{/* <Controller
|
||||||
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
<FormControl
|
<FormControl
|
||||||
|
|||||||
+6
@@ -36,6 +36,7 @@ export const SecretSyncReviewFields = () => {
|
|||||||
secretPath,
|
secretPath,
|
||||||
syncOptions: {
|
syncOptions: {
|
||||||
// appendSuffix, prependPrefix,
|
// appendSuffix, prependPrefix,
|
||||||
|
disableSecretDeletion,
|
||||||
initialSyncBehavior
|
initialSyncBehavior
|
||||||
},
|
},
|
||||||
destination,
|
destination,
|
||||||
@@ -111,6 +112,11 @@ export const SecretSyncReviewFields = () => {
|
|||||||
{/* <SecretSyncLabel label="Prepend Prefix">{prependPrefix}</SecretSyncLabel>
|
{/* <SecretSyncLabel label="Prepend Prefix">{prependPrefix}</SecretSyncLabel>
|
||||||
<SecretSyncLabel label="Append Suffix">{appendSuffix}</SecretSyncLabel> */}
|
<SecretSyncLabel label="Append Suffix">{appendSuffix}</SecretSyncLabel> */}
|
||||||
{AdditionalSyncOptionsFieldsComponent}
|
{AdditionalSyncOptionsFieldsComponent}
|
||||||
|
{disableSecretDeletion && (
|
||||||
|
<SecretSyncLabel label="Secret Deletion">
|
||||||
|
<Badge variant="primary">Disabled</Badge>
|
||||||
|
</SecretSyncLabel>
|
||||||
|
)}
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div className="flex flex-col gap-3">
|
<div className="flex flex-col gap-3">
|
||||||
|
|||||||
@@ -7,7 +7,8 @@ export const BaseSecretSyncSchema = <T extends AnyZodObject | undefined = undefi
|
|||||||
additionalSyncOptions?: T
|
additionalSyncOptions?: T
|
||||||
) => {
|
) => {
|
||||||
const baseSyncOptionsSchema = z.object({
|
const baseSyncOptionsSchema = z.object({
|
||||||
initialSyncBehavior: z.nativeEnum(SecretSyncInitialSyncBehavior)
|
initialSyncBehavior: z.nativeEnum(SecretSyncInitialSyncBehavior),
|
||||||
|
disableSecretDeletion: z.boolean().optional().default(false)
|
||||||
// scott: removed temporarily for evaluation of template formatting
|
// scott: removed temporarily for evaluation of template formatting
|
||||||
// prependPrefix: z
|
// prependPrefix: z
|
||||||
// .string()
|
// .string()
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import { SecretSyncInitialSyncBehavior, SecretSyncStatus } from "@app/hooks/api/
|
|||||||
|
|
||||||
export type RootSyncOptions = {
|
export type RootSyncOptions = {
|
||||||
initialSyncBehavior: SecretSyncInitialSyncBehavior;
|
initialSyncBehavior: SecretSyncInitialSyncBehavior;
|
||||||
|
disableSecretDeletion?: boolean;
|
||||||
// prependPrefix?: string;
|
// prependPrefix?: string;
|
||||||
// appendSuffix?: string;
|
// appendSuffix?: string;
|
||||||
};
|
};
|
||||||
|
|||||||
+24
-20
@@ -4,7 +4,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
|||||||
|
|
||||||
import { ProjectPermissionCan } from "@app/components/permissions";
|
import { ProjectPermissionCan } from "@app/components/permissions";
|
||||||
import { SecretSyncLabel } from "@app/components/secret-syncs";
|
import { SecretSyncLabel } from "@app/components/secret-syncs";
|
||||||
import { IconButton } from "@app/components/v2";
|
import { Badge, IconButton } from "@app/components/v2";
|
||||||
import { ProjectPermissionSub } from "@app/context";
|
import { ProjectPermissionSub } from "@app/context";
|
||||||
import { ProjectPermissionSecretSyncActions } from "@app/context/ProjectPermissionContext/types";
|
import { ProjectPermissionSecretSyncActions } from "@app/context/ProjectPermissionContext/types";
|
||||||
import { SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP } from "@app/helpers/secretSyncs";
|
import { SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP } from "@app/helpers/secretSyncs";
|
||||||
@@ -24,7 +24,8 @@ export const SecretSyncOptionsSection = ({ secretSync, onEditOptions }: Props) =
|
|||||||
syncOptions: {
|
syncOptions: {
|
||||||
// appendSuffix,
|
// appendSuffix,
|
||||||
// prependPrefix,
|
// prependPrefix,
|
||||||
initialSyncBehavior
|
initialSyncBehavior,
|
||||||
|
disableSecretDeletion
|
||||||
}
|
}
|
||||||
} = secretSync;
|
} = secretSync;
|
||||||
|
|
||||||
@@ -58,24 +59,22 @@ export const SecretSyncOptionsSection = ({ secretSync, onEditOptions }: Props) =
|
|||||||
<div className="flex w-full flex-col gap-3 rounded-lg border border-mineshaft-600 bg-mineshaft-900 px-4 py-3">
|
<div className="flex w-full flex-col gap-3 rounded-lg border border-mineshaft-600 bg-mineshaft-900 px-4 py-3">
|
||||||
<div className="flex items-center justify-between border-b border-mineshaft-400 pb-2">
|
<div className="flex items-center justify-between border-b border-mineshaft-400 pb-2">
|
||||||
<h3 className="font-semibold text-mineshaft-100">Sync Options</h3>
|
<h3 className="font-semibold text-mineshaft-100">Sync Options</h3>
|
||||||
{AdditionalSyncOptionsComponent && (
|
<ProjectPermissionCan
|
||||||
<ProjectPermissionCan
|
I={ProjectPermissionSecretSyncActions.Edit}
|
||||||
I={ProjectPermissionSecretSyncActions.Edit}
|
a={ProjectPermissionSub.SecretSyncs}
|
||||||
a={ProjectPermissionSub.SecretSyncs}
|
>
|
||||||
>
|
{(isAllowed) => (
|
||||||
{(isAllowed) => (
|
<IconButton
|
||||||
<IconButton
|
variant="plain"
|
||||||
variant="plain"
|
colorSchema="secondary"
|
||||||
colorSchema="secondary"
|
isDisabled={!isAllowed}
|
||||||
isDisabled={!isAllowed}
|
ariaLabel="Edit sync options"
|
||||||
ariaLabel="Edit sync options"
|
onClick={onEditOptions}
|
||||||
onClick={onEditOptions}
|
>
|
||||||
>
|
<FontAwesomeIcon icon={faEdit} />
|
||||||
<FontAwesomeIcon icon={faEdit} />
|
</IconButton>
|
||||||
</IconButton>
|
)}
|
||||||
)}
|
</ProjectPermissionCan>
|
||||||
</ProjectPermissionCan>
|
|
||||||
)}
|
|
||||||
</div>
|
</div>
|
||||||
<div>
|
<div>
|
||||||
<div className="space-y-3">
|
<div className="space-y-3">
|
||||||
@@ -85,6 +84,11 @@ export const SecretSyncOptionsSection = ({ secretSync, onEditOptions }: Props) =
|
|||||||
{/* <SecretSyncLabel label="Prefix">{prependPrefix}</SecretSyncLabel>
|
{/* <SecretSyncLabel label="Prefix">{prependPrefix}</SecretSyncLabel>
|
||||||
<SecretSyncLabel label="Suffix">{appendSuffix}</SecretSyncLabel> */}
|
<SecretSyncLabel label="Suffix">{appendSuffix}</SecretSyncLabel> */}
|
||||||
{AdditionalSyncOptionsComponent}
|
{AdditionalSyncOptionsComponent}
|
||||||
|
{disableSecretDeletion && (
|
||||||
|
<SecretSyncLabel label="Secret Deletion">
|
||||||
|
<Badge variant="primary">Disabled</Badge>
|
||||||
|
</SecretSyncLabel>
|
||||||
|
)}
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
Reference in New Issue
Block a user