mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 19:26:19 +00:00
Correct logging references
This commit is contained in:
@@ -13,6 +13,7 @@ import {
|
|||||||
import { ValidationError } from '../../utils/errors';
|
import { ValidationError } from '../../utils/errors';
|
||||||
import { EESecretService, EELogService } from '../../ee/services';
|
import { EESecretService, EELogService } from '../../ee/services';
|
||||||
import { postHogClient } from '../../services';
|
import { postHogClient } from '../../services';
|
||||||
|
import { BadRequestError } from '../../utils/errors';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create secret(s) for workspace with id [workspaceId] and environment [environment]
|
* Create secret(s) for workspace with id [workspaceId] and environment [environment]
|
||||||
@@ -124,7 +125,7 @@ export const createSecrets = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
if (postHogClient) {
|
if (postHogClient) {
|
||||||
postHogClient.capture({
|
postHogClient.capture({
|
||||||
event: 'secrets deleted',
|
event: 'secrets added',
|
||||||
distinctId: req.user.email,
|
distinctId: req.user.email,
|
||||||
properties: {
|
properties: {
|
||||||
numberOfSecrets: toAdd.length,
|
numberOfSecrets: toAdd.length,
|
||||||
@@ -190,6 +191,20 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
channel,
|
channel,
|
||||||
ipAddress: req.ip
|
ipAddress: req.ip
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (postHogClient) {
|
||||||
|
postHogClient.capture({
|
||||||
|
event: 'secrets deleted',
|
||||||
|
distinctId: req.user.email,
|
||||||
|
properties: {
|
||||||
|
numberOfSecrets: secrets.length,
|
||||||
|
environment,
|
||||||
|
workspaceId,
|
||||||
|
channel,
|
||||||
|
userAgent: req.headers?.['user-agent']
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
secrets
|
secrets
|
||||||
@@ -197,13 +212,12 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Update secret(s) in workspace with id [workspaceId] and environment [environment]
|
* Update secret(s)
|
||||||
* @param req
|
* @param req
|
||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
export const updateSecrets = async (req: Request, res: Response) => {
|
export const updateSecrets = async (req: Request, res: Response) => {
|
||||||
const channel = req.headers?.['user-agent']?.toLowerCase().includes('mozilla') ? 'web' : 'cli';
|
const channel = req.headers?.['user-agent']?.toLowerCase().includes('mozilla') ? 'web' : 'cli';
|
||||||
const { workspaceId, environment } = req.body;
|
|
||||||
|
|
||||||
// TODO: move type
|
// TODO: move type
|
||||||
interface PatchSecret {
|
interface PatchSecret {
|
||||||
@@ -257,7 +271,7 @@ export const updateSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
const b = await Secret.bulkWrite(ops);
|
await Secret.bulkWrite(ops);
|
||||||
|
|
||||||
let newSecretsObj: { [key: string]: PatchSecret } = {};
|
let newSecretsObj: { [key: string]: PatchSecret } = {};
|
||||||
req.body.secrets.forEach((secret: PatchSecret) => {
|
req.body.secrets.forEach((secret: PatchSecret) => {
|
||||||
@@ -320,7 +334,7 @@ export const updateSecrets = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
Object.keys(workspaceSecretObj).forEach(async (key) => {
|
Object.keys(workspaceSecretObj).forEach(async (key) => {
|
||||||
const updateAction = await EELogService.createActionSecret({
|
const updateAction = await EELogService.createActionSecret({
|
||||||
name: ACTION_DELETE_SECRETS,
|
name: ACTION_UPDATE_SECRETS,
|
||||||
userId: req.user._id.toString(),
|
userId: req.user._id.toString(),
|
||||||
workspaceId: key,
|
workspaceId: key,
|
||||||
secretIds: workspaceSecretObj[key].map((secret: ISecret) => secret._id)
|
secretIds: workspaceSecretObj[key].map((secret: ISecret) => secret._id)
|
||||||
@@ -342,7 +356,7 @@ export const updateSecrets = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
if (postHogClient) {
|
if (postHogClient) {
|
||||||
postHogClient.capture({
|
postHogClient.capture({
|
||||||
event: 'secrets deleted',
|
event: 'secrets modified',
|
||||||
distinctId: req.user.email,
|
distinctId: req.user.email,
|
||||||
properties: {
|
properties: {
|
||||||
numberOfSecrets: workspaceSecretObj[key].length,
|
numberOfSecrets: workspaceSecretObj[key].length,
|
||||||
@@ -354,41 +368,6 @@ export const updateSecrets = async (req: Request, res: Response) => {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
const updateAction = await EELogService.createActionSecret({
|
|
||||||
name: ACTION_UPDATE_SECRETS,
|
|
||||||
userId: req.user._id.toString(),
|
|
||||||
workspaceId,
|
|
||||||
secretIds: req.secrets.map((secret: ISecret) => secret._id)
|
|
||||||
});
|
|
||||||
|
|
||||||
// (EE) create (audit) log
|
|
||||||
updateAction && await EELogService.createLog({
|
|
||||||
userId: req.user._id.toString(),
|
|
||||||
workspaceId,
|
|
||||||
actions: [updateAction],
|
|
||||||
channel,
|
|
||||||
ipAddress: req.ip
|
|
||||||
});
|
|
||||||
|
|
||||||
// (EE) take a secret snapshot
|
|
||||||
await EESecretService.takeSecretSnapshot({
|
|
||||||
workspaceId
|
|
||||||
});
|
|
||||||
|
|
||||||
if (postHogClient) {
|
|
||||||
postHogClient.capture({
|
|
||||||
event: 'secrets modified',
|
|
||||||
distinctId: req.user.email,
|
|
||||||
properties: {
|
|
||||||
numberOfSecrets: req.secrets.length,
|
|
||||||
environment,
|
|
||||||
workspaceId,
|
|
||||||
channel: req.headers?.['user-agent']?.toLowerCase().includes('mozilla') ? 'web' : 'cli',
|
|
||||||
userAgent: req.headers?.['user-agent']
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
secrets: await Secret.find({
|
secrets: await Secret.find({
|
||||||
@@ -400,7 +379,7 @@ export const updateSecrets = async (req: Request, res: Response) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Delete secret(s) in workspace with id [workspaceId] and environment [environment]
|
* Delete secret(s) with id [workspaceId] and environment [environment]
|
||||||
* @param req
|
* @param req
|
||||||
* @param res
|
* @param res
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -8,15 +8,6 @@ import {
|
|||||||
ENV_PROD
|
ENV_PROD
|
||||||
} from '../../variables';
|
} from '../../variables';
|
||||||
|
|
||||||
/**
|
|
||||||
* TODO:
|
|
||||||
* 1. Modify SecretVersion to also contain XX
|
|
||||||
* - type
|
|
||||||
* - user
|
|
||||||
* - environment
|
|
||||||
* 2. Modify SecretSnapshot to point to arrays of SecretVersion
|
|
||||||
*/
|
|
||||||
|
|
||||||
export interface ISecretVersion {
|
export interface ISecretVersion {
|
||||||
_id?: Types.ObjectId;
|
_id?: Types.ObjectId;
|
||||||
secret: Types.ObjectId;
|
secret: Types.ObjectId;
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ router.post(
|
|||||||
!secret.secretValueIV ||
|
!secret.secretValueIV ||
|
||||||
!secret.secretValueTag
|
!secret.secretValueTag
|
||||||
) {
|
) {
|
||||||
throw new Error('secrets array must contain objects that conform to the Secret interface');
|
throw new Error('secrets array must contain objects that have required secret properties');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else if (typeof value === 'object') {
|
} else if (typeof value === 'object') {
|
||||||
@@ -51,7 +51,7 @@ router.post(
|
|||||||
!value.secretValueIV ||
|
!value.secretValueIV ||
|
||||||
!value.secretValueTag
|
!value.secretValueTag
|
||||||
) {
|
) {
|
||||||
throw new Error('secrets array must contain objects that conform to the Secret interface');
|
throw new Error('secrets object is missing required secret properties');
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
throw new Error('secrets must be an object or an array of objects')
|
throw new Error('secrets must be an object or an array of objects')
|
||||||
@@ -87,8 +87,6 @@ router.get(
|
|||||||
|
|
||||||
router.patch(
|
router.patch(
|
||||||
'/',
|
'/',
|
||||||
body('workspaceId').exists().trim(),
|
|
||||||
body('environment').exists().trim().isIn(['dev', 'staging', 'prod', 'test']),
|
|
||||||
body('secrets')
|
body('secrets')
|
||||||
.exists()
|
.exists()
|
||||||
.custom((value) => {
|
.custom((value) => {
|
||||||
@@ -105,7 +103,7 @@ router.patch(
|
|||||||
!secret.secretValueIV ||
|
!secret.secretValueIV ||
|
||||||
!secret.secretValueTag
|
!secret.secretValueTag
|
||||||
) {
|
) {
|
||||||
throw new Error('secrets array must contain objects that conform to the Secret interface');
|
throw new Error('secrets array must contain objects that have required secret properties');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else if (typeof value === 'object') {
|
} else if (typeof value === 'object') {
|
||||||
@@ -119,7 +117,7 @@ router.patch(
|
|||||||
!value.secretValueIV ||
|
!value.secretValueIV ||
|
||||||
!value.secretValueTag
|
!value.secretValueTag
|
||||||
) {
|
) {
|
||||||
throw new Error('secrets array must contain objects that conform to the Secret interface');
|
throw new Error('secrets object is missing required secret properties');
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
throw new Error('secrets must be an object or an array of objects')
|
throw new Error('secrets must be an object or an array of objects')
|
||||||
@@ -131,10 +129,6 @@ router.patch(
|
|||||||
requireAuth({
|
requireAuth({
|
||||||
acceptedAuthModes: ['jwt']
|
acceptedAuthModes: ['jwt']
|
||||||
}),
|
}),
|
||||||
requireWorkspaceAuth({
|
|
||||||
acceptedRoles: [ADMIN, MEMBER],
|
|
||||||
location: 'body'
|
|
||||||
}),
|
|
||||||
requireSecretsAuth({
|
requireSecretsAuth({
|
||||||
acceptedRoles: [ADMIN, MEMBER]
|
acceptedRoles: [ADMIN, MEMBER]
|
||||||
}),
|
}),
|
||||||
|
|||||||
Reference in New Issue
Block a user