Merge pull request #1378 from Infisical/patch-service-token-fetch

patch get secret by name
This commit is contained in:
Akhil Mohan
2024-02-07 23:00:20 +05:30
committed by GitHub
+17 -5
View File
@@ -537,18 +537,30 @@ export const secretServiceFactory = ({
const secretBlindIndex = await interalGenSecBlindIndexByName(projectId, secretName); const secretBlindIndex = await interalGenSecBlindIndexByName(projectId, secretName);
const secret = await (typeof version !== undefined // Case: The old python SDK uses incorrect logic https://github.com/Infisical/infisical-python/blob/main/infisical/client/infisicalclient.py#L89.
// Fetch secrets using service tokens cannot fetch personal secrets, only shared.
// The mongo backend used to correct this mistake, this line also adds it to current backend
// Mongo backend check: https://github.com/Infisical/infisical-mongo/blob/main/backend/src/helpers/secrets.ts#L658
let secretType = type;
if (actor === ActorType.SERVICE) {
logger.info(
`secretServiceFactory: overriding secret type for service token [projectId=${projectId}] [factoryFunctionName=getSecretByName]`
);
secretType = SecretType.Shared;
}
const secret = await (typeof version === undefined
? secretDAL.findOne({ ? secretDAL.findOne({
folderId, folderId,
type, type: secretType,
userId: type === SecretType.Personal ? actorId : null, userId: secretType === SecretType.Personal ? actorId : null,
secretBlindIndex secretBlindIndex
}) })
: secretVersionDAL : secretVersionDAL
.findOne({ .findOne({
folderId, folderId,
type, type: secretType,
userId: type === SecretType.Personal ? actorId : null, userId: secretType === SecretType.Personal ? actorId : null,
secretBlindIndex secretBlindIndex
}) })
.then((el) => SecretsSchema.parse({ ...el, id: el.secretId }))); .then((el) => SecretsSchema.parse({ ...el, id: el.secretId })));