This commit is contained in:
x032205
2025-05-15 16:32:57 -04:00
parent 6188de43e4
commit c519cee5d1
14 changed files with 232 additions and 71 deletions
@@ -0,0 +1,21 @@
import { Knex } from "knex";
import { TableName } from "../schemas";
export async function up(knex: Knex): Promise<void> {
await knex.schema.alterTable(TableName.Organization, (t) => {
t.boolean("secretsProductEnabled").defaultTo(true);
t.boolean("pkiProductEnabled").defaultTo(true);
t.boolean("kmsProductEnabled").defaultTo(true);
t.boolean("sshProductEnabled").defaultTo(true);
});
}
export async function down(knex: Knex): Promise<void> {
await knex.schema.alterTable(TableName.Organization, (t) => {
t.dropColumn("secretsProductEnabled");
t.dropColumn("pkiProductEnabled");
t.dropColumn("kmsProductEnabled");
t.dropColumn("sshProductEnabled");
});
}
+5 -1
View File
@@ -28,7 +28,11 @@ export const OrganizationsSchema = z.object({
privilegeUpgradeInitiatedByUsername: z.string().nullable().optional(), privilegeUpgradeInitiatedByUsername: z.string().nullable().optional(),
privilegeUpgradeInitiatedAt: z.date().nullable().optional(), privilegeUpgradeInitiatedAt: z.date().nullable().optional(),
bypassOrgAuthEnabled: z.boolean().default(false), bypassOrgAuthEnabled: z.boolean().default(false),
userTokenExpiration: z.string().nullable().optional() userTokenExpiration: z.string().nullable().optional(),
secretsProductEnabled: z.boolean().default(true).nullable().optional(),
pkiProductEnabled: z.boolean().default(true).nullable().optional(),
kmsProductEnabled: z.boolean().default(true).nullable().optional(),
sshProductEnabled: z.boolean().default(true).nullable().optional()
}); });
export type TOrganizations = z.infer<typeof OrganizationsSchema>; export type TOrganizations = z.infer<typeof OrganizationsSchema>;
+2 -2
View File
@@ -110,7 +110,7 @@ export const registerV1Routes = async (server: FastifyZodProvider) => {
await pkiRouter.register(registerPkiCollectionRouter, { prefix: "/collections" }); await pkiRouter.register(registerPkiCollectionRouter, { prefix: "/collections" });
await pkiRouter.register(registerPkiSubscriberRouter, { prefix: "/subscribers" }); await pkiRouter.register(registerPkiSubscriberRouter, { prefix: "/subscribers" });
}, },
{ prefix: "/pki" } { prefix: "/pki" } // TODO(andrey): Block this if PKI PRODUCT disabled?
); );
await server.register(registerProjectBotRouter, { prefix: "/bot" }); await server.register(registerProjectBotRouter, { prefix: "/bot" });
@@ -129,7 +129,7 @@ export const registerV1Routes = async (server: FastifyZodProvider) => {
await server.register(registerUserEngagementRouter, { prefix: "/user-engagement" }); await server.register(registerUserEngagementRouter, { prefix: "/user-engagement" });
await server.register(registerDashboardRouter, { prefix: "/dashboard" }); await server.register(registerDashboardRouter, { prefix: "/dashboard" });
await server.register(registerCmekRouter, { prefix: "/kms" }); await server.register(registerCmekRouter, { prefix: "/kms" }); // TODO(andrey): Block this if KMS PRODUCT disabled?
await server.register(registerExternalGroupOrgRoleMappingRouter, { prefix: "/external-group-mappings" }); await server.register(registerExternalGroupOrgRoleMappingRouter, { prefix: "/external-group-mappings" });
await server.register( await server.register(
@@ -275,7 +275,11 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
}, },
{ message: "Duration value must be at least 1" } { message: "Duration value must be at least 1" }
) )
.optional() .optional(),
secretsProductEnabled: z.boolean().optional(),
pkiProductEnabled: z.boolean().optional(),
kmsProductEnabled: z.boolean().optional(),
sshProductEnabled: z.boolean().optional()
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -286,6 +290,9 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
}, },
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT]),
handler: async (req) => { handler: async (req) => {
console.log("REQ BODY");
console.log(req.body);
const organization = await server.services.org.updateOrg({ const organization = await server.services.org.updateOrg({
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
+1 -1
View File
@@ -9,7 +9,7 @@ export const registerV3Routes = async (server: FastifyZodProvider) => {
await server.register(registerSignupRouter, { prefix: "/signup" }); await server.register(registerSignupRouter, { prefix: "/signup" });
await server.register(registerLoginRouter, { prefix: "/auth" }); await server.register(registerLoginRouter, { prefix: "/auth" });
await server.register(registerUserRouter, { prefix: "/users" }); await server.register(registerUserRouter, { prefix: "/users" });
await server.register(registerSecretRouter, { prefix: "/secrets" }); await server.register(registerSecretRouter, { prefix: "/secrets" }); // TODO(andrey): Block this if SECRETS PRODUCT disabled?
await server.register(registerSecretBlindIndexRouter, { prefix: "/workspaces" }); await server.register(registerSecretBlindIndexRouter, { prefix: "/workspaces" });
await server.register(registerExternalMigrationRouter, { prefix: "/migrate" }); await server.register(registerExternalMigrationRouter, { prefix: "/migrate" });
}; };
+5 -1
View File
@@ -18,5 +18,9 @@ export const sanitizedOrganizationSchema = OrganizationsSchema.pick({
privilegeUpgradeInitiatedByUsername: true, privilegeUpgradeInitiatedByUsername: true,
privilegeUpgradeInitiatedAt: true, privilegeUpgradeInitiatedAt: true,
bypassOrgAuthEnabled: true, bypassOrgAuthEnabled: true,
userTokenExpiration: true userTokenExpiration: true,
secretsProductEnabled: true,
pkiProductEnabled: true,
kmsProductEnabled: true,
sshProductEnabled: true
}); });
+10 -2
View File
@@ -355,7 +355,11 @@ export const orgServiceFactory = ({
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
bypassOrgAuthEnabled, bypassOrgAuthEnabled,
userTokenExpiration userTokenExpiration,
secretsProductEnabled,
pkiProductEnabled,
kmsProductEnabled,
sshProductEnabled
} }
}: TUpdateOrgDTO) => { }: TUpdateOrgDTO) => {
const appCfg = getConfig(); const appCfg = getConfig();
@@ -457,7 +461,11 @@ export const orgServiceFactory = ({
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
bypassOrgAuthEnabled, bypassOrgAuthEnabled,
userTokenExpiration userTokenExpiration,
secretsProductEnabled,
pkiProductEnabled,
kmsProductEnabled,
sshProductEnabled
}); });
if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` }); if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` });
return org; return org;
+4
View File
@@ -75,6 +75,10 @@ export type TUpdateOrgDTO = {
allowSecretSharingOutsideOrganization: boolean; allowSecretSharingOutsideOrganization: boolean;
bypassOrgAuthEnabled: boolean; bypassOrgAuthEnabled: boolean;
userTokenExpiration: string; userTokenExpiration: string;
secretsProductEnabled: boolean;
pkiProductEnabled: boolean;
kmsProductEnabled: boolean;
sshProductEnabled: boolean;
}>; }>;
} & TOrgPermission; } & TOrgPermission;
@@ -112,7 +112,11 @@ export const useUpdateOrg = () => {
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
bypassOrgAuthEnabled, bypassOrgAuthEnabled,
userTokenExpiration userTokenExpiration,
secretsProductEnabled,
pkiProductEnabled,
kmsProductEnabled,
sshProductEnabled
}) => { }) => {
return apiRequest.patch(`/api/v1/organization/${orgId}`, { return apiRequest.patch(`/api/v1/organization/${orgId}`, {
name, name,
@@ -124,7 +128,11 @@ export const useUpdateOrg = () => {
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
bypassOrgAuthEnabled, bypassOrgAuthEnabled,
userTokenExpiration userTokenExpiration,
secretsProductEnabled,
pkiProductEnabled,
kmsProductEnabled,
sshProductEnabled
}); });
}, },
onSuccess: () => { onSuccess: () => {
@@ -20,6 +20,10 @@ export type Organization = {
allowSecretSharingOutsideOrganization?: boolean; allowSecretSharingOutsideOrganization?: boolean;
userTokenExpiration?: string; userTokenExpiration?: string;
userRole: string; userRole: string;
secretsProductEnabled: boolean;
pkiProductEnabled: boolean;
kmsProductEnabled: boolean;
sshProductEnabled: boolean;
}; };
export type UpdateOrgDTO = { export type UpdateOrgDTO = {
@@ -34,6 +38,10 @@ export type UpdateOrgDTO = {
allowSecretSharingOutsideOrganization?: boolean; allowSecretSharingOutsideOrganization?: boolean;
bypassOrgAuthEnabled?: boolean; bypassOrgAuthEnabled?: boolean;
userTokenExpiration?: string; userTokenExpiration?: string;
secretsProductEnabled?: boolean;
pkiProductEnabled?: boolean;
kmsProductEnabled?: boolean;
sshProductEnabled?: boolean;
}; };
export type BillingDetails = { export type BillingDetails = {
@@ -268,62 +268,70 @@ export const MinimizedOrgSidebar = () => {
</DropdownMenu> </DropdownMenu>
</div> </div>
<div className="space-y-1"> <div className="space-y-1">
<Link to="/organization/secret-manager/overview"> {currentOrg.secretsProductEnabled && (
{({ isActive }) => ( <Link to="/organization/secret-manager/overview">
<MenuIconButton {({ isActive }) => (
isSelected={ <MenuIconButton
isActive || isSelected={
window.location.pathname.startsWith( isActive ||
`/organization/${ProjectType.SecretManager}` window.location.pathname.startsWith(
) `/organization/${ProjectType.SecretManager}`
} )
icon="sliding-carousel" }
> icon="sliding-carousel"
Secrets >
</MenuIconButton> Secrets
)} </MenuIconButton>
</Link> )}
<Link to="/organization/cert-manager/overview"> </Link>
{({ isActive }) => ( )}
<MenuIconButton {currentOrg.pkiProductEnabled && (
isSelected={ <Link to="/organization/cert-manager/overview">
isActive || {({ isActive }) => (
window.location.pathname.startsWith( <MenuIconButton
`/organization/${ProjectType.CertificateManager}` isSelected={
) isActive ||
} window.location.pathname.startsWith(
icon="note" `/organization/${ProjectType.CertificateManager}`
> )
PKI }
</MenuIconButton> icon="note"
)} >
</Link> PKI
<Link to="/organization/kms/overview"> </MenuIconButton>
{({ isActive }) => ( )}
<MenuIconButton </Link>
isSelected={ )}
isActive || {currentOrg.kmsProductEnabled && (
window.location.pathname.startsWith(`/organization/${ProjectType.KMS}`) <Link to="/organization/kms/overview">
} {({ isActive }) => (
icon="unlock" <MenuIconButton
> isSelected={
KMS isActive ||
</MenuIconButton> window.location.pathname.startsWith(`/organization/${ProjectType.KMS}`)
)} }
</Link> icon="unlock"
<Link to="/organization/ssh/overview"> >
{({ isActive }) => ( KMS
<MenuIconButton </MenuIconButton>
isSelected={ )}
isActive || </Link>
window.location.pathname.startsWith(`/organization/${ProjectType.SSH}`) )}
} {currentOrg.sshProductEnabled && (
icon="verified" <Link to="/organization/ssh/overview">
> {({ isActive }) => (
SSH <MenuIconButton
</MenuIconButton> isSelected={
)} isActive ||
</Link> window.location.pathname.startsWith(`/organization/${ProjectType.SSH}`)
}
icon="verified"
>
SSH
</MenuIconButton>
)}
</Link>
)}
<div className="w-full bg-mineshaft-500" style={{ height: "1px" }} /> <div className="w-full bg-mineshaft-500" style={{ height: "1px" }} />
<Link to="/organization/secret-scanning"> <Link to="/organization/secret-scanning">
{({ isActive }) => ( {({ isActive }) => (
@@ -3,14 +3,18 @@ import { useOrgPermission } from "@app/context";
import { OrgDeleteSection } from "../OrgDeleteSection"; import { OrgDeleteSection } from "../OrgDeleteSection";
import { OrgIncidentContactsSection } from "../OrgIncidentContactsSection"; import { OrgIncidentContactsSection } from "../OrgIncidentContactsSection";
import { OrgNameChangeSection } from "../OrgNameChangeSection"; import { OrgNameChangeSection } from "../OrgNameChangeSection";
import { OrgProductSelectSection } from "../OrgProductSelectSection";
export const OrgGeneralTab = () => { export const OrgGeneralTab = () => {
const { membership } = useOrgPermission(); const { membership } = useOrgPermission();
return ( return (
<div className="rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-6"> <>
<OrgNameChangeSection /> <div className="mb-6 rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-6">
<OrgIncidentContactsSection /> <OrgNameChangeSection />
{membership && membership.role === "admin" && <OrgDeleteSection />} <OrgIncidentContactsSection />
</div> {membership && membership.role === "admin" && <OrgDeleteSection />}
</div>
<OrgProductSelectSection />
</>
); );
}; };
@@ -0,0 +1,84 @@
import { createNotification } from "@app/components/notifications";
import { Switch } from "@app/components/v2";
import { useOrganization } from "@app/context";
import { useUpdateOrg } from "@app/hooks/api";
import { useEffect, useState } from "react";
export const OrgProductSelectSection = () => {
const [toggledProducts, setToggledProducts] = useState<{
[key: string]: { name: string; enabled: boolean };
}>({
secretsProductEnabled: {
name: "Secrets",
enabled: true
},
pkiProductEnabled: {
name: "PKI",
enabled: true
},
kmsProductEnabled: {
name: "KMS",
enabled: true
},
sshProductEnabled: {
name: "SSH",
enabled: true
}
});
const { currentOrg } = useOrganization();
const { mutateAsync } = useUpdateOrg();
useEffect(() => {
for (const [key, value] of Object.entries(currentOrg)) {
if (key in toggledProducts && typeof value === "boolean") {
setToggledProducts((products) => ({
...products,
[key]: { ...products[key], enabled: value }
}));
}
}
}, [currentOrg]);
const onProductToggle = async (value: boolean, key: string) => {
setToggledProducts((products) => ({
...products,
[key]: { ...products[key], enabled: value }
}));
console.log(key, value);
// Update backend
await mutateAsync({
orgId: currentOrg.id,
[key]: value
});
createNotification({
text: `Successfully ${value ? "enabled" : "disabled"} ${toggledProducts[key].name}`,
type: "success"
});
};
return (
<div className="mb-6 rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
<h2 className="text-xl font-semibold text-mineshaft-100">Organization Products</h2>
<p className="mb-4 text-gray-400">
Select which products are available for your organization.
</p>
<div className="flex flex-col gap-2">
{Object.entries(toggledProducts).map(([key, product]) => (
<Switch
key={key}
id={`enable-${key}`}
onCheckedChange={(value) => onProductToggle(value, key)}
isChecked={product.enabled}
>
<p className="mr-4 w-12">{product.name}</p>
</Switch>
))}
</div>
</div>
);
};
@@ -0,0 +1 @@
export { OrgProductSelectSection } from "./OrgProductSelectSection";