mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
get rid of resource from policies, only using account path
This commit is contained in:
@@ -29,11 +29,6 @@ export const pamAccessPolicyFactory: TApprovalResourceFactory<
|
||||
for (const policy of policies) {
|
||||
const p = policy as TPamAccessPolicy;
|
||||
for (const c of p.conditions.conditions) {
|
||||
if (c.resourceIds && !c.resourceIds.some((r) => r === inputs.resourceId)) {
|
||||
// eslint-disable-next-line no-continue
|
||||
continue;
|
||||
}
|
||||
|
||||
// Find the most specific path pattern
|
||||
// TODO(andrey): Make matching logic more advanced by accounting for wildcard positions
|
||||
for (const pathPattern of c.accountPaths) {
|
||||
|
||||
@@ -12,14 +12,12 @@ import {
|
||||
|
||||
// Inputs
|
||||
export const PamAccessPolicyInputsSchema = z.object({
|
||||
resourceId: z.string().uuid(),
|
||||
accountPath: z.string()
|
||||
});
|
||||
|
||||
// Conditions
|
||||
export const PamAccessPolicyConditionsSchema = z
|
||||
.object({
|
||||
resourceIds: z.string().uuid().array().optional(),
|
||||
accountPaths: z.string().array() // TODO(andrey): Add path & wildcard validation
|
||||
})
|
||||
.array();
|
||||
@@ -44,7 +42,6 @@ export const PamAccessPolicyConstraintsSchema = z.object({
|
||||
|
||||
// Request Data
|
||||
export const PamAccessPolicyRequestDataSchema = z.object({
|
||||
resourceId: z.string().uuid(),
|
||||
accountPath: z.string(),
|
||||
accessDuration: DurationSchema
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user