mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 18:27:36 +00:00
chore: rolled back service token permission changes
This commit is contained in:
@@ -856,14 +856,12 @@ export const buildServiceTokenProjectPermission = (
|
|||||||
) => {
|
) => {
|
||||||
const canWrite = permission.includes("write");
|
const canWrite = permission.includes("write");
|
||||||
const canRead = permission.includes("read");
|
const canRead = permission.includes("read");
|
||||||
|
|
||||||
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
|
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
|
||||||
scopes.forEach(({ secretPath, environment }) => {
|
scopes.forEach(({ secretPath, environment }) => {
|
||||||
[ProjectPermissionSub.Secrets, ProjectPermissionSub.SecretImports, ProjectPermissionSub.SecretFolders].forEach(
|
[ProjectPermissionSub.Secrets, ProjectPermissionSub.SecretImports, ProjectPermissionSub.SecretFolders].forEach(
|
||||||
(subject) => {
|
(subject) => {
|
||||||
if (canWrite) {
|
if (canWrite) {
|
||||||
can(ProjectPermissionActions.Edit, subject, {
|
can(ProjectPermissionActions.Edit, subject, {
|
||||||
// TODO: @Akhi
|
|
||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
secretPath: { $glob: secretPath },
|
secretPath: { $glob: secretPath },
|
||||||
environment
|
environment
|
||||||
@@ -879,27 +877,13 @@ export const buildServiceTokenProjectPermission = (
|
|||||||
environment
|
environment
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
if (canRead && subject !== ProjectPermissionSub.Secrets) {
|
if (canRead) {
|
||||||
can(ProjectPermissionActions.Read, subject, {
|
can(ProjectPermissionActions.Read, subject, {
|
||||||
// @ts-expect-error type
|
// @ts-expect-error type
|
||||||
secretPath: { $glob: secretPath },
|
secretPath: { $glob: secretPath },
|
||||||
environment
|
environment
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
if (subject === ProjectPermissionSub.Secrets && canRead) {
|
|
||||||
// @ts-expect-error type
|
|
||||||
can(ProjectPermissionSecretActions.ReadValue, subject as ProjectPermissionSub.Secrets, {
|
|
||||||
secretPath: { $glob: secretPath },
|
|
||||||
environment
|
|
||||||
});
|
|
||||||
|
|
||||||
// @ts-expect-error type
|
|
||||||
can(ProjectPermissionSecretActions.DescribeSecret, subject as ProjectPermissionSub.Secrets, {
|
|
||||||
secretPath: { $glob: secretPath },
|
|
||||||
environment
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user