mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 22:28:15 +00:00
fix(additional-privileges): return correct project membership ID
This commit is contained in:
@@ -84,7 +84,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
privilege: {
|
privilege: {
|
||||||
...privilege,
|
...privilege,
|
||||||
identityId: req.body.identityId,
|
identityId: req.body.identityId,
|
||||||
projectMembershipId: req.body.projectId,
|
projectMembershipId: privilege.projectMembershipId || req.body.projectId,
|
||||||
projectId: req.body.projectId,
|
projectId: req.body.projectId,
|
||||||
slug: privilege.name
|
slug: privilege.name
|
||||||
}
|
}
|
||||||
@@ -168,7 +168,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
privilege: {
|
privilege: {
|
||||||
...privilege,
|
...privilege,
|
||||||
identityId: privilegeDoc.actorIdentityId as string,
|
identityId: privilegeDoc.actorIdentityId as string,
|
||||||
projectMembershipId: privilegeDoc.projectId as string,
|
projectMembershipId: privilege.projectMembershipId || (privilegeDoc.projectId as string),
|
||||||
projectId: privilegeDoc.projectId as string,
|
projectId: privilegeDoc.projectId as string,
|
||||||
slug: privilege.name
|
slug: privilege.name
|
||||||
}
|
}
|
||||||
@@ -222,7 +222,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
privilege: {
|
privilege: {
|
||||||
...privilege,
|
...privilege,
|
||||||
identityId: privilegeDoc.actorIdentityId as string,
|
identityId: privilegeDoc.actorIdentityId as string,
|
||||||
projectMembershipId: privilegeDoc.projectId as string,
|
projectMembershipId: privilege.projectMembershipId || (privilegeDoc.projectId as string),
|
||||||
projectId: privilegeDoc.projectId as string,
|
projectId: privilegeDoc.projectId as string,
|
||||||
slug: privilege.name
|
slug: privilege.name
|
||||||
}
|
}
|
||||||
@@ -276,7 +276,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
privilege: {
|
privilege: {
|
||||||
...privilege,
|
...privilege,
|
||||||
identityId: privilegeDoc.actorIdentityId as string,
|
identityId: privilegeDoc.actorIdentityId as string,
|
||||||
projectMembershipId: privilegeDoc.projectId as string,
|
projectMembershipId: privilege.projectMembershipId || (privilegeDoc.projectId as string),
|
||||||
projectId: privilegeDoc.projectId as string,
|
projectId: privilegeDoc.projectId as string,
|
||||||
slug: privilege.name
|
slug: privilege.name
|
||||||
}
|
}
|
||||||
@@ -391,7 +391,7 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
privileges: privileges.map((privilege) => ({
|
privileges: privileges.map((privilege) => ({
|
||||||
...privilege,
|
...privilege,
|
||||||
identityId: req.query.identityId,
|
identityId: req.query.identityId,
|
||||||
projectMembershipId: privilege.projectId as string,
|
projectMembershipId: privilege.projectMembershipId || (privilege.projectId as string),
|
||||||
projectId: req.query.projectId,
|
projectId: req.query.projectId,
|
||||||
slug: privilege.name
|
slug: privilege.name
|
||||||
}))
|
}))
|
||||||
|
|||||||
@@ -58,6 +58,21 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
const scope = factory.getScopeField(dto.scopeData);
|
const scope = factory.getScopeField(dto.scopeData);
|
||||||
const dbActorField = data.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
const dbActorField = data.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
||||||
|
|
||||||
|
let projectMembershipId: string | undefined;
|
||||||
|
if (scope.key === "projectId") {
|
||||||
|
const projectMembership = await membershipDAL.findOne({
|
||||||
|
[dbActorField]: data.actorId,
|
||||||
|
scopeProjectId: scope.value,
|
||||||
|
scope: AccessScope.Project
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!projectMembership) {
|
||||||
|
throw new NotFoundError({ message: `Project membership for ${data.actorType} ${data.actorId} not found` });
|
||||||
|
}
|
||||||
|
|
||||||
|
projectMembershipId = projectMembership.id;
|
||||||
|
}
|
||||||
|
|
||||||
const existingSlug = await additionalPrivilegeDAL.findOne({
|
const existingSlug = await additionalPrivilegeDAL.findOne({
|
||||||
name: data.name,
|
name: data.name,
|
||||||
[dbActorField]: data.actorId,
|
[dbActorField]: data.actorId,
|
||||||
@@ -79,7 +94,11 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
additionalPrivilege: { ...additionalPrivilege, permissions: unpackPermissions(additionalPrivilege.permissions) }
|
additionalPrivilege: {
|
||||||
|
...additionalPrivilege,
|
||||||
|
permissions: unpackPermissions(additionalPrivilege.permissions),
|
||||||
|
projectMembershipId
|
||||||
|
}
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -103,7 +122,11 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
additionalPrivilege: { ...additionalPrivilege, permissions: unpackPermissions(additionalPrivilege.permissions) }
|
additionalPrivilege: {
|
||||||
|
...additionalPrivilege,
|
||||||
|
permissions: unpackPermissions(additionalPrivilege.permissions),
|
||||||
|
projectMembershipId
|
||||||
|
}
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -114,6 +137,21 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
const scope = factory.getScopeField(dto.scopeData);
|
const scope = factory.getScopeField(dto.scopeData);
|
||||||
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
||||||
|
|
||||||
|
let projectMembershipId: string | undefined;
|
||||||
|
if (scope.key === "projectId") {
|
||||||
|
const projectMembership = await membershipDAL.findOne({
|
||||||
|
[dbActorField]: dto.selector.actorId,
|
||||||
|
scopeProjectId: scope.value,
|
||||||
|
scope: AccessScope.Project
|
||||||
|
});
|
||||||
|
if (!projectMembership) {
|
||||||
|
throw new NotFoundError({
|
||||||
|
message: `Project membership for ${dto.selector.actorType} ${dto.selector.actorId} not found`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
projectMembershipId = projectMembership.id;
|
||||||
|
}
|
||||||
|
|
||||||
const existingPrivilege = await additionalPrivilegeDAL.findOne({
|
const existingPrivilege = await additionalPrivilegeDAL.findOne({
|
||||||
[dbActorField]: dto.selector.actorId,
|
[dbActorField]: dto.selector.actorId,
|
||||||
id: dto.selector.id,
|
id: dto.selector.id,
|
||||||
@@ -136,7 +174,11 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
additionalPrivilege: { ...additionalPrivilege, permissions: unpackPermissions(additionalPrivilege.permissions) }
|
additionalPrivilege: {
|
||||||
|
...additionalPrivilege,
|
||||||
|
permissions: unpackPermissions(additionalPrivilege.permissions),
|
||||||
|
projectMembershipId
|
||||||
|
}
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -158,7 +200,11 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
additionalPrivilege: { ...additionalPrivilege, permissions: unpackPermissions(additionalPrivilege.permissions) }
|
additionalPrivilege: {
|
||||||
|
...additionalPrivilege,
|
||||||
|
permissions: unpackPermissions(additionalPrivilege.permissions),
|
||||||
|
projectMembershipId
|
||||||
|
}
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -169,6 +215,21 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
const scope = factory.getScopeField(dto.scopeData);
|
const scope = factory.getScopeField(dto.scopeData);
|
||||||
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
||||||
|
|
||||||
|
let projectMembershipId: string | undefined;
|
||||||
|
if (scope.key === "projectId") {
|
||||||
|
const projectMembership = await membershipDAL.findOne({
|
||||||
|
[dbActorField]: dto.selector.actorId,
|
||||||
|
scopeProjectId: scope.value,
|
||||||
|
scope: AccessScope.Project
|
||||||
|
});
|
||||||
|
if (!projectMembership) {
|
||||||
|
throw new NotFoundError({
|
||||||
|
message: `Project membership for ${dto.selector.actorType} ${dto.selector.actorId} not found`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
projectMembershipId = projectMembership.id;
|
||||||
|
}
|
||||||
|
|
||||||
const existingPrivilege = await additionalPrivilegeDAL.findOne({
|
const existingPrivilege = await additionalPrivilegeDAL.findOne({
|
||||||
id: selector.id,
|
id: selector.id,
|
||||||
[dbActorField]: dto.selector.actorId,
|
[dbActorField]: dto.selector.actorId,
|
||||||
@@ -179,7 +240,11 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
|
|
||||||
const additionalPrivilege = await additionalPrivilegeDAL.deleteById(existingPrivilege.id);
|
const additionalPrivilege = await additionalPrivilegeDAL.deleteById(existingPrivilege.id);
|
||||||
return {
|
return {
|
||||||
additionalPrivilege: { ...additionalPrivilege, permissions: unpackPermissions(additionalPrivilege.permissions) }
|
additionalPrivilege: {
|
||||||
|
...additionalPrivilege,
|
||||||
|
permissions: unpackPermissions(additionalPrivilege.permissions),
|
||||||
|
projectMembershipId
|
||||||
|
}
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -190,6 +255,21 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
const scope = factory.getScopeField(dto.scopeData);
|
const scope = factory.getScopeField(dto.scopeData);
|
||||||
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
||||||
|
|
||||||
|
let projectMembershipId: string | undefined;
|
||||||
|
if (scope.key === "projectId") {
|
||||||
|
const projectMembership = await membershipDAL.findOne({
|
||||||
|
[dbActorField]: dto.selector.actorId,
|
||||||
|
scopeProjectId: scope.value,
|
||||||
|
scope: AccessScope.Project
|
||||||
|
});
|
||||||
|
if (!projectMembership) {
|
||||||
|
throw new NotFoundError({
|
||||||
|
message: `Project membership for ${dto.selector.actorType} ${dto.selector.actorId} not found`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
projectMembershipId = projectMembership.id;
|
||||||
|
}
|
||||||
|
|
||||||
const additionalPrivilege = await additionalPrivilegeDAL.findOne({
|
const additionalPrivilege = await additionalPrivilegeDAL.findOne({
|
||||||
id: selector.id,
|
id: selector.id,
|
||||||
[dbActorField]: dto.selector.actorId,
|
[dbActorField]: dto.selector.actorId,
|
||||||
@@ -199,7 +279,11 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
throw new NotFoundError({ message: `Additional privilege with id ${selector.id} doesn't exist` });
|
throw new NotFoundError({ message: `Additional privilege with id ${selector.id} doesn't exist` });
|
||||||
|
|
||||||
return {
|
return {
|
||||||
additionalPrivilege: { ...additionalPrivilege, permissions: unpackPermissions(additionalPrivilege.permissions) }
|
additionalPrivilege: {
|
||||||
|
...additionalPrivilege,
|
||||||
|
permissions: unpackPermissions(additionalPrivilege.permissions),
|
||||||
|
projectMembershipId
|
||||||
|
}
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -230,6 +314,21 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
const scope = factory.getScopeField(dto.scopeData);
|
const scope = factory.getScopeField(dto.scopeData);
|
||||||
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
const dbActorField = dto.selector.actorType === ActorType.IDENTITY ? "actorIdentityId" : "actorUserId";
|
||||||
|
|
||||||
|
let projectMembershipId: string | undefined;
|
||||||
|
if (scope.key === "projectId") {
|
||||||
|
const projectMembership = await membershipDAL.findOne({
|
||||||
|
[dbActorField]: dto.selector.actorId,
|
||||||
|
scopeProjectId: scope.value,
|
||||||
|
scope: AccessScope.Project
|
||||||
|
});
|
||||||
|
if (!projectMembership) {
|
||||||
|
throw new NotFoundError({
|
||||||
|
message: `Project membership for ${dto.selector.actorType} ${dto.selector.actorId} not found`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
projectMembershipId = projectMembership.id;
|
||||||
|
}
|
||||||
|
|
||||||
const additionalPrivileges = await additionalPrivilegeDAL.find({
|
const additionalPrivileges = await additionalPrivilegeDAL.find({
|
||||||
[dbActorField]: dto.selector.actorId,
|
[dbActorField]: dto.selector.actorId,
|
||||||
[scope.key]: scope.value
|
[scope.key]: scope.value
|
||||||
@@ -238,6 +337,7 @@ export const additionalPrivilegeServiceFactory = ({
|
|||||||
return {
|
return {
|
||||||
additionalPrivileges: additionalPrivileges.map((el) => ({
|
additionalPrivileges: additionalPrivileges.map((el) => ({
|
||||||
...el,
|
...el,
|
||||||
|
projectMembershipId,
|
||||||
permissions: unpackPermissions(el.permissions)
|
permissions: unpackPermissions(el.permissions)
|
||||||
}))
|
}))
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user