fix: add folder exists check to dashboard router endpoint

This commit is contained in:
Scott Wilson
2025-08-29 10:46:59 -07:00
parent 7f958e6d89
commit cf64c89ea3
3 changed files with 36 additions and 0 deletions
@@ -703,6 +703,9 @@ export const registerDashboardRouter = async (server: FastifyZodProvider) => {
// prevent older projects from accessing endpoint // prevent older projects from accessing endpoint
if (!shouldUseSecretV2Bridge) throw new BadRequestError({ message: "Project version not supported" }); if (!shouldUseSecretV2Bridge) throw new BadRequestError({ message: "Project version not supported" });
// verify folder exists and user has project permission
await server.services.folder.getFolderByPath({ projectId, environment, secretPath }, req.permission);
const tags = req.query.tags?.split(",") ?? []; const tags = req.query.tags?.split(",") ?? [];
let remainingLimit = limit; let remainingLimit = limit;
@@ -30,6 +30,7 @@ import {
TDeleteFolderDTO, TDeleteFolderDTO,
TDeleteManyFoldersDTO, TDeleteManyFoldersDTO,
TGetFolderByIdDTO, TGetFolderByIdDTO,
TGetFolderByPathDTO,
TGetFolderDTO, TGetFolderDTO,
TGetFoldersDeepByEnvsDTO, TGetFoldersDeepByEnvsDTO,
TUpdateFolderDTO, TUpdateFolderDTO,
@@ -1398,6 +1399,31 @@ export const secretFolderServiceFactory = ({
}; };
}; };
const getFolderByPath = async (
{ projectId, environment, secretPath }: TGetFolderByPathDTO,
actor: OrgServiceActor
) => {
// folder check is allowed to be read by anyone
// permission is to check if user has access
await permissionService.getProjectPermission({
actor: actor.type,
actorId: actor.id,
projectId,
actorAuthMethod: actor.authMethod,
actorOrgId: actor.orgId,
actionProjectType: ActionProjectType.SecretManager
});
const folder = await folderDAL.findBySecretPath(projectId, environment, secretPath);
if (!folder)
throw new NotFoundError({
message: `Could not find folder with path "${secretPath}" in environment "${environment}" for project with ID "${projectId}"`
});
return folder;
};
return { return {
createFolder, createFolder,
updateFolder, updateFolder,
@@ -1405,6 +1431,7 @@ export const secretFolderServiceFactory = ({
deleteFolder, deleteFolder,
getFolders, getFolders,
getFolderById, getFolderById,
getFolderByPath,
getProjectFolderCount, getProjectFolderCount,
getFoldersMultiEnv, getFoldersMultiEnv,
getFoldersDeepByEnvs, getFoldersDeepByEnvs,
@@ -91,3 +91,9 @@ export type TDeleteManyFoldersDTO = {
idOrName: string; idOrName: string;
}>; }>;
}; };
export type TGetFolderByPathDTO = {
projectId: string;
environment: string;
secretPath: string;
};