mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge remote-tracking branch 'origin' into network-access
This commit is contained in:
@@ -108,6 +108,22 @@ brews:
|
|||||||
zsh_completion.install "completions/infisical.zsh" => "_infisical"
|
zsh_completion.install "completions/infisical.zsh" => "_infisical"
|
||||||
fish_completion.install "completions/infisical.fish"
|
fish_completion.install "completions/infisical.fish"
|
||||||
man1.install "manpages/infisical.1.gz"
|
man1.install "manpages/infisical.1.gz"
|
||||||
|
- name: 'infisical@{{.Version}}'
|
||||||
|
tap:
|
||||||
|
owner: Infisical
|
||||||
|
name: homebrew-get-cli
|
||||||
|
commit_author:
|
||||||
|
name: "Infisical"
|
||||||
|
email: ai@infisical.com
|
||||||
|
folder: Formula
|
||||||
|
homepage: "https://infisical.com"
|
||||||
|
description: "The official Infisical CLI"
|
||||||
|
install: |-
|
||||||
|
bin.install "infisical"
|
||||||
|
bash_completion.install "completions/infisical.bash" => "infisical"
|
||||||
|
zsh_completion.install "completions/infisical.zsh" => "_infisical"
|
||||||
|
fish_completion.install "completions/infisical.fish"
|
||||||
|
man1.install "manpages/infisical.1.gz"
|
||||||
|
|
||||||
nfpms:
|
nfpms:
|
||||||
- id: infisical
|
- id: infisical
|
||||||
|
|||||||
@@ -30,7 +30,6 @@ export const createSecretImport = async (req: Request, res: Response) => {
|
|||||||
if (doesImportExist) {
|
if (doesImportExist) {
|
||||||
throw BadRequestError({ message: "Secret import already exist" });
|
throw BadRequestError({ message: "Secret import already exist" });
|
||||||
}
|
}
|
||||||
|
|
||||||
importSecDoc.imports.push({
|
importSecDoc.imports.push({
|
||||||
environment: secretImport.environment,
|
environment: secretImport.environment,
|
||||||
secretPath: secretImport.secretPath
|
secretPath: secretImport.secretPath
|
||||||
|
|||||||
@@ -830,7 +830,7 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
|
|
||||||
// TODO(akhilmhdh) - secret-imp change this to org type
|
// TODO(akhilmhdh) - secret-imp change this to org type
|
||||||
let importedSecrets: any[] = [];
|
let importedSecrets: any[] = [];
|
||||||
if (include_imports) {
|
if (include_imports === "true") {
|
||||||
importedSecrets = await getAllImportedSecrets(workspaceId, environment, folderId as string);
|
importedSecrets = await getAllImportedSecrets(workspaceId, environment, folderId as string);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -25,14 +25,17 @@ export const getSecretsRaw = async (req: Request, res: Response) => {
|
|||||||
let secretPath = req.query.secretPath as string;
|
let secretPath = req.query.secretPath as string;
|
||||||
const includeImports = req.query.include_imports as string;
|
const includeImports = req.query.include_imports as string;
|
||||||
|
|
||||||
// if the service token has single scope, it will get all secrets for that scope by default
|
// if the service token has single scope, it will get all secrets for that scope by default
|
||||||
const serviceTokenDetails: IServiceTokenData = req?.serviceTokenData
|
const serviceTokenDetails: IServiceTokenData = req?.serviceTokenData;
|
||||||
if (serviceTokenDetails) {
|
if (serviceTokenDetails) {
|
||||||
if (serviceTokenDetails.scopes.length == 1 && !containsGlobPatterns(serviceTokenDetails.scopes[0].secretPath)) {
|
if (
|
||||||
const scope = serviceTokenDetails.scopes[0]
|
serviceTokenDetails.scopes.length == 1 &&
|
||||||
secretPath = scope.secretPath
|
!containsGlobPatterns(serviceTokenDetails.scopes[0].secretPath)
|
||||||
environment = scope.environment
|
) {
|
||||||
workspaceId = serviceTokenDetails.workspace.toString()
|
const scope = serviceTokenDetails.scopes[0];
|
||||||
|
secretPath = scope.secretPath;
|
||||||
|
environment = scope.environment;
|
||||||
|
workspaceId = serviceTokenDetails.workspace.toString();
|
||||||
} else {
|
} else {
|
||||||
requireWorkspaceAuth({
|
requireWorkspaceAuth({
|
||||||
acceptedRoles: [ADMIN, MEMBER],
|
acceptedRoles: [ADMIN, MEMBER],
|
||||||
@@ -41,7 +44,7 @@ export const getSecretsRaw = async (req: Request, res: Response) => {
|
|||||||
requiredPermissions: [PERMISSION_READ_SECRETS],
|
requiredPermissions: [PERMISSION_READ_SECRETS],
|
||||||
requireBlindIndicesEnabled: true,
|
requireBlindIndicesEnabled: true,
|
||||||
requireE2EEOff: true
|
requireE2EEOff: true
|
||||||
})
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -56,7 +59,7 @@ export const getSecretsRaw = async (req: Request, res: Response) => {
|
|||||||
workspaceId: new Types.ObjectId(workspaceId)
|
workspaceId: new Types.ObjectId(workspaceId)
|
||||||
});
|
});
|
||||||
|
|
||||||
if (includeImports) {
|
if (includeImports === "true") {
|
||||||
const folders = await Folder.findOne({ workspace: workspaceId, environment });
|
const folders = await Folder.findOne({ workspace: workspaceId, environment });
|
||||||
let folderId = "root";
|
let folderId = "root";
|
||||||
// if folder exist get it and replace folderid with new one
|
// if folder exist get it and replace folderid with new one
|
||||||
@@ -294,7 +297,7 @@ export const getSecrets = async (req: Request, res: Response) => {
|
|||||||
authData: req.authData
|
authData: req.authData
|
||||||
});
|
});
|
||||||
|
|
||||||
if (includeImports) {
|
if (includeImports === "true") {
|
||||||
const folders = await Folder.findOne({ workspace: workspaceId, environment });
|
const folders = await Folder.findOne({ workspace: workspaceId, environment });
|
||||||
let folderId = "root";
|
let folderId = "root";
|
||||||
// if folder exist get it and replace folderid with new one
|
// if folder exist get it and replace folderid with new one
|
||||||
|
|||||||
@@ -46,7 +46,7 @@ router.delete(
|
|||||||
body("secretImportPath").isString().exists().trim(),
|
body("secretImportPath").isString().exists().trim(),
|
||||||
body("secretImportEnv").isString().exists().trim(),
|
body("secretImportEnv").isString().exists().trim(),
|
||||||
validateRequest,
|
validateRequest,
|
||||||
secretImportController.updateSecretImport
|
secretImportController.deleteSecretImport
|
||||||
);
|
);
|
||||||
|
|
||||||
router.get(
|
router.get(
|
||||||
|
|||||||
@@ -143,13 +143,13 @@ var runCmd = &cobra.Command{
|
|||||||
|
|
||||||
err = executeMultipleCommandWithEnvs(command, len(secretsByKey), env)
|
err = executeMultipleCommandWithEnvs(command, len(secretsByKey), env)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to execute your chained command")
|
fmt.Println(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
} else {
|
} else {
|
||||||
err = executeSingleCommandWithEnvs(args, len(secretsByKey), env)
|
err = executeSingleCommandWithEnvs(args, len(secretsByKey), env)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to execute your single command")
|
fmt.Println(err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -82,4 +82,28 @@ Password: `testInfisical1`
|
|||||||
```bash
|
```bash
|
||||||
# To stop environment use Control+C (on Mac) CTRL+C (on Win) or
|
# To stop environment use Control+C (on Mac) CTRL+C (on Win) or
|
||||||
docker-compose -f docker-compose.dev.yml down
|
docker-compose -f docker-compose.dev.yml down
|
||||||
|
```
|
||||||
|
|
||||||
|
## Starting Infisical docs locally
|
||||||
|
|
||||||
|
We use [Mintlify](https://mintlify.com/) for our docs.
|
||||||
|
|
||||||
|
#### Install Mintlify CLI.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
npm i -g mintlify
|
||||||
|
```
|
||||||
|
|
||||||
|
or
|
||||||
|
|
||||||
|
```bash
|
||||||
|
yarn global add mintlify
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Running the docs
|
||||||
|
Go to `docs` directory and run `mintlify dev`. This will start up the docs on `localhost:3000`
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# From the root directory
|
||||||
|
cd docs; mintlify dev;
|
||||||
```
|
```
|
||||||
@@ -45,8 +45,8 @@ To add an import, simply click on the `Add import` button and provide the enviro
|
|||||||

|

|
||||||
|
|
||||||
The hierarchy of importing secrets is governed by a "last-one-wins" rule. This means the sequence in which you import matters - the final folder imported will override secrets from any prior folders.
|
The hierarchy of importing secrets is governed by a "last-one-wins" rule. This means the sequence in which you import matters - the final folder imported will override secrets from any prior folders.
|
||||||
Moreover, any secrets you define directly in your environment will take precedence over secrets from any imported folders.
|
Additionally, any secrets you define directly in your environment will override any secrets that are imported with the same name.
|
||||||
|
|
||||||
You can modify this sequence by dragging and rearranging the folders using the `Change Order` drag handle.
|
You can modify the order of folders to control overrides using the `Change Order` drag handle.
|
||||||
|
|
||||||

|

|
||||||
|
|||||||
@@ -66,12 +66,12 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
# The host that should be used to pull secrets from. If left empty, the value specified in Global configuration will be used
|
||||||
hostAPI: https://app.infisical.com/api
|
hostAPI: https://app.infisical.com/api
|
||||||
resyncInterval:
|
resyncInterval: 60
|
||||||
authentication:
|
authentication:
|
||||||
serviceToken:
|
serviceToken:
|
||||||
serviceTokenSecretReference:
|
serviceTokenSecretReference:
|
||||||
secretName: service-token
|
secretName: service-token
|
||||||
secretNamespace: option
|
secretNamespace: default
|
||||||
secretsScope:
|
secretsScope:
|
||||||
envSlug: dev
|
envSlug: dev
|
||||||
secretsPath: "/"
|
secretsPath: "/"
|
||||||
|
|||||||
@@ -127,7 +127,7 @@ const AddProjectMemberDialog = ({
|
|||||||
</div>
|
</div>
|
||||||
) : (
|
) : (
|
||||||
<Button
|
<Button
|
||||||
onButtonPressed={() => router.push(`/settings/org/${router.query.id}`)}
|
onButtonPressed={() => router.push(`/org/${localStorage.getItem("orgData.id")}/members`)}
|
||||||
color="mineshaft"
|
color="mineshaft"
|
||||||
text={t("section.members.add-dialog.add-user-to-org") as string}
|
text={t("section.members.add-dialog.add-user-to-org") as string}
|
||||||
size="md"
|
size="md"
|
||||||
|
|||||||
Reference in New Issue
Block a user