mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 09:28:06 +00:00
fix: only check for delete protection if deleting org identity, not sub-org identity membership
This commit is contained in:
@@ -329,14 +329,14 @@ export const identityServiceFactory = ({
|
|||||||
|
|
||||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionIdentityActions.Delete, OrgPermissionSubjects.Identity);
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionIdentityActions.Delete, OrgPermissionSubjects.Identity);
|
||||||
|
|
||||||
if (identityOrgMembership.identity.hasDeleteProtection)
|
|
||||||
throw new BadRequestError({ message: "Identity has delete protection" });
|
|
||||||
|
|
||||||
if (identityOrgMembership.identity.projectId) {
|
if (identityOrgMembership.identity.projectId) {
|
||||||
throw new BadRequestError({ message: `Identity is managed by project` });
|
throw new BadRequestError({ message: `Identity is managed by project` });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (identityOrgMembership.identity.orgId === actorOrgId) {
|
if (identityOrgMembership.identity.orgId === actorOrgId) {
|
||||||
|
if (identityOrgMembership.identity.hasDeleteProtection)
|
||||||
|
throw new BadRequestError({ message: "Identity has delete protection" });
|
||||||
|
|
||||||
const deletedIdentity = await identityDAL.deleteById(id);
|
const deletedIdentity = await identityDAL.deleteById(id);
|
||||||
await licenseService.updateSubscriptionOrgMemberCount(identityOrgMembership.scopeOrgId);
|
await licenseService.updateSubscriptionOrgMemberCount(identityOrgMembership.scopeOrgId);
|
||||||
return { ...deletedIdentity, orgId: identityOrgMembership.scopeOrgId };
|
return { ...deletedIdentity, orgId: identityOrgMembership.scopeOrgId };
|
||||||
|
|||||||
Reference in New Issue
Block a user