mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 05:27:48 +00:00
Fix: Duplicate access request check
This commit is contained in:
+18
-15
@@ -37,6 +37,7 @@ type TSecretApprovalRequestServiceFactoryDep = {
|
|||||||
accessApprovalRequestDAL: Pick<
|
accessApprovalRequestDAL: Pick<
|
||||||
TAccessApprovalRequestDALFactory,
|
TAccessApprovalRequestDALFactory,
|
||||||
| "create"
|
| "create"
|
||||||
|
| "find"
|
||||||
| "findRequestsWithPrivilegeByPolicyIds"
|
| "findRequestsWithPrivilegeByPolicyIds"
|
||||||
| "findById"
|
| "findById"
|
||||||
| "transaction"
|
| "transaction"
|
||||||
@@ -117,31 +118,33 @@ export const accessApprovalRequestServiceFactory = ({
|
|||||||
approvers.map((approver) => approver.approverId)
|
approvers.map((approver) => approver.approverId)
|
||||||
);
|
);
|
||||||
|
|
||||||
const duplicateRequest = await accessApprovalRequestDAL.findOne({
|
const duplicateRequests = await accessApprovalRequestDAL.find({
|
||||||
policyId: policy.id,
|
policyId: policy.id,
|
||||||
requestedBy: membership.id,
|
requestedBy: membership.id,
|
||||||
permissions: JSON.stringify(requestedPermissions),
|
permissions: JSON.stringify(requestedPermissions),
|
||||||
isTemporary
|
isTemporary
|
||||||
});
|
});
|
||||||
|
|
||||||
if (duplicateRequest) {
|
if (duplicateRequests?.length > 0) {
|
||||||
if (duplicateRequest.privilegeId) {
|
for await (const duplicateRequest of duplicateRequests) {
|
||||||
const privilege = await additionalPrivilegeDAL.findById(duplicateRequest.privilegeId);
|
if (duplicateRequest.privilegeId) {
|
||||||
|
const privilege = await additionalPrivilegeDAL.findById(duplicateRequest.privilegeId);
|
||||||
|
|
||||||
const isExpired = new Date() > new Date(privilege.temporaryAccessEndTime || ("" as string));
|
const isExpired = new Date() > new Date(privilege.temporaryAccessEndTime || ("" as string));
|
||||||
|
|
||||||
if (!isExpired || !privilege.isTemporary) {
|
if (!isExpired || !privilege.isTemporary) {
|
||||||
throw new BadRequestError({ message: "You already have an active privilege with the same criteria" });
|
throw new BadRequestError({ message: "You already have an active privilege with the same criteria" });
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
const reviewers = await accessApprovalRequestReviewerDAL.find({
|
const reviewers = await accessApprovalRequestReviewerDAL.find({
|
||||||
requestId: duplicateRequest.id
|
requestId: duplicateRequest.id
|
||||||
});
|
});
|
||||||
|
|
||||||
const isRejected = reviewers.some((reviewer) => reviewer.status === ApprovalStatus.REJECTED);
|
const isRejected = reviewers.some((reviewer) => reviewer.status === ApprovalStatus.REJECTED);
|
||||||
|
|
||||||
if (!isRejected) {
|
if (!isRejected) {
|
||||||
throw new BadRequestError({ message: "You already have a pending access request with the same criteria" });
|
throw new BadRequestError({ message: "You already have a pending access request with the same criteria" });
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user