mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 00:27:30 +00:00
misc: add endpoint for environment terraform resource
This commit is contained in:
@@ -106,6 +106,7 @@ export enum EventType {
|
|||||||
CREATE_ENVIRONMENT = "create-environment",
|
CREATE_ENVIRONMENT = "create-environment",
|
||||||
UPDATE_ENVIRONMENT = "update-environment",
|
UPDATE_ENVIRONMENT = "update-environment",
|
||||||
DELETE_ENVIRONMENT = "delete-environment",
|
DELETE_ENVIRONMENT = "delete-environment",
|
||||||
|
GET_ENVIRONMENT = "get-environment",
|
||||||
ADD_WORKSPACE_MEMBER = "add-workspace-member",
|
ADD_WORKSPACE_MEMBER = "add-workspace-member",
|
||||||
ADD_BATCH_WORKSPACE_MEMBER = "add-workspace-members",
|
ADD_BATCH_WORKSPACE_MEMBER = "add-workspace-members",
|
||||||
REMOVE_WORKSPACE_MEMBER = "remove-workspace-member",
|
REMOVE_WORKSPACE_MEMBER = "remove-workspace-member",
|
||||||
@@ -831,6 +832,13 @@ interface CreateEnvironmentEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface GetEnvironmentEvent {
|
||||||
|
type: EventType.GET_ENVIRONMENT;
|
||||||
|
metadata: {
|
||||||
|
id: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
interface UpdateEnvironmentEvent {
|
interface UpdateEnvironmentEvent {
|
||||||
type: EventType.UPDATE_ENVIRONMENT;
|
type: EventType.UPDATE_ENVIRONMENT;
|
||||||
metadata: {
|
metadata: {
|
||||||
@@ -1230,6 +1238,7 @@ export type Event =
|
|||||||
| UpdateIdentityOidcAuthEvent
|
| UpdateIdentityOidcAuthEvent
|
||||||
| GetIdentityOidcAuthEvent
|
| GetIdentityOidcAuthEvent
|
||||||
| CreateEnvironmentEvent
|
| CreateEnvironmentEvent
|
||||||
|
| GetEnvironmentEvent
|
||||||
| UpdateEnvironmentEvent
|
| UpdateEnvironmentEvent
|
||||||
| DeleteEnvironmentEvent
|
| DeleteEnvironmentEvent
|
||||||
| AddWorkspaceMemberEvent
|
| AddWorkspaceMemberEvent
|
||||||
|
|||||||
@@ -510,6 +510,10 @@ export const ENVIRONMENTS = {
|
|||||||
DELETE: {
|
DELETE: {
|
||||||
workspaceId: "The ID of the project to delete the environment from.",
|
workspaceId: "The ID of the project to delete the environment from.",
|
||||||
id: "The ID of the environment to delete."
|
id: "The ID of the environment to delete."
|
||||||
|
},
|
||||||
|
GET: {
|
||||||
|
workspaceId: "The ID of the project the environment belongs to.",
|
||||||
|
id: "The ID of the environment to fetch."
|
||||||
}
|
}
|
||||||
} as const;
|
} as const;
|
||||||
|
|
||||||
|
|||||||
@@ -9,6 +9,55 @@ import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
|||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
export const registerProjectEnvRouter = async (server: FastifyZodProvider) => {
|
export const registerProjectEnvRouter = async (server: FastifyZodProvider) => {
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: "/:workspaceId/environments/:envId",
|
||||||
|
config: {
|
||||||
|
rateLimit: writeLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
description: "Get Environment",
|
||||||
|
security: [
|
||||||
|
{
|
||||||
|
bearerAuth: []
|
||||||
|
}
|
||||||
|
],
|
||||||
|
params: z.object({
|
||||||
|
workspaceId: z.string().trim().describe(ENVIRONMENTS.GET.workspaceId),
|
||||||
|
envId: z.string().trim().describe(ENVIRONMENTS.GET.id)
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
environment: ProjectEnvironmentsSchema
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
|
handler: async (req) => {
|
||||||
|
const environment = await server.services.projectEnv.getEnvironmentById({
|
||||||
|
actorId: req.permission.id,
|
||||||
|
actor: req.permission.type,
|
||||||
|
actorOrgId: req.permission.orgId,
|
||||||
|
actorAuthMethod: req.permission.authMethod,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
id: req.params.envId
|
||||||
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
projectId: environment.projectId,
|
||||||
|
event: {
|
||||||
|
type: EventType.GET_ENVIRONMENT,
|
||||||
|
metadata: {
|
||||||
|
id: environment.id
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return { environment };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
server.route({
|
server.route({
|
||||||
method: "POST",
|
method: "POST",
|
||||||
url: "/:workspaceId/environments",
|
url: "/:workspaceId/environments",
|
||||||
|
|||||||
@@ -24,10 +24,15 @@ export const projectEnvDALFactory = (db: TDbClient) => {
|
|||||||
// we are using postion based sorting as its a small list
|
// we are using postion based sorting as its a small list
|
||||||
// this will return the last value of the position in a folder with secret imports
|
// this will return the last value of the position in a folder with secret imports
|
||||||
const findLastEnvPosition = async (projectId: string, tx?: Knex) => {
|
const findLastEnvPosition = async (projectId: string, tx?: Knex) => {
|
||||||
|
// acquire update lock on project environments.
|
||||||
|
// this ensures that concurrent invocations will wait and execute sequentially
|
||||||
|
await (tx || db)(TableName.Environment).where({ projectId }).forUpdate();
|
||||||
|
|
||||||
const lastPos = await (tx || db)(TableName.Environment)
|
const lastPos = await (tx || db)(TableName.Environment)
|
||||||
.where({ projectId })
|
.where({ projectId })
|
||||||
.max("position", { as: "position" })
|
.max("position", { as: "position" })
|
||||||
.first();
|
.first();
|
||||||
|
|
||||||
return lastPos?.position || 0;
|
return lastPos?.position || 0;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -3,12 +3,12 @@ import { ForbiddenError } from "@casl/ability";
|
|||||||
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
||||||
|
|
||||||
import { TProjectDALFactory } from "../project/project-dal";
|
import { TProjectDALFactory } from "../project/project-dal";
|
||||||
import { TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
import { TSecretFolderDALFactory } from "../secret-folder/secret-folder-dal";
|
||||||
import { TProjectEnvDALFactory } from "./project-env-dal";
|
import { TProjectEnvDALFactory } from "./project-env-dal";
|
||||||
import { TCreateEnvDTO, TDeleteEnvDTO, TUpdateEnvDTO } from "./project-env-types";
|
import { TCreateEnvDTO, TDeleteEnvDTO, TGetEnvDTO, TUpdateEnvDTO } from "./project-env-types";
|
||||||
|
|
||||||
type TProjectEnvServiceFactoryDep = {
|
type TProjectEnvServiceFactoryDep = {
|
||||||
projectEnvDAL: TProjectEnvDALFactory;
|
projectEnvDAL: TProjectEnvDALFactory;
|
||||||
@@ -139,9 +139,35 @@ export const projectEnvServiceFactory = ({
|
|||||||
return env;
|
return env;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const getEnvironmentById = async ({ projectId, actor, actorId, actorOrgId, actorAuthMethod, id }: TGetEnvDTO) => {
|
||||||
|
const { permission } = await permissionService.getProjectPermission(
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
projectId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
);
|
||||||
|
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Environments);
|
||||||
|
|
||||||
|
const [env] = await projectEnvDAL.find({
|
||||||
|
id,
|
||||||
|
projectId
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!env) {
|
||||||
|
throw new NotFoundError({
|
||||||
|
message: "Environment does not exist"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return env;
|
||||||
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
createEnvironment,
|
createEnvironment,
|
||||||
updateEnvironment,
|
updateEnvironment,
|
||||||
deleteEnvironment
|
deleteEnvironment,
|
||||||
|
getEnvironmentById
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -20,3 +20,7 @@ export type TReorderEnvDTO = {
|
|||||||
id: string;
|
id: string;
|
||||||
pos: number;
|
pos: number;
|
||||||
} & TProjectPermission;
|
} & TProjectPermission;
|
||||||
|
|
||||||
|
export type TGetEnvDTO = {
|
||||||
|
id: string;
|
||||||
|
} & TProjectPermission;
|
||||||
|
|||||||
Reference in New Issue
Block a user