mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 17:27:40 +00:00
feat(secret-approval): added permission for policy management and fixed bugs on fellow user reviewing secrets
This commit is contained in:
@@ -6,8 +6,9 @@ import { ApprovalStatus, SecretApprovalRequest } from "../../models/secretApprov
|
|||||||
import * as reqValidator from "../../validation/secretApprovalRequest";
|
import * as reqValidator from "../../validation/secretApprovalRequest";
|
||||||
import { getFolderWithPathFromId } from "../../services/FolderService";
|
import { getFolderWithPathFromId } from "../../services/FolderService";
|
||||||
import { BadRequestError, UnauthorizedRequestError } from "../../utils/errors";
|
import { BadRequestError, UnauthorizedRequestError } from "../../utils/errors";
|
||||||
import { ISecretApprovalPolicy } from "../../models/secretApprovalPolicy";
|
import { ISecretApprovalPolicy, SecretApprovalPolicy } from "../../models/secretApprovalPolicy";
|
||||||
import { performSecretApprovalRequestMerge } from "../../services/SecretApprovalService";
|
import { performSecretApprovalRequestMerge } from "../../services/SecretApprovalService";
|
||||||
|
import { Types } from "mongoose";
|
||||||
|
|
||||||
export const getSecretApprovalRequests = async (req: Request, res: Response) => {
|
export const getSecretApprovalRequests = async (req: Request, res: Response) => {
|
||||||
const {
|
const {
|
||||||
@@ -17,24 +18,43 @@ export const getSecretApprovalRequests = async (req: Request, res: Response) =>
|
|||||||
const { membership } = await getUserProjectPermissions(req.user._id, workspaceId);
|
const { membership } = await getUserProjectPermissions(req.user._id, workspaceId);
|
||||||
|
|
||||||
const query = {
|
const query = {
|
||||||
workspace: workspaceId,
|
workspace: new Types.ObjectId(workspaceId),
|
||||||
environment,
|
environment,
|
||||||
committer,
|
committer: committer ? new Types.ObjectId(committer) : undefined,
|
||||||
status,
|
status
|
||||||
...(membership.role !== "admin"
|
|
||||||
? { $or: [{ committer: membership.id }, { "policy.approvers": membership.id }] }
|
|
||||||
: {})
|
|
||||||
};
|
};
|
||||||
// to strip of undefined in query we use es6 spread to ignore those fields
|
// to strip of undefined in query we use es6 spread to ignore those fields
|
||||||
Object.entries(query).forEach(
|
Object.entries(query).forEach(
|
||||||
([key, value]) => value === undefined && delete query[key as keyof typeof query]
|
([key, value]) => value === undefined && delete query[key as keyof typeof query]
|
||||||
);
|
);
|
||||||
const approvalRequests = await SecretApprovalRequest.find(query)
|
const approvalRequests = await SecretApprovalRequest.aggregate([
|
||||||
.sort({ createdAt: -1 })
|
{
|
||||||
.limit(limit)
|
$match: query
|
||||||
.skip(offset)
|
},
|
||||||
.populate("policy")
|
{
|
||||||
.lean();
|
$lookup: {
|
||||||
|
from: SecretApprovalPolicy.collection.name,
|
||||||
|
localField: "policy",
|
||||||
|
foreignField: "_id",
|
||||||
|
as: "policy"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{ $unwind: "$policy" },
|
||||||
|
...(membership.role !== "admin"
|
||||||
|
? [
|
||||||
|
{
|
||||||
|
$match: {
|
||||||
|
$or: [
|
||||||
|
{ committer: new Types.ObjectId(membership.id) },
|
||||||
|
{ "policy.approvers": new Types.ObjectId(membership.id) }
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
: []),
|
||||||
|
{ $skip: offset },
|
||||||
|
{ $limit: limit }
|
||||||
|
]);
|
||||||
if (!approvalRequests.length) return res.send({ approvals: [] });
|
if (!approvalRequests.length) return res.send({ approvals: [] });
|
||||||
|
|
||||||
const unqiueEnvs = environment ?? {
|
const unqiueEnvs = environment ?? {
|
||||||
@@ -114,7 +134,7 @@ export const updateSecretApprovalReviewStatus = async (req: Request, res: Respon
|
|||||||
if (
|
if (
|
||||||
membership.role !== "admin" &&
|
membership.role !== "admin" &&
|
||||||
secretApprovalRequest.committer !== membership.id &&
|
secretApprovalRequest.committer !== membership.id &&
|
||||||
!secretApprovalRequest.policy.approvers.find((approverId) => approverId === membership.id)
|
!secretApprovalRequest.policy.approvers.find((approverId) => approverId.equals(membership.id))
|
||||||
) {
|
) {
|
||||||
throw UnauthorizedRequestError({ message: "User has no access" });
|
throw UnauthorizedRequestError({ message: "User has no access" });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -42,7 +42,7 @@ export const getSecretPolicyOfBoard = async (
|
|||||||
// now sort by priority. exact secret path gets first match followed by glob followed by just env scoped
|
// now sort by priority. exact secret path gets first match followed by glob followed by just env scoped
|
||||||
// if that is tie get by first createdAt
|
// if that is tie get by first createdAt
|
||||||
const policiesByPriority = policiesFilteredByPath.sort(
|
const policiesByPriority = policiesFilteredByPath.sort(
|
||||||
(a, b) => getPolicyScore(a) - getPolicyScore(b)
|
(a, b) => getPolicyScore(b) - getPolicyScore(a)
|
||||||
);
|
);
|
||||||
const finalPolicy = policiesByPriority.shift();
|
const finalPolicy = policiesByPriority.shift();
|
||||||
return finalPolicy;
|
return finalPolicy;
|
||||||
|
|||||||
@@ -20,7 +20,8 @@ export enum ProjectPermissionSub {
|
|||||||
IpAllowList = "ip-allowlist",
|
IpAllowList = "ip-allowlist",
|
||||||
Workspace = "workspace",
|
Workspace = "workspace",
|
||||||
Secrets = "secrets",
|
Secrets = "secrets",
|
||||||
SecretRollback = "secret-rollback"
|
SecretRollback = "secret-rollback",
|
||||||
|
SecretApproval = "secret-approval"
|
||||||
}
|
}
|
||||||
|
|
||||||
type SubjectFields = {
|
type SubjectFields = {
|
||||||
@@ -43,6 +44,7 @@ export type ProjectPermissionSet =
|
|||||||
| [ProjectPermissionActions, ProjectPermissionSub.IpAllowList]
|
| [ProjectPermissionActions, ProjectPermissionSub.IpAllowList]
|
||||||
| [ProjectPermissionActions, ProjectPermissionSub.Settings]
|
| [ProjectPermissionActions, ProjectPermissionSub.Settings]
|
||||||
| [ProjectPermissionActions, ProjectPermissionSub.ServiceTokens]
|
| [ProjectPermissionActions, ProjectPermissionSub.ServiceTokens]
|
||||||
|
| [ProjectPermissionActions, ProjectPermissionSub.SecretApproval]
|
||||||
| [ProjectPermissionActions.Delete, ProjectPermissionSub.Workspace]
|
| [ProjectPermissionActions.Delete, ProjectPermissionSub.Workspace]
|
||||||
| [ProjectPermissionActions.Edit, ProjectPermissionSub.Workspace]
|
| [ProjectPermissionActions.Edit, ProjectPermissionSub.Workspace]
|
||||||
| [ProjectPermissionActions.Read, ProjectPermissionSub.SecretRollback]
|
| [ProjectPermissionActions.Read, ProjectPermissionSub.SecretRollback]
|
||||||
|
|||||||
@@ -9,13 +9,14 @@ export const useCreateSecretApprovalPolicy = () => {
|
|||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation<{}, {}, TCreateSecretPolicyDTO>({
|
return useMutation<{}, {}, TCreateSecretPolicyDTO>({
|
||||||
mutationFn: async ({ environment, workspaceId, approvals, approvers, secretPath }) => {
|
mutationFn: async ({ environment, workspaceId, approvals, approvers, secretPath, name }) => {
|
||||||
const { data } = await apiRequest.post("/api/v1/secret-approvals", {
|
const { data } = await apiRequest.post("/api/v1/secret-approvals", {
|
||||||
environment,
|
environment,
|
||||||
workspaceId,
|
workspaceId,
|
||||||
approvals,
|
approvals,
|
||||||
approvers,
|
approvers,
|
||||||
secretPath
|
secretPath,
|
||||||
|
name
|
||||||
});
|
});
|
||||||
return data;
|
return data;
|
||||||
},
|
},
|
||||||
@@ -29,11 +30,12 @@ export const useUpdateSecretApprovalPolicy = () => {
|
|||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation<{}, {}, TUpdateSecretPolicyDTO>({
|
return useMutation<{}, {}, TUpdateSecretPolicyDTO>({
|
||||||
mutationFn: async ({ id, approvers, approvals, secretPath }) => {
|
mutationFn: async ({ id, approvers, approvals, secretPath, name }) => {
|
||||||
const { data } = await apiRequest.patch(`/api/v1/secret-approvals/${id}`, {
|
const { data } = await apiRequest.patch(`/api/v1/secret-approvals/${id}`, {
|
||||||
approvals,
|
approvals,
|
||||||
approvers,
|
approvers,
|
||||||
secretPath
|
secretPath,
|
||||||
|
name
|
||||||
});
|
});
|
||||||
return data;
|
return data;
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -20,6 +20,7 @@ export type TGetSecretApprovalPolicyOfBoardDTO = {
|
|||||||
|
|
||||||
export type TCreateSecretPolicyDTO = {
|
export type TCreateSecretPolicyDTO = {
|
||||||
workspaceId: string;
|
workspaceId: string;
|
||||||
|
name?: string;
|
||||||
environment: string;
|
environment: string;
|
||||||
secretPath?: string | null;
|
secretPath?: string | null;
|
||||||
approvers?: string[];
|
approvers?: string[];
|
||||||
@@ -28,6 +29,7 @@ export type TCreateSecretPolicyDTO = {
|
|||||||
|
|
||||||
export type TUpdateSecretPolicyDTO = {
|
export type TUpdateSecretPolicyDTO = {
|
||||||
id: string;
|
id: string;
|
||||||
|
name?: string;
|
||||||
approvers?: string[];
|
approvers?: string[];
|
||||||
secretPath?: string | null;
|
secretPath?: string | null;
|
||||||
approvals?: number;
|
approvals?: number;
|
||||||
|
|||||||
+8
-1
@@ -9,6 +9,7 @@ import {
|
|||||||
faLock,
|
faLock,
|
||||||
faNetworkWired,
|
faNetworkWired,
|
||||||
faPuzzlePiece,
|
faPuzzlePiece,
|
||||||
|
faShield,
|
||||||
faTags,
|
faTags,
|
||||||
faUser,
|
faUser,
|
||||||
faUsers
|
faUsers
|
||||||
@@ -18,7 +19,7 @@ import { zodResolver } from "@hookform/resolvers/zod";
|
|||||||
|
|
||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
import { Button, FormControl, Input, UpgradePlanModal } from "@app/components/v2";
|
import { Button, FormControl, Input, UpgradePlanModal } from "@app/components/v2";
|
||||||
import { useOrganization, useSubscription, useWorkspace } from "@app/context";
|
import { ProjectPermissionSub, useOrganization, useSubscription, useWorkspace } from "@app/context";
|
||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
import { useCreateRole, useUpdateRole } from "@app/hooks/api";
|
import { useCreateRole, useUpdateRole } from "@app/hooks/api";
|
||||||
import { TRole } from "@app/hooks/api/roles/types";
|
import { TRole } from "@app/hooks/api/roles/types";
|
||||||
@@ -41,6 +42,12 @@ const SINGLE_PERMISSION_LIST = [
|
|||||||
icon: faPuzzlePiece,
|
icon: faPuzzlePiece,
|
||||||
formName: "integrations"
|
formName: "integrations"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
title: "Secret Protect policy",
|
||||||
|
subtitle: "Manage policies for secret protection for unauthorized secret changes",
|
||||||
|
icon: faShield,
|
||||||
|
formName: ProjectPermissionSub.SecretApproval
|
||||||
|
},
|
||||||
{
|
{
|
||||||
title: "Roles",
|
title: "Roles",
|
||||||
subtitle: "Role management control",
|
subtitle: "Role management control",
|
||||||
|
|||||||
+3
@@ -1,6 +1,7 @@
|
|||||||
/* eslint-disable no-param-reassign */
|
/* eslint-disable no-param-reassign */
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { ProjectPermissionSub } from "@app/context";
|
||||||
import { TProjectPermission } from "@app/hooks/api/roles/types";
|
import { TProjectPermission } from "@app/hooks/api/roles/types";
|
||||||
|
|
||||||
const generalPermissionSchema = z
|
const generalPermissionSchema = z
|
||||||
@@ -41,6 +42,8 @@ export const formSchema = z.object({
|
|||||||
tags: generalPermissionSchema,
|
tags: generalPermissionSchema,
|
||||||
"audit-logs": generalPermissionSchema,
|
"audit-logs": generalPermissionSchema,
|
||||||
"ip-allowlist": generalPermissionSchema,
|
"ip-allowlist": generalPermissionSchema,
|
||||||
|
// akhilmhdh: refactor all keys like below
|
||||||
|
[ProjectPermissionSub.SecretApproval]: generalPermissionSchema,
|
||||||
workspace: z
|
workspace: z
|
||||||
.object({
|
.object({
|
||||||
edit: z.boolean().optional(),
|
edit: z.boolean().optional(),
|
||||||
|
|||||||
+3
-1
@@ -6,6 +6,7 @@ import { motion } from "framer-motion";
|
|||||||
import { twMerge } from "tailwind-merge";
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
import { Checkbox, Select, SelectItem } from "@app/components/v2";
|
import { Checkbox, Select, SelectItem } from "@app/components/v2";
|
||||||
|
import { ProjectPermissionSub } from "@app/context";
|
||||||
import { useToggle } from "@app/hooks";
|
import { useToggle } from "@app/hooks";
|
||||||
|
|
||||||
import { TFormSchema } from "./ProjectRoleModifySection.utils";
|
import { TFormSchema } from "./ProjectRoleModifySection.utils";
|
||||||
@@ -21,7 +22,8 @@ type Props = {
|
|||||||
| "environments"
|
| "environments"
|
||||||
| "tags"
|
| "tags"
|
||||||
| "audit-logs"
|
| "audit-logs"
|
||||||
| "ip-allowlist";
|
| "ip-allowlist"
|
||||||
|
| ProjectPermissionSub.SecretApproval;
|
||||||
isNonEditable?: boolean;
|
isNonEditable?: boolean;
|
||||||
setValue: UseFormSetValue<TFormSchema>;
|
setValue: UseFormSetValue<TFormSchema>;
|
||||||
control: Control<TFormSchema>;
|
control: Control<TFormSchema>;
|
||||||
|
|||||||
@@ -14,9 +14,9 @@ export const SecretApprovalPage = () => {
|
|||||||
const workspaceId = currentWorkspace?._id || "";
|
const workspaceId = currentWorkspace?._id || "";
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="container mx-auto bg-bunker-800 text-white w-full h-full">
|
<div className="container mx-auto bg-bunker-800 text-white w-full h-full max-w-7xl">
|
||||||
<div className="my-6">
|
<div className="my-6">
|
||||||
<p className="text-3xl font-semibold text-gray-200">Admin Panels</p>
|
<p className="text-3xl font-semibold text-gray-200">Secret Approvals</p>
|
||||||
</div>
|
</div>
|
||||||
<Tabs defaultValue={TabSection.ApprovalRequests}>
|
<Tabs defaultValue={TabSection.ApprovalRequests}>
|
||||||
<TabList>
|
<TabList>
|
||||||
|
|||||||
+20
-6
@@ -2,6 +2,7 @@ import { faFileShield, faPlus } from "@fortawesome/free-solid-svg-icons";
|
|||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
|
import { ProjectPermissionCan } from "@app/components/permissions";
|
||||||
import {
|
import {
|
||||||
Button,
|
Button,
|
||||||
DeleteActionModal,
|
DeleteActionModal,
|
||||||
@@ -15,6 +16,7 @@ import {
|
|||||||
THead,
|
THead,
|
||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
|
import { ProjectPermissionActions, ProjectPermissionSub, useProjectPermission } from "@app/context";
|
||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
import {
|
import {
|
||||||
useDeleteSecretApprovalPolicy,
|
useDeleteSecretApprovalPolicy,
|
||||||
@@ -35,11 +37,15 @@ export const SecretApprovalPolicyList = ({ workspaceId }: Props) => {
|
|||||||
"secretPolicyForm",
|
"secretPolicyForm",
|
||||||
"deletePolicy"
|
"deletePolicy"
|
||||||
] as const);
|
] as const);
|
||||||
|
const permission = useProjectPermission();
|
||||||
const { createNotification } = useNotificationContext();
|
const { createNotification } = useNotificationContext();
|
||||||
|
|
||||||
const { data: members } = useGetWorkspaceUsers(workspaceId);
|
const { data: members } = useGetWorkspaceUsers(workspaceId);
|
||||||
const { data: policies, isLoading: isPoliciesLoading } = useGetSecretApprovalPolicies({
|
const { data: policies, isLoading: isPoliciesLoading } = useGetSecretApprovalPolicies({
|
||||||
workspaceId
|
workspaceId,
|
||||||
|
options: {
|
||||||
|
enabled: permission.can(ProjectPermissionActions.Read, ProjectPermissionSub.SecretApproval)
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
const { mutateAsync: deleteSecretApprovalPolicy } = useDeleteSecretApprovalPolicy();
|
const { mutateAsync: deleteSecretApprovalPolicy } = useDeleteSecretApprovalPolicy();
|
||||||
@@ -75,12 +81,20 @@ export const SecretApprovalPolicyList = ({ workspaceId }: Props) => {
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div>
|
<div>
|
||||||
<Button
|
<ProjectPermissionCan
|
||||||
onClick={() => handlePopUpOpen("secretPolicyForm")}
|
I={ProjectPermissionActions.Create}
|
||||||
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
a={ProjectPermissionSub.SecretApproval}
|
||||||
>
|
>
|
||||||
Create policy
|
{(isAllowed) => (
|
||||||
</Button>
|
<Button
|
||||||
|
onClick={() => handlePopUpOpen("secretPolicyForm")}
|
||||||
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
|
isDisabled={!isAllowed}
|
||||||
|
>
|
||||||
|
Create policy
|
||||||
|
</Button>
|
||||||
|
)}
|
||||||
|
</ProjectPermissionCan>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<TableContainer>
|
<TableContainer>
|
||||||
|
|||||||
+41
-18
@@ -2,6 +2,7 @@ import { useState } from "react";
|
|||||||
import { faCheckCircle, faPencil, faTrash } from "@fortawesome/free-solid-svg-icons";
|
import { faCheckCircle, faPencil, faTrash } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
|
import { ProjectPermissionCan } from "@app/components/permissions";
|
||||||
import {
|
import {
|
||||||
DropdownMenu,
|
DropdownMenu,
|
||||||
DropdownMenuContent,
|
DropdownMenuContent,
|
||||||
@@ -11,9 +12,9 @@ import {
|
|||||||
IconButton,
|
IconButton,
|
||||||
Input,
|
Input,
|
||||||
Td,
|
Td,
|
||||||
Tooltip,
|
|
||||||
Tr
|
Tr
|
||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
|
import { ProjectPermissionActions, ProjectPermissionSub, useProjectPermission } from "@app/context";
|
||||||
import { useUpdateSecretApprovalPolicy } from "@app/hooks/api";
|
import { useUpdateSecretApprovalPolicy } from "@app/hooks/api";
|
||||||
import { TSecretApprovalPolicy } from "@app/hooks/api/types";
|
import { TSecretApprovalPolicy } from "@app/hooks/api/types";
|
||||||
import { TWorkspaceUser } from "@app/hooks/api/users/types";
|
import { TWorkspaceUser } from "@app/hooks/api/users/types";
|
||||||
@@ -35,6 +36,7 @@ export const SecretApprovalPolicyRow = ({
|
|||||||
}: Props) => {
|
}: Props) => {
|
||||||
const [selectedApprovers, setSelectedApprovers] = useState<string[]>([]);
|
const [selectedApprovers, setSelectedApprovers] = useState<string[]>([]);
|
||||||
const { mutate: updateSecretApprovalPolicy, isLoading } = useUpdateSecretApprovalPolicy();
|
const { mutate: updateSecretApprovalPolicy, isLoading } = useUpdateSecretApprovalPolicy();
|
||||||
|
const permission = useProjectPermission();
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<Tr>
|
<Tr>
|
||||||
@@ -62,7 +64,13 @@ export const SecretApprovalPolicyRow = ({
|
|||||||
}
|
}
|
||||||
}}
|
}}
|
||||||
>
|
>
|
||||||
<DropdownMenuTrigger asChild disabled={isLoading}>
|
<DropdownMenuTrigger
|
||||||
|
asChild
|
||||||
|
disabled={
|
||||||
|
isLoading ||
|
||||||
|
permission.cannot(ProjectPermissionActions.Edit, ProjectPermissionSub.SecretApproval)
|
||||||
|
}
|
||||||
|
>
|
||||||
<Input
|
<Input
|
||||||
isReadOnly
|
isReadOnly
|
||||||
value={policy.approvers?.length ? `${policy.approvers.length} selected` : "None"}
|
value={policy.approvers?.length ? `${policy.approvers.length} selected` : "None"}
|
||||||
@@ -98,22 +106,37 @@ export const SecretApprovalPolicyRow = ({
|
|||||||
<Td>{policy.approvals}</Td>
|
<Td>{policy.approvals}</Td>
|
||||||
<Td>
|
<Td>
|
||||||
<div className="flex items-center justify-end space-x-4">
|
<div className="flex items-center justify-end space-x-4">
|
||||||
<Tooltip content="Edit">
|
<ProjectPermissionCan
|
||||||
<IconButton variant="plain" ariaLabel="edit" onClick={onEdit}>
|
I={ProjectPermissionActions.Edit}
|
||||||
<FontAwesomeIcon icon={faPencil} size="lg" />
|
a={ProjectPermissionSub.SecretApproval}
|
||||||
</IconButton>
|
renderTooltip
|
||||||
</Tooltip>
|
allowedLabel="Edit"
|
||||||
<Tooltip content="Delete">
|
>
|
||||||
<IconButton
|
{(isAllowed) => (
|
||||||
variant="plain"
|
<IconButton variant="plain" ariaLabel="edit" onClick={onEdit} isDisabled={!isAllowed}>
|
||||||
colorSchema="danger"
|
<FontAwesomeIcon icon={faPencil} size="lg" />
|
||||||
size="lg"
|
</IconButton>
|
||||||
ariaLabel="edit"
|
)}
|
||||||
onClick={onDelete}
|
</ProjectPermissionCan>
|
||||||
>
|
<ProjectPermissionCan
|
||||||
<FontAwesomeIcon icon={faTrash} />
|
I={ProjectPermissionActions.Delete}
|
||||||
</IconButton>
|
a={ProjectPermissionSub.SecretApproval}
|
||||||
</Tooltip>
|
renderTooltip
|
||||||
|
allowedLabel="Delete"
|
||||||
|
>
|
||||||
|
{(isAllowed) => (
|
||||||
|
<IconButton
|
||||||
|
variant="plain"
|
||||||
|
colorSchema="danger"
|
||||||
|
size="lg"
|
||||||
|
ariaLabel="edit"
|
||||||
|
onClick={onDelete}
|
||||||
|
isDisabled={!isAllowed}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={faTrash} />
|
||||||
|
</IconButton>
|
||||||
|
)}
|
||||||
|
</ProjectPermissionCan>
|
||||||
</div>
|
</div>
|
||||||
</Td>
|
</Td>
|
||||||
</Tr>
|
</Tr>
|
||||||
|
|||||||
+4
-2
@@ -19,6 +19,7 @@ export type Props = {
|
|||||||
secretVersion?: DecryptedSecret;
|
secretVersion?: DecryptedSecret;
|
||||||
newVersion?: Omit<TSecretApprovalSecChange, "tags"> & { tags?: WsTag[] };
|
newVersion?: Omit<TSecretApprovalSecChange, "tags"> & { tags?: WsTag[] };
|
||||||
presentSecretVersionNumber: number;
|
presentSecretVersionNumber: number;
|
||||||
|
hasMerged?: Boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
const generateItemTitle = (op: CommitType) => {
|
const generateItemTitle = (op: CommitType) => {
|
||||||
@@ -38,10 +39,11 @@ export const SecretApprovalRequestChangeItem = ({
|
|||||||
op,
|
op,
|
||||||
secretVersion,
|
secretVersion,
|
||||||
newVersion,
|
newVersion,
|
||||||
presentSecretVersionNumber
|
presentSecretVersionNumber,
|
||||||
|
hasMerged
|
||||||
}: Props) => {
|
}: Props) => {
|
||||||
// meaning request has changed
|
// meaning request has changed
|
||||||
const isStale = (secretVersion?.version || 1) < presentSecretVersionNumber;
|
const isStale = (secretVersion?.version || 1) < presentSecretVersionNumber && !hasMerged;
|
||||||
return (
|
return (
|
||||||
<div className="bg-bunker-500 rounded-lg pt-2 pb-4 px-4">
|
<div className="bg-bunker-500 rounded-lg pt-2 pb-4 px-4">
|
||||||
<div className="py-3 px-1 flex items-center">
|
<div className="py-3 px-1 flex items-center">
|
||||||
|
|||||||
+1
@@ -211,6 +211,7 @@ export const SecretApprovalRequestChanges = ({
|
|||||||
({ op, secretVersion, secret, newVersion }, index) => (
|
({ op, secretVersion, secret, newVersion }, index) => (
|
||||||
<SecretApprovalRequestChangeItem
|
<SecretApprovalRequestChangeItem
|
||||||
op={op}
|
op={op}
|
||||||
|
hasMerged={hasMerged}
|
||||||
secretVersion={secretVersion}
|
secretVersion={secretVersion}
|
||||||
presentSecretVersionNumber={secret?.version || 0}
|
presentSecretVersionNumber={secret?.version || 0}
|
||||||
newVersion={newVersion}
|
newVersion={newVersion}
|
||||||
|
|||||||
Reference in New Issue
Block a user