fix: allow identities to list projects they are apart of

This commit is contained in:
Daniel Hougaard
2025-06-01 00:12:56 +04:00
parent 4db82e37c1
commit dfcf613023
3 changed files with 57 additions and 2 deletions
@@ -173,7 +173,7 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
}) })
} }
}, },
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.IDENTITY_ACCESS_TOKEN]),
handler: async (req) => { handler: async (req) => {
const workspaces = await server.services.project.getProjects({ const workspaces = await server.services.project.getProjects({
includeRoles: req.query.includeRoles, includeRoles: req.query.includeRoles,
@@ -22,6 +22,56 @@ export type TProjectDALFactory = ReturnType<typeof projectDALFactory>;
export const projectDALFactory = (db: TDbClient) => { export const projectDALFactory = (db: TDbClient) => {
const projectOrm = ormify(db, TableName.Project); const projectOrm = ormify(db, TableName.Project);
const findIdentityProjects = async (identityId: string, orgId: string, projectType: ProjectType | "all") => {
try {
const workspaces = await db(TableName.IdentityProjectMembership)
.where({ identityId })
.join(TableName.Project, `${TableName.IdentityProjectMembership}.projectId`, `${TableName.Project}.id`)
.where(`${TableName.Project}.orgId`, orgId)
.andWhere((qb) => {
if (projectType !== "all") {
void qb.where(`${TableName.Project}.type`, projectType);
}
})
.leftJoin(TableName.Environment, `${TableName.Environment}.projectId`, `${TableName.Project}.id`)
.select(
selectAllTableCols(TableName.Project),
db.ref("id").withSchema(TableName.Project).as("_id"),
db.ref("id").withSchema(TableName.Environment).as("envId"),
db.ref("slug").withSchema(TableName.Environment).as("envSlug"),
db.ref("name").withSchema(TableName.Environment).as("envName")
)
.orderBy([
{ column: `${TableName.Project}.name`, order: "asc" },
{ column: `${TableName.Environment}.position`, order: "asc" }
]);
const nestedWorkspaces = sqlNestRelationships({
data: workspaces,
key: "id",
parentMapper: ({ _id, ...el }) => ({ _id, ...ProjectsSchema.parse(el) }),
childrenMapper: [
{
key: "envId",
label: "environments" as const,
mapper: ({ envId: id, envSlug: slug, envName: name }) => ({
id,
slug,
name
})
}
]
});
return nestedWorkspaces.map((workspace) => ({
...workspace,
organization: workspace.orgId
}));
} catch (error) {
throw new DatabaseError({ error, name: "Find identity projects" });
}
};
const findUserProjects = async (userId: string, orgId: string, projectType: ProjectType | "all") => { const findUserProjects = async (userId: string, orgId: string, projectType: ProjectType | "all") => {
try { try {
const workspaces = await db const workspaces = await db
@@ -443,6 +493,7 @@ export const projectDALFactory = (db: TDbClient) => {
return { return {
...projectOrm, ...projectOrm,
findUserProjects, findUserProjects,
findIdentityProjects,
setProjectUpgradeStatus, setProjectUpgradeStatus,
findAllProjectsByIdentity, findAllProjectsByIdentity,
findProjectGhostUser, findProjectGhostUser,
@@ -573,12 +573,16 @@ export const projectServiceFactory = ({
const getProjects = async ({ const getProjects = async ({
actorId, actorId,
actor,
includeRoles, includeRoles,
actorAuthMethod, actorAuthMethod,
actorOrgId, actorOrgId,
type = ProjectType.SecretManager type = ProjectType.SecretManager
}: TListProjectsDTO) => { }: TListProjectsDTO) => {
const workspaces = await projectDAL.findUserProjects(actorId, actorOrgId, type); const workspaces =
actor === ActorType.IDENTITY
? await projectDAL.findIdentityProjects(actorId, actorOrgId, type)
: await projectDAL.findUserProjects(actorId, actorOrgId, type);
if (includeRoles) { if (includeRoles) {
const { permission } = await permissionService.getUserOrgPermission( const { permission } = await permissionService.getUserOrgPermission(