mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 01:27:41 +00:00
fix: allow identities to list projects they are apart of
This commit is contained in:
@@ -173,7 +173,7 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY]),
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.API_KEY, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const workspaces = await server.services.project.getProjects({
|
const workspaces = await server.services.project.getProjects({
|
||||||
includeRoles: req.query.includeRoles,
|
includeRoles: req.query.includeRoles,
|
||||||
|
|||||||
@@ -22,6 +22,56 @@ export type TProjectDALFactory = ReturnType<typeof projectDALFactory>;
|
|||||||
export const projectDALFactory = (db: TDbClient) => {
|
export const projectDALFactory = (db: TDbClient) => {
|
||||||
const projectOrm = ormify(db, TableName.Project);
|
const projectOrm = ormify(db, TableName.Project);
|
||||||
|
|
||||||
|
const findIdentityProjects = async (identityId: string, orgId: string, projectType: ProjectType | "all") => {
|
||||||
|
try {
|
||||||
|
const workspaces = await db(TableName.IdentityProjectMembership)
|
||||||
|
.where({ identityId })
|
||||||
|
.join(TableName.Project, `${TableName.IdentityProjectMembership}.projectId`, `${TableName.Project}.id`)
|
||||||
|
.where(`${TableName.Project}.orgId`, orgId)
|
||||||
|
.andWhere((qb) => {
|
||||||
|
if (projectType !== "all") {
|
||||||
|
void qb.where(`${TableName.Project}.type`, projectType);
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.leftJoin(TableName.Environment, `${TableName.Environment}.projectId`, `${TableName.Project}.id`)
|
||||||
|
.select(
|
||||||
|
selectAllTableCols(TableName.Project),
|
||||||
|
db.ref("id").withSchema(TableName.Project).as("_id"),
|
||||||
|
db.ref("id").withSchema(TableName.Environment).as("envId"),
|
||||||
|
db.ref("slug").withSchema(TableName.Environment).as("envSlug"),
|
||||||
|
db.ref("name").withSchema(TableName.Environment).as("envName")
|
||||||
|
)
|
||||||
|
.orderBy([
|
||||||
|
{ column: `${TableName.Project}.name`, order: "asc" },
|
||||||
|
{ column: `${TableName.Environment}.position`, order: "asc" }
|
||||||
|
]);
|
||||||
|
|
||||||
|
const nestedWorkspaces = sqlNestRelationships({
|
||||||
|
data: workspaces,
|
||||||
|
key: "id",
|
||||||
|
parentMapper: ({ _id, ...el }) => ({ _id, ...ProjectsSchema.parse(el) }),
|
||||||
|
childrenMapper: [
|
||||||
|
{
|
||||||
|
key: "envId",
|
||||||
|
label: "environments" as const,
|
||||||
|
mapper: ({ envId: id, envSlug: slug, envName: name }) => ({
|
||||||
|
id,
|
||||||
|
slug,
|
||||||
|
name
|
||||||
|
})
|
||||||
|
}
|
||||||
|
]
|
||||||
|
});
|
||||||
|
|
||||||
|
return nestedWorkspaces.map((workspace) => ({
|
||||||
|
...workspace,
|
||||||
|
organization: workspace.orgId
|
||||||
|
}));
|
||||||
|
} catch (error) {
|
||||||
|
throw new DatabaseError({ error, name: "Find identity projects" });
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
const findUserProjects = async (userId: string, orgId: string, projectType: ProjectType | "all") => {
|
const findUserProjects = async (userId: string, orgId: string, projectType: ProjectType | "all") => {
|
||||||
try {
|
try {
|
||||||
const workspaces = await db
|
const workspaces = await db
|
||||||
@@ -443,6 +493,7 @@ export const projectDALFactory = (db: TDbClient) => {
|
|||||||
return {
|
return {
|
||||||
...projectOrm,
|
...projectOrm,
|
||||||
findUserProjects,
|
findUserProjects,
|
||||||
|
findIdentityProjects,
|
||||||
setProjectUpgradeStatus,
|
setProjectUpgradeStatus,
|
||||||
findAllProjectsByIdentity,
|
findAllProjectsByIdentity,
|
||||||
findProjectGhostUser,
|
findProjectGhostUser,
|
||||||
|
|||||||
@@ -573,12 +573,16 @@ export const projectServiceFactory = ({
|
|||||||
|
|
||||||
const getProjects = async ({
|
const getProjects = async ({
|
||||||
actorId,
|
actorId,
|
||||||
|
actor,
|
||||||
includeRoles,
|
includeRoles,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId,
|
actorOrgId,
|
||||||
type = ProjectType.SecretManager
|
type = ProjectType.SecretManager
|
||||||
}: TListProjectsDTO) => {
|
}: TListProjectsDTO) => {
|
||||||
const workspaces = await projectDAL.findUserProjects(actorId, actorOrgId, type);
|
const workspaces =
|
||||||
|
actor === ActorType.IDENTITY
|
||||||
|
? await projectDAL.findIdentityProjects(actorId, actorOrgId, type)
|
||||||
|
: await projectDAL.findUserProjects(actorId, actorOrgId, type);
|
||||||
|
|
||||||
if (includeRoles) {
|
if (includeRoles) {
|
||||||
const { permission } = await permissionService.getUserOrgPermission(
|
const { permission } = await permissionService.getUserOrgPermission(
|
||||||
|
|||||||
Reference in New Issue
Block a user