mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 04:27:29 +00:00
Remove role and roleId from group project membership
This commit is contained in:
@@ -37,9 +37,6 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
if (!(await knex.schema.hasTable(TableName.GroupProjectMembership))) {
|
if (!(await knex.schema.hasTable(TableName.GroupProjectMembership))) {
|
||||||
await knex.schema.createTable(TableName.GroupProjectMembership, (t) => {
|
await knex.schema.createTable(TableName.GroupProjectMembership, (t) => {
|
||||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||||
t.string("role").notNullable();
|
|
||||||
t.uuid("roleId");
|
|
||||||
t.foreign("roleId").references("id").inTable(TableName.ProjectRoles);
|
|
||||||
t.string("projectId").notNullable();
|
t.string("projectId").notNullable();
|
||||||
t.foreign("projectId").references("id").inTable(TableName.Project).onDelete("CASCADE");
|
t.foreign("projectId").references("id").inTable(TableName.Project).onDelete("CASCADE");
|
||||||
t.uuid("groupId").notNullable();
|
t.uuid("groupId").notNullable();
|
||||||
|
|||||||
@@ -9,8 +9,6 @@ import { TImmutableDBKeys } from "./models";
|
|||||||
|
|
||||||
export const GroupProjectMembershipsSchema = z.object({
|
export const GroupProjectMembershipsSchema = z.object({
|
||||||
id: z.string().uuid(),
|
id: z.string().uuid(),
|
||||||
role: z.string(),
|
|
||||||
roleId: z.string().uuid().nullable().optional(),
|
|
||||||
projectId: z.string(),
|
projectId: z.string(),
|
||||||
groupId: z.string().uuid(),
|
groupId: z.string().uuid(),
|
||||||
createdAt: z.date(),
|
createdAt: z.date(),
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ export const getDefaultOnPremFeatures = () => {
|
|||||||
secretVersioning: true,
|
secretVersioning: true,
|
||||||
pitRecovery: false,
|
pitRecovery: false,
|
||||||
ipAllowlisting: true,
|
ipAllowlisting: true,
|
||||||
rbac: false,
|
rbac: true,
|
||||||
customRateLimits: false,
|
customRateLimits: false,
|
||||||
customAlerts: false,
|
customAlerts: false,
|
||||||
auditLogs: false,
|
auditLogs: false,
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
|
|||||||
secretVersioning: true,
|
secretVersioning: true,
|
||||||
pitRecovery: false,
|
pitRecovery: false,
|
||||||
ipAllowlisting: false,
|
ipAllowlisting: false,
|
||||||
rbac: false,
|
rbac: true,
|
||||||
customRateLimits: false,
|
customRateLimits: false,
|
||||||
customAlerts: false,
|
customAlerts: false,
|
||||||
auditLogs: false,
|
auditLogs: false,
|
||||||
|
|||||||
@@ -35,7 +35,7 @@ export type TFeatureSet = {
|
|||||||
secretVersioning: true;
|
secretVersioning: true;
|
||||||
pitRecovery: false;
|
pitRecovery: false;
|
||||||
ipAllowlisting: false;
|
ipAllowlisting: false;
|
||||||
rbac: false;
|
rbac: true;
|
||||||
customRateLimits: false;
|
customRateLimits: false;
|
||||||
customAlerts: false;
|
customAlerts: false;
|
||||||
auditLogs: false;
|
auditLogs: false;
|
||||||
|
|||||||
@@ -73,7 +73,6 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
.select(
|
.select(
|
||||||
db.ref("id").withSchema(TableName.GroupProjectMembership).as("membershipId"),
|
db.ref("id").withSchema(TableName.GroupProjectMembership).as("membershipId"),
|
||||||
// TODO(roll-forward-migration): remove this field when we drop this in next migration after a week
|
// TODO(roll-forward-migration): remove this field when we drop this in next migration after a week
|
||||||
db.ref("role").withSchema(TableName.GroupProjectMembership).as("oldRoleField"),
|
|
||||||
db.ref("createdAt").withSchema(TableName.GroupProjectMembership).as("membershipCreatedAt"),
|
db.ref("createdAt").withSchema(TableName.GroupProjectMembership).as("membershipCreatedAt"),
|
||||||
db.ref("updatedAt").withSchema(TableName.GroupProjectMembership).as("membershipUpdatedAt"),
|
db.ref("updatedAt").withSchema(TableName.GroupProjectMembership).as("membershipUpdatedAt"),
|
||||||
db.ref("projectId").withSchema(TableName.GroupProjectMembership),
|
db.ref("projectId").withSchema(TableName.GroupProjectMembership),
|
||||||
@@ -102,7 +101,6 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
.select(
|
.select(
|
||||||
db.ref("id").withSchema(TableName.ProjectMembership).as("membershipId"),
|
db.ref("id").withSchema(TableName.ProjectMembership).as("membershipId"),
|
||||||
// TODO(roll-forward-migration): remove this field when we drop this in next migration after a week
|
// TODO(roll-forward-migration): remove this field when we drop this in next migration after a week
|
||||||
db.ref("role").withSchema(TableName.ProjectMembership).as("oldRoleField"),
|
|
||||||
db.ref("createdAt").withSchema(TableName.ProjectMembership).as("membershipCreatedAt"),
|
db.ref("createdAt").withSchema(TableName.ProjectMembership).as("membershipCreatedAt"),
|
||||||
db.ref("updatedAt").withSchema(TableName.ProjectMembership).as("membershipUpdatedAt"),
|
db.ref("updatedAt").withSchema(TableName.ProjectMembership).as("membershipUpdatedAt"),
|
||||||
db.ref("projectId").withSchema(TableName.ProjectMembership),
|
db.ref("projectId").withSchema(TableName.ProjectMembership),
|
||||||
@@ -115,18 +113,11 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
const permission = sqlNestRelationships({
|
const permission = sqlNestRelationships({
|
||||||
data: docs.concat(groupDocs),
|
data: docs.concat(groupDocs),
|
||||||
key: "projectId",
|
key: "projectId",
|
||||||
parentMapper: ({
|
parentMapper: ({ orgId, orgAuthEnforced, membershipId, membershipCreatedAt, membershipUpdatedAt, role }) => ({
|
||||||
orgId,
|
|
||||||
orgAuthEnforced,
|
|
||||||
membershipId,
|
|
||||||
membershipCreatedAt,
|
|
||||||
membershipUpdatedAt,
|
|
||||||
oldRoleField
|
|
||||||
}) => ({
|
|
||||||
orgId,
|
orgId,
|
||||||
orgAuthEnforced,
|
orgAuthEnforced,
|
||||||
userId,
|
userId,
|
||||||
role: oldRoleField,
|
role,
|
||||||
id: membershipId,
|
id: membershipId,
|
||||||
projectId,
|
projectId,
|
||||||
createdAt: membershipCreatedAt,
|
createdAt: membershipCreatedAt,
|
||||||
|
|||||||
@@ -102,9 +102,7 @@ export const groupProjectServiceFactory = ({
|
|||||||
const groupProjectMembership = await groupProjectDAL.create(
|
const groupProjectMembership = await groupProjectDAL.create(
|
||||||
{
|
{
|
||||||
groupId: group.id,
|
groupId: group.id,
|
||||||
projectId: project.id,
|
projectId: project.id
|
||||||
role: isCustomRole ? ProjectMembershipRole.Custom : role,
|
|
||||||
roleId: customRole?.id
|
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
@@ -212,14 +210,6 @@ export const groupProjectServiceFactory = ({
|
|||||||
const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
|
const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
|
||||||
if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` });
|
if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` });
|
||||||
|
|
||||||
const { permission: groupRolePermission } = await permissionService.getProjectPermissionByRole(
|
|
||||||
projectGroup.role,
|
|
||||||
project.id
|
|
||||||
);
|
|
||||||
|
|
||||||
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, groupRolePermission);
|
|
||||||
if (!hasRequiredPriviledges) throw new ForbiddenRequestError({ message: "Failed to delete more privileged group" });
|
|
||||||
|
|
||||||
// validate custom roles input
|
// validate custom roles input
|
||||||
const customInputRoles = roles.filter(
|
const customInputRoles = roles.filter(
|
||||||
({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole)
|
({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole)
|
||||||
@@ -295,12 +285,6 @@ export const groupProjectServiceFactory = ({
|
|||||||
actorOrgId
|
actorOrgId
|
||||||
);
|
);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Delete, ProjectPermissionSub.Groups);
|
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Delete, ProjectPermissionSub.Groups);
|
||||||
const { permission: groupRolePermission } = await permissionService.getProjectPermissionByRole(
|
|
||||||
groupProjectMembership.role,
|
|
||||||
project.id
|
|
||||||
);
|
|
||||||
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, groupRolePermission);
|
|
||||||
if (!hasRequiredPriviledges) throw new ForbiddenRequestError({ message: "Failed to delete more privileged group" });
|
|
||||||
|
|
||||||
const groupMembers = await userGroupMembershipDAL.findGroupMembersNotInProject(group.id, project.id);
|
const groupMembers = await userGroupMembershipDAL.findGroupMembersNotInProject(group.id, project.id);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user