feat(secret-sync): Add gitlab secret sync
@@ -2228,6 +2228,11 @@ export const AppConnections = {
|
|||||||
},
|
},
|
||||||
FLYIO: {
|
FLYIO: {
|
||||||
accessToken: "The Access Token used to access fly.io."
|
accessToken: "The Access Token used to access fly.io."
|
||||||
|
},
|
||||||
|
GITLAB: {
|
||||||
|
instanceUrl: "The GitLab instance URL to connect with.",
|
||||||
|
accessToken: "The Access Token used to access GitLab.",
|
||||||
|
code: "The OAuth code to use to connect with GitLab."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
@@ -2401,6 +2406,16 @@ export const SecretSyncs = {
|
|||||||
},
|
},
|
||||||
FLYIO: {
|
FLYIO: {
|
||||||
appId: "The ID of the Fly.io app to sync secrets to."
|
appId: "The ID of the Fly.io app to sync secrets to."
|
||||||
|
},
|
||||||
|
GITLAB: {
|
||||||
|
projectId: "The GitLab project to sync secrets to.",
|
||||||
|
projectName: "The GitLab project name to sync secrets to.",
|
||||||
|
groupId: "The GitLab group to sync secrets to.",
|
||||||
|
scope: "The GitLab project scope that secrets should be synced to. (default: individual)",
|
||||||
|
targetEnvironment: "The GitLab environment scope that secrets should be synced to. (default: *)",
|
||||||
|
shouldProtectSecrets: "Whether variables should be protected",
|
||||||
|
shouldMaskSecrets: "Whether variables should be masked in logs",
|
||||||
|
shouldHideSecrets: "Whether variables should be hidden"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -46,6 +46,7 @@ import {
|
|||||||
GitHubRadarConnectionListItemSchema,
|
GitHubRadarConnectionListItemSchema,
|
||||||
SanitizedGitHubRadarConnectionSchema
|
SanitizedGitHubRadarConnectionSchema
|
||||||
} from "@app/services/app-connection/github-radar";
|
} from "@app/services/app-connection/github-radar";
|
||||||
|
import { GitLabConnectionListItemSchema, SanitizedGitLabConnectionSchema } from "@app/services/app-connection/gitlab";
|
||||||
import {
|
import {
|
||||||
HCVaultConnectionListItemSchema,
|
HCVaultConnectionListItemSchema,
|
||||||
SanitizedHCVaultConnectionSchema
|
SanitizedHCVaultConnectionSchema
|
||||||
@@ -109,7 +110,8 @@ const SanitizedAppConnectionSchema = z.union([
|
|||||||
...SanitizedOnePassConnectionSchema.options,
|
...SanitizedOnePassConnectionSchema.options,
|
||||||
...SanitizedHerokuConnectionSchema.options,
|
...SanitizedHerokuConnectionSchema.options,
|
||||||
...SanitizedRenderConnectionSchema.options,
|
...SanitizedRenderConnectionSchema.options,
|
||||||
...SanitizedFlyioConnectionSchema.options
|
...SanitizedFlyioConnectionSchema.options,
|
||||||
|
...SanitizedGitLabConnectionSchema.options
|
||||||
]);
|
]);
|
||||||
|
|
||||||
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
||||||
@@ -139,7 +141,8 @@ const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
|||||||
OnePassConnectionListItemSchema,
|
OnePassConnectionListItemSchema,
|
||||||
HerokuConnectionListItemSchema,
|
HerokuConnectionListItemSchema,
|
||||||
RenderConnectionListItemSchema,
|
RenderConnectionListItemSchema,
|
||||||
FlyioConnectionListItemSchema
|
FlyioConnectionListItemSchema,
|
||||||
|
GitLabConnectionListItemSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -0,0 +1,94 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { readLimit } from "@app/server/config/rateLimiter";
|
||||||
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import {
|
||||||
|
CreateGitLabConnectionSchema,
|
||||||
|
SanitizedGitLabConnectionSchema,
|
||||||
|
TGitLabGroup,
|
||||||
|
TGitLabProject,
|
||||||
|
UpdateGitLabConnectionSchema
|
||||||
|
} from "@app/services/app-connection/gitlab";
|
||||||
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
|
import { registerAppConnectionEndpoints } from "./app-connection-endpoints";
|
||||||
|
|
||||||
|
export const registerGitLabConnectionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
registerAppConnectionEndpoints({
|
||||||
|
app: AppConnection.GitLab,
|
||||||
|
server,
|
||||||
|
sanitizedResponseSchema: SanitizedGitLabConnectionSchema,
|
||||||
|
createSchema: CreateGitLabConnectionSchema,
|
||||||
|
updateSchema: UpdateGitLabConnectionSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
// The below endpoints are not exposed and for Infisical App use
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: `/:connectionId/projects`,
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
params: z.object({
|
||||||
|
connectionId: z.string().uuid()
|
||||||
|
}),
|
||||||
|
querystring: z.object({
|
||||||
|
group: z.string().optional()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z
|
||||||
|
.object({
|
||||||
|
id: z.string(),
|
||||||
|
name: z.string()
|
||||||
|
})
|
||||||
|
.array()
|
||||||
|
}
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
|
handler: async (req) => {
|
||||||
|
const { connectionId } = req.params;
|
||||||
|
|
||||||
|
const projects: TGitLabProject[] = await server.services.appConnection.gitlab.listProjects(
|
||||||
|
connectionId,
|
||||||
|
req.permission,
|
||||||
|
req.query.group
|
||||||
|
);
|
||||||
|
|
||||||
|
return projects;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: `/:connectionId/groups`,
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
params: z.object({
|
||||||
|
connectionId: z.string().uuid()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z
|
||||||
|
.object({
|
||||||
|
id: z.string(),
|
||||||
|
name: z.string()
|
||||||
|
})
|
||||||
|
.array()
|
||||||
|
}
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
|
handler: async (req) => {
|
||||||
|
const { connectionId } = req.params;
|
||||||
|
|
||||||
|
const groups: TGitLabGroup[] = await server.services.appConnection.gitlab.listGroups(
|
||||||
|
connectionId,
|
||||||
|
req.permission
|
||||||
|
);
|
||||||
|
|
||||||
|
return groups;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -15,6 +15,7 @@ import { registerFlyioConnectionRouter } from "./flyio-connection-router";
|
|||||||
import { registerGcpConnectionRouter } from "./gcp-connection-router";
|
import { registerGcpConnectionRouter } from "./gcp-connection-router";
|
||||||
import { registerGitHubConnectionRouter } from "./github-connection-router";
|
import { registerGitHubConnectionRouter } from "./github-connection-router";
|
||||||
import { registerGitHubRadarConnectionRouter } from "./github-radar-connection-router";
|
import { registerGitHubRadarConnectionRouter } from "./github-radar-connection-router";
|
||||||
|
import { registerGitLabConnectionRouter } from "./gitlab-connection-router";
|
||||||
import { registerHCVaultConnectionRouter } from "./hc-vault-connection-router";
|
import { registerHCVaultConnectionRouter } from "./hc-vault-connection-router";
|
||||||
import { registerHerokuConnectionRouter } from "./heroku-connection-router";
|
import { registerHerokuConnectionRouter } from "./heroku-connection-router";
|
||||||
import { registerHumanitecConnectionRouter } from "./humanitec-connection-router";
|
import { registerHumanitecConnectionRouter } from "./humanitec-connection-router";
|
||||||
@@ -58,5 +59,6 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record<AppConnection, (server:
|
|||||||
[AppConnection.OnePass]: registerOnePassConnectionRouter,
|
[AppConnection.OnePass]: registerOnePassConnectionRouter,
|
||||||
[AppConnection.Heroku]: registerHerokuConnectionRouter,
|
[AppConnection.Heroku]: registerHerokuConnectionRouter,
|
||||||
[AppConnection.Render]: registerRenderConnectionRouter,
|
[AppConnection.Render]: registerRenderConnectionRouter,
|
||||||
[AppConnection.Flyio]: registerFlyioConnectionRouter
|
[AppConnection.Flyio]: registerFlyioConnectionRouter,
|
||||||
|
[AppConnection.GitLab]: registerGitLabConnectionRouter
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
import { CreateGitLabSyncSchema, GitLabSyncSchema, UpdateGitLabSyncSchema } from "@app/services/secret-sync/gitlab";
|
||||||
|
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
|
||||||
|
import { registerSyncSecretsEndpoints } from "./secret-sync-endpoints";
|
||||||
|
|
||||||
|
export const registerGitLabSyncRouter = async (server: FastifyZodProvider) =>
|
||||||
|
registerSyncSecretsEndpoints({
|
||||||
|
destination: SecretSync.GitLab,
|
||||||
|
server,
|
||||||
|
responseSchema: GitLabSyncSchema,
|
||||||
|
createSchema: CreateGitLabSyncSchema,
|
||||||
|
updateSchema: UpdateGitLabSyncSchema
|
||||||
|
});
|
||||||
@@ -12,6 +12,7 @@ import { registerDatabricksSyncRouter } from "./databricks-sync-router";
|
|||||||
import { registerFlyioSyncRouter } from "./flyio-sync-router";
|
import { registerFlyioSyncRouter } from "./flyio-sync-router";
|
||||||
import { registerGcpSyncRouter } from "./gcp-sync-router";
|
import { registerGcpSyncRouter } from "./gcp-sync-router";
|
||||||
import { registerGitHubSyncRouter } from "./github-sync-router";
|
import { registerGitHubSyncRouter } from "./github-sync-router";
|
||||||
|
import { registerGitLabSyncRouter } from "./gitlab-sync-router";
|
||||||
import { registerHCVaultSyncRouter } from "./hc-vault-sync-router";
|
import { registerHCVaultSyncRouter } from "./hc-vault-sync-router";
|
||||||
import { registerHerokuSyncRouter } from "./heroku-sync-router";
|
import { registerHerokuSyncRouter } from "./heroku-sync-router";
|
||||||
import { registerHumanitecSyncRouter } from "./humanitec-sync-router";
|
import { registerHumanitecSyncRouter } from "./humanitec-sync-router";
|
||||||
@@ -43,5 +44,6 @@ export const SECRET_SYNC_REGISTER_ROUTER_MAP: Record<SecretSync, (server: Fastif
|
|||||||
[SecretSync.OnePass]: registerOnePassSyncRouter,
|
[SecretSync.OnePass]: registerOnePassSyncRouter,
|
||||||
[SecretSync.Heroku]: registerHerokuSyncRouter,
|
[SecretSync.Heroku]: registerHerokuSyncRouter,
|
||||||
[SecretSync.Render]: registerRenderSyncRouter,
|
[SecretSync.Render]: registerRenderSyncRouter,
|
||||||
[SecretSync.Flyio]: registerFlyioSyncRouter
|
[SecretSync.Flyio]: registerFlyioSyncRouter,
|
||||||
|
[SecretSync.GitLab]: registerGitLabSyncRouter
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -26,6 +26,7 @@ import { DatabricksSyncListItemSchema, DatabricksSyncSchema } from "@app/service
|
|||||||
import { FlyioSyncListItemSchema, FlyioSyncSchema } from "@app/services/secret-sync/flyio";
|
import { FlyioSyncListItemSchema, FlyioSyncSchema } from "@app/services/secret-sync/flyio";
|
||||||
import { GcpSyncListItemSchema, GcpSyncSchema } from "@app/services/secret-sync/gcp";
|
import { GcpSyncListItemSchema, GcpSyncSchema } from "@app/services/secret-sync/gcp";
|
||||||
import { GitHubSyncListItemSchema, GitHubSyncSchema } from "@app/services/secret-sync/github";
|
import { GitHubSyncListItemSchema, GitHubSyncSchema } from "@app/services/secret-sync/github";
|
||||||
|
import { GitLabSyncListItemSchema, GitLabSyncSchema } from "@app/services/secret-sync/gitlab";
|
||||||
import { HCVaultSyncListItemSchema, HCVaultSyncSchema } from "@app/services/secret-sync/hc-vault";
|
import { HCVaultSyncListItemSchema, HCVaultSyncSchema } from "@app/services/secret-sync/hc-vault";
|
||||||
import { HerokuSyncListItemSchema, HerokuSyncSchema } from "@app/services/secret-sync/heroku";
|
import { HerokuSyncListItemSchema, HerokuSyncSchema } from "@app/services/secret-sync/heroku";
|
||||||
import { HumanitecSyncListItemSchema, HumanitecSyncSchema } from "@app/services/secret-sync/humanitec";
|
import { HumanitecSyncListItemSchema, HumanitecSyncSchema } from "@app/services/secret-sync/humanitec";
|
||||||
@@ -55,7 +56,8 @@ const SecretSyncSchema = z.discriminatedUnion("destination", [
|
|||||||
OnePassSyncSchema,
|
OnePassSyncSchema,
|
||||||
HerokuSyncSchema,
|
HerokuSyncSchema,
|
||||||
RenderSyncSchema,
|
RenderSyncSchema,
|
||||||
FlyioSyncSchema
|
FlyioSyncSchema,
|
||||||
|
GitLabSyncSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
||||||
@@ -78,7 +80,8 @@ const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
|||||||
OnePassSyncListItemSchema,
|
OnePassSyncListItemSchema,
|
||||||
HerokuSyncListItemSchema,
|
HerokuSyncListItemSchema,
|
||||||
RenderSyncListItemSchema,
|
RenderSyncListItemSchema,
|
||||||
FlyioSyncListItemSchema
|
FlyioSyncListItemSchema,
|
||||||
|
GitLabSyncListItemSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerSecretSyncRouter = async (server: FastifyZodProvider) => {
|
export const registerSecretSyncRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -25,7 +25,8 @@ export enum AppConnection {
|
|||||||
OnePass = "1password",
|
OnePass = "1password",
|
||||||
Heroku = "heroku",
|
Heroku = "heroku",
|
||||||
Render = "render",
|
Render = "render",
|
||||||
Flyio = "flyio"
|
Flyio = "flyio",
|
||||||
|
GitLab = "gitlab"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum AWSRegion {
|
export enum AWSRegion {
|
||||||
|
|||||||
@@ -64,6 +64,7 @@ import {
|
|||||||
GitHubRadarConnectionMethod,
|
GitHubRadarConnectionMethod,
|
||||||
validateGitHubRadarConnectionCredentials
|
validateGitHubRadarConnectionCredentials
|
||||||
} from "./github-radar";
|
} from "./github-radar";
|
||||||
|
import { getGitLabConnectionListItem, GitLabConnectionMethod, validateGitLabConnectionCredentials } from "./gitlab";
|
||||||
import {
|
import {
|
||||||
getHCVaultConnectionListItem,
|
getHCVaultConnectionListItem,
|
||||||
HCVaultConnectionMethod,
|
HCVaultConnectionMethod,
|
||||||
@@ -128,7 +129,8 @@ export const listAppConnectionOptions = () => {
|
|||||||
getOnePassConnectionListItem(),
|
getOnePassConnectionListItem(),
|
||||||
getHerokuConnectionListItem(),
|
getHerokuConnectionListItem(),
|
||||||
getRenderConnectionListItem(),
|
getRenderConnectionListItem(),
|
||||||
getFlyioConnectionListItem()
|
getFlyioConnectionListItem(),
|
||||||
|
getGitLabConnectionListItem()
|
||||||
].sort((a, b) => a.name.localeCompare(b.name));
|
].sort((a, b) => a.name.localeCompare(b.name));
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -206,7 +208,8 @@ export const validateAppConnectionCredentials = async (
|
|||||||
[AppConnection.OnePass]: validateOnePassConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.OnePass]: validateOnePassConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Heroku]: validateHerokuConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Heroku]: validateHerokuConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Render]: validateRenderConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Render]: validateRenderConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Flyio]: validateFlyioConnectionCredentials as TAppConnectionCredentialsValidator
|
[AppConnection.Flyio]: validateFlyioConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
|
[AppConnection.GitLab]: validateGitLabConnectionCredentials as TAppConnectionCredentialsValidator
|
||||||
};
|
};
|
||||||
|
|
||||||
return VALIDATE_APP_CONNECTION_CREDENTIALS_MAP[appConnection.app](appConnection);
|
return VALIDATE_APP_CONNECTION_CREDENTIALS_MAP[appConnection.app](appConnection);
|
||||||
@@ -223,6 +226,7 @@ export const getAppConnectionMethodName = (method: TAppConnection["method"]) =>
|
|||||||
case GitHubConnectionMethod.OAuth:
|
case GitHubConnectionMethod.OAuth:
|
||||||
case AzureDevOpsConnectionMethod.OAuth:
|
case AzureDevOpsConnectionMethod.OAuth:
|
||||||
case HerokuConnectionMethod.OAuth:
|
case HerokuConnectionMethod.OAuth:
|
||||||
|
case GitLabConnectionMethod.OAuth:
|
||||||
return "OAuth";
|
return "OAuth";
|
||||||
case HerokuConnectionMethod.AuthToken:
|
case HerokuConnectionMethod.AuthToken:
|
||||||
return "Auth Token";
|
return "Auth Token";
|
||||||
@@ -318,7 +322,8 @@ export const TRANSITION_CONNECTION_CREDENTIALS_TO_PLATFORM: Record<
|
|||||||
[AppConnection.OnePass]: platformManagedCredentialsNotSupported,
|
[AppConnection.OnePass]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Heroku]: platformManagedCredentialsNotSupported,
|
[AppConnection.Heroku]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Render]: platformManagedCredentialsNotSupported,
|
[AppConnection.Render]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Flyio]: platformManagedCredentialsNotSupported
|
[AppConnection.Flyio]: platformManagedCredentialsNotSupported,
|
||||||
|
[AppConnection.GitLab]: platformManagedCredentialsNotSupported
|
||||||
};
|
};
|
||||||
|
|
||||||
export const enterpriseAppCheck = async (
|
export const enterpriseAppCheck = async (
|
||||||
|
|||||||
@@ -27,7 +27,8 @@ export const APP_CONNECTION_NAME_MAP: Record<AppConnection, string> = {
|
|||||||
[AppConnection.OnePass]: "1Password",
|
[AppConnection.OnePass]: "1Password",
|
||||||
[AppConnection.Heroku]: "Heroku",
|
[AppConnection.Heroku]: "Heroku",
|
||||||
[AppConnection.Render]: "Render",
|
[AppConnection.Render]: "Render",
|
||||||
[AppConnection.Flyio]: "Fly.io"
|
[AppConnection.Flyio]: "Fly.io",
|
||||||
|
[AppConnection.GitLab]: "GitLab"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const APP_CONNECTION_PLAN_MAP: Record<AppConnection, AppConnectionPlanType> = {
|
export const APP_CONNECTION_PLAN_MAP: Record<AppConnection, AppConnectionPlanType> = {
|
||||||
@@ -57,5 +58,6 @@ export const APP_CONNECTION_PLAN_MAP: Record<AppConnection, AppConnectionPlanTyp
|
|||||||
[AppConnection.MySql]: AppConnectionPlanType.Regular,
|
[AppConnection.MySql]: AppConnectionPlanType.Regular,
|
||||||
[AppConnection.Heroku]: AppConnectionPlanType.Regular,
|
[AppConnection.Heroku]: AppConnectionPlanType.Regular,
|
||||||
[AppConnection.Render]: AppConnectionPlanType.Regular,
|
[AppConnection.Render]: AppConnectionPlanType.Regular,
|
||||||
[AppConnection.Flyio]: AppConnectionPlanType.Regular
|
[AppConnection.Flyio]: AppConnectionPlanType.Regular,
|
||||||
|
[AppConnection.GitLab]: AppConnectionPlanType.Regular
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -56,6 +56,8 @@ import { gcpConnectionService } from "./gcp/gcp-connection-service";
|
|||||||
import { ValidateGitHubConnectionCredentialsSchema } from "./github";
|
import { ValidateGitHubConnectionCredentialsSchema } from "./github";
|
||||||
import { githubConnectionService } from "./github/github-connection-service";
|
import { githubConnectionService } from "./github/github-connection-service";
|
||||||
import { ValidateGitHubRadarConnectionCredentialsSchema } from "./github-radar";
|
import { ValidateGitHubRadarConnectionCredentialsSchema } from "./github-radar";
|
||||||
|
import { ValidateGitLabConnectionCredentialsSchema } from "./gitlab";
|
||||||
|
import { gitlabConnectionService } from "./gitlab/gitlab-connection-service";
|
||||||
import { ValidateHCVaultConnectionCredentialsSchema } from "./hc-vault";
|
import { ValidateHCVaultConnectionCredentialsSchema } from "./hc-vault";
|
||||||
import { hcVaultConnectionService } from "./hc-vault/hc-vault-connection-service";
|
import { hcVaultConnectionService } from "./hc-vault/hc-vault-connection-service";
|
||||||
import { ValidateHerokuConnectionCredentialsSchema } from "./heroku";
|
import { ValidateHerokuConnectionCredentialsSchema } from "./heroku";
|
||||||
@@ -113,7 +115,8 @@ const VALIDATE_APP_CONNECTION_CREDENTIALS_MAP: Record<AppConnection, TValidateAp
|
|||||||
[AppConnection.OnePass]: ValidateOnePassConnectionCredentialsSchema,
|
[AppConnection.OnePass]: ValidateOnePassConnectionCredentialsSchema,
|
||||||
[AppConnection.Heroku]: ValidateHerokuConnectionCredentialsSchema,
|
[AppConnection.Heroku]: ValidateHerokuConnectionCredentialsSchema,
|
||||||
[AppConnection.Render]: ValidateRenderConnectionCredentialsSchema,
|
[AppConnection.Render]: ValidateRenderConnectionCredentialsSchema,
|
||||||
[AppConnection.Flyio]: ValidateFlyioConnectionCredentialsSchema
|
[AppConnection.Flyio]: ValidateFlyioConnectionCredentialsSchema,
|
||||||
|
[AppConnection.GitLab]: ValidateGitLabConnectionCredentialsSchema
|
||||||
};
|
};
|
||||||
|
|
||||||
export const appConnectionServiceFactory = ({
|
export const appConnectionServiceFactory = ({
|
||||||
@@ -521,6 +524,7 @@ export const appConnectionServiceFactory = ({
|
|||||||
onepass: onePassConnectionService(connectAppConnectionById),
|
onepass: onePassConnectionService(connectAppConnectionById),
|
||||||
heroku: herokuConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
heroku: herokuConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
render: renderConnectionService(connectAppConnectionById),
|
render: renderConnectionService(connectAppConnectionById),
|
||||||
flyio: flyioConnectionService(connectAppConnectionById)
|
flyio: flyioConnectionService(connectAppConnectionById),
|
||||||
|
gitlab: gitlabConnectionService(connectAppConnectionById, appConnectionDAL, kmsService)
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -92,6 +92,12 @@ import {
|
|||||||
TGitHubRadarConnectionInput,
|
TGitHubRadarConnectionInput,
|
||||||
TValidateGitHubRadarConnectionCredentialsSchema
|
TValidateGitHubRadarConnectionCredentialsSchema
|
||||||
} from "./github-radar";
|
} from "./github-radar";
|
||||||
|
import {
|
||||||
|
TGitLabConnection,
|
||||||
|
TGitLabConnectionConfig,
|
||||||
|
TGitLabConnectionInput,
|
||||||
|
TValidateGitLabConnectionCredentialsSchema
|
||||||
|
} from "./gitlab";
|
||||||
import {
|
import {
|
||||||
THCVaultConnection,
|
THCVaultConnection,
|
||||||
THCVaultConnectionConfig,
|
THCVaultConnectionConfig,
|
||||||
@@ -182,6 +188,7 @@ export type TAppConnection = { id: string } & (
|
|||||||
| THerokuConnection
|
| THerokuConnection
|
||||||
| TRenderConnection
|
| TRenderConnection
|
||||||
| TFlyioConnection
|
| TFlyioConnection
|
||||||
|
| TGitLabConnection
|
||||||
);
|
);
|
||||||
|
|
||||||
export type TAppConnectionRaw = NonNullable<Awaited<ReturnType<TAppConnectionDALFactory["findById"]>>>;
|
export type TAppConnectionRaw = NonNullable<Awaited<ReturnType<TAppConnectionDALFactory["findById"]>>>;
|
||||||
@@ -216,6 +223,7 @@ export type TAppConnectionInput = { id: string } & (
|
|||||||
| THerokuConnectionInput
|
| THerokuConnectionInput
|
||||||
| TRenderConnectionInput
|
| TRenderConnectionInput
|
||||||
| TFlyioConnectionInput
|
| TFlyioConnectionInput
|
||||||
|
| TGitLabConnectionInput
|
||||||
);
|
);
|
||||||
|
|
||||||
export type TSqlConnectionInput =
|
export type TSqlConnectionInput =
|
||||||
@@ -257,7 +265,8 @@ export type TAppConnectionConfig =
|
|||||||
| TOnePassConnectionConfig
|
| TOnePassConnectionConfig
|
||||||
| THerokuConnectionConfig
|
| THerokuConnectionConfig
|
||||||
| TRenderConnectionConfig
|
| TRenderConnectionConfig
|
||||||
| TFlyioConnectionConfig;
|
| TFlyioConnectionConfig
|
||||||
|
| TGitLabConnectionConfig;
|
||||||
|
|
||||||
export type TValidateAppConnectionCredentialsSchema =
|
export type TValidateAppConnectionCredentialsSchema =
|
||||||
| TValidateAwsConnectionCredentialsSchema
|
| TValidateAwsConnectionCredentialsSchema
|
||||||
@@ -286,7 +295,8 @@ export type TValidateAppConnectionCredentialsSchema =
|
|||||||
| TValidateOnePassConnectionCredentialsSchema
|
| TValidateOnePassConnectionCredentialsSchema
|
||||||
| TValidateHerokuConnectionCredentialsSchema
|
| TValidateHerokuConnectionCredentialsSchema
|
||||||
| TValidateRenderConnectionCredentialsSchema
|
| TValidateRenderConnectionCredentialsSchema
|
||||||
| TValidateFlyioConnectionCredentialsSchema;
|
| TValidateFlyioConnectionCredentialsSchema
|
||||||
|
| TValidateGitLabConnectionCredentialsSchema;
|
||||||
|
|
||||||
export type TListAwsConnectionKmsKeys = {
|
export type TListAwsConnectionKmsKeys = {
|
||||||
connectionId: string;
|
connectionId: string;
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export enum GitLabConnectionMethod {
|
||||||
|
OAuth = "oauth",
|
||||||
|
AccessToken = "access-token"
|
||||||
|
}
|
||||||
@@ -0,0 +1,510 @@
|
|||||||
|
/* eslint-disable no-await-in-loop */
|
||||||
|
import { AxiosError, AxiosResponse } from "axios";
|
||||||
|
|
||||||
|
import { getConfig } from "@app/lib/config/env";
|
||||||
|
import { request } from "@app/lib/config/request";
|
||||||
|
import { BadRequestError, InternalServerError } from "@app/lib/errors";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import { encryptAppConnectionCredentials } from "@app/services/app-connection/app-connection-fns";
|
||||||
|
import { IntegrationUrls } from "@app/services/integration-auth/integration-list";
|
||||||
|
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||||
|
|
||||||
|
import { TAppConnectionDALFactory } from "../app-connection-dal";
|
||||||
|
import { GitLabConnectionMethod } from "./gitlab-connection-enums";
|
||||||
|
import { TGitLabConnection, TGitLabConnectionConfig, TGitLabGroup, TGitLabProject } from "./gitlab-connection-types";
|
||||||
|
|
||||||
|
interface GitLabOAuthTokenResponse {
|
||||||
|
access_token: string;
|
||||||
|
token_type: string;
|
||||||
|
expires_in: number;
|
||||||
|
refresh_token: string;
|
||||||
|
created_at: number;
|
||||||
|
scope?: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export const getGitLabConnectionListItem = () => {
|
||||||
|
const { CLIENT_ID_GITLAB_LOGIN } = getConfig();
|
||||||
|
|
||||||
|
return {
|
||||||
|
name: "GitLab" as const,
|
||||||
|
app: AppConnection.GitLab as const,
|
||||||
|
methods: Object.values(GitLabConnectionMethod) as [
|
||||||
|
GitLabConnectionMethod.AccessToken,
|
||||||
|
GitLabConnectionMethod.OAuth
|
||||||
|
],
|
||||||
|
oauthClientId: CLIENT_ID_GITLAB_LOGIN
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
export const refreshGitLabToken = async (
|
||||||
|
refreshToken: string,
|
||||||
|
appId: string,
|
||||||
|
orgId: string,
|
||||||
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "updateById">,
|
||||||
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">,
|
||||||
|
instanceUrl?: string
|
||||||
|
): Promise<string> => {
|
||||||
|
const { CLIENT_ID_GITLAB_LOGIN, CLIENT_SECRET_GITLAB_LOGIN, SITE_URL } = getConfig();
|
||||||
|
if (!CLIENT_SECRET_GITLAB_LOGIN || !CLIENT_ID_GITLAB_LOGIN || !SITE_URL) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: `GitLab environment variables have not been configured`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const payload = new URLSearchParams({
|
||||||
|
grant_type: "refresh_token",
|
||||||
|
refresh_token: refreshToken,
|
||||||
|
client_id: CLIENT_ID_GITLAB_LOGIN,
|
||||||
|
client_secret: CLIENT_SECRET_GITLAB_LOGIN,
|
||||||
|
redirect_uri: `${SITE_URL}/integrations/gitlab/oauth2/callback`
|
||||||
|
});
|
||||||
|
|
||||||
|
try {
|
||||||
|
const { data } = await request.post<GitLabOAuthTokenResponse>(
|
||||||
|
`${instanceUrl ? `${instanceUrl}/oauth/token` : IntegrationUrls.GITLAB_TOKEN_URL}`,
|
||||||
|
payload.toString(),
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/x-www-form-urlencoded",
|
||||||
|
Accept: "application/json"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
const expiresAt = new Date(Date.now() + data.expires_in * 1000 - 60000);
|
||||||
|
|
||||||
|
const encryptedCredentials = await encryptAppConnectionCredentials({
|
||||||
|
credentials: {
|
||||||
|
refreshToken: data.refresh_token,
|
||||||
|
accessToken: data.access_token,
|
||||||
|
expiresAt
|
||||||
|
},
|
||||||
|
orgId,
|
||||||
|
kmsService
|
||||||
|
});
|
||||||
|
|
||||||
|
await appConnectionDAL.updateById(appId, { encryptedCredentials });
|
||||||
|
|
||||||
|
return data.access_token;
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to refresh GitLab token: ${error.message}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Unable to refresh GitLab token"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const exchangeGitLabOAuthCode = async (
|
||||||
|
code: string,
|
||||||
|
instanceUrl?: string
|
||||||
|
): Promise<GitLabOAuthTokenResponse> => {
|
||||||
|
const { CLIENT_ID_GITLAB_LOGIN, CLIENT_SECRET_GITLAB_LOGIN, SITE_URL } = getConfig();
|
||||||
|
if (!CLIENT_SECRET_GITLAB_LOGIN || !CLIENT_ID_GITLAB_LOGIN || !SITE_URL) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: `GitLab environment variables have not been configured`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const payload = new URLSearchParams({
|
||||||
|
grant_type: "authorization_code",
|
||||||
|
code,
|
||||||
|
client_id: CLIENT_ID_GITLAB_LOGIN,
|
||||||
|
client_secret: CLIENT_SECRET_GITLAB_LOGIN,
|
||||||
|
redirect_uri: `${SITE_URL}/integrations/gitlab/oauth2/callback`
|
||||||
|
});
|
||||||
|
|
||||||
|
const response = await request.post<GitLabOAuthTokenResponse>(
|
||||||
|
instanceUrl ? `${instanceUrl}/oauth/token` : IntegrationUrls.GITLAB_TOKEN_URL,
|
||||||
|
payload.toString(),
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/x-www-form-urlencoded",
|
||||||
|
Accept: "application/json"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!response.data) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to exchange OAuth code: Empty response"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return response.data;
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to exchange OAuth code: ${error.message}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Unable to exchange OAuth code"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const validateGitLabConnectionCredentials = async (config: TGitLabConnectionConfig) => {
|
||||||
|
const { credentials: inputCredentials, method } = config;
|
||||||
|
|
||||||
|
let accessToken: string;
|
||||||
|
let oauthData: GitLabOAuthTokenResponse | null = null;
|
||||||
|
|
||||||
|
if (method === GitLabConnectionMethod.OAuth && "code" in inputCredentials) {
|
||||||
|
oauthData = await exchangeGitLabOAuthCode(inputCredentials.code, inputCredentials.instanceUrl);
|
||||||
|
accessToken = oauthData.access_token;
|
||||||
|
} else if (method === GitLabConnectionMethod.AccessToken && "accessToken" in inputCredentials) {
|
||||||
|
accessToken = inputCredentials.accessToken;
|
||||||
|
} else {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Invalid credentials for the selected connection method"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
let response: AxiosResponse<TGitLabProject[]> | null = null;
|
||||||
|
|
||||||
|
try {
|
||||||
|
response = await request.get<TGitLabProject[]>(
|
||||||
|
`${inputCredentials.instanceUrl ? `${inputCredentials.instanceUrl}/api` : IntegrationUrls.GITLAB_API_URL}/v4/groups`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
Accept: "application/json"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to validate credentials: ${error.message}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Unable to validate connection: verify credentials"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!response?.data) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to validate credentials: Response was empty"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (method === GitLabConnectionMethod.OAuth && oauthData) {
|
||||||
|
return {
|
||||||
|
accessToken,
|
||||||
|
refreshToken: oauthData.refresh_token,
|
||||||
|
expiresAt: new Date(Date.now() + oauthData.expires_in * 1000 - 60000),
|
||||||
|
tokenType: oauthData.token_type,
|
||||||
|
createdAt: new Date(oauthData.created_at * 1000)
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
return inputCredentials;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const listGitLabProjects = async ({
|
||||||
|
appConnection,
|
||||||
|
appConnectionDAL,
|
||||||
|
kmsService,
|
||||||
|
teamId
|
||||||
|
}: {
|
||||||
|
appConnection: TGitLabConnection;
|
||||||
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "updateById">;
|
||||||
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||||
|
teamId?: string;
|
||||||
|
}): Promise<TGitLabProject[]> => {
|
||||||
|
let { accessToken } = appConnection.credentials;
|
||||||
|
|
||||||
|
if (
|
||||||
|
appConnection.method === GitLabConnectionMethod.OAuth &&
|
||||||
|
appConnection.credentials.refreshToken &&
|
||||||
|
appConnection.credentials.expiresAt < new Date()
|
||||||
|
) {
|
||||||
|
accessToken = await refreshGitLabToken(
|
||||||
|
appConnection.credentials.refreshToken,
|
||||||
|
appConnection.id,
|
||||||
|
appConnection.orgId,
|
||||||
|
appConnectionDAL,
|
||||||
|
kmsService,
|
||||||
|
appConnection.credentials.instanceUrl
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const gitLabApiUrl = appConnection.credentials.instanceUrl
|
||||||
|
? `${appConnection.credentials.instanceUrl}/api/v4`
|
||||||
|
: `${IntegrationUrls.GITLAB_API_URL}/v4`;
|
||||||
|
|
||||||
|
const projects: TGitLabProject[] = [];
|
||||||
|
let page = 1;
|
||||||
|
const perPage = 100;
|
||||||
|
let hasMorePages = true;
|
||||||
|
|
||||||
|
try {
|
||||||
|
if (teamId) {
|
||||||
|
while (hasMorePages) {
|
||||||
|
const { data } = await request.get<TGitLabProject[]>(`${gitLabApiUrl}/groups/${teamId}/projects`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
Accept: "application/json"
|
||||||
|
},
|
||||||
|
params: {
|
||||||
|
page: page.toString(),
|
||||||
|
per_page: perPage.toString(),
|
||||||
|
order_by: "updated_at",
|
||||||
|
sort: "desc",
|
||||||
|
include_subgroups: "true"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!data) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to get group projects: Response was empty"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
data.forEach((project) => {
|
||||||
|
projects.push({
|
||||||
|
name: project.name,
|
||||||
|
id: project.id.toString()
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
hasMorePages = data.length === perPage;
|
||||||
|
page += 1;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
const { data: userData } = await request.get<{ id: string }>(`${gitLabApiUrl}/user`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
Accept: "application/json"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!userData?.id) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to get current user information"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
while (hasMorePages) {
|
||||||
|
const { data } = await request.get<TGitLabProject[]>(`${gitLabApiUrl}/users/${userData.id}/projects`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
Accept: "application/json"
|
||||||
|
},
|
||||||
|
params: {
|
||||||
|
page: page.toString(),
|
||||||
|
per_page: perPage.toString(),
|
||||||
|
order_by: "updated_at",
|
||||||
|
sort: "desc"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!data) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to get user projects: Response was empty"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
data.forEach((project) => {
|
||||||
|
projects.push({
|
||||||
|
name: project.name,
|
||||||
|
id: project.id.toString()
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
hasMorePages = data.length === perPage;
|
||||||
|
page += 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (projects.length === 0 && appConnection.method === GitLabConnectionMethod.AccessToken) {
|
||||||
|
try {
|
||||||
|
const { data: tokenAssociations } = await request.get<{
|
||||||
|
projects?: TGitLabProject[];
|
||||||
|
groups?: Array<{ projects?: TGitLabProject[] }>;
|
||||||
|
}>(`${gitLabApiUrl}/personal_access_tokens/self/associations`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
Accept: "application/json"
|
||||||
|
},
|
||||||
|
params: {
|
||||||
|
min_access_level: "50"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (tokenAssociations?.projects) {
|
||||||
|
tokenAssociations.projects.forEach((project) => {
|
||||||
|
projects.push({
|
||||||
|
name: project.name,
|
||||||
|
id: project.id.toString()
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (tokenAssociations?.groups) {
|
||||||
|
tokenAssociations.groups.forEach((group) => {
|
||||||
|
if (group.projects) {
|
||||||
|
group.projects.forEach((project) => {
|
||||||
|
const existingProject = projects.find((p) => p.id === project.id.toString());
|
||||||
|
if (!existingProject) {
|
||||||
|
projects.push({
|
||||||
|
name: project.name,
|
||||||
|
id: project.id.toString()
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
logger.warn(error, "Failed to fetch projects via personal access token associations:");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return projects;
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
const status = error.response?.status;
|
||||||
|
const { message } = error;
|
||||||
|
|
||||||
|
if (status === 401) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `GitLab authentication failed: ${message}`
|
||||||
|
});
|
||||||
|
} else if (status === 403) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `GitLab access forbidden: ${message}`
|
||||||
|
});
|
||||||
|
} else if (status === 404) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: teamId ? `GitLab group not found or access denied: ${message}` : `GitLab user not found: ${message}`
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to fetch GitLab projects: ${message}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (error instanceof InternalServerError) {
|
||||||
|
throw error;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Unable to fetch GitLab projects"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const listGitLabGroups = async ({
|
||||||
|
appConnection,
|
||||||
|
appConnectionDAL,
|
||||||
|
kmsService,
|
||||||
|
includeSubgroups = true,
|
||||||
|
owned = false
|
||||||
|
}: {
|
||||||
|
appConnection: TGitLabConnection;
|
||||||
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "updateById">;
|
||||||
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||||
|
includeSubgroups?: boolean;
|
||||||
|
owned?: boolean;
|
||||||
|
}): Promise<TGitLabGroup[]> => {
|
||||||
|
let { accessToken } = appConnection.credentials;
|
||||||
|
|
||||||
|
if (
|
||||||
|
appConnection.method === GitLabConnectionMethod.OAuth &&
|
||||||
|
appConnection.credentials.refreshToken &&
|
||||||
|
appConnection.credentials.expiresAt < new Date()
|
||||||
|
) {
|
||||||
|
accessToken = await refreshGitLabToken(
|
||||||
|
appConnection.credentials.refreshToken,
|
||||||
|
appConnection.id,
|
||||||
|
appConnection.orgId,
|
||||||
|
appConnectionDAL,
|
||||||
|
kmsService,
|
||||||
|
appConnection.credentials.instanceUrl
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const gitLabApiUrl = appConnection.credentials.instanceUrl
|
||||||
|
? `${appConnection.credentials.instanceUrl}/api/v4`
|
||||||
|
: `${IntegrationUrls.GITLAB_API_URL}/v4`;
|
||||||
|
|
||||||
|
const groups: TGitLabGroup[] = [];
|
||||||
|
let page = 1;
|
||||||
|
const perPage = 100;
|
||||||
|
let hasMorePages = true;
|
||||||
|
|
||||||
|
try {
|
||||||
|
while (hasMorePages) {
|
||||||
|
const { data } = await request.get<TGitLabGroup[]>(`${gitLabApiUrl}/groups`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
Accept: "application/json"
|
||||||
|
},
|
||||||
|
params: {
|
||||||
|
page: page.toString(),
|
||||||
|
per_page: perPage.toString(),
|
||||||
|
order_by: "name",
|
||||||
|
sort: "asc",
|
||||||
|
all_available: (!owned).toString(),
|
||||||
|
owned: owned.toString(),
|
||||||
|
min_access_level: "10",
|
||||||
|
...(includeSubgroups && { with_custom_attributes: "true" })
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!data) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to get groups: Response was empty"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
data.forEach((group) => {
|
||||||
|
groups.push({
|
||||||
|
id: group.id.toString(),
|
||||||
|
name: group.name
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
hasMorePages = data.length === perPage;
|
||||||
|
page += 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
return groups;
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
const status = error.response?.status;
|
||||||
|
const { message } = error;
|
||||||
|
|
||||||
|
if (status === 401) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `GitLab authentication failed: ${message}`
|
||||||
|
});
|
||||||
|
} else if (status === 403) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `GitLab access forbidden: ${message}`
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to fetch GitLab groups: ${message}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (error instanceof InternalServerError) {
|
||||||
|
throw error;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Unable to fetch GitLab groups"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,139 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { AppConnections } from "@app/lib/api-docs";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import {
|
||||||
|
BaseAppConnectionSchema,
|
||||||
|
GenericCreateAppConnectionFieldsSchema,
|
||||||
|
GenericUpdateAppConnectionFieldsSchema
|
||||||
|
} from "@app/services/app-connection/app-connection-schemas";
|
||||||
|
|
||||||
|
import { GitLabConnectionMethod } from "./gitlab-connection-enums";
|
||||||
|
|
||||||
|
// Fixed: Use consistent accessToken naming throughout
|
||||||
|
export const GitLabConnectionAccessTokenCredentialsSchema = z.object({
|
||||||
|
accessToken: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Access Token required")
|
||||||
|
.describe(AppConnections.CREDENTIALS.GITLAB.accessToken),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.url("Invalid Instance URL")
|
||||||
|
.optional()
|
||||||
|
.describe(AppConnections.CREDENTIALS.GITLAB.instanceUrl)
|
||||||
|
});
|
||||||
|
|
||||||
|
export const GitLabConnectionOAuthCredentialsSchema = z.object({
|
||||||
|
code: z.string().trim().min(1, "OAuth code required").describe(AppConnections.CREDENTIALS.GITLAB.code),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.url("Invalid Instance URL")
|
||||||
|
.optional()
|
||||||
|
.describe(AppConnections.CREDENTIALS.GITLAB.instanceUrl)
|
||||||
|
});
|
||||||
|
|
||||||
|
// Fixed: Updated schema to match GitLab's actual OAuth response structure
|
||||||
|
export const GitLabConnectionOAuthOutputCredentialsSchema = z.object({
|
||||||
|
accessToken: z.string().trim(),
|
||||||
|
refreshToken: z.string().trim(),
|
||||||
|
expiresAt: z.date(),
|
||||||
|
tokenType: z.string().optional().default("bearer"),
|
||||||
|
createdAt: z.string().optional(),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.url("Invalid Instance URL")
|
||||||
|
.optional()
|
||||||
|
.describe(AppConnections.CREDENTIALS.GITLAB.instanceUrl)
|
||||||
|
});
|
||||||
|
|
||||||
|
// Schema for refresh token input during initial setup
|
||||||
|
export const GitLabConnectionRefreshTokenCredentialsSchema = z.object({
|
||||||
|
refreshToken: z.string().trim().min(1, "Refresh token required"),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.url("Invalid Instance URL")
|
||||||
|
.optional()
|
||||||
|
.describe(AppConnections.CREDENTIALS.GITLAB.instanceUrl)
|
||||||
|
});
|
||||||
|
|
||||||
|
const BaseGitLabConnectionSchema = BaseAppConnectionSchema.extend({
|
||||||
|
app: z.literal(AppConnection.GitLab)
|
||||||
|
});
|
||||||
|
|
||||||
|
export const GitLabConnectionSchema = z.intersection(
|
||||||
|
BaseGitLabConnectionSchema,
|
||||||
|
z.discriminatedUnion("method", [
|
||||||
|
z.object({
|
||||||
|
method: z.literal(GitLabConnectionMethod.AccessToken),
|
||||||
|
credentials: GitLabConnectionAccessTokenCredentialsSchema
|
||||||
|
}),
|
||||||
|
z.object({
|
||||||
|
method: z.literal(GitLabConnectionMethod.OAuth),
|
||||||
|
credentials: GitLabConnectionOAuthOutputCredentialsSchema
|
||||||
|
})
|
||||||
|
])
|
||||||
|
);
|
||||||
|
|
||||||
|
export const SanitizedGitLabConnectionSchema = z.discriminatedUnion("method", [
|
||||||
|
BaseGitLabConnectionSchema.extend({
|
||||||
|
method: z.literal(GitLabConnectionMethod.AccessToken),
|
||||||
|
credentials: GitLabConnectionAccessTokenCredentialsSchema.pick({
|
||||||
|
instanceUrl: true
|
||||||
|
}) // Don't expose sensitive data
|
||||||
|
}),
|
||||||
|
BaseGitLabConnectionSchema.extend({
|
||||||
|
method: z.literal(GitLabConnectionMethod.OAuth),
|
||||||
|
credentials: GitLabConnectionOAuthOutputCredentialsSchema.pick({
|
||||||
|
instanceUrl: true
|
||||||
|
})
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
export const ValidateGitLabConnectionCredentialsSchema = z.discriminatedUnion("method", [
|
||||||
|
z.object({
|
||||||
|
method: z.literal(GitLabConnectionMethod.AccessToken).describe(AppConnections.CREATE(AppConnection.GitLab).method),
|
||||||
|
credentials: GitLabConnectionAccessTokenCredentialsSchema.describe(
|
||||||
|
AppConnections.CREATE(AppConnection.GitLab).credentials
|
||||||
|
)
|
||||||
|
}),
|
||||||
|
z.object({
|
||||||
|
method: z.literal(GitLabConnectionMethod.OAuth).describe(AppConnections.CREATE(AppConnection.GitLab).method),
|
||||||
|
credentials: z
|
||||||
|
.union([
|
||||||
|
GitLabConnectionOAuthCredentialsSchema,
|
||||||
|
GitLabConnectionRefreshTokenCredentialsSchema,
|
||||||
|
GitLabConnectionOAuthOutputCredentialsSchema
|
||||||
|
])
|
||||||
|
.describe(AppConnections.CREATE(AppConnection.GitLab).credentials)
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
export const CreateGitLabConnectionSchema = ValidateGitLabConnectionCredentialsSchema.and(
|
||||||
|
GenericCreateAppConnectionFieldsSchema(AppConnection.GitLab)
|
||||||
|
);
|
||||||
|
|
||||||
|
export const UpdateGitLabConnectionSchema = z
|
||||||
|
.object({
|
||||||
|
credentials: z
|
||||||
|
.union([
|
||||||
|
GitLabConnectionAccessTokenCredentialsSchema,
|
||||||
|
GitLabConnectionOAuthOutputCredentialsSchema,
|
||||||
|
GitLabConnectionRefreshTokenCredentialsSchema,
|
||||||
|
GitLabConnectionOAuthCredentialsSchema
|
||||||
|
])
|
||||||
|
.optional()
|
||||||
|
.describe(AppConnections.UPDATE(AppConnection.GitLab).credentials)
|
||||||
|
})
|
||||||
|
.and(GenericUpdateAppConnectionFieldsSchema(AppConnection.GitLab));
|
||||||
|
|
||||||
|
export const GitLabConnectionListItemSchema = z.object({
|
||||||
|
name: z.literal("GitLab"),
|
||||||
|
app: z.literal(AppConnection.GitLab),
|
||||||
|
methods: z.nativeEnum(GitLabConnectionMethod).array(),
|
||||||
|
oauthClientId: z.string().optional()
|
||||||
|
});
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { OrgServiceActor } from "@app/lib/types";
|
||||||
|
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||||
|
|
||||||
|
import { TAppConnectionDALFactory } from "../app-connection-dal";
|
||||||
|
import { AppConnection } from "../app-connection-enums";
|
||||||
|
import { listGitLabGroups, listGitLabProjects } from "./gitlab-connection-fns";
|
||||||
|
import { TGitLabConnection } from "./gitlab-connection-types";
|
||||||
|
|
||||||
|
type TGetAppConnectionFunc = (
|
||||||
|
app: AppConnection,
|
||||||
|
connectionId: string,
|
||||||
|
actor: OrgServiceActor
|
||||||
|
) => Promise<TGitLabConnection>;
|
||||||
|
|
||||||
|
export const gitlabConnectionService = (
|
||||||
|
getAppConnection: TGetAppConnectionFunc,
|
||||||
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "updateById">,
|
||||||
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">
|
||||||
|
) => {
|
||||||
|
const listProjects = async (connectionId: string, actor: OrgServiceActor, teamId?: string) => {
|
||||||
|
try {
|
||||||
|
const appConnection = await getAppConnection(AppConnection.GitLab, connectionId, actor);
|
||||||
|
const projects = await listGitLabProjects({ appConnection, appConnectionDAL, kmsService, teamId });
|
||||||
|
return projects;
|
||||||
|
} catch (error) {
|
||||||
|
logger.error(error, `Failed to establish connection with GitLab for app ${connectionId}`);
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const listGroups = async (connectionId: string, actor: OrgServiceActor) => {
|
||||||
|
try {
|
||||||
|
const appConnection = await getAppConnection(AppConnection.GitLab, connectionId, actor);
|
||||||
|
const groups = await listGitLabGroups({ appConnection, appConnectionDAL, kmsService });
|
||||||
|
return groups;
|
||||||
|
} catch (error) {
|
||||||
|
logger.error(error, `Failed to establish connection with GitLab for app ${connectionId}`);
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return {
|
||||||
|
listProjects,
|
||||||
|
listGroups
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { DiscriminativePick } from "@app/lib/types";
|
||||||
|
|
||||||
|
import { AppConnection } from "../app-connection-enums";
|
||||||
|
import {
|
||||||
|
CreateGitLabConnectionSchema,
|
||||||
|
GitLabConnectionSchema,
|
||||||
|
ValidateGitLabConnectionCredentialsSchema
|
||||||
|
} from "./gitlab-connection-schemas";
|
||||||
|
|
||||||
|
export type TGitLabConnection = z.infer<typeof GitLabConnectionSchema>;
|
||||||
|
|
||||||
|
export type TGitLabConnectionInput = z.infer<typeof CreateGitLabConnectionSchema> & {
|
||||||
|
app: AppConnection.GitLab;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TValidateGitLabConnectionCredentialsSchema = typeof ValidateGitLabConnectionCredentialsSchema;
|
||||||
|
|
||||||
|
export type TGitLabConnectionConfig = DiscriminativePick<TGitLabConnectionInput, "method" | "app" | "credentials"> & {
|
||||||
|
orgId: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabProject = {
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabAccessTokenCredentials = {
|
||||||
|
accessToken: string;
|
||||||
|
instanceUrl: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabOAuthCredentials = {
|
||||||
|
accessToken: string;
|
||||||
|
refreshToken: string;
|
||||||
|
expiresAt: Date;
|
||||||
|
tokenType?: string;
|
||||||
|
createdAt?: Date;
|
||||||
|
instanceUrl: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabOAuthCodeCredentials = {
|
||||||
|
code: string;
|
||||||
|
instanceUrl: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabRefreshTokenCredentials = {
|
||||||
|
refreshToken: string;
|
||||||
|
instanceUrl: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export interface TGitLabGroup {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export * from "./gitlab-connection-enums";
|
||||||
|
export * from "./gitlab-connection-fns";
|
||||||
|
export * from "./gitlab-connection-schemas";
|
||||||
|
export * from "./gitlab-connection-types";
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
import { TSecretSyncListItem } from "@app/services/secret-sync/secret-sync-types";
|
||||||
|
|
||||||
|
export const GITLAB_SYNC_LIST_OPTION: TSecretSyncListItem = {
|
||||||
|
name: "GitLab",
|
||||||
|
destination: SecretSync.GitLab,
|
||||||
|
connection: AppConnection.GitLab,
|
||||||
|
canImportSecrets: false
|
||||||
|
};
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export enum GitLabSyncScope {
|
||||||
|
Individual = "individual",
|
||||||
|
Group = "group"
|
||||||
|
}
|
||||||
@@ -0,0 +1,369 @@
|
|||||||
|
/* eslint-disable no-await-in-loop */
|
||||||
|
import { request } from "@app/lib/config/request";
|
||||||
|
import { TAppConnectionDALFactory } from "@app/services/app-connection/app-connection-dal";
|
||||||
|
import { GitLabConnectionMethod, refreshGitLabToken, TGitLabConnection } from "@app/services/app-connection/gitlab";
|
||||||
|
import { IntegrationUrls } from "@app/services/integration-auth/integration-list";
|
||||||
|
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||||
|
import { TGitLabSyncWithCredentials, TGitLabVariable } from "@app/services/secret-sync/gitlab/gitlab-sync-types";
|
||||||
|
import { SecretSyncError } from "@app/services/secret-sync/secret-sync-errors";
|
||||||
|
import { matchesSchema } from "@app/services/secret-sync/secret-sync-fns";
|
||||||
|
import { TSecretMap } from "@app/services/secret-sync/secret-sync-types";
|
||||||
|
|
||||||
|
import { SECRET_SYNC_NAME_MAP } from "../secret-sync-maps";
|
||||||
|
|
||||||
|
interface TGitLabVariablePayload {
|
||||||
|
key?: string;
|
||||||
|
value: string;
|
||||||
|
variable_type?: "env_var" | "file";
|
||||||
|
environment_scope?: string;
|
||||||
|
protected?: boolean;
|
||||||
|
masked?: boolean;
|
||||||
|
masked_and_hidden?: boolean;
|
||||||
|
description?: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
interface TGitLabVariableCreate extends TGitLabVariablePayload {
|
||||||
|
key: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
interface TGitLabVariableUpdate extends Omit<TGitLabVariablePayload, "key"> {}
|
||||||
|
|
||||||
|
type TGitLabSyncFactoryDeps = {
|
||||||
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "updateById">;
|
||||||
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||||
|
};
|
||||||
|
|
||||||
|
const getValidAccessToken = async (
|
||||||
|
connection: TGitLabConnection,
|
||||||
|
appConnectionDAL: Pick<TAppConnectionDALFactory, "updateById">,
|
||||||
|
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">
|
||||||
|
): Promise<string> => {
|
||||||
|
if (
|
||||||
|
connection.method === GitLabConnectionMethod.OAuth &&
|
||||||
|
connection.credentials.refreshToken &&
|
||||||
|
connection.credentials.expiresAt < new Date()
|
||||||
|
) {
|
||||||
|
const accessToken = await refreshGitLabToken(
|
||||||
|
connection.credentials.refreshToken,
|
||||||
|
connection.id,
|
||||||
|
connection.orgId,
|
||||||
|
appConnectionDAL,
|
||||||
|
kmsService
|
||||||
|
);
|
||||||
|
return accessToken;
|
||||||
|
}
|
||||||
|
return connection.credentials.accessToken;
|
||||||
|
};
|
||||||
|
|
||||||
|
const getGitLabApiUrl = (connection: TGitLabConnection): string => {
|
||||||
|
const baseUrl = connection.credentials.instanceUrl || IntegrationUrls.GITLAB_API_URL;
|
||||||
|
return baseUrl.includes("/api") ? baseUrl : `${baseUrl}/api`;
|
||||||
|
};
|
||||||
|
|
||||||
|
const buildVariablesEndpoint = (apiUrl: string, projectId: string): string => {
|
||||||
|
return `${apiUrl}/v4/projects/${encodeURIComponent(projectId)}/variables`;
|
||||||
|
};
|
||||||
|
|
||||||
|
const getGitLabVariables = async ({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
targetEnvironment
|
||||||
|
}: {
|
||||||
|
accessToken: string;
|
||||||
|
connection: TGitLabConnection;
|
||||||
|
projectId: string;
|
||||||
|
targetEnvironment?: string;
|
||||||
|
}): Promise<TGitLabVariable[]> => {
|
||||||
|
try {
|
||||||
|
const apiUrl = getGitLabApiUrl(connection);
|
||||||
|
const baseEndpoint = buildVariablesEndpoint(apiUrl, projectId);
|
||||||
|
|
||||||
|
const headers = {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
};
|
||||||
|
|
||||||
|
let allVariables: TGitLabVariable[] = [];
|
||||||
|
let url: string | null = `${baseEndpoint}?per_page=100`;
|
||||||
|
|
||||||
|
if (targetEnvironment) {
|
||||||
|
url += `&filter[environment_scope]=${encodeURIComponent(targetEnvironment)}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
while (url) {
|
||||||
|
const response = await request.get<TGitLabVariable[]>(url, { headers });
|
||||||
|
allVariables = [...allVariables, ...(response.data || [])];
|
||||||
|
|
||||||
|
const linkHeader = response.headers.link as string;
|
||||||
|
const nextLink = linkHeader?.split(",").find((part: string) => part.includes('rel="next"'));
|
||||||
|
|
||||||
|
if (nextLink) {
|
||||||
|
url = nextLink.trim().split(";")[0].slice(1, -1);
|
||||||
|
} else {
|
||||||
|
url = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (targetEnvironment) {
|
||||||
|
return allVariables.filter((variable) => variable.environment_scope === targetEnvironment);
|
||||||
|
}
|
||||||
|
|
||||||
|
return allVariables;
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: "list_variables"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const createGitLabVariable = async ({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
variable
|
||||||
|
}: {
|
||||||
|
accessToken: string;
|
||||||
|
connection: TGitLabConnection;
|
||||||
|
projectId: string;
|
||||||
|
variable: TGitLabVariableCreate;
|
||||||
|
}): Promise<void> => {
|
||||||
|
try {
|
||||||
|
const apiUrl = getGitLabApiUrl(connection);
|
||||||
|
const endpoint = buildVariablesEndpoint(apiUrl, projectId);
|
||||||
|
|
||||||
|
const payload = {
|
||||||
|
key: variable.key,
|
||||||
|
value: variable.value,
|
||||||
|
variable_type: variable.variable_type || "env_var",
|
||||||
|
environment_scope: variable.environment_scope || "*",
|
||||||
|
protected: variable.protected || false,
|
||||||
|
masked: variable.masked || false,
|
||||||
|
masked_and_hidden: variable.masked_and_hidden || false,
|
||||||
|
raw: false,
|
||||||
|
...(variable.description && { description: variable.description })
|
||||||
|
};
|
||||||
|
|
||||||
|
await request.post(endpoint, payload, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: variable.key
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const updateGitLabVariable = async ({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
key,
|
||||||
|
variable,
|
||||||
|
targetEnvironment
|
||||||
|
}: {
|
||||||
|
accessToken: string;
|
||||||
|
connection: TGitLabConnection;
|
||||||
|
projectId: string;
|
||||||
|
key: string;
|
||||||
|
variable: TGitLabVariableUpdate;
|
||||||
|
targetEnvironment?: string;
|
||||||
|
}): Promise<void> => {
|
||||||
|
try {
|
||||||
|
const apiUrl = getGitLabApiUrl(connection);
|
||||||
|
const baseEndpoint = buildVariablesEndpoint(apiUrl, projectId);
|
||||||
|
let url = `${baseEndpoint}/${encodeURIComponent(key)}`;
|
||||||
|
|
||||||
|
if (targetEnvironment) {
|
||||||
|
url += `?filter[environment_scope]=${encodeURIComponent(targetEnvironment)}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
const payload = {
|
||||||
|
value: variable.value,
|
||||||
|
...(variable.variable_type && { variable_type: variable.variable_type }),
|
||||||
|
...(variable.environment_scope && { environment_scope: variable.environment_scope }),
|
||||||
|
...(variable.protected !== undefined && { protected: variable.protected }),
|
||||||
|
...(variable.masked !== undefined && { masked: variable.masked }),
|
||||||
|
...(variable.masked_and_hidden !== undefined && { masked_and_hidden: variable.masked_and_hidden }),
|
||||||
|
...(variable.description !== undefined && { description: variable.description || "" })
|
||||||
|
};
|
||||||
|
|
||||||
|
await request.put(url, payload, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: key
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const deleteGitLabVariable = async ({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
key,
|
||||||
|
targetEnvironment
|
||||||
|
}: {
|
||||||
|
accessToken: string;
|
||||||
|
connection: TGitLabConnection;
|
||||||
|
projectId: string;
|
||||||
|
key: string;
|
||||||
|
targetEnvironment?: string;
|
||||||
|
}): Promise<void> => {
|
||||||
|
try {
|
||||||
|
const apiUrl = getGitLabApiUrl(connection);
|
||||||
|
const baseEndpoint = buildVariablesEndpoint(apiUrl, projectId);
|
||||||
|
let url = `${baseEndpoint}/${encodeURIComponent(key)}`;
|
||||||
|
|
||||||
|
if (targetEnvironment) {
|
||||||
|
url += `?filter[environment_scope]=${encodeURIComponent(targetEnvironment)}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
await request.delete(url, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Accept-Encoding": "application/json",
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
}
|
||||||
|
});
|
||||||
|
} catch (error: unknown) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const GitLabSyncFns = {
|
||||||
|
syncSecrets: async (
|
||||||
|
secretSync: TGitLabSyncWithCredentials,
|
||||||
|
secretMap: TSecretMap,
|
||||||
|
{ appConnectionDAL, kmsService }: TGitLabSyncFactoryDeps
|
||||||
|
): Promise<void> => {
|
||||||
|
const { connection, environment, destinationConfig } = secretSync;
|
||||||
|
|
||||||
|
const { projectId, targetEnvironment } = destinationConfig;
|
||||||
|
|
||||||
|
const accessToken = await getValidAccessToken(connection, appConnectionDAL, kmsService);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const currentVariables = await getGitLabVariables({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
targetEnvironment
|
||||||
|
});
|
||||||
|
|
||||||
|
const currentVariableMap = new Map(currentVariables.map((v) => [v.key, v]));
|
||||||
|
|
||||||
|
for (const [key, { value }] of Object.entries(secretMap)) {
|
||||||
|
const existingVariable = currentVariableMap.get(key);
|
||||||
|
|
||||||
|
if (existingVariable) {
|
||||||
|
if (existingVariable.value !== value) {
|
||||||
|
await updateGitLabVariable({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
key,
|
||||||
|
variable: {
|
||||||
|
value,
|
||||||
|
variable_type: existingVariable.variable_type,
|
||||||
|
environment_scope: targetEnvironment || existingVariable.environment_scope,
|
||||||
|
protected: destinationConfig.shouldProtectSecrets ?? existingVariable.protected,
|
||||||
|
...(!existingVariable.masked && destinationConfig.shouldMaskSecrets && { masked: value?.length > 8 }),
|
||||||
|
...(!existingVariable.hidden &&
|
||||||
|
destinationConfig.shouldHideSecrets && { masked_and_hidden: value?.length > 8 }),
|
||||||
|
description: existingVariable.description ?? undefined
|
||||||
|
},
|
||||||
|
targetEnvironment
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
await createGitLabVariable({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
variable: {
|
||||||
|
key,
|
||||||
|
value,
|
||||||
|
variable_type: "env_var",
|
||||||
|
environment_scope: targetEnvironment || "*",
|
||||||
|
protected: destinationConfig.shouldProtectSecrets || false,
|
||||||
|
masked: value?.length > 8 ? destinationConfig.shouldMaskSecrets || false : false,
|
||||||
|
masked_and_hidden: value?.length > 8 ? destinationConfig.shouldHideSecrets || false : false
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!secretSync.syncOptions.disableSecretDeletion) {
|
||||||
|
for (const variable of currentVariables) {
|
||||||
|
const shouldDelete =
|
||||||
|
matchesSchema(variable.key, environment?.slug || "", secretSync.syncOptions.keySchema) &&
|
||||||
|
!(variable.key in secretMap);
|
||||||
|
|
||||||
|
if (shouldDelete) {
|
||||||
|
await deleteGitLabVariable({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
key: variable.key,
|
||||||
|
targetEnvironment
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: "batch_sync"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
},
|
||||||
|
|
||||||
|
removeSecrets: async (
|
||||||
|
secretSync: TGitLabSyncWithCredentials,
|
||||||
|
secretMap: TSecretMap,
|
||||||
|
{ appConnectionDAL, kmsService }: TGitLabSyncFactoryDeps
|
||||||
|
): Promise<void> => {
|
||||||
|
const { connection, destinationConfig } = secretSync;
|
||||||
|
|
||||||
|
const { projectId, targetEnvironment } = destinationConfig;
|
||||||
|
|
||||||
|
const accessToken = await getValidAccessToken(connection, appConnectionDAL, kmsService);
|
||||||
|
|
||||||
|
try {
|
||||||
|
for (const key of Object.keys(secretMap)) {
|
||||||
|
await deleteGitLabVariable({
|
||||||
|
accessToken,
|
||||||
|
connection,
|
||||||
|
projectId,
|
||||||
|
key,
|
||||||
|
targetEnvironment
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: "batch_remove"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
},
|
||||||
|
|
||||||
|
getSecrets: async (secretSync: TGitLabSyncWithCredentials): Promise<TSecretMap> => {
|
||||||
|
throw new Error(`${SECRET_SYNC_NAME_MAP[secretSync.destination]} does not support importing secrets.`);
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { SecretSyncs } from "@app/lib/api-docs";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
import {
|
||||||
|
BaseSecretSyncSchema,
|
||||||
|
GenericCreateSecretSyncFieldsSchema,
|
||||||
|
GenericUpdateSecretSyncFieldsSchema
|
||||||
|
} from "@app/services/secret-sync/secret-sync-schemas";
|
||||||
|
import { TSyncOptionsConfig } from "@app/services/secret-sync/secret-sync-types";
|
||||||
|
|
||||||
|
import { GitLabSyncScope } from "./gitlab-sync-enums";
|
||||||
|
|
||||||
|
const GitLabSyncDestinationConfigSchema = z.discriminatedUnion("scope", [
|
||||||
|
z.object({
|
||||||
|
scope: z.literal(GitLabSyncScope.Individual).describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.scope),
|
||||||
|
projectId: z.string().min(1, "Project ID is required").describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.projectId),
|
||||||
|
projectName: z
|
||||||
|
.string()
|
||||||
|
.min(1, "Project name is required")
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.projectName),
|
||||||
|
targetEnvironment: z
|
||||||
|
.string()
|
||||||
|
.optional()
|
||||||
|
.default("*")
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.targetEnvironment),
|
||||||
|
shouldProtectSecrets: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.shouldProtectSecrets),
|
||||||
|
shouldMaskSecrets: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.shouldMaskSecrets),
|
||||||
|
shouldHideSecrets: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.shouldHideSecrets)
|
||||||
|
}),
|
||||||
|
z.object({
|
||||||
|
scope: z.literal(GitLabSyncScope.Group).describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.scope),
|
||||||
|
groupId: z.string().min(1, "Group ID is required").describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.groupId),
|
||||||
|
projectId: z.string().min(1, "Project ID is required").describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.projectId),
|
||||||
|
projectName: z
|
||||||
|
.string()
|
||||||
|
.min(1, "Project name is required")
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.projectName),
|
||||||
|
targetEnvironment: z
|
||||||
|
.string()
|
||||||
|
.optional()
|
||||||
|
.default("*")
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.targetEnvironment),
|
||||||
|
shouldProtectSecrets: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.shouldProtectSecrets),
|
||||||
|
shouldMaskSecrets: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.shouldMaskSecrets),
|
||||||
|
shouldHideSecrets: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.GITLAB.shouldHideSecrets)
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
const GitLabSyncOptionsConfig: TSyncOptionsConfig = { canImportSecrets: false };
|
||||||
|
|
||||||
|
export const GitLabSyncSchema = BaseSecretSyncSchema(SecretSync.GitLab, GitLabSyncOptionsConfig).extend({
|
||||||
|
destination: z.literal(SecretSync.GitLab),
|
||||||
|
destinationConfig: GitLabSyncDestinationConfigSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const CreateGitLabSyncSchema = GenericCreateSecretSyncFieldsSchema(
|
||||||
|
SecretSync.GitLab,
|
||||||
|
GitLabSyncOptionsConfig
|
||||||
|
).extend({
|
||||||
|
destinationConfig: GitLabSyncDestinationConfigSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const UpdateGitLabSyncSchema = GenericUpdateSecretSyncFieldsSchema(
|
||||||
|
SecretSync.GitLab,
|
||||||
|
GitLabSyncOptionsConfig
|
||||||
|
).extend({
|
||||||
|
destinationConfig: GitLabSyncDestinationConfigSchema.optional()
|
||||||
|
});
|
||||||
|
|
||||||
|
export const GitLabSyncListItemSchema = z.object({
|
||||||
|
name: z.literal("GitLab"),
|
||||||
|
connection: z.literal(AppConnection.GitLab),
|
||||||
|
destination: z.literal(SecretSync.GitLab),
|
||||||
|
canImportSecrets: z.literal(false)
|
||||||
|
});
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TGitLabConnection } from "@app/services/app-connection/gitlab";
|
||||||
|
|
||||||
|
import { CreateGitLabSyncSchema, GitLabSyncListItemSchema, GitLabSyncSchema } from "./gitlab-sync-schemas";
|
||||||
|
|
||||||
|
export type TGitLabSync = z.infer<typeof GitLabSyncSchema>;
|
||||||
|
export type TGitLabSyncInput = z.infer<typeof CreateGitLabSyncSchema>;
|
||||||
|
export type TGitLabSyncListItem = z.infer<typeof GitLabSyncListItemSchema>;
|
||||||
|
|
||||||
|
export type TGitLabSyncWithCredentials = TGitLabSync & {
|
||||||
|
connection: TGitLabConnection;
|
||||||
|
};
|
||||||
|
|
||||||
|
// GitLab CI/CD Variable structure based on API documentation
|
||||||
|
export type TGitLabVariable = {
|
||||||
|
key: string;
|
||||||
|
value: string;
|
||||||
|
variable_type: "env_var" | "file";
|
||||||
|
protected: boolean;
|
||||||
|
masked: boolean;
|
||||||
|
hidden: boolean;
|
||||||
|
raw: boolean;
|
||||||
|
environment_scope: string;
|
||||||
|
description: string | null;
|
||||||
|
};
|
||||||
|
|
||||||
|
// Type for creating a new variable
|
||||||
|
export type TGitLabVariableCreate = {
|
||||||
|
key: string;
|
||||||
|
value: string;
|
||||||
|
variable_type?: "env_var" | "file";
|
||||||
|
protected?: boolean;
|
||||||
|
masked?: boolean;
|
||||||
|
raw?: boolean;
|
||||||
|
environment_scope?: string;
|
||||||
|
description?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
// Type for updating an existing variable
|
||||||
|
export type TGitLabVariableUpdate = {
|
||||||
|
value: string;
|
||||||
|
variable_type?: "env_var" | "file";
|
||||||
|
protected?: boolean;
|
||||||
|
masked?: boolean;
|
||||||
|
raw?: boolean;
|
||||||
|
environment_scope?: string;
|
||||||
|
description?: string | null;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabListVariables = {
|
||||||
|
accessToken: string;
|
||||||
|
projectId: string;
|
||||||
|
environmentScope?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabCreateVariable = TGitLabListVariables & {
|
||||||
|
variable: TGitLabVariableCreate;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabUpdateVariable = TGitLabListVariables & {
|
||||||
|
key: string;
|
||||||
|
variable: TGitLabVariableUpdate;
|
||||||
|
};
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export * from "./gitlab-sync-constants";
|
||||||
|
export * from "./gitlab-sync-fns";
|
||||||
|
export * from "./gitlab-sync-schemas";
|
||||||
|
export * from "./gitlab-sync-types";
|
||||||
@@ -18,7 +18,8 @@ export enum SecretSync {
|
|||||||
OnePass = "1password",
|
OnePass = "1password",
|
||||||
Heroku = "heroku",
|
Heroku = "heroku",
|
||||||
Render = "render",
|
Render = "render",
|
||||||
Flyio = "flyio"
|
Flyio = "flyio",
|
||||||
|
GitLab = "gitlab"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum SecretSyncInitialSyncBehavior {
|
export enum SecretSyncInitialSyncBehavior {
|
||||||
|
|||||||
@@ -32,6 +32,7 @@ import { CAMUNDA_SYNC_LIST_OPTION, camundaSyncFactory } from "./camunda";
|
|||||||
import { FLYIO_SYNC_LIST_OPTION, FlyioSyncFns } from "./flyio";
|
import { FLYIO_SYNC_LIST_OPTION, FlyioSyncFns } from "./flyio";
|
||||||
import { GCP_SYNC_LIST_OPTION } from "./gcp";
|
import { GCP_SYNC_LIST_OPTION } from "./gcp";
|
||||||
import { GcpSyncFns } from "./gcp/gcp-sync-fns";
|
import { GcpSyncFns } from "./gcp/gcp-sync-fns";
|
||||||
|
import { GITLAB_SYNC_LIST_OPTION, GitLabSyncFns } from "./gitlab";
|
||||||
import { HC_VAULT_SYNC_LIST_OPTION, HCVaultSyncFns } from "./hc-vault";
|
import { HC_VAULT_SYNC_LIST_OPTION, HCVaultSyncFns } from "./hc-vault";
|
||||||
import { HEROKU_SYNC_LIST_OPTION, HerokuSyncFns } from "./heroku";
|
import { HEROKU_SYNC_LIST_OPTION, HerokuSyncFns } from "./heroku";
|
||||||
import { HUMANITEC_SYNC_LIST_OPTION } from "./humanitec";
|
import { HUMANITEC_SYNC_LIST_OPTION } from "./humanitec";
|
||||||
@@ -63,7 +64,8 @@ const SECRET_SYNC_LIST_OPTIONS: Record<SecretSync, TSecretSyncListItem> = {
|
|||||||
[SecretSync.OnePass]: ONEPASS_SYNC_LIST_OPTION,
|
[SecretSync.OnePass]: ONEPASS_SYNC_LIST_OPTION,
|
||||||
[SecretSync.Heroku]: HEROKU_SYNC_LIST_OPTION,
|
[SecretSync.Heroku]: HEROKU_SYNC_LIST_OPTION,
|
||||||
[SecretSync.Render]: RENDER_SYNC_LIST_OPTION,
|
[SecretSync.Render]: RENDER_SYNC_LIST_OPTION,
|
||||||
[SecretSync.Flyio]: FLYIO_SYNC_LIST_OPTION
|
[SecretSync.Flyio]: FLYIO_SYNC_LIST_OPTION,
|
||||||
|
[SecretSync.GitLab]: GITLAB_SYNC_LIST_OPTION
|
||||||
};
|
};
|
||||||
|
|
||||||
export const listSecretSyncOptions = () => {
|
export const listSecretSyncOptions = () => {
|
||||||
@@ -227,6 +229,8 @@ export const SecretSyncFns = {
|
|||||||
return RenderSyncFns.syncSecrets(secretSync, schemaSecretMap);
|
return RenderSyncFns.syncSecrets(secretSync, schemaSecretMap);
|
||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
return FlyioSyncFns.syncSecrets(secretSync, schemaSecretMap);
|
return FlyioSyncFns.syncSecrets(secretSync, schemaSecretMap);
|
||||||
|
case SecretSync.GitLab:
|
||||||
|
return GitLabSyncFns.syncSecrets(secretSync, schemaSecretMap, { appConnectionDAL, kmsService });
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled sync destination for sync secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
`Unhandled sync destination for sync secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||||
@@ -313,6 +317,9 @@ export const SecretSyncFns = {
|
|||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
secretMap = await FlyioSyncFns.getSecrets(secretSync);
|
secretMap = await FlyioSyncFns.getSecrets(secretSync);
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.GitLab:
|
||||||
|
secretMap = await GitLabSyncFns.getSecrets(secretSync);
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled sync destination for get secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
`Unhandled sync destination for get secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||||
@@ -386,6 +393,8 @@ export const SecretSyncFns = {
|
|||||||
return RenderSyncFns.removeSecrets(secretSync, schemaSecretMap);
|
return RenderSyncFns.removeSecrets(secretSync, schemaSecretMap);
|
||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
return FlyioSyncFns.removeSecrets(secretSync, schemaSecretMap);
|
return FlyioSyncFns.removeSecrets(secretSync, schemaSecretMap);
|
||||||
|
case SecretSync.GitLab:
|
||||||
|
return GitLabSyncFns.removeSecrets(secretSync, schemaSecretMap, { appConnectionDAL, kmsService });
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled sync destination for remove secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
`Unhandled sync destination for remove secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||||
|
|||||||
@@ -21,7 +21,8 @@ export const SECRET_SYNC_NAME_MAP: Record<SecretSync, string> = {
|
|||||||
[SecretSync.OnePass]: "1Password",
|
[SecretSync.OnePass]: "1Password",
|
||||||
[SecretSync.Heroku]: "Heroku",
|
[SecretSync.Heroku]: "Heroku",
|
||||||
[SecretSync.Render]: "Render",
|
[SecretSync.Render]: "Render",
|
||||||
[SecretSync.Flyio]: "Fly.io"
|
[SecretSync.Flyio]: "Fly.io",
|
||||||
|
[SecretSync.GitLab]: "GitLab"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
||||||
@@ -44,7 +45,8 @@ export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
|||||||
[SecretSync.OnePass]: AppConnection.OnePass,
|
[SecretSync.OnePass]: AppConnection.OnePass,
|
||||||
[SecretSync.Heroku]: AppConnection.Heroku,
|
[SecretSync.Heroku]: AppConnection.Heroku,
|
||||||
[SecretSync.Render]: AppConnection.Render,
|
[SecretSync.Render]: AppConnection.Render,
|
||||||
[SecretSync.Flyio]: AppConnection.Flyio
|
[SecretSync.Flyio]: AppConnection.Flyio,
|
||||||
|
[SecretSync.GitLab]: AppConnection.GitLab
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SECRET_SYNC_PLAN_MAP: Record<SecretSync, SecretSyncPlanType> = {
|
export const SECRET_SYNC_PLAN_MAP: Record<SecretSync, SecretSyncPlanType> = {
|
||||||
@@ -67,5 +69,6 @@ export const SECRET_SYNC_PLAN_MAP: Record<SecretSync, SecretSyncPlanType> = {
|
|||||||
[SecretSync.OnePass]: SecretSyncPlanType.Regular,
|
[SecretSync.OnePass]: SecretSyncPlanType.Regular,
|
||||||
[SecretSync.Heroku]: SecretSyncPlanType.Regular,
|
[SecretSync.Heroku]: SecretSyncPlanType.Regular,
|
||||||
[SecretSync.Render]: SecretSyncPlanType.Regular,
|
[SecretSync.Render]: SecretSyncPlanType.Regular,
|
||||||
[SecretSync.Flyio]: SecretSyncPlanType.Regular
|
[SecretSync.Flyio]: SecretSyncPlanType.Regular,
|
||||||
|
[SecretSync.GitLab]: SecretSyncPlanType.Regular
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -74,6 +74,7 @@ import {
|
|||||||
} from "./azure-key-vault";
|
} from "./azure-key-vault";
|
||||||
import { TFlyioSync, TFlyioSyncInput, TFlyioSyncListItem, TFlyioSyncWithCredentials } from "./flyio/flyio-sync-types";
|
import { TFlyioSync, TFlyioSyncInput, TFlyioSyncListItem, TFlyioSyncWithCredentials } from "./flyio/flyio-sync-types";
|
||||||
import { TGcpSync, TGcpSyncInput, TGcpSyncListItem, TGcpSyncWithCredentials } from "./gcp";
|
import { TGcpSync, TGcpSyncInput, TGcpSyncListItem, TGcpSyncWithCredentials } from "./gcp";
|
||||||
|
import { TGitLabSync, TGitLabSyncInput, TGitLabSyncListItem, TGitLabSyncWithCredentials } from "./gitlab";
|
||||||
import {
|
import {
|
||||||
THCVaultSync,
|
THCVaultSync,
|
||||||
THCVaultSyncInput,
|
THCVaultSyncInput,
|
||||||
@@ -127,7 +128,8 @@ export type TSecretSync =
|
|||||||
| TOnePassSync
|
| TOnePassSync
|
||||||
| THerokuSync
|
| THerokuSync
|
||||||
| TRenderSync
|
| TRenderSync
|
||||||
| TFlyioSync;
|
| TFlyioSync
|
||||||
|
| TGitLabSync;
|
||||||
|
|
||||||
export type TSecretSyncWithCredentials =
|
export type TSecretSyncWithCredentials =
|
||||||
| TAwsParameterStoreSyncWithCredentials
|
| TAwsParameterStoreSyncWithCredentials
|
||||||
@@ -149,7 +151,8 @@ export type TSecretSyncWithCredentials =
|
|||||||
| TOnePassSyncWithCredentials
|
| TOnePassSyncWithCredentials
|
||||||
| THerokuSyncWithCredentials
|
| THerokuSyncWithCredentials
|
||||||
| TRenderSyncWithCredentials
|
| TRenderSyncWithCredentials
|
||||||
| TFlyioSyncWithCredentials;
|
| TFlyioSyncWithCredentials
|
||||||
|
| TGitLabSyncWithCredentials;
|
||||||
|
|
||||||
export type TSecretSyncInput =
|
export type TSecretSyncInput =
|
||||||
| TAwsParameterStoreSyncInput
|
| TAwsParameterStoreSyncInput
|
||||||
@@ -171,7 +174,8 @@ export type TSecretSyncInput =
|
|||||||
| TOnePassSyncInput
|
| TOnePassSyncInput
|
||||||
| THerokuSyncInput
|
| THerokuSyncInput
|
||||||
| TRenderSyncInput
|
| TRenderSyncInput
|
||||||
| TFlyioSyncInput;
|
| TFlyioSyncInput
|
||||||
|
| TGitLabSyncInput;
|
||||||
|
|
||||||
export type TSecretSyncListItem =
|
export type TSecretSyncListItem =
|
||||||
| TAwsParameterStoreSyncListItem
|
| TAwsParameterStoreSyncListItem
|
||||||
@@ -193,7 +197,8 @@ export type TSecretSyncListItem =
|
|||||||
| TOnePassSyncListItem
|
| TOnePassSyncListItem
|
||||||
| THerokuSyncListItem
|
| THerokuSyncListItem
|
||||||
| TRenderSyncListItem
|
| TRenderSyncListItem
|
||||||
| TFlyioSyncListItem;
|
| TFlyioSyncListItem
|
||||||
|
| TGitLabSyncListItem;
|
||||||
|
|
||||||
export type TSyncOptionsConfig = {
|
export type TSyncOptionsConfig = {
|
||||||
canImportSecrets: boolean;
|
canImportSecrets: boolean;
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Available"
|
||||||
|
openapi: "GET /api/v1/app-connections/gitlab/available"
|
||||||
|
---
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
title: "Create"
|
||||||
|
openapi: "POST /api/v1/app-connections/gitlab"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Gitlab OAuth Connections must be created through the Infisical UI.
|
||||||
|
Check out the configuration docs for [Gitlab OAuth Connections](/integrations/app-connections/gitlab) for a step-by-step
|
||||||
|
guide.
|
||||||
|
</Note>
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Delete"
|
||||||
|
openapi: "DELETE /api/v1/app-connections/gitlab/{connectionId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by ID"
|
||||||
|
openapi: "GET /api/v1/app-connections/gitlab/{connectionId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by Name"
|
||||||
|
openapi: "GET /api/v1/app-connections/gitlab/connection-name/{connectionName}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "List"
|
||||||
|
openapi: "GET /api/v1/app-connections/gitlab"
|
||||||
|
---
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
title: "Update"
|
||||||
|
openapi: "PATCH /api/v1/app-connections/gitlab/{connectionId}"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Gitlab OAuth Connections must be updated through the Infisical UI.
|
||||||
|
Check out the configuration docs for [Gitlab OAuth Connections](/integrations/app-connections/gitlab) for a step-by-step
|
||||||
|
guide.
|
||||||
|
</Note>
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Create"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/gitlab"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Delete"
|
||||||
|
openapi: "DELETE /api/v1/secret-syncs/gitlab/{syncId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by ID"
|
||||||
|
openapi: "GET /api/v1/secret-syncs/gitlab/{syncId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by Name"
|
||||||
|
openapi: "GET /api/v1/secret-syncs/gitlab/sync-name/{syncName}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "List"
|
||||||
|
openapi: "GET /api/v1/secret-syncs/gitlab"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Remove Secrets"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/gitlab/{syncId}/remove-secrets"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Sync Secrets"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/gitlab/{syncId}/sync-secrets"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Update"
|
||||||
|
openapi: "PATCH /api/v1/secret-syncs/gitlab/{syncId}"
|
||||||
|
---
|
||||||
|
Before Width: | Height: | Size: 759 KiB After Width: | Height: | Size: 606 KiB |
|
After Width: | Height: | Size: 593 KiB |
|
Before Width: | Height: | Size: 1.2 MiB |
|
After Width: | Height: | Size: 935 KiB |
|
Before Width: | Height: | Size: 497 KiB After Width: | Height: | Size: 344 KiB |
|
After Width: | Height: | Size: 294 KiB |
|
After Width: | Height: | Size: 196 KiB |
|
After Width: | Height: | Size: 260 KiB |
|
Before Width: | Height: | Size: 540 KiB After Width: | Height: | Size: 380 KiB |
|
After Width: | Height: | Size: 531 KiB |
|
After Width: | Height: | Size: 480 KiB |
|
After Width: | Height: | Size: 284 KiB |
|
After Width: | Height: | Size: 917 KiB |
|
After Width: | Height: | Size: 426 KiB |
|
After Width: | Height: | Size: 708 KiB |
|
After Width: | Height: | Size: 464 KiB |
|
After Width: | Height: | Size: 782 KiB |
|
Before Width: | Height: | Size: 592 KiB |
|
After Width: | Height: | Size: 946 KiB |
|
After Width: | Height: | Size: 636 KiB |
|
After Width: | Height: | Size: 582 KiB |
|
After Width: | Height: | Size: 646 KiB |
|
After Width: | Height: | Size: 636 KiB |
|
After Width: | Height: | Size: 618 KiB |
|
After Width: | Height: | Size: 569 KiB |
@@ -0,0 +1,176 @@
|
|||||||
|
---
|
||||||
|
title: "GitLab App Connection"
|
||||||
|
description: "Learn how to configure a GitLab App Connection for Infisical using OAuth or Access Token methods."
|
||||||
|
---
|
||||||
|
|
||||||
|
Infisical supports two methods for connecting to GitLab: **OAuth** and **Access Token**. Choose the method that best fits your setup and security requirements.
|
||||||
|
|
||||||
|
<Tabs>
|
||||||
|
<Tab title="OAuth Method">
|
||||||
|
The OAuth method provides secure authentication through GitLab's OAuth flow.
|
||||||
|
|
||||||
|
<Accordion title="Self-Hosted Instance Setup">
|
||||||
|
Using the GitLab App Connection with OAuth on a self-hosted instance of Infisical requires configuring an OAuth application in GitLab and registering your instance with it.
|
||||||
|
|
||||||
|
**Prerequisites:**
|
||||||
|
- A GitLab account with existing projects
|
||||||
|
- Self-hosted Infisical instance
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Create an OAuth application in GitLab">
|
||||||
|
Navigate to your user Settings > Applications to create a new GitLab application.
|
||||||
|
|
||||||
|

|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
Create the application. As part of the form, set the **Redirect URI** to `https://your-domain.com/integrations/gitlab/oauth2/callback`.
|
||||||
|
|
||||||
|

|
||||||
|

|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
The domain you defined in the Redirect URI should be equivalent to the `SITE_URL` configured in your Infisical instance.
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
If you have a GitLab group, you can create an OAuth application under it in your group Settings > Applications.
|
||||||
|
</Note>
|
||||||
|
</Step>
|
||||||
|
<Step title="Add your GitLab OAuth application credentials to Infisical">
|
||||||
|
Obtain the **Application ID** and **Secret** for your GitLab OAuth application.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Back in your Infisical instance, add two new environment variables for the credentials of your GitLab OAuth application:
|
||||||
|
|
||||||
|
- `CLIENT_ID_GITLAB`: The **Application ID** of your GitLab OAuth application.
|
||||||
|
- `CLIENT_SECRET_GITLAB`: The **Secret** of your GitLab OAuth application.
|
||||||
|
|
||||||
|
Once added, restart your Infisical instance and use the GitLab App Connection.
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
## Setup GitLab OAuth Connection in Infisical
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Navigate to App Connections">
|
||||||
|
Navigate to the **App Connections** tab on the **Organization Settings** page.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Add Connection">
|
||||||
|
Select the **GitLab App Connection** option from the connection options modal.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Choose OAuth Method">
|
||||||
|
Select the **OAuth** method and click **Connect to GitLab**.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Grant Access">
|
||||||
|
You will be redirected to GitLab to grant Infisical access to your GitLab account. Once granted, you will be redirected back to Infisical's App Connections page.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Connection Created">
|
||||||
|
Your **GitLab App Connection** is now available for use.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
|
||||||
|
<Tab title="Access Token Method">
|
||||||
|
The Access Token method uses a GitLab access token for authentication, providing a straightforward setup process.
|
||||||
|
|
||||||
|
## Generate GitLab Access Token
|
||||||
|
|
||||||
|
<Tabs>
|
||||||
|
<Tab title="Personal Access Token">
|
||||||
|
Personal access tokens provide access to your GitLab account and all projects you have access to.
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Navigate to Access Tokens">
|
||||||
|
Log in to your GitLab account and navigate to User Settings > Access tokens. Click **Add new token** to create a new personal access token.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Configure Token">
|
||||||
|
Fill in the token details:
|
||||||
|
- **Token name**: A descriptive name for the token (e.g., "connection-token")
|
||||||
|
- **Expiration date**: Set an appropriate expiration date
|
||||||
|
- **Select scopes**: Choose the **api** scope for full API access
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
</Step>
|
||||||
|
<Step title="Copy Token">
|
||||||
|
Copy the generated token immediately as it won't be shown again.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
<Warning>
|
||||||
|
Keep your access token secure and do not share it. Anyone with access to this token can access your GitLab account and projects.
|
||||||
|
</Warning>
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Tab>
|
||||||
|
|
||||||
|
<Tab title="Project Access Token">
|
||||||
|
Project access tokens provide access to a specific GitLab project, offering more granular control.
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Navigate to Project Settings">
|
||||||
|
Go to your GitLab project and navigate to Settings > Access Tokens. Click **Add new token** to create a new project access token.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Configure Token">
|
||||||
|
Fill in the token details:
|
||||||
|
- **Token name**: A descriptive name for the token
|
||||||
|
- **Expiration date**: Set an appropriate expiration date
|
||||||
|
- **Select role**: Choose **Owner** or higher role
|
||||||
|
- **Select scopes**: Choose the **api** scope for API access
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
</Step>
|
||||||
|
<Step title="Copy Token">
|
||||||
|
Copy the generated token immediately as it won't be shown again.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Tab>
|
||||||
|
</Tabs>
|
||||||
|
|
||||||
|
## Setup GitLab Access Token Connection in Infisical
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Navigate to App Connections">
|
||||||
|
Navigate to the **App Connections** tab on the **Organization Settings** page.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Add Connection">
|
||||||
|
Select the **GitLab App Connection** option from the connection options modal.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Configure Access Token">
|
||||||
|
Select the **Access Token** method and paste your GitLab access token in the provided field.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Click **Connect** to establish the connection.
|
||||||
|
</Step>
|
||||||
|
<Step title="Connection Created">
|
||||||
|
Your **GitLab App Connection** is now available for use.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Access Token connections require manual token rotation when your GitLab access token expires or is regenerated. Monitor your connection status and update the token as needed.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
</Tabs>
|
||||||
@@ -0,0 +1,175 @@
|
|||||||
|
---
|
||||||
|
title: "GitLab Sync"
|
||||||
|
description: "Learn how to configure a GitLab Sync for Infisical."
|
||||||
|
---
|
||||||
|
|
||||||
|
**Prerequisites:**
|
||||||
|
|
||||||
|
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||||
|
- Create a [GitLab Connection](/integrations/app-connections/gitlab)
|
||||||
|
|
||||||
|
<Tabs>
|
||||||
|
<Tab title="Infisical UI">
|
||||||
|
1. Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
|
||||||
|

|
||||||
|
|
||||||
|
2. Select the **GitLab** option.
|
||||||
|

|
||||||
|
|
||||||
|
3. Configure the **Source** from where secrets should be retrieved, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Environment**: The project environment to retrieve secrets from.
|
||||||
|
- **Secret Path**: The folder path to retrieve secrets from.
|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|
4. Configure the **Destination** to where secrets should be deployed, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **GitLab Connection**: The GitLab Connection to authenticate with.
|
||||||
|
- **Scope**: The GitLab secret scope to sync secrets to.
|
||||||
|
- **Individual**: Sync secrets to a specific project.
|
||||||
|
- **Group**: Sync secrets to a project within a group.
|
||||||
|
<p class="height:1px" />
|
||||||
|
The remaining fields are determined by the selected **Scope**:
|
||||||
|
<AccordionGroup>
|
||||||
|
<Accordion title="Individual">
|
||||||
|
- **GitLab Project**: The project to deploy secrets to.
|
||||||
|
- **GitLab Environment Scope**: The environment scope to deploy secrets to (optional, defaults to "*" for all environments).
|
||||||
|
- **Mark Infisical secrets in GitLab as 'Protected' secrets**: If enabled, synced secrets will be marked as protected in GitLab.
|
||||||
|
- **Mark Infisical secrets in GitLab as 'Masked' secrets**: If enabled, synced secrets will be masked in GitLab CI/CD logs.
|
||||||
|
- **Mark Infisical secrets in GitLab as 'Hidden' secrets**: If enabled, synced secrets will be hidden from the GitLab UI.
|
||||||
|
</Accordion>
|
||||||
|
<Accordion title="Group">
|
||||||
|
- **GitLab Group**: The group containing the project.
|
||||||
|
- **GitLab Project**: The project to deploy secrets to.
|
||||||
|
- **GitLab Environment Scope**: The environment scope to deploy secrets to (optional, defaults to "*" for all environments).
|
||||||
|
- **Mark Infisical secrets in GitLab as 'Protected' secrets**: If enabled, synced secrets will be marked as protected in GitLab.
|
||||||
|
- **Mark Infisical secrets in GitLab as 'Masked' secrets**: If enabled, synced secrets will be masked in GitLab CI/CD logs.
|
||||||
|
- **Mark Infisical secrets in GitLab as 'Hidden' secrets**: If enabled, synced secrets will be hidden from the GitLab UI.
|
||||||
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
|
|
||||||
|
5. Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
|
||||||
|
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
|
||||||
|
<Note>
|
||||||
|
GitLab does not support importing secrets.
|
||||||
|
</Note>
|
||||||
|
- **Key Schema**: Template that determines how secret names are transformed when syncing, using `{{secretKey}}` as a placeholder for the original secret name and `{{environment}}` for the environment.
|
||||||
|
<Note>
|
||||||
|
We highly recommend using a Key Schema to ensure that Infisical only manages the specific keys you intend, keeping everything else untouched.
|
||||||
|
</Note>
|
||||||
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
|
6. Configure the **Details** of your GitLab Sync, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Name**: The name of your sync. Must be slug-friendly.
|
||||||
|
- **Description**: An optional description for your sync.
|
||||||
|
|
||||||
|
7. Review your GitLab Sync configuration, then click **Create Sync**.
|
||||||
|

|
||||||
|
|
||||||
|
8. If enabled, your GitLab Sync will begin syncing your secrets to the destination endpoint.
|
||||||
|

|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
<Tab title="API">
|
||||||
|
To create a **GitLab Sync**, make an API request to the [Create GitLab Sync](/api-reference/endpoints/secret-syncs/gitlab/create) API endpoint.
|
||||||
|
|
||||||
|
### Sample request
|
||||||
|
|
||||||
|
```bash Request
|
||||||
|
curl --request POST \
|
||||||
|
--url https://app.infisical.com/api/v1/secret-syncs/gitlab \
|
||||||
|
--header 'Content-Type: application/json' \
|
||||||
|
--data '{
|
||||||
|
"name": "my-gitlab-sync",
|
||||||
|
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"description": "an example sync",
|
||||||
|
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"environment": "dev",
|
||||||
|
"secretPath": "/my-secrets",
|
||||||
|
"isEnabled": true,
|
||||||
|
"syncOptions": {
|
||||||
|
"initialSyncBehavior": "overwrite-destination"
|
||||||
|
},
|
||||||
|
"destinationConfig": {
|
||||||
|
"scope": "individual",
|
||||||
|
"projectId": "70998370",
|
||||||
|
"projectName": "test",
|
||||||
|
"targetEnvironment": "*",
|
||||||
|
"shouldProtectSecrets": true,
|
||||||
|
"shouldMaskSecrets": true,
|
||||||
|
"shouldHideSecrets": false
|
||||||
|
}
|
||||||
|
}'
|
||||||
|
```
|
||||||
|
|
||||||
|
### Sample response
|
||||||
|
|
||||||
|
```bash Response
|
||||||
|
{
|
||||||
|
"secretSync": {
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"name": "my-gitlab-sync",
|
||||||
|
"description": "an example sync",
|
||||||
|
"isEnabled": true,
|
||||||
|
"version": 1,
|
||||||
|
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"createdAt": "2023-11-07T05:31:56Z",
|
||||||
|
"updatedAt": "2023-11-07T05:31:56Z",
|
||||||
|
"syncStatus": "succeeded",
|
||||||
|
"lastSyncJobId": "123",
|
||||||
|
"lastSyncMessage": null,
|
||||||
|
"lastSyncedAt": "2023-11-07T05:31:56Z",
|
||||||
|
"importStatus": null,
|
||||||
|
"lastImportJobId": null,
|
||||||
|
"lastImportMessage": null,
|
||||||
|
"lastImportedAt": null,
|
||||||
|
"removeStatus": null,
|
||||||
|
"lastRemoveJobId": null,
|
||||||
|
"lastRemoveMessage": null,
|
||||||
|
"lastRemovedAt": null,
|
||||||
|
"syncOptions": {
|
||||||
|
"initialSyncBehavior": "overwrite-destination"
|
||||||
|
},
|
||||||
|
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"connection": {
|
||||||
|
"app": "gitlab",
|
||||||
|
"name": "my-gitlab-connection",
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||||
|
},
|
||||||
|
"environment": {
|
||||||
|
"slug": "dev",
|
||||||
|
"name": "Development",
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||||
|
},
|
||||||
|
"folder": {
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"path": "/my-secrets"
|
||||||
|
},
|
||||||
|
"destination": "gitlab",
|
||||||
|
"destinationConfig": {
|
||||||
|
"scope": "individual",
|
||||||
|
"projectId": "70998370",
|
||||||
|
"projectName": "test",
|
||||||
|
"targetEnvironment": "*",
|
||||||
|
"shouldProtectSecrets": true,
|
||||||
|
"shouldMaskSecrets": true,
|
||||||
|
"shouldHideSecrets": false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
</Tab>
|
||||||
|
|
||||||
|
</Tabs>
|
||||||
@@ -508,6 +508,7 @@
|
|||||||
"integrations/app-connections/gcp",
|
"integrations/app-connections/gcp",
|
||||||
"integrations/app-connections/github",
|
"integrations/app-connections/github",
|
||||||
"integrations/app-connections/github-radar",
|
"integrations/app-connections/github-radar",
|
||||||
|
"integrations/app-connections/gitlab",
|
||||||
"integrations/app-connections/hashicorp-vault",
|
"integrations/app-connections/hashicorp-vault",
|
||||||
"integrations/app-connections/heroku",
|
"integrations/app-connections/heroku",
|
||||||
"integrations/app-connections/humanitec",
|
"integrations/app-connections/humanitec",
|
||||||
@@ -544,6 +545,7 @@
|
|||||||
"integrations/secret-syncs/flyio",
|
"integrations/secret-syncs/flyio",
|
||||||
"integrations/secret-syncs/gcp-secret-manager",
|
"integrations/secret-syncs/gcp-secret-manager",
|
||||||
"integrations/secret-syncs/github",
|
"integrations/secret-syncs/github",
|
||||||
|
"integrations/secret-syncs/gitlab",
|
||||||
"integrations/secret-syncs/hashicorp-vault",
|
"integrations/secret-syncs/hashicorp-vault",
|
||||||
"integrations/secret-syncs/heroku",
|
"integrations/secret-syncs/heroku",
|
||||||
"integrations/secret-syncs/humanitec",
|
"integrations/secret-syncs/humanitec",
|
||||||
@@ -1305,6 +1307,18 @@
|
|||||||
"api-reference/endpoints/app-connections/github/delete"
|
"api-reference/endpoints/app-connections/github/delete"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"group": "GitLab",
|
||||||
|
"pages": [
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/list",
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/available",
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/get-by-id",
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/get-by-name",
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/create",
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/update",
|
||||||
|
"api-reference/endpoints/app-connections/gitlab/delete"
|
||||||
|
]
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"group": "GitHub Radar",
|
"group": "GitHub Radar",
|
||||||
"pages": [
|
"pages": [
|
||||||
@@ -1642,6 +1656,19 @@
|
|||||||
"api-reference/endpoints/secret-syncs/github/remove-secrets"
|
"api-reference/endpoints/secret-syncs/github/remove-secrets"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"group": "GitLab",
|
||||||
|
"pages": [
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/list",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/get-by-id",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/get-by-name",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/create",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/update",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/delete",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/sync-secrets",
|
||||||
|
"api-reference/endpoints/secret-syncs/gitlab/remove-secrets"
|
||||||
|
]
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"group": "Hashicorp Vault",
|
"group": "Hashicorp Vault",
|
||||||
"pages": [
|
"pages": [
|
||||||
|
|||||||
@@ -0,0 +1,278 @@
|
|||||||
|
import { Controller, useFormContext, useWatch } from "react-hook-form";
|
||||||
|
import { SingleValue } from "react-select";
|
||||||
|
import { faCircleInfo } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
|
import { SecretSyncConnectionField } from "@app/components/secret-syncs/forms/SecretSyncConnectionField";
|
||||||
|
import {
|
||||||
|
FilterableSelect,
|
||||||
|
FormControl,
|
||||||
|
Input,
|
||||||
|
Select,
|
||||||
|
SelectItem,
|
||||||
|
Switch,
|
||||||
|
Tooltip
|
||||||
|
} from "@app/components/v2";
|
||||||
|
import {
|
||||||
|
TGitLabGroup,
|
||||||
|
TGitLabProject,
|
||||||
|
useGitlabConnectionListGroups,
|
||||||
|
useGitlabConnectionListProjects
|
||||||
|
} from "@app/hooks/api/appConnections/gitlab";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
import { GitlabSyncScope } from "@app/hooks/api/secretSyncs/types/gitlab-sync";
|
||||||
|
|
||||||
|
import { TSecretSyncForm } from "../schemas";
|
||||||
|
|
||||||
|
const SecretProtectionOption = ({
|
||||||
|
title,
|
||||||
|
isEnabled,
|
||||||
|
onChange,
|
||||||
|
id,
|
||||||
|
isDisabled = false,
|
||||||
|
tooltip
|
||||||
|
}: {
|
||||||
|
title: string;
|
||||||
|
isEnabled: boolean;
|
||||||
|
onChange: (checked: boolean) => void;
|
||||||
|
id: string;
|
||||||
|
isDisabled?: boolean;
|
||||||
|
tooltip?: string;
|
||||||
|
}) => {
|
||||||
|
return (
|
||||||
|
<div className="flex items-start justify-between rounded-lg border border-mineshaft-600 bg-mineshaft-800/50 p-4 transition-all duration-200 hover:border-mineshaft-500">
|
||||||
|
<div className="flex flex-1 items-start space-x-3">
|
||||||
|
<div className="min-w-0 flex-1">
|
||||||
|
<div className="mb-1 flex items-center gap-2">
|
||||||
|
<h4 className="text-sm font-medium text-bunker-100">{title}</h4>
|
||||||
|
{tooltip && (
|
||||||
|
<Tooltip className="max-w-sm" content={tooltip}>
|
||||||
|
<FontAwesomeIcon
|
||||||
|
icon={faCircleInfo}
|
||||||
|
className="cursor-help text-xs text-mineshaft-400 hover:text-mineshaft-300"
|
||||||
|
/>
|
||||||
|
</Tooltip>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div className="ml-4 flex-shrink-0">
|
||||||
|
<Switch id={id} onCheckedChange={onChange} isChecked={isEnabled} isDisabled={isDisabled} />
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
};
|
||||||
|
|
||||||
|
export const GitLabSyncFields = () => {
|
||||||
|
const { control, setValue } = useFormContext<
|
||||||
|
TSecretSyncForm & { destination: SecretSync.Gitlab }
|
||||||
|
>();
|
||||||
|
|
||||||
|
const connectionId = useWatch({ name: "connection.id", control });
|
||||||
|
const scope = useWatch({ name: "destinationConfig.scope", control });
|
||||||
|
const selectedGroup = useWatch({ name: "destinationConfig.groupId", control });
|
||||||
|
const shouldMaskSecrets = useWatch({ name: "destinationConfig.shouldMaskSecrets", control });
|
||||||
|
|
||||||
|
const { data: groups, isLoading: isGroupsLoading } = useGitlabConnectionListGroups(connectionId, {
|
||||||
|
enabled: Boolean(connectionId) && scope === GitlabSyncScope.Group
|
||||||
|
});
|
||||||
|
|
||||||
|
const { data: projects, isLoading: isProjectsLoading } = useGitlabConnectionListProjects(
|
||||||
|
connectionId,
|
||||||
|
selectedGroup,
|
||||||
|
{
|
||||||
|
enabled: Boolean(connectionId)
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className="h-[calc(100vh-20rem)] overflow-auto">
|
||||||
|
<SecretSyncConnectionField
|
||||||
|
onChange={() => {
|
||||||
|
setValue("destinationConfig.projectId", "");
|
||||||
|
setValue("destinationConfig.projectName", "");
|
||||||
|
setValue("destinationConfig.groupId", "");
|
||||||
|
setValue("destinationConfig.scope", GitlabSyncScope.Individual);
|
||||||
|
}}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
name="destinationConfig.scope"
|
||||||
|
control={control}
|
||||||
|
defaultValue={GitlabSyncScope.Individual}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl errorText={error?.message} isError={Boolean(error?.message)} label="Scope">
|
||||||
|
<Select
|
||||||
|
value={value}
|
||||||
|
onValueChange={(val) => {
|
||||||
|
onChange(val);
|
||||||
|
setValue("destinationConfig.projectId", "");
|
||||||
|
setValue("destinationConfig.projectName", "");
|
||||||
|
setValue("destinationConfig.groupId", "");
|
||||||
|
}}
|
||||||
|
className="w-full border border-mineshaft-500 capitalize"
|
||||||
|
position="popper"
|
||||||
|
placeholder="Select a scope..."
|
||||||
|
dropdownContainerClassName="max-w-none"
|
||||||
|
>
|
||||||
|
{Object.values(GitlabSyncScope).map((projectScope) => (
|
||||||
|
<SelectItem className="capitalize" value={projectScope} key={projectScope}>
|
||||||
|
{projectScope.replace("-", " ")}
|
||||||
|
</SelectItem>
|
||||||
|
))}
|
||||||
|
</Select>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
{scope === GitlabSyncScope.Group && (
|
||||||
|
<Controller
|
||||||
|
name="destinationConfig.groupId"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
label="Group"
|
||||||
|
helperText={
|
||||||
|
<Tooltip
|
||||||
|
className="max-w-md"
|
||||||
|
content="Ensure the group exists in the connection's GitLab instance URL."
|
||||||
|
>
|
||||||
|
<div>
|
||||||
|
<span>Don't see the group you're looking for?</span>{" "}
|
||||||
|
<FontAwesomeIcon icon={faCircleInfo} className="text-mineshaft-400" />
|
||||||
|
</div>
|
||||||
|
</Tooltip>
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FilterableSelect
|
||||||
|
menuPlacement="top"
|
||||||
|
isLoading={isGroupsLoading && Boolean(connectionId)}
|
||||||
|
isDisabled={!connectionId}
|
||||||
|
value={groups?.find((group) => group.id === value) ?? null}
|
||||||
|
onChange={(option) => {
|
||||||
|
onChange((option as SingleValue<TGitLabGroup>)?.id ?? "");
|
||||||
|
}}
|
||||||
|
options={groups}
|
||||||
|
placeholder="Select a group..."
|
||||||
|
getOptionLabel={(option) => option.name}
|
||||||
|
getOptionValue={(option) => option.id}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
name="destinationConfig.projectId"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
label="GitLab Project"
|
||||||
|
helperText={
|
||||||
|
<Tooltip
|
||||||
|
className="max-w-md"
|
||||||
|
content="Ensure the project exists in the connection's GitLab instance URL."
|
||||||
|
>
|
||||||
|
<div>
|
||||||
|
<span>Don't see the project you're looking for?</span>{" "}
|
||||||
|
<FontAwesomeIcon icon={faCircleInfo} className="text-mineshaft-400" />
|
||||||
|
</div>
|
||||||
|
</Tooltip>
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FilterableSelect
|
||||||
|
menuPlacement="top"
|
||||||
|
isLoading={isProjectsLoading && Boolean(connectionId)}
|
||||||
|
isDisabled={!connectionId || (scope === GitlabSyncScope.Group && !selectedGroup)}
|
||||||
|
value={projects?.find((project) => project.id === value) ?? null}
|
||||||
|
onChange={(option) => {
|
||||||
|
onChange((option as SingleValue<TGitLabProject>)?.id ?? "");
|
||||||
|
setValue(
|
||||||
|
"destinationConfig.projectName",
|
||||||
|
(option as SingleValue<TGitLabProject>)?.name ?? ""
|
||||||
|
);
|
||||||
|
}}
|
||||||
|
options={projects}
|
||||||
|
placeholder="Select a project..."
|
||||||
|
getOptionLabel={(option) => option.name}
|
||||||
|
getOptionValue={(option) => option.id}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue=""
|
||||||
|
name="destinationConfig.targetEnvironment"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="GitLab Environment Scope (Optional)"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="*" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
{/* Secret Protection Settings Section */}
|
||||||
|
<div className="mt-6">
|
||||||
|
<div className="space-y-4">
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="destinationConfig.shouldProtectSecrets"
|
||||||
|
render={({ field: { onChange, value } }) => (
|
||||||
|
<SecretProtectionOption
|
||||||
|
id="should-protect-secrets"
|
||||||
|
title="Mark Infisical secrets in GitLab as 'Protected' secrets"
|
||||||
|
isEnabled={value || false}
|
||||||
|
onChange={onChange}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="destinationConfig.shouldMaskSecrets"
|
||||||
|
render={({ field: { onChange, value } }) => (
|
||||||
|
<SecretProtectionOption
|
||||||
|
id="should-mask-secrets"
|
||||||
|
title="Mark Infisical secrets in GitLab as 'Masked' secrets"
|
||||||
|
tooltip="GitLab has limitations for masked variables: secrets must be at least 8 characters long and not match existing CI/CD variable names. Secrets not meeting these criteria won't be masked."
|
||||||
|
isEnabled={value || false}
|
||||||
|
onChange={(checked) => {
|
||||||
|
onChange(checked);
|
||||||
|
if (!checked) {
|
||||||
|
setValue("destinationConfig.shouldHideSecrets", false);
|
||||||
|
}
|
||||||
|
}}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="destinationConfig.shouldHideSecrets"
|
||||||
|
render={({ field: { onChange, value } }) => (
|
||||||
|
<div className='"max-h-32 opacity-100" transition-all duration-300'>
|
||||||
|
<SecretProtectionOption
|
||||||
|
id="should-hide-secrets"
|
||||||
|
title="Mark Infisical secrets in GitLab as 'Protected' secrets"
|
||||||
|
tooltip="Secrets can only be marked as hidden if they are also masked."
|
||||||
|
isEnabled={value || false}
|
||||||
|
onChange={onChange}
|
||||||
|
isDisabled={!shouldMaskSecrets}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -14,6 +14,7 @@ import { DatabricksSyncFields } from "./DatabricksSyncFields";
|
|||||||
import { FlyioSyncFields } from "./FlyioSyncFields";
|
import { FlyioSyncFields } from "./FlyioSyncFields";
|
||||||
import { GcpSyncFields } from "./GcpSyncFields";
|
import { GcpSyncFields } from "./GcpSyncFields";
|
||||||
import { GitHubSyncFields } from "./GitHubSyncFields";
|
import { GitHubSyncFields } from "./GitHubSyncFields";
|
||||||
|
import { GitLabSyncFields } from "./GitLabSyncFields";
|
||||||
import { HCVaultSyncFields } from "./HCVaultSyncFields";
|
import { HCVaultSyncFields } from "./HCVaultSyncFields";
|
||||||
import { HerokuSyncFields } from "./HerokuSyncFields";
|
import { HerokuSyncFields } from "./HerokuSyncFields";
|
||||||
import { HumanitecSyncFields } from "./HumanitecSyncFields";
|
import { HumanitecSyncFields } from "./HumanitecSyncFields";
|
||||||
@@ -70,6 +71,8 @@ export const SecretSyncDestinationFields = () => {
|
|||||||
return <RenderSyncFields />;
|
return <RenderSyncFields />;
|
||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
return <FlyioSyncFields />;
|
return <FlyioSyncFields />;
|
||||||
|
case SecretSync.Gitlab:
|
||||||
|
return <GitLabSyncFields />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Config Field: ${destination}`);
|
throw new Error(`Unhandled Destination Config Field: ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -55,6 +55,7 @@ export const SecretSyncOptionsFields = ({ hideInitialSync }: Props) => {
|
|||||||
case SecretSync.Heroku:
|
case SecretSync.Heroku:
|
||||||
case SecretSync.Render:
|
case SecretSync.Render:
|
||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
|
case SecretSync.Gitlab:
|
||||||
AdditionalSyncOptionsFieldsComponent = null;
|
AdditionalSyncOptionsFieldsComponent = null;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
|
|||||||
@@ -0,0 +1,32 @@
|
|||||||
|
import { useFormContext } from "react-hook-form";
|
||||||
|
|
||||||
|
import { GenericFieldLabel } from "@app/components/secret-syncs";
|
||||||
|
import { TSecretSyncForm } from "@app/components/secret-syncs/forms/schemas";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
|
||||||
|
export const GitLabSyncReviewFields = () => {
|
||||||
|
const { watch } = useFormContext<TSecretSyncForm & { destination: SecretSync.Gitlab }>();
|
||||||
|
const projectId = watch("destinationConfig.projectId");
|
||||||
|
const targetEnvironment = watch("destinationConfig.targetEnvironment");
|
||||||
|
const groupId = watch("destinationConfig.groupId");
|
||||||
|
const scope = watch("destinationConfig.scope");
|
||||||
|
const shouldProtectSecrets = watch("destinationConfig.shouldProtectSecrets");
|
||||||
|
const shouldMaskSecrets = watch("destinationConfig.shouldMaskSecrets");
|
||||||
|
const shouldHideSecrets = watch("destinationConfig.shouldHideSecrets");
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<GenericFieldLabel label="Scope">{scope}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Project ID">{projectId}</GenericFieldLabel>
|
||||||
|
{groupId && <GenericFieldLabel label="Group ID">{groupId}</GenericFieldLabel>}
|
||||||
|
{targetEnvironment && (
|
||||||
|
<GenericFieldLabel label="Environment">{targetEnvironment}</GenericFieldLabel>
|
||||||
|
)}
|
||||||
|
<GenericFieldLabel label="Protect Secrets">
|
||||||
|
{shouldProtectSecrets ? "Yes" : "No"}
|
||||||
|
</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Mask Secrets">{shouldMaskSecrets ? "Yes" : "No"}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Hide Secrets">{shouldHideSecrets ? "Yes" : "No"}</GenericFieldLabel>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -23,6 +23,7 @@ import { DatabricksSyncReviewFields } from "./DatabricksSyncReviewFields";
|
|||||||
import { FlyioSyncReviewFields } from "./FlyioSyncReviewFields";
|
import { FlyioSyncReviewFields } from "./FlyioSyncReviewFields";
|
||||||
import { GcpSyncReviewFields } from "./GcpSyncReviewFields";
|
import { GcpSyncReviewFields } from "./GcpSyncReviewFields";
|
||||||
import { GitHubSyncReviewFields } from "./GitHubSyncReviewFields";
|
import { GitHubSyncReviewFields } from "./GitHubSyncReviewFields";
|
||||||
|
import { GitLabSyncReviewFields } from "./GitLabSyncReviewFields";
|
||||||
import { HCVaultSyncReviewFields } from "./HCVaultSyncReviewFields";
|
import { HCVaultSyncReviewFields } from "./HCVaultSyncReviewFields";
|
||||||
import { HerokuSyncReviewFields } from "./HerokuSyncReviewFields";
|
import { HerokuSyncReviewFields } from "./HerokuSyncReviewFields";
|
||||||
import { HumanitecSyncReviewFields } from "./HumanitecSyncReviewFields";
|
import { HumanitecSyncReviewFields } from "./HumanitecSyncReviewFields";
|
||||||
@@ -116,6 +117,9 @@ export const SecretSyncReviewFields = () => {
|
|||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
DestinationFieldsComponent = <FlyioSyncReviewFields />;
|
DestinationFieldsComponent = <FlyioSyncReviewFields />;
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Gitlab:
|
||||||
|
DestinationFieldsComponent = <GitLabSyncReviewFields />;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Review Fields: ${destination}`);
|
throw new Error(`Unhandled Destination Review Fields: ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,32 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { BaseSecretSyncSchema } from "@app/components/secret-syncs/forms/schemas/base-secret-sync-schema";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
import { GitlabSyncScope } from "@app/hooks/api/secretSyncs/types/gitlab-sync";
|
||||||
|
|
||||||
|
export const GitlabSyncDestinationSchema = BaseSecretSyncSchema().merge(
|
||||||
|
z.object({
|
||||||
|
destination: z.literal(SecretSync.Gitlab),
|
||||||
|
destinationConfig: z.discriminatedUnion("scope", [
|
||||||
|
z.object({
|
||||||
|
scope: z.literal(GitlabSyncScope.Individual),
|
||||||
|
projectId: z.string().trim().min(1, "Project ID required"),
|
||||||
|
projectName: z.string().trim().min(1, "Project name required"),
|
||||||
|
targetEnvironment: z.string().optional(),
|
||||||
|
shouldProtectSecrets: z.boolean().optional().default(false),
|
||||||
|
shouldMaskSecrets: z.boolean().optional().default(false),
|
||||||
|
shouldHideSecrets: z.boolean().optional().default(false)
|
||||||
|
}),
|
||||||
|
z.object({
|
||||||
|
scope: z.literal(GitlabSyncScope.Group),
|
||||||
|
projectId: z.string().trim().min(1, "Project ID required"),
|
||||||
|
projectName: z.string().trim().min(1, "Project name required"),
|
||||||
|
targetEnvironment: z.string().optional(),
|
||||||
|
groupId: z.string().trim().min(1, "Group ID required"),
|
||||||
|
shouldProtectSecrets: z.boolean().optional().default(false),
|
||||||
|
shouldMaskSecrets: z.boolean().optional().default(false),
|
||||||
|
shouldHideSecrets: z.boolean().optional().default(false)
|
||||||
|
})
|
||||||
|
])
|
||||||
|
})
|
||||||
|
);
|
||||||
@@ -11,6 +11,7 @@ import { DatabricksSyncDestinationSchema } from "./databricks-sync-destination-s
|
|||||||
import { FlyioSyncDestinationSchema } from "./flyio-sync-destination-schema";
|
import { FlyioSyncDestinationSchema } from "./flyio-sync-destination-schema";
|
||||||
import { GcpSyncDestinationSchema } from "./gcp-sync-destination-schema";
|
import { GcpSyncDestinationSchema } from "./gcp-sync-destination-schema";
|
||||||
import { GitHubSyncDestinationSchema } from "./github-sync-destination-schema";
|
import { GitHubSyncDestinationSchema } from "./github-sync-destination-schema";
|
||||||
|
import { GitlabSyncDestinationSchema } from "./gitlab-sync-destination-schema";
|
||||||
import { HCVaultSyncDestinationSchema } from "./hc-vault-sync-destination-schema";
|
import { HCVaultSyncDestinationSchema } from "./hc-vault-sync-destination-schema";
|
||||||
import { HerokuSyncDestinationSchema } from "./heroku-sync-destination-schema";
|
import { HerokuSyncDestinationSchema } from "./heroku-sync-destination-schema";
|
||||||
import { HumanitecSyncDestinationSchema } from "./humanitec-sync-destination-schema";
|
import { HumanitecSyncDestinationSchema } from "./humanitec-sync-destination-schema";
|
||||||
@@ -41,7 +42,8 @@ const SecretSyncUnionSchema = z.discriminatedUnion("destination", [
|
|||||||
OnePassSyncDestinationSchema,
|
OnePassSyncDestinationSchema,
|
||||||
HerokuSyncDestinationSchema,
|
HerokuSyncDestinationSchema,
|
||||||
RenderSyncDestinationSchema,
|
RenderSyncDestinationSchema,
|
||||||
FlyioSyncDestinationSchema
|
FlyioSyncDestinationSchema,
|
||||||
|
GitlabSyncDestinationSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const SecretSyncFormSchema = SecretSyncUnionSchema;
|
export const SecretSyncFormSchema = SecretSyncUnionSchema;
|
||||||
|
|||||||
@@ -23,6 +23,7 @@ import {
|
|||||||
GcpConnectionMethod,
|
GcpConnectionMethod,
|
||||||
GitHubConnectionMethod,
|
GitHubConnectionMethod,
|
||||||
GitHubRadarConnectionMethod,
|
GitHubRadarConnectionMethod,
|
||||||
|
GitlabConnectionMethod,
|
||||||
HCVaultConnectionMethod,
|
HCVaultConnectionMethod,
|
||||||
HumanitecConnectionMethod,
|
HumanitecConnectionMethod,
|
||||||
LdapConnectionMethod,
|
LdapConnectionMethod,
|
||||||
@@ -84,7 +85,8 @@ export const APP_CONNECTION_MAP: Record<
|
|||||||
[AppConnection.OnePass]: { name: "1Password", image: "1Password.png" },
|
[AppConnection.OnePass]: { name: "1Password", image: "1Password.png" },
|
||||||
[AppConnection.Heroku]: { name: "Heroku", image: "Heroku.png" },
|
[AppConnection.Heroku]: { name: "Heroku", image: "Heroku.png" },
|
||||||
[AppConnection.Render]: { name: "Render", image: "Render.png" },
|
[AppConnection.Render]: { name: "Render", image: "Render.png" },
|
||||||
[AppConnection.Flyio]: { name: "Fly.io", image: "Flyio.svg" }
|
[AppConnection.Flyio]: { name: "Fly.io", image: "Flyio.svg" },
|
||||||
|
[AppConnection.Gitlab]: { name: "Gitlab", image: "GitLab.png" }
|
||||||
};
|
};
|
||||||
|
|
||||||
export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => {
|
export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => {
|
||||||
@@ -98,6 +100,7 @@ export const getAppConnectionMethodDetails = (method: TAppConnection["method"])
|
|||||||
case AzureDevOpsConnectionMethod.OAuth:
|
case AzureDevOpsConnectionMethod.OAuth:
|
||||||
case GitHubConnectionMethod.OAuth:
|
case GitHubConnectionMethod.OAuth:
|
||||||
case HerokuConnectionMethod.OAuth:
|
case HerokuConnectionMethod.OAuth:
|
||||||
|
case GitlabConnectionMethod.OAuth:
|
||||||
return { name: "OAuth", icon: faPassport };
|
return { name: "OAuth", icon: faPassport };
|
||||||
case AwsConnectionMethod.AccessKey:
|
case AwsConnectionMethod.AccessKey:
|
||||||
case OCIConnectionMethod.AccessKey:
|
case OCIConnectionMethod.AccessKey:
|
||||||
|
|||||||
@@ -73,6 +73,10 @@ export const SECRET_SYNC_MAP: Record<SecretSync, { name: string; image: string }
|
|||||||
[SecretSync.Flyio]: {
|
[SecretSync.Flyio]: {
|
||||||
name: "Fly.io",
|
name: "Fly.io",
|
||||||
image: "Flyio.svg"
|
image: "Flyio.svg"
|
||||||
|
},
|
||||||
|
[SecretSync.Gitlab]: {
|
||||||
|
name: "Gitlab",
|
||||||
|
image: "GitLab.png"
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -96,7 +100,8 @@ export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
|||||||
[SecretSync.OnePass]: AppConnection.OnePass,
|
[SecretSync.OnePass]: AppConnection.OnePass,
|
||||||
[SecretSync.Heroku]: AppConnection.Heroku,
|
[SecretSync.Heroku]: AppConnection.Heroku,
|
||||||
[SecretSync.Render]: AppConnection.Render,
|
[SecretSync.Render]: AppConnection.Render,
|
||||||
[SecretSync.Flyio]: AppConnection.Flyio
|
[SecretSync.Flyio]: AppConnection.Flyio,
|
||||||
|
[SecretSync.Gitlab]: AppConnection.Gitlab
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP: Record<
|
export const SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP: Record<
|
||||||
|
|||||||
@@ -25,5 +25,6 @@ export enum AppConnection {
|
|||||||
OnePass = "1password",
|
OnePass = "1password",
|
||||||
Heroku = "heroku",
|
Heroku = "heroku",
|
||||||
Render = "render",
|
Render = "render",
|
||||||
Flyio = "flyio"
|
Flyio = "flyio",
|
||||||
|
Gitlab = "gitlab"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
export * from "./queries";
|
||||||
|
export * from "./types";
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
import { useQuery, UseQueryOptions } from "@tanstack/react-query";
|
||||||
|
|
||||||
|
import { apiRequest } from "@app/config/request";
|
||||||
|
|
||||||
|
import { appConnectionKeys } from "../queries";
|
||||||
|
import { TGitLabGroup, TGitLabProject } from "./types";
|
||||||
|
|
||||||
|
const gitlabConnectionKeys = {
|
||||||
|
all: [...appConnectionKeys.all, "gitlab"] as const,
|
||||||
|
listProjects: (connectionId: string, group?: string) =>
|
||||||
|
[...gitlabConnectionKeys.all, "projects", connectionId, group] as const,
|
||||||
|
listGroups: (connectionId: string) =>
|
||||||
|
[...gitlabConnectionKeys.all, "groups", connectionId] as const
|
||||||
|
};
|
||||||
|
|
||||||
|
export const useGitlabConnectionListProjects = (
|
||||||
|
connectionId: string,
|
||||||
|
group?: string,
|
||||||
|
options?: Omit<
|
||||||
|
UseQueryOptions<
|
||||||
|
TGitLabProject[],
|
||||||
|
unknown,
|
||||||
|
TGitLabProject[],
|
||||||
|
ReturnType<typeof gitlabConnectionKeys.listProjects>
|
||||||
|
>,
|
||||||
|
"queryKey" | "queryFn"
|
||||||
|
>
|
||||||
|
) => {
|
||||||
|
return useQuery({
|
||||||
|
queryKey: gitlabConnectionKeys.listProjects(connectionId, group),
|
||||||
|
queryFn: async () => {
|
||||||
|
const { data } = await apiRequest.get<TGitLabProject[]>(
|
||||||
|
`/api/v1/app-connections/gitlab/${connectionId}/projects${group ? `?group=${group}` : ""}`
|
||||||
|
);
|
||||||
|
|
||||||
|
return data;
|
||||||
|
},
|
||||||
|
...options
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
|
export const useGitlabConnectionListGroups = (
|
||||||
|
connectionId: string,
|
||||||
|
options?: Omit<
|
||||||
|
UseQueryOptions<
|
||||||
|
TGitLabGroup[],
|
||||||
|
unknown,
|
||||||
|
TGitLabGroup[],
|
||||||
|
ReturnType<typeof gitlabConnectionKeys.listGroups>
|
||||||
|
>,
|
||||||
|
"queryKey" | "queryFn"
|
||||||
|
>
|
||||||
|
) => {
|
||||||
|
return useQuery({
|
||||||
|
queryKey: gitlabConnectionKeys.listGroups(connectionId),
|
||||||
|
queryFn: async () => {
|
||||||
|
const { data } = await apiRequest.get<TGitLabGroup[]>(
|
||||||
|
`/api/v1/app-connections/gitlab/${connectionId}/groups`
|
||||||
|
);
|
||||||
|
|
||||||
|
return data;
|
||||||
|
},
|
||||||
|
...options
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
export type TGitLabProject = {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGitLabGroup = {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
};
|
||||||
@@ -123,6 +123,11 @@ export type TFlyioConnectionOption = TAppConnectionOptionBase & {
|
|||||||
app: AppConnection.Flyio;
|
app: AppConnection.Flyio;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export type TGitlabConnectionOption = TAppConnectionOptionBase & {
|
||||||
|
app: AppConnection.Gitlab;
|
||||||
|
oauthClientId?: string;
|
||||||
|
};
|
||||||
|
|
||||||
export type TAppConnectionOption =
|
export type TAppConnectionOption =
|
||||||
| TAwsConnectionOption
|
| TAwsConnectionOption
|
||||||
| TGitHubConnectionOption
|
| TGitHubConnectionOption
|
||||||
@@ -148,7 +153,8 @@ export type TAppConnectionOption =
|
|||||||
| TOnePassConnectionOption
|
| TOnePassConnectionOption
|
||||||
| THerokuConnectionOption
|
| THerokuConnectionOption
|
||||||
| TRenderConnectionOption
|
| TRenderConnectionOption
|
||||||
| TFlyioConnectionOption;
|
| TFlyioConnectionOption
|
||||||
|
| TGitlabConnectionOption;
|
||||||
|
|
||||||
export type TAppConnectionOptionMap = {
|
export type TAppConnectionOptionMap = {
|
||||||
[AppConnection.AWS]: TAwsConnectionOption;
|
[AppConnection.AWS]: TAwsConnectionOption;
|
||||||
@@ -178,4 +184,5 @@ export type TAppConnectionOptionMap = {
|
|||||||
[AppConnection.Heroku]: THerokuConnectionOption;
|
[AppConnection.Heroku]: THerokuConnectionOption;
|
||||||
[AppConnection.Render]: TRenderConnectionOption;
|
[AppConnection.Render]: TRenderConnectionOption;
|
||||||
[AppConnection.Flyio]: TFlyioConnectionOption;
|
[AppConnection.Flyio]: TFlyioConnectionOption;
|
||||||
|
[AppConnection.Gitlab]: TGitlabConnectionOption;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import { TRootAppConnection } from "@app/hooks/api/appConnections/types/root-connection";
|
||||||
|
|
||||||
|
export enum GitlabConnectionMethod {
|
||||||
|
AccessToken = "access-token",
|
||||||
|
OAuth = "oauth"
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TGitlabConnection = TRootAppConnection & { app: AppConnection.Gitlab } & (
|
||||||
|
| {
|
||||||
|
method: GitlabConnectionMethod.AccessToken;
|
||||||
|
credentials: {
|
||||||
|
instanceUrl?: string;
|
||||||
|
accessToken: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
method: GitlabConnectionMethod.OAuth;
|
||||||
|
credentials: {
|
||||||
|
code: string;
|
||||||
|
instanceUrl?: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
);
|
||||||
@@ -13,6 +13,7 @@ import { TFlyioConnection } from "./flyio-connection";
|
|||||||
import { TGcpConnection } from "./gcp-connection";
|
import { TGcpConnection } from "./gcp-connection";
|
||||||
import { TGitHubConnection } from "./github-connection";
|
import { TGitHubConnection } from "./github-connection";
|
||||||
import { TGitHubRadarConnection } from "./github-radar-connection";
|
import { TGitHubRadarConnection } from "./github-radar-connection";
|
||||||
|
import { TGitlabConnection } from "./gitlab-connection";
|
||||||
import { THCVaultConnection } from "./hc-vault-connection";
|
import { THCVaultConnection } from "./hc-vault-connection";
|
||||||
import { THerokuConnection } from "./heroku-connection";
|
import { THerokuConnection } from "./heroku-connection";
|
||||||
import { THumanitecConnection } from "./humanitec-connection";
|
import { THumanitecConnection } from "./humanitec-connection";
|
||||||
@@ -41,6 +42,7 @@ export * from "./flyio-connection";
|
|||||||
export * from "./gcp-connection";
|
export * from "./gcp-connection";
|
||||||
export * from "./github-connection";
|
export * from "./github-connection";
|
||||||
export * from "./github-radar-connection";
|
export * from "./github-radar-connection";
|
||||||
|
export * from "./gitlab-connection";
|
||||||
export * from "./hc-vault-connection";
|
export * from "./hc-vault-connection";
|
||||||
export * from "./heroku-connection";
|
export * from "./heroku-connection";
|
||||||
export * from "./humanitec-connection";
|
export * from "./humanitec-connection";
|
||||||
@@ -83,7 +85,8 @@ export type TAppConnection =
|
|||||||
| TOnePassConnection
|
| TOnePassConnection
|
||||||
| THerokuConnection
|
| THerokuConnection
|
||||||
| TRenderConnection
|
| TRenderConnection
|
||||||
| TFlyioConnection;
|
| TFlyioConnection
|
||||||
|
| TGitlabConnection;
|
||||||
|
|
||||||
export type TAvailableAppConnection = Pick<TAppConnection, "name" | "id">;
|
export type TAvailableAppConnection = Pick<TAppConnection, "name" | "id">;
|
||||||
|
|
||||||
@@ -138,4 +141,5 @@ export type TAppConnectionMap = {
|
|||||||
[AppConnection.Heroku]: THerokuConnection;
|
[AppConnection.Heroku]: THerokuConnection;
|
||||||
[AppConnection.Render]: TRenderConnection;
|
[AppConnection.Render]: TRenderConnection;
|
||||||
[AppConnection.Flyio]: TFlyioConnection;
|
[AppConnection.Flyio]: TFlyioConnection;
|
||||||
|
[AppConnection.Gitlab]: TGitlabConnection;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -18,7 +18,8 @@ export enum SecretSync {
|
|||||||
OnePass = "1password",
|
OnePass = "1password",
|
||||||
Heroku = "heroku",
|
Heroku = "heroku",
|
||||||
Render = "render",
|
Render = "render",
|
||||||
Flyio = "flyio"
|
Flyio = "flyio",
|
||||||
|
Gitlab = "gitlab"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum SecretSyncStatus {
|
export enum SecretSyncStatus {
|
||||||
|
|||||||
@@ -0,0 +1,37 @@
|
|||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
import { TRootSecretSync } from "@app/hooks/api/secretSyncs/types/root-sync";
|
||||||
|
|
||||||
|
export enum GitlabSyncScope {
|
||||||
|
Individual = "individual",
|
||||||
|
Group = "group"
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TGitlabSync = TRootSecretSync & {
|
||||||
|
destination: SecretSync.Gitlab;
|
||||||
|
destinationConfig:
|
||||||
|
| {
|
||||||
|
scope: GitlabSyncScope.Individual;
|
||||||
|
projectId: string;
|
||||||
|
projectName: string;
|
||||||
|
targetEnvironment?: string;
|
||||||
|
shouldProtectSecrets?: boolean;
|
||||||
|
shouldMaskSecrets?: boolean;
|
||||||
|
shouldHideSecrets?: boolean;
|
||||||
|
}
|
||||||
|
| {
|
||||||
|
scope: GitlabSyncScope.Group;
|
||||||
|
groupId: string;
|
||||||
|
projectId: string;
|
||||||
|
projectName: string;
|
||||||
|
targetEnvironment?: string;
|
||||||
|
shouldProtectSecrets?: boolean;
|
||||||
|
shouldMaskSecrets?: boolean;
|
||||||
|
shouldHideSecrets?: boolean;
|
||||||
|
};
|
||||||
|
connection: {
|
||||||
|
app: AppConnection.Gitlab;
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -13,6 +13,7 @@ import { TDatabricksSync } from "./databricks-sync";
|
|||||||
import { TFlyioSync } from "./flyio-sync";
|
import { TFlyioSync } from "./flyio-sync";
|
||||||
import { TGcpSync } from "./gcp-sync";
|
import { TGcpSync } from "./gcp-sync";
|
||||||
import { TGitHubSync } from "./github-sync";
|
import { TGitHubSync } from "./github-sync";
|
||||||
|
import { TGitlabSync } from "./gitlab-sync";
|
||||||
import { THCVaultSync } from "./hc-vault-sync";
|
import { THCVaultSync } from "./hc-vault-sync";
|
||||||
import { THerokuSync } from "./heroku-sync";
|
import { THerokuSync } from "./heroku-sync";
|
||||||
import { THumanitecSync } from "./humanitec-sync";
|
import { THumanitecSync } from "./humanitec-sync";
|
||||||
@@ -49,7 +50,8 @@ export type TSecretSync =
|
|||||||
| TOnePassSync
|
| TOnePassSync
|
||||||
| THerokuSync
|
| THerokuSync
|
||||||
| TRenderSync
|
| TRenderSync
|
||||||
| TFlyioSync;
|
| TFlyioSync
|
||||||
|
| TGitlabSync;
|
||||||
|
|
||||||
export type TListSecretSyncs = { secretSyncs: TSecretSync[] };
|
export type TListSecretSyncs = { secretSyncs: TSecretSync[] };
|
||||||
|
|
||||||
|
|||||||
@@ -22,6 +22,7 @@ import { FlyioConnectionForm } from "./FlyioConnectionForm";
|
|||||||
import { GcpConnectionForm } from "./GcpConnectionForm";
|
import { GcpConnectionForm } from "./GcpConnectionForm";
|
||||||
import { GitHubConnectionForm } from "./GitHubConnectionForm";
|
import { GitHubConnectionForm } from "./GitHubConnectionForm";
|
||||||
import { GitHubRadarConnectionForm } from "./GitHubRadarConnectionForm";
|
import { GitHubRadarConnectionForm } from "./GitHubRadarConnectionForm";
|
||||||
|
import { GitLabConnectionForm } from "./GitLabConnectionForm";
|
||||||
import { HCVaultConnectionForm } from "./HCVaultConnectionForm";
|
import { HCVaultConnectionForm } from "./HCVaultConnectionForm";
|
||||||
import { HerokuConnectionForm } from "./HerokuAppConnectionForm";
|
import { HerokuConnectionForm } from "./HerokuAppConnectionForm";
|
||||||
import { HumanitecConnectionForm } from "./HumanitecConnectionForm";
|
import { HumanitecConnectionForm } from "./HumanitecConnectionForm";
|
||||||
@@ -128,6 +129,8 @@ const CreateForm = ({ app, onComplete }: CreateFormProps) => {
|
|||||||
return <RenderConnectionForm onSubmit={onSubmit} />;
|
return <RenderConnectionForm onSubmit={onSubmit} />;
|
||||||
case AppConnection.Flyio:
|
case AppConnection.Flyio:
|
||||||
return <FlyioConnectionForm onSubmit={onSubmit} />;
|
return <FlyioConnectionForm onSubmit={onSubmit} />;
|
||||||
|
case AppConnection.Gitlab:
|
||||||
|
return <GitLabConnectionForm onSubmit={onSubmit} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App ${app}`);
|
throw new Error(`Unhandled App ${app}`);
|
||||||
}
|
}
|
||||||
@@ -218,6 +221,8 @@ const UpdateForm = ({ appConnection, onComplete }: UpdateFormProps) => {
|
|||||||
return <RenderConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
return <RenderConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
case AppConnection.Flyio:
|
case AppConnection.Flyio:
|
||||||
return <FlyioConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
return <FlyioConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
|
case AppConnection.Gitlab:
|
||||||
|
return <GitLabConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`);
|
throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,297 @@
|
|||||||
|
/* eslint-disable no-case-declarations */
|
||||||
|
/* eslint-disable no-nested-ternary */
|
||||||
|
import crypto from "crypto";
|
||||||
|
|
||||||
|
import { useState } from "react";
|
||||||
|
import { Controller, FormProvider, useForm } from "react-hook-form";
|
||||||
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import {
|
||||||
|
Button,
|
||||||
|
FormControl,
|
||||||
|
Input,
|
||||||
|
ModalClose,
|
||||||
|
SecretInput,
|
||||||
|
Select,
|
||||||
|
SelectItem
|
||||||
|
} from "@app/components/v2";
|
||||||
|
import { APP_CONNECTION_MAP, getAppConnectionMethodDetails } from "@app/helpers/appConnections";
|
||||||
|
import { isInfisicalCloud } from "@app/helpers/platform";
|
||||||
|
import { useGetAppConnectionOption } from "@app/hooks/api/appConnections";
|
||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import {
|
||||||
|
GitlabConnectionMethod,
|
||||||
|
TGitlabConnection
|
||||||
|
} from "@app/hooks/api/appConnections/types/gitlab-connection";
|
||||||
|
|
||||||
|
import {
|
||||||
|
genericAppConnectionFieldsSchema,
|
||||||
|
GenericAppConnectionsFields
|
||||||
|
} from "./GenericAppConnectionFields";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
appConnection?: TGitlabConnection;
|
||||||
|
onSubmit: (formData: FormData) => Promise<void>;
|
||||||
|
};
|
||||||
|
|
||||||
|
const formSchema = z.discriminatedUnion("method", [
|
||||||
|
genericAppConnectionFieldsSchema.extend({
|
||||||
|
app: z.literal(AppConnection.Gitlab),
|
||||||
|
method: z.literal(GitlabConnectionMethod.AccessToken),
|
||||||
|
credentials: z.object({
|
||||||
|
accessToken: z.string().min(1, "Access token is required"),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.transform((value) => value || undefined)
|
||||||
|
.refine((value) => (!value ? true : z.string().url().safeParse(value).success), {
|
||||||
|
message: "Invalid instance URL"
|
||||||
|
})
|
||||||
|
.optional()
|
||||||
|
})
|
||||||
|
}),
|
||||||
|
genericAppConnectionFieldsSchema.extend({
|
||||||
|
app: z.literal(AppConnection.Gitlab),
|
||||||
|
method: z.literal(GitlabConnectionMethod.OAuth),
|
||||||
|
credentials: z.object({
|
||||||
|
code: z.string().min(1, "Code is required"),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.transform((value) => value || undefined)
|
||||||
|
.refine((value) => (!value ? true : z.string().url().safeParse(value).success), {
|
||||||
|
message: "Invalid instance URL"
|
||||||
|
})
|
||||||
|
.optional()
|
||||||
|
})
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
type FormData = z.infer<typeof formSchema>;
|
||||||
|
|
||||||
|
export const GitLabConnectionForm = ({ appConnection, onSubmit: formSubmit }: Props) => {
|
||||||
|
const isUpdate = Boolean(appConnection);
|
||||||
|
const [isRedirecting, setIsRedirecting] = useState(false);
|
||||||
|
|
||||||
|
const {
|
||||||
|
option: { oauthClientId },
|
||||||
|
isLoading
|
||||||
|
} = useGetAppConnectionOption(AppConnection.Gitlab);
|
||||||
|
|
||||||
|
const form = useForm<FormData>({
|
||||||
|
resolver: zodResolver(formSchema),
|
||||||
|
defaultValues:
|
||||||
|
appConnection?.method === GitlabConnectionMethod.OAuth
|
||||||
|
? { ...appConnection, credentials: { code: "custom" } }
|
||||||
|
: (appConnection ??
|
||||||
|
({
|
||||||
|
app: AppConnection.Gitlab,
|
||||||
|
method: GitlabConnectionMethod.AccessToken,
|
||||||
|
credentials: {
|
||||||
|
accessToken: "",
|
||||||
|
instanceUrl: ""
|
||||||
|
}
|
||||||
|
} as FormData))
|
||||||
|
});
|
||||||
|
|
||||||
|
const {
|
||||||
|
handleSubmit,
|
||||||
|
control,
|
||||||
|
watch,
|
||||||
|
setValue,
|
||||||
|
formState: { isSubmitting, isDirty }
|
||||||
|
} = form;
|
||||||
|
|
||||||
|
const selectedMethod = watch("method");
|
||||||
|
const gitLabURL = watch("credentials.instanceUrl");
|
||||||
|
|
||||||
|
const onSubmit = async (formData: FormData) => {
|
||||||
|
try {
|
||||||
|
switch (formData.method) {
|
||||||
|
case GitlabConnectionMethod.AccessToken:
|
||||||
|
await formSubmit(formData);
|
||||||
|
break;
|
||||||
|
|
||||||
|
case GitlabConnectionMethod.OAuth:
|
||||||
|
if (!oauthClientId) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
setIsRedirecting(true);
|
||||||
|
|
||||||
|
// Generate CSRF token
|
||||||
|
const state = crypto.randomBytes(16).toString("hex");
|
||||||
|
|
||||||
|
// Store state and form data for callback
|
||||||
|
localStorage.setItem("latestCSRFToken", state);
|
||||||
|
localStorage.setItem(
|
||||||
|
"gitlabConnectionFormData",
|
||||||
|
JSON.stringify({
|
||||||
|
...formData,
|
||||||
|
connectionId: appConnection?.id,
|
||||||
|
isUpdate
|
||||||
|
})
|
||||||
|
);
|
||||||
|
|
||||||
|
// Redirect to Gitlab OAuth
|
||||||
|
const baseURL =
|
||||||
|
gitLabURL && (gitLabURL as string)?.trim() !== ""
|
||||||
|
? (gitLabURL as string)?.trim()
|
||||||
|
: "https://gitlab.com";
|
||||||
|
const oauthUrl = new URL(`${baseURL}/oauth/authorize`);
|
||||||
|
oauthUrl.searchParams.set("client_id", oauthClientId);
|
||||||
|
oauthUrl.searchParams.set(
|
||||||
|
"redirect_uri",
|
||||||
|
`${window.location.origin}/integrations/gitlab/oauth2/callback`
|
||||||
|
);
|
||||||
|
oauthUrl.searchParams.set("response_type", "code");
|
||||||
|
oauthUrl.searchParams.set("state", state);
|
||||||
|
|
||||||
|
window.location.assign(oauthUrl.toString());
|
||||||
|
break;
|
||||||
|
|
||||||
|
default:
|
||||||
|
throw new Error("Unhandled Gitlab Connection method");
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
console.error("Error handling form submission:", error);
|
||||||
|
setIsRedirecting(false);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let isMissingConfig: boolean;
|
||||||
|
|
||||||
|
switch (selectedMethod) {
|
||||||
|
case GitlabConnectionMethod.OAuth:
|
||||||
|
isMissingConfig = !oauthClientId;
|
||||||
|
break;
|
||||||
|
case GitlabConnectionMethod.AccessToken:
|
||||||
|
isMissingConfig = false;
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
throw new Error(`Unhandled Gitlab Connection method: ${selectedMethod}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
const methodDetails = getAppConnectionMethodDetails(selectedMethod);
|
||||||
|
|
||||||
|
return (
|
||||||
|
<FormProvider {...form}>
|
||||||
|
<form onSubmit={handleSubmit(onSubmit)}>
|
||||||
|
{!isUpdate && <GenericAppConnectionsFields />}
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
name="credentials.instanceUrl"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Self-hosted URL (optional)"
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
tooltipText="Will default to GitLab Cloud if not specified."
|
||||||
|
>
|
||||||
|
<Input
|
||||||
|
value={value}
|
||||||
|
onChange={(e) => onChange(e.target.value)}
|
||||||
|
placeholder="https://gitlab.com"
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
name="method"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
tooltipText={`The method you would like to use to connect with ${
|
||||||
|
APP_CONNECTION_MAP[AppConnection.Gitlab].name
|
||||||
|
}. This field cannot be changed after creation.`}
|
||||||
|
errorText={
|
||||||
|
!isLoading && isMissingConfig && selectedMethod === GitlabConnectionMethod.OAuth
|
||||||
|
? `Environment variables have not been configured. ${
|
||||||
|
isInfisicalCloud()
|
||||||
|
? "Please contact Infisical."
|
||||||
|
: `See Docs to configure Gitlab ${methodDetails.name} Connections.`
|
||||||
|
}`
|
||||||
|
: error?.message
|
||||||
|
}
|
||||||
|
isError={Boolean(error?.message) || isMissingConfig}
|
||||||
|
label="Method"
|
||||||
|
>
|
||||||
|
<Select
|
||||||
|
isDisabled={isUpdate}
|
||||||
|
value={value}
|
||||||
|
onValueChange={(val) => {
|
||||||
|
onChange(val);
|
||||||
|
if (val === GitlabConnectionMethod.OAuth) {
|
||||||
|
setValue("credentials.code", "custom");
|
||||||
|
}
|
||||||
|
}}
|
||||||
|
className="w-full border border-mineshaft-500"
|
||||||
|
position="popper"
|
||||||
|
dropdownContainerClassName="max-w-none"
|
||||||
|
>
|
||||||
|
{Object.values(GitlabConnectionMethod).map((method) => {
|
||||||
|
return (
|
||||||
|
<SelectItem value={method} key={method}>
|
||||||
|
{getAppConnectionMethodDetails(method).name}{" "}
|
||||||
|
{method === GitlabConnectionMethod.AccessToken ? " (Recommended)" : ""}
|
||||||
|
</SelectItem>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</Select>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
|
||||||
|
{selectedMethod === GitlabConnectionMethod.AccessToken && (
|
||||||
|
<Controller
|
||||||
|
name="credentials.accessToken"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Access Token"
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
tooltipText="Your Gitlab Access Token"
|
||||||
|
>
|
||||||
|
<SecretInput
|
||||||
|
containerClassName="text-gray-400 group-focus-within:!border-primary-400/50 border border-mineshaft-500 bg-mineshaft-900 px-2.5 py-1.5"
|
||||||
|
value={value}
|
||||||
|
onChange={(e) => onChange(e.target.value)}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
|
||||||
|
<div className="mt-8 flex items-center">
|
||||||
|
<Button
|
||||||
|
className="mr-4"
|
||||||
|
size="sm"
|
||||||
|
type="submit"
|
||||||
|
colorSchema="secondary"
|
||||||
|
isLoading={isSubmitting || isRedirecting}
|
||||||
|
isDisabled={
|
||||||
|
isSubmitting ||
|
||||||
|
(!isUpdate && !isDirty) ||
|
||||||
|
(isMissingConfig && selectedMethod === GitlabConnectionMethod.OAuth) ||
|
||||||
|
isRedirecting
|
||||||
|
}
|
||||||
|
>
|
||||||
|
{isRedirecting && selectedMethod === GitlabConnectionMethod.OAuth
|
||||||
|
? "Redirecting to Gitlab..."
|
||||||
|
: isUpdate
|
||||||
|
? "Reconnect to Gitlab"
|
||||||
|
: "Connect to Gitlab"}
|
||||||
|
</Button>
|
||||||
|
<ModalClose asChild>
|
||||||
|
<Button colorSchema="secondary" variant="plain">
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
</ModalClose>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
</FormProvider>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
import { TGitlabSync } from "@app/hooks/api/secretSyncs/types/gitlab-sync";
|
||||||
|
|
||||||
|
import { getSecretSyncDestinationColValues } from "../helpers";
|
||||||
|
import { SecretSyncTableCell } from "../SecretSyncTableCell";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
secretSync: TGitlabSync;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const GitLabSyncDestinationCol = ({ secretSync }: Props) => {
|
||||||
|
const { primaryText, secondaryText } = getSecretSyncDestinationColValues(secretSync);
|
||||||
|
|
||||||
|
return <SecretSyncTableCell primaryText={primaryText} secondaryText={secondaryText} />;
|
||||||
|
};
|
||||||
@@ -11,6 +11,7 @@ import { DatabricksSyncDestinationCol } from "./DatabricksSyncDestinationCol";
|
|||||||
import { FlyioSyncDestinationCol } from "./FlyioSyncDestinationCol";
|
import { FlyioSyncDestinationCol } from "./FlyioSyncDestinationCol";
|
||||||
import { GcpSyncDestinationCol } from "./GcpSyncDestinationCol";
|
import { GcpSyncDestinationCol } from "./GcpSyncDestinationCol";
|
||||||
import { GitHubSyncDestinationCol } from "./GitHubSyncDestinationCol";
|
import { GitHubSyncDestinationCol } from "./GitHubSyncDestinationCol";
|
||||||
|
import { GitLabSyncDestinationCol } from "./GitLabSyncDestinationCol";
|
||||||
import { HCVaultSyncDestinationCol } from "./HCVaultSyncDestinationCol";
|
import { HCVaultSyncDestinationCol } from "./HCVaultSyncDestinationCol";
|
||||||
import { HerokuSyncDestinationCol } from "./HerokuSyncDestinationCol";
|
import { HerokuSyncDestinationCol } from "./HerokuSyncDestinationCol";
|
||||||
import { HumanitecSyncDestinationCol } from "./HumanitecSyncDestinationCol";
|
import { HumanitecSyncDestinationCol } from "./HumanitecSyncDestinationCol";
|
||||||
@@ -67,6 +68,8 @@ export const SecretSyncDestinationCol = ({ secretSync }: Props) => {
|
|||||||
return <RenderSyncDestinationCol secretSync={secretSync} />;
|
return <RenderSyncDestinationCol secretSync={secretSync} />;
|
||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
return <FlyioSyncDestinationCol secretSync={secretSync} />;
|
return <FlyioSyncDestinationCol secretSync={secretSync} />;
|
||||||
|
case SecretSync.Gitlab:
|
||||||
|
return <GitLabSyncDestinationCol secretSync={secretSync} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled Secret Sync Destination Col: ${(secretSync as TSecretSync).destination}`
|
`Unhandled Secret Sync Destination Col: ${(secretSync as TSecretSync).destination}`
|
||||||
|
|||||||
@@ -128,6 +128,10 @@ export const getSecretSyncDestinationColValues = (secretSync: TSecretSync) => {
|
|||||||
primaryText = destinationConfig.appId;
|
primaryText = destinationConfig.appId;
|
||||||
secondaryText = "App ID";
|
secondaryText = "App ID";
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Gitlab:
|
||||||
|
primaryText = destinationConfig.projectName;
|
||||||
|
secondaryText = destinationConfig.projectId;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Col Values ${destination}`);
|
throw new Error(`Unhandled Destination Col Values ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
import { GenericFieldLabel } from "@app/components/secret-syncs";
|
||||||
|
import { TGitlabSync } from "@app/hooks/api/secretSyncs/types/gitlab-sync";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
secretSync: TGitlabSync;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const GitLabSyncDestinationSection = ({ secretSync }: Props) => {
|
||||||
|
const {
|
||||||
|
destinationConfig: {
|
||||||
|
projectName,
|
||||||
|
projectId,
|
||||||
|
targetEnvironment,
|
||||||
|
shouldProtectSecrets,
|
||||||
|
shouldMaskSecrets,
|
||||||
|
shouldHideSecrets
|
||||||
|
}
|
||||||
|
} = secretSync;
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<GenericFieldLabel label="Project Name">{projectName}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Project ID">{projectId}</GenericFieldLabel>
|
||||||
|
{targetEnvironment && (
|
||||||
|
<GenericFieldLabel label="Environment">{targetEnvironment}</GenericFieldLabel>
|
||||||
|
)}
|
||||||
|
<GenericFieldLabel label="Protect Secrets">
|
||||||
|
{shouldProtectSecrets ? "Yes" : "No"}
|
||||||
|
</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Mask Secrets">{shouldMaskSecrets ? "Yes" : "No"}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Hide Secrets">{shouldHideSecrets ? "Yes" : "No"}</GenericFieldLabel>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -22,6 +22,7 @@ import { DatabricksSyncDestinationSection } from "./DatabricksSyncDestinationSec
|
|||||||
import { FlyioSyncDestinationSection } from "./FlyioSyncDestinationSection";
|
import { FlyioSyncDestinationSection } from "./FlyioSyncDestinationSection";
|
||||||
import { GcpSyncDestinationSection } from "./GcpSyncDestinationSection";
|
import { GcpSyncDestinationSection } from "./GcpSyncDestinationSection";
|
||||||
import { GitHubSyncDestinationSection } from "./GitHubSyncDestinationSection";
|
import { GitHubSyncDestinationSection } from "./GitHubSyncDestinationSection";
|
||||||
|
import { GitLabSyncDestinationSection } from "./GitLabSyncDestinationSection";
|
||||||
import { HCVaultSyncDestinationSection } from "./HCVaultSyncDestinationSection";
|
import { HCVaultSyncDestinationSection } from "./HCVaultSyncDestinationSection";
|
||||||
import { HerokuSyncDestinationSection } from "./HerokuSyncDestinationSection";
|
import { HerokuSyncDestinationSection } from "./HerokuSyncDestinationSection";
|
||||||
import { HumanitecSyncDestinationSection } from "./HumanitecSyncDestinationSection";
|
import { HumanitecSyncDestinationSection } from "./HumanitecSyncDestinationSection";
|
||||||
@@ -106,6 +107,9 @@ export const SecretSyncDestinationSection = ({ secretSync, onEditDestination }:
|
|||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
DestinationComponents = <FlyioSyncDestinationSection secretSync={secretSync} />;
|
DestinationComponents = <FlyioSyncDestinationSection secretSync={secretSync} />;
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Gitlab:
|
||||||
|
DestinationComponents = <GitLabSyncDestinationSection secretSync={secretSync} />;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Section components: ${destination}`);
|
throw new Error(`Unhandled Destination Section components: ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -58,6 +58,7 @@ export const SecretSyncOptionsSection = ({ secretSync, onEditOptions }: Props) =
|
|||||||
case SecretSync.Heroku:
|
case SecretSync.Heroku:
|
||||||
case SecretSync.Render:
|
case SecretSync.Render:
|
||||||
case SecretSync.Flyio:
|
case SecretSync.Flyio:
|
||||||
|
case SecretSync.Gitlab:
|
||||||
AdditionalSyncOptionsComponent = null;
|
AdditionalSyncOptionsComponent = null;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
|
|||||||
@@ -3,11 +3,13 @@ import { useNavigate, useSearch } from "@tanstack/react-router";
|
|||||||
|
|
||||||
import { ROUTE_PATHS } from "@app/const/routes";
|
import { ROUTE_PATHS } from "@app/const/routes";
|
||||||
import { useWorkspace } from "@app/context";
|
import { useWorkspace } from "@app/context";
|
||||||
import { useAuthorizeIntegration } from "@app/hooks/api";
|
import { useCreateAppConnection, useUpdateAppConnection } from "@app/hooks/api/appConnections";
|
||||||
|
import { GitlabConnectionMethod } from "@app/hooks/api/appConnections/types/gitlab-connection";
|
||||||
|
|
||||||
export const GitLabOAuthCallbackPage = () => {
|
export const GitLabOAuthCallbackPage = () => {
|
||||||
const navigate = useNavigate();
|
const navigate = useNavigate();
|
||||||
const { mutateAsync } = useAuthorizeIntegration();
|
const { mutateAsync: createAppConnection } = useCreateAppConnection();
|
||||||
|
const { mutateAsync: updateAppConnection } = useUpdateAppConnection();
|
||||||
|
|
||||||
const { code, state } = useSearch({
|
const { code, state } = useSearch({
|
||||||
from: ROUTE_PATHS.SecretManager.Integratons.GitlabOauthCallbackPage.id
|
from: ROUTE_PATHS.SecretManager.Integratons.GitlabOauthCallbackPage.id
|
||||||
@@ -17,37 +19,83 @@ export const GitLabOAuthCallbackPage = () => {
|
|||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
(async () => {
|
(async () => {
|
||||||
try {
|
try {
|
||||||
// validate state
|
// Validate CSRF state token
|
||||||
const [csrfToken, url] = (state as string).split("|", 2);
|
const [csrfToken] = (state as string).split("|", 2);
|
||||||
|
const storedState = localStorage.getItem("latestCSRFToken");
|
||||||
|
if (csrfToken !== storedState) {
|
||||||
|
console.error("CSRF token mismatch");
|
||||||
|
navigate({
|
||||||
|
to: "/organization/app-connections",
|
||||||
|
search: { error: "invalid_state" }
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
if (csrfToken !== localStorage.getItem("latestCSRFToken")) return;
|
|
||||||
localStorage.removeItem("latestCSRFToken");
|
localStorage.removeItem("latestCSRFToken");
|
||||||
|
|
||||||
const integrationAuth = await mutateAsync({
|
// Retrieve stored form dataAdd commentMore actions
|
||||||
workspaceId: currentWorkspace.id,
|
const storedFormData = localStorage.getItem("gitlabConnectionFormData");
|
||||||
code: code as string,
|
if (!storedFormData) {
|
||||||
integration: "gitlab",
|
console.error("No stored form data found");
|
||||||
...(url === ""
|
navigate({
|
||||||
? {}
|
to: "/organization/app-connections",
|
||||||
: {
|
search: { error: "missing_form_data" }
|
||||||
url
|
});
|
||||||
})
|
return;
|
||||||
});
|
}
|
||||||
|
|
||||||
|
const formData = JSON.parse(storedFormData);
|
||||||
|
localStorage.removeItem("gitlabConnectionFormData");
|
||||||
|
|
||||||
|
// Prepare app connection data with OAuth credentials
|
||||||
|
const connectionData = {
|
||||||
|
...formData,
|
||||||
|
method: GitlabConnectionMethod.OAuth,
|
||||||
|
credentials: {
|
||||||
|
code: code as string
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let appConnection;
|
||||||
|
|
||||||
|
// Create or update app connection
|
||||||
|
if (formData.isUpdate && formData.connectionId) {
|
||||||
|
appConnection = await updateAppConnection({
|
||||||
|
connectionId: formData.connectionId,
|
||||||
|
...connectionData
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
appConnection = await createAppConnection({
|
||||||
|
workspaceId: currentWorkspace.id,
|
||||||
|
...connectionData
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Navigate to success page or app connections list
|
||||||
|
|
||||||
navigate({
|
navigate({
|
||||||
to: "/secret-manager/$projectId/integrations/gitlab/create",
|
to: "/organization/app-connections",
|
||||||
params: {
|
|
||||||
projectId: currentWorkspace.id
|
|
||||||
},
|
|
||||||
search: {
|
search: {
|
||||||
integrationAuthId: integrationAuth.id
|
success: formData.isUpdate ? "connection_updated" : "connection_created",
|
||||||
|
connectionId: appConnection.id
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
console.error(err);
|
console.error("Error handling GitLab OAuth callback:", err);
|
||||||
|
navigate({
|
||||||
|
to: "/organization/app-connections",
|
||||||
|
search: { error: "connection_failed" }
|
||||||
|
});
|
||||||
}
|
}
|
||||||
})();
|
})();
|
||||||
}, []);
|
}, [code, state, navigate, createAppConnection, updateAppConnection, currentWorkspace.id]);
|
||||||
|
|
||||||
return <div />;
|
return (
|
||||||
|
<div className="flex h-screen items-center justify-center">
|
||||||
|
<div className="text-center">
|
||||||
|
<div className="mx-auto mb-4 h-8 w-8 animate-spin rounded-full border-b-2 border-primary" />
|
||||||
|
<p className="text-gray-600">Connecting to GitLab...</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
};
|
};
|
||||||
|
|||||||