mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 17:26:36 +00:00
Patch Vercel case where secrets can be of type plain and sensitive
This commit is contained in:
@@ -545,7 +545,7 @@ const syncSecretsVercel = async ({
|
|||||||
value: string;
|
value: string;
|
||||||
target: string[];
|
target: string[];
|
||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
// Get all (decrypted) secrets back from Vercel in
|
// Get all (decrypted) secrets back from Vercel in
|
||||||
// decrypted format
|
// decrypted format
|
||||||
@@ -574,7 +574,10 @@ const syncSecretsVercel = async ({
|
|||||||
.data
|
.data
|
||||||
.envs
|
.envs
|
||||||
.filter((secret: VercelSecret) => secret.target.includes(integration.targetEnvironment))
|
.filter((secret: VercelSecret) => secret.target.includes(integration.targetEnvironment))
|
||||||
.map(async (secret: VercelSecret) => (await axios.get(
|
.map(async (secret: VercelSecret) => {
|
||||||
|
if (secret.type === 'encrypted') {
|
||||||
|
// case: secret is encrypted -> need to decrypt
|
||||||
|
return (await axios.get(
|
||||||
`${INTEGRATION_VERCEL_API_URL}/v9/projects/${integration.app}/env/${secret.id}`,
|
`${INTEGRATION_VERCEL_API_URL}/v9/projects/${integration.app}/env/${secret.id}`,
|
||||||
{
|
{
|
||||||
params,
|
params,
|
||||||
@@ -583,8 +586,11 @@ const syncSecretsVercel = async ({
|
|||||||
'Accept-Encoding': 'application/json'
|
'Accept-Encoding': 'application/json'
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
)).data)
|
)).data;
|
||||||
)).reduce((obj: any, secret: any) => ({
|
}
|
||||||
|
|
||||||
|
return secret;
|
||||||
|
}))).reduce((obj: any, secret: any) => ({
|
||||||
...obj,
|
...obj,
|
||||||
[secret.key]: secret
|
[secret.key]: secret
|
||||||
}), {});
|
}), {});
|
||||||
@@ -615,8 +621,10 @@ const syncSecretsVercel = async ({
|
|||||||
id: res[key].id,
|
id: res[key].id,
|
||||||
key: key,
|
key: key,
|
||||||
value: secrets[key],
|
value: secrets[key],
|
||||||
type: "encrypted",
|
type: res[key].type,
|
||||||
target: [integration.targetEnvironment],
|
target: res[key].target.includes(integration.targetEnvironment)
|
||||||
|
? [...res[key].target]
|
||||||
|
: [...res[key].target, integration.targetEnvironment]
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
@@ -625,7 +633,7 @@ const syncSecretsVercel = async ({
|
|||||||
id: res[key].id,
|
id: res[key].id,
|
||||||
key: key,
|
key: key,
|
||||||
value: res[key].value,
|
value: res[key].value,
|
||||||
type: "encrypted",
|
type: "encrypted", // value doesn't matter
|
||||||
target: [integration.targetEnvironment],
|
target: [integration.targetEnvironment],
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -650,17 +658,20 @@ const syncSecretsVercel = async ({
|
|||||||
if (updateSecrets.length > 0) {
|
if (updateSecrets.length > 0) {
|
||||||
updateSecrets.forEach(async (secret: VercelSecret) => {
|
updateSecrets.forEach(async (secret: VercelSecret) => {
|
||||||
const { id, ...updatedSecret } = secret;
|
const { id, ...updatedSecret } = secret;
|
||||||
await axios.patch(
|
|
||||||
`${INTEGRATION_VERCEL_API_URL}/v9/projects/${integration.app}/env/${secret.id}`,
|
if (secret.type !== 'sensitive') {
|
||||||
updatedSecret,
|
await axios.patch(
|
||||||
{
|
`${INTEGRATION_VERCEL_API_URL}/v9/projects/${integration.app}/env/${secret.id}`,
|
||||||
params,
|
updatedSecret,
|
||||||
headers: {
|
{
|
||||||
Authorization: `Bearer ${accessToken}`,
|
params,
|
||||||
'Accept-Encoding': 'application/json'
|
headers: {
|
||||||
},
|
Authorization: `Bearer ${accessToken}`,
|
||||||
}
|
'Accept-Encoding': 'application/json'
|
||||||
);
|
},
|
||||||
|
}
|
||||||
|
);
|
||||||
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -118,7 +118,6 @@ router.delete( // TODO - rewire dashboard to this route
|
|||||||
workspaceController.deleteWorkspaceMembership
|
workspaceController.deleteWorkspaceMembership
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|
||||||
router.patch(
|
router.patch(
|
||||||
'/:workspaceId/auto-capitalization',
|
'/:workspaceId/auto-capitalization',
|
||||||
requireAuth({
|
requireAuth({
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
import { Bot, IBot } from '../models';
|
|
||||||
import * as Sentry from '@sentry/node';
|
|
||||||
import { handleEventHelper } from '../helpers/event';
|
import { handleEventHelper } from '../helpers/event';
|
||||||
|
|
||||||
interface Event {
|
interface Event {
|
||||||
|
|||||||
@@ -30,3 +30,20 @@ Select which Infisical environment secrets you want to sync to which Vercel app
|
|||||||
|
|
||||||

|

|
||||||

|

|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Infisical syncs every envar to Vercel with type `encrypted` unless an existing
|
||||||
|
envar with the same name in Vercel exists with a different type. Note that
|
||||||
|
Infisical will not be able to update Vercel envars with type `sensitive` since
|
||||||
|
they can only be decrypted and modified by Vercel's deployment systems.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
<Warning>
|
||||||
|
The following environment variable names are reserved by Vercel and cannot be
|
||||||
|
synced: `AWS_SECRET_KEY`, `AWS_EXECUTION_ENV`, `AWS_LAMBDA_LOG_GROUP_NAME`,
|
||||||
|
`AWS_LAMBDA_LOG_STREAM_NAME`, `AWS_LAMBDA_FUNCTION_NAME`,
|
||||||
|
`AWS_LAMBDA_FUNCTION_MEMORY_SIZE`, `AWS_LAMBDA_FUNCTION_VERSION`,
|
||||||
|
`NOW_REGION`, `TZ`, `LAMBDA_TASK_ROOT`, `LAMBDA_RUNTIME_DIR`,
|
||||||
|
`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`,
|
||||||
|
`AWS_REGION`, and `AWS_DEFAULT_REGION`.
|
||||||
|
</Warning>
|
||||||
|
|||||||
Reference in New Issue
Block a user