patch service token migration backwards with mongo

This commit is contained in:
Maidul Islam
2024-01-27 12:40:37 +05:30
committed by Akhil Mohan
parent 9677836b76
commit e28416b50b
6 changed files with 25 additions and 14 deletions
+7
View File
@@ -78,6 +78,7 @@
"@types/pg": "^8.10.9", "@types/pg": "^8.10.9",
"@types/picomatch": "^2.3.3", "@types/picomatch": "^2.3.3",
"@types/prompt-sync": "^4.2.3", "@types/prompt-sync": "^4.2.3",
"@types/uuid": "^9.0.7",
"@typescript-eslint/eslint-plugin": "^6.13.2", "@typescript-eslint/eslint-plugin": "^6.13.2",
"@typescript-eslint/parser": "^6.13.2", "@typescript-eslint/parser": "^6.13.2",
"eslint": "^8.55.0", "eslint": "^8.55.0",
@@ -3960,6 +3961,12 @@
"@types/node": "*" "@types/node": "*"
} }
}, },
"node_modules/@types/uuid": {
"version": "9.0.7",
"resolved": "https://registry.npmjs.org/@types/uuid/-/uuid-9.0.7.tgz",
"integrity": "sha512-WUtIVRUZ9i5dYXefDEAI7sh9/O7jGvHg7Df/5O/gtH3Yabe5odI3UWopVR1qbPXQtvOxWu3mM4XxlYeZtMWF4g==",
"dev": true
},
"node_modules/@types/xml-crypto": { "node_modules/@types/xml-crypto": {
"version": "1.4.6", "version": "1.4.6",
"resolved": "https://registry.npmjs.org/@types/xml-crypto/-/xml-crypto-1.4.6.tgz", "resolved": "https://registry.npmjs.org/@types/xml-crypto/-/xml-crypto-1.4.6.tgz",
+1
View File
@@ -44,6 +44,7 @@
"@types/pg": "^8.10.9", "@types/pg": "^8.10.9",
"@types/picomatch": "^2.3.3", "@types/picomatch": "^2.3.3",
"@types/prompt-sync": "^4.2.3", "@types/prompt-sync": "^4.2.3",
"@types/uuid": "^9.0.7",
"@typescript-eslint/eslint-plugin": "^6.13.2", "@typescript-eslint/eslint-plugin": "^6.13.2",
"@typescript-eslint/parser": "^6.13.2", "@typescript-eslint/parser": "^6.13.2",
"eslint": "^8.55.0", "eslint": "^8.55.0",
+1 -1
View File
@@ -8,7 +8,7 @@ import { z } from "zod";
import { TImmutableDBKeys } from "./models"; import { TImmutableDBKeys } from "./models";
export const ServiceTokensSchema = z.object({ export const ServiceTokensSchema = z.object({
id: z.string().uuid(), id: z.string(),
name: z.string(), name: z.string(),
scopes: z.unknown(), scopes: z.unknown(),
permissions: z.string().array(), permissions: z.string().array(),
@@ -239,18 +239,17 @@ export const buildServiceTokenProjectPermission = (
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility); const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
scopes.forEach(({ secretPath, environment }) => { scopes.forEach(({ secretPath, environment }) => {
if (canWrite) { if (canWrite) {
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Secrets, { secretPath, environment }); // TODO: @Akhi
can(ProjectPermissionActions.Create, ProjectPermissionSub.Secrets, { // @ts-expect-error type
secretPath, can(ProjectPermissionActions.Edit, ProjectPermissionSub.Secrets, { secretPath: { $glob: secretPath }, environment });
environment // @ts-expect-error type
}); can(ProjectPermissionActions.Create, ProjectPermissionSub.Secrets, { secretPath: { $glob: secretPath }, environment });
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Secrets, { // @ts-expect-error type
secretPath, can(ProjectPermissionActions.Delete, ProjectPermissionSub.Secrets, {secretPath: { $glob: secretPath }, environment });
environment
});
} }
if (canRead) { if (canRead) {
can(ProjectPermissionActions.Read, ProjectPermissionSub.Secrets, { secretPath, environment }); // @ts-expect-error type
can(ProjectPermissionActions.Read, ProjectPermissionSub.Secrets, { secretPath: { $glob: secretPath }, environment });
} }
}); });
@@ -4,6 +4,7 @@ import { TDbClient } from "@app/db";
import { SecretsSchema, SecretType, TableName, TSecrets, TSecretsUpdate } from "@app/db/schemas"; import { SecretsSchema, SecretType, TableName, TSecrets, TSecretsUpdate } from "@app/db/schemas";
import { BadRequestError, DatabaseError } from "@app/lib/errors"; import { BadRequestError, DatabaseError } from "@app/lib/errors";
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex"; import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
import { validate as uuidValidate } from 'uuid';
export type TSecretDALFactory = ReturnType<typeof secretDALFactory>; export type TSecretDALFactory = ReturnType<typeof secretDALFactory>;
@@ -79,6 +80,11 @@ export const secretDALFactory = (db: TDbClient) => {
const findByFolderId = async (folderId: string, userId?: string, tx?: Knex) => { const findByFolderId = async (folderId: string, userId?: string, tx?: Knex) => {
try { try {
// check if not uui then userId id is null (corner case because service token's ID is not UUI in effort to keep backwards compatibility from mongo)
if (userId && !uuidValidate(userId)) {
userId = undefined
}
const secs = await (tx || db)(TableName.Secret) const secs = await (tx || db)(TableName.Secret)
.where({ folderId }) .where({ folderId })
.where((bd) => { .where((bd) => {
+1 -3
View File
@@ -1432,8 +1432,6 @@ const main = async () => {
postgresTableName: TableName.ServiceToken, postgresTableName: TableName.ServiceToken,
returnKeys: ["id"], returnKeys: ["id"],
preProcessing: async (doc) => { preProcessing: async (doc) => {
const id = uuidV4();
const projectKvRes = await projectKv const projectKvRes = await projectKv
.get(doc.workspace.toString()) .get(doc.workspace.toString())
.catch(() => null); .catch(() => null);
@@ -1443,7 +1441,7 @@ const main = async () => {
if (!userId) return; if (!userId) return;
return { return {
id, id: doc._id.toString(),
projectId: doc.workspace.toString(), projectId: doc.workspace.toString(),
name: doc.name, name: doc.name,
createdBy: userId, createdBy: userId,