mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 19:28:51 +00:00
patch service token migration backwards with mongo
This commit is contained in:
committed by
Akhil Mohan
parent
9677836b76
commit
e28416b50b
Generated
+7
@@ -78,6 +78,7 @@
|
|||||||
"@types/pg": "^8.10.9",
|
"@types/pg": "^8.10.9",
|
||||||
"@types/picomatch": "^2.3.3",
|
"@types/picomatch": "^2.3.3",
|
||||||
"@types/prompt-sync": "^4.2.3",
|
"@types/prompt-sync": "^4.2.3",
|
||||||
|
"@types/uuid": "^9.0.7",
|
||||||
"@typescript-eslint/eslint-plugin": "^6.13.2",
|
"@typescript-eslint/eslint-plugin": "^6.13.2",
|
||||||
"@typescript-eslint/parser": "^6.13.2",
|
"@typescript-eslint/parser": "^6.13.2",
|
||||||
"eslint": "^8.55.0",
|
"eslint": "^8.55.0",
|
||||||
@@ -3960,6 +3961,12 @@
|
|||||||
"@types/node": "*"
|
"@types/node": "*"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/@types/uuid": {
|
||||||
|
"version": "9.0.7",
|
||||||
|
"resolved": "https://registry.npmjs.org/@types/uuid/-/uuid-9.0.7.tgz",
|
||||||
|
"integrity": "sha512-WUtIVRUZ9i5dYXefDEAI7sh9/O7jGvHg7Df/5O/gtH3Yabe5odI3UWopVR1qbPXQtvOxWu3mM4XxlYeZtMWF4g==",
|
||||||
|
"dev": true
|
||||||
|
},
|
||||||
"node_modules/@types/xml-crypto": {
|
"node_modules/@types/xml-crypto": {
|
||||||
"version": "1.4.6",
|
"version": "1.4.6",
|
||||||
"resolved": "https://registry.npmjs.org/@types/xml-crypto/-/xml-crypto-1.4.6.tgz",
|
"resolved": "https://registry.npmjs.org/@types/xml-crypto/-/xml-crypto-1.4.6.tgz",
|
||||||
|
|||||||
@@ -44,6 +44,7 @@
|
|||||||
"@types/pg": "^8.10.9",
|
"@types/pg": "^8.10.9",
|
||||||
"@types/picomatch": "^2.3.3",
|
"@types/picomatch": "^2.3.3",
|
||||||
"@types/prompt-sync": "^4.2.3",
|
"@types/prompt-sync": "^4.2.3",
|
||||||
|
"@types/uuid": "^9.0.7",
|
||||||
"@typescript-eslint/eslint-plugin": "^6.13.2",
|
"@typescript-eslint/eslint-plugin": "^6.13.2",
|
||||||
"@typescript-eslint/parser": "^6.13.2",
|
"@typescript-eslint/parser": "^6.13.2",
|
||||||
"eslint": "^8.55.0",
|
"eslint": "^8.55.0",
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { z } from "zod";
|
|||||||
import { TImmutableDBKeys } from "./models";
|
import { TImmutableDBKeys } from "./models";
|
||||||
|
|
||||||
export const ServiceTokensSchema = z.object({
|
export const ServiceTokensSchema = z.object({
|
||||||
id: z.string().uuid(),
|
id: z.string(),
|
||||||
name: z.string(),
|
name: z.string(),
|
||||||
scopes: z.unknown(),
|
scopes: z.unknown(),
|
||||||
permissions: z.string().array(),
|
permissions: z.string().array(),
|
||||||
|
|||||||
@@ -239,18 +239,17 @@ export const buildServiceTokenProjectPermission = (
|
|||||||
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
|
const { can, build } = new AbilityBuilder<MongoAbility<ProjectPermissionSet>>(createMongoAbility);
|
||||||
scopes.forEach(({ secretPath, environment }) => {
|
scopes.forEach(({ secretPath, environment }) => {
|
||||||
if (canWrite) {
|
if (canWrite) {
|
||||||
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Secrets, { secretPath, environment });
|
// TODO: @Akhi
|
||||||
can(ProjectPermissionActions.Create, ProjectPermissionSub.Secrets, {
|
// @ts-expect-error type
|
||||||
secretPath,
|
can(ProjectPermissionActions.Edit, ProjectPermissionSub.Secrets, { secretPath: { $glob: secretPath }, environment });
|
||||||
environment
|
// @ts-expect-error type
|
||||||
});
|
can(ProjectPermissionActions.Create, ProjectPermissionSub.Secrets, { secretPath: { $glob: secretPath }, environment });
|
||||||
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Secrets, {
|
// @ts-expect-error type
|
||||||
secretPath,
|
can(ProjectPermissionActions.Delete, ProjectPermissionSub.Secrets, {secretPath: { $glob: secretPath }, environment });
|
||||||
environment
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
if (canRead) {
|
if (canRead) {
|
||||||
can(ProjectPermissionActions.Read, ProjectPermissionSub.Secrets, { secretPath, environment });
|
// @ts-expect-error type
|
||||||
|
can(ProjectPermissionActions.Read, ProjectPermissionSub.Secrets, { secretPath: { $glob: secretPath }, environment });
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ import { TDbClient } from "@app/db";
|
|||||||
import { SecretsSchema, SecretType, TableName, TSecrets, TSecretsUpdate } from "@app/db/schemas";
|
import { SecretsSchema, SecretType, TableName, TSecrets, TSecretsUpdate } from "@app/db/schemas";
|
||||||
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
|
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
|
||||||
|
import { validate as uuidValidate } from 'uuid';
|
||||||
|
|
||||||
export type TSecretDALFactory = ReturnType<typeof secretDALFactory>;
|
export type TSecretDALFactory = ReturnType<typeof secretDALFactory>;
|
||||||
|
|
||||||
@@ -79,6 +80,11 @@ export const secretDALFactory = (db: TDbClient) => {
|
|||||||
|
|
||||||
const findByFolderId = async (folderId: string, userId?: string, tx?: Knex) => {
|
const findByFolderId = async (folderId: string, userId?: string, tx?: Knex) => {
|
||||||
try {
|
try {
|
||||||
|
// check if not uui then userId id is null (corner case because service token's ID is not UUI in effort to keep backwards compatibility from mongo)
|
||||||
|
if (userId && !uuidValidate(userId)) {
|
||||||
|
userId = undefined
|
||||||
|
}
|
||||||
|
|
||||||
const secs = await (tx || db)(TableName.Secret)
|
const secs = await (tx || db)(TableName.Secret)
|
||||||
.where({ folderId })
|
.where({ folderId })
|
||||||
.where((bd) => {
|
.where((bd) => {
|
||||||
|
|||||||
@@ -1432,8 +1432,6 @@ const main = async () => {
|
|||||||
postgresTableName: TableName.ServiceToken,
|
postgresTableName: TableName.ServiceToken,
|
||||||
returnKeys: ["id"],
|
returnKeys: ["id"],
|
||||||
preProcessing: async (doc) => {
|
preProcessing: async (doc) => {
|
||||||
const id = uuidV4();
|
|
||||||
|
|
||||||
const projectKvRes = await projectKv
|
const projectKvRes = await projectKv
|
||||||
.get(doc.workspace.toString())
|
.get(doc.workspace.toString())
|
||||||
.catch(() => null);
|
.catch(() => null);
|
||||||
@@ -1443,7 +1441,7 @@ const main = async () => {
|
|||||||
if (!userId) return;
|
if (!userId) return;
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id,
|
id: doc._id.toString(),
|
||||||
projectId: doc.workspace.toString(),
|
projectId: doc.workspace.toString(),
|
||||||
name: doc.name,
|
name: doc.name,
|
||||||
createdBy: userId,
|
createdBy: userId,
|
||||||
|
|||||||
Reference in New Issue
Block a user