mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
feat: finished migrator logic
This commit is contained in:
@@ -723,7 +723,7 @@ export const snapshotDALFactory = (db: TDbClient) => {
|
|||||||
// special query for migration for secret v2
|
// special query for migration for secret v2
|
||||||
const findNSecretV1SnapshotByFolderId = async (folderId: string, n = 15, tx?: Knex) => {
|
const findNSecretV1SnapshotByFolderId = async (folderId: string, n = 15, tx?: Knex) => {
|
||||||
try {
|
try {
|
||||||
const data = await (tx || db.replicaNode())(TableName.Snapshot)
|
const query = (tx || db.replicaNode())(TableName.Snapshot)
|
||||||
.leftJoin(TableName.SnapshotSecret, `${TableName.Snapshot}.id`, `${TableName.SnapshotSecret}.snapshotId`)
|
.leftJoin(TableName.SnapshotSecret, `${TableName.Snapshot}.id`, `${TableName.SnapshotSecret}.snapshotId`)
|
||||||
.leftJoin(
|
.leftJoin(
|
||||||
TableName.SecretVersion,
|
TableName.SecretVersion,
|
||||||
@@ -749,8 +749,12 @@ export const snapshotDALFactory = (db: TDbClient) => {
|
|||||||
)
|
)
|
||||||
)
|
)
|
||||||
.orderBy(`${TableName.Snapshot}.createdAt`, "desc")
|
.orderBy(`${TableName.Snapshot}.createdAt`, "desc")
|
||||||
.where(`${TableName.Snapshot}.folderId`, folderId)
|
.where(`${TableName.Snapshot}.folderId`, folderId);
|
||||||
.andWhere("rank", "<", n);
|
const data = await (tx || db)
|
||||||
|
.with("w", query)
|
||||||
|
.select("*")
|
||||||
|
.from<Awaited<typeof query>[number]>("w")
|
||||||
|
.andWhere("w.rank", "<", n);
|
||||||
|
|
||||||
return sqlNestRelationships({
|
return sqlNestRelationships({
|
||||||
data,
|
data,
|
||||||
|
|||||||
@@ -1016,7 +1016,8 @@ export const registerRoutes = async (
|
|||||||
secretFolderVersionDAL: folderVersionDAL,
|
secretFolderVersionDAL: folderVersionDAL,
|
||||||
snapshotDAL,
|
snapshotDAL,
|
||||||
identityAccessTokenDAL,
|
identityAccessTokenDAL,
|
||||||
secretSharingDAL
|
secretSharingDAL,
|
||||||
|
secretVersionV2DAL: secretVersionV2BridgeDAL
|
||||||
});
|
});
|
||||||
|
|
||||||
const oidcService = oidcConfigServiceFactory({
|
const oidcService = oidcConfigServiceFactory({
|
||||||
|
|||||||
@@ -7,11 +7,13 @@ import { TIdentityAccessTokenDALFactory } from "../identity-access-token/identit
|
|||||||
import { TSecretVersionDALFactory } from "../secret/secret-version-dal";
|
import { TSecretVersionDALFactory } from "../secret/secret-version-dal";
|
||||||
import { TSecretFolderVersionDALFactory } from "../secret-folder/secret-folder-version-dal";
|
import { TSecretFolderVersionDALFactory } from "../secret-folder/secret-folder-version-dal";
|
||||||
import { TSecretSharingDALFactory } from "../secret-sharing/secret-sharing-dal";
|
import { TSecretSharingDALFactory } from "../secret-sharing/secret-sharing-dal";
|
||||||
|
import { TSecretVersionV2DALFactory } from "../secret-v2-bridge/secret-version-dal";
|
||||||
|
|
||||||
type TDailyResourceCleanUpQueueServiceFactoryDep = {
|
type TDailyResourceCleanUpQueueServiceFactoryDep = {
|
||||||
auditLogDAL: Pick<TAuditLogDALFactory, "pruneAuditLog">;
|
auditLogDAL: Pick<TAuditLogDALFactory, "pruneAuditLog">;
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "removeExpiredTokens">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "removeExpiredTokens">;
|
||||||
secretVersionDAL: Pick<TSecretVersionDALFactory, "pruneExcessVersions">;
|
secretVersionDAL: Pick<TSecretVersionDALFactory, "pruneExcessVersions">;
|
||||||
|
secretVersionV2DAL: Pick<TSecretVersionV2DALFactory, "pruneExcessVersions">;
|
||||||
secretFolderVersionDAL: Pick<TSecretFolderVersionDALFactory, "pruneExcessVersions">;
|
secretFolderVersionDAL: Pick<TSecretFolderVersionDALFactory, "pruneExcessVersions">;
|
||||||
snapshotDAL: Pick<TSnapshotDALFactory, "pruneExcessSnapshots">;
|
snapshotDAL: Pick<TSnapshotDALFactory, "pruneExcessSnapshots">;
|
||||||
secretSharingDAL: Pick<TSecretSharingDALFactory, "pruneExpiredSharedSecrets">;
|
secretSharingDAL: Pick<TSecretSharingDALFactory, "pruneExpiredSharedSecrets">;
|
||||||
@@ -27,7 +29,8 @@ export const dailyResourceCleanUpQueueServiceFactory = ({
|
|||||||
secretVersionDAL,
|
secretVersionDAL,
|
||||||
secretFolderVersionDAL,
|
secretFolderVersionDAL,
|
||||||
identityAccessTokenDAL,
|
identityAccessTokenDAL,
|
||||||
secretSharingDAL
|
secretSharingDAL,
|
||||||
|
secretVersionV2DAL
|
||||||
}: TDailyResourceCleanUpQueueServiceFactoryDep) => {
|
}: TDailyResourceCleanUpQueueServiceFactoryDep) => {
|
||||||
queueService.start(QueueName.DailyResourceCleanUp, async () => {
|
queueService.start(QueueName.DailyResourceCleanUp, async () => {
|
||||||
logger.info(`${QueueName.DailyResourceCleanUp}: queue task started`);
|
logger.info(`${QueueName.DailyResourceCleanUp}: queue task started`);
|
||||||
@@ -36,6 +39,7 @@ export const dailyResourceCleanUpQueueServiceFactory = ({
|
|||||||
await secretSharingDAL.pruneExpiredSharedSecrets();
|
await secretSharingDAL.pruneExpiredSharedSecrets();
|
||||||
await snapshotDAL.pruneExcessSnapshots();
|
await snapshotDAL.pruneExcessSnapshots();
|
||||||
await secretVersionDAL.pruneExcessVersions();
|
await secretVersionDAL.pruneExcessVersions();
|
||||||
|
await secretVersionV2DAL.pruneExcessVersions();
|
||||||
await secretFolderVersionDAL.pruneExcessVersions();
|
await secretFolderVersionDAL.pruneExcessVersions();
|
||||||
logger.info(`${QueueName.DailyResourceCleanUp}: queue task completed`);
|
logger.info(`${QueueName.DailyResourceCleanUp}: queue task completed`);
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -885,7 +885,7 @@ export const secretQueueFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const snapshots = await snapshotDAL.findNSecretV1SnapshotByFolderId(folderId, 10, tx);
|
const snapshots = await snapshotDAL.findNSecretV1SnapshotByFolderId(folderId, 10, tx);
|
||||||
const projectV3SecretVersions: Record<string, TSecretVersionsV2> = {};
|
const projectV3SecretVersionsGroupById: Record<string, TSecretVersionsV2> = {};
|
||||||
const projectV3SecretVersionTags: { secret_versions_v2Id: string; secret_tagsId: string }[] = [];
|
const projectV3SecretVersionTags: { secret_versions_v2Id: string; secret_tagsId: string }[] = [];
|
||||||
const projectV3SnapshotSecrets: Omit<TSecretSnapshotSecretsV2, "id">[] = [];
|
const projectV3SnapshotSecrets: Omit<TSecretSnapshotSecretsV2, "id">[] = [];
|
||||||
snapshots.forEach(({ secretVersions = [], ...snapshot }) => {
|
snapshots.forEach(({ secretVersions = [], ...snapshot }) => {
|
||||||
@@ -897,7 +897,7 @@ export const secretQueueFactory = ({
|
|||||||
updatedAt: snapshot.updatedAt,
|
updatedAt: snapshot.updatedAt,
|
||||||
envId: el.snapshotEnvId
|
envId: el.snapshotEnvId
|
||||||
});
|
});
|
||||||
if (projectV3SecretVersions[el.id]) return;
|
if (projectV3SecretVersionsGroupById[el.id]) return;
|
||||||
|
|
||||||
const key = decryptSymmetric128BitHexKeyUTF8({
|
const key = decryptSymmetric128BitHexKeyUTF8({
|
||||||
ciphertext: el.secretKeyCiphertext,
|
ciphertext: el.secretKeyCiphertext,
|
||||||
@@ -925,7 +925,7 @@ export const secretQueueFactory = ({
|
|||||||
const encryptedComment = comment
|
const encryptedComment = comment
|
||||||
? secretManagerEncryptor({ plainText: Buffer.from(comment) }).cipherTextBlob
|
? secretManagerEncryptor({ plainText: Buffer.from(comment) }).cipherTextBlob
|
||||||
: null;
|
: null;
|
||||||
projectV3SecretVersions[el.id] = {
|
projectV3SecretVersionsGroupById[el.id] = {
|
||||||
id: el.id,
|
id: el.id,
|
||||||
createdAt: el.createdAt,
|
createdAt: el.createdAt,
|
||||||
updatedAt: el.updatedAt,
|
updatedAt: el.updatedAt,
|
||||||
@@ -948,12 +948,14 @@ export const secretQueueFactory = ({
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
if (projectV3SecretVersionTags.length) {
|
const projectV3SecretVersions = Object.values(projectV3SecretVersionsGroupById);
|
||||||
await secretVersionV2BridgeDAL.insertMany(Object.values(projectV3SecretVersions), tx);
|
if (projectV3SecretVersions.length) {
|
||||||
|
await secretVersionV2BridgeDAL.insertMany(projectV3SecretVersions, tx);
|
||||||
}
|
}
|
||||||
if (projectV3SecretVersionTags.length) {
|
if (projectV3SecretVersionTags.length) {
|
||||||
await secretVersionTagV2BridgeDAL.insertMany(projectV3SecretVersionTags, tx);
|
await secretVersionTagV2BridgeDAL.insertMany(projectV3SecretVersionTags, tx);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (projectV3SnapshotSecrets.length) {
|
if (projectV3SnapshotSecrets.length) {
|
||||||
await snapshotSecretV2BridgeDAL.insertMany(projectV3SnapshotSecrets, tx);
|
await snapshotSecretV2BridgeDAL.insertMany(projectV3SnapshotSecrets, tx);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1935,15 +1935,21 @@ export const secretServiceFactory = ({
|
|||||||
offset = 0,
|
offset = 0,
|
||||||
secretId
|
secretId
|
||||||
}: TGetSecretVersionsDTO) => {
|
}: TGetSecretVersionsDTO) => {
|
||||||
const secretVersionV2 = await secretV2BridgeService.getSecretVersions({
|
const secretVersionV2 = await secretV2BridgeService
|
||||||
actorId,
|
.getSecretVersions({
|
||||||
actor,
|
actorId,
|
||||||
actorOrgId,
|
actor,
|
||||||
actorAuthMethod,
|
actorOrgId,
|
||||||
limit,
|
actorAuthMethod,
|
||||||
offset,
|
limit,
|
||||||
secretId
|
offset,
|
||||||
});
|
secretId
|
||||||
|
})
|
||||||
|
.catch((err) => {
|
||||||
|
if ((err as Error).message === "BadRequest: Failed to find secret") {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
});
|
||||||
if (secretVersionV2) return secretVersionV2;
|
if (secretVersionV2) return secretVersionV2;
|
||||||
|
|
||||||
const secret = await secretDAL.findById(secretId);
|
const secret = await secretDAL.findById(secretId);
|
||||||
|
|||||||
Reference in New Issue
Block a user