mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 16:27:40 +00:00
feat: added description for all api endpoints
This commit is contained in:
@@ -7,6 +7,7 @@ import { z } from "zod";
|
|||||||
import { IdentityProjectAdditionalPrivilegeSchema } from "@app/db/schemas";
|
import { IdentityProjectAdditionalPrivilegeSchema } from "@app/db/schemas";
|
||||||
import { IdentityProjectAdditionalPrivilegeTemporaryMode } from "@app/ee/services/identity-project-additional-privilege/identity-project-additional-privilege-types";
|
import { IdentityProjectAdditionalPrivilegeTemporaryMode } from "@app/ee/services/identity-project-additional-privilege/identity-project-additional-privilege-types";
|
||||||
import { ProjectPermissionSet } from "@app/ee/services/permission/project-permission";
|
import { ProjectPermissionSet } from "@app/ee/services/permission/project-permission";
|
||||||
|
import { IDENTITY_ADDITIONAL_PRIVILEGE } from "@app/lib/api-docs";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
@@ -18,41 +19,59 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
schema: {
|
schema: {
|
||||||
body: z.union([
|
body: z.union([
|
||||||
z.object({
|
z.object({
|
||||||
identityId: z.string().min(1),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.identityId),
|
||||||
projectSlug: z.string().min(1),
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.projectSlug),
|
||||||
slug: z
|
slug: z
|
||||||
.string()
|
.string()
|
||||||
.min(1)
|
.min(1)
|
||||||
.max(60)
|
.max(60)
|
||||||
.trim()
|
.trim()
|
||||||
.optional()
|
|
||||||
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
||||||
|
.refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Slug must be a valid slug"
|
message: "Slug must be a valid slug"
|
||||||
}),
|
})
|
||||||
permissions: z.any().array(),
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug),
|
||||||
isPackedPermission: z.boolean().optional().default(false),
|
permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions),
|
||||||
isTemporary: z.literal(false).default(false)
|
isPackedPermission: z
|
||||||
|
.boolean()
|
||||||
|
.optional()
|
||||||
|
.default(false)
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.isPackPermission),
|
||||||
|
isTemporary: z.literal(false).default(false).describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.isTemporary)
|
||||||
}),
|
}),
|
||||||
z.object({
|
z.object({
|
||||||
identityId: z.string(),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.identityId),
|
||||||
projectSlug: z.string().min(1),
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.projectSlug),
|
||||||
slug: z
|
slug: z
|
||||||
.string()
|
.string()
|
||||||
.min(1)
|
.min(1)
|
||||||
.max(60)
|
.max(60)
|
||||||
.trim()
|
.trim()
|
||||||
.optional()
|
|
||||||
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
||||||
|
.refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Slug must be a valid slug"
|
message: "Slug must be a valid slug"
|
||||||
}),
|
})
|
||||||
permissions: z.any().array(),
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.slug),
|
||||||
isTemporary: z.literal(true),
|
permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.permissions),
|
||||||
isPackedPermission: z.boolean().optional().default(false),
|
isPackedPermission: z
|
||||||
temporaryMode: z.nativeEnum(IdentityProjectAdditionalPrivilegeTemporaryMode),
|
.boolean()
|
||||||
temporaryRange: z.string().refine((val) => ms(val) > 0, "Temporary range must be a positive number"),
|
.optional()
|
||||||
temporaryAccessStartTime: z.string().datetime()
|
.default(false)
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.isPackPermission),
|
||||||
|
isTemporary: z.literal(true).describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.isTemporary),
|
||||||
|
temporaryMode: z
|
||||||
|
.nativeEnum(IdentityProjectAdditionalPrivilegeTemporaryMode)
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.temporaryMode),
|
||||||
|
temporaryRange: z
|
||||||
|
.string()
|
||||||
|
.refine((val) => ms(val) > 0, "Temporary range must be a positive number")
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.temporaryRange),
|
||||||
|
temporaryAccessStartTime: z
|
||||||
|
.string()
|
||||||
|
.datetime()
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.CREATE.temporaryAccessStartTime)
|
||||||
})
|
})
|
||||||
]),
|
]),
|
||||||
response: {
|
response: {
|
||||||
@@ -83,9 +102,9 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
// disallow empty string
|
// disallow empty string
|
||||||
slug: z.string().min(1),
|
slug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.slug),
|
||||||
identityId: z.string().min(1),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.identityId),
|
||||||
projectSlug: z.string().min(1),
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.projectSlug),
|
||||||
data: z
|
data: z
|
||||||
.object({
|
.object({
|
||||||
slug: z
|
slug: z
|
||||||
@@ -93,15 +112,29 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
.min(1)
|
.min(1)
|
||||||
.max(60)
|
.max(60)
|
||||||
.trim()
|
.trim()
|
||||||
|
.refine((val) => val.toLowerCase() === val, "Must be lowercase")
|
||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Slug must be a valid slug"
|
message: "Slug must be a valid slug"
|
||||||
}),
|
})
|
||||||
isPackedPermission: z.boolean().optional().default(false),
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.newSlug),
|
||||||
permissions: z.any().array(),
|
isPackedPermission: z
|
||||||
isTemporary: z.boolean(),
|
.boolean()
|
||||||
temporaryMode: z.nativeEnum(IdentityProjectAdditionalPrivilegeTemporaryMode),
|
.optional()
|
||||||
temporaryRange: z.string().refine((val) => ms(val) > 0, "Temporary range must be a positive number"),
|
.default(false)
|
||||||
temporaryAccessStartTime: z.string().datetime()
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.isPackPermission),
|
||||||
|
permissions: z.any().array().describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.permissions),
|
||||||
|
isTemporary: z.boolean().describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.isTemporary),
|
||||||
|
temporaryMode: z
|
||||||
|
.nativeEnum(IdentityProjectAdditionalPrivilegeTemporaryMode)
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.temporaryMode),
|
||||||
|
temporaryRange: z
|
||||||
|
.string()
|
||||||
|
.refine((val) => ms(val) > 0, "Temporary range must be a positive number")
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.temporaryRange),
|
||||||
|
temporaryAccessStartTime: z
|
||||||
|
.string()
|
||||||
|
.datetime()
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.UPDATE.temporaryAccessStartTime)
|
||||||
})
|
})
|
||||||
.partial()
|
.partial()
|
||||||
}),
|
}),
|
||||||
@@ -136,9 +169,9 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
method: "DELETE",
|
method: "DELETE",
|
||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
slug: z.string().min(1),
|
slug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.slug),
|
||||||
identityId: z.string().min(1),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.identityId),
|
||||||
projectSlug: z.string().min(1)
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.DELETE.projectSlug)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -164,11 +197,11 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
slug: z.string()
|
slug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.slug)
|
||||||
}),
|
}),
|
||||||
querystring: z.object({
|
querystring: z.object({
|
||||||
identityId: z.string().min(1),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.identityId),
|
||||||
projectSlug: z.string().min(1)
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.GET_BY_SLUG.projectSlug)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -195,12 +228,13 @@ export const registerIdentityProjectAdditionalPrivilegeRouter = async (server: F
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
querystring: z.object({
|
querystring: z.object({
|
||||||
identityId: z.string().min(1),
|
identityId: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.LIST.identityId),
|
||||||
projectSlug: z.string().min(1),
|
projectSlug: z.string().min(1).describe(IDENTITY_ADDITIONAL_PRIVILEGE.LIST.projectSlug),
|
||||||
unpacked: z
|
unpacked: z
|
||||||
.enum(["false", "true"])
|
.enum(["false", "true"])
|
||||||
.transform((el) => el === "true")
|
.transform((el) => el === "true")
|
||||||
.default("true")
|
.default("true")
|
||||||
|
.describe(IDENTITY_ADDITIONAL_PRIVILEGE.LIST.unpacked)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ import { z } from "zod";
|
|||||||
|
|
||||||
import { ProjectUserAdditionalPrivilegeSchema } from "@app/db/schemas";
|
import { ProjectUserAdditionalPrivilegeSchema } from "@app/db/schemas";
|
||||||
import { ProjectUserAdditionalPrivilegeTemporaryMode } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-types";
|
import { ProjectUserAdditionalPrivilegeTemporaryMode } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-types";
|
||||||
|
import { PROJECT_USER_ADDITIONAL_PRIVILEGE } from "@app/lib/api-docs";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
@@ -15,37 +16,47 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
|
|||||||
schema: {
|
schema: {
|
||||||
body: z.union([
|
body: z.union([
|
||||||
z.object({
|
z.object({
|
||||||
projectMembershipId: z.string(),
|
projectMembershipId: z.string().min(1).describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.projectMembershipId),
|
||||||
slug: z
|
slug: z
|
||||||
.string()
|
.string()
|
||||||
.min(1)
|
.min(1)
|
||||||
.max(60)
|
.max(60)
|
||||||
.trim()
|
.trim()
|
||||||
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
||||||
|
.refine((v) => v.toLowerCase() === v, "Slug must be lowercase")
|
||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Slug must be a valid slug"
|
message: "Slug must be a valid slug"
|
||||||
}),
|
})
|
||||||
permissions: z.any().array(),
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug),
|
||||||
isTemporary: z.literal(false).default(false)
|
permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions),
|
||||||
|
isTemporary: z.literal(false).default(false).describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.isTemporary)
|
||||||
}),
|
}),
|
||||||
z.object({
|
z.object({
|
||||||
projectMembershipId: z.string(),
|
projectMembershipId: z.string().min(1).describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.projectMembershipId),
|
||||||
slug: z
|
slug: z
|
||||||
.string()
|
.string()
|
||||||
.min(1)
|
.min(1)
|
||||||
.max(60)
|
.max(60)
|
||||||
.trim()
|
.trim()
|
||||||
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
.default(`privilege-${slugify(alphaNumericNanoId(12))}`)
|
||||||
|
.refine((v) => v.toLowerCase() === v, "Slug must be lowercase")
|
||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Slug must be a valid slug"
|
message: "Slug must be a valid slug"
|
||||||
}),
|
})
|
||||||
name: z.string().trim(),
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.slug),
|
||||||
description: z.string().trim().optional(),
|
permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.permissions),
|
||||||
permissions: z.any().array(),
|
isTemporary: z.literal(true).describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.isTemporary),
|
||||||
isTemporary: z.literal(true),
|
temporaryMode: z
|
||||||
temporaryMode: z.nativeEnum(ProjectUserAdditionalPrivilegeTemporaryMode),
|
.nativeEnum(ProjectUserAdditionalPrivilegeTemporaryMode)
|
||||||
temporaryRange: z.string().refine((val) => ms(val) > 0, "Temporary range must be a positive number"),
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.temporaryMode),
|
||||||
temporaryAccessStartTime: z.string().datetime()
|
temporaryRange: z
|
||||||
|
.string()
|
||||||
|
.refine((val) => ms(val) > 0, "Temporary range must be a positive number")
|
||||||
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.temporaryRange),
|
||||||
|
temporaryAccessStartTime: z
|
||||||
|
.string()
|
||||||
|
.datetime()
|
||||||
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.CREATE.temporaryAccessStartTime)
|
||||||
})
|
})
|
||||||
]),
|
]),
|
||||||
response: {
|
response: {
|
||||||
@@ -73,7 +84,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
|
|||||||
method: "PATCH",
|
method: "PATCH",
|
||||||
schema: {
|
schema: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
privilegeId: z.string()
|
privilegeId: z.string().min(1).describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.privilegeId)
|
||||||
}),
|
}),
|
||||||
body: z
|
body: z
|
||||||
.object({
|
.object({
|
||||||
@@ -84,12 +95,21 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
|
|||||||
.refine((v) => v.toLowerCase() === v, "Slug must be lowercase")
|
.refine((v) => v.toLowerCase() === v, "Slug must be lowercase")
|
||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Slug must be a valid slug"
|
message: "Slug must be a valid slug"
|
||||||
}),
|
})
|
||||||
permissions: z.any().array(),
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.slug),
|
||||||
isTemporary: z.boolean(),
|
permissions: z.any().array().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.permissions),
|
||||||
temporaryMode: z.nativeEnum(ProjectUserAdditionalPrivilegeTemporaryMode),
|
isTemporary: z.boolean().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.isTemporary),
|
||||||
temporaryRange: z.string().refine((val) => ms(val) > 0, "Temporary range must be a positive number"),
|
temporaryMode: z
|
||||||
temporaryAccessStartTime: z.string().datetime()
|
.nativeEnum(ProjectUserAdditionalPrivilegeTemporaryMode)
|
||||||
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.temporaryMode),
|
||||||
|
temporaryRange: z
|
||||||
|
.string()
|
||||||
|
.refine((val) => ms(val) > 0, "Temporary range must be a positive number")
|
||||||
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.temporaryRange),
|
||||||
|
temporaryAccessStartTime: z
|
||||||
|
.string()
|
||||||
|
.datetime()
|
||||||
|
.describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.UPDATE.temporaryAccessStartTime)
|
||||||
})
|
})
|
||||||
.partial(),
|
.partial(),
|
||||||
response: {
|
response: {
|
||||||
@@ -118,7 +138,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
|
|||||||
method: "DELETE",
|
method: "DELETE",
|
||||||
schema: {
|
schema: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
privilegeId: z.string()
|
privilegeId: z.string().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.DELETE.privilegeId)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -144,7 +164,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
querystring: z.object({
|
querystring: z.object({
|
||||||
projectMembershipId: z.string()
|
projectMembershipId: z.string().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.LIST.projectMembershipId)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
@@ -170,7 +190,7 @@ export const registerUserAdditionalPrivilegeRouter = async (server: FastifyZodPr
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
privilegeId: z.string()
|
privilegeId: z.string().describe(PROJECT_USER_ADDITIONAL_PRIVILEGE.GET_BY_PRIVILEGEID.privilegeId)
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
|
|||||||
@@ -397,3 +397,81 @@ export const SECRET_TAGS = {
|
|||||||
projectId: "The ID of the project to delete the tag from."
|
projectId: "The ID of the project to delete the tag from."
|
||||||
}
|
}
|
||||||
} as const;
|
} as const;
|
||||||
|
|
||||||
|
export const IDENTITY_ADDITIONAL_PRIVILEGE = {
|
||||||
|
CREATE: {
|
||||||
|
projectSlug: "The slug of the project of the dynamic secret in.",
|
||||||
|
identityId: "The ID of the identity to delete.",
|
||||||
|
slug: "The slug of the privilege to create.",
|
||||||
|
permissions:
|
||||||
|
"The permission object for the privilege. Refer https://casl.js.org/v6/en/guide/define-rules#the-shape-of-raw-rule to understand the shape",
|
||||||
|
isPackPermission: "Whether the server should pack(compact) the permission object.",
|
||||||
|
isTemporary: "Whether the privilege is temporary.",
|
||||||
|
temporaryMode: "Type of temporary access given. Types: relative",
|
||||||
|
temporaryRange: "TTL for the temporay time. Eg: 1m, 1h, 1d",
|
||||||
|
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
||||||
|
},
|
||||||
|
UPDATE: {
|
||||||
|
projectSlug: "The slug of the project of the dynamic secret in.",
|
||||||
|
identityId: "The ID of the identity to delete.",
|
||||||
|
slug: "The slug of the privilege to create.",
|
||||||
|
newSlug: "The new slug of the privilege to create.",
|
||||||
|
permissions:
|
||||||
|
"The permission object for the privilege. Refer https://casl.js.org/v6/en/guide/define-rules#the-shape-of-raw-rule to understand the shape",
|
||||||
|
isPackPermission: "Whether the server should pack(compact) the permission object.",
|
||||||
|
isTemporary: "Whether the privilege is temporary.",
|
||||||
|
temporaryMode: "Type of temporary access given. Types: relative",
|
||||||
|
temporaryRange: "TTL for the temporay time. Eg: 1m, 1h, 1d",
|
||||||
|
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
||||||
|
},
|
||||||
|
DELETE: {
|
||||||
|
projectSlug: "The slug of the project of the dynamic secret in.",
|
||||||
|
identityId: "The ID of the identity to delete.",
|
||||||
|
slug: "The slug of the privilege to create."
|
||||||
|
},
|
||||||
|
GET_BY_SLUG: {
|
||||||
|
projectSlug: "The slug of the project of the dynamic secret in.",
|
||||||
|
identityId: "The ID of the identity to delete.",
|
||||||
|
slug: "The slug of the privilege to create."
|
||||||
|
},
|
||||||
|
LIST: {
|
||||||
|
projectSlug: "The slug of the project of the dynamic secret in.",
|
||||||
|
identityId: "The ID of the identity to delete.",
|
||||||
|
unpacked: "Whether the system should send the permissions as unpacked"
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
export const PROJECT_USER_ADDITIONAL_PRIVILEGE = {
|
||||||
|
CREATE: {
|
||||||
|
projectMembershipId: "Project membership id of user",
|
||||||
|
slug: "The slug of the privilege to create.",
|
||||||
|
permissions:
|
||||||
|
"The permission object for the privilege. Refer https://casl.js.org/v6/en/guide/define-rules#the-shape-of-raw-rule to understand the shape",
|
||||||
|
isPackPermission: "Whether the server should pack(compact) the permission object.",
|
||||||
|
isTemporary: "Whether the privilege is temporary.",
|
||||||
|
temporaryMode: "Type of temporary access given. Types: relative",
|
||||||
|
temporaryRange: "TTL for the temporay time. Eg: 1m, 1h, 1d",
|
||||||
|
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
||||||
|
},
|
||||||
|
UPDATE: {
|
||||||
|
privilegeId: "The id of privilege object",
|
||||||
|
slug: "The slug of the privilege to create.",
|
||||||
|
newSlug: "The new slug of the privilege to create.",
|
||||||
|
permissions:
|
||||||
|
"The permission object for the privilege. Refer https://casl.js.org/v6/en/guide/define-rules#the-shape-of-raw-rule to understand the shape",
|
||||||
|
isPackPermission: "Whether the server should pack(compact) the permission object.",
|
||||||
|
isTemporary: "Whether the privilege is temporary.",
|
||||||
|
temporaryMode: "Type of temporary access given. Types: relative",
|
||||||
|
temporaryRange: "TTL for the temporay time. Eg: 1m, 1h, 1d",
|
||||||
|
temporaryAccessStartTime: "ISO time for which temporary access should begin."
|
||||||
|
},
|
||||||
|
DELETE: {
|
||||||
|
privilegeId: "The id of privilege object"
|
||||||
|
},
|
||||||
|
GET_BY_PRIVILEGEID: {
|
||||||
|
privilegeId: "The id of privilege object"
|
||||||
|
},
|
||||||
|
LIST: {
|
||||||
|
projectMembershipId: "Project membership id of user"
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|||||||
+1
-1
@@ -331,7 +331,7 @@ export const IdentityRbacSection = ({ identityProjectMember, onOpenUpgradeModal
|
|||||||
)}
|
)}
|
||||||
isLoading={roleForm.formState.isSubmitting}
|
isLoading={roleForm.formState.isSubmitting}
|
||||||
>
|
>
|
||||||
Save Changes
|
Save Roles
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
</form>
|
</form>
|
||||||
|
|||||||
+1
-1
@@ -328,7 +328,7 @@ export const MemberRbacSection = ({ projectMember, onOpenUpgradeModal }: Props)
|
|||||||
)}
|
)}
|
||||||
isLoading={roleForm.formState.isSubmitting}
|
isLoading={roleForm.formState.isSubmitting}
|
||||||
>
|
>
|
||||||
Save Changes
|
Save Roles
|
||||||
</Button>
|
</Button>
|
||||||
</div>
|
</div>
|
||||||
</form>
|
</form>
|
||||||
|
|||||||
Reference in New Issue
Block a user