requested changes

This commit is contained in:
Daniel Hougaard
2025-07-10 16:14:40 +04:00
parent 7d2d69fc7d
commit e71b136859
6 changed files with 67 additions and 20 deletions
@@ -0,0 +1,55 @@
import { Knex } from "knex";
import { TableName } from "../schemas";
export async function up(knex: Knex): Promise<void> {
const existingSecretApprovalPolicies = await knex(TableName.SecretApprovalPolicy)
.whereNull("secretPath")
.orWhere("secretPath", "");
const existingAccessApprovalPolicies = await knex(TableName.AccessApprovalPolicy)
.whereNull("secretPath")
.orWhere("secretPath", "");
// update all the secret approval policies secretPath to be "/**"
if (existingSecretApprovalPolicies.length) {
await knex(TableName.SecretApprovalPolicy)
.whereIn(
"id",
existingSecretApprovalPolicies.map((el) => el.id)
)
.update({
secretPath: "/**"
});
}
// update all the access approval policies secretPath to be "/**"
if (existingAccessApprovalPolicies.length) {
await knex(TableName.AccessApprovalPolicy)
.whereIn(
"id",
existingAccessApprovalPolicies.map((el) => el.id)
)
.update({
secretPath: "/**"
});
}
await knex.schema.alterTable(TableName.SecretApprovalPolicy, (table) => {
table.string("secretPath").notNullable().alter();
});
await knex.schema.alterTable(TableName.AccessApprovalPolicy, (table) => {
table.string("secretPath").notNullable().alter();
});
}
export async function down(knex: Knex): Promise<void> {
await knex.schema.alterTable(TableName.SecretApprovalPolicy, (table) => {
table.string("secretPath").nullable().alter();
});
await knex.schema.alterTable(TableName.AccessApprovalPolicy, (table) => {
table.string("secretPath").nullable().alter();
});
}
@@ -23,10 +23,8 @@ export const registerSecretApprovalPolicyRouter = async (server: FastifyZodProvi
environment: z.string(), environment: z.string(),
secretPath: z secretPath: z
.string() .string()
.optional() .min(1, { message: "Secret path cannot be empty" })
.nullable() .transform((val) => removeTrailingSlash(val)),
.default("/")
.transform((val) => (val ? removeTrailingSlash(val) : val)),
approvers: z approvers: z
.discriminatedUnion("type", [ .discriminatedUnion("type", [
z.object({ type: z.literal(ApproverType.Group), id: z.string() }), z.object({ type: z.literal(ApproverType.Group), id: z.string() }),
@@ -100,9 +98,10 @@ export const registerSecretApprovalPolicyRouter = async (server: FastifyZodProvi
approvals: z.number().min(1).default(1), approvals: z.number().min(1).default(1),
secretPath: z secretPath: z
.string() .string()
.trim()
.min(1, { message: "Secret path cannot be empty" })
.optional() .optional()
.nullable() .transform((val) => (val ? removeTrailingSlash(val) : undefined)),
.transform((val) => (val ? removeTrailingSlash(val) : val)),
enforcementLevel: z.nativeEnum(EnforcementLevel).optional(), enforcementLevel: z.nativeEnum(EnforcementLevel).optional(),
allowedSelfApprovals: z.boolean().default(true) allowedSelfApprovals: z.boolean().default(true)
}), }),
@@ -4,7 +4,7 @@ import { ApproverType, BypasserType } from "../access-approval-policy/access-app
export type TCreateSapDTO = { export type TCreateSapDTO = {
approvals: number; approvals: number;
secretPath?: string | null; secretPath: string;
environment: string; environment: string;
approvers: ({ type: ApproverType.Group; id: string } | { type: ApproverType.User; id?: string; username?: string })[]; approvers: ({ type: ApproverType.Group; id: string } | { type: ApproverType.User; id?: string; username?: string })[];
bypassers?: ( bypassers?: (
@@ -20,7 +20,7 @@ export type TCreateSapDTO = {
export type TUpdateSapDTO = { export type TUpdateSapDTO = {
secretPolicyId: string; secretPolicyId: string;
approvals?: number; approvals?: number;
secretPath?: string | null; secretPath?: string;
approvers: ({ type: ApproverType.Group; id: string } | { type: ApproverType.User; id?: string; username?: string })[]; approvers: ({ type: ApproverType.Group; id: string } | { type: ApproverType.User; id?: string; username?: string })[];
bypassers?: ( bypassers?: (
| { type: BypasserType.Group; id: string } | { type: BypasserType.Group; id: string }
@@ -170,7 +170,7 @@ export type TCreateAccessPolicyDTO = {
approvers?: Approver[]; approvers?: Approver[];
bypassers?: Bypasser[]; bypassers?: Bypasser[];
approvals?: number; approvals?: number;
secretPath?: string; secretPath: string;
enforcementLevel?: EnforcementLevel; enforcementLevel?: EnforcementLevel;
allowedSelfApprovals: boolean; allowedSelfApprovals: boolean;
approvalsRequired?: { numberOfApprovals: number; stepNumber: number }[]; approvalsRequired?: { numberOfApprovals: number; stepNumber: number }[];
@@ -49,7 +49,7 @@ export type TCreateSecretPolicyDTO = {
workspaceId: string; workspaceId: string;
name?: string; name?: string;
environment: string; environment: string;
secretPath?: string | null; secretPath: string;
approvers?: Approver[]; approvers?: Approver[];
bypassers?: Bypasser[]; bypassers?: Bypasser[];
approvals?: number; approvals?: number;
@@ -62,7 +62,7 @@ export type TUpdateSecretPolicyDTO = {
name?: string; name?: string;
approvers?: Approver[]; approvers?: Approver[];
bypassers?: Bypasser[]; bypassers?: Bypasser[];
secretPath?: string | null; secretPath?: string;
approvals?: number; approvals?: number;
allowedSelfApprovals?: boolean; allowedSelfApprovals?: boolean;
enforcementLevel?: EnforcementLevel; enforcementLevel?: EnforcementLevel;
@@ -55,7 +55,7 @@ const formSchema = z
.object({ .object({
environment: z.object({ slug: z.string(), name: z.string() }), environment: z.object({ slug: z.string(), name: z.string() }),
name: z.string().optional(), name: z.string().optional(),
secretPath: z.string().trim().optional(), secretPath: z.string().trim().min(1),
approvals: z.number().min(1).default(1), approvals: z.number().min(1).default(1),
userApprovers: z userApprovers: z
.object({ type: z.literal(ApproverType.User), id: z.string() }) .object({ type: z.literal(ApproverType.User), id: z.string() })
@@ -106,14 +106,6 @@ const formSchema = z
message: "At least one approver should be provided" message: "At least one approver should be provided"
}); });
} }
} else if (data.policyType === PolicyType.AccessPolicy) {
if (!data.secretPath) {
ctx.addIssue({
path: ["secretPath"],
code: z.ZodIssueCode.custom,
message: "Secret path cannot be empty"
});
}
} }
}); });
@@ -477,6 +469,7 @@ const Form = ({
<FormControl <FormControl
tooltipText="Secret paths support glob patterns. For example, '/**' will match all paths." tooltipText="Secret paths support glob patterns. For example, '/**' will match all paths."
label="Secret Path" label="Secret Path"
isRequired
isError={Boolean(error)} isError={Boolean(error)}
errorText={error?.message} errorText={error?.message}
className="flex-1" className="flex-1"