mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 14:26:25 +00:00
feat(rbac): resolved batch bug in permission check
This commit is contained in:
@@ -163,19 +163,19 @@ export const batchSecrets = async (req: Request, res: Response) => {
|
|||||||
// not using service token using auth
|
// not using service token using auth
|
||||||
if (!(req.authData.authPayload instanceof ServiceTokenData)) {
|
if (!(req.authData.authPayload instanceof ServiceTokenData)) {
|
||||||
const { permission } = await getUserProjectPermissions(req.user._id, workspaceId);
|
const { permission } = await getUserProjectPermissions(req.user._id, workspaceId);
|
||||||
if (!createSecrets.length)
|
if (createSecrets.length)
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionActions.Create,
|
ProjectPermissionActions.Create,
|
||||||
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
||||||
);
|
);
|
||||||
|
|
||||||
if (!updateSecrets.length)
|
if (updateSecrets.length)
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionActions.Edit,
|
ProjectPermissionActions.Edit,
|
||||||
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
||||||
);
|
);
|
||||||
|
|
||||||
if (!deleteSecrets.length)
|
if (deleteSecrets.length)
|
||||||
ForbiddenError.from(permission).throwUnlessCan(
|
ForbiddenError.from(permission).throwUnlessCan(
|
||||||
ProjectPermissionActions.Delete,
|
ProjectPermissionActions.Delete,
|
||||||
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
||||||
|
|||||||
@@ -333,6 +333,10 @@ export const DashboardPage = () => {
|
|||||||
permission.cannot(
|
permission.cannot(
|
||||||
ProjectPermissionActions.Edit,
|
ProjectPermissionActions.Edit,
|
||||||
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
||||||
|
) &&
|
||||||
|
permission.cannot(
|
||||||
|
ProjectPermissionActions.Create,
|
||||||
|
subject(ProjectPermissionSub.Secrets, { environment, secretPath })
|
||||||
);
|
);
|
||||||
|
|
||||||
const canDoRollback = !isReadOnly;
|
const canDoRollback = !isReadOnly;
|
||||||
|
|||||||
@@ -304,10 +304,6 @@ export const SecretInputRow = memo(
|
|||||||
(isOverridden ? isAddOnly : shouldBeBlockedInAddOnly)
|
(isOverridden ? isAddOnly : shouldBeBlockedInAddOnly)
|
||||||
}
|
}
|
||||||
{...field}
|
{...field}
|
||||||
onChange={(val) => {
|
|
||||||
console.log(val);
|
|
||||||
field.onChange(val);
|
|
||||||
}}
|
|
||||||
/>
|
/>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
|
|||||||
Reference in New Issue
Block a user