Addressed pr comments

This commit is contained in:
Carlos Monastyrski
2025-08-03 13:02:20 -03:00
parent 4f0007faa5
commit ebe05661d3
14 changed files with 76 additions and 52 deletions
@@ -25,9 +25,9 @@ export async function up(knex: Knex): Promise<void> {
}
export async function down(knex: Knex): Promise<void> {
if (await knex.schema.hasColumn(TableName.IdentityLdapAuth, "template")) {
if (await knex.schema.hasColumn(TableName.IdentityLdapAuth, "templateId")) {
await knex.schema.alterTable(TableName.IdentityLdapAuth, (t) => {
t.dropForeign("templateId");
t.dropForeign(["templateId"]);
t.dropColumn("templateId");
});
}
@@ -419,15 +419,6 @@ const buildMemberPermission = () => {
can(OrgPermissionGatewayActions.AttachGateways, OrgPermissionSubjects.Gateway);
can(OrgPermissionMachineIdentityAuthTemplateActions.ListTemplates, OrgPermissionSubjects.MachineIdentityAuthTemplate);
can(OrgPermissionMachineIdentityAuthTemplateActions.EditTemplates, OrgPermissionSubjects.MachineIdentityAuthTemplate);
can(
OrgPermissionMachineIdentityAuthTemplateActions.CreateTemplates,
OrgPermissionSubjects.MachineIdentityAuthTemplate
);
can(
OrgPermissionMachineIdentityAuthTemplateActions.DeleteTemplates,
OrgPermissionSubjects.MachineIdentityAuthTemplate
);
can(
OrgPermissionMachineIdentityAuthTemplateActions.UnlinkTemplates,
OrgPermissionSubjects.MachineIdentityAuthTemplate
@@ -35,7 +35,11 @@ export const registerIdentityTemplateRouter = async (server: FastifyZodProvider)
}
],
body: z.object({
name: z.string().trim().min(1, TEMPLATE_VALIDATION_MESSAGES.TEMPLATE_NAME_REQUIRED),
name: z
.string()
.trim()
.min(1, TEMPLATE_VALIDATION_MESSAGES.TEMPLATE_NAME_REQUIRED)
.max(64, TEMPLATE_VALIDATION_MESSAGES.TEMPLATE_NAME_MAX_LENGTH),
authMethod: z.nativeEnum(IdentityAuthTemplateMethod),
templateFields: ldapTemplateFieldsSchema
}),
@@ -91,7 +95,12 @@ export const registerIdentityTemplateRouter = async (server: FastifyZodProvider)
templateId: z.string().min(1, TEMPLATE_VALIDATION_MESSAGES.TEMPLATE_ID_REQUIRED)
}),
body: z.object({
name: z.string().trim().optional(),
name: z
.string()
.trim()
.min(1, TEMPLATE_VALIDATION_MESSAGES.TEMPLATE_NAME_REQUIRED)
.max(64, TEMPLATE_VALIDATION_MESSAGES.TEMPLATE_NAME_MAX_LENGTH)
.optional(),
templateFields: ldapTemplateFieldsSchema.partial().optional()
}),
response: {
@@ -232,7 +241,8 @@ export const registerIdentityTemplateRouter = async (server: FastifyZodProvider)
],
querystring: z.object({
limit: z.coerce.number().positive().max(100).default(5).optional(),
offset: z.coerce.number().min(0).default(0).optional()
offset: z.coerce.number().min(0).default(0).optional(),
search: z.string().optional()
}),
response: {
200: z.object({
@@ -247,6 +257,7 @@ export const registerIdentityTemplateRouter = async (server: FastifyZodProvider)
const { templates, totalCount } = await server.services.identityAuthTemplate.listTemplates({
limit: req.query.limit,
offset: req.query.offset,
search: req.query.search,
actor: req.permission.type,
actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod,
@@ -303,7 +314,7 @@ export const registerIdentityTemplateRouter = async (server: FastifyZodProvider)
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: {
hide: false,
description: "Get identity auth templates by authentication method",
description: "Get template usage by template ID",
security: [
{
bearerAuth: []
@@ -338,7 +349,7 @@ export const registerIdentityTemplateRouter = async (server: FastifyZodProvider)
method: "POST",
url: "/:templateId/usage",
config: {
rateLimit: readLimit
rateLimit: writeLimit
},
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: {
@@ -14,9 +14,18 @@ export const identityAuthTemplateDALFactory = (db: TDbClient) => {
const findByOrgId = async (
orgId: string,
{ limit, offset, tx }: { limit?: number; offset?: number; tx?: Knex } = {}
{ limit, offset, search, tx }: { limit?: number; offset?: number; search?: string; tx?: Knex } = {}
) => {
let query = (tx || db.replicaNode())(TableName.IdentityAuthTemplate).where({ orgId }).orderBy("createdAt", "desc");
let query = (tx || db.replicaNode())(TableName.IdentityAuthTemplate).where({ orgId });
let countQuery = (tx || db.replicaNode())(TableName.IdentityAuthTemplate).where({ orgId });
if (search) {
const searchFilter = `%${search.toLowerCase()}%`;
query = query.whereRaw("LOWER(name) LIKE ?", [searchFilter]);
countQuery = countQuery.whereRaw("LOWER(name) LIKE ?", [searchFilter]);
}
query = query.orderBy("createdAt", "desc");
if (limit !== undefined) {
query = query.limit(limit);
@@ -27,9 +36,7 @@ export const identityAuthTemplateDALFactory = (db: TDbClient) => {
const docs = await query;
const [{ count }] = (await (tx || db.replicaNode())(TableName.IdentityAuthTemplate)
.where({ orgId })
.count("* as count")) as [{ count: string | number }];
const [{ count }] = (await countQuery.count("* as count")) as [{ count: string | number }];
return { docs, totalCount: Number(count) };
};
@@ -60,10 +67,17 @@ export const identityAuthTemplateDALFactory = (db: TDbClient) => {
}
};
const findByIdAndOrgId = async (id: string, orgId: string, tx?: Knex) => {
const query = (tx || db.replicaNode())(TableName.IdentityAuthTemplate).where({ id, orgId });
const doc = await query;
return doc?.[0];
};
return {
...identityAuthTemplateOrm,
findByOrgId,
findByAuthMethod,
findTemplateUsages
findTemplateUsages,
findByIdAndOrgId
};
};
@@ -4,6 +4,7 @@ export enum IdentityAuthTemplateMethod {
export const TEMPLATE_VALIDATION_MESSAGES = {
TEMPLATE_NAME_REQUIRED: "Template name is required",
TEMPLATE_NAME_MAX_LENGTH: "Template name must be at most 64 characters long",
AUTH_METHOD_REQUIRED: "Auth method is required",
TEMPLATE_ID_REQUIRED: "Template ID is required",
LDAP_URL_REQUIRED: "LDAP URL is required",
@@ -249,19 +249,20 @@ export const identityAuthTemplateServiceFactory = ({
const { decryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization,
orgId: actorOrgId
orgId: template.orgId
});
const decryptedTemplateFields = decryptor({ cipherTextBlob: template.templateFields }).toString();
return {
...template,
// eslint-disable-next-line @typescript-eslint/no-unsafe-assignment
templateFields: JSON.parse(decryptedTemplateFields.toString())
templateFields: JSON.parse(decryptedTemplateFields)
};
};
const listTemplates = async ({
limit,
offset,
search,
actorId,
actorAuthMethod,
actor,
@@ -280,7 +281,7 @@ export const identityAuthTemplateServiceFactory = ({
OrgPermissionSubjects.MachineIdentityAuthTemplate
);
const { docs, totalCount } = await identityAuthTemplateDAL.findByOrgId(actorOrgId, { limit, offset });
const { docs, totalCount } = await identityAuthTemplateDAL.findByOrgId(actorOrgId, { limit, offset, search });
const { decryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization,
@@ -16,16 +16,16 @@ export type TTemplateFieldsByMethod = {
};
// Generic base types that use conditional types for type safety
export type TCreateIdentityAuthTemplateDTO<T extends IdentityAuthTemplateMethod = IdentityAuthTemplateMethod> = {
export type TCreateIdentityAuthTemplateDTO = {
name: string;
authMethod: T;
templateFields: TTemplateFieldsByMethod[T];
authMethod: IdentityAuthTemplateMethod;
templateFields: TTemplateFieldsByMethod[IdentityAuthTemplateMethod];
} & Omit<TProjectPermission, "projectId">;
export type TUpdateIdentityAuthTemplateDTO<T extends IdentityAuthTemplateMethod = IdentityAuthTemplateMethod> = {
export type TUpdateIdentityAuthTemplateDTO = {
templateId: string;
name?: string;
templateFields?: Partial<TTemplateFieldsByMethod[T]>;
templateFields?: Partial<TTemplateFieldsByMethod[IdentityAuthTemplateMethod]>;
} & Omit<TProjectPermission, "projectId">;
export type TDeleteIdentityAuthTemplateDTO = {
@@ -39,6 +39,7 @@ export type TGetIdentityAuthTemplateDTO = {
export type TListIdentityAuthTemplatesDTO = {
limit?: number;
offset?: number;
search?: string;
} & Omit<TProjectPermission, "projectId">;
export type TGetTemplatesByAuthMethodDTO = {
@@ -55,5 +56,5 @@ export type TUnlinkTemplateUsageDTO = {
} & Omit<TProjectPermission, "projectId">;
// Specific LDAP types for convenience
export type TCreateLdapTemplateDTO = TCreateIdentityAuthTemplateDTO<IdentityAuthTemplateMethod.LDAP>;
export type TUpdateLdapTemplateDTO = TUpdateIdentityAuthTemplateDTO<IdentityAuthTemplateMethod.LDAP>;
export type TCreateLdapTemplateDTO = TCreateIdentityAuthTemplateDTO;
export type TUpdateLdapTemplateDTO = TUpdateIdentityAuthTemplateDTO;
@@ -250,7 +250,9 @@ export const identityLdapAuthServiceFactory = ({
orgId: identityMembershipOrg.orgId
});
const template = templateId ? await identityAuthTemplateDAL.findById(templateId) : undefined;
const template = templateId
? await identityAuthTemplateDAL.findByIdAndOrgId(templateId, identityMembershipOrg.orgId)
: undefined;
let ldapConfig: { bindDN: string; bindPass: string; searchBase: string; url: string };
if (template) {
@@ -401,7 +403,9 @@ export const identityLdapAuthServiceFactory = ({
orgId: identityMembershipOrg.orgId
});
const template = templateId ? await identityAuthTemplateDAL.findById(templateId) : undefined;
const template = templateId
? await identityAuthTemplateDAL.findByIdAndOrgId(templateId, identityMembershipOrg.orgId)
: undefined;
let config: {
bindDN?: string;
bindPass?: string;