mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 07:27:58 +00:00
feat(rbac): fixed merge conflicts and resolved some more issues with permission checks
This commit is contained in:
@@ -201,14 +201,6 @@ export const logout = async (req: Request, res: Response) => {
|
||||
});
|
||||
};
|
||||
|
||||
export const getCommonPasswords = async (req: Request, res: Response) => {
|
||||
const commonPasswords = fs
|
||||
.readFileSync(path.resolve(__dirname, "../../data/" + "common_passwords.txt"), "utf8")
|
||||
.split("\n");
|
||||
|
||||
return res.status(200).send(commonPasswords);
|
||||
};
|
||||
|
||||
export const revokeAllSessions = async (req: Request, res: Response) => {
|
||||
await TokenVersion.updateMany(
|
||||
{
|
||||
|
||||
@@ -203,7 +203,6 @@ export const getUserWorkspacePermissions = async (req: Request, res: Response) =
|
||||
params: { workspaceId }
|
||||
} = await validateRequest(GetUserProjectPermission, req);
|
||||
const { permission } = await getUserProjectPermissions(req.user.id, workspaceId);
|
||||
|
||||
res.status(200).json({
|
||||
data: {
|
||||
permissions: packRules(permission.rules)
|
||||
|
||||
@@ -77,16 +77,6 @@ export const batchSecrets = async (req: Request, res: Response) => {
|
||||
|
||||
const folders = await Folder.findOne({ workspace: workspaceId, environment });
|
||||
|
||||
if (req.authData.authPayload instanceof ServiceTokenData) {
|
||||
await validateServiceTokenDataClientForWorkspace({
|
||||
serviceTokenData: req.authData.authPayload,
|
||||
workspaceId: new Types.ObjectId(workspaceId),
|
||||
environment,
|
||||
secretPath,
|
||||
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||
});
|
||||
}
|
||||
|
||||
if (secretPath) {
|
||||
folderId = await getFolderIdFromServiceToken(workspaceId, environment, secretPath);
|
||||
}
|
||||
@@ -100,7 +90,15 @@ export const batchSecrets = async (req: Request, res: Response) => {
|
||||
);
|
||||
}
|
||||
|
||||
if (req.user?._id) {
|
||||
if (req.authData.authPayload instanceof ServiceTokenData) {
|
||||
await validateServiceTokenDataClientForWorkspace({
|
||||
serviceTokenData: req.authData.authPayload,
|
||||
workspaceId: new Types.ObjectId(workspaceId),
|
||||
environment,
|
||||
secretPath,
|
||||
requiredPermissions: [PERMISSION_WRITE_SECRETS]
|
||||
});
|
||||
} else {
|
||||
const { permission } = await getUserProjectPermissions(req.user._id, workspaceId);
|
||||
ForbiddenError.from(permission).throwUnlessCan(
|
||||
ProjectPermissionActions.Create,
|
||||
|
||||
@@ -44,6 +44,4 @@ const membershipOrgSchema = new Schema(
|
||||
}
|
||||
);
|
||||
|
||||
const MembershipOrg = model<IMembershipOrg>("MembershipOrg", membershipOrgSchema);
|
||||
|
||||
export default MembershipOrg;
|
||||
export const MembershipOrg = model<IMembershipOrg>("MembershipOrg", membershipOrgSchema);
|
||||
|
||||
@@ -38,8 +38,6 @@ router.post(
|
||||
authController.checkAuth
|
||||
);
|
||||
|
||||
router.get("/common-passwords", authLimiter, authController.getCommonPasswords);
|
||||
|
||||
router.delete(
|
||||
// TODO endpoint: deprecate (moved to DELETE v2/users/me/sessions)
|
||||
"/sessions",
|
||||
|
||||
@@ -93,11 +93,11 @@ router.get(
|
||||
);
|
||||
|
||||
router.get(
|
||||
"/:integrationAuthId/teamcity/build-configs",
|
||||
requireAuth({
|
||||
acceptedAuthModes: [AuthMode.JWT],
|
||||
}),
|
||||
integrationAuthController.getIntegrationAuthTeamCityBuildConfigs
|
||||
"/:integrationAuthId/teamcity/build-configs",
|
||||
requireAuth({
|
||||
acceptedAuthModes: [AuthMode.JWT]
|
||||
}),
|
||||
integrationAuthController.getIntegrationAuthTeamCityBuildConfigs
|
||||
);
|
||||
|
||||
router.delete(
|
||||
|
||||
@@ -219,7 +219,6 @@ export const getUserProjectPermissions = async (userId: string, workspaceId: str
|
||||
}>("customRole")
|
||||
.exec();
|
||||
|
||||
console.log(membership, userId, workspaceId);
|
||||
if (!membership || (membership.role === "custom" && !membership.customRole)) {
|
||||
throw UnauthorizedRequestError({ message: "User doesn't belong to organization" });
|
||||
}
|
||||
|
||||
@@ -6,7 +6,6 @@ import { MembershipNotFoundError } from "../utils/errors";
|
||||
import { AuthData } from "../interfaces/middleware";
|
||||
import { ActorType } from "../ee/models";
|
||||
import { z } from "zod";
|
||||
import { ADMIN, CUSTOM, MEMBER, VIEWER } from "../variables";
|
||||
|
||||
/**
|
||||
* Validate authenticated clients for membership with id [membershipId] based
|
||||
@@ -66,7 +65,7 @@ export const DeleteMembershipV1 = z.object({
|
||||
|
||||
export const ChangeMembershipRoleV1 = z.object({
|
||||
body: z.object({
|
||||
role: z.enum([ADMIN, VIEWER, MEMBER, CUSTOM])
|
||||
role: z.string().trim()
|
||||
}),
|
||||
params: z.object({ membershipId: z.string().trim() })
|
||||
});
|
||||
|
||||
@@ -11,7 +11,7 @@ export const CreateRoleSchema = z.object({
|
||||
.object({
|
||||
subject: z.string(),
|
||||
action: z.string(),
|
||||
condition: z.record(z.union([z.string(), z.number()])).optional()
|
||||
conditions: z.record(z.union([z.string(), z.number()])).optional()
|
||||
})
|
||||
.array()
|
||||
})
|
||||
@@ -31,7 +31,7 @@ export const UpdateRoleSchema = z.object({
|
||||
.object({
|
||||
subject: z.string(),
|
||||
action: z.string(),
|
||||
condition: z.record(z.union([z.string(), z.number()])).optional()
|
||||
conditions: z.record(z.union([z.string(), z.number()])).optional()
|
||||
})
|
||||
.array()
|
||||
.optional()
|
||||
|
||||
Reference in New Issue
Block a user