feat: fixed secret approval for architecture v2

This commit is contained in:
=
2024-07-30 23:19:06 +05:30
parent acf9a488ac
commit f7ef86eb11
5 changed files with 76 additions and 70 deletions
@@ -261,31 +261,30 @@ export const registerSecretApprovalRequestRouter = async (server: FastifyZodProv
secretPath: z.string(), secretPath: z.string(),
commits: secretRawSchema commits: secretRawSchema
.omit({ _id: true, environment: true, workspace: true, type: true, version: true }) .omit({ _id: true, environment: true, workspace: true, type: true, version: true })
.merge( .extend({
z.object({ op: z.string(),
tags: tagSchema, tags: tagSchema,
secret: z secret: z
.object({ .object({
id: z.string(), id: z.string(),
version: z.number(), version: z.number(),
secretKey: z.string(), secretKey: z.string(),
secretValue: z.string().optional(), secretValue: z.string().optional(),
secretComment: z.string().optional() secretComment: z.string().optional()
}) })
.optional() .optional()
.nullable(), .nullable(),
secretVersion: z secretVersion: z
.object({ .object({
id: z.string(), id: z.string(),
version: z.number(), version: z.number(),
secretKey: z.string(), secretKey: z.string(),
secretValue: z.string().optional(), secretValue: z.string().optional(),
secretComment: z.string().optional(), secretComment: z.string().optional(),
tags: tagSchema tags: tagSchema
}) })
.optional() .optional()
}) })
)
.array() .array()
}) })
) )
+10 -11
View File
@@ -29,17 +29,16 @@ export const registerSnapshotRouter = async (server: FastifyZodProvider) => {
name: z.string() name: z.string()
}), }),
secretVersions: secretRawSchema secretVersions: secretRawSchema
.omit({ _id: true, environment: true, workspace: true, type: true, version: true }) .omit({ _id: true, environment: true, workspace: true, type: true })
.merge( .extend({
z.object({ secretId: z.string(),
tags: SecretTagsSchema.pick({ tags: SecretTagsSchema.pick({
id: true, id: true,
slug: true, slug: true,
name: true, name: true,
color: true color: true
}).array() }).array()
}) })
)
.array(), .array(),
folderVersion: z.object({ id: z.string(), name: z.string() }).array(), folderVersion: z.object({ id: z.string(), name: z.string() }).array(),
createdAt: z.date(), createdAt: z.date(),
@@ -242,7 +242,7 @@ export const secretApprovalRequestSecretDALFactory = (db: TDbClient) => {
`${TableName.SecretApprovalRequestSecretTagV2}.tagId`, `${TableName.SecretApprovalRequestSecretTagV2}.tagId`,
`${TableName.SecretTag}.id` `${TableName.SecretTag}.id`
) )
.leftJoin(TableName.SecretV2, `${TableName.SecretApprovalRequestSecretV2}.secretId`, `${TableName.Secret}.id`) .leftJoin(TableName.SecretV2, `${TableName.SecretApprovalRequestSecretV2}.secretId`, `${TableName.SecretV2}.id`)
.leftJoin( .leftJoin(
TableName.SecretVersionV2, TableName.SecretVersionV2,
`${TableName.SecretVersionV2}.id`, `${TableName.SecretVersionV2}.id`,
@@ -230,28 +230,32 @@ export const secretApprovalRequestServiceFactory = ({
secretComment: el.encryptedComment secretComment: el.encryptedComment
? secretManagerDecryptor({ cipherTextBlob: el.encryptedComment }).toString() ? secretManagerDecryptor({ cipherTextBlob: el.encryptedComment }).toString()
: undefined, : undefined,
secret: { secret: el.secret
secretKey: el.secret.key, ? {
id: el.secret.id, secretKey: el.secret.key,
version: el.secret.version, id: el.secret.id,
secretValue: el.secret.encryptedValue version: el.secret.version,
? secretManagerDecryptor({ cipherTextBlob: el.secret.encryptedValue }).toString() secretValue: el.secret.encryptedValue
: undefined, ? secretManagerDecryptor({ cipherTextBlob: el.secret.encryptedValue }).toString()
secretComment: el.secret.encryptedComment : undefined,
? secretManagerDecryptor({ cipherTextBlob: el.secret.encryptedComment }).toString() secretComment: el.secret.encryptedComment
: undefined ? secretManagerDecryptor({ cipherTextBlob: el.secret.encryptedComment }).toString()
}, : undefined
secretVersion: { }
secretKey: el.secretVersion.key, : undefined,
id: el.secretVersion.id, secretVersion: el.secretVersion
version: el.secretVersion.version, ? {
secretValue: el.secretVersion.encryptedValue secretKey: el.secretVersion.key,
? secretManagerDecryptor({ cipherTextBlob: el.secretVersion.encryptedValue }).toString() id: el.secretVersion.id,
: undefined, version: el.secretVersion.version,
secretComment: el.secretVersion.encryptedComment secretValue: el.secretVersion.encryptedValue
? secretManagerDecryptor({ cipherTextBlob: el.secretVersion.encryptedComment }).toString() ? secretManagerDecryptor({ cipherTextBlob: el.secretVersion.encryptedValue }).toString()
: undefined : undefined,
} secretComment: el.secretVersion.encryptedComment
? secretManagerDecryptor({ cipherTextBlob: el.secretVersion.encryptedComment }).toString()
: undefined
}
: undefined
})); }));
} else { } else {
if (!botKey) throw new BadRequestError({ message: "Bot key not found" }); if (!botKey) throw new BadRequestError({ message: "Bot key not found" });
@@ -259,16 +263,20 @@ export const secretApprovalRequestServiceFactory = ({
secrets = encrypedSecrets.map((el) => ({ secrets = encrypedSecrets.map((el) => ({
...el, ...el,
...decryptSecretWithBot(el, botKey), ...decryptSecretWithBot(el, botKey),
secret: { secret: el.secret
id: el.secret.id, ? {
version: el.secret.version, id: el.secret.id,
...decryptSecretWithBot(el.secret, botKey) version: el.secret.version,
}, ...decryptSecretWithBot(el.secret, botKey)
secretVersion: { }
id: el.secretVersion.id, : undefined,
version: el.secretVersion.version, secretVersion: el.secretVersion
...decryptSecretWithBot(el.secretVersion, botKey) ? {
} id: el.secretVersion.id,
version: el.secretVersion.version,
...decryptSecretWithBot(el.secretVersion, botKey)
}
: undefined
})); }));
} }
const secretPath = await folderDAL.findSecretPathByFolderIds(secretApprovalRequest.projectId, [ const secretPath = await folderDAL.findSecretPathByFolderIds(secretApprovalRequest.projectId, [
@@ -505,7 +505,7 @@ export const snapshotDALFactory = (db: TDbClient) => {
db.ref("max").withSchema("secGroupByMaxVersion").as("latestSecretVersion"), db.ref("max").withSchema("secGroupByMaxVersion").as("latestSecretVersion"),
db.ref("max").withSchema("folderGroupByMaxVersion").as("latestFolderVersion"), db.ref("max").withSchema("folderGroupByMaxVersion").as("latestFolderVersion"),
db.ref("id").withSchema(TableName.SecretTag).as("tagId"), db.ref("id").withSchema(TableName.SecretTag).as("tagId"),
db.ref("id").withSchema(TableName.SecretVersionTag).as("tagVersionId"), db.ref("id").withSchema(TableName.SecretVersionV2Tag).as("tagVersionId"),
db.ref("color").withSchema(TableName.SecretTag).as("tagColor"), db.ref("color").withSchema(TableName.SecretTag).as("tagColor"),
db.ref("slug").withSchema(TableName.SecretTag).as("tagSlug"), db.ref("slug").withSchema(TableName.SecretTag).as("tagSlug"),
db.ref("name").withSchema(TableName.SecretTag).as("tagName") db.ref("name").withSchema(TableName.SecretTag).as("tagName")