mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Ghost user!
This commit is contained in:
@@ -1,4 +1,5 @@
|
|||||||
import { registerLoginRouter } from "./login-router";
|
import { registerLoginRouter } from "./login-router";
|
||||||
|
import { registerProjectRouter } from "./project-router";
|
||||||
import { registerSecretBlindIndexRouter } from "./secret-blind-index-router";
|
import { registerSecretBlindIndexRouter } from "./secret-blind-index-router";
|
||||||
import { registerSecretRouter } from "./secret-router";
|
import { registerSecretRouter } from "./secret-router";
|
||||||
import { registerSignupRouter } from "./signup-router";
|
import { registerSignupRouter } from "./signup-router";
|
||||||
@@ -10,4 +11,5 @@ export const registerV3Routes = async (server: FastifyZodProvider) => {
|
|||||||
await server.register(registerUserRouter, { prefix: "/users" });
|
await server.register(registerUserRouter, { prefix: "/users" });
|
||||||
await server.register(registerSecretRouter, { prefix: "/secrets" });
|
await server.register(registerSecretRouter, { prefix: "/secrets" });
|
||||||
await server.register(registerSecretBlindIndexRouter, { prefix: "/workspaces" });
|
await server.register(registerSecretBlindIndexRouter, { prefix: "/workspaces" });
|
||||||
|
await server.register(registerProjectRouter, { prefix: "/projects" });
|
||||||
};
|
};
|
||||||
|
|||||||
126
backend/src/server/routes/v3/project-router.ts
Normal file
126
backend/src/server/routes/v3/project-router.ts
Normal file
@@ -0,0 +1,126 @@
|
|||||||
|
import crypto from "crypto";
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { ProjectMembershipRole, ProjectsSchema } from "@app/db/schemas";
|
||||||
|
import { encryptAsymmetric } from "@app/lib/crypto";
|
||||||
|
import { createWsMembers } from "@app/lib/project";
|
||||||
|
import { authRateLimit } from "@app/server/config/rateLimiter";
|
||||||
|
|
||||||
|
const projectWithEnv = ProjectsSchema.merge(
|
||||||
|
z.object({
|
||||||
|
_id: z.string(),
|
||||||
|
environments: z.object({ name: z.string(), slug: z.string(), id: z.string() }).array()
|
||||||
|
})
|
||||||
|
);
|
||||||
|
|
||||||
|
export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
||||||
|
/* Create new project */
|
||||||
|
server.route({
|
||||||
|
method: "POST",
|
||||||
|
url: "/",
|
||||||
|
config: {
|
||||||
|
rateLimit: authRateLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
body: z.object({
|
||||||
|
projectName: z.string().trim(),
|
||||||
|
inviteAllOrgMembers: z.boolean(),
|
||||||
|
organizationId: z.string().trim()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
workspace: projectWithEnv
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
// 1. create the ghost user and add it to the org as admin
|
||||||
|
const ghost = await server.services.org.addGhostUser(req.body.organizationId);
|
||||||
|
|
||||||
|
// 2. create the workspace
|
||||||
|
const workspace = await server.services.project.createProject({
|
||||||
|
actorId: ghost.user.id,
|
||||||
|
actor: req.permission.type,
|
||||||
|
orgId: req.body.organizationId,
|
||||||
|
workspaceName: req.body.projectName
|
||||||
|
});
|
||||||
|
|
||||||
|
// 3. create a random key that we'll use as the project key
|
||||||
|
const randomBytes = crypto.randomBytes(16).toString("hex");
|
||||||
|
|
||||||
|
const ghostPrivateKey = ghost.keys.plainPrivateKey;
|
||||||
|
|
||||||
|
const { ciphertext: encryptedProjectKey, nonce: encryptedProjectKeyIv } = encryptAsymmetric(
|
||||||
|
randomBytes,
|
||||||
|
ghost.keys.publicKey,
|
||||||
|
ghostPrivateKey
|
||||||
|
);
|
||||||
|
|
||||||
|
// 3. create workspace keys for the ghost user
|
||||||
|
await server.services.projectKey.uploadProjectKeys({
|
||||||
|
projectId: workspace.id,
|
||||||
|
actor: req.permission.type,
|
||||||
|
actorId: ghost.user.id,
|
||||||
|
nonce: encryptedProjectKeyIv,
|
||||||
|
receiverId: ghost.user.id,
|
||||||
|
encryptedKey: encryptedProjectKey
|
||||||
|
});
|
||||||
|
|
||||||
|
// 4. create a project bot
|
||||||
|
const bot = await server.services.projectBot.findBotByProjectId({
|
||||||
|
actorId: ghost.user.id,
|
||||||
|
actor: req.permission.type,
|
||||||
|
projectId: workspace.id
|
||||||
|
});
|
||||||
|
|
||||||
|
// 5. activate the bot
|
||||||
|
await server.services.projectBot.setBotActiveState({
|
||||||
|
botKey: {
|
||||||
|
encryptedKey: encryptedProjectKey,
|
||||||
|
nonce: encryptedProjectKeyIv
|
||||||
|
},
|
||||||
|
actorId: ghost.user.id,
|
||||||
|
isActive: true,
|
||||||
|
actor: req.permission.type,
|
||||||
|
botId: bot.id
|
||||||
|
});
|
||||||
|
|
||||||
|
// 6. get the current user & org membership
|
||||||
|
const user = await server.services.user.getMe(req.permission.id);
|
||||||
|
const userOrgMembership = await server.services.permission.getUserOrgPermission(user.id, req.body.organizationId);
|
||||||
|
|
||||||
|
// 7. Get the latest key from the ghost!
|
||||||
|
const latestKey = await server.services.projectKey.getLatestProjectKey({
|
||||||
|
actorId: ghost.user.id,
|
||||||
|
actor: req.permission.type,
|
||||||
|
projectId: workspace.id
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!latestKey) throw new Error("Failed to get latest key");
|
||||||
|
|
||||||
|
// 8. Create workspace members for the current user
|
||||||
|
|
||||||
|
const projectAdmin = await createWsMembers({
|
||||||
|
decryptKey: latestKey,
|
||||||
|
members: [
|
||||||
|
{
|
||||||
|
userPublicKey: user.publicKey,
|
||||||
|
orgMembershipId: userOrgMembership.membership.id,
|
||||||
|
projectMembershipRole: ProjectMembershipRole.Admin // <-- Make the first user an admin
|
||||||
|
}
|
||||||
|
],
|
||||||
|
userPrivateKey: ghostPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
|
// 9. Add the current user to the workspace
|
||||||
|
await server.services.projectMembership.addUsersToProject({
|
||||||
|
projectId: workspace.id,
|
||||||
|
actorId: ghost.user.id,
|
||||||
|
actor: req.permission.type,
|
||||||
|
members: projectAdmin
|
||||||
|
});
|
||||||
|
|
||||||
|
return { workspace };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -275,7 +275,7 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
|
|||||||
if (isOauthSignUpDisabled) throw new BadRequestError({ message: "User signup disabled", name: "Oauth 2 login" });
|
if (isOauthSignUpDisabled) throw new BadRequestError({ message: "User signup disabled", name: "Oauth 2 login" });
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
user = await userDAL.create({ email, firstName, lastName, authMethods: [authMethod] });
|
user = await userDAL.create({ email, firstName, lastName, authMethods: [authMethod], ghost: false });
|
||||||
}
|
}
|
||||||
const isLinkingRequired = !user?.authMethods?.includes(authMethod);
|
const isLinkingRequired = !user?.authMethods?.includes(authMethod);
|
||||||
const isUserCompleted = user.isAccepted;
|
const isUserCompleted = user.isAccepted;
|
||||||
|
|||||||
@@ -76,7 +76,8 @@ export const orgDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("lastName").withSchema(TableName.Users),
|
db.ref("lastName").withSchema(TableName.Users),
|
||||||
db.ref("id").withSchema(TableName.Users).as("userId"),
|
db.ref("id").withSchema(TableName.Users).as("userId"),
|
||||||
db.ref("publicKey").withSchema(TableName.UserEncryptionKey)
|
db.ref("publicKey").withSchema(TableName.UserEncryptionKey)
|
||||||
);
|
)
|
||||||
|
.where({ ghost: false }); // MAKE SURE USER IS NOT A GHOST USER
|
||||||
return members.map(({ email, firstName, lastName, userId, publicKey, ...data }) => ({
|
return members.map(({ email, firstName, lastName, userId, publicKey, ...data }) => ({
|
||||||
...data,
|
...data,
|
||||||
user: { email, firstName, lastName, id: userId, publicKey }
|
user: { email, firstName, lastName, id: userId, publicKey }
|
||||||
@@ -86,6 +87,43 @@ export const orgDALFactory = (db: TDbClient) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const findOrgGhostUser = async (orgId: string) => {
|
||||||
|
try {
|
||||||
|
const [member] = await db(TableName.OrgMembership)
|
||||||
|
.where({ orgId })
|
||||||
|
.join(TableName.Users, `${TableName.OrgMembership}.userId`, `${TableName.Users}.id`)
|
||||||
|
.leftJoin(TableName.UserEncryptionKey, `${TableName.UserEncryptionKey}.userId`, `${TableName.Users}.id`)
|
||||||
|
.select(
|
||||||
|
db.ref("id").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("orgId").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("role").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("roleId").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("status").withSchema(TableName.OrgMembership),
|
||||||
|
db.ref("email").withSchema(TableName.Users),
|
||||||
|
db.ref("id").withSchema(TableName.Users).as("userId"),
|
||||||
|
db.ref("publicKey").withSchema(TableName.UserEncryptionKey)
|
||||||
|
)
|
||||||
|
.where({ ghost: true });
|
||||||
|
return member;
|
||||||
|
} catch (error) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const ghostUserExists = async (orgId: string) => {
|
||||||
|
try {
|
||||||
|
const [member] = await db(TableName.OrgMembership)
|
||||||
|
.where({ orgId })
|
||||||
|
.join(TableName.Users, `${TableName.OrgMembership}.userId`, `${TableName.Users}.id`)
|
||||||
|
.leftJoin(TableName.UserEncryptionKey, `${TableName.UserEncryptionKey}.userId`, `${TableName.Users}.id`)
|
||||||
|
.select(db.ref("id").withSchema(TableName.Users).as("userId"))
|
||||||
|
.where({ ghost: true });
|
||||||
|
return !!member;
|
||||||
|
} catch (error) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
const create = async (dto: TOrganizationsInsert, tx?: Knex) => {
|
const create = async (dto: TOrganizationsInsert, tx?: Knex) => {
|
||||||
try {
|
try {
|
||||||
const [organization] = await (tx || db)(TableName.Organization).insert(dto).returning("*");
|
const [organization] = await (tx || db)(TableName.Organization).insert(dto).returning("*");
|
||||||
@@ -191,6 +229,8 @@ export const orgDALFactory = (db: TDbClient) => {
|
|||||||
findAllOrgMembers,
|
findAllOrgMembers,
|
||||||
findOrgById,
|
findOrgById,
|
||||||
findAllOrgsByUserId,
|
findAllOrgsByUserId,
|
||||||
|
ghostUserExists,
|
||||||
|
findOrgGhostUser,
|
||||||
create,
|
create,
|
||||||
updateById,
|
updateById,
|
||||||
deleteById,
|
deleteById,
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
import slugify from "@sindresorhus/slugify";
|
import slugify from "@sindresorhus/slugify";
|
||||||
|
import crypto from "crypto";
|
||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
|
|
||||||
import { OrgMembershipRole, OrgMembershipStatus } from "@app/db/schemas";
|
import { OrgMembershipRole, OrgMembershipStatus } from "@app/db/schemas";
|
||||||
@@ -11,6 +12,7 @@ import { TSamlConfigDALFactory } from "@app/ee/services/saml-config/saml-config-
|
|||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { generateAsymmetricKeyPair } from "@app/lib/crypto";
|
import { generateAsymmetricKeyPair } from "@app/lib/crypto";
|
||||||
import { generateSymmetricKey, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
import { generateSymmetricKey, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||||
|
import { generateUserSrpKeys } from "@app/lib/crypto/srp";
|
||||||
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||||
import { isDisposableEmail } from "@app/lib/validator";
|
import { isDisposableEmail } from "@app/lib/validator";
|
||||||
@@ -118,6 +120,49 @@ export const orgServiceFactory = ({
|
|||||||
return workspaces.filter((workspace) => organizationWorkspaceIds.has(workspace.id));
|
return workspaces.filter((workspace) => organizationWorkspaceIds.has(workspace.id));
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const addGhostUser = async (orgId: string) => {
|
||||||
|
const email = `ghost@${orgId}.com`;
|
||||||
|
const password = crypto.randomBytes(128).toString("hex");
|
||||||
|
|
||||||
|
const user = await userDAL.create({
|
||||||
|
ghost: true,
|
||||||
|
authMethods: [AuthMethod.EMAIL],
|
||||||
|
email: `ghost@${orgId}.com`,
|
||||||
|
isAccepted: true
|
||||||
|
});
|
||||||
|
|
||||||
|
const encKeys = await generateUserSrpKeys(email, password);
|
||||||
|
|
||||||
|
await userDAL.upsertUserEncryptionKey(user.id, {
|
||||||
|
encryptionVersion: 2,
|
||||||
|
protectedKey: encKeys.protectedKey,
|
||||||
|
protectedKeyIV: encKeys.protectedKeyIV,
|
||||||
|
protectedKeyTag: encKeys.protectedKeyTag,
|
||||||
|
publicKey: encKeys.publicKey,
|
||||||
|
encryptedPrivateKey: encKeys.encryptedPrivateKey,
|
||||||
|
iv: encKeys.encryptedPrivateKeyIV,
|
||||||
|
tag: encKeys.encryptedPrivateKeyTag,
|
||||||
|
salt: encKeys.salt,
|
||||||
|
verifier: encKeys.verifier
|
||||||
|
});
|
||||||
|
|
||||||
|
const createMembershipData = {
|
||||||
|
orgId,
|
||||||
|
userId: user.id,
|
||||||
|
role: OrgMembershipRole.Admin,
|
||||||
|
status: OrgMembershipStatus.Accepted
|
||||||
|
};
|
||||||
|
|
||||||
|
console.log("createMembershipData", createMembershipData);
|
||||||
|
|
||||||
|
await orgDAL.createMembership(createMembershipData);
|
||||||
|
|
||||||
|
return {
|
||||||
|
user,
|
||||||
|
keys: encKeys
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Update organization details
|
* Update organization details
|
||||||
* */
|
* */
|
||||||
@@ -338,7 +383,8 @@ export const orgServiceFactory = ({
|
|||||||
{
|
{
|
||||||
email: inviteeEmail,
|
email: inviteeEmail,
|
||||||
isAccepted: false,
|
isAccepted: false,
|
||||||
authMethods: [AuthMethod.EMAIL]
|
authMethods: [AuthMethod.EMAIL],
|
||||||
|
ghost: false
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
@@ -491,6 +537,7 @@ export const orgServiceFactory = ({
|
|||||||
deleteOrganizationById,
|
deleteOrganizationById,
|
||||||
deleteOrgMembership,
|
deleteOrgMembership,
|
||||||
findAllWorkspaces,
|
findAllWorkspaces,
|
||||||
|
addGhostUser,
|
||||||
updateOrgMembership,
|
updateOrgMembership,
|
||||||
// incident contacts
|
// incident contacts
|
||||||
findIncidentContacts,
|
findIncidentContacts,
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { SecretEncryptionAlgo, SecretKeyEncoding } from "@app/db/schemas";
|
import { SecretEncryptionAlgo, SecretKeyEncoding } from "@app/db/schemas";
|
||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
@@ -6,17 +7,16 @@ import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services
|
|||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import {
|
import {
|
||||||
decryptAsymmetric,
|
decryptAsymmetric,
|
||||||
decryptSymmetric,
|
|
||||||
decryptSymmetric128BitHexKeyUTF8,
|
|
||||||
encryptSymmetric,
|
encryptSymmetric,
|
||||||
encryptSymmetric128BitHexKeyUTF8,
|
encryptSymmetric128BitHexKeyUTF8,
|
||||||
generateAsymmetricKeyPair
|
generateAsymmetricKeyPair
|
||||||
} from "@app/lib/crypto";
|
} from "@app/lib/crypto";
|
||||||
|
import { infisicalSymmetricDecrypt } from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { TProjectPermission } from "@app/lib/types";
|
import { TProjectPermission } from "@app/lib/types";
|
||||||
|
|
||||||
import { TProjectBotDALFactory } from "./project-bot-dal";
|
import { TProjectBotDALFactory } from "./project-bot-dal";
|
||||||
import { TSetActiveStateDTO } from "./project-bot-types";
|
import { TGetPrivateKeyDTO, TSetActiveStateDTO } from "./project-bot-types";
|
||||||
|
|
||||||
type TProjectBotServiceFactoryDep = {
|
type TProjectBotServiceFactoryDep = {
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getProjectPermission">;
|
||||||
@@ -26,48 +26,35 @@ type TProjectBotServiceFactoryDep = {
|
|||||||
export type TProjectBotServiceFactory = ReturnType<typeof projectBotServiceFactory>;
|
export type TProjectBotServiceFactory = ReturnType<typeof projectBotServiceFactory>;
|
||||||
|
|
||||||
export const projectBotServiceFactory = ({ projectBotDAL, permissionService }: TProjectBotServiceFactoryDep) => {
|
export const projectBotServiceFactory = ({ projectBotDAL, permissionService }: TProjectBotServiceFactoryDep) => {
|
||||||
const getBotKey = async (projectId: string) => {
|
const getBotPrivateKey = async ({ encoding, nonce, tag, encryptedPrivateKey }: TGetPrivateKeyDTO) =>
|
||||||
const appCfg = getConfig();
|
infisicalSymmetricDecrypt({
|
||||||
const encryptionKey = appCfg.ENCRYPTION_KEY;
|
keyEncoding: encoding,
|
||||||
const rootEncryptionKey = appCfg.ROOT_ENCRYPTION_KEY;
|
iv: nonce,
|
||||||
|
tag,
|
||||||
|
ciphertext: encryptedPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
|
const getBotKey = async (projectId: string) => {
|
||||||
const bot = await projectBotDAL.findOne({ projectId });
|
const bot = await projectBotDAL.findOne({ projectId });
|
||||||
if (!bot) throw new BadRequestError({ message: "failed to find bot key" });
|
if (!bot) throw new BadRequestError({ message: "failed to find bot key" });
|
||||||
if (!bot.isActive) throw new BadRequestError({ message: "Bot is not active" });
|
if (!bot.isActive) throw new BadRequestError({ message: "Bot is not active" });
|
||||||
if (!bot.encryptedProjectKeyNonce || !bot.encryptedProjectKey)
|
if (!bot.encryptedProjectKeyNonce || !bot.encryptedProjectKey)
|
||||||
throw new BadRequestError({ message: "Encryption key missing" });
|
throw new BadRequestError({ message: "Encryption key missing" });
|
||||||
|
|
||||||
if (rootEncryptionKey && (bot.keyEncoding as SecretKeyEncoding) === SecretKeyEncoding.BASE64) {
|
const privateKeyBot = await getBotPrivateKey({
|
||||||
const privateKeyBot = decryptSymmetric({
|
nonce: bot.iv,
|
||||||
iv: bot.iv,
|
tag: bot.tag,
|
||||||
tag: bot.tag,
|
encryptedPrivateKey: bot.encryptedPrivateKey,
|
||||||
ciphertext: bot.encryptedPrivateKey,
|
encoding: bot.keyEncoding as SecretKeyEncoding
|
||||||
key: rootEncryptionKey
|
});
|
||||||
});
|
|
||||||
return decryptAsymmetric({
|
|
||||||
ciphertext: bot.encryptedProjectKey,
|
|
||||||
privateKey: privateKeyBot,
|
|
||||||
nonce: bot.encryptedProjectKeyNonce,
|
|
||||||
publicKey: bot.sender.publicKey
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (encryptionKey && (bot.keyEncoding as SecretKeyEncoding) === SecretKeyEncoding.UTF8) {
|
|
||||||
const privateKeyBot = decryptSymmetric128BitHexKeyUTF8({
|
|
||||||
iv: bot.iv,
|
|
||||||
tag: bot.tag,
|
|
||||||
ciphertext: bot.encryptedPrivateKey,
|
|
||||||
key: encryptionKey
|
|
||||||
});
|
|
||||||
return decryptAsymmetric({
|
|
||||||
ciphertext: bot.encryptedProjectKey,
|
|
||||||
privateKey: privateKeyBot,
|
|
||||||
nonce: bot.encryptedProjectKeyNonce,
|
|
||||||
publicKey: bot.sender.publicKey
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
throw new BadRequestError({
|
console.log("privateKeyBot", privateKeyBot);
|
||||||
message: "Failed to obtain bot copy of workspace key needed for operation"
|
|
||||||
|
return decryptAsymmetric({
|
||||||
|
ciphertext: bot.encryptedProjectKey,
|
||||||
|
privateKey: privateKeyBot,
|
||||||
|
nonce: bot.encryptedProjectKeyNonce,
|
||||||
|
publicKey: bot.sender.publicKey
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -131,12 +118,16 @@ export const projectBotServiceFactory = ({ projectBotDAL, permissionService }: T
|
|||||||
if (!botKey?.nonce || !botKey?.encryptedKey) {
|
if (!botKey?.nonce || !botKey?.encryptedKey) {
|
||||||
throw new BadRequestError({ message: "Failed to set bot active - missing bot key" });
|
throw new BadRequestError({ message: "Failed to set bot active - missing bot key" });
|
||||||
}
|
}
|
||||||
const doc = await projectBotDAL.updateById(botId, {
|
const doc = await projectBotDAL.updateById(
|
||||||
isActive: true,
|
botId,
|
||||||
encryptedProjectKey: botKey.encryptedKey,
|
{
|
||||||
encryptedProjectKeyNonce: botKey.nonce,
|
isActive: true,
|
||||||
senderId: actorId
|
encryptedProjectKey: botKey.encryptedKey,
|
||||||
});
|
encryptedProjectKeyNonce: botKey.nonce,
|
||||||
|
senderId: actorId
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
if (!doc) throw new BadRequestError({ message: "Failed to update bot active state" });
|
if (!doc) throw new BadRequestError({ message: "Failed to update bot active state" });
|
||||||
return doc;
|
return doc;
|
||||||
}
|
}
|
||||||
@@ -153,6 +144,7 @@ export const projectBotServiceFactory = ({ projectBotDAL, permissionService }: T
|
|||||||
return {
|
return {
|
||||||
findBotByProjectId,
|
findBotByProjectId,
|
||||||
setBotActiveState,
|
setBotActiveState,
|
||||||
|
getBotPrivateKey,
|
||||||
getBotKey
|
getBotKey
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import { SecretKeyEncoding } from "@app/db/schemas";
|
||||||
import { TProjectPermission } from "@app/lib/types";
|
import { TProjectPermission } from "@app/lib/types";
|
||||||
|
|
||||||
export type TSetActiveStateDTO = {
|
export type TSetActiveStateDTO = {
|
||||||
@@ -8,3 +9,10 @@ export type TSetActiveStateDTO = {
|
|||||||
};
|
};
|
||||||
botId: string;
|
botId: string;
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
export type TGetPrivateKeyDTO = {
|
||||||
|
encoding: SecretKeyEncoding;
|
||||||
|
nonce: string;
|
||||||
|
tag: string;
|
||||||
|
encryptedPrivateKey: string;
|
||||||
|
};
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
import { ForbiddenError } from "@casl/ability";
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services/permission/project-permission";
|
||||||
@@ -43,7 +44,7 @@ export const projectKeyServiceFactory = ({
|
|||||||
name: "Upload project keys"
|
name: "Upload project keys"
|
||||||
});
|
});
|
||||||
|
|
||||||
await projectKeyDAL.create({ projectId, receiverId, encryptedKey, nonce, senderId: actorId });
|
await projectKeyDAL.create({ projectId, receiverId, encryptedKey, nonce, senderId: actorId }, tx);
|
||||||
};
|
};
|
||||||
|
|
||||||
const getLatestProjectKey = async ({ actorId, projectId, actor, actorOrgId }: TGetLatestProjectKeyDTO) => {
|
const getLatestProjectKey = async ({ actorId, projectId, actor, actorOrgId }: TGetLatestProjectKeyDTO) => {
|
||||||
|
|||||||
@@ -24,15 +24,16 @@ export const projectMembershipDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("projectId").withSchema(TableName.ProjectMembership),
|
db.ref("projectId").withSchema(TableName.ProjectMembership),
|
||||||
db.ref("role").withSchema(TableName.ProjectMembership),
|
db.ref("role").withSchema(TableName.ProjectMembership),
|
||||||
db.ref("roleId").withSchema(TableName.ProjectMembership),
|
db.ref("roleId").withSchema(TableName.ProjectMembership),
|
||||||
|
db.ref("ghost").withSchema(TableName.Users),
|
||||||
db.ref("email").withSchema(TableName.Users),
|
db.ref("email").withSchema(TableName.Users),
|
||||||
db.ref("publicKey").withSchema(TableName.UserEncryptionKey),
|
db.ref("publicKey").withSchema(TableName.UserEncryptionKey),
|
||||||
db.ref("firstName").withSchema(TableName.Users),
|
db.ref("firstName").withSchema(TableName.Users),
|
||||||
db.ref("lastName").withSchema(TableName.Users),
|
db.ref("lastName").withSchema(TableName.Users),
|
||||||
db.ref("id").withSchema(TableName.Users).as("userId")
|
db.ref("id").withSchema(TableName.Users).as("userId")
|
||||||
);
|
);
|
||||||
return members.map(({ email, firstName, lastName, publicKey, ...data }) => ({
|
return members.map(({ email, firstName, lastName, publicKey, ghost, ...data }) => ({
|
||||||
...data,
|
...data,
|
||||||
user: { email, firstName, lastName, id: data.userId, publicKey }
|
user: { email, firstName, lastName, id: data.userId, publicKey, ghost }
|
||||||
}));
|
}));
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new DatabaseError({ error, name: "Find all project members" });
|
throw new DatabaseError({ error, name: "Find all project members" });
|
||||||
|
|||||||
@@ -134,11 +134,16 @@ export const projectMembershipServiceFactory = ({
|
|||||||
|
|
||||||
await projectMembershipDAL.transaction(async (tx) => {
|
await projectMembershipDAL.transaction(async (tx) => {
|
||||||
await projectMembershipDAL.insertMany(
|
await projectMembershipDAL.insertMany(
|
||||||
orgMembers.map(({ userId }) => ({
|
orgMembers.map(({ userId, id: membershipId }) => {
|
||||||
projectId,
|
const role =
|
||||||
userId: userId as string,
|
members.find((i) => i.orgMembershipId === membershipId)?.projectRole || ProjectMembershipRole.Member;
|
||||||
role: ProjectMembershipRole.Member
|
|
||||||
})),
|
return {
|
||||||
|
projectId,
|
||||||
|
userId: userId as string,
|
||||||
|
role
|
||||||
|
};
|
||||||
|
}),
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
const encKeyGroupByOrgMembId = groupBy(members, (i) => i.orgMembershipId);
|
const encKeyGroupByOrgMembId = groupBy(members, (i) => i.orgMembershipId);
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import { ProjectMembershipRole } from "@app/db/schemas";
|
||||||
import { TProjectPermission } from "@app/lib/types";
|
import { TProjectPermission } from "@app/lib/types";
|
||||||
|
|
||||||
export type TGetProjectMembershipDTO = TProjectPermission;
|
export type TGetProjectMembershipDTO = TProjectPermission;
|
||||||
@@ -20,5 +21,6 @@ export type TAddUsersToWorkspaceDTO = {
|
|||||||
orgMembershipId: string;
|
orgMembershipId: string;
|
||||||
workspaceEncryptedKey: string;
|
workspaceEncryptedKey: string;
|
||||||
workspaceEncryptedNonce: string;
|
workspaceEncryptedNonce: string;
|
||||||
|
projectRole: ProjectMembershipRole;
|
||||||
}[];
|
}[];
|
||||||
} & TProjectPermission;
|
} & TProjectPermission;
|
||||||
|
|||||||
@@ -66,10 +66,15 @@ export const projectServiceFactory = ({
|
|||||||
|
|
||||||
const newProject = projectDAL.transaction(async (tx) => {
|
const newProject = projectDAL.transaction(async (tx) => {
|
||||||
const project = await projectDAL.create(
|
const project = await projectDAL.create(
|
||||||
{ name: workspaceName, orgId, slug: slugify(`${workspaceName}-${alphaNumericNanoId(4)}`) },
|
{
|
||||||
|
name: workspaceName,
|
||||||
|
orgId,
|
||||||
|
slug: slugify(`${workspaceName}-${alphaNumericNanoId(4)}`),
|
||||||
|
e2ee: false
|
||||||
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
// set user as admin member for proeject
|
// set user as admin member for project
|
||||||
await projectMembershipDAL.create(
|
await projectMembershipDAL.create(
|
||||||
{
|
{
|
||||||
userId: actorId,
|
userId: actorId,
|
||||||
@@ -78,6 +83,7 @@ export const projectServiceFactory = ({
|
|||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
|
|
||||||
// generate the blind index for project
|
// generate the blind index for project
|
||||||
await secretBlindIndexDAL.create(
|
await secretBlindIndexDAL.create(
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -13,12 +13,12 @@ nacl.util = require("tweetnacl-util");
|
|||||||
*/
|
*/
|
||||||
const generateKeyPair = () => {
|
const generateKeyPair = () => {
|
||||||
const pair = nacl.box.keyPair();
|
const pair = nacl.box.keyPair();
|
||||||
|
|
||||||
return ({
|
return {
|
||||||
publicKey: nacl.util.encodeBase64(pair.publicKey),
|
publicKey: nacl.util.encodeBase64(pair.publicKey),
|
||||||
privateKey: nacl.util.encodeBase64(pair.secretKey)
|
privateKey: nacl.util.encodeBase64(pair.secretKey)
|
||||||
});
|
};
|
||||||
}
|
};
|
||||||
|
|
||||||
type EncryptAsymmetricProps = {
|
type EncryptAsymmetricProps = {
|
||||||
plaintext: string;
|
plaintext: string;
|
||||||
@@ -29,27 +29,19 @@ type EncryptAsymmetricProps = {
|
|||||||
/**
|
/**
|
||||||
* Verify that private key [privateKey] is the one that corresponds to
|
* Verify that private key [privateKey] is the one that corresponds to
|
||||||
* the public key [publicKey]
|
* the public key [publicKey]
|
||||||
* @param {Object}
|
* @param {Object}
|
||||||
* @param {String} - base64-encoded Nacl private key
|
* @param {String} - base64-encoded Nacl private key
|
||||||
* @param {String} - base64-encoded Nacl public key
|
* @param {String} - base64-encoded Nacl public key
|
||||||
*/
|
*/
|
||||||
const verifyPrivateKey = ({
|
const verifyPrivateKey = ({ privateKey, publicKey }: { privateKey: string; publicKey: string }) => {
|
||||||
privateKey,
|
|
||||||
publicKey
|
|
||||||
}: {
|
|
||||||
privateKey: string;
|
|
||||||
publicKey: string;
|
|
||||||
}) => {
|
|
||||||
const derivedPublicKey = nacl.util.encodeBase64(
|
const derivedPublicKey = nacl.util.encodeBase64(
|
||||||
nacl.box.keyPair.fromSecretKey(
|
nacl.box.keyPair.fromSecretKey(nacl.util.decodeBase64(privateKey)).publicKey
|
||||||
nacl.util.decodeBase64(privateKey)
|
|
||||||
).publicKey
|
|
||||||
);
|
);
|
||||||
|
|
||||||
if (derivedPublicKey !== publicKey) {
|
if (derivedPublicKey !== publicKey) {
|
||||||
throw new Error("Failed to verify private key");
|
throw new Error("Failed to verify private key");
|
||||||
}
|
}
|
||||||
}
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Derive a key from password [password] and salt [salt] using Argon2id
|
* Derive a key from password [password] and salt [salt] using Argon2id
|
||||||
@@ -229,7 +221,8 @@ export {
|
|||||||
decryptAssymmetric,
|
decryptAssymmetric,
|
||||||
decryptSymmetric,
|
decryptSymmetric,
|
||||||
deriveArgonKey,
|
deriveArgonKey,
|
||||||
encryptAssymmetric,
|
encryptAssymmetric,
|
||||||
encryptSymmetric,
|
encryptSymmetric,
|
||||||
generateKeyPair,
|
generateKeyPair,
|
||||||
verifyPrivateKey};
|
verifyPrivateKey
|
||||||
|
};
|
||||||
|
|||||||
@@ -158,19 +158,21 @@ export const useGetWorkspaceIntegrations = (workspaceId: string) =>
|
|||||||
|
|
||||||
export const createWorkspace = ({
|
export const createWorkspace = ({
|
||||||
organizationId,
|
organizationId,
|
||||||
workspaceName
|
projectName,
|
||||||
|
inviteAllOrgMembers
|
||||||
}: CreateWorkspaceDTO): Promise<{ data: { workspace: Workspace } }> => {
|
}: CreateWorkspaceDTO): Promise<{ data: { workspace: Workspace } }> => {
|
||||||
return apiRequest.post("/api/v1/workspace", { workspaceName, organizationId });
|
return apiRequest.post("/api/v3/projects", { projectName, inviteAllOrgMembers, organizationId });
|
||||||
};
|
};
|
||||||
|
|
||||||
export const useCreateWorkspace = () => {
|
export const useCreateWorkspace = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation<{ data: { workspace: Workspace } }, {}, CreateWorkspaceDTO>({
|
return useMutation<{ data: { workspace: Workspace } }, {}, CreateWorkspaceDTO>({
|
||||||
mutationFn: async ({ organizationId, workspaceName }) =>
|
mutationFn: async ({ organizationId, projectName, inviteAllOrgMembers }) =>
|
||||||
createWorkspace({
|
createWorkspace({
|
||||||
organizationId,
|
organizationId,
|
||||||
workspaceName
|
projectName,
|
||||||
|
inviteAllOrgMembers
|
||||||
}),
|
}),
|
||||||
onSuccess: () => {
|
onSuccess: () => {
|
||||||
queryClient.invalidateQueries(workspaceKeys.getAllUserWorkspace);
|
queryClient.invalidateQueries(workspaceKeys.getAllUserWorkspace);
|
||||||
|
|||||||
@@ -25,7 +25,8 @@ export type NameWorkspaceSecretsDTO = {
|
|||||||
|
|
||||||
// mutation dto
|
// mutation dto
|
||||||
export type CreateWorkspaceDTO = {
|
export type CreateWorkspaceDTO = {
|
||||||
workspaceName: string;
|
projectName: string;
|
||||||
|
inviteAllOrgMembers: boolean;
|
||||||
organizationId: string;
|
organizationId: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,5 @@
|
|||||||
// REFACTOR(akhilmhdh): This file needs to be split into multiple components too complex
|
// REFACTOR(akhilmhdh): This file needs to be split into multiple components too complex
|
||||||
|
|
||||||
import crypto from "crypto";
|
|
||||||
|
|
||||||
import { useEffect, useState } from "react";
|
import { useEffect, useState } from "react";
|
||||||
import { Controller, useForm } from "react-hook-form";
|
import { Controller, useForm } from "react-hook-form";
|
||||||
import { useTranslation } from "react-i18next";
|
import { useTranslation } from "react-i18next";
|
||||||
@@ -23,7 +21,7 @@ import {
|
|||||||
faNetworkWired,
|
faNetworkWired,
|
||||||
faPlug,
|
faPlug,
|
||||||
faPlus,
|
faPlus,
|
||||||
faUserPlus,
|
faUserPlus
|
||||||
} from "@fortawesome/free-solid-svg-icons";
|
} from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
import { yupResolver } from "@hookform/resolvers/yup";
|
import { yupResolver } from "@hookform/resolvers/yup";
|
||||||
@@ -33,7 +31,6 @@ import * as yup from "yup";
|
|||||||
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
import { useNotificationContext } from "@app/components/context/Notifications/NotificationProvider";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import onboardingCheck from "@app/components/utilities/checks/OnboardingCheck";
|
import onboardingCheck from "@app/components/utilities/checks/OnboardingCheck";
|
||||||
import { encryptAssymmetric } from "@app/components/utilities/cryptography/crypto";
|
|
||||||
import {
|
import {
|
||||||
Button,
|
Button,
|
||||||
Checkbox,
|
Checkbox,
|
||||||
@@ -53,13 +50,12 @@ import {
|
|||||||
} from "@app/context";
|
} from "@app/context";
|
||||||
import { withPermission } from "@app/hoc";
|
import { withPermission } from "@app/hoc";
|
||||||
import {
|
import {
|
||||||
fetchOrgUsers,
|
// fetchOrgUsers,
|
||||||
useAddUserToWs,
|
// useAddUserToWs,
|
||||||
useCreateWorkspace,
|
useCreateWorkspace,
|
||||||
useRegisterUserAction,
|
useRegisterUserAction,
|
||||||
useUploadWsKey
|
|
||||||
} from "@app/hooks/api";
|
} from "@app/hooks/api";
|
||||||
import { fetchUserWsKey } from "@app/hooks/api/keys/queries";
|
// import { fetchUserWsKey } from "@app/hooks/api/keys/queries";
|
||||||
import { useFetchServerStatus } from "@app/hooks/api/serverDetails";
|
import { useFetchServerStatus } from "@app/hooks/api/serverDetails";
|
||||||
import { usePopUp } from "@app/hooks/usePopUp";
|
import { usePopUp } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
@@ -475,7 +471,7 @@ const OrganizationPage = withPermission(
|
|||||||
const currentOrg = String(router.query.id);
|
const currentOrg = String(router.query.id);
|
||||||
const orgWorkspaces = workspaces?.filter((workspace) => workspace.orgId === currentOrg) || [];
|
const orgWorkspaces = workspaces?.filter((workspace) => workspace.orgId === currentOrg) || [];
|
||||||
const { createNotification } = useNotificationContext();
|
const { createNotification } = useNotificationContext();
|
||||||
const addWsUser = useAddUserToWs();
|
// const addWsUser = useAddUserToWs();
|
||||||
|
|
||||||
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
||||||
"addNewWs",
|
"addNewWs",
|
||||||
@@ -497,7 +493,6 @@ const OrganizationPage = withPermission(
|
|||||||
const [searchFilter, setSearchFilter] = useState("");
|
const [searchFilter, setSearchFilter] = useState("");
|
||||||
const createWs = useCreateWorkspace();
|
const createWs = useCreateWorkspace();
|
||||||
const { user } = useUser();
|
const { user } = useUser();
|
||||||
const uploadWsKey = useUploadWsKey();
|
|
||||||
const { data: serverDetails } = useFetchServerStatus();
|
const { data: serverDetails } = useFetchServerStatus();
|
||||||
|
|
||||||
const onCreateProject = async ({ name, addMembers }: TAddProjectFormData) => {
|
const onCreateProject = async ({ name, addMembers }: TAddProjectFormData) => {
|
||||||
@@ -510,45 +505,31 @@ const OrganizationPage = withPermission(
|
|||||||
}
|
}
|
||||||
} = await createWs.mutateAsync({
|
} = await createWs.mutateAsync({
|
||||||
organizationId: currentOrg,
|
organizationId: currentOrg,
|
||||||
workspaceName: name
|
inviteAllOrgMembers: addMembers,
|
||||||
});
|
projectName: name
|
||||||
|
|
||||||
const randomBytes = crypto.randomBytes(16).toString("hex");
|
|
||||||
const PRIVATE_KEY = String(localStorage.getItem("PRIVATE_KEY"));
|
|
||||||
const { ciphertext, nonce } = encryptAssymmetric({
|
|
||||||
plaintext: randomBytes,
|
|
||||||
publicKey: user.publicKey,
|
|
||||||
privateKey: PRIVATE_KEY
|
|
||||||
});
|
|
||||||
|
|
||||||
await uploadWsKey.mutateAsync({
|
|
||||||
encryptedKey: ciphertext,
|
|
||||||
nonce,
|
|
||||||
userId: user?.id,
|
|
||||||
workspaceId: newWorkspaceId
|
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/*
|
||||||
if (addMembers) {
|
if (addMembers) {
|
||||||
// not using hooks because need at this point only
|
// not using hooks because need at this point only
|
||||||
const orgUsers = await fetchOrgUsers(currentOrg);
|
const orgUsers = await fetchOrgUsers(currentOrg);
|
||||||
const decryptKey = await fetchUserWsKey(newWorkspaceId);
|
const decryptKey = await fetchUserWsKey(newWorkspaceId);
|
||||||
const members = orgUsers
|
|
||||||
.filter(
|
await addWsUser.mutateAsync({
|
||||||
({ status, user: orgUser }) => status === "accepted" && user.email !== orgUser.email
|
workspaceId: newWorkspaceId,
|
||||||
)
|
decryptKey,
|
||||||
.map(({ user: orgUser, id: orgMembershipId }) => ({
|
userPrivateKey: PRIVATE_KEY,
|
||||||
userPublicKey: orgUser.publicKey,
|
members: orgUsers
|
||||||
orgMembershipId
|
.filter(
|
||||||
}));
|
({ status, user: orgUser }) => status === "accepted" && user.email !== orgUser.email
|
||||||
if (members.length) {
|
)
|
||||||
await addWsUser.mutateAsync({
|
.map(({ user: orgUser, id: orgMembershipId }) => ({
|
||||||
workspaceId: newWorkspaceId,
|
userPublicKey: orgUser.publicKey,
|
||||||
decryptKey,
|
orgMembershipId
|
||||||
userPrivateKey: PRIVATE_KEY,
|
}))
|
||||||
members
|
});
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
*/
|
||||||
createNotification({ text: "Workspace created", type: "success" });
|
createNotification({ text: "Workspace created", type: "success" });
|
||||||
handlePopUpClose("addNewWs");
|
handlePopUpClose("addNewWs");
|
||||||
router.push(`/project/${newWorkspaceId}/secrets/overview`);
|
router.push(`/project/${newWorkspaceId}/secrets/overview`);
|
||||||
@@ -735,7 +716,7 @@ const OrganizationPage = withPermission(
|
|||||||
new Date().getTime() - new Date(user?.createdAt).getTime() <
|
new Date().getTime() - new Date(user?.createdAt).getTime() <
|
||||||
30 * 24 * 60 * 60 * 1000
|
30 * 24 * 60 * 60 * 1000
|
||||||
) && (
|
) && (
|
||||||
<div className="mb-4 flex flex-col items-start justify-start px-6 pb-6 pb-0 text-3xl">
|
<div className="mb-4 flex flex-col items-start justify-start px-6 pb-0 text-3xl">
|
||||||
<p className="mr-4 mb-4 font-semibold text-white">Onboarding Guide</p>
|
<p className="mr-4 mb-4 font-semibold text-white">Onboarding Guide</p>
|
||||||
<div className="mb-3 grid w-full grid-cols-1 gap-3 lg:grid-cols-2 xl:grid-cols-3 2xl:grid-cols-4">
|
<div className="mb-3 grid w-full grid-cols-1 gap-3 lg:grid-cols-2 xl:grid-cols-3 2xl:grid-cols-4">
|
||||||
<LearningItemSquare
|
<LearningItemSquare
|
||||||
|
|||||||
Reference in New Issue
Block a user