Commit Graph

17222 Commits

Author SHA1 Message Date
Victor Hugo dos Santos
33b12ad417 Merge pull request #4989 from Infisical/feature/aws-iam-pam
feature(pam): add support to AWS IAM PAM
2025-12-08 14:52:55 -03:00
Victor Santos
2e4a1acd03 fix: enhance error messaging and improve resource selection in PAM components
- Updated error message in AWS IAM resource factory to include the PAM role ARN for better debugging.
- Added functionality to clear the search input when a value is selected in the ResourceSelect component, improving user experience.
- Refactored AwsIamAccountForm to fetch PAM resource details based on account or provided resourceId and resourceType, ensuring accurate role ARN usage in trust policy.
2025-12-08 14:28:05 -03:00
Victor Santos
d09849d9dc refactor: update PAM session status handling and improve enum definitions
- Changed PAM session status from 'Expired' to 'Ended' in the database update logic and service layer for clarity.
- Updated the PamSessionStatus enum to consolidate the definitions of 'Ended' and 'Expired', reflecting that 'Ended' can result from both user action and automatic expiration.
- Removed references to 'Expired' in the frontend components and adjusted related UI elements for consistency.
2025-12-08 12:19:19 -03:00
varonix
a6631217f1 Merge pull request #4990 from Infisical/fix-additional-privilege-old-projects
fix(additional-privileges): return correct project membership ID
2025-12-08 03:25:01 -05:00
Victor Santos
a0718321e7 fix: improve error handling in AWS IAM role assumption methods
- Added try-catch blocks to handle errors during role assumption in both assumePamRole and assumeTargetRole functions.
- Enhanced error messages to include specific details about the failure, improving debugging and user feedback.
- Updated console URL generation to directly use the SigninToken from the token response, ensuring correct URL formation.
2025-12-07 20:48:15 -03:00
Victor Santos
3e77c33532 feat: enhance AWS IAM resource handling with new gateway access schema and improved project ID management
- Introduced GatewayAccessResponseSchema for consistent response structures across Postgres, MySQL, and SSH resources.
- Updated PAM account router to utilize the new schema, streamlining response validation.
- Refactored AWS IAM service to improve project ID handling during role assumption and credential management.
- Enhanced AWS IAM resource schemas to support gateway-specific configurations, improving flexibility and type safety.
2025-12-07 20:32:59 -03:00
Daniel Hougaard
20570094be Update types.tsx 2025-12-06 09:39:46 -05:00
Daniel Hougaard
0f3108f6fb fix: removed projectMembershipId entirely 2025-12-06 09:37:25 -05:00
Victor Santos
69fd05bc1e style: enhance UI elements in AWS IAM forms with transition effects
- Updated the target role and AWS IAM role setup sections to include a transition effect on hover, improving user experience and visual feedback.
- Ensured consistency in styling across both AWS IAM account and resource forms.
2025-12-05 17:43:01 -03:00
Victor Santos
c5169217a4 refactor: streamline account path handling in PAM components
- Updated PamAccessAccountModal and PamAccountsTable to simplify account path construction by removing leading and trailing slashes.
- Enhanced readability and consistency in path handling across components.
2025-12-05 17:09:59 -03:00
Victor Santos
6db5188b36 feat: update AWS IAM session duration handling and improve account access functionality
- Changed session duration parameter from maxSessionDuration to defaultSessionDuration for consistency.
- Refactored AWS STS client creation to use a hardcoded default region, simplifying the configuration.
- Enhanced PAM account access modal to include account path and project ID in the access request.
- Updated various components and schemas to reflect the new session duration naming and improve type safety.
2025-12-05 16:56:55 -03:00
Piyush Gupta
1269e7c245 Merge pull request #4976 from Infisical/chore/external-kms-api-refactor
chore: external-kms API refactor
2025-12-06 01:23:05 +05:30
Piyush Gupta
32ecbd2d6d fix: edge cases 2025-12-05 23:46:37 +05:30
carlosmonastyrski
bf93644ce0 Merge pull request #4992 from Infisical/fix/pki-renewals
fix: renewals for internal CAs and minor improvement on the export certificate modal
2025-12-05 15:03:24 -03:00
Carlos Monastyrski
9e1a3c6fe0 Improve pkcs12 error message 2025-12-05 14:55:55 -03:00
Piyush Gupta
1f0daf447e fix: review changes 2025-12-05 22:17:42 +05:30
Victor Santos
feb1d9b854 Merge branch 'main' into feature/aws-iam-pam 2025-12-05 13:29:30 -03:00
Carlos Monastyrski
d8feb988ea Remove redundant null check 2025-12-05 13:06:56 -03:00
Carlos Monastyrski
c81116ff60 Fix renewal issue for internal CAs and improve export certificate modal 2025-12-05 12:48:25 -03:00
Piyush Gupta
3f70897593 Merge pull request #4970 from Infisical/chore/pam-access-account-with-path
chore: updates pam access account endpoint to use account path instead of id [PAM-64]
2025-12-05 20:03:33 +05:30
Piyush Gupta
fd1a3d5d12 fix: review changes 2025-12-05 19:39:21 +05:30
Piyush Gupta
58fbbe0d91 Merge branch 'main' of https://github.com/Infisical/infisical into chore/external-kms-api-refactor 2025-12-05 18:01:43 +05:30
Daniel Hougaard
b3f2fb1399 added missed endpoint 2025-12-04 23:02:29 -08:00
Victor Santos
b2e4c1e6bf feat: update PAM account types and endpoint handling for optional rotation settings
- Made the rotationEnabled field optional in the account schema to enhance flexibility.
- Updated endpoint logic to default rotationEnabled to false if not provided in the request.
- Adjusted account DTOs to reflect the optional nature of rotationEnabled, improving type safety.
2025-12-05 01:44:33 -03:00
Daniel Hougaard
cc9cee3953 fix(additional-privileges): return correct project membership ID 2025-12-04 20:43:30 -08:00
Victor Santos
a755b5bfa0 feat: improve PAM account update handling with enhanced error management
- Added try-catch block to handle potential database errors during account updates.
- Implemented specific error handling for unique constraint violations, providing clearer feedback for duplicate account names.
- Updated AWS IAM account schema to indicate that credential rotation is not supported, defaulting to false.
2025-12-05 01:14:28 -03:00
Victor Santos
ac5c185f76 feat: enhance PAM account handling with type safety and improved response structure
- Introduced type inference for sanitized accounts to ensure consistent data handling.
- Updated account response structure to explicitly cast accounts to the sanitized type.
- Refined the decryption function to omit sensitive fields from the returned account object.
- Improved error handling in SQL resource factory by enforcing required gateway ID validation.
2025-12-05 00:56:33 -03:00
Victor Santos
aac84e3952 feat: enhance AWS IAM resource support with refined validation and response structure
- Updated AWS IAM resource response schema to include distinct object structures for Postgres, MySQL, and SSH resource types.
- Improved validation for project ID to ensure it is a valid UUID.
- Adjusted console URL expiration handling to default to a calculated date if not provided.
- Modified regex for ARN role validation to accommodate additional characters.
2025-12-04 23:54:24 -03:00
Victor Santos
b589ab3be4 feat: add AWS IAM resource support with console access functionality
- Introduced AWS IAM resource type in the system, allowing users to create and manage AWS IAM accounts.
- Implemented AWS IAM resource forms and account forms for creating and updating IAM resources and accounts.
- Added functionality to generate AWS Console URLs for IAM accounts, enabling direct access to the AWS Console.
- Updated various components and hooks to handle AWS IAM-specific logic, including session expiration and access management.
- Enhanced the UI to reflect AWS IAM integration, including new modals and forms for user interaction.
2025-12-04 23:41:36 -03:00
carlosmonastyrski
4a62a872eb Merge pull request #4980 from Infisical/feat/PKI-67
feature: refine PKI access control permissions
2025-12-04 23:21:07 -03:00
Carlos Monastyrski
e870b449d6 Skip private key on response if user do not have access to read 2025-12-04 21:13:43 -03:00
Carlos Monastyrski
90c73def68 UI improvements on PKI product 2025-12-04 18:55:26 -03:00
Piyush Gupta
f14b03b6ac fix: kms endpoints to rerutn credentialsHash 2025-12-05 02:49:20 +05:30
Scott Wilson
c9a2a9d8f8 Merge pull request #4987 from Infisical/fix-change-org-query-removal
fix(frontend): correct query removal call sequence in when changing organization
2025-12-04 09:23:25 -08:00
Carlos Monastyrski
003aa1cd59 Remove duplicate read permission on default roles 2025-12-04 14:18:10 -03:00
Scott Wilson
462968780d fix: correct query removal call sequence in when changing organization 2025-12-04 09:13:40 -08:00
Carlos Monastyrski
2b038575ad Remove unused ca.id on CertificateAuthorities permission 2025-12-04 12:17:59 -03:00
Carlos Monastyrski
3f73f7cb05 Fix unit test 2025-12-04 10:53:39 -03:00
Carlos Monastyrski
022c2a860e Improve list endpoints permissions check and address PR comments 2025-12-04 04:58:32 -03:00
Victor Hugo dos Santos
a287f1f95e Merge pull request #4983 from Infisical/fix/fetch-native-integrations-only-if-secret-manager
improvement(integrations): adjust integration fetching in PolicySelectionModal and RolePermissionsSection based on project type
2025-12-03 19:14:00 -03:00
Scott Wilson
6430f7e459 Merge pull request #4986 from Infisical/improvement-unknown-user-tooltip
improvement(frontend): add tooltip explaining unknown user actor in audit logs
2025-12-03 13:58:35 -08:00
Scott Wilson
72799f6b00 improvement: address feedback 2025-12-03 13:42:52 -08:00
Scott Wilson
0e5cadd997 improvement: add tooltip explaining unknown user actor in audit logs 2025-12-03 13:32:19 -08:00
Piyush Gupta
bd149940a5 fix: provider error in external kms 2025-12-04 02:40:36 +05:30
Piyush Gupta
fef8d53428 fix: error -> BadRequestError 2025-12-04 02:21:32 +05:30
Piyush Gupta
313fc3f761 fix: provider -> configuration 2025-12-04 02:16:58 +05:30
Akhil Mohan
27af9b935b Merge pull request #4985 from Infisical/fix/scim-range-error
fix(ui): resolves range error that happaned when providing a large ttl for scim token
2025-12-04 02:10:40 +05:30
Akhil Mohan
7ffb416900 Merge pull request #4984 from Infisical/fix/audit-log-identity-change
fix(api): resolved identity name missing in audit log
2025-12-04 02:06:00 +05:30
Piyush Gupta
23e22eae95 Merge branch 'main' of https://github.com/Infisical/infisical into chore/external-kms-api-refactor 2025-12-04 01:27:37 +05:30
=
02b29b5ae0 fix(ui): resolves range error that happaned when providing a large ttl in scim 2025-12-04 01:18:24 +05:30