Commit Graph

17197 Commits

Author SHA1 Message Date
Victor Santos
3e77c33532 feat: enhance AWS IAM resource handling with new gateway access schema and improved project ID management
- Introduced GatewayAccessResponseSchema for consistent response structures across Postgres, MySQL, and SSH resources.
- Updated PAM account router to utilize the new schema, streamlining response validation.
- Refactored AWS IAM service to improve project ID handling during role assumption and credential management.
- Enhanced AWS IAM resource schemas to support gateway-specific configurations, improving flexibility and type safety.
2025-12-07 20:32:59 -03:00
Victor Santos
69fd05bc1e style: enhance UI elements in AWS IAM forms with transition effects
- Updated the target role and AWS IAM role setup sections to include a transition effect on hover, improving user experience and visual feedback.
- Ensured consistency in styling across both AWS IAM account and resource forms.
2025-12-05 17:43:01 -03:00
Victor Santos
c5169217a4 refactor: streamline account path handling in PAM components
- Updated PamAccessAccountModal and PamAccountsTable to simplify account path construction by removing leading and trailing slashes.
- Enhanced readability and consistency in path handling across components.
2025-12-05 17:09:59 -03:00
Victor Santos
6db5188b36 feat: update AWS IAM session duration handling and improve account access functionality
- Changed session duration parameter from maxSessionDuration to defaultSessionDuration for consistency.
- Refactored AWS STS client creation to use a hardcoded default region, simplifying the configuration.
- Enhanced PAM account access modal to include account path and project ID in the access request.
- Updated various components and schemas to reflect the new session duration naming and improve type safety.
2025-12-05 16:56:55 -03:00
Victor Santos
feb1d9b854 Merge branch 'main' into feature/aws-iam-pam 2025-12-05 13:29:30 -03:00
Piyush Gupta
3f70897593 Merge pull request #4970 from Infisical/chore/pam-access-account-with-path
chore: updates pam access account endpoint to use account path instead of id [PAM-64]
2025-12-05 20:03:33 +05:30
Victor Santos
b2e4c1e6bf feat: update PAM account types and endpoint handling for optional rotation settings
- Made the rotationEnabled field optional in the account schema to enhance flexibility.
- Updated endpoint logic to default rotationEnabled to false if not provided in the request.
- Adjusted account DTOs to reflect the optional nature of rotationEnabled, improving type safety.
2025-12-05 01:44:33 -03:00
Victor Santos
a755b5bfa0 feat: improve PAM account update handling with enhanced error management
- Added try-catch block to handle potential database errors during account updates.
- Implemented specific error handling for unique constraint violations, providing clearer feedback for duplicate account names.
- Updated AWS IAM account schema to indicate that credential rotation is not supported, defaulting to false.
2025-12-05 01:14:28 -03:00
Victor Santos
ac5c185f76 feat: enhance PAM account handling with type safety and improved response structure
- Introduced type inference for sanitized accounts to ensure consistent data handling.
- Updated account response structure to explicitly cast accounts to the sanitized type.
- Refined the decryption function to omit sensitive fields from the returned account object.
- Improved error handling in SQL resource factory by enforcing required gateway ID validation.
2025-12-05 00:56:33 -03:00
Victor Santos
aac84e3952 feat: enhance AWS IAM resource support with refined validation and response structure
- Updated AWS IAM resource response schema to include distinct object structures for Postgres, MySQL, and SSH resource types.
- Improved validation for project ID to ensure it is a valid UUID.
- Adjusted console URL expiration handling to default to a calculated date if not provided.
- Modified regex for ARN role validation to accommodate additional characters.
2025-12-04 23:54:24 -03:00
Victor Santos
b589ab3be4 feat: add AWS IAM resource support with console access functionality
- Introduced AWS IAM resource type in the system, allowing users to create and manage AWS IAM accounts.
- Implemented AWS IAM resource forms and account forms for creating and updating IAM resources and accounts.
- Added functionality to generate AWS Console URLs for IAM accounts, enabling direct access to the AWS Console.
- Updated various components and hooks to handle AWS IAM-specific logic, including session expiration and access management.
- Enhanced the UI to reflect AWS IAM integration, including new modals and forms for user interaction.
2025-12-04 23:41:36 -03:00
carlosmonastyrski
4a62a872eb Merge pull request #4980 from Infisical/feat/PKI-67
feature: refine PKI access control permissions
2025-12-04 23:21:07 -03:00
Carlos Monastyrski
e870b449d6 Skip private key on response if user do not have access to read 2025-12-04 21:13:43 -03:00
Carlos Monastyrski
90c73def68 UI improvements on PKI product 2025-12-04 18:55:26 -03:00
Scott Wilson
c9a2a9d8f8 Merge pull request #4987 from Infisical/fix-change-org-query-removal
fix(frontend): correct query removal call sequence in when changing organization
2025-12-04 09:23:25 -08:00
Carlos Monastyrski
003aa1cd59 Remove duplicate read permission on default roles 2025-12-04 14:18:10 -03:00
Scott Wilson
462968780d fix: correct query removal call sequence in when changing organization 2025-12-04 09:13:40 -08:00
Carlos Monastyrski
2b038575ad Remove unused ca.id on CertificateAuthorities permission 2025-12-04 12:17:59 -03:00
Carlos Monastyrski
3f73f7cb05 Fix unit test 2025-12-04 10:53:39 -03:00
Carlos Monastyrski
022c2a860e Improve list endpoints permissions check and address PR comments 2025-12-04 04:58:32 -03:00
Victor Hugo dos Santos
a287f1f95e Merge pull request #4983 from Infisical/fix/fetch-native-integrations-only-if-secret-manager
improvement(integrations): adjust integration fetching in PolicySelectionModal and RolePermissionsSection based on project type
2025-12-03 19:14:00 -03:00
Scott Wilson
6430f7e459 Merge pull request #4986 from Infisical/improvement-unknown-user-tooltip
improvement(frontend): add tooltip explaining unknown user actor in audit logs
2025-12-03 13:58:35 -08:00
Scott Wilson
72799f6b00 improvement: address feedback 2025-12-03 13:42:52 -08:00
Scott Wilson
0e5cadd997 improvement: add tooltip explaining unknown user actor in audit logs 2025-12-03 13:32:19 -08:00
Akhil Mohan
27af9b935b Merge pull request #4985 from Infisical/fix/scim-range-error
fix(ui): resolves range error that happaned when providing a large ttl for scim token
2025-12-04 02:10:40 +05:30
Akhil Mohan
7ffb416900 Merge pull request #4984 from Infisical/fix/audit-log-identity-change
fix(api): resolved identity name missing in audit log
2025-12-04 02:06:00 +05:30
=
02b29b5ae0 fix(ui): resolves range error that happaned when providing a large ttl in scim 2025-12-04 01:18:24 +05:30
=
41aa7f85f5 fix(api): resolved identity name missing in audit log 2025-12-04 01:04:12 +05:30
Victor Santos
8f3e5a8362 refactor: Consolidate project ID retrieval in PolicySelectionModal and RolePermissionsSection for improved clarity and consistency 2025-12-03 16:25:27 -03:00
Victor Santos
935d400a97 Enhancement(api): Update useGetWorkspaceIntegrations to accept options for enabled state and refetch interval; adjust integration fetching in PolicySelectionModal and RolePermissionsSection based on project type. 2025-12-03 16:21:13 -03:00
Fang-Pen Lin
aa9c125124 Merge pull request #4967 from Infisical/PKI-49-check-template-for-external-ca-with-acme
improvement(api): check template for external ca with acme
2025-12-03 10:56:31 -08:00
Carlos Monastyrski
b53348a684 Address greptile comments 2025-12-03 11:05:27 -03:00
Piyush Gupta
aff783a9b3 Merge pull request #4966 from Infisical/fix/get-token-auth-token-endpoint
fix: get token auth token endpoint [ENG-4248]
2025-12-03 11:41:18 +05:30
Fang-Pen Lin
d7e9f93165 Fix rebase syntax error 2025-12-02 20:10:55 -08:00
Fang-Pen Lin
5a70d96464 More test cases 2025-12-02 20:10:54 -08:00
Fang-Pen Lin
ad4dbcb1ed Fix test cases 2025-12-02 20:10:53 -08:00
Fang-Pen Lin
acefc75a35 Also check algorithm 2025-12-02 20:10:52 -08:00
Fang-Pen Lin
222707a5e3 Add tons of test cases 2025-12-02 20:10:51 -08:00
Fang-Pen Lin
eb43a88fb9 Names 2025-12-02 20:10:50 -08:00
Fang-Pen Lin
f837f75d5e Add tests for external CA template check with dns names 2025-12-02 20:10:49 -08:00
Fang-Pen Lin
11ccfb6da2 Implement template check for external ca
# Conflicts:
#	backend/src/ee/services/pki-acme/pki-acme-service.ts
#	backend/src/server/routes/index.ts
2025-12-02 20:10:48 -08:00
Carlos Monastyrski
1458fddc15 Lint fix 2025-12-03 00:26:05 -03:00
Carlos Monastyrski
f55f03cfb1 Merge remote-tracking branch 'origin/main' into feat/PKI-67 2025-12-03 00:17:29 -03:00
Carlos Monastyrski
71a76bc941 PKI refine access control 2025-12-03 00:05:18 -03:00
Maidul Islam
4ec0a92888 add gamma clodufront url to csp 2025-12-02 18:56:17 -08:00
Maidul Islam
0862869268 add gamma cloudfront address 2025-12-02 18:41:44 -08:00
Maidul Islam
0a162e768c add gamma assets cloudfront to CSP 2025-12-02 18:10:55 -08:00
varonix
4f78315b8b Merge pull request #4978 from Infisical/fix-duplicate-admin-role 2025-12-02 17:18:11 -08:00
Daniel Hougaard
e93a7e2c09 fix: duplicate admin role 2025-12-02 16:12:19 -08:00
Maidul Islam
ca64644ab2 Merge pull request #4977 from Infisical/feature/export-assets-command-and-cdn-docs
feature(cdn): add export-assets script and CDN documentation
2025-12-02 16:01:44 -08:00