mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 03:28:58 +00:00
Added: - New error types such as `IntegrationNotFoundError`, `WorkspaceNotFoundError`, `AccountNotFoundError' and more. Refactored: - Refactored most of the middlewares and very little number of helper functions to use RequestError - Deleted unused imports Changed: - Some of the error types in middlewares changed to more related error types. - Environment variable of 'VERBOSE_ERROR_OUTPUT' changed to more reliable validation method in `config/index.ts` as per @dangtony98 requested.
45 lines
1.2 KiB
TypeScript
45 lines
1.2 KiB
TypeScript
import { Request, Response, NextFunction } from 'express';
|
|
import { validateMembership } from '../helpers/membership';
|
|
import { UnauthorizedRequestError } from '../utils/errors';
|
|
|
|
type req = 'params' | 'body' | 'query';
|
|
|
|
/**
|
|
* Validate if user on request is a member with proper roles for workspace
|
|
* on request params.
|
|
* @param {Object} obj
|
|
* @param {String[]} obj.acceptedRoles - accepted workspace roles
|
|
* @param {String[]} obj.acceptedStatuses - accepted workspace statuses
|
|
* @param {String[]} obj.location - location of [workspaceId] on request (e.g. params, body) for parsing
|
|
*/
|
|
const requireWorkspaceAuth = ({
|
|
acceptedRoles,
|
|
acceptedStatuses,
|
|
location = 'params'
|
|
}: {
|
|
acceptedRoles: string[];
|
|
acceptedStatuses: string[];
|
|
location?: req;
|
|
}) => {
|
|
return async (req: Request, res: Response, next: NextFunction) => {
|
|
// workspace authorization middleware
|
|
|
|
try {
|
|
const membership = await validateMembership({
|
|
userId: req.user._id.toString(),
|
|
workspaceId: req[location].workspaceId,
|
|
acceptedRoles,
|
|
acceptedStatuses
|
|
});
|
|
|
|
req.membership = membership;
|
|
|
|
return next();
|
|
} catch (err) {
|
|
return next(UnauthorizedRequestError({message: 'Unable to authenticate workspace'}))
|
|
}
|
|
};
|
|
};
|
|
|
|
export default requireWorkspaceAuth;
|