mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
92 lines
3.7 KiB
TypeScript
92 lines
3.7 KiB
TypeScript
import { TDbClient } from "@app/db";
|
|
import { TableName } from "@app/db/schemas";
|
|
import { DatabaseError } from "@app/lib/errors";
|
|
import { selectAllTableCols } from "@app/lib/knex";
|
|
|
|
export type TPermissionDALFactory = ReturnType<typeof permissionDALFactory>;
|
|
|
|
export const permissionDALFactory = (db: TDbClient) => {
|
|
const getOrgPermission = async (userId: string, orgId: string) => {
|
|
try {
|
|
const membership = await db(TableName.OrgMembership)
|
|
.leftJoin(TableName.OrgRoles, `${TableName.OrgMembership}.roleId`, `${TableName.OrgRoles}.id`)
|
|
.join(TableName.Organization, `${TableName.OrgMembership}.orgId`, `${TableName.Organization}.id`)
|
|
.where("userId", userId)
|
|
.where(`${TableName.OrgMembership}.orgId`, orgId)
|
|
.select(db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"))
|
|
.select("permissions")
|
|
.select(selectAllTableCols(TableName.OrgMembership))
|
|
.first();
|
|
|
|
return membership;
|
|
} catch (error) {
|
|
throw new DatabaseError({ error, name: "GetOrgPermission" });
|
|
}
|
|
};
|
|
|
|
const getOrgIdentityPermission = async (identityId: string, orgId: string) => {
|
|
try {
|
|
const membership = await db(TableName.IdentityOrgMembership)
|
|
.leftJoin(TableName.OrgRoles, `${TableName.IdentityOrgMembership}.roleId`, `${TableName.OrgRoles}.id`)
|
|
.join(TableName.Organization, `${TableName.IdentityOrgMembership}.orgId`, `${TableName.Organization}.id`)
|
|
.where("identityId", identityId)
|
|
.where(`${TableName.IdentityOrgMembership}.orgId`, orgId)
|
|
.select(selectAllTableCols(TableName.IdentityOrgMembership))
|
|
.select(db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"))
|
|
.select("permissions")
|
|
.first();
|
|
return membership;
|
|
} catch (error) {
|
|
throw new DatabaseError({ error, name: "GetOrgIdentityPermission" });
|
|
}
|
|
};
|
|
|
|
const getProjectPermission = async (userId: string, projectId: string) => {
|
|
try {
|
|
const membership = await db(TableName.ProjectMembership)
|
|
.leftJoin(TableName.ProjectRoles, `${TableName.ProjectMembership}.roleId`, `${TableName.ProjectRoles}.id`)
|
|
.join(TableName.Project, `${TableName.ProjectMembership}.projectId`, `${TableName.Project}.id`)
|
|
.join(TableName.Organization, `${TableName.Project}.orgId`, `${TableName.Organization}.id`)
|
|
.where("userId", userId)
|
|
.where(`${TableName.ProjectMembership}.projectId`, projectId)
|
|
.select(selectAllTableCols(TableName.ProjectMembership))
|
|
.select(
|
|
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
|
|
db.ref("orgId").withSchema(TableName.Project)
|
|
)
|
|
.select("permissions")
|
|
.first();
|
|
|
|
return membership;
|
|
} catch (error) {
|
|
throw new DatabaseError({ error, name: "GetProjectPermission" });
|
|
}
|
|
};
|
|
|
|
const getProjectIdentityPermission = async (identityId: string, projectId: string) => {
|
|
try {
|
|
const membership = await db(TableName.IdentityProjectMembership)
|
|
.leftJoin(
|
|
TableName.ProjectRoles,
|
|
`${TableName.IdentityProjectMembership}.roleId`,
|
|
`${TableName.ProjectRoles}.id`
|
|
)
|
|
.where("identityId", identityId)
|
|
.where(`${TableName.IdentityProjectMembership}.projectId`, projectId)
|
|
.select(selectAllTableCols(TableName.IdentityProjectMembership))
|
|
.select("permissions")
|
|
.first();
|
|
return membership;
|
|
} catch (error) {
|
|
throw new DatabaseError({ error, name: "GetProjectIdentityPermission" });
|
|
}
|
|
};
|
|
|
|
return {
|
|
getOrgPermission,
|
|
getOrgIdentityPermission,
|
|
getProjectPermission,
|
|
getProjectIdentityPermission
|
|
};
|
|
};
|