mirror of
https://github.com/fosrl/pangolin.git
synced 2026-07-21 21:16:30 +02:00
Compare commits
18 Commits
1.21.0-rc.0
..
dev
| Author | SHA1 | Date | |
|---|---|---|---|
| 19c1c2042b | |||
| 56fcb80b23 | |||
| 5d38059b95 | |||
| df0198df9c | |||
| 26713b53f6 | |||
| 2bc6b28978 | |||
| f1ed4da8a4 | |||
| adeefb9dbd | |||
| bf1cc705a5 | |||
| 0b82dae01e | |||
| 75afe6ece2 | |||
| 70e2fe1e4e | |||
| 17e03457e1 | |||
| 4d8cb7e231 | |||
| 9561d23f1e | |||
| a2e1c7b751 | |||
| 9e2ec72ced | |||
| 02fe1f3abd |
@@ -41,7 +41,7 @@ services:
|
|||||||
- 80:80 # Port for traefik because of the network_mode
|
- 80:80 # Port for traefik because of the network_mode
|
||||||
|
|
||||||
traefik:
|
traefik:
|
||||||
image: traefik:v3.7
|
image: traefik:v3.6
|
||||||
container_name: traefik
|
container_name: traefik
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
network_mode: service:gerbil # Ports appear on the gerbil service
|
network_mode: service:gerbil # Ports appear on the gerbil service
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ services:
|
|||||||
- 80:80{{end}}
|
- 80:80{{end}}
|
||||||
|
|
||||||
traefik:
|
traefik:
|
||||||
image: docker.io/traefik:v3.7
|
image: docker.io/traefik:v3.6
|
||||||
container_name: traefik
|
container_name: traefik
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
{{if .InstallGerbil}}network_mode: service:gerbil # Ports appear on the gerbil service{{end}}{{if not .InstallGerbil}}
|
{{if .InstallGerbil}}network_mode: service:gerbil # Ports appear on the gerbil service{{end}}{{if not .InstallGerbil}}
|
||||||
|
|||||||
+10
-7
@@ -934,7 +934,7 @@
|
|||||||
"newtVersion": "Version",
|
"newtVersion": "Version",
|
||||||
"architecture": "Architecture",
|
"architecture": "Architecture",
|
||||||
"sites": "Sites",
|
"sites": "Sites",
|
||||||
"siteWgAnyClients": "Use any WireGuard client to connect. You will have to address internal resources using the peer IP.",
|
"siteWgAnyClients": "Use any WireGuard client to connect. You will have to address private resources using the peer IP.",
|
||||||
"siteWgCompatibleAllClients": "Compatible with all WireGuard clients",
|
"siteWgCompatibleAllClients": "Compatible with all WireGuard clients",
|
||||||
"siteWgManualConfigurationRequired": "Manual configuration required",
|
"siteWgManualConfigurationRequired": "Manual configuration required",
|
||||||
"userErrorNotAdminOrOwner": "User is not an admin or owner",
|
"userErrorNotAdminOrOwner": "User is not an admin or owner",
|
||||||
@@ -1995,6 +1995,9 @@
|
|||||||
"domainPickerSubdomain": "Subdomain: {subdomain}",
|
"domainPickerSubdomain": "Subdomain: {subdomain}",
|
||||||
"domainPickerNamespace": "Namespace: {namespace}",
|
"domainPickerNamespace": "Namespace: {namespace}",
|
||||||
"domainPickerShowMore": "Show More",
|
"domainPickerShowMore": "Show More",
|
||||||
|
"domainPickerNoDomainsAvailableTitle": "No domains available",
|
||||||
|
"domainPickerNoDomainsAvailableDescription": "You don't have any domains set up yet. Create a domain to continue.",
|
||||||
|
"domainPickerNoDomainsAvailableAction": "Go to Domains",
|
||||||
"regionSelectorTitle": "Select Region",
|
"regionSelectorTitle": "Select Region",
|
||||||
"domainPickerRemoteExitNodeWarning": "Provided domains are not supported when sites connect to remote exit nodes. For resources to be available on remote nodes, use a custom domain instead.",
|
"domainPickerRemoteExitNodeWarning": "Provided domains are not supported when sites connect to remote exit nodes. For resources to be available on remote nodes, use a custom domain instead.",
|
||||||
"regionSelectorInfo": "Selecting a region helps us provide better performance for your location. You do not have to be in the same region as your server.",
|
"regionSelectorInfo": "Selecting a region helps us provide better performance for your location. You do not have to be in the same region as your server.",
|
||||||
@@ -2358,7 +2361,7 @@
|
|||||||
"resourcesTableProxyResources": "Public",
|
"resourcesTableProxyResources": "Public",
|
||||||
"resourcesTableClientResources": "Private",
|
"resourcesTableClientResources": "Private",
|
||||||
"resourcesTableNoProxyResourcesFound": "No proxy resources found.",
|
"resourcesTableNoProxyResourcesFound": "No proxy resources found.",
|
||||||
"resourcesTableNoInternalResourcesFound": "No internal resources found.",
|
"resourcesTableNoInternalResourcesFound": "No private resources found.",
|
||||||
"resourcesTableDestination": "Destination",
|
"resourcesTableDestination": "Destination",
|
||||||
"resourcesTableAlias": "Alias",
|
"resourcesTableAlias": "Alias",
|
||||||
"resourcesTableAliasAddress": "Alias Address",
|
"resourcesTableAliasAddress": "Alias Address",
|
||||||
@@ -2381,9 +2384,9 @@
|
|||||||
"editInternalResourceDialogCancel": "Cancel",
|
"editInternalResourceDialogCancel": "Cancel",
|
||||||
"editInternalResourceDialogSaveResource": "Save Resource",
|
"editInternalResourceDialogSaveResource": "Save Resource",
|
||||||
"editInternalResourceDialogSuccess": "Success",
|
"editInternalResourceDialogSuccess": "Success",
|
||||||
"editInternalResourceDialogInternalResourceUpdatedSuccessfully": "Internal resource updated successfully",
|
"editInternalResourceDialogInternalResourceUpdatedSuccessfully": "Private resource updated successfully",
|
||||||
"editInternalResourceDialogError": "Error",
|
"editInternalResourceDialogError": "Error",
|
||||||
"editInternalResourceDialogFailedToUpdateInternalResource": "Failed to update internal resource",
|
"editInternalResourceDialogFailedToUpdateInternalResource": "Failed to update private resource",
|
||||||
"editInternalResourceDialogNameRequired": "Name is required",
|
"editInternalResourceDialogNameRequired": "Name is required",
|
||||||
"editInternalResourceDialogNameMaxLength": "Name must be less than 255 characters",
|
"editInternalResourceDialogNameMaxLength": "Name must be less than 255 characters",
|
||||||
"editInternalResourceDialogProxyPortMin": "Proxy port must be at least 1",
|
"editInternalResourceDialogProxyPortMin": "Proxy port must be at least 1",
|
||||||
@@ -2409,7 +2412,7 @@
|
|||||||
"editInternalResourceDialogAlias": "Alias",
|
"editInternalResourceDialogAlias": "Alias",
|
||||||
"editInternalResourceDialogAliasDescription": "An optional internal DNS alias for this resource.",
|
"editInternalResourceDialogAliasDescription": "An optional internal DNS alias for this resource.",
|
||||||
"createInternalResourceDialogNoSitesAvailable": "No Sites Available",
|
"createInternalResourceDialogNoSitesAvailable": "No Sites Available",
|
||||||
"createInternalResourceDialogNoSitesAvailableDescription": "You need to have at least one Newt site with a subnet configured to create internal resources.",
|
"createInternalResourceDialogNoSitesAvailableDescription": "You need to have at least one Newt site with a subnet configured to create private resources.",
|
||||||
"createInternalResourceDialogClose": "Close",
|
"createInternalResourceDialogClose": "Close",
|
||||||
"createInternalResourceDialogCreateClientResource": "Create Private Resource",
|
"createInternalResourceDialogCreateClientResource": "Create Private Resource",
|
||||||
"createInternalResourceDialogCreateClientResourceDescription": "Create a new resource that will only be accessible to clients connected to the organization",
|
"createInternalResourceDialogCreateClientResourceDescription": "Create a new resource that will only be accessible to clients connected to the organization",
|
||||||
@@ -2438,9 +2441,9 @@
|
|||||||
"createInternalResourceDialogCancel": "Cancel",
|
"createInternalResourceDialogCancel": "Cancel",
|
||||||
"createInternalResourceDialogCreateResource": "Create Resource",
|
"createInternalResourceDialogCreateResource": "Create Resource",
|
||||||
"createInternalResourceDialogSuccess": "Success",
|
"createInternalResourceDialogSuccess": "Success",
|
||||||
"createInternalResourceDialogInternalResourceCreatedSuccessfully": "Internal resource created successfully",
|
"createInternalResourceDialogInternalResourceCreatedSuccessfully": "Private resource created successfully",
|
||||||
"createInternalResourceDialogError": "Error",
|
"createInternalResourceDialogError": "Error",
|
||||||
"createInternalResourceDialogFailedToCreateInternalResource": "Failed to create internal resource",
|
"createInternalResourceDialogFailedToCreateInternalResource": "Failed to create private resource",
|
||||||
"createInternalResourceDialogNameRequired": "Name is required",
|
"createInternalResourceDialogNameRequired": "Name is required",
|
||||||
"createInternalResourceDialogNameMaxLength": "Name must be less than 255 characters",
|
"createInternalResourceDialogNameMaxLength": "Name must be less than 255 characters",
|
||||||
"createInternalResourceDialogPleaseSelectSite": "Please select a site",
|
"createInternalResourceDialogPleaseSelectSite": "Please select a site",
|
||||||
|
|||||||
@@ -30,14 +30,14 @@ export const NotifyTrialExpiring = ({
|
|||||||
const isLastDay = daysRemaining === 1;
|
const isLastDay = daysRemaining === 1;
|
||||||
|
|
||||||
const previewText = hasEnded
|
const previewText = hasEnded
|
||||||
? `Your trial for ${orgName} has ended.`
|
? `Your cloud trial for ${orgName} has ended.`
|
||||||
: isLastDay
|
: isLastDay
|
||||||
? `Your trial for ${orgName} ends tomorrow.`
|
? `Your cloud trial for ${orgName} ends tomorrow.`
|
||||||
: `Your trial for ${orgName} ends in ${daysRemaining} days.`;
|
: `Your cloud trial for ${orgName} ends in ${daysRemaining} days.`;
|
||||||
|
|
||||||
const heading = hasEnded
|
const heading = hasEnded
|
||||||
? "Your Trial Ended"
|
? "Your Cloud Trial Ended"
|
||||||
: "Your Trial is Ending Soon";
|
: "Your Cloud Trial is Ending Soon";
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<Html>
|
<Html>
|
||||||
@@ -55,7 +55,7 @@ export const NotifyTrialExpiring = ({
|
|||||||
{hasEnded ? (
|
{hasEnded ? (
|
||||||
<>
|
<>
|
||||||
<EmailText>
|
<EmailText>
|
||||||
Your free trial for{" "}
|
Your cloud free trial for{" "}
|
||||||
<strong>{orgName}</strong> ended on{" "}
|
<strong>{orgName}</strong> ended on{" "}
|
||||||
<strong>{trialEndsAt}</strong>. Your account
|
<strong>{trialEndsAt}</strong>. Your account
|
||||||
has been moved to the free plan, which
|
has been moved to the free plan, which
|
||||||
@@ -64,10 +64,11 @@ export const NotifyTrialExpiring = ({
|
|||||||
|
|
||||||
<EmailText>
|
<EmailText>
|
||||||
Some features and resources may now be
|
Some features and resources may now be
|
||||||
restricted. To restore full
|
restricted. To restore full access and
|
||||||
access and continue using all the features
|
continue using all the features you had
|
||||||
you had during your trial, please upgrade to
|
during your trial, please upgrade to a paid
|
||||||
a paid plan.
|
plan. This does not effect any self hosted
|
||||||
|
licenses.
|
||||||
</EmailText>
|
</EmailText>
|
||||||
|
|
||||||
<EmailText>
|
<EmailText>
|
||||||
@@ -93,7 +94,8 @@ export const NotifyTrialExpiring = ({
|
|||||||
<EmailText>
|
<EmailText>
|
||||||
After your trial ends, your account will be
|
After your trial ends, your account will be
|
||||||
moved to the free plan and some
|
moved to the free plan and some
|
||||||
functionality may be restricted.
|
functionality may be restricted. This does
|
||||||
|
not effect any self hosted licenses.
|
||||||
</EmailText>
|
</EmailText>
|
||||||
|
|
||||||
<EmailText>
|
<EmailText>
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ import { logIncomingMiddleware } from "./middlewares/logIncoming";
|
|||||||
import helmet from "helmet";
|
import helmet from "helmet";
|
||||||
import swaggerUi from "swagger-ui-express";
|
import swaggerUi from "swagger-ui-express";
|
||||||
import { OpenApiGeneratorV3 } from "@asteasolutions/zod-to-openapi";
|
import { OpenApiGeneratorV3 } from "@asteasolutions/zod-to-openapi";
|
||||||
import { registry } from "./openApi";
|
import { registry, openApiTags } from "./openApi";
|
||||||
import fs from "fs";
|
import fs from "fs";
|
||||||
import path from "path";
|
import path from "path";
|
||||||
import { APP_PATH } from "./lib/consts";
|
import { APP_PATH } from "./lib/consts";
|
||||||
@@ -181,7 +181,8 @@ function getOpenApiDocumentation() {
|
|||||||
version: "v1",
|
version: "v1",
|
||||||
title: "Pangolin Integration API"
|
title: "Pangolin Integration API"
|
||||||
},
|
},
|
||||||
servers: [{ url: "/v1" }]
|
servers: [{ url: "/v1" }],
|
||||||
|
tags: openApiTags
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!process.env.DISABLE_GEN_OPENAPI) {
|
if (!process.env.DISABLE_GEN_OPENAPI) {
|
||||||
|
|||||||
+34
-3
@@ -15,10 +15,41 @@ function getSegmentRegex(patternPart: string): RegExp {
|
|||||||
return regex;
|
return regex;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Decodes percent-encoding (so an encoded slash like `%2F` is treated as a
|
||||||
|
// real path separator, matching what most backends will do) and then
|
||||||
|
// resolves `.` / `..` segments, so a request like `/public%2F..%2Fadmin/`
|
||||||
|
// or `/public/../admin/` is matched as `/admin/`, not as a literal segment
|
||||||
|
// or a wildcard-swallowed sequence under `/public/*`.
|
||||||
|
function decodeAndResolvePath(p: string): string[] {
|
||||||
|
const rawParts = p.split("/").filter(Boolean);
|
||||||
|
|
||||||
|
const resolved: string[] = [];
|
||||||
|
for (const rawPart of rawParts) {
|
||||||
|
let part: string;
|
||||||
|
try {
|
||||||
|
part = decodeURIComponent(rawPart);
|
||||||
|
} catch {
|
||||||
|
part = rawPart;
|
||||||
|
}
|
||||||
|
|
||||||
|
// an encoded slash can turn one raw segment into several real ones
|
||||||
|
for (const segment of part.split("/").filter(Boolean)) {
|
||||||
|
if (segment === ".") {
|
||||||
|
continue;
|
||||||
|
} else if (segment === "..") {
|
||||||
|
resolved.pop();
|
||||||
|
} else {
|
||||||
|
resolved.push(segment);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return resolved;
|
||||||
|
}
|
||||||
|
|
||||||
export function isPathAllowed(pattern: string, path: string): boolean {
|
export function isPathAllowed(pattern: string, path: string): boolean {
|
||||||
const normalize = (p: string) => p.split("/").filter(Boolean);
|
const patternParts = pattern.split("/").filter(Boolean);
|
||||||
const patternParts = normalize(pattern);
|
const pathParts = decodeAndResolvePath(path);
|
||||||
const pathParts = normalize(path);
|
|
||||||
|
|
||||||
function matchSegments(
|
function matchSegments(
|
||||||
patternIndex: number,
|
patternIndex: number,
|
||||||
|
|||||||
+18
-7
@@ -4,23 +4,34 @@ export const registry = new OpenAPIRegistry();
|
|||||||
|
|
||||||
export enum OpenAPITags {
|
export enum OpenAPITags {
|
||||||
Site = "Site",
|
Site = "Site",
|
||||||
Org = "Organization",
|
|
||||||
PublicResource = "Public Resource",
|
PublicResource = "Public Resource",
|
||||||
|
Target = "Resource Target",
|
||||||
PrivateResource = "Private Resource",
|
PrivateResource = "Private Resource",
|
||||||
Policy = "Policy",
|
Client = "Client",
|
||||||
|
Org = "Organization",
|
||||||
|
Domain = "Domain",
|
||||||
|
PublicResourcePolicy = "Public Resource Policy",
|
||||||
Role = "Role",
|
Role = "Role",
|
||||||
User = "User",
|
User = "User",
|
||||||
Invitation = "User Invitation",
|
|
||||||
Target = "Resource Target",
|
|
||||||
Rule = "Rule",
|
Rule = "Rule",
|
||||||
|
Invitation = "User Invitation",
|
||||||
AccessToken = "Access Token",
|
AccessToken = "Access Token",
|
||||||
GlobalIdp = "Identity Provider (Global)",
|
GlobalIdp = "Identity Provider (Global)",
|
||||||
OrgIdp = "Identity Provider (Organization Only)",
|
OrgIdp = "Identity Provider (Organization Only)",
|
||||||
Client = "Client",
|
|
||||||
ApiKey = "API Key",
|
ApiKey = "API Key",
|
||||||
SiteProvisioningKey = "Site Provisioning Key",
|
SiteProvisioningKey = "Site Provisioning Key",
|
||||||
Domain = "Domain",
|
|
||||||
Blueprint = "Blueprint",
|
Blueprint = "Blueprint",
|
||||||
Ssh = "SSH",
|
Ssh = "SSH",
|
||||||
Logs = "Logs"
|
Logs = "Logs",
|
||||||
|
EventStreamingDestination = "Event Streaming Destination",
|
||||||
|
AlertRule = "Alert Rule",
|
||||||
|
HealthCheck = "Health Check",
|
||||||
|
PublicResourcePolicyLegacy = "Public Resource Policy (Legacy)",
|
||||||
|
PublicResourceLegacy = "Public Resource (Legacy)",
|
||||||
|
PrivateResourceLegacy = "Private Resource (Legacy)"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Order here controls the order tags are displayed in Swagger UI
|
||||||
|
export const openApiTags = Object.values(OpenAPITags).map((name) => ({
|
||||||
|
name
|
||||||
|
}));
|
||||||
|
|||||||
@@ -191,7 +191,7 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/org/{orgId}/alert-rule",
|
path: "/org/{orgId}/alert-rule",
|
||||||
description: "Create an alert rule for a specific organization.",
|
description: "Create an alert rule for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.AlertRule],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -34,7 +34,7 @@ registry.registerPath({
|
|||||||
method: "delete",
|
method: "delete",
|
||||||
path: "/org/{orgId}/alert-rule/{alertRuleId}",
|
path: "/org/{orgId}/alert-rule/{alertRuleId}",
|
||||||
description: "Delete an alert rule for a specific organization.",
|
description: "Delete an alert rule for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.AlertRule],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema
|
params: paramsSchema
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/alert-rule/{alertRuleId}",
|
path: "/org/{orgId}/alert-rule/{alertRuleId}",
|
||||||
description: "Get a specific alert rule for an organization.",
|
description: "Get a specific alert rule for an organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.AlertRule],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema
|
params: paramsSchema
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -90,7 +90,7 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/alert-rules",
|
path: "/org/{orgId}/alert-rules",
|
||||||
description: "List all alert rules for a specific organization.",
|
description: "List all alert rules for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.AlertRule],
|
||||||
request: {
|
request: {
|
||||||
query: querySchema,
|
query: querySchema,
|
||||||
params: paramsSchema
|
params: paramsSchema
|
||||||
|
|||||||
@@ -158,7 +158,7 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/org/{orgId}/alert-rule/{alertRuleId}",
|
path: "/org/{orgId}/alert-rule/{alertRuleId}",
|
||||||
description: "Update an alert rule for a specific organization.",
|
description: "Update an alert rule for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.AlertRule],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -52,7 +52,7 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/org/{orgId}/event-streaming-destination",
|
path: "/org/{orgId}/event-streaming-destination",
|
||||||
description: "Create an event streaming destination for a specific organization.",
|
description: "Create an event streaming destination for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.EventStreamingDestination],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -35,7 +35,7 @@ registry.registerPath({
|
|||||||
path: "/org/{orgId}/event-streaming-destination/{destinationId}",
|
path: "/org/{orgId}/event-streaming-destination/{destinationId}",
|
||||||
description:
|
description:
|
||||||
"Delete an event streaming destination for a specific organization.",
|
"Delete an event streaming destination for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.EventStreamingDestination],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema
|
params: paramsSchema
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -109,7 +109,7 @@ registry.registerPath({
|
|||||||
path: "/org/{orgId}/event-streaming-destination",
|
path: "/org/{orgId}/event-streaming-destination",
|
||||||
description:
|
description:
|
||||||
"List all event streaming destinations for a specific organization.",
|
"List all event streaming destinations for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.EventStreamingDestination],
|
||||||
request: {
|
request: {
|
||||||
query: querySchema,
|
query: querySchema,
|
||||||
params: paramsSchema
|
params: paramsSchema
|
||||||
|
|||||||
@@ -55,7 +55,7 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/org/{orgId}/event-streaming-destination/{destinationId}",
|
path: "/org/{orgId}/event-streaming-destination/{destinationId}",
|
||||||
description: "Update an event streaming destination for a specific organization.",
|
description: "Update an event streaming destination for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.EventStreamingDestination],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/org/{orgId}/health-check",
|
path: "/org/{orgId}/health-check",
|
||||||
description: "Create a health check for a specific organization.",
|
description: "Create a health check for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.HealthCheck],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ registry.registerPath({
|
|||||||
method: "delete",
|
method: "delete",
|
||||||
path: "/org/{orgId}/health-check/{healthCheckId}",
|
path: "/org/{orgId}/health-check/{healthCheckId}",
|
||||||
description: "Delete a health check for a specific organization.",
|
description: "Delete a health check for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.HealthCheck],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema
|
params: paramsSchema
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/health-checks",
|
path: "/org/{orgId}/health-checks",
|
||||||
description: "List health checks for an organization.",
|
description: "List health checks for an organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.HealthCheck],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
query: querySchema
|
query: querySchema
|
||||||
|
|||||||
@@ -109,7 +109,7 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/org/{orgId}/health-check/{healthCheckId}",
|
path: "/org/{orgId}/health-check/{healthCheckId}",
|
||||||
description: "Update a health check for a specific organization.",
|
description: "Update a health check for a specific organization.",
|
||||||
tags: [OpenAPITags.Org],
|
tags: [OpenAPITags.HealthCheck],
|
||||||
request: {
|
request: {
|
||||||
params: paramsSchema,
|
params: paramsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -17,6 +17,10 @@ import * as logs from "#private/routers/auditLogs";
|
|||||||
import * as alertEvents from "#private/routers/alertEvents";
|
import * as alertEvents from "#private/routers/alertEvents";
|
||||||
import * as certificates from "#private/routers/certificates";
|
import * as certificates from "#private/routers/certificates";
|
||||||
import * as siteProvisioning from "#private/routers/siteProvisioning";
|
import * as siteProvisioning from "#private/routers/siteProvisioning";
|
||||||
|
import * as policy from "#private/routers/policy";
|
||||||
|
import * as eventStreamingDestination from "#private/routers/eventStreamingDestination";
|
||||||
|
import * as alertRule from "#private/routers/alertRule";
|
||||||
|
import * as healthChecks from "#private/routers/healthChecks";
|
||||||
|
|
||||||
import {
|
import {
|
||||||
verifyApiKeyHasAction,
|
verifyApiKeyHasAction,
|
||||||
@@ -26,6 +30,7 @@ import {
|
|||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyApiKeyUserAccess,
|
verifyApiKeyUserAccess,
|
||||||
verifyApiKeySiteProvisioningKeyAccess,
|
verifyApiKeySiteProvisioningKeyAccess,
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyLimits
|
verifyLimits
|
||||||
} from "@server/middlewares";
|
} from "@server/middlewares";
|
||||||
import * as user from "#private/routers/user";
|
import * as user from "#private/routers/user";
|
||||||
@@ -259,3 +264,150 @@ authenticated.patch(
|
|||||||
logActionAudit(ActionsEnum.updateSiteProvisioningKey),
|
logActionAudit(ActionsEnum.updateSiteProvisioningKey),
|
||||||
siteProvisioning.updateSiteProvisioningKey
|
siteProvisioning.updateSiteProvisioningKey
|
||||||
);
|
);
|
||||||
|
|
||||||
|
authenticated.get(
|
||||||
|
["/org/:orgId/resource-policies", "/org/:orgId/public-resource-policies"],
|
||||||
|
verifyValidLicense,
|
||||||
|
verifyValidSubscription(tierMatrix.resourcePolicies),
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.listResourcePolicies),
|
||||||
|
logActionAudit(ActionsEnum.listResourcePolicies),
|
||||||
|
policy.listResourcePolicies
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
["/org/:orgId/resource-policy", "/org/:orgId/public-resource-policy"],
|
||||||
|
verifyValidLicense,
|
||||||
|
verifyValidSubscription(tierMatrix.resourcePolicies),
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.createResourcePolicy),
|
||||||
|
logActionAudit(ActionsEnum.createResourcePolicy),
|
||||||
|
policy.createResourcePolicy
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.delete(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId",
|
||||||
|
"/public-resource-policy/:resourcePolicyId"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyValidLicense,
|
||||||
|
verifyValidSubscription(tierMatrix.resourcePolicies),
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.deleteResourcePolicy),
|
||||||
|
logActionAudit(ActionsEnum.deleteResourcePolicy),
|
||||||
|
policy.deleteResourcePolicy
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.put(
|
||||||
|
"/org/:orgId/event-streaming-destination",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.createEventStreamingDestination),
|
||||||
|
logActionAudit(ActionsEnum.createEventStreamingDestination),
|
||||||
|
eventStreamingDestination.createEventStreamingDestination
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
"/org/:orgId/event-streaming-destination/:destinationId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.updateEventStreamingDestination),
|
||||||
|
logActionAudit(ActionsEnum.updateEventStreamingDestination),
|
||||||
|
eventStreamingDestination.updateEventStreamingDestination
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.delete(
|
||||||
|
"/org/:orgId/event-streaming-destination/:destinationId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.deleteEventStreamingDestination),
|
||||||
|
logActionAudit(ActionsEnum.deleteEventStreamingDestination),
|
||||||
|
eventStreamingDestination.deleteEventStreamingDestination
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.get(
|
||||||
|
"/org/:orgId/event-streaming-destinations",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.listEventStreamingDestinations),
|
||||||
|
eventStreamingDestination.listEventStreamingDestinations
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.put(
|
||||||
|
"/org/:orgId/alert-rule",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.createAlertRule),
|
||||||
|
logActionAudit(ActionsEnum.createAlertRule),
|
||||||
|
alertRule.createAlertRule
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
"/org/:orgId/alert-rule/:alertRuleId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.updateAlertRule),
|
||||||
|
logActionAudit(ActionsEnum.updateAlertRule),
|
||||||
|
alertRule.updateAlertRule
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.delete(
|
||||||
|
"/org/:orgId/alert-rule/:alertRuleId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.deleteAlertRule),
|
||||||
|
logActionAudit(ActionsEnum.deleteAlertRule),
|
||||||
|
alertRule.deleteAlertRule
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.get(
|
||||||
|
"/org/:orgId/alert-rules",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.listAlertRules),
|
||||||
|
alertRule.listAlertRules
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.get(
|
||||||
|
"/org/:orgId/alert-rule/:alertRuleId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.getAlertRule),
|
||||||
|
alertRule.getAlertRule
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.get(
|
||||||
|
"/org/:orgId/health-checks",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.listHealthChecks),
|
||||||
|
healthChecks.listHealthChecks
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.put(
|
||||||
|
"/org/:orgId/health-check",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.createHealthCheck),
|
||||||
|
logActionAudit(ActionsEnum.createHealthCheck),
|
||||||
|
healthChecks.createHealthCheck
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
"/org/:orgId/health-check/:healthCheckId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.updateHealthCheck),
|
||||||
|
logActionAudit(ActionsEnum.updateHealthCheck),
|
||||||
|
healthChecks.updateHealthCheck
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.delete(
|
||||||
|
"/org/:orgId/health-check/:healthCheckId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.deleteHealthCheck),
|
||||||
|
logActionAudit(ActionsEnum.deleteHealthCheck),
|
||||||
|
healthChecks.deleteHealthCheck
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.get(
|
||||||
|
"/org/:orgId/health-check/:healthCheckId/status-history",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.getTarget),
|
||||||
|
healthChecks.getHealthCheckStatusHistory
|
||||||
|
);
|
||||||
|
|||||||
@@ -121,7 +121,7 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/org/{orgId}/resource-policy",
|
path: "/org/{orgId}/resource-policy",
|
||||||
description: "Create a resource policy.",
|
description: "Create a resource policy.",
|
||||||
tags: [OpenAPITags.Org, OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: createResourcePolicyParamsSchema,
|
params: createResourcePolicyParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ registry.registerPath({
|
|||||||
method: "delete",
|
method: "delete",
|
||||||
path: "/resource-policy/{resourcePolicyId}",
|
path: "/resource-policy/{resourcePolicyId}",
|
||||||
description: "Delete a resource policy.",
|
description: "Delete a resource policy.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: deleteResourcePolicySchema
|
params: deleteResourcePolicySchema
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/resource-policies",
|
path: "/org/{orgId}/resource-policies",
|
||||||
description: "List resource policies for an organization.",
|
description: "List resource policies for an organization.",
|
||||||
tags: [OpenAPITags.Org, OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
orgId: z.string()
|
orgId: z.string()
|
||||||
|
|||||||
@@ -45,6 +45,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/access-token",
|
path: "/resource/{resourceId}/access-token",
|
||||||
description: "Generate a new access token for a resource.",
|
description: "Generate a new access token for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: generateAccssTokenParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: generateAccessTokenBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/access-token",
|
||||||
|
description: "Generate a new access token for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.AccessToken],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.AccessToken],
|
||||||
request: {
|
request: {
|
||||||
params: generateAccssTokenParamsSchema,
|
params: generateAccssTokenParamsSchema,
|
||||||
|
|||||||
@@ -159,6 +159,35 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/access-tokens",
|
path: "/resource/{resourceId}/access-tokens",
|
||||||
description: "List all access tokens for a resource.",
|
description: "List all access tokens for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
resourceId: z.number()
|
||||||
|
}),
|
||||||
|
query: listAccessTokensSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/access-tokens",
|
||||||
|
description: "List all access tokens for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.AccessToken],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.AccessToken],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
|
|||||||
@@ -236,6 +236,38 @@ function runTests() {
|
|||||||
"Root path should not match non-root path"
|
"Root path should not match non-root path"
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Path traversal / encoded-slash bypass regression tests
|
||||||
|
assertEquals(
|
||||||
|
isPathAllowed("public/*", "public/../admin"),
|
||||||
|
false,
|
||||||
|
"Literal .. traversal out of an allowed prefix must not match"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
isPathAllowed("public/*", "public%2F..%2Fadmin"),
|
||||||
|
false,
|
||||||
|
"Encoded-slash traversal out of an allowed prefix must not match"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
isPathAllowed("public/*", "public%2f..%2fadmin%2ffile"),
|
||||||
|
false,
|
||||||
|
"Encoded-slash traversal is case-insensitively decoded before matching"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
isPathAllowed("admin/*", "public/../admin/secret"),
|
||||||
|
true,
|
||||||
|
".. traversal INTO a restricted path should still be caught by its own rule"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
isPathAllowed("public/*", "public%2Ffoo"),
|
||||||
|
true,
|
||||||
|
"Encoded slash without traversal should still resolve and match normally"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
isPathAllowed("public/*", "public/./foo"),
|
||||||
|
true,
|
||||||
|
"Single-dot segments are a no-op and should not affect matching"
|
||||||
|
);
|
||||||
|
|
||||||
console.log("All path matching tests passed!");
|
console.log("All path matching tests passed!");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -418,7 +418,7 @@ export async function verifyResourceSession(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// check for HTTP Basic Auth header
|
// check for HTTP Basic Auth header
|
||||||
const clientHeaderAuthKey = `headerAuth:${clientHeaderAuth}`;
|
const clientHeaderAuthKey = `headerAuth:${resource.resourceId}:${clientHeaderAuth}`;
|
||||||
if (headerAuth && clientHeaderAuth) {
|
if (headerAuth && clientHeaderAuth) {
|
||||||
if (localCache.get(clientHeaderAuthKey)) {
|
if (localCache.get(clientHeaderAuthKey)) {
|
||||||
logger.debug(
|
logger.debug(
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ const UpdateDomainResponseDataSchema = z.object({
|
|||||||
|
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "patch",
|
method: "post",
|
||||||
path: "/org/{orgId}/domain/{domainId}",
|
path: "/org/{orgId}/domain/{domainId}",
|
||||||
description: "Update a domain by domainId.",
|
description: "Update a domain by domainId.",
|
||||||
tags: [OpenAPITags.Domain],
|
tags: [OpenAPITags.Domain],
|
||||||
@@ -55,6 +55,31 @@ registry.registerPath({
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "patch",
|
||||||
|
path: "/org/{orgId}/domain/{domainId}",
|
||||||
|
description:
|
||||||
|
"Update a domain by domainId. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.Domain],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
domainId: z.string(),
|
||||||
|
orgId: z.string()
|
||||||
|
})
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: createApiResponseSchema(UpdateDomainResponseDataSchema)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
export async function updateOrgDomain(
|
export async function updateOrgDomain(
|
||||||
req: Request,
|
req: Request,
|
||||||
res: Response,
|
res: Response,
|
||||||
|
|||||||
+266
-60
@@ -163,7 +163,7 @@ authenticated.get(
|
|||||||
|
|
||||||
// Site Resource endpoints
|
// Site Resource endpoints
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/org/:orgId/site-resource",
|
["/org/:orgId/site-resource", "/org/:orgId/private-resource"],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.createSiteResource),
|
verifyApiKeyHasAction(ActionsEnum.createSiteResource),
|
||||||
@@ -172,7 +172,10 @@ authenticated.put(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/org/:orgId/site/:siteId/resources",
|
[
|
||||||
|
"/org/:orgId/site/:siteId/resources",
|
||||||
|
"/org/:orgId/site/:siteId/private-resources"
|
||||||
|
],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyApiKeySiteAccess,
|
verifyApiKeySiteAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listSiteResources),
|
verifyApiKeyHasAction(ActionsEnum.listSiteResources),
|
||||||
@@ -180,21 +183,21 @@ authenticated.get(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/org/:orgId/site-resources",
|
["/org/:orgId/site-resources", "/org/:orgId/private-resources"],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listSiteResources),
|
verifyApiKeyHasAction(ActionsEnum.listSiteResources),
|
||||||
siteResource.listAllSiteResourcesByOrg
|
siteResource.listAllSiteResourcesByOrg
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/site-resource/:siteResourceId",
|
["/site-resource/:siteResourceId", "/private-resource/:siteResourceId"],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.getSiteResource),
|
verifyApiKeyHasAction(ActionsEnum.getSiteResource),
|
||||||
siteResource.getSiteResource
|
siteResource.getSiteResource
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId",
|
["/site-resource/:siteResourceId", "/private-resource/:siteResourceId"],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.updateSiteResource),
|
verifyApiKeyHasAction(ActionsEnum.updateSiteResource),
|
||||||
@@ -203,7 +206,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.delete(
|
authenticated.delete(
|
||||||
"/site-resource/:siteResourceId",
|
["/site-resource/:siteResourceId", "/private-resource/:siteResourceId"],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.deleteSiteResource),
|
verifyApiKeyHasAction(ActionsEnum.deleteSiteResource),
|
||||||
logActionAudit(ActionsEnum.deleteSiteResource),
|
logActionAudit(ActionsEnum.deleteSiteResource),
|
||||||
@@ -211,28 +214,40 @@ authenticated.delete(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/site-resource/:siteResourceId/roles",
|
[
|
||||||
|
"/site-resource/:siteResourceId/roles",
|
||||||
|
"/private-resource/:siteResourceId/roles"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResourceRoles),
|
verifyApiKeyHasAction(ActionsEnum.listResourceRoles),
|
||||||
siteResource.listSiteResourceRoles
|
siteResource.listSiteResourceRoles
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/site-resource/:siteResourceId/users",
|
[
|
||||||
|
"/site-resource/:siteResourceId/users",
|
||||||
|
"/private-resource/:siteResourceId/users"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResourceUsers),
|
verifyApiKeyHasAction(ActionsEnum.listResourceUsers),
|
||||||
siteResource.listSiteResourceUsers
|
siteResource.listSiteResourceUsers
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/site-resource/:siteResourceId/clients",
|
[
|
||||||
|
"/site-resource/:siteResourceId/clients",
|
||||||
|
"/private-resource/:siteResourceId/clients"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResourceUsers),
|
verifyApiKeyHasAction(ActionsEnum.listResourceUsers),
|
||||||
siteResource.listSiteResourceClients
|
siteResource.listSiteResourceClients
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/roles",
|
[
|
||||||
|
"/site-resource/:siteResourceId/roles",
|
||||||
|
"/private-resource/:siteResourceId/roles"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -242,7 +257,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/users",
|
[
|
||||||
|
"/site-resource/:siteResourceId/users",
|
||||||
|
"/private-resource/:siteResourceId/users"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeySetResourceUsers,
|
verifyApiKeySetResourceUsers,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -252,7 +270,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/roles/add",
|
[
|
||||||
|
"/site-resource/:siteResourceId/roles/add",
|
||||||
|
"/private-resource/:siteResourceId/roles/add"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -262,7 +283,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/roles/remove",
|
[
|
||||||
|
"/site-resource/:siteResourceId/roles/remove",
|
||||||
|
"/private-resource/:siteResourceId/roles/remove"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -272,7 +296,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/users/add",
|
[
|
||||||
|
"/site-resource/:siteResourceId/users/add",
|
||||||
|
"/private-resource/:siteResourceId/users/add"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeySetResourceUsers,
|
verifyApiKeySetResourceUsers,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -282,7 +309,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/users/remove",
|
[
|
||||||
|
"/site-resource/:siteResourceId/users/remove",
|
||||||
|
"/private-resource/:siteResourceId/users/remove"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeySetResourceUsers,
|
verifyApiKeySetResourceUsers,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -292,7 +322,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/clients",
|
[
|
||||||
|
"/site-resource/:siteResourceId/clients",
|
||||||
|
"/private-resource/:siteResourceId/clients"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeySetResourceClients,
|
verifyApiKeySetResourceClients,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -302,7 +335,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/clients/add",
|
[
|
||||||
|
"/site-resource/:siteResourceId/clients/add",
|
||||||
|
"/private-resource/:siteResourceId/clients/add"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeySetResourceClients,
|
verifyApiKeySetResourceClients,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -312,7 +348,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/site-resource/:siteResourceId/clients/remove",
|
[
|
||||||
|
"/site-resource/:siteResourceId/clients/remove",
|
||||||
|
"/private-resource/:siteResourceId/clients/remove"
|
||||||
|
],
|
||||||
verifyApiKeySiteResourceAccess,
|
verifyApiKeySiteResourceAccess,
|
||||||
verifyApiKeySetResourceClients,
|
verifyApiKeySetResourceClients,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -322,7 +361,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/client/:clientId/site-resources",
|
["/client/:clientId/site-resources", "/client/:clientId/private-resources"],
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourceUsers),
|
verifyApiKeyHasAction(ActionsEnum.setResourceUsers),
|
||||||
logActionAudit(ActionsEnum.setResourceUsers),
|
logActionAudit(ActionsEnum.setResourceUsers),
|
||||||
@@ -330,7 +369,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/org/:orgId/resource",
|
["/org/:orgId/resource", "/org/:orgId/public-resource"],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.createResource),
|
verifyApiKeyHasAction(ActionsEnum.createResource),
|
||||||
@@ -339,7 +378,10 @@ authenticated.put(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/org/:orgId/site/:siteId/resource",
|
[
|
||||||
|
"/org/:orgId/site/:siteId/resource",
|
||||||
|
"/org/:orgId/site/:siteId/public-resource"
|
||||||
|
],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.createResource),
|
verifyApiKeyHasAction(ActionsEnum.createResource),
|
||||||
@@ -348,14 +390,14 @@ authenticated.put(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/site/:siteId/resources",
|
["/site/:siteId/resources", "/site/:siteId/public-resources"],
|
||||||
verifyApiKeySiteAccess,
|
verifyApiKeySiteAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResources),
|
verifyApiKeyHasAction(ActionsEnum.listResources),
|
||||||
resource.listResources
|
resource.listResources
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/org/:orgId/resources",
|
["/org/:orgId/resources", "/org/:orgId/public-resources"],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResources),
|
verifyApiKeyHasAction(ActionsEnum.listResources),
|
||||||
resource.listResources
|
resource.listResources
|
||||||
@@ -384,6 +426,15 @@ authenticated.put(
|
|||||||
domain.createOrgDomain
|
domain.createOrgDomain
|
||||||
);
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
"/org/:orgId/domain/:domainId",
|
||||||
|
verifyApiKeyOrgAccess,
|
||||||
|
verifyApiKeyDomainAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.updateOrgDomain),
|
||||||
|
domain.updateOrgDomain
|
||||||
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.patch(
|
authenticated.patch(
|
||||||
"/org/:orgId/domain/:domainId",
|
"/org/:orgId/domain/:domainId",
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
@@ -443,42 +494,45 @@ authenticated.delete(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource/:resourceId/roles",
|
["/resource/:resourceId/roles", "/public-resource/:resourceId/roles"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResourceRoles),
|
verifyApiKeyHasAction(ActionsEnum.listResourceRoles),
|
||||||
resource.listResourceRoles
|
resource.listResourceRoles
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource/:resourceId/users",
|
["/resource/:resourceId/users", "/public-resource/:resourceId/users"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResourceUsers),
|
verifyApiKeyHasAction(ActionsEnum.listResourceUsers),
|
||||||
resource.listResourceUsers
|
resource.listResourceUsers
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource/:resourceId",
|
["/resource/:resourceId", "/public-resource/:resourceId"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.getResource),
|
verifyApiKeyHasAction(ActionsEnum.getResource),
|
||||||
resource.getResource
|
resource.getResource
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource-policy/:resourcePolicyId",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId",
|
||||||
|
"/public-resource-policy/:resourcePolicyId"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.getResourcePolicy),
|
verifyApiKeyHasAction(ActionsEnum.getResourcePolicy),
|
||||||
policy.getResourcePolicy
|
policy.getResourcePolicy
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource/:resourceId/policies",
|
["/resource/:resourceId/policies", "/public-resource/:resourceId/policies"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.getResourcePolicy),
|
verifyApiKeyHasAction(ActionsEnum.getResourcePolicy),
|
||||||
resource.getResourcePolicies
|
resource.getResourcePolicies
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId",
|
["/resource/:resourceId", "/public-resource/:resourceId"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.updateResource),
|
verifyApiKeyHasAction(ActionsEnum.updateResource),
|
||||||
@@ -486,15 +540,29 @@ authenticated.post(
|
|||||||
resource.updateResource
|
resource.updateResource
|
||||||
);
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId",
|
||||||
|
"/public-resource-policy/:resourcePolicyId"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.updateResourcePolicy),
|
||||||
|
policy.updateResourcePolicy
|
||||||
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource-policy/:resourcePolicyId",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId",
|
||||||
|
"/public-resource-policy/:resourcePolicyId"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.updateResourcePolicy),
|
verifyApiKeyHasAction(ActionsEnum.updateResourcePolicy),
|
||||||
policy.updateResourcePolicy
|
policy.updateResourcePolicy
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.delete(
|
authenticated.delete(
|
||||||
"/resource/:resourceId",
|
["/resource/:resourceId", "/public-resource/:resourceId"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.deleteResource),
|
verifyApiKeyHasAction(ActionsEnum.deleteResource),
|
||||||
logActionAudit(ActionsEnum.deleteResource),
|
logActionAudit(ActionsEnum.deleteResource),
|
||||||
@@ -502,7 +570,7 @@ authenticated.delete(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource/:resourceId/target",
|
["/resource/:resourceId/target", "/public-resource/:resourceId/target"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.createTarget),
|
verifyApiKeyHasAction(ActionsEnum.createTarget),
|
||||||
@@ -511,14 +579,14 @@ authenticated.put(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource/:resourceId/targets",
|
["/resource/:resourceId/targets", "/public-resource/:resourceId/targets"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listTargets),
|
verifyApiKeyHasAction(ActionsEnum.listTargets),
|
||||||
target.listTargets
|
target.listTargets
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource/:resourceId/rule",
|
["/resource/:resourceId/rule", "/public-resource/:resourceId/rule"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.createResourceRule),
|
verifyApiKeyHasAction(ActionsEnum.createResourceRule),
|
||||||
@@ -527,14 +595,17 @@ authenticated.put(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/resource/:resourceId/rules",
|
["/resource/:resourceId/rules", "/public-resource/:resourceId/rules"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResourceRules),
|
verifyApiKeyHasAction(ActionsEnum.listResourceRules),
|
||||||
resource.listResourceRules
|
resource.listResourceRules
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/rule/:ruleId",
|
[
|
||||||
|
"/resource/:resourceId/rule/:ruleId",
|
||||||
|
"/public-resource/:resourceId/rule/:ruleId"
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.updateResourceRule),
|
verifyApiKeyHasAction(ActionsEnum.updateResourceRule),
|
||||||
@@ -543,7 +614,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.delete(
|
authenticated.delete(
|
||||||
"/resource/:resourceId/rule/:ruleId",
|
[
|
||||||
|
"/resource/:resourceId/rule/:ruleId",
|
||||||
|
"/public-resource/:resourceId/rule/:ruleId"
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.deleteResourceRule),
|
verifyApiKeyHasAction(ActionsEnum.deleteResourceRule),
|
||||||
logActionAudit(ActionsEnum.deleteResourceRule),
|
logActionAudit(ActionsEnum.deleteResourceRule),
|
||||||
@@ -625,7 +699,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/roles",
|
["/resource/:resourceId/roles", "/public-resource/:resourceId/roles"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -635,7 +709,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/users",
|
["/resource/:resourceId/users", "/public-resource/:resourceId/users"],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeySetResourceUsers,
|
verifyApiKeySetResourceUsers,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -644,8 +718,11 @@ authenticated.post(
|
|||||||
resource.setResourceUsers
|
resource.setResourceUsers
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.put(
|
authenticated.post(
|
||||||
"/resource-policy/:resourcePolicyId/access-control",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/access-control",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/access-control"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -656,8 +733,27 @@ authenticated.put(
|
|||||||
policy.setResourcePolicyAccessControl
|
policy.setResourcePolicyAccessControl
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource-policy/:resourcePolicyId/password",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/access-control",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/access-control"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyApiKeyRoleAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyUserHasAction(ActionsEnum.setResourcePolicyUsers),
|
||||||
|
verifyUserHasAction(ActionsEnum.setResourcePolicyRoles),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyUsers),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyRoles),
|
||||||
|
policy.setResourcePolicyAccessControl
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/password",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/password"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyPassword),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyPassword),
|
||||||
@@ -665,8 +761,24 @@ authenticated.put(
|
|||||||
policy.setResourcePolicyPassword
|
policy.setResourcePolicyPassword
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource-policy/:resourcePolicyId/pincode",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/password",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/password"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyPassword),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyPassword),
|
||||||
|
policy.setResourcePolicyPassword
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/pincode",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/pincode"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyPincode),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyPincode),
|
||||||
@@ -674,8 +786,24 @@ authenticated.put(
|
|||||||
policy.setResourcePolicyPincode
|
policy.setResourcePolicyPincode
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource-policy/:resourcePolicyId/header-auth",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/pincode",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/pincode"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyPincode),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyPincode),
|
||||||
|
policy.setResourcePolicyPincode
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/header-auth",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/header-auth"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyHeaderAuth),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyHeaderAuth),
|
||||||
@@ -683,8 +811,24 @@ authenticated.put(
|
|||||||
policy.setResourcePolicyHeaderAuth
|
policy.setResourcePolicyHeaderAuth
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource-policy/:resourcePolicyId/whitelist",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/header-auth",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/header-auth"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyHeaderAuth),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyHeaderAuth),
|
||||||
|
policy.setResourcePolicyHeaderAuth
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/whitelist",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/whitelist"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyWhitelist),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyWhitelist),
|
||||||
@@ -692,8 +836,37 @@ authenticated.put(
|
|||||||
policy.setResourcePolicyWhitelist
|
policy.setResourcePolicyWhitelist
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
authenticated.put(
|
authenticated.put(
|
||||||
"/resource-policy/:resourcePolicyId/rules",
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/whitelist",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/whitelist"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyWhitelist),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyWhitelist),
|
||||||
|
policy.setResourcePolicyWhitelist
|
||||||
|
);
|
||||||
|
|
||||||
|
authenticated.post(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/rules",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/rules"
|
||||||
|
],
|
||||||
|
verifyApiKeyResourcePolicyAccess,
|
||||||
|
verifyLimits,
|
||||||
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyRules),
|
||||||
|
logActionAudit(ActionsEnum.setResourcePolicyRules),
|
||||||
|
policy.setResourcePolicyRules
|
||||||
|
);
|
||||||
|
|
||||||
|
// Deprecated: use POST instead. Kept for backward compatibility.
|
||||||
|
authenticated.put(
|
||||||
|
[
|
||||||
|
"/resource-policy/:resourcePolicyId/rules",
|
||||||
|
"/public-resource-policy/:resourcePolicyId/rules"
|
||||||
|
],
|
||||||
verifyApiKeyResourcePolicyAccess,
|
verifyApiKeyResourcePolicyAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyRules),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePolicyRules),
|
||||||
@@ -702,7 +875,10 @@ authenticated.put(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/roles/add",
|
[
|
||||||
|
"/resource/:resourceId/roles/add",
|
||||||
|
"/public-resource/:resourceId/roles/add"
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -712,7 +888,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/roles/remove",
|
[
|
||||||
|
"/resource/:resourceId/roles/remove",
|
||||||
|
"/public-resource/:resourceId/roles/remove"
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyRoleAccess,
|
verifyApiKeyRoleAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -722,7 +901,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/users/add",
|
[
|
||||||
|
"/resource/:resourceId/users/add",
|
||||||
|
"/public-resource/:resourceId/users/add"
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeySetResourceUsers,
|
verifyApiKeySetResourceUsers,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -732,7 +914,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
"/resource/:resourceId/users/remove",
|
[
|
||||||
|
"/resource/:resourceId/users/remove",
|
||||||
|
"/public-resource/:resourceId/users/remove"
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeySetResourceUsers,
|
verifyApiKeySetResourceUsers,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
@@ -742,7 +927,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/password`,
|
[`/resource/:resourceId/password`, `/public-resource/:resourceId/password`],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePassword),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePassword),
|
||||||
@@ -751,7 +936,7 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/pincode`,
|
[`/resource/:resourceId/pincode`, `/public-resource/:resourceId/pincode`],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourcePincode),
|
verifyApiKeyHasAction(ActionsEnum.setResourcePincode),
|
||||||
@@ -760,7 +945,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/header-auth`,
|
[
|
||||||
|
`/resource/:resourceId/header-auth`,
|
||||||
|
`/public-resource/:resourceId/header-auth`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourceHeaderAuth),
|
verifyApiKeyHasAction(ActionsEnum.setResourceHeaderAuth),
|
||||||
@@ -769,7 +957,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/whitelist`,
|
[
|
||||||
|
`/resource/:resourceId/whitelist`,
|
||||||
|
`/public-resource/:resourceId/whitelist`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourceWhitelist),
|
verifyApiKeyHasAction(ActionsEnum.setResourceWhitelist),
|
||||||
@@ -778,7 +969,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/whitelist/add`,
|
[
|
||||||
|
`/resource/:resourceId/whitelist/add`,
|
||||||
|
`/public-resource/:resourceId/whitelist/add`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourceWhitelist),
|
verifyApiKeyHasAction(ActionsEnum.setResourceWhitelist),
|
||||||
@@ -786,7 +980,10 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/whitelist/remove`,
|
[
|
||||||
|
`/resource/:resourceId/whitelist/remove`,
|
||||||
|
`/public-resource/:resourceId/whitelist/remove`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.setResourceWhitelist),
|
verifyApiKeyHasAction(ActionsEnum.setResourceWhitelist),
|
||||||
@@ -794,14 +991,20 @@ authenticated.post(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
`/resource/:resourceId/whitelist`,
|
[
|
||||||
|
`/resource/:resourceId/whitelist`,
|
||||||
|
`/public-resource/:resourceId/whitelist`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.getResourceWhitelist),
|
verifyApiKeyHasAction(ActionsEnum.getResourceWhitelist),
|
||||||
resource.getResourceWhitelist
|
resource.getResourceWhitelist
|
||||||
);
|
);
|
||||||
|
|
||||||
authenticated.post(
|
authenticated.post(
|
||||||
`/resource/:resourceId/access-token`,
|
[
|
||||||
|
`/resource/:resourceId/access-token`,
|
||||||
|
`/public-resource/:resourceId/access-token`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyLimits,
|
verifyLimits,
|
||||||
verifyApiKeyHasAction(ActionsEnum.generateAccessToken),
|
verifyApiKeyHasAction(ActionsEnum.generateAccessToken),
|
||||||
@@ -825,7 +1028,10 @@ authenticated.get(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
`/resource/:resourceId/access-tokens`,
|
[
|
||||||
|
`/resource/:resourceId/access-tokens`,
|
||||||
|
`/public-resource/:resourceId/access-tokens`
|
||||||
|
],
|
||||||
verifyApiKeyResourceAccess,
|
verifyApiKeyResourceAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listAccessTokens),
|
verifyApiKeyHasAction(ActionsEnum.listAccessTokens),
|
||||||
accessToken.listAccessTokens
|
accessToken.listAccessTokens
|
||||||
@@ -1155,7 +1361,7 @@ authenticated.get(
|
|||||||
);
|
);
|
||||||
|
|
||||||
authenticated.get(
|
authenticated.get(
|
||||||
"/org/:orgId/resource-names",
|
["/org/:orgId/resource-names", "/org/:orgId/public-resource-names"],
|
||||||
verifyApiKeyOrgAccess,
|
verifyApiKeyOrgAccess,
|
||||||
verifyApiKeyHasAction(ActionsEnum.listResources),
|
verifyApiKeyHasAction(ActionsEnum.listResources),
|
||||||
resource.listAllResourceNames
|
resource.listAllResourceNames
|
||||||
|
|||||||
@@ -168,7 +168,7 @@ registry.registerPath({
|
|||||||
path: "/org/{orgId}/resource-policy/{niceId}",
|
path: "/org/{orgId}/resource-policy/{niceId}",
|
||||||
description:
|
description:
|
||||||
"Get a resource policy by orgId and niceId. NiceId is a readable ID for the resource and unique on a per org basis.",
|
"Get a resource policy by orgId and niceId. NiceId is a readable ID for the resource and unique on a per org basis.",
|
||||||
tags: [OpenAPITags.Org, OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
orgId: z.string(),
|
orgId: z.string(),
|
||||||
@@ -182,7 +182,20 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource-policy/{resourcePolicyId}",
|
path: "/resource-policy/{resourcePolicyId}",
|
||||||
description: "Get a resource policy by its resourcePolicyId.",
|
description: "Get a resource policy by its resourcePolicyId.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
resourcePolicyId: z.number()
|
||||||
|
})
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}",
|
||||||
|
description: "Get a resource policy by its resourcePolicyId.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
resourcePolicyId: z.number()
|
resourcePolicyId: z.number()
|
||||||
|
|||||||
@@ -40,7 +40,66 @@ registry.registerPath({
|
|||||||
path: "/resource-policy/{resourceId}/access-control",
|
path: "/resource-policy/{resourceId}/access-control",
|
||||||
description:
|
description:
|
||||||
"Set access control users for a resource policy, including SSO, users, roles, Identity provider.",
|
"Set access control users for a resource policy, including SSO, users, roles, Identity provider.",
|
||||||
tags: [OpenAPITags.Policy, OpenAPITags.User],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyAccessControlParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyAcccessControlBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourceId}/access-control",
|
||||||
|
description:
|
||||||
|
"Set access control users for a resource policy, including SSO, users, roles, Identity provider.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy, OpenAPITags.User],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyAccessControlParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyAcccessControlBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourceId}/access-control",
|
||||||
|
description:
|
||||||
|
"Set access control users for a resource policy, including SSO, users, roles, Identity provider. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyAccessControlParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyAcccessControlBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourceId}/access-control",
|
||||||
|
description:
|
||||||
|
"Set access control users for a resource policy, including SSO, users, roles, Identity provider. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy, OpenAPITags.User],
|
||||||
request: {
|
request: {
|
||||||
params: setResourcePolicyAccessControlParamsSchema,
|
params: setResourcePolicyAccessControlParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -25,11 +25,70 @@ const setResourcePolicyHeaderAuthBodySchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "put",
|
method: "post",
|
||||||
path: "/resource-policy/{resourcePolicyId}/header-auth",
|
path: "/resource-policy/{resourcePolicyId}/header-auth",
|
||||||
description:
|
description:
|
||||||
"Set or update the header authentication for a resource policy. If user and password is not provided, it will remove the header authentication.",
|
"Set or update the header authentication for a resource policy. If user and password is not provided, it will remove the header authentication.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyHeaderAuthParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyHeaderAuthBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/header-auth",
|
||||||
|
description:
|
||||||
|
"Set or update the header authentication for a resource policy. If user and password is not provided, it will remove the header authentication.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyHeaderAuthParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyHeaderAuthBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourcePolicyId}/header-auth",
|
||||||
|
description:
|
||||||
|
"Set or update the header authentication for a resource policy. If user and password is not provided, it will remove the header authentication. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyHeaderAuthParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyHeaderAuthBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/header-auth",
|
||||||
|
description:
|
||||||
|
"Set or update the header authentication for a resource policy. If user and password is not provided, it will remove the header authentication. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: setResourcePolicyHeaderAuthParamsSchema,
|
params: setResourcePolicyHeaderAuthParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -20,11 +20,70 @@ const setResourcePolicyPasswordBodySchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "put",
|
method: "post",
|
||||||
path: "/resource-policy/{resourcePolicyId}/password",
|
path: "/resource-policy/{resourcePolicyId}/password",
|
||||||
description:
|
description:
|
||||||
"Set the password for a resource policy. Setting the password to null will remove it.",
|
"Set the password for a resource policy. Setting the password to null will remove it.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyPasswordParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyPasswordBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/password",
|
||||||
|
description:
|
||||||
|
"Set the password for a resource policy. Setting the password to null will remove it.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyPasswordParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyPasswordBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourcePolicyId}/password",
|
||||||
|
description:
|
||||||
|
"Set the password for a resource policy. Setting the password to null will remove it. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyPasswordParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyPasswordBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/password",
|
||||||
|
description:
|
||||||
|
"Set the password for a resource policy. Setting the password to null will remove it. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: setResourcePolicyPasswordParamsSchema,
|
params: setResourcePolicyPasswordParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -23,11 +23,70 @@ const setResourcePolicyPincodeBodySchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "put",
|
method: "post",
|
||||||
path: "/resource-policy/{resourcePolicyId}/pincode",
|
path: "/resource-policy/{resourcePolicyId}/pincode",
|
||||||
description:
|
description:
|
||||||
"Set the PIN code for a resource policy. Setting the PIN code to null will remove it.",
|
"Set the PIN code for a resource policy. Setting the PIN code to null will remove it.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyPincodeParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyPincodeBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/pincode",
|
||||||
|
description:
|
||||||
|
"Set the PIN code for a resource policy. Setting the PIN code to null will remove it.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyPincodeParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyPincodeBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourcePolicyId}/pincode",
|
||||||
|
description:
|
||||||
|
"Set the PIN code for a resource policy. Setting the PIN code to null will remove it. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyPincodeParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyPincodeBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/pincode",
|
||||||
|
description:
|
||||||
|
"Set the PIN code for a resource policy. Setting the PIN code to null will remove it. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: setResourcePolicyPincodeParamsSchema,
|
params: setResourcePolicyPincodeParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -43,11 +43,70 @@ const setResourcePolicyRulesParamsSchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "put",
|
method: "post",
|
||||||
path: "/resource-policy/{resourcePolicyId}/rules",
|
path: "/resource-policy/{resourcePolicyId}/rules",
|
||||||
description:
|
description:
|
||||||
"Set all rules for a resource policy at once. This will replace all existing rules.",
|
"Set all rules for a resource policy at once. This will replace all existing rules.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyRulesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyRulesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/rules",
|
||||||
|
description:
|
||||||
|
"Set all rules for a resource policy at once. This will replace all existing rules.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyRulesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyRulesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourcePolicyId}/rules",
|
||||||
|
description:
|
||||||
|
"Set all rules for a resource policy at once. This will replace all existing rules. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyRulesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyRulesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/rules",
|
||||||
|
description:
|
||||||
|
"Set all rules for a resource policy at once. This will replace all existing rules. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: setResourcePolicyRulesParamsSchema,
|
params: setResourcePolicyRulesParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -28,11 +28,70 @@ const setResourcePolicyWhitelistParamsSchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "put",
|
method: "post",
|
||||||
path: "/resource-policy/{resourcePolicyId}/whitelist",
|
path: "/resource-policy/{resourcePolicyId}/whitelist",
|
||||||
description:
|
description:
|
||||||
"Set email whitelist for a resource policy. This will replace all existing emails.",
|
"Set email whitelist for a resource policy. This will replace all existing emails.",
|
||||||
tags: [OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyWhitelistParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyWhitelistBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/whitelist",
|
||||||
|
description:
|
||||||
|
"Set email whitelist for a resource policy. This will replace all existing emails.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyWhitelistParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyWhitelistBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourcePolicyId}/whitelist",
|
||||||
|
description:
|
||||||
|
"Set email whitelist for a resource policy. This will replace all existing emails. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicyLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourcePolicyWhitelistParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourcePolicyWhitelistBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}/whitelist",
|
||||||
|
description:
|
||||||
|
"Set email whitelist for a resource policy. This will replace all existing emails. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: setResourcePolicyWhitelistParamsSchema,
|
params: setResourcePolicyWhitelistParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -19,10 +19,66 @@ const updateResourcePolicyBodySchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "put",
|
method: "post",
|
||||||
path: "/resource-policy/{resourcePolicyId}",
|
path: "/resource-policy/{resourcePolicyId}",
|
||||||
description: "Update a resource policy.",
|
description: "Update a resource policy.",
|
||||||
tags: [OpenAPITags.Org, OpenAPITags.Policy],
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: updateResourcePolicyParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: updateResourcePolicyBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}",
|
||||||
|
description: "Update a resource policy.",
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: updateResourcePolicyParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: updateResourcePolicyBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/resource-policy/{resourcePolicyId}",
|
||||||
|
description: "Update a resource policy. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
|
request: {
|
||||||
|
params: updateResourcePolicyParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: updateResourcePolicyBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource-policy/{resourcePolicyId}",
|
||||||
|
description: "Update a resource policy. Deprecated: use POST instead.",
|
||||||
|
deprecated: true,
|
||||||
|
tags: [OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: updateResourcePolicyParamsSchema,
|
params: updateResourcePolicyParamsSchema,
|
||||||
body: {
|
body: {
|
||||||
|
|||||||
@@ -34,6 +34,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/whitelist/add",
|
path: "/resource/{resourceId}/whitelist/add",
|
||||||
description: "Add a single email to the resource whitelist.",
|
description: "Add a single email to the resource whitelist.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: addEmailToResourceWhitelistParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: addEmailToResourceWhitelistBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/whitelist/add",
|
||||||
|
description: "Add a single email to the resource whitelist.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: addEmailToResourceWhitelistParamsSchema,
|
params: addEmailToResourceWhitelistParamsSchema,
|
||||||
@@ -144,10 +177,7 @@ export async function addEmailToResourceWhitelist(
|
|||||||
.from(resourcePolicyWhiteList)
|
.from(resourcePolicyWhiteList)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(
|
eq(resourcePolicyWhiteList.resourcePolicyId, policyId),
|
||||||
resourcePolicyWhiteList.resourcePolicyId,
|
|
||||||
policyId
|
|
||||||
),
|
|
||||||
eq(resourcePolicyWhiteList.email, email)
|
eq(resourcePolicyWhiteList.email, email)
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -28,6 +28,40 @@ const addRoleToResourceParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/roles/add",
|
path: "/resource/{resourceId}/roles/add",
|
||||||
|
description:
|
||||||
|
"Add a single role to a resource. When the resource has an inline policy defined (no shared resource policy assigned), the role is added to the inline policy instead of directly to the resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: addRoleToResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: addRoleToResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/roles/add",
|
||||||
description:
|
description:
|
||||||
"Add a single role to a resource. When the resource has an inline policy defined (no shared resource policy assigned), the role is added to the inline policy instead of directly to the resource.",
|
"Add a single role to a resource. When the resource has an inline policy defined (no shared resource policy assigned), the role is added to the inline policy instead of directly to the resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
||||||
|
|||||||
@@ -28,6 +28,40 @@ const addUserToResourceParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/users/add",
|
path: "/resource/{resourceId}/users/add",
|
||||||
|
description:
|
||||||
|
"Add a single user to a resource. When the resource has an inline policy defined (no shared resource policy assigned), the user is added to the inline policy instead of directly to the resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: addUserToResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: addUserToResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/users/add",
|
||||||
description:
|
description:
|
||||||
"Add a single user to a resource. When the resource has an inline policy defined (no shared resource policy assigned), the user is added to the inline policy instead of directly to the resource.",
|
"Add a single user to a resource. When the resource has an inline policy defined (no shared resource policy assigned), the user is added to the inline policy instead of directly to the resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
||||||
|
|||||||
@@ -153,6 +153,39 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/org/{orgId}/resource",
|
path: "/org/{orgId}/resource",
|
||||||
description: "Create a resource.",
|
description: "Create a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: createResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: createHttpResourceSchema.or(createRawResourceSchema)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/org/{orgId}/public-resource",
|
||||||
|
description: "Create a resource.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: createResourceParamsSchema,
|
params: createResourceParamsSchema,
|
||||||
|
|||||||
@@ -9,16 +9,14 @@ import createHttpError from "http-errors";
|
|||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { fromError } from "zod-validation-error";
|
import { fromError } from "zod-validation-error";
|
||||||
import {
|
import {
|
||||||
isValidCIDR,
|
RESOURCE_RULE_MATCH_TYPES,
|
||||||
isValidIP,
|
getResourceRuleValueValidationError
|
||||||
isValidUrlGlobPattern
|
|
||||||
} from "@server/lib/validators";
|
} from "@server/lib/validators";
|
||||||
import { OpenAPITags, registry } from "@server/openApi";
|
import { OpenAPITags, registry } from "@server/openApi";
|
||||||
import { isValidRegionId } from "@server/db/regions";
|
|
||||||
|
|
||||||
const createResourceRuleSchema = z.strictObject({
|
const createResourceRuleSchema = z.strictObject({
|
||||||
action: z.enum(["ACCEPT", "DROP", "PASS"]),
|
action: z.enum(["ACCEPT", "DROP", "PASS"]),
|
||||||
match: z.enum(["CIDR", "IP", "PATH", "COUNTRY", "ASN", "REGION"]),
|
match: z.enum(RESOURCE_RULE_MATCH_TYPES),
|
||||||
value: z.string().min(1),
|
value: z.string().min(1),
|
||||||
priority: z.int(),
|
priority: z.int(),
|
||||||
enabled: z.boolean().optional()
|
enabled: z.boolean().optional()
|
||||||
@@ -32,6 +30,39 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/resource/{resourceId}/rule",
|
path: "/resource/{resourceId}/rule",
|
||||||
description: "Create a resource rule.",
|
description: "Create a resource rule.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: createResourceRuleParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: createResourceRuleSchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource/{resourceId}/rule",
|
||||||
|
description: "Create a resource rule.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
||||||
request: {
|
request: {
|
||||||
params: createResourceRuleParamsSchema,
|
params: createResourceRuleParamsSchema,
|
||||||
@@ -118,39 +149,14 @@ export async function createResourceRule(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (match === "CIDR") {
|
const valueValidationError = getResourceRuleValueValidationError(
|
||||||
if (!isValidCIDR(value)) {
|
match,
|
||||||
return next(
|
value
|
||||||
createHttpError(
|
);
|
||||||
HttpCode.BAD_REQUEST,
|
if (valueValidationError) {
|
||||||
"Invalid CIDR provided"
|
return next(
|
||||||
)
|
createHttpError(HttpCode.BAD_REQUEST, valueValidationError)
|
||||||
);
|
);
|
||||||
}
|
|
||||||
} else if (match === "IP") {
|
|
||||||
if (!isValidIP(value)) {
|
|
||||||
return next(
|
|
||||||
createHttpError(HttpCode.BAD_REQUEST, "Invalid IP provided")
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} else if (match === "PATH") {
|
|
||||||
if (!isValidUrlGlobPattern(value)) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invalid URL glob pattern provided"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} else if (match === "REGION") {
|
|
||||||
if (!isValidRegionId(value)) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invalid region ID provided"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Create the new resource rule
|
// Create the new resource rule
|
||||||
|
|||||||
@@ -22,6 +22,32 @@ registry.registerPath({
|
|||||||
method: "delete",
|
method: "delete",
|
||||||
path: "/resource/{resourceId}",
|
path: "/resource/{resourceId}",
|
||||||
description: "Delete a resource.",
|
description: "Delete a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: deleteResourceSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "delete",
|
||||||
|
path: "/public-resource/{resourceId}",
|
||||||
|
description: "Delete a resource.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: deleteResourceSchema
|
params: deleteResourceSchema
|
||||||
|
|||||||
@@ -19,6 +19,32 @@ registry.registerPath({
|
|||||||
method: "delete",
|
method: "delete",
|
||||||
path: "/resource/{resourceId}/rule/{ruleId}",
|
path: "/resource/{resourceId}/rule/{ruleId}",
|
||||||
description: "Delete a resource rule.",
|
description: "Delete a resource rule.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: deleteResourceRuleSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "delete",
|
||||||
|
path: "/public-resource/{resourceId}/rule/{ruleId}",
|
||||||
|
description: "Delete a resource rule.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
||||||
request: {
|
request: {
|
||||||
params: deleteResourceRuleSchema
|
params: deleteResourceRuleSchema
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ registry.registerPath({
|
|||||||
path: "/org/{orgId}/resource/{niceId}",
|
path: "/org/{orgId}/resource/{niceId}",
|
||||||
description:
|
description:
|
||||||
"Get a resource by orgId and niceId. NiceId is a readable ID for the resource and unique on a per org basis.",
|
"Get a resource by orgId and niceId. NiceId is a readable ID for the resource and unique on a per org basis.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
orgId: z.string(),
|
orgId: z.string(),
|
||||||
@@ -92,6 +92,34 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}",
|
path: "/resource/{resourceId}",
|
||||||
description: "Get a resource by resourceId.",
|
description: "Get a resource by resourceId.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
resourceId: z.number()
|
||||||
|
})
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}",
|
||||||
|
description: "Get a resource by resourceId.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
|
|||||||
@@ -25,8 +25,21 @@ export type GetResourcePoliciesResponse = {
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/policies",
|
path: "/resource/{resourceId}/policies",
|
||||||
description: "Get the inline and shared policies associated with a resource.",
|
description:
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Policy],
|
"Get the inline and shared policies associated with a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: getResourcePoliciesParamsSchema
|
||||||
|
},
|
||||||
|
responses: {}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/policies",
|
||||||
|
description:
|
||||||
|
"Get the inline and shared policies associated with a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResource, OpenAPITags.PublicResourcePolicy],
|
||||||
request: {
|
request: {
|
||||||
params: getResourcePoliciesParamsSchema
|
params: getResourcePoliciesParamsSchema
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -44,6 +44,32 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/whitelist",
|
path: "/resource/{resourceId}/whitelist",
|
||||||
description: "Get the whitelist of emails for a specific resource.",
|
description: "Get the whitelist of emails for a specific resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: getResourceWhitelistSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/whitelist",
|
||||||
|
description: "Get the whitelist of emails for a specific resource.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: getResourceWhitelistSchema
|
params: getResourceWhitelistSchema
|
||||||
|
|||||||
@@ -33,6 +33,34 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/resources-names",
|
path: "/org/{orgId}/resources-names",
|
||||||
description: "List all resource names for an organization.",
|
description: "List all resource names for an organization.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
orgId: z.string()
|
||||||
|
})
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/org/{orgId}/public-resource-names",
|
||||||
|
description: "List all resource names for an organization.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
|
|||||||
@@ -48,6 +48,32 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/roles",
|
path: "/resource/{resourceId}/roles",
|
||||||
description: "List all roles for a resource.",
|
description: "List all roles for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listResourceRolesSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/roles",
|
||||||
|
description: "List all roles for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
||||||
request: {
|
request: {
|
||||||
params: listResourceRolesSchema
|
params: listResourceRolesSchema
|
||||||
|
|||||||
@@ -71,6 +71,33 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/rules",
|
path: "/resource/{resourceId}/rules",
|
||||||
description: "List rules for a resource.",
|
description: "List rules for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listResourceRulesParamsSchema,
|
||||||
|
query: listResourceRulesSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/rules",
|
||||||
|
description: "List rules for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
||||||
request: {
|
request: {
|
||||||
params: listResourceRulesParamsSchema,
|
params: listResourceRulesParamsSchema,
|
||||||
|
|||||||
@@ -38,6 +38,32 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/users",
|
path: "/resource/{resourceId}/users",
|
||||||
description: "List all users for a resource.",
|
description: "List all users for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listResourceUsersSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/users",
|
||||||
|
description: "List all users for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
||||||
request: {
|
request: {
|
||||||
params: listResourceUsersSchema
|
params: listResourceUsersSchema
|
||||||
|
|||||||
@@ -409,6 +409,35 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/resources",
|
path: "/org/{orgId}/resources",
|
||||||
description: "List resources for an organization.",
|
description: "List resources for an organization.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
orgId: z.string()
|
||||||
|
}),
|
||||||
|
query: listResourcesSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/org/{orgId}/public-resources",
|
||||||
|
description: "List resources for an organization.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
|
|||||||
@@ -34,6 +34,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/whitelist/remove",
|
path: "/resource/{resourceId}/whitelist/remove",
|
||||||
description: "Remove a single email from the resource whitelist.",
|
description: "Remove a single email from the resource whitelist.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: removeEmailFromResourceWhitelistParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: removeEmailFromResourceWhitelistBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/whitelist/remove",
|
||||||
|
description: "Remove a single email from the resource whitelist.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
request: {
|
request: {
|
||||||
params: removeEmailFromResourceWhitelistParamsSchema,
|
params: removeEmailFromResourceWhitelistParamsSchema,
|
||||||
@@ -143,10 +176,7 @@ export async function removeEmailFromResourceWhitelist(
|
|||||||
.from(resourcePolicyWhiteList)
|
.from(resourcePolicyWhiteList)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(
|
eq(resourcePolicyWhiteList.resourcePolicyId, policyId),
|
||||||
resourcePolicyWhiteList.resourcePolicyId,
|
|
||||||
policyId
|
|
||||||
),
|
|
||||||
eq(resourcePolicyWhiteList.email, email)
|
eq(resourcePolicyWhiteList.email, email)
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
@@ -164,10 +194,7 @@ export async function removeEmailFromResourceWhitelist(
|
|||||||
.delete(resourcePolicyWhiteList)
|
.delete(resourcePolicyWhiteList)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(
|
eq(resourcePolicyWhiteList.resourcePolicyId, policyId),
|
||||||
resourcePolicyWhiteList.resourcePolicyId,
|
|
||||||
policyId
|
|
||||||
),
|
|
||||||
eq(resourcePolicyWhiteList.email, email)
|
eq(resourcePolicyWhiteList.email, email)
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -29,6 +29,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/roles/remove",
|
path: "/resource/{resourceId}/roles/remove",
|
||||||
description: "Remove a single role from a resource.",
|
description: "Remove a single role from a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: removeRoleFromResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: removeRoleFromResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/roles/remove",
|
||||||
|
description: "Remove a single role from a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
||||||
request: {
|
request: {
|
||||||
params: removeRoleFromResourceParamsSchema,
|
params: removeRoleFromResourceParamsSchema,
|
||||||
|
|||||||
@@ -29,6 +29,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/users/remove",
|
path: "/resource/{resourceId}/users/remove",
|
||||||
description: "Remove a single user from a resource.",
|
description: "Remove a single user from a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: removeUserFromResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: removeUserFromResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/users/remove",
|
||||||
|
description: "Remove a single user from a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
||||||
request: {
|
request: {
|
||||||
params: removeUserFromResourceParamsSchema,
|
params: removeUserFromResourceParamsSchema,
|
||||||
|
|||||||
@@ -29,6 +29,40 @@ const setResourceAuthMethodsBodySchema = z.strictObject({
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/header-auth",
|
path: "/resource/{resourceId}/header-auth",
|
||||||
|
description:
|
||||||
|
"Set or update the header authentication for a resource. If user and password is not provided, it will remove the header authentication.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourceAuthMethodsParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourceAuthMethodsBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/header-auth",
|
||||||
description:
|
description:
|
||||||
"Set or update the header authentication for a resource. If user and password is not provided, it will remove the header authentication.",
|
"Set or update the header authentication for a resource. If user and password is not provided, it will remove the header authentication.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
|
|||||||
@@ -27,6 +27,40 @@ const setResourceAuthMethodsBodySchema = z.strictObject({
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/password",
|
path: "/resource/{resourceId}/password",
|
||||||
|
description:
|
||||||
|
"Set the password for a resource. Setting the password to null will remove it.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourceAuthMethodsParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourceAuthMethodsBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/password",
|
||||||
description:
|
description:
|
||||||
"Set the password for a resource. Setting the password to null will remove it.",
|
"Set the password for a resource. Setting the password to null will remove it.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
|
|||||||
@@ -27,6 +27,40 @@ const setResourceAuthMethodsBodySchema = z.strictObject({
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/pincode",
|
path: "/resource/{resourceId}/pincode",
|
||||||
|
description:
|
||||||
|
"Set the PIN code for a resource. Setting the PIN code to null will remove it.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourceAuthMethodsParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourceAuthMethodsBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/pincode",
|
||||||
description:
|
description:
|
||||||
"Set the PIN code for a resource. Setting the PIN code to null will remove it.",
|
"Set the PIN code for a resource. Setting the PIN code to null will remove it.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
|
|||||||
@@ -21,6 +21,40 @@ const setResourceRolesParamsSchema = z.strictObject({
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/roles",
|
path: "/resource/{resourceId}/roles",
|
||||||
|
description:
|
||||||
|
"Set roles for a resource. This will replace all existing roles. When the resource has an inline policy defined (no shared resource policy assigned), roles are set on the inline policy instead of directly on the resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourceRolesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourceRolesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/roles",
|
||||||
description:
|
description:
|
||||||
"Set roles for a resource. This will replace all existing roles. When the resource has an inline policy defined (no shared resource policy assigned), roles are set on the inline policy instead of directly on the resource.",
|
"Set roles for a resource. This will replace all existing roles. When the resource has an inline policy defined (no shared resource policy assigned), roles are set on the inline policy instead of directly on the resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Role],
|
||||||
|
|||||||
@@ -21,6 +21,40 @@ const setUserResourcesParamsSchema = z.strictObject({
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/users",
|
path: "/resource/{resourceId}/users",
|
||||||
|
description:
|
||||||
|
"Set users for a resource. This will replace all existing users. When the resource has an inline policy defined (no shared resource policy assigned), users are set on the inline policy instead of directly on the resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setUserResourcesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setUserResourcesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/users",
|
||||||
description:
|
description:
|
||||||
"Set users for a resource. This will replace all existing users. When the resource has an inline policy defined (no shared resource policy assigned), users are set on the inline policy instead of directly on the resource.",
|
"Set users for a resource. This will replace all existing users. When the resource has an inline policy defined (no shared resource policy assigned), users are set on the inline policy instead of directly on the resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.User],
|
||||||
|
|||||||
@@ -35,6 +35,40 @@ const setResourceWhitelistParamsSchema = z.strictObject({
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/whitelist",
|
path: "/resource/{resourceId}/whitelist",
|
||||||
|
description:
|
||||||
|
"Set email whitelist for a resource. This will replace all existing emails.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setResourceWhitelistParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setResourceWhitelistBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/whitelist",
|
||||||
description:
|
description:
|
||||||
"Set email whitelist for a resource. This will replace all existing emails.",
|
"Set email whitelist for a resource. This will replace all existing emails.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
|
|||||||
@@ -240,6 +240,42 @@ const updateRawResourceBodySchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}",
|
path: "/resource/{resourceId}",
|
||||||
|
description:
|
||||||
|
"Update a resource. Policy fields (sso, mfa, pincode, password, whitelist) update the inline policy when no shared resource policy is assigned; when a shared policy is assigned those fields override the shared policy for this resource only.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: updateResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: updateHttpResourceBodySchema.and(
|
||||||
|
updateRawResourceBodySchema
|
||||||
|
)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}",
|
||||||
description:
|
description:
|
||||||
"Update a resource. Policy fields (sso, mfa, pincode, password, whitelist) update the inline policy when no shared resource policy is assigned; when a shared policy is assigned those fields override the shared policy for this resource only.",
|
"Update a resource. Policy fields (sso, mfa, pincode, password, whitelist) update the inline policy when no shared resource policy is assigned; when a shared policy is assigned those fields override the shared policy for this resource only.",
|
||||||
tags: [OpenAPITags.PublicResource],
|
tags: [OpenAPITags.PublicResource],
|
||||||
|
|||||||
@@ -9,12 +9,11 @@ import createHttpError from "http-errors";
|
|||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { fromError } from "zod-validation-error";
|
import { fromError } from "zod-validation-error";
|
||||||
import {
|
import {
|
||||||
isValidCIDR,
|
RESOURCE_RULE_MATCH_TYPES,
|
||||||
isValidIP,
|
getResourceRuleValueValidationError,
|
||||||
isValidUrlGlobPattern
|
ResourceRuleMatchType
|
||||||
} from "@server/lib/validators";
|
} from "@server/lib/validators";
|
||||||
import { OpenAPITags, registry } from "@server/openApi";
|
import { OpenAPITags, registry } from "@server/openApi";
|
||||||
import { isValidRegionId } from "@server/db/regions";
|
|
||||||
|
|
||||||
// Define Zod schema for request parameters validation
|
// Define Zod schema for request parameters validation
|
||||||
const updateResourceRuleParamsSchema = z.strictObject({
|
const updateResourceRuleParamsSchema = z.strictObject({
|
||||||
@@ -22,15 +21,7 @@ const updateResourceRuleParamsSchema = z.strictObject({
|
|||||||
resourceId: z.coerce.number().int().positive()
|
resourceId: z.coerce.number().int().positive()
|
||||||
});
|
});
|
||||||
|
|
||||||
const resourceRuleMatchSchema = z.enum([
|
const resourceRuleMatchSchema = z.enum(RESOURCE_RULE_MATCH_TYPES);
|
||||||
"CIDR",
|
|
||||||
"IP",
|
|
||||||
"PATH",
|
|
||||||
"COUNTRY",
|
|
||||||
"COUNTRY_IS_NOT",
|
|
||||||
"ASN",
|
|
||||||
"REGION"
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Define Zod schema for request body validation
|
// Define Zod schema for request body validation
|
||||||
const updateResourceRuleSchema = z
|
const updateResourceRuleSchema = z
|
||||||
@@ -49,6 +40,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/resource/{resourceId}/rule/{ruleId}",
|
path: "/resource/{resourceId}/rule/{ruleId}",
|
||||||
description: "Update a resource rule.",
|
description: "Update a resource rule.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: updateResourceRuleParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: updateResourceRuleSchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/public-resource/{resourceId}/rule/{ruleId}",
|
||||||
|
description: "Update a resource rule.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Rule],
|
||||||
request: {
|
request: {
|
||||||
params: updateResourceRuleParamsSchema,
|
params: updateResourceRuleParamsSchema,
|
||||||
@@ -140,14 +164,7 @@ export async function updateResourceRule(
|
|||||||
resource.resourcePolicyId === null &&
|
resource.resourcePolicyId === null &&
|
||||||
resource.defaultResourcePolicyId !== null;
|
resource.defaultResourcePolicyId !== null;
|
||||||
|
|
||||||
let existingMatch:
|
let existingMatch: ResourceRuleMatchType;
|
||||||
| "CIDR"
|
|
||||||
| "IP"
|
|
||||||
| "PATH"
|
|
||||||
| "COUNTRY"
|
|
||||||
| "COUNTRY_IS_NOT"
|
|
||||||
| "ASN"
|
|
||||||
| "REGION";
|
|
||||||
|
|
||||||
if (isInlinePolicy) {
|
if (isInlinePolicy) {
|
||||||
const policyId = resource.defaultResourcePolicyId!;
|
const policyId = resource.defaultResourcePolicyId!;
|
||||||
@@ -231,42 +248,14 @@ export async function updateResourceRule(
|
|||||||
const { value } = updateData;
|
const { value } = updateData;
|
||||||
|
|
||||||
if (value !== undefined) {
|
if (value !== undefined) {
|
||||||
if (match === "CIDR") {
|
const valueValidationError = getResourceRuleValueValidationError(
|
||||||
if (!isValidCIDR(value)) {
|
match,
|
||||||
return next(
|
value
|
||||||
createHttpError(
|
);
|
||||||
HttpCode.BAD_REQUEST,
|
if (valueValidationError) {
|
||||||
"Invalid CIDR provided"
|
return next(
|
||||||
)
|
createHttpError(HttpCode.BAD_REQUEST, valueValidationError)
|
||||||
);
|
);
|
||||||
}
|
|
||||||
} else if (match === "IP") {
|
|
||||||
if (!isValidIP(value)) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invalid IP provided"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} else if (match === "PATH") {
|
|
||||||
if (!isValidUrlGlobPattern(value)) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invalid URL glob pattern provided"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} else if (match === "REGION") {
|
|
||||||
if (!isValidRegionId(value)) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invalid region ID provided"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -177,7 +177,7 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/sites",
|
path: "/org/{orgId}/sites",
|
||||||
description: "List all sites in an organization",
|
description: "List all sites in an organization",
|
||||||
tags: [OpenAPITags.Org, OpenAPITags.Site],
|
tags: [OpenAPITags.Site],
|
||||||
request: {
|
request: {
|
||||||
params: listSitesParamsSchema,
|
params: listSitesParamsSchema,
|
||||||
query: listSitesSchema
|
query: listSitesSchema
|
||||||
|
|||||||
@@ -31,6 +31,40 @@ const addClientToSiteResourceParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/clients/add",
|
path: "/site-resource/{siteResourceId}/clients/add",
|
||||||
|
description:
|
||||||
|
"Add a single client to a site resource. Clients with a userId cannot be added.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: addClientToSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: addClientToSiteResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/clients/add",
|
||||||
description:
|
description:
|
||||||
"Add a single client to a site resource. Clients with a userId cannot be added.",
|
"Add a single client to a site resource. Clients with a userId cannot be added.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
||||||
|
|||||||
@@ -33,6 +33,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/roles/add",
|
path: "/site-resource/{siteResourceId}/roles/add",
|
||||||
description: "Add a single role to a site resource.",
|
description: "Add a single role to a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: addRoleToSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: addRoleToSiteResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/roles/add",
|
||||||
|
description: "Add a single role to a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
||||||
request: {
|
request: {
|
||||||
params: addRoleToSiteResourceParamsSchema,
|
params: addRoleToSiteResourceParamsSchema,
|
||||||
|
|||||||
@@ -33,6 +33,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/users/add",
|
path: "/site-resource/{siteResourceId}/users/add",
|
||||||
description: "Add a single user to a site resource.",
|
description: "Add a single user to a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: addUserToSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: addUserToSiteResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/users/add",
|
||||||
|
description: "Add a single user to a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
||||||
request: {
|
request: {
|
||||||
params: addUserToSiteResourceParamsSchema,
|
params: addUserToSiteResourceParamsSchema,
|
||||||
|
|||||||
@@ -38,6 +38,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/client/{clientId}/site-resources",
|
path: "/client/{clientId}/site-resources",
|
||||||
description: "Add a machine client to multiple site resources at once.",
|
description: "Add a machine client to multiple site resources at once.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: batchAddClientToSiteResourcesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: batchAddClientToSiteResourcesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/client/{clientId}/private-resources",
|
||||||
|
description: "Add a machine client to multiple site resources at once.",
|
||||||
tags: [OpenAPITags.Client],
|
tags: [OpenAPITags.Client],
|
||||||
request: {
|
request: {
|
||||||
params: batchAddClientToSiteResourcesParamsSchema,
|
params: batchAddClientToSiteResourcesParamsSchema,
|
||||||
|
|||||||
@@ -207,6 +207,39 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/org/{orgId}/site-resource",
|
path: "/org/{orgId}/site-resource",
|
||||||
description: "Create a new site resource.",
|
description: "Create a new site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: createSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: createSiteResourceSchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/org/{orgId}/private-resource",
|
||||||
|
description: "Create a new site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: createSiteResourceParamsSchema,
|
params: createSiteResourceParamsSchema,
|
||||||
|
|||||||
@@ -27,6 +27,32 @@ registry.registerPath({
|
|||||||
method: "delete",
|
method: "delete",
|
||||||
path: "/site-resource/{siteResourceId}",
|
path: "/site-resource/{siteResourceId}",
|
||||||
description: "Delete a site resource.",
|
description: "Delete a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: deleteSiteResourceParamsSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "delete",
|
||||||
|
path: "/private-resource/{siteResourceId}",
|
||||||
|
description: "Delete a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: deleteSiteResourceParamsSchema
|
params: deleteSiteResourceParamsSchema
|
||||||
|
|||||||
@@ -57,6 +57,36 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/site-resource/{siteResourceId}",
|
path: "/site-resource/{siteResourceId}",
|
||||||
description: "Get a specific site resource by siteResourceId.",
|
description: "Get a specific site resource by siteResourceId.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: z.object({
|
||||||
|
siteResourceId: z.number(),
|
||||||
|
siteId: z.number(),
|
||||||
|
orgId: z.string()
|
||||||
|
})
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/private-resource/{siteResourceId}",
|
||||||
|
description: "Get a specific site resource by siteResourceId.",
|
||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
|
|||||||
@@ -230,6 +230,33 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/site-resources",
|
path: "/org/{orgId}/site-resources",
|
||||||
description: "List all site resources for an organization.",
|
description: "List all site resources for an organization.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listAllSiteResourcesByOrgParamsSchema,
|
||||||
|
query: listAllSiteResourcesByOrgQuerySchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/org/{orgId}/private-resources",
|
||||||
|
description: "List all site resources for an organization.",
|
||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: listAllSiteResourcesByOrgParamsSchema,
|
params: listAllSiteResourcesByOrgParamsSchema,
|
||||||
|
|||||||
@@ -39,6 +39,32 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/site-resource/{siteResourceId}/clients",
|
path: "/site-resource/{siteResourceId}/clients",
|
||||||
description: "List all clients for a site resource.",
|
description: "List all clients for a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listSiteResourceClientsSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/private-resource/{siteResourceId}/clients",
|
||||||
|
description: "List all clients for a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
||||||
request: {
|
request: {
|
||||||
params: listSiteResourceClientsSchema
|
params: listSiteResourceClientsSchema
|
||||||
|
|||||||
@@ -40,6 +40,32 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/site-resource/{siteResourceId}/roles",
|
path: "/site-resource/{siteResourceId}/roles",
|
||||||
description: "List all roles for a site resource.",
|
description: "List all roles for a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listSiteResourceRolesSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/private-resource/{siteResourceId}/roles",
|
||||||
|
description: "List all roles for a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
||||||
request: {
|
request: {
|
||||||
params: listSiteResourceRolesSchema
|
params: listSiteResourceRolesSchema
|
||||||
|
|||||||
@@ -43,6 +43,32 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/site-resource/{siteResourceId}/users",
|
path: "/site-resource/{siteResourceId}/users",
|
||||||
description: "List all users for a site resource.",
|
description: "List all users for a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listSiteResourceUsersSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/private-resource/{siteResourceId}/users",
|
||||||
|
description: "List all users for a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
||||||
request: {
|
request: {
|
||||||
params: listSiteResourceUsersSchema
|
params: listSiteResourceUsersSchema
|
||||||
|
|||||||
@@ -67,6 +67,33 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}/site/{siteId}/resources",
|
path: "/org/{orgId}/site/{siteId}/resources",
|
||||||
description: "List site resources for a site.",
|
description: "List site resources for a site.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listSiteResourcesParamsSchema,
|
||||||
|
query: listSiteResourcesQuerySchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/org/{orgId}/site/{siteId}/private-resources",
|
||||||
|
description: "List site resources for a site.",
|
||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: listSiteResourcesParamsSchema,
|
params: listSiteResourcesParamsSchema,
|
||||||
|
|||||||
@@ -31,6 +31,40 @@ const removeClientFromSiteResourceParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/clients/remove",
|
path: "/site-resource/{siteResourceId}/clients/remove",
|
||||||
|
description:
|
||||||
|
"Remove a single client from a site resource. Clients with a userId cannot be removed.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: removeClientFromSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: removeClientFromSiteResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/clients/remove",
|
||||||
description:
|
description:
|
||||||
"Remove a single client from a site resource. Clients with a userId cannot be removed.",
|
"Remove a single client from a site resource. Clients with a userId cannot be removed.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
||||||
|
|||||||
@@ -33,6 +33,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/roles/remove",
|
path: "/site-resource/{siteResourceId}/roles/remove",
|
||||||
description: "Remove a single role from a site resource.",
|
description: "Remove a single role from a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: removeRoleFromSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: removeRoleFromSiteResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/roles/remove",
|
||||||
|
description: "Remove a single role from a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
||||||
request: {
|
request: {
|
||||||
params: removeRoleFromSiteResourceParamsSchema,
|
params: removeRoleFromSiteResourceParamsSchema,
|
||||||
|
|||||||
@@ -33,6 +33,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/users/remove",
|
path: "/site-resource/{siteResourceId}/users/remove",
|
||||||
description: "Remove a single user from a site resource.",
|
description: "Remove a single user from a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: removeUserFromSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: removeUserFromSiteResourceBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/users/remove",
|
||||||
|
description: "Remove a single user from a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
||||||
request: {
|
request: {
|
||||||
params: removeUserFromSiteResourceParamsSchema,
|
params: removeUserFromSiteResourceParamsSchema,
|
||||||
|
|||||||
@@ -31,6 +31,40 @@ const setSiteResourceClientsParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/clients",
|
path: "/site-resource/{siteResourceId}/clients",
|
||||||
|
description:
|
||||||
|
"Set clients for a site resource. This will replace all existing clients. Clients with a userId cannot be added.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setSiteResourceClientsParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setSiteResourceClientsBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/clients",
|
||||||
description:
|
description:
|
||||||
"Set clients for a site resource. This will replace all existing clients. Clients with a userId cannot be added.",
|
"Set clients for a site resource. This will replace all existing clients. Clients with a userId cannot be added.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Client],
|
||||||
|
|||||||
@@ -32,6 +32,40 @@ const setSiteResourceRolesParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/roles",
|
path: "/site-resource/{siteResourceId}/roles",
|
||||||
|
description:
|
||||||
|
"Set roles for a site resource. This will replace all existing roles.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setSiteResourceRolesParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setSiteResourceRolesBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/roles",
|
||||||
description:
|
description:
|
||||||
"Set roles for a site resource. This will replace all existing roles.",
|
"Set roles for a site resource. This will replace all existing roles.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.Role],
|
||||||
|
|||||||
@@ -33,6 +33,40 @@ const setSiteResourceUsersParamsSchema = z
|
|||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}/users",
|
path: "/site-resource/{siteResourceId}/users",
|
||||||
|
description:
|
||||||
|
"Set users for a site resource. This will replace all existing users.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: setSiteResourceUsersParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: setSiteResourceUsersBodySchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}/users",
|
||||||
description:
|
description:
|
||||||
"Set users for a site resource. This will replace all existing users.",
|
"Set users for a site resource. This will replace all existing users.",
|
||||||
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
tags: [OpenAPITags.PrivateResource, OpenAPITags.User],
|
||||||
|
|||||||
@@ -213,6 +213,39 @@ registry.registerPath({
|
|||||||
method: "post",
|
method: "post",
|
||||||
path: "/site-resource/{siteResourceId}",
|
path: "/site-resource/{siteResourceId}",
|
||||||
description: "Update a site resource.",
|
description: "Update a site resource.",
|
||||||
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: updateSiteResourceParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: updateSiteResourceSchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "post",
|
||||||
|
path: "/private-resource/{siteResourceId}",
|
||||||
|
description: "Update a site resource.",
|
||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: updateSiteResourceParamsSchema,
|
params: updateSiteResourceParamsSchema,
|
||||||
|
|||||||
@@ -93,6 +93,39 @@ registry.registerPath({
|
|||||||
method: "put",
|
method: "put",
|
||||||
path: "/resource/{resourceId}/target",
|
path: "/resource/{resourceId}/target",
|
||||||
description: "Create a target for a resource.",
|
description: "Create a target for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: createTargetParamsSchema,
|
||||||
|
body: {
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: createTargetSchema
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "put",
|
||||||
|
path: "/public-resource/{resourceId}/target",
|
||||||
|
description: "Create a target for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Target],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Target],
|
||||||
request: {
|
request: {
|
||||||
params: createTargetParamsSchema,
|
params: createTargetParamsSchema,
|
||||||
|
|||||||
@@ -92,6 +92,33 @@ registry.registerPath({
|
|||||||
method: "get",
|
method: "get",
|
||||||
path: "/resource/{resourceId}/targets",
|
path: "/resource/{resourceId}/targets",
|
||||||
description: "List targets for a resource.",
|
description: "List targets for a resource.",
|
||||||
|
tags: [OpenAPITags.PublicResourceLegacy],
|
||||||
|
request: {
|
||||||
|
params: listTargetsParamsSchema,
|
||||||
|
query: listTargetsSchema
|
||||||
|
},
|
||||||
|
responses: {
|
||||||
|
200: {
|
||||||
|
description: "Successful response",
|
||||||
|
content: {
|
||||||
|
"application/json": {
|
||||||
|
schema: z.object({
|
||||||
|
data: z.record(z.string(), z.any()).nullable(),
|
||||||
|
success: z.boolean(),
|
||||||
|
error: z.boolean(),
|
||||||
|
message: z.string(),
|
||||||
|
status: z.number()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
registry.registerPath({
|
||||||
|
method: "get",
|
||||||
|
path: "/public-resource/{resourceId}/targets",
|
||||||
|
description: "List targets for a resource.",
|
||||||
tags: [OpenAPITags.PublicResource, OpenAPITags.Target],
|
tags: [OpenAPITags.PublicResource, OpenAPITags.Target],
|
||||||
request: {
|
request: {
|
||||||
params: listTargetsParamsSchema,
|
params: listTargetsParamsSchema,
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
"use client";
|
"use client";
|
||||||
|
|
||||||
import { Alert, AlertDescription } from "@/components/ui/alert";
|
import { Alert, AlertDescription, AlertTitle } from "@/components/ui/alert";
|
||||||
import { Button } from "@/components/ui/button";
|
import { Button } from "@/components/ui/button";
|
||||||
import { Card, CardContent } from "@/components/ui/card";
|
import { Card, CardContent } from "@/components/ui/card";
|
||||||
import {
|
import {
|
||||||
@@ -43,10 +43,12 @@ import {
|
|||||||
CheckCircle2,
|
CheckCircle2,
|
||||||
ChevronsUpDown,
|
ChevronsUpDown,
|
||||||
ExternalLink,
|
ExternalLink,
|
||||||
|
Globe,
|
||||||
KeyRound,
|
KeyRound,
|
||||||
Zap
|
Zap
|
||||||
} from "lucide-react";
|
} from "lucide-react";
|
||||||
import { useTranslations } from "next-intl";
|
import { useTranslations } from "next-intl";
|
||||||
|
import Link from "next/link";
|
||||||
import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
||||||
import { usePaidStatus } from "@/hooks/usePaidStatus";
|
import { usePaidStatus } from "@/hooks/usePaidStatus";
|
||||||
import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
||||||
@@ -494,6 +496,28 @@ export default function DomainPicker({
|
|||||||
const hasMoreProvided =
|
const hasMoreProvided =
|
||||||
sortedAvailableOptions.length > providedDomainsShown;
|
sortedAvailableOptions.length > providedDomainsShown;
|
||||||
|
|
||||||
|
const noDomainsAvailable =
|
||||||
|
!loadingDomains &&
|
||||||
|
organizationDomains.length === 0 &&
|
||||||
|
(build === "oss" || hideFreeDomain || requiresPaywall);
|
||||||
|
|
||||||
|
if (noDomainsAvailable) {
|
||||||
|
return (
|
||||||
|
<Alert>
|
||||||
|
<Globe className="h-4 w-4" />
|
||||||
|
<AlertTitle>{t("domainPickerNoDomainsAvailableTitle")}</AlertTitle>
|
||||||
|
<AlertDescription className="space-y-3">
|
||||||
|
<p>{t("domainPickerNoDomainsAvailableDescription")}</p>
|
||||||
|
<Button asChild size="sm" variant="outline">
|
||||||
|
<Link href={`/${orgId}/settings/domains`}>
|
||||||
|
{t("domainPickerNoDomainsAvailableAction")}
|
||||||
|
</Link>
|
||||||
|
</Button>
|
||||||
|
</AlertDescription>
|
||||||
|
</Alert>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="space-y-4">
|
<div className="space-y-4">
|
||||||
<div className="grid grid-cols-1 sm:grid-cols-2 gap-4">
|
<div className="grid grid-cols-1 sm:grid-cols-2 gap-4">
|
||||||
|
|||||||
@@ -95,7 +95,10 @@ export function useOptimisticLabels({
|
|||||||
}
|
}
|
||||||
|
|
||||||
async function refresh() {
|
async function refresh() {
|
||||||
router.refresh();
|
// Only refresh if the labels have been modified
|
||||||
|
if (pendingActions.length > 0) {
|
||||||
|
router.refresh();
|
||||||
|
}
|
||||||
setPendingActions([]);
|
setPendingActions([]);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user