Compare commits

..

1 Commits

Author SHA1 Message Date
Fred KISSIE e99cd52e99 🐛 Fix log retention access pulling from the wrong org settings field 2026-08-04 21:55:34 +02:00
4 changed files with 10 additions and 32 deletions
+1 -1
View File
@@ -1,4 +1,4 @@
FROM node:25-alpine
FROM node:24-alpine
WORKDIR /app
+3 -3
View File
@@ -28,7 +28,7 @@ async function getAccessDays(orgId: string): Promise<number> {
const [org] = await db
.select({
settingsLogRetentionDaysAction: orgs.settingsLogRetentionDaysAction
settingsLogRetentionDaysAccess: orgs.settingsLogRetentionDaysAccess
})
.from(orgs)
.where(eq(orgs.orgId, orgId))
@@ -41,11 +41,11 @@ async function getAccessDays(orgId: string): Promise<number> {
// store the result in cache
await cache.set(
`org_${orgId}_accessDays`,
org.settingsLogRetentionDaysAction,
org.settingsLogRetentionDaysAccess,
300
);
return org.settingsLogRetentionDaysAction;
return org.settingsLogRetentionDaysAccess;
}
export async function cleanUpOldLogs(orgId: string, retentionDays: number) {
@@ -10,12 +10,12 @@
*
* This file is not licensed under the AGPLv3.
*/
import { certificates, db, domainNamespaces, domains, orgDomains } from "@server/db";
import { certificates, db, domains, orgDomains } from "@server/db";
import response from "@server/lib/response";
import logger from "@server/logger";
import { type GetBatchedCertificateResponse } from "@server/routers/certificates/types";
import HttpCode from "@server/types/HttpCode";
import { and, eq, inArray, isNotNull, or } from "drizzle-orm";
import { and, eq, inArray, or } from "drizzle-orm";
import { NextFunction, Request, Response } from "express";
import createHttpError from "http-errors";
import { z } from "zod";
@@ -63,28 +63,14 @@ async function query(orgId: string, domainList: string[]) {
})
.from(certificates)
.innerJoin(domains, eq(certificates.domainId, domains.domainId))
.leftJoin(
.innerJoin(
orgDomains,
and(
eq(domains.domainId, orgDomains.domainId),
eq(orgDomains.orgId, orgId)
)
)
.leftJoin(
domainNamespaces,
eq(domains.domainId, domainNamespaces.domainId)
)
.where(
and(
inArray(certificates.domain, domainList),
// Namespace domains are shared across all orgs, so they skip
// the org-ownership check (mirrors verifyCertificateAccess).
or(
isNotNull(orgDomains.orgId),
isNotNull(domainNamespaces.domainNamespaceId)
)
)
);
.where(and(inArray(certificates.domain, domainList)));
// All non resolved domain certificates might be `ns` or `wildcard`,
// which means exact domain certificates do not exist
@@ -124,27 +110,19 @@ async function query(orgId: string, domainList: string[]) {
})
.from(certificates)
.innerJoin(domains, eq(certificates.domainId, domains.domainId))
.leftJoin(
.innerJoin(
orgDomains,
and(
eq(domains.domainId, orgDomains.domainId),
eq(orgDomains.orgId, orgId)
)
)
.leftJoin(
domainNamespaces,
eq(domains.domainId, domainNamespaces.domainId)
)
.where(
and(
eq(certificates.wildcard, true),
or(
inArray(certificates.domain, [...domainLevelDownSet]),
inArray(certificates.domain, [...wildcardDomainSet])
),
or(
isNotNull(orgDomains.orgId),
isNotNull(domainNamespaces.domainNamespaceId)
)
)
);
+1 -1
View File
@@ -111,7 +111,7 @@ export function useCertificate({
let certError: string | null = null;
if (restartCert.isError) {
certError = "Failed to restart";
} else if (isError || (!isLoading && data === null)) {
} else if (isError || initialCertValue === null) {
// Null value means failed to get the certificate
certError = "Failed";
}