Compare commits

..

1 Commits

Author SHA1 Message Date
Fred KISSIE e99cd52e99 🐛 Fix log retention access pulling from the wrong org settings field 2026-08-04 21:55:34 +02:00
3 changed files with 9 additions and 31 deletions
+3 -3
View File
@@ -28,7 +28,7 @@ async function getAccessDays(orgId: string): Promise<number> {
const [org] = await db const [org] = await db
.select({ .select({
settingsLogRetentionDaysAction: orgs.settingsLogRetentionDaysAction settingsLogRetentionDaysAccess: orgs.settingsLogRetentionDaysAccess
}) })
.from(orgs) .from(orgs)
.where(eq(orgs.orgId, orgId)) .where(eq(orgs.orgId, orgId))
@@ -41,11 +41,11 @@ async function getAccessDays(orgId: string): Promise<number> {
// store the result in cache // store the result in cache
await cache.set( await cache.set(
`org_${orgId}_accessDays`, `org_${orgId}_accessDays`,
org.settingsLogRetentionDaysAction, org.settingsLogRetentionDaysAccess,
300 300
); );
return org.settingsLogRetentionDaysAction; return org.settingsLogRetentionDaysAccess;
} }
export async function cleanUpOldLogs(orgId: string, retentionDays: number) { export async function cleanUpOldLogs(orgId: string, retentionDays: number) {
@@ -10,12 +10,12 @@
* *
* This file is not licensed under the AGPLv3. * This file is not licensed under the AGPLv3.
*/ */
import { certificates, db, domainNamespaces, domains, orgDomains } from "@server/db"; import { certificates, db, domains, orgDomains } from "@server/db";
import response from "@server/lib/response"; import response from "@server/lib/response";
import logger from "@server/logger"; import logger from "@server/logger";
import { type GetBatchedCertificateResponse } from "@server/routers/certificates/types"; import { type GetBatchedCertificateResponse } from "@server/routers/certificates/types";
import HttpCode from "@server/types/HttpCode"; import HttpCode from "@server/types/HttpCode";
import { and, eq, inArray, isNotNull, or } from "drizzle-orm"; import { and, eq, inArray, or } from "drizzle-orm";
import { NextFunction, Request, Response } from "express"; import { NextFunction, Request, Response } from "express";
import createHttpError from "http-errors"; import createHttpError from "http-errors";
import { z } from "zod"; import { z } from "zod";
@@ -63,28 +63,14 @@ async function query(orgId: string, domainList: string[]) {
}) })
.from(certificates) .from(certificates)
.innerJoin(domains, eq(certificates.domainId, domains.domainId)) .innerJoin(domains, eq(certificates.domainId, domains.domainId))
.leftJoin( .innerJoin(
orgDomains, orgDomains,
and( and(
eq(domains.domainId, orgDomains.domainId), eq(domains.domainId, orgDomains.domainId),
eq(orgDomains.orgId, orgId) eq(orgDomains.orgId, orgId)
) )
) )
.leftJoin( .where(and(inArray(certificates.domain, domainList)));
domainNamespaces,
eq(domains.domainId, domainNamespaces.domainId)
)
.where(
and(
inArray(certificates.domain, domainList),
// Namespace domains are shared across all orgs, so they skip
// the org-ownership check (mirrors verifyCertificateAccess).
or(
isNotNull(orgDomains.orgId),
isNotNull(domainNamespaces.domainNamespaceId)
)
)
);
// All non resolved domain certificates might be `ns` or `wildcard`, // All non resolved domain certificates might be `ns` or `wildcard`,
// which means exact domain certificates do not exist // which means exact domain certificates do not exist
@@ -124,27 +110,19 @@ async function query(orgId: string, domainList: string[]) {
}) })
.from(certificates) .from(certificates)
.innerJoin(domains, eq(certificates.domainId, domains.domainId)) .innerJoin(domains, eq(certificates.domainId, domains.domainId))
.leftJoin( .innerJoin(
orgDomains, orgDomains,
and( and(
eq(domains.domainId, orgDomains.domainId), eq(domains.domainId, orgDomains.domainId),
eq(orgDomains.orgId, orgId) eq(orgDomains.orgId, orgId)
) )
) )
.leftJoin(
domainNamespaces,
eq(domains.domainId, domainNamespaces.domainId)
)
.where( .where(
and( and(
eq(certificates.wildcard, true), eq(certificates.wildcard, true),
or( or(
inArray(certificates.domain, [...domainLevelDownSet]), inArray(certificates.domain, [...domainLevelDownSet]),
inArray(certificates.domain, [...wildcardDomainSet]) inArray(certificates.domain, [...wildcardDomainSet])
),
or(
isNotNull(orgDomains.orgId),
isNotNull(domainNamespaces.domainNamespaceId)
) )
) )
); );
+1 -1
View File
@@ -111,7 +111,7 @@ export function useCertificate({
let certError: string | null = null; let certError: string | null = null;
if (restartCert.isError) { if (restartCert.isError) {
certError = "Failed to restart"; certError = "Failed to restart";
} else if (isError || (!isLoading && data === null)) { } else if (isError || initialCertValue === null) {
// Null value means failed to get the certificate // Null value means failed to get the certificate
certError = "Failed"; certError = "Failed";
} }