2018-09-25 16:28:26 +00:00
|
|
|
import { get } from '@ember/object';
|
|
|
|
import Service, { inject as service } from '@ember/service';
|
|
|
|
import RSVP from 'rsvp';
|
2018-07-19 01:59:04 +00:00
|
|
|
import ControlGroupError from 'vault/lib/control-group-error';
|
|
|
|
import getStorage from 'vault/lib/token-storage';
|
2019-10-04 20:15:33 +00:00
|
|
|
import parseURL from 'core/utils/parse-url';
|
2018-07-19 01:59:04 +00:00
|
|
|
|
|
|
|
const CONTROL_GROUP_PREFIX = 'vault:cg-';
|
|
|
|
const TOKEN_SEPARATOR = '☃';
|
|
|
|
|
|
|
|
// list of endpoints that return wrapped responses
|
|
|
|
// without `wrap-ttl`
|
|
|
|
const WRAPPED_RESPONSE_PATHS = [
|
|
|
|
'sys/wrapping/rewrap',
|
|
|
|
'sys/wrapping/wrap',
|
|
|
|
'sys/replication/performance/primary/secondary-token',
|
|
|
|
'sys/replication/dr/primary/secondary-token',
|
|
|
|
];
|
|
|
|
|
|
|
|
const storageKey = (accessor, path) => {
|
|
|
|
return `${CONTROL_GROUP_PREFIX}${accessor}${TOKEN_SEPARATOR}${path}`;
|
|
|
|
};
|
|
|
|
|
|
|
|
export { storageKey, CONTROL_GROUP_PREFIX, TOKEN_SEPARATOR };
|
|
|
|
export default Service.extend({
|
2018-09-25 16:28:26 +00:00
|
|
|
version: service(),
|
|
|
|
router: service(),
|
2018-07-19 01:59:04 +00:00
|
|
|
|
|
|
|
storage() {
|
|
|
|
return getStorage();
|
|
|
|
},
|
|
|
|
|
|
|
|
keyFromAccessor(accessor) {
|
|
|
|
let keys = this.storage().keys() || [];
|
|
|
|
let returnKey = keys
|
|
|
|
.filter(k => k.startsWith(CONTROL_GROUP_PREFIX))
|
|
|
|
.find(key => key.replace(CONTROL_GROUP_PREFIX, '').startsWith(accessor));
|
|
|
|
return returnKey ? returnKey : null;
|
|
|
|
},
|
|
|
|
|
|
|
|
storeControlGroupToken(info) {
|
|
|
|
let key = storageKey(info.accessor, info.creation_path);
|
|
|
|
this.storage().setItem(key, info);
|
|
|
|
},
|
|
|
|
|
|
|
|
deleteControlGroupToken(accessor) {
|
|
|
|
this.unmarkTokenForUnwrap();
|
|
|
|
let key = this.keyFromAccessor(accessor);
|
|
|
|
this.storage().removeItem(key);
|
|
|
|
},
|
|
|
|
|
|
|
|
deleteTokens() {
|
|
|
|
let keys = this.storage().keys() || [];
|
|
|
|
keys.filter(k => k.startsWith(CONTROL_GROUP_PREFIX)).forEach(key => this.storage().removeItem(key));
|
|
|
|
},
|
|
|
|
|
|
|
|
wrapInfoForAccessor(accessor) {
|
|
|
|
let key = this.keyFromAccessor(accessor);
|
|
|
|
return key ? this.storage().getItem(key) : null;
|
|
|
|
},
|
|
|
|
|
|
|
|
tokenToUnwrap: null,
|
|
|
|
markTokenForUnwrap(accessor) {
|
|
|
|
this.set('tokenToUnwrap', this.wrapInfoForAccessor(accessor));
|
|
|
|
},
|
|
|
|
|
|
|
|
unmarkTokenForUnwrap() {
|
|
|
|
this.set('tokenToUnwrap', null);
|
|
|
|
},
|
|
|
|
|
|
|
|
tokenForUrl(url) {
|
|
|
|
if (this.get('version.isOSS')) {
|
|
|
|
return null;
|
|
|
|
}
|
2019-10-04 20:15:33 +00:00
|
|
|
let pathForUrl = parseURL(url).pathname;
|
|
|
|
pathForUrl = pathForUrl.replace('/v1/', '');
|
2018-07-19 01:59:04 +00:00
|
|
|
let tokenInfo = this.get('tokenToUnwrap');
|
|
|
|
if (tokenInfo && tokenInfo.creation_path === pathForUrl) {
|
|
|
|
let { token, accessor, creation_time } = tokenInfo;
|
|
|
|
return { token, accessor, creationTime: creation_time };
|
|
|
|
}
|
|
|
|
return null;
|
|
|
|
},
|
|
|
|
|
|
|
|
checkForControlGroup(callbackArgs, response, wasWrapTTLRequested) {
|
2018-09-25 16:28:26 +00:00
|
|
|
let creationPath = response && get(response, 'wrap_info.creation_path');
|
2018-07-19 01:59:04 +00:00
|
|
|
if (
|
|
|
|
this.get('version.isOSS') ||
|
|
|
|
wasWrapTTLRequested ||
|
|
|
|
!response ||
|
|
|
|
(creationPath && WRAPPED_RESPONSE_PATHS.includes(creationPath)) ||
|
|
|
|
!response.wrap_info
|
|
|
|
) {
|
|
|
|
return RSVP.resolve(...callbackArgs);
|
|
|
|
}
|
|
|
|
let error = new ControlGroupError(response.wrap_info);
|
|
|
|
return RSVP.reject(error);
|
|
|
|
},
|
|
|
|
|
Update ui dependencies (#7244)
* be more specific about node version, and specify a yarn version
* update ember, ember-cli, ember-data, ember-data-model-fragments
* use router handlers to access transition information
* fix shadowing of component helper
* update ivy-codemirror, ember-cli-inject-live-reload
* remove custom router service
* don't use transition.queryParams
* update ember-cli-deprecation-workflow
* refactor kv v1 to use 'path' instead of 'id' on creation
* fix auth-jwt-test and toolbar-link-test
* update ember composable helpers
* remove Ember.copy from test file
* no more deprecations in the workflow
* fix more secret tests
* fix remaining failed tests
* move select component to core because it's used by ttl-picker
* generate new model class for each test instead of reusing an existing one
* fix selectors on kmip tests
* refactor how control groups construct urls from the new transition objects
* add router service override back in, and have it be evented so that we can trigger router events on it
* move stories and markdown files to core if the component lives in core
* update ember-cli, ember-cli-babel, ember-auto-import
* update base64js, date-fns, deepmerge, codemirror, broccoli-asset-rev
* update linting rules
* fix test selectors
* update ember-api-actions, ember-concurrency, ember-load-initializers, escape-string-regexp, normalize.css, prettier-eslint-cli, jsdoc-to-markdown
* remove test-results dir
* update base64js, ember-cli-clipboard, ember-cli-sass, ember-cli-string-helpers, ember-cli-template-lint, ember-cli-uglify, ember-link-action
* fix linting
* run yarn install without restoring from cache
* refactor how tests are run and handle the vault server subprocess
* update makefile for new test task names
* update circle config to use the new yarn task
* fix writing the seal keys when starting the dev server
* remove optional deps from the lockfile
* don't ignore-optional on yarn install
* remove errant console.log
* update ember-basic-dropdown-hover, jsonlint, yargs-parser
* update ember-cli-flash
* add back optionalDeps
* update @babel/core@7.5.5, ember-basic-dropdown@1.1.3, eslint-plugin-ember@6.8.2
* update storybook to the latest release
* add a babel config with targets so that the ember babel plugin works properly
* update ember-resolver, move ember-cli-storybook to devDependencies
* revert normalize.css upgrade
* silence fetchadapter warning for now
* exclude 3rd party array helper now that ember includes one
* fix switch and entity lookup styling
* only add -root suffix if it's not in versions mode
* make sure drop always has an array on the aws role form
* fix labels like we did with the backport
* update eslintignore
* update the yarn version in the docker build file
* update eslint ignore
2019-08-19 20:45:39 +00:00
|
|
|
paramsFromTransition(transitionTo, params, queryParams) {
|
|
|
|
let returnedParams = params.slice();
|
|
|
|
let qps = queryParams;
|
|
|
|
transitionTo.paramNames.map(name => {
|
|
|
|
let param = transitionTo.params[name];
|
|
|
|
if (param.length) {
|
|
|
|
// push on to the front of the array since were're started at the end
|
|
|
|
returnedParams.unshift(param);
|
2018-07-19 01:59:04 +00:00
|
|
|
}
|
Update ui dependencies (#7244)
* be more specific about node version, and specify a yarn version
* update ember, ember-cli, ember-data, ember-data-model-fragments
* use router handlers to access transition information
* fix shadowing of component helper
* update ivy-codemirror, ember-cli-inject-live-reload
* remove custom router service
* don't use transition.queryParams
* update ember-cli-deprecation-workflow
* refactor kv v1 to use 'path' instead of 'id' on creation
* fix auth-jwt-test and toolbar-link-test
* update ember composable helpers
* remove Ember.copy from test file
* no more deprecations in the workflow
* fix more secret tests
* fix remaining failed tests
* move select component to core because it's used by ttl-picker
* generate new model class for each test instead of reusing an existing one
* fix selectors on kmip tests
* refactor how control groups construct urls from the new transition objects
* add router service override back in, and have it be evented so that we can trigger router events on it
* move stories and markdown files to core if the component lives in core
* update ember-cli, ember-cli-babel, ember-auto-import
* update base64js, date-fns, deepmerge, codemirror, broccoli-asset-rev
* update linting rules
* fix test selectors
* update ember-api-actions, ember-concurrency, ember-load-initializers, escape-string-regexp, normalize.css, prettier-eslint-cli, jsdoc-to-markdown
* remove test-results dir
* update base64js, ember-cli-clipboard, ember-cli-sass, ember-cli-string-helpers, ember-cli-template-lint, ember-cli-uglify, ember-link-action
* fix linting
* run yarn install without restoring from cache
* refactor how tests are run and handle the vault server subprocess
* update makefile for new test task names
* update circle config to use the new yarn task
* fix writing the seal keys when starting the dev server
* remove optional deps from the lockfile
* don't ignore-optional on yarn install
* remove errant console.log
* update ember-basic-dropdown-hover, jsonlint, yargs-parser
* update ember-cli-flash
* add back optionalDeps
* update @babel/core@7.5.5, ember-basic-dropdown@1.1.3, eslint-plugin-ember@6.8.2
* update storybook to the latest release
* add a babel config with targets so that the ember babel plugin works properly
* update ember-resolver, move ember-cli-storybook to devDependencies
* revert normalize.css upgrade
* silence fetchadapter warning for now
* exclude 3rd party array helper now that ember includes one
* fix switch and entity lookup styling
* only add -root suffix if it's not in versions mode
* make sure drop always has an array on the aws role form
* fix labels like we did with the backport
* update eslintignore
* update the yarn version in the docker build file
* update eslint ignore
2019-08-19 20:45:39 +00:00
|
|
|
});
|
|
|
|
qps = { ...queryParams, ...transitionTo.queryParams };
|
|
|
|
// if there's a parent transition, recurse to get its route params
|
|
|
|
if (transitionTo.parent) {
|
|
|
|
[returnedParams, qps] = this.paramsFromTransition(transitionTo.parent, returnedParams, qps);
|
2018-07-19 01:59:04 +00:00
|
|
|
}
|
Update ui dependencies (#7244)
* be more specific about node version, and specify a yarn version
* update ember, ember-cli, ember-data, ember-data-model-fragments
* use router handlers to access transition information
* fix shadowing of component helper
* update ivy-codemirror, ember-cli-inject-live-reload
* remove custom router service
* don't use transition.queryParams
* update ember-cli-deprecation-workflow
* refactor kv v1 to use 'path' instead of 'id' on creation
* fix auth-jwt-test and toolbar-link-test
* update ember composable helpers
* remove Ember.copy from test file
* no more deprecations in the workflow
* fix more secret tests
* fix remaining failed tests
* move select component to core because it's used by ttl-picker
* generate new model class for each test instead of reusing an existing one
* fix selectors on kmip tests
* refactor how control groups construct urls from the new transition objects
* add router service override back in, and have it be evented so that we can trigger router events on it
* move stories and markdown files to core if the component lives in core
* update ember-cli, ember-cli-babel, ember-auto-import
* update base64js, date-fns, deepmerge, codemirror, broccoli-asset-rev
* update linting rules
* fix test selectors
* update ember-api-actions, ember-concurrency, ember-load-initializers, escape-string-regexp, normalize.css, prettier-eslint-cli, jsdoc-to-markdown
* remove test-results dir
* update base64js, ember-cli-clipboard, ember-cli-sass, ember-cli-string-helpers, ember-cli-template-lint, ember-cli-uglify, ember-link-action
* fix linting
* run yarn install without restoring from cache
* refactor how tests are run and handle the vault server subprocess
* update makefile for new test task names
* update circle config to use the new yarn task
* fix writing the seal keys when starting the dev server
* remove optional deps from the lockfile
* don't ignore-optional on yarn install
* remove errant console.log
* update ember-basic-dropdown-hover, jsonlint, yargs-parser
* update ember-cli-flash
* add back optionalDeps
* update @babel/core@7.5.5, ember-basic-dropdown@1.1.3, eslint-plugin-ember@6.8.2
* update storybook to the latest release
* add a babel config with targets so that the ember babel plugin works properly
* update ember-resolver, move ember-cli-storybook to devDependencies
* revert normalize.css upgrade
* silence fetchadapter warning for now
* exclude 3rd party array helper now that ember includes one
* fix switch and entity lookup styling
* only add -root suffix if it's not in versions mode
* make sure drop always has an array on the aws role form
* fix labels like we did with the backport
* update eslintignore
* update the yarn version in the docker build file
* update eslint ignore
2019-08-19 20:45:39 +00:00
|
|
|
return [returnedParams, qps];
|
|
|
|
},
|
|
|
|
|
|
|
|
urlFromTransition(transitionObj) {
|
|
|
|
let transition = transitionObj.to;
|
|
|
|
let [params, queryParams] = this.paramsFromTransition(transition, [], {});
|
|
|
|
let url = this.get('router').urlFor(transition.name, ...params, {
|
|
|
|
queryParams,
|
2018-07-19 01:59:04 +00:00
|
|
|
});
|
|
|
|
return url.replace('/ui', '');
|
|
|
|
},
|
|
|
|
|
|
|
|
handleError(error, transition) {
|
|
|
|
let { accessor, token, creation_path, creation_time, ttl } = error;
|
|
|
|
let url = this.urlFromTransition(transition);
|
|
|
|
let data = { accessor, token, creation_path, creation_time, ttl };
|
|
|
|
data.uiParams = { url };
|
|
|
|
this.storeControlGroupToken(data);
|
|
|
|
return this.get('router').transitionTo('vault.cluster.access.control-group-accessor', accessor);
|
|
|
|
},
|
|
|
|
|
|
|
|
logFromError(error) {
|
|
|
|
let { accessor, token, creation_path, creation_time, ttl } = error;
|
|
|
|
let data = { accessor, token, creation_path, creation_time, ttl };
|
|
|
|
this.storeControlGroupToken(data);
|
|
|
|
|
|
|
|
let href = this.get('router').urlFor('vault.cluster.access.control-group-accessor', accessor);
|
|
|
|
let lines = [
|
|
|
|
`A Control Group was encountered at ${error.creation_path}.`,
|
|
|
|
`The Control Group Token is ${error.token}.`,
|
|
|
|
`The Accessor is ${error.accessor}.`,
|
|
|
|
`Visit <a href='${href}'>${href}</a> for more details.`,
|
|
|
|
];
|
|
|
|
return {
|
|
|
|
type: 'error-with-html',
|
|
|
|
content: lines.join('\n'),
|
|
|
|
};
|
|
|
|
},
|
|
|
|
});
|