Skip to content

Commit

Permalink
UI Database Secrets Engine (MongoDB) (#10655)
Browse files Browse the repository at this point in the history
* move the ttls on enable for db to default and not as options

* refactor form field to angle brackets

* add database to supported backend

* initial setup of components and models

* setup selectable cards, need to make own component

* styling setup

* subtext and links

* number styling

* search select put in place and button, all pretty things

* search label text

* messy but closer to data configuration. making models and fetching those models on routes

* connection adapter and serializer that is pulled in by the overview route

* clean up and add new model params connections and roles to overview route hbs

* setting up overview as route with SecretHeader component.  TODO, show Overview tab, but have link to route.  It's going be on the secret header list component

* setup overview tab on secret-list-header to go to overview page

* setup id in overview route

* Correct link on secrets engine list for database and others

* Roles tab on database fetches correct model

* Update options for backend with hasOverview param so overview tab is rendered conditionally on secret list header

* create new getCrendentialsComponent

* Rename database connection parent component and start working on display

* setup routing to credentials route for database from overview page

* setup network request for the credentials of role

* setup serializer for credentials

* redirect previous route

* fix border color on button disable

* add margin to back button

* change to glimmer component

* glimmerize and clean up the get-credentials-card

* Begin database connection show and create form

* add component test for the get-credentials-card

* Database connection model and field groups

* add static roles to searhSelect

* add staticRoles on overview page

* Toolbar and tabs on database connection show view looks correct

* combine static and dynamic role models for pagination

* Update database-list-item with real link to connection

* Add support for optionalText edit type on form-field

* handle situation when no static and/or dynamic roles

* turn partial into component so can handle computed and eventually click actions, similar to transform

* glimmerize database-list-item

* use lazy capabilities on list role and static-role actions

* Create connection works and redirects to show page

* creds request based on dynamic or static and unload the store by record creds when they transition away.

* dynamcially add in backend for queries

* fixes on overview page for get credentials with hardcoded backend and layout for static creds

* Rotate and Reset connection actions working on connection

* get credentials set the query params

* setup async for handling permission errors on overivew

* Move query logic to store for getting both types of role

* Filtering works on combined role models

* cleanup

* Fix no meta on connections list

* better handle the situation where you don't have access to list roles but do to generate

* implment updated empty state component and add to credentials page when roleType is noRoleType

* glimmerize the input search component

* move logic for generate credentials urlto the generate creds component

* remove query param for role type

* handle permissions on the overview page

* permissions for role list

* New roles route for backends

* handle different permissions for empty return on 404 vs 403 on overview page

* fix links on overview page

* Connetions WIP

* setup lazy caps for the connections model and list

* add computed to role and static role models to clean up permissions

* setup actions for connections list

* Update form-field to show password type and update json input to angle bracket syntax with optional theme option

* setup capabilities on overview for empty state

* fix hardcoded on the backend

* toggle inner label has width 100%

* Add custom update password togglable input on database connection edit form, and only submit defined attrs

* Add updateRecord to connection adapter

* glimmerize secret list header and make new component which either shows or does not show the tab based on permissions

* Remove tabs on show connection

* add peek record

* Update database role to get both models on a single model, remove static-role model and adapter, remove roles route

* fix creds permissions on database-list-item

* add component info and rename for secret-list-header-tab

* fix issues on overview page

* Add path to individual role on serializer

* add accetpance test for testing the engine

* fix transform test

* test fix

* Update connection before role created, disable button with tooltip if user cannot update path

* Add add-to-array and remove-from-array helpers with tests

* Clean up connection update on delete or create role, cleanup logs, role create link works

* Database role create and edit forms with readonly fields and validation. Add readonly-form-field

* Add field div around ttl picker for correct spacing on form-field

* fix the breadcrumbs

* PLaceholder test for readonly form field

* create new helper to format time duration

* tooltip and formatting on static role

* more on static roles time stuff

* clean up

* clean up

* fixes on the test and addition of another helper test

* fix secrets machine test

* Add modal to connection creation flow

* fix issue with readonly form field test

* Add is-empty-object helper and tests

* Role error handling

* Remove Atlas option from connection list, add defaults to db role form

* clean up stuff though might have made it uglier

* clean up

* Add capabilities checks on connection actions

* Fix jsdocs on readonly-form-field

* Fix json editor height on form field

* Readonly form has notallowed cursor, readonly form field updates

* Add blank field rendering to info-table-row

* Start writing readonly form field tests

* Address some PR comments

* fix fallback action on search select

* cleanup per comments

* fix readonly form field test and lint

* Cleanup string helpers

* Replace renderBlank with alwaysRender logic

* re-humanize label on readonly form field

* Show defaultShown value on info-table-row if no value and always render

* Show default on role and connection show table

* Add changelog

Co-authored-by: Chelsea Shaw <[email protected]>
  • Loading branch information
Monkeychip and chelshaw authored Feb 18, 2021
1 parent 2c67114 commit 4be76bf
Show file tree
Hide file tree
Showing 80 changed files with 3,082 additions and 151 deletions.
3 changes: 3 additions & 0 deletions changelog/10655.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
ui: Database secrets engine, supporting MongoDB only
```
76 changes: 76 additions & 0 deletions ui/app/adapters/database/connection.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
import ApplicationAdapter from '../application';

export default ApplicationAdapter.extend({
namespace: 'v1',

urlFor(backend, id, type = '') {
if (type === 'ROTATE') {
return `${this.buildURL()}/${backend}/rotate-root/${id}`;
} else if (type === 'RESET') {
return `${this.buildURL()}/${backend}/reset/${id}`;
}
let url = `${this.buildURL()}/${backend}/config`;
if (id) {
url = `${this.buildURL()}/${backend}/config/${id}`;
}
return url;
},
optionsForQuery(id) {
let data = {};
if (!id) {
data['list'] = true;
}
return { data };
},
fetchByQuery(store, query) {
const { backend, id } = query;
return this.ajax(this.urlFor(backend, id), 'GET', this.optionsForQuery(id)).then(resp => {
resp.backend = backend;
if (id) {
resp.id = id;
}
return resp;
});
},
query(store, type, query) {
return this.fetchByQuery(store, query);
},

queryRecord(store, type, query) {
return this.fetchByQuery(store, query);
},

createRecord(store, type, snapshot) {
const serializer = store.serializerFor(type.modelName);
const data = serializer.serialize(snapshot);
const id = snapshot.attr('name');
const backend = snapshot.attr('backend');

return this.ajax(this.urlFor(backend, id), 'POST', { data }).then(() => {
// ember data doesn't like 204s if it's not a DELETE
return {
data: {
id,
...data,
},
};
});
},

updateRecord() {
return this.createRecord(...arguments);
},

deleteRecord(store, type, snapshot) {
const id = snapshot.id;
return this.ajax(this.urlFor('database', id), 'DELETE');
},

rotateRootCredentials(backend, id) {
return this.ajax(this.urlFor('database', id, 'ROTATE'), 'POST');
},

resetConnection(backend, id) {
return this.ajax(this.urlFor(backend, id, 'RESET'), 'POST');
},
});
17 changes: 17 additions & 0 deletions ui/app/adapters/database/credential.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
import ApplicationAdapter from '../application';

export default ApplicationAdapter.extend({
namespace: 'v1',

fetchByQuery(store, query) {
const { backend, roleType, secret } = query;
let creds = roleType === 'static' ? 'static-creds' : 'creds';
return this.ajax(
`${this.buildURL()}/${encodeURIComponent(backend)}/${creds}/${encodeURIComponent(secret)}`,
'GET'
);
},
queryRecord(store, type, query) {
return this.fetchByQuery(store, query);
},
});
168 changes: 168 additions & 0 deletions ui/app/adapters/database/role.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,168 @@
import { assign } from '@ember/polyfills';
import { assert } from '@ember/debug';
import ApplicationAdapter from '../application';
import { allSettled } from 'rsvp';
import { addToArray } from 'vault/helpers/add-to-array';
import { removeFromArray } from 'vault/helpers/remove-from-array';

export default ApplicationAdapter.extend({
namespace: 'v1',
pathForType() {
assert('Generate the url dynamically based on role type', false);
},

urlFor(backend, id, type = 'dynamic') {
let role = 'roles';
if (type === 'static') {
role = 'static-roles';
}
let url = `${this.buildURL()}/${backend}/${role}`;
if (id) {
url = `${this.buildURL()}/${backend}/${role}/${id}`;
}
return url;
},

staticRoles(backend, id) {
return this.ajax(this.urlFor(backend, id, 'static'), 'GET', this.optionsForQuery(id));
},

dynamicRoles(backend, id) {
return this.ajax(this.urlFor(backend, id), 'GET', this.optionsForQuery(id));
},

optionsForQuery(id) {
let data = {};
if (!id) {
data['list'] = true;
}
return { data };
},

fetchByQuery(store, query) {
const { backend, id } = query;
return this.ajax(this.urlFor(backend, id), 'GET', this.optionsForQuery(id)).then(resp => {
resp.id = id;
resp.backend = backend;
return resp;
});
},

queryRecord(store, type, query) {
const { backend, id } = query;
const staticReq = this.staticRoles(backend, id);
const dynamicReq = this.dynamicRoles(backend, id);

return allSettled([staticReq, dynamicReq]).then(([staticResp, dynamicResp]) => {
if (!staticResp.value && !dynamicResp.value) {
// Throw error, both reqs failed
throw dynamicResp.reason;
}
// Names are distinct across both types of role,
// so only one request should ever come back with value
let type = staticResp.value ? 'static' : 'dynamic';
let successful = staticResp.value || dynamicResp.value;
let resp = {
data: {},
backend,
secret: id,
};

resp.data = assign({}, resp.data, successful.data, { backend, type, secret: id });

return resp;
});
},

query(store, type, query) {
const { backend } = query;
const staticReq = this.staticRoles(backend);
const dynamicReq = this.dynamicRoles(backend);

return allSettled([staticReq, dynamicReq]).then(([staticResp, dynamicResp]) => {
let resp = {
backend,
data: { keys: [] },
};

if (staticResp.reason && dynamicResp.reason) {
// both failed, throw error
throw dynamicResp.reason;
}
// at least one request has data
let staticRoles = [];
let dynamicRoles = [];

if (staticResp.value) {
staticRoles = staticResp.value.data.keys;
}
if (dynamicResp.value) {
dynamicRoles = dynamicResp.value.data.keys;
}

resp.data = assign(
{},
resp.data,
{ keys: [...staticRoles, ...dynamicRoles] },
{ backend },
{ staticRoles, dynamicRoles }
);

return resp;
});
},

async _updateAllowedRoles(store, { role, backend, db, type = 'add' }) {
const connection = await store.queryRecord('database/connection', { backend, id: db });
let roles = [...connection.allowed_roles];
const allowedRoles = type === 'add' ? addToArray([roles, role]) : removeFromArray([roles, role]);
connection.allowed_roles = allowedRoles;
return connection.save();
},

async createRecord(store, type, snapshot) {
const serializer = store.serializerFor(type.modelName);
const data = serializer.serialize(snapshot);
const roleType = snapshot.attr('type');
const backend = snapshot.attr('backend');
const id = snapshot.attr('name');
const db = snapshot.attr('database');
await this._updateAllowedRoles(store, {
role: id,
backend,
db: db[0],
});

return this.ajax(this.urlFor(backend, id, roleType), 'POST', { data }).then(() => {
// ember data doesn't like 204s if it's not a DELETE
return {
data: assign({}, data, { id }),
};
});
},

async deleteRecord(store, type, snapshot) {
const roleType = snapshot.attr('type');
const backend = snapshot.attr('backend');
const id = snapshot.attr('name');
const db = snapshot.attr('database');
await this._updateAllowedRoles(store, {
role: id,
backend,
db: db[0],
type: 'remove',
});

return this.ajax(this.urlFor(backend, id, roleType), 'DELETE');
},

async updateRecord(store, type, snapshot) {
const serializer = store.serializerFor(type.modelName);
const data = serializer.serialize(snapshot);
const roleType = snapshot.attr('type');
const backend = snapshot.attr('backend');
const id = snapshot.attr('name');

return this.ajax(this.urlFor(backend, id, roleType), 'POST', { data }).then(() => data);
},
});
1 change: 1 addition & 0 deletions ui/app/adapters/generated-item-list.js
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ export default ApplicationAdapter.extend({
urlForItem() {},
dynamicApiPath: '',
getDynamicApiPath: task(function*(id) {
// TODO: remove yield at some point.
let result = yield this.store.peekRecord('auth-method', id);
this.dynamicApiPath = result.apiPath;
return;
Expand Down
Loading

0 comments on commit 4be76bf

Please sign in to comment.