pr_01m47d24b0e6n91zwymwxg0vpx/services/actions/src/settings.rs
| 1 | //! Secrets and variables, a repository's or its workspace's: one list for |
| 2 | //! every reader, shaped like Vercel's environment variables. Each row is a |
| 3 | //! key, its type (a secret, or a variable shown as Config), the |
| 4 | //! environments it applies to and who reads it: workflows, deployments, or |
| 5 | //! both. A key may have one row per environment, so production and |
| 6 | //! previews can hold different values; a key's rows never overlap. |
| 7 | //! |
| 8 | //! A reader asking for an environment gets the row naming it, else the |
| 9 | //! key's row for every environment. A project's row overrides its |
| 10 | //! workspace's of the same key. |
| 11 | //! |
| 12 | //! A repository's rows belong to its project (its primary one, when it |
| 13 | //! carries several): asked for by repository, as GitHub's API does, they |
| 14 | //! are the project's. Rows from before projects move over the first time |
| 15 | //! they are touched. Names are upper-cased, as GitHub treats |
| 16 | //! them without regard to case. Agents never read any. |
| 17 | |
| 18 | use g1t_contracts::actions::{ |
| 19 | CONSUMERS, DeleteSettingArgs, ResolveSettingsArgs, ResolvedSettings, SetSettingArgs, Setting, SettingsArgs, |
| 20 | SettingsOwner, |
| 21 | }; |
| 22 | use g1t_contracts::projects::{ByRepoArgs, ProjectRef}; |
| 23 | use g1t_contracts::time::rfc3339; |
| 24 | use g1t_contracts::{FailureCode, Outcome, PrincipalKind, Role, User, new_id}; |
| 25 | use g1t_kit::now_ms; |
| 26 | use serde::Deserialize; |
| 27 | use serde_json::{Map, Value}; |
| 28 | use worker::Result; |
| 29 | use worker::wasm_bindgen::JsValue; |
| 30 | |
| 31 | use crate::{Actions, check, fail}; |
| 32 | |
| 33 | /// The largest value, as on GitHub. |
| 34 | const MAX_VALUE_BYTES: usize = 48 * 1024; |
| 35 | const MAX_PER_OWNER: u32 = 200; |
| 36 | const MAX_NOTE: usize = 500; |
| 37 | |
| 38 | #[derive(Deserialize)] |
| 39 | struct SettingRow { |
| 40 | id: String, |
| 41 | scope: String, |
| 42 | kind: String, |
| 43 | name: String, |
| 44 | value: String, |
| 45 | updated_at: String, |
| 46 | available_to: String, |
| 47 | environments: String, |
| 48 | repositories: Option<String>, |
| 49 | note: Option<String>, |
| 50 | updated_by: Option<String>, |
| 51 | } |
| 52 | |
| 53 | /// A name GitHub would accept: letters, digits and `_`, not starting with |
| 54 | /// a digit, `GITHUB_` or `G1T_`, which are g1t's own (`G1T_TOKEN` and its |
| 55 | /// alias `GITHUB_TOKEN`). |
| 56 | fn valid_name(name: &str) -> Result<String, String> { |
| 57 | let upper = name.trim().to_ascii_uppercase(); |
| 58 | if upper.is_empty() || upper.len() > 100 { |
| 59 | return Err("A name is 1 to 100 characters.".to_owned()); |
| 60 | } |
| 61 | if !upper.chars().all(|c| c.is_ascii_alphanumeric() || c == '_') { |
| 62 | return Err("A name has only letters, digits and underscores.".to_owned()); |
| 63 | } |
| 64 | if upper.starts_with(|c: char| c.is_ascii_digit()) { |
| 65 | return Err("A name cannot start with a digit.".to_owned()); |
| 66 | } |
| 67 | if upper.starts_with("GITHUB_") || upper.starts_with("G1T_") { |
| 68 | return Err("Names starting with G1T_ or GITHUB_ are kept for g1t's own, such as G1T_TOKEN.".to_owned()); |
| 69 | } |
| 70 | Ok(upper) |
| 71 | } |
| 72 | |
| 73 | /// Environments' names: lowercase letters, digits, `-` and `_`, each once. |
| 74 | fn valid_environments(list: &[String]) -> Result<Vec<String>, String> { |
| 75 | let mut out: Vec<String> = Vec::new(); |
| 76 | for name in list { |
| 77 | let lower = name.trim().to_ascii_lowercase(); |
| 78 | if lower.is_empty() { |
| 79 | continue; |
| 80 | } |
| 81 | if lower.len() > 40 || !lower.chars().all(|c| c.is_ascii_alphanumeric() || c == '-' || c == '_') { |
| 82 | return Err(format!("`{name}` is not an environment's name: up to 40 letters, digits, - and _.")); |
| 83 | } |
| 84 | if !out.contains(&lower) { |
| 85 | out.push(lower); |
| 86 | } |
| 87 | } |
| 88 | out.sort(); |
| 89 | Ok(out) |
| 90 | } |
| 91 | |
| 92 | fn consumers(list: &[String]) -> Result<Vec<String>, String> { |
| 93 | let mut out: Vec<String> = Vec::new(); |
| 94 | for item in list { |
| 95 | let item = item.trim().to_ascii_lowercase(); |
| 96 | if !CONSUMERS.contains(&item.as_str()) { |
| 97 | return Err(format!("`{item}` is not a reader: use workflows or deployments.")); |
| 98 | } |
| 99 | if !out.contains(&item) { |
| 100 | out.push(item); |
| 101 | } |
| 102 | } |
| 103 | if out.is_empty() { |
| 104 | return Err("Choose who reads it: workflows, deployments, or both.".to_owned()); |
| 105 | } |
| 106 | Ok(out) |
| 107 | } |
| 108 | |
| 109 | fn split(list: &str) -> Vec<String> { |
| 110 | list.split(',').filter(|s| !s.is_empty()).map(str::to_owned).collect() |
| 111 | } |
| 112 | |
| 113 | impl SettingRow { |
| 114 | fn environments(&self) -> Vec<String> { |
| 115 | split(&self.environments) |
| 116 | } |
| 117 | |
| 118 | /// A workspace's row: the projects it reaches. The column predates |
| 119 | /// projects; it holds their slugs. |
| 120 | fn projects(&self) -> Vec<String> { |
| 121 | self.repositories.as_deref().and_then(|json| serde_json::from_str(json).ok()).unwrap_or_default() |
| 122 | } |
| 123 | |
| 124 | fn reaches(&self, project: &str) -> bool { |
| 125 | let list = self.projects(); |
| 126 | list.is_empty() || list.iter().any(|p| p.eq_ignore_ascii_case(project)) |
| 127 | } |
| 128 | |
| 129 | /// Whether it and rows for `environments` would both apply somewhere. |
| 130 | fn overlaps(&self, environments: &[String]) -> bool { |
| 131 | let mine = self.environments(); |
| 132 | mine.is_empty() == environments.is_empty() && (mine.is_empty() || mine.iter().any(|e| environments.contains(e))) |
| 133 | } |
| 134 | |
| 135 | fn describe(self) -> Setting { |
| 136 | Setting { |
| 137 | available_to: split(&self.available_to), |
| 138 | environments: self.environments(), |
| 139 | projects: self.projects(), |
| 140 | value: (self.kind == "variable").then_some(self.value), |
| 141 | id: self.id, |
| 142 | name: self.name, |
| 143 | kind: self.kind, |
| 144 | scope: self.scope, |
| 145 | updated_at: self.updated_at, |
| 146 | note: self.note, |
| 147 | updated_by: self.updated_by, |
| 148 | } |
| 149 | } |
| 150 | } |
| 151 | |
| 152 | /// Where settings live: `(scope, owner)` with the owner a project id or a |
| 153 | /// workspace slug. |
| 154 | struct Place { |
| 155 | scope: &'static str, |
| 156 | owner: String, |
| 157 | namespace: String, |
| 158 | /// The project's slug, for a project's place. |
| 159 | slug: String, |
| 160 | } |
| 161 | |
| 162 | impl Actions { |
| 163 | async fn place(&self, actor: &User, owner: &SettingsOwner, changing: bool) -> Result<Outcome<Place>> { |
| 164 | if actor.kind == PrincipalKind::Agent { |
| 165 | return Ok(fail(FailureCode::Forbidden, "Agents cannot read or change secrets and variables.")); |
| 166 | } |
| 167 | // A workspace's tokens, G1T_TOKEN among them, read the names but |
| 168 | // never change them: a workflow must not rewrite what it runs with. |
| 169 | if changing && actor.kind == PrincipalKind::Workspace { |
| 170 | return Ok(fail( |
| 171 | FailureCode::Forbidden, |
| 172 | "A workspace's tokens, G1T_TOKEN included, cannot change secrets and variables. Use a person's token or the site.", |
| 173 | )); |
| 174 | } |
| 175 | match (&owner.repo, &owner.workspace) { |
| 176 | (Some(path), _) => { |
| 177 | if !actor.is_member(&path.namespace.to_lowercase()) { |
| 178 | return Ok(fail(FailureCode::Forbidden, format!("Only members of {} can see its secrets and variables.", path.namespace))); |
| 179 | } |
| 180 | let Some(repo) = self.visible_repo(path, &Some(actor.clone())).await? else { |
| 181 | return Ok(fail(FailureCode::NotFound, "There is no such repository.")); |
| 182 | }; |
| 183 | let Some(project) = self.project_of(&repo.id).await? else { |
| 184 | return Ok(fail(FailureCode::NotFound, "The repository has no project.")); |
| 185 | }; |
| 186 | Ok(Outcome::Ok(Place { scope: "project", owner: project.id, namespace: repo.namespace, slug: project.slug })) |
| 187 | } |
| 188 | (None, Some(slug)) => { |
| 189 | let slug = slug.to_lowercase(); |
| 190 | let role = actor.workspaces.iter().find(|m| m.slug.eq_ignore_ascii_case(&slug)).map(|m| m.role); |
| 191 | match role { |
| 192 | None => Ok(fail(FailureCode::Forbidden, format!("Only members of {slug} can see its secrets and variables."))), |
| 193 | Some(Role::Member) if changing => Ok(fail(FailureCode::Forbidden, format!("Only owners of {slug} can change its secrets and variables."))), |
| 194 | Some(_) => Ok(Outcome::Ok(Place { scope: "workspace", owner: slug.clone(), namespace: slug, slug: String::new() })), |
| 195 | } |
| 196 | } |
| 197 | (None, None) => Ok(fail(FailureCode::Invalid, "Give `repo` or `workspace`.")), |
| 198 | } |
| 199 | } |
| 200 | |
| 201 | /// A repository's primary project, with the rows kept under the |
| 202 | /// repository before projects moved to it. |
| 203 | pub(crate) async fn project_of(&self, repo_id: &str) -> Result<Option<ProjectRef>> { |
| 204 | let projects: Vec<ProjectRef> = |
| 205 | g1t_kit::call(&self.projects, "by_repo", &ByRepoArgs { repo_id: repo_id.to_owned() }).await?; |
| 206 | let Some(project) = projects.into_iter().find(|p| p.primary) else { |
| 207 | return Ok(None); |
| 208 | }; |
| 209 | self.db |
| 210 | .prepare("UPDATE settings SET owner = ?, scope = 'project' WHERE owner = ?") |
| 211 | .bind(&[project.id.as_str().into(), repo_id.into()])? |
| 212 | .run() |
| 213 | .await?; |
| 214 | Ok(Some(project)) |
| 215 | } |
| 216 | |
| 217 | /// `secret`, `variable`, or `None` for both. |
| 218 | fn kind(kind: &str) -> Outcome<Option<&'static str>> { |
| 219 | match kind { |
| 220 | "secret" | "secrets" => Outcome::Ok(Some("secret")), |
| 221 | "variable" | "variables" | "config" => Outcome::Ok(Some("variable")), |
| 222 | "" | "all" => Outcome::Ok(None), |
| 223 | _ => fail(FailureCode::Invalid, "`kind` is `secret` or `variable`."), |
| 224 | } |
| 225 | } |
| 226 | |
| 227 | async fn rows(&self, owner: &str) -> Result<Vec<SettingRow>> { |
| 228 | self.db |
| 229 | .prepare("SELECT * FROM settings WHERE owner = ? ORDER BY name, environments") |
| 230 | .bind(&[owner.into()])? |
| 231 | .all() |
| 232 | .await? |
| 233 | .results::<SettingRow>() |
| 234 | } |
| 235 | |
| 236 | pub async fn settings(&self, a: SettingsArgs) -> Result<Outcome<Vec<Setting>>> { |
| 237 | let kind = check!(Self::kind(&a.kind)); |
| 238 | let place = check!(self.place(&a.actor, &a.owner, false).await?); |
| 239 | let mut out: Vec<Setting> = Vec::new(); |
| 240 | // A project's list shows the workspace's rows that reach it, but for |
| 241 | // keys it sets itself. |
| 242 | if place.scope == "project" { |
| 243 | let own: Vec<String> = self.rows(&place.owner).await?.into_iter().map(|row| row.name).collect(); |
| 244 | for row in self.rows(&place.namespace.to_lowercase()).await? { |
| 245 | if row.reaches(&place.slug) && !own.contains(&row.name) { |
| 246 | out.push(row.describe()); |
| 247 | } |
| 248 | } |
| 249 | } |
| 250 | out.extend(self.rows(&place.owner).await?.into_iter().map(SettingRow::describe)); |
| 251 | out.retain(|setting| kind.is_none_or(|kind| setting.kind == kind)); |
| 252 | out.sort_by(|a, b| a.name.cmp(&b.name).then(a.environments.cmp(&b.environments))); |
| 253 | Ok(Outcome::Ok(out)) |
| 254 | } |
| 255 | |
| 256 | fn seal(&self, value: &str, id: &str) -> Outcome<String> { |
| 257 | match &self.sealer { |
| 258 | Some(sealer) => Outcome::Ok(sealer.seal(value, id)), |
| 259 | None => fail(FailureCode::Conflict, "Secrets cannot be saved yet: g1t's key for them is not set."), |
| 260 | } |
| 261 | } |
| 262 | |
| 263 | pub async fn set_setting(&self, a: SetSettingArgs) -> Result<Outcome<Setting>> { |
| 264 | let Some(kind) = check!(Self::kind(&a.kind)) else { |
| 265 | return Ok(fail(FailureCode::Invalid, "`kind` is `secret` or `variable`.")); |
| 266 | }; |
| 267 | let name = match valid_name(&a.name) { |
| 268 | Ok(name) => name, |
| 269 | Err(problem) => return Ok(fail(FailureCode::Invalid, problem)), |
| 270 | }; |
| 271 | if a.value.as_ref().is_some_and(|v| v.len() > MAX_VALUE_BYTES) { |
| 272 | return Ok(fail(FailureCode::Invalid, "A value is at most 48 KB.")); |
| 273 | } |
| 274 | if a.note.as_ref().is_some_and(|n| n.len() > MAX_NOTE) { |
| 275 | return Ok(fail(FailureCode::Invalid, "A note is at most 500 characters.")); |
| 276 | } |
| 277 | let readers = match a.available_to.as_deref().map(consumers).transpose() { |
| 278 | Ok(readers) => readers, |
| 279 | Err(problem) => return Ok(fail(FailureCode::Invalid, problem)), |
| 280 | }; |
| 281 | let environments = match a.environments.as_deref().map(valid_environments).transpose() { |
| 282 | Ok(environments) => environments, |
| 283 | Err(problem) => return Ok(fail(FailureCode::Invalid, problem)), |
| 284 | }; |
| 285 | let place = check!(self.place(&a.actor, &a.owner, true).await?); |
| 286 | if a.projects.as_ref().is_some_and(|r| !r.is_empty()) && place.scope != "workspace" { |
| 287 | return Ok(fail(FailureCode::Invalid, "Only a workspace's rows choose projects.")); |
| 288 | } |
| 289 | let rows = self.rows(&place.owner).await?; |
| 290 | // A secret and a variable may share a key, as on GitHub, where |
| 291 | // workflows read them apart (`secrets.X`, `vars.X`). |
| 292 | let same_key: Vec<&SettingRow> = rows.iter().filter(|row| row.name == name).collect(); |
| 293 | // The row being changed: by id, else the key's row for every |
| 294 | // environment (GitHub's API names a secret by its key alone). |
| 295 | let existing = match &a.id { |
| 296 | Some(id) => match rows.iter().find(|row| &row.id == id) { |
| 297 | Some(row) => Some(row), |
| 298 | None => return Ok(fail(FailureCode::NotFound, "There is no such row.")), |
| 299 | }, |
| 300 | None if a.environments.is_none() => same_key.iter().copied().find(|row| row.environments.is_empty() && row.kind == kind), |
| 301 | None => None, |
| 302 | }; |
| 303 | if existing.is_some_and(|row| row.kind == "secret" && kind == "variable") { |
| 304 | return Ok(fail(FailureCode::Invalid, "A secret cannot become config: its value is sealed. Add a config row and remove the secret.")); |
| 305 | } |
| 306 | let environments = environments.unwrap_or_else(|| existing.map(SettingRow::environments).unwrap_or_default()); |
| 307 | // A key's rows never apply to the same environment twice. |
| 308 | if let Some(clash) = same_key |
| 309 | .iter() |
| 310 | .find(|row| row.kind == kind && existing.is_none_or(|e| e.id != row.id) && row.overlaps(&environments)) |
| 311 | { |
| 312 | let at = if clash.environments.is_empty() { "all environments".to_owned() } else { clash.environments.replace(',', ", ") }; |
| 313 | let what = if kind == "secret" { "secret" } else { "config" }; |
| 314 | return Ok(fail( |
| 315 | FailureCode::Conflict, |
| 316 | format!("{name} already has a {what} row for {at}. Edit that row, or choose other environments."), |
| 317 | )); |
| 318 | } |
| 319 | if existing.is_none() && rows.len() as u32 >= MAX_PER_OWNER { |
| 320 | return Ok(fail(FailureCode::Invalid, format!("There can be at most {MAX_PER_OWNER} secrets and variables here."))); |
| 321 | } |
| 322 | let id = existing.map(|row| row.id.clone()).unwrap_or_else(|| new_id("set", now_ms())); |
| 323 | let value = match (&a.value, existing) { |
| 324 | (Some(value), _) if kind == "secret" => check!(self.seal(value, &id)), |
| 325 | (Some(value), _) => value.clone(), |
| 326 | // Config becoming a secret: its value is sealed now. |
| 327 | (None, Some(row)) if row.kind == "variable" && kind == "secret" => check!(self.seal(&row.value, &id)), |
| 328 | (None, Some(row)) => row.value.clone(), |
| 329 | (None, None) => return Ok(fail(FailureCode::Invalid, "A new row needs a `value`.")), |
| 330 | }; |
| 331 | let available_to = readers |
| 332 | .map(|r| r.join(",")) |
| 333 | .or_else(|| existing.map(|row| row.available_to.clone())) |
| 334 | .unwrap_or_else(|| CONSUMERS.join(",")); |
| 335 | let repositories: Option<String> = match &a.projects { |
| 336 | Some(list) if list.is_empty() => None, |
| 337 | Some(list) => Some(serde_json::to_string(list).unwrap_or_default()), |
| 338 | None => existing.and_then(|row| row.repositories.clone()), |
| 339 | }; |
| 340 | let note = match &a.note { |
| 341 | Some(note) if note.trim().is_empty() => None, |
| 342 | Some(note) => Some(note.trim().to_owned()), |
| 343 | None => existing.and_then(|row| row.note.clone()), |
| 344 | }; |
| 345 | let at = rfc3339(now_ms()); |
| 346 | let optional = |v: Option<&str>| v.map_or(JsValue::NULL, JsValue::from); |
| 347 | self.db |
| 348 | .prepare( |
| 349 | "INSERT INTO settings (id, scope, owner, kind, name, value, updated_at, available_to, environments, repositories, note, updated_by) |
| 350 | VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) |
| 351 | ON CONFLICT (id) DO UPDATE SET kind = excluded.kind, value = excluded.value, updated_at = excluded.updated_at, |
| 352 | available_to = excluded.available_to, environments = excluded.environments, |
| 353 | repositories = excluded.repositories, note = excluded.note, updated_by = excluded.updated_by", |
| 354 | ) |
| 355 | .bind(&[ |
| 356 | id.as_str().into(), |
| 357 | place.scope.into(), |
| 358 | place.owner.as_str().into(), |
| 359 | kind.into(), |
| 360 | name.as_str().into(), |
| 361 | value.into(), |
| 362 | at.as_str().into(), |
| 363 | available_to.as_str().into(), |
| 364 | environments.join(",").into(), |
| 365 | optional(repositories.as_deref()), |
| 366 | optional(note.as_deref()), |
| 367 | a.actor.username.as_str().into(), |
| 368 | ])? |
| 369 | .run() |
| 370 | .await?; |
| 371 | let row = self |
| 372 | .db |
| 373 | .prepare("SELECT * FROM settings WHERE id = ?") |
| 374 | .bind(&[id.as_str().into()])? |
| 375 | .first::<SettingRow>(None) |
| 376 | .await? |
| 377 | .expect("just written"); |
| 378 | Ok(Outcome::Ok(row.describe())) |
| 379 | } |
| 380 | |
| 381 | pub async fn delete_setting(&self, a: DeleteSettingArgs) -> Result<Outcome<bool>> { |
| 382 | let kind = check!(Self::kind(&a.kind)); |
| 383 | let place = check!(self.place(&a.actor, &a.owner, true).await?); |
| 384 | let name = a.name.trim().to_ascii_uppercase(); |
| 385 | let removed = match &a.id { |
| 386 | Some(id) => self |
| 387 | .db |
| 388 | .prepare("DELETE FROM settings WHERE owner = ? AND id = ? RETURNING id") |
| 389 | .bind(&[place.owner.as_str().into(), id.as_str().into()])? |
| 390 | .all() |
| 391 | .await?, |
| 392 | None => self |
| 393 | .db |
| 394 | .prepare("DELETE FROM settings WHERE owner = ? AND name = ? AND (?3 IS NULL OR kind = ?3) RETURNING id") |
| 395 | .bind(&[place.owner.as_str().into(), name.as_str().into(), kind.map_or(JsValue::NULL, JsValue::from)])? |
| 396 | .all() |
| 397 | .await?, |
| 398 | }; |
| 399 | Ok(if removed.results::<Value>()?.is_empty() { |
| 400 | fail(FailureCode::NotFound, format!("There is nothing called {} here.", a.name)) |
| 401 | } else { |
| 402 | Outcome::Ok(true) |
| 403 | }) |
| 404 | } |
| 405 | |
| 406 | /// What one reader of a repository gets: per key, the row for |
| 407 | /// `environment`, else the row for every environment; the repository's |
| 408 | /// over its workspace's. No secrets unless `trusted`. |
| 409 | #[allow(clippy::too_many_arguments)] |
| 410 | async fn resolved( |
| 411 | &self, |
| 412 | project_id: &str, |
| 413 | project_slug: &str, |
| 414 | namespace: &str, |
| 415 | kind: &str, |
| 416 | consumer: &str, |
| 417 | environment: Option<&str>, |
| 418 | trusted: bool, |
| 419 | ) -> Result<Map<String, Value>> { |
| 420 | if kind == "secret" && !trusted { |
| 421 | return Ok(Map::new()); |
| 422 | } |
| 423 | let environment = environment.map(str::to_ascii_lowercase); |
| 424 | let mut out = Map::new(); |
| 425 | for owner in [namespace.to_lowercase(), project_id.to_owned()] { |
| 426 | let rows: Vec<SettingRow> = self |
| 427 | .rows(&owner) |
| 428 | .await? |
| 429 | .into_iter() |
| 430 | .filter(|row| row.kind == kind) |
| 431 | .filter(|row| split(&row.available_to).iter().any(|r| r == consumer)) |
| 432 | .filter(|row| row.scope != "workspace" || row.reaches(project_slug)) |
| 433 | .collect(); |
| 434 | let mut names: Vec<&str> = rows.iter().map(|row| row.name.as_str()).collect(); |
| 435 | names.dedup(); |
| 436 | for name in names { |
| 437 | let of_key: Vec<&SettingRow> = rows.iter().filter(|row| row.name == name).collect(); |
| 438 | let chosen = environment |
| 439 | .as_deref() |
| 440 | .and_then(|env| of_key.iter().find(|row| row.environments().iter().any(|e| e == env))) |
| 441 | .or_else(|| of_key.iter().find(|row| row.environments.is_empty())); |
| 442 | let Some(row) = chosen else { |
| 443 | // Rows only for other environments: this reader gets |
| 444 | // none, nor the workspace's. |
| 445 | out.remove(name); |
| 446 | continue; |
| 447 | }; |
| 448 | let value = if kind == "secret" { |
| 449 | match self.sealer.as_ref().and_then(|sealer| sealer.open(&row.value, &row.id)) { |
| 450 | Some(value) => value, |
| 451 | None => continue, |
| 452 | } |
| 453 | } else { |
| 454 | row.value.clone() |
| 455 | }; |
| 456 | out.insert(name.to_owned(), Value::String(value)); |
| 457 | } |
| 458 | } |
| 459 | Ok(out) |
| 460 | } |
| 461 | |
| 462 | /// The `vars` context of a repository's runs. `environment` is the job's |
| 463 | /// `environment:`, when it has one. |
| 464 | pub async fn variables_for(&self, repo_id: &str, repo: &str, environment: Option<&str>, trusted: bool) -> Result<Map<String, Value>> { |
| 465 | let (namespace, _) = repo.split_once('/').unwrap_or((repo, "")); |
| 466 | let Some(project) = self.project_of(repo_id).await? else { |
| 467 | return Ok(Map::new()); |
| 468 | }; |
| 469 | self.resolved(&project.id, &project.slug, namespace, "variable", "workflows", environment, trusted).await |
| 470 | } |
| 471 | |
| 472 | /// The `secrets` context of a repository's runs, opened. |
| 473 | pub async fn secrets_for(&self, repo_id: &str, repo: &str, environment: Option<&str>, trusted: bool) -> Result<Map<String, Value>> { |
| 474 | let (namespace, _) = repo.split_once('/').unwrap_or((repo, "")); |
| 475 | let Some(project) = self.project_of(repo_id).await? else { |
| 476 | return Ok(Map::new()); |
| 477 | }; |
| 478 | self.resolved(&project.id, &project.slug, namespace, "secret", "workflows", environment, trusted).await |
| 479 | } |
| 480 | |
| 481 | /// `resolve_settings`, for the deployments service: what a deploy build |
| 482 | /// and its running app get. |
| 483 | pub async fn resolve_settings(&self, a: ResolveSettingsArgs) -> Result<ResolvedSettings> { |
| 484 | let environment = a.environment.as_deref(); |
| 485 | // Rows kept under the repository from before projects move to its |
| 486 | // primary project first, however the project is named here. |
| 487 | let primary = self.project_of(&a.repo_id).await?; |
| 488 | let (project_id, slug) = match (a.project_id, a.project_slug, primary) { |
| 489 | (Some(id), Some(slug), _) => (id, slug), |
| 490 | (_, _, Some(project)) => (project.id, project.slug), |
| 491 | _ => return Ok(ResolvedSettings::default()), |
| 492 | }; |
| 493 | Ok(ResolvedSettings { |
| 494 | secrets: self |
| 495 | .resolved(&project_id, &slug, &a.repo.namespace, "secret", &a.consumer, environment, a.trusted) |
| 496 | .await?, |
| 497 | variables: self |
| 498 | .resolved(&project_id, &slug, &a.repo.namespace, "variable", &a.consumer, environment, a.trusted) |
| 499 | .await?, |
| 500 | }) |
| 501 | } |
| 502 | } |
| 503 | |
| 504 | #[cfg(test)] |
| 505 | mod tests { |
| 506 | use super::{SettingRow, consumers, valid_environments, valid_name}; |
| 507 | |
| 508 | fn row(environments: &str) -> SettingRow { |
| 509 | SettingRow { |
| 510 | id: "set_1".into(), |
| 511 | scope: "repository".into(), |
| 512 | kind: "secret".into(), |
| 513 | name: "STRIPE_KEY".into(), |
| 514 | value: String::new(), |
| 515 | updated_at: String::new(), |
| 516 | available_to: "workflows,deployments".into(), |
| 517 | environments: environments.into(), |
| 518 | repositories: None, |
| 519 | note: None, |
| 520 | updated_by: None, |
| 521 | } |
| 522 | } |
| 523 | |
| 524 | #[test] |
| 525 | fn names_follow_githubs_rules_and_keep_g1ts_own() { |
| 526 | assert_eq!(valid_name("npm_token").unwrap(), "NPM_TOKEN"); |
| 527 | assert!(valid_name("GITHUB_TOKEN").is_err()); |
| 528 | assert!(valid_name("G1T_TOKEN").is_err()); |
| 529 | assert!(valid_name("1PASSWORD").is_err()); |
| 530 | assert!(valid_name("MY-TOKEN").is_err()); |
| 531 | assert!(valid_name("").is_err()); |
| 532 | } |
| 533 | |
| 534 | #[test] |
| 535 | fn environments_and_readers_are_checked() { |
| 536 | assert_eq!(valid_environments(&["Production".into(), "preview".into(), "production".into()]).unwrap(), vec!["preview", "production"]); |
| 537 | assert!(valid_environments(&["staging env".into()]).is_err()); |
| 538 | assert_eq!(consumers(&["Deployments".into(), "deployments".into()]).unwrap(), vec!["deployments"]); |
| 539 | assert!(consumers(&["agents".into()]).is_err()); |
| 540 | assert!(consumers(&[]).is_err()); |
| 541 | } |
| 542 | |
| 543 | #[test] |
| 544 | fn a_keys_rows_cannot_share_an_environment() { |
| 545 | assert!(row("production").overlaps(&["production".into(), "preview".into()])); |
| 546 | assert!(!row("production").overlaps(&["preview".into()])); |
| 547 | // One row for every environment, and others for some, live together. |
| 548 | assert!(!row("").overlaps(&["preview".into()])); |
| 549 | assert!(row("").overlaps(&[])); |
| 550 | } |
| 551 | } |