mirror of
https://github.com/dadosfera/maestro.git
synced 2026-09-01 12:18:15 +00:00
Compare commits
53
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d4ba45fd03 | ||
|
|
82f1035a5e | ||
|
|
9a217dff57 | ||
|
|
cd4382c1ff | ||
|
|
0e038d0b12 | ||
|
|
c97a02cb17 | ||
|
|
878ec977b8 | ||
|
|
8006867bc2 | ||
|
|
784b0ef090 | ||
|
|
b736cddf07 | ||
|
|
3d6328fb0b | ||
|
|
4246c7495e | ||
|
|
3d40746ccb | ||
|
|
3ab2f8f27d | ||
|
|
b44d23552c | ||
|
|
8e63757738 | ||
|
|
3b84409003 | ||
|
|
0ce3822300 | ||
|
|
a2c7ce00db | ||
|
|
121e30ce45 | ||
|
|
85c8a4937d | ||
|
|
53920f2f3f | ||
|
|
8c34914806 | ||
|
|
1881d07c4a | ||
|
|
3b8310fdca | ||
|
|
52bda8ebe2 | ||
|
|
275a53dbd1 | ||
|
|
9cefdb226d | ||
|
|
007f3911ff | ||
|
|
8ac0a8a79f | ||
|
|
285de97375 | ||
|
|
e2a7d2b92b | ||
|
|
da23ad76db | ||
|
|
55b0961b82 | ||
|
|
d3c5c0fa63 | ||
|
|
5dbc644d1d | ||
|
|
8eddb9e1bf | ||
|
|
76485f929d | ||
|
|
8e0182aa50 | ||
|
|
a18bdccc09 | ||
|
|
b27298501d | ||
|
|
33ebc91826 | ||
|
|
6948156693 | ||
|
|
0aaa4384c3 | ||
|
|
1f9d0c29ec | ||
|
|
039c652b28 | ||
|
|
653d4f53b5 | ||
|
|
31f8c2c1a6 | ||
|
|
adeb022818 | ||
|
|
f61c241dde | ||
|
|
e326cab44d | ||
|
|
3f8dc5cabe | ||
|
|
e7f410831f |
@@ -0,0 +1,12 @@
|
||||
node_modules
|
||||
dist
|
||||
.git
|
||||
*.log
|
||||
npm-debug.log*
|
||||
.DS_Store
|
||||
.env
|
||||
.env.*
|
||||
coverage
|
||||
.nyc_output
|
||||
*.tgz
|
||||
!protospack.tgz
|
||||
+2
-1
@@ -1,4 +1,5 @@
|
||||
FROM node:18.17-alpine AS base_image
|
||||
FROM node:20-alpine AS base_image
|
||||
RUN npm install -g npm@latest
|
||||
|
||||
FROM base_image AS build_base
|
||||
WORKDIR /app
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
FROM node:22-alpine AS base_image
|
||||
RUN npm install -g npm@latest
|
||||
|
||||
FROM base_image AS build_base
|
||||
WORKDIR /app
|
||||
RUN apk update
|
||||
RUN apk add --no-cache \
|
||||
aws-cli \
|
||||
chromium \
|
||||
nss \
|
||||
freetype \
|
||||
harfbuzz \
|
||||
ca-certificates \
|
||||
ttf-freefont
|
||||
COPY package*.json ./
|
||||
|
||||
ENV PUPPETEER_SKIP_CHROMIUM_DOWNLOAD=true \
|
||||
PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium-browser
|
||||
|
||||
|
||||
# Local build with secrets
|
||||
FROM build_base AS build
|
||||
RUN --mount=type=secret,id=aws,target=/root/.aws/credentials \
|
||||
aws codeartifact login --tool npm --namespace @dadosfera --repository dadosfera-npm --domain dadosfera --domain-owner 611330257153 --region us-east-1
|
||||
RUN npm ci
|
||||
COPY . .
|
||||
RUN npm run build
|
||||
|
||||
|
||||
FROM base_image
|
||||
WORKDIR /app
|
||||
COPY --from=build /app/dist ./dist
|
||||
COPY --from=build /app/node_modules ./node_modules
|
||||
COPY --from=build /app/package*.json ./
|
||||
RUN apk update
|
||||
RUN apk add --no-cache \
|
||||
chromium \
|
||||
nss \
|
||||
freetype \
|
||||
harfbuzz \
|
||||
ca-certificates \
|
||||
ttf-freefont
|
||||
|
||||
ENV PUPPETEER_SKIP_CHROMIUM_DOWNLOAD=true \
|
||||
PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium-browser
|
||||
|
||||
ENTRYPOINT ["npm", "run", "start:prod"]
|
||||
@@ -48,6 +48,9 @@ spec:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
# Auth Provider Configuration (cognito or keycloak)
|
||||
- name: AUTH_PROVIDER
|
||||
value: {{ .Values.maestro.auth_provider | default "cognito" | quote }}
|
||||
- name: AWS_IDENTITY_POOL_ID
|
||||
value: {{ .Values.maestro.aws_identity_pool_id }}
|
||||
- name: AWS_REGION
|
||||
@@ -108,6 +111,8 @@ spec:
|
||||
value: "{{ .Values.maestro.redis_tls }}"
|
||||
- name: PLATFORM_API_URL
|
||||
value: {{ .Values.maestro.platform_api_url }}
|
||||
- name: STORAGE_EXPLORER_API_URL
|
||||
value: {{ .Values.maestro.storage_explorer_api_url | quote }}
|
||||
- name: JWT_PRIVATE_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
|
||||
@@ -9,6 +9,7 @@ maestro:
|
||||
cookie_secret: "ff7bc13823edb2ae50d248e5780bddc9d4b31c36"
|
||||
redis_database: "1"
|
||||
platform_api_url: https://xs2hkhq07k.execute-api.us-east-1.amazonaws.com
|
||||
storage_explorer_api_url: "http://storage-explorer-{customer}.data-apps.svc.cluster.local:8000/api"
|
||||
|
||||
hostname: maestro.stg.dadosfera.ai
|
||||
|
||||
|
||||
@@ -27,6 +27,9 @@ resources:
|
||||
cpu: 2000m
|
||||
memory: 2Gi
|
||||
maestro:
|
||||
# Auth provider: "cognito" (default) or "keycloak"
|
||||
# Note: maestro doesn't connect to Keycloak directly, only duc does
|
||||
auth_provider: "cognito"
|
||||
aws_identity_pool_id: "us-east-1_Mrezsw9Sn"
|
||||
duc_url: duc.dadosfera.ai
|
||||
in_factory_url: in-factory.dadosfera.ai
|
||||
@@ -44,6 +47,7 @@ maestro:
|
||||
open_customer_id: f239718a-a271-4ef9-ae7e-02a2f0f3aa6e
|
||||
open_group_id: 401573bb-334f-44b2-b30e-88d4cea31ae9
|
||||
platform_api_url: https://oz8v2zid1e.execute-api.us-east-1.amazonaws.com
|
||||
storage_explorer_api_url: "https://storage-explorer-{customer}.dadosfera.ai/api"
|
||||
dedicated_proxy: ""
|
||||
restricted_ip: ""
|
||||
redis_host: "aaapzppmlyamkocqwstpo7zvopczyyiyuy6xzm2g6c5k4mq3a66be4a-0.redis.sa-saopaulo-1.oci.oraclecloud.com"
|
||||
|
||||
+1136
-281
File diff suppressed because it is too large
Load Diff
Generated
+2122
-2991
File diff suppressed because it is too large
Load Diff
+9
-3
@@ -35,7 +35,7 @@
|
||||
"@aws-sdk/signature-v4": "^3.370.0",
|
||||
"@dadosfera/dadosfera-logs": "^1.0.0-beta.4",
|
||||
"@dadosfera/protospack": "2.5.3",
|
||||
"@dadosfera/protospack-v2": "3.38.0-beta.18",
|
||||
"@dadosfera/protospack-v2": "^3.38.0-beta.26",
|
||||
"@grpc/grpc-js": "^1.9.3",
|
||||
"@grpc/proto-loader": "^0.7.9",
|
||||
"@nestjs/cli": "^9.5.0",
|
||||
@@ -49,7 +49,7 @@
|
||||
"@nestjs/schematics": "^9.2.0",
|
||||
"@nestjs/swagger": "^6.3.0",
|
||||
"@nestjs/testing": "^9.4.3",
|
||||
"axios": "^0.27.2",
|
||||
"axios": "^0.30.2",
|
||||
"cache-manager": "^5.1.4",
|
||||
"cache-manager-ioredis-yet": "^1.1.0",
|
||||
"class-transformer": "^0.5.1",
|
||||
@@ -80,7 +80,13 @@
|
||||
"swagger-ui-express": "^4.6.3"
|
||||
},
|
||||
"overrides": {
|
||||
"multer": "1.4.5-lts.1"
|
||||
"multer": "2.0.2",
|
||||
"form-data": "^4.0.4",
|
||||
"body-parser": "^1.20.3",
|
||||
"cross-spawn": "^7.0.5",
|
||||
"glob": "^10.5.0",
|
||||
"path-to-regexp": "^3.3.0",
|
||||
"semver": "^7.5.2"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/cache-manager": "^4.0.6",
|
||||
|
||||
@@ -34,6 +34,7 @@ import { AssignModule } from './modules/assign/assign.module';
|
||||
import { ShareMetadataModule } from './modules/share-metadata/share-metadata.module';
|
||||
import { ApiKeyModule } from './modules/api-key/api-key.module';
|
||||
import { PlatformApiModule } from './modules/platform-api/platform-api.module';
|
||||
import { StorageExplorerModule } from './modules/storage-explorer/storage-explorer.module';
|
||||
|
||||
@Module({
|
||||
providers: [
|
||||
@@ -75,6 +76,7 @@ import { PlatformApiModule } from './modules/platform-api/platform-api.module';
|
||||
IdentityProviderModule,
|
||||
NetworkPolicyModule,
|
||||
PlatformApiModule,
|
||||
StorageExplorerModule,
|
||||
//Always leave HealthModule last, so it is on the bottom of swagger
|
||||
HealthModule,
|
||||
],
|
||||
|
||||
@@ -668,6 +668,35 @@ export const PERMISSIONS_GROUPS = {
|
||||
},
|
||||
},
|
||||
},
|
||||
STORAGE_EXPLORER: {
|
||||
title: {
|
||||
'pt-br': 'Storage Explorer',
|
||||
'en-us': 'Storage Explorer',
|
||||
'es-es': 'Storage Explorer',
|
||||
},
|
||||
permissions: {
|
||||
READ: {
|
||||
seqid: 51,
|
||||
claim: 'storage-explorer:read',
|
||||
usage: PermissionUsages.PUBLIC,
|
||||
name: {
|
||||
'pt-br': 'Ler dados do Storage Explorer',
|
||||
'en-us': 'Read Storage Explorer data',
|
||||
'es-es': 'Leer datos del Storage Explorer',
|
||||
},
|
||||
},
|
||||
WRITE: {
|
||||
seqid: 52,
|
||||
claim: 'storage-explorer:write',
|
||||
usage: PermissionUsages.PUBLIC,
|
||||
name: {
|
||||
'pt-br': 'Escrever dados no Storage Explorer',
|
||||
'en-us': 'Write Storage Explorer data',
|
||||
'es-es': 'Escribir datos en Storage Explorer',
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
};
|
||||
export interface DadosferaModule {
|
||||
name: string;
|
||||
|
||||
@@ -55,6 +55,7 @@ import jwt, { JwtPayload } from 'jsonwebtoken';
|
||||
import { LanguageEnum } from 'src/utils/languages.enum';
|
||||
import { Language } from 'src/decorators/language.decorator';
|
||||
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
|
||||
import { ApiKeyService } from 'src/modules/api-key/api-key.service';
|
||||
|
||||
type CookiesValues = {
|
||||
accessToken?: string;
|
||||
@@ -74,6 +75,7 @@ export class AuthController {
|
||||
@Inject(DadosferaLogger)
|
||||
dadosferaLogger: DadosferaLogger,
|
||||
private authClient: AuthClientService,
|
||||
private apiKeyService: ApiKeyService,
|
||||
) {
|
||||
this.logger = dadosferaLogger.logger;
|
||||
|
||||
@@ -190,13 +192,14 @@ export class AuthController {
|
||||
) {
|
||||
this.logger.info('/auth - change-password');
|
||||
|
||||
const { oldPassword, newPassword } = body;
|
||||
const { oldPassword, newPassword, totpCode } = body;
|
||||
const { authorization: accessToken } = headers;
|
||||
|
||||
return this.authClient.changePassword({
|
||||
accessToken,
|
||||
oldPassword,
|
||||
newPassword,
|
||||
totpCode,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -214,7 +217,8 @@ export class AuthController {
|
||||
|
||||
const { username } = body;
|
||||
|
||||
return this.authClient.resetPassword({ username }, metadata);
|
||||
await this.authClient.resetPassword({ username }, metadata);
|
||||
return { authProvider: process.env.AUTH_PROVIDER || 'cognito' };
|
||||
}
|
||||
|
||||
@ApiInternalOnlyEndpoint()
|
||||
@@ -475,10 +479,29 @@ export class AuthController {
|
||||
async getMe(@Req() req: Request, @Res() res: Response) {
|
||||
this.logger.info('GET /auth/me ')
|
||||
|
||||
// Check for API key header first
|
||||
const apiKey = req.get('X-Api-key');
|
||||
if (apiKey) {
|
||||
this.logger.info('Authenticating via X-Api-key header');
|
||||
const { api_key } = await this.apiKeyService.get(apiKey);
|
||||
|
||||
const userDto = {
|
||||
id: api_key.user_id,
|
||||
name: api_key.username,
|
||||
customer: {
|
||||
id: api_key.customer_id,
|
||||
name: api_key.customer_name,
|
||||
tier: api_key.customer_tier,
|
||||
}
|
||||
};
|
||||
|
||||
return res.status(200).json(userDto);
|
||||
}
|
||||
|
||||
// Get token and headers
|
||||
const accessToken = req.cookies['ddf-auth'];
|
||||
const refreshToken = req.cookies['ddf-refresh-auth'];
|
||||
const userId = req.cookies['ddf-user-id'];
|
||||
const refreshToken = req.cookies['ddf-refresh-auth'];
|
||||
const userId = req.cookies['ddf-user-id'];
|
||||
const resourceHost = req.headers["host"]
|
||||
|
||||
const hasUserSession = Boolean(accessToken) && Boolean(userId);
|
||||
|
||||
@@ -8,10 +8,11 @@ import { AuthClientService } from './auth.service';
|
||||
import { DucClient } from '../duc/client.config';
|
||||
import { GoogleLoginStrategy } from './passport-strategies/google-strategy';
|
||||
import { getOauthSecrets } from 'src/utils/OauthSecrets';
|
||||
import { ApiKeyModule } from '../api-key/api-key.module';
|
||||
const client = new DucClient();
|
||||
|
||||
@Module({
|
||||
imports: [ClientsModule.register([client.providerOptions])],
|
||||
imports: [ClientsModule.register([client.providerOptions]), ApiKeyModule],
|
||||
controllers: [AuthController],
|
||||
providers: [
|
||||
AuthClientService,
|
||||
|
||||
@@ -143,6 +143,7 @@ export class AuthClientService implements OnModuleInit {
|
||||
accessToken,
|
||||
oldPassword,
|
||||
newPassword,
|
||||
totpCode,
|
||||
}: AuthChangePasswordRequest) {
|
||||
this.logger.info('ChangePassword');
|
||||
|
||||
@@ -151,6 +152,7 @@ export class AuthClientService implements OnModuleInit {
|
||||
accessToken,
|
||||
oldPassword,
|
||||
newPassword,
|
||||
totpCode,
|
||||
}),
|
||||
);
|
||||
}
|
||||
|
||||
@@ -98,6 +98,8 @@ export class IDataAsset {
|
||||
embed?: EmbedObject;
|
||||
@ApiPropertyOptional({ enum: DataAssetShareType })
|
||||
share_type?: DataAssetShareType;
|
||||
@ApiPropertyOptional()
|
||||
docs?: string;
|
||||
}
|
||||
|
||||
export class IOneDataAsset {
|
||||
@@ -200,6 +202,8 @@ export class IUpdateDataRequest {
|
||||
embed: EmbedObject;
|
||||
@ApiPropertyOptional({ enum: DataAssetShareType })
|
||||
share_type?: DataAssetShareType;
|
||||
@ApiPropertyOptional()
|
||||
docs?: string;
|
||||
}
|
||||
export class ICreateDataAsset implements CreateDataAssetRequest {
|
||||
@ApiProperty()
|
||||
@@ -214,6 +218,8 @@ export class ICreateDataAsset implements CreateDataAssetRequest {
|
||||
location: string;
|
||||
@ApiPropertyOptional()
|
||||
embed: EmbedObject;
|
||||
@ApiPropertyOptional()
|
||||
docs: string;
|
||||
}
|
||||
|
||||
export class IPreview {
|
||||
|
||||
@@ -136,4 +136,32 @@ export class CustomersController {
|
||||
const result = await this.customersService.getAccessDashboardUrl(user.customer_name, metadata);
|
||||
return result;
|
||||
}
|
||||
|
||||
@Get(':id/organization-info')
|
||||
@Authenticated()
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.USERS.permissions.ADMIN)
|
||||
@ApiOkResponse({ description: 'Organization information' })
|
||||
async getOrganizationInfo(@Param('id') id: string) {
|
||||
this.logger.info('getOrganizationInfo', { id });
|
||||
return this.customersService.getOrganizationInfo(id);
|
||||
}
|
||||
|
||||
@Put(':id/organization-info')
|
||||
@Authenticated()
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.USERS.permissions.ADMIN)
|
||||
@HttpCode(HttpStatus.OK)
|
||||
@ApiOkResponse({ description: 'Organization information updated' })
|
||||
async updateOrganizationInfo(
|
||||
@Param('id') id: string,
|
||||
@Body() body: {
|
||||
companyName: string;
|
||||
companySite: string;
|
||||
domain: string;
|
||||
cnpj: string;
|
||||
description: string;
|
||||
},
|
||||
) {
|
||||
return this.customersService.updateOrganizationInfo(id, body);
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -223,4 +223,57 @@ export class CustomersService implements OnModuleInit {
|
||||
})
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
async updateOrganizationInfo(
|
||||
customerId: string,
|
||||
data: {
|
||||
companyName: string;
|
||||
companySite: string;
|
||||
domain: string;
|
||||
cnpj: string;
|
||||
description: string;
|
||||
},
|
||||
) {
|
||||
try {
|
||||
const result = await lastValueFrom(
|
||||
this.customerService.OrganizationUpdate({
|
||||
customerId,
|
||||
companyName: data.companyName || '',
|
||||
companySite: data.companySite || '',
|
||||
domain: data.domain || '',
|
||||
cnpj: data.cnpj || '',
|
||||
description: data.description || '',
|
||||
}),
|
||||
);
|
||||
|
||||
return result;
|
||||
} catch (err) {
|
||||
if (err.details === ErrorCodes.CUSTOMER.NOT_FOUND)
|
||||
throw new HttpException(err.details, HttpStatus.NOT_FOUND);
|
||||
else throw err;
|
||||
}
|
||||
}
|
||||
|
||||
async getOrganizationInfo(customerId: string) {
|
||||
try {
|
||||
const customerResponse = await lastValueFrom(
|
||||
this.customerService.CustomerFindOneById({ id: customerId })
|
||||
);
|
||||
|
||||
const customer = customerResponse.customer;
|
||||
|
||||
return {
|
||||
companyName: customer.companyName || '',
|
||||
companySite: customer.companySite || '',
|
||||
domain: customer.domain || '',
|
||||
cnpj: customer.cnpj || '',
|
||||
description: customer.description || ''
|
||||
};
|
||||
} catch (err) {
|
||||
if (err.details === ErrorCodes.CUSTOMER.NOT_FOUND)
|
||||
throw new HttpException(err.details, HttpStatus.NOT_FOUND);
|
||||
else throw err;
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
import { ApiProperty, ApiPropertyOptional } from '@nestjs/swagger';
|
||||
|
||||
export class OrganizationUpdateRequest {
|
||||
@ApiProperty()
|
||||
name: string;
|
||||
@ApiPropertyOptional()
|
||||
companySite: string;
|
||||
@ApiProperty()
|
||||
domain: string;
|
||||
@ApiPropertyOptional()
|
||||
info: string;
|
||||
@ApiPropertyOptional()
|
||||
cnpj: string;
|
||||
}
|
||||
|
||||
export class OrganizationResponse {
|
||||
@ApiProperty()
|
||||
name: string;
|
||||
@ApiPropertyOptional()
|
||||
companySite: string;
|
||||
@ApiProperty()
|
||||
domain: string;
|
||||
@ApiPropertyOptional()
|
||||
info: string;
|
||||
@ApiPropertyOptional()
|
||||
cnpj: string;
|
||||
}
|
||||
@@ -26,6 +26,14 @@ import { DynamoDBService, ReferenceColumn } from '../../services/dynamodb';
|
||||
import { CustomersService } from '../customers/customers.service';
|
||||
import { validateCronAgainstScheduleLimit } from '../../utils/cron-validation';
|
||||
|
||||
|
||||
type ValidateTablesDTO = {
|
||||
tables: Array<{
|
||||
table_schema: string,
|
||||
table_name: string
|
||||
}>
|
||||
}
|
||||
|
||||
@ApiTags('Platform API')
|
||||
@Controller('platform')
|
||||
export class PlatformApiController {
|
||||
@@ -630,21 +638,39 @@ export class PlatformApiController {
|
||||
@ApiOperation({ summary: 'Execute a pipeline' })
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||
async executePipeline(@Body() body: any, @User() user: RequestUser) {
|
||||
return this.platformApiService.proxy('POST', '/pipeline/execute', user, body);
|
||||
// Inject customer_id (actually customer_name) into body for Platform-API
|
||||
// Note: Platform-API was created before customer_id existed, so it expects customer_name in the customer_id field
|
||||
const enrichedBody = {
|
||||
...body,
|
||||
customer_id: user.customer_name,
|
||||
};
|
||||
return this.platformApiService.proxy('POST', '/pipeline/execute', user, enrichedBody);
|
||||
}
|
||||
|
||||
@Post('pipeline/pause')
|
||||
@ApiOperation({ summary: 'Pause a pipeline' })
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||
async pausePipeline(@Body() body: any, @User() user: RequestUser) {
|
||||
return this.platformApiService.proxy('POST', '/pipeline/pause', user, body);
|
||||
// Inject customer_id (actually customer_name) into body for Platform-API
|
||||
// Note: Platform-API was created before customer_id existed, so it expects customer_name in the customer_id field
|
||||
const enrichedBody = {
|
||||
...body,
|
||||
customer_id: user.customer_name,
|
||||
};
|
||||
return this.platformApiService.proxy('POST', '/pipeline/pause', user, enrichedBody);
|
||||
}
|
||||
|
||||
@Post('pipeline/unpause')
|
||||
@ApiOperation({ summary: 'Unpause a pipeline' })
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||
async unpausePipeline(@Body() body: any, @User() user: RequestUser) {
|
||||
return this.platformApiService.proxy('POST', '/pipeline/unpause', user, body);
|
||||
// Inject customer_id (actually customer_name) into body for Platform-API
|
||||
// Note: Platform-API was created before customer_id existed, so it expects customer_name in the customer_id field
|
||||
const enrichedBody = {
|
||||
...body,
|
||||
customer_id: user.customer_name,
|
||||
};
|
||||
return this.platformApiService.proxy('POST', '/pipeline/unpause', user, enrichedBody);
|
||||
}
|
||||
|
||||
@Put('pipeline/:pipelineId/memory')
|
||||
@@ -702,6 +728,57 @@ export class PlatformApiController {
|
||||
);
|
||||
}
|
||||
|
||||
// ==================== Catalog ROUTES ====================
|
||||
|
||||
@Get('pipelines/catalog/tables')
|
||||
@ApiOperation({ summary: 'Get all tables available' })
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.GET)
|
||||
async getAvailableTables(
|
||||
@User() user: RequestUser,
|
||||
@Query() query: Record<string, string>,
|
||||
) {
|
||||
return this.platformApiService.proxy(
|
||||
'GET',
|
||||
'/catalog/tables',
|
||||
user,
|
||||
undefined,
|
||||
query,
|
||||
);
|
||||
}
|
||||
|
||||
@Get('pipelines/catalog/schemas')
|
||||
@ApiOperation({ summary: 'Get all schemas available' })
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.GET)
|
||||
async getAvailableSchemas(
|
||||
@User() user: RequestUser,
|
||||
@Query() query: Record<string, string>,
|
||||
) {
|
||||
return this.platformApiService.proxy(
|
||||
'GET',
|
||||
'/catalog/schemas',
|
||||
user,
|
||||
undefined,
|
||||
query,
|
||||
);
|
||||
}
|
||||
|
||||
@Post('pipelines/catalog/tables/validate')
|
||||
@ApiOperation({ summary: 'Validate tables and schemas' })
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||
async validateTableAndSchema(
|
||||
@User() user: RequestUser,
|
||||
@Query() query: Record<string, string>,
|
||||
@Body() validateTablesDto: ValidateTablesDTO[]
|
||||
) {
|
||||
return this.platformApiService.proxy(
|
||||
'POST',
|
||||
'/catalog/tables/validate',
|
||||
user,
|
||||
validateTablesDto,
|
||||
query,
|
||||
);
|
||||
}
|
||||
|
||||
// ==================== PIPELINE RUN ROUTES ====================
|
||||
|
||||
@Get('pipeline/:pipelineId/pipeline_run')
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
export const STORAGE_EXPLORER_CONFIG = {
|
||||
getUrl: (customerName: string): string => {
|
||||
const urlTemplate = process.env.STORAGE_EXPLORER_API_URL;
|
||||
if (!urlTemplate) {
|
||||
throw new Error('STORAGE_EXPLORER_API_URL environment variable is not set');
|
||||
}
|
||||
// Replace {customer_id} placeholder with actual customer ID
|
||||
// For local: http://172.17.0.1:8000/api (no placeholder)
|
||||
// For prod: https://storage-explorer-{customer_id}.dadosfera.ai/api
|
||||
return urlTemplate.replace('{customer}', customerName);
|
||||
},
|
||||
timeout: parseInt(process.env.STORAGE_EXPLORER_TIMEOUT || '30000', 10),
|
||||
};
|
||||
@@ -0,0 +1,383 @@
|
||||
import {
|
||||
Controller,
|
||||
Get,
|
||||
Post,
|
||||
Put,
|
||||
Param,
|
||||
Body,
|
||||
Query,
|
||||
Inject,
|
||||
UseInterceptors,
|
||||
UploadedFiles,
|
||||
Headers,
|
||||
} from '@nestjs/common';
|
||||
import { ApiTags, ApiOperation, ApiConsumes } from '@nestjs/swagger';
|
||||
import { FilesInterceptor } from '@nestjs/platform-express';
|
||||
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
|
||||
import FormData from 'form-data';
|
||||
|
||||
import {
|
||||
Authenticated,
|
||||
RequireAllPermissions,
|
||||
} from '../../decorators/authentication.decorator';
|
||||
import { User, RequestUser } from '../../decorators/user.decorator';
|
||||
import { StorageExplorerService } from './storage-explorer.service';
|
||||
import { PERMISSIONS_GROUPS } from '../../authentication/permissions.enum';
|
||||
|
||||
@ApiTags('Storage Explorer')
|
||||
@Controller('storage-explorer')
|
||||
@Authenticated()
|
||||
export class StorageExplorerController {
|
||||
private logger: any;
|
||||
|
||||
constructor(
|
||||
private readonly storageExplorerService: StorageExplorerService,
|
||||
@Inject(DadosferaLogger) dadosferaLogger: DadosferaLogger,
|
||||
) {
|
||||
this.logger = dadosferaLogger.logger;
|
||||
}
|
||||
|
||||
// ============================================
|
||||
// TABLE OPERATIONS
|
||||
// ============================================
|
||||
|
||||
@ApiOperation({ summary: 'Validate table name in PostgreSQL and Snowflake' })
|
||||
@Post('tables/validate-name')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.WRITE)
|
||||
async validateTableName(
|
||||
@Body() body: any,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'POST',
|
||||
'/tables/validate-name',
|
||||
user,
|
||||
|
||||
body,
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Create a new table' })
|
||||
@Post('tables')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.WRITE)
|
||||
async createTable(
|
||||
@Body() body: any,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'POST',
|
||||
'/tables/',
|
||||
user,
|
||||
|
||||
body,
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'List all tables with pagination' })
|
||||
@Get('tables')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async listTables(
|
||||
@Query('page') page: number,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
'/tables/',
|
||||
user,
|
||||
|
||||
undefined,
|
||||
{ page },
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Get table details by ID' })
|
||||
@Get('tables/:tableId')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async getTable(
|
||||
@Param('tableId') tableId: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
`/tables/${tableId}`,
|
||||
user,
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Link a dataset to a table' })
|
||||
@Post('tables/:tableId/datasets/:datasetId')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.WRITE)
|
||||
async linkDatasetToTable(
|
||||
@Param('tableId') tableId: string,
|
||||
@Param('datasetId') datasetId: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'POST',
|
||||
`/tables/${tableId}/datasets/${datasetId}`,
|
||||
user,
|
||||
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Get all datasets linked to a table' })
|
||||
@Get('tables/:tableId/datasets')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async getTableDatasets(
|
||||
@Param('tableId') tableId: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
`/tables/${tableId}/datasets`,
|
||||
user,
|
||||
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Get table schema' })
|
||||
@Get('tables/:tableId/schema')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async getTableSchema(
|
||||
@Param('tableId') tableId: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
`/tables/${tableId}/schema`,
|
||||
user,
|
||||
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Validate schema compatibility between table and dataset' })
|
||||
@Post('tables/:tableId/validate-compatibility/:datasetId')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async validateSchemaCompatibility(
|
||||
@Param('tableId') tableId: string,
|
||||
@Param('datasetId') datasetId: string,
|
||||
@User() user: RequestUser,
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'POST',
|
||||
`/tables/${tableId}/validate-compatibility/${datasetId}`,
|
||||
user,
|
||||
|
||||
);
|
||||
}
|
||||
|
||||
// ============================================
|
||||
// DATASET OPERATIONS
|
||||
// ============================================
|
||||
|
||||
@ApiOperation({ summary: 'Get dataset preview data' })
|
||||
@Get('datasets/:datasetId/preview')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async getDatasetPreview(
|
||||
@Param('datasetId') datasetId: string,
|
||||
@Query('limit') limit: number,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
`/datasets/${datasetId}/preview`,
|
||||
user,
|
||||
|
||||
undefined,
|
||||
{ limit },
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Get dataset schema information' })
|
||||
@Get('datasets/:datasetId/schema')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async getDatasetSchema(
|
||||
@Param('datasetId') datasetId: string,
|
||||
@Query('force_refresh') forceRefresh: boolean,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
`/datasets/${datasetId}/schema`,
|
||||
user,
|
||||
|
||||
undefined,
|
||||
{ force_refresh: forceRefresh },
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'List all datasets for a specific upload' })
|
||||
@Get('datasets/upload/:uploadId')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async listDatasetsByUpload(
|
||||
@Param('uploadId') uploadId: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
`/datasets/upload/${uploadId}`,
|
||||
user,
|
||||
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Refresh dataset schema with new parsing options (Excel)' })
|
||||
@Put('datasets/:datasetId/refresh-schema')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.WRITE)
|
||||
async refreshDatasetSchema(
|
||||
@Param('datasetId') datasetId: string,
|
||||
@Body() body: any,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'PUT',
|
||||
`/datasets/${datasetId}/refresh-schema`,
|
||||
user,
|
||||
|
||||
body,
|
||||
);
|
||||
}
|
||||
|
||||
// ============================================
|
||||
// STORAGE OPERATIONS
|
||||
// ============================================
|
||||
|
||||
@ApiOperation({ summary: 'List file explorer uploads with pagination' })
|
||||
@Get('storage/uploads/history')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async listFileExplorerUploads(
|
||||
@Query('page') page: number,
|
||||
@Query('limit') limit: number,
|
||||
@Query('folder_path') folderPath: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
'/storage/uploads/history',
|
||||
user,
|
||||
|
||||
undefined,
|
||||
{ page, limit, folder_path: folderPath },
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Browse folders and files in storage' })
|
||||
@Get('storage/browse')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async browseStorage(
|
||||
@Query('path') path: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
'/storage/browse',
|
||||
user,
|
||||
|
||||
undefined,
|
||||
{ path },
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Upload multiple files to storage' })
|
||||
@Post('storage/upload/batch')
|
||||
@ApiConsumes('multipart/form-data')
|
||||
@UseInterceptors(FilesInterceptor('files'))
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.WRITE)
|
||||
async batchUpload(
|
||||
@UploadedFiles() files: Array<Express.Multer.File>,
|
||||
@Body('folder_path') folderPath: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
// Create FormData to forward files to storage-explorer API
|
||||
const formData = new FormData();
|
||||
|
||||
// Add files
|
||||
if (files && files.length > 0) {
|
||||
files.forEach((file) => {
|
||||
formData.append('files', file.buffer, {
|
||||
filename: file.originalname,
|
||||
contentType: file.mimetype,
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
// Add folder_path
|
||||
if (folderPath) {
|
||||
formData.append('folder_path', folderPath);
|
||||
}
|
||||
|
||||
return this.storageExplorerService.proxyFormData(
|
||||
'POST',
|
||||
'/storage/upload/batch',
|
||||
user,
|
||||
|
||||
formData,
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Create a new folder in storage' })
|
||||
@Post('storage/folder/create')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.WRITE)
|
||||
async createFolder(
|
||||
@Body() body: any,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'POST',
|
||||
'/storage/folder/create',
|
||||
user,
|
||||
|
||||
body,
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Download a file from storage' })
|
||||
@Get('storage/download')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async downloadFile(
|
||||
@Query('file_path') filePath: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
'/storage/download',
|
||||
user,
|
||||
|
||||
undefined,
|
||||
{ file_path: filePath },
|
||||
);
|
||||
}
|
||||
|
||||
@ApiOperation({ summary: 'Get detailed file metadata' })
|
||||
@Get('storage/metadata')
|
||||
@RequireAllPermissions(PERMISSIONS_GROUPS.STORAGE_EXPLORER.permissions.READ)
|
||||
async getFileMetadata(
|
||||
@Query('file_path') filePath: string,
|
||||
@User() user: RequestUser,
|
||||
|
||||
) {
|
||||
return this.storageExplorerService.proxy(
|
||||
'GET',
|
||||
'/storage/metadata',
|
||||
user,
|
||||
undefined,
|
||||
{ file_path: filePath },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
|
||||
|
||||
import { StorageExplorerController } from './storage-explorer.controller';
|
||||
import { StorageExplorerService } from './storage-explorer.service';
|
||||
|
||||
@Module({
|
||||
imports: [],
|
||||
controllers: [StorageExplorerController],
|
||||
providers: [StorageExplorerService, DadosferaLogger],
|
||||
exports: [StorageExplorerService],
|
||||
})
|
||||
export class StorageExplorerModule {}
|
||||
@@ -0,0 +1,178 @@
|
||||
import { Injectable, Inject, HttpException } from '@nestjs/common';
|
||||
import axios, { AxiosResponse, Method } from 'axios';
|
||||
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
|
||||
|
||||
import { RequestUser } from '../../decorators/user.decorator';
|
||||
import { STORAGE_EXPLORER_CONFIG } from './storage-explorer.config';
|
||||
|
||||
@Injectable()
|
||||
export class StorageExplorerService {
|
||||
private logger: any;
|
||||
|
||||
constructor(
|
||||
@Inject(DadosferaLogger) dadosferaLogger: DadosferaLogger,
|
||||
) {
|
||||
this.logger = dadosferaLogger.logger;
|
||||
}
|
||||
|
||||
async proxy(
|
||||
method: string,
|
||||
path: string,
|
||||
user: RequestUser,
|
||||
body?: any,
|
||||
query?: Record<string, any>
|
||||
): Promise<any> {
|
||||
// Validate customer_id is present for multi-tenant isolation
|
||||
if (!user.customer_id) {
|
||||
throw new HttpException('Customer ID is required for storage operations', 400);
|
||||
}
|
||||
|
||||
// Get customer-specific storage-explorer URL
|
||||
const baseUrl = STORAGE_EXPLORER_CONFIG.getUrl(user.customer_name);
|
||||
const url = new URL(`${baseUrl}${path}`);
|
||||
|
||||
// Add query params
|
||||
if (query) {
|
||||
Object.entries(query).forEach(([key, value]) => {
|
||||
if (value !== undefined && value !== null) {
|
||||
url.searchParams.set(key, String(value));
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
const headers: Record<string, string> = {
|
||||
'content-type': 'application/json',
|
||||
};
|
||||
|
||||
this.logger.info('Proxying request to storage-explorer', {
|
||||
method: method.toUpperCase(),
|
||||
path,
|
||||
customer_id: user.customer_id,
|
||||
storage_url: baseUrl,
|
||||
user_id: user.user_id,
|
||||
});
|
||||
|
||||
try {
|
||||
const response: AxiosResponse = await axios({
|
||||
method: method as Method,
|
||||
url: url.href,
|
||||
headers,
|
||||
data: body,
|
||||
timeout: STORAGE_EXPLORER_CONFIG.timeout,
|
||||
validateStatus: () => true, // Don't throw on non-2xx
|
||||
});
|
||||
|
||||
// Propagate non-2xx responses as HttpExceptions
|
||||
if (response.status >= 400) {
|
||||
throw new HttpException(response.data, response.status);
|
||||
}
|
||||
|
||||
return response.data;
|
||||
} catch (error) {
|
||||
this.logger.error('Storage Explorer API proxy error', {
|
||||
error: error.message,
|
||||
status: error.response?.status,
|
||||
path,
|
||||
storage_url: baseUrl,
|
||||
method: method.toUpperCase(),
|
||||
});
|
||||
|
||||
if (error instanceof HttpException) {
|
||||
throw error;
|
||||
}
|
||||
|
||||
if (error.response) {
|
||||
throw new HttpException(error.response.data, error.response.status);
|
||||
}
|
||||
|
||||
if (error.code === 'ECONNREFUSED') {
|
||||
throw new HttpException('Storage Explorer API service unavailable', 503);
|
||||
}
|
||||
|
||||
if (error.code === 'ETIMEDOUT' || error.code === 'ECONNABORTED') {
|
||||
throw new HttpException('Storage Explorer API request timeout', 504);
|
||||
}
|
||||
|
||||
throw new HttpException('Internal server error', 500);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Proxy with file upload support (multipart/form-data)
|
||||
*/
|
||||
async proxyFormData(
|
||||
method: string,
|
||||
path: string,
|
||||
user: RequestUser,
|
||||
formData: any,
|
||||
query?: Record<string, any>,
|
||||
): Promise<any> {
|
||||
// Validate customer_id is present for multi-tenant isolation
|
||||
if (!user.customer_id) {
|
||||
throw new HttpException('Customer ID is required for storage operations', 400);
|
||||
}
|
||||
|
||||
// Get customer-specific storage-explorer URL
|
||||
const baseUrl = STORAGE_EXPLORER_CONFIG.getUrl(user.customer_name);
|
||||
const url = new URL(`${baseUrl}${path}`);
|
||||
|
||||
// Add query params
|
||||
if (query) {
|
||||
Object.entries(query).forEach(([key, value]) => {
|
||||
if (value !== undefined && value !== null) {
|
||||
url.searchParams.set(key, String(value));
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
const headers: Record<string, string> = {
|
||||
// Let axios set Content-Type for multipart/form-data with boundary
|
||||
...formData.getHeaders?.(),
|
||||
};
|
||||
|
||||
this.logger.info('Proxying form data request to storage-explorer', {
|
||||
method: method.toUpperCase(),
|
||||
path,
|
||||
customer_id: user.customer_id,
|
||||
storage_url: baseUrl,
|
||||
user_id: user.user_id,
|
||||
});
|
||||
|
||||
try {
|
||||
const response: AxiosResponse = await axios({
|
||||
method: method as Method,
|
||||
url: url.href,
|
||||
headers,
|
||||
data: formData,
|
||||
timeout: STORAGE_EXPLORER_CONFIG.timeout,
|
||||
maxContentLength: Infinity,
|
||||
maxBodyLength: Infinity,
|
||||
validateStatus: () => true,
|
||||
});
|
||||
|
||||
if (response.status >= 400) {
|
||||
throw new HttpException(response.data, response.status);
|
||||
}
|
||||
|
||||
return response.data;
|
||||
} catch (error) {
|
||||
this.logger.error('Storage Explorer API form data proxy error', {
|
||||
error: error.message,
|
||||
status: error.response?.status,
|
||||
path,
|
||||
storage_url: baseUrl,
|
||||
method: method.toUpperCase(),
|
||||
});
|
||||
|
||||
if (error instanceof HttpException) {
|
||||
throw error;
|
||||
}
|
||||
|
||||
if (error.response) {
|
||||
throw new HttpException(error.response.data, error.response.status);
|
||||
}
|
||||
|
||||
throw new HttpException('Internal server error', 500);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -43,7 +43,7 @@ export class User {
|
||||
@ApiProperty()
|
||||
companyName?: string;
|
||||
@ApiProperty()
|
||||
companySite?: string;
|
||||
personalSite?: string;
|
||||
@ApiPropertyOptional()
|
||||
customer?: Customer;
|
||||
@ApiProperty()
|
||||
@@ -64,6 +64,8 @@ export class UserNoRolesAndCustomer extends OmitType(UserNoRoles, [
|
||||
export class IUserByCustomer extends OmitType(User, ['customer']) {
|
||||
@ApiPropertyOptional()
|
||||
permissions?: string[];
|
||||
@ApiPropertyOptional()
|
||||
authProvider?: string;
|
||||
}
|
||||
|
||||
export class CreateUserReq {
|
||||
@@ -117,7 +119,7 @@ export class UpdateUserReq {
|
||||
@ApiPropertyOptional()
|
||||
bio?: string;
|
||||
@ApiPropertyOptional()
|
||||
companySite?: string;
|
||||
personalSite?: string;
|
||||
@ApiPropertyOptional()
|
||||
companyName?: string;
|
||||
@ApiPropertyOptional()
|
||||
|
||||
@@ -274,9 +274,17 @@ export class UsersController {
|
||||
@Language() language: LanguageEnum,
|
||||
) {
|
||||
|
||||
if (user.user_id !== id || !user.permissions.includes(PERMISSIONS_GROUPS.USERS.permissions.ADMIN.seqid)) {
|
||||
const isSameUser = user.user_id === id;
|
||||
const isSuperAdmin = user.permissions.includes(PERMISSIONS_GROUPS.USERS.permissions.ADMIN.seqid)
|
||||
if (!isSameUser && !isSuperAdmin) {
|
||||
throw new ErrorBuilder(ErrorCodes.AUTH.FORBIDDEN);
|
||||
}
|
||||
|
||||
if (isSameUser && !isSuperAdmin && body.roleNames) {
|
||||
// Prevent users from updating their own roles
|
||||
delete body.roleNames;
|
||||
}
|
||||
|
||||
this.logger.info('updateUser', { user });
|
||||
this.userService.setLanguage(language);
|
||||
return await this.userService.updateUser(body, id, user.customer_id);
|
||||
|
||||
@@ -125,6 +125,7 @@ export class UsersService implements OnModuleInit {
|
||||
return { permissions };
|
||||
});
|
||||
res.user.permissions = permissions;
|
||||
res.user.authProvider = process.env.AUTH_PROVIDER || 'cognito';
|
||||
return res;
|
||||
}
|
||||
|
||||
@@ -162,7 +163,7 @@ export class UsersService implements OnModuleInit {
|
||||
name: updateUserDTO.name,
|
||||
bio: updateUserDTO.bio,
|
||||
companyName: updateUserDTO.companyName,
|
||||
companySite: updateUserDTO.companySite,
|
||||
personalSite: updateUserDTO.personalSite,
|
||||
customerId,
|
||||
id,
|
||||
metabaseUserId: undefined,
|
||||
|
||||
@@ -14,7 +14,10 @@ export class ValidationPipe implements PipeTransform<any> {
|
||||
return value;
|
||||
}
|
||||
const object = plainToInstance(metatype, value);
|
||||
const errors = await validate(object);
|
||||
const errors = await validate(object, {
|
||||
forbidUnknownValues: false,
|
||||
whitelist: true,
|
||||
});
|
||||
if (errors.length > 0) {
|
||||
const errorMessages = errors.map((err) => err.constraints);
|
||||
throw new BadRequestException(errorMessages);
|
||||
|
||||
Reference in New Issue
Block a user