Compare commits

...
157 Commits
Author SHA1 Message Date
Rafael Santana 873f7ea314 Merge pull request #225 from dadosfera/helm-chart
UPDATE: create helm chart for maestro
2024-12-18 16:07:39 -03:00
Rafael ad03d663bb CI: updating CI to use beta branch 2024-12-09 14:00:56 -03:00
Rafael c10f85950a UPDATE: Commented out the aws beanstalk deployment 2024-10-12 13:28:06 -03:00
Rafael 7d69220461 UPDATE: create helm chart for maestro 2024-10-12 13:19:57 -03:00
Gabriel Amorim e316bd1a7b Merge pull request #224 from dadosfera/feat/dev-docker
FEAT: dev docker
2024-08-16 20:31:13 -03:00
Gabriel Rosa fd47a746af FIX: microservices urls 2024-08-16 22:19:11 +00:00
Gabriel Rosa 5038c7845f FEAT: dev docker 2024-08-16 21:59:23 +00:00
Gabriel Amorim 9876eab521 Merge pull request #223 from dadosfera/feat/rls
Feat/rls
2024-08-16 17:16:18 -03:00
Gabriel Rosa 99a52c3ff2 FEAT: new protospack version 2024-08-16 17:05:38 -03:00
Gabriel Rosa 0119cee3c6 FIX: removed unused imports 2024-08-14 11:29:14 -03:00
Gabriel Rosa c7e850cc79 FEAT: rls rules routes 2024-08-14 11:13:19 -03:00
Gabriel Rosa 5da47e5438 FEAT: create RLS on pi-factory 2024-08-07 18:16:20 -03:00
Gabriel Rosa b0f9f5c77e [skip ci] DOC: improving documentation in portuguese 2024-08-05 17:57:06 -03:00
Gabriel Amorim 35f35ddeb3 Merge pull request #222 from dadosfera/SOLENG-4628-feat/restrict-asset-options
[SOLENG-4628] feat/restrict asset options
2024-07-10 12:03:32 -03:00
Gabriel Rosa 90155a8811 FIX: cahnged self-hosted actions runner to run test 2024-07-10 10:43:40 -03:00
Gabriel Rosa ae8baca694 Merge branch 'main' into SOLENG-4628-feat/restrict-asset-options 2024-07-08 09:39:53 -03:00
Gabriel Amorim 82b8751f65 Merge pull request #221 from dadosfera/fix/docker-compose
FIX: use docker compose instead of docker-compose
2024-06-28 16:58:18 -03:00
Gabriel Rosa 78ee64fc45 FIX: login aws on test 2024-06-28 16:55:31 -03:00
Gabriel Rosa 2f30837fed FIX: use docker compose instead of docker-compose 2024-06-28 16:47:45 -03:00
Gabriel Amorim f46b1b62db Merge pull request #220 from dadosfera/feat/new-customer-monitoring
FEAT: new customer monitoring dashboard
2024-06-28 16:37:38 -03:00
Gabriel Rosa 8b6cd8a88e FEAT: customer monitoring dashboard 2024-06-21 09:21:27 -03:00
Gabriel Rosa 0c333b476a FEAT: new customer monitoring 2024-06-20 10:50:07 -03:00
Gabriel Rosa 1aa9371245 FIX: Preserve slash escape 2024-05-08 18:09:56 -03:00
Gabriel Rosa 14fcf4a0a1 CI: format the node_exporter url with format() 2024-05-08 18:01:44 -03:00
Gabriel Rosa 24f824bcd1 FIX: update protospack version 2024-05-08 17:17:55 -03:00
Gabriel Rosa fcdd0bf571 Merge branch 'main' into SOLENG-4628-feat/restrict-asset-options 2024-05-08 15:37:45 -03:00
Gabriel Amorim c416a2cb97 Merge pull request #219 from dadosfera/feat/pipeline-monitoring-dashboard
Feat: pipeline monitoring dashboard
2024-05-06 16:52:26 -03:00
Gabriel Rosa d03021fc9d new protospack release 2024-05-06 15:28:26 -03:00
Gabriel Rosa 574cf48726 FIX: npm audit fix 2024-05-02 12:11:46 -03:00
Gabriel Rosa 7cef404acf FEAT: get monitoring dashboard url 2024-05-02 12:11:35 -03:00
Gabriel Rosa 3c32c3c7d4 CI: Update actions/checkout to v4 2024-04-22 14:57:01 -03:00
Gabriel Amorim d44531b963 Merge pull request #218 from dadosfera/feat/choose-deploy-dockerhub
[ TECN-6603 ] CI: update action versions and choose wether to upload to dockerhub
2024-01-10 10:05:47 -03:00
Gabriel Rosa 36c80b480e CI: update action versions and choose wether to upload to dockerhub 2024-01-04 14:58:47 -03:00
Rafael Santana eeef97679c Merge pull request #217 from dadosfera/ci/dockerhub
UPDATE: updating maestro to deploy image to dockerhub
2023-11-26 21:18:32 -03:00
Rafael Santana c789dae3f6 UPDATE: updating maestro to deploy image to dockerhub 2023-11-26 20:50:10 -03:00
Gabriel Amorim 4b20388d45 DOCS: update some routes swagger 2023-09-20 09:39:43 -03:00
Gabriel Amorim 33fd2bd35f FIX: update old protospack library 2023-09-20 09:39:27 -03:00
Gabriel Amorim 654c837d3f FEAT: new node version 2023-09-18 11:34:23 -03:00
Gabriel Amorim 416b58080d CI: fixed conventional-changelog-eslint version 2023-09-18 11:33:09 -03:00
Allan Sene 216defb76f Updated file 2023-06-11 22:43:43 -03:00
Gabriel Amorim 0970c748e0 Merge pull request #216 from dadosfera/feat/generate-token
Feat: generate token
2023-05-17 10:03:00 -03:00
Gabriel Amorim aabd741cad FEAT: new Customer Get Token Route 2023-05-16 09:05:05 -03:00
Gabriel Amorim 950c6414b6 FIX: update to new nestjs version 2023-05-12 08:28:33 -03:00
Gabriel Amorim d1149a4d52 Merge pull request #215 from dadosfera/alpha
FIX: permissions.enum.ts
2023-05-08 16:02:33 -03:00
Gabriel Amorim 4c6f4bfd84 FIX: renamed reference to intelligence permission 2023-05-08 15:56:52 -03:00
Gabriel Amorim 9caf3dc67f FIX: renamed reference to intelligence permission 2023-05-08 15:48:46 -03:00
Beatriz Antunes 635c4da48c Update permissions.enum.ts 2023-05-08 15:44:05 -03:00
Gabriel Amorim 44bb205483 Merge pull request #214 from dadosfera/fix/get-links-permission
FIX: remove permission check to get customer links
2023-05-05 13:52:38 -03:00
Gabriel Amorim edb4622684 FIX: remove permission to get customer links 2023-05-05 12:13:55 -03:00
Victor Radael abb46d78da Merge pull request #212 from dadosfera/feature/customer-links
SOLENG-1481 - Customer links endpoints
2023-04-17 17:01:41 -03:00
Victor Radael 04fdc0368a Merge pull request #213 from dadosfera/update/hubspot-tables
UPDATE: HubspotTables
2023-04-15 14:49:47 -03:00
Victor Radael 50d76622c5 UPDATE: HubspotTables 2023-04-15 14:45:18 -03:00
Victor Radael 238f56cb76 Merge branch 'SOLENG-1736' into feature/customer-links 2023-04-14 14:44:57 -03:00
Victor Radael e721d6f5f5 Merge branch 'main' into feature/customer-links 2023-04-14 13:30:57 -03:00
Victor Radael 44df13e820 UPDATE: Att protospack-v2 version 2023-04-14 13:13:47 -03:00
Victor Radael 1fd0f79dd5 Att hubspot connection 2023-04-13 15:41:44 -03:00
Victor Radael 1b92371737 Att hubspot connection 2023-04-13 14:55:33 -03:00
Colombo bf5b3484a1 FEAT: add controller method interfaces 2023-04-11 20:39:47 -03:00
Colombo eb1e248d4b FEAT: add customer (links) endpoint 2023-04-11 17:04:40 -03:00
Colombo 0827414051 FEAT: add new dto property 2023-04-10 19:36:36 -03:00
Colombo 081986607b CHORE: change protospack package to beta 2023-04-06 17:07:23 -03:00
Gabriel Amorim 189080199a Merge pull request #211 from dadosfera/feat/trigger-catalog-task
Feat/trigger catalog task
2023-03-17 12:14:15 -03:00
Gabriel Amorim 55281e3965 FIX: docs 2023-03-16 17:58:11 -03:00
Gabriel Amorim db8a6175e8 new protospack version 2023-03-16 17:45:15 -03:00
Gabriel Amorim 7b0d4dd5bc FIX: set route params type 2023-03-16 17:45:03 -03:00
Gabriel Amorim 6fd277ef3a docs 2023-03-14 16:02:22 -03:00
Gabriel Amorim 7b25bfdb69 FIX: add table_schema to request 2023-03-14 16:00:57 -03:00
Gabriel Amorim 2abc19c589 FEAT: trigger and get dataset cataloging task 2023-03-14 13:39:21 -03:00
Gabriel Amorim faf6b1df75 Merge pull request #210 from dadosfera/fix/delete-connector
Fix/delete connector
2023-03-09 18:14:14 -03:00
Gabriel Amorim 422be4a422 swaggers 2023-03-06 12:11:13 -03:00
Gabriel Amorim da136e0ef0 FIX: better swagger generation strategy (Only PRD server on external docs) 2023-03-06 12:10:12 -03:00
Gabriel Amorim 737cc9b8ea FIX: removed wrong JSON.parse on connector delete response 2023-03-06 12:09:29 -03:00
Gabriel Amorim 23f6b179fd Merge pull request #209 from dadosfera/feat/google-sheets-link
Feat/google sheets link
2023-02-27 16:03:52 -03:00
Gabriel Amorim 03e451c21d Merge branch 'main' into feat/google-sheets-link 2023-02-27 11:26:03 -03:00
Gabriel Amorim be061a0fb9 Merge pull request #208 from dadosfera/fix/upload-files
FIX: create pipeline from any file type on upload
2023-02-24 17:10:08 -03:00
Gabriel Amorim c83f6a68d1 update protospack version 2023-02-24 16:50:29 -03:00
Gabriel Amorim 2646e3e4f6 FEAT: return google sheets entire link 2023-02-24 15:58:06 -03:00
Gabriel Amorim 06424d6bcf FIX: docs 2023-02-24 14:47:49 -03:00
Gabriel Amorim 45b82515fc FIX: do not return config_controls that the pipeline don't have 2023-02-24 14:31:50 -03:00
Gabriel Amorim a9cc951e34 FIX: new error codes 2023-02-23 17:14:47 -03:00
Gabriel Amorim 93ccf506fb FIX: csv import with header=false 2023-02-22 15:13:36 -03:00
Gabriel Amorim 706d0ccfa0 FIX: get right image url 2023-02-22 14:32:41 -03:00
Beatriz Antunes c2eec4e95c Merge pull request #207 from dadosfera/fix/hubspot-chat-permission
FIX: change permission to access support chat
2023-02-22 13:10:54 -03:00
Gabriel Amorim ac3132b6eb FIX: create pipeline from any file type on upload 2023-02-22 10:18:28 -03:00
Gabriel Amorim ee8c5e7a93 Merge pull request #206 from dadosfera/feat/docs-refactor
Feat: docs refactor
2023-02-17 14:36:19 -03:00
Gabriel Rosa a2c1f2da6f FIX: new zendesk permission 2023-02-17 14:33:14 -03:00
Gabriel Rosa 7ecb50315f Update action 2023-02-17 11:01:29 -03:00
Gabriel Rosa 84b3370826 Update action 2023-02-17 11:01:08 -03:00
Gabriel Rosa aa9e0536a7 FIX: tests 2023-02-17 09:55:10 -03:00
Gabriel Rosa 544d13fac5 FIX: readme improved 2023-02-16 17:01:49 -03:00
Gabriel Rosa a4ff07a285 FIX: removed connection test from external docs 2023-02-16 12:07:47 -03:00
Gabriel Rosa 28578d3aa8 FIX: better query params on catalog get all 2023-02-15 16:46:32 -03:00
Gabriel Rosa b8ea729a33 FIX: add external docs to docsfera 2023-02-15 14:16:28 -03:00
Gabriel Rosa b383070b68 Internal docs 2023-02-15 14:07:26 -03:00
Gabriel Rosa 87882b5afc FIX: add multiple servers 2023-02-15 13:14:53 -03:00
Gabriel Rosa 6a14c2b459 FIX: hide internal endpoints 2023-02-15 13:13:43 -03:00
Gabriel Rosa f0bfb6ba8e FIX: new semantic release 2023-02-14 16:57:45 -03:00
Gabriel Rosa 99288fa805 FIX: new sematic release version 2023-02-14 16:55:39 -03:00
Gabriel Rosa 35cc0094b3 FIX: new sematic release 2023-02-14 16:51:53 -03:00
Gabriel Rosa 98262bcba9 FIX: Run semantic release on manual deploy 2023-02-14 16:48:46 -03:00
Gabriel Rosa a2c9a462e4 Run semantic release on manual deploy 2023-02-14 16:46:54 -03:00
Gabriel Rosa c5c089e5d5 Better error handling and documentation on refresh token 2023-02-14 09:25:14 -03:00
Gabriel Rosa de06512249 FIX: changed language strategy to use new custom decorator 2023-02-14 08:56:23 -03:00
Gabriel Rosa 9058b80383 Merge branch 'main' into feat/docs-refactor 2023-02-13 12:16:12 -03:00
Gabriel Rosa be64c582e1 Inject permissions more safe 2023-02-13 12:03:28 -03:00
Gabriel Rosa d6b3e02890 FIX: automattically skip ssl when microservices connection are local 2023-02-13 10:30:50 -03:00
Gabriel Amorim d06910515b FIX: force deploy 2023-02-10 15:53:10 -03:00
Gabriel Amorim d1b328d481 Merge pull request #204 from dadosfera/feat/oauth-login
Feat/oauth login
2023-02-10 14:58:20 -03:00
Gabriel Rosa fbc0d2eede FIX: moved decorators to a separate folder 2023-02-10 14:23:27 -03:00
Gabriel Rosa 945955a71c Merge branch 'main' into feat/oauth-login 2023-02-09 15:21:05 -03:00
Gabriel Rosa 9fcbeda470 FIX: deprecating old pipeline routes 2023-02-08 18:07:06 -03:00
Gabriel Rosa 8043635b1c FIX: add authentication to swagger 2023-02-08 15:23:49 -03:00
Gabriel Amorim cdba41dffa Merge pull request #203 from dadosfera/force-deploy
FIX: force deploy
2023-02-03 17:24:13 -03:00
Gabriel Rosa 5020e8913e FIX: force deploy 2023-02-03 17:21:53 -03:00
Gabriel Amorim 89369270b9 Merge pull request #202 from dadosfera/feat/embed-private
Feat/embed private
2023-02-03 17:14:14 -03:00
Gabriel Rosa 52f17725af new protospack version 2023-02-03 15:03:51 -03:00
Gabriel Rosa 6da213aebc starting module strategy 2023-02-03 11:14:15 -03:00
Gabriel Rosa a353a1b45c FIX: new permission 2023-02-02 14:00:24 -03:00
Gabriel Rosa b36ff624b5 FIX: add logic for fetching shared data_assets 2023-02-01 18:00:36 -03:00
Gabriel Rosa 03c09a525b DOCS: documenting oauth flow 2023-02-01 10:07:45 -03:00
Gabriel Amorim 9ea610a405 Merge pull request #201 from dadosfera/fix/oauth-facebook
FIX: add all scopes to facebook oauth
2023-01-31 16:08:15 -03:00
Gabriel Rosa cd97bcbac0 FIX: add all scopes to facebook oauth 2023-01-31 16:04:57 -03:00
Gabriel Rosa 52bf2bdef3 teste new docsfera cloud function url 2023-01-31 09:34:34 -03:00
Gabriel Rosa 161d1fa05d Added some logs 2023-01-30 16:35:05 -03:00
Gabriel Rosa 642bf462ad FIX: add fallback language to pt-br 2023-01-26 17:00:27 -03:00
Gabriel Rosa 6d61d74d0c FIX: set google callback 2023-01-25 09:51:22 -03:00
Gabriel Rosa 2bc060b13d FEAT: oauth sign in 2023-01-24 19:19:00 -03:00
Anderson Feitosa 28efdf95d9 Merge pull request #200 from dadosfera/feature/upload-to-s3-presigned
feature/upload-to-s3-presigned
2023-01-24 06:39:49 -03:00
Anderson Feitosa 1ef9fd4298 FEAT: update packages 2023-01-23 13:56:51 -03:00
Anderson Feitosa 5c24ec5560 FEAT: fix upload id 2023-01-20 10:05:36 -03:00
Anderson Feitosa 962e094a65 FEAT: add upload init multi part upload 2023-01-19 17:17:33 -03:00
Anderson Feitosa 131b166d8d REFACTOR: get data from body 2023-01-16 10:56:03 -03:00
Anderson Feitosa 5419f3690c FEAT: update endpoint to get signed url to upload csv file 2023-01-16 10:55:27 -03:00
Gabriel Amorim 6f3eb7965b Merge pull request #199 from dadosfera/fix/can-untoggle
FIX: canUntoggle logic
2023-01-12 18:10:23 -03:00
Gabriel Rosa 909f0d4a4e new protospack version 2023-01-12 17:59:02 -03:00
Gabriel Rosa 8c8fdf5f88 FIX: canUntoggle logic 2023-01-12 16:47:43 -03:00
Anderson Feitosa e9582a51c2 Merge pull request #198 from dadosfera/feature/mixpanel-first-name
feature/mixpanel-first-name
2023-01-12 12:28:24 -03:00
Anderson Feitosa 0590c20af8 FEAT: add more prefixed values 2023-01-12 12:03:04 -03:00
Anderson Feitosa 05eefe866b FEAT: add suffix on email 2023-01-12 12:02:16 -03:00
Anderson Feitosa fa023756c7 FEAT: replace dadosfera with empty string 2023-01-12 11:56:47 -03:00
Anderson Feitosa 7f967e5e75 FEAT: update hardcoded separator 2023-01-12 11:52:51 -03:00
Anderson Feitosa 2a0b17e45a FEAT: add more prefixed values 2023-01-12 11:49:32 -03:00
Anderson Feitosa b1f6d765b2 FEAT: add more prefixed values 2023-01-12 11:47:04 -03:00
Anderson Feitosa 3c9ed08515 FEAT: split email into fist name and last name 2023-01-12 11:40:14 -03:00
Gabriel Amorim c7ca8297c9 Merge pull request #197 from dadosfera/fix/reset-password-email
FIX: send language on reset password email
2023-01-10 20:29:58 -03:00
Gabriel Rosa d269e9efe4 FIX: send language on reset password email 2023-01-10 18:50:32 -03:00
Gabriel Amorim 61cc238891 Merge pull request #196 from dadosfera/feat/cognito-mailing
FIX: send language on create users and resend invite
2023-01-10 18:06:06 -03:00
Gabriel Rosa b5df916511 Merge branch 'main' into feat/cognito-mailing 2023-01-10 15:05:18 -03:00
Gabriel Amorim 95da106fb8 Merge pull request #195 from dadosfera/fix/customer-schedule-limit
fix/customer-schedule-limit
2023-01-06 18:29:57 -03:00
Gabriel Rosa 5730402312 update protospack 2023-01-06 18:04:16 -03:00
Gabriel Rosa c2ea8b69da FIX: customer scheduleLimit on login 2023-01-06 15:24:01 -03:00
Gabriel Rosa 14081bb9ca FIX: send language on create users and resend invite 2023-01-06 15:18:49 -03:00
Victor Radael 82d9024f24 Merge pull request #193 from dadosfera/feat/update-connection
Feat/update connection
2022-12-27 17:21:25 -03:00
Gabriel Rosa 53a6d3957a Merge branch 'main' into feat/update-connection 2022-12-27 17:01:32 -03:00
Victor Radael db55a8abde FEAT: Update OAuth Connection 2022-12-26 17:47:30 -03:00
Victor Radael 8f40b159d6 FEAT: MERGE main to deploy 2022-12-26 17:43:31 -03:00
Victor Radael 190a63f0eb FEAT: Update OAuth Connection 2022-12-20 17:01:00 -03:00
104 changed files with 15522 additions and 14965 deletions
+1 -1
View File
@@ -8,7 +8,7 @@ module.exports = {
extends: [
'eslint:recommended',
'plugin:@typescript-eslint/recommended',
'plugin:prettier/recommended',
'prettier',
],
root: true,
env: {
+73
View File
@@ -0,0 +1,73 @@
name: Deploy K8S Modifications
on:
push:
branches:
- main
- beta
jobs:
extract_environment:
runs-on: ubuntu-22.04
outputs:
environment: ${{ steps.extract_environment.outputs.environment }}
steps:
- name: Extract Environment
run: |
if [ ${GITHUB_REF} == "refs/heads/main" ]; then
echo "environment=prd" >> $GITHUB_OUTPUT
elif [ ${GITHUB_REF} == "refs/heads/beta" ]; then
echo "environment=stg" >> $GITHUB_OUTPUT
fi
id: extract_environment
helmfile-deploy:
needs: [extract_environment]
runs-on: [self-hosted, "prd-azure"]
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Set up Helm
uses: azure/setup-helm@v1
with:
version: 'v3.9.0'
- name: Install Azure ClI
run: |
curl -sL https://aka.ms/InstallAzureCLIDeb | bash
- uses: azure/login@v2
with:
creds: '{"clientId":"${{ secrets.ARM_CLIENT_ID }}","clientSecret":"${{ secrets.ARM_CLIENT_SECRET }}","subscriptionId":"${{ secrets.ARM_SUBSCRIPTION_ID }}","tenantId":"${{ secrets.ARM_TENANT_ID }}"}'
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.8'
- name: Install Helmfile
run: |
wget https://github.com/helmfile/helmfile/releases/download/v0.148.0/helmfile_0.148.0_linux_amd64.tar.gz
tar -xzf helmfile_0.148.0_linux_amd64.tar.gz
mv helmfile /usr/local/bin/
helmfile --version
- name: Install Helm Diff Plugin
run: helm plugin install https://github.com/databus23/helm-diff || true
- name: Setup kubectl
uses: azure/setup-kubectl@v1
with:
version: 'v1.30.1'
- name: Authenticate with cluster
env:
CLUSTER_NAME: platform-${{ needs.extract_environment.outputs.environment }}
run: az aks get-credentials --resource-group dadosfera-prd --name ${CLUSTER_NAME} --overwrite-existing
- name: Run Helmfile Apply
env:
ENV: ${{ needs.extract_environment.outputs.environment }}
run: helmfile -f helmfiles/${ENV}.yaml sync
+113 -86
View File
@@ -3,6 +3,7 @@ on:
push:
branches:
- main
- beta
workflow_dispatch:
inputs:
environment:
@@ -11,8 +12,12 @@ on:
type: choice
options:
- stg
- stg2
- prd
push_to_dockerhub:
description: "Push image to Dockerhub?"
required: true
type: boolean
default: false
jobs:
extract_environment:
@@ -29,6 +34,8 @@ jobs:
echo "environment=${DEPLOY_ENV}" >> $GITHUB_OUTPUT
elif [ ${GITHUB_REF} == "refs/heads/main" ]; then
echo "environment=prd" >> $GITHUB_OUTPUT
elif [ ${GITHUB_REF} == "refs/heads/beta" ]; then
echo "environment=stg" >> $GITHUB_OUTPUT
fi
id: extract_environment
@@ -39,54 +46,51 @@ jobs:
new_release_version: ${{ (steps.semantic.outputs.new_release_published == 'true' && steps.semantic.outputs.new_release_version) || (github.event_name == 'workflow_dispatch' && '0.0.0') }}
steps:
- name: Checkout
uses: actions/checkout@v3
uses: actions/checkout@v4
- if: github.event_name != 'workflow_dispatch'
name: Semantic Release
uses: cycjimmy/semantic-release-action@v2
uses: cycjimmy/semantic-release-action@v3
id: semantic
with:
semantic_version: 16
extra_plugins: |
conventional-changelog-eslint
conventional-changelog-eslint@4.0.0
branches: |
[
'main'
'main',
{
name: 'alpha',
prerelease: true
},
{
name: 'beta',
prerelease: true
}
]
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
deploy-info:
if: ${{ github.event_name == 'workflow_dispatch'}}
build_ecr_image:
if: ${{ github.event_name == 'workflow_dispatch' || needs.semantic_release.outputs.new_release_published == 'true' }}
needs: [extract_environment, semantic_release]
runs-on: ubuntu-latest
runs-on:
[self-hosted, "prd"]
steps:
- name: Create summary
- name: Printing stats
env:
EVENT: ${{ github.event_name }}
IMAGE_TAG: ${{ needs.semantic_release.outputs.new_release_version }}
ENV: ${{ needs.extract_environment.outputs.environment }}
run: echo "### Deploy da branch \`$GITHUB_REF_NAME\` no ambiente **$ENV** :rocket:" >> $GITHUB_STEP_SUMMARY
run: echo ${GITHUB_REF#refs/heads/}
deploy:
if: ${{ github.event_name == 'workflow_dispatch' || needs.semantic_release.outputs.new_release_published == 'true' }}
needs: [extract_environment, semantic_release]
runs-on:
[self-hosted, "${{ needs.extract_environment.outputs.environment }}"]
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v4
- name: Update Pip
run: |
python3 -m pip install --upgrade pip
- name: Install Docker Compose
run: |
python3 -m pip install docker-compose --upgrade
- name: Install AWS CLI
run: |
python3 -m pip install awscli --upgrade
@@ -96,14 +100,14 @@ jobs:
python3 -m pip install awsebcli --upgrade
- name: Configure AWS Region
uses: aws-actions/configure-aws-credentials@v1-node16
uses: aws-actions/configure-aws-credentials@v4
id: aws
with:
aws-region: us-east-1
- name: Login to AWS ECR
id: login_ecr
uses: aws-actions/amazon-ecr-login@v1
uses: aws-actions/amazon-ecr-login@v2
- name: Build, Tag, and Push Image to AWS ECR
env:
@@ -111,80 +115,103 @@ jobs:
IMAGE_TAG: ${{ needs.semantic_release.outputs.new_release_version }}
ACCOUNT_ID: ${{ steps.aws.outputs.aws-account-id }}
run: |
docker-compose -f build.docker-compose.yml build
docker-compose -f build.docker-compose.yml push
docker compose -f build.docker-compose.yml build
docker compose -f build.docker-compose.yml push
- name: Create ZIP file to Deploy AWS Beanstalk
- name: Login to Docker Hub
if: ${{inputs.push_to_dockerhub}}
uses: docker/login-action@v2
with:
username: dadosfera
password: ${{ secrets.DOCKERHUB_PASSWORD }}
- name: Build, Tag, and Push Image to Dockerhub
if: ${{inputs.push_to_dockerhub}}
env:
ENV: ${{ needs.extract_environment.outputs.environment }}
IMAGE_TAG: ${{ needs.semantic_release.outputs.new_release_version }}
ACCOUNT_ID: ${{ steps.aws.outputs.aws-account-id }}
NODE_EXPORTER_URL: ${{needs.extract_environment.outputs.environment == 'prd' && '611330257153.dkr.ecr.us-east-1.amazonaws.com\/monitoring\/node_exporter:latest' || '468720548566.dkr.ecr.us-east-1.amazonaws.com\/monitoring\/node_exporter:latest'}}
run: |
sed -i -e "s/\${ENV}/$ENV/g" docker-compose.yml
sed -i -e "s/\${IMAGE_TAG}/$IMAGE_TAG/g" docker-compose.yml
sed -i -e "s/\${ACCOUNT_ID}/$ACCOUNT_ID/g" docker-compose.yml
sed -i -e "s/\${NODE_EXPORTER_URL}/$NODE_EXPORTER_URL/g" docker-compose.yml
zip deploy.zip docker-compose.yml -r .ebextensions
docker compose -f build.docker-compose.dockerhub.yml build
docker compose -f build.docker-compose.dockerhub.yml push
- name: Deploy AWS Beanstalk
env:
ENV: ${{ needs.extract_environment.outputs.environment }}
AWS_REGION: us-east-1
APP_NAME: ${{ github.event.repository.name }}
run: |
eb use $APP_NAME-$ENV
echo -e "deploy:\n artifact: deploy.zip" >> .elasticbeanstalk/config.yml
eb deploy
# - name: Create ZIP file to Deploy AWS Beanstalk
# env:
# ENV: ${{ needs.extract_environment.outputs.environment }}
# IMAGE_TAG: ${{ needs.semantic_release.outputs.new_release_version }}
# ACCOUNT_ID: ${{ steps.aws.outputs.aws-account-id }}
# NODE_EXPORTER_URL: ${{needs.extract_environment.outputs.environment == 'prd' && '611330257153.dkr.ecr.us-east-1.amazonaws.com\/monitoring\/node_exporter:latest' || '468720548566.dkr.ecr.us-east-1.amazonaws.com\/monitoring\/node_exporter:latest'}}
# run: |
# sed -i -e "s/\${ENV}/$ENV/g" docker-compose.yml
# sed -i -e "s/\${IMAGE_TAG}/$IMAGE_TAG/g" docker-compose.yml
# sed -i -e "s/\${ACCOUNT_ID}/$ACCOUNT_ID/g" docker-compose.yml
# sed -i -e "s/\${NODE_EXPORTER_URL}/$NODE_EXPORTER_URL/g" docker-compose.yml
# zip deploy.zip docker-compose.yml -r .ebextensions
# - name: Deploy AWS Beanstalk
# env:
# ENV: ${{ needs.extract_environment.outputs.environment }}
# AWS_REGION: us-east-1
# APP_NAME: ${{ github.event.repository.name }}
# run: |
# eb use $APP_NAME-$ENV
# echo -e "deploy:\n artifact: deploy.zip" >> .elasticbeanstalk/config.yml
# eb deploy
- name: Remove Docker's Trash
if: always()
run: |
docker system prune --volumes -a -f
docker system df
api_docs:
needs: [extract_environment, semantic_release, deploy]
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Extract Docs BlockId and PageId
helmfile-deploy:
needs: [extract_environment, semantic_release, build_ecr_image]
runs-on: [self-hosted, "prd-azure"]
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Set up Helm
uses: azure/setup-helm@v1
with:
version: 'v3.9.0'
- name: Install Azure ClI
run: |
curl -sL https://aka.ms/InstallAzureCLIDeb | bash
- uses: azure/login@v2
with:
creds: '{"clientId":"${{ secrets.ARM_CLIENT_ID }}","clientSecret":"${{ secrets.ARM_CLIENT_SECRET }}","subscriptionId":"${{ secrets.ARM_SUBSCRIPTION_ID }}","tenantId":"${{ secrets.ARM_TENANT_ID }}"}'
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.8'
- name: Install Helmfile
run: |
wget https://github.com/helmfile/helmfile/releases/download/v0.148.0/helmfile_0.148.0_linux_amd64.tar.gz
tar -xzf helmfile_0.148.0_linux_amd64.tar.gz
mv helmfile /usr/local/bin/
helmfile --version
- name: Install Helm Diff Plugin
run: helm plugin install https://github.com/databus23/helm-diff || true
- name: Setup kubectl
uses: azure/setup-kubectl@v1
with:
version: 'v1.30.1'
- name: Authenticate with cluster
env:
CLUSTER_NAME: platform-${{ needs.extract_environment.outputs.environment }}
run: az aks get-credentials --resource-group dadosfera-prd --name ${CLUSTER_NAME} --overwrite-existing
- name: Run Helmfile Apply
env:
ENV: ${{ needs.extract_environment.outputs.environment }}
STG2_DOCS_BLOCK_ID: ${{ secrets.DEV_DOCS_BLOCK_ID }}
STG2_DOCS_PAGE_ID: ${{ secrets.DEV_DOCS_PAGE_ID }}
STG_DOCS_BLOCK_ID: ${{ secrets.STG_DOCS_BLOCK_ID }}
STG_DOCS_PAGE_ID: ${{ secrets.STG_DOCS_PAGE_ID }}
PRD_DOCS_BLOCK_ID: ${{ secrets.PRD_DOCS_BLOCK_ID }}
PRD_DOCS_PAGE_ID: ${{ secrets.PRD_DOCS_PAGE_ID }}
shell: bash
run: |
if [ $ENV == "stg2" ]; then
echo "block_id=$STG2_DOCS_BLOCK_ID" >> $GITHUB_OUTPUT
echo "page_id=$STG2_DOCS_PAGE_ID" >> $GITHUB_OUTPUT
elif [ $ENV == "stg" ]; then
echo "block_id=$STG_DOCS_BLOCK_ID" >> $GITHUB_OUTPUT
echo "page_id=$STG_DOCS_PAGE_ID" >> $GITHUB_OUTPUT
elif [ $ENV == "prd" ]; then
echo "block_id=$PRD_DOCS_BLOCK_ID" >> $GITHUB_OUTPUT
echo "page_id=$PRD_DOCS_PAGE_ID" >> $GITHUB_OUTPUT
fi
id: extract_docs_info
- name: Generate API docs
env:
DOCS_URL: ${{ secrets.DOCS_URL }}
DOCS_API_TOKEN: ${{ secrets.DOCS_API_TOKEN }}
DOCS_PAGE_ID: ${{ steps.extract_docs_info.outputs.page_id }}
DOCS_BLOCK_ID: ${{ steps.extract_docs_info.outputs.block_id }}
EVENT: ${{ github.event_name }}
RELEASE_VERSION: ${{ needs.semantic_release.outputs.new_release_version }}
run: |
if [ ${EVENT} != "workflow_dispatch" ]; then
sed -i -E "s/(\"title\": )\"Maestro.+\"/\1\"Maestro - $RELEASE_VERSION\"/g" docsfera.json
fi
sed -i -e "s/\${DOCS_API_TOKEN}/$DOCS_API_TOKEN/g" docsfera.json
sed -i -e "s/\${DOCS_PAGE_ID}/$DOCS_PAGE_ID/g" docsfera.json
sed -i -e "s/\${DOCS_BLOCK_ID}/$DOCS_BLOCK_ID/g" docsfera.json
curl -X POST -H 'Content-Type: application/json' -d @docsfera.json $DOCS_URL
IMAGE_TAG: ${{ needs.semantic_release.outputs.new_release_version }}
run: helmfile -f helmfiles/${ENV}.yaml sync --set image.tag=$IMAGE_TAG
+6 -11
View File
@@ -6,23 +6,18 @@ on:
jobs:
test:
runs-on: self-hosted
runs-on: [self-hosted, prd]
env:
APP_NAME: ${{ github.event.repository.name }}
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v4
- name: Build
env:
APP_NAME: ${{ github.event.repository.name }}
run: |
docker build -t $APP_NAME --target test .
run: docker build -t ${APP_NAME}_teste --target test .
- name: Run Test
env:
ENV: test
APP_NAME: ${{ github.event.repository.name }}
run: |
docker run --rm --entrypoint="npm" $APP_NAME run test
run: docker run ${APP_NAME}_teste
- name: Remove Docker's Trash
if: always()
+79
View File
@@ -0,0 +1,79 @@
name: Validate K8S Modifications
on:
pull_request:
branches:
- main
- stg
jobs:
extract_environment:
runs-on: ubuntu-22.04
outputs:
environment: ${{ steps.extract_environment.outputs.environment }}
steps:
- name: Extract Environment
run: |
if [ "${{ github.event.pull_request.base.ref }}" == "main" ]; then
echo "environment=prd" >> $GITHUB_OUTPUT
elif [ "${{ github.event.pull_request.base.ref }}" == "beta" ]; then
echo "environment=stg" >> $GITHUB_OUTPUT
fi
id: extract_environment
helmfile-deploy:
needs: [extract_environment]
runs-on: [self-hosted, "prd-azure"]
steps:
- name: Summary
env:
ENV: ${{ needs.extract_environment.outputs.environment }}
run: |
echo "### :rocket: Deploy da branch \`$GITHUB_REF_NAME\` para o environment ($ENV)" >> $GITHUB_STEP_SUMMARY
- name: Checkout code
uses: actions/checkout@v3
- name: Set up Helm
uses: azure/setup-helm@v1
with:
version: 'v3.9.0'
- name: Install Azure ClI
run: |
curl -sL https://aka.ms/InstallAzureCLIDeb | bash
- uses: azure/login@v2
with:
creds: '{"clientId":"${{ secrets.ARM_CLIENT_ID }}","clientSecret":"${{ secrets.ARM_CLIENT_SECRET }}","subscriptionId":"${{ secrets.ARM_SUBSCRIPTION_ID }}","tenantId":"${{ secrets.ARM_TENANT_ID }}"}'
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.8'
- name: Install Helmfile
run: |
wget https://github.com/helmfile/helmfile/releases/download/v0.148.0/helmfile_0.148.0_linux_amd64.tar.gz
tar -xzf helmfile_0.148.0_linux_amd64.tar.gz
mv helmfile /usr/local/bin/
helmfile --version
- name: Install Helm Diff Plugin
run: helm plugin install https://github.com/databus23/helm-diff || true
- name: Setup kubectl
uses: azure/setup-kubectl@v1
with:
version: 'v1.30.1'
- name: Authenticate with cluster
env:
CLUSTER_NAME: platform-${{ needs.extract_environment.outputs.environment }}
run: az aks get-credentials --resource-group dadosfera-prd --name ${CLUSTER_NAME} --overwrite-existing
- name: Run Helmfile Diff
env:
ENV: ${{ needs.extract_environment.outputs.environment }}
run: helmfile -f helmfiles/${ENV}.yaml diff
+1 -1
View File
@@ -1 +1 @@
18.3.0
18.17
+1
View File
@@ -12,6 +12,7 @@
"start:debug"
],
"runtimeExecutable": "npm",
"runtimeVersion": "18.17",
"skipFiles": [
"<node_internals>/**"
],
+38 -16
View File
@@ -1,21 +1,43 @@
# install all dependencies
FROM node:18.3.0-alpine3.15 as packages
FROM node:18.17-alpine AS base_image
FROM base_image AS build_base
WORKDIR /app
COPY package.json package-lock.json ./
RUN apk add --no-cache aws-cli \
&& aws codeartifact login --tool npm --namespace @dadosfera --repository dadosfera-npm --domain dadosfera --domain-owner 611330257153 --region us-east-1 \
&& npm install
RUN apk update
# needed packages to build dependencies from source
RUN apk add --no-cache aws-cli
COPY package*.json ./
# run aws cli without mounting secret, because CI already has AWS credentials
FROM build_base AS ci_image
RUN aws codeartifact login --tool npm --namespace @dadosfera --repository dadosfera-npm --domain dadosfera --domain-owner 611330257153 --region us-east-1
RUN npm ci
COPY . .
# unit test specific build
FROM node:18.3.0-alpine3.15 as test
WORKDIR /app
COPY --from=packages /app/node_modules ./node_modules
COPY . ./
FROM ci_image AS test
ENV DUC_URL=0.0.0.0:50051
ENTRYPOINT ["npm", "run", "test"]
FROM node:18.3.0-alpine3.15
WORKDIR /app
COPY . /app/
COPY --from=packages /app/node_modules ./node_modules
# dev build
FROM build_base AS dev
RUN --mount=type=secret,id=aws,target=/root/.aws/credentials \
aws codeartifact login --tool npm --namespace @dadosfera --repository dadosfera-npm --domain dadosfera --domain-owner 611330257153 --region us-east-1
# flag --build-from-source is required to force-build sqlite3
RUN npm ci
COPY . .
ENTRYPOINT npm run start:dev
FROM ci_image AS prod_build
RUN npm run build
EXPOSE 3333
ENTRYPOINT npm run start
FROM base_image
WORKDIR /app
COPY --from=prod_build /app/dist ./dist
COPY --from=prod_build /app/node_modules ./node_modules
COPY --from=prod_build /app/package*.json ./
ENTRYPOINT npm run start:prod
+10
View File
@@ -0,0 +1,10 @@
LICENSE
Copyright (C) 2023 Dadosfera
All rights reserved.
This software and related documentation are provided under a license agreement containing restrictions on use and disclosure and are protected by intellectual property laws. Except as expressly permitted in your license agreement or allowed by law, you may not use, copy, reproduce, translate, broadcast, modify, license, transmit, distribute, exhibit, perform, publish, or display any part, in any form, or by any means.
Reverse engineering, disassembly, or decompilation of this software, unless required by law for interoperability, is prohibited.
If you have any questions about this, please contact Dadosfera.ai at legal@dadosfera.ai
+174 -122
View File
@@ -1,68 +1,102 @@
<p align="center">
<image src="./assets/maestro.svg" style="width:10rem">
</p>
</p>
# Maestro
Maestro is the Dadosfera's gateway, it's responsible for the communication between the frontend application and Dadosfera's microservices.
## 🚀 Starting
These instructions will allow you to get a working copy of the project on your local machine for development and testing purposes.
Maestro é a API principal da Dadosfera. É responsável pela comunicação do Frontend com nossos microsserviços.
### 📋 Requirements
- [NodeJS v18.3.0 LTS / NPM v8.11](https://nodejs.org/pt-br/download/) (you can opt to use [NVM](https://github.com/nvm-sh/nvm) to easily manage node versions)
- Request access to AWS Console dev account for **all services** (avoid gradually asking for each needed service. it will slow down your development cycle)
- Create your Access Key on the "Security credentials" menu
- Set the Access Key on your local development machine
- Request access to the dev, stg and prd VPNs
```mermaid
graph TD;
Frontend<-->Maestro;
Maestro<-->duc;
Maestro<-->pi-factory;
Maestro<-->in-factory;
```
### 🔧 Installation<a id="installation"></a>
- Clone the repository
- SSH
```
git clone git@github.com:dadosfera/maestro.git
```
or
É uma API REST, desenvolvida em NodeJs utilizando o Framework [NestJs](https://docs.nestjs.com/).
- HTTPS
```
git clone https://github.com/dadosfera/maestro.git
```
## 🚀 Iniciando
- Select the correct node version (optional, only if using [NVM](https://github.com/nvm-sh/nvm)):
```sh
nvm use
```
Estas instruções permitirão que você obtenha uma cópia funcional do projeto em sua máquina local para desenvolvimento e testes.
- Install the project dependencies:
```sh
npm i
```
### 📋 Requisitos
- Setup the following enviroment variables:
```
ENV=
DUC_URL=
INFACTORY_URL=
OTFACTORY_URL=
PIFACTORY_URL=
SM_OAUTH_PATH=
```
- [NodeJS v18.17 / NPM v9.6.7](https://nodejs.org/pt-br/download/)
- Start the server:
```sh
# dev mode
npm run start:dev
> Dica: Utilize [NVM](https://github.com/nvm-sh/nvm) para gerenciar facilmente as versões do node
# or in debug mode
npm run start:debug
```
The service should start successfully.
- Solicite acesso à conta de desenvolvimento do AWS Console para **todos os serviços necessários**
- Crie sua Access Key no menu "Security credentials"
- Defina a Access Key em sua máquina de desenvolvimento local
- Solicite acesso às VPNs de stg e prd
## Authentication decorators
Maestro have utilities to ease the user authentication on every controller and route. The following decorators are available:
### 🔧 Instalação<a id="installation"></a>
- Clone o repositório
```sh
git clone git@github.com:dadosfera/maestro.git
```
- Selecione a versão correta do node (opcional, apenas se estiver usando o [NVM](https://github.com/nvm-sh/nvm)):
```sh
nvm use
```
- Instale as dependências do projeto:
```sh
npm i
```
- Configure as seguintes variáveis de ambiente:
```
ENV=
DUC_URL=
INFACTORY_URL=
OTFACTORY_URL=
PIFACTORY_URL=
SM_OAUTH_PATH=
```
- Inicie o servidor:
```sh
npm run start:dev
```
> Se preferir, utilize o debbuger do VSCode apertando F5
O serviço deve iniciar com sucesso.
## 📄 Documentação
O NestJs facilita a documentação de cada rota usando decoradores em todas as propriedades de solicitações e respostas. Ele gera automaticamente um swagger para as informações fornecidas e fornece uma rota para acessá-lo em http://localhost:3333/api. Para mais informações, consulte a [documentação oficial](https://docs.nestjs.com/openapi/introduction).
### - Documentações múltiplas
Atualmente, estamos gerando **2 documentações diferentes**: Interna e Externa.
Todas as rotas que têm o decorador `@ApiInternalOnly()` não serão visíveis no swagger da API **Externa**.
- Quando você inicia a aplicação com `npm run start:dev`, ela servirá e gerará o JSON do swagger da API **Interna**
- Quando você executa `npm run docs`, ele gerará o JSON do swagger de ambas as APIs **Interna** e **Externa** e os salvará em `docsfera.json` e `docsfera.external.json`, respectivamente;
> Link para documentação interna: https://dadosfera.github.io/docsfera
É importante executar `npm run docs` antes de cada implantação para que sempre tenhamos as documentações mais atualizadas publicadas.
## Decoradores de autenticação
O Maestro possui utilitários para facilitar a autenticação do usuário em todos os controladores e rotas. Os seguintes decoradores estão disponíveis:
### `@Authenticated`
If the user must be authenticated to make request, we can use the `@Authenticated` decorator in the controller or route, as needed.
Se o usuário precisar estar autenticado para fazer uma solicitação, podemos usar o decorador `@Authenticated` no controlador ou rota, conforme necessário.
```ts
import { Authenticated } from '../../authentication/authentication.decorator';
@@ -74,7 +108,7 @@ class FooController {
@Get('bar')
async getBar() {
this.logger.info('user is authenticated!');
this.logger.info('usuário está autenticado!');
return { authenticated: true };
}
@@ -91,14 +125,14 @@ class FooController {
@Get('bar')
@Authenticated()
async getBar() {
this.logger.info('user is authenticated!');
this.logger.info('usuário está autenticado!');
return { authenticated: true };
}
@Post('bar')
async postBar() {
this.logger.info('user is NOT authenticated!');
this.logger.info('usuário NÃO está autenticado!');
return { authenticated: false };
}
@@ -106,7 +140,8 @@ class FooController {
```
### `@RequireAllPermissions`
This decorator requires that **all permissions** listed are granted to the requesting user.
Este decorador exige que **todas as permissões** listadas sejam concedidas ao usuário solicitante.
```ts
import { RequireAllPermissions } from '../../authentication/authentication.decorator';
@@ -125,7 +160,8 @@ class FooController {
```
### `@RequireSomePermission`
In the following case, the user is required to have **at least one** listed permission.
No caso seguinte, é necessário que o usuário tenha **pelo menos uma** das permissões listadas.
```ts
import { RequireSomePermission } from '../../authentication/authentication.decorator';
@@ -144,17 +180,19 @@ class FooController {
```
### `@AuthenticateCondition`
If a more complicated authentication check needs to be done, we can use the `@AuthenticateCondition` decorator to define it. The custom function must return `true` to authenticate the request.
In the following example:
- all routes on the `FooController` controller can only be requested from localhost
- `POST /foo/bar` can only be requested from localhost **and** by users from customer id `111...eef`
Se for necessária uma verificação de autenticação mais complicada, podemos usar o decorador `@AuthenticateCondition` para defini-la. A função personalizada deve retornar `true` para autenticar a solicitação.
No exemplo a seguir:
- todas as rotas no controlador `FooController` só podem ser solicitadas a partir do localhost
- `POST /foo/bar` só pode ser solicitado a partir do localhost **e** por usuários do cliente com id `111...eef`
```ts
import { AuthenticateCondition } from '../../authentication/authentication.decorator';
@Controller('foo')
// allow requests only from localhost
// permitir solicitações apenas do localhost
@AuthenticateCondition((request: Request) => request.ip === '::ffff:127.0.0.1')
class FooController {
/* ... */
@@ -165,61 +203,68 @@ class FooController {
}
@Post('bar')
// allow requests only from a specific customer
@AuthenticateCondition((request: Request, user: RequestUser) => user.customer_id === '1113e943-2187-4fdd-9c2c-54338fedaeef')
// permitir solicitações apenas de um cliente específico
@AuthenticateCondition(
(request: Request, user: RequestUser) =>
user.customer_id === '1113e943-2187-4fdd-9c2c-54338fedaeef',
)
async postBar() {
/* ... */
}
}
```
### Note on authentication decorators
- The old authentication method placed the user data in the `request.body.info` field, this imposes certain issues regarding the request body because this data should be from the frontend without any modification by Maestro. Now this usage is ⚠️ **DEPRECATED** ⚠️. We are working to migrate to the `@User` parameter decorator. The old method is working while the migration is in progress.
### Nota sobre decoradores de autenticação
- Authentication decorators can be used together and all of them **must** pass to the request be authenticated, but in the general case you don't need to (*and wouldn't like to...*) use all of them together, as you can code all of the authentication logic in the `@AuthenticateCondition` decorator.
- O método antigo de autenticação colocava os dados do usuário no campo `request.body.info`, o que impõe certos problemas em relação ao corpo da solicitação, pois esses dados devem vir do frontend sem qualquer modificação pelo Maestro. Agora, esse uso está ⚠️ **DESCONTINUADO** ⚠️. Estamos trabalhando para migrar para o decorador de parâmetro `@User`. O método antigo está funcionando enquanto a migração está em andamento.
```ts
import {
RequireAllPermissions,
RequireSomePermission,
AuthenticateCondition,
} from '../../authentication/authentication.decorator';
import { PERMISSIONS } from '../../authentication/permissions.enum';
import { Waa, Baz } from './authenticationFunctions'
- Os decoradores de autenticação podem ser usados juntos e todos eles **devem** passar para que a solicitação seja autenticada, mas, no caso geral, você não precisa (_e não gostaria de..._) usar todos eles juntos, pois você pode codificar toda a lógica de autenticação no decorador `@AuthenticateCondition`.
@Controller('foo')
@RequireAllPermissions(Permissions.FOO.USE, Permissions.FOO.REQUEST)
@RequireSomePermission(Permissions.FOO.MANAGE, Permissions.FOO.ADMIN)
@AuthenticateCondition(Waa)
@AuthenticateCondition(Baz)
class FooController {
```ts
import {
RequireAllPermissions,
RequireSomePermission,
AuthenticateCondition,
} from '../../authentication/authentication.decorator';
import { PERMISSIONS } from '../../authentication/permissions.enum';
import { Waa, Baz } from './authenticationFunctions';
@Controller('foo')
@RequireAllPermissions(Permissions.FOO.USE, Permissions.FOO.REQUEST)
@RequireSomePermission(Permissions.FOO.MANAGE, Permissions.FOO.ADMIN)
@AuthenticateCondition(Waa)
@AuthenticateCondition(Baz)
class FooController {
/* ... */
@Get('bar')
async getBar() {
/* ... */
@Get('bar')
async getBar() {
/* ... */
}
@Post('bar')
@RequireAllPermissions(Permissions.BAR.MANAGE, Permissions.BAR.USE, Permissions.BAR.REQUEST)
async postBar() {
/* ... */
}
}
```
- If `@RequireAllPermissions` and `@RequireSomePermission` are used with **only a single permission**, they present the **exactly same behavior**.
@Post('bar')
@RequireAllPermissions(
Permissions.BAR.MANAGE,
Permissions.BAR.USE,
Permissions.BAR.REQUEST,
)
async postBar() {
/* ... */
}
}
```
```ts
// same behavior
@RequireAllPermissions(Permissions.BAR.MANAGE)
@RequireSomePermission(Permissions.BAR.MANAGE)
```
- Se `@RequireAllPermissions` e `@RequireSomePermission` forem usados com **apenas uma única permissão**, eles apresentam o **exatamente mesmo comportamento**.
```ts
// mesmo comportamento
@RequireAllPermissions(Permissions.BAR.MANAGE)
@RequireSomePermission(Permissions.BAR.MANAGE)
```
## Decorador de parâmetro `@User`
## `@User` parameter decorator
The requesting user data can be obtained using the @User parameter decorator, like in the following snippet:
Os dados do usuário solicitante podem ser obtidos usando o decorador de parâmetro @User, como no exemplo a seguir:
```ts
import { User, RequestUser } from '../../authentication/user.decorator';
@@ -237,7 +282,7 @@ class FooController {
}
```
If the user is required to be logged in, set `required` to `true`, as you would want in the `change-password` operation:
Se o usuário precisar estar logado, defina `required` como `true`, como por exemplo:
```ts
import { User, RequestUser } from '../../authentication/user.decorator';
@@ -263,39 +308,46 @@ class UserController {
}
```
## 📦 Development
### ⌨️ Coding Style
By default, we use [ESLint](https://eslint.org/) + [Prettier](https://prettier.io/) with default settings.
## 📦 Desenvolvimento
**We recommend using Visual Studio Code and installing the recommended extensions to ease the development process.**
### ⌨️ Estilo de Codificação
### Commits pattern
Our workflow pipeline follows the conventional commits specs ([cheat sheets](https://cheatography.com/albelop/cheat-sheets/conventional-commits/)) to release versions accordingly.
Por padrão, usamos [ESLint](https://eslint.org/) + [Prettier](https://prettier.io/) com configurações padrão.
Format: `<type>[optional scope]: <description>`
**Recomendamos usar o Visual Studio Code e instalar as extensões recomendadas para facilitar o processo de desenvolvimento.**
Example: `FIX: ensure Range headers adhere more closely to RFC 2616`
### Padrão de commits
### Branching naming convention
- **Feature**: Any code changes for a new module or use case should be done on a feature branch. This branch is created based on the `main` branch. When all changes are done, a Pull Request/Merge Request is needed to put all of these changes back to the `main` branch. Examples: `feature/integrate-swagger`, `feature/JIRA-1234`, `feature/JIRA-1234_support-dark-theme`.
Nosso pipeline de fluxo de trabalho segue as especificações de commits convencionais ([cheat sheets](https://cheatography.com/albelop/cheat-sheets/conventional-commits/)) para liberar versões conforme necessário.
**It is recommended to use all lower caps letters and hyphen (-) to separate words unless it is a specific item name or ID. Underscore (_) could be used to separate the ID and description.**
Formato: `<type>[optional scope]: <description>`
- **Bug Fix**: If the code changes made from the feature branch were rejected after a release, sprint or demo, any necessary fixes after that should be done on the bugfix branch. Examples: `bugfix/more-gray-shades`, `bugfix/JIRA-1444_gray-on-blur-fix`.
Exemplo: `FIX: ensure Range headers adhere more closely to RFC 2616`
- **Hot Fix**: If there is a need to fix a blocker, do a temporary patch, apply a critical framework or configuration change that should be handled immediately, it should be created as a Hotfix. Examples: `hotfix/disable-endpoint-zero-day-exploit`, `hotfix/increase-scaling-threshold`.
### Convenção de nomenclatura de branchs
- **Experimental**: A branch for playing around. Any new feature or idea that is not part of a release or a sprint. Example: `experimental/dark-theme-support`.
- **Feature**: Quaisquer alterações de código para um novo módulo ou caso de uso devem ser feitas em uma branch de feature. Esta branch é criada com base na branch `main`. Quando todas as alterações estiverem concluídas, será necessário um Pull Request/Merge Request para colocar todas essas alterações de volta na branch `main`. Exemplos: `feature/integrate-swagger`, `feature/JIRA-1234`, `feature/JIRA-1234_support-dark-theme`.
### Making a Pull Request
1. Commit your changes
2. Open the Pull Request on GitHub
3. Send Pull Request link in Microsfera Google Chat Group for review and possible approval
**Recomenda-se usar todas as letras em minúsculas e hífen (-) para separar palavras, a menos que seja um nome ou ID de item específico. O sublinhado (\_) pode ser usado para separar o ID e a descrição.**
## 🛠️ Built with
Some technologies used in this project:
- **Bug Fix**: Se as alterações de código feitas na branch de feature foram rejeitadas após um lançamento, sprint ou demo, quaisquer correções necessárias após isso devem ser feitas na branch de correção de bug. Exemplos: `bugfix/more-gray-shades`, `bugfix/JIRA-1444_gray-on-blur-fix`.
- [NestJS](https://docs.nestjs.com) - Framework for building efficient and scalable NodeJS server-side applications
- **Hot Fix**: Se houver necessidade de corrigir um bloqueador, fazer um patch temporário, aplicar uma mudança crítica de framework ou configuração que deva ser tratada imediatamente, ela deve ser criada como um Hotfix. Exemplos: `hotfix/disable-endpoint-zero-day-exploit`, `hotfix/increase-scaling-threshold`.
## ⚙️ Back-end Architecture
The architecture can be found at [this link](https://sites.google.com/dadosfera.ai/wikidoproduto/time/back-end).
- **Experimental**: Uma branch para experimentar. Qualquer nova feature ou ideia que não faça parte de um lançamento ou sprint. Exemplo: `experimental/dark-theme-support`.
### Fazendo um Pull Request
1. Comite suas alterações
2. Abra o Pull Request no GitHub
3. Envie o link do Pull Request no grupo de chat do Google da Microsfera para revisão e possível aprovação
## 🛠️ Construído com
Algumas tecnologias usadas neste projeto:
- [NestJS](https://docs.nestjs.com) - Framework para construir aplicações NodeJS eficientes e escaláveis no lado do servidor
## ⚙️ Arquitetura de Back-end
A arquitetura pode ser encontrada neste [link](https://sites.google.com/dadosfera.ai/wikidoproduto/time/back-end).
+4
View File
@@ -0,0 +1,4 @@
services:
maestro:
build: .
image: dadosfera/maestro_${ENV}:${IMAGE_TAG}
+1 -2
View File
@@ -1,5 +1,4 @@
version: "3.8"
services:
maestro:
build: .
image: ${ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/microservices/maestro_${ENV}:${IMAGE_TAG}
image: ${ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/microservices/maestro_prd:${IMAGE_TAG}
+28
View File
@@ -0,0 +1,28 @@
services:
maestro:
image: dadosfera/maestro_${ENV}:${IMAGE_TAG}
container_name: maestro
restart: always
ports:
- 3333:3333
env_file:
- .env
node_exporter:
image: ${NODE_EXPORTER_URL}
container_name: node_exporter
restart: always
volumes:
- /proc:/host/proc:ro
- /sys:/host/sys:ro
- /:/rootfs:ro
- /run/dbus/system_bus_socket:/var/run/dbus/system_bus_socket:ro
command:
- '--path.procfs=/host/proc'
- '--path.rootfs=/rootfs'
- '--path.sysfs=/host/sys'
- '--collector.filesystem.ignored-mount-points=^/(sys|proc|dev|host|etc)($$|/)'
- '--collector.systemd'
- '--collector.processes'
network_mode: host
pid: host
-1
View File
@@ -1,4 +1,3 @@
version: "3.8"
services:
maestro:
image: ${ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/microservices/maestro_${ENV}:${IMAGE_TAG}
File diff suppressed because it is too large Load Diff
+5015 -2666
View File
File diff suppressed because it is too large Load Diff
+18
View File
@@ -0,0 +1,18 @@
declare global {
namespace NodeJS {
interface ProcessEnv {
NODE_ENV: 'test';
ENV: 'local' | 'stg' | 'prd' | 'test';
LOCAL_ENV: 'stg' | 'prd';
DUC_URL: string;
INFACTORY_URL: string;
PIFACTORY_URL: string;
INTERNAL_SWAGGER: 'true' | 'false';
AWS_REGION: string;
}
}
}
export {};
+16
View File
@@ -0,0 +1,16 @@
charts:
- name: maestro
chart: ../maestro
values:
- ../maestro/values.yaml
set:
- name: maestro.duc_url
value: duc.dadosfera.ai
- name: hostname
value: maestro.dadosfera.ai
- name: maestro.pi_factory_url
value: pi-factory.dadosfera.ai
- name: maestro.in_factory_url
value: in-factory.dadosfera.ai
- name: maestro.tr_factory_url
value: in-factory.dadosfera.ai
+16
View File
@@ -0,0 +1,16 @@
charts:
- name: maestro
chart: ../maestro
values:
- ../maestro/values.yaml
set:
- name: maestro.duc_url
value: duc-temp.dadosfera.ai
- name: hostname
value: maestro-temp.dadosfera.ai
- name: maestro.pi_factory_url
value: pi-factory-temp.dadosfera.ai
- name: maestro.in_factory_url
value: in-factory-temp.dadosfera.ai
- name: maestro.tr_factory_url
value: in-factory-temp.dadosfera.ai
+23
View File
@@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
+24
View File
@@ -0,0 +1,24 @@
apiVersion: v2
name: maestro
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"
View File
+112
View File
@@ -0,0 +1,112 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: maestro
namespace: applications
labels:
app: maestro
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: maestro
strategy:
rollingUpdate:
maxSurge: 25%
maxUnavailable: 25%
type: RollingUpdate
template:
metadata:
labels:
app: maestro
spec:
imagePullSecrets:
- name: {{ .Values.imagePullSecrets }}
nodeSelector:
"beta.kubernetes.io/os": linux
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: application
operator: In
values:
- backend
containers:
- name: maestro
image: {{ .Values.image.repository }}:{{ .Values.image.tag }}
ports:
- containerPort: {{ .Values.containerPort }}
resources:
requests:
cpu: {{ .Values.resources.requests.cpu }}
memory: {{ .Values.resources.requests.memory }}
limits:
cpu: {{ .Values.resources.limits.cpu }}
memory: {{ .Values.resources.limits.memory }}
env:
- name: AWS_IDENTITY_POOL_ID
value: {{ .Values.maestro.aws_identity_pool_id }}
- name: AWS_REGION
value: "us-east-1"
- name: BASE_HOST
value: "maestro_prd"
- name: BUCKET_CUSTOMER_CSV_ASSETS
value: {{ .Values.maestro.bucket_customer_csv_assets }}
- name: CONNECTORS_INDEX
value: "connectors"
- name: DUC_URL
value: {{ .Values.maestro.duc_url }}
- name: ELASTIC_APM_ENVIRONMENT
value: {{ .Values.maestro.env }}
- name: ELASTIC_APM_SERVER_URL
value: "https://apm-server.dadosfera.ai"
- name: ELASTIC_APM_SERVICE_NAME
value: {{ .Values.maestro.apm_service }}
- name: ENV
value: {{ .Values.maestro.env }}
- name: INFACTORY_URL
value: {{ .Values.maestro.in_factory_url }}
- name: LOGGER_GELF_HOST
value: "logstash-pipelines.dadosfera.ai"
- name: LOGGER_GELF_PORT
value: "{{ .Values.maestro.logger_gelf_port }}"
- name: NIMBUS_BASE_URL
value: "http://nimbus-api"
- name: NPM_TOKEN
value: {{ .Values.maestro.npm_token }}
- name: PB_TOKEN_PATH
value: {{ .Values.maestro.pb_token_path }}
- name: PIFACTORY_URL
value: {{ .Values.maestro.pi_factory_url }}
- name: SM_OAUTH_PATH
value: {{ .Values.maestro.sm_oauth_path }}
- name: TRFACTORY_URL
value: {{ .Values.maestro.tr_factory_url }}
- name: UPLOAD_FILE_AGENT_CONNECTION
value: {{ .Values.maestro.upload_file_agent_connection }}
- name: JWT_PRIVATE_KEY
valueFrom:
secretKeyRef:
name: prd-duc
key: jwt_token
- name: AWS_ACCESS_KEY_ID
valueFrom:
secretKeyRef:
name: prd-maestro
key: AWS_ACCESS_KEY_ID
- name: AWS_SECRET_ACCESS_KEY
valueFrom:
secretKeyRef:
name: prd-maestro
key: AWS_SECRET_ACCESS_KEY
- name: AWS_DEFAULT_REGION
valueFrom:
secretKeyRef:
name: prd-maestro
key: AWS_DEFAULT_REGION
+27
View File
@@ -0,0 +1,27 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
annotations:
nginx.ingress.kubernetes.io/proxy-body-size: "0"
nginx.ingress.kubernetes.io/server-snippet: |
underscores_in_headers on;
ignore_invalid_headers on;
generation: 1
labels:
app: maestro
name: maestro
namespace: applications
spec:
ingressClassName: nginx
rules:
- host: {{ .Values.hostname }}
http:
paths:
- backend:
service:
name: maestro
port:
number: {{ .Values.ingress.port }}
path: /
pathType: Prefix
+40
View File
@@ -0,0 +1,40 @@
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: prd-maestro
namespace: applications
labels:
app: maestro
spec:
refreshInterval: 1h
secretStoreRef:
name: secretsmanager-prd
kind: SecretStore
target:
name: prd-maestro
creationPolicy: Owner
data:
- secretKey: AWS_ACCESS_KEY_ID
remoteRef:
key: prd/microservices/aws_credentials/maestro
version: "AWSCURRENT"
property: AWS_ACCESS_KEY_ID
- secretKey: AWS_SECRET_ACCESS_KEY
remoteRef:
key: prd/microservices/aws_credentials/maestro
version: "AWSCURRENT"
property: AWS_SECRET_ACCESS_KEY
- secretKey: AWS_DEFAULT_REGION
remoteRef:
key: prd/microservices/aws_credentials/maestro
version: "AWSCURRENT"
property: AWS_DEFAULT_REGION
- secretKey: jwt_token
remoteRef:
key: {{ .Values.maestro.jwt_token_secret_id }}
version: "AWSCURRENT"
property: token
+18
View File
@@ -0,0 +1,18 @@
apiVersion: v1
kind: Service
metadata:
name: maestro
namespace: applications
labels:
app: maestro
spec:
type: ClusterIP
ports:
- name: maestro
protocol: TCP
port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
selector:
app: maestro
+49
View File
@@ -0,0 +1,49 @@
# Default values for metabase.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 3
hostname: maestro-temp.dadosfera.ai
image:
repository: 611330257153.dkr.ecr.us-east-1.amazonaws.com/microservices/maestro_prd
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: 1.56.0
containerPort: 3333
imagePullSecrets: "applications-secrets-ecr-auth-token-external-secret"
service:
type: ClusterIP
port: 3333
targetPort: 3333
ingress:
enabled: false
port: 3333
resources:
requests:
cpu: 100m
memory: 1500Mi
limits:
cpu: 2000m
memory: 2Gi
maestro:
aws_identity_pool_id: "us-east-1_Mrezsw9Sn"
duc_url: duc.dadosfera.ai
in_factory_url: in-factory.dadosfera.ai
bucket_customer_csv_assets: "customers-csv-assets-prd-611330257153"
env: prd
apm_service: maestro
jwt_token_secret_id: prd/root/jwt_token
logger_gelf_port: "1026"
npm_token: npm_Xp17h3daMkORcZ55NY95Ez4gRfdzsQ3UvINP
pb_token_path: prd/root/productboard_token
pi_factory_url: pi-factory.dadosfera.ai
sm_oauth_path: prd/root/oauth_applications
tr_factory_url: in-factory.dadosfera.ai
upload_file_agent_connection: cbc2f881-58c4-4d60-8003-0979b0b5b911
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
targetMemoryUtilizationPercentage: 80
+4289 -11511
View File
File diff suppressed because it is too large Load Diff
+46 -45
View File
@@ -6,93 +6,94 @@
"private": true,
"license": "UNLICENSED",
"engines": {
"node": "18.3.0"
"node": "18.17"
},
"scripts": {
"preinstall": "aws codeartifact login --tool npm --namespace @dadosfera --repository dadosfera-npm --domain dadosfera --domain-owner 611330257153 --region us-east-1",
"co:login": "aws codeartifact login --tool npm --namespace @dadosfera --repository dadosfera-npm --domain dadosfera --domain-owner 611330257153 --region us-east-1",
"proto-update": "npm i @dadosfera/protospack-v2@latest --save-exact",
"prebuild": "rimraf dist",
"build": "nest build",
"format": "prettier --write \"src/**/*.ts\" \"test/**/*.ts\"",
"start": "nest start",
"start:dev": "nest start --watch",
"start:debug": "nest start --debug --watch",
"start:prod": "npm run build && node dist/main",
"start:dev": "export INTERNAL_SWAGGER=true && nest start --watch",
"start:debug": "npm run start:dev",
"start:prod": "node dist/main",
"docs": "export KILL_AFTER_START=1 && nest start && export INTERNAL_SWAGGER=true && nest start",
"lint": "eslint \"{src,apps,libs,test}/**/*.ts\" --fix",
"test": "jest",
"test": "jest --detectOpenHandles --forceExit",
"test:watch": "jest --watch",
"test:cov": "jest --coverage",
"test:debug": "node --inspect-brk -r tsconfig-paths/register -r ts-node/register node_modules/.bin/jest --runInBand",
"test:e2e": "jest --config ./test/jest-e2e.json"
},
"dependencies": {
"@aws-sdk/client-secrets-manager": "^3.112.0",
"@aws-sdk/client-secrets-manager": "^3.414.0",
"@dadosfera/dadosfera-logs": "^1.0.0-beta.4",
"@dadosfera/protospack-v2": "3.27.0",
"@grpc/grpc-js": "^1.6.7",
"@grpc/proto-loader": "^0.6.13",
"@nestjs/common": "^8.4.7",
"@nestjs/config": "^1.2.1",
"@nestjs/core": "^8.4.7",
"@nestjs/mapped-types": "*",
"@nestjs/microservices": "^8.4.7",
"@nestjs/passport": "^8.2.2",
"@nestjs/platform-express": "^8.4.7",
"@nestjs/schedule": "^1.1.0",
"@nestjs/swagger": "^5.2.1",
"@dadosfera/protospack": "2.5.3",
"@dadosfera/protospack-v2": "3.34.0",
"@grpc/grpc-js": "^1.9.3",
"@grpc/proto-loader": "^0.7.9",
"@nestjs/cli": "^9.5.0",
"@nestjs/common": "^9.4.3",
"@nestjs/config": "^2.3.4",
"@nestjs/core": "^9.4.3",
"@nestjs/mapped-types": "^1.2.2",
"@nestjs/microservices": "^9.4.3",
"@nestjs/passport": "^9.0.3",
"@nestjs/platform-express": "^9.4.3",
"@nestjs/schematics": "^9.2.0",
"@nestjs/swagger": "^6.3.0",
"@nestjs/testing": "^9.4.3",
"axios": "^0.27.2",
"class-transformer": "^0.5.1",
"class-validator": "^0.13.2",
"cron-parser": "^4.4.0",
"class-validator": "^0.14.0",
"cron-parser": "^4.9.0",
"dotenv": "^14.3.2",
"elastic-apm-node": "^3.36.0",
"helmet": "^5.1.0",
"jsonwebtoken": "^8.5.1",
"elastic-apm-node": "^3.50.0",
"helmet": "^5.1.1",
"jsonwebtoken": "^9.0.2",
"jwk-to-pem": "^2.0.5",
"mixpanel": "^0.17.0",
"ms": "^3.0.0-canary.1",
"passport": "^0.6.0",
"passport-facebook": "^3.0.0",
"passport-forcedotcom": "^0.2.0",
"passport-google-oauth20": "^2.0.0",
"passport-hubspot-oauth2": "^1.0.3",
"passport-mailchimp": "^1.1.0",
"protospack": "2.5.2",
"reflect-metadata": "^0.1.13",
"rimraf": "^3.0.2",
"rxjs": "^7.5.5",
"swagger-ui-express": "^4.4.0"
"swagger-ui-express": "^4.6.3"
},
"overrides": {
"multer": "1.4.5-lts.1"
},
"devDependencies": {
"@nestjs/cli": "^8.2.8",
"@nestjs/schematics": "^8.0.11",
"@nestjs/testing": "^8.4.7",
"@types/express": "^4.17.13",
"@types/express": "^4.17.17",
"@types/jest": "27.0.2",
"@types/jsonwebtoken": "^8.5.8",
"@types/jsonwebtoken": "^8.5.9",
"@types/jwk-to-pem": "^2.0.1",
"@types/multer": "^1.4.7",
"@types/node": "^16.11.41",
"@types/node": "^16.18.52",
"@types/passport-facebook": "^2.1.11",
"@types/passport-google-oauth20": "^2.0.11",
"@types/passport-oauth2": "^1.4.11",
"@types/passport-oauth2": "^1.4.12",
"@types/supertest": "^2.0.12",
"@typescript-eslint/eslint-plugin": "^5.29.0",
"@typescript-eslint/parser": "^5.29.0",
"eslint": "^8.18.0",
"eslint-config-prettier": "^8.5.0",
"eslint-plugin-prettier": "^4.0.0",
"@typescript-eslint/eslint-plugin": "^5.62.0",
"@typescript-eslint/parser": "^5.62.0",
"eslint": "^8.49.0",
"eslint-config-prettier": "^8.10.0",
"eslint-plugin-prettier": "^4.2.1",
"jest": "^27.5.1",
"nock": "^13.2.7",
"prettier": "^2.7.1",
"nock": "^13.3.3",
"prettier": "^2.8.8",
"source-map-support": "^0.5.20",
"supertest": "^6.2.3",
"supertest": "^6.3.3",
"ts-jest": "^27.1.5",
"ts-loader": "^9.3.1",
"ts-node": "^10.8.1",
"tsconfig-paths": "^3.14.1",
"typescript": "^4.6.3"
"ts-loader": "^9.4.4",
"ts-node": "^10.9.1",
"tsconfig-paths": "^3.14.2",
"typescript": "^4.9.5"
}
}
+9 -7
View File
@@ -25,6 +25,7 @@ import { ConfigModule } from '@nestjs/config';
import { PipelinesV2Module } from './modules/pipelinesV2/pipelines.module';
import { ProductboardModule } from './modules/productboard/productboard.module';
import { MixpanelModule } from './modules/mixpanel/mixpanel.module';
import { CustomersModule } from './modules/customers/customers.module';
@Module({
controllers: [],
@@ -40,24 +41,25 @@ import { MixpanelModule } from './modules/mixpanel/mixpanel.module';
isGlobal: true,
}),
AuthModule,
ConnectionModule,
NetworkConfigModule,
InputsModule,
PipelinesV2Module,
CatalogModule,
ConnectorModule,
PermissionsModule,
TermsOfUseModule,
ConnectionModule,
NetworkConfigModule,
ConnectionTestModule,
PipelinesModule,
PipelinesV2Module,
TransformationsModule,
HealthModule,
CatalogModule,
UsersModule,
RolesModule,
InputsModule,
OauthModule,
CatalogModule,
ProductboardModule,
MixpanelModule,
CustomersModule,
//Always leave HealthModule last, so it is on the bottom of swagger
HealthModule,
],
})
export class AppModule {}
@@ -1,56 +0,0 @@
import { Request } from 'express';
import { CustomDecorator } from '@nestjs/common';
import { PermissionsObjectPermission } from './permissions.enum';
import { RequestUser } from './user.decorator';
export const AUTH_FUNCTION_KEY = '__AUTH_FUNCTION__';
export type AuthenticationFunction = (req: Request, user: any) => boolean;
// implementation copied from SetMetadata, but tweaked to get existing values
// of the metadataKey and accumulate it with the new metadataValue
function SetMultipleMetadata(metadataKey, metadataValue): CustomDecorator {
const decoratorFactory = (target, key, descriptor) => {
// .start: tweak
// descriptor?.value = function decorator; target = class decorator
const accumulatedVal =
Reflect.getMetadata(metadataKey, descriptor?.value ?? target) ?? [];
accumulatedVal.push(metadataValue);
// .end: tweak
if (descriptor) {
Reflect.defineMetadata(metadataKey, accumulatedVal, descriptor.value);
return descriptor;
}
Reflect.defineMetadata(metadataKey, accumulatedVal, target);
return target;
};
decoratorFactory.KEY = metadataKey;
return decoratorFactory as any;
}
export function RequireAllPermissions(
...permissions: PermissionsObjectPermission[]
) {
return SetMultipleMetadata(AUTH_FUNCTION_KEY, (req, user: RequestUser) =>
permissions.every(({ seqid }) => user.permissions.includes(seqid)),
);
}
export function RequireSomePermission(
...permissions: PermissionsObjectPermission[]
) {
return SetMultipleMetadata(AUTH_FUNCTION_KEY, (req, user: RequestUser) =>
permissions.some(({ seqid }) => user.permissions.includes(seqid)),
);
}
export function AuthenticateCondition(func: AuthenticationFunction) {
return SetMultipleMetadata(AUTH_FUNCTION_KEY, func);
}
export function Authenticated() {
return SetMultipleMetadata(AUTH_FUNCTION_KEY, () => true);
}
@@ -11,7 +11,7 @@ import {
Authenticated,
RequireAllPermissions,
RequireSomePermission,
} from './authentication.decorator';
} from '../decorators/authentication.decorator';
import { AuthenticationGuard } from './authentication.guard';
import { PERMISSIONS_GROUPS } from './permissions.enum';
import { AuthClientService } from '../modules/auth/auth.service';
@@ -44,7 +44,7 @@ class NoClassAuthController {
@Get('has-all-permissions')
@RequireAllPermissions(
PERMISSIONS_GROUPS.ZENDESK.permissions.OPEN,
PERMISSIONS_GROUPS.ANALYZE.permissions.METABASE,
PERMISSIONS_GROUPS.DATAVIZ.permissions.METABASE,
)
async hasAllPermissions(@Body() body) {
return { body };
@@ -53,7 +53,7 @@ class NoClassAuthController {
@Get('has-some-permission')
@RequireSomePermission(
PERMISSIONS_GROUPS.ZENDESK.permissions.OPEN,
PERMISSIONS_GROUPS.ANALYZE.permissions.METABASE,
PERMISSIONS_GROUPS.DATAVIZ.permissions.METABASE,
)
async hasSomePermission(@Body() body) {
return { body };
@@ -62,7 +62,7 @@ class NoClassAuthController {
@Controller('class-auth-condition')
@AuthenticateCondition((req) => req.get('x-on-class') === 'ok')
@RequireSomePermission(PERMISSIONS_GROUPS.ANALYZE.permissions.METABASE)
@RequireSomePermission(PERMISSIONS_GROUPS.DATAVIZ.permissions.METABASE)
class ClassAuthConditionController {
@Get('body')
async getBody(@Body() body) {
@@ -444,13 +444,13 @@ describe('authentication.guard', () => {
NoClassAuthTest(tokenZ, ['zendesk']);
ClassAuthConditionTest(tokenZ, ['zendesk']);
const tokenM = CreateToken([PERMISSIONS_GROUPS.ANALYZE.permissions.METABASE]);
const tokenM = CreateToken([PERMISSIONS_GROUPS.DATAVIZ.permissions.METABASE]);
NoClassAuthTest(tokenM, ['metabase']);
ClassAuthConditionTest(tokenM, ['metabase']);
const tokenZM = CreateToken([
PERMISSIONS_GROUPS.ZENDESK.permissions.OPEN,
PERMISSIONS_GROUPS.ANALYZE.permissions.METABASE,
PERMISSIONS_GROUPS.DATAVIZ.permissions.METABASE,
]);
NoClassAuthTest(tokenZM, ['zendesk', 'metabase']);
ClassAuthConditionTest(tokenZM, ['zendesk', 'metabase']);
+2 -2
View File
@@ -13,8 +13,8 @@ import { AuthClientService } from '../modules/auth/auth.service';
import {
AuthenticationFunction,
AUTH_FUNCTION_KEY,
} from './authentication.decorator';
import { RequestUser } from './user.decorator';
} from '../decorators/authentication.decorator';
import { RequestUser } from '../decorators/user.decorator';
import ErrorBuilder from '../utils/ErrorBuilder';
import ErrorCodes from '../utils/errorCodes';
+97 -17
View File
@@ -55,9 +55,18 @@ export const PERMISSIONS_GROUPS = {
'es-es': '',
},
},
GENERATE_TOKEN: {
seqid: 46,
claim: 'customer:generate-token',
usage: PermissionUsages.PUBLIC,
name: {
'pt-br': 'Gerar Token de Acesso',
'en-us': 'Generate Acess Token',
'es-es': 'Gerar Token de Acceso',
},
},
},
},
PIPELINE: {
title: {
'pt-br': 'Coletar | Pipelines',
@@ -107,7 +116,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
CONNECTION: {
title: {
'pt-br': 'Coletar | Fontes de dados',
@@ -147,7 +155,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
NETWORK_CONFIG: {
title: {
'pt-br': 'Coletar | Redes',
@@ -177,7 +184,6 @@ export const PERMISSIONS_GROUPS = {
// },
},
},
OUTPUT: {
title: {
'pt-br': 'Output',
@@ -227,7 +233,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
TRANSFORMATIONS: {
title: {
'pt-br': 'Micro-transformações',
@@ -277,7 +282,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
CATALOG: {
title: {
'pt-br': 'Explorar | Catálogo',
@@ -336,9 +340,28 @@ export const PERMISSIONS_GROUPS = {
'es-es': 'Gestor de catálogos. Puede ver y editar todos los activos.',
},
},
EMBED_ANALYTICS: {
seqid: 44,
claim: 'catalog:embed',
usage: PermissionUsages.INTERNAL,
name: {
'pt-br': 'Acessar Módulo de Incorporação de Ativos',
'en-us': 'Access Embedding analytics Module',
'es-es': 'Acceder al Módulo de Incorporación de Activos',
},
},
TRIGGER_CATALOG_TASK: {
seqid: 45,
claim: 'catalog:trigger-task',
usage: PermissionUsages.INTERNAL,
name: {
'pt-br': 'Executar a catalogação de um ativo',
'en-us': 'Trigger an asset cataloging',
'es-es': 'Realizar el listado de un activo',
},
},
},
},
CONNECTORS: {
title: {
'pt-br': 'Conectores',
@@ -388,7 +411,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
SNOWFLAKE: {
title: {
'pt-br': 'Explorar | Consolidar',
@@ -408,7 +430,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
ZENDESK: {
title: {
'pt-br': 'Zendesk',
@@ -418,18 +439,17 @@ export const PERMISSIONS_GROUPS = {
permissions: {
OPEN: {
seqid: 16,
claim: 'GET /zendesk',
claim: 'support-chat:access',
usage: PermissionUsages.INTERNAL,
name: {
'pt-br': 'Acessar Zendesk',
'en-us': 'Access Zendesk',
'es-es': 'Acceso Zendesk',
'pt-br': 'Acessar chat de suporte',
'en-us': 'Access support chat',
'es-es': 'Acceder al chat de soporte',
},
},
},
},
ANALYZE: {
DATAVIZ: {
title: {
'pt-br': 'Analisar | Visualização',
'en-us': 'Analyze | Visualization',
@@ -446,6 +466,15 @@ export const PERMISSIONS_GROUPS = {
'es-es': 'Acceso Metabase',
},
},
},
},
INTELLIGENCE: {
title: {
'pt-br': 'Analisar | Inteligência',
'en-us': 'Analyze | Intelligence',
'es-es': 'Analizar | Inteligencia',
},
permissions: {
INTELLIGENCE: {
seqid: 31,
claim: 'intelligence:open',
@@ -458,7 +487,6 @@ export const PERMISSIONS_GROUPS = {
},
},
},
MODULES: {
title: {
'pt-br': 'Módulos da Dadosfera',
@@ -555,8 +583,55 @@ export const PERMISSIONS_GROUPS = {
},
},
},
CUSTOMER: {
title: {
'pt-br': 'Organização',
'en-us': 'Organization',
'es-es': 'Organización',
},
permissions: {
MONITORING_DASHBOARD: {
seqid: 47,
claim: 'customer:monitoring-dashboard',
usage: PermissionUsages.PUBLIC,
name: {
'pt-br': 'Ver o dashboard de monitoramento',
'en-us': 'View the monitoring dashboard',
'es-es': 'Ver el dashboard de monitoreo',
},
},
},
},
};
export interface DadosferaModule {
name: string;
description: string;
key: string;
permissionSeqId: number;
}
export const DADOSFERA_MODULES: Array<DadosferaModule> = [
{
name: 'Intelligence Module',
description: 'Orchest Module',
key: 'intelligence',
permissionSeqId:
PERMISSIONS_GROUPS.INTELLIGENCE.permissions.INTELLIGENCE.seqid,
},
{
name: 'Proccessing Module',
description: 'Proccessing Module',
key: 'process',
permissionSeqId:
PERMISSIONS_GROUPS.PROCESS.permissions.TRANSFORMATION.seqid,
},
{
name: 'Embedded Analytics',
description: 'Embedded Analytics Module',
key: 'embedded-analytics',
permissionSeqId:
PERMISSIONS_GROUPS.PROCESS.permissions.TRANSFORMATION.seqid,
},
];
// traverses the object searching for duplicate seqids or claims (executes at runtime)
let nextAvailableSeqid = 0;
const seqids = Object.values(PERMISSIONS_GROUPS).flatMap((namespace) =>
@@ -576,4 +651,9 @@ Object.values(PERMISSIONS_GROUPS).map((namespace) =>
}),
);
DADOSFERA_MODULES.map((m) => m.key).forEach((m, i, arr) => {
if (arr.indexOf(m) !== i)
throw new Error(`DADOSFERA_MODULES[${i}] does not have a unique key`);
});
logger.log(`next available seqid ${nextAvailableSeqid + 1}`);
@@ -0,0 +1,41 @@
import { applyDecorators } from '@nestjs/common';
import { ApiSecurity } from '@nestjs/swagger';
import { type Request } from 'express';
import { type PermissionsObjectPermission } from '../authentication/permissions.enum';
import { type RequestUser } from './user.decorator';
import { SetMultipleMetadata } from './shared';
export const AUTH_FUNCTION_KEY = '__AUTH_FUNCTION__';
export type AuthenticationFunction = (req: Request, user: any) => boolean;
export function RequireAllPermissions(
...permissions: PermissionsObjectPermission[]
) {
return createAuthenticatedDecorator((req, user: RequestUser) =>
permissions.every(({ seqid }) => user.permissions.includes(seqid)),
);
}
export function RequireSomePermission(
...permissions: PermissionsObjectPermission[]
) {
return createAuthenticatedDecorator((req, user: RequestUser) =>
permissions.some(({ seqid }) => user.permissions.includes(seqid)),
);
}
export function AuthenticateCondition(func: AuthenticationFunction) {
return createAuthenticatedDecorator(func);
}
export function Authenticated() {
return createAuthenticatedDecorator(() => true);
}
function createAuthenticatedDecorator(metadataValue: AuthenticationFunction) {
return applyDecorators(
ApiSecurity('access-token'),
SetMultipleMetadata(AUTH_FUNCTION_KEY, metadataValue),
);
}
+25
View File
@@ -0,0 +1,25 @@
import { createParamDecorator, type ExecutionContext } from '@nestjs/common';
import { LanguageEnum } from 'src/utils/languages.enum';
export const Language: () => ParameterDecorator = createParamDecorator(
(options: any, ctx: ExecutionContext): LanguageEnum => {
const headers = ctx.switchToHttp()?.getRequest()?.headers;
if (!headers) return LanguageEnum.ptbr;
let language: LanguageEnum =
headers['dadosfera-lang'] ?? headers['accept-language'];
language = language?.toLowerCase().trim() as LanguageEnum;
if (!language) return LanguageEnum.ptbr;
Object.values(LanguageEnum).some((l) => {
if (language === l || l.includes(language)) {
language = l;
return true;
}
language = LanguageEnum.enus;
});
return language;
},
);
+28
View File
@@ -0,0 +1,28 @@
import { type CustomDecorator } from '@nestjs/common';
// implementation copied from SetMetadata, but tweaked to get existing values
// of the metadataKey and accumulate it with the new metadataValue
export function SetMultipleMetadata(
metadataKey,
metadataValue,
): CustomDecorator {
const decoratorFactory: CustomDecorator = (target, key?, descriptor?) => {
// .start: tweak
// descriptor?.value = function decorator; target = class decorator
const accumulatedVal =
Reflect.getMetadata(metadataKey, descriptor?.value ?? target) ?? [];
accumulatedVal.push(metadataValue);
// .end: tweak
if (descriptor) {
Reflect.defineMetadata(metadataKey, accumulatedVal, descriptor.value);
return descriptor;
}
Reflect.defineMetadata(metadataKey, accumulatedVal, target);
return target;
};
decoratorFactory.KEY = metadataKey;
return decoratorFactory;
}
+13
View File
@@ -0,0 +1,13 @@
import { applyDecorators } from '@nestjs/common';
import { ApiExcludeController, ApiExcludeEndpoint } from '@nestjs/swagger';
export function ApiInternalOnlyEndpoint() {
if (process.env.INTERNAL_SWAGGER !== 'true')
return applyDecorators(ApiExcludeEndpoint());
return () => null;
}
export function ApiInternalOnlyController() {
if (process.env.INTERNAL_SWAGGER !== 'true')
return applyDecorators(ApiExcludeController());
return () => null;
}
@@ -1,17 +1,14 @@
import request from 'supertest';
import { Test } from '@nestjs/testing';
import { HttpStatus, INestApplication } from '@nestjs/common';
import { APP_GUARD } from '@nestjs/core';
import jwt from 'jsonwebtoken';
import { Controller, Get } from '@nestjs/common';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { AuthenticationGuard } from './authentication.guard';
import { Controller, Get, HttpStatus, INestApplication } from '@nestjs/common';
import { APP_GUARD } from '@nestjs/core';
import { Test } from '@nestjs/testing';
import jwt from 'jsonwebtoken';
import request from 'supertest';
import { AuthenticationGuard } from '../authentication/authentication.guard';
import { PERMISSIONS_GROUPS } from '../authentication/permissions.enum';
import { AuthClientService } from '../modules/auth/auth.service';
import ErrorCodes from '../utils/errorCodes';
import { User } from './user.decorator';
import { PERMISSIONS_GROUPS } from './permissions.enum';
const logger = {
info: (...args) => args,
@@ -49,7 +46,7 @@ describe('user.decorator', () => {
const fakeUserPayload = {
user_id: 'd50d33c7-6c2b-463c-861f-e21667e7c125',
username: 'super.admin',
permissions: [PERMISSIONS_GROUPS.ANALYZE.permissions.METABASE].map(
permissions: [PERMISSIONS_GROUPS.DATAVIZ.permissions.METABASE].map(
({ seqid }) => seqid,
),
customer_id: '9d18e8ae-24b9-41a3-9e8f-a25ce57555b11',
@@ -1,4 +1,4 @@
import { createParamDecorator, ExecutionContext } from '@nestjs/common';
import { createParamDecorator, type ExecutionContext } from '@nestjs/common';
import ErrorBuilder from '../utils/ErrorBuilder';
import ErrorCodes from '../utils/errorCodes';
+21 -10
View File
@@ -24,11 +24,10 @@ async function bootstrap() {
optionsSuccessStatus: 204,
},
});
app.use(helmet());
configureSwagger(app);
await app.listen(3333);
if (process.env.KILL_AFTER_START) await app.close();
}
function configureSwagger(app: INestApplication) {
@@ -39,24 +38,36 @@ function configureSwagger(app: INestApplication) {
.replace('\n', '')
.trim();
} catch (error) {
console.log("Can't get branch name", error);
console.warn("Can't get branch name", error);
}
const swaggerTitle = branchName ? `Maestro - ${branchName}` : 'Maestro';
const config = new DocumentBuilder()
const swaggerConfig = new DocumentBuilder()
.setTitle(swaggerTitle)
.setDescription('Documentation for Maestro gateway')
.addBearerAuth(
{ type: 'http', scheme: 'bearer', bearerFormat: 'JWT' },
'Authorization',
)
.build();
.addSecurity('access-token', {
type: 'apiKey',
name: 'Authorization',
in: 'header',
})
.setDescription('This is the Maestro API');
if (process.env.INTERNAL_SWAGGER !== 'true')
swaggerConfig.addServer('https://maestro.dadosfera.ai', 'Dadosfera API');
const config = swaggerConfig.build();
const document = SwaggerModule.createDocument(app, config);
const swaggerJsonFile =
process.env.INTERNAL_SWAGGER === 'true'
? 'docsfera.json'
: 'docsfera.external.json';
if (process.env.ENV === 'local') SwaggerModule.setup('api', app, document);
writeFileSync(
'docsfera.json',
swaggerJsonFile,
JSON.stringify(
{
service: '${DOCS_API_TOKEN}',
+38
View File
@@ -0,0 +1,38 @@
# Auth
## SSO/oAuth
### Strategy
We are using [PassportJs](https://www.passportjs.org/) to handle oAuth authentications.
When the client (front end) makes a `GET /auth/oauth/{strategy}` Passport automatically redirects the user to the `strategy` login page. To do that we must configure and use a **Passport Strategy**. We must also have a callback route, conventionally `GET /auth/oauth/{strategy}/callback`, so the oAuth app can report the status of the user's login.
- If the oAuth is successfull we call DUC's `AuthOauthSignIn` request that gets the tokens from Cognito and saves them on cache temporarily under a key we call `session`. Duc returns that `session` to maestro which then redirects the user to our app login page with that `session` as a query param.
- If the oAuth login is not successfull for some reason or the user **does not** exist on DUC's database we redirect the user to our login page with an `error` and `error_description` as query params.
### Routes
So in order to have an SSO login, besides configuring the Strategy, we must have two routes for each Strategy, like in the example below:
```ts
@Get('oauth/google')
@UseGuards(AuthGuard('google-login'))
googleOauth() {
this.logger.info('/oauth/google');
return true;
}
@Get('oauth/google/callback')
@UseGuards(AuthGuard('google-login'))
@Redirect()
async googleOauthCallback(@Req() req) {
const { url, email, token, language = 'pt-br' } = await this.callback(req);
if (url.searchParams.get('error')) {
this.logger.error('/oauth/google - ERROR');
return { url: url.href };
}
// ... Rest of the logic
return { url: url.href };
}
```
+167 -27
View File
@@ -8,8 +8,17 @@ import {
Inject,
UseFilters,
Get,
UseGuards,
Redirect,
Req,
Param,
} from '@nestjs/common';
import { ApiTags } from '@nestjs/swagger';
import {
ApiHeaders,
ApiOkResponse,
ApiSecurity,
ApiTags,
} from '@nestjs/swagger';
import {
AuthChangePasswordRequest,
AuthResetPasswordRequest,
@@ -24,24 +33,33 @@ import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import {
Authenticated,
RequireAllPermissions,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { AuthClientService } from './auth.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { GrpcToHttpExceptionFilter } from '../../error/grpc-to-http-exception.filter';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { Metadata } from '@grpc/grpc-js';
import { RequestUser, User } from 'src/decorators/user.decorator';
import {
AuthRefreshAccessTokenReq,
AuthRefreshAccessTokenRes,
AuthSignInReq,
AuthSignInRes,
} from './dtos/login';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
import { AuthGuard } from '@nestjs/passport';
import { Request } from 'express';
import ErrorCodes, { OauthErrors } from 'src/utils/errorCodes';
import jwt from 'jsonwebtoken';
import { LanguageEnum } from 'src/utils/languages.enum';
import { Language } from 'src/decorators/language.decorator';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
@ApiTags('Auth')
@ApiHeaders([{ name: 'dadosfera-lang', enum: LanguageEnum, required: false }])
@UseFilters(new GrpcToHttpExceptionFilter())
@Controller('auth')
export class AuthController {
logger: DadosferaLogger;
redirectUrl: string;
constructor(
@Inject(DadosferaLogger)
@@ -49,20 +67,49 @@ export class AuthController {
private authClient: AuthClientService,
) {
this.logger = dadosferaLogger.logger;
switch (process.env.ENV) {
case 'stg':
this.redirectUrl = `https://app.${process.env.ENV}.dadosfera.ai/auth/login`;
break;
case 'prd':
this.redirectUrl = `https://app.dadosfera.ai/auth/login`;
break;
default:
this.redirectUrl = `http://localhost:4200/auth/login`;
}
}
@Post('sign-in')
@HttpCode(HttpStatus.OK)
async signIn(
@Body() { username, password, totp }: AuthSignInReq,
@Headers('Dadosfera-Lang') language: string,
@Language() language: LanguageEnum,
): Promise<AuthSignInRes> {
this.logger.info('/auth - SignIn');
const metadata = new Metadata();
metadata.add('language', language || 'pt-br');
const metadata = PackTheMetadata({ language });
return this.authClient.signIn({ username, password, totp }, metadata);
}
@Post('refresh-access-token')
@HttpCode(HttpStatus.OK)
@ApiOkResponse({ type: AuthRefreshAccessTokenRes })
async refreshAccessToken(
@Body() body: AuthRefreshAccessTokenReq,
@Language() language: LanguageEnum,
) {
this.logger.info('/auth - RefreshAccessToken');
const { refreshToken, customerName: customer_name } = body;
const metadata = PackTheMetadata({
customer_name,
language,
});
return this.authClient.refreshAccessToken({ refreshToken }, metadata);
}
@ApiInternalOnlyEndpoint()
@Post('/sso/snowflake')
@RequireAllPermissions(PERMISSIONS_GROUPS.SNOWFLAKE.permissions.OPEN)
@HttpCode(HttpStatus.OK)
@@ -78,23 +125,7 @@ export class AuthController {
});
}
@Post('refresh-access-token')
@HttpCode(HttpStatus.OK)
async refreshAccessToken(
@Body()
{ refreshToken, customerName: customer_name }: AuthRefreshAccessTokenReq,
@Headers('Dadosfera-Lang') language: string,
) {
this.logger.info('/auth - RefreshAccessToken');
const metadata = PackTheMetadata({
customer_name,
language,
});
return this.authClient.refreshAccessToken({ refreshToken }, metadata);
}
@ApiInternalOnlyEndpoint()
@Post('change-password')
@HttpCode(HttpStatus.OK)
async changePassword(
@@ -113,16 +144,24 @@ export class AuthController {
});
}
@ApiInternalOnlyEndpoint()
@Post('reset-password')
@HttpCode(HttpStatus.OK)
async resetPassword(@Body() body: AuthResetPasswordRequest) {
async resetPassword(
@Body() body: AuthResetPasswordRequest,
@Language() language: LanguageEnum,
) {
this.logger.info('/auth - reset-password');
const metadata = PackTheMetadata({
language: language,
});
const { username } = body;
return this.authClient.resetPassword({ username });
return this.authClient.resetPassword({ username }, metadata);
}
@ApiInternalOnlyEndpoint()
@Post('verify-reset-password-code')
@HttpCode(HttpStatus.OK)
async verifyResetPasswordCode(
@@ -135,6 +174,7 @@ export class AuthController {
return this.authClient.verifyResetPasswordCode({ username, code });
}
@ApiInternalOnlyEndpoint()
@Post('confirm-reset-password')
@HttpCode(HttpStatus.OK)
async confirmResetPassword(@Body() body: AuthConfirmResetPasswordRequest) {
@@ -149,6 +189,7 @@ export class AuthController {
});
}
@ApiInternalOnlyEndpoint()
@Post('enable-totp')
@HttpCode(HttpStatus.OK)
async enableTotpMFA(
@@ -163,6 +204,7 @@ export class AuthController {
return this.authClient.enableTotpMFA({ accessToken, password });
}
@ApiInternalOnlyEndpoint()
@Post('disable-totp')
@HttpCode(HttpStatus.OK)
async disableTotpMFA(
@@ -177,6 +219,7 @@ export class AuthController {
return this.authClient.disableTotpMFA({ accessToken, password });
}
@ApiInternalOnlyEndpoint()
@Post('dismiss-totp')
@HttpCode(HttpStatus.OK)
async dismissTotpMFA(@Headers() headers) {
@@ -187,6 +230,7 @@ export class AuthController {
return this.authClient.dismissTotpMFA({ accessToken });
}
@ApiInternalOnlyEndpoint()
@Post('verify-totp')
@HttpCode(HttpStatus.OK)
async verifyTotp(@Body() body: AuthVerifyTotpMfaRequest, @Headers() headers) {
@@ -198,10 +242,106 @@ export class AuthController {
return this.authClient.verifyTotp({ accessToken, totp });
}
@ApiInternalOnlyEndpoint()
@Authenticated()
@ApiSecurity('access-token')
@Get('verify-access-token')
@HttpCode(HttpStatus.OK)
verifyAccessToken() {
return { access_token_status: 'valid' };
}
@ApiInternalOnlyEndpoint()
@Get('session/:session')
getSession(@Param('session') session: string) {
return this.authClient.getSession(session);
}
@ApiInternalOnlyEndpoint()
@Get('oauth/google')
@UseGuards(AuthGuard('google-login'))
googleOauth() {
this.logger.info('/oauth/google');
return true;
}
@ApiInternalOnlyEndpoint()
@Get('oauth/google/callback')
@UseGuards(AuthGuard('google-login'))
@Redirect()
async googleOauthCallback(@Req() req) {
const { url, email, token, language = 'pt-br' } = await this.callback(req);
if (url.searchParams.get('error')) {
this.logger.error('/oauth/google - ERROR');
return { url: url.href };
}
await this.authClient
.oauthSignIn({
username: email,
token,
})
.then(({ session }) => {
this.logger.info('/oauth/google - SUCESS');
url.searchParams.set('session', session);
})
.catch((err) => {
this.logger.error('/oauth/google - ERROR');
let error = OauthErrors.INVALID_CREDENTIALS[language].error;
let error_description =
OauthErrors.INVALID_CREDENTIALS[language].error_description;
switch (err.details) {
case ErrorCodes.USER.NOT_FOUND:
error = OauthErrors.USER_NOT_FOUND[language].error;
error_description =
OauthErrors.USER_NOT_FOUND[language].error_description(email);
break;
case ErrorCodes.AUTH.UNAUTHORIZED:
error = OauthErrors.INVALID_SESSION[language].error;
error_description =
OauthErrors.INVALID_SESSION[language].error_description;
break;
}
url.searchParams.set('error', error);
url.searchParams.set('error_description', error_description);
return null;
});
return { url: url.href };
}
async callback(req: Request) {
const { error, state } = req.query;
const { authInfo } = req;
const url = new URL(this.redirectUrl);
let email, token, error_title, error_description;
let language: 'pt-br' | 'en-us' = 'pt-br';
const stateObject = jwt.verify(
state as string,
process.env.JWT_PRIVATE_KEY,
);
if (typeof stateObject != 'string') language = stateObject.language;
if (error || !authInfo) {
this.logger.error(error);
if (!authInfo) this.logger.error('No authInfo', { request: req });
error_title = OauthErrors.INVALID_CREDENTIALS[language].error;
error_description =
OauthErrors.INVALID_CREDENTIALS[language].error_description;
if (error) error_description += ` - [${error}]`;
} else {
const { accessToken } = authInfo as any;
const { _json: userInfo } = req.user as any;
email = userInfo.email;
token = accessToken;
}
if (error_title) {
url.searchParams.set('error', error_title);
url.searchParams.set('error_description', error_description);
}
return { token, email, url, language };
}
}
+8 -1
View File
@@ -6,12 +6,19 @@ import { AuthController } from './auth.controller';
import { AuthClientService } from './auth.service';
import { DucClient } from '../duc/client.config';
import { GoogleLoginStrategy } from './passport-strategies/google-strategy';
import { getOauthSecrets } from 'src/utils/OauthSecrets';
const client = new DucClient();
@Module({
imports: [ClientsModule.register([client.providerOptions])],
controllers: [AuthController],
providers: [AuthClientService, DadosferaLogger],
providers: [
AuthClientService,
DadosferaLogger,
GoogleLoginStrategy,
{ provide: 'OAUTH_SECRETS', useValue: getOauthSecrets() },
],
exports: [AuthClientService],
})
export class AuthModule {}
+18 -2
View File
@@ -90,10 +90,15 @@ export class AuthClientService implements OnModuleInit {
);
}
async resetPassword({ username }: AuthResetPasswordRequest) {
async resetPassword(
{ username }: AuthResetPasswordRequest,
metadata: Metadata,
) {
this.logger.info('resetPassword');
return lastValueFrom(this.authService.AuthResetPassword({ username }));
return lastValueFrom(
this.authService.AuthResetPassword({ username }, metadata),
);
}
async verifyResetPasswordCode({
@@ -152,4 +157,15 @@ export class AuthClientService implements OnModuleInit {
this.authService.AuthVerifyTotpMfa({ accessToken, totp }),
);
}
async getSession(session: string) {
return lastValueFrom(this.authService.AuthGetSession({ session }));
}
async oauthSignIn(data: { username: string; token: string }) {
const { username, token } = data;
return lastValueFrom(
this.authService.AuthOauthSignIn({ token, username, refreshToken: '' }),
);
}
}
+15 -1
View File
@@ -1,3 +1,4 @@
import { Link } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/entities';
import {
AuthSignInRequest,
AuthSignInResponse,
@@ -72,6 +73,10 @@ export class AuthCustomer {
name: string;
@ApiProperty()
tier: string;
@ApiProperty()
scheduleLimit: string;
@ApiProperty()
links: Link[];
}
export class AuthSignInReq implements AuthSignInRequest {
@@ -79,7 +84,10 @@ export class AuthSignInReq implements AuthSignInRequest {
username: string;
@ApiProperty()
password: string;
@ApiPropertyOptional()
@ApiPropertyOptional({
description:
'TOTP code used to login when Multi-Factor Authentication is enabled',
})
totp: string;
}
@@ -104,3 +112,9 @@ export class AuthRefreshAccessTokenReq {
@ApiProperty()
customerName: string;
}
export class AuthRefreshAccessTokenRes {
@ApiProperty()
permissions: string[];
@ApiProperty()
accessToken: string;
}
@@ -0,0 +1,46 @@
import {
AuthenticateOptionsGoogle,
Profile,
Strategy,
StrategyOptions,
} from 'passport-google-oauth20';
import { PassportStrategy } from '@nestjs/passport';
import { Inject, Injectable } from '@nestjs/common';
import { OauthSecrets } from 'src/utils/OauthSecrets';
import { Request } from 'express';
import jwt from 'jsonwebtoken';
@Injectable()
export class GoogleLoginStrategy extends PassportStrategy(
Strategy,
'google-login',
) {
redirect_uri: string;
constructor(
@Inject('OAUTH_SECRETS')
private readonly oauthSecrets: OauthSecrets,
) {
const options: StrategyOptions = {
clientID: oauthSecrets['google-login'].client_id,
clientSecret: oauthSecrets['google-login'].client_secret,
callbackURL: oauthSecrets['google-login'].redirect_uri,
scope: ['email', 'profile', 'openid'],
};
const verify = (
accessToken: string,
refreshToken: string,
profile: Profile,
done,
) => {
return done(null, profile, { accessToken, refreshToken });
};
super(options, verify);
}
authenticate(req: Request, options: AuthenticateOptionsGoogle) {
const language = req.headers['dadosfera-lang'] || req.query.language;
options.state = jwt.sign({ language }, process.env.JWT_PRIVATE_KEY);
super.authenticate(req, options);
}
}
+5 -4
View File
@@ -6,6 +6,10 @@ import {
import { credentials } from '@grpc/grpc-js';
import { Catalog } from '@dadosfera/protospack-v2';
const isLocalConnection =
process.env.PIFACTORY_URL.startsWith('pi-factory:') ||
process.env.PIFACTORY_URL.includes('0.0.0.0');
export class CatalogClientConfiguration {
public name = 'CatalogClientConfiguration';
private config: GrpcOptions = {
@@ -16,10 +20,7 @@ export class CatalogClientConfiguration {
Catalog.ProtoPackages.ReadPackage,
Catalog.ProtoPackages.WritePackage,
],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [
Catalog.ProtoPaths.ReadFilePath,
Catalog.ProtoPaths.WriteFilePath,
+219 -43
View File
@@ -1,28 +1,39 @@
import {
BadRequestException,
Body,
Controller,
Delete,
ForbiddenException,
Get,
Headers,
HttpException,
Inject,
NotFoundException,
Param,
Post,
Put,
Query,
UseFilters,
} from '@nestjs/common';
import { ApiTags } from '@nestjs/swagger';
import {
ApiCreatedResponse,
ApiHeaders,
ApiOkResponse,
ApiTags,
} from '@nestjs/swagger';
import {
Authenticated,
RequireAllPermissions,
RequireSomePermission,
} from '../../authentication/authentication.decorator';
} from '../../decorators/authentication.decorator';
import { PERMISSIONS_GROUPS } from '../../authentication/permissions.enum';
import { CatalogService } from './catalog.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import {
BatchRemoveRlsRulesRequest,
GetDatasetCatalogTaskRes,
ICatalogAllRequest,
ICatalogAllResponse,
IColumnsMetadataResponse,
ICreateDataAsset,
@@ -32,10 +43,21 @@ import {
IOneDataAsset,
IPreviewResponse,
IUpdateDataRequest,
TriggerCatalogReq,
TriggerCatalogRes,
} from './dtos';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { Language } from 'src/decorators/language.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
import {
AddRlsRuleRequest,
GetNimbusDashboardsRequest,
GetRlsRulesRequest,
} from '@dadosfera/protospack-v2/dist/lib/Catalog/interfaces/messages';
@ApiTags('Catalog')
@ApiHeaders([{ name: 'dadosfera-lang', enum: LanguageEnum, required: false }])
@Controller('catalog')
@UseFilters(new GrpcToHttpExceptionFilter())
@Authenticated()
@@ -56,7 +78,7 @@ export class CatalogController {
)
async searchCatalog(
@User() user: RequestUser,
@Query() query,
@Query() query: ICatalogAllRequest,
): Promise<ICatalogAllResponse> {
const { user_id, customer_name, customer_id, username, permissions } = user;
this.logger.info(`/catalog - searchCatalog`, {
@@ -88,6 +110,7 @@ export class CatalogController {
return res;
}
@ApiInternalOnlyEndpoint()
@Get('data-asset')
async findByPipelineAndObject(@User() user: RequestUser, @Query() query) {
const { username, user_id, customer_id, customer_name, permissions } = user;
@@ -98,7 +121,7 @@ export class CatalogController {
});
if (!pipeline || !object) {
throw new HttpException('Query params not provided', 400);
throw new BadRequestException('Query params not provided');
}
const is_data_manager = permissions.includes(
@@ -136,12 +159,12 @@ export class CatalogController {
return { data_asset };
}
throw new HttpException(
throw new ForbiddenException(
'You do not have permission to access this data asset.',
403,
);
}
@ApiInternalOnlyEndpoint()
@Get('tags')
@RequireSomePermission(
PERMISSIONS_GROUPS.CATALOG.permissions.GET,
@@ -172,12 +195,12 @@ export class CatalogController {
)
async getDataAsset(
@User() user: RequestUser,
@Headers() headers,
@Param('id') id,
@Param('id') id: string,
@Query('shared') shared?: 'true',
) {
const { username, user_id, customer_id, customer_name, permissions } = user;
this.logger.info(`/catalog - ON GET ONE DASHBOARD METABASE ROUTE`, {
this.logger.info(`GET /data-asset/${id}`, {
username,
customer_name,
});
@@ -188,7 +211,7 @@ export class CatalogController {
let has_permission = false;
const metadata = PackTheMetadata({
username,
user_id: undefined,
user_id,
customer_id,
customer_name,
});
@@ -200,27 +223,27 @@ export class CatalogController {
id,
metadata,
});
has_permission =
is_data_manager ||
data_asset?.owner === username ||
(user_roles as Array<any>).some((r) => data_asset.p_roles.includes(r)) ||
data_asset.p_users.includes(user_id);
if (
shared === 'true' &&
(data_asset.share_type === undefined || data_asset.share_type === 'none')
)
throw new NotFoundException();
if (!has_permission)
throw new ForbiddenException(
'You do not have permission to access this data asset.',
);
delete data_asset.p_roles;
delete data_asset.p_users;
if (data_asset?.owner === username) has_permission = true;
for (const role of user_roles) {
if (data_asset.p_roles.includes(role)) has_permission = true;
}
if (data_asset.p_users.includes(user_id)) has_permission = true;
if (is_data_manager || has_permission) {
delete data_asset.p_roles;
delete data_asset.p_users;
return { data_asset };
}
throw new HttpException(
'You do not have permission to access this data asset.',
403,
);
return { data_asset };
}
@ApiInternalOnlyEndpoint()
@Get('data-asset/rls/:id')
@RequireSomePermission(
PERMISSIONS_GROUPS.CATALOG.permissions.GET,
@@ -229,7 +252,7 @@ export class CatalogController {
async getDataAssetRls(
@User() user: RequestUser,
@Headers() headers,
@Param('id') id,
@Param('id') id: string,
) {
const { username, user_id, customer_id, customer_name, permissions } = user;
@@ -271,9 +294,8 @@ export class CatalogController {
return { data_asset };
}
throw new HttpException(
throw new ForbiddenException(
'You do not have permission to access this data asset.',
403,
);
}
@@ -284,8 +306,8 @@ export class CatalogController {
)
async getDataAssetColumnsMetadata(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Param('id') id,
@Language() language: LanguageEnum,
@Param('id') id: string,
): Promise<IColumnsMetadataResponse> {
const { customer_name, customer_id, user_id, username } = user;
@@ -315,8 +337,8 @@ export class CatalogController {
)
async getDataAssetPreview(
@User() user: RequestUser,
@Headers('Dadosfera-lang') language,
@Param('id') id,
@Language() language: LanguageEnum,
@Param('id') id: string,
): Promise<IPreviewResponse> {
const { customer_name, customer_id, user_id, username } = user;
@@ -345,8 +367,8 @@ export class CatalogController {
)
async getDataAssetDocs(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Param('id') id,
@Language() language: LanguageEnum,
@Param('id') id: string,
): Promise<IDocsResponse> {
const { customer_name, customer_id, user_id, username } = user;
@@ -375,8 +397,8 @@ export class CatalogController {
)
async updateDataAsset(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Param('id') id,
@Language() language: LanguageEnum,
@Param('id') data_asset_id: string,
@Body() body: IUpdateDataRequest,
): Promise<IOneDataAsset> {
const { customer_id, customer_name, user_id, username } = user;
@@ -390,7 +412,7 @@ export class CatalogController {
const result = await this.catalogService.updateOneDataAsset({
body,
data_asset_id: id,
data_asset_id,
customer_id,
metadata,
});
@@ -430,6 +452,7 @@ export class CatalogController {
return res;
}
@ApiInternalOnlyEndpoint()
@Put('data-asset/:id/manage-permissions')
async manageDataAssetPermissions(
@Param('id') id: string,
@@ -451,6 +474,7 @@ export class CatalogController {
return { data_asset: JSON.parse(response.data_asset) };
}
@ApiInternalOnlyEndpoint()
@Put('data-asset/:id/revoke-permissions')
async revokeDataAssetPermissions(
@Param('id') id: string,
@@ -561,10 +585,162 @@ export class CatalogController {
username,
});
const response = await this.catalogService.deleteComment(
{ data_asset_id: id, comment: body.comment },
{
data_asset_id: id,
comment: { ...body.comment, created_at: undefined, message: undefined },
},
metadata,
);
return response;
}
@Post('dataset-catalog-task')
@RequireAllPermissions(
PERMISSIONS_GROUPS.CATALOG.permissions.TRIGGER_CATALOG_TASK,
)
@ApiCreatedResponse({ type: TriggerCatalogRes })
async triggerCatalog(
@User() user: RequestUser,
@Body() body: TriggerCatalogReq,
) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const session = await this.catalogService.triggerCatalog(body, metadata);
return { session };
}
@Get('dataset-catalog-task/:session')
@RequireAllPermissions(
PERMISSIONS_GROUPS.CATALOG.permissions.TRIGGER_CATALOG_TASK,
)
@ApiOkResponse({ type: GetDatasetCatalogTaskRes })
async getCatalogTask(
@User() user: RequestUser,
@Param('session') session: string,
) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const response = await this.catalogService.getDatasetCatalogTask(
session,
metadata,
);
return response;
}
@Post('rls-rule')
@RequireAllPermissions(PERMISSIONS_GROUPS.CATALOG.permissions.DATA_MANAGER)
async addRlsRule(@User() user: RequestUser, @Body() body: AddRlsRuleRequest) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const response = await this.catalogService.addRlsRule(body, metadata);
return response;
}
@Get('rls-rule/:id')
@RequireAllPermissions(PERMISSIONS_GROUPS.CATALOG.permissions.DATA_MANAGER)
async getOneRlsRule(@Param('id') id: string, @User() user: RequestUser) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const idInt = parseInt(id);
const response = await this.catalogService.getOneRlsRule(idInt, metadata);
return response;
}
@Get('rls-rule')
@RequireAllPermissions(PERMISSIONS_GROUPS.CATALOG.permissions.DATA_MANAGER)
async getRlsRules(
@User() user: RequestUser,
@Query() query: GetRlsRulesRequest,
) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const response = await this.catalogService.getRlsRules(query, metadata);
return response;
}
@Delete('rls-rule/:id')
@RequireAllPermissions(PERMISSIONS_GROUPS.CATALOG.permissions.DATA_MANAGER)
async removeRlsRule(@Param('id') id: string, @User() user: RequestUser) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const idInt = parseInt(id);
const response = await this.catalogService.removeRlsRule(idInt, metadata);
return response;
}
@Delete('rls-rule')
@RequireAllPermissions(PERMISSIONS_GROUPS.CATALOG.permissions.DATA_MANAGER)
async batchRemoveRlsRules(
@Query() query: BatchRemoveRlsRulesRequest,
@User() user: RequestUser,
) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
await this.catalogService.batchRemoveRlsRule(query, metadata);
return { message: 'OK' };
}
@Get('nimbus-dashboards')
@RequireAllPermissions(PERMISSIONS_GROUPS.CATALOG.permissions.DATA_MANAGER)
async getNimbusDashboards(
@User() user: RequestUser,
@Body() body: GetNimbusDashboardsRequest,
) {
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
customer_name,
user_id,
username,
});
const dashboards = await this.catalogService.getNimbusDashboards(
body,
metadata,
);
return JSON.parse(dashboards);
}
}
+88 -1
View File
@@ -6,6 +6,7 @@ import {
Messages,
} from '@dadosfera/protospack-v2/dist/lib/Catalog';
import {
BadRequestException,
HttpException,
HttpStatus,
Inject,
@@ -18,7 +19,16 @@ import { CatalogClientConfiguration } from './catalog-client';
import { UsersService } from '../users/users.service';
import { RolesService } from '../roles/roles.service';
import { Metadata } from '@grpc/grpc-js';
import { IUpdateDataRequest } from './dtos';
import {
BatchRemoveRlsRulesRequest,
IUpdateDataRequest,
TriggerCatalogReq,
} from './dtos';
import {
AddRlsRuleRequest,
GetNimbusDashboardsRequest,
GetRlsRulesRequest,
} from '@dadosfera/protospack-v2/dist/lib/Catalog/interfaces/messages';
class CatalogService implements OnModuleInit {
catalogReadService: ReadService.CatalogReadServices;
@@ -333,6 +343,83 @@ class CatalogService implements OnModuleInit {
} as typeof data_asset;
});
}
async triggerCatalog(data: TriggerCatalogReq, metadata: Metadata) {
const { session } = await lastValueFrom(
this.catalogWriteService.TriggerDatasetCataloging(data, metadata),
);
return session;
}
async getDatasetCatalogTask(session: string, metadata: Metadata) {
const res = await lastValueFrom(
this.catalogReadService.GetDatasetCatalogTask({ session }, metadata),
);
return res;
}
async addRlsRule(data: AddRlsRuleRequest, metadata: Metadata) {
const res = await lastValueFrom(
this.catalogWriteService.AddRlsRule(data, metadata),
);
return res;
}
async removeRlsRule(id: number, metadata: Metadata) {
const res = await lastValueFrom(
this.catalogWriteService.RemoveRlsRule({ id }, metadata),
);
return res;
}
async batchRemoveRlsRule(
query: BatchRemoveRlsRulesRequest,
metadata: Metadata,
) {
const { id_rls, nimbus_dashboard_id } = query;
if (id_rls && nimbus_dashboard_id) {
throw new BadRequestException(
"You can't delete using both parameters. Choose either 'id_rls' or 'nimbus_dashboard_id'",
);
}
if (id_rls) {
await lastValueFrom(
this.catalogWriteService.RemoveRlsRulesByRlsId({ id_rls }, metadata),
);
} else if (nimbus_dashboard_id) {
await lastValueFrom(
this.catalogWriteService.RemoveRlsRulesByDashboardId(
{ nimbus_dashboard_id: parseInt(nimbus_dashboard_id) },
metadata,
),
);
}
return 'OK';
}
async getRlsRules(data: GetRlsRulesRequest, metadata: Metadata) {
const res = await lastValueFrom(
this.catalogReadService.GetRlsRules(data, metadata),
);
return res.rls_rules;
}
async getOneRlsRule(id: number, metadata: Metadata) {
const res = await lastValueFrom(
this.catalogReadService.GetOneRlsRule({ id }, metadata),
);
return res.rls_rule;
}
async getNimbusDashboards(
data: GetNimbusDashboardsRequest,
metadata: Metadata,
) {
const res = await lastValueFrom(
this.catalogReadService.GetNimbusDashboards(data, metadata),
);
return res.dashboards;
}
}
export { CatalogService };
+98 -2
View File
@@ -1,6 +1,15 @@
import { ApiProperty, ApiPropertyOptional } from '@nestjs/swagger';
import { ApiProperty, ApiPropertyOptional, PickType } from '@nestjs/swagger';
import { CreateDataAssetRequest } from '@dadosfera/protospack-v2/dist/lib/Catalog/interfaces/messages';
export enum DataAssetShareType {
none = 'none',
public = 'public',
private = 'private',
}
export enum OrderEnum {
asc = 'asc',
desc = 'desc',
}
export class EmbedObject {
@ApiProperty()
url: string;
@@ -87,6 +96,8 @@ export class IDataAsset {
comments: IComment[];
@ApiPropertyOptional()
embed?: EmbedObject;
@ApiPropertyOptional({ enum: DataAssetShareType })
share_type?: DataAssetShareType;
}
export class IOneDataAsset {
@@ -99,9 +110,43 @@ export class IMakeAComment {
message: string;
}
export class CommentToDelete extends PickType(IComment, ['id', 'username']) {}
export class IDeleteComment {
@ApiProperty()
comment: IComment;
comment: CommentToDelete;
}
export class ICatalogAllRequest {
@ApiPropertyOptional({
description: 'Texto usado para filtrar os ativos no catálogo.',
})
search;
@ApiPropertyOptional({
description: 'Número de registros a ser retornado',
maximum: 10000,
minimum: 1,
})
size: number;
@ApiPropertyOptional({
description: 'Usado para paginação, em conjunto com `size`',
minimum: 1,
})
page: number;
@ApiPropertyOptional({
description:
'Campo do data asset para usar na ordenação. Padrão: `created_at` ',
})
sort_by: string;
@ApiPropertyOptional({
enum: OrderEnum,
default: OrderEnum.asc,
description: 'Tipo de ordenação - `asc`: crescente; `desc`: decrescente ',
})
order?: OrderEnum;
}
export class ICatalogAllResponse {
@@ -135,6 +180,8 @@ export class IUpdateDataRequest {
tags: string[];
@ApiPropertyOptional()
embed: EmbedObject;
@ApiPropertyOptional({ enum: DataAssetShareType })
share_type?: DataAssetShareType;
}
export class ICreateDataAsset implements CreateDataAssetRequest {
@ApiProperty()
@@ -224,3 +271,52 @@ export class IColumnsMetadataResponse {
@ApiProperty({ type: [IColumnMetadata] })
columns_metadata: IColumnMetadata[];
}
export class TriggerCatalogReq {
@ApiProperty({
description: 'Name of the table on Snowflake',
example: 'TB__4DXSD4_TEST',
})
table_name: string;
@ApiPropertyOptional({
description:
'Schema where the asset is located. If not set defaults to "PUBLIC"',
})
table_schema?: string;
@ApiPropertyOptional({
description: 'Id of the pipeline that generated the asset.',
})
pipeline_id: string;
}
export class TriggerCatalogRes {
@ApiProperty()
session: string;
}
export class GetDatasetCatalogTaskRes {
@ApiProperty()
created_at: string;
@ApiProperty()
customer_name: string;
@ApiProperty()
session_id: string;
@ApiProperty()
status: string;
@ApiProperty()
table_name: string;
@ApiProperty()
updated_at: string;
@ApiProperty()
updated_by: string;
}
export class BatchRemoveRlsRulesRequest {
@ApiPropertyOptional()
nimbus_dashboard_id?: string;
@ApiPropertyOptional()
id_rls?: string;
}
@@ -6,14 +6,17 @@ import {
} from '@nestjs/microservices';
import { ConnectionTest } from '@dadosfera/protospack-v2';
const isLocalConnection =
process.env.INFACTORY_URL.startsWith('in-factory:') ||
process.env.INFACTORY_URL.includes('0.0.0.0');
export class ConnectionTestClientConfiguration {
private config: GrpcOptions = {
transport: Transport.GRPC,
options: {
url: process.env.INFACTORY_URL,
package: [ConnectionTest.ProtoPackages.ReadPackage],
credentials:
process.env.ENV === 'local' ? undefined : credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [ConnectionTest.ProtoPaths.ReadFilePath],
loader: {
keepCase: true,
@@ -9,7 +9,7 @@ import {
ValidationPipe,
} from '@nestjs/common';
import { ApiOkResponse, ApiTags } from '@nestjs/swagger';
import { User, RequestUser } from 'src/authentication/user.decorator';
import { User, RequestUser } from 'src/decorators/user.decorator';
import { ConnectionTestService } from './connection-test.service';
import {
ConnectionTestPingRes,
@@ -24,9 +24,11 @@ import {
GetTableMetadataReq,
} from './dto/connection-test';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { Authenticated } from 'src/authentication/authentication.decorator';
import { Authenticated } from 'src/decorators/authentication.decorator';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
@ApiInternalOnlyController()
@ApiTags('Connection Test')
@Controller('connection-test')
@UseFilters(new GrpcToHttpExceptionFilter())
@@ -19,7 +19,7 @@ import {
CreateConnectionDto,
DatabaseConnectionPropertiesDto,
} from '../connection/dtos/connection';
import { RequestUser } from 'src/authentication/user.decorator';
import { RequestUser } from 'src/decorators/user.decorator';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
@Injectable()
+5 -4
View File
@@ -6,6 +6,10 @@ import {
} from '@nestjs/microservices';
import { ConnectionManager } from '@dadosfera/protospack-v2';
const isLocalConnection =
process.env.INFACTORY_URL.startsWith('in-factory:') ||
process.env.INFACTORY_URL.includes('0.0.0.0');
export class ConnectionClientConfiguration {
public name = 'ConnectionClientConfiguration';
private config: GrpcOptions = {
@@ -16,10 +20,7 @@ export class ConnectionClientConfiguration {
ConnectionManager.ProtoPackages.WritePackage,
ConnectionManager.ProtoPackages.ReadPackage,
],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [
ConnectionManager.ProtoPaths.WriteFilePath,
ConnectionManager.ProtoPaths.ReadFilePath,
+14 -13
View File
@@ -7,34 +7,36 @@ import {
Param,
Delete,
Get,
Headers,
Query,
UseFilters,
} from '@nestjs/common';
import { ApiBearerAuth, ApiTags } from '@nestjs/swagger';
import { ApiExcludeEndpoint, ApiTags } from '@nestjs/swagger';
import { ConnectionClientService } from './client.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import {
Authenticated,
RequireAllPermissions,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { ValidationPipe } from '../../pipes/object-validation.pipe';
import {
ConnectionDetailsRes,
ConnectionRes,
ConnectionsRes,
GetAllConnectionsReq,
UpdateConnectionDto,
} from './dtos/connection';
import { CreateConnectionDto } from './dtos/connection';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { Language } from 'src/decorators/language.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
const connectionPermissions = PERMISSIONS_GROUPS.CONNECTION.permissions;
@UseFilters(new GrpcToHttpExceptionFilter())
@ApiTags('connections')
@ApiBearerAuth()
@Authenticated()
@Controller('connections')
export class ConnectionController {
@@ -47,7 +49,9 @@ export class ConnectionController {
this.logger = dadosferaLogger.logger;
}
@ApiInternalOnlyEndpoint()
@Get('connections-migration')
@ApiExcludeEndpoint()
@RequireAllPermissions(
PERMISSIONS_GROUPS.DADOSFERA.permissions.CONNECTIONS_MIGRATION,
)
@@ -83,12 +87,11 @@ export class ConnectionController {
@RequireAllPermissions(connectionPermissions.CREATE)
async updateConnection(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language: string,
@Language() language: LanguageEnum,
@Param('id') id: string,
@Body(new ValidationPipe()) body: UpdateConnectionDto,
): Promise<ConnectionRes> {
this.logger.info('/connections - Update Connection');
if (!language) language = 'en-us';
const { user_id, customer_id, customer_name, username } = user;
const metadata = PackTheMetadata({
@@ -135,11 +138,10 @@ export class ConnectionController {
@Get()
async getAllConnections(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Query() queries,
@Language() language: LanguageEnum,
@Query() queries: GetAllConnectionsReq,
): Promise<ConnectionsRes> {
this.logger.info('/connections - Get All Connection');
if (!language) language = 'en-us';
const { user_id, customer_id, customer_name, username } = user;
const { search, size, page, ...filters } = queries;
@@ -161,13 +163,12 @@ export class ConnectionController {
@Get('/:id')
async getConnectionDetails(
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@User() user: RequestUser,
@Param('id') id,
@Param('id') id: string,
@Query() queries,
): Promise<ConnectionDetailsRes> {
this.logger.info('/connections - Get Connection Details');
if (!language) language = 'en-us';
console.log(queries);
+14 -2
View File
@@ -9,6 +9,7 @@ import {
ConnectionToCatalog,
} from '@dadosfera/protospack-v2/dist/lib/ConnectionManager/interfaces/entities';
import {
GetAllConnectionRequest,
GetAllConnectionResponse,
GetConnectionDetailsResponse,
GetConnectionResponse,
@@ -21,7 +22,7 @@ export type ConnectionCredentialsType =
| 'oauth'
| 'api_key'
| 'service_account'
| 'headers_authF';
| 'headers_auth';
export interface ConnectionApiConnection {
config_id: string;
plugin: string;
@@ -94,7 +95,6 @@ export class ConnectionDto implements Connection {
export class ConnectionToCatalogDto implements ConnectionToCatalog {
// ---Automatically generated information - will not be sent by the frontend--- //
id: string;
customer_id: string;
updated_at: string;
created_at: string;
@@ -104,6 +104,9 @@ export class ConnectionToCatalogDto implements ConnectionToCatalog {
customer_name: string;
// ---Information sent by the frontend--- //
@ApiPropertyOptional()
id: string;
@ApiProperty()
name: string;
@@ -147,6 +150,15 @@ export class UpdateConnectionDto extends PickType(ConnectionDto, [
'properties',
]) {}
export class GetAllConnectionsReq implements GetAllConnectionRequest {
@ApiPropertyOptional()
search?: string;
@ApiPropertyOptional()
page?: string;
@ApiPropertyOptional()
size?: string;
}
export class ConnectionsRes implements GetAllConnectionResponse {
@ApiProperty({ type: [ConnectionToCatalogDto] })
connections: ConnectionToCatalogDto[];
+5 -4
View File
@@ -6,6 +6,10 @@ import {
} from '@nestjs/microservices';
import { ConnectorManager } from '@dadosfera/protospack-v2';
const isLocalConnection =
process.env.INFACTORY_URL.startsWith('in-factory:') ||
process.env.INFACTORY_URL.includes('0.0.0.0');
export class ConnectorClientConfiguration {
public name = 'ConnectorClientConfiguration';
private config: GrpcOptions = {
@@ -16,10 +20,7 @@ export class ConnectorClientConfiguration {
ConnectorManager.ProtoPackages.WritePackage,
ConnectorManager.ProtoPackages.ReadPackage,
],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [
ConnectorManager.ProtoPaths.WriteFilePath,
ConnectorManager.ProtoPaths.ReadFilePath,
+12 -17
View File
@@ -11,11 +11,10 @@ import {
UploadedFile,
UseInterceptors,
Inject,
Headers,
UploadedFiles,
} from '@nestjs/common';
import { FileInterceptor, FilesInterceptor } from '@nestjs/platform-express';
import { ApiBearerAuth, ApiConsumes, ApiTags } from '@nestjs/swagger';
import { ApiConsumes, ApiTags } from '@nestjs/swagger';
import { ConnectorClientService } from './client.service';
import { AddTagDto } from './dtos/add-tag';
import { CreateConnectorDto } from './dtos/create-connector';
@@ -27,11 +26,14 @@ import {
Authenticated,
RequireAllPermissions,
RequireSomePermission,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import { Language } from 'src/decorators/language.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
@ApiInternalOnlyController()
@ApiTags('connectors')
@ApiBearerAuth()
@Authenticated()
@Controller('connectors')
export class ConnectorController {
@@ -98,11 +100,10 @@ export class ConnectorController {
PERMISSIONS_GROUPS.PIPELINE.permissions.DELETE,
)
async getAllConnectors(
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
@Query() queries: GetAllDto,
) {
this.logger.info('/GET - getAllConnectors Route');
if (!language) language = 'en-us';
const { search, size, page, ...filters } = queries;
@@ -143,12 +144,11 @@ export class ConnectorController {
PERMISSIONS_GROUPS.PIPELINE.permissions.DELETE,
)
async getConnector(
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
@Param('plugin') plugin: string,
@Query('version') version: string,
) {
this.logger.info('/GET/:plugin - getConnector Route');
if (!language) language = 'en-us';
const pluginId = `${plugin}-${version}`;
@@ -172,13 +172,11 @@ export class ConnectorController {
PERMISSIONS_GROUPS.PIPELINE.permissions.DELETE,
)
async getConnectorDetails(
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
@Param('plugin') plugin: string,
@Query('version') version: string,
) {
this.logger.info('/upload - Upload Connector Route');
if (!language) language = 'en-us';
const pluginId = `${plugin}-${version}`;
const response: any = await this.connectorClientService.getConnectorDetails(
@@ -275,16 +273,13 @@ export class ConnectorController {
@Param('plugin') plugin: string,
@Query('version') version: string,
) {
this.logger.info('/upload - Upload Connector Route');
this.logger.info('DELETE /:plugin - Delete Connector Route');
const response: any = await this.connectorClientService.deleteConnector(
const response = await this.connectorClientService.deleteConnector(
plugin,
version,
);
return {
message: response.message || 'ok',
connector: { ...JSON.parse(response.connector) },
};
return { message: response.message, connector: response.connector };
}
}
@@ -0,0 +1,93 @@
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { IdResponse } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/messages';
import {
Body,
Controller,
Get,
HttpCode,
HttpStatus,
Inject,
Param,
Put,
Query,
UseFilters,
} from '@nestjs/common';
import { ApiOkResponse, ApiProduces, ApiTags } from '@nestjs/swagger';
import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import {
Authenticated,
RequireAllPermissions,
} from 'src/decorators/authentication.decorator';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { CustomersService } from './customers.service';
import { CustomerLinkRequest, CustomerLinksResponse } from './dtos/customers';
import { RequestUser, User } from 'src/decorators/user.decorator';
import type { StringValue } from 'ms';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
@ApiTags('Customers')
@Controller('customers')
@Authenticated()
@UseFilters(GrpcToHttpExceptionFilter)
export class CustomersController {
logger: DadosferaLogger;
constructor(
@Inject(DadosferaLogger)
dadosferaLogger: DadosferaLogger,
private customersService: CustomersService,
) {
this.logger = dadosferaLogger.logger;
}
@Get(':id/links')
@ApiOkResponse({ type: CustomerLinksResponse })
async getCustomerLinks(@Param('id') id: string) {
this.logger.info('getCustomerLinks', { id });
const links = await this.customersService.getLinks(id);
return { links };
}
@Put(':id/links')
@RequireAllPermissions(PERMISSIONS_GROUPS.USERS.permissions.ADMIN)
@ApiOkResponse()
@HttpCode(HttpStatus.OK)
async setCustomerLinks(
@Body() body: CustomerLinkRequest,
@Param('id') id: string,
) {
const { links } = body;
this.logger.info('setCustomerLinks', { id, links });
await this.customersService.setLinks(id, links);
}
@Get('token')
@RequireAllPermissions(PERMISSIONS_GROUPS.AUTH.permissions.GENERATE_TOKEN)
@ApiProduces('text/plain')
async getCustomerToken(
@Query('exp') exp: StringValue,
@User() user: RequestUser,
): Promise<string> {
this.logger.info('getCustomerToken', { exp, user });
const data = {
customerId: user.customer_id,
userId: user.user_id,
customerName: user.customer_name,
};
return this.customersService.generateToken(exp, data);
}
@Get('monitoring-dashboard')
@RequireAllPermissions(
PERMISSIONS_GROUPS.CUSTOMER.permissions.MONITORING_DASHBOARD,
)
async getCustomerMonitoringDashboard(
@User() user: RequestUser,
): Promise<{ url: string }> {
this.logger.info('getCustomerMonitoringDashboard');
const metadata = PackTheMetadata(user);
return this.customersService.getMonitoringDashboardUrl(metadata);
}
}
+23
View File
@@ -0,0 +1,23 @@
import { Module } from '@nestjs/common';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { ClientsModule } from '@nestjs/microservices';
import { DucClient } from '../duc/client.config';
import { CustomersController } from './customers.controller';
import { CustomersService } from './customers.service';
import { PipelinesClientConfiguration } from '../pipelinesV2/pipelines-client';
const ducClient = new DucClient();
const piFactoryClient = new PipelinesClientConfiguration();
@Module({
imports: [
ClientsModule.register([
ducClient.providerOptions,
piFactoryClient.providerOptions,
]),
],
controllers: [CustomersController],
providers: [CustomersService, DadosferaLogger],
exports: [CustomersService],
})
export class CustomersModule {}
+154
View File
@@ -0,0 +1,154 @@
import {
OnModuleInit,
Inject,
Injectable,
HttpException,
HttpStatus,
InternalServerErrorException,
} from '@nestjs/common';
import { firstValueFrom, lastValueFrom } from 'rxjs';
import { Link } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/entities';
import { DucClient } from '../duc/client.config';
import { ClientGrpc } from '@nestjs/microservices';
import { ProtoServices } from '@dadosfera/protospack-v2/dist/lib/Duc';
import { CustomerUpdateRequest } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/messages';
import { CustomersProtoService } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/write-service';
import ErrorCodes from 'src/utils/errorCodes';
import jwt from 'jsonwebtoken';
import {
GetSecretValueCommand,
SecretsManagerClient,
} from '@aws-sdk/client-secrets-manager';
import getEnv from 'src/utils/getEnv';
import { logger } from 'elastic-apm-node';
import {
ReadService,
ProtoServices as PipelineProtoServices,
} from '@dadosfera/protospack-v2/dist/lib/PipelineV2';
import { Metadata } from '@grpc/grpc-js';
import { PipelinesClientConfiguration } from '../pipelinesV2/pipelines-client';
// This function will accept any string, which may result in a bug.
@Injectable()
export class CustomersService implements OnModuleInit {
private customerService: CustomersProtoService;
private pipelineReadService: ReadService.PipelineV2ReadService;
constructor(
@Inject(DucClient.name) private readonly grpcClient: ClientGrpc,
@Inject(PipelinesClientConfiguration.name)
private readonly pipelinesGrpcClient: ClientGrpc,
) {}
onModuleInit() {
this.customerService = this.grpcClient.getService<CustomersProtoService>(
ProtoServices.CustomersProtoService,
);
this.pipelineReadService =
this.pipelinesGrpcClient.getService<ReadService.PipelineV2ReadService>(
PipelineProtoServices.PipelineV2ReadService,
);
}
async getLinks(customerId: string) {
try {
const result = await lastValueFrom(
this.customerService.CustomerFindOneById({ id: customerId }),
);
return result.customer?.links || [];
} catch (err) {
if (err.details === ErrorCodes.CUSTOMER.NOT_FOUND)
throw new HttpException(err.details, HttpStatus.NOT_FOUND);
throw err;
}
}
async setLinks(customerId: string, links: Link[]) {
if (!customerId || !links) {
throw new HttpException(null, HttpStatus.BAD_REQUEST);
}
try {
return await firstValueFrom(
this.customerService.CustomerUpdate({
id: customerId,
links,
} as CustomerUpdateRequest),
);
} catch (err) {
if (err.details === ErrorCodes.CUSTOMER.NOT_FOUND)
throw new HttpException(err.details, HttpStatus.NOT_FOUND);
else throw err;
}
}
async generateToken(
expiresIn = '30m',
data: { customerId: string; userId: string; customerName: string },
) {
const { customerId, userId: generatedById, customerName } = data;
const secretsManagerClient = new SecretsManagerClient({});
const getSecretComand = new GetSecretValueCommand({
SecretId: `${getEnv()}/${customerName}/jwt-signing-key`,
});
let private_key_pem;
await secretsManagerClient
.send(getSecretComand)
.then((res) => {
const secret = JSON.parse(res.SecretString);
private_key_pem = secret.private_key_pem;
})
.catch((err) => {
logger.error(err.stack);
throw new InternalServerErrorException(
'Error finding keys for customer',
);
});
let jwt_token;
try {
jwt_token = jwt.sign(
{
customerId,
generatedById,
},
private_key_pem,
{
algorithm: 'RS256',
expiresIn,
issuer: 'maestro',
},
);
} catch (err) {
logger.error(err.stack);
throw new InternalServerErrorException('Error generating token');
}
// const verify = jwt.verify(jwt_token, public_key_pem, {
// algorithms: ['RS256'],
// issuer: 'maestro',
// });
// const decoded = jwt.decode(jwt_token, { complete: true });
return jwt_token;
}
async getMonitoringDashboardUrl(metadata: Metadata) {
logger.info('CustomersService - getMonitoringDashboardUrl');
const res = await lastValueFrom(
this.pipelineReadService.PipelineV2GetDashboardUrl(
{
dashboard_id: '45',
exp: '15m',
metabase_customer_name: 'dadosferatech',
},
metadata,
),
);
logger.info('Done');
return res;
}
}
+22
View File
@@ -0,0 +1,22 @@
import { Link } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/entities';
import { ApiProperty, ApiPropertyOptional } from '@nestjs/swagger';
export class CustomerLink implements Link {
@ApiProperty()
href: string;
@ApiProperty()
name: string;
@ApiProperty()
description: string;
@ApiPropertyOptional()
iconSrc: string;
}
export class CustomerLinkRequest {
@ApiProperty({ type: [CustomerLink] })
links: CustomerLink[];
}
export class CustomerLinksResponse {
@ApiProperty({ type: [CustomerLink] })
links: CustomerLink[];
}
+5 -4
View File
@@ -9,6 +9,10 @@ import {
ProtoPaths,
} from '@dadosfera/protospack-v2/dist/lib/Duc';
const isLocalConnection =
process.env.DUC_URL.startsWith('duc:') ||
process.env.DUC_URL.includes('0.0.0.0');
export class DucClient {
public name = 'DucClient';
@@ -17,10 +21,7 @@ export class DucClient {
options: {
url: process.env.DUC_URL,
package: [ProtoPackages.WritePackage, ProtoPackages.ReadPackage],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [ProtoPaths.WriteFilePath, ProtoPaths.ReadFilePath],
loader: {
keepCase: true,
+1 -1
View File
@@ -1,4 +1,4 @@
import { Info } from 'protospack/dist/lib/interfaces';
import { Info } from '@dadosfera/protospack/dist/lib/interfaces';
interface Values {
jdbc_user: string;
+5 -5
View File
@@ -2,10 +2,13 @@ import { Input } from '@dadosfera/protospack-v2';
import { credentials } from '@grpc/grpc-js';
import {
ClientProviderOptions,
GrpcOptions,
Transport,
type GrpcOptions,
} from '@nestjs/microservices';
const isLocalConnection =
process.env.INFACTORY_URL.startsWith('in-factory:') ||
process.env.INFACTORY_URL.includes('0.0.0.0');
export class InputsGrpcClient {
public readonly name = 'InputsGrpcClient';
private config: GrpcOptions = {
@@ -16,10 +19,7 @@ export class InputsGrpcClient {
Input.ProtoPackages.WritePackage,
Input.ProtoPackages.ReadPackage,
],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [
Input.ProtoPaths.WriteFilePath,
Input.ProtoPaths.ReadFilePath,
+8 -4
View File
@@ -12,7 +12,7 @@ import {
import { InputsService } from './inputs.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { PERMISSIONS_GROUPS } from '../../authentication/permissions.enum';
import { AuthenticateCondition } from 'src/authentication/authentication.decorator';
import { AuthenticateCondition } from 'src/decorators/authentication.decorator';
import { ApiOkResponse, ApiTags } from '@nestjs/swagger';
import {
CreateInputReq,
@@ -21,9 +21,10 @@ import {
Input,
} from './dtos/input.model';
import { UpdateInputRequest } from './dtos/old_interfaces';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { Info } from '@dadosfera/protospack-v2/dist/lib/Input/interfaces/entities';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
@ApiTags('Inputs')
@Controller('inputs')
@@ -66,6 +67,7 @@ export class InputsController {
this.logger = dadosferaLogger.logger;
}
@ApiInternalOnlyEndpoint()
@Get('available-entities/:plugin')
@ApiOkResponse({ type: GetAvailableEntitiesRes })
async getAvailableEntities(
@@ -102,6 +104,7 @@ export class InputsController {
return response;
}
@ApiInternalOnlyEndpoint()
@Get()
async findAll(@User() user: RequestUser) {
const { user_id, customer_id, customer_name: customer } = user;
@@ -120,8 +123,7 @@ export class InputsController {
}
@Get('/:id')
async findOne(@Body() body, @Param() params) {
const { id } = params;
async findOne(@Body() body, @Param('id') id: string) {
this.logger.info(`/input/${id} - ON FIND ONE ROUTE`, {
user: body.info.user_id,
customer: body.info.customer,
@@ -132,6 +134,7 @@ export class InputsController {
return response;
}
@ApiInternalOnlyEndpoint()
@Patch(':id')
async update(@Body() updateInputDto: UpdateInputRequest, @Param() params) {
const { id } = params;
@@ -147,6 +150,7 @@ export class InputsController {
return response;
}
@ApiInternalOnlyEndpoint()
@Delete(':id')
async delete(@Body() data, @Param() params) {
const { id } = params;
-2
View File
@@ -5,7 +5,6 @@ import {
Inject,
Injectable,
} from '@nestjs/common';
import { Timeout } from '@nestjs/schedule';
import CronParser, { CronExpression } from 'cron-parser';
import { ClientGrpc } from '@nestjs/microservices';
import DadosferaLogger from '@dadosfera/dadosfera-logs/dist';
@@ -222,7 +221,6 @@ export class InputsService {
return lastValueFrom(this.inputWriteService.InputRemove(idRequest));
}
@Timeout(60000 * 10) // Timeout set for 10 minutes
async testConnection(data) {
try {
const testConnectionInputResponse =
+64 -4
View File
@@ -1,8 +1,10 @@
import { Body, Controller, Inject, Param, Post } from '@nestjs/common';
import { init } from 'mixpanel';
import { Authenticated } from 'src/authentication/authentication.decorator';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { Authenticated } from 'src/decorators/authentication.decorator';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
@ApiInternalOnlyController()
@Authenticated()
@Controller('trackEvent')
export class MixpanelController {
@@ -15,9 +17,55 @@ export class MixpanelController {
delete body.info;
const mixpanel = init(this.mixpanelToken);
const separator = user.username.includes('-') ? '-' : '.';
const removeValues = [
'.dadosferatech.dadosfera',
'.demo.dadosfera',
'.dadosferademo',
'.dadosferarh.dadosfera',
'.dadosferatech.dadosfera2',
'.dadosferatech.dadosfera',
'.dadosfera.fin',
'.dadosferafin.dadosfera',
'.praxio.dadosfera',
'.dadosfera.tech',
'.treinamentos@dadosfera.ai',
'.dadosfera2',
'.treinamentosfera',
'.dadosfera',
];
let username = user.username;
removeValues.forEach((value) => {
username = username.replace(value, '');
});
username = username.split('@')?.[0];
username = username.split('+')?.[0];
let firstName = username
.substring(0, username.indexOf(separator))
.replace('dadosfera', '');
let lastName = username
.substring(username.lastIndexOf(separator) + 1)
.replace('dadosfera', '');
if (!firstName) {
firstName = lastName;
lastName = '';
}
firstName = this.capitalize(firstName);
lastName = this.capitalize(lastName);
await mixpanel.people.set(user.username, {
$name: user.username,
$email: user.username,
$first_name: firstName,
$last_name: lastName,
$name: this.getFullName(firstName, lastName),
$email: user.username.includes('@')
? user.username
: user.username + '@dadosfera.ai',
customer_name: user.customer_name,
});
@@ -30,4 +78,16 @@ export class MixpanelController {
return { id, body, user: user.username };
}
capitalize(sentence: string): string {
if (!sentence) {
return '';
}
return sentence[0].toUpperCase() + sentence.substring(1);
}
getFullName(firstName: string, lastName: string) {
return `${firstName}${lastName ? ' ' + lastName : ''}`;
}
}
+2 -2
View File
@@ -1,5 +1,5 @@
import { Module } from '@nestjs/common';
import { getSecreteFromSecreteManager } from 'src/utils/SecretManager';
import { getSecretFromSecretsManager } from 'src/utils/SecretManager';
import { MixpanelController } from './mixpanel.controller';
@Module({
@@ -7,7 +7,7 @@ import { MixpanelController } from './mixpanel.controller';
providers: [
{
provide: 'MIXPANEL_TOKEN',
useValue: getSecreteFromSecreteManager(
useValue: getSecretFromSecretsManager(
`${process.env.ENV}/root/mixpanel_token`,
),
},
@@ -6,6 +6,10 @@ import {
} from '@nestjs/microservices';
import { NetworkConfig } from '@dadosfera/protospack-v2';
const isLocalConnection =
process.env.INFACTORY_URL.startsWith('in-factory:') ||
process.env.INFACTORY_URL.includes('0.0.0.0');
export class NetworkConfigGrpcClient {
public name = 'NetworkConfigGrpcClient';
@@ -17,8 +21,7 @@ export class NetworkConfigGrpcClient {
NetworkConfig.ProtoPackages.ReadPackage,
NetworkConfig.ProtoPackages.WritePackage,
],
credentials:
process.env.ENV === 'local' ? undefined : credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [
NetworkConfig.ProtoPaths.ReadFilePath,
NetworkConfig.ProtoPaths.WriteFilePath,
@@ -1,12 +1,9 @@
import {
Body,
Controller,
Delete,
Get,
Headers,
Inject,
Param,
Patch,
Post,
Query,
UploadedFile,
@@ -15,7 +12,7 @@ import {
import { NetworkConfigService } from './network-config.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { ApiConsumes, ApiOkResponse, ApiTags } from '@nestjs/swagger';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import {
CreateNetworkConfigReq,
CreateNetworkConfigRes,
@@ -26,7 +23,9 @@ import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import {
Authenticated,
RequireAllPermissions,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { Language } from 'src/decorators/language.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
const networkConfigPermissions = PERMISSIONS_GROUPS.NETWORK_CONFIG.permissions;
@ApiTags('Network Config')
@@ -40,18 +39,18 @@ export class NetworkConfigController {
) {
this.logger = dadosferaLogger.logger;
}
@Get()
@ApiOkResponse({ type: FindAllNetworkConfigsRes })
async findAllNetworkConfigs(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@Query() queries,
) {
this.logger.info('GET /network-config', {
user: user.user_id,
customer: user.customer_name,
});
if (!language) language = 'en-us';
const { user_id, customer_id, customer_name } = user;
const { search, size, page, ...filters } = queries;
@@ -79,14 +78,14 @@ export class NetworkConfigController {
@ApiOkResponse({ type: FindAllNetworkConfigsRes })
async findNetworkConfigByIdDetails(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@Param('id') id: string,
) {
this.logger.info('GET /network-config/:id', {
user: user.user_id,
customer: user.customer_name,
});
if (!language) language = 'en-us';
return this.networkConfigService.findNetworkConfigByIdDetails(id, {
customer_name: user.customer_name,
customer_id: user.customer_id,
+17 -5
View File
@@ -5,6 +5,7 @@ import { ConnectionClientService } from '../connection/client.service';
import jwt from 'jsonwebtoken';
import DadosferaLogger from '@dadosfera/dadosfera-logs/dist';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
@ApiTags('oauth')
@Controller('oauth')
export class OauthController {
@@ -15,7 +16,6 @@ export class OauthController {
private logger: DadosferaLogger,
) {
switch (process.env.ENV) {
case 'dev':
case 'stg':
this.redirectUrl = `https://app.${process.env.ENV}.dadosfera.ai/collect/auth-callback`;
break;
@@ -32,6 +32,7 @@ export class OauthController {
return true;
}
@ApiInternalOnlyEndpoint()
@Get('hubspot/callback')
@UseGuards(AuthGuard('hubspot'))
@Redirect()
@@ -45,6 +46,7 @@ export class OauthController {
return true;
}
@ApiInternalOnlyEndpoint()
@Get('googleads/callback')
@UseGuards(AuthGuard('google'))
@Redirect()
@@ -58,6 +60,7 @@ export class OauthController {
return true;
}
@ApiInternalOnlyEndpoint()
@Get('google-sheets/callback')
@UseGuards(AuthGuard('google'))
@Redirect()
@@ -71,6 +74,7 @@ export class OauthController {
return true;
}
@ApiInternalOnlyEndpoint()
@Get('facebook/callback')
@UseGuards(AuthGuard('facebook'))
@Redirect()
@@ -84,6 +88,7 @@ export class OauthController {
return true;
}
@ApiInternalOnlyEndpoint()
@Get('mailchimp/callback')
@UseGuards(AuthGuard('mailchimp'))
@Redirect()
@@ -97,6 +102,7 @@ export class OauthController {
return true;
}
@ApiInternalOnlyEndpoint()
@Get('salesforce/callback')
@UseGuards(AuthGuard('salesforce'))
@Redirect()
@@ -148,10 +154,16 @@ export class OauthController {
const { customer_id, customer_name, user_id } = connectionInfo;
try {
const response = await this.connectionService.createConnection(
connectionInfo,
PackTheMetadata({ customer_id, customer_name, user_id }),
);
const response = connectionInfo.id
? await this.connectionService.updateConnection(
connectionInfo.id,
connectionInfo,
PackTheMetadata({ customer_id, customer_name, user_id }),
)
: await this.connectionService.createConnection(
connectionInfo,
PackTheMetadata({ customer_id, customer_name, user_id }),
);
url.searchParams.set('connection_id', response.connection.id);
return { url: url.href };
} catch (error) {
+2
View File
@@ -23,6 +23,7 @@ export class OauthService {
user_id,
customer_id,
customer_name,
id,
} = query;
const properties = { plugin, credentials_type: 'oauth' };
@@ -45,6 +46,7 @@ export class OauthService {
type,
properties,
plugin,
id,
};
return jwt.sign({ ...newConnection }, process.env.JWT_PRIVATE_KEY);
}
@@ -44,7 +44,8 @@ export class FacebookStrategy extends PassportStrategy(Strategy) {
req,
'application',
);
options.scope = 'ads_read ads_management';
options.scope =
'pages_show_list ads_read pages_read_engagement ads_management';
super.authenticate(req, options);
}
}
@@ -29,7 +29,6 @@ export class GoogleStrategy extends PassportStrategy(Strategy, 'google') {
super(options, verify);
switch (process.env.ENV) {
case 'dev':
case 'stg':
this.redirect_uri = `https://maestro.${process.env.ENV}.dadosfera.ai/oauth`;
break;
@@ -17,7 +17,7 @@ export class HubspotStrategy extends PassportStrategy(Strategy) {
clientSecret: oauthSecrets.hubspot.client_secret,
callbackURL: oauthSecrets.hubspot.redirect_uri,
scope:
'automation business-intelligence oauth forms integration-sync sales-email-read crm.lists.read crm.objects.contacts.read crm.schemas.contacts.read crm.objects.companies.read crm.objects.deals.read crm.schemas.companies.read crm.schemas.deals.read crm.objects.owners.read crm.objects.quotes.read crm.schemas.quotes.read crm.objects.line_items.read crm.schemas.line_items.read',
'tickets automation business-intelligence oauth forms integration-sync sales-email-read crm.lists.read crm.objects.contacts.read crm.schemas.contacts.read crm.objects.companies.read crm.objects.deals.read crm.schemas.companies.read crm.schemas.deals.read crm.objects.owners.read crm.objects.quotes.read crm.schemas.quotes.read crm.objects.line_items.read crm.schemas.line_items.read',
passReqToCallback: true,
},
(accessToken, refreshToken, tokenInfo, profile, done) => {
@@ -1,13 +1,16 @@
import { Controller, Get, Headers, Inject } from '@nestjs/common';
import { Controller, Get, Inject } from '@nestjs/common';
import { ApiHeader, ApiOkResponse, ApiTags } from '@nestjs/swagger';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { Authenticated } from 'src/authentication/authentication.decorator';
import { Authenticated } from 'src/decorators/authentication.decorator';
import { PermissionUsages } from 'src/authentication/permissions.enum';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
import { GetPublicPermissionsRes } from './dto/entities';
import { PermissionsService } from './permissions.service';
import { Language } from 'src/decorators/language.decorator';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
@ApiInternalOnlyController()
@ApiTags('Permissions')
@Authenticated()
@Controller('permissions')
@@ -32,10 +35,10 @@ export class PermissionsController {
@ApiOkResponse({ type: GetPublicPermissionsRes })
getPublicPermissions(
@User() user: RequestUser,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('getPublicPermissions', { user });
if (!language) language = 'en-us';
const permissionGroups = this.permissionsService.getPermissionsGrouped(
PermissionUsages.PUBLIC,
language,
@@ -44,8 +44,11 @@ export class PermissionsService
);
}
// internally used to send permissions to duc on microservice startup
async onApplicationBootstrap() {
// Do not sent permissions if running local but pointing to a remote DUC url
if (process.env.ENV == 'local' && !process.env.DUC_URL.includes('0.0.0.0'))
return;
this.logger.info('sending permissions to DUC...');
const permissions = Object.values(PERMISSIONS_GROUPS).flatMap((namespace) =>
@@ -57,10 +60,10 @@ export class PermissionsService
}).catch((err: ErrorBuilder) => {
if (
err.code === 'No connection established' &&
(process.env.LOCAL_ENV === 'true' || process.env.ENV === 'local')
process.env.ENV === 'local'
) {
return this.logger.info(
"couldn't connect to DUC. suppresing in local env",
"couldn't connect to DUC. suppressing in local env",
);
}
+6 -2
View File
@@ -1,6 +1,9 @@
import { ConflictException, Inject, OnModuleInit } from '@nestjs/common';
import { ClientGrpc } from '@nestjs/microservices';
import { PipelineServicesNames, PipelinesServiceInterface } from 'protospack';
import {
PipelineServicesNames,
PipelinesServiceInterface,
} from '@dadosfera/protospack';
import { lastValueFrom } from 'rxjs';
import { IIdRequest } from './interfaces';
@@ -11,9 +14,10 @@ import { PipelinesClientConfiguration } from './pipelines-client';
export class PipelinesClientService implements OnModuleInit {
private pipelineService: PipelinesServiceInterface;
logger: DadosferaLogger;
constructor(
@Inject(DadosferaLogger)
dadosferaLogger: DadosferaLogger,
dadosferaLogger: DadosferaLogger,
@Inject(PipelinesClientConfiguration.name)
private readonly grpcClient: ClientGrpc,
) {
+1 -1
View File
@@ -1,4 +1,4 @@
import { Info } from 'protospack/dist/lib/interfaces';
import { Info } from '@dadosfera/protospack/dist/lib/interfaces';
export interface ICreatePipelineDto {
input: IdRequest;
+6 -5
View File
@@ -3,9 +3,13 @@ import {
GrpcOptions,
Transport,
} from '@nestjs/microservices';
import { PipelinePackages, PipelineProtoFilePath } from 'protospack';
import { PipelinePackages, PipelineProtoFilePath } from '@dadosfera/protospack';
import { credentials } from '@grpc/grpc-js';
const isLocalConnection =
process.env.PIFACTORY_URL.startsWith('pi-factory:') ||
process.env.PIFACTORY_URL.includes('0.0.0.0');
export class PipelinesClientConfiguration {
public name = 'PipelinesClientConfiguration';
private config: GrpcOptions = {
@@ -13,10 +17,7 @@ export class PipelinesClientConfiguration {
options: {
url: process.env.PIFACTORY_URL,
package: PipelinePackages,
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: PipelineProtoFilePath,
loader: {
keepCase: true,
+16 -6
View File
@@ -1,13 +1,15 @@
import { Body, Controller, Get, Inject, Param, Post } from '@nestjs/common';
import { ApiTags } from '@nestjs/swagger';
import { ApiOperation, ApiTags } from '@nestjs/swagger';
import {
AuthenticateCondition,
Authenticated,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { PERMISSIONS_GROUPS } from '../../authentication/permissions.enum';
import { PipelinesService } from './pipelines.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
@ApiInternalOnlyController()
@ApiTags('Pipelines')
@Controller('pipelines')
@Authenticated()
@@ -42,8 +44,12 @@ export class PipelinesController {
}
@Post('start/:id')
async activate(@Param() params, @Body() body) {
const { id } = params;
@ApiOperation({
deprecated: true,
description:
'This method is deprecated. Please use route /pipelinesV2/start/:id instead',
})
async activate(@Param('id') id: string, @Body() body) {
const { info } = body;
this.logger.info(
@@ -60,8 +66,12 @@ export class PipelinesController {
}
@Get(':id/status')
async getPipelineStatus(@Body() body, @Param() params) {
const { id } = params;
@ApiOperation({
deprecated: true,
description:
'This method is deprecated. Please use route /pipelinesV2/:id/status instead',
})
async getPipelineStatus(@Body() body, @Param('id') id: string) {
body.id = id;
this.logger.info(
+41 -4
View File
@@ -1,5 +1,5 @@
import { ApiProperty, ApiPropertyOptional, OmitType } from '@nestjs/swagger';
import { Info } from 'protospack/dist/lib/interfaces';
import { Info } from '@dadosfera/protospack/dist/lib/interfaces';
export class IPipelineV2 {
@ApiProperty()
@@ -10,6 +10,8 @@ export class IPipelineV2 {
@ApiProperty()
description: string;
@ApiProperty()
type: string;
@ApiProperty()
connection_id: string;
@ApiProperty()
cron: string;
@@ -67,13 +69,32 @@ export interface IGetPipelineLogsRequest {
details: string;
}
export class IUploadCSVFile {
@ApiProperty({ format: 'binary' })
file: string;
export class IInitUploadCSVFile {
@ApiProperty()
file_name: string;
@ApiProperty()
parts: number;
}
export class ICompleteUploadCSVFile {
@ApiProperty()
upload_id: string;
@ApiProperty()
file_name: string;
@ApiProperty()
parts: { ETag: string; PartNumber: number }[];
}
export class ICreatePipelineCSVFile {
@ApiProperty()
name: string;
@ApiProperty()
file_name: string;
@ApiProperty()
description: string;
@@ -85,4 +106,20 @@ export class IUploadCSVFile {
@ApiProperty()
header: boolean;
@ApiProperty()
engine: string;
}
export class PipelineFindAllReq {
@ApiPropertyOptional()
search?: string | undefined;
@ApiPropertyOptional()
filters?: string | undefined;
@ApiPropertyOptional()
size?: string | undefined;
@ApiPropertyOptional()
page?: string | undefined;
@ApiPropertyOptional()
type?: string | undefined;
}
+5 -4
View File
@@ -9,6 +9,10 @@ import {
} from '@dadosfera/protospack-v2/dist/lib/PipelineV2';
import { credentials } from '@grpc/grpc-js';
const isLocalConnection =
process.env.PIFACTORY_URL.startsWith('pi-factory:') ||
process.env.PIFACTORY_URL.includes('0.0.0.0');
export class PipelinesClientConfiguration {
public name = 'PipelinesClientConfiguration';
private config: GrpcOptions = {
@@ -16,10 +20,7 @@ export class PipelinesClientConfiguration {
options: {
url: process.env.PIFACTORY_URL,
package: [ProtoPackages.ReadPackage, ProtoPackages.WritePackage],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [ProtoPaths.ReadFilePath, ProtoPaths.WriteFilePath],
loader: {
keepCase: true,
+156 -83
View File
@@ -7,44 +7,50 @@ import {
Param,
Post,
Put,
Headers,
Query,
UseFilters,
HttpCode,
HttpStatus,
Patch,
UseInterceptors,
UploadedFile,
HttpException,
BadRequestException,
CacheTTL,
} from '@nestjs/common';
import {
ApiConsumes,
ApiCreatedResponse,
ApiHeaders,
ApiNoContentResponse,
ApiOperation,
ApiTags,
} from '@nestjs/swagger';
import {
AuthenticateCondition,
RequireAllPermissions,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { PERMISSIONS_GROUPS } from '../../authentication/permissions.enum';
import { PipelinesService } from './pipelines.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { Messages } from '@dadosfera/protospack-v2/dist/lib/PipelineV2';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
import { PipelinesService as OldPipelineService } from 'src/modules/pipelines/pipelines.service';
import {
ICompleteUploadCSVFile,
ICreatePipelineCSVFile,
ICreatePipelineV2Req,
IPipelineV2,
IUploadCSVFile,
IInitUploadCSVFile,
PipelineFindAllReq,
} from './interfaces';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { FileInterceptor } from '@nestjs/platform-express';
import { LanguageEnum } from 'src/utils/languages.enum';
import { Language } from 'src/decorators/language.decorator';
import { ApiInternalOnlyEndpoint } from 'src/decorators/swagger.decorator';
@UseFilters(new GrpcToHttpExceptionFilter())
@ApiTags('PipelinesV2')
@ApiHeaders([{ name: 'dadosfera-lang', enum: LanguageEnum, required: false }])
@UseFilters(new GrpcToHttpExceptionFilter())
@Controller('pipelinesV2')
@AuthenticateCondition((req, user) => {
let action;
@@ -81,15 +87,27 @@ export class PipelinesController {
this.logger = dadosferaLogger.logger;
}
@Get('monitoring-dashboard')
async getMonitoringDashboard(@User() user: RequestUser) {
this.logger.info('PipelinesController - getMonitoringDashboard', { user });
const metadata = PackTheMetadata(user);
const response =
await this.pipelinesClientService.getMonitoringDashboardUrl(metadata);
return response;
}
@Post()
@ApiCreatedResponse({ type: IPipelineV2 })
async create(
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@User() user: RequestUser,
@Body() createPipelineDto: ICreatePipelineV2Req,
) {
this.logger.info('PipelinesController - create', { user });
if (!language) language = 'en-us';
const { customer_id, customer_name, username, user_id } = user;
const metadata = PackTheMetadata({
customer_id,
@@ -110,13 +128,11 @@ export class PipelinesController {
@Get()
async findAll(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Query() data,
@Language() language: LanguageEnum,
@Query() data: PipelineFindAllReq,
) {
this.logger.info('PipelinesController - findAll', { user });
if (!language) language = 'en-us';
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
customer_id,
@@ -136,16 +152,13 @@ export class PipelinesController {
@Get('/download-logs')
async downloadLogs(
@User() user: RequestUser,
@Headers('Dadosfera-Lang') language,
@Query() query,
@Language() language: LanguageEnum,
@Query('pipeline_run_id') pipeline_run_id: string,
) {
this.logger.info('PipelinesController - downloadLogs', { user });
if (!language) language = 'en-us';
if (!query) {
throw new HttpException('Query params not provided', 400);
}
if (!pipeline_run_id)
throw new BadRequestException('Missing pipeline_run_id');
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
@@ -157,7 +170,7 @@ export class PipelinesController {
});
const url = await this.pipelinesClientService.downloadLogs(
query.pipeline_run_id,
pipeline_run_id,
metadata,
);
@@ -168,42 +181,51 @@ export class PipelinesController {
@Get(':id/config')
async getPipelineproperties(
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@User() user: RequestUser,
@Param('id') id,
@Param('id') id: string,
) {
this.logger.info('PipelinesController - getPipelineproperties', { user });
const metadata = PackTheMetadata({
...user,
language: language || 'pt-br',
});
const metadata = PackTheMetadata({ ...user, language: language });
return this.pipelinesClientService.findOneProperties(id, metadata);
}
@Get(':id/objects')
async getPipelineObjects(
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@User() user: RequestUser,
@Param('id') id,
@Param('id') id: string,
) {
this.logger.info('PipelinesController - getPipelineObjects', { user });
const metadata = PackTheMetadata({
...user,
language: language || 'pt-br',
});
const metadata = PackTheMetadata({ ...user, language: language });
return this.pipelinesClientService.findOneObjects(id, metadata);
}
@Get(':id/status')
async getPipelineStatus(@Body() body, @Param('id') id: string) {
body.id = id;
this.logger.info(
process.env.DEV_URL + `/pipeline/${id} - ON GET PIPELINE STATUS ROUTE`,
{
user: body.info.user_id,
customer: body.info.customer,
},
);
const response = await this.oldPipelinesService.getPipelineStatus(body);
return response;
}
@Get('/:id')
async findOne(
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@User() user: RequestUser,
@Param('id') id,
@Param('id') id: string,
): Promise<Messages.PipelineV2FindOneResponse> {
this.logger.info('PipelinesController - findOne', { user });
if (!language) language = 'en-us';
const { customer_id, customer_name, user_id, username } = user;
const metadata = PackTheMetadata({
@@ -237,11 +259,11 @@ export class PipelinesController {
return result;
}
@Put('/:id')
@Patch('/:id')
async update(
@Headers('Dadosfera-Lang') language,
@Language() language: LanguageEnum,
@Body() updatePipelineDto,
@Param('id') id,
@Param('id') id: string,
@User() user: RequestUser,
) {
this.logger.info('PipelinesController - update', { user });
@@ -249,7 +271,6 @@ export class PipelinesController {
delete updatePipelineDto.info;
const { customer_id, customer_name, user_id, username } = user;
if (!language) language = 'en-us';
const metadata = PackTheMetadata({
customer_id,
@@ -272,25 +293,29 @@ export class PipelinesController {
return response;
}
@Patch('/:id')
async updateByPatch(
@Headers('Dadosfera-Lang') language,
@ApiInternalOnlyEndpoint()
@Put('/:id')
@ApiOperation({
deprecated: true,
description: 'This method is deprecated. Please use PATCH instead',
})
async updateDeprecated(
@Language() language: LanguageEnum,
@Body() updatePipelineDto,
@Param('id') id,
@Param('id') id: string,
@User() user: RequestUser,
) {
this.logger.info('PipelinesController - patch', { user });
this.logger.info('PipelinesController - put', { user });
const response = await this.update(language, updatePipelineDto, id, user);
this.logger.info('PipelinesController - patch: OK', { user });
this.logger.info('PipelinesController - put: OK', { user });
return response;
}
@Delete(':id')
@ApiNoContentResponse()
@HttpCode(HttpStatus.NO_CONTENT)
async delete(@Param() params, @User() user: RequestUser) {
async delete(@Param('id') id: string, @User() user: RequestUser) {
this.logger.info('PipelinesController - delete', { user });
const { id } = params;
const metadata = PackTheMetadata({
customer_id: user.customer_id,
customer_name: user.customer_name,
@@ -300,37 +325,28 @@ export class PipelinesController {
this.logger.info('PipelinesController - delete: OK');
}
@Post('/upload')
@ApiInternalOnlyEndpoint()
@Post('/init-upload')
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.CREATE)
@ApiConsumes('multipart/form-data')
@UseInterceptors(
FileInterceptor('file', { limits: { fileSize: 50 * 1000 * 1000 + 1 } }),
)
async uploadFile(
async initUploadFile(
@User() user: RequestUser,
@UploadedFile() file,
@Body() body: IUploadCSVFile,
@Body() body: IInitUploadCSVFile,
) {
this.logger.info('/upload - Upload Connector Route');
this.logger.info('/upload - Init Upload File Route');
const metadata = PackTheMetadata({ ...user });
const parts_of_file_name = file.originalname.split('.');
const file_format = parts_of_file_name.pop();
const file_name = parts_of_file_name.join('.');
let name = `${new Date().getTime()}_${file_name}`;
body.name ? (name = `${new Date().getTime()}_${body.name}`) : name;
const { file_name, parts } = body;
const source_prefix = `${user.customer_name}/${name}.${file_format}`;
const { urls, upload_id } =
await this.pipelinesClientService.initUploadFile(
{
name: file_name,
parts: String(parts),
},
metadata,
);
const response = await this.pipelinesClientService.uploadFile(
{
file,
name,
},
metadata,
);
if (!response.url) {
if (!urls) {
this.logger.info('pipeline/upload - Failed File pipeline');
throw new HttpException(
'Upload failed, try again in a few minutes, if the problem persists, contact support.',
@@ -338,26 +354,65 @@ export class PipelinesController {
);
}
const { sep, header, encoding, description } = body;
return { urls: JSON.parse(urls), upload_id };
}
const upload_pipeline = {
@ApiInternalOnlyEndpoint()
@Post('/complete-upload')
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.CREATE)
async completeUploadFile(
@User() user: RequestUser,
@Body() body: ICompleteUploadCSVFile,
) {
this.logger.info('/upload - Complete Upload File Route');
const metadata = PackTheMetadata({ ...user });
const { upload_id, parts, file_name } = body;
return await this.pipelinesClientService.completeUploadFile(
{ upload_id, parts, file_name },
metadata,
);
}
@ApiInternalOnlyEndpoint()
@Post('/file')
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.CREATE)
async uploadedFile(
@User() user: RequestUser,
@Body() body: ICreatePipelineCSVFile,
) {
this.logger.info('/file - Upload Connector Route');
const metadata = PackTheMetadata({ ...user });
const { name, sep, header, encoding, description, file_name, engine } =
body;
const file_format_params = {
...(sep && { sep }),
...(encoding && { encoding }),
...(header !== undefined ? { header } : {}),
};
const source_prefix = `${user.customer_name}/${file_name}`;
const upload_pipeline: ICreatePipelineV2Req = {
connection_id: process.env.UPLOAD_FILE_AGENT_CONNECTION,
connector_name: 'Amazon S3',
connector_plugin: 'aws_s3',
connector_version: '1.0.0',
image_url: 'https://assets.dadosfera.ai/images/connectors/csv.svg',
name: body.name || file_name,
image_url: `https://assets.dadosfera.ai/images/connectors/${engine}.svg`,
name,
description,
transformations_ids: [],
tags: [],
cron: '@once',
config: { cron: '@once', tables: [] },
type: 'upload',
properties: {
engine: 'csv',
engine,
source_bucket: process.env.BUCKET_CUSTOMER_CSV_ASSETS,
source_prefix,
file_format_params: { sep, encoding, header: Boolean(header) },
is_a_upload_csv: true,
file_format_params,
},
input_id: undefined,
};
@@ -369,4 +424,22 @@ export class PipelinesController {
return pipeline;
}
@ApiInternalOnlyEndpoint()
@Post('start/:id')
async activate(@Param('id') id: string, @Body() body) {
const { info } = body;
this.logger.info(
process.env.DEV_URL + `/pipeline/start/${id} - ON START PIPELINE ROUTE`,
{
user: body.info.user_id,
customer: body.info.customer,
},
);
const response = await this.oldPipelinesService.runPipeline({ id, info });
return response;
}
}
+66 -20
View File
@@ -21,9 +21,9 @@ import { PipelineV2CreateRequest } from '@dadosfera/protospack-v2/dist/lib/Pipel
import { Metadata } from '@grpc/grpc-js';
import { ConnectorClientService } from '../connector/client.service';
import { InputsService } from '../inputs/inputs.service';
import { RequestUser } from 'src/authentication/user.decorator';
import { RequestUser } from 'src/decorators/user.decorator';
import { TransformationsService } from '../transformations/transformations.service';
import { getObjValueFromPath } from 'src/utils/ObjValueFromPath';
import { getObjValueFromPath, objHasPath } from 'src/utils/ObjValueFromPath';
import ErrorCodes from 'src/utils/errorCodes';
import ErrorBuilder from 'src/utils/ErrorBuilder';
@@ -220,7 +220,7 @@ export class PipelinesService implements OnModuleInit {
this.logger.info('PipelinesClientService - findOneProperties');
const { pipeline } = await this.findOne({ id }, metadata);
const pipelineProperties = JSON.parse(pipeline.properties);
const properties = JSON.parse(pipeline.properties);
const connectorId = `${pipeline.connector_plugin}-${pipeline.connector_version}`;
@@ -228,24 +228,38 @@ export class PipelinesService implements OnModuleInit {
connectorId,
metadata.get('language')[0].toString(),
);
const connector = JSON.parse(res.connector);
const config_controls = connector.config_controls || [];
const connector: { [key: string]: any; config_controls: any[] } =
JSON.parse(res.connector);
const config_controls = (connector.config_controls || []).filter(
(config_control) => {
const path: string = config_control.name;
if (!objHasPath({ object: { properties }, path })) return false;
for (const config_control of config_controls) {
const path: string = config_control.name;
const default_value = getObjValueFromPath({
object: { properties: pipelineProperties },
path,
});
if (default_value != undefined)
config_control.default_value = default_value;
}
let default_value = getObjValueFromPath({
object: { properties },
path,
});
if (default_value != undefined) {
if (
path === 'properties.spreadsheet_id' &&
typeof default_value === 'string'
)
default_value = 'https://docs.google.com/spreadsheets/d/'.concat(
default_value,
);
config_control.default_value = default_value;
}
return true;
},
);
return {
pipeline: {
...pipeline,
config_controls,
properties: pipelineProperties,
properties,
},
};
}
@@ -261,13 +275,10 @@ export class PipelinesService implements OnModuleInit {
return { objects: JSON.parse(objects) };
}
async uploadFile(uploadFile, metadata) {
async initUploadFile(uploadFile, metadata) {
const body: Messages.PipelineV2UploadFileRequest = {
file: {
buffer: uploadFile.file.buffer,
mimetypes: uploadFile.file.mimetype,
},
name: uploadFile.name,
parts: uploadFile.parts,
};
return lastValueFrom(
@@ -293,4 +304,39 @@ export class PipelinesService implements OnModuleInit {
return url;
}
async completeUploadFile(uploadFile, metadata) {
const body: Messages.PipelineV2CompleteUploadFileRequest = {
upload_id: uploadFile.upload_id,
parts: JSON.stringify(uploadFile.parts),
name: uploadFile.file_name,
};
return lastValueFrom(
this.pipelineWriteService.PipelineV2CompleteUploadFile(body, metadata),
).catch((err) => {
throw new HttpException(
err.details,
err.code === 6 ? HttpStatus.CONFLICT : 400,
);
});
}
async getMonitoringDashboardUrl(metadata: Metadata) {
this.logger.info('PipelinesClientService - getMonitoringDashboardUrl');
const res = await lastValueFrom(
this.pipelineReadService.PipelineV2GetDashboardUrl(
{
dashboard_id: '83',
exp: '15m',
metabase_customer_name: 'dadosferatech',
},
metadata,
),
);
this.logger.info('Done');
return res;
}
}
@@ -1,12 +1,16 @@
import { Body, Controller, HttpException, Post } from '@nestjs/common';
import { ApiTags } from '@nestjs/swagger';
import axios from 'axios';
import { User, RequestUser } from 'src/authentication/user.decorator';
import { getSecreteFromSecreteManager } from 'src/utils/SecretManager';
import { Authenticated } from 'src/decorators/authentication.decorator';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
import { User, RequestUser } from 'src/decorators/user.decorator';
import { getSecretFromSecretsManager } from 'src/utils/SecretManager';
import { INote } from './dtos';
@ApiInternalOnlyController()
@ApiTags('Productboard')
@Controller('productboard')
@Authenticated()
export class ProductboardController {
@Post('notes')
async sendNote(@Body() note: INote, @User() user: RequestUser) {
@@ -18,7 +22,7 @@ export class ProductboardController {
: username + `@${customer_name}.default`;
const path = process.env.PB_TOKEN_PATH;
const token = await getSecreteFromSecreteManager(path);
const token = await getSecretFromSecretsManager(path);
const response = await axios
.post(
+8
View File
@@ -25,6 +25,8 @@ export class RoleDto {
customer?: Customer;
@ApiProperty()
usage: string;
@ApiPropertyOptional({ description: 'Whether this role can be untoggled' })
canUntoggle?: boolean;
}
export class CustomerRole extends OmitType(RoleDto, ['customer']) {}
@@ -34,11 +36,17 @@ export enum TrueOrFalseEnum {
true = 'true',
false = 'false',
}
export enum CanUntoggleLogicEnum {
data_assets_sharing = 'data_assets_sharing',
}
export class GetRolesByCustomerReq {
@ApiPropertyOptional()
permissionId?: string[];
@ApiPropertyOptional({ enum: TrueOrFalseEnum })
getUsers?: TrueOrFalseEnum;
@ApiPropertyOptional({ enum: CanUntoggleLogicEnum })
canUntoggleLogic?: CanUntoggleLogicEnum;
}
export class GetRolesByCustomerRes {
+18 -21
View File
@@ -3,7 +3,6 @@ import {
Controller,
Delete,
Get,
Headers,
Inject,
Param,
Patch,
@@ -14,11 +13,11 @@ import {
} from '@nestjs/common';
import {
ApiCreatedResponse,
ApiHeader,
ApiHeaders,
ApiOkResponse,
ApiTags,
} from '@nestjs/swagger';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { RolesService } from './roles.service';
import {
@@ -43,16 +42,14 @@ import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import {
Authenticated,
RequireAllPermissions,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
import { Language } from 'src/decorators/language.decorator';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
@ApiInternalOnlyController()
@ApiTags('Roles')
@ApiHeader({
name: 'dadosfera-lang',
enum: LanguageEnum,
required: false,
description: 'Defaults to pt-br',
})
@ApiHeaders([{ name: 'dadosfera-lang', enum: LanguageEnum, required: false }])
@Authenticated()
@UseFilters(new GrpcToHttpExceptionFilter())
@Controller('roles')
@@ -71,12 +68,12 @@ export class RolesController {
@ApiOkResponse({ type: GetRolesByCustomerRes })
async searchRoles(
@User() user: RequestUser,
@Query() filters: GetRolesByCustomerReq,
@Headers('dadosfera-lang') language,
@Query() params: GetRolesByCustomerReq,
@Language() language: LanguageEnum,
) {
this.logger.info('searchRoles', { user });
this.rolesService.setLanguage(language);
return await this.rolesService.roleSearch(filters, user);
return await this.rolesService.roleSearch(params, user);
}
@Post()
@@ -85,7 +82,7 @@ export class RolesController {
async createRole(
@User() user: RequestUser,
@Body() body: CreateRoleReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('createRole', { user });
this.rolesService.setLanguage(language);
@@ -98,7 +95,7 @@ export class RolesController {
async grantPermissionsToRole(
@User() user: RequestUser,
@Body() body: GrantPermissionsToRoleReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('grantPermissionsToRole', { user });
this.rolesService.setLanguage(language);
@@ -111,7 +108,7 @@ export class RolesController {
async revokePermissionsFromRole(
@User() user: RequestUser,
@Body() body: RevokePermissionsFromRoleReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('revokePermissionsToRole', { user });
this.rolesService.setLanguage(language);
@@ -124,7 +121,7 @@ export class RolesController {
async setRolePermissions(
@User() user: RequestUser,
@Body() body: SetRolePermissionsReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('setRolePermissions', { user });
this.rolesService.setLanguage(language);
@@ -137,7 +134,7 @@ export class RolesController {
async setRoleUsers(
@User() user: RequestUser,
@Body() body: SetRoleUsersReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('setRoleUsers', { user });
this.rolesService.setLanguage(language);
@@ -150,7 +147,7 @@ export class RolesController {
async getRoleById(
@User() user: RequestUser,
@Param('id') id: string,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('getRoleById', { user });
this.rolesService.setLanguage(language);
@@ -162,7 +159,7 @@ export class RolesController {
async deleteRole(
@User() user: RequestUser,
@Param('id') id: string,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('deleteRole', { user });
this.rolesService.setLanguage(language);
@@ -176,7 +173,7 @@ export class RolesController {
@User() user: RequestUser,
@Param('id') id: string,
@Body() body: UpdateRoleReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('updateRole', { user });
this.rolesService.setLanguage(language);
+9 -16
View File
@@ -18,7 +18,7 @@ import { Permission } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/ent
import { lastValueFrom } from 'rxjs';
import { PermissionsService } from '../permissions/permissions.service';
import { LanguageEnum } from 'src/utils/languages.enum';
import { RequestUser } from 'src/authentication/user.decorator';
import { RequestUser } from 'src/decorators/user.decorator';
import { DucClient } from '../duc/client.config';
interface GetRolesPermissionsName {
@@ -70,12 +70,7 @@ export class RolesService {
return { role: roleTreated };
}
async roleSearch(
filters: GetRolesByCustomerReq,
{ customer_id, access_token }: any,
) {
const meta = new Metadata();
meta.add('access_token', access_token);
async roleSearch(filters: GetRolesByCustomerReq, { customer_id }) {
let { permissionId: permissionIds } = filters;
if (permissionIds && !Array.isArray(permissionIds))
permissionIds = [permissionIds];
@@ -89,15 +84,13 @@ export class RolesService {
return seqId;
}) || [];
const roles = await lastValueFrom(
this.rolesClientService.RoleSearch(
{
customerId: customer_id,
getUsers: isGetUsers,
permissionIds: [],
permissionSeqIds,
},
meta,
),
this.rolesClientService.RoleSearch({
customerId: customer_id,
getUsers: isGetUsers,
permissionIds: [],
permissionSeqIds,
canUntoggleLogic: filters.canUntoggleLogic,
}),
);
const rolesTreated = this.getRolesPermissionsName(roles.roles);
return { roles: rolesTreated };
@@ -9,17 +9,22 @@ import {
Headers,
UseFilters,
} from '@nestjs/common';
import { ApiTags } from '@nestjs/swagger';
import { ApiHeaders, ApiTags } from '@nestjs/swagger';
import { TermsOfUseAcceptRequest } from '@dadosfera/protospack-v2/dist/lib/Duc/interfaces/messages';
import { TermsOfUseClientService } from './termsOfUse.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { GrpcToHttpExceptionFilter } from '../../error/grpc-to-http-exception.filter';
import { RequestUser, User } from '../../authentication/user.decorator';
import { RequestUser, User } from '../../decorators/user.decorator';
import { Metadata } from '@grpc/grpc-js';
import { Language } from 'src/decorators/language.decorator';
import { LanguageEnum } from 'src/utils/languages.enum';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
@ApiInternalOnlyController()
@ApiTags('TermsOfUse')
@ApiHeaders([{ name: 'dadosfera-lang', enum: LanguageEnum, required: false }])
@UseFilters(new GrpcToHttpExceptionFilter())
@Controller('terms-of-use')
export class TermsOfUseController {
@@ -36,7 +41,7 @@ export class TermsOfUseController {
@Get('token')
async getToken(
@User({ required: true }) user: RequestUser,
@Headers('Dadosfera-Lang') language: string,
@Language() language: LanguageEnum,
) {
this.logger.info('/terms-of-use - get token');
const metadata = new Metadata();
+1 -1
View File
@@ -1,4 +1,4 @@
import { Info } from 'protospack/dist/lib/interfaces';
import { Info } from '@dadosfera/protospack/dist/lib/interfaces';
export interface ICreateTransformationsRequest {
transformations: Transformation[];
@@ -6,6 +6,10 @@ import {
import { credentials } from '@grpc/grpc-js';
import { Transformation } from '@dadosfera/protospack-v2';
const isLocalConnection =
process.env.INFACTORY_URL.startsWith('in-factory:') ||
process.env.INFACTORY_URL.includes('0.0.0.0');
export class TransformationsClientConfiguration {
public name = 'TransformationsClientConfiguration';
private config: GrpcOptions = {
@@ -13,10 +17,7 @@ export class TransformationsClientConfiguration {
options: {
url: process.env.INFACTORY_URL,
package: [Transformation.ProtoPackages.WritePackage],
credentials:
process.env.LOCAL_ENV || process.env.ENV === 'local'
? undefined
: credentials.createSsl(),
credentials: isLocalConnection ? undefined : credentials.createSsl(),
protoPath: [Transformation.ProtoPaths.WriteFilePath],
loader: {
enums: String,
@@ -12,15 +12,17 @@ import { ApiTags } from '@nestjs/swagger';
import { TransformationsClientService } from './client.service';
import { IIdRequest } from './interfaces';
import {
AuthenticateCondition,
Authenticated,
RequireSomePermission,
} from 'src/authentication/authentication.decorator';
} from 'src/decorators/authentication.decorator';
import { PERMISSIONS_GROUPS } from '../../authentication/permissions.enum';
import { TransformationsService } from './transformations.service';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { RequestUser, User } from 'src/authentication/user.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
const pipelinePermissions = PERMISSIONS_GROUPS.PIPELINE.permissions;
@ApiInternalOnlyController()
@ApiTags('Transformations')
@Controller('transformations')
@Authenticated()
@@ -70,8 +72,7 @@ export class TransformationsController {
@Get('/:id')
@RequireSomePermission(pipelinePermissions.GET)
async findOne(@Body() data, @Param() params) {
const { id } = params;
async findOne(@Body() data, @Param('id') id: string) {
this.logger.info(`/transformation/${id} - ON Find One ROUTE`, {
user: data.info.user_id,
customer: data.info.customer,
+43 -36
View File
@@ -1,9 +1,9 @@
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import {
Body,
Controller,
Delete,
Get,
Headers,
HttpCode,
HttpStatus,
Inject,
@@ -16,18 +16,22 @@ import {
} from '@nestjs/common';
import {
ApiCreatedResponse,
ApiHeader,
ApiHeaders,
ApiOkResponse,
ApiTags,
} from '@nestjs/swagger';
import { DadosferaLogger } from '@dadosfera/dadosfera-logs';
import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import {
Authenticated,
RequireAllPermissions,
} from 'src/authentication/authentication.decorator';
import { PERMISSIONS_GROUPS } from 'src/authentication/permissions.enum';
import { RequestUser, User } from 'src/authentication/user.decorator';
} from 'src/decorators/authentication.decorator';
import { Language } from 'src/decorators/language.decorator';
import { ApiInternalOnlyController } from 'src/decorators/swagger.decorator';
import { RequestUser, User } from 'src/decorators/user.decorator';
import { GrpcToHttpExceptionFilter } from 'src/error/grpc-to-http-exception.filter';
import { PackTheMetadata } from 'src/utils/ PackTheMetadata';
import ErrorBuilder from 'src/utils/ErrorBuilder';
import ErrorCodes from 'src/utils/errorCodes';
import { LanguageEnum } from 'src/utils/languages.enum';
import {
AssignRoleToUserReq,
@@ -40,26 +44,19 @@ import {
GetAllHierarchiesRes,
GetAllJobTitlesRes,
GetAllUsersByCustomerIdRes,
IUserByCustomer,
SetUserRolesReq,
SetUserRolesRes,
UnassignRoleToUserReq,
UpdateUserReq,
UpdateUserRes,
IUserByCustomer,
} from './dtos/entities';
import { UsersService } from './users.service';
import { Metadata } from '@grpc/grpc-js';
import ErrorBuilder from 'src/utils/ErrorBuilder';
import ErrorCodes from 'src/utils/errorCodes';
@ApiInternalOnlyController()
@ApiTags('Users')
@Controller('users')
@ApiHeader({
name: 'dadosfera-lang',
enum: LanguageEnum,
required: false,
description: 'Defaults to pt-br',
})
@ApiHeaders([{ name: 'dadosfera-lang', enum: LanguageEnum, required: false }])
@Authenticated()
@UseFilters(GrpcToHttpExceptionFilter)
export class UsersController {
@@ -76,7 +73,7 @@ export class UsersController {
@Get()
async getAllUsersByCustomerId(
@User() user: RequestUser,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
): Promise<GetAllUsersByCustomerIdRes> {
this.logger.info('getAllUsersByCustomerId', { user });
this.userService.setLanguage(language);
@@ -88,7 +85,7 @@ export class UsersController {
@ApiOkResponse({ type: GetAllHierarchiesRes })
async getAllHierarchies(
@User() user: RequestUser,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
): Promise<GetAllHierarchiesRes> {
this.logger.info('getAllHierarchies', { user });
this.userService.setLanguage(language);
@@ -100,7 +97,7 @@ export class UsersController {
@ApiOkResponse({ type: GetAllDepartmentsRes })
async getAllDepartments(
@User() user: RequestUser,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
): Promise<GetAllDepartmentsRes> {
this.logger.info('getAllHierarchies', { user });
this.userService.setLanguage(language);
@@ -112,7 +109,7 @@ export class UsersController {
@ApiOkResponse({ type: GetAllDepartmentsRes })
async getAllJobTitles(
@User() user: RequestUser,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
): Promise<GetAllJobTitlesRes> {
this.logger.info('getAllHierarchies', { user });
this.userService.setLanguage(language);
@@ -126,7 +123,7 @@ export class UsersController {
async findOneById(
@User() user: RequestUser,
@Param('id') id: string,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('findOneById', { user });
this.userService.setLanguage(language);
@@ -147,14 +144,16 @@ export class UsersController {
async createUser(
@User() user: RequestUser,
@Body() body: CreateUserReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
const meta = new Metadata();
meta.add('access_token', user.access_token);
const metadata = PackTheMetadata({
access_token: user.access_token,
language,
});
this.logger.info('createUser', { user });
this.userService.setLanguage(language);
return await this.userService.createUser(body, meta);
return await this.userService.createUser(body, metadata);
}
@Post('batch')
@@ -163,13 +162,17 @@ export class UsersController {
async batchCreateUser(
@User() user: RequestUser,
@Body() body: BatchCreateUserReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
const meta = new Metadata();
meta.add('access_token', user.access_token);
this.logger.info('batchCreateUser', { user });
this.userService.setLanguage(language);
return await this.userService.batchCreateUser(body, meta);
const metadata = PackTheMetadata({
access_token: user.access_token,
language,
});
return await this.userService.batchCreateUser(body, metadata);
}
@Post(':id/resend-invite')
@@ -178,11 +181,15 @@ export class UsersController {
async resendInvite(
@User() user: RequestUser,
@Param('id') id: string,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('resendInvite', { user });
this.userService.setLanguage(language);
return this.userService.resendInvite({ id });
const metadata = PackTheMetadata({
language,
});
return this.userService.resendInvite({ id }, metadata);
}
@Delete('role')
@@ -190,7 +197,7 @@ export class UsersController {
async unassignRoleToUser(
@User() user: RequestUser,
@Query() request: UnassignRoleToUserReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('unassignRoleToUser', { user });
this.userService.setLanguage(language);
@@ -203,7 +210,7 @@ export class UsersController {
async deleteUser(
@User() user: RequestUser,
@Param('id') id: string,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('deleteUser', { user });
this.userService.setLanguage(language);
@@ -216,7 +223,7 @@ export class UsersController {
async setUserRoles(
@User() user: RequestUser,
@Body() body: SetUserRolesReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('createUser', { user });
this.userService.setLanguage(language);
@@ -228,7 +235,7 @@ export class UsersController {
async assignRoleToUser(
@User() user: RequestUser,
@Body() body: AssignRoleToUserReq,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('assignRoleToUser', { user });
this.userService.setLanguage(language);
@@ -242,7 +249,7 @@ export class UsersController {
@User() user: RequestUser,
@Body() body: UpdateUserReq,
@Param('id') id: string,
@Headers('dadosfera-lang') language,
@Language() language: LanguageEnum,
) {
this.logger.info('updateUser', { user });
this.userService.setLanguage(language);
+4 -2
View File
@@ -185,8 +185,10 @@ export class UsersService implements OnModuleInit {
};
}
async resendInvite(body: IdRequest) {
return lastValueFrom(this.usersClientService.UserResendInvite(body));
async resendInvite(body: IdRequest, metadata: Metadata) {
return lastValueFrom(
this.usersClientService.UserResendInvite(body, metadata),
);
}
async assignRoleToUser(body: AssignRoleToUserRequest) {
+1
View File
@@ -10,6 +10,7 @@ interface IMetadata {
sensitive?: string;
roles?: string[];
is_data_manager?: boolean;
access_token?: string;
}
export function PackTheMetadata(info: IMetadata): Metadata {
+22
View File
@@ -119,6 +119,14 @@ export function EnrichErrorCode(code: string) {
code,
};
case ErrorCodes.AUTH.INVALID_REFRESH_TOKEN:
return {
statusCode: HttpStatus.UNAUTHORIZED,
error: 'Acesso expirado!',
message: 'Seu acesso expirou, favor fazer login novamente.',
code,
};
case ErrorCodes.AUTH.FORBIDDEN:
return {
statusCode: HttpStatus.FORBIDDEN,
@@ -300,6 +308,20 @@ export function EnrichErrorCode(code: string) {
'Tente realizar a ação novamente. Caso o erro persista, entre em contato com o suporte',
code,
};
case ErrorCodes.CATALOG.PREVIEW_TOO_BIG:
return {
statusCode: HttpStatus.INTERNAL_SERVER_ERROR,
error: 'Erro ao buscar prévia',
message: 'Ocorreu um erro devido ao tamanho da prévia do ativo.',
code,
};
case ErrorCodes.CATALOG.METADATA_TOO_BIG:
return {
statusCode: HttpStatus.INTERNAL_SERVER_ERROR,
error: 'Erro ao buscar informações',
message: 'Ocorreu um erro devido ao tamanho das informações do ativo.',
code,
};
case ErrorCodes.INTERNAL:
case ErrorCodes.UNKNOWN:
default:
+4
View File
@@ -2,6 +2,7 @@ import {
SecretsManagerClient,
GetSecretValueCommand,
} from '@aws-sdk/client-secrets-manager';
let cachedSecrets: OauthSecrets;
class OauthSecretsObject {
client_id = '';
@@ -15,8 +16,10 @@ export class OauthSecrets {
mailchimp = new OauthSecretsObject();
facebook = new OauthSecretsObject();
salesforce = new OauthSecretsObject();
'google-login' = new OauthSecretsObject();
}
export async function getOauthSecrets() {
if (cachedSecrets) return cachedSecrets;
const secrets = new OauthSecrets();
const path = process.env.SM_OAUTH_PATH;
const secretsManagerClient = new SecretsManagerClient({});
@@ -37,5 +40,6 @@ export async function getOauthSecrets() {
};
}
}
cachedSecrets = secrets;
return secrets;
}

Some files were not shown because too many files have changed in this diff Show More