mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add enable/disable support for user secrets (#27537)
Users can now disable a secret to stop it from being injected into workspaces without deleting it, and re-enable it later. Disabled secrets stay visible and editable everywhere they already appear. An enabled secret must have at least one injection target; a secret with no target can be stored only while disabled. Existing target-less secrets are migrated to disabled to preserve current behavior. Support spans the REST API, SDK, CLI, dashboard, and audit log.
This commit is contained in:
@@ -278,10 +278,11 @@ func dbAgentDevcontainersToProto(devcontainers []database.WorkspaceAgentDevconta
|
||||
func dbUserSecretsToProto(secrets []database.UserSecret) []*agentproto.WorkspaceSecret {
|
||||
ret := make([]*agentproto.WorkspaceSecret, 0, len(secrets))
|
||||
for _, s := range secrets {
|
||||
// Only include secrets that have an environment variable
|
||||
// name or file path set. Secrets with neither are not
|
||||
// injected at runtime.
|
||||
if s.EnvName == "" && s.FilePath == "" {
|
||||
// Skip disabled secrets so they are not injected as env vars or
|
||||
// written to secret files. The API guarantees every enabled
|
||||
// secret has at least one of env_name or file_path set, so we
|
||||
// don't need to filter both-empty rows separately here.
|
||||
if !s.Enabled {
|
||||
continue
|
||||
}
|
||||
ret = append(ret, &agentproto.WorkspaceSecret{
|
||||
|
||||
@@ -468,19 +468,20 @@ func TestGetManifest(t *testing.T) {
|
||||
mDB.EXPECT().GetWorkspaceByID(gomock.Any(), workspace.ID).Return(workspace, nil)
|
||||
|
||||
// Return a mix of secrets: env-only, file-only, both, and
|
||||
// one with neither set. The last should be filtered out.
|
||||
// one explicitly disabled. The disabled secret should be
|
||||
// filtered out.
|
||||
mDB.EXPECT().ListUserSecretsWithValues(gomock.Any(), workspace.OwnerID).Return([]database.UserSecret{
|
||||
{EnvName: "GITHUB_TOKEN", FilePath: "", Value: "ghp_xxxx"},
|
||||
{EnvName: "", FilePath: "~/.ssh/id_rsa", Value: "private-key"},
|
||||
{EnvName: "BOTH_ENV", FilePath: "/etc/both", Value: "both-val"},
|
||||
{EnvName: "", FilePath: "", Value: "stored-only"},
|
||||
{EnvName: "GITHUB_TOKEN", FilePath: "", Value: "ghp_xxxx", Enabled: true},
|
||||
{EnvName: "", FilePath: "~/.ssh/id_rsa", Value: "private-key", Enabled: true},
|
||||
{EnvName: "BOTH_ENV", FilePath: "/etc/both", Value: "both-val", Enabled: true},
|
||||
{EnvName: "DISABLED_ENV", FilePath: "", Value: "disabled-val", Enabled: false},
|
||||
}, nil)
|
||||
|
||||
got, err := api.GetManifest(context.Background(), &agentproto.GetManifestRequest{})
|
||||
require.NoError(t, err)
|
||||
|
||||
// The secret with neither env_name nor file_path should
|
||||
// be filtered out, leaving exactly 3.
|
||||
// The disabled secret should be filtered out, leaving
|
||||
// exactly 3.
|
||||
require.Len(t, got.Secrets, 3)
|
||||
require.Equal(t, "GITHUB_TOKEN", got.Secrets[0].EnvName)
|
||||
require.Equal(t, "", got.Secrets[0].FilePath)
|
||||
|
||||
Reference in New Issue
Block a user