0
Fork 0
mirror of https://github.com/logto-io/logto.git synced 2024-12-30 20:33:54 -05:00

feat(schemas): drop m2m credentials in existing logto email connector config (#4126)

This commit is contained in:
Darcy Ye 2023-07-06 13:47:14 +08:00 committed by GitHub
parent d6dc308fd4
commit dd657d3877
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -0,0 +1,88 @@
import { GlobalValues } from '@logto/shared';
import { appendPath } from '@silverhand/essentials';
import { sql } from 'slonik';
import type { AlterationScript } from '../lib/types/alteration.js';
type M2mCredentials = {
appSecret: string;
appId: string;
endpoint: string;
tokenEndpoint: string;
resource: string;
};
type EmailServiceConnector = {
tenantId: string;
config: Partial<M2mCredentials> & Record<string, unknown>;
};
type CloudConnectionData = {
tenantId: string;
value: { appSecret: string; appId: string; resource: string };
};
enum ServiceConnector {
Email = 'logto-email',
}
const cloudConnectionKey = 'cloudConnection';
const alteration: AlterationScript = {
up: async (pool) => {
const { rows: rawConnectors } = await pool.query<EmailServiceConnector>(sql`
select tenant_id, config from connectors where connector_id = ${ServiceConnector.Email};
`);
const connectors = rawConnectors.map((rawConnector) => {
const {
tenantId,
config: { appSecret, appId, endpoint, tokenEndpoint, resource, ...rest },
} = rawConnector;
return { tenantId, config: rest };
});
for (const connector of connectors) {
const { tenantId, config } = connector;
// eslint-disable-next-line no-await-in-loop
await pool.query(sql`
update connectors set config = ${JSON.stringify(
config
)} where tenant_id = ${tenantId} and connector_id = ${ServiceConnector.Email};
`);
}
},
down: async (pool) => {
const { rows: cloudConnections } = await pool.query<CloudConnectionData>(sql`
select tenant_id, value from logto_configs where key = ${cloudConnectionKey};
`);
/** Get `endpoint` and `tokenEndpoints` */
const globalValues = new GlobalValues();
const { cloudUrlSet, adminUrlSet } = globalValues;
const endpoint = appendPath(cloudUrlSet.endpoint, 'api').toString();
const tokenEndpoint = appendPath(adminUrlSet.endpoint, 'oidc/token').toString();
const { rows: rawEmailServiceConnectors } = await pool.query<EmailServiceConnector>(sql`
select tenant_id, config from connectors where connector_id = ${ServiceConnector.Email};
`);
const tenantIdsWithM2mCredentials = new Set(cloudConnections.map(({ tenantId }) => tenantId));
const emailServiceConnectors = rawEmailServiceConnectors.filter(({ tenantId }) =>
tenantIdsWithM2mCredentials.has(tenantId)
);
for (const emailServiceConnector of emailServiceConnectors) {
const { tenantId: currentTenantId, config } = emailServiceConnector;
const newConfig = {
...config,
endpoint,
tokenEndpoint,
...cloudConnections.find(({ tenantId }) => tenantId === currentTenantId)?.value,
};
// eslint-disable-next-line no-await-in-loop
await pool.query(sql`
update connectors set config = ${JSON.stringify(
newConfig
)} where tenant_id = ${currentTenantId} and connector_id = ${ServiceConnector.Email};
`);
}
},
};
export default alteration;