mirror of
https://github.com/coollabsio/coolify.git
synced 2026-10-06 14:07:37 -04:00
Queue database imports from upload, S3, or server paths via REST, and manage Cloudflare DNS records from integration tokens and domain UIs.
140 lines
4.6 KiB
PHP
140 lines
4.6 KiB
PHP
<?php
|
|
|
|
namespace App\Livewire\Security;
|
|
|
|
use App\Models\IntegrationToken;
|
|
use App\Services\Dns\CloudflareDnsProvider;
|
|
use App\Services\IntegrationTokenValidator;
|
|
use Illuminate\Foundation\Auth\Access\AuthorizesRequests;
|
|
use Illuminate\Support\Facades\DB;
|
|
use Livewire\Component;
|
|
|
|
class IntegrationTokenForm extends Component
|
|
{
|
|
use AuthorizesRequests;
|
|
|
|
public bool $modal_mode = false;
|
|
|
|
public string $provider = 'cloudflare';
|
|
|
|
public string $name = '';
|
|
|
|
public string $token = '';
|
|
|
|
public array $capabilities = ['dns'];
|
|
|
|
public array $metadata = [];
|
|
|
|
public bool $automaticDns = true;
|
|
|
|
public function mount(): void
|
|
{
|
|
$this->authorize('create', IntegrationToken::class);
|
|
}
|
|
|
|
public function updatedProvider(): void
|
|
{
|
|
if ($this->provider === 'cloudflare') {
|
|
$this->capabilities = ['dns'];
|
|
$this->metadata = [];
|
|
$this->automaticDns = true;
|
|
} else {
|
|
$this->capabilities = ['secrets'];
|
|
$this->metadata = $this->provider === 'infisical'
|
|
? ['base_url' => 'https://app.infisical.com']
|
|
: [];
|
|
}
|
|
}
|
|
|
|
protected function rules(): array
|
|
{
|
|
$allowedCapability = $this->provider === 'cloudflare' ? 'dns' : 'secrets';
|
|
|
|
$rules = [
|
|
'provider' => ['required', 'in:'.implode(',', array_keys(IntegrationToken::PROVIDER_NAMES))],
|
|
'name' => ['required', 'string', 'max:255'],
|
|
'token' => ['required', 'string'],
|
|
'capabilities' => ['required', 'array', 'min:1'],
|
|
'capabilities.*' => ['required', 'in:'.$allowedCapability],
|
|
'automaticDns' => ['boolean'],
|
|
];
|
|
|
|
if ($this->provider === 'infisical') {
|
|
$rules['metadata.base_url'] = ['required', 'url:http,https'];
|
|
$rules['metadata.client_id'] = ['required', 'string'];
|
|
}
|
|
|
|
if ($this->provider === 'doppler') {
|
|
$rules['token'][] = 'regex:/^dp\.(st|sa)\./';
|
|
}
|
|
|
|
if ($this->provider === 'vault') {
|
|
$rules['metadata.base_url'] = ['required', 'url:http,https'];
|
|
$rules['metadata.namespace'] = ['nullable', 'string'];
|
|
}
|
|
|
|
return $rules;
|
|
}
|
|
|
|
protected function messages(): array
|
|
{
|
|
return [
|
|
'capabilities.required' => 'Select at least one capability.',
|
|
'capabilities.min' => 'Select at least one capability.',
|
|
'token.regex' => 'Use a Doppler service token (dp.st.*) or service account token (dp.sa.*).',
|
|
];
|
|
}
|
|
|
|
public function addToken(IntegrationTokenValidator $validator, CloudflareDnsProvider $cloudflare): void
|
|
{
|
|
$validated = $this->validate();
|
|
$metadata = array_filter(data_get($validated, 'metadata', []), fn ($value) => filled($value));
|
|
if ($validated['provider'] === 'cloudflare' && ! $validated['automaticDns']) {
|
|
$metadata['automatic_dns'] = false;
|
|
}
|
|
|
|
try {
|
|
if (! $validator->validate($validated['provider'], $validated['token'], $validated['capabilities'], $metadata)) {
|
|
$this->dispatch('error', $validator->errorMessage($validated['provider']));
|
|
|
|
return;
|
|
}
|
|
|
|
$integrationToken = DB::transaction(function () use ($validated, $metadata, $cloudflare): IntegrationToken {
|
|
$token = IntegrationToken::query()->create([
|
|
'provider' => $validated['provider'], 'name' => $validated['name'], 'token' => $validated['token'],
|
|
'capabilities' => $validated['capabilities'], 'metadata' => $metadata ?: null, 'team_id' => currentTeam()->id,
|
|
]);
|
|
if ($token->provider === 'cloudflare') {
|
|
$cloudflare->syncZones($token);
|
|
}
|
|
|
|
return $token;
|
|
});
|
|
|
|
auditLog('ui.integration_token.created', [
|
|
'team_id' => currentTeam()->id,
|
|
'integration_token_uuid' => $integrationToken->uuid,
|
|
'integration_token_name' => $integrationToken->name,
|
|
'provider' => $integrationToken->provider,
|
|
]);
|
|
|
|
$this->reset(['name', 'token']);
|
|
$this->dispatch('integrationTokenAdded')->to(IntegrationTokens::class);
|
|
|
|
if ($this->modal_mode) {
|
|
$this->dispatch('close-modal');
|
|
}
|
|
|
|
$this->dispatch('success', 'Integration token added successfully.');
|
|
} catch (\Throwable $e) {
|
|
handleError($e, $this);
|
|
}
|
|
}
|
|
|
|
public function render()
|
|
{
|
|
return view('livewire.security.integration-token-form');
|
|
}
|
|
}
|