mirror of
https://github.com/bitwarden/server.git
synced 2025-07-03 09:02:48 -05:00
Merge branch 'main' into ac/ac-1682/ef-migrations
# Conflicts: # src/Sql/dbo/Stored Procedures/Organization_EnableCollectionEnhancements.sql # util/SqliteMigrations/SqliteMigrations.csproj
This commit is contained in:
@ -0,0 +1,50 @@
|
||||
-- Remove old stored procedures and SelectionReadOnlyArray for Flexible Collections
|
||||
-- They have been superseded via their respective _V2 variants and the CollectionAccessSelectionType
|
||||
|
||||
IF OBJECT_ID('[dbo].[CollectionUser_UpdateUsers]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[CollectionUser_UpdateUsers]
|
||||
END
|
||||
GO
|
||||
|
||||
IF OBJECT_ID('[dbo].[Group_UpdateWithCollections]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[Group_UpdateWithCollections]
|
||||
END
|
||||
GO
|
||||
|
||||
IF OBJECT_ID('[dbo].[Collection_UpdateWithGroupsAndUsers]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[Collection_UpdateWithGroupsAndUsers]
|
||||
END
|
||||
GO
|
||||
|
||||
IF OBJECT_ID('[dbo].[OrganizationUser_UpdateWithCollections]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[OrganizationUser_UpdateWithCollections]
|
||||
END
|
||||
GO
|
||||
|
||||
IF OBJECT_ID('[dbo].[Group_CreateWithCollections]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[Group_CreateWithCollections]
|
||||
END
|
||||
GO
|
||||
|
||||
IF OBJECT_ID('[dbo].[OrganizationUser_CreateWithCollections]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[OrganizationUser_CreateWithCollections]
|
||||
END
|
||||
GO
|
||||
|
||||
IF OBJECT_ID('[dbo].[Collection_CreateWithGroupsAndUsers]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP PROCEDURE [dbo].[Collection_CreateWithGroupsAndUsers]
|
||||
END
|
||||
GO
|
||||
|
||||
IF TYPE_ID('[dbo].[SelectionReadOnlyArray]') IS NOT NULL
|
||||
BEGIN
|
||||
DROP TYPE [dbo].[SelectionReadOnlyArray]
|
||||
END
|
||||
GO
|
@ -0,0 +1,156 @@
|
||||
CREATE OR ALTER PROCEDURE [dbo].[Organization_EnableCollectionEnhancements]
|
||||
@OrganizationId UNIQUEIDENTIFIER
|
||||
AS
|
||||
BEGIN
|
||||
SET NOCOUNT ON
|
||||
|
||||
-- Step 1: AccessAll migration for Groups
|
||||
-- Create a temporary table to store the groups with AccessAll = 1
|
||||
SELECT [Id] AS [GroupId], [OrganizationId]
|
||||
INTO #TempGroupsAccessAll
|
||||
FROM [dbo].[Group]
|
||||
WHERE [OrganizationId] = @OrganizationId
|
||||
AND [AccessAll] = 1;
|
||||
|
||||
-- Step 2: AccessAll migration for OrganizationUsers
|
||||
-- Create a temporary table to store the OrganizationUsers with AccessAll = 1
|
||||
SELECT [Id] AS [OrganizationUserId], [OrganizationId]
|
||||
INTO #TempUsersAccessAll
|
||||
FROM [dbo].[OrganizationUser]
|
||||
WHERE [OrganizationId] = @OrganizationId
|
||||
AND [AccessAll] = 1;
|
||||
|
||||
-- Step 3: For all OrganizationUsers with Manager role or 'EditAssignedCollections' permission update their existing CollectionUser rows and insert new rows with [Manage] = 1
|
||||
-- and finally update all OrganizationUsers with Manager role to User role
|
||||
-- Create a temporary table to store the OrganizationUsers with Manager role or 'EditAssignedCollections' permission
|
||||
SELECT ou.[Id] AS [OrganizationUserId],
|
||||
CASE WHEN ou.[Type] = 3 THEN 1 ELSE 0 END AS [IsManager]
|
||||
INTO #TempUserManagers
|
||||
FROM [dbo].[OrganizationUser] ou
|
||||
WHERE ou.[OrganizationId] = @OrganizationId
|
||||
AND (ou.[Type] = 3 OR (ou.[Permissions] IS NOT NULL
|
||||
AND ISJSON(ou.[Permissions]) > 0 AND JSON_VALUE(ou.[Permissions], '$.editAssignedCollections') = 'true'));
|
||||
|
||||
-- Step 4: Bump AccountRevisionDate for all OrganizationUsers updated in the previous steps
|
||||
-- Combine and union the distinct OrganizationUserIds from all steps into a single variable
|
||||
DECLARE @OrgUsersToBump [dbo].[GuidIdArray]
|
||||
INSERT INTO @OrgUsersToBump
|
||||
SELECT DISTINCT [OrganizationUserId] AS Id
|
||||
FROM (
|
||||
-- Step 1
|
||||
SELECT GU.[OrganizationUserId]
|
||||
FROM [dbo].[GroupUser] GU
|
||||
INNER JOIN #TempGroupsAccessAll TG ON GU.[GroupId] = TG.[GroupId]
|
||||
|
||||
UNION
|
||||
|
||||
-- Step 2
|
||||
SELECT [OrganizationUserId]
|
||||
FROM #TempUsersAccessAll
|
||||
|
||||
UNION
|
||||
|
||||
-- Step 3
|
||||
SELECT [OrganizationUserId]
|
||||
FROM #TempUserManagers
|
||||
) AS CombinedOrgUsers;
|
||||
|
||||
BEGIN TRY
|
||||
BEGIN TRANSACTION;
|
||||
-- Step 1
|
||||
-- Update existing rows in [dbo].[CollectionGroup]
|
||||
UPDATE CG
|
||||
SET
|
||||
CG.[ReadOnly] = 0,
|
||||
CG.[HidePasswords] = 0,
|
||||
CG.[Manage] = 0
|
||||
FROM [dbo].[CollectionGroup] CG
|
||||
INNER JOIN [dbo].[Collection] C ON CG.[CollectionId] = C.[Id]
|
||||
INNER JOIN #TempGroupsAccessAll TG ON CG.[GroupId] = TG.[GroupId]
|
||||
WHERE C.[OrganizationId] = TG.[OrganizationId];
|
||||
|
||||
-- Insert new rows into [dbo].[CollectionGroup]
|
||||
INSERT INTO [dbo].[CollectionGroup] ([CollectionId], [GroupId], [ReadOnly], [HidePasswords], [Manage])
|
||||
SELECT C.[Id], TG.[GroupId], 0, 0, 0
|
||||
FROM [dbo].[Collection] C
|
||||
INNER JOIN #TempGroupsAccessAll TG ON C.[OrganizationId] = TG.[OrganizationId]
|
||||
LEFT JOIN [dbo].[CollectionGroup] CG ON CG.[CollectionId] = C.[Id] AND CG.[GroupId] = TG.[GroupId]
|
||||
WHERE CG.[CollectionId] IS NULL;
|
||||
|
||||
-- Update Group to clear AccessAll flag and update RevisionDate
|
||||
UPDATE G
|
||||
SET [AccessAll] = 0, [RevisionDate] = GETUTCDATE()
|
||||
FROM [dbo].[Group] G
|
||||
INNER JOIN #TempGroupsAccessAll TG ON G.[Id] = TG.[GroupId];
|
||||
|
||||
-- Step 2
|
||||
-- Update existing rows in [dbo].[CollectionUser]
|
||||
UPDATE target
|
||||
SET
|
||||
target.[ReadOnly] = 0,
|
||||
target.[HidePasswords] = 0,
|
||||
target.[Manage] = 0
|
||||
FROM [dbo].[CollectionUser] AS target
|
||||
INNER JOIN [dbo].[Collection] AS C ON target.[CollectionId] = C.[Id]
|
||||
INNER JOIN #TempUsersAccessAll AS TU ON C.[OrganizationId] = TU.[OrganizationId] AND target.[OrganizationUserId] = TU.[OrganizationUserId];
|
||||
|
||||
-- Insert new rows into [dbo].[CollectionUser]
|
||||
INSERT INTO [dbo].[CollectionUser] ([CollectionId], [OrganizationUserId], [ReadOnly], [HidePasswords], [Manage])
|
||||
SELECT C.[Id] AS [CollectionId], TU.[OrganizationUserId], 0, 0, 0
|
||||
FROM [dbo].[Collection] C
|
||||
INNER JOIN #TempUsersAccessAll TU ON C.[OrganizationId] = TU.[OrganizationId]
|
||||
LEFT JOIN [dbo].[CollectionUser] target
|
||||
ON target.[CollectionId] = C.[Id] AND target.[OrganizationUserId] = TU.[OrganizationUserId]
|
||||
WHERE target.[CollectionId] IS NULL;
|
||||
|
||||
-- Update OrganizationUser to clear AccessAll flag
|
||||
UPDATE OU
|
||||
SET [AccessAll] = 0, [RevisionDate] = GETUTCDATE()
|
||||
FROM [dbo].[OrganizationUser] OU
|
||||
INNER JOIN #TempUsersAccessAll TU ON OU.[Id] = TU.[OrganizationUserId];
|
||||
|
||||
-- Step 3
|
||||
-- Update [dbo].[CollectionUser] with [Manage] = 1 using the temporary table
|
||||
UPDATE CU
|
||||
SET CU.[ReadOnly] = 0,
|
||||
CU.[HidePasswords] = 0,
|
||||
CU.[Manage] = 1
|
||||
FROM [dbo].[CollectionUser] CU
|
||||
INNER JOIN #TempUserManagers TUM ON CU.[OrganizationUserId] = TUM.[OrganizationUserId];
|
||||
|
||||
-- Insert rows to [dbo].[CollectionUser] with [Manage] = 1 using the temporary table
|
||||
-- This is for orgUsers who are Managers / EditAssignedCollections but have access via a group
|
||||
-- We cannot give the whole group Manage permissions so we have to give them a direct assignment
|
||||
INSERT INTO [dbo].[CollectionUser] ([CollectionId], [OrganizationUserId], [ReadOnly], [HidePasswords], [Manage])
|
||||
SELECT DISTINCT CG.[CollectionId], TUM.[OrganizationUserId], 0, 0, 1
|
||||
FROM [dbo].[CollectionGroup] CG
|
||||
INNER JOIN [dbo].[GroupUser] GU ON CG.[GroupId] = GU.[GroupId]
|
||||
INNER JOIN #TempUserManagers TUM ON GU.[OrganizationUserId] = TUM.[OrganizationUserId]
|
||||
WHERE NOT EXISTS (
|
||||
SELECT 1 FROM [dbo].[CollectionUser] CU
|
||||
WHERE CU.[CollectionId] = CG.[CollectionId] AND CU.[OrganizationUserId] = TUM.[OrganizationUserId]
|
||||
);
|
||||
|
||||
-- Update [dbo].[OrganizationUser] to migrate all OrganizationUsers with Manager role to User role
|
||||
UPDATE OU
|
||||
SET OU.[Type] = 2, OU.[RevisionDate] = GETUTCDATE() -- User
|
||||
FROM [dbo].[OrganizationUser] OU
|
||||
INNER JOIN #TempUserManagers TUM ON ou.[Id] = TUM.[OrganizationUserId]
|
||||
WHERE TUM.[IsManager] = 1; -- Filter for Managers
|
||||
|
||||
-- Step 4
|
||||
-- Execute User_BumpAccountRevisionDateByOrganizationUserIds for the distinct OrganizationUserIds
|
||||
EXEC [dbo].[User_BumpAccountRevisionDateByOrganizationUserIds] @OrgUsersToBump;
|
||||
COMMIT TRANSACTION;
|
||||
END TRY
|
||||
BEGIN CATCH
|
||||
ROLLBACK TRANSACTION;
|
||||
THROW;
|
||||
END CATCH;
|
||||
|
||||
-- Drop the temporary table
|
||||
DROP TABLE #TempGroupsAccessAll;
|
||||
DROP TABLE #TempUsersAccessAll;
|
||||
DROP TABLE #TempUserManagers;
|
||||
END
|
||||
GO
|
@ -0,0 +1,54 @@
|
||||
-- Add columns LimitCollectionCreationDeletion, AllowAdminAccessToAllCollectionItems, FlexibleCollections to view
|
||||
CREATE OR ALTER VIEW [dbo].[ProviderUserProviderOrganizationDetailsView]
|
||||
AS
|
||||
SELECT
|
||||
PU.[UserId],
|
||||
PO.[OrganizationId],
|
||||
O.[Name],
|
||||
O.[Enabled],
|
||||
O.[UsePolicies],
|
||||
O.[UseSso],
|
||||
O.[UseKeyConnector],
|
||||
O.[UseScim],
|
||||
O.[UseGroups],
|
||||
O.[UseDirectory],
|
||||
O.[UseEvents],
|
||||
O.[UseTotp],
|
||||
O.[Use2fa],
|
||||
O.[UseApi],
|
||||
O.[UseResetPassword],
|
||||
O.[SelfHost],
|
||||
O.[UsersGetPremium],
|
||||
O.[UseCustomPermissions],
|
||||
O.[Seats],
|
||||
O.[MaxCollections],
|
||||
O.[MaxStorageGb],
|
||||
O.[Identifier],
|
||||
PO.[Key],
|
||||
O.[PublicKey],
|
||||
O.[PrivateKey],
|
||||
PU.[Status],
|
||||
PU.[Type],
|
||||
PO.[ProviderId],
|
||||
PU.[Id] ProviderUserId,
|
||||
P.[Name] ProviderName,
|
||||
O.[PlanType],
|
||||
O.[LimitCollectionCreationDeletion],
|
||||
O.[AllowAdminAccessToAllCollectionItems],
|
||||
O.[FlexibleCollections]
|
||||
FROM
|
||||
[dbo].[ProviderUser] PU
|
||||
INNER JOIN
|
||||
[dbo].[ProviderOrganization] PO ON PO.[ProviderId] = PU.[ProviderId]
|
||||
INNER JOIN
|
||||
[dbo].[Organization] O ON O.[Id] = PO.[OrganizationId]
|
||||
INNER JOIN
|
||||
[dbo].[Provider] P ON P.[Id] = PU.[ProviderId]
|
||||
GO
|
||||
|
||||
--Manually refresh ProviderOrganizationOrganizationDetailsView
|
||||
IF OBJECT_ID('[dbo].[ProviderUserProviderOrganizationDetails_ReadByUserIdStatus]') IS NOT NULL
|
||||
BEGIN
|
||||
EXECUTE sp_refreshsqlmodule N'[dbo].[ProviderUserProviderOrganizationDetails_ReadByUserIdStatus]';
|
||||
END
|
||||
GO
|
@ -0,0 +1,27 @@
|
||||
CREATE OR ALTER PROCEDURE [dbo].[CipherOrganizationDetails_ReadUnassignedByOrganizationId]
|
||||
@OrganizationId UNIQUEIDENTIFIER
|
||||
AS
|
||||
BEGIN
|
||||
SET NOCOUNT ON
|
||||
|
||||
SELECT
|
||||
C.*,
|
||||
CASE
|
||||
WHEN O.[UseTotp] = 1 THEN 1
|
||||
ELSE 0
|
||||
END [OrganizationUseTotp]
|
||||
FROM
|
||||
[dbo].[CipherView] C
|
||||
LEFT JOIN
|
||||
[dbo].[OrganizationView] O ON O.[Id] = C.[OrganizationId]
|
||||
LEFT JOIN
|
||||
[dbo].[CollectionCipher] CC ON C.[Id] = CC.[CipherId]
|
||||
LEFT JOIN
|
||||
[dbo].[Collection] S ON S.[Id] = CC.[CollectionId]
|
||||
AND S.[OrganizationId] = C.[OrganizationId]
|
||||
WHERE
|
||||
C.[UserId] IS NULL
|
||||
AND C.[OrganizationId] = @OrganizationId
|
||||
AND CC.[CipherId] IS NULL
|
||||
END
|
||||
GO
|
61
util/Migrator/DbScripts/2024-02-12_00_FixGrantSave.sql
Normal file
61
util/Migrator/DbScripts/2024-02-12_00_FixGrantSave.sql
Normal file
@ -0,0 +1,61 @@
|
||||
CREATE OR ALTER PROCEDURE [dbo].[Grant_Save]
|
||||
@Key NVARCHAR(200),
|
||||
@Type NVARCHAR(50),
|
||||
@SubjectId NVARCHAR(200),
|
||||
@SessionId NVARCHAR(100),
|
||||
@ClientId NVARCHAR(200),
|
||||
@Description NVARCHAR(200),
|
||||
@CreationDate DATETIME2,
|
||||
@ExpirationDate DATETIME2,
|
||||
@ConsumedDate DATETIME2,
|
||||
@Data NVARCHAR(MAX)
|
||||
AS
|
||||
BEGIN
|
||||
SET NOCOUNT ON
|
||||
|
||||
-- First, try to update the existing row
|
||||
UPDATE [dbo].[Grant]
|
||||
SET
|
||||
[Type] = @Type,
|
||||
[SubjectId] = @SubjectId,
|
||||
[SessionId] = @SessionId,
|
||||
[ClientId] = @ClientId,
|
||||
[Description] = @Description,
|
||||
[CreationDate] = @CreationDate,
|
||||
[ExpirationDate] = @ExpirationDate,
|
||||
[ConsumedDate] = @ConsumedDate,
|
||||
[Data] = @Data
|
||||
WHERE
|
||||
[Key] = @Key
|
||||
|
||||
-- If no row was updated, insert a new one
|
||||
IF @@ROWCOUNT = 0
|
||||
BEGIN
|
||||
INSERT INTO [dbo].[Grant]
|
||||
(
|
||||
[Key],
|
||||
[Type],
|
||||
[SubjectId],
|
||||
[SessionId],
|
||||
[ClientId],
|
||||
[Description],
|
||||
[CreationDate],
|
||||
[ExpirationDate],
|
||||
[ConsumedDate],
|
||||
[Data]
|
||||
)
|
||||
VALUES
|
||||
(
|
||||
@Key,
|
||||
@Type,
|
||||
@SubjectId,
|
||||
@SessionId,
|
||||
@ClientId,
|
||||
@Description,
|
||||
@CreationDate,
|
||||
@ExpirationDate,
|
||||
@ConsumedDate,
|
||||
@Data
|
||||
)
|
||||
END
|
||||
END
|
Reference in New Issue
Block a user