Take view archived config into account on users and posts api endpoints (#19014)
* Take view archived config into account on users and posts api endpoints * Move the inChannel check to the top level
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
8588f69850
Коммит
009d02c57a
12
api4/post.go
12
api4/post.go
@@ -182,6 +182,18 @@ func getPostsForChannel(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if !*c.App.Config().TeamSettings.ExperimentalViewArchivedChannels {
|
||||||
|
channel, err := c.App.GetChannel(channelId)
|
||||||
|
if err != nil {
|
||||||
|
c.Err = err
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if channel.DeleteAt != 0 {
|
||||||
|
c.Err = model.NewAppError("Api4.getPostsForChannel", "api.user.view_archived_channels.get_posts_for_channel.app_error", nil, "", http.StatusForbidden)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
var list *model.PostList
|
var list *model.PostList
|
||||||
var err *model.AppError
|
var err *model.AppError
|
||||||
etag := ""
|
etag := ""
|
||||||
|
|||||||
@@ -1202,6 +1202,28 @@ func TestGetPostsForChannel(t *testing.T) {
|
|||||||
require.Equal(t, "", posts.NextPostId, "should return an empty NextPostId")
|
require.Equal(t, "", posts.NextPostId, "should return an empty NextPostId")
|
||||||
require.Equal(t, "", posts.PrevPostId, "should return an empty PrevPostId")
|
require.Equal(t, "", posts.PrevPostId, "should return an empty PrevPostId")
|
||||||
})
|
})
|
||||||
|
|
||||||
|
th.TestForAllClients(t, func(t *testing.T, c *model.Client4) {
|
||||||
|
channel := th.CreatePublicChannel()
|
||||||
|
th.CreatePostWithClient(th.SystemAdminClient, channel)
|
||||||
|
th.SystemAdminClient.DeleteChannel(channel.Id)
|
||||||
|
|
||||||
|
experimentalViewArchivedChannels := *th.App.Config().TeamSettings.ExperimentalViewArchivedChannels
|
||||||
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.TeamSettings.ExperimentalViewArchivedChannels = true })
|
||||||
|
defer th.App.UpdateConfig(func(cfg *model.Config) {
|
||||||
|
*cfg.TeamSettings.ExperimentalViewArchivedChannels = experimentalViewArchivedChannels
|
||||||
|
})
|
||||||
|
|
||||||
|
// the endpoint should work fine when viewing archived channels is enabled
|
||||||
|
_, _, err = c.GetPostsForChannel(channel.Id, 0, 10, "", false)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// the endpoint should return forbidden if viewing archived channels is disabled
|
||||||
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.TeamSettings.ExperimentalViewArchivedChannels = false })
|
||||||
|
_, resp, err = c.GetPostsForChannel(channel.Id, 0, 10, "", false)
|
||||||
|
require.Error(t, err)
|
||||||
|
CheckForbiddenStatus(t, resp)
|
||||||
|
}, "Should forbid to retrieve posts if the channel is archived and users are not allowed to view archived messages")
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetFlaggedPostsForUser(t *testing.T) {
|
func TestGetFlaggedPostsForUser(t *testing.T) {
|
||||||
|
|||||||
15
api4/user.go
15
api4/user.go
@@ -735,6 +735,20 @@ func getUsers(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
var profiles []*model.User
|
var profiles []*model.User
|
||||||
etag := ""
|
etag := ""
|
||||||
|
|
||||||
|
if inChannelId != "" {
|
||||||
|
if !*c.App.Config().TeamSettings.ExperimentalViewArchivedChannels {
|
||||||
|
channel, appErr := c.App.GetChannel(inChannelId)
|
||||||
|
if appErr != nil {
|
||||||
|
c.Err = appErr
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if channel.DeleteAt != 0 {
|
||||||
|
c.Err = model.NewAppError("Api4.getUsersInChannel", "api.user.view_archived_channels.get_users_in_channel.app_error", nil, "", http.StatusForbidden)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if withoutTeamBool, _ := strconv.ParseBool(withoutTeam); withoutTeamBool {
|
if withoutTeamBool, _ := strconv.ParseBool(withoutTeam); withoutTeamBool {
|
||||||
// Use a special permission for now
|
// Use a special permission for now
|
||||||
if !c.App.SessionHasPermissionTo(*c.AppContext.Session(), model.PermissionListUsersWithoutTeam) {
|
if !c.App.SessionHasPermissionTo(*c.AppContext.Session(), model.PermissionListUsersWithoutTeam) {
|
||||||
@@ -784,6 +798,7 @@ func getUsers(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
c.SetPermissionError(model.PermissionReadChannel)
|
c.SetPermissionError(model.PermissionReadChannel)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if sort == "status" {
|
if sort == "status" {
|
||||||
profiles, err = c.App.GetUsersInChannelPageByStatus(userGetOptions, c.IsSystemAdmin())
|
profiles, err = c.App.GetUsersInChannelPageByStatus(userGetOptions, c.IsSystemAdmin())
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -2657,6 +2657,51 @@ func TestGetUsersInChannel(t *testing.T) {
|
|||||||
|
|
||||||
_, _, err = th.SystemAdminClient.GetUsersInChannel(channelId, 0, 60, "")
|
_, _, err = th.SystemAdminClient.GetUsersInChannel(channelId, 0, 60, "")
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
t.Run("Should forbid getting the members of an archived channel if users are not allowed to view archived messages", func(t *testing.T) {
|
||||||
|
th.LoginBasic()
|
||||||
|
channel, _, appErr := th.SystemAdminClient.CreateChannel(&model.Channel{
|
||||||
|
DisplayName: "User Created Channel",
|
||||||
|
Name: model.NewId(),
|
||||||
|
Type: model.ChannelTypeOpen,
|
||||||
|
TeamId: th.BasicTeam.Id,
|
||||||
|
})
|
||||||
|
require.NoError(t, appErr)
|
||||||
|
_, aErr := th.App.AddUserToChannel(th.BasicUser, channel, false)
|
||||||
|
require.Nil(t, aErr)
|
||||||
|
_, aErr = th.App.AddUserToChannel(th.BasicUser2, channel, false)
|
||||||
|
require.Nil(t, aErr)
|
||||||
|
th.SystemAdminClient.DeleteChannel(channel.Id)
|
||||||
|
|
||||||
|
experimentalViewArchivedChannels := *th.App.Config().TeamSettings.ExperimentalViewArchivedChannels
|
||||||
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.TeamSettings.ExperimentalViewArchivedChannels = true })
|
||||||
|
defer th.App.UpdateConfig(func(cfg *model.Config) {
|
||||||
|
*cfg.TeamSettings.ExperimentalViewArchivedChannels = experimentalViewArchivedChannels
|
||||||
|
})
|
||||||
|
|
||||||
|
// the endpoint should work fine for all clients when viewing
|
||||||
|
// archived channels is enabled
|
||||||
|
for _, client := range []*model.Client4{th.SystemAdminClient, th.Client, th.LocalClient} {
|
||||||
|
users, _, userErr := client.GetUsersInChannel(channel.Id, 0, 1000, "")
|
||||||
|
require.NoError(t, userErr)
|
||||||
|
require.Len(t, users, 3)
|
||||||
|
}
|
||||||
|
|
||||||
|
// the endpoint should return forbidden if viewing archived
|
||||||
|
// channels is disabled for all clients but the Local one
|
||||||
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.TeamSettings.ExperimentalViewArchivedChannels = false })
|
||||||
|
for _, client := range []*model.Client4{th.SystemAdminClient, th.Client} {
|
||||||
|
users, resp, userErr := client.GetUsersInChannel(channel.Id, 0, 1000, "")
|
||||||
|
require.Error(t, userErr)
|
||||||
|
require.Len(t, users, 0)
|
||||||
|
CheckForbiddenStatus(t, resp)
|
||||||
|
}
|
||||||
|
|
||||||
|
// local client should be able to get the users still
|
||||||
|
users, _, appErr := th.LocalClient.GetUsersInChannel(channel.Id, 0, 1000, "")
|
||||||
|
require.NoError(t, appErr)
|
||||||
|
require.Len(t, users, 3)
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetUsersNotInChannel(t *testing.T) {
|
func TestGetUsersNotInChannel(t *testing.T) {
|
||||||
|
|||||||
@@ -4251,6 +4251,14 @@
|
|||||||
"id": "api.user.verify_email.token_parse.error",
|
"id": "api.user.verify_email.token_parse.error",
|
||||||
"translation": "Failed to parse token data from email verification"
|
"translation": "Failed to parse token data from email verification"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "api.user.view_archived_channels.get_posts_for_channel.app_error",
|
||||||
|
"translation": "Cannot retrieve posts for an archived channel"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "api.user.view_archived_channels.get_users_in_channel.app_error",
|
||||||
|
"translation": "Cannot retrieve users for an archived channel"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "api.web_socket.connect.upgrade.app_error",
|
"id": "api.web_socket.connect.upgrade.app_error",
|
||||||
"translation": "Failed to upgrade websocket connection."
|
"translation": "Failed to upgrade websocket connection."
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user