MM-45272: Fix getPostThread permissions (#20565)

Summary
Fix permissions for the the getPostThread API Method.
User can view thread if user is member of the channel
User can view threads in public channels (in the user's team) that they're not a member of, only if compliance export is disabled.

Ticket Link
https://mattermost.atlassian.net/browse/MM-45272
Этот коммит содержится в:
Ashish Bhate
2022-07-28 20:25:20 +05:30
коммит произвёл GitHub
родитель 0ee05ce054
Коммит 04cd6d35e9
3 изменённых файлов: 50 добавлений и 1 удалений

Просмотреть файл

@@ -525,6 +525,35 @@ func getPostThread(c *Context, w http.ResponseWriter, r *http.Request) {
return
}
rPost, err := c.App.GetSinglePost(c.Params.PostId, false)
if err != nil {
c.Err = err
return
}
hasPermission := false
becauseCompliance := false
if c.App.SessionHasPermissionToChannel(c.AppContext, *c.AppContext.Session(), rPost.ChannelId, model.PermissionReadChannel) {
hasPermission = true
} else if channel, cErr := c.App.GetChannel(c.AppContext, rPost.ChannelId); cErr == nil {
if channel.Type == model.ChannelTypeOpen &&
c.App.SessionHasPermissionToTeam(*c.AppContext.Session(), channel.TeamId, model.PermissionReadPublicChannel) {
hasPermission = true
if *c.App.Config().MessageExportSettings.EnableExport {
hasPermission = false
becauseCompliance = true
}
}
}
if !hasPermission {
if becauseCompliance {
c.Err = model.NewAppError("getPostThread", "api.post.compliance_enabled.join_channel_to_view_post", nil, "", http.StatusForbidden)
} else {
c.SetPermissionError(model.PermissionReadChannel)
}
return
}
// For now, by default we return all items unless it's set to maintain
// backwards compatibility with mobile. But when the next ESR passes, we need to
// change this to web.PerPageDefault.

Просмотреть файл

@@ -2191,10 +2191,26 @@ func TestGetPostThread(t *testing.T) {
client.RemoveUserFromChannel(th.BasicChannel.Id, th.BasicUser.Id)
// Channel is public, should be able to read post
messageExportEnabled := *th.App.Config().MessageExportSettings.EnableExport
// Channel is public, and compliance export is OFF, should be able to read post
th.App.UpdateConfig(func(cfg *model.Config) {
*cfg.MessageExportSettings.EnableExport = false
})
_, _, err = client.GetPostThread(th.BasicPost.Id, "", false)
require.NoError(t, err)
// channel is public, and compliance export is ON, should NOT be able to read post
th.App.UpdateConfig(func(cfg *model.Config) {
*cfg.MessageExportSettings.EnableExport = true
})
_, resp, err = client.GetPostThread(th.BasicPost.Id, "", false)
require.Error(t, err)
CheckForbiddenStatus(t, resp)
th.App.UpdateConfig(func(cfg *model.Config) {
*cfg.MessageExportSettings.EnableExport = messageExportEnabled
})
privatePost := th.CreatePostWithClient(client, th.BasicPrivateChannel)
_, _, err = client.GetPostThread(privatePost.Id, "", false)

Просмотреть файл

@@ -2237,6 +2237,10 @@
"id": "api.post.check_for_out_of_channel_mentions.message.one",
"translation": "@{{.Username}} did not get notified by this mention because they are not in the channel."
},
{
"id": "api.post.compliance_enabled.join_channel_to_view_post",
"translation": "Due to compliance rules configured on this instance the channel must be joined before its posts can be read."
},
{
"id": "api.post.create_post.can_not_post_to_deleted.error",
"translation": "Can not post to deleted channel."