Improves validation in getRolesByName endpoint (#25215)
* Improves validation in getRolesByName endpoint * Updates the max constant and fixes linter * Adds a mechanism to split roles in chunks in the webapp client --------- Co-authored-by: Mattermost Build <build@mattermost.com>
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
be24f108e1
Коммит
0e60f3d542
@@ -12,6 +12,8 @@ import (
|
||||
"github.com/mattermost/mattermost/server/v8/channels/audit"
|
||||
)
|
||||
|
||||
const GetRolesByNamesMax = 100
|
||||
|
||||
var notAllowedPermissions = []string{
|
||||
model.PermissionSysconsoleWriteUserManagementSystemRoles.Id,
|
||||
model.PermissionSysconsoleReadUserManagementSystemRoles.Id,
|
||||
@@ -89,6 +91,13 @@ func getRolesByNames(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
if len(rolenames) > GetRolesByNamesMax {
|
||||
c.Err = model.NewAppError("getRolesByNames", "api.roles.get_multiple_by_name_too_many.request_error", map[string]any{
|
||||
"MaxNames": GetRolesByNamesMax,
|
||||
}, "", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
cleanedRoleNames, valid := model.CleanRoleNames(rolenames)
|
||||
if !valid {
|
||||
c.SetInvalidParam("rolename")
|
||||
|
||||
@@ -184,6 +184,18 @@ func TestGetRolesByNames(t *testing.T) {
|
||||
_, _, err = client.GetRolesByNames(context.Background(), []string{model.NewId(), model.NewId(), "", " "})
|
||||
require.NoError(t, err)
|
||||
})
|
||||
|
||||
th.TestForAllClients(t, func(t *testing.T, client *model.Client4) {
|
||||
// too many roles should error with bad request
|
||||
roles := []string{}
|
||||
for i := 0; i < GetRolesByNamesMax+10; i++ {
|
||||
roles = append(roles, role1.Name)
|
||||
}
|
||||
|
||||
_, resp, err := client.GetRolesByNames(context.Background(), roles)
|
||||
require.Error(t, err)
|
||||
CheckBadRequestStatus(t, resp)
|
||||
})
|
||||
}
|
||||
|
||||
func TestPatchRole(t *testing.T) {
|
||||
|
||||
@@ -2682,6 +2682,10 @@
|
||||
"id": "api.restricted_system_admin",
|
||||
"translation": "This action is forbidden to a restricted system admin."
|
||||
},
|
||||
{
|
||||
"id": "api.roles.get_multiple_by_name_too_many.request_error",
|
||||
"translation": "Unable to get that many roles by name. Only {{.MaxNames}} roles can be requested at once."
|
||||
},
|
||||
{
|
||||
"id": "api.roles.patch_roles.license.error",
|
||||
"translation": "Your license does not support advanced permissions."
|
||||
|
||||
Ссылка в новой задаче
Block a user