Return 400 bad request codes for webhooks when attachment or text is too long (#4879)
Этот коммит содержится в:
коммит произвёл
enahum
родитель
53847af2c4
Коммит
15638d7405
@@ -7,6 +7,7 @@ import (
|
|||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
"unicode/utf8"
|
||||||
|
|
||||||
l4g "github.com/alecthomas/log4go"
|
l4g "github.com/alecthomas/log4go"
|
||||||
"github.com/gorilla/mux"
|
"github.com/gorilla/mux"
|
||||||
@@ -387,18 +388,35 @@ func incomingWebhook(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
text := parsedRequest.Text
|
text := parsedRequest.Text
|
||||||
if len(text) == 0 && parsedRequest.Attachments == nil {
|
if len(text) == 0 && parsedRequest.Attachments == nil {
|
||||||
c.Err = model.NewLocAppError("incomingWebhook", "web.incoming_webhook.text.app_error", nil, "")
|
c.Err = model.NewLocAppError("incomingWebhook", "web.incoming_webhook.text.app_error", nil, "")
|
||||||
|
c.Err.StatusCode = http.StatusBadRequest
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
textSize := utf8.RuneCountInString(text)
|
||||||
|
if textSize > model.POST_MESSAGE_MAX_RUNES {
|
||||||
|
c.Err = model.NewLocAppError("incomingWebhook", "web.incoming_webhook.text.length.app_error", map[string]interface{}{"Max": model.POST_MESSAGE_MAX_RUNES, "Actual": textSize}, "")
|
||||||
|
c.Err.StatusCode = http.StatusBadRequest
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
channelName := parsedRequest.ChannelName
|
channelName := parsedRequest.ChannelName
|
||||||
webhookType := parsedRequest.Type
|
webhookType := parsedRequest.Type
|
||||||
|
|
||||||
//attachments is in here for slack compatibility
|
// attachments is in here for slack compatibility
|
||||||
if parsedRequest.Attachments != nil {
|
if parsedRequest.Attachments != nil {
|
||||||
if len(parsedRequest.Props) == 0 {
|
if len(parsedRequest.Props) == 0 {
|
||||||
parsedRequest.Props = make(model.StringInterface)
|
parsedRequest.Props = make(model.StringInterface)
|
||||||
}
|
}
|
||||||
parsedRequest.Props["attachments"] = parsedRequest.Attachments
|
parsedRequest.Props["attachments"] = parsedRequest.Attachments
|
||||||
|
|
||||||
|
attachmentSize := utf8.RuneCountInString(model.StringInterfaceToJson(parsedRequest.Props))
|
||||||
|
// Minus 100 to leave room for setting post type in the Props
|
||||||
|
if attachmentSize > model.POST_PROPS_MAX_RUNES-100 {
|
||||||
|
c.Err = model.NewLocAppError("incomingWebhook", "web.incoming_webhook.attachment.app_error", map[string]interface{}{"Max": model.POST_PROPS_MAX_RUNES - 100, "Actual": attachmentSize}, "")
|
||||||
|
c.Err.StatusCode = http.StatusBadRequest
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
webhookType = model.POST_SLACK_ATTACHMENT
|
webhookType = model.POST_SLACK_ATTACHMENT
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"github.com/mattermost/platform/model"
|
"github.com/mattermost/platform/model"
|
||||||
"github.com/mattermost/platform/utils"
|
"github.com/mattermost/platform/utils"
|
||||||
|
"net/http"
|
||||||
"testing"
|
"testing"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -646,10 +647,56 @@ func TestIncomingWebhooks(t *testing.T) {
|
|||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
if _, err := Client.DoPost(url, "{\"text\":\"\"}", "application/json"); err == nil {
|
if _, err := Client.DoPost(url, "{\"text\":\"\"}", "application/json"); err == nil || err.StatusCode != http.StatusBadRequest {
|
||||||
t.Fatal("should have failed - no text")
|
t.Fatal("should have failed - no text")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
tooLongText := ""
|
||||||
|
for i := 0; i < 8200; i++ {
|
||||||
|
tooLongText += "a"
|
||||||
|
}
|
||||||
|
|
||||||
|
if _, err := Client.DoPost(url, "{\"text\":\""+tooLongText+"\"}", "application/json"); err == nil || err.StatusCode != http.StatusBadRequest {
|
||||||
|
t.Fatal("should have failed - text too long")
|
||||||
|
}
|
||||||
|
|
||||||
|
attachmentPayload = `{
|
||||||
|
"text": "this is a test",
|
||||||
|
"attachments": [
|
||||||
|
{
|
||||||
|
"fallback": "Required plain-text summary of the attachment.",
|
||||||
|
|
||||||
|
"color": "#36a64f",
|
||||||
|
|
||||||
|
"pretext": "Optional text that appears above the attachment block",
|
||||||
|
|
||||||
|
"author_name": "Bobby Tables",
|
||||||
|
"author_link": "http://flickr.com/bobby/",
|
||||||
|
"author_icon": "http://flickr.com/icons/bobby.jpg",
|
||||||
|
|
||||||
|
"title": "Slack API Documentation",
|
||||||
|
"title_link": "https://api.slack.com/",
|
||||||
|
|
||||||
|
"text": "` + tooLongText + `",
|
||||||
|
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"title": "Priority",
|
||||||
|
"value": "High",
|
||||||
|
"short": false
|
||||||
|
}
|
||||||
|
],
|
||||||
|
|
||||||
|
"image_url": "http://my-website.com/path/to/image.jpg",
|
||||||
|
"thumb_url": "http://example.com/path/to/thumb.png"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}`
|
||||||
|
|
||||||
|
if _, err := Client.DoPost(url, attachmentPayload, "application/json"); err == nil || err.StatusCode != http.StatusBadRequest {
|
||||||
|
t.Fatal("should have failed with bad request - attachment too long")
|
||||||
|
}
|
||||||
|
|
||||||
utils.Cfg.ServiceSettings.EnableIncomingWebhooks = false
|
utils.Cfg.ServiceSettings.EnableIncomingWebhooks = false
|
||||||
|
|
||||||
if _, err := Client.DoPost(url, "{\"text\":\"this is a test\"}", "application/json"); err == nil {
|
if _, err := Client.DoPost(url, "{\"text\":\"this is a test\"}", "application/json"); err == nil {
|
||||||
|
|||||||
@@ -5375,6 +5375,14 @@
|
|||||||
"id": "web.incoming_webhook.text.app_error",
|
"id": "web.incoming_webhook.text.app_error",
|
||||||
"translation": "No text specified"
|
"translation": "No text specified"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "web.incoming_webhook.text.length.app_error",
|
||||||
|
"translation": "Maximum text length is {{.Max}} characters, received size is {{.Actual}}"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "web.incoming_webhook.attachment.app_error",
|
||||||
|
"translation": "Maximum attachments length is {{.Max}} characters, received size is {{.Actual}}"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "web.incoming_webhook.user.app_error",
|
"id": "web.incoming_webhook.user.app_error",
|
||||||
"translation": "Couldn't find the user"
|
"translation": "Couldn't find the user"
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user