[MM-37716] Drop support for LHS specific bot icons (#18087)

Этот коммит содержится в:
Ben Schumacher
2021-08-12 00:27:35 +02:00
коммит произвёл GitHub
родитель 99bb6084b3
Коммит 225565f412
13 изменённых файлов: 0 добавлений и 1013 удалений

Просмотреть файл

@@ -5,9 +5,6 @@ package api4
import (
"encoding/json"
"fmt"
"io"
"io/ioutil"
"net/http"
"strconv"
@@ -25,10 +22,6 @@ func (api *API) InitBot() {
api.BaseRoutes.Bot.Handle("/enable", api.ApiSessionRequired(enableBot)).Methods("POST")
api.BaseRoutes.Bot.Handle("/convert_to_user", api.ApiSessionRequired(convertBotToUser)).Methods("POST")
api.BaseRoutes.Bot.Handle("/assign/{user_id:[A-Za-z0-9]+}", api.ApiSessionRequired(assignBot)).Methods("POST")
api.BaseRoutes.Bot.Handle("/icon", api.ApiSessionRequiredTrustRequester(getBotIconImage)).Methods("GET")
api.BaseRoutes.Bot.Handle("/icon", api.ApiSessionRequired(setBotIconImage)).Methods("POST")
api.BaseRoutes.Bot.Handle("/icon", api.ApiSessionRequired(deleteBotIconImage)).Methods("DELETE")
}
func createBot(c *Context, w http.ResponseWriter, r *http.Request) {
@@ -274,128 +267,6 @@ func assignBot(c *Context, w http.ResponseWriter, _ *http.Request) {
}
}
func getBotIconImage(c *Context, w http.ResponseWriter, r *http.Request) {
c.RequireBotUserId()
if c.Err != nil {
return
}
botUserId := c.Params.BotUserId
canSee, err := c.App.UserCanSeeOtherUser(c.AppContext.Session().UserId, botUserId)
if err != nil {
c.Err = err
return
}
if !canSee {
c.SetPermissionError(model.PermissionViewMembers)
return
}
img, err := c.App.GetBotIconImage(botUserId)
if err != nil {
c.Err = err
return
}
user, err := c.App.GetUser(botUserId)
if err != nil {
c.Err = err
return
}
etag := strconv.FormatInt(user.LastPictureUpdate, 10)
if c.HandleEtag(etag, "Get Icon Image", w, r) {
return
}
w.Header().Set("Cache-Control", fmt.Sprintf("max-age=%v, private", 24*60*60)) // 24 hrs
w.Header().Set(model.HeaderEtagServer, etag)
w.Header().Set("Content-Type", "image/svg+xml")
w.Write(img)
}
func setBotIconImage(c *Context, w http.ResponseWriter, r *http.Request) {
defer io.Copy(ioutil.Discard, r.Body)
c.RequireBotUserId()
if c.Err != nil {
return
}
botUserId := c.Params.BotUserId
auditRec := c.MakeAuditRecord("setBotIconImage", audit.Fail)
defer c.LogAuditRec(auditRec)
auditRec.AddMeta("bot_id", botUserId)
if err := c.App.SessionHasPermissionToManageBot(*c.AppContext.Session(), botUserId); err != nil {
c.Err = err
return
}
if r.ContentLength > *c.App.Config().FileSettings.MaxFileSize {
c.Err = model.NewAppError("setBotIconImage", "api.bot.set_bot_icon_image.too_large.app_error", nil, "", http.StatusRequestEntityTooLarge)
return
}
if err := r.ParseMultipartForm(*c.App.Config().FileSettings.MaxFileSize); err != nil {
c.Err = model.NewAppError("setBotIconImage", "api.bot.set_bot_icon_image.parse.app_error", nil, err.Error(), http.StatusInternalServerError)
return
}
m := r.MultipartForm
imageArray, ok := m.File["image"]
if !ok {
c.Err = model.NewAppError("setBotIconImage", "api.bot.set_bot_icon_image.no_file.app_error", nil, "", http.StatusBadRequest)
return
}
if len(imageArray) <= 0 {
c.Err = model.NewAppError("setBotIconImage", "api.bot.set_bot_icon_image.array.app_error", nil, "", http.StatusBadRequest)
return
}
imageData := imageArray[0]
if err := c.App.SetBotIconImageFromMultiPartFile(botUserId, imageData); err != nil {
c.Err = err
return
}
auditRec.Success()
c.LogAudit("")
ReturnStatusOK(w)
}
func deleteBotIconImage(c *Context, w http.ResponseWriter, r *http.Request) {
defer io.Copy(ioutil.Discard, r.Body)
c.RequireBotUserId()
if c.Err != nil {
return
}
botUserId := c.Params.BotUserId
auditRec := c.MakeAuditRecord("deleteBotIconImage", audit.Fail)
defer c.LogAuditRec(auditRec)
auditRec.AddMeta("bot_id", botUserId)
if err := c.App.SessionHasPermissionToManageBot(*c.AppContext.Session(), botUserId); err != nil {
c.Err = err
return
}
if err := c.App.DeleteBotIconImage(botUserId); err != nil {
c.Err = err
return
}
auditRec.Success()
c.LogAudit("")
ReturnStatusOK(w)
}
func convertBotToUser(c *Context, w http.ResponseWriter, r *http.Request) {
c.RequireBotUserId()
if c.Err != nil {

Просмотреть файл

@@ -5,19 +5,13 @@ package api4
import (
"encoding/json"
"fmt"
"io/ioutil"
"net/http"
"os"
"path/filepath"
"strings"
"testing"
"github.com/stretchr/testify/require"
"github.com/mattermost/mattermost-server/v6/model"
"github.com/mattermost/mattermost-server/v6/utils/fileutils"
"github.com/mattermost/mattermost-server/v6/utils/testutils"
)
func TestCreateBot(t *testing.T) {
@@ -1212,202 +1206,6 @@ func TestAssignBot(t *testing.T) {
})
}
func TestSetBotIconImage(t *testing.T) {
th := Setup(t).InitBasic()
defer th.TearDown()
user := th.BasicUser
defer th.RestoreDefaultRolePermissions(th.SaveDefaultRolePermissions())
th.AddPermissionToRole(model.PermissionCreateBot.Id, model.SystemUserRoleId)
th.AddPermissionToRole(model.PermissionManageBots.Id, model.SystemUserRoleId)
th.AddPermissionToRole(model.PermissionReadBots.Id, model.SystemUserRoleId)
th.App.UpdateConfig(func(cfg *model.Config) {
*cfg.ServiceSettings.EnableBotAccountCreation = true
})
bot := &model.Bot{
Username: GenerateTestUsername(),
Description: "bot",
}
bot, resp := th.Client.CreateBot(bot)
CheckCreatedStatus(t, resp)
defer th.App.PermanentDeleteBot(bot.UserId)
badData, err := testutils.ReadTestFile("test.png")
require.NoError(t, err)
goodData, err := testutils.ReadTestFile("test.svg")
require.NoError(t, err)
// SetBotIconImage only allowed for bots
_, resp = th.SystemAdminClient.SetBotIconImage(user.Id, goodData)
CheckNotFoundStatus(t, resp)
// png/jpg is not allowed
ok, resp := th.Client.SetBotIconImage(bot.UserId, badData)
require.False(t, ok, "Should return false, set icon image only allows svg")
CheckBadRequestStatus(t, resp)
ok, resp = th.Client.SetBotIconImage(model.NewId(), badData)
require.False(t, ok, "Should return false, set icon image not allowed")
CheckNotFoundStatus(t, resp)
_, resp = th.Client.SetBotIconImage(bot.UserId, goodData)
CheckNoError(t, resp)
// status code returns either forbidden or unauthorized
// note: forbidden is set as default at Client4.SetBotIconImage when request is terminated early by server
th.Client.Logout()
_, resp = th.Client.SetBotIconImage(bot.UserId, badData)
if resp.StatusCode == http.StatusForbidden {
CheckForbiddenStatus(t, resp)
} else if resp.StatusCode == http.StatusUnauthorized {
CheckUnauthorizedStatus(t, resp)
} else {
require.Fail(t, "Should have failed either forbidden or unauthorized")
}
_, resp = th.SystemAdminClient.SetBotIconImage(bot.UserId, goodData)
CheckNoError(t, resp)
fpath := fmt.Sprintf("/bots/%v/icon.svg", bot.UserId)
actualData, appErr := th.App.ReadFile(fpath)
require.Nil(t, appErr)
require.NotNil(t, actualData)
require.Equal(t, goodData, actualData)
info := &model.FileInfo{Path: fpath}
err = th.cleanupTestFile(info)
require.NoError(t, err)
}
func TestGetBotIconImage(t *testing.T) {
th := Setup(t)
defer th.TearDown()
defer th.RestoreDefaultRolePermissions(th.SaveDefaultRolePermissions())
th.AddPermissionToRole(model.PermissionCreateBot.Id, model.SystemUserRoleId)
th.AddPermissionToRole(model.PermissionManageBots.Id, model.SystemUserRoleId)
th.AddPermissionToRole(model.PermissionReadBots.Id, model.SystemUserRoleId)
th.App.UpdateConfig(func(cfg *model.Config) {
*cfg.ServiceSettings.EnableBotAccountCreation = true
})
bot := &model.Bot{
Username: GenerateTestUsername(),
Description: "bot",
}
bot, resp := th.Client.CreateBot(bot)
CheckCreatedStatus(t, resp)
defer th.App.PermanentDeleteBot(bot.UserId)
// Get icon image for user with no icon
data, resp := th.Client.GetBotIconImage(bot.UserId)
CheckNotFoundStatus(t, resp)
require.Equal(t, 0, len(data))
// Set an icon image
path, _ := fileutils.FindDir("tests")
svgFile, fileErr := os.Open(filepath.Join(path, "test.svg"))
require.NoError(t, fileErr)
defer svgFile.Close()
expectedData, err := ioutil.ReadAll(svgFile)
require.NoError(t, err)
svgFile.Seek(0, 0)
fpath := fmt.Sprintf("/bots/%v/icon.svg", bot.UserId)
_, appErr := th.App.WriteFile(svgFile, fpath)
require.Nil(t, appErr)
data, resp = th.Client.GetBotIconImage(bot.UserId)
CheckNoError(t, resp)
require.Equal(t, expectedData, data)
_, resp = th.Client.GetBotIconImage("junk")
CheckBadRequestStatus(t, resp)
_, resp = th.Client.GetBotIconImage(model.NewId())
CheckNotFoundStatus(t, resp)
th.Client.Logout()
_, resp = th.Client.GetBotIconImage(bot.UserId)
CheckUnauthorizedStatus(t, resp)
_, resp = th.SystemAdminClient.GetBotIconImage(bot.UserId)
CheckNoError(t, resp)
info := &model.FileInfo{Path: "/bots/" + bot.UserId + "/icon.svg"}
err = th.cleanupTestFile(info)
require.NoError(t, err)
}
func TestDeleteBotIconImage(t *testing.T) {
th := Setup(t)
defer th.TearDown()
defer th.RestoreDefaultRolePermissions(th.SaveDefaultRolePermissions())
th.AddPermissionToRole(model.PermissionCreateBot.Id, model.SystemUserRoleId)
th.AddPermissionToRole(model.PermissionManageBots.Id, model.SystemUserRoleId)
th.AddPermissionToRole(model.PermissionReadBots.Id, model.SystemUserRoleId)
th.App.UpdateConfig(func(cfg *model.Config) {
*cfg.ServiceSettings.EnableBotAccountCreation = true
})
bot := &model.Bot{
Username: GenerateTestUsername(),
Description: "bot",
}
bot, resp := th.Client.CreateBot(bot)
CheckCreatedStatus(t, resp)
defer th.App.PermanentDeleteBot(bot.UserId)
// Get icon image for user with no icon
data, resp := th.Client.GetBotIconImage(bot.UserId)
CheckNotFoundStatus(t, resp)
require.Equal(t, 0, len(data))
// Set an icon image
svgData, err := testutils.ReadTestFile("test.svg")
require.NoError(t, err)
_, resp = th.Client.SetBotIconImage(bot.UserId, svgData)
CheckNoError(t, resp)
fpath := fmt.Sprintf("/bots/%v/icon.svg", bot.UserId)
exists, appErr := th.App.FileExists(fpath)
require.Nil(t, appErr)
require.True(t, exists, "icon.svg needs to exist for the user")
data, resp = th.Client.GetBotIconImage(bot.UserId)
CheckNoError(t, resp)
require.Equal(t, svgData, data)
success, resp := th.Client.DeleteBotIconImage("junk")
CheckBadRequestStatus(t, resp)
require.False(t, success)
success, resp = th.Client.DeleteBotIconImage(model.NewId())
CheckNotFoundStatus(t, resp)
require.False(t, success)
success, resp = th.Client.DeleteBotIconImage(bot.UserId)
CheckNoError(t, resp)
require.True(t, success)
th.Client.Logout()
success, resp = th.Client.DeleteBotIconImage(bot.UserId)
CheckUnauthorizedStatus(t, resp)
require.False(t, success)
exists, appErr = th.App.FileExists(fpath)
require.Nil(t, appErr)
require.False(t, exists, "icon.svg should not for the user")
}
func TestConvertBotToUser(t *testing.T) {
th := Setup(t).InitBasic()
defer th.TearDown()