Merge pull request #474 from mattermost/PL-4
Fixes PL-1 and PL-3 Restricting team creation
Этот коммит содержится в:
42
api/team.go
42
api/team.go
@@ -44,6 +44,10 @@ func signupTeam(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if !isTreamCreationAllowed(c, email) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
subjectPage := NewServerTemplatePage("signup_team_subject", c.GetSiteURL())
|
subjectPage := NewServerTemplatePage("signup_team_subject", c.GetSiteURL())
|
||||||
bodyPage := NewServerTemplatePage("signup_team_body", c.GetSiteURL())
|
bodyPage := NewServerTemplatePage("signup_team_body", c.GetSiteURL())
|
||||||
bodyPage.Props["TourUrl"] = utils.Cfg.TeamSettings.TourLink
|
bodyPage.Props["TourUrl"] = utils.Cfg.TeamSettings.TourLink
|
||||||
@@ -89,6 +93,11 @@ func createTeamFromSignup(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
c.Err = err
|
c.Err = err
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if !isTreamCreationAllowed(c, teamSignup.Team.Email) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
teamSignup.Team.Id = ""
|
teamSignup.Team.Id = ""
|
||||||
|
|
||||||
password := teamSignup.User.Password
|
password := teamSignup.User.Password
|
||||||
@@ -169,6 +178,10 @@ func createTeam(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if !isTreamCreationAllowed(c, team.Email) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
if utils.Cfg.ServiceSettings.Mode != utils.MODE_DEV {
|
if utils.Cfg.ServiceSettings.Mode != utils.MODE_DEV {
|
||||||
c.Err = model.NewAppError("createTeam", "The mode does not allow network creation without a valid invite", "")
|
c.Err = model.NewAppError("createTeam", "The mode does not allow network creation without a valid invite", "")
|
||||||
return
|
return
|
||||||
@@ -196,6 +209,35 @@ func createTeam(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func isTreamCreationAllowed(c *Context, email string) bool {
|
||||||
|
|
||||||
|
email = strings.ToLower(email)
|
||||||
|
|
||||||
|
if utils.Cfg.TeamSettings.DisableTeamCreation {
|
||||||
|
c.Err = model.NewAppError("isTreamCreationAllowed", "Team creation has been disabled. Please ask your systems administrator for details.", "")
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// commas and @ signs are optional
|
||||||
|
// can be in the form of "@corp.mattermost.com, mattermost.com mattermost.org" -> corp.mattermost.com mattermost.com mattermost.org
|
||||||
|
domains := strings.Fields(strings.TrimSpace(strings.ToLower(strings.Replace(strings.Replace(utils.Cfg.TeamSettings.RestrictCreationToDomains, "@", " ", -1), ",", " ", -1))))
|
||||||
|
|
||||||
|
matched := false
|
||||||
|
for _, d := range domains {
|
||||||
|
if strings.HasSuffix(email, "@"+d) {
|
||||||
|
matched = true
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(utils.Cfg.TeamSettings.RestrictCreationToDomains) > 0 && !matched {
|
||||||
|
c.Err = model.NewAppError("isTreamCreationAllowed", "Email must be from a specific domain (e.g. @example.com). Please ask your systems administrator for details.", "")
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
func findTeamByName(c *Context, w http.ResponseWriter, r *http.Request) {
|
func findTeamByName(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||||
|
|
||||||
m := model.MapFromJson(r.Body)
|
m := model.MapFromJson(r.Body)
|
||||||
|
|||||||
@@ -104,6 +104,8 @@
|
|||||||
"HelpLink": "/static/help/configure_links.html",
|
"HelpLink": "/static/help/configure_links.html",
|
||||||
"ReportProblemLink": "/static/help/configure_links.html",
|
"ReportProblemLink": "/static/help/configure_links.html",
|
||||||
"TourLink": "/static/help/configure_links.html",
|
"TourLink": "/static/help/configure_links.html",
|
||||||
"DefaultThemeColor": "#2389D7"
|
"DefaultThemeColor": "#2389D7",
|
||||||
|
"DisableTeamCreation": false,
|
||||||
|
"RestrictCreationToDomains": ""
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -94,6 +94,8 @@
|
|||||||
"HelpLink": "/static/help/configure_links.html",
|
"HelpLink": "/static/help/configure_links.html",
|
||||||
"ReportProblemLink": "/static/help/configure_links.html",
|
"ReportProblemLink": "/static/help/configure_links.html",
|
||||||
"TourLink": "/static/help/configure_links.html",
|
"TourLink": "/static/help/configure_links.html",
|
||||||
"DefaultThemeColor": "#2389D7"
|
"DefaultThemeColor": "#2389D7",
|
||||||
|
"DisableTeamCreation": false,
|
||||||
|
"RestrictCreationToDomains": ""
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -94,6 +94,8 @@
|
|||||||
"HelpLink": "/static/help/configure_links.html",
|
"HelpLink": "/static/help/configure_links.html",
|
||||||
"ReportProblemLink": "/static/help/configure_links.html",
|
"ReportProblemLink": "/static/help/configure_links.html",
|
||||||
"TourLink": "/static/help/configure_links.html",
|
"TourLink": "/static/help/configure_links.html",
|
||||||
"DefaultThemeColor": "#2389D7"
|
"DefaultThemeColor": "#2389D7",
|
||||||
|
"DisableTeamCreation": false,
|
||||||
|
"RestrictCreationToDomains": ""
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -119,6 +119,8 @@ type TeamSettings struct {
|
|||||||
ReportProblemLink string
|
ReportProblemLink string
|
||||||
TourLink string
|
TourLink string
|
||||||
DefaultThemeColor string
|
DefaultThemeColor string
|
||||||
|
DisableTeamCreation bool
|
||||||
|
RestrictCreationToDomains string
|
||||||
}
|
}
|
||||||
|
|
||||||
type Config struct {
|
type Config struct {
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user