MM-10516: Added support for PostActions in ephemeral posts (#10258)
* Added support for PostActions in ephemeral posts The general approach is that we take all the metadata that DoPostAction needs to process client DoPostActionRequests, and store it in a serialized, encrypted Cookie field, in the PostAction struct. The client then must send it back, and it is then used to process PostActions as a fallback top the metadata in the database. This PR adds a new config setting, `ServiceSettings.ActionCookieSecret`. In a cluster environment it must be the same for all instances. - Added type PostActionCookie, and a Cookie string to PostAction. - Added App.AddActionCookiesToPost. - Use App.AddActionCookiesToPost in api4.createEphemeralPost, App.SendEphemeralPost, App.UpdateEphemeralPost. - Added App.DoPostActionWithCookie to process incoming requests with cookies. For backward compatibility, it prefers the metadata in the database; falls back to cookie. - Added plugin.API.UpdateEphemeralPost and plugin.API.DeleteEphemeralPost. - Added App.encryptActionCookie/App.decryptActionCookie. * Style * Fixed an unfortunate typo, tested with matterpoll * minor PR feedback * Fixed uninitialized Context * Fixed another test failure * Fixed permission check * Added api test for DoPostActionWithCookie * Replaced config.ActionCookieSecret with Server.PostActionCookieSecret Modeled after AsymetricSigningKey * style * Set DeleteAt in DeleteEphemeralPost * PR feedback * Removed deadwood comment * Added EXPERIMENTAL comment to the 2 APIs in question
Этот коммит содержится в:
@@ -4,7 +4,9 @@
|
||||
package api4
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"io/ioutil"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
@@ -15,6 +17,82 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
type testHandler struct {
|
||||
t *testing.T
|
||||
}
|
||||
|
||||
func (th *testHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
bb, err := ioutil.ReadAll(r.Body)
|
||||
assert.Nil(th.t, err)
|
||||
assert.NotEmpty(th.t, string(bb))
|
||||
poir := model.PostActionIntegrationRequestFromJson(bytes.NewReader(bb))
|
||||
assert.NotEmpty(th.t, poir.UserId)
|
||||
assert.NotEmpty(th.t, poir.ChannelId)
|
||||
assert.Empty(th.t, poir.TeamId)
|
||||
assert.NotEmpty(th.t, poir.PostId)
|
||||
assert.NotEmpty(th.t, poir.TriggerId)
|
||||
assert.Equal(th.t, "button", poir.Type)
|
||||
assert.Equal(th.t, "test-value", poir.Context["test-key"])
|
||||
w.Write([]byte("{}"))
|
||||
w.WriteHeader(200)
|
||||
}
|
||||
|
||||
func TestPostActionCookies(t *testing.T) {
|
||||
th := Setup().InitBasic()
|
||||
defer th.TearDown()
|
||||
Client := th.Client
|
||||
|
||||
th.App.UpdateConfig(func(cfg *model.Config) {
|
||||
*cfg.ServiceSettings.AllowedUntrustedInternalConnections = "localhost 127.0.0.1"
|
||||
})
|
||||
|
||||
handler := &testHandler{t}
|
||||
server := httptest.NewServer(handler)
|
||||
action := model.PostAction{
|
||||
Id: model.NewId(),
|
||||
Name: "Test-action",
|
||||
Type: model.POST_ACTION_TYPE_BUTTON,
|
||||
Integration: &model.PostActionIntegration{
|
||||
URL: server.URL,
|
||||
Context: map[string]interface{}{
|
||||
"test-key": "test-value",
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
post := &model.Post{
|
||||
Id: model.NewId(),
|
||||
Type: model.POST_EPHEMERAL,
|
||||
UserId: th.BasicUser.Id,
|
||||
ChannelId: th.BasicChannel.Id,
|
||||
CreateAt: model.GetMillis(),
|
||||
UpdateAt: model.GetMillis(),
|
||||
Props: map[string]interface{}{
|
||||
"attachments": []*model.SlackAttachment{
|
||||
{
|
||||
Title: "some-title",
|
||||
TitleLink: "https://some-url.com",
|
||||
Text: "some-text",
|
||||
ImageURL: "https://some-other-url.com",
|
||||
Actions: []*model.PostAction{&action},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
post.GenerateActionIds()
|
||||
assert.Equal(t, 32, len(th.App.PostActionCookieSecret()))
|
||||
post = model.AddPostActionCookies(post, th.App.PostActionCookieSecret())
|
||||
|
||||
ok, resp := Client.DoPostActionWithCookie(post.Id, action.Id, "", action.Cookie)
|
||||
assert.True(t, ok)
|
||||
assert.NotNil(t, resp)
|
||||
assert.Equal(t, 200, resp.StatusCode)
|
||||
assert.Nil(t, resp.Error)
|
||||
assert.NotNil(t, resp.RequestId)
|
||||
assert.NotNil(t, resp.ServerVersion)
|
||||
}
|
||||
|
||||
func TestOpenDialog(t *testing.T) {
|
||||
th := Setup().InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
Ссылка в новой задаче
Block a user