Restricted cloud settings (#15528)
Co-authored-by: Mattermod <mattermod@users.noreply.github.com>
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
1d2220141e
Коммит
43ed6ad690
@@ -270,6 +270,11 @@ func getLogs(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
auditRec := c.MakeAuditRecord("getLogs", audit.Fail)
|
auditRec := c.MakeAuditRecord("getLogs", audit.Fail)
|
||||||
defer c.LogAuditRec(auditRec)
|
defer c.LogAuditRec(auditRec)
|
||||||
|
|
||||||
|
if *c.App.Config().ExperimentalSettings.RestrictSystemAdmin {
|
||||||
|
c.Err = model.NewAppError("getLogs", "api.restricted_system_admin", nil, "", http.StatusForbidden)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
if !c.App.SessionHasPermissionTo(*c.App.Session(), model.PERMISSION_SYSCONSOLE_READ_REPORTING) {
|
if !c.App.SessionHasPermissionTo(*c.App.Session(), model.PERMISSION_SYSCONSOLE_READ_REPORTING) {
|
||||||
c.SetPermissionError(model.PERMISSION_SYSCONSOLE_READ_REPORTING)
|
c.SetPermissionError(model.PERMISSION_SYSCONSOLE_READ_REPORTING)
|
||||||
return
|
return
|
||||||
|
|||||||
@@ -277,6 +277,12 @@ func TestGetLogs(t *testing.T) {
|
|||||||
require.NotEmpty(t, logs, "should not be empty")
|
require.NotEmpty(t, logs, "should not be empty")
|
||||||
})
|
})
|
||||||
|
|
||||||
|
th.TestForSystemAdminAndLocal(t, func(t *testing.T, c *model.Client4) {
|
||||||
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.ExperimentalSettings.RestrictSystemAdmin = true })
|
||||||
|
_, resp := th.Client.GetLogs(0, 10)
|
||||||
|
CheckForbiddenStatus(t, resp)
|
||||||
|
})
|
||||||
|
|
||||||
_, resp := th.Client.GetLogs(0, 10)
|
_, resp := th.Client.GetLogs(0, 10)
|
||||||
CheckForbiddenStatus(t, resp)
|
CheckForbiddenStatus(t, resp)
|
||||||
|
|
||||||
|
|||||||
@@ -2536,7 +2536,7 @@ type PluginState struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type PluginSettings struct {
|
type PluginSettings struct {
|
||||||
Enable *bool `access:"plugins"`
|
Enable *bool `access:"plugins,write_restrictable"`
|
||||||
EnableUploads *bool `access:"plugins,write_restrictable"`
|
EnableUploads *bool `access:"plugins,write_restrictable"`
|
||||||
AllowInsecureDownloadUrl *bool `access:"plugins,write_restrictable"`
|
AllowInsecureDownloadUrl *bool `access:"plugins,write_restrictable"`
|
||||||
EnableHealthCheck *bool `access:"plugins,write_restrictable"`
|
EnableHealthCheck *bool `access:"plugins,write_restrictable"`
|
||||||
@@ -2544,12 +2544,12 @@ type PluginSettings struct {
|
|||||||
ClientDirectory *string `access:"plugins,write_restrictable"`
|
ClientDirectory *string `access:"plugins,write_restrictable"`
|
||||||
Plugins map[string]map[string]interface{} `access:"plugins"`
|
Plugins map[string]map[string]interface{} `access:"plugins"`
|
||||||
PluginStates map[string]*PluginState `access:"plugins"`
|
PluginStates map[string]*PluginState `access:"plugins"`
|
||||||
EnableMarketplace *bool `access:"plugins"`
|
EnableMarketplace *bool `access:"plugins,write_restrictable"`
|
||||||
EnableRemoteMarketplace *bool `access:"plugins"`
|
EnableRemoteMarketplace *bool `access:"plugins,write_restrictable"`
|
||||||
AutomaticPrepackagedPlugins *bool `access:"plugins"`
|
AutomaticPrepackagedPlugins *bool `access:"plugins,write_restrictable"`
|
||||||
RequirePluginSignature *bool `access:"plugins"`
|
RequirePluginSignature *bool `access:"plugins,write_restrictable"`
|
||||||
MarketplaceUrl *string `access:"plugins"`
|
MarketplaceUrl *string `access:"plugins,write_restrictable"`
|
||||||
SignaturePublicKeyFiles []string `access:"plugins"`
|
SignaturePublicKeyFiles []string `access:"plugins,write_restrictable"`
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *PluginSettings) SetDefaults(ls LogSettings) {
|
func (s *PluginSettings) SetDefaults(ls LogSettings) {
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user