From 4de81fa94cffabdd5df17723f918505ed5ac0190 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20Espino?= Date: Thu, 30 May 2019 19:23:26 +0200 Subject: [PATCH] MM-15835: correct errors and content types for oauth api calls (#10999) * MM-15835: correct errors and content types for oauth api calls * Addressing PR review comments --- app/oauth.go | 4 ++-- web/handlers.go | 2 +- web/web.go | 15 +++++++++++++++ 3 files changed, 18 insertions(+), 3 deletions(-) diff --git a/app/oauth.go b/app/oauth.go index a05fe1e947..ab419fcbeb 100644 --- a/app/oauth.go +++ b/app/oauth.go @@ -246,7 +246,7 @@ func (a *App) GetOAuthAccessTokenForCodeFlow(clientId, grantType, redirectUri, c var authData *model.AuthData result := <-a.Srv.Store.OAuth().GetAuthData(code) if result.Err != nil { - return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.expired_code.app_error", nil, "", http.StatusInternalServerError) + return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.expired_code.app_error", nil, "", http.StatusBadRequest) } authData = result.Data.(*model.AuthData) @@ -267,7 +267,7 @@ func (a *App) GetOAuthAccessTokenForCodeFlow(clientId, grantType, redirectUri, c result = <-a.Srv.Store.OAuth().GetPreviousAccessData(user.Id, clientId) if result.Err != nil { - return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.internal.app_error", nil, "", http.StatusInternalServerError) + return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.internal.app_error", nil, "", http.StatusBadRequest) } if result.Data != nil { diff --git a/web/handlers.go b/web/handlers.go index 71ad6af03e..cfc02650f0 100644 --- a/web/handlers.go +++ b/web/handlers.go @@ -195,7 +195,7 @@ func (h Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) { c.Err.IsOAuth = false } - if IsApiCall(c.App, r) || IsWebhookCall(c.App, r) || len(r.Header.Get("X-Mobile-App")) > 0 { + if IsApiCall(c.App, r) || IsWebhookCall(c.App, r) || IsOAuthApiCall(c.App, r) || len(r.Header.Get("X-Mobile-App")) > 0 { w.WriteHeader(c.Err.StatusCode) w.Write([]byte(c.Err.ToJson())) } else { diff --git a/web/web.go b/web/web.go index 9e3e46ad19..1e1499c0d6 100644 --- a/web/web.go +++ b/web/web.go @@ -86,6 +86,21 @@ func IsWebhookCall(a *app.App, r *http.Request) bool { return strings.HasPrefix(r.URL.Path, path.Join(subpath, "hooks")+"/") } +func IsOAuthApiCall(config configservice.ConfigService, r *http.Request) bool { + subpath, _ := utils.GetSubpathFromConfig(config.Config()) + + if r.Method == "POST" && r.URL.Path == path.Join(subpath, "oauth", "authorize") { + return true + } + + if r.URL.Path == path.Join(subpath, "oauth", "apps", "authorized") || + r.URL.Path == path.Join(subpath, "oauth", "deauthorize") || + r.URL.Path == path.Join(subpath, "oauth", "access_token") { + return true + } + return false +} + func ReturnStatusOK(w http.ResponseWriter) { m := make(map[string]string) m[model.STATUS] = model.STATUS_OK