Remove remote users from the license counting and explicitly dissallow them to log in (#22582)
* Making all the counts aware of Remote users * Disable login for remote users * Adding tests for login remote_users error * Adding tests for the store * Adding frontend part of not counting remote users in the license * Addressing PR review comment * Adding the new ExternaUserId field to users * Running make migrations-extract * Running make app-layers and make gen-serialized * Revert "Adding the new ExternaUserId field to users" This reverts commit 12e5fd518962a16cdbdb8964179b6cd8e915f230. * Adding GetUserByRemoteID methods * Adding needed migration for users * i18n-extract * Fixing postgres increase remote user id field size migration up and down * run make gen-serialized * Removing migration code * Not count remote users as part of the cloud pricing * Add the cloud subscription when a user gets promote from remote to not-remote * Fixing merge problems --------- Co-authored-by: Mattermost Build <build@mattermost.com>
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
5a349873f7
Коммит
5f7482e541
@@ -557,12 +557,14 @@ func getFilteredUsersStats(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
channelID := r.URL.Query().Get("in_channel")
|
||||
includeDeleted := r.URL.Query().Get("include_deleted")
|
||||
includeBotAccounts := r.URL.Query().Get("include_bots")
|
||||
includeRemoteUsers := r.URL.Query().Get("include_remote_users")
|
||||
rolesString := r.URL.Query().Get("roles")
|
||||
channelRolesString := r.URL.Query().Get("channel_roles")
|
||||
teamRolesString := r.URL.Query().Get("team_roles")
|
||||
|
||||
includeDeletedBool, _ := strconv.ParseBool(includeDeleted)
|
||||
includeBotAccountsBool, _ := strconv.ParseBool(includeBotAccounts)
|
||||
includeRemoteUsersBool, _ := strconv.ParseBool(includeRemoteUsers)
|
||||
|
||||
roles := []string{}
|
||||
var rolesValid bool
|
||||
@@ -593,6 +595,7 @@ func getFilteredUsersStats(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
options := &model.UserCountOptions{
|
||||
IncludeDeleted: includeDeletedBool,
|
||||
IncludeBotAccounts: includeBotAccountsBool,
|
||||
IncludeRemoteUsers: includeRemoteUsersBool,
|
||||
TeamId: teamID,
|
||||
ChannelId: channelID,
|
||||
Roles: roles,
|
||||
@@ -1832,6 +1835,7 @@ func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
"api.user.check_user_mfa.bad_code.app_error",
|
||||
"api.user.login.blank_pwd.app_error",
|
||||
"api.user.login.bot_login_forbidden.app_error",
|
||||
"api.user.login.remote_users.login.error",
|
||||
"api.user.login.client_side_cert.certificate.app_error",
|
||||
"api.user.login.inactive.app_error",
|
||||
"api.user.login.not_verified.app_error",
|
||||
@@ -1932,6 +1936,11 @@ func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
}
|
||||
|
||||
if user.IsRemote() {
|
||||
c.Err = model.NewAppError("login", "api.user.login.remote_users.login.error", nil, "", http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
|
||||
c.LogAuditWithUserId(user.Id, "authenticated")
|
||||
|
||||
err = c.App.DoLogin(c.AppContext, w, r, user, deviceId, false, false, false)
|
||||
|
||||
@@ -3842,6 +3842,18 @@ func TestLogin(t *testing.T) {
|
||||
CheckErrorID(t, err, "api.user.login.bot_login_forbidden.app_error")
|
||||
})
|
||||
|
||||
t.Run("remote user login rejected", func(t *testing.T) {
|
||||
email := th.GenerateTestEmail()
|
||||
user := model.User{Email: email, Nickname: "Darth Vader", Password: "hello1", Username: GenerateTestUsername(), Roles: model.SystemAdminRoleId + " " + model.SystemUserRoleId, RemoteId: model.NewString("remote-id")}
|
||||
ruser, _, _ := th.Client.CreateUser(context.Background(), &user)
|
||||
|
||||
_, err := th.SystemAdminClient.UpdateUserPassword(context.Background(), ruser.Id, "", "password")
|
||||
require.NoError(t, err)
|
||||
|
||||
_, _, err = th.Client.Login(context.Background(), ruser.Email, "password")
|
||||
CheckErrorID(t, err, "api.user.login.remote_users.login.error")
|
||||
})
|
||||
|
||||
t.Run("login with terms_of_service set", func(t *testing.T) {
|
||||
termsOfService, appErr := th.App.CreateTermsOfService("terms of service", th.BasicUser.Id)
|
||||
require.Nil(t, appErr)
|
||||
|
||||
Ссылка в новой задаче
Block a user