MM-22785 audit server CLI (#14144)
Add auditing to server CLI. Also: - simplify auditing in API layer - reduce number of AddMeta calls - have models serialize themselves - more consistent field naming
Этот коммит содержится в:
@@ -10,6 +10,7 @@ import (
|
||||
"fmt"
|
||||
|
||||
"github.com/mattermost/mattermost-server/v5/app"
|
||||
"github.com/mattermost/mattermost-server/v5/audit"
|
||||
"github.com/mattermost/mattermost-server/v5/model"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
@@ -172,11 +173,16 @@ func createCommandCmdF(command *cobra.Command, args []string) error {
|
||||
URL: url,
|
||||
}
|
||||
|
||||
if _, err := a.CreateCommand(newCommand); err != nil {
|
||||
return errors.New("unable to create command '" + newCommand.DisplayName + "'. " + err.Error())
|
||||
createdCommand, errCreate := a.CreateCommand(newCommand)
|
||||
if errCreate != nil {
|
||||
return errors.New("unable to create command '" + newCommand.DisplayName + "'. " + errCreate.Error())
|
||||
}
|
||||
CommandPrettyPrintln("created command '" + newCommand.DisplayName + "'")
|
||||
|
||||
auditRec := a.MakeAuditRecord("createCommand", audit.Success)
|
||||
auditRec.AddMeta("user", user)
|
||||
auditRec.AddMeta("command", createdCommand)
|
||||
a.LogAuditRec(auditRec, nil)
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -224,9 +230,13 @@ func moveCommandCmdF(command *cobra.Command, args []string) error {
|
||||
CommandPrintErrorln("Unable to move command '" + command.DisplayName + "' error: " + err.Error())
|
||||
} else {
|
||||
CommandPrettyPrintln("Moved command '" + command.DisplayName + "'")
|
||||
|
||||
auditRec := a.MakeAuditRecord("moveCommand", audit.Success)
|
||||
auditRec.AddMeta("team", team)
|
||||
auditRec.AddMeta("command", command)
|
||||
a.LogAuditRec(auditRec, nil)
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -282,15 +292,20 @@ func deleteCommandCmdF(command *cobra.Command, args []string) error {
|
||||
command.SilenceUsage = true
|
||||
return errors.New("Unable to find command '" + args[0] + "'")
|
||||
}
|
||||
|
||||
if err := a.DeleteCommand(slashCommand.Id); err != nil {
|
||||
command.SilenceUsage = true
|
||||
return errors.New("Unable to delete command '" + slashCommand.Id + "' error: " + err.Error())
|
||||
}
|
||||
CommandPrettyPrintln("Deleted command '" + slashCommand.Id + "' (" + slashCommand.DisplayName + ")")
|
||||
|
||||
auditRec := a.MakeAuditRecord("deleteCommand", audit.Success)
|
||||
auditRec.AddMeta("command", slashCommand)
|
||||
a.LogAuditRec(auditRec, nil)
|
||||
return nil
|
||||
}
|
||||
|
||||
func modifyCommandCmdF(command *cobra.Command, args []string) error {
|
||||
func modifyCommandCmdF(command *cobra.Command, args []string) (cmdError error) {
|
||||
a, err := InitDBCommandContextCobra(command)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -304,6 +319,10 @@ func modifyCommandCmdF(command *cobra.Command, args []string) error {
|
||||
}
|
||||
modifiedCommand := oldCommand
|
||||
|
||||
auditRec := a.MakeAuditRecord("modifyCommand", audit.Fail)
|
||||
defer func() { a.LogAuditRec(auditRec, cmdError) }()
|
||||
auditRec.AddMeta("command", oldCommand)
|
||||
|
||||
// get creator user
|
||||
creator, _ := command.Flags().GetString("creator")
|
||||
if creator != "" {
|
||||
@@ -376,10 +395,14 @@ func modifyCommandCmdF(command *cobra.Command, args []string) error {
|
||||
}
|
||||
modifiedCommand.Method = method
|
||||
|
||||
if _, err := a.UpdateCommand(oldCommand, modifiedCommand); err != nil {
|
||||
return errors.New("unable to modify command '" + modifiedCommand.DisplayName + "'. " + err.Error())
|
||||
updatedCommand, errUpdated := a.UpdateCommand(oldCommand, modifiedCommand)
|
||||
if errUpdated != nil {
|
||||
return errors.New("unable to modify command '" + modifiedCommand.DisplayName + "'. " + errUpdated.Error())
|
||||
}
|
||||
CommandPrettyPrintln("modified command '" + modifiedCommand.DisplayName + "'")
|
||||
|
||||
auditRec.Success()
|
||||
auditRec.AddMeta("update", updatedCommand)
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
Ссылка в новой задаче
Block a user