MM 57516 - deactivate actions to ldap users (#28199)

* MM-57516 - restrict activation/deactivation over ldap users

* Add unit tests

* refactor test to unify repeated actions

* add disable actions in user details too

* migrate test to use react-testing-library

* add new ldap user test and fix other existing tests

* restrict ldap users status management via api

* use correct server status and update tests

---------

Co-authored-by: Mattermost Build <build@mattermost.com>
Этот коммит содержится в:
Pablo Vélez
2024-10-09 18:59:53 +02:00
коммит произвёл GitHub
родитель ac38f5f751
Коммит 6cafd45fc9
10 изменённых файлов: 1413 добавлений и 851 удалений

Просмотреть файл

@@ -1540,6 +1540,11 @@ func updateUserActive(c *Context, w http.ResponseWriter, r *http.Request) {
return
}
if user.AuthService == model.UserAuthServiceLdap {
c.Err = model.NewAppError("updateUserActive", "api.user.update_active.cannot_modify_status_when_user_is_managed_by_ldap.app_error", nil, "userId="+c.Params.UserId, http.StatusForbidden)
return
}
if _, err = c.App.UpdateActive(c.AppContext, user, active); err != nil {
c.Err = err
return

Просмотреть файл

@@ -2684,6 +2684,31 @@ func TestUpdateUserActive(t *testing.T) {
require.NoError(t, err)
})
})
t.Run("update active status of LDAP user should fail", func(t *testing.T) {
th := Setup(t).InitBasic()
defer th.TearDown()
ldapUser := &model.User{
Email: "ldapuser@mattermost-customer.com",
Username: "ldapuser",
Password: "Password123",
AuthService: model.UserAuthServiceLdap,
EmailVerified: true,
}
user, appErr := th.App.CreateUser(th.Context, ldapUser)
require.Nil(t, appErr)
th.TestForSystemAdminAndLocal(t, func(t *testing.T, client *model.Client4) {
resp, err := client.UpdateUserActive(context.Background(), user.Id, false)
require.Error(t, err)
CheckForbiddenStatus(t, resp)
resp, err = client.UpdateUserActive(context.Background(), user.Id, true)
require.Error(t, err)
CheckForbiddenStatus(t, resp)
})
})
}
func TestGetUsers(t *testing.T) {