MM-23408: Added channel ID check for Plugin API UploadFile (#14138)
* Added 2 checks for app/file.go - Check if channel id exist - Check if user has permission to the upload file to the channel Also added translations for 2 errors defined in app/file.go * fixed 1 failing test that was linked with UploadFile * Fixed small issue, according to the review. * missed 1 review item. Just updated the code for it. * fix 1 failing test, assuming that the file upload is required. ignoring nouser idea. Added the translation for english for 2 newly defined errors. * removed new line * trying to fix the translation issue. Added the missing translations from master. * as per discussion, we need to revert the check for user channel permission. So reverted it. * Update app/file_test.go Co-Authored-By: Alejandro García Montoro <alejandro.garciamontoro@gmail.com> * Update i18n/en.json Co-Authored-By: Alejandro García Montoro <alejandro.garciamontoro@gmail.com> * Update file.go Move the check to the top of the method. * go fmt Co-authored-by: mattermod <mattermod@users.noreply.github.com> Co-authored-by: Alejandro García Montoro <alejandro.garciamontoro@gmail.com> Co-authored-by: Ben Schumacher <ben.schumacher@mattermost.com>
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
8de5dd9022
Коммит
7787998bee
@@ -434,8 +434,13 @@ func (a *App) UploadFiles(teamId string, channelId string, userId string, files
|
||||
|
||||
// UploadFile uploads a single file in form of a completely constructed byte array for a channel.
|
||||
func (a *App) UploadFile(data []byte, channelId string, filename string) (*model.FileInfo, *model.AppError) {
|
||||
info, _, appError := a.DoUploadFileExpectModification(time.Now(), "noteam", channelId, "nouser", filename, data)
|
||||
_, err := a.GetChannel(channelId)
|
||||
if err != nil && channelId != "" {
|
||||
return nil, model.NewAppError("UploadFile", "api.file.upload_file.incorrect_channelId.app_error",
|
||||
map[string]interface{}{"channelId": channelId}, "", http.StatusBadRequest)
|
||||
}
|
||||
|
||||
info, _, appError := a.DoUploadFileExpectModification(time.Now(), "noteam", channelId, "nouser", filename, data)
|
||||
if appError != nil {
|
||||
return nil, appError
|
||||
}
|
||||
|
||||
Ссылка в новой задаче
Block a user