MM-67279: Fix private channel enumeration via /mute slash command (#35099) (#35149)

Automatic Merge
Этот коммит содержится в:
Mattermost Build
2026-01-30 18:23:33 +02:00
коммит произвёл GitHub
родитель 452bad21e9
Коммит 83006ff8ca
3 изменённых файлов: 4 добавлений и 7 удалений

Просмотреть файл

@@ -64,7 +64,7 @@ func (*MuteProvider) DoCommand(a *app.App, c request.CTX, args *model.CommandArg
channelMember, err := a.ToggleMuteChannel(c, channel.Id, args.UserId)
if err != nil {
return &model.CommandResponse{Text: args.T("api.command_mute.not_member.error", map[string]any{"Channel": channelName}), ResponseType: model.CommandResponseTypeEphemeral}
return &model.CommandResponse{Text: args.T("api.command_mute.error", map[string]any{"Channel": channelName}), ResponseType: model.CommandResponseTypeEphemeral}
}
// Direct and Group messages won't have a nice channel title, omit it

Просмотреть файл

@@ -130,13 +130,14 @@ func TestMuteCommandNotMember(t *testing.T) {
cmd := &MuteProvider{}
// First mute the channel
// Muting a channel that the user is not a member of should return
// the same error as a non-existent channel to prevent channel enumeration
resp := cmd.DoCommand(th.App, th.Context, &model.CommandArgs{
T: i18n.IdentityTfunc(),
ChannelId: channel1.Id,
UserId: th.BasicUser.Id,
}, channel2.Name)
assert.Equal(t, "api.command_mute.not_member.error", resp.Text)
assert.Equal(t, "api.command_mute.error", resp.Text)
}
func TestMuteCommandNotChannel(t *testing.T) {

Просмотреть файл

@@ -1241,10 +1241,6 @@
"id": "api.command_mute.no_channel.error",
"translation": "Could not find the specified channel. Please use the [channel handle](https://docs.mattermost.com/messaging/managing-channels.html#naming-a-channel) to identify channels."
},
{
"id": "api.command_mute.not_member.error",
"translation": "Could not mute channel {{.Channel}} as you are not a member."
},
{
"id": "api.command_mute.success_mute",
"translation": "You will not receive notifications for {{.Channel}} until channel mute is turned off."