[CLD-8304] Return 501 if not a cloud license accessing IP Filtering (#28093)
* Return 501 if not a cloud license accessing IP Filtering * Changes for PR feedback
Этот коммит содержится в:
@@ -20,7 +20,7 @@ func (api *API) InitIPFiltering() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func ensureIPFilteringInterface(c *Context, where string) (einterfaces.IPFilteringInterface, bool) {
|
func ensureIPFilteringInterface(c *Context, where string) (einterfaces.IPFilteringInterface, bool) {
|
||||||
if c.App.IPFiltering() == nil || !c.App.Config().FeatureFlags.CloudIPFiltering || c.App.License() == nil || c.App.License().SkuShortName != model.LicenseShortSkuEnterprise {
|
if c.App.IPFiltering() == nil || !c.App.Config().FeatureFlags.CloudIPFiltering || c.App.License() == nil || !c.App.License().IsCloud() || c.App.License().SkuShortName != model.LicenseShortSkuEnterprise {
|
||||||
c.Err = model.NewAppError(where, "api.context.ip_filtering.not_available.app_error", nil, "", http.StatusNotImplemented)
|
c.Err = model.NewAppError(where, "api.context.ip_filtering.not_available.app_error", nil, "", http.StatusNotImplemented)
|
||||||
return nil, false
|
return nil, false
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -30,16 +30,11 @@ func Test_getIPFilters(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
t.Run("No license returns 501", func(t *testing.T) {
|
t.Run("No license returns 501", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
th.App.Srv().RemoveLicense()
|
th.App.Srv().RemoveLicense()
|
||||||
@@ -59,10 +54,6 @@ func Test_getIPFilters(t *testing.T) {
|
|||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
th.App.Srv().SetLicense(lic)
|
th.App.Srv().SetLicense(lic)
|
||||||
@@ -76,16 +67,11 @@ func Test_getIPFilters(t *testing.T) {
|
|||||||
})
|
})
|
||||||
|
|
||||||
t.Run("Feature flag and license but no permission", func(t *testing.T) {
|
t.Run("Feature flag and license but no permission", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
th.App.Srv().SetLicense(lic)
|
th.App.Srv().SetLicense(lic)
|
||||||
@@ -99,8 +85,7 @@ func Test_getIPFilters(t *testing.T) {
|
|||||||
})
|
})
|
||||||
|
|
||||||
t.Run("Feature flag and license and permission", func(t *testing.T) {
|
t.Run("Feature flag and license and permission", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
@@ -111,10 +96,6 @@ func Test_getIPFilters(t *testing.T) {
|
|||||||
Description: "test",
|
Description: "test",
|
||||||
},
|
},
|
||||||
}, nil)
|
}, nil)
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
th.App.Srv().SetLicense(lic)
|
th.App.Srv().SetLicense(lic)
|
||||||
@@ -126,6 +107,32 @@ func Test_getIPFilters(t *testing.T) {
|
|||||||
require.NotNil(t, ipFilters)
|
require.NotNil(t, ipFilters)
|
||||||
require.Equal(t, 200, r.StatusCode)
|
require.Equal(t, 200, r.StatusCode)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
t.Run("Feature flag and license and permission but not cloud returns 503", func(t *testing.T) {
|
||||||
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
|
th := Setup(t).InitBasic()
|
||||||
|
defer th.TearDown()
|
||||||
|
|
||||||
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
|
ipFiltering.Mock.On("GetIPFilters").Return(&model.AllowedIPRanges{
|
||||||
|
model.AllowedIPRange{
|
||||||
|
CIDRBlock: "127.0.0.1/32",
|
||||||
|
Description: "test",
|
||||||
|
},
|
||||||
|
}, nil)
|
||||||
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
|
lic.Features.Cloud = model.NewPointer(false)
|
||||||
|
|
||||||
|
th.App.Srv().SetLicense(lic)
|
||||||
|
|
||||||
|
th.Client.Login(context.Background(), th.SystemAdminUser.Email, th.SystemAdminUser.Password)
|
||||||
|
|
||||||
|
ipFilters, r, err := th.Client.GetIPFilters(context.Background())
|
||||||
|
require.Error(t, err)
|
||||||
|
require.Nil(t, ipFilters)
|
||||||
|
require.Equal(t, 501, r.StatusCode)
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func Test_applyIPFilters(t *testing.T) {
|
func Test_applyIPFilters(t *testing.T) {
|
||||||
@@ -141,16 +148,11 @@ func Test_applyIPFilters(t *testing.T) {
|
|||||||
|
|
||||||
// Initialize the allowedRanges variable
|
// Initialize the allowedRanges variable
|
||||||
t.Run("No license returns 501", func(t *testing.T) {
|
t.Run("No license returns 501", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
th.App.Srv().RemoveLicense()
|
th.App.Srv().RemoveLicense()
|
||||||
@@ -170,10 +172,6 @@ func Test_applyIPFilters(t *testing.T) {
|
|||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
th.App.Srv().SetLicense(lic)
|
th.App.Srv().SetLicense(lic)
|
||||||
|
|
||||||
@@ -186,18 +184,13 @@ func Test_applyIPFilters(t *testing.T) {
|
|||||||
})
|
})
|
||||||
|
|
||||||
t.Run("feature flag and license but no permission", func(t *testing.T) {
|
t.Run("feature flag and license but no permission", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
th.App.Srv().SetLicense(lic)
|
th.App.Srv().SetLicense(lic)
|
||||||
|
|
||||||
@@ -208,8 +201,7 @@ func Test_applyIPFilters(t *testing.T) {
|
|||||||
})
|
})
|
||||||
|
|
||||||
t.Run("Feature flag and license and permission", func(t *testing.T) {
|
t.Run("Feature flag and license and permission", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
@@ -222,10 +214,6 @@ func Test_applyIPFilters(t *testing.T) {
|
|||||||
Description: "test",
|
Description: "test",
|
||||||
},
|
},
|
||||||
}, nil)
|
}, nil)
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
cloud := &mocks.CloudInterface{}
|
cloud := &mocks.CloudInterface{}
|
||||||
@@ -260,16 +248,11 @@ func Test_getMyIP(t *testing.T) {
|
|||||||
ExpiresAt: model.GetMillis() + 100000,
|
ExpiresAt: model.GetMillis() + 100000,
|
||||||
}
|
}
|
||||||
t.Run("No license returns 501", func(t *testing.T) {
|
t.Run("No license returns 501", func(t *testing.T) {
|
||||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
t.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
|
||||||
th := Setup(t).InitBasic()
|
th := Setup(t).InitBasic()
|
||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
|
|
||||||
th.App.Srv().RemoveLicense()
|
th.App.Srv().RemoveLicense()
|
||||||
@@ -291,10 +274,6 @@ func Test_getMyIP(t *testing.T) {
|
|||||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||||
|
|
||||||
ipFiltering := &mocks.IPFilteringInterface{}
|
ipFiltering := &mocks.IPFilteringInterface{}
|
||||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
|
||||||
defer func() {
|
|
||||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
|
||||||
}()
|
|
||||||
th.App.Srv().IPFiltering = ipFiltering
|
th.App.Srv().IPFiltering = ipFiltering
|
||||||
th.App.Srv().SetLicense(lic)
|
th.App.Srv().SetLicense(lic)
|
||||||
|
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user