* Initial comit for ip filtering service implementation

* Add audit logs for IP Filters

* start of webapp work

* Stashing

* Updates based on Agniva's feedback around service vs einterface

* Updates completed

* Commit before refactoring, everything's working

* First pass of cleanup complete, front-end tests added

* actually add files

* Updates to some translation strings, running i18n-extract

* Lock everything behind a feature flag

* Fix tests, try to fix some linter stuff

* Fixed linter for JS, on to scss

* Fixed linter for scss

* Fix linter

* More fixes for pipeline

* Support for IPV6

* Remove tsx file that was removed in masteR

* Revert package.json and package-lock.json to master, add cidr-regex dep into channels/package.json

* Another commit to force fix Github

* Fixes around IPV6. Some suggestions from Matt re: UX review. Fixing pipelines for tests and types on new cidr-regex package

* Changes to address Matt's feedback

* A few more changes for clean up

* Add support for permissions

* Fix vet for OpenAPI spec

* Actually add the yaml file for openapi

* Add permission migration to allow support for IP Filtering

* Fix tests

* Final fixes from Matt

* Remove cancel button from page, update link outs to documentation

* Update test to account for removed cancel button

* Adjustments based on feedback from Harrison

* More fixes from PR feedback

* Add a t to fix translations that doesn't seem to be breaking anyone else?

* More fix

* updates for PR feedback

* Fix linter

* Fix types

* Now fix the linter again

* Add back tests because Harrison was able to get them running

* Adjustments for PR feedback

* Remove admin_definition.jsx

* Fix linter

* [CLD-6453] IP Filtering notification email for sysadmins (#25224)

* Initial commit for IP filtering alert email

* Updates to style for email, addition of ip_filtering email:

* Fix pipelines

* Adjustments from Matt's feedback

* Padding changes

* template diff (#25249)

Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>

* Fix hardcoded true, remove bool return value

---------

Co-authored-by: Mattermost Build <build@mattermost.com>
Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>

* Lock feature behind enterprise license. Drop cidr-regex in favour of ipaddr.js dependency. Refactor isIpAddressWithinRanges to use ipaddr.js

* Add a couple server tests

* fix linter

* Fix types from merge conflicts

---------

Co-authored-by: Mattermost Build <build@mattermost.com>
Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>
Этот коммит содержится в:
Nick Misasi
2023-11-14 09:12:04 -05:00
коммит произвёл GitHub
родитель 7bf9be2619
Коммит e1c851a3ca
82 изменённых файлов: 4533 добавлений и 19 удалений

Просмотреть файл

@@ -49,6 +49,7 @@ build-v4: node_modules playbooks
@cat $(V4_SRC)/permissions.yaml >> $(V4_YAML)
@cat $(V4_SRC)/imports.yaml >> $(V4_YAML)
@cat $(V4_SRC)/exports.yaml >> $(V4_YAML)
@cat $(V4_SRC)/ip_filters.yaml >> $(V4_YAML)
@if [ -r $(PLAYBOOKS_SRC)/paths.yaml ]; then cat $(PLAYBOOKS_SRC)/paths.yaml >> $(V4_YAML); fi
@if [ -r $(PLAYBOOKS_SRC)/merged-definitions.yaml ]; then cat $(PLAYBOOKS_SRC)/merged-definitions.yaml >> $(V4_YAML); else cat $(V4_SRC)/definitions.yaml >> $(V4_YAML); fi
@echo Extracting code samples

Просмотреть файл

@@ -3515,6 +3515,15 @@ components:
description: The time in milliseconds in which this acknowledgement was made.
type: integer
format: int64
AllowedIPRange:
type: object
properties:
CIDRBlock:
description: An IP address range in CIDR notation
type: string
Description:
description: A description for the CIDRBlock
type: string
externalDocs:
description: Find out more about Mattermost
url: 'https://about.mattermost.com'

92
api/v4/source/ip_filters.yaml Обычный файл
Просмотреть файл

@@ -0,0 +1,92 @@
/api/v4/ip_filtering:
get:
tags:
- ip
- filtering
summary: Get all IP filters
description: >
Retrieve a list of IP filters applied to the workspace
__Minimum server version__: 9.1
__Note:__ This is intended for internal use and only applicable to Cloud workspaces
operationId: GetIPFilters
responses:
"200":
description: IP Filters returned successfully
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/AllowedIPRange"
"401":
$ref: "#/components/responses/Unauthorized"
"500":
$ref: "#/components/responses/InternalServerError"
"501":
$ref: "#/components/responses/NotImplemented"
post:
tags:
- ip
- filtering
summary: Get all IP filters
description: >
Adjust IP Filters applied to the workspace
__Minimum server version__: 9.1
__Note:__ This is intended for internal use and only applicable to Cloud workspaces
operationId: ApplyIPFilters
requestBody:
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/AllowedIPRange"
description: IP Filters to apply
required: true
responses:
"200":
description: IP Filters returned successfully
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/AllowedIPRange"
"401":
$ref: "#/components/responses/Unauthorized"
"500":
$ref: "#/components/responses/InternalServerError"
"501":
$ref: "#/components/responses/NotImplemented"
/api/v4/ip_filtering/my_ip:
get:
tags:
- ip
- filtering
summary: Get all IP filters
description: >
Retrieve your current IP address as seen by the workspace
__Minimum server version__: 9.1
__Note:__ This is intended for internal use and only applicable to Cloud workspaces
operationId: MyIP
responses:
"200":
description: IP address returned successfully
content:
application/json:
schema:
type: object
properties:
ip:
type: string
description: Your current IP address
example: "192.168.0.1"
"401":
$ref: "#/components/responses/Unauthorized"
"500":
$ref: "#/components/responses/InternalServerError"
"501":
$ref: "#/components/responses/NotImplemented"