[CLD-6324] Cloud IP Filtering (#24726)
* Initial comit for ip filtering service implementation * Add audit logs for IP Filters * start of webapp work * Stashing * Updates based on Agniva's feedback around service vs einterface * Updates completed * Commit before refactoring, everything's working * First pass of cleanup complete, front-end tests added * actually add files * Updates to some translation strings, running i18n-extract * Lock everything behind a feature flag * Fix tests, try to fix some linter stuff * Fixed linter for JS, on to scss * Fixed linter for scss * Fix linter * More fixes for pipeline * Support for IPV6 * Remove tsx file that was removed in masteR * Revert package.json and package-lock.json to master, add cidr-regex dep into channels/package.json * Another commit to force fix Github * Fixes around IPV6. Some suggestions from Matt re: UX review. Fixing pipelines for tests and types on new cidr-regex package * Changes to address Matt's feedback * A few more changes for clean up * Add support for permissions * Fix vet for OpenAPI spec * Actually add the yaml file for openapi * Add permission migration to allow support for IP Filtering * Fix tests * Final fixes from Matt * Remove cancel button from page, update link outs to documentation * Update test to account for removed cancel button * Adjustments based on feedback from Harrison * More fixes from PR feedback * Add a t to fix translations that doesn't seem to be breaking anyone else? * More fix * updates for PR feedback * Fix linter * Fix types * Now fix the linter again * Add back tests because Harrison was able to get them running * Adjustments for PR feedback * Remove admin_definition.jsx * Fix linter * [CLD-6453] IP Filtering notification email for sysadmins (#25224) * Initial commit for IP filtering alert email * Updates to style for email, addition of ip_filtering email: * Fix pipelines * Adjustments from Matt's feedback * Padding changes * template diff (#25249) Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com> * Fix hardcoded true, remove bool return value --------- Co-authored-by: Mattermost Build <build@mattermost.com> Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com> * Lock feature behind enterprise license. Drop cidr-regex in favour of ipaddr.js dependency. Refactor isIpAddressWithinRanges to use ipaddr.js * Add a couple server tests * fix linter * Fix types from merge conflicts --------- Co-authored-by: Mattermost Build <build@mattermost.com> Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>
Этот коммит содержится в:
@@ -137,6 +137,8 @@ type Routes struct {
|
||||
HostedCustomer *mux.Router // 'api/v4/hosted_customer'
|
||||
|
||||
Drafts *mux.Router // 'api/v4/drafts'
|
||||
|
||||
IPFiltering *mux.Router // 'api/v4/ip_filtering'
|
||||
}
|
||||
|
||||
type API struct {
|
||||
@@ -261,6 +263,8 @@ func Init(srv *app.Server) (*API, error) {
|
||||
|
||||
api.BaseRoutes.Drafts = api.BaseRoutes.APIRoot.PathPrefix("/drafts").Subrouter()
|
||||
|
||||
api.BaseRoutes.IPFiltering = api.BaseRoutes.APIRoot.PathPrefix("/ip_filtering").Subrouter()
|
||||
|
||||
api.InitUser()
|
||||
api.InitBot()
|
||||
api.InitTeam()
|
||||
@@ -304,6 +308,7 @@ func Init(srv *app.Server) (*API, error) {
|
||||
api.InitUsage()
|
||||
api.InitHostedCustomer()
|
||||
api.InitDrafts()
|
||||
api.InitIPFiltering()
|
||||
|
||||
srv.Router.Handle("/api/v4/{anything:.*}", http.HandlerFunc(api.Handle404))
|
||||
|
||||
|
||||
139
server/channels/api4/ip_filtering.go
Обычный файл
139
server/channels/api4/ip_filtering.go
Обычный файл
@@ -0,0 +1,139 @@
|
||||
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
|
||||
// See LICENSE.txt for license information.
|
||||
|
||||
package api4
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
|
||||
"github.com/mattermost/mattermost/server/public/model"
|
||||
"github.com/mattermost/mattermost/server/public/shared/mlog"
|
||||
"github.com/mattermost/mattermost/server/v8/channels/app"
|
||||
"github.com/mattermost/mattermost/server/v8/channels/audit"
|
||||
"github.com/mattermost/mattermost/server/v8/einterfaces"
|
||||
)
|
||||
|
||||
func (api *API) InitIPFiltering() {
|
||||
api.BaseRoutes.IPFiltering.Handle("", api.APISessionRequired(getIPFilters)).Methods("GET")
|
||||
api.BaseRoutes.IPFiltering.Handle("", api.APISessionRequired(applyIPFilters)).Methods("POST")
|
||||
api.BaseRoutes.IPFiltering.Handle("/my_ip", api.APISessionRequired(myIP)).Methods("GET")
|
||||
}
|
||||
|
||||
func ensureIPFilteringInterface(c *Context, where string) (einterfaces.IPFilteringInterface, bool) {
|
||||
if c.App.IPFiltering() == nil || !c.App.Config().FeatureFlags.CloudIPFiltering || c.App.License() == nil || c.App.License().SkuShortName != model.LicenseShortSkuEnterprise {
|
||||
c.Err = model.NewAppError(where, "api.context.ip_filtering.not_available.app_error", nil, "", http.StatusNotImplemented)
|
||||
return nil, false
|
||||
}
|
||||
return c.App.IPFiltering(), true
|
||||
}
|
||||
|
||||
func getIPFilters(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
ipFiltering, ok := ensureIPFilteringInterface(c, "getIPFilters")
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
if !c.App.SessionHasPermissionTo(*c.AppContext.Session(), model.PermissionSysconsoleReadIPFilters) {
|
||||
c.SetPermissionError(model.PermissionSysconsoleReadIPFilters)
|
||||
return
|
||||
}
|
||||
|
||||
allowedRanges, err := ipFiltering.GetIPFilters()
|
||||
if err != nil {
|
||||
c.Err = model.NewAppError("getIPFilters", "api.context.ip_filtering.get_ip_filters.app_error", nil, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
|
||||
if err := json.NewEncoder(w).Encode(allowedRanges); err != nil {
|
||||
c.Err = model.NewAppError("getIPFilters", "api.context.ip_filtering.get_ip_filters.app_error", nil, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
func applyIPFilters(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
ipFiltering, ok := ensureIPFilteringInterface(c, "applyIPFilters")
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
if !c.App.SessionHasPermissionTo(*c.AppContext.Session(), model.PermissionSysconsoleWriteIPFilters) {
|
||||
c.SetPermissionError(model.PermissionSysconsoleWriteIPFilters)
|
||||
return
|
||||
}
|
||||
|
||||
auditRec := c.MakeAuditRecord("applyIPFilters", audit.Fail)
|
||||
defer c.LogAuditRecWithLevel(auditRec, app.LevelContent)
|
||||
|
||||
allowedRanges := &model.AllowedIPRanges{} // Initialize the allowedRanges variable
|
||||
if err := json.NewDecoder(r.Body).Decode(allowedRanges); err != nil {
|
||||
c.Err = model.NewAppError("applyIPFilters", "api.context.ip_filtering.apply_ip_filters.app_error", nil, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
|
||||
audit.AddEventParameterAuditable(auditRec, "IPFilter", allowedRanges)
|
||||
|
||||
updatedAllowedRanges, err := ipFiltering.ApplyIPFilters(allowedRanges)
|
||||
|
||||
if err != nil {
|
||||
c.Err = model.NewAppError("applyIPFilters", "api.context.ip_filtering.apply_ip_filters.app_error", nil, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
|
||||
auditRec.Success()
|
||||
|
||||
c.App.Srv().Go(func() {
|
||||
initiatingUser, err := c.App.Srv().Store().User().GetProfileByIds(context.Background(), []string{c.AppContext.Session().UserId}, nil, true)
|
||||
if err != nil {
|
||||
mlog.Error("Failed to get initiating user", mlog.Err(err))
|
||||
}
|
||||
|
||||
users, err := c.App.Srv().Store().User().GetSystemAdminProfiles()
|
||||
if err != nil {
|
||||
mlog.Error("Failed to get system admins", mlog.Err(err))
|
||||
}
|
||||
|
||||
cloudWorkspaceOwnerEmailAddress := ""
|
||||
if c.App.License().IsCloud() {
|
||||
portalUserCustomer, cErr := c.App.Cloud().GetCloudCustomer(c.AppContext.Session().UserId)
|
||||
if cErr != nil {
|
||||
mlog.Error("Failed to get portal user customer", mlog.Err(cErr))
|
||||
}
|
||||
if cErr == nil && portalUserCustomer != nil {
|
||||
cloudWorkspaceOwnerEmailAddress = portalUserCustomer.Email
|
||||
}
|
||||
}
|
||||
|
||||
for _, user := range users {
|
||||
if err = c.App.Srv().EmailService.SendIPFiltersChangedEmail(user.Email, initiatingUser[0], *c.App.Config().ServiceSettings.SiteURL, *c.App.Config().CloudSettings.CWSURL, user.Locale, cloudWorkspaceOwnerEmailAddress == user.Email); err != nil {
|
||||
mlog.Error("Error while sending IP filters changed email", mlog.Err(err))
|
||||
}
|
||||
}
|
||||
})
|
||||
|
||||
if err := json.NewEncoder(w).Encode(updatedAllowedRanges); err != nil {
|
||||
c.Err = model.NewAppError("getIPFilters", "api.context.ip_filtering.get_ip_filters.app_error", nil, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
func myIP(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
_, ok := ensureIPFilteringInterface(c, "myIP")
|
||||
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
response := &model.GetIPAddressResponse{
|
||||
IP: c.AppContext.IPAddress(),
|
||||
}
|
||||
|
||||
json, err := json.Marshal(response)
|
||||
if err != nil {
|
||||
c.Err = model.NewAppError("myIP", "api.context.ip_filtering.get_my_ip.failed", nil, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
|
||||
w.Write(json)
|
||||
}
|
||||
310
server/channels/api4/ip_filtering_test.go
Обычный файл
310
server/channels/api4/ip_filtering_test.go
Обычный файл
@@ -0,0 +1,310 @@
|
||||
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
|
||||
// See LICENSE.txt for license information.
|
||||
package api4
|
||||
|
||||
import (
|
||||
"context"
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/mattermost/mattermost/server/public/model"
|
||||
"github.com/mattermost/mattermost/server/public/plugin/plugintest/mock"
|
||||
"github.com/mattermost/mattermost/server/v8/einterfaces/mocks"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
func Test_getIPFilters(t *testing.T) {
|
||||
lic := &model.License{
|
||||
Features: &model.Features{
|
||||
CustomPermissionsSchemes: model.NewBool(false),
|
||||
Cloud: model.NewBool(true),
|
||||
},
|
||||
Customer: &model.Customer{
|
||||
Name: "TestName",
|
||||
Email: "test@example.com",
|
||||
},
|
||||
SkuName: "SKU NAME",
|
||||
SkuShortName: model.LicenseShortSkuEnterprise,
|
||||
StartsAt: model.GetMillis() - 1000,
|
||||
ExpiresAt: model.GetMillis() + 100000,
|
||||
}
|
||||
|
||||
t.Run("No license returns 501", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().RemoveLicense()
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.GetIPFilters(context.Background())
|
||||
require.Error(t, err)
|
||||
require.Nil(t, ipFilters)
|
||||
require.Equal(t, 501, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("No feature flag returns 501", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "false")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.GetIPFilters(context.Background())
|
||||
require.Error(t, err)
|
||||
require.Nil(t, ipFilters)
|
||||
require.Equal(t, 501, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("Feature flag and license but no permission", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser2.Email, th.BasicUser2.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.GetIPFilters(context.Background())
|
||||
require.Error(t, err)
|
||||
require.Nil(t, ipFilters)
|
||||
require.Equal(t, 403, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("Feature flag and license and permission", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFiltering.Mock.On("GetIPFilters").Return(&model.AllowedIPRanges{
|
||||
model.AllowedIPRange{
|
||||
CIDRBlock: "127.0.0.1/32",
|
||||
Description: "test",
|
||||
},
|
||||
}, nil)
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
th.Client.Login(context.Background(), th.SystemAdminUser.Email, th.SystemAdminUser.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.GetIPFilters(context.Background())
|
||||
require.NoError(t, err)
|
||||
require.NotNil(t, ipFilters)
|
||||
require.Equal(t, 200, r.StatusCode)
|
||||
})
|
||||
}
|
||||
|
||||
func Test_applyIPFilters(t *testing.T) {
|
||||
allowedRanges := &model.AllowedIPRanges{
|
||||
model.AllowedIPRange{
|
||||
CIDRBlock: "127.0.0.1/32",
|
||||
Description: "test",
|
||||
},
|
||||
}
|
||||
|
||||
lic := &model.License{
|
||||
Features: &model.Features{
|
||||
CustomPermissionsSchemes: model.NewBool(false),
|
||||
Cloud: model.NewBool(true),
|
||||
},
|
||||
Customer: &model.Customer{
|
||||
Name: "TestName",
|
||||
Email: "test@example.com",
|
||||
},
|
||||
SkuName: "SKU NAME",
|
||||
SkuShortName: model.LicenseShortSkuEnterprise,
|
||||
StartsAt: model.GetMillis() - 1000,
|
||||
ExpiresAt: model.GetMillis() + 100000,
|
||||
}
|
||||
// Initialize the allowedRanges variable
|
||||
t.Run("No license returns 501", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().RemoveLicense()
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.ApplyIPFilters(context.Background(), allowedRanges)
|
||||
require.Error(t, err)
|
||||
require.Nil(t, ipFilters)
|
||||
require.Equal(t, 501, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("License but no feature flag returns 501", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "false")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.ApplyIPFilters(context.Background(), allowedRanges)
|
||||
require.Error(t, err)
|
||||
require.Nil(t, ipFilters)
|
||||
require.Equal(t, 501, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("feature flag and license but no permission", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
ipFilters, r, err := th.Client.ApplyIPFilters(context.Background(), allowedRanges)
|
||||
require.Error(t, err)
|
||||
require.Nil(t, ipFilters)
|
||||
require.Equal(t, 403, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("Feature flag and license and permission", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFiltering.Mock.On("ApplyIPFilters", mock.Anything).Return(&model.AllowedIPRanges{
|
||||
model.AllowedIPRange{
|
||||
CIDRBlock: "127.0.0.1/32",
|
||||
Description: "test",
|
||||
},
|
||||
}, nil)
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
th.Client.Login(context.Background(), th.SystemAdminUser.Email, th.SystemAdminUser.Password)
|
||||
|
||||
ipFilters, r, err := th.Client.ApplyIPFilters(context.Background(), allowedRanges)
|
||||
require.NoError(t, err)
|
||||
require.NotNil(t, ipFilters)
|
||||
require.Equal(t, 200, r.StatusCode)
|
||||
})
|
||||
}
|
||||
|
||||
func Test_getMyIP(t *testing.T) {
|
||||
lic := &model.License{
|
||||
Features: &model.Features{
|
||||
CustomPermissionsSchemes: model.NewBool(false),
|
||||
Cloud: model.NewBool(true),
|
||||
},
|
||||
Customer: &model.Customer{
|
||||
Name: "TestName",
|
||||
Email: "test@example.com",
|
||||
},
|
||||
SkuName: "SKU NAME",
|
||||
SkuShortName: model.LicenseShortSkuEnterprise,
|
||||
StartsAt: model.GetMillis() - 1000,
|
||||
ExpiresAt: model.GetMillis() + 100000,
|
||||
}
|
||||
t.Run("No license returns 501", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "true")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
|
||||
th.App.Srv().RemoveLicense()
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
myIP, r, err := th.Client.GetMyIP(context.Background())
|
||||
require.Error(t, err)
|
||||
require.Nil(t, myIP)
|
||||
require.Equal(t, 501, r.StatusCode)
|
||||
})
|
||||
|
||||
t.Run("Licensed, but no feature flag returns 501", func(t *testing.T) {
|
||||
os.Setenv("MM_FEATUREFLAGS_CLOUDIPFILTERING", "false")
|
||||
defer os.Unsetenv("MM_FEATUREFLAGS_CLOUDIPFILTERING")
|
||||
th := Setup(t).InitBasic()
|
||||
defer th.TearDown()
|
||||
|
||||
th.Client.Login(context.Background(), th.BasicUser.Email, th.BasicUser.Password)
|
||||
|
||||
ipFiltering := &mocks.IPFilteringInterface{}
|
||||
ipFilteringImpl := th.App.Srv().IPFiltering
|
||||
defer func() {
|
||||
th.App.Srv().IPFiltering = ipFilteringImpl
|
||||
}()
|
||||
th.App.Srv().IPFiltering = ipFiltering
|
||||
th.App.Srv().SetLicense(lic)
|
||||
|
||||
myIP, r, err := th.Client.GetMyIP(context.Background())
|
||||
require.Error(t, err)
|
||||
require.Nil(t, myIP)
|
||||
require.Equal(t, 501, r.StatusCode)
|
||||
})
|
||||
}
|
||||
Ссылка в новой задаче
Block a user