[CLD-6324] Cloud IP Filtering (#24726)
* Initial comit for ip filtering service implementation * Add audit logs for IP Filters * start of webapp work * Stashing * Updates based on Agniva's feedback around service vs einterface * Updates completed * Commit before refactoring, everything's working * First pass of cleanup complete, front-end tests added * actually add files * Updates to some translation strings, running i18n-extract * Lock everything behind a feature flag * Fix tests, try to fix some linter stuff * Fixed linter for JS, on to scss * Fixed linter for scss * Fix linter * More fixes for pipeline * Support for IPV6 * Remove tsx file that was removed in masteR * Revert package.json and package-lock.json to master, add cidr-regex dep into channels/package.json * Another commit to force fix Github * Fixes around IPV6. Some suggestions from Matt re: UX review. Fixing pipelines for tests and types on new cidr-regex package * Changes to address Matt's feedback * A few more changes for clean up * Add support for permissions * Fix vet for OpenAPI spec * Actually add the yaml file for openapi * Add permission migration to allow support for IP Filtering * Fix tests * Final fixes from Matt * Remove cancel button from page, update link outs to documentation * Update test to account for removed cancel button * Adjustments based on feedback from Harrison * More fixes from PR feedback * Add a t to fix translations that doesn't seem to be breaking anyone else? * More fix * updates for PR feedback * Fix linter * Fix types * Now fix the linter again * Add back tests because Harrison was able to get them running * Adjustments for PR feedback * Remove admin_definition.jsx * Fix linter * [CLD-6453] IP Filtering notification email for sysadmins (#25224) * Initial commit for IP filtering alert email * Updates to style for email, addition of ip_filtering email: * Fix pipelines * Adjustments from Matt's feedback * Padding changes * template diff (#25249) Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com> * Fix hardcoded true, remove bool return value --------- Co-authored-by: Mattermost Build <build@mattermost.com> Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com> * Lock feature behind enterprise license. Drop cidr-regex in favour of ipaddr.js dependency. Refactor isIpAddressWithinRanges to use ipaddr.js * Add a couple server tests * fix linter * Fix types from merge conflicts --------- Co-authored-by: Mattermost Build <build@mattermost.com> Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>
Этот коммит содержится в:
@@ -555,6 +555,10 @@ func (c *Client4) sharedChannelsRoute() string {
|
||||
return "/sharedchannels"
|
||||
}
|
||||
|
||||
func (c *Client4) ipFiltersRoute() string {
|
||||
return "/ip_filtering"
|
||||
}
|
||||
|
||||
func (c *Client4) permissionsRoute() string {
|
||||
return "/permissions"
|
||||
}
|
||||
@@ -8028,6 +8032,52 @@ func (c *Client4) GetProductLimits(ctx context.Context) (*ProductLimits, *Respon
|
||||
return productLimits, BuildResponse(r), nil
|
||||
}
|
||||
|
||||
func (c *Client4) GetIPFilters(ctx context.Context) (*AllowedIPRanges, *Response, error) {
|
||||
r, err := c.DoAPIGet(ctx, c.ipFiltersRoute(), "")
|
||||
if err != nil {
|
||||
return nil, BuildResponse(r), err
|
||||
}
|
||||
|
||||
defer closeBody(r)
|
||||
|
||||
var allowedIPRanges *AllowedIPRanges
|
||||
json.NewDecoder(r.Body).Decode(&allowedIPRanges)
|
||||
return allowedIPRanges, BuildResponse(r), nil
|
||||
}
|
||||
|
||||
func (c *Client4) ApplyIPFilters(ctx context.Context, allowedRanges *AllowedIPRanges) (*AllowedIPRanges, *Response, error) {
|
||||
payload, err := json.Marshal(allowedRanges)
|
||||
if err != nil {
|
||||
return nil, nil, NewAppError("ApplyIPFilters", "api.marshal_error", nil, "", http.StatusInternalServerError).Wrap(err)
|
||||
}
|
||||
|
||||
r, err := c.DoAPIPostBytes(ctx, c.ipFiltersRoute(), payload)
|
||||
if err != nil {
|
||||
return nil, BuildResponse(r), err
|
||||
}
|
||||
|
||||
defer closeBody(r)
|
||||
|
||||
var allowedIPRanges *AllowedIPRanges
|
||||
json.NewDecoder(r.Body).Decode(&allowedIPRanges)
|
||||
|
||||
return allowedIPRanges, BuildResponse(r), nil
|
||||
}
|
||||
|
||||
func (c *Client4) GetMyIP(ctx context.Context) (*GetIPAddressResponse, *Response, error) {
|
||||
r, err := c.DoAPIGet(ctx, c.ipFiltersRoute()+"/my_ip", "")
|
||||
if err != nil {
|
||||
return nil, BuildResponse(r), err
|
||||
}
|
||||
|
||||
defer closeBody(r)
|
||||
|
||||
var response *GetIPAddressResponse
|
||||
json.NewDecoder(r.Body).Decode(&response)
|
||||
|
||||
return response, BuildResponse(r), nil
|
||||
}
|
||||
|
||||
func (c *Client4) CreateCustomerPayment(ctx context.Context) (*StripeSetupIntent, *Response, error) {
|
||||
r, err := c.DoAPIPost(ctx, c.cloudRoute()+"/payment", "")
|
||||
if err != nil {
|
||||
|
||||
@@ -44,7 +44,8 @@ type FeatureFlags struct {
|
||||
|
||||
StreamlinedMarketplace bool
|
||||
|
||||
ConsumePostHook bool
|
||||
CloudIPFiltering bool
|
||||
ConsumePostHook bool
|
||||
}
|
||||
|
||||
func (f *FeatureFlags) SetDefaults() {
|
||||
@@ -60,6 +61,7 @@ func (f *FeatureFlags) SetDefaults() {
|
||||
f.CloudReverseTrial = false
|
||||
f.EnableExportDirectDownload = false
|
||||
f.StreamlinedMarketplace = true
|
||||
f.CloudIPFiltering = false
|
||||
f.ConsumePostHook = false
|
||||
}
|
||||
|
||||
|
||||
20
server/public/model/ip_filtering.go
Обычный файл
20
server/public/model/ip_filtering.go
Обычный файл
@@ -0,0 +1,20 @@
|
||||
package model
|
||||
|
||||
type AllowedIPRanges []AllowedIPRange
|
||||
|
||||
type AllowedIPRange struct {
|
||||
CIDRBlock string `json:"cidr_block"`
|
||||
Description string `json:"description"`
|
||||
Enabled bool `json:"enabled"`
|
||||
OwnerID string `json:"owner_id"`
|
||||
}
|
||||
|
||||
func (air *AllowedIPRanges) Auditable() map[string]interface{} {
|
||||
return map[string]interface{}{
|
||||
"AllowedIPRanges": air,
|
||||
}
|
||||
}
|
||||
|
||||
type GetIPAddressResponse struct {
|
||||
IP string `json:"ip"`
|
||||
}
|
||||
@@ -44,4 +44,5 @@ const (
|
||||
MigrationKeyElasticsearchFixChannelIndex = "elasticsearch_fix_channel_index_migration"
|
||||
MigrationKeyS3Path = "s3_path_migration"
|
||||
MigrationKeyDeleteEmptyDrafts = "delete_empty_drafts_migration"
|
||||
MigrationKeyAddIPFilteringPermissions = "add_ip_filtering_permissions"
|
||||
)
|
||||
|
||||
@@ -267,6 +267,9 @@ var PermissionSysconsoleWriteSitePublicLinks *Permission
|
||||
var PermissionSysconsoleReadSiteNotices *Permission
|
||||
var PermissionSysconsoleWriteSiteNotices *Permission
|
||||
|
||||
var PermissionSysconsoleReadIPFilters *Permission
|
||||
var PermissionSysconsoleWriteIPFilters *Permission
|
||||
|
||||
var PermissionSysconsoleReadAuthentication *Permission
|
||||
var PermissionSysconsoleWriteAuthentication *Permission
|
||||
|
||||
@@ -1646,6 +1649,20 @@ func initializePermissions() {
|
||||
PermissionScopeSystem,
|
||||
}
|
||||
|
||||
PermissionSysconsoleReadIPFilters = &Permission{
|
||||
"sysconsole_read_site_ip_filters",
|
||||
"",
|
||||
"",
|
||||
PermissionScopeSystem,
|
||||
}
|
||||
|
||||
PermissionSysconsoleWriteIPFilters = &Permission{
|
||||
"sysconsole_write_site_ip_filters",
|
||||
"",
|
||||
"",
|
||||
PermissionScopeSystem,
|
||||
}
|
||||
|
||||
// Deprecated
|
||||
PermissionSysconsoleReadAuthentication = &Permission{
|
||||
"sysconsole_read_authentication",
|
||||
@@ -2160,6 +2177,7 @@ func initializePermissions() {
|
||||
PermissionSysconsoleReadExperimentalFeatureFlags,
|
||||
PermissionSysconsoleReadExperimentalBleve,
|
||||
PermissionSysconsoleReadProductsBoards,
|
||||
PermissionSysconsoleReadIPFilters,
|
||||
}
|
||||
|
||||
SysconsoleWritePermissions = []*Permission{
|
||||
@@ -2218,6 +2236,7 @@ func initializePermissions() {
|
||||
PermissionSysconsoleWriteExperimentalFeatureFlags,
|
||||
PermissionSysconsoleWriteExperimentalBleve,
|
||||
PermissionSysconsoleWriteProductsBoards,
|
||||
PermissionSysconsoleWriteIPFilters,
|
||||
}
|
||||
|
||||
SystemScopedPermissionsMinusSysconsole := []*Permission{
|
||||
|
||||
Ссылка в новой задаче
Block a user