* Initial comit for ip filtering service implementation

* Add audit logs for IP Filters

* start of webapp work

* Stashing

* Updates based on Agniva's feedback around service vs einterface

* Updates completed

* Commit before refactoring, everything's working

* First pass of cleanup complete, front-end tests added

* actually add files

* Updates to some translation strings, running i18n-extract

* Lock everything behind a feature flag

* Fix tests, try to fix some linter stuff

* Fixed linter for JS, on to scss

* Fixed linter for scss

* Fix linter

* More fixes for pipeline

* Support for IPV6

* Remove tsx file that was removed in masteR

* Revert package.json and package-lock.json to master, add cidr-regex dep into channels/package.json

* Another commit to force fix Github

* Fixes around IPV6. Some suggestions from Matt re: UX review. Fixing pipelines for tests and types on new cidr-regex package

* Changes to address Matt's feedback

* A few more changes for clean up

* Add support for permissions

* Fix vet for OpenAPI spec

* Actually add the yaml file for openapi

* Add permission migration to allow support for IP Filtering

* Fix tests

* Final fixes from Matt

* Remove cancel button from page, update link outs to documentation

* Update test to account for removed cancel button

* Adjustments based on feedback from Harrison

* More fixes from PR feedback

* Add a t to fix translations that doesn't seem to be breaking anyone else?

* More fix

* updates for PR feedback

* Fix linter

* Fix types

* Now fix the linter again

* Add back tests because Harrison was able to get them running

* Adjustments for PR feedback

* Remove admin_definition.jsx

* Fix linter

* [CLD-6453] IP Filtering notification email for sysadmins (#25224)

* Initial commit for IP filtering alert email

* Updates to style for email, addition of ip_filtering email:

* Fix pipelines

* Adjustments from Matt's feedback

* Padding changes

* template diff (#25249)

Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>

* Fix hardcoded true, remove bool return value

---------

Co-authored-by: Mattermost Build <build@mattermost.com>
Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>

* Lock feature behind enterprise license. Drop cidr-regex in favour of ipaddr.js dependency. Refactor isIpAddressWithinRanges to use ipaddr.js

* Add a couple server tests

* fix linter

* Fix types from merge conflicts

---------

Co-authored-by: Mattermost Build <build@mattermost.com>
Co-authored-by: Gabe Jackson <3694686+gabrieljackson@users.noreply.github.com>
Этот коммит содержится в:
Nick Misasi
2023-11-14 09:12:04 -05:00
коммит произвёл GitHub
родитель 7bf9be2619
Коммит e1c851a3ca
82 изменённых файлов: 4533 добавлений и 19 удалений

Просмотреть файл

@@ -555,6 +555,10 @@ func (c *Client4) sharedChannelsRoute() string {
return "/sharedchannels"
}
func (c *Client4) ipFiltersRoute() string {
return "/ip_filtering"
}
func (c *Client4) permissionsRoute() string {
return "/permissions"
}
@@ -8028,6 +8032,52 @@ func (c *Client4) GetProductLimits(ctx context.Context) (*ProductLimits, *Respon
return productLimits, BuildResponse(r), nil
}
func (c *Client4) GetIPFilters(ctx context.Context) (*AllowedIPRanges, *Response, error) {
r, err := c.DoAPIGet(ctx, c.ipFiltersRoute(), "")
if err != nil {
return nil, BuildResponse(r), err
}
defer closeBody(r)
var allowedIPRanges *AllowedIPRanges
json.NewDecoder(r.Body).Decode(&allowedIPRanges)
return allowedIPRanges, BuildResponse(r), nil
}
func (c *Client4) ApplyIPFilters(ctx context.Context, allowedRanges *AllowedIPRanges) (*AllowedIPRanges, *Response, error) {
payload, err := json.Marshal(allowedRanges)
if err != nil {
return nil, nil, NewAppError("ApplyIPFilters", "api.marshal_error", nil, "", http.StatusInternalServerError).Wrap(err)
}
r, err := c.DoAPIPostBytes(ctx, c.ipFiltersRoute(), payload)
if err != nil {
return nil, BuildResponse(r), err
}
defer closeBody(r)
var allowedIPRanges *AllowedIPRanges
json.NewDecoder(r.Body).Decode(&allowedIPRanges)
return allowedIPRanges, BuildResponse(r), nil
}
func (c *Client4) GetMyIP(ctx context.Context) (*GetIPAddressResponse, *Response, error) {
r, err := c.DoAPIGet(ctx, c.ipFiltersRoute()+"/my_ip", "")
if err != nil {
return nil, BuildResponse(r), err
}
defer closeBody(r)
var response *GetIPAddressResponse
json.NewDecoder(r.Body).Decode(&response)
return response, BuildResponse(r), nil
}
func (c *Client4) CreateCustomerPayment(ctx context.Context) (*StripeSetupIntent, *Response, error) {
r, err := c.DoAPIPost(ctx, c.cloudRoute()+"/payment", "")
if err != nil {

Просмотреть файл

@@ -44,7 +44,8 @@ type FeatureFlags struct {
StreamlinedMarketplace bool
ConsumePostHook bool
CloudIPFiltering bool
ConsumePostHook bool
}
func (f *FeatureFlags) SetDefaults() {
@@ -60,6 +61,7 @@ func (f *FeatureFlags) SetDefaults() {
f.CloudReverseTrial = false
f.EnableExportDirectDownload = false
f.StreamlinedMarketplace = true
f.CloudIPFiltering = false
f.ConsumePostHook = false
}

20
server/public/model/ip_filtering.go Обычный файл
Просмотреть файл

@@ -0,0 +1,20 @@
package model
type AllowedIPRanges []AllowedIPRange
type AllowedIPRange struct {
CIDRBlock string `json:"cidr_block"`
Description string `json:"description"`
Enabled bool `json:"enabled"`
OwnerID string `json:"owner_id"`
}
func (air *AllowedIPRanges) Auditable() map[string]interface{} {
return map[string]interface{}{
"AllowedIPRanges": air,
}
}
type GetIPAddressResponse struct {
IP string `json:"ip"`
}

Просмотреть файл

@@ -44,4 +44,5 @@ const (
MigrationKeyElasticsearchFixChannelIndex = "elasticsearch_fix_channel_index_migration"
MigrationKeyS3Path = "s3_path_migration"
MigrationKeyDeleteEmptyDrafts = "delete_empty_drafts_migration"
MigrationKeyAddIPFilteringPermissions = "add_ip_filtering_permissions"
)

Просмотреть файл

@@ -267,6 +267,9 @@ var PermissionSysconsoleWriteSitePublicLinks *Permission
var PermissionSysconsoleReadSiteNotices *Permission
var PermissionSysconsoleWriteSiteNotices *Permission
var PermissionSysconsoleReadIPFilters *Permission
var PermissionSysconsoleWriteIPFilters *Permission
var PermissionSysconsoleReadAuthentication *Permission
var PermissionSysconsoleWriteAuthentication *Permission
@@ -1646,6 +1649,20 @@ func initializePermissions() {
PermissionScopeSystem,
}
PermissionSysconsoleReadIPFilters = &Permission{
"sysconsole_read_site_ip_filters",
"",
"",
PermissionScopeSystem,
}
PermissionSysconsoleWriteIPFilters = &Permission{
"sysconsole_write_site_ip_filters",
"",
"",
PermissionScopeSystem,
}
// Deprecated
PermissionSysconsoleReadAuthentication = &Permission{
"sysconsole_read_authentication",
@@ -2160,6 +2177,7 @@ func initializePermissions() {
PermissionSysconsoleReadExperimentalFeatureFlags,
PermissionSysconsoleReadExperimentalBleve,
PermissionSysconsoleReadProductsBoards,
PermissionSysconsoleReadIPFilters,
}
SysconsoleWritePermissions = []*Permission{
@@ -2218,6 +2236,7 @@ func initializePermissions() {
PermissionSysconsoleWriteExperimentalFeatureFlags,
PermissionSysconsoleWriteExperimentalBleve,
PermissionSysconsoleWriteProductsBoards,
PermissionSysconsoleWriteIPFilters,
}
SystemScopedPermissionsMinusSysconsole := []*Permission{