Fixing SanitizeProfile (#3930)
Этот коммит содержится в:
коммит произвёл
Corey Hulen
родитель
717e8197ff
Коммит
eb0111f6bb
29
api/user.go
29
api/user.go
@@ -898,8 +898,7 @@ func getInitialLoad(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
profiles := dp.Data.(map[string]*model.User)
|
profiles := dp.Data.(map[string]*model.User)
|
||||||
|
|
||||||
for k, p := range profiles {
|
for k, p := range profiles {
|
||||||
p.SanitizeProfile(c.IsSystemAdmin(), false, true, true)
|
profiles[k] = sanitizeProfile(c, p)
|
||||||
profiles[k] = p
|
|
||||||
}
|
}
|
||||||
|
|
||||||
il.DirectProfiles = profiles
|
il.DirectProfiles = profiles
|
||||||
@@ -974,8 +973,7 @@ func getProfilesForDirectMessageList(c *Context, w http.ResponseWriter, r *http.
|
|||||||
profiles := result.Data.(map[string]*model.User)
|
profiles := result.Data.(map[string]*model.User)
|
||||||
|
|
||||||
for k, p := range profiles {
|
for k, p := range profiles {
|
||||||
p.SanitizeProfile(c.IsSystemAdmin(), false, false, false)
|
profiles[k] = sanitizeProfile(c, p)
|
||||||
profiles[k] = p
|
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Write([]byte(model.UserMapToJson(profiles)))
|
w.Write([]byte(model.UserMapToJson(profiles)))
|
||||||
@@ -1004,8 +1002,7 @@ func getProfiles(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
profiles := result.Data.(map[string]*model.User)
|
profiles := result.Data.(map[string]*model.User)
|
||||||
|
|
||||||
for k, p := range profiles {
|
for k, p := range profiles {
|
||||||
p.SanitizeProfile(c.IsSystemAdmin(), false, true, true)
|
profiles[k] = sanitizeProfile(c, p)
|
||||||
profiles[k] = p
|
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(model.HEADER_ETAG_SERVER, etag)
|
w.Header().Set(model.HEADER_ETAG_SERVER, etag)
|
||||||
@@ -1026,8 +1023,7 @@ func getDirectProfiles(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
profiles := result.Data.(map[string]*model.User)
|
profiles := result.Data.(map[string]*model.User)
|
||||||
|
|
||||||
for k, p := range profiles {
|
for k, p := range profiles {
|
||||||
p.SanitizeProfile(c.IsSystemAdmin(), false, true, true)
|
profiles[k] = sanitizeProfile(c, p)
|
||||||
profiles[k] = p
|
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set(model.HEADER_ETAG_SERVER, etag)
|
w.Header().Set(model.HEADER_ETAG_SERVER, etag)
|
||||||
@@ -1276,7 +1272,7 @@ func uploadProfileImage(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
l4g.Error(utils.T("api.user.get_me.getting.error"), c.Session.UserId)
|
l4g.Error(utils.T("api.user.get_me.getting.error"), c.Session.UserId)
|
||||||
} else {
|
} else {
|
||||||
user := result.Data.(*model.User)
|
user := result.Data.(*model.User)
|
||||||
user.SanitizeProfile(c.IsSystemAdmin(), false, true, true)
|
user = sanitizeProfile(c, user)
|
||||||
message := model.NewWebSocketEvent("", "", c.Session.UserId, model.WEBSOCKET_EVENT_USER_UPDATED)
|
message := model.NewWebSocketEvent("", "", c.Session.UserId, model.WEBSOCKET_EVENT_USER_UPDATED)
|
||||||
message.Add("user", user)
|
message.Add("user", user)
|
||||||
go Publish(message)
|
go Publish(message)
|
||||||
@@ -1326,7 +1322,7 @@ func updateUser(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
updatedUser := rusers[0]
|
updatedUser := rusers[0]
|
||||||
updatedUser.SanitizeProfile(c.IsSystemAdmin(), false, true, true)
|
updatedUser = sanitizeProfile(c, updatedUser)
|
||||||
|
|
||||||
message := model.NewWebSocketEvent("", "", user.Id, model.WEBSOCKET_EVENT_USER_UPDATED)
|
message := model.NewWebSocketEvent("", "", user.Id, model.WEBSOCKET_EVENT_USER_UPDATED)
|
||||||
message.Add("user", updatedUser)
|
message.Add("user", updatedUser)
|
||||||
@@ -2567,3 +2563,16 @@ func userTyping(req *model.WebSocketRequest) (map[string]interface{}, *model.App
|
|||||||
|
|
||||||
return nil, nil
|
return nil, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func sanitizeProfile(c *Context, user *model.User) *model.User {
|
||||||
|
options := utils.Cfg.GetSanitizeOptions()
|
||||||
|
|
||||||
|
if c.IsSystemAdmin() {
|
||||||
|
options["email"] = true
|
||||||
|
options["fullname"] = true
|
||||||
|
}
|
||||||
|
|
||||||
|
user.SanitizeProfile(options)
|
||||||
|
|
||||||
|
return user
|
||||||
|
}
|
||||||
|
|||||||
@@ -434,6 +434,13 @@ func TestGetDirectProfiles(t *testing.T) {
|
|||||||
|
|
||||||
th.BasicClient.Must(th.BasicClient.CreateDirectChannel(th.BasicUser2.Id))
|
th.BasicClient.Must(th.BasicClient.CreateDirectChannel(th.BasicUser2.Id))
|
||||||
|
|
||||||
|
prevShowEmail := utils.Cfg.PrivacySettings.ShowEmailAddress
|
||||||
|
defer func() {
|
||||||
|
utils.Cfg.PrivacySettings.ShowEmailAddress = prevShowEmail
|
||||||
|
}()
|
||||||
|
|
||||||
|
utils.Cfg.PrivacySettings.ShowEmailAddress = true
|
||||||
|
|
||||||
if result, err := th.BasicClient.GetDirectProfiles(""); err != nil {
|
if result, err := th.BasicClient.GetDirectProfiles(""); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else {
|
} else {
|
||||||
@@ -446,6 +453,34 @@ func TestGetDirectProfiles(t *testing.T) {
|
|||||||
if users[th.BasicUser2.Id] == nil {
|
if users[th.BasicUser2.Id] == nil {
|
||||||
t.Fatal("missing expected user")
|
t.Fatal("missing expected user")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
for _, user := range users {
|
||||||
|
if user.Email == "" {
|
||||||
|
t.Fatal("problem with show email")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
utils.Cfg.PrivacySettings.ShowEmailAddress = false
|
||||||
|
|
||||||
|
if result, err := th.BasicClient.GetDirectProfiles(""); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
} else {
|
||||||
|
users := result.Data.(map[string]*model.User)
|
||||||
|
|
||||||
|
if len(users) != 1 {
|
||||||
|
t.Fatal("map was wrong length")
|
||||||
|
}
|
||||||
|
|
||||||
|
if users[th.BasicUser2.Id] == nil {
|
||||||
|
t.Fatal("missing expected user")
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, user := range users {
|
||||||
|
if user.Email != "" {
|
||||||
|
t.Fatal("problem with show email")
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -454,6 +489,13 @@ func TestGetProfilesForDirectMessageList(t *testing.T) {
|
|||||||
|
|
||||||
th.BasicClient.Must(th.BasicClient.CreateDirectChannel(th.BasicUser2.Id))
|
th.BasicClient.Must(th.BasicClient.CreateDirectChannel(th.BasicUser2.Id))
|
||||||
|
|
||||||
|
prevShowEmail := utils.Cfg.PrivacySettings.ShowEmailAddress
|
||||||
|
defer func() {
|
||||||
|
utils.Cfg.PrivacySettings.ShowEmailAddress = prevShowEmail
|
||||||
|
}()
|
||||||
|
|
||||||
|
utils.Cfg.PrivacySettings.ShowEmailAddress = true
|
||||||
|
|
||||||
if result, err := th.BasicClient.GetProfilesForDirectMessageList(th.BasicTeam.Id); err != nil {
|
if result, err := th.BasicClient.GetProfilesForDirectMessageList(th.BasicTeam.Id); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else {
|
} else {
|
||||||
@@ -462,6 +504,30 @@ func TestGetProfilesForDirectMessageList(t *testing.T) {
|
|||||||
if len(users) < 1 {
|
if len(users) < 1 {
|
||||||
t.Fatal("map was wrong length")
|
t.Fatal("map was wrong length")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
for _, user := range users {
|
||||||
|
if user.Email == "" {
|
||||||
|
t.Fatal("problem with show email")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
utils.Cfg.PrivacySettings.ShowEmailAddress = false
|
||||||
|
|
||||||
|
if result, err := th.BasicClient.GetProfilesForDirectMessageList(th.BasicTeam.Id); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
} else {
|
||||||
|
users := result.Data.(map[string]*model.User)
|
||||||
|
|
||||||
|
if len(users) < 1 {
|
||||||
|
t.Fatal("map was wrong length")
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, user := range users {
|
||||||
|
if user.Email != "" {
|
||||||
|
t.Fatal("problem with show email")
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -250,18 +250,8 @@ func (u *User) ClearNonProfileFields() {
|
|||||||
u.FailedAttempts = 0
|
u.FailedAttempts = 0
|
||||||
}
|
}
|
||||||
|
|
||||||
func (u *User) SanitizeProfile(isSystemAdmin, pwdupdate, fullname, email bool) {
|
func (u *User) SanitizeProfile(options map[string]bool) {
|
||||||
options := map[string]bool{}
|
u.ClearNonProfileFields()
|
||||||
options["passwordupdate"] = pwdupdate
|
|
||||||
|
|
||||||
if isSystemAdmin {
|
|
||||||
options["fullname"] = true
|
|
||||||
options["email"] = true
|
|
||||||
} else {
|
|
||||||
options["fullname"] = fullname
|
|
||||||
options["email"] = email
|
|
||||||
u.ClearNonProfileFields()
|
|
||||||
}
|
|
||||||
|
|
||||||
u.Sanitize(options)
|
u.Sanitize(options)
|
||||||
}
|
}
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user