MM-63195: Enforce MFA requirement for non-self requests (#30290)
https://mattermost.atlassian.net/browse/MM-63195 ```release-note NONE ```
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
96c2d4ae56
Коммит
fa9af97727
@@ -1650,7 +1650,12 @@ func updateUserMfa(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if user, err := c.App.GetUser(c.Params.UserId); err == nil {
|
if appErr := c.App.MFARequired(c.AppContext); !c.AppContext.Session().Local && c.AppContext.Session().UserId != c.Params.UserId && appErr != nil {
|
||||||
|
c.Err = appErr
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if user, appErr := c.App.GetUser(c.Params.UserId); appErr == nil {
|
||||||
audit.AddEventParameterAuditable(auditRec, "user", user)
|
audit.AddEventParameterAuditable(auditRec, "user", user)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1672,8 +1677,8 @@ func updateUserMfa(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
|
|
||||||
c.LogAudit("attempt")
|
c.LogAudit("attempt")
|
||||||
|
|
||||||
if err := c.App.UpdateMfa(c.AppContext, activate, c.Params.UserId, code); err != nil {
|
if appErr := c.App.UpdateMfa(c.AppContext, activate, c.Params.UserId, code); appErr != nil {
|
||||||
c.Err = err
|
c.Err = appErr
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -3443,20 +3443,44 @@ func TestUpdateUserMfa(t *testing.T) {
|
|||||||
defer th.TearDown()
|
defer th.TearDown()
|
||||||
|
|
||||||
th.App.Srv().SetLicense(model.NewTestLicense("mfa"))
|
th.App.Srv().SetLicense(model.NewTestLicense("mfa"))
|
||||||
|
t.Run("Without enforcing", func(t *testing.T) {
|
||||||
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.ServiceSettings.EnableMultifactorAuthentication = true })
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.ServiceSettings.EnableMultifactorAuthentication = true })
|
||||||
|
|
||||||
session, _ := th.App.GetSession(th.Client.AuthToken)
|
session, _ := th.App.GetSession(th.Client.AuthToken)
|
||||||
session.IsOAuth = true
|
session.IsOAuth = true
|
||||||
th.App.AddSessionToCache(session)
|
th.App.AddSessionToCache(session)
|
||||||
|
|
||||||
|
defer th.Server.Platform().ClearUserSessionCacheLocal(th.BasicUser.Id)
|
||||||
|
|
||||||
resp, err := th.Client.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
resp, err := th.Client.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
||||||
require.Error(t, err)
|
require.Error(t, err)
|
||||||
CheckForbiddenStatus(t, resp)
|
CheckForbiddenStatus(t, resp)
|
||||||
|
|
||||||
th.TestForSystemAdminAndLocal(t, func(t *testing.T, client *model.Client4) {
|
th.TestForSystemAdminAndLocal(t, func(t *testing.T, client *model.Client4) {
|
||||||
_, err = client.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
_, err := client.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
})
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
t.Run("Enforcing", func(t *testing.T) {
|
||||||
|
th.App.UpdateConfig(func(cfg *model.Config) {
|
||||||
|
*cfg.ServiceSettings.EnableMultifactorAuthentication = true
|
||||||
|
*cfg.ServiceSettings.EnforceMultifactorAuthentication = true
|
||||||
|
})
|
||||||
|
|
||||||
|
resp, err := th.Client.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
||||||
|
require.NoError(t, err)
|
||||||
|
CheckOKStatus(t, resp)
|
||||||
|
|
||||||
|
resp, err = th.LocalClient.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
||||||
|
require.NoError(t, err)
|
||||||
|
CheckOKStatus(t, resp)
|
||||||
|
|
||||||
|
resp, err = th.SystemAdminClient.UpdateUserMfa(context.Background(), th.BasicUser.Id, "12345", false)
|
||||||
|
require.Error(t, err)
|
||||||
|
CheckForbiddenStatus(t, resp)
|
||||||
|
CheckErrorID(t, err, "api.context.mfa_required.app_error")
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestUserLoginMFAFlow(t *testing.T) {
|
func TestUserLoginMFAFlow(t *testing.T) {
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user