mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 23:16:37 +08:00
fix(config): serve public settings and enforce login CAP
Public config now comes from admin as a flat visibility=1 map instead of a cross-plugin query that compared an integer column to "visible". Login and register resolve CaptchaService per request so CAP is not skipped when user applies before cap.
This commit is contained in:
@@ -18,6 +18,14 @@ import (
|
||||
|
||||
const maskedConfigValue = "******"
|
||||
|
||||
// PublicConfigAdapter exposes visibility=1 system configs as PublicConfigProvider.
|
||||
type PublicConfigAdapter struct{}
|
||||
|
||||
// PublicConfig returns the unauthenticated public config map.
|
||||
func (PublicConfigAdapter) PublicConfig(ctx context.Context) (map[string]string, error) {
|
||||
return PublicSystemConfigs(ctx)
|
||||
}
|
||||
|
||||
// PublicSystemConfigs returns the key/value map exposed to unauthenticated clients.
|
||||
func PublicSystemConfigs(ctx context.Context) (map[string]string, error) {
|
||||
configs, err := repository.ListVisibleSystemConfigs(ctx)
|
||||
|
||||
@@ -69,6 +69,51 @@ func setupSystemConfigTest(t *testing.T) (*gorm.DB, func()) {
|
||||
return sqliteDB, cleanup
|
||||
}
|
||||
|
||||
func TestPublicSystemConfigsExposesVisibleKeys(t *testing.T) {
|
||||
dbConn, cleanup := setupSystemConfigTest(t)
|
||||
defer cleanup()
|
||||
repository.ResetSystemConfigRAMCacheForTest()
|
||||
ctx := context.Background()
|
||||
|
||||
hidden := model.SystemConfig{
|
||||
Key: "secret_key",
|
||||
Value: "nope",
|
||||
Type: "system",
|
||||
Visibility: model.ConfigVisibilityHidden,
|
||||
}
|
||||
visible := model.SystemConfig{
|
||||
Key: model.ConfigKeyCapLoginEnabled,
|
||||
Value: "true",
|
||||
Type: "system",
|
||||
Visibility: model.ConfigVisibilityVisible,
|
||||
}
|
||||
if err := dbConn.Create(&hidden).Error; err != nil {
|
||||
t.Fatalf("Create(hidden) error = %v", err)
|
||||
}
|
||||
if err := dbConn.Create(&visible).Error; err != nil {
|
||||
t.Fatalf("Create(visible) error = %v", err)
|
||||
}
|
||||
|
||||
got, err := service.PublicSystemConfigs(ctx)
|
||||
if err != nil {
|
||||
t.Fatalf("PublicSystemConfigs() error = %v", err)
|
||||
}
|
||||
if got[model.ConfigKeyCapLoginEnabled] != "true" {
|
||||
t.Fatalf("PublicSystemConfigs()[%s] = %q, want %q", model.ConfigKeyCapLoginEnabled, got[model.ConfigKeyCapLoginEnabled], "true")
|
||||
}
|
||||
if _, ok := got["secret_key"]; ok {
|
||||
t.Fatalf("PublicSystemConfigs() leaked hidden key secret_key")
|
||||
}
|
||||
|
||||
viaProvider, err := service.PublicConfigAdapter{}.PublicConfig(ctx)
|
||||
if err != nil {
|
||||
t.Fatalf("PublicConfigAdapter.PublicConfig() error = %v", err)
|
||||
}
|
||||
if viaProvider[model.ConfigKeyCapLoginEnabled] != "true" {
|
||||
t.Fatalf("PublicConfigAdapter.PublicConfig()[%s] = %q, want %q", model.ConfigKeyCapLoginEnabled, viaProvider[model.ConfigKeyCapLoginEnabled], "true")
|
||||
}
|
||||
}
|
||||
|
||||
func TestListSystemConfigsByKeys_EmptyKeys(t *testing.T) {
|
||||
result, err := repository.ListSystemConfigsByKeys(context.Background(), nil)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user