mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
dbeaver/pro#5711 Add validation for team id (#3459)
* dbeaver/pro#5711 Add validation for team id * dbeaver/pro#5711 Add validation for user id * dbeaver/pro#5711 add user name and team id validation --------- Co-authored-by: naumov <iamemptyhuh@gmail.com> Co-authored-by: Evgenia <139753579+EvgeniaBzzz@users.noreply.github.com>
This commit is contained in:
co-authored by
naumov
Evgenia
parent
a098db62c3
commit
aba27cf9d3
+12
@@ -51,6 +51,7 @@ import org.jkiss.dbeaver.model.secret.DBSSecretController;
|
||||
import org.jkiss.dbeaver.model.security.*;
|
||||
import org.jkiss.dbeaver.model.security.user.SMTeam;
|
||||
import org.jkiss.dbeaver.model.security.user.SMUser;
|
||||
import org.jkiss.dbeaver.utils.GeneralUtils;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
import java.text.MessageFormat;
|
||||
@@ -162,6 +163,11 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
throw new DBWebException("Empty user name");
|
||||
}
|
||||
String userId = userName.toLowerCase();
|
||||
try {
|
||||
GeneralUtils.validateResourceNameUnconditionally(userId);
|
||||
} catch (DBException e) {
|
||||
throw new DBWebException(e.getMessage(), e);
|
||||
}
|
||||
webSession.addInfoMessage("Create new user - " + userId);
|
||||
|
||||
try {
|
||||
@@ -223,6 +229,12 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
if (user == null) {
|
||||
throw new DBWebException("Admin user is not found");
|
||||
}
|
||||
try {
|
||||
GeneralUtils.validateResourceNameUnconditionally(teamId);
|
||||
} catch (DBException e) {
|
||||
throw new DBWebException(e.getMessage(), e);
|
||||
}
|
||||
|
||||
webSession.addInfoMessage("Create new team - " + teamId);
|
||||
try {
|
||||
SMTeam newTeam = webSession.getAdminSecurityController().createTeam(
|
||||
|
||||
+12
-3
@@ -1,13 +1,13 @@
|
||||
/*
|
||||
* CloudBeaver - Cloud Database Manager
|
||||
* Copyright (C) 2020-2024 DBeaver Corp and others
|
||||
* Copyright (C) 2020-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0.
|
||||
* you may not use this file except in compliance with the License.
|
||||
*/
|
||||
import { observer } from 'mobx-react-lite';
|
||||
|
||||
import { Container, Group, InputField, Textarea, useAutoLoad, useResource, useTranslate } from '@cloudbeaver/core-blocks';
|
||||
import { Container, Group, InputField, Textarea, useAutoLoad, useCustomInputValidation, useResource, useTranslate } from '@cloudbeaver/core-blocks';
|
||||
import { ServerConfigResource } from '@cloudbeaver/core-root';
|
||||
import { type TabContainerPanelComponent, useTab, useTabState } from '@cloudbeaver/core-ui';
|
||||
|
||||
@@ -15,6 +15,7 @@ import type { TeamFormProps } from '../TeamsAdministrationFormService.js';
|
||||
import { Permissions } from './Permissions.js';
|
||||
import { TeamMetaParameters } from './TeamMetaParameters.js';
|
||||
import type { TeamOptionsFormPart } from './TeamOptionsFormPart.js';
|
||||
import { ENTITY_ID_VALIDATION } from '../../../shared/ENTITY_ID_VALIDATION.js';
|
||||
|
||||
export const TeamOptions: TabContainerPanelComponent<TeamFormProps> = observer(function TeamOptions({ formState, tabId }) {
|
||||
const serverConfigResource = useResource(TeamOptions, ServerConfigResource, undefined);
|
||||
@@ -26,10 +27,18 @@ export const TeamOptions: TabContainerPanelComponent<TeamFormProps> = observer(f
|
||||
|
||||
useAutoLoad(TeamOptions, tabState, tab.selected && !loaded);
|
||||
|
||||
const idValidationRef = useCustomInputValidation<string>(value => {
|
||||
if (!value.match(ENTITY_ID_VALIDATION)) {
|
||||
return translate('plugin_authentication_administration_team_id_validation_error');
|
||||
}
|
||||
|
||||
return null;
|
||||
});
|
||||
|
||||
return (
|
||||
<Container overflow>
|
||||
<Group small gap>
|
||||
<InputField name="teamId" state={tabState.state} readOnly={edit || formState.isDisabled} required tiny fill>
|
||||
<InputField ref={idValidationRef} name="teamId" state={tabState.state} readOnly={edit || formState.isDisabled} required tiny fill>
|
||||
{translate('administration_teams_team_id')}
|
||||
</InputField>
|
||||
<InputField name="teamName" state={tabState.state} readOnly={formState.isDisabled} required tiny fill>
|
||||
|
||||
+11
-1
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* CloudBeaver - Cloud Database Manager
|
||||
* Copyright (C) 2020-2024 DBeaver Corp and others
|
||||
* Copyright (C) 2020-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0.
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -22,6 +22,7 @@ import { isValuesEqual } from '@cloudbeaver/core-utils';
|
||||
|
||||
import type { UserFormProps } from '../AdministrationUserFormService.js';
|
||||
import type { UserFormInfoPart } from './UserFormInfoPart.js';
|
||||
import { ENTITY_ID_VALIDATION } from '../../shared/ENTITY_ID_VALIDATION.js';
|
||||
|
||||
const PASSWORD_PLACEHOLDER = '••••••';
|
||||
|
||||
@@ -44,6 +45,14 @@ export const UserFormInfoCredentials = observer<Props>(function UserFormInfoCred
|
||||
local = !editing || (!!userInfo.data && isLocalUser(userInfo.data));
|
||||
}
|
||||
|
||||
const usernameValidationRef = useCustomInputValidation<string>(value => {
|
||||
if (!value.match(ENTITY_ID_VALIDATION)) {
|
||||
return translate('plugin_authentication_administration_user_username_validation_error');
|
||||
}
|
||||
|
||||
return null;
|
||||
});
|
||||
|
||||
const passwordRepeatRef = useCustomInputValidation<string>(value => {
|
||||
if (!isValuesEqual(value, tabState.state.password, null)) {
|
||||
return translate('authentication_user_passwords_not_match');
|
||||
@@ -55,6 +64,7 @@ export const UserFormInfoCredentials = observer<Props>(function UserFormInfoCred
|
||||
<Container gap vertical>
|
||||
<GroupTitle keepSize>{translate('authentication_user_credentials')}</GroupTitle>
|
||||
<InputField
|
||||
ref={usernameValidationRef}
|
||||
description={!editing ? translate('authentication_user_name_description') : undefined}
|
||||
type="text"
|
||||
name="userId"
|
||||
|
||||
+9
@@ -0,0 +1,9 @@
|
||||
/*
|
||||
* CloudBeaver - Cloud Database Manager
|
||||
* Copyright (C) 2020-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0.
|
||||
* you may not use this file except in compliance with the License.
|
||||
*/
|
||||
|
||||
export const ENTITY_ID_VALIDATION = /^(?!\.)[^\\/:\\"'<>|?*]+$/u;
|
||||
@@ -138,4 +138,13 @@ export default [
|
||||
|
||||
['plugin_authentication_administration_team_form_edit_label', 'Team editing form'],
|
||||
['plugin_authentication_administration_user_form_edit_label', 'User editing form'],
|
||||
|
||||
[
|
||||
'plugin_authentication_administration_user_username_validation_error',
|
||||
"User's name may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
[
|
||||
'plugin_authentication_administration_team_id_validation_error',
|
||||
"Team's ID may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
];
|
||||
|
||||
@@ -127,4 +127,13 @@ export default [
|
||||
],
|
||||
['plugin_authentication_administration_team_form_edit_label', 'Team editing form'],
|
||||
['plugin_authentication_administration_user_form_edit_label', 'User editing form'],
|
||||
|
||||
[
|
||||
'plugin_authentication_administration_user_username_validation_error',
|
||||
"User's name may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
[
|
||||
'plugin_authentication_administration_team_id_validation_error',
|
||||
"Team's ID may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
];
|
||||
|
||||
@@ -85,4 +85,13 @@ export default [
|
||||
|
||||
['plugin_authentication_administration_team_form_edit_label', 'Team editing form'],
|
||||
['plugin_authentication_administration_user_form_edit_label', 'User editing form'],
|
||||
|
||||
[
|
||||
'plugin_authentication_administration_user_username_validation_error',
|
||||
"User's name may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
[
|
||||
'plugin_authentication_administration_team_id_validation_error',
|
||||
"Team's ID may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
];
|
||||
|
||||
@@ -146,4 +146,13 @@ export default [
|
||||
|
||||
['plugin_authentication_administration_team_form_edit_label', 'Форма редактирования команды'],
|
||||
['plugin_authentication_administration_user_form_edit_label', 'Форма редактирования пользователя'],
|
||||
|
||||
[
|
||||
'plugin_authentication_administration_user_username_validation_error',
|
||||
'Имя пользователя не может содержать следующие символы / : " \\ \' <> | ? * и не может начинаться с точки',
|
||||
],
|
||||
[
|
||||
'plugin_authentication_administration_team_id_validation_error',
|
||||
'ID команды не может содержать следующие символы / : " \\ \' <> | ? * и не может начинаться с точки',
|
||||
],
|
||||
];
|
||||
|
||||
@@ -136,4 +136,13 @@ export default [
|
||||
],
|
||||
['plugin_authentication_administration_team_form_edit_label', 'Biểu mẫu chỉnh sửa nhóm'],
|
||||
['plugin_authentication_administration_user_form_edit_label', 'Biểu mẫu chỉnh sửa người dùng'],
|
||||
|
||||
[
|
||||
'plugin_authentication_administration_user_username_validation_error',
|
||||
"User's name may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
[
|
||||
'plugin_authentication_administration_team_id_validation_error',
|
||||
"Team's ID may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
];
|
||||
|
||||
@@ -117,4 +117,13 @@ export default [
|
||||
|
||||
['plugin_authentication_administration_team_form_edit_label', 'Team editing form'],
|
||||
['plugin_authentication_administration_user_form_edit_label', 'User editing form'],
|
||||
|
||||
[
|
||||
'plugin_authentication_administration_user_username_validation_error',
|
||||
"User's name may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
[
|
||||
'plugin_authentication_administration_team_id_validation_error',
|
||||
"Team's ID may not contain the following symbols / : \" \\ ' <> | ? * and can't start with a dot",
|
||||
],
|
||||
];
|
||||
|
||||
Reference in New Issue
Block a user