From dfbb2846a5d6610428fcd220cfc812fba8dc1dd2 Mon Sep 17 00:00:00 2001 From: Ruslan Musaev <43766501+HocKu7@users.noreply.github.com> Date: Thu, 24 Apr 2025 12:55:53 +0200 Subject: [PATCH] Dbeaver/pro#5168 avoid leakage of lincense (#3343) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * dbeaver/pro#5168 avoid leakage of license * dbeaver/pro#5168 avoid leakage of license * dbeaver/pro#5168 avoid leakage of license * dbeaver/pro#5168 avoid leakage of license * CB-5168 fix schema * [#113] Add clsx dependency to UI kit (#3335) * chore: add clsx dependency to ui-kit * chore: import clsx from ui-kit * refactor: use clsx for class management in Button * refactor: use clsx in Checkbox * refactor: use clsx in Input component * feat: use clsx in radio and radiogroup * feat: use clsx in Select component * feat: reexport VisuallyHidden and Focus trap components from ariakit * CB-5839 fix: resource blocking (#3199) * CB-5839 fix: resource blocking * CB-5839 fix: unlock nav resources * fix: connections loading * feat: select new folder or connection * chore: localization * chore: revert improvements * fix: load connections list for connection selector * fix: error * fix: wrong action handler * CB-5839 fix: resources tree validation * fix: reaction concurrency * CB-5839 fixes build for new CellFormatter (ObjectMenuCell) after merge conflicts * СB-5839 changes delay for menu item loaders * CB-5839 fix: keys intersection detection in resources * CB-5839 fix: keys intersection detection in resources --------- Co-authored-by: mr-anton-t <42037741+mr-anton-t@users.noreply.github.com> Co-authored-by: Daria Marutkina <125263541+dariamarutkina@users.noreply.github.com> Co-authored-by: sergeyteleshev Co-authored-by: Evgenia <139753579+EvgeniaBzzz@users.noreply.github.com> * CB-6308 fix: grid auto-size (#3298) * CB-6308 fix: grid auto-size * CB-6308 fix: grid auto size * CB-6308 fix: icons sizing in grid * CB-6308 fix: grid header * CB-6308 fix: types * fix: min-width for columns --------- Co-authored-by: mr-anton-t <42037741+mr-anton-t@users.noreply.github.com> Co-authored-by: Daria Marutkina <125263541+dariamarutkina@users.noreply.github.com> * CB 6296 Delete row shortcut not working (#3340) * CB-6296 fix: delete keystroke marks selected row for deletion * CB-6296 fix: focus first element on load, remove extra handler It was noticed that just after the open, onKeyDown event doesn't reach DataGrid, because focus was not in sync with lib. Also fixes CB-6229 since they have the same root problem with encountered bag * CB-6286 refactor: change onCellKeyDown handler interface inside DataGridProps * CB-6296 refactor: set initial focus differently * CB-6296 refactor: remove manual scroll control We use grid inner scrollToCell method and don't need additional native scrolling * refactor: don't expose inner data-grid type --------- Co-authored-by: Evgenia <139753579+EvgeniaBzzz@users.noreply.github.com> Co-authored-by: Alexey * CB-5168 fix * CB-5168 fix schema * dbeaver#pro5168 hide product config for anonym * dbeaver/pro#5168 avoid leakage of lincense * dbeaver/pro#5168 avoid leakage of lincense * dbeaver/pro#5168 avoid leakage of lincense --------- Co-authored-by: Sychev Andrey <44414066+SychevAndrey@users.noreply.github.com> Co-authored-by: Alexey Co-authored-by: mr-anton-t <42037741+mr-anton-t@users.noreply.github.com> Co-authored-by: Daria Marutkina <125263541+dariamarutkina@users.noreply.github.com> Co-authored-by: sergeyteleshev Co-authored-by: Evgenia <139753579+EvgeniaBzzz@users.noreply.github.com> Co-authored-by: naumov --- .../src/io/cloudbeaver/model/WebProductInfo.java | 11 ++++++++++- .../src/io/cloudbeaver/model/WebServerConfig.java | 9 +++++++-- .../io/cloudbeaver/service/core/DBWServiceCore.java | 2 +- .../service/core/WebServiceBindingCore.java | 2 +- .../cloudbeaver/service/core/impl/WebServiceCore.java | 7 +++++-- webapp/packages/core-root/src/ProductInfoResource.ts | 8 ++++---- webapp/packages/plugin-product/package.json | 1 + .../packages/plugin-product/src/ProductBootstrap.ts | 6 ++++-- .../packages/plugin-product/src/ProductInfoDialog.tsx | 7 ++++--- webapp/packages/plugin-product/tsconfig.json | 3 +++ webapp/yarn.lock | 1 + 11 files changed, 41 insertions(+), 16 deletions(-) diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebProductInfo.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebProductInfo.java index f366371837..3e5940060e 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebProductInfo.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebProductInfo.java @@ -32,6 +32,12 @@ import java.util.Date; */ public class WebProductInfo { + private final boolean provideSensitiveInformation; + + public WebProductInfo(boolean provideSensitiveInformation) { + this.provideSensitiveInformation = provideSensitiveInformation; + } + @Property public String getId() { return CommonUtils.notEmpty(Platform.getProduct().getId()); @@ -68,7 +74,9 @@ public class WebProductInfo { @Property public String getLicenseInfo() { - return ServletAppUtils.getServletApplication().getInfoDetails(new VoidProgressMonitor()); + return provideSensitiveInformation + ? ServletAppUtils.getServletApplication().getInfoDetails(new VoidProgressMonitor()) + : ""; } @Property @@ -83,4 +91,5 @@ public class WebProductInfo { return CommonUtils.notEmpty(product.getProperty("productPurchaseURL")); } + } diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebServerConfig.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebServerConfig.java index b1ec00ef96..5b3b5b9d92 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebServerConfig.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/model/WebServerConfig.java @@ -40,6 +40,7 @@ import java.util.Map; public class WebServerConfig { private final WebApplication application; + private boolean provideSensitiveInformation = true; public WebServerConfig(@NotNull WebApplication application) { this.application = application; @@ -92,7 +93,7 @@ public class WebServerConfig { @Property public String getLicenseStatus() { - return application.getLicenseStatus(); + return provideSensitiveInformation ? application.getLicenseStatus() : ""; } @Property @@ -168,7 +169,7 @@ public class WebServerConfig { @Property public WebProductInfo getProductInfo() { - return new WebProductInfo(); + return new WebProductInfo(provideSensitiveInformation); } @Property @@ -180,4 +181,8 @@ public class WebServerConfig { public Boolean isDistributed() { return application.isDistributed(); } + + public void setProvideSensitiveInformation(boolean provideSensitiveInformation) { + this.provideSensitiveInformation = provideSensitiveInformation; + } } diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java index 67c2bfc335..028e937780 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java @@ -39,7 +39,7 @@ import java.util.Map; public interface DBWServiceCore extends DBWService { @WebAction(authRequired = false, initializationRequired = false) - WebServerConfig getServerConfig() throws DBWebException; + WebServerConfig getServerConfig(@Nullable WebSession webSession) throws DBWebException; /** * Returns information of system. diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/WebServiceBindingCore.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/WebServiceBindingCore.java index 65252b753c..15375dd792 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/WebServiceBindingCore.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/WebServiceBindingCore.java @@ -52,7 +52,7 @@ public class WebServiceBindingCore extends WebServiceBindingBase public void bindWiring(DBWBindingContext model) throws DBWebException { WebAppSessionManager sessionManager = WebAppUtils.getWebApplication().getSessionManager(); model.getQueryType() - .dataFetcher("serverConfig", env -> getService(env).getServerConfig()) + .dataFetcher("serverConfig", env -> getService(env).getServerConfig(findWebSession(env))) .dataFetcher("systemInfo", env -> getService(env).getSystemInformationProperties(getWebSession(env))) .dataFetcher("productSettings", env -> getService(env).getProductSettings(getWebSession(env))) diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/impl/WebServiceCore.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/impl/WebServiceCore.java index 675a10b255..8b954ae6f9 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/impl/WebServiceCore.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/impl/WebServiceCore.java @@ -69,8 +69,11 @@ public class WebServiceCore implements DBWServiceCore { private static final Log log = Log.getLog(WebServiceCore.class); @Override - public WebServerConfig getServerConfig() { - return WebAppUtils.getWebApplication().getWebServerConfig(); + public WebServerConfig getServerConfig(@Nullable WebSession webSession) { + WebServerConfig webServerConfig = WebAppUtils.getWebApplication().getWebServerConfig(); + webServerConfig.setProvideSensitiveInformation(webServerConfig.isConfigurationMode() || + (webSession != null && webSession.getUser() != null)); + return webServerConfig; } @Override diff --git a/webapp/packages/core-root/src/ProductInfoResource.ts b/webapp/packages/core-root/src/ProductInfoResource.ts index 932f9ed27e..0a7f892e4b 100644 --- a/webapp/packages/core-root/src/ProductInfoResource.ts +++ b/webapp/packages/core-root/src/ProductInfoResource.ts @@ -1,6 +1,6 @@ /* * CloudBeaver - Cloud Database Manager - * Copyright (C) 2020-2024 DBeaver Corp and others + * Copyright (C) 2020-2025 DBeaver Corp and others * * Licensed under the Apache License, Version 2.0. * you may not use this file except in compliance with the License. @@ -9,7 +9,7 @@ import { injectable } from '@cloudbeaver/core-di'; import { CachedDataResource } from '@cloudbeaver/core-resource'; import { GraphQLService, type ProductInfoFragment } from '@cloudbeaver/core-sdk'; -import { ServerConfigResource } from './ServerConfigResource.js'; +import { SessionDataResource } from './SessionDataResource.js'; export type ProductInfo = ProductInfoFragment['productInfo']; @@ -17,10 +17,10 @@ export type ProductInfo = ProductInfoFragment['productInfo']; export class ProductInfoResource extends CachedDataResource { constructor( private readonly graphQLService: GraphQLService, - serverConfigResource: ServerConfigResource, + sessionDataResource: SessionDataResource, ) { super(() => null, undefined, []); - this.sync(serverConfigResource); + this.sync(sessionDataResource); } protected async loader(): Promise { diff --git a/webapp/packages/plugin-product/package.json b/webapp/packages/plugin-product/package.json index 25302d3d77..cf5c052462 100644 --- a/webapp/packages/plugin-product/package.json +++ b/webapp/packages/plugin-product/package.json @@ -19,6 +19,7 @@ "validate-dependencies": "core-cli-validate-dependencies" }, "dependencies": { + "@cloudbeaver/core-authentication": "workspace:*", "@cloudbeaver/core-blocks": "workspace:*", "@cloudbeaver/core-di": "workspace:*", "@cloudbeaver/core-dialogs": "workspace:*", diff --git a/webapp/packages/plugin-product/src/ProductBootstrap.ts b/webapp/packages/plugin-product/src/ProductBootstrap.ts index 085fbd341a..0e41d4b510 100644 --- a/webapp/packages/plugin-product/src/ProductBootstrap.ts +++ b/webapp/packages/plugin-product/src/ProductBootstrap.ts @@ -1,6 +1,6 @@ /* * CloudBeaver - Cloud Database Manager - * Copyright (C) 2020-2024 DBeaver Corp and others + * Copyright (C) 2020-2025 DBeaver Corp and others * * Licensed under the Apache License, Version 2.0. * you may not use this file except in compliance with the License. @@ -10,6 +10,7 @@ import { Bootstrap, injectable } from '@cloudbeaver/core-di'; import { CommonDialogService } from '@cloudbeaver/core-dialogs'; import { ProductInfoResource } from '@cloudbeaver/core-root'; import { MenuBaseItem, MenuService } from '@cloudbeaver/core-view'; +import { UserInfoResource } from '@cloudbeaver/core-authentication'; import { TOP_NAV_BAR_SETTINGS_MENU } from '@cloudbeaver/plugin-settings-menu'; const ProductInfoDialog = importLazyComponent(() => import('./ProductInfoDialog.js').then(m => m.ProductInfoDialog)); @@ -18,6 +19,7 @@ const ProductInfoDialog = importLazyComponent(() => import('./ProductInfoDialog. export class ProductBootstrap extends Bootstrap { constructor( private readonly productInfoResource: ProductInfoResource, + private readonly userInfoResource: UserInfoResource, private readonly commonDialogService: CommonDialogService, private readonly menuService: MenuService, ) { @@ -27,7 +29,7 @@ export class ProductBootstrap extends Bootstrap { override register(): void { this.menuService.addCreator({ menus: [TOP_NAV_BAR_SETTINGS_MENU], - isApplicable: () => !!this.productInfoResource.data, + isApplicable: () => !this.userInfoResource.isAnonymous() && !!this.productInfoResource.data, getItems: (context, items) => [ ...items, new MenuBaseItem( diff --git a/webapp/packages/plugin-product/src/ProductInfoDialog.tsx b/webapp/packages/plugin-product/src/ProductInfoDialog.tsx index 0d7fb20d43..0439db8aae 100644 --- a/webapp/packages/plugin-product/src/ProductInfoDialog.tsx +++ b/webapp/packages/plugin-product/src/ProductInfoDialog.tsx @@ -1,6 +1,6 @@ /* * CloudBeaver - Cloud Database Manager - * Copyright (C) 2020-2024 DBeaver Corp and others + * Copyright (C) 2020-2025 DBeaver Corp and others * * Licensed under the Apache License, Version 2.0. * you may not use this file except in compliance with the License. @@ -20,6 +20,7 @@ import { Link, s, TextPlaceholder, + useResource, useS, useTranslate, } from '@cloudbeaver/core-blocks'; @@ -34,12 +35,12 @@ import ProductInfoDialogStyles from './ProductInfoDialog.module.css'; export const ProductInfoDialog = observer>(function ProductInfoDialog(props) { const translate = useTranslate(); - const serverConfigResource = useService(ProductInfoResource); + const productInfoResource = useResource(ProductInfoDialog, ProductInfoResource, undefined); const themeService = useService(ThemeService); const version = useAppVersion(); - const productInfo = serverConfigResource.data; + const productInfo = productInfoResource.data; const logoIcon = themeService.themeId === 'light' ? '/icons/product-logo_light.svg' : '/icons/product-logo_dark.svg'; const styles = useS(ProductInfoDialogStyles); diff --git a/webapp/packages/plugin-product/tsconfig.json b/webapp/packages/plugin-product/tsconfig.json index 75ed829737..b8af8fecdb 100644 --- a/webapp/packages/plugin-product/tsconfig.json +++ b/webapp/packages/plugin-product/tsconfig.json @@ -7,6 +7,9 @@ "composite": true }, "references": [ + { + "path": "../core-authentication" + }, { "path": "../core-blocks" }, diff --git a/webapp/yarn.lock b/webapp/yarn.lock index 2f1008c6af..1c1838cea5 100644 --- a/webapp/yarn.lock +++ b/webapp/yarn.lock @@ -3480,6 +3480,7 @@ __metadata: version: 0.0.0-use.local resolution: "@cloudbeaver/plugin-product@workspace:packages/plugin-product" dependencies: + "@cloudbeaver/core-authentication": "workspace:*" "@cloudbeaver/core-blocks": "workspace:*" "@cloudbeaver/core-cli": "workspace:*" "@cloudbeaver/core-di": "workspace:*"