mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(coderd): ensure correct RBAC when enqueueing notifications (#15478)
- Assert rbac in fake notifications enqueuer - Move fake notifications enqueuer to separate notificationstest package - Update dbauthz rbac policy to allow provisionerd and autostart to create and read notification messages - Update tests as required
This commit is contained in:
@@ -36,6 +36,7 @@ import (
|
||||
"github.com/coder/coder/v2/coderd/database/pubsub"
|
||||
"github.com/coder/coder/v2/coderd/externalauth"
|
||||
"github.com/coder/coder/v2/coderd/notifications"
|
||||
"github.com/coder/coder/v2/coderd/notifications/notificationstest"
|
||||
"github.com/coder/coder/v2/coderd/provisionerdserver"
|
||||
"github.com/coder/coder/v2/coderd/schedule"
|
||||
"github.com/coder/coder/v2/coderd/schedule/cron"
|
||||
@@ -1634,7 +1635,7 @@ func TestNotifications(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
ctx := context.Background()
|
||||
notifEnq := &testutil.FakeNotificationsEnqueuer{}
|
||||
notifEnq := ¬ificationstest.FakeEnqueuer{}
|
||||
|
||||
srv, db, ps, pd := setup(t, false, &overrides{
|
||||
notificationEnqueuer: notifEnq,
|
||||
@@ -1713,17 +1714,18 @@ func TestNotifications(t *testing.T) {
|
||||
|
||||
if tc.shouldNotify {
|
||||
// Validate that the notification was sent and contained the expected values.
|
||||
require.Len(t, notifEnq.Sent, 1)
|
||||
require.Equal(t, notifEnq.Sent[0].UserID, user.ID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, template.ID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, workspace.ID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, workspace.OrganizationID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, user.ID)
|
||||
sent := notifEnq.Sent()
|
||||
require.Len(t, sent, 1)
|
||||
require.Equal(t, sent[0].UserID, user.ID)
|
||||
require.Contains(t, sent[0].Targets, template.ID)
|
||||
require.Contains(t, sent[0].Targets, workspace.ID)
|
||||
require.Contains(t, sent[0].Targets, workspace.OrganizationID)
|
||||
require.Contains(t, sent[0].Targets, user.ID)
|
||||
if tc.deletionReason == database.BuildReasonInitiator {
|
||||
require.Equal(t, initiator.Username, notifEnq.Sent[0].Labels["initiator"])
|
||||
require.Equal(t, initiator.Username, sent[0].Labels["initiator"])
|
||||
}
|
||||
} else {
|
||||
require.Len(t, notifEnq.Sent, 0)
|
||||
require.Len(t, notifEnq.Sent(), 0)
|
||||
}
|
||||
})
|
||||
}
|
||||
@@ -1755,7 +1757,7 @@ func TestNotifications(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
ctx := context.Background()
|
||||
notifEnq := &testutil.FakeNotificationsEnqueuer{}
|
||||
notifEnq := ¬ificationstest.FakeEnqueuer{}
|
||||
|
||||
// Otherwise `(*Server).FailJob` fails with:
|
||||
// audit log - get build {"error": "sql: no rows in result set"}
|
||||
@@ -1824,15 +1826,16 @@ func TestNotifications(t *testing.T) {
|
||||
|
||||
if tc.shouldNotify {
|
||||
// Validate that the notification was sent and contained the expected values.
|
||||
require.Len(t, notifEnq.Sent, 1)
|
||||
require.Equal(t, notifEnq.Sent[0].UserID, user.ID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, template.ID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, workspace.ID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, workspace.OrganizationID)
|
||||
require.Contains(t, notifEnq.Sent[0].Targets, user.ID)
|
||||
require.Equal(t, string(tc.buildReason), notifEnq.Sent[0].Labels["reason"])
|
||||
sent := notifEnq.Sent()
|
||||
require.Len(t, sent, 1)
|
||||
require.Equal(t, sent[0].UserID, user.ID)
|
||||
require.Contains(t, sent[0].Targets, template.ID)
|
||||
require.Contains(t, sent[0].Targets, workspace.ID)
|
||||
require.Contains(t, sent[0].Targets, workspace.OrganizationID)
|
||||
require.Contains(t, sent[0].Targets, user.ID)
|
||||
require.Equal(t, string(tc.buildReason), sent[0].Labels["reason"])
|
||||
} else {
|
||||
require.Len(t, notifEnq.Sent, 0)
|
||||
require.Len(t, notifEnq.Sent(), 0)
|
||||
}
|
||||
})
|
||||
}
|
||||
@@ -1844,7 +1847,7 @@ func TestNotifications(t *testing.T) {
|
||||
ctx := context.Background()
|
||||
|
||||
// given
|
||||
notifEnq := &testutil.FakeNotificationsEnqueuer{}
|
||||
notifEnq := ¬ificationstest.FakeEnqueuer{}
|
||||
srv, db, ps, pd := setup(t, true /* ignoreLogErrors */, &overrides{notificationEnqueuer: notifEnq})
|
||||
|
||||
templateAdmin := dbgen.User(t, db, database.User{RBACRoles: []string{codersdk.RoleTemplateAdmin}})
|
||||
@@ -1886,19 +1889,20 @@ func TestNotifications(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// then
|
||||
require.Len(t, notifEnq.Sent, 1)
|
||||
assert.Equal(t, notifEnq.Sent[0].UserID, templateAdmin.ID)
|
||||
assert.Equal(t, notifEnq.Sent[0].TemplateID, notifications.TemplateWorkspaceManualBuildFailed)
|
||||
assert.Contains(t, notifEnq.Sent[0].Targets, template.ID)
|
||||
assert.Contains(t, notifEnq.Sent[0].Targets, workspace.ID)
|
||||
assert.Contains(t, notifEnq.Sent[0].Targets, workspace.OrganizationID)
|
||||
assert.Contains(t, notifEnq.Sent[0].Targets, user.ID)
|
||||
assert.Equal(t, workspace.Name, notifEnq.Sent[0].Labels["name"])
|
||||
assert.Equal(t, template.DisplayName, notifEnq.Sent[0].Labels["template_name"])
|
||||
assert.Equal(t, version.Name, notifEnq.Sent[0].Labels["template_version_name"])
|
||||
assert.Equal(t, user.Username, notifEnq.Sent[0].Labels["initiator"])
|
||||
assert.Equal(t, user.Username, notifEnq.Sent[0].Labels["workspace_owner_username"])
|
||||
assert.Equal(t, strconv.Itoa(int(build.BuildNumber)), notifEnq.Sent[0].Labels["workspace_build_number"])
|
||||
sent := notifEnq.Sent()
|
||||
require.Len(t, sent, 1)
|
||||
assert.Equal(t, sent[0].UserID, templateAdmin.ID)
|
||||
assert.Equal(t, sent[0].TemplateID, notifications.TemplateWorkspaceManualBuildFailed)
|
||||
assert.Contains(t, sent[0].Targets, template.ID)
|
||||
assert.Contains(t, sent[0].Targets, workspace.ID)
|
||||
assert.Contains(t, sent[0].Targets, workspace.OrganizationID)
|
||||
assert.Contains(t, sent[0].Targets, user.ID)
|
||||
assert.Equal(t, workspace.Name, sent[0].Labels["name"])
|
||||
assert.Equal(t, template.DisplayName, sent[0].Labels["template_name"])
|
||||
assert.Equal(t, version.Name, sent[0].Labels["template_version_name"])
|
||||
assert.Equal(t, user.Username, sent[0].Labels["initiator"])
|
||||
assert.Equal(t, user.Username, sent[0].Labels["workspace_owner_username"])
|
||||
assert.Equal(t, strconv.Itoa(int(build.BuildNumber)), sent[0].Labels["workspace_build_number"])
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user