fix: allow all users to read system notification templates (#14181)

This commit is contained in:
Danny Kopping
2024-08-06 15:37:49 +02:00
committed by GitHub
parent 70a694ed4c
commit 58428aafce
3 changed files with 48 additions and 7 deletions
+6 -6
View File
@@ -1489,13 +1489,13 @@ func (q *querier) GetNotificationTemplateByID(ctx context.Context, id uuid.UUID)
}
func (q *querier) GetNotificationTemplatesByKind(ctx context.Context, kind database.NotificationTemplateKind) ([]database.NotificationTemplate, error) {
// TODO: restrict 'system' kind to admins only?
// All notification templates share the same rbac.Object, so there is no need
// to authorize them individually. If this passes, all notification templates can be read.
if err := q.authorizeContext(ctx, policy.ActionRead, rbac.ResourceNotificationTemplate); err != nil {
return nil, err
// Anyone can read the system notification templates.
if kind == database.NotificationTemplateKindSystem {
return q.db.GetNotificationTemplatesByKind(ctx, kind)
}
return q.db.GetNotificationTemplatesByKind(ctx, kind)
// TODO(dannyk): handle template ownership when we support user-default notification templates.
return nil, sql.ErrNoRows
}
func (q *querier) GetNotificationsSettings(ctx context.Context) (string, error) {
+3 -1
View File
@@ -2610,8 +2610,10 @@ func (s *MethodTestSuite) TestNotifications() {
}))
s.Run("GetNotificationTemplatesByKind", s.Subtest(func(db database.Store, check *expects) {
check.Args(database.NotificationTemplateKindSystem).
Asserts(rbac.ResourceNotificationTemplate, policy.ActionRead).
Asserts().
Errors(dbmem.ErrUnimplemented)
// TODO(dannyk): add support for other database.NotificationTemplateKind types once implemented.
}))
s.Run("UpdateNotificationTemplateMethodByID", s.Subtest(func(db database.Store, check *expects) {
check.Args(database.UpdateNotificationTemplateMethodByIDParams{