-
Notifications
You must be signed in to change notification settings - Fork 275
feat: [OCISDEV-1437] show suggested expiry date of 30 days, tests #12988
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,10 @@ | ||
| Change: Default 30-day expiration for personalized shares | ||
|
|
||
| When a user or group share of a file or folder is created without an | ||
| expiration date, the server now preconfigures a default expiration of 30 days | ||
| to encourage data minimization. The sharer can override or shorten this value. | ||
|
|
||
| Space memberships are exempt and stay unbounded, as they represent a permanent | ||
| organizational role. | ||
|
|
||
| https://github.com/owncloud/ocis/pull/12988 |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ import ( | |
| "net/url" | ||
| "slices" | ||
| "strings" | ||
| "time" | ||
|
|
||
| gateway "github.com/cs3org/go-cs3apis/cs3/gateway/v1beta1" | ||
| grouppb "github.com/cs3org/go-cs3apis/cs3/identity/group/v1beta1" | ||
|
|
@@ -46,6 +47,9 @@ import ( | |
| const ( | ||
| invalidIdMsg = "invalid driveID or itemID" | ||
| parseDriveIDErrMsg = "could not parse driveID" | ||
|
|
||
| // default expiration for user/group shares created without one; space memberships are exempt | ||
| defaultShareExpirationDays = 30 | ||
| ) | ||
|
|
||
| // DriveItemPermissionsProvider contains the methods related to handling permissions on drive items | ||
|
|
@@ -177,6 +181,16 @@ func (s DriveItemPermissionsService) Invite(ctx context.Context, resourceId *sto | |
| var shareid string | ||
| var expiration *types.Timestamp | ||
| var cTime *types.Timestamp | ||
|
|
||
| // use the client-supplied expiration, else default non-space shares to defaultShareExpirationDays | ||
| var shareExpiration *types.Timestamp | ||
| switch { | ||
| case invite.ExpirationDateTime != nil: | ||
| shareExpiration = utils.TimeToTS(*invite.ExpirationDateTime) | ||
| case !IsSpaceRoot(statResponse.GetInfo().GetId()): | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I don't quite understand why you force every invite to have an expiration date. It's not correct. The task description sounds "When sharing files from the SAFE, all shares that are being created should have a suggested expiration date of 30 days. This value can be overridden by the creator, but the suggestion should be there all the same. " |
||
| shareExpiration = utils.TimeToTS(time.Now().UTC().AddDate(0, 0, defaultShareExpirationDays)) | ||
| } | ||
|
|
||
| switch driveRecipient.GetLibreGraphRecipientType() { | ||
| case "group": | ||
| group, err := s.identityCache.GetGroup(ctx, objectID) | ||
|
|
@@ -192,8 +206,8 @@ func (s DriveItemPermissionsService) Invite(ctx context.Context, resourceId *sto | |
| }, | ||
| } | ||
| createShareRequest := createShareRequestToGroup(group, statResponse.GetInfo(), cs3ResourcePermissions) | ||
| if invite.ExpirationDateTime != nil { | ||
| createShareRequest.GetGrant().Expiration = utils.TimeToTS(*invite.ExpirationDateTime) | ||
| if shareExpiration != nil { | ||
| createShareRequest.GetGrant().Expiration = shareExpiration | ||
| } | ||
| createShareResponse, err := gatewayClient.CreateShare(ctx, createShareRequest) | ||
| if err := errorcode.FromCS3Status(createShareResponse.GetStatus(), err); err != nil { | ||
|
|
@@ -259,8 +273,8 @@ func (s DriveItemPermissionsService) Invite(ctx context.Context, resourceId *sto | |
| expiration = createShareResponse.GetShare().GetExpiration() | ||
| } else { | ||
| createShareRequest := createShareRequestToUser(user, statResponse.GetInfo(), cs3ResourcePermissions) | ||
| if invite.ExpirationDateTime != nil { | ||
| createShareRequest.GetGrant().Expiration = utils.TimeToTS(*invite.ExpirationDateTime) | ||
| if shareExpiration != nil { | ||
| createShareRequest.GetGrant().Expiration = shareExpiration | ||
| } | ||
| createShareResponse, err := gatewayClient.CreateShare(ctx, createShareRequest) | ||
| if err := errorcode.FromCS3Status(createShareResponse.GetStatus(), err); err != nil { | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,49 @@ | ||
| package middleware | ||
|
|
||
| import ( | ||
| "net/http" | ||
| "net/http/httptest" | ||
| "testing" | ||
|
|
||
| "github.com/owncloud/ocis/v2/ocis-pkg/oidc" | ||
| "github.com/owncloud/ocis/v2/services/proxy/pkg/router" | ||
| ) | ||
|
|
||
| type stubAuth struct { | ||
| name string | ||
| err error // non-nil => this authenticator fails with this error | ||
| calls *[]string | ||
| } | ||
|
|
||
| func (s stubAuth) Authenticate(r *http.Request) (*http.Request, error) { | ||
| *s.calls = append(*s.calls, s.name) | ||
| if s.err != nil { | ||
| return nil, s.err | ||
| } | ||
| return r, nil | ||
| } | ||
|
|
||
| // A transient OIDC failure followed by a succeeding authenticator must serve 200, | ||
| // not 503 — the deferral flag exists so authenticator order does not matter. | ||
| func TestTransientThenSuccessServes200(t *testing.T) { | ||
| var calls []string | ||
| auths := []Authenticator{ | ||
| stubAuth{name: "oidc-transient", err: oidc.ErrTemporarilyUnavailable, calls: &calls}, | ||
| stubAuth{name: "public-share-ok", err: nil, calls: &calls}, | ||
| } | ||
|
|
||
| served := false | ||
| handler := Authentication(auths, EnableBasicAuth(false))( | ||
| http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { served = true }), | ||
| ) | ||
|
|
||
| req := httptest.NewRequest(http.MethodGet, "http://example.com/dav/public-files/x", http.NoBody) | ||
| req = req.WithContext(router.SetRoutingInfo(req.Context(), router.RoutingInfo{})) | ||
| rr := httptest.NewRecorder() | ||
| handler.ServeHTTP(rr, req) | ||
|
|
||
| t.Logf("authenticators called: %v, status: %d", calls, rr.Code) | ||
| if !served || rr.Code != http.StatusOK { | ||
| t.Fatalf("want 200 served by later authenticator, got status=%d served=%v (calls=%v)", rr.Code, served, calls) | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -184,7 +184,6 @@ Feature: sharing | |
| | permissions | all | | ||
| | stime | A_NUMBER | | ||
| | parent | | | ||
| | expiration | | | ||
|
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Now expiration date will be non-empty and relative so removed from assert since test subject is different than expiration date. |
||
| | token | | | ||
| | uid_file_owner | %username% | | ||
| | displayname_file_owner | %displayname% | | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should it be configurable?