Relax admin automated account registration
Some checks failed
Lint / pnpm_install (pull_request) Successful in 1m42s
Publish Docker image / Build (pull_request) Successful in 5m34s
Test (production install and build) / production (20.16.0) (pull_request) Successful in 1m18s
Test (backend) / unit (20.16.0) (pull_request) Successful in 8m41s
Lint / lint (backend) (pull_request) Successful in 2m22s
Lint / lint (frontend) (pull_request) Successful in 2m19s
Lint / lint (frontend-embed) (pull_request) Successful in 2m21s
Lint / lint (frontend-shared) (pull_request) Successful in 2m25s
Test (backend) / e2e (20.16.0) (pull_request) Failing after 12m43s
Lint / lint (misskey-bubble-game) (pull_request) Successful in 2m40s
Lint / lint (misskey-js) (pull_request) Successful in 2m29s
Lint / lint (misskey-reversi) (pull_request) Successful in 2m27s
Lint / lint (sw) (pull_request) Successful in 2m53s
Lint / typecheck (misskey-js) (pull_request) Successful in 1m33s
Lint / typecheck (backend) (pull_request) Successful in 2m43s
Lint / typecheck (sw) (pull_request) Successful in 1m47s

Signed-off-by: eternal-flame-AD <yume@yumechi.jp>
This commit is contained in:
ゆめ 2024-11-14 02:50:44 -06:00
parent 7748ab5dd0
commit da4bfb501f
No known key found for this signature in database
2 changed files with 83 additions and 2 deletions

View file

@ -15,18 +15,21 @@ import { DI } from '@/di-symbols.js';
import type { Config } from '@/config.js'; import type { Config } from '@/config.js';
import { ApiError } from '@/server/api/error.js'; import { ApiError } from '@/server/api/error.js';
import { Packed } from '@/misc/json-schema.js'; import { Packed } from '@/misc/json-schema.js';
import { RoleService } from '@/core/RoleService.js';
export const meta = { export const meta = {
tags: ['admin'], tags: ['admin'],
errors: { errors: {
accessDenied: { accessDenied: {
httpStatusCode: 403,
message: 'Access denied.', message: 'Access denied.',
code: 'ACCESS_DENIED', code: 'ACCESS_DENIED',
id: '1fb7cb09-d46a-4fff-b8df-057708cce513', id: '1fb7cb09-d46a-4fff-b8df-057708cce513',
}, },
wrongInitialPassword: { wrongInitialPassword: {
httpStatusCode: 401,
message: 'Initial password is incorrect.', message: 'Initial password is incorrect.',
code: 'INCORRECT_INITIAL_PASSWORD', code: 'INCORRECT_INITIAL_PASSWORD',
id: '97147c55-1ae1-4f6f-91d6-e1c3e0e76d62', id: '97147c55-1ae1-4f6f-91d6-e1c3e0e76d62',
@ -65,6 +68,7 @@ export default class extends Endpoint<typeof meta, typeof paramDef> { // eslint-
@Inject(DI.usersRepository) @Inject(DI.usersRepository)
private usersRepository: UsersRepository, private usersRepository: UsersRepository,
private roleService: RoleService,
private userEntityService: UserEntityService, private userEntityService: UserEntityService,
private signupService: SignupService, private signupService: SignupService,
private instanceActorService: InstanceActorService, private instanceActorService: InstanceActorService,
@ -85,8 +89,8 @@ export default class extends Endpoint<typeof meta, typeof paramDef> { // eslint-
// 初期パスワードが設定されていないのに初期パスワードが入力された場合 // 初期パスワードが設定されていないのに初期パスワードが入力された場合
throw new ApiError(meta.errors.wrongInitialPassword); throw new ApiError(meta.errors.wrongInitialPassword);
} }
} else if ((realUsers && !me?.isRoot) || token !== null) { } else if (!(me?.isRoot) && !await this.roleService.isAdministrator(me)) {
// 初回セットアップではなく、管理者でない場合 or 外部トークンを使用している場合 // 管理者でない場合
throw new ApiError(meta.errors.accessDenied); throw new ApiError(meta.errors.accessDenied);
} }

View file

@ -0,0 +1,77 @@
/*
* SPDX-FileCopyrightText: syuilo and misskey-project
* SPDX-License-Identifier: AGPL-3.0-only
*/
process.env.NODE_ENV = 'test';
import * as assert from 'assert';
import type * as misskey from 'misskey-js';
import { api, role, signup } from '../utils.js';
describe('Admin Create User', () => {
let admin: misskey.entities.SignupResponse;
let user: misskey.entities.SignupResponse;
let formerAdmin: misskey.entities.SignupResponse;
let adminRole : misskey.entities.Role;
let formerAdminRole : misskey.entities.Role;
beforeAll(async () => {
admin = await signup({ username: 'admin' });
formerAdmin = await signup({ username: 'former-admin' });
user = await signup({ username: 'user' });
adminRole = await role(admin, {
name: 'admin',
isAdministrator: true
});
formerAdminRole = await role(formerAdmin, {
name: 'former_admin',
isAdministrator: true
});
}, 1000 * 60 * 2);
test('Create User', async () => {
const newUser1 = await api('admin/accounts/create', {
username: 'new_user1',
password: 'password',
}, admin);
assert.strictEqual(newUser1.status, 200);
const newUser2 = await api('admin/accounts/create', {
username: 'new_user2',
password: 'password',
}, formerAdmin);
assert.strictEqual(newUser2.status, 200);
const newUser3 = await api('admin/accounts/create', {
username: 'new_user3',
password: 'password',
}, user);
assert.strictEqual(newUser3.status, 403);
});
test('Revoking Admin Role', async () => {
const res = await api('admin/roles/delete', {roleId: formerAdminRole.id}, admin);
assert.strictEqual(res.status, 200);
const res2 = await api('admin/roles/delete', {roleId: adminRole.id}, formerAdmin);
assert.strictEqual(res2.status, 403);
});
test('Revoked User Should Not Create User', async () => {
const newUser4 = await api('admin/accounts/create', {
username: 'new_user4',
password: 'password',
}, formerAdmin);
assert.strictEqual(newUser4.status, 403);
const newUser5 = await api('admin/accounts/create', {
username: 'new_user5',
password: 'password',
}, admin);
assert.strictEqual(newUser5.status, 200);
});
})