add default_persistence_allowed

In addition set all config options in every test, as catch2 can run
tests out of order and as demonstrated in
e1ad60af4f this can be an issue
This commit is contained in:
Luca Matei Pintilie
2025-11-28 21:54:38 +01:00
committed by mathieui
parent fbb93dbd08
commit 51930c1e78
4 changed files with 47 additions and 4 deletions
+3 -2
View File
@@ -19,8 +19,9 @@ For admins
---------- ----------
- Command line option --test-config (or -t) has been added. When used, - Command line option --test-config (or -t) has been added. When used,
biboumi will just exit without any error if the configuration is correct biboumi will just exit without any error if the configuration is correct
- Options persist_user_denylist and persist_user_allowlist have been added to - Options default_persistence_allowed, persist_user_denylist, and
granualy control who can set the persist option persist_user_allowlist have been added to granualy control who can set the
persist option
For packagers For packagers
------------- -------------
+6
View File
@@ -260,6 +260,12 @@ persist_user_allowlist
A list of XMPP XMPP users or domains who are allowed to change the `persist` A list of XMPP XMPP users or domains who are allowed to change the `persist`
ad-hoc option. ad-hoc option.
default_persistence_allowed
~~~~~~~~~~~~~~~~~~~~~~~~~~~
If a given XMPP user or domain is not in either denylist or allowlist this
option decides if the user is allowed to persist or not.
TLS configuration TLS configuration
----------------- -----------------
@@ -19,7 +19,7 @@ namespace utils
* 2. `persist_user_allowlist` contains the requester's jid * 2. `persist_user_allowlist` contains the requester's jid
* 3. `persist_user_denylist` contains the requester's domain * 3. `persist_user_denylist` contains the requester's domain
* 4. `persist_user_allowlist` contains the contains the requester's domain * 4. `persist_user_allowlist` contains the contains the requester's domain
* 5. allow * 5. `default_persistence_allowed` is true (default true)
*/ */
inline bool is_requester_allowed_to_persist(const Jid &requester) { inline bool is_requester_allowed_to_persist(const Jid &requester) {
// requester.bare checks // requester.bare checks
@@ -50,6 +50,6 @@ inline bool is_requester_allowed_to_persist(const Jid &requester) {
// default allow // default allow
// 5. // 5.
return true; return Config::get_bool("default_persistence_allowed", true);
} }
} }
+36
View File
@@ -9,6 +9,31 @@ TEST_CASE("default")
Config::clear(); Config::clear();
Config::set("persist_user_denylist", ""); Config::set("persist_user_denylist", "");
Config::set("persist_user_allowlist", ""); Config::set("persist_user_allowlist", "");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == true);
Config::clear();
}
TEST_CASE("default - default_persistence_allowed - false")
{
Jid jid("foo@example.com");
Config::clear();
Config::set("persist_user_denylist", "");
Config::set("persist_user_allowlist", "");
Config::set("default_persistence_allowed", "false");
bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == false);
Config::clear();
}
TEST_CASE("default - default_persistence_allowed - true")
{
Jid jid("foo@example.com");
Config::clear();
Config::set("persist_user_denylist", "");
Config::set("persist_user_allowlist", "");
Config::set("default_persistence_allowed", "true");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == true); CHECK(result == true);
Config::clear(); Config::clear();
@@ -19,6 +44,8 @@ TEST_CASE("denylist - jid")
Jid jid("foo@example.com"); Jid jid("foo@example.com");
Config::clear(); Config::clear();
Config::set("persist_user_denylist", "foo@example.com"); Config::set("persist_user_denylist", "foo@example.com");
Config::set("persist_user_allowlist", "");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == false); CHECK(result == false);
Config::clear(); Config::clear();
@@ -29,6 +56,8 @@ TEST_CASE("denylist - domain")
Jid jid("foo@example.com"); Jid jid("foo@example.com");
Config::clear(); Config::clear();
Config::set("persist_user_denylist", "example.com"); Config::set("persist_user_denylist", "example.com");
Config::set("persist_user_allowlist", "");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == false); CHECK(result == false);
Config::clear(); Config::clear();
@@ -39,6 +68,8 @@ TEST_CASE("allowlist - jid")
Jid jid("foo@example.com"); Jid jid("foo@example.com");
Config::clear(); Config::clear();
Config::set("persist_user_allowlist", "foo@example.com"); Config::set("persist_user_allowlist", "foo@example.com");
Config::set("persist_user_denylist", "");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == true); CHECK(result == true);
Config::clear(); Config::clear();
@@ -49,6 +80,8 @@ TEST_CASE("allowlist - domain")
Jid jid("foo@example.com"); Jid jid("foo@example.com");
Config::clear(); Config::clear();
Config::set("persist_user_allowlist", "example.com"); Config::set("persist_user_allowlist", "example.com");
Config::set("persist_user_denylist", "");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == true); CHECK(result == true);
Config::clear(); Config::clear();
@@ -60,6 +93,7 @@ TEST_CASE("denylist + allowlist - deny domain, allow jid")
Config::clear(); Config::clear();
Config::set("persist_user_denylist", "example.com"); Config::set("persist_user_denylist", "example.com");
Config::set("persist_user_allowlist", "foo@example.com"); Config::set("persist_user_allowlist", "foo@example.com");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == true); CHECK(result == true);
Config::clear(); Config::clear();
@@ -71,6 +105,7 @@ TEST_CASE("denylist + allowlist - deny jid, allow domain")
Config::clear(); Config::clear();
Config::set("persist_user_denylist", "foo@example.com"); Config::set("persist_user_denylist", "foo@example.com");
Config::set("persist_user_allowlist", "example.com"); Config::set("persist_user_allowlist", "example.com");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == false); CHECK(result == false);
Config::clear(); Config::clear();
@@ -82,6 +117,7 @@ TEST_CASE("denylist + allowlist - deny jid, allow jid")
Config::clear(); Config::clear();
Config::set("persist_user_denylist", "foo@example.com"); Config::set("persist_user_denylist", "foo@example.com");
Config::set("persist_user_allowlist", "foo@example.com"); Config::set("persist_user_allowlist", "foo@example.com");
Config::set("default_persistence_allowed", "");
bool result = utils::is_requester_allowed_to_persist(jid); bool result = utils::is_requester_allowed_to_persist(jid);
CHECK(result == false); CHECK(result == false);
Config::clear(); Config::clear();