mirror of
https://github.com/suitenumerique/meet.git
synced 2026-09-08 00:15:42 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a42b126357 |
@@ -24,6 +24,7 @@ and this project adheres to
|
|||||||
- 🐛(frontend) keep the sending resolution picked while the camera is off #1667
|
- 🐛(frontend) keep the sending resolution picked while the camera is off #1667
|
||||||
- 🐛(frontend) restore automatic lower-hand on speaking
|
- 🐛(frontend) restore automatic lower-hand on speaking
|
||||||
- 🐛(frontend) center Avatar initials with a font-aware cap-height ratio
|
- 🐛(frontend) center Avatar initials with a font-aware cap-height ratio
|
||||||
|
- 🔒️(backend) reject inactive users in resource server backend
|
||||||
|
|
||||||
## [1.30.0] - 2026-09-01
|
## [1.30.0] - 2026-09-01
|
||||||
|
|
||||||
|
|||||||
@@ -286,6 +286,10 @@ class ResourceServerBackend(LaSuiteBackend):
|
|||||||
if user is None and settings.OIDC_CREATE_USER:
|
if user is None and settings.OIDC_CREATE_USER:
|
||||||
user = self.create_user(sub)
|
user = self.create_user(sub)
|
||||||
|
|
||||||
|
if user is not None and not user.is_active:
|
||||||
|
logger.warning("Inactive user attempted authentication: %s", user.pk)
|
||||||
|
raise SuspiciousOperation("User account is disabled.")
|
||||||
|
|
||||||
return user
|
return user
|
||||||
|
|
||||||
def create_user(self, sub):
|
def create_user(self, sub):
|
||||||
|
|||||||
@@ -0,0 +1,96 @@
|
|||||||
|
"""Tests for the external API ResourceServerBackend."""
|
||||||
|
|
||||||
|
from django.core.exceptions import SuspiciousOperation
|
||||||
|
|
||||||
|
import pytest
|
||||||
|
import responses
|
||||||
|
from rest_framework.test import APIClient
|
||||||
|
|
||||||
|
from core.external_api.authentication import ResourceServerBackend
|
||||||
|
from core.factories import UserFactory
|
||||||
|
from core.models import User
|
||||||
|
|
||||||
|
pytestmark = pytest.mark.django_db
|
||||||
|
|
||||||
|
|
||||||
|
def _payload(sub):
|
||||||
|
return {"sub": sub, "active": True, "scope": "lasuite_meet", "client_id": "app"}
|
||||||
|
|
||||||
|
|
||||||
|
def test_resource_server_backend_get_or_create_user_active():
|
||||||
|
"""An existing active user matching the sub should be returned."""
|
||||||
|
|
||||||
|
user = UserFactory()
|
||||||
|
|
||||||
|
result = ResourceServerBackend().get_or_create_user(
|
||||||
|
access_token="token", id_token=None, payload=_payload(user.sub)
|
||||||
|
)
|
||||||
|
|
||||||
|
assert result == user
|
||||||
|
|
||||||
|
|
||||||
|
def test_resource_server_backend_get_or_create_user_inactive():
|
||||||
|
"""An inactive user should be rejected even with a valid token."""
|
||||||
|
|
||||||
|
user = UserFactory(is_active=False)
|
||||||
|
|
||||||
|
with pytest.raises(SuspiciousOperation, match="User account is disabled."):
|
||||||
|
ResourceServerBackend().get_or_create_user(
|
||||||
|
access_token="token", id_token=None, payload=_payload(user.sub)
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def test_resource_server_backend_get_or_create_user_creates(settings):
|
||||||
|
"""An unknown sub should create an active user when OIDC_CREATE_USER is set."""
|
||||||
|
|
||||||
|
settings.OIDC_CREATE_USER = True
|
||||||
|
|
||||||
|
result = ResourceServerBackend().get_or_create_user(
|
||||||
|
access_token="token", id_token=None, payload=_payload("new-sub")
|
||||||
|
)
|
||||||
|
|
||||||
|
assert result.sub == "new-sub"
|
||||||
|
assert result.is_active is True
|
||||||
|
assert User.objects.filter(sub="new-sub").exists()
|
||||||
|
|
||||||
|
|
||||||
|
def test_resource_server_backend_get_or_create_user_no_creation(settings):
|
||||||
|
"""An unknown sub should return None when OIDC_CREATE_USER is unset."""
|
||||||
|
|
||||||
|
settings.OIDC_CREATE_USER = False
|
||||||
|
|
||||||
|
result = ResourceServerBackend().get_or_create_user(
|
||||||
|
access_token="token", id_token=None, payload=_payload("new-sub")
|
||||||
|
)
|
||||||
|
|
||||||
|
assert result is None
|
||||||
|
assert not User.objects.filter(sub="new-sub").exists()
|
||||||
|
|
||||||
|
|
||||||
|
@responses.activate
|
||||||
|
def test_api_rooms_list_resource_server_inactive_user(settings):
|
||||||
|
"""End to end: a valid introspected token for an inactive user should get 401."""
|
||||||
|
|
||||||
|
settings.OIDC_OP_INTROSPECTION_ENDPOINT = "https://oidc.example.com/introspect"
|
||||||
|
settings.OIDC_OP_URL = "https://oidc.example.com"
|
||||||
|
|
||||||
|
user = UserFactory(is_active=False)
|
||||||
|
|
||||||
|
responses.add(
|
||||||
|
responses.POST,
|
||||||
|
"https://oidc.example.com/introspect",
|
||||||
|
json={
|
||||||
|
"iss": "https://oidc.example.com",
|
||||||
|
"active": True,
|
||||||
|
"sub": user.sub,
|
||||||
|
"scope": "lasuite_meet",
|
||||||
|
"client_id": "app",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
|
||||||
|
client = APIClient()
|
||||||
|
client.credentials(HTTP_AUTHORIZATION="Bearer rs-token")
|
||||||
|
response = client.get("/external-api/v1.0/rooms/")
|
||||||
|
|
||||||
|
assert response.status_code == 401
|
||||||
|
assert "login failed" in str(response.data).lower()
|
||||||
Reference in New Issue
Block a user