diff options
author | Joram Wilander <jwawilander@gmail.com> | 2016-05-16 12:55:22 -0400 |
---|---|---|
committer | Christopher Speller <crspeller@gmail.com> | 2016-05-16 12:55:22 -0400 |
commit | 1f609e9cf799ddb6bedd5fe3c0eeb36b92ed243d (patch) | |
tree | f30ee0f416a9a7b5d76070e6a0ff999c08f44f47 /store | |
parent | c5f105787c7d740eaa9fb01891711a6fb72f7480 (diff) | |
download | chat-1f609e9cf799ddb6bedd5fe3c0eeb36b92ed243d.tar.gz chat-1f609e9cf799ddb6bedd5fe3c0eeb36b92ed243d.tar.bz2 chat-1f609e9cf799ddb6bedd5fe3c0eeb36b92ed243d.zip |
Check team member instead of session for team admin role when updating/deleting channels (#3007)
Diffstat (limited to 'store')
-rw-r--r-- | store/sql_team_store.go | 21 | ||||
-rw-r--r-- | store/sql_team_store_test.go | 31 | ||||
-rw-r--r-- | store/store.go | 1 |
3 files changed, 53 insertions, 0 deletions
diff --git a/store/sql_team_store.go b/store/sql_team_store.go index c17a45d97..daaa1bac1 100644 --- a/store/sql_team_store.go +++ b/store/sql_team_store.go @@ -411,6 +411,27 @@ func (s SqlTeamStore) UpdateMember(member *model.TeamMember) StoreChannel { return storeChannel } +func (s SqlTeamStore) GetMember(teamId string, userId string) StoreChannel { + storeChannel := make(StoreChannel) + + go func() { + result := StoreResult{} + + var member model.TeamMember + err := s.GetReplica().SelectOne(&member, "SELECT * FROM TeamMembers WHERE TeamId = :TeamId AND UserId = :UserId", map[string]interface{}{"TeamId": teamId, "UserId": userId}) + if err != nil { + result.Err = model.NewLocAppError("SqlTeamStore.GetMember", "store.sql_team.get_member.app_error", nil, "teamId="+teamId+" userId="+userId+" "+err.Error()) + } else { + result.Data = member + } + + storeChannel <- result + close(storeChannel) + }() + + return storeChannel +} + func (s SqlTeamStore) GetMembers(teamId string) StoreChannel { storeChannel := make(StoreChannel) diff --git a/store/sql_team_store_test.go b/store/sql_team_store_test.go index d5ee15bc6..be72786d3 100644 --- a/store/sql_team_store_test.go +++ b/store/sql_team_store_test.go @@ -403,3 +403,34 @@ func TestTeamMembers(t *testing.T) { } } } + +func TestGetTeamMember(t *testing.T) { + Setup() + + teamId1 := model.NewId() + + m1 := &model.TeamMember{TeamId: teamId1, UserId: model.NewId()} + Must(store.Team().SaveMember(m1)) + + if r := <-store.Team().GetMember(m1.TeamId, m1.UserId); r.Err != nil { + t.Fatal(r.Err) + } else { + rm1 := r.Data.(model.TeamMember) + + if rm1.TeamId != m1.TeamId { + t.Fatal("bad team id") + } + + if rm1.UserId != m1.UserId { + t.Fatal("bad user id") + } + } + + if r := <-store.Team().GetMember(m1.TeamId, ""); r.Err == nil { + t.Fatal("empty user id - should have failed") + } + + if r := <-store.Team().GetMember("", m1.UserId); r.Err == nil { + t.Fatal("empty team id - should have failed") + } +} diff --git a/store/store.go b/store/store.go index 7f62fcd97..ebbd2e454 100644 --- a/store/store.go +++ b/store/store.go @@ -61,6 +61,7 @@ type TeamStore interface { AnalyticsTeamCount() StoreChannel SaveMember(member *model.TeamMember) StoreChannel UpdateMember(member *model.TeamMember) StoreChannel + GetMember(teamId string, userId string) StoreChannel GetMembers(teamId string) StoreChannel GetTeamsForUser(userId string) StoreChannel RemoveMember(teamId string, userId string) StoreChannel |