feat: ability to edit authorized integration in web UI (#12601)
Extends the UI introduced in #12558 to have edit capabilities. (not in scope: "Add" for a new Authorized Integration will be the next update to this UI; `create-authorized-integration` CLI is still the only way to create a new record) This PR includes a few refactoring steps. The goal of these steps is to have `services/auth` be a single entrypoint for validating, inserting, or updating an authorized integration. Some logic is moved out of `services/authz` because it is not authorization related, and some is moved out of `services/auth/method` to allow it to be reused during validation without creating a cyclical module dependency. This PR also adds comprehensive validation to the more complex fields in the authorized integration, such as the issuer and claim rules. This validation applies to the `forgejo admin user create-authorized-integration` CLI as well. The visible UI is the same as #12558, but with a "Save" button, and the ability to display errors:  ## Checklist The [contributor guide](https://forgejo.org/docs/next/contributor/) contains information that will be helpful to first time contributors. All work and communication must conform to Forgejo's [AI Agreement](https://codeberg.org/forgejo/governance/src/branch/main/AIAgreement.md). There also are a few [conditions for merging Pull Requests in Forgejo repositories](https://codeberg.org/forgejo/governance/src/branch/main/PullRequestsAgreement.md). You are also welcome to join the [Forgejo development chatroom](https://matrix.to/#/#forgejo-development:matrix.org). ### Tests for Go changes - I added test coverage for Go changes... - [x] in their respective `*_test.go` for unit tests. - [ ] in the `tests/integration` directory if it involves interactions with a live Forgejo server. - I ran... - [x] `make pr-go` before pushing ### Tests for JavaScript changes - I added test coverage for JavaScript changes... - [ ] in `web_src/js/*.test.js` if it can be unit tested. - [x] in `tests/e2e/*.test.e2e.js` if it requires interactions with a live Forgejo server (see also the [developer guide for JavaScript testing](https://codeberg.org/forgejo/forgejo/src/branch/forgejo/tests/e2e/README.md#end-to-end-tests)). ### Documentation - [ ] I created a pull request [to the documentation](https://codeberg.org/forgejo/docs) to explain to Forgejo users how to use this change. - [x] I did not document these changes and I do not expect someone else to do it. - Documentation is on my TODO list and will be completed before release. ### Release notes - [x] This change will be noticed by a Forgejo user or admin (feature, bug fix, performance, etc.). I suggest to include a release note for this change. - [ ] This change is not visible to a Forgejo user or admin (refactor, dependency upgrade, etc.). I think there is no need to add a release note for this change. Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12601 Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
This commit is contained in:
committed by
Mathieu Fenniak
parent
8a1021e2a0
commit
cf087a2f12
@@ -184,6 +184,18 @@ func InsertAuthorizedIntegration(ctx context.Context, ai *AuthorizedIntegration)
|
||||
return err
|
||||
}
|
||||
|
||||
func UpdateAuthorizedIntegration(ctx context.Context, ai *AuthorizedIntegration) error {
|
||||
// NoAutoTime -- UpdatedUnix is used to track the last used time, don't update it when editing
|
||||
// AllCols -- ensure ResourceAllRepo can be set to false
|
||||
rowsImpacted, err := db.GetEngine(ctx).ID(ai.ID).NoAutoTime().AllCols().Update(ai)
|
||||
if rowsImpacted == 0 {
|
||||
return fmt.Errorf("authorized integration update affected 0 records: %w", util.ErrNotExist)
|
||||
} else if rowsImpacted != 1 {
|
||||
return fmt.Errorf("authorized integration update affected %d records", rowsImpacted)
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
// Bump the UpdatedUnix field of this authorized integration to now, tracking when it was last used for authentication.
|
||||
// To reduce database write workload, this is only tracked by one-minute intervals -- the UPDATE statement conditionally
|
||||
// avoids writes.
|
||||
|
||||
@@ -54,3 +54,12 @@ func InsertAuthorizedIntegrationResourceRepos(ctx context.Context, aiID int64, r
|
||||
return nil
|
||||
})
|
||||
}
|
||||
|
||||
func UpdateAuthorizedIntegrationResourceRepos(ctx context.Context, aiID int64, resources []*AuthorizedIntegResourceRepo) error {
|
||||
return db.WithTx(ctx, func(ctx context.Context) error {
|
||||
if _, err := db.GetEngine(ctx).Delete(&AuthorizedIntegResourceRepo{IntegID: aiID}); err != nil {
|
||||
return err
|
||||
}
|
||||
return InsertAuthorizedIntegrationResourceRepos(ctx, aiID, resources)
|
||||
})
|
||||
}
|
||||
|
||||
@@ -175,3 +175,21 @@ func TestListAuthorizedIntegrationOptions(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, ais)
|
||||
}
|
||||
|
||||
func TestUpdateAuthorizedIntegration(t *testing.T) {
|
||||
require.NoError(t, unittest.PrepareTestDatabase())
|
||||
|
||||
ai := makeAuthorizedIntegration(t)
|
||||
ai.Name = "Hello, world!"
|
||||
ai.ResourceAllRepos = false
|
||||
createdUnix := ai.CreatedUnix
|
||||
updatedUnix := ai.UpdatedUnix
|
||||
|
||||
require.NoError(t, auth_model.UpdateAuthorizedIntegration(t.Context(), ai))
|
||||
|
||||
fromDB := unittest.AssertExistsAndLoadBean(t, &auth_model.AuthorizedIntegration{ID: ai.ID})
|
||||
assert.Equal(t, "Hello, world!", fromDB.Name)
|
||||
assert.False(t, fromDB.ResourceAllRepos)
|
||||
assert.Equal(t, createdUnix, fromDB.CreatedUnix)
|
||||
assert.Equal(t, updatedUnix, fromDB.UpdatedUnix) // not changed -- used to track usage for authentication
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user