Merge pull request #23308 from Roshick/patch-2

fix(auth): filter only for users in emailMatchingUserEntityProfileEmail resolver
This commit is contained in:
Patrik Oldsberg
2024-03-25 16:02:01 +01:00
committed by GitHub
4 changed files with 75 additions and 2 deletions
@@ -0,0 +1,54 @@
/*
* Copyright 2024 The Backstage Authors
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
import { CatalogAuthResolverContext } from './CatalogAuthResolverContext';
import { getVoidLogger } from '@backstage/backend-common';
import { CatalogApi } from '@backstage/catalog-client';
import { mockServices } from '@backstage/backend-test-utils';
import { TokenIssuer } from '../../identity/types';
import { DiscoveryService } from '@backstage/backend-plugin-api';
describe('CatalogAuthResolverContext', () => {
beforeEach(() => {
jest.clearAllMocks();
});
const mockCatalogApi = {
getEntities: jest.fn().mockResolvedValue({ items: [{}] }),
} as Partial<jest.Mocked<CatalogApi>>;
it('adds kind to filter when missing', async () => {
const context = CatalogAuthResolverContext.create({
logger: getVoidLogger(),
catalogApi: mockCatalogApi as CatalogApi,
tokenIssuer: {} as TokenIssuer,
tokenManager: mockServices.tokenManager(),
discovery: {} as DiscoveryService,
auth: mockServices.auth(),
httpAuth: mockServices.httpAuth(),
});
await context.findCatalogUser({
filter: [{}, { kind: 'group' }, { KIND: 'USER' }],
});
expect(mockCatalogApi.getEntities).toHaveBeenCalledWith(
{
filter: [{ kind: 'user' }, { kind: 'group' }, { KIND: 'USER' }],
},
{ token: 'mock-service-token:{"sub":"plugin:test","target":"catalog"}' },
);
});
});
@@ -123,8 +123,21 @@ export class CatalogAuthResolverContext implements AuthResolverContext {
const res = await this.catalogApi.getEntities({ filter }, { token });
result = res.items;
} else if ('filter' in query) {
const filter = [query.filter].flat().map(value => {
if (
!Object.keys(value).some(
key => key.toLocaleLowerCase('en-US') === 'kind',
)
) {
return {
...value,
kind: 'user',
};
}
return value;
});
const res = await this.catalogApi.getEntities(
{ filter: query.filter },
{ filter: filter },
{ token },
);
result = res.items;