-
Notifications
You must be signed in to change notification settings - Fork 174
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
kie-issues#2466: Serverless Logic Web Tools: Runtime Tools settings doesn't validate the data index url. #2608
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change | ||||
---|---|---|---|---|---|---|
|
@@ -17,10 +17,10 @@ | |||||
* under the License. | ||||||
*/ | ||||||
|
||||||
import React from "react"; | ||||||
import React, { useEffect } from "react"; | ||||||
import { Button, ButtonVariant } from "@patternfly/react-core/dist/js/components/Button"; | ||||||
import { EmptyState, EmptyStateBody, EmptyStateIcon } from "@patternfly/react-core/dist/js/components/EmptyState"; | ||||||
import { ActionGroup, Form, FormGroup } from "@patternfly/react-core/dist/js/components/Form"; | ||||||
import { ActionGroup, Form, FormAlert, FormGroup } from "@patternfly/react-core/dist/js/components/Form"; | ||||||
import { InputGroup, InputGroupText } from "@patternfly/react-core/dist/js/components/InputGroup"; | ||||||
import { Modal, ModalVariant } from "@patternfly/react-core/dist/js/components/Modal"; | ||||||
import { PageSection } from "@patternfly/react-core/dist/js/components/Page"; | ||||||
|
@@ -43,14 +43,28 @@ import { | |||||
saveConfigCookie, | ||||||
} from "./RuntimeToolsConfig"; | ||||||
import { removeTrailingSlashFromUrl } from "../../url"; | ||||||
import { validDataIndexUrl } from "../../url"; | ||||||
import { Alert } from "@patternfly/react-core/dist/js"; | ||||||
import { useAppI18n } from "../../i18n"; | ||||||
|
||||||
const PAGE_TITLE = "Runtime Tools"; | ||||||
|
||||||
enum DataIndexValidation { | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. XXS suggestion. On some pages we call this
Suggested change
|
||||||
INITIAL = "INITIAL", | ||||||
INVALID = "INVALID", | ||||||
} | ||||||
|
||||||
export function RuntimeToolsSettings(props: SettingsPageProps) { | ||||||
const { i18n } = useAppI18n(); | ||||||
const settings = useSettings(); | ||||||
const settingsDispatch = useSettingsDispatch(); | ||||||
const [config, setConfig] = useState(settings.runtimeTools.config); | ||||||
const [isModalOpen, setIsModalOpen] = useState(false); | ||||||
const [isDataIndexUrlValidated, setDataIndexUrlValidated] = useState(DataIndexValidation.INVALID); | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
|
||||||
useEffect(() => { | ||||||
setDataIndexUrlValidated(DataIndexValidation.INITIAL); | ||||||
}, [config]); | ||||||
|
||||||
const handleModalToggle = useCallback(() => { | ||||||
setIsModalOpen((prevIsModalOpen) => !prevIsModalOpen); | ||||||
|
@@ -80,6 +94,11 @@ export function RuntimeToolsSettings(props: SettingsPageProps) { | |||||
const newConfig: RuntimeToolsSettingsConfig = { | ||||||
dataIndexUrl: removeTrailingSlashFromUrl(config.dataIndexUrl), | ||||||
}; | ||||||
if (!validDataIndexUrl(config.dataIndexUrl)) { | ||||||
setDataIndexUrlValidated(DataIndexValidation.INVALID); | ||||||
return; | ||||||
} | ||||||
|
||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. After checking if it's valid it would be great to really test the url answers to a simple query.
Maybe we can move verifyDataIndex() inside the package runtime-tools-swf-gateway-api to avoid code duplication.
|
||||||
setConfig(newConfig); | ||||||
settingsDispatch.runtimeTools.setConfig(newConfig); | ||||||
saveConfigCookie(newConfig); | ||||||
|
@@ -144,6 +163,17 @@ export function RuntimeToolsSettings(props: SettingsPageProps) { | |||||
appendTo={props.pageContainerRef.current || document.body} | ||||||
> | ||||||
<Form> | ||||||
{isDataIndexUrlValidated === DataIndexValidation.INVALID && ( | ||||||
<FormAlert> | ||||||
<Alert | ||||||
variant="danger" | ||||||
title={i18n.openshift.configModal.validDataIndexURLError} | ||||||
aria-live="polite" | ||||||
isInline | ||||||
data-testid="alert-data-index-url-invalid" | ||||||
/> | ||||||
</FormAlert> | ||||||
)} | ||||||
<FormGroup | ||||||
label={"Data Index URL"} | ||||||
labelIcon={ | ||||||
|
Original file line number | Diff line number | Diff line change | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
|
@@ -26,3 +26,12 @@ | |||||||||
export function removeTrailingSlashFromUrl(url: string): string { | ||||||||||
return url.replace(/\/$/, ""); | ||||||||||
} | ||||||||||
|
||||||||||
export function validDataIndexUrl(url: string): boolean { | ||||||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We can make this name consistent with the other kie-tools validation functions.
Suggested change
|
||||||||||
try { | ||||||||||
new URL(url); | ||||||||||
return true; | ||||||||||
Comment on lines
+32
to
+33
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I found a bug here, we are accepting every protocol in this function. @tiagobento it's out of scope, but do you think we should also reproduce this suggestion here?
Suggested change
|
||||||||||
} catch (_) { | ||||||||||
return false; | ||||||||||
} | ||||||||||
} |
Original file line number | Diff line number | Diff line change | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
@@ -0,0 +1,31 @@ | ||||||||||||||
/* | ||||||||||||||
* Licensed to the Apache Software Foundation (ASF) under one | ||||||||||||||
* or more contributor license agreements. See the NOTICE file | ||||||||||||||
* distributed with this work for additional information | ||||||||||||||
* regarding copyright ownership. The ASF licenses this file | ||||||||||||||
* to you under the Apache License, Version 2.0 (the | ||||||||||||||
* "License"); you may not use this file except in compliance | ||||||||||||||
* with the License. You may obtain a copy of the License at | ||||||||||||||
* | ||||||||||||||
* http://www.apache.org/licenses/LICENSE-2.0 | ||||||||||||||
* | ||||||||||||||
* Unless required by applicable law or agreed to in writing, | ||||||||||||||
* software distributed under the License is distributed on an | ||||||||||||||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||||||||||||||
* KIND, either express or implied. See the License for the | ||||||||||||||
* specific language governing permissions and limitations | ||||||||||||||
* under the License. | ||||||||||||||
*/ | ||||||||||||||
|
||||||||||||||
import { validDataIndexUrl } from "../../src/url"; | ||||||||||||||
|
||||||||||||||
describe("removeTrailingSlash", () => { | ||||||||||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Leftover? |
||||||||||||||
it.each([ | ||||||||||||||
["http://example.com/", true], | ||||||||||||||
["https://example.com/", true], | ||||||||||||||
Comment on lines
+24
to
+25
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's ensure we accept only http/https protocol.
Suggested change
|
||||||||||||||
["loremIpsum", false], | ||||||||||||||
["google.com", false], | ||||||||||||||
])("should validate the data index URL", (inputUrl, isValidUrl) => { | ||||||||||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's improve the log messages.
Suggested change
|
||||||||||||||
expect(validDataIndexUrl(inputUrl)).toBe(isValidUrl); | ||||||||||||||
}); | ||||||||||||||
}); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for taking care of the translations.
This section is related to the OpenShift settings page.
I suggest creating a section for RuntimeToolsSettings page to store this property.
ie:
RuntimeToolsSettings.configModal.validDataIndexURLError