Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/brave-fans-tie.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@rocket.chat/meteor": patch
"@rocket.chat/i18n": patch
---

Adds 4 new permissions (assigned to admins by default) to control the visibility of each tab inside the ABAC Administration panel
14 changes: 8 additions & 6 deletions apps/meteor/client/views/admin/ABAC/AdminABACPage.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ import RoomsContextualBarWithData from './ABACRoomsTab/RoomsContextualBarWithDat
import RoomsPage from './ABACRoomsTab/RoomsPage';
import SettingsPage from './ABACSettingTab/SettingsPage';
import AdminABACTabs from './AdminABACTabs';
import { useABACTabPermissions } from './hooks/useABACTabPermissions';
import { useIsABACAvailable } from './hooks/useIsABACAvailable';
import { useExternalLink } from '../../../hooks/useExternalLink';
import { useLdapSync } from '../../../hooks/useLdapSync';
Expand All @@ -34,6 +35,7 @@ const AdminABACPage = ({ shouldShowWarning }: AdminABACPageProps) => {
const abacEnabled = useSetting('ABAC_Enabled');
const handleSyncNow = useLdapSync();
const isSyncDisabled = !ldapEnabled || !abacEnabled;
const tabPermissions = useABACTabPermissions();
Comment thread
KevLehman marked this conversation as resolved.
Comment thread
KevLehman marked this conversation as resolved.

const handleCloseContextualbar = useEffectEvent((): void => {
if (!context) {
Expand Down Expand Up @@ -84,21 +86,21 @@ const AdminABACPage = ({ shouldShowWarning }: AdminABACPageProps) => {
)}
<AdminABACTabs />
<PageContent>
{tab === 'settings' && <SettingsPage />}
{tab === 'room-attributes' && <AttributesPage />}
{tab === 'rooms' && <RoomsPage />}
{tab === 'logs' && <LogsPage />}
{tab === 'settings' && tabPermissions.settings && <SettingsPage />}
{tab === 'room-attributes' && tabPermissions['room-attributes'] && <AttributesPage />}
{tab === 'rooms' && tabPermissions.rooms && <RoomsPage />}
{tab === 'logs' && tabPermissions.logs && <LogsPage />}
</PageContent>
</Page>
{isABACAvailable === true && tab !== undefined && context !== undefined && (
<ContextualbarDialog onClose={() => handleCloseContextualbar()}>
{tab === 'room-attributes' && (
{tab === 'room-attributes' && tabPermissions['room-attributes'] && (
<>
{context === 'new' && <AttributesContextualBar onClose={() => handleCloseContextualbar()} />}
{context === 'edit' && _id && <AttributesContextualBarWithData id={_id} onClose={() => handleCloseContextualbar()} />}
</>
)}
{tab === 'rooms' && (
{tab === 'rooms' && tabPermissions.rooms && (
<>
{context === 'new' && <RoomsContextualBar onClose={() => handleCloseContextualbar()} />}
{context === 'edit' && _id && <RoomsContextualBarWithData id={_id} onClose={() => handleCloseContextualbar()} />}
Expand Down
24 changes: 15 additions & 9 deletions apps/meteor/client/views/admin/ABAC/AdminABACRoute.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ import { memo, useEffect, useLayoutEffect } from 'react';
import { useTranslation } from 'react-i18next';

import AdminABACPage from './AdminABACPage';
import type { ABACTab } from './hooks/useABACTabPermissions';
import { ABAC_TAB_ORDER, useABACTabPermissions } from './hooks/useABACTabPermissions';
import ABACUpsellModal from '../../../components/ABAC/ABACUpsellModal/ABACUpsellModal';
import { useUpsellActions } from '../../../components/GenericUpsellModal/hooks';
import PageSkeleton from '../../../components/PageSkeleton';
Expand All @@ -14,24 +16,28 @@ import EditableSettingsProvider from '../settings/EditableSettingsProvider';

const AdminABACRoute = (): ReactElement => {
const { t } = useTranslation();
// TODO: Check what permission is needed to view the ABAC page
const canViewABACPage = usePermission('abac-management');
const { data: hasABAC = false } = useHasLicenseModule('abac');
const isModalOpen = !!useCurrentModal();
const tab = useRouteParameter('tab');
const router = useRouter();
const tabPermissions = useABACTabPermissions();
const firstAllowedTab = ABAC_TAB_ORDER.find((t) => tabPermissions[t]);
const isAllowedTab = (ABAC_TAB_ORDER as readonly string[]).includes(tab ?? '') && tabPermissions[tab as ABACTab];

// Check if setting exists in the DB to decide if we show warning or upsell
const ABACEnabledSetting = useSettingStructure('ABAC_Enabled');

useLayoutEffect(() => {
if (!tab) {
router.navigate({
name: 'admin-ABAC',
params: { tab: 'settings' },
});
if (firstAllowedTab && !isAllowedTab) {
router.navigate(
{
name: 'admin-ABAC',
params: { tab: firstAllowedTab },
},
{ replace: true },
);
}
}, [tab, router]);
}, [router, firstAllowedTab, isAllowedTab]);

const { shouldShowUpsell, handleManageSubscription } = useUpsellActions(hasABAC);

Expand All @@ -48,7 +54,7 @@ const AdminABACRoute = (): ReactElement => {
return <PageSkeleton />;
}

if (!canViewABACPage || (ABACEnabledSetting === undefined && !hasABAC)) {
if (!canViewABACPage || !firstAllowedTab || (ABACEnabledSetting === undefined && !hasABAC)) {
return <NotAuthorizedPage />;
}

Expand Down
35 changes: 23 additions & 12 deletions apps/meteor/client/views/admin/ABAC/AdminABACTabs.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,13 @@ import { Tabs, TabsItem } from '@rocket.chat/fuselage';
import { useRouteParameter, useRouter } from '@rocket.chat/ui-contexts';
import { useTranslation } from 'react-i18next';

import { useABACTabPermissions } from './hooks/useABACTabPermissions';

const AdminABACTabs = () => {
const { t } = useTranslation();
const router = useRouter();
const tab = useRouteParameter('tab');
const tabPermissions = useABACTabPermissions();
const handleTabClick = (tab: string) => {
router.navigate({
name: 'admin-ABAC',
Expand All @@ -14,18 +17,26 @@ const AdminABACTabs = () => {
};
return (
<Tabs>
<TabsItem selected={tab === 'settings'} onClick={() => handleTabClick('settings')}>
{t('Settings')}
</TabsItem>
<TabsItem selected={tab === 'room-attributes'} onClick={() => handleTabClick('room-attributes')}>
{t('ABAC_Room_Attributes')}
</TabsItem>
<TabsItem selected={tab === 'rooms'} onClick={() => handleTabClick('rooms')}>
{t('Rooms')}
</TabsItem>
<TabsItem selected={tab === 'logs'} onClick={() => handleTabClick('logs')}>
{t('ABAC_Logs')}
</TabsItem>
{tabPermissions.settings && (
<TabsItem selected={tab === 'settings'} onClick={() => handleTabClick('settings')}>
{t('Settings')}
</TabsItem>
)}
{tabPermissions['room-attributes'] && (
<TabsItem selected={tab === 'room-attributes'} onClick={() => handleTabClick('room-attributes')}>
{t('ABAC_Room_Attributes')}
</TabsItem>
)}
{tabPermissions.rooms && (
<TabsItem selected={tab === 'rooms'} onClick={() => handleTabClick('rooms')}>
{t('Rooms')}
</TabsItem>
)}
{tabPermissions.logs && (
<TabsItem selected={tab === 'logs'} onClick={() => handleTabClick('logs')}>
{t('ABAC_Logs')}
</TabsItem>
)}
</Tabs>
);
};
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
import { usePermission } from '@rocket.chat/ui-contexts';

export type ABACTab = 'settings' | 'room-attributes' | 'rooms' | 'logs';

export const ABAC_TAB_ORDER: ABACTab[] = ['settings', 'room-attributes', 'rooms', 'logs'];

export const useABACTabPermissions = (): Record<ABACTab, boolean> => {
return {
'settings': usePermission('manage-abac-admin-settings'),
'room-attributes': usePermission('manage-abac-admin-room-attributes'),
'rooms': usePermission('manage-abac-admin-rooms'),
'logs': usePermission('view-abac-admin-audit'),
};
};
9 changes: 8 additions & 1 deletion apps/meteor/client/views/admin/sidebarItems.ts
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,14 @@ export const {
href: '/admin/ABAC',
i18nLabel: 'ABAC',
icon: 'team-lock',
permissionGranted: (): boolean => hasPermission('abac-management'),
permissionGranted: (): boolean =>
hasPermission('abac-management') &&
hasAtLeastOnePermission([
'manage-abac-admin-settings',
'manage-abac-admin-room-attributes',
'manage-abac-admin-rooms',
'view-abac-admin-audit',
]),
},
{
href: '/admin/device-management',
Expand Down
30 changes: 15 additions & 15 deletions apps/meteor/ee/server/api/abac/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ const abacEndpoints = API.v1
'abac/rooms/:rid/attributes',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
body: POSTRoomAbacAttributesBodySchema,
response: {
200: GenericSuccessSchema,
Expand Down Expand Up @@ -74,7 +74,7 @@ const abacEndpoints = API.v1
'abac/rooms/:rid/attributes',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
response: {
200: GenericSuccessSchema,
401: validateUnauthorizedErrorResponse,
Expand All @@ -97,7 +97,7 @@ const abacEndpoints = API.v1
'abac/rooms/:rid/attributes/:key',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
license: ['abac'],
body: POSTSingleRoomAbacAttributeBodySchema,
response: {
Expand All @@ -124,7 +124,7 @@ const abacEndpoints = API.v1
'abac/rooms/:rid/attributes/:key',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
body: PUTRoomAbacAttributeValuesBodySchema,
response: {
200: GenericSuccessSchema,
Expand All @@ -151,7 +151,7 @@ const abacEndpoints = API.v1
'abac/rooms/:rid/attributes/:key',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
response: {
200: GenericSuccessSchema,
401: validateUnauthorizedErrorResponse,
Expand All @@ -172,7 +172,7 @@ const abacEndpoints = API.v1
'abac/attributes',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
query: GETAbacAttributesQuerySchema,
response: {
200: GETAbacAttributesResponseSchema,
Expand Down Expand Up @@ -203,7 +203,7 @@ const abacEndpoints = API.v1
'abac/users/sync',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
license: ['abac', 'ldap-enterprise'],
body: POSTAbacUsersSyncBodySchema,
response: {
Expand All @@ -229,7 +229,7 @@ const abacEndpoints = API.v1
'abac/attributes',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
license: ['abac'],
body: POSTAbacAttributeDefinitionSchema,
response: {
Expand All @@ -253,7 +253,7 @@ const abacEndpoints = API.v1
'abac/attributes/:_id',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
license: ['abac'],
body: PUTAbacAttributeUpdateBodySchema,
response: {
Expand All @@ -278,7 +278,7 @@ const abacEndpoints = API.v1
'abac/attributes/:_id',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
response: {
200: GETAbacAttributeByIdResponseSchema,
401: validateUnauthorizedErrorResponse,
Expand All @@ -297,7 +297,7 @@ const abacEndpoints = API.v1
'abac/attributes/:_id',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
response: {
200: GenericSuccessSchema,
401: validateUnauthorizedErrorResponse,
Expand All @@ -316,7 +316,7 @@ const abacEndpoints = API.v1
'abac/attributes/:key/is-in-use',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-room-attributes'],
response: {
200: GETAbacAttributeIsInUseResponseSchema,
401: validateUnauthorizedErrorResponse,
Expand All @@ -334,7 +334,7 @@ const abacEndpoints = API.v1
'abac/rooms',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
response: {
200: GETAbacRoomsResponseValidator,
401: validateUnauthorizedErrorResponse,
Expand Down Expand Up @@ -364,7 +364,7 @@ const abacEndpoints = API.v1
'abac/pdp/health',
{
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'manage-abac-admin-settings'],
rateLimiterOptions: {
numRequestsAllowed: 5,
intervalTimeInMS: 60000,
Expand Down Expand Up @@ -396,7 +396,7 @@ const abacEndpoints = API.v1
},
query: GETAbacAuditEventsQuerySchema,
authRequired: true,
permissionsRequired: ['abac-management'],
permissionsRequired: ['abac-management', 'view-abac-admin-audit'],
license: ['abac', 'auditing'],
},
async function action() {
Expand Down
8 changes: 7 additions & 1 deletion apps/meteor/ee/server/lib/abac/index.ts
Original file line number Diff line number Diff line change
@@ -1,7 +1,13 @@
import { Permissions } from '@rocket.chat/models';

export const createPermissions = async () => {
const permissions = [{ _id: 'abac-management', roles: ['admin'] }];
const permissions = [
{ _id: 'abac-management', roles: ['admin'] },
{ _id: 'manage-abac-admin-settings', roles: ['admin'] },
{ _id: 'manage-abac-admin-room-attributes', roles: ['admin'] },
{ _id: 'manage-abac-admin-rooms', roles: ['admin'] },
{ _id: 'view-abac-admin-audit', roles: ['admin'] },
];

for (const permission of permissions) {
void Permissions.create(permission._id, permission.roles);
Expand Down
Loading
Loading