Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
fix(appstore): Only send subscription keys to valid appstores
Signed-off-by: Joas Schilling <[email protected]>
  • Loading branch information
nickvergessen authored and skjnldsv committed Jan 16, 2024
commit 0148dab1e71456a43442925c1e1e7102049da8a0
11 changes: 7 additions & 4 deletions lib/private/App/AppStore/Fetcher/Fetcher.php
Original file line number Diff line number Diff line change
Expand Up @@ -109,10 +109,13 @@ protected function fetch($ETag, $content) {
];
}

// If we have a valid subscription key, send it to the appstore
$subscriptionKey = $this->config->getAppValue('support', 'subscription_key');
if ($this->registry->delegateHasValidSubscription() && $subscriptionKey) {
$options['headers']['X-NC-Subscription-Key'] = $subscriptionKey;
if ($this->config->getSystemValueString('appstoreurl', 'https://apps.nextcloud.com/api/v1') === 'https://apps.nextcloud.com/api/v1') {
// If we have a valid subscription key, send it to the appstore
$subscriptionKey = $this->config->getAppValue('support', 'subscription_key');
if ($this->registry->delegateHasValidSubscription() && $subscriptionKey) {
$options['headers'] ??= [];
$options['headers']['X-NC-Subscription-Key'] = $subscriptionKey;
}
}

$client = $this->clientService->newClient();
Expand Down
95 changes: 93 additions & 2 deletions tests/lib/App/AppStore/Fetcher/AppFetcherTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -2094,6 +2094,95 @@ public function testSetVersion() {
}

public function testGetAppsAllowlist() {
$this->config->method('getSystemValueString')
->willReturnCallback(function ($key, $default) {
if ($key === 'version') {
return '11.0.0.2';
} else {
return $default;
}
});
$this->config->method('getSystemValue')
->willReturnCallback(function ($key, $default) {
if ($key === 'appsallowlist') {
return ['contacts'];
}
return $default;
});
$this->config->method('getAppValue')
->willReturnCallback(function ($app, $key, $default) {
if ($app === 'support' && $key === 'subscription_key') {
return 'subscription-key';
}
return $default;
});
$this->config
->method('getSystemValueBool')
->willReturnArgument(1);

$file = $this->createMock(ISimpleFile::class);
$folder = $this->createMock(ISimpleFolder::class);
$folder
->expects($this->once())
->method('getFile')
->with('apps.json')
->willThrowException(new NotFoundException());
$folder
->expects($this->once())
->method('newFile')
->with('apps.json')
->willReturn($file);
$this->appData
->expects($this->once())
->method('getFolder')
->with('/')
->willReturn($folder);
$client = $this->createMock(IClient::class);
$this->clientService
->expects($this->once())
->method('newClient')
->willReturn($client);
$response = $this->createMock(IResponse::class);
$client
->expects($this->once())
->method('get')
->with('https://apps.nextcloud.com/api/v1/apps.json', [
'timeout' => 60,
'headers' => [
'X-NC-Subscription-Key' => 'subscription-key',
],
])
->willReturn($response);
$response
->expects($this->once())
->method('getBody')
->willReturn(self::$responseJson);
$response->method('getHeader')
->with($this->equalTo('ETag'))
->willReturn('"myETag"');
$this->timeFactory
->expects($this->once())
->method('getTime')
->willReturn(1234);

$this->registry
->expects($this->exactly(2))
->method('delegateHasValidSubscription')
->willReturn(true);

$file
->expects($this->once())
->method('putContent');
$file
->method('getContent')
->willReturn(json_encode(self::$expectedResponse));

$apps = array_values($this->fetcher->get());
$this->assertEquals(count($apps), 1);
$this->assertEquals($apps[0]['id'], 'contacts');
}

public function testGetAppsAllowlistCustomAppstore(): void {
$this->config->method('getSystemValueString')
->willReturnCallback(function ($key, $default) {
if ($key === 'version') {
Expand Down Expand Up @@ -2142,7 +2231,9 @@ public function testGetAppsAllowlist() {
$client
->expects($this->once())
->method('get')
->with('https://custom.appsstore.endpoint/api/v1/apps.json')
->with('https://custom.appsstore.endpoint/api/v1/apps.json', [
'timeout' => 60,
])
->willReturn($response);
$response
->expects($this->once())
Expand All @@ -2157,7 +2248,7 @@ public function testGetAppsAllowlist() {
->willReturn(1234);

$this->registry
->expects($this->exactly(2))
->expects($this->exactly(1))
->method('delegateHasValidSubscription')
->willReturn(true);

Expand Down