0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 13:08:40 +08:00
discourse/lib/theme_settings_validator.rb
Martin Brennan 7e77ce4bd3
DEV: Add resolve_group_membership functionality to theme settings (#41360)
Currently, theme settings with `type: list` and `list_type: group`
require client-side permission checks, but `currentUser.groups` only
includes visible groups, not all groups the user belongs to. This makes
permission checks unreliable and can leak hidden group membership.

To address this, this commit adds an opt-in `resolve_group_membership:
true` option that replaces the group ID list with a user_in_SETTING_NAME
boolean resolved server-side via `guardian.in_any_groups?`. The original
group list is removed from the frontend payload to prevent leaking group
IDs.

Since theme settings are cached per-theme (not per-user), the resolution
happens after the cache lookup during per-request serialization in
`ApplicationLayoutPreloader#activated_themes_json`.

Example YAML:

```yaml
copy_button_allowed_groups:
  type: list
  list_type: group
  resolve_group_membership: true
  default: "1|3"
```

Frontend usage:

```javascript
if (!settings.user_in_copy_button_allowed_groups) return;
```
2026-07-08 09:29:21 +10:00

103 lines
2.8 KiB
Ruby
Vendored

# frozen_string_literal: true
# Service class that holds helper methods that can be used to validate theme settings.
class ThemeSettingsValidator
class << self
def is_value_present?(value)
!value.nil?
end
def is_valid_value_type?(value, type)
case type
when types[:integer]
value.is_a?(Integer)
when types[:float]
value.is_a?(Integer) || value.is_a?(Float)
when types[:bool]
value.is_a?(TrueClass) || value.is_a?(FalseClass)
when types[:list]
value.is_a?(String)
when types[:objects]
value.is_a?(Array) && value.all? { |v| v.is_a?(Hash) }
else
true
end
end
def validate_value(value, type, opts)
errors = []
errors.concat(validate_resolve_group_membership(opts, type))
case type
when types[:enum]
if opts[:choices].exclude?(value) && opts[:choices].map(&:to_s).exclude?(value)
errors << I18n.t(
"themes.settings_errors.enum_value_not_valid",
choices: opts[:choices].join(", "),
)
end
when types[:integer], types[:float]
validate_value_in_range!(
value,
min: opts[:min],
max: opts[:max],
errors:,
translation_prefix: "number",
)
when types[:string]
validate_value_in_range!(
value.to_s.length,
min: opts[:min],
max: opts[:max],
errors:,
translation_prefix: "string",
)
when types[:objects]
errors.concat(
SchemaSettingsObjectValidator.validate_objects(schema: opts[:schema], objects: value),
)
end
errors
end
def validate_resolve_group_membership(opts, type)
errors = []
if opts[:resolve_group_membership]
if type != types[:list]
errors << I18n.t("themes.settings_errors.resolve_group_membership_requires_list")
elsif opts[:list_type] != "group"
errors << I18n.t("themes.settings_errors.resolve_group_membership_requires_group_list")
end
end
errors
end
private
def types
ThemeSetting.types
end
def validate_value_in_range!(value, min:, max:, errors:, translation_prefix:)
if min && max && max != Float::INFINITY && !(min..max).include?(value)
errors << I18n.t(
"themes.settings_errors.#{translation_prefix}_value_not_valid_min_max",
min: min,
max: max,
)
elsif min && value < min
errors << I18n.t(
"themes.settings_errors.#{translation_prefix}_value_not_valid_min",
min: min,
)
elsif max && value > max
errors << I18n.t(
"themes.settings_errors.#{translation_prefix}_value_not_valid_max",
max: max,
)
end
end
end
end