diff --git a/system/service/access_control.go b/system/service/access_control.go index 5d946d09c..7f550bba2 100644 --- a/system/service/access_control.go +++ b/system/service/access_control.go @@ -2,6 +2,7 @@ package service import ( "context" + internalAuth "github.com/cortezaproject/corteza-server/pkg/auth" "github.com/cortezaproject/corteza-server/pkg/permissions" "github.com/cortezaproject/corteza-server/system/types" @@ -157,10 +158,20 @@ func (svc accessControl) CanDeleteUser(ctx context.Context, u *types.User) bool } func (svc accessControl) CanUnmaskEmail(ctx context.Context, u *types.User) bool { + if internalAuth.GetIdentityFromContext(ctx).Identity() == u.ID { + // Make an exception when users are reading their own info + return true + } + return svc.can(ctx, u, "unmask.email") } func (svc accessControl) CanUnmaskName(ctx context.Context, u *types.User) bool { + if internalAuth.GetIdentityFromContext(ctx).Identity() == u.ID { + // Make an exception when users are reading their own info + return true + } + return svc.can(ctx, u, "unmask.name") } @@ -219,6 +230,8 @@ func (svc accessControl) Whitelist() permissions.Whitelist { "delete", "suspend", "unsuspend", + "unmask.email", + "unmask.name", ) wl.Set( diff --git a/system/service/user.go b/system/service/user.go index a5b56317e..291e050f9 100644 --- a/system/service/user.go +++ b/system/service/user.go @@ -48,11 +48,6 @@ type ( user repository.UserRepository role repository.RoleRepository credentials repository.CredentialsRepository - - // @todo wire this with settings (privacy.mask.email) - privacyMaskEmail bool - // @todo wire this with settings (privacy.mask.name) - privacyMaskName bool } userAuth interface { @@ -113,14 +108,6 @@ func User(ctx context.Context) UserService { auth: DefaultAuth, subscription: CurrentSubscription, - - // @todo wire this with settings (privacy.mask.email) - // new default value will be true! - privacyMaskEmail: false, - - // @todo wire this with settings (privacy.mask.name) - // new default value will be true! - privacyMaskName: false, }).With(ctx) } @@ -146,9 +133,6 @@ func (svc user) With(ctx context.Context) UserService { user: repository.User(ctx, db), role: repository.Role(ctx, db), credentials: repository.Credentials(ctx, db), - - privacyMaskEmail: svc.privacyMaskEmail, - privacyMaskName: svc.privacyMaskName, } } @@ -229,16 +213,11 @@ func (svc user) Find(f types.UserFilter) (types.UserSet, types.UserFilter, error } } - if svc.privacyMaskEmail { - // Prepare filter for email unmasking check - f.IsEmailUnmaskable = svc.ac.FilterUsersWithUnmaskableEmail(svc.ctx) + // Prepare filter for email unmasking check + f.IsEmailUnmaskable = svc.ac.FilterUsersWithUnmaskableEmail(svc.ctx) - } - - if svc.privacyMaskName { - // Prepare filter for name unmasking check - f.IsNameUnmaskable = svc.ac.FilterUsersWithUnmaskableName(svc.ctx) - } + // Prepare filter for name unmasking check + f.IsNameUnmaskable = svc.ac.FilterUsersWithUnmaskableName(svc.ctx) f.IsReadable = svc.ac.FilterReadableUsers(svc.ctx) @@ -486,11 +465,11 @@ func (svc user) SetPassword(userID uint64, newPassword string) (err error) { // Masks (or leaves as-is) private data on user func (svc user) handlePrivateData(u *types.User) { - if svc.privacyMaskEmail && !svc.ac.CanUnmaskEmail(svc.ctx, u) { + if !svc.ac.CanUnmaskEmail(svc.ctx, u) { u.Email = maskPrivateDataEmail } - if svc.privacyMaskName && !svc.ac.CanUnmaskEmail(svc.ctx, u) { + if !svc.ac.CanUnmaskName(svc.ctx, u) { u.Name = maskPrivateDataName } }