Skip to content

Commit f6b1a44

Browse files
committed
[fix] Do not allow applying more than 1 templates of same VPN server #832
Fixes #832
1 parent 04b3ddb commit f6b1a44

3 files changed

Lines changed: 91 additions & 1 deletion

File tree

openwisp_controller/config/base/config.py

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
import collections
22
import logging
33
import re
4+
from collections import defaultdict
45

56
from cache_memoize import cache_memoize
67
from django.core.exceptions import ObjectDoesNotExist, PermissionDenied, ValidationError
@@ -185,6 +186,45 @@ def _get_templates_from_pk_set(cls, pk_set):
185186
templates = pk_set
186187
return templates
187188

189+
@classmethod
190+
def validate_duplicate_vpn_templates(cls, action, instance, templates):
191+
"""
192+
Validates if there are duplicate templates for the same VPN server.
193+
Raises a ValidationError if duplicates are found.
194+
"""
195+
if action != 'pre_add':
196+
return
197+
198+
def format_template_list(names):
199+
quoted = [f'"{name}"' for name in names]
200+
if len(quoted) == 2:
201+
return ' and '.join(quoted)
202+
return ', '.join(quoted[:-1]) + ' and ' + quoted[-1]
203+
204+
def add_vpn_templates(templates_queryset):
205+
for template in templates_queryset.filter(type='vpn'):
206+
if template.name not in vpn_templates[template.vpn.name]:
207+
vpn_templates[template.vpn.name].append(template.name)
208+
209+
vpn_templates = defaultdict(list)
210+
add_vpn_templates(instance.templates)
211+
add_vpn_templates(templates)
212+
213+
error_lines = [
214+
'You cannot select multiple VPN client templates related to'
215+
' the same VPN server.'
216+
]
217+
for vpn_name, template_names in vpn_templates.items():
218+
if len(template_names) < 2:
219+
continue
220+
template_list = format_template_list(sorted(template_names))
221+
error_lines.append(
222+
f'The templates {template_list} are all linked'
223+
f' to the same VPN server: "{vpn_name}".'
224+
)
225+
if len(error_lines) > 1:
226+
raise ValidationError('\n'.join(error_lines))
227+
188228
@classmethod
189229
def clean_templates(cls, action, instance, pk_set, raw_data=None, **kwargs):
190230
"""
@@ -203,6 +243,7 @@ def clean_templates(cls, action, instance, pk_set, raw_data=None, **kwargs):
203243
)
204244
if not templates:
205245
return
246+
cls.validate_duplicate_vpn_templates(action, instance, templates)
206247
backend = instance.get_backend_instance(template_instances=templates)
207248
try:
208249
cls.clean_netjsonconfig_backend(backend)

openwisp_controller/config/tests/test_config.py

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -892,6 +892,55 @@ class TestTransactionConfig(
892892
TestVpnX509Mixin,
893893
TransactionTestCase,
894894
):
895+
def test_multiple_vpn_templates_same_vpn(self):
896+
vpn1 = self._create_vpn(name='vpn1')
897+
vpn2 = self._create_vpn(name='vpn2')
898+
vpn1_template1 = self._create_template(
899+
name='vpn1-template1', type='vpn', vpn=vpn1
900+
)
901+
vpn1_template2 = self._create_template(
902+
name='vpn1-template2', type='vpn', vpn=vpn1
903+
)
904+
vpn2_template1 = self._create_template(
905+
name='vpn2-template1', type='vpn', vpn=vpn2
906+
)
907+
vpn2_template2 = self._create_template(
908+
name='vpn2-template2', type='vpn', vpn=vpn2
909+
)
910+
vpn2_template3 = self._create_template(
911+
name='vpn2-template3', type='vpn', vpn=vpn2
912+
)
913+
config = self._create_config(device=self._create_device())
914+
config.templates.add(vpn1_template1)
915+
with self.subTest('Adding template one by one'):
916+
with self.assertRaises(ValidationError) as context_manager:
917+
config.templates.add(vpn1_template2)
918+
self.assertEqual(
919+
context_manager.exception.message,
920+
'You cannot select multiple VPN client templates related to the'
921+
' same VPN server.\n'
922+
'The templates "vpn1-template1" and "vpn1-template2" are all'
923+
' linked to the same VPN server: "vpn1".',
924+
)
925+
926+
with self.subTest('Add duplicate templates for multiple VPN'):
927+
config.refresh_from_db()
928+
self.assertEqual(config.templates.count(), 1)
929+
self.assertEqual(config.vpnclient_set.count(), 1)
930+
with self.assertRaises(ValidationError) as context_manager:
931+
config.templates.add(
932+
vpn1_template2, vpn2_template1, vpn2_template2, vpn2_template3
933+
)
934+
self.assertEqual(
935+
context_manager.exception.message,
936+
'You cannot select multiple VPN client templates related to the'
937+
' same VPN server.\n'
938+
'The templates "vpn1-template1" and "vpn1-template2" are all'
939+
' linked to the same VPN server: "vpn1".\n'
940+
'The templates "vpn2-template1", "vpn2-template2" and "vpn2-template3"'
941+
' are all linked to the same VPN server: "vpn2".',
942+
)
943+
895944
def test_certificate_renew_invalidates_checksum_cache(self):
896945
config = self._create_config(organization=self._get_org())
897946
vpn_template = self._create_template(

openwisp_controller/config/tests/test_vpn.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,7 +249,7 @@ def test_vpn_client_deletion(self):
249249
def _assert_vpn_client_cert(cert, vpn_client, cert_ct, vpn_client_ct):
250250
self.assertEqual(Cert.objects.filter(pk=cert.pk).count(), 1)
251251
self.assertEqual(VpnClient.objects.filter(pk=vpn_client.pk).count(), 1)
252-
vpnclient.delete()
252+
c.templates.remove(t)
253253
self.assertEqual(
254254
Cert.objects.filter(pk=cert.pk, revoked=False).count(), cert_ct
255255
)

0 commit comments

Comments
 (0)