mirror of
https://github.com/jenkinsci/kubernetes-operator.git
synced 2026-10-09 17:35:32 +02:00
update to go1.24
This commit is contained in:
@@ -18,6 +18,7 @@ package v1alpha2
|
||||
|
||||
import (
|
||||
"compress/gzip"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"io"
|
||||
@@ -37,10 +38,10 @@ import (
|
||||
)
|
||||
|
||||
var (
|
||||
jenkinslog = logf.Log.WithName("jenkins-resource") // log is for logging in this package.
|
||||
SecValidator = *NewSecurityValidator()
|
||||
_ webhook.Validator = &Jenkins{}
|
||||
initialSecurityWarningsDownloadSucceded = false
|
||||
jenkinslog = logf.Log.WithName("jenkins-resource") // log is for logging in this package.
|
||||
SecValidator = *NewSecurityValidator()
|
||||
_ webhook.CustomValidator = &Jenkins{}
|
||||
initialSecurityWarningsDownloadSucceded = false
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -60,28 +61,36 @@ func (in *Jenkins) SetupWebhookWithManager(mgr ctrl.Manager) error {
|
||||
// TODO(user): change verbs to "verbs=create;update;delete" if you want to enable deletion validation.
|
||||
// +kubebuilder:webhook:path=/validate-jenkins-io-jenkins-io-v1alpha2-jenkins,mutating=false,failurePolicy=fail,sideEffects=None,groups=jenkins.io.jenkins.io,resources=jenkins,verbs=create;update,versions=v1alpha2,name=vjenkins.kb.io,admissionReviewVersions={v1}
|
||||
|
||||
// ValidateCreate implements webhook.Validator so a webhook will be registered for the type
|
||||
func (in *Jenkins) ValidateCreate() (admission.Warnings, error) {
|
||||
if in.Spec.ValidateSecurityWarnings {
|
||||
jenkinslog.Info("validate create", "name", in.Name)
|
||||
err := Validate(*in)
|
||||
// ValidateCreate implements webhook.CustomValidator so a webhook will be registered for the type
|
||||
func (in *Jenkins) ValidateCreate(ctx context.Context, obj runtime.Object) (admission.Warnings, error) {
|
||||
jenkins, ok := obj.(*Jenkins)
|
||||
if !ok {
|
||||
return nil, errors.New("expected a Jenkins object")
|
||||
}
|
||||
if jenkins.Spec.ValidateSecurityWarnings {
|
||||
jenkinslog.Info("validate create", "name", jenkins.Name)
|
||||
err := Validate(*jenkins)
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
// ValidateUpdate implements webhook.Validator so a webhook will be registered for the type
|
||||
func (in *Jenkins) ValidateUpdate(old runtime.Object) (admission.Warnings, error) {
|
||||
if in.Spec.ValidateSecurityWarnings {
|
||||
jenkinslog.Info("validate update", "name", in.Name)
|
||||
return nil, Validate(*in)
|
||||
// ValidateUpdate implements webhook.CustomValidator so a webhook will be registered for the type
|
||||
func (in *Jenkins) ValidateUpdate(ctx context.Context, oldObj, newObj runtime.Object) (admission.Warnings, error) {
|
||||
jenkins, ok := newObj.(*Jenkins)
|
||||
if !ok {
|
||||
return nil, errors.New("expected a Jenkins object")
|
||||
}
|
||||
if jenkins.Spec.ValidateSecurityWarnings {
|
||||
jenkinslog.Info("validate update", "name", jenkins.Name)
|
||||
return nil, Validate(*jenkins)
|
||||
}
|
||||
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
func (in *Jenkins) ValidateDelete() (admission.Warnings, error) {
|
||||
func (in *Jenkins) ValidateDelete(ctx context.Context, obj runtime.Object) (admission.Warnings, error) {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
package v1alpha2
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"testing"
|
||||
|
||||
@@ -79,7 +80,7 @@ func TestValidate(t *testing.T) {
|
||||
t.Run("Validating when plugins data file is not fetched", func(t *testing.T) {
|
||||
userplugins := []Plugin{{Name: "script-security", Version: "1.77"}, {Name: "git-client", Version: "3.9"}, {Name: "git", Version: "4.8.1"}, {Name: "plain-credentials", Version: "1.7"}}
|
||||
jenkinscr := *createJenkinsCR(userplugins, true)
|
||||
_, got := jenkinscr.ValidateCreate()
|
||||
_, got := jenkinscr.ValidateCreate(context.TODO(), &jenkinscr)
|
||||
assert.Equal(t, got, errors.New("plugins data has not been fetched"))
|
||||
})
|
||||
|
||||
@@ -95,7 +96,7 @@ func TestValidate(t *testing.T) {
|
||||
{Name: "plain-credentials"}}}
|
||||
userplugins := []Plugin{{Name: "script-security", Version: "1.77"}, {Name: "git-client", Version: "3.9"}, {Name: "git", Version: "4.8.1"}, {Name: "plain-credentials", Version: "1.7"}}
|
||||
jenkinscr := *createJenkinsCR(userplugins, true)
|
||||
_, got := jenkinscr.ValidateCreate()
|
||||
_, got := jenkinscr.ValidateCreate(context.TODO(), &jenkinscr)
|
||||
assert.Nil(t, got)
|
||||
})
|
||||
|
||||
@@ -113,7 +114,7 @@ func TestValidate(t *testing.T) {
|
||||
}}
|
||||
userplugins := []Plugin{{Name: "google-login", Version: "1.2"}, {Name: "mailer", Version: "1.1"}, {Name: "git", Version: "4.8.1"}, {Name: "command-launcher", Version: "1.6"}, {Name: "workflow-cps", Version: "2.59"}}
|
||||
jenkinscr := *createJenkinsCR(userplugins, true)
|
||||
_, got := jenkinscr.ValidateCreate()
|
||||
_, got := jenkinscr.ValidateCreate(context.TODO(), &jenkinscr)
|
||||
assert.Equal(t, got, errors.New("security vulnerabilities detected in the following user-defined plugins: \nworkflow-cps:2.59\ngoogle-login:1.2\nmailer:1.1"))
|
||||
})
|
||||
|
||||
@@ -136,19 +137,19 @@ func TestValidate(t *testing.T) {
|
||||
|
||||
userplugins = []Plugin{{Name: "handy-uri-templates-2-api", Version: "2.1.8-1.0"}, {Name: "resource-disposer", Version: "0.8"}, {Name: "jjwt-api", Version: "0.11.2-9.c8b45b8bb173"}, {Name: "blueocean-github-pipeline", Version: "1.2.0-beta-3"}, {Name: "ghprb", Version: "1.39"}}
|
||||
newjenkinscr := *createJenkinsCR(userplugins, true)
|
||||
_, got := newjenkinscr.ValidateUpdate(&oldjenkinscr)
|
||||
_, got := newjenkinscr.ValidateUpdate(context.TODO(), &oldjenkinscr, &newjenkinscr)
|
||||
assert.Equal(t, got, errors.New("security vulnerabilities detected in the following user-defined plugins: \nhandy-uri-templates-2-api:2.1.8-1.0\nresource-disposer:0.8\nblueocean-github-pipeline:1.2.0-beta-3\nghprb:1.39"))
|
||||
})
|
||||
|
||||
t.Run("Validation is turned off", func(t *testing.T) {
|
||||
userplugins := []Plugin{{Name: "google-login", Version: "1.2"}, {Name: "mailer", Version: "1.1"}, {Name: "git", Version: "4.8.1"}, {Name: "command-launcher", Version: "1.6"}, {Name: "workflow-cps", Version: "2.59"}}
|
||||
jenkinscr := *createJenkinsCR(userplugins, false)
|
||||
_, got := jenkinscr.ValidateCreate()
|
||||
_, got := jenkinscr.ValidateCreate(context.TODO(), &jenkinscr)
|
||||
assert.Nil(t, got)
|
||||
|
||||
userplugins = []Plugin{{Name: "google-login", Version: "1.2"}, {Name: "mailer", Version: "1.1"}, {Name: "git", Version: "4.8.1"}, {Name: "command-launcher", Version: "1.6"}, {Name: "workflow-cps", Version: "2.59"}}
|
||||
newjenkinscr := *createJenkinsCR(userplugins, false)
|
||||
_, got = newjenkinscr.ValidateUpdate(&jenkinscr)
|
||||
_, got = newjenkinscr.ValidateUpdate(context.TODO(), &jenkinscr, &newjenkinscr)
|
||||
assert.Nil(t, got)
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user