fix: read enterprise modules from licenses.info - #7746
diegolmello wants to merge 2 commits into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedReview was skipped as selected files did not have any reviewable changes. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (2)
🔇 Additional comments (4)
WalkthroughEnterprise module retrieval now uses a version-dependent SDK endpoint. The REST endpoint types include the ChangesEnterprise module retrieval
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant getEnterpriseModules
participant fetchEnterpriseModules
participant SDK
participant ServerRecord
participant Redux
getEnterpriseModules->>fetchEnterpriseModules: select retrieval by server version
alt version 6.5.0 or later
fetchEnterpriseModules->>SDK: call licenses.info
SDK-->>fetchEnterpriseModules: return license.activeModules
else version 3.1.0 to below 6.5.0
fetchEnterpriseModules->>SDK: call license:getModules
SDK-->>fetchEnterpriseModules: return modules
end
fetchEnterpriseModules-->>getEnterpriseModules: return modules or no modules
getEnterpriseModules->>ServerRecord: save comma-separated modules when returned
getEnterpriseModules->>Redux: dispatch modules or clear module state
Suggested labels: Merge Risk: ⚪ Minimal · up to No concrete merge-blocking issue is established. The change retains older-server retrieval while using licenses.info on newer servers; merge after normal checks pass. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change replaces the license lookup used by newer servers while preserving the checked feature-permission gates. No new authorization bypass was established, but the newer endpoint’s access controls and full response remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Warning Errors were encountered while retrieving linked issues. Errors (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Android Build Available Rocket.Chat 4.77.0.109821 Internal App Sharing: https://play.google.com/apps/test/RQQ8k09hlnQ/ahAO29uNQLNaCiL-ugmFOM3hlb-D0s91IFRIV4aRIl2VP6yN9POc9g2HTkfBIUiYm_647aBHwR1nosnAjvl29xJEh0 |
|
Android Build Available Rocket.Chat 4.78.0.109845 Internal App Sharing: https://play.google.com/apps/test/RQQ8k09hlnQ/ahAO29uNQSsG6vJUsyYlAWBrJSdmWs2leGoilCeK-YC0mZc74oNMi75y6i6MbXkKCtoPGlX1U32pmIvIJVMH2uOOCF |
|
iOS Build Available Rocket.Chat 4.78.0.109849 |
Proposed changes
The app loaded the workspace's enterprise modules through the DDP method
license:getModules. The server has deprecated everylicense:*method (removal in 9.0.0) in favour of/v1/licenses.info. Servers that run withTEST_MODE=trueorROCKET_CHAT_DEPRECATION_THROW_ERRORS_FOR_VERSIONS_UNDER=9.0.0already throw on those methods and answer with a 500. When that happens the modules list stays empty, so every licensed feature is hidden, including "Voice call" in the sidebar.getEnterpriseModulesnow picks its source by server version:GET licenses.info, readinglicense.activeModules. The endpoint shipped in 6.5.0 and has returnedactiveModulessince then.license:getModules, unchanged.The PR also adds a REST type for
licenses.infoand drops thenew Promise(async …)wrapper around the function.Issue(s)
https://rocketchat.atlassian.net/browse/NATIVE-1698
How to test or reproduce
teams-voip, running withTEST_MODE=trueorROCKET_CHAT_DEPRECATION_THROW_ERRORS_FOR_VERSIONS_UNDER=9.0.0.allow-internal-voice-callsorallow-external-voice-calls.Screenshots
Types of changes
Checklist
Further comments
The pre-6.5.0 path stays because the app still connects to older servers when a workspace has a supported-versions exception.
Summary by CodeRabbit