mirror of
https://github.com/fleetdm/fleet
synced 2026-04-22 05:57:36 +00:00
for #31182 # Details This PR implements the "Action Required" state for Windows host disk encryption. This includes updates to reporting for: * disk encryption summary (`GET /fleet/disk_encryption`) * config profiles summary (`GET /configuration_profiles/summary`) * config profile status ( `GET /configuration_profiles/{profile_uuid}/status`) For disk encryption summary, the statuses are now determined according to [the rules in the Figma](https://www.figma.com/design/XbhlPuEJxQtOgTZW9EOJZp/-28133-Enforce-BitLocker-PIN?node-id=5484-928&t=JB13g8zQ2QDVEmPB-0). TL;DR if the criteria for "verified" or "verifying" are set, but a required PIN is not set, we report a host as "action required". For profiles, I followed what seems to be the existing pattern and set the profile status to "pending" if the disk encryption status is "action required". This is what we do for hosts with the "enforcing" or "removing enforcement" statuses. A lot of the changes in these files are due to the creation of the `fleet.DiskEncryptionConfig` struct to hold info about disk encryption config, and passing variables of that type to various functions instead of passing a `bool` to indicate whether encryption is enabled. Other than that, the functional changes are constrained to a few files. > Note: to get the "require bitlocker pin" UI, compile the front end with: ``` SHOW_BITLOCKER_PIN_OPTION=true NODE_ENV=development yarn run webpack --progress --watch ``` # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. Changelog will be added when feature is complete. - [X] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements) ## Testing - [X] Added/updated automated tests - [X] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [ ] QA'd all new/changed functionality manually Could use some help testing this end-to-end. I was able to test the banners showing up correctly, but testing the Disk Encryption table requires some Windows-MDM-fu (I just get all zeroes). ## Database migrations - [X] Checked table schema to confirm autoupdate - [X] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [X] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [X] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`).
113 lines
3.2 KiB
TypeScript
113 lines
3.2 KiB
TypeScript
import React from "react";
|
|
import ReactTooltip from "react-tooltip";
|
|
import { uniqueId } from "lodash";
|
|
|
|
import Icon from "components/Icon";
|
|
import TextCell from "components/TableContainer/DataTable/TextCell";
|
|
import {
|
|
LinuxDiskEncryptionStatus,
|
|
ProfileOperationType,
|
|
ProfilePlatform,
|
|
} from "interfaces/mdm";
|
|
import { COLORS } from "styles/var/colors";
|
|
|
|
import { OsSettingsTableStatusValue } from "../OSSettingsTableConfig";
|
|
import TooltipContent from "./components/Tooltip/TooltipContent";
|
|
import {
|
|
isDiskEncryptionProfile,
|
|
LINUX_DISK_ENCRYPTION_DISPLAY_CONFIG,
|
|
PROFILE_DISPLAY_CONFIG,
|
|
ProfileDisplayOption,
|
|
WINDOWS_DISK_ENCRYPTION_DISPLAY_CONFIG,
|
|
} from "./helpers";
|
|
|
|
const baseClass = "os-settings-status-cell";
|
|
|
|
interface IOSSettingStatusCellProps {
|
|
status: OsSettingsTableStatusValue;
|
|
operationType: ProfileOperationType | null;
|
|
profileName: string;
|
|
hostPlatform?: ProfilePlatform;
|
|
}
|
|
|
|
const OSSettingStatusCell = ({
|
|
status,
|
|
operationType,
|
|
profileName = "",
|
|
hostPlatform,
|
|
}: IOSSettingStatusCellProps) => {
|
|
let displayOption: ProfileDisplayOption = null;
|
|
|
|
if (hostPlatform === "linux") {
|
|
displayOption =
|
|
LINUX_DISK_ENCRYPTION_DISPLAY_CONFIG[status as LinuxDiskEncryptionStatus];
|
|
}
|
|
|
|
// windows hosts do not have an operation type at the moment and their display options are
|
|
// different than mac hosts.
|
|
else if (
|
|
!operationType &&
|
|
status !== "success" &&
|
|
status !== "acknowledged"
|
|
) {
|
|
displayOption = WINDOWS_DISK_ENCRYPTION_DISPLAY_CONFIG[status];
|
|
} else if (operationType) {
|
|
displayOption = PROFILE_DISPLAY_CONFIG[operationType]?.[status];
|
|
}
|
|
|
|
const isDeviceUser = window.location.pathname
|
|
.toLowerCase()
|
|
.includes("/device/");
|
|
|
|
if (displayOption) {
|
|
const { statusText, iconName, tooltip } = displayOption;
|
|
const tooltipId = uniqueId();
|
|
return (
|
|
<span className={baseClass}>
|
|
<Icon name={iconName} />
|
|
{tooltip ? (
|
|
<>
|
|
<span
|
|
className={`${baseClass}__status-text`}
|
|
data-tip
|
|
data-for={tooltipId}
|
|
data-tip-disable={false}
|
|
>
|
|
{statusText}
|
|
</span>
|
|
<ReactTooltip
|
|
place="top"
|
|
effect="solid"
|
|
backgroundColor={COLORS["tooltip-bg"]}
|
|
id={tooltipId}
|
|
data-html
|
|
>
|
|
<span className="tooltip__tooltip-text">
|
|
{status !== "action_required" ? (
|
|
<TooltipContent
|
|
innerContent={tooltip}
|
|
innerProps={{
|
|
isDiskEncryptionProfile: isDiskEncryptionProfile(
|
|
profileName
|
|
),
|
|
}}
|
|
/>
|
|
) : (
|
|
<TooltipContent
|
|
innerContent={tooltip}
|
|
innerProps={{ isDeviceUser, profileName }}
|
|
/>
|
|
)}
|
|
</span>
|
|
</ReactTooltip>
|
|
</>
|
|
) : (
|
|
statusText
|
|
)}
|
|
</span>
|
|
);
|
|
}
|
|
// graceful error - this state should not be reached based on the API spec
|
|
return <TextCell value="Unrecognized" />;
|
|
};
|
|
export default OSSettingStatusCell;
|