You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

SearchActionIT.java 114KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2024 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.issue.ws;
  21. import com.google.common.collect.Sets;
  22. import com.google.gson.JsonElement;
  23. import com.google.gson.JsonParser;
  24. import java.time.Clock;
  25. import java.util.Arrays;
  26. import java.util.Collections;
  27. import java.util.List;
  28. import java.util.Map;
  29. import java.util.Optional;
  30. import java.util.Random;
  31. import java.util.Set;
  32. import java.util.function.Consumer;
  33. import java.util.stream.Collectors;
  34. import java.util.stream.IntStream;
  35. import java.util.stream.Stream;
  36. import org.junit.Before;
  37. import org.junit.Rule;
  38. import org.junit.Test;
  39. import org.sonar.api.issue.IssueStatus;
  40. import org.sonar.api.issue.impact.SoftwareQuality;
  41. import org.sonar.api.resources.Languages;
  42. import org.sonar.api.rule.RuleKey;
  43. import org.sonar.api.rule.RuleStatus;
  44. import org.sonar.api.rules.CleanCodeAttribute;
  45. import org.sonar.api.rules.CleanCodeAttributeCategory;
  46. import org.sonar.api.rules.RuleType;
  47. import org.sonar.api.server.ws.WebService;
  48. import org.sonar.api.utils.Durations;
  49. import org.sonar.api.utils.System2;
  50. import org.sonar.api.web.UserRole;
  51. import org.sonar.core.util.UuidFactoryFast;
  52. import org.sonar.core.util.Uuids;
  53. import org.sonar.db.DbClient;
  54. import org.sonar.db.DbSession;
  55. import org.sonar.db.DbTester;
  56. import org.sonar.db.component.BranchDto;
  57. import org.sonar.db.component.BranchType;
  58. import org.sonar.db.component.ComponentDto;
  59. import org.sonar.db.component.ProjectData;
  60. import org.sonar.db.component.SnapshotDto;
  61. import org.sonar.db.issue.ImpactDto;
  62. import org.sonar.db.issue.IssueChangeDto;
  63. import org.sonar.db.issue.IssueDto;
  64. import org.sonar.db.issue.IssueFixedDto;
  65. import org.sonar.db.permission.GroupPermissionDto;
  66. import org.sonar.db.project.ProjectDto;
  67. import org.sonar.db.protobuf.DbCommons;
  68. import org.sonar.db.protobuf.DbIssues;
  69. import org.sonar.db.rule.RuleDto;
  70. import org.sonar.db.rule.RuleTesting;
  71. import org.sonar.db.user.UserDto;
  72. import org.sonar.server.common.avatar.AvatarResolverImpl;
  73. import org.sonar.server.es.EsTester;
  74. import org.sonar.server.es.SearchOptions;
  75. import org.sonar.server.issue.IssueFieldsSetter;
  76. import org.sonar.server.issue.TextRangeResponseFormatter;
  77. import org.sonar.server.issue.TransitionService;
  78. import org.sonar.server.issue.index.IssueIndex;
  79. import org.sonar.server.issue.index.IssueIndexSyncProgressChecker;
  80. import org.sonar.server.issue.index.IssueIndexer;
  81. import org.sonar.server.issue.index.IssueIteratorFactory;
  82. import org.sonar.server.issue.index.IssueQuery;
  83. import org.sonar.server.issue.index.IssueQueryFactory;
  84. import org.sonar.server.issue.workflow.FunctionExecutor;
  85. import org.sonar.server.issue.workflow.IssueWorkflow;
  86. import org.sonar.server.permission.index.PermissionIndexer;
  87. import org.sonar.server.permission.index.WebAuthorizationTypeSupport;
  88. import org.sonar.server.tester.UserSessionRule;
  89. import org.sonar.server.ws.MessageFormattingUtils;
  90. import org.sonar.server.ws.TestRequest;
  91. import org.sonar.server.ws.TestResponse;
  92. import org.sonar.server.ws.WsActionTester;
  93. import org.sonarqube.ws.Common;
  94. import org.sonarqube.ws.Common.Severity;
  95. import org.sonarqube.ws.Issues.Issue;
  96. import org.sonarqube.ws.Issues.SearchWsResponse;
  97. import static java.util.Arrays.asList;
  98. import static java.util.Collections.singletonList;
  99. import static org.apache.commons.lang.StringUtils.EMPTY;
  100. import static org.assertj.core.api.Assertions.assertThat;
  101. import static org.assertj.core.api.Assertions.assertThatThrownBy;
  102. import static org.assertj.core.groups.Tuple.tuple;
  103. import static org.sonar.api.issue.Issue.RESOLUTION_FALSE_POSITIVE;
  104. import static org.sonar.api.issue.Issue.RESOLUTION_FIXED;
  105. import static org.sonar.api.issue.Issue.RESOLUTION_REMOVED;
  106. import static org.sonar.api.issue.Issue.RESOLUTION_SAFE;
  107. import static org.sonar.api.issue.Issue.RESOLUTION_WONT_FIX;
  108. import static org.sonar.api.issue.Issue.STATUS_CLOSED;
  109. import static org.sonar.api.issue.Issue.STATUS_CONFIRMED;
  110. import static org.sonar.api.issue.Issue.STATUS_OPEN;
  111. import static org.sonar.api.issue.Issue.STATUS_REOPENED;
  112. import static org.sonar.api.issue.Issue.STATUS_RESOLVED;
  113. import static org.sonar.api.issue.Issue.STATUS_REVIEWED;
  114. import static org.sonar.api.resources.Qualifiers.UNIT_TEST_FILE;
  115. import static org.sonar.api.rules.RuleType.CODE_SMELL;
  116. import static org.sonar.api.server.ws.WebService.Param.FACETS;
  117. import static org.sonar.api.utils.DateUtils.formatDateTime;
  118. import static org.sonar.api.utils.DateUtils.parseDate;
  119. import static org.sonar.api.utils.DateUtils.parseDateTime;
  120. import static org.sonar.api.web.UserRole.ISSUE_ADMIN;
  121. import static org.sonar.db.component.ComponentTesting.newFileDto;
  122. import static org.sonar.db.issue.IssueTesting.newIssue;
  123. import static org.sonar.db.protobuf.DbIssues.MessageFormattingType.CODE;
  124. import static org.sonar.db.rule.RuleDescriptionSectionDto.createDefaultRuleDescriptionSection;
  125. import static org.sonar.db.rule.RuleTesting.XOO_X1;
  126. import static org.sonar.db.rule.RuleTesting.XOO_X2;
  127. import static org.sonar.db.rule.RuleTesting.newRule;
  128. import static org.sonar.server.issue.CommentAction.COMMENT_KEY;
  129. import static org.sonar.server.tester.UserSessionRule.standalone;
  130. import static org.sonarqube.ws.Common.RuleType.BUG;
  131. import static org.sonarqube.ws.Common.RuleType.SECURITY_HOTSPOT_VALUE;
  132. import static org.sonarqube.ws.Common.RuleType.VULNERABILITY;
  133. import static org.sonarqube.ws.client.component.ComponentsWsParameters.PARAM_BRANCH;
  134. import static org.sonarqube.ws.client.issue.IssuesWsParameters.ACTION_ASSIGN;
  135. import static org.sonarqube.ws.client.issue.IssuesWsParameters.ACTION_SET_TAGS;
  136. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_ADDITIONAL_FIELDS;
  137. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_ASSIGNEES;
  138. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_CLEAN_CODE_ATTRIBUTE_CATEGORIES;
  139. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_CODE_VARIANTS;
  140. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_COMPONENTS;
  141. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_CREATED_AFTER;
  142. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_HIDE_COMMENTS;
  143. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_IMPACT_SEVERITIES;
  144. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_IMPACT_SOFTWARE_QUALITIES;
  145. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_IN_NEW_CODE_PERIOD;
  146. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_ISSUE_STATUSES;
  147. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_PULL_REQUEST;
  148. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_RULES;
  149. import static org.sonarqube.ws.client.issue.IssuesWsParameters.PARAM_STATUSES;
  150. public class SearchActionIT {
  151. public static final DbIssues.MessageFormatting MESSAGE_FORMATTING = DbIssues.MessageFormatting.newBuilder()
  152. .setStart(0).setEnd(11).setType(CODE).build();
  153. private final UuidFactoryFast uuidFactory = UuidFactoryFast.getInstance();
  154. @Rule
  155. public UserSessionRule userSession = standalone();
  156. @Rule
  157. public DbTester db = DbTester.create();
  158. @Rule
  159. public EsTester es = EsTester.create();
  160. private final DbClient dbClient = db.getDbClient();
  161. private final DbSession session = db.getSession();
  162. private final IssueIndex issueIndex = new IssueIndex(es.client(), System2.INSTANCE, userSession, new WebAuthorizationTypeSupport(userSession));
  163. private final IssueIndexer issueIndexer = new IssueIndexer(es.client(), dbClient, new IssueIteratorFactory(dbClient), null);
  164. private final IssueQueryFactory issueQueryFactory = new IssueQueryFactory(dbClient, Clock.systemUTC(), userSession);
  165. private final IssueFieldsSetter issueFieldsSetter = new IssueFieldsSetter();
  166. private final IssueWorkflow issueWorkflow = new IssueWorkflow(new FunctionExecutor(issueFieldsSetter), issueFieldsSetter);
  167. private final SearchResponseLoader searchResponseLoader = new SearchResponseLoader(userSession, dbClient, new TransitionService(userSession, issueWorkflow));
  168. private final Languages languages = new Languages();
  169. private final UserResponseFormatter userFormatter = new UserResponseFormatter(new AvatarResolverImpl());
  170. private final SearchResponseFormat searchResponseFormat = new SearchResponseFormat(new Durations(), languages, new TextRangeResponseFormatter(), userFormatter);
  171. private final IssueIndexSyncProgressChecker issueIndexSyncProgressChecker = new IssueIndexSyncProgressChecker(dbClient);
  172. private final WsActionTester ws = new WsActionTester(
  173. new SearchAction(userSession, issueIndex, issueQueryFactory, issueIndexSyncProgressChecker, searchResponseLoader, searchResponseFormat, System2.INSTANCE, dbClient));
  174. private final PermissionIndexer permissionIndexer = new PermissionIndexer(dbClient, es.client(), issueIndexer);
  175. @Before
  176. public void setUp() {
  177. issueWorkflow.start();
  178. }
  179. @Test
  180. public void givenPrivateProject_responseContainsAllFieldsExceptAdditionalFields() {
  181. UserDto user = db.users().insertUser();
  182. userSession.logIn(user);
  183. ProjectData projectData = db.components().insertPrivateProject();
  184. ProjectDto projectDto = projectData.getProjectDto();
  185. db.users().insertProjectPermissionOnUser(user, UserRole.USER, projectDto);
  186. ComponentDto project = projectData.getMainBranchComponent();
  187. ComponentDto file = db.components().insertComponent(newFileDto(project));
  188. UserDto simon = db.users().insertUser();
  189. RuleDto rule = newIssueRule();
  190. IssueDto issue = db.issues().insertIssue(rule, project, file, i -> i
  191. .setEffort(10L)
  192. .setLine(42)
  193. .setChecksum("a227e508d6646b55a086ee11d63b21e9")
  194. .setMessage("the message")
  195. .setMessageFormattings(DbIssues.MessageFormattings.newBuilder().addMessageFormatting(MESSAGE_FORMATTING).build())
  196. .setStatus(STATUS_RESOLVED)
  197. .setResolution(RESOLUTION_FIXED)
  198. .setSeverity("MAJOR")
  199. .setAuthorLogin("John")
  200. .setAssigneeUuid(simon.getUuid())
  201. .setTags(asList("bug", "owasp"))
  202. .setIssueCreationDate(parseDate("2014-09-03"))
  203. .setIssueUpdateDate(parseDate("2017-12-04"))
  204. .setCodeVariants(List.of("variant1", "variant2")));
  205. indexPermissionsAndIssues();
  206. SearchWsResponse response = ws.newRequest()
  207. .executeProtobuf(SearchWsResponse.class);
  208. assertThat(response.getIssuesList())
  209. .extracting(
  210. Issue::getKey, Issue::getRule, Issue::getSeverity, Issue::getComponent, Issue::getResolution, Issue::getStatus, Issue::getMessage, Issue::getMessageFormattingsList,
  211. Issue::getEffort, Issue::getAssignee, Issue::getAuthor, Issue::getLine, Issue::getHash, Issue::getTagsList, Issue::getCreationDate, Issue::getUpdateDate,
  212. Issue::getQuickFixAvailable, Issue::getCodeVariantsList)
  213. .containsExactlyInAnyOrder(
  214. tuple(issue.getKey(), rule.getKey().toString(), Severity.MAJOR, file.getKey(), RESOLUTION_FIXED, STATUS_RESOLVED, "the message",
  215. MessageFormattingUtils.dbMessageFormattingListToWs(List.of(MESSAGE_FORMATTING)), "10min",
  216. simon.getLogin(), "John", 42, "a227e508d6646b55a086ee11d63b21e9", asList("bug", "owasp"), formatDateTime(issue.getIssueCreationDate()),
  217. formatDateTime(issue.getIssueUpdateDate()), false, List.of("variant1", "variant2")));
  218. }
  219. @Test
  220. public void response_contains_correct_actions() {
  221. UserDto user = db.users().insertUser();
  222. userSession.logIn(user);
  223. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  224. ComponentDto file = db.components().insertComponent(newFileDto(project));
  225. RuleDto rule = newIssueRule();
  226. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_OPEN));
  227. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_FIXED));
  228. indexPermissionsAndIssues();
  229. SearchWsResponse response = ws.newRequest()
  230. .setParam(PARAM_ADDITIONAL_FIELDS, "actions")
  231. .setParam(PARAM_STATUSES, STATUS_OPEN)
  232. .executeProtobuf(SearchWsResponse.class);
  233. assertThat(
  234. response
  235. .getIssuesList()
  236. .get(0)
  237. .getActions()
  238. .getActionsList())
  239. .isEqualTo(asList(ACTION_SET_TAGS, COMMENT_KEY, ACTION_ASSIGN));
  240. response = ws.newRequest()
  241. .setParam(PARAM_ADDITIONAL_FIELDS, "actions")
  242. .setParam(PARAM_STATUSES, STATUS_RESOLVED)
  243. .executeProtobuf(SearchWsResponse.class);
  244. assertThat(
  245. response
  246. .getIssuesList()
  247. .get(0)
  248. .getActions()
  249. .getActionsList())
  250. .isEqualTo(asList(ACTION_SET_TAGS, COMMENT_KEY));
  251. }
  252. @Test
  253. public void issue_on_external_rule() {
  254. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  255. ComponentDto file = db.components().insertComponent(newFileDto(project));
  256. RuleDto rule = db.rules().insertIssueRule(RuleTesting.EXTERNAL_XOO, r -> r.setIsExternal(true).setLanguage("xoo"));
  257. IssueDto issue = db.issues().insertIssue(rule, project, file);
  258. indexPermissionsAndIssues();
  259. SearchWsResponse response = ws.newRequest()
  260. .executeProtobuf(SearchWsResponse.class);
  261. assertThat(response.getIssuesList())
  262. .extracting(Issue::getKey, Issue::getRule, Issue::getExternalRuleEngine)
  263. .containsExactlyInAnyOrder(tuple(issue.getKey(), rule.getKey().toString(), "xoo"));
  264. }
  265. @Test
  266. public void issue_on_external_adhoc_rule_without_metadata() {
  267. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  268. indexPermissions();
  269. ComponentDto file = db.components().insertComponent(newFileDto(project));
  270. RuleDto rule = db.rules().insertIssueRule(RuleTesting.EXTERNAL_XOO, r -> r.setIsExternal(true)
  271. .setName("xoo:x1:name")
  272. .setAdHocName(null)
  273. .setLanguage("xoo")
  274. .setIsAdHoc(true));
  275. IssueDto issue = db.issues().insertIssue(rule, project, file);
  276. indexIssues();
  277. SearchWsResponse response = ws.newRequest()
  278. .setParam("additionalFields", "rules")
  279. .executeProtobuf(SearchWsResponse.class);
  280. assertThat(response.getIssuesList())
  281. .extracting(Issue::getKey, Issue::getRule, Issue::getExternalRuleEngine)
  282. .containsExactlyInAnyOrder(tuple(issue.getKey(), rule.getKey().toString(), "xoo"));
  283. assertThat((response.getRules().getRulesList()))
  284. .extracting(Common.Rule::getKey, Common.Rule::getName)
  285. .containsExactlyInAnyOrder(tuple(rule.getKey().toString(), rule.getName()));
  286. }
  287. @Test
  288. public void issue_on_external_adhoc_rule_with_metadata() {
  289. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  290. indexPermissions();
  291. ComponentDto file = db.components().insertComponent(newFileDto(project));
  292. RuleDto rule = db.rules().insertIssueRule(RuleTesting.EXTERNAL_XOO,
  293. r -> r
  294. .setIsExternal(true)
  295. .setLanguage("xoo")
  296. .setIsAdHoc(true)
  297. .setAdHocName("different_rule_name"));
  298. IssueDto issue = db.issues().insertIssue(rule, project, file);
  299. indexIssues();
  300. SearchWsResponse response = ws.newRequest()
  301. .setParam("additionalFields", "rules")
  302. .executeProtobuf(SearchWsResponse.class);
  303. assertThat(response.getIssuesList())
  304. .extracting(Issue::getKey, Issue::getRule, Issue::getExternalRuleEngine)
  305. .containsExactlyInAnyOrder(tuple(issue.getKey(), rule.getKey().toString(), "xoo"));
  306. assertThat(response.getRules().getRulesList())
  307. .extracting(Common.Rule::getKey, Common.Rule::getName)
  308. .containsExactlyInAnyOrder(tuple(rule.getKey().toString(), rule.getAdHocName()));
  309. }
  310. @Test
  311. public void issue_with_cross_file_locations() {
  312. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  313. indexPermissions();
  314. ComponentDto file = db.components().insertComponent(newFileDto(project));
  315. ComponentDto anotherFile = db.components().insertComponent(newFileDto(project));
  316. DbIssues.Locations.Builder locations = DbIssues.Locations.newBuilder().addFlow(DbIssues.Flow.newBuilder().addAllLocation(Arrays.asList(
  317. DbIssues.Location.newBuilder()
  318. .setComponentId(file.uuid())
  319. .setMsg("FLOW MESSAGE")
  320. .setTextRange(DbCommons.TextRange.newBuilder()
  321. .setStartLine(1)
  322. .setEndLine(1)
  323. .setStartOffset(0)
  324. .setEndOffset(12)
  325. .build())
  326. .build(),
  327. DbIssues.Location.newBuilder()
  328. .setComponentId(anotherFile.uuid())
  329. .setMsg("ANOTHER FLOW MESSAGE")
  330. .addMsgFormatting(DbIssues.MessageFormatting.newBuilder().setStart(0).setEnd(20).setType(CODE).build())
  331. .setTextRange(DbCommons.TextRange.newBuilder()
  332. .setStartLine(1)
  333. .setEndLine(1)
  334. .setStartOffset(0)
  335. .setEndOffset(12)
  336. .build())
  337. .build(),
  338. DbIssues.Location.newBuilder()
  339. // .setComponentId(no component id set)
  340. .setMsg("FLOW MESSAGE WITHOUT FILE UUID")
  341. .setTextRange(DbCommons.TextRange.newBuilder()
  342. .setStartLine(1)
  343. .setEndLine(1)
  344. .setStartOffset(0)
  345. .setEndOffset(12)
  346. .build())
  347. .build())));
  348. RuleDto rule = newIssueRule();
  349. db.issues().insertIssue(rule, project, file, i -> i.setLocations(locations.build()));
  350. indexIssues();
  351. SearchWsResponse result = ws.newRequest().executeProtobuf(SearchWsResponse.class);
  352. assertThat(result.getIssuesCount()).isOne();
  353. assertThat(result.getIssues(0).getFlows(0).getLocationsList()).extracting(Common.Location::getComponent, Common.Location::getMsg, Common.Location::getMsgFormattingsList)
  354. .containsExactlyInAnyOrder(
  355. tuple(file.getKey(), "FLOW MESSAGE", List.of()),
  356. tuple(anotherFile.getKey(), "ANOTHER FLOW MESSAGE", List.of(Common.MessageFormatting.newBuilder()
  357. .setStart(0).setEnd(20).setType(Common.MessageFormattingType.CODE).build())),
  358. tuple(file.getKey(), "FLOW MESSAGE WITHOUT FILE UUID", List.of()));
  359. }
  360. @Test
  361. public void issue_with_comments() {
  362. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John"));
  363. UserDto fabrice = db.users().insertUser(u -> u.setLogin("fabrice").setName("Fabrice").setEmail("fabrice@email.com"));
  364. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  365. indexPermissions();
  366. ComponentDto file = db.components().insertComponent(newFileDto(project));
  367. RuleDto rule = newIssueRule();
  368. IssueDto issue = db.issues().insertIssue(rule, project, file, i -> i.setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2"));
  369. dbClient.issueChangeDao().insert(session,
  370. new IssueChangeDto()
  371. .setUuid(Uuids.createFast())
  372. .setIssueKey(issue.getKey())
  373. .setKey("COMMENT-ABCD")
  374. .setChangeData("*My comment*")
  375. .setChangeType(IssueChangeDto.TYPE_COMMENT)
  376. .setUserUuid(john.getUuid())
  377. .setProjectUuid(project.branchUuid())
  378. .setIssueChangeCreationDate(parseDateTime("2014-09-09T12:00:00+0000").getTime()));
  379. dbClient.issueChangeDao().insert(session,
  380. new IssueChangeDto()
  381. .setUuid(Uuids.createFast())
  382. .setIssueKey(issue.getKey())
  383. .setKey("COMMENT-ABCE")
  384. .setChangeData("Another comment")
  385. .setChangeType(IssueChangeDto.TYPE_COMMENT)
  386. .setUserUuid(fabrice.getUuid())
  387. .setProjectUuid(project.branchUuid())
  388. .setIssueChangeCreationDate(parseDateTime("2014-09-10T12:00:00+0000").getTime()));
  389. dbClient.issueChangeDao().insert(session,
  390. new IssueChangeDto()
  391. .setUuid(Uuids.createFast())
  392. .setIssueKey(issue.getKey())
  393. .setKey("COMMENT-NO-USER")
  394. .setChangeData("Another comment without user")
  395. .setChangeType(IssueChangeDto.TYPE_COMMENT)
  396. .setProjectUuid(project.branchUuid())
  397. .setIssueChangeCreationDate(parseDateTime("2022-09-10T12:00:00+0000").getTime()));
  398. session.commit();
  399. indexIssues();
  400. userSession.logIn(john);
  401. ws.newRequest()
  402. .setParam("additionalFields", "comments,users")
  403. .execute()
  404. .assertJson(this.getClass(), "issue_with_comments.json");
  405. }
  406. @Test
  407. public void issue_with_comment_hidden() {
  408. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  409. UserDto fabrice = db.users().insertUser(u -> u.setLogin("fabrice").setName("Fabrice").setEmail("fabrice@email.com"));
  410. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  411. indexPermissions();
  412. ComponentDto file = db.components().insertComponent(newFileDto(project));
  413. RuleDto rule = newIssueRule();
  414. IssueDto issue = db.issues().insertIssue(rule, project, file, i -> i.setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2"));
  415. dbClient.issueChangeDao().insert(session,
  416. new IssueChangeDto()
  417. .setUuid(Uuids.createFast())
  418. .setIssueKey(issue.getKey())
  419. .setKey("COMMENT-ABCD")
  420. .setChangeData("*My comment*")
  421. .setChangeType(IssueChangeDto.TYPE_COMMENT)
  422. .setUserUuid(john.getUuid())
  423. .setProjectUuid(project.branchUuid())
  424. .setCreatedAt(parseDateTime("2014-09-09T12:00:00+0000").getTime()));
  425. dbClient.issueChangeDao().insert(session,
  426. new IssueChangeDto()
  427. .setUuid(Uuids.createFast())
  428. .setIssueKey(issue.getKey())
  429. .setKey("COMMENT-ABCE")
  430. .setChangeData("Another comment")
  431. .setChangeType(IssueChangeDto.TYPE_COMMENT)
  432. .setUserUuid(fabrice.getUuid())
  433. .setProjectUuid(project.branchUuid())
  434. .setCreatedAt(parseDateTime("2014-09-10T19:10:03+0000").getTime()));
  435. session.commit();
  436. indexIssues();
  437. userSession.logIn(john);
  438. SearchWsResponse response = ws.newRequest()
  439. .setParam(PARAM_HIDE_COMMENTS, "true")
  440. .executeProtobuf(SearchWsResponse.class);
  441. assertThat(response.getIssuesList())
  442. .extracting(Issue::getKey, i -> i.getComments().getCommentsList())
  443. .containsExactlyInAnyOrder(tuple(issue.getKey(), Collections.emptyList()));
  444. }
  445. @Test
  446. public void load_additional_fields() {
  447. UserDto simon = db.users().insertUser(u -> u.setLogin("simon").setName("Simon").setEmail("simon@email.com"));
  448. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  449. indexPermissions();
  450. ComponentDto file = db.components().insertComponent(newFileDto(project));
  451. RuleDto rule = newIssueRule();
  452. db.issues().insertIssue(rule, project, file, i -> i.setAssigneeUuid(simon.getUuid()).setType(CODE_SMELL));
  453. indexIssues();
  454. userSession.logIn("john");
  455. ws.newRequest()
  456. .setParam("additionalFields", "_all").execute()
  457. .assertJson(this.getClass(), "load_additional_fields.json");
  458. }
  459. @Test
  460. public void load_additional_fields_with_issue_admin_permission() {
  461. UserDto simon = db.users().insertUser(u -> u.setLogin("simon").setName("Simon").setEmail("simon@email.com"));
  462. UserDto fabrice = db.users().insertUser(u -> u.setLogin("fabrice").setName("Fabrice").setEmail("fabrice@email.com"));
  463. ProjectData project = db.components().insertPublicProject("PROJECT_ID",
  464. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java"));
  465. grantPermissionToAnyone(project.getProjectDto(), ISSUE_ADMIN);
  466. indexPermissions();
  467. ComponentDto file = db.components().insertComponent(newFileDto(project.getMainBranchComponent(), null, "FILE_ID").setKey("FILE_KEY").setLanguage("js"));
  468. IssueDto issue = newIssue(newIssueRule(), project.getMainBranchComponent(), file)
  469. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  470. .setAuthorLogin(fabrice.getLogin())
  471. .setAssigneeUuid(simon.getUuid());
  472. dbClient.issueDao().insert(session, issue);
  473. session.commit();
  474. indexIssues();
  475. userSession.logIn("john")
  476. .addProjectPermission(ISSUE_ADMIN, project.getMainBranchComponent()); // granted by Anyone
  477. ws.newRequest()
  478. .setParam("additionalFields", "_all").execute()
  479. .assertJson(this.getClass(), "load_additional_fields_with_issue_admin_permission.json");
  480. }
  481. @Test
  482. public void search_by_rule_key() {
  483. RuleDto rule = newIssueRule();
  484. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  485. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  486. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  487. db.issues().insertIssue(rule, project, file);
  488. session.commit();
  489. indexIssues();
  490. userSession.logIn("john")
  491. .addProjectPermission(ISSUE_ADMIN, project); // granted by Anyone
  492. indexPermissions();
  493. TestResponse execute = ws.newRequest()
  494. .setParam(PARAM_RULES, rule.getKey().toString())
  495. .setParam("additionalFields", "_all")
  496. .execute();
  497. execute.assertJson(this.getClass(), "result_for_rule_search.json");
  498. }
  499. @Test
  500. public void search_adhoc_issue_by_rule_key_returns_correct_rule_name() {
  501. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  502. ComponentDto file = db.components().insertComponent(newFileDto(project));
  503. RuleDto rule = db.rules().insertIssueRule(RuleTesting.EXTERNAL_XOO, r -> r.setIsExternal(true)
  504. .setIsAdHoc(true)
  505. .setLanguage("xoo")
  506. .setName(RuleTesting.EXTERNAL_XOO.toString())
  507. .setAdHocName("adHocRuleName"));
  508. db.issues().insertIssue(rule, project, file);
  509. indexPermissionsAndIssues();
  510. SearchWsResponse response = ws.newRequest()
  511. .setParam(PARAM_RULES, rule.getKey().toString())
  512. .setParam("additionalFields", "_all")
  513. .executeProtobuf(SearchWsResponse.class);
  514. assertThat(response.getRules().getRulesList())
  515. .extracting(Common.Rule::getKey, Common.Rule::getName)
  516. .containsExactlyInAnyOrder(tuple(rule.getKey().toString(), rule.getAdHocName()));
  517. }
  518. @Test
  519. public void search_by_non_existing_rule_key() {
  520. RuleDto rule = newIssueRule();
  521. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  522. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  523. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  524. db.issues().insertIssue(rule, project, file);
  525. session.commit();
  526. indexIssues();
  527. userSession.logIn("john")
  528. .addProjectPermission(ISSUE_ADMIN, project); // granted by Anyone
  529. indexPermissions();
  530. TestResponse execute = ws.newRequest()
  531. .setParam(PARAM_RULES, "nonexisting:rulekey")
  532. .setParam("additionalFields", "_all")
  533. .execute();
  534. execute.assertJson(this.getClass(), "no_issue.json");
  535. }
  536. @Test
  537. public void search_by_variants_with_facets() {
  538. RuleDto rule = newIssueRule();
  539. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  540. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  541. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  542. db.issues().insertIssue(rule, project, file, i -> i.setCodeVariants(List.of("variant1")));
  543. db.issues().insertIssue(rule, project, file, i -> i.setCodeVariants(List.of("variant2")));
  544. db.issues().insertIssue(rule, project, file, i -> i.setCodeVariants(List.of("variant1", "variant2")));
  545. db.issues().insertIssue(rule, project, file, i -> i.setCodeVariants(List.of("variant2", "variant3")));
  546. indexPermissionsAndIssues();
  547. ws.newRequest()
  548. .setParam(PARAM_CODE_VARIANTS, "variant2,variant3")
  549. .setParam(FACETS, PARAM_CODE_VARIANTS)
  550. .execute()
  551. .assertJson(this.getClass(), "search_by_variants_with_facets.json");
  552. }
  553. @Test
  554. public void search_whenFilteringByIssueStatuses_shouldReturnIssueStatusesFacet() {
  555. RuleDto rule = newIssueRule();
  556. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  557. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  558. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  559. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_OPEN));
  560. IssueDto expectedIssue = db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_WONT_FIX));
  561. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_FALSE_POSITIVE));
  562. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_FIXED));
  563. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_CLOSED).setResolution(RESOLUTION_WONT_FIX));
  564. // security hotspot should be ignored
  565. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_REVIEWED).setResolution(RESOLUTION_SAFE));
  566. indexPermissionsAndIssues();
  567. SearchWsResponse response = ws.newRequest()
  568. .setParam(PARAM_ISSUE_STATUSES, IssueStatus.ACCEPTED.name())
  569. .setParam(FACETS, PARAM_ISSUE_STATUSES)
  570. .executeProtobuf(SearchWsResponse.class);
  571. List<Issue> issuesList = response.getIssuesList();
  572. assertThat(issuesList)
  573. .extracting(Issue::getKey)
  574. .containsExactlyInAnyOrder(expectedIssue.getKey());
  575. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  576. .stream().filter(facet -> facet.getProperty().equals(PARAM_ISSUE_STATUSES))
  577. .findFirst();
  578. assertThat(first.get().getValuesList())
  579. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  580. .containsExactlyInAnyOrder(
  581. tuple(IssueStatus.OPEN.name(), 1L),
  582. tuple(IssueStatus.ACCEPTED.name(), 1L),
  583. tuple(IssueStatus.FIXED.name(), 2L),
  584. tuple(IssueStatus.FALSE_POSITIVE.name(), 1L));
  585. }
  586. @Test
  587. public void search_whenIssueStatusesFacetRequested_shouldReturnFacet() {
  588. RuleDto rule = newIssueRule();
  589. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  590. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  591. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  592. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_OPEN));
  593. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_REOPENED));
  594. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_CONFIRMED));
  595. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_WONT_FIX));
  596. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_FALSE_POSITIVE));
  597. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_RESOLVED).setResolution(RESOLUTION_FIXED));
  598. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_CLOSED).setResolution(RESOLUTION_REMOVED));
  599. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_CLOSED).setResolution(RESOLUTION_FIXED));
  600. // security hotspot should be ignored
  601. db.issues().insertIssue(rule, project, file, i -> i.setStatus(STATUS_REVIEWED).setResolution(RESOLUTION_SAFE));
  602. indexPermissionsAndIssues();
  603. SearchWsResponse response = ws.newRequest()
  604. .setParam(FACETS, PARAM_ISSUE_STATUSES)
  605. .executeProtobuf(SearchWsResponse.class);
  606. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  607. .stream().filter(facet -> facet.getProperty().equals(PARAM_ISSUE_STATUSES))
  608. .findFirst();
  609. assertThat(first.get().getValuesList())
  610. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  611. .containsExactlyInAnyOrder(
  612. tuple(IssueStatus.OPEN.name(), 2L),
  613. tuple(IssueStatus.ACCEPTED.name(), 1L),
  614. tuple(IssueStatus.CONFIRMED.name(), 1L),
  615. tuple(IssueStatus.FIXED.name(), 3L),
  616. tuple(IssueStatus.FALSE_POSITIVE.name(), 1L));
  617. }
  618. @Test
  619. public void search_whenImpactSoftwareQualitiesFacetRequested_shouldReturnFacet() {
  620. RuleDto rule = newIssueRule();
  621. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  622. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  623. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  624. IssueDto issue1 = db.issues().insertIssue(rule, project, file, i -> i
  625. .addImpact(new ImpactDto(uuidFactory.create(), SoftwareQuality.SECURITY, org.sonar.api.issue.impact.Severity.HIGH))
  626. .addImpact(new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.HIGH)));
  627. IssueDto issue2 = db.issues().insertIssue(rule, project, file, i -> i
  628. .addImpact(new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.HIGH)));
  629. IssueDto issue3 = db.issues().insertIssue(rule, project, file, i -> i
  630. .addImpact(new ImpactDto(uuidFactory.create(), SoftwareQuality.SECURITY, org.sonar.api.issue.impact.Severity.MEDIUM))
  631. .addImpact(new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.LOW)));
  632. indexPermissionsAndIssues();
  633. SearchWsResponse response = ws.newRequest()
  634. .setParam(FACETS, PARAM_IMPACT_SOFTWARE_QUALITIES)
  635. .executeProtobuf(SearchWsResponse.class);
  636. assertThat(response.getIssuesList())
  637. .extracting(Issue::getKey)
  638. .containsExactlyInAnyOrder(issue1.getKey(), issue2.getKey(), issue3.getKey());
  639. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  640. .stream().filter(facet -> facet.getProperty().equals(PARAM_IMPACT_SOFTWARE_QUALITIES))
  641. .findFirst();
  642. assertThat(first.get().getValuesList())
  643. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  644. .containsExactlyInAnyOrder(
  645. tuple("MAINTAINABILITY", 3L),
  646. tuple("RELIABILITY", 3L),
  647. tuple("SECURITY", 2L));
  648. }
  649. @Test
  650. public void search_whenFilteredByImpactSeverities_shouldReturnImpactSoftwareQualitiesFacet() {
  651. RuleDto rule = newIssueRule();
  652. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  653. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  654. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  655. IssueDto issue1 = db.issues().insertIssue(rule, project, file, i -> i
  656. .addImpact(new ImpactDto().setSoftwareQuality(SoftwareQuality.SECURITY).setSeverity(org.sonar.api.issue.impact.Severity.HIGH).setUuid(uuidFactory.create()))
  657. .addImpact(new ImpactDto().setSoftwareQuality(SoftwareQuality.RELIABILITY).setSeverity(org.sonar.api.issue.impact.Severity.HIGH).setUuid(uuidFactory.create())));
  658. IssueDto issue2 = db.issues().insertIssue(rule, project, file, i -> i
  659. .addImpact(new ImpactDto().setSoftwareQuality(SoftwareQuality.RELIABILITY).setSeverity(org.sonar.api.issue.impact.Severity.HIGH).setUuid(uuidFactory.create())));
  660. IssueDto issue3 = db.issues().insertIssue(rule, project, file, i -> i
  661. .addImpact(new ImpactDto().setSoftwareQuality(SoftwareQuality.SECURITY).setSeverity(org.sonar.api.issue.impact.Severity.MEDIUM).setUuid(uuidFactory.create()))
  662. .addImpact(new ImpactDto().setSoftwareQuality(SoftwareQuality.RELIABILITY).setSeverity(org.sonar.api.issue.impact.Severity.LOW).setUuid(uuidFactory.create())));
  663. indexPermissionsAndIssues();
  664. Map<Common.SoftwareQuality, Common.ImpactSeverity> expectedImpacts = Map.of(Common.SoftwareQuality.SECURITY, Common.ImpactSeverity.MEDIUM,
  665. Common.SoftwareQuality.RELIABILITY, Common.ImpactSeverity.LOW,
  666. Common.SoftwareQuality.MAINTAINABILITY, Common.ImpactSeverity.HIGH);
  667. SearchWsResponse response = ws.newRequest()
  668. .setParam(PARAM_IMPACT_SEVERITIES, org.sonar.api.issue.impact.Severity.LOW.name())
  669. .setParam(FACETS, PARAM_IMPACT_SOFTWARE_QUALITIES)
  670. .executeProtobuf(SearchWsResponse.class);
  671. List<Issue> issuesList = response.getIssuesList();
  672. assertThat(issuesList)
  673. .extracting(Issue::getKey)
  674. .containsExactlyInAnyOrder(issue3.getKey());
  675. Issue issue = issuesList.get(0);
  676. Map<Common.SoftwareQuality, Common.ImpactSeverity> impactsInResponse = issue.getImpactsList()
  677. .stream()
  678. .collect(Collectors.toMap(Common.Impact::getSoftwareQuality, Common.Impact::getSeverity));
  679. assertThat(impactsInResponse).isEqualTo(expectedImpacts);
  680. assertThat(issue.getCleanCodeAttribute()).isEqualTo(Common.CleanCodeAttribute.CLEAR);
  681. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  682. .stream().filter(facet -> facet.getProperty().equals(PARAM_IMPACT_SOFTWARE_QUALITIES))
  683. .findFirst();
  684. assertThat(first.get().getValuesList())
  685. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  686. .containsExactlyInAnyOrder(
  687. tuple("MAINTAINABILITY", 0L),
  688. tuple("RELIABILITY", 1L),
  689. tuple("SECURITY", 0L));
  690. }
  691. @Test
  692. public void search_whenImpactSeveritiesFacetRequested_shouldReturnFacet() {
  693. RuleDto rule = newIssueRule();
  694. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  695. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  696. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  697. IssueDto issue1 = db.issues().insertIssue(rule, project, file, i -> i.replaceAllImpacts(List.of(
  698. new ImpactDto(uuidFactory.create(), SoftwareQuality.SECURITY, org.sonar.api.issue.impact.Severity.HIGH),
  699. new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.HIGH))));
  700. IssueDto issue2 = db.issues().insertIssue(rule, project, file, i -> i.replaceAllImpacts(List.of(
  701. new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.HIGH))));
  702. IssueDto issue3 = db.issues().insertIssue(rule, project, file, i -> i.replaceAllImpacts(List.of(
  703. new ImpactDto(uuidFactory.create(), SoftwareQuality.MAINTAINABILITY, org.sonar.api.issue.impact.Severity.LOW),
  704. new ImpactDto(uuidFactory.create(), SoftwareQuality.SECURITY, org.sonar.api.issue.impact.Severity.MEDIUM),
  705. new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.LOW))));
  706. indexPermissionsAndIssues();
  707. SearchWsResponse response = ws.newRequest()
  708. .setParam(FACETS, PARAM_IMPACT_SEVERITIES)
  709. .executeProtobuf(SearchWsResponse.class);
  710. assertThat(response.getIssuesList())
  711. .extracting(Issue::getKey)
  712. .containsExactlyInAnyOrder(issue1.getKey(), issue2.getKey(), issue3.getKey());
  713. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  714. .stream().filter(facet -> facet.getProperty().equals(PARAM_IMPACT_SEVERITIES))
  715. .findFirst();
  716. assertThat(first.get().getValuesList())
  717. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  718. .containsExactlyInAnyOrder(
  719. tuple("HIGH", 2L),
  720. tuple("MEDIUM", 1L),
  721. tuple("LOW", 1L));
  722. }
  723. @Test
  724. public void search_whenFilteredByImpactSoftwareQualities_shouldReturnFacet() {
  725. RuleDto rule = newIssueRule();
  726. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  727. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  728. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  729. IssueDto issue1 = db.issues().insertIssue(rule, project, file, i -> i.replaceAllImpacts(List.of(
  730. new ImpactDto(uuidFactory.create(), SoftwareQuality.SECURITY, org.sonar.api.issue.impact.Severity.HIGH),
  731. new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.HIGH))));
  732. db.issues().insertIssue(rule, project, file, i -> i.replaceAllImpacts(List.of(
  733. new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.HIGH))));
  734. IssueDto issue3 = db.issues().insertIssue(rule, project, file, i -> i.replaceAllImpacts(List.of(
  735. new ImpactDto(uuidFactory.create(), SoftwareQuality.MAINTAINABILITY, org.sonar.api.issue.impact.Severity.LOW),
  736. new ImpactDto(uuidFactory.create(), SoftwareQuality.SECURITY, org.sonar.api.issue.impact.Severity.MEDIUM),
  737. new ImpactDto(uuidFactory.create(), SoftwareQuality.RELIABILITY, org.sonar.api.issue.impact.Severity.LOW))));
  738. indexPermissionsAndIssues();
  739. SearchWsResponse response = ws.newRequest()
  740. .setParam(PARAM_IMPACT_SOFTWARE_QUALITIES, SoftwareQuality.SECURITY.name())
  741. .setParam(FACETS, PARAM_IMPACT_SEVERITIES)
  742. .executeProtobuf(SearchWsResponse.class);
  743. assertThat(response.getIssuesList())
  744. .extracting(Issue::getKey)
  745. .containsExactlyInAnyOrder(issue1.getKey(), issue3.getKey());
  746. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  747. .stream().filter(facet -> facet.getProperty().equals(PARAM_IMPACT_SEVERITIES))
  748. .findFirst();
  749. assertThat(first.get().getValuesList())
  750. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  751. .containsExactlyInAnyOrder(
  752. tuple("HIGH", 1L),
  753. tuple("MEDIUM", 1L),
  754. tuple("LOW", 0L));
  755. }
  756. @Test
  757. public void search_whenFilteredByCleanCodeAttributeCategory_shouldReturnFacet() {
  758. // INTENTIONAL
  759. RuleDto rule1 = newIssueRule("clear-rule", ruleDto -> ruleDto.setCleanCodeAttribute(CleanCodeAttribute.CLEAR));
  760. RuleDto rule2 = newIssueRule("complete-rule", ruleDto -> ruleDto.setCleanCodeAttribute(CleanCodeAttribute.COMPLETE));
  761. // ADAPTABLE
  762. RuleDto rule3 = newIssueRule("distinct-rule", ruleDto -> ruleDto.setCleanCodeAttribute(CleanCodeAttribute.DISTINCT));
  763. // RESPONSIBLE
  764. RuleDto rule4 = newIssueRule("lawful-rule", ruleDto -> ruleDto.setCleanCodeAttribute(CleanCodeAttribute.LAWFUL));
  765. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  766. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID").setLanguage("java")).getMainBranchComponent();
  767. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY").setLanguage("java"));
  768. IssueDto issue1 = db.issues().insertIssue(rule1, project, file);
  769. IssueDto issue2 = db.issues().insertIssue(rule2, project, file);
  770. IssueDto issue3 = db.issues().insertIssue(rule3, project, file);
  771. IssueDto issue4 = db.issues().insertIssue(rule4, project, file);
  772. IssueDto issue5 = db.issues().insertIssue(rule1, project, file);
  773. indexPermissionsAndIssues();
  774. SearchWsResponse response = ws.newRequest()
  775. .setParam(PARAM_CLEAN_CODE_ATTRIBUTE_CATEGORIES, CleanCodeAttributeCategory.INTENTIONAL.name())
  776. .setParam(FACETS, PARAM_CLEAN_CODE_ATTRIBUTE_CATEGORIES)
  777. .executeProtobuf(SearchWsResponse.class);
  778. assertThat(response.getIssuesList())
  779. .extracting(Issue::getKey)
  780. .containsExactlyInAnyOrder(issue1.getKey(), issue2.getKey(), issue5.getKey());
  781. Optional<Common.Facet> first = response.getFacets().getFacetsList()
  782. .stream().filter(facet -> facet.getProperty().equals(PARAM_CLEAN_CODE_ATTRIBUTE_CATEGORIES))
  783. .findFirst();
  784. assertThat(first.get().getValuesList())
  785. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  786. .containsExactlyInAnyOrder(
  787. tuple("INTENTIONAL", 3L),
  788. tuple("ADAPTABLE", 1L),
  789. tuple("RESPONSIBLE", 1L),
  790. tuple("CONSISTENT", 0L));
  791. }
  792. @Test
  793. public void issue_on_removed_file() {
  794. RuleDto rule = newIssueRule();
  795. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY").setKey("PROJECT_KEY")).getMainBranchComponent();
  796. indexPermissions();
  797. ComponentDto removedFile = db.components().insertComponent(newFileDto(project).setUuid("REMOVED_FILE_ID")
  798. .setKey("REMOVED_FILE_KEY")
  799. .setEnabled(false));
  800. IssueDto issue = newIssue(rule, project, removedFile)
  801. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  802. .setComponent(removedFile)
  803. .setStatus("OPEN").setResolution("OPEN")
  804. .setSeverity("MAJOR")
  805. .setIssueCreationDate(parseDateTime("2014-09-04T00:00:00+0100"))
  806. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"));
  807. dbClient.issueDao().insert(session, issue);
  808. session.commit();
  809. indexIssues();
  810. ws.newRequest()
  811. .execute()
  812. .assertJson(this.getClass(), "issue_on_removed_file.json");
  813. }
  814. @Test
  815. public void apply_paging_with_one_component() {
  816. RuleDto rule = newIssueRule();
  817. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY").setKey("PROJECT_KEY")).getMainBranchComponent();
  818. indexPermissions();
  819. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  820. for (int i = 0; i < SearchOptions.MAX_PAGE_SIZE + 1; i++) {
  821. IssueDto issue = newIssue(rule, project, file).setAssigneeUuid(null).setChecksum(null);
  822. dbClient.issueDao().insert(session, issue);
  823. }
  824. session.commit();
  825. indexIssues();
  826. ws.newRequest().setParam(PARAM_COMPONENTS, file.getKey()).execute()
  827. .assertJson(this.getClass(), "apply_paging_with_one_component.json");
  828. }
  829. @Test
  830. public void filter_by_assigned_to_me() {
  831. UserDto alice = db.users().insertUser(u -> u.setLogin("alice").setName("Alice").setEmail("alice@email.com"));
  832. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  833. ComponentDto project = db.components().insertPublicProject(c -> c.setUuid("PROJECT_ID").setKey("PROJECT_KEY").setBranchUuid("PROJECT_ID")).getMainBranchComponent();
  834. indexPermissions();
  835. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  836. RuleDto rule = newIssueRule();
  837. IssueDto issue1 = newIssue(rule, project, file)
  838. .setIssueCreationDate(parseDate("2014-09-04"))
  839. .setIssueUpdateDate(parseDate("2017-12-04"))
  840. .setEffort(10L)
  841. .setStatus("OPEN")
  842. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  843. .setSeverity("MAJOR")
  844. .setAssigneeUuid(john.getUuid());
  845. IssueDto issue2 = newIssue(rule, project, file)
  846. .setIssueCreationDate(parseDate("2014-09-04"))
  847. .setIssueUpdateDate(parseDate("2017-12-04"))
  848. .setEffort(10L)
  849. .setStatus("OPEN")
  850. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  851. .setSeverity("MAJOR")
  852. .setAssigneeUuid(alice.getUuid());
  853. IssueDto issue3 = newIssue(rule, project, file)
  854. .setIssueCreationDate(parseDate("2014-09-04"))
  855. .setIssueUpdateDate(parseDate("2017-12-04"))
  856. .setEffort(10L)
  857. .setStatus("OPEN")
  858. .setKee("82fd47d4-4037-b650-80bc-7b112bd4eac2")
  859. .setSeverity("MAJOR")
  860. .setAssigneeUuid(null);
  861. dbClient.issueDao().insert(session, issue1, issue2, issue3);
  862. session.commit();
  863. indexIssues();
  864. userSession.logIn(john);
  865. ws.newRequest()
  866. .setParam("resolved", "false")
  867. .setParam("assignees", "__me__")
  868. .setParam(FACETS, "assignees,assigned_to_me")
  869. .execute()
  870. .assertJson(this.getClass(), "filter_by_assigned_to_me.json");
  871. }
  872. @Test
  873. public void filter_by_new_code_period() {
  874. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  875. UserDto alice = db.users().insertUser(u -> u.setLogin("alice").setName("Alice").setEmail("alice@email.com"));
  876. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  877. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID")).getMainBranchComponent();
  878. SnapshotDto snapshotDto = db.components().insertSnapshot(project, s -> s.setLast(true).setPeriodDate(parseDateTime("2014-09-05T00:00:00+0100").getTime()));
  879. indexPermissions();
  880. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  881. RuleDto rule = newIssueRule();
  882. IssueDto issue1 = newIssue(rule, project, file)
  883. .setIssueCreationDate(parseDateTime("2014-09-04T00:00:00+0100"))
  884. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"))
  885. .setEffort(10L)
  886. .setStatus("OPEN")
  887. .setMessage(null)
  888. .setTags(null)
  889. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  890. .setSeverity("MAJOR")
  891. .setChecksum(null)
  892. .setAssigneeUuid(john.getUuid());
  893. IssueDto issue2 = newIssue(rule, project, file)
  894. .setIssueCreationDate(parseDateTime("2014-09-06T00:00:00+0100"))
  895. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"))
  896. .setEffort(10L)
  897. .setStatus("OPEN")
  898. .setMessage(null)
  899. .setTags(null)
  900. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  901. .setSeverity("MAJOR")
  902. .setChecksum(null)
  903. .setAssigneeUuid(alice.getUuid());
  904. dbClient.issueDao().insert(session, issue1, issue2);
  905. session.commit();
  906. indexIssues();
  907. userSession.logIn(john);
  908. ws.newRequest()
  909. .setParam(PARAM_IN_NEW_CODE_PERIOD, "true")
  910. .setParam(PARAM_COMPONENTS, "PROJECT_KEY")
  911. .execute()
  912. .assertJson(this.getClass(), "filter_by_leak_period.json");
  913. }
  914. @Test
  915. public void explicit_false_value_for_new_code_period_parameters_has_no_effect() {
  916. ws.newRequest()
  917. .setParam(PARAM_IN_NEW_CODE_PERIOD, "false")
  918. .execute()
  919. .assertJson(this.getClass(), "default_page_size_is_100.json");
  920. }
  921. @Test
  922. public void filter_by_leak_period_without_a_period() {
  923. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  924. UserDto alice = db.users().insertUser(u -> u.setLogin("alice").setName("Alice").setEmail("alice@email.com"));
  925. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY")).getMainBranchComponent();
  926. SnapshotDto snapshotDto = db.components().insertSnapshot(project);
  927. indexPermissions();
  928. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  929. RuleDto rule = newIssueRule();
  930. IssueDto issue1 = newIssue(rule, project, file)
  931. .setIssueCreationDate(parseDateTime("2014-09-04T00:00:00+0100"))
  932. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"))
  933. .setEffort(10L)
  934. .setStatus("OPEN")
  935. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  936. .setSeverity("MAJOR")
  937. .setChecksum(null)
  938. .setAssigneeUuid(john.getUuid());
  939. IssueDto issue2 = newIssue(rule, project, file)
  940. .setIssueCreationDate(parseDateTime("2014-09-04T00:00:00+0100"))
  941. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"))
  942. .setEffort(10L)
  943. .setStatus("OPEN")
  944. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  945. .setSeverity("MAJOR")
  946. .setChecksum(null)
  947. .setAssigneeUuid(alice.getUuid());
  948. dbClient.issueDao().insert(session, issue1, issue2);
  949. session.commit();
  950. indexIssues();
  951. userSession.logIn(john);
  952. ws.newRequest()
  953. .setParam(PARAM_COMPONENTS, "PROJECT_KEY")
  954. .setParam(PARAM_IN_NEW_CODE_PERIOD, "true")
  955. .execute()
  956. .assertJson(this.getClass(), "empty_result.json");
  957. }
  958. @Test
  959. public void filter_by_leak_period_has_no_effect_on_prs() {
  960. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  961. UserDto alice = db.users().insertUser(u -> u.setLogin("alice").setName("Alice").setEmail("alice@email.com"));
  962. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY")).getMainBranchComponent();
  963. ComponentDto pr = db.components().insertProjectBranch(project, b -> b.setBranchType(BranchType.PULL_REQUEST).setKey("pr"));
  964. SnapshotDto snapshotDto = db.components().insertSnapshot(pr);
  965. indexPermissions();
  966. ComponentDto file = db.components().insertComponent(newFileDto(pr, null, "FILE_ID", project.uuid()).setKey("FILE_KEY"));
  967. RuleDto rule = newIssueRule();
  968. IssueDto issue1 = newIssue(rule, pr, file)
  969. .setIssueCreationDate(parseDateTime("2014-09-04T00:00:00+0100"))
  970. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"))
  971. .setEffort(10L)
  972. .setTags(null)
  973. .setMessage(null)
  974. .setStatus("OPEN")
  975. .setAuthorLogin("john")
  976. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  977. .setSeverity("MAJOR")
  978. .setAssigneeUuid(john.getUuid());
  979. IssueDto issue2 = newIssue(rule, pr, file)
  980. .setIssueCreationDate(parseDateTime("2014-09-04T00:00:00+0100"))
  981. .setIssueUpdateDate(parseDateTime("2017-12-04T00:00:00+0100"))
  982. .setEffort(10L)
  983. .setTags(null)
  984. .setMessage(null)
  985. .setStatus("OPEN")
  986. .setAuthorLogin("john")
  987. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  988. .setSeverity("MAJOR")
  989. .setAssigneeUuid(alice.getUuid());
  990. dbClient.issueDao().insert(session, issue1, issue2);
  991. session.commit();
  992. indexIssues();
  993. userSession.logIn(john);
  994. ws.newRequest()
  995. .setParam(PARAM_COMPONENTS, "PROJECT_KEY")
  996. .setParam(PARAM_PULL_REQUEST, "pr")
  997. .setParam(PARAM_IN_NEW_CODE_PERIOD, "true")
  998. .execute()
  999. .assertJson(this.getClass(), "filter_by_leak_period_has_no_effect_on_prs.json");
  1000. }
  1001. @Test
  1002. public void return_empty_when_login_is_unknown() {
  1003. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  1004. UserDto alice = db.users().insertUser(u -> u.setLogin("alice").setName("Alice").setEmail("alice@email.com"));
  1005. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY")).getMainBranchComponent();
  1006. indexPermissions();
  1007. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1008. RuleDto rule = newIssueRule();
  1009. IssueDto issue1 = newIssue(rule, project, file)
  1010. .setIssueCreationDate(parseDate("2014-09-04"))
  1011. .setIssueUpdateDate(parseDate("2017-12-04"))
  1012. .setEffort(10L)
  1013. .setStatus("OPEN")
  1014. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  1015. .setSeverity("MAJOR")
  1016. .setAssigneeUuid(john.getUuid());
  1017. IssueDto issue2 = newIssue(rule, project, file)
  1018. .setIssueCreationDate(parseDate("2014-09-04"))
  1019. .setIssueUpdateDate(parseDate("2017-12-04"))
  1020. .setEffort(10L)
  1021. .setStatus("OPEN")
  1022. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  1023. .setSeverity("MAJOR")
  1024. .setAssigneeUuid(alice.getUuid());
  1025. IssueDto issue3 = newIssue(rule, project, file)
  1026. .setIssueCreationDate(parseDate("2014-09-04"))
  1027. .setIssueUpdateDate(parseDate("2017-12-04"))
  1028. .setEffort(10L)
  1029. .setStatus("OPEN")
  1030. .setKee("82fd47d4-4037-b650-80bc-7b112bd4eac2")
  1031. .setSeverity("MAJOR")
  1032. .setAssigneeUuid(null);
  1033. dbClient.issueDao().insert(session, issue1, issue2, issue3);
  1034. session.commit();
  1035. indexIssues();
  1036. userSession.logIn(john);
  1037. SearchWsResponse response = ws.newRequest()
  1038. .setParam("resolved", "false")
  1039. .setParam("assignees", "unknown")
  1040. .setParam(FACETS, "assignees")
  1041. .executeProtobuf(SearchWsResponse.class);
  1042. assertThat(response.getIssuesList()).isEmpty();
  1043. }
  1044. @Test
  1045. public void filter_by_assigned_to_me_when_not_authenticate() {
  1046. UserDto alice = db.users().insertUser(u -> u.setLogin("alice").setName("Alice").setEmail("alice@email.com"));
  1047. UserDto john = db.users().insertUser(u -> u.setLogin("john").setName("John").setEmail("john@email.com"));
  1048. UserDto poy = db.users().insertUser(u -> u.setLogin("poy").setName("poypoy").setEmail("poypoy@email.com"));
  1049. userSession.logIn(poy);
  1050. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY")).getMainBranchComponent();
  1051. indexPermissions();
  1052. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1053. RuleDto rule = newIssueRule();
  1054. IssueDto issue1 = newIssue(rule, project, file)
  1055. .setStatus("OPEN")
  1056. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  1057. .setAssigneeUuid(john.getUuid());
  1058. IssueDto issue2 = newIssue(rule, project, file)
  1059. .setStatus("OPEN")
  1060. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  1061. .setAssigneeUuid(alice.getUuid());
  1062. IssueDto issue3 = newIssue(rule, project, file)
  1063. .setStatus("OPEN")
  1064. .setKee("82fd47d4-4037-b650-80bc-7b112bd4eac2")
  1065. .setAssigneeUuid(null);
  1066. dbClient.issueDao().insert(session, issue1, issue2, issue3);
  1067. session.commit();
  1068. indexIssues();
  1069. ws.newRequest()
  1070. .setParam("resolved", "false")
  1071. .setParam("assignees", "__me__")
  1072. .execute()
  1073. .assertJson(this.getClass(), "empty_result.json");
  1074. }
  1075. @Test
  1076. public void search_by_author() {
  1077. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1078. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1079. RuleDto rule = db.rules().insertIssueRule();
  1080. IssueDto issue1 = db.issues().insertIssue(rule, project, file, i -> i.setAuthorLogin("leia"));
  1081. IssueDto issue2 = db.issues().insertIssue(rule, project, file, i -> i.setAuthorLogin("luke"));
  1082. IssueDto issue3 = db.issues().insertIssue(rule, project, file, i -> i.setAuthorLogin("han, solo"));
  1083. indexPermissionsAndIssues();
  1084. SearchWsResponse response = ws.newRequest()
  1085. .setMultiParam("author", asList("leia", "han, solo"))
  1086. .setParam(FACETS, "author")
  1087. .executeProtobuf(SearchWsResponse.class);
  1088. assertThat(response.getIssuesList())
  1089. .extracting(Issue::getKey)
  1090. .containsExactlyInAnyOrder(issue1.getKey(), issue3.getKey());
  1091. Common.Facet facet = response.getFacets().getFacetsList().get(0);
  1092. assertThat(facet.getProperty()).isEqualTo("author");
  1093. assertThat(facet.getValuesList())
  1094. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  1095. .containsExactlyInAnyOrder(
  1096. tuple("leia", 1L),
  1097. tuple("luke", 1L),
  1098. tuple("han, solo", 1L));
  1099. assertThat(ws.newRequest()
  1100. .setMultiParam("author", singletonList("unknown"))
  1101. .executeProtobuf(SearchWsResponse.class).getIssuesList())
  1102. .isEmpty();
  1103. }
  1104. @Test
  1105. public void filter_by_test_scope() {
  1106. ProjectData projectData = db.components().insertPublicProject("PROJECT_ID",
  1107. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID"));
  1108. ComponentDto project = projectData.getMainBranchComponent();
  1109. indexPermissions();
  1110. ComponentDto mainCodeFile = db.components().insertComponent(
  1111. newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1112. ComponentDto testCodeFile = db.components().insertComponent(
  1113. newFileDto(project, null, "ANOTHER_FILE_ID").setKey("ANOTHER_FILE_KEY").setQualifier(UNIT_TEST_FILE));
  1114. RuleDto rule = newIssueRule();
  1115. IssueDto issue1 = newIssue(rule, project, mainCodeFile)
  1116. .setIssueCreationDate(parseDate("2014-09-04"))
  1117. .setIssueUpdateDate(parseDate("2017-12-04"))
  1118. .setEffort(10L)
  1119. .setStatus("OPEN")
  1120. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  1121. .setSeverity("MAJOR");
  1122. IssueDto issue2 = newIssue(rule, project, mainCodeFile)
  1123. .setIssueCreationDate(parseDate("2014-09-04"))
  1124. .setIssueUpdateDate(parseDate("2017-12-04"))
  1125. .setEffort(10L)
  1126. .setStatus("OPEN")
  1127. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  1128. .setSeverity("MAJOR");
  1129. IssueDto issue3 = newIssue(rule, project, testCodeFile)
  1130. .setIssueCreationDate(parseDate("2014-09-04"))
  1131. .setIssueUpdateDate(parseDate("2017-12-04"))
  1132. .setEffort(10L)
  1133. .setStatus("OPEN")
  1134. .setKee("82fd47d4-4037-b650-80bc-7b112bd4eac2")
  1135. .setSeverity("MAJOR");
  1136. dbClient.issueDao().insert(session, issue1, issue2, issue3);
  1137. session.commit();
  1138. indexIssues();
  1139. ws.newRequest()
  1140. .setParam("scopes", "TEST")
  1141. .setParam(FACETS, "scopes")
  1142. .execute()
  1143. .assertJson(this.getClass(), "filter_by_test_scope.json");
  1144. }
  1145. @Test
  1146. public void filter_by_main_scope() {
  1147. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  1148. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID")).getMainBranchComponent();
  1149. indexPermissions();
  1150. ComponentDto mainCodeFile = db.components().insertComponent(
  1151. newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1152. ComponentDto testCodeFile = db.components().insertComponent(
  1153. newFileDto(project, null, "ANOTHER_FILE_ID").setKey("ANOTHER_FILE_KEY").setQualifier(UNIT_TEST_FILE));
  1154. RuleDto rule = newIssueRule();
  1155. IssueDto issue1 = newIssue(rule, project, mainCodeFile)
  1156. .setIssueCreationDate(parseDate("2014-09-04"))
  1157. .setIssueUpdateDate(parseDate("2017-12-04"))
  1158. .setEffort(10L)
  1159. .setStatus("OPEN")
  1160. .setKee("83ec1d05-9397-4137-9978-85368bcc3b90")
  1161. .setSeverity("MAJOR");
  1162. IssueDto issue2 = newIssue(rule, project, mainCodeFile)
  1163. .setIssueCreationDate(parseDate("2014-09-04"))
  1164. .setIssueUpdateDate(parseDate("2017-12-04"))
  1165. .setEffort(10L)
  1166. .setStatus("OPEN")
  1167. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  1168. .setSeverity("MAJOR");
  1169. IssueDto issue3 = newIssue(rule, project, testCodeFile)
  1170. .setIssueCreationDate(parseDate("2014-09-04"))
  1171. .setIssueUpdateDate(parseDate("2017-12-04"))
  1172. .setEffort(10L)
  1173. .setStatus("OPEN")
  1174. .setKee("82fd47d4-4037-b650-80bc-7b112bd4eac2")
  1175. .setSeverity("MAJOR");
  1176. dbClient.issueDao().insert(session, issue1, issue2, issue3);
  1177. session.commit();
  1178. indexIssues();
  1179. ws.newRequest()
  1180. .setParam("scopes", "MAIN")
  1181. .setParam(FACETS, "scopes")
  1182. .execute()
  1183. .assertJson(this.getClass(), "filter_by_main_scope.json");
  1184. }
  1185. @Test
  1186. public void filter_by_scope_always_returns_all_scope_facet_values() {
  1187. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  1188. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID")).getMainBranchComponent();
  1189. indexPermissions();
  1190. ComponentDto mainCodeFile = db.components().insertComponent(
  1191. newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1192. RuleDto rule = newIssueRule();
  1193. IssueDto issue1 = newIssue(rule, project, mainCodeFile)
  1194. .setIssueCreationDate(parseDate("2014-09-04"))
  1195. .setIssueUpdateDate(parseDate("2017-12-04"))
  1196. .setEffort(10L)
  1197. .setStatus("OPEN")
  1198. .setKee("83ec1d05-9397-4137-9978-85368bcc3b90")
  1199. .setSeverity("MAJOR");
  1200. IssueDto issue2 = newIssue(rule, project, mainCodeFile)
  1201. .setIssueCreationDate(parseDate("2014-09-04"))
  1202. .setIssueUpdateDate(parseDate("2017-12-04"))
  1203. .setEffort(10L)
  1204. .setStatus("OPEN")
  1205. .setKee("7b112bd4-b650-4037-80bc-82fd47d4eac2")
  1206. .setSeverity("MAJOR");
  1207. dbClient.issueDao().insert(session, issue1, issue2);
  1208. session.commit();
  1209. indexIssues();
  1210. ws.newRequest()
  1211. .setParam("scopes", "MAIN")
  1212. .setParam(FACETS, "scopes")
  1213. .execute()
  1214. .assertJson(this.getClass(), "filter_by_main_scope_2.json");
  1215. }
  1216. @Test
  1217. public void sort_by_updated_at() {
  1218. RuleDto rule = newIssueRule();
  1219. ComponentDto project = db.components().insertPublicProject("PROJECT_ID",
  1220. c -> c.setKey("PROJECT_KEY").setName("NAME_PROJECT_ID").setLongName("LONG_NAME_PROJECT_ID")).getMainBranchComponent();
  1221. indexPermissions();
  1222. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1223. dbClient.issueDao().insert(session, newIssue(rule, project, file)
  1224. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac1")
  1225. .setIssueUpdateDate(parseDateTime("2014-11-02T00:00:00+0100")));
  1226. dbClient.issueDao().insert(session, newIssue(rule, project, file)
  1227. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac2")
  1228. .setIssueUpdateDate(parseDateTime("2014-11-01T00:00:00+0100")));
  1229. dbClient.issueDao().insert(session, newIssue(rule, project, file)
  1230. .setKee("82fd47d4-b650-4037-80bc-7b112bd4eac3")
  1231. .setIssueUpdateDate(parseDateTime("2014-11-03T00:00:00+0100")));
  1232. session.commit();
  1233. indexIssues();
  1234. TestResponse response = ws.newRequest()
  1235. .setParam("s", IssueQuery.SORT_BY_UPDATE_DATE)
  1236. .setParam("asc", "false")
  1237. .execute();
  1238. JsonElement parse = JsonParser.parseString(response.getInput());
  1239. assertThat(parse.getAsJsonObject().get("issues").getAsJsonArray())
  1240. .extracting(o -> o.getAsJsonObject().get("key").getAsString())
  1241. .containsExactly("82fd47d4-b650-4037-80bc-7b112bd4eac3", "82fd47d4-b650-4037-80bc-7b112bd4eac1", "82fd47d4-b650-4037-80bc-7b112bd4eac2");
  1242. }
  1243. @Test
  1244. public void only_vulnerabilities_are_returned_by_owaspAsvs40() {
  1245. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1246. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1247. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1248. .setSecurityStandards(Sets.newHashSet("cwe:20", "owaspTop10:a1", "pciDss-3.2:6.5.3", "owaspAsvs-4.0:12.3.1"))
  1249. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1250. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1251. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1252. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1253. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1254. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1255. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1256. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1257. indexPermissionsAndIssues();
  1258. SearchWsResponse result = ws.newRequest()
  1259. .setParam("owaspAsvs-4.0", "12.3.1")
  1260. .executeProtobuf(SearchWsResponse.class);
  1261. assertThat(result.getIssuesList())
  1262. .extracting(Issue::getKey)
  1263. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1264. result = ws.newRequest()
  1265. .setParam("owaspAsvs-4.0", "12")
  1266. .executeProtobuf(SearchWsResponse.class);
  1267. assertThat(result.getIssuesList())
  1268. .extracting(Issue::getKey)
  1269. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1270. }
  1271. @Test
  1272. public void only_vulnerabilities_are_returned_by_owaspAsvs40_with_level() {
  1273. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1274. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1275. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1276. RuleDto issueRule1 = db.rules().insertIssueRule(r -> r.setSecurityStandards(Set.of("owaspAsvs-4.0:1.7.2", "owaspAsvs-4.0:12.3.1")));
  1277. RuleDto issueRule2 = db.rules().insertIssueRule(r -> r.setSecurityStandards(Set.of("owaspAsvs-4.0:2.2.5")));
  1278. RuleDto issueRule3 = db.rules().insertIssueRule(r -> r.setSecurityStandards(Set.of("owaspAsvs-4.0:2.2.5", "owaspAsvs-4.0:12.1.3")));
  1279. IssueDto issueDto1 = db.issues().insertIssue(issueRule1, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1280. IssueDto issueDto2 = db.issues().insertIssue(issueRule2, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1281. IssueDto issueDto3 = db.issues().insertIssue(issueRule3, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1282. indexPermissionsAndIssues();
  1283. SearchWsResponse result = ws.newRequest()
  1284. .setParam("owaspAsvs-4.0", "1")
  1285. .setParam("owaspAsvsLevel", "1")
  1286. .executeProtobuf(SearchWsResponse.class);
  1287. assertThat(result.getIssuesList()).isEmpty();
  1288. result = ws.newRequest()
  1289. .setParam("owaspAsvs-4.0", "1")
  1290. .setParam("owaspAsvsLevel", "2")
  1291. .executeProtobuf(SearchWsResponse.class);
  1292. assertThat(result.getIssuesList())
  1293. .extracting(Issue::getKey)
  1294. .containsExactlyInAnyOrder(issueDto1.getKey());
  1295. result = ws.newRequest()
  1296. .setParam("owaspAsvs-4.0", "12")
  1297. .setParam("owaspAsvsLevel", "1")
  1298. .executeProtobuf(SearchWsResponse.class);
  1299. assertThat(result.getIssuesList())
  1300. .extracting(Issue::getKey)
  1301. .containsExactlyInAnyOrder(issueDto1.getKey());
  1302. result = ws.newRequest()
  1303. .setParam("owaspAsvs-4.0", "12")
  1304. .setParam("owaspAsvsLevel", "2")
  1305. .executeProtobuf(SearchWsResponse.class);
  1306. assertThat(result.getIssuesList())
  1307. .extracting(Issue::getKey)
  1308. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto3.getKey());
  1309. }
  1310. @Test
  1311. public void only_vulnerabilities_are_returned_by_pciDss32() {
  1312. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1313. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1314. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1315. .setSecurityStandards(Sets.newHashSet("cwe:20", "owaspTop10:a1", "pciDss-3.2:6.5.3", "pciDss-3.2:10.1"))
  1316. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1317. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1318. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1319. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1320. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1321. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1322. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1323. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1324. indexPermissionsAndIssues();
  1325. SearchWsResponse result = ws.newRequest()
  1326. .setParam("pciDss-3.2", "10")
  1327. .executeProtobuf(SearchWsResponse.class);
  1328. assertThat(result.getIssuesList())
  1329. .extracting(Issue::getKey)
  1330. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1331. result = ws.newRequest()
  1332. .setParam("pciDss-3.2", "10.1")
  1333. .executeProtobuf(SearchWsResponse.class);
  1334. assertThat(result.getIssuesList())
  1335. .extracting(Issue::getKey)
  1336. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1337. }
  1338. @Test
  1339. public void multiple_categories_pciDss32() {
  1340. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1341. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1342. // Rule 1
  1343. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1344. .setSecurityStandards(Sets.newHashSet("cwe:20", "owaspTop10:a1", "pciDss-3.2:6.5.3", "pciDss-3.2:10.1"))
  1345. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1346. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1347. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1348. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1349. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1350. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1351. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1352. // Rule 2
  1353. ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1354. .setSecurityStandards(Sets.newHashSet("pciDss-4.0:6.5.3", "pciDss-3.2:1.1"))
  1355. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1356. issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1357. hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1358. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1359. issueRule = db.rules().insertIssueRule(ruleConsumer);
  1360. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1361. IssueDto issueDto4 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1362. // Rule 3
  1363. ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1364. .setSecurityStandards(Sets.newHashSet("pciDss-4.0:6.5.3", "pciDss-3.2:2.3", "pciDss-3.2:10.1.2"))
  1365. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1366. issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1367. hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1368. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1369. issueRule = db.rules().insertIssueRule(ruleConsumer);
  1370. IssueDto issueDto5 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1371. IssueDto issueDto6 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1372. indexPermissionsAndIssues();
  1373. SearchWsResponse result = ws.newRequest()
  1374. .setParam("pciDss-3.2", "1,10")
  1375. .executeProtobuf(SearchWsResponse.class);
  1376. assertThat(result.getIssuesList())
  1377. .extracting(Issue::getKey)
  1378. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey(), issueDto3.getKey(), issueDto4.getKey(), issueDto5.getKey(), issueDto6.getKey());
  1379. result = ws.newRequest()
  1380. .setParam("pciDss-3.2", "1")
  1381. .executeProtobuf(SearchWsResponse.class);
  1382. assertThat(result.getIssuesList())
  1383. .extracting(Issue::getKey)
  1384. .containsExactlyInAnyOrder(issueDto3.getKey(), issueDto4.getKey());
  1385. result = ws.newRequest()
  1386. .setParam("pciDss-3.2", "1,10,4")
  1387. .executeProtobuf(SearchWsResponse.class);
  1388. assertThat(result.getIssuesList())
  1389. .extracting(Issue::getKey)
  1390. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey(), issueDto3.getKey(), issueDto4.getKey(), issueDto5.getKey(), issueDto6.getKey());
  1391. result = ws.newRequest()
  1392. .setParam("pciDss-3.2", "4")
  1393. .executeProtobuf(SearchWsResponse.class);
  1394. assertThat(result.getIssuesList()).isEmpty();
  1395. result = ws.newRequest()
  1396. .setParam("pciDss-3.2", "4,7,12")
  1397. .executeProtobuf(SearchWsResponse.class);
  1398. assertThat(result.getIssuesList()).isEmpty();
  1399. result = ws.newRequest()
  1400. .setParam("pciDss-3.2", "10.1")
  1401. .executeProtobuf(SearchWsResponse.class);
  1402. assertThat(result.getIssuesList())
  1403. .extracting(Issue::getKey)
  1404. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1405. }
  1406. @Test
  1407. public void only_vulnerabilities_are_returned_by_pciDss40() {
  1408. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1409. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1410. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1411. .setSecurityStandards(Sets.newHashSet("cwe:20", "owaspTop10:a1", "pciDss-4.0:6.5.3", "pciDss-4.0:10.1"))
  1412. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1413. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1414. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1415. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1416. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1417. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1418. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1419. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1420. indexPermissionsAndIssues();
  1421. SearchWsResponse result = ws.newRequest()
  1422. .setParam("pciDss-4.0", "10,6,5")
  1423. .executeProtobuf(SearchWsResponse.class);
  1424. assertThat(result.getIssuesList())
  1425. .extracting(Issue::getKey)
  1426. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1427. result = ws.newRequest()
  1428. .setParam("pciDss-4.0", "10.1,6.5,5.5")
  1429. .executeProtobuf(SearchWsResponse.class);
  1430. assertThat(result.getIssuesList())
  1431. .extracting(Issue::getKey)
  1432. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1433. }
  1434. @Test
  1435. public void multiple_categories_pciDss40() {
  1436. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1437. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1438. // Rule 1
  1439. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1440. .setSecurityStandards(Sets.newHashSet("cwe:20", "owaspTop10:a1", "pciDss-4.0:6.5.3", "pciDss-4.0:10.1"))
  1441. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1442. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1443. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1444. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1445. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1446. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1447. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1448. // Rule 2
  1449. ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1450. .setSecurityStandards(Sets.newHashSet("pciDss-4.0:6.5.3", "pciDss-4.0:1.1"))
  1451. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1452. issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1453. hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1454. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1455. issueRule = db.rules().insertIssueRule(ruleConsumer);
  1456. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1457. IssueDto issueDto4 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1458. // Rule 3
  1459. ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1460. .setSecurityStandards(Sets.newHashSet("pciDss-3.2:6.5.3", "pciDss-4.0:2.3"))
  1461. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1462. issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1463. hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1464. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1465. issueRule = db.rules().insertIssueRule(ruleConsumer);
  1466. IssueDto issueDto5 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1467. IssueDto issueDto6 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1468. indexPermissionsAndIssues();
  1469. SearchWsResponse result = ws.newRequest()
  1470. .setParam("pciDss-4.0", "1,10")
  1471. .executeProtobuf(SearchWsResponse.class);
  1472. assertThat(result.getIssuesList())
  1473. .extracting(Issue::getKey)
  1474. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey(), issueDto3.getKey(), issueDto4.getKey());
  1475. result = ws.newRequest()
  1476. .setParam("pciDss-4.0", "1")
  1477. .executeProtobuf(SearchWsResponse.class);
  1478. assertThat(result.getIssuesList())
  1479. .extracting(Issue::getKey)
  1480. .containsExactlyInAnyOrder(issueDto3.getKey(), issueDto4.getKey());
  1481. result = ws.newRequest()
  1482. .setParam("pciDss-4.0", "1,10,4")
  1483. .executeProtobuf(SearchWsResponse.class);
  1484. assertThat(result.getIssuesList())
  1485. .extracting(Issue::getKey)
  1486. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey(), issueDto3.getKey(), issueDto4.getKey());
  1487. result = ws.newRequest()
  1488. .setParam("pciDss-4.0", "4")
  1489. .executeProtobuf(SearchWsResponse.class);
  1490. assertThat(result.getIssuesList()).isEmpty();
  1491. result = ws.newRequest()
  1492. .setParam("pciDss-4.0", "4,7,12")
  1493. .executeProtobuf(SearchWsResponse.class);
  1494. assertThat(result.getIssuesList()).isEmpty();
  1495. }
  1496. @Test
  1497. public void only_vulnerabilities_are_returned_by_cwe() {
  1498. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1499. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1500. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1501. .setSecurityStandards(Sets.newHashSet("cwe:20", "cwe:564", "cwe:89", "cwe:943", "owaspTop10:a1"))
  1502. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1503. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1504. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1505. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1506. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1507. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1508. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1509. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1510. indexPermissionsAndIssues();
  1511. SearchWsResponse result = ws.newRequest()
  1512. .setParam("cwe", "20")
  1513. .executeProtobuf(SearchWsResponse.class);
  1514. assertThat(result.getIssuesList())
  1515. .extracting(Issue::getKey)
  1516. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1517. }
  1518. @Test
  1519. public void only_vulnerabilities_are_returned_by_owasp() {
  1520. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1521. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1522. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1523. .setSecurityStandards(Sets.newHashSet("cwe:20", "cwe:564", "cwe:89", "cwe:943", "owaspTop10:a1", "owaspTop10-2021:a2"))
  1524. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1525. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1526. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1527. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1528. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1529. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1530. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1531. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1532. indexPermissionsAndIssues();
  1533. SearchWsResponse result = ws.newRequest()
  1534. .setParam("owaspTop10", "a1")
  1535. .executeProtobuf(SearchWsResponse.class);
  1536. assertThat(result.getIssuesList())
  1537. .extracting(Issue::getKey)
  1538. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1539. }
  1540. @Test
  1541. public void only_vulnerabilities_are_returned_by_owasp_2021() {
  1542. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1543. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1544. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1545. .setSecurityStandards(Sets.newHashSet("cwe:20", "cwe:564", "cwe:89", "cwe:943", "owaspTop10:a1", "owaspTop10-2021:a2"))
  1546. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1547. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1548. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1549. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1550. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1551. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1552. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1553. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1554. indexPermissionsAndIssues();
  1555. SearchWsResponse result = ws.newRequest()
  1556. .setParam("owaspTop10-2021", "a2")
  1557. .executeProtobuf(SearchWsResponse.class);
  1558. assertThat(result.getIssuesList())
  1559. .extracting(Issue::getKey)
  1560. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1561. }
  1562. @Test
  1563. public void only_vulnerabilities_are_returned_by_sansTop25() {
  1564. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1565. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1566. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1567. .setSecurityStandards(Sets.newHashSet("cwe:266", "cwe:732", "owaspTop10:a5"))
  1568. .setSystemTags(Sets.newHashSet("cert", "cwe", "owasp-a5", "sans-top25-porous"));
  1569. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("cert", "cwe", "owasp-a5", "sans-top25-porous"));
  1570. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1571. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1572. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1573. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1574. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1575. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1576. indexPermissionsAndIssues();
  1577. SearchWsResponse result = ws.newRequest()
  1578. .setParam("sansTop25", "porous-defenses")
  1579. .executeProtobuf(SearchWsResponse.class);
  1580. assertThat(result.getIssuesList())
  1581. .extracting(Issue::getKey)
  1582. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1583. }
  1584. @Test
  1585. public void only_vulnerabilities_are_returned_by_sonarsource_security() {
  1586. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1587. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1588. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1589. .setSecurityStandards(Sets.newHashSet("cwe:20", "cwe:564", "cwe:89", "cwe:943", "owaspTop10:a1"))
  1590. .setSystemTags(Sets.newHashSet("cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1591. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1592. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1593. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1594. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1595. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1596. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1597. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(CODE_SMELL));
  1598. indexPermissionsAndIssues();
  1599. SearchWsResponse result = ws.newRequest()
  1600. .setParam("sonarsourceSecurity", "sql-injection")
  1601. .executeProtobuf(SearchWsResponse.class);
  1602. assertThat(result.getIssuesList())
  1603. .extracting(Issue::getKey)
  1604. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1605. }
  1606. @Test
  1607. public void security_hotspots_are_not_returned_by_default() {
  1608. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1609. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1610. RuleDto rule = db.rules().insertIssueRule();
  1611. db.issues().insertIssue(rule, project, file, i -> i.setType(RuleType.BUG));
  1612. db.issues().insertIssue(rule, project, file, i -> i.setType(RuleType.VULNERABILITY));
  1613. db.issues().insertIssue(rule, project, file, i -> i.setType(CODE_SMELL));
  1614. db.issues().insertHotspot(project, file);
  1615. indexPermissionsAndIssues();
  1616. SearchWsResponse result = ws.newRequest().executeProtobuf(SearchWsResponse.class);
  1617. assertThat(result.getIssuesList())
  1618. .extracting(Issue::getType)
  1619. .containsExactlyInAnyOrder(BUG, VULNERABILITY, Common.RuleType.CODE_SMELL);
  1620. }
  1621. @Test
  1622. public void security_hotspots_are_not_returned_by_issues_param() {
  1623. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1624. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1625. RuleDto issueRule = db.rules().insertIssueRule();
  1626. IssueDto bugIssue = db.issues().insertIssue(issueRule, project, file, i -> i.setType(RuleType.BUG));
  1627. IssueDto vulnerabilityIssue = db.issues().insertIssue(issueRule, project, file, i -> i.setType(RuleType.VULNERABILITY));
  1628. IssueDto codeSmellIssue = db.issues().insertIssue(issueRule, project, file, i -> i.setType(CODE_SMELL));
  1629. RuleDto hotspotRule = db.rules().insertHotspotRule();
  1630. IssueDto hotspot = db.issues().insertHotspot(hotspotRule, project, file);
  1631. indexPermissionsAndIssues();
  1632. SearchWsResponse result = ws.newRequest()
  1633. .setParam("issues", Stream.of(bugIssue, vulnerabilityIssue, codeSmellIssue, hotspot).map(IssueDto::getKey).collect(Collectors.joining(",")))
  1634. .executeProtobuf(SearchWsResponse.class);
  1635. assertThat(result.getIssuesList())
  1636. .extracting(Issue::getType)
  1637. .containsExactlyInAnyOrder(BUG, VULNERABILITY, Common.RuleType.CODE_SMELL);
  1638. }
  1639. @Test
  1640. public void security_hotspots_are_not_returned_by_cwe() {
  1641. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1642. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1643. Consumer<RuleDto> ruleConsumer = ruleDefinitionDto -> ruleDefinitionDto
  1644. .setSecurityStandards(Sets.newHashSet("cwe:20", "cwe:564", "cwe:89", "cwe:943", "owaspTop10:a1"))
  1645. .setSystemTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1646. Consumer<IssueDto> issueConsumer = issueDto -> issueDto.setTags(Sets.newHashSet("bad-practice", "cwe", "owasp-a1", "sans-top25-insecure", "sql"));
  1647. RuleDto hotspotRule = db.rules().insertHotspotRule(ruleConsumer);
  1648. db.issues().insertHotspot(hotspotRule, project, file, issueConsumer);
  1649. RuleDto issueRule = db.rules().insertIssueRule(ruleConsumer);
  1650. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1651. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueConsumer, issueDto -> issueDto.setType(RuleType.VULNERABILITY));
  1652. indexPermissions();
  1653. indexIssues();
  1654. SearchWsResponse result = ws.newRequest()
  1655. .setParam("cwe", "20")
  1656. .executeProtobuf(SearchWsResponse.class);
  1657. assertThat(result.getIssuesList())
  1658. .extracting(Issue::getKey)
  1659. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey());
  1660. }
  1661. @Test
  1662. public void security_hotspots_are_not_returned_by_assignees() {
  1663. UserDto user = db.users().insertUser();
  1664. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1665. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1666. RuleDto hotspotRule = db.rules().insertHotspotRule();
  1667. db.issues().insertHotspot(hotspotRule, project, file, issueDto -> issueDto.setAssigneeUuid(user.getUuid()));
  1668. RuleDto issueRule = db.rules().insertIssueRule();
  1669. IssueDto issueDto1 = db.issues().insertIssue(issueRule, project, file, issueDto -> issueDto.setAssigneeUuid(user.getUuid()));
  1670. IssueDto issueDto2 = db.issues().insertIssue(issueRule, project, file, issueDto -> issueDto.setAssigneeUuid(user.getUuid()));
  1671. IssueDto issueDto3 = db.issues().insertIssue(issueRule, project, file, issueDto -> issueDto.setAssigneeUuid(user.getUuid()));
  1672. IssueDto issueDto4 = db.issues().insertIssue(issueRule, project, file, issueDto -> issueDto.setAssigneeUuid(user.getUuid()));
  1673. indexPermissionsAndIssues();
  1674. SearchWsResponse result = ws.newRequest()
  1675. .setParam(PARAM_ASSIGNEES, user.getLogin())
  1676. .executeProtobuf(SearchWsResponse.class);
  1677. assertThat(result.getIssuesList())
  1678. .extracting(Issue::getKey)
  1679. .containsExactlyInAnyOrder(issueDto1.getKey(), issueDto2.getKey(), issueDto3.getKey(), issueDto4.getKey());
  1680. }
  1681. @Test
  1682. public void security_hotspots_are_not_returned_by_rule() {
  1683. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1684. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1685. RuleDto hotspotRule = db.rules().insertHotspotRule();
  1686. db.issues().insertHotspot(hotspotRule, project, file);
  1687. indexPermissionsAndIssues();
  1688. SearchWsResponse result = ws.newRequest()
  1689. .setParam("rules", hotspotRule.getKey().toString())
  1690. .executeProtobuf(SearchWsResponse.class);
  1691. assertThat(result.getIssuesList()).isEmpty();
  1692. }
  1693. @Test
  1694. public void security_hotspots_are_not_returned_by_issues_param_only() {
  1695. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1696. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1697. RuleDto rule = db.rules().insertHotspotRule();
  1698. List<IssueDto> hotspots = IntStream.range(1, 2 + new Random().nextInt(10))
  1699. .mapToObj(value -> db.issues().insertHotspot(rule, project, file))
  1700. .toList();
  1701. indexPermissions();
  1702. indexIssues();
  1703. SearchWsResponse result = ws.newRequest()
  1704. .setParam("issues", hotspots.stream().map(IssueDto::getKey).collect(Collectors.joining(",")))
  1705. .executeProtobuf(SearchWsResponse.class);
  1706. assertThat(result.getIssuesList())
  1707. .isEmpty();
  1708. }
  1709. @Test
  1710. public void fail_if_trying_to_filter_issues_by_hotspots() {
  1711. ComponentDto mainBranch = db.components().insertPublicProject().getMainBranchComponent();
  1712. ComponentDto file = db.components().insertComponent(newFileDto(mainBranch));
  1713. RuleDto hotspotRule = newHotspotRule();
  1714. db.issues().insertHotspot(hotspotRule, mainBranch, file);
  1715. insertIssues(i -> i.setType(RuleType.BUG), i -> i.setType(RuleType.VULNERABILITY),
  1716. i -> i.setType(RuleType.CODE_SMELL));
  1717. indexPermissionsAndIssues();
  1718. TestRequest request = ws.newRequest()
  1719. .setParam("types", RuleType.SECURITY_HOTSPOT.toString());
  1720. assertThatThrownBy(request::execute)
  1721. .isInstanceOf(IllegalArgumentException.class)
  1722. .hasMessage("Value of parameter 'types' (SECURITY_HOTSPOT) must be one of: [CODE_SMELL, BUG, VULNERABILITY]");
  1723. }
  1724. @Test
  1725. public void security_hotspot_are_ignored_when_filtering_by_severities() {
  1726. ComponentDto project = db.components().insertPublicProject().getMainBranchComponent();
  1727. ComponentDto file = db.components().insertComponent(newFileDto(project));
  1728. RuleDto issueRule = db.rules().insertIssueRule();
  1729. IssueDto bugIssue = db.issues().insertIssue(issueRule, project, file, i -> i.setType(RuleType.BUG).setSeverity(Severity.MAJOR.name()));
  1730. IssueDto vulnerabilityIssue = db.issues().insertIssue(issueRule, project, file, i -> i.setType(RuleType.VULNERABILITY).setSeverity(Severity.MAJOR.name()));
  1731. IssueDto codeSmellIssue = db.issues().insertIssue(issueRule, project, file, i -> i.setType(CODE_SMELL).setSeverity(Severity.MAJOR.name()));
  1732. RuleDto hotspotRule = db.rules().insertHotspotRule();
  1733. db.issues().insertHotspot(hotspotRule, project, file, i -> i.setSeverity(Severity.MAJOR.name()));
  1734. indexPermissions();
  1735. indexIssues();
  1736. SearchWsResponse result = ws.newRequest()
  1737. .setParam("severities", Severity.MAJOR.name())
  1738. .setParam(FACETS, "severities")
  1739. .executeProtobuf(SearchWsResponse.class);
  1740. assertThat(result.getIssuesList())
  1741. .extracting(Issue::getKey, Issue::getType)
  1742. .containsExactlyInAnyOrder(
  1743. tuple(bugIssue.getKey(), BUG),
  1744. tuple(vulnerabilityIssue.getKey(), VULNERABILITY),
  1745. tuple(codeSmellIssue.getKey(), Common.RuleType.CODE_SMELL));
  1746. assertThat(result.getFacets().getFacets(0).getValuesList())
  1747. .extracting(Common.FacetValue::getVal, Common.FacetValue::getCount)
  1748. .containsExactlyInAnyOrder(tuple("MAJOR", 3L), tuple("INFO", 0L), tuple("MINOR", 0L), tuple("CRITICAL", 0L), tuple("BLOCKER", 0L));
  1749. }
  1750. @Test
  1751. public void return_total_effort() {
  1752. insertIssues(i -> i.setEffort(10L), i -> i.setEffort(15L));
  1753. indexPermissionsAndIssues();
  1754. SearchWsResponse response = ws.newRequest().executeProtobuf(SearchWsResponse.class);
  1755. assertThat(response.getEffortTotal()).isEqualTo(25L);
  1756. }
  1757. @Test
  1758. public void givenNotQuickFixableIssue_returnIssueIsNotQuickFixable() {
  1759. insertIssues(i -> i.setQuickFixAvailable(false));
  1760. indexPermissionsAndIssues();
  1761. SearchWsResponse response = ws.newRequest().executeProtobuf(SearchWsResponse.class);
  1762. assertThat(response.getIssuesList()).hasSize(1);
  1763. assertThat(response.getIssuesList().get(0).getQuickFixAvailable()).isFalse();
  1764. }
  1765. @Test
  1766. public void givenQuickFixableIssue_returnIssueIsQuickFixable() {
  1767. insertIssues(i -> i.setQuickFixAvailable(true));
  1768. indexPermissionsAndIssues();
  1769. SearchWsResponse response = ws.newRequest().executeProtobuf(SearchWsResponse.class);
  1770. assertThat(response.getIssuesList()).hasSize(1);
  1771. assertThat(response.getIssuesList().get(0).getQuickFixAvailable()).isTrue();
  1772. }
  1773. @Test
  1774. public void paging() {
  1775. RuleDto rule = newIssueRule();
  1776. ComponentDto project = db.components().insertPublicProject("PROJECT_ID", c -> c.setKey("PROJECT_KEY")).getMainBranchComponent();
  1777. indexPermissions();
  1778. ComponentDto file = db.components().insertComponent(newFileDto(project, null, "FILE_ID").setKey("FILE_KEY"));
  1779. for (int i = 0; i < 12; i++) {
  1780. IssueDto issue = newIssue(rule, project, file).setChecksum(null);
  1781. dbClient.issueDao().insert(session, issue);
  1782. }
  1783. session.commit();
  1784. indexIssues();
  1785. ws.newRequest()
  1786. .setParam(WebService.Param.PAGE, "2")
  1787. .setParam(WebService.Param.PAGE_SIZE, "9")
  1788. .execute()
  1789. .assertJson(this.getClass(), "paging.json");
  1790. }
  1791. @Test
  1792. public void paging_with_page_size_to_minus_one() {
  1793. TestRequest requestWithNegativePageSize = ws.newRequest()
  1794. .setParam(WebService.Param.PAGE, "1")
  1795. .setParam(WebService.Param.PAGE_SIZE, "-1");
  1796. assertThatThrownBy(requestWithNegativePageSize::execute)
  1797. .isInstanceOf(IllegalArgumentException.class)
  1798. .hasMessage("Page size must be between 1 and 500 (got -1)");
  1799. }
  1800. @Test
  1801. public void default_page_size_is_100() {
  1802. ws.newRequest()
  1803. .execute()
  1804. .assertJson(this.getClass(), "default_page_size_is_100.json");
  1805. }
  1806. // SONAR-10217
  1807. @Test
  1808. public void empty_search_with_unknown_branch() {
  1809. SearchWsResponse response = ws.newRequest()
  1810. .setParam("onComponentOnly", "true")
  1811. .setParam("components", "foo")
  1812. .setParam("branch", "bar")
  1813. .executeProtobuf(SearchWsResponse.class);
  1814. assertThat(response)
  1815. .extracting(SearchWsResponse::getIssuesList, r -> r.getPaging().getTotal())
  1816. .containsExactlyInAnyOrder(Collections.emptyList(), 0);
  1817. }
  1818. @Test
  1819. public void empty_search() {
  1820. SearchWsResponse response = ws.newRequest().executeProtobuf(SearchWsResponse.class);
  1821. assertThat(response)
  1822. .extracting(SearchWsResponse::getIssuesList, r -> r.getPaging().getTotal())
  1823. .containsExactlyInAnyOrder(Collections.emptyList(), 0);
  1824. }
  1825. @Test
  1826. public void fail_when_invalid_format() {
  1827. TestRequest invalidFormatRequest = ws.newRequest()
  1828. .setParam(PARAM_CREATED_AFTER, "wrong-date-input");
  1829. assertThatThrownBy(invalidFormatRequest::execute)
  1830. .isInstanceOf(IllegalArgumentException.class)
  1831. .hasMessage("Date 'wrong-date-input' cannot be parsed as either a date or date+time");
  1832. }
  1833. @Test
  1834. public void test_definition() {
  1835. WebService.Action def = ws.getDef();
  1836. assertThat(def.key()).isEqualTo("search");
  1837. assertThat(def.isInternal()).isFalse();
  1838. assertThat(def.isPost()).isFalse();
  1839. assertThat(def.since()).isEqualTo("3.6");
  1840. assertThat(def.responseExampleAsString()).isNotEmpty();
  1841. assertThat(def.params()).extracting("key").containsExactlyInAnyOrder(
  1842. "additionalFields", "asc", "assigned", "assignees", "author", "components", "branch", "pullRequest", "createdAfter", "createdAt",
  1843. "createdBefore", "createdInLast", "directories", "facets", "files", "issues", "scopes", "languages", "onComponentOnly",
  1844. "p", "projects", "ps", "resolutions", "resolved", "rules", "s", "severities", "statuses", "tags", "types", "pciDss-3.2", "pciDss-4.0", "owaspAsvs-4.0",
  1845. "owaspAsvsLevel", "owaspTop10", "owaspTop10-2021", "sansTop25", "cwe", "sonarsourceSecurity", "timeZone", "inNewCodePeriod", "codeVariants",
  1846. "cleanCodeAttributeCategories", "impactSeverities", "impactSoftwareQualities", "issueStatuses", "fixedInPullRequest");
  1847. WebService.Param branch = def.param(PARAM_BRANCH);
  1848. assertThat(branch.isInternal()).isFalse();
  1849. assertThat(branch.isRequired()).isFalse();
  1850. assertThat(branch.since()).isEqualTo("6.6");
  1851. WebService.Param projectUuids = def.param("projects");
  1852. assertThat(projectUuids.description()).isEqualTo("To retrieve issues associated to a specific list of projects (comma-separated list of project keys). " +
  1853. "This parameter is mostly used by the Issues page, please prefer usage of the componentKeys parameter. If this parameter is set, projectUuids must not be set.");
  1854. }
  1855. @Test
  1856. public void search_when_additional_field_set_return_context_key() {
  1857. insertIssues(issue -> issue.setRuleDescriptionContextKey("spring"));
  1858. indexPermissionsAndIssues();
  1859. SearchWsResponse response = ws.newRequest()
  1860. .setParam("additionalFields", "ruleDescriptionContextKey")
  1861. .executeProtobuf(SearchWsResponse.class);
  1862. assertThat(response.getIssuesList()).isNotEmpty()
  1863. .extracting(Issue::getRuleDescriptionContextKey).containsExactly("spring");
  1864. }
  1865. @Test
  1866. public void search_when_no_additional_field_return_empty_context_key() {
  1867. insertIssues(issue -> issue.setRuleDescriptionContextKey("spring"));
  1868. indexPermissionsAndIssues();
  1869. SearchWsResponse response = ws.newRequest()
  1870. .executeProtobuf(SearchWsResponse.class);
  1871. assertThat(response.getIssuesList()).isNotEmpty()
  1872. .extracting(Issue::getRuleDescriptionContextKey).containsExactly(EMPTY);
  1873. }
  1874. @Test
  1875. public void search_when_additional_field_but_no_context_key_return_empty_context_key() {
  1876. insertIssues(issue -> issue.setRuleDescriptionContextKey(null));
  1877. indexPermissionsAndIssues();
  1878. SearchWsResponse response = ws.newRequest()
  1879. .setParam("additionalFields", "ruleDescriptionContextKey")
  1880. .executeProtobuf(SearchWsResponse.class);
  1881. assertThat(response.getIssuesList()).isNotEmpty()
  1882. .extracting(Issue::getRuleDescriptionContextKey).containsExactly(EMPTY);
  1883. }
  1884. @Test
  1885. public void search_when_additional_field_set_to_all_return_context_key() {
  1886. insertIssues(issue -> issue.setRuleDescriptionContextKey("spring"));
  1887. indexPermissionsAndIssues();
  1888. SearchWsResponse response = ws.newRequest()
  1889. .setParam("additionalFields", "_all")
  1890. .executeProtobuf(SearchWsResponse.class);
  1891. assertThat(response.getIssuesList()).isNotEmpty()
  1892. .extracting(Issue::getRuleDescriptionContextKey).containsExactly("spring");
  1893. }
  1894. @Test
  1895. public void search_whenFixedInPullRequestSetAndNoComponentsSet_throwException() {
  1896. TestRequest request = ws.newRequest()
  1897. .setParam("fixedInPullRequest", "1000");
  1898. assertThatThrownBy(request::execute)
  1899. .isInstanceOf(IllegalArgumentException.class)
  1900. .hasMessage("Exactly one project needs to be provided in the 'components' param when used together with 'fixedInPullRequest' param");
  1901. }
  1902. @Test
  1903. public void search_whenFixedInPullRequestSetAndWrongBranchIsSet_throwException() {
  1904. String pullRequestId = "1000";
  1905. String pullRequestUuid = "pullRequestUuid";
  1906. userSession.logIn(db.users().insertUser());
  1907. ProjectData project = db.components().insertPublicProject();
  1908. db.getDbClient().branchDao().insert(session, new BranchDto()
  1909. .setUuid(pullRequestUuid)
  1910. .setProjectUuid(project.projectUuid())
  1911. .setKey(pullRequestId)
  1912. .setIsMain(false)
  1913. .setBranchType(BranchType.PULL_REQUEST)
  1914. .setMergeBranchUuid(project.mainBranchUuid()));
  1915. db.getDbClient().branchDao().insert(session, new BranchDto()
  1916. .setUuid("wrongBranchUuid")
  1917. .setProjectUuid(project.projectUuid())
  1918. .setKey("wrongBranch")
  1919. .setIsMain(false)
  1920. .setBranchType(BranchType.BRANCH)
  1921. .setMergeBranchUuid("wrongTargetBranchUuid"));
  1922. session.commit();
  1923. TestRequest request = ws.newRequest().setParam("fixedInPullRequest", pullRequestId).setParam("components", project.projectKey())
  1924. .setParam("branch", "wrongBranch");
  1925. assertThatThrownBy(request::execute)
  1926. .isInstanceOf(IllegalArgumentException.class)
  1927. .hasMessage("Pull request with key '1000' does not target branch 'wrongBranch'");
  1928. }
  1929. @Test
  1930. public void search_whenFixedInPullRequestSetAndProjectDoesNotExist_throwException() {
  1931. String pullRequestId = "1000";
  1932. String pullRequestUuid = "pullRequestUuid";
  1933. userSession.logIn(db.users().insertUser());
  1934. ProjectData project = db.components().insertPublicProject();
  1935. db.getDbClient().branchDao().insert(session, new BranchDto()
  1936. .setUuid(pullRequestUuid)
  1937. .setProjectUuid(project.projectUuid())
  1938. .setKey(pullRequestId)
  1939. .setIsMain(false)
  1940. .setBranchType(BranchType.PULL_REQUEST)
  1941. .setMergeBranchUuid(project.mainBranchUuid()));
  1942. session.commit();
  1943. TestRequest request = ws.newRequest().setParam("fixedInPullRequest", pullRequestId).setParam("components", "nonExistingProjectKey");
  1944. assertThatThrownBy(request::execute)
  1945. .isInstanceOf(IllegalArgumentException.class)
  1946. .hasMessage("Project with key 'nonExistingProjectKey' does not exist");
  1947. }
  1948. @Test
  1949. public void search_whenWrongFixedInPullRequestSet_throwException() {
  1950. String pullRequestId = "wrongPullRequest";
  1951. String pullRequestUuid = "pullRequestUuid";
  1952. userSession.logIn(db.users().insertUser());
  1953. ProjectData project = db.components().insertPublicProject();
  1954. db.getDbClient().branchDao().insert(session, new BranchDto()
  1955. .setUuid(pullRequestUuid)
  1956. .setProjectUuid(project.projectUuid())
  1957. .setKey("pullRequestId")
  1958. .setIsMain(false)
  1959. .setBranchType(BranchType.PULL_REQUEST)
  1960. .setMergeBranchUuid(project.mainBranchUuid()));
  1961. session.commit();
  1962. TestRequest request = ws.newRequest().setParam("fixedInPullRequest", pullRequestId).setParam("components", project.projectKey());
  1963. assertThatThrownBy(request::execute)
  1964. .isInstanceOf(IllegalArgumentException.class)
  1965. .hasMessage("Pull request with key 'wrongPullRequest' does not exist for project " + project.projectKey());
  1966. }
  1967. @Test
  1968. public void search_whenFixedInPullRequestSetAndNonExistingBranchIsSet_throwException() {
  1969. String pullRequestId = "1000";
  1970. String pullRequestUuid = "pullRequestUuid";
  1971. userSession.logIn(db.users().insertUser());
  1972. ProjectData project = db.components().insertPublicProject();
  1973. db.getDbClient().branchDao().insert(session, new BranchDto()
  1974. .setUuid(pullRequestUuid)
  1975. .setProjectUuid(project.projectUuid())
  1976. .setKey(pullRequestId)
  1977. .setIsMain(false)
  1978. .setBranchType(BranchType.PULL_REQUEST)
  1979. .setMergeBranchUuid(project.mainBranchUuid()));
  1980. session.commit();
  1981. TestRequest request = ws.newRequest().setParam("fixedInPullRequest", pullRequestId).setParam("components", project.projectKey())
  1982. .setParam("branch", "nonExistingBranch");
  1983. assertThatThrownBy(request::execute)
  1984. .isInstanceOf(IllegalArgumentException.class)
  1985. .hasMessage("Branch with key 'nonExistingBranch' does not exist");
  1986. }
  1987. @Test
  1988. public void search_whenFixedInPullRequestSetAndComponentsIsSetButNoIssueFixedInPR_returnZeroIssues() {
  1989. String pullRequestId = "1000";
  1990. String pullRequestUuid = "pullRequestUuid";
  1991. String issueKey = "issueKey";
  1992. userSession.logIn(db.users().insertUser());
  1993. ProjectData project = db.components().insertPublicProject();
  1994. db.getDbClient().branchDao().insert(session, new BranchDto()
  1995. .setUuid(pullRequestUuid)
  1996. .setProjectUuid(project.projectUuid())
  1997. .setKey(pullRequestId)
  1998. .setIsMain(false)
  1999. .setBranchType(BranchType.PULL_REQUEST)
  2000. .setMergeBranchUuid(project.mainBranchUuid()));
  2001. TestRequest request = ws.newRequest().setParam("components", project.projectKey()).setParam("fixedInPullRequest", pullRequestId);
  2002. insertIssues(project.getMainBranchComponent(), i -> i.setKee(issueKey));
  2003. session.commit();
  2004. indexPermissionsAndIssues();
  2005. SearchWsResponse response = request.executeProtobuf(SearchWsResponse.class);
  2006. List<Issue> issuesList = response.getIssuesList();
  2007. assertThat(issuesList).isEmpty();
  2008. }
  2009. @Test
  2010. public void search_whenFixedInPullRequestSetAndComponentsIsSet_returnOneIssueFixedInPR() {
  2011. String pullRequestId = "1000";
  2012. String pullRequestUuid = "pullRequestUuid";
  2013. String issueKey = "issueKey";
  2014. userSession.logIn(db.users().insertUser());
  2015. ProjectData project = db.components().insertPublicProject();
  2016. db.getDbClient().branchDao().insert(session, new BranchDto()
  2017. .setUuid(pullRequestUuid)
  2018. .setProjectUuid(project.projectUuid())
  2019. .setKey(pullRequestId)
  2020. .setIsMain(false)
  2021. .setBranchType(BranchType.PULL_REQUEST)
  2022. .setMergeBranchUuid(project.mainBranchUuid()));
  2023. TestRequest request = ws.newRequest().setParam("components", project.projectKey()).setParam("fixedInPullRequest", pullRequestId);
  2024. insertIssues(project.getMainBranchComponent(), i -> i.setKee(issueKey));
  2025. db.getDbClient().issueFixedDao().insert(session, new IssueFixedDto(pullRequestUuid, issueKey));
  2026. session.commit();
  2027. indexPermissionsAndIssues();
  2028. SearchWsResponse response = request.executeProtobuf(SearchWsResponse.class);
  2029. List<Issue> issuesList = response.getIssuesList();
  2030. assertThat(issuesList).hasSize(1);
  2031. assertThat(issuesList.get(0).getKey()).isEqualTo(issueKey);
  2032. }
  2033. private RuleDto newIssueRule() {
  2034. RuleDto rule = newRule(XOO_X1, createDefaultRuleDescriptionSection(uuidFactory.create(), "Rule desc"))
  2035. .setLanguage("xoo")
  2036. .setName("Rule name")
  2037. .setStatus(RuleStatus.READY);
  2038. db.rules().insert(rule);
  2039. return rule;
  2040. }
  2041. private RuleDto newIssueRule(String ruleKey, Consumer<RuleDto> consumer) {
  2042. RuleDto rule = newRule(RuleKey.of("xoo", ruleKey),
  2043. createDefaultRuleDescriptionSection(uuidFactory.create(), "Rule desc"))
  2044. .setLanguage("xoo")
  2045. .setName("Rule name")
  2046. .setStatus(RuleStatus.READY);
  2047. consumer.accept(rule);
  2048. db.rules().insert(rule);
  2049. return rule;
  2050. }
  2051. private RuleDto newHotspotRule() {
  2052. RuleDto rule = newRule(XOO_X2, createDefaultRuleDescriptionSection(uuidFactory.create(), "Rule desc"))
  2053. .setLanguage("xoo")
  2054. .setName("Rule name")
  2055. .setStatus(RuleStatus.READY)
  2056. .setType(SECURITY_HOTSPOT_VALUE);
  2057. db.rules().insert(rule);
  2058. return rule;
  2059. }
  2060. private void indexPermissions() {
  2061. permissionIndexer.indexAll(permissionIndexer.getIndexTypes());
  2062. }
  2063. private void indexIssues() {
  2064. issueIndexer.indexAllIssues();
  2065. }
  2066. private void grantPermissionToAnyone(ProjectDto project, String permission) {
  2067. dbClient.groupPermissionDao().insert(session,
  2068. new GroupPermissionDto()
  2069. .setUuid(Uuids.createFast())
  2070. .setGroupUuid(null)
  2071. .setEntityUuid(project.getUuid())
  2072. .setEntityName(project.getName())
  2073. .setRole(permission),
  2074. project, null);
  2075. session.commit();
  2076. userSession.logIn().addProjectPermission(permission, project);
  2077. }
  2078. private void insertIssues(Consumer<IssueDto>... populators) {
  2079. UserDto john = db.users().insertUser();
  2080. userSession.logIn(john);
  2081. RuleDto rule = db.rules().insertIssueRule();
  2082. ComponentDto branch = db.components().insertPublicProject().getMainBranchComponent();
  2083. ComponentDto file = db.components().insertComponent(newFileDto(branch));
  2084. for (Consumer<IssueDto> populator : populators) {
  2085. db.issues().insertIssue(rule, branch, file, populator);
  2086. }
  2087. }
  2088. private void insertIssues(ComponentDto branch, Consumer<IssueDto>... populators) {
  2089. UserDto john = db.users().insertUser();
  2090. userSession.logIn(john);
  2091. RuleDto rule = db.rules().insertIssueRule();
  2092. ComponentDto file = db.components().insertComponent(newFileDto(branch));
  2093. for (Consumer<IssueDto> populator : populators) {
  2094. db.issues().insertIssue(rule, branch, file, populator);
  2095. }
  2096. }
  2097. private void indexPermissionsAndIssues() {
  2098. indexPermissions();
  2099. indexIssues();
  2100. }
  2101. }