3 * Copyright (C) 2009-2017 SonarSource SA
4 * mailto:info AT sonarsource DOT com
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 3 of the License, or (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public License
17 * along with this program; if not, write to the Free Software Foundation,
18 * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
20 package org.sonar.server.permission.ws.template;
22 import java.util.Collection;
23 import java.util.HashSet;
24 import java.util.List;
25 import org.sonar.api.i18n.I18n;
26 import org.sonar.api.resources.Qualifiers;
27 import org.sonar.api.resources.ResourceTypes;
28 import org.sonar.api.server.ws.Request;
29 import org.sonar.api.server.ws.Response;
30 import org.sonar.api.server.ws.WebService;
31 import org.sonar.api.server.ws.WebService.Param;
32 import org.sonar.db.DbClient;
33 import org.sonar.db.DbSession;
34 import org.sonar.db.component.ComponentDto;
35 import org.sonar.db.component.ComponentQuery;
36 import org.sonar.db.permission.template.PermissionTemplateDto;
37 import org.sonar.server.permission.PermissionTemplateService;
38 import org.sonar.server.permission.ws.PermissionWsSupport;
39 import org.sonar.server.permission.ws.PermissionsWsAction;
40 import org.sonar.server.project.Visibility;
41 import org.sonar.server.user.UserSession;
42 import org.sonarqube.ws.client.permission.BulkApplyTemplateWsRequest;
44 import static org.sonar.api.utils.DateUtils.parseDateOrDateTime;
45 import static org.sonar.core.util.Protobuf.setNullable;
46 import static org.sonar.server.permission.PermissionPrivilegeChecker.checkGlobalAdmin;
47 import static org.sonar.server.permission.ws.PermissionsWsParametersBuilder.createTemplateParameters;
48 import static org.sonar.server.permission.ws.template.WsTemplateRef.newTemplateRef;
49 import static org.sonar.server.ws.KeyExamples.KEY_PROJECT_EXAMPLE_001;
50 import static org.sonar.server.ws.KeyExamples.KEY_PROJECT_EXAMPLE_002;
51 import static org.sonar.server.ws.WsParameterBuilder.QualifierParameterContext.newQualifierParameterContext;
52 import static org.sonar.server.ws.WsParameterBuilder.createRootQualifiersParameter;
53 import static org.sonarqube.ws.client.permission.PermissionsWsParameters.PARAM_ORGANIZATION;
54 import static org.sonarqube.ws.client.permission.PermissionsWsParameters.PARAM_QUALIFIER;
55 import static org.sonarqube.ws.client.permission.PermissionsWsParameters.PARAM_TEMPLATE_ID;
56 import static org.sonarqube.ws.client.permission.PermissionsWsParameters.PARAM_TEMPLATE_NAME;
57 import static org.sonarqube.ws.client.project.ProjectsWsParameters.PARAM_ANALYZED_BEFORE;
58 import static org.sonarqube.ws.client.project.ProjectsWsParameters.PARAM_ON_PROVISIONED_ONLY;
59 import static org.sonarqube.ws.client.project.ProjectsWsParameters.PARAM_PROJECTS;
60 import static org.sonarqube.ws.client.project.ProjectsWsParameters.PARAM_QUALIFIERS;
61 import static org.sonarqube.ws.client.project.ProjectsWsParameters.PARAM_VISIBILITY;
63 public class BulkApplyTemplateAction implements PermissionsWsAction {
65 private final DbClient dbClient;
66 private final UserSession userSession;
67 private final PermissionTemplateService permissionTemplateService;
68 private final PermissionWsSupport wsSupport;
69 private final I18n i18n;
70 private final ResourceTypes resourceTypes;
72 public BulkApplyTemplateAction(DbClient dbClient, UserSession userSession, PermissionTemplateService permissionTemplateService, PermissionWsSupport wsSupport, I18n i18n,
73 ResourceTypes resourceTypes) {
74 this.dbClient = dbClient;
75 this.userSession = userSession;
76 this.permissionTemplateService = permissionTemplateService;
77 this.wsSupport = wsSupport;
79 this.resourceTypes = resourceTypes;
83 public void define(WebService.NewController context) {
84 WebService.NewAction action = context.createAction("bulk_apply_template")
85 .setDescription("Apply a permission template to several projects.<br />" +
86 "The template id or name must be provided.<br />" +
87 "Requires the following permission: 'Administer System'.")
92 action.createParam(Param.TEXT_QUERY)
93 .setDescription("Limit search to: <ul>" +
94 "<li>project names that contain the supplied string</li>" +
95 "<li>project keys that are exactly the same as the supplied string</li>" +
97 .setExampleValue("apac");
99 createRootQualifiersParameter(action, newQualifierParameterContext(i18n, resourceTypes))
100 .setDefaultValue(Qualifiers.PROJECT)
101 .setDeprecatedKey(PARAM_QUALIFIER, "6.6");
103 createTemplateParameters(action);
106 .createParam(PARAM_PROJECTS)
107 .setDescription("Comma-separated list of project keys")
109 .setExampleValue(String.join(",", KEY_PROJECT_EXAMPLE_001, KEY_PROJECT_EXAMPLE_002));
111 action.createParam(PARAM_VISIBILITY)
112 .setDescription("Filter the projects that should be visible to everyone (%s), or only specific user/groups (%s).<br/>" +
113 "If no visibility is specified, the default project visibility of the organization will be used.",
114 Visibility.PUBLIC.getLabel(), Visibility.PRIVATE.getLabel())
118 .setPossibleValues(Visibility.getLabels());
120 action.createParam(PARAM_ANALYZED_BEFORE)
121 .setDescription("Filter the projects for which last analysis is older than the given date (exclusive).<br> " +
122 "Either a date (server timezone) or datetime can be provided.")
124 .setExampleValue("2017-10-19 or 2017-10-19T13:00:00+0200")
127 action.createParam(PARAM_ON_PROVISIONED_ONLY)
128 .setDescription("Filter the projects that are provisioned")
129 .setBooleanPossibleValues()
130 .setDefaultValue("false")
135 public void handle(Request request, Response response) throws Exception {
136 doHandle(toBulkApplyTemplateWsRequest(request));
137 response.noContent();
140 private void doHandle(BulkApplyTemplateWsRequest request) {
141 try (DbSession dbSession = dbClient.openSession(false)) {
142 PermissionTemplateDto template = wsSupport.findTemplate(dbSession, newTemplateRef(
143 request.getTemplateId(), request.getOrganization(), request.getTemplateName()));
144 checkGlobalAdmin(userSession, template.getOrganizationUuid());
146 ComponentQuery componentQuery = buildDbQuery(request);
147 List<ComponentDto> projects = dbClient.componentDao().selectByQuery(dbSession, template.getOrganizationUuid(), componentQuery, 0, Integer.MAX_VALUE);
149 permissionTemplateService.applyAndCommit(dbSession, template, projects);
153 private static BulkApplyTemplateWsRequest toBulkApplyTemplateWsRequest(Request request) {
154 return new BulkApplyTemplateWsRequest()
155 .setOrganization(request.param(PARAM_ORGANIZATION))
156 .setTemplateId(request.param(PARAM_TEMPLATE_ID))
157 .setTemplateName(request.param(PARAM_TEMPLATE_NAME))
158 .setQualifiers(request.mandatoryParamAsStrings(PARAM_QUALIFIERS))
159 .setQuery(request.param(Param.TEXT_QUERY))
160 .setVisibility(request.param(PARAM_VISIBILITY))
161 .setOnProvisionedOnly(request.mandatoryParamAsBoolean(PARAM_ON_PROVISIONED_ONLY))
162 .setAnalyzedBefore(request.param(PARAM_ANALYZED_BEFORE))
163 .setProjects(request.paramAsStrings(PARAM_PROJECTS));
166 private static ComponentQuery buildDbQuery(BulkApplyTemplateWsRequest request) {
167 Collection<String> qualifiers = request.getQualifiers();
168 ComponentQuery.Builder query = ComponentQuery.builder()
169 .setQualifiers(qualifiers.toArray(new String[qualifiers.size()]));
171 setNullable(request.getQuery(), q -> {
172 query.setNameOrKeyQuery(q);
173 query.setPartialMatchOnKey(true);
176 setNullable(request.getVisibility(), v -> query.setPrivate(Visibility.isPrivate(v)));
177 setNullable(request.getAnalyzedBefore(), d -> query.setAnalyzedBefore(parseDateOrDateTime(d).getTime()));
178 setNullable(request.isOnProvisionedOnly(), query::setOnProvisionedOnly);
179 setNullable(request.getProjects(), keys -> query.setComponentKeys(new HashSet<>(keys)));
181 return query.build();