You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

SetSeverityActionIT.java 11KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2023 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.issue.ws;
  21. import java.util.List;
  22. import javax.annotation.Nullable;
  23. import org.junit.Rule;
  24. import org.junit.Test;
  25. import org.mockito.ArgumentCaptor;
  26. import org.sonar.api.server.ws.Request;
  27. import org.sonar.api.server.ws.Response;
  28. import org.sonar.api.server.ws.WebService;
  29. import org.sonar.api.utils.System2;
  30. import org.sonar.core.issue.FieldDiffs;
  31. import org.sonar.core.util.SequenceUuidFactory;
  32. import org.sonar.db.DbClient;
  33. import org.sonar.db.DbTester;
  34. import org.sonar.db.component.BranchDto;
  35. import org.sonar.db.component.BranchType;
  36. import org.sonar.db.component.ComponentDto;
  37. import org.sonar.db.issue.IssueDbTester;
  38. import org.sonar.db.issue.IssueDto;
  39. import org.sonar.db.project.ProjectDto;
  40. import org.sonar.db.rule.RuleDto;
  41. import org.sonar.db.user.UserDto;
  42. import org.sonar.server.es.EsTester;
  43. import org.sonar.server.exceptions.ForbiddenException;
  44. import org.sonar.server.exceptions.NotFoundException;
  45. import org.sonar.server.exceptions.UnauthorizedException;
  46. import org.sonar.server.issue.IssueFieldsSetter;
  47. import org.sonar.server.issue.IssueFinder;
  48. import org.sonar.server.issue.TestIssueChangePostProcessor;
  49. import org.sonar.server.issue.WebIssueStorage;
  50. import org.sonar.server.issue.index.IssueIndexer;
  51. import org.sonar.server.issue.index.IssueIteratorFactory;
  52. import org.sonar.server.issue.notification.IssuesChangesNotificationSerializer;
  53. import org.sonar.server.notification.NotificationManager;
  54. import org.sonar.server.pushapi.issues.IssueChangeEventService;
  55. import org.sonar.server.rule.DefaultRuleFinder;
  56. import org.sonar.server.rule.RuleDescriptionFormatter;
  57. import org.sonar.server.tester.UserSessionRule;
  58. import org.sonar.server.ws.TestRequest;
  59. import org.sonar.server.ws.TestResponse;
  60. import org.sonar.server.ws.WsActionTester;
  61. import static java.lang.String.format;
  62. import static java.util.Optional.ofNullable;
  63. import static org.assertj.core.api.Assertions.assertThat;
  64. import static org.assertj.core.api.Assertions.assertThatThrownBy;
  65. import static org.mockito.ArgumentMatchers.any;
  66. import static org.mockito.ArgumentMatchers.eq;
  67. import static org.mockito.Mockito.mock;
  68. import static org.mockito.Mockito.verify;
  69. import static org.mockito.Mockito.verifyNoInteractions;
  70. import static org.sonar.api.rule.Severity.MAJOR;
  71. import static org.sonar.api.rule.Severity.MINOR;
  72. import static org.sonar.api.rules.RuleType.CODE_SMELL;
  73. import static org.sonar.api.web.UserRole.ISSUE_ADMIN;
  74. import static org.sonar.api.web.UserRole.USER;
  75. import static org.sonar.db.component.ComponentTesting.newFileDto;
  76. import static org.sonar.db.issue.IssueTesting.newIssue;
  77. public class SetSeverityActionIT {
  78. @Rule
  79. public DbTester dbTester = DbTester.create();
  80. @Rule
  81. public EsTester es = EsTester.create();
  82. @Rule
  83. public UserSessionRule userSession = UserSessionRule.standalone();
  84. private System2 system2 = mock(System2.class);
  85. private DbClient dbClient = dbTester.getDbClient();
  86. private IssueDbTester issueDbTester = new IssueDbTester(dbTester);
  87. private OperationResponseWriter responseWriter = mock(OperationResponseWriter.class);
  88. private ArgumentCaptor<SearchResponseData> preloadedSearchResponseDataCaptor = ArgumentCaptor.forClass(SearchResponseData.class);
  89. private IssueChangeEventService issueChangeEventService = mock(IssueChangeEventService.class);
  90. private IssueIndexer issueIndexer = new IssueIndexer(es.client(), dbClient, new IssueIteratorFactory(dbClient), null);
  91. private TestIssueChangePostProcessor issueChangePostProcessor = new TestIssueChangePostProcessor();
  92. private IssuesChangesNotificationSerializer issuesChangesSerializer = new IssuesChangesNotificationSerializer();
  93. private WsActionTester tester = new WsActionTester(new SetSeverityAction(userSession, dbClient, issueChangeEventService,
  94. new IssueFinder(dbClient, userSession), new IssueFieldsSetter(),
  95. new IssueUpdater(dbClient,
  96. new WebIssueStorage(system2, dbClient, new DefaultRuleFinder(dbClient, mock(RuleDescriptionFormatter.class)), issueIndexer, new SequenceUuidFactory()),
  97. mock(NotificationManager.class), issueChangePostProcessor, issuesChangesSerializer),
  98. responseWriter));
  99. @Test
  100. public void set_severity() {
  101. IssueDto issueDto = issueDbTester.insertIssue(i -> i.setSeverity(MAJOR));
  102. setUserWithBrowseAndAdministerIssuePermission(issueDto);
  103. call(issueDto.getKey(), MINOR);
  104. verify(responseWriter).write(eq(issueDto.getKey()), preloadedSearchResponseDataCaptor.capture(), any(Request.class), any(Response.class));
  105. verifyContentOfPreloadedSearchResponseData(issueDto);
  106. verify(issueChangeEventService).distributeIssueChangeEvent(any(), any(), any(), any(), any(), any());
  107. IssueDto issueReloaded = dbClient.issueDao().selectByKey(dbTester.getSession(), issueDto.getKey()).get();
  108. assertThat(issueReloaded.getSeverity()).isEqualTo(MINOR);
  109. assertThat(issueReloaded.isManualSeverity()).isTrue();
  110. assertThat(issueChangePostProcessor.calledComponents())
  111. .extracting(ComponentDto::uuid)
  112. .containsExactlyInAnyOrder(issueDto.getComponentUuid());
  113. }
  114. @Test
  115. public void set_severity_is_not_distributed_for_pull_request() {
  116. RuleDto rule = dbTester.rules().insertIssueRule();
  117. ComponentDto mainBranch = dbTester.components().insertPrivateProject().getMainBranchComponent();
  118. ComponentDto pullRequest = dbTester.components().insertProjectBranch(mainBranch, b -> b.setKey("myBranch1")
  119. .setBranchType(BranchType.PULL_REQUEST)
  120. .setMergeBranchUuid(mainBranch.uuid()));
  121. ComponentDto file = dbTester.components().insertComponent(newFileDto(pullRequest));
  122. IssueDto issue = newIssue(rule, pullRequest, file).setType(CODE_SMELL).setSeverity(MAJOR);
  123. issueDbTester.insertIssue(issue);
  124. setUserWithBrowseAndAdministerIssuePermission(issue);
  125. call(issue.getKey(), MINOR);
  126. verifyNoInteractions(issueChangeEventService);
  127. }
  128. @Test
  129. public void insert_entry_in_changelog_when_setting_severity() {
  130. IssueDto issueDto = issueDbTester.insertIssue(i -> i.setSeverity(MAJOR));
  131. setUserWithBrowseAndAdministerIssuePermission(issueDto);
  132. call(issueDto.getKey(), MINOR);
  133. List<FieldDiffs> fieldDiffs = dbClient.issueChangeDao().selectChangelogByIssue(dbTester.getSession(), issueDto.getKey());
  134. assertThat(fieldDiffs).hasSize(1);
  135. assertThat(fieldDiffs.get(0).diffs()).hasSize(1);
  136. assertThat(fieldDiffs.get(0).diffs().get("severity").newValue()).isEqualTo(MINOR);
  137. assertThat(fieldDiffs.get(0).diffs().get("severity").oldValue()).isEqualTo(MAJOR);
  138. }
  139. @Test
  140. public void fail_if_bad_severity() {
  141. IssueDto issueDto = issueDbTester.insertIssue(i -> i.setSeverity("unknown"));
  142. setUserWithBrowseAndAdministerIssuePermission(issueDto);
  143. assertThatThrownBy(() -> call(issueDto.getKey(), "unknown"))
  144. .isInstanceOf(IllegalArgumentException.class)
  145. .hasMessage("Value of parameter 'severity' (unknown) must be one of: [INFO, MINOR, MAJOR, CRITICAL, BLOCKER]");
  146. }
  147. @Test
  148. public void fail_NFE_if_hotspot() {
  149. IssueDto hotspot = issueDbTester.insertHotspot(h -> h.setSeverity("CRITICAL"));
  150. setUserWithBrowseAndAdministerIssuePermission(hotspot);
  151. String hotspotKey = hotspot.getKey();
  152. assertThatThrownBy(() -> call(hotspotKey, "MAJOR"))
  153. .isInstanceOf(NotFoundException.class)
  154. .hasMessage("Issue with key '%s' does not exist", hotspotKey);
  155. }
  156. @Test
  157. public void fail_when_not_authenticated() {
  158. assertThatThrownBy(() -> call("ABCD", MAJOR))
  159. .isInstanceOf(UnauthorizedException.class);
  160. }
  161. @Test
  162. public void fail_when_missing_browse_permission() {
  163. IssueDto issueDto = issueDbTester.insertIssue();
  164. logInAndAddProjectPermission(issueDto, ISSUE_ADMIN);
  165. assertThatThrownBy(() -> call(issueDto.getKey(), MAJOR))
  166. .isInstanceOf(ForbiddenException.class);
  167. }
  168. @Test
  169. public void fail_when_missing_administer_issue_permission() {
  170. IssueDto issueDto = issueDbTester.insertIssue();
  171. logInAndAddProjectPermission(issueDto, USER);
  172. assertThatThrownBy(() -> call(issueDto.getKey(), MAJOR))
  173. .isInstanceOf(ForbiddenException.class);
  174. }
  175. @Test
  176. public void test_definition() {
  177. WebService.Action action = tester.getDef();
  178. assertThat(action.key()).isEqualTo("set_severity");
  179. assertThat(action.isPost()).isTrue();
  180. assertThat(action.isInternal()).isFalse();
  181. assertThat(action.params()).hasSize(2);
  182. assertThat(action.responseExample()).isNotNull();
  183. }
  184. private TestResponse call(@Nullable String issueKey, @Nullable String severity) {
  185. TestRequest request = tester.newRequest();
  186. ofNullable(issueKey).ifPresent(issue -> request.setParam("issue", issue));
  187. ofNullable(severity).ifPresent(value -> request.setParam("severity", value));
  188. return request.execute();
  189. }
  190. private void logInAndAddProjectPermission(IssueDto issueDto, String permission) {
  191. BranchDto branchDto = dbClient.branchDao().selectByUuid(dbTester.getSession(), issueDto.getProjectUuid())
  192. .orElseThrow(() -> new IllegalStateException(format("Couldn't find branch with uuid : %s", issueDto.getProjectUuid())));
  193. UserDto user = dbTester.users().insertUser("john");
  194. userSession.logIn(user)
  195. .addProjectPermission(permission, dbClient.projectDao().selectByUuid(dbTester.getSession(), branchDto.getProjectUuid())
  196. .orElseThrow(() -> new IllegalStateException(format("Couldn't find project with uuid %s", branchDto.getProjectUuid()))));
  197. }
  198. private void setUserWithBrowseAndAdministerIssuePermission(IssueDto issueDto) {
  199. BranchDto branchDto = dbClient.branchDao().selectByUuid(dbTester.getSession(), issueDto.getProjectUuid())
  200. .orElseThrow(() -> new IllegalStateException(format("Couldn't find branch with uuid : %s", issueDto.getProjectUuid())));
  201. ProjectDto project = dbClient.projectDao().selectByUuid(dbTester.getSession(), branchDto.getProjectUuid())
  202. .orElseThrow(() -> new IllegalStateException(format("Couldn't find project with uuid : %s", branchDto.getProjectUuid())));
  203. UserDto user = dbTester.users().insertUser("john");
  204. userSession.logIn(user)
  205. .addProjectPermission(ISSUE_ADMIN, project)
  206. .addProjectPermission(USER, project)
  207. .registerBranches(branchDto);
  208. }
  209. private void verifyContentOfPreloadedSearchResponseData(IssueDto issue) {
  210. SearchResponseData preloadedSearchResponseData = preloadedSearchResponseDataCaptor.getValue();
  211. assertThat(preloadedSearchResponseData.getIssues())
  212. .extracting(IssueDto::getKey)
  213. .containsOnly(issue.getKey());
  214. assertThat(preloadedSearchResponseData.getRules())
  215. .extracting(RuleDto::getKey)
  216. .containsOnly(issue.getRuleKey());
  217. assertThat(preloadedSearchResponseData.getComponents())
  218. .extracting(ComponentDto::uuid)
  219. .containsOnly(issue.getComponentUuid(), issue.getProjectUuid());
  220. }
  221. }