You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

AssignActionTest.java 12KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2020 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.issue.ws;
  21. import java.util.Optional;
  22. import javax.annotation.Nullable;
  23. import org.junit.Rule;
  24. import org.junit.Test;
  25. import org.junit.rules.ExpectedException;
  26. import org.sonar.api.impl.utils.TestSystem2;
  27. import org.sonar.api.rules.RuleType;
  28. import org.sonar.db.DbClient;
  29. import org.sonar.db.DbSession;
  30. import org.sonar.db.DbTester;
  31. import org.sonar.db.issue.IssueDto;
  32. import org.sonar.db.organization.OrganizationDto;
  33. import org.sonar.db.user.UserDto;
  34. import org.sonar.server.es.EsTester;
  35. import org.sonar.server.exceptions.ForbiddenException;
  36. import org.sonar.server.exceptions.NotFoundException;
  37. import org.sonar.server.exceptions.UnauthorizedException;
  38. import org.sonar.server.issue.IssueFieldsSetter;
  39. import org.sonar.server.issue.IssueFinder;
  40. import org.sonar.server.issue.TestIssueChangePostProcessor;
  41. import org.sonar.server.issue.WebIssueStorage;
  42. import org.sonar.server.issue.index.IssueIndexer;
  43. import org.sonar.server.issue.index.IssueIteratorFactory;
  44. import org.sonar.server.issue.notification.IssuesChangesNotification;
  45. import org.sonar.server.issue.notification.IssuesChangesNotificationSerializer;
  46. import org.sonar.server.notification.NotificationManager;
  47. import org.sonar.server.organization.DefaultOrganizationProvider;
  48. import org.sonar.server.organization.TestDefaultOrganizationProvider;
  49. import org.sonar.server.rule.DefaultRuleFinder;
  50. import org.sonar.server.tester.UserSessionRule;
  51. import org.sonar.server.ws.WsActionTester;
  52. import static org.assertj.core.api.Assertions.assertThat;
  53. import static org.assertj.core.api.Assertions.assertThatThrownBy;
  54. import static org.junit.rules.ExpectedException.none;
  55. import static org.mockito.ArgumentMatchers.any;
  56. import static org.mockito.Mockito.mock;
  57. import static org.mockito.Mockito.verify;
  58. import static org.sonar.api.rules.RuleType.CODE_SMELL;
  59. import static org.sonar.api.rules.RuleType.SECURITY_HOTSPOT;
  60. import static org.sonar.api.web.UserRole.CODEVIEWER;
  61. import static org.sonar.api.web.UserRole.USER;
  62. import static org.sonar.server.tester.UserSessionRule.standalone;
  63. public class AssignActionTest {
  64. private static final String PREVIOUS_ASSIGNEE = "previous";
  65. private static final String CURRENT_USER_LOGIN = "john";
  66. private static final String CURRENT_USER_UUID = "1";
  67. private static final long PAST = 10_000_000_000L;
  68. private static final long NOW = 50_000_000_000L;
  69. private TestSystem2 system2 = new TestSystem2().setNow(NOW);
  70. @Rule
  71. public ExpectedException expectedException = none();
  72. @Rule
  73. public UserSessionRule userSession = standalone();
  74. @Rule
  75. public EsTester es = EsTester.create();
  76. @Rule
  77. public DbTester db = DbTester.create(system2);
  78. public DbClient dbClient = db.getDbClient();
  79. private DbSession session = db.getSession();
  80. private NotificationManager notificationManager = mock(NotificationManager.class);
  81. private DefaultOrganizationProvider defaultOrganizationProvider = TestDefaultOrganizationProvider.from(db);
  82. private IssueIndexer issueIndexer = new IssueIndexer(es.client(), dbClient, new IssueIteratorFactory(dbClient));
  83. private OperationResponseWriter responseWriter = mock(OperationResponseWriter.class);
  84. private TestIssueChangePostProcessor issueChangePostProcessor = new TestIssueChangePostProcessor();
  85. private IssuesChangesNotificationSerializer issuesChangesSerializer = new IssuesChangesNotificationSerializer();
  86. private AssignAction underTest = new AssignAction(system2, userSession, dbClient, new IssueFinder(dbClient, userSession), new IssueFieldsSetter(),
  87. new IssueUpdater(dbClient,
  88. new WebIssueStorage(system2, dbClient, new DefaultRuleFinder(dbClient, defaultOrganizationProvider), issueIndexer),
  89. notificationManager, issueChangePostProcessor, issuesChangesSerializer),
  90. responseWriter);
  91. private WsActionTester ws = new WsActionTester(underTest);
  92. @Test
  93. public void assign_to_someone() {
  94. IssueDto issue = newIssueWithBrowsePermission();
  95. UserDto arthur = insertUser("arthur");
  96. ws.newRequest()
  97. .setParam("issue", issue.getKey())
  98. .setParam("assignee", arthur.getLogin())
  99. .execute();
  100. checkIssueAssignee(issue.getKey(), arthur.getUuid());
  101. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  102. assertThat(optionalIssueDto).isPresent();
  103. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(arthur.getUuid());
  104. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  105. }
  106. @Test
  107. public void assign_to_me() {
  108. IssueDto issue = newIssueWithBrowsePermission();
  109. ws.newRequest()
  110. .setParam("issue", issue.getKey())
  111. .setParam("assignee", "_me")
  112. .execute();
  113. checkIssueAssignee(issue.getKey(), CURRENT_USER_UUID);
  114. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  115. assertThat(optionalIssueDto).isPresent();
  116. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(CURRENT_USER_UUID);
  117. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  118. }
  119. @Test
  120. public void unassign() {
  121. IssueDto issue = newIssueWithBrowsePermission();
  122. ws.newRequest()
  123. .setParam("issue", issue.getKey())
  124. .execute();
  125. checkIssueAssignee(issue.getKey(), null);
  126. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  127. assertThat(optionalIssueDto).isPresent();
  128. assertThat(optionalIssueDto.get().getAssigneeUuid()).isNull();
  129. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  130. }
  131. @Test
  132. public void unassign_with_empty_assignee_param() {
  133. IssueDto issue = newIssueWithBrowsePermission();
  134. ws.newRequest()
  135. .setParam("issue", issue.getKey())
  136. .setParam("assignee", "")
  137. .execute();
  138. checkIssueAssignee(issue.getKey(), null);
  139. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  140. assertThat(optionalIssueDto).isPresent();
  141. assertThat(optionalIssueDto.get().getAssigneeUuid()).isNull();
  142. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  143. }
  144. @Test
  145. public void nothing_to_do_when_new_assignee_is_same_as_old_one() {
  146. UserDto user = insertUser("Bob");
  147. IssueDto issue = newIssue(user.getUuid());
  148. setUserWithBrowsePermission(issue);
  149. ws.newRequest()
  150. .setParam("issue", issue.getKey())
  151. .setParam("assignee", user.getLogin())
  152. .execute();
  153. IssueDto issueReloaded = dbClient.issueDao().selectByKey(db.getSession(), issue.getKey()).get();
  154. assertThat(issueReloaded.getAssigneeUuid()).isEqualTo(user.getUuid());
  155. assertThat(issueReloaded.getUpdatedAt()).isEqualTo(PAST);
  156. assertThat(issueReloaded.getIssueUpdateTime()).isEqualTo(PAST);
  157. }
  158. @Test
  159. public void send_notification() {
  160. IssueDto issue = newIssueWithBrowsePermission();
  161. UserDto arthur = insertUser("arthur");
  162. ws.newRequest()
  163. .setParam("issue", issue.getKey())
  164. .setParam("assignee", arthur.getLogin())
  165. .execute();
  166. verify(notificationManager).scheduleForSending(any(IssuesChangesNotification.class));
  167. }
  168. @Test
  169. public void fail_when_assignee_does_not_exist() {
  170. IssueDto issue = newIssueWithBrowsePermission();
  171. expectedException.expect(NotFoundException.class);
  172. ws.newRequest()
  173. .setParam("issue", issue.getKey())
  174. .setParam("assignee", "unknown")
  175. .execute();
  176. }
  177. @Test
  178. public void fail_when_trying_assign_to_hotspot() {
  179. IssueDto hotspot = db.issues().insertHotspot(
  180. h -> h
  181. .setAssigneeUuid(PREVIOUS_ASSIGNEE)
  182. .setCreatedAt(PAST).setIssueCreationTime(PAST)
  183. .setUpdatedAt(PAST).setIssueUpdateTime(PAST)
  184. );
  185. setUserWithBrowsePermission(hotspot);
  186. UserDto arthur = insertUser("arthur");
  187. assertThatThrownBy(() -> ws.newRequest()
  188. .setParam("issue", hotspot.getKey())
  189. .setParam("assignee", arthur.getLogin())
  190. .execute())
  191. .isInstanceOf(NotFoundException.class)
  192. .hasMessage("Issue with key '%s' does not exist", hotspot.getKey());
  193. }
  194. @Test
  195. public void fail_when_assignee_is_disabled() {
  196. IssueDto issue = newIssueWithBrowsePermission();
  197. db.users().insertUser(user -> user.setActive(false));
  198. expectedException.expect(NotFoundException.class);
  199. ws.newRequest()
  200. .setParam("issue", issue.getKey())
  201. .setParam("assignee", "unknown")
  202. .execute();
  203. }
  204. @Test
  205. public void fail_when_not_authenticated() {
  206. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  207. userSession.anonymous();
  208. expectedException.expect(UnauthorizedException.class);
  209. ws.newRequest()
  210. .setParam("issue", issue.getKey())
  211. .setParam("assignee", "_me")
  212. .execute();
  213. }
  214. @Test
  215. public void fail_when_missing_browse_permission() {
  216. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  217. setUserWithPermission(issue, CODEVIEWER);
  218. expectedException.expect(ForbiddenException.class);
  219. ws.newRequest()
  220. .setParam("issue", issue.getKey())
  221. .setParam("assignee", "_me")
  222. .execute();
  223. }
  224. @Test
  225. public void fail_when_assignee_is_not_member_of_organization_of_project_issue() {
  226. OrganizationDto org = db.organizations().insert(organizationDto -> organizationDto.setKey("Organization key"));
  227. IssueDto issueDto = db.issues().insertIssue(org, i -> i.setType(CODE_SMELL));
  228. setUserWithBrowsePermission(issueDto);
  229. OrganizationDto otherOrganization = db.organizations().insert();
  230. UserDto assignee = db.users().insertUser("arthur");
  231. db.organizations().addMember(otherOrganization, assignee);
  232. expectedException.expect(IllegalArgumentException.class);
  233. expectedException.expectMessage("User 'arthur' is not member of organization 'Organization key'");
  234. ws.newRequest()
  235. .setParam("issue", issueDto.getKey())
  236. .setParam("assignee", "arthur")
  237. .execute();
  238. }
  239. private UserDto insertUser(String login) {
  240. UserDto user = db.users().insertUser(login);
  241. db.organizations().addMember(db.getDefaultOrganization(), user);
  242. return user;
  243. }
  244. private IssueDto newIssue(String assignee) {
  245. return newIssue(assignee, CODE_SMELL);
  246. }
  247. private IssueDto newIssue(String assignee, RuleType ruleType) {
  248. return db.issues().insertIssue(
  249. issueDto -> issueDto
  250. .setAssigneeUuid(assignee)
  251. .setCreatedAt(PAST).setIssueCreationTime(PAST)
  252. .setUpdatedAt(PAST).setIssueUpdateTime(PAST)
  253. .setType(ruleType));
  254. }
  255. private IssueDto newIssueWithBrowsePermission() {
  256. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  257. setUserWithBrowsePermission(issue);
  258. return issue;
  259. }
  260. private void setUserWithBrowsePermission(IssueDto issue) {
  261. setUserWithPermission(issue, USER);
  262. }
  263. private void setUserWithPermission(IssueDto issue, String permission) {
  264. UserDto user = insertUser(CURRENT_USER_LOGIN);
  265. userSession.logIn(user)
  266. .addProjectPermission(permission,
  267. dbClient.componentDao().selectByUuid(db.getSession(), issue.getProjectUuid()).get(),
  268. dbClient.componentDao().selectByUuid(db.getSession(), issue.getComponentUuid()).get());
  269. }
  270. private void checkIssueAssignee(String issueKey, @Nullable String expectedAssignee) {
  271. IssueDto issueReloaded = dbClient.issueDao().selectByKey(db.getSession(), issueKey).get();
  272. assertThat(issueReloaded.getAssigneeUuid()).isEqualTo(expectedAssignee);
  273. assertThat(issueReloaded.getIssueUpdateTime()).isEqualTo(NOW);
  274. assertThat(issueReloaded.getUpdatedAt()).isEqualTo(NOW);
  275. }
  276. }