You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

AssignActionTest.java 11KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2019 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.issue.ws;
  21. import java.util.Optional;
  22. import javax.annotation.Nullable;
  23. import org.junit.Rule;
  24. import org.junit.Test;
  25. import org.junit.rules.ExpectedException;
  26. import org.sonar.api.rules.RuleType;
  27. import org.sonar.api.utils.internal.TestSystem2;
  28. import org.sonar.db.DbClient;
  29. import org.sonar.db.DbSession;
  30. import org.sonar.db.DbTester;
  31. import org.sonar.db.issue.IssueDto;
  32. import org.sonar.db.organization.OrganizationDto;
  33. import org.sonar.db.user.UserDto;
  34. import org.sonar.server.es.EsTester;
  35. import org.sonar.server.exceptions.ForbiddenException;
  36. import org.sonar.server.exceptions.NotFoundException;
  37. import org.sonar.server.exceptions.UnauthorizedException;
  38. import org.sonar.server.issue.IssueFieldsSetter;
  39. import org.sonar.server.issue.IssueFinder;
  40. import org.sonar.server.issue.WebIssueStorage;
  41. import org.sonar.server.issue.IssueUpdater;
  42. import org.sonar.server.issue.TestIssueChangePostProcessor;
  43. import org.sonar.server.issue.index.IssueIndexer;
  44. import org.sonar.server.issue.index.IssueIteratorFactory;
  45. import org.sonar.server.notification.NotificationManager;
  46. import org.sonar.server.organization.DefaultOrganizationProvider;
  47. import org.sonar.server.organization.TestDefaultOrganizationProvider;
  48. import org.sonar.server.rule.DefaultRuleFinder;
  49. import org.sonar.server.tester.UserSessionRule;
  50. import org.sonar.server.ws.WsActionTester;
  51. import static org.assertj.core.api.Assertions.assertThat;
  52. import static org.junit.rules.ExpectedException.none;
  53. import static org.mockito.Mockito.mock;
  54. import static org.sonar.api.web.UserRole.CODEVIEWER;
  55. import static org.sonar.api.web.UserRole.USER;
  56. import static org.sonar.server.tester.UserSessionRule.standalone;
  57. public class AssignActionTest {
  58. private static final String PREVIOUS_ASSIGNEE = "previous";
  59. private static final String CURRENT_USER_LOGIN = "john";
  60. private static final String CURRENT_USER_UUID = "1";
  61. private static final long PAST = 10_000_000_000L;
  62. private static final long NOW = 50_000_000_000L;
  63. private TestSystem2 system2 = new TestSystem2().setNow(NOW);
  64. @Rule
  65. public ExpectedException expectedException = none();
  66. @Rule
  67. public UserSessionRule userSession = standalone();
  68. @Rule
  69. public EsTester es = EsTester.create();
  70. @Rule
  71. public DbTester db = DbTester.create(system2);
  72. public DbClient dbClient = db.getDbClient();
  73. private DbSession session = db.getSession();
  74. private DefaultOrganizationProvider defaultOrganizationProvider = TestDefaultOrganizationProvider.from(db);
  75. private IssueIndexer issueIndexer = new IssueIndexer(es.client(), dbClient, new IssueIteratorFactory(dbClient));
  76. private OperationResponseWriter responseWriter = mock(OperationResponseWriter.class);
  77. private TestIssueChangePostProcessor issueChangePostProcessor = new TestIssueChangePostProcessor();
  78. private AssignAction underTest = new AssignAction(system2, userSession, dbClient, new IssueFinder(dbClient, userSession), new IssueFieldsSetter(),
  79. new IssueUpdater(dbClient,
  80. new WebIssueStorage(system2, dbClient, new DefaultRuleFinder(dbClient, defaultOrganizationProvider), issueIndexer),
  81. mock(NotificationManager.class), issueChangePostProcessor),
  82. responseWriter);
  83. private WsActionTester ws = new WsActionTester(underTest);
  84. @Test
  85. public void assign_to_someone() {
  86. IssueDto issue = newIssueWithBrowsePermission();
  87. UserDto arthur = insertUser("arthur");
  88. ws.newRequest()
  89. .setParam("issue", issue.getKey())
  90. .setParam("assignee", "arthur")
  91. .execute();
  92. checkIssueAssignee(issue.getKey(), arthur.getUuid());
  93. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  94. assertThat(optionalIssueDto).isPresent();
  95. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(arthur.getUuid());
  96. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  97. }
  98. @Test
  99. public void assign_to_me() {
  100. IssueDto issue = newIssueWithBrowsePermission();
  101. ws.newRequest()
  102. .setParam("issue", issue.getKey())
  103. .setParam("assignee", "_me")
  104. .execute();
  105. checkIssueAssignee(issue.getKey(), CURRENT_USER_UUID);
  106. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  107. assertThat(optionalIssueDto).isPresent();
  108. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(CURRENT_USER_UUID);
  109. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  110. }
  111. @Test
  112. public void assign_to_me_using_deprecated_me_param() {
  113. IssueDto issue = newIssueWithBrowsePermission();
  114. ws.newRequest()
  115. .setParam("issue", issue.getKey())
  116. .setParam("me", "true")
  117. .execute();
  118. checkIssueAssignee(issue.getKey(), CURRENT_USER_UUID);
  119. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  120. assertThat(optionalIssueDto).isPresent();
  121. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(CURRENT_USER_UUID);
  122. }
  123. @Test
  124. public void unassign() {
  125. IssueDto issue = newIssueWithBrowsePermission();
  126. ws.newRequest()
  127. .setParam("issue", issue.getKey())
  128. .execute();
  129. checkIssueAssignee(issue.getKey(), null);
  130. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  131. assertThat(optionalIssueDto).isPresent();
  132. assertThat(optionalIssueDto.get().getAssigneeUuid()).isNull();
  133. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  134. }
  135. @Test
  136. public void unassign_with_empty_assignee_param() {
  137. IssueDto issue = newIssueWithBrowsePermission();
  138. ws.newRequest()
  139. .setParam("issue", issue.getKey())
  140. .setParam("assignee", "")
  141. .execute();
  142. checkIssueAssignee(issue.getKey(), null);
  143. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  144. assertThat(optionalIssueDto).isPresent();
  145. assertThat(optionalIssueDto.get().getAssigneeUuid()).isNull();
  146. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  147. }
  148. @Test
  149. public void nothing_to_do_when_new_assignee_is_same_as_old_one() {
  150. UserDto user = insertUser("Bob");
  151. IssueDto issue = newIssue(user.getUuid());
  152. setUserWithBrowsePermission(issue);
  153. ws.newRequest()
  154. .setParam("issue", issue.getKey())
  155. .setParam("assignee", user.getLogin())
  156. .execute();
  157. IssueDto issueReloaded = dbClient.issueDao().selectByKey(db.getSession(), issue.getKey()).get();
  158. assertThat(issueReloaded.getAssigneeUuid()).isEqualTo(user.getUuid());
  159. assertThat(issueReloaded.getUpdatedAt()).isEqualTo(PAST);
  160. assertThat(issueReloaded.getIssueUpdateTime()).isEqualTo(PAST);
  161. }
  162. @Test
  163. public void fail_when_assignee_does_not_exist() {
  164. IssueDto issue = newIssueWithBrowsePermission();
  165. expectedException.expect(NotFoundException.class);
  166. ws.newRequest()
  167. .setParam("issue", issue.getKey())
  168. .setParam("assignee", "unknown")
  169. .execute();
  170. }
  171. @Test
  172. public void fail_when_trying_to_assign_hotspot() {
  173. IssueDto issueDto = db.issues().insertIssue(i -> i.setType(RuleType.SECURITY_HOTSPOT));
  174. setUserWithBrowsePermission(issueDto);
  175. UserDto arthur = insertUser("arthur");
  176. expectedException.expect(IllegalArgumentException.class);
  177. expectedException.expectMessage("It is not allowed to assign a security hotspot");
  178. ws.newRequest()
  179. .setParam("issue", issueDto.getKey())
  180. .setParam("assignee", "arthur")
  181. .execute();
  182. }
  183. @Test
  184. public void fail_when_assignee_is_disabled() {
  185. IssueDto issue = newIssueWithBrowsePermission();
  186. db.users().insertUser(user -> user.setActive(false));
  187. expectedException.expect(NotFoundException.class);
  188. ws.newRequest()
  189. .setParam("issue", issue.getKey())
  190. .setParam("assignee", "unknown")
  191. .execute();
  192. }
  193. @Test
  194. public void fail_when_not_authenticated() {
  195. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  196. userSession.anonymous();
  197. expectedException.expect(UnauthorizedException.class);
  198. ws.newRequest()
  199. .setParam("issue", issue.getKey())
  200. .setParam("assignee", "_me")
  201. .execute();
  202. }
  203. @Test
  204. public void fail_when_missing_browse_permission() {
  205. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  206. setUserWithPermission(issue, CODEVIEWER);
  207. expectedException.expect(ForbiddenException.class);
  208. ws.newRequest()
  209. .setParam("issue", issue.getKey())
  210. .setParam("assignee", "_me")
  211. .execute();
  212. }
  213. @Test
  214. public void fail_when_assignee_is_not_member_of_organization_of_project_issue() {
  215. OrganizationDto org = db.organizations().insert(organizationDto -> organizationDto.setKey("Organization key"));
  216. IssueDto issueDto = db.issues().insertIssue(org, i -> i.setType(RuleType.CODE_SMELL));
  217. setUserWithBrowsePermission(issueDto);
  218. OrganizationDto otherOrganization = db.organizations().insert();
  219. UserDto assignee = db.users().insertUser("arthur");
  220. db.organizations().addMember(otherOrganization, assignee);
  221. expectedException.expect(IllegalArgumentException.class);
  222. expectedException.expectMessage("User 'arthur' is not member of organization 'Organization key'");
  223. ws.newRequest()
  224. .setParam("issue", issueDto.getKey())
  225. .setParam("assignee", "arthur")
  226. .execute();
  227. }
  228. private UserDto insertUser(String login) {
  229. UserDto user = db.users().insertUser(login);
  230. db.organizations().addMember(db.getDefaultOrganization(), user);
  231. return user;
  232. }
  233. private IssueDto newIssue(String assignee) {
  234. IssueDto issue = db.issues().insertIssue(
  235. issueDto -> issueDto
  236. .setAssigneeUuid(assignee)
  237. .setCreatedAt(PAST).setIssueCreationTime(PAST)
  238. .setUpdatedAt(PAST).setIssueUpdateTime(PAST)
  239. .setType(RuleType.CODE_SMELL));
  240. return issue;
  241. }
  242. private IssueDto newIssueWithBrowsePermission() {
  243. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  244. setUserWithBrowsePermission(issue);
  245. return issue;
  246. }
  247. private void setUserWithBrowsePermission(IssueDto issue) {
  248. setUserWithPermission(issue, USER);
  249. }
  250. private void setUserWithPermission(IssueDto issue, String permission) {
  251. insertUser(CURRENT_USER_LOGIN);
  252. userSession.logIn(CURRENT_USER_LOGIN)
  253. .addProjectPermission(permission,
  254. dbClient.componentDao().selectByUuid(db.getSession(), issue.getProjectUuid()).get(),
  255. dbClient.componentDao().selectByUuid(db.getSession(), issue.getComponentUuid()).get());
  256. }
  257. private void checkIssueAssignee(String issueKey, @Nullable String expectedAssignee) {
  258. IssueDto issueReloaded = dbClient.issueDao().selectByKey(db.getSession(), issueKey).get();
  259. assertThat(issueReloaded.getAssigneeUuid()).isEqualTo(expectedAssignee);
  260. assertThat(issueReloaded.getIssueUpdateTime()).isEqualTo(NOW);
  261. assertThat(issueReloaded.getUpdatedAt()).isEqualTo(NOW);
  262. }
  263. }