You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

AssignActionTest.java 11KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2019 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.issue.ws;
  21. import java.util.Optional;
  22. import javax.annotation.Nullable;
  23. import org.junit.Rule;
  24. import org.junit.Test;
  25. import org.junit.rules.ExpectedException;
  26. import org.sonar.api.rules.RuleType;
  27. import org.sonar.api.utils.internal.TestSystem2;
  28. import org.sonar.db.DbClient;
  29. import org.sonar.db.DbSession;
  30. import org.sonar.db.DbTester;
  31. import org.sonar.db.issue.IssueDto;
  32. import org.sonar.db.organization.OrganizationDto;
  33. import org.sonar.db.user.UserDto;
  34. import org.sonar.server.es.EsTester;
  35. import org.sonar.server.exceptions.ForbiddenException;
  36. import org.sonar.server.exceptions.NotFoundException;
  37. import org.sonar.server.exceptions.UnauthorizedException;
  38. import org.sonar.server.issue.IssueFieldsSetter;
  39. import org.sonar.server.issue.IssueFinder;
  40. import org.sonar.server.issue.IssueUpdater;
  41. import org.sonar.server.issue.TestIssueChangePostProcessor;
  42. import org.sonar.server.issue.WebIssueStorage;
  43. import org.sonar.server.issue.index.IssueIndexer;
  44. import org.sonar.server.issue.index.IssueIteratorFactory;
  45. import org.sonar.server.notification.NotificationManager;
  46. import org.sonar.server.organization.DefaultOrganizationProvider;
  47. import org.sonar.server.organization.TestDefaultOrganizationProvider;
  48. import org.sonar.server.rule.DefaultRuleFinder;
  49. import org.sonar.server.tester.UserSessionRule;
  50. import org.sonar.server.ws.WsActionTester;
  51. import static org.assertj.core.api.Assertions.assertThat;
  52. import static org.junit.rules.ExpectedException.none;
  53. import static org.mockito.Mockito.mock;
  54. import static org.sonar.api.web.UserRole.CODEVIEWER;
  55. import static org.sonar.api.web.UserRole.USER;
  56. import static org.sonar.server.tester.UserSessionRule.standalone;
  57. public class AssignActionTest {
  58. private static final String PREVIOUS_ASSIGNEE = "previous";
  59. private static final String CURRENT_USER_LOGIN = "john";
  60. private static final String CURRENT_USER_UUID = "1";
  61. private static final long PAST = 10_000_000_000L;
  62. private static final long NOW = 50_000_000_000L;
  63. private TestSystem2 system2 = new TestSystem2().setNow(NOW);
  64. @Rule
  65. public ExpectedException expectedException = none();
  66. @Rule
  67. public UserSessionRule userSession = standalone();
  68. @Rule
  69. public EsTester es = EsTester.create();
  70. @Rule
  71. public DbTester db = DbTester.create(system2);
  72. public DbClient dbClient = db.getDbClient();
  73. private DbSession session = db.getSession();
  74. private DefaultOrganizationProvider defaultOrganizationProvider = TestDefaultOrganizationProvider.from(db);
  75. private IssueIndexer issueIndexer = new IssueIndexer(es.client(), dbClient, new IssueIteratorFactory(dbClient));
  76. private OperationResponseWriter responseWriter = mock(OperationResponseWriter.class);
  77. private TestIssueChangePostProcessor issueChangePostProcessor = new TestIssueChangePostProcessor();
  78. private AssignAction underTest = new AssignAction(system2, userSession, dbClient, new IssueFinder(dbClient, userSession), new IssueFieldsSetter(),
  79. new IssueUpdater(dbClient,
  80. new WebIssueStorage(system2, dbClient, new DefaultRuleFinder(dbClient, defaultOrganizationProvider), issueIndexer),
  81. mock(NotificationManager.class), issueChangePostProcessor),
  82. responseWriter);
  83. private WsActionTester ws = new WsActionTester(underTest);
  84. @Test
  85. public void assign_to_someone() {
  86. IssueDto issue = newIssueWithBrowsePermission();
  87. UserDto arthur = insertUser("arthur");
  88. ws.newRequest()
  89. .setParam("issue", issue.getKey())
  90. .setParam("assignee", "arthur")
  91. .execute();
  92. checkIssueAssignee(issue.getKey(), arthur.getUuid());
  93. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  94. assertThat(optionalIssueDto).isPresent();
  95. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(arthur.getUuid());
  96. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  97. }
  98. @Test
  99. public void assign_to_me() {
  100. IssueDto issue = newIssueWithBrowsePermission();
  101. ws.newRequest()
  102. .setParam("issue", issue.getKey())
  103. .setParam("assignee", "_me")
  104. .execute();
  105. checkIssueAssignee(issue.getKey(), CURRENT_USER_UUID);
  106. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  107. assertThat(optionalIssueDto).isPresent();
  108. assertThat(optionalIssueDto.get().getAssigneeUuid()).isEqualTo(CURRENT_USER_UUID);
  109. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  110. }
  111. @Test
  112. public void unassign() {
  113. IssueDto issue = newIssueWithBrowsePermission();
  114. ws.newRequest()
  115. .setParam("issue", issue.getKey())
  116. .execute();
  117. checkIssueAssignee(issue.getKey(), null);
  118. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  119. assertThat(optionalIssueDto).isPresent();
  120. assertThat(optionalIssueDto.get().getAssigneeUuid()).isNull();
  121. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  122. }
  123. @Test
  124. public void unassign_with_empty_assignee_param() {
  125. IssueDto issue = newIssueWithBrowsePermission();
  126. ws.newRequest()
  127. .setParam("issue", issue.getKey())
  128. .setParam("assignee", "")
  129. .execute();
  130. checkIssueAssignee(issue.getKey(), null);
  131. Optional<IssueDto> optionalIssueDto = dbClient.issueDao().selectByKey(session, issue.getKey());
  132. assertThat(optionalIssueDto).isPresent();
  133. assertThat(optionalIssueDto.get().getAssigneeUuid()).isNull();
  134. assertThat(issueChangePostProcessor.wasCalled()).isFalse();
  135. }
  136. @Test
  137. public void nothing_to_do_when_new_assignee_is_same_as_old_one() {
  138. UserDto user = insertUser("Bob");
  139. IssueDto issue = newIssue(user.getUuid());
  140. setUserWithBrowsePermission(issue);
  141. ws.newRequest()
  142. .setParam("issue", issue.getKey())
  143. .setParam("assignee", user.getLogin())
  144. .execute();
  145. IssueDto issueReloaded = dbClient.issueDao().selectByKey(db.getSession(), issue.getKey()).get();
  146. assertThat(issueReloaded.getAssigneeUuid()).isEqualTo(user.getUuid());
  147. assertThat(issueReloaded.getUpdatedAt()).isEqualTo(PAST);
  148. assertThat(issueReloaded.getIssueUpdateTime()).isEqualTo(PAST);
  149. }
  150. @Test
  151. public void fail_when_assignee_does_not_exist() {
  152. IssueDto issue = newIssueWithBrowsePermission();
  153. expectedException.expect(NotFoundException.class);
  154. ws.newRequest()
  155. .setParam("issue", issue.getKey())
  156. .setParam("assignee", "unknown")
  157. .execute();
  158. }
  159. @Test
  160. public void fail_when_trying_to_assign_hotspot() {
  161. IssueDto issueDto = db.issues().insertIssue(i -> i.setType(RuleType.SECURITY_HOTSPOT));
  162. setUserWithBrowsePermission(issueDto);
  163. UserDto arthur = insertUser("arthur");
  164. expectedException.expect(IllegalArgumentException.class);
  165. expectedException.expectMessage("Assigning security hotspots is not allowed");
  166. ws.newRequest()
  167. .setParam("issue", issueDto.getKey())
  168. .setParam("assignee", "arthur")
  169. .execute();
  170. }
  171. @Test
  172. public void fail_when_assignee_is_disabled() {
  173. IssueDto issue = newIssueWithBrowsePermission();
  174. db.users().insertUser(user -> user.setActive(false));
  175. expectedException.expect(NotFoundException.class);
  176. ws.newRequest()
  177. .setParam("issue", issue.getKey())
  178. .setParam("assignee", "unknown")
  179. .execute();
  180. }
  181. @Test
  182. public void fail_when_not_authenticated() {
  183. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  184. userSession.anonymous();
  185. expectedException.expect(UnauthorizedException.class);
  186. ws.newRequest()
  187. .setParam("issue", issue.getKey())
  188. .setParam("assignee", "_me")
  189. .execute();
  190. }
  191. @Test
  192. public void fail_when_missing_browse_permission() {
  193. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  194. setUserWithPermission(issue, CODEVIEWER);
  195. expectedException.expect(ForbiddenException.class);
  196. ws.newRequest()
  197. .setParam("issue", issue.getKey())
  198. .setParam("assignee", "_me")
  199. .execute();
  200. }
  201. @Test
  202. public void fail_when_assignee_is_not_member_of_organization_of_project_issue() {
  203. OrganizationDto org = db.organizations().insert(organizationDto -> organizationDto.setKey("Organization key"));
  204. IssueDto issueDto = db.issues().insertIssue(org, i -> i.setType(RuleType.CODE_SMELL));
  205. setUserWithBrowsePermission(issueDto);
  206. OrganizationDto otherOrganization = db.organizations().insert();
  207. UserDto assignee = db.users().insertUser("arthur");
  208. db.organizations().addMember(otherOrganization, assignee);
  209. expectedException.expect(IllegalArgumentException.class);
  210. expectedException.expectMessage("User 'arthur' is not member of organization 'Organization key'");
  211. ws.newRequest()
  212. .setParam("issue", issueDto.getKey())
  213. .setParam("assignee", "arthur")
  214. .execute();
  215. }
  216. private UserDto insertUser(String login) {
  217. UserDto user = db.users().insertUser(login);
  218. db.organizations().addMember(db.getDefaultOrganization(), user);
  219. return user;
  220. }
  221. private IssueDto newIssue(String assignee) {
  222. IssueDto issue = db.issues().insertIssue(
  223. issueDto -> issueDto
  224. .setAssigneeUuid(assignee)
  225. .setCreatedAt(PAST).setIssueCreationTime(PAST)
  226. .setUpdatedAt(PAST).setIssueUpdateTime(PAST)
  227. .setType(RuleType.CODE_SMELL));
  228. return issue;
  229. }
  230. private IssueDto newIssueWithBrowsePermission() {
  231. IssueDto issue = newIssue(PREVIOUS_ASSIGNEE);
  232. setUserWithBrowsePermission(issue);
  233. return issue;
  234. }
  235. private void setUserWithBrowsePermission(IssueDto issue) {
  236. setUserWithPermission(issue, USER);
  237. }
  238. private void setUserWithPermission(IssueDto issue, String permission) {
  239. insertUser(CURRENT_USER_LOGIN);
  240. userSession.logIn(CURRENT_USER_LOGIN)
  241. .addProjectPermission(permission,
  242. dbClient.componentDao().selectByUuid(db.getSession(), issue.getProjectUuid()).get(),
  243. dbClient.componentDao().selectByUuid(db.getSession(), issue.getComponentUuid()).get());
  244. }
  245. private void checkIssueAssignee(String issueKey, @Nullable String expectedAssignee) {
  246. IssueDto issueReloaded = dbClient.issueDao().selectByKey(db.getSession(), issueKey).get();
  247. assertThat(issueReloaded.getAssigneeUuid()).isEqualTo(expectedAssignee);
  248. assertThat(issueReloaded.getIssueUpdateTime()).isEqualTo(NOW);
  249. assertThat(issueReloaded.getUpdatedAt()).isEqualTo(NOW);
  250. }
  251. }