folders_test.go 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328
  1. package api
  2. import (
  3. "encoding/json"
  4. "path/filepath"
  5. "testing"
  6. "github.com/go-macaron/session"
  7. "github.com/grafana/grafana/pkg/api/dtos"
  8. "github.com/grafana/grafana/pkg/bus"
  9. "github.com/grafana/grafana/pkg/middleware"
  10. m "github.com/grafana/grafana/pkg/models"
  11. "github.com/grafana/grafana/pkg/services/dashboards"
  12. macaron "gopkg.in/macaron.v1"
  13. . "github.com/smartystreets/goconvey/convey"
  14. )
  15. func TestFoldersApiEndpoint(t *testing.T) {
  16. Convey("Given a dashboard", t, func() {
  17. fakeDash := m.NewDashboard("Child dash")
  18. fakeDash.Id = 1
  19. fakeDash.FolderId = 1
  20. fakeDash.HasAcl = false
  21. bus.AddHandler("test", func(query *m.GetDashboardQuery) error {
  22. query.Result = fakeDash
  23. return nil
  24. })
  25. updateFolderCmd := m.UpdateFolderCommand{}
  26. Convey("When user is an Org Editor", func() {
  27. role := m.ROLE_EDITOR
  28. loggedInUserScenarioWithRole("When calling GET on", "GET", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  29. callGetFolder(sc)
  30. So(sc.resp.Code, ShouldEqual, 404)
  31. })
  32. updateFolderScenario("When calling PUT on", "/api/folders/1", "/api/folders/:id", role, updateFolderCmd, func(sc *scenarioContext) {
  33. callUpdateFolder(sc)
  34. So(sc.resp.Code, ShouldEqual, 404)
  35. })
  36. loggedInUserScenarioWithRole("When calling DELETE on", "DELETE", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  37. callDeleteFolder(sc)
  38. So(sc.resp.Code, ShouldEqual, 404)
  39. })
  40. })
  41. })
  42. Convey("Given a folder which does not have an acl", t, func() {
  43. fakeFolder := m.NewDashboardFolder("Folder")
  44. fakeFolder.Id = 1
  45. fakeFolder.HasAcl = false
  46. bus.AddHandler("test", func(query *m.GetDashboardQuery) error {
  47. query.Result = fakeFolder
  48. return nil
  49. })
  50. viewerRole := m.ROLE_VIEWER
  51. editorRole := m.ROLE_EDITOR
  52. aclMockResp := []*m.DashboardAclInfoDTO{
  53. {Role: &viewerRole, Permission: m.PERMISSION_VIEW},
  54. {Role: &editorRole, Permission: m.PERMISSION_EDIT},
  55. }
  56. bus.AddHandler("test", func(query *m.GetDashboardAclInfoListQuery) error {
  57. query.Result = aclMockResp
  58. return nil
  59. })
  60. bus.AddHandler("test", func(query *m.GetTeamsByUserQuery) error {
  61. query.Result = []*m.Team{}
  62. return nil
  63. })
  64. cmd := m.CreateFolderCommand{
  65. Title: fakeFolder.Title,
  66. }
  67. Convey("When user is an Org Viewer", func() {
  68. role := m.ROLE_VIEWER
  69. loggedInUserScenarioWithRole("When calling GET on", "GET", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  70. folder := getFolderShouldReturn200(sc)
  71. Convey("Should not be able to edit or save folder", func() {
  72. So(folder.CanEdit, ShouldBeFalse)
  73. So(folder.CanSave, ShouldBeFalse)
  74. So(folder.CanAdmin, ShouldBeFalse)
  75. })
  76. })
  77. loggedInUserScenarioWithRole("When calling DELETE on", "DELETE", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  78. callDeleteFolder(sc)
  79. So(sc.resp.Code, ShouldEqual, 403)
  80. })
  81. createFolderScenario("When calling POST on", "/api/folders", "/api/folders", role, cmd, func(sc *scenarioContext) {
  82. callCreateFolder(sc)
  83. So(sc.resp.Code, ShouldEqual, 403)
  84. })
  85. })
  86. Convey("When user is an Org Editor", func() {
  87. role := m.ROLE_EDITOR
  88. loggedInUserScenarioWithRole("When calling GET on", "GET", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  89. folder := getFolderShouldReturn200(sc)
  90. Convey("Should be able to edit or save folder", func() {
  91. So(folder.CanEdit, ShouldBeTrue)
  92. So(folder.CanSave, ShouldBeTrue)
  93. So(folder.CanAdmin, ShouldBeFalse)
  94. })
  95. })
  96. loggedInUserScenarioWithRole("When calling DELETE on", "DELETE", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  97. callDeleteFolder(sc)
  98. So(sc.resp.Code, ShouldEqual, 200)
  99. })
  100. createFolderScenario("When calling POST on", "/api/folders", "/api/folders", role, cmd, func(sc *scenarioContext) {
  101. callCreateFolder(sc)
  102. So(sc.resp.Code, ShouldEqual, 200)
  103. })
  104. })
  105. })
  106. Convey("Given a folder which have an acl", t, func() {
  107. fakeFolder := m.NewDashboardFolder("Folder")
  108. fakeFolder.Id = 1
  109. fakeFolder.HasAcl = true
  110. bus.AddHandler("test", func(query *m.GetDashboardQuery) error {
  111. query.Result = fakeFolder
  112. return nil
  113. })
  114. aclMockResp := []*m.DashboardAclInfoDTO{
  115. {
  116. DashboardId: 1,
  117. Permission: m.PERMISSION_EDIT,
  118. UserId: 200,
  119. },
  120. }
  121. bus.AddHandler("test", func(query *m.GetDashboardAclInfoListQuery) error {
  122. query.Result = aclMockResp
  123. return nil
  124. })
  125. bus.AddHandler("test", func(query *m.GetTeamsByUserQuery) error {
  126. query.Result = []*m.Team{}
  127. return nil
  128. })
  129. cmd := m.CreateFolderCommand{
  130. Title: fakeFolder.Title,
  131. }
  132. Convey("When user is an Org Viewer and has no permissions for this folder", func() {
  133. role := m.ROLE_VIEWER
  134. loggedInUserScenarioWithRole("When calling GET on", "GET", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  135. sc.handlerFunc = GetFolderById
  136. sc.fakeReqWithParams("GET", sc.url, map[string]string{}).exec()
  137. Convey("Should be denied access", func() {
  138. So(sc.resp.Code, ShouldEqual, 403)
  139. })
  140. })
  141. loggedInUserScenarioWithRole("When calling DELETE on", "DELETE", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  142. callDeleteFolder(sc)
  143. So(sc.resp.Code, ShouldEqual, 403)
  144. })
  145. createFolderScenario("When calling POST on", "/api/folders", "/api/folders", role, cmd, func(sc *scenarioContext) {
  146. callCreateFolder(sc)
  147. So(sc.resp.Code, ShouldEqual, 403)
  148. })
  149. })
  150. Convey("When user is an Org Editor and has no permissions for this folder", func() {
  151. role := m.ROLE_EDITOR
  152. loggedInUserScenarioWithRole("When calling GET on", "GET", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  153. sc.handlerFunc = GetFolderById
  154. sc.fakeReqWithParams("GET", sc.url, map[string]string{}).exec()
  155. Convey("Should be denied access", func() {
  156. So(sc.resp.Code, ShouldEqual, 403)
  157. })
  158. })
  159. loggedInUserScenarioWithRole("When calling DELETE on", "DELETE", "/api/folders/1", "/api/folders/:id", role, func(sc *scenarioContext) {
  160. callDeleteFolder(sc)
  161. So(sc.resp.Code, ShouldEqual, 403)
  162. })
  163. createFolderScenario("When calling POST on", "/api/folders", "/api/folders", role, cmd, func(sc *scenarioContext) {
  164. callCreateFolder(sc)
  165. So(sc.resp.Code, ShouldEqual, 403)
  166. })
  167. })
  168. })
  169. }
  170. func getFolderShouldReturn200(sc *scenarioContext) dtos.Folder {
  171. callGetFolder(sc)
  172. So(sc.resp.Code, ShouldEqual, 200)
  173. folder := dtos.Folder{}
  174. err := json.NewDecoder(sc.resp.Body).Decode(&folder)
  175. So(err, ShouldBeNil)
  176. return folder
  177. }
  178. func callGetFolder(sc *scenarioContext) {
  179. sc.handlerFunc = GetFolderById
  180. sc.fakeReqWithParams("GET", sc.url, map[string]string{}).exec()
  181. }
  182. func callDeleteFolder(sc *scenarioContext) {
  183. bus.AddHandler("test", func(cmd *m.DeleteDashboardCommand) error {
  184. return nil
  185. })
  186. sc.handlerFunc = DeleteFolder
  187. sc.fakeReqWithParams("DELETE", sc.url, map[string]string{}).exec()
  188. }
  189. func callCreateFolder(sc *scenarioContext) {
  190. bus.AddHandler("test", func(cmd *m.SaveDashboardCommand) error {
  191. cmd.Result = &m.Dashboard{Id: 1, Slug: "folder", Version: 2}
  192. return nil
  193. })
  194. sc.fakeReqWithParams("POST", sc.url, map[string]string{}).exec()
  195. }
  196. func callUpdateFolder(sc *scenarioContext) {
  197. bus.AddHandler("test", func(cmd *m.SaveDashboardCommand) error {
  198. cmd.Result = &m.Dashboard{Id: 1, Slug: "folder", Version: 2}
  199. return nil
  200. })
  201. sc.fakeReqWithParams("PUT", sc.url, map[string]string{}).exec()
  202. }
  203. func createFolderScenario(desc string, url string, routePattern string, role m.RoleType, cmd m.CreateFolderCommand, fn scenarioFunc) {
  204. Convey(desc+" "+url, func() {
  205. defer bus.ClearBusHandlers()
  206. sc := &scenarioContext{
  207. url: url,
  208. }
  209. viewsPath, _ := filepath.Abs("../../public/views")
  210. sc.m = macaron.New()
  211. sc.m.Use(macaron.Renderer(macaron.RenderOptions{
  212. Directory: viewsPath,
  213. Delims: macaron.Delims{Left: "[[", Right: "]]"},
  214. }))
  215. sc.m.Use(middleware.GetContextHandler())
  216. sc.m.Use(middleware.Sessioner(&session.Options{}))
  217. sc.defaultHandler = wrap(func(c *middleware.Context) Response {
  218. sc.context = c
  219. sc.context.UserId = TestUserID
  220. sc.context.OrgId = TestOrgID
  221. sc.context.OrgRole = role
  222. return CreateFolder(c, cmd)
  223. })
  224. fakeRepo = &fakeDashboardRepo{}
  225. dashboards.SetRepository(fakeRepo)
  226. sc.m.Post(routePattern, sc.defaultHandler)
  227. fn(sc)
  228. })
  229. }
  230. func updateFolderScenario(desc string, url string, routePattern string, role m.RoleType, cmd m.UpdateFolderCommand, fn scenarioFunc) {
  231. Convey(desc+" "+url, func() {
  232. defer bus.ClearBusHandlers()
  233. sc := &scenarioContext{
  234. url: url,
  235. }
  236. viewsPath, _ := filepath.Abs("../../public/views")
  237. sc.m = macaron.New()
  238. sc.m.Use(macaron.Renderer(macaron.RenderOptions{
  239. Directory: viewsPath,
  240. Delims: macaron.Delims{Left: "[[", Right: "]]"},
  241. }))
  242. sc.m.Use(middleware.GetContextHandler())
  243. sc.m.Use(middleware.Sessioner(&session.Options{}))
  244. sc.defaultHandler = wrap(func(c *middleware.Context) Response {
  245. sc.context = c
  246. sc.context.UserId = TestUserID
  247. sc.context.OrgId = TestOrgID
  248. sc.context.OrgRole = role
  249. return UpdateFolder(c, cmd)
  250. })
  251. fakeRepo = &fakeDashboardRepo{}
  252. dashboards.SetRepository(fakeRepo)
  253. sc.m.Put(routePattern, sc.defaultHandler)
  254. fn(sc)
  255. })
  256. }