test_permissions.py 6.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172
  1. from io import StringIO
  2. from django.core.files.uploadedfile import InMemoryUploadedFile
  3. from django.urls import reverse
  4. from model_bakery import baker
  5. from glitchtip.test_utils.test_case import APIPermissionTestCase
  6. class ReleaseAPIPermissionTests(APIPermissionTestCase):
  7. def setUp(self):
  8. self.create_user_org()
  9. self.set_client_credentials(self.auth_token.token)
  10. self.project = baker.make("projects.Project", organization=self.organization)
  11. self.release = baker.make("releases.Release", organization=self.organization)
  12. self.release.projects.add(self.project)
  13. self.organization_list_url = reverse(
  14. "api:list_releases",
  15. kwargs={"organization_slug": self.organization.slug},
  16. )
  17. self.project_list_url = reverse(
  18. "api:list_project_releases",
  19. kwargs={
  20. "organization_slug": self.organization.slug,
  21. "project_slug": self.project.slug,
  22. },
  23. )
  24. self.organization_detail_url = reverse(
  25. "api:get_release",
  26. kwargs={
  27. "organization_slug": self.organization.slug,
  28. "version": self.release.version,
  29. },
  30. )
  31. self.project_detail_url = reverse(
  32. "api:get_project_release",
  33. kwargs={
  34. "organization_slug": self.organization.slug,
  35. "project_slug": self.project.slug,
  36. "version": self.release.version,
  37. },
  38. )
  39. self.org_delete_url = reverse(
  40. "api:delete_organization_release",
  41. kwargs={
  42. "organization_slug": self.organization.slug,
  43. "version": self.release.version,
  44. },
  45. )
  46. self.project_delete_url = reverse(
  47. "api:delete_project_release",
  48. kwargs={
  49. "organization_slug": self.organization.slug,
  50. "project_slug": self.project.slug,
  51. "version": self.release.version,
  52. },
  53. )
  54. def test_list(self):
  55. self.assertGetReqStatusCode(self.organization_list_url, 403)
  56. self.assertGetReqStatusCode(self.project_list_url, 403)
  57. self.auth_token.add_permission("project:releases")
  58. self.assertGetReqStatusCode(self.organization_list_url, 200)
  59. self.assertGetReqStatusCode(self.project_list_url, 200)
  60. def test_retrieve(self):
  61. self.assertGetReqStatusCode(self.organization_detail_url, 403)
  62. self.assertGetReqStatusCode(self.project_detail_url, 403)
  63. self.auth_token.add_permission("project:releases")
  64. self.assertGetReqStatusCode(self.organization_detail_url, 200)
  65. self.assertGetReqStatusCode(self.project_detail_url, 200)
  66. def test_assemble(self):
  67. url = self.organization_detail_url + "assemble/"
  68. data = {
  69. "checksum": "94bc085fe32db9b4b1b82236214d65eeeeeeeeee",
  70. "chunks": ["94bc085fe32db9b4b1b82236214d65eeeeeeeeee"],
  71. }
  72. self.assertPostReqStatusCode(url, data, 403)
  73. self.auth_token.add_permission("project:write")
  74. self.assertPostReqStatusCode(url, data, 200)
  75. def test_create(self):
  76. self.auth_token.add_permission("project:read")
  77. data = {"version": "new-version", "projects": [self.project.slug]}
  78. self.assertPostReqStatusCode(self.organization_list_url, data, 403)
  79. self.assertPostReqStatusCode(self.project_list_url, data, 403)
  80. self.auth_token.add_permission("project:releases")
  81. self.assertPostReqStatusCode(self.organization_list_url, data, 201)
  82. self.assertPostReqStatusCode(self.project_list_url, data, 201)
  83. def test_org_release_destroy(self):
  84. self.auth_token.add_permissions(["project:read", "project:write"])
  85. self.assertDeleteReqStatusCode(self.org_delete_url, 403)
  86. self.auth_token.add_permission("project:releases")
  87. self.assertDeleteReqStatusCode(self.org_delete_url, 204)
  88. def test_project_release_destroy(self):
  89. self.auth_token.add_permissions(["project:read", "project:write"])
  90. self.assertDeleteReqStatusCode(self.project_delete_url, 403)
  91. self.auth_token.add_permission("project:releases")
  92. self.assertDeleteReqStatusCode(self.project_delete_url, 204)
  93. def test_update(self):
  94. self.auth_token.add_permission("project:read")
  95. data = {"version": "newer-version"}
  96. self.assertPutReqStatusCode(self.organization_detail_url, data, 403)
  97. self.auth_token.add_permission("project:releases")
  98. self.assertPutReqStatusCode(self.organization_detail_url, data, 200)
  99. class ReleaseFileAPIPermissionTests(APIPermissionTestCase):
  100. def setUp(self):
  101. self.create_user_org()
  102. self.set_client_credentials(self.auth_token.token)
  103. self.project = baker.make("projects.Project", organization=self.organization)
  104. self.release = baker.make(
  105. "releases.Release", organization=self.organization, projects=[self.project]
  106. )
  107. self.release_file = baker.make("releases.ReleaseFile", release=self.release)
  108. self.list_url = reverse(
  109. "api:list_project_release_files",
  110. kwargs={
  111. "organization_slug": self.organization.slug,
  112. "project_slug": self.project.slug,
  113. "version": self.release.version,
  114. },
  115. )
  116. self.detail_url = reverse(
  117. "files-detail",
  118. kwargs={
  119. "project_pk": self.organization.slug + "/" + self.project.slug,
  120. "release_version": self.release.version,
  121. "pk": self.release_file.pk,
  122. },
  123. )
  124. def test_list(self):
  125. self.assertGetReqStatusCode(self.list_url, 403)
  126. self.auth_token.add_permission("project:releases")
  127. self.assertGetReqStatusCode(self.list_url, 200)
  128. def test_retrieve(self):
  129. self.assertGetReqStatusCode(self.detail_url, 403)
  130. self.auth_token.add_permission("project:read")
  131. self.assertGetReqStatusCode(self.detail_url, 200)
  132. # Skip for now, requires DRF test client
  133. def xtest_create(self):
  134. self.auth_token.add_permission("project:read")
  135. im_io = StringIO()
  136. file = InMemoryUploadedFile(
  137. im_io, None, "name.txt", "text/plain", len(im_io.getvalue()), None
  138. )
  139. data = {"name": "name", "file": file}
  140. self.assertPostReqStatusCode(self.list_url, data, 403)
  141. self.auth_token.add_permission("project:releases")
  142. self.assertPostReqStatusCode(self.list_url, data, 201)
  143. def test_destroy(self):
  144. self.auth_token.add_permissions(["project:read", "project:write"])
  145. self.assertDeleteReqStatusCode(self.detail_url, 403)
  146. self.auth_token.add_permission("project:releases")
  147. self.assertDeleteReqStatusCode(self.detail_url, 204)