test_permissions.py 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. from io import StringIO
  2. from django.core.files.uploadedfile import InMemoryUploadedFile
  3. from django.urls import reverse
  4. from model_bakery import baker
  5. from glitchtip.test_utils.test_case import APIPermissionTestCase
  6. class ReleaseAPIPermissionTests(APIPermissionTestCase):
  7. def setUp(self):
  8. self.create_user_org()
  9. self.set_client_credentials(self.auth_token.token)
  10. self.project = baker.make("projects.Project", organization=self.organization)
  11. self.release = baker.make("releases.Release", organization=self.organization)
  12. self.release.projects.add(self.project)
  13. self.organization_list_url = reverse(
  14. "api:list_releases", args=[self.organization.slug]
  15. )
  16. self.project_list_url = reverse(
  17. "api:list_project_releases",
  18. kwargs={
  19. "organization_slug": self.organization.slug,
  20. "project_slug": self.project.slug,
  21. },
  22. )
  23. self.organization_detail_url = reverse(
  24. "api:get_release",
  25. kwargs={
  26. "organization_slug": self.organization.slug,
  27. "version": self.release.version,
  28. },
  29. )
  30. self.project_detail_url = reverse(
  31. "api:get_project_release",
  32. kwargs={
  33. "organization_slug": self.organization.slug,
  34. "project_slug": self.project.slug,
  35. "version": self.release.version,
  36. },
  37. )
  38. self.org_delete_url = reverse(
  39. "api:delete_organization_release",
  40. kwargs={
  41. "organization_slug": self.organization.slug,
  42. "version": self.release.version,
  43. },
  44. )
  45. self.project_delete_url = reverse(
  46. "api:delete_project_release",
  47. kwargs={
  48. "organization_slug": self.organization.slug,
  49. "project_slug": self.project.slug,
  50. "version": self.release.version,
  51. },
  52. )
  53. def test_list(self):
  54. self.assertGetReqStatusCode(self.organization_list_url, 403)
  55. self.assertGetReqStatusCode(self.project_list_url, 403)
  56. self.auth_token.add_permission("project:releases")
  57. self.assertGetReqStatusCode(self.organization_list_url, 200)
  58. self.assertGetReqStatusCode(self.project_list_url, 200)
  59. def test_retrieve(self):
  60. self.assertGetReqStatusCode(self.organization_detail_url, 403)
  61. self.assertGetReqStatusCode(self.project_detail_url, 403)
  62. self.auth_token.add_permission("project:releases")
  63. self.assertGetReqStatusCode(self.organization_detail_url, 200)
  64. self.assertGetReqStatusCode(self.project_detail_url, 200)
  65. def test_assemble(self):
  66. url = reverse(
  67. "api:assemble_release", args=[self.organization.slug, self.release.version]
  68. )
  69. data = {
  70. "checksum": "94bc085fe32db9b4b1b82236214d65eeeeeeeeee",
  71. "chunks": ["94bc085fe32db9b4b1b82236214d65eeeeeeeeee"],
  72. }
  73. self.assertPostReqStatusCode(url, data, 403)
  74. self.auth_token.add_permission("project:write")
  75. self.assertPostReqStatusCode(url, data, 200)
  76. def test_create(self):
  77. self.auth_token.add_permission("project:read")
  78. data = {"version": "new-version", "projects": [self.project.slug]}
  79. self.assertPostReqStatusCode(self.organization_list_url, data, 403)
  80. self.assertPostReqStatusCode(self.project_list_url, data, 403)
  81. self.auth_token.add_permission("project:releases")
  82. self.assertPostReqStatusCode(self.organization_list_url, data, 201)
  83. self.assertPostReqStatusCode(self.project_list_url, data, 201)
  84. def test_org_release_destroy(self):
  85. self.auth_token.add_permissions(["project:read", "project:write"])
  86. self.assertDeleteReqStatusCode(self.org_delete_url, 403)
  87. self.auth_token.add_permission("project:releases")
  88. self.assertDeleteReqStatusCode(self.org_delete_url, 204)
  89. def test_project_release_destroy(self):
  90. self.auth_token.add_permissions(["project:read", "project:write"])
  91. self.assertDeleteReqStatusCode(self.project_delete_url, 403)
  92. self.auth_token.add_permission("project:releases")
  93. self.assertDeleteReqStatusCode(self.project_delete_url, 204)
  94. def test_update(self):
  95. self.auth_token.add_permission("project:read")
  96. data = {"version": "newer-version"}
  97. self.assertPutReqStatusCode(self.organization_detail_url, data, 403)
  98. self.auth_token.add_permission("project:releases")
  99. self.assertPutReqStatusCode(self.organization_detail_url, data, 200)
  100. class ReleaseFileAPIPermissionTests(APIPermissionTestCase):
  101. def setUp(self):
  102. self.create_user_org()
  103. self.set_client_credentials(self.auth_token.token)
  104. self.project = baker.make("projects.Project", organization=self.organization)
  105. self.release = baker.make(
  106. "releases.Release", organization=self.organization, projects=[self.project]
  107. )
  108. self.release_file = baker.make(
  109. "sourcecode.DebugSymbolBundle", release=self.release
  110. )
  111. self.list_url = reverse(
  112. "api:list_project_release_files",
  113. kwargs={
  114. "organization_slug": self.organization.slug,
  115. "project_slug": self.project.slug,
  116. "version": self.release.version,
  117. },
  118. )
  119. self.detail_url = reverse(
  120. "api:get_project_release_file",
  121. kwargs={
  122. "organization_slug": self.organization.slug,
  123. "project_slug": self.project.slug,
  124. "version": self.release.version,
  125. "file_id": self.release_file.pk,
  126. },
  127. )
  128. def test_list(self):
  129. self.assertGetReqStatusCode(self.list_url, 403)
  130. self.auth_token.add_permission("project:releases")
  131. self.assertGetReqStatusCode(self.list_url, 200)
  132. def test_retrieve(self):
  133. self.assertGetReqStatusCode(self.detail_url, 403)
  134. self.auth_token.add_permission("project:releases")
  135. self.assertGetReqStatusCode(self.detail_url, 200)
  136. # Skip for now, requires DRF test client
  137. def xtest_create(self):
  138. self.auth_token.add_permission("project:read")
  139. im_io = StringIO()
  140. file = InMemoryUploadedFile(
  141. im_io, None, "name.txt", "text/plain", len(im_io.getvalue()), None
  142. )
  143. data = {"name": "name", "file": file}
  144. self.assertPostReqStatusCode(self.list_url, data, 403)
  145. self.auth_token.add_permission("project:releases")
  146. self.assertPostReqStatusCode(self.list_url, data, 201)
  147. def test_destroy(self):
  148. self.auth_token.add_permissions(["project:read", "project:write"])
  149. self.assertDeleteReqStatusCode(self.detail_url, 403)
  150. self.auth_token.add_permission("project:releases")
  151. self.assertDeleteReqStatusCode(self.detail_url, 204)