test_permissions.py 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151
  1. from io import StringIO
  2. from django.core.files.uploadedfile import InMemoryUploadedFile
  3. from django.urls import reverse
  4. from model_bakery import baker
  5. from glitchtip.test_utils.test_case import APIPermissionTestCase
  6. from organizations_ext.models import OrganizationUserRole
  7. class ReleaseAPIPermissionTests(APIPermissionTestCase):
  8. def setUp(self):
  9. self.create_user_org()
  10. self.set_client_credentials(self.auth_token.token)
  11. self.project = baker.make("projects.Project", organization=self.organization)
  12. self.release = baker.make("releases.Release", organization=self.organization)
  13. self.release.projects.add(self.project)
  14. self.organization_list_url = reverse(
  15. "organization-releases-list",
  16. kwargs={"organization_slug": self.organization.slug},
  17. )
  18. self.project_list_url = reverse(
  19. "project-releases-list",
  20. kwargs={"project_pk": self.organization.slug + "/" + self.project.slug},
  21. )
  22. self.organization_detail_url = reverse(
  23. "organization-releases-detail",
  24. kwargs={
  25. "organization_slug": self.organization.slug,
  26. "version": self.release.version,
  27. },
  28. )
  29. self.project_detail_url = reverse(
  30. "project-releases-detail",
  31. kwargs={
  32. "project_pk": self.organization.slug + "/" + self.project.slug,
  33. "version": self.release.version,
  34. },
  35. )
  36. def test_list(self):
  37. self.assertGetReqStatusCode(self.organization_list_url, 403)
  38. self.assertGetReqStatusCode(self.project_list_url, 403)
  39. self.auth_token.add_permission("project:read")
  40. self.assertGetReqStatusCode(self.organization_list_url, 200)
  41. self.assertGetReqStatusCode(self.project_list_url, 200)
  42. def test_retrieve(self):
  43. self.assertGetReqStatusCode(self.organization_detail_url, 403)
  44. self.assertGetReqStatusCode(self.project_detail_url, 403)
  45. self.auth_token.add_permission("project:read")
  46. self.assertGetReqStatusCode(self.organization_detail_url, 200)
  47. self.assertGetReqStatusCode(self.project_detail_url, 200)
  48. def test_assemble(self):
  49. url = self.organization_detail_url + "assemble/"
  50. data = {
  51. "checksum": "94bc085fe32db9b4b1b82236214d65eeeeeeeeee",
  52. "chunks": ["94bc085fe32db9b4b1b82236214d65eeeeeeeeee"],
  53. }
  54. self.assertPostReqStatusCode(url, data, 403)
  55. self.auth_token.add_permission("project:write")
  56. self.assertPostReqStatusCode(url, data, 200)
  57. def test_create(self):
  58. self.auth_token.add_permission("project:read")
  59. data = {"version": "new-version"}
  60. self.assertPostReqStatusCode(self.organization_list_url, data, 403)
  61. self.assertPostReqStatusCode(self.project_list_url, data, 403)
  62. self.auth_token.add_permission("project:releases")
  63. # Unsure if this should be supported
  64. # self.assertPostReqStatusCode(self.organization_list_url, data, 201)
  65. self.assertPostReqStatusCode(self.project_list_url, data, 201)
  66. def test_destroy(self):
  67. self.auth_token.add_permissions(["project:read", "project:write"])
  68. self.assertDeleteReqStatusCode(self.project_detail_url, 403)
  69. self.auth_token.add_permission("project:releases")
  70. self.assertDeleteReqStatusCode(self.project_detail_url, 204)
  71. def test_user_destroy(self):
  72. self.client.force_login(self.user)
  73. self.set_user_role(OrganizationUserRole.MEMBER)
  74. self.assertDeleteReqStatusCode(self.project_detail_url, 204)
  75. def test_update(self):
  76. self.auth_token.add_permission("project:read")
  77. data = {"version": "newer-version"}
  78. self.assertPutReqStatusCode(self.organization_detail_url, data, 403)
  79. self.auth_token.add_permission("project:releases")
  80. self.assertPutReqStatusCode(self.organization_detail_url, data, 200)
  81. class ReleaseFileAPIPermissionTests(APIPermissionTestCase):
  82. def setUp(self):
  83. self.create_user_org()
  84. self.set_client_credentials(self.auth_token.token)
  85. self.project = baker.make("projects.Project", organization=self.organization)
  86. self.release = baker.make(
  87. "releases.Release", organization=self.organization, projects=[self.project]
  88. )
  89. self.release_file = baker.make("releases.ReleaseFile", release=self.release)
  90. self.list_url = reverse(
  91. "files-list",
  92. kwargs={
  93. "project_pk": self.organization.slug + "/" + self.project.slug,
  94. "release_version": self.release.version,
  95. },
  96. )
  97. self.detail_url = reverse(
  98. "files-detail",
  99. kwargs={
  100. "project_pk": self.organization.slug + "/" + self.project.slug,
  101. "release_version": self.release.version,
  102. "pk": self.release_file.pk,
  103. },
  104. )
  105. def test_list(self):
  106. self.assertGetReqStatusCode(self.list_url, 403)
  107. self.auth_token.add_permission("project:read")
  108. self.assertGetReqStatusCode(self.list_url, 200)
  109. def test_retrieve(self):
  110. self.assertGetReqStatusCode(self.detail_url, 403)
  111. self.auth_token.add_permission("project:read")
  112. self.assertGetReqStatusCode(self.detail_url, 200)
  113. def test_create(self):
  114. self.auth_token.add_permission("project:read")
  115. im_io = StringIO()
  116. file = InMemoryUploadedFile(
  117. im_io, None, "name.txt", "text/plain", len(im_io.getvalue()), None
  118. )
  119. data = {"name": "name", "file": file}
  120. self.assertPostReqStatusCode(self.list_url, data, 403)
  121. self.auth_token.add_permission("project:releases")
  122. self.assertPostReqStatusCode(self.list_url, data, 201)
  123. def test_destroy(self):
  124. self.auth_token.add_permissions(["project:read", "project:write"])
  125. self.assertDeleteReqStatusCode(self.detail_url, 403)
  126. self.auth_token.add_permission("project:releases")
  127. self.assertDeleteReqStatusCode(self.detail_url, 204)