Merge branch '16265-security-updates' into dependabot/bundler/apps/workbench/loofah...
[arvados.git] / services / api / test / unit / collection_test.rb
index 4790501ddd5aaa875f5c716d88b9ac0464cec607..bf1ba517ebcb6bf26aec3027a084fee086ff810b 100644 (file)
@@ -1013,10 +1013,27 @@ class CollectionTest < ActiveSupport::TestCase
     assert_empty Collection.where(uuid: uuid)
   end
 
-  test "create collections with default properties" do
+  test "empty names are exempt from name uniqueness" do
+    act_as_user users(:active) do
+      c1 = Collection.new(name: nil, manifest_text: '', owner_uuid: groups(:aproject).uuid)
+      assert c1.save
+      c2 = Collection.new(name: '', manifest_text: '', owner_uuid: groups(:aproject).uuid)
+      assert c2.save
+      c3 = Collection.new(name: '', manifest_text: '', owner_uuid: groups(:aproject).uuid)
+      assert c3.save
+      c4 = Collection.new(name: 'c4', manifest_text: '', owner_uuid: groups(:aproject).uuid)
+      assert c4.save
+      c5 = Collection.new(name: 'c4', manifest_text: '', owner_uuid: groups(:aproject).uuid)
+      assert_raises(ActiveRecord::RecordNotUnique) do
+        c5.save
+      end
+    end
+  end
+
+  test "create collections with managed properties" do
     Rails.configuration.Collections.ManagedProperties = {
-      'default_prop1' => {'value' => 'prop1_value'},
-      'responsible_person_uuid' => {'function' => 'original_owner'}
+      'default_prop1' => {'Value' => 'prop1_value'},
+      'responsible_person_uuid' => {'Function' => 'original_owner'}
     }
     # Test collection without initial properties
     act_as_user users(:active) do
@@ -1045,9 +1062,9 @@ class CollectionTest < ActiveSupport::TestCase
     end
   end
 
-  test "update collection with protected default properties" do
+  test "update collection with protected managed properties" do
     Rails.configuration.Collections.ManagedProperties = {
-      'default_prop1' => {'value' => 'prop1_value', 'protected' => true},
+      'default_prop1' => {'Value' => 'prop1_value', 'Protected' => true},
     }
     act_as_user users(:active) do
       c = create_collection 'foo', Encoding::US_ASCII
@@ -1073,4 +1090,25 @@ class CollectionTest < ActiveSupport::TestCase
       end
     end
   end
+
+  test "collection names must be displayable in a filesystem" do
+    set_user_from_auth :active
+    ["", "{SOLIDUS}"].each do |subst|
+      Rails.configuration.Collections.ForwardSlashNameSubstitution = subst
+      c = Collection.create
+      [[nil, true],
+       ["", true],
+       [".", false],
+       ["..", false],
+       ["...", true],
+       ["..z..", true],
+       ["foo/bar", subst != ""],
+       ["../..", subst != ""],
+       ["/", subst != ""],
+      ].each do |name, valid|
+        c.name = name
+        assert_equal valid, c.valid?, "#{name.inspect} should be #{valid ? "valid" : "invalid"}"
+      end
+    end
+  end
 end