Merge branch '1977-provenance-report' of git.clinicalfuture.com:arvados into 1977...
[arvados.git] / services / api / app / controllers / arvados / v1 / collections_controller.rb
index d14de73bfe06329acd2e27c4fa011aeb93ca7994..294e092f6cf7e253994c624e3ff476c265b09db3 100644 (file)
@@ -12,6 +12,7 @@ class Arvados::V1::CollectionsController < ApplicationController
                    'arvados#group'
                  end
     unless current_user.can? write: owner_uuid
+      logger.warn "User #{current_user.andand.uuid} tried to set collection owner_uuid to #{owner_uuid}"
       raise ArvadosModel::PermissionDeniedError
     end
     act_as_system_user do
@@ -77,63 +78,69 @@ class Arvados::V1::CollectionsController < ApplicationController
         end
       end
     end
-    gr
   end
 
   def generate_provenance_edges(visited, uuid)
     m = collection_uuid(uuid)
+    uuid = m if m
 
-    if not uuid or uuid.empty? or visited[uuid] or visited[m]
+    if not uuid or uuid.empty? or visited[uuid]
       return ""
     end
 
-    #puts "visiting #{uuid}"
+    logger.debug "visiting #{uuid}"
 
     if m  
       # uuid is a collection
-      uuid = m
-      Collection.where(uuid:"uuid").each do |c|
-        visited[uuid] = c
+      Collection.readable_by(current_user).where(uuid: uuid).each do |c|
+        visited[uuid] = c.as_api_response
+        visited[uuid][:files] = []
+        c.files.each do |f|
+          visited[uuid][:files] << f
+        end
       end
 
-      Job.where(output: uuid).each do |job|
+      Job.readable_by(current_user).where(output: uuid).each do |job|
         generate_provenance_edges(visited, job.uuid)
       end
 
-      Job.where(log: uuid).each do |job|
+      Job.readable_by(current_user).where(log: uuid).each do |job|
         generate_provenance_edges(visited, job.uuid)
       end
       
     else
-      visited[uuid] = true
-
       # uuid is something else
-      rsc = ArvadosBase::resource_class_for_uuid uuid
-
+      rsc = ArvadosModel::resource_class_for_uuid uuid
       if rsc == Job
-        Job.where(uuid: uuid).each do |job|
-          visited[uuid] = job
-          script_param_edges(visited, job, "", job.script_parameters)
+        Job.readable_by(current_user).where(uuid: uuid).each do |job|
+          visited[uuid] = job.as_api_response
+          script_param_edges(visited, job.script_parameters)
         end
+      elsif rsc != nil
+        rsc.where(uuid: uuid).each do |r|
+          visited[uuid] = r.as_api_response
+        end
+      end
     end
 
-    Link.where(head_uuid: uuid, link_class: "provenance").each do |link|
+    Link.readable_by(current_user).
+      where(head_uuid: uuid, link_class: "provenance").
+      each do |link|
+      visited[link.uuid] = link.as_api_response
       generate_provenance_edges(visited, link.tail_uuid)
     end
 
     #puts "finished #{uuid}"
-
-    gr
   end
 
-  def provenance 
+  def provenance
     visited = {}
-    generate_provenance_edges(visited, @object.uuid)
-    visited
+    generate_provenance_edges(visited, @object[:uuid])
+    render json: visited
   end
 
-  protected
 
+  protected
   def find_object_by_uuid
     super
     if !@object and !params[:uuid].match(/^[0-9a-f]+\+\d+$/)
@@ -152,4 +159,5 @@ class Arvados::V1::CollectionsController < ApplicationController
       end
     end
   end
+
 end