Merge branch 'master' into 5365-not-link-unreadables
[arvados.git] / apps / workbench / test / integration / anonymous_access_test.rb
index b4bd3b571cb8088fbdc3e65e026eec9b5bda858a..0455dc994ea7213d7f9a3a4448b63a5a5da7d9a6 100644 (file)
@@ -8,39 +8,33 @@ class AnonymousAccessTest < ActionDispatch::IntegrationTest
 
   setup do
     need_javascript
+    Rails.configuration.anonymous_user_token = api_fixture('api_client_authorizations')['anonymous']['api_token']
   end
 
-  def verify_homepage_anonymous_enabled user, is_active, has_profile
+  PUBLIC_PROJECT = "/projects/#{api_fixture('groups')['anonymously_accessible_project']['uuid']}"
+
+  def verify_site_navigation_anonymous_enabled user, is_active
     if user
       if user['is_active']
-        if has_profile
-          assert_text 'Unrestricted public data'
-          assert_selector 'a', text: 'Projects'
-        else
-          assert_text 'All required fields must be completed before you can proceed'
-        end
+        assert_text 'Unrestricted public data'
+        assert_selector 'a', text: 'Projects'
       else
         assert_text 'indicate that you have read and accepted the user agreement'
       end
       within('.navbar-fixed-top') do
-        assert_no_text 'You are viewing public data'
+        assert_selector 'a', text: Rails.configuration.site_name.downcase
         assert_selector 'a', text: "#{user['email']}"
         find('a', text: "#{user['email']}").click
         within('.dropdown-menu') do
           assert_selector 'a', text: 'Log out'
         end
       end
-    else
+    else  # anonymous
       assert_text 'Unrestricted public data'
       within('.navbar-fixed-top') do
-        assert_text 'You are viewing public data'
-        anonymous_user = api_fixture('users')['anonymous']
-        assert_selector 'a', "#{anonymous_user['email']}"
-        find('a', text: "#{anonymous_user['email']}").click
-        within('.dropdown-menu') do
-          assert_selector 'a', text: 'Log in'
-          assert_no_selector 'a', text: 'Log out'
-        end
+        assert_text Rails.configuration.site_name.downcase
+        assert_no_selector 'a', text: Rails.configuration.site_name.downcase
+        assert_selector 'a', text: 'Log in'
       end
     end
   end
@@ -49,55 +43,22 @@ class AnonymousAccessTest < ActionDispatch::IntegrationTest
     [nil, nil, false, false],
     ['inactive', api_fixture('users')['inactive'], false, false],
     ['active', api_fixture('users')['active'], true, true],
-    ['active_no_prefs_profile', api_fixture('users')['active_no_prefs_profile'], true, false],
-    ['admin', api_fixture('users')['admin'], true, true],
-  ].each do |token, user, is_active, has_profile|
-    test "visit public project as user #{token} when anonymous browsing is enabled" do
-      Rails.configuration.anonymous_user_token = api_fixture('api_client_authorizations')['anonymous']['api_token']
-
-      path = "/projects/#{api_fixture('groups')['anonymously_accessible_project']['uuid']}/?public_data=true"
-
-      if !token
-        visit path
-      else
-        visit page_with_token(token, path)
-      end
-      verify_homepage_anonymous_enabled user, is_active, has_profile
-    end
-  end
-
-  [
-    [nil, nil],
-    ['active', api_fixture('users')['active']],
   ].each do |token, user, is_active|
-    test "visit public project as user #{token} when anonymous browsing is not enabled" do
-      Rails.configuration.anonymous_user_token = false
-
-      path = "/projects/#{api_fixture('groups')['anonymously_accessible_project']['uuid']}/?public_data=true"
+    test "visit public project as user #{token.inspect} when anonymous browsing is enabled" do
       if !token
-        visit path
+        visit PUBLIC_PROJECT
       else
-        visit page_with_token(token, path)
+        visit page_with_token(token, PUBLIC_PROJECT)
       end
 
-      if user
-        assert_text 'Unrestricted public data'
-      else
-        assert_text 'Please log in'
-      end
+      verify_site_navigation_anonymous_enabled user, is_active
     end
   end
 
-  test "visit non-public project as anonymous when anonymous browsing is enabled and expect page not found" do
-    Rails.configuration.anonymous_user_token = api_fixture('api_client_authorizations')['anonymous']['api_token']
-    visit "/projects/#{api_fixture('groups')['aproject']['uuid']}/?public_data=true"
-    assert_text 'Not Found'
-  end
-
   test "selection actions when anonymous user accesses shared project" do
-    Rails.configuration.anonymous_user_token = api_fixture('api_client_authorizations')['anonymous']['api_token']
-    visit "/projects/#{api_fixture('groups')['anonymously_accessible_project']['uuid']}/?public_data=true"
+    visit PUBLIC_PROJECT
 
+    assert_selector 'a', text: 'Description'
     assert_selector 'a', text: 'Data collections'
     assert_selector 'a', text: 'Jobs and pipelines'
     assert_selector 'a', text: 'Pipeline templates'
@@ -106,6 +67,7 @@ class AnonymousAccessTest < ActionDispatch::IntegrationTest
     assert_no_selector 'a', text: 'Other objects'
     assert_no_selector 'button', text: 'Add data'
 
+    click_link 'Data collections'
     click_button 'Selection'
     within('.selection-action-container') do
       assert_selector 'li', text: 'Compare selected'
@@ -116,71 +78,75 @@ class AnonymousAccessTest < ActionDispatch::IntegrationTest
     end
   end
 
-  def visit_publicly_accessible_project
-    Rails.configuration.anonymous_user_token = api_fixture('api_client_authorizations')['anonymous']['api_token']
-    visit "/projects/#{api_fixture('groups')['anonymously_accessible_project']['uuid']}/?public_data=true"
-  end
-
-  test "verify dashboard when anonymous user accesses shared project" do
-    visit_publicly_accessible_project
-    assert_selector 'a', text: 'You are viewing public data'
-
-    # go to dashboard
-    click_link 'You are viewing public data'
-    assert_no_selector 'a', text: 'Run a pipeline'
-    assert_selector 'a', text: 'All pipelines'
-    assert_selector 'a', text: 'All jobs'
-    assert_selector 'a', text: 'All collections'
-  end
-
   test "anonymous user accesses data collections tab in shared project" do
-    visit_publicly_accessible_project
+    visit PUBLIC_PROJECT
+    click_link 'Data collections'
+    collection = api_fixture('collections')['user_agreement_in_anonymously_accessible_project']
+    assert_text 'GNU General Public License'
 
-    assert_selector 'a', text: 'Data collections (1)'
+    assert_selector 'a', text: 'Data collections'
 
     # click on show collection
-    within first('tr[data-kind="arvados#collection"]') do
+    within "tr[data-object-uuid=\"#{collection['uuid']}\"]" do
       click_link 'Show'
     end
 
     # in collection page
     assert_no_selector 'input', text: 'Create sharing link'
+    assert_no_text 'Sharing and permissions'
     assert_no_selector 'a', text: 'Upload'
     assert_no_selector 'button', 'Selection'
 
-    within ('#collection_files') do
-      assert_text 'GNU_General_Public_License,_version_3.pdf'
-      # how do i assert the view and download links?
+    within '#collection_files tr,li', text: 'GNU_General_Public_License,_version_3.pdf' do
+      assert page.has_no_selector?('[value*="GNU_General_Public_License"]')
+      find 'a[title~=View]'
+      find 'a[title~=Download]'
     end
   end
 
-  [ 'job', 'pipelineInstance' ].each do |type|
-    test "anonymous user accesses jobs and pipelines tab in shared project and clicks on #{type}" do
-      visit_publicly_accessible_project
+  test 'view file' do
+    magic = rand(2**512).to_s 36
+    CollectionsController.any_instance.stubs(:file_enumerator).returns([magic])
+    collection = api_fixture('collections')['public_text_file']
+    visit '/collections/' + collection['uuid']
+    find('tr,li', text: 'Hello world.txt').
+      find('a[title~=View]').click
+    assert_text magic
+  end
 
-      assert_selector 'a', 'Jobs and pipelines (2)'
+  [
+    'running_job',
+    'completed_job',
+    'pipelineInstance'
+  ].each do |type|
+    test "anonymous user accesses jobs and pipelines tab in shared project and clicks on #{type}" do
+      visit PUBLIC_PROJECT
+      click_link 'Data collections'
+      assert_text 'GNU General Public License'
 
       click_link 'Jobs and pipelines'
-      assert_text 'hash job'
+      assert_text 'Pipeline in publicly accessible project'
 
-      # click on type specified collection
-      if type == 'job'
-        verify_job_row
+      # click on the specified job
+      if type.include? 'job'
+        verify_job_row type
       else
         verify_pipeline_instance_row
       end
     end
   end
 
-  def verify_job_row
-    within first('tr[data-kind="arvados#job"]') do
-      assert_text 'hash job using'
+  def verify_job_row look_for
+    within first('tr', text: look_for) do
       click_link 'Show'
     end
+    assert_text 'script_version'
 
-    # in job page
+    assert_text 'zzzzz-tpzed-xurymjxw79nv3jz' # modified by user
+    assert_no_selector 'a', text: 'zzzzz-tpzed-xurymjxw79nv3jz'
+    assert_no_selector 'a', text: 'Move job'
+    assert_no_selector 'button', text: 'Cancel'
     assert_no_selector 'button', text: 'Re-run job'
-    assert_text 'script_version'
   end
 
   def verify_pipeline_instance_row
@@ -190,15 +156,17 @@ class AnonymousAccessTest < ActionDispatch::IntegrationTest
     end
 
     # in pipeline instance page
+    assert_text 'This pipeline is complete'
     assert_no_selector 'a', text: 'Re-run with latest'
     assert_no_selector 'a', text: 'Re-run options'
-    assert_text 'This pipeline is complete'
   end
 
   test "anonymous user accesses pipeline templates tab in shared project" do
-    visit_publicly_accessible_project
+    visit PUBLIC_PROJECT
+    click_link 'Data collections'
+    assert_text 'GNU General Public License'
 
-    assert_selector 'a', 'Pipeline templates (1)'
+    assert_selector 'a', text: 'Pipeline templates'
 
     click_link 'Pipeline templates'
     assert_text 'Pipeline template in publicly accessible project'
@@ -211,4 +179,44 @@ class AnonymousAccessTest < ActionDispatch::IntegrationTest
     assert_text 'script version'
     assert_no_selector 'a', text: 'Run this pipeline'
   end
+
+  [
+    ['pipeline_in_publicly_accessible_project', true],
+    ['pipeline_in_publicly_accessible_project_but_other_objects_elsewhere', false],
+    ['pipeline_in_publicly_accessible_project_but_other_objects_elsewhere', false, 'admin'],
+  ].each do |pipeline_fixture, objects_readable, user=nil|
+    test "accesse #{pipeline_fixture} in public project with objects readable=#{objects_readable} with user #{user}" do
+      pipeline = api_fixture('pipeline_instances')[pipeline_fixture]
+      page = "/pipeline_instances/#{pipeline['uuid']}"
+      if user
+        visit page_with_token user, page
+      else
+        visit page
+      end
+
+      click_link 'foo'  # click job link
+
+      if objects_readable or (!objects_readable and user)
+        assert_text 'This pipeline was created from'
+        assert_no_text 'Output data not available'
+        assert_selector 'a', pipeline['components']['foo']['job']['uuid']
+        assert_selector 'a[href="#Log"]', text: 'Log'
+        assert_no_selector 'a[data-toggle="disabled"]', text: 'Log'
+      else
+        assert_no_text 'This pipeline was created from' # template not readable
+        assert_text 'Output data not available'
+        assert_no_selector 'a', text: pipeline['components']['foo']['job']['uuid']
+        assert_text pipeline['job']
+        assert_selector 'a[href="#Log"]', text: 'Log'
+        assert_selector 'a[data-toggle="disabled"]', text: 'Log'
+      end
+
+      click_link 'Log'
+      if objects_readable or (!objects_readable and user)
+        assert_no_text 'foo'  # should be in Log tab
+      else
+        assert_text 'foo'     # Log tab disabled and hence still in Components tab
+      end
+    end
+  end
 end