X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/74cdb4454d4adc6b403c207169313f37332d8aac..5ea0a240eb08a4d43d5f7670a694f0158f0bac36:/services/api/test/integration/users_test.rb diff --git a/services/api/test/integration/users_test.rb b/services/api/test/integration/users_test.rb index 0d6c0f360f..5886fb2d08 100644 --- a/services/api/test/integration/users_test.rb +++ b/services/api/test/integration/users_test.rb @@ -1,3 +1,7 @@ +# Copyright (C) The Arvados Authors. All rights reserved. +# +# SPDX-License-Identifier: AGPL-3.0 + require 'test_helper' require 'helpers/users_test_helper' @@ -5,18 +9,20 @@ class UsersTest < ActionDispatch::IntegrationTest include UsersTestHelper test "setup user multiple times" do - repo_name = 'test_repo' - - post "/arvados/v1/users/setup", { - repo_name: repo_name, - openid_prefix: 'https://www.google.com/accounts/o8/id', - user: { - uuid: 'zzzzz-tpzed-abcdefghijklmno', - first_name: "in_create_test_first_name", - last_name: "test_last_name", - email: "foo@example.com" - } - }, auth(:admin) + repo_name = 'usertestrepo' + + post "/arvados/v1/users/setup", + params: { + repo_name: repo_name, + openid_prefix: 'https://www.google.com/accounts/o8/id', + user: { + uuid: 'zzzzz-tpzed-abcdefghijklmno', + first_name: "in_create_test_first_name", + last_name: "test_last_name", + email: "foo@example.com" + } + }, + headers: auth(:admin) assert_response :success @@ -35,7 +41,7 @@ class UsersTest < ActionDispatch::IntegrationTest created['uuid'], created['email'], 'arvados#user', false, 'arvados#user' verify_link response_items, 'arvados#repository', true, 'permission', 'can_manage', - repo_name, created['uuid'], 'arvados#repository', true, 'Repository' + 'foo/usertestrepo', created['uuid'], 'arvados#repository', true, 'Repository' verify_link response_items, 'arvados#group', true, 'permission', 'can_read', 'All users', created['uuid'], 'arvados#group', true, 'Group' @@ -46,19 +52,30 @@ class UsersTest < ActionDispatch::IntegrationTest verify_system_group_permission_link_for created['uuid'] # invoke setup again with the same data - post "/arvados/v1/users/setup", { - repo_name: repo_name, - vm_uuid: virtual_machines(:testvm).uuid, - openid_prefix: 'https://www.google.com/accounts/o8/id', - user: { + post "/arvados/v1/users/setup", + params: { + repo_name: repo_name, + vm_uuid: virtual_machines(:testvm).uuid, + openid_prefix: 'https://www.google.com/accounts/o8/id', + user: { + uuid: 'zzzzz-tpzed-abcdefghijklmno', + first_name: "in_create_test_first_name", + last_name: "test_last_name", + email: "foo@example.com" + } + }, + headers: auth(:admin) + assert_response 422 # cannot create another user with same UUID + + # invoke setup on the same user + post "/arvados/v1/users/setup", + params: { + repo_name: repo_name, + vm_uuid: virtual_machines(:testvm).uuid, + openid_prefix: 'https://www.google.com/accounts/o8/id', uuid: 'zzzzz-tpzed-abcdefghijklmno', - first_name: "in_create_test_first_name", - last_name: "test_last_name", - email: "foo@example.com" - } - }, auth(:admin) - - assert_response :success + }, + headers: auth(:admin) response_items = json_response['items'] @@ -71,7 +88,7 @@ class UsersTest < ActionDispatch::IntegrationTest # arvados#user, repo link and link add user to 'All users' group verify_link response_items, 'arvados#repository', true, 'permission', 'can_manage', - repo_name, created['uuid'], 'arvados#repository', true, 'Repository' + 'foo/usertestrepo', created['uuid'], 'arvados#repository', true, 'Repository' verify_link response_items, 'arvados#group', true, 'permission', 'can_read', 'All users', created['uuid'], 'arvados#group', true, 'Group' @@ -83,12 +100,14 @@ class UsersTest < ActionDispatch::IntegrationTest end test "setup user in multiple steps and verify response" do - post "/arvados/v1/users/setup", { - openid_prefix: 'http://www.example.com/account', - user: { - email: "foo@example.com" - } - }, auth(:admin) + post "/arvados/v1/users/setup", + params: { + openid_prefix: 'http://www.example.com/account', + user: { + email: "foo@example.com" + } + }, + headers: auth(:admin) assert_response :success response_items = json_response['items'] @@ -105,18 +124,17 @@ class UsersTest < ActionDispatch::IntegrationTest verify_link response_items, 'arvados#group', true, 'permission', 'can_read', 'All users', created['uuid'], 'arvados#group', true, 'Group' - verify_link response_items, 'arvados#repository', false, 'permission', 'can_manage', - 'test_repo', created['uuid'], 'arvados#repository', true, 'Repository' - verify_link response_items, 'arvados#virtualMachine', false, 'permission', 'can_login', nil, created['uuid'], 'arvados#virtualMachine', false, 'VirtualMachine' # invoke setup with a repository - post "/arvados/v1/users/setup", { - openid_prefix: 'http://www.example.com/account', - repo_name: 'new_repo', - uuid: created['uuid'] - }, auth(:admin) + post "/arvados/v1/users/setup", + params: { + openid_prefix: 'http://www.example.com/account', + repo_name: 'newusertestrepo', + uuid: created['uuid'] + }, + headers: auth(:admin) assert_response :success @@ -130,20 +148,22 @@ class UsersTest < ActionDispatch::IntegrationTest 'All users', created['uuid'], 'arvados#group', true, 'Group' verify_link response_items, 'arvados#repository', true, 'permission', 'can_manage', - 'new_repo', created['uuid'], 'arvados#repository', true, 'Repository' + 'foo/newusertestrepo', created['uuid'], 'arvados#repository', true, 'Repository' verify_link response_items, 'arvados#virtualMachine', false, 'permission', 'can_login', nil, created['uuid'], 'arvados#virtualMachine', false, 'VirtualMachine' # invoke setup with a vm_uuid - post "/arvados/v1/users/setup", { - vm_uuid: virtual_machines(:testvm).uuid, - openid_prefix: 'http://www.example.com/account', - user: { - email: 'junk_email' + post "/arvados/v1/users/setup", + params: { + vm_uuid: virtual_machines(:testvm).uuid, + openid_prefix: 'http://www.example.com/account', + user: { + email: 'junk_email' + }, + uuid: created['uuid'] }, - uuid: created['uuid'] - }, auth(:admin) + headers: auth(:admin) assert_response :success @@ -156,21 +176,19 @@ class UsersTest < ActionDispatch::IntegrationTest verify_link response_items, 'arvados#group', true, 'permission', 'can_read', 'All users', created['uuid'], 'arvados#group', true, 'Group' - # since no repo name in input, we won't get any; even though user has one - verify_link response_items, 'arvados#repository', false, 'permission', 'can_manage', - 'new_repo', created['uuid'], 'arvados#repository', true, 'Repository' - verify_link response_items, 'arvados#virtualMachine', true, 'permission', 'can_login', virtual_machines(:testvm).uuid, created['uuid'], 'arvados#virtualMachine', false, 'VirtualMachine' end test "setup and unsetup user" do - post "/arvados/v1/users/setup", { - repo_name: 'test_repo', - vm_uuid: virtual_machines(:testvm).uuid, - user: {email: 'foo@example.com'}, - openid_prefix: 'https://www.google.com/accounts/o8/id' - }, auth(:admin) + post "/arvados/v1/users/setup", + params: { + repo_name: 'newusertestrepo', + vm_uuid: virtual_machines(:testvm).uuid, + user: {email: 'foo@example.com'}, + openid_prefix: 'https://www.google.com/accounts/o8/id' + }, + headers: auth(:admin) assert_response :success response_items = json_response['items'] @@ -186,14 +204,14 @@ class UsersTest < ActionDispatch::IntegrationTest 'All users', created['uuid'], 'arvados#group', true, 'Group' verify_link response_items, 'arvados#repository', true, 'permission', 'can_manage', - 'test_repo', created['uuid'], 'arvados#repository', true, 'Repository' + 'foo/newusertestrepo', created['uuid'], 'arvados#repository', true, 'Repository' verify_link response_items, 'arvados#virtualMachine', true, 'permission', 'can_login', virtual_machines(:testvm).uuid, created['uuid'], 'arvados#virtualMachine', false, 'VirtualMachine' verify_link_existence created['uuid'], created['email'], true, true, true, true, false - post "/arvados/v1/users/#{created['uuid']}/unsetup", {}, auth(:admin) + post "/arvados/v1/users/#{created['uuid']}/unsetup", params: {}, headers: auth(:admin) assert_response :success @@ -213,4 +231,48 @@ class UsersTest < ActionDispatch::IntegrationTest nil end + test 'merge active into project_viewer account' do + post('/arvados/v1/groups', + params: { + group: { + group_class: 'project', + name: "active user's stuff", + }, + }, + headers: auth(:project_viewer)) + assert_response(:success) + project_uuid = json_response['uuid'] + + post('/arvados/v1/users/merge', + params: { + new_user_token: api_client_authorizations(:project_viewer_trustedclient).api_token, + new_owner_uuid: project_uuid, + redirect_to_new_user: true, + }, + headers: auth(:active_trustedclient)) + assert_response(:success) + + get('/arvados/v1/users/current', params: {}, headers: auth(:active)) + assert_response(:success) + assert_equal(users(:project_viewer).uuid, json_response['uuid']) + + get('/arvados/v1/authorized_keys/' + authorized_keys(:active).uuid, + params: {}, + headers: auth(:active)) + assert_response(:success) + assert_equal(users(:project_viewer).uuid, json_response['owner_uuid']) + assert_equal(users(:project_viewer).uuid, json_response['authorized_user_uuid']) + + get('/arvados/v1/repositories/' + repositories(:foo).uuid, + params: {}, + headers: auth(:active)) + assert_response(:success) + assert_equal(users(:project_viewer).uuid, json_response['owner_uuid']) + + get('/arvados/v1/groups/' + groups(:aproject).uuid, + params: {}, + headers: auth(:active)) + assert_response(:success) + assert_equal(project_uuid, json_response['owner_uuid']) + end end