From 2e16169509772bfa17e4fbe040aa31bbd9b2b4d9 Mon Sep 17 00:00:00 2001 From: Alexander Skoblikov Date: Wed, 22 Mar 2023 22:56:07 +0100 Subject: [PATCH] CB-3261 validate empty project id (#1550) Co-authored-by: dariamarutkina <125263541+dariamarutkina@users.noreply.github.com> --- .../rm/local/LocalResourceController.java | 24 ++++++++++++------ .../test/platform/ResourceManagerTest.java | 25 ++++++++++++++++--- .../rmReadEmptyProjectIdResources.json | 3 +++ 3 files changed, 41 insertions(+), 11 deletions(-) create mode 100644 server/test/io.cloudbeaver.test.platform/workspace/gql_scripts/rmReadEmptyProjectIdResources.json diff --git a/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/rm/local/LocalResourceController.java b/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/rm/local/LocalResourceController.java index 886ba81a66..1fbbd8f06b 100644 --- a/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/rm/local/LocalResourceController.java +++ b/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/rm/local/LocalResourceController.java @@ -180,8 +180,9 @@ public class LocalResourceController implements RMController { return accessibleSharedProjects .stream() + .filter(smObjectPermissions -> CommonUtils.isNotEmpty(smObjectPermissions.getObjectId())) .map(projectPermission -> makeProjectFromPath( - sharedProjectsPath.resolve(parseProjectName(projectPermission.getObjectId()).getName()), + sharedProjectsPath.resolve(parseProjectNameUnsafe(projectPermission.getObjectId()).getName()), Arrays.stream(projectPermission.getPermissions()).map(RMProjectPermission::fromPermission).collect(Collectors.toSet()), RMProjectType.SHARED, true) ) @@ -804,7 +805,7 @@ public class LocalResourceController implements RMController { return getGlobalProjectPath(); case SHARED: return sharedProjectsPath.resolve(projectName); - default: + case USER: var activeUserCredentials = credentialsProvider.getActiveUserCredentials(); var userId = activeUserCredentials == null ? null : activeUserCredentials.getUserId(); var isAdmin = activeUserCredentials != null && activeUserCredentials.hasPermission(DBWConstants.PERMISSION_ADMIN); @@ -812,6 +813,8 @@ public class LocalResourceController implements RMController { throw new DBException("No access to the project: " + projectName); } return userProjectsPath.resolve(projectName); + default: + throw new DBException("Invalid project type [" + type + "]"); } } @@ -981,7 +984,15 @@ public class LocalResourceController implements RMController { return RMProjectType.getByPrefix(prefix); } } - public static RMProjectName parseProjectName(String projectId) { + + public static RMProjectName parseProjectName(String projectId) throws DBException { + if (CommonUtils.isEmpty(projectId)) { + throw new DBException("Project id is empty"); + } + return parseProjectNameUnsafe(projectId); + } + + private static RMProjectName parseProjectNameUnsafe(String projectId) { String prefix; String name; int divPos = projectId.indexOf("_"); @@ -996,16 +1007,13 @@ public class LocalResourceController implements RMController { } public static boolean isGlobalProject(String projectId) { - RMProjectName rmProjectName = parseProjectName(projectId); + RMProjectName rmProjectName = parseProjectNameUnsafe(projectId); return RMProjectType.GLOBAL.getPrefix().equals(rmProjectName.getPrefix()); } public static boolean isPrivateProject(String projectId, String userId) { - RMProjectName rmProjectName = parseProjectName(projectId); + RMProjectName rmProjectName = parseProjectNameUnsafe(projectId); return RMProjectType.USER.getPrefix().equals(rmProjectName.getPrefix()) && rmProjectName.name.equals(userId); } - - - } diff --git a/server/test/io.cloudbeaver.test.platform/src/io/cloudbeaver/test/platform/ResourceManagerTest.java b/server/test/io.cloudbeaver.test.platform/src/io/cloudbeaver/test/platform/ResourceManagerTest.java index 126709368f..46746f78be 100644 --- a/server/test/io.cloudbeaver.test.platform/src/io/cloudbeaver/test/platform/ResourceManagerTest.java +++ b/server/test/io.cloudbeaver.test.platform/src/io/cloudbeaver/test/platform/ResourceManagerTest.java @@ -24,6 +24,7 @@ import org.jkiss.dbeaver.model.auth.SMAuthStatus; import org.jkiss.dbeaver.model.data.json.JSONUtils; import org.jkiss.utils.CommonUtils; import org.junit.Assert; +import org.junit.BeforeClass; import org.junit.Test; import java.net.CookieManager; @@ -34,23 +35,41 @@ public class ResourceManagerTest { public static final String GQL_TEMPLATE_RM_WRITE_RESOURCE = "rmWriteResource.json"; public static final String GQL_TEMPLATE_RM_DELETE_RESOURCE = "navDeleteNode.json"; + public static final String GQL_READ_EMPTY_PROJECT_ID_RESOURCES = "rmReadEmptyProjectIdResources.json"; - @Test - public void createDeleteResourceTest() throws Exception { + private static HttpClient client; + + @BeforeClass + public static void init() throws Exception { Assert.assertTrue(CBApplication.getInstance().getAppConfiguration().isResourceManagerEnabled()); - HttpClient client = HttpClient.newBuilder() + client = HttpClient.newBuilder() .cookieHandler(new CookieManager()) .version(HttpClient.Version.HTTP_2) .build(); Map authInfo = WebTestUtils.authenticateUser( client, CEServerTestSuite.getScriptsPath(), CEServerTestSuite.GQL_API_URL); Assert.assertEquals(SMAuthStatus.SUCCESS.name(), JSONUtils.getString(authInfo, "authStatus")); + + } + + @Test + public void createDeleteResourceTest() throws Exception { Assert.assertTrue(createResource(client, false)); Assert.assertFalse(createResource(client, false)); Assert.assertTrue(createResource(client, true)); Assert.assertEquals(1, deleteResource(client)); } + @Test + public void listResourcesWithInvalidProjectId() throws Exception { + String input = WebTestUtils.readScriptTemplate(GQL_READ_EMPTY_PROJECT_ID_RESOURCES, CEServerTestSuite.getScriptsPath()); + Map map = WebTestUtils.doPost(CEServerTestSuite.GQL_API_URL, input, client); + var errors = JSONUtils.getObjectList(map, "errors"); + Assert.assertFalse("No errors happened with empty project id request", errors.isEmpty()); + var rmError = errors.get(0); + //FIXME stupid way to validate error + Assert.assertTrue(JSONUtils.getString(rmError, "message", "").contains("Project id is empty")); + } private boolean createResource(HttpClient client, boolean forceOverwrite) throws Exception { String input = WebTestUtils.readScriptTemplate( diff --git a/server/test/io.cloudbeaver.test.platform/workspace/gql_scripts/rmReadEmptyProjectIdResources.json b/server/test/io.cloudbeaver.test.platform/workspace/gql_scripts/rmReadEmptyProjectIdResources.json new file mode 100644 index 0000000000..114f2ea64c --- /dev/null +++ b/server/test/io.cloudbeaver.test.platform/workspace/gql_scripts/rmReadEmptyProjectIdResources.json @@ -0,0 +1,3 @@ +{ + "query": "query {\n rmListResources(projectId: \"\") {\n name\n folder\n}\n}" +} \ No newline at end of file