From b7055791257e51cf22a5d2dc9c0cf2af529a3a5e Mon Sep 17 00:00:00 2001 From: John Chilton Date: Tue, 29 Nov 2016 14:10:34 -0500 Subject: [PATCH] Fix configuration API admin checking and tests. - Move CasperJS tests for configuration API into API test framework. - Fix bug where configuration API wouldn't treat master API key as coming from an admin user. --- .../webapps/galaxy/api/configuration.py | 2 +- test/api/test_configuration.py | 41 ++++++++++ test/casperjs/api-configuration-tests.js | 75 ------------------- 3 files changed, 42 insertions(+), 76 deletions(-) create mode 100644 test/api/test_configuration.py delete mode 100644 test/casperjs/api-configuration-tests.js diff --git a/lib/galaxy/webapps/galaxy/api/configuration.py b/lib/galaxy/webapps/galaxy/api/configuration.py index b1188b01ada..7187a67f8ef 100644 --- a/lib/galaxy/webapps/galaxy/api/configuration.py +++ b/lib/galaxy/webapps/galaxy/api/configuration.py @@ -29,7 +29,7 @@ class ConfigurationController( BaseAPIController ): Note: a more complete list is returned if the user is an admin. """ - is_admin = self.user_manager.is_admin( trans.user ) + is_admin = trans.user_is_admin() serialization_params = self._parse_serialization_params( kwd, 'all' ) return self.get_config_dict( trans, is_admin, **serialization_params ) diff --git a/test/api/test_configuration.py b/test/api/test_configuration.py new file mode 100644 index 00000000000..c6927a3d8d4 --- /dev/null +++ b/test/api/test_configuration.py @@ -0,0 +1,41 @@ +from base import api +from base.api_asserts import ( + assert_has_keys, + assert_not_has_keys, +) + +TEST_KEYS_FOR_ALL_USERS = [ + 'enable_unique_workflow_defaults', + 'ftp_upload_site', + 'ftp_upload_dir', + 'wiki_url', + 'support_url', + 'logo_url', + 'terms_url', + 'allow_user_dataset_purge', +] +TEST_KEYS_FOR_ADMIN_ONLY = [ + 'library_import_dir', + 'user_library_import_dir', + 'allow_library_path_paste', + 'allow_user_deletion', +] + + +class ConfigurationApiTestCase(api.ApiTestCase): + + def test_normal_user_configuration(self): + config = self._get_configuration() + assert_has_keys(config, *TEST_KEYS_FOR_ALL_USERS) + assert_not_has_keys(config, *TEST_KEYS_FOR_ADMIN_ONLY) + + def test_admin_user_configuration(self): + config = self._get_configuration(admin=True) + assert_has_keys(config, *TEST_KEYS_FOR_ALL_USERS) + assert_has_keys(config, *TEST_KEYS_FOR_ADMIN_ONLY) + + def _get_configuration(self, data={}, admin=False): + response = self._get("configuration", data=data, admin=admin) + self._assert_status_code_is(response, 200) + configuration = response.json() + return configuration diff --git a/test/casperjs/api-configuration-tests.js b/test/casperjs/api-configuration-tests.js deleted file mode 100644 index faeb301c92a..00000000000 --- a/test/casperjs/api-configuration-tests.js +++ /dev/null @@ -1,75 +0,0 @@ -var require = patchRequire( require ), - spaceghost = require( 'spaceghost' ).fromCasper( casper ), - xpath = require( 'casper' ).selectXPath, - utils = require( 'utils' ), - format = utils.format; - -spaceghost.test.begin( 'Test the Galaxy configuration API', 0, function suite( test ){ - spaceghost.start(); - - // =================================================================== SET UP - var email = spaceghost.user.getRandomEmail(), - password = '123456'; - if( spaceghost.fixtureData.testUser ){ - email = spaceghost.fixtureData.testUser.email; - password = spaceghost.fixtureData.testUser.password; - } - spaceghost.user.loginOrRegisterUser( email, password ); - - // =================================================================== TESTS - var normKeys = [ - 'enable_unique_workflow_defaults', - 'ftp_upload_site', - 'ftp_upload_dir', - 'wiki_url', - 'support_url', - 'logo_url', - 'terms_url', - 'allow_user_dataset_purge' - ], - adminKeys = normKeys.concat([ - 'library_import_dir', - 'user_library_import_dir', - 'allow_library_path_paste', - 'allow_user_creation', - 'allow_user_deletion' - ]); - - // ------------------------------------------------------------------------------------------- INDEX - spaceghost.openHomePage().then( function(){ - this.test.comment( 'index should get a (shortened) list of configuration settings ' - + 'when requested by a normal user' ); - - var configIndex = this.api.configuration.index(); - this.debug( this.jsonStr( configIndex ) ); - this.test.assert( utils.isObject( configIndex ), "index returned an object" ); - this.test.assert( this.hasKeys( configIndex, normKeys ), 'Has the proper keys' ); - - }); - spaceghost.user.logout(); - - // ------------------------------------------------------------------------------------------- INDEX (admin) - spaceghost.tryStepsCatch( function tryAdminLogin(){ - spaceghost.user.loginAdmin(); - }, function(){} ); - - //}, function failedLoginRegister(){ - // this.info( 'Admin level configuration API tests not run: no admin account available' ); - spaceghost.openHomePage().waitForMasthead( function(){ - if( spaceghost.user.userIsAdmin() ){ - this.test.comment( 'index should get a (full) list of configuration settings ' - + 'when requested by an admin user' ); - configIndex = this.api.configuration.index(); - this.debug( this.jsonStr( configIndex ) ); - this.test.assert( utils.isObject( configIndex ), "index returned an object" ); - this.test.assert( this.hasKeys( configIndex, adminKeys ), 'Has the proper keys' ); - - } else { - this.info( 'Admin level configuration API tests not run: no admin account available' ); - } - }); - - // =================================================================== - spaceghost.run( function(){ test.done(); }); -}); -