diff --git a/lib/galaxy/security/__init__.py b/lib/galaxy/security/__init__.py index 964b1fd26a0..4601fae47d6 100644 --- a/lib/galaxy/security/__init__.py +++ b/lib/galaxy/security/__init__.py @@ -26,7 +26,7 @@ class RBACAgent: LIBRARY_MODIFY = Action( "modify library item", "Users having associated role can modify this library item", "grant" ), LIBRARY_MANAGE = Action( "manage library permissions", "Users having associated role can manage roles associated with permissions on this library item", "grant" ), # Request type permissions - REQUEST_TYPE_ACCESS = Action( "access request_type", "Restrict access to only users having associated role", "restrict" ) + REQUEST_TYPE_ACCESS = Action( "access request_type", "Users having associated role can access this sequencer configuration", "grant" ) ) def get_action( self, name, default=None ): @@ -917,12 +917,12 @@ class GalaxyRBACAgent( RBACAgent ): request_type_actions = [] for permission in request_type.actions: if permission.action == action.action: - request_type_actions.append(permission) + request_type_actions.append( permission ) if not request_type_actions: - return action.model == 'restrict' + return False ret_val = False - for item_action in item_actions: - if item_action.role in roles: + for request_type_action in request_type_actions: + if request_type_action.role in roles: ret_val = True break return ret_val diff --git a/lib/galaxy/web/controllers/requests_common.py b/lib/galaxy/web/controllers/requests_common.py index ee83e7cfda9..9190514542c 100644 --- a/lib/galaxy/web/controllers/requests_common.py +++ b/lib/galaxy/web/controllers/requests_common.py @@ -170,6 +170,11 @@ class RequestsCommon( BaseController, UsesFormDefinitionWidgets ): elif user is None: message = 'Invalid user ID (%s)' % str(user_id) status = 'error' + # when creating a request from the user perspective, check if the + # user has access permission to this request_type + elif cntrller == 'requests' and not trans.app.security_agent.can_access_request_type( user.all_roles(), request_type ): + message = '%s does not have access permission to the "%s" sequencer configuration.' % ( user.email, request_type.name ) + status = 'error' elif not name: message = 'Enter the name of the request.' status = 'error' diff --git a/test/functional/test_sample_tracking.py b/test/functional/test_sample_tracking.py index 16c2d6b4397..05444f2a833 100644 --- a/test/functional/test_sample_tracking.py +++ b/test/functional/test_sample_tracking.py @@ -444,12 +444,7 @@ class TestFormsAndSampleTracking( TwillTestCase ): for values in field_values: strings_displayed_after_submit.append( values ) # list folders that populates folder selectfield when a data library is selected - folder_options = [] - folder_options.append( library2_folder1.name ) - folder_options.append( library2_folder2.name ) - folder_options.append( library2_folder3.name ) - folder_options.append( library2_folder4.name ) - # Add samples to the request + folder_options = [ library2_folder1.name, library2_folder2.name, library2_folder3.name, library2_folder4.name ] # Add samples to the request self.add_samples( cntrller='requests', request_id=self.security.encode_id( request1.id ), sample_value_tuples=sample_value_tuples, @@ -485,12 +480,11 @@ class TestFormsAndSampleTracking( TwillTestCase ): for values in field_values: strings_displayed_after_submit.append( values ) strings_displayed = [ 'Edit Current Samples of Sequencing Request "%s"' % request1.name, - '' ] # sample name input field - # all the folders in library2 should show up in the folder selectlist - strings_displayed.append( library2_folder1.name ) - strings_displayed.append( library2_folder2.name ) - strings_displayed.append( library2_folder3.name ) - strings_displayed.append( library2_folder4.name ) + '', # sample name input field + library2_folder1.name, # all the folders in library2 should show up in the folder selectlist + library2_folder2.name, + library2_folder3.name, + library2_folder4.name ] # Add samples to the request self.edit_samples( cntrller='requests', request_id=self.security.encode_id( request1.id ), @@ -716,11 +710,7 @@ class TestFormsAndSampleTracking( TwillTestCase ): state='All', strings_displayed=[ request1.name, request2.name ] ) # list folders that populates folder selectfield when a data library is selected - folder_options = [] - folder_options.append( library2_folder1.name ) - folder_options.append( library2_folder2.name ) - folder_options.append( library2_folder3.name ) - folder_options.append( library2_folder4.name ) + folder_options = [ library2_folder1.name, library2_folder2.name, library2_folder3.name, library2_folder4.name ] # set the target data library to library2 using sample operation user interface self.change_sample_target_data_library( cntrller='requests', request_id=self.security.encode_id( request2.id ),