|
|
|
@@ -144,19 +144,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
t.Run("When user is an Org Viewer", func(t *testing.T) {
|
|
|
|
|
role := models.ROLE_VIEWER
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
dash := getDashboardShouldReturn200(sc)
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
|
|
|
|
|
assert.False(t, dash.Meta.CanEdit)
|
|
|
|
|
assert.False(t, dash.Meta.CanSave)
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -170,20 +157,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, &HTTPServer{
|
|
|
|
|
Cfg: setting.NewCfg(),
|
|
|
|
|
LibraryPanelService: &mockLibraryPanelService{},
|
|
|
|
|
LibraryElementService: &mockLibraryElementService{},
|
|
|
|
|
})
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -218,19 +191,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
t.Run("When user is an Org Editor", func(t *testing.T) {
|
|
|
|
|
role := models.ROLE_EDITOR
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
dash := getDashboardShouldReturn200(sc)
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
|
|
|
|
|
assert.True(t, dash.Meta.CanEdit)
|
|
|
|
|
assert.True(t, dash.Meta.CanSave)
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -243,19 +203,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, &HTTPServer{
|
|
|
|
|
Cfg: setting.NewCfg(),
|
|
|
|
|
LibraryPanelService: &mockLibraryPanelService{},
|
|
|
|
|
LibraryElementService: &mockLibraryElementService{},
|
|
|
|
|
})
|
|
|
|
|
assert.Equal(t, 200, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -353,16 +300,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
t.Run("When user is an Org Viewer and has no permissions for this dashboard", func(t *testing.T) {
|
|
|
|
|
role := models.ROLE_VIEWER
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
sc.handlerFunc = hs.GetDashboard
|
|
|
|
|
sc.fakeReqWithParams("GET", sc.url, map[string]string{}).exec()
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -373,15 +310,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, hs)
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -411,17 +339,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
t.Run("When user is an Org Editor and has no permissions for this dashboard", func(t *testing.T) {
|
|
|
|
|
role := models.ROLE_EDITOR
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
sc.handlerFunc = hs.GetDashboard
|
|
|
|
|
sc.fakeReqWithParams("GET", sc.url, map[string]string{}).exec()
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -433,15 +350,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, hs)
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUp()
|
|
|
|
@@ -484,22 +392,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
return state
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
bus.AddHandler("test", func(query *models.GetDashboardAclInfoListQuery) error {
|
|
|
|
|
query.Result = mockResult
|
|
|
|
|
return nil
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
dash := getDashboardShouldReturn200(sc)
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
assert.True(t, dash.Meta.CanEdit)
|
|
|
|
|
assert.True(t, dash.Meta.CanSave)
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi",
|
|
|
|
|
"/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
@@ -512,14 +404,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, hs)
|
|
|
|
|
assert.Equal(t, 200, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -567,17 +451,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
return state
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
dash := getDashboardShouldReturn200(sc)
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
assert.True(t, dash.Meta.CanEdit)
|
|
|
|
|
assert.False(t, dash.Meta.CanSave)
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -590,14 +463,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.False(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, hs)
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -623,16 +488,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
return state
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
dash := getDashboardShouldReturn200(sc)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
assert.True(t, dash.Meta.CanEdit)
|
|
|
|
|
assert.True(t, dash.Meta.CanSave)
|
|
|
|
|
assert.True(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -644,14 +499,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.True(t, dash.Meta.CanAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, hs)
|
|
|
|
|
assert.Equal(t, 200, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -691,16 +538,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
return state
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
dash := getDashboardShouldReturn200(sc)
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
assert.False(t, dash.Meta.CanEdit)
|
|
|
|
|
assert.False(t, dash.Meta.CanSave)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling GET on", "GET", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -710,14 +547,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
assert.False(t, dash.Meta.CanSave)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/child-dash", "/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, hs)
|
|
|
|
|
assert.Equal(t, 403, sc.resp.Code)
|
|
|
|
|
assert.Equal(t, "child-dash", state.dashQueries[0].Slug)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/uid/abcdefghi", "/api/dashboards/uid/:uid", role, func(sc *scenarioContext) {
|
|
|
|
|
state := setUpInner()
|
|
|
|
|
|
|
|
|
@@ -758,18 +587,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
query.Result = dashboards
|
|
|
|
|
return nil
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
role := models.ROLE_EDITOR
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/dash",
|
|
|
|
|
"/api/dashboards/db/:slug", role, func(sc *scenarioContext) {
|
|
|
|
|
callDeleteDashboardBySlug(sc, &HTTPServer{Cfg: setting.NewCfg()})
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, 412, sc.resp.Code)
|
|
|
|
|
result := sc.ToJSON()
|
|
|
|
|
assert.Equal(t, "multiple-slugs-exists", result.Get("status").MustString())
|
|
|
|
|
assert.Equal(t, models.ErrDashboardsWithSameSlugExists.Error(), result.Get("message").MustString())
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
t.Run("Post dashboard response tests", func(t *testing.T) {
|
|
|
|
@@ -1132,21 +949,6 @@ func TestDashboardAPIEndpoint(t *testing.T) {
|
|
|
|
|
})
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/dash",
|
|
|
|
|
"/api/dashboards/db/:slug", models.ROLE_EDITOR, func(sc *scenarioContext) {
|
|
|
|
|
setUp()
|
|
|
|
|
|
|
|
|
|
callDeleteDashboardBySlug(sc, &HTTPServer{
|
|
|
|
|
Cfg: setting.NewCfg(),
|
|
|
|
|
LibraryPanelService: &mockLibraryPanelService{},
|
|
|
|
|
LibraryElementService: &mockLibraryElementService{},
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, 400, sc.resp.Code)
|
|
|
|
|
result := sc.ToJSON()
|
|
|
|
|
assert.Equal(t, models.ErrDashboardCannotDeleteProvisionedDashboard.Error(), result.Get("error").MustString())
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
loggedInUserScenarioWithRole(t, "When calling DELETE on", "DELETE", "/api/dashboards/db/abcdefghi", "/api/dashboards/db/:uid", models.ROLE_EDITOR, func(sc *scenarioContext) {
|
|
|
|
|
setUp()
|
|
|
|
|
|
|
|
|
|