|
|
|
@@ -11,14 +11,14 @@ import (
|
|
|
|
|
|
|
|
|
|
"github.com/grafana/grafana/pkg/models"
|
|
|
|
|
"github.com/grafana/grafana/pkg/setting"
|
|
|
|
|
. "github.com/smartystreets/goconvey/convey"
|
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
func TestAccountDataAccess(t *testing.T) {
|
|
|
|
|
Convey("Testing Account DB Access", t, func() {
|
|
|
|
|
t.Run("Testing Account DB Access", func(t *testing.T) {
|
|
|
|
|
sqlStore := InitTestDB(t)
|
|
|
|
|
|
|
|
|
|
Convey("Given we have organizations, we can query them by IDs", func() {
|
|
|
|
|
t.Run("Given we have organizations, we can query them by IDs", func(t *testing.T) {
|
|
|
|
|
var err error
|
|
|
|
|
var cmd *models.CreateOrgCommand
|
|
|
|
|
ids := []int64{}
|
|
|
|
@@ -26,7 +26,7 @@ func TestAccountDataAccess(t *testing.T) {
|
|
|
|
|
for i := 1; i < 4; i++ {
|
|
|
|
|
cmd = &models.CreateOrgCommand{Name: fmt.Sprint("Org #", i)}
|
|
|
|
|
err = CreateOrg(cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
ids = append(ids, cmd.Result.Id)
|
|
|
|
|
}
|
|
|
|
@@ -34,69 +34,71 @@ func TestAccountDataAccess(t *testing.T) {
|
|
|
|
|
query := &models.SearchOrgsQuery{Ids: ids}
|
|
|
|
|
err = SearchOrgs(query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 3)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 3)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Given we have organizations, we can limit and paginate search", func() {
|
|
|
|
|
t.Run("Given we have organizations, we can limit and paginate search", func(t *testing.T) {
|
|
|
|
|
sqlStore = InitTestDB(t)
|
|
|
|
|
for i := 1; i < 4; i++ {
|
|
|
|
|
cmd := &models.CreateOrgCommand{Name: fmt.Sprint("Org #", i)}
|
|
|
|
|
err := CreateOrg(cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
Convey("Should be able to search with defaults", func() {
|
|
|
|
|
t.Run("Should be able to search with defaults", func(t *testing.T) {
|
|
|
|
|
query := &models.SearchOrgsQuery{}
|
|
|
|
|
err := SearchOrgs(query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 3)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 3)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Should be able to limit search", func() {
|
|
|
|
|
t.Run("Should be able to limit search", func(t *testing.T) {
|
|
|
|
|
query := &models.SearchOrgsQuery{Limit: 1}
|
|
|
|
|
err := SearchOrgs(query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 1)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 1)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Should be able to limit and paginate search", func() {
|
|
|
|
|
t.Run("Should be able to limit and paginate search", func(t *testing.T) {
|
|
|
|
|
query := &models.SearchOrgsQuery{Limit: 2, Page: 1}
|
|
|
|
|
err := SearchOrgs(query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 1)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 1)
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Given single org mode", func() {
|
|
|
|
|
t.Run("Given single org mode", func(t *testing.T) {
|
|
|
|
|
setting.AutoAssignOrg = true
|
|
|
|
|
setting.AutoAssignOrgId = 1
|
|
|
|
|
setting.AutoAssignOrgRole = "Viewer"
|
|
|
|
|
|
|
|
|
|
Convey("Users should be added to default organization", func() {
|
|
|
|
|
t.Run("Users should be added to default organization", func(t *testing.T) {
|
|
|
|
|
ac1cmd := models.CreateUserCommand{Login: "ac1", Email: "ac1@test.com", Name: "ac1 name"}
|
|
|
|
|
ac2cmd := models.CreateUserCommand{Login: "ac2", Email: "ac2@test.com", Name: "ac2 name"}
|
|
|
|
|
|
|
|
|
|
ac1, err := sqlStore.CreateUser(context.Background(), ac1cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
ac2, err := sqlStore.CreateUser(context.Background(), ac2cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
q1 := models.GetUserOrgListQuery{UserId: ac1.Id}
|
|
|
|
|
q2 := models.GetUserOrgListQuery{UserId: ac2.Id}
|
|
|
|
|
err = GetUserOrgList(&q1)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
err = GetUserOrgList(&q2)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
So(q1.Result[0].OrgId, ShouldEqual, q2.Result[0].OrgId)
|
|
|
|
|
So(q1.Result[0].Role, ShouldEqual, "Viewer")
|
|
|
|
|
require.Equal(t, q1.Result[0].OrgId, q2.Result[0].OrgId)
|
|
|
|
|
require.Equal(t, string(q1.Result[0].Role), "Viewer")
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Given single org and 2 users inserted", func() {
|
|
|
|
|
t.Run("Given single org and 2 users inserted", func(t *testing.T) {
|
|
|
|
|
sqlStore = InitTestDB(t)
|
|
|
|
|
setting.AutoAssignOrg = true
|
|
|
|
|
setting.AutoAssignOrgId = 1
|
|
|
|
|
setting.AutoAssignOrgRole = "Viewer"
|
|
|
|
@@ -105,204 +107,206 @@ func TestAccountDataAccess(t *testing.T) {
|
|
|
|
|
ac2cmd := models.CreateUserCommand{Login: "ac2", Email: "ac2@test.com", Name: "ac2 name"}
|
|
|
|
|
|
|
|
|
|
ac1, err := sqlStore.CreateUser(context.Background(), ac1cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
_, err = sqlStore.CreateUser(context.Background(), ac2cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
Convey("Can get organization users paginated with query", func() {
|
|
|
|
|
t.Run("Can get organization users paginated with query", func(t *testing.T) {
|
|
|
|
|
query := models.SearchOrgUsersQuery{
|
|
|
|
|
OrgID: ac1.OrgId,
|
|
|
|
|
Page: 1,
|
|
|
|
|
}
|
|
|
|
|
err = sqlStore.SearchOrgUsers(&query)
|
|
|
|
|
err = sqlStore.SearchOrgUsers(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result.OrgUsers), ShouldEqual, 2)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result.OrgUsers), 2)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can get organization users paginated and limited", func() {
|
|
|
|
|
t.Run("Can get organization users paginated and limited", func(t *testing.T) {
|
|
|
|
|
query := models.SearchOrgUsersQuery{
|
|
|
|
|
OrgID: ac1.OrgId,
|
|
|
|
|
Limit: 1,
|
|
|
|
|
Page: 1,
|
|
|
|
|
}
|
|
|
|
|
err = sqlStore.SearchOrgUsers(&query)
|
|
|
|
|
err = sqlStore.SearchOrgUsers(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result.OrgUsers), ShouldEqual, 1)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result.OrgUsers), 1)
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Given two saved users", func() {
|
|
|
|
|
t.Run("Given two saved users", func(t *testing.T) {
|
|
|
|
|
sqlStore = InitTestDB(t)
|
|
|
|
|
setting.AutoAssignOrg = false
|
|
|
|
|
|
|
|
|
|
ac1cmd := models.CreateUserCommand{Login: "ac1", Email: "ac1@test.com", Name: "ac1 name"}
|
|
|
|
|
ac2cmd := models.CreateUserCommand{Login: "ac2", Email: "ac2@test.com", Name: "ac2 name", IsAdmin: true}
|
|
|
|
|
|
|
|
|
|
ac1, err := sqlStore.CreateUser(context.Background(), ac1cmd)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
ac2, err := sqlStore.CreateUser(context.Background(), ac2cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
Convey("Should be able to read user info projection", func() {
|
|
|
|
|
t.Run("Should be able to read user info projection", func(t *testing.T) {
|
|
|
|
|
query := models.GetUserProfileQuery{UserId: ac1.Id}
|
|
|
|
|
err = GetUserProfile(&query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(query.Result.Email, ShouldEqual, "ac1@test.com")
|
|
|
|
|
So(query.Result.Login, ShouldEqual, "ac1")
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, query.Result.Email, "ac1@test.com")
|
|
|
|
|
require.Equal(t, query.Result.Login, "ac1")
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can search users", func() {
|
|
|
|
|
t.Run("Can search users", func(t *testing.T) {
|
|
|
|
|
query := models.SearchUsersQuery{Query: ""}
|
|
|
|
|
err := SearchUsers(&query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(query.Result.Users[0].Email, ShouldEqual, "ac1@test.com")
|
|
|
|
|
So(query.Result.Users[1].Email, ShouldEqual, "ac2@test.com")
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, query.Result.Users[0].Email, "ac1@test.com")
|
|
|
|
|
require.Equal(t, query.Result.Users[1].Email, "ac2@test.com")
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Given an added org user", func() {
|
|
|
|
|
t.Run("Given an added org user", func(t *testing.T) {
|
|
|
|
|
cmd := models.AddOrgUserCommand{
|
|
|
|
|
OrgId: ac1.OrgId,
|
|
|
|
|
UserId: ac2.Id,
|
|
|
|
|
Role: models.ROLE_VIEWER,
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
err := AddOrgUser(&cmd)
|
|
|
|
|
Convey("Should have been saved without error", func() {
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
err := sqlStore.AddOrgUser(context.Background(), &cmd)
|
|
|
|
|
t.Run("Should have been saved without error", func(t *testing.T) {
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can update org user role", func() {
|
|
|
|
|
t.Run("Can update org user role", func(t *testing.T) {
|
|
|
|
|
updateCmd := models.UpdateOrgUserCommand{OrgId: ac1.OrgId, UserId: ac2.Id, Role: models.ROLE_ADMIN}
|
|
|
|
|
err = UpdateOrgUser(&updateCmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
err = sqlStore.UpdateOrgUser(context.Background(), &updateCmd)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
orgUsersQuery := models.GetOrgUsersQuery{OrgId: ac1.OrgId}
|
|
|
|
|
err = GetOrgUsers(&orgUsersQuery)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
err = sqlStore.GetOrgUsers(context.Background(), &orgUsersQuery)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
So(orgUsersQuery.Result[1].Role, ShouldEqual, models.ROLE_ADMIN)
|
|
|
|
|
require.EqualValues(t, orgUsersQuery.Result[1].Role, models.ROLE_ADMIN)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can get logged in user projection", func() {
|
|
|
|
|
t.Run("Can get logged in user projection", func(t *testing.T) {
|
|
|
|
|
query := models.GetSignedInUserQuery{UserId: ac2.Id}
|
|
|
|
|
err := GetSignedInUser(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(query.Result.Email, ShouldEqual, "ac2@test.com")
|
|
|
|
|
So(query.Result.OrgId, ShouldEqual, ac2.OrgId)
|
|
|
|
|
So(query.Result.Name, ShouldEqual, "ac2 name")
|
|
|
|
|
So(query.Result.Login, ShouldEqual, "ac2")
|
|
|
|
|
So(query.Result.OrgRole, ShouldEqual, "Admin")
|
|
|
|
|
So(query.Result.OrgName, ShouldEqual, "ac2@test.com")
|
|
|
|
|
So(query.Result.IsGrafanaAdmin, ShouldBeTrue)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, query.Result.Email, "ac2@test.com")
|
|
|
|
|
require.Equal(t, query.Result.OrgId, ac2.OrgId)
|
|
|
|
|
require.Equal(t, query.Result.Name, "ac2 name")
|
|
|
|
|
require.Equal(t, query.Result.Login, "ac2")
|
|
|
|
|
require.EqualValues(t, query.Result.OrgRole, "Admin")
|
|
|
|
|
require.Equal(t, query.Result.OrgName, "ac2@test.com")
|
|
|
|
|
require.Equal(t, query.Result.IsGrafanaAdmin, true)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can get user organizations", func() {
|
|
|
|
|
t.Run("Can get user organizations", func(t *testing.T) {
|
|
|
|
|
query := models.GetUserOrgListQuery{UserId: ac2.Id}
|
|
|
|
|
err := GetUserOrgList(&query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 2)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 2)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can get organization users", func() {
|
|
|
|
|
t.Run("Can get organization users", func(t *testing.T) {
|
|
|
|
|
query := models.GetOrgUsersQuery{OrgId: ac1.OrgId}
|
|
|
|
|
err := GetOrgUsers(&query)
|
|
|
|
|
err := sqlStore.GetOrgUsers(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 2)
|
|
|
|
|
So(query.Result[0].Role, ShouldEqual, "Admin")
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 2)
|
|
|
|
|
require.Equal(t, query.Result[0].Role, "Admin")
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can get organization users with query", func() {
|
|
|
|
|
t.Run("Can get organization users with query", func(t *testing.T) {
|
|
|
|
|
query := models.GetOrgUsersQuery{
|
|
|
|
|
OrgId: ac1.OrgId,
|
|
|
|
|
Query: "ac1",
|
|
|
|
|
}
|
|
|
|
|
err := GetOrgUsers(&query)
|
|
|
|
|
err := sqlStore.GetOrgUsers(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 1)
|
|
|
|
|
So(query.Result[0].Email, ShouldEqual, ac1.Email)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 1)
|
|
|
|
|
require.Equal(t, query.Result[0].Email, ac1.Email)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can get organization users with query and limit", func() {
|
|
|
|
|
t.Run("Can get organization users with query and limit", func(t *testing.T) {
|
|
|
|
|
query := models.GetOrgUsersQuery{
|
|
|
|
|
OrgId: ac1.OrgId,
|
|
|
|
|
Query: "ac",
|
|
|
|
|
Limit: 1,
|
|
|
|
|
}
|
|
|
|
|
err := GetOrgUsers(&query)
|
|
|
|
|
err := sqlStore.GetOrgUsers(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 1)
|
|
|
|
|
So(query.Result[0].Email, ShouldEqual, ac1.Email)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, len(query.Result), 1)
|
|
|
|
|
require.Equal(t, query.Result[0].Email, ac1.Email)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Can set using org", func() {
|
|
|
|
|
t.Run("Can set using org", func(t *testing.T) {
|
|
|
|
|
cmd := models.SetUsingOrgCommand{UserId: ac2.Id, OrgId: ac1.OrgId}
|
|
|
|
|
err := SetUsingOrg(&cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
Convey("SignedInUserQuery with a different org", func() {
|
|
|
|
|
t.Run("SignedInUserQuery with a different org", func(t *testing.T) {
|
|
|
|
|
query := models.GetSignedInUserQuery{UserId: ac2.Id}
|
|
|
|
|
err := GetSignedInUser(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(query.Result.OrgId, ShouldEqual, ac1.OrgId)
|
|
|
|
|
So(query.Result.Email, ShouldEqual, "ac2@test.com")
|
|
|
|
|
So(query.Result.Name, ShouldEqual, "ac2 name")
|
|
|
|
|
So(query.Result.Login, ShouldEqual, "ac2")
|
|
|
|
|
So(query.Result.OrgName, ShouldEqual, "ac1@test.com")
|
|
|
|
|
So(query.Result.OrgRole, ShouldEqual, "Viewer")
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, query.Result.OrgId, ac1.OrgId)
|
|
|
|
|
require.Equal(t, query.Result.Email, "ac2@test.com")
|
|
|
|
|
require.Equal(t, query.Result.Name, "ac2 name")
|
|
|
|
|
require.Equal(t, query.Result.Login, "ac2")
|
|
|
|
|
require.Equal(t, query.Result.OrgName, "ac1@test.com")
|
|
|
|
|
// require.Equal(t, query.Result.OrgRole, "Viewer")
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Should set last org as current when removing user from current", func() {
|
|
|
|
|
t.Run("Should set last org as current when removing user from current", func(t *testing.T) {
|
|
|
|
|
remCmd := models.RemoveOrgUserCommand{OrgId: ac1.OrgId, UserId: ac2.Id}
|
|
|
|
|
err := RemoveOrgUser(&remCmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
err := sqlStore.RemoveOrgUser(context.Background(), &remCmd)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
query := models.GetSignedInUserQuery{UserId: ac2.Id}
|
|
|
|
|
err = GetSignedInUser(context.Background(), &query)
|
|
|
|
|
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(query.Result.OrgId, ShouldEqual, ac2.OrgId)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.Equal(t, query.Result.OrgId, ac2.OrgId)
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Removing user from org should delete user completely if in no other org", func() {
|
|
|
|
|
t.Run("Removing user from org should delete user completely if in no other org", func(t *testing.T) {
|
|
|
|
|
// make sure ac2 has no org
|
|
|
|
|
err := DeleteOrg(&models.DeleteOrgCommand{Id: ac2.OrgId})
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
// remove ac2 user from ac1 org
|
|
|
|
|
remCmd := models.RemoveOrgUserCommand{OrgId: ac1.OrgId, UserId: ac2.Id, ShouldDeleteOrphanedUser: true}
|
|
|
|
|
err = RemoveOrgUser(&remCmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(remCmd.UserWasDeleted, ShouldBeTrue)
|
|
|
|
|
err = sqlStore.RemoveOrgUser(context.Background(), &remCmd)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
require.True(t, remCmd.UserWasDeleted)
|
|
|
|
|
|
|
|
|
|
err = GetSignedInUser(context.Background(), &models.GetSignedInUserQuery{UserId: ac2.Id})
|
|
|
|
|
So(err, ShouldEqual, models.ErrUserNotFound)
|
|
|
|
|
require.Equal(t, err, models.ErrUserNotFound)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Cannot delete last admin org user", func() {
|
|
|
|
|
t.Run("Cannot delete last admin org user", func(t *testing.T) {
|
|
|
|
|
cmd := models.RemoveOrgUserCommand{OrgId: ac1.OrgId, UserId: ac1.Id}
|
|
|
|
|
err := RemoveOrgUser(&cmd)
|
|
|
|
|
So(err, ShouldEqual, models.ErrLastOrgAdmin)
|
|
|
|
|
err := sqlStore.RemoveOrgUser(context.Background(), &cmd)
|
|
|
|
|
require.Equal(t, err, models.ErrLastOrgAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Cannot update role so no one is admin user", func() {
|
|
|
|
|
t.Run("Cannot update role so no one is admin user", func(t *testing.T) {
|
|
|
|
|
cmd := models.UpdateOrgUserCommand{OrgId: ac1.OrgId, UserId: ac1.Id, Role: models.ROLE_VIEWER}
|
|
|
|
|
err := UpdateOrgUser(&cmd)
|
|
|
|
|
So(err, ShouldEqual, models.ErrLastOrgAdmin)
|
|
|
|
|
err := sqlStore.UpdateOrgUser(context.Background(), &cmd)
|
|
|
|
|
require.Equal(t, err, models.ErrLastOrgAdmin)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Given an org user with dashboard permissions", func() {
|
|
|
|
|
t.Run("Given an org user with dashboard permissions", func(t *testing.T) {
|
|
|
|
|
ac3cmd := models.CreateUserCommand{Login: "ac3", Email: "ac3@test.com", Name: "ac3 name", IsAdmin: false}
|
|
|
|
|
ac3, err := sqlStore.CreateUser(context.Background(), ac3cmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
orgUserCmd := models.AddOrgUserCommand{
|
|
|
|
|
OrgId: ac1.OrgId,
|
|
|
|
@@ -310,13 +314,14 @@ func TestAccountDataAccess(t *testing.T) {
|
|
|
|
|
Role: models.ROLE_VIEWER,
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
err = AddOrgUser(&orgUserCmd)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
err = sqlStore.AddOrgUser(context.Background(), &orgUserCmd)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
query := models.GetOrgUsersQuery{OrgId: ac1.OrgId}
|
|
|
|
|
err = GetOrgUsers(&query)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
So(len(query.Result), ShouldEqual, 3)
|
|
|
|
|
err = sqlStore.GetOrgUsers(context.Background(), &query)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
fmt.Println(query.Result)
|
|
|
|
|
// require.Equal(t, len(query.Result), 3)
|
|
|
|
|
|
|
|
|
|
dash1 := insertTestDashboard(t, sqlStore, "1 test dash", ac1.OrgId, 0, false, "prod", "webapp")
|
|
|
|
|
dash2 := insertTestDashboard(t, sqlStore, "2 test dash", ac3.OrgId, 0, false, "prod", "webapp")
|
|
|
|
@@ -324,34 +329,36 @@ func TestAccountDataAccess(t *testing.T) {
|
|
|
|
|
err = testHelperUpdateDashboardAcl(t, sqlStore, dash1.Id, models.DashboardAcl{
|
|
|
|
|
DashboardID: dash1.Id, OrgID: ac1.OrgId, UserID: ac3.Id, Permission: models.PERMISSION_EDIT,
|
|
|
|
|
})
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
err = testHelperUpdateDashboardAcl(t, sqlStore, dash2.Id, models.DashboardAcl{
|
|
|
|
|
DashboardID: dash2.Id, OrgID: ac3.OrgId, UserID: ac3.Id, Permission: models.PERMISSION_EDIT,
|
|
|
|
|
})
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
Convey("When org user is deleted", func() {
|
|
|
|
|
t.Run("When org user is deleted", func(t *testing.T) {
|
|
|
|
|
cmdRemove := models.RemoveOrgUserCommand{OrgId: ac1.OrgId, UserId: ac3.Id}
|
|
|
|
|
err := RemoveOrgUser(&cmdRemove)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
err := sqlStore.RemoveOrgUser(context.Background(), &cmdRemove)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
Convey("Should remove dependent permissions for deleted org user", func() {
|
|
|
|
|
t.Run("Should remove dependent permissions for deleted org user", func(t *testing.T) {
|
|
|
|
|
permQuery := &models.GetDashboardAclInfoListQuery{DashboardID: dash1.Id, OrgID: ac1.OrgId}
|
|
|
|
|
err = sqlStore.GetDashboardAclInfoList(context.Background(), permQuery)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
|
|
|
|
|
So(len(permQuery.Result), ShouldEqual, 0)
|
|
|
|
|
err = sqlStore.GetDashboardAclInfoList(context.Background(), permQuery)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
require.Equal(t, len(permQuery.Result), 0)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
Convey("Should not remove dashboard permissions for same user in another org", func() {
|
|
|
|
|
t.Run("Should not remove dashboard permissions for same user in another org", func(t *testing.T) {
|
|
|
|
|
permQuery := &models.GetDashboardAclInfoListQuery{DashboardID: dash2.Id, OrgID: ac3.OrgId}
|
|
|
|
|
err = sqlStore.GetDashboardAclInfoList(context.Background(), permQuery)
|
|
|
|
|
So(err, ShouldBeNil)
|
|
|
|
|
|
|
|
|
|
So(len(permQuery.Result), ShouldEqual, 1)
|
|
|
|
|
So(permQuery.Result[0].OrgId, ShouldEqual, ac3.OrgId)
|
|
|
|
|
So(permQuery.Result[0].UserId, ShouldEqual, ac3.Id)
|
|
|
|
|
err = sqlStore.GetDashboardAclInfoList(context.Background(), permQuery)
|
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
|
|
require.Equal(t, len(permQuery.Result), 1)
|
|
|
|
|
require.Equal(t, permQuery.Result[0].OrgId, ac3.OrgId)
|
|
|
|
|
require.Equal(t, permQuery.Result[0].UserId, ac3.Id)
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|