diff --git a/e2e-test/src/test/java/org/alfresco/test/search/functional/AbstractE2EFunctionalTest.java b/e2e-test/src/test/java/org/alfresco/test/search/functional/AbstractE2EFunctionalTest.java index 732b3525e..dedd48b10 100644 --- a/e2e-test/src/test/java/org/alfresco/test/search/functional/AbstractE2EFunctionalTest.java +++ b/e2e-test/src/test/java/org/alfresco/test/search/functional/AbstractE2EFunctionalTest.java @@ -18,7 +18,6 @@ import org.alfresco.rest.search.SearchResponse; import org.alfresco.utility.LogFactory; import org.alfresco.utility.TasProperties; import org.alfresco.utility.Utility; -import org.alfresco.utility.constants.UserRole; import org.alfresco.utility.data.DataContent; import org.alfresco.utility.data.DataSite; import org.alfresco.utility.data.DataUser; diff --git a/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/AbstractGSE2ETest.java b/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/AbstractGSE2ETest.java index 9cef07df1..04d51f9ff 100644 --- a/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/AbstractGSE2ETest.java +++ b/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/AbstractGSE2ETest.java @@ -59,6 +59,8 @@ public abstract class AbstractGSE2ETest extends AbstractInsightEngineE2ETest protected static final String SEARCH_LANGUAGE_CMIS = "cmis"; + protected RecordCategory rootCategory; + protected Record electronicRecord, nonElectronicRecord; @Autowired protected RestAPIFactory restAPIFactory; @@ -74,7 +76,7 @@ public abstract class AbstractGSE2ETest extends AbstractInsightEngineE2ETest testSite = createRMSite(); // create the Root category - RecordCategory rootCategory = createRootCategory(ROOT_CATEGORY_NAME); + rootCategory = createRootCategory(ROOT_CATEGORY_NAME); Assert.assertNotNull(rootCategory, "Root category was not created!"); // Add two children (categories) on Root category @@ -93,9 +95,10 @@ public abstract class AbstractGSE2ETest extends AbstractInsightEngineE2ETest createRecordFolder(childCategory2.getId(), FOLDER2); // Complete a file - Record electronicRecord = createElectronicRecord(folder1.getId(), ELECTRONIC_FILE); + electronicRecord = createElectronicRecord(folder1.getId(), ELECTRONIC_FILE); completeRecord(electronicRecord.getId()); - createNonElectronicRecord(folder1.getId(), NON_ELECTRONIC_FILE); + + nonElectronicRecord = createNonElectronicRecord(folder1.getId(), NON_ELECTRONIC_FILE); // Add an electronic record on folder2 createElectronicRecord(folder2.getId(), ELECTRONIC_FILE); @@ -120,18 +123,6 @@ public abstract class AbstractGSE2ETest extends AbstractInsightEngineE2ETest return dataSite.createRMSite(RMSiteCompliance.STANDARD); } - - /** - * Helper method to create a test user with rm role - * - * @param userRole the rm role - * @return the created user model - */ - protected UserModel createUserWithRMRole(UserModel user, String userRole) - { - getRestAPIFactory().getRMUserAPI().assignRoleToUser(user.getUsername(), userRole); - return user; - } protected RestAPIFactory getRestAPIFactory() { @@ -309,4 +300,17 @@ public abstract class AbstractGSE2ETest extends AbstractInsightEngineE2ETest RecordCategoryChild recordFolderModel = createRecordCategoryChildModel(name, RECORD_FOLDER_TYPE); return getRestAPIFactory().getRecordCategoryAPI(asUser).createRecordCategoryChild(recordFolderModel, recordCategoryId); } + + + /** + * Helper method to create a test user with rm role + * + * @param userRole the rm role + * @return the created user model + */ + protected UserModel createUserWithRMRole(UserModel user, String userRole) + { + getRestAPIFactory().getRMUserAPI().assignRoleToUser(user.getUsername(), userRole); + return user; + } } diff --git a/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/sql/SearchSqlGSE2ETest.java b/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/sql/SearchSqlGSE2ETest.java index 7ecf8ed56..2362bf560 100644 --- a/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/sql/SearchSqlGSE2ETest.java +++ b/e2e-test/src/test/java/org/alfresco/test/search/functional/gs/sql/SearchSqlGSE2ETest.java @@ -14,6 +14,7 @@ import java.util.List; import org.alfresco.rest.core.RestResponse; import org.alfresco.rest.rm.community.model.record.Record; import org.alfresco.rest.rm.community.model.recordcategory.RecordCategoryChild; +import org.alfresco.rest.rm.community.model.user.UserPermissions; import org.alfresco.rest.rm.enterprise.core.ClassificationData; import org.alfresco.rest.search.SearchSqlRequest; import org.alfresco.search.TestGroup; @@ -41,9 +42,9 @@ public class SearchSqlGSE2ETest extends AbstractGSE2ETest private FolderModel testFolder; private RecordCategoryChild recordFolder; - private FileModel fileRecord, fileUnclassified, fileClassifiedAsTopSecret, fileClassifiedAsSecret, fileClassifiedAsConfidential; + private FileModel fileRecord, fileRecordElectronic, fileUnclassified, fileClassifiedAsTopSecret, fileClassifiedAsSecret, fileClassifiedAsConfidential; - private Record elecRecord; + private Record inPlaceRecord, elecRecord; @BeforeClass(alwaysRun = true) public void dataPreparation() throws Exception @@ -57,23 +58,23 @@ public class SearchSqlGSE2ETest extends AbstractGSE2ETest testUserNoAccess = dataUser.createRandomTestUser("UserSearchNoAccess"); // Add users to testSite - getDataUser().addUserToSite(testUserSecret, testSite, UserRole.SiteContributor); + getDataUser().addUserToSite(testUserSecret, testSite, UserRole.SiteCollaborator); getDataUser().addUserToSite(testUserConfidential, testSite, UserRole.SiteConsumer); // Assign classification levels - getClassificationService().assignClearance(dataContent.getAdminUser(), testUserGSTopSecret, ClassificationData.TOP_SECRET_CLASSIFICATION_LEVEL_ID); - getClassificationService().assignClearance(dataContent.getAdminUser(), testUserSecret, ClassificationData.SECRET_CLASSIFICATION_LEVEL_ID); - getClassificationService().assignClearance(dataContent.getAdminUser(), testUserConfidential, ClassificationData.CONFIDENTIAL_CLASSIFICATION_LEVEL_ID); - getClassificationService().assignClearance(dataContent.getAdminUser(), testUserNoAccess, ClassificationData.UNCLASSIFIED_CLASSIFICATION_LEVEL_ID); + getClassificationService().assignClearance(adminUserModel, testUserGSTopSecret, ClassificationData.TOP_SECRET_CLASSIFICATION_LEVEL_ID); + getClassificationService().assignClearance(adminUserModel, testUserSecret, ClassificationData.SECRET_CLASSIFICATION_LEVEL_ID); + getClassificationService().assignClearance(adminUserModel, testUserConfidential, ClassificationData.CONFIDENTIAL_CLASSIFICATION_LEVEL_ID); + getClassificationService().assignClearance(adminUserModel, testUserNoAccess, ClassificationData.UNCLASSIFIED_CLASSIFICATION_LEVEL_ID); - // Create a folder and a file + // Create a folder and files testFolder = dataContent.usingUser(testUser).usingSite(testSite).createFolder(); + fileRecord = new FileModel(unique_searchString + "record-1.txt", "record1", "record1", FileType.TEXT_PLAIN, "record1"); dataContent.usingUser(testUser).usingSite(testSite).createContent(fileRecord); - // File a Electronic Record - recordFolder = createCategoryFolderInFilePlan(); - elecRecord = createElectronicRecord(recordFolder.getId(), fileRecord.getName()); + fileRecordElectronic = new FileModel(unique_searchString + "e-record-1.txt", "e-record1", "e-record1", FileType.TEXT_PLAIN, "e-record1"); + dataContent.usingUser(testUser).usingSite(testSite).createContent(fileRecordElectronic); // Create Files to be classified later fileClassifiedAsTopSecret = new FileModel(unique_searchString + "TopS-1.txt", "top", "top", FileType.TEXT_PLAIN, "top"); @@ -111,7 +112,7 @@ public class SearchSqlGSE2ETest extends AbstractGSE2ETest restClient.assertStatusCodeIs(HttpStatus.OK); response.assertThat().body("list.pagination.count", Matchers.equalTo(0)); - // Verify that the site member can see the content: Contributor + // Verify that the site member can see the content: Collaborator response = searchSql(sqlRequest, testUserSecret); restClient.assertStatusCodeIs(HttpStatus.OK); @@ -127,8 +128,8 @@ public class SearchSqlGSE2ETest extends AbstractGSE2ETest @Test(priority = 2, groups = {TestGroup.ACS_611n}) public void testSQLFiltersClassifiedFiles() { - // Create classified files as testUser - getClassificationService().classifyNode(dataContent.getAdminUser(), fileClassifiedAsTopSecret.getNodeRefWithoutVersion(), ClassificationData.TOP_SECRET_CLASSIFICATION_LEVEL_ID); + // Classify files as testUserGSTopSecret + getClassificationService().classifyNode(adminUserModel, fileClassifiedAsTopSecret.getNodeRefWithoutVersion(), ClassificationData.TOP_SECRET_CLASSIFICATION_LEVEL_ID); getClassificationService().classifyNode(testUserGSTopSecret, fileClassifiedAsSecret.getNodeRefWithoutVersion(), ClassificationData.SECRET_CLASSIFICATION_LEVEL_ID); getClassificationService().classifyNode(testUserGSTopSecret, fileClassifiedAsConfidential.getNodeRefWithoutVersion(), ClassificationData.CONFIDENTIAL_CLASSIFICATION_LEVEL_ID); @@ -138,10 +139,18 @@ public class SearchSqlGSE2ETest extends AbstractGSE2ETest // Check Aggregate query response doesn't bring up classification levels the user should not see SearchSqlRequest sqlRequest = new SearchSqlRequest(); - sqlRequest.setSql("select sc_classification, count(*) from alfresco where SITE = '" + testSite.getId() + "' group by sc_classification"); + sqlRequest.setSql("select sc_classification, count(*) from alfresco group by sc_classification"); RestResponse response = searchSql(sqlRequest, testUserGSTopSecret); restClient.assertStatusCodeIs(HttpStatus.OK); + // TODO: Validate impact of Site not being specified + // response.assertThat().body("list.pagination.count", Matchers.equalTo(3)); //Actual count = 4 is Site is not specified + + sqlRequest = new SearchSqlRequest(); + sqlRequest.setSql("select sc_classification, count(*) from alfresco where SITE = '" + testSite.getId() + "' group by sc_classification"); + + response = searchSql(sqlRequest, testUserGSTopSecret); + restClient.assertStatusCodeIs(HttpStatus.OK); response.assertThat().body("list.pagination.count", Matchers.equalTo(3)); response = searchSql(sqlRequest, testUserSecret); @@ -193,4 +202,91 @@ public class SearchSqlGSE2ETest extends AbstractGSE2ETest Assert.assertFalse(results.contains(fileClassifiedAsConfidential.getName()), "Confidential file is included in the results when not expected"); Assert.assertFalse(results.contains(fileUnclassified.getName()), "Unclassified file included in the results when not expected"); } + + @Test(priority = 3, groups = {TestGroup.ACS_611n}) + public void testSQLFiltersElectronicRecords() + { + // File a Electronic Record + recordFolder = createCategoryFolderInFilePlan(); + elecRecord = createElectronicRecord(recordFolder.getId(), fileRecord.getName()); + + // Add permission for the GS user to Read Records + getRestAPIFactory().getRMUserAPI().addUserPermission(recordFolder.getParentId(), testUserGSTopSecret, UserPermissions.PERMISSION_READ_RECORDS); + + // Wait for the record to be indexed and check that it can be found + boolean fileFound = isContentInSearchResults("rma:identifier:'*'", elecRecord.getName(), true); + Assert.assertTrue(fileFound, "Expected record file, not found"); + + // Verify that user can see the electronic record with minimum read records permissions + SearchSqlRequest sqlRequest = new SearchSqlRequest(); + sqlRequest.setSql("select cm_name, PATH from alfresco where rma_identifier = '*' and type = 'cm:content'"); + + RestResponse response = searchSql(sqlRequest, testUserGSTopSecret); + restClient.assertStatusCodeIs(HttpStatus.OK); + response.assertThat().body("list.pagination.count", Matchers.equalTo(1)); + + // Verify that user can not see the electronic record with no read permissions + response = searchSql(sqlRequest, testUserConfidential); + restClient.assertStatusCodeIs(HttpStatus.OK); + response.assertThat().body("list.pagination.count", Matchers.equalTo(0)); + } + + @Test(priority = 4, groups = {TestGroup.ACS_611n}) + public void testSQLFiltersInPlaceRecords() + { + // Declare a file as Record + inPlaceRecord = getRestAPIFactory().getFilesAPI().declareAsRecord(fileRecord.getNodeRefWithoutVersion()); + + // Wait for the record to be indexed + boolean fileFound = isContentInSearchResults("rma:identifier:'*'", inPlaceRecord.getName(), true); + Assert.assertTrue(fileFound, "Expected in place record file, not found"); + + // Verify that user can see the in place record without any additional permissions + SearchSqlRequest sqlRequest = new SearchSqlRequest(); + sqlRequest.setSql("select cm_name from alfresco where rma_identifier = '*' and Site = '" + testSite.getId() + "'"); + + RestResponse response = searchSql(sqlRequest, testUserGSTopSecret); + restClient.assertStatusCodeIs(HttpStatus.OK); + response.assertThat().body("list.pagination.count", Matchers.equalTo(1)); + response.assertThat().body("list.entries.entry[0].value", Matchers.contains(inPlaceRecord.getName())); + + // Verify that other site members can see the in place record with no additional permissions + response = searchSql(sqlRequest, testUserConfidential); + restClient.assertStatusCodeIs(HttpStatus.OK); + response.assertThat().body("list.pagination.count", Matchers.equalTo(1)); + response.assertThat().body("list.entries.entry[0].value", Matchers.contains(inPlaceRecord.getName())); + + response = searchSql(sqlRequest, testUserNoAccess); + restClient.assertStatusCodeIs(HttpStatus.OK); + response.assertThat().body("list.pagination.count", Matchers.equalTo(0)); + } + + @Test(priority = 5, groups = {TestGroup.ACS_611n}, enabled = false) + public void testSQLFiltersRecordsCascadedPermissions() + { + // Search for records when user does not have read permission + boolean fileFound = isContentInSearchResults(NON_ELECTRONIC_FILE, NON_ELECTRONIC_FILE, false); + Assert.assertTrue(fileFound, "Non electronic record file found in the results, when user doesn't have read permissions"); + + // Search for records when user does not have read permission + fileFound = isContentInSearchResults(ELECTRONIC_FILE, ELECTRONIC_FILE, false); + Assert.assertTrue(fileFound, "Electronic record file found in the results, when user doesn't have read permissions"); + + // Assign Read permissions to the user at rootCategory level + getRestAPIFactory().getRMUserAPI().addUserPermission(rootCategory.getId(), testUserGSTopSecret, UserPermissions.PERMISSION_READ_RECORDS); + + // Check that the record can now be found + isContentInSearchResults(NON_ELECTRONIC_FILE, NON_ELECTRONIC_FILE, true); + Assert.assertTrue(fileFound, "Expected non electronic record file, not found"); + + // TODO: Add sql test for ELECTRONIC_FILE and Non ELECTRONIC_FILE + fileFound = isContentInSearchResults(ELECTRONIC_FILE, ELECTRONIC_FILE, true); + Assert.assertTrue(fileFound, "Expected electronic record file, not found"); + + SearchSqlRequest sqlRequest = new SearchSqlRequest(); + sqlRequest.setSql("select cm_name from alfresco where rma_identifier = '*' and cm_name in (" + ELECTRONIC_FILE + " , " + NON_ELECTRONIC_FILE + ")"); + + RestResponse response = searchSql(sqlRequest, testUserGSTopSecret); + restClient.assertStatusCodeIs(HttpStatus.OK); + } }