From b9a4df14f51d9cfd5212fcd1c96273ec15871b97 Mon Sep 17 00:00:00 2001 From: cagache Date: Fri, 16 Aug 2019 10:56:08 +0300 Subject: [PATCH 1/7] code review comments --- .../module/org_alfresco_module_rm/hold/HoldServiceImpl.java | 2 +- .../org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java index 0fdb4fb3c9..d64918e545 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java @@ -637,7 +637,7 @@ public class HoldServiceImpl extends ServiceBaseImpl if (!nodeService.hasAspect(nodeRef, ASPECT_FROZEN)) { //set in transaction cache in order not to trigger update policy when adding the aspect - transactionalResourceHelper.getSet(nodeRef).add("frozen"); + transactionalResourceHelper.getSet("frozen").add(nodeRef); // add freeze aspect nodeService.addAspect(nodeRef, ASPECT_FROZEN, props); diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java index 7ddceb5808..99678eace2 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java @@ -241,7 +241,7 @@ public class FrozenAspect extends BaseBehaviourBean AuthenticationUtil.runAsSystem((RunAsWork) () -> { // check to not throw exception when the aspect is being added if (nodeService.exists(nodeRef) && freezeService.isFrozen(nodeRef) && - !transactionalResourceHelper.getSet(nodeRef).contains("frozen") ) + !transactionalResourceHelper.getSet("frozen").contains(nodeRef) ) { throw new AccessDeniedException("Frozen nodes can not be updated."); } From 54420ca2129010ff19ade4e7b8853f5e56b318db Mon Sep 17 00:00:00 2001 From: cagache Date: Fri, 16 Aug 2019 16:10:09 +0300 Subject: [PATCH 2/7] RM-6906 Add integration tests for prevent update of held content. Added fix to not trigger onUpdateProperties policy when removing the frozen aspect. --- .../hold/HoldServiceImpl.java | 25 +-- .../model/rma/aspect/FrozenAspect.java | 56 +---- .../hold/UpdateHeldActiveContentTest.java | 211 ++++++++++++++++++ 3 files changed, 229 insertions(+), 63 deletions(-) create mode 100644 rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java index d64918e545..e2bdd33280 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java @@ -228,6 +228,8 @@ public class HoldServiceImpl extends ServiceBaseImpl if (nodeService.hasAspect(nodeRef, ASPECT_FROZEN)) { // remove the freeze aspect from the node + //set in transaction cache in order not to trigger update policy when removing the aspect + transactionalResourceHelper.getSet(nodeRef).add("frozen"); nodeService.removeAspect(nodeRef, ASPECT_FROZEN); } @@ -242,6 +244,8 @@ public class HoldServiceImpl extends ServiceBaseImpl if (recordsOtherHolds.size() == index) { // remove the freeze aspect from the node + //set in transaction cache in order not to trigger update policy when removing the aspect + transactionalResourceHelper.getSet(record).add("frozen"); nodeService.removeAspect(record, ASPECT_FROZEN); } } @@ -716,12 +720,12 @@ public class HoldServiceImpl extends ServiceBaseImpl { // run as system so we don't run into further permission issues // we already know we have to have the correct capability to get here - authenticationUtil.runAsSystem(new RunAsWork() - { - @Override - public Void doWork() + authenticationUtil.runAsSystem((RunAsWork) () -> { { + // remove from hold + //set in transaction cache in order not to trigger update policy when removing the child association + transactionalResourceHelper.getSet(nodeRef).add("frozen"); nodeService.removeChild(hold, nodeRef); // audit that the node has been remove from the hold @@ -730,19 +734,14 @@ public class HoldServiceImpl extends ServiceBaseImpl return null; } - }); + }); } } // run as system as we can't be sure if have remove aspect rights on node - authenticationUtil.runAsSystem(new RunAsWork() - { - @Override - public Void doWork() - { - removeFreezeAspect(nodeRef, 0); - return null; - } + authenticationUtil.runAsSystem((RunAsWork) () -> { + removeFreezeAspect(nodeRef, 0); + return null; }); } } diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java index 99678eace2..c6a5a35853 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java @@ -38,8 +38,6 @@ import java.util.Map; import org.alfresco.module.org_alfresco_module_rm.freeze.FreezeService; import org.alfresco.module.org_alfresco_module_rm.model.BaseBehaviourBean; -import org.alfresco.repo.content.ContentServicePolicies; -import org.alfresco.repo.copy.CopyServicePolicies; import org.alfresco.repo.node.NodeServicePolicies; import org.alfresco.repo.policy.Behaviour.NotificationFrequency; import org.alfresco.repo.policy.annotation.Behaviour; @@ -67,9 +65,7 @@ public class FrozenAspect extends BaseBehaviourBean NodeServicePolicies.OnAddAspectPolicy, NodeServicePolicies.OnRemoveAspectPolicy, NodeServicePolicies.OnUpdatePropertiesPolicy, - NodeServicePolicies.OnMoveNodePolicy, - ContentServicePolicies.OnContentUpdatePolicy, - CopyServicePolicies.BeforeCopyPolicy + NodeServicePolicies.BeforeMoveNodePolicy { /** freeze service */ protected FreezeService freezeService; @@ -209,14 +205,14 @@ public class FrozenAspect extends BaseBehaviourBean @Override @Behaviour ( - kind = BehaviourKind.ASSOCIATION, + kind = BehaviourKind.CLASS, notificationFrequency = NotificationFrequency.FIRST_EVENT ) - public void onMoveNode(final ChildAssociationRef oldChildAssocRef, final ChildAssociationRef newChildAssocRef) + public void beforeMoveNode(ChildAssociationRef oldChildAssocRef, NodeRef newParentRef) { AuthenticationUtil.runAsSystem((RunAsWork) () -> { - if (nodeService.exists(newChildAssocRef.getParentRef()) && - nodeService.exists(newChildAssocRef.getChildRef())) + if (nodeService.exists(oldChildAssocRef.getChildRef()) && + freezeService.isFrozen(oldChildAssocRef.getChildRef())) { throw new AccessDeniedException("Frozen nodes can not be moved."); } @@ -233,7 +229,7 @@ public class FrozenAspect extends BaseBehaviourBean @Behaviour ( kind = BehaviourKind.CLASS, - notificationFrequency = NotificationFrequency.TRANSACTION_COMMIT + notificationFrequency = NotificationFrequency.FIRST_EVENT ) public void onUpdateProperties(NodeRef nodeRef, Map before, Map after) @@ -248,44 +244,4 @@ public class FrozenAspect extends BaseBehaviourBean return null; }); } - - /** - * Behaviour associated with updating the content - *

- * Ensures that the content of a frozen node can not be updated - */ - @Override - @Behaviour - ( - kind = BehaviourKind.CLASS, - notificationFrequency = NotificationFrequency.TRANSACTION_COMMIT - ) - public void onContentUpdate(NodeRef nodeRef, boolean newContent) - { - AuthenticationUtil.runAsSystem((RunAsWork) () -> { - if (nodeService.exists(nodeRef) && freezeService.isFrozen(nodeRef)) - { - // never allow to update the content of a frozen node - throw new AccessDeniedException("Frozen nodes content can not be updated."); - } - return null; - }); - } - - @Override - @Behaviour - ( - kind = BehaviourKind.CLASS - ) - public void beforeCopy(QName classRef, NodeRef sourceNodeRef, NodeRef targetNodeRef) - { - AuthenticationUtil.runAsSystem((RunAsWork) () -> { - if (nodeService.exists(sourceNodeRef) && freezeService.isFrozen(sourceNodeRef)) - { - throw new AccessDeniedException("Frozen nodes can not be copied."); - } - - return null; - }); - } } diff --git a/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java b/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java new file mode 100644 index 0000000000..b981a84c5d --- /dev/null +++ b/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java @@ -0,0 +1,211 @@ +/* + * #%L + * Alfresco Records Management Module + * %% + * Copyright (C) 2005 - 2019 Alfresco Software Limited + * %% + * This file is part of the Alfresco software. + * - + * If the software was purchased under a paid Alfresco license, the terms of + * the paid license agreement will prevail. Otherwise, the software is + * provided under the following open source license terms: + * - + * Alfresco is free software: you can redistribute it and/or modify + * it under the terms of the GNU Lesser General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * - + * Alfresco is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Lesser General Public License for more details. + * - + * You should have received a copy of the GNU Lesser General Public License + * along with Alfresco. If not, see . + * #L% + */ +package org.alfresco.module.org_alfresco_module_rm.test.integration.hold; + +import org.alfresco.model.ContentModel; +import org.alfresco.module.org_alfresco_module_rm.test.util.BaseRMTestCase; +import org.alfresco.repo.content.MimetypeMap; +import org.alfresco.repo.security.permissions.AccessDeniedException; +import org.alfresco.service.cmr.model.FileNotFoundException; +import org.alfresco.service.cmr.repository.ContentData; +import org.alfresco.service.cmr.repository.NodeRef; +import org.springframework.extensions.webscripts.GUID; + +/** + * Prevent Updating Held Active Content Integration Tests + * + * @author Claudia Agache + * @since 3.2 + */ +public class UpdateHeldActiveContentTest extends BaseRMTestCase +{ + @Override + protected boolean isCollaborationSiteTest() + { + return true; + } + + /** + * Given active content on hold + * When I try to delete the content + * Then I am not successful + */ + public void testDeleteHeldDocument() + { + doBehaviourDrivenTest(new BehaviourDrivenTest() + { + public void given() + { + // create a hold + NodeRef hold = holdService.createHold(filePlan, GUID.generate(), GUID.generate(), GUID.generate()); + + // add the active content to hold + holdService.addToHold(hold, dmDocument); + } + + public void when() + { + try + { + fileFolderService.delete(dmDocument); + fail("Expected AccessDeniedException to be thrown"); + } + catch (AccessDeniedException ade) + { + assertTrue(ade.getMessage().contains("Frozen nodes can not be deleted.")); + } + } + }); + } + + /** + * Given active content on hold + * When I try to copy the content + * Then I am not successful + */ + public void testCopyHeldDocument() + { + doBehaviourDrivenTest(new BehaviourDrivenTest(AccessDeniedException.class) + { + public void given() + { + // create a hold + NodeRef hold = holdService.createHold(filePlan, GUID.generate(), GUID.generate(), GUID.generate()); + + // add the active content to hold + holdService.addToHold(hold, dmDocument); + } + + public void when() throws FileNotFoundException + { + fileFolderService.copy(dmDocument, dmFolder1, null); + } + }); + } + + /** + * Given active content on hold + * When I try to move the content + * Then I am not successful + */ + public void testMoveHeldDocument() + { + doBehaviourDrivenTest(new BehaviourDrivenTest() + { + public void given() + { + // create a hold + NodeRef hold = holdService.createHold(filePlan, GUID.generate(), GUID.generate(), GUID.generate()); + + // add the active content to hold + holdService.addToHold(hold, dmDocument); + } + + public void when() throws FileNotFoundException + { + try + { + fileFolderService.move(dmDocument, dmFolder1, null); + fail("Expected AccessDeniedException to be thrown"); + } + catch (AccessDeniedException ade) + { + assertTrue(ade.getMessage().contains("Frozen nodes can not be moved.")); + } + } + }); + } + + /** + * Given active content on hold + * When I try to edit the properties + * Or perform an action that edits the properties + * Then I am not successful + */ + public void testUpdateHeldDocumentProperties() + { + doBehaviourDrivenTest(new BehaviourDrivenTest() + { + public void given() + { + // create a hold + NodeRef hold = holdService.createHold(filePlan, GUID.generate(), GUID.generate(), GUID.generate()); + + // add the active content to hold + holdService.addToHold(hold, dmDocument); + } + + public void when() + { + try + { + nodeService.setProperty(dmDocument, ContentModel.PROP_DESCRIPTION, "description"); + fail("Expected AccessDeniedException to be thrown"); + } + catch (AccessDeniedException ade) + { + assertTrue(ade.getMessage().contains("Frozen nodes can not be updated.")); + } + } + }); + } + + /** + * Given active content on hold + * When I try to update the content + * Then I am not successful + */ + public void testUpdateHeldDocumentContent() + { + doBehaviourDrivenTest(new BehaviourDrivenTest() + { + public void given() + { + // create a hold + NodeRef hold = holdService.createHold(filePlan, GUID.generate(), GUID.generate(), GUID.generate()); + + // add the active content to hold + holdService.addToHold(hold, dmDocument); + } + + public void when() + { + try + { + ContentData content = (ContentData) nodeService.getProperty(dmDocument, PROP_CONTENT); + nodeService.setProperty(dmDocument, PROP_CONTENT, ContentData.setMimetype(content, + MimetypeMap.MIMETYPE_TEXT_PLAIN)); + fail("Expected AccessDeniedException to be thrown"); + } + catch (AccessDeniedException ade) + { + assertTrue(ade.getMessage().contains("Frozen nodes can not be updated.")); + } + } + }); + } +} From cc968e5aa82f5f79491e4d6cb29e52f89e5c56d4 Mon Sep 17 00:00:00 2001 From: cagache Date: Fri, 16 Aug 2019 17:28:53 +0300 Subject: [PATCH 3/7] small fix --- .../hold/HoldServiceImpl.java | 22 +++++++++---------- 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java index e2bdd33280..70a08a409c 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java @@ -229,7 +229,7 @@ public class HoldServiceImpl extends ServiceBaseImpl { // remove the freeze aspect from the node //set in transaction cache in order not to trigger update policy when removing the aspect - transactionalResourceHelper.getSet(nodeRef).add("frozen"); + transactionalResourceHelper.getSet("frozen").add(nodeRef); nodeService.removeAspect(nodeRef, ASPECT_FROZEN); } @@ -245,7 +245,7 @@ public class HoldServiceImpl extends ServiceBaseImpl { // remove the freeze aspect from the node //set in transaction cache in order not to trigger update policy when removing the aspect - transactionalResourceHelper.getSet(record).add("frozen"); + transactionalResourceHelper.getSet("frozen").add(record); nodeService.removeAspect(record, ASPECT_FROZEN); } } @@ -721,19 +721,17 @@ public class HoldServiceImpl extends ServiceBaseImpl // run as system so we don't run into further permission issues // we already know we have to have the correct capability to get here authenticationUtil.runAsSystem((RunAsWork) () -> { - { + // remove from hold + //set in transaction cache in order not to trigger update policy when removing the child association + transactionalResourceHelper.getSet("frozen").add(nodeRef); + nodeService.removeChild(hold, nodeRef); - // remove from hold - //set in transaction cache in order not to trigger update policy when removing the child association - transactionalResourceHelper.getSet(nodeRef).add("frozen"); - nodeService.removeChild(hold, nodeRef); + // audit that the node has been remove from the hold + // TODO add details of the hold that the node was removed from + recordsManagementAuditService.auditEvent(nodeRef, AUDIT_REMOVE_FROM_HOLD); - // audit that the node has been remove from the hold - // TODO add details of the hold that the node was removed from - recordsManagementAuditService.auditEvent(nodeRef, AUDIT_REMOVE_FROM_HOLD); + return null; - return null; - } }); } } From f858d6d203725b505502afad99632242e55d1cb9 Mon Sep 17 00:00:00 2001 From: cagache Date: Fri, 16 Aug 2019 19:08:54 +0300 Subject: [PATCH 4/7] Added fix to not trigger onUpdateProperties policy when deleting a hold. --- .../module/org_alfresco_module_rm/hold/HoldServiceImpl.java | 2 ++ 1 file changed, 2 insertions(+) diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java index 70a08a409c..c4da746aa2 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/hold/HoldServiceImpl.java @@ -202,6 +202,8 @@ public class HoldServiceImpl extends ServiceBaseImpl List frozenNodes = getHeld(hold); for (NodeRef frozenNode : frozenNodes) { + //set in transaction cache in order not to trigger update policy when removing the child association + transactionalResourceHelper.getSet("frozen").add(frozenNode); removeFreezeAspect(frozenNode, 1); } From a5d245b5f6063b9d1abd5df20810511e012fbdbd Mon Sep 17 00:00:00 2001 From: cagache Date: Mon, 19 Aug 2019 15:02:40 +0300 Subject: [PATCH 5/7] Throw PermissionDeniedException instead of AccessDeniedException and internationalized the messages. --- .../messages/hold-service.properties | 6 ++- .../model/rma/aspect/FrozenAspect.java | 12 ++--- .../hold/UpdateHeldActiveContentTest.java | 53 ++++--------------- 3 files changed, 22 insertions(+), 49 deletions(-) diff --git a/rm-community/rm-community-repo/config/alfresco/module/org_alfresco_module_rm/messages/hold-service.properties b/rm-community/rm-community-repo/config/alfresco/module/org_alfresco_module_rm/messages/hold-service.properties index ae21a7ddb8..6e3cc58d4f 100644 --- a/rm-community/rm-community-repo/config/alfresco/module/org_alfresco_module_rm/messages/hold-service.properties +++ b/rm-community/rm-community-repo/config/alfresco/module/org_alfresco_module_rm/messages/hold-service.properties @@ -1,4 +1,8 @@ rm.hold.not-hold=The node {0} is not a hold. rm.hold.add-to-hold-invalid-type={0} is neither a record nor a record folder nor active content. Only records, record \ folders or active content can be added to a hold. -rm.hold.add-to-hold-archived-node=Archived nodes can't be added to hold. \ No newline at end of file +rm.hold.add-to-hold-archived-node=Archived nodes can't be added to hold. +rm.hold.delete-frozen-node=Frozen nodes can not be deleted. +rm.hold.delete-node-frozen-children=Can not delete node, because it contains a frozen child node. +rm.hold.move-frozen-node=Frozen nodes can not be moved. +rm.hold.update-frozen-node=Frozen nodes can not be updated. \ No newline at end of file diff --git a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java index c6a5a35853..18cbd5f544 100644 --- a/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java +++ b/rm-community/rm-community-repo/source/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspect.java @@ -45,10 +45,11 @@ import org.alfresco.repo.policy.annotation.BehaviourBean; import org.alfresco.repo.policy.annotation.BehaviourKind; import org.alfresco.repo.security.authentication.AuthenticationUtil; import org.alfresco.repo.security.authentication.AuthenticationUtil.RunAsWork; -import org.alfresco.repo.security.permissions.AccessDeniedException; +import org.alfresco.rest.framework.core.exceptions.PermissionDeniedException; import org.alfresco.service.cmr.repository.ChildAssociationRef; import org.alfresco.service.cmr.repository.NodeRef; import org.alfresco.service.namespace.QName; +import org.springframework.extensions.surf.util.I18NUtil; /** * rma:frozen behaviour bean @@ -95,7 +96,7 @@ public class FrozenAspect extends BaseBehaviourBean if (nodeService.exists(nodeRef) && freezeService.isFrozen(nodeRef)) { // never allow to delete a frozen node - throw new AccessDeniedException("Frozen nodes can not be deleted."); + throw new PermissionDeniedException(I18NUtil.getMessage("rm.hold.delete-frozen-node")); } // check children @@ -121,7 +122,7 @@ public class FrozenAspect extends BaseBehaviourBean if (freezeService.isFrozen(nodeRef)) { // never allow to delete a node with a frozen child - throw new AccessDeniedException("Can not delete node, because it contains a frozen child node."); + throw new PermissionDeniedException(I18NUtil.getMessage("rm.hold.delete-node-frozen-children")); } // check children @@ -214,7 +215,7 @@ public class FrozenAspect extends BaseBehaviourBean if (nodeService.exists(oldChildAssocRef.getChildRef()) && freezeService.isFrozen(oldChildAssocRef.getChildRef())) { - throw new AccessDeniedException("Frozen nodes can not be moved."); + throw new PermissionDeniedException(I18NUtil.getMessage("rm.hold.move-frozen-node")); } return null; }); @@ -232,14 +233,13 @@ public class FrozenAspect extends BaseBehaviourBean notificationFrequency = NotificationFrequency.FIRST_EVENT ) public void onUpdateProperties(NodeRef nodeRef, Map before, Map after) - { AuthenticationUtil.runAsSystem((RunAsWork) () -> { // check to not throw exception when the aspect is being added if (nodeService.exists(nodeRef) && freezeService.isFrozen(nodeRef) && !transactionalResourceHelper.getSet("frozen").contains(nodeRef) ) { - throw new AccessDeniedException("Frozen nodes can not be updated."); + throw new PermissionDeniedException(I18NUtil.getMessage("rm.hold.update-frozen-node")); } return null; }); diff --git a/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java b/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java index b981a84c5d..a5e8ac9cd0 100644 --- a/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java +++ b/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java @@ -30,6 +30,7 @@ import org.alfresco.model.ContentModel; import org.alfresco.module.org_alfresco_module_rm.test.util.BaseRMTestCase; import org.alfresco.repo.content.MimetypeMap; import org.alfresco.repo.security.permissions.AccessDeniedException; +import org.alfresco.rest.framework.core.exceptions.PermissionDeniedException; import org.alfresco.service.cmr.model.FileNotFoundException; import org.alfresco.service.cmr.repository.ContentData; import org.alfresco.service.cmr.repository.NodeRef; @@ -56,7 +57,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testDeleteHeldDocument() { - doBehaviourDrivenTest(new BehaviourDrivenTest() + doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) { public void given() { @@ -69,15 +70,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() { - try - { - fileFolderService.delete(dmDocument); - fail("Expected AccessDeniedException to be thrown"); - } - catch (AccessDeniedException ade) - { - assertTrue(ade.getMessage().contains("Frozen nodes can not be deleted.")); - } + fileFolderService.delete(dmDocument); } }); } @@ -114,7 +107,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testMoveHeldDocument() { - doBehaviourDrivenTest(new BehaviourDrivenTest() + doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) { public void given() { @@ -127,15 +120,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() throws FileNotFoundException { - try - { - fileFolderService.move(dmDocument, dmFolder1, null); - fail("Expected AccessDeniedException to be thrown"); - } - catch (AccessDeniedException ade) - { - assertTrue(ade.getMessage().contains("Frozen nodes can not be moved.")); - } + fileFolderService.move(dmDocument, dmFolder1, null); } }); } @@ -148,7 +133,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testUpdateHeldDocumentProperties() { - doBehaviourDrivenTest(new BehaviourDrivenTest() + doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) { public void given() { @@ -161,15 +146,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() { - try - { - nodeService.setProperty(dmDocument, ContentModel.PROP_DESCRIPTION, "description"); - fail("Expected AccessDeniedException to be thrown"); - } - catch (AccessDeniedException ade) - { - assertTrue(ade.getMessage().contains("Frozen nodes can not be updated.")); - } + nodeService.setProperty(dmDocument, ContentModel.PROP_DESCRIPTION, "description"); } }); } @@ -181,7 +158,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testUpdateHeldDocumentContent() { - doBehaviourDrivenTest(new BehaviourDrivenTest() + doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) { public void given() { @@ -194,17 +171,9 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() { - try - { - ContentData content = (ContentData) nodeService.getProperty(dmDocument, PROP_CONTENT); - nodeService.setProperty(dmDocument, PROP_CONTENT, ContentData.setMimetype(content, - MimetypeMap.MIMETYPE_TEXT_PLAIN)); - fail("Expected AccessDeniedException to be thrown"); - } - catch (AccessDeniedException ade) - { - assertTrue(ade.getMessage().contains("Frozen nodes can not be updated.")); - } + ContentData content = (ContentData) nodeService.getProperty(dmDocument, PROP_CONTENT); + nodeService.setProperty(dmDocument, PROP_CONTENT, ContentData.setMimetype(content, + MimetypeMap.MIMETYPE_TEXT_PLAIN)); } }); } From b769ce2892d04fc2759d109d39a6fb5104807255 Mon Sep 17 00:00:00 2001 From: cagache Date: Mon, 19 Aug 2019 17:12:58 +0300 Subject: [PATCH 6/7] Check exception messages --- .../hold/UpdateHeldActiveContentTest.java | 52 +++++++++++++++---- 1 file changed, 42 insertions(+), 10 deletions(-) diff --git a/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java b/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java index a5e8ac9cd0..a50c65a3b8 100644 --- a/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java +++ b/rm-community/rm-community-repo/test/java/org/alfresco/module/org_alfresco_module_rm/test/integration/hold/UpdateHeldActiveContentTest.java @@ -57,7 +57,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testDeleteHeldDocument() { - doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) + doBehaviourDrivenTest(new BehaviourDrivenTest() { public void given() { @@ -70,7 +70,15 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() { - fileFolderService.delete(dmDocument); + try + { + fileFolderService.delete(dmDocument); + fail("Expected PermissionDeniedException to be thrown"); + } + catch (PermissionDeniedException pde) + { + assertTrue(pde.getMessage().contains("Frozen nodes can not be deleted.")); + } } }); } @@ -107,7 +115,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testMoveHeldDocument() { - doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) + doBehaviourDrivenTest(new BehaviourDrivenTest() { public void given() { @@ -120,7 +128,15 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() throws FileNotFoundException { - fileFolderService.move(dmDocument, dmFolder1, null); + try + { + fileFolderService.move(dmDocument, dmFolder1, null); + fail("Expected PermissionDeniedException to be thrown"); + } + catch (PermissionDeniedException pde) + { + assertTrue(pde.getMessage().contains("Frozen nodes can not be moved.")); + } } }); } @@ -133,7 +149,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testUpdateHeldDocumentProperties() { - doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) + doBehaviourDrivenTest(new BehaviourDrivenTest() { public void given() { @@ -146,7 +162,15 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() { - nodeService.setProperty(dmDocument, ContentModel.PROP_DESCRIPTION, "description"); + try + { + nodeService.setProperty(dmDocument, ContentModel.PROP_DESCRIPTION, "description"); + fail("Expected PermissionDeniedException to be thrown"); + } + catch (PermissionDeniedException pde) + { + assertTrue(pde.getMessage().contains("Frozen nodes can not be updated.")); + } } }); } @@ -158,7 +182,7 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase */ public void testUpdateHeldDocumentContent() { - doBehaviourDrivenTest(new BehaviourDrivenTest(PermissionDeniedException.class) + doBehaviourDrivenTest(new BehaviourDrivenTest() { public void given() { @@ -171,9 +195,17 @@ public class UpdateHeldActiveContentTest extends BaseRMTestCase public void when() { - ContentData content = (ContentData) nodeService.getProperty(dmDocument, PROP_CONTENT); - nodeService.setProperty(dmDocument, PROP_CONTENT, ContentData.setMimetype(content, - MimetypeMap.MIMETYPE_TEXT_PLAIN)); + try + { + ContentData content = (ContentData) nodeService.getProperty(dmDocument, PROP_CONTENT); + nodeService.setProperty(dmDocument, PROP_CONTENT, ContentData.setMimetype(content, + MimetypeMap.MIMETYPE_TEXT_PLAIN)); + fail("Expected PermissionDeniedException to be thrown"); + } + catch (PermissionDeniedException pde) + { + assertTrue(pde.getMessage().contains("Frozen nodes can not be updated.")); + } } }); } From ac4b8d4b9a10fba440ee75de5a8125a41b7408df Mon Sep 17 00:00:00 2001 From: Ross Gale Date: Mon, 19 Aug 2019 15:56:10 +0100 Subject: [PATCH 7/7] RM-6873 adding changes from update branch and updating tests --- .../rma/aspect/FrozenAspectUnitTest.java | 41 +++++-------------- 1 file changed, 11 insertions(+), 30 deletions(-) diff --git a/rm-community/rm-community-repo/unit-test/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspectUnitTest.java b/rm-community/rm-community-repo/unit-test/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspectUnitTest.java index e94f2ad103..8a323d794b 100644 --- a/rm-community/rm-community-repo/unit-test/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspectUnitTest.java +++ b/rm-community/rm-community-repo/unit-test/java/org/alfresco/module/org_alfresco_module_rm/model/rma/aspect/FrozenAspectUnitTest.java @@ -43,6 +43,7 @@ import org.alfresco.model.ContentModel; import org.alfresco.module.org_alfresco_module_rm.freeze.FreezeService; import org.alfresco.module.org_alfresco_module_rm.util.TransactionalResourceHelper; import org.alfresco.repo.security.permissions.AccessDeniedException; +import org.alfresco.rest.framework.core.exceptions.PermissionDeniedException; import org.alfresco.service.cmr.dictionary.DictionaryService; import org.alfresco.service.cmr.repository.ChildAssociationRef; import org.alfresco.service.cmr.repository.NodeRef; @@ -165,7 +166,7 @@ public class FrozenAspectUnitTest /** * Test before delete throws an error if a node is frozen */ - @Test(expected = AccessDeniedException.class) + @Test(expected = PermissionDeniedException.class) public void testBeforeDeleteNodeThrowsExceptionIfNodeFrozen() { when(mockFreezeService.isFrozen(content)).thenReturn(true); @@ -186,7 +187,7 @@ public class FrozenAspectUnitTest /** * Test before delete throws an error for a node with frozen children */ - @Test (expected = AccessDeniedException.class) + @Test (expected = PermissionDeniedException.class) public void testBeforeDeleteThrowsExceptionForFrozenChild() { when(mockChildRef.getChildRef()).thenReturn(child); @@ -225,22 +226,22 @@ public class FrozenAspectUnitTest } /** - * Test on move throws an error for a frozen node + * Test before move throws an error for a frozen node */ - @Test(expected = AccessDeniedException.class) - public void testOnMoveThrowsExceptionForFrozenNode() + @Test(expected = PermissionDeniedException.class) + public void testBeforeMoveThrowsExceptionForFrozenNode() { - when(mockNewRef.getParentRef()).thenReturn(parent); - when(mockNewRef.getChildRef()).thenReturn(child); - when(mockNodeService.exists(parent)).thenReturn(true); + when(mockOldRef.getParentRef()).thenReturn(parent); + when(mockOldRef.getChildRef()).thenReturn(child); when(mockNodeService.exists(child)).thenReturn(true); - frozenAspect.onMoveNode(mockOldRef, mockNewRef); + when(mockFreezeService.isFrozen(child)).thenReturn(true); + frozenAspect.beforeMoveNode(mockOldRef, null); } /** * Test update properties throws an error for frozen nodes */ - @Test(expected = AccessDeniedException.class) + @Test(expected = PermissionDeniedException.class) public void testUpdatePropertiesThrowsExceptionForFrozenNode() { when(mockFreezeService.isFrozen(content)).thenReturn(true); @@ -248,24 +249,4 @@ public class FrozenAspectUnitTest when(mockSet.contains("frozen")).thenReturn(false); frozenAspect.onUpdateProperties(content, null, null); } - - /** - * Test on content update throws an error for frozen nodes - */ - @Test(expected = AccessDeniedException.class) - public void testOnContentUpdateThrowsExceptionForFrozenNode() - { - when(mockFreezeService.isFrozen(content)).thenReturn(true); - frozenAspect.onContentUpdate(content, false); - } - - /** - * Test before copy throws an error for frozen node - */ - @Test(expected = AccessDeniedException.class) - public void testBeforeCopyThrowsExceptionForFrozenNode() - { - when(mockFreezeService.isFrozen(content)).thenReturn(true); - frozenAspect.beforeCopy(null, content, null); - } }