Class AclAdviceTest


public class AclAdviceTest extends BaseSpringContextTest5
Tests of ACL management: adding and removing from objects during CRUD operations. (AclAdvice)
Author:
keshav, paul
  • Constructor Details

    • AclAdviceTest

      public AclAdviceTest()
  • Method Details

    • testSecuredNotChild

      @Test public void testSecuredNotChild()
    • testArrayDesignAcls

      @Test public void testArrayDesignAcls()
    • testSignup

      @Test public void testSignup()
    • testArrayDesignAclsUser

      @Test public void testArrayDesignAclsUser()
    • testNumExperiments

      @Test public void testNumExperiments()
    • testExpressionExperimentAcls

      @Test public void testExpressionExperimentAcls()
    • testAnalysisAcl

      @Test public void testAnalysisAcl()
    • testResultSetOfPrivateExperimentIsNotReadableAnonymously

      @Test public void testResultSetOfPrivateExperimentIsNotReadableAnonymously()
      A result set of a private experiment must not be readable anonymously.

      GET /resultSets/{id} used to serve the whole thing -- design, factor values, per-probe results with genes -- to anonymous callers for experiments GET /datasets/{id} correctly hid, because ExpressionAnalysisResultSetService's loaders carried no ACL annotations at all while DifferentialExpressionAnalysisService's always had them.

    • testAnalysisAclOnReanalysis

      @Test public void testAnalysisAclOnReanalysis()
      Re-running an analysis deletes the old one and persists a new one in the same call. Prod lost the ACL for every analysis created from 2026-08-23 onward -- 376 of them, along with every one of their result sets -- and every affected run was a re-run, so pin the second-analysis path specifically.
    • testUpdateAcl

      @Test public void testUpdateAcl()
    • testPersistingAnAnalysisDoesNotStealTheExperimentsFactors

      @Test public void testPersistingAnAnalysisDoesNotStealTheExperimentsFactors()
      🛑 Persisting an analysis must NOT re-parent the EXPERIMENT's factors onto the ANALYSIS, and deleting that analysis must not take their ACLs with it.

      ExpressionAnalysisResultSet's security owner is its analysis, so a result set's insert seeds the parent-stash walk with the analysis's OID. The walk descends resultSet.experimentalFactors and, before the isIntermediateAncestor guard, force-flattened each of the experiment's factors onto the analysis. AclDaoImpl.delete then recurses findChildren with deleteChildren=true, so deleting the analysis DELETED THE FACTORS' ACL ROWS. Every later ACL check on such a factor is a NotFoundException surfacing as "Access is denied" — to an administrator, because the row is gone rather than a permission refused.

      Measured on production 2026-09-10 before the fix: 436 ExperimentalFactor ACL rows parented to a DifferentialExpressionAnalysis over 281 designs, 8 factors already with no ACL row. GSE19804's factor 74321 was parented to DEA 432031, the analysis its retype deletes — which is why three fixes aimed at the factor-removal path never reached the cause.

      Both halves are asserted deliberately. The parentage is the DEFECT; the surviving removal is the SYMPTOM that was chased three times. A test on the symptom alone would pass again the next time something re-homes a factor for a different reason.