Class AclAdviceTest
- Author:
- keshav, paul
-
Field Summary
Fields inherited from class BaseSpringContextTest5
arrayDesignPersister, externalDatabaseService, log, persisterHelper, taxonService, testHelper -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidvoidRe-running an analysis deletes the old one and persists a new one in the same call.voidvoidvoidvoidvoid🛑 Persisting an analysis must NOT re-parent the EXPERIMENT's factors onto the ANALYSIS, and deleting that analysis must not take their ACLs with it.voidA result set of a private experiment must not be readable anonymously.voidvoidvoidMethods inherited from class BaseSpringContextTest5
addTestAnalyses, countRowsInTable, deleteFromTables, getJdbcTemplate, getNewTestPersistentCompleteExpressionExperiment, getTaxon, getTestNonPersistentBioSequence, getTestPersistentArrayDesign, getTestPersistentArrayDesign, getTestPersistentArrayDesign, getTestPersistentBasicExpressionExperiment, getTestPersistentBasicExpressionExperiment, getTestPersistentBibliographicReference, getTestPersistentBioAssay, getTestPersistentBioAssay, getTestPersistentBioMaterial, getTestPersistentBioMaterial, getTestPersistentBioSequence, getTestPersistentBioSequence, getTestPersistentBioSequence2GeneProducts, getTestPersistentBlatResult, getTestPersistentBlatResult, getTestPersistentCompleteExpressionExperiment, getTestPersistentCompleteExpressionExperimentWithSequences, getTestPersistentCompleteExpressionExperimentWithSequences, getTestPersistentContact, getTestPersistentDatabaseEntry, getTestPersistentDatabaseEntry, getTestPersistentDatabaseEntry, getTestPersistentDatabaseEntry, getTestPersistentDatabaseEntry, getTestPersistentExpressionExperiment, getTestPersistentExpressionExperiment, getTestPersistentGene, getTestPersistentGene, getTestPersistentGeneProduct, getTestPersistentQuantitationType, randomName, resetTestCollectionSize, runAsAdmin, runAsAgent, runAsAnonymous, runAsUser, runAsUser, setTestCollectionSizeMethods inherited from class BaseIntegrationTest5
setUpAuthentication, tearDownSecurityContext
-
Constructor Details
-
AclAdviceTest
public AclAdviceTest()
-
-
Method Details
-
testSecuredNotChild
@Test public void testSecuredNotChild() -
testArrayDesignAcls
@Test public void testArrayDesignAcls() -
testSignup
@Test public void testSignup() -
testArrayDesignAclsUser
@Test public void testArrayDesignAclsUser() -
testNumExperiments
@Test public void testNumExperiments() -
testExpressionExperimentAcls
@Test public void testExpressionExperimentAcls() -
testAnalysisAcl
@Test public void testAnalysisAcl() -
testResultSetOfPrivateExperimentIsNotReadableAnonymously
@Test public void testResultSetOfPrivateExperimentIsNotReadableAnonymously()A result set of a private experiment must not be readable anonymously.GET /resultSets/{id}used to serve the whole thing -- design, factor values, per-probe results with genes -- to anonymous callers for experimentsGET /datasets/{id}correctly hid, becauseExpressionAnalysisResultSetService's loaders carried no ACL annotations at all whileDifferentialExpressionAnalysisService's always had them. -
testAnalysisAclOnReanalysis
@Test public void testAnalysisAclOnReanalysis()Re-running an analysis deletes the old one and persists a new one in the same call. Prod lost the ACL for every analysis created from 2026-08-23 onward -- 376 of them, along with every one of their result sets -- and every affected run was a re-run, so pin the second-analysis path specifically. -
testUpdateAcl
@Test public void testUpdateAcl() -
testPersistingAnAnalysisDoesNotStealTheExperimentsFactors
@Test public void testPersistingAnAnalysisDoesNotStealTheExperimentsFactors()🛑 Persisting an analysis must NOT re-parent the EXPERIMENT's factors onto the ANALYSIS, and deleting that analysis must not take their ACLs with it.ExpressionAnalysisResultSet's security owner is its analysis, so a result set's insert seeds the parent-stash walk with the analysis's OID. The walk descendsresultSet.experimentalFactorsand, before theisIntermediateAncestorguard, force-flattened each of the experiment's factors onto the analysis.AclDaoImpl.deletethen recursesfindChildrenwithdeleteChildren=true, so deleting the analysis DELETED THE FACTORS' ACL ROWS. Every later ACL check on such a factor is a NotFoundException surfacing as "Access is denied" — to an administrator, because the row is gone rather than a permission refused.Measured on production 2026-09-10 before the fix: 436 ExperimentalFactor ACL rows parented to a DifferentialExpressionAnalysis over 281 designs, 8 factors already with no ACL row. GSE19804's factor 74321 was parented to DEA 432031, the analysis its retype deletes — which is why three fixes aimed at the factor-removal path never reached the cause.
Both halves are asserted deliberately. The parentage is the DEFECT; the surviving removal is the SYMPTOM that was chased three times. A test on the symptom alone would pass again the next time something re-homes a factor for a different reason.
-