Class AclLinterServiceTest
-
Nested Class Summary
Nested classes/interfaces inherited from class BaseDatabaseTest5
BaseDatabaseTest5.BaseDatabaseTestContextConfiguration -
Field Summary
Fields inherited from class BaseDatabaseTest5
sessionFactory -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidtest()voidRepairing a top-level Securable must leave it editable.voidPhase 3 gsec HQL deprecation: empty path forlintAclObjectIdentityLackingSecurable.voidPhase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backedlintAclObjectIdentityLackingSecurable(dangling-AOI variant).void🛑 A SecuredChild whose parent is present AND CORRECT but which does not inherit reaches no other predicate, and grants nothing.voidPhase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backedlintSecurableLackingObjectIdentity(bulk variant).voidPhase 3 gsec HQL deprecation: regression coverage for the single-id variant oflintSecurableLackingObjectIdentity.voidPhase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backedlintSecuredNotChildWithParent(bulk variant).voidPhase 3 gsec HQL deprecation: regression coverage for the single-id variant oflintSecuredNotChildWithParent.Methods inherited from class BaseDatabaseTest5
flushAndClearSession
-
Constructor Details
-
AclLinterServiceTest
public AclLinterServiceTest()
-
-
Method Details
-
test
@Test @WithMockUser(authorities="GROUP_ADMIN") public void test() -
testLintSecurableLackingObjectIdentity_emptyAndHappyPath
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecurableLackingObjectIdentity_emptyAndHappyPath()Phase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backedlintSecurableLackingObjectIdentity(bulk variant).The pre-conversion HQL path returned entity-ids in
Entitybut not inAclObjectIdentity. The new path reads existing AOI identifiers fromacl_object_identityJOINacl_classvia raw SQL and does the set difference in Java. We verify two cases:- Empty path: a class with zero entity rows produces zero "lacking identity" results.
- Happy path: when we seed an AOI for an entity-id, that id is NOT reported as lacking.
-
testLintSecurableLackingObjectIdentity_singleId
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecurableLackingObjectIdentity_singleId()Phase 3 gsec HQL deprecation: regression coverage for the single-id variant oflintSecurableLackingObjectIdentity.Verifies that querying an entity-id that has an AOI returns no "lacks ACL identity" results, and that querying an entity-id with no AOI does report it (when there is no entity row, the lacks-AOI lint short-circuits cleanly).
-
testLintAclObjectIdentityLackingSecurable_reportsDangling
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintAclObjectIdentityLackingSecurable_reportsDangling()Phase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backedlintAclObjectIdentityLackingSecurable(dangling-AOI variant). -
testLintAclObjectIdentityLackingSecurable_emptyPath
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintAclObjectIdentityLackingSecurable_emptyPath()Phase 3 gsec HQL deprecation: empty path forlintAclObjectIdentityLackingSecurable.With no acl_object_identity rows seeded for
BioAssay, the dangling-AOI lint must report nothing for that class. -
testLintSecuredNotChildWithParent_reportsWhenParentSet
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecuredNotChildWithParent_reportsWhenParentSet()Phase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backedlintSecuredNotChildWithParent(bulk variant).Seeds an AOI for
ExpressionExperiment(aSecuredNotChild) carrying a non-nullparent_object, then verifies the linter reports the entity in dry-run mode. -
testLintSecuredNotChildWithParent_singleId_noAoi
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecuredNotChildWithParent_singleId_noAoi()Phase 3 gsec HQL deprecation: regression coverage for the single-id variant oflintSecuredNotChildWithParent. Verifies that an identifier with no AOI does not surface as a finding (short-circuits cleanly). -
testFixingATopLevelSecurableGrantsAdministration
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testFixingATopLevelSecurableGrantsAdministration()Repairing a top-level Securable must leave it editable.The fix used to be a bare
aclService.createAcl(oi), which writes an identity with no parent, no access control entries andentries_inheritingset — "inherit from a parent that does not exist". Nothing then grants ADMINISTRATION or WRITE, so theACL_SECURABLE_EDITvoter denies every caller including an administrator, and the linter reports a successful fix on an entity that is still un-writable. That is how ExpressionExperiments 93287, 93288, 93289, 93433 and 93434 came out of a repair run still answering 403. -
testLintChildWithoutParentAlsoSeesAPresentParentThatIsNotInherited
@Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintChildWithoutParentAlsoSeesAPresentParentThatIsNotInherited()🛑 A SecuredChild whose parent is present AND CORRECT but which does not inherit reaches no other predicate, and grants nothing.lintSecuredChildWithIncorrectParentcompares parent type and identifier and passes such a row; this check used to require a null parent and passed it too. The row carries no ACEs of its own, so an ACL lookup finds no permissions and denies — "Access is denied" even for an administrator.Two live populations on production 2026-09-10: 292 ExpressionAnalysisResultSet rows in exactly this state, 285 of them under PUBLIC experiments, and 8 ExperimentalFactor rows this linter had itself created.
-