Class AclLinterServiceTest

java.lang.Object
ubic.gemma.core.util.test.BaseTest5
ubic.gemma.core.util.test.BaseDatabaseTest5
ubic.gemma.core.security.authorization.acl.AclLinterServiceTest

@ContextConfiguration @TestExecutionListeners(value=org.springframework.security.test.context.support.WithSecurityContextTestExecutionListener.class, mergeMode=MERGE_WITH_DEFAULTS) public class AclLinterServiceTest extends BaseDatabaseTest5
  • Constructor Details

    • AclLinterServiceTest

      public AclLinterServiceTest()
  • Method Details

    • test

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void test()
    • testLintSecurableLackingObjectIdentity_emptyAndHappyPath

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecurableLackingObjectIdentity_emptyAndHappyPath()
      Phase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backed lintSecurableLackingObjectIdentity (bulk variant).

      The pre-conversion HQL path returned entity-ids in Entity but not in AclObjectIdentity. The new path reads existing AOI identifiers from acl_object_identity JOIN acl_class via raw SQL and does the set difference in Java. We verify two cases:

      1. Empty path: a class with zero entity rows produces zero "lacking identity" results.
      2. Happy path: when we seed an AOI for an entity-id, that id is NOT reported as lacking.
    • testLintSecurableLackingObjectIdentity_singleId

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecurableLackingObjectIdentity_singleId()
      Phase 3 gsec HQL deprecation: regression coverage for the single-id variant of lintSecurableLackingObjectIdentity.

      Verifies that querying an entity-id that has an AOI returns no "lacks ACL identity" results, and that querying an entity-id with no AOI does report it (when there is no entity row, the lacks-AOI lint short-circuits cleanly).

    • testLintAclObjectIdentityLackingSecurable_reportsDangling

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintAclObjectIdentityLackingSecurable_reportsDangling()
      Phase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backed lintAclObjectIdentityLackingSecurable (dangling-AOI variant).
    • testLintAclObjectIdentityLackingSecurable_emptyPath

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintAclObjectIdentityLackingSecurable_emptyPath()
      Phase 3 gsec HQL deprecation: empty path for lintAclObjectIdentityLackingSecurable.

      With no acl_object_identity rows seeded for BioAssay, the dangling-AOI lint must report nothing for that class.

    • testLintSecuredNotChildWithParent_reportsWhenParentSet

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecuredNotChildWithParent_reportsWhenParentSet()
      Phase 3 gsec HQL deprecation: regression coverage for the converted JdbcTemplate-backed lintSecuredNotChildWithParent (bulk variant).

      Seeds an AOI for ExpressionExperiment (a SecuredNotChild) carrying a non-null parent_object, then verifies the linter reports the entity in dry-run mode.

    • testLintSecuredNotChildWithParent_singleId_noAoi

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintSecuredNotChildWithParent_singleId_noAoi()
      Phase 3 gsec HQL deprecation: regression coverage for the single-id variant of lintSecuredNotChildWithParent. Verifies that an identifier with no AOI does not surface as a finding (short-circuits cleanly).
    • testFixingATopLevelSecurableGrantsAdministration

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testFixingATopLevelSecurableGrantsAdministration()
      Repairing a top-level Securable must leave it editable.

      The fix used to be a bare aclService.createAcl(oi), which writes an identity with no parent, no access control entries and entries_inheriting set — "inherit from a parent that does not exist". Nothing then grants ADMINISTRATION or WRITE, so the ACL_SECURABLE_EDIT voter denies every caller including an administrator, and the linter reports a successful fix on an entity that is still un-writable. That is how ExpressionExperiments 93287, 93288, 93289, 93433 and 93434 came out of a repair run still answering 403.

    • testLintChildWithoutParentAlsoSeesAPresentParentThatIsNotInherited

      @Test @WithMockUser(authorities="GROUP_ADMIN") public void testLintChildWithoutParentAlsoSeesAPresentParentThatIsNotInherited()
      🛑 A SecuredChild whose parent is present AND CORRECT but which does not inherit reaches no other predicate, and grants nothing.

      lintSecuredChildWithIncorrectParent compares parent type and identifier and passes such a row; this check used to require a null parent and passed it too. The row carries no ACEs of its own, so an ACL lookup finds no permissions and denies — "Access is denied" even for an administrator.

      Two live populations on production 2026-09-10: 292 ExpressionAnalysisResultSet rows in exactly this state, 285 of them under PUBLIC experiments, and 8 ExperimentalFactor rows this linter had itself created.