Class AbstractCuratableDaoTest
Tested here, on the rule itself, rather than through a DAO query: a filtered query for a non-administrator also carries the ACL EXISTS clause, and test-created entities have no ACL rows, so every such query returns nothing whatever the troubled filter says. A test asserting emptiness there would pass with the rule broken.
- Author:
- gembro
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidvoidvoid🛑 A curator sees troubled entities without asking.voidAn administrator is unchanged by the widening.voidAnd the widening does not reach anyone else:GROUP_AGENTon its own is not a curating role, so an agent that holds only it is still shown the ordinary view.voidA filter on a DIFFERENT alias must not disarm the rule for this one.void🛑 ...but a caller who asks about trouble is not contradicted.void🛑 The short spelling counts too.void...but only for the entity it belongs to: it is this dataset's flag, not its platform's.voidThe default is unchanged: an ordinary caller does not see troubled entities.
-
Constructor Details
-
AbstractCuratableDaoTest
public AbstractCuratableDaoTest()
-
-
Method Details
-
authenticateAsOrdinaryUser
@BeforeEach public void authenticateAsOrdinaryUser() -
clearContext
@AfterEach public void clearContext() -
testTroubledAreHiddenByDefault
@Test public void testTroubledAreHiddenByDefault()The default is unchanged: an ordinary caller does not see troubled entities. -
testAskingAboutTroubleIsNotNegated
@Test public void testAskingAboutTroubleIsNotNegated()🛑 ...but a caller who asks about trouble is not contradicted.ANDing
troubled = falseonto a query that saystroubled = trueyields an empty list rather than an error, so a curator asking which of their datasets are troubled was told "none" — the one answer that is never useful and never obviously wrong. The hiding is editorial, not access control: a troubled dataset is not secret, it is one ordinary users are being told not to rely on. -
testAnotherAliasDoesNotDisarmIt
@Test public void testAnotherAliasDoesNotDisarmIt()A filter on a DIFFERENT alias must not disarm the rule for this one. -
testTheAdvertisedShortAliasDisarmsItToo
@Test public void testTheAdvertisedShortAliasDisarmsItToo()🛑 The short spelling counts too.troubledis advertised as an alias forcurationDetails.troubledand lands on the curation-details alias instead of the object alias; a rule matching only the long name left the short one hidden AND contradicted, sofilter=troubled = trueanswered 0 where the flag was set on 4. -
testTheShortAliasSaysNothingAboutAnAssociatedEntity
@Test public void testTheShortAliasSaysNothingAboutAnAssociatedEntity()...but only for the entity it belongs to: it is this dataset's flag, not its platform's. -
testACuratorSeesTroubledWithoutAskingForThem
@Test public void testACuratorSeesTroubledWithoutAskingForThem()🛑 A curator sees troubled entities without asking. Paul, 2026-09-09: "troubled experiments have to be reachable by curators, how else can they fix the trouble."The authority is spelled out rather than inherited: an administrator satisfies
hasAuthority('GROUP_CURATOR')through the role hierarchy only inside a@PreAuthorizeexpression, and this rule is a plain method call that sees just the granted authorities. A caller holdingGROUP_CURATORalone —gemmaAgentis one — was hidden from every troubled dataset before this. -
testAnAdministratorStillSeesTroubled
@Test public void testAnAdministratorStillSeesTroubled()An administrator is unchanged by the widening. -
testAnAgentAuthorityAloneDoesNotSeeTroubled
@Test public void testAnAgentAuthorityAloneDoesNotSeeTroubled()And the widening does not reach anyone else:GROUP_AGENTon its own is not a curating role, so an agent that holds only it is still shown the ordinary view.
-