Class AbstractCuratableDaoTest

java.lang.Object
ubic.gemma.persistence.service.common.auditAndSecurity.curation.AbstractCuratableDaoTest

public class AbstractCuratableDaoTest extends Object
The rule that decides whether a caller sees troubled entities.

Tested here, on the rule itself, rather than through a DAO query: a filtered query for a non-administrator also carries the ACL EXISTS clause, and test-created entities have no ACL rows, so every such query returns nothing whatever the troubled filter says. A test asserting emptiness there would pass with the rule broken.

Author:
gembro
  • Constructor Details

    • AbstractCuratableDaoTest

      public AbstractCuratableDaoTest()
  • Method Details

    • authenticateAsOrdinaryUser

      @BeforeEach public void authenticateAsOrdinaryUser()
    • clearContext

      @AfterEach public void clearContext()
    • testTroubledAreHiddenByDefault

      @Test public void testTroubledAreHiddenByDefault()
      The default is unchanged: an ordinary caller does not see troubled entities.
    • testAskingAboutTroubleIsNotNegated

      @Test public void testAskingAboutTroubleIsNotNegated()
      🛑 ...but a caller who asks about trouble is not contradicted.

      ANDing troubled = false onto a query that says troubled = true yields an empty list rather than an error, so a curator asking which of their datasets are troubled was told "none" — the one answer that is never useful and never obviously wrong. The hiding is editorial, not access control: a troubled dataset is not secret, it is one ordinary users are being told not to rely on.

    • testAnotherAliasDoesNotDisarmIt

      @Test public void testAnotherAliasDoesNotDisarmIt()
      A filter on a DIFFERENT alias must not disarm the rule for this one.
    • testTheAdvertisedShortAliasDisarmsItToo

      @Test public void testTheAdvertisedShortAliasDisarmsItToo()
      🛑 The short spelling counts too. troubled is advertised as an alias for curationDetails.troubled and lands on the curation-details alias instead of the object alias; a rule matching only the long name left the short one hidden AND contradicted, so filter=troubled = true answered 0 where the flag was set on 4.
    • testTheShortAliasSaysNothingAboutAnAssociatedEntity

      @Test public void testTheShortAliasSaysNothingAboutAnAssociatedEntity()
      ...but only for the entity it belongs to: it is this dataset's flag, not its platform's.
    • testACuratorSeesTroubledWithoutAskingForThem

      @Test public void testACuratorSeesTroubledWithoutAskingForThem()
      🛑 A curator sees troubled entities without asking. Paul, 2026-09-09: "troubled experiments have to be reachable by curators, how else can they fix the trouble."

      The authority is spelled out rather than inherited: an administrator satisfies hasAuthority('GROUP_CURATOR') through the role hierarchy only inside a @PreAuthorize expression, and this rule is a plain method call that sees just the granted authorities. A caller holding GROUP_CURATOR alone — gemmaAgent is one — was hidden from every troubled dataset before this.

    • testAnAdministratorStillSeesTroubled

      @Test public void testAnAdministratorStillSeesTroubled()
      An administrator is unchanged by the widening.
    • testAnAgentAuthorityAloneDoesNotSeeTroubled

      @Test public void testAnAgentAuthorityAloneDoesNotSeeTroubled()
      And the widening does not reach anyone else: GROUP_AGENT on its own is not a curating role, so an agent that holds only it is still shown the ordinary view.