Browse Source

Simplify parent tenant validation

pull/25357/head
maliming 5 months ago
parent
commit
9456694f08
No known key found for this signature in database GPG Key ID: A646B9CB645ECEA4
  1. 2
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json
  2. 2
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json
  3. 53
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs
  4. 38
      modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs

2
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json

@ -76,7 +76,7 @@
"Volo.Abp.Identity:010007": "You can't change your two factor setting.",
"Volo.Abp.Identity:010008": "Changing the two factor setting is not allowed.",
"Volo.Abp.Identity:010009": "You cannot delegate yourself!",
"Volo.Abp.Identity:010010": "The parent organisation unit ('{ParentId}') does not exist or belong to a different tenant.",
"Volo.Abp.Identity:010010": "The parent organisation unit ('{ParentId}') does not exist, or it belongs to a different tenant.",
"Volo.Abp.Identity:010021": "Name exist: '{0}'",
"Volo.Abp.Identity:010022": "Can not update a static ClaimType.",
"Volo.Abp.Identity:010023": "Can not delete a static ClaimType.",

2
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json

@ -77,7 +77,7 @@
"Volo.Abp.Identity:010007": "You can't change your two factor setting.",
"Volo.Abp.Identity:010008": "It's not allowed to change two factor setting.",
"Volo.Abp.Identity:010009": "You can not delegate yourself.",
"Volo.Abp.Identity:010010": "The parent organization unit ('{ParentId}') does not exist or belong to a different tenant.",
"Volo.Abp.Identity:010010": "The parent organization unit ('{ParentId}') does not exist, or it belongs to a different tenant.",
"Volo.Abp.Identity:010021": "Name exist: '{0}'.",
"Volo.Abp.Identity:010022": "Can not update a static ClaimType.",
"Volo.Abp.Identity:010023": "Can not delete a static ClaimType.",

53
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs

@ -41,14 +41,11 @@ public class OrganizationUnitManager : DomainService
[UnitOfWork]
public virtual async Task CreateAsync(OrganizationUnit organizationUnit)
{
using (CurrentTenant.Change(organizationUnit.TenantId))
{
await ValidateParentTenantAsync(organizationUnit.ParentId, organizationUnit.TenantId);
await ValidateParentTenantAsync(organizationUnit.ParentId, organizationUnit.TenantId);
organizationUnit.Code = await GetNextChildCodeAsync(organizationUnit.ParentId);
await ValidateOrganizationUnitAsync(organizationUnit);
await OrganizationUnitRepository.InsertAsync(organizationUnit);
}
organizationUnit.Code = await GetNextChildCodeAsync(organizationUnit.ParentId);
await ValidateOrganizationUnitAsync(organizationUnit);
await OrganizationUnitRepository.InsertAsync(organizationUnit);
}
public virtual async Task UpdateAsync(OrganizationUnit organizationUnit)
@ -112,31 +109,28 @@ public class OrganizationUnitManager : DomainService
return;
}
using (CurrentTenant.Change(organizationUnit.TenantId))
{
await ValidateParentTenantAsync(parentId, organizationUnit.TenantId);
await ValidateParentTenantAsync(parentId, organizationUnit.TenantId);
//Should find children before Code change
var children = await FindChildrenAsync(id, true);
//Store old code of OU
var oldCode = organizationUnit.Code;
//Should find children before Code change
var children = await FindChildrenAsync(id, true);
//Move OU
organizationUnit.Code = await GetNextChildCodeAsync(parentId);
organizationUnit.ParentId = parentId;
//Store old code of OU
var oldCode = organizationUnit.Code;
await ValidateOrganizationUnitAsync(organizationUnit);
//Move OU
organizationUnit.Code = await GetNextChildCodeAsync(parentId);
organizationUnit.ParentId = parentId;
//Update Children Codes
foreach (var child in children)
{
child.Code = OrganizationUnit.AppendCode(organizationUnit.Code, OrganizationUnit.GetRelativeCode(child.Code, oldCode));
await OrganizationUnitRepository.UpdateAsync(child);
}
await ValidateOrganizationUnitAsync(organizationUnit);
await OrganizationUnitRepository.UpdateAsync(organizationUnit);
//Update Children Codes
foreach (var child in children)
{
child.Code = OrganizationUnit.AppendCode(organizationUnit.Code, OrganizationUnit.GetRelativeCode(child.Code, oldCode));
await OrganizationUnitRepository.UpdateAsync(child);
}
await OrganizationUnitRepository.UpdateAsync(organizationUnit);
}
public virtual async Task<string> GetCodeOrDefaultAsync(Guid id)
@ -165,12 +159,7 @@ public class OrganizationUnitManager : DomainService
return;
}
OrganizationUnit parent;
using (CurrentTenant.Change(tenantId))
{
parent = await OrganizationUnitRepository.FindAsync(parentId.Value);
}
var parent = await OrganizationUnitRepository.FindAsync(parentId.Value);
if (parent == null || parent.TenantId != tenantId)
{
throw new BusinessException(IdentityErrorCodes.OrganizationUnitParentTenantMismatch)

38
modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs

@ -160,44 +160,6 @@ public class OrganizationUnitManager_Tests : AbpIdentityDomainTestBase
}
}
[Fact]
public async Task Should_Not_Create_Organization_Unit_From_Host_With_Cross_Tenant_Parent()
{
var hostOu = await _organizationUnitRepository.GetAsync("OU1");
var newOu = new OrganizationUnit(_guidGenerator.Create(), "ForeignTenantOu", hostOu.Id, Guid.NewGuid());
var ex = await Assert.ThrowsAsync<BusinessException>(
async () => await _organizationUnitManager.CreateAsync(newOu));
ex.Code.ShouldBe(IdentityErrorCodes.OrganizationUnitParentTenantMismatch);
}
[Fact]
public async Task Should_Allow_Host_To_Create_Tenant_Organization_Unit_Under_Same_Tenant_Parent()
{
var tenantId = Guid.NewGuid();
OrganizationUnit tenantRoot;
using (_currentTenant.Change(tenantId))
{
tenantRoot = new OrganizationUnit(_guidGenerator.Create(), "TenantRoot", null, tenantId);
await _organizationUnitManager.CreateAsync(tenantRoot);
}
var child = new OrganizationUnit(_guidGenerator.Create(), "TenantChild", tenantRoot.Id, tenantId);
await _organizationUnitManager.CreateAsync(child);
using (_currentTenant.Change(tenantId))
{
var loaded = await _organizationUnitRepository.FindAsync(child.Id);
loaded.ShouldNotBeNull();
loaded.ParentId.ShouldBe(tenantRoot.Id);
loaded.TenantId.ShouldBe(tenantId);
loaded.Code.ShouldBe(OrganizationUnit.AppendCode(tenantRoot.Code, OrganizationUnit.CreateCode(1)));
}
}
[Fact]
public async Task Should_Reject_Cross_Tenant_Parent_When_Multi_Tenancy_Filter_Disabled()
{

Loading…
Cancel
Save