Browse Source

Simplify parent tenant validation

pull/25357/head
maliming 5 months ago
parent
commit
9456694f08
No known key found for this signature in database GPG Key ID: A646B9CB645ECEA4
  1. 2
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json
  2. 2
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json
  3. 53
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs
  4. 38
      modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs

2
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json

@ -76,7 +76,7 @@
"Volo.Abp.Identity:010007": "You can't change your two factor setting.", "Volo.Abp.Identity:010007": "You can't change your two factor setting.",
"Volo.Abp.Identity:010008": "Changing the two factor setting is not allowed.", "Volo.Abp.Identity:010008": "Changing the two factor setting is not allowed.",
"Volo.Abp.Identity:010009": "You cannot delegate yourself!", "Volo.Abp.Identity:010009": "You cannot delegate yourself!",
"Volo.Abp.Identity:010010": "The parent organisation unit ('{ParentId}') does not exist or belong to a different tenant.", "Volo.Abp.Identity:010010": "The parent organisation unit ('{ParentId}') does not exist, or it belongs to a different tenant.",
"Volo.Abp.Identity:010021": "Name exist: '{0}'", "Volo.Abp.Identity:010021": "Name exist: '{0}'",
"Volo.Abp.Identity:010022": "Can not update a static ClaimType.", "Volo.Abp.Identity:010022": "Can not update a static ClaimType.",
"Volo.Abp.Identity:010023": "Can not delete a static ClaimType.", "Volo.Abp.Identity:010023": "Can not delete a static ClaimType.",

2
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json

@ -77,7 +77,7 @@
"Volo.Abp.Identity:010007": "You can't change your two factor setting.", "Volo.Abp.Identity:010007": "You can't change your two factor setting.",
"Volo.Abp.Identity:010008": "It's not allowed to change two factor setting.", "Volo.Abp.Identity:010008": "It's not allowed to change two factor setting.",
"Volo.Abp.Identity:010009": "You can not delegate yourself.", "Volo.Abp.Identity:010009": "You can not delegate yourself.",
"Volo.Abp.Identity:010010": "The parent organization unit ('{ParentId}') does not exist or belong to a different tenant.", "Volo.Abp.Identity:010010": "The parent organization unit ('{ParentId}') does not exist, or it belongs to a different tenant.",
"Volo.Abp.Identity:010021": "Name exist: '{0}'.", "Volo.Abp.Identity:010021": "Name exist: '{0}'.",
"Volo.Abp.Identity:010022": "Can not update a static ClaimType.", "Volo.Abp.Identity:010022": "Can not update a static ClaimType.",
"Volo.Abp.Identity:010023": "Can not delete a static ClaimType.", "Volo.Abp.Identity:010023": "Can not delete a static ClaimType.",

53
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs

@ -41,14 +41,11 @@ public class OrganizationUnitManager : DomainService
[UnitOfWork] [UnitOfWork]
public virtual async Task CreateAsync(OrganizationUnit organizationUnit) public virtual async Task CreateAsync(OrganizationUnit organizationUnit)
{ {
using (CurrentTenant.Change(organizationUnit.TenantId)) await ValidateParentTenantAsync(organizationUnit.ParentId, organizationUnit.TenantId);
{
await ValidateParentTenantAsync(organizationUnit.ParentId, organizationUnit.TenantId);
organizationUnit.Code = await GetNextChildCodeAsync(organizationUnit.ParentId); organizationUnit.Code = await GetNextChildCodeAsync(organizationUnit.ParentId);
await ValidateOrganizationUnitAsync(organizationUnit); await ValidateOrganizationUnitAsync(organizationUnit);
await OrganizationUnitRepository.InsertAsync(organizationUnit); await OrganizationUnitRepository.InsertAsync(organizationUnit);
}
} }
public virtual async Task UpdateAsync(OrganizationUnit organizationUnit) public virtual async Task UpdateAsync(OrganizationUnit organizationUnit)
@ -112,31 +109,28 @@ public class OrganizationUnitManager : DomainService
return; return;
} }
using (CurrentTenant.Change(organizationUnit.TenantId)) await ValidateParentTenantAsync(parentId, organizationUnit.TenantId);
{
await ValidateParentTenantAsync(parentId, organizationUnit.TenantId);
//Should find children before Code change //Should find children before Code change
var children = await FindChildrenAsync(id, true); var children = await FindChildrenAsync(id, true);
//Store old code of OU
var oldCode = organizationUnit.Code;
//Move OU //Store old code of OU
organizationUnit.Code = await GetNextChildCodeAsync(parentId); var oldCode = organizationUnit.Code;
organizationUnit.ParentId = parentId;
await ValidateOrganizationUnitAsync(organizationUnit); //Move OU
organizationUnit.Code = await GetNextChildCodeAsync(parentId);
organizationUnit.ParentId = parentId;
//Update Children Codes await ValidateOrganizationUnitAsync(organizationUnit);
foreach (var child in children)
{
child.Code = OrganizationUnit.AppendCode(organizationUnit.Code, OrganizationUnit.GetRelativeCode(child.Code, oldCode));
await OrganizationUnitRepository.UpdateAsync(child);
}
await OrganizationUnitRepository.UpdateAsync(organizationUnit); //Update Children Codes
foreach (var child in children)
{
child.Code = OrganizationUnit.AppendCode(organizationUnit.Code, OrganizationUnit.GetRelativeCode(child.Code, oldCode));
await OrganizationUnitRepository.UpdateAsync(child);
} }
await OrganizationUnitRepository.UpdateAsync(organizationUnit);
} }
public virtual async Task<string> GetCodeOrDefaultAsync(Guid id) public virtual async Task<string> GetCodeOrDefaultAsync(Guid id)
@ -165,12 +159,7 @@ public class OrganizationUnitManager : DomainService
return; return;
} }
OrganizationUnit parent; var parent = await OrganizationUnitRepository.FindAsync(parentId.Value);
using (CurrentTenant.Change(tenantId))
{
parent = await OrganizationUnitRepository.FindAsync(parentId.Value);
}
if (parent == null || parent.TenantId != tenantId) if (parent == null || parent.TenantId != tenantId)
{ {
throw new BusinessException(IdentityErrorCodes.OrganizationUnitParentTenantMismatch) throw new BusinessException(IdentityErrorCodes.OrganizationUnitParentTenantMismatch)

38
modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs

@ -160,44 +160,6 @@ public class OrganizationUnitManager_Tests : AbpIdentityDomainTestBase
} }
} }
[Fact]
public async Task Should_Not_Create_Organization_Unit_From_Host_With_Cross_Tenant_Parent()
{
var hostOu = await _organizationUnitRepository.GetAsync("OU1");
var newOu = new OrganizationUnit(_guidGenerator.Create(), "ForeignTenantOu", hostOu.Id, Guid.NewGuid());
var ex = await Assert.ThrowsAsync<BusinessException>(
async () => await _organizationUnitManager.CreateAsync(newOu));
ex.Code.ShouldBe(IdentityErrorCodes.OrganizationUnitParentTenantMismatch);
}
[Fact]
public async Task Should_Allow_Host_To_Create_Tenant_Organization_Unit_Under_Same_Tenant_Parent()
{
var tenantId = Guid.NewGuid();
OrganizationUnit tenantRoot;
using (_currentTenant.Change(tenantId))
{
tenantRoot = new OrganizationUnit(_guidGenerator.Create(), "TenantRoot", null, tenantId);
await _organizationUnitManager.CreateAsync(tenantRoot);
}
var child = new OrganizationUnit(_guidGenerator.Create(), "TenantChild", tenantRoot.Id, tenantId);
await _organizationUnitManager.CreateAsync(child);
using (_currentTenant.Change(tenantId))
{
var loaded = await _organizationUnitRepository.FindAsync(child.Id);
loaded.ShouldNotBeNull();
loaded.ParentId.ShouldBe(tenantRoot.Id);
loaded.TenantId.ShouldBe(tenantId);
loaded.Code.ShouldBe(OrganizationUnit.AppendCode(tenantRoot.Code, OrganizationUnit.CreateCode(1)));
}
}
[Fact] [Fact]
public async Task Should_Reject_Cross_Tenant_Parent_When_Multi_Tenancy_Filter_Disabled() public async Task Should_Reject_Cross_Tenant_Parent_When_Multi_Tenancy_Filter_Disabled()
{ {

Loading…
Cancel
Save