Browse Source

Merge pull request #8253 from adovh/bug/fix-alarm-assignment-check-user-id

[3.5] added assignee check for alarm
pull/8257/head
Andrew Shvayka 4 years ago
committed by GitHub
parent
commit
0b0fb2e6e5
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
  1. 3
      application/src/main/java/org/thingsboard/server/controller/AlarmController.java
  2. 2
      application/src/main/java/org/thingsboard/server/service/entitiy/alarm/DefaultTbAlarmService.java
  3. 3
      application/src/test/java/org/thingsboard/server/controller/AbstractWebTest.java
  4. 34
      application/src/test/java/org/thingsboard/server/controller/BaseAlarmControllerTest.java

3
application/src/main/java/org/thingsboard/server/controller/AlarmController.java

@ -139,6 +139,9 @@ public class AlarmController extends BaseController {
checkNotNull(alarm.getOriginator());
checkEntity(alarm.getId(), alarm, Resource.ALARM);
checkEntityId(alarm.getOriginator(), Operation.READ);
if (alarm.getAssigneeId() != null) {
checkUserId(alarm.getAssigneeId(), Operation.READ);
}
return tbAlarmService.save(alarm, getCurrentUser());
}

2
application/src/main/java/org/thingsboard/server/service/entitiy/alarm/DefaultTbAlarmService.java

@ -70,7 +70,7 @@ public class DefaultTbAlarmService extends AbstractTbEntityService implements Tb
UserId newAssignee = alarm.getAssigneeId();
UserId curAssignee = resultAlarm.getAssigneeId();
if (newAssignee != null && !newAssignee.equals(curAssignee)) {
resultAlarm = assign(alarm, newAssignee, alarm.getAssignTs(), user);
resultAlarm = assign(resultAlarm, newAssignee, alarm.getAssignTs(), user);
} else if (newAssignee == null && curAssignee != null) {
resultAlarm = unassign(alarm, alarm.getAssignTs(), user);
}

3
application/src/test/java/org/thingsboard/server/controller/AbstractWebTest.java

@ -352,6 +352,7 @@ public abstract class AbstractWebTest extends AbstractInMemoryStorageTest {
protected Tenant savedDifferentTenant;
protected User savedDifferentTenantUser;
private Customer savedDifferentCustomer;
protected User differentCustomerUser;
protected void loginDifferentTenant() throws Exception {
if (savedDifferentTenant != null) {
@ -379,7 +380,7 @@ public abstract class AbstractWebTest extends AbstractInMemoryStorageTest {
createDifferentCustomer();
loginTenantAdmin();
User differentCustomerUser = new User();
differentCustomerUser = new User();
differentCustomerUser.setAuthority(Authority.CUSTOMER_USER);
differentCustomerUser.setTenantId(tenantId);
differentCustomerUser.setCustomerId(savedDifferentCustomer.getId());

34
application/src/test/java/org/thingsboard/server/controller/BaseAlarmControllerTest.java

@ -656,4 +656,38 @@ public abstract class BaseAlarmControllerTest extends AbstractControllerTest {
return foundAlarm;
}
@Test
public void testCreateAlarmWithOtherTenantsAssignee() throws Exception {
loginDifferentTenant();
loginTenantAdmin();
Alarm alarm = Alarm.builder()
.tenantId(tenantId)
.customerId(customerId)
.originator(customerDevice.getId())
.severity(AlarmSeverity.CRITICAL)
.assigneeId(savedDifferentTenantUser.getId())
.build();
doPost("/api/alarm", alarm).andExpect(status().isForbidden());
}
@Test
public void testCreateAlarmWithOtherCustomerAsAssignee() throws Exception {
loginDifferentCustomer();
loginCustomerUser();
Alarm alarm = Alarm.builder()
.tenantId(tenantId)
.customerId(customerId)
.originator(customerDevice.getId())
.severity(AlarmSeverity.CRITICAL)
.assigneeId(differentCustomerUser.getId())
.build();
doPost("/api/alarm", alarm).andExpect(status().isForbidden());
}
}

Loading…
Cancel
Save