Browse Source

Permission check for getDeviceProfileInfoById

pull/6642/head
Viacheslav Klimov 4 years ago
parent
commit
7c1d0fb646
  1. 2
      application/src/main/java/org/thingsboard/server/controller/DeviceProfileController.java
  2. 2
      application/src/test/java/org/thingsboard/server/controller/AbstractWebTest.java
  3. 20
      application/src/test/java/org/thingsboard/server/controller/BaseDeviceProfileControllerTest.java
  4. 5
      common/data/src/main/java/org/thingsboard/server/common/data/DeviceProfileInfo.java

2
application/src/main/java/org/thingsboard/server/controller/DeviceProfileController.java

@ -109,7 +109,7 @@ public class DeviceProfileController extends BaseController {
checkParameter(DEVICE_PROFILE_ID, strDeviceProfileId);
try {
DeviceProfileId deviceProfileId = new DeviceProfileId(toUUID(strDeviceProfileId));
return checkNotNull(deviceProfileService.findDeviceProfileInfoById(getTenantId(), deviceProfileId));
return new DeviceProfileInfo(checkDeviceProfileId(deviceProfileId, Operation.READ));
} catch (Exception e) {
throw handleException(e);
}

2
application/src/test/java/org/thingsboard/server/controller/AbstractWebTest.java

@ -216,6 +216,7 @@ public abstract class AbstractWebTest extends AbstractInMemoryStorageTest {
loginSysAdmin();
doDelete("/api/tenant/" + tenantId.getId().toString())
.andExpect(status().isOk());
deleteDifferentTenant();
verifyNoTenantsLeft();
@ -297,6 +298,7 @@ public abstract class AbstractWebTest extends AbstractInMemoryStorageTest {
loginSysAdmin();
doDelete("/api/tenant/" + savedDifferentTenant.getId().getId().toString())
.andExpect(status().isOk());
savedDifferentTenant = null;
}
}

20
application/src/test/java/org/thingsboard/server/controller/BaseDeviceProfileControllerTest.java

@ -125,6 +125,16 @@ public abstract class BaseDeviceProfileControllerTest extends AbstractController
Assert.assertEquals(savedDeviceProfile, foundDeviceProfile);
}
@Test
public void whenGetDeviceProfileById_thenPermissionsAreChecked() throws Exception {
DeviceProfile deviceProfile = createDeviceProfile("Device profile 1", null);
deviceProfile = doPost("/api/deviceProfile", deviceProfile, DeviceProfile.class);
loginDifferentTenant();
doGet("/api/deviceProfile/" + deviceProfile.getId())
.andExpect(status().isForbidden());
}
@Test
public void testFindDeviceProfileInfoById() throws Exception {
DeviceProfile deviceProfile = this.createDeviceProfile("Device Profile", null);
@ -136,6 +146,16 @@ public abstract class BaseDeviceProfileControllerTest extends AbstractController
Assert.assertEquals(savedDeviceProfile.getType(), foundDeviceProfileInfo.getType());
}
@Test
public void whenGetDeviceProfileInfoById_thenPermissionsAreChecked() throws Exception {
DeviceProfile deviceProfile = createDeviceProfile("Device profile 1", null);
deviceProfile = doPost("/api/deviceProfile", deviceProfile, DeviceProfile.class);
loginDifferentTenant();
doGet("/api/deviceProfileInfo/" + deviceProfile.getId())
.andExpect(status().isForbidden());
}
@Test
public void testFindDefaultDeviceProfileInfo() throws Exception {
DeviceProfileInfo foundDefaultDeviceProfileInfo = doGet("/api/deviceProfileInfo/default", DeviceProfileInfo.class);

5
common/data/src/main/java/org/thingsboard/server/common/data/DeviceProfileInfo.java

@ -63,4 +63,9 @@ public class DeviceProfileInfo extends EntityInfo {
this.transportType = transportType;
}
public DeviceProfileInfo(DeviceProfile profile) {
this(profile.getId(), profile.getName(), profile.getImage(), profile.getDefaultDashboardId(),
profile.getType(), profile.getTransportType());
}
}

Loading…
Cancel
Save