Browse Source

update alarm comment moderation logic: delete is allowed for author or tenant admin only

pull/15715/head
dashevchenko 4 months ago
parent
commit
8082d60ffe
  1. 17
      application/src/main/java/org/thingsboard/server/controller/AlarmCommentController.java
  2. 12
      application/src/test/java/org/thingsboard/server/controller/AlarmCommentControllerTest.java

17
application/src/main/java/org/thingsboard/server/controller/AlarmCommentController.java

@ -81,11 +81,7 @@ public class AlarmCommentController extends BaseController {
Alarm alarm = checkAlarmInfoId(alarmId, Operation.WRITE); Alarm alarm = checkAlarmInfoId(alarmId, Operation.WRITE);
SecurityUser currentUser = getCurrentUser(); SecurityUser currentUser = getCurrentUser();
if (alarmComment.getId() != null) { if (alarmComment.getId() != null) {
AlarmComment existingAlarmComment = checkAlarmCommentId(alarmComment.getId(), alarmId); checkUserPermission(alarmComment, alarmId, "edit", currentUser);
if (existingAlarmComment.getUserId() != null && !existingAlarmComment.getUserId().equals(currentUser.getId())) {
throw new ThingsboardException("User is not allowed to edit other user's comment",
ThingsboardErrorCode.PERMISSION_DENIED);
}
} }
alarmComment.setAlarmId(alarmId); alarmComment.setAlarmId(alarmId);
alarmComment.setType(AlarmCommentType.OTHER); alarmComment.setType(AlarmCommentType.OTHER);
@ -104,6 +100,9 @@ public class AlarmCommentController extends BaseController {
AlarmCommentId alarmCommentId = new AlarmCommentId(toUUID(strCommentId)); AlarmCommentId alarmCommentId = new AlarmCommentId(toUUID(strCommentId));
AlarmComment alarmComment = checkAlarmCommentId(alarmCommentId, alarmId); AlarmComment alarmComment = checkAlarmCommentId(alarmCommentId, alarmId);
SecurityUser currentUser = getCurrentUser(); SecurityUser currentUser = getCurrentUser();
if (!currentUser.isTenantAdmin()) {
checkUserPermission(alarmComment, alarmId, "delete", currentUser);
}
tbAlarmCommentService.deleteAlarmComment(alarm, alarmComment, currentUser); tbAlarmCommentService.deleteAlarmComment(alarm, alarmComment, currentUser);
} }
@ -131,4 +130,12 @@ public class AlarmCommentController extends BaseController {
return checkNotNull(alarmCommentService.findAlarmComments(alarm.getTenantId(), alarmId, pageLink)); return checkNotNull(alarmCommentService.findAlarmComments(alarm.getTenantId(), alarmId, pageLink));
} }
private void checkUserPermission(AlarmComment alarmComment, AlarmId alarmId, String operation, SecurityUser currentUser) throws ThingsboardException {
AlarmComment existingAlarmComment = checkAlarmCommentId(alarmComment.getId(), alarmId);
if (existingAlarmComment.getUserId() != null && !existingAlarmComment.getUserId().equals(currentUser.getId())) {
throw new ThingsboardException("User is not allowed to " + operation + " other user's comment",
ThingsboardErrorCode.PERMISSION_DENIED);
}
}
} }

12
application/src/test/java/org/thingsboard/server/controller/AlarmCommentControllerTest.java

@ -235,7 +235,7 @@ public class AlarmCommentControllerTest extends AbstractControllerTest {
} }
@Test @Test
public void testDeleteOthersAlarmCommentIsAllowedForUserWithAlarmWritePermission() throws Exception { public void testDeleteOthersAlarmCommentIsAllowedForAuthorOrTenantAdmin() throws Exception {
loginCustomerUser(); loginCustomerUser();
AlarmComment alarmComment = createAlarmComment(alarm.getId()); AlarmComment alarmComment = createAlarmComment(alarm.getId());
@ -243,15 +243,19 @@ public class AlarmCommentControllerTest extends AbstractControllerTest {
Mockito.reset(tbClusterService, auditLogService); Mockito.reset(tbClusterService, auditLogService);
doDelete("/api/alarm/" + alarm.getId() + "/comment/" + alarmComment.getId()) doDelete("/api/alarm/" + alarm.getId() + "/comment/" + alarmComment.getId())
.andExpect(status().isOk()); .andExpect(status().isForbidden())
.andExpect(statusReason(containsString("User is not allowed to delete other user's comment")));
loginTenantAdmin();
doDelete("/api/alarm/" + alarm.getId() + "/comment/" + alarmComment.getId())
.andExpect(status().isOk());
AlarmComment expectedAlarmComment = AlarmComment.builder() AlarmComment expectedAlarmComment = AlarmComment.builder()
.alarmId(alarm.getId()) .alarmId(alarm.getId())
.type(AlarmCommentType.SYSTEM) .type(AlarmCommentType.SYSTEM)
.comment(JacksonUtil.newObjectNode().put("text", String.format("Comment was deleted by user %s", .comment(JacksonUtil.newObjectNode().put("text", String.format("Comment was deleted by user %s",
SECOND_CUSTOMER_USER_EMAIL))) TENANT_ADMIN_EMAIL)))
.build(); .build();
testLogEntityActionEntityEqClass(alarm, alarm.getId(), tenantId, customerId, secondCustomerUserId, SECOND_CUSTOMER_USER_EMAIL, ActionType.DELETED_COMMENT, 1, expectedAlarmComment); testLogEntityActionEntityEqClass(alarm, alarm.getId(), tenantId, customerId, tenantAdminUserId, TENANT_ADMIN_EMAIL, ActionType.DELETED_COMMENT, 1, expectedAlarmComment);
} }
@Test @Test

Loading…
Cancel
Save