Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -270,7 +270,6 @@ async def count(self, request: RequestRelationCollection) -> Response:
@check_method(RequestMethod.DELETE)
async def delete_list(self, request: RequestRelationCollection) -> Response:
"""delete and dissociate"""
await self.permission.can(request.user, request.collection, "delete")
try:
parent_ids = unpack_id(request.collection.schema, request.pks)
except (FieldValidatorException, CollectionResourceException) as e:
Expand All @@ -281,6 +280,11 @@ async def delete_list(self, request: RequestRelationCollection) -> Response:
if request.query:
delete_mode = bool(request.query.get("delete", False))

if delete_mode is True:
await self.permission.can(request.user, request.foreign_collection, "delete")
else:
await self.permission.can(request.user, request.collection, "edit")

filter = await self.get_base_fk_filter(request)

if (
Expand Down
59 changes: 54 additions & 5 deletions src/agent_toolkit/tests/resources/collections/test_crud_related.py
Original file line number Diff line number Diff line change
Expand Up @@ -1254,7 +1254,7 @@ def test_delete_list(self, mock_mach_id: Mock):
) as fake_delete_one_to_many:
response = self.loop.run_until_complete(self.crud_related_resource.delete_list(request))
fake_delete_one_to_many.assert_awaited()
self.permission_service.can.assert_any_await(request.user, request.collection, "delete")
self.permission_service.can.assert_any_await(request.user, request.collection, "edit")
self.permission_service.can.reset_mock()

assert response.status == 204
Expand All @@ -1275,7 +1275,7 @@ def test_delete_list(self, mock_mach_id: Mock):
) as fake_delete_many_to_many:
response = self.loop.run_until_complete(self.crud_related_resource.delete_list(request))
fake_delete_many_to_many.assert_awaited()
self.permission_service.can.assert_any_await(request.user, request.collection, "delete")
self.permission_service.can.assert_any_await(request.user, request.collection, "edit")
self.permission_service.can.reset_mock()

assert response.status == 204
Expand Down Expand Up @@ -1303,7 +1303,7 @@ def test_delete_list_error(self, mock_mach_id: Mock):
None, # user
)
response = self.loop.run_until_complete(crud_related_resource.delete_list(request))
self.permission_service.can.assert_any_await(request.user, request.collection, "delete")
self.permission_service.can.assert_not_awaited()
self.permission_service.can.reset_mock()
assert response.status == 500
response_content = json.loads(response.body)
Expand Down Expand Up @@ -1331,7 +1331,7 @@ def test_delete_list_error(self, mock_mach_id: Mock):
) as fake_delete_many_to_many:
response = self.loop.run_until_complete(crud_related_resource.delete_list(request))
fake_delete_many_to_many.assert_awaited()
self.permission_service.can.assert_any_await(request.user, request.collection, "delete")
self.permission_service.can.assert_any_await(request.user, request.collection, "edit")
self.permission_service.can.reset_mock()
assert response.status == 500
response_content = json.loads(response.body)
Expand All @@ -1358,7 +1358,7 @@ def test_delete_list_error(self, mock_mach_id: Mock):
None, # user
)
response = self.loop.run_until_complete(crud_related_resource.delete_list(request))
self.permission_service.can.assert_any_await(request.user, request.collection, "delete")
self.permission_service.can.assert_any_await(request.user, request.collection, "edit")
self.permission_service.can.reset_mock()
assert response.status == 500
response_content = json.loads(response.body)
Expand All @@ -1368,6 +1368,55 @@ def test_delete_list_error(self, mock_mach_id: Mock):
"status": 500,
}

def test_delete_list_should_check_delete_permission_when_delete_flag_is_set(self):
query_get_params = {
"collection_name": "customer",
"relation_name": "order",
"timezone": "Europe/Paris",
"fields[order]": "id,cost",
"pks": "2", # customer id
"delete": True,
}
request = RequestRelationCollection(
RequestMethod.DELETE,
*self.mk_request_customer_order_one_to_many(),
{"data": [{"id": "201", "type": "order"}]},
query_get_params,
{},
None,
)
with patch.object(
self.crud_related_resource, "_delete_one_to_many", new_callable=AsyncMock
) as fake_delete_one_to_many:
self.loop.run_until_complete(self.crud_related_resource.delete_list(request))
fake_delete_one_to_many.assert_awaited()
self.permission_service.can.assert_any_await(request.user, request.foreign_collection, "delete")
self.permission_service.can.reset_mock()

def test_delete_list_should_check_edit_permission_when_delete_flag_is_not_set(self):
query_get_params = {
"collection_name": "customer",
"relation_name": "order",
"timezone": "Europe/Paris",
"fields[order]": "id,cost",
"pks": "2", # customer id
}
request = RequestRelationCollection(
RequestMethod.DELETE,
*self.mk_request_customer_order_one_to_many(),
{"data": [{"id": "201", "type": "order"}]},
query_get_params,
{},
None,
)
with patch.object(
self.crud_related_resource, "_delete_one_to_many", new_callable=AsyncMock
) as fake_delete_one_to_many:
self.loop.run_until_complete(self.crud_related_resource.delete_list(request))
fake_delete_one_to_many.assert_awaited()
self.permission_service.can.assert_any_await(request.user, request.collection, "edit")
self.permission_service.can.reset_mock()

# _associate_one_to_many
def test_associate_one_to_many(self):
crud_related_resource = CrudRelatedResource(
Expand Down