Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@
OrganizationReleasePermission,
)
from sentry.api.bases.project import ProjectEndpoint, ProjectReleasePermission
from sentry.auth.staff import is_active_staff
from sentry.models.commitcomparison import CommitComparison
from sentry.models.organization import Organization
from sentry.models.project import Project
Expand Down Expand Up @@ -140,6 +141,9 @@ def delete(self, request: Request, organization: Organization, snapshot_id: str)
except (PreprodArtifact.DoesNotExist, ValueError):
return Response({"detail": "Snapshot not found"}, status=404)

if not is_active_staff(request) and not request.access.has_project_access(artifact.project):
return Response({"detail": "Snapshot not found"}, status=404)

try:
artifact.preprodsnapshotmetrics
except PreprodSnapshotMetrics.DoesNotExist:
Expand Down Expand Up @@ -188,12 +192,15 @@ def get(self, request: Request, organization: Organization, snapshot_id: str) ->
return Response({"detail": "Feature not enabled"}, status=403)

try:
artifact = PreprodArtifact.objects.select_related("commit_comparison").get(
artifact = PreprodArtifact.objects.select_related("commit_comparison", "project").get(
id=snapshot_id, project__organization_id=organization.id
)
except (PreprodArtifact.DoesNotExist, ValueError):
return Response({"detail": "Snapshot not found"}, status=404)

if not is_active_staff(request) and not request.access.has_project_access(artifact.project):
return Response({"detail": "Snapshot not found"}, status=404)

try:
snapshot_metrics = artifact.preprodsnapshotmetrics
except PreprodSnapshotMetrics.DoesNotExist:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -581,3 +581,61 @@ def test_get_snapshot_no_metrics(self) -> None:

assert response.status_code == 404
assert response.data["detail"] == "Snapshot metrics not found"

def test_get_snapshot_returns_404_for_member_without_project_access(self) -> None:
self.org.flags.allow_joinleave = False
self.org.save()
artifact, _, _, _, _ = self._create_artifact_with_manifest()
team = self.create_team(organization=self.org)
outsider = self.create_user(is_superuser=False)
self.create_member(user=outsider, organization=self.org, role="member", teams=[team])
self.login_as(user=outsider)

url = self._get_detail_url(artifact.id)
with self.feature("organizations:preprod-snapshots"):
response = self.client.get(url)

assert response.status_code == 404


class ProjectPreprodSnapshotDeleteTest(APITestCase):
def setUp(self) -> None:
super().setUp()
self.login_as(user=self.user)
self.org = self.create_organization(owner=self.user)
self.project = self.create_project(organization=self.org)

def _delete_url(self, snapshot_id):
return reverse(
"sentry-api-0-project-preprod-snapshots-detail",
args=[self.org.slug, snapshot_id],
)

def _create_snapshot_artifact(self):
artifact = PreprodArtifact.objects.create(
project=self.project,
state=PreprodArtifact.ArtifactState.UPLOADED,
app_id="com.example.app",
)
PreprodSnapshotMetrics.objects.create(
preprod_artifact=artifact,
image_count=0,
extras={"manifest_key": f"{self.org.id}/{self.project.id}/{artifact.id}/manifest.json"},
)
return artifact

def test_delete_returns_404_for_member_without_project_access(self) -> None:
self.org.flags.allow_joinleave = False
self.org.save()
artifact = self._create_snapshot_artifact()
team = self.create_team(organization=self.org)
outsider = self.create_user(is_superuser=False)
self.create_member(user=outsider, organization=self.org, role="member", teams=[team])
self.login_as(user=outsider)

url = self._delete_url(artifact.id)
with self.feature("organizations:preprod-snapshots"):
response = self.client.delete(url)

assert response.status_code == 404
assert PreprodArtifact.objects.filter(id=artifact.id).exists()
Loading