Commit 06e96907 authored by Oswaldo Ferreira's avatar Oswaldo Ferreira Committed by Toon Claes

Add filter param for authorized projects for current_user for V4

parent a9a58156
---
title: Add filter param for authorized projects for current_user for V4
merge_request:
author:
...@@ -37,6 +37,7 @@ Parameters: ...@@ -37,6 +37,7 @@ Parameters:
| `search` | string | no | Return list of authorized projects matching the search criteria | | `search` | string | no | Return list of authorized projects matching the search criteria |
| `simple` | boolean | no | Return only the ID, URL, name, and path of each project | | `simple` | boolean | no | Return only the ID, URL, name, and path of each project |
| `owned` | boolean | no | Limit by projects owned by the current user | | `owned` | boolean | no | Limit by projects owned by the current user |
| `authorized` | boolean | no | Limit by projects authorized for the current user |
| `starred` | boolean | no | Limit by projects starred by the current user | | `starred` | boolean | no | Limit by projects starred by the current user |
```json ```json
......
...@@ -53,3 +53,4 @@ changes are in V4: ...@@ -53,3 +53,4 @@ changes are in V4:
- Remove `GET /groups/owned`. Use `GET /groups?owned=true` instead [!9505](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9505) - Remove `GET /groups/owned`. Use `GET /groups?owned=true` instead [!9505](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9505)
- Return 202 with JSON body on async removals on V4 API (DELETE `/projects/:id/repository/merged_branches` and DELETE `/projects/:id`) [!9449](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9449) - Return 202 with JSON body on async removals on V4 API (DELETE `/projects/:id/repository/merged_branches` and DELETE `/projects/:id`) [!9449](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9449)
- `projects/:id/milestones?iid[]=x&iid[]=y` array filter has been renamed to `iids` [!9096](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9096) - `projects/:id/milestones?iid[]=x&iid[]=y` array filter has been renamed to `iids` [!9096](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9096)
- Enable filtering user's authorized projects with boolean param `authorized` on `/projects` endpoint [!9674](https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9674)
...@@ -252,6 +252,10 @@ module API ...@@ -252,6 +252,10 @@ module API
# project helpers # project helpers
def filter_projects(projects) def filter_projects(projects)
if params[:authorized]
projects = projects.merge(current_user.authorized_projects)
end
if params[:owned] if params[:owned]
projects = projects.merge(current_user.owned_projects) projects = projects.merge(current_user.owned_projects)
end end
......
...@@ -43,9 +43,10 @@ describe API::Projects, api: true do ...@@ -43,9 +43,10 @@ describe API::Projects, api: true do
describe 'GET /projects' do describe 'GET /projects' do
shared_examples_for 'projects response' do shared_examples_for 'projects response' do
it 'returns an array of projects' do it 'returns an array of projects' do
get api('/projects', current_user) get api('/projects', current_user), filter
expect(response).to have_http_status(200) expect(response).to have_http_status(200)
expect(response).to include_pagination_headers
expect(json_response).to be_an Array expect(json_response).to be_an Array
expect(json_response.map { |p| p['id'] }).to contain_exactly(*projects.map(&:id)) expect(json_response.map { |p| p['id'] }).to contain_exactly(*projects.map(&:id))
end end
...@@ -61,6 +62,7 @@ describe API::Projects, api: true do ...@@ -61,6 +62,7 @@ describe API::Projects, api: true do
context 'when unauthenticated' do context 'when unauthenticated' do
it_behaves_like 'projects response' do it_behaves_like 'projects response' do
let(:filter) { {} }
let(:current_user) { nil } let(:current_user) { nil }
let(:projects) { [public_project] } let(:projects) { [public_project] }
end end
...@@ -68,6 +70,7 @@ describe API::Projects, api: true do ...@@ -68,6 +70,7 @@ describe API::Projects, api: true do
context 'when authenticated as regular user' do context 'when authenticated as regular user' do
it_behaves_like 'projects response' do it_behaves_like 'projects response' do
let(:filter) { {} }
let(:current_user) { user } let(:current_user) { user }
let(:projects) { [public_project, project, project2, project3] } let(:projects) { [public_project, project, project2, project3] }
end end
...@@ -133,13 +136,18 @@ describe API::Projects, api: true do ...@@ -133,13 +136,18 @@ describe API::Projects, api: true do
end end
context 'and using search' do context 'and using search' do
it 'returns searched project' do it_behaves_like 'projects response' do
get api('/projects', user), { search: project.name } let(:filter) { { search: project.name } }
let(:current_user) { user }
let(:projects) { [project] }
end
end
expect(response).to have_http_status(200) context 'and authorized=true' do
expect(response).to include_pagination_headers it_behaves_like 'projects response' do
expect(json_response).to be_an Array let(:filter) { { authorized: true } }
expect(json_response.length).to eq(1) let(:current_user) { user }
let(:projects) { [project, project2, project3] }
end end
end end
...@@ -216,36 +224,52 @@ describe API::Projects, api: true do ...@@ -216,36 +224,52 @@ describe API::Projects, api: true do
end end
context 'and with all query parameters' do context 'and with all query parameters' do
# | | project5 | project6 | project7 | project8 | project9 | let!(:project5) { create(:empty_project, :public, path: 'gitlab5', namespace: create(:namespace)) }
# |---------+----------+----------+----------+----------+----------|
# | search | x | | x | x | x |
# | starred | x | x | | x | x |
# | public | x | x | x | | x |
# | owned | x | x | x | x | |
let!(:project5) { create(:empty_project, :public, path: 'gitlab5', namespace: user.namespace) }
let!(:project6) { create(:empty_project, :public, path: 'project6', namespace: user.namespace) } let!(:project6) { create(:empty_project, :public, path: 'project6', namespace: user.namespace) }
let!(:project7) { create(:empty_project, :public, path: 'gitlab7', namespace: user.namespace) } let!(:project7) { create(:empty_project, :public, path: 'gitlab7', namespace: user.namespace) }
let!(:project8) { create(:empty_project, path: 'gitlab8', namespace: user.namespace) } let!(:project8) { create(:empty_project, path: 'gitlab8', namespace: user.namespace) }
let!(:project9) { create(:empty_project, :public, path: 'gitlab9') } let!(:project9) { create(:empty_project, :public, path: 'gitlab9') }
before do before do
user.update_attributes(starred_projects: [project5, project6, project8, project9]) user.update_attributes(starred_projects: [project5, project7, project8, project9])
end end
it 'returns only projects that satify all query parameters' do context 'including owned filter' do
get api('/projects', user), { visibility: 'public', owned: true, starred: true, search: 'gitlab' } it 'returns only projects that satify all query parameters' do
get api('/projects', user), { visibility: 'public', owned: true, starred: true, search: 'gitlab' }
expect(response).to have_http_status(200) expect(response).to have_http_status(200)
expect(response).to include_pagination_headers expect(response).to include_pagination_headers
expect(json_response).to be_an Array expect(json_response).to be_an Array
expect(json_response.size).to eq(1) expect(json_response.size).to eq(1)
expect(json_response.first['id']).to eq(project5.id) expect(json_response.first['id']).to eq(project7.id)
end
end
context 'including authorized filter' do
before do
create(:project_member,
user: user,
project: project5,
access_level: ProjectMember::MASTER)
end
it 'returns only projects that satify all query parameters' do
get api('/projects', user), { visibility: 'public', authorized: true, starred: true, search: 'gitlab' }
expect(response).to have_http_status(200)
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
expect(json_response.size).to eq(2)
expect(json_response.map { |project| project.fetch('id') }).to contain_exactly(project5.id, project7.id)
end
end end
end end
end end
context 'when authenticated as a different user' do context 'when authenticated as a different user' do
it_behaves_like 'projects response' do it_behaves_like 'projects response' do
let(:filter) { {} }
let(:current_user) { user2 } let(:current_user) { user2 }
let(:projects) { [public_project] } let(:projects) { [public_project] }
end end
...@@ -253,6 +277,7 @@ describe API::Projects, api: true do ...@@ -253,6 +277,7 @@ describe API::Projects, api: true do
context 'when authenticated as admin' do context 'when authenticated as admin' do
it_behaves_like 'projects response' do it_behaves_like 'projects response' do
let(:filter) { {} }
let(:current_user) { admin } let(:current_user) { admin }
let(:projects) { Project.all } let(:projects) { Project.all }
end end
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment