Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@Paurikova2
Copy link
Collaborator

@Paurikova2 Paurikova2 commented Jul 3, 2025

Phases MP MM MB MR JM Total
ETA 0 0 0 0 0 0
Developing 6 0 0 0 0 0
Review 0 0 0 0 0 0
Total - - - - - 0
ETA est. 0
ETA cust. - - - - - 0

Problem description

Changing the submitter did not update the resource policy rights.

Summary by CodeRabbit

  • New Features

    • Expanded access control to allow users in the submitters group of a collection to access and claim ownership of workspace items, even without explicit READ permission.
    • Ownership of workspace items can now be transferred to users in the submitters group, updating submission rights accordingly.
  • Tests

    • Added an integration test to verify share token generation and ownership transfer to a third user in the submitters group.

@Paurikova2 Paurikova2 self-assigned this Jul 3, 2025
@coderabbitai
Copy link

coderabbitai bot commented Jul 3, 2025

Walkthrough

The changes enhance authorization logic in the submission workflow by considering both explicit READ permissions and submitter group membership when granting access or transferring ownership of workspace items. Tests have been added to validate the new access control and ownership transfer scenarios involving submitter group members.

Changes

File(s) Change Summary
.../SubmissionController.java Enhanced setOwner method: now checks for submitter group membership in addition to READ permission; updates resource policies logic.
.../WorkspaceItemRestRepository.java Updated findByShareToken to allow access if user is in submitter group or has READ permission; injected GroupService.
.../SubmissionControllerIT.java Added integration test for ownership transfer via share token and submitter group membership; setup and assertions expanded.

Sequence Diagram(s)

sequenceDiagram
    participant User
    participant SubmissionController
    participant WorkspaceItem
    participant Collection
    participant GroupService
    participant ResourcePolicyService

    User->>SubmissionController: Request setOwner(workspaceItemId)
    SubmissionController->>WorkspaceItem: Retrieve item & collection
    SubmissionController->>Collection: Get submitters group
    SubmissionController->>GroupService: Check if user is in submitters group
    alt User in submitters group or has READ permission
        SubmissionController->>ResourcePolicyService: Update submission policies to current user
        SubmissionController->>WorkspaceItem: Set submitter to user & update
    else
        SubmissionController->>User: Throw AccessDeniedException
    end
Loading

Suggested reviewers

  • milanmajchrak
  • vidiecan

Poem

In the warren of code, permissions grew tight,
Now submitters and readers both share the right.
With tokens and groups, the ownership flows,
As rabbits ensure that the right user knows.
Tests hop along, confirming the way—
Secure and precise, for another bright day!
🐇✨


📜 Recent review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a02339c and 8c623fc.

📒 Files selected for processing (1)
  • dspace-server-webapp/src/test/java/org/dspace/app/rest/SubmissionControllerIT.java (3 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • dspace-server-webapp/src/test/java/org/dspace/app/rest/SubmissionControllerIT.java
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Run Integration Tests
  • GitHub Check: Run Unit Tests
  • GitHub Check: dspace-dependencies / docker-build (linux/amd64, ubuntu-latest, true)
✨ Finishing Touches
  • 📝 Generate Docstrings

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@Paurikova2 Paurikova2 linked an issue Jul 3, 2025 that may be closed by this pull request
@Paurikova2 Paurikova2 requested a review from Copilot July 3, 2025 12:25

This comment was marked as outdated.

@Paurikova2 Paurikova2 requested a review from Copilot July 4, 2025 05:02

This comment was marked as outdated.

@Paurikova2 Paurikova2 requested a review from milanmajchrak July 4, 2025 09:50
@Paurikova2 Paurikova2 requested a review from milanmajchrak July 4, 2025 11:50
milanmajchrak
milanmajchrak previously approved these changes Jul 4, 2025
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR extends sharing functionality by recognizing a collection’s submitters group in authorization checks, updating submission-level resource policies when ownership changes, and adding an integration test for transferring ownership to a third party.

  • Allow members of the collection’s submitters group to view and claim shared workspace items
  • Update TYPE_SUBMISSION resource policies to assign to the new submitter in setOwner
  • Add an integration test covering ownership transfer to a third person in the submitters group

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
SubmissionControllerIT.java New test generateShareTokenAndSetOwnerTo3rdPersonTest for multi-step ownership transfer
WorkspaceItemRestRepository.java Extend findByShareToken to permit submitters group access
SubmissionController.java Verify group membership in setOwner and update resource policies
Comments suppressed due to low confidence (2)

dspace-server-webapp/src/main/java/org/dspace/app/rest/repository/SubmissionController.java:179

  • The new loop updating ResourcePolicy entries when changing submitter isn't directly covered by existing tests; consider adding assertions to verify that policies are reassigned correctly.
        List<ResourcePolicy> resourcePolicies = resourcePolicyService.find(context,

dspace-server-webapp/src/main/java/org/dspace/app/rest/repository/WorkspaceItemRestRepository.java:502

  • This code assumes the share token maps to exactly one item; add a check on witems.size() and throw an error if multiple items share the same token to avoid unpredictable behavior.
            Collection collection = witems.get(0).getCollection();

@Paurikova2 Paurikova2 requested a review from milanmajchrak July 8, 2025 07:28
@milanmajchrak milanmajchrak changed the title Update the resource policy rights when changing submitter UFAL/Update the resource policy rights when changing submitter Jul 8, 2025
Copy link
Collaborator

@milanmajchrak milanmajchrak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

shareLink Copilot message

@Paurikova2 Paurikova2 requested a review from milanmajchrak July 9, 2025 07:49
@milanmajchrak milanmajchrak requested a review from vidiecan July 9, 2025 12:13
@milanmajchrak milanmajchrak merged commit d32eca8 into dtq-dev Jul 10, 2025
11 checks passed
milanmajchrak added a commit that referenced this pull request Jul 10, 2025
* UFAL/DOI - Added type of resource to data cite (#975)

* UFAL/The process output is not displayed because of S3 direct download (#971)

* The S3 direct download is provided only for the files located in the ORIGINAL bundle

* Use constant for the ORIGINAL string value

* Check if type is html (#983)

* check if type is html

* added test for html mime type

* used static string for text/html, added check

* Ufal dtq sync062025 (#985)

* we should identify as clarin-dspace

Fix test

(cherry picked from commit 6cdf2d1)

* update email templates to use dspace.shortname

dspace.name can be a long string not fit for Email subjects nor
signatures

(cherry picked from commit 98d60dd)

* match v5 submission

(cherry picked from commit 4a2b65f)

* get rid of lr.help.phone

Phone is now conditional in the templates.
Use `mail.message.helpdesk.telephone` if you want it.

The change in the *.java files is to preserve the params counts. The
relevant templates are getting the phone directly from config

(cherry picked from commit cba5695)

* Add option to configure oai sample identifier

some validators use this value, should be a real id in prod deployments

(cherry picked from commit 912f13f)

* NRP deposit license

(cherry picked from commit ba23878)

* Fix ufal#1219

Get rid of setting the jsse.enableSNIExtension property which causes
issues with handle minting

(cherry picked from commit 7d03173)

* UFAL/Improve file preview generating (#972)

* get name and size from metadata and header of file, avoid input stream using

* remove temp file, checkstyle, do not load full file

* add { } after if

* added check for max preview file

* used ZipFile and TarArchived for filepreview generating

* added removed lines

* used 7z for zip and tar files

* removed 7z and used zip and tar entry

* improved file previrew generating speed, used string builder, xml builder, authorization only if is required

* checkstyle, return boolean from haspreview and previrews from getPreview, replaced return with continue

* fix problem with hibernate session

* fix .tar.gz generating

* skip fully entry for tar

* added indexes for speed up queries

* added license header

* named constant by upper case

* inicialized fileInfo, refactorization of code based on copilot review

---------

Co-authored-by: milanmajchrak <[email protected]>

* Fix the file preview integration test (#989)

* The hasPreview method has been changed, but the IT wasn't updated correctly

* Use the correct checkbox for the input field - use repeatable (#991)

* UFAL/EU Sponsor openaire id should not be required (#1001)

* EU Sponsor openaire id should not be required

* Not required also in the czech submission forms

* Logging error message while emailing users (#1000)

* Logging error message

---------

Co-authored-by: Matus Kasak <[email protected]>
Co-authored-by: milanmajchrak <[email protected]>

* UFAL/Teaching and clariah submissions does not have clarin-license (#1005)

* UFAL/Fix logging in LogoImportController (#1003)

* fix logging

* used formatter for msg

* UFAL/Update the resource policy rights when changing submitter (#1002)

* removed res policies for submitter and created newones when item is shared

* avoid magic number, use constant

* set submitter in existing res policies

* removed not used shared link

* UFAL/Added date to title when creating new version (#984)

* added date to versioned item title

* used more modern approach for getting current time

* renamed test

* used var for reusing

* UFAL/Item handle info in email after download request (#1006)

* Added item handle to email

* Exception when item not found

* Checked grammar

* Handled multiple items found by bitstream

* Using PID instead of handle

---------

Co-authored-by: Matus Kasak <[email protected]>

---------

Co-authored-by: Paurikova2 <[email protected]>
Co-authored-by: Ondřej Košarko <[email protected]>
Co-authored-by: Kasinhou <[email protected]>
Co-authored-by: Matus Kasak <[email protected]>
Co-authored-by: jurinecko <[email protected]>
kosarko added a commit to ufal/clarin-dspace that referenced this pull request Jul 14, 2025
dataquest-dev/dtq-dev sync

Syncing dtq-dev ~lindat-2025.07.16198085191. This contains the following changes:

UFAL/DOI - Added type of resource to data cite (dataquest-dev#975)
Check if type is html (dataquest-dev#983)
UFAL/Improve file preview generating (dataquest-dev#972)
UFAL/Fix logging in LogoImportController (dataquest-dev#1003)
UFAL/Update the resource policy rights when changing submitter (dataquest-dev#1002)
UFAL/Added date to title when creating new version (dataquest-dev#984)

UFAL/The process output is not displayed because of S3 direct download (dataquest-dev#971)
Fix the file preview integration test (dataquest-dev#989)
Use the correct checkbox for the input field - use repeatable (dataquest-dev#991)
UFAL/EU Sponsor openaire id should not be required (dataquest-dev#1001)

Logging error message while emailing users (dataquest-dev#1000)
UFAL/Item handle info in email after download request (dataquest-dev#1006)                                                                                                                                                                                             
Ufal dtq sync062025 (dataquest-dev#985)
Merge commit '33d330a' into HEAD

UFAL/Teaching and clariah submissions does not have clarin-license (dataquest-dev#1005)
milanmajchrak added a commit that referenced this pull request Jul 24, 2025
* UFAL/DOI - Added type of resource to data cite (#975)

* UFAL/The process output is not displayed because of S3 direct download (#971)

* The S3 direct download is provided only for the files located in the ORIGINAL bundle

* Use constant for the ORIGINAL string value

* Check if type is html (#983)

* check if type is html

* added test for html mime type

* used static string for text/html, added check

* Ufal dtq sync062025 (#985)

* we should identify as clarin-dspace

Fix test

(cherry picked from commit 6cdf2d1)

* update email templates to use dspace.shortname

dspace.name can be a long string not fit for Email subjects nor
signatures

(cherry picked from commit 98d60dd)

* match v5 submission

(cherry picked from commit 4a2b65f)

* get rid of lr.help.phone

Phone is now conditional in the templates.
Use `mail.message.helpdesk.telephone` if you want it.

The change in the *.java files is to preserve the params counts. The
relevant templates are getting the phone directly from config

(cherry picked from commit cba5695)

* Add option to configure oai sample identifier

some validators use this value, should be a real id in prod deployments

(cherry picked from commit 912f13f)

* NRP deposit license

(cherry picked from commit ba23878)

* Fix ufal#1219

Get rid of setting the jsse.enableSNIExtension property which causes
issues with handle minting

(cherry picked from commit 7d03173)

* UFAL/Improve file preview generating (#972)

* get name and size from metadata and header of file, avoid input stream using

* remove temp file, checkstyle, do not load full file

* add { } after if

* added check for max preview file

* used ZipFile and TarArchived for filepreview generating

* added removed lines

* used 7z for zip and tar files

* removed 7z and used zip and tar entry

* improved file previrew generating speed, used string builder, xml builder, authorization only if is required

* checkstyle, return boolean from haspreview and previrews from getPreview, replaced return with continue

* fix problem with hibernate session

* fix .tar.gz generating

* skip fully entry for tar

* added indexes for speed up queries

* added license header

* named constant by upper case

* inicialized fileInfo, refactorization of code based on copilot review

---------

Co-authored-by: milanmajchrak <[email protected]>

* Fix the file preview integration test (#989)

* The hasPreview method has been changed, but the IT wasn't updated correctly

* Use the correct checkbox for the input field - use repeatable (#991)

* UFAL/EU Sponsor openaire id should not be required (#1001)

* EU Sponsor openaire id should not be required

* Not required also in the czech submission forms

* Logging error message while emailing users (#1000)

* Logging error message

---------

Co-authored-by: Matus Kasak <[email protected]>
Co-authored-by: milanmajchrak <[email protected]>

* UFAL/Teaching and clariah submissions does not have clarin-license (#1005)

* UFAL/Fix logging in LogoImportController (#1003)

* fix logging

* used formatter for msg

* UFAL/Update the resource policy rights when changing submitter (#1002)

* removed res policies for submitter and created newones when item is shared

* avoid magic number, use constant

* set submitter in existing res policies

* removed not used shared link

* UFAL/Added date to title when creating new version (#984)

* added date to versioned item title

* used more modern approach for getting current time

* renamed test

* used var for reusing

* UFAL/Item handle info in email after download request (#1006)

* Added item handle to email

* Exception when item not found

* Checked grammar

* Handled multiple items found by bitstream

* Using PID instead of handle

---------

Co-authored-by: Matus Kasak <[email protected]>

* UFAL/Incorrect password hash funct used during migration (#999)

* password in request is already hashed, used different password hash funct

* renamed password param in eperson endpoint

* [devOps] labelling reviewing process

* [devOps] labelling reviewing process

* UFAL/New version keeps the old identifier

* UFAL/Send email to editor after submitting item (#1016)

Co-authored-by: Matus Kasak <[email protected]>

* UFAL/Local file size is 0 for file with no zero size (#1017)

* update item metadata after the bitstream size has changed

* issue 1241: ItemFilesMetadataRepair script implementation (DSpace#1243) (#1021)

* issue 1241: ItemFilesMetadataRepair script implementation

* extend script to be applicabble for all items, and for items with files metadata that have missing bitstreams (files)

* implement dry-run option

* option description fix

* Improve error message

* Use "0" instead of "" + 0

* Improve error message

(cherry picked from commit 706f6f6)

Co-authored-by: kuchtiak-ufal <[email protected]>

* UFAL/Refbox upgrade (#1015)

* Created integration test

* Created an endpoint for complete ref box information like in the v5

* Added integration tests for formatting authors

* Removed double semicolon

* Fetch the metadata value following the current locale

* Updated firstMetadataValue because it did return empty string instead of null

* Use DEFAULT_LANGUAGE instead of current locale

* UFAL/Added doc - issue link (#1023)

---------

Co-authored-by: Paurikova2 <[email protected]>
Co-authored-by: Ondřej Košarko <[email protected]>
Co-authored-by: Kasinhou <[email protected]>
Co-authored-by: Matus Kasak <[email protected]>
Co-authored-by: jurinecko <[email protected]>
Co-authored-by: jm <jm@maz>
Co-authored-by: kuchtiak-ufal <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UFAL/Share submission not working correctly

4 participants