Commit fbd124bf authored by Frédéric Buclin's avatar Frédéric Buclin

Bug 1232186: Component.update and Component.delete are broken

r=dkl
parent 21b3145e
...@@ -28,6 +28,8 @@ extends 'Bugzilla::API::1_0::Resource'; ...@@ -28,6 +28,8 @@ extends 'Bugzilla::API::1_0::Resource';
use constant PUBLIC_METHODS => qw( use constant PUBLIC_METHODS => qw(
create create
delete
update
); );
use constant CREATE_MAPPED_FIELDS => { use constant CREATE_MAPPED_FIELDS => {
...@@ -129,7 +131,7 @@ sub _component_params_to_objects { ...@@ -129,7 +131,7 @@ sub _component_params_to_objects {
# To get the component objects for product/component combination # To get the component objects for product/component combination
# first obtain the product object from the passed product name # first obtain the product object from the passed product name
foreach my $name_hash (@{$params->{names}}) { foreach my $name_hash (@{$params->{names}}) {
my $product = $user->can_admin_product($name_hash->{product}); my $product = $user->check_can_admin_product($name_hash->{product});
push @components, @{ Bugzilla::Component->match({ push @components, @{ Bugzilla::Component->match({
product_id => $product->id, product_id => $product->id,
name => $name_hash->{component} name => $name_hash->{component}
...@@ -157,9 +159,8 @@ sub _component_params_to_objects { ...@@ -157,9 +159,8 @@ sub _component_params_to_objects {
sub update { sub update {
my ($self, $params) = @_; my ($self, $params) = @_;
my $dbh = Bugzilla->dbh; my $dbh = Bugzilla->dbh;
my $user = Bugzilla->user; my $user = Bugzilla->login(LOGIN_REQUIRED);
Bugzilla->login(LOGIN_REQUIRED);
$user->in_group('editcomponents') $user->in_group('editcomponents')
|| scalar @{ $user->get_products_by_permission('editcomponents') } || scalar @{ $user->get_products_by_permission('editcomponents') }
|| ThrowUserError("auth_failure", { group => "editcomponents", || ThrowUserError("auth_failure", { group => "editcomponents",
...@@ -248,11 +249,9 @@ sub update { ...@@ -248,11 +249,9 @@ sub update {
sub delete { sub delete {
my ($self, $params) = @_; my ($self, $params) = @_;
my $dbh = Bugzilla->dbh; my $dbh = Bugzilla->dbh;
my $user = Bugzilla->user; my $user = Bugzilla->login(LOGIN_REQUIRED);
Bugzilla->login(LOGIN_REQUIRED);
$user->in_group('editcomponents') $user->in_group('editcomponents')
|| scalar @{ $user->get_products_by_permission('editcomponents') } || scalar @{ $user->get_products_by_permission('editcomponents') }
|| ThrowUserError("auth_failure", { group => "editcomponents", || ThrowUserError("auth_failure", { group => "editcomponents",
......
...@@ -21,6 +21,8 @@ use Bugzilla::WebService::Util qw(translate params_to_objects validate); ...@@ -21,6 +21,8 @@ use Bugzilla::WebService::Util qw(translate params_to_objects validate);
use constant PUBLIC_METHODS => qw( use constant PUBLIC_METHODS => qw(
create create
delete
update
); );
use constant CREATE_MAPPED_FIELDS => { use constant CREATE_MAPPED_FIELDS => {
...@@ -78,7 +80,7 @@ sub _component_params_to_objects { ...@@ -78,7 +80,7 @@ sub _component_params_to_objects {
# To get the component objects for product/component combination # To get the component objects for product/component combination
# first obtain the product object from the passed product name # first obtain the product object from the passed product name
foreach my $name_hash (@{$params->{names}}) { foreach my $name_hash (@{$params->{names}}) {
my $product = $user->can_admin_product($name_hash->{product}); my $product = $user->check_can_admin_product($name_hash->{product});
push @components, @{ Bugzilla::Component->match({ push @components, @{ Bugzilla::Component->match({
product_id => $product->id, product_id => $product->id,
name => $name_hash->{component} name => $name_hash->{component}
...@@ -106,9 +108,8 @@ sub _component_params_to_objects { ...@@ -106,9 +108,8 @@ sub _component_params_to_objects {
sub update { sub update {
my ($self, $params) = @_; my ($self, $params) = @_;
my $dbh = Bugzilla->dbh; my $dbh = Bugzilla->dbh;
my $user = Bugzilla->user; my $user = Bugzilla->login(LOGIN_REQUIRED);
Bugzilla->login(LOGIN_REQUIRED);
$user->in_group('editcomponents') $user->in_group('editcomponents')
|| scalar @{ $user->get_products_by_permission('editcomponents') } || scalar @{ $user->get_products_by_permission('editcomponents') }
|| ThrowUserError("auth_failure", { group => "editcomponents", || ThrowUserError("auth_failure", { group => "editcomponents",
...@@ -197,11 +198,9 @@ sub update { ...@@ -197,11 +198,9 @@ sub update {
sub delete { sub delete {
my ($self, $params) = @_; my ($self, $params) = @_;
my $dbh = Bugzilla->dbh; my $dbh = Bugzilla->dbh;
my $user = Bugzilla->user; my $user = Bugzilla->login(LOGIN_REQUIRED);
Bugzilla->login(LOGIN_REQUIRED);
$user->in_group('editcomponents') $user->in_group('editcomponents')
|| scalar @{ $user->get_products_by_permission('editcomponents') } || scalar @{ $user->get_products_by_permission('editcomponents') }
|| ThrowUserError("auth_failure", { group => "editcomponents", || ThrowUserError("auth_failure", { group => "editcomponents",
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment