1 | package edu.ucsb.cs156.dining.controllers; | |
2 | ||
3 | import edu.ucsb.cs156.dining.entities.MenuItem; | |
4 | import edu.ucsb.cs156.dining.entities.Review; | |
5 | import edu.ucsb.cs156.dining.entities.User; | |
6 | import edu.ucsb.cs156.dining.errors.EntityNotFoundException; | |
7 | import edu.ucsb.cs156.dining.models.CurrentUser; | |
8 | import edu.ucsb.cs156.dining.models.EditedReview; | |
9 | import edu.ucsb.cs156.dining.models.Entree; | |
10 | import edu.ucsb.cs156.dining.repositories.MenuItemRepository; | |
11 | import edu.ucsb.cs156.dining.repositories.ReviewRepository; | |
12 | import edu.ucsb.cs156.dining.statuses.ModerationStatus; | |
13 | import io.swagger.v3.oas.annotations.Operation; | |
14 | import io.swagger.v3.oas.annotations.Parameter; | |
15 | import io.swagger.v3.oas.annotations.tags.Tag; | |
16 | import lombok.extern.slf4j.Slf4j; | |
17 | import com.fasterxml.jackson.core.JsonProcessingException; | |
18 | ||
19 | import java.time.LocalDateTime; | |
20 | import java.util.HashMap; | |
21 | import java.util.List; | |
22 | import java.util.Map; | |
23 | ||
24 | import org.springframework.beans.factory.annotation.Autowired; | |
25 | import org.springframework.format.annotation.DateTimeFormat; | |
26 | import org.springframework.http.HttpStatus; | |
27 | import org.springframework.http.ResponseEntity; | |
28 | import org.springframework.security.access.AccessDeniedException; | |
29 | import org.springframework.security.access.prepost.PreAuthorize; | |
30 | import org.springframework.web.bind.annotation.DeleteMapping; | |
31 | import org.springframework.web.bind.annotation.ExceptionHandler; | |
32 | import org.springframework.web.bind.annotation.GetMapping; | |
33 | import org.springframework.web.bind.annotation.PathVariable; | |
34 | import org.springframework.web.bind.annotation.PostMapping; | |
35 | import org.springframework.web.bind.annotation.PutMapping; | |
36 | import org.springframework.web.bind.annotation.RequestBody; | |
37 | import org.springframework.web.bind.annotation.RequestMapping; | |
38 | import org.springframework.web.bind.annotation.RequestParam; | |
39 | import org.springframework.web.bind.annotation.RestController; | |
40 | import org.springframework.web.server.ResponseStatusException; | |
41 | ||
42 | import com.nimbusds.openid.connect.sdk.claims.UserInfo; | |
43 | ||
44 | import jakarta.validation.Valid; | |
45 | ||
46 | /** | |
47 | * This is a REST controller for Reviews | |
48 | */ | |
49 | ||
50 | @Tag(name = "Review") | |
51 | @RequestMapping("/api/reviews") | |
52 | @RestController | |
53 | @Slf4j | |
54 | public class ReviewController extends ApiController { | |
55 | ||
56 | @ExceptionHandler(IllegalArgumentException.class) | |
57 | public ResponseEntity<Map<String, String>> handleValidationExceptions(IllegalArgumentException ex) { | |
58 | Map<String, String> errors = new HashMap<>(); | |
59 | errors.put("error", ex.getMessage()); | |
60 |
1
1. handleValidationExceptions : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::handleValidationExceptions → KILLED |
return ResponseEntity.badRequest().body(errors); |
61 | } | |
62 | ||
63 | @Autowired | |
64 | ReviewRepository reviewRepository; | |
65 | ||
66 | @Autowired | |
67 | MenuItemRepository menuItemRepository; | |
68 | ||
69 | /** | |
70 | * This method returns a list of all Reviews. | |
71 | * | |
72 | * @return a list of all Reviews | |
73 | */ | |
74 | @Operation(summary = "List all Reviews") | |
75 | @PreAuthorize("hasRole('ROLE_ADMIN')") | |
76 | @GetMapping("/all") | |
77 | public Iterable<Review> allReviews() { | |
78 | log.info("Attempting to log all reviews"); | |
79 | Iterable<Review> reviews = reviewRepository.findAll(); | |
80 | log.info("all reviews found, ", reviews); | |
81 |
1
1. allReviews : replaced return value with Collections.emptyList for edu/ucsb/cs156/dining/controllers/ReviewController::allReviews → KILLED |
return reviews; |
82 | } | |
83 | ||
84 | /** | |
85 | * This method allows a user to submit a review | |
86 | * | |
87 | * @return message that says an review was added to the database | |
88 | * @param itemId id of the item | |
89 | * @param dateItemServed localDataTime | |
90 | * All others params must not be parameters and instead | |
91 | * derived from data sources that are dynamic (Date), or | |
92 | * set to be null or some other signifier | |
93 | */ | |
94 | @Operation(summary = "Create a new review") | |
95 | @PreAuthorize("hasRole('ROLE_USER')") | |
96 | @PostMapping("/post") | |
97 | public Review postReview( | |
98 | @Parameter(name = "itemId") @RequestParam long itemId, | |
99 | @Parameter(description = "Comments by the reviewer, can be blank") @RequestParam(required = false) String reviewerComments, | |
100 | @Parameter(name = "itemsStars") @RequestParam Long itemsStars, | |
101 | @Parameter(name = "dateItemServed", description = "date (in iso format, e.g. YYYY-mm-ddTHH:MM:SS; see https://en.wikipedia.org/wiki/ISO_8601)") @RequestParam("dateItemServed") @DateTimeFormat(iso = DateTimeFormat.ISO.DATE_TIME) LocalDateTime dateItemServed) // For | |
102 | throws JsonProcessingException { | |
103 | LocalDateTime now = LocalDateTime.now(); | |
104 | Review review = new Review(); | |
105 |
1
1. postReview : removed call to edu/ucsb/cs156/dining/entities/Review::setDateItemServed → KILLED |
review.setDateItemServed(dateItemServed); |
106 | ||
107 | // Reviewer comments moderation logic | |
108 |
2
1. postReview : negated conditional → KILLED 2. postReview : negated conditional → KILLED |
if (reviewerComments != null && !reviewerComments.trim().isEmpty()) { |
109 |
1
1. postReview : removed call to edu/ucsb/cs156/dining/entities/Review::setReviewerComments → KILLED |
review.setReviewerComments(reviewerComments); |
110 | } else { | |
111 |
1
1. postReview : removed call to edu/ucsb/cs156/dining/entities/Review::setStatus → KILLED |
review.setStatus(ModerationStatus.APPROVED); // auto-approve |
112 | } | |
113 | | |
114 | ||
115 | ||
116 | // Ensure user inputs rating 1-5 | |
117 |
4
1. postReview : negated conditional → KILLED 2. postReview : changed conditional boundary → KILLED 3. postReview : changed conditional boundary → KILLED 4. postReview : negated conditional → KILLED |
if (itemsStars < 1 || itemsStars > 5) { |
118 | throw new IllegalArgumentException("Items stars must be between 1 and 5."); | |
119 | } | |
120 | ||
121 |
1
1. postReview : removed call to edu/ucsb/cs156/dining/entities/Review::setItemsStars → KILLED |
review.setItemsStars(itemsStars); |
122 | ||
123 | MenuItem reviewedItem = menuItemRepository.findById(itemId).orElseThrow( | |
124 |
1
1. lambda$postReview$0 : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::lambda$postReview$0 → KILLED |
() -> new EntityNotFoundException(MenuItem.class, itemId) |
125 | ); | |
126 |
1
1. postReview : removed call to edu/ucsb/cs156/dining/entities/Review::setItem → KILLED |
review.setItem(reviewedItem); |
127 | CurrentUser user = getCurrentUser(); | |
128 |
1
1. postReview : removed call to edu/ucsb/cs156/dining/entities/Review::setReviewer → KILLED |
review.setReviewer(user.getUser()); |
129 | log.info("reviews={}", review); | |
130 | review = reviewRepository.save(review); | |
131 |
1
1. postReview : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::postReview → KILLED |
return review; |
132 | } | |
133 | ||
134 | @Operation(summary = "Get a single review by id") | |
135 | @PreAuthorize("hasRole('ROLE_USER')") | |
136 | @GetMapping("/get") | |
137 | public Review getReview(@Parameter(name = "id") @RequestParam Long id) { | |
138 | log.info("Attempting to get review with id {}", id); | |
139 | | |
140 | Review review = reviewRepository.findById(id) | |
141 |
1
1. lambda$getReview$1 : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::lambda$getReview$1 → KILLED |
.orElseThrow(() -> new EntityNotFoundException(Review.class, id)); |
142 | | |
143 | // Check if user has permission to view this review | |
144 | User currentUser = getCurrentUser().getUser(); | |
145 | | |
146 | // User can view their own reviews or if they are an admin | |
147 |
2
1. getReview : negated conditional → KILLED 2. getReview : negated conditional → KILLED |
if (currentUser.getId() != review.getReviewer().getId() && !currentUser.getAdmin()) { |
148 | throw new AccessDeniedException("You don't have permission to view this review"); | |
149 | } | |
150 | | |
151 |
1
1. getReview : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::getReview → KILLED |
return review; |
152 | } | |
153 | ||
154 | /** | |
155 | * This method allows a user to get a list of reviews that they have previously made. | |
156 | * Only user can only get a list of their own reviews, and you cant request another persons reviews | |
157 | * @return a list of reviews sent by a given user | |
158 | */ | |
159 | @Operation(summary = "Get all reviews a user has sent: only callable by the user") | |
160 | @PreAuthorize("hasRole('ROLE_USER')") | |
161 | @GetMapping("/userReviews") | |
162 | public Iterable<Review> get_all_review_by_user_id(){ | |
163 | CurrentUser user = getCurrentUser(); | |
164 | Iterable<Review> reviews = reviewRepository.findByReviewer(user.getUser()); | |
165 |
1
1. get_all_review_by_user_id : replaced return value with Collections.emptyList for edu/ucsb/cs156/dining/controllers/ReviewController::get_all_review_by_user_id → KILLED |
return reviews; |
166 | } | |
167 | ||
168 | @Operation(summary = "Edit a review") | |
169 | @PreAuthorize("hasRole('ROLE_USER')") | |
170 | @PutMapping("/reviewer") | |
171 | public Review editReview(@Parameter Long id, @RequestBody @Valid EditedReview incoming) { | |
172 | ||
173 | Review oldReview = reviewRepository.findById(id).orElseThrow( | |
174 |
1
1. lambda$editReview$2 : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::lambda$editReview$2 → KILLED |
() -> new EntityNotFoundException(Review.class, id) |
175 | ); | |
176 | User current = getCurrentUser().getUser(); | |
177 |
1
1. editReview : negated conditional → KILLED |
if(current.getId() != oldReview.getReviewer().getId()) { |
178 | throw new AccessDeniedException("No permission to edit review"); | |
179 | } | |
180 | ||
181 |
4
1. editReview : negated conditional → KILLED 2. editReview : negated conditional → KILLED 3. editReview : changed conditional boundary → KILLED 4. editReview : changed conditional boundary → KILLED |
if(incoming.getItemStars() < 1 || incoming.getItemStars() > 5) { |
182 | throw new IllegalArgumentException("Items stars must be between 1 and 5."); | |
183 | }else{ | |
184 |
1
1. editReview : removed call to edu/ucsb/cs156/dining/entities/Review::setItemsStars → KILLED |
oldReview.setItemsStars(incoming.getItemStars()); |
185 | } | |
186 | ||
187 |
2
1. editReview : negated conditional → KILLED 2. editReview : negated conditional → KILLED |
if (incoming.getReviewerComments() != null &&!incoming.getReviewerComments().trim().isEmpty()) { |
188 |
1
1. editReview : removed call to edu/ucsb/cs156/dining/entities/Review::setReviewerComments → KILLED |
oldReview.setReviewerComments(incoming.getReviewerComments()); |
189 | }else{ | |
190 |
1
1. editReview : removed call to edu/ucsb/cs156/dining/entities/Review::setReviewerComments → KILLED |
oldReview.setReviewerComments(null); |
191 | } | |
192 | ||
193 |
1
1. editReview : removed call to edu/ucsb/cs156/dining/entities/Review::setDateItemServed → KILLED |
oldReview.setDateItemServed(incoming.getDateItemServed()); |
194 | ||
195 |
1
1. editReview : removed call to edu/ucsb/cs156/dining/entities/Review::setStatus → KILLED |
oldReview.setStatus(ModerationStatus.AWAITING_REVIEW); |
196 |
1
1. editReview : removed call to edu/ucsb/cs156/dining/entities/Review::setModeratorComments → KILLED |
oldReview.setModeratorComments(null); |
197 | ||
198 | Review review = reviewRepository.save(oldReview); | |
199 | ||
200 |
1
1. editReview : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::editReview → KILLED |
return review; |
201 | } | |
202 | ||
203 | @Operation(summary = "Delete a review") | |
204 | @PreAuthorize("hasRole('ROLE_USER')") | |
205 | @DeleteMapping("/reviewer") | |
206 | public Object deleteReview(@Parameter Long id) { | |
207 | Review review = reviewRepository.findById(id).orElseThrow( | |
208 |
1
1. lambda$deleteReview$3 : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::lambda$deleteReview$3 → KILLED |
() -> new EntityNotFoundException(Review.class, id) |
209 | ); | |
210 | ||
211 | User current = getCurrentUser().getUser(); | |
212 |
2
1. deleteReview : negated conditional → KILLED 2. deleteReview : negated conditional → KILLED |
if(current.getId() != review.getReviewer().getId() && !current.getAdmin()) { |
213 | throw new AccessDeniedException("No permission to delete review"); | |
214 | } | |
215 | ||
216 |
1
1. deleteReview : removed call to edu/ucsb/cs156/dining/repositories/ReviewRepository::delete → KILLED |
reviewRepository.delete(review); |
217 |
1
1. deleteReview : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::deleteReview → KILLED |
return genericMessage("Review with id %s deleted".formatted(id)); |
218 | } | |
219 | ||
220 | @Operation(summary = "Moderate a review") | |
221 | @PreAuthorize("hasRole('ROLE_ADMIN')") | |
222 | @PutMapping("/moderate") | |
223 | public Review moderateReview(@Parameter Long id, @Parameter ModerationStatus status, @Parameter String moderatorComments) { | |
224 | Review review = reviewRepository.findById(id).orElseThrow( | |
225 |
1
1. lambda$moderateReview$4 : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::lambda$moderateReview$4 → KILLED |
() -> new EntityNotFoundException(Review.class, id) |
226 | ); | |
227 | ||
228 |
1
1. moderateReview : removed call to edu/ucsb/cs156/dining/entities/Review::setModeratorComments → KILLED |
review.setModeratorComments(moderatorComments); |
229 |
1
1. moderateReview : removed call to edu/ucsb/cs156/dining/entities/Review::setStatus → KILLED |
review.setStatus(status); |
230 | ||
231 | review = reviewRepository.save(review); | |
232 |
1
1. moderateReview : replaced return value with null for edu/ucsb/cs156/dining/controllers/ReviewController::moderateReview → KILLED |
return review; |
233 | } | |
234 | ||
235 | @Operation(summary = "See reviews that need moderation") | |
236 | @PreAuthorize("hasRole('ROLE_ADMIN')") | |
237 | @GetMapping("/needsmoderation") | |
238 | public Iterable<Review> needsmoderation() { | |
239 | Iterable<Review> reviewsList = reviewRepository.findByStatus(ModerationStatus.AWAITING_REVIEW); | |
240 |
1
1. needsmoderation : replaced return value with Collections.emptyList for edu/ucsb/cs156/dining/controllers/ReviewController::needsmoderation → KILLED |
return reviewsList; |
241 | } | |
242 | } | |
Mutations | ||
60 |
1.1 |
|
81 |
1.1 |
|
105 |
1.1 |
|
108 |
1.1 2.2 |
|
109 |
1.1 |
|
111 |
1.1 |
|
117 |
1.1 2.2 3.3 4.4 |
|
121 |
1.1 |
|
124 |
1.1 |
|
126 |
1.1 |
|
128 |
1.1 |
|
131 |
1.1 |
|
141 |
1.1 |
|
147 |
1.1 2.2 |
|
151 |
1.1 |
|
165 |
1.1 |
|
174 |
1.1 |
|
177 |
1.1 |
|
181 |
1.1 2.2 3.3 4.4 |
|
184 |
1.1 |
|
187 |
1.1 2.2 |
|
188 |
1.1 |
|
190 |
1.1 |
|
193 |
1.1 |
|
195 |
1.1 |
|
196 |
1.1 |
|
200 |
1.1 |
|
208 |
1.1 |
|
212 |
1.1 2.2 |
|
216 |
1.1 |
|
217 |
1.1 |
|
225 |
1.1 |
|
228 |
1.1 |
|
229 |
1.1 |
|
232 |
1.1 |
|
240 |
1.1 |