# copyright 2015 LOGILAB S.A. (Paris, FRANCE), all rights reserved.# contact http://www.logilab.fr/ -- mailto:contact@logilab.fr## This file is part of CubicWeb.## CubicWeb is free software: you can redistribute it and/or modify it under the# terms of the GNU Lesser General Public License as published by the Free# Software Foundation, either version 2.1 of the License, or (at your option)# any later version.## CubicWeb is distributed in the hope that it will be useful, but WITHOUT# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS# FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License for more# details.## You should have received a copy of the GNU Lesser General Public License along# with CubicWeb. If not, see <http://www.gnu.org/licenses/>.fromcubicweb.devtools.testlibimportCubicWebTCfromcubicweb.serverimporthookfromcubicweb.predicatesimportis_instanceclassSecurityHooksTC(CubicWebTC):defsetup_database(self):withself.admin_access.repo_cnx()ascnx:self.add_eid=cnx.create_entity('EmailAddress',address=u'hop@perdu.com',reverse_use_email=cnx.user.eid).eidcnx.commit()deftest_inlined_cw_edited_relation(self):"""modification of cw_edited to add an inlined relation shouldn't trigger a security error. Test for https://www.cubicweb.org/ticket/5477315 """sender=self.repo.schema['Email'].rdef('sender')withself.temporary_permissions((sender,{'add':()})):classMyHook(hook.Hook):__regid__='test.pouet'__select__=hook.Hook.__select__&is_instance('Email')events=('before_add_entity',)def__call__(self):self.entity.cw_edited['sender']=self._cw.user.primary_email[0].eidwithself.temporary_appobjects(MyHook):withself.admin_access.repo_cnx()ascnx:email=cnx.create_entity('Email',messageid=u'1234')cnx.commit()self.assertEqual(email.sender[0].eid,self.add_eid)if__name__=='__main__':fromlogilab.common.testlibimportunittest_mainunittest_main()