openhim-core
Version:
The OpenHIM core application that provides logging and routing of http requests
615 lines (611 loc) • 22.6 kB
HTML
<html lang="en">
<head>
<title>Code coverage report for src/api/audits.coffee</title>
<meta charset="utf-8" />
<link rel="stylesheet" href="../../prettify.css" />
<link rel="stylesheet" href="../../base.css" />
<meta name="viewport" content="width=device-width, initial-scale=1">
<style type='text/css'>
.coverage-summary .sorter {
background-image: url(../../sort-arrow-sprite.png);
}
</style>
</head>
<body>
<div class='wrapper'>
<div class='pad1'>
<h1>
<a href="../../index.html">All files</a> / <a href="index.html">src/api</a> audits.coffee
</h1>
<div class='clearfix'>
<div class='fl pad1y space-right2'>
<span class="strong">25.33% </span>
<span class="quiet">Statements</span>
<span class='fraction'>19/75</span>
</div>
<div class='fl pad1y space-right2'>
<span class="strong">0% </span>
<span class="quiet">Branches</span>
<span class='fraction'>0/14</span>
</div>
<div class='fl pad1y space-right2'>
<span class="strong">0% </span>
<span class="quiet">Functions</span>
<span class='fraction'>0/7</span>
</div>
<div class='fl pad1y space-right2'>
<span class="strong">25.33% </span>
<span class="quiet">Lines</span>
<span class='fraction'>19/75</span>
</div>
</div>
</div>
<div class='status-line low'></div>
<pre><table class="coverage">
<tr><td class="line-count quiet">1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184</td><td class="line-coverage quiet"><span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-yes">1x</span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-no"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span>
<span class="cline-any cline-neutral"> </span></td><td class="text"><pre class="prettyprint lang-js">Audit = require('../model/audits').Audit
AuditMeta = require('../model/audits').AuditMeta
authorisation = require './authorisation'
Q = require 'q'
logger = require 'winston'
utils = require "../utils"
atna = require 'atna-audit'
auditing = require '../auditing'
os = require 'os'
config = require "../config/config"
config.router = config.get('router')
config.api = config.get('api')
himSourceID = config.get('auditing').auditEvents.auditSourceID
# function to construct projection object
getProjectionObject = <span class="fstat-no" title="function not covered" >(</span>filterRepresentation) ->
<span class="cstat-no" title="statement not covered" > switch filterRepresentation</span>
when "simpledetails"
# view minimum required data for audit details view
<span class="cstat-no" title="statement not covered" > return {</span>}
when "full"
# view all audit data
<span class="cstat-no" title="statement not covered" > return {</span>}
else
# no filterRepresentation supplied - simple view
# view minimum required data for audits
return { "participantObjectIdentification": 0, "activeParticipant": 0, "rawMessage": 0 }
# Audit the audit record retrieval
auditLogUsed = <span class="fstat-no" title="function not covered" >(</span>auditId, outcome, user) ->
<span class="cstat-no" title="statement not covered" > groups = u</span>ser.groups.join(',')
<span class="cstat-no" title="statement not covered" > uri = "https://#{config.router.externalHostname}:#{config.api.httpsPort}/audits/#{a</span>uditId}"
<span class="cstat-no" title="statement not covered" > audit = a</span>tna.auditLogUsedAudit outcome, himSourceID, os.hostname(), user.email, groups, groups, uri
<span class="cstat-no" title="statement not covered" > audit = a</span>tna.wrapInSyslog audit
auditing.sendAuditEvent audit, <span class="fstat-no" title="function not covered" ></span>->
logger.debug "Processed audit log used message for user '#{user.email}' and audit '#{auditId}'"
###
# Adds a Audit
###
exports.addAudit = <span class="fstat-no" title="function not covered" ></span>->
# Test if the user is authorised
if not authorisation.inGroup 'admin', this.authenticated
<span class="cstat-no" title="statement not covered" > utils.logAndSetResponse this, 403, "User #{this.authenticated.email} is not an admin, API access to addAudit denied.", 'info'</span>
<span class="cstat-no" title="statement not covered" > return</span>
<span class="cstat-no" title="statement not covered" > auditData = this.request.b</span>ody
try
<span class="cstat-no" title="statement not covered" > audit = new A</span>udit auditData
<span class="cstat-no" title="statement not covered" > result = y</span>ield Q.ninvoke audit, 'save'
<span class="cstat-no" title="statement not covered" > yield Q.ninvoke auditing, 'processAuditMeta', audit</span>
<span class="cstat-no" title="statement not covered" > logger.info "User #{this.authenticated.email} created audit with id #{audit.id}"</span>
<span class="cstat-no" title="statement not covered" > this.body = '</span>Audit successfully created'
this.status = 201
catch <span class="cstat-no" title="statement not covered" >e</span>
<span class="cstat-no" title="statement not covered" > logger.error "Could not add a audit via the API: #{e.message}"</span>
<span class="cstat-no" title="statement not covered" > this.body = e.m</span>essage
this.status = 400
###
# Retrieves the list of Audits
###
exports.getAudits = <span class="fstat-no" title="function not covered" ></span>->
# Must be admin
if not authorisation.inGroup 'admin', this.authenticated
<span class="cstat-no" title="statement not covered" > utils.logAndSetResponse this, 403, "User #{this.authenticated.email} is not an admin, API access to getAudits denied.", 'info'</span>
<span class="cstat-no" title="statement not covered" > return</span>
try
<span class="cstat-no" title="statement not covered" > filtersObject = this.request.q</span>uery
#get limit and page values
<span class="cstat-no" title="statement not covered" > filterLimit = filtersObject.filterLimit ? 0</span>
<span class="cstat-no" title="statement not covered" > filterPage = filtersObject.filterPage ? 0</span>
<span class="cstat-no" title="statement not covered" > filterRepresentation = filtersObject.f</span>ilterRepresentation
#remove limit/page/filterRepresentation values from filtersObject (Not apart of filtering and will break filter if present)
<span class="cstat-no" title="statement not covered" > delete filtersObject.f</span>ilterLimit
<span class="cstat-no" title="statement not covered" > delete filtersObject.f</span>ilterPage
<span class="cstat-no" title="statement not covered" > delete filtersObject.f</span>ilterRepresentation
#determine skip amount
<span class="cstat-no" title="statement not covered" > filterSkip = filterPage*f</span>ilterLimit
# get projection object
<span class="cstat-no" title="statement not covered" > projectionFiltersObject = g</span>etProjectionObject filterRepresentation
if filtersObject.filters?
<span class="cstat-no" title="statement not covered" > filters = JSON.parse filtersObject.filters</span>
else
<span class="cstat-no" title="statement not covered" > filters = {}</span>
# parse date to get it into the correct format for querying
if filters['eventIdentification.eventDateTime']
<span class="cstat-no" title="statement not covered" > filters['eventIdentification.eventDateTime'] = JSON.parse filters['eventIdentification.eventDateTime']</span>
if filters['participantObjectIdentification.participantObjectID']
# filter by AND on same property for patientID and objectID
<span class="cstat-no" title="statement not covered" > if filters['participantObjectIdentification.participantObjectID'].type</span>
<span class="cstat-no" title="statement not covered" > patientID = new R</span>egExp filters['participantObjectIdentification.participantObjectID'].patientID
<span class="cstat-no" title="statement not covered" > objectID = new R</span>egExp filters['participantObjectIdentification.participantObjectID'].objectID
filters['$and'] = [ { 'participantObjectIdentification.participantObjectID': patientID }, { 'participantObjectIdentification.participantObjectID': objectID } ]
# remove participantObjectIdentification.participantObjectID property as we create a new '$and' operator
<span class="cstat-no" title="statement not covered" > delete filters['participantObjectIdentification.participantObjectID']</span>
else
<span class="cstat-no" title="statement not covered" > participantObjectID = J</span>SON.parse filters['participantObjectIdentification.participantObjectID']
<span class="cstat-no" title="statement not covered" > filters['participantObjectIdentification.participantObjectID'] = new RegExp "#{participantObjectID}"</span>
# execute the query
<span class="cstat-no" title="statement not covered" > this.body = y</span>ield Audit
.find filters, projectionFiltersObject
.skip filterSkip
.limit parseInt filterLimit
.sort 'eventIdentification.eventDateTime': -1
.exec()
# audit each retrieved record, but only for non-basic representation requests
<span class="cstat-no" title="statement not covered" > if filterRepresentation is 'full' or filterRepresentation is 'simpledetails'</span>
<span class="cstat-no" title="statement not covered" > for record in this.body</span>
auditLogUsed record._id, atna.OUTCOME_SUCCESS, this.authenticated
catch <span class="cstat-no" title="statement not covered" >e</span>
utils.logAndSetResponse this, 500, "Could not retrieve audits via the API: #{e}", 'error'
###
# Retrieves the details for a specific Audit Record
###
exports.getAuditById = <span class="fstat-no" title="function not covered" >(</span>auditId) ->
# Must be admin
if not authorisation.inGroup 'admin', this.authenticated
<span class="cstat-no" title="statement not covered" > utils.logAndSetResponse this, 403, "User #{this.authenticated.email} is not an admin, API access to getAuditById denied.", 'info'</span>
<span class="cstat-no" title="statement not covered" > return</span>
# Get the values to use
<span class="cstat-no" title="statement not covered" > auditId = u</span>nescape auditId
try
# get projection object
<span class="cstat-no" title="statement not covered" > projectionFiltersObject = g</span>etProjectionObject 'full'
<span class="cstat-no" title="statement not covered" > result = y</span>ield Audit.findById(auditId, projectionFiltersObject).exec()
# Test if the result if valid
<span class="cstat-no" title="statement not covered" > if not result</span>
<span class="cstat-no" title="statement not covered" > this.body = "Could not find audits record with ID: #{a</span>uditId}"
<span class="cstat-no" title="statement not covered" > this.status = 4</span>04
auditLogUsed auditId, atna.OUTCOME_MINOR_FAILURE, this.authenticated
else
<span class="cstat-no" title="statement not covered" > this.body = r</span>esult
auditLogUsed auditId, atna.OUTCOME_SUCCESS, this.authenticated
catch <span class="cstat-no" title="statement not covered" >e</span>
<span class="cstat-no" title="statement not covered" > utils.logAndSetResponse this, 500, "Could not get audit by ID via the API: #{e}", 'error'</span>
auditLogUsed auditId, atna.OUTCOME_MAJOR_FAILURE, this.authenticated
###
# construct audit filtering dropdown options
###
exports.getAuditsFilterOptions = <span class="fstat-no" title="function not covered" ></span>->
# Must be admin
if not authorisation.inGroup 'admin', this.authenticated
<span class="cstat-no" title="statement not covered" > utils.logAndSetResponse this, 403, "User #{this.authenticated.email} is not an admin, API access to getAudits denied.", 'info'</span>
<span class="cstat-no" title="statement not covered" > return</span>
try
this.body = yield AuditMeta.findOne({}).exec()
catch <span class="cstat-no" title="statement not covered" >e</span>
utils.logAndSetResponse this, 500, "Could not retrieve audits filter options via the API: #{e}", 'error'
</pre></td></tr>
</table></pre>
<div class='push'></div><!-- for sticky footer -->
</div><!-- /wrapper -->
<div class='footer quiet pad2 space-top1 center small'>
Code coverage
generated by <a href="http://istanbul-js.org/" target="_blank">istanbul</a> at Mon Oct 10 2016 13:39:22 GMT+0200 (SAST)
</div>
</div>
<script src="../../prettify.js"></script>
<script>
window.onload = function () {
if (typeof prettyPrint === 'function') {
prettyPrint();
}
};
</script>
<script src="../../sorter.js"></script>
</body>
</html>