You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@chemistry.apache.org by ga...@apache.org on 2012/04/03 07:14:54 UTC

svn commit: r1308692 [5/42] - in /chemistry/site/trunk/content/java/0.7.0/maven/chemistry-opencmis-server/chemistry-opencmis-server-inmemory: ./ css/ images/ images/logos/ xref-test/ xref-test/org/ xref-test/org/apache/ xref-test/org/apache/chemistry/ ...

Added: chemistry/site/trunk/content/java/0.7.0/maven/chemistry-opencmis-server/chemistry-opencmis-server-inmemory/xref-test/org/apache/chemistry/opencmis/inmemory/AclPermissionsTest.html
URL: http://svn.apache.org/viewvc/chemistry/site/trunk/content/java/0.7.0/maven/chemistry-opencmis-server/chemistry-opencmis-server-inmemory/xref-test/org/apache/chemistry/opencmis/inmemory/AclPermissionsTest.html?rev=1308692&view=auto
==============================================================================
--- chemistry/site/trunk/content/java/0.7.0/maven/chemistry-opencmis-server/chemistry-opencmis-server-inmemory/xref-test/org/apache/chemistry/opencmis/inmemory/AclPermissionsTest.html (added)
+++ chemistry/site/trunk/content/java/0.7.0/maven/chemistry-opencmis-server/chemistry-opencmis-server-inmemory/xref-test/org/apache/chemistry/opencmis/inmemory/AclPermissionsTest.html Tue Apr  3 05:14:48 2012
@@ -0,0 +1,1284 @@
+<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
+<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
+<head>
+<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1" />
+<title>AclPermissionsTest xref</title>
+<link type="text/css" rel="stylesheet" href="../../../../../stylesheet.css" />
+</head>
+<body>
+<pre>
+
+<a name="1" href="#1">1</a>   <strong class="jxr_keyword">package</strong> org.apache.chemistry.opencmis.inmemory;
+<a name="2" href="#2">2</a>   
+<a name="3" href="#3">3</a>   <strong class="jxr_keyword">import</strong> <strong class="jxr_keyword">static</strong> org.junit.Assert.assertTrue;
+<a name="4" href="#4">4</a>   <strong class="jxr_keyword">import</strong> <strong class="jxr_keyword">static</strong> org.junit.Assert.fail;
+<a name="5" href="#5">5</a>   
+<a name="6" href="#6">6</a>   <strong class="jxr_keyword">import</strong> java.math.BigInteger;
+<a name="7" href="#7">7</a>   <strong class="jxr_keyword">import</strong> java.util.ArrayList;
+<a name="8" href="#8">8</a>   <strong class="jxr_keyword">import</strong> java.util.Arrays;
+<a name="9" href="#9">9</a>   <strong class="jxr_keyword">import</strong> java.util.Collections;
+<a name="10" href="#10">10</a>  <strong class="jxr_keyword">import</strong> java.util.GregorianCalendar;
+<a name="11" href="#11">11</a>  <strong class="jxr_keyword">import</strong> java.util.HashMap;
+<a name="12" href="#12">12</a>  <strong class="jxr_keyword">import</strong> java.util.List;
+<a name="13" href="#13">13</a>  <strong class="jxr_keyword">import</strong> java.util.Map;
+<a name="14" href="#14">14</a>  
+<a name="15" href="#15">15</a>  <strong class="jxr_keyword">import</strong> junit.framework.Assert;
+<a name="16" href="#16">16</a>  
+<a name="17" href="#17">17</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.PropertyIds;
+<a name="18" href="#18">18</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.Ace;
+<a name="19" href="#19">19</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.Acl;
+<a name="20" href="#20">20</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ContentStream;
+<a name="21" href="#21">21</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ExtensionsData;
+<a name="22" href="#22">22</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ObjectData;
+<a name="23" href="#23">23</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ObjectInFolderContainer;
+<a name="24" href="#24">24</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ObjectInFolderData;
+<a name="25" href="#25">25</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ObjectInFolderList;
+<a name="26" href="#26">26</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ObjectList;
+<a name="27" href="#27">27</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.ObjectParentData;
+<a name="28" href="#28">28</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.Properties;
+<a name="29" href="#29">29</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.PropertyData;
+<a name="30" href="#30">30</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.data.RenditionData;
+<a name="31" href="#31">31</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.enums.AclPropagation;
+<a name="32" href="#32">32</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.enums.BaseTypeId;
+<a name="33" href="#33">33</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.enums.IncludeRelationships;
+<a name="34" href="#34">34</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.enums.VersioningState;
+<a name="35" href="#35">35</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.exceptions.CmisPermissionDeniedException;
+<a name="36" href="#36">36</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.impl.jaxb.EnumBaseObjectTypeIds;
+<a name="37" href="#37">37</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.impl.jaxb.EnumBasicPermissions;
+<a name="38" href="#38">38</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.server.CallContext;
+<a name="39" href="#39">39</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.commons.spi.Holder;
+<a name="40" href="#40">40</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.inmemory.storedobj.api.ObjectStore;
+<a name="41" href="#41">41</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.inmemory.storedobj.impl.InMemoryAce;
+<a name="42" href="#42">42</a>  <strong class="jxr_keyword">import</strong> org.apache.chemistry.opencmis.server.support.query.CalendarHelper;
+<a name="43" href="#43">43</a>  <strong class="jxr_keyword">import</strong> org.apache.commons.logging.Log;
+<a name="44" href="#44">44</a>  <strong class="jxr_keyword">import</strong> org.apache.commons.logging.LogFactory;
+<a name="45" href="#45">45</a>  <strong class="jxr_keyword">import</strong> org.junit.After;
+<a name="46" href="#46">46</a>  <strong class="jxr_keyword">import</strong> org.junit.Before;
+<a name="47" href="#47">47</a>  <strong class="jxr_keyword">import</strong> org.junit.Test;
+<a name="48" href="#48">48</a>  
+<a name="49" href="#49">49</a>  <strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">class</strong> <a href="../../../../../org/apache/chemistry/opencmis/inmemory/AclPermissionsTest.html">AclPermissionsTest</a> <strong class="jxr_keyword">extends</strong> <a href="../../../../../org/apache/chemistry/opencmis/inmemory/AbstractServiceTest.html">AbstractServiceTest</a>  {
+<a name="50" href="#50">50</a>  
+<a name="51" href="#51">51</a>  	<strong class="jxr_keyword">private</strong> <strong class="jxr_keyword">static</strong> Log LOG = LogFactory.getLog(AclPermissionsTest.<strong class="jxr_keyword">class</strong>);
+<a name="52" href="#52">52</a>  	<strong class="jxr_keyword">private</strong> <strong class="jxr_keyword">static</strong> <strong class="jxr_keyword">final</strong> BigInteger MINUS_ONE = BigInteger.valueOf(-1L);
+<a name="53" href="#53">53</a>  	
+<a name="54" href="#54">54</a>      <strong class="jxr_keyword">protected</strong> <a href="../../../../../org/apache/chemistry/opencmis/inmemory/ObjectCreator.html">ObjectCreator</a> fCreator;
+<a name="55" href="#55">55</a>  	<strong class="jxr_keyword">protected</strong> ObjectStore objectStore = <strong class="jxr_keyword">null</strong>;
+<a name="56" href="#56">56</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt; addACEs = <strong class="jxr_keyword">null</strong>;
+<a name="57" href="#57">57</a>  	<strong class="jxr_keyword">protected</strong> Acl addAcl = <strong class="jxr_keyword">null</strong>;
+<a name="58" href="#58">58</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt; standardACEs = <strong class="jxr_keyword">null</strong>;
+<a name="59" href="#59">59</a>  	<strong class="jxr_keyword">protected</strong> Acl standardAcl = <strong class="jxr_keyword">null</strong>;
+<a name="60" href="#60">60</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt; noReadACEs = <strong class="jxr_keyword">null</strong>;
+<a name="61" href="#61">61</a>  	<strong class="jxr_keyword">protected</strong> Acl noReadAcl = <strong class="jxr_keyword">null</strong>;
+<a name="62" href="#62">62</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt;readACEs = <strong class="jxr_keyword">null</strong>;
+<a name="63" href="#63">63</a>  	<strong class="jxr_keyword">protected</strong> Acl readAcl = <strong class="jxr_keyword">null</strong>;
+<a name="64" href="#64">64</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt;readWriteACEs = <strong class="jxr_keyword">null</strong>;
+<a name="65" href="#65">65</a>  	<strong class="jxr_keyword">protected</strong> Acl readWriteAcl = <strong class="jxr_keyword">null</strong>;
+<a name="66" href="#66">66</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt; writerReadACEs = <strong class="jxr_keyword">null</strong>;
+<a name="67" href="#67">67</a>  	<strong class="jxr_keyword">protected</strong> Acl writerReadAcl = <strong class="jxr_keyword">null</strong>;
+<a name="68" href="#68">68</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt; adminACEs = <strong class="jxr_keyword">null</strong>;
+<a name="69" href="#69">69</a>  	<strong class="jxr_keyword">protected</strong> Acl adminAcl = <strong class="jxr_keyword">null</strong>;
+<a name="70" href="#70">70</a>  	<strong class="jxr_keyword">protected</strong> List&lt;Ace&gt; testUserACEs = <strong class="jxr_keyword">null</strong>;
+<a name="71" href="#71">71</a>  	<strong class="jxr_keyword">protected</strong> Acl testUserAcl = <strong class="jxr_keyword">null</strong>;
+<a name="72" href="#72">72</a>  	<strong class="jxr_keyword">protected</strong> Acl defaultAcl = <strong class="jxr_keyword">null</strong>;
+<a name="73" href="#73">73</a>  	
+<a name="74" href="#74">74</a>  	<strong class="jxr_keyword">protected</strong> <strong class="jxr_keyword">static</strong> Map&lt;String, String&gt; idMap = <strong class="jxr_keyword">new</strong> HashMap&lt;String, String&gt;();
+<a name="75" href="#75">75</a>  	
+<a name="76" href="#76">76</a>      @Override
+<a name="77" href="#77">77</a>      @After
+<a name="78" href="#78">78</a>      <strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> tearDown() {
+<a name="79" href="#79">79</a>          <strong class="jxr_keyword">super</strong>.tearDown();
+<a name="80" href="#80">80</a>      }
+<a name="81" href="#81">81</a>  
+<a name="82" href="#82">82</a>      @Override
+<a name="83" href="#83">83</a>      @Before
+<a name="84" href="#84">84</a>      <strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> setUp() {
+<a name="85" href="#85">85</a>          <strong class="jxr_keyword">super</strong>.setTypeCreatorClass(UnitTestTypeSystemCreator.<strong class="jxr_keyword">class</strong>.getName());
+<a name="86" href="#86">86</a>          <strong class="jxr_keyword">super</strong>.setUp();
+<a name="87" href="#87">87</a>          fCreator = <strong class="jxr_keyword">new</strong> <a href="../../../../../org/apache/chemistry/opencmis/inmemory/ObjectCreator.html">ObjectCreator</a>(fFactory, fObjSvc, fRepositoryId);
+<a name="88" href="#88">88</a>  		 List&lt;String&gt; principalIds = <strong class="jxr_keyword">new</strong> ArrayList&lt;String&gt;(3);
+<a name="89" href="#89">89</a>  		 principalIds.add(<span class="jxr_string">"TestAdmin"</span>);
+<a name="90" href="#90">90</a>  		 principalIds.add(<span class="jxr_string">"Writer"</span>);
+<a name="91" href="#91">91</a>  		 principalIds.add(<span class="jxr_string">"Reader"</span>);
+<a name="92" href="#92">92</a>  		 principalIds.add(<span class="jxr_string">"TestUser"</span>);
+<a name="93" href="#93">93</a>  		addACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(4);
+<a name="94" href="#94">94</a>  		addACEs.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="95" href="#95">95</a>  		addACEs.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="96" href="#96">96</a>  		addACEs.add(createAce(<span class="jxr_string">"TestUser"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="97" href="#97">97</a>  		addACEs.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="98" href="#98">98</a>  		addAcl = fFactory.createAccessControlList(addACEs);
+<a name="99" href="#99">99</a>  		
+<a name="100" href="#100">100</a> 		standardACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(3);
+<a name="101" href="#101">101</a> 		standardACEs.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="102" href="#102">102</a> 		standardACEs.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="103" href="#103">103</a> 		standardACEs.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="104" href="#104">104</a> 		standardAcl = fFactory.createAccessControlList(standardACEs);	
+<a name="105" href="#105">105</a> 		
+<a name="106" href="#106">106</a> 		noReadACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(2);
+<a name="107" href="#107">107</a> 		noReadACEs.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="108" href="#108">108</a> 		noReadACEs.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="109" href="#109">109</a> 		noReadAcl = fFactory.createAccessControlList(noReadACEs);	
+<a name="110" href="#110">110</a> 		
+<a name="111" href="#111">111</a> 		readACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="112" href="#112">112</a> 		readACEs.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="113" href="#113">113</a> 		readAcl = fFactory.createAccessControlList(readACEs);	
+<a name="114" href="#114">114</a> 		
+<a name="115" href="#115">115</a> 		readWriteACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(2);
+<a name="116" href="#116">116</a> 		readWriteACEs.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="117" href="#117">117</a> 		readWriteACEs.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="118" href="#118">118</a> 		readWriteAcl = fFactory.createAccessControlList(readWriteACEs);	
+<a name="119" href="#119">119</a> 		
+<a name="120" href="#120">120</a> 		testUserACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="121" href="#121">121</a> 		testUserACEs.add(createAce(<span class="jxr_string">"TestUser"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="122" href="#122">122</a> 		testUserAcl = fFactory.createAccessControlList(testUserACEs);	
+<a name="123" href="#123">123</a> 		
+<a name="124" href="#124">124</a> 		writerReadACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="125" href="#125">125</a> 		writerReadACEs.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="126" href="#126">126</a> 		writerReadAcl = fFactory.createAccessControlList(writerReadACEs);	
+<a name="127" href="#127">127</a> 		
+<a name="128" href="#128">128</a> 		adminACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="129" href="#129">129</a> 		adminACEs.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="130" href="#130">130</a> 		adminAcl = fFactory.createAccessControlList(adminACEs);	
+<a name="131" href="#131">131</a> 		
+<a name="132" href="#132">132</a> 		List&lt;Ace&gt; defaultACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="133" href="#133">133</a>         defaultACEs.add(createAce(InMemoryAce.getAnyoneUser(), EnumBasicPermissions.CMIS_ALL));
+<a name="134" href="#134">134</a>         defaultAcl = fFactory.createAccessControlList(defaultACEs); 
+<a name="135" href="#135">135</a> 	}
+<a name="136" href="#136">136</a> 
+<a name="137" href="#137">137</a> 	@Test
+<a name="138" href="#138">138</a> 	<strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> testCreateObjectsWithAcl()
+<a name="139" href="#139">139</a> 	{
+<a name="140" href="#140">140</a> 		<em class="jxr_comment">// create a document with initial ACL</em>
+<a name="141" href="#141">141</a> 		String docId = createDocumentWithAcls(<span class="jxr_string">"complexDocument"</span>,  fRootFolderId, UnitTestTypeSystemCreator.COMPLEX_TYPE,
+<a name="142" href="#142">142</a> 				addAcl, defaultAcl);
+<a name="143" href="#143">143</a> 		Acl acl1 = fAclSvc.getAcl(fRepositoryId, docId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="144" href="#144">144</a> 		assertTrue(aclEquals(addAcl, acl1));
+<a name="145" href="#145">145</a> 		
+<a name="146" href="#146">146</a> 		<em class="jxr_comment">// create a folder with initial ACL</em>
+<a name="147" href="#147">147</a> 		String folderId = createFolderWithAcls(<span class="jxr_string">"folderWithAcl"</span>, fRootFolderId, BaseTypeId.CMIS_FOLDER.value(),
+<a name="148" href="#148">148</a> 				addAcl, defaultAcl);
+<a name="149" href="#149">149</a> 		Acl acl2 = fAclSvc.getAcl(fRepositoryId, folderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="150" href="#150">150</a> 		assertTrue(aclEquals(addAcl, acl2));
+<a name="151" href="#151">151</a> 		
+<a name="152" href="#152">152</a> 		<em class="jxr_comment">// add acl later</em>
+<a name="153" href="#153">153</a> 		String docId2 = createVersionedDocument(<span class="jxr_string">"complexDocument2"</span>,  fRootFolderId);
+<a name="154" href="#154">154</a>         Acl acl = fAclSvc.applyAcl(fRepositoryId, docId2, addAcl, defaultAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="155" href="#155">155</a> 		assertTrue(aclEquals(addAcl, acl));
+<a name="156" href="#156">156</a> 		
+<a name="157" href="#157">157</a> 		String folderId2 = createFolder(<span class="jxr_string">"folder2"</span>, fRootFolderId, <span class="jxr_string">"cmis:folder"</span>);
+<a name="158" href="#158">158</a> 		acl2 = fAclSvc.applyAcl(fRepositoryId, folderId2, addAcl, defaultAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="159" href="#159">159</a> 		assertTrue(aclEquals(addAcl, acl2));
+<a name="160" href="#160">160</a> 		
+<a name="161" href="#161">161</a> 		<em class="jxr_comment">// add a subfolder</em>
+<a name="162" href="#162">162</a> 		String subFolderId = createFolder(<span class="jxr_string">"subFolder"</span>, folderId,  BaseTypeId.CMIS_FOLDER.value());
+<a name="163" href="#163">163</a> 		<em class="jxr_comment">// folder should inherit acl</em>
+<a name="164" href="#164">164</a> 		Acl subAcl = fAclSvc.getAcl(fRepositoryId, subFolderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="165" href="#165">165</a> 		assertTrue(aclEquals(addAcl, subAcl));
+<a name="166" href="#166">166</a> 		
+<a name="167" href="#167">167</a> 		<em class="jxr_comment">// add a document</em>
+<a name="168" href="#168">168</a> 		String subDocId = createVersionedDocument(<span class="jxr_string">"subDoc"</span>, subFolderId);
+<a name="169" href="#169">169</a> 		<em class="jxr_comment">// document should inherit acl</em>
+<a name="170" href="#170">170</a> 		Acl subAclDoc = fAclSvc.getAcl(fRepositoryId, subDocId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="171" href="#171">171</a> 		assertTrue(aclEquals(addAcl, subAclDoc));
+<a name="172" href="#172">172</a> 		
+<a name="173" href="#173">173</a> 		<em class="jxr_comment">// remove an ace, no permission is left for TestUser</em>
+<a name="174" href="#174">174</a> 		Acl removeAcl = createAcl(<span class="jxr_string">"TestUser"</span>, EnumBasicPermissions.CMIS_WRITE);
+<a name="175" href="#175">175</a> 		Acl acl3 = fAclSvc.applyAcl(fRepositoryId, docId2, <strong class="jxr_keyword">null</strong>, removeAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="176" href="#176">176</a> 		
+<a name="177" href="#177">177</a> 		List&lt;Ace&gt; compareRemoveACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(3);
+<a name="178" href="#178">178</a> 		compareRemoveACEs.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="179" href="#179">179</a> 		compareRemoveACEs.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="180" href="#180">180</a> 		compareRemoveACEs.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="181" href="#181">181</a> 		Acl compareRemoveAcl = fFactory.createAccessControlList(compareRemoveACEs);
+<a name="182" href="#182">182</a> 		
+<a name="183" href="#183">183</a> 		assertTrue(aclEquals(compareRemoveAcl, acl3));
+<a name="184" href="#184">184</a> 		
+<a name="185" href="#185">185</a> 		<em class="jxr_comment">// addACE not propagated</em>
+<a name="186" href="#186">186</a> 		Acl addPropAcl = createAcl(<span class="jxr_string">"TestUser"</span>, EnumBasicPermissions.CMIS_WRITE);
+<a name="187" href="#187">187</a> 		
+<a name="188" href="#188">188</a> 		Acl acl4 = fAclSvc.applyAcl(fRepositoryId, subFolderId, addPropAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="189" href="#189">189</a> 		Acl subAclDoc2 = fAclSvc.getAcl(fRepositoryId, subDocId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="190" href="#190">190</a> 		assertTrue(aclEquals(addAcl, subAclDoc2));  <em class="jxr_comment">// acl of doc did not change</em>
+<a name="191" href="#191">191</a> 		
+<a name="192" href="#192">192</a> 		List&lt;Ace&gt; compareRemoveACEs2 = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(4);
+<a name="193" href="#193">193</a> 		compareRemoveACEs2.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="194" href="#194">194</a> 		compareRemoveACEs2.add(createAce(<span class="jxr_string">"Writer"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="195" href="#195">195</a> 		compareRemoveACEs2.add(createAce(<span class="jxr_string">"TestUser"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="196" href="#196">196</a> 		compareRemoveACEs2.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="197" href="#197">197</a> 		Acl compareRemoveAcl2 = fFactory.createAccessControlList(compareRemoveACEs2);
+<a name="198" href="#198">198</a> 		assertTrue(aclEquals(compareRemoveAcl2, acl4)); 
+<a name="199" href="#199">199</a> 		
+<a name="200" href="#200">200</a> 		<em class="jxr_comment">// addACE propagated</em>
+<a name="201" href="#201">201</a> 		Acl acl5 = fAclSvc.applyAcl(fRepositoryId, subFolderId, addPropAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.PROPAGATE, <strong class="jxr_keyword">null</strong>);
+<a name="202" href="#202">202</a> 		Acl subAclDoc3 = fAclSvc.getAcl(fRepositoryId, subDocId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="203" href="#203">203</a> 		assertTrue(aclEquals(compareRemoveAcl2, subAclDoc3));  <em class="jxr_comment">// acl of doc did change</em>
+<a name="204" href="#204">204</a> 		assertTrue(aclEquals(compareRemoveAcl2, acl5)); 
+<a name="205" href="#205">205</a> 	}
+<a name="206" href="#206">206</a> 		
+<a name="207" href="#207">207</a> 	
+<a name="208" href="#208">208</a> 	@Test
+<a name="209" href="#209">209</a> 	<strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> checkNavigationServiceGeneralAccess()
+<a name="210" href="#210">210</a> 	{
+<a name="211" href="#211">211</a> 		<em class="jxr_comment">// starts with call context TestUser</em>
+<a name="212" href="#212">212</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="213" href="#213">213</a> 		String docId = createDocumentWithAcls(<span class="jxr_string">"doc"</span>,  fRootFolderId, <span class="jxr_string">"ComplexType"</span>,
+<a name="214" href="#214">214</a> 				standardAcl, defaultAcl);
+<a name="215" href="#215">215</a> 		String folderId = createFolderWithAcls(<span class="jxr_string">"folder"</span>, fRootFolderId, <span class="jxr_string">"cmis:folder"</span>, standardAcl, defaultAcl);
+<a name="216" href="#216">216</a> <em class="jxr_comment">//		fTestCallContext = new DummyCallContext("Writer");</em>
+<a name="217" href="#217">217</a> 		String subFolderId = createFolderWithAcls(<span class="jxr_string">"subFolder"</span>, folderId, <span class="jxr_string">"cmis:folder"</span>, standardAcl, <strong class="jxr_keyword">null</strong>);
+<a name="218" href="#218">218</a> 		
+<a name="219" href="#219">219</a> 		
+<a name="220" href="#220">220</a> 		<em class="jxr_comment">// TestUser has no permission at all</em>
+<a name="221" href="#221">221</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="222" href="#222">222</a> 		<strong class="jxr_keyword">boolean</strong> exceptionThrown = false;
+<a name="223" href="#223">223</a> 		<strong class="jxr_keyword">try</strong>
+<a name="224" href="#224">224</a> 		{
+<a name="225" href="#225">225</a> 			ObjectInFolderList list = fNavSvc.getChildren(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, false, IncludeRelationships.NONE, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, 
+<a name="226" href="#226">226</a> 					BigInteger.ZERO , BigInteger.ZERO, <strong class="jxr_keyword">null</strong>);
+<a name="227" href="#227">227</a> 		}
+<a name="228" href="#228">228</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="229" href="#229">229</a> 		{
+<a name="230" href="#230">230</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="231" href="#231">231</a> 		}
+<a name="232" href="#232">232</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="233" href="#233">233</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="234" href="#234">234</a> 		
+<a name="235" href="#235">235</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="236" href="#236">236</a> 		ObjectInFolderList list = fNavSvc.getChildren(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, false, IncludeRelationships.NONE, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>,
+<a name="237" href="#237">237</a> 				BigInteger.ZERO , BigInteger.ZERO, <strong class="jxr_keyword">null</strong>);
+<a name="238" href="#238">238</a> 		
+<a name="239" href="#239">239</a> 		
+<a name="240" href="#240">240</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="241" href="#241">241</a> 		exceptionThrown = false;
+<a name="242" href="#242">242</a> 		<strong class="jxr_keyword">try</strong>
+<a name="243" href="#243">243</a> 		{
+<a name="244" href="#244">244</a> 			List&lt;ObjectInFolderContainer&gt; list2 = fNavSvc.getDescendants(fRepositoryId, folderId, MINUS_ONE, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="245" href="#245">245</a> 		}
+<a name="246" href="#246">246</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="247" href="#247">247</a> 		{
+<a name="248" href="#248">248</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="249" href="#249">249</a> 		}
+<a name="250" href="#250">250</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="251" href="#251">251</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="252" href="#252">252</a> 		
+<a name="253" href="#253">253</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="254" href="#254">254</a> 		List&lt;ObjectInFolderContainer&gt; list2 = fNavSvc.getDescendants(fRepositoryId, folderId, MINUS_ONE, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="255" href="#255">255</a> 		
+<a name="256" href="#256">256</a> 		
+<a name="257" href="#257">257</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="258" href="#258">258</a> 		exceptionThrown = false;
+<a name="259" href="#259">259</a> 		<strong class="jxr_keyword">try</strong>
+<a name="260" href="#260">260</a> 		{
+<a name="261" href="#261">261</a> 			List&lt;ObjectInFolderContainer&gt; list3 = fNavSvc.getFolderTree(fRepositoryId, folderId, BigInteger.ONE, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="262" href="#262">262</a> 		}
+<a name="263" href="#263">263</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="264" href="#264">264</a> 		{
+<a name="265" href="#265">265</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="266" href="#266">266</a> 		}
+<a name="267" href="#267">267</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="268" href="#268">268</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="269" href="#269">269</a> 		
+<a name="270" href="#270">270</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="271" href="#271">271</a> 		List&lt;ObjectInFolderContainer&gt; list3 = fNavSvc.getFolderTree(fRepositoryId, folderId, BigInteger.ONE, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="272" href="#272">272</a> 		
+<a name="273" href="#273">273</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="274" href="#274">274</a> 		exceptionThrown = false;
+<a name="275" href="#275">275</a> 		<strong class="jxr_keyword">try</strong>
+<a name="276" href="#276">276</a> 		{
+<a name="277" href="#277">277</a> 			List&lt;ObjectParentData&gt; list4 = fNavSvc.getObjectParents(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="278" href="#278">278</a> 		}
+<a name="279" href="#279">279</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="280" href="#280">280</a> 		{
+<a name="281" href="#281">281</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="282" href="#282">282</a> 		}
+<a name="283" href="#283">283</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="284" href="#284">284</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="285" href="#285">285</a> 		
+<a name="286" href="#286">286</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="287" href="#287">287</a> 		List&lt;ObjectParentData&gt; list4 = fNavSvc.getObjectParents(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="288" href="#288">288</a> 		
+<a name="289" href="#289">289</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="290" href="#290">290</a> 		exceptionThrown = false;
+<a name="291" href="#291">291</a> 		<strong class="jxr_keyword">try</strong>
+<a name="292" href="#292">292</a> 		{
+<a name="293" href="#293">293</a> 			ObjectData list5 = fNavSvc.getFolderParent(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="294" href="#294">294</a> 		}
+<a name="295" href="#295">295</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="296" href="#296">296</a> 		{
+<a name="297" href="#297">297</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="298" href="#298">298</a> 		}
+<a name="299" href="#299">299</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="300" href="#300">300</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="301" href="#301">301</a> 		
+<a name="302" href="#302">302</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="303" href="#303">303</a> 		ObjectData list5 = fNavSvc.getFolderParent(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="304" href="#304">304</a> 	
+<a name="305" href="#305">305</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="306" href="#306">306</a> 		exceptionThrown = false;
+<a name="307" href="#307">307</a> 		<strong class="jxr_keyword">try</strong>
+<a name="308" href="#308">308</a> 		{
+<a name="309" href="#309">309</a> 			ObjectList list6 = fNavSvc.getCheckedOutDocs(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, IncludeRelationships.NONE, 
+<a name="310" href="#310">310</a> 					<strong class="jxr_keyword">null</strong>, MINUS_ONE, MINUS_ONE, <strong class="jxr_keyword">null</strong>);
+<a name="311" href="#311">311</a> 		}
+<a name="312" href="#312">312</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="313" href="#313">313</a> 		{
+<a name="314" href="#314">314</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="315" href="#315">315</a> 		}
+<a name="316" href="#316">316</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="317" href="#317">317</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="318" href="#318">318</a> 		
+<a name="319" href="#319">319</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="320" href="#320">320</a> 		ObjectList list6 = fNavSvc.getCheckedOutDocs(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, IncludeRelationships.NONE, 
+<a name="321" href="#321">321</a> 				<strong class="jxr_keyword">null</strong>, MINUS_ONE, MINUS_ONE, <strong class="jxr_keyword">null</strong>);
+<a name="322" href="#322">322</a> 	}
+<a name="323" href="#323">323</a> 	
+<a name="324" href="#324">324</a> 	@Test
+<a name="325" href="#325">325</a> 	<strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> testAclServiceGeneralAccess()
+<a name="326" href="#326">326</a> 	{
+<a name="327" href="#327">327</a> 	    List&lt;Ace&gt; initialACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(4);
+<a name="328" href="#328">328</a> 	    initialACEs.addAll(standardACEs);
+<a name="329" href="#329">329</a> 	    initialACEs.add(createAce(<span class="jxr_string">"Admin2"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="330" href="#330">330</a>         Acl initialAcl = fFactory.createAccessControlList(initialACEs);   
+<a name="331" href="#331">331</a>         
+<a name="332" href="#332">332</a>         List&lt;Ace&gt; expectedACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(5);
+<a name="333" href="#333">333</a>         expectedACEs.addAll(initialACEs);
+<a name="334" href="#334">334</a>         expectedACEs.addAll(testUserACEs);
+<a name="335" href="#335">335</a>         Acl expectedAcl = fFactory.createAccessControlList(expectedACEs);   
+<a name="336" href="#336">336</a>         
+<a name="337" href="#337">337</a> 	    List&lt;Ace&gt; removeACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="338" href="#338">338</a>         removeACEs.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="339" href="#339">339</a> 		Acl removeAcl = fFactory.createAccessControlList(removeACEs);
+<a name="340" href="#340">340</a> 		
+<a name="341" href="#341">341</a> 		List&lt;Ace&gt; removeACEs2 = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(2);
+<a name="342" href="#342">342</a> 		removeACEs2.add(createAce(<span class="jxr_string">"TestAdmin"</span>, EnumBasicPermissions.CMIS_ALL));
+<a name="343" href="#343">343</a> 		removeACEs2.add(createAce(<span class="jxr_string">"Reader"</span>, EnumBasicPermissions.CMIS_READ));
+<a name="344" href="#344">344</a> 		Acl removeAcl2 = fFactory.createAccessControlList(removeACEs2);
+<a name="345" href="#345">345</a> 		
+<a name="346" href="#346">346</a> 		List&lt;Ace&gt; testUserACEs = <strong class="jxr_keyword">new</strong> ArrayList&lt;Ace&gt;(1);
+<a name="347" href="#347">347</a> 		testUserACEs.add(createAce(<span class="jxr_string">"TestUser"</span>, EnumBasicPermissions.CMIS_WRITE));
+<a name="348" href="#348">348</a> 		Acl testUserAcl = fFactory.createAccessControlList(testUserACEs);
+<a name="349" href="#349">349</a> 		
+<a name="350" href="#350">350</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="351" href="#351">351</a> 		String docId = createDocumentWithAcls(<span class="jxr_string">"doc"</span>,  fRootFolderId, <span class="jxr_string">"ComplexType"</span>,
+<a name="352" href="#352">352</a> 		        initialAcl, defaultAcl);
+<a name="353" href="#353">353</a> 		String folderId = createFolderWithAcls(<span class="jxr_string">"folder"</span>, fRootFolderId, <span class="jxr_string">"cmis:folder"</span>, initialAcl, defaultAcl);
+<a name="354" href="#354">354</a> 		String subFolderId = createFolderWithAcls(<span class="jxr_string">"subFolder"</span>, folderId, <span class="jxr_string">"cmis:folder"</span>, initialAcl, defaultAcl);
+<a name="355" href="#355">355</a> 		
+<a name="356" href="#356">356</a> 		<em class="jxr_comment">// getAcl of a folder</em>
+<a name="357" href="#357">357</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="358" href="#358">358</a> 		<strong class="jxr_keyword">boolean</strong> exceptionThrown = false;
+<a name="359" href="#359">359</a> 		<strong class="jxr_keyword">try</strong>
+<a name="360" href="#360">360</a> 		{
+<a name="361" href="#361">361</a> 			Acl acl = fAclSvc.getAcl(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>); 
+<a name="362" href="#362">362</a> 		}
+<a name="363" href="#363">363</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="364" href="#364">364</a> 		{
+<a name="365" href="#365">365</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="366" href="#366">366</a> 		}
+<a name="367" href="#367">367</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="368" href="#368">368</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to get acl of folder"</span>);
+<a name="369" href="#369">369</a> 		
+<a name="370" href="#370">370</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="371" href="#371">371</a> 		Acl acl = fAclSvc.getAcl(fRepositoryId, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="372" href="#372">372</a> 		
+<a name="373" href="#373">373</a> 		<em class="jxr_comment">// getAcl of a document</em>
+<a name="374" href="#374">374</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="375" href="#375">375</a> 		exceptionThrown = false;
+<a name="376" href="#376">376</a> 		<strong class="jxr_keyword">try</strong>
+<a name="377" href="#377">377</a> 		{
+<a name="378" href="#378">378</a> 			Acl docAcl = fAclSvc.getAcl(fRepositoryId, docId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>); 
+<a name="379" href="#379">379</a> 		}
+<a name="380" href="#380">380</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="381" href="#381">381</a> 		{
+<a name="382" href="#382">382</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="383" href="#383">383</a> 		}
+<a name="384" href="#384">384</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="385" href="#385">385</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to get acl of doc)"</span>);
+<a name="386" href="#386">386</a> 		
+<a name="387" href="#387">387</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="388" href="#388">388</a> 		Acl docAcl = fAclSvc.getAcl(fRepositoryId, docId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="389" href="#389">389</a> 		
+<a name="390" href="#390">390</a> 		<em class="jxr_comment">// applyAcl</em>
+<a name="391" href="#391">391</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="392" href="#392">392</a> 		exceptionThrown = false;
+<a name="393" href="#393">393</a> 		<strong class="jxr_keyword">try</strong>
+<a name="394" href="#394">394</a> 		{
+<a name="395" href="#395">395</a> 			Acl docAcl2 = fAclSvc.applyAcl(fRepositoryId, docId, initialAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="396" href="#396">396</a> 		}
+<a name="397" href="#397">397</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="398" href="#398">398</a> 		{
+<a name="399" href="#399">399</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="400" href="#400">400</a> 		}
+<a name="401" href="#401">401</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="402" href="#402">402</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions)"</span>);
+<a name="403" href="#403">403</a> 		
+<a name="404" href="#404">404</a> <em class="jxr_comment">//		switchCallContext("Writer");</em>
+<a name="405" href="#405">405</a>         switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="406" href="#406">406</a> 		Acl docAcl2 = fAclSvc.applyAcl(fRepositoryId, docId, initialAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="407" href="#407">407</a> 		
+<a name="408" href="#408">408</a> 		<em class="jxr_comment">// applyAcl when not allowed to subItem</em>
+<a name="409" href="#409">409</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="410" href="#410">410</a> 		Acl docAcl4 = fAclSvc.applyAcl(fRepositoryId, subFolderId, <strong class="jxr_keyword">null</strong>, removeAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="411" href="#411">411</a> 		
+<a name="412" href="#412">412</a> <em class="jxr_comment">//        switchCallContext("Writer");</em>
+<a name="413" href="#413">413</a>         switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="414" href="#414">414</a>         <em class="jxr_comment">// apply an ACL where the current user has permission to modify ACL on folder but not on sub-folder:</em>
+<a name="415" href="#415">415</a> 		Acl docAcl5 = fAclSvc.applyAcl(fRepositoryId, folderId, testUserAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.PROPAGATE, <strong class="jxr_keyword">null</strong>);
+<a name="416" href="#416">416</a> 		switchCallContext(<span class="jxr_string">"Admin"</span>);
+<a name="417" href="#417">417</a> 		Acl docAcl6 = fAclSvc.getAcl(fRepositoryId, folderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="418" href="#418">418</a> 		assertTrue(aclEquals(expectedAcl, docAcl6)); 
+<a name="419" href="#419">419</a> 		Acl docAcl7 = fAclSvc.getAcl(fRepositoryId, subFolderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="420" href="#420">420</a> 		assertTrue(aclEquals(standardAcl, docAcl7)); 
+<a name="421" href="#421">421</a> 	}
+<a name="422" href="#422">422</a> 	
+<a name="423" href="#423">423</a> 	@Test
+<a name="424" href="#424">424</a> 	<strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> testObjectServiceGeneralAccess()
+<a name="425" href="#425">425</a> 	{
+<a name="426" href="#426">426</a> 			
+<a name="427" href="#427">427</a> 		<em class="jxr_comment">// starts with call context TestUser</em>
+<a name="428" href="#428">428</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="429" href="#429">429</a> 		String docId = createDocumentWithAcls(<span class="jxr_string">"doc"</span>,  fRootFolderId, <span class="jxr_string">"ComplexType"</span>,
+<a name="430" href="#430">430</a> 				standardAcl, defaultAcl);
+<a name="431" href="#431">431</a> 		String folderId = createFolderWithAcls(<span class="jxr_string">"folder"</span>, fRootFolderId, <span class="jxr_string">"cmis:folder"</span>, standardAcl, defaultAcl);
+<a name="432" href="#432">432</a> <em class="jxr_comment">//		fTestCallContext = new DummyCallContext("Writer");</em>
+<a name="433" href="#433">433</a> 		String subFolderId = createFolderWithAcls(<span class="jxr_string">"subFolder"</span>, folderId, <span class="jxr_string">"cmis:folder"</span>, standardAcl, <strong class="jxr_keyword">null</strong>);
+<a name="434" href="#434">434</a> 		String noReadFolderId = createFolderWithAcls(<span class="jxr_string">"noReadFolder"</span>, folderId, <span class="jxr_string">"cmis:folder"</span>, <strong class="jxr_keyword">null</strong>, readAcl);
+<a name="435" href="#435">435</a> 		String adminFolderId = createFolderWithAcls(<span class="jxr_string">"adminFolder"</span>, folderId, <span class="jxr_string">"cmis:folder"</span>, <strong class="jxr_keyword">null</strong>, readWriteAcl);
+<a name="436" href="#436">436</a> 		
+<a name="437" href="#437">437</a> 		<em class="jxr_comment">// TestUser has no permission at all</em>
+<a name="438" href="#438">438</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="439" href="#439">439</a> 		<strong class="jxr_keyword">boolean</strong> exceptionThrown = false;
+<a name="440" href="#440">440</a> 		<strong class="jxr_keyword">try</strong>
+<a name="441" href="#441">441</a> 		{
+<a name="442" href="#442">442</a> 			Properties properties = createDocumentProperties(<span class="jxr_string">"doc"</span>, <span class="jxr_string">"ComplexType"</span>);
+<a name="443" href="#443">443</a> 			String id = fObjSvc.createDocument(fRepositoryId, properties, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>,
+<a name="444" href="#444">444</a> 					<strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="445" href="#445">445</a> 		}
+<a name="446" href="#446">446</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="447" href="#447">447</a> 		{
+<a name="448" href="#448">448</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="449" href="#449">449</a> 		}
+<a name="450" href="#450">450</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="451" href="#451">451</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to create a document"</span>);
+<a name="452" href="#452">452</a> 		
+<a name="453" href="#453">453</a> 		exceptionThrown = false;
+<a name="454" href="#454">454</a> 		<strong class="jxr_keyword">try</strong>
+<a name="455" href="#455">455</a> 		{
+<a name="456" href="#456">456</a> 			String id = fObjSvc.createFolder(fRepositoryId, <strong class="jxr_keyword">null</strong>, folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="457" href="#457">457</a> 		}
+<a name="458" href="#458">458</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="459" href="#459">459</a> 		{
+<a name="460" href="#460">460</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="461" href="#461">461</a> 		}
+<a name="462" href="#462">462</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="463" href="#463">463</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to create a folder"</span>);
+<a name="464" href="#464">464</a> 		
+<a name="465" href="#465">465</a> 		<em class="jxr_comment">/*</em>
+<a name="466" href="#466">466</a> <em class="jxr_comment">		exceptionThrown = false;</em>
+<a name="467" href="#467">467</a> <em class="jxr_comment">		try</em>
+<a name="468" href="#468">468</a> <em class="jxr_comment">		{</em>
+<a name="469" href="#469">469</a> <em class="jxr_comment">			Properties properties = createRelationshipProperties(folderId, fRootFolderId);</em>
+<a name="470" href="#470">470</a> <em class="jxr_comment">			String id1 = fObjSvc.createRelationship(fRepositoryId, properties, null, null, null, null);</em>
+<a name="471" href="#471">471</a> <em class="jxr_comment">		}</em>
+<a name="472" href="#472">472</a> <em class="jxr_comment">		catch (CmisPermissionDeniedException e)</em>
+<a name="473" href="#473">473</a> <em class="jxr_comment">		{</em>
+<a name="474" href="#474">474</a> <em class="jxr_comment">			exceptionThrown = true;</em>
+<a name="475" href="#475">475</a> <em class="jxr_comment">		}</em>
+<a name="476" href="#476">476</a> <em class="jxr_comment">		if (!exceptionThrown)</em>
+<a name="477" href="#477">477</a> <em class="jxr_comment">			Assert.fail("TestUser has no permissions to create a relationship: missing read permission for source id");</em>
+<a name="478" href="#478">478</a> <em class="jxr_comment">		</em>
+<a name="479" href="#479">479</a> <em class="jxr_comment">		exceptionThrown = false;</em>
+<a name="480" href="#480">480</a> <em class="jxr_comment">		Properties properties = createRelationshipProperties( fRootFolderId, folderId);</em>
+<a name="481" href="#481">481</a> <em class="jxr_comment">		try</em>
+<a name="482" href="#482">482</a> <em class="jxr_comment">		{</em>
+<a name="483" href="#483">483</a> <em class="jxr_comment">			String id2 = fObjSvc.createRelationship(fRepositoryId, properties, null, null, null, null);</em>
+<a name="484" href="#484">484</a> <em class="jxr_comment">		}</em>
+<a name="485" href="#485">485</a> <em class="jxr_comment">		catch (CmisPermissionDeniedException e)</em>
+<a name="486" href="#486">486</a> <em class="jxr_comment">		{</em>
+<a name="487" href="#487">487</a> <em class="jxr_comment">			exceptionThrown = true;</em>
+<a name="488" href="#488">488</a> <em class="jxr_comment">		}</em>
+<a name="489" href="#489">489</a> <em class="jxr_comment">		if (!exceptionThrown)</em>
+<a name="490" href="#490">490</a> <em class="jxr_comment">			Assert.fail("TestUser has no permissions to create a relationship: missing read permission for destination");</em>
+<a name="491" href="#491">491</a> <em class="jxr_comment">		*/</em>
+<a name="492" href="#492">492</a> 		
+<a name="493" href="#493">493</a> 		exceptionThrown = false;
+<a name="494" href="#494">494</a> 		<strong class="jxr_keyword">try</strong>
+<a name="495" href="#495">495</a> 		{
+<a name="496" href="#496">496</a> 			Properties props = fObjSvc.getProperties(fRepositoryId,  folderId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="497" href="#497">497</a> 		}
+<a name="498" href="#498">498</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="499" href="#499">499</a> 		{
+<a name="500" href="#500">500</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="501" href="#501">501</a> 		}
+<a name="502" href="#502">502</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="503" href="#503">503</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to get properties of the folder"</span>);
+<a name="504" href="#504">504</a> 		
+<a name="505" href="#505">505</a> 		exceptionThrown = false;
+<a name="506" href="#506">506</a> 		<strong class="jxr_keyword">try</strong>
+<a name="507" href="#507">507</a> 		{
+<a name="508" href="#508">508</a> 			Properties props = fObjSvc.getProperties(fRepositoryId,  docId, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="509" href="#509">509</a> 		}
+<a name="510" href="#510">510</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="511" href="#511">511</a> 		{
+<a name="512" href="#512">512</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="513" href="#513">513</a> 		}
+<a name="514" href="#514">514</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="515" href="#515">515</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to get properties of the document"</span>);
+<a name="516" href="#516">516</a> 		
+<a name="517" href="#517">517</a> 		exceptionThrown = false;
+<a name="518" href="#518">518</a> 		<strong class="jxr_keyword">try</strong>
+<a name="519" href="#519">519</a> 		{
+<a name="520" href="#520">520</a> 			List&lt;RenditionData&gt; renditions = fObjSvc.getRenditions(fRepositoryId,  docId, <strong class="jxr_keyword">null</strong>, BigInteger.valueOf(-1),
+<a name="521" href="#521">521</a> 					BigInteger.valueOf(-1), <strong class="jxr_keyword">null</strong>);
+<a name="522" href="#522">522</a> 		}
+<a name="523" href="#523">523</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="524" href="#524">524</a> 		{
+<a name="525" href="#525">525</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="526" href="#526">526</a> 		}
+<a name="527" href="#527">527</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="528" href="#528">528</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to get renditions of the document"</span>);
+<a name="529" href="#529">529</a> 		
+<a name="530" href="#530">530</a> 		exceptionThrown = false;
+<a name="531" href="#531">531</a> 		<strong class="jxr_keyword">try</strong>
+<a name="532" href="#532">532</a> 		{
+<a name="533" href="#533">533</a> 			ContentStream contentStream =  fObjSvc.getContentStream(fRepositoryId,  docId, <strong class="jxr_keyword">null</strong>, BigInteger.valueOf(-1),
+<a name="534" href="#534">534</a> 					BigInteger.valueOf(-1), <strong class="jxr_keyword">null</strong>);
+<a name="535" href="#535">535</a> 		}
+<a name="536" href="#536">536</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="537" href="#537">537</a> 		{
+<a name="538" href="#538">538</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="539" href="#539">539</a> 		}
+<a name="540" href="#540">540</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="541" href="#541">541</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions to get contentStream of the document"</span>);
+<a name="542" href="#542">542</a> 		
+<a name="543" href="#543">543</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="544" href="#544">544</a> 		exceptionThrown = false;
+<a name="545" href="#545">545</a> 		Properties properties = createDocumentProperties( <span class="jxr_string">"name"</span>, <span class="jxr_string">"typeId"</span>);
+<a name="546" href="#546">546</a> 		<strong class="jxr_keyword">try</strong>
+<a name="547" href="#547">547</a> 		{	
+<a name="548" href="#548">548</a> 			fObjSvc.updateProperties(fRepositoryId,
+<a name="549" href="#549">549</a> 					<strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(<span class="jxr_string">"changeToken"</span>), properties, <strong class="jxr_keyword">null</strong>);
+<a name="550" href="#550">550</a> 		}
+<a name="551" href="#551">551</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="552" href="#552">552</a> 		{
+<a name="553" href="#553">553</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="554" href="#554">554</a> 		}
+<a name="555" href="#555">555</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="556" href="#556">556</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to update properties of the document"</span>);
+<a name="557" href="#557">557</a> 		
+<a name="558" href="#558">558</a> 		exceptionThrown = false;
+<a name="559" href="#559">559</a> 		properties = createDocumentProperties( <span class="jxr_string">"name"</span>, <span class="jxr_string">"typeId"</span>);
+<a name="560" href="#560">560</a> 		<strong class="jxr_keyword">try</strong>
+<a name="561" href="#561">561</a> 		{	
+<a name="562" href="#562">562</a> 			fObjSvc.updateProperties(fRepositoryId,
+<a name="563" href="#563">563</a> 					<strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(<span class="jxr_string">"changeToken"</span>), properties, <strong class="jxr_keyword">null</strong>);
+<a name="564" href="#564">564</a> 		}
+<a name="565" href="#565">565</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="566" href="#566">566</a> 		{
+<a name="567" href="#567">567</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="568" href="#568">568</a> 		}
+<a name="569" href="#569">569</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="570" href="#570">570</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to update properties of the document"</span>);
+<a name="571" href="#571">571</a> 		
+<a name="572" href="#572">572</a> 		exceptionThrown = false;
+<a name="573" href="#573">573</a> 		<strong class="jxr_keyword">try</strong>
+<a name="574" href="#574">574</a> 		{	
+<a name="575" href="#575">575</a> 			fObjSvc.moveObject(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), subFolderId,
+<a name="576" href="#576">576</a> 					fRootFolderId, <strong class="jxr_keyword">null</strong>);
+<a name="577" href="#577">577</a> 		}
+<a name="578" href="#578">578</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="579" href="#579">579</a> 		{
+<a name="580" href="#580">580</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="581" href="#581">581</a> 		}
+<a name="582" href="#582">582</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="583" href="#583">583</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to move document"</span>);
+<a name="584" href="#584">584</a> 		
+<a name="585" href="#585">585</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);
+<a name="586" href="#586">586</a> 		exceptionThrown = false;
+<a name="587" href="#587">587</a> 		<strong class="jxr_keyword">try</strong>
+<a name="588" href="#588">588</a> 		{	
+<a name="589" href="#589">589</a> 			fObjSvc.moveObject(fRepositoryId,<strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), adminFolderId,
+<a name="590" href="#590">590</a> 					fRootFolderId, <strong class="jxr_keyword">null</strong>);
+<a name="591" href="#591">591</a> 		}
+<a name="592" href="#592">592</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="593" href="#593">593</a> 		{
+<a name="594" href="#594">594</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="595" href="#595">595</a> 		}
+<a name="596" href="#596">596</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="597" href="#597">597</a> 			Assert.fail(<span class="jxr_string">"Writer has no permissions to move document to admin folder"</span>);
+<a name="598" href="#598">598</a> 		
+<a name="599" href="#599">599</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="600" href="#600">600</a> 		exceptionThrown = false;
+<a name="601" href="#601">601</a> 		<strong class="jxr_keyword">try</strong>
+<a name="602" href="#602">602</a> 		{	
+<a name="603" href="#603">603</a> 			fObjSvc.deleteObject(fRepositoryId, docId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="604" href="#604">604</a> 		}
+<a name="605" href="#605">605</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="606" href="#606">606</a> 		{
+<a name="607" href="#607">607</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="608" href="#608">608</a> 		}
+<a name="609" href="#609">609</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="610" href="#610">610</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to delete document "</span>);
+<a name="611" href="#611">611</a> 		
+<a name="612" href="#612">612</a> 		exceptionThrown = false;
+<a name="613" href="#613">613</a> 		<strong class="jxr_keyword">try</strong>
+<a name="614" href="#614">614</a> 		{	
+<a name="615" href="#615">615</a> 			fObjSvc.deleteObject(fRepositoryId, adminFolderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="616" href="#616">616</a> 		}
+<a name="617" href="#617">617</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="618" href="#618">618</a> 		{
+<a name="619" href="#619">619</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="620" href="#620">620</a> 		}
+<a name="621" href="#621">621</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="622" href="#622">622</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to delete admin folder "</span>);
+<a name="623" href="#623">623</a> 		
+<a name="624" href="#624">624</a> 		exceptionThrown = false;
+<a name="625" href="#625">625</a> 		<strong class="jxr_keyword">try</strong>
+<a name="626" href="#626">626</a> 		{	
+<a name="627" href="#627">627</a> 			fObjSvc.setContentStream(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt; (docId), <strong class="jxr_keyword">true</strong>,
+<a name="628" href="#628">628</a> 					<strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(<span class="jxr_string">"changeToken"</span>), <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="629" href="#629">629</a> 		}
+<a name="630" href="#630">630</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="631" href="#631">631</a> 		{
+<a name="632" href="#632">632</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="633" href="#633">633</a> 		}
+<a name="634" href="#634">634</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="635" href="#635">635</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to set content "</span>);
+<a name="636" href="#636">636</a> 		
+<a name="637" href="#637">637</a> 		exceptionThrown = false;
+<a name="638" href="#638">638</a> 		<strong class="jxr_keyword">try</strong>
+<a name="639" href="#639">639</a> 		{	
+<a name="640" href="#640">640</a> 			fObjSvc.deleteContentStream(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt; (docId), 
+<a name="641" href="#641">641</a> 					<strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(<span class="jxr_string">"changeToken"</span>), <strong class="jxr_keyword">null</strong>);
+<a name="642" href="#642">642</a> 		}
+<a name="643" href="#643">643</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="644" href="#644">644</a> 		{
+<a name="645" href="#645">645</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="646" href="#646">646</a> 		}
+<a name="647" href="#647">647</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="648" href="#648">648</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to delete content "</span>);
+<a name="649" href="#649">649</a> 		
+<a name="650" href="#650">650</a> 		exceptionThrown = false;
+<a name="651" href="#651">651</a> 		<strong class="jxr_keyword">try</strong>
+<a name="652" href="#652">652</a> 		{	
+<a name="653" href="#653">653</a> 			fObjSvc.deleteTree(fRepositoryId, folderId, <strong class="jxr_keyword">true</strong>,
+<a name="654" href="#654">654</a> 					 <strong class="jxr_keyword">null</strong>, false, <strong class="jxr_keyword">null</strong>);
+<a name="655" href="#655">655</a> 		}
+<a name="656" href="#656">656</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="657" href="#657">657</a> 		{
+<a name="658" href="#658">658</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="659" href="#659">659</a> 		}
+<a name="660" href="#660">660</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="661" href="#661">661</a> 			Assert.fail(<span class="jxr_string">"Reader has no permissions to delete tree "</span>);
+<a name="662" href="#662">662</a> 	}
+<a name="663" href="#663">663</a> 	
+<a name="664" href="#664">664</a> 	@Test
+<a name="665" href="#665">665</a> 	<strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> testMultiFilingServiceGeneralAccess()
+<a name="666" href="#666">666</a> 	{
+<a name="667" href="#667">667</a> 		<em class="jxr_comment">// starts with call context TestUser</em>
+<a name="668" href="#668">668</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="669" href="#669">669</a> 		String docId = createDocumentWithAcls(<span class="jxr_string">"doc"</span>,  fRootFolderId, <span class="jxr_string">"ComplexType"</span>,
+<a name="670" href="#670">670</a> 				standardAcl, defaultAcl);
+<a name="671" href="#671">671</a> 		String folderId = createFolderWithAcls(<span class="jxr_string">"folder"</span>, fRootFolderId, <span class="jxr_string">"cmis:folder"</span>, 
+<a name="672" href="#672">672</a> 				addAcl, defaultAcl);
+<a name="673" href="#673">673</a> 		String noReadFolderId = createFolderWithAcls(<span class="jxr_string">"noReadFolder"</span>, folderId, <span class="jxr_string">"cmis:folder"</span>, 
+<a name="674" href="#674">674</a> 				<strong class="jxr_keyword">null</strong>, readAcl);
+<a name="675" href="#675">675</a> 		
+<a name="676" href="#676">676</a> 		<em class="jxr_comment">// TestUser has no permission at the document</em>
+<a name="677" href="#677">677</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="678" href="#678">678</a> 		<strong class="jxr_keyword">boolean</strong> exceptionThrown = false;
+<a name="679" href="#679">679</a> 		<strong class="jxr_keyword">try</strong>
+<a name="680" href="#680">680</a> 		{
+<a name="681" href="#681">681</a> 			
+<a name="682" href="#682">682</a> 			fMultiSvc.addObjectToFolder(fRepositoryId, docId, folderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="683" href="#683">683</a> 		}
+<a name="684" href="#684">684</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="685" href="#685">685</a> 		{
+<a name="686" href="#686">686</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="687" href="#687">687</a> 		}
+<a name="688" href="#688">688</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="689" href="#689">689</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permissions at the document to add a parent"</span>);
+<a name="690" href="#690">690</a> 		
+<a name="691" href="#691">691</a> 		exceptionThrown = false;
+<a name="692" href="#692">692</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);  <em class="jxr_comment">// has no permission at the folder</em>
+<a name="693" href="#693">693</a> 		<strong class="jxr_keyword">try</strong>
+<a name="694" href="#694">694</a> 		{
+<a name="695" href="#695">695</a> 			
+<a name="696" href="#696">696</a> 			fMultiSvc.addObjectToFolder(fRepositoryId, docId, noReadFolderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="697" href="#697">697</a> 		}
+<a name="698" href="#698">698</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="699" href="#699">699</a> 		{
+<a name="700" href="#700">700</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="701" href="#701">701</a> 		}
+<a name="702" href="#702">702</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="703" href="#703">703</a> 			Assert.fail(<span class="jxr_string">"Reader has no permission at the folder to add a parent"</span>);
+<a name="704" href="#704">704</a> 		
+<a name="705" href="#705">705</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="706" href="#706">706</a> 		fMultiSvc.addObjectToFolder(fRepositoryId, docId, noReadFolderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="707" href="#707">707</a> 		fMultiSvc.addObjectToFolder(fRepositoryId, docId, folderId, <strong class="jxr_keyword">true</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="708" href="#708">708</a> 		
+<a name="709" href="#709">709</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);  
+<a name="710" href="#710">710</a> 		<strong class="jxr_keyword">try</strong>
+<a name="711" href="#711">711</a> 		{
+<a name="712" href="#712">712</a> 			
+<a name="713" href="#713">713</a> 			fMultiSvc.removeObjectFromFolder(fRepositoryId, docId, noReadFolderId, <strong class="jxr_keyword">null</strong>);
+<a name="714" href="#714">714</a> 		}
+<a name="715" href="#715">715</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="716" href="#716">716</a> 		{
+<a name="717" href="#717">717</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="718" href="#718">718</a> 		}
+<a name="719" href="#719">719</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="720" href="#720">720</a> 			Assert.fail(<span class="jxr_string">"Reader has no permission at the folder to remove a parent"</span>);
+<a name="721" href="#721">721</a> 		
+<a name="722" href="#722">722</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>); 
+<a name="723" href="#723">723</a> 		<strong class="jxr_keyword">try</strong>
+<a name="724" href="#724">724</a> 		{
+<a name="725" href="#725">725</a> 			
+<a name="726" href="#726">726</a> 			fMultiSvc.removeObjectFromFolder(fRepositoryId, docId, folderId, <strong class="jxr_keyword">null</strong>);
+<a name="727" href="#727">727</a> 		}
+<a name="728" href="#728">728</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="729" href="#729">729</a> 		{
+<a name="730" href="#730">730</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="731" href="#731">731</a> 		}
+<a name="732" href="#732">732</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="733" href="#733">733</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permission at the object to remove a parent"</span>);
+<a name="734" href="#734">734</a> 	}
+<a name="735" href="#735">735</a> 	
+<a name="736" href="#736">736</a> 	@Test
+<a name="737" href="#737">737</a> 	<strong class="jxr_keyword">public</strong> <strong class="jxr_keyword">void</strong> testVersioningServiceGeneralAccess()
+<a name="738" href="#738">738</a> 	{
+<a name="739" href="#739">739</a> 		<em class="jxr_comment">// starts with call context TestUser</em>
+<a name="740" href="#740">740</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="741" href="#741">741</a> 		String docId = createDocumentWithAcls(<span class="jxr_string">"doc"</span>,  fRootFolderId, UnitTestTypeSystemCreator.VERSIONED_TYPE,
+<a name="742" href="#742">742</a> 		        VersioningState.MAJOR, standardAcl, defaultAcl);
+<a name="743" href="#743">743</a> 	
+<a name="744" href="#744">744</a> 		<em class="jxr_comment">// TestUser has no permission at all</em>
+<a name="745" href="#745">745</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="746" href="#746">746</a> 		<strong class="jxr_keyword">boolean</strong> exceptionThrown = false;
+<a name="747" href="#747">747</a> 		<strong class="jxr_keyword">try</strong>
+<a name="748" href="#748">748</a> 		{
+<a name="749" href="#749">749</a> 			Holder&lt;String&gt; docIdHolder = <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId);
+<a name="750" href="#750">750</a> 			fVerSvc.checkOut(fRepositoryId, docIdHolder, <strong class="jxr_keyword">null</strong>, 
+<a name="751" href="#751">751</a> 					<strong class="jxr_keyword">new</strong> Holder&lt;Boolean&gt;(false));
+<a name="752" href="#752">752</a> 		}
+<a name="753" href="#753">753</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="754" href="#754">754</a> 		{
+<a name="755" href="#755">755</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="756" href="#756">756</a> 		}
+<a name="757" href="#757">757</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="758" href="#758">758</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permission to checkout)"</span>);
+<a name="759" href="#759">759</a> 		
+<a name="760" href="#760">760</a> 		<em class="jxr_comment">// Reader has only read permission</em>
+<a name="761" href="#761">761</a> 		switchCallContext(<span class="jxr_string">"Reader"</span>);
+<a name="762" href="#762">762</a> 		exceptionThrown = false;
+<a name="763" href="#763">763</a> 		<strong class="jxr_keyword">try</strong>
+<a name="764" href="#764">764</a> 		{
+<a name="765" href="#765">765</a> 			fVerSvc.checkOut(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">null</strong>, 
+<a name="766" href="#766">766</a> 					<strong class="jxr_keyword">new</strong> Holder&lt;Boolean&gt;(false));
+<a name="767" href="#767">767</a> 		}
+<a name="768" href="#768">768</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="769" href="#769">769</a> 		{
+<a name="770" href="#770">770</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="771" href="#771">771</a> 		}
+<a name="772" href="#772">772</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="773" href="#773">773</a> 			Assert.fail(<span class="jxr_string">"Reader has not enough permission to checkout)"</span>);
+<a name="774" href="#774">774</a> 		
+<a name="775" href="#775">775</a> 		<em class="jxr_comment">// checkout</em>
+<a name="776" href="#776">776</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="777" href="#777">777</a> 		fAclSvc.applyAcl(fRepositoryId, docId, testUserAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="778" href="#778">778</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="779" href="#779">779</a> 		Holder&lt;String&gt; docIdHolder = <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId);
+<a name="780" href="#780">780</a> 		fVerSvc.checkOut(fRepositoryId, docIdHolder, <strong class="jxr_keyword">null</strong>, 
+<a name="781" href="#781">781</a> 				<strong class="jxr_keyword">new</strong> Holder&lt;Boolean&gt;(false));
+<a name="782" href="#782">782</a> 	
+<a name="783" href="#783">783</a>         switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="784" href="#784">784</a> 		fAclSvc.applyAcl(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>, testUserAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="785" href="#785">785</a> 		
+<a name="786" href="#786">786</a> 		<em class="jxr_comment">// TestUser has no permission at all, only checkout user can checkin</em>
+<a name="787" href="#787">787</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="788" href="#788">788</a> 		exceptionThrown = false;
+<a name="789" href="#789">789</a> 		<strong class="jxr_keyword">try</strong>
+<a name="790" href="#790">790</a> 		{
+<a name="791" href="#791">791</a> 			fVerSvc.cancelCheckOut(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>);
+<a name="792" href="#792">792</a> 		}
+<a name="793" href="#793">793</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="794" href="#794">794</a> 		{
+<a name="795" href="#795">795</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="796" href="#796">796</a> 		}
+<a name="797" href="#797">797</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="798" href="#798">798</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permission to cancelCheckOut)"</span>);
+<a name="799" href="#799">799</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="800" href="#800">800</a> 		fAclSvc.applyAcl(fRepositoryId, docId, testUserAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="801" href="#801">801</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="802" href="#802">802</a> 		fVerSvc.cancelCheckOut(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>);
+<a name="803" href="#803">803</a> 		
+<a name="804" href="#804">804</a> 		<em class="jxr_comment">// writer looses write permission</em>
+<a name="805" href="#805">805</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);
+<a name="806" href="#806">806</a> 		fVerSvc.checkOut(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">null</strong>, 
+<a name="807" href="#807">807</a> 				<strong class="jxr_keyword">new</strong> Holder&lt;Boolean&gt;(false));
+<a name="808" href="#808">808</a> 
+<a name="809" href="#809">809</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="810" href="#810">810</a> 		fAclSvc.applyAcl(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>, readWriteAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="811" href="#811">811</a> 	
+<a name="812" href="#812">812</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);
+<a name="813" href="#813">813</a>         exceptionThrown = false;
+<a name="814" href="#814">814</a> 		<strong class="jxr_keyword">try</strong>
+<a name="815" href="#815">815</a> 		{
+<a name="816" href="#816">816</a> 			fVerSvc.cancelCheckOut(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>);
+<a name="817" href="#817">817</a> 		}
+<a name="818" href="#818">818</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="819" href="#819">819</a> 		{
+<a name="820" href="#820">820</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="821" href="#821">821</a> 		}
+<a name="822" href="#822">822</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="823" href="#823">823</a> 			Assert.fail(<span class="jxr_string">"Reader has not enough permission to cancelCheckOut)"</span>);
+<a name="824" href="#824">824</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="825" href="#825">825</a> 		fAclSvc.applyAcl(fRepositoryId, docId, readWriteAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="826" href="#826">826</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);
+<a name="827" href="#827">827</a> 		fVerSvc.cancelCheckOut(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>);
+<a name="828" href="#828">828</a> 				
+<a name="829" href="#829">829</a> 		<em class="jxr_comment">// TestUser has no permission at all</em>
+<a name="830" href="#830">830</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="831" href="#831">831</a> 		fAclSvc.applyAcl(fRepositoryId, docId, testUserAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="832" href="#832">832</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="833" href="#833">833</a> 		fVerSvc.checkOut(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">null</strong>, 
+<a name="834" href="#834">834</a> 				<strong class="jxr_keyword">new</strong> Holder&lt;Boolean&gt;(false));
+<a name="835" href="#835">835</a> 
+<a name="836" href="#836">836</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="837" href="#837">837</a> 		fAclSvc.applyAcl(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>, testUserAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="838" href="#838">838</a> 	
+<a name="839" href="#839">839</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="840" href="#840">840</a> 		exceptionThrown = false;
+<a name="841" href="#841">841</a> 		<strong class="jxr_keyword">try</strong>
+<a name="842" href="#842">842</a> 		{
+<a name="843" href="#843">843</a> 			fVerSvc.checkIn(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">true</strong>,  <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>,
+<a name="844" href="#844">844</a> 					<strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="845" href="#845">845</a> 		}
+<a name="846" href="#846">846</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="847" href="#847">847</a> 		{
+<a name="848" href="#848">848</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="849" href="#849">849</a> 		}
+<a name="850" href="#850">850</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="851" href="#851">851</a> 			Assert.fail(<span class="jxr_string">"TestUser has no permission to checkIn)"</span>);
+<a name="852" href="#852">852</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="853" href="#853">853</a> 		fAclSvc.applyAcl(fRepositoryId, docId, testUserAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="854" href="#854">854</a> 		switchCallContext(<span class="jxr_string">"TestUser"</span>);
+<a name="855" href="#855">855</a> 		fVerSvc.checkIn(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">true</strong>,  <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>,
+<a name="856" href="#856">856</a> 				<strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="857" href="#857">857</a> 
+<a name="858" href="#858">858</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="859" href="#859">859</a> 		fAclSvc.applyAcl(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>, testUserAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="860" href="#860">860</a> 		
+<a name="861" href="#861">861</a> 		<em class="jxr_comment">// writer looses write permission</em>
+<a name="862" href="#862">862</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);
+<a name="863" href="#863">863</a> 		fVerSvc.checkOut(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">null</strong>, 
+<a name="864" href="#864">864</a> 				<strong class="jxr_keyword">new</strong> Holder&lt;Boolean&gt;(false));
+<a name="865" href="#865">865</a>         
+<a name="866" href="#866">866</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="867" href="#867">867</a> 		fAclSvc.applyAcl(fRepositoryId, docId, <strong class="jxr_keyword">null</strong>, readWriteAcl, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="868" href="#868">868</a> 
+<a name="869" href="#869">869</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);	
+<a name="870" href="#870">870</a> 		exceptionThrown = false;
+<a name="871" href="#871">871</a> 		<strong class="jxr_keyword">try</strong>
+<a name="872" href="#872">872</a> 		{
+<a name="873" href="#873">873</a> 			fVerSvc.checkIn(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">true</strong>,  <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>,
+<a name="874" href="#874">874</a> 					<strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>);
+<a name="875" href="#875">875</a> 		}
+<a name="876" href="#876">876</a> 		<strong class="jxr_keyword">catch</strong> (CmisPermissionDeniedException e)
+<a name="877" href="#877">877</a> 		{
+<a name="878" href="#878">878</a> 			exceptionThrown = <strong class="jxr_keyword">true</strong>;
+<a name="879" href="#879">879</a> 		}
+<a name="880" href="#880">880</a> 		<strong class="jxr_keyword">if</strong> (!exceptionThrown)
+<a name="881" href="#881">881</a> 			Assert.fail(<span class="jxr_string">"Writer has not enough permission to checkIn)"</span>);
+<a name="882" href="#882">882</a> 		switchCallContext(<span class="jxr_string">"TestAdmin"</span>);
+<a name="883" href="#883">883</a> 		fAclSvc.applyAcl(fRepositoryId, docId, readWriteAcl, <strong class="jxr_keyword">null</strong>, AclPropagation.OBJECTONLY, <strong class="jxr_keyword">null</strong>);
+<a name="884" href="#884">884</a> 		switchCallContext(<span class="jxr_string">"Writer"</span>);
+<a name="885" href="#885">885</a> 		fVerSvc.checkIn(fRepositoryId, <strong class="jxr_keyword">new</strong> Holder&lt;String&gt;(docId), <strong class="jxr_keyword">true</strong>,  <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>, <strong class="jxr_keyword">null</strong>,

[... 390 lines stripped ...]