Skip to content

Allow Dataset Creation API to take Template ID - #12405

Open
stevenwinship wants to merge 3 commits into
developfrom
12132-dataset-creation-with-template
Open

Allow Dataset Creation API to take Template ID#12405
stevenwinship wants to merge 3 commits into
developfrom
12132-dataset-creation-with-template

Conversation

@stevenwinship

Copy link
Copy Markdown
Contributor

What this PR does / why we need it: Users creating Datasets need to be able to set the Template via the Create API

Which issue(s) this PR closes:#12132

Special notes for your reviewer:

Suggestions on how to test this:

Does this PR introduce a user interface change? If mockups are available, please link/include them here:

Is there a release notes update needed for this change?:

Additional documentation:

@stevenwinship stevenwinship self-assigned this May 22, 2026
@github-actions github-actions Bot added FY26 Sprint 22 FY26 Sprint 22 (2026-04-22 - 2026-05-06) FY26 Sprint 23 FY26 Sprint 23 (2026-05-06 - 2026-05-20) FY26 Sprint 24 FY26 Sprint 24 (2026-05-20 - 2026-06-03) GREI Re-arch Issues related to the GREI Dataverse rearchitecture Size: 10 A percentage of a sprint. 7 hours. SPA These changes are required for the Dataverse SPA SPA.Q4.2025.1 Create/Edit Template Feature Status: Needs Input Applied to issues in need of input from someone currently unavailable Type: Feature a feature request labels May 22, 2026
@stevenwinship stevenwinship moved this to In Progress 💻 in IQSS Dataverse Project May 22, 2026
@coveralls

coveralls commented May 22, 2026

Copy link
Copy Markdown

Coverage Status

Coverage is 24.975%12132-dataset-creation-with-template into develop. No base build found for develop.

@github-actions

This comment has been minimized.

1 similar comment
@github-actions

This comment has been minimized.

@stevenwinship stevenwinship moved this from In Progress 💻 to Ready for Review ⏩ in IQSS Dataverse Project May 26, 2026
@stevenwinship stevenwinship removed their assignment May 26, 2026
@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch 2 times, most recently from 5b23c8f to ce7a795 Compare May 26, 2026 18:17
@github-actions

This comment has been minimized.

1 similar comment
@github-actions

This comment has been minimized.

@github-actions

github-actions Bot commented May 26, 2026

Copy link
Copy Markdown

Test Results

403 tests  ±0   388 ✅ ±0   33m 10s ⏱️ -43s
 55 suites ±0    15 💤 ±0 
 55 files   ±0     0 ❌ ±0 

Results for commit 48a1ed8. ± Comparison against base commit 72a5ad2.

♻️ This comment has been updated with latest results.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from ce7a795 to e8f7f1f Compare May 26, 2026 21:13
@github-actions

This comment has been minimized.

@ekraffmiller

Copy link
Copy Markdown
Contributor

@stevenwinship to support the SPA, we also need the Get Dataset API to return the template_id, can you add that to this PR? Or would it be better to have a separate issue?

@ekraffmiller

Copy link
Copy Markdown
Contributor

@stevenwinship to support the SPA, we also need the Get Dataset API to return the template_id, can you add that to this PR? Or would it be better to have a separate issue?

Update from Steve, this is already in the current PR. thanks!

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from e8f7f1f to 665d78c Compare May 29, 2026 15:50
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from 665d78c to 99a1d0e Compare June 1, 2026 13:03
@github-actions

This comment has been minimized.

@cmbz cmbz added the FY26 Sprint 26 FY26 Sprint 26 (2026-06-17 - 2026-07-01) label Jun 18, 2026
@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from 57b5e40 to 409d37d Compare June 22, 2026 17:42
@github-actions

This comment has been minimized.

@ekraffmiller ekraffmiller removed the Status: Needs Input Applied to issues in need of input from someone currently unavailable label Jun 26, 2026
@cmbz cmbz added the FY27 Sprint 1 FY27 Sprint 1 (2026-07-01 - 2026-07-15) label Jul 1, 2026
@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from 409d37d to 02485c3 Compare July 2, 2026 13:15
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from 02485c3 to ca86a75 Compare July 2, 2026 20:47
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from ca86a75 to 5d521c1 Compare July 13, 2026 14:24
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from 5d521c1 to d1c2b58 Compare July 13, 2026 18:13
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from d1c2b58 to b3a5be4 Compare July 13, 2026 19:55
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from b3a5be4 to ec3d937 Compare July 14, 2026 13:08
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from ec3d937 to c0812ca Compare July 15, 2026 13:06
@github-actions

This comment has been minimized.

@cmbz cmbz added the FY27 Sprint 2 FY27 Sprint 2 (2026-07-15 - 2026-07-29) label Jul 15, 2026
@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from c0812ca to 0c2bdbc Compare July 20, 2026 13:05
@github-actions

This comment has been minimized.

@stevenwinship
stevenwinship force-pushed the 12132-dataset-creation-with-template branch from 0c2bdbc to 48a1ed8 Compare July 22, 2026 15:35
@github-actions

Copy link
Copy Markdown

📦 Pushed preview images as

ghcr.io/gdcc/dataverse:12132-dataset-creation-with-template
ghcr.io/gdcc/configbaker:12132-dataset-creation-with-template

🚢 See on GHCR. Use by referencing with full name as printed above, mind the registry name.

@rtreacy rtreacy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude
PR #12405 Review: Allow Dataset Creation API to take Template ID

What it does

Adds support for "templateId": $templateId in the POST /dataverses/{identifier}/datasets JSON payload. JsonParser.parseDataset() now looks up the template and calls dataset.setTemplate(template); JsonPrinter echoes templateId back in dataset JSON; and CreateNewDatasetCommand's existing (Dataset, DataverseRequest, Template, boolean) constructor is tweaked to fall back to theDataset.getTemplate() when no Template object is passed explicitly — which is how the value set by the JSON parser reaches the command that bumps the template's usage count. JsonParser's constructor gained a TemplateServiceBean dependency, which required updating every call site (production and test) — hence the size of the diff.

Correctness issues

  1. Missing dataverse scoping on the template lookup (authorization gap). templateService.find(templateId) (JsonParser.java:292) looks up any template in the system by ID, with no check that it belongs to the target dataverse (owner) or one of its ancestors. Contrast with the UI flow (DatasetPage.java:2247), which only offers templates from dataverseService.find(ownerId).getTemplates(). Via this API, a user with AddDataset permission on dataverse A can supply the numeric ID of a template that lives in an unrelated, possibly private/restricted dataverse B, and:
  • dataset.setTemplate(template) persists that cross-dataverse association and is echoed back as templateId in the dataset JSON.

  • CreateNewDatasetCommand.postPersist calls ctxt.templates().incrementUsageCount(template.getId()) unconditionally on that foreign template.

    The practical impact is limited — in this API flow getVersionToPersist() still calls the no-arg theDataset.getOrCreateEditVersion(), so the template's field defaults are never applied to the new dataset (unlike the UI path); the effect is essentially an ID-based association plus a usage-count bump on a template the caller may have no visibility into. Still, it's a real scoping gap versus the UI's behavior and worth validating (template.getDataverse() is an ancestor of owner, or reject with 400) before merging.

  1. Non-existent templateId fails silently. templateService.find() returns null for an unknown ID (thin wrapper over em.find), and the code does nothing to handle that — dataset.setTemplate(null) is a no-op. Every other invalid-value case in this same method throws a JsonParseException (see the Invalid dataset type: ... branch immediately above this new code, JsonParser.java:288). A typo'd or stale templateId should produce a clear 400 error ("Invalid templateId: " + templateId), not silently create the dataset without the requested template.

  2. obj.getInt("templateId", 0) can throw an uncaught ClassCastException. If a caller sends "templateId": "5" (string instead of number), JsonObject.getInt throws ClassCastException, not JsonParseException. The only wrapper at the call site (Dataverses.parseDataset, line ~779) catches JsonParsingException | JsonParseException — a ClassCastException would propagate as an unhandled 500 instead of a clean 400. Worth wrapping the read (or catching/rethrowing as JsonParseException) for consistency with how the rest of this method reports bad input.

Test coverage

  • The new DataversesIT test covers the happy path well (create with a valid templateId, verify it round-trips via GET, clean up).
  • No test for an invalid/non-existent templateId (would currently reveal issue #2 — silently succeeds instead of erroring).
  • No test asserting that a templateId from an unrelated dataverse is rejected (would currently reveal issue #1 — silently succeeds).
  • Since neither is currently rejected, existing tests can't catch these gaps; adding negative-path tests here would both document intended behavior and force the scoping/error-handling to be decided explicitly.

Style / minor

  • Several files unrelated in substance to the feature (ImportGenericServiceBean.java, ImportServiceBean.java, SchemaDotOrgExporterTest.java, FeedbackUtilTest.java, DataversesIT.java) show large import-block reshuffles/wildcards (import edu.harvard.iq.dataverse.;, jakarta.ejb.;, java.util.*;) alongside the one-line change they actually needed (adding a TemplateServiceBean mock/field). This looks like an IDE "organize imports" pass swept up in the commit — harmless (the project's style guide explicitly says wildcard imports are "neither encouraged nor discouraged," and checkstyle's AvoidStarImport is disabled), but it's pure churn that bloats the diff and increases merge-conflict risk for unrelated in-flight PRs touching these same files. Worth trimming to just the needed changes if easy to do, though not blocking.
  • Long.valueOf(templateId) where templateId is declared int templateId = obj.getInt(...) is a bit roundabout (auto-boxing an int into a Long via valueOf rather than just widening) — cosmetic only.

Verdict

The core wiring (constructor threading, JSON round-trip) is correct and the happy-path test passes. Before merging, I'd want: (1) a decision on whether templateId should be scoped to the target dataverse's own/inherited templates, since that's the existing UI behavior and its absence is the main risk here, and (2) explicit error handling for an unknown templateId instead of silent success, matching the pattern used for every other invalid field in this method.

@rtreacy rtreacy self-assigned this Jul 27, 2026
@rtreacy rtreacy moved this from Ready for Review ⏩ to In Review 🔎 in IQSS Dataverse Project Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

FY26 Sprint 22 FY26 Sprint 22 (2026-04-22 - 2026-05-06) FY26 Sprint 23 FY26 Sprint 23 (2026-05-06 - 2026-05-20) FY26 Sprint 24 FY26 Sprint 24 (2026-05-20 - 2026-06-03) FY26 Sprint 25 FY26 Sprint 25 (2026-06-03 - 2026-06-17) FY26 Sprint 26 FY26 Sprint 26 (2026-06-17 - 2026-07-01) FY27 Sprint 1 FY27 Sprint 1 (2026-07-01 - 2026-07-15) FY27 Sprint 2 FY27 Sprint 2 (2026-07-15 - 2026-07-29) GREI Re-arch Issues related to the GREI Dataverse rearchitecture Size: 10 A percentage of a sprint. 7 hours. SPA.Q4.2025.1 Create/Edit Template Feature SPA These changes are required for the Dataverse SPA Type: Feature a feature request

Projects

Status: In Review 🔎

Development

Successfully merging this pull request may close these issues.

Support applying template id in API of dataset creation and persist dataset–template associations

5 participants