2019-10-26 22:27:04 +02:00
|
|
|
<?php
|
2020-02-22 18:14:36 +01:00
|
|
|
/**
|
|
|
|
* This file is part of Part-DB (https://github.com/Part-DB/Part-DB-symfony).
|
|
|
|
*
|
|
|
|
* Copyright (C) 2019 - 2020 Jan Böhmer (https://github.com/jbtronics)
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License as published
|
|
|
|
* by the Free Software Foundation, either version 3 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public License
|
|
|
|
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
|
|
|
*/
|
2020-01-05 15:55:16 +01:00
|
|
|
|
|
|
|
declare(strict_types=1);
|
|
|
|
|
2019-10-26 22:27:04 +02:00
|
|
|
namespace App\Tests\Controller\AdminPages;
|
|
|
|
|
|
|
|
use Symfony\Bundle\FrameworkBundle\Test\WebTestCase;
|
2019-10-31 23:05:20 +01:00
|
|
|
use Symfony\Component\Security\Core\Exception\AccessDeniedException;
|
2019-10-26 22:27:04 +02:00
|
|
|
|
2019-10-31 22:37:54 +01:00
|
|
|
/**
|
|
|
|
* @group slow
|
2019-12-27 15:20:06 +01:00
|
|
|
* @group DB
|
2019-10-31 22:37:54 +01:00
|
|
|
*/
|
2019-10-26 22:27:04 +02:00
|
|
|
abstract class AbstractAdminControllerTest extends WebTestCase
|
|
|
|
{
|
|
|
|
protected static $base_path = 'not_valid';
|
|
|
|
protected static $entity_class = 'not valid';
|
|
|
|
|
2020-03-29 22:47:25 +02:00
|
|
|
public function readDataProvider(): array
|
2019-10-26 22:27:04 +02:00
|
|
|
{
|
|
|
|
return [
|
|
|
|
['noread', false],
|
|
|
|
['anonymous', true],
|
|
|
|
['user', true],
|
2019-11-09 00:47:20 +01:00
|
|
|
['admin', true],
|
2019-10-26 22:27:04 +02:00
|
|
|
];
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @dataProvider readDataProvider
|
2019-10-31 22:37:54 +01:00
|
|
|
* @group slow
|
2019-10-26 22:27:04 +02:00
|
|
|
* Tests if you can access the /new part which is used to list all entities. Checks if permissions are working
|
|
|
|
*/
|
2020-01-05 15:55:16 +01:00
|
|
|
public function testListEntries(string $user, bool $read): void
|
2019-10-26 22:27:04 +02:00
|
|
|
{
|
2019-11-23 15:03:08 +01:00
|
|
|
static::ensureKernelShutdown();
|
|
|
|
|
2019-10-26 22:27:04 +02:00
|
|
|
//Test read access
|
|
|
|
$client = static::createClient([], [
|
|
|
|
'PHP_AUTH_USER' => $user,
|
2019-11-09 00:47:20 +01:00
|
|
|
'PHP_AUTH_PW' => 'test',
|
2019-10-26 22:27:04 +02:00
|
|
|
]);
|
|
|
|
|
2020-03-29 18:24:10 +02:00
|
|
|
$client->catchExceptions(false);
|
2020-01-05 15:55:16 +01:00
|
|
|
if (false === $read) {
|
2019-10-31 23:05:20 +01:00
|
|
|
$this->expectException(AccessDeniedException::class);
|
|
|
|
}
|
|
|
|
|
|
|
|
$client->catchExceptions(false);
|
|
|
|
|
2019-10-26 22:27:04 +02:00
|
|
|
//Test read/list access by access /new overview page
|
2020-03-29 22:37:27 +02:00
|
|
|
$client->request('GET', static::$base_path.'/new');
|
2019-10-26 22:27:04 +02:00
|
|
|
$this->assertFalse($client->getResponse()->isRedirect());
|
2020-01-05 15:55:16 +01:00
|
|
|
$this->assertSame($read, $client->getResponse()->isSuccessful(), 'Controller was not successful!');
|
2020-08-21 21:36:22 +02:00
|
|
|
$this->assertSame($read, !$client->getResponse()->isForbidden(), 'Permission Checking not working!');
|
2019-10-26 22:27:04 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @dataProvider readDataProvider
|
2019-10-31 22:37:54 +01:00
|
|
|
* @group slow
|
2019-10-26 22:27:04 +02:00
|
|
|
* Tests if it possible to access an specific entity. Checks if permissions are working.
|
|
|
|
*/
|
2020-01-05 15:55:16 +01:00
|
|
|
public function testReadEntity(string $user, bool $read): void
|
2019-10-26 22:27:04 +02:00
|
|
|
{
|
|
|
|
//Test read access
|
|
|
|
$client = static::createClient([], [
|
|
|
|
'PHP_AUTH_USER' => $user,
|
2019-11-09 00:47:20 +01:00
|
|
|
'PHP_AUTH_PW' => 'test',
|
2019-10-26 22:27:04 +02:00
|
|
|
]);
|
|
|
|
|
2019-10-31 23:05:20 +01:00
|
|
|
$client->catchExceptions(false);
|
2020-01-05 15:55:16 +01:00
|
|
|
if (false === $read) {
|
2019-10-31 23:05:20 +01:00
|
|
|
$this->expectException(AccessDeniedException::class);
|
|
|
|
}
|
|
|
|
|
2019-10-26 22:27:04 +02:00
|
|
|
//Test read/list access by access /new overview page
|
2020-03-29 22:37:27 +02:00
|
|
|
$client->request('GET', static::$base_path.'/1');
|
2019-10-26 22:27:04 +02:00
|
|
|
$this->assertFalse($client->getResponse()->isRedirect());
|
2020-01-05 15:55:16 +01:00
|
|
|
$this->assertSame($read, $client->getResponse()->isSuccessful(), 'Controller was not successful!');
|
2020-08-21 21:36:22 +02:00
|
|
|
$this->assertSame($read, !$client->getResponse()->isForbidden(), 'Permission Checking not working!');
|
2019-10-26 22:27:04 +02:00
|
|
|
}
|
|
|
|
|
2020-03-29 22:47:25 +02:00
|
|
|
public function deleteDataProvider(): array
|
2019-10-26 22:27:04 +02:00
|
|
|
{
|
|
|
|
return [
|
|
|
|
['noread', false],
|
|
|
|
['anonymous', false],
|
|
|
|
['user', true],
|
2019-11-09 00:47:20 +01:00
|
|
|
['admin', true],
|
2019-10-26 22:27:04 +02:00
|
|
|
];
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Tests if deleting an entity is working.
|
2019-11-09 00:47:20 +01:00
|
|
|
*
|
2019-10-31 22:37:54 +01:00
|
|
|
* @group slow
|
2019-10-26 22:27:04 +02:00
|
|
|
* @dataProvider deleteDataProvider
|
|
|
|
*/
|
2020-01-05 15:55:16 +01:00
|
|
|
public function testDeleteEntity(string $user, bool $delete): void
|
2019-10-26 22:27:04 +02:00
|
|
|
{
|
|
|
|
//Test read access
|
|
|
|
$client = static::createClient([], [
|
|
|
|
'PHP_AUTH_USER' => $user,
|
2019-11-09 00:47:20 +01:00
|
|
|
'PHP_AUTH_PW' => 'test',
|
2019-10-26 22:27:04 +02:00
|
|
|
]);
|
|
|
|
|
2019-10-31 23:05:20 +01:00
|
|
|
$client->catchExceptions(false);
|
2020-01-05 15:55:16 +01:00
|
|
|
if (false === $delete) {
|
2019-11-09 00:47:20 +01:00
|
|
|
$this->expectException(AccessDeniedException::class);
|
2019-10-31 23:05:20 +01:00
|
|
|
}
|
|
|
|
|
2019-10-26 22:27:04 +02:00
|
|
|
//Test read/list access by access /new overview page
|
2020-03-29 22:37:27 +02:00
|
|
|
$client->request('DELETE', static::$base_path.'/7');
|
2019-10-26 22:27:04 +02:00
|
|
|
|
|
|
|
//Page is redirected to '/new', when delete was successful
|
2020-01-05 15:55:16 +01:00
|
|
|
$this->assertSame($delete, $client->getResponse()->isRedirect(static::$base_path.'/new'));
|
2020-08-21 21:36:22 +02:00
|
|
|
$this->assertSame($delete, !$client->getResponse()->isForbidden(), 'Permission Checking not working!');
|
2019-10-26 22:27:04 +02:00
|
|
|
}
|
2019-11-09 00:47:20 +01:00
|
|
|
}
|