. */ declare(strict_types=1); namespace App\Tests\EventSubscriber; use App\Entity\UserSystem\Group; use App\Entity\UserSystem\User; use App\Entity\UserSystem\WebauthnKey; use App\EventSubscriber\UserSystem\PasswordChangeNeededSubscriber; use PHPUnit\Framework\TestCase; use Ramsey\Uuid\Uuid; use Webauthn\TrustPath\EmptyTrustPath; class PasswordChangeNeededSubscriberTest extends TestCase { public function testTFARedirectNeeded(): void { $user = new User(); $group = new Group(); //A user without a group must not redirect $user->setGroup(null); $this->assertFalse(PasswordChangeNeededSubscriber::TFARedirectNeeded($user)); //When the group does not enforce the redirect the user must not be redirected $user->setGroup($group); $this->assertFalse(PasswordChangeNeededSubscriber::TFARedirectNeeded($user)); //The user must be redirected if the group enforces 2FA, and it does not have a method $group->setEnforce2FA(true); $this->assertTrue(PasswordChangeNeededSubscriber::TFARedirectNeeded($user)); //User must not be redirect if google authenticator is set up $user->setGoogleAuthenticatorSecret('abcd'); $this->assertFalse(PasswordChangeNeededSubscriber::TFARedirectNeeded($user)); //User must not be redirect if 2FA is set up $user->setGoogleAuthenticatorSecret(null); $user->addWebauthnKey(new WebauthnKey( "Test", "Test", [], "Test", new EmptyTrustPath(), Uuid::fromDateTime(new \DateTime()), "", "", 0 )); $this->assertFalse(PasswordChangeNeededSubscriber::TFARedirectNeeded($user)); } }