$user, 'PHP_AUTH_PW' => 'test', ]); if (false === $read) { $this->expectException(AccessDeniedException::class); } $client->catchExceptions(false); //Test read/list access by access /new overview page $crawler = $client->request('GET', static::$base_path.'/new'); $this->assertFalse($client->getResponse()->isRedirect()); $this->assertSame($read, $client->getResponse()->isSuccessful(), 'Controller was not successful!'); $this->assertSame($read, ! $client->getResponse()->isForbidden(), 'Permission Checking not working!'); } /** * @dataProvider readDataProvider * @group slow * Tests if it possible to access an specific entity. Checks if permissions are working. */ public function testReadEntity(string $user, bool $read): void { //Test read access $client = static::createClient([], [ 'PHP_AUTH_USER' => $user, 'PHP_AUTH_PW' => 'test', ]); $client->catchExceptions(false); if (false === $read) { $this->expectException(AccessDeniedException::class); } //Test read/list access by access /new overview page $crawler = $client->request('GET', static::$base_path.'/1'); $this->assertFalse($client->getResponse()->isRedirect()); $this->assertSame($read, $client->getResponse()->isSuccessful(), 'Controller was not successful!'); $this->assertSame($read, ! $client->getResponse()->isForbidden(), 'Permission Checking not working!'); } public function deleteDataProvider() { return [ ['noread', false], ['anonymous', false], ['user', true], ['admin', true], ]; } /** * Tests if deleting an entity is working. * * @group slow * @dataProvider deleteDataProvider */ public function testDeleteEntity(string $user, bool $delete): void { //Test read access $client = static::createClient([], [ 'PHP_AUTH_USER' => $user, 'PHP_AUTH_PW' => 'test', ]); $client->catchExceptions(false); if (false === $delete) { $this->expectException(AccessDeniedException::class); } //Test read/list access by access /new overview page $crawler = $client->request('DELETE', static::$base_path.'/7'); //Page is redirected to '/new', when delete was successful $this->assertSame($delete, $client->getResponse()->isRedirect(static::$base_path.'/new')); $this->assertSame($delete, ! $client->getResponse()->isForbidden(), 'Permission Checking not working!'); } }