Changeset View
Changeset View
Standalone View
Standalone View
src/tests/Feature/Controller/Reseller/GroupsTest.php
Show All 30 Lines | class GroupsTest extends TestCase | ||||
/** | /** | ||||
* Test groups searching (/api/v4/groups) | * Test groups searching (/api/v4/groups) | ||||
*/ | */ | ||||
public function testIndex(): void | public function testIndex(): void | ||||
{ | { | ||||
$user = $this->getTestUser('john@kolab.org'); | $user = $this->getTestUser('john@kolab.org'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
$group = $this->getTestGroup('group-test@kolab.org'); | $group = $this->getTestGroup('group-test@kolab.org'); | ||||
$group->assignToWallet($user->wallets->first()); | $group->assignToWallet($user->wallets->first()); | ||||
// Non-admin user | // Non-admin user | ||||
$response = $this->actingAs($user)->get("api/v4/groups"); | $response = $this->actingAs($user)->get("api/v4/groups"); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
// Admin user | // Admin user | ||||
$response = $this->actingAs($admin)->get("api/v4/groups"); | $response = $this->actingAs($admin)->get("api/v4/groups"); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
// Reseller from a different tenant | |||||
$response = $this->actingAs($reseller2)->get("api/v4/groups"); | |||||
$response->assertStatus(403); | |||||
// Search with no search criteria | // Search with no search criteria | ||||
$response = $this->actingAs($reseller1)->get("api/v4/groups"); | $response = $this->actingAs($reseller1)->get("api/v4/groups"); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame(0, $json['count']); | $this->assertSame(0, $json['count']); | ||||
$this->assertSame([], $json['list']); | $this->assertSame([], $json['list']); | ||||
Show All 33 Lines | public function testIndex(): void | ||||
$response = $this->actingAs($reseller1)->get("api/v4/groups?owner={$ned->id}"); | $response = $this->actingAs($reseller1)->get("api/v4/groups?owner={$ned->id}"); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame(0, $json['count']); | $this->assertSame(0, $json['count']); | ||||
$this->assertCount(0, $json['list']); | $this->assertCount(0, $json['list']); | ||||
// Test unauth access to other tenant's groups | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->get("api/v4/groups?search=kolab.org"); | $response = $this->actingAs($reseller2)->get("api/v4/groups?search=kolab.org"); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame(0, $json['count']); | $this->assertSame(0, $json['count']); | ||||
$this->assertSame([], $json['list']); | $this->assertSame([], $json['list']); | ||||
$response = $this->actingAs($reseller2)->get("api/v4/groups?owner={$user->id}"); | $response = $this->actingAs($reseller2)->get("api/v4/groups?owner={$user->id}"); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame(0, $json['count']); | $this->assertSame(0, $json['count']); | ||||
$this->assertSame([], $json['list']); | $this->assertSame([], $json['list']); | ||||
} | } | ||||
/** | /** | ||||
* Test fetching group info | * Test fetching group info | ||||
*/ | */ | ||||
public function testShow(): void | public function testShow(): void | ||||
{ | { | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$user = $this->getTestUser('test1@domainscontroller.com'); | $user = $this->getTestUser('test1@domainscontroller.com'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
$group = $this->getTestGroup('group-test@kolab.org'); | $group = $this->getTestGroup('group-test@kolab.org'); | ||||
$group->assignToWallet($user->wallets->first()); | $group->assignToWallet($user->wallets->first()); | ||||
// Only resellers can access it | // Only resellers can access it | ||||
$response = $this->actingAs($user)->get("api/v4/groups/{$group->id}"); | $response = $this->actingAs($user)->get("api/v4/groups/{$group->id}"); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($admin)->get("api/v4/groups/{$group->id}"); | $response = $this->actingAs($admin)->get("api/v4/groups/{$group->id}"); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($reseller2)->get("api/v4/groups/{$group->id}"); | $response = $this->actingAs($reseller2)->get("api/v4/groups/{$group->id}"); | ||||
$response->assertStatus(403); | $response->assertStatus(404); | ||||
$response = $this->actingAs($reseller1)->get("api/v4/groups/{$group->id}"); | $response = $this->actingAs($reseller1)->get("api/v4/groups/{$group->id}"); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertEquals($group->id, $json['id']); | $this->assertEquals($group->id, $json['id']); | ||||
$this->assertEquals($group->email, $json['email']); | $this->assertEquals($group->email, $json['email']); | ||||
$this->assertEquals($group->status, $json['status']); | $this->assertEquals($group->status, $json['status']); | ||||
} | } | ||||
/** | /** | ||||
* Test fetching group status (GET /api/v4/domains/<domain-id>/status) | * Test fetching group status (GET /api/v4/domains/<domain-id>/status) | ||||
*/ | */ | ||||
public function testStatus(): void | public function testStatus(): void | ||||
{ | { | ||||
Queue::fake(); // disable jobs | Queue::fake(); // disable jobs | ||||
$user = $this->getTestUser('john@kolab.org'); | $user = $this->getTestUser('john@kolab.org'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$group = $this->getTestGroup('group-test@kolab.org'); | $group = $this->getTestGroup('group-test@kolab.org'); | ||||
$group->assignToWallet($user->wallets->first()); | $group->assignToWallet($user->wallets->first()); | ||||
// This end-point does not exist for admins | // This end-point does not exist for admins | ||||
$response = $this->actingAs($reseller1)->get("/api/v4/groups/{$group->id}/status"); | $response = $this->actingAs($reseller1)->get("/api/v4/groups/{$group->id}/status"); | ||||
$response->assertStatus(404); | $response->assertStatus(404); | ||||
} | } | ||||
/** | /** | ||||
* Test group creating (POST /api/v4/groups) | * Test group creating (POST /api/v4/groups) | ||||
*/ | */ | ||||
public function testStore(): void | public function testStore(): void | ||||
{ | { | ||||
$user = $this->getTestUser('john@kolab.org'); | $user = $this->getTestUser('john@kolab.org'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
// Test unauthorized access to reseller API | // Test unauthorized access to reseller API | ||||
$response = $this->actingAs($user)->post("/api/v4/groups", []); | $response = $this->actingAs($user)->post("/api/v4/groups", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
// Reseller or admin can't create groups | // Reseller or admin can't create groups | ||||
$response = $this->actingAs($admin)->post("/api/v4/groups", []); | $response = $this->actingAs($admin)->post("/api/v4/groups", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/groups", []); | $response = $this->actingAs($reseller1)->post("/api/v4/groups", []); | ||||
$response->assertStatus(404); | $response->assertStatus(404); | ||||
} | } | ||||
/** | /** | ||||
* Test group suspending (POST /api/v4/groups/<group-id>/suspend) | * Test group suspending (POST /api/v4/groups/<group-id>/suspend) | ||||
*/ | */ | ||||
public function testSuspend(): void | public function testSuspend(): void | ||||
{ | { | ||||
Queue::fake(); // disable jobs | Queue::fake(); // disable jobs | ||||
$user = $this->getTestUser('john@kolab.org'); | $user = $this->getTestUser('john@kolab.org'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
$group = $this->getTestGroup('group-test@kolab.org'); | $group = $this->getTestGroup('group-test@kolab.org'); | ||||
$group->assignToWallet($user->wallets->first()); | $group->assignToWallet($user->wallets->first()); | ||||
// Test unauthorized access to reseller API | // Test unauthorized access to reseller API | ||||
$response = $this->actingAs($user)->post("/api/v4/groups/{$group->id}/suspend", []); | $response = $this->actingAs($user)->post("/api/v4/groups/{$group->id}/suspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
// Test unauthorized access to reseller API | // Test unauthorized access to reseller API | ||||
Show All 13 Lines | public function testSuspend(): void | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
$this->assertSame("Distribution list suspended successfully.", $json['message']); | $this->assertSame("Distribution list suspended successfully.", $json['message']); | ||||
$this->assertCount(2, $json); | $this->assertCount(2, $json); | ||||
$this->assertTrue($group->fresh()->isSuspended()); | $this->assertTrue($group->fresh()->isSuspended()); | ||||
// Test unauth access to other tenant's groups | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->post("/api/v4/groups/{$group->id}/suspend", []); | $response = $this->actingAs($reseller2)->post("/api/v4/groups/{$group->id}/suspend", []); | ||||
$response->assertStatus(404); | $response->assertStatus(404); | ||||
} | } | ||||
/** | /** | ||||
* Test user un-suspending (POST /api/v4/users/<user-id>/unsuspend) | * Test user un-suspending (POST /api/v4/users/<user-id>/unsuspend) | ||||
*/ | */ | ||||
public function testUnsuspend(): void | public function testUnsuspend(): void | ||||
{ | { | ||||
Queue::fake(); // disable jobs | Queue::fake(); // disable jobs | ||||
$user = $this->getTestUser('john@kolab.org'); | $user = $this->getTestUser('john@kolab.org'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
$group = $this->getTestGroup('group-test@kolab.org'); | $group = $this->getTestGroup('group-test@kolab.org'); | ||||
$group->assignToWallet($user->wallets->first()); | $group->assignToWallet($user->wallets->first()); | ||||
$group->status |= Group::STATUS_SUSPENDED; | $group->status |= Group::STATUS_SUSPENDED; | ||||
$group->save(); | $group->save(); | ||||
// Test unauthorized access to reseller API | // Test unauthorized access to reseller API | ||||
$response = $this->actingAs($user)->post("/api/v4/groups/{$group->id}/unsuspend", []); | $response = $this->actingAs($user)->post("/api/v4/groups/{$group->id}/unsuspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
Show All 15 Lines | public function testUnsuspend(): void | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
$this->assertSame("Distribution list unsuspended successfully.", $json['message']); | $this->assertSame("Distribution list unsuspended successfully.", $json['message']); | ||||
$this->assertCount(2, $json); | $this->assertCount(2, $json); | ||||
$this->assertFalse($group->fresh()->isSuspended()); | $this->assertFalse($group->fresh()->isSuspended()); | ||||
// Test unauth access to other tenant's groups | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->post("/api/v4/groups/{$group->id}/unsuspend", []); | $response = $this->actingAs($reseller2)->post("/api/v4/groups/{$group->id}/unsuspend", []); | ||||
$response->assertStatus(404); | $response->assertStatus(404); | ||||
} | } | ||||
} | } |