Changeset View
Changeset View
Standalone View
Standalone View
src/tests/Feature/Controller/Reseller/UsersTest.php
Show All 11 Lines | |||||
{ | { | ||||
/** | /** | ||||
* {@inheritDoc} | * {@inheritDoc} | ||||
*/ | */ | ||||
public function setUp(): void | public function setUp(): void | ||||
{ | { | ||||
parent::setUp(); | parent::setUp(); | ||||
self::useResellerUrl(); | self::useResellerUrl(); | ||||
\config(['app.tenant_id' => 1]); | |||||
$this->deleteTestUser('UsersControllerTest1@userscontroller.com'); | $this->deleteTestUser('UsersControllerTest1@userscontroller.com'); | ||||
$this->deleteTestUser('test@testsearch.com'); | $this->deleteTestUser('test@testsearch.com'); | ||||
$this->deleteTestDomain('testsearch.com'); | $this->deleteTestDomain('testsearch.com'); | ||||
} | } | ||||
/** | /** | ||||
* {@inheritDoc} | * {@inheritDoc} | ||||
*/ | */ | ||||
public function tearDown(): void | public function tearDown(): void | ||||
{ | { | ||||
$this->deleteTestUser('UsersControllerTest1@userscontroller.com'); | $this->deleteTestUser('UsersControllerTest1@userscontroller.com'); | ||||
$this->deleteTestUser('test@testsearch.com'); | $this->deleteTestUser('test@testsearch.com'); | ||||
$this->deleteTestDomain('testsearch.com'); | $this->deleteTestDomain('testsearch.com'); | ||||
\config(['app.tenant_id' => 1]); | |||||
parent::tearDown(); | parent::tearDown(); | ||||
} | } | ||||
/** | /** | ||||
* Test user deleting (DELETE /api/v4/users/<id>) | * Test user deleting (DELETE /api/v4/users/<id>) | ||||
*/ | */ | ||||
public function testDestroy(): void | public function testDestroy(): void | ||||
{ | { | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | $user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | ||||
// Test unauth access | // Test unauth access | ||||
$response = $this->delete("api/v4/users/{$user->id}"); | $response = $this->delete("api/v4/users/{$user->id}"); | ||||
$response->assertStatus(401); | $response->assertStatus(401); | ||||
// The end-point does not exist | // The end-point does not exist | ||||
$response = $this->actingAs($reseller1)->delete("api/v4/users/{$user->id}"); | $response = $this->actingAs($reseller1)->delete("api/v4/users/{$user->id}"); | ||||
$response->assertStatus(404); | $response->assertStatus(404); | ||||
} | } | ||||
/** | /** | ||||
* Test users searching (/api/v4/users) | * Test users searching (/api/v4/users) | ||||
*/ | */ | ||||
public function testIndex(): void | public function testIndex(): void | ||||
{ | { | ||||
Queue::fake(); | Queue::fake(); | ||||
$user = $this->getTestUser('john@kolab.org'); | $user = $this->getTestUser('john@kolab.org'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
\config(['app.tenant_id' => 2]); | |||||
// Guess access | // Guess access | ||||
$response = $this->get("api/v4/users"); | $response = $this->get("api/v4/users"); | ||||
$response->assertStatus(401); | $response->assertStatus(401); | ||||
// Normal user | // Normal user | ||||
$response = $this->actingAs($user)->get("api/v4/users"); | $response = $this->actingAs($user)->get("api/v4/users"); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
// Admin user | // Admin user | ||||
$response = $this->actingAs($admin)->get("api/v4/users"); | $response = $this->actingAs($admin)->get("api/v4/users"); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
// Reseller from another tenant | |||||
$response = $this->actingAs($reseller1)->get("api/v4/users"); | |||||
$response->assertStatus(403); | |||||
// Search with no search criteria | // Search with no search criteria | ||||
$response = $this->actingAs($reseller2)->get("api/v4/users"); | $response = $this->actingAs($reseller2)->get("api/v4/users"); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame(0, $json['count']); | $this->assertSame(0, $json['count']); | ||||
$this->assertSame([], $json['list']); | $this->assertSame([], $json['list']); | ||||
Show All 40 Lines | public function testIndex(): void | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame(0, $json['count']); | $this->assertSame(0, $json['count']); | ||||
$this->assertSame([], $json['list']); | $this->assertSame([], $json['list']); | ||||
// Create a domain with some users in the Sample Tenant so we have anything to search for | // Create a domain with some users in the Sample Tenant so we have anything to search for | ||||
$domain = $this->getTestDomain('testsearch.com', ['type' => \App\Domain::TYPE_EXTERNAL]); | $domain = $this->getTestDomain('testsearch.com', ['type' => \App\Domain::TYPE_EXTERNAL]); | ||||
$domain->tenant_id = 2; | $domain->tenant_id = $reseller2->tenant_id; | ||||
$domain->save(); | $domain->save(); | ||||
$user = $this->getTestUser('test@testsearch.com'); | $user = $this->getTestUser('test@testsearch.com'); | ||||
$user->tenant_id = 2; | $user->tenant_id = $reseller2->tenant_id; | ||||
$user->save(); | $user->save(); | ||||
$plan = \App\Plan::where('title', 'group')->first(); | $plan = \App\Plan::where('title', 'group')->first(); | ||||
$user->assignPlan($plan, $domain); | $user->assignPlan($plan, $domain); | ||||
$user->setAliases(['alias@testsearch.com']); | $user->setAliases(['alias@testsearch.com']); | ||||
$user->setSetting('external_email', 'john.doe.external@gmail.com'); | $user->setSetting('external_email', 'john.doe.external@gmail.com'); | ||||
// Search by domain | // Search by domain | ||||
$response = $this->actingAs($reseller2)->get("api/v4/users?search=testsearch.com"); | $response = $this->actingAs($reseller2)->get("api/v4/users?search=testsearch.com"); | ||||
▲ Show 20 Lines • Show All 99 Lines • ▼ Show 20 Lines | public function testIndex(): void | ||||
$this->assertTrue($json['list'][0]['isDeleted']); | $this->assertTrue($json['list'][0]['isDeleted']); | ||||
} | } | ||||
/** | /** | ||||
* Test reseting 2FA (POST /api/v4/users/<user-id>/reset2FA) | * Test reseting 2FA (POST /api/v4/users/<user-id>/reset2FA) | ||||
*/ | */ | ||||
public function testReset2FA(): void | public function testReset2FA(): void | ||||
{ | { | ||||
Queue::fake(); // disable jobs | |||||
$user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | $user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
$sku2fa = \App\Sku::firstOrCreate(['title' => '2fa']); | $sku2fa = \App\Sku::withEnvTenantContext()->where('title', '2fa')->first(); | ||||
$user->assignSku($sku2fa); | $user->assignSku($sku2fa); | ||||
\App\Auth\SecondFactor::seed('userscontrollertest1@userscontroller.com'); | \App\Auth\SecondFactor::seed('userscontrollertest1@userscontroller.com'); | ||||
// Test unauthorized access | // Test unauthorized access | ||||
$response = $this->actingAs($user)->post("/api/v4/users/{$user->id}/reset2FA", []); | $response = $this->actingAs($user)->post("/api/v4/users/{$user->id}/reset2FA", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($admin)->post("/api/v4/users/{$user->id}/reset2FA", []); | $response = $this->actingAs($admin)->post("/api/v4/users/{$user->id}/reset2FA", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/reset2FA", []); | $response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/reset2FA", []); | ||||
$response->assertStatus(403); | $response->assertStatus(404); | ||||
// Touching admins is forbidden | // Touching admins is forbidden | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users/{$admin->id}/reset2FA", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users/{$admin->id}/reset2FA", []); | ||||
$response->assertStatus(404); | $response->assertStatus(403); | ||||
$entitlements = $user->fresh()->entitlements()->where('sku_id', $sku2fa->id)->get(); | $entitlements = $user->fresh()->entitlements()->where('sku_id', $sku2fa->id)->get(); | ||||
$this->assertCount(1, $entitlements); | $this->assertCount(1, $entitlements); | ||||
$sf = new \App\Auth\SecondFactor($user); | $sf = new \App\Auth\SecondFactor($user); | ||||
$this->assertCount(1, $sf->factors()); | $this->assertCount(1, $sf->factors()); | ||||
// Test reseting 2FA | // Test reseting 2FA | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users/{$user->id}/reset2FA", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users/{$user->id}/reset2FA", []); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
$this->assertSame("2-Factor authentication reset successfully.", $json['message']); | $this->assertSame("2-Factor authentication reset successfully.", $json['message']); | ||||
$this->assertCount(2, $json); | $this->assertCount(2, $json); | ||||
$entitlements = $user->fresh()->entitlements()->where('sku_id', $sku2fa->id)->get(); | $entitlements = $user->fresh()->entitlements()->where('sku_id', $sku2fa->id)->get(); | ||||
$this->assertCount(0, $entitlements); | $this->assertCount(0, $entitlements); | ||||
$sf = new \App\Auth\SecondFactor($user); | $sf = new \App\Auth\SecondFactor($user); | ||||
$this->assertCount(0, $sf->factors()); | $this->assertCount(0, $sf->factors()); | ||||
// Other tenant's user | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/reset2FA", []); | |||||
$response->assertStatus(404); | |||||
} | } | ||||
/** | /** | ||||
* Test user creation (POST /api/v4/users) | * Test user creation (POST /api/v4/users) | ||||
*/ | */ | ||||
public function testStore(): void | public function testStore(): void | ||||
{ | { | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
// The end-point does not exist | // The end-point does not exist | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users", []); | ||||
$response->assertStatus(404); | $response->assertStatus(404); | ||||
} | } | ||||
/** | /** | ||||
* Test user suspending (POST /api/v4/users/<user-id>/suspend) | * Test user suspending (POST /api/v4/users/<user-id>/suspend) | ||||
*/ | */ | ||||
public function testSuspend(): void | public function testSuspend(): void | ||||
{ | { | ||||
Queue::fake(); // disable jobs | Queue::fake(); // disable jobs | ||||
$user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | $user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
// Test unauthorized access | // Test unauthorized access | ||||
$response = $this->actingAs($user)->post("/api/v4/users/{$user->id}/suspend", []); | $response = $this->actingAs($user)->post("/api/v4/users/{$user->id}/suspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($admin)->post("/api/v4/users/{$user->id}/suspend", []); | $response = $this->actingAs($admin)->post("/api/v4/users/{$user->id}/suspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/suspend", []); | $response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/suspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(404); | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users/{$admin->id}/suspend", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users/{$admin->id}/suspend", []); | ||||
$response->assertStatus(404); | $response->assertStatus(403); | ||||
$this->assertFalse($user->isSuspended()); | $this->assertFalse($user->isSuspended()); | ||||
// Test suspending the user | // Test suspending the user | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users/{$user->id}/suspend", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users/{$user->id}/suspend", []); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
$this->assertSame("User suspended successfully.", $json['message']); | $this->assertSame("User suspended successfully.", $json['message']); | ||||
$this->assertCount(2, $json); | $this->assertCount(2, $json); | ||||
$this->assertTrue($user->fresh()->isSuspended()); | $this->assertTrue($user->fresh()->isSuspended()); | ||||
// Access to other tenant's users | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/suspend", []); | |||||
$response->assertStatus(404); | |||||
} | } | ||||
/** | /** | ||||
* Test user un-suspending (POST /api/v4/users/<user-id>/unsuspend) | * Test user un-suspending (POST /api/v4/users/<user-id>/unsuspend) | ||||
*/ | */ | ||||
public function testUnsuspend(): void | public function testUnsuspend(): void | ||||
{ | { | ||||
Queue::fake(); // disable jobs | Queue::fake(); // disable jobs | ||||
$user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | $user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
// Test unauthorized access to admin API | // Test unauthorized access to admin API | ||||
$response = $this->actingAs($user)->post("/api/v4/users/{$user->id}/unsuspend", []); | $response = $this->actingAs($user)->post("/api/v4/users/{$user->id}/unsuspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($admin)->post("/api/v4/users/{$user->id}/unsuspend", []); | $response = $this->actingAs($admin)->post("/api/v4/users/{$user->id}/unsuspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/unsuspend", []); | $response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/unsuspend", []); | ||||
$response->assertStatus(403); | $response->assertStatus(404); | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users/{$admin->id}/unsuspend", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users/{$admin->id}/unsuspend", []); | ||||
$response->assertStatus(404); | $response->assertStatus(403); | ||||
$this->assertFalse($user->isSuspended()); | $this->assertFalse($user->isSuspended()); | ||||
$user->suspend(); | $user->suspend(); | ||||
$this->assertTrue($user->isSuspended()); | $this->assertTrue($user->isSuspended()); | ||||
// Test suspending the user | // Test suspending the user | ||||
$response = $this->actingAs($reseller1)->post("/api/v4/users/{$user->id}/unsuspend", []); | $response = $this->actingAs($reseller1)->post("/api/v4/users/{$user->id}/unsuspend", []); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
$this->assertSame("User unsuspended successfully.", $json['message']); | $this->assertSame("User unsuspended successfully.", $json['message']); | ||||
$this->assertCount(2, $json); | $this->assertCount(2, $json); | ||||
$this->assertFalse($user->fresh()->isSuspended()); | $this->assertFalse($user->fresh()->isSuspended()); | ||||
// Access to other tenant's users | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->post("/api/v4/users/{$user->id}/unsuspend", []); | |||||
$response->assertStatus(404); | |||||
} | } | ||||
/** | /** | ||||
* Test user update (PUT /api/v4/users/<user-id>) | * Test user update (PUT /api/v4/users/<user-id>) | ||||
*/ | */ | ||||
public function testUpdate(): void | public function testUpdate(): void | ||||
{ | { | ||||
$user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | $user = $this->getTestUser('UsersControllerTest1@userscontroller.com'); | ||||
$admin = $this->getTestUser('jeroen@jeroen.jeroen'); | $admin = $this->getTestUser('jeroen@jeroen.jeroen'); | ||||
$reseller1 = $this->getTestUser('reseller@kolabnow.com'); | $reseller1 = $this->getTestUser('reseller@' . \config('app.domain')); | ||||
$reseller2 = $this->getTestUser('reseller@reseller.com'); | $reseller2 = $this->getTestUser('reseller@sample-tenant.dev-local'); | ||||
// Test unauthorized access | // Test unauthorized access | ||||
$response = $this->actingAs($user)->put("/api/v4/users/{$user->id}", []); | $response = $this->actingAs($user)->put("/api/v4/users/{$user->id}", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($admin)->put("/api/v4/users/{$user->id}", []); | $response = $this->actingAs($admin)->put("/api/v4/users/{$user->id}", []); | ||||
$response->assertStatus(403); | $response->assertStatus(403); | ||||
$response = $this->actingAs($reseller2)->put("/api/v4/users/{$user->id}", []); | $response = $this->actingAs($reseller2)->put("/api/v4/users/{$user->id}", []); | ||||
$response->assertStatus(403); | $response->assertStatus(404); | ||||
$response = $this->actingAs($reseller1)->put("/api/v4/users/{$admin->id}", []); | $response = $this->actingAs($reseller1)->put("/api/v4/users/{$admin->id}", []); | ||||
$response->assertStatus(404); | $response->assertStatus(403); | ||||
// Test updatig the user data (empty data) | // Test updatig the user data (empty data) | ||||
$response = $this->actingAs($reseller1)->put("/api/v4/users/{$user->id}", []); | $response = $this->actingAs($reseller1)->put("/api/v4/users/{$user->id}", []); | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
Show All 17 Lines | public function testUpdate(): void | ||||
$response->assertStatus(200); | $response->assertStatus(200); | ||||
$json = $response->json(); | $json = $response->json(); | ||||
$this->assertSame('success', $json['status']); | $this->assertSame('success', $json['status']); | ||||
$this->assertSame("User data updated successfully.", $json['message']); | $this->assertSame("User data updated successfully.", $json['message']); | ||||
$this->assertCount(2, $json); | $this->assertCount(2, $json); | ||||
$this->assertSame('modified@test.com', $user->getSetting('external_email')); | $this->assertSame('modified@test.com', $user->getSetting('external_email')); | ||||
// Access to other tenant's users | |||||
\config(['app.tenant_id' => 2]); | |||||
$response = $this->actingAs($reseller2)->put("/api/v4/users/{$user->id}", $post); | |||||
$response->assertStatus(404); | |||||
} | } | ||||
} | } |