nextcloud/apps/dav/tests/unit/Connector/Sabre/PublicAuthTest.php

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

408 lines
12 KiB
PHP
Raw Normal View History

2016-04-01 11:35:37 -04:00
<?php
2016-05-26 13:56:05 -04:00
/**
* SPDX-FileCopyrightText: 2022-2024 Nextcloud GmbH and Nextcloud contributors
* SPDX-FileCopyrightText: 2016 ownCloud, Inc.
* SPDX-License-Identifier: AGPL-3.0-only
2016-05-26 13:56:05 -04:00
*/
2016-05-25 10:04:15 -04:00
namespace OCA\DAV\Tests\unit\Connector;
2016-04-01 11:35:37 -04:00
use OCA\DAV\Connector\Sabre\PublicAuth;
2016-04-01 11:35:37 -04:00
use OCP\IRequest;
use OCP\ISession;
use OCP\Security\Bruteforce\IThrottler;
2016-04-01 11:35:37 -04:00
use OCP\Share\Exceptions\ShareNotFound;
use OCP\Share\IManager;
use OCP\Share\IShare;
use Psr\Log\LoggerInterface;
2016-04-01 11:35:37 -04:00
/**
2016-05-25 10:04:15 -04:00
* Class PublicAuthTest
*
* @group DB
*
2016-05-25 10:04:15 -04:00
* @package OCA\DAV\Tests\unit\Connector
*/
2016-05-25 10:04:15 -04:00
class PublicAuthTest extends \Test\TestCase {
2016-04-01 11:35:37 -04:00
/** @var ISession|MockObject */
2016-04-01 11:35:37 -04:00
private $session;
/** @var IRequest|MockObject */
2016-04-01 11:35:37 -04:00
private $request;
/** @var IManager|MockObject */
2016-04-01 11:35:37 -04:00
private $shareManager;
/** @var PublicAuth */
2016-04-01 11:35:37 -04:00
private $auth;
/** @var IThrottler|MockObject */
private $throttler;
/** @var LoggerInterface|MockObject */
private $logger;
2016-04-01 11:35:37 -04:00
/** @var string */
private $oldUser;
protected function setUp(): void {
2016-04-01 11:35:37 -04:00
parent::setUp();
$this->session = $this->createMock(ISession::class);
$this->request = $this->createMock(IRequest::class);
$this->shareManager = $this->createMock(IManager::class);
$this->throttler = $this->createMock(IThrottler::class);
$this->logger = $this->createMock(LoggerInterface::class);
2016-04-01 11:35:37 -04:00
$this->auth = new PublicAuth(
2016-04-01 11:35:37 -04:00
$this->request,
$this->shareManager,
$this->session,
$this->throttler,
$this->logger,
2016-04-01 11:35:37 -04:00
);
// Store current user
$this->oldUser = \OC_User::getUser();
}
protected function tearDown(): void {
2016-04-01 11:35:37 -04:00
\OC_User::setIncognitoMode(false);
// Set old user
\OC_User::setUserId($this->oldUser);
\OC_Util::setupFS($this->oldUser);
parent::tearDown();
}
public function testGetToken(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$result = $this->invokePrivate($this->auth, 'getToken');
$this->assertSame('GX9HSGQrGE', $result);
}
public function testGetTokenInvalid(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files');
$this->expectException(\Sabre\DAV\Exception\NotFound::class);
$this->invokePrivate($this->auth, 'getToken');
}
public function testCheckTokenValidShare(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
$share->method('getPassword')->willReturn(null);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->willReturn($share);
$result = $this->invokePrivate($this->auth, 'checkToken');
$this->assertSame([true, 'principals/GX9HSGQrGE'], $result);
}
public function testCheckTokenInvalidShare(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$this->shareManager
->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->will($this->throwException(new ShareNotFound()));
$this->expectException(\Sabre\DAV\Exception\NotFound::class);
$this->invokePrivate($this->auth, 'checkToken');
}
public function testCheckTokenAlreadyAuthenticated(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
$share->method('getShareType')->willReturn(42);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->willReturn($share);
$this->session->method('exists')->with('public_link_authenticated')->willReturn(true);
$this->session->method('get')->with('public_link_authenticated')->willReturn('42');
$result = $this->invokePrivate($this->auth, 'checkToken');
$this->assertSame([true, 'principals/GX9HSGQrGE'], $result);
}
public function testCheckTokenPasswordNotAuthenticated(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(42);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->willReturn($share);
$this->session->method('exists')->with('public_link_authenticated')->willReturn(false);
$this->expectException(\Sabre\DAV\Exception\NotAuthenticated::class);
$this->invokePrivate($this->auth, 'checkToken');
}
public function testCheckTokenPasswordAuthenticatedWrongShare(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(42);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->willReturn($share);
$this->session->method('exists')->with('public_link_authenticated')->willReturn(false);
$this->session->method('get')->with('public_link_authenticated')->willReturn('43');
$this->expectException(\Sabre\DAV\Exception\NotAuthenticated::class);
$this->invokePrivate($this->auth, 'checkToken');
}
public function testNoShare(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
2016-04-01 11:35:37 -04:00
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willThrowException(new ShareNotFound());
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertFalse($result);
}
public function testShareNoPassword(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
2016-04-01 11:35:37 -04:00
$share->method('getPassword')->willReturn(null);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willReturn($share);
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertTrue($result);
}
public function testSharePasswordFancyShareType(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
2016-04-01 11:35:37 -04:00
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(42);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willReturn($share);
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertFalse($result);
}
public function testSharePasswordRemote(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
2016-04-01 11:35:37 -04:00
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(IShare::TYPE_REMOTE);
2016-04-01 11:35:37 -04:00
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willReturn($share);
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertTrue($result);
}
public function testSharePasswordLinkValidPassword(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
2016-04-01 11:35:37 -04:00
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(IShare::TYPE_LINK);
2016-04-01 11:35:37 -04:00
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willReturn($share);
$this->shareManager->expects($this->once())
->method('checkPassword')->with(
$this->equalTo($share),
$this->equalTo('password')
)->willReturn(true);
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertTrue($result);
}
public function testSharePasswordMailValidPassword(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(IShare::TYPE_EMAIL);
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->willReturn($share);
$this->shareManager->expects($this->once())
->method('checkPassword')->with(
$this->equalTo($share),
$this->equalTo('password')
)->willReturn(true);
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertTrue($result);
}
public function testInvalidSharePasswordLinkValidSession(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
2016-04-01 11:35:37 -04:00
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(IShare::TYPE_LINK);
2016-04-01 11:35:37 -04:00
$share->method('getId')->willReturn('42');
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willReturn($share);
$this->shareManager->expects($this->once())
->method('checkPassword')
2016-04-01 11:35:37 -04:00
->with(
$this->equalTo($share),
$this->equalTo('password')
)->willReturn(false);
$this->session->method('exists')->with('public_link_authenticated')->willReturn(true);
$this->session->method('get')->with('public_link_authenticated')->willReturn('42');
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertTrue($result);
}
public function testSharePasswordLinkInvalidSession(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
2016-04-01 11:35:37 -04:00
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(IShare::TYPE_LINK);
2016-04-01 11:35:37 -04:00
$share->method('getId')->willReturn('42');
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
2016-04-01 11:35:37 -04:00
->willReturn($share);
$this->shareManager->expects($this->once())
->method('checkPassword')
2016-04-01 11:35:37 -04:00
->with(
$this->equalTo($share),
$this->equalTo('password')
)->willReturn(false);
$this->session->method('exists')->with('public_link_authenticated')->willReturn(true);
$this->session->method('get')->with('public_link_authenticated')->willReturn('43');
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertFalse($result);
}
public function testSharePasswordMailInvalidSession(): void {
$this->request->method('getPathInfo')
->willReturn('/dav/files/GX9HSGQrGE');
$share = $this->getMockBuilder(IShare::class)
->disableOriginalConstructor()
->getMock();
$share->method('getPassword')->willReturn('password');
$share->method('getShareType')->willReturn(IShare::TYPE_EMAIL);
$share->method('getId')->willReturn('42');
$this->shareManager->expects($this->once())
->method('getShareByToken')
->with('GX9HSGQrGE')
->willReturn($share);
$this->shareManager->expects($this->once())
->method('checkPassword')
->with(
$this->equalTo($share),
$this->equalTo('password')
)->willReturn(false);
$this->session->method('exists')->with('public_link_authenticated')->willReturn(true);
$this->session->method('get')->with('public_link_authenticated')->willReturn('43');
$result = $this->invokePrivate($this->auth, 'validateUserPass', ['username', 'password']);
$this->assertFalse($result);
}
2016-04-01 11:35:37 -04:00
}