|
1
|
|
|
<?php |
|
2
|
|
|
|
|
3
|
|
|
namespace PSFS\tests\base; |
|
4
|
|
|
|
|
5
|
|
|
use Exception; |
|
6
|
|
|
use PHPUnit\Framework\TestCase; |
|
7
|
|
|
use PSFS\base\exception\GeneratorException; |
|
8
|
|
|
use PSFS\base\Request; |
|
9
|
|
|
use PSFS\base\Security; |
|
10
|
|
|
use PSFS\services\AdminServices; |
|
11
|
|
|
|
|
12
|
|
|
/** |
|
13
|
|
|
* Class SecurityTest |
|
14
|
|
|
* @package PSFS\tests\base |
|
15
|
|
|
* @runInSeparateProcess |
|
16
|
|
|
*/ |
|
17
|
|
|
class SecurityTest extends TestCase |
|
18
|
|
|
{ |
|
19
|
|
|
/** |
|
20
|
|
|
* Test to check if the Logger has been created successful |
|
21
|
|
|
* @return Security |
|
22
|
|
|
*/ |
|
23
|
|
|
public function getInstance(): Security |
|
24
|
|
|
{ |
|
25
|
|
|
global $_SESSION; |
|
26
|
|
|
if (null === $_SESSION) { |
|
27
|
|
|
$_SESSION = []; |
|
28
|
|
|
} |
|
29
|
|
|
$instance = Security::getInstance(true); |
|
30
|
|
|
Security::setTest(false); |
|
31
|
|
|
|
|
32
|
|
|
$this->assertNotNull($instance, 'Security instance is null'); |
|
33
|
|
|
$this->assertInstanceOf(Security::class, $instance, 'Instance is different than expected'); |
|
34
|
|
|
return $instance; |
|
35
|
|
|
} |
|
36
|
|
|
|
|
37
|
|
|
/** |
|
38
|
|
|
* Test basic static functionality for Security class |
|
39
|
|
|
* @covers |
|
40
|
|
|
*/ |
|
41
|
|
|
public function testSecurityBasics(): Security |
|
42
|
|
|
{ |
|
43
|
|
|
$security = $this->getInstance(); |
|
44
|
|
|
$this->assertInstanceOf(Security::class, $security); |
|
45
|
|
|
|
|
46
|
|
|
$profiles = $security->getAdminProfiles(); |
|
47
|
|
|
$this->assertArrayHasKey(Security::ADMIN_ID_TOKEN, $profiles, 'Malformed array'); |
|
48
|
|
|
$this->assertArrayHasKey(Security::MANAGER_ID_TOKEN, $profiles, 'Malformed array'); |
|
49
|
|
|
$this->assertArrayHasKey(Security::USER_ID_TOKEN, $profiles, 'Malformed array'); |
|
50
|
|
|
|
|
51
|
|
|
$cleanProfiles = $security->getAdminCleanProfiles(); |
|
52
|
|
|
$this->assertNotEmpty($cleanProfiles, 'Malformed security profiles array'); |
|
53
|
|
|
$this->assertTrue(in_array(Security::ADMIN_ID_TOKEN, $cleanProfiles, true), 'Key not exists'); |
|
54
|
|
|
$this->assertTrue(in_array(Security::MANAGER_ID_TOKEN, $cleanProfiles, true), 'Key not exists'); |
|
55
|
|
|
$this->assertTrue(in_array(Security::USER_ID_TOKEN, $cleanProfiles, true), 'Key not exists'); |
|
56
|
|
|
return $security; |
|
57
|
|
|
} |
|
58
|
|
|
|
|
59
|
|
|
/** |
|
60
|
|
|
* @depends testSecurityBasics |
|
61
|
|
|
* @return Security |
|
62
|
|
|
* @throws GeneratorException |
|
63
|
|
|
*/ |
|
64
|
|
|
public function testSecurityUserManagement(): Security |
|
65
|
|
|
{ |
|
66
|
|
|
$user = [ |
|
67
|
|
|
'username' => uniqid('test', true), |
|
68
|
|
|
'password' => uniqid('test', true), |
|
69
|
|
|
'profile' => Security::ADMIN_ID_TOKEN, |
|
70
|
|
|
]; |
|
71
|
|
|
$security = $this->getInstance(); |
|
72
|
|
|
$security->saveUser($user); |
|
73
|
|
|
|
|
74
|
|
|
$this->assertFileExists(CONFIG_DIR . DIRECTORY_SEPARATOR . 'admins.json', 'Error trying to save admins'); |
|
75
|
|
|
$this->assertNull($security->getUser()); |
|
76
|
|
|
$this->assertNull($security->getAdmin()); |
|
77
|
|
|
$this->assertTrue($security->canDo('something')); |
|
78
|
|
|
$this->assertFalse($security->isLogged()); |
|
79
|
|
|
$this->assertFalse($security->isAdmin()); |
|
80
|
|
|
|
|
81
|
|
|
$security->updateUser($user); |
|
82
|
|
|
$this->assertNotNull($security->getUser(), 'An error occurred when update user in session'); |
|
83
|
|
|
$this->assertFalse($security->checkAdmin(uniqid('test', true), uniqid('error', true), true), 'Error checking admin user'); |
|
84
|
|
|
$this->assertNull($security->getAdmin(), 'Wrong admin parser'); |
|
85
|
|
|
|
|
86
|
|
|
$_COOKIE[substr(Security::MANAGER_ID_TOKEN, 0, 8)] = base64_encode($user['username'] . ':' . $user['password']); |
|
87
|
|
|
Request::getInstance()->init(); |
|
88
|
|
|
$this->assertTrue($security->checkAdmin(null, null, true), 'An error occurred verifying the admin user'); |
|
89
|
|
|
AdminServices::setTest(true); |
|
90
|
|
|
$admins = AdminServices::getInstance()->getAdmins(); |
|
91
|
|
|
$this->assertArrayHasKey($user['username'], $admins, 'Admin is not into credentials file'); |
|
92
|
|
|
$this->assertEquals($user['profile'], $admins[$user['username']]['profile'], 'Admin user with different profile'); |
|
93
|
|
|
$admin = $security->getAdmin(); |
|
94
|
|
|
$this->assertNotNull($admin, 'An error ocurred gathering the admin user'); |
|
95
|
|
|
$this->assertEquals($admin['alias'], $user['username'], 'Wrong data gathered from admins.json'); |
|
96
|
|
|
$this->assertEquals($admin['profile'], $user['profile'], 'Wrong profile gathered from admins.json'); |
|
97
|
|
|
$this->assertTrue($security->isSuperAdmin(), 'Wrong checking for super admin profile'); |
|
98
|
|
|
$this->assertTrue($security->isLogged()); |
|
99
|
|
|
$this->assertTrue($security->isAdmin()); |
|
100
|
|
|
|
|
101
|
|
|
$security->updateSession(true); |
|
102
|
|
|
$this->assertNotEmpty($security->getSessionKey(Security::ADMIN_ID_TOKEN), 'Error saving sessions'); |
|
103
|
|
|
return $security; |
|
104
|
|
|
|
|
105
|
|
|
} |
|
106
|
|
|
|
|
107
|
|
|
/** |
|
108
|
|
|
* @param Security $security |
|
109
|
|
|
* @depends testSecurityUserManagement |
|
110
|
|
|
* @throws Exception |
|
111
|
|
|
*/ |
|
112
|
|
|
public function testSessionHandler(Security $security) |
|
113
|
|
|
{ |
|
114
|
|
|
|
|
115
|
|
|
$testValue = random_int(0, 1e5); |
|
116
|
|
|
$security->setSessionKey('test', $testValue); |
|
117
|
|
|
$this->assertNotNull($security->getSessionKey('test'), 'Error trying to gather the session key'); |
|
118
|
|
|
$this->assertEquals($security->getSessionKey('test'), $testValue, 'The session key value is not the same than expected'); |
|
119
|
|
|
|
|
120
|
|
|
$flashValue = 'test value for flash'; |
|
121
|
|
|
$security->setFlash('flash_test', $flashValue); |
|
122
|
|
|
$security->updateSession(); |
|
123
|
|
|
$this->assertNotEmpty($security->getFlashes(), 'Flash key not saved'); |
|
124
|
|
|
$gatherData = $security->getFlash('flash_test'); |
|
125
|
|
|
$this->assertNotNull($gatherData, 'Error trying to gather the flash key'); |
|
126
|
|
|
$this->assertEquals($flashValue, $gatherData, 'Error gathering the flash data, there is not the same data than expected'); |
|
127
|
|
|
$security->clearFlashes(); |
|
128
|
|
|
$this->assertNull($security->getFlash('flash_test'), 'Flash key not deleted'); |
|
129
|
|
|
$this->assertEmpty($security->getFlashes(), 'Flash with data yet'); |
|
130
|
|
|
$security->closeSession(); |
|
131
|
|
|
} |
|
132
|
|
|
|
|
133
|
|
|
} |