use OCA\DAV\CalDAV\BirthdayService;
use OCA\DAV\CalDAV\CalendarHome;
use OCP\IConfig;
+use OCP\IUser;
use Sabre\DAV\Server;
use Sabre\DAV\ServerPlugin;
use Sabre\HTTP\RequestInterface;
*/
protected $server;
+ /** @var IUser */
+ private $user;
+
/**
* PublishPlugin constructor.
*
* @param IConfig $config
* @param BirthdayService $birthdayService
+ * @param IUser $user
*/
- public function __construct(IConfig $config, BirthdayService $birthdayService) {
+ public function __construct(IConfig $config, BirthdayService $birthdayService, IUser $user) {
$this->config = $config;
$this->birthdayService = $birthdayService;
+ $this->user = $user;
}
/**
return;
}
- $principalUri = $node->getOwner();
- $userId = substr($principalUri, 17);
+ $owner = substr($node->getOwner(), 17);
+ if($owner !== $this->user->getUID()) {
+ $this->server->httpResponse->setStatus(403);
+ return false;
+ }
- $this->config->setUserValue($userId, 'dav', 'generateBirthdayCalendar', 'yes');
- $this->birthdayService->syncUser($userId);
+ $this->config->setUserValue($this->user->getUID(), 'dav', 'generateBirthdayCalendar', 'yes');
+ $this->birthdayService->syncUser($this->user->getUID());
$this->server->httpResponse->setStatus(204);
use OCA\DAV\CalDAV\Calendar;
use OCA\DAV\CalDAV\CalendarHome;
use OCP\IConfig;
+use OCP\IUser;
use Test\TestCase;
class EnablePluginTest extends TestCase {
/** @var BirthdayService |\PHPUnit\Framework\MockObject\MockObject */
protected $birthdayService;
+ /** @var IUser|\PHPUnit\Framework\MockObject\MockObject */
+ protected $user;
+
/** @var \OCA\DAV\CalDAV\BirthdayCalendar\EnablePlugin $plugin */
protected $plugin;
$this->config = $this->createMock(IConfig::class);
$this->birthdayService = $this->createMock(BirthdayService::class);
+ $this->user = $this->createMock(IUser::class);
- $this->plugin = new EnablePlugin($this->config, $this->birthdayService);
+ $this->plugin = new EnablePlugin($this->config, $this->birthdayService, $this->user);
$this->plugin->initialize($this->server);
$this->request = $this->createMock(\Sabre\HTTP\RequestInterface::class);
public function testInitialize(): void {
$server = $this->createMock(\Sabre\DAV\Server::class);
- $plugin = new EnablePlugin($this->config, $this->birthdayService);
+ $plugin = new EnablePlugin($this->config, $this->birthdayService, $this->user);
$server->expects($this->once())
->method('on')
$this->plugin->httpPost($this->request, $this->response);
}
+ public function testHttpPostNotAuthorized(): void {
+ $calendarHome = $this->createMock(CalendarHome::class);
+
+ $this->server->expects($this->once())
+ ->method('getRequestUri')
+ ->willReturn('/bar/foo');
+ $this->server->tree->expects($this->once())
+ ->method('getNodeForPath')
+ ->with('/bar/foo')
+ ->willReturn($calendarHome);
+
+ $calendarHome->expects($this->once())
+ ->method('getOwner')
+ ->willReturn('principals/users/BlaBlub');
+
+ $this->request->expects($this->once())
+ ->method('getBodyAsString')
+ ->willReturn('<nc:enable-birthday-calendar xmlns:nc="http://nextcloud.com/ns"/>');
+
+ $this->request->expects($this->once())
+ ->method('getUrl')
+ ->willReturn('url_abc');
+
+ $this->server->xml->expects($this->once())
+ ->method('parse')
+ ->willReturnCallback(function ($requestBody, $url, &$documentType): void {
+ $documentType = '{http://nextcloud.com/ns}enable-birthday-calendar';
+ });
+
+ $this->user->expects(self::once())
+ ->method('getUID')
+ ->willReturn('admin');
+
+ $this->server->httpResponse->expects($this->once())
+ ->method('setStatus')
+ ->with(403);
+
+ $this->config->expects($this->never())
+ ->method('setUserValue');
+
+ $this->birthdayService->expects($this->never())
+ ->method('syncUser');
+
+
+ $result = $this->plugin->httpPost($this->request, $this->response);
+
+ $this->assertEquals(false, $result);
+ }
+
public function testHttpPost(): void {
$calendarHome = $this->createMock(CalendarHome::class);
$documentType = '{http://nextcloud.com/ns}enable-birthday-calendar';
});
+ $this->user->expects(self::exactly(3))
+ ->method('getUID')
+ ->willReturn('BlaBlub');
+
$this->config->expects($this->once())
->method('setUserValue')
->with('BlaBlub', 'dav', 'generateBirthdayCalendar', 'yes');