You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

api_user_search_test.go 2.8KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394
  1. // Copyright 2019 The Gitea Authors. All rights reserved.
  2. // SPDX-License-Identifier: MIT
  3. package integration
  4. import (
  5. "fmt"
  6. "net/http"
  7. "testing"
  8. auth_model "code.gitea.io/gitea/models/auth"
  9. "code.gitea.io/gitea/models/unittest"
  10. user_model "code.gitea.io/gitea/models/user"
  11. "code.gitea.io/gitea/modules/setting"
  12. api "code.gitea.io/gitea/modules/structs"
  13. "code.gitea.io/gitea/tests"
  14. "github.com/stretchr/testify/assert"
  15. )
  16. type SearchResults struct {
  17. OK bool `json:"ok"`
  18. Data []*api.User `json:"data"`
  19. }
  20. func TestAPIUserSearchLoggedIn(t *testing.T) {
  21. defer tests.PrepareTestEnv(t)()
  22. adminUsername := "user1"
  23. session := loginUser(t, adminUsername)
  24. token := getTokenForLoggedInUser(t, session, auth_model.AccessTokenScopeReadUser)
  25. query := "user2"
  26. req := NewRequestf(t, "GET", "/api/v1/users/search?token=%s&q=%s", token, query)
  27. resp := MakeRequest(t, req, http.StatusOK)
  28. var results SearchResults
  29. DecodeJSON(t, resp, &results)
  30. assert.NotEmpty(t, results.Data)
  31. for _, user := range results.Data {
  32. assert.Contains(t, user.UserName, query)
  33. assert.NotEmpty(t, user.Email)
  34. }
  35. }
  36. func TestAPIUserSearchNotLoggedIn(t *testing.T) {
  37. defer tests.PrepareTestEnv(t)()
  38. query := "user2"
  39. req := NewRequestf(t, "GET", "/api/v1/users/search?q=%s", query)
  40. resp := MakeRequest(t, req, http.StatusOK)
  41. var results SearchResults
  42. DecodeJSON(t, resp, &results)
  43. assert.NotEmpty(t, results.Data)
  44. var modelUser *user_model.User
  45. for _, user := range results.Data {
  46. assert.Contains(t, user.UserName, query)
  47. modelUser = unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: user.ID})
  48. if modelUser.KeepEmailPrivate {
  49. assert.EqualValues(t, fmt.Sprintf("%s@%s", modelUser.LowerName, setting.Service.NoReplyAddress), user.Email)
  50. } else {
  51. assert.EqualValues(t, modelUser.Email, user.Email)
  52. }
  53. }
  54. }
  55. func TestAPIUserSearchAdminLoggedInUserHidden(t *testing.T) {
  56. defer tests.PrepareTestEnv(t)()
  57. adminUsername := "user1"
  58. session := loginUser(t, adminUsername)
  59. token := getTokenForLoggedInUser(t, session, auth_model.AccessTokenScopeReadUser)
  60. query := "user31"
  61. req := NewRequestf(t, "GET", "/api/v1/users/search?token=%s&q=%s", token, query)
  62. req.SetBasicAuth(token, "x-oauth-basic")
  63. resp := MakeRequest(t, req, http.StatusOK)
  64. var results SearchResults
  65. DecodeJSON(t, resp, &results)
  66. assert.NotEmpty(t, results.Data)
  67. for _, user := range results.Data {
  68. assert.Contains(t, user.UserName, query)
  69. assert.NotEmpty(t, user.Email)
  70. assert.EqualValues(t, "private", user.Visibility)
  71. }
  72. }
  73. func TestAPIUserSearchNotLoggedInUserHidden(t *testing.T) {
  74. defer tests.PrepareTestEnv(t)()
  75. query := "user31"
  76. req := NewRequestf(t, "GET", "/api/v1/users/search?q=%s", query)
  77. resp := MakeRequest(t, req, http.StatusOK)
  78. var results SearchResults
  79. DecodeJSON(t, resp, &results)
  80. assert.Empty(t, results.Data)
  81. }