You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

sessions_controller_test.rb 5.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189
  1. # frozen_string_literal: true
  2. # Redmine - project management software
  3. # Copyright (C) 2006- Jean-Philippe Lang
  4. #
  5. # This program is free software; you can redistribute it and/or
  6. # modify it under the terms of the GNU General Public License
  7. # as published by the Free Software Foundation; either version 2
  8. # of the License, or (at your option) any later version.
  9. #
  10. # This program is distributed in the hope that it will be useful,
  11. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. # GNU General Public License for more details.
  14. #
  15. # You should have received a copy of the GNU General Public License
  16. # along with this program; if not, write to the Free Software
  17. # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  18. require_relative '../test_helper'
  19. class SessionsControllerTest < Redmine::ControllerTest
  20. include Redmine::I18n
  21. tests WelcomeController
  22. fixtures :users, :email_addresses
  23. def setup
  24. Rails.application.config.redmine_verify_sessions = true
  25. end
  26. def teardown
  27. Rails.application.config.redmine_verify_sessions = false
  28. end
  29. def test_session_token_should_be_updated
  30. token = Token.create!(:user_id => 2, :action => 'session', :created_on => 10.hours.ago, :updated_on => 10.hours.ago)
  31. created = token.reload.created_on
  32. get(:index, :session => {:user_id => 2, :tk => token.value})
  33. assert_response :success
  34. token.reload
  35. assert_equal created.to_i, token.created_on.to_i
  36. assert_not_equal created.to_i, token.updated_on.to_i
  37. assert token.updated_on > created
  38. end
  39. def test_session_token_should_be_updated_only_once_per_minute
  40. token = Token.create!(:user_id => 2, :action => 'session', :created_on => 1.second.ago, :updated_on => 1.second.ago)
  41. updated = token.reload.updated_on
  42. get :index, :session => {
  43. :user_id => 2,
  44. :tk => token.value
  45. }
  46. assert_response :success
  47. token.reload
  48. assert_equal updated.to_i, token.updated_on.to_i
  49. end
  50. def test_user_session_should_not_be_reset_if_lifetime_and_timeout_disabled
  51. created = 2.years.ago
  52. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  53. with_settings :session_lifetime => '0', :session_timeout => '0' do
  54. get(:index, :session => {:user_id => 2, :tk => token.value})
  55. assert_response :success
  56. end
  57. end
  58. def test_user_session_without_token_should_be_reset
  59. get(:index, :session => {:user_id => 2})
  60. assert_redirected_to 'http://test.host/login?back_url=http%3A%2F%2Ftest.host%2F'
  61. end
  62. def test_expired_user_session_should_be_reset_if_lifetime_enabled
  63. created = 2.days.ago
  64. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  65. with_settings :session_timeout => '720' do
  66. get(
  67. :index,
  68. :session => {
  69. :user_id => 2,
  70. :tk => token.value
  71. }
  72. )
  73. assert_redirected_to 'http://test.host/login?back_url=http%3A%2F%2Ftest.host%2F'
  74. end
  75. end
  76. def test_valid_user_session_should_not_be_reset_if_lifetime_enabled
  77. created = 3.hours.ago
  78. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  79. with_settings :session_timeout => '720' do
  80. get(
  81. :index,
  82. :session => {
  83. :user_id => 2,
  84. :tk => token.value
  85. }
  86. )
  87. assert_response :success
  88. end
  89. end
  90. def test_expired_user_session_should_be_reset_if_timeout_enabled
  91. created = 4.hours.ago
  92. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  93. with_settings :session_timeout => '60' do
  94. get(
  95. :index,
  96. :session => {
  97. :user_id => 2,
  98. :tk => token.value
  99. }
  100. )
  101. assert_redirected_to 'http://test.host/login?back_url=http%3A%2F%2Ftest.host%2F'
  102. end
  103. end
  104. def test_valid_user_session_should_not_be_reset_if_timeout_enabled
  105. created = 10.minutes.ago
  106. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  107. with_settings :session_timeout => '60' do
  108. get(
  109. :index,
  110. :session => {
  111. :user_id => 2,
  112. :tk => token.value
  113. }
  114. )
  115. assert_response :success
  116. end
  117. end
  118. def test_expired_user_session_should_be_restarted_if_autologin
  119. created = 2.hours.ago
  120. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  121. with_settings :session_lifetime => '720', :session_timeout => '60', :autologin => 7 do
  122. autologin_token = Token.create!(:user_id => 2, :action => 'autologin', :created_on => 1.day.ago)
  123. @request.cookies['autologin'] = autologin_token.value
  124. get(
  125. :index,
  126. :session => {
  127. :user_id => 2,
  128. :tk => token.value
  129. }
  130. )
  131. assert_equal 2, session[:user_id]
  132. assert_response :success
  133. assert_not_equal token.value, session[:tk]
  134. end
  135. end
  136. def test_expired_user_session_should_set_locale
  137. set_language_if_valid 'it'
  138. user = User.find(2)
  139. user.language = 'fr'
  140. user.save!
  141. created = 4.hours.ago
  142. token = Token.create!(:user_id => 2, :action => 'session', :created_on => created, :updated_on => created)
  143. with_settings :session_timeout => '60' do
  144. get(
  145. :index,
  146. :session => {
  147. :user_id => user.id,
  148. :tk => token.value
  149. }
  150. )
  151. assert_redirected_to 'http://test.host/login?back_url=http%3A%2F%2Ftest.host%2F'
  152. assert_include "Veuillez vous reconnecter", flash[:error]
  153. assert_equal :fr, current_language
  154. end
  155. end
  156. def test_anonymous_session_should_not_be_reset
  157. with_settings :session_lifetime => '720', :session_timeout => '60' do
  158. get :index
  159. assert_response :success
  160. end
  161. end
  162. end