You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

token_test.rb 5.0KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140
  1. # Redmine - project management software
  2. # Copyright (C) 2006-2017 Jean-Philippe Lang
  3. #
  4. # This program is free software; you can redistribute it and/or
  5. # modify it under the terms of the GNU General Public License
  6. # as published by the Free Software Foundation; either version 2
  7. # of the License, or (at your option) any later version.
  8. #
  9. # This program is distributed in the hope that it will be useful,
  10. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. # GNU General Public License for more details.
  13. #
  14. # You should have received a copy of the GNU General Public License
  15. # along with this program; if not, write to the Free Software
  16. # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  17. require File.expand_path('../../test_helper', __FILE__)
  18. class TokenTest < ActiveSupport::TestCase
  19. fixtures :tokens, :users, :email_addresses
  20. def setup
  21. User.current = nil
  22. end
  23. def test_create
  24. token = Token.new
  25. token.save
  26. assert_equal 40, token.value.length
  27. assert !token.expired?
  28. end
  29. def test_create_should_remove_existing_tokens
  30. user = User.find(1)
  31. t1 = Token.create(:user => user, :action => 'register')
  32. t2 = Token.create(:user => user, :action => 'register')
  33. assert_not_equal t1.value, t2.value
  34. assert !Token.exists?(t1.id)
  35. assert Token.exists?(t2.id)
  36. end
  37. def test_create_session_or_autologin_token_should_keep_last_10_tokens
  38. Token.delete_all
  39. user = User.find(1)
  40. ["autologin", "session"].each do |action|
  41. assert_difference 'Token.count', 10 do
  42. 10.times { Token.create!(:user => user, :action => action) }
  43. end
  44. assert_no_difference 'Token.count' do
  45. Token.create!(:user => user, :action => action)
  46. end
  47. end
  48. end
  49. def test_destroy_expired_should_not_destroy_session_feeds_and_api_tokens
  50. Token.delete_all
  51. Token.create!(:user_id => 1, :action => 'api', :created_on => 7.days.ago)
  52. Token.create!(:user_id => 1, :action => 'feeds', :created_on => 7.days.ago)
  53. Token.create!(:user_id => 1, :action => 'session', :created_on => 7.days.ago)
  54. assert_no_difference 'Token.count' do
  55. assert_equal 0, Token.destroy_expired
  56. end
  57. end
  58. def test_destroy_expired_should_destroy_expired_tokens
  59. Token.delete_all
  60. # Expiration of autologin tokens is determined by Setting.autologin
  61. Setting.autologin = "7"
  62. Token.create!(:user_id => 2, :action => 'autologin', :created_on => 3.weeks.ago)
  63. Token.create!(:user_id => 3, :action => 'autologin', :created_on => 3.days.ago)
  64. # Expiration of register and recovery tokens is determined by Token.validity_time
  65. Token.create!(:user_id => 1, :action => 'register', :created_on => 7.days.ago)
  66. Token.create!(:user_id => 3, :action => 'register', :created_on => 7.hours.ago)
  67. Token.create!(:user_id => 2, :action => 'recovery', :created_on => 3.days.ago)
  68. Token.create!(:user_id => 3, :action => 'recovery', :created_on => 3.hours.ago)
  69. # Expiration of tokens with unknown action is determined by Token.validity_time
  70. Token.create!(:user_id => 2, :action => 'unknown_action', :created_on => 2.days.ago)
  71. Token.create!(:user_id => 3, :action => 'unknown_action', :created_on => 2.hours.ago)
  72. assert_difference 'Token.count', -4 do
  73. assert_equal 4, Token.destroy_expired
  74. end
  75. end
  76. def test_find_active_user_should_return_user
  77. token = Token.create!(:user_id => 1, :action => 'api')
  78. assert_equal User.find(1), Token.find_active_user('api', token.value)
  79. end
  80. def test_find_active_user_should_return_nil_for_locked_user
  81. token = Token.create!(:user_id => 1, :action => 'api')
  82. User.find(1).lock!
  83. assert_nil Token.find_active_user('api', token.value)
  84. end
  85. def test_find_user_should_return_user
  86. token = Token.create!(:user_id => 1, :action => 'api')
  87. assert_equal User.find(1), Token.find_user('api', token.value)
  88. end
  89. def test_find_user_should_return_locked_user
  90. token = Token.create!(:user_id => 1, :action => 'api')
  91. User.find(1).lock!
  92. assert_equal User.find(1), Token.find_user('api', token.value)
  93. end
  94. def test_find_token_should_return_the_token
  95. token = Token.create!(:user_id => 1, :action => 'api')
  96. assert_equal token, Token.find_token('api', token.value)
  97. end
  98. def test_find_token_should_return_the_token_with_validity
  99. token = Token.create!(:user_id => 1, :action => 'api', :created_on => 1.hour.ago)
  100. assert_equal token, Token.find_token('api', token.value, 1)
  101. end
  102. def test_find_token_should_return_nil_with_wrong_action
  103. token = Token.create!(:user_id => 1, :action => 'feeds')
  104. assert_nil Token.find_token('api', token.value)
  105. end
  106. def test_find_token_should_return_nil_without_user
  107. token = Token.create!(:user_id => 999, :action => 'api')
  108. assert_nil Token.find_token('api', token.value)
  109. end
  110. def test_find_token_should_return_nil_with_validity_expired
  111. token = Token.create!(:user_id => 999, :action => 'api', :created_on => 2.days.ago)
  112. assert_nil Token.find_token('api', token.value, 1)
  113. end
  114. end