You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

user_test.rb 45KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351
  1. # frozen_string_literal: true
  2. # Redmine - project management software
  3. # Copyright (C) 2006-2021 Jean-Philippe Lang
  4. #
  5. # This program is free software; you can redistribute it and/or
  6. # modify it under the terms of the GNU General Public License
  7. # as published by the Free Software Foundation; either version 2
  8. # of the License, or (at your option) any later version.
  9. #
  10. # This program is distributed in the hope that it will be useful,
  11. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. # GNU General Public License for more details.
  14. #
  15. # You should have received a copy of the GNU General Public License
  16. # along with this program; if not, write to the Free Software
  17. # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  18. require File.expand_path('../../test_helper', __FILE__)
  19. class UserTest < ActiveSupport::TestCase
  20. fixtures :users, :email_addresses, :members, :projects, :roles, :member_roles, :auth_sources,
  21. :trackers, :issue_statuses,
  22. :projects_trackers,
  23. :watchers,
  24. :issue_categories, :enumerations, :issues,
  25. :journals, :journal_details,
  26. :groups_users,
  27. :enabled_modules,
  28. :tokens,
  29. :user_preferences,
  30. :custom_fields, :custom_fields_projects, :custom_fields_trackers, :custom_values
  31. include Redmine::I18n
  32. def setup
  33. @admin = User.find(1)
  34. @jsmith = User.find(2)
  35. @dlopper = User.find(3)
  36. User.current = nil
  37. end
  38. def test_admin_scope_without_args_should_return_admin_users
  39. users = User.admin.to_a
  40. assert users.any?
  41. assert users.all? {|u| u.admin == true}
  42. end
  43. def test_admin_scope_with_true_should_return_admin_users
  44. users = User.admin(true).to_a
  45. assert users.any?
  46. assert users.all? {|u| u.admin == true}
  47. end
  48. def test_admin_scope_with_false_should_return_non_admin_users
  49. users = User.admin(false).to_a
  50. assert users.any?
  51. assert users.all? {|u| u.admin == false}
  52. end
  53. def test_sorted_scope_should_sort_user_by_display_name
  54. # Use .active to ignore anonymous with localized display name
  55. assert_equal User.active.map(&:name).map(&:downcase).sort,
  56. User.active.sorted.map(&:name).map(&:downcase)
  57. end
  58. def test_generate
  59. User.generate!(:firstname => 'Testing connection')
  60. User.generate!(:firstname => 'Testing connection')
  61. assert_equal 2, User.where(:firstname => 'Testing connection').count
  62. end
  63. def test_truth
  64. assert_kind_of User, @jsmith
  65. end
  66. def test_should_validate_status
  67. user = User.new
  68. user.status = 0
  69. assert !user.save
  70. assert_include I18n.translate('activerecord.errors.messages.invalid'), user.errors[:status]
  71. end
  72. def test_mail_should_be_stripped
  73. u = User.new
  74. u.mail = " foo@bar.com "
  75. assert_equal "foo@bar.com", u.mail
  76. end
  77. def test_should_create_email_address
  78. u = User.new(:firstname => "new", :lastname => "user")
  79. u.login = "create_email_address"
  80. u.mail = "defaultemail@somenet.foo"
  81. assert u.save
  82. u.reload
  83. assert u.email_address
  84. assert_equal "defaultemail@somenet.foo", u.email_address.address
  85. assert_equal true, u.email_address.is_default
  86. assert_equal true, u.email_address.notify
  87. end
  88. def test_should_not_create_user_without_mail
  89. set_language_if_valid 'en'
  90. u = User.new(:firstname => "new", :lastname => "user")
  91. u.login = "user_without_mail"
  92. assert !u.save
  93. assert_equal ["Email #{I18n.translate('activerecord.errors.messages.blank')}"], u.errors.full_messages
  94. end
  95. def test_should_not_create_user_with_blank_mail
  96. set_language_if_valid 'en'
  97. u = User.new(:firstname => "new", :lastname => "user")
  98. u.login = "user_with_blank_mail"
  99. u.mail = ''
  100. assert !u.save
  101. assert_equal ["Email #{I18n.translate('activerecord.errors.messages.blank')}"], u.errors.full_messages
  102. end
  103. def test_should_not_update_user_with_blank_mail
  104. set_language_if_valid 'en'
  105. u = User.find(2)
  106. u.mail = ''
  107. assert !u.save
  108. assert_equal ["Email #{I18n.translate('activerecord.errors.messages.blank')}"], u.errors.full_messages
  109. end
  110. def test_login_length_validation
  111. user = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  112. user.login = "x" * (User::LOGIN_LENGTH_LIMIT+1)
  113. assert !user.valid?
  114. user.login = "x" * (User::LOGIN_LENGTH_LIMIT)
  115. assert user.valid?
  116. assert user.save
  117. end
  118. def test_generate_password_should_respect_minimum_password_length
  119. with_settings :password_min_length => 15 do
  120. user = User.generate!(:generate_password => true)
  121. assert user.password.length >= 15
  122. end
  123. end
  124. def test_generate_password_should_not_generate_password_with_less_than_10_characters
  125. with_settings :password_min_length => 4 do
  126. user = User.generate!(:generate_password => true)
  127. assert user.password.length >= 10
  128. end
  129. end
  130. def test_generate_password_on_create_should_set_password
  131. user = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  132. user.login = "newuser"
  133. user.generate_password = true
  134. assert user.save
  135. password = user.password
  136. assert user.check_password?(password)
  137. end
  138. def test_generate_password_on_update_should_update_password
  139. user = User.find(2)
  140. hash = user.hashed_password
  141. user.generate_password = true
  142. assert user.save
  143. password = user.password
  144. assert user.check_password?(password)
  145. assert_not_equal hash, user.reload.hashed_password
  146. end
  147. def test_create
  148. user = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  149. user.login = "jsmith"
  150. user.password, user.password_confirmation = "password", "password"
  151. # login uniqueness
  152. assert !user.save
  153. assert_equal 1, user.errors.count
  154. user.login = "newuser"
  155. user.password, user.password_confirmation = "password", "pass"
  156. # password confirmation
  157. assert !user.save
  158. assert_equal 1, user.errors.count
  159. user.password, user.password_confirmation = "password", "password"
  160. assert user.save
  161. end
  162. def test_user_before_create_should_set_the_mail_notification_to_the_default_setting
  163. @user1 = User.generate!
  164. assert_equal 'only_my_events', @user1.mail_notification
  165. with_settings :default_notification_option => 'all' do
  166. @user2 = User.generate!
  167. assert_equal 'all', @user2.mail_notification
  168. end
  169. end
  170. def test_user_login_should_be_case_insensitive
  171. u = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  172. u.login = 'newuser'
  173. u.password, u.password_confirmation = "password", "password"
  174. assert u.save
  175. u = User.new(:firstname => "Similar", :lastname => "User",
  176. :mail => "similaruser@somenet.foo")
  177. u.login = 'NewUser'
  178. u.password, u.password_confirmation = "password", "password"
  179. assert !u.save
  180. assert_include I18n.translate('activerecord.errors.messages.taken'), u.errors[:login]
  181. end
  182. def test_mail_uniqueness_should_not_be_case_sensitive
  183. set_language_if_valid 'en'
  184. u = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  185. u.login = 'newuser1'
  186. u.password, u.password_confirmation = "password", "password"
  187. assert u.save
  188. u = User.new(:firstname => "new", :lastname => "user", :mail => "newUser@Somenet.foo")
  189. u.login = 'newuser2'
  190. u.password, u.password_confirmation = "password", "password"
  191. assert !u.save
  192. assert_include "Email #{I18n.translate('activerecord.errors.messages.taken')}", u.errors.full_messages
  193. end
  194. def test_update
  195. assert_equal "admin", @admin.login
  196. @admin.login = "john"
  197. assert @admin.save, @admin.errors.full_messages.join("; ")
  198. @admin.reload
  199. assert_equal "john", @admin.login
  200. end
  201. def test_update_should_not_fail_for_legacy_user_with_different_case_logins
  202. u1 = User.new(:firstname => "new", :lastname => "user", :mail => "newuser1@somenet.foo")
  203. u1.login = 'newuser1'
  204. assert u1.save
  205. u2 = User.new(:firstname => "new", :lastname => "user", :mail => "newuser2@somenet.foo")
  206. u2.login = 'newuser1'
  207. assert u2.save(:validate => false)
  208. user = User.find(u2.id)
  209. user.firstname = "firstname"
  210. assert user.save, "Save failed"
  211. end
  212. def test_destroy_should_delete_members_and_roles
  213. members = Member.where(:user_id => 2)
  214. ms = members.count
  215. rs = members.collect(&:roles).flatten.size
  216. assert ms > 0
  217. assert rs > 0
  218. assert_difference 'Member.count', - ms do
  219. assert_difference 'MemberRole.count', - rs do
  220. User.find(2).destroy
  221. end
  222. end
  223. assert_nil User.find_by_id(2)
  224. assert_equal 0, Member.where(:user_id => 2).count
  225. end
  226. def test_destroy_should_update_attachments
  227. set_tmp_attachments_directory
  228. attachment = Attachment.create!(:container => Project.find(1),
  229. :file => uploaded_test_file("testfile.txt", "text/plain"),
  230. :author_id => 2)
  231. User.find(2).destroy
  232. assert_nil User.find_by_id(2)
  233. assert_equal User.anonymous, attachment.reload.author
  234. end
  235. def test_destroy_should_update_comments
  236. comment = Comment.create!(
  237. :commented => News.create!(:project_id => 1,
  238. :author_id => 1, :title => 'foo', :description => 'foo'),
  239. :author => User.find(2),
  240. :comments => 'foo'
  241. )
  242. User.find(2).destroy
  243. assert_nil User.find_by_id(2)
  244. assert_equal User.anonymous, comment.reload.author
  245. end
  246. def test_destroy_should_update_issues
  247. issue = Issue.create!(:project_id => 1, :author_id => 2,
  248. :tracker_id => 1, :subject => 'foo')
  249. User.find(2).destroy
  250. assert_nil User.find_by_id(2)
  251. assert_equal User.anonymous, issue.reload.author
  252. end
  253. def test_destroy_should_unassign_issues
  254. issue = Issue.create!(:project_id => 1, :author_id => 1,
  255. :tracker_id => 1, :subject => 'foo', :assigned_to_id => 2)
  256. User.find(2).destroy
  257. assert_nil User.find_by_id(2)
  258. assert_nil issue.reload.assigned_to
  259. end
  260. def test_destroy_should_update_journals
  261. issue = Issue.generate!(:project_id => 1, :author_id => 2,
  262. :tracker_id => 1, :subject => 'foo')
  263. issue.init_journal(User.find(2), "update")
  264. issue.save!
  265. User.find(2).destroy
  266. assert_nil User.find_by_id(2)
  267. assert_equal User.anonymous, issue.journals.first.reload.user
  268. end
  269. def test_destroy_should_update_journal_details_old_value
  270. issue = Issue.generate!(:project_id => 1, :author_id => 1,
  271. :tracker_id => 1, :subject => 'foo', :assigned_to_id => 2)
  272. issue.init_journal(User.find(1), "update")
  273. issue.assigned_to_id = nil
  274. assert_difference 'JournalDetail.count' do
  275. issue.save!
  276. end
  277. journal_detail = JournalDetail.order('id DESC').first
  278. assert_equal '2', journal_detail.old_value
  279. User.find(2).destroy
  280. assert_nil User.find_by_id(2)
  281. assert_equal User.anonymous.id.to_s, journal_detail.reload.old_value
  282. end
  283. def test_destroy_should_update_journal_details_value
  284. issue = Issue.generate!(:project_id => 1, :author_id => 1,
  285. :tracker_id => 1, :subject => 'foo')
  286. issue.init_journal(User.find(1), "update")
  287. issue.assigned_to_id = 2
  288. assert_difference 'JournalDetail.count' do
  289. issue.save!
  290. end
  291. journal_detail = JournalDetail.order('id DESC').first
  292. assert_equal '2', journal_detail.value
  293. User.find(2).destroy
  294. assert_nil User.find_by_id(2)
  295. assert_equal User.anonymous.id.to_s, journal_detail.reload.value
  296. end
  297. def test_destroy_should_update_messages
  298. board = Board.create!(:project_id => 1, :name => 'Board', :description => 'Board')
  299. message = Message.create!(:board_id => board.id, :author_id => 2,
  300. :subject => 'foo', :content => 'foo')
  301. User.find(2).destroy
  302. assert_nil User.find_by_id(2)
  303. assert_equal User.anonymous, message.reload.author
  304. end
  305. def test_destroy_should_update_news
  306. news = News.create!(:project_id => 1, :author_id => 2,
  307. :title => 'foo', :description => 'foo')
  308. User.find(2).destroy
  309. assert_nil User.find_by_id(2)
  310. assert_equal User.anonymous, news.reload.author
  311. end
  312. def test_destroy_should_delete_private_queries
  313. query = Query.new(:name => 'foo', :visibility => Query::VISIBILITY_PRIVATE)
  314. query.project_id = 1
  315. query.user_id = 2
  316. query.save!
  317. User.find(2).destroy
  318. assert_nil User.find_by_id(2)
  319. assert_nil Query.find_by_id(query.id)
  320. end
  321. def test_destroy_should_update_public_queries
  322. query = Query.new(:name => 'foo', :visibility => Query::VISIBILITY_PUBLIC)
  323. query.project_id = 1
  324. query.user_id = 2
  325. query.save!
  326. User.find(2).destroy
  327. assert_nil User.find_by_id(2)
  328. assert_equal User.anonymous, query.reload.user
  329. end
  330. def test_destroy_should_update_time_entries
  331. entry = TimeEntry.new(:hours => '2', :spent_on => Date.today,
  332. :activity => TimeEntryActivity.create!(:name => 'foo'))
  333. entry.project_id = 1
  334. entry.user_id = 2
  335. entry.save!
  336. User.find(2).destroy
  337. assert_nil User.find_by_id(2)
  338. assert_equal User.anonymous, entry.reload.user
  339. end
  340. def test_destroy_should_delete_tokens
  341. token = Token.create!(:user_id => 2, :value => 'foo')
  342. User.find(2).destroy
  343. assert_nil User.find_by_id(2)
  344. assert_nil Token.find_by_id(token.id)
  345. end
  346. def test_destroy_should_delete_watchers
  347. issue = Issue.create!(:project_id => 1, :author_id => 1,
  348. :tracker_id => 1, :subject => 'foo')
  349. watcher = Watcher.create!(:user_id => 2, :watchable => issue)
  350. User.find(2).destroy
  351. assert_nil User.find_by_id(2)
  352. assert_nil Watcher.find_by_id(watcher.id)
  353. end
  354. def test_destroy_should_update_wiki_contents
  355. wiki_content = WikiContent.create!(
  356. :text => 'foo',
  357. :author_id => 2,
  358. :page => WikiPage.create!(:title => 'Foo',
  359. :wiki => Wiki.create!(:project_id => 3,
  360. :start_page => 'Start'))
  361. )
  362. wiki_content.text = 'bar'
  363. assert_difference 'WikiContentVersion.count' do
  364. wiki_content.save!
  365. end
  366. User.find(2).destroy
  367. assert_nil User.find_by_id(2)
  368. assert_equal User.anonymous, wiki_content.reload.author
  369. wiki_content.versions.each do |version|
  370. assert_equal User.anonymous, version.reload.author
  371. end
  372. end
  373. def test_destroy_should_nullify_issue_categories
  374. category = IssueCategory.create!(:project_id => 1, :assigned_to_id => 2, :name => 'foo')
  375. User.find(2).destroy
  376. assert_nil User.find_by_id(2)
  377. assert_nil category.reload.assigned_to_id
  378. end
  379. def test_destroy_should_nullify_changesets
  380. changeset =
  381. Changeset.
  382. create!(
  383. :repository =>
  384. Repository::Subversion.
  385. create!(
  386. :project_id => 1,
  387. :url => 'file:///tmp',
  388. :identifier => 'tmp'
  389. ),
  390. :revision => '12',
  391. :committed_on => Time.now,
  392. :committer => 'jsmith'
  393. )
  394. assert_equal 2, changeset.user_id
  395. User.find(2).destroy
  396. assert_nil User.find_by_id(2)
  397. assert_nil changeset.reload.user_id
  398. end
  399. def test_anonymous_user_should_not_be_destroyable
  400. assert_no_difference 'User.count' do
  401. assert_equal false, User.anonymous.destroy
  402. end
  403. end
  404. def test_password_change_should_destroy_tokens
  405. recovery_token = Token.create!(:user_id => 2, :action => 'recovery')
  406. autologin_token = Token.create!(:user_id => 2, :action => 'autologin')
  407. user = User.find(2)
  408. user.password, user.password_confirmation = "a new password", "a new password"
  409. assert user.save
  410. assert_nil Token.find_by_id(recovery_token.id)
  411. assert_nil Token.find_by_id(autologin_token.id)
  412. end
  413. def test_mail_change_should_destroy_tokens
  414. recovery_token = Token.create!(:user_id => 2, :action => 'recovery')
  415. autologin_token = Token.create!(:user_id => 2, :action => 'autologin')
  416. user = User.find(2)
  417. user.mail = "user@somwehere.com"
  418. assert user.save
  419. assert_nil Token.find_by_id(recovery_token.id)
  420. assert_equal autologin_token, Token.find_by_id(autologin_token.id)
  421. end
  422. def test_change_on_other_fields_should_not_destroy_tokens
  423. recovery_token = Token.create!(:user_id => 2, :action => 'recovery')
  424. autologin_token = Token.create!(:user_id => 2, :action => 'autologin')
  425. user = User.find(2)
  426. user.firstname = "Bobby"
  427. assert user.save
  428. assert_equal recovery_token, Token.find_by_id(recovery_token.id)
  429. assert_equal autologin_token, Token.find_by_id(autologin_token.id)
  430. end
  431. def test_validate_login_presence
  432. @admin.login = ""
  433. assert !@admin.save
  434. assert_equal 1, @admin.errors.count
  435. end
  436. def test_validate_mail_notification_inclusion
  437. u = User.new
  438. u.mail_notification = 'foo'
  439. u.save
  440. assert_not_equal [], u.errors[:mail_notification]
  441. end
  442. def test_password
  443. user = User.try_to_login("admin", "admin")
  444. assert_kind_of User, user
  445. assert_equal "admin", user.login
  446. user.password = "hello123"
  447. assert user.save
  448. user = User.try_to_login("admin", "hello123")
  449. assert_kind_of User, user
  450. assert_equal "admin", user.login
  451. end
  452. def test_validate_password_length
  453. with_settings :password_min_length => '100' do
  454. user = User.new(:firstname => "new100",
  455. :lastname => "user100", :mail => "newuser100@somenet.foo")
  456. user.login = "newuser100"
  457. user.password, user.password_confirmation = "password100", "password100"
  458. assert !user.save
  459. assert_equal 1, user.errors.count
  460. end
  461. end
  462. def test_validate_password_format
  463. Setting::PASSWORD_CHAR_CLASSES.each do |key, regexp|
  464. with_settings :password_required_char_classes => key do
  465. user = User.new(:firstname => "new", :lastname => "user", :login => "random", :mail => "random@somnet.foo")
  466. p = 'PASSWDpasswd01234!@#$%'.gsub(regexp, '')
  467. user.password, user.password_confirmation = p, p
  468. assert !user.save
  469. assert_equal 1, user.errors.count
  470. end
  471. end
  472. end
  473. def test_name_format
  474. assert_equal 'John S.', @jsmith.name(:firstname_lastinitial)
  475. assert_equal 'Smith, John', @jsmith.name(:lastname_comma_firstname)
  476. assert_equal 'J. Smith', @jsmith.name(:firstinitial_lastname)
  477. assert_equal 'J.-P. Lang', User.new(:firstname => 'Jean-Philippe', :lastname => 'Lang').name(:firstinitial_lastname)
  478. end
  479. def test_name_should_use_setting_as_default_format
  480. with_settings :user_format => :firstname_lastname do
  481. assert_equal 'John Smith', @jsmith.reload.name
  482. end
  483. with_settings :user_format => :username do
  484. assert_equal 'jsmith', @jsmith.reload.name
  485. end
  486. with_settings :user_format => :lastname do
  487. assert_equal 'Smith', @jsmith.reload.name
  488. end
  489. end
  490. def test_today_should_return_the_day_according_to_user_time_zone
  491. preference = User.find(1).pref
  492. date = Date.new(2012, 05, 15)
  493. time = Time.gm(2012, 05, 15, 23, 30).utc # 2012-05-15 23:30 UTC
  494. Date.stubs(:today).returns(date)
  495. Time.stubs(:now).returns(time)
  496. preference.update_attribute :time_zone, 'Baku' # UTC+4
  497. assert_equal '2012-05-16', User.find(1).today.to_s
  498. preference.update_attribute :time_zone, 'La Paz' # UTC-4
  499. assert_equal '2012-05-15', User.find(1).today.to_s
  500. preference.update_attribute :time_zone, ''
  501. assert_equal '2012-05-15', User.find(1).today.to_s
  502. end
  503. def test_time_to_date_should_return_the_date_according_to_user_time_zone
  504. preference = User.find(1).pref
  505. time = Time.gm(2012, 05, 15, 23, 30).utc # 2012-05-15 23:30 UTC
  506. preference.update_attribute :time_zone, 'Baku' # UTC+4
  507. assert_equal '2012-05-16', User.find(1).time_to_date(time).to_s
  508. preference.update_attribute :time_zone, 'La Paz' # UTC-4
  509. assert_equal '2012-05-15', User.find(1).time_to_date(time).to_s
  510. preference.update_attribute :time_zone, ''
  511. assert_equal time.localtime.to_date.to_s, User.find(1).time_to_date(time).to_s
  512. end
  513. def test_convert_time_to_user_timezone_should_return_the_time_according_to_user_time_zone
  514. preference = User.find(1).pref
  515. time = Time.gm(2012, 05, 15, 23, 30).utc # 2012-05-15 23:30 UTC
  516. time_not_utc = Time.new(2012, 05, 15, 23, 30)
  517. preference.update_attribute :time_zone, 'Baku' # UTC+5
  518. assert_equal '2012-05-16 04:30:00 +0500', User.find(1).convert_time_to_user_timezone(time).to_s
  519. preference.update_attribute :time_zone, 'La Paz' # UTC-4
  520. assert_equal '2012-05-15 19:30:00 -0400', User.find(1).convert_time_to_user_timezone(time).to_s
  521. preference.update_attribute :time_zone, ''
  522. assert_equal time.localtime.to_s, User.find(1).convert_time_to_user_timezone(time).to_s
  523. assert_equal time_not_utc, User.find(1).convert_time_to_user_timezone(time_not_utc)
  524. end
  525. def test_fields_for_order_statement_should_return_fields_according_user_format_setting
  526. with_settings :user_format => 'lastname_comma_firstname' do
  527. assert_equal ['users.lastname', 'users.firstname', 'users.id'],
  528. User.fields_for_order_statement
  529. end
  530. end
  531. def test_fields_for_order_statement_width_table_name_should_prepend_table_name
  532. with_settings :user_format => 'lastname_firstname' do
  533. assert_equal ['authors.lastname', 'authors.firstname', 'authors.id'],
  534. User.fields_for_order_statement('authors')
  535. end
  536. end
  537. def test_fields_for_order_statement_with_blank_format_should_return_default
  538. with_settings :user_format => '' do
  539. assert_equal ['users.firstname', 'users.lastname', 'users.id'],
  540. User.fields_for_order_statement
  541. end
  542. end
  543. def test_fields_for_order_statement_with_invalid_format_should_return_default
  544. with_settings :user_format => 'foo' do
  545. assert_equal ['users.firstname', 'users.lastname', 'users.id'],
  546. User.fields_for_order_statement
  547. end
  548. end
  549. test ".try_to_login with good credentials should return the user" do
  550. user = User.try_to_login("admin", "admin")
  551. assert_kind_of User, user
  552. assert_equal "admin", user.login
  553. end
  554. test ".try_to_login with wrong credentials should return nil" do
  555. assert_nil User.try_to_login("admin", "foo")
  556. end
  557. def test_try_to_login_with_locked_user_should_return_nil
  558. @jsmith.status = User::STATUS_LOCKED
  559. @jsmith.save!
  560. user = User.try_to_login("jsmith", "jsmith")
  561. assert_nil user
  562. end
  563. def test_try_to_login_with_locked_user_and_not_active_only_should_return_user
  564. @jsmith.status = User::STATUS_LOCKED
  565. @jsmith.save!
  566. user = User.try_to_login("jsmith", "jsmith", false)
  567. assert_equal @jsmith, user
  568. end
  569. test ".try_to_login should fall-back to case-insensitive if user login is not found as-typed" do
  570. user = User.try_to_login("AdMin", "admin")
  571. assert_kind_of User, user
  572. assert_equal "admin", user.login
  573. end
  574. test ".try_to_login should select the exact matching user first" do
  575. case_sensitive_user = User.generate! do |user|
  576. user.password = "admin123"
  577. end
  578. # bypass validations to make it appear like existing data
  579. case_sensitive_user.update_attribute(:login, 'ADMIN')
  580. user = User.try_to_login("ADMIN", "admin123")
  581. assert_kind_of User, user
  582. assert_equal "ADMIN", user.login
  583. end
  584. test "#try_to_login! using LDAP with existing user and failed connection to the LDAP server" do
  585. auth_source = AuthSourceLdap.find(1)
  586. user = users(:users_001)
  587. user.update_column :auth_source_id, auth_source.id
  588. AuthSource.any_instance.stubs(:initialize_ldap_con).raises(Net::LDAP::Error, 'Cannot connect')
  589. assert_raise(AuthSourceException){User.try_to_login!('admin', 'admin')}
  590. end
  591. test "#try_to_login using LDAP with existing user and failed connection to the LDAP server" do
  592. auth_source = AuthSourceLdap.find(1)
  593. user = users(:users_001)
  594. user.update_column :auth_source_id, auth_source.id
  595. AuthSource.any_instance.stubs(:initialize_ldap_con).raises(Net::LDAP::Error, 'Cannot connect')
  596. assert_nil User.try_to_login('admin', 'admin')
  597. end
  598. test "#try_to_login using LDAP with new user and failed connection to the LDAP server" do
  599. auth_source = AuthSourceLdap.find(1)
  600. auth_source.update onthefly_register: true
  601. AuthSource.any_instance.stubs(:initialize_ldap_con).raises(Net::LDAP::Error, 'Cannot connect')
  602. assert_nil User.try_to_login('edavis', 'wrong')
  603. end
  604. if ldap_configured?
  605. test "#try_to_login using LDAP" do
  606. assert_nil User.try_to_login('edavis', 'wrong')
  607. end
  608. test "#try_to_login using LDAP binding with user's account" do
  609. auth_source = AuthSourceLdap.find(1)
  610. auth_source.account = "uid=$login,ou=Person,dc=redmine,dc=org"
  611. auth_source.account_password = ''
  612. auth_source.save!
  613. ldap_user = User.new(:mail => 'example1@redmine.org', :firstname => 'LDAP', :lastname => 'user', :auth_source_id => 1)
  614. ldap_user.login = 'example1'
  615. ldap_user.save!
  616. assert_equal ldap_user, User.try_to_login('example1', '123456')
  617. assert_nil User.try_to_login('example1', '11111')
  618. end
  619. test "#try_to_login using LDAP on the fly registration" do
  620. AuthSourceLdap.find(1).update_attribute :onthefly_register, true
  621. assert_difference('User.count') do
  622. assert User.try_to_login('edavis', '123456')
  623. end
  624. assert_no_difference('User.count') do
  625. assert User.try_to_login('edavis', '123456')
  626. end
  627. assert_nil User.try_to_login('example1', '11111')
  628. end
  629. test "#try_to_login using LDAP on the fly registration and binding with user's account" do
  630. auth_source = AuthSourceLdap.find(1)
  631. auth_source.update_attribute :onthefly_register, true
  632. auth_source = AuthSourceLdap.find(1)
  633. auth_source.account = "uid=$login,ou=Person,dc=redmine,dc=org"
  634. auth_source.account_password = ''
  635. auth_source.save!
  636. assert_difference('User.count') do
  637. assert User.try_to_login('example1', '123456')
  638. end
  639. assert_no_difference('User.count') do
  640. assert User.try_to_login('example1', '123456')
  641. end
  642. assert_nil User.try_to_login('example1', '11111')
  643. end
  644. else
  645. puts "Skipping LDAP tests."
  646. end
  647. def test_create_anonymous
  648. AnonymousUser.delete_all
  649. anon = User.anonymous
  650. assert !anon.new_record?
  651. assert_kind_of AnonymousUser, anon
  652. end
  653. def test_ensure_single_anonymous_user
  654. AnonymousUser.delete_all
  655. anon1 = User.anonymous
  656. assert !anon1.new_record?
  657. assert_kind_of AnonymousUser, anon1
  658. anon2 =
  659. AnonymousUser.
  660. create(
  661. :lastname => 'Anonymous', :firstname => '',
  662. :login => '', :status => 0
  663. )
  664. assert_equal 1, anon2.errors.count
  665. end
  666. def test_rss_key
  667. assert_nil @jsmith.rss_token
  668. key = @jsmith.rss_key
  669. assert_equal 40, key.length
  670. @jsmith.reload
  671. assert_equal key, @jsmith.rss_key
  672. end
  673. def test_rss_key_should_not_be_generated_twice
  674. assert_difference 'Token.count', 1 do
  675. key1 = @jsmith.rss_key
  676. key2 = @jsmith.rss_key
  677. assert_equal key1, key2
  678. end
  679. end
  680. def test_api_key_should_not_be_generated_twice
  681. assert_difference 'Token.count', 1 do
  682. key1 = @jsmith.api_key
  683. key2 = @jsmith.api_key
  684. assert_equal key1, key2
  685. end
  686. end
  687. test "#api_key should generate a new one if the user doesn't have one" do
  688. user = User.generate!(:api_token => nil)
  689. assert_nil user.api_token
  690. key = user.api_key
  691. assert_equal 40, key.length
  692. user.reload
  693. assert_equal key, user.api_key
  694. end
  695. test "#api_key should return the existing api token value" do
  696. user = User.generate!
  697. token = Token.create!(:action => 'api')
  698. user.api_token = token
  699. assert user.save
  700. assert_equal token.value, user.api_key
  701. end
  702. test "#find_by_api_key should return nil if no matching key is found" do
  703. assert_nil User.find_by_api_key('zzzzzzzzz')
  704. end
  705. test "#find_by_api_key should return nil if the key is found for an inactive user" do
  706. user = User.generate!
  707. user.status = User::STATUS_LOCKED
  708. token = Token.create!(:action => 'api')
  709. user.api_token = token
  710. user.save
  711. assert_nil User.find_by_api_key(token.value)
  712. end
  713. test "#find_by_api_key should return the user if the key is found for an active user" do
  714. user = User.generate!
  715. token = Token.create!(:action => 'api')
  716. user.api_token = token
  717. user.save
  718. assert_equal user, User.find_by_api_key(token.value)
  719. end
  720. def test_default_admin_account_changed_should_return_false_if_account_was_not_changed
  721. user = User.find_by_login("admin")
  722. user.password = "admin"
  723. assert user.save(:validate => false)
  724. assert_equal false, User.default_admin_account_changed?
  725. end
  726. def test_default_admin_account_changed_should_return_true_if_password_was_changed
  727. user = User.find_by_login("admin")
  728. user.password = "newpassword"
  729. user.save!
  730. assert_equal true, User.default_admin_account_changed?
  731. end
  732. def test_default_admin_account_changed_should_return_true_if_account_is_disabled
  733. user = User.find_by_login("admin")
  734. user.password = "admin"
  735. user.status = User::STATUS_LOCKED
  736. assert user.save(:validate => false)
  737. assert_equal true, User.default_admin_account_changed?
  738. end
  739. def test_default_admin_account_changed_should_return_true_if_account_does_not_exist
  740. user = User.find_by_login("admin")
  741. user.destroy
  742. assert_equal true, User.default_admin_account_changed?
  743. end
  744. def test_membership_with_project_should_return_membership
  745. project = Project.find(1)
  746. membership = @jsmith.membership(project)
  747. assert_kind_of Member, membership
  748. assert_equal @jsmith, membership.user
  749. assert_equal project, membership.project
  750. end
  751. def test_membership_with_project_id_should_return_membership
  752. project = Project.find(1)
  753. membership = @jsmith.membership(1)
  754. assert_kind_of Member, membership
  755. assert_equal @jsmith, membership.user
  756. assert_equal project, membership.project
  757. end
  758. def test_membership_for_non_member_should_return_nil
  759. project = Project.find(1)
  760. user = User.generate!
  761. membership = user.membership(1)
  762. assert_nil membership
  763. end
  764. def test_roles_for_project_with_member_on_public_project_should_return_roles_and_non_member
  765. roles = @jsmith.roles_for_project(Project.find(1))
  766. assert_kind_of Role, roles.first
  767. assert_equal ["Manager"], roles.map(&:name)
  768. end
  769. def test_roles_for_project_with_member_on_private_project_should_return_roles
  770. Project.find(1).update_attribute :is_public, false
  771. roles = @jsmith.roles_for_project(Project.find(1))
  772. assert_kind_of Role, roles.first
  773. assert_equal ["Manager"], roles.map(&:name)
  774. end
  775. def test_roles_for_project_with_non_member_with_public_project_should_return_non_member
  776. set_language_if_valid 'en'
  777. roles = User.find(8).roles_for_project(Project.find(1))
  778. assert_equal ["Non member"], roles.map(&:name)
  779. end
  780. def test_roles_for_project_with_non_member_with_public_project_and_override_should_return_override_roles
  781. project = Project.find(1)
  782. Member.create!(:project => project, :principal => Group.non_member, :role_ids => [1, 2])
  783. roles = User.find(8).roles_for_project(project)
  784. assert_equal ["Developer", "Manager"], roles.map(&:name).sort
  785. end
  786. def test_roles_for_project_with_non_member_with_private_project_should_return_no_roles
  787. Project.find(1).update_attribute :is_public, false
  788. roles = User.find(8).roles_for_project(Project.find(1))
  789. assert_equal [], roles.map(&:name)
  790. end
  791. def test_roles_for_project_with_non_member_with_private_project_and_override_should_return_no_roles
  792. project = Project.find(1)
  793. project.update_attribute :is_public, false
  794. Member.create!(:project => project, :principal => Group.non_member, :role_ids => [1, 2])
  795. roles = User.find(8).roles_for_project(project)
  796. assert_equal [], roles.map(&:name).sort
  797. end
  798. def test_roles_for_project_with_anonymous_with_public_project_should_return_anonymous
  799. set_language_if_valid 'en'
  800. roles = User.anonymous.roles_for_project(Project.find(1))
  801. assert_equal ["Anonymous"], roles.map(&:name)
  802. end
  803. def test_roles_for_project_with_anonymous_with_public_project_and_override_should_return_override_roles
  804. project = Project.find(1)
  805. Member.create!(:project => project, :principal => Group.anonymous, :role_ids => [1, 2])
  806. roles = User.anonymous.roles_for_project(project)
  807. assert_equal ["Developer", "Manager"], roles.map(&:name).sort
  808. end
  809. def test_roles_for_project_with_anonymous_with_private_project_should_return_no_roles
  810. Project.find(1).update_attribute :is_public, false
  811. roles = User.anonymous.roles_for_project(Project.find(1))
  812. assert_equal [], roles.map(&:name)
  813. end
  814. def test_roles_for_project_with_anonymous_with_private_project_and_override_should_return_no_roles
  815. project = Project.find(1)
  816. project.update_attribute :is_public, false
  817. Member.create!(:project => project, :principal => Group.anonymous, :role_ids => [1, 2])
  818. roles = User.anonymous.roles_for_project(project)
  819. assert_equal [], roles.map(&:name).sort
  820. end
  821. def test_roles_for_project_should_be_unique
  822. m = Member.new(:user_id => 1, :project_id => 1)
  823. m.member_roles.build(:role_id => 1)
  824. m.member_roles.build(:role_id => 1)
  825. m.save!
  826. user = User.find(1)
  827. project = Project.find(1)
  828. assert_equal 1, user.roles_for_project(project).size
  829. assert_equal [1], user.roles_for_project(project).map(&:id)
  830. end
  831. def test_projects_by_role_for_user_with_role
  832. user = User.find(2)
  833. assert_kind_of Hash, user.projects_by_role
  834. assert_equal 2, user.projects_by_role.size
  835. assert_equal [1, 5], user.projects_by_role[Role.find(1)].collect(&:id).sort
  836. assert_equal [2], user.projects_by_role[Role.find(2)].collect(&:id).sort
  837. end
  838. def test_project_ids_by_role_should_not_poison_cache_when_first_called_from_chained_scopes
  839. user = User.find(2)
  840. project = Project.find(1)
  841. project.children.visible(user)
  842. assert_equal [1, 2, 5], user.project_ids_by_role.values.flatten.sort
  843. end
  844. def test_accessing_projects_by_role_with_no_projects_should_return_an_empty_array
  845. user = User.find(2)
  846. assert_equal [], user.projects_by_role[Role.find(3)]
  847. # should not update the hash
  848. assert_nil user.projects_by_role.values.detect(&:blank?)
  849. end
  850. def test_projects_by_role_for_user_with_no_role
  851. user = User.generate!
  852. assert_equal({}, user.projects_by_role)
  853. end
  854. def test_projects_by_role_for_anonymous
  855. assert_equal({}, User.anonymous.projects_by_role)
  856. end
  857. def test_valid_notification_options
  858. # without memberships
  859. assert_equal 5, User.find(7).valid_notification_options.size
  860. # with memberships
  861. assert_equal 6, User.find(2).valid_notification_options.size
  862. end
  863. def test_valid_notification_options_class_method
  864. assert_equal 5, User.valid_notification_options.size
  865. assert_equal 5, User.valid_notification_options(User.find(7)).size
  866. assert_equal 6, User.valid_notification_options(User.find(2)).size
  867. end
  868. def test_notified_project_ids_setter_should_coerce_to_unique_integer_array
  869. @jsmith.notified_project_ids = ["1", "123", "2u", "wrong", "12", 6, 12, -35, ""]
  870. assert_equal [1, 123, 2, 12, 6], @jsmith.notified_projects_ids
  871. end
  872. def test_mail_notification_all
  873. @jsmith.mail_notification = 'all'
  874. @jsmith.notified_project_ids = []
  875. @jsmith.save
  876. @jsmith.reload
  877. assert @jsmith.projects.first.recipients.include?(@jsmith.mail)
  878. end
  879. def test_mail_notification_selected
  880. @jsmith.mail_notification = 'selected'
  881. @jsmith.notified_project_ids = [1]
  882. @jsmith.save
  883. @jsmith.reload
  884. assert Project.find(1).recipients.include?(@jsmith.mail)
  885. end
  886. def test_mail_notification_only_my_events
  887. @jsmith.mail_notification = 'only_my_events'
  888. @jsmith.notified_project_ids = []
  889. @jsmith.save
  890. @jsmith.reload
  891. assert !@jsmith.projects.first.recipients.include?(@jsmith.mail)
  892. end
  893. def test_comments_sorting_preference
  894. assert !@jsmith.wants_comments_in_reverse_order?
  895. @jsmith.pref.comments_sorting = 'asc'
  896. assert !@jsmith.wants_comments_in_reverse_order?
  897. @jsmith.pref.comments_sorting = 'desc'
  898. assert @jsmith.wants_comments_in_reverse_order?
  899. end
  900. def test_find_by_mail_should_be_case_insensitive
  901. u = User.find_by_mail('JSmith@somenet.foo')
  902. assert_not_nil u
  903. assert_equal 'jsmith@somenet.foo', u.mail
  904. end
  905. def test_random_password
  906. u = User.new
  907. u.random_password
  908. assert !u.password.blank?
  909. assert !u.password_confirmation.blank?
  910. end
  911. def test_random_password_include_required_characters
  912. with_settings :password_required_char_classes => Setting::PASSWORD_CHAR_CLASSES do
  913. u = User.new(:firstname => "new", :lastname => "user", :login => "random", :mail => "random@somnet.foo")
  914. u.random_password
  915. assert u.valid?
  916. end
  917. end
  918. test "#change_password_allowed? should be allowed if no auth source is set" do
  919. user = User.generate!
  920. assert user.change_password_allowed?
  921. end
  922. test "#change_password_allowed? should delegate to the auth source" do
  923. user = User.generate!
  924. allowed_auth_source = AuthSource.generate!
  925. def allowed_auth_source.allow_password_changes?; true; end
  926. denied_auth_source = AuthSource.generate!
  927. def denied_auth_source.allow_password_changes?; false; end
  928. assert user.change_password_allowed?
  929. user.auth_source = allowed_auth_source
  930. assert user.change_password_allowed?, "User not allowed to change password, though auth source does"
  931. user.auth_source = denied_auth_source
  932. assert !user.change_password_allowed?, "User allowed to change password, though auth source does not"
  933. end
  934. def test_own_account_deletable_should_be_true_with_unsubscrive_enabled
  935. with_settings :unsubscribe => '1' do
  936. assert_equal true, User.find(2).own_account_deletable?
  937. end
  938. end
  939. def test_own_account_deletable_should_be_false_with_unsubscrive_disabled
  940. with_settings :unsubscribe => '0' do
  941. assert_equal false, User.find(2).own_account_deletable?
  942. end
  943. end
  944. def test_own_account_deletable_should_be_false_for_a_single_admin
  945. User.admin.where("id <> ?", 1).delete_all
  946. with_settings :unsubscribe => '1' do
  947. assert_equal false, User.find(1).own_account_deletable?
  948. end
  949. end
  950. def test_own_account_deletable_should_be_true_for_an_admin_if_other_admin_exists
  951. User.generate! do |user|
  952. user.admin = true
  953. end
  954. with_settings :unsubscribe => '1' do
  955. assert_equal true, User.find(1).own_account_deletable?
  956. end
  957. end
  958. test "#allowed_to? for archived project should return false" do
  959. project = Project.find(1)
  960. project.archive
  961. project.reload
  962. assert_equal false, @admin.allowed_to?(:view_issues, project)
  963. end
  964. test "#allowed_to? for closed project should return true for read actions" do
  965. project = Project.find(1)
  966. project.close
  967. project.reload
  968. assert_equal false, @admin.allowed_to?(:edit_project, project)
  969. assert_equal true, @admin.allowed_to?(:view_project, project)
  970. end
  971. test "#allowed_to? for project with module disabled should return false" do
  972. project = Project.find(1)
  973. project.enabled_module_names = ["issue_tracking"]
  974. assert_equal true, @admin.allowed_to?(:add_issues, project)
  975. assert_equal false, @admin.allowed_to?(:view_wiki_pages, project)
  976. end
  977. test "#allowed_to? for admin users should return true" do
  978. project = Project.find(1)
  979. assert ! @admin.member_of?(project)
  980. %w(edit_issues delete_issues manage_news add_documents manage_wiki).each do |p|
  981. assert_equal true, @admin.allowed_to?(p.to_sym, project)
  982. end
  983. end
  984. test "#allowed_to? for normal users" do
  985. project = Project.find(1)
  986. # Manager
  987. assert_equal true, @jsmith.allowed_to?(:delete_messages, project)
  988. # Developer
  989. assert_equal false, @dlopper.allowed_to?(:delete_messages, project)
  990. end
  991. test "#allowed_to? with empty array should return false" do
  992. assert_equal false, @admin.allowed_to?(:view_project, [])
  993. end
  994. test "#allowed_to? with multiple projects" do
  995. assert_equal true, @admin.allowed_to?(:view_project, Project.all.to_a)
  996. # cannot see Project(2)
  997. assert_equal false, @dlopper.allowed_to?(:view_project, Project.all.to_a)
  998. # Manager or Developer everywhere
  999. assert_equal true, @jsmith.allowed_to?(:edit_issues, @jsmith.projects.to_a)
  1000. # Dev cannot delete_issue_watchers
  1001. assert_equal false, @jsmith.allowed_to?(:delete_issue_watchers, @jsmith.projects.to_a)
  1002. end
  1003. test "#allowed_to? with with options[:global] should return true if user has one role with the permission" do
  1004. # only Developer on a project, not Manager anywhere
  1005. @dlopper2 = User.find(5)
  1006. @anonymous = User.find(6)
  1007. assert_equal true, @jsmith.allowed_to?(:delete_issue_watchers, nil, :global => true)
  1008. assert_equal false, @dlopper2.allowed_to?(:delete_issue_watchers, nil, :global => true)
  1009. assert_equal true, @dlopper2.allowed_to?(:add_issues, nil, :global => true)
  1010. assert_equal false, @anonymous.allowed_to?(:add_issues, nil, :global => true)
  1011. assert_equal true, @anonymous.allowed_to?(:view_issues, nil, :global => true)
  1012. end
  1013. # this is just a proxy method, the test only calls it to ensure it doesn't break trivially
  1014. test "#allowed_to_globally?" do
  1015. # only Developer on a project, not Manager anywhere
  1016. @dlopper2 = User.find(5)
  1017. @anonymous = User.find(6)
  1018. assert_equal true, @jsmith.allowed_to_globally?(:delete_issue_watchers)
  1019. assert_equal false, @dlopper2.allowed_to_globally?(:delete_issue_watchers)
  1020. assert_equal true, @dlopper2.allowed_to_globally?(:add_issues)
  1021. assert_equal false, @anonymous.allowed_to_globally?(:add_issues)
  1022. assert_equal true, @anonymous.allowed_to_globally?(:view_issues)
  1023. end
  1024. def test_notify_about_issue
  1025. project = Project.find(1)
  1026. author = User.generate!
  1027. assignee = User.generate!
  1028. Member.create!(:user => assignee, :project => project, :role_ids => [1])
  1029. member = User.generate!
  1030. Member.create!(:user => member, :project => project, :role_ids => [1])
  1031. issue = Issue.generate!(:project => project, :assigned_to => assignee, :author => author)
  1032. tests = {
  1033. author => %w(all only_my_events only_owner selected),
  1034. assignee => %w(all only_my_events only_assigned selected),
  1035. member => %w(all)
  1036. }
  1037. tests.each do |user, expected|
  1038. User::MAIL_NOTIFICATION_OPTIONS.map(&:first).each do |option|
  1039. user.mail_notification = option
  1040. assert_equal expected.include?(option), user.notify_about?(issue)
  1041. end
  1042. end
  1043. end
  1044. def test_notify_about_issue_for_previous_assignee
  1045. assignee = User.generate!(:mail_notification => 'only_assigned')
  1046. Member.create!(:user => assignee, :project_id => 1, :role_ids => [1])
  1047. new_assignee = User.generate!(:mail_notification => 'only_assigned')
  1048. Member.create!(:user => new_assignee, :project_id => 1, :role_ids => [1])
  1049. issue = Issue.generate!(:assigned_to => assignee)
  1050. assert assignee.notify_about?(issue)
  1051. assert !new_assignee.notify_about?(issue)
  1052. issue.assigned_to = new_assignee
  1053. assert assignee.notify_about?(issue)
  1054. assert new_assignee.notify_about?(issue)
  1055. issue.save!
  1056. assert assignee.notify_about?(issue)
  1057. assert new_assignee.notify_about?(issue)
  1058. issue.save!
  1059. assert !assignee.notify_about?(issue)
  1060. assert new_assignee.notify_about?(issue)
  1061. end
  1062. def test_notify_about_news
  1063. user = User.generate!
  1064. news = News.new
  1065. User::MAIL_NOTIFICATION_OPTIONS.map(&:first).each do |option|
  1066. user.mail_notification = option
  1067. assert_equal (option != 'none'), user.notify_about?(news)
  1068. end
  1069. end
  1070. def test_salt_unsalted_passwords
  1071. # Restore a user with an unsalted password
  1072. user = User.find(1)
  1073. user.salt = nil
  1074. user.hashed_password = User.hash_password("unsalted")
  1075. user.save!
  1076. User.salt_unsalted_passwords!
  1077. user.reload
  1078. # Salt added
  1079. assert !user.salt.blank?
  1080. # Password still valid
  1081. assert user.check_password?("unsalted")
  1082. assert_equal user, User.try_to_login(user.login, "unsalted")
  1083. end
  1084. def test_bookmarked_project_ids
  1085. # User with bookmarked projects
  1086. assert_equal [1, 5], User.find(1).bookmarked_project_ids
  1087. # User without bookmarked projects
  1088. assert_equal [], User.find(2).bookmarked_project_ids
  1089. end
  1090. def test_remove_custom_field_references_upon_destroy
  1091. cf1 = IssueCustomField.create(field_format: 'user', name: 'user cf', is_for_all: true, tracker_ids: Tracker.pluck(:id))
  1092. cf2 = IssueCustomField.create(field_format: 'user', name: 'users cf', is_for_all: true, multiple: true, tracker_ids: Tracker.pluck(:id))
  1093. issue = Issue.first
  1094. issue.init_journal(@admin)
  1095. assert_difference ->{cf1.custom_values.count} do
  1096. assert_difference ->{cf2.custom_values.count}, 2 do
  1097. issue.update(custom_field_values:
  1098. {
  1099. cf1.id => @jsmith.id,
  1100. cf2.id => [@dlopper.id, @jsmith.id]
  1101. })
  1102. end
  1103. end
  1104. assert cv1 = cf1.custom_values.where(customized_id: issue.id).last
  1105. assert_equal @jsmith.id.to_s, cv1.value
  1106. assert cv2 = cf2.custom_values.where(customized_id: issue.id)
  1107. assert_equal 2, cv2.size
  1108. assert cv2a = cv2.detect{|cv| cv.value == @dlopper.id.to_s}
  1109. assert cv2b = cv2.detect{|cv| cv.value == @jsmith.id.to_s}
  1110. # 2 custom values from the issue and 1 custom value from the user (CustomValue#3)
  1111. assert_difference ->{CustomValue.count}, -3 do
  1112. @jsmith.destroy
  1113. end
  1114. assert_raise(ActiveRecord::RecordNotFound){cv1.reload}
  1115. assert_raise(ActiveRecord::RecordNotFound){cv2b.reload}
  1116. cv2a.reload
  1117. assert_equal @dlopper.id.to_s, cv2a.value
  1118. end
  1119. end