You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

user_test.rb 42KB


  1. # Redmine - project management software
  2. # Copyright (C) 2006-2017 Jean-Philippe Lang
  3. #
  4. # This program is free software; you can redistribute it and/or
  5. # modify it under the terms of the GNU General Public License
  6. # as published by the Free Software Foundation; either version 2
  7. # of the License, or (at your option) any later version.
  8. #
  9. # This program is distributed in the hope that it will be useful,
  10. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. # GNU General Public License for more details.
  13. #
  14. # You should have received a copy of the GNU General Public License
  15. # along with this program; if not, write to the Free Software
  16. # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  17. require File.expand_path('../../test_helper', __FILE__)
  18. class UserTest < ActiveSupport::TestCase
  19. fixtures :users, :email_addresses, :members, :projects, :roles, :member_roles, :auth_sources,
  20. :trackers, :issue_statuses,
  21. :projects_trackers,
  22. :watchers,
  23. :issue_categories, :enumerations, :issues,
  24. :journals, :journal_details,
  25. :groups_users,
  26. :enabled_modules,
  27. :tokens
  28. include Redmine::I18n
  29. def setup
  30. @admin = User.find(1)
  31. @jsmith = User.find(2)
  32. @dlopper = User.find(3)
  33. end
  34. def test_admin_scope_without_args_should_return_admin_users
  35. users = User.admin.to_a
  36. assert users.any?
  37. assert users.all? {|u| u.admin == true}
  38. end
  39. def test_admin_scope_with_true_should_return_admin_users
  40. users = User.admin(true).to_a
  41. assert users.any?
  42. assert users.all? {|u| u.admin == true}
  43. end
  44. def test_admin_scope_with_false_should_return_non_admin_users
  45. users = User.admin(false).to_a
  46. assert users.any?
  47. assert users.all? {|u| u.admin == false}
  48. end
  49. def test_sorted_scope_should_sort_user_by_display_name
  50. # Use .active to ignore anonymous with localized display name
  51. assert_equal User.active.map(&:name).map(&:downcase).sort,
  52. User.active.sorted.map(&:name).map(&:downcase)
  53. end
  54. def test_generate
  55. User.generate!(:firstname => 'Testing connection')
  56. User.generate!(:firstname => 'Testing connection')
  57. assert_equal 2, User.where(:firstname => 'Testing connection').count
  58. end
  59. def test_truth
  60. assert_kind_of User, @jsmith
  61. end
  62. def test_should_validate_status
  63. user = User.new
  64. user.status = 0
  65. assert !user.save
  66. assert_include I18n.translate('activerecord.errors.messages.invalid'), user.errors[:status]
  67. end
  68. def test_mail_should_be_stripped
  69. u = User.new
  70. u.mail = " foo@bar.com "
  71. assert_equal "foo@bar.com", u.mail
  72. end
  73. def test_should_create_email_address
  74. u = User.new(:firstname => "new", :lastname => "user")
  75. u.login = "create_email_address"
  76. u.mail = "defaultemail@somenet.foo"
  77. assert u.save
  78. u.reload
  79. assert u.email_address
  80. assert_equal "defaultemail@somenet.foo", u.email_address.address
  81. assert_equal true, u.email_address.is_default
  82. assert_equal true, u.email_address.notify
  83. end
  84. def test_should_not_create_user_without_mail
  85. set_language_if_valid 'en'
  86. u = User.new(:firstname => "new", :lastname => "user")
  87. u.login = "user_without_mail"
  88. assert !u.save
  89. assert_equal ["Email #{I18n.translate('activerecord.errors.messages.blank')}"], u.errors.full_messages
  90. end
  91. def test_should_not_create_user_with_blank_mail
  92. set_language_if_valid 'en'
  93. u = User.new(:firstname => "new", :lastname => "user")
  94. u.login = "user_with_blank_mail"
  95. u.mail = ''
  96. assert !u.save
  97. assert_equal ["Email #{I18n.translate('activerecord.errors.messages.blank')}"], u.errors.full_messages
  98. end
  99. def test_should_not_update_user_with_blank_mail
  100. set_language_if_valid 'en'
  101. u = User.find(2)
  102. u.mail = ''
  103. assert !u.save
  104. assert_equal ["Email #{I18n.translate('activerecord.errors.messages.blank')}"], u.errors.full_messages
  105. end
  106. def test_login_length_validation
  107. user = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  108. user.login = "x" * (User::LOGIN_LENGTH_LIMIT+1)
  109. assert !user.valid?
  110. user.login = "x" * (User::LOGIN_LENGTH_LIMIT)
  111. assert user.valid?
  112. assert user.save
  113. end
  114. def test_generate_password_should_respect_minimum_password_length
  115. with_settings :password_min_length => 15 do
  116. user = User.generate!(:generate_password => true)
  117. assert user.password.length >= 15
  118. end
  119. end
  120. def test_generate_password_should_not_generate_password_with_less_than_10_characters
  121. with_settings :password_min_length => 4 do
  122. user = User.generate!(:generate_password => true)
  123. assert user.password.length >= 10
  124. end
  125. end
  126. def test_generate_password_on_create_should_set_password
  127. user = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  128. user.login = "newuser"
  129. user.generate_password = true
  130. assert user.save
  131. password = user.password
  132. assert user.check_password?(password)
  133. end
  134. def test_generate_password_on_update_should_update_password
  135. user = User.find(2)
  136. hash = user.hashed_password
  137. user.generate_password = true
  138. assert user.save
  139. password = user.password
  140. assert user.check_password?(password)
  141. assert_not_equal hash, user.reload.hashed_password
  142. end
  143. def test_create
  144. user = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  145. user.login = "jsmith"
  146. user.password, user.password_confirmation = "password", "password"
  147. # login uniqueness
  148. assert !user.save
  149. assert_equal 1, user.errors.count
  150. user.login = "newuser"
  151. user.password, user.password_confirmation = "password", "pass"
  152. # password confirmation
  153. assert !user.save
  154. assert_equal 1, user.errors.count
  155. user.password, user.password_confirmation = "password", "password"
  156. assert user.save
  157. end
  158. def test_user_before_create_should_set_the_mail_notification_to_the_default_setting
  159. @user1 = User.generate!
  160. assert_equal 'only_my_events', @user1.mail_notification
  161. with_settings :default_notification_option => 'all' do
  162. @user2 = User.generate!
  163. assert_equal 'all', @user2.mail_notification
  164. end
  165. end
  166. def test_user_login_should_be_case_insensitive
  167. u = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  168. u.login = 'newuser'
  169. u.password, u.password_confirmation = "password", "password"
  170. assert u.save
  171. u = User.new(:firstname => "Similar", :lastname => "User",
  172. :mail => "similaruser@somenet.foo")
  173. u.login = 'NewUser'
  174. u.password, u.password_confirmation = "password", "password"
  175. assert !u.save
  176. assert_include I18n.translate('activerecord.errors.messages.taken'), u.errors[:login]
  177. end
  178. def test_mail_uniqueness_should_not_be_case_sensitive
  179. set_language_if_valid 'en'
  180. u = User.new(:firstname => "new", :lastname => "user", :mail => "newuser@somenet.foo")
  181. u.login = 'newuser1'
  182. u.password, u.password_confirmation = "password", "password"
  183. assert u.save
  184. u = User.new(:firstname => "new", :lastname => "user", :mail => "newUser@Somenet.foo")
  185. u.login = 'newuser2'
  186. u.password, u.password_confirmation = "password", "password"
  187. assert !u.save
  188. assert_include "Email #{I18n.translate('activerecord.errors.messages.taken')}", u.errors.full_messages
  189. end
  190. def test_update
  191. assert_equal "admin", @admin.login
  192. @admin.login = "john"
  193. assert @admin.save, @admin.errors.full_messages.join("; ")
  194. @admin.reload
  195. assert_equal "john", @admin.login
  196. end
  197. def test_update_should_not_fail_for_legacy_user_with_different_case_logins
  198. u1 = User.new(:firstname => "new", :lastname => "user", :mail => "newuser1@somenet.foo")
  199. u1.login = 'newuser1'
  200. assert u1.save
  201. u2 = User.new(:firstname => "new", :lastname => "user", :mail => "newuser2@somenet.foo")
  202. u2.login = 'newuser1'
  203. assert u2.save(:validate => false)
  204. user = User.find(u2.id)
  205. user.firstname = "firstname"
  206. assert user.save, "Save failed"
  207. end
  208. def test_destroy_should_delete_members_and_roles
  209. members = Member.where(:user_id => 2)
  210. ms = members.count
  211. rs = members.collect(&:roles).flatten.size
  212. assert ms > 0
  213. assert rs > 0
  214. assert_difference 'Member.count', - ms do
  215. assert_difference 'MemberRole.count', - rs do
  216. User.find(2).destroy
  217. end
  218. end
  219. assert_nil User.find_by_id(2)
  220. assert_equal 0, Member.where(:user_id => 2).count
  221. end
  222. def test_destroy_should_update_attachments
  223. attachment = Attachment.create!(:container => Project.find(1),
  224. :file => uploaded_test_file("testfile.txt", "text/plain"),
  225. :author_id => 2)
  226. User.find(2).destroy
  227. assert_nil User.find_by_id(2)
  228. assert_equal User.anonymous, attachment.reload.author
  229. end
  230. def test_destroy_should_update_comments
  231. comment = Comment.create!(
  232. :commented => News.create!(:project_id => 1,
  233. :author_id => 1, :title => 'foo', :description => 'foo'),
  234. :author => User.find(2),
  235. :comments => 'foo'
  236. )
  237. User.find(2).destroy
  238. assert_nil User.find_by_id(2)
  239. assert_equal User.anonymous, comment.reload.author
  240. end
  241. def test_destroy_should_update_issues
  242. issue = Issue.create!(:project_id => 1, :author_id => 2,
  243. :tracker_id => 1, :subject => 'foo')
  244. User.find(2).destroy
  245. assert_nil User.find_by_id(2)
  246. assert_equal User.anonymous, issue.reload.author
  247. end
  248. def test_destroy_should_unassign_issues
  249. issue = Issue.create!(:project_id => 1, :author_id => 1,
  250. :tracker_id => 1, :subject => 'foo', :assigned_to_id => 2)
  251. User.find(2).destroy
  252. assert_nil User.find_by_id(2)
  253. assert_nil issue.reload.assigned_to
  254. end
  255. def test_destroy_should_update_journals
  256. issue = Issue.create!(:project_id => 1, :author_id => 2,
  257. :tracker_id => 1, :subject => 'foo')
  258. issue.init_journal(User.find(2), "update")
  259. issue.save!
  260. User.find(2).destroy
  261. assert_nil User.find_by_id(2)
  262. assert_equal User.anonymous, issue.journals.first.reload.user
  263. end
  264. def test_destroy_should_update_journal_details_old_value
  265. issue = Issue.create!(:project_id => 1, :author_id => 1,
  266. :tracker_id => 1, :subject => 'foo', :assigned_to_id => 2)
  267. issue.init_journal(User.find(1), "update")
  268. issue.assigned_to_id = nil
  269. assert_difference 'JournalDetail.count' do
  270. issue.save!
  271. end
  272. journal_detail = JournalDetail.order('id DESC').first
  273. assert_equal '2', journal_detail.old_value
  274. User.find(2).destroy
  275. assert_nil User.find_by_id(2)
  276. assert_equal User.anonymous.id.to_s, journal_detail.reload.old_value
  277. end
  278. def test_destroy_should_update_journal_details_value
  279. issue = Issue.create!(:project_id => 1, :author_id => 1,
  280. :tracker_id => 1, :subject => 'foo')
  281. issue.init_journal(User.find(1), "update")
  282. issue.assigned_to_id = 2
  283. assert_difference 'JournalDetail.count' do
  284. issue.save!
  285. end
  286. journal_detail = JournalDetail.order('id DESC').first
  287. assert_equal '2', journal_detail.value
  288. User.find(2).destroy
  289. assert_nil User.find_by_id(2)
  290. assert_equal User.anonymous.id.to_s, journal_detail.reload.value
  291. end
  292. def test_destroy_should_update_messages
  293. board = Board.create!(:project_id => 1, :name => 'Board', :description => 'Board')
  294. message = Message.create!(:board_id => board.id, :author_id => 2,
  295. :subject => 'foo', :content => 'foo')
  296. User.find(2).destroy
  297. assert_nil User.find_by_id(2)
  298. assert_equal User.anonymous, message.reload.author
  299. end
  300. def test_destroy_should_update_news
  301. news = News.create!(:project_id => 1, :author_id => 2,
  302. :title => 'foo', :description => 'foo')
  303. User.find(2).destroy
  304. assert_nil User.find_by_id(2)
  305. assert_equal User.anonymous, news.reload.author
  306. end
  307. def test_destroy_should_delete_private_queries
  308. query = Query.new(:name => 'foo', :visibility => Query::VISIBILITY_PRIVATE)
  309. query.project_id = 1
  310. query.user_id = 2
  311. query.save!
  312. User.find(2).destroy
  313. assert_nil User.find_by_id(2)
  314. assert_nil Query.find_by_id(query.id)
  315. end
  316. def test_destroy_should_update_public_queries
  317. query = Query.new(:name => 'foo', :visibility => Query::VISIBILITY_PUBLIC)
  318. query.project_id = 1
  319. query.user_id = 2
  320. query.save!
  321. User.find(2).destroy
  322. assert_nil User.find_by_id(2)
  323. assert_equal User.anonymous, query.reload.user
  324. end
  325. def test_destroy_should_update_time_entries
  326. entry = TimeEntry.new(:hours => '2', :spent_on => Date.today,
  327. :activity => TimeEntryActivity.create!(:name => 'foo'))
  328. entry.project_id = 1
  329. entry.user_id = 2
  330. entry.save!
  331. User.find(2).destroy
  332. assert_nil User.find_by_id(2)
  333. assert_equal User.anonymous, entry.reload.user
  334. end
  335. def test_destroy_should_delete_tokens
  336. token = Token.create!(:user_id => 2, :value => 'foo')
  337. User.find(2).destroy
  338. assert_nil User.find_by_id(2)
  339. assert_nil Token.find_by_id(token.id)
  340. end
  341. def test_destroy_should_delete_watchers
  342. issue = Issue.create!(:project_id => 1, :author_id => 1,
  343. :tracker_id => 1, :subject => 'foo')
  344. watcher = Watcher.create!(:user_id => 2, :watchable => issue)
  345. User.find(2).destroy
  346. assert_nil User.find_by_id(2)
  347. assert_nil Watcher.find_by_id(watcher.id)
  348. end
  349. def test_destroy_should_update_wiki_contents
  350. wiki_content = WikiContent.create!(
  351. :text => 'foo',
  352. :author_id => 2,
  353. :page => WikiPage.create!(:title => 'Foo',
  354. :wiki => Wiki.create!(:project_id => 3,
  355. :start_page => 'Start'))
  356. )
  357. wiki_content.text = 'bar'
  358. assert_difference 'WikiContent::Version.count' do
  359. wiki_content.save!
  360. end
  361. User.find(2).destroy
  362. assert_nil User.find_by_id(2)
  363. assert_equal User.anonymous, wiki_content.reload.author
  364. wiki_content.versions.each do |version|
  365. assert_equal User.anonymous, version.reload.author
  366. end
  367. end
  368. def test_destroy_should_nullify_issue_categories
  369. category = IssueCategory.create!(:project_id => 1, :assigned_to_id => 2, :name => 'foo')
  370. User.find(2).destroy
  371. assert_nil User.find_by_id(2)
  372. assert_nil category.reload.assigned_to_id
  373. end
  374. def test_destroy_should_nullify_changesets
  375. changeset = Changeset.create!(
  376. :repository => Repository::Subversion.create!(
  377. :project_id => 1,
  378. :url => 'file:///tmp',
  379. :identifier => 'tmp'
  380. ),
  381. :revision => '12',
  382. :committed_on => Time.now,
  383. :committer => 'jsmith'
  384. )
  385. assert_equal 2, changeset.user_id
  386. User.find(2).destroy
  387. assert_nil User.find_by_id(2)
  388. assert_nil changeset.reload.user_id
  389. end
  390. def test_anonymous_user_should_not_be_destroyable
  391. assert_no_difference 'User.count' do
  392. assert_equal false, User.anonymous.destroy
  393. end
  394. end
  395. def test_password_change_should_destroy_tokens
  396. recovery_token = Token.create!(:user_id => 2, :action => 'recovery')
  397. autologin_token = Token.create!(:user_id => 2, :action => 'autologin')
  398. user = User.find(2)
  399. user.password, user.password_confirmation = "a new password", "a new password"
  400. assert user.save
  401. assert_nil Token.find_by_id(recovery_token.id)
  402. assert_nil Token.find_by_id(autologin_token.id)
  403. end
  404. def test_mail_change_should_destroy_tokens
  405. recovery_token = Token.create!(:user_id => 2, :action => 'recovery')
  406. autologin_token = Token.create!(:user_id => 2, :action => 'autologin')
  407. user = User.find(2)
  408. user.mail = "user@somwehere.com"
  409. assert user.save
  410. assert_nil Token.find_by_id(recovery_token.id)
  411. assert_equal autologin_token, Token.find_by_id(autologin_token.id)
  412. end
  413. def test_change_on_other_fields_should_not_destroy_tokens
  414. recovery_token = Token.create!(:user_id => 2, :action => 'recovery')
  415. autologin_token = Token.create!(:user_id => 2, :action => 'autologin')
  416. user = User.find(2)
  417. user.firstname = "Bobby"
  418. assert user.save
  419. assert_equal recovery_token, Token.find_by_id(recovery_token.id)
  420. assert_equal autologin_token, Token.find_by_id(autologin_token.id)
  421. end
  422. def test_validate_login_presence
  423. @admin.login = ""
  424. assert !@admin.save
  425. assert_equal 1, @admin.errors.count
  426. end
  427. def test_validate_mail_notification_inclusion
  428. u = User.new
  429. u.mail_notification = 'foo'
  430. u.save
  431. assert_not_equal [], u.errors[:mail_notification]
  432. end
  433. def test_password
  434. user = User.try_to_login("admin", "admin")
  435. assert_kind_of User, user
  436. assert_equal "admin", user.login
  437. user.password = "hello123"
  438. assert user.save
  439. user = User.try_to_login("admin", "hello123")
  440. assert_kind_of User, user
  441. assert_equal "admin", user.login
  442. end
  443. def test_validate_password_length
  444. with_settings :password_min_length => '100' do
  445. user = User.new(:firstname => "new100",
  446. :lastname => "user100", :mail => "newuser100@somenet.foo")
  447. user.login = "newuser100"
  448. user.password, user.password_confirmation = "password100", "password100"
  449. assert !user.save
  450. assert_equal 1, user.errors.count
  451. end
  452. end
  453. def test_name_format
  454. assert_equal 'John S.', @jsmith.name(:firstname_lastinitial)
  455. assert_equal 'Smith, John', @jsmith.name(:lastname_comma_firstname)
  456. assert_equal 'J. Smith', @jsmith.name(:firstinitial_lastname)
  457. assert_equal 'J.-P. Lang', User.new(:firstname => 'Jean-Philippe', :lastname => 'Lang').name(:firstinitial_lastname)
  458. end
  459. def test_name_should_use_setting_as_default_format
  460. with_settings :user_format => :firstname_lastname do
  461. assert_equal 'John Smith', @jsmith.reload.name
  462. end
  463. with_settings :user_format => :username do
  464. assert_equal 'jsmith', @jsmith.reload.name
  465. end
  466. with_settings :user_format => :lastname do
  467. assert_equal 'Smith', @jsmith.reload.name
  468. end
  469. end
  470. def test_today_should_return_the_day_according_to_user_time_zone
  471. preference = User.find(1).pref
  472. date = Date.new(2012, 05, 15)
  473. time = Time.gm(2012, 05, 15, 23, 30).utc # 2012-05-15 23:30 UTC
  474. Date.stubs(:today).returns(date)
  475. Time.stubs(:now).returns(time)
  476. preference.update_attribute :time_zone, 'Baku' # UTC+4
  477. assert_equal '2012-05-16', User.find(1).today.to_s
  478. preference.update_attribute :time_zone, 'La Paz' # UTC-4
  479. assert_equal '2012-05-15', User.find(1).today.to_s
  480. preference.update_attribute :time_zone, ''
  481. assert_equal '2012-05-15', User.find(1).today.to_s
  482. end
  483. def test_time_to_date_should_return_the_date_according_to_user_time_zone
  484. preference = User.find(1).pref
  485. time = Time.gm(2012, 05, 15, 23, 30).utc # 2012-05-15 23:30 UTC
  486. preference.update_attribute :time_zone, 'Baku' # UTC+4
  487. assert_equal '2012-05-16', User.find(1).time_to_date(time).to_s
  488. preference.update_attribute :time_zone, 'La Paz' # UTC-4
  489. assert_equal '2012-05-15', User.find(1).time_to_date(time).to_s
  490. preference.update_attribute :time_zone, ''
  491. assert_equal '2012-05-15', User.find(1).time_to_date(time).to_s
  492. end
  493. def test_fields_for_order_statement_should_return_fields_according_user_format_setting
  494. with_settings :user_format => 'lastname_comma_firstname' do
  495. assert_equal ['users.lastname', 'users.firstname', 'users.id'],
  496. User.fields_for_order_statement
  497. end
  498. end
  499. def test_fields_for_order_statement_width_table_name_should_prepend_table_name
  500. with_settings :user_format => 'lastname_firstname' do
  501. assert_equal ['authors.lastname', 'authors.firstname', 'authors.id'],
  502. User.fields_for_order_statement('authors')
  503. end
  504. end
  505. def test_fields_for_order_statement_with_blank_format_should_return_default
  506. with_settings :user_format => '' do
  507. assert_equal ['users.firstname', 'users.lastname', 'users.id'],
  508. User.fields_for_order_statement
  509. end
  510. end
  511. def test_fields_for_order_statement_with_invalid_format_should_return_default
  512. with_settings :user_format => 'foo' do
  513. assert_equal ['users.firstname', 'users.lastname', 'users.id'],
  514. User.fields_for_order_statement
  515. end
  516. end
  517. test ".try_to_login with good credentials should return the user" do
  518. user = User.try_to_login("admin", "admin")
  519. assert_kind_of User, user
  520. assert_equal "admin", user.login
  521. end
  522. test ".try_to_login with wrong credentials should return nil" do
  523. assert_nil User.try_to_login("admin", "foo")
  524. end
  525. def test_try_to_login_with_locked_user_should_return_nil
  526. @jsmith.status = User::STATUS_LOCKED
  527. @jsmith.save!
  528. user = User.try_to_login("jsmith", "jsmith")
  529. assert_nil user
  530. end
  531. def test_try_to_login_with_locked_user_and_not_active_only_should_return_user
  532. @jsmith.status = User::STATUS_LOCKED
  533. @jsmith.save!
  534. user = User.try_to_login("jsmith", "jsmith", false)
  535. assert_equal @jsmith, user
  536. end
  537. test ".try_to_login should fall-back to case-insensitive if user login is not found as-typed" do
  538. user = User.try_to_login("AdMin", "admin")
  539. assert_kind_of User, user
  540. assert_equal "admin", user.login
  541. end
  542. test ".try_to_login should select the exact matching user first" do
  543. case_sensitive_user = User.generate! do |user|
  544. user.password = "admin123"
  545. end
  546. # bypass validations to make it appear like existing data
  547. case_sensitive_user.update_attribute(:login, 'ADMIN')
  548. user = User.try_to_login("ADMIN", "admin123")
  549. assert_kind_of User, user
  550. assert_equal "ADMIN", user.login
  551. end
  552. if ldap_configured?
  553. test "#try_to_login using LDAP with failed connection to the LDAP server" do
  554. auth_source = AuthSourceLdap.find(1)
  555. AuthSource.any_instance.stubs(:initialize_ldap_con).raises(Net::LDAP::Error, 'Cannot connect')
  556. assert_nil User.try_to_login('edavis', 'wrong')
  557. end
  558. test "#try_to_login using LDAP" do
  559. assert_nil User.try_to_login('edavis', 'wrong')
  560. end
  561. test "#try_to_login using LDAP binding with user's account" do
  562. auth_source = AuthSourceLdap.find(1)
  563. auth_source.account = "uid=$login,ou=Person,dc=redmine,dc=org"
  564. auth_source.account_password = ''
  565. auth_source.save!
  566. ldap_user = User.new(:mail => 'example1@redmine.org', :firstname => 'LDAP', :lastname => 'user', :auth_source_id => 1)
  567. ldap_user.login = 'example1'
  568. ldap_user.save!
  569. assert_equal ldap_user, User.try_to_login('example1', '123456')
  570. assert_nil User.try_to_login('example1', '11111')
  571. end
  572. test "#try_to_login using LDAP on the fly registration" do
  573. AuthSourceLdap.find(1).update_attribute :onthefly_register, true
  574. assert_difference('User.count') do
  575. assert User.try_to_login('edavis', '123456')
  576. end
  577. assert_no_difference('User.count') do
  578. assert User.try_to_login('edavis', '123456')
  579. end
  580. assert_nil User.try_to_login('example1', '11111')
  581. end
  582. test "#try_to_login using LDAP on the fly registration and binding with user's account" do
  583. auth_source = AuthSourceLdap.find(1)
  584. auth_source.update_attribute :onthefly_register, true
  585. auth_source = AuthSourceLdap.find(1)
  586. auth_source.account = "uid=$login,ou=Person,dc=redmine,dc=org"
  587. auth_source.account_password = ''
  588. auth_source.save!
  589. assert_difference('User.count') do
  590. assert User.try_to_login('example1', '123456')
  591. end
  592. assert_no_difference('User.count') do
  593. assert User.try_to_login('example1', '123456')
  594. end
  595. assert_nil User.try_to_login('example1', '11111')
  596. end
  597. else
  598. puts "Skipping LDAP tests."
  599. end
  600. def test_create_anonymous
  601. AnonymousUser.delete_all
  602. anon = User.anonymous
  603. assert !anon.new_record?
  604. assert_kind_of AnonymousUser, anon
  605. end
  606. def test_ensure_single_anonymous_user
  607. AnonymousUser.delete_all
  608. anon1 = User.anonymous
  609. assert !anon1.new_record?
  610. assert_kind_of AnonymousUser, anon1
  611. anon2 = AnonymousUser.create(
  612. :lastname => 'Anonymous', :firstname => '',
  613. :login => '', :status => 0)
  614. assert_equal 1, anon2.errors.count
  615. end
  616. def test_rss_key
  617. assert_nil @jsmith.rss_token
  618. key = @jsmith.rss_key
  619. assert_equal 40, key.length
  620. @jsmith.reload
  621. assert_equal key, @jsmith.rss_key
  622. end
  623. def test_rss_key_should_not_be_generated_twice
  624. assert_difference 'Token.count', 1 do
  625. key1 = @jsmith.rss_key
  626. key2 = @jsmith.rss_key
  627. assert_equal key1, key2
  628. end
  629. end
  630. def test_api_key_should_not_be_generated_twice
  631. assert_difference 'Token.count', 1 do
  632. key1 = @jsmith.api_key
  633. key2 = @jsmith.api_key
  634. assert_equal key1, key2
  635. end
  636. end
  637. test "#api_key should generate a new one if the user doesn't have one" do
  638. user = User.generate!(:api_token => nil)
  639. assert_nil user.api_token
  640. key = user.api_key
  641. assert_equal 40, key.length
  642. user.reload
  643. assert_equal key, user.api_key
  644. end
  645. test "#api_key should return the existing api token value" do
  646. user = User.generate!
  647. token = Token.create!(:action => 'api')
  648. user.api_token = token
  649. assert user.save
  650. assert_equal token.value, user.api_key
  651. end
  652. test "#find_by_api_key should return nil if no matching key is found" do
  653. assert_nil User.find_by_api_key('zzzzzzzzz')
  654. end
  655. test "#find_by_api_key should return nil if the key is found for an inactive user" do
  656. user = User.generate!
  657. user.status = User::STATUS_LOCKED
  658. token = Token.create!(:action => 'api')
  659. user.api_token = token
  660. user.save
  661. assert_nil User.find_by_api_key(token.value)
  662. end
  663. test "#find_by_api_key should return the user if the key is found for an active user" do
  664. user = User.generate!
  665. token = Token.create!(:action => 'api')
  666. user.api_token = token
  667. user.save
  668. assert_equal user, User.find_by_api_key(token.value)
  669. end
  670. def test_default_admin_account_changed_should_return_false_if_account_was_not_changed
  671. user = User.find_by_login("admin")
  672. user.password = "admin"
  673. assert user.save(:validate => false)
  674. assert_equal false, User.default_admin_account_changed?
  675. end
  676. def test_default_admin_account_changed_should_return_true_if_password_was_changed
  677. user = User.find_by_login("admin")
  678. user.password = "newpassword"
  679. user.save!
  680. assert_equal true, User.default_admin_account_changed?
  681. end
  682. def test_default_admin_account_changed_should_return_true_if_account_is_disabled
  683. user = User.find_by_login("admin")
  684. user.password = "admin"
  685. user.status = User::STATUS_LOCKED
  686. assert user.save(:validate => false)
  687. assert_equal true, User.default_admin_account_changed?
  688. end
  689. def test_default_admin_account_changed_should_return_true_if_account_does_not_exist
  690. user = User.find_by_login("admin")
  691. user.destroy
  692. assert_equal true, User.default_admin_account_changed?
  693. end
  694. def test_membership_with_project_should_return_membership
  695. project = Project.find(1)
  696. membership = @jsmith.membership(project)
  697. assert_kind_of Member, membership
  698. assert_equal @jsmith, membership.user
  699. assert_equal project, membership.project
  700. end
  701. def test_membership_with_project_id_should_return_membership
  702. project = Project.find(1)
  703. membership = @jsmith.membership(1)
  704. assert_kind_of Member, membership
  705. assert_equal @jsmith, membership.user
  706. assert_equal project, membership.project
  707. end
  708. def test_membership_for_non_member_should_return_nil
  709. project = Project.find(1)
  710. user = User.generate!
  711. membership = user.membership(1)
  712. assert_nil membership
  713. end
  714. def test_roles_for_project_with_member_on_public_project_should_return_roles_and_non_member
  715. roles = @jsmith.roles_for_project(Project.find(1))
  716. assert_kind_of Role, roles.first
  717. assert_equal ["Manager"], roles.map(&:name)
  718. end
  719. def test_roles_for_project_with_member_on_private_project_should_return_roles
  720. Project.find(1).update_attribute :is_public, false
  721. roles = @jsmith.roles_for_project(Project.find(1))
  722. assert_kind_of Role, roles.first
  723. assert_equal ["Manager"], roles.map(&:name)
  724. end
  725. def test_roles_for_project_with_non_member_with_public_project_should_return_non_member
  726. set_language_if_valid 'en'
  727. roles = User.find(8).roles_for_project(Project.find(1))
  728. assert_equal ["Non member"], roles.map(&:name)
  729. end
  730. def test_roles_for_project_with_non_member_with_public_project_and_override_should_return_override_roles
  731. project = Project.find(1)
  732. Member.create!(:project => project, :principal => Group.non_member, :role_ids => [1, 2])
  733. roles = User.find(8).roles_for_project(project)
  734. assert_equal ["Developer", "Manager"], roles.map(&:name).sort
  735. end
  736. def test_roles_for_project_with_non_member_with_private_project_should_return_no_roles
  737. Project.find(1).update_attribute :is_public, false
  738. roles = User.find(8).roles_for_project(Project.find(1))
  739. assert_equal [], roles.map(&:name)
  740. end
  741. def test_roles_for_project_with_non_member_with_private_project_and_override_should_return_no_roles
  742. project = Project.find(1)
  743. project.update_attribute :is_public, false
  744. Member.create!(:project => project, :principal => Group.non_member, :role_ids => [1, 2])
  745. roles = User.find(8).roles_for_project(project)
  746. assert_equal [], roles.map(&:name).sort
  747. end
  748. def test_roles_for_project_with_anonymous_with_public_project_should_return_anonymous
  749. set_language_if_valid 'en'
  750. roles = User.anonymous.roles_for_project(Project.find(1))
  751. assert_equal ["Anonymous"], roles.map(&:name)
  752. end
  753. def test_roles_for_project_with_anonymous_with_public_project_and_override_should_return_override_roles
  754. project = Project.find(1)
  755. Member.create!(:project => project, :principal => Group.anonymous, :role_ids => [1, 2])
  756. roles = User.anonymous.roles_for_project(project)
  757. assert_equal ["Developer", "Manager"], roles.map(&:name).sort
  758. end
  759. def test_roles_for_project_with_anonymous_with_private_project_should_return_no_roles
  760. Project.find(1).update_attribute :is_public, false
  761. roles = User.anonymous.roles_for_project(Project.find(1))
  762. assert_equal [], roles.map(&:name)
  763. end
  764. def test_roles_for_project_with_anonymous_with_private_project_and_override_should_return_no_roles
  765. project = Project.find(1)
  766. project.update_attribute :is_public, false
  767. Member.create!(:project => project, :principal => Group.anonymous, :role_ids => [1, 2])
  768. roles = User.anonymous.roles_for_project(project)
  769. assert_equal [], roles.map(&:name).sort
  770. end
  771. def test_roles_for_project_should_be_unique
  772. m = Member.new(:user_id => 1, :project_id => 1)
  773. m.member_roles.build(:role_id => 1)
  774. m.member_roles.build(:role_id => 1)
  775. m.save!
  776. user = User.find(1)
  777. project = Project.find(1)
  778. assert_equal 1, user.roles_for_project(project).size
  779. assert_equal [1], user.roles_for_project(project).map(&:id)
  780. end
  781. def test_projects_by_role_for_user_with_role
  782. user = User.find(2)
  783. assert_kind_of Hash, user.projects_by_role
  784. assert_equal 2, user.projects_by_role.size
  785. assert_equal [1,5], user.projects_by_role[Role.find(1)].collect(&:id).sort
  786. assert_equal [2], user.projects_by_role[Role.find(2)].collect(&:id).sort
  787. end
  788. def test_project_ids_by_role_should_not_poison_cache_when_first_called_from_chained_scopes
  789. user = User.find(2)
  790. project = Project.find(1)
  791. project.children.visible(user)
  792. assert_equal [1, 2, 5], user.project_ids_by_role.values.flatten.sort
  793. end
  794. def test_accessing_projects_by_role_with_no_projects_should_return_an_empty_array
  795. user = User.find(2)
  796. assert_equal [], user.projects_by_role[Role.find(3)]
  797. # should not update the hash
  798. assert_nil user.projects_by_role.values.detect(&:blank?)
  799. end
  800. def test_projects_by_role_for_user_with_no_role
  801. user = User.generate!
  802. assert_equal({}, user.projects_by_role)
  803. end
  804. def test_projects_by_role_for_anonymous
  805. assert_equal({}, User.anonymous.projects_by_role)
  806. end
  807. def test_valid_notification_options
  808. # without memberships
  809. assert_equal 5, User.find(7).valid_notification_options.size
  810. # with memberships
  811. assert_equal 6, User.find(2).valid_notification_options.size
  812. end
  813. def test_valid_notification_options_class_method
  814. assert_equal 5, User.valid_notification_options.size
  815. assert_equal 5, User.valid_notification_options(User.find(7)).size
  816. assert_equal 6, User.valid_notification_options(User.find(2)).size
  817. end
  818. def test_notified_project_ids_setter_should_coerce_to_unique_integer_array
  819. @jsmith.notified_project_ids = ["1", "123", "2u", "wrong", "12", 6, 12, -35, ""]
  820. assert_equal [1, 123, 2, 12, 6], @jsmith.notified_projects_ids
  821. end
  822. def test_mail_notification_all
  823. @jsmith.mail_notification = 'all'
  824. @jsmith.notified_project_ids = []
  825. @jsmith.save
  826. @jsmith.reload
  827. assert @jsmith.projects.first.recipients.include?(@jsmith.mail)
  828. end
  829. def test_mail_notification_selected
  830. @jsmith.mail_notification = 'selected'
  831. @jsmith.notified_project_ids = [1]
  832. @jsmith.save
  833. @jsmith.reload
  834. assert Project.find(1).recipients.include?(@jsmith.mail)
  835. end
  836. def test_mail_notification_only_my_events
  837. @jsmith.mail_notification = 'only_my_events'
  838. @jsmith.notified_project_ids = []
  839. @jsmith.save
  840. @jsmith.reload
  841. assert !@jsmith.projects.first.recipients.include?(@jsmith.mail)
  842. end
  843. def test_comments_sorting_preference
  844. assert !@jsmith.wants_comments_in_reverse_order?
  845. @jsmith.pref.comments_sorting = 'asc'
  846. assert !@jsmith.wants_comments_in_reverse_order?
  847. @jsmith.pref.comments_sorting = 'desc'
  848. assert @jsmith.wants_comments_in_reverse_order?
  849. end
  850. def test_find_by_mail_should_be_case_insensitive
  851. u = User.find_by_mail('JSmith@somenet.foo')
  852. assert_not_nil u
  853. assert_equal 'jsmith@somenet.foo', u.mail
  854. end
  855. def test_random_password
  856. u = User.new
  857. u.random_password
  858. assert !u.password.blank?
  859. assert !u.password_confirmation.blank?
  860. end
  861. test "#change_password_allowed? should be allowed if no auth source is set" do
  862. user = User.generate!
  863. assert user.change_password_allowed?
  864. end
  865. test "#change_password_allowed? should delegate to the auth source" do
  866. user = User.generate!
  867. allowed_auth_source = AuthSource.generate!
  868. def allowed_auth_source.allow_password_changes?; true; end
  869. denied_auth_source = AuthSource.generate!
  870. def denied_auth_source.allow_password_changes?; false; end
  871. assert user.change_password_allowed?
  872. user.auth_source = allowed_auth_source
  873. assert user.change_password_allowed?, "User not allowed to change password, though auth source does"
  874. user.auth_source = denied_auth_source
  875. assert !user.change_password_allowed?, "User allowed to change password, though auth source does not"
  876. end
  877. def test_own_account_deletable_should_be_true_with_unsubscrive_enabled
  878. with_settings :unsubscribe => '1' do
  879. assert_equal true, User.find(2).own_account_deletable?
  880. end
  881. end
  882. def test_own_account_deletable_should_be_false_with_unsubscrive_disabled
  883. with_settings :unsubscribe => '0' do
  884. assert_equal false, User.find(2).own_account_deletable?
  885. end
  886. end
  887. def test_own_account_deletable_should_be_false_for_a_single_admin
  888. User.admin.where("id <> ?", 1).delete_all
  889. with_settings :unsubscribe => '1' do
  890. assert_equal false, User.find(1).own_account_deletable?
  891. end
  892. end
  893. def test_own_account_deletable_should_be_true_for_an_admin_if_other_admin_exists
  894. User.generate! do |user|
  895. user.admin = true
  896. end
  897. with_settings :unsubscribe => '1' do
  898. assert_equal true, User.find(1).own_account_deletable?
  899. end
  900. end
  901. test "#allowed_to? for archived project should return false" do
  902. project = Project.find(1)
  903. project.archive
  904. project.reload
  905. assert_equal false, @admin.allowed_to?(:view_issues, project)
  906. end
  907. test "#allowed_to? for closed project should return true for read actions" do
  908. project = Project.find(1)
  909. project.close
  910. project.reload
  911. assert_equal false, @admin.allowed_to?(:edit_project, project)
  912. assert_equal true, @admin.allowed_to?(:view_project, project)
  913. end
  914. test "#allowed_to? for project with module disabled should return false" do
  915. project = Project.find(1)
  916. project.enabled_module_names = ["issue_tracking"]
  917. assert_equal true, @admin.allowed_to?(:add_issues, project)
  918. assert_equal false, @admin.allowed_to?(:view_wiki_pages, project)
  919. end
  920. test "#allowed_to? for admin users should return true" do
  921. project = Project.find(1)
  922. assert ! @admin.member_of?(project)
  923. %w(edit_issues delete_issues manage_news add_documents manage_wiki).each do |p|
  924. assert_equal true, @admin.allowed_to?(p.to_sym, project)
  925. end
  926. end
  927. test "#allowed_to? for normal users" do
  928. project = Project.find(1)
  929. assert_equal true, @jsmith.allowed_to?(:delete_messages, project) #Manager
  930. assert_equal false, @dlopper.allowed_to?(:delete_messages, project) #Developer
  931. end
  932. test "#allowed_to? with empty array should return false" do
  933. assert_equal false, @admin.allowed_to?(:view_project, [])
  934. end
  935. test "#allowed_to? with multiple projects" do
  936. assert_equal true, @admin.allowed_to?(:view_project, Project.all.to_a)
  937. assert_equal false, @dlopper.allowed_to?(:view_project, Project.all.to_a) #cannot see Project(2)
  938. assert_equal true, @jsmith.allowed_to?(:edit_issues, @jsmith.projects.to_a) #Manager or Developer everywhere
  939. assert_equal false, @jsmith.allowed_to?(:delete_issue_watchers, @jsmith.projects.to_a) #Dev cannot delete_issue_watchers
  940. end
  941. test "#allowed_to? with with options[:global] should return true if user has one role with the permission" do
  942. @dlopper2 = User.find(5) #only Developer on a project, not Manager anywhere
  943. @anonymous = User.find(6)
  944. assert_equal true, @jsmith.allowed_to?(:delete_issue_watchers, nil, :global => true)
  945. assert_equal false, @dlopper2.allowed_to?(:delete_issue_watchers, nil, :global => true)
  946. assert_equal true, @dlopper2.allowed_to?(:add_issues, nil, :global => true)
  947. assert_equal false, @anonymous.allowed_to?(:add_issues, nil, :global => true)
  948. assert_equal true, @anonymous.allowed_to?(:view_issues, nil, :global => true)
  949. end
  950. # this is just a proxy method, the test only calls it to ensure it doesn't break trivially
  951. test "#allowed_to_globally?" do
  952. @dlopper2 = User.find(5) #only Developer on a project, not Manager anywhere
  953. @anonymous = User.find(6)
  954. assert_equal true, @jsmith.allowed_to_globally?(:delete_issue_watchers)
  955. assert_equal false, @dlopper2.allowed_to_globally?(:delete_issue_watchers)
  956. assert_equal true, @dlopper2.allowed_to_globally?(:add_issues)
  957. assert_equal false, @anonymous.allowed_to_globally?(:add_issues)
  958. assert_equal true, @anonymous.allowed_to_globally?(:view_issues)
  959. end
  960. def test_notify_about_issue
  961. project = Project.find(1)
  962. author = User.generate!
  963. assignee = User.generate!
  964. Member.create!(:user => assignee, :project => project, :role_ids => [1])
  965. member = User.generate!
  966. Member.create!(:user => member, :project => project, :role_ids => [1])
  967. issue = Issue.generate!(:project => project, :assigned_to => assignee, :author => author)
  968. tests = {
  969. author => %w(all only_my_events only_owner selected),
  970. assignee => %w(all only_my_events only_assigned selected),
  971. member => %w(all)
  972. }
  973. tests.each do |user, expected|
  974. User::MAIL_NOTIFICATION_OPTIONS.map(&:first).each do |option|
  975. user.mail_notification = option
  976. assert_equal expected.include?(option), user.notify_about?(issue)
  977. end
  978. end
  979. end
  980. def test_notify_about_issue_for_previous_assignee
  981. assignee = User.generate!(:mail_notification => 'only_assigned')
  982. Member.create!(:user => assignee, :project_id => 1, :role_ids => [1])
  983. new_assignee = User.generate!(:mail_notification => 'only_assigned')
  984. Member.create!(:user => new_assignee, :project_id => 1, :role_ids => [1])
  985. issue = Issue.generate!(:assigned_to => assignee)
  986. assert assignee.notify_about?(issue)
  987. assert !new_assignee.notify_about?(issue)
  988. issue.assigned_to = new_assignee
  989. assert assignee.notify_about?(issue)
  990. assert new_assignee.notify_about?(issue)
  991. issue.save!
  992. assert assignee.notify_about?(issue)
  993. assert new_assignee.notify_about?(issue)
  994. issue.save!
  995. assert !assignee.notify_about?(issue)
  996. assert new_assignee.notify_about?(issue)
  997. end
  998. def test_notify_about_news
  999. user = User.generate!
  1000. news = News.new
  1001. User::MAIL_NOTIFICATION_OPTIONS.map(&:first).each do |option|
  1002. user.mail_notification = option
  1003. assert_equal (option != 'none'), user.notify_about?(news)
  1004. end
  1005. end
  1006. def test_salt_unsalted_passwords
  1007. # Restore a user with an unsalted password
  1008. user = User.find(1)
  1009. user.salt = nil
  1010. user.hashed_password = User.hash_password("unsalted")
  1011. user.save!
  1012. User.salt_unsalted_passwords!
  1013. user.reload
  1014. # Salt added
  1015. assert !user.salt.blank?
  1016. # Password still valid
  1017. assert user.check_password?("unsalted")
  1018. assert_equal user, User.try_to_login(user.login, "unsalted")
  1019. end
  1020. if Object.const_defined?(:OpenID)
  1021. def test_setting_identity_url
  1022. normalized_open_id_url = 'http://example.com/'
  1023. u = User.new( :identity_url => 'http://example.com/' )
  1024. assert_equal normalized_open_id_url, u.identity_url
  1025. end
  1026. def test_setting_identity_url_without_trailing_slash
  1027. normalized_open_id_url = 'http://example.com/'
  1028. u = User.new( :identity_url => 'http://example.com' )
  1029. assert_equal normalized_open_id_url, u.identity_url
  1030. end
  1031. def test_setting_identity_url_without_protocol
  1032. normalized_open_id_url = 'http://example.com/'
  1033. u = User.new( :identity_url => 'example.com' )
  1034. assert_equal normalized_open_id_url, u.identity_url
  1035. end
  1036. def test_setting_blank_identity_url
  1037. u = User.new( :identity_url => 'example.com' )
  1038. u.identity_url = ''
  1039. assert u.identity_url.blank?
  1040. end
  1041. def test_setting_invalid_identity_url
  1042. u = User.new( :identity_url => 'this is not an openid url' )
  1043. assert u.identity_url.blank?
  1044. end
  1045. else
  1046. puts "Skipping openid tests."
  1047. end
  1048. end