-
Notifications
You must be signed in to change notification settings - Fork 26
Expand file tree
/
Copy pathAuthorizationTest.php
More file actions
127 lines (100 loc) · 4.59 KB
/
AuthorizationTest.php
File metadata and controls
127 lines (100 loc) · 4.59 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
<?php
declare(strict_types=1);
namespace SimpleSAML\Test\Module\oidc\unit\Admin;
use PHPUnit\Framework\Attributes\CoversClass;
use PHPUnit\Framework\MockObject\MockObject;
use PHPUnit\Framework\TestCase;
use SimpleSAML\Error\Exception;
use SimpleSAML\Module\oidc\Admin\Authorization;
use SimpleSAML\Module\oidc\Bridges\SspBridge;
use SimpleSAML\Module\oidc\Bridges\SspBridge\Utils;
use SimpleSAML\Module\oidc\Exceptions\AuthorizationException;
use SimpleSAML\Module\oidc\Services\AuthContextService;
use SimpleSAML\Utils\Auth;
#[CoversClass(Authorization::class)]
class AuthorizationTest extends TestCase
{
protected MockObject $sspBridgeMock;
protected MockObject $sspBridgeUtilsMock;
protected MockObject $sspBridgeUtilsAuthMock;
protected MockObject $authContextServiceMock;
protected function setUp(): void
{
$this->sspBridgeMock = $this->createMock(SspBridge::class);
$this->sspBridgeUtilsMock = $this->createMock(Utils::class);
$this->sspBridgeMock->method('utils')->willReturn($this->sspBridgeUtilsMock);
$this->sspBridgeUtilsAuthMock = $this->createMock(Auth::class);
$this->sspBridgeUtilsMock->method('auth')->willReturn($this->sspBridgeUtilsAuthMock);
$this->authContextServiceMock = $this->createMock(AuthContextService::class);
}
protected function sut(
?SspBridge $sspBridge = null,
?AuthContextService $authContextService = null,
): Authorization {
$sspBridge ??= $this->sspBridgeMock;
$authContextService ??= $this->authContextServiceMock;
return new Authorization($sspBridge, $authContextService);
}
public function testCanCreateInstance(): void
{
$this->assertInstanceOf(Authorization::class, $this->sut());
}
public function testCanCheckIsAdmin(): void
{
$this->assertFalse($this->sut()->isAdmin());
$this->sspBridgeUtilsAuthMock->method('isAdmin')->willReturn(true);
$this->assertTrue($this->sut()->isAdmin());
}
public function testCanRequireAdmin(): void
{
$this->expectException(AuthorizationException::class);
$this->expectExceptionMessage('admin');
$this->sspBridgeUtilsAuthMock->method('isAdmin')->willReturn(false);
$this->sut()->requireAdmin();
}
public function testCanForceRequireAdmin(): void
{
$this->sspBridgeUtilsAuthMock->expects($this->once())->method('requireAdmin');
$this->sspBridgeUtilsAuthMock->expects($this->once())->method('isAdmin')->willReturn(true);
$this->sut()->requireAdmin(true);
}
public function testThrowsOnForceRequireAdminError(): void
{
$this->sspBridgeUtilsAuthMock->expects($this->once())->method('requireAdmin')
->willThrowException(new Exception('error'));
$this->expectException(AuthorizationException::class);
$this->expectExceptionMessage('admin');
$this->sut()->requireAdmin(true);
}
public function testRequireAdminOrUserWithPermissionReturnsIfAdmin(): void
{
$this->sspBridgeUtilsAuthMock->expects($this->once())->method('isAdmin')->willReturn(true);
$this->authContextServiceMock->expects($this->never())->method('requirePermission');
$this->sut()->requireAdminOrUserWithPermission('permission');
}
public function testRequireAdminOrUserWithPermissionReturnsIfUser(): void
{
$this->sspBridgeUtilsAuthMock->expects($this->atLeastOnce())->method('isAdmin')
->willReturnOnConsecutiveCalls(
false,
true, // After requireAdmin called, isAdmin will return true
);
$this->sspBridgeUtilsAuthMock->expects($this->once())->method('requireAdmin');
$this->authContextServiceMock->expects($this->once())->method('requirePermission');
$this->sut()->requireAdminOrUserWithPermission('permission');
}
public function testRequireUserWithPermissionThrowsIfUserNotAuthorized(): void
{
$this->expectException(AuthorizationException::class);
$this->expectExceptionMessage('access required');
$this->sspBridgeUtilsAuthMock->expects($this->atLeastOnce())->method('isAdmin')->willReturn(false);
$this->authContextServiceMock->expects($this->once())->method('requirePermission')
->willThrowException(new Exception('error'));
$this->sut()->requireAdminOrUserWithPermission('permission');
}
public function testCanGetUserId(): void
{
$this->authContextServiceMock->expects($this->once())->method('getAuthUserId')->willReturn('id');
$this->assertSame('id', $this->sut()->getUserId());
}
}