2021-10-09 01:49:45 +13:00
|
|
|
<?php
|
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
namespace Tests\E2E\Services\Databases;
|
2021-10-09 01:49:45 +13:00
|
|
|
|
|
|
|
use Tests\E2E\Client;
|
|
|
|
use Tests\E2E\Scopes\Scope;
|
|
|
|
use Tests\E2E\Scopes\ProjectCustom;
|
|
|
|
use Tests\E2E\Scopes\SideClient;
|
2022-08-14 22:33:36 +12:00
|
|
|
use Utopia\Database\ID;
|
2022-08-14 17:21:11 +12:00
|
|
|
use Utopia\Database\Permission;
|
|
|
|
use Utopia\Database\Role;
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
class DatabasesPermissionsMemberTest extends Scope
|
2021-10-09 01:49:45 +13:00
|
|
|
{
|
|
|
|
use ProjectCustom;
|
|
|
|
use SideClient;
|
2022-06-22 22:51:49 +12:00
|
|
|
use DatabasesPermissionsScope;
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2021-10-22 13:38:17 +13:00
|
|
|
public array $collections = [];
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2021-10-22 13:38:17 +13:00
|
|
|
public function createUsers(): array
|
2021-10-09 01:49:45 +13:00
|
|
|
{
|
2021-10-22 13:38:17 +13:00
|
|
|
return [
|
|
|
|
'user1' => $this->createUser('user1', 'lorem@ipsum.com'),
|
|
|
|
'user2' => $this->createUser('user2', 'dolor@ipsum.com'),
|
|
|
|
];
|
|
|
|
}
|
|
|
|
|
2022-08-09 14:48:56 +12:00
|
|
|
public function permissionsProvider(): array
|
2021-10-22 13:38:17 +13:00
|
|
|
{
|
|
|
|
return [
|
2022-08-14 17:21:11 +12:00
|
|
|
[[Permission::read(Role::any())]],
|
|
|
|
[[Permission::read(Role::users())]],
|
2022-08-14 22:33:36 +12:00
|
|
|
[[Permission::read(Role::user(ID::custom('random')))]],
|
|
|
|
[[Permission::read(Role::user(ID::custom('lorem'))), Permission::update(Role::user('lorem')), Permission::delete(Role::user('lorem'))]],
|
|
|
|
[[Permission::read(Role::user(ID::custom('dolor'))), Permission::update(Role::user('dolor')), Permission::delete(Role::user('dolor'))]],
|
|
|
|
[[Permission::read(Role::user(ID::custom('dolor'))), Permission::read(Role::user('lorem')), Permission::update(Role::user('dolor')), Permission::delete(Role::user('dolor'))]],
|
2022-08-14 17:21:11 +12:00
|
|
|
[[Permission::update(Role::any()), Permission::delete(Role::any())]],
|
|
|
|
[[Permission::read(Role::any()), Permission::update(Role::any()), Permission::delete(Role::any())]],
|
|
|
|
[[Permission::read(Role::users()), Permission::update(Role::users()), Permission::delete(Role::users())]],
|
|
|
|
[[Permission::read(Role::any()), Permission::update(Role::users()), Permission::delete(Role::users())]],
|
2021-10-22 13:38:17 +13:00
|
|
|
];
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Setup database
|
|
|
|
*
|
2022-08-09 14:48:56 +12:00
|
|
|
* Data providers lose object state so explicitly pass [$users, $collections] to each iteration
|
|
|
|
*
|
2021-10-22 13:38:17 +13:00
|
|
|
* @return array
|
2022-08-09 14:48:56 +12:00
|
|
|
* @throws \Exception
|
2021-10-22 13:38:17 +13:00
|
|
|
*/
|
|
|
|
public function testSetupDatabase(): array
|
|
|
|
{
|
|
|
|
$this->createUsers();
|
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
$db = $this->client->call(Client::METHOD_POST, '/databases', $this->getServerHeader(), [
|
2022-08-14 22:33:36 +12:00
|
|
|
'databaseId' => ID::unique(),
|
2022-06-22 22:51:49 +12:00
|
|
|
'name' => 'Test Database',
|
|
|
|
]);
|
|
|
|
$this->assertEquals(201, $db['headers']['status-code']);
|
|
|
|
|
|
|
|
$databaseId = $db['body']['$id'];
|
|
|
|
|
|
|
|
$public = $this->client->call(Client::METHOD_POST, '/databases/' . $databaseId . '/collections', $this->getServerHeader(), [
|
2022-08-14 22:33:36 +12:00
|
|
|
'collectionId' => ID::unique(),
|
2021-10-09 01:49:45 +13:00
|
|
|
'name' => 'Movies',
|
2022-08-03 16:17:49 +12:00
|
|
|
'permissions' => [
|
2022-08-14 17:21:11 +12:00
|
|
|
Permission::read(Role::any()),
|
|
|
|
Permission::create(Role::any()),
|
|
|
|
Permission::update(Role::any()),
|
|
|
|
Permission::delete(Role::any()),
|
2022-08-03 16:17:49 +12:00
|
|
|
],
|
|
|
|
'documentSecurity' => true,
|
2021-10-09 01:49:45 +13:00
|
|
|
]);
|
2021-10-22 13:38:17 +13:00
|
|
|
$this->assertEquals(201, $public['headers']['status-code']);
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2021-10-22 13:38:17 +13:00
|
|
|
$this->collections = ['public' => $public['body']['$id']];
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
$response = $this->client->call(Client::METHOD_POST, '/databases/' . $databaseId . '/collections/' . $this->collections['public'] . '/attributes/string', $this->getServerHeader(), [
|
2021-12-17 04:04:30 +13:00
|
|
|
'key' => 'title',
|
2021-10-09 01:49:45 +13:00
|
|
|
'size' => 256,
|
|
|
|
'required' => true,
|
|
|
|
]);
|
2022-07-19 01:22:23 +12:00
|
|
|
$this->assertEquals(202, $response['headers']['status-code']);
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
$private = $this->client->call(Client::METHOD_POST, '/databases/' . $databaseId . '/collections', $this->getServerHeader(), [
|
2022-08-14 22:33:36 +12:00
|
|
|
'collectionId' => ID::unique(),
|
2021-10-09 01:49:45 +13:00
|
|
|
'name' => 'Private Movies',
|
2022-08-03 16:17:49 +12:00
|
|
|
'permissions' => [
|
2022-08-14 17:21:11 +12:00
|
|
|
Permission::read(Role::users()),
|
|
|
|
Permission::create(Role::users()),
|
|
|
|
Permission::update(Role::users()),
|
|
|
|
Permission::delete(Role::users()),
|
2022-08-03 16:17:49 +12:00
|
|
|
],
|
|
|
|
'documentSecurity' => true,
|
2021-10-09 01:49:45 +13:00
|
|
|
]);
|
2021-10-22 13:38:17 +13:00
|
|
|
$this->assertEquals(201, $private['headers']['status-code']);
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2021-10-22 13:38:17 +13:00
|
|
|
$this->collections['private'] = $private['body']['$id'];
|
2021-10-09 01:49:45 +13:00
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
$this->client->call(Client::METHOD_POST, '/databases/' . $databaseId . '/collections/' . $this->collections['private'] . '/attributes/string', $this->getServerHeader(), [
|
2021-12-17 04:04:30 +13:00
|
|
|
'key' => 'title',
|
2021-10-09 01:49:45 +13:00
|
|
|
'size' => 256,
|
|
|
|
'required' => true,
|
|
|
|
]);
|
2022-07-19 01:22:23 +12:00
|
|
|
$this->assertEquals(202, $response['headers']['status-code']);
|
2021-10-09 01:49:45 +13:00
|
|
|
|
|
|
|
sleep(2);
|
|
|
|
|
2021-10-22 13:38:17 +13:00
|
|
|
return [
|
|
|
|
'users' => $this->users,
|
2022-06-22 22:51:49 +12:00
|
|
|
'collections' => $this->collections,
|
|
|
|
'databaseId' => $databaseId
|
2021-10-22 13:38:17 +13:00
|
|
|
];
|
2021-10-09 01:49:45 +13:00
|
|
|
}
|
|
|
|
|
2021-10-22 13:38:17 +13:00
|
|
|
/**
|
|
|
|
* Data provider params are passed before test dependencies
|
2022-08-09 14:48:56 +12:00
|
|
|
* @dataProvider permissionsProvider
|
2021-10-22 13:38:17 +13:00
|
|
|
* @depends testSetupDatabase
|
|
|
|
*/
|
2022-08-09 14:48:56 +12:00
|
|
|
public function testReadDocuments($permissions, $data)
|
2021-10-09 01:49:45 +13:00
|
|
|
{
|
2021-10-22 13:38:17 +13:00
|
|
|
$users = $data['users'];
|
|
|
|
$collections = $data['collections'];
|
2022-06-22 22:51:49 +12:00
|
|
|
$databaseId = $data['databaseId'];
|
2021-10-22 13:38:17 +13:00
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
$response = $this->client->call(Client::METHOD_POST, '/databases/' . $databaseId . '/collections/' . $collections['public'] . '/documents', $this->getServerHeader(), [
|
2022-08-14 22:33:36 +12:00
|
|
|
'documentId' => ID::unique(),
|
2021-10-22 13:38:17 +13:00
|
|
|
'data' => [
|
|
|
|
'title' => 'Lorem',
|
|
|
|
],
|
2022-08-09 14:48:56 +12:00
|
|
|
'permissions' => $permissions
|
2021-10-22 13:38:17 +13:00
|
|
|
]);
|
|
|
|
$this->assertEquals(201, $response['headers']['status-code']);
|
|
|
|
|
2022-06-22 22:51:49 +12:00
|
|
|
$response = $this->client->call(Client::METHOD_POST, '/databases/' . $databaseId . '/collections/' . $collections['private'] . '/documents', $this->getServerHeader(), [
|
2022-08-14 22:33:36 +12:00
|
|
|
'documentId' => ID::unique(),
|
2021-10-22 13:38:17 +13:00
|
|
|
'data' => [
|
|
|
|
'title' => 'Lorem',
|
|
|
|
],
|
2022-08-09 14:48:56 +12:00
|
|
|
'permissions' => $permissions
|
2021-10-22 13:38:17 +13:00
|
|
|
]);
|
|
|
|
$this->assertEquals(201, $response['headers']['status-code']);
|
2021-10-09 01:49:45 +13:00
|
|
|
|
|
|
|
/**
|
2022-08-15 19:20:10 +12:00
|
|
|
* Check "any" collection
|
2021-10-09 01:49:45 +13:00
|
|
|
*/
|
2022-06-22 22:51:49 +12:00
|
|
|
$documents = $this->client->call(Client::METHOD_GET, '/databases/' . $databaseId . '/collections/' . $collections['public'] . '/documents', [
|
2021-10-09 01:49:45 +13:00
|
|
|
'origin' => 'http://localhost',
|
|
|
|
'content-type' => 'application/json',
|
|
|
|
'x-appwrite-project' => $this->getProject()['$id'],
|
2021-10-22 13:38:17 +13:00
|
|
|
'cookie' => 'a_session_' . $this->getProject()['$id'] . '=' . $users['user1']['session'],
|
2021-10-09 01:49:45 +13:00
|
|
|
]);
|
|
|
|
|
|
|
|
foreach ($documents['body']['documents'] as $document) {
|
2022-08-19 16:04:33 +12:00
|
|
|
$hasPermissions = \array_reduce([
|
|
|
|
Role::any()->toString(),
|
|
|
|
Role::users()->toString(),
|
|
|
|
Role::user($users['user1']['$id'])->toString(),
|
|
|
|
], function (bool $carry, string $role) use ($document) {
|
2022-08-03 16:17:49 +12:00
|
|
|
if ($carry) {
|
2022-08-09 14:48:56 +12:00
|
|
|
return true;
|
2022-08-03 16:17:49 +12:00
|
|
|
}
|
|
|
|
foreach ($document['$permissions'] as $permission) {
|
2022-08-19 16:04:33 +12:00
|
|
|
$permission = Permission::parse($permission);
|
|
|
|
if ($permission->getPermission() == 'read' && $permission->getRole() == $role) {
|
2022-08-03 16:17:49 +12:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false;
|
2021-10-09 01:49:45 +13:00
|
|
|
}, false);
|
2022-08-09 14:48:56 +12:00
|
|
|
|
2021-10-09 01:49:45 +13:00
|
|
|
$this->assertTrue($hasPermissions);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Check role:member collection
|
|
|
|
*/
|
2022-06-22 22:51:49 +12:00
|
|
|
$documents = $this->client->call(Client::METHOD_GET, '/databases/' . $databaseId . '/collections/' . $collections['private'] . '/documents', [
|
2021-10-09 01:49:45 +13:00
|
|
|
'origin' => 'http://localhost',
|
|
|
|
'content-type' => 'application/json',
|
|
|
|
'x-appwrite-project' => $this->getProject()['$id'],
|
2021-10-22 13:38:17 +13:00
|
|
|
'cookie' => 'a_session_' . $this->getProject()['$id'] . '=' . $users['user1']['session'],
|
2021-10-09 01:49:45 +13:00
|
|
|
]);
|
|
|
|
|
|
|
|
foreach ($documents['body']['documents'] as $document) {
|
2022-08-19 16:04:33 +12:00
|
|
|
$hasPermissions = \array_reduce([
|
|
|
|
Role::any()->toString(),
|
|
|
|
Role::users()->toString(),
|
|
|
|
Role::user($users['user1']['$id'])->toString(),
|
|
|
|
], function (bool $carry, string $role) use ($document) {
|
2022-08-03 16:17:49 +12:00
|
|
|
if ($carry) {
|
2022-08-09 14:48:56 +12:00
|
|
|
return true;
|
2022-08-03 16:17:49 +12:00
|
|
|
}
|
|
|
|
foreach ($document['$permissions'] as $permission) {
|
2022-08-19 16:04:33 +12:00
|
|
|
$permission = Permission::parse($permission);
|
|
|
|
if ($permission->getPermission() == 'read' && $permission->getRole() == $role) {
|
2022-08-03 16:17:49 +12:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false;
|
2021-10-09 01:49:45 +13:00
|
|
|
}, false);
|
2022-08-09 14:48:56 +12:00
|
|
|
|
2021-10-09 01:49:45 +13:00
|
|
|
$this->assertTrue($hasPermissions);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|