1
0
Fork 0
mirror of https://github.com/buddypress/buddypress.git synced 2026-07-22 20:56:55 +08:00
buddypress/tests/phpunit/testcases/notifications/test-controller.php
Renato Alves f15348c102 A user is no longer de-authenticated when making REST API requests.
We are introducing a new `BP_LoggedIn_User` class to fetch data about a BuddyPress logged-in user. This new addition fixes an issue where a user could be de-authenticated when making REST API requests.

Props dcavins, DJPaul, johnjamesjacoby, and imath.

Closes https://github.com/buddypress/buddypress/pull/395
See #9229 and #9145
Fixes #7658

git-svn-id: https://buddypress.svn.wordpress.org/trunk@14070 cdf35c40-ae34-48e0-9cc9-0c9da1808c22
2024-11-03 18:19:06 +00:00

743 lines
24 KiB
PHP

<?php
/**
* Notifications Controller Tests.
*
* @group notifications
*/
class BP_Tests_Notifications_REST_Controller extends BP_Test_REST_Controller_Testcase {
protected $notification_id;
protected $controller = 'BP_Notifications_REST_Controller';
protected $handle = 'notifications';
public function set_up() {
parent::set_up();
$this->notification_id = $this->bp::factory()->notification->create();
}
public function test_register_routes() {
$routes = $this->server->get_routes();
// Main.
$this->assertArrayHasKey( $this->endpoint_url, $routes );
$this->assertCount( 2, $routes[ $this->endpoint_url ] );
// Single.
$this->assertArrayHasKey( $this->endpoint_url . '/(?P<id>[\d]+)', $routes );
$this->assertCount( 3, $routes[ $this->endpoint_url . '/(?P<id>[\d]+)' ] );
}
/**
* @group get_items
*/
public function test_get_items() {
$notification_id = $this->bp::factory()->notification->create( array( 'user_id' => $this->user ) );
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'GET', $this->endpoint_url );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( 'user_id' => $this->user ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$all_data = $response->get_data();
$this->assertNotEmpty( $all_data );
$this->assertCount( 1, $all_data );
$this->assertSame( $notification_id, $all_data[0]['id'] );
}
/**
* @group get_items
*/
public function test_admin_can_get_items_from_multiple_users() {
$u1 = static::factory()->user->create();
$u2 = static::factory()->user->create();
$this->bp::factory()->notification->create( array( 'user_id' => $u1 ) );
$this->bp::factory()->notification->create( array( 'user_id' => $u2 ) );
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'GET', $this->endpoint_url );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( 'user_ids' => array( $u1, $u2 ) ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$all_data = $response->get_data();
$this->assertNotEmpty( $all_data );
$this->assertEqualSets(
array( $u1, $u2 ),
wp_list_pluck( $all_data, 'user_id' )
);
}
/**
* @group get_items
*/
public function test_user_can_not_get_items_from_multiple_users() {
$u1 = static::factory()->user->create();
$u2 = static::factory()->user->create();
$u3 = static::factory()->user->create();
$this->bp::factory()->notification->create( array( 'user_id' => $u1 ) );
$this->bp::factory()->notification->create( array( 'user_id' => $u2 ) );
wp_set_current_user( $u3 );
$request = new WP_REST_Request( 'GET', $this->endpoint_url );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( 'user_ids' => array( $u1, $u2 ) ) );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group get_items
*/
public function test_get_items_user_not_logged_in() {
$request = new WP_REST_Request( 'GET', $this->endpoint_url );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group get_items
*/
public function test_get_items_user_cannot_see_notifications_from_others() {
$u = static::factory()->user->create();
wp_set_current_user( $u );
$request = new WP_REST_Request( 'GET', $this->endpoint_url );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group get_item
*/
public function test_get_item() {
wp_set_current_user( $this->user );
$notification = $this->endpoint->get_notification_object( $this->notification_id );
$this->assertEquals( $this->notification_id, $notification->id );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification->id ) );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$all_data = $response->get_data();
$this->assertNotEmpty( $all_data );
$this->check_notification_data( $notification, $all_data );
}
/**
* @group get_item
*/
public function test_get_embedded_user_from_notification_item() {
wp_set_current_user( $this->user );
$notification_id = $this->bp::factory()->notification->create( array( 'user_id' => $this->user ) );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( '_embed' => 'user' ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$data = $this->server->response_to_data( $response, true );
$this->assertNotEmpty( $data['_embedded']['user'] );
$embedded_user = current( $data['_embedded']['user'] );
$this->assertNotEmpty( $embedded_user );
$this->assertSame( $notification_id, $data['id'] );
$this->assertSame( $this->user, $embedded_user['id'] );
}
/**
* @group get_item
*/
public function test_get_embedded_group_from_notification_item() {
$group_id = $this->bp::factory()->group->create();
$notification_id = $this->bp::factory()->notification->create(
$this->set_notification_data(
array(
'component_name' => buddypress()->groups->id,
'item_id' => $group_id,
)
)
);
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( '_embed' => 'group' ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$data = $this->server->response_to_data( $response, true );
$this->assertNotEmpty( $data['_embedded']['group'] );
$embedded_group = current( $data['_embedded']['group'] );
$this->assertNotEmpty( $embedded_group );
$this->assertSame( $notification_id, $data['id'] );
$this->assertSame( $group_id, $embedded_group['id'] );
}
/**
* @group get_item
*/
public function test_get_embedded_activity_from_notification_item() {
$activity_id = $this->bp::factory()->activity->create();
$notification_id = $this->bp::factory()->notification->create(
$this->set_notification_data(
array(
'component_name' => buddypress()->activity->id,
'item_id' => $activity_id,
)
)
);
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( '_embed' => 'activity' ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$data = $this->server->response_to_data( $response, true );
$this->assertNotEmpty( $data['_embedded']['activity'] );
$embedded_activity = current( $data['_embedded']['activity'] );
$this->assertNotEmpty( $embedded_activity );
$this->assertSame( $notification_id, $data['id'] );
$this->assertSame( $activity_id, $embedded_activity['id'] );
}
/**
* @group get_item
*/
public function test_get_embedded_blog_from_notification_item() {
$this->skipWithoutMultisite();
$this->markTestSkipped( 'Test is failing due to another test resetting the blog.' );
$blog_title = 'The Foo Bar Blog';
wp_set_current_user( $this->user );
$blog_id = self::factory()->blog->create(
array( 'title' => $blog_title )
);
$notification_id = $this->bp::factory()->notification->create(
$this->set_notification_data(
array(
'component_name' => buddypress()->blogs->id,
'item_id' => $blog_id,
)
)
);
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'view' );
$request->set_query_params( array( '_embed' => 'blog' ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$data = $this->server->response_to_data( $response, true );
$this->assertNotEmpty( $data['_embedded']['blog'] );
$embedded_blog = current( $data['_embedded']['blog'] );
$this->assertNotEmpty( $embedded_blog );
$this->assertSame( $notification_id, $data['id'] );
$this->assertSame( $blog_id, $embedded_blog['id'] );
$this->assertSame( $blog_title, $embedded_blog['name'] );
}
/**
* @group get_item
*/
public function test_get_item_user_not_logged_in() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group get_item
*/
public function test_get_item_user_cannot_see_notification() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
$u = static::factory()->user->create();
wp_set_current_user( $u );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group create_item
*/
public function test_create_item() {
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'POST', $this->endpoint_url );
$request->add_header( 'content-type', 'application/x-www-form-urlencoded' );
$params = $this->set_notification_data();
$request->set_param( 'context', 'edit' );
$request->set_body_params( $params );
$response = $this->server->dispatch( $request );
$this->check_create_notification_response( $response );
}
/**
* @group create_item
*/
public function test_rest_create_item() {
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'POST', $this->endpoint_url );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data();
$request->set_body( wp_json_encode( $params ) );
$response = $this->server->dispatch( $request );
$this->check_create_notification_response( $response );
}
/**
* @group create_item
*/
public function test_create_item_user_not_logged_in() {
$request = new WP_REST_Request( 'POST', $this->endpoint_url );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data();
$request->set_body( wp_json_encode( $params ) );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group create_item
*/
public function test_create_item_user_cannot_create() {
$u = static::factory()->user->create();
wp_set_current_user( $u );
$request = new WP_REST_Request( 'POST', $this->endpoint_url );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data();
$request->set_body( wp_json_encode( $params ) );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group update_item
*/
public function test_update_item() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'PUT', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data( array( 'is_new' => 0 ) );
$request->set_body( wp_json_encode( $params ) );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$new_data = $response->get_data();
$this->assertNotEmpty( $new_data );
$n = $this->endpoint->get_notification_object( $new_data['id'] );
$this->assertEquals( $params['is_new'], $n->is_new );
}
/**
* @group update_item
*/
public function test_update_item_invalid_id() {
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'PUT', sprintf( $this->endpoint_url . '/%d', REST_TESTS_IMPOSSIBLY_HIGH_NUMBER ) );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data( array( 'is_new' => 0 ) );
$request->set_body( wp_json_encode( $params ) );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_notification_invalid_id', $response, 404 );
}
/**
* @group update_item
*/
public function test_update_item_user_not_logged_in() {
$request = new WP_REST_Request( 'PUT', sprintf( $this->endpoint_url . '/%d', $this->notification_id ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group update_item
*/
public function test_update_item_user_without_access() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
$u = static::factory()->user->create();
wp_set_current_user( $u );
$request = new WP_REST_Request( 'PUT', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group update_item
*/
public function test_update_item_same_status() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'PUT', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data( array( 'is_new' => 1 ) );
$request->set_body( wp_json_encode( $params ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_user_cannot_update_notification_status', $response, 500 );
}
/**
* @group delete_item
*/
public function test_delete_item() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
$notification = $this->endpoint->get_notification_object( $notification_id );
$this->assertEquals( $notification_id, $notification->id );
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'DELETE', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertNotInstanceOf( 'WP_Error', $response );
$this->assertEquals( 200, $response->get_status() );
$all_data = $response->get_data();
$this->assertNotEmpty( $all_data );
$this->check_notification_data( $notification, $all_data['previous'] );
}
/**
* @group delete_item
*/
public function test_delete_item_invalid_id() {
wp_set_current_user( $this->user );
$request = new WP_REST_Request( 'DELETE', sprintf( $this->endpoint_url . '/%d', REST_TESTS_IMPOSSIBLY_HIGH_NUMBER ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_notification_invalid_id', $response, 404 );
}
/**
* @group delete_item
*/
public function test_delete_item_user_not_logged_in() {
$request = new WP_REST_Request( 'DELETE', sprintf( $this->endpoint_url . '/%d', $this->notification_id ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group delete_item
*/
public function test_delete_item_user_without_access() {
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
$u = static::factory()->user->create();
wp_set_current_user( $u );
$request = new WP_REST_Request( 'DELETE', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'edit' );
$response = $this->server->dispatch( $request );
$this->assertErrorResponse( 'bp_rest_authorization_required', $response, rest_authorization_required_code() );
}
/**
* @group prepare_item
*/
public function test_prepare_item() {
wp_set_current_user( $this->user );
$notification = $this->endpoint->get_notification_object( $this->notification_id );
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $notification->id ) );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$this->assertEquals( 200, $response->get_status() );
$all_data = $response->get_data();
$this->assertNotEmpty( $all_data );
$this->check_notification_data( $notification, $all_data );
}
protected function check_notification_data( $notification, $data ) {
$this->assertEquals( $notification->id, $data['id'] );
$this->assertEquals( $notification->user_id, $data['user_id'] );
$this->assertEquals( $notification->item_id, $data['item_id'] );
$this->assertEquals( $notification->secondary_item_id, $data['secondary_item_id'] );
$this->assertEquals( $notification->component_name, $data['component'] );
$this->assertEquals( $notification->component_action, $data['action'] );
$this->assertEquals(
bp_rest_prepare_date_response( $notification->date_notified, get_date_from_gmt( $notification->date_notified ) ),
$data['date']
);
$this->assertEquals( bp_rest_prepare_date_response( $notification->date_notified ), $data['date_gmt'] );
$this->assertEquals( $notification->is_new, $data['is_new'] );
}
protected function set_notification_data( $args = array() ) {
return wp_parse_args(
$args,
array(
'user_id' => $this->user,
'is_new' => 1,
)
);
}
protected function check_update_notification_response( $response ) {
$this->assertNotInstanceOf( 'WP_Error', $response );
$response = rest_ensure_response( $response );
$this->assertEquals( 200, $response->get_status() );
$headers = $response->get_headers();
$this->assertArrayNotHasKey( 'Location', $headers );
$data = $response->get_data();
$this->assertNotEmpty( $data );
$group = $this->endpoint->get_notification_object( $data['id'] );
$this->check_notification_data( $group, $data );
}
protected function check_create_notification_response( $response ) {
$this->assertNotInstanceOf( 'WP_Error', $response );
$response = rest_ensure_response( $response );
$this->assertEquals( 200, $response->get_status() );
$data = $response->get_data();
$this->assertNotEmpty( $data );
$notification = $this->endpoint->get_notification_object( $data['id'] );
$this->check_notification_data( $notification, $data );
}
public function test_get_item_schema() {
$request = new WP_REST_Request( 'OPTIONS', $this->endpoint_url );
$response = $this->server->dispatch( $request );
$data = $response->get_data();
$properties = $data['schema']['properties'];
$this->assertEquals( 9, count( $properties ) );
$this->assertArrayHasKey( 'id', $properties );
$this->assertArrayHasKey( 'item_id', $properties );
$this->assertArrayHasKey( 'secondary_item_id', $properties );
$this->assertArrayHasKey( 'user_id', $properties );
$this->assertArrayHasKey( 'component', $properties );
$this->assertArrayHasKey( 'action', $properties );
$this->assertArrayHasKey( 'date', $properties );
$this->assertArrayHasKey( 'date_gmt', $properties );
$this->assertArrayHasKey( 'is_new', $properties );
}
public function test_context_param() {
// Collection.
$request = new WP_REST_Request( 'OPTIONS', $this->endpoint_url );
$response = $this->server->dispatch( $request );
$data = $response->get_data();
$this->assertEquals( 'view', $data['endpoints'][0]['args']['context']['default'] );
$this->assertEquals( array( 'view', 'edit' ), $data['endpoints'][0]['args']['context']['enum'] );
// Single.
$request = new WP_REST_Request( 'OPTIONS', sprintf( $this->endpoint_url . '/%d', $this->notification_id ) );
$response = $this->server->dispatch( $request );
$data = $response->get_data();
$this->assertEquals( 'view', $data['endpoints'][0]['args']['context']['default'] );
$this->assertEquals( array( 'view', 'edit' ), $data['endpoints'][0]['args']['context']['enum'] );
}
public function update_additional_field( $value, $data, $attribute ) {
return bp_notifications_update_meta( $data->id, '_' . $attribute, $value );
}
public function get_additional_field( $data, $attribute ) {
return bp_notifications_get_meta( $data['id'], '_' . $attribute );
}
/**
* @group additional_fields
*/
public function test_additional_fields() {
$registered_fields = $GLOBALS['wp_rest_additional_fields'];
bp_rest_register_field(
'notifications',
'foo_field',
array(
'get_callback' => array( $this, 'get_additional_field' ),
'update_callback' => array( $this, 'update_additional_field' ),
'schema' => array(
'description' => 'Notification Meta Field',
'type' => 'string',
'context' => array( 'view', 'edit' ),
),
)
);
wp_set_current_user( $this->user );
$expected = 'bar_value';
// POST
$request = new WP_REST_Request( 'POST', $this->endpoint_url );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/x-www-form-urlencoded' );
$params = $this->set_notification_data( array( 'foo_field' => $expected ) );
$request->set_body_params( $params );
$response = $this->server->dispatch( $request );
$create_data = $response->get_data();
$this->assertTrue( $expected === $create_data['foo_field'] );
// GET
$request = new WP_REST_Request( 'GET', sprintf( $this->endpoint_url . '/%d', $create_data['id'] ) );
$request->set_param( 'context', 'view' );
$response = $this->server->dispatch( $request );
$get_data = $response->get_data();
$this->assertTrue( $expected === $get_data['foo_field'] );
$GLOBALS['wp_rest_additional_fields'] = $registered_fields;
}
/**
* @group additional_fields
*/
public function test_update_additional_fields() {
$registered_fields = $GLOBALS['wp_rest_additional_fields'];
bp_rest_register_field(
'notifications',
'bar_field',
array(
'get_callback' => array( $this, 'get_additional_field' ),
'update_callback' => array( $this, 'update_additional_field' ),
'schema' => array(
'description' => 'Notification Meta Field',
'type' => 'string',
'context' => array( 'view', 'edit' ),
),
)
);
$notification_id = $this->bp::factory()->notification->create( $this->set_notification_data() );
wp_set_current_user( $this->user );
$expected = 'foo_value';
// Put
$request = new WP_REST_Request( 'PUT', sprintf( $this->endpoint_url . '/%d', $notification_id ) );
$request->set_param( 'context', 'edit' );
$request->add_header( 'content-type', 'application/json' );
$params = $this->set_notification_data(
array(
'is_new' => 0,
'bar_field' => 'foo_value',
)
);
$request->set_body( wp_json_encode( $params ) );
$response = $this->server->dispatch( $request );
$update_data = $response->get_data();
$this->assertTrue( $expected === $update_data['bar_field'] );
$GLOBALS['wp_rest_additional_fields'] = $registered_fields;
}
}