account_test.rb
297 lines
| 10.0 KiB
| text/x-ruby
|
RubyLexer
|
r6535 | # Redmine - project management software | ||
|
r12461 | # Copyright (C) 2006-2014 Jean-Philippe Lang | ||
|
r5 | # | ||
# This program is free software; you can redistribute it and/or | ||||
# modify it under the terms of the GNU General Public License | ||||
# as published by the Free Software Foundation; either version 2 | ||||
# of the License, or (at your option) any later version. | ||||
|
r6535 | # | ||
|
r5 | # This program is distributed in the hope that it will be useful, | ||
# but WITHOUT ANY WARRANTY; without even the implied warranty of | ||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||||
# GNU General Public License for more details. | ||||
|
r6535 | # | ||
|
r5 | # You should have received a copy of the GNU General Public License | ||
# along with this program; if not, write to the Free Software | ||||
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. | ||||
|
r4395 | require File.expand_path('../../test_helper', __FILE__) | ||
|
r5 | |||
|
r1661 | begin | ||
|
r11666 | require 'mocha/setup' | ||
|
r1661 | rescue | ||
# Won't run some tests | ||||
end | ||||
|
r5 | class AccountTest < ActionController::IntegrationTest | ||
|
r3009 | fixtures :users, :roles | ||
|
r5 | |||
def test_login | ||||
|
r60 | get "my/page" | ||
|
r2430 | assert_redirected_to "/login?back_url=http%3A%2F%2Fwww.example.com%2Fmy%2Fpage" | ||
|
r10 | log_user('jsmith', 'jsmith') | ||
|
r6535 | |||
|
r60 | get "my/account" | ||
|
r5 | assert_response :success | ||
|
r6535 | assert_template "my/account" | ||
|
r5 | end | ||
|
r6535 | |||
|
r2460 | def test_autologin | ||
user = User.find(1) | ||||
Setting.autologin = "7" | ||||
Token.delete_all | ||||
|
r6535 | |||
|
r2460 | # User logs in with 'autologin' checked | ||
post '/login', :username => user.login, :password => 'admin', :autologin => 1 | ||||
|
r4293 | assert_redirected_to '/my/page' | ||
|
r10704 | token = Token.first | ||
|
r2460 | assert_not_nil token | ||
assert_equal user, token.user | ||||
assert_equal 'autologin', token.action | ||||
assert_equal user.id, session[:user_id] | ||||
assert_equal token.value, cookies['autologin'] | ||||
|
r6535 | |||
|
r2460 | # Session is cleared | ||
reset! | ||||
User.current = nil | ||||
# Clears user's last login timestamp | ||||
user.update_attribute :last_login_on, nil | ||||
assert_nil user.reload.last_login_on | ||||
|
r6535 | |||
|
r11761 | # User comes back with user's autologin cookie | ||
|
r2460 | cookies[:autologin] = token.value | ||
get '/my/page' | ||||
assert_response :success | ||||
assert_template 'my/page' | ||||
assert_equal user.id, session[:user_id] | ||||
assert_not_nil user.reload.last_login_on | ||||
end | ||||
|
r6535 | |||
|
r11289 | def test_autologin_should_use_autologin_cookie_name | ||
Token.delete_all | ||||
Redmine::Configuration.stubs(:[]).with('autologin_cookie_name').returns('custom_autologin') | ||||
Redmine::Configuration.stubs(:[]).with('autologin_cookie_path').returns('/') | ||||
Redmine::Configuration.stubs(:[]).with('autologin_cookie_secure').returns(false) | ||||
with_settings :autologin => '7' do | ||||
assert_difference 'Token.count' do | ||||
post '/login', :username => 'admin', :password => 'admin', :autologin => 1 | ||||
end | ||||
assert_response 302 | ||||
assert cookies['custom_autologin'].present? | ||||
token = cookies['custom_autologin'] | ||||
|
r11437 | |||
|
r11289 | # Session is cleared | ||
reset! | ||||
cookies['custom_autologin'] = token | ||||
get '/my/page' | ||||
assert_response :success | ||||
|
r11290 | |||
assert_difference 'Token.count', -1 do | ||||
post '/logout' | ||||
end | ||||
assert cookies['custom_autologin'].blank? | ||||
|
r11289 | end | ||
end | ||||
|
r10 | def test_lost_password | ||
|
r214 | Token.delete_all | ||
|
r6535 | |||
|
r10 | get "account/lost_password" | ||
assert_response :success | ||||
assert_template "account/lost_password" | ||||
|
r9758 | assert_select 'input[name=mail]' | ||
|
r6535 | |||
|
r2120 | post "account/lost_password", :mail => 'jSmith@somenet.foo' | ||
|
r2430 | assert_redirected_to "/login" | ||
|
r6535 | |||
|
r10701 | token = Token.first | ||
|
r10 | assert_equal 'recovery', token.action | ||
assert_equal 'jsmith@somenet.foo', token.user.mail | ||||
assert !token.expired? | ||||
|
r6535 | |||
|
r10 | get "account/lost_password", :token => token.value | ||
assert_response :success | ||||
assert_template "account/password_recovery" | ||||
|
r9758 | assert_select 'input[type=hidden][name=token][value=?]', token.value | ||
assert_select 'input[name=new_password]' | ||||
assert_select 'input[name=new_password_confirmation]' | ||||
|
r6535 | |||
|
r11437 | post "account/lost_password", | ||
:token => token.value, :new_password => 'newpass123', | ||||
:new_password_confirmation => 'newpass123' | ||||
|
r2430 | assert_redirected_to "/login" | ||
|
r10 | assert_equal 'Password was successfully updated.', flash[:notice] | ||
|
r6535 | |||
|
r10659 | log_user('jsmith', 'newpass123') | ||
|
r6535 | assert_equal 0, Token.count | ||
|
r902 | end | ||
|
r6535 | |||
|
r11851 | def test_user_with_must_change_passwd_should_be_forced_to_change_its_password | ||
User.find_by_login('jsmith').update_attribute :must_change_passwd, true | ||||
post '/login', :username => 'jsmith', :password => 'jsmith' | ||||
assert_redirected_to '/my/page' | ||||
follow_redirect! | ||||
assert_redirected_to '/my/password' | ||||
get '/issues' | ||||
assert_redirected_to '/my/password' | ||||
end | ||||
def test_user_with_must_change_passwd_should_be_able_to_change_its_password | ||||
User.find_by_login('jsmith').update_attribute :must_change_passwd, true | ||||
post '/login', :username => 'jsmith', :password => 'jsmith' | ||||
assert_redirected_to '/my/page' | ||||
follow_redirect! | ||||
assert_redirected_to '/my/password' | ||||
follow_redirect! | ||||
assert_response :success | ||||
post '/my/password', :password => 'jsmith', :new_password => 'newpassword', :new_password_confirmation => 'newpassword' | ||||
assert_redirected_to '/my/account' | ||||
follow_redirect! | ||||
assert_response :success | ||||
assert_equal false, User.find_by_login('jsmith').must_change_passwd? | ||||
end | ||||
|
r902 | def test_register_with_automatic_activation | ||
Setting.self_registration = '3' | ||||
|
r6535 | |||
|
r902 | get 'account/register' | ||
assert_response :success | ||||
assert_template 'account/register' | ||||
|
r6535 | |||
|
r11437 | post 'account/register', | ||
:user => {:login => "newuser", :language => "en", | ||||
:firstname => "New", :lastname => "User", :mail => "newuser@foo.bar", | ||||
:password => "newpass123", :password_confirmation => "newpass123"} | ||||
|
r4293 | assert_redirected_to '/my/account' | ||
|
r1507 | follow_redirect! | ||
assert_response :success | ||||
assert_template 'my/account' | ||||
|
r6535 | |||
|
r2526 | user = User.find_by_login('newuser') | ||
assert_not_nil user | ||||
assert user.active? | ||||
assert_not_nil user.last_login_on | ||||
|
r902 | end | ||
|
r6535 | |||
|
r902 | def test_register_with_manual_activation | ||
Setting.self_registration = '2' | ||||
|
r6535 | |||
|
r11437 | post 'account/register', | ||
:user => {:login => "newuser", :language => "en", | ||||
:firstname => "New", :lastname => "User", :mail => "newuser@foo.bar", | ||||
:password => "newpass123", :password_confirmation => "newpass123"} | ||||
|
r2430 | assert_redirected_to '/login' | ||
|
r902 | assert !User.find_by_login('newuser').active? | ||
end | ||||
|
r6535 | |||
|
r902 | def test_register_with_email_activation | ||
Setting.self_registration = '1' | ||||
Token.delete_all | ||||
|
r6535 | |||
|
r11437 | post 'account/register', | ||
:user => {:login => "newuser", :language => "en", | ||||
:firstname => "New", :lastname => "User", :mail => "newuser@foo.bar", | ||||
:password => "newpass123", :password_confirmation => "newpass123"} | ||||
|
r2430 | assert_redirected_to '/login' | ||
|
r902 | assert !User.find_by_login('newuser').active? | ||
|
r6535 | |||
|
r10701 | token = Token.first | ||
|
r902 | assert_equal 'register', token.action | ||
assert_equal 'newuser@foo.bar', token.user.mail | ||||
assert !token.expired? | ||||
|
r6535 | |||
|
r902 | get 'account/activate', :token => token.value | ||
|
r2430 | assert_redirected_to '/login' | ||
|
r10659 | log_user('newuser', 'newpass123') | ||
|
r902 | end | ||
|
r6535 | |||
|
r1661 | def test_onthefly_registration | ||
# disable registration | ||||
Setting.self_registration = '0' | ||||
|
r11437 | AuthSource.expects(:authenticate).returns( | ||
{:login => 'foo', :firstname => 'Foo', :lastname => 'Smith', | ||||
:mail => 'foo@bar.com', :auth_source_id => 66}) | ||||
|
r6535 | |||
|
r8061 | post '/login', :username => 'foo', :password => 'bar' | ||
|
r4293 | assert_redirected_to '/my/page' | ||
|
r6535 | |||
|
r1661 | user = User.find_by_login('foo') | ||
assert user.is_a?(User) | ||||
assert_equal 66, user.auth_source_id | ||||
assert user.hashed_password.blank? | ||||
end | ||||
|
r6535 | |||
|
r1661 | def test_onthefly_registration_with_invalid_attributes | ||
# disable registration | ||||
Setting.self_registration = '0' | ||||
|
r11437 | AuthSource.expects(:authenticate).returns( | ||
{:login => 'foo', :lastname => 'Smith', :auth_source_id => 66}) | ||||
|
r6535 | |||
|
r8061 | post '/login', :username => 'foo', :password => 'bar' | ||
|
r1661 | assert_response :success | ||
assert_template 'account/register' | ||||
assert_tag :input, :attributes => { :name => 'user[firstname]', :value => '' } | ||||
assert_tag :input, :attributes => { :name => 'user[lastname]', :value => 'Smith' } | ||||
assert_no_tag :input, :attributes => { :name => 'user[login]' } | ||||
assert_no_tag :input, :attributes => { :name => 'user[password]' } | ||||
|
r6535 | |||
|
r11437 | post 'account/register', | ||
:user => {:firstname => 'Foo', :lastname => 'Smith', :mail => 'foo@bar.com'} | ||||
|
r2430 | assert_redirected_to '/my/account' | ||
|
r6535 | |||
|
r1661 | user = User.find_by_login('foo') | ||
assert user.is_a?(User) | ||||
assert_equal 66, user.auth_source_id | ||||
assert user.hashed_password.blank? | ||||
end | ||||
|
r11716 | |||
def test_registered_user_should_be_able_to_get_a_new_activation_email | ||||
Token.delete_all | ||||
|
r11755 | |||
|
r11716 | with_settings :self_registration => '1', :default_language => 'en' do | ||
# register a new account | ||||
assert_difference 'User.count' do | ||||
assert_difference 'Token.count' do | ||||
post 'account/register', | ||||
:user => {:login => "newuser", :language => "en", | ||||
:firstname => "New", :lastname => "User", :mail => "newuser@foo.bar", | ||||
:password => "newpass123", :password_confirmation => "newpass123"} | ||||
end | ||||
end | ||||
user = User.order('id desc').first | ||||
assert_equal User::STATUS_REGISTERED, user.status | ||||
reset! | ||||
# try to use "lost password" | ||||
assert_no_difference 'ActionMailer::Base.deliveries.size' do | ||||
post '/account/lost_password', :mail => 'newuser@foo.bar' | ||||
end | ||||
assert_redirected_to '/account/lost_password' | ||||
follow_redirect! | ||||
assert_response :success | ||||
assert_select 'div.flash', :text => /new activation email/ | ||||
assert_select 'div.flash a[href=/account/activation_email]' | ||||
# request a new action activation email | ||||
assert_difference 'ActionMailer::Base.deliveries.size' do | ||||
get '/account/activation_email' | ||||
end | ||||
assert_redirected_to '/login' | ||||
token = Token.order('id desc').first | ||||
activation_path = "/account/activate?token=#{token.value}" | ||||
assert_include activation_path, mail_body(ActionMailer::Base.deliveries.last) | ||||
# activate the account | ||||
get activation_path | ||||
assert_redirected_to '/login' | ||||
post '/login', :username => 'newuser', :password => 'newpass123' | ||||
assert_redirected_to '/my/page' | ||||
end | ||||
end | ||||
|
r5 | end | ||