user_test.go 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380
  1. // Copyright 2018 Frédéric Guillot. All rights reserved.
  2. // Use of this source code is governed by the Apache 2.0
  3. // license that can be found in the LICENSE file.
  4. // +build integration
  5. package tests
  6. import (
  7. "testing"
  8. miniflux "miniflux.app/client"
  9. )
  10. func TestWithWrongCredentials(t *testing.T) {
  11. client := miniflux.New(testBaseURL, "invalid", "invalid")
  12. _, err := client.Users()
  13. if err == nil {
  14. t.Fatal(`Using bad credentials should raise an error`)
  15. }
  16. if err != miniflux.ErrNotAuthorized {
  17. t.Fatal(`A "Not Authorized" error should be raised`)
  18. }
  19. }
  20. func TestGetCurrentLoggedUser(t *testing.T) {
  21. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  22. user, err := client.Me()
  23. if err != nil {
  24. t.Fatal(err)
  25. }
  26. if user.ID == 0 {
  27. t.Fatalf(`Invalid userID, got %q`, user.ID)
  28. }
  29. if user.Username != testAdminUsername {
  30. t.Fatalf(`Invalid username, got %q`, user.Username)
  31. }
  32. }
  33. func TestGetUsers(t *testing.T) {
  34. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  35. users, err := client.Users()
  36. if err != nil {
  37. t.Fatal(err)
  38. }
  39. if len(users) == 0 {
  40. t.Fatal("The list of users is empty")
  41. }
  42. if users[0].ID == 0 {
  43. t.Fatalf(`Invalid userID, got "%v"`, users[0].ID)
  44. }
  45. if users[0].Username != testAdminUsername {
  46. t.Fatalf(`Invalid username, got "%v" instead of "%v"`, users[0].Username, testAdminUsername)
  47. }
  48. if users[0].Password != "" {
  49. t.Fatalf(`Invalid password, got "%v"`, users[0].Password)
  50. }
  51. if users[0].Language != "en_US" {
  52. t.Fatalf(`Invalid language, got "%v"`, users[0].Language)
  53. }
  54. if users[0].Theme != "default" {
  55. t.Fatalf(`Invalid theme, got "%v"`, users[0].Theme)
  56. }
  57. if users[0].Timezone != "UTC" {
  58. t.Fatalf(`Invalid timezone, got "%v"`, users[0].Timezone)
  59. }
  60. if !users[0].IsAdmin {
  61. t.Fatalf(`Invalid role, got "%v"`, users[0].IsAdmin)
  62. }
  63. }
  64. func TestCreateStandardUser(t *testing.T) {
  65. username := getRandomUsername()
  66. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  67. user, err := client.CreateUser(username, testStandardPassword, false)
  68. if err != nil {
  69. t.Fatal(err)
  70. }
  71. if user.ID == 0 {
  72. t.Fatalf(`Invalid userID, got "%v"`, user.ID)
  73. }
  74. if user.Username != username {
  75. t.Fatalf(`Invalid username, got "%v" instead of "%v"`, user.Username, username)
  76. }
  77. if user.Password != "" {
  78. t.Fatalf(`Invalid password, got "%v"`, user.Password)
  79. }
  80. if user.Language != "en_US" {
  81. t.Fatalf(`Invalid language, got "%v"`, user.Language)
  82. }
  83. if user.Theme != "default" {
  84. t.Fatalf(`Invalid theme, got "%v"`, user.Theme)
  85. }
  86. if user.Timezone != "UTC" {
  87. t.Fatalf(`Invalid timezone, got "%v"`, user.Timezone)
  88. }
  89. if user.IsAdmin {
  90. t.Fatalf(`Invalid role, got "%v"`, user.IsAdmin)
  91. }
  92. if user.LastLoginAt != nil {
  93. t.Fatalf(`Invalid last login date, got "%v"`, user.LastLoginAt)
  94. }
  95. }
  96. func TestRemoveUser(t *testing.T) {
  97. username := getRandomUsername()
  98. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  99. user, err := client.CreateUser(username, testStandardPassword, false)
  100. if err != nil {
  101. t.Fatal(err)
  102. }
  103. if err := client.DeleteUser(user.ID); err != nil {
  104. t.Fatalf(`Unable to remove user: "%v"`, err)
  105. }
  106. }
  107. func TestGetUserByID(t *testing.T) {
  108. username := getRandomUsername()
  109. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  110. user, err := client.CreateUser(username, testStandardPassword, false)
  111. if err != nil {
  112. t.Fatal(err)
  113. }
  114. _, err = client.UserByID(99999)
  115. if err == nil {
  116. t.Fatal(`Should returns a 404`)
  117. }
  118. user, err = client.UserByID(user.ID)
  119. if err != nil {
  120. t.Fatal(err)
  121. }
  122. if user.ID == 0 {
  123. t.Fatalf(`Invalid userID, got "%v"`, user.ID)
  124. }
  125. if user.Username != username {
  126. t.Fatalf(`Invalid username, got "%v" instead of "%v"`, user.Username, username)
  127. }
  128. if user.Password != "" {
  129. t.Fatalf(`Invalid password, got "%v"`, user.Password)
  130. }
  131. if user.Language != "en_US" {
  132. t.Fatalf(`Invalid language, got "%v"`, user.Language)
  133. }
  134. if user.Theme != "default" {
  135. t.Fatalf(`Invalid theme, got "%v"`, user.Theme)
  136. }
  137. if user.Timezone != "UTC" {
  138. t.Fatalf(`Invalid timezone, got "%v"`, user.Timezone)
  139. }
  140. if user.IsAdmin {
  141. t.Fatalf(`Invalid role, got "%v"`, user.IsAdmin)
  142. }
  143. if user.LastLoginAt != nil {
  144. t.Fatalf(`Invalid last login date, got "%v"`, user.LastLoginAt)
  145. }
  146. }
  147. func TestGetUserByUsername(t *testing.T) {
  148. username := getRandomUsername()
  149. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  150. user, err := client.CreateUser(username, testStandardPassword, false)
  151. if err != nil {
  152. t.Fatal(err)
  153. }
  154. _, err = client.UserByUsername("missinguser")
  155. if err == nil {
  156. t.Fatal(`Should returns a 404`)
  157. }
  158. user, err = client.UserByUsername(username)
  159. if err != nil {
  160. t.Fatal(err)
  161. }
  162. if user.ID == 0 {
  163. t.Fatalf(`Invalid userID, got "%v"`, user.ID)
  164. }
  165. if user.Username != username {
  166. t.Fatalf(`Invalid username, got "%v" instead of "%v"`, user.Username, username)
  167. }
  168. if user.Password != "" {
  169. t.Fatalf(`Invalid password, got "%v"`, user.Password)
  170. }
  171. if user.Language != "en_US" {
  172. t.Fatalf(`Invalid language, got "%v"`, user.Language)
  173. }
  174. if user.Theme != "default" {
  175. t.Fatalf(`Invalid theme, got "%v"`, user.Theme)
  176. }
  177. if user.Timezone != "UTC" {
  178. t.Fatalf(`Invalid timezone, got "%v"`, user.Timezone)
  179. }
  180. if user.IsAdmin {
  181. t.Fatalf(`Invalid role, got "%v"`, user.IsAdmin)
  182. }
  183. if user.LastLoginAt != nil {
  184. t.Fatalf(`Invalid last login date, got "%v"`, user.LastLoginAt)
  185. }
  186. }
  187. func TestUpdateUserTheme(t *testing.T) {
  188. username := getRandomUsername()
  189. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  190. user, err := client.CreateUser(username, testStandardPassword, false)
  191. if err != nil {
  192. t.Fatal(err)
  193. }
  194. theme := "black"
  195. user, err = client.UpdateUser(user.ID, &miniflux.UserModification{Theme: &theme})
  196. if err != nil {
  197. t.Fatal(err)
  198. }
  199. if user.Theme != theme {
  200. t.Fatalf(`Unable to update user Theme: got "%v" instead of "%v"`, user.Theme, theme)
  201. }
  202. }
  203. func TestUpdateUserThemeWithInvalidValue(t *testing.T) {
  204. username := getRandomUsername()
  205. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  206. user, err := client.CreateUser(username, testStandardPassword, false)
  207. if err != nil {
  208. t.Fatal(err)
  209. }
  210. theme := "something that doesn't exists"
  211. _, err = client.UpdateUser(user.ID, &miniflux.UserModification{Theme: &theme})
  212. if err == nil {
  213. t.Fatal(`Updating a user Theme with an invalid value should raise an error`)
  214. }
  215. }
  216. func TestCannotCreateDuplicateUser(t *testing.T) {
  217. username := getRandomUsername()
  218. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  219. _, err := client.CreateUser(username, testStandardPassword, false)
  220. if err != nil {
  221. t.Fatal(err)
  222. }
  223. _, err = client.CreateUser(username, testStandardPassword, false)
  224. if err == nil {
  225. t.Fatal(`Duplicate users should not be allowed`)
  226. }
  227. }
  228. func TestCannotListUsersAsNonAdmin(t *testing.T) {
  229. username := getRandomUsername()
  230. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  231. _, err := client.CreateUser(username, testStandardPassword, false)
  232. if err != nil {
  233. t.Fatal(err)
  234. }
  235. client = miniflux.New(testBaseURL, username, testStandardPassword)
  236. _, err = client.Users()
  237. if err == nil {
  238. t.Fatal(`Standard users should not be able to list any users`)
  239. }
  240. if err != miniflux.ErrForbidden {
  241. t.Fatal(`A "Forbidden" error should be raised`)
  242. }
  243. }
  244. func TestCannotGetUserAsNonAdmin(t *testing.T) {
  245. username := getRandomUsername()
  246. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  247. user, err := client.CreateUser(username, testStandardPassword, false)
  248. if err != nil {
  249. t.Fatal(err)
  250. }
  251. client = miniflux.New(testBaseURL, username, testStandardPassword)
  252. _, err = client.UserByID(user.ID)
  253. if err == nil {
  254. t.Fatal(`Standard users should not be able to get any users`)
  255. }
  256. if err != miniflux.ErrForbidden {
  257. t.Fatal(`A "Forbidden" error should be raised`)
  258. }
  259. }
  260. func TestCannotUpdateUserAsNonAdmin(t *testing.T) {
  261. username := getRandomUsername()
  262. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  263. user, err := client.CreateUser(username, testStandardPassword, false)
  264. if err != nil {
  265. t.Fatal(err)
  266. }
  267. client = miniflux.New(testBaseURL, username, testStandardPassword)
  268. _, err = client.UpdateUser(user.ID, &miniflux.UserModification{})
  269. if err == nil {
  270. t.Fatal(`Standard users should not be able to update any users`)
  271. }
  272. if err != miniflux.ErrForbidden {
  273. t.Fatal(`A "Forbidden" error should be raised`)
  274. }
  275. }
  276. func TestCannotCreateUserAsNonAdmin(t *testing.T) {
  277. username := getRandomUsername()
  278. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  279. _, err := client.CreateUser(username, testStandardPassword, false)
  280. if err != nil {
  281. t.Fatal(err)
  282. }
  283. client = miniflux.New(testBaseURL, username, testStandardPassword)
  284. _, err = client.CreateUser(username, testStandardPassword, false)
  285. if err == nil {
  286. t.Fatal(`Standard users should not be able to create users`)
  287. }
  288. if err != miniflux.ErrForbidden {
  289. t.Fatal(`A "Forbidden" error should be raised`)
  290. }
  291. }
  292. func TestCannotDeleteUserAsNonAdmin(t *testing.T) {
  293. username := getRandomUsername()
  294. client := miniflux.New(testBaseURL, testAdminUsername, testAdminPassword)
  295. user, err := client.CreateUser(username, testStandardPassword, false)
  296. if err != nil {
  297. t.Fatal(err)
  298. }
  299. client = miniflux.New(testBaseURL, username, testStandardPassword)
  300. err = client.DeleteUser(user.ID)
  301. if err == nil {
  302. t.Fatal(`Standard users should not be able to remove any users`)
  303. }
  304. if err != miniflux.ErrForbidden {
  305. t.Fatal(`A "Forbidden" error should be raised`)
  306. }
  307. }