. */ declare(strict_types=1); namespace Fisharebest\Webtrees\Http\Middleware; use Fig\Http\Message\StatusCodeInterface; use Fisharebest\Webtrees\Exceptions\HttpAccessDeniedException; use Fisharebest\Webtrees\GuestUser; use Fisharebest\Webtrees\TestCase; use Fisharebest\Webtrees\User; use Psr\Http\Server\RequestHandlerInterface; use function response; /** * Test the AuthAdministrator middleware. * * @covers \Fisharebest\Webtrees\Http\Middleware\AuthAdministrator */ class AuthAdministratorTest extends TestCase { /** * @return void */ public function testAllowed(): void { $handler = self::createMock(RequestHandlerInterface::class); $handler->method('handle')->willReturn(response('lorem ipsum')); $user = self::createMock(User::class); $user->method('getPreference')->with(User::PREF_IS_ADMINISTRATOR)->willReturn('1'); $request = self::createRequest()->withAttribute('user', $user); $middleware = new AuthAdministrator(); $response = $middleware->process($request, $handler); self::assertSame(StatusCodeInterface::STATUS_OK, $response->getStatusCode()); self::assertSame('lorem ipsum', (string) $response->getBody()); } /** * @return void */ public function testNotAllowed(): void { $this->expectException(HttpAccessDeniedException::class); $this->expectExceptionMessage('You do not have permission to view this page.'); $handler = self::createMock(RequestHandlerInterface::class); $handler->method('handle')->willReturn(response('lorem ipsum')); $user = self::createMock(User::class); $user->method('getPreference')->with(User::PREF_IS_ADMINISTRATOR)->willReturn(''); $request = self::createRequest()->withAttribute('user', $user); $middleware = new AuthAdministrator(); $middleware->process($request, $handler); } /** * @return void */ public function testNotLoggedIn(): void { $handler = self::createMock(RequestHandlerInterface::class); $handler->method('handle')->willReturn(response('lorem ipsum')); $request = self::createRequest()->withAttribute('user', new GuestUser()); $middleware = new AuthAdministrator(); $response = $middleware->process($request, $handler); self::assertSame(StatusCodeInterface::STATUS_FOUND, $response->getStatusCode()); } }