. */ declare(strict_types=1); namespace Fisharebest\Webtrees\Http\Middleware; use Fig\Http\Message\StatusCodeInterface; use Fisharebest\Webtrees\Exceptions\HttpAccessDeniedException; use Fisharebest\Webtrees\GuestUser; use Fisharebest\Webtrees\TestCase; use Fisharebest\Webtrees\Tree; use Fisharebest\Webtrees\User; use Psr\Http\Server\RequestHandlerInterface; use function response; /** * Test the AuthModerator middleware. * * @covers \Fisharebest\Webtrees\Http\Middleware\AuthModerator */ class AuthModeratorTest extends TestCase { /** * @return void */ public function testAllowed(): void { $handler = self::createMock(RequestHandlerInterface::class); $handler->method('handle')->willReturn(response('lorem ipsum')); $user = self::createMock(User::class); $user->method('getPreference')->with(User::PREF_IS_ADMINISTRATOR)->willReturn(''); $tree = self::createMock(Tree::class); $tree->method('getUserPreference')->with($user, User::PREF_TREE_ROLE)->willReturn(User::ROLE_MODERATOR); $request = self::createRequest()->withAttribute('tree', $tree)->withAttribute('user', $user); $middleware = new AuthModerator(); $response = $middleware->process($request, $handler); self::assertSame(StatusCodeInterface::STATUS_OK, $response->getStatusCode()); self::assertSame('lorem ipsum', (string) $response->getBody()); } /** * @return void */ public function testNotAllowed(): void { $this->expectException(HttpAccessDeniedException::class); $this->expectExceptionMessage('You do not have permission to view this page.'); $handler = self::createMock(RequestHandlerInterface::class); $handler->method('handle')->willReturn(response('lorem ipsum')); $user = self::createMock(User::class); $user->method('getPreference')->with(User::PREF_IS_ADMINISTRATOR)->willReturn(''); $tree = self::createMock(Tree::class); $tree->method('getUserPreference')->with($user, User::PREF_TREE_ROLE)->willReturn('edit'); $request = self::createRequest()->withAttribute('tree', $tree)->withAttribute('user', $user); $middleware = new AuthModerator(); $middleware->process($request, $handler); } /** * @return void */ public function testNotLoggedIn(): void { $handler = self::createMock(RequestHandlerInterface::class); $handler->method('handle')->willReturn(response('lorem ipsum')); $tree = self::createMock(Tree::class); $request = self::createRequest()->withAttribute('tree', $tree)->withAttribute('user', new GuestUser()); $middleware = new AuthModerator(); $response = $middleware->process($request, $handler); self::assertSame(StatusCodeInterface::STATUS_FOUND, $response->getStatusCode()); } }