1<?php
2
3declare(strict_types=1);
4
5namespace ZnoteX\Tests\Security;
6
7use PHPUnit\Framework\TestCase;
8
9final class AdminPermissionsTest extends TestCase
10{
11 protected function setUp(): void
12 {
13 $GLOBALS['config'] = [
14 'ServerEngine' => 'TFS_10',
15 'page_admin_access' => ['OwnerAccount'],
16 'page_admin_roles' => [
17 'ModeratorAccount' => ['gallery', 'reports'],
18 'SupportAccount' => 'helpdesk',
19 ],
20 ];
21 }
22
23 public function testOwnerNameGrantsTheOwnerRole(): void
24 {
25 $roles = \admin_roles(['name' => 'OwnerAccount']);
26 $this->assertSame(['owner'], $roles);
27 }
28
29 public function testAssignedModulesAreHonoured(): void
30 {
31 $roles = \admin_roles(['name' => 'ModeratorAccount']);
32 $this->assertSame(['gallery', 'reports'], $roles);
33 }
34
35 public function testASingleAssignedModuleStringIsNormalisedToAnArray(): void
36 {
37 $roles = \admin_roles(['name' => 'SupportAccount']);
38 $this->assertSame(['helpdesk'], $roles);
39 }
40
41 public function testUnknownAccountGetsNoRoles(): void
42 {
43 $roles = \admin_roles(['name' => 'SomeoneElse']);
44 $this->assertSame([], $roles);
45 }
46
47 public function testNonArrayUserDataGetsNoRoles(): void
48 {
49 $this->assertSame([], \admin_roles(null));
50 $this->assertSame([], \admin_roles(false));
51 }
52
53 public function testOthireIdentityIsTheAccountIdNotTheName(): void
54 {
55 $GLOBALS['config']['ServerEngine'] = 'OTHIRE';
56 $GLOBALS['config']['page_admin_access'] = [42];
57
58 $this->assertSame(['owner'], \admin_roles(['id' => 42, 'name' => 'OwnerAccount']));
59 $this->assertSame([], \admin_roles(['id' => 99, 'name' => 'OwnerAccount']));
60 }
61
62 public function testOwnerCanReachEveryModule(): void
63 {
64 $this->assertTrue(\acp_can_module('update', ['name' => 'OwnerAccount']));
65 $this->assertTrue(\acp_can_module('settings', ['name' => 'OwnerAccount']));
66 }
67
68 public function testAScopedAccountOnlyReachesItsGrantedModules(): void
69 {
70 $this->assertTrue(\acp_can_module('gallery', ['name' => 'ModeratorAccount']));
71 $this->assertFalse(\acp_can_module('accounts', ['name' => 'ModeratorAccount']));
72 }
73
74 public function testAScopedAccountAlwaysReachesDashboardAndSearch(): void
75 {
76 $this->assertTrue(\acp_can_module('dashboard', ['name' => 'ModeratorAccount']));
77 $this->assertTrue(\acp_can_module('search', ['name' => 'ModeratorAccount']));
78 }
79
80 public function testAnUngrantedAccountReachesNoModuleAtAll(): void
81 {
82 // 'update' was never granted to anyone in this fixture, so only the
83 // owner bypass in acp_can_module() may reach it.
84 $this->assertFalse(\acp_can_module('update', ['name' => 'ModeratorAccount']));
85 $this->assertFalse(\acp_can_module('update', ['name' => 'SupportAccount']));
86 }
87
88 public function testAnonymousVisitorHasNoAccess(): void
89 {
90 $this->assertFalse(\acp_can_module('dashboard', null));
91 }
92}
93