Add tests

This commit is contained in:
Roeland Jago Douma 2016-09-15 12:12:30 +02:00
parent 7c078a81b4
commit 6dace7f6ad
No known key found for this signature in database
GPG key ID: 1E152838F164D13B
2 changed files with 43 additions and 38 deletions

View file

@ -26,6 +26,7 @@ namespace Test\AppFramework\Controller;
use OC\AppFramework\Http\Request; use OC\AppFramework\Http\Request;
use OCP\AppFramework\Http\DataResponse; use OCP\AppFramework\Http\DataResponse;
use OCP\AppFramework\Http\EmptyContentSecurityPolicy;
use OCP\AppFramework\OCSController; use OCP\AppFramework\OCSController;
use OCP\IConfig; use OCP\IConfig;
use OCP\Security\ISecureRandom; use OCP\Security\ISecureRandom;
@ -92,8 +93,9 @@ class OCSControllerTest extends \Test\TestCase {
$params = new DataResponse(['test' => 'hi']); $params = new DataResponse(['test' => 'hi']);
$out = $controller->buildResponse($params, 'xml')->render(); $response = $controller->buildResponse($params, 'xml');
$this->assertEquals($expected, $out); $this->assertSame(EmptyContentSecurityPolicy::class, get_class($response->getContentSecurityPolicy()));
$this->assertEquals($expected, $response->render());
} }
public function testJSON() { public function testJSON() {
@ -111,8 +113,10 @@ class OCSControllerTest extends \Test\TestCase {
'"totalitems":"","itemsperpage":""},"data":{"test":"hi"}}}'; '"totalitems":"","itemsperpage":""},"data":{"test":"hi"}}}';
$params = new DataResponse(['test' => 'hi']); $params = new DataResponse(['test' => 'hi']);
$out = $controller->buildResponse($params, 'json')->render(); $response = $controller->buildResponse($params, 'json');
$this->assertEquals($expected, $out); $this->assertSame(EmptyContentSecurityPolicy::class, get_class($response->getContentSecurityPolicy()));
$this->assertEquals($expected, $response->render());
$this->assertEquals($expected, $response->render());
} }
public function testXMLV2() { public function testXMLV2() {
@ -141,8 +145,9 @@ class OCSControllerTest extends \Test\TestCase {
$params = new DataResponse(['test' => 'hi']); $params = new DataResponse(['test' => 'hi']);
$out = $controller->buildResponse($params, 'xml')->render(); $response = $controller->buildResponse($params, 'xml');
$this->assertEquals($expected, $out); $this->assertSame(EmptyContentSecurityPolicy::class, get_class($response->getContentSecurityPolicy()));
$this->assertEquals($expected, $response->render());
} }
public function testJSONV2() { public function testJSONV2() {
@ -159,7 +164,8 @@ class OCSControllerTest extends \Test\TestCase {
$expected = '{"ocs":{"meta":{"status":"ok","statuscode":200,"message":"OK"},"data":{"test":"hi"}}}'; $expected = '{"ocs":{"meta":{"status":"ok","statuscode":200,"message":"OK"},"data":{"test":"hi"}}}';
$params = new DataResponse(['test' => 'hi']); $params = new DataResponse(['test' => 'hi']);
$out = $controller->buildResponse($params, 'json')->render(); $response = $controller->buildResponse($params, 'json');
$this->assertEquals($expected, $out); $this->assertSame(EmptyContentSecurityPolicy::class, get_class($response->getContentSecurityPolicy()));
$this->assertEquals($expected, $response->render());
} }
} }

View file

@ -37,13 +37,17 @@ use OC\AppFramework\Utility\ControllerMethodReflector;
use OC\Security\CSP\ContentSecurityPolicy; use OC\Security\CSP\ContentSecurityPolicy;
use OC\Security\CSP\ContentSecurityPolicyManager; use OC\Security\CSP\ContentSecurityPolicyManager;
use OCP\AppFramework\Controller; use OCP\AppFramework\Controller;
use OCP\AppFramework\Http\EmptyContentSecurityPolicy;
use OCP\AppFramework\Http\RedirectResponse; use OCP\AppFramework\Http\RedirectResponse;
use OCP\AppFramework\Http\JSONResponse; use OCP\AppFramework\Http\JSONResponse;
use OCP\AppFramework\Http\Response;
use OCP\AppFramework\Http\TemplateResponse; use OCP\AppFramework\Http\TemplateResponse;
use OCP\IConfig;
use OCP\ILogger; use OCP\ILogger;
use OCP\INavigationManager; use OCP\INavigationManager;
use OCP\IRequest; use OCP\IRequest;
use OCP\IURLGenerator; use OCP\IURLGenerator;
use OCP\Security\ISecureRandom;
class SecurityMiddlewareTest extends \Test\TestCase { class SecurityMiddlewareTest extends \Test\TestCase {
@ -72,30 +76,13 @@ class SecurityMiddlewareTest extends \Test\TestCase {
protected function setUp() { protected function setUp() {
parent::setUp(); parent::setUp();
$this->controller = $this->getMockBuilder('OCP\AppFramework\Controller') $this->controller = $this->createMock(Controller::class);
->disableOriginalConstructor()
->getMock();
$this->reader = new ControllerMethodReflector(); $this->reader = new ControllerMethodReflector();
$this->logger = $this->getMockBuilder( $this->logger = $this->createMock(ILogger::class);
'OCP\ILogger') $this->navigationManager = $this->createMock(INavigationManager::class);
->disableOriginalConstructor() $this->urlGenerator = $this->createMock(IURLGenerator::class);
->getMock(); $this->request = $this->createMock(IRequest::class);
$this->navigationManager = $this->getMockBuilder( $this->contentSecurityPolicyManager = $this->createMock(ContentSecurityPolicyManager::class);
'OCP\INavigationManager')
->disableOriginalConstructor()
->getMock();
$this->urlGenerator = $this->getMockBuilder(
'OCP\IURLGenerator')
->disableOriginalConstructor()
->getMock();
$this->request = $this->getMockBuilder(
'OCP\IRequest')
->disableOriginalConstructor()
->getMock();
$this->contentSecurityPolicyManager = $this->getMockBuilder(
'OC\Security\CSP\ContentSecurityPolicyManager')
->disableOriginalConstructor()
->getMock();
$this->middleware = $this->getMiddleware(true, true); $this->middleware = $this->getMiddleware(true, true);
$this->secException = new SecurityException('hey', false); $this->secException = new SecurityException('hey', false);
$this->secAjaxException = new SecurityException('hey', true); $this->secAjaxException = new SecurityException('hey', true);
@ -459,8 +446,8 @@ class SecurityMiddlewareTest extends \Test\TestCase {
'REQUEST_URI' => 'owncloud/index.php/apps/specialapp' 'REQUEST_URI' => 'owncloud/index.php/apps/specialapp'
] ]
], ],
$this->getMockBuilder('\OCP\Security\ISecureRandom')->getMock(), $this->createMock(ISecureRandom::class),
$this->getMockBuilder('\OCP\IConfig')->getMock() $this->createMock(IConfig::class)
); );
$this->middleware = $this->getMiddleware(false, false); $this->middleware = $this->getMiddleware(false, false);
$this->urlGenerator $this->urlGenerator
@ -494,8 +481,8 @@ class SecurityMiddlewareTest extends \Test\TestCase {
'REQUEST_URI' => 'owncloud/index.php/apps/specialapp', 'REQUEST_URI' => 'owncloud/index.php/apps/specialapp',
], ],
], ],
$this->getMockBuilder('\OCP\Security\ISecureRandom')->getMock(), $this->createMock(ISecureRandom::class),
$this->getMockBuilder('\OCP\IConfig')->getMock() $this->createMock(IConfig::class)
); );
$this->middleware = $this->getMiddleware(false, false); $this->middleware = $this->getMiddleware(false, false);
@ -540,8 +527,8 @@ class SecurityMiddlewareTest extends \Test\TestCase {
'REQUEST_URI' => 'owncloud/index.php/apps/specialapp' 'REQUEST_URI' => 'owncloud/index.php/apps/specialapp'
] ]
], ],
$this->getMockBuilder('\OCP\Security\ISecureRandom')->getMock(), $this->createMock(ISecureRandom::class),
$this->getMockBuilder('\OCP\IConfig')->getMock() $this->createMock(IConfig::class)
); );
$this->middleware = $this->getMiddleware(false, false); $this->middleware = $this->getMiddleware(false, false);
$this->logger $this->logger
@ -566,7 +553,7 @@ class SecurityMiddlewareTest extends \Test\TestCase {
} }
public function testAfterController() { public function testAfterController() {
$response = $this->getMockBuilder('\OCP\AppFramework\Http\Response')->disableOriginalConstructor()->getMock(); $response = $this->createMock(Response::class);
$defaultPolicy = new ContentSecurityPolicy(); $defaultPolicy = new ContentSecurityPolicy();
$defaultPolicy->addAllowedImageDomain('defaultpolicy'); $defaultPolicy->addAllowedImageDomain('defaultpolicy');
$currentPolicy = new ContentSecurityPolicy(); $currentPolicy = new ContentSecurityPolicy();
@ -592,4 +579,16 @@ class SecurityMiddlewareTest extends \Test\TestCase {
$this->middleware->afterController($this->controller, 'test', $response); $this->middleware->afterController($this->controller, 'test', $response);
} }
public function testAfterControllerEmptyCSP() {
$response = $this->createMock(Response::class);
$emptyPolicy = new EmptyContentSecurityPolicy();
$response->expects($this->any())
->method('getContentSecurityPolicy')
->willReturn($emptyPolicy);
$response->expects($this->never())
->method('setContentSecurityPolicy');
$this->middleware->afterController($this->controller, 'test', $response);
}
} }