1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95
|
<?php
/**
* Matomo - free/libre analytics platform
*
* @link https://matomo.org
* @license https://www.gnu.org/licenses/gpl-3.0.html GPL v3 or later
*/
namespace Piwik\Plugins\UsersManager\tests\Integration;
use Piwik\Plugins\UsersManager\API as UsersManagerAPI;
use Piwik\Plugins\UsersManager\Model as UsersManagerModel;
use Piwik\Tests\Framework\Fixture;
use Piwik\Tests\Framework\TestCase\IntegrationTestCase;
/**
* @group UsersManager
* @group TokenSecureOnlyTest
*/
class TokenSecureOnlyTest extends IntegrationTestCase
{
protected static $tokenSecureOnly = 'f3fa8c38fd277a9af0fab7e35f9736fe';
public static function beforeTableDataCached()
{
self::createUserAndTokens();
}
private static function createUserAndTokens()
{
if (!Fixture::siteCreated($idSite = 1)) {
Fixture::createWebsite('2021-01-01');
}
if (!UsersManagerAPI::getInstance()->userExists('user1')) {
UsersManagerAPI::getInstance()->addUser('user1', 'user1password', 'user@limited.com');
UsersManagerAPI::getInstance()->setUserAccess('user1', 'view', [1]);
$userModel = new UsersManagerModel();
$userModel->addTokenAuth(
'user1',
self::$tokenSecureOnly,
'Secure Only',
'2020-01-02 03:04:05',
null,
false,
true
);
}
}
/**
* Secure only tokens should return a 401 code if used in a GET request
*/
public function testSecureOnlyTokenAccessDeniedIfGet()
{
$url = Fixture::getTestRootUrl() . '?' . http_build_query([
'module' => 'API',
'method' => 'API.getMatomoVersion',
'token_auth' => self::$tokenSecureOnly,
]);
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$out = curl_exec($ch);
$responseInfo = curl_getinfo($ch);
curl_close($ch);
$this->assertEquals(401, $responseInfo["http_code"]);
$this->assertStringContainsString("or is required to be sent as a POST parameter", $out);
}
/**
* Secure only tokens should return a 200 code if used in a POST request
*/
public function testSecureOnlyTokenAccessGrantedIfPost()
{
$url = Fixture::getTestRootUrl() . '?' . http_build_query([
'module' => 'API',
'method' => 'API.getMatomoVersion',
]);
$ch = curl_init();
curl_setopt($ch, CURLOPT_POSTFIELDS, ['token_auth' => self::$tokenSecureOnly]);
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_exec($ch);
$responseInfo = curl_getinfo($ch);
curl_close($ch);
$this->assertEquals(200, $responseInfo["http_code"]);
}
}
|