File: TokenSecureOnlyTest.php

package info (click to toggle)
matomo 5.8.0-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 95,068 kB
  • sloc: php: 289,425; xml: 127,249; javascript: 112,130; python: 202; sh: 178; makefile: 20; sql: 10
file content (95 lines) | stat: -rw-r--r-- 2,948 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
<?php

/**
 * Matomo - free/libre analytics platform
 *
 * @link    https://matomo.org
 * @license https://www.gnu.org/licenses/gpl-3.0.html GPL v3 or later
 */

namespace Piwik\Plugins\UsersManager\tests\Integration;

use Piwik\Plugins\UsersManager\API as UsersManagerAPI;
use Piwik\Plugins\UsersManager\Model as UsersManagerModel;
use Piwik\Tests\Framework\Fixture;
use Piwik\Tests\Framework\TestCase\IntegrationTestCase;

/**
 * @group UsersManager
 * @group TokenSecureOnlyTest
 */
class TokenSecureOnlyTest extends IntegrationTestCase
{
    protected static $tokenSecureOnly = 'f3fa8c38fd277a9af0fab7e35f9736fe';

    public static function beforeTableDataCached()
    {
        self::createUserAndTokens();
    }

    private static function createUserAndTokens()
    {
        if (!Fixture::siteCreated($idSite = 1)) {
            Fixture::createWebsite('2021-01-01');
        }

        if (!UsersManagerAPI::getInstance()->userExists('user1')) {
            UsersManagerAPI::getInstance()->addUser('user1', 'user1password', 'user@limited.com');
            UsersManagerAPI::getInstance()->setUserAccess('user1', 'view', [1]);

            $userModel = new UsersManagerModel();
            $userModel->addTokenAuth(
                'user1',
                self::$tokenSecureOnly,
                'Secure Only',
                '2020-01-02 03:04:05',
                null,
                false,
                true
            );
        }
    }

    /**
     * Secure only tokens should return a 401 code if used in a GET request
     */
    public function testSecureOnlyTokenAccessDeniedIfGet()
    {
        $url = Fixture::getTestRootUrl() . '?' . http_build_query([
                'module' => 'API',
                'method' => 'API.getMatomoVersion',
                'token_auth' => self::$tokenSecureOnly,
            ]);

        $ch = curl_init();
        curl_setopt($ch, CURLOPT_URL, $url);
        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
        $out = curl_exec($ch);
        $responseInfo = curl_getinfo($ch);
        curl_close($ch);

        $this->assertEquals(401, $responseInfo["http_code"]);
        $this->assertStringContainsString("or is required to be sent as a POST parameter", $out);
    }

    /**
     * Secure only tokens should return a 200 code if used in a POST request
     */
    public function testSecureOnlyTokenAccessGrantedIfPost()
    {
        $url = Fixture::getTestRootUrl() . '?' . http_build_query([
                'module' => 'API',
                'method' => 'API.getMatomoVersion',
            ]);

        $ch = curl_init();
        curl_setopt($ch, CURLOPT_POSTFIELDS, ['token_auth' => self::$tokenSecureOnly]);
        curl_setopt($ch, CURLOPT_URL, $url);
        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
        curl_exec($ch);
        $responseInfo = curl_getinfo($ch);
        curl_close($ch);

        $this->assertEquals(200, $responseInfo["http_code"]);
    }
}