123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326 |
- <?php
- /**
- * @author Christoph Wurst <christoph@owncloud.com>
- *
- * @copyright Copyright (c) 2016, ownCloud, Inc.
- * @license AGPL-3.0
- *
- * This code is free software: you can redistribute it and/or modify
- * it under the terms of the GNU Affero General Public License, version 3,
- * as published by the Free Software Foundation.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU Affero General Public License for more details.
- *
- * You should have received a copy of the GNU Affero General Public License, version 3,
- * along with this program. If not, see <http://www.gnu.org/licenses/>
- *
- */
- namespace Test\Core\Controller;
- use OC\Authentication\TwoFactorAuth\Manager;
- use OC\Authentication\TwoFactorAuth\ProviderSet;
- use OC\Core\Controller\TwoFactorChallengeController;
- use OC_Util;
- use OCP\AppFramework\Http\RedirectResponse;
- use OCP\AppFramework\Http\TemplateResponse;
- use OCP\Authentication\TwoFactorAuth\IProvider;
- use OCP\Authentication\TwoFactorAuth\TwoFactorException;
- use OCP\IRequest;
- use OCP\ISession;
- use OCP\IURLGenerator;
- use OCP\IUser;
- use OCP\IUserSession;
- use OCP\Template;
- use PHPUnit_Framework_MockObject_MockObject;
- use Test\TestCase;
- class TwoFactorChallengeControllerTest extends TestCase {
- /** @var IRequest|PHPUnit_Framework_MockObject_MockObject */
- private $request;
- /** @var Manager|PHPUnit_Framework_MockObject_MockObject */
- private $twoFactorManager;
- /** @var IUserSession|PHPUnit_Framework_MockObject_MockObject */
- private $userSession;
- /** @var ISession|PHPUnit_Framework_MockObject_MockObject */
- private $session;
- /** @var IURLGenerator|PHPUnit_Framework_MockObject_MockObject */
- private $urlGenerator;
- /** @var TwoFactorChallengeController|PHPUnit_Framework_MockObject_MockObject */
- private $controller;
- protected function setUp() {
- parent::setUp();
- $this->request = $this->createMock(IRequest::class);
- $this->twoFactorManager = $this->createMock(Manager::class);
- $this->userSession = $this->createMock(IUserSession::class);
- $this->session = $this->createMock(ISession::class);
- $this->urlGenerator = $this->createMock(IURLGenerator::class);
- $this->controller = $this->getMockBuilder(TwoFactorChallengeController::class)
- ->setConstructorArgs([
- 'core',
- $this->request,
- $this->twoFactorManager,
- $this->userSession,
- $this->session,
- $this->urlGenerator,
- ])
- ->setMethods(['getLogoutUrl'])
- ->getMock();
- $this->controller->expects($this->any())
- ->method('getLogoutUrl')
- ->willReturn('logoutAttribute');
- }
- public function testSelectChallenge() {
- $user = $this->getMockBuilder(IUser::class)->getMock();
- $p1 = $this->createMock(IProvider::class);
- $p1->method('getId')->willReturn('p1');
- $backupProvider = $this->createMock(IProvider::class);
- $backupProvider->method('getId')->willReturn('backup_codes');
- $providerSet = new ProviderSet([$p1, $backupProvider], true);
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProviderSet')
- ->with($user)
- ->will($this->returnValue($providerSet));
- $expected = new TemplateResponse('core', 'twofactorselectchallenge', [
- 'providers' => [
- $p1,
- ],
- 'providerMissing' => true,
- 'backupProvider' => $backupProvider,
- 'redirect_url' => '/some/url',
- 'logout_url' => 'logoutAttribute',
- ], 'guest');
- $this->assertEquals($expected, $this->controller->selectChallenge('/some/url'));
- }
- public function testShowChallenge() {
- $user = $this->createMock(IUser::class);
- $provider = $this->createMock(IProvider::class);
- $provider->method('getId')->willReturn('myprovider');
- $backupProvider = $this->createMock(IProvider::class);
- $backupProvider->method('getId')->willReturn('backup_codes');
- $tmpl = $this->createMock(Template::class);
- $providerSet = new ProviderSet([$provider, $backupProvider], true);
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProviderSet')
- ->with($user)
- ->will($this->returnValue($providerSet));
- $provider->expects($this->once())
- ->method('getId')
- ->will($this->returnValue('u2f'));
- $backupProvider->expects($this->once())
- ->method('getId')
- ->will($this->returnValue('backup_codes'));
- $this->session->expects($this->once())
- ->method('exists')
- ->with('two_factor_auth_error')
- ->will($this->returnValue(true));
- $this->session->expects($this->exactly(2))
- ->method('remove')
- ->with($this->logicalOr($this->equalTo('two_factor_auth_error'), $this->equalTo('two_factor_auth_error_message')));
- $provider->expects($this->once())
- ->method('getTemplate')
- ->with($user)
- ->will($this->returnValue($tmpl));
- $tmpl->expects($this->once())
- ->method('fetchPage')
- ->will($this->returnValue('<html/>'));
- $expected = new TemplateResponse('core', 'twofactorshowchallenge', [
- 'error' => true,
- 'provider' => $provider,
- 'backupProvider' => $backupProvider,
- 'logout_url' => 'logoutAttribute',
- 'template' => '<html/>',
- 'redirect_url' => '/re/dir/ect/url',
- 'error_message' => null,
- ], 'guest');
- $this->assertEquals($expected, $this->controller->showChallenge('myprovider', '/re/dir/ect/url'));
- }
- public function testShowInvalidChallenge() {
- $user = $this->createMock(IUser::class);
- $providerSet = new ProviderSet([], false);
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProviderSet')
- ->with($user)
- ->will($this->returnValue($providerSet));
- $this->urlGenerator->expects($this->once())
- ->method('linkToRoute')
- ->with('core.TwoFactorChallenge.selectChallenge')
- ->will($this->returnValue('select/challenge/url'));
- $expected = new RedirectResponse('select/challenge/url');
- $this->assertEquals($expected, $this->controller->showChallenge('myprovider', 'redirect/url'));
- }
- public function testSolveChallenge() {
- $user = $this->createMock(IUser::class);
- $provider = $this->createMock(IProvider::class);
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProvider')
- ->with($user, 'myprovider')
- ->will($this->returnValue($provider));
- $this->twoFactorManager->expects($this->once())
- ->method('verifyChallenge')
- ->with('myprovider', $user, 'token')
- ->will($this->returnValue(true));
- $expected = new RedirectResponse(OC_Util::getDefaultPageUrl());
- $this->assertEquals($expected, $this->controller->solveChallenge('myprovider', 'token'));
- }
- public function testSolveValidChallengeAndRedirect() {
- $user = $this->createMock(IUser::class);
- $provider = $this->createMock(IProvider::class);
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProvider')
- ->with($user, 'myprovider')
- ->will($this->returnValue($provider));
- $this->twoFactorManager->expects($this->once())
- ->method('verifyChallenge')
- ->with('myprovider', $user, 'token')
- ->willReturn(true);
- $this->urlGenerator->expects($this->once())
- ->method('getAbsoluteURL')
- ->with('redirect url')
- ->willReturn('redirect/url');
- $expected = new RedirectResponse('redirect/url');
- $this->assertEquals($expected, $this->controller->solveChallenge('myprovider', 'token', 'redirect%20url'));
- }
- public function testSolveChallengeInvalidProvider() {
- $user = $this->getMockBuilder(IUser::class)->getMock();
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProvider')
- ->with($user, 'myprovider')
- ->will($this->returnValue(null));
- $this->urlGenerator->expects($this->once())
- ->method('linkToRoute')
- ->with('core.TwoFactorChallenge.selectChallenge')
- ->will($this->returnValue('select/challenge/url'));
- $expected = new RedirectResponse('select/challenge/url');
- $this->assertEquals($expected, $this->controller->solveChallenge('myprovider', 'token'));
- }
- public function testSolveInvalidChallenge() {
- $user = $this->createMock(IUser::class);
- $provider = $this->createMock(IProvider::class);
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProvider')
- ->with($user, 'myprovider')
- ->will($this->returnValue($provider));
- $this->twoFactorManager->expects($this->once())
- ->method('verifyChallenge')
- ->with('myprovider', $user, 'token')
- ->will($this->returnValue(false));
- $this->session->expects($this->once())
- ->method('set')
- ->with('two_factor_auth_error', true);
- $this->urlGenerator->expects($this->once())
- ->method('linkToRoute')
- ->with('core.TwoFactorChallenge.showChallenge', [
- 'challengeProviderId' => 'myprovider',
- 'redirect_url' => '/url',
- ])
- ->will($this->returnValue('files/index/url'));
- $provider->expects($this->once())
- ->method('getId')
- ->will($this->returnValue('myprovider'));
- $expected = new RedirectResponse('files/index/url');
- $this->assertEquals($expected, $this->controller->solveChallenge('myprovider', 'token', '/url'));
- }
- public function testSolveChallengeTwoFactorException() {
- $user = $this->createMock(IUser::class);
- $provider = $this->createMock(IProvider::class);
- $exception = new TwoFactorException("2FA failed");
- $this->userSession->expects($this->once())
- ->method('getUser')
- ->will($this->returnValue($user));
- $this->twoFactorManager->expects($this->once())
- ->method('getProvider')
- ->with($user, 'myprovider')
- ->will($this->returnValue($provider));
- $this->twoFactorManager->expects($this->once())
- ->method('verifyChallenge')
- ->with('myprovider', $user, 'token')
- ->will($this->throwException($exception));
- $this->session->expects($this->at(0))
- ->method('set')
- ->with('two_factor_auth_error_message', "2FA failed");
- $this->session->expects($this->at(1))
- ->method('set')
- ->with('two_factor_auth_error', true);
- $this->urlGenerator->expects($this->once())
- ->method('linkToRoute')
- ->with('core.TwoFactorChallenge.showChallenge', [
- 'challengeProviderId' => 'myprovider',
- 'redirect_url' => '/url',
- ])
- ->will($this->returnValue('files/index/url'));
- $provider->expects($this->once())
- ->method('getId')
- ->will($this->returnValue('myprovider'));
- $expected = new RedirectResponse('files/index/url');
- $this->assertEquals($expected, $this->controller->solveChallenge('myprovider', 'token', '/url'));
- }
- }
|