test_room.py 87 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488
  1. # Copyright 2020 Dirk Klimpel
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. import json
  15. import urllib.parse
  16. from http import HTTPStatus
  17. from typing import List, Optional
  18. from unittest.mock import Mock
  19. from parameterized import parameterized
  20. import synapse.rest.admin
  21. from synapse.api.constants import EventTypes, Membership
  22. from synapse.api.errors import Codes
  23. from synapse.handlers.pagination import PaginationHandler
  24. from synapse.rest.client import directory, events, login, room
  25. from tests import unittest
  26. """Tests admin REST events for /rooms paths."""
  27. class DeleteRoomTestCase(unittest.HomeserverTestCase):
  28. servlets = [
  29. synapse.rest.admin.register_servlets,
  30. login.register_servlets,
  31. events.register_servlets,
  32. room.register_servlets,
  33. room.register_deprecated_servlets,
  34. ]
  35. def prepare(self, reactor, clock, hs):
  36. self.event_creation_handler = hs.get_event_creation_handler()
  37. hs.config.consent.user_consent_version = "1"
  38. consent_uri_builder = Mock()
  39. consent_uri_builder.build_user_consent_uri.return_value = "http://example.com"
  40. self.event_creation_handler._consent_uri_builder = consent_uri_builder
  41. self.store = hs.get_datastore()
  42. self.admin_user = self.register_user("admin", "pass", admin=True)
  43. self.admin_user_tok = self.login("admin", "pass")
  44. self.other_user = self.register_user("user", "pass")
  45. self.other_user_tok = self.login("user", "pass")
  46. # Mark the admin user as having consented
  47. self.get_success(self.store.user_set_consent_version(self.admin_user, "1"))
  48. self.room_id = self.helper.create_room_as(
  49. self.other_user, tok=self.other_user_tok
  50. )
  51. self.url = "/_synapse/admin/v1/rooms/%s" % self.room_id
  52. def test_requester_is_no_admin(self):
  53. """
  54. If the user is not a server admin, an error 403 is returned.
  55. """
  56. channel = self.make_request(
  57. "DELETE",
  58. self.url,
  59. {},
  60. access_token=self.other_user_tok,
  61. )
  62. self.assertEqual(403, channel.code, msg=channel.json_body)
  63. self.assertEqual(Codes.FORBIDDEN, channel.json_body["errcode"])
  64. def test_room_does_not_exist(self):
  65. """
  66. Check that unknown rooms/server return error 404.
  67. """
  68. url = "/_synapse/admin/v1/rooms/%s" % "!unknown:test"
  69. channel = self.make_request(
  70. "DELETE",
  71. url,
  72. {},
  73. access_token=self.admin_user_tok,
  74. )
  75. self.assertEqual(404, channel.code, msg=channel.json_body)
  76. self.assertEqual(Codes.NOT_FOUND, channel.json_body["errcode"])
  77. def test_room_is_not_valid(self):
  78. """
  79. Check that invalid room names, return an error 400.
  80. """
  81. url = "/_synapse/admin/v1/rooms/%s" % "invalidroom"
  82. channel = self.make_request(
  83. "DELETE",
  84. url,
  85. {},
  86. access_token=self.admin_user_tok,
  87. )
  88. self.assertEqual(400, channel.code, msg=channel.json_body)
  89. self.assertEqual(
  90. "invalidroom is not a legal room ID",
  91. channel.json_body["error"],
  92. )
  93. def test_new_room_user_does_not_exist(self):
  94. """
  95. Tests that the user ID must be from local server but it does not have to exist.
  96. """
  97. body = json.dumps({"new_room_user_id": "@unknown:test"})
  98. channel = self.make_request(
  99. "DELETE",
  100. self.url,
  101. content=body,
  102. access_token=self.admin_user_tok,
  103. )
  104. self.assertEqual(200, channel.code, msg=channel.json_body)
  105. self.assertIn("new_room_id", channel.json_body)
  106. self.assertIn("kicked_users", channel.json_body)
  107. self.assertIn("failed_to_kick_users", channel.json_body)
  108. self.assertIn("local_aliases", channel.json_body)
  109. def test_new_room_user_is_not_local(self):
  110. """
  111. Check that only local users can create new room to move members.
  112. """
  113. body = json.dumps({"new_room_user_id": "@not:exist.bla"})
  114. channel = self.make_request(
  115. "DELETE",
  116. self.url,
  117. content=body,
  118. access_token=self.admin_user_tok,
  119. )
  120. self.assertEqual(400, channel.code, msg=channel.json_body)
  121. self.assertEqual(
  122. "User must be our own: @not:exist.bla",
  123. channel.json_body["error"],
  124. )
  125. def test_block_is_not_bool(self):
  126. """
  127. If parameter `block` is not boolean, return an error
  128. """
  129. body = json.dumps({"block": "NotBool"})
  130. channel = self.make_request(
  131. "DELETE",
  132. self.url,
  133. content=body,
  134. access_token=self.admin_user_tok,
  135. )
  136. self.assertEqual(400, channel.code, msg=channel.json_body)
  137. self.assertEqual(Codes.BAD_JSON, channel.json_body["errcode"])
  138. def test_purge_is_not_bool(self):
  139. """
  140. If parameter `purge` is not boolean, return an error
  141. """
  142. body = json.dumps({"purge": "NotBool"})
  143. channel = self.make_request(
  144. "DELETE",
  145. self.url,
  146. content=body,
  147. access_token=self.admin_user_tok,
  148. )
  149. self.assertEqual(400, channel.code, msg=channel.json_body)
  150. self.assertEqual(Codes.BAD_JSON, channel.json_body["errcode"])
  151. def test_purge_room_and_block(self):
  152. """Test to purge a room and block it.
  153. Members will not be moved to a new room and will not receive a message.
  154. """
  155. # Test that room is not purged
  156. with self.assertRaises(AssertionError):
  157. self._is_purged(self.room_id)
  158. # Test that room is not blocked
  159. self._is_blocked(self.room_id, expect=False)
  160. # Assert one user in room
  161. self._is_member(room_id=self.room_id, user_id=self.other_user)
  162. body = json.dumps({"block": True, "purge": True})
  163. channel = self.make_request(
  164. "DELETE",
  165. self.url.encode("ascii"),
  166. content=body,
  167. access_token=self.admin_user_tok,
  168. )
  169. self.assertEqual(200, channel.code, msg=channel.json_body)
  170. self.assertEqual(None, channel.json_body["new_room_id"])
  171. self.assertEqual(self.other_user, channel.json_body["kicked_users"][0])
  172. self.assertIn("failed_to_kick_users", channel.json_body)
  173. self.assertIn("local_aliases", channel.json_body)
  174. self._is_purged(self.room_id)
  175. self._is_blocked(self.room_id, expect=True)
  176. self._has_no_members(self.room_id)
  177. def test_purge_room_and_not_block(self):
  178. """Test to purge a room and do not block it.
  179. Members will not be moved to a new room and will not receive a message.
  180. """
  181. # Test that room is not purged
  182. with self.assertRaises(AssertionError):
  183. self._is_purged(self.room_id)
  184. # Test that room is not blocked
  185. self._is_blocked(self.room_id, expect=False)
  186. # Assert one user in room
  187. self._is_member(room_id=self.room_id, user_id=self.other_user)
  188. body = json.dumps({"block": False, "purge": True})
  189. channel = self.make_request(
  190. "DELETE",
  191. self.url.encode("ascii"),
  192. content=body,
  193. access_token=self.admin_user_tok,
  194. )
  195. self.assertEqual(200, channel.code, msg=channel.json_body)
  196. self.assertEqual(None, channel.json_body["new_room_id"])
  197. self.assertEqual(self.other_user, channel.json_body["kicked_users"][0])
  198. self.assertIn("failed_to_kick_users", channel.json_body)
  199. self.assertIn("local_aliases", channel.json_body)
  200. self._is_purged(self.room_id)
  201. self._is_blocked(self.room_id, expect=False)
  202. self._has_no_members(self.room_id)
  203. def test_block_room_and_not_purge(self):
  204. """Test to block a room without purging it.
  205. Members will not be moved to a new room and will not receive a message.
  206. The room will not be purged.
  207. """
  208. # Test that room is not purged
  209. with self.assertRaises(AssertionError):
  210. self._is_purged(self.room_id)
  211. # Test that room is not blocked
  212. self._is_blocked(self.room_id, expect=False)
  213. # Assert one user in room
  214. self._is_member(room_id=self.room_id, user_id=self.other_user)
  215. body = json.dumps({"block": True, "purge": False})
  216. channel = self.make_request(
  217. "DELETE",
  218. self.url.encode("ascii"),
  219. content=body,
  220. access_token=self.admin_user_tok,
  221. )
  222. self.assertEqual(200, channel.code, msg=channel.json_body)
  223. self.assertEqual(None, channel.json_body["new_room_id"])
  224. self.assertEqual(self.other_user, channel.json_body["kicked_users"][0])
  225. self.assertIn("failed_to_kick_users", channel.json_body)
  226. self.assertIn("local_aliases", channel.json_body)
  227. with self.assertRaises(AssertionError):
  228. self._is_purged(self.room_id)
  229. self._is_blocked(self.room_id, expect=True)
  230. self._has_no_members(self.room_id)
  231. @parameterized.expand([(True,), (False,)])
  232. def test_block_unknown_room(self, purge: bool) -> None:
  233. """
  234. We can block an unknown room. In this case, the `purge` argument
  235. should be ignored.
  236. """
  237. room_id = "!unknown:test"
  238. # The room isn't already in the blocked rooms table
  239. self._is_blocked(room_id, expect=False)
  240. # Request the room be blocked.
  241. channel = self.make_request(
  242. "DELETE",
  243. f"/_synapse/admin/v1/rooms/{room_id}",
  244. {"block": True, "purge": purge},
  245. access_token=self.admin_user_tok,
  246. )
  247. # The room is now blocked.
  248. self.assertEqual(
  249. HTTPStatus.OK, int(channel.result["code"]), msg=channel.result["body"]
  250. )
  251. self._is_blocked(room_id)
  252. def test_shutdown_room_consent(self):
  253. """Test that we can shutdown rooms with local users who have not
  254. yet accepted the privacy policy. This used to fail when we tried to
  255. force part the user from the old room.
  256. Members will be moved to a new room and will receive a message.
  257. """
  258. self.event_creation_handler._block_events_without_consent_error = None
  259. # Assert one user in room
  260. users_in_room = self.get_success(self.store.get_users_in_room(self.room_id))
  261. self.assertEqual([self.other_user], users_in_room)
  262. # Enable require consent to send events
  263. self.event_creation_handler._block_events_without_consent_error = "Error"
  264. # Assert that the user is getting consent error
  265. self.helper.send(
  266. self.room_id, body="foo", tok=self.other_user_tok, expect_code=403
  267. )
  268. # Test that room is not purged
  269. with self.assertRaises(AssertionError):
  270. self._is_purged(self.room_id)
  271. # Assert one user in room
  272. self._is_member(room_id=self.room_id, user_id=self.other_user)
  273. # Test that the admin can still send shutdown
  274. channel = self.make_request(
  275. "DELETE",
  276. self.url,
  277. json.dumps({"new_room_user_id": self.admin_user}),
  278. access_token=self.admin_user_tok,
  279. )
  280. self.assertEqual(200, channel.code, msg=channel.json_body)
  281. self.assertEqual(self.other_user, channel.json_body["kicked_users"][0])
  282. self.assertIn("new_room_id", channel.json_body)
  283. self.assertIn("failed_to_kick_users", channel.json_body)
  284. self.assertIn("local_aliases", channel.json_body)
  285. # Test that member has moved to new room
  286. self._is_member(
  287. room_id=channel.json_body["new_room_id"], user_id=self.other_user
  288. )
  289. self._is_purged(self.room_id)
  290. self._has_no_members(self.room_id)
  291. def test_shutdown_room_block_peek(self):
  292. """Test that a world_readable room can no longer be peeked into after
  293. it has been shut down.
  294. Members will be moved to a new room and will receive a message.
  295. """
  296. self.event_creation_handler._block_events_without_consent_error = None
  297. # Enable world readable
  298. url = "rooms/%s/state/m.room.history_visibility" % (self.room_id,)
  299. channel = self.make_request(
  300. "PUT",
  301. url.encode("ascii"),
  302. json.dumps({"history_visibility": "world_readable"}),
  303. access_token=self.other_user_tok,
  304. )
  305. self.assertEqual(200, channel.code, msg=channel.json_body)
  306. # Test that room is not purged
  307. with self.assertRaises(AssertionError):
  308. self._is_purged(self.room_id)
  309. # Assert one user in room
  310. self._is_member(room_id=self.room_id, user_id=self.other_user)
  311. # Test that the admin can still send shutdown
  312. channel = self.make_request(
  313. "DELETE",
  314. self.url,
  315. json.dumps({"new_room_user_id": self.admin_user}),
  316. access_token=self.admin_user_tok,
  317. )
  318. self.assertEqual(200, channel.code, msg=channel.json_body)
  319. self.assertEqual(self.other_user, channel.json_body["kicked_users"][0])
  320. self.assertIn("new_room_id", channel.json_body)
  321. self.assertIn("failed_to_kick_users", channel.json_body)
  322. self.assertIn("local_aliases", channel.json_body)
  323. # Test that member has moved to new room
  324. self._is_member(
  325. room_id=channel.json_body["new_room_id"], user_id=self.other_user
  326. )
  327. self._is_purged(self.room_id)
  328. self._has_no_members(self.room_id)
  329. # Assert we can no longer peek into the room
  330. self._assert_peek(self.room_id, expect_code=403)
  331. def _is_blocked(self, room_id, expect=True):
  332. """Assert that the room is blocked or not"""
  333. d = self.store.is_room_blocked(room_id)
  334. if expect:
  335. self.assertTrue(self.get_success(d))
  336. else:
  337. self.assertIsNone(self.get_success(d))
  338. def _has_no_members(self, room_id):
  339. """Assert there is now no longer anyone in the room"""
  340. users_in_room = self.get_success(self.store.get_users_in_room(room_id))
  341. self.assertEqual([], users_in_room)
  342. def _is_member(self, room_id, user_id):
  343. """Test that user is member of the room"""
  344. users_in_room = self.get_success(self.store.get_users_in_room(room_id))
  345. self.assertIn(user_id, users_in_room)
  346. def _is_purged(self, room_id):
  347. """Test that the following tables have been purged of all rows related to the room."""
  348. for table in PURGE_TABLES:
  349. count = self.get_success(
  350. self.store.db_pool.simple_select_one_onecol(
  351. table=table,
  352. keyvalues={"room_id": room_id},
  353. retcol="COUNT(*)",
  354. desc="test_purge_room",
  355. )
  356. )
  357. self.assertEqual(count, 0, msg=f"Rows not purged in {table}")
  358. def _assert_peek(self, room_id, expect_code):
  359. """Assert that the admin user can (or cannot) peek into the room."""
  360. url = "rooms/%s/initialSync" % (room_id,)
  361. channel = self.make_request(
  362. "GET", url.encode("ascii"), access_token=self.admin_user_tok
  363. )
  364. self.assertEqual(expect_code, channel.code, msg=channel.json_body)
  365. url = "events?timeout=0&room_id=" + room_id
  366. channel = self.make_request(
  367. "GET", url.encode("ascii"), access_token=self.admin_user_tok
  368. )
  369. self.assertEqual(expect_code, channel.code, msg=channel.json_body)
  370. class DeleteRoomV2TestCase(unittest.HomeserverTestCase):
  371. servlets = [
  372. synapse.rest.admin.register_servlets,
  373. login.register_servlets,
  374. events.register_servlets,
  375. room.register_servlets,
  376. room.register_deprecated_servlets,
  377. ]
  378. def prepare(self, reactor, clock, hs):
  379. self.event_creation_handler = hs.get_event_creation_handler()
  380. hs.config.consent.user_consent_version = "1"
  381. consent_uri_builder = Mock()
  382. consent_uri_builder.build_user_consent_uri.return_value = "http://example.com"
  383. self.event_creation_handler._consent_uri_builder = consent_uri_builder
  384. self.store = hs.get_datastore()
  385. self.admin_user = self.register_user("admin", "pass", admin=True)
  386. self.admin_user_tok = self.login("admin", "pass")
  387. self.other_user = self.register_user("user", "pass")
  388. self.other_user_tok = self.login("user", "pass")
  389. # Mark the admin user as having consented
  390. self.get_success(self.store.user_set_consent_version(self.admin_user, "1"))
  391. self.room_id = self.helper.create_room_as(
  392. self.other_user, tok=self.other_user_tok
  393. )
  394. self.url = f"/_synapse/admin/v2/rooms/{self.room_id}"
  395. self.url_status_by_room_id = (
  396. f"/_synapse/admin/v2/rooms/{self.room_id}/delete_status"
  397. )
  398. self.url_status_by_delete_id = "/_synapse/admin/v2/rooms/delete_status/"
  399. @parameterized.expand(
  400. [
  401. ("DELETE", "/_synapse/admin/v2/rooms/%s"),
  402. ("GET", "/_synapse/admin/v2/rooms/%s/delete_status"),
  403. ("GET", "/_synapse/admin/v2/rooms/delete_status/%s"),
  404. ]
  405. )
  406. def test_requester_is_no_admin(self, method: str, url: str):
  407. """
  408. If the user is not a server admin, an error 403 is returned.
  409. """
  410. channel = self.make_request(
  411. method,
  412. url % self.room_id,
  413. content={},
  414. access_token=self.other_user_tok,
  415. )
  416. self.assertEqual(HTTPStatus.FORBIDDEN, channel.code, msg=channel.json_body)
  417. self.assertEqual(Codes.FORBIDDEN, channel.json_body["errcode"])
  418. @parameterized.expand(
  419. [
  420. ("DELETE", "/_synapse/admin/v2/rooms/%s"),
  421. ("GET", "/_synapse/admin/v2/rooms/%s/delete_status"),
  422. ("GET", "/_synapse/admin/v2/rooms/delete_status/%s"),
  423. ]
  424. )
  425. def test_room_does_not_exist(self, method: str, url: str):
  426. """
  427. Check that unknown rooms/server return error 404.
  428. """
  429. channel = self.make_request(
  430. method,
  431. url % "!unknown:test",
  432. content={},
  433. access_token=self.admin_user_tok,
  434. )
  435. self.assertEqual(HTTPStatus.NOT_FOUND, channel.code, msg=channel.json_body)
  436. self.assertEqual(Codes.NOT_FOUND, channel.json_body["errcode"])
  437. @parameterized.expand(
  438. [
  439. ("DELETE", "/_synapse/admin/v2/rooms/%s"),
  440. ("GET", "/_synapse/admin/v2/rooms/%s/delete_status"),
  441. ]
  442. )
  443. def test_room_is_not_valid(self, method: str, url: str):
  444. """
  445. Check that invalid room names, return an error 400.
  446. """
  447. channel = self.make_request(
  448. method,
  449. url % "invalidroom",
  450. content={},
  451. access_token=self.admin_user_tok,
  452. )
  453. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  454. self.assertEqual(
  455. "invalidroom is not a legal room ID",
  456. channel.json_body["error"],
  457. )
  458. def test_new_room_user_does_not_exist(self):
  459. """
  460. Tests that the user ID must be from local server but it does not have to exist.
  461. """
  462. channel = self.make_request(
  463. "DELETE",
  464. self.url,
  465. content={"new_room_user_id": "@unknown:test"},
  466. access_token=self.admin_user_tok,
  467. )
  468. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  469. self.assertIn("delete_id", channel.json_body)
  470. delete_id = channel.json_body["delete_id"]
  471. self._test_result(delete_id, self.other_user, expect_new_room=True)
  472. def test_new_room_user_is_not_local(self):
  473. """
  474. Check that only local users can create new room to move members.
  475. """
  476. channel = self.make_request(
  477. "DELETE",
  478. self.url,
  479. content={"new_room_user_id": "@not:exist.bla"},
  480. access_token=self.admin_user_tok,
  481. )
  482. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  483. self.assertEqual(
  484. "User must be our own: @not:exist.bla",
  485. channel.json_body["error"],
  486. )
  487. def test_block_is_not_bool(self):
  488. """
  489. If parameter `block` is not boolean, return an error
  490. """
  491. channel = self.make_request(
  492. "DELETE",
  493. self.url,
  494. content={"block": "NotBool"},
  495. access_token=self.admin_user_tok,
  496. )
  497. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  498. self.assertEqual(Codes.BAD_JSON, channel.json_body["errcode"])
  499. def test_purge_is_not_bool(self):
  500. """
  501. If parameter `purge` is not boolean, return an error
  502. """
  503. channel = self.make_request(
  504. "DELETE",
  505. self.url,
  506. content={"purge": "NotBool"},
  507. access_token=self.admin_user_tok,
  508. )
  509. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  510. self.assertEqual(Codes.BAD_JSON, channel.json_body["errcode"])
  511. def test_delete_expired_status(self):
  512. """Test that the task status is removed after expiration."""
  513. # first task, do not purge, that we can create a second task
  514. channel = self.make_request(
  515. "DELETE",
  516. self.url.encode("ascii"),
  517. content={"purge": False},
  518. access_token=self.admin_user_tok,
  519. )
  520. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  521. self.assertIn("delete_id", channel.json_body)
  522. delete_id1 = channel.json_body["delete_id"]
  523. # go ahead
  524. self.reactor.advance(PaginationHandler.CLEAR_PURGE_AFTER_MS / 1000 / 2)
  525. # second task
  526. channel = self.make_request(
  527. "DELETE",
  528. self.url.encode("ascii"),
  529. content={"purge": True},
  530. access_token=self.admin_user_tok,
  531. )
  532. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  533. self.assertIn("delete_id", channel.json_body)
  534. delete_id2 = channel.json_body["delete_id"]
  535. # get status
  536. channel = self.make_request(
  537. "GET",
  538. self.url_status_by_room_id,
  539. access_token=self.admin_user_tok,
  540. )
  541. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  542. self.assertEqual(2, len(channel.json_body["results"]))
  543. self.assertEqual("complete", channel.json_body["results"][0]["status"])
  544. self.assertEqual("complete", channel.json_body["results"][1]["status"])
  545. self.assertEqual(delete_id1, channel.json_body["results"][0]["delete_id"])
  546. self.assertEqual(delete_id2, channel.json_body["results"][1]["delete_id"])
  547. # get status after more than clearing time for first task
  548. # second task is not cleared
  549. self.reactor.advance(PaginationHandler.CLEAR_PURGE_AFTER_MS / 1000 / 2)
  550. channel = self.make_request(
  551. "GET",
  552. self.url_status_by_room_id,
  553. access_token=self.admin_user_tok,
  554. )
  555. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  556. self.assertEqual(1, len(channel.json_body["results"]))
  557. self.assertEqual("complete", channel.json_body["results"][0]["status"])
  558. self.assertEqual(delete_id2, channel.json_body["results"][0]["delete_id"])
  559. # get status after more than clearing time for all tasks
  560. self.reactor.advance(PaginationHandler.CLEAR_PURGE_AFTER_MS / 1000 / 2)
  561. channel = self.make_request(
  562. "GET",
  563. self.url_status_by_room_id,
  564. access_token=self.admin_user_tok,
  565. )
  566. self.assertEqual(HTTPStatus.NOT_FOUND, channel.code, msg=channel.json_body)
  567. self.assertEqual(Codes.NOT_FOUND, channel.json_body["errcode"])
  568. def test_delete_same_room_twice(self):
  569. """Test that the call for delete a room at second time gives an exception."""
  570. body = {"new_room_user_id": self.admin_user}
  571. # first call to delete room
  572. # and do not wait for finish the task
  573. first_channel = self.make_request(
  574. "DELETE",
  575. self.url.encode("ascii"),
  576. content=body,
  577. access_token=self.admin_user_tok,
  578. await_result=False,
  579. )
  580. # second call to delete room
  581. second_channel = self.make_request(
  582. "DELETE",
  583. self.url.encode("ascii"),
  584. content=body,
  585. access_token=self.admin_user_tok,
  586. )
  587. self.assertEqual(
  588. HTTPStatus.BAD_REQUEST, second_channel.code, msg=second_channel.json_body
  589. )
  590. self.assertEqual(Codes.UNKNOWN, second_channel.json_body["errcode"])
  591. self.assertEqual(
  592. f"History purge already in progress for {self.room_id}",
  593. second_channel.json_body["error"],
  594. )
  595. # get result of first call
  596. first_channel.await_result()
  597. self.assertEqual(HTTPStatus.OK, first_channel.code, msg=first_channel.json_body)
  598. self.assertIn("delete_id", first_channel.json_body)
  599. # check status after finish the task
  600. self._test_result(
  601. first_channel.json_body["delete_id"],
  602. self.other_user,
  603. expect_new_room=True,
  604. )
  605. def test_purge_room_and_block(self):
  606. """Test to purge a room and block it.
  607. Members will not be moved to a new room and will not receive a message.
  608. """
  609. # Test that room is not purged
  610. with self.assertRaises(AssertionError):
  611. self._is_purged(self.room_id)
  612. # Test that room is not blocked
  613. self._is_blocked(self.room_id, expect=False)
  614. # Assert one user in room
  615. self._is_member(room_id=self.room_id, user_id=self.other_user)
  616. channel = self.make_request(
  617. "DELETE",
  618. self.url.encode("ascii"),
  619. content={"block": True, "purge": True},
  620. access_token=self.admin_user_tok,
  621. )
  622. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  623. self.assertIn("delete_id", channel.json_body)
  624. delete_id = channel.json_body["delete_id"]
  625. self._test_result(delete_id, self.other_user)
  626. self._is_purged(self.room_id)
  627. self._is_blocked(self.room_id, expect=True)
  628. self._has_no_members(self.room_id)
  629. def test_purge_room_and_not_block(self):
  630. """Test to purge a room and do not block it.
  631. Members will not be moved to a new room and will not receive a message.
  632. """
  633. # Test that room is not purged
  634. with self.assertRaises(AssertionError):
  635. self._is_purged(self.room_id)
  636. # Test that room is not blocked
  637. self._is_blocked(self.room_id, expect=False)
  638. # Assert one user in room
  639. self._is_member(room_id=self.room_id, user_id=self.other_user)
  640. channel = self.make_request(
  641. "DELETE",
  642. self.url.encode("ascii"),
  643. content={"block": False, "purge": True},
  644. access_token=self.admin_user_tok,
  645. )
  646. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  647. self.assertIn("delete_id", channel.json_body)
  648. delete_id = channel.json_body["delete_id"]
  649. self._test_result(delete_id, self.other_user)
  650. self._is_purged(self.room_id)
  651. self._is_blocked(self.room_id, expect=False)
  652. self._has_no_members(self.room_id)
  653. def test_block_room_and_not_purge(self):
  654. """Test to block a room without purging it.
  655. Members will not be moved to a new room and will not receive a message.
  656. The room will not be purged.
  657. """
  658. # Test that room is not purged
  659. with self.assertRaises(AssertionError):
  660. self._is_purged(self.room_id)
  661. # Test that room is not blocked
  662. self._is_blocked(self.room_id, expect=False)
  663. # Assert one user in room
  664. self._is_member(room_id=self.room_id, user_id=self.other_user)
  665. channel = self.make_request(
  666. "DELETE",
  667. self.url.encode("ascii"),
  668. content={"block": True, "purge": False},
  669. access_token=self.admin_user_tok,
  670. )
  671. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  672. self.assertIn("delete_id", channel.json_body)
  673. delete_id = channel.json_body["delete_id"]
  674. self._test_result(delete_id, self.other_user)
  675. with self.assertRaises(AssertionError):
  676. self._is_purged(self.room_id)
  677. self._is_blocked(self.room_id, expect=True)
  678. self._has_no_members(self.room_id)
  679. def test_shutdown_room_consent(self):
  680. """Test that we can shutdown rooms with local users who have not
  681. yet accepted the privacy policy. This used to fail when we tried to
  682. force part the user from the old room.
  683. Members will be moved to a new room and will receive a message.
  684. """
  685. self.event_creation_handler._block_events_without_consent_error = None
  686. # Assert one user in room
  687. users_in_room = self.get_success(self.store.get_users_in_room(self.room_id))
  688. self.assertEqual([self.other_user], users_in_room)
  689. # Enable require consent to send events
  690. self.event_creation_handler._block_events_without_consent_error = "Error"
  691. # Assert that the user is getting consent error
  692. self.helper.send(
  693. self.room_id, body="foo", tok=self.other_user_tok, expect_code=403
  694. )
  695. # Test that room is not purged
  696. with self.assertRaises(AssertionError):
  697. self._is_purged(self.room_id)
  698. # Assert one user in room
  699. self._is_member(room_id=self.room_id, user_id=self.other_user)
  700. # Test that the admin can still send shutdown
  701. channel = self.make_request(
  702. "DELETE",
  703. self.url,
  704. content={"new_room_user_id": self.admin_user},
  705. access_token=self.admin_user_tok,
  706. )
  707. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  708. self.assertIn("delete_id", channel.json_body)
  709. delete_id = channel.json_body["delete_id"]
  710. self._test_result(delete_id, self.other_user, expect_new_room=True)
  711. channel = self.make_request(
  712. "GET",
  713. self.url_status_by_room_id,
  714. access_token=self.admin_user_tok,
  715. )
  716. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  717. self.assertEqual(1, len(channel.json_body["results"]))
  718. # Test that member has moved to new room
  719. self._is_member(
  720. room_id=channel.json_body["results"][0]["shutdown_room"]["new_room_id"],
  721. user_id=self.other_user,
  722. )
  723. self._is_purged(self.room_id)
  724. self._has_no_members(self.room_id)
  725. def test_shutdown_room_block_peek(self):
  726. """Test that a world_readable room can no longer be peeked into after
  727. it has been shut down.
  728. Members will be moved to a new room and will receive a message.
  729. """
  730. self.event_creation_handler._block_events_without_consent_error = None
  731. # Enable world readable
  732. url = "rooms/%s/state/m.room.history_visibility" % (self.room_id,)
  733. channel = self.make_request(
  734. "PUT",
  735. url.encode("ascii"),
  736. content={"history_visibility": "world_readable"},
  737. access_token=self.other_user_tok,
  738. )
  739. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  740. # Test that room is not purged
  741. with self.assertRaises(AssertionError):
  742. self._is_purged(self.room_id)
  743. # Assert one user in room
  744. self._is_member(room_id=self.room_id, user_id=self.other_user)
  745. # Test that the admin can still send shutdown
  746. channel = self.make_request(
  747. "DELETE",
  748. self.url,
  749. content={"new_room_user_id": self.admin_user},
  750. access_token=self.admin_user_tok,
  751. )
  752. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  753. self.assertIn("delete_id", channel.json_body)
  754. delete_id = channel.json_body["delete_id"]
  755. self._test_result(delete_id, self.other_user, expect_new_room=True)
  756. channel = self.make_request(
  757. "GET",
  758. self.url_status_by_room_id,
  759. access_token=self.admin_user_tok,
  760. )
  761. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  762. self.assertEqual(1, len(channel.json_body["results"]))
  763. # Test that member has moved to new room
  764. self._is_member(
  765. room_id=channel.json_body["results"][0]["shutdown_room"]["new_room_id"],
  766. user_id=self.other_user,
  767. )
  768. self._is_purged(self.room_id)
  769. self._has_no_members(self.room_id)
  770. # Assert we can no longer peek into the room
  771. self._assert_peek(self.room_id, expect_code=403)
  772. def _is_blocked(self, room_id: str, expect: bool = True) -> None:
  773. """Assert that the room is blocked or not"""
  774. d = self.store.is_room_blocked(room_id)
  775. if expect:
  776. self.assertTrue(self.get_success(d))
  777. else:
  778. self.assertIsNone(self.get_success(d))
  779. def _has_no_members(self, room_id: str) -> None:
  780. """Assert there is now no longer anyone in the room"""
  781. users_in_room = self.get_success(self.store.get_users_in_room(room_id))
  782. self.assertEqual([], users_in_room)
  783. def _is_member(self, room_id: str, user_id: str) -> None:
  784. """Test that user is member of the room"""
  785. users_in_room = self.get_success(self.store.get_users_in_room(room_id))
  786. self.assertIn(user_id, users_in_room)
  787. def _is_purged(self, room_id: str) -> None:
  788. """Test that the following tables have been purged of all rows related to the room."""
  789. for table in PURGE_TABLES:
  790. count = self.get_success(
  791. self.store.db_pool.simple_select_one_onecol(
  792. table=table,
  793. keyvalues={"room_id": room_id},
  794. retcol="COUNT(*)",
  795. desc="test_purge_room",
  796. )
  797. )
  798. self.assertEqual(count, 0, msg=f"Rows not purged in {table}")
  799. def _assert_peek(self, room_id: str, expect_code: int) -> None:
  800. """Assert that the admin user can (or cannot) peek into the room."""
  801. url = f"rooms/{room_id}/initialSync"
  802. channel = self.make_request(
  803. "GET", url.encode("ascii"), access_token=self.admin_user_tok
  804. )
  805. self.assertEqual(expect_code, channel.code, msg=channel.json_body)
  806. url = "events?timeout=0&room_id=" + room_id
  807. channel = self.make_request(
  808. "GET", url.encode("ascii"), access_token=self.admin_user_tok
  809. )
  810. self.assertEqual(expect_code, channel.code, msg=channel.json_body)
  811. def _test_result(
  812. self,
  813. delete_id: str,
  814. kicked_user: str,
  815. expect_new_room: bool = False,
  816. ) -> None:
  817. """
  818. Test that the result is the expected.
  819. Uses both APIs (status by room_id and delete_id)
  820. Args:
  821. delete_id: id of this purge
  822. kicked_user: a user_id which is kicked from the room
  823. expect_new_room: if we expect that a new room was created
  824. """
  825. # get information by room_id
  826. channel_room_id = self.make_request(
  827. "GET",
  828. self.url_status_by_room_id,
  829. access_token=self.admin_user_tok,
  830. )
  831. self.assertEqual(
  832. HTTPStatus.OK, channel_room_id.code, msg=channel_room_id.json_body
  833. )
  834. self.assertEqual(1, len(channel_room_id.json_body["results"]))
  835. self.assertEqual(
  836. delete_id, channel_room_id.json_body["results"][0]["delete_id"]
  837. )
  838. # get information by delete_id
  839. channel_delete_id = self.make_request(
  840. "GET",
  841. self.url_status_by_delete_id + delete_id,
  842. access_token=self.admin_user_tok,
  843. )
  844. self.assertEqual(
  845. HTTPStatus.OK,
  846. channel_delete_id.code,
  847. msg=channel_delete_id.json_body,
  848. )
  849. # test values that are the same in both responses
  850. for content in [
  851. channel_room_id.json_body["results"][0],
  852. channel_delete_id.json_body,
  853. ]:
  854. self.assertEqual("complete", content["status"])
  855. self.assertEqual(kicked_user, content["shutdown_room"]["kicked_users"][0])
  856. self.assertIn("failed_to_kick_users", content["shutdown_room"])
  857. self.assertIn("local_aliases", content["shutdown_room"])
  858. self.assertNotIn("error", content)
  859. if expect_new_room:
  860. self.assertIsNotNone(content["shutdown_room"]["new_room_id"])
  861. else:
  862. self.assertIsNone(content["shutdown_room"]["new_room_id"])
  863. class RoomTestCase(unittest.HomeserverTestCase):
  864. """Test /room admin API."""
  865. servlets = [
  866. synapse.rest.admin.register_servlets,
  867. login.register_servlets,
  868. room.register_servlets,
  869. directory.register_servlets,
  870. ]
  871. def prepare(self, reactor, clock, hs):
  872. # Create user
  873. self.admin_user = self.register_user("admin", "pass", admin=True)
  874. self.admin_user_tok = self.login("admin", "pass")
  875. def test_list_rooms(self):
  876. """Test that we can list rooms"""
  877. # Create 3 test rooms
  878. total_rooms = 3
  879. room_ids = []
  880. for _ in range(total_rooms):
  881. room_id = self.helper.create_room_as(
  882. self.admin_user, tok=self.admin_user_tok
  883. )
  884. room_ids.append(room_id)
  885. # Request the list of rooms
  886. url = "/_synapse/admin/v1/rooms"
  887. channel = self.make_request(
  888. "GET",
  889. url.encode("ascii"),
  890. access_token=self.admin_user_tok,
  891. )
  892. # Check request completed successfully
  893. self.assertEqual(200, channel.code, msg=channel.json_body)
  894. # Check that response json body contains a "rooms" key
  895. self.assertTrue(
  896. "rooms" in channel.json_body,
  897. msg="Response body does not " "contain a 'rooms' key",
  898. )
  899. # Check that 3 rooms were returned
  900. self.assertEqual(3, len(channel.json_body["rooms"]), msg=channel.json_body)
  901. # Check their room_ids match
  902. returned_room_ids = [room["room_id"] for room in channel.json_body["rooms"]]
  903. self.assertEqual(room_ids, returned_room_ids)
  904. # Check that all fields are available
  905. for r in channel.json_body["rooms"]:
  906. self.assertIn("name", r)
  907. self.assertIn("canonical_alias", r)
  908. self.assertIn("joined_members", r)
  909. self.assertIn("joined_local_members", r)
  910. self.assertIn("version", r)
  911. self.assertIn("creator", r)
  912. self.assertIn("encryption", r)
  913. self.assertIn("federatable", r)
  914. self.assertIn("public", r)
  915. self.assertIn("join_rules", r)
  916. self.assertIn("guest_access", r)
  917. self.assertIn("history_visibility", r)
  918. self.assertIn("state_events", r)
  919. # Check that the correct number of total rooms was returned
  920. self.assertEqual(channel.json_body["total_rooms"], total_rooms)
  921. # Check that the offset is correct
  922. # Should be 0 as we aren't paginating
  923. self.assertEqual(channel.json_body["offset"], 0)
  924. # Check that the prev_batch parameter is not present
  925. self.assertNotIn("prev_batch", channel.json_body)
  926. # We shouldn't receive a next token here as there's no further rooms to show
  927. self.assertNotIn("next_batch", channel.json_body)
  928. def test_list_rooms_pagination(self):
  929. """Test that we can get a full list of rooms through pagination"""
  930. # Create 5 test rooms
  931. total_rooms = 5
  932. room_ids = []
  933. for _ in range(total_rooms):
  934. room_id = self.helper.create_room_as(
  935. self.admin_user, tok=self.admin_user_tok
  936. )
  937. room_ids.append(room_id)
  938. # Set the name of the rooms so we get a consistent returned ordering
  939. for idx, room_id in enumerate(room_ids):
  940. self.helper.send_state(
  941. room_id,
  942. "m.room.name",
  943. {"name": str(idx)},
  944. tok=self.admin_user_tok,
  945. )
  946. # Request the list of rooms
  947. returned_room_ids = []
  948. start = 0
  949. limit = 2
  950. run_count = 0
  951. should_repeat = True
  952. while should_repeat:
  953. run_count += 1
  954. url = "/_synapse/admin/v1/rooms?from=%d&limit=%d&order_by=%s" % (
  955. start,
  956. limit,
  957. "name",
  958. )
  959. channel = self.make_request(
  960. "GET",
  961. url.encode("ascii"),
  962. access_token=self.admin_user_tok,
  963. )
  964. self.assertEqual(200, channel.code, msg=channel.json_body)
  965. self.assertTrue("rooms" in channel.json_body)
  966. for r in channel.json_body["rooms"]:
  967. returned_room_ids.append(r["room_id"])
  968. # Check that the correct number of total rooms was returned
  969. self.assertEqual(channel.json_body["total_rooms"], total_rooms)
  970. # Check that the offset is correct
  971. # We're only getting 2 rooms each page, so should be 2 * last run_count
  972. self.assertEqual(channel.json_body["offset"], 2 * (run_count - 1))
  973. if run_count > 1:
  974. # Check the value of prev_batch is correct
  975. self.assertEqual(channel.json_body["prev_batch"], 2 * (run_count - 2))
  976. if "next_batch" not in channel.json_body:
  977. # We have reached the end of the list
  978. should_repeat = False
  979. else:
  980. # Make another query with an updated start value
  981. start = channel.json_body["next_batch"]
  982. # We should've queried the endpoint 3 times
  983. self.assertEqual(
  984. run_count,
  985. 3,
  986. msg="Should've queried 3 times for 5 rooms with limit 2 per query",
  987. )
  988. # Check that we received all of the room ids
  989. self.assertEqual(room_ids, returned_room_ids)
  990. url = "/_synapse/admin/v1/rooms?from=%d&limit=%d" % (start, limit)
  991. channel = self.make_request(
  992. "GET",
  993. url.encode("ascii"),
  994. access_token=self.admin_user_tok,
  995. )
  996. self.assertEqual(200, channel.code, msg=channel.json_body)
  997. def test_correct_room_attributes(self):
  998. """Test the correct attributes for a room are returned"""
  999. # Create a test room
  1000. room_id = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1001. test_alias = "#test:test"
  1002. test_room_name = "something"
  1003. # Have another user join the room
  1004. user_2 = self.register_user("user4", "pass")
  1005. user_tok_2 = self.login("user4", "pass")
  1006. self.helper.join(room_id, user_2, tok=user_tok_2)
  1007. # Create a new alias to this room
  1008. url = "/_matrix/client/r0/directory/room/%s" % (urllib.parse.quote(test_alias),)
  1009. channel = self.make_request(
  1010. "PUT",
  1011. url.encode("ascii"),
  1012. {"room_id": room_id},
  1013. access_token=self.admin_user_tok,
  1014. )
  1015. self.assertEqual(200, channel.code, msg=channel.json_body)
  1016. # Set this new alias as the canonical alias for this room
  1017. self.helper.send_state(
  1018. room_id,
  1019. "m.room.aliases",
  1020. {"aliases": [test_alias]},
  1021. tok=self.admin_user_tok,
  1022. state_key="test",
  1023. )
  1024. self.helper.send_state(
  1025. room_id,
  1026. "m.room.canonical_alias",
  1027. {"alias": test_alias},
  1028. tok=self.admin_user_tok,
  1029. )
  1030. # Set a name for the room
  1031. self.helper.send_state(
  1032. room_id,
  1033. "m.room.name",
  1034. {"name": test_room_name},
  1035. tok=self.admin_user_tok,
  1036. )
  1037. # Request the list of rooms
  1038. url = "/_synapse/admin/v1/rooms"
  1039. channel = self.make_request(
  1040. "GET",
  1041. url.encode("ascii"),
  1042. access_token=self.admin_user_tok,
  1043. )
  1044. self.assertEqual(200, channel.code, msg=channel.json_body)
  1045. # Check that rooms were returned
  1046. self.assertTrue("rooms" in channel.json_body)
  1047. rooms = channel.json_body["rooms"]
  1048. # Check that only one room was returned
  1049. self.assertEqual(len(rooms), 1)
  1050. # And that the value of the total_rooms key was correct
  1051. self.assertEqual(channel.json_body["total_rooms"], 1)
  1052. # Check that the offset is correct
  1053. # We're not paginating, so should be 0
  1054. self.assertEqual(channel.json_body["offset"], 0)
  1055. # Check that there is no `prev_batch`
  1056. self.assertNotIn("prev_batch", channel.json_body)
  1057. # Check that there is no `next_batch`
  1058. self.assertNotIn("next_batch", channel.json_body)
  1059. # Check that all provided attributes are set
  1060. r = rooms[0]
  1061. self.assertEqual(room_id, r["room_id"])
  1062. self.assertEqual(test_room_name, r["name"])
  1063. self.assertEqual(test_alias, r["canonical_alias"])
  1064. def test_room_list_sort_order(self):
  1065. """Test room list sort ordering. alphabetical name versus number of members,
  1066. reversing the order, etc.
  1067. """
  1068. def _order_test(
  1069. order_type: str,
  1070. expected_room_list: List[str],
  1071. reverse: bool = False,
  1072. ):
  1073. """Request the list of rooms in a certain order. Assert that order is what
  1074. we expect
  1075. Args:
  1076. order_type: The type of ordering to give the server
  1077. expected_room_list: The list of room_ids in the order we expect to get
  1078. back from the server
  1079. """
  1080. # Request the list of rooms in the given order
  1081. url = "/_synapse/admin/v1/rooms?order_by=%s" % (order_type,)
  1082. if reverse:
  1083. url += "&dir=b"
  1084. channel = self.make_request(
  1085. "GET",
  1086. url.encode("ascii"),
  1087. access_token=self.admin_user_tok,
  1088. )
  1089. self.assertEqual(200, channel.code, msg=channel.json_body)
  1090. # Check that rooms were returned
  1091. self.assertTrue("rooms" in channel.json_body)
  1092. rooms = channel.json_body["rooms"]
  1093. # Check for the correct total_rooms value
  1094. self.assertEqual(channel.json_body["total_rooms"], 3)
  1095. # Check that the offset is correct
  1096. # We're not paginating, so should be 0
  1097. self.assertEqual(channel.json_body["offset"], 0)
  1098. # Check that there is no `prev_batch`
  1099. self.assertNotIn("prev_batch", channel.json_body)
  1100. # Check that there is no `next_batch`
  1101. self.assertNotIn("next_batch", channel.json_body)
  1102. # Check that rooms were returned in alphabetical order
  1103. returned_order = [r["room_id"] for r in rooms]
  1104. self.assertListEqual(expected_room_list, returned_order) # order is checked
  1105. # Create 3 test rooms
  1106. room_id_1 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1107. room_id_2 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1108. room_id_3 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1109. # Set room names in alphabetical order. room 1 -> A, 2 -> B, 3 -> C
  1110. self.helper.send_state(
  1111. room_id_1,
  1112. "m.room.name",
  1113. {"name": "A"},
  1114. tok=self.admin_user_tok,
  1115. )
  1116. self.helper.send_state(
  1117. room_id_2,
  1118. "m.room.name",
  1119. {"name": "B"},
  1120. tok=self.admin_user_tok,
  1121. )
  1122. self.helper.send_state(
  1123. room_id_3,
  1124. "m.room.name",
  1125. {"name": "C"},
  1126. tok=self.admin_user_tok,
  1127. )
  1128. # Set room canonical room aliases
  1129. self._set_canonical_alias(room_id_1, "#A_alias:test", self.admin_user_tok)
  1130. self._set_canonical_alias(room_id_2, "#B_alias:test", self.admin_user_tok)
  1131. self._set_canonical_alias(room_id_3, "#C_alias:test", self.admin_user_tok)
  1132. # Set room member size in the reverse order. room 1 -> 1 member, 2 -> 2, 3 -> 3
  1133. user_1 = self.register_user("bob1", "pass")
  1134. user_1_tok = self.login("bob1", "pass")
  1135. self.helper.join(room_id_2, user_1, tok=user_1_tok)
  1136. user_2 = self.register_user("bob2", "pass")
  1137. user_2_tok = self.login("bob2", "pass")
  1138. self.helper.join(room_id_3, user_2, tok=user_2_tok)
  1139. user_3 = self.register_user("bob3", "pass")
  1140. user_3_tok = self.login("bob3", "pass")
  1141. self.helper.join(room_id_3, user_3, tok=user_3_tok)
  1142. # Test different sort orders, with forward and reverse directions
  1143. _order_test("name", [room_id_1, room_id_2, room_id_3])
  1144. _order_test("name", [room_id_3, room_id_2, room_id_1], reverse=True)
  1145. _order_test("canonical_alias", [room_id_1, room_id_2, room_id_3])
  1146. _order_test("canonical_alias", [room_id_3, room_id_2, room_id_1], reverse=True)
  1147. _order_test("joined_members", [room_id_3, room_id_2, room_id_1])
  1148. _order_test("joined_members", [room_id_1, room_id_2, room_id_3], reverse=True)
  1149. _order_test("joined_local_members", [room_id_3, room_id_2, room_id_1])
  1150. _order_test(
  1151. "joined_local_members", [room_id_1, room_id_2, room_id_3], reverse=True
  1152. )
  1153. _order_test("version", [room_id_1, room_id_2, room_id_3])
  1154. _order_test("version", [room_id_1, room_id_2, room_id_3], reverse=True)
  1155. _order_test("creator", [room_id_1, room_id_2, room_id_3])
  1156. _order_test("creator", [room_id_1, room_id_2, room_id_3], reverse=True)
  1157. _order_test("encryption", [room_id_1, room_id_2, room_id_3])
  1158. _order_test("encryption", [room_id_1, room_id_2, room_id_3], reverse=True)
  1159. _order_test("federatable", [room_id_1, room_id_2, room_id_3])
  1160. _order_test("federatable", [room_id_1, room_id_2, room_id_3], reverse=True)
  1161. _order_test("public", [room_id_1, room_id_2, room_id_3])
  1162. # Different sort order of SQlite and PostreSQL
  1163. # _order_test("public", [room_id_3, room_id_2, room_id_1], reverse=True)
  1164. _order_test("join_rules", [room_id_1, room_id_2, room_id_3])
  1165. _order_test("join_rules", [room_id_1, room_id_2, room_id_3], reverse=True)
  1166. _order_test("guest_access", [room_id_1, room_id_2, room_id_3])
  1167. _order_test("guest_access", [room_id_1, room_id_2, room_id_3], reverse=True)
  1168. _order_test("history_visibility", [room_id_1, room_id_2, room_id_3])
  1169. _order_test(
  1170. "history_visibility", [room_id_1, room_id_2, room_id_3], reverse=True
  1171. )
  1172. _order_test("state_events", [room_id_3, room_id_2, room_id_1])
  1173. _order_test("state_events", [room_id_1, room_id_2, room_id_3], reverse=True)
  1174. def test_search_term(self):
  1175. """Test that searching for a room works correctly"""
  1176. # Create two test rooms
  1177. room_id_1 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1178. room_id_2 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1179. room_name_1 = "something"
  1180. room_name_2 = "LoremIpsum"
  1181. # Set the name for each room
  1182. self.helper.send_state(
  1183. room_id_1,
  1184. "m.room.name",
  1185. {"name": room_name_1},
  1186. tok=self.admin_user_tok,
  1187. )
  1188. self.helper.send_state(
  1189. room_id_2,
  1190. "m.room.name",
  1191. {"name": room_name_2},
  1192. tok=self.admin_user_tok,
  1193. )
  1194. self._set_canonical_alias(room_id_1, "#Room_Alias1:test", self.admin_user_tok)
  1195. def _search_test(
  1196. expected_room_id: Optional[str],
  1197. search_term: str,
  1198. expected_http_code: int = 200,
  1199. ):
  1200. """Search for a room and check that the returned room's id is a match
  1201. Args:
  1202. expected_room_id: The room_id expected to be returned by the API. Set
  1203. to None to expect zero results for the search
  1204. search_term: The term to search for room names with
  1205. expected_http_code: The expected http code for the request
  1206. """
  1207. url = "/_synapse/admin/v1/rooms?search_term=%s" % (search_term,)
  1208. channel = self.make_request(
  1209. "GET",
  1210. url.encode("ascii"),
  1211. access_token=self.admin_user_tok,
  1212. )
  1213. self.assertEqual(expected_http_code, channel.code, msg=channel.json_body)
  1214. if expected_http_code != 200:
  1215. return
  1216. # Check that rooms were returned
  1217. self.assertTrue("rooms" in channel.json_body)
  1218. rooms = channel.json_body["rooms"]
  1219. # Check that the expected number of rooms were returned
  1220. expected_room_count = 1 if expected_room_id else 0
  1221. self.assertEqual(len(rooms), expected_room_count)
  1222. self.assertEqual(channel.json_body["total_rooms"], expected_room_count)
  1223. # Check that the offset is correct
  1224. # We're not paginating, so should be 0
  1225. self.assertEqual(channel.json_body["offset"], 0)
  1226. # Check that there is no `prev_batch`
  1227. self.assertNotIn("prev_batch", channel.json_body)
  1228. # Check that there is no `next_batch`
  1229. self.assertNotIn("next_batch", channel.json_body)
  1230. if expected_room_id:
  1231. # Check that the first returned room id is correct
  1232. r = rooms[0]
  1233. self.assertEqual(expected_room_id, r["room_id"])
  1234. # Test searching by room name
  1235. _search_test(room_id_1, "something")
  1236. _search_test(room_id_1, "thing")
  1237. _search_test(room_id_2, "LoremIpsum")
  1238. _search_test(room_id_2, "lorem")
  1239. # Test case insensitive
  1240. _search_test(room_id_1, "SOMETHING")
  1241. _search_test(room_id_1, "THING")
  1242. _search_test(room_id_2, "LOREMIPSUM")
  1243. _search_test(room_id_2, "LOREM")
  1244. _search_test(None, "foo")
  1245. _search_test(None, "bar")
  1246. _search_test(None, "", expected_http_code=400)
  1247. # Test that the whole room id returns the room
  1248. _search_test(room_id_1, room_id_1)
  1249. # Test that the search by room_id is case sensitive
  1250. _search_test(None, room_id_1.lower())
  1251. # Test search part of local part of room id do not match
  1252. _search_test(None, room_id_1[1:10])
  1253. # Test that whole room alias return no result, because of domain
  1254. _search_test(None, "#Room_Alias1:test")
  1255. # Test search local part of alias
  1256. _search_test(room_id_1, "alias1")
  1257. def test_search_term_non_ascii(self):
  1258. """Test that searching for a room with non-ASCII characters works correctly"""
  1259. # Create test room
  1260. room_id = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1261. room_name = "ж"
  1262. # Set the name for the room
  1263. self.helper.send_state(
  1264. room_id,
  1265. "m.room.name",
  1266. {"name": room_name},
  1267. tok=self.admin_user_tok,
  1268. )
  1269. # make the request and test that the response is what we wanted
  1270. search_term = urllib.parse.quote("ж", "utf-8")
  1271. url = "/_synapse/admin/v1/rooms?search_term=%s" % (search_term,)
  1272. channel = self.make_request(
  1273. "GET",
  1274. url.encode("ascii"),
  1275. access_token=self.admin_user_tok,
  1276. )
  1277. self.assertEqual(200, channel.code, msg=channel.json_body)
  1278. self.assertEqual(room_id, channel.json_body.get("rooms")[0].get("room_id"))
  1279. self.assertEqual("ж", channel.json_body.get("rooms")[0].get("name"))
  1280. def test_single_room(self):
  1281. """Test that a single room can be requested correctly"""
  1282. # Create two test rooms
  1283. room_id_1 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1284. room_id_2 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1285. room_name_1 = "something"
  1286. room_name_2 = "else"
  1287. # Set the name for each room
  1288. self.helper.send_state(
  1289. room_id_1,
  1290. "m.room.name",
  1291. {"name": room_name_1},
  1292. tok=self.admin_user_tok,
  1293. )
  1294. self.helper.send_state(
  1295. room_id_2,
  1296. "m.room.name",
  1297. {"name": room_name_2},
  1298. tok=self.admin_user_tok,
  1299. )
  1300. url = "/_synapse/admin/v1/rooms/%s" % (room_id_1,)
  1301. channel = self.make_request(
  1302. "GET",
  1303. url.encode("ascii"),
  1304. access_token=self.admin_user_tok,
  1305. )
  1306. self.assertEqual(200, channel.code, msg=channel.json_body)
  1307. self.assertIn("room_id", channel.json_body)
  1308. self.assertIn("name", channel.json_body)
  1309. self.assertIn("topic", channel.json_body)
  1310. self.assertIn("avatar", channel.json_body)
  1311. self.assertIn("canonical_alias", channel.json_body)
  1312. self.assertIn("joined_members", channel.json_body)
  1313. self.assertIn("joined_local_members", channel.json_body)
  1314. self.assertIn("joined_local_devices", channel.json_body)
  1315. self.assertIn("version", channel.json_body)
  1316. self.assertIn("creator", channel.json_body)
  1317. self.assertIn("encryption", channel.json_body)
  1318. self.assertIn("federatable", channel.json_body)
  1319. self.assertIn("public", channel.json_body)
  1320. self.assertIn("join_rules", channel.json_body)
  1321. self.assertIn("guest_access", channel.json_body)
  1322. self.assertIn("history_visibility", channel.json_body)
  1323. self.assertIn("state_events", channel.json_body)
  1324. self.assertEqual(room_id_1, channel.json_body["room_id"])
  1325. def test_single_room_devices(self):
  1326. """Test that `joined_local_devices` can be requested correctly"""
  1327. room_id_1 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1328. url = "/_synapse/admin/v1/rooms/%s" % (room_id_1,)
  1329. channel = self.make_request(
  1330. "GET",
  1331. url.encode("ascii"),
  1332. access_token=self.admin_user_tok,
  1333. )
  1334. self.assertEqual(200, channel.code, msg=channel.json_body)
  1335. self.assertEqual(1, channel.json_body["joined_local_devices"])
  1336. # Have another user join the room
  1337. user_1 = self.register_user("foo", "pass")
  1338. user_tok_1 = self.login("foo", "pass")
  1339. self.helper.join(room_id_1, user_1, tok=user_tok_1)
  1340. url = "/_synapse/admin/v1/rooms/%s" % (room_id_1,)
  1341. channel = self.make_request(
  1342. "GET",
  1343. url.encode("ascii"),
  1344. access_token=self.admin_user_tok,
  1345. )
  1346. self.assertEqual(200, channel.code, msg=channel.json_body)
  1347. self.assertEqual(2, channel.json_body["joined_local_devices"])
  1348. # leave room
  1349. self.helper.leave(room_id_1, self.admin_user, tok=self.admin_user_tok)
  1350. self.helper.leave(room_id_1, user_1, tok=user_tok_1)
  1351. url = "/_synapse/admin/v1/rooms/%s" % (room_id_1,)
  1352. channel = self.make_request(
  1353. "GET",
  1354. url.encode("ascii"),
  1355. access_token=self.admin_user_tok,
  1356. )
  1357. self.assertEqual(200, channel.code, msg=channel.json_body)
  1358. self.assertEqual(0, channel.json_body["joined_local_devices"])
  1359. def test_room_members(self):
  1360. """Test that room members can be requested correctly"""
  1361. # Create two test rooms
  1362. room_id_1 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1363. room_id_2 = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1364. # Have another user join the room
  1365. user_1 = self.register_user("foo", "pass")
  1366. user_tok_1 = self.login("foo", "pass")
  1367. self.helper.join(room_id_1, user_1, tok=user_tok_1)
  1368. # Have another user join the room
  1369. user_2 = self.register_user("bar", "pass")
  1370. user_tok_2 = self.login("bar", "pass")
  1371. self.helper.join(room_id_1, user_2, tok=user_tok_2)
  1372. self.helper.join(room_id_2, user_2, tok=user_tok_2)
  1373. # Have another user join the room
  1374. user_3 = self.register_user("foobar", "pass")
  1375. user_tok_3 = self.login("foobar", "pass")
  1376. self.helper.join(room_id_2, user_3, tok=user_tok_3)
  1377. url = "/_synapse/admin/v1/rooms/%s/members" % (room_id_1,)
  1378. channel = self.make_request(
  1379. "GET",
  1380. url.encode("ascii"),
  1381. access_token=self.admin_user_tok,
  1382. )
  1383. self.assertEqual(200, channel.code, msg=channel.json_body)
  1384. self.assertCountEqual(
  1385. ["@admin:test", "@foo:test", "@bar:test"], channel.json_body["members"]
  1386. )
  1387. self.assertEqual(channel.json_body["total"], 3)
  1388. url = "/_synapse/admin/v1/rooms/%s/members" % (room_id_2,)
  1389. channel = self.make_request(
  1390. "GET",
  1391. url.encode("ascii"),
  1392. access_token=self.admin_user_tok,
  1393. )
  1394. self.assertEqual(200, channel.code, msg=channel.json_body)
  1395. self.assertCountEqual(
  1396. ["@admin:test", "@bar:test", "@foobar:test"], channel.json_body["members"]
  1397. )
  1398. self.assertEqual(channel.json_body["total"], 3)
  1399. def test_room_state(self):
  1400. """Test that room state can be requested correctly"""
  1401. # Create two test rooms
  1402. room_id = self.helper.create_room_as(self.admin_user, tok=self.admin_user_tok)
  1403. url = "/_synapse/admin/v1/rooms/%s/state" % (room_id,)
  1404. channel = self.make_request(
  1405. "GET",
  1406. url.encode("ascii"),
  1407. access_token=self.admin_user_tok,
  1408. )
  1409. self.assertEqual(200, channel.code, msg=channel.json_body)
  1410. self.assertIn("state", channel.json_body)
  1411. # testing that the state events match is painful and not done here. We assume that
  1412. # the create_room already does the right thing, so no need to verify that we got
  1413. # the state events it created.
  1414. def _set_canonical_alias(self, room_id: str, test_alias: str, admin_user_tok: str):
  1415. # Create a new alias to this room
  1416. url = "/_matrix/client/r0/directory/room/%s" % (urllib.parse.quote(test_alias),)
  1417. channel = self.make_request(
  1418. "PUT",
  1419. url.encode("ascii"),
  1420. {"room_id": room_id},
  1421. access_token=admin_user_tok,
  1422. )
  1423. self.assertEqual(200, channel.code, msg=channel.json_body)
  1424. # Set this new alias as the canonical alias for this room
  1425. self.helper.send_state(
  1426. room_id,
  1427. "m.room.aliases",
  1428. {"aliases": [test_alias]},
  1429. tok=admin_user_tok,
  1430. state_key="test",
  1431. )
  1432. self.helper.send_state(
  1433. room_id,
  1434. "m.room.canonical_alias",
  1435. {"alias": test_alias},
  1436. tok=admin_user_tok,
  1437. )
  1438. class JoinAliasRoomTestCase(unittest.HomeserverTestCase):
  1439. servlets = [
  1440. synapse.rest.admin.register_servlets,
  1441. room.register_servlets,
  1442. login.register_servlets,
  1443. ]
  1444. def prepare(self, reactor, clock, homeserver):
  1445. self.admin_user = self.register_user("admin", "pass", admin=True)
  1446. self.admin_user_tok = self.login("admin", "pass")
  1447. self.creator = self.register_user("creator", "test")
  1448. self.creator_tok = self.login("creator", "test")
  1449. self.second_user_id = self.register_user("second", "test")
  1450. self.second_tok = self.login("second", "test")
  1451. self.public_room_id = self.helper.create_room_as(
  1452. self.creator, tok=self.creator_tok, is_public=True
  1453. )
  1454. self.url = f"/_synapse/admin/v1/join/{self.public_room_id}"
  1455. def test_requester_is_no_admin(self):
  1456. """
  1457. If the user is not a server admin, an error 403 is returned.
  1458. """
  1459. body = json.dumps({"user_id": self.second_user_id})
  1460. channel = self.make_request(
  1461. "POST",
  1462. self.url,
  1463. content=body,
  1464. access_token=self.second_tok,
  1465. )
  1466. self.assertEqual(403, channel.code, msg=channel.json_body)
  1467. self.assertEqual(Codes.FORBIDDEN, channel.json_body["errcode"])
  1468. def test_invalid_parameter(self):
  1469. """
  1470. If a parameter is missing, return an error
  1471. """
  1472. body = json.dumps({"unknown_parameter": "@unknown:test"})
  1473. channel = self.make_request(
  1474. "POST",
  1475. self.url,
  1476. content=body,
  1477. access_token=self.admin_user_tok,
  1478. )
  1479. self.assertEqual(400, channel.code, msg=channel.json_body)
  1480. self.assertEqual(Codes.MISSING_PARAM, channel.json_body["errcode"])
  1481. def test_local_user_does_not_exist(self):
  1482. """
  1483. Tests that a lookup for a user that does not exist returns a 404
  1484. """
  1485. body = json.dumps({"user_id": "@unknown:test"})
  1486. channel = self.make_request(
  1487. "POST",
  1488. self.url,
  1489. content=body,
  1490. access_token=self.admin_user_tok,
  1491. )
  1492. self.assertEqual(404, channel.code, msg=channel.json_body)
  1493. self.assertEqual(Codes.NOT_FOUND, channel.json_body["errcode"])
  1494. def test_remote_user(self):
  1495. """
  1496. Check that only local user can join rooms.
  1497. """
  1498. body = json.dumps({"user_id": "@not:exist.bla"})
  1499. channel = self.make_request(
  1500. "POST",
  1501. self.url,
  1502. content=body,
  1503. access_token=self.admin_user_tok,
  1504. )
  1505. self.assertEqual(400, channel.code, msg=channel.json_body)
  1506. self.assertEqual(
  1507. "This endpoint can only be used with local users",
  1508. channel.json_body["error"],
  1509. )
  1510. def test_room_does_not_exist(self):
  1511. """
  1512. Check that unknown rooms/server return error 404.
  1513. """
  1514. body = json.dumps({"user_id": self.second_user_id})
  1515. url = "/_synapse/admin/v1/join/!unknown:test"
  1516. channel = self.make_request(
  1517. "POST",
  1518. url,
  1519. content=body,
  1520. access_token=self.admin_user_tok,
  1521. )
  1522. self.assertEqual(404, channel.code, msg=channel.json_body)
  1523. self.assertEqual("No known servers", channel.json_body["error"])
  1524. def test_room_is_not_valid(self):
  1525. """
  1526. Check that invalid room names, return an error 400.
  1527. """
  1528. body = json.dumps({"user_id": self.second_user_id})
  1529. url = "/_synapse/admin/v1/join/invalidroom"
  1530. channel = self.make_request(
  1531. "POST",
  1532. url,
  1533. content=body,
  1534. access_token=self.admin_user_tok,
  1535. )
  1536. self.assertEqual(400, channel.code, msg=channel.json_body)
  1537. self.assertEqual(
  1538. "invalidroom was not legal room ID or room alias",
  1539. channel.json_body["error"],
  1540. )
  1541. def test_join_public_room(self):
  1542. """
  1543. Test joining a local user to a public room with "JoinRules.PUBLIC"
  1544. """
  1545. body = json.dumps({"user_id": self.second_user_id})
  1546. channel = self.make_request(
  1547. "POST",
  1548. self.url,
  1549. content=body,
  1550. access_token=self.admin_user_tok,
  1551. )
  1552. self.assertEqual(200, channel.code, msg=channel.json_body)
  1553. self.assertEqual(self.public_room_id, channel.json_body["room_id"])
  1554. # Validate if user is a member of the room
  1555. channel = self.make_request(
  1556. "GET",
  1557. "/_matrix/client/r0/joined_rooms",
  1558. access_token=self.second_tok,
  1559. )
  1560. self.assertEquals(200, channel.code, msg=channel.json_body)
  1561. self.assertEqual(self.public_room_id, channel.json_body["joined_rooms"][0])
  1562. def test_join_private_room_if_not_member(self):
  1563. """
  1564. Test joining a local user to a private room with "JoinRules.INVITE"
  1565. when server admin is not member of this room.
  1566. """
  1567. private_room_id = self.helper.create_room_as(
  1568. self.creator, tok=self.creator_tok, is_public=False
  1569. )
  1570. url = f"/_synapse/admin/v1/join/{private_room_id}"
  1571. body = json.dumps({"user_id": self.second_user_id})
  1572. channel = self.make_request(
  1573. "POST",
  1574. url,
  1575. content=body,
  1576. access_token=self.admin_user_tok,
  1577. )
  1578. self.assertEqual(403, channel.code, msg=channel.json_body)
  1579. self.assertEqual(Codes.FORBIDDEN, channel.json_body["errcode"])
  1580. def test_join_private_room_if_member(self):
  1581. """
  1582. Test joining a local user to a private room with "JoinRules.INVITE",
  1583. when server admin is member of this room.
  1584. """
  1585. private_room_id = self.helper.create_room_as(
  1586. self.creator, tok=self.creator_tok, is_public=False
  1587. )
  1588. self.helper.invite(
  1589. room=private_room_id,
  1590. src=self.creator,
  1591. targ=self.admin_user,
  1592. tok=self.creator_tok,
  1593. )
  1594. self.helper.join(
  1595. room=private_room_id, user=self.admin_user, tok=self.admin_user_tok
  1596. )
  1597. # Validate if server admin is a member of the room
  1598. channel = self.make_request(
  1599. "GET",
  1600. "/_matrix/client/r0/joined_rooms",
  1601. access_token=self.admin_user_tok,
  1602. )
  1603. self.assertEquals(200, channel.code, msg=channel.json_body)
  1604. self.assertEqual(private_room_id, channel.json_body["joined_rooms"][0])
  1605. # Join user to room.
  1606. url = f"/_synapse/admin/v1/join/{private_room_id}"
  1607. body = json.dumps({"user_id": self.second_user_id})
  1608. channel = self.make_request(
  1609. "POST",
  1610. url,
  1611. content=body,
  1612. access_token=self.admin_user_tok,
  1613. )
  1614. self.assertEqual(200, channel.code, msg=channel.json_body)
  1615. self.assertEqual(private_room_id, channel.json_body["room_id"])
  1616. # Validate if user is a member of the room
  1617. channel = self.make_request(
  1618. "GET",
  1619. "/_matrix/client/r0/joined_rooms",
  1620. access_token=self.second_tok,
  1621. )
  1622. self.assertEquals(200, channel.code, msg=channel.json_body)
  1623. self.assertEqual(private_room_id, channel.json_body["joined_rooms"][0])
  1624. def test_join_private_room_if_owner(self):
  1625. """
  1626. Test joining a local user to a private room with "JoinRules.INVITE",
  1627. when server admin is owner of this room.
  1628. """
  1629. private_room_id = self.helper.create_room_as(
  1630. self.admin_user, tok=self.admin_user_tok, is_public=False
  1631. )
  1632. url = f"/_synapse/admin/v1/join/{private_room_id}"
  1633. body = json.dumps({"user_id": self.second_user_id})
  1634. channel = self.make_request(
  1635. "POST",
  1636. url,
  1637. content=body,
  1638. access_token=self.admin_user_tok,
  1639. )
  1640. self.assertEqual(200, channel.code, msg=channel.json_body)
  1641. self.assertEqual(private_room_id, channel.json_body["room_id"])
  1642. # Validate if user is a member of the room
  1643. channel = self.make_request(
  1644. "GET",
  1645. "/_matrix/client/r0/joined_rooms",
  1646. access_token=self.second_tok,
  1647. )
  1648. self.assertEquals(200, channel.code, msg=channel.json_body)
  1649. self.assertEqual(private_room_id, channel.json_body["joined_rooms"][0])
  1650. def test_context_as_non_admin(self):
  1651. """
  1652. Test that, without being admin, one cannot use the context admin API
  1653. """
  1654. # Create a room.
  1655. user_id = self.register_user("test", "test")
  1656. user_tok = self.login("test", "test")
  1657. self.register_user("test_2", "test")
  1658. user_tok_2 = self.login("test_2", "test")
  1659. room_id = self.helper.create_room_as(user_id, tok=user_tok)
  1660. # Populate the room with events.
  1661. events = []
  1662. for i in range(30):
  1663. events.append(
  1664. self.helper.send_event(
  1665. room_id, "com.example.test", content={"index": i}, tok=user_tok
  1666. )
  1667. )
  1668. # Now attempt to find the context using the admin API without being admin.
  1669. midway = (len(events) - 1) // 2
  1670. for tok in [user_tok, user_tok_2]:
  1671. channel = self.make_request(
  1672. "GET",
  1673. "/_synapse/admin/v1/rooms/%s/context/%s"
  1674. % (room_id, events[midway]["event_id"]),
  1675. access_token=tok,
  1676. )
  1677. self.assertEquals(403, channel.code, msg=channel.json_body)
  1678. self.assertEqual(Codes.FORBIDDEN, channel.json_body["errcode"])
  1679. def test_context_as_admin(self):
  1680. """
  1681. Test that, as admin, we can find the context of an event without having joined the room.
  1682. """
  1683. # Create a room. We're not part of it.
  1684. user_id = self.register_user("test", "test")
  1685. user_tok = self.login("test", "test")
  1686. room_id = self.helper.create_room_as(user_id, tok=user_tok)
  1687. # Populate the room with events.
  1688. events = []
  1689. for i in range(30):
  1690. events.append(
  1691. self.helper.send_event(
  1692. room_id, "com.example.test", content={"index": i}, tok=user_tok
  1693. )
  1694. )
  1695. # Now let's fetch the context for this room.
  1696. midway = (len(events) - 1) // 2
  1697. channel = self.make_request(
  1698. "GET",
  1699. "/_synapse/admin/v1/rooms/%s/context/%s"
  1700. % (room_id, events[midway]["event_id"]),
  1701. access_token=self.admin_user_tok,
  1702. )
  1703. self.assertEquals(200, channel.code, msg=channel.json_body)
  1704. self.assertEquals(
  1705. channel.json_body["event"]["event_id"], events[midway]["event_id"]
  1706. )
  1707. for found_event in channel.json_body["events_before"]:
  1708. for j, posted_event in enumerate(events):
  1709. if found_event["event_id"] == posted_event["event_id"]:
  1710. self.assertTrue(j < midway)
  1711. break
  1712. else:
  1713. self.fail("Event %s from events_before not found" % j)
  1714. for found_event in channel.json_body["events_after"]:
  1715. for j, posted_event in enumerate(events):
  1716. if found_event["event_id"] == posted_event["event_id"]:
  1717. self.assertTrue(j > midway)
  1718. break
  1719. else:
  1720. self.fail("Event %s from events_after not found" % j)
  1721. class MakeRoomAdminTestCase(unittest.HomeserverTestCase):
  1722. servlets = [
  1723. synapse.rest.admin.register_servlets,
  1724. room.register_servlets,
  1725. login.register_servlets,
  1726. ]
  1727. def prepare(self, reactor, clock, homeserver):
  1728. self.admin_user = self.register_user("admin", "pass", admin=True)
  1729. self.admin_user_tok = self.login("admin", "pass")
  1730. self.creator = self.register_user("creator", "test")
  1731. self.creator_tok = self.login("creator", "test")
  1732. self.second_user_id = self.register_user("second", "test")
  1733. self.second_tok = self.login("second", "test")
  1734. self.public_room_id = self.helper.create_room_as(
  1735. self.creator, tok=self.creator_tok, is_public=True
  1736. )
  1737. self.url = "/_synapse/admin/v1/rooms/{}/make_room_admin".format(
  1738. self.public_room_id
  1739. )
  1740. def test_public_room(self):
  1741. """Test that getting admin in a public room works."""
  1742. room_id = self.helper.create_room_as(
  1743. self.creator, tok=self.creator_tok, is_public=True
  1744. )
  1745. channel = self.make_request(
  1746. "POST",
  1747. f"/_synapse/admin/v1/rooms/{room_id}/make_room_admin",
  1748. content={},
  1749. access_token=self.admin_user_tok,
  1750. )
  1751. self.assertEqual(200, channel.code, msg=channel.json_body)
  1752. # Now we test that we can join the room and ban a user.
  1753. self.helper.join(room_id, self.admin_user, tok=self.admin_user_tok)
  1754. self.helper.change_membership(
  1755. room_id,
  1756. self.admin_user,
  1757. "@test:test",
  1758. Membership.BAN,
  1759. tok=self.admin_user_tok,
  1760. )
  1761. def test_private_room(self):
  1762. """Test that getting admin in a private room works and we get invited."""
  1763. room_id = self.helper.create_room_as(
  1764. self.creator,
  1765. tok=self.creator_tok,
  1766. is_public=False,
  1767. )
  1768. channel = self.make_request(
  1769. "POST",
  1770. f"/_synapse/admin/v1/rooms/{room_id}/make_room_admin",
  1771. content={},
  1772. access_token=self.admin_user_tok,
  1773. )
  1774. self.assertEqual(200, channel.code, msg=channel.json_body)
  1775. # Now we test that we can join the room (we should have received an
  1776. # invite) and can ban a user.
  1777. self.helper.join(room_id, self.admin_user, tok=self.admin_user_tok)
  1778. self.helper.change_membership(
  1779. room_id,
  1780. self.admin_user,
  1781. "@test:test",
  1782. Membership.BAN,
  1783. tok=self.admin_user_tok,
  1784. )
  1785. def test_other_user(self):
  1786. """Test that giving admin in a public room works to a non-admin user works."""
  1787. room_id = self.helper.create_room_as(
  1788. self.creator, tok=self.creator_tok, is_public=True
  1789. )
  1790. channel = self.make_request(
  1791. "POST",
  1792. f"/_synapse/admin/v1/rooms/{room_id}/make_room_admin",
  1793. content={"user_id": self.second_user_id},
  1794. access_token=self.admin_user_tok,
  1795. )
  1796. self.assertEqual(200, channel.code, msg=channel.json_body)
  1797. # Now we test that we can join the room and ban a user.
  1798. self.helper.join(room_id, self.second_user_id, tok=self.second_tok)
  1799. self.helper.change_membership(
  1800. room_id,
  1801. self.second_user_id,
  1802. "@test:test",
  1803. Membership.BAN,
  1804. tok=self.second_tok,
  1805. )
  1806. def test_not_enough_power(self):
  1807. """Test that we get a sensible error if there are no local room admins."""
  1808. room_id = self.helper.create_room_as(
  1809. self.creator, tok=self.creator_tok, is_public=True
  1810. )
  1811. # The creator drops admin rights in the room.
  1812. pl = self.helper.get_state(
  1813. room_id, EventTypes.PowerLevels, tok=self.creator_tok
  1814. )
  1815. pl["users"][self.creator] = 0
  1816. self.helper.send_state(
  1817. room_id, EventTypes.PowerLevels, body=pl, tok=self.creator_tok
  1818. )
  1819. channel = self.make_request(
  1820. "POST",
  1821. f"/_synapse/admin/v1/rooms/{room_id}/make_room_admin",
  1822. content={},
  1823. access_token=self.admin_user_tok,
  1824. )
  1825. # We expect this to fail with a 400 as there are no room admins.
  1826. #
  1827. # (Note we assert the error message to ensure that it's not denied for
  1828. # some other reason)
  1829. self.assertEqual(400, channel.code, msg=channel.json_body)
  1830. self.assertEqual(
  1831. channel.json_body["error"],
  1832. "No local admin user in room with power to update power levels.",
  1833. )
  1834. class BlockRoomTestCase(unittest.HomeserverTestCase):
  1835. servlets = [
  1836. synapse.rest.admin.register_servlets,
  1837. room.register_servlets,
  1838. login.register_servlets,
  1839. ]
  1840. def prepare(self, reactor, clock, hs):
  1841. self._store = hs.get_datastore()
  1842. self.admin_user = self.register_user("admin", "pass", admin=True)
  1843. self.admin_user_tok = self.login("admin", "pass")
  1844. self.other_user = self.register_user("user", "pass")
  1845. self.other_user_tok = self.login("user", "pass")
  1846. self.room_id = self.helper.create_room_as(
  1847. self.other_user, tok=self.other_user_tok
  1848. )
  1849. self.url = "/_synapse/admin/v1/rooms/%s/block"
  1850. @parameterized.expand([("PUT",), ("GET",)])
  1851. def test_requester_is_no_admin(self, method: str):
  1852. """If the user is not a server admin, an error 403 is returned."""
  1853. channel = self.make_request(
  1854. method,
  1855. self.url % self.room_id,
  1856. content={},
  1857. access_token=self.other_user_tok,
  1858. )
  1859. self.assertEqual(HTTPStatus.FORBIDDEN, channel.code, msg=channel.json_body)
  1860. self.assertEqual(Codes.FORBIDDEN, channel.json_body["errcode"])
  1861. @parameterized.expand([("PUT",), ("GET",)])
  1862. def test_room_is_not_valid(self, method: str):
  1863. """Check that invalid room names, return an error 400."""
  1864. channel = self.make_request(
  1865. method,
  1866. self.url % "invalidroom",
  1867. content={},
  1868. access_token=self.admin_user_tok,
  1869. )
  1870. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  1871. self.assertEqual(
  1872. "invalidroom is not a legal room ID",
  1873. channel.json_body["error"],
  1874. )
  1875. def test_block_is_not_valid(self):
  1876. """If parameter `block` is not valid, return an error."""
  1877. # `block` is not valid
  1878. channel = self.make_request(
  1879. "PUT",
  1880. self.url % self.room_id,
  1881. content={"block": "NotBool"},
  1882. access_token=self.admin_user_tok,
  1883. )
  1884. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  1885. self.assertEqual(Codes.BAD_JSON, channel.json_body["errcode"])
  1886. # `block` is not set
  1887. channel = self.make_request(
  1888. "PUT",
  1889. self.url % self.room_id,
  1890. content={},
  1891. access_token=self.admin_user_tok,
  1892. )
  1893. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  1894. self.assertEqual(Codes.MISSING_PARAM, channel.json_body["errcode"])
  1895. # no content is send
  1896. channel = self.make_request(
  1897. "PUT",
  1898. self.url % self.room_id,
  1899. access_token=self.admin_user_tok,
  1900. )
  1901. self.assertEqual(HTTPStatus.BAD_REQUEST, channel.code, msg=channel.json_body)
  1902. self.assertEqual(Codes.NOT_JSON, channel.json_body["errcode"])
  1903. def test_block_room(self):
  1904. """Test that block a room is successful."""
  1905. def _request_and_test_block_room(room_id: str) -> None:
  1906. self._is_blocked(room_id, expect=False)
  1907. channel = self.make_request(
  1908. "PUT",
  1909. self.url % room_id,
  1910. content={"block": True},
  1911. access_token=self.admin_user_tok,
  1912. )
  1913. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  1914. self.assertTrue(channel.json_body["block"])
  1915. self._is_blocked(room_id, expect=True)
  1916. # known internal room
  1917. _request_and_test_block_room(self.room_id)
  1918. # unknown internal room
  1919. _request_and_test_block_room("!unknown:test")
  1920. # unknown remote room
  1921. _request_and_test_block_room("!unknown:remote")
  1922. def test_block_room_twice(self):
  1923. """Test that block a room that is already blocked is successful."""
  1924. self._is_blocked(self.room_id, expect=False)
  1925. for _ in range(2):
  1926. channel = self.make_request(
  1927. "PUT",
  1928. self.url % self.room_id,
  1929. content={"block": True},
  1930. access_token=self.admin_user_tok,
  1931. )
  1932. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  1933. self.assertTrue(channel.json_body["block"])
  1934. self._is_blocked(self.room_id, expect=True)
  1935. def test_unblock_room(self):
  1936. """Test that unblock a room is successful."""
  1937. def _request_and_test_unblock_room(room_id: str) -> None:
  1938. self._block_room(room_id)
  1939. channel = self.make_request(
  1940. "PUT",
  1941. self.url % room_id,
  1942. content={"block": False},
  1943. access_token=self.admin_user_tok,
  1944. )
  1945. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  1946. self.assertFalse(channel.json_body["block"])
  1947. self._is_blocked(room_id, expect=False)
  1948. # known internal room
  1949. _request_and_test_unblock_room(self.room_id)
  1950. # unknown internal room
  1951. _request_and_test_unblock_room("!unknown:test")
  1952. # unknown remote room
  1953. _request_and_test_unblock_room("!unknown:remote")
  1954. def test_unblock_room_twice(self):
  1955. """Test that unblock a room that is not blocked is successful."""
  1956. self._block_room(self.room_id)
  1957. for _ in range(2):
  1958. channel = self.make_request(
  1959. "PUT",
  1960. self.url % self.room_id,
  1961. content={"block": False},
  1962. access_token=self.admin_user_tok,
  1963. )
  1964. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  1965. self.assertFalse(channel.json_body["block"])
  1966. self._is_blocked(self.room_id, expect=False)
  1967. def test_get_blocked_room(self):
  1968. """Test get status of a blocked room"""
  1969. def _request_blocked_room(room_id: str) -> None:
  1970. self._block_room(room_id)
  1971. channel = self.make_request(
  1972. "GET",
  1973. self.url % room_id,
  1974. access_token=self.admin_user_tok,
  1975. )
  1976. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  1977. self.assertTrue(channel.json_body["block"])
  1978. self.assertEqual(self.other_user, channel.json_body["user_id"])
  1979. # known internal room
  1980. _request_blocked_room(self.room_id)
  1981. # unknown internal room
  1982. _request_blocked_room("!unknown:test")
  1983. # unknown remote room
  1984. _request_blocked_room("!unknown:remote")
  1985. def test_get_unblocked_room(self):
  1986. """Test get status of a unblocked room"""
  1987. def _request_unblocked_room(room_id: str) -> None:
  1988. self._is_blocked(room_id, expect=False)
  1989. channel = self.make_request(
  1990. "GET",
  1991. self.url % room_id,
  1992. access_token=self.admin_user_tok,
  1993. )
  1994. self.assertEqual(HTTPStatus.OK, channel.code, msg=channel.json_body)
  1995. self.assertFalse(channel.json_body["block"])
  1996. self.assertNotIn("user_id", channel.json_body)
  1997. # known internal room
  1998. _request_unblocked_room(self.room_id)
  1999. # unknown internal room
  2000. _request_unblocked_room("!unknown:test")
  2001. # unknown remote room
  2002. _request_unblocked_room("!unknown:remote")
  2003. def _is_blocked(self, room_id: str, expect: bool = True) -> None:
  2004. """Assert that the room is blocked or not"""
  2005. d = self._store.is_room_blocked(room_id)
  2006. if expect:
  2007. self.assertTrue(self.get_success(d))
  2008. else:
  2009. self.assertIsNone(self.get_success(d))
  2010. def _block_room(self, room_id: str) -> None:
  2011. """Block a room in database"""
  2012. self.get_success(self._store.block_room(room_id, self.other_user))
  2013. self._is_blocked(room_id, expect=True)
  2014. PURGE_TABLES = [
  2015. "current_state_events",
  2016. "event_backward_extremities",
  2017. "event_forward_extremities",
  2018. "event_json",
  2019. "event_push_actions",
  2020. "event_search",
  2021. "events",
  2022. "group_rooms",
  2023. "public_room_list_stream",
  2024. "receipts_graph",
  2025. "receipts_linearized",
  2026. "room_aliases",
  2027. "room_depth",
  2028. "room_memberships",
  2029. "room_stats_state",
  2030. "room_stats_current",
  2031. "room_stats_earliest_token",
  2032. "rooms",
  2033. "stream_ordering_to_exterm",
  2034. "users_in_public_rooms",
  2035. "users_who_share_private_rooms",
  2036. "appservice_room_list",
  2037. "e2e_room_keys",
  2038. "event_push_summary",
  2039. "pusher_throttle",
  2040. "group_summary_rooms",
  2041. "room_account_data",
  2042. "room_tags",
  2043. # "state_groups", # Current impl leaves orphaned state groups around.
  2044. "state_groups_state",
  2045. ]