UserModelTest.php 6.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205
  1. <?php
  2. namespace Tests\Feature\Models;
  3. use App\Models\AuthLog;
  4. use App\Models\Group;
  5. use App\Models\TwoFAccount;
  6. use App\Models\User;
  7. use Illuminate\Auth\Events\PasswordReset;
  8. use Illuminate\Support\Facades\Artisan;
  9. use Illuminate\Support\Facades\DB;
  10. use Illuminate\Support\Facades\Event;
  11. use Illuminate\Support\Facades\Password;
  12. use Illuminate\Support\Facades\Storage;
  13. use PHPUnit\Framework\Attributes\CoversClass;
  14. use Tests\Data\OtpTestData;
  15. use Tests\FeatureTestCase;
  16. /**
  17. * UserModelTest test class
  18. */
  19. #[CoversClass(User::class)]
  20. class UserModelTest extends FeatureTestCase
  21. {
  22. /**
  23. * @test
  24. */
  25. public function test_admin_scope_returns_only_admin()
  26. {
  27. User::factory()->count(4)->create();
  28. $firstAdmin = User::factory()->administrator()->create([
  29. 'name' => 'first',
  30. ]);
  31. $secondAdmin = User::factory()->administrator()->create([
  32. 'name' => 'secondAdmin',
  33. ]);
  34. $admins = User::admins()->get();
  35. $this->assertCount(2, $admins);
  36. $this->assertEquals($admins[0]->is_admin, true);
  37. $this->assertEquals($admins[1]->is_admin, true);
  38. $this->assertEquals($admins[0]->name, $firstAdmin->name);
  39. $this->assertEquals($admins[1]->name, $secondAdmin->name);
  40. }
  41. /**
  42. * @test
  43. */
  44. public function test_isAdministrator_returns_correct_state()
  45. {
  46. $user = User::factory()->create();
  47. $admin = User::factory()->administrator()->create();
  48. $this->assertEquals($user->isAdministrator(), false);
  49. $this->assertEquals($admin->isAdministrator(), true);
  50. }
  51. /**
  52. * @test
  53. */
  54. public function test_promoteToAdministrator_sets_administrator_status()
  55. {
  56. $user = User::factory()->create();
  57. $user->promoteToAdministrator();
  58. $this->assertEquals($user->isAdministrator(), true);
  59. }
  60. /**
  61. * @test
  62. */
  63. public function test_promoteToAdministrator_demote_administrator_status()
  64. {
  65. $admin = User::factory()->administrator()->create();
  66. // We need another admin to prevent demoting event returning false
  67. // and blocking the demotion
  68. $another_admin = User::factory()->administrator()->create();
  69. $admin->promoteToAdministrator(false);
  70. $admin->save();
  71. $this->assertFalse($admin->isAdministrator());
  72. }
  73. /**
  74. * @test
  75. */
  76. public function test_resetPassword_resets_password_with_success()
  77. {
  78. $user = User::factory()->create();
  79. $oldPassword = $user->password;
  80. $user->resetPassword();
  81. $this->assertNotEquals($user->password, $oldPassword);
  82. }
  83. /**
  84. * @test
  85. */
  86. public function test_resetPassword_dispatch_event()
  87. {
  88. Event::fake();
  89. $user = User::factory()->create();
  90. Event::assertDispatched(
  91. PasswordReset::class,
  92. $user->resetPassword()
  93. );
  94. }
  95. /**
  96. * @test
  97. */
  98. public function test_delete_removes_user_data()
  99. {
  100. Artisan::call('passport:install', [
  101. '--verbose' => 2,
  102. '--no-interaction' => 1
  103. ]);
  104. $user = User::factory()->create();
  105. TwoFAccount::factory()->for($user)->create();
  106. AuthLog::factory()->for($user, 'authenticatable')->create();
  107. Group::factory()->for($user)->create();
  108. DB::table('webauthn_credentials')->insert([
  109. 'id' => '-VOLFKPY-_FuMI_sJ7gMllK76L3VoRUINj6lL_Z3qDg',
  110. 'authenticatable_type' => \App\Models\User::class,
  111. 'authenticatable_id' => $user->id,
  112. 'user_id' => 'e8af6f703f8042aa91c30cf72289aa07',
  113. 'counter' => 0,
  114. 'rp_id' => 'http://localhost',
  115. 'origin' => 'http://localhost',
  116. 'aaguid' => '00000000-0000-0000-0000-000000000000',
  117. 'attestation_format' => 'none',
  118. 'public_key' => 'eyJpdiI6Imp0U0NVeFNNbW45KzEvMXpad2p2SUE9PSIsInZhbHVlIjoic0VxZ2I1WnlHM2lJakhkWHVkK2kzMWtibk1IN2ZlaExGT01qOElXMDdRTjhnVlR0TDgwOHk1S0xQUy9BQ1JCWHRLNzRtenNsMml1dVQydWtERjFEU0h0bkJGT2RwUXE1M1JCcVpablE2Y2VGV2YvVEE2RGFIRUE5L0x1K0JIQXhLVE1aNVNmN3AxeHdjRUo2V0hwREZSRTJYaThNNnB1VnozMlVXZEVPajhBL3d3ODlkTVN3bW54RTEwSG0ybzRQZFFNNEFrVytUYThub2IvMFRtUlBZamoyZElWKzR1bStZQ1IwU3FXbkYvSm1FU2FlMTFXYUo0SG9kc1BDME9CNUNKeE9IelE5d2dmNFNJRXBKNUdlVzJ3VHUrQWJZRFluK0hib0xvVTdWQ0ZISjZmOWF3by83aVJES1dxbU9Zd1lhRTlLVmhZSUdlWmlBOUFtcTM2ZVBaRWNKNEFSQUhENk5EaC9hN3REdnVFbm16WkRxekRWOXd4cVcvZFdKa2tlWWJqZWlmZnZLS0F1VEVCZEZQcXJkTExiNWRyQmxsZWtaSDRlT3VVS0ZBSXFBRG1JMjRUMnBKRXZxOUFUa2xxMjg2TEplUzdscVo2UytoVU5SdXk1OE1lcFN6aU05ZkVXTkdIM2tKM3Q5bmx1TGtYb1F5bGxxQVR3K3BVUVlia1VybDFKRm9lZDViNzYraGJRdmtUb2FNTEVGZmZYZ3lYRDRiOUVjRnJpcTVvWVExOHJHSTJpMnVBZ3E0TmljbUlKUUtXY2lSWDh1dE5MVDNRUzVRSkQrTjVJUU8rSGhpeFhRRjJvSEdQYjBoVT0iLCJtYWMiOiI5MTdmNWRkZGE5OTEwNzQ3MjhkYWVhYjRlNjk0MWZlMmI5OTQ4YzlmZWI1M2I4OGVkMjE1MjMxNjUwOWRmZTU2IiwidGFnIjoiIn0=',
  119. 'updated_at' => now(),
  120. 'created_at' => now(),
  121. ]);
  122. $user->createToken('myToken', []);
  123. Password::broker('webauthn')->createToken($user);
  124. Password::broker()->createToken($user);
  125. $user->delete();
  126. $this->assertDatabaseMissing('twofaccounts', [
  127. 'user_id' => $user->id,
  128. ]);
  129. $this->assertDatabaseMissing('groups', [
  130. 'user_id' => $user->id,
  131. ]);
  132. $this->assertDatabaseMissing('webauthn_credentials', [
  133. 'authenticatable_id' => $user->id,
  134. ]);
  135. $this->assertDatabaseMissing(config('auth.passwords.webauthn.table'), [
  136. 'email' => $user->email,
  137. ]);
  138. $this->assertDatabaseMissing('oauth_access_tokens', [
  139. 'user_id' => $user->id,
  140. ]);
  141. $this->assertDatabaseMissing(config('auth.passwords.users.table'), [
  142. 'email' => $user->email,
  143. ]);
  144. $this->assertDatabaseMissing('auth_logs', [
  145. 'authenticatable_id' => $user->id,
  146. ]);
  147. }
  148. /**
  149. * @test
  150. */
  151. public function test_delete_flushes_icons_of_user_twofaccounts()
  152. {
  153. Storage::fake('icons');
  154. $user = User::factory()->create();
  155. $twofaccount = TwoFAccount::factory()->for($user)->create();
  156. $twofaccount->setIcon(base64_decode(OtpTestData::ICON_PNG_DATA), 'png');
  157. $twofaccount->save();
  158. Storage::disk('icons')->assertExists($twofaccount->icon);
  159. $user->delete();
  160. Storage::disk('icons')->assertMissing($twofaccount->icon);
  161. }
  162. /**
  163. * @test
  164. */
  165. public function test_delete_does_not_delete_the_only_admin()
  166. {
  167. $admin = User::factory()->administrator()->create();
  168. $this->assertEquals(1, User::admins()->count());
  169. $isDeleted = $admin->delete();
  170. $this->assertFalse($isDeleted);
  171. }
  172. }