2016-07-31 00:26:49 +03:00
|
|
|
<?php
|
2017-10-12 11:13:20 +03:00
|
|
|
declare(strict_types=1);
|
|
|
|
|
2016-07-31 00:26:49 +03:00
|
|
|
namespace ShlinkioTest\Shlink\Rest\Middleware;
|
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
use Exception;
|
|
|
|
use Fig\Http\Message\RequestMethodInterface;
|
2017-03-24 22:34:18 +03:00
|
|
|
use PHPUnit\Framework\TestCase;
|
2018-09-28 23:08:01 +03:00
|
|
|
use Prophecy\Argument;
|
2016-07-31 00:26:49 +03:00
|
|
|
use Prophecy\Prophecy\ObjectProphecy;
|
2018-09-28 23:08:01 +03:00
|
|
|
use Psr\Container\ContainerExceptionInterface;
|
|
|
|
use Psr\Http\Message\ResponseInterface;
|
|
|
|
use Psr\Http\Message\ServerRequestInterface;
|
|
|
|
use Psr\Http\Server\MiddlewareInterface;
|
2018-03-26 20:02:41 +03:00
|
|
|
use Psr\Http\Server\RequestHandlerInterface;
|
2017-07-07 14:12:45 +03:00
|
|
|
use Shlinkio\Shlink\Rest\Action\AuthenticateAction;
|
2018-09-28 23:08:01 +03:00
|
|
|
use Shlinkio\Shlink\Rest\Authentication\Plugin\AuthenticationPluginInterface;
|
2018-09-29 09:16:40 +03:00
|
|
|
use Shlinkio\Shlink\Rest\Authentication\RequestToHttpAuthPlugin;
|
|
|
|
use Shlinkio\Shlink\Rest\Authentication\RequestToHttpAuthPluginInterface;
|
2018-09-28 23:08:01 +03:00
|
|
|
use Shlinkio\Shlink\Rest\Exception\NoAuthenticationException;
|
|
|
|
use Shlinkio\Shlink\Rest\Exception\VerifyAuthenticationException;
|
2018-09-24 20:24:23 +03:00
|
|
|
use Shlinkio\Shlink\Rest\Middleware\AuthenticationMiddleware;
|
2018-09-28 23:08:01 +03:00
|
|
|
use Shlinkio\Shlink\Rest\Util\RestUtils;
|
2016-07-31 00:26:49 +03:00
|
|
|
use Zend\Diactoros\Response;
|
2018-12-26 01:01:30 +03:00
|
|
|
use Zend\Diactoros\ServerRequest;
|
2017-03-24 23:38:43 +03:00
|
|
|
use Zend\Expressive\Router\Route;
|
2016-07-31 00:26:49 +03:00
|
|
|
use Zend\Expressive\Router\RouteResult;
|
2018-09-28 23:08:01 +03:00
|
|
|
use function implode;
|
|
|
|
use function sprintf;
|
2018-03-21 03:05:55 +03:00
|
|
|
use function Zend\Stratigility\middleware;
|
|
|
|
|
2018-09-24 20:24:23 +03:00
|
|
|
class AuthenticationMiddlewareTest extends TestCase
|
2016-07-31 00:26:49 +03:00
|
|
|
{
|
2018-11-20 21:30:27 +03:00
|
|
|
/** @var AuthenticationMiddleware */
|
2018-11-20 21:37:22 +03:00
|
|
|
private $middleware;
|
2018-11-20 21:30:27 +03:00
|
|
|
/** @var ObjectProphecy */
|
2018-11-20 21:37:22 +03:00
|
|
|
private $requestToPlugin;
|
2016-07-31 00:26:49 +03:00
|
|
|
|
2018-11-20 21:30:27 +03:00
|
|
|
/** @var callable */
|
2018-11-20 21:37:22 +03:00
|
|
|
private $dummyMiddleware;
|
2018-03-21 13:13:03 +03:00
|
|
|
|
2016-07-31 00:26:49 +03:00
|
|
|
public function setUp()
|
|
|
|
{
|
2018-09-29 09:16:40 +03:00
|
|
|
$this->requestToPlugin = $this->prophesize(RequestToHttpAuthPluginInterface::class);
|
2018-11-18 18:28:04 +03:00
|
|
|
$this->middleware = new AuthenticationMiddleware($this->requestToPlugin->reveal(), [AuthenticateAction::class]);
|
2016-07-31 00:26:49 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @test
|
2018-09-28 23:08:01 +03:00
|
|
|
* @dataProvider provideWhitelistedRequests
|
2016-07-31 00:26:49 +03:00
|
|
|
*/
|
2018-09-28 23:08:01 +03:00
|
|
|
public function someWhiteListedSituationsFallbackToNextMiddleware(ServerRequestInterface $request)
|
2016-07-31 00:26:49 +03:00
|
|
|
{
|
2018-09-28 23:08:01 +03:00
|
|
|
$handler = $this->prophesize(RequestHandlerInterface::class);
|
|
|
|
$handle = $handler->handle($request)->willReturn(new Response());
|
2018-09-29 09:16:40 +03:00
|
|
|
$fromRequest = $this->requestToPlugin->fromRequest(Argument::any())->willReturn(
|
2018-09-28 23:08:01 +03:00
|
|
|
$this->prophesize(AuthenticationPluginInterface::class)->reveal()
|
2016-07-31 00:26:49 +03:00
|
|
|
);
|
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
$this->middleware->process($request, $handler->reveal());
|
2016-07-31 00:26:49 +03:00
|
|
|
|
2018-11-11 15:18:21 +03:00
|
|
|
$handle->shouldHaveBeenCalledOnce();
|
2018-09-28 23:08:01 +03:00
|
|
|
$fromRequest->shouldNotHaveBeenCalled();
|
2016-07-31 00:26:49 +03:00
|
|
|
}
|
2016-07-31 14:01:08 +03:00
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
public function provideWhitelistedRequests(): array
|
2016-07-31 14:01:08 +03:00
|
|
|
{
|
2018-09-28 23:08:01 +03:00
|
|
|
$dummyMiddleware = $this->getDummyMiddleware();
|
|
|
|
|
|
|
|
return [
|
2018-12-26 01:01:30 +03:00
|
|
|
'with no route result' => [new ServerRequest()],
|
|
|
|
'with failure route result' => [(new ServerRequest())->withAttribute(
|
2018-09-28 23:08:01 +03:00
|
|
|
RouteResult::class,
|
|
|
|
RouteResult::fromRouteFailure([RequestMethodInterface::METHOD_GET])
|
|
|
|
)],
|
2018-12-26 01:01:30 +03:00
|
|
|
'with whitelisted route' => [(new ServerRequest())->withAttribute(
|
2018-09-28 23:08:01 +03:00
|
|
|
RouteResult::class,
|
|
|
|
RouteResult::fromRoute(
|
|
|
|
new Route('foo', $dummyMiddleware, Route::HTTP_METHOD_ANY, AuthenticateAction::class)
|
|
|
|
)
|
|
|
|
)],
|
2018-12-26 01:01:30 +03:00
|
|
|
'with OPTIONS method' => [(new ServerRequest())->withAttribute(
|
2018-09-28 23:08:01 +03:00
|
|
|
RouteResult::class,
|
|
|
|
RouteResult::fromRoute(new Route('bar', $dummyMiddleware), [])
|
|
|
|
)->withMethod(RequestMethodInterface::METHOD_OPTIONS)],
|
|
|
|
];
|
2016-07-31 14:01:08 +03:00
|
|
|
}
|
|
|
|
|
2016-08-07 20:53:14 +03:00
|
|
|
/**
|
|
|
|
* @test
|
2018-09-28 23:08:01 +03:00
|
|
|
* @dataProvider provideExceptions
|
2016-08-07 20:53:14 +03:00
|
|
|
*/
|
2018-09-28 23:08:01 +03:00
|
|
|
public function errorIsReturnedWhenNoValidAuthIsProvided($e)
|
2016-08-07 20:53:14 +03:00
|
|
|
{
|
2018-12-26 01:01:30 +03:00
|
|
|
$request = (new ServerRequest())->withAttribute(
|
2016-08-07 20:53:14 +03:00
|
|
|
RouteResult::class,
|
2018-09-28 23:08:01 +03:00
|
|
|
RouteResult::fromRoute(new Route('bar', $this->getDummyMiddleware()), [])
|
2018-09-29 09:16:40 +03:00
|
|
|
);
|
|
|
|
$fromRequest = $this->requestToPlugin->fromRequest(Argument::any())->willThrow($e);
|
2018-09-28 23:08:01 +03:00
|
|
|
|
|
|
|
/** @var Response\JsonResponse $response */
|
|
|
|
$response = $this->middleware->process($request, $this->prophesize(RequestHandlerInterface::class)->reveal());
|
|
|
|
$payload = $response->getPayload();
|
|
|
|
|
|
|
|
$this->assertEquals(RestUtils::INVALID_AUTHORIZATION_ERROR, $payload['error']);
|
|
|
|
$this->assertEquals(sprintf(
|
|
|
|
'Expected one of the following authentication headers, but none were provided, ["%s"]',
|
2018-09-29 09:16:40 +03:00
|
|
|
implode('", "', RequestToHttpAuthPlugin::SUPPORTED_AUTH_HEADERS)
|
2018-09-28 23:08:01 +03:00
|
|
|
), $payload['message']);
|
2018-11-11 15:18:21 +03:00
|
|
|
$fromRequest->shouldHaveBeenCalledOnce();
|
2018-09-28 23:08:01 +03:00
|
|
|
}
|
2016-08-07 20:53:14 +03:00
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
public function provideExceptions(): array
|
|
|
|
{
|
|
|
|
return [
|
|
|
|
[new class extends Exception implements ContainerExceptionInterface {
|
|
|
|
}],
|
|
|
|
[NoAuthenticationException::fromExpectedTypes([])],
|
|
|
|
];
|
2016-08-07 20:53:14 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @test
|
|
|
|
*/
|
2018-09-28 23:08:01 +03:00
|
|
|
public function errorIsReturnedWhenVerificationFails()
|
2016-08-07 20:53:14 +03:00
|
|
|
{
|
2018-12-26 01:01:30 +03:00
|
|
|
$request = (new ServerRequest())->withAttribute(
|
2016-08-07 20:53:14 +03:00
|
|
|
RouteResult::class,
|
2018-09-28 23:08:01 +03:00
|
|
|
RouteResult::fromRoute(new Route('bar', $this->getDummyMiddleware()), [])
|
2018-09-29 09:16:40 +03:00
|
|
|
);
|
2018-09-28 23:08:01 +03:00
|
|
|
$plugin = $this->prophesize(AuthenticationPluginInterface::class);
|
2017-03-25 11:37:13 +03:00
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
$verify = $plugin->verify($request)->willThrow(
|
|
|
|
VerifyAuthenticationException::withError('the_error', 'the_message')
|
2016-08-07 20:53:14 +03:00
|
|
|
);
|
2018-09-29 09:16:40 +03:00
|
|
|
$fromRequest = $this->requestToPlugin->fromRequest(Argument::any())->willReturn($plugin->reveal());
|
2018-09-28 23:08:01 +03:00
|
|
|
|
|
|
|
/** @var Response\JsonResponse $response */
|
|
|
|
$response = $this->middleware->process($request, $this->prophesize(RequestHandlerInterface::class)->reveal());
|
|
|
|
$payload = $response->getPayload();
|
|
|
|
|
|
|
|
$this->assertEquals('the_error', $payload['error']);
|
|
|
|
$this->assertEquals('the_message', $payload['message']);
|
2018-11-11 15:18:21 +03:00
|
|
|
$verify->shouldHaveBeenCalledOnce();
|
|
|
|
$fromRequest->shouldHaveBeenCalledOnce();
|
2016-08-07 20:53:14 +03:00
|
|
|
}
|
|
|
|
|
2016-07-31 14:01:08 +03:00
|
|
|
/**
|
|
|
|
* @test
|
|
|
|
*/
|
2018-09-28 23:08:01 +03:00
|
|
|
public function updatedResponseIsReturnedWhenVerificationPasses()
|
2016-07-31 14:01:08 +03:00
|
|
|
{
|
2018-09-28 23:08:01 +03:00
|
|
|
$newResponse = new Response();
|
2018-12-26 01:01:30 +03:00
|
|
|
$request = (new ServerRequest())->withAttribute(
|
2016-07-31 14:01:08 +03:00
|
|
|
RouteResult::class,
|
2018-09-28 23:08:01 +03:00
|
|
|
RouteResult::fromRoute(new Route('bar', $this->getDummyMiddleware()), [])
|
2018-09-29 09:16:40 +03:00
|
|
|
);
|
2018-09-28 23:08:01 +03:00
|
|
|
$plugin = $this->prophesize(AuthenticationPluginInterface::class);
|
2016-07-31 14:01:08 +03:00
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
$verify = $plugin->verify($request)->will(function () {
|
|
|
|
});
|
|
|
|
$update = $plugin->update($request, Argument::type(ResponseInterface::class))->willReturn($newResponse);
|
2018-09-29 09:16:40 +03:00
|
|
|
$fromRequest = $this->requestToPlugin->fromRequest(Argument::any())->willReturn($plugin->reveal());
|
2018-09-28 23:08:01 +03:00
|
|
|
|
|
|
|
$handler = $this->prophesize(RequestHandlerInterface::class);
|
|
|
|
$handle = $handler->handle($request)->willReturn(new Response());
|
|
|
|
$response = $this->middleware->process($request, $handler->reveal());
|
|
|
|
|
|
|
|
$this->assertSame($response, $newResponse);
|
2018-11-11 15:18:21 +03:00
|
|
|
$verify->shouldHaveBeenCalledOnce();
|
|
|
|
$update->shouldHaveBeenCalledOnce();
|
|
|
|
$handle->shouldHaveBeenCalledOnce();
|
|
|
|
$fromRequest->shouldHaveBeenCalledOnce();
|
2016-07-31 14:01:08 +03:00
|
|
|
}
|
|
|
|
|
2018-09-28 23:08:01 +03:00
|
|
|
private function getDummyMiddleware(): MiddlewareInterface
|
2016-07-31 14:01:08 +03:00
|
|
|
{
|
2018-09-28 23:08:01 +03:00
|
|
|
return middleware(function () {
|
|
|
|
return new Response\EmptyResponse();
|
|
|
|
});
|
2016-07-31 14:01:08 +03:00
|
|
|
}
|
2016-07-31 00:26:49 +03:00
|
|
|
}
|