tests: add test cases for non-admin actions to admin resources

This commit is contained in:
Saw-jan
2024-07-18 17:43:16 +05:45
parent 81ef018b9f
commit dd8a3eb3d2
15 changed files with 273 additions and 48 deletions
@@ -33,9 +33,9 @@ The expected failures in this file are from features in the owncloud/ocis repo.
- [apiAccountsHashDifficulty/assignRole.feature:27](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiAccountsHashDifficulty/assignRole.feature#L27) - [apiAccountsHashDifficulty/assignRole.feature:27](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiAccountsHashDifficulty/assignRole.feature#L27)
- [apiAccountsHashDifficulty/assignRole.feature:28](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiAccountsHashDifficulty/assignRole.feature#L28) - [apiAccountsHashDifficulty/assignRole.feature:28](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiAccountsHashDifficulty/assignRole.feature#L28)
- [apiGraph/assignRole.feature:30](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraph/assignRole.feature#L30) - [apiGraph/getAssignedRole.feature:31](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraph/getAssignedRole.feature#L31)
- [apiGraph/assignRole.feature:31](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraph/assignRole.feature#L31) - [apiGraph/getAssignedRole.feature:32](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraph/getAssignedRole.feature#L32)
- [apiGraph/assignRole.feature:32](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraph/assignRole.feature#L32) - [apiGraph/getAssignedRole.feature:33](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraph/getAssignedRole.feature#L33)
#### [A User can get information of another user with Graph API](https://github.com/owncloud/ocis/issues/5125) #### [A User can get information of another user with Graph API](https://github.com/owncloud/ocis/issues/5125)
@@ -63,31 +63,34 @@ The expected failures in this file are from features in the owncloud/ocis repo.
- [apiGraphUserGroup/getUser.feature:646](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L646) - [apiGraphUserGroup/getUser.feature:646](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L646)
- [apiGraphUserGroup/getUser.feature:647](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L647) - [apiGraphUserGroup/getUser.feature:647](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L647)
- [apiGraphUserGroup/getUser.feature:648](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L648) - [apiGraphUserGroup/getUser.feature:648](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L648)
- [apiGraphUserGroup/getUser.feature:663](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L663)
- [apiGraphUserGroup/getUser.feature:664](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L664)
- [apiGraphUserGroup/getUser.feature:665](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getUser.feature#L665)
#### [Normal user can get expanded members information of a group](https://github.com/owncloud/ocis/issues/5604) #### [Normal user can get expanded members information of a group](https://github.com/owncloud/ocis/issues/5604)
- [apiGraphUserGroup/getGroup.feature:399](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L399) - [apiGraphUserGroup/getGroup.feature:399](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L399)
- [apiGraphUserGroup/getGroup.feature:400](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L400) - [apiGraphUserGroup/getGroup.feature:400](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L400)
- [apiGraphUserGroup/getGroup.feature:401](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L401) - [apiGraphUserGroup/getGroup.feature:401](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L401)
- [apiGraphUserGroup/getGroup.feature:460](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L460)
- [apiGraphUserGroup/getGroup.feature:461](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L461)
- [apiGraphUserGroup/getGroup.feature:462](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L462)
- [apiGraphUserGroup/getGroup.feature:508](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L508)
- [apiGraphUserGroup/getGroup.feature:509](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L509)
- [apiGraphUserGroup/getGroup.feature:510](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/getGroup.feature#L510)
#### [Same users can be added in a group multiple time](https://github.com/owncloud/ocis/issues/5702) #### [Same users can be added in a group multiple time](https://github.com/owncloud/ocis/issues/5702)
- [apiGraphUserGroup/addUserToGroup.feature:289](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L289) - [apiGraphUserGroup/addUserToGroup.feature:295](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L295)
#### [API requests for a non-existent resources should return 404](https://github.com/owncloud/ocis/issues/5939)
- [apiGraphUserGroup/addUserToGroup.feature:205](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L205)
- [apiGraphUserGroup/addUserToGroup.feature:206](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L206)
- [apiGraphUserGroup/addUserToGroup.feature:207](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L207)
### [Users are added in a group with wrong host in host-part of user](https://github.com/owncloud/ocis/issues/5871) ### [Users are added in a group with wrong host in host-part of user](https://github.com/owncloud/ocis/issues/5871)
- [apiGraphUserGroup/addUserToGroup.feature:373](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L373) - [apiGraphUserGroup/addUserToGroup.feature:379](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L379)
- [apiGraphUserGroup/addUserToGroup.feature:387](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L387) - [apiGraphUserGroup/addUserToGroup.feature:393](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L393)
### [Adding the same user as multiple members in a single request results in listing the same user twice in the group](https://github.com/owncloud/ocis/issues/5855) ### [Adding the same user as multiple members in a single request results in listing the same user twice in the group](https://github.com/owncloud/ocis/issues/5855)
- [apiGraphUserGroup/addUserToGroup.feature:424](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L424) - [apiGraphUserGroup/addUserToGroup.feature:430](https://github.com/owncloud/ocis/blob/master/tests/acceptance/features/apiGraphUserGroup/addUserToGroup.feature#L430)
### [Shared file locking is not possible using different path](https://github.com/owncloud/ocis/issues/7599) ### [Shared file locking is not possible using different path](https://github.com/owncloud/ocis/issues/7599)
@@ -58,3 +58,15 @@ Feature: change role
| Space Admin | | Space Admin |
| User | | User |
| User Light | | User Light |
Scenario Outline: non-admin user tries to change the role of nonexistent user
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
And user "Brian" has been created with default attributes and without skeleton files
When user "Alice" tries to change the role of user "nonexistent" to role "Admin" using the Graph API
Then the HTTP status code should be "403"
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
@@ -3,10 +3,12 @@ Feature: assign role
I want to assign roles to users. I want to assign roles to users.
So that users without an admin role cannot get the list of roles, assignments list and assign roles to users So that users without an admin role cannot get the list of roles, assignments list and assign roles to users
Background:
Scenario Outline: assign role to the user using graph api
Given user "Alice" has been created with default attributes and without skeleton files Given user "Alice" has been created with default attributes and without skeleton files
And the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
Scenario Outline: get assigned role of a user
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When the administrator retrieves the assigned role of user "Alice" using the Graph API When the administrator retrieves the assigned role of user "Alice" using the Graph API
Then the HTTP status code should be "200" Then the HTTP status code should be "200"
And the Graph API response should have the role "<user-role>" And the Graph API response should have the role "<user-role>"
@@ -18,9 +20,8 @@ Feature: assign role
| User Light | | User Light |
@issue-5032 @issue-5032
Scenario Outline: assign role to the user with graph api and list role with setting api Scenario Outline: get assigned role of a user via setting api
Given user "Alice" has been created with default attributes and without skeleton files Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
And the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" tries to get list of assignment When user "Alice" tries to get list of assignment
Then the HTTP status code should be "<http-status-code>" Then the HTTP status code should be "<http-status-code>"
And the setting API response should have the role "<user-role>" And the setting API response should have the role "<user-role>"
@@ -32,9 +33,8 @@ Feature: assign role
| User Light | 401 | | User Light | 401 |
Scenario Outline: assign role to the user with setting api and list role with graph api Scenario Outline: get role of a user assigned via setting api
Given user "Alice" has been created with default attributes and without skeleton files Given the administrator has given "Alice" the role "<user-role>" using the settings api
And the administrator has given "Alice" the role "<user-role>" using the settings api
When the administrator retrieves the assigned role of user "Alice" using the Graph API When the administrator retrieves the assigned role of user "Alice" using the Graph API
Then the HTTP status code should be "200" Then the HTTP status code should be "200"
And the Graph API response should have the role "<user-role>" And the Graph API response should have the role "<user-role>"
@@ -44,3 +44,15 @@ Feature: assign role
| Space Admin | | Space Admin |
| User | | User |
| User Light | | User Light |
Scenario: non-admin user tries to get assigned role of another user
Given user "Brian" has been created with default attributes and without skeleton files
When user "Alice" tries to get the assigned role of user "Brian" using the Graph API
Then the HTTP status code should be "403"
Scenario: non-admin user tries to get assigned role of nonexistent user
Given user "Brian" has been created with default attributes and without skeleton files
When user "Alice" tries to get the assigned role of user "nonexistent" using the Graph API
Then the HTTP status code should be "403"
@@ -29,3 +29,15 @@ Feature: unassign user role
When user "Alice" tries to unassign the role of user "Alice" using the Graph API When user "Alice" tries to unassign the role of user "Alice" using the Graph API
Then the HTTP status code should be "403" Then the HTTP status code should be "403"
And user "Alice" should have the role "Admin" assigned And user "Alice" should have the role "Admin" assigned
Scenario: non-admin user tries to unassign role of another user
Given user "Brian" has been created with default attributes and without skeleton files
When user "Alice" tries to unassign the role of user "Brian" using the Graph API
Then the HTTP status code should be "403"
And user "Brian" should have the role "User" assigned
Scenario: non-admin user tries to unassign role of nonexistent user
When user "Alice" tries to unassign the role of user "nonexistent" using the Graph API
Then the HTTP status code should be "403"
@@ -198,8 +198,8 @@ Feature: add users to group
Scenario Outline: user other than the admin tries to add user to a nonexistent group Scenario Outline: user other than the admin tries to add user to a nonexistent group
Given user "Brian" has been created with default attributes and without skeleton files Given user "Brian" has been created with default attributes and without skeleton files
And the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API And the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When the user "Alice" tries to add user "Brian" to a nonexistent group using the Graph API When user "Alice" tries to add user "Brian" to a nonexistent group using the Graph API
Then the HTTP status code should be "404" Then the HTTP status code should be "403"
Examples: Examples:
| user-role | | user-role |
| Space Admin | | Space Admin |
@@ -213,6 +213,12 @@ Feature: add users to group
Then the HTTP status code should be "404" Then the HTTP status code should be "404"
Scenario: non-admin user tries to add a nonexistent user to a group
Given group "groupA" has been created
When user "Alice" tries to add nonexistent user to group "groupA" using the Graph API
Then the HTTP status code should be "403"
Scenario: admin tries to add user to a group without sending the group Scenario: admin tries to add user to a group without sending the group
When the administrator tries to add user "Alice" to a nonexistent group using the Graph API When the administrator tries to add user "Alice" to a nonexistent group using the Graph API
Then the HTTP status code should be "404" Then the HTTP status code should be "404"
@@ -49,6 +49,11 @@ Feature: delete groups
| 50%2Eagle | %2E literal looks like an escaped "." | | 50%2Eagle | %2E literal looks like an escaped "." |
| 50%2Fix | %2F literal looks like an escaped slash | | 50%2Fix | %2F literal looks like an escaped slash |
Scenario: admin user tries to delete nonexistent group
When user "Alice" tries to delete group "nonexistent" using the Graph API
Then the HTTP status code should be "404"
@issue-5938 @issue-5938
Scenario Outline: user other than the admin can't delete a group Scenario Outline: user other than the admin can't delete a group
Given user "Brian" has been created with default attributes and without skeleton files Given user "Brian" has been created with default attributes and without skeleton files
@@ -63,6 +68,17 @@ Feature: delete groups
| User | | User |
| User Light | | User Light |
Scenario Outline: non-admin user tries to delete nonexistent group
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" tries to delete group "nonexistent" using the Graph API
Then the HTTP status code should be "403"
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
@issue-903 @issue-903
Scenario: deleted group should not be listed in the sharees list Scenario: deleted group should not be listed in the sharees list
Given group "grp1" has been created Given group "grp1" has been created
@@ -40,3 +40,15 @@ Feature: edit group name
When user "Alice" tries to rename a nonexistent group to "grp1" using the Graph API When user "Alice" tries to rename a nonexistent group to "grp1" using the Graph API
Then the HTTP status code should be "404" Then the HTTP status code should be "404"
And group "grp1" should not exist And group "grp1" should not exist
Scenario Outline: non-admin user tries to rename nonexistent group
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" tries to rename a nonexistent group to "grp1" using the Graph API
Then the HTTP status code should be "403"
And group "grp1" should not exist
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
@@ -120,6 +120,22 @@ Feature: edit user
| displayName with characters | *:!;_+-&#(?) | *:!;_+-&#(?) | | displayName with characters | *:!;_+-&#(?) | *:!;_+-&#(?) |
Scenario: admin user tries to edit nonexistent user's name
When the user "Alice" tries to change the user name of user "nonexistent" to "newusername" using the Graph API
Then the HTTP status code should be "404"
Scenario Outline: non-admin user tries to edit nonexistent user's name
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When the user "Alice" tries to change the user name of user "nonexistent" to "newusername" using the Graph API
Then the HTTP status code should be "403"
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
Scenario Outline: normal user should not be able to change his/her own display name Scenario Outline: normal user should not be able to change his/her own display name
Given the administrator has assigned the role "<user-role>" to user "Brian" using the Graph API Given the administrator has assigned the role "<user-role>" to user "Brian" using the Graph API
When the user "Brian" tries to change the display name of user "Brian" to "Brian Murphy" using the Graph API When the user "Brian" tries to change the display name of user "Brian" to "Brian Murphy" using the Graph API
@@ -387,7 +387,7 @@ Feature: get groups and their members
"properties": { "properties": {
"message": { "message": {
"type": "string", "type": "string",
"enum": ["Unauthorized"] "enum": ["Forbidden"]
} }
} }
} }
@@ -401,7 +401,7 @@ Feature: get groups and their members
| User Light | | User Light |
Scenario: get details of a group Scenario: admin user gets details of a group
Given group "tea-lover" has been created Given group "tea-lover" has been created
When user "Alice" gets details of the group "tea-lover" using the Graph API When user "Alice" gets details of the group "tea-lover" using the Graph API
Then the HTTP status code should be "200" Then the HTTP status code should be "200"
@@ -426,6 +426,41 @@ Feature: get groups and their members
} }
""" """
@issue-5604
Scenario Outline: non-admin user tries to get details of a group
Given group "tea-lover" has been created
And the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" gets details of the group "tea-lover" using the Graph API
Then the HTTP status code should be "403"
And the JSON data of the response should match
"""
{
"type": "object",
"required": [
"error"
],
"properties": {
"error": {
"type": "object",
"required": [
"message"
],
"properties": {
"message": {
"type": "string",
"enum": ["Forbidden"]
}
}
}
}
}
"""
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
Scenario Outline: get details of group with UTF-8 characters name Scenario Outline: get details of group with UTF-8 characters name
Given group "<group>" has been created Given group "<group>" has been created
@@ -463,6 +498,17 @@ Feature: get groups and their members
When user "Alice" gets details of the group "non-existing" using the Graph API When user "Alice" gets details of the group "non-existing" using the Graph API
Then the HTTP status code should be "404" Then the HTTP status code should be "404"
@issue-5604
Scenario Outline: non-admin user tries to get group information of non-existing group
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" gets details of the group "non-existing" using the Graph API
Then the HTTP status code should be "403"
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
Scenario Outline: non-admin user searches for a group by group name Scenario Outline: non-admin user searches for a group by group name
Given these users have been created with default attributes and without skeleton files: Given these users have been created with default attributes and without skeleton files:
@@ -55,7 +55,7 @@ Feature: get users
Given the administrator has assigned the role "<user-role-2>" to user "Alice" using the Graph API Given the administrator has assigned the role "<user-role-2>" to user "Alice" using the Graph API
And the administrator has assigned the role "<user-role>" to user "Brian" using the Graph API And the administrator has assigned the role "<user-role>" to user "Brian" using the Graph API
When user "Brian" tries to get information of user "Alice" using Graph API When user "Brian" tries to get information of user "Alice" using Graph API
Then the HTTP status code should be "401" Then the HTTP status code should be "403"
And the JSON data of the response should match And the JSON data of the response should match
""" """
{ {
@@ -72,7 +72,7 @@ Feature: get users
"properties": { "properties": {
"message": { "message": {
"type": "string", "type": "string",
"const": "Unauthorized" "const": "Forbidden"
} }
} }
} }
@@ -608,7 +608,7 @@ Feature: get users
And group "coffee-lover" has been created And group "coffee-lover" has been created
And user "Brian" has been added to group "coffee-lover" And user "Brian" has been added to group "coffee-lover"
When the user "Alice" gets user "Brian" along with his group information using Graph API When the user "Alice" gets user "Brian" along with his group information using Graph API
Then the HTTP status code should be "401" Then the HTTP status code should be "403"
And the JSON data of the response should match And the JSON data of the response should match
""" """
{ {
@@ -625,7 +625,7 @@ Feature: get users
"properties": { "properties": {
"message": { "message": {
"type": "string", "type": "string",
"const": "Unauthorized" "const": "Forbidden"
} }
} }
} }
@@ -648,6 +648,23 @@ Feature: get users
| User Light | Admin | | User Light | Admin |
Scenario: admin user tries to get the information of nonexistent user
Given the administrator has assigned the role "Admin" to user "Alice" using the Graph API
When user "Alice" tries to get information of user "nonexistent" using Graph API
Then the HTTP status code should be "404"
@issue-5125
Scenario Outline: non-admin user tries to get the information of nonexistent user
Given the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" tries to get information of user "nonexistent" using Graph API
Then the HTTP status code should be "403"
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
Scenario: admin user gets all users of certain groups Scenario: admin user gets all users of certain groups
Given the administrator has assigned the role "Admin" to user "Alice" using the Graph API Given the administrator has assigned the role "Admin" to user "Alice" using the Graph API
And user "Carol" has been created with default attributes and without skeleton files And user "Carol" has been created with default attributes and without skeleton files
@@ -155,6 +155,18 @@ Feature: remove a user from a group
When the administrator tries to remove user "Alice" from a nonexistent group using the Graph API When the administrator tries to remove user "Alice" from a nonexistent group using the Graph API
Then the HTTP status code should be "404" Then the HTTP status code should be "404"
Scenario Outline: non-admin user tries to remove a user from a nonexistent group
Given user "Brian" has been created with default attributes and without skeleton files
And the administrator has assigned the role "<user-role>" to user "Alice" using the Graph API
When user "Alice" tries to remove user "Brian" from a nonexistent group using the Graph API
Then the HTTP status code should be "403"
Examples:
| user-role |
| Space Admin |
| User |
| User Light |
@issue-5938 @issue-5938
Scenario Outline: user other than the admin can't remove a user from their group Scenario Outline: user other than the admin can't remove a user from their group
Given user "Brian" has been created with default attributes and without skeleton files Given user "Brian" has been created with default attributes and without skeleton files
@@ -114,7 +114,17 @@ Feature: Disabling and deleting space
| Space Admin | | Space Admin |
Scenario Outline: user with role user and user light cannot delete others disabled space via the Graph API Scenario Outline: user with role user and user light cannot disable space
Given the administrator has assigned the role "<user-role>" to user "Carol" using the Graph API
When user "Carol" tries to delete a space "Project Moon" owned by user "Alice"
Then the HTTP status code should be "404"
Examples:
| user-role |
| User |
| User Light |
Scenario Outline: user with role user and user light cannot delete others disabled space
Given the administrator has assigned the role "<user-role>" to user "Carol" using the Graph API Given the administrator has assigned the role "<user-role>" to user "Carol" using the Graph API
And user "Alice" has disabled a space "Project Moon" And user "Alice" has disabled a space "Project Moon"
When user "Carol" tries to delete a space "Project Moon" owned by user "Alice" When user "Carol" tries to delete a space "Project Moon" owned by user "Alice"
@@ -123,3 +133,23 @@ Feature: Disabling and deleting space
| user-role | | user-role |
| User | | User |
| User Light | | User Light |
Scenario Outline: viewer and space editor cannot disable space
When user "<user>" tries to disable a space "Project Moon" owned by user "Alice"
Then the HTTP status code should be "404"
And the user "<user>" should have a space called "Project Moon"
Examples:
| user |
| Brian |
| Bob |
Scenario Outline: viewer and space editor cannot delete disabled space
Given user "Alice" has disabled a space "Project Moon"
When user "<user>" tries to delete a space "Project Moon" owned by user "Alice"
Then the HTTP status code should be "404"
Examples:
| user |
| Brian |
| Bob |
@@ -141,7 +141,7 @@ class GraphContext implements Context {
$response = $this->editUserUsingTheGraphApi($byUser, $user, $userName); $response = $this->editUserUsingTheGraphApi($byUser, $user, $userName);
$this->featureContext->setResponse($response); $this->featureContext->setResponse($response);
// need to add user to list to delete him after test // need to add user to list to delete him after test
if (!empty($userName)) { if (!empty($userName) && $this->featureContext->getAttributeOfCreatedUser($userName, 'id')) {
$this->featureContext->addUserToCreatedUsersList($userName, $this->featureContext->getUserPassword($user)); $this->featureContext->addUserToCreatedUsersList($userName, $this->featureContext->getUserPassword($user));
} }
} }
@@ -230,8 +230,7 @@ class GraphContext implements Context {
*/ */
public function editUserUsingTheGraphApi(string $byUser, string $user, string $userName = null, string $password = null, string $email = null, string $displayName = null, bool $accountEnabled = true, string $method="PATCH"): ResponseInterface { public function editUserUsingTheGraphApi(string $byUser, string $user, string $userName = null, string $password = null, string $email = null, string $displayName = null, bool $accountEnabled = true, string $method="PATCH"): ResponseInterface {
$user = $this->featureContext->getActualUsername($user); $user = $this->featureContext->getActualUsername($user);
$userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id'); $userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?: $user;
$userId = $userId ?? $user;
return GraphHelper::editUser( return GraphHelper::editUser(
$this->featureContext->getBaseUrl(), $this->featureContext->getBaseUrl(),
$this->featureContext->getStepLineRef(), $this->featureContext->getStepLineRef(),
@@ -491,8 +490,7 @@ class GraphContext implements Context {
): ResponseInterface { ): ResponseInterface {
$credentials = $this->getAdminOrUserCredentials($byUser); $credentials = $this->getAdminOrUserCredentials($byUser);
$user = $this->featureContext->getActualUsername($user); $user = $this->featureContext->getActualUsername($user);
$userId = $this->featureContext->getAttributeOfCreatedUser($user, "id"); $userId = $this->featureContext->getAttributeOfCreatedUser($user, "id") ?: $user;
$userId = $userId ?? $user;
return GraphHelper::editUser( return GraphHelper::editUser(
$this->featureContext->getBaseUrl(), $this->featureContext->getBaseUrl(),
$this->featureContext->getStepLineRef(), $this->featureContext->getStepLineRef(),
@@ -793,18 +791,20 @@ class GraphContext implements Context {
/** /**
* @When the administrator tries to add nonexistent user to group :group using the Graph API * @When the administrator tries to add nonexistent user to group :group using the Graph API
* @When user :byUser tries to add nonexistent user to group :group using the Graph API
* *
* @param string $group * @param string $group
* @param string|null $byUser
* *
* @return void * @return void
*/ */
public function theAdministratorTriesToAddNonExistentUserToGroupUsingTheGraphAPI(string $group): void { public function theAdministratorTriesToAddNonExistentUserToGroupUsingTheGraphAPI(string $group, ?string $byUser = null): void {
$this->featureContext->setResponse($this->addUserToGroup($group, "nonexistent")); $this->featureContext->setResponse($this->addUserToGroup($group, "nonexistent", $byUser));
} }
/** /**
* @When the administrator tries to add user :user to a nonexistent group using the Graph API * @When the administrator tries to add user :user to a nonexistent group using the Graph API
* @When the user :byUser tries to add user :user to a nonexistent group using the Graph API * @When user :byUser tries to add user :user to a nonexistent group using the Graph API
* *
* @param string $user * @param string $user
* @param string|null $byUser * @param string|null $byUser
@@ -1038,7 +1038,7 @@ class GraphContext implements Context {
* @return void * @return void
*/ */
public function userDeletesGroupUsingTheGraphApi(string $group, ?string $user = null): void { public function userDeletesGroupUsingTheGraphApi(string $group, ?string $user = null): void {
$groupId = $this->featureContext->getAttributeOfCreatedGroup($group, "id"); $groupId = $this->featureContext->getAttributeOfCreatedGroup($group, "id") ?: $group;
$response = $this->deleteGroupWithId($groupId, $user); $response = $this->deleteGroupWithId($groupId, $user);
if ($response->getStatusCode() === 204) { if ($response->getStatusCode() === 204) {
$this->featureContext->rememberThatGroupIsNotExpectedToExist($group); $this->featureContext->rememberThatGroupIsNotExpectedToExist($group);
@@ -1750,7 +1750,7 @@ class GraphContext implements Context {
* @throws Exception * @throws Exception
*/ */
public function theAdministratorHasGivenTheRoleUsingTheGraphApi(string $role, string $user): void { public function theAdministratorHasGivenTheRoleUsingTheGraphApi(string $role, string $user): void {
$userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?? $user; $userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?: $user;
if (empty($this->appEntity)) { if (empty($this->appEntity)) {
$this->setApplicationEntity(); $this->setApplicationEntity();
@@ -1783,7 +1783,7 @@ class GraphContext implements Context {
*/ */
public function userRetrievesAssignedRoleUsingTheGraphApi(string $user): void { public function userRetrievesAssignedRoleUsingTheGraphApi(string $user): void {
$admin = $this->featureContext->getAdminUserName(); $admin = $this->featureContext->getAdminUserName();
$userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?? $user; $userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?: $user;
$this->featureContext->setResponse( $this->featureContext->setResponse(
GraphHelper::getAssignedRole( GraphHelper::getAssignedRole(
$this->featureContext->getBaseUrl(), $this->featureContext->getBaseUrl(),
@@ -1795,6 +1795,29 @@ class GraphContext implements Context {
); );
} }
/**
* @When /^user "([^"]*)" tries to get the assigned role of user "([^"]*)" using the Graph API$/
*
* @param string $user
* @param string $ofUser
*
* @return void
* @throws GuzzleException
*/
public function userTriesToGetAssignedRoleOfUserUsingTheGraphApi(string $user, string $ofUser): void {
$credentials = $this->getAdminOrUserCredentials($user);
$userId = $this->featureContext->getAttributeOfCreatedUser($ofUser, 'id') ?: $user;
$this->featureContext->setResponse(
GraphHelper::getAssignedRole(
$this->featureContext->getBaseUrl(),
$this->featureContext->getStepLineRef(),
$credentials['username'],
$credentials['password'],
$userId
)
);
}
/** /**
* set application Entity in global variable * set application Entity in global variable
* *
@@ -2323,7 +2346,7 @@ class GraphContext implements Context {
* @throws GuzzleException * @throws GuzzleException
*/ */
public function getAssignedRole(string $user): ResponseInterface { public function getAssignedRole(string $user): ResponseInterface {
$userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?? $this->featureContext->getUserIdByUserName($user); $userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?: $this->featureContext->getUserIdByUserName($user);
return ( return (
GraphHelper::getAssignedRole( GraphHelper::getAssignedRole(
$this->featureContext->getBAseUrl(), $this->featureContext->getBAseUrl(),
@@ -2347,9 +2370,17 @@ class GraphContext implements Context {
* @throws Exception * @throws Exception
*/ */
public function theUserUnassignsTheRoleOfUserUsingTheGraphApi(string $user, string $ofUser): void { public function theUserUnassignsTheRoleOfUserUsingTheGraphApi(string $user, string $ofUser): void {
$userId = $this->featureContext->getAttributeOfCreatedUser($ofUser, 'id') ?? $ofUser;
$credentials = $this->getAdminOrUserCredentials($user); $credentials = $this->getAdminOrUserCredentials($user);
$appRoleAssignmentId = $this->featureContext->getJsonDecodedResponse($this->getAssignedRole($ofUser))["value"][0]["id"]; $userId = $this->featureContext->getAttributeOfCreatedUser($ofUser, 'id');
// get 'User' role id for nonexistent user
if (!$userId && $ofUser !== $this->featureContext->getAdminUsername()) {
$appRoleAssignmentId = $this->getRoleIdByRoleName("User");
} else {
$appRoleAssignmentId = $this->featureContext->getJsonDecodedResponse($this->getAssignedRole($ofUser))["value"][0]["id"];
}
$userId = $userId ?: $ofUser;
$this->featureContext->setResponse( $this->featureContext->setResponse(
GraphHelper::unassignRole( GraphHelper::unassignRole(
@@ -2419,7 +2450,7 @@ class GraphContext implements Context {
* @throws Exception * @throws Exception
*/ */
public function userChangesTheRoleOfUserToRoleUsingTheGraphApi(string $user, string $ofUser, string $role): void { public function userChangesTheRoleOfUserToRoleUsingTheGraphApi(string $user, string $ofUser, string $role): void {
$userId = $this->featureContext->getAttributeOfCreatedUser($ofUser, 'id') ?? $ofUser; $userId = $this->featureContext->getAttributeOfCreatedUser($ofUser, 'id') ?: $ofUser;
$credentials = $this->getAdminOrUserCredentials($user); $credentials = $this->getAdminOrUserCredentials($user);
if (empty($this->appEntity)) { if (empty($this->appEntity)) {
$this->setApplicationEntity(); $this->setApplicationEntity();
@@ -131,7 +131,7 @@ class SettingsContext implements Context {
public function theAdministratorHasGivenUserTheRole(string $user, string $role): void { public function theAdministratorHasGivenUserTheRole(string $user, string $role): void {
$admin = $this->featureContext->getAdminUserName(); $admin = $this->featureContext->getAdminUserName();
$roleId = $this->getRoleIdByRoleName($admin, $role); $roleId = $this->getRoleIdByRoleName($admin, $role);
$userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?? $user; $userId = $this->featureContext->getAttributeOfCreatedUser($user, 'id') ?: $user;
$response = $this->assignRoleToUser($admin, $userId, $roleId); $response = $this->assignRoleToUser($admin, $userId, $roleId);
$this->featureContext->theHTTPStatusCodeShouldBe( $this->featureContext->theHTTPStatusCodeShouldBe(
201, 201,
@@ -375,7 +375,7 @@ Feature: upload file
And for user "Alice" the content of the file "/textfile.txt" of the space "new-space" should be "" And for user "Alice" the content of the file "/textfile.txt" of the space "new-space" should be ""
@issue-8699 @issue-8699
Scenario: user updates a file inside a shared space with empty content Scenario: user updates a file inside a link shared space with empty content
Given using SharingNG Given using SharingNG
And user "Brian" has been created with default attributes and without skeleton files And user "Brian" has been created with default attributes and without skeleton files
And the administrator has assigned the role "Space Admin" to user "Alice" using the Graph API And the administrator has assigned the role "Space Admin" to user "Alice" using the Graph API