|
|
|
@ -9,10 +9,13 @@ |
|
|
|
namespace Test\User; |
|
|
|
|
|
|
|
use OC\AppFramework\Http\Request; |
|
|
|
use OC\Authentication\Exceptions\InvalidTokenException; |
|
|
|
use OC\Authentication\Exceptions\PasswordLoginForbiddenException; |
|
|
|
use OC\Authentication\Token\IProvider; |
|
|
|
use OC\Authentication\Token\IToken; |
|
|
|
use OC\Security\Bruteforce\Throttler; |
|
|
|
use OC\Session\Memory; |
|
|
|
use OC\User\LoginException; |
|
|
|
use OC\User\Manager; |
|
|
|
use OC\User\Session; |
|
|
|
use OC\User\User; |
|
|
|
@ -23,6 +26,7 @@ use OCP\ICacheFactory; |
|
|
|
use OCP\IConfig; |
|
|
|
use OCP\ILogger; |
|
|
|
use OCP\IRequest; |
|
|
|
use OCP\IRequestId; |
|
|
|
use OCP\ISession; |
|
|
|
use OCP\IUser; |
|
|
|
use OCP\Lockdown\ILockdownManager; |
|
|
|
@ -30,6 +34,7 @@ use OCP\Security\ISecureRandom; |
|
|
|
use OCP\User\Events\PostLoginEvent; |
|
|
|
use PHPUnit\Framework\MockObject\MockObject; |
|
|
|
use Symfony\Component\EventDispatcher\EventDispatcherInterface; |
|
|
|
use OC\Security\CSRF\CsrfTokenManager; |
|
|
|
|
|
|
|
/** |
|
|
|
* @group DB |
|
|
|
@ -136,7 +141,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
->method('getUID') |
|
|
|
->willReturn('foo'); |
|
|
|
|
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession->setUser($user); |
|
|
|
} |
|
|
|
|
|
|
|
@ -147,7 +152,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('bar') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
$session->expects($this->exactly(2)) |
|
|
|
->method('set') |
|
|
|
->with($this->callback(function ($key) { |
|
|
|
@ -217,7 +222,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
|
|
|
|
|
|
|
|
public function testLoginValidPasswordDisabled() { |
|
|
|
$this->expectException(\OC\User\LoginException::class); |
|
|
|
$this->expectException(LoginException::class); |
|
|
|
|
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$session->expects($this->never()) |
|
|
|
@ -227,9 +232,9 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('bar') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
|
|
|
|
$managerMethods = get_class_methods(\OC\User\Manager::class); |
|
|
|
$managerMethods = get_class_methods(Manager::class); |
|
|
|
//keep following methods intact in order to ensure hooks are working
|
|
|
|
$mockedManagerMethods = array_diff($managerMethods, ['__construct', 'emit', 'listen']); |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
@ -257,13 +262,13 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->dispatcher->expects($this->never()) |
|
|
|
->method('dispatch'); |
|
|
|
|
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession->login('foo', 'bar'); |
|
|
|
} |
|
|
|
|
|
|
|
public function testLoginInvalidPassword() { |
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$managerMethods = get_class_methods(\OC\User\Manager::class); |
|
|
|
$managerMethods = get_class_methods(Manager::class); |
|
|
|
//keep following methods intact in order to ensure hooks are working
|
|
|
|
$mockedManagerMethods = array_diff($managerMethods, ['__construct', 'emit', 'listen']); |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
@ -276,7 +281,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
]) |
|
|
|
->getMock(); |
|
|
|
$backend = $this->createMock(\Test\Util\User\Dummy::class); |
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
|
|
|
|
$user = $this->createMock(IUser::class); |
|
|
|
|
|
|
|
@ -287,7 +292,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('bar') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
|
|
|
|
$user->expects($this->never()) |
|
|
|
->method('isEnabled'); |
|
|
|
@ -308,7 +313,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
public function testLoginNonExisting() { |
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$manager = $this->createMock(Manager::class); |
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
|
|
|
|
$session->expects($this->never()) |
|
|
|
->method('set'); |
|
|
|
@ -317,7 +322,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('bar') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
|
|
|
|
$manager->expects($this->once()) |
|
|
|
->method('checkPasswordNoLogging') |
|
|
|
@ -328,13 +333,13 @@ class SessionTest extends \Test\TestCase { |
|
|
|
} |
|
|
|
|
|
|
|
public function testLogClientInNoTokenPasswordWith2fa() { |
|
|
|
$this->expectException(\OC\Authentication\Exceptions\PasswordLoginForbiddenException::class); |
|
|
|
$this->expectException(PasswordLoginForbiddenException::class); |
|
|
|
|
|
|
|
$manager = $this->createMock(Manager::class); |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$request = $this->createMock(IRequest::class); |
|
|
|
|
|
|
|
/** @var \OC\User\Session $userSession */ |
|
|
|
/** @var Session $userSession */ |
|
|
|
$userSession = $this->getMockBuilder(Session::class) |
|
|
|
->setConstructorArgs([$manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher]) |
|
|
|
->setMethods(['login', 'supportsCookies', 'createSessionToken', 'getUser']) |
|
|
|
@ -343,7 +348,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('doe') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
$this->config->expects($this->once()) |
|
|
|
->method('getSystemValue') |
|
|
|
->with('token_auth_enforced', false) |
|
|
|
@ -379,7 +384,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('doe') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
$this->config->expects($this->once()) |
|
|
|
->method('getSystemValue') |
|
|
|
->with('token_auth_enforced', false) |
|
|
|
@ -396,7 +401,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$request = $this->createMock(IRequest::class); |
|
|
|
|
|
|
|
/** @var \OC\User\Session $userSession */ |
|
|
|
/** @var Session $userSession */ |
|
|
|
$userSession = $this->getMockBuilder(Session::class) |
|
|
|
->setConstructorArgs([$manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher]) |
|
|
|
->setMethods(['isTokenPassword', 'login', 'supportsCookies', 'createSessionToken', 'getUser']) |
|
|
|
@ -432,13 +437,13 @@ class SessionTest extends \Test\TestCase { |
|
|
|
|
|
|
|
|
|
|
|
public function testLogClientInNoTokenPasswordNo2fa() { |
|
|
|
$this->expectException(\OC\Authentication\Exceptions\PasswordLoginForbiddenException::class); |
|
|
|
$this->expectException(PasswordLoginForbiddenException::class); |
|
|
|
|
|
|
|
$manager = $this->createMock(Manager::class); |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$request = $this->createMock(IRequest::class); |
|
|
|
|
|
|
|
/** @var \OC\User\Session $userSession */ |
|
|
|
/** @var Session $userSession */ |
|
|
|
$userSession = $this->getMockBuilder(Session::class) |
|
|
|
->setConstructorArgs([$manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher]) |
|
|
|
->setMethods(['login', 'isTwoFactorEnforced']) |
|
|
|
@ -447,7 +452,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with('doe') |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
$this->config->expects($this->once()) |
|
|
|
->method('getSystemValue') |
|
|
|
->with('token_auth_enforced', false) |
|
|
|
@ -477,7 +482,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
|
|
|
|
public function testRememberLoginValidToken() { |
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$managerMethods = get_class_methods(\OC\User\Manager::class); |
|
|
|
$managerMethods = get_class_methods(Manager::class); |
|
|
|
//keep following methods intact in order to ensure hooks are working
|
|
|
|
$mockedManagerMethods = array_diff($managerMethods, ['__construct', 'emit', 'listen']); |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
@ -567,7 +572,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
|
|
|
|
public function testRememberLoginInvalidSessionToken() { |
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$managerMethods = get_class_methods(\OC\User\Manager::class); |
|
|
|
$managerMethods = get_class_methods(Manager::class); |
|
|
|
//keep following methods intact in order to ensure hooks are working
|
|
|
|
$mockedManagerMethods = array_diff($managerMethods, ['__construct', 'emit', 'listen']); |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
@ -612,7 +617,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('renewSessionToken') |
|
|
|
->with($oldSessionId, $sessionId) |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
|
|
|
|
$user->expects($this->never()) |
|
|
|
->method('getUID') |
|
|
|
@ -632,7 +637,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
|
|
|
|
public function testRememberLoginInvalidToken() { |
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$managerMethods = get_class_methods(\OC\User\Manager::class); |
|
|
|
$managerMethods = get_class_methods(Manager::class); |
|
|
|
//keep following methods intact in order to ensure hooks are working
|
|
|
|
$mockedManagerMethods = array_diff($managerMethods, ['__construct', 'emit', 'listen']); |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
@ -685,7 +690,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
|
|
|
|
public function testRememberLoginInvalidUser() { |
|
|
|
$session = $this->getMockBuilder(Memory::class)->setConstructorArgs([''])->getMock(); |
|
|
|
$managerMethods = get_class_methods(\OC\User\Manager::class); |
|
|
|
$managerMethods = get_class_methods(Manager::class); |
|
|
|
//keep following methods intact in order to ensure hooks are working
|
|
|
|
$mockedManagerMethods = array_diff($managerMethods, ['__construct', 'emit', 'listen']); |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
@ -735,7 +740,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
'bar' => new User('bar', null, $this->createMock(EventDispatcherInterface::class)) |
|
|
|
]; |
|
|
|
|
|
|
|
$manager = $this->getMockBuilder('\OC\User\Manager') |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
->disableOriginalConstructor() |
|
|
|
->getMock(); |
|
|
|
|
|
|
|
@ -768,18 +773,18 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$manager = $this->createMock(Manager::class); |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$user = $this->createMock(IUser::class); |
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
|
|
|
|
$random = $this->createMock(ISecureRandom::class); |
|
|
|
$requestId = $this->createMock(IRequestId::class); |
|
|
|
$config = $this->createMock(IConfig::class); |
|
|
|
$csrf = $this->getMockBuilder('\OC\Security\CSRF\CsrfTokenManager') |
|
|
|
$csrf = $this->getMockBuilder(CsrfTokenManager::class) |
|
|
|
->disableOriginalConstructor() |
|
|
|
->getMock(); |
|
|
|
$request = new \OC\AppFramework\Http\Request([ |
|
|
|
$request = new Request([ |
|
|
|
'server' => [ |
|
|
|
'HTTP_USER_AGENT' => 'Firefox', |
|
|
|
] |
|
|
|
], $random, $config, $csrf); |
|
|
|
], $requestId, $config, $csrf); |
|
|
|
|
|
|
|
$uid = 'user123'; |
|
|
|
$loginName = 'User123'; |
|
|
|
@ -796,7 +801,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with($password) |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
|
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('generateToken') |
|
|
|
@ -809,18 +814,18 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$manager = $this->createMock(Manager::class); |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$user = $this->createMock(IUser::class); |
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
|
|
|
|
$random = $this->createMock(ISecureRandom::class); |
|
|
|
$requestId = $this->createMock(IRequestId::class); |
|
|
|
$config = $this->createMock(IConfig::class); |
|
|
|
$csrf = $this->getMockBuilder('\OC\Security\CSRF\CsrfTokenManager') |
|
|
|
$csrf = $this->getMockBuilder(CsrfTokenManager::class) |
|
|
|
->disableOriginalConstructor() |
|
|
|
->getMock(); |
|
|
|
$request = new \OC\AppFramework\Http\Request([ |
|
|
|
$request = new Request([ |
|
|
|
'server' => [ |
|
|
|
'HTTP_USER_AGENT' => 'Firefox', |
|
|
|
] |
|
|
|
], $random, $config, $csrf); |
|
|
|
], $requestId, $config, $csrf); |
|
|
|
|
|
|
|
$uid = 'user123'; |
|
|
|
$loginName = 'User123'; |
|
|
|
@ -837,7 +842,7 @@ class SessionTest extends \Test\TestCase { |
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('getToken') |
|
|
|
->with($password) |
|
|
|
->will($this->throwException(new \OC\Authentication\Exceptions\InvalidTokenException())); |
|
|
|
->will($this->throwException(new InvalidTokenException())); |
|
|
|
|
|
|
|
$this->tokenProvider->expects($this->once()) |
|
|
|
->method('generateToken') |
|
|
|
@ -847,24 +852,24 @@ class SessionTest extends \Test\TestCase { |
|
|
|
} |
|
|
|
|
|
|
|
public function testCreateSessionTokenWithTokenPassword() { |
|
|
|
$manager = $this->getMockBuilder('\OC\User\Manager') |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
->disableOriginalConstructor() |
|
|
|
->getMock(); |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$token = $this->createMock(IToken::class); |
|
|
|
$user = $this->createMock(IUser::class); |
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
|
|
|
|
$random = $this->createMock(ISecureRandom::class); |
|
|
|
$requestId = $this->createMock(IRequestId::class); |
|
|
|
$config = $this->createMock(IConfig::class); |
|
|
|
$csrf = $this->getMockBuilder('\OC\Security\CSRF\CsrfTokenManager') |
|
|
|
$csrf = $this->getMockBuilder(CsrfTokenManager::class) |
|
|
|
->disableOriginalConstructor() |
|
|
|
->getMock(); |
|
|
|
$request = new \OC\AppFramework\Http\Request([ |
|
|
|
$request = new Request([ |
|
|
|
'server' => [ |
|
|
|
'HTTP_USER_AGENT' => 'Firefox', |
|
|
|
] |
|
|
|
], $random, $config, $csrf); |
|
|
|
], $requestId, $config, $csrf); |
|
|
|
|
|
|
|
$uid = 'user123'; |
|
|
|
$loginName = 'User123'; |
|
|
|
@ -896,11 +901,11 @@ class SessionTest extends \Test\TestCase { |
|
|
|
} |
|
|
|
|
|
|
|
public function testCreateSessionTokenWithNonExistentUser() { |
|
|
|
$manager = $this->getMockBuilder('\OC\User\Manager') |
|
|
|
$manager = $this->getMockBuilder(Manager::class) |
|
|
|
->disableOriginalConstructor() |
|
|
|
->getMock(); |
|
|
|
$session = $this->createMock(ISession::class); |
|
|
|
$userSession = new \OC\User\Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$userSession = new Session($manager, $session, $this->timeFactory, $this->tokenProvider, $this->config, $this->random, $this->lockdownManager, $this->logger, $this->dispatcher); |
|
|
|
$request = $this->createMock(IRequest::class); |
|
|
|
|
|
|
|
$uid = 'user123'; |
|
|
|
|