Files
cloudron-box/src/test/user-test.js

719 lines
24 KiB
JavaScript
Raw Normal View History

/* global it:false */
/* global describe:false */
/* global before:false */
/* global after:false */
'use strict';
2016-02-08 16:53:20 -08:00
var async = require('async'),
database = require('../database.js'),
expect = require('expect.js'),
2016-02-08 16:53:20 -08:00
groupdb = require('../groupdb.js'),
groups = require('../groups.js'),
2016-01-18 14:19:20 +01:00
mailer = require('../mailer.js'),
user = require('../user.js'),
userdb = require('../userdb.js'),
UserError = user.UserError;
var USERNAME = 'noBody';
var USERNAME_NEW = 'noBodyNew';
var EMAIL = 'noBody@no.body';
var EMAIL_NEW = 'noBodyNew@no.body';
2016-01-20 14:50:06 +01:00
var PASSWORD = 'sTrOnG#$34134';
var NEW_PASSWORD = 'oTHER@#$235';
var DISPLAY_NAME = 'Nobody cares';
2016-01-25 14:08:35 +01:00
var DISPLAY_NAME_NEW = 'Somone cares';
2016-01-18 15:16:18 +01:00
var userObject = null;
var NON_ADMIN_GROUP = 'members';
2016-05-01 20:01:34 -07:00
var AUDIT_SOURCE = { ip: '1.2.3.4' };
function cleanupUsers(done) {
2016-02-08 16:53:20 -08:00
async.series([
groupdb._clear,
userdb._clear,
mailer._clearMailQueue
], done);
}
2016-02-08 15:16:59 -08:00
function createOwner(done) {
2016-02-08 16:53:20 -08:00
groups.create('admin', function () { // ignore error since it might already exist
groups.create(NON_ADMIN_GROUP, function () { // ignore error since it might already exist
user.createOwner(USERNAME, PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
2016-01-18 15:16:18 +01:00
userObject = result;
2016-01-18 15:16:18 +01:00
done();
});
2016-02-08 16:53:20 -08:00
});
});
}
function setup(done) {
2016-02-08 21:17:21 -08:00
async.series([
database.initialize,
database._clear,
mailer._clearMailQueue
], done);
}
function cleanup(done) {
2016-01-18 14:19:20 +01:00
mailer._clearMailQueue();
database._clear(done);
}
2016-01-18 14:19:20 +01:00
function checkMails(number, done) {
// mails are enqueued async
setTimeout(function () {
expect(mailer._getMailQueue().length).to.equal(number);
mailer._clearMailQueue();
done();
}, 500);
}
describe('User', function () {
before(setup);
after(cleanup);
describe('create', function() {
before(cleanupUsers);
after(cleanupUsers);
2016-01-20 14:50:06 +01:00
it('fails due to short password', function (done) {
2016-05-01 20:01:34 -07:00
user.create(USERNAME, 'Fo$%23', EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
2016-01-20 14:50:06 +01:00
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-01-20 14:50:06 +01:00
done();
});
});
it('fails due to missing upper case password', function (done) {
2016-05-01 20:01:34 -07:00
user.create(USERNAME, 'thisiseightch%$234arslong', EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
2016-01-20 14:50:06 +01:00
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-01-20 14:50:06 +01:00
done();
});
});
it('fails due to missing numerics in password', function (done) {
2016-05-01 20:01:34 -07:00
user.create(USERNAME, 'foobaRASDF%', EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
2016-01-20 14:50:06 +01:00
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-01-20 14:50:06 +01:00
done();
});
});
it('fails due to missing special chars in password', function (done) {
2016-05-01 20:01:34 -07:00
user.create(USERNAME, 'foobaRASDF23423', EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
2016-01-20 14:50:06 +01:00
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-01-20 14:50:06 +01:00
done();
});
});
2016-04-14 16:30:31 +02:00
it('fails due to reserved username', function (done) {
2016-05-01 20:01:34 -07:00
user.create('admin', PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
2016-04-14 16:30:31 +02:00
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-04-14 16:30:31 +02:00
done();
});
});
it('fails due to reserved username', function (done) {
2016-05-23 14:52:29 -07:00
user.create('Mailer-Daemon', PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
2016-04-14 16:30:31 +02:00
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-04-14 16:30:31 +02:00
done();
});
});
2016-05-23 14:56:09 -07:00
it('fails due to short username', function (done) {
user.create('Z', PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-05-23 14:56:09 -07:00
done();
});
});
it('fails due to long username', function (done) {
user.create(new Array(257).fill('Z').join(''), PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-05-23 14:56:09 -07:00
done();
});
});
it('fails due to reserved pattern', function (done) {
user.create('maybe-app', PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
2016-05-23 14:56:09 -07:00
done();
});
});
2016-01-18 14:19:20 +01:00
it('succeeds and attempts to send invite', function (done) {
2016-05-01 20:01:34 -07:00
user.createOwner(USERNAME, PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).not.to.be.ok();
expect(result).to.be.ok();
expect(result.username).to.equal(USERNAME.toLowerCase());
expect(result.email).to.equal(EMAIL.toLowerCase());
// first user is owner, do not send mail to admins
2016-02-08 21:17:21 -08:00
checkMails(0, done);
});
});
it('fails because of invalid BAD_FIELD', function (done) {
expect(function () {
user.create(EMAIL, {}, function () {});
}).to.throwException();
expect(function () {
user.create(12345, PASSWORD, EMAIL, function () {});
}).to.throwException();
expect(function () {
user.create(USERNAME, PASSWORD, EMAIL, {});
}).to.throwException();
expect(function () {
user.create(USERNAME, PASSWORD, EMAIL, {}, function () {});
}).to.throwException();
expect(function () {
user.create(USERNAME, PASSWORD, EMAIL, {});
}).to.throwException();
2016-01-18 13:50:54 +01:00
expect(function () {
user.create(USERNAME, PASSWORD, EMAIL, false, null, 'foobar');
}).to.throwException();
done();
});
it('fails because user exists', function (done) {
2016-05-01 20:01:34 -07:00
user.create(USERNAME, PASSWORD, EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).to.be.ok();
expect(result).not.to.be.ok();
expect(error.reason).to.equal(UserError.ALREADY_EXISTS);
done();
});
});
it('fails because password is empty', function (done) {
2016-05-01 20:01:34 -07:00
user.create(USERNAME, '', EMAIL, DISPLAY_NAME, AUDIT_SOURCE, function (error, result) {
expect(error).to.be.ok();
expect(result).not.to.be.ok();
expect(error.reason).to.equal(UserError.BAD_FIELD);
done();
});
});
});
2016-01-13 12:28:38 -08:00
describe('getOwner', function() {
before(cleanupUsers);
after(cleanupUsers);
it('fails because there is no owner', function (done) {
user.getOwner(function (error) {
expect(error.reason).to.be(UserError.NOT_FOUND);
done();
});
});
it('succeeds', function (done) {
2016-02-08 15:16:59 -08:00
createOwner(function (error) {
2016-01-13 12:28:38 -08:00
if (error) return done(error);
user.getOwner(function (error, owner) {
expect(error).to.be(null);
expect(owner.email).to.be(EMAIL.toLowerCase());
2016-01-13 12:28:38 -08:00
done();
});
});
});
});
describe('verify', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
it('fails due to non existing user', function (done) {
user.verify('somerandomid', PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.NOT_FOUND);
done();
});
});
it('fails due to empty password', function (done) {
user.verify(userObject.id, '', function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('fails due to wrong password', function (done) {
user.verify(userObject.id, PASSWORD+PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('succeeds', function (done) {
user.verify(userObject.id, PASSWORD, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
done();
});
});
});
describe('verifyWithUsername', function () {
before(createOwner);
after(cleanupUsers);
it('fails due to non existing username', function (done) {
user.verifyWithUsername(USERNAME+USERNAME, PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.NOT_FOUND);
done();
});
});
it('fails due to empty password', function (done) {
user.verifyWithUsername(USERNAME, '', function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('fails due to wrong password', function (done) {
user.verifyWithUsername(USERNAME, PASSWORD+PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('succeeds', function (done) {
user.verifyWithUsername(USERNAME, PASSWORD, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
done();
});
});
it('succeeds for different username case', function (done) {
user.verifyWithUsername(USERNAME.toUpperCase(), PASSWORD, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
done();
});
});
});
describe('verifyWithEmail', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
it('fails due to non existing user', function (done) {
user.verifyWithEmail(EMAIL+EMAIL, PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.NOT_FOUND);
done();
});
});
it('fails due to empty password', function (done) {
user.verifyWithEmail(EMAIL, '', function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('fails due to wrong password', function (done) {
user.verifyWithEmail(EMAIL, PASSWORD+PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('succeeds', function (done) {
user.verifyWithEmail(EMAIL, PASSWORD, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
done();
});
});
it('succeeds for different email case', function (done) {
user.verifyWithEmail(EMAIL.toUpperCase(), PASSWORD, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
done();
});
});
});
describe('retrieving', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
it('fails due to non existing user', function (done) {
user.get('some non existing username', function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
done();
});
});
it('succeeds', function (done) {
2016-04-04 16:40:47 +02:00
user.get(userObject.id, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
2016-04-04 16:40:47 +02:00
expect(result.id).to.equal(userObject.id);
expect(result.email).to.equal(EMAIL.toLowerCase());
expect(result.username).to.equal(USERNAME.toLowerCase());
2016-01-25 14:08:35 +01:00
expect(result.displayName).to.equal(DISPLAY_NAME);
done();
});
});
});
describe('update', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
it('fails due to unknown userid', function (done) {
var data = { username: USERNAME_NEW, email: EMAIL_NEW, displayName: DISPLAY_NAME_NEW };
user.update(USERNAME, data, AUDIT_SOURCE, function (error) {
expect(error).to.be.a(UserError);
expect(error.reason).to.equal(UserError.NOT_FOUND);
done();
});
});
it('fails due to invalid email', function (done) {
var data = { username: USERNAME_NEW, email: 'brokenemailaddress', displayName: DISPLAY_NAME_NEW };
user.update(userObject.id, data, AUDIT_SOURCE, function (error) {
expect(error).to.be.a(UserError);
expect(error.reason).to.equal(UserError.BAD_FIELD);
done();
});
});
it('succeeds', function (done) {
var data = { username: USERNAME_NEW, email: EMAIL_NEW, displayName: DISPLAY_NAME_NEW };
user.update(userObject.id, data, AUDIT_SOURCE, function (error) {
expect(error).to.not.be.ok();
2016-04-04 16:40:47 +02:00
user.get(userObject.id, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
expect(result.email).to.equal(EMAIL_NEW.toLowerCase());
expect(result.username).to.equal(USERNAME_NEW.toLowerCase());
2016-01-25 14:08:35 +01:00
expect(result.displayName).to.equal(DISPLAY_NAME_NEW);
done();
});
});
});
it('succeeds with same data', function (done) {
var data = { username: USERNAME_NEW, email: EMAIL_NEW, displayName: DISPLAY_NAME_NEW };
user.update(userObject.id, data, AUDIT_SOURCE, function (error) {
expect(error).to.not.be.ok();
2016-04-04 16:40:47 +02:00
user.get(userObject.id, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
expect(result.email).to.equal(EMAIL_NEW.toLowerCase());
expect(result.username).to.equal(USERNAME_NEW.toLowerCase());
expect(result.displayName).to.equal(DISPLAY_NAME_NEW);
done();
});
});
});
});
2016-03-09 06:18:39 +01:00
describe('admin change triggers mail', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
var user1 = {
username: 'seconduser',
password: 'ASDFkljsf#$^%2354',
email: 'some@thi.ng'
};
it('make second user admin succeeds', function (done) {
2016-02-08 21:05:02 -08:00
var invitor = { username: USERNAME, email: EMAIL };
2016-05-01 20:01:34 -07:00
user.create(user1.username, user1.password, user1.email, DISPLAY_NAME, AUDIT_SOURCE, { invitor: invitor }, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
2016-04-04 16:40:47 +02:00
user1.id = result.id;
user.setGroups(user1.id, [ groups.ADMIN_GROUP_ID ], function (error) {
expect(error).to.not.be.ok();
2016-01-18 14:19:20 +01:00
// one mail for user creation, one mail for admin change
checkMails(2, done);
});
});
});
it('add user to non admin group does not trigger admin mail', function (done) {
user.setGroups(user1.id, [ groups.ADMIN_GROUP_ID, NON_ADMIN_GROUP ], function (error) {
expect(error).to.equal(null);
checkMails(0, done);
});
});
it('succeeds to remove admin flag', function (done) {
user.setGroups(user1.id, [ NON_ADMIN_GROUP ], function (error) {
expect(error).to.eql(null);
2016-01-18 14:19:20 +01:00
checkMails(1, done);
});
});
});
2016-01-15 16:12:45 +01:00
describe('get admins', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
2016-01-15 16:12:45 +01:00
after(cleanupUsers);
it('succeeds for one admins', function (done) {
user.getAllAdmins(function (error, admins) {
expect(error).to.eql(null);
expect(admins.length).to.equal(1);
expect(admins[0].username).to.equal(USERNAME.toLowerCase());
2016-01-15 16:12:45 +01:00
done();
});
});
it('succeeds for two admins', function (done) {
var user1 = {
username: 'seconduser',
2016-01-20 14:50:06 +01:00
password: 'Adfasdkjf#$%43',
2016-01-15 16:12:45 +01:00
email: 'some@thi.ng'
};
2016-02-08 21:05:02 -08:00
var invitor = { username: USERNAME, email: EMAIL };
2016-05-01 20:01:34 -07:00
user.create(user1.username, user1.password, user1.email, DISPLAY_NAME, AUDIT_SOURCE, { invitor: invitor }, function (error, result) {
2016-01-15 16:12:45 +01:00
expect(error).to.eql(null);
expect(result).to.be.ok();
2016-04-04 16:40:47 +02:00
user1.id = result.id;
groups.setGroups(user1.id, [ groups.ADMIN_GROUP_ID ], function (error) {
2016-01-15 16:12:45 +01:00
expect(error).to.eql(null);
user.getAllAdmins(function (error, admins) {
expect(error).to.eql(null);
expect(admins.length).to.equal(2);
expect(admins[0].username).to.equal(USERNAME.toLowerCase());
expect(admins[1].username).to.equal(user1.username.toLowerCase());
2016-01-18 14:19:20 +01:00
// one mail for user creation one mail for admin change
checkMails(1, done); // FIXME should be 2 for admin change
2016-01-15 16:12:45 +01:00
});
});
});
});
});
2016-06-07 09:59:29 -07:00
describe('count', function () {
before(createOwner);
after(cleanupUsers);
it('succeeds', function (done) {
user.count(function (error, count) {
expect(error).to.not.be.ok();
expect(count).to.be(1);
done();
});
});
});
2016-01-15 16:12:45 +01:00
describe('set password', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
it('fails due to unknown user', function (done) {
user.setPassword('doesnotexist', NEW_PASSWORD, function (error) {
expect(error).to.be.ok();
done();
});
});
it('fails due to empty password', function (done) {
user.setPassword(userObject.id, '', function (error) {
expect(error).to.be.ok();
done();
});
});
it('fails due to invalid password', function (done) {
user.setPassword(userObject.id, 'foobar', function (error) {
expect(error).to.be.ok();
done();
});
});
it('succeeds', function (done) {
user.setPassword(userObject.id, NEW_PASSWORD, function (error) {
expect(error).to.not.be.ok();
done();
});
});
it('actually changed the password (unable to login with old pasword)', function (done) {
user.verify(userObject.id, PASSWORD, function (error, result) {
expect(error).to.be.ok();
expect(result).to.not.be.ok();
expect(error.reason).to.equal(UserError.WRONG_PASSWORD);
done();
});
});
it('actually changed the password (login with new password)', function (done) {
user.verify(userObject.id, NEW_PASSWORD, function (error, result) {
expect(error).to.not.be.ok();
expect(result).to.be.ok();
done();
});
});
});
describe('resetPasswordByIdentifier', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
after(cleanupUsers);
it('fails due to unkown email', function (done) {
user.resetPasswordByIdentifier('unknown@mail.com', function (error) {
expect(error).to.be.an(UserError);
expect(error.reason).to.eql(UserError.NOT_FOUND);
done();
});
});
it('fails due to unkown username', function (done) {
user.resetPasswordByIdentifier('unknown', function (error) {
expect(error).to.be.an(UserError);
expect(error.reason).to.eql(UserError.NOT_FOUND);
done();
});
});
it('succeeds with email', function (done) {
user.resetPasswordByIdentifier(EMAIL, function (error) {
expect(error).to.not.be.ok();
2016-01-18 14:19:20 +01:00
checkMails(1, done);
});
});
it('succeeds with username', function (done) {
user.resetPasswordByIdentifier(USERNAME, function (error) {
expect(error).to.not.be.ok();
2016-01-18 14:19:20 +01:00
checkMails(1, done);
});
});
});
2016-01-18 15:16:18 +01:00
describe('send invite', function () {
2016-02-08 15:16:59 -08:00
before(createOwner);
2016-01-18 15:16:18 +01:00
after(cleanupUsers);
it('fails for unknown user', function (done) {
user.sendInvite('unknown user', function (error) {
expect(error).to.be.a(UserError);
expect(error.reason).to.equal(UserError.NOT_FOUND);
checkMails(0, done);
});
});
it('succeeds', function (done) {
user.sendInvite(userObject.id, function (error) {
expect(error).to.eql(null);
checkMails(1, done);
2016-01-18 15:16:18 +01:00
});
});
});
2016-06-02 22:25:48 -07:00
describe('remove', function () {
before(createOwner);
after(cleanupUsers);
it('fails for unkown user', function (done) {
user.remove('unknown', { }, function (error) {
expect(error.reason).to.be(UserError.NOT_FOUND);
done();
});
});
it('can remove valid user', function (done) {
user.remove(userObject.id, { }, function (error) {
expect(error).to.be(null);
done();
});
});
});
});