perms_test.go 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307
  1. // Copyright 2020 The Gogs Authors. All rights reserved.
  2. // Use of this source code is governed by a MIT-style
  3. // license that can be found in the LICENSE file.
  4. package db
  5. import (
  6. "testing"
  7. "github.com/stretchr/testify/assert"
  8. )
  9. func Test_perms(t *testing.T) {
  10. if testing.Short() {
  11. t.Skip()
  12. }
  13. t.Parallel()
  14. tables := []interface{}{new(Access)}
  15. db := &perms{
  16. DB: initTestDB(t, "perms", tables...),
  17. }
  18. for _, tc := range []struct {
  19. name string
  20. test func(*testing.T, *perms)
  21. }{
  22. {"AccessMode", test_perms_AccessMode},
  23. {"Authorize", test_perms_Authorize},
  24. {"SetRepoPerms", test_perms_SetRepoPerms},
  25. } {
  26. t.Run(tc.name, func(t *testing.T) {
  27. t.Cleanup(func() {
  28. err := clearTables(t, db.DB, tables...)
  29. if err != nil {
  30. t.Fatal(err)
  31. }
  32. })
  33. tc.test(t, db)
  34. })
  35. if t.Failed() {
  36. break
  37. }
  38. }
  39. }
  40. func test_perms_AccessMode(t *testing.T, db *perms) {
  41. // Set up permissions
  42. err := db.SetRepoPerms(1, map[int64]AccessMode{
  43. 2: AccessModeWrite,
  44. 3: AccessModeAdmin,
  45. })
  46. if err != nil {
  47. t.Fatal(err)
  48. }
  49. err = db.SetRepoPerms(2, map[int64]AccessMode{
  50. 1: AccessModeRead,
  51. })
  52. if err != nil {
  53. t.Fatal(err)
  54. }
  55. publicRepoID := int64(1)
  56. publicRepoOpts := AccessModeOptions{
  57. OwnerID: 98,
  58. }
  59. privateRepoID := int64(2)
  60. privateRepoOpts := AccessModeOptions{
  61. OwnerID: 99,
  62. Private: true,
  63. }
  64. tests := []struct {
  65. name string
  66. userID int64
  67. repoID int64
  68. opts AccessModeOptions
  69. expAccessMode AccessMode
  70. }{
  71. {
  72. name: "nil repository",
  73. expAccessMode: AccessModeNone,
  74. },
  75. {
  76. name: "anonymous user has read access to public repository",
  77. repoID: publicRepoID,
  78. opts: publicRepoOpts,
  79. expAccessMode: AccessModeRead,
  80. },
  81. {
  82. name: "anonymous user has no access to private repository",
  83. repoID: privateRepoID,
  84. opts: privateRepoOpts,
  85. expAccessMode: AccessModeNone,
  86. },
  87. {
  88. name: "user is the owner",
  89. userID: 98,
  90. repoID: publicRepoID,
  91. opts: publicRepoOpts,
  92. expAccessMode: AccessModeOwner,
  93. },
  94. {
  95. name: "user 1 has read access to public repo",
  96. userID: 1,
  97. repoID: publicRepoID,
  98. opts: publicRepoOpts,
  99. expAccessMode: AccessModeRead,
  100. },
  101. {
  102. name: "user 2 has write access to public repo",
  103. userID: 2,
  104. repoID: publicRepoID,
  105. opts: publicRepoOpts,
  106. expAccessMode: AccessModeWrite,
  107. },
  108. {
  109. name: "user 3 has admin access to public repo",
  110. userID: 3,
  111. repoID: publicRepoID,
  112. opts: publicRepoOpts,
  113. expAccessMode: AccessModeAdmin,
  114. },
  115. {
  116. name: "user 1 has read access to private repo",
  117. userID: 1,
  118. repoID: privateRepoID,
  119. opts: privateRepoOpts,
  120. expAccessMode: AccessModeRead,
  121. },
  122. {
  123. name: "user 2 has no access to private repo",
  124. userID: 2,
  125. repoID: privateRepoID,
  126. opts: privateRepoOpts,
  127. expAccessMode: AccessModeNone,
  128. },
  129. {
  130. name: "user 3 has no access to private repo",
  131. userID: 3,
  132. repoID: privateRepoID,
  133. opts: privateRepoOpts,
  134. expAccessMode: AccessModeNone,
  135. },
  136. }
  137. for _, test := range tests {
  138. t.Run(test.name, func(t *testing.T) {
  139. mode := db.AccessMode(test.userID, test.repoID, test.opts)
  140. assert.Equal(t, test.expAccessMode, mode)
  141. })
  142. }
  143. }
  144. func test_perms_Authorize(t *testing.T, db *perms) {
  145. // Set up permissions
  146. err := db.SetRepoPerms(1, map[int64]AccessMode{
  147. 1: AccessModeRead,
  148. 2: AccessModeWrite,
  149. 3: AccessModeAdmin,
  150. })
  151. if err != nil {
  152. t.Fatal(err)
  153. }
  154. repo := &Repository{
  155. ID: 1,
  156. OwnerID: 98,
  157. }
  158. tests := []struct {
  159. name string
  160. userID int64
  161. desired AccessMode
  162. expAuthorized bool
  163. }{
  164. {
  165. name: "user 1 has read and wants read",
  166. userID: 1,
  167. desired: AccessModeRead,
  168. expAuthorized: true,
  169. },
  170. {
  171. name: "user 1 has read and wants write",
  172. userID: 1,
  173. desired: AccessModeWrite,
  174. expAuthorized: false,
  175. },
  176. {
  177. name: "user 2 has write and wants read",
  178. userID: 2,
  179. desired: AccessModeRead,
  180. expAuthorized: true,
  181. },
  182. {
  183. name: "user 2 has write and wants write",
  184. userID: 2,
  185. desired: AccessModeWrite,
  186. expAuthorized: true,
  187. },
  188. {
  189. name: "user 2 has write and wants admin",
  190. userID: 2,
  191. desired: AccessModeAdmin,
  192. expAuthorized: false,
  193. },
  194. {
  195. name: "user 3 has admin and wants read",
  196. userID: 3,
  197. desired: AccessModeRead,
  198. expAuthorized: true,
  199. },
  200. {
  201. name: "user 3 has admin and wants write",
  202. userID: 3,
  203. desired: AccessModeWrite,
  204. expAuthorized: true,
  205. },
  206. {
  207. name: "user 3 has admin and wants admin",
  208. userID: 3,
  209. desired: AccessModeAdmin,
  210. expAuthorized: true,
  211. },
  212. }
  213. for _, test := range tests {
  214. t.Run(test.name, func(t *testing.T) {
  215. authorized := db.Authorize(test.userID, repo.ID, test.desired, AccessModeOptions{
  216. OwnerID: repo.OwnerID,
  217. Private: repo.IsPrivate,
  218. })
  219. assert.Equal(t, test.expAuthorized, authorized)
  220. })
  221. }
  222. }
  223. func test_perms_SetRepoPerms(t *testing.T, db *perms) {
  224. for _, update := range []struct {
  225. repoID int64
  226. accessMap map[int64]AccessMode
  227. }{
  228. {
  229. repoID: 1,
  230. accessMap: map[int64]AccessMode{
  231. 1: AccessModeWrite,
  232. 2: AccessModeWrite,
  233. 3: AccessModeAdmin,
  234. 4: AccessModeWrite,
  235. },
  236. },
  237. {
  238. repoID: 2,
  239. accessMap: map[int64]AccessMode{
  240. 1: AccessModeWrite,
  241. 2: AccessModeRead,
  242. 4: AccessModeWrite,
  243. 5: AccessModeWrite,
  244. },
  245. },
  246. {
  247. repoID: 1,
  248. accessMap: map[int64]AccessMode{
  249. 2: AccessModeWrite,
  250. 3: AccessModeAdmin,
  251. },
  252. },
  253. {
  254. repoID: 2,
  255. accessMap: map[int64]AccessMode{
  256. 1: AccessModeWrite,
  257. 2: AccessModeRead,
  258. 5: AccessModeWrite,
  259. },
  260. },
  261. } {
  262. err := db.SetRepoPerms(update.repoID, update.accessMap)
  263. if err != nil {
  264. t.Fatal(err)
  265. }
  266. }
  267. var accesses []*Access
  268. err := db.Order("user_id, repo_id").Find(&accesses).Error
  269. if err != nil {
  270. t.Fatal(err)
  271. }
  272. // Ignore ID fields
  273. for _, a := range accesses {
  274. a.ID = 0
  275. }
  276. expAccesses := []*Access{
  277. {UserID: 1, RepoID: 2, Mode: AccessModeWrite},
  278. {UserID: 2, RepoID: 1, Mode: AccessModeWrite},
  279. {UserID: 2, RepoID: 2, Mode: AccessModeRead},
  280. {UserID: 3, RepoID: 1, Mode: AccessModeAdmin},
  281. {UserID: 5, RepoID: 2, Mode: AccessModeWrite},
  282. }
  283. assert.Equal(t, expAccesses, accesses)
  284. }