appwrite/tests/e2e/Services/GraphQL/Legacy/AuthTest.php

255 lines
9.4 KiB
PHP
Raw Normal View History

2022-07-13 07:38:11 +00:00
<?php
namespace Tests\E2E\Services\GraphQL\Legacy;
2022-07-13 07:38:11 +00:00
use Tests\E2E\Client;
use Tests\E2E\Scopes\ProjectCustom;
use Tests\E2E\Scopes\Scope;
use Tests\E2E\Scopes\SideClient;
use Tests\E2E\Services\GraphQL\Base;
2023-01-16 09:25:40 +00:00
use Utopia\Database\Helpers\ID;
use Utopia\Database\Helpers\Permission;
2024-03-06 17:34:21 +00:00
use Utopia\Database\Helpers\Role;
2022-07-13 07:38:11 +00:00
2022-09-22 08:29:42 +00:00
class AuthTest extends Scope
2022-07-13 07:38:11 +00:00
{
use ProjectCustom;
use SideClient;
2022-09-22 08:29:42 +00:00
use Base;
2022-07-13 07:38:11 +00:00
private array $account1;
private array $account2;
private string $token1;
private string $token2;
private array $database;
private array $collection;
2022-07-13 07:38:11 +00:00
public function setUp(): void
{
parent::setUp();
$projectId = $this->getProject()['$id'];
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_ACCOUNT);
2022-07-13 07:38:11 +00:00
$email1 = 'test' . \rand() . '@test.com';
$email2 = 'test' . \rand() . '@test.com';
// Create account 1
$graphQLPayload = [
'query' => $query,
'variables' => [
2022-09-22 01:53:41 +00:00
'userId' => ID::unique(),
2022-07-13 07:38:11 +00:00
'name' => 'User Name',
'email' => $email1,
'password' => 'password',
],
];
$this->account1 = $this->client->call(Client::METHOD_POST, '/graphql', [
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
], $graphQLPayload);
// Create account 2
2022-09-22 08:22:10 +00:00
$graphQLPayload['variables']['userId'] = ID::unique();
2022-07-13 07:38:11 +00:00
$graphQLPayload['variables']['email'] = $email2;
2022-09-22 08:22:10 +00:00
2022-07-13 07:38:11 +00:00
$account2 = $this->client->call(Client::METHOD_POST, '/graphql', [
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
], $graphQLPayload);
// Create session 1
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_ACCOUNT_SESSION);
2022-07-13 07:38:11 +00:00
$graphQLPayload = [
'query' => $query,
'variables' => [
'email' => $email1,
'password' => 'password',
]
];
$session1 = $this->client->call(Client::METHOD_POST, '/graphql', [
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
], $graphQLPayload);
2023-12-08 23:36:01 +00:00
$this->token1 = $session1['cookies']['a_session_' . $projectId];
2022-07-13 07:38:11 +00:00
// Create session 2
$graphQLPayload['variables']['email'] = $email2;
2022-09-22 08:29:42 +00:00
2022-07-13 07:38:11 +00:00
$session2 = $this->client->call(Client::METHOD_POST, '/graphql', [
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
], $graphQLPayload);
2023-12-08 23:36:01 +00:00
$this->token2 = $session2['cookies']['a_session_' . $projectId];
2022-07-13 07:38:11 +00:00
// Create database
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_DATABASE);
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-09-22 01:53:41 +00:00
'databaseId' => ID::unique(),
2022-07-13 07:38:11 +00:00
'name' => 'Actors',
]
];
$this->database = $this->client->call(Client::METHOD_POST, '/graphql', [
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'x-appwrite-key' => $this->getProject()['apiKey'],
], $gqlPayload);
// Create collection
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_COLLECTION);
2022-12-08 03:08:57 +00:00
$userId = $this->account1['body']['data']['accountCreate']['_id'];
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-12-08 03:08:57 +00:00
'databaseId' => $this->database['body']['data']['databasesCreate']['_id'],
'collectionId' => ID::unique(),
2022-07-13 07:38:11 +00:00
'name' => 'Actors',
2022-09-21 07:11:49 +00:00
'documentSecurity' => true,
'permissions' => [
Permission::create(Role::user($userId))
]
2022-07-13 07:38:11 +00:00
]
];
$this->collection = $this->client->call(Client::METHOD_POST, '/graphql', [
2022-07-13 07:38:11 +00:00
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'x-appwrite-key' => $this->getProject()['apiKey'],
], $gqlPayload);
// Create string attribute
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_STRING_ATTRIBUTE);
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-12-08 03:08:57 +00:00
'databaseId' => $this->database['body']['data']['databasesCreate']['_id'],
'collectionId' => $this->collection['body']['data']['databasesCreateCollection']['_id'],
2022-07-13 07:38:11 +00:00
'key' => 'name',
'size' => 256,
'required' => true,
]
];
$this->client->call(Client::METHOD_POST, '/graphql', [
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'x-appwrite-key' => $this->getProject()['apiKey'],
], $gqlPayload);
sleep(1);
}
public function testInvalidAuth()
{
$projectId = $this->getProject()['$id'];
// Create document as account 1
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_DOCUMENT);
2022-12-08 03:08:57 +00:00
$userId = $this->account1['body']['data']['accountCreate']['_id'];
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-12-08 03:08:57 +00:00
'databaseId' => $this->database['body']['data']['databasesCreate']['_id'],
'collectionId' => $this->collection['body']['data']['databasesCreateCollection']['_id'],
'documentId' => ID::unique(),
2022-07-13 07:38:11 +00:00
'data' => [
'name' => 'John Doe',
],
2022-09-21 07:11:49 +00:00
'permissions' => [
Permission::read(Role::user($userId)),
Permission::update(Role::user($userId)),
Permission::delete(Role::user($userId)),
]
2022-07-13 07:38:11 +00:00
]
];
$document = $this->client->call(Client::METHOD_POST, '/graphql', [
2022-07-13 07:38:11 +00:00
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'cookie' => 'a_session_' . $projectId . '=' . $this->token1,
], $gqlPayload);
// Try to read as account 1
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::GET_DOCUMENT);
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-12-08 03:08:57 +00:00
'databaseId' => $this->database['body']['data']['databasesCreate']['_id'],
'collectionId' => $this->collection['body']['data']['databasesCreateCollection']['_id'],
'documentId' => $document['body']['data']['databasesCreateDocument']['_id'],
2022-07-13 07:38:11 +00:00
]
];
$document = $this->client->call(Client::METHOD_POST, '/graphql', [
2022-07-13 07:38:11 +00:00
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'cookie' => 'a_session_' . $projectId . '=' . $this->token1,
], $gqlPayload);
$this->assertIsArray($document['body']['data']['databasesGetDocument']);
$this->assertArrayNotHasKey('errors', $document['body']);
2022-07-13 07:38:11 +00:00
// Try to read as account 2
$document = $this->client->call(Client::METHOD_POST, '/graphql', [
2022-07-13 07:38:11 +00:00
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'cookie' => 'a_session_' . $projectId . '=' . $this->token2,
], $gqlPayload);
$this->assertArrayHasKey('errors', $document['body']);
2025-12-11 09:56:45 +00:00
$documentId = $gqlPayload['variables']['documentId'];
$this->assertEquals("Document with the requested ID '$documentId' could not be found.", $document['body']['errors'][0]['message']);
2022-07-13 07:38:11 +00:00
}
public function testValidAuth()
{
$projectId = $this->getProject()['$id'];
// Create document as account 1
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::CREATE_DOCUMENT);
2022-12-08 03:08:57 +00:00
$userId = $this->account1['body']['data']['accountCreate']['_id'];
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-12-08 03:08:57 +00:00
'databaseId' => $this->database['body']['data']['databasesCreate']['_id'],
'collectionId' => $this->collection['body']['data']['databasesCreateCollection']['_id'],
'documentId' => ID::unique(),
2022-07-13 07:38:11 +00:00
'data' => [
'name' => 'John Doe',
],
2022-09-21 08:17:17 +00:00
'permissions' => [
Permission::read(Role::user($userId)),
Permission::update(Role::user($userId)),
Permission::delete(Role::user($userId)),
],
2022-07-13 07:38:11 +00:00
]
];
$document = $this->client->call(Client::METHOD_POST, '/graphql', [
2022-07-13 07:38:11 +00:00
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'cookie' => 'a_session_' . $projectId . '=' . $this->token1,
], $gqlPayload);
// Try to delete as account 1
2025-08-19 11:03:18 +00:00
$query = $this->getQuery(self::DELETE_DOCUMENT);
2022-07-13 07:38:11 +00:00
$gqlPayload = [
'query' => $query,
'variables' => [
2022-12-08 03:08:57 +00:00
'databaseId' => $this->database['body']['data']['databasesCreate']['_id'],
'collectionId' => $this->collection['body']['data']['databasesCreateCollection']['_id'],
'documentId' => $document['body']['data']['databasesCreateDocument']['_id'],
2022-07-13 07:38:11 +00:00
]
];
$document = $this->client->call(Client::METHOD_POST, '/graphql', [
2022-07-13 07:38:11 +00:00
'content-type' => 'application/json',
'x-appwrite-project' => $projectId,
'cookie' => 'a_session_' . $projectId . '=' . $this->token1,
], $gqlPayload);
$this->assertIsNotArray($document['body']);
$this->assertEquals(204, $document['headers']['status-code']);
2022-07-13 07:38:11 +00:00
}
}