Classes List

Symfony\Component\Security\Core\Tests\Authorization\AccessDecisionManagerTest

 1 
 2 
 3 
 4 
 5 
 6 
 7 
 8 
 9 
 10 
 11 
 12 
 13 
 14 
 15 
 16 
 17 
 18 
 19 
 20 
 21 
 22 
 23 
 24 
 25 
 26 
 27 
 28 
 29 
 30 
 31 
 32 
 33 
 34 
 35 
 36 
 37 
 38 
 39 
 40 
 41 
 42 
 43 
 44 
 45 
 46 
 47 
 48 
 49 
 50 
 51 
 52 
 53 
 54 
 55 
 56 
 57 
 58 
 59 
 60 
 61 
 62 
 63 
 64 
 65 
 66 
 67 
 68 
 69 
 70 
 71 
 72 
 73 
 74 
 75 
 76 
 77 
 78 
 79 
 80 
 81 
 82 
 83 
 84 
 85 
 86 
 87 
 88 
 89 
 90 
 91 
 92 
 93 
 94 
 95 
 96 
 97 
 98 
 99 
 100 
 101 
 102 
 103 
 104 
 105 
 106 
 107 
 108 
 109 
 110 
 111 
 112 
 113 
 114 
 115 
 116 
 117 
 118 
 119 
 120 
 121 
 122 
 123 
 124 
 125 
 126 
 127 
 128 
 129 
 130 
 131 
 132 
 133 
 134 
 135 
 136 
 137 
 138 
 139 
 140 
 141 
 142 
 143 
 144 
 145 
 146 
 147 
 148 
 149 
 150 
 151 
 152 
 153 
 154 
 155 
 156 
 157 
 158 
 159 
 160 
 161 
 162 
 163 
 164 
 165 
 166 
 167 
 168 
 169 
 170 
 171 
 172 
 173 
 174 
 175 
<?php

/* * This file is part of the Symfony package. * * (c) Fabien Potencier <fabien@symfony.com> * * For the full copyright and license information, please view the LICENSE * file that was distributed with this source code. */


namespace Symfony\Component\Security\Core\Tests\Authorization;

use PHPUnit\Framework\TestCase;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Authorization\AccessDecisionManager;
use Symfony\Component\Security\Core\Authorization\Voter\VoterInterface;
use Symfony\Component\Security\Core\Exception\LogicException;
use Symfony\Component\Security\Core\Tests\Authorization\Stub\VoterWithoutInterface;

class AccessDecisionManagerTest extends TestCase
{
    /** * @expectedException \InvalidArgumentException */
    public function testSetUnsupportedStrategy()
    {
        new AccessDecisionManager(array($this->getVoter(VoterInterface::ACCESS_GRANTED)), 'fooBar');
    }

    /** * @dataProvider getStrategyTests */
    public function testStrategies($strategy$voters$allowIfAllAbstainDecisions$allowIfEqualGrantedDeniedDecisions$expected)
    {
        $token = $this->getMockBuilder('Symfony\Component\Security\Core\Authentication\Token\TokenInterface')->getMock();
        $manager = new AccessDecisionManager($voters$strategy$allowIfAllAbstainDecisions$allowIfEqualGrantedDeniedDecisions);

        $this->assertSame($expected$manager->decide($tokenarray('ROLE_FOO')));
    }

    /** * @dataProvider getStrategiesWith2RolesTests */
    public function testStrategiesWith2Roles($token$strategy$voter$expected)
    {
        $manager = new AccessDecisionManager(array($voter), $strategy);

        $this->assertSame($expected$manager->decide($tokenarray('ROLE_FOO''ROLE_BAR')));
    }

    public function getStrategiesWith2RolesTests()
    {
        $token = $this->getMockBuilder('Symfony\Component\Security\Core\Authentication\Token\TokenInterface')->getMock();

        return array(
            array($token'affirmative'$this->getVoter(VoterInterface::ACCESS_DENIED), false),
            array($token'affirmative'$this->getVoter(VoterInterface::ACCESS_GRANTED), true),

            array($token'consensus'$this->getVoter(VoterInterface::ACCESS_DENIED), false),
            array($token'consensus'$this->getVoter(VoterInterface::ACCESS_GRANTED), true),

            array($token'unanimous'$this->getVoterFor2Roles($tokenVoterInterface::ACCESS_DENIEDVoterInterface::ACCESS_DENIED), false),
            array($token'unanimous'$this->getVoterFor2Roles($tokenVoterInterface::ACCESS_DENIEDVoterInterface::ACCESS_GRANTED), false),
            array($token'unanimous'$this->getVoterFor2Roles($tokenVoterInterface::ACCESS_GRANTEDVoterInterface::ACCESS_DENIED), false),
            array($token'unanimous'$this->getVoterFor2Roles($tokenVoterInterface::ACCESS_GRANTEDVoterInterface::ACCESS_GRANTED), true),
        );
    }

    protected function getVoterFor2Roles($token$vote1$vote2)
    {
        $voter = $this->getMockBuilder('Symfony\Component\Security\Core\Authorization\Voter\VoterInterface')->getMock();
        $voter->expects($this->any())
              ->method('vote')
              ->will($this->returnValueMap(array(
                  array($tokennullarray('ROLE_FOO'), $vote1),
                  array($tokennullarray('ROLE_BAR'), $vote2),
              )))
        ;

        return $voter;
    }

    public function getStrategyTests()
    {
        return array(
            // affirmative
            array(AccessDecisionManager::STRATEGY_AFFIRMATIVE$this->getVoters(100), falsetruetrue),
            array(AccessDecisionManager::STRATEGY_AFFIRMATIVE$this->getVoters(120), falsetruetrue),
            array(AccessDecisionManager::STRATEGY_AFFIRMATIVE$this->getVoters(010), falsetruefalse),
            array(AccessDecisionManager::STRATEGY_AFFIRMATIVE$this->getVoters(001), falsetruefalse),
            array(AccessDecisionManager::STRATEGY_AFFIRMATIVE$this->getVoters(001), truetruetrue),

            // consensus
            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(100), falsetruetrue),
            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(120), falsetruefalse),
            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(210), falsetruetrue),

            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(001), falsetruefalse),

            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(001), truetruetrue),

            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(220), falsetruetrue),
            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(221), falsetruetrue),

            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(220), falsefalsefalse),
            array(AccessDecisionManager::STRATEGY_CONSENSUS$this->getVoters(221), falsefalsefalse),

            // unanimous
            array(AccessDecisionManager::STRATEGY_UNANIMOUS$this->getVoters(100), falsetruetrue),
            array(AccessDecisionManager::STRATEGY_UNANIMOUS$this->getVoters(101), falsetruetrue),
            array(AccessDecisionManager::STRATEGY_UNANIMOUS$this->getVoters(110), falsetruefalse),

            array(AccessDecisionManager::STRATEGY_UNANIMOUS$this->getVoters(002), falsetruefalse),
            array(AccessDecisionManager::STRATEGY_UNANIMOUS$this->getVoters(002), truetruetrue),
        );
    }

    protected function getVoters($grants$denies$abstains)
    {
        $voters = array();
        for ($i = 0$i < $grants++$i) {
            $voters[] = $this->getVoter(VoterInterface::ACCESS_GRANTED);
        }
        for ($i = 0$i < $denies++$i) {
            $voters[] = $this->getVoter(VoterInterface::ACCESS_DENIED);
        }
        for ($i = 0$i < $abstains++$i) {
            $voters[] = $this->getVoter(VoterInterface::ACCESS_ABSTAIN);
        }

        return $voters;
    }

    protected function getVoter($vote)
    {
        $voter = $this->getMockBuilder('Symfony\Component\Security\Core\Authorization\Voter\VoterInterface')->getMock();
        $voter->expects($this->any())
              ->method('vote')
              ->will($this->returnValue($vote));

        return $voter;
    }

    public function testVotingWrongTypeNoVoteMethod()
    {
        $exception = LogicException::class;
        $message = sprintf('stdClass should implement the %s interface when used as voter.'VoterInterface::class);

        if (method_exists($this'expectException')) {
            $this->expectException($exception);
            $this->expectExceptionMessage($message);
        } else {
            $this->setExpectedException($exception$message);
        }

        $adm = new AccessDecisionManager(array(new \stdClass()));
        $token = $this->getMockBuilder(TokenInterface::class)->getMock();

        $adm->decide($tokenarray('TEST'));
    }

    /** * @group legacy * @expectedDeprecation Calling vote() on an voter without Symfony\Component\Security\Core\Authorization\Voter\VoterInterface is deprecated as of 3.4 and will be removed in 4.0. Implement the Symfony\Component\Security\Core\Authorization\Voter\VoterInterface on your voter. */
    public function testVotingWrongTypeWithVote()
    {
        $adm = new AccessDecisionManager(array(new VoterWithoutInterface()));
        $token = $this->getMockBuilder(TokenInterface::class)->getMock();

        $adm->decide($tokenarray('TEST'));
    }
}