mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-10-08 05:43:18 +01:00
Compare commits
1 Commits
v0.20.1
...
feature/fi
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1162853f57 |
@@ -1,37 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Auth;
|
|
||||||
|
|
||||||
use Illuminate\Auth\EloquentUserProvider;
|
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
|
||||||
use Illuminate\Database\Eloquent\Model;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* User provider that only resolves non-placeholder users.
|
|
||||||
*
|
|
||||||
* Placeholder users are created by imports and when members are removed from an
|
|
||||||
* organization. They can share an email address with a real user, so resolving a user by
|
|
||||||
* email can return a placeholder instead of the real account. The login flow filters them
|
|
||||||
* out explicitly, but the password broker and the guard credential checks (for example the
|
|
||||||
* password confirmation) resolve users through the configured user provider.
|
|
||||||
*
|
|
||||||
* Registered as the "eloquent" provider driver in the AuthServiceProvider, so it replaces the
|
|
||||||
* built-in one for every provider in config/auth.php.
|
|
||||||
*/
|
|
||||||
class ActiveUserProvider extends EloquentUserProvider
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* @param Model|null $model
|
|
||||||
* @return Builder<Model>
|
|
||||||
*/
|
|
||||||
#[\Override]
|
|
||||||
protected function newModelQuery($model = null): Builder
|
|
||||||
{
|
|
||||||
$query = parent::newModelQuery($model);
|
|
||||||
$query->getQuery()->where('is_placeholder', '=', false);
|
|
||||||
|
|
||||||
return $query;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -24,7 +24,6 @@ class ImportRequest extends BaseFormRequest
|
|||||||
'data' => [
|
'data' => [
|
||||||
'required',
|
'required',
|
||||||
'string',
|
'string',
|
||||||
'max:'.config('import.max_data_size'),
|
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -38,10 +38,7 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string|null $pending_email
|
* @property string|null $pending_email
|
||||||
* @property Carbon|null $email_verified_at
|
* @property Carbon|null $email_verified_at
|
||||||
* @property string|null $password
|
* @property string|null $password
|
||||||
* @property string|null $remember_token
|
|
||||||
* @property string|null $two_factor_secret
|
* @property string|null $two_factor_secret
|
||||||
* @property string|null $two_factor_recovery_codes
|
|
||||||
* @property Carbon|null $two_factor_confirmed_at
|
|
||||||
* @property string $timezone
|
* @property string $timezone
|
||||||
* @property bool $is_placeholder
|
* @property bool $is_placeholder
|
||||||
* @property Weekday $week_start
|
* @property Weekday $week_start
|
||||||
@@ -153,9 +150,7 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
|
|
||||||
public function canAccessPanel(Panel $panel): bool
|
public function canAccessPanel(Panel $panel): bool
|
||||||
{
|
{
|
||||||
return $this->is_placeholder === false
|
return in_array($this->email, config('auth.super_admins', []), true) && $this->hasVerifiedEmail();
|
||||||
&& in_array($this->email, config('auth.super_admins', []), true)
|
|
||||||
&& $this->hasVerifiedEmail();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public function isMemberOfOrganization(Organization $organization): bool
|
public function isMemberOfOrganization(Organization $organization): bool
|
||||||
|
|||||||
@@ -4,14 +4,11 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Providers;
|
namespace App\Providers;
|
||||||
|
|
||||||
use App\Auth\ActiveUserProvider;
|
|
||||||
use App\Models\Passport\AuthCode;
|
use App\Models\Passport\AuthCode;
|
||||||
use App\Models\Passport\Client;
|
use App\Models\Passport\Client;
|
||||||
use App\Models\Passport\RefreshToken;
|
use App\Models\Passport\RefreshToken;
|
||||||
use App\Models\Passport\Token;
|
use App\Models\Passport\Token;
|
||||||
use Illuminate\Contracts\Foundation\Application;
|
|
||||||
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
|
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
|
||||||
use Illuminate\Support\Facades\Auth;
|
|
||||||
use Laravel\Passport\Passport;
|
use Laravel\Passport\Passport;
|
||||||
|
|
||||||
class AuthServiceProvider extends ServiceProvider
|
class AuthServiceProvider extends ServiceProvider
|
||||||
@@ -29,13 +26,6 @@ class AuthServiceProvider extends ServiceProvider
|
|||||||
*/
|
*/
|
||||||
public function boot(): void
|
public function boot(): void
|
||||||
{
|
{
|
||||||
// Replaces the built-in eloquent user provider, so that no authentication flow can
|
|
||||||
// resolve a placeholder user. The driver name is kept, because Passport recognizes
|
|
||||||
// only providers that are configured with the driver "eloquent".
|
|
||||||
Auth::provider('eloquent', function (Application $app, array $config): ActiveUserProvider {
|
|
||||||
return new ActiveUserProvider($app->make('hash'), $config['model']);
|
|
||||||
});
|
|
||||||
|
|
||||||
// define scopes for passport tokens
|
// define scopes for passport tokens
|
||||||
Passport::tokensCan([
|
Passport::tokensCan([
|
||||||
'create' => 'Create resources',
|
'create' => 'Create resources',
|
||||||
|
|||||||
@@ -9,8 +9,11 @@ use App\Service\Import\Importers\ImporterContract;
|
|||||||
use App\Service\Import\Importers\ImporterProvider;
|
use App\Service\Import\Importers\ImporterProvider;
|
||||||
use App\Service\Import\Importers\ImportException;
|
use App\Service\Import\Importers\ImportException;
|
||||||
use App\Service\Import\Importers\ReportDto;
|
use App\Service\Import\Importers\ReportDto;
|
||||||
|
use Illuminate\Support\Carbon;
|
||||||
use Illuminate\Support\Facades\Cache;
|
use Illuminate\Support\Facades\Cache;
|
||||||
use Illuminate\Support\Facades\DB;
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Storage;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
|
||||||
class ImportService
|
class ImportService
|
||||||
{
|
{
|
||||||
@@ -22,6 +25,8 @@ class ImportService
|
|||||||
/** @var ImporterContract $importer */
|
/** @var ImporterContract $importer */
|
||||||
$importer = app(ImporterProvider::class)->getImporter($importerType);
|
$importer = app(ImporterProvider::class)->getImporter($importerType);
|
||||||
$importer->init($organization);
|
$importer->init($organization);
|
||||||
|
Storage::disk(config('filesystems.default'))
|
||||||
|
->put('import/'.Carbon::now()->toDateString().'-'.$organization->getKey().'-'.Str::uuid(), $data);
|
||||||
|
|
||||||
$lock = Cache::lock('import:'.$organization->getKey(), config('octane.max_execution_time', 60) + 1);
|
$lock = Cache::lock('import:'.$organization->getKey(), config('octane.max_execution_time', 60) + 1);
|
||||||
|
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ use Illuminate\Support\Str;
|
|||||||
use League\Csv\Reader;
|
use League\Csv\Reader;
|
||||||
use Override;
|
use Override;
|
||||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||||
|
use ZipArchive;
|
||||||
|
|
||||||
class SolidtimeImporter extends DefaultImporter
|
class SolidtimeImporter extends DefaultImporter
|
||||||
{
|
{
|
||||||
@@ -33,10 +34,16 @@ class SolidtimeImporter extends DefaultImporter
|
|||||||
$temporaryDirectoryZip = null;
|
$temporaryDirectoryZip = null;
|
||||||
$temporaryDirectory = null;
|
$temporaryDirectory = null;
|
||||||
try {
|
try {
|
||||||
|
$zip = new ZipArchive;
|
||||||
$temporaryDirectoryZip = TemporaryDirectory::make();
|
$temporaryDirectoryZip = TemporaryDirectory::make();
|
||||||
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
|
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
|
||||||
|
$res = $zip->open($temporaryDirectoryZip->path('import.zip'), ZipArchive::RDONLY);
|
||||||
|
if ($res !== true) {
|
||||||
|
throw new ImportException('Invalid ZIP, error code: '.$res);
|
||||||
|
}
|
||||||
$temporaryDirectory = TemporaryDirectory::make();
|
$temporaryDirectory = TemporaryDirectory::make();
|
||||||
app(ZipImportHelper::class)->extract($temporaryDirectoryZip->path('import.zip'), $temporaryDirectory->path());
|
$zip->extractTo($temporaryDirectory->path());
|
||||||
|
$zip->close();
|
||||||
|
|
||||||
if (! file_exists($temporaryDirectory->path('meta.json'))) {
|
if (! file_exists($temporaryDirectory->path('meta.json'))) {
|
||||||
throw new ImportException('File "meta.json" missing in ZIP');
|
throw new ImportException('File "meta.json" missing in ZIP');
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ use Illuminate\Support\Str;
|
|||||||
use Override;
|
use Override;
|
||||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||||
use ValueError;
|
use ValueError;
|
||||||
|
use ZipArchive;
|
||||||
|
|
||||||
class TogglDataImporter extends DefaultImporter
|
class TogglDataImporter extends DefaultImporter
|
||||||
{
|
{
|
||||||
@@ -25,10 +26,16 @@ class TogglDataImporter extends DefaultImporter
|
|||||||
$temporaryDirectoryZip = null;
|
$temporaryDirectoryZip = null;
|
||||||
$temporaryDirectory = null;
|
$temporaryDirectory = null;
|
||||||
try {
|
try {
|
||||||
|
$zip = new ZipArchive;
|
||||||
$temporaryDirectoryZip = TemporaryDirectory::make();
|
$temporaryDirectoryZip = TemporaryDirectory::make();
|
||||||
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
|
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
|
||||||
|
$res = $zip->open($temporaryDirectoryZip->path('import.zip'), ZipArchive::RDONLY);
|
||||||
|
if ($res !== true) {
|
||||||
|
throw new ImportException('Invalid ZIP, error code: '.$res);
|
||||||
|
}
|
||||||
$temporaryDirectory = TemporaryDirectory::make();
|
$temporaryDirectory = TemporaryDirectory::make();
|
||||||
app(ZipImportHelper::class)->extract($temporaryDirectoryZip->path('import.zip'), $temporaryDirectory->path());
|
$zip->extractTo($temporaryDirectory->path());
|
||||||
|
$zip->close();
|
||||||
if (! file_exists($temporaryDirectory->path('clients.json'))) {
|
if (! file_exists($temporaryDirectory->path('clients.json'))) {
|
||||||
throw new ImportException('File "clients.json" missing in ZIP');
|
throw new ImportException('File "clients.json" missing in ZIP');
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,129 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Service\Import\Importers;
|
|
||||||
|
|
||||||
use ZipArchive;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Extracts uploaded ZIP archives with limits on file count, total uncompressed
|
|
||||||
* size and entry paths, so a small malicious archive can not fill the disk
|
|
||||||
* (decompression bomb) or write outside the target directory (zip slip).
|
|
||||||
*/
|
|
||||||
class ZipImportHelper
|
|
||||||
{
|
|
||||||
private const int CHUNK_SIZE = 1024 * 1024;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @throws ImportException
|
|
||||||
*/
|
|
||||||
public function extract(string $zipPath, string $targetPath): void
|
|
||||||
{
|
|
||||||
$zip = new ZipArchive;
|
|
||||||
$res = $zip->open($zipPath, ZipArchive::RDONLY);
|
|
||||||
if ($res !== true) {
|
|
||||||
throw new ImportException('Invalid ZIP, error code: '.$res);
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
$maxFiles = (int) config('import.zip_max_files');
|
|
||||||
$maxUncompressedSize = (int) config('import.zip_max_uncompressed_size');
|
|
||||||
|
|
||||||
if ($zip->numFiles > $maxFiles) {
|
|
||||||
throw new ImportException('ZIP contains too many files, maximum is '.$maxFiles);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check the sizes declared in the archive before writing anything to disk
|
|
||||||
$declaredSize = 0;
|
|
||||||
for ($index = 0; $index < $zip->numFiles; $index++) {
|
|
||||||
$stat = $zip->statIndex($index);
|
|
||||||
if ($stat === false) {
|
|
||||||
throw new ImportException('Invalid ZIP entry');
|
|
||||||
}
|
|
||||||
$this->validateEntryName($stat['name']);
|
|
||||||
$declaredSize += $stat['size'];
|
|
||||||
if ($declaredSize > $maxUncompressedSize) {
|
|
||||||
throw new ImportException('ZIP uncompressed size exceeds the maximum of '.$maxUncompressedSize.' bytes');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// The declared sizes can be forged, so the written bytes are counted as well
|
|
||||||
$writtenSize = 0;
|
|
||||||
for ($index = 0; $index < $zip->numFiles; $index++) {
|
|
||||||
$stat = $zip->statIndex($index);
|
|
||||||
if ($stat === false) {
|
|
||||||
throw new ImportException('Invalid ZIP entry');
|
|
||||||
}
|
|
||||||
$name = $stat['name'];
|
|
||||||
$entryPath = $targetPath.DIRECTORY_SEPARATOR.$name;
|
|
||||||
|
|
||||||
if (str_ends_with($name, '/')) {
|
|
||||||
$this->ensureDirectoryExists($entryPath);
|
|
||||||
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
$this->ensureDirectoryExists(dirname($entryPath));
|
|
||||||
|
|
||||||
$stream = $zip->getStreamIndex($index);
|
|
||||||
if ($stream === false) {
|
|
||||||
throw new ImportException('ZIP entry "'.$name.'" can not be read');
|
|
||||||
}
|
|
||||||
$target = fopen($entryPath, 'wb');
|
|
||||||
if ($target === false) {
|
|
||||||
fclose($stream);
|
|
||||||
throw new ImportException('ZIP entry "'.$name.'" can not be extracted');
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
while (! feof($stream)) {
|
|
||||||
$chunk = fread($stream, self::CHUNK_SIZE);
|
|
||||||
if ($chunk === false) {
|
|
||||||
throw new ImportException('ZIP entry "'.$name.'" can not be read');
|
|
||||||
}
|
|
||||||
$writtenSize += strlen($chunk);
|
|
||||||
if ($writtenSize > $maxUncompressedSize) {
|
|
||||||
throw new ImportException('ZIP uncompressed size exceeds the maximum of '.$maxUncompressedSize.' bytes');
|
|
||||||
}
|
|
||||||
fwrite($target, $chunk);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
fclose($target);
|
|
||||||
fclose($stream);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
$zip->close();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @throws ImportException
|
|
||||||
*/
|
|
||||||
private function validateEntryName(string $name): void
|
|
||||||
{
|
|
||||||
if ($name === '' || str_contains($name, "\0") || str_contains($name, '\\') || str_starts_with($name, '/')) {
|
|
||||||
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
|
|
||||||
}
|
|
||||||
if (preg_match('/^[a-zA-Z]:/', $name) === 1) {
|
|
||||||
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
|
|
||||||
}
|
|
||||||
foreach (explode('/', rtrim($name, '/')) as $segment) {
|
|
||||||
if ($segment === '' || $segment === '..') {
|
|
||||||
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @throws ImportException
|
|
||||||
*/
|
|
||||||
private function ensureDirectoryExists(string $path): void
|
|
||||||
{
|
|
||||||
if (is_dir($path)) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (! mkdir($path, 0700, true) && ! is_dir($path)) {
|
|
||||||
throw new ImportException('Directory "'.$path.'" can not be created');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -218,16 +218,7 @@ class MemberService
|
|||||||
|
|
||||||
$placeholderUser = $user->replicate();
|
$placeholderUser = $user->replicate();
|
||||||
$placeholderUser->is_placeholder = true;
|
$placeholderUser->is_placeholder = true;
|
||||||
// Reset authentication relevant properties on the placeholder user
|
$placeholderUser->current_team_id = $member->organization_id;
|
||||||
$placeholderUser->password = null;
|
|
||||||
$placeholderUser->remember_token = null;
|
|
||||||
$placeholderUser->two_factor_secret = null;
|
|
||||||
$placeholderUser->two_factor_recovery_codes = null;
|
|
||||||
$placeholderUser->two_factor_confirmed_at = null;
|
|
||||||
$placeholderUser->email_verified_at = null;
|
|
||||||
$placeholderUser->pending_email = null;
|
|
||||||
$placeholderUser->current_team_id = null;
|
|
||||||
$placeholderUser->profile_photo_path = null;
|
|
||||||
$placeholderUser->save();
|
$placeholderUser->save();
|
||||||
|
|
||||||
$member->user()->associate($placeholderUser);
|
$member->user()->associate($placeholderUser);
|
||||||
|
|||||||
@@ -1,34 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
return [
|
|
||||||
|
|
||||||
/*
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
| Import payload limit
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
|
|
|
||||||
| Maximum length of the base64 encoded "data" field of an import request in
|
|
||||||
| bytes. Requests with a larger payload are rejected with a validation error.
|
|
||||||
|
|
|
||||||
*/
|
|
||||||
|
|
||||||
'max_data_size' => (int) (env('IMPORT_MAX_DATA_SIZE') ?: 50 * 1024 * 1024),
|
|
||||||
|
|
||||||
/*
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
| ZIP extraction limits
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
|
|
|
||||||
| Limits applied to ZIP based importers before and during extraction to
|
|
||||||
| protect the instance against decompression bombs. The uncompressed size
|
|
||||||
| is the sum of all files in the archive in bytes.
|
|
||||||
|
|
|
||||||
*/
|
|
||||||
|
|
||||||
'zip_max_files' => (int) (env('IMPORT_ZIP_MAX_FILES') ?: 100),
|
|
||||||
|
|
||||||
'zip_max_uncompressed_size' => (int) (env('IMPORT_ZIP_MAX_UNCOMPRESSED_SIZE') ?: 500 * 1024 * 1024),
|
|
||||||
|
|
||||||
];
|
|
||||||
@@ -1,53 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
use Illuminate\Database\Migrations\Migration;
|
|
||||||
use Illuminate\Database\Query\Builder;
|
|
||||||
use Illuminate\Support\Facades\DB;
|
|
||||||
|
|
||||||
return new class extends Migration
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Placeholder users used to be created as a full copy of the user they were made from,
|
|
||||||
* which included the credentials and the account state of that user. A placeholder is a
|
|
||||||
* stand-in for a person in one organization, not an account, and the row shares the email
|
|
||||||
* address with the real account, so these values are removed from the placeholders that
|
|
||||||
* already exist. The organization a placeholder belongs to is recorded on its member row.
|
|
||||||
*/
|
|
||||||
public function up(): void
|
|
||||||
{
|
|
||||||
DB::table('users')
|
|
||||||
->where('is_placeholder', '=', true)
|
|
||||||
->where(function (Builder $builder): void {
|
|
||||||
$builder->whereNotNull('password')
|
|
||||||
->orWhereNotNull('remember_token')
|
|
||||||
->orWhereNotNull('two_factor_secret')
|
|
||||||
->orWhereNotNull('two_factor_recovery_codes')
|
|
||||||
->orWhereNotNull('two_factor_confirmed_at')
|
|
||||||
->orWhereNotNull('email_verified_at')
|
|
||||||
->orWhereNotNull('pending_email')
|
|
||||||
->orWhereNotNull('current_team_id')
|
|
||||||
->orWhereNotNull('profile_photo_path');
|
|
||||||
})
|
|
||||||
->update([
|
|
||||||
'password' => null,
|
|
||||||
'remember_token' => null,
|
|
||||||
'two_factor_secret' => null,
|
|
||||||
'two_factor_recovery_codes' => null,
|
|
||||||
'two_factor_confirmed_at' => null,
|
|
||||||
'email_verified_at' => null,
|
|
||||||
'pending_email' => null,
|
|
||||||
'current_team_id' => null,
|
|
||||||
'profile_photo_path' => null,
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Reverse the migrations.
|
|
||||||
*/
|
|
||||||
public function down(): void
|
|
||||||
{
|
|
||||||
//
|
|
||||||
}
|
|
||||||
};
|
|
||||||
@@ -6,7 +6,6 @@ namespace Tests\Feature;
|
|||||||
|
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use Illuminate\Foundation\Testing\RefreshDatabase;
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
||||||
use Illuminate\Support\Facades\Hash;
|
|
||||||
use Tests\TestCase;
|
use Tests\TestCase;
|
||||||
|
|
||||||
class PasswordConfirmationTest extends TestCase
|
class PasswordConfirmationTest extends TestCase
|
||||||
@@ -44,43 +43,4 @@ class PasswordConfirmationTest extends TestCase
|
|||||||
|
|
||||||
$response->assertSessionHasErrors();
|
$response->assertSessionHasErrors();
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_password_can_be_confirmed_if_a_placeholder_user_with_the_same_email_exists(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
// Placeholders created by an import have no password at all. The placeholder is created
|
|
||||||
// first so that it would be returned by an unordered lookup by email.
|
|
||||||
$email = 'shared@example.com';
|
|
||||||
User::factory()->placeholder()->create(['email' => $email, 'password' => null]);
|
|
||||||
$user = User::factory()->create(['email' => $email, 'password' => Hash::make('secret-password')]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$response = $this->actingAs($user)->post('/user/confirm-password', [
|
|
||||||
'password' => 'secret-password',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$response->assertRedirect();
|
|
||||||
$response->assertSessionHasNoErrors();
|
|
||||||
$this->assertTrue($this->app['session']->has('auth.password_confirmed_at'));
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_password_confirmation_ignores_the_password_of_a_placeholder_user_with_the_same_email(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
// Placeholders created by removing a member copy the password hash as of the removal,
|
|
||||||
// so the placeholder holds a password that the real user has since replaced.
|
|
||||||
$email = 'shared@example.com';
|
|
||||||
User::factory()->placeholder()->create(['email' => $email, 'password' => Hash::make('outdated-password')]);
|
|
||||||
$user = User::factory()->create(['email' => $email, 'password' => Hash::make('current-password')]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$response = $this->actingAs($user)->post('/user/confirm-password', [
|
|
||||||
'password' => 'outdated-password',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$response->assertSessionHasErrors();
|
|
||||||
$this->assertFalse($this->app['session']->has('auth.password_confirmed_at'));
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ namespace Tests\Feature;
|
|||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use Illuminate\Auth\Notifications\ResetPassword;
|
use Illuminate\Auth\Notifications\ResetPassword;
|
||||||
use Illuminate\Foundation\Testing\RefreshDatabase;
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
||||||
use Illuminate\Support\Facades\Hash;
|
|
||||||
use Illuminate\Support\Facades\Notification;
|
use Illuminate\Support\Facades\Notification;
|
||||||
use Laravel\Fortify\Features;
|
use Laravel\Fortify\Features;
|
||||||
use Tests\TestCase;
|
use Tests\TestCase;
|
||||||
@@ -94,62 +93,4 @@ class PasswordResetTest extends TestCase
|
|||||||
return true;
|
return true;
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_password_reset_targets_the_real_user_when_a_placeholder_user_with_the_same_email_exists(): void
|
|
||||||
{
|
|
||||||
|
|
||||||
Notification::fake();
|
|
||||||
|
|
||||||
// The placeholder is created first so that it would be returned by an unordered lookup by email
|
|
||||||
$email = 'shared@example.com';
|
|
||||||
$placeholder = User::factory()->placeholder()->create(['email' => $email]);
|
|
||||||
$user = User::factory()->create(['email' => $email]);
|
|
||||||
$placeholderPasswordBefore = $placeholder->password;
|
|
||||||
|
|
||||||
$response = $this->post('/forgot-password', [
|
|
||||||
'email' => $email,
|
|
||||||
]);
|
|
||||||
|
|
||||||
$response->assertSessionHasNoErrors();
|
|
||||||
Notification::assertNotSentTo($placeholder, ResetPassword::class);
|
|
||||||
Notification::assertSentTo($user, ResetPassword::class, function (ResetPassword $notification) use ($email) {
|
|
||||||
$response = $this->post('/reset-password', [
|
|
||||||
'token' => $notification->token,
|
|
||||||
'email' => $email,
|
|
||||||
'password' => 'new-password-123',
|
|
||||||
'password_confirmation' => 'new-password-123',
|
|
||||||
]);
|
|
||||||
|
|
||||||
$response->assertSessionHasNoErrors();
|
|
||||||
|
|
||||||
return true;
|
|
||||||
});
|
|
||||||
|
|
||||||
$placeholder->refresh();
|
|
||||||
$user->refresh();
|
|
||||||
$this->assertSame($placeholderPasswordBefore, $placeholder->password);
|
|
||||||
$this->assertTrue(Hash::check('new-password-123', $user->password));
|
|
||||||
|
|
||||||
$response = $this->post('/login', [
|
|
||||||
'email' => $email,
|
|
||||||
'password' => 'new-password-123',
|
|
||||||
]);
|
|
||||||
|
|
||||||
$response->assertSessionHasNoErrors();
|
|
||||||
$this->assertAuthenticatedAs($user);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_password_reset_link_is_not_sent_if_only_a_placeholder_user_with_the_email_exists(): void
|
|
||||||
{
|
|
||||||
Notification::fake();
|
|
||||||
|
|
||||||
$placeholder = User::factory()->placeholder()->create();
|
|
||||||
|
|
||||||
$response = $this->post('/forgot-password', [
|
|
||||||
'email' => $placeholder->email,
|
|
||||||
]);
|
|
||||||
|
|
||||||
$response->assertSessionHasErrors('email');
|
|
||||||
Notification::assertNothingSent();
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,90 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace Tests\Unit\Auth;
|
|
||||||
|
|
||||||
use App\Auth\ActiveUserProvider;
|
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Support\Facades\Auth;
|
|
||||||
use PHPUnit\Framework\Attributes\CoversClass;
|
|
||||||
use Tests\TestCaseWithDatabase;
|
|
||||||
|
|
||||||
#[CoversClass(ActiveUserProvider::class)]
|
|
||||||
class ActiveUserProviderTest extends TestCaseWithDatabase
|
|
||||||
{
|
|
||||||
public function test_password_broker_uses_the_active_user_provider(): void
|
|
||||||
{
|
|
||||||
// Act
|
|
||||||
$brokerProvider = Auth::createUserProvider(config('auth.passwords.users.provider'));
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertInstanceOf(ActiveUserProvider::class, $brokerProvider);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_api_guard_uses_the_active_user_provider(): void
|
|
||||||
{
|
|
||||||
// Act
|
|
||||||
$guardProvider = Auth::createUserProvider(config('auth.guards.api.provider'));
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertInstanceOf(ActiveUserProvider::class, $guardProvider);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_web_guard_uses_the_active_user_provider(): void
|
|
||||||
{
|
|
||||||
// Act
|
|
||||||
$guardProvider = Auth::createUserProvider(config('auth.guards.web.provider'));
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertInstanceOf(ActiveUserProvider::class, $guardProvider);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_retrieve_by_credentials_ignores_placeholder_users_with_the_same_email(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$email = 'shared@example.com';
|
|
||||||
$placeholder = User::factory()->placeholder()->create(['email' => $email]);
|
|
||||||
$user = User::factory()->create(['email' => $email]);
|
|
||||||
$provider = Auth::createUserProvider('users');
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$result = $provider->retrieveByCredentials(['email' => $email]);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertInstanceOf(User::class, $result);
|
|
||||||
$this->assertTrue($user->is($result));
|
|
||||||
$this->assertFalse($placeholder->is($result));
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_retrieve_by_credentials_returns_null_if_only_a_placeholder_user_exists(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$email = 'placeholder-only@example.com';
|
|
||||||
User::factory()->placeholder()->create(['email' => $email]);
|
|
||||||
$provider = Auth::createUserProvider('users');
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$result = $provider->retrieveByCredentials(['email' => $email]);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertNull($result);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_retrieve_by_id_returns_null_for_placeholder_users(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$placeholder = User::factory()->placeholder()->create();
|
|
||||||
$user = User::factory()->create();
|
|
||||||
$provider = Auth::createUserProvider('users');
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$placeholderResult = $provider->retrieveById($placeholder->getKey());
|
|
||||||
$userResult = $provider->retrieveById($user->getKey());
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertNull($placeholderResult);
|
|
||||||
$this->assertInstanceOf(User::class, $userResult);
|
|
||||||
$this->assertTrue($user->is($userResult));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -97,29 +97,6 @@ class ImportEndpointTest extends ApiEndpointTestAbstract
|
|||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_import_fails_if_data_exceeds_maximum_size(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
config(['import.max_data_size' => 16]);
|
|
||||||
$user = $this->createUserWithPermission([
|
|
||||||
'import',
|
|
||||||
]);
|
|
||||||
$this->mock(ImportService::class, function (MockInterface $mock): void {
|
|
||||||
$mock->shouldNotReceive('import');
|
|
||||||
});
|
|
||||||
Passport::actingAs($user->user);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$response = $this->postJson(route('api.v1.import.import', ['organization' => $user->organization->getKey()]), [
|
|
||||||
'type' => 'toggl_time_entries',
|
|
||||||
'data' => base64_encode(str_repeat('a', 15)),
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$response->assertStatus(422);
|
|
||||||
$response->assertJsonValidationErrors(['data']);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_import_return_error_message_if_import_fails(): void
|
public function test_import_return_error_message_if_import_fails(): void
|
||||||
{
|
{
|
||||||
// Arrange
|
// Arrange
|
||||||
|
|||||||
@@ -105,9 +105,6 @@ class OrganizationInvitationEndpointTest extends EndpointTestAbstract
|
|||||||
$this->assertDatabaseMissing(OrganizationInvitation::class, [
|
$this->assertDatabaseMissing(OrganizationInvitation::class, [
|
||||||
'id' => $invitation->getKey(),
|
'id' => $invitation->getKey(),
|
||||||
]);
|
]);
|
||||||
// Joining sets the organization as the current one for the user, independently of the
|
|
||||||
// placeholders that were merged into them
|
|
||||||
$this->assertSame($user->organization->getKey(), $user2->user->fresh()->current_team_id);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_accepting_invitation_while_logged_out_redirects_to_login(): void
|
public function test_accepting_invitation_while_logged_out_redirects_to_login(): void
|
||||||
|
|||||||
@@ -53,23 +53,6 @@ class UserModelTest extends ModelTestAbstract
|
|||||||
$this->assertTrue($canAccess);
|
$this->assertTrue($canAccess);
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_placeholder_user_with_a_super_admin_email_can_not_access_admin_panel(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
Config::set('auth.super_admins', ['some@email.test', 'other@email.test']);
|
|
||||||
$user = User::factory()->placeholder()->create([
|
|
||||||
'email' => 'some@email.test',
|
|
||||||
]);
|
|
||||||
$panelProvider = new AdminPanelProvider(app());
|
|
||||||
$mainPanel = $panelProvider->panel(Panel::make());
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$canAccess = $user->canAccessPanel($mainPanel);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertFalse($canAccess);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_scope_belongs_to_organization_returns_only_users_of_organization_including_owners(): void
|
public function test_scope_belongs_to_organization_returns_only_users_of_organization_including_owners(): void
|
||||||
{
|
{
|
||||||
// Arrange
|
// Arrange
|
||||||
|
|||||||
@@ -412,11 +412,10 @@ class DeletionServiceTest extends TestCaseWithDatabase
|
|||||||
$this->assertDatabaseHas(Organization::class, [
|
$this->assertDatabaseHas(Organization::class, [
|
||||||
'id' => $organizationOfA->getKey(),
|
'id' => $organizationOfA->getKey(),
|
||||||
]);
|
]);
|
||||||
// The placeholder user should exist and must not reference the deleted organization,
|
// The placeholder user should exist with current_team_id set to the org where they are a placeholder
|
||||||
// which is what caused the foreign key violation in #989
|
|
||||||
$placeholderUser = User::query()->where('is_placeholder', true)->first();
|
$placeholderUser = User::query()->where('is_placeholder', true)->first();
|
||||||
$this->assertNotNull($placeholderUser);
|
$this->assertNotNull($placeholderUser);
|
||||||
$this->assertNull($placeholderUser->current_team_id);
|
$this->assertSame($organizationOfA->getKey(), $placeholderUser->current_team_id);
|
||||||
$this->assertDatabaseHas(Member::class, [
|
$this->assertDatabaseHas(Member::class, [
|
||||||
'id' => $memberBInOrgA->getKey(),
|
'id' => $memberBInOrgA->getKey(),
|
||||||
'user_id' => $placeholderUser->getKey(),
|
'user_id' => $placeholderUser->getKey(),
|
||||||
|
|||||||
@@ -41,7 +41,6 @@ class ImportServiceTest extends TestCase
|
|||||||
$this->assertSame(1, $report->usersCreated);
|
$this->assertSame(1, $report->usersCreated);
|
||||||
$this->assertSame(2, $report->projectsCreated);
|
$this->assertSame(2, $report->projectsCreated);
|
||||||
$this->assertSame(1, $report->clientsCreated);
|
$this->assertSame(1, $report->clientsCreated);
|
||||||
Storage::disk(config('filesystems.default'))->assertDirectoryEmpty('import');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_import_releases_lock_if_an_exception_happens_during_the_import(): void
|
public function test_import_releases_lock_if_an_exception_happens_during_the_import(): void
|
||||||
|
|||||||
@@ -42,31 +42,6 @@ class SolidtimeImporterTest extends ImporterTestAbstract
|
|||||||
$this->fail();
|
$this->fail();
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_import_throws_exception_if_zip_exceeds_uncompressed_size_limit(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
config(['import.zip_max_uncompressed_size' => 10]);
|
|
||||||
$zipPath = $this->createTestZip('solidtime_import_test_1');
|
|
||||||
$timezone = 'Europe/Vienna';
|
|
||||||
$organization = Organization::factory()->create();
|
|
||||||
$importer = new SolidtimeImporter;
|
|
||||||
$importer->init($organization);
|
|
||||||
$data = file_get_contents($zipPath);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
$importer->importData($data, $timezone);
|
|
||||||
} catch (Exception $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertInstanceOf(ImportException::class, $e);
|
|
||||||
$this->assertSame('ZIP uncompressed size exceeds the maximum of 10 bytes', $e->getMessage());
|
|
||||||
$this->assertSame(0, $importer->getReport()->timeEntriesCreated);
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_import_of_test_file_succeeds(): void
|
public function test_import_of_test_file_succeeds(): void
|
||||||
{
|
{
|
||||||
// Arrange
|
// Arrange
|
||||||
|
|||||||
@@ -39,31 +39,6 @@ class TogglDataImporterTest extends ImporterTestAbstract
|
|||||||
$this->fail();
|
$this->fail();
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_import_throws_exception_if_zip_contains_too_many_files(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
config(['import.zip_max_files' => 1]);
|
|
||||||
$zipPath = $this->createTestZip('toggl_data_import_test_1');
|
|
||||||
$timezone = 'Europe/Vienna';
|
|
||||||
$organization = Organization::factory()->create();
|
|
||||||
$importer = new TogglDataImporter;
|
|
||||||
$importer->init($organization);
|
|
||||||
$data = file_get_contents($zipPath);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
$importer->importData($data, $timezone);
|
|
||||||
} catch (Exception $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertInstanceOf(ImportException::class, $e);
|
|
||||||
$this->assertSame('ZIP contains too many files, maximum is 1', $e->getMessage());
|
|
||||||
$this->assertSame(0, $importer->getReport()->projectsCreated);
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_import_of_test_file_succeeds(): void
|
public function test_import_of_test_file_succeeds(): void
|
||||||
{
|
{
|
||||||
// Arrange
|
// Arrange
|
||||||
|
|||||||
@@ -1,254 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace Tests\Unit\Service\Import\Importers;
|
|
||||||
|
|
||||||
use App\Service\Import\Importers\ImportException;
|
|
||||||
use App\Service\Import\Importers\ZipImportHelper;
|
|
||||||
use PHPUnit\Framework\Attributes\CoversClass;
|
|
||||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
|
||||||
use Tests\TestCase;
|
|
||||||
use ZipArchive;
|
|
||||||
|
|
||||||
#[CoversClass(ZipImportHelper::class)]
|
|
||||||
class ZipImportHelperTest extends TestCase
|
|
||||||
{
|
|
||||||
private TemporaryDirectory $sourceDirectory;
|
|
||||||
|
|
||||||
private TemporaryDirectory $targetDirectory;
|
|
||||||
|
|
||||||
protected function setUp(): void
|
|
||||||
{
|
|
||||||
parent::setUp();
|
|
||||||
$this->sourceDirectory = TemporaryDirectory::make();
|
|
||||||
$this->targetDirectory = TemporaryDirectory::make();
|
|
||||||
}
|
|
||||||
|
|
||||||
protected function tearDown(): void
|
|
||||||
{
|
|
||||||
$this->sourceDirectory->delete();
|
|
||||||
$this->targetDirectory->delete();
|
|
||||||
parent::tearDown();
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @param array<string, string> $files
|
|
||||||
*/
|
|
||||||
private function createZip(array $files): string
|
|
||||||
{
|
|
||||||
$zipPath = $this->sourceDirectory->path('test.zip');
|
|
||||||
$zip = new ZipArchive;
|
|
||||||
$zip->open($zipPath, ZipArchive::CREATE);
|
|
||||||
foreach ($files as $name => $content) {
|
|
||||||
$zip->addFromString($name, $content);
|
|
||||||
}
|
|
||||||
$zip->close();
|
|
||||||
|
|
||||||
return $zipPath;
|
|
||||||
}
|
|
||||||
|
|
||||||
private function assertNothingExtracted(): void
|
|
||||||
{
|
|
||||||
$this->assertSame([], array_values(array_diff(scandir($this->targetDirectory->path()), ['.', '..'])));
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_extracts_files_and_nested_directories(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'meta.json' => '{"version":"1.0"}',
|
|
||||||
'nested/dir/file.csv' => 'a,b',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('{"version":"1.0"}', file_get_contents($this->targetDirectory->path('meta.json')));
|
|
||||||
$this->assertSame('a,b', file_get_contents($this->targetDirectory->path('nested/dir/file.csv')));
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_file_is_not_a_zip(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$path = $this->sourceDirectory->path('not-a-zip.txt');
|
|
||||||
file_put_contents($path, 'not a zip');
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($path, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('Invalid ZIP, error code: 19', $e->getMessage());
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_zip_contains_too_many_files(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
config(['import.zip_max_files' => 2]);
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'a.txt' => 'a',
|
|
||||||
'b.txt' => 'b',
|
|
||||||
'c.txt' => 'c',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP contains too many files, maximum is 2', $e->getMessage());
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_before_writing_if_declared_uncompressed_size_exceeds_limit(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
config(['import.zip_max_uncompressed_size' => 100]);
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'a.txt' => str_repeat('a', 60),
|
|
||||||
'b.txt' => str_repeat('b', 60),
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP uncompressed size exceeds the maximum of 100 bytes', $e->getMessage());
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_actual_uncompressed_size_exceeds_limit_despite_forged_headers(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
config(['import.zip_max_uncompressed_size' => 1000]);
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'bomb.bin' => str_repeat("\0", 100000),
|
|
||||||
]);
|
|
||||||
// Forge the uncompressed size in the local file header (offset 22) and central directory header (offset 24)
|
|
||||||
$content = file_get_contents($zipPath);
|
|
||||||
$forgedSize = pack('V', 10);
|
|
||||||
$localHeaderOffset = strpos($content, "PK\x03\x04");
|
|
||||||
$centralHeaderOffset = strpos($content, "PK\x01\x02");
|
|
||||||
$this->assertNotFalse($localHeaderOffset);
|
|
||||||
$this->assertNotFalse($centralHeaderOffset);
|
|
||||||
$content = substr_replace($content, $forgedSize, $localHeaderOffset + 22, 4);
|
|
||||||
$content = substr_replace($content, $forgedSize, $centralHeaderOffset + 24, 4);
|
|
||||||
file_put_contents($zipPath, $content);
|
|
||||||
$zip = new ZipArchive;
|
|
||||||
$this->assertTrue($zip->open($zipPath, ZipArchive::RDONLY));
|
|
||||||
$this->assertSame(10, $zip->statIndex(0)['size']);
|
|
||||||
$zip->close();
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP uncompressed size exceeds the maximum of 1000 bytes', $e->getMessage());
|
|
||||||
$extracted = $this->targetDirectory->path('bomb.bin');
|
|
||||||
if (file_exists($extracted)) {
|
|
||||||
$this->assertLessThanOrEqual(1000, filesize($extracted));
|
|
||||||
}
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_zip_contains_path_traversal(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'../evil.txt' => 'evil',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP contains an invalid file path: "../evil.txt"', $e->getMessage());
|
|
||||||
$this->assertFileDoesNotExist(dirname($this->targetDirectory->path()).'/evil.txt');
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_zip_contains_nested_path_traversal(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'sub/../../evil.txt' => 'evil',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP contains an invalid file path: "sub/../../evil.txt"', $e->getMessage());
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_zip_contains_absolute_path(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'/tmp/evil.txt' => 'evil',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP contains an invalid file path: "/tmp/evil.txt"', $e->getMessage());
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_extract_throws_exception_if_zip_contains_backslash_path(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$zipPath = $this->createZip([
|
|
||||||
'..\\evil.txt' => 'evil',
|
|
||||||
]);
|
|
||||||
|
|
||||||
// Act
|
|
||||||
try {
|
|
||||||
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
|
|
||||||
} catch (ImportException $e) {
|
|
||||||
// Assert
|
|
||||||
$this->assertSame('ZIP contains an invalid file path: "..\\evil.txt"', $e->getMessage());
|
|
||||||
$this->assertNothingExtracted();
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
$this->fail();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -13,7 +13,6 @@ use App\Models\TimeEntry;
|
|||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use App\Service\MemberService;
|
use App\Service\MemberService;
|
||||||
use App\Service\UserService;
|
use App\Service\UserService;
|
||||||
use Illuminate\Support\Facades\Hash;
|
|
||||||
use InvalidArgumentException;
|
use InvalidArgumentException;
|
||||||
use PHPUnit\Framework\Attributes\CoversClass;
|
use PHPUnit\Framework\Attributes\CoversClass;
|
||||||
use Tests\TestCaseWithDatabase;
|
use Tests\TestCaseWithDatabase;
|
||||||
@@ -65,48 +64,6 @@ class MemberServiceTest extends TestCaseWithDatabase
|
|||||||
$this->assertSame(Role::Admin->value, $oldOwnerMember->refresh()->role);
|
$this->assertSame(Role::Admin->value, $oldOwnerMember->refresh()->role);
|
||||||
}
|
}
|
||||||
|
|
||||||
public function test_make_member_to_placeholder_does_not_copy_the_credentials_and_account_state_of_the_user(): void
|
|
||||||
{
|
|
||||||
// Arrange
|
|
||||||
$user = User::factory()->create([
|
|
||||||
'password' => Hash::make('secret-password'),
|
|
||||||
'remember_token' => 'remember-me-token',
|
|
||||||
'two_factor_secret' => 'two-factor-secret',
|
|
||||||
'two_factor_recovery_codes' => 'two-factor-recovery-codes',
|
|
||||||
'two_factor_confirmed_at' => '2026-09-16 10:00:00',
|
|
||||||
'email_verified_at' => '2026-09-16 09:00:00',
|
|
||||||
'pending_email' => 'pending@example.com',
|
|
||||||
'profile_photo_path' => 'profile-photos/photo.png',
|
|
||||||
]);
|
|
||||||
$organization = Organization::factory()->create();
|
|
||||||
$member = Member::factory()->forOrganization($organization)->forUser($user)->role(Role::Employee)->create();
|
|
||||||
|
|
||||||
// Act
|
|
||||||
$this->memberService->makeMemberToPlaceholder($member);
|
|
||||||
|
|
||||||
// Assert
|
|
||||||
$member->refresh();
|
|
||||||
$placeholderUser = $member->user;
|
|
||||||
$this->assertTrue($placeholderUser->is_placeholder);
|
|
||||||
$this->assertSame($user->email, $placeholderUser->email);
|
|
||||||
$this->assertNull($placeholderUser->password);
|
|
||||||
$this->assertNull($placeholderUser->remember_token);
|
|
||||||
$this->assertNull($placeholderUser->two_factor_secret);
|
|
||||||
$this->assertNull($placeholderUser->two_factor_recovery_codes);
|
|
||||||
$this->assertNull($placeholderUser->two_factor_confirmed_at);
|
|
||||||
$this->assertNull($placeholderUser->email_verified_at);
|
|
||||||
$this->assertNull($placeholderUser->pending_email);
|
|
||||||
$this->assertNull($placeholderUser->current_team_id);
|
|
||||||
$this->assertNull($placeholderUser->profile_photo_path);
|
|
||||||
// the user the placeholder was created from keeps their own credentials and state
|
|
||||||
$user->refresh();
|
|
||||||
$this->assertTrue(Hash::check('secret-password', (string) $user->password));
|
|
||||||
$this->assertSame('two-factor-secret', $user->two_factor_secret);
|
|
||||||
$this->assertNotNull($user->email_verified_at);
|
|
||||||
$this->assertSame('pending@example.com', $user->pending_email);
|
|
||||||
$this->assertSame('profile-photos/photo.png', $user->profile_photo_path);
|
|
||||||
}
|
|
||||||
|
|
||||||
public function test_make_member_to_placeholder_creates_new_user_based_on_member_and_changes_member_to_placeholder(): void
|
public function test_make_member_to_placeholder_creates_new_user_based_on_member_and_changes_member_to_placeholder(): void
|
||||||
{
|
{
|
||||||
// Arrange
|
// Arrange
|
||||||
|
|||||||
Reference in New Issue
Block a user