added some more tests (#1835)
This commit is contained in:
@@ -12,6 +12,11 @@ namespace App\Tests\Saml\Controller;
|
||||
use App\Saml\Controller\SamlController;
|
||||
use App\Tests\Mocks\Saml\SamlAuthFactory;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use PHPUnit\Util\Xml;
|
||||
use Symfony\Component\HttpFoundation\Request;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpFoundation\Session\SessionInterface;
|
||||
use Symfony\Component\Security\Core\Security;
|
||||
|
||||
/**
|
||||
* @group integration
|
||||
@@ -42,4 +47,58 @@ class SamlControllerTest extends TestCase
|
||||
$sut = new SamlController($oauth);
|
||||
$sut->logoutAction();
|
||||
}
|
||||
|
||||
public function testMetadataAction()
|
||||
{
|
||||
$expected = <<<EOD
|
||||
<?xml version="1.0"?>
|
||||
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" validUntil="2020-07-23T10:26:50Z" cacheDuration="PT604800S" entityID="https://127.0.0.1:8010/auth/saml/metadata">
|
||||
<md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
|
||||
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://127.0.0.1:8010/auth/saml/logout" />
|
||||
<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
|
||||
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://127.0.0.1:8010/auth/saml/acs" index="1" />
|
||||
</md:SPSSODescriptor>
|
||||
<md:Organization>
|
||||
<md:OrganizationName xml:lang="en">Kimai</md:OrganizationName>
|
||||
<md:OrganizationDisplayName xml:lang="en">Kimai</md:OrganizationDisplayName>
|
||||
<md:OrganizationURL xml:lang="en">https://www.kimai.org</md:OrganizationURL>
|
||||
</md:Organization>
|
||||
<md:ContactPerson contactType="technical">
|
||||
<md:GivenName>Kimai Admin</md:GivenName>
|
||||
<md:EmailAddress>kimai-tech@example.com</md:EmailAddress>
|
||||
</md:ContactPerson>
|
||||
<md:ContactPerson contactType="support">
|
||||
<md:GivenName>Kimai Support</md:GivenName>
|
||||
<md:EmailAddress>kimai-support@example.com</md:EmailAddress>
|
||||
</md:ContactPerson>
|
||||
</md:EntityDescriptor>
|
||||
EOD;
|
||||
|
||||
$oauth = $this->getAuth();
|
||||
$sut = new SamlController($oauth);
|
||||
$result = $sut->metadataAction();
|
||||
|
||||
self::assertInstanceOf(Response::class, $result);
|
||||
self::assertEquals('xml', $result->headers->get('Content-Type'));
|
||||
|
||||
$expected = Xml::load($expected);
|
||||
$actual = Xml::load($result->getContent());
|
||||
|
||||
// the "validUntil" attribute in the outer node changes per request
|
||||
self::assertEquals($expected->firstChild->firstChild, $actual->firstChild->firstChild);
|
||||
}
|
||||
|
||||
public function testLoginActionThrowsErrorOnSecurityErrorAttribute()
|
||||
{
|
||||
$this->expectException(\RuntimeException::class);
|
||||
$this->expectExceptionMessage('My test error');
|
||||
|
||||
$request = new Request();
|
||||
$request->setSession($this->createMock(SessionInterface::class));
|
||||
$request->attributes->set(Security::AUTHENTICATION_ERROR, new \Exception('My test error'));
|
||||
|
||||
$oauth = $this->getAuth();
|
||||
$sut = new SamlController($oauth);
|
||||
$sut->loginAction($request);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -19,6 +19,7 @@ use Hslavich\OneloginSamlBundle\Security\Authentication\Token\SamlToken;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use Symfony\Component\Security\Core\Authentication\Token\AnonymousToken;
|
||||
use Symfony\Component\Security\Core\Authentication\Token\UsernamePasswordToken;
|
||||
use Symfony\Component\Security\Core\Exception\AuthenticationException;
|
||||
use Symfony\Component\Security\Core\User\ChainUserProvider;
|
||||
|
||||
/**
|
||||
@@ -26,7 +27,7 @@ use Symfony\Component\Security\Core\User\ChainUserProvider;
|
||||
*/
|
||||
class SamlProviderTest extends TestCase
|
||||
{
|
||||
protected function getSamlProvider($mapping = null, $loadUser = false): SamlProvider
|
||||
protected function getSamlProvider($mapping = null, $loadUser = false, ?SamlUserFactory $userFactory = null): SamlProvider
|
||||
{
|
||||
if (null === $mapping) {
|
||||
$mapping = [
|
||||
@@ -41,12 +42,16 @@ class SamlProviderTest extends TestCase
|
||||
];
|
||||
}
|
||||
|
||||
if (null === $userFactory) {
|
||||
$userFactory = new SamlUserFactory($mapping);
|
||||
}
|
||||
|
||||
$repository = $this->getMockBuilder(UserRepository::class)->disableOriginalConstructor()->getMock();
|
||||
if ($loadUser !== false) {
|
||||
$repository->expects($this->once())->method('loadUserByUsername')->willReturn($loadUser);
|
||||
}
|
||||
$userProvider = new ChainUserProvider([new DoctrineUserProvider($repository)]);
|
||||
$provider = new SamlProvider($repository, $userProvider, new SamlTokenFactory(), new SamlUserFactory($mapping));
|
||||
$provider = new SamlProvider($repository, $userProvider, new SamlTokenFactory(), $userFactory);
|
||||
|
||||
return $provider;
|
||||
}
|
||||
@@ -108,4 +113,22 @@ class SamlProviderTest extends TestCase
|
||||
self::assertEquals('Tralalala', $tokenUser->getTitle());
|
||||
self::assertEquals('foo@example.com', $tokenUser->getEmail());
|
||||
}
|
||||
|
||||
public function testAuthenticateThrowsAuthenticationException()
|
||||
{
|
||||
$this->expectException(AuthenticationException::class);
|
||||
$this->expectExceptionMessage('Failed creating or hydrating user "foo1@example.com": Missing user attribute: Email');
|
||||
|
||||
$user = new User();
|
||||
$user->setAuth(User::AUTH_SAML);
|
||||
|
||||
$token = new SamlToken([]);
|
||||
$token->setUser('foo1@example.com');
|
||||
$token->setAttributes([
|
||||
'Chicken' => ['foo@example.com'],
|
||||
]);
|
||||
|
||||
$sut = $this->getSamlProvider(null, $user);
|
||||
$sut->authenticate($token);
|
||||
}
|
||||
}
|
||||
|
||||
33
tests/Saml/SamlAuthTest.php
Normal file
33
tests/Saml/SamlAuthTest.php
Normal file
@@ -0,0 +1,33 @@
|
||||
<?php
|
||||
|
||||
/*
|
||||
* This file is part of the Kimai time-tracking app.
|
||||
*
|
||||
* For the full copyright and license information, please view the LICENSE
|
||||
* file that was distributed with this source code.
|
||||
*/
|
||||
|
||||
namespace App\Tests\Saml;
|
||||
|
||||
use App\Tests\Mocks\Saml\SamlAuthFactory;
|
||||
use OneLogin\Saml2\Utils;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
/**
|
||||
* @covers \App\Saml\SamlAuth
|
||||
*/
|
||||
class SamlAuthTest extends TestCase
|
||||
{
|
||||
public function testCreateToken()
|
||||
{
|
||||
$previous = Utils::getProxyVars();
|
||||
self::assertFalse($previous);
|
||||
|
||||
$sut = (new SamlAuthFactory($this))->create(null, true);
|
||||
|
||||
$current = Utils::getProxyVars();
|
||||
self::assertTrue($current);
|
||||
|
||||
Utils::setProxyVars($previous);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user