Release 1.6.2 (#1289)
* include user teams in user entity * prevent unauthorized access via API * improve teamlead permission handling in team timesheets * add team data to user entity * add security tests * highlight menu for invoice template copy * unified handling of invoice data across all templates * access to the current users data in invoice templates * permission improvement in invoice form * allow to skip record rows * allow to add new invoice locations without overwriting the global ones * allow to order user preferences * change permission for normal users with access to view_other_timesheets * properly validate invoice template field length * allow to replace multiple variables in cell values text * upgraded office invoice template * doctrine deprecation fix * upgrade phpoffice/phpword * fix future begin check for default rounding rules * dashboard widget counter: respect visibility and teams - fixes #1161 * fix future begin check for default rounding rules * added new events for pre and post invoice rendering * fix permission issue for users without team seeing all records * prevent error in spreadsheet renderer for empty invoices
This commit is contained in:
@@ -16,7 +16,7 @@ use App\Entity\User;
|
||||
*/
|
||||
class ConfigurationControllerTest extends APIControllerBaseTest
|
||||
{
|
||||
public function testI18nIsSecure()
|
||||
public function testIsSecure()
|
||||
{
|
||||
$this->assertUrlIsSecured('/api/config/i18n');
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@ class StatusControllerTest extends APIControllerBaseTest
|
||||
public function testIsSecure()
|
||||
{
|
||||
$this->assertUrlIsSecured('/api/ping');
|
||||
$this->assertUrlIsSecured('/api/version');
|
||||
}
|
||||
|
||||
public function testPing()
|
||||
|
||||
@@ -31,6 +31,11 @@ class TagControllerTest extends APIControllerBaseTest
|
||||
$this->importFixture($em, $fixture);
|
||||
}
|
||||
|
||||
public function testIsSecure()
|
||||
{
|
||||
$this->assertUrlIsSecured('/api/tags');
|
||||
}
|
||||
|
||||
public function testGetCollection()
|
||||
{
|
||||
$client = $this->getClientForAuthenticatedUser(User::ROLE_USER);
|
||||
|
||||
@@ -30,6 +30,8 @@ class TeamControllerTest extends APIControllerBaseTest
|
||||
public function testIsSecure()
|
||||
{
|
||||
$this->assertUrlIsSecured('/api/teams');
|
||||
$this->assertUrlIsSecuredForRole(User::ROLE_USER, '/api/teams');
|
||||
$this->assertUrlIsSecuredForRole(User::ROLE_TEAMLEAD, '/api/teams');
|
||||
}
|
||||
|
||||
public function testGetCollection()
|
||||
@@ -56,7 +58,7 @@ class TeamControllerTest extends APIControllerBaseTest
|
||||
|
||||
public function testNotFound()
|
||||
{
|
||||
$this->assertEntityNotFound(User::ROLE_USER, '/api/teams/3');
|
||||
$this->assertEntityNotFound(User::ROLE_ADMIN, '/api/teams/3');
|
||||
}
|
||||
|
||||
public function testDeleteActionWithUnknownTeam()
|
||||
@@ -80,7 +82,7 @@ class TeamControllerTest extends APIControllerBaseTest
|
||||
$this->assertEquals(Response::HTTP_NO_CONTENT, $client->getResponse()->getStatusCode());
|
||||
$this->assertEmpty($client->getResponse()->getContent());
|
||||
|
||||
$this->assertEntityNotFound(User::ROLE_USER, '/api/teams/' . $id);
|
||||
$this->assertEntityNotFound(User::ROLE_ADMIN, '/api/teams/' . $id);
|
||||
}
|
||||
|
||||
protected function assertStructure(array $result, $full = true)
|
||||
@@ -90,7 +92,9 @@ class TeamControllerTest extends APIControllerBaseTest
|
||||
];
|
||||
|
||||
if ($full) {
|
||||
$expectedKeys = array_merge($expectedKeys, []);
|
||||
$expectedKeys = array_merge($expectedKeys, [
|
||||
'teamlead', 'users'
|
||||
]);
|
||||
}
|
||||
|
||||
$actual = array_keys($result);
|
||||
|
||||
@@ -19,6 +19,8 @@ class UserControllerTest extends APIControllerBaseTest
|
||||
public function testIsSecure()
|
||||
{
|
||||
$this->assertUrlIsSecured('/api/users');
|
||||
$this->assertUrlIsSecuredForRole(User::ROLE_USER, '/api/users');
|
||||
$this->assertUrlIsSecuredForRole(User::ROLE_TEAMLEAD, '/api/users');
|
||||
$this->assertUrlIsSecuredForRole(User::ROLE_ADMIN, '/api/users');
|
||||
}
|
||||
|
||||
@@ -118,7 +120,7 @@ class UserControllerTest extends APIControllerBaseTest
|
||||
if ($full) {
|
||||
$expectedKeys = array_merge(
|
||||
$expectedKeys,
|
||||
['title', 'avatar', 'roles', 'language', 'timezone']
|
||||
['title', 'avatar', 'teams', 'roles', 'language', 'timezone']
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user