|
2 | 2 | from django.contrib.auth.models import Permission |
3 | 3 | from django.test import TestCase |
4 | 4 | from django.urls import reverse |
| 5 | +from swapper import load_model |
5 | 6 |
|
6 | 7 | from openwisp_users.api.throttling import AuthRateThrottle |
7 | 8 |
|
| 9 | +from ..models import Template |
8 | 10 | from .mixins import TestMultitenancyMixin |
9 | 11 |
|
10 | 12 | User = get_user_model() |
| 13 | +Group = load_model('openwisp_users', 'Group') |
| 14 | +OrganizationUser = load_model('openwisp_users', 'OrganizationUser') |
11 | 15 |
|
12 | 16 |
|
13 | 17 | class TestPermissionClasses(TestMultitenancyMixin, TestCase): |
14 | 18 | def setUp(self): |
15 | 19 | AuthRateThrottle.rate = 0 |
| 20 | + self.template_model = Template |
16 | 21 | self.member_url = reverse('test_api_member_view') |
17 | 22 | self.manager_url = reverse('test_api_manager_view') |
18 | 23 | self.owner_url = reverse('test_api_owner_view') |
@@ -122,28 +127,127 @@ def test_organization_field_with_errored_parent(self): |
122 | 127 | self.client.get(reverse('test_error_field_view'), **auth) |
123 | 128 | self.assertIn('Organization not found', str(error.exception)) |
124 | 129 |
|
125 | | - def test_custom_django_model_permission_with_view_permission(self): |
| 130 | + def test_view_permission_with_operator(self): |
| 131 | + user = User.objects.create_user( |
| 132 | + username='operator', password='tester', email='operator@test.com' |
| 133 | + ) |
| 134 | + operator_group = Group.objects.filter(name='Operator') |
| 135 | + user.groups.set(operator_group) |
| 136 | + org1 = self._get_org() |
| 137 | + OrganizationUser.objects.create(user=user, organization=org1, is_admin=True) |
| 138 | + self.client.force_login(user) |
| 139 | + token = self._obtain_auth_token() |
| 140 | + auth = dict(HTTP_AUTHORIZATION=f'Bearer {token}') |
| 141 | + t1 = self._create_template(organization=org1) |
| 142 | + with self.subTest('Get Template List'): |
| 143 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 144 | + self.assertEqual(response.status_code, 403) |
| 145 | + with self.subTest('Get Template Detail'): |
| 146 | + response = self.client.get( |
| 147 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 148 | + ) |
| 149 | + self.assertEqual(response.status_code, 403) |
| 150 | + |
| 151 | + def test_view_permission_with_administrator(self): |
| 152 | + user = User.objects.create_user( |
| 153 | + username='operator', password='tester', email='operator@test.com' |
| 154 | + ) |
| 155 | + administrator_group = Group.objects.get(name='Administrator') |
| 156 | + change_perm = Permission.objects.get(codename='change_template') |
| 157 | + administrator_group.permissions.add(change_perm) |
| 158 | + user.groups.add(administrator_group) |
| 159 | + org1 = self._get_org() |
| 160 | + OrganizationUser.objects.create(user=user, organization=org1, is_admin=True) |
| 161 | + self.client.force_login(user) |
| 162 | + token = self._obtain_auth_token() |
| 163 | + auth = dict(HTTP_AUTHORIZATION=f'Bearer {token}') |
| 164 | + t1 = self._create_template(organization=org1) |
| 165 | + with self.subTest('Get Template List'): |
| 166 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 167 | + self.assertEqual(response.status_code, 200) |
| 168 | + with self.subTest('Get Template Detail'): |
| 169 | + response = self.client.get( |
| 170 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 171 | + ) |
| 172 | + self.assertEqual(response.status_code, 200) |
| 173 | + permissions = administrator_group.permissions.values_list('codename', flat=True) |
| 174 | + self.assertFalse('view_template' in permissions) |
| 175 | + self.assertTrue('change_template' in permissions) |
| 176 | + |
| 177 | + def test_view_permission_with_operator_having_view_perm(self): |
| 178 | + user = User.objects.create_user( |
| 179 | + username='operator', password='tester', email='operator@test.com' |
| 180 | + ) |
| 181 | + operator_group = Group.objects.get(name='Operator') |
| 182 | + view_perm = Permission.objects.get(codename='view_template') |
| 183 | + operator_group.permissions.add(view_perm) |
| 184 | + user.groups.add(operator_group) |
| 185 | + org1 = self._get_org() |
| 186 | + OrganizationUser.objects.create(user=user, organization=org1, is_admin=True) |
| 187 | + self.client.force_login(user) |
| 188 | + token = self._obtain_auth_token() |
| 189 | + auth = dict(HTTP_AUTHORIZATION=f'Bearer {token}') |
| 190 | + t1 = self._create_template(organization=org1) |
| 191 | + with self.subTest('Get Template List'): |
| 192 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 193 | + self.assertEqual(response.status_code, 200) |
| 194 | + with self.subTest('Get Template Detail'): |
| 195 | + response = self.client.get( |
| 196 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 197 | + ) |
| 198 | + self.assertEqual(response.status_code, 200) |
| 199 | + with self.subTest('Change Template Detail'): |
| 200 | + data = {'name': 'change-template'} |
| 201 | + response = self.client.patch( |
| 202 | + reverse('test_template_detail', args=[t1.pk]), data, **auth |
| 203 | + ) |
| 204 | + self.assertEqual(response.status_code, 403) |
| 205 | + with self.subTest('Delete Template'): |
| 206 | + response = self.client.delete( |
| 207 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 208 | + ) |
| 209 | + self.assertEqual(response.status_code, 403) |
| 210 | + |
| 211 | + def test_view_django_model_permission_with_view_perm(self): |
126 | 212 | user = User.objects.create_user( |
127 | 213 | username='operator', password='tester', email='operator@test.com' |
128 | 214 | ) |
129 | 215 | user_permissions = Permission.objects.filter(codename='view_template') |
130 | 216 | user.user_permissions.add(*user_permissions) |
131 | 217 | user.organizations_dict # force caching |
| 218 | + org1 = self._get_org() |
| 219 | + OrganizationUser.objects.create(user=user, organization=org1, is_admin=True) |
132 | 220 | self.client.force_login(user) |
133 | 221 | token = self._obtain_auth_token() |
134 | 222 | auth = dict(HTTP_AUTHORIZATION=f'Bearer {token}') |
135 | | - response = self.client.get(reverse('test_template_list'), **auth) |
136 | | - self.assertEqual(response.status_code, 200) |
| 223 | + t1 = self._create_template(organization=org1) |
| 224 | + with self.subTest('Get Template List'): |
| 225 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 226 | + self.assertEqual(response.status_code, 200) |
| 227 | + with self.subTest('Get Template Detail'): |
| 228 | + response = self.client.get( |
| 229 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 230 | + ) |
| 231 | + self.assertEqual(response.status_code, 200) |
137 | 232 |
|
138 | | - def test_custom_django_model_permission_with_change_permission(self): |
| 233 | + def test_view_django_model_permission_with_change_perm(self): |
139 | 234 | user = User.objects.create_user( |
140 | 235 | username='operator', password='tester', email='operator@test.com' |
141 | 236 | ) |
142 | 237 | user_permissions = Permission.objects.filter(codename='change_template') |
143 | 238 | user.user_permissions.add(*user_permissions) |
144 | 239 | user.organizations_dict # force caching |
| 240 | + org1 = self._get_org() |
| 241 | + OrganizationUser.objects.create(user=user, organization=org1, is_admin=True) |
145 | 242 | self.client.force_login(user) |
146 | 243 | token = self._obtain_auth_token() |
147 | 244 | auth = dict(HTTP_AUTHORIZATION=f'Bearer {token}') |
148 | | - response = self.client.get(reverse('test_template_list'), **auth) |
149 | | - self.assertEqual(response.status_code, 200) |
| 245 | + t1 = self._create_template(organization=org1) |
| 246 | + with self.subTest('Get Template List'): |
| 247 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 248 | + self.assertEqual(response.status_code, 200) |
| 249 | + with self.subTest('Get Template Detail'): |
| 250 | + response = self.client.get( |
| 251 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 252 | + ) |
| 253 | + self.assertEqual(response.status_code, 200) |
0 commit comments