|
| 1 | +from django.contrib.auth import get_user_model |
| 2 | +from django.contrib.auth.models import Permission |
1 | 3 | from django.test import TestCase |
2 | 4 | from django.urls import reverse |
| 5 | +from swapper import load_model |
3 | 6 |
|
4 | 7 | from openwisp_users.api.throttling import AuthRateThrottle |
5 | 8 |
|
| 9 | +from ..models import Template |
6 | 10 | from .mixins import TestMultitenancyMixin |
7 | 11 |
|
| 12 | +User = get_user_model() |
| 13 | +Group = load_model('openwisp_users', 'Group') |
| 14 | +OrganizationUser = load_model('openwisp_users', 'OrganizationUser') |
| 15 | + |
8 | 16 |
|
9 | 17 | class TestPermissionClasses(TestMultitenancyMixin, TestCase): |
10 | 18 | def setUp(self): |
11 | 19 | AuthRateThrottle.rate = 0 |
| 20 | + self.template_model = Template |
12 | 21 | self.member_url = reverse('test_api_member_view') |
13 | 22 | self.manager_url = reverse('test_api_manager_view') |
14 | 23 | self.owner_url = reverse('test_api_owner_view') |
@@ -117,3 +126,106 @@ def test_organization_field_with_errored_parent(self): |
117 | 126 | with self.assertRaises(AttributeError) as error: |
118 | 127 | self.client.get(reverse('test_error_field_view'), **auth) |
119 | 128 | self.assertIn('Organization not found', str(error.exception)) |
| 129 | + |
| 130 | + def _get_auth_template(self, user, org1): |
| 131 | + OrganizationUser.objects.create(user=user, organization=org1, is_admin=True) |
| 132 | + self.client.force_login(user) |
| 133 | + token = self._obtain_auth_token(user) |
| 134 | + auth = dict(HTTP_AUTHORIZATION=f'Bearer {token}') |
| 135 | + t1 = self._create_template(organization=org1) |
| 136 | + return (auth, t1) |
| 137 | + |
| 138 | + def test_view_permission_with_operator(self): |
| 139 | + user = self._get_user() |
| 140 | + operator_group = Group.objects.filter(name='Operator') |
| 141 | + user.groups.set(operator_group) |
| 142 | + org1 = self._get_org() |
| 143 | + auth, t1 = self._get_auth_template(user, org1) |
| 144 | + with self.subTest('Get Template List'): |
| 145 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 146 | + self.assertEqual(response.status_code, 403) |
| 147 | + with self.subTest('Get Template Detail'): |
| 148 | + response = self.client.get( |
| 149 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 150 | + ) |
| 151 | + self.assertEqual(response.status_code, 403) |
| 152 | + |
| 153 | + def test_view_permission_with_administrator(self): |
| 154 | + user = self._get_user() |
| 155 | + administrator_group = Group.objects.get(name='Administrator') |
| 156 | + change_perm = Permission.objects.get(codename='change_template') |
| 157 | + administrator_group.permissions.add(change_perm) |
| 158 | + user.groups.add(administrator_group) |
| 159 | + org1 = self._get_org() |
| 160 | + auth, t1 = self._get_auth_template(user, org1) |
| 161 | + with self.subTest('Get Template List'): |
| 162 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 163 | + self.assertEqual(response.status_code, 200) |
| 164 | + with self.subTest('Get Template Detail'): |
| 165 | + response = self.client.get( |
| 166 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 167 | + ) |
| 168 | + self.assertEqual(response.status_code, 200) |
| 169 | + permissions = administrator_group.permissions.values_list('codename', flat=True) |
| 170 | + self.assertFalse('view_template' in permissions) |
| 171 | + self.assertTrue('change_template' in permissions) |
| 172 | + |
| 173 | + def test_view_permission_with_operator_having_view_perm(self): |
| 174 | + user = self._get_user() |
| 175 | + operator_group = Group.objects.get(name='Operator') |
| 176 | + view_perm = Permission.objects.get(codename='view_template') |
| 177 | + operator_group.permissions.add(view_perm) |
| 178 | + user.groups.add(operator_group) |
| 179 | + org1 = self._get_org() |
| 180 | + auth, t1 = self._get_auth_template(user, org1) |
| 181 | + with self.subTest('Get Template List'): |
| 182 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 183 | + self.assertEqual(response.status_code, 200) |
| 184 | + with self.subTest('Get Template Detail'): |
| 185 | + response = self.client.get( |
| 186 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 187 | + ) |
| 188 | + self.assertEqual(response.status_code, 200) |
| 189 | + with self.subTest('Change Template Detail'): |
| 190 | + data = {'name': 'change-template'} |
| 191 | + response = self.client.patch( |
| 192 | + reverse('test_template_detail', args=[t1.pk]), data, **auth |
| 193 | + ) |
| 194 | + self.assertEqual(response.status_code, 403) |
| 195 | + with self.subTest('Delete Template'): |
| 196 | + response = self.client.delete( |
| 197 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 198 | + ) |
| 199 | + self.assertEqual(response.status_code, 403) |
| 200 | + |
| 201 | + def test_view_django_model_permission_with_view_perm(self): |
| 202 | + user = self._get_user() |
| 203 | + user_permissions = Permission.objects.filter(codename='view_template') |
| 204 | + user.user_permissions.add(*user_permissions) |
| 205 | + user.organizations_dict # force caching |
| 206 | + org1 = self._get_org() |
| 207 | + auth, t1 = self._get_auth_template(user, org1) |
| 208 | + with self.subTest('Get Template List'): |
| 209 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 210 | + self.assertEqual(response.status_code, 200) |
| 211 | + with self.subTest('Get Template Detail'): |
| 212 | + response = self.client.get( |
| 213 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 214 | + ) |
| 215 | + self.assertEqual(response.status_code, 200) |
| 216 | + |
| 217 | + def test_view_django_model_permission_with_change_perm(self): |
| 218 | + user = self._get_user() |
| 219 | + user_permissions = Permission.objects.filter(codename='change_template') |
| 220 | + user.user_permissions.add(*user_permissions) |
| 221 | + user.organizations_dict # force caching |
| 222 | + org1 = self._get_org() |
| 223 | + auth, t1 = self._get_auth_template(user, org1) |
| 224 | + with self.subTest('Get Template List'): |
| 225 | + response = self.client.get(reverse('test_template_list'), **auth) |
| 226 | + self.assertEqual(response.status_code, 200) |
| 227 | + with self.subTest('Get Template Detail'): |
| 228 | + response = self.client.get( |
| 229 | + reverse('test_template_detail', args=[t1.pk]), **auth |
| 230 | + ) |
| 231 | + self.assertEqual(response.status_code, 200) |
0 commit comments