8 use Wikimedia\TestingAccessWrapper;
24 'sessionCookieName' =>
$name,
25 'sessionCookieOptions' => [],
27 if ( $prefix !==
null ) {
28 $params[
'sessionCookieOptions'][
'prefix'] = $prefix;
31 if ( !$this->config ) {
32 $this->config = new \HashConfig( [
33 'CookiePrefix' =>
'wgCookiePrefix',
34 'EnableBotPasswords' =>
true,
35 'BotPasswordsDatabase' =>
false,
46 'logger' =>
new \Psr\Log\NullLogger,
57 'wgEnableBotPasswords' =>
true,
58 'wgBotPasswordsDatabase' =>
false,
59 'wgCentralIdLookupProvider' =>
'local',
60 'wgGrantPermissions' => [
61 'test' => [
'read' =>
true ],
68 $passwordHash = $passwordFactory->newFromPlaintext(
'foobaz' );
70 $sysop = static::getTestSysop()->getUser();
76 [
'bp_user' => $userId,
'bp_app_id' =>
'BotPasswordSessionProvider' ],
83 'bp_app_id' =>
'BotPasswordSessionProvider',
84 'bp_password' => $passwordHash->toString(),
85 'bp_token' =>
'token!',
86 'bp_restrictions' =>
'{"IPAddresses":["127.0.0.0/8"]}',
87 'bp_grants' =>
'["test"]',
95 $provider =
new BotPasswordSessionProvider();
96 $this->fail(
'Expected exception not thrown' );
97 }
catch ( \InvalidArgumentException $ex ) {
99 'MediaWiki\\Session\\BotPasswordSessionProvider::__construct: priority must be specified',
105 $provider =
new BotPasswordSessionProvider( [
108 $this->fail(
'Expected exception not thrown' );
109 }
catch ( \InvalidArgumentException $ex ) {
111 'MediaWiki\\Session\\BotPasswordSessionProvider::__construct: Invalid priority',
117 $provider =
new BotPasswordSessionProvider( [
120 $this->fail(
'Expected exception not thrown' );
121 }
catch ( \InvalidArgumentException $ex ) {
123 'MediaWiki\\Session\\BotPasswordSessionProvider::__construct: Invalid priority',
128 $provider =
new BotPasswordSessionProvider( [
131 $priv = TestingAccessWrapper::newFromObject( $provider );
132 $this->assertSame( 40, $priv->priority );
133 $this->assertSame(
'_BPsession', $priv->sessionCookieName );
134 $this->assertSame( [], $priv->sessionCookieOptions );
136 $provider =
new BotPasswordSessionProvider( [
138 'sessionCookieName' =>
null,
140 $priv = TestingAccessWrapper::newFromObject( $provider );
141 $this->assertSame(
'_BPsession', $priv->sessionCookieName );
143 $provider =
new BotPasswordSessionProvider( [
145 'sessionCookieName' =>
'Foo',
146 'sessionCookieOptions' => [
'Bar' ],
148 $priv = TestingAccessWrapper::newFromObject( $provider );
149 $this->assertSame(
'Foo', $priv->sessionCookieName );
150 $this->assertSame( [
'Bar' ], $priv->sessionCookieOptions );
156 $this->assertTrue( $provider->persistsSessionId() );
157 $this->assertFalse( $provider->canChangeUser() );
159 $this->assertNull( $provider->newSessionInfo() );
160 $this->assertNull( $provider->newSessionInfo(
'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa' ) );
166 $request->setCookie(
'_BPsession',
'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
'wgCookiePrefix' );
168 if ( !defined(
'MW_API' ) ) {
169 $this->assertNull( $provider->provideSessionInfo(
$request ) );
170 define(
'MW_API', 1 );
173 $info = $provider->provideSessionInfo(
$request );
175 $this->assertSame(
'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa', $info->getId() );
177 $this->config->set(
'EnableBotPasswords',
false );
178 $this->assertNull( $provider->provideSessionInfo(
$request ) );
179 $this->config->set(
'EnableBotPasswords',
true );
181 $this->assertNull( $provider->provideSessionInfo(
new \
FauxRequest ) );
186 $user = static::getTestSysop()->getUser();
188 ->setMethods( [
'getIP' ] )->getMock();
189 $request->expects( $this->
any() )->method(
'getIP' )
190 ->will( $this->returnValue(
'127.0.0.1' ) );
193 $session = $provider->newSessionForRequest(
$user, $bp,
$request );
196 $this->assertEquals( $session->getId(),
$request->getSession()->getId() );
197 $this->assertEquals(
$user->getName(), $session->getUser()->getName() );
199 $this->assertEquals( [
200 'centralId' => $bp->getUserCentralId(),
201 'appId' => $bp->getAppId(),
202 'token' => $bp->getToken(),
203 'rights' => [
'read' ],
204 ], $session->getProviderMetadata() );
206 $this->assertEquals( [
'read' ], $session->getAllowedUserRights() );
210 $logger = new \TestLogger(
true );
212 $provider->setLogger( $logger );
214 $user = static::getTestSysop()->getUser();
216 ->setMethods( [
'getIP' ] )->getMock();
217 $request->expects( $this->
any() )->method(
'getIP' )
218 ->will( $this->returnValue(
'127.0.0.1' ) );
222 'provider' => $provider,
223 'id' =>
'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
225 'persisted' =>
false,
227 'centralId' => $bp->getUserCentralId(),
228 'appId' => $bp->getAppId(),
229 'token' => $bp->getToken(),
232 $dataMD = $data[
'metadata'];
234 foreach ( array_keys( $data[
'metadata'] )
as $key ) {
235 $data[
'metadata'] = $dataMD;
236 unset( $data[
'metadata'][$key] );
238 $metadata = $info->getProviderMetadata();
240 $this->assertFalse( $provider->refreshSessionInfo( $info,
$request, $metadata ) );
242 [ LogLevel::INFO,
'Session "{session}": Missing metadata: {missing}' ]
243 ], $logger->getBuffer() );
244 $logger->clearBuffer();
247 $data[
'metadata'] = $dataMD;
248 $data[
'metadata'][
'appId'] =
'Foobar';
250 $metadata = $info->getProviderMetadata();
251 $this->assertFalse( $provider->refreshSessionInfo( $info,
$request, $metadata ) );
253 [ LogLevel::INFO,
'Session "{session}": No BotPassword for {centralId} {appId}' ],
254 ], $logger->getBuffer() );
255 $logger->clearBuffer();
257 $data[
'metadata'] = $dataMD;
258 $data[
'metadata'][
'token'] =
'Foobar';
260 $metadata = $info->getProviderMetadata();
261 $this->assertFalse( $provider->refreshSessionInfo( $info,
$request, $metadata ) );
263 [ LogLevel::INFO,
'Session "{session}": BotPassword token check failed' ],
264 ], $logger->getBuffer() );
265 $logger->clearBuffer();
268 ->setMethods( [
'getIP' ] )->getMock();
269 $request2->expects( $this->
any() )->method(
'getIP' )
270 ->will( $this->returnValue(
'10.0.0.1' ) );
271 $data[
'metadata'] = $dataMD;
273 $metadata = $info->getProviderMetadata();
274 $this->assertFalse( $provider->refreshSessionInfo( $info, $request2, $metadata ) );
276 [ LogLevel::INFO,
'Session "{session}": Restrictions check failed' ],
277 ], $logger->getBuffer() );
278 $logger->clearBuffer();
281 $metadata = $info->getProviderMetadata();
282 $this->assertTrue( $provider->refreshSessionInfo( $info,
$request, $metadata ) );
283 $this->assertSame( [], $logger->getBuffer() );
284 $this->assertEquals( $dataMD + [
'rights' => [
'read' ] ], $metadata );
288 $logger = new \TestLogger(
true );
290 $provider->setLogger( $logger );
293 $backendPriv = TestingAccessWrapper::newFromObject( $backend );
296 $provider->getAllowedUserRights( $backend );
297 $this->fail(
'Expected exception not thrown' );
298 }
catch ( \InvalidArgumentException $ex ) {
299 $this->assertSame(
'Backend\'s provider isn\'t $this', $ex->getMessage() );
302 $backendPriv->provider = $provider;
303 $backendPriv->providerMetadata = [
'rights' => [
'foo',
'bar',
'baz' ] ];
304 $this->assertSame( [
'foo',
'bar',
'baz' ], $provider->getAllowedUserRights( $backend ) );
305 $this->assertSame( [], $logger->getBuffer() );
307 $backendPriv->providerMetadata = [
'foo' =>
'bar' ];
308 $this->assertSame( [], $provider->getAllowedUserRights( $backend ) );
312 'MediaWiki\\Session\\BotPasswordSessionProvider::getAllowedUserRights: ' .
313 'No provider metadata, returning no rights allowed'
315 ], $logger->getBuffer() );
316 $logger->clearBuffer();
318 $backendPriv->providerMetadata = [
'rights' =>
'bar' ];
319 $this->assertSame( [], $provider->getAllowedUserRights( $backend ) );
323 'MediaWiki\\Session\\BotPasswordSessionProvider::getAllowedUserRights: ' .
324 'No provider metadata, returning no rights allowed'
326 ], $logger->getBuffer() );
327 $logger->clearBuffer();
329 $backendPriv->providerMetadata =
null;
330 $this->assertSame( [], $provider->getAllowedUserRights( $backend ) );
334 'MediaWiki\\Session\\BotPasswordSessionProvider::getAllowedUserRights: ' .
335 'No provider metadata, returning no rights allowed'
337 ], $logger->getBuffer() );
338 $logger->clearBuffer();