silverstripe-framework/tests/php/Security/PermissionRoleTest.php

56 lines
1.8 KiB
PHP
Raw Normal View History

<?php
2016-10-14 14:30:05 +13:00
namespace SilverStripe\Security\Tests;
use SilverStripe\ORM\DataObject;
2016-10-14 14:30:05 +13:00
use SilverStripe\Security\PermissionRole;
2016-06-23 11:37:22 +12:00
use SilverStripe\Security\PermissionRoleCode;
use SilverStripe\Dev\FunctionalTest;
2016-10-14 14:30:05 +13:00
use ReflectionMethod;
class PermissionRoleTest extends FunctionalTest {
protected static $fixture_file = 'PermissionRoleTest.yml';
2014-08-15 18:53:05 +12:00
public function testDelete() {
2016-10-14 14:30:05 +13:00
$role = $this->objFromFixture(PermissionRole::class, 'role');
2014-08-15 18:53:05 +12:00
$role->delete();
2014-08-15 18:53:05 +12:00
2016-10-14 14:30:05 +13:00
$this->assertEquals(0, DataObject::get(PermissionRole::class, "\"ID\"={$role->ID}")->count(),
'Role is removed');
2016-10-14 14:30:05 +13:00
$this->assertEquals(0, DataObject::get(PermissionRoleCode::class,"\"RoleID\"={$role->ID}")->count(),
'Permissions removed along with the role');
}
public function testValidatesPrivilegedPermissions() {
$nonAdminCode = new PermissionRoleCode(array('Code' => 'CMS_ACCESS_CMSMain'));
$nonAdminValidateMethod = new ReflectionMethod($nonAdminCode, 'validate');
$nonAdminValidateMethod->setAccessible(true);
$adminCode = new PermissionRoleCode(array('Code' => 'ADMIN'));
$adminValidateMethod = new ReflectionMethod($adminCode, 'validate');
$adminValidateMethod->setAccessible(true);
$this->logInWithPermission('APPLY_ROLES');
$result = $nonAdminValidateMethod->invoke($nonAdminCode);
$this->assertTrue(
$result->valid(),
'Members with only APPLY_ROLES can create non-privileged permission role codes'
);
$this->logInWithPermission('APPLY_ROLES');
$result = $adminValidateMethod->invoke($adminCode);
$this->assertFalse(
$result->valid(),
'Members with only APPLY_ROLES can\'t create privileged permission role codes'
);
$this->logInWithPermission('ADMIN');
$result = $adminValidateMethod->invoke($adminCode);
$this->assertTrue(
$result->valid(),
'Members with ADMIN can create privileged permission role codes'
);
}
}