mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 14:05:37 +02:00
3873e4ba00
See https://github.com/silverstripe/silverstripe-framework/pull/7037 and https://github.com/silverstripe/silverstripe-framework/issues/6681 Squashed commit of the following: commit8f65e56532
Author: Ingo Schommer <me@chillu.com> Date: Thu Jun 22 22:25:50 2017 +1200 Fixed upgrade guide spelling commit76f95944fa
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 16:38:34 2017 +1200 BUG Fix non-test class manifest including sapphiretest / functionaltest commit9379834cb4
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 15:50:47 2017 +1200 BUG Fix nesting bug in Kernel commit188ce35d82
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 15:14:51 2017 +1200 BUG fix db bootstrapping issues commit7ed4660e7a
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 14:49:07 2017 +1200 BUG Fix issue in DetailedErrorFormatter commit738f50c497
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 11:49:19 2017 +1200 Upgrading notes on mysite/_config.php commit6279d28e5e
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 11:43:28 2017 +1200 Update developer documentation commit5c90d53a84
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 22 10:48:44 2017 +1200 Update installer to not use global databaseConfig commitf9b2ba4755
Author: Damian Mooyman <damian@silverstripe.com> Date: Wed Jun 21 21:04:39 2017 +1200 Fix behat issues commit5b59a912b6
Author: Damian Mooyman <damian@silverstripe.com> Date: Wed Jun 21 17:07:11 2017 +1200 Move HTTPApplication to SilverStripe\Control namespace commite2c4a18f63
Author: Damian Mooyman <damian@silverstripe.com> Date: Wed Jun 21 16:29:03 2017 +1200 More documentation Fix up remaining tests Refactor temp DB into TempDatabase class so it’s available outside of unit tests. commit5d235e64f3
Author: Damian Mooyman <damian@silverstripe.com> Date: Wed Jun 21 12:13:15 2017 +1200 API HTTPRequestBuilder::createFromEnvironment() now cleans up live globals BUG Fix issue with SSViewer Fix Security / View tests commitd88d4ed4e4
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 20 16:39:43 2017 +1200 API Refactor AppKernel into CoreKernel commitf7946aec33
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 20 16:00:40 2017 +1200 Docs and minor cleanup commit12bd31f936
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 20 15:34:34 2017 +1200 API Remove OutputMiddleware API Move environment / global / ini management into Environment class API Move getTempFolder into TempFolder class API Implement HTTPRequestBuilder / CLIRequestBuilder BUG Restore SS_ALLOWED_HOSTS check in original location API CoreKernel now requires $basePath to be passed in API Refactor installer.php to use application to bootstrap API move memstring conversion globals to Convert BUG Fix error in CoreKernel nesting not un-nesting itself properly. commitbba9791146
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 19 18:07:53 2017 +1200 API Create HTTPMiddleware and standardise middleware for request handling commit2a10c2397b
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 19 17:42:42 2017 +1200 Fixed ORM tests commitd75a8d1d93
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 19 17:15:07 2017 +1200 FIx i18n tests commit06364af3c3
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 19 16:59:34 2017 +1200 Fix controller namespace Move states to sub namespace commit2a278e2953
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 19 12:49:45 2017 +1200 Fix forms namespace commitb65c21241b
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 15 18:56:48 2017 +1200 Update API usages commitd1d4375c95
Author: Damian Mooyman <damian@silverstripe.com> Date: Thu Jun 15 18:41:44 2017 +1200 API Refactor $flush into HTPPApplication API Enforce health check in Controller::pushCurrent() API Better global backup / restore Updated Director::test() to use new API commitb220534f06
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 22:05:57 2017 +1200 Move app nesting to a test state helper commit603704165c
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 21:46:04 2017 +1200 Restore kernel stack to fix multi-level nesting commit2f6336a15b
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 17:23:21 2017 +1200 API Implement kernel nesting commitfc7188da7d
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 15:43:13 2017 +1200 Fix core tests commita0ae723514
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 15:23:52 2017 +1200 Fix manifest tests commitca03395251
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 15:00:00 2017 +1200 API Move extension management into test state commitc66d433977
Author: Damian Mooyman <damian@silverstripe.com> Date: Tue Jun 13 14:10:59 2017 +1200 API Refactor SapphireTest state management into SapphireTestState API Remove Injector::unregisterAllObjects() API Remove FakeController commitf26ae75c6e
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 12 18:04:34 2017 +1200 Implement basic CLI application object commit001d559662
Author: Damian Mooyman <damian@silverstripe.com> Date: Mon Jun 12 17:39:38 2017 +1200 Remove references to SapphireTest::is_running_test() Upgrade various code commitde079c041d
Author: Damian Mooyman <damian@silverstripe.com> Date: Wed Jun 7 18:07:33 2017 +1200 API Implement APP object API Refactor of Session
219 lines
7.3 KiB
PHP
219 lines
7.3 KiB
PHP
<?php
|
|
|
|
namespace SilverStripe\Forms\Tests\GridField;
|
|
|
|
use SilverStripe\Control\Controller;
|
|
use SilverStripe\Control\HTTPRequest;
|
|
use SilverStripe\Control\HTTPResponse_Exception;
|
|
use SilverStripe\Control\Session;
|
|
use SilverStripe\Dev\CSSContentParser;
|
|
use SilverStripe\Dev\SapphireTest;
|
|
use SilverStripe\Forms\FieldList;
|
|
use SilverStripe\Forms\Form;
|
|
use SilverStripe\Forms\GridField\GridField;
|
|
use SilverStripe\Forms\GridField\GridFieldConfig;
|
|
use SilverStripe\Forms\GridField\GridFieldDeleteAction;
|
|
use SilverStripe\Forms\Tests\GridField\GridFieldTest\Cheerleader;
|
|
use SilverStripe\Forms\Tests\GridField\GridFieldTest\Permissions;
|
|
use SilverStripe\Forms\Tests\GridField\GridFieldTest\Player;
|
|
use SilverStripe\Forms\Tests\GridField\GridFieldTest\Team;
|
|
use SilverStripe\ORM\ArrayList;
|
|
use SilverStripe\ORM\DataList;
|
|
use SilverStripe\ORM\ValidationException;
|
|
use SilverStripe\Security\Security;
|
|
use SilverStripe\Security\SecurityToken;
|
|
|
|
class GridFieldDeleteActionTest extends SapphireTest
|
|
{
|
|
|
|
/**
|
|
* @var ArrayList
|
|
*/
|
|
protected $list;
|
|
|
|
/**
|
|
* @var GridField
|
|
*/
|
|
protected $gridField;
|
|
|
|
/**
|
|
* @var Form
|
|
*/
|
|
protected $form;
|
|
|
|
/**
|
|
* @var string
|
|
*/
|
|
protected static $fixture_file = 'GridFieldActionTest.yml';
|
|
|
|
/**
|
|
* @var array
|
|
*/
|
|
protected static $extra_dataobjects = [
|
|
Team::class,
|
|
Cheerleader::class,
|
|
Player::class,
|
|
Permissions::class,
|
|
];
|
|
|
|
protected function setUp()
|
|
{
|
|
parent::setUp();
|
|
$this->list = new DataList(Team::class);
|
|
$config = GridFieldConfig::create()->addComponent(new GridFieldDeleteAction());
|
|
$this->gridField = new GridField('testfield', 'testfield', $this->list, $config);
|
|
$this->form = new Form(null, 'mockform', new FieldList(array($this->gridField)), new FieldList());
|
|
}
|
|
|
|
public function testDontShowDeleteButtons()
|
|
{
|
|
if (Security::getCurrentUser()) {
|
|
Security::setCurrentUser(null);
|
|
}
|
|
$content = new CSSContentParser($this->gridField->FieldHolder());
|
|
// Check that there are content
|
|
$this->assertEquals(4, count($content->getBySelector('.ss-gridfield-item')));
|
|
// Make sure that there are no delete buttons
|
|
$this->assertEquals(
|
|
0,
|
|
count($content->getBySelector('.gridfield-button-delete')),
|
|
'Delete buttons should not show when not logged in.'
|
|
);
|
|
}
|
|
|
|
public function testShowDeleteButtonsWithAdminPermission()
|
|
{
|
|
$this->logInWithPermission('ADMIN');
|
|
$content = new CSSContentParser($this->gridField->FieldHolder());
|
|
$deleteButtons = $content->getBySelector('.gridfield-button-delete');
|
|
$this->assertEquals(3, count($deleteButtons), 'Delete buttons should show when logged in.');
|
|
}
|
|
|
|
public function testActionsRequireCSRF()
|
|
{
|
|
$this->logInWithPermission('ADMIN');
|
|
$this->expectException(HTTPResponse_Exception::class);
|
|
$this->expectExceptionMessage(_t(
|
|
"SilverStripe\\Forms\\Form.CSRF_FAILED_MESSAGE",
|
|
"There seems to have been a technical problem. Please click the back button, ".
|
|
"refresh your browser, and try again."
|
|
));
|
|
$this->expectExceptionCode(400);
|
|
$stateID = 'testGridStateActionField';
|
|
$request = new HTTPRequest(
|
|
'POST',
|
|
'url',
|
|
array(),
|
|
array(
|
|
'action_gridFieldAlterAction?StateID='.$stateID,
|
|
'SecurityID' => null,
|
|
)
|
|
);
|
|
$request->setSession(new Session([]));
|
|
$this->gridField->gridFieldAlterAction(array('StateID'=>$stateID), $this->form, $request);
|
|
}
|
|
|
|
public function testDeleteActionWithoutCorrectPermission()
|
|
{
|
|
if (Security::getCurrentUser()) {
|
|
Security::setCurrentUser(null);
|
|
}
|
|
$this->expectException(ValidationException::class);
|
|
|
|
$stateID = 'testGridStateActionField';
|
|
$session = Controller::curr()->getRequest()->getSession();
|
|
$session->set(
|
|
$stateID,
|
|
array(
|
|
'grid' => '',
|
|
'actionName' => 'deleterecord',
|
|
'args' => array(
|
|
'RecordID' => $this->idFromFixture(Team::class, 'team1')
|
|
)
|
|
)
|
|
);
|
|
$token = SecurityToken::inst();
|
|
$request = new HTTPRequest(
|
|
'POST',
|
|
'url',
|
|
array(),
|
|
array(
|
|
'action_gridFieldAlterAction?StateID='.$stateID => true,
|
|
$token->getName() => $token->getValue(),
|
|
)
|
|
);
|
|
$request->setSession($session);
|
|
$this->gridField->gridFieldAlterAction(array('StateID'=>$stateID), $this->form, $request);
|
|
$this->assertEquals(
|
|
3,
|
|
$this->list->count(),
|
|
'User should\'t be able to delete records without correct permissions.'
|
|
);
|
|
}
|
|
|
|
public function testDeleteActionWithAdminPermission()
|
|
{
|
|
$this->logInWithPermission('ADMIN');
|
|
$stateID = 'testGridStateActionField';
|
|
$session = Controller::curr()->getRequest()->getSession();
|
|
$session->set(
|
|
$stateID,
|
|
array(
|
|
'grid'=>'',
|
|
'actionName'=>'deleterecord',
|
|
'args' => array(
|
|
'RecordID' => $this->idFromFixture(Team::class, 'team1')
|
|
)
|
|
)
|
|
);
|
|
$token = SecurityToken::inst();
|
|
$request = new HTTPRequest(
|
|
'POST',
|
|
'url',
|
|
array(),
|
|
array(
|
|
'action_gridFieldAlterAction?StateID='.$stateID=>true,
|
|
$token->getName() => $token->getValue(),
|
|
)
|
|
);
|
|
$request->setSession($session);
|
|
$this->gridField->gridFieldAlterAction(array('StateID'=>$stateID), $this->form, $request);
|
|
$this->assertEquals(2, $this->list->count(), 'User should be able to delete records with ADMIN permission.');
|
|
}
|
|
|
|
public function testDeleteActionRemoveRelation()
|
|
{
|
|
$this->logInWithPermission('ADMIN');
|
|
|
|
$config = GridFieldConfig::create()->addComponent(new GridFieldDeleteAction(true));
|
|
|
|
$session = Controller::curr()->getRequest()->getSession();
|
|
$gridField = new GridField('testfield', 'testfield', $this->list, $config);
|
|
new Form(null, 'mockform', new FieldList(array($gridField)), new FieldList());
|
|
$stateID = 'testGridStateActionField';
|
|
$session->set(
|
|
$stateID,
|
|
array(
|
|
'grid'=>'',
|
|
'actionName'=>'deleterecord',
|
|
'args' => array(
|
|
'RecordID' => $this->idFromFixture(Team::class, 'team1')
|
|
)
|
|
)
|
|
);
|
|
$token = SecurityToken::inst();
|
|
$request = new HTTPRequest(
|
|
'POST',
|
|
'url',
|
|
array(),
|
|
array(
|
|
'action_gridFieldAlterAction?StateID='.$stateID=>true,
|
|
$token->getName() => $token->getValue(),
|
|
)
|
|
);
|
|
$request->setSession($session);
|
|
$gridField->gridFieldAlterAction(array('StateID'=>$stateID), $this->form, $request);
|
|
$this->assertEquals(2, $this->list->count(), 'User should be able to delete records with ADMIN permission.');
|
|
}
|
|
}
|