gitea源码

org_test.go 9.3KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254
  1. // Copyright 2019 The Gitea Authors. All rights reserved.
  2. // SPDX-License-Identifier: MIT
  3. package integration
  4. import (
  5. "fmt"
  6. "net/http"
  7. "strings"
  8. "testing"
  9. auth_model "code.gitea.io/gitea/models/auth"
  10. "code.gitea.io/gitea/models/db"
  11. "code.gitea.io/gitea/models/organization"
  12. "code.gitea.io/gitea/models/perm"
  13. "code.gitea.io/gitea/models/unit"
  14. "code.gitea.io/gitea/models/unittest"
  15. user_model "code.gitea.io/gitea/models/user"
  16. api "code.gitea.io/gitea/modules/structs"
  17. "code.gitea.io/gitea/tests"
  18. "github.com/stretchr/testify/assert"
  19. "github.com/stretchr/testify/require"
  20. )
  21. func TestOrgRepos(t *testing.T) {
  22. defer tests.PrepareTestEnv(t)()
  23. var (
  24. users = []string{"user1", "user2"}
  25. cases = map[string][]string{
  26. "alphabetically": {"repo21", "repo3", "repo5"},
  27. "reversealphabetically": {"repo5", "repo3", "repo21"},
  28. }
  29. )
  30. for _, user := range users {
  31. t.Run(user, func(t *testing.T) {
  32. session := loginUser(t, user)
  33. for sortBy, repos := range cases {
  34. req := NewRequest(t, "GET", "/org3?sort="+sortBy)
  35. resp := session.MakeRequest(t, req, http.StatusOK)
  36. htmlDoc := NewHTMLParser(t, resp.Body)
  37. sel := htmlDoc.doc.Find("a.name")
  38. assert.Len(t, repos, len(sel.Nodes))
  39. for i := range repos {
  40. assert.Equal(t, repos[i], strings.TrimSpace(sel.Eq(i).Text()))
  41. }
  42. }
  43. })
  44. }
  45. }
  46. func TestLimitedOrg(t *testing.T) {
  47. defer tests.PrepareTestEnv(t)()
  48. // not logged in user
  49. req := NewRequest(t, "GET", "/limited_org")
  50. MakeRequest(t, req, http.StatusNotFound)
  51. req = NewRequest(t, "GET", "/limited_org/public_repo_on_limited_org")
  52. MakeRequest(t, req, http.StatusNotFound)
  53. req = NewRequest(t, "GET", "/limited_org/private_repo_on_limited_org")
  54. MakeRequest(t, req, http.StatusNotFound)
  55. // login non-org member user
  56. session := loginUser(t, "user2")
  57. req = NewRequest(t, "GET", "/limited_org")
  58. session.MakeRequest(t, req, http.StatusOK)
  59. req = NewRequest(t, "GET", "/limited_org/public_repo_on_limited_org")
  60. session.MakeRequest(t, req, http.StatusOK)
  61. req = NewRequest(t, "GET", "/limited_org/private_repo_on_limited_org")
  62. session.MakeRequest(t, req, http.StatusNotFound)
  63. // site admin
  64. session = loginUser(t, "user1")
  65. req = NewRequest(t, "GET", "/limited_org")
  66. session.MakeRequest(t, req, http.StatusOK)
  67. req = NewRequest(t, "GET", "/limited_org/public_repo_on_limited_org")
  68. session.MakeRequest(t, req, http.StatusOK)
  69. req = NewRequest(t, "GET", "/limited_org/private_repo_on_limited_org")
  70. session.MakeRequest(t, req, http.StatusOK)
  71. }
  72. func TestPrivateOrg(t *testing.T) {
  73. defer tests.PrepareTestEnv(t)()
  74. // not logged in user
  75. req := NewRequest(t, "GET", "/privated_org")
  76. MakeRequest(t, req, http.StatusNotFound)
  77. req = NewRequest(t, "GET", "/privated_org/public_repo_on_private_org")
  78. MakeRequest(t, req, http.StatusNotFound)
  79. req = NewRequest(t, "GET", "/privated_org/private_repo_on_private_org")
  80. MakeRequest(t, req, http.StatusNotFound)
  81. // login non-org member user
  82. session := loginUser(t, "user2")
  83. req = NewRequest(t, "GET", "/privated_org")
  84. session.MakeRequest(t, req, http.StatusNotFound)
  85. req = NewRequest(t, "GET", "/privated_org/public_repo_on_private_org")
  86. session.MakeRequest(t, req, http.StatusNotFound)
  87. req = NewRequest(t, "GET", "/privated_org/private_repo_on_private_org")
  88. session.MakeRequest(t, req, http.StatusNotFound)
  89. // non-org member who is collaborator on repo in private org
  90. session = loginUser(t, "user4")
  91. req = NewRequest(t, "GET", "/privated_org")
  92. session.MakeRequest(t, req, http.StatusNotFound)
  93. req = NewRequest(t, "GET", "/privated_org/public_repo_on_private_org") // colab of this repo
  94. session.MakeRequest(t, req, http.StatusOK)
  95. req = NewRequest(t, "GET", "/privated_org/private_repo_on_private_org")
  96. session.MakeRequest(t, req, http.StatusNotFound)
  97. // site admin
  98. session = loginUser(t, "user1")
  99. req = NewRequest(t, "GET", "/privated_org")
  100. session.MakeRequest(t, req, http.StatusOK)
  101. req = NewRequest(t, "GET", "/privated_org/public_repo_on_private_org")
  102. session.MakeRequest(t, req, http.StatusOK)
  103. req = NewRequest(t, "GET", "/privated_org/private_repo_on_private_org")
  104. session.MakeRequest(t, req, http.StatusOK)
  105. }
  106. func TestOrgMembers(t *testing.T) {
  107. defer tests.PrepareTestEnv(t)()
  108. // not logged in user
  109. req := NewRequest(t, "GET", "/org/org25/members")
  110. MakeRequest(t, req, http.StatusOK)
  111. // org member
  112. session := loginUser(t, "user24")
  113. req = NewRequest(t, "GET", "/org/org25/members")
  114. session.MakeRequest(t, req, http.StatusOK)
  115. // site admin
  116. session = loginUser(t, "user1")
  117. req = NewRequest(t, "GET", "/org/org25/members")
  118. session.MakeRequest(t, req, http.StatusOK)
  119. }
  120. func TestOrgRestrictedUser(t *testing.T) {
  121. defer tests.PrepareTestEnv(t)()
  122. // privated_org is a private org who has id 23
  123. orgName := "privated_org"
  124. // public_repo_on_private_org is a public repo on privated_org
  125. repoName := "public_repo_on_private_org"
  126. // user29 is a restricted user who is not a member of the organization
  127. restrictedUser := "user29"
  128. // #17003 reports a bug whereby adding a restricted user to a read-only team doesn't work
  129. // assert restrictedUser cannot see the org or the public repo
  130. restrictedSession := loginUser(t, restrictedUser)
  131. req := NewRequest(t, "GET", "/"+orgName)
  132. restrictedSession.MakeRequest(t, req, http.StatusNotFound)
  133. req = NewRequest(t, "GET", fmt.Sprintf("/%s/%s", orgName, repoName))
  134. restrictedSession.MakeRequest(t, req, http.StatusNotFound)
  135. // Therefore create a read-only team
  136. adminSession := loginUser(t, "user1")
  137. token := getTokenForLoggedInUser(t, adminSession, auth_model.AccessTokenScopeWriteOrganization)
  138. teamToCreate := &api.CreateTeamOption{
  139. Name: "codereader",
  140. Description: "Code Reader",
  141. IncludesAllRepositories: true,
  142. Permission: "read",
  143. Units: []string{"repo.code"},
  144. }
  145. req = NewRequestWithJSON(t, "POST", fmt.Sprintf("/api/v1/orgs/%s/teams", orgName), teamToCreate).
  146. AddTokenAuth(token)
  147. var apiTeam api.Team
  148. resp := adminSession.MakeRequest(t, req, http.StatusCreated)
  149. DecodeJSON(t, resp, &apiTeam)
  150. checkTeamResponse(t, "CreateTeam_codereader", &apiTeam, teamToCreate.Name, teamToCreate.Description, teamToCreate.IncludesAllRepositories,
  151. "none", teamToCreate.Units, nil)
  152. checkTeamBean(t, apiTeam.ID, teamToCreate.Name, teamToCreate.Description, teamToCreate.IncludesAllRepositories,
  153. "none", teamToCreate.Units, nil)
  154. // teamID := apiTeam.ID
  155. // Now we need to add the restricted user to the team
  156. req = NewRequest(t, "PUT", fmt.Sprintf("/api/v1/teams/%d/members/%s", apiTeam.ID, restrictedUser)).
  157. AddTokenAuth(token)
  158. _ = adminSession.MakeRequest(t, req, http.StatusNoContent)
  159. // Now we need to check if the restrictedUser can access the repo
  160. req = NewRequest(t, "GET", "/"+orgName)
  161. restrictedSession.MakeRequest(t, req, http.StatusOK)
  162. req = NewRequest(t, "GET", fmt.Sprintf("/%s/%s", orgName, repoName))
  163. restrictedSession.MakeRequest(t, req, http.StatusOK)
  164. }
  165. func TestTeamSearch(t *testing.T) {
  166. defer tests.PrepareTestEnv(t)()
  167. user := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 15})
  168. org := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 17})
  169. var results TeamSearchResults
  170. session := loginUser(t, user.Name)
  171. req := NewRequestf(t, "GET", "/org/%s/teams/-/search?q=%s", org.Name, "_team")
  172. resp := session.MakeRequest(t, req, http.StatusOK)
  173. DecodeJSON(t, resp, &results)
  174. assert.NotEmpty(t, results.Data)
  175. assert.Len(t, results.Data, 2)
  176. assert.Equal(t, "review_team", results.Data[0].Name)
  177. assert.Equal(t, "test_team", results.Data[1].Name)
  178. // no access if not organization member
  179. user5 := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 5})
  180. session = loginUser(t, user5.Name)
  181. req = NewRequestf(t, "GET", "/org/%s/teams/-/search?q=%s", org.Name, "team")
  182. session.MakeRequest(t, req, http.StatusNotFound)
  183. t.Run("SearchWithPermission", func(t *testing.T) {
  184. ctx := t.Context()
  185. const testOrgID int64 = 500
  186. const testRepoID int64 = 2000
  187. testTeam := &organization.Team{OrgID: testOrgID, LowerName: "test_team", AccessMode: perm.AccessModeNone}
  188. require.NoError(t, db.Insert(ctx, testTeam))
  189. require.NoError(t, db.Insert(ctx, &organization.TeamRepo{OrgID: testOrgID, TeamID: testTeam.ID, RepoID: testRepoID}))
  190. require.NoError(t, db.Insert(ctx, &organization.TeamUnit{OrgID: testOrgID, TeamID: testTeam.ID, Type: unit.TypeCode, AccessMode: perm.AccessModeRead}))
  191. require.NoError(t, db.Insert(ctx, &organization.TeamUnit{OrgID: testOrgID, TeamID: testTeam.ID, Type: unit.TypeIssues, AccessMode: perm.AccessModeWrite}))
  192. teams, err := organization.GetTeamsWithAccessToAnyRepoUnit(ctx, testOrgID, testRepoID, perm.AccessModeRead, unit.TypeCode, unit.TypeIssues)
  193. require.NoError(t, err)
  194. assert.Len(t, teams, 1) // can read "code" or "issues"
  195. teams, err = organization.GetTeamsWithAccessToAnyRepoUnit(ctx, testOrgID, testRepoID, perm.AccessModeWrite, unit.TypeCode)
  196. require.NoError(t, err)
  197. assert.Empty(t, teams) // cannot write "code"
  198. teams, err = organization.GetTeamsWithAccessToAnyRepoUnit(ctx, testOrgID, testRepoID, perm.AccessModeWrite, unit.TypeIssues)
  199. require.NoError(t, err)
  200. assert.Len(t, teams, 1) // can write "issues"
  201. _, _ = db.GetEngine(ctx).ID(testTeam.ID).Update(&organization.Team{AccessMode: perm.AccessModeWrite})
  202. teams, err = organization.GetTeamsWithAccessToAnyRepoUnit(ctx, testOrgID, testRepoID, perm.AccessModeWrite, unit.TypeCode)
  203. require.NoError(t, err)
  204. assert.Len(t, teams, 1) // team permission is "write", so can write "code"
  205. })
  206. }