PersistentTokenBasedRememberMeServicesTest.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317
  1. <?php
  2. namespace Symfony\Tests\Component\Security\Http\RememberMe;
  3. use Symfony\Component\Security\Http\RememberMe\RememberMeServicesInterface;
  4. use Symfony\Component\Security\Core\Authentication\Token\RememberMeToken;
  5. use Symfony\Component\HttpFoundation\HeaderBag;
  6. use Symfony\Component\Security\Core\Exception\UsernameNotFoundException;
  7. use Symfony\Component\Security\Core\Authentication\RememberMe\PersistentToken;
  8. use Symfony\Component\HttpFoundation\Request;
  9. use Symfony\Component\HttpFoundation\Response;
  10. use Symfony\Component\Security\Http\RememberMe\PersistentTokenBasedRememberMeServices;
  11. use Symfony\Component\Security\Core\Exception\TokenNotFoundException;
  12. use Symfony\Component\Security\Core\Exception\CookieTheftException;
  13. class PersistentTokenBasedRememberMeServicesTest extends \PHPUnit_Framework_TestCase
  14. {
  15. public function testAutoLoginReturnsNullWhenNoCookie()
  16. {
  17. $service = $this->getService(null, array('name' => 'foo'));
  18. $this->assertNull($service->autoLogin(new Request()));
  19. }
  20. public function testAutoLoginThrowsExceptionOnInvalidCookie()
  21. {
  22. $service = $this->getService(null, array('name' => 'foo', 'path' => null, 'domain' => null, 'always_remember_me' => false, 'remember_me_parameter' => 'foo'));
  23. $request = new Request;
  24. $request->request->set('foo', 'true');
  25. $request->cookies->set('foo', 'foo');
  26. $this->assertNull($service->autoLogin($request));
  27. $this->assertTrue($request->attributes->get(RememberMeServicesInterface::COOKIE_ATTR_NAME)->isCleared());
  28. }
  29. public function testAutoLoginThrowsExceptionOnNonExistentToken()
  30. {
  31. $service = $this->getService(null, array('name' => 'foo', 'path' => null, 'domain' => null, 'always_remember_me' => false, 'remember_me_parameter' => 'foo'));
  32. $request = new Request;
  33. $request->request->set('foo', 'true');
  34. $request->cookies->set('foo', $this->encodeCookie(array(
  35. $series = 'fooseries',
  36. $tokenValue = 'foovalue',
  37. )));
  38. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  39. $tokenProvider
  40. ->expects($this->once())
  41. ->method('loadTokenBySeries')
  42. ->will($this->throwException(new TokenNotFoundException('Token not found.')))
  43. ;
  44. $service->setTokenProvider($tokenProvider);
  45. $this->assertNull($service->autoLogin($request));
  46. $this->assertTrue($request->attributes->get(RememberMeServicesInterface::COOKIE_ATTR_NAME)->isCleared());
  47. }
  48. public function testAutoLoginReturnsNullOnNonExistentUser()
  49. {
  50. $userProvider = $this->getProvider();
  51. $service = $this->getService($userProvider, array('name' => 'foo', 'path' => null, 'domain' => null, 'always_remember_me' => true, 'lifetime' => 3600, 'secure' => false, 'httponly' => false));
  52. $request = new Request;
  53. $request->cookies->set('foo', $this->encodeCookie(array('fooseries', 'foovalue')));
  54. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  55. $tokenProvider
  56. ->expects($this->once())
  57. ->method('loadTokenBySeries')
  58. ->will($this->returnValue(new PersistentToken('fooclass', 'fooname', 'fooseries', 'foovalue', new \DateTime())))
  59. ;
  60. $service->setTokenProvider($tokenProvider);
  61. $userProvider
  62. ->expects($this->once())
  63. ->method('loadUserByUsername')
  64. ->will($this->throwException(new UsernameNotFoundException('user not found')))
  65. ;
  66. $this->assertNull($service->autoLogin($request));
  67. $this->assertTrue($request->attributes->has(RememberMeServicesInterface::COOKIE_ATTR_NAME));
  68. }
  69. public function testAutoLoginThrowsExceptionOnStolenCookieAndRemovesItFromThePersistentBackend()
  70. {
  71. $userProvider = $this->getProvider();
  72. $service = $this->getService($userProvider, array('name' => 'foo', 'path' => null, 'domain' => null, 'always_remember_me' => true));
  73. $request = new Request;
  74. $request->cookies->set('foo', $this->encodeCookie(array('fooseries', 'foovalue')));
  75. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  76. $service->setTokenProvider($tokenProvider);
  77. $tokenProvider
  78. ->expects($this->once())
  79. ->method('loadTokenBySeries')
  80. ->will($this->returnValue(new PersistentToken('fooclass', 'foouser', 'fooseries', 'anotherFooValue', new \DateTime())))
  81. ;
  82. $tokenProvider
  83. ->expects($this->once())
  84. ->method('deleteTokenBySeries')
  85. ->with($this->equalTo('fooseries'))
  86. ->will($this->returnValue(null))
  87. ;
  88. try {
  89. $service->autoLogin($request);
  90. $this->fail('Expected CookieTheftException was not thrown.');
  91. } catch (CookieTheftException $theft) { }
  92. $this->assertTrue($request->attributes->has(RememberMeServicesInterface::COOKIE_ATTR_NAME));
  93. }
  94. public function testAutoLoginDoesNotAcceptAnExpiredCookie()
  95. {
  96. $service = $this->getService(null, array('name' => 'foo', 'path' => null, 'domain' => null, 'always_remember_me' => true, 'lifetime' => 3600));
  97. $request = new Request;
  98. $request->cookies->set('foo', $this->encodeCookie(array('fooseries', 'foovalue')));
  99. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  100. $tokenProvider
  101. ->expects($this->once())
  102. ->method('loadTokenBySeries')
  103. ->with($this->equalTo('fooseries'))
  104. ->will($this->returnValue(new PersistentToken('fooclass', 'username', 'fooseries', 'foovalue', new \DateTime('yesterday'))))
  105. ;
  106. $service->setTokenProvider($tokenProvider);
  107. $this->assertNull($service->autoLogin($request));
  108. $this->assertTrue($request->attributes->has(RememberMeServicesInterface::COOKIE_ATTR_NAME));
  109. }
  110. public function testAutoLogin()
  111. {
  112. $user = $this->getMock('Symfony\Component\Security\Core\User\UserInterface');
  113. $user
  114. ->expects($this->once())
  115. ->method('getRoles')
  116. ->will($this->returnValue(array('ROLE_FOO')))
  117. ;
  118. $userProvider = $this->getProvider();
  119. $userProvider
  120. ->expects($this->once())
  121. ->method('loadUserByUsername')
  122. ->with($this->equalTo('foouser'))
  123. ->will($this->returnValue($user))
  124. ;
  125. $service = $this->getService($userProvider, array('name' => 'foo', 'path' => null, 'domain' => null, 'secure' => false, 'httponly' => false, 'always_remember_me' => true, 'lifetime' => 3600));
  126. $request = new Request;
  127. $request->cookies->set('foo', $this->encodeCookie(array('fooseries', 'foovalue')));
  128. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  129. $tokenProvider
  130. ->expects($this->once())
  131. ->method('loadTokenBySeries')
  132. ->with($this->equalTo('fooseries'))
  133. ->will($this->returnValue(new PersistentToken('fooclass', 'foouser', 'fooseries', 'foovalue', new \DateTime())))
  134. ;
  135. $service->setTokenProvider($tokenProvider);
  136. $returnedToken = $service->autoLogin($request);
  137. $this->assertInstanceOf('Symfony\Component\Security\Core\Authentication\Token\RememberMeToken', $returnedToken);
  138. $this->assertSame($user, $returnedToken->getUser());
  139. $this->assertEquals('fookey', $returnedToken->getKey());
  140. $this->assertTrue($request->attributes->has(RememberMeServicesInterface::COOKIE_ATTR_NAME));
  141. }
  142. public function testLogout()
  143. {
  144. $service = $this->getService(null, array('name' => 'foo', 'path' => '/foo', 'domain' => 'foodomain.foo'));
  145. $request = new Request();
  146. $request->cookies->set('foo', $this->encodeCookie(array('fooseries', 'foovalue')));
  147. $response = new Response();
  148. $token = $this->getMock('Symfony\Component\Security\Core\Authentication\Token\TokenInterface');
  149. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  150. $tokenProvider
  151. ->expects($this->once())
  152. ->method('deleteTokenBySeries')
  153. ->with($this->equalTo('fooseries'))
  154. ->will($this->returnValue(null))
  155. ;
  156. $service->setTokenProvider($tokenProvider);
  157. $service->logout($request, $response, $token);
  158. $cookie = $request->attributes->get(RememberMeServicesInterface::COOKIE_ATTR_NAME);
  159. $this->assertTrue($cookie->isCleared());
  160. $this->assertEquals('/foo', $cookie->getPath());
  161. $this->assertEquals('foodomain.foo', $cookie->getDomain());
  162. }
  163. public function testLogoutSimplyIgnoresNonSetRequestCookie()
  164. {
  165. $service = $this->getService(null, array('name' => 'foo', 'path' => null, 'domain' => null));
  166. $request = new Request;
  167. $response = new Response;
  168. $token = $this->getMock('Symfony\Component\Security\Core\Authentication\Token\TokenInterface');
  169. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  170. $tokenProvider
  171. ->expects($this->never())
  172. ->method('deleteTokenBySeries')
  173. ;
  174. $service->setTokenProvider($tokenProvider);
  175. $service->logout($request, $response, $token);
  176. $cookie = $request->attributes->get(RememberMeServicesInterface::COOKIE_ATTR_NAME);
  177. $this->assertTrue($cookie->isCleared());
  178. $this->assertNull($cookie->getPath());
  179. $this->assertNull($cookie->getDomain());
  180. }
  181. public function testLogoutSimplyIgnoresInvalidCookie()
  182. {
  183. $service = $this->getService(null, array('name' => 'foo', 'path' => null, 'domain' => null));
  184. $request = new Request;
  185. $request->cookies->set('foo', 'somefoovalue');
  186. $response = new Response;
  187. $token = $this->getMock('Symfony\Component\Security\Core\Authentication\Token\TokenInterface');
  188. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  189. $tokenProvider
  190. ->expects($this->never())
  191. ->method('deleteTokenBySeries')
  192. ;
  193. $service->setTokenProvider($tokenProvider);
  194. $service->logout($request, $response, $token);
  195. $this->assertTrue($request->attributes->get(RememberMeServicesInterface::COOKIE_ATTR_NAME)->isCleared());
  196. }
  197. public function testLoginFail()
  198. {
  199. $service = $this->getService(null, array('name' => 'foo', 'path' => null, 'domain' => null));
  200. $request = new Request();
  201. $this->assertFalse($request->attributes->has(RememberMeServicesInterface::COOKIE_ATTR_NAME));
  202. $service->loginFail($request);
  203. $this->assertTrue($request->attributes->get(RememberMeServicesInterface::COOKIE_ATTR_NAME)->isCleared());
  204. }
  205. public function testLoginSuccessSetsCookieWhenLoggedInWithNonRememberMeTokenInterfaceImplementation()
  206. {
  207. $service = $this->getService(null, array('name' => 'foo', 'domain' => 'myfoodomain.foo', 'path' => '/foo/path', 'secure' => true, 'httponly' => true, 'lifetime' => 3600, 'always_remember_me' => true));
  208. $request = new Request;
  209. $response = new Response;
  210. $account = $this->getMock('Symfony\Component\Security\Core\User\UserInterface');
  211. $account
  212. ->expects($this->once())
  213. ->method('getUsername')
  214. ->will($this->returnValue('foo'))
  215. ;
  216. $token = $this->getMock('Symfony\Component\Security\Core\Authentication\Token\TokenInterface');
  217. $token
  218. ->expects($this->any())
  219. ->method('getUser')
  220. ->will($this->returnValue($account))
  221. ;
  222. $tokenProvider = $this->getMock('Symfony\Component\Security\Core\Authentication\RememberMe\TokenProviderInterface');
  223. $tokenProvider
  224. ->expects($this->once())
  225. ->method('createNewToken')
  226. ;
  227. $service->setTokenProvider($tokenProvider);
  228. $this->assertFalse($response->headers->hasCookie('foo'));
  229. $service->loginSuccess($request, $response, $token);
  230. $cookie = $response->headers->getCookie('foo');
  231. $this->assertFalse($cookie->isCleared());
  232. $this->assertTrue($cookie->isSecure());
  233. $this->assertTrue($cookie->isHttpOnly());
  234. $this->assertTrue($cookie->getExpiresTime() > time() + 3590 && $cookie->getExpiresTime() < time() + 3610);
  235. $this->assertEquals('myfoodomain.foo', $cookie->getDomain());
  236. $this->assertEquals('/foo/path', $cookie->getPath());
  237. }
  238. protected function encodeCookie(array $parts)
  239. {
  240. $service = $this->getService();
  241. $r = new \ReflectionMethod($service, 'encodeCookie');
  242. $r->setAccessible(true);
  243. return $r->invoke($service, $parts);
  244. }
  245. protected function getService($userProvider = null, $options = array(), $logger = null)
  246. {
  247. if (null === $userProvider) {
  248. $userProvider = $this->getProvider();
  249. }
  250. return new PersistentTokenBasedRememberMeServices(array($userProvider), 'fookey', 'fookey', $options, $logger);
  251. }
  252. protected function getProvider()
  253. {
  254. $provider = $this->getMock('Symfony\Component\Security\Core\User\UserProviderInterface');
  255. $provider
  256. ->expects($this->any())
  257. ->method('supportsClass')
  258. ->will($this->returnValue(true))
  259. ;
  260. return $provider;
  261. }
  262. }