summaryrefslogtreecommitdiff
path: root/tests/units/Core/Security/AccessMapTest.php
blob: 61693ce81381970f589eb68201054dd871f0fb68 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
<?php

require_once __DIR__.'/../../Base.php';

use Kanboard\Core\Security\AccessMap;

class AccessMapTest extends Base
{
    public function testRoleHierarchy()
    {
        $acl = new AccessMap;
        $acl->setRoleHierarchy('admin', array('manager', 'user'));
        $acl->setRoleHierarchy('manager', array('user'));

        $this->assertEquals(array('admin'), $acl->getRoleHierarchy('admin'));
        $this->assertEquals(array('manager', 'admin'), $acl->getRoleHierarchy('manager'));
        $this->assertEquals(array('user', 'admin', 'manager'), $acl->getRoleHierarchy('user'));
    }

    public function testAddRulesAndGetRoles()
    {
        $acl = new AccessMap;
        $acl->setDefaultRole('role3');
        $acl->setRoleHierarchy('role2', array('role1'));

        $acl->add('MyController', 'myAction1', 'role2');
        $acl->add('MyController', 'myAction2', 'role1');
        $acl->add('MyAdminController', '*', 'role2');
        $acl->add('SomethingElse', array('actionA', 'actionB'), 'role2');

        $this->assertEquals(array('role2'), $acl->getRoles('mycontroller', 'MyAction1'));
        $this->assertEquals(array('role1', 'role2'), $acl->getRoles('mycontroller', 'MyAction2'));
        $this->assertEquals(array('role2'), $acl->getRoles('Myadmincontroller', 'MyAction'));
        $this->assertEquals(array('role3'), $acl->getRoles('AnotherController', 'ActionNotFound'));
        $this->assertEquals(array('role2'), $acl->getRoles('somethingelse', 'actiona'));
        $this->assertEquals(array('role2'), $acl->getRoles('somethingelse', 'actionb'));
        $this->assertEquals(array('role3'), $acl->getRoles('somethingelse', 'actionc'));
    }
}