| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | <?php | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | namespace Tests\Permissions; | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | use BookStack\Auth\User; | 
					
						
							| 
									
										
										
										
											2020-11-22 08:17:45 +08:00
										 |  |  | use BookStack\Entities\Models\Book; | 
					
						
							|  |  |  | use BookStack\Entities\Models\Bookshelf; | 
					
						
							|  |  |  | use BookStack\Entities\Models\Chapter; | 
					
						
							|  |  |  | use BookStack\Entities\Models\Entity; | 
					
						
							|  |  |  | use BookStack\Entities\Models\Page; | 
					
						
							| 
									
										
										
										
											2020-12-19 05:42:43 +08:00
										 |  |  | use Illuminate\Support\Str; | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  | use Tests\TestCase; | 
					
						
							| 
									
										
										
										
											2017-11-19 23:56:06 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  | class EntityPermissionsTest extends TestCase | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | { | 
					
						
							| 
									
										
										
										
											2017-11-19 23:56:06 +08:00
										 |  |  |     /** | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  |      * @var User | 
					
						
							| 
									
										
										
										
											2017-11-19 23:56:06 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     protected $user; | 
					
						
							| 
									
										
										
										
											2017-11-19 23:56:06 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * @var User | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |     protected $viewer; | 
					
						
							| 
									
										
										
										
											2017-11-19 23:56:06 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-10-31 04:29:59 +08:00
										 |  |  |     protected function setUp(): void | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         parent::setUp(); | 
					
						
							| 
									
										
										
										
											2016-05-07 21:29:43 +08:00
										 |  |  |         $this->user = $this->getEditor(); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |         $this->viewer = $this->getViewer(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |     protected function setRestrictionsForTestRoles(Entity $entity, array $actions = []) | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2018-04-15 01:47:13 +08:00
										 |  |  |         $roles = [ | 
					
						
							|  |  |  |             $this->user->roles->first(), | 
					
						
							|  |  |  |             $this->viewer->roles->first(), | 
					
						
							|  |  |  |         ]; | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setEntityRestrictions($entity, $actions, $roles); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     public function test_bookshelf_view_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Bookshelf $shelf */ | 
					
						
							|  |  |  |         $shelf = Bookshelf::query()->first(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($shelf->getUrl()) | 
					
						
							|  |  |  |             ->assertStatus(200); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, []); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->followingRedirects()->get($shelf->getUrl()) | 
					
						
							|  |  |  |             ->assertSee('Bookshelf not found'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl()) | 
					
						
							|  |  |  |             ->assertSee($shelf->name); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_bookshelf_update_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Bookshelf $shelf */ | 
					
						
							|  |  |  |         $shelf = Bookshelf::query()->first(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($shelf->getUrl('/edit')) | 
					
						
							|  |  |  |             ->assertSee('Edit Book'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $resp = $this->get($shelf->getUrl('/edit')) | 
					
						
							|  |  |  |             ->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->followRedirects($resp)->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/edit')) | 
					
						
							|  |  |  |             ->assertOk(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_bookshelf_delete_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Bookshelf $shelf */ | 
					
						
							|  |  |  |         $shelf = Bookshelf::query()->first(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($shelf->getUrl('/delete')) | 
					
						
							|  |  |  |             ->assertSee('Delete Book'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/delete'))->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/delete')) | 
					
						
							|  |  |  |             ->assertOk() | 
					
						
							|  |  |  |             ->assertSee('Delete Book'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     public function test_book_view_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $bookPage = $book->pages->first(); | 
					
						
							|  |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($bookUrl) | 
					
						
							|  |  |  |             ->assertOk(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, []); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->followingRedirects()->get($bookUrl) | 
					
						
							|  |  |  |             ->assertSee('Book not found'); | 
					
						
							|  |  |  |         $this->followingRedirects()->get($bookPage->getUrl()) | 
					
						
							|  |  |  |             ->assertSee('Page not found'); | 
					
						
							|  |  |  |         $this->followingRedirects()->get($bookChapter->getUrl()) | 
					
						
							|  |  |  |             ->assertSee('Chapter not found'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl) | 
					
						
							|  |  |  |             ->assertSee($book->name); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl()) | 
					
						
							|  |  |  |             ->assertSee($bookPage->name); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl()) | 
					
						
							|  |  |  |             ->assertSee($bookChapter->name); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_book_create_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |         $this->actingAs($this->viewer) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($bookUrl) | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($bookUrl) | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'delete', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/create-chapter')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->get($bookUrl . '/create-page')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->get($bookUrl) | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'create']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $resp = $this->post($book->getUrl('/create-chapter'), [ | 
					
						
							| 
									
										
										
										
											2021-09-19 04:21:44 +08:00
										 |  |  |             'name'        => 'test chapter', | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             'description' => 'desc', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |         $resp->assertRedirect($book->getUrl('/chapter/test-chapter')); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->get($book->getUrl('/create-page')); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->where('draft', '=', true)->orderBy('id', 'desc')->first(); | 
					
						
							|  |  |  |         $resp = $this->post($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'test page', | 
					
						
							|  |  |  |             'html' => 'test content', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |         $resp->assertRedirect($book->getUrl('/page/test-page')); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->get($bookUrl) | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_book_update_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $bookPage = $book->pages->first(); | 
					
						
							|  |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($bookUrl . '/edit') | 
					
						
							|  |  |  |             ->assertSee('Edit Book'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/edit')->assertOk(); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/edit')->assertOk(); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/edit')->assertSee('Edit Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_book_delete_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $bookPage = $book->pages->first(); | 
					
						
							|  |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($bookUrl . '/delete') | 
					
						
							|  |  |  |             ->assertSee('Delete Book'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/delete')->assertOk()->assertSee('Delete Book'); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl('/delete'))->assertOk()->assertSee('Delete Page'); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl('/delete'))->assertSee('Delete Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_chapter_view_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $chapterPage = $chapter->pages->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $chapterUrl = $chapter->getUrl(); | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($chapterUrl)->assertOk(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, []); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->followingRedirects()->get($chapterUrl)->assertSee('Chapter not found'); | 
					
						
							|  |  |  |         $this->followingRedirects()->get($chapterPage->getUrl())->assertSee('Page not found'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl)->assertSee($chapter->name); | 
					
						
							|  |  |  |         $this->get($chapterPage->getUrl())->assertSee($chapterPage->name); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_chapter_create_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $chapterUrl = $chapter->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($chapterUrl) | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Page'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view', 'delete', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl . '/create-page')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($chapterUrl)->assertElementNotContains('.actions', 'New Page'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view', 'create']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapter->getUrl('/create-page')); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->where('draft', '=', true)->orderBy('id', 'desc')->first(); | 
					
						
							|  |  |  |         $resp = $this->post($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'test page', | 
					
						
							|  |  |  |             'html' => 'test content', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |         $resp->assertRedirect($chapter->book->getUrl('/page/test-page')); | 
					
						
							| 
									
										
										
										
											2017-04-30 05:01:43 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl)->assertElementContains('.actions', 'New Page'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_chapter_update_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $chapterPage = $chapter->pages->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $chapterUrl = $chapter->getUrl(); | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($chapterUrl . '/edit') | 
					
						
							|  |  |  |             ->assertSee('Edit Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($chapterPage->getUrl() . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl . '/edit')->assertOk()->assertSee('Edit Chapter'); | 
					
						
							|  |  |  |         $this->get($chapterPage->getUrl() . '/edit')->assertOk(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_chapter_delete_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $chapterPage = $chapter->pages->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $chapterUrl = $chapter->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($chapterUrl . '/delete') | 
					
						
							|  |  |  |             ->assertSee('Delete Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($chapterPage->getUrl() . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($chapter, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($chapterUrl . '/delete')->assertOk()->assertSee('Delete Chapter'); | 
					
						
							|  |  |  |         $this->get($chapterPage->getUrl() . '/delete')->assertOk()->assertSee('Delete Page'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_page_view_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $pageUrl = $page->getUrl(); | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($pageUrl)->assertOk(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, ['update', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($pageUrl)->assertSee('Page not found'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, ['view']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($pageUrl)->assertSee($page->name); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_page_update_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $pageUrl = $page->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($pageUrl . '/edit') | 
					
						
							|  |  |  |             ->assertElementExists('input[name="name"][value="' . $page->name . '"]'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($pageUrl . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($pageUrl . '/edit') | 
					
						
							|  |  |  |             ->assertOk() | 
					
						
							|  |  |  |             ->assertElementExists('input[name="name"][value="' . $page->name . '"]'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_page_delete_restriction() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $pageUrl = $page->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($pageUrl . '/delete') | 
					
						
							|  |  |  |             ->assertSee('Delete Page'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($pageUrl . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($pageUrl . '/delete')->assertOk()->assertSee('Delete Page'); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     protected function entityRestrictionFormTest(string $model, string $title, string $permission, string $roleId) | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         /** @var Entity $modelInstance */ | 
					
						
							|  |  |  |         $modelInstance = $model::query()->first(); | 
					
						
							|  |  |  |         $this->asAdmin()->get($modelInstance->getUrl('/permissions')) | 
					
						
							|  |  |  |             ->assertSee($title); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->put($modelInstance->getUrl('/permissions'), [ | 
					
						
							| 
									
										
										
										
											2021-09-19 04:21:44 +08:00
										 |  |  |             'restricted'   => 'true', | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             'restrictions' => [ | 
					
						
							|  |  |  |                 $roleId => [ | 
					
						
							| 
									
										
										
										
											2021-09-19 04:21:44 +08:00
										 |  |  |                     $permission => 'true', | 
					
						
							|  |  |  |                 ], | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ], | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->assertDatabaseHas($modelInstance->getTable(), ['id' => $modelInstance->id, 'restricted' => true]); | 
					
						
							|  |  |  |         $this->assertDatabaseHas('entity_permissions', [ | 
					
						
							|  |  |  |             'restrictable_id'   => $modelInstance->id, | 
					
						
							|  |  |  |             'restrictable_type' => $modelInstance->getMorphClass(), | 
					
						
							|  |  |  |             'role_id'           => $roleId, | 
					
						
							|  |  |  |             'action'            => $permission, | 
					
						
							|  |  |  |         ]); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     public function test_bookshelf_restriction_form() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->entityRestrictionFormTest(Bookshelf::class, 'Bookshelf Permissions', 'view', '2'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     public function test_book_restriction_form() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->entityRestrictionFormTest(Book::class, 'Book Permissions', 'view', '2'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_chapter_restriction_form() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->entityRestrictionFormTest(Chapter::class, 'Chapter Permissions', 'update', '2'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_page_restriction_form() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->entityRestrictionFormTest(Page::class, 'Page Permissions', 'delete', '2'); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_restricted_pages_not_visible_in_book_navigation_on_pages() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $page = $chapter->pages->first(); | 
					
						
							|  |  |  |         $page2 = $chapter->pages[2]; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, []); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($page2->getUrl()) | 
					
						
							|  |  |  |             ->assertElementNotContains('.sidebar-page-list', $page->name); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_restricted_pages_not_visible_in_book_navigation_on_chapters() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $page = $chapter->pages->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, []); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($chapter->getUrl()) | 
					
						
							|  |  |  |             ->assertElementNotContains('.sidebar-page-list', $page->name); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_restricted_pages_not_visible_on_chapter_pages() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |         $page = $chapter->pages->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($page, []); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($chapter->getUrl()) | 
					
						
							|  |  |  |             ->assertDontSee($page->name); | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-12-18 01:31:18 +08:00
										 |  |  |     public function test_restricted_chapter_pages_not_visible_on_book_page() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Chapter $chapter */ | 
					
						
							| 
									
										
										
										
											2020-12-18 01:31:18 +08:00
										 |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($chapter->book->getUrl()) | 
					
						
							|  |  |  |             ->assertSee($chapter->pages->first()->name); | 
					
						
							| 
									
										
										
										
											2020-12-18 01:31:18 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         foreach ($chapter->pages as $page) { | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |             $this->setRestrictionsForTestRoles($page, []); | 
					
						
							| 
									
										
										
										
											2020-12-18 01:31:18 +08:00
										 |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->user) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($chapter->book->getUrl()) | 
					
						
							|  |  |  |             ->assertDontSee($chapter->pages->first()->name); | 
					
						
							| 
									
										
										
										
											2020-12-18 01:31:18 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     public function test_bookshelf_update_restriction_override() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Bookshelf $shelf */ | 
					
						
							|  |  |  |         $shelf = Bookshelf::query()->first(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->viewer) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($shelf->getUrl('/edit')) | 
					
						
							|  |  |  |             ->assertDontSee('Edit Book'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/edit'))->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/edit'))->assertOk(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_bookshelf_delete_restriction_override() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Bookshelf $shelf */ | 
					
						
							|  |  |  |         $shelf = Bookshelf::query()->first(); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->viewer) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($shelf->getUrl('/delete')) | 
					
						
							|  |  |  |             ->assertDontSee('Delete Book'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/delete'))->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($shelf, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($shelf->getUrl('/delete'))->assertOk()->assertSee('Delete Book'); | 
					
						
							| 
									
										
										
										
											2018-09-21 22:15:16 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |     public function test_book_create_restriction_override() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->viewer) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($bookUrl) | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'delete', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/create-chapter')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookUrl . '/create-page')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookUrl)->assertElementNotContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementNotContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'create']); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $resp = $this->post($book->getUrl('/create-chapter'), [ | 
					
						
							| 
									
										
										
										
											2021-09-19 04:21:44 +08:00
										 |  |  |             'name'        => 'test chapter', | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             'description' => 'test desc', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |         $resp->assertRedirect($book->getUrl('/chapter/test-chapter')); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->get($book->getUrl('/create-page')); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->where('draft', '=', true)->orderByDesc('id')->first(); | 
					
						
							|  |  |  |         $resp = $this->post($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'test page', | 
					
						
							|  |  |  |             'html' => 'test desc', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |         $resp->assertRedirect($book->getUrl('/page/test-page')); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->get($bookUrl) | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Page') | 
					
						
							|  |  |  |             ->assertElementContains('.actions', 'New Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_book_update_restriction_override() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |         $bookPage = $book->pages->first(); | 
					
						
							|  |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->viewer)->get($bookUrl . '/edit') | 
					
						
							|  |  |  |             ->assertDontSee('Edit Book'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/edit')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/edit')->assertOk(); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/edit')->assertOk(); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/edit')->assertSee('Edit Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_book_delete_restriction_override() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |         $bookPage = $book->pages->first(); | 
					
						
							|  |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $bookUrl = $book->getUrl(); | 
					
						
							|  |  |  |         $this->actingAs($this->viewer) | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |             ->get($bookUrl . '/delete') | 
					
						
							|  |  |  |             ->assertDontSee('Delete Book'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'update']); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/delete')->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, ['view', 'delete']); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookUrl . '/delete')->assertOk()->assertSee('Delete Book'); | 
					
						
							|  |  |  |         $this->get($bookPage->getUrl() . '/delete')->assertOk()->assertSee('Delete Page'); | 
					
						
							|  |  |  |         $this->get($bookChapter->getUrl() . '/delete')->assertSee('Delete Chapter'); | 
					
						
							| 
									
										
										
										
											2016-03-31 03:15:44 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-04-22 20:39:34 +08:00
										 |  |  |     public function test_page_visible_if_has_permissions_when_book_not_visible() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2017-11-19 23:56:06 +08:00
										 |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							|  |  |  |         $bookPage = $bookChapter->pages->first(); | 
					
						
							| 
									
										
										
										
											2020-12-19 05:42:43 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         foreach ([$book, $bookChapter, $bookPage] as $entity) { | 
					
						
							|  |  |  |             $entity->name = Str::random(24); | 
					
						
							|  |  |  |             $entity->save(); | 
					
						
							|  |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, []); | 
					
						
							|  |  |  |         $this->setRestrictionsForTestRoles($bookPage, ['view']); | 
					
						
							| 
									
										
										
										
											2017-04-22 20:39:34 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->viewer); | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $resp = $this->get($bookPage->getUrl()); | 
					
						
							|  |  |  |         $resp->assertOk(); | 
					
						
							|  |  |  |         $resp->assertSee($bookPage->name); | 
					
						
							|  |  |  |         $resp->assertDontSee(substr($book->name, 0, 15)); | 
					
						
							|  |  |  |         $resp->assertDontSee(substr($bookChapter->name, 0, 15)); | 
					
						
							| 
									
										
										
										
											2017-04-22 20:39:34 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-31 22:47:08 +08:00
										 |  |  |     public function test_book_sort_view_permission() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $firstBook */ | 
					
						
							|  |  |  |         $firstBook = Book::query()->first(); | 
					
						
							|  |  |  |         /** @var Book $secondBook */ | 
					
						
							|  |  |  |         $secondBook = Book::query()->find(2); | 
					
						
							| 
									
										
										
										
											2017-12-31 22:47:08 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($firstBook, ['view', 'update']); | 
					
						
							|  |  |  |         $this->setRestrictionsForTestRoles($secondBook, ['view']); | 
					
						
							| 
									
										
										
										
											2017-12-31 22:47:08 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         // Test sort page visibility
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($secondBook->getUrl('/sort'))->assertRedirect('/'); | 
					
						
							|  |  |  |         $this->get('/')->assertSee('You do not have permission'); | 
					
						
							| 
									
										
										
										
											2017-12-31 22:47:08 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         // Check sort page on first book
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($firstBook->getUrl('/sort')); | 
					
						
							| 
									
										
										
										
											2017-12-31 22:47:08 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-07-14 21:12:29 +08:00
										 |  |  |     public function test_can_create_page_if_chapter_has_permissions_when_book_not_visible() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         /** @var Book $book */ | 
					
						
							|  |  |  |         $book = Book::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($book, []); | 
					
						
							| 
									
										
										
										
											2018-07-14 21:12:29 +08:00
										 |  |  |         $bookChapter = $book->chapters->first(); | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($bookChapter, ['view']); | 
					
						
							| 
									
										
										
										
											2018-07-14 21:12:29 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->actingAs($this->user)->get($bookChapter->getUrl()) | 
					
						
							|  |  |  |             ->assertDontSee('New Page'); | 
					
						
							| 
									
										
										
										
											2018-07-14 21:12:29 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-04 06:11:00 +08:00
										 |  |  |         $this->setRestrictionsForTestRoles($bookChapter, ['view', 'create']); | 
					
						
							| 
									
										
										
										
											2018-07-14 21:12:29 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-18 05:35:28 +08:00
										 |  |  |         $this->get($bookChapter->getUrl('/create-page')); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->where('draft', '=', true)->orderByDesc('id')->first(); | 
					
						
							|  |  |  |         $resp = $this->post($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'test page', | 
					
						
							|  |  |  |             'html' => 'test content', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |         $resp->assertRedirect($book->getUrl('/page/test-page')); | 
					
						
							| 
									
										
										
										
											2018-07-14 21:12:29 +08:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2016-03-06 02:09:21 +08:00
										 |  |  | } |