| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | <?php | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-10 22:54:58 +08:00
										 |  |  | namespace Tests\Actions; | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-18 19:43:05 +08:00
										 |  |  | use function app; | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | use BookStack\Actions\Activity; | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  | use BookStack\Actions\ActivityLogger; | 
					
						
							| 
									
										
										
										
											2020-11-08 08:03:19 +08:00
										 |  |  | use BookStack\Actions\ActivityType; | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | use BookStack\Auth\UserRepo; | 
					
						
							| 
									
										
										
										
											2021-03-21 23:04:32 +08:00
										 |  |  | use BookStack\Entities\Models\Chapter; | 
					
						
							| 
									
										
										
										
											2020-11-22 08:17:45 +08:00
										 |  |  | use BookStack\Entities\Models\Page; | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | use BookStack\Entities\Repos\PageRepo; | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | use BookStack\Entities\Tools\TrashCan; | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | use Carbon\Carbon; | 
					
						
							| 
									
										
										
										
											2021-12-10 22:54:58 +08:00
										 |  |  | use function config; | 
					
						
							| 
									
										
										
										
											2021-12-18 19:43:05 +08:00
										 |  |  | use Tests\TestCase; | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | class AuditLogTest extends TestCase | 
					
						
							|  |  |  | { | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |     /** @var ActivityLogger */ | 
					
						
							| 
									
										
										
										
											2020-11-08 08:03:19 +08:00
										 |  |  |     protected $activityService; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-10-31 04:29:59 +08:00
										 |  |  |     protected function setUp(): void | 
					
						
							| 
									
										
										
										
											2020-11-08 08:03:19 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         parent::setUp(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService = app(ActivityLogger::class); | 
					
						
							| 
									
										
										
										
											2020-11-08 08:03:19 +08:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |     public function test_only_accessible_with_right_permissions() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $viewer = $this->getViewer(); | 
					
						
							|  |  |  |         $this->actingAs($viewer); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('/settings/audit'); | 
					
						
							|  |  |  |         $this->assertPermissionError($resp); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->giveUserPermissions($viewer, ['settings-manage']); | 
					
						
							|  |  |  |         $resp = $this->get('/settings/audit'); | 
					
						
							|  |  |  |         $this->assertPermissionError($resp); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->giveUserPermissions($viewer, ['users-manage']); | 
					
						
							|  |  |  |         $resp = $this->get('/settings/audit'); | 
					
						
							|  |  |  |         $resp->assertStatus(200); | 
					
						
							|  |  |  |         $resp->assertSeeText('Audit Log'); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_shows_activity() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $admin = $this->getAdmin(); | 
					
						
							|  |  |  |         $this->actingAs($admin); | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::PAGE_CREATE, $page); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  |         $activity = Activity::query()->orderBy('id', 'desc')->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit'); | 
					
						
							|  |  |  |         $resp->assertSeeText($page->name); | 
					
						
							|  |  |  |         $resp->assertSeeText('page_create'); | 
					
						
							|  |  |  |         $resp->assertSeeText($activity->created_at->toDateTimeString()); | 
					
						
							| 
									
										
										
										
											2020-11-06 20:54:39 +08:00
										 |  |  |         $resp->assertElementContains('.table-user-item', $admin->name); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_shows_name_for_deleted_items() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  |         $this->actingAs($this->getAdmin()); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  |         $page = Page::query()->first(); | 
					
						
							|  |  |  |         $pageName = $page->name; | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::PAGE_CREATE, $page); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         app(PageRepo::class)->destroy($page); | 
					
						
							| 
									
										
										
										
											2020-11-06 20:54:39 +08:00
										 |  |  |         app(TrashCan::class)->empty(); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit'); | 
					
						
							|  |  |  |         $resp->assertSeeText('Deleted Item'); | 
					
						
							|  |  |  |         $resp->assertSeeText('Name: ' . $pageName); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_shows_activity_for_deleted_users() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $viewer = $this->getViewer(); | 
					
						
							|  |  |  |         $this->actingAs($viewer); | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::PAGE_CREATE, $page); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($this->getAdmin()); | 
					
						
							|  |  |  |         app(UserRepo::class)->destroy($viewer); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit'); | 
					
						
							|  |  |  |         $resp->assertSeeText("[ID: {$viewer->id}] Deleted User"); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_filters_by_key() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $this->actingAs($this->getAdmin()); | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::PAGE_CREATE, $page); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit'); | 
					
						
							|  |  |  |         $resp->assertSeeText($page->name); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit?event=page_delete'); | 
					
						
							|  |  |  |         $resp->assertDontSeeText($page->name); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     public function test_date_filters() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $this->actingAs($this->getAdmin()); | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::PAGE_CREATE, $page); | 
					
						
							| 
									
										
										
										
											2020-09-19 19:06:45 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $yesterday = (Carbon::now()->subDay()->format('Y-m-d')); | 
					
						
							|  |  |  |         $tomorrow = (Carbon::now()->addDay()->format('Y-m-d')); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit?date_from=' . $yesterday); | 
					
						
							|  |  |  |         $resp->assertSeeText($page->name); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit?date_from=' . $tomorrow); | 
					
						
							|  |  |  |         $resp->assertDontSeeText($page->name); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit?date_to=' . $tomorrow); | 
					
						
							|  |  |  |         $resp->assertSeeText($page->name); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->get('settings/audit?date_to=' . $yesterday); | 
					
						
							|  |  |  |         $resp->assertDontSeeText($page->name); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-21 23:04:32 +08:00
										 |  |  |     public function test_user_filter() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $admin = $this->getAdmin(); | 
					
						
							|  |  |  |         $editor = $this->getEditor(); | 
					
						
							|  |  |  |         $this->actingAs($admin); | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::PAGE_CREATE, $page); | 
					
						
							| 
									
										
										
										
											2021-03-21 23:04:32 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($editor); | 
					
						
							|  |  |  |         $chapter = Chapter::query()->first(); | 
					
						
							| 
									
										
										
										
											2021-12-12 01:29:33 +08:00
										 |  |  |         $this->activityService->add(ActivityType::CHAPTER_UPDATE, $chapter); | 
					
						
							| 
									
										
										
										
											2021-03-21 23:04:32 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->actingAs($admin)->get('settings/audit?user=' . $admin->id); | 
					
						
							|  |  |  |         $resp->assertSeeText($page->name); | 
					
						
							|  |  |  |         $resp->assertDontSeeText($chapter->name); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->actingAs($admin)->get('settings/audit?user=' . $editor->id); | 
					
						
							|  |  |  |         $resp->assertSeeText($chapter->name); | 
					
						
							|  |  |  |         $resp->assertDontSeeText($page->name); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2021-09-27 00:18:12 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |     public function test_ip_address_logged_and_visible() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         config()->set('app.proxies', '*'); | 
					
						
							|  |  |  |         $editor = $this->getEditor(); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($editor)->put($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'Updated page', | 
					
						
							|  |  |  |             'html' => '<p>Updated content</p>', | 
					
						
							|  |  |  |         ], [ | 
					
						
							| 
									
										
										
										
											2021-09-30 06:53:11 +08:00
										 |  |  |             'X-Forwarded-For' => '192.123.45.1', | 
					
						
							| 
									
										
										
										
											2021-09-27 00:18:12 +08:00
										 |  |  |         ])->assertRedirect($page->refresh()->getUrl()); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->assertDatabaseHas('activities', [ | 
					
						
							| 
									
										
										
										
											2021-09-30 06:53:11 +08:00
										 |  |  |             'type'      => ActivityType::PAGE_UPDATE, | 
					
						
							|  |  |  |             'ip'        => '192.123.45.1', | 
					
						
							|  |  |  |             'user_id'   => $editor->id, | 
					
						
							| 
									
										
										
										
											2021-09-27 00:18:12 +08:00
										 |  |  |             'entity_id' => $page->id, | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $resp = $this->asAdmin()->get('/settings/audit'); | 
					
						
							|  |  |  |         $resp->assertSee('192.123.45.1'); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-10 15:03:17 +08:00
										 |  |  |     public function test_ip_address_is_searchable() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         config()->set('app.proxies', '*'); | 
					
						
							|  |  |  |         $editor = $this->getEditor(); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($editor)->put($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'Updated page', | 
					
						
							|  |  |  |             'html' => '<p>Updated content</p>', | 
					
						
							|  |  |  |         ], [ | 
					
						
							|  |  |  |             'X-Forwarded-For' => '192.123.45.1', | 
					
						
							|  |  |  |         ])->assertRedirect($page->refresh()->getUrl()); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-18 19:05:41 +08:00
										 |  |  |         $this->actingAs($editor)->put($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'Updated page', | 
					
						
							|  |  |  |             'html' => '<p>Updated content</p>', | 
					
						
							|  |  |  |         ], [ | 
					
						
							|  |  |  |             'X-Forwarded-For' => '192.122.45.1', | 
					
						
							|  |  |  |         ])->assertRedirect($page->refresh()->getUrl()); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-10 15:03:17 +08:00
										 |  |  |         $resp = $this->asAdmin()->get('/settings/audit?&ip=192.123'); | 
					
						
							|  |  |  |         $resp->assertSee('192.123.45.1'); | 
					
						
							| 
									
										
										
										
											2021-12-18 19:05:41 +08:00
										 |  |  |         $resp->assertDontSee('192.122.45.1'); | 
					
						
							| 
									
										
										
										
											2021-12-10 15:03:17 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-27 00:18:12 +08:00
										 |  |  |     public function test_ip_address_not_logged_in_demo_mode() | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         config()->set('app.proxies', '*'); | 
					
						
							|  |  |  |         config()->set('app.env', 'demo'); | 
					
						
							|  |  |  |         $editor = $this->getEditor(); | 
					
						
							|  |  |  |         /** @var Page $page */ | 
					
						
							|  |  |  |         $page = Page::query()->first(); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->actingAs($editor)->put($page->getUrl(), [ | 
					
						
							|  |  |  |             'name' => 'Updated page', | 
					
						
							|  |  |  |             'html' => '<p>Updated content</p>', | 
					
						
							|  |  |  |         ], [ | 
					
						
							|  |  |  |             'X-Forwarded-For' => '192.123.45.1', | 
					
						
							| 
									
										
										
										
											2021-09-30 06:53:11 +08:00
										 |  |  |             'REMOTE_ADDR'     => '192.123.45.2', | 
					
						
							| 
									
										
										
										
											2021-09-27 00:18:12 +08:00
										 |  |  |         ])->assertRedirect($page->refresh()->getUrl()); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         $this->assertDatabaseHas('activities', [ | 
					
						
							| 
									
										
										
										
											2021-09-30 06:53:11 +08:00
										 |  |  |             'type'      => ActivityType::PAGE_UPDATE, | 
					
						
							|  |  |  |             'ip'        => '127.0.0.1', | 
					
						
							|  |  |  |             'user_id'   => $editor->id, | 
					
						
							| 
									
										
										
										
											2021-09-27 00:18:12 +08:00
										 |  |  |             'entity_id' => $page->id, | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | } |