Chris@1494: # Redmine - project management software Chris@1494: # Copyright (C) 2006-2014 Jean-Philippe Lang Chris@1494: # Chris@1494: # This program is free software; you can redistribute it and/or Chris@1494: # modify it under the terms of the GNU General Public License Chris@1494: # as published by the Free Software Foundation; either version 2 Chris@1494: # of the License, or (at your option) any later version. Chris@1494: # Chris@1494: # This program is distributed in the hope that it will be useful, Chris@1494: # but WITHOUT ANY WARRANTY; without even the implied warranty of Chris@1494: # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the Chris@1494: # GNU General Public License for more details. Chris@1494: # Chris@1494: # You should have received a copy of the GNU General Public License Chris@1494: # along with this program; if not, write to the Free Software Chris@1494: # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. Chris@1494: Chris@1494: require File.expand_path('../../test_helper', __FILE__) Chris@1494: Chris@1494: class AuthSourceLdapTest < ActiveSupport::TestCase Chris@1494: include Redmine::I18n Chris@1494: fixtures :auth_sources Chris@1494: Chris@1494: def setup Chris@1494: end Chris@1494: Chris@1494: def test_create Chris@1494: a = AuthSourceLdap.new(:name => 'My LDAP', :host => 'ldap.example.net', :port => 389, :base_dn => 'dc=example,dc=net', :attr_login => 'sAMAccountName') Chris@1494: assert a.save Chris@1494: end Chris@1494: Chris@1494: def test_should_strip_ldap_attributes Chris@1494: a = AuthSourceLdap.new(:name => 'My LDAP', :host => 'ldap.example.net', :port => 389, :base_dn => 'dc=example,dc=net', :attr_login => 'sAMAccountName', Chris@1494: :attr_firstname => 'givenName ') Chris@1494: assert a.save Chris@1494: assert_equal 'givenName', a.reload.attr_firstname Chris@1494: end Chris@1494: Chris@1494: def test_replace_port_zero_to_389 Chris@1494: a = AuthSourceLdap.new( Chris@1494: :name => 'My LDAP', :host => 'ldap.example.net', :port => 0, Chris@1494: :base_dn => 'dc=example,dc=net', :attr_login => 'sAMAccountName', Chris@1494: :attr_firstname => 'givenName ') Chris@1494: assert a.save Chris@1494: assert_equal 389, a.port Chris@1494: end Chris@1494: Chris@1494: def test_filter_should_be_validated Chris@1494: set_language_if_valid 'en' Chris@1494: Chris@1494: a = AuthSourceLdap.new(:name => 'My LDAP', :host => 'ldap.example.net', :port => 389, :attr_login => 'sn') Chris@1494: a.filter = "(mail=*@redmine.org" Chris@1494: assert !a.valid? Chris@1494: assert_include "LDAP filter is invalid", a.errors.full_messages Chris@1494: Chris@1494: a.filter = "(mail=*@redmine.org)" Chris@1494: assert a.valid? Chris@1494: end Chris@1494: Chris@1494: if ldap_configured? Chris@1494: test '#authenticate with a valid LDAP user should return the user attributes' do Chris@1494: auth = AuthSourceLdap.find(1) Chris@1494: auth.update_attribute :onthefly_register, true Chris@1494: Chris@1494: attributes = auth.authenticate('example1','123456') Chris@1494: assert attributes.is_a?(Hash), "An hash was not returned" Chris@1494: assert_equal 'Example', attributes[:firstname] Chris@1494: assert_equal 'One', attributes[:lastname] Chris@1494: assert_equal 'example1@redmine.org', attributes[:mail] Chris@1494: assert_equal auth.id, attributes[:auth_source_id] Chris@1494: attributes.keys.each do |attribute| Chris@1494: assert User.new.respond_to?("#{attribute}="), "Unexpected :#{attribute} attribute returned" Chris@1494: end Chris@1494: end Chris@1494: Chris@1494: test '#authenticate with an invalid LDAP user should return nil' do Chris@1494: auth = AuthSourceLdap.find(1) Chris@1494: assert_equal nil, auth.authenticate('nouser','123456') Chris@1494: end Chris@1494: Chris@1494: test '#authenticate without a login should return nil' do Chris@1494: auth = AuthSourceLdap.find(1) Chris@1494: assert_equal nil, auth.authenticate('','123456') Chris@1494: end Chris@1494: Chris@1494: test '#authenticate without a password should return nil' do Chris@1494: auth = AuthSourceLdap.find(1) Chris@1494: assert_equal nil, auth.authenticate('edavis','') Chris@1494: end Chris@1494: Chris@1494: test '#authenticate without filter should return any user' do Chris@1494: auth = AuthSourceLdap.find(1) Chris@1494: assert auth.authenticate('example1','123456') Chris@1494: assert auth.authenticate('edavis', '123456') Chris@1494: end Chris@1494: Chris@1494: test '#authenticate with filter should return user who matches the filter only' do Chris@1494: auth = AuthSourceLdap.find(1) Chris@1494: auth.filter = "(mail=*@redmine.org)" Chris@1494: Chris@1494: assert auth.authenticate('example1','123456') Chris@1494: assert_nil auth.authenticate('edavis', '123456') Chris@1494: end Chris@1494: Chris@1494: def test_authenticate_should_timeout Chris@1494: auth_source = AuthSourceLdap.find(1) Chris@1494: auth_source.timeout = 1 Chris@1494: def auth_source.initialize_ldap_con(*args); sleep(5); end Chris@1494: Chris@1494: assert_raise AuthSourceTimeoutException do Chris@1494: auth_source.authenticate 'example1', '123456' Chris@1494: end Chris@1494: end Chris@1494: Chris@1494: def test_search_should_return_matching_entries Chris@1494: results = AuthSource.search("exa") Chris@1494: assert_equal 1, results.size Chris@1494: result = results.first Chris@1494: assert_kind_of Hash, result Chris@1494: assert_equal "example1", result[:login] Chris@1494: assert_equal "Example", result[:firstname] Chris@1494: assert_equal "One", result[:lastname] Chris@1494: assert_equal "example1@redmine.org", result[:mail] Chris@1494: assert_equal 1, result[:auth_source_id] Chris@1494: end Chris@1494: Chris@1494: def test_search_with_no_match_should_return_an_empty_array Chris@1494: results = AuthSource.search("wro") Chris@1494: assert_equal [], results Chris@1494: end Chris@1494: Chris@1494: def test_search_with_exception_should_return_an_empty_array Chris@1494: Net::LDAP.stubs(:new).raises(Net::LDAP::LdapError, 'Cannot connect') Chris@1494: Chris@1494: results = AuthSource.search("exa") Chris@1494: assert_equal [], results Chris@1494: end Chris@1494: else Chris@1494: puts '(Test LDAP server not configured)' Chris@1494: end Chris@1494: end