users_test.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592
  1. // Copyright 2020 The Gogs Authors. All rights reserved.
  2. // Use of this source code is governed by a MIT-style
  3. // license that can be found in the LICENSE file.
  4. package db
  5. import (
  6. "context"
  7. "fmt"
  8. "os"
  9. "strings"
  10. "testing"
  11. "time"
  12. "github.com/stretchr/testify/assert"
  13. "github.com/stretchr/testify/require"
  14. "gorm.io/gorm"
  15. "gogs.io/gogs/internal/auth"
  16. "gogs.io/gogs/internal/dbtest"
  17. "gogs.io/gogs/internal/dbutil"
  18. "gogs.io/gogs/internal/errutil"
  19. "gogs.io/gogs/internal/osutil"
  20. "gogs.io/gogs/internal/userutil"
  21. "gogs.io/gogs/public"
  22. )
  23. func TestUser_BeforeCreate(t *testing.T) {
  24. now := time.Now()
  25. db := &gorm.DB{
  26. Config: &gorm.Config{
  27. SkipDefaultTransaction: true,
  28. NowFunc: func() time.Time {
  29. return now
  30. },
  31. },
  32. }
  33. t.Run("CreatedUnix has been set", func(t *testing.T) {
  34. user := &User{
  35. CreatedUnix: 1,
  36. }
  37. _ = user.BeforeCreate(db)
  38. assert.Equal(t, int64(1), user.CreatedUnix)
  39. assert.Equal(t, int64(0), user.UpdatedUnix)
  40. })
  41. t.Run("CreatedUnix has not been set", func(t *testing.T) {
  42. user := &User{}
  43. _ = user.BeforeCreate(db)
  44. assert.Equal(t, db.NowFunc().Unix(), user.CreatedUnix)
  45. assert.Equal(t, db.NowFunc().Unix(), user.UpdatedUnix)
  46. })
  47. }
  48. func TestUser_AfterFind(t *testing.T) {
  49. now := time.Now()
  50. db := &gorm.DB{
  51. Config: &gorm.Config{
  52. SkipDefaultTransaction: true,
  53. NowFunc: func() time.Time {
  54. return now
  55. },
  56. },
  57. }
  58. user := &User{
  59. CreatedUnix: now.Unix(),
  60. UpdatedUnix: now.Unix(),
  61. }
  62. _ = user.AfterFind(db)
  63. assert.Equal(t, user.CreatedUnix, user.Created.Unix())
  64. assert.Equal(t, user.UpdatedUnix, user.Updated.Unix())
  65. }
  66. func TestUsers(t *testing.T) {
  67. if testing.Short() {
  68. t.Skip()
  69. }
  70. t.Parallel()
  71. tables := []interface{}{new(User), new(EmailAddress), new(Repository), new(Follow)}
  72. db := &users{
  73. DB: dbtest.NewDB(t, "users", tables...),
  74. }
  75. for _, tc := range []struct {
  76. name string
  77. test func(t *testing.T, db *users)
  78. }{
  79. {"Authenticate", usersAuthenticate},
  80. {"Count", usersCount},
  81. {"Create", usersCreate},
  82. {"DeleteCustomAvatar", usersDeleteCustomAvatar},
  83. {"GetByEmail", usersGetByEmail},
  84. {"GetByID", usersGetByID},
  85. {"GetByUsername", usersGetByUsername},
  86. {"HasForkedRepository", usersHasForkedRepository},
  87. {"IsUsernameUsed", usersIsUsernameUsed},
  88. {"List", usersList},
  89. {"ListFollowers", usersListFollowers},
  90. {"ListFollowings", usersListFollowings},
  91. {"UseCustomAvatar", usersUseCustomAvatar},
  92. } {
  93. t.Run(tc.name, func(t *testing.T) {
  94. t.Cleanup(func() {
  95. err := clearTables(t, db.DB, tables...)
  96. require.NoError(t, err)
  97. })
  98. tc.test(t, db)
  99. })
  100. if t.Failed() {
  101. break
  102. }
  103. }
  104. }
  105. func usersAuthenticate(t *testing.T, db *users) {
  106. ctx := context.Background()
  107. password := "pa$$word"
  108. alice, err := db.Create(ctx, "alice", "alice@example.com",
  109. CreateUserOptions{
  110. Password: password,
  111. },
  112. )
  113. require.NoError(t, err)
  114. t.Run("user not found", func(t *testing.T) {
  115. _, err := db.Authenticate(ctx, "bob", password, -1)
  116. wantErr := auth.ErrBadCredentials{Args: map[string]interface{}{"login": "bob"}}
  117. assert.Equal(t, wantErr, err)
  118. })
  119. t.Run("invalid password", func(t *testing.T) {
  120. _, err := db.Authenticate(ctx, alice.Name, "bad_password", -1)
  121. wantErr := auth.ErrBadCredentials{Args: map[string]interface{}{"login": alice.Name, "userID": alice.ID}}
  122. assert.Equal(t, wantErr, err)
  123. })
  124. t.Run("via email and password", func(t *testing.T) {
  125. user, err := db.Authenticate(ctx, alice.Email, password, -1)
  126. require.NoError(t, err)
  127. assert.Equal(t, alice.Name, user.Name)
  128. })
  129. t.Run("via username and password", func(t *testing.T) {
  130. user, err := db.Authenticate(ctx, alice.Name, password, -1)
  131. require.NoError(t, err)
  132. assert.Equal(t, alice.Name, user.Name)
  133. })
  134. t.Run("login source mismatch", func(t *testing.T) {
  135. _, err := db.Authenticate(ctx, alice.Email, password, 1)
  136. gotErr := fmt.Sprintf("%v", err)
  137. wantErr := ErrLoginSourceMismatch{args: map[string]interface{}{"actual": 0, "expect": 1}}.Error()
  138. assert.Equal(t, wantErr, gotErr)
  139. })
  140. t.Run("via login source", func(t *testing.T) {
  141. mockLoginSources := NewMockLoginSourcesStore()
  142. mockLoginSources.GetByIDFunc.SetDefaultHook(func(ctx context.Context, id int64) (*LoginSource, error) {
  143. mockProvider := NewMockProvider()
  144. mockProvider.AuthenticateFunc.SetDefaultReturn(&auth.ExternalAccount{}, nil)
  145. s := &LoginSource{
  146. IsActived: true,
  147. Provider: mockProvider,
  148. }
  149. return s, nil
  150. })
  151. setMockLoginSourcesStore(t, mockLoginSources)
  152. bob, err := db.Create(ctx, "bob", "bob@example.com",
  153. CreateUserOptions{
  154. Password: password,
  155. LoginSource: 1,
  156. },
  157. )
  158. require.NoError(t, err)
  159. user, err := db.Authenticate(ctx, bob.Email, password, 1)
  160. require.NoError(t, err)
  161. assert.Equal(t, bob.Name, user.Name)
  162. })
  163. t.Run("new user via login source", func(t *testing.T) {
  164. mockLoginSources := NewMockLoginSourcesStore()
  165. mockLoginSources.GetByIDFunc.SetDefaultHook(func(ctx context.Context, id int64) (*LoginSource, error) {
  166. mockProvider := NewMockProvider()
  167. mockProvider.AuthenticateFunc.SetDefaultReturn(
  168. &auth.ExternalAccount{
  169. Name: "cindy",
  170. Email: "cindy@example.com",
  171. },
  172. nil,
  173. )
  174. s := &LoginSource{
  175. IsActived: true,
  176. Provider: mockProvider,
  177. }
  178. return s, nil
  179. })
  180. setMockLoginSourcesStore(t, mockLoginSources)
  181. user, err := db.Authenticate(ctx, "cindy", password, 1)
  182. require.NoError(t, err)
  183. assert.Equal(t, "cindy", user.Name)
  184. user, err = db.GetByUsername(ctx, "cindy")
  185. require.NoError(t, err)
  186. assert.Equal(t, "cindy@example.com", user.Email)
  187. })
  188. }
  189. func usersCount(t *testing.T, db *users) {
  190. ctx := context.Background()
  191. // Has no user initially
  192. got := db.Count(ctx)
  193. assert.Equal(t, int64(0), got)
  194. _, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  195. require.NoError(t, err)
  196. got = db.Count(ctx)
  197. assert.Equal(t, int64(1), got)
  198. // Create an organization shouldn't count
  199. // TODO: Use Orgs.Create to replace SQL hack when the method is available.
  200. org1, err := db.Create(ctx, "org1", "org1@example.com", CreateUserOptions{})
  201. require.NoError(t, err)
  202. err = db.Exec(
  203. dbutil.Quote("UPDATE %s SET type = ? WHERE id = ?", "user"),
  204. UserTypeOrganization, org1.ID,
  205. ).Error
  206. require.NoError(t, err)
  207. got = db.Count(ctx)
  208. assert.Equal(t, int64(1), got)
  209. }
  210. func usersCreate(t *testing.T, db *users) {
  211. ctx := context.Background()
  212. alice, err := db.Create(
  213. ctx,
  214. "alice",
  215. "alice@example.com",
  216. CreateUserOptions{
  217. Activated: true,
  218. },
  219. )
  220. require.NoError(t, err)
  221. t.Run("name not allowed", func(t *testing.T) {
  222. _, err := db.Create(ctx, "-", "", CreateUserOptions{})
  223. wantErr := ErrNameNotAllowed{
  224. args: errutil.Args{
  225. "reason": "reserved",
  226. "name": "-",
  227. },
  228. }
  229. assert.Equal(t, wantErr, err)
  230. })
  231. t.Run("name already exists", func(t *testing.T) {
  232. _, err := db.Create(ctx, alice.Name, "", CreateUserOptions{})
  233. wantErr := ErrUserAlreadyExist{
  234. args: errutil.Args{
  235. "name": alice.Name,
  236. },
  237. }
  238. assert.Equal(t, wantErr, err)
  239. })
  240. t.Run("email already exists", func(t *testing.T) {
  241. _, err := db.Create(ctx, "bob", alice.Email, CreateUserOptions{})
  242. wantErr := ErrEmailAlreadyUsed{
  243. args: errutil.Args{
  244. "email": alice.Email,
  245. },
  246. }
  247. assert.Equal(t, wantErr, err)
  248. })
  249. user, err := db.GetByUsername(ctx, alice.Name)
  250. require.NoError(t, err)
  251. assert.Equal(t, db.NowFunc().Format(time.RFC3339), user.Created.UTC().Format(time.RFC3339))
  252. assert.Equal(t, db.NowFunc().Format(time.RFC3339), user.Updated.UTC().Format(time.RFC3339))
  253. }
  254. func usersDeleteCustomAvatar(t *testing.T, db *users) {
  255. ctx := context.Background()
  256. alice, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  257. require.NoError(t, err)
  258. avatar, err := public.Files.ReadFile("img/avatar_default.png")
  259. require.NoError(t, err)
  260. avatarPath := userutil.CustomAvatarPath(alice.ID)
  261. _ = os.Remove(avatarPath)
  262. defer func() { _ = os.Remove(avatarPath) }()
  263. err = db.UseCustomAvatar(ctx, alice.ID, avatar)
  264. require.NoError(t, err)
  265. // Make sure avatar is saved and the user flag is updated.
  266. got := osutil.IsFile(avatarPath)
  267. assert.True(t, got)
  268. alice, err = db.GetByID(ctx, alice.ID)
  269. require.NoError(t, err)
  270. assert.True(t, alice.UseCustomAvatar)
  271. // Delete avatar should remove the file and revert the user flag.
  272. err = db.DeleteCustomAvatar(ctx, alice.ID)
  273. require.NoError(t, err)
  274. got = osutil.IsFile(avatarPath)
  275. assert.False(t, got)
  276. alice, err = db.GetByID(ctx, alice.ID)
  277. require.NoError(t, err)
  278. assert.False(t, alice.UseCustomAvatar)
  279. }
  280. func usersGetByEmail(t *testing.T, db *users) {
  281. ctx := context.Background()
  282. t.Run("empty email", func(t *testing.T) {
  283. _, err := db.GetByEmail(ctx, "")
  284. wantErr := ErrUserNotExist{args: errutil.Args{"email": ""}}
  285. assert.Equal(t, wantErr, err)
  286. })
  287. t.Run("ignore organization", func(t *testing.T) {
  288. // TODO: Use Orgs.Create to replace SQL hack when the method is available.
  289. org, err := db.Create(ctx, "gogs", "gogs@exmaple.com", CreateUserOptions{})
  290. require.NoError(t, err)
  291. err = db.Model(&User{}).Where("id", org.ID).UpdateColumn("type", UserTypeOrganization).Error
  292. require.NoError(t, err)
  293. _, err = db.GetByEmail(ctx, org.Email)
  294. wantErr := ErrUserNotExist{args: errutil.Args{"email": org.Email}}
  295. assert.Equal(t, wantErr, err)
  296. })
  297. t.Run("by primary email", func(t *testing.T) {
  298. alice, err := db.Create(ctx, "alice", "alice@exmaple.com", CreateUserOptions{})
  299. require.NoError(t, err)
  300. _, err = db.GetByEmail(ctx, alice.Email)
  301. wantErr := ErrUserNotExist{args: errutil.Args{"email": alice.Email}}
  302. assert.Equal(t, wantErr, err)
  303. // Mark user as activated
  304. // TODO: Use UserEmails.Verify to replace SQL hack when the method is available.
  305. err = db.Model(&User{}).Where("id", alice.ID).UpdateColumn("is_active", true).Error
  306. require.NoError(t, err)
  307. user, err := db.GetByEmail(ctx, alice.Email)
  308. require.NoError(t, err)
  309. assert.Equal(t, alice.Name, user.Name)
  310. })
  311. t.Run("by secondary email", func(t *testing.T) {
  312. bob, err := db.Create(ctx, "bob", "bob@example.com", CreateUserOptions{})
  313. require.NoError(t, err)
  314. // TODO: Use UserEmails.Create to replace SQL hack when the method is available.
  315. email2 := "bob2@exmaple.com"
  316. err = db.Exec(`INSERT INTO email_address (uid, email) VALUES (?, ?)`, bob.ID, email2).Error
  317. require.NoError(t, err)
  318. _, err = db.GetByEmail(ctx, email2)
  319. wantErr := ErrUserNotExist{args: errutil.Args{"email": email2}}
  320. assert.Equal(t, wantErr, err)
  321. // TODO: Use UserEmails.Verify to replace SQL hack when the method is available.
  322. err = db.Exec(`UPDATE email_address SET is_activated = ? WHERE email = ?`, true, email2).Error
  323. require.NoError(t, err)
  324. user, err := db.GetByEmail(ctx, email2)
  325. require.NoError(t, err)
  326. assert.Equal(t, bob.Name, user.Name)
  327. })
  328. }
  329. func usersGetByID(t *testing.T, db *users) {
  330. ctx := context.Background()
  331. alice, err := db.Create(ctx, "alice", "alice@exmaple.com", CreateUserOptions{})
  332. require.NoError(t, err)
  333. user, err := db.GetByID(ctx, alice.ID)
  334. require.NoError(t, err)
  335. assert.Equal(t, alice.Name, user.Name)
  336. _, err = db.GetByID(ctx, 404)
  337. wantErr := ErrUserNotExist{args: errutil.Args{"userID": int64(404)}}
  338. assert.Equal(t, wantErr, err)
  339. }
  340. func usersGetByUsername(t *testing.T, db *users) {
  341. ctx := context.Background()
  342. alice, err := db.Create(ctx, "alice", "alice@exmaple.com", CreateUserOptions{})
  343. require.NoError(t, err)
  344. user, err := db.GetByUsername(ctx, alice.Name)
  345. require.NoError(t, err)
  346. assert.Equal(t, alice.Name, user.Name)
  347. _, err = db.GetByUsername(ctx, "bad_username")
  348. wantErr := ErrUserNotExist{args: errutil.Args{"name": "bad_username"}}
  349. assert.Equal(t, wantErr, err)
  350. }
  351. func usersHasForkedRepository(t *testing.T, db *users) {
  352. ctx := context.Background()
  353. has := db.HasForkedRepository(ctx, 1, 1)
  354. assert.False(t, has)
  355. _, err := NewReposStore(db.DB).Create(
  356. ctx,
  357. 1,
  358. CreateRepoOptions{
  359. Name: "repo1",
  360. ForkID: 1,
  361. },
  362. )
  363. require.NoError(t, err)
  364. has = db.HasForkedRepository(ctx, 1, 1)
  365. assert.True(t, has)
  366. }
  367. func usersIsUsernameUsed(t *testing.T, db *users) {
  368. ctx := context.Background()
  369. alice, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  370. require.NoError(t, err)
  371. got := db.IsUsernameUsed(ctx, alice.Name)
  372. assert.True(t, got)
  373. got = db.IsUsernameUsed(ctx, "bob")
  374. assert.False(t, got)
  375. }
  376. func usersList(t *testing.T, db *users) {
  377. ctx := context.Background()
  378. alice, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  379. require.NoError(t, err)
  380. bob, err := db.Create(ctx, "bob", "bob@example.com", CreateUserOptions{})
  381. require.NoError(t, err)
  382. // Create an organization shouldn't count
  383. // TODO: Use Orgs.Create to replace SQL hack when the method is available.
  384. org1, err := db.Create(ctx, "org1", "org1@example.com", CreateUserOptions{})
  385. require.NoError(t, err)
  386. err = db.Exec(
  387. dbutil.Quote("UPDATE %s SET type = ? WHERE id = ?", "user"),
  388. UserTypeOrganization, org1.ID,
  389. ).Error
  390. require.NoError(t, err)
  391. got, err := db.List(ctx, 1, 1)
  392. require.NoError(t, err)
  393. require.Len(t, got, 1)
  394. assert.Equal(t, alice.ID, got[0].ID)
  395. got, err = db.List(ctx, 2, 1)
  396. require.NoError(t, err)
  397. require.Len(t, got, 1)
  398. assert.Equal(t, bob.ID, got[0].ID)
  399. got, err = db.List(ctx, 1, 3)
  400. require.NoError(t, err)
  401. require.Len(t, got, 2)
  402. assert.Equal(t, alice.ID, got[0].ID)
  403. assert.Equal(t, bob.ID, got[1].ID)
  404. }
  405. func usersListFollowers(t *testing.T, db *users) {
  406. ctx := context.Background()
  407. john, err := db.Create(ctx, "john", "john@example.com", CreateUserOptions{})
  408. require.NoError(t, err)
  409. got, err := db.ListFollowers(ctx, john.ID, 1, 1)
  410. require.NoError(t, err)
  411. assert.Empty(t, got)
  412. alice, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  413. require.NoError(t, err)
  414. bob, err := db.Create(ctx, "bob", "bob@example.com", CreateUserOptions{})
  415. require.NoError(t, err)
  416. followsStore := NewFollowsStore(db.DB)
  417. err = followsStore.Follow(ctx, alice.ID, john.ID)
  418. require.NoError(t, err)
  419. err = followsStore.Follow(ctx, bob.ID, john.ID)
  420. require.NoError(t, err)
  421. // First page only has bob
  422. got, err = db.ListFollowers(ctx, john.ID, 1, 1)
  423. require.NoError(t, err)
  424. require.Len(t, got, 1)
  425. assert.Equal(t, bob.ID, got[0].ID)
  426. // Second page only has alice
  427. got, err = db.ListFollowers(ctx, john.ID, 2, 1)
  428. require.NoError(t, err)
  429. require.Len(t, got, 1)
  430. assert.Equal(t, alice.ID, got[0].ID)
  431. }
  432. func usersListFollowings(t *testing.T, db *users) {
  433. ctx := context.Background()
  434. john, err := db.Create(ctx, "john", "john@example.com", CreateUserOptions{})
  435. require.NoError(t, err)
  436. got, err := db.ListFollowers(ctx, john.ID, 1, 1)
  437. require.NoError(t, err)
  438. assert.Empty(t, got)
  439. alice, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  440. require.NoError(t, err)
  441. bob, err := db.Create(ctx, "bob", "bob@example.com", CreateUserOptions{})
  442. require.NoError(t, err)
  443. followsStore := NewFollowsStore(db.DB)
  444. err = followsStore.Follow(ctx, john.ID, alice.ID)
  445. require.NoError(t, err)
  446. err = followsStore.Follow(ctx, john.ID, bob.ID)
  447. require.NoError(t, err)
  448. // First page only has bob
  449. got, err = db.ListFollowings(ctx, john.ID, 1, 1)
  450. require.NoError(t, err)
  451. require.Len(t, got, 1)
  452. assert.Equal(t, bob.ID, got[0].ID)
  453. // Second page only has alice
  454. got, err = db.ListFollowings(ctx, john.ID, 2, 1)
  455. require.NoError(t, err)
  456. require.Len(t, got, 1)
  457. assert.Equal(t, alice.ID, got[0].ID)
  458. }
  459. func usersUseCustomAvatar(t *testing.T, db *users) {
  460. ctx := context.Background()
  461. alice, err := db.Create(ctx, "alice", "alice@example.com", CreateUserOptions{})
  462. require.NoError(t, err)
  463. avatar, err := public.Files.ReadFile("img/avatar_default.png")
  464. require.NoError(t, err)
  465. avatarPath := userutil.CustomAvatarPath(alice.ID)
  466. _ = os.Remove(avatarPath)
  467. defer func() { _ = os.Remove(avatarPath) }()
  468. err = db.UseCustomAvatar(ctx, alice.ID, avatar)
  469. require.NoError(t, err)
  470. // Make sure avatar is saved and the user flag is updated.
  471. got := osutil.IsFile(avatarPath)
  472. assert.True(t, got)
  473. alice, err = db.GetByID(ctx, alice.ID)
  474. require.NoError(t, err)
  475. assert.True(t, alice.UseCustomAvatar)
  476. }
  477. func TestIsUsernameAllowed(t *testing.T) {
  478. for name := range reservedUsernames {
  479. t.Run(name, func(t *testing.T) {
  480. assert.True(t, IsErrNameNotAllowed(isUsernameAllowed(name)))
  481. })
  482. }
  483. for _, pattern := range reservedUsernamePatterns {
  484. t.Run(pattern, func(t *testing.T) {
  485. username := strings.ReplaceAll(pattern, "*", "alice")
  486. assert.True(t, IsErrNameNotAllowed(isUsernameAllowed(username)))
  487. })
  488. }
  489. }