page.test.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504
  1. const mongoose = require('mongoose');
  2. const { getInstance } = require('../setup-crowi');
  3. let testUser0;
  4. let testUser1;
  5. let testUser2;
  6. let testGroup0;
  7. let parentPage;
  8. describe('Page', () => {
  9. // eslint-disable-next-line no-unused-vars
  10. let crowi;
  11. let Page;
  12. let PageQueryBuilder;
  13. let User;
  14. let UserGroup;
  15. let UserGroupRelation;
  16. beforeAll(async(done) => {
  17. crowi = await getInstance();
  18. User = mongoose.model('User');
  19. UserGroup = mongoose.model('UserGroup');
  20. UserGroupRelation = mongoose.model('UserGroupRelation');
  21. Page = mongoose.model('Page');
  22. PageQueryBuilder = Page.PageQueryBuilder;
  23. await User.insertMany([
  24. { name: 'Anon 0', username: 'anonymous0', email: 'anonymous0@example.com' },
  25. { name: 'Anon 1', username: 'anonymous1', email: 'anonymous1@example.com' },
  26. { name: 'Anon 2', username: 'anonymous2', email: 'anonymous2@example.com' },
  27. ]);
  28. await UserGroup.insertMany([
  29. { name: 'TestGroup0' },
  30. { name: 'TestGroup1' },
  31. ]);
  32. testUser0 = await User.findOne({ username: 'anonymous0' });
  33. testUser1 = await User.findOne({ username: 'anonymous1' });
  34. testUser2 = await User.findOne({ username: 'anonymous2' });
  35. testGroup0 = await UserGroup.findOne({ name: 'TestGroup0' });
  36. await UserGroupRelation.insertMany([
  37. {
  38. relatedGroup: testGroup0,
  39. relatedUser: testUser0,
  40. },
  41. {
  42. relatedGroup: testGroup0,
  43. relatedUser: testUser1,
  44. },
  45. ]);
  46. await Page.insertMany([
  47. {
  48. path: '/user/anonymous0/memo',
  49. grant: Page.GRANT_RESTRICTED,
  50. grantedUsers: [testUser0],
  51. creator: testUser0,
  52. },
  53. {
  54. path: '/grant',
  55. grant: Page.GRANT_PUBLIC,
  56. grantedUsers: [testUser0],
  57. creator: testUser0,
  58. },
  59. {
  60. path: '/grant/public',
  61. grant: Page.GRANT_PUBLIC,
  62. grantedUsers: [testUser0],
  63. creator: testUser0,
  64. },
  65. {
  66. path: '/grant/restricted',
  67. grant: Page.GRANT_RESTRICTED,
  68. grantedUsers: [testUser0],
  69. creator: testUser0,
  70. },
  71. {
  72. path: '/grant/specified',
  73. grant: Page.GRANT_SPECIFIED,
  74. grantedUsers: [testUser0],
  75. creator: testUser0,
  76. },
  77. {
  78. path: '/grant/owner',
  79. grant: Page.GRANT_OWNER,
  80. grantedUsers: [testUser0],
  81. creator: testUser0,
  82. },
  83. {
  84. path: '/page/child/without/parents',
  85. grant: Page.GRANT_PUBLIC,
  86. creator: testUser0,
  87. },
  88. {
  89. path: '/grant/groupacl',
  90. grant: Page.GRANT_USER_GROUP,
  91. grantedUsers: [],
  92. grantedGroup: testGroup0,
  93. creator: testUser1,
  94. },
  95. {
  96. path: '/page1',
  97. grant: Page.GRANT_PUBLIC,
  98. creator: testUser0,
  99. },
  100. {
  101. path: '/page1/child1',
  102. grant: Page.GRANT_PUBLIC,
  103. creator: testUser0,
  104. },
  105. {
  106. path: '/page2',
  107. grant: Page.GRANT_PUBLIC,
  108. creator: testUser0,
  109. },
  110. ]);
  111. parentPage = await Page.findOne({ path: '/grant' });
  112. done();
  113. });
  114. describe('.isPublic', () => {
  115. describe('with a public page', () => {
  116. test('should return true', async() => {
  117. const page = await Page.findOne({ path: '/grant/public' });
  118. expect(page.isPublic()).toEqual(true);
  119. });
  120. });
  121. ['restricted', 'specified', 'owner'].forEach((grant) => {
  122. describe(`with a ${grant} page`, () => {
  123. test('should return false', async() => {
  124. const page = await Page.findOne({ path: `/grant/${grant}` });
  125. expect(page.isPublic()).toEqual(false);
  126. });
  127. });
  128. });
  129. });
  130. describe('.getDeletedPageName', () => {
  131. test('should return trash page name', () => {
  132. expect(Page.getDeletedPageName('/hoge')).toEqual('/trash/hoge');
  133. expect(Page.getDeletedPageName('hoge')).toEqual('/trash/hoge');
  134. });
  135. });
  136. describe('.getRevertDeletedPageName', () => {
  137. test('should return reverted trash page name', () => {
  138. expect(Page.getRevertDeletedPageName('/hoge')).toEqual('/hoge');
  139. expect(Page.getRevertDeletedPageName('/trash/hoge')).toEqual('/hoge');
  140. expect(Page.getRevertDeletedPageName('/trash/hoge/trash')).toEqual('/hoge/trash');
  141. });
  142. });
  143. describe('.isDeletableName', () => {
  144. test('should decide deletable or not', () => {
  145. expect(Page.isDeletableName('/hoge')).toBeTruthy();
  146. expect(Page.isDeletableName('/user/xxx')).toBeFalsy();
  147. expect(Page.isDeletableName('/user/xxx123')).toBeFalsy();
  148. expect(Page.isDeletableName('/user/xxx/')).toBeTruthy();
  149. expect(Page.isDeletableName('/user/xxx/hoge')).toBeTruthy();
  150. });
  151. });
  152. describe('.isCreatableName', () => {
  153. test('should decide creatable or not', () => {
  154. expect(Page.isCreatableName('/hoge')).toBeTruthy();
  155. // edge cases
  156. expect(Page.isCreatableName('/me')).toBeFalsy();
  157. expect(Page.isCreatableName('/me/')).toBeFalsy();
  158. expect(Page.isCreatableName('/me/x')).toBeFalsy();
  159. expect(Page.isCreatableName('/meeting')).toBeTruthy();
  160. expect(Page.isCreatableName('/meeting/x')).toBeTruthy();
  161. // end with "edit"
  162. expect(Page.isCreatableName('/meeting/edit')).toBeFalsy();
  163. // under score
  164. expect(Page.isCreatableName('/_')).toBeTruthy();
  165. expect(Page.isCreatableName('/_template')).toBeTruthy();
  166. expect(Page.isCreatableName('/__template')).toBeTruthy();
  167. expect(Page.isCreatableName('/_r/x')).toBeFalsy();
  168. expect(Page.isCreatableName('/_api')).toBeFalsy();
  169. expect(Page.isCreatableName('/_apix')).toBeFalsy();
  170. expect(Page.isCreatableName('/_api/x')).toBeFalsy();
  171. expect(Page.isCreatableName('/hoge/xx.md')).toBeFalsy();
  172. // start with https?
  173. expect(Page.isCreatableName('/http://demo.growi.org/hoge')).toBeFalsy();
  174. expect(Page.isCreatableName('/https://demo.growi.org/hoge')).toBeFalsy();
  175. expect(Page.isCreatableName('http://demo.growi.org/hoge')).toBeFalsy();
  176. expect(Page.isCreatableName('https://demo.growi.org/hoge')).toBeFalsy();
  177. expect(Page.isCreatableName('/ the / path / with / space')).toBeFalsy();
  178. const forbidden = ['installer', 'register', 'login', 'logout',
  179. 'admin', 'files', 'trash', 'paste', 'comments'];
  180. for (let i = 0; i < forbidden.length; i++) {
  181. const pn = forbidden[i];
  182. expect(Page.isCreatableName(`/${pn}`)).toBeFalsy();
  183. expect(Page.isCreatableName(`/${pn}/`)).toBeFalsy();
  184. expect(Page.isCreatableName(`/${pn}/abc`)).toBeFalsy();
  185. }
  186. });
  187. });
  188. describe('.isAccessiblePageByViewer', () => {
  189. describe('with a granted page', () => {
  190. test('should return true with granted user', async() => {
  191. const user = await User.findOne({ email: 'anonymous0@example.com' });
  192. const page = await Page.findOne({ path: '/user/anonymous0/memo' });
  193. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  194. expect(bool).toEqual(true);
  195. });
  196. test('should return false without user', async() => {
  197. const user = null;
  198. const page = await Page.findOne({ path: '/user/anonymous0/memo' });
  199. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  200. expect(bool).toEqual(true);
  201. });
  202. });
  203. describe('with a public page', () => {
  204. test('should return true with user', async() => {
  205. const user = await User.findOne({ email: 'anonymous1@example.com' });
  206. const page = await Page.findOne({ path: '/grant/public' });
  207. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  208. expect(bool).toEqual(true);
  209. });
  210. test('should return true with out', async() => {
  211. const user = null;
  212. const page = await Page.findOne({ path: '/grant/public' });
  213. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  214. expect(bool).toEqual(true);
  215. });
  216. });
  217. describe('with a restricted page', () => {
  218. test('should return false with user who has no grant', async() => {
  219. const user = await User.findOne({ email: 'anonymous1@example.com' });
  220. const page = await Page.findOne({ path: '/grant/owner' });
  221. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  222. expect(bool).toEqual(false);
  223. });
  224. test('should return false without user', async() => {
  225. const user = null;
  226. const page = await Page.findOne({ path: '/grant/owner' });
  227. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  228. expect(bool).toEqual(false);
  229. });
  230. });
  231. });
  232. describe('.findPage', () => {
  233. describe('findByIdAndViewer', () => {
  234. test('should find page (public)', async() => {
  235. const expectedPage = await Page.findOne({ path: '/grant/public' });
  236. const page = await Page.findByIdAndViewer(expectedPage.id, testUser0);
  237. expect(page).not.toBeNull();
  238. expect(page.path).toEqual(expectedPage.path);
  239. });
  240. test('should find page (anyone knows link)', async() => {
  241. const expectedPage = await Page.findOne({ path: '/grant/restricted' });
  242. const page = await Page.findByIdAndViewer(expectedPage.id, testUser1);
  243. expect(page).not.toBeNull();
  244. expect(page.path).toEqual(expectedPage.path);
  245. });
  246. test('should find page (only me)', async() => {
  247. const expectedPage = await Page.findOne({ path: '/grant/owner' });
  248. const page = await Page.findByIdAndViewer(expectedPage.id, testUser0);
  249. expect(page).not.toBeNull();
  250. expect(page.path).toEqual(expectedPage.path);
  251. });
  252. test('should not be found by grant (only me)', async() => {
  253. const expectedPage = await Page.findOne({ path: '/grant/owner' });
  254. const page = await Page.findByIdAndViewer(expectedPage.id, testUser1);
  255. expect(page).toBeNull();
  256. });
  257. });
  258. describe('findByIdAndViewer granted userGroup', () => {
  259. test('should find page', async() => {
  260. const expectedPage = await Page.findOne({ path: '/grant/groupacl' });
  261. const page = await Page.findByIdAndViewer(expectedPage.id, testUser0);
  262. expect(page).not.toBeNull();
  263. expect(page.path).toEqual(expectedPage.path);
  264. });
  265. test('should not be found by grant', async() => {
  266. const expectedPage = await Page.findOne({ path: '/grant/groupacl' });
  267. const page = await Page.findByIdAndViewer(expectedPage.id, testUser2);
  268. expect(page).toBeNull();
  269. });
  270. });
  271. });
  272. describe('PageQueryBuilder.addConditionToListWithDescendants', () => {
  273. test('can retrieve descendants of /page', async() => {
  274. const builder = new PageQueryBuilder(Page.find());
  275. builder.addConditionToListWithDescendants('/page');
  276. const result = await builder.query.exec();
  277. // assert totalCount
  278. expect(result.length).toEqual(1);
  279. // assert paths
  280. const pagePaths = result.map((page) => { return page.path });
  281. expect(pagePaths).toContainEqual('/page/child/without/parents');
  282. });
  283. test('can retrieve descendants of /page1', async() => {
  284. const builder = new PageQueryBuilder(Page.find());
  285. builder.addConditionToListWithDescendants('/page1/');
  286. const result = await builder.query.exec();
  287. // assert totalCount
  288. expect(result.length).toEqual(2);
  289. // assert paths
  290. const pagePaths = result.map((page) => { return page.path });
  291. expect(pagePaths).toContainEqual('/page1');
  292. expect(pagePaths).toContainEqual('/page1/child1');
  293. });
  294. });
  295. describe('PageQueryBuilder.addConditionToListOnlyDescendants', () => {
  296. test('can retrieve only descendants of /page', async() => {
  297. const builder = new PageQueryBuilder(Page.find());
  298. builder.addConditionToListOnlyDescendants('/page');
  299. const result = await builder.query.exec();
  300. // assert totalCount
  301. expect(result.length).toEqual(1);
  302. // assert paths
  303. const pagePaths = result.map((page) => { return page.path });
  304. expect(pagePaths).toContainEqual('/page/child/without/parents');
  305. });
  306. test('can retrieve only descendants of /page1', async() => {
  307. const builder = new PageQueryBuilder(Page.find());
  308. builder.addConditionToListOnlyDescendants('/page1');
  309. const result = await builder.query.exec();
  310. // assert totalCount
  311. expect(result.length).toEqual(1);
  312. // assert paths
  313. const pagePaths = result.map((page) => { return page.path });
  314. expect(pagePaths).toContainEqual('/page1/child1');
  315. });
  316. });
  317. describe('PageQueryBuilder.addConditionToListByStartWith', () => {
  318. test('can retrieve pages which starts with /page', async() => {
  319. const builder = new PageQueryBuilder(Page.find());
  320. builder.addConditionToListByStartWith('/page');
  321. const result = await builder.query.exec();
  322. // assert totalCount
  323. expect(result.length).toEqual(4);
  324. // assert paths
  325. const pagePaths = result.map((page) => { return page.path });
  326. expect(pagePaths).toContainEqual('/page/child/without/parents');
  327. expect(pagePaths).toContainEqual('/page1');
  328. expect(pagePaths).toContainEqual('/page1/child1');
  329. expect(pagePaths).toContainEqual('/page2');
  330. });
  331. });
  332. describe('.findListWithDescendants', () => {
  333. test('can retrieve all pages with testUser0', async() => {
  334. const result = await Page.findListWithDescendants('/grant', testUser0);
  335. const { pages } = result;
  336. // assert totalCount
  337. expect(pages.length).toEqual(5);
  338. // assert paths
  339. const pagePaths = await pages.map((page) => { return page.path });
  340. expect(pagePaths).toContainEqual('/grant/groupacl');
  341. expect(pagePaths).toContainEqual('/grant/specified');
  342. expect(pagePaths).toContainEqual('/grant/owner');
  343. expect(pagePaths).toContainEqual('/grant/public');
  344. expect(pagePaths).toContainEqual('/grant');
  345. });
  346. test('can retrieve all pages with testUser1', async() => {
  347. const result = await Page.findListWithDescendants('/grant', testUser1);
  348. const { pages } = result;
  349. // assert totalCount
  350. expect(pages.length).toEqual(5);
  351. // assert paths
  352. const pagePaths = await pages.map((page) => { return page.path });
  353. expect(pagePaths).toContainEqual('/grant/groupacl');
  354. expect(pagePaths).toContainEqual('/grant/specified');
  355. expect(pagePaths).toContainEqual('/grant/owner');
  356. expect(pagePaths).toContainEqual('/grant/public');
  357. expect(pagePaths).toContainEqual('/grant');
  358. });
  359. test('can retrieve all pages with testUser2', async() => {
  360. const result = await Page.findListWithDescendants('/grant', testUser2);
  361. const { pages } = result;
  362. // assert totalCount
  363. expect(pages.length).toEqual(5);
  364. // assert paths
  365. const pagePaths = await pages.map((page) => { return page.path });
  366. expect(pagePaths).toContainEqual('/grant/groupacl');
  367. expect(pagePaths).toContainEqual('/grant/specified');
  368. expect(pagePaths).toContainEqual('/grant/owner');
  369. expect(pagePaths).toContainEqual('/grant/public');
  370. expect(pagePaths).toContainEqual('/grant');
  371. });
  372. test('can retrieve all pages without user', async() => {
  373. const result = await Page.findListWithDescendants('/grant', null);
  374. const { pages } = result;
  375. // assert totalCount
  376. expect(pages.length).toEqual(5);
  377. // assert paths
  378. const pagePaths = await pages.map((page) => { return page.path });
  379. expect(pagePaths).toContainEqual('/grant/groupacl');
  380. expect(pagePaths).toContainEqual('/grant/specified');
  381. expect(pagePaths).toContainEqual('/grant/owner');
  382. expect(pagePaths).toContainEqual('/grant/public');
  383. expect(pagePaths).toContainEqual('/grant');
  384. });
  385. });
  386. describe('.findManageableListWithDescendants', () => {
  387. test('can retrieve all pages with testUser0', async() => {
  388. const pages = await Page.findManageableListWithDescendants(parentPage, testUser0);
  389. // assert totalCount
  390. expect(pages.length).toEqual(5);
  391. // assert paths
  392. const pagePaths = await pages.map((page) => { return page.path });
  393. expect(pagePaths).toContainEqual('/grant/groupacl');
  394. expect(pagePaths).toContainEqual('/grant/specified');
  395. expect(pagePaths).toContainEqual('/grant/owner');
  396. expect(pagePaths).toContainEqual('/grant/public');
  397. expect(pagePaths).toContainEqual('/grant');
  398. });
  399. test('can retrieve group page and public page which starts with testUser1', async() => {
  400. const pages = await Page.findManageableListWithDescendants(parentPage, testUser1);
  401. // assert totalCount
  402. expect(pages.length).toEqual(3);
  403. // assert paths
  404. const pagePaths = await pages.map((page) => { return page.path });
  405. expect(pagePaths).toContainEqual('/grant/groupacl');
  406. expect(pagePaths).toContainEqual('/grant/public');
  407. expect(pagePaths).toContainEqual('/grant');
  408. });
  409. test('can retrieve only public page which starts with testUser2', async() => {
  410. const pages = await Page.findManageableListWithDescendants(parentPage, testUser2);
  411. // assert totalCount
  412. expect(pages.length).toEqual(2);
  413. // assert paths
  414. const pagePaths = await pages.map((page) => { return page.path });
  415. expect(pagePaths).toContainEqual('/grant/public');
  416. expect(pagePaths).toContainEqual('/grant');
  417. });
  418. test('can retrieve only public page which starts without user', async() => {
  419. const pages = await Page.findManageableListWithDescendants(parentPage, null);
  420. // assert totalCount
  421. expect(pages).toBeNull();
  422. });
  423. });
  424. });