page.test.js 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510
  1. const mongoose = require('mongoose');
  2. const { getInstance } = require('../setup-crowi');
  3. let testUser0;
  4. let testUser1;
  5. let testUser2;
  6. let testGroup0;
  7. let parentPage;
  8. describe('Page', () => {
  9. // eslint-disable-next-line no-unused-vars
  10. let crowi;
  11. let Page;
  12. let PageQueryBuilder;
  13. let User;
  14. let UserGroup;
  15. let UserGroupRelation;
  16. beforeAll(async(done) => {
  17. crowi = await getInstance();
  18. User = mongoose.model('User');
  19. UserGroup = mongoose.model('UserGroup');
  20. UserGroupRelation = mongoose.model('UserGroupRelation');
  21. Page = mongoose.model('Page');
  22. PageQueryBuilder = Page.PageQueryBuilder;
  23. await User.insertMany([
  24. { name: 'Anon 0', username: 'anonymous0', email: 'anonymous0@example.com' },
  25. { name: 'Anon 1', username: 'anonymous1', email: 'anonymous1@example.com' },
  26. { name: 'Anon 2', username: 'anonymous2', email: 'anonymous2@example.com' },
  27. ]);
  28. await UserGroup.insertMany([
  29. { name: 'TestGroup0' },
  30. { name: 'TestGroup1' },
  31. ]);
  32. testUser0 = await User.findOne({ username: 'anonymous0' });
  33. testUser1 = await User.findOne({ username: 'anonymous1' });
  34. testUser2 = await User.findOne({ username: 'anonymous2' });
  35. testGroup0 = await UserGroup.findOne({ name: 'TestGroup0' });
  36. await UserGroupRelation.insertMany([
  37. {
  38. relatedGroup: testGroup0,
  39. relatedUser: testUser0,
  40. },
  41. {
  42. relatedGroup: testGroup0,
  43. relatedUser: testUser1,
  44. },
  45. ]);
  46. await Page.insertMany([
  47. {
  48. path: '/user/anonymous0/memo',
  49. grant: Page.GRANT_RESTRICTED,
  50. grantedUsers: [testUser0],
  51. creator: testUser0,
  52. },
  53. {
  54. path: '/grant',
  55. grant: Page.GRANT_PUBLIC,
  56. grantedUsers: [testUser0],
  57. creator: testUser0,
  58. },
  59. {
  60. path: '/grant/public',
  61. grant: Page.GRANT_PUBLIC,
  62. grantedUsers: [testUser0],
  63. creator: testUser0,
  64. },
  65. {
  66. path: '/grant/restricted',
  67. grant: Page.GRANT_RESTRICTED,
  68. grantedUsers: [testUser0],
  69. creator: testUser0,
  70. },
  71. {
  72. path: '/grant/specified',
  73. grant: Page.GRANT_SPECIFIED,
  74. grantedUsers: [testUser0],
  75. creator: testUser0,
  76. },
  77. {
  78. path: '/grant/owner',
  79. grant: Page.GRANT_OWNER,
  80. grantedUsers: [testUser0],
  81. creator: testUser0,
  82. },
  83. {
  84. path: '/page/child/without/parents',
  85. grant: Page.GRANT_PUBLIC,
  86. creator: testUser0,
  87. },
  88. {
  89. path: '/grant/groupacl',
  90. grant: Page.GRANT_USER_GROUP,
  91. grantedUsers: [],
  92. grantedGroup: testGroup0,
  93. creator: testUser1,
  94. },
  95. {
  96. path: '/page1',
  97. grant: Page.GRANT_PUBLIC,
  98. creator: testUser0,
  99. },
  100. {
  101. path: '/page1/child1',
  102. grant: Page.GRANT_PUBLIC,
  103. creator: testUser0,
  104. },
  105. {
  106. path: '/page2',
  107. grant: Page.GRANT_PUBLIC,
  108. creator: testUser0,
  109. },
  110. ]);
  111. parentPage = await Page.findOne({ path: '/grant' });
  112. done();
  113. });
  114. describe('.isPublic', () => {
  115. describe('with a public page', () => {
  116. test('should return true', async() => {
  117. const page = await Page.findOne({ path: '/grant/public' });
  118. expect(page.isPublic()).toEqual(true);
  119. });
  120. });
  121. ['restricted', 'specified', 'owner'].forEach((grant) => {
  122. describe(`with a ${grant} page`, () => {
  123. test('should return false', async() => {
  124. const page = await Page.findOne({ path: `/grant/${grant}` });
  125. expect(page.isPublic()).toEqual(false);
  126. });
  127. });
  128. });
  129. });
  130. describe('.getDeletedPageName', () => {
  131. test('should return trash page name', () => {
  132. expect(Page.getDeletedPageName('/hoge')).toEqual('/trash/hoge');
  133. expect(Page.getDeletedPageName('hoge')).toEqual('/trash/hoge');
  134. });
  135. });
  136. describe('.getRevertDeletedPageName', () => {
  137. test('should return reverted trash page name', () => {
  138. expect(Page.getRevertDeletedPageName('/hoge')).toEqual('/hoge');
  139. expect(Page.getRevertDeletedPageName('/trash/hoge')).toEqual('/hoge');
  140. expect(Page.getRevertDeletedPageName('/trash/hoge/trash')).toEqual('/hoge/trash');
  141. });
  142. });
  143. describe('.isDeletableName', () => {
  144. test('should decide deletable or not', () => {
  145. expect(Page.isDeletableName('/hoge')).toBeTruthy();
  146. expect(Page.isDeletableName('/user/xxx')).toBeFalsy();
  147. expect(Page.isDeletableName('/user/xxx123')).toBeFalsy();
  148. expect(Page.isDeletableName('/user/xxx/')).toBeTruthy();
  149. expect(Page.isDeletableName('/user/xxx/hoge')).toBeTruthy();
  150. });
  151. });
  152. describe('.isCreatableName', () => {
  153. test('should decide creatable or not', () => {
  154. expect(Page.isCreatableName('/hoge')).toBeTruthy();
  155. // edge cases
  156. expect(Page.isCreatableName('/me')).toBeFalsy();
  157. expect(Page.isCreatableName('/me/')).toBeFalsy();
  158. expect(Page.isCreatableName('/me/x')).toBeFalsy();
  159. expect(Page.isCreatableName('/meeting')).toBeTruthy();
  160. expect(Page.isCreatableName('/meeting/x')).toBeTruthy();
  161. // end with "edit"
  162. expect(Page.isCreatableName('/meeting/edit')).toBeFalsy();
  163. // under score
  164. expect(Page.isCreatableName('/_')).toBeTruthy();
  165. expect(Page.isCreatableName('/_template')).toBeTruthy();
  166. expect(Page.isCreatableName('/__template')).toBeTruthy();
  167. expect(Page.isCreatableName('/_r/x')).toBeFalsy();
  168. expect(Page.isCreatableName('/_api')).toBeFalsy();
  169. expect(Page.isCreatableName('/_apix')).toBeFalsy();
  170. expect(Page.isCreatableName('/_api/x')).toBeFalsy();
  171. expect(Page.isCreatableName('/hoge/xx.md')).toBeFalsy();
  172. // relative path
  173. expect(Page.isCreatableName('/..')).toBeFalsy();
  174. expect(Page.isCreatableName('/../page')).toBeFalsy();
  175. expect(Page.isCreatableName('/page/..')).toBeFalsy();
  176. expect(Page.isCreatableName('/page/../page')).toBeFalsy();
  177. // start with https?
  178. expect(Page.isCreatableName('/http://demo.growi.org/hoge')).toBeFalsy();
  179. expect(Page.isCreatableName('/https://demo.growi.org/hoge')).toBeFalsy();
  180. expect(Page.isCreatableName('http://demo.growi.org/hoge')).toBeFalsy();
  181. expect(Page.isCreatableName('https://demo.growi.org/hoge')).toBeFalsy();
  182. expect(Page.isCreatableName('/ the / path / with / space')).toBeFalsy();
  183. const forbidden = ['installer', 'register', 'login', 'logout',
  184. 'admin', 'files', 'trash', 'paste', 'comments'];
  185. for (let i = 0; i < forbidden.length; i++) {
  186. const pn = forbidden[i];
  187. expect(Page.isCreatableName(`/${pn}`)).toBeFalsy();
  188. expect(Page.isCreatableName(`/${pn}/`)).toBeFalsy();
  189. expect(Page.isCreatableName(`/${pn}/abc`)).toBeFalsy();
  190. }
  191. });
  192. });
  193. describe('.isAccessiblePageByViewer', () => {
  194. describe('with a granted page', () => {
  195. test('should return true with granted user', async() => {
  196. const user = await User.findOne({ email: 'anonymous0@example.com' });
  197. const page = await Page.findOne({ path: '/user/anonymous0/memo' });
  198. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  199. expect(bool).toEqual(true);
  200. });
  201. test('should return false without user', async() => {
  202. const user = null;
  203. const page = await Page.findOne({ path: '/user/anonymous0/memo' });
  204. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  205. expect(bool).toEqual(true);
  206. });
  207. });
  208. describe('with a public page', () => {
  209. test('should return true with user', async() => {
  210. const user = await User.findOne({ email: 'anonymous1@example.com' });
  211. const page = await Page.findOne({ path: '/grant/public' });
  212. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  213. expect(bool).toEqual(true);
  214. });
  215. test('should return true with out', async() => {
  216. const user = null;
  217. const page = await Page.findOne({ path: '/grant/public' });
  218. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  219. expect(bool).toEqual(true);
  220. });
  221. });
  222. describe('with a restricted page', () => {
  223. test('should return false with user who has no grant', async() => {
  224. const user = await User.findOne({ email: 'anonymous1@example.com' });
  225. const page = await Page.findOne({ path: '/grant/owner' });
  226. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  227. expect(bool).toEqual(false);
  228. });
  229. test('should return false without user', async() => {
  230. const user = null;
  231. const page = await Page.findOne({ path: '/grant/owner' });
  232. const bool = await Page.isAccessiblePageByViewer(page.id, user);
  233. expect(bool).toEqual(false);
  234. });
  235. });
  236. });
  237. describe('.findPage', () => {
  238. describe('findByIdAndViewer', () => {
  239. test('should find page (public)', async() => {
  240. const expectedPage = await Page.findOne({ path: '/grant/public' });
  241. const page = await Page.findByIdAndViewer(expectedPage.id, testUser0);
  242. expect(page).not.toBeNull();
  243. expect(page.path).toEqual(expectedPage.path);
  244. });
  245. test('should find page (anyone knows link)', async() => {
  246. const expectedPage = await Page.findOne({ path: '/grant/restricted' });
  247. const page = await Page.findByIdAndViewer(expectedPage.id, testUser1);
  248. expect(page).not.toBeNull();
  249. expect(page.path).toEqual(expectedPage.path);
  250. });
  251. test('should find page (only me)', async() => {
  252. const expectedPage = await Page.findOne({ path: '/grant/owner' });
  253. const page = await Page.findByIdAndViewer(expectedPage.id, testUser0);
  254. expect(page).not.toBeNull();
  255. expect(page.path).toEqual(expectedPage.path);
  256. });
  257. test('should not be found by grant (only me)', async() => {
  258. const expectedPage = await Page.findOne({ path: '/grant/owner' });
  259. const page = await Page.findByIdAndViewer(expectedPage.id, testUser1);
  260. expect(page).toBeNull();
  261. });
  262. });
  263. describe('findByIdAndViewer granted userGroup', () => {
  264. test('should find page', async() => {
  265. const expectedPage = await Page.findOne({ path: '/grant/groupacl' });
  266. const page = await Page.findByIdAndViewer(expectedPage.id, testUser0);
  267. expect(page).not.toBeNull();
  268. expect(page.path).toEqual(expectedPage.path);
  269. });
  270. test('should not be found by grant', async() => {
  271. const expectedPage = await Page.findOne({ path: '/grant/groupacl' });
  272. const page = await Page.findByIdAndViewer(expectedPage.id, testUser2);
  273. expect(page).toBeNull();
  274. });
  275. });
  276. });
  277. describe('PageQueryBuilder.addConditionToListWithDescendants', () => {
  278. test('can retrieve descendants of /page', async() => {
  279. const builder = new PageQueryBuilder(Page.find());
  280. builder.addConditionToListWithDescendants('/page');
  281. const result = await builder.query.exec();
  282. // assert totalCount
  283. expect(result.length).toEqual(1);
  284. // assert paths
  285. const pagePaths = result.map((page) => { return page.path });
  286. expect(pagePaths).toContainEqual('/page/child/without/parents');
  287. });
  288. test('can retrieve descendants of /page1', async() => {
  289. const builder = new PageQueryBuilder(Page.find());
  290. builder.addConditionToListWithDescendants('/page1/');
  291. const result = await builder.query.exec();
  292. // assert totalCount
  293. expect(result.length).toEqual(2);
  294. // assert paths
  295. const pagePaths = result.map((page) => { return page.path });
  296. expect(pagePaths).toContainEqual('/page1');
  297. expect(pagePaths).toContainEqual('/page1/child1');
  298. });
  299. });
  300. describe('PageQueryBuilder.addConditionToListOnlyDescendants', () => {
  301. test('can retrieve only descendants of /page', async() => {
  302. const builder = new PageQueryBuilder(Page.find());
  303. builder.addConditionToListOnlyDescendants('/page');
  304. const result = await builder.query.exec();
  305. // assert totalCount
  306. expect(result.length).toEqual(1);
  307. // assert paths
  308. const pagePaths = result.map((page) => { return page.path });
  309. expect(pagePaths).toContainEqual('/page/child/without/parents');
  310. });
  311. test('can retrieve only descendants of /page1', async() => {
  312. const builder = new PageQueryBuilder(Page.find());
  313. builder.addConditionToListOnlyDescendants('/page1');
  314. const result = await builder.query.exec();
  315. // assert totalCount
  316. expect(result.length).toEqual(1);
  317. // assert paths
  318. const pagePaths = result.map((page) => { return page.path });
  319. expect(pagePaths).toContainEqual('/page1/child1');
  320. });
  321. });
  322. describe('PageQueryBuilder.addConditionToListByStartWith', () => {
  323. test('can retrieve pages which starts with /page', async() => {
  324. const builder = new PageQueryBuilder(Page.find());
  325. builder.addConditionToListByStartWith('/page');
  326. const result = await builder.query.exec();
  327. // assert totalCount
  328. expect(result.length).toEqual(4);
  329. // assert paths
  330. const pagePaths = result.map((page) => { return page.path });
  331. expect(pagePaths).toContainEqual('/page/child/without/parents');
  332. expect(pagePaths).toContainEqual('/page1');
  333. expect(pagePaths).toContainEqual('/page1/child1');
  334. expect(pagePaths).toContainEqual('/page2');
  335. });
  336. });
  337. describe('.findListWithDescendants', () => {
  338. test('can retrieve all pages with testUser0', async() => {
  339. const result = await Page.findListWithDescendants('/grant', testUser0);
  340. const { pages } = result;
  341. // assert totalCount
  342. expect(pages.length).toEqual(5);
  343. // assert paths
  344. const pagePaths = await pages.map((page) => { return page.path });
  345. expect(pagePaths).toContainEqual('/grant/groupacl');
  346. expect(pagePaths).toContainEqual('/grant/specified');
  347. expect(pagePaths).toContainEqual('/grant/owner');
  348. expect(pagePaths).toContainEqual('/grant/public');
  349. expect(pagePaths).toContainEqual('/grant');
  350. });
  351. test('can retrieve all pages with testUser1', async() => {
  352. const result = await Page.findListWithDescendants('/grant', testUser1);
  353. const { pages } = result;
  354. // assert totalCount
  355. expect(pages.length).toEqual(5);
  356. // assert paths
  357. const pagePaths = await pages.map((page) => { return page.path });
  358. expect(pagePaths).toContainEqual('/grant/groupacl');
  359. expect(pagePaths).toContainEqual('/grant/specified');
  360. expect(pagePaths).toContainEqual('/grant/owner');
  361. expect(pagePaths).toContainEqual('/grant/public');
  362. expect(pagePaths).toContainEqual('/grant');
  363. });
  364. test('can retrieve all pages with testUser2', async() => {
  365. const result = await Page.findListWithDescendants('/grant', testUser2);
  366. const { pages } = result;
  367. // assert totalCount
  368. expect(pages.length).toEqual(5);
  369. // assert paths
  370. const pagePaths = await pages.map((page) => { return page.path });
  371. expect(pagePaths).toContainEqual('/grant/groupacl');
  372. expect(pagePaths).toContainEqual('/grant/specified');
  373. expect(pagePaths).toContainEqual('/grant/owner');
  374. expect(pagePaths).toContainEqual('/grant/public');
  375. expect(pagePaths).toContainEqual('/grant');
  376. });
  377. test('can retrieve all pages without user', async() => {
  378. const result = await Page.findListWithDescendants('/grant', null);
  379. const { pages } = result;
  380. // assert totalCount
  381. expect(pages.length).toEqual(5);
  382. // assert paths
  383. const pagePaths = await pages.map((page) => { return page.path });
  384. expect(pagePaths).toContainEqual('/grant/groupacl');
  385. expect(pagePaths).toContainEqual('/grant/specified');
  386. expect(pagePaths).toContainEqual('/grant/owner');
  387. expect(pagePaths).toContainEqual('/grant/public');
  388. expect(pagePaths).toContainEqual('/grant');
  389. });
  390. });
  391. describe('.findManageableListWithDescendants', () => {
  392. test('can retrieve all pages with testUser0', async() => {
  393. const pages = await Page.findManageableListWithDescendants(parentPage, testUser0);
  394. // assert totalCount
  395. expect(pages.length).toEqual(5);
  396. // assert paths
  397. const pagePaths = await pages.map((page) => { return page.path });
  398. expect(pagePaths).toContainEqual('/grant/groupacl');
  399. expect(pagePaths).toContainEqual('/grant/specified');
  400. expect(pagePaths).toContainEqual('/grant/owner');
  401. expect(pagePaths).toContainEqual('/grant/public');
  402. expect(pagePaths).toContainEqual('/grant');
  403. });
  404. test('can retrieve group page and public page which starts with testUser1', async() => {
  405. const pages = await Page.findManageableListWithDescendants(parentPage, testUser1);
  406. // assert totalCount
  407. expect(pages.length).toEqual(3);
  408. // assert paths
  409. const pagePaths = await pages.map((page) => { return page.path });
  410. expect(pagePaths).toContainEqual('/grant/groupacl');
  411. expect(pagePaths).toContainEqual('/grant/public');
  412. expect(pagePaths).toContainEqual('/grant');
  413. });
  414. test('can retrieve only public page which starts with testUser2', async() => {
  415. const pages = await Page.findManageableListWithDescendants(parentPage, testUser2);
  416. // assert totalCount
  417. expect(pages.length).toEqual(2);
  418. // assert paths
  419. const pagePaths = await pages.map((page) => { return page.path });
  420. expect(pagePaths).toContainEqual('/grant/public');
  421. expect(pagePaths).toContainEqual('/grant');
  422. });
  423. test('can retrieve only public page which starts without user', async() => {
  424. const pages = await Page.findManageableListWithDescendants(parentPage, null);
  425. // assert totalCount
  426. expect(pages).toBeNull();
  427. });
  428. });
  429. });