3 use MediaWiki\Block\Restriction\PageRestriction
;
4 use MediaWiki\Block\SystemBlock
;
5 use MediaWiki\MediaWikiServices
;
10 * @covers \MediaWiki\Permissions\PermissionManager::getPermissionErrors
11 * @covers \MediaWiki\Permissions\PermissionManager::getPermissionErrorsInternal
13 class TitlePermissionTest
extends MediaWikiLangTestCase
{
18 protected $userName, $altUserName;
28 protected $user, $anonUser, $userUser, $altUser;
30 protected function setUp() {
34 $localOffset = date( 'Z' ) / 60;
36 $this->setMwGlobals( [
37 'wgLocaltimezone' => $localZone,
38 'wgLocalTZoffset' => $localOffset,
39 'wgNamespaceProtection' => [
40 NS_MEDIAWIKI
=> 'editinterface',
43 // Without this testUserBlock will use a non-English context on non-English MediaWiki
44 // installations (because of how Title::checkUserBlock is implemented) and fail.
45 RequestContext
::resetMain();
47 $this->userName
= 'Useruser';
48 $this->altUserName
= 'Altuseruser';
49 date_default_timezone_set( $localZone );
51 $this->title
= Title
::makeTitle( NS_MAIN
, "Main Page" );
52 if ( !isset( $this->userUser
) ||
!( $this->userUser
instanceof User
) ) {
53 $this->userUser
= User
::newFromName( $this->userName
);
55 if ( !$this->userUser
->getId() ) {
56 $this->userUser
= User
::createNew( $this->userName
, [
57 "email" => "test@example.com",
58 "real_name" => "Test User" ] );
59 $this->userUser
->load();
62 $this->altUser
= User
::newFromName( $this->altUserName
);
63 if ( !$this->altUser
->getId() ) {
64 $this->altUser
= User
::createNew( $this->altUserName
, [
65 "email" => "alttest@example.com",
66 "real_name" => "Test User Alt" ] );
67 $this->altUser
->load();
70 $this->anonUser
= User
::newFromId( 0 );
72 $this->user
= $this->userUser
;
74 $this->overrideMwServices();
77 protected function setUserPerm( $perm ) {
78 // Setting member variables is evil!!!
80 if ( is_array( $perm ) ) {
81 $this->user
->mRights
= $perm;
83 $this->user
->mRights
= [ $perm ];
87 protected function setTitle( $ns, $title = "Main_Page" ) {
88 $this->title
= Title
::makeTitle( $ns, $title );
91 protected function setUser( $userName = null ) {
92 if ( $userName === 'anon' ) {
93 $this->user
= $this->anonUser
;
94 } elseif ( $userName === null ||
$userName === $this->userName
) {
95 $this->user
= $this->userUser
;
97 $this->user
= $this->altUser
;
102 * @todo This test method should be split up into separate test methods and
105 * This test is failing per T201776.
108 * @covers \MediaWiki\Permissions\PermissionManager::checkQuickPermissions
110 public function testQuickPermissions() {
111 $prefix = MediaWikiServices
::getInstance()->getContentLanguage()->
112 getFormattedNsText( NS_PROJECT
);
114 $this->setUser( 'anon' );
115 $this->setTitle( NS_TALK
);
116 $this->setUserPerm( "createtalk" );
117 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
118 $this->assertEquals( [], $res );
120 $this->setTitle( NS_TALK
);
121 $this->setUserPerm( "createpage" );
122 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
123 $this->assertEquals( [ [ "nocreatetext" ] ], $res );
125 $this->setTitle( NS_TALK
);
126 $this->setUserPerm( "" );
127 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
128 $this->assertEquals( [ [ 'nocreatetext' ] ], $res );
130 $this->setTitle( NS_MAIN
);
131 $this->setUserPerm( "createpage" );
132 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
133 $this->assertEquals( [], $res );
135 $this->setTitle( NS_MAIN
);
136 $this->setUserPerm( "createtalk" );
137 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
138 $this->assertEquals( [ [ 'nocreatetext' ] ], $res );
140 $this->setUser( $this->userName
);
141 $this->setTitle( NS_TALK
);
142 $this->setUserPerm( "createtalk" );
143 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
144 $this->assertEquals( [], $res );
146 $this->setTitle( NS_TALK
);
147 $this->setUserPerm( "createpage" );
148 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
149 $this->assertEquals( [ [ 'nocreate-loggedin' ] ], $res );
151 $this->setTitle( NS_TALK
);
152 $this->setUserPerm( "" );
153 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
154 $this->assertEquals( [ [ 'nocreate-loggedin' ] ], $res );
156 $this->setTitle( NS_MAIN
);
157 $this->setUserPerm( "createpage" );
158 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
159 $this->assertEquals( [], $res );
161 $this->setTitle( NS_MAIN
);
162 $this->setUserPerm( "createtalk" );
163 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
164 $this->assertEquals( [ [ 'nocreate-loggedin' ] ], $res );
166 $this->setTitle( NS_MAIN
);
167 $this->setUserPerm( "" );
168 $res = $this->title
->getUserPermissionsErrors( 'create', $this->user
);
169 $this->assertEquals( [ [ 'nocreate-loggedin' ] ], $res );
171 $this->setUser( 'anon' );
172 $this->setTitle( NS_USER
, $this->userName
. '' );
173 $this->setUserPerm( "" );
174 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
175 $this->assertEquals( [ [ 'cant-move-user-page' ], [ 'movenologintext' ] ], $res );
177 $this->setTitle( NS_USER
, $this->userName
. '/subpage' );
178 $this->setUserPerm( "" );
179 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
180 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
182 $this->setTitle( NS_USER
, $this->userName
. '' );
183 $this->setUserPerm( "move-rootuserpages" );
184 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
185 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
187 $this->setTitle( NS_USER
, $this->userName
. '/subpage' );
188 $this->setUserPerm( "move-rootuserpages" );
189 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
190 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
192 $this->setTitle( NS_USER
, $this->userName
. '' );
193 $this->setUserPerm( "" );
194 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
195 $this->assertEquals( [ [ 'cant-move-user-page' ], [ 'movenologintext' ] ], $res );
197 $this->setTitle( NS_USER
, $this->userName
. '/subpage' );
198 $this->setUserPerm( "" );
199 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
200 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
202 $this->setTitle( NS_USER
, $this->userName
. '' );
203 $this->setUserPerm( "move-rootuserpages" );
204 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
205 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
207 $this->setTitle( NS_USER
, $this->userName
. '/subpage' );
208 $this->setUserPerm( "move-rootuserpages" );
209 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
210 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
212 $this->setUser( $this->userName
);
213 $this->setTitle( NS_FILE
, "img.png" );
214 $this->setUserPerm( "" );
215 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
216 $this->assertEquals( [ [ 'movenotallowedfile' ], [ 'movenotallowed' ] ], $res );
218 $this->setTitle( NS_FILE
, "img.png" );
219 $this->setUserPerm( "movefile" );
220 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
221 $this->assertEquals( [ [ 'movenotallowed' ] ], $res );
223 $this->setUser( 'anon' );
224 $this->setTitle( NS_FILE
, "img.png" );
225 $this->setUserPerm( "" );
226 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
227 $this->assertEquals( [ [ 'movenotallowedfile' ], [ 'movenologintext' ] ], $res );
229 $this->setTitle( NS_FILE
, "img.png" );
230 $this->setUserPerm( "movefile" );
231 $res = $this->title
->getUserPermissionsErrors( 'move', $this->user
);
232 $this->assertEquals( [ [ 'movenologintext' ] ], $res );
234 $this->setUser( $this->userName
);
235 $this->setUserPerm( "move" );
236 $this->runGroupPermissions( 'move', [ [ 'movenotallowedfile' ] ] );
238 $this->setUserPerm( "" );
239 $this->runGroupPermissions(
241 [ [ 'movenotallowedfile' ], [ 'movenotallowed' ] ]
244 $this->setUser( 'anon' );
245 $this->setUserPerm( "move" );
246 $this->runGroupPermissions( 'move', [ [ 'movenotallowedfile' ] ] );
248 $this->setUserPerm( "" );
249 $this->runGroupPermissions(
251 [ [ 'movenotallowedfile' ], [ 'movenotallowed' ] ],
252 [ [ 'movenotallowedfile' ], [ 'movenologintext' ] ]
255 if ( $this->isWikitextNS( NS_MAIN
) ) {
256 // NOTE: some content models don't allow moving
257 // @todo find a Wikitext namespace for testing
259 $this->setTitle( NS_MAIN
);
260 $this->setUser( 'anon' );
261 $this->setUserPerm( "move" );
262 $this->runGroupPermissions( 'move', [] );
264 $this->setUserPerm( "" );
265 $this->runGroupPermissions( 'move', [ [ 'movenotallowed' ] ],
266 [ [ 'movenologintext' ] ] );
268 $this->setUser( $this->userName
);
269 $this->setUserPerm( "" );
270 $this->runGroupPermissions( 'move', [ [ 'movenotallowed' ] ] );
272 $this->setUserPerm( "move" );
273 $this->runGroupPermissions( 'move', [] );
275 $this->setUser( 'anon' );
276 $this->setUserPerm( 'move' );
277 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
278 $this->assertEquals( [], $res );
280 $this->setUserPerm( '' );
281 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
282 $this->assertEquals( [ [ 'movenotallowed' ] ], $res );
285 $this->setTitle( NS_USER
);
286 $this->setUser( $this->userName
);
287 $this->setUserPerm( [ "move", "move-rootuserpages" ] );
288 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
289 $this->assertEquals( [], $res );
291 $this->setUserPerm( "move" );
292 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
293 $this->assertEquals( [ [ 'cant-move-to-user-page' ] ], $res );
295 $this->setUser( 'anon' );
296 $this->setUserPerm( [ "move", "move-rootuserpages" ] );
297 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
298 $this->assertEquals( [], $res );
300 $this->setTitle( NS_USER
, "User/subpage" );
301 $this->setUserPerm( [ "move", "move-rootuserpages" ] );
302 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
303 $this->assertEquals( [], $res );
305 $this->setUserPerm( "move" );
306 $res = $this->title
->getUserPermissionsErrors( 'move-target', $this->user
);
307 $this->assertEquals( [], $res );
309 $this->setUser( 'anon' );
312 [ [ 'badaccess-groups', "*, [[$prefix:Users|Users]]", 2 ] ],
313 [ [ 'badaccess-group0' ] ],
320 "[[$prefix:Administrators|Administrators]]", 1 ],
323 [ [ 'badaccess-group0' ], [ 'protect-cantedit' ] ],
324 [ [ 'protect-cantedit' ] ],
327 '' => [ [], [], [], true ]
330 foreach ( [ "edit", "protect", "" ] as $action ) {
331 $this->setUserPerm( null );
332 $this->assertEquals( $check[$action][0],
333 $this->title
->getUserPermissionsErrors( $action, $this->user
, true ) );
334 $this->assertEquals( $check[$action][0],
335 $this->title
->getUserPermissionsErrors( $action, $this->user
, 'full' ) );
336 $this->assertEquals( $check[$action][0],
337 $this->title
->getUserPermissionsErrors( $action, $this->user
, 'secure' ) );
339 global $wgGroupPermissions;
340 $old = $wgGroupPermissions;
341 $wgGroupPermissions = [];
343 $this->assertEquals( $check[$action][1],
344 $this->title
->getUserPermissionsErrors( $action, $this->user
, true ) );
345 $this->assertEquals( $check[$action][1],
346 $this->title
->getUserPermissionsErrors( $action, $this->user
, 'full' ) );
347 $this->assertEquals( $check[$action][1],
348 $this->title
->getUserPermissionsErrors( $action, $this->user
, 'secure' ) );
349 $wgGroupPermissions = $old;
351 $this->setUserPerm( $action );
352 $this->assertEquals( $check[$action][2],
353 $this->title
->getUserPermissionsErrors( $action, $this->user
, true ) );
354 $this->assertEquals( $check[$action][2],
355 $this->title
->getUserPermissionsErrors( $action, $this->user
, 'full' ) );
356 $this->assertEquals( $check[$action][2],
357 $this->title
->getUserPermissionsErrors( $action, $this->user
, 'secure' ) );
359 $this->setUserPerm( $action );
360 $this->assertEquals( $check[$action][3],
361 $this->title
->userCan( $action, $this->user
, true ) );
362 $this->assertEquals( $check[$action][3],
363 $this->title
->quickUserCan( $action, $this->user
) );
364 # count( User::getGroupsWithPermissions( $action ) ) < 1
368 protected function runGroupPermissions( $action, $result, $result2 = null ) {
369 global $wgGroupPermissions;
371 if ( $result2 === null ) {
375 $wgGroupPermissions['autoconfirmed']['move'] = false;
376 $wgGroupPermissions['user']['move'] = false;
377 $res = $this->title
->getUserPermissionsErrors( $action, $this->user
);
378 $this->assertEquals( $result, $res );
380 $wgGroupPermissions['autoconfirmed']['move'] = true;
381 $wgGroupPermissions['user']['move'] = false;
382 $res = $this->title
->getUserPermissionsErrors( $action, $this->user
);
383 $this->assertEquals( $result2, $res );
385 $wgGroupPermissions['autoconfirmed']['move'] = true;
386 $wgGroupPermissions['user']['move'] = true;
387 $res = $this->title
->getUserPermissionsErrors( $action, $this->user
);
388 $this->assertEquals( $result2, $res );
390 $wgGroupPermissions['autoconfirmed']['move'] = false;
391 $wgGroupPermissions['user']['move'] = true;
392 $res = $this->title
->getUserPermissionsErrors( $action, $this->user
);
393 $this->assertEquals( $result2, $res );
397 * @todo This test method should be split up into separate test methods and
399 * @covers \MediaWiki\Permissions\PermissionManager::checkSpecialsAndNSPermissions
401 public function testSpecialsAndNSPermissions() {
402 global $wgNamespaceProtection;
403 $this->setUser( $this->userName
);
405 $this->setTitle( NS_SPECIAL
);
407 $this->assertEquals( [ [ 'badaccess-group0' ], [ 'ns-specialprotected' ] ],
408 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
410 $this->setTitle( NS_MAIN
);
411 $this->setUserPerm( 'bogus' );
412 $this->assertEquals( [],
413 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
415 $this->setTitle( NS_MAIN
);
416 $this->setUserPerm( '' );
417 $this->assertEquals( [ [ 'badaccess-group0' ] ],
418 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
420 $wgNamespaceProtection[NS_USER
] = [ 'bogus' ];
422 $this->setTitle( NS_USER
);
423 $this->setUserPerm( '' );
424 $this->assertEquals( [ [ 'badaccess-group0' ],
425 [ 'namespaceprotected', 'User', 'bogus' ] ],
426 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
428 $this->setTitle( NS_MEDIAWIKI
);
429 $this->setUserPerm( 'bogus' );
430 $this->assertEquals( [ [ 'protectedinterface', 'bogus' ] ],
431 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
433 $this->setTitle( NS_MEDIAWIKI
);
434 $this->setUserPerm( 'bogus' );
435 $this->assertEquals( [ [ 'protectedinterface', 'bogus' ] ],
436 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
438 $wgNamespaceProtection = null;
440 $this->setUserPerm( 'bogus' );
441 $this->assertEquals( [],
442 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
443 $this->assertEquals( true,
444 $this->title
->userCan( 'bogus', $this->user
) );
446 $this->setUserPerm( '' );
447 $this->assertEquals( [ [ 'badaccess-group0' ] ],
448 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
449 $this->assertEquals( false,
450 $this->title
->userCan( 'bogus', $this->user
) );
454 * @todo This test method should be split up into separate test methods and
456 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
458 public function testJsConfigEditPermissions() {
459 $this->setUser( $this->userName
);
461 $this->setTitle( NS_USER
, $this->userName
. '/test.js' );
462 $this->runConfigEditPermissions(
463 [ [ 'badaccess-group0' ], [ 'mycustomjsprotected', 'bogus' ] ],
465 [ [ 'badaccess-group0' ], [ 'mycustomjsprotected', 'bogus' ] ],
466 [ [ 'badaccess-group0' ], [ 'mycustomjsprotected', 'bogus' ] ],
467 [ [ 'badaccess-group0' ] ],
469 [ [ 'badaccess-group0' ], [ 'mycustomjsprotected', 'bogus' ] ],
470 [ [ 'badaccess-group0' ], [ 'mycustomjsprotected', 'bogus' ] ],
471 [ [ 'badaccess-group0' ] ],
472 [ [ 'badaccess-groups' ] ]
477 * @todo This test method should be split up into separate test methods and
479 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
481 public function testJsonConfigEditPermissions() {
482 $prefix = MediaWikiServices
::getInstance()->getContentLanguage()->
483 getFormattedNsText( NS_PROJECT
);
484 $this->setUser( $this->userName
);
486 $this->setTitle( NS_USER
, $this->userName
. '/test.json' );
487 $this->runConfigEditPermissions(
488 [ [ 'badaccess-group0' ], [ 'mycustomjsonprotected', 'bogus' ] ],
490 [ [ 'badaccess-group0' ], [ 'mycustomjsonprotected', 'bogus' ] ],
491 [ [ 'badaccess-group0' ] ],
492 [ [ 'badaccess-group0' ], [ 'mycustomjsonprotected', 'bogus' ] ],
494 [ [ 'badaccess-group0' ], [ 'mycustomjsonprotected', 'bogus' ] ],
495 [ [ 'badaccess-group0' ] ],
496 [ [ 'badaccess-group0' ], [ 'mycustomjsonprotected', 'bogus' ] ],
497 [ [ 'badaccess-groups' ] ]
502 * @todo This test method should be split up into separate test methods and
504 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
506 public function testCssConfigEditPermissions() {
507 $this->setUser( $this->userName
);
509 $this->setTitle( NS_USER
, $this->userName
. '/test.css' );
510 $this->runConfigEditPermissions(
511 [ [ 'badaccess-group0' ], [ 'mycustomcssprotected', 'bogus' ] ],
513 [ [ 'badaccess-group0' ] ],
514 [ [ 'badaccess-group0' ], [ 'mycustomcssprotected', 'bogus' ] ],
515 [ [ 'badaccess-group0' ], [ 'mycustomcssprotected', 'bogus' ] ],
517 [ [ 'badaccess-group0' ] ],
518 [ [ 'badaccess-group0' ], [ 'mycustomcssprotected', 'bogus' ] ],
519 [ [ 'badaccess-group0' ], [ 'mycustomcssprotected', 'bogus' ] ],
520 [ [ 'badaccess-groups' ] ]
525 * @todo This test method should be split up into separate test methods and
527 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
529 public function testOtherJsConfigEditPermissions() {
530 $this->setUser( $this->userName
);
532 $this->setTitle( NS_USER
, $this->altUserName
. '/test.js' );
533 $this->runConfigEditPermissions(
534 [ [ 'badaccess-group0' ], [ 'customjsprotected', 'bogus' ] ],
536 [ [ 'badaccess-group0' ], [ 'customjsprotected', 'bogus' ] ],
537 [ [ 'badaccess-group0' ], [ 'customjsprotected', 'bogus' ] ],
538 [ [ 'badaccess-group0' ], [ 'customjsprotected', 'bogus' ] ],
540 [ [ 'badaccess-group0' ], [ 'customjsprotected', 'bogus' ] ],
541 [ [ 'badaccess-group0' ], [ 'customjsprotected', 'bogus' ] ],
542 [ [ 'badaccess-group0' ] ],
543 [ [ 'badaccess-groups' ] ]
548 * @todo This test method should be split up into separate test methods and
550 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
552 public function testOtherJsonConfigEditPermissions() {
553 $this->setUser( $this->userName
);
555 $this->setTitle( NS_USER
, $this->altUserName
. '/test.json' );
556 $this->runConfigEditPermissions(
557 [ [ 'badaccess-group0' ], [ 'customjsonprotected', 'bogus' ] ],
559 [ [ 'badaccess-group0' ], [ 'customjsonprotected', 'bogus' ] ],
560 [ [ 'badaccess-group0' ], [ 'customjsonprotected', 'bogus' ] ],
561 [ [ 'badaccess-group0' ], [ 'customjsonprotected', 'bogus' ] ],
563 [ [ 'badaccess-group0' ], [ 'customjsonprotected', 'bogus' ] ],
564 [ [ 'badaccess-group0' ] ],
565 [ [ 'badaccess-group0' ], [ 'customjsonprotected', 'bogus' ] ],
566 [ [ 'badaccess-groups' ] ]
571 * @todo This test method should be split up into separate test methods and
573 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
575 public function testOtherCssConfigEditPermissions() {
576 $this->setUser( $this->userName
);
578 $this->setTitle( NS_USER
, $this->altUserName
. '/test.css' );
579 $this->runConfigEditPermissions(
580 [ [ 'badaccess-group0' ], [ 'customcssprotected', 'bogus' ] ],
582 [ [ 'badaccess-group0' ], [ 'customcssprotected', 'bogus' ] ],
583 [ [ 'badaccess-group0' ], [ 'customcssprotected', 'bogus' ] ],
584 [ [ 'badaccess-group0' ], [ 'customcssprotected', 'bogus' ] ],
586 [ [ 'badaccess-group0' ] ],
587 [ [ 'badaccess-group0' ], [ 'customcssprotected', 'bogus' ] ],
588 [ [ 'badaccess-group0' ], [ 'customcssprotected', 'bogus' ] ],
589 [ [ 'badaccess-groups' ] ]
594 * @todo This test method should be split up into separate test methods and
596 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
598 public function testOtherNonConfigEditPermissions() {
599 $this->setUser( $this->userName
);
601 $this->setTitle( NS_USER
, $this->altUserName
. '/tempo' );
602 $this->runConfigEditPermissions(
603 [ [ 'badaccess-group0' ] ],
605 [ [ 'badaccess-group0' ] ],
606 [ [ 'badaccess-group0' ] ],
607 [ [ 'badaccess-group0' ] ],
609 [ [ 'badaccess-group0' ] ],
610 [ [ 'badaccess-group0' ] ],
611 [ [ 'badaccess-group0' ] ],
612 [ [ 'badaccess-groups' ] ]
617 * @todo This should use data providers like the other methods here.
618 * @covers \MediaWiki\Permissions\PermissionManager::checkUserConfigPermissions
620 public function testPatrolActionConfigEditPermissions() {
621 $this->setUser( 'anon' );
622 $this->setTitle( NS_USER
, 'ToPatrolOrNotToPatrol' );
623 $this->runConfigEditPermissions(
624 [ [ 'badaccess-group0' ] ],
626 [ [ 'badaccess-group0' ] ],
627 [ [ 'badaccess-group0' ] ],
628 [ [ 'badaccess-group0' ] ],
630 [ [ 'badaccess-group0' ] ],
631 [ [ 'badaccess-group0' ] ],
632 [ [ 'badaccess-group0' ] ],
633 [ [ 'badaccess-groups' ] ]
637 protected function runConfigEditPermissions(
647 $this->setUserPerm( '' );
648 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
649 $this->assertEquals( $resultNone, $result );
651 $this->setUserPerm( 'editmyusercss' );
652 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
653 $this->assertEquals( $resultMyCss, $result );
655 $this->setUserPerm( 'editmyuserjson' );
656 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
657 $this->assertEquals( $resultMyJson, $result );
659 $this->setUserPerm( 'editmyuserjs' );
660 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
661 $this->assertEquals( $resultMyJs, $result );
663 $this->setUserPerm( 'editusercss' );
664 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
665 $this->assertEquals( $resultUserCss, $result );
667 $this->setUserPerm( 'edituserjson' );
668 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
669 $this->assertEquals( $resultUserJson, $result );
671 $this->setUserPerm( 'edituserjs' );
672 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
673 $this->assertEquals( $resultUserJs, $result );
675 $this->setUserPerm( '' );
676 $result = $this->title
->getUserPermissionsErrors( 'patrol', $this->user
);
677 $this->assertEquals( reset( $resultPatrol[0] ), reset( $result[0] ) );
679 $this->setUserPerm( [ 'edituserjs', 'edituserjson', 'editusercss' ] );
680 $result = $this->title
->getUserPermissionsErrors( 'bogus', $this->user
);
681 $this->assertEquals( [ [ 'badaccess-group0' ] ], $result );
685 * @todo This test method should be split up into separate test methods and
688 * This test is failing per T201776.
691 * @covers \MediaWiki\Permissions\PermissionManager::checkPageRestrictions
693 public function testPageRestrictions() {
694 $prefix = MediaWikiServices
::getInstance()->getContentLanguage()->
695 getFormattedNsText( NS_PROJECT
);
697 $this->setTitle( NS_MAIN
);
698 $this->title
->mRestrictionsLoaded
= true;
699 $this->setUserPerm( "edit" );
700 $this->title
->mRestrictions
= [ "bogus" => [ 'bogus', "sysop", "protect", "" ] ];
702 $this->assertEquals( [],
703 $this->title
->getUserPermissionsErrors( 'edit',
706 $this->assertEquals( true,
707 $this->title
->quickUserCan( 'edit', $this->user
) );
708 $this->title
->mRestrictions
= [ "edit" => [ 'bogus', "sysop", "protect", "" ],
709 "bogus" => [ 'bogus', "sysop", "protect", "" ] ];
711 $this->assertEquals( [ [ 'badaccess-group0' ],
712 [ 'protectedpagetext', 'bogus', 'bogus' ],
713 [ 'protectedpagetext', 'editprotected', 'bogus' ],
714 [ 'protectedpagetext', 'protect', 'bogus' ] ],
715 $this->title
->getUserPermissionsErrors( 'bogus',
717 $this->assertEquals( [ [ 'protectedpagetext', 'bogus', 'edit' ],
718 [ 'protectedpagetext', 'editprotected', 'edit' ],
719 [ 'protectedpagetext', 'protect', 'edit' ] ],
720 $this->title
->getUserPermissionsErrors( 'edit',
722 $this->setUserPerm( "" );
723 $this->assertEquals( [ [ 'badaccess-group0' ],
724 [ 'protectedpagetext', 'bogus', 'bogus' ],
725 [ 'protectedpagetext', 'editprotected', 'bogus' ],
726 [ 'protectedpagetext', 'protect', 'bogus' ] ],
727 $this->title
->getUserPermissionsErrors( 'bogus',
729 $this->assertEquals( [ [ 'badaccess-groups', "*, [[$prefix:Users|Users]]", 2 ],
730 [ 'protectedpagetext', 'bogus', 'edit' ],
731 [ 'protectedpagetext', 'editprotected', 'edit' ],
732 [ 'protectedpagetext', 'protect', 'edit' ] ],
733 $this->title
->getUserPermissionsErrors( 'edit',
735 $this->setUserPerm( [ "edit", "editprotected" ] );
736 $this->assertEquals( [ [ 'badaccess-group0' ],
737 [ 'protectedpagetext', 'bogus', 'bogus' ],
738 [ 'protectedpagetext', 'protect', 'bogus' ] ],
739 $this->title
->getUserPermissionsErrors( 'bogus',
741 $this->assertEquals( [
742 [ 'protectedpagetext', 'bogus', 'edit' ],
743 [ 'protectedpagetext', 'protect', 'edit' ] ],
744 $this->title
->getUserPermissionsErrors( 'edit',
747 $this->title
->mCascadeRestriction
= true;
748 $this->setUserPerm( "edit" );
749 $this->assertEquals( false,
750 $this->title
->quickUserCan( 'bogus', $this->user
) );
751 $this->assertEquals( false,
752 $this->title
->quickUserCan( 'edit', $this->user
) );
753 $this->assertEquals( [ [ 'badaccess-group0' ],
754 [ 'protectedpagetext', 'bogus', 'bogus' ],
755 [ 'protectedpagetext', 'editprotected', 'bogus' ],
756 [ 'protectedpagetext', 'protect', 'bogus' ] ],
757 $this->title
->getUserPermissionsErrors( 'bogus',
759 $this->assertEquals( [ [ 'protectedpagetext', 'bogus', 'edit' ],
760 [ 'protectedpagetext', 'editprotected', 'edit' ],
761 [ 'protectedpagetext', 'protect', 'edit' ] ],
762 $this->title
->getUserPermissionsErrors( 'edit',
765 $this->setUserPerm( [ "edit", "editprotected" ] );
766 $this->assertEquals( false,
767 $this->title
->quickUserCan( 'bogus', $this->user
) );
768 $this->assertEquals( false,
769 $this->title
->quickUserCan( 'edit', $this->user
) );
770 $this->assertEquals( [ [ 'badaccess-group0' ],
771 [ 'protectedpagetext', 'bogus', 'bogus' ],
772 [ 'protectedpagetext', 'protect', 'bogus' ],
773 [ 'protectedpagetext', 'protect', 'bogus' ] ],
774 $this->title
->getUserPermissionsErrors( 'bogus',
776 $this->assertEquals( [ [ 'protectedpagetext', 'bogus', 'edit' ],
777 [ 'protectedpagetext', 'protect', 'edit' ],
778 [ 'protectedpagetext', 'protect', 'edit' ] ],
779 $this->title
->getUserPermissionsErrors( 'edit',
784 * @covers \MediaWiki\Permissions\PermissionManager::checkCascadingSourcesRestrictions
786 public function testCascadingSourcesRestrictions() {
787 $this->setTitle( NS_MAIN
, "test page" );
788 $this->setUserPerm( [ "edit", "bogus" ] );
790 $this->title
->mCascadeSources
= [
791 Title
::makeTitle( NS_MAIN
, "Bogus" ),
792 Title
::makeTitle( NS_MAIN
, "UnBogus" )
794 $this->title
->mCascadingRestrictions
= [
795 "bogus" => [ 'bogus', "sysop", "protect", "" ]
798 $this->assertEquals( false,
799 $this->title
->userCan( 'bogus', $this->user
) );
800 $this->assertEquals( [
801 [ "cascadeprotected", 2, "* [[:Bogus]]\n* [[:UnBogus]]\n", 'bogus' ],
802 [ "cascadeprotected", 2, "* [[:Bogus]]\n* [[:UnBogus]]\n", 'bogus' ],
803 [ "cascadeprotected", 2, "* [[:Bogus]]\n* [[:UnBogus]]\n", 'bogus' ] ],
804 $this->title
->getUserPermissionsErrors( 'bogus', $this->user
) );
806 $this->assertEquals( true,
807 $this->title
->userCan( 'edit', $this->user
) );
808 $this->assertEquals( [],
809 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
813 * @todo This test method should be split up into separate test methods and
815 * @covers \MediaWiki\Permissions\PermissionManager::checkActionPermissions
817 public function testActionPermissions() {
818 $this->setUserPerm( [ "createpage" ] );
819 $this->setTitle( NS_MAIN
, "test page" );
820 $this->title
->mTitleProtection
['permission'] = '';
821 $this->title
->mTitleProtection
['user'] = $this->user
->getId();
822 $this->title
->mTitleProtection
['expiry'] = 'infinity';
823 $this->title
->mTitleProtection
['reason'] = 'test';
824 $this->title
->mCascadeRestriction
= false;
826 $this->assertEquals( [ [ 'titleprotected', 'Useruser', 'test' ] ],
827 $this->title
->getUserPermissionsErrors( 'create', $this->user
) );
828 $this->assertEquals( false,
829 $this->title
->userCan( 'create', $this->user
) );
831 $this->title
->mTitleProtection
['permission'] = 'editprotected';
832 $this->setUserPerm( [ 'createpage', 'protect' ] );
833 $this->assertEquals( [ [ 'titleprotected', 'Useruser', 'test' ] ],
834 $this->title
->getUserPermissionsErrors( 'create', $this->user
) );
835 $this->assertEquals( false,
836 $this->title
->userCan( 'create', $this->user
) );
838 $this->setUserPerm( [ 'createpage', 'editprotected' ] );
839 $this->assertEquals( [],
840 $this->title
->getUserPermissionsErrors( 'create', $this->user
) );
841 $this->assertEquals( true,
842 $this->title
->userCan( 'create', $this->user
) );
844 $this->setUserPerm( [ 'createpage' ] );
845 $this->assertEquals( [ [ 'titleprotected', 'Useruser', 'test' ] ],
846 $this->title
->getUserPermissionsErrors( 'create', $this->user
) );
847 $this->assertEquals( false,
848 $this->title
->userCan( 'create', $this->user
) );
850 $this->setTitle( NS_MEDIA
, "test page" );
851 $this->setUserPerm( [ "move" ] );
852 $this->assertEquals( false,
853 $this->title
->userCan( 'move', $this->user
) );
854 $this->assertEquals( [ [ 'immobile-source-namespace', 'Media' ] ],
855 $this->title
->getUserPermissionsErrors( 'move', $this->user
) );
857 $this->setTitle( NS_HELP
, "test page" );
858 $this->assertEquals( [],
859 $this->title
->getUserPermissionsErrors( 'move', $this->user
) );
860 $this->assertEquals( true,
861 $this->title
->userCan( 'move', $this->user
) );
863 $this->title
->mInterwiki
= "no";
864 $this->assertEquals( [ [ 'immobile-source-page' ] ],
865 $this->title
->getUserPermissionsErrors( 'move', $this->user
) );
866 $this->assertEquals( false,
867 $this->title
->userCan( 'move', $this->user
) );
869 $this->setTitle( NS_MEDIA
, "test page" );
870 $this->assertEquals( false,
871 $this->title
->userCan( 'move-target', $this->user
) );
872 $this->assertEquals( [ [ 'immobile-target-namespace', 'Media' ] ],
873 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
875 $this->setTitle( NS_HELP
, "test page" );
876 $this->assertEquals( [],
877 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
878 $this->assertEquals( true,
879 $this->title
->userCan( 'move-target', $this->user
) );
881 $this->title
->mInterwiki
= "no";
882 $this->assertEquals( [ [ 'immobile-target-page' ] ],
883 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
884 $this->assertEquals( false,
885 $this->title
->userCan( 'move-target', $this->user
) );
889 * @covers \MediaWiki\Permissions\PermissionManager::checkUserBlock
891 public function testUserBlock() {
892 $this->setMwGlobals( [
893 'wgEmailConfirmToEdit' => true,
894 'wgEmailAuthentication' => true,
895 'wgBlockDisablesLogin' => false,
897 $this->overrideMwServices();
899 $this->setUserPerm( [ 'createpage', 'edit', 'move', 'rollback', 'patrol', 'upload', 'purge' ] );
900 $this->setTitle( NS_HELP
, "test page" );
902 # $wgEmailConfirmToEdit only applies to 'edit' action
903 $this->assertEquals( [],
904 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
905 $this->assertContains( [ 'confirmedittext' ],
906 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
908 $this->setMwGlobals( 'wgEmailConfirmToEdit', false );
909 $this->overrideMwServices();
911 $this->assertNotContains( [ 'confirmedittext' ],
912 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
914 # $wgEmailConfirmToEdit && !$user->isEmailConfirmed() && $action != 'createaccount'
915 $this->assertEquals( [],
916 $this->title
->getUserPermissionsErrors( 'move-target',
922 $this->user
->mBlockedby
= $this->user
->getId();
923 $this->user
->mBlock
= new Block( [
924 'address' => '127.0.8.1',
925 'by' => $this->user
->getId(),
926 'reason' => 'no reason given',
927 'timestamp' => $prev +
3600,
931 $this->user
->mBlock
->setTimestamp( 0 );
932 $this->assertEquals( [ [ 'autoblockedtext',
933 '[[User:Useruser|Useruser]]', 'no reason given', '127.0.0.1',
934 'Useruser', null, 'infinite', '127.0.8.1',
935 $wgLang->timeanddate( wfTimestamp( TS_MW
, $prev ), true ) ] ],
936 $this->title
->getUserPermissionsErrors( 'move-target',
939 $this->assertEquals( false, $this->title
->userCan( 'move-target', $this->user
) );
940 // quickUserCan should ignore user blocks
941 $this->assertEquals( true, $this->title
->quickUserCan( 'move-target', $this->user
) );
943 global $wgLocalTZoffset;
944 $wgLocalTZoffset = -60;
945 $this->user
->mBlockedby
= $this->user
->getName();
946 $this->user
->mBlock
= new Block( [
947 'address' => '127.0.8.1',
948 'by' => $this->user
->getId(),
949 'reason' => 'no reason given',
954 $this->assertEquals( [ [ 'blockedtext',
955 '[[User:Useruser|Useruser]]', 'no reason given', '127.0.0.1',
956 'Useruser', null, '23:00, 31 December 1969', '127.0.8.1',
957 $wgLang->timeanddate( wfTimestamp( TS_MW
, $now ), true ) ] ],
958 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
959 # $action != 'read' && $action != 'createaccount' && $user->isBlockedFrom( $this )
960 # $user->blockedFor() == ''
961 # $user->mBlock->mExpiry == 'infinity'
963 $this->user
->mBlockedby
= $this->user
->getName();
964 $this->user
->mBlock
= new SystemBlock( [
965 'address' => '127.0.8.1',
966 'by' => $this->user
->getId(),
967 'reason' => 'no reason given',
969 'systemBlock' => 'test',
972 $errors = [ [ 'systemblockedtext',
973 '[[User:Useruser|Useruser]]', 'no reason given', '127.0.0.1',
974 'Useruser', 'test', 'infinite', '127.0.8.1',
975 $wgLang->timeanddate( wfTimestamp( TS_MW
, $now ), true ) ] ];
977 $this->assertEquals( $errors,
978 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
979 $this->assertEquals( $errors,
980 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
981 $this->assertEquals( $errors,
982 $this->title
->getUserPermissionsErrors( 'rollback', $this->user
) );
983 $this->assertEquals( $errors,
984 $this->title
->getUserPermissionsErrors( 'patrol', $this->user
) );
985 $this->assertEquals( $errors,
986 $this->title
->getUserPermissionsErrors( 'upload', $this->user
) );
987 $this->assertEquals( [],
988 $this->title
->getUserPermissionsErrors( 'purge', $this->user
) );
990 // partial block message test
991 $this->user
->mBlockedby
= $this->user
->getName();
992 $this->user
->mBlock
= new Block( [
993 'address' => '127.0.8.1',
994 'by' => $this->user
->getId(),
995 'reason' => 'no reason given',
1001 $this->assertEquals( [],
1002 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
1003 $this->assertEquals( [],
1004 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
1005 $this->assertEquals( [],
1006 $this->title
->getUserPermissionsErrors( 'rollback', $this->user
) );
1007 $this->assertEquals( [],
1008 $this->title
->getUserPermissionsErrors( 'patrol', $this->user
) );
1009 $this->assertEquals( [],
1010 $this->title
->getUserPermissionsErrors( 'upload', $this->user
) );
1011 $this->assertEquals( [],
1012 $this->title
->getUserPermissionsErrors( 'purge', $this->user
) );
1014 $this->user
->mBlock
->setRestrictions( [
1015 ( new PageRestriction( 0, $this->title
->getArticleID() ) )->setTitle( $this->title
),
1018 $errors = [ [ 'blockedtext-partial',
1019 '[[User:Useruser|Useruser]]', 'no reason given', '127.0.0.1',
1020 'Useruser', null, '23:00, 31 December 1969', '127.0.8.1',
1021 $wgLang->timeanddate( wfTimestamp( TS_MW
, $now ), true ) ] ];
1023 $this->assertEquals( $errors,
1024 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
1025 $this->assertEquals( $errors,
1026 $this->title
->getUserPermissionsErrors( 'move-target', $this->user
) );
1027 $this->assertEquals( $errors,
1028 $this->title
->getUserPermissionsErrors( 'rollback', $this->user
) );
1029 $this->assertEquals( $errors,
1030 $this->title
->getUserPermissionsErrors( 'patrol', $this->user
) );
1031 $this->assertEquals( [],
1032 $this->title
->getUserPermissionsErrors( 'upload', $this->user
) );
1033 $this->assertEquals( [],
1034 $this->title
->getUserPermissionsErrors( 'purge', $this->user
) );
1037 $this->user
->mBlockedby
= null;
1038 $this->user
->mBlock
= null;
1040 $this->assertEquals( [],
1041 $this->title
->getUserPermissionsErrors( 'edit', $this->user
) );
1045 * @covers \MediaWiki\Permissions\PermissionManager::checkUserBlock
1047 * Tests to determine that the passed in permission does not get mixed up with
1048 * an action of the same name.
1050 public function testUserBlockAction() {
1053 $tester = $this->getMockBuilder( Action
::class )
1054 ->disableOriginalConstructor()
1056 $tester->method( 'getName' )
1057 ->willReturn( 'tester' );
1058 $tester->method( 'getRestriction' )
1059 ->willReturn( 'test' );
1060 $tester->method( 'requiresUnblock' )
1061 ->willReturn( false );
1063 $this->setMwGlobals( [
1065 'tester' => $tester,
1067 'wgGroupPermissions' => [
1075 $this->user
->mBlockedby
= $this->user
->getName();
1076 $this->user
->mBlock
= new Block( [
1077 'address' => '127.0.8.1',
1078 'by' => $this->user
->getId(),
1079 'reason' => 'no reason given',
1080 'timestamp' => $now,
1082 'expiry' => 'infinity',
1085 $errors = [ [ 'blockedtext',
1086 '[[User:Useruser|Useruser]]', 'no reason given', '127.0.0.1',
1087 'Useruser', null, 'infinite', '127.0.8.1',
1088 $wgLang->timeanddate( wfTimestamp( TS_MW
, $now ), true ) ] ];
1090 $this->assertEquals( $errors,
1091 $this->title
->getUserPermissionsErrors( 'tester', $this->user
) );