6 class WebRequestTest
extends MediaWikiTestCase
{
9 protected function setUp() {
12 $this->oldServer
= $_SERVER;
15 protected function tearDown() {
16 $_SERVER = $this->oldServer
;
22 * @dataProvider provideDetectServer
23 * @covers WebRequest::detectServer
24 * @covers WebRequest::detectProtocol
26 public function testDetectServer( $expected, $input, $description ) {
27 $this->setMwGlobals( 'wgAssumeProxiesUseDefaultProtocolPorts', true );
29 $this->setServerVars( $input );
30 $result = WebRequest
::detectServer();
31 $this->assertEquals( $expected, $result, $description );
34 public static function provideDetectServer() {
49 'Host header with secure'
57 'Default SERVER_PORT',
71 'HTTP_X_FORWARDED_PROTO' => 'https',
80 'SERVER_PORT' => '81',
81 'HTTP_X_FORWARDED_PROTO' => 'https',
98 'Host server name precedence'
103 'HTTP_HOST' => '[::1]',
104 'SERVER_NAME' => '::1',
105 'SERVER_PORT' => '81',
112 'SERVER_NAME' => '[2001'
114 'Kind of like lighttpd per commit message in MW r83847',
117 'http://[2a01:e35:2eb4:1::2]:777',
119 'SERVER_NAME' => '[2a01:e35:2eb4:1::2]:777'
121 'Possible lighttpd environment per bug 14977 comment 13',
127 * @param array $data Request data
128 * @param array $config
129 * - float 'requestTime': Mock value for `$_SERVER['REQUEST_TIME_FLOAT']`.
132 protected function mockWebRequest( array $data = [], array $config = [] ) {
133 // Cannot use PHPUnit getMockBuilder() as it does not support
134 // overriding protected properties afterwards
135 $reflection = new ReflectionClass( WebRequest
::class );
136 $req = $reflection->newInstanceWithoutConstructor();
138 $prop = $reflection->getProperty( 'data' );
139 $prop->setAccessible( true );
140 $prop->setValue( $req, $data );
142 if ( isset( $config['requestTime'] ) ) {
143 $prop = $reflection->getProperty( 'requestTime' );
144 $prop->setAccessible( true );
145 $prop->setValue( $req, $config['requestTime'] );
152 * @covers WebRequest::getElapsedTime
154 public function testGetElapsedTime() {
155 $now = microtime( true ) - 10.0;
156 $req = $this->mockWebRequest( [], [ 'requestTime' => $now ] );
157 $this->assertGreaterThanOrEqual( 10.0, $req->getElapsedTime() );
158 // Catch common errors, but don't fail on slow hardware or VMs (T199764).
159 $this->assertEquals( 10.0, $req->getElapsedTime(), '', 60.0 );
163 * @covers WebRequest::getVal
164 * @covers WebRequest::getGPCVal
165 * @covers WebRequest::normalizeUnicode
167 public function testGetValNormal() {
168 // Assert that WebRequest normalises GPC data using UtfNormal\Validator
169 $input = "a \x00 null";
170 $normal = "a \xef\xbf\xbd null";
171 $req = $this->mockWebRequest( [ 'x' => $input, 'y' => [ $input, $input ] ] );
172 $this->assertSame( $normal, $req->getVal( 'x' ) );
173 $this->assertNotSame( $input, $req->getVal( 'x' ) );
174 $this->assertSame( [ $normal, $normal ], $req->getArray( 'y' ) );
178 * @covers WebRequest::getVal
179 * @covers WebRequest::getGPCVal
181 public function testGetVal() {
182 $req = $this->mockWebRequest( [ 'x' => 'Value', 'y' => [ 'a' ], 'crlf' => "A\r\nb" ] );
183 $this->assertSame( 'Value', $req->getVal( 'x' ), 'Simple value' );
184 $this->assertSame( null, $req->getVal( 'z' ), 'Not found' );
185 $this->assertSame( null, $req->getVal( 'y' ), 'Array is ignored' );
186 $this->assertSame( "A\r\nb", $req->getVal( 'crlf' ), 'CRLF' );
190 * @covers WebRequest::getRawVal
192 public function testGetRawVal() {
193 $req = $this->mockWebRequest( [
198 $this->assertSame( 'Value', $req->getRawVal( 'x' ) );
199 $this->assertSame( null, $req->getRawVal( 'z' ), 'Not found' );
200 $this->assertSame( null, $req->getRawVal( 'y' ), 'Array is ignored' );
201 $this->assertSame( "A\r\nb", $req->getRawVal( 'crlf' ), 'CRLF' );
205 * @covers WebRequest::getArray
207 public function testGetArray() {
208 $req = $this->mockWebRequest( [ 'x' => 'Value', 'y' => [ 'a', 'b' ] ] );
209 $this->assertSame( [ 'Value' ], $req->getArray( 'x' ), 'Value becomes array' );
210 $this->assertSame( null, $req->getArray( 'z' ), 'Not found' );
211 $this->assertSame( [ 'a', 'b' ], $req->getArray( 'y' ) );
215 * @covers WebRequest::getIntArray
217 public function testGetIntArray() {
218 $req = $this->mockWebRequest( [ 'x' => [ 'Value' ], 'y' => [ '0', '4.2', '-2' ] ] );
219 $this->assertSame( [ 0 ], $req->getIntArray( 'x' ), 'Text becomes 0' );
220 $this->assertSame( null, $req->getIntArray( 'z' ), 'Not found' );
221 $this->assertSame( [ 0, 4, -2 ], $req->getIntArray( 'y' ) );
225 * @covers WebRequest::getInt
227 public function testGetInt() {
228 $req = $this->mockWebRequest( [
235 $this->assertSame( 0, $req->getInt( 'x' ), 'Text' );
236 $this->assertSame( 0, $req->getInt( 'y' ), 'Array' );
237 $this->assertSame( 0, $req->getInt( 'z' ), 'Not found' );
238 $this->assertSame( 0, $req->getInt( 'zero' ) );
239 $this->assertSame( 4, $req->getInt( 'answer' ) );
240 $this->assertSame( -2, $req->getInt( 'neg' ) );
244 * @covers WebRequest::getIntOrNull
246 public function testGetIntOrNull() {
247 $req = $this->mockWebRequest( [
254 $this->assertSame( null, $req->getIntOrNull( 'x' ), 'Text' );
255 $this->assertSame( null, $req->getIntOrNull( 'y' ), 'Array' );
256 $this->assertSame( null, $req->getIntOrNull( 'z' ), 'Not found' );
257 $this->assertSame( 0, $req->getIntOrNull( 'zero' ) );
258 $this->assertSame( 4, $req->getIntOrNull( 'answer' ) );
259 $this->assertSame( -2, $req->getIntOrNull( 'neg' ) );
263 * @covers WebRequest::getFloat
265 public function testGetFloat() {
266 $req = $this->mockWebRequest( [
273 $this->assertSame( 0.0, $req->getFloat( 'x' ), 'Text' );
274 $this->assertSame( 0.0, $req->getFloat( 'y' ), 'Array' );
275 $this->assertSame( 0.0, $req->getFloat( 'z' ), 'Not found' );
276 $this->assertSame( 0.0, $req->getFloat( 'zero' ) );
277 $this->assertSame( 4.2, $req->getFloat( 'answer' ) );
278 $this->assertSame( -2.0, $req->getFloat( 'neg' ) );
282 * @covers WebRequest::getBool
284 public function testGetBool() {
285 $req = $this->mockWebRequest( [
292 $this->assertSame( true, $req->getBool( 'x' ), 'Text' );
293 $this->assertSame( false, $req->getBool( 'y' ), 'Array' );
294 $this->assertSame( false, $req->getBool( 'z' ), 'Not found' );
295 $this->assertSame( false, $req->getBool( 'zero' ) );
296 $this->assertSame( true, $req->getBool( 'f' ) );
297 $this->assertSame( true, $req->getBool( 't' ) );
300 public static function provideFuzzyBool() {
303 [ '', false, '(empty string)' ],
316 * @dataProvider provideFuzzyBool
317 * @covers WebRequest::getFuzzyBool
319 public function testGetFuzzyBool( $value, $expected, $message = null ) {
320 $req = $this->mockWebRequest( [ 'x' => $value ] );
321 $this->assertSame( $expected, $req->getFuzzyBool( 'x' ), $message ?
: "Value: '$value'" );
325 * @covers WebRequest::getFuzzyBool
327 public function testGetFuzzyBoolDefault() {
328 $req = $this->mockWebRequest();
329 $this->assertSame( false, $req->getFuzzyBool( 'z' ), 'Not found' );
333 * @covers WebRequest::getCheck
335 public function testGetCheck() {
336 $req = $this->mockWebRequest( [ 'x' => 'Value', 'zero' => '0' ] );
337 $this->assertSame( false, $req->getCheck( 'z' ), 'Not found' );
338 $this->assertSame( true, $req->getCheck( 'x' ), 'Text' );
339 $this->assertSame( true, $req->getCheck( 'zero' ) );
343 * @covers WebRequest::getText
345 public function testGetText() {
346 // Avoid FauxRequest (overrides getText)
347 $req = $this->mockWebRequest( [ 'crlf' => "Va\r\nlue" ] );
348 $this->assertSame( "Va\nlue", $req->getText( 'crlf' ), 'CR stripped' );
352 * @covers WebRequest::getValues
354 public function testGetValues() {
355 $values = [ 'x' => 'Value', 'y' => '' ];
356 // Avoid FauxRequest (overrides getValues)
357 $req = $this->mockWebRequest( $values );
358 $this->assertSame( $values, $req->getValues() );
359 $this->assertSame( [ 'x' => 'Value' ], $req->getValues( 'x' ), 'Specific keys' );
363 * @covers WebRequest::getValueNames
365 public function testGetValueNames() {
366 $req = $this->mockWebRequest( [ 'x' => 'Value', 'y' => '' ] );
367 $this->assertSame( [ 'x', 'y' ], $req->getValueNames() );
368 $this->assertSame( [ 'x' ], $req->getValueNames( [ 'y' ] ), 'Exclude keys' );
372 * @dataProvider provideGetIP
373 * @covers WebRequest::getIP
375 public function testGetIP( $expected, $input, $squid, $xffList, $private, $description ) {
376 $this->setServerVars( $input );
377 $this->setMwGlobals( [
378 'wgUsePrivateIPs' => $private,
380 'IsTrustedProxy' => [
381 function ( &$ip, &$trusted ) use ( $xffList ) {
382 $trusted = $trusted ||
in_array( $ip, $xffList );
389 $this->setService( 'ProxyLookup', new ProxyLookup( [], $squid ) );
391 $request = new WebRequest();
392 $result = $request->getIP();
393 $this->assertEquals( $expected, $result, $description );
396 public static function provideGetIP() {
401 'REMOTE_ADDR' => '127.0.0.1'
411 'REMOTE_ADDR' => '::1'
421 'REMOTE_ADDR' => 'abcd:0001:002:03:4:555:6666:7777',
422 'HTTP_X_FORWARDED_FOR' => '12.0.0.1, abcd:0001:002:03:4:555:6666:7777',
424 [ 'ABCD:1:2:3:4:555:6666:7777' ],
432 'REMOTE_ADDR' => '12.0.0.1',
433 'HTTP_X_FORWARDED_FOR' => '12.0.0.3, 12.0.0.2'
435 [ '12.0.0.1', '12.0.0.2' ],
438 'With X-Forwaded-For'
443 'REMOTE_ADDR' => '12.0.0.1',
444 'HTTP_X_FORWARDED_FOR' => '12.0.0.3, 12.0.0.2'
449 'With X-Forwaded-For and disallowed server'
454 'REMOTE_ADDR' => '12.0.0.1',
455 'HTTP_X_FORWARDED_FOR' => '12.0.0.3, 12.0.0.2'
460 'With multiple X-Forwaded-For and only one allowed server'
465 'REMOTE_ADDR' => '12.0.0.2',
466 'HTTP_X_FORWARDED_FOR' => '10.0.0.4, 10.0.0.3, 12.0.0.2'
468 [ '12.0.0.1', '12.0.0.2' ],
471 'With X-Forwaded-For and private IP (from cache proxy)'
476 'REMOTE_ADDR' => '12.0.0.2',
477 'HTTP_X_FORWARDED_FOR' => '10.0.0.4, 10.0.0.3, 12.0.0.2'
479 [ '12.0.0.1', '12.0.0.2', '10.0.0.3' ],
482 'With X-Forwaded-For and private IP (allowed)'
487 'REMOTE_ADDR' => '12.0.0.2',
488 'HTTP_X_FORWARDED_FOR' => '10.0.0.4, 10.0.0.3, 12.0.0.2'
490 [ '12.0.0.1', '12.0.0.2' ],
493 'With X-Forwaded-For and private IP (allowed)'
498 'REMOTE_ADDR' => '12.0.0.2',
499 'HTTP_X_FORWARDED_FOR' => '10.0.0.4, 10.0.0.3, 12.0.0.2'
501 [ '12.0.0.1', '12.0.0.2' ],
504 'With X-Forwaded-For and private IP (disallowed)'
509 'REMOTE_ADDR' => '12.0.0.1',
510 'HTTP_X_FORWARDED_FOR' => '12.0.0.3, 12.0.0.2'
513 [ '12.0.0.1', '12.0.0.2' ],
515 'With X-Forwaded-For'
520 'REMOTE_ADDR' => '12.0.0.1',
521 'HTTP_X_FORWARDED_FOR' => '12.0.0.3, 12.0.0.2'
526 'With multiple X-Forwaded-For and only one allowed server'
531 'REMOTE_ADDR' => '12.0.0.2',
532 'HTTP_X_FORWARDED_FOR' => '10.0.0.3, 12.0.0.2'
537 'With X-Forwaded-For and private IP and hook (disallowed)'
542 'REMOTE_ADDR' => 'abcd:0001:002:03:4:555:6666:7777',
543 'HTTP_X_FORWARDED_FOR' => '12.0.0.1, abcd:0001:002:03:4:555:6666:7777',
545 [ 'ABCD:1:2:3::/64' ],
553 'REMOTE_ADDR' => '12.0.0.1',
554 'HTTP_X_FORWARDED_FOR' => '12.0.0.3, 12.0.0.2'
565 * @expectedException MWException
566 * @covers WebRequest::getIP
568 public function testGetIpLackOfRemoteAddrThrowAnException() {
569 // ensure that local install state doesn't interfere with test
570 $this->setMwGlobals( [
571 'wgSquidServersNoPurge' => [],
572 'wgSquidServers' => [],
573 'wgUsePrivateIPs' => false,
576 $this->setService( 'ProxyLookup', new ProxyLookup( [], [] ) );
578 $request = new WebRequest();
579 # Next call throw an exception about lacking an IP
583 public static function provideLanguageData() {
585 [ '', [], 'Empty Accept-Language header' ],
586 [ 'en', [ 'en' => 1 ], 'One language' ],
587 [ 'en, ar', [ 'en' => 1, 'ar' => 1 ], 'Two languages listed in appearance order.' ],
590 [ 'zh-cn' => 1, 'zh-tw' => 1 ],
591 'Two equally prefered languages, listed in appearance order per rfc3282. Checks c9119'
595 [ 'es' => 1, 'en' => '0.5' ],
596 'Spanish as first language and English and second'
598 [ 'en; q=0.5, es', [ 'es' => 1, 'en' => '0.5' ], 'Less prefered language first' ],
599 [ 'fr, en; q=0.5, es', [ 'fr' => 1, 'es' => 1, 'en' => '0.5' ], 'Three languages' ],
600 [ 'en; q=0.5, es', [ 'es' => 1, 'en' => '0.5' ], 'Two languages' ],
601 [ 'en, zh;q=0', [ 'en' => 1 ], "It's Chinese to me" ],
603 'es; q=1, pt;q=0.7, it; q=0.6, de; q=0.1, ru;q=0',
604 [ 'es' => '1', 'pt' => '0.7', 'it' => '0.6', 'de' => '0.1' ],
605 'Preference for Romance languages'
609 [ 'en-gb' => 1, 'en-us' => '1' ],
610 'Two equally prefered English variants'
612 [ '_', [], 'Invalid input' ],
617 * @dataProvider provideLanguageData
618 * @covers WebRequest::getAcceptLang
620 public function testAcceptLang( $acceptLanguageHeader, $expectedLanguages, $description ) {
621 $this->setServerVars( [ 'HTTP_ACCEPT_LANGUAGE' => $acceptLanguageHeader ] );
622 $request = new WebRequest();
623 $this->assertSame( $request->getAcceptLang(), $expectedLanguages, $description );
626 protected function setServerVars( $vars ) {
627 // Don't remove vars which should be available in all SAPI.
628 if ( !isset( $vars['REQUEST_TIME_FLOAT'] ) ) {
629 $vars['REQUEST_TIME_FLOAT'] = $_SERVER['REQUEST_TIME_FLOAT'];
631 if ( !isset( $vars['REQUEST_TIME'] ) ) {
632 $vars['REQUEST_TIME'] = $_SERVER['REQUEST_TIME'];