mirror of
https://github.com/projectsend/projectsend.git
synced 2026-09-17 09:05:08 +00:00
6e47d76ba6
Client file sharing, rebuilt from the ground up: a private area per client, resumable uploads, folders, groups and categories, sharing with expiry dates and download limits, comments, file versions, an activity log, a REST API, and sixteen languages. This repository begins here. ProjectSend 2 was developed privately, and that development history is not published — the previous generation remains available, with its own history, at projectsend/legacy. Free software under the GNU General Public License v2, or (at your option) any later version.
113 lines
3.4 KiB
PHP
113 lines
3.4 KiB
PHP
<?php
|
|
|
|
namespace Tests\Feature\Auth;
|
|
|
|
use App\Models\User;
|
|
use App\Modules\Identity\Notifications\ResetPasswordNotification;
|
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
|
use Illuminate\Support\Facades\Notification;
|
|
use Tests\TestCase;
|
|
|
|
class PasswordResetTest extends TestCase
|
|
{
|
|
use RefreshDatabase;
|
|
|
|
protected function setUp(): void
|
|
{
|
|
parent::setUp();
|
|
|
|
// The app redirects everything to /setup until a staff user exists.
|
|
User::factory()->create();
|
|
}
|
|
|
|
public function test_reset_password_link_screen_can_be_rendered()
|
|
{
|
|
$response = $this->get('/forgot-password');
|
|
|
|
$response->assertStatus(200);
|
|
}
|
|
|
|
public function test_reset_password_link_can_be_requested()
|
|
{
|
|
Notification::fake();
|
|
|
|
$user = User::factory()->create();
|
|
|
|
$this->post('/forgot-password', ['email' => $user->email]);
|
|
|
|
Notification::assertSentTo($user, ResetPasswordNotification::class);
|
|
}
|
|
|
|
public function test_reset_password_screen_can_be_rendered()
|
|
{
|
|
Notification::fake();
|
|
|
|
$user = User::factory()->create();
|
|
|
|
$this->post('/forgot-password', ['email' => $user->email]);
|
|
|
|
Notification::assertSentTo($user, ResetPasswordNotification::class, function ($notification) {
|
|
$response = $this->get('/reset-password/'.$notification->token);
|
|
|
|
$response->assertStatus(200);
|
|
|
|
return true;
|
|
});
|
|
}
|
|
|
|
public function test_password_can_be_reset_with_valid_token()
|
|
{
|
|
Notification::fake();
|
|
|
|
$user = User::factory()->create();
|
|
|
|
$this->post('/forgot-password', ['email' => $user->email]);
|
|
|
|
Notification::assertSentTo($user, ResetPasswordNotification::class, function ($notification) use ($user) {
|
|
$response = $this->post('/reset-password', [
|
|
'token' => $notification->token,
|
|
'email' => $user->email,
|
|
'password' => 'new-password-1234',
|
|
'password_confirmation' => 'new-password-1234',
|
|
]);
|
|
|
|
$response
|
|
->assertSessionHasNoErrors()
|
|
->assertRedirect(route('login'));
|
|
|
|
return true;
|
|
});
|
|
}
|
|
|
|
/**
|
|
* That this endpoint enforces the policy at all — the shipped default
|
|
* being a 12-character minimum.
|
|
*
|
|
* This assertion used to be described as covering the policy itself,
|
|
* on the grounds that Password::defaults() is central and every field
|
|
* leans on it. That stopped being true when the minimum became
|
|
* configurable: PasswordPolicy now decides it, and whether a *changed*
|
|
* minimum reaches each surface is proven in
|
|
* tests/Feature/Identity/PasswordPolicyTest.php.
|
|
*/
|
|
public function test_a_password_below_the_minimum_length_is_rejected()
|
|
{
|
|
Notification::fake();
|
|
|
|
$user = User::factory()->create();
|
|
|
|
$this->post('/forgot-password', ['email' => $user->email]);
|
|
|
|
Notification::assertSentTo($user, ResetPasswordNotification::class, function ($notification) use ($user) {
|
|
$this->post('/reset-password', [
|
|
'token' => $notification->token,
|
|
'email' => $user->email,
|
|
'password' => 'short-11ch',
|
|
'password_confirmation' => 'short-11ch',
|
|
])->assertSessionHasErrors('password');
|
|
|
|
return true;
|
|
});
|
|
}
|
|
}
|