diff --git a/app/controllers/api/account.php b/app/controllers/api/account.php index d813f5ca82..e97576ee5d 100644 --- a/app/controllers/api/account.php +++ b/app/controllers/api/account.php @@ -119,10 +119,6 @@ App::post('/v1/account') ->setParam('resource', 'users/'.$user->getId()) ; - $user - ->setAttribute('roles', Authorization::getRoles()) - ; - $response ->setStatusCode(Response::STATUS_CODE_CREATED) ->dynamic($user, Response::MODEL_USER) @@ -628,8 +624,6 @@ App::get('/v1/account') /** @var Appwrite\Utopia\Response $response */ /** @var Appwrite\Database\Document $user */ - $user->setAttribute('roles', Authorization::getRoles()); - $response->dynamic($user, Response::MODEL_USER); }, ['response', 'user']); @@ -820,8 +814,6 @@ App::patch('/v1/account/name') throw new Exception('Failed saving user to DB', 500); } - $user->setAttribute('roles', Authorization::getRoles()); - $audits ->setParam('userId', $user->getId()) ->setParam('event', 'account.update.name') @@ -863,8 +855,6 @@ App::patch('/v1/account/password') throw new Exception('Failed saving user to DB', 500); } - $user->setAttribute('roles', Authorization::getRoles()); - $audits ->setParam('userId', $user->getId()) ->setParam('event', 'account.update.password') @@ -920,8 +910,6 @@ App::patch('/v1/account/email') if (false === $user) { throw new Exception('Failed saving user to DB', 500); } - - $user->setAttribute('roles', Authorization::getRoles()); $audits ->setParam('userId', $user->getId()) @@ -964,9 +952,7 @@ App::patch('/v1/account/prefs') ->setParam('resource', 'users/'.$user->getId()) ; - $prefs = $user->getAttribute('prefs', new \stdClass); - - $response->dynamic(new Document($prefs), Response::MODEL_ANY); + $response->dynamic($user, Response::MODEL_USER); }, ['response', 'user', 'projectDB', 'audits']); App::delete('/v1/account') @@ -1013,8 +999,6 @@ App::delete('/v1/account') ->setParam('data', $user->getArrayCopy()) ; - $user->setAttribute('roles', Authorization::getRoles()); - $webhooks ->setParam('payload', $response->output($user, Response::MODEL_USER)) ; diff --git a/src/Appwrite/Utopia/Response/Model/User.php b/src/Appwrite/Utopia/Response/Model/User.php index c89956b3e2..79c34db5ef 100644 --- a/src/Appwrite/Utopia/Response/Model/User.php +++ b/src/Appwrite/Utopia/Response/Model/User.php @@ -47,13 +47,6 @@ class User extends Model 'default' => new \stdClass, 'example' => ['theme' => 'pink', 'timezone' => 'UTC'], ]) - ->addRule('roles', [ - 'type' => self::TYPE_STRING, - 'description' => 'User list of roles', - 'default' => [], - 'example' => '*', - 'array' => true, - ]) ; } diff --git a/tests/e2e/Services/Account/AccountBase.php b/tests/e2e/Services/Account/AccountBase.php index c061986d6a..ce93ead1ca 100644 --- a/tests/e2e/Services/Account/AccountBase.php +++ b/tests/e2e/Services/Account/AccountBase.php @@ -152,10 +152,6 @@ trait AccountBase $this->assertIsNumeric($response['body']['registration']); $this->assertEquals($response['body']['email'], $email); $this->assertEquals($response['body']['name'], $name); - $this->assertContains('*', $response['body']['roles']); - $this->assertContains('user:'.$response['body']['$id'], $response['body']['roles']); - $this->assertContains('role:1', $response['body']['roles']); - $this->assertCount(3, $response['body']['roles']); /** * Test for FAILURE @@ -573,8 +569,8 @@ trait AccountBase $this->assertIsArray($response['body']); $this->assertNotEmpty($response['body']); $this->assertNotEmpty($response['body']); - $this->assertEquals('prefValue1', $response['body']['prefKey1']); - $this->assertEquals('prefValue2', $response['body']['prefKey2']); + $this->assertEquals('prefValue1', $response['body']['prefs']['prefKey1']); + $this->assertEquals('prefValue2', $response['body']['prefs']['prefKey2']); /** * Test for FAILURE diff --git a/tests/e2e/Services/Users/UsersBase.php b/tests/e2e/Services/Users/UsersBase.php index 747fd53916..14805273e6 100644 --- a/tests/e2e/Services/Users/UsersBase.php +++ b/tests/e2e/Services/Users/UsersBase.php @@ -25,7 +25,6 @@ trait UsersBase $this->assertEquals($user['body']['email'], 'users.service@example.com'); $this->assertEquals($user['body']['status'], 0); $this->assertGreaterThan(0, $user['body']['registration']); - $this->assertIsArray($user['body']['roles']); return ['userId' => $user['body']['$id']]; } @@ -48,7 +47,6 @@ trait UsersBase $this->assertEquals($user['body']['email'], 'users.service@example.com'); $this->assertEquals($user['body']['status'], 0); $this->assertGreaterThan(0, $user['body']['registration']); - $this->assertIsArray($user['body']['roles']); $sessions = $this->client->call(Client::METHOD_GET, '/users/' . $data['userId'] . '/sessions', array_merge([ 'content-type' => 'application/json', diff --git a/tests/e2e/Services/Webhooks/WebhooksBase.php b/tests/e2e/Services/Webhooks/WebhooksBase.php index 99a8ff01d0..a4f0c9e5dc 100644 --- a/tests/e2e/Services/Webhooks/WebhooksBase.php +++ b/tests/e2e/Services/Webhooks/WebhooksBase.php @@ -45,7 +45,6 @@ trait WebhooksBase $this->assertEquals($webhook['data']['email'], $email); $this->assertEquals($webhook['data']['emailVerification'], false); $this->assertEquals($webhook['data']['prefs'], []); - $this->assertEquals($webhook['data']['roles'], ['*', 'user:'.$id, 'role:1']); return [ 'id' => $id, @@ -306,7 +305,6 @@ trait WebhooksBase $this->assertEquals($webhook['data']['email'], $email); $this->assertEquals($webhook['data']['emailVerification'], false); $this->assertEquals($webhook['data']['prefs'], []); - $this->assertEquals($webhook['data']['roles'], ['*', 'user:'.$id, 'role:1']); return $data; } @@ -348,7 +346,6 @@ trait WebhooksBase $this->assertEquals($webhook['data']['email'], $email); $this->assertEquals($webhook['data']['emailVerification'], false); $this->assertEquals($webhook['data']['prefs'], []); - $this->assertEquals($webhook['data']['roles'], ['*', 'user:'.$id, 'role:1']); $data['password'] = 'new-password'; @@ -392,13 +389,57 @@ trait WebhooksBase $this->assertEquals($webhook['data']['email'], $newEmail); $this->assertEquals($webhook['data']['emailVerification'], false); $this->assertEquals($webhook['data']['prefs'], []); - $this->assertEquals($webhook['data']['roles'], ['*', 'user:'.$id, 'role:1']); $data['email'] = $newEmail; return $data; } + /** + * @depends testUpdateAccountEmail + */ + public function testUpdateAccountPrefs($data): array + { + $id = $data['id'] ?? ''; + $email = $data['email'] ?? ''; + $session = $data['session'] ?? ''; + + $account = $this->client->call(Client::METHOD_PATCH, '/account/prefs', array_merge([ + 'origin' => 'http://localhost', + 'content-type' => 'application/json', + 'x-appwrite-project' => $this->getProject()['$id'], + 'cookie' => 'a_session_'.$this->getProject()['$id'].'=' . $session, + ]), [ + 'prefs' => [ + 'prefKey1' => 'prefValue1', + 'prefKey2' => 'prefValue2', + ] + ]); + + $this->assertEquals($account['headers']['status-code'], 200); + $this->assertIsArray($account['body']); + + $webhook = $this->getLastRequest(); + + $this->assertEquals($webhook['method'], 'POST'); + $this->assertEquals($webhook['headers']['Content-Type'], 'application/json'); + $this->assertEquals($webhook['headers']['User-Agent'], 'Appwrite-Server vdev. Please report abuse at security@appwrite.io'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Event'], 'account.update.prefs'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Signature'], 'not-yet-implemented'); + $this->assertNotEmpty($webhook['data']['$id']); + $this->assertEquals($webhook['data']['name'], 'New Name'); + $this->assertIsInt($webhook['data']['registration']); + $this->assertEquals($webhook['data']['status'], 0); + $this->assertEquals($webhook['data']['email'], $email); + $this->assertEquals($webhook['data']['emailVerification'], false); + $this->assertEquals($webhook['data']['prefs'], [ + 'prefKey1' => 'prefValue1', + 'prefKey2' => 'prefValue2', + ]); + + return $data; + } + public function testCreateFile():array { /** diff --git a/tests/e2e/Services/Webhooks/WebhooksCustomServerTest.php b/tests/e2e/Services/Webhooks/WebhooksCustomServerTest.php index 68b36e9d14..91446d175c 100644 --- a/tests/e2e/Services/Webhooks/WebhooksCustomServerTest.php +++ b/tests/e2e/Services/Webhooks/WebhooksCustomServerTest.php @@ -2,6 +2,7 @@ namespace Tests\E2E\Services\Webhooks; +use Tests\E2E\Client; use Tests\E2E\Scopes\ProjectCustom; use Tests\E2E\Scopes\Scope; use Tests\E2E\Scopes\SideServer; @@ -11,4 +12,117 @@ class WebhooksCustomServerTest extends Scope use WebhooksBase; use ProjectCustom; use SideServer; + + public function testCreateUser():array + { + $email = uniqid().'user@localhost.test'; + $password = 'password'; + $name = 'User Name'; + + /** + * Test for SUCCESS + */ + $user = $this->client->call(Client::METHOD_POST, '/users', array_merge([ + 'content-type' => 'application/json', + 'x-appwrite-project' => $this->getProject()['$id'], + ], $this->getHeaders()), [ + 'email' => $email, + 'password' => $password, + 'name' => $name, + ]); + + $this->assertEquals($user['headers']['status-code'], 201); + $this->assertNotEmpty($user['body']['$id']); + + $id = $user['body']['$id']; + + $webhook = $this->getLastRequest(); + + $this->assertEquals($webhook['method'], 'POST'); + $this->assertEquals($webhook['headers']['Content-Type'], 'application/json'); + $this->assertEquals($webhook['headers']['User-Agent'], 'Appwrite-Server vdev. Please report abuse at security@appwrite.io'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Event'], 'users.create'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Signature'], 'not-yet-implemented'); + $this->assertNotEmpty($webhook['data']['$id']); + $this->assertEquals($webhook['data']['name'], $name); + $this->assertIsInt($webhook['data']['registration']); + $this->assertEquals($webhook['data']['status'], 0); + $this->assertEquals($webhook['data']['email'], $email); + $this->assertEquals($webhook['data']['emailVerification'], false); + $this->assertEquals($webhook['data']['prefs'], []); + + /** + * Test for FAILURE + */ + return ['userId' => $user['body']['$id'], 'name' => $user['body']['name'], 'email' => $user['body']['email']]; + } + + /** + * @depends testCreateUser + */ + public function testUpdateUserStatus(array $data):array + { + /** + * Test for SUCCESS + */ + $user = $this->client->call(Client::METHOD_PATCH, '/users/' . $data['userId'] . '/status', array_merge([ + 'content-type' => 'application/json', + 'x-appwrite-project' => $this->getProject()['$id'], + ], $this->getHeaders()), [ + 'status' => 2, + ]); + + $this->assertEquals($user['headers']['status-code'], 200); + $this->assertNotEmpty($user['body']['$id']); + + $webhook = $this->getLastRequest(); + + $this->assertEquals($webhook['method'], 'POST'); + $this->assertEquals($webhook['headers']['Content-Type'], 'application/json'); + $this->assertEquals($webhook['headers']['User-Agent'], 'Appwrite-Server vdev. Please report abuse at security@appwrite.io'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Event'], 'users.update.status'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Signature'], 'not-yet-implemented'); + $this->assertNotEmpty($webhook['data']['$id']); + $this->assertEquals($webhook['data']['name'], $data['name']); + $this->assertIsInt($webhook['data']['registration']); + $this->assertEquals($webhook['data']['status'], 2); + $this->assertEquals($webhook['data']['email'], $data['email']); + $this->assertEquals($webhook['data']['emailVerification'], false); + $this->assertEquals($webhook['data']['prefs'], []); + + return $data; + } + + /** + * @depends testUpdateUserStatus + */ + public function testDeleteUser(array $data):array + { + /** + * Test for SUCCESS + */ + $user = $this->client->call(Client::METHOD_DELETE, '/users/' . $data['userId'], array_merge([ + 'content-type' => 'application/json', + 'x-appwrite-project' => $this->getProject()['$id'], + ], $this->getHeaders())); + + $this->assertEquals($user['headers']['status-code'], 204); + + $webhook = $this->getLastRequest(); + + $this->assertEquals($webhook['method'], 'POST'); + $this->assertEquals($webhook['headers']['Content-Type'], 'application/json'); + $this->assertEquals($webhook['headers']['User-Agent'], 'Appwrite-Server vdev. Please report abuse at security@appwrite.io'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Event'], 'users.delete'); + $this->assertEquals($webhook['headers']['X-Appwrite-Webhook-Signature'], 'not-yet-implemented'); + $this->assertNotEmpty($webhook['data']['$id']); + $this->assertEquals($webhook['data']['name'], $data['name']); + $this->assertIsInt($webhook['data']['registration']); + $this->assertEquals($webhook['data']['status'], 2); + $this->assertEquals($webhook['data']['email'], $data['email']); + $this->assertEquals($webhook['data']['emailVerification'], false); + $this->assertEquals($webhook['data']['prefs'], []); + + return $data; + } } \ No newline at end of file diff --git a/tests/e2e/Services/Workers/WebhooksTest.php b/tests/e2e/Services/Workers/WebhooksTest.php index 67c51785cd..ced80832ae 100644 --- a/tests/e2e/Services/Workers/WebhooksTest.php +++ b/tests/e2e/Services/Workers/WebhooksTest.php @@ -147,6 +147,5 @@ class WebhooksTest extends Scope $this->assertEquals($webhook['data']['name'], $name); $this->assertIsBool($webhook['data']['emailVerification']); $this->assertIsArray($webhook['data']['prefs']); - $this->assertIsArray($webhook['data']['roles']); } } \ No newline at end of file