|
@@ -21,6 +21,36 @@ class RequestTest extends PHPUnit_Framework_TestCase
|
|
|
$_POST = array();
|
|
$_POST = array();
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
|
|
+ /**
|
|
|
|
|
+ * Returns 16 random hexadecimal characters.
|
|
|
|
|
+ *
|
|
|
|
|
+ * @access public
|
|
|
|
|
+ * @return string
|
|
|
|
|
+ */
|
|
|
|
|
+ public function getRandomId()
|
|
|
|
|
+ {
|
|
|
|
|
+ // 8 binary bytes are 16 characters long in hex
|
|
|
|
|
+ return bin2hex(random_bytes(8));
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ /**
|
|
|
|
|
+ * Returns random query safe characters.
|
|
|
|
|
+ *
|
|
|
|
|
+ * @access public
|
|
|
|
|
+ * @return string
|
|
|
|
|
+ */
|
|
|
|
|
+ public function getRandomQueryChars()
|
|
|
|
|
+ {
|
|
|
|
|
+ $queryChars = '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ=';
|
|
|
|
|
+ $queryCharCount = strlen($queryChars) - 1;
|
|
|
|
|
+ $resultLength = random_int(1, 10);
|
|
|
|
|
+ $result = '';
|
|
|
|
|
+ for ($i = 0; $i < $resultLength; ++$i) {
|
|
|
|
|
+ $result .= $queryChars[random_int(0, $queryCharCount)];
|
|
|
|
|
+ }
|
|
|
|
|
+ return $result;
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
public function testView()
|
|
public function testView()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
@@ -33,24 +63,27 @@ class RequestTest extends PHPUnit_Framework_TestCase
|
|
|
public function testRead()
|
|
public function testRead()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('read', $request->getOperation());
|
|
$this->assertEquals('read', $request->getOperation());
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
public function testDelete()
|
|
public function testDelete()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
- $_GET['pasteid'] = 'foo';
|
|
|
|
|
|
|
+ $_GET['pasteid'] = $id;
|
|
|
$_GET['deletetoken'] = 'bar';
|
|
$_GET['deletetoken'] = 'bar';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
|
$this->assertEquals('delete', $request->getOperation());
|
|
$this->assertEquals('delete', $request->getOperation());
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('bar', $request->getParam('deletetoken'));
|
|
$this->assertEquals('bar', $request->getParam('deletetoken'));
|
|
|
}
|
|
}
|
|
|
|
|
|
|
@@ -84,74 +117,103 @@ class RequestTest extends PHPUnit_Framework_TestCase
|
|
|
public function testApiRead()
|
|
public function testApiRead()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
$_SERVER['HTTP_ACCEPT'] = 'application/json, text/javascript, */*; q=0.01';
|
|
$_SERVER['HTTP_ACCEPT'] = 'application/json, text/javascript, */*; q=0.01';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertTrue($request->isJsonApiCall(), 'is JSON Api call');
|
|
$this->assertTrue($request->isJsonApiCall(), 'is JSON Api call');
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('read', $request->getOperation());
|
|
$this->assertEquals('read', $request->getOperation());
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
public function testApiDelete()
|
|
public function testApiDelete()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'POST';
|
|
$_SERVER['REQUEST_METHOD'] = 'POST';
|
|
|
$_SERVER['HTTP_X_REQUESTED_WITH'] = 'JSONHttpRequest';
|
|
$_SERVER['HTTP_X_REQUESTED_WITH'] = 'JSONHttpRequest';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET = array($id => '');
|
|
|
$_POST['deletetoken'] = 'bar';
|
|
$_POST['deletetoken'] = 'bar';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertTrue($request->isJsonApiCall(), 'is JSON Api call');
|
|
$this->assertTrue($request->isJsonApiCall(), 'is JSON Api call');
|
|
|
$this->assertEquals('delete', $request->getOperation());
|
|
$this->assertEquals('delete', $request->getOperation());
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('bar', $request->getParam('deletetoken'));
|
|
$this->assertEquals('bar', $request->getParam('deletetoken'));
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
public function testReadWithNegotiation()
|
|
public function testReadWithNegotiation()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
$_SERVER['HTTP_ACCEPT'] = 'text/html,text/html; charset=UTF-8,application/xhtml+xml, application/xml;q=0.9,*/*;q=0.8, text/csv,application/json';
|
|
$_SERVER['HTTP_ACCEPT'] = 'text/html,text/html; charset=UTF-8,application/xhtml+xml, application/xml;q=0.9,*/*;q=0.8, text/csv,application/json';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('read', $request->getOperation());
|
|
$this->assertEquals('read', $request->getOperation());
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
public function testReadWithXhtmlNegotiation()
|
|
public function testReadWithXhtmlNegotiation()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
$_SERVER['HTTP_ACCEPT'] = 'application/xhtml+xml,text/html,text/html; charset=UTF-8, application/xml;q=0.9,*/*;q=0.8, text/csv,application/json';
|
|
$_SERVER['HTTP_ACCEPT'] = 'application/xhtml+xml,text/html,text/html; charset=UTF-8, application/xml;q=0.9,*/*;q=0.8, text/csv,application/json';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('read', $request->getOperation());
|
|
$this->assertEquals('read', $request->getOperation());
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
public function testApiReadWithNegotiation()
|
|
public function testApiReadWithNegotiation()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
$_SERVER['HTTP_ACCEPT'] = 'text/plain,text/csv, application/xml;q=0.9, application/json, text/html,text/html; charset=UTF-8,application/xhtml+xml, */*;q=0.8';
|
|
$_SERVER['HTTP_ACCEPT'] = 'text/plain,text/csv, application/xml;q=0.9, application/json, text/html,text/html; charset=UTF-8,application/xhtml+xml, */*;q=0.8';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertTrue($request->isJsonApiCall(), 'is JSON Api call');
|
|
$this->assertTrue($request->isJsonApiCall(), 'is JSON Api call');
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('read', $request->getOperation());
|
|
$this->assertEquals('read', $request->getOperation());
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
public function testReadWithFailedNegotiation()
|
|
public function testReadWithFailedNegotiation()
|
|
|
{
|
|
{
|
|
|
$this->reset();
|
|
$this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
$_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
$_SERVER['HTTP_ACCEPT'] = 'text/plain,text/csv, application/xml;q=0.9, */*;q=0.8';
|
|
$_SERVER['HTTP_ACCEPT'] = 'text/plain,text/csv, application/xml;q=0.9, */*;q=0.8';
|
|
|
- $_SERVER['QUERY_STRING'] = 'foo';
|
|
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = $id;
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
$request = new Request;
|
|
$request = new Request;
|
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
$this->assertFalse($request->isJsonApiCall(), 'is HTML call');
|
|
|
- $this->assertEquals('foo', $request->getParam('pasteid'));
|
|
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
$this->assertEquals('read', $request->getOperation());
|
|
$this->assertEquals('read', $request->getOperation());
|
|
|
}
|
|
}
|
|
|
|
|
+
|
|
|
|
|
+ public function testPasteIdExtraction()
|
|
|
|
|
+ {
|
|
|
|
|
+ $this->reset();
|
|
|
|
|
+ $id = $this->getRandomId();
|
|
|
|
|
+ $queryParams = array($id);
|
|
|
|
|
+ $queryParamCount = random_int(1, 5);
|
|
|
|
|
+ for ($i = 0; $i < $queryParamCount; ++$i) {
|
|
|
|
|
+ array_push($queryParams, $this->getRandomQueryChars());
|
|
|
|
|
+ }
|
|
|
|
|
+ shuffle($queryParams);
|
|
|
|
|
+ $_SERVER['REQUEST_METHOD'] = 'GET';
|
|
|
|
|
+ $_SERVER['QUERY_STRING'] = implode('&', $queryParams);
|
|
|
|
|
+ $_GET[$id] = '';
|
|
|
|
|
+ $request = new Request;
|
|
|
|
|
+ $this->assertEquals($id, $request->getParam('pasteid'));
|
|
|
|
|
+ }
|
|
|
}
|
|
}
|