user_test.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496
  1. package sqlstore
  2. import (
  3. "context"
  4. "fmt"
  5. "testing"
  6. "time"
  7. . "github.com/smartystreets/goconvey/convey"
  8. "github.com/grafana/grafana/pkg/models"
  9. )
  10. func TestUserDataAccess(t *testing.T) {
  11. Convey("Testing DB", t, func() {
  12. ss := InitTestDB(t)
  13. Convey("Creates a user", func() {
  14. cmd := &models.CreateUserCommand{
  15. Email: "usertest@test.com",
  16. Name: "user name",
  17. Login: "user_test_login",
  18. }
  19. err := CreateUser(context.Background(), cmd)
  20. So(err, ShouldBeNil)
  21. Convey("Loading a user", func() {
  22. query := models.GetUserByIdQuery{Id: cmd.Result.Id}
  23. err := GetUserById(&query)
  24. So(err, ShouldBeNil)
  25. So(query.Result.Email, ShouldEqual, "usertest@test.com")
  26. So(query.Result.Password, ShouldEqual, "")
  27. So(query.Result.Rands, ShouldHaveLength, 10)
  28. So(query.Result.Salt, ShouldHaveLength, 10)
  29. So(query.Result.IsDisabled, ShouldBeFalse)
  30. })
  31. })
  32. Convey("Creates disabled user", func() {
  33. cmd := &models.CreateUserCommand{
  34. Email: "usertest@test.com",
  35. Name: "user name",
  36. Login: "user_test_login",
  37. IsDisabled: true,
  38. }
  39. err := CreateUser(context.Background(), cmd)
  40. So(err, ShouldBeNil)
  41. Convey("Loading a user", func() {
  42. query := models.GetUserByIdQuery{Id: cmd.Result.Id}
  43. err := GetUserById(&query)
  44. So(err, ShouldBeNil)
  45. So(query.Result.Email, ShouldEqual, "usertest@test.com")
  46. So(query.Result.Password, ShouldEqual, "")
  47. So(query.Result.Rands, ShouldHaveLength, 10)
  48. So(query.Result.Salt, ShouldHaveLength, 10)
  49. So(query.Result.IsDisabled, ShouldBeTrue)
  50. })
  51. })
  52. Convey("Given 5 users", func() {
  53. users := createFiveTestUsers(func(i int) *models.CreateUserCommand {
  54. return &models.CreateUserCommand{
  55. Email: fmt.Sprint("user", i, "@test.com"),
  56. Name: fmt.Sprint("user", i),
  57. Login: fmt.Sprint("loginuser", i),
  58. IsDisabled: false,
  59. }
  60. })
  61. Convey("Can return the first page of users and a total count", func() {
  62. query := models.SearchUsersQuery{Query: "", Page: 1, Limit: 3}
  63. err := SearchUsers(&query)
  64. So(err, ShouldBeNil)
  65. So(len(query.Result.Users), ShouldEqual, 3)
  66. So(query.Result.TotalCount, ShouldEqual, 5)
  67. })
  68. Convey("Can return the second page of users and a total count", func() {
  69. query := models.SearchUsersQuery{Query: "", Page: 2, Limit: 3}
  70. err := SearchUsers(&query)
  71. So(err, ShouldBeNil)
  72. So(len(query.Result.Users), ShouldEqual, 2)
  73. So(query.Result.TotalCount, ShouldEqual, 5)
  74. })
  75. Convey("Can return list of users matching query on user name", func() {
  76. query := models.SearchUsersQuery{Query: "use", Page: 1, Limit: 3}
  77. err := SearchUsers(&query)
  78. So(err, ShouldBeNil)
  79. So(len(query.Result.Users), ShouldEqual, 3)
  80. So(query.Result.TotalCount, ShouldEqual, 5)
  81. query = models.SearchUsersQuery{Query: "ser1", Page: 1, Limit: 3}
  82. err = SearchUsers(&query)
  83. So(err, ShouldBeNil)
  84. So(len(query.Result.Users), ShouldEqual, 1)
  85. So(query.Result.TotalCount, ShouldEqual, 1)
  86. query = models.SearchUsersQuery{Query: "USER1", Page: 1, Limit: 3}
  87. err = SearchUsers(&query)
  88. So(err, ShouldBeNil)
  89. So(len(query.Result.Users), ShouldEqual, 1)
  90. So(query.Result.TotalCount, ShouldEqual, 1)
  91. query = models.SearchUsersQuery{Query: "idontexist", Page: 1, Limit: 3}
  92. err = SearchUsers(&query)
  93. So(err, ShouldBeNil)
  94. So(len(query.Result.Users), ShouldEqual, 0)
  95. So(query.Result.TotalCount, ShouldEqual, 0)
  96. })
  97. Convey("Can return list of users matching query on email", func() {
  98. query := models.SearchUsersQuery{Query: "ser1@test.com", Page: 1, Limit: 3}
  99. err := SearchUsers(&query)
  100. So(err, ShouldBeNil)
  101. So(len(query.Result.Users), ShouldEqual, 1)
  102. So(query.Result.TotalCount, ShouldEqual, 1)
  103. })
  104. Convey("Can return list of users matching query on login name", func() {
  105. query := models.SearchUsersQuery{Query: "loginuser1", Page: 1, Limit: 3}
  106. err := SearchUsers(&query)
  107. So(err, ShouldBeNil)
  108. So(len(query.Result.Users), ShouldEqual, 1)
  109. So(query.Result.TotalCount, ShouldEqual, 1)
  110. })
  111. Convey("Can return list users based on their auth type", func() {
  112. // add users to auth table
  113. for index, user := range users {
  114. authModule := "killa"
  115. // define every second user as ldap
  116. if index%2 == 0 {
  117. authModule = "ldap"
  118. }
  119. cmd2 := &models.SetAuthInfoCommand{
  120. UserId: user.Id,
  121. AuthModule: authModule,
  122. AuthId: "gorilla",
  123. }
  124. err := SetAuthInfo(cmd2)
  125. So(err, ShouldBeNil)
  126. }
  127. query := models.SearchUsersQuery{AuthModule: "ldap"}
  128. err := SearchUsers(&query)
  129. So(err, ShouldBeNil)
  130. So(query.Result.Users, ShouldHaveLength, 3)
  131. zero, second, fourth := false, false, false
  132. for _, user := range query.Result.Users {
  133. if user.Name == "user0" {
  134. zero = true
  135. }
  136. if user.Name == "user2" {
  137. second = true
  138. }
  139. if user.Name == "user4" {
  140. fourth = true
  141. }
  142. }
  143. So(zero, ShouldBeTrue)
  144. So(second, ShouldBeTrue)
  145. So(fourth, ShouldBeTrue)
  146. })
  147. Convey("Can return list users based on their is_disabled flag", func() {
  148. ss = InitTestDB(t)
  149. createFiveTestUsers(func(i int) *models.CreateUserCommand {
  150. return &models.CreateUserCommand{
  151. Email: fmt.Sprint("user", i, "@test.com"),
  152. Name: fmt.Sprint("user", i),
  153. Login: fmt.Sprint("loginuser", i),
  154. IsDisabled: i%2 == 0,
  155. }
  156. })
  157. query := models.SearchUsersQuery{IsDisabled: "false"}
  158. err := SearchUsers(&query)
  159. So(err, ShouldBeNil)
  160. So(query.Result.Users, ShouldHaveLength, 2)
  161. first, third := false, false
  162. for _, user := range query.Result.Users {
  163. if user.Name == "user1" {
  164. first = true
  165. }
  166. if user.Name == "user3" {
  167. third = true
  168. }
  169. }
  170. So(first, ShouldBeTrue)
  171. So(third, ShouldBeTrue)
  172. ss = InitTestDB(t)
  173. users = createFiveTestUsers(func(i int) *models.CreateUserCommand {
  174. return &models.CreateUserCommand{
  175. Email: fmt.Sprint("user", i, "@test.com"),
  176. Name: fmt.Sprint("user", i),
  177. Login: fmt.Sprint("loginuser", i),
  178. IsDisabled: false,
  179. }
  180. })
  181. })
  182. Convey("when a user is an org member and has been assigned permissions", func() {
  183. err := AddOrgUser(&models.AddOrgUserCommand{LoginOrEmail: users[1].Login, Role: models.ROLE_VIEWER, OrgId: users[0].OrgId, UserId: users[1].Id})
  184. So(err, ShouldBeNil)
  185. testHelperUpdateDashboardAcl(1, models.DashboardAcl{DashboardId: 1, OrgId: users[0].OrgId, UserId: users[1].Id, Permission: models.PERMISSION_EDIT})
  186. So(err, ShouldBeNil)
  187. err = SavePreferences(&models.SavePreferencesCommand{UserId: users[1].Id, OrgId: users[0].OrgId, HomeDashboardId: 1, Theme: "dark"})
  188. So(err, ShouldBeNil)
  189. Convey("when the user is deleted", func() {
  190. err = DeleteUser(&models.DeleteUserCommand{UserId: users[1].Id})
  191. So(err, ShouldBeNil)
  192. Convey("Should delete connected org users and permissions", func() {
  193. query := &models.GetOrgUsersQuery{OrgId: users[0].OrgId}
  194. err = GetOrgUsersForTest(query)
  195. So(err, ShouldBeNil)
  196. So(len(query.Result), ShouldEqual, 1)
  197. permQuery := &models.GetDashboardAclInfoListQuery{DashboardId: 1, OrgId: users[0].OrgId}
  198. err = GetDashboardAclInfoList(permQuery)
  199. So(err, ShouldBeNil)
  200. So(len(permQuery.Result), ShouldEqual, 0)
  201. prefsQuery := &models.GetPreferencesQuery{OrgId: users[0].OrgId, UserId: users[1].Id}
  202. err = GetPreferences(prefsQuery)
  203. So(err, ShouldBeNil)
  204. So(prefsQuery.Result.OrgId, ShouldEqual, 0)
  205. So(prefsQuery.Result.UserId, ShouldEqual, 0)
  206. })
  207. })
  208. Convey("when retreiving signed in user for orgId=0 result should return active org id", func() {
  209. ss.CacheService.Flush()
  210. query := &models.GetSignedInUserQuery{OrgId: users[1].OrgId, UserId: users[1].Id}
  211. err := ss.GetSignedInUserWithCache(query)
  212. So(err, ShouldBeNil)
  213. So(query.Result, ShouldNotBeNil)
  214. So(query.OrgId, ShouldEqual, users[1].OrgId)
  215. err = SetUsingOrg(&models.SetUsingOrgCommand{UserId: users[1].Id, OrgId: users[0].OrgId})
  216. So(err, ShouldBeNil)
  217. query = &models.GetSignedInUserQuery{OrgId: 0, UserId: users[1].Id}
  218. err = ss.GetSignedInUserWithCache(query)
  219. So(err, ShouldBeNil)
  220. So(query.Result, ShouldNotBeNil)
  221. So(query.Result.OrgId, ShouldEqual, users[0].OrgId)
  222. cacheKey := newSignedInUserCacheKey(query.Result.OrgId, query.UserId)
  223. _, found := ss.CacheService.Get(cacheKey)
  224. So(found, ShouldBeTrue)
  225. })
  226. })
  227. Convey("When batch disabling users", func() {
  228. Convey("Should disable all users", func() {
  229. disableCmd := models.BatchDisableUsersCommand{
  230. UserIds: []int64{1, 2, 3, 4, 5},
  231. IsDisabled: true,
  232. }
  233. err := BatchDisableUsers(&disableCmd)
  234. So(err, ShouldBeNil)
  235. query := &models.SearchUsersQuery{IsDisabled: "true"}
  236. err = SearchUsers(query)
  237. So(err, ShouldBeNil)
  238. So(query.Result.TotalCount, ShouldEqual, 5)
  239. })
  240. Convey("Should enable all users", func() {
  241. ss = InitTestDB(t)
  242. createFiveTestUsers(func(i int) *models.CreateUserCommand {
  243. return &models.CreateUserCommand{
  244. Email: fmt.Sprint("user", i, "@test.com"),
  245. Name: fmt.Sprint("user", i),
  246. Login: fmt.Sprint("loginuser", i),
  247. IsDisabled: true,
  248. }
  249. })
  250. disableCmd := models.BatchDisableUsersCommand{
  251. UserIds: []int64{1, 2, 3, 4, 5},
  252. IsDisabled: false,
  253. }
  254. err := BatchDisableUsers(&disableCmd)
  255. So(err, ShouldBeNil)
  256. query := &models.SearchUsersQuery{IsDisabled: "false"}
  257. err = SearchUsers(query)
  258. So(err, ShouldBeNil)
  259. So(query.Result.TotalCount, ShouldEqual, 5)
  260. })
  261. Convey("Should disable only specific users", func() {
  262. ss = InitTestDB(t)
  263. users = createFiveTestUsers(func(i int) *models.CreateUserCommand {
  264. return &models.CreateUserCommand{
  265. Email: fmt.Sprint("user", i, "@test.com"),
  266. Name: fmt.Sprint("user", i),
  267. Login: fmt.Sprint("loginuser", i),
  268. IsDisabled: false,
  269. }
  270. })
  271. userIdsToDisable := []int64{}
  272. for i := 0; i < 3; i++ {
  273. userIdsToDisable = append(userIdsToDisable, users[i].Id)
  274. }
  275. disableCmd := models.BatchDisableUsersCommand{
  276. UserIds: userIdsToDisable,
  277. IsDisabled: true,
  278. }
  279. err := BatchDisableUsers(&disableCmd)
  280. So(err, ShouldBeNil)
  281. query := models.SearchUsersQuery{}
  282. err = SearchUsers(&query)
  283. So(err, ShouldBeNil)
  284. So(query.Result.TotalCount, ShouldEqual, 5)
  285. for _, user := range query.Result.Users {
  286. shouldBeDisabled := false
  287. // Check if user id is in the userIdsToDisable list
  288. for _, disabledUserId := range userIdsToDisable {
  289. if user.Id == disabledUserId {
  290. So(user.IsDisabled, ShouldBeTrue)
  291. shouldBeDisabled = true
  292. }
  293. }
  294. // Otherwise user shouldn't be disabled
  295. if !shouldBeDisabled {
  296. So(user.IsDisabled, ShouldBeFalse)
  297. }
  298. }
  299. })
  300. // Since previous tests were destructive
  301. ss = InitTestDB(t)
  302. users = createFiveTestUsers(func(i int) *models.CreateUserCommand {
  303. return &models.CreateUserCommand{
  304. Email: fmt.Sprint("user", i, "@test.com"),
  305. Name: fmt.Sprint("user", i),
  306. Login: fmt.Sprint("loginuser", i),
  307. IsDisabled: false,
  308. }
  309. })
  310. })
  311. Convey("When searching users", func() {
  312. // Find a user to set tokens on
  313. login := "loginuser0"
  314. // Calling GetUserByAuthInfoQuery on an existing user will populate an entry in the user_auth table
  315. // Make the first log-in during the past
  316. getTime = func() time.Time { return time.Now().AddDate(0, 0, -2) }
  317. query := &models.GetUserByAuthInfoQuery{Login: login, AuthModule: "test1", AuthId: "test1"}
  318. err := GetUserByAuthInfo(query)
  319. getTime = time.Now
  320. So(err, ShouldBeNil)
  321. So(query.Result.Login, ShouldEqual, login)
  322. // Add a second auth module for this user
  323. // Have this module's last log-in be more recent
  324. getTime = func() time.Time { return time.Now().AddDate(0, 0, -1) }
  325. query = &models.GetUserByAuthInfoQuery{Login: login, AuthModule: "test2", AuthId: "test2"}
  326. err = GetUserByAuthInfo(query)
  327. getTime = time.Now
  328. So(err, ShouldBeNil)
  329. So(query.Result.Login, ShouldEqual, login)
  330. Convey("Should return the only most recently used auth_module", func() {
  331. searchUserQuery := &models.SearchUsersQuery{}
  332. err = SearchUsers(searchUserQuery)
  333. So(err, ShouldBeNil)
  334. So(searchUserQuery.Result.Users, ShouldHaveLength, 5)
  335. for _, user := range searchUserQuery.Result.Users {
  336. if user.Login == login {
  337. So(user.AuthModule, ShouldHaveLength, 1)
  338. So(user.AuthModule[0], ShouldEqual, "test2")
  339. }
  340. }
  341. // "log in" again with the first auth module
  342. updateAuthCmd := &models.UpdateAuthInfoCommand{UserId: query.Result.Id, AuthModule: "test1", AuthId: "test1"}
  343. err = UpdateAuthInfo(updateAuthCmd)
  344. So(err, ShouldBeNil)
  345. searchUserQuery = &models.SearchUsersQuery{}
  346. err = SearchUsers(searchUserQuery)
  347. So(err, ShouldBeNil)
  348. for _, user := range searchUserQuery.Result.Users {
  349. if user.Login == login {
  350. So(user.AuthModule, ShouldHaveLength, 1)
  351. So(user.AuthModule[0], ShouldEqual, "test1")
  352. }
  353. }
  354. })
  355. })
  356. })
  357. Convey("Given one grafana admin user", func() {
  358. var err error
  359. createUserCmd := &models.CreateUserCommand{
  360. Email: fmt.Sprint("admin", "@test.com"),
  361. Name: fmt.Sprint("admin"),
  362. Login: fmt.Sprint("admin"),
  363. IsAdmin: true,
  364. }
  365. err = CreateUser(context.Background(), createUserCmd)
  366. So(err, ShouldBeNil)
  367. Convey("Cannot make themselves a non-admin", func() {
  368. updateUserPermsCmd := models.UpdateUserPermissionsCommand{IsGrafanaAdmin: false, UserId: 1}
  369. updatePermsError := UpdateUserPermissions(&updateUserPermsCmd)
  370. So(updatePermsError, ShouldEqual, models.ErrLastGrafanaAdmin)
  371. query := models.GetUserByIdQuery{Id: createUserCmd.Result.Id}
  372. getUserError := GetUserById(&query)
  373. So(getUserError, ShouldBeNil)
  374. So(query.Result.IsAdmin, ShouldEqual, true)
  375. })
  376. })
  377. })
  378. }
  379. func GetOrgUsersForTest(query *models.GetOrgUsersQuery) error {
  380. query.Result = make([]*models.OrgUserDTO, 0)
  381. sess := x.Table("org_user")
  382. sess.Join("LEFT ", x.Dialect().Quote("user"), fmt.Sprintf("org_user.user_id=%s.id", x.Dialect().Quote("user")))
  383. sess.Where("org_user.org_id=?", query.OrgId)
  384. sess.Cols("org_user.org_id", "org_user.user_id", "user.email", "user.login", "org_user.role")
  385. err := sess.Find(&query.Result)
  386. return err
  387. }
  388. func createFiveTestUsers(fn func(i int) *models.CreateUserCommand) []models.User {
  389. var err error
  390. var cmd *models.CreateUserCommand
  391. users := []models.User{}
  392. for i := 0; i < 5; i++ {
  393. cmd = fn(i)
  394. err = CreateUser(context.Background(), cmd)
  395. users = append(users, cmd.Result)
  396. So(err, ShouldBeNil)
  397. }
  398. return users
  399. }