FilterAdminTest.php 16.4 KB
Newer Older
1 2 3 4
<?php

/**
 * @file
5
 * Contains \Drupal\filter\Tests\FilterAdminTest.
6 7 8 9
 */

namespace Drupal\filter\Tests;

10
use Drupal\Component\Utility\Html;
11
use Drupal\Component\Utility\Unicode;
12
use Drupal\simpletest\WebTestBase;
13
use Drupal\user\RoleInterface;
14

15
/**
16 17 18
 * Thoroughly test the administrative interface of the filter module.
 *
 * @group filter
19
 */
20
class FilterAdminTest extends WebTestBase {
21 22

  /**
23
   * {@inheritdoc}
24
   */
25
  public static $modules = array('filter', 'node');
26

27 28 29 30 31 32 33 34 35 36 37 38 39 40
  /**
   * An user with administration permissions.
   *
   * @var \Drupal\user\UserInterface
   */
  protected $adminUser;

  /**
   * An user with permissions to create pages.
   *
   * @var \Drupal\user\UserInterface
   */
  protected $webUser;

41 42 43
  /**
   * {@inheritdoc}
   */
44
  protected function setUp() {
45 46
    parent::setUp();

47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96
    $this->drupalCreateContentType(array('type' => 'page', 'name' => 'Basic page'));

    // Set up the filter formats used by this test.
    $basic_html_format = entity_create('filter_format', array(
      'format' => 'basic_html',
      'name' => 'Basic HTML',
      'filters' => array(
        'filter_html' => array(
          'status' => 1,
          'settings' => array(
            'allowed_html' => '<p> <br> <strong> <a> <em>',
          ),
        ),
      ),
    ));
    $basic_html_format->save();
    $restricted_html_format = entity_create('filter_format', array(
      'format' => 'restricted_html',
      'name' => 'Restricted HTML',
      'filters' => array(
        'filter_html' => array(
          'status' => TRUE,
          'weight' => -10,
          'settings' => array(
            'allowed_html' => '<p> <br> <strong> <a> <em> <h4>',
          ),
        ),
        'filter_autop' => array(
          'status' => TRUE,
          'weight' => 0,
        ),
        'filter_url' => array(
          'status' => TRUE,
          'weight' => 0,
        ),
        'filter_htmlcorrector' => array(
          'status' => TRUE,
          'weight' => 10,
        ),
      ),
    ));
    $restricted_html_format->save();
    $full_html_format = entity_create('filter_format', array(
      'format' => 'full_html',
      'name' => 'Full HTML',
      'weight' => 1,
      'filters' => array(),
    ));
    $full_html_format->save();

97
    $this->adminUser = $this->drupalCreateUser(array(
98
      'administer filters',
99 100 101
      $basic_html_format->getPermissionName(),
      $restricted_html_format->getPermissionName(),
      $full_html_format->getPermissionName(),
102 103
    ));

104
    $this->webUser = $this->drupalCreateUser(array('create page content', 'edit own page content'));
105 106
    user_role_grant_permissions('authenticated', array($basic_html_format->getPermissionName()));
    user_role_grant_permissions('anonymous', array($restricted_html_format->getPermissionName()));
107
    $this->drupalLogin($this->adminUser);
108 109
  }

110 111 112
  /**
   * Tests the format administration functionality.
   */
113 114 115 116
  function testFormatAdmin() {
    // Add text format.
    $this->drupalGet('admin/config/content/formats');
    $this->clickLink('Add text format');
117
    $format_id = Unicode::strtolower($this->randomMachineName());
118
    $name = $this->randomMachineName();
119 120 121 122
    $edit = array(
      'format' => $format_id,
      'name' => $name,
    );
123
    $this->drupalPostForm(NULL, $edit, t('Save configuration'));
124 125 126

    // Verify default weight of the text format.
    $this->drupalGet('admin/config/content/formats');
127
    $this->assertFieldByName("formats[$format_id][weight]", 0, 'Text format weight was saved.');
128 129 130 131 132

    // Change the weight of the text format.
    $edit = array(
      "formats[$format_id][weight]" => 5,
    );
133
    $this->drupalPostForm('admin/config/content/formats', $edit, t('Save changes'));
134
    $this->assertFieldByName("formats[$format_id][weight]", 5, 'Text format weight was saved.');
135 136 137

    // Edit text format.
    $this->drupalGet('admin/config/content/formats');
138 139 140
    // Cannot use the assertNoLinkByHref method as it does partial url matching
    // and 'admin/config/content/formats/manage/' . $format_id . '/disable'
    // exists.
141
    // @todo: See https://www.drupal.org/node/2031223 for the above.
142
    $edit_link = $this->xpath('//a[@href=:href]', array(
143
      ':href' => \Drupal::url('entity.filter_format.edit_form', ['filter_format' => $format_id])
144 145 146 147
    ));
    $this->assertTrue($edit_link, format_string('Link href %href found.',
      array('%href' => 'admin/config/content/formats/manage/' . $format_id)
    ));
148
    $this->drupalGet('admin/config/content/formats/manage/' . $format_id);
149
    $this->drupalPostForm(NULL, array(), t('Save configuration'));
150 151 152

    // Verify that the custom weight of the text format has been retained.
    $this->drupalGet('admin/config/content/formats');
153
    $this->assertFieldByName("formats[$format_id][weight]", 5, 'Text format weight was retained.');
154 155

    // Disable text format.
156 157
    $this->assertLinkByHref('admin/config/content/formats/manage/' . $format_id . '/disable');
    $this->drupalGet('admin/config/content/formats/manage/' . $format_id . '/disable');
158
    $this->drupalPostForm(NULL, array(), t('Disable'));
159 160

    // Verify that disabled text format no longer exists.
161
    $this->drupalGet('admin/config/content/formats/manage/' . $format_id);
162
    $this->assertResponse(404, 'Disabled text format no longer exists.');
163 164 165 166 167 168 169

    // Attempt to create a format of the same machine name as the disabled
    // format but with a different human readable name.
    $edit = array(
      'format' => $format_id,
      'name' => 'New format',
    );
170
    $this->drupalPostForm('admin/config/content/formats/add', $edit, t('Save configuration'));
171 172 173 174 175 176 177 178
    $this->assertText('The machine-readable name is already in use. It must be unique.');

    // Attempt to create a format of the same human readable name as the
    // disabled format but with a different machine name.
    $edit = array(
      'format' => 'new_format',
      'name' => $name,
    );
179
    $this->drupalPostForm('admin/config/content/formats/add', $edit, t('Save configuration'));
180 181 182 183 184 185
    $this->assertRaw(t('Text format names must be unique. A format named %name already exists.', array(
      '%name' => $name,
    )));
  }

  /**
186
   * Tests filter administration functionality.
187 188
   */
  function testFilterAdmin() {
189 190
    $first_filter = 'filter_autop';
    $second_filter = 'filter_url';
191

192
    $basic = 'basic_html';
193
    $restricted = 'restricted_html';
194 195 196 197
    $full = 'full_html';
    $plain = 'plain_text';

    // Check that the fallback format exists and cannot be disabled.
198
    $this->assertTrue($plain == filter_fallback_format(), 'The fallback format is set to plain text.');
199
    $this->drupalGet('admin/config/content/formats');
200 201
    $this->assertNoRaw('admin/config/content/formats/manage/' . $plain . '/disable', 'Disable link for the fallback format not found.');
    $this->drupalGet('admin/config/content/formats/manage/' . $plain . '/disable');
202
    $this->assertResponse(403, 'The fallback format cannot be disabled.');
203 204

    // Verify access permissions to Full HTML format.
205
    $full_format = entity_load('filter_format', $full);
206 207
    $this->assertTrue($full_format->access('use', $this->adminUser), 'Admin user may use Full HTML.');
    $this->assertFalse($full_format->access('use', $this->webUser), 'Web user may not use Full HTML.');
208 209 210 211

    // Add an additional tag.
    $edit = array();
    $edit['filters[filter_html][settings][allowed_html]'] = '<a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <quote>';
212
    $this->drupalPostForm('admin/config/content/formats/manage/' . $restricted, $edit, t('Save configuration'));
213
    $this->assertUrl('admin/config/content/formats');
214
    $this->drupalGet('admin/config/content/formats/manage/' . $restricted);
215
    $this->assertFieldByName('filters[filter_html][settings][allowed_html]', $edit['filters[filter_html][settings][allowed_html]'], 'Allowed HTML tag added.');
216 217 218 219 220

    $elements = $this->xpath('//select[@name=:first]/following::select[@name=:second]', array(
      ':first' => 'filters[' . $first_filter . '][weight]',
      ':second' => 'filters[' . $second_filter . '][weight]',
    ));
221
    $this->assertTrue(!empty($elements), 'Order confirmed in admin interface.');
222 223 224 225 226

    // Reorder filters.
    $edit = array();
    $edit['filters[' . $second_filter . '][weight]'] = 1;
    $edit['filters[' . $first_filter . '][weight]'] = 2;
227
    $this->drupalPostForm(NULL, $edit, t('Save configuration'));
228
    $this->assertUrl('admin/config/content/formats');
229
    $this->drupalGet('admin/config/content/formats/manage/' . $restricted);
230 231
    $this->assertFieldByName('filters[' . $second_filter . '][weight]', 1, 'Order saved successfully.');
    $this->assertFieldByName('filters[' . $first_filter . '][weight]', 2, 'Order saved successfully.');
232 233 234 235 236

    $elements = $this->xpath('//select[@name=:first]/following::select[@name=:second]', array(
      ':first' => 'filters[' . $second_filter . '][weight]',
      ':second' => 'filters[' . $first_filter . '][weight]',
    ));
237
    $this->assertTrue(!empty($elements), 'Reorder confirmed in admin interface.');
238

239 240
    $filter_format = entity_load('filter_format', $restricted);
    foreach ($filter_format->filters() as $filter_name => $filter) {
241 242
      if ($filter_name == $second_filter || $filter_name == $first_filter) {
        $filters[] = $filter_name;
243 244
      }
    }
245 246
    // Ensure that the second filter is now before the first filter.
    $this->assertEqual($filter_format->filters($second_filter)->weight + 1, $filter_format->filters($first_filter)->weight, 'Order confirmed in configuration.');
247 248 249

    // Add format.
    $edit = array();
250
    $edit['format'] = Unicode::strtolower($this->randomMachineName());
251
    $edit['name'] = $this->randomMachineName();
252
    $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'] = 1;
253 254
    $edit['filters[' . $second_filter . '][status]'] = TRUE;
    $edit['filters[' . $first_filter . '][status]'] = TRUE;
255
    $this->drupalPostForm('admin/config/content/formats/add', $edit, t('Save configuration'));
256
    $this->assertUrl('admin/config/content/formats');
257
    $this->assertRaw(t('Added text format %format.', array('%format' => $edit['name'])), 'New filter created.');
258

259
    filter_formats_reset();
260
    $format = entity_load('filter_format', $edit['format']);
261
    $this->assertNotNull($format, 'Format found in database.');
262
    $this->drupalGet('admin/config/content/formats/manage/' . $format->id());
263
    $this->assertFieldByName('roles[' . RoleInterface::AUTHENTICATED_ID . ']', '', 'Role found.');
264 265
    $this->assertFieldByName('filters[' . $second_filter . '][status]', '', 'Line break filter found.');
    $this->assertFieldByName('filters[' . $first_filter . '][status]', '', 'Url filter found.');
266 267

    // Disable new filter.
268
    $this->drupalPostForm('admin/config/content/formats/manage/' . $format->id() . '/disable', array(), t('Disable'));
269
    $this->assertUrl('admin/config/content/formats');
270
    $this->assertRaw(t('Disabled text format %format.', array('%format' => $edit['name'])), 'Format successfully disabled.');
271 272

    // Allow authenticated users on full HTML.
273
    $format = entity_load('filter_format', $full);
274
    $edit = array();
275 276
    $edit['roles[' . RoleInterface::ANONYMOUS_ID . ']'] = 0;
    $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'] = 1;
277
    $this->drupalPostForm('admin/config/content/formats/manage/' . $full, $edit, t('Save configuration'));
278
    $this->assertUrl('admin/config/content/formats');
279
    $this->assertRaw(t('The text format %format has been updated.', array('%format' => $format->label())), 'Full HTML format successfully updated.');
280 281

    // Switch user.
282
    $this->drupalLogin($this->webUser);
283 284

    $this->drupalGet('node/add/page');
285
    $this->assertRaw('<option value="' . $full . '">Full HTML</option>', 'Full HTML filter accessible.');
286

287
    // Use basic HTML and see if it removes tags that are not allowed.
288
    $body = '<em>' . $this->randomMachineName() . '</em>';
289 290 291 292
    $extra_text = 'text';
    $text = $body . '<random>' . $extra_text . '</random>';

    $edit = array();
293
    $edit['title[0][value]'] = $this->randomMachineName();
294 295
    $edit['body[0][value]'] = $text;
    $edit['body[0][format]'] = $basic;
296
    $this->drupalPostForm('node/add/page', $edit, t('Save'));
297
    $this->assertRaw(t('Basic page %title has been created.', array('%title' => $edit['title[0][value]'])), 'Filtered node created.');
298

299
    $node = $this->drupalGetNodeByTitle($edit['title[0][value]']);
300
    $this->assertTrue($node, 'Node found in database.');
301

302
    $this->drupalGet('node/' . $node->id());
303
    $this->assertRaw($body . $extra_text, 'Filter removed invalid tag.');
304 305

    // Use plain text and see if it escapes all tags, whether allowed or not.
306 307
    // In order to test plain text, we have to enable the hidden variable for
    // "show_fallback_format", which displays plain text in the format list.
308
    $this->config('filter.settings')
309 310
      ->set('always_show_fallback_choice', TRUE)
      ->save();
311
    $edit = array();
312
    $edit['body[0][format]'] = $plain;
313
    $this->drupalPostForm('node/' . $node->id() . '/edit', $edit, t('Save'));
314
    $this->drupalGet('node/' . $node->id());
315
    $this->assertEscaped($text, 'The "Plain text" text format escapes all HTML tags.');
316
    $this->config('filter.settings')
317 318
      ->set('always_show_fallback_choice', FALSE)
      ->save();
319 320

    // Switch user.
321
    $this->drupalLogin($this->adminUser);
322 323 324 325 326

    // Clean up.
    // Allowed tags.
    $edit = array();
    $edit['filters[filter_html][settings][allowed_html]'] = '<a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>';
327
    $this->drupalPostForm('admin/config/content/formats/manage/' . $basic, $edit, t('Save configuration'));
328
    $this->assertUrl('admin/config/content/formats');
329
    $this->drupalGet('admin/config/content/formats/manage/' . $basic);
330
    $this->assertFieldByName('filters[filter_html][settings][allowed_html]', $edit['filters[filter_html][settings][allowed_html]'], 'Changes reverted.');
331 332 333

    // Full HTML.
    $edit = array();
334
    $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'] = FALSE;
335
    $this->drupalPostForm('admin/config/content/formats/manage/' . $full, $edit, t('Save configuration'));
336
    $this->assertUrl('admin/config/content/formats');
337
    $this->assertRaw(t('The text format %format has been updated.', array('%format' => $format->label())), 'Full HTML format successfully reverted.');
338
    $this->drupalGet('admin/config/content/formats/manage/' . $full);
339
    $this->assertFieldByName('roles[' . RoleInterface::AUTHENTICATED_ID . ']', $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'], 'Changes reverted.');
340 341 342 343 344

    // Filter order.
    $edit = array();
    $edit['filters[' . $second_filter . '][weight]'] = 2;
    $edit['filters[' . $first_filter . '][weight]'] = 1;
345
    $this->drupalPostForm('admin/config/content/formats/manage/' . $basic, $edit, t('Save configuration'));
346
    $this->assertUrl('admin/config/content/formats');
347
    $this->drupalGet('admin/config/content/formats/manage/' . $basic);
348 349
    $this->assertFieldByName('filters[' . $second_filter . '][weight]', $edit['filters[' . $second_filter . '][weight]'], 'Changes reverted.');
    $this->assertFieldByName('filters[' . $first_filter . '][weight]', $edit['filters[' . $first_filter . '][weight]'], 'Changes reverted.');
350 351 352 353 354 355 356 357
  }

  /**
   * Tests the URL filter settings form is properly validated.
   */
  function testUrlFilterAdmin() {
    // The form does not save with an invalid filter URL length.
    $edit = array(
358
      'filters[filter_url][settings][filter_url_length]' => $this->randomMachineName(4),
359
    );
360
    $this->drupalPostForm('admin/config/content/formats/manage/basic_html', $edit, t('Save configuration'));
361
    $this->assertNoRaw(t('The text format %format has been updated.', array('%format' => 'Basic HTML')));
362
  }
363

364 365 366 367 368 369 370
  /**
   * Tests whether filter tips page is not HTML escaped.
   */
  function testFilterTipHtmlEscape() {
    $this->drupalLogin($this->adminUser);
    global $base_url;

371 372 373
    $site_name_with_markup = 'Filter test <script>alert(\'here\');</script> site name';
    $this->config('system.site')->set('name', $site_name_with_markup)->save();

374 375
    // It is not possible to test the whole filter tip page.
    // Therefore we test only some parts.
376
    $link = '<a href="' . $base_url . '">' . Html::escape($site_name_with_markup) . '</a>';
377
    $ampersand = '&amp;';
378 379
    $link_as_code = '<code>' . Html::escape($link) . '</code>';
    $ampersand_as_code = '<code>' . Html::escape($ampersand) . '</code>';
380 381 382 383 384 385 386 387 388

    $this->drupalGet('filter/tips');

    $this->assertRaw('<td class="type">' . $link_as_code . '</td>');
    $this->assertRaw('<td class="get">' . $link . '</td>');
    $this->assertRaw('<td class="type">' . $ampersand_as_code . '</td>');
    $this->assertRaw('<td class="get">' . $ampersand . '</td>');
  }

389
}