
368 lines
10 KiB

* @copyright Copyright (c) 2016 Lukas Reschke <>
* @license GNU AGPL version 3 or any later version
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, either version 3 of the
* License, or (at your option) any later version.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* GNU Affero General Public License for more details.
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <>.
namespace OCA\User_SAML\Tests\Controller;
use OCA\User_SAML\Controller\SAMLController;
use OCA\User_SAML\Exceptions\NoUserFoundException;
use OCA\User_SAML\SAMLSettings;
use OCA\User_SAML\UserBackend;
use OCA\User_SAML\UserData;
use OCA\User_SAML\UserResolver;
use OCP\AppFramework\Http\RedirectResponse;
use OCP\AppFramework\Http\TemplateResponse;
use OCP\IConfig;
use OCP\IL10N;
use OCP\ILogger;
use OCP\IRequest;
use OCP\ISession;
use OCP\IURLGenerator;
use OCP\IUser;
use OCP\IUserSession;
use PHPUnit\Framework\MockObject\MockObject;
use OCP\Security\ICrypto;
use Test\TestCase;
class SAMLControllerTest extends TestCase {
/** @var UserResolver|\PHPUnit\Framework\MockObject\MockObject */
protected $userResolver;
/** @var UserData|\PHPUnit\Framework\MockObject\MockObject */
private $userData;
/** @var IRequest|\PHPUnit_Framework_MockObject_MockObject */
private $request;
/** @var ISession|\PHPUnit_Framework_MockObject_MockObject */
private $session;
/** @var IUserSession|\PHPUnit_Framework_MockObject_MockObject */
private $userSession;
/** @var SAMLSettings|\PHPUnit_Framework_MockObject_MockObject*/
private $samlSettings;
/** @var UserBackend|\PHPUnit_Framework_MockObject_MockObject */
private $userBackend;
/** @var IConfig|\PHPUnit_Framework_MockObject_MockObject */
private $config;
/** @var IURLGenerator|\PHPUnit_Framework_MockObject_MockObject */
private $urlGenerator;
/** @var ILogger|\PHPUnit_Framework_MockObject_MockObject */
private $logger;
/** @var IL10N|\PHPUnit_Framework_MockObject_MockObject */
private $l;
/** @var ICrypto|MockObject */
private $crypto;
/** @var SAMLController */
private $samlController;
protected function setUp(): void {
$this->request = $this->createMock(IRequest::class);
$this->session = $this->createMock(ISession::class);
$this->userSession = $this->createMock(IUserSession::class);
$this->samlSettings = $this->createMock(SAMLSettings::class);
$this->userBackend = $this->createMock(UserBackend::class);
$this->config = $this->createMock(IConfig::class);
$this->urlGenerator = $this->createMock(IURLGenerator::class);
$this->logger = $this->createMock(ILogger::class);
$this->l = $this->createMock(IL10N::class);
$this->userResolver = $this->createMock(UserResolver::class);
$this->userData = $this->createMock(UserData::class);
$this->crypto = $this->createMock(ICrypto::class);
function($param) {
return $param;
->willReturnCallback(function($key, $default) {
return $default;
$this->samlController = new SAMLController(
* @expectedExceptionMessage Type of "UnknownValue" is not supported for user_saml
* @expectedException \Exception
public function testLoginWithInvalidAppValue() {
->with('user_saml', 'type')
public function samlUserDataProvider() {
$userNotExisting = 0;
$userExisting = 1;
$userLazyExisting = 2;
$apDisabled = 0;
$apEnabled = 1;
$apEnabledUnsuccessful = 2;
return [
[ # 0 - Not existing uid in settings array
'foo' => 'bar',
'bar' => 'foo',
[ # 1 - existing user
'foo' => 'bar',
'bar' => 'foo',
'uid' => 'MyUid',
[ # 2 - existing user and uid attribute in array
'foo' => 'bar',
'bar' => 'foo',
'uid' => ['MyUid'],
[ # 3 - Not existing user with provisioning
'foo' => 'bar',
'bar' => 'foo',
'uid' => 'MyUid',
[ # 4 - Not existing user with malfunctioning backend
'foo' => 'bar',
'bar' => 'foo',
'uid' => 'MyUid',
[ # 5 - Not existing user without provisioning
'foo' => 'bar',
'bar' => 'foo',
'uid' => 'MyUid',
[ # 6 - Not yet mapped user without provisioning
'foo' => 'bar',
'bar' => 'foo',
'uid' => 'MyUid',
* @dataProvider samlUserDataProvider
public function testLoginWithEnvVariable(array $samlUserData, string $redirect, int $userState, int $autoProvision) {
->willReturnCallback(function (string $app, string $key) {
if($app === 'user_saml') {
if($key === 'type') {
return 'environment-variable';
if($key === 'general-uid_mapping') {
return 'uid';
return null;
->expects(isset($samlUserData['uid']) ? $this->any() : $this->never())
->willReturn($userState > 0 ? 'MyUid' : '');
if(strpos($redirect, 'notProvisioned') !== false) {
} else {
->willReturn($userState === 1);
if(isset($samlUserData['uid']) && !($userState === 0 && $autoProvision === 0)) {
/** @var IUser|MockObject $user */
$user = $this->createMock(IUser::class);
$im = $this->userResolver
if($autoProvision < 2) {
} else {
$im->willThrowException(new NoUserFoundException());
->expects($this->exactly((int)($autoProvision < 2)))
if($userState === 0) {
->with('MyUid', true)
->willThrowException(new NoUserFoundException());
} else if($userState === 2) {
->with('MyUid', true)
->willReturn(isset($samlUserData['uid']) ? 'MyUid' : '');
->expects($autoProvision > 0 ? $this->once() : $this->any())
->willReturn($autoProvision > 0);
->expects($this->exactly(min(1, $autoProvision)))
$expected = new RedirectResponse($redirect);
$result = $this->samlController->login(1);
$this->assertEquals($expected, $result);
public function testNotProvisioned() {
$expected = new TemplateResponse('user_saml', 'notProvisioned', [], 'guest');
$this->assertEquals($expected, $this->samlController->notProvisioned());
* @dataProvider dataTestGenericError
* @param string $messageSend
* @param string $messageExpected
public function testGenericError($messageSend, $messageExpected) {
$expected = new TemplateResponse('user_saml', 'error', ['message' => $messageExpected], 'guest');
$this->assertEquals($expected, $this->samlController->genericError($messageSend));
public function dataTestGenericError() {
return [
['messageSend' => '', 'messageExpected' => 'Unknown error, please check the log file for more details.'],
['messageSend' => 'test message', 'messageExpected' => 'test message'],
* @dataProvider dataTestGetSSODisplayName
* @param string $configuredDisplayName
* @param string $expected
public function testGetSSODisplayName($configuredDisplayName, $expected) {
$result = $this->invokePrivate($this->samlController, 'getSSODisplayName', [$configuredDisplayName]);
$this->assertSame($expected, $result);
public function dataTestGetSSODisplayName() {
return [
['My identity provider', 'My identity provider'],
['', 'SSO & SAML log in']