search_controller_test.rb 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469
  1. # encoding: utf-8
  2. require 'test_helper'
  3. class SearchControllerTest < ActionDispatch::IntegrationTest
  4. def base_data
  5. # clear cache
  6. Cache.clear
  7. # remove background jobs
  8. Delayed::Job.destroy_all
  9. # set current user
  10. UserInfo.current_user_id = 1
  11. # set accept header
  12. @headers = { 'ACCEPT' => 'application/json', 'CONTENT_TYPE' => 'application/json' }
  13. # create agent
  14. roles = Role.where(name: %w(Admin Agent))
  15. groups = Group.all
  16. @admin = User.create_or_update(
  17. login: 'search-admin',
  18. firstname: 'Search',
  19. lastname: 'Admin',
  20. email: 'search-admin@example.com',
  21. password: 'adminpw',
  22. active: true,
  23. roles: roles,
  24. groups: groups,
  25. )
  26. # create agent
  27. roles = Role.where(name: 'Agent')
  28. @agent = User.create_or_update(
  29. login: 'search-agent@example.com',
  30. firstname: 'Search 1234',
  31. lastname: 'Agent',
  32. email: 'search-agent@example.com',
  33. password: 'agentpw',
  34. active: true,
  35. roles: roles,
  36. groups: groups,
  37. )
  38. # create customer without org
  39. roles = Role.where(name: 'Customer')
  40. @customer_without_org = User.create_or_update(
  41. login: 'search-customer1@example.com',
  42. firstname: 'Search',
  43. lastname: 'Customer1',
  44. email: 'search-customer1@example.com',
  45. password: 'customer1pw',
  46. active: true,
  47. roles: roles,
  48. )
  49. # create orgs
  50. @organization = Organization.create_or_update(
  51. name: 'Rest Org',
  52. )
  53. @organization2 = Organization.create_or_update(
  54. name: 'Rest Org #2',
  55. )
  56. @organization3 = Organization.create_or_update(
  57. name: 'Rest Org #3',
  58. )
  59. # create customer with org
  60. @customer_with_org2 = User.create_or_update(
  61. login: 'search-customer2@example.com',
  62. firstname: 'Search',
  63. lastname: 'Customer2',
  64. email: 'search-customer2@example.com',
  65. password: 'customer2pw',
  66. active: true,
  67. roles: roles,
  68. organization_id: @organization.id,
  69. )
  70. @customer_with_org3 = User.create_or_update(
  71. login: 'search-customer3@example.com',
  72. firstname: 'Search',
  73. lastname: 'Customer3',
  74. email: 'search-customer3@example.com',
  75. password: 'customer3pw',
  76. active: true,
  77. roles: roles,
  78. organization_id: @organization.id,
  79. )
  80. Ticket.all.destroy_all
  81. @ticket1 = Ticket.create(
  82. title: 'test 1234-1',
  83. group: Group.lookup(name: 'Users'),
  84. customer_id: @customer_without_org.id,
  85. state: Ticket::State.lookup(name: 'new'),
  86. priority: Ticket::Priority.lookup(name: '2 normal'),
  87. updated_by_id: 1,
  88. created_by_id: 1,
  89. )
  90. @article1 = Ticket::Article.create(
  91. ticket_id: @ticket1.id,
  92. from: 'some_sender1@example.com',
  93. to: 'some_recipient1@example.com',
  94. subject: 'some subject1',
  95. message_id: 'some@id',
  96. body: 'some message1',
  97. internal: false,
  98. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  99. type: Ticket::Article::Type.where(name: 'email').first,
  100. updated_by_id: 1,
  101. created_by_id: 1,
  102. )
  103. sleep 1
  104. @ticket2 = Ticket.create(
  105. title: 'test 1234-2',
  106. group: Group.lookup(name: 'Users'),
  107. customer_id: @customer_with_org2.id,
  108. state: Ticket::State.lookup(name: 'new'),
  109. priority: Ticket::Priority.lookup(name: '2 normal'),
  110. updated_by_id: 1,
  111. created_by_id: 1,
  112. )
  113. @article2 = Ticket::Article.create(
  114. ticket_id: @ticket2.id,
  115. from: 'some_sender2@example.com',
  116. to: 'some_recipient2@example.com',
  117. subject: 'some subject2',
  118. message_id: 'some@id',
  119. body: 'some message2',
  120. internal: false,
  121. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  122. type: Ticket::Article::Type.where(name: 'email').first,
  123. updated_by_id: 1,
  124. created_by_id: 1,
  125. )
  126. sleep 1
  127. @ticket3 = Ticket.create(
  128. title: 'test 1234-2',
  129. group: Group.lookup(name: 'Users'),
  130. customer_id: @customer_with_org3.id,
  131. state: Ticket::State.lookup(name: 'new'),
  132. priority: Ticket::Priority.lookup(name: '2 normal'),
  133. updated_by_id: 1,
  134. created_by_id: 1,
  135. )
  136. @article3 = Ticket::Article.create(
  137. ticket_id: @ticket3.id,
  138. from: 'some_sender3@example.com',
  139. to: 'some_recipient3@example.com',
  140. subject: 'some subject3',
  141. message_id: 'some@id',
  142. body: 'some message3',
  143. internal: false,
  144. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  145. type: Ticket::Article::Type.where(name: 'email').first,
  146. updated_by_id: 1,
  147. created_by_id: 1,
  148. )
  149. # configure es
  150. if ENV['ES_URL']
  151. #fail "ERROR: Need ES_URL - hint ES_URL='http://172.0.0.1:9200'"
  152. Setting.set('es_url', ENV['ES_URL'])
  153. # Setting.set('es_url', 'http://172.0.0.1:9200')
  154. # Setting.set('es_index', 'estest.local_zammad')
  155. # Setting.set('es_user', 'elasticsearch')
  156. # Setting.set('es_password', 'zammad')
  157. # set max attachment size in mb
  158. Setting.set('es_attachment_max_size_in_mb', 1)
  159. if ENV['ES_INDEX']
  160. #fail "ERROR: Need ES_INDEX - hint ES_INDEX='estest.local_zammad'"
  161. Setting.set('es_index', ENV['ES_INDEX'])
  162. end
  163. # drop/create indexes
  164. #Rake::Task["searchindex:drop"].execute
  165. #Rake::Task["searchindex:create"].execute
  166. system('rake searchindex:rebuild')
  167. # execute background jobs
  168. Scheduler.worker(true)
  169. sleep 6
  170. end
  171. end
  172. test 'settings index with nobody' do
  173. base_data
  174. params = {
  175. query: 'test 1234',
  176. limit: 2,
  177. }
  178. post '/api/v1/search/ticket', params.to_json, @headers
  179. assert_response(401)
  180. result = JSON.parse(@response.body)
  181. assert_equal(Hash, result.class)
  182. assert_not(result.empty?)
  183. assert_equal('authentication failed', result['error'])
  184. post '/api/v1/search/user', params.to_json, @headers
  185. assert_response(401)
  186. result = JSON.parse(@response.body)
  187. assert_equal(Hash, result.class)
  188. assert_not(result.empty?)
  189. assert_equal('authentication failed', result['error'])
  190. post '/api/v1/search', params.to_json, @headers
  191. assert_response(401)
  192. result = JSON.parse(@response.body)
  193. assert_equal(Hash, result.class)
  194. assert_not(result.empty?)
  195. assert_equal('authentication failed', result['error'])
  196. end
  197. test 'settings index with admin' do
  198. base_data
  199. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-admin@example.com', 'adminpw')
  200. params = {
  201. query: '1234*',
  202. limit: 1,
  203. }
  204. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  205. assert_response(200)
  206. result = JSON.parse(@response.body)
  207. assert_equal(Hash, result.class)
  208. assert(result)
  209. assert_equal('Ticket', result['result'][0]['type'])
  210. assert_equal(@ticket3.id, result['result'][0]['id'])
  211. assert_equal('User', result['result'][1]['type'])
  212. assert_equal(@agent.id, result['result'][1]['id'])
  213. assert_not(result['result'][2])
  214. params = {
  215. query: '1234*',
  216. limit: 10,
  217. }
  218. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  219. assert_response(200)
  220. result = JSON.parse(@response.body)
  221. assert_equal(Hash, result.class)
  222. assert(result)
  223. assert_equal('Ticket', result['result'][0]['type'])
  224. assert_equal(@ticket3.id, result['result'][0]['id'])
  225. assert_equal('Ticket', result['result'][1]['type'])
  226. assert_equal(@ticket2.id, result['result'][1]['id'])
  227. assert_equal('Ticket', result['result'][2]['type'])
  228. assert_equal(@ticket1.id, result['result'][2]['id'])
  229. assert_equal('User', result['result'][3]['type'])
  230. assert_equal(@agent.id, result['result'][3]['id'])
  231. assert_not(result['result'][4])
  232. params = {
  233. query: '1234*',
  234. limit: 10,
  235. }
  236. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  237. assert_response(200)
  238. result = JSON.parse(@response.body)
  239. assert_equal(Hash, result.class)
  240. assert(result)
  241. assert_equal('Ticket', result['result'][0]['type'])
  242. assert_equal(@ticket3.id, result['result'][0]['id'])
  243. assert_equal('Ticket', result['result'][1]['type'])
  244. assert_equal(@ticket2.id, result['result'][1]['id'])
  245. assert_equal('Ticket', result['result'][2]['type'])
  246. assert_equal(@ticket1.id, result['result'][2]['id'])
  247. assert_not(result['result'][3])
  248. params = {
  249. query: '1234*',
  250. limit: 10,
  251. }
  252. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  253. assert_response(200)
  254. result = JSON.parse(@response.body)
  255. assert_equal(Hash, result.class)
  256. assert_equal('User', result['result'][0]['type'])
  257. assert_equal(@agent.id, result['result'][0]['id'])
  258. assert_not(result['result'][1])
  259. end
  260. test 'settings index with agent' do
  261. base_data
  262. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-agent@example.com', 'agentpw')
  263. params = {
  264. query: '1234*',
  265. limit: 1,
  266. }
  267. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  268. assert_response(200)
  269. result = JSON.parse(@response.body)
  270. assert_equal(Hash, result.class)
  271. assert(result)
  272. assert_equal('Ticket', result['result'][0]['type'])
  273. assert_equal(@ticket3.id, result['result'][0]['id'])
  274. assert_equal('User', result['result'][1]['type'])
  275. assert_equal(@agent.id, result['result'][1]['id'])
  276. assert_not(result['result'][2])
  277. params = {
  278. query: '1234*',
  279. limit: 10,
  280. }
  281. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  282. assert_response(200)
  283. result = JSON.parse(@response.body)
  284. assert_equal(Hash, result.class)
  285. assert(result)
  286. assert_equal('Ticket', result['result'][0]['type'])
  287. assert_equal(@ticket3.id, result['result'][0]['id'])
  288. assert_equal('Ticket', result['result'][1]['type'])
  289. assert_equal(@ticket2.id, result['result'][1]['id'])
  290. assert_equal('Ticket', result['result'][2]['type'])
  291. assert_equal(@ticket1.id, result['result'][2]['id'])
  292. assert_equal('User', result['result'][3]['type'])
  293. assert_equal(@agent.id, result['result'][3]['id'])
  294. assert_not(result['result'][4])
  295. params = {
  296. query: '1234*',
  297. limit: 10,
  298. }
  299. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  300. assert_response(200)
  301. result = JSON.parse(@response.body)
  302. assert_equal(Hash, result.class)
  303. assert(result)
  304. assert_equal('Ticket', result['result'][0]['type'])
  305. assert_equal(@ticket3.id, result['result'][0]['id'])
  306. assert_equal('Ticket', result['result'][1]['type'])
  307. assert_equal(@ticket2.id, result['result'][1]['id'])
  308. assert_equal('Ticket', result['result'][2]['type'])
  309. assert_equal(@ticket1.id, result['result'][2]['id'])
  310. assert_not(result['result'][3])
  311. params = {
  312. query: '1234*',
  313. limit: 10,
  314. }
  315. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  316. assert_response(200)
  317. result = JSON.parse(@response.body)
  318. assert_equal(Hash, result.class)
  319. assert_equal('User', result['result'][0]['type'])
  320. assert_equal(@agent.id, result['result'][0]['id'])
  321. assert_not(result['result'][1])
  322. end
  323. test 'settings index with customer 1' do
  324. base_data
  325. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-customer1@example.com', 'customer1pw')
  326. params = {
  327. query: '1234*',
  328. limit: 10,
  329. }
  330. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  331. assert_response(200)
  332. result = JSON.parse(@response.body)
  333. assert_equal(Hash, result.class)
  334. assert(result)
  335. assert_equal('Ticket', result['result'][0]['type'])
  336. assert_equal(@ticket1.id, result['result'][0]['id'])
  337. assert_not(result['result'][1])
  338. params = {
  339. query: '1234*',
  340. limit: 10,
  341. }
  342. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  343. assert_response(200)
  344. result = JSON.parse(@response.body)
  345. assert_equal(Hash, result.class)
  346. assert(result)
  347. assert_equal('Ticket', result['result'][0]['type'])
  348. assert_equal(@ticket1.id, result['result'][0]['id'])
  349. assert_not(result['result'][1])
  350. params = {
  351. query: '1234*',
  352. limit: 10,
  353. }
  354. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  355. assert_response(200)
  356. result = JSON.parse(@response.body)
  357. assert_equal(Hash, result.class)
  358. assert_not(result['result'][0])
  359. end
  360. test 'settings index with customer 2' do
  361. base_data
  362. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-customer2@example.com', 'customer2pw')
  363. params = {
  364. query: '1234*',
  365. limit: 10,
  366. }
  367. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  368. assert_response(200)
  369. result = JSON.parse(@response.body)
  370. assert_equal(Hash, result.class)
  371. assert(result)
  372. assert_equal('Ticket', result['result'][0]['type'])
  373. assert_equal(@ticket3.id, result['result'][0]['id'])
  374. assert_equal('Ticket', result['result'][1]['type'])
  375. assert_equal(@ticket2.id, result['result'][1]['id'])
  376. assert_not(result['result'][2])
  377. params = {
  378. query: '1234*',
  379. limit: 10,
  380. }
  381. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  382. assert_response(200)
  383. result = JSON.parse(@response.body)
  384. assert_equal(Hash, result.class)
  385. assert(result)
  386. assert_equal('Ticket', result['result'][0]['type'])
  387. assert_equal(@ticket3.id, result['result'][0]['id'])
  388. assert_equal('Ticket', result['result'][1]['type'])
  389. assert_equal(@ticket2.id, result['result'][1]['id'])
  390. assert_not(result['result'][2])
  391. params = {
  392. query: '1234*',
  393. limit: 10,
  394. }
  395. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  396. assert_response(200)
  397. result = JSON.parse(@response.body)
  398. assert_equal(Hash, result.class)
  399. assert_not(result['result'][0])
  400. end
  401. end