search_controller_test.rb 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453
  1. # encoding: utf-8
  2. require 'test_helper'
  3. class SearchControllerTest < ActionDispatch::IntegrationTest
  4. setup do
  5. # set accept header
  6. @headers = { 'ACCEPT' => 'application/json', 'CONTENT_TYPE' => 'application/json' }
  7. # create agent
  8. roles = Role.where( name: %w(Admin Agent) )
  9. groups = Group.all
  10. UserInfo.current_user_id = 1
  11. @admin = User.create_or_update(
  12. login: 'search-admin',
  13. firstname: 'Search',
  14. lastname: 'Admin',
  15. email: 'search-admin@example.com',
  16. password: 'adminpw',
  17. active: true,
  18. roles: roles,
  19. groups: groups,
  20. )
  21. # create agent
  22. roles = Role.where( name: 'Agent' )
  23. @agent = User.create_or_update(
  24. login: 'search-agent@example.com',
  25. firstname: 'Search 1234',
  26. lastname: 'Agent',
  27. email: 'search-agent@example.com',
  28. password: 'agentpw',
  29. active: true,
  30. roles: roles,
  31. groups: groups,
  32. )
  33. # create customer without org
  34. roles = Role.where( name: 'Customer' )
  35. @customer_without_org = User.create_or_update(
  36. login: 'search-customer1@example.com',
  37. firstname: 'Search',
  38. lastname: 'Customer1',
  39. email: 'search-customer1@example.com',
  40. password: 'customer1pw',
  41. active: true,
  42. roles: roles,
  43. )
  44. # create orgs
  45. @organization = Organization.create_or_update(
  46. name: 'Rest Org',
  47. )
  48. @organization2 = Organization.create_or_update(
  49. name: 'Rest Org #2',
  50. )
  51. @organization3 = Organization.create_or_update(
  52. name: 'Rest Org #3',
  53. )
  54. # create customer with org
  55. @customer_with_org2 = User.create_or_update(
  56. login: 'search-customer2@example.com',
  57. firstname: 'Search',
  58. lastname: 'Customer2',
  59. email: 'search-customer2@example.com',
  60. password: 'customer2pw',
  61. active: true,
  62. roles: roles,
  63. organization_id: @organization.id,
  64. )
  65. @customer_with_org3 = User.create_or_update(
  66. login: 'search-customer3@example.com',
  67. firstname: 'Search',
  68. lastname: 'Customer3',
  69. email: 'search-customer3@example.com',
  70. password: 'customer3pw',
  71. active: true,
  72. roles: roles,
  73. organization_id: @organization.id,
  74. )
  75. Ticket.all.destroy_all
  76. @ticket1 = Ticket.create(
  77. title: 'test 1234-1',
  78. group: Group.lookup( name: 'Users'),
  79. customer_id: @customer_without_org.id,
  80. state: Ticket::State.lookup( name: 'new' ),
  81. priority: Ticket::Priority.lookup( name: '2 normal' ),
  82. updated_by_id: 1,
  83. created_by_id: 1,
  84. )
  85. @article1 = Ticket::Article.create(
  86. ticket_id: @ticket1.id,
  87. from: 'some_sender1@example.com',
  88. to: 'some_recipient1@example.com',
  89. subject: 'some subject1',
  90. message_id: 'some@id',
  91. body: 'some message1',
  92. internal: false,
  93. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  94. type: Ticket::Article::Type.where(name: 'email').first,
  95. updated_by_id: 1,
  96. created_by_id: 1,
  97. )
  98. sleep 1
  99. @ticket2 = Ticket.create(
  100. title: 'test 1234-2',
  101. group: Group.lookup( name: 'Users'),
  102. customer_id: @customer_with_org2.id,
  103. state: Ticket::State.lookup( name: 'new' ),
  104. priority: Ticket::Priority.lookup( name: '2 normal' ),
  105. updated_by_id: 1,
  106. created_by_id: 1,
  107. )
  108. @article2 = Ticket::Article.create(
  109. ticket_id: @ticket2.id,
  110. from: 'some_sender2@example.com',
  111. to: 'some_recipient2@example.com',
  112. subject: 'some subject2',
  113. message_id: 'some@id',
  114. body: 'some message2',
  115. internal: false,
  116. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  117. type: Ticket::Article::Type.where(name: 'email').first,
  118. updated_by_id: 1,
  119. created_by_id: 1,
  120. )
  121. sleep 1
  122. @ticket3 = Ticket.create(
  123. title: 'test 1234-2',
  124. group: Group.lookup( name: 'Users'),
  125. customer_id: @customer_with_org3.id,
  126. state: Ticket::State.lookup( name: 'new' ),
  127. priority: Ticket::Priority.lookup( name: '2 normal' ),
  128. updated_by_id: 1,
  129. created_by_id: 1,
  130. )
  131. @article3 = Ticket::Article.create(
  132. ticket_id: @ticket3.id,
  133. from: 'some_sender3@example.com',
  134. to: 'some_recipient3@example.com',
  135. subject: 'some subject3',
  136. message_id: 'some@id',
  137. body: 'some message3',
  138. internal: false,
  139. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  140. type: Ticket::Article::Type.where(name: 'email').first,
  141. updated_by_id: 1,
  142. created_by_id: 1,
  143. )
  144. # configure es
  145. if ENV['ES_URL']
  146. #fail "ERROR: Need ES_URL - hint ES_URL='http://172.0.0.1:9200'"
  147. Setting.set('es_url', ENV['ES_URL'])
  148. # Setting.set('es_url', 'http://172.0.0.1:9200')
  149. # Setting.set('es_index', 'estest.local_zammad')
  150. # Setting.set('es_user', 'elasticsearch')
  151. # Setting.set('es_password', 'zammad')
  152. # set max attachment size in mb
  153. Setting.set('es_attachment_max_size_in_mb', 1 )
  154. if ENV['ES_INDEX']
  155. #fail "ERROR: Need ES_INDEX - hint ES_INDEX='estest.local_zammad'"
  156. Setting.set('es_index', ENV['ES_INDEX'])
  157. end
  158. # drop/create indexes
  159. #Rake::Task["searchindex:drop"].execute
  160. #Rake::Task["searchindex:create"].execute
  161. system('rake searchindex:rebuild')
  162. # execute background jobs
  163. Scheduler.worker(true)
  164. sleep 6
  165. end
  166. end
  167. test 'settings index with nobody' do
  168. params = {
  169. query: 'test 1234',
  170. limit: 2,
  171. }
  172. post '/api/v1/search/ticket', params.to_json, @headers
  173. assert_response(401)
  174. result = JSON.parse(@response.body)
  175. assert_equal(result.class, Hash)
  176. assert_not(result.empty?)
  177. post '/api/v1/search/user', params.to_json, @headers
  178. assert_response(401)
  179. result = JSON.parse(@response.body)
  180. assert_equal(result.class, Hash)
  181. assert_not(result.empty?)
  182. post '/api/v1/search', params.to_json, @headers
  183. assert_response(401)
  184. result = JSON.parse(@response.body)
  185. assert_equal(result.class, Hash)
  186. assert_not(result.empty?)
  187. end
  188. test 'settings index with admin' do
  189. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-admin@example.com', 'adminpw')
  190. params = {
  191. query: '1234*',
  192. limit: 1,
  193. }
  194. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  195. assert_response(200)
  196. result = JSON.parse(@response.body)
  197. assert_equal(Hash, result.class)
  198. assert(result)
  199. assert_equal('Ticket', result['result'][0]['type'])
  200. assert_equal(@ticket3.id, result['result'][0]['id'])
  201. assert_equal('User', result['result'][1]['type'])
  202. assert_equal(@agent.id, result['result'][1]['id'])
  203. assert_not(result['result'][2])
  204. params = {
  205. query: '1234*',
  206. limit: 10,
  207. }
  208. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  209. assert_response(200)
  210. result = JSON.parse(@response.body)
  211. assert_equal(Hash, result.class)
  212. assert(result)
  213. assert_equal('Ticket', result['result'][0]['type'])
  214. assert_equal(@ticket3.id, result['result'][0]['id'])
  215. assert_equal('Ticket', result['result'][1]['type'])
  216. assert_equal(@ticket2.id, result['result'][1]['id'])
  217. assert_equal('Ticket', result['result'][2]['type'])
  218. assert_equal(@ticket1.id, result['result'][2]['id'])
  219. assert_equal('User', result['result'][3]['type'])
  220. assert_equal(@agent.id, result['result'][3]['id'])
  221. assert_not(result['result'][4])
  222. params = {
  223. query: '1234*',
  224. limit: 10,
  225. }
  226. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  227. assert_response(200)
  228. result = JSON.parse(@response.body)
  229. assert_equal(Hash, result.class)
  230. assert(result)
  231. assert_equal('Ticket', result['result'][0]['type'])
  232. assert_equal(@ticket3.id, result['result'][0]['id'])
  233. assert_equal('Ticket', result['result'][1]['type'])
  234. assert_equal(@ticket2.id, result['result'][1]['id'])
  235. assert_equal('Ticket', result['result'][2]['type'])
  236. assert_equal(@ticket1.id, result['result'][2]['id'])
  237. assert_not(result['result'][3])
  238. params = {
  239. query: '1234*',
  240. limit: 10,
  241. }
  242. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  243. assert_response(200)
  244. result = JSON.parse(@response.body)
  245. assert_equal(Hash, result.class)
  246. assert_equal('User', result['result'][0]['type'])
  247. assert_equal(@agent.id, result['result'][0]['id'])
  248. assert_not(result['result'][1])
  249. end
  250. test 'settings index with agent' do
  251. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-agent@example.com', 'agentpw')
  252. params = {
  253. query: '1234*',
  254. limit: 1,
  255. }
  256. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  257. assert_response(200)
  258. result = JSON.parse(@response.body)
  259. assert_equal(Hash, result.class)
  260. assert(result)
  261. assert_equal('Ticket', result['result'][0]['type'])
  262. assert_equal(@ticket3.id, result['result'][0]['id'])
  263. assert_equal('User', result['result'][1]['type'])
  264. assert_equal(@agent.id, result['result'][1]['id'])
  265. assert_not(result['result'][2])
  266. params = {
  267. query: '1234*',
  268. limit: 10,
  269. }
  270. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  271. assert_response(200)
  272. result = JSON.parse(@response.body)
  273. assert_equal(Hash, result.class)
  274. assert(result)
  275. assert_equal('Ticket', result['result'][0]['type'])
  276. assert_equal(@ticket3.id, result['result'][0]['id'])
  277. assert_equal('Ticket', result['result'][1]['type'])
  278. assert_equal(@ticket2.id, result['result'][1]['id'])
  279. assert_equal('Ticket', result['result'][2]['type'])
  280. assert_equal(@ticket1.id, result['result'][2]['id'])
  281. assert_equal('User', result['result'][3]['type'])
  282. assert_equal(@agent.id, result['result'][3]['id'])
  283. assert_not(result['result'][4])
  284. params = {
  285. query: '1234*',
  286. limit: 10,
  287. }
  288. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  289. assert_response(200)
  290. result = JSON.parse(@response.body)
  291. assert_equal(Hash, result.class)
  292. assert(result)
  293. assert_equal('Ticket', result['result'][0]['type'])
  294. assert_equal(@ticket3.id, result['result'][0]['id'])
  295. assert_equal('Ticket', result['result'][1]['type'])
  296. assert_equal(@ticket2.id, result['result'][1]['id'])
  297. assert_equal('Ticket', result['result'][2]['type'])
  298. assert_equal(@ticket1.id, result['result'][2]['id'])
  299. assert_not(result['result'][3])
  300. params = {
  301. query: '1234*',
  302. limit: 10,
  303. }
  304. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  305. assert_response(200)
  306. result = JSON.parse(@response.body)
  307. assert_equal(Hash, result.class)
  308. assert_equal('User', result['result'][0]['type'])
  309. assert_equal(@agent.id, result['result'][0]['id'])
  310. assert_not(result['result'][1])
  311. end
  312. test 'settings index with customer 1' do
  313. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-customer1@example.com', 'customer1pw')
  314. params = {
  315. query: '1234*',
  316. limit: 10,
  317. }
  318. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  319. assert_response(200)
  320. result = JSON.parse(@response.body)
  321. assert_equal(Hash, result.class)
  322. assert(result)
  323. assert_equal('Ticket', result['result'][0]['type'])
  324. assert_equal(@ticket1.id, result['result'][0]['id'])
  325. assert_not(result['result'][1])
  326. params = {
  327. query: '1234*',
  328. limit: 10,
  329. }
  330. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  331. assert_response(200)
  332. result = JSON.parse(@response.body)
  333. assert_equal(Hash, result.class)
  334. assert(result)
  335. assert_equal('Ticket', result['result'][0]['type'])
  336. assert_equal(@ticket1.id, result['result'][0]['id'])
  337. assert_not(result['result'][1])
  338. params = {
  339. query: '1234*',
  340. limit: 10,
  341. }
  342. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  343. assert_response(200)
  344. result = JSON.parse(@response.body)
  345. assert_equal(Hash, result.class)
  346. assert_not(result['result'][0])
  347. end
  348. test 'settings index with customer 2' do
  349. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-customer2@example.com', 'customer2pw')
  350. params = {
  351. query: '1234*',
  352. limit: 10,
  353. }
  354. post '/api/v1/search', params.to_json, @headers.merge('Authorization' => credentials)
  355. assert_response(200)
  356. result = JSON.parse(@response.body)
  357. assert_equal(Hash, result.class)
  358. assert(result)
  359. assert_equal('Ticket', result['result'][0]['type'])
  360. assert_equal(@ticket3.id, result['result'][0]['id'])
  361. assert_equal('Ticket', result['result'][1]['type'])
  362. assert_equal(@ticket2.id, result['result'][1]['id'])
  363. assert_not(result['result'][2])
  364. params = {
  365. query: '1234*',
  366. limit: 10,
  367. }
  368. post '/api/v1/search/ticket', params.to_json, @headers.merge('Authorization' => credentials)
  369. assert_response(200)
  370. result = JSON.parse(@response.body)
  371. assert_equal(Hash, result.class)
  372. assert(result)
  373. assert_equal('Ticket', result['result'][0]['type'])
  374. assert_equal(@ticket3.id, result['result'][0]['id'])
  375. assert_equal('Ticket', result['result'][1]['type'])
  376. assert_equal(@ticket2.id, result['result'][1]['id'])
  377. assert_not(result['result'][2])
  378. params = {
  379. query: '1234*',
  380. limit: 10,
  381. }
  382. post '/api/v1/search/user', params.to_json, @headers.merge('Authorization' => credentials)
  383. assert_response(200)
  384. result = JSON.parse(@response.body)
  385. assert_equal(Hash, result.class)
  386. assert_not(result['result'][0])
  387. end
  388. end