search_controller_test.rb 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447
  1. # encoding: utf-8
  2. require 'test_helper'
  3. require 'rake'
  4. class SearchControllerTest < ActionDispatch::IntegrationTest
  5. setup do
  6. # set current user
  7. UserInfo.current_user_id = 1
  8. # set accept header
  9. @headers = { 'ACCEPT' => 'application/json', 'CONTENT_TYPE' => 'application/json' }
  10. # create agent
  11. roles = Role.where(name: %w(Admin Agent))
  12. groups = Group.all
  13. @admin = User.create_or_update(
  14. login: 'search-admin',
  15. firstname: 'Search',
  16. lastname: 'Admin',
  17. email: 'search-admin@example.com',
  18. password: 'adminpw',
  19. active: true,
  20. roles: roles,
  21. groups: groups,
  22. )
  23. # create agent
  24. roles = Role.where(name: 'Agent')
  25. @agent = User.create_or_update(
  26. login: 'search-agent@example.com',
  27. firstname: 'Search 1234',
  28. lastname: 'Agent',
  29. email: 'search-agent@example.com',
  30. password: 'agentpw',
  31. active: true,
  32. roles: roles,
  33. groups: groups,
  34. )
  35. # create customer without org
  36. roles = Role.where(name: 'Customer')
  37. @customer_without_org = User.create_or_update(
  38. login: 'search-customer1@example.com',
  39. firstname: 'Search',
  40. lastname: 'Customer1',
  41. email: 'search-customer1@example.com',
  42. password: 'customer1pw',
  43. active: true,
  44. roles: roles,
  45. )
  46. # create orgs
  47. @organization = Organization.create_or_update(
  48. name: 'Rest Org',
  49. )
  50. @organization2 = Organization.create_or_update(
  51. name: 'Rest Org #2',
  52. )
  53. @organization3 = Organization.create_or_update(
  54. name: 'Rest Org #3',
  55. )
  56. # create customer with org
  57. @customer_with_org2 = User.create_or_update(
  58. login: 'search-customer2@example.com',
  59. firstname: 'Search',
  60. lastname: 'Customer2',
  61. email: 'search-customer2@example.com',
  62. password: 'customer2pw',
  63. active: true,
  64. roles: roles,
  65. organization_id: @organization.id,
  66. )
  67. @customer_with_org3 = User.create_or_update(
  68. login: 'search-customer3@example.com',
  69. firstname: 'Search',
  70. lastname: 'Customer3',
  71. email: 'search-customer3@example.com',
  72. password: 'customer3pw',
  73. active: true,
  74. roles: roles,
  75. organization_id: @organization.id,
  76. )
  77. @ticket1 = Ticket.create!(
  78. title: 'test 1234-1',
  79. group: Group.lookup(name: 'Users'),
  80. customer_id: @customer_without_org.id,
  81. state: Ticket::State.lookup(name: 'new'),
  82. priority: Ticket::Priority.lookup(name: '2 normal'),
  83. )
  84. @article1 = Ticket::Article.create!(
  85. ticket_id: @ticket1.id,
  86. from: 'some_sender1@example.com',
  87. to: 'some_recipient1@example.com',
  88. subject: 'some subject1',
  89. message_id: 'some@id',
  90. body: 'some message1',
  91. internal: false,
  92. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  93. type: Ticket::Article::Type.where(name: 'email').first,
  94. )
  95. travel 1.second
  96. @ticket2 = Ticket.create!(
  97. title: 'test 1234-2',
  98. group: Group.lookup(name: 'Users'),
  99. customer_id: @customer_with_org2.id,
  100. state: Ticket::State.lookup(name: 'new'),
  101. priority: Ticket::Priority.lookup(name: '2 normal'),
  102. )
  103. @article2 = Ticket::Article.create!(
  104. ticket_id: @ticket2.id,
  105. from: 'some_sender2@example.com',
  106. to: 'some_recipient2@example.com',
  107. subject: 'some subject2',
  108. message_id: 'some@id',
  109. body: 'some message2',
  110. internal: false,
  111. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  112. type: Ticket::Article::Type.where(name: 'email').first,
  113. )
  114. travel 1.second
  115. @ticket3 = Ticket.create!(
  116. title: 'test 1234-2',
  117. group: Group.lookup(name: 'Users'),
  118. customer_id: @customer_with_org3.id,
  119. state: Ticket::State.lookup(name: 'new'),
  120. priority: Ticket::Priority.lookup(name: '2 normal'),
  121. )
  122. @article3 = Ticket::Article.create!(
  123. ticket_id: @ticket3.id,
  124. from: 'some_sender3@example.com',
  125. to: 'some_recipient3@example.com',
  126. subject: 'some subject3',
  127. message_id: 'some@id',
  128. body: 'some message3',
  129. internal: false,
  130. sender: Ticket::Article::Sender.where(name: 'Customer').first,
  131. type: Ticket::Article::Type.where(name: 'email').first,
  132. )
  133. # configure es
  134. if ENV['ES_URL'].present?
  135. #fail "ERROR: Need ES_URL - hint ES_URL='http://127.0.0.1:9200'"
  136. Setting.set('es_url', ENV['ES_URL'])
  137. # Setting.set('es_url', 'http://127.0.0.1:9200')
  138. # Setting.set('es_index', 'estest.local_zammad')
  139. # Setting.set('es_user', 'elasticsearch')
  140. # Setting.set('es_password', 'zammad')
  141. if ENV['ES_INDEX_RAND'].present?
  142. ENV['ES_INDEX'] = "es_index_#{rand(999_999_999)}"
  143. end
  144. if ENV['ES_INDEX'].blank?
  145. raise "ERROR: Need ES_INDEX - hint ES_INDEX='estest.local_zammad'"
  146. end
  147. Setting.set('es_index', ENV['ES_INDEX'])
  148. # set max attachment size in mb
  149. Setting.set('es_attachment_max_size_in_mb', 1)
  150. travel 1.minute
  151. # drop/create indexes
  152. Rake::Task.clear
  153. Zammad::Application.load_tasks
  154. #Rake::Task["searchindex:drop"].execute
  155. #Rake::Task["searchindex:create"].execute
  156. Rake::Task['searchindex:rebuild'].execute
  157. # execute background jobs
  158. Scheduler.worker(true)
  159. sleep 6
  160. end
  161. end
  162. teardown do
  163. if ENV['ES_URL'].present?
  164. Rake::Task['searchindex:drop'].execute
  165. end
  166. end
  167. test 'settings index with nobody' do
  168. params = {
  169. query: 'test 1234',
  170. limit: 2,
  171. }
  172. post '/api/v1/search/ticket', params: params.to_json, headers: @headers
  173. assert_response(401)
  174. result = JSON.parse(@response.body)
  175. assert_equal(Hash, result.class)
  176. assert_not(result.empty?)
  177. assert_equal('authentication failed', result['error'])
  178. post '/api/v1/search/user', params: params.to_json, headers: @headers
  179. assert_response(401)
  180. result = JSON.parse(@response.body)
  181. assert_equal(Hash, result.class)
  182. assert_not(result.empty?)
  183. assert_equal('authentication failed', result['error'])
  184. post '/api/v1/search', params: params.to_json, headers: @headers
  185. assert_response(401)
  186. result = JSON.parse(@response.body)
  187. assert_equal(Hash, result.class)
  188. assert_not(result.empty?)
  189. assert_equal('authentication failed', result['error'])
  190. end
  191. test 'settings index with admin' do
  192. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-admin@example.com', 'adminpw')
  193. params = {
  194. query: '1234*',
  195. limit: 1,
  196. }
  197. post '/api/v1/search', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  198. assert_response(200)
  199. result = JSON.parse(@response.body)
  200. assert_equal(Hash, result.class)
  201. assert(result)
  202. assert_equal('Ticket', result['result'][0]['type'])
  203. assert_equal(@ticket3.id, result['result'][0]['id'])
  204. assert_equal('User', result['result'][1]['type'])
  205. assert_equal(@agent.id, result['result'][1]['id'])
  206. assert_not(result['result'][2])
  207. params = {
  208. query: '1234*',
  209. limit: 10,
  210. }
  211. post '/api/v1/search', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  212. assert_response(200)
  213. result = JSON.parse(@response.body)
  214. assert_equal(Hash, result.class)
  215. assert(result)
  216. assert_equal('Ticket', result['result'][0]['type'])
  217. assert_equal(@ticket3.id, result['result'][0]['id'])
  218. assert_equal('Ticket', result['result'][1]['type'])
  219. assert_equal(@ticket2.id, result['result'][1]['id'])
  220. assert_equal('Ticket', result['result'][2]['type'])
  221. assert_equal(@ticket1.id, result['result'][2]['id'])
  222. assert_equal('User', result['result'][3]['type'])
  223. assert_equal(@agent.id, result['result'][3]['id'])
  224. assert_not(result['result'][4])
  225. params = {
  226. query: '1234*',
  227. limit: 10,
  228. }
  229. post '/api/v1/search/ticket', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  230. assert_response(200)
  231. result = JSON.parse(@response.body)
  232. assert_equal(Hash, result.class)
  233. assert(result)
  234. assert_equal('Ticket', result['result'][0]['type'])
  235. assert_equal(@ticket3.id, result['result'][0]['id'])
  236. assert_equal('Ticket', result['result'][1]['type'])
  237. assert_equal(@ticket2.id, result['result'][1]['id'])
  238. assert_equal('Ticket', result['result'][2]['type'])
  239. assert_equal(@ticket1.id, result['result'][2]['id'])
  240. assert_not(result['result'][3])
  241. params = {
  242. query: '1234*',
  243. limit: 10,
  244. }
  245. post '/api/v1/search/user', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  246. assert_response(200)
  247. result = JSON.parse(@response.body)
  248. assert_equal(Hash, result.class)
  249. assert_equal('User', result['result'][0]['type'])
  250. assert_equal(@agent.id, result['result'][0]['id'])
  251. assert_not(result['result'][1])
  252. end
  253. test 'settings index with agent' do
  254. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-agent@example.com', 'agentpw')
  255. params = {
  256. query: '1234*',
  257. limit: 1,
  258. }
  259. post '/api/v1/search', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  260. assert_response(200)
  261. result = JSON.parse(@response.body)
  262. assert_equal(Hash, result.class)
  263. assert(result)
  264. assert_equal('Ticket', result['result'][0]['type'])
  265. assert_equal(@ticket3.id, result['result'][0]['id'])
  266. assert_equal('User', result['result'][1]['type'])
  267. assert_equal(@agent.id, result['result'][1]['id'])
  268. assert_not(result['result'][2])
  269. params = {
  270. query: '1234*',
  271. limit: 10,
  272. }
  273. post '/api/v1/search', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  274. assert_response(200)
  275. result = JSON.parse(@response.body)
  276. assert_equal(Hash, result.class)
  277. assert(result)
  278. assert_equal('Ticket', result['result'][0]['type'])
  279. assert_equal(@ticket3.id, result['result'][0]['id'])
  280. assert_equal('Ticket', result['result'][1]['type'])
  281. assert_equal(@ticket2.id, result['result'][1]['id'])
  282. assert_equal('Ticket', result['result'][2]['type'])
  283. assert_equal(@ticket1.id, result['result'][2]['id'])
  284. assert_equal('User', result['result'][3]['type'])
  285. assert_equal(@agent.id, result['result'][3]['id'])
  286. assert_not(result['result'][4])
  287. params = {
  288. query: '1234*',
  289. limit: 10,
  290. }
  291. post '/api/v1/search/ticket', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  292. assert_response(200)
  293. result = JSON.parse(@response.body)
  294. assert_equal(Hash, result.class)
  295. assert(result)
  296. assert_equal('Ticket', result['result'][0]['type'])
  297. assert_equal(@ticket3.id, result['result'][0]['id'])
  298. assert_equal('Ticket', result['result'][1]['type'])
  299. assert_equal(@ticket2.id, result['result'][1]['id'])
  300. assert_equal('Ticket', result['result'][2]['type'])
  301. assert_equal(@ticket1.id, result['result'][2]['id'])
  302. assert_not(result['result'][3])
  303. params = {
  304. query: '1234*',
  305. limit: 10,
  306. }
  307. post '/api/v1/search/user', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  308. assert_response(200)
  309. result = JSON.parse(@response.body)
  310. assert_equal(Hash, result.class)
  311. assert_equal('User', result['result'][0]['type'])
  312. assert_equal(@agent.id, result['result'][0]['id'])
  313. assert_not(result['result'][1])
  314. end
  315. test 'settings index with customer 1' do
  316. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-customer1@example.com', 'customer1pw')
  317. params = {
  318. query: '1234*',
  319. limit: 10,
  320. }
  321. post '/api/v1/search', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  322. assert_response(200)
  323. result = JSON.parse(@response.body)
  324. assert_equal(Hash, result.class)
  325. assert(result)
  326. assert_equal('Ticket', result['result'][0]['type'])
  327. assert_equal(@ticket1.id, result['result'][0]['id'])
  328. assert_not(result['result'][1])
  329. params = {
  330. query: '1234*',
  331. limit: 10,
  332. }
  333. post '/api/v1/search/ticket', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  334. assert_response(200)
  335. result = JSON.parse(@response.body)
  336. assert_equal(Hash, result.class)
  337. assert(result)
  338. assert_equal('Ticket', result['result'][0]['type'])
  339. assert_equal(@ticket1.id, result['result'][0]['id'])
  340. assert_not(result['result'][1])
  341. params = {
  342. query: '1234*',
  343. limit: 10,
  344. }
  345. post '/api/v1/search/user', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  346. assert_response(200)
  347. result = JSON.parse(@response.body)
  348. assert_equal(Hash, result.class)
  349. assert_not(result['result'][0])
  350. end
  351. test 'settings index with customer 2' do
  352. credentials = ActionController::HttpAuthentication::Basic.encode_credentials('search-customer2@example.com', 'customer2pw')
  353. params = {
  354. query: '1234*',
  355. limit: 10,
  356. }
  357. post '/api/v1/search', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  358. assert_response(200)
  359. result = JSON.parse(@response.body)
  360. assert_equal(Hash, result.class)
  361. assert(result)
  362. assert_equal('Ticket', result['result'][0]['type'])
  363. assert_equal(@ticket3.id, result['result'][0]['id'])
  364. assert_equal('Ticket', result['result'][1]['type'])
  365. assert_equal(@ticket2.id, result['result'][1]['id'])
  366. assert_not(result['result'][2])
  367. params = {
  368. query: '1234*',
  369. limit: 10,
  370. }
  371. post '/api/v1/search/ticket', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  372. assert_response(200)
  373. result = JSON.parse(@response.body)
  374. assert_equal(Hash, result.class)
  375. assert(result)
  376. assert_equal('Ticket', result['result'][0]['type'])
  377. assert_equal(@ticket3.id, result['result'][0]['id'])
  378. assert_equal('Ticket', result['result'][1]['type'])
  379. assert_equal(@ticket2.id, result['result'][1]['id'])
  380. assert_not(result['result'][2])
  381. params = {
  382. query: '1234*',
  383. limit: 10,
  384. }
  385. post '/api/v1/search/user', params: params.to_json, headers: @headers.merge('Authorization' => credentials)
  386. assert_response(200)
  387. result = JSON.parse(@response.body)
  388. assert_equal(Hash, result.class)
  389. assert_not(result['result'][0])
  390. end
  391. end