Merge pull request #2957 from overleaf/ew-validate-saml-email
Validate saml email before register GitOrigin-RevId: 6dcf3bccd280abd7bd3ced2d4fd2f69c590f74c1
This commit is contained in:
@@ -23,13 +23,18 @@ describe('UserCreator', function() {
|
||||
'../../models/User': {
|
||||
User: this.UserModel
|
||||
},
|
||||
'logger-sharelatex': {
|
||||
'logger-sharelatex': (this.Logger = {
|
||||
error: sinon.stub()
|
||||
},
|
||||
}),
|
||||
'metrics-sharelatex': { timeAsyncMethod() {} },
|
||||
'../../infrastructure/Features': (this.Features = {
|
||||
hasFeature: sinon.stub().returns(false)
|
||||
}),
|
||||
'./UserDeleter': (this.UserDeleter = {
|
||||
promises: {
|
||||
deleteNewUser: sinon.stub().resolves()
|
||||
}
|
||||
}),
|
||||
'./UserGetter': (this.UserGetter = {
|
||||
promises: {
|
||||
getUser: sinon.stub().resolves(this.user)
|
||||
@@ -51,79 +56,60 @@ describe('UserCreator', function() {
|
||||
|
||||
describe('createNewUser', function() {
|
||||
describe('with callbacks', function() {
|
||||
it('should take the opts and put them in the model', function(done) {
|
||||
const opts = {
|
||||
it('should take the opts and put them in the model', async function() {
|
||||
const user = await this.UserCreator.promises.createNewUser({
|
||||
email: this.email,
|
||||
holdingAccount: true
|
||||
}
|
||||
this.UserCreator.createNewUser(opts, (err, user) => {
|
||||
assert.ifError(err)
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.first_name, 'bob.oswald')
|
||||
done()
|
||||
})
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.first_name, 'bob.oswald')
|
||||
})
|
||||
|
||||
it('should use the start of the email if the first name is empty string', function(done) {
|
||||
const opts = {
|
||||
it('should use the start of the email if the first name is empty string', async function() {
|
||||
const user = await this.UserCreator.promises.createNewUser({
|
||||
email: this.email,
|
||||
holdingAccount: true,
|
||||
first_name: ''
|
||||
}
|
||||
this.UserCreator.createNewUser(opts, (err, user) => {
|
||||
assert.ifError(err)
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.first_name, 'bob.oswald')
|
||||
done()
|
||||
})
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.first_name, 'bob.oswald')
|
||||
})
|
||||
|
||||
it('should use the first name if passed', function(done) {
|
||||
const opts = {
|
||||
it('should use the first name if passed', async function() {
|
||||
const user = await this.UserCreator.promises.createNewUser({
|
||||
email: this.email,
|
||||
holdingAccount: true,
|
||||
first_name: 'fiiirstname'
|
||||
}
|
||||
this.UserCreator.createNewUser(opts, (err, user) => {
|
||||
assert.ifError(err)
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.first_name, 'fiiirstname')
|
||||
done()
|
||||
})
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.first_name, 'fiiirstname')
|
||||
})
|
||||
|
||||
it('should use the last name if passed', function(done) {
|
||||
const opts = {
|
||||
it('should use the last name if passed', async function() {
|
||||
const user = await this.UserCreator.promises.createNewUser({
|
||||
email: this.email,
|
||||
holdingAccount: true,
|
||||
last_name: 'lastNammmmeee'
|
||||
}
|
||||
this.UserCreator.createNewUser(opts, (err, user) => {
|
||||
assert.ifError(err)
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.last_name, 'lastNammmmeee')
|
||||
done()
|
||||
})
|
||||
assert.equal(user.email, this.email)
|
||||
assert.equal(user.holdingAccount, true)
|
||||
assert.equal(user.last_name, 'lastNammmmeee')
|
||||
})
|
||||
|
||||
it('should set emails attribute', function(done) {
|
||||
this.UserCreator.createNewUser({ email: this.email }, (err, user) => {
|
||||
assert.ifError(err)
|
||||
user.email.should.equal(this.email)
|
||||
user.emails.length.should.equal(1)
|
||||
user.emails[0].email.should.equal(this.email)
|
||||
user.emails[0].createdAt.should.be.a('date')
|
||||
user.emails[0].reversedHostname.should.equal('moc.liamg')
|
||||
done()
|
||||
it('should set emails attribute', async function() {
|
||||
const user = await this.UserCreator.promises.createNewUser({
|
||||
email: this.email
|
||||
})
|
||||
user.email.should.equal(this.email)
|
||||
user.emails.length.should.equal(1)
|
||||
user.emails[0].email.should.equal(this.email)
|
||||
user.emails[0].createdAt.should.be.a('date')
|
||||
user.emails[0].reversedHostname.should.equal('moc.liamg')
|
||||
})
|
||||
|
||||
it('should not add affiliation', function() {})
|
||||
|
||||
describe('with affiliations feature', function() {
|
||||
let attributes, user
|
||||
beforeEach(function() {
|
||||
@@ -133,17 +119,16 @@ describe('UserCreator', function() {
|
||||
.withArgs('affiliations')
|
||||
.returns(true)
|
||||
})
|
||||
|
||||
describe('when v1 affiliations API does not return an error', function() {
|
||||
beforeEach(function(done) {
|
||||
this.UserCreator.createNewUser(attributes, (err, createdUser) => {
|
||||
user = createdUser
|
||||
assert.ifError(err)
|
||||
done()
|
||||
})
|
||||
beforeEach(async function() {
|
||||
user = await this.UserCreator.promises.createNewUser(attributes)
|
||||
})
|
||||
|
||||
it('should flag that affiliation is unchecked', function() {
|
||||
user.emails[0].affiliationUnchecked.should.equal(true)
|
||||
})
|
||||
|
||||
it('should try to add affiliation to v1', function() {
|
||||
sinon.assert.calledOnce(
|
||||
this.UserUpdater.promises.addAffiliationForNewUser
|
||||
@@ -154,22 +139,22 @@ describe('UserCreator', function() {
|
||||
this.email
|
||||
)
|
||||
})
|
||||
|
||||
it('should query for updated user data', function() {
|
||||
sinon.assert.calledOnce(this.UserGetter.promises.getUser)
|
||||
})
|
||||
})
|
||||
|
||||
describe('when v1 affiliations API does return an error', function() {
|
||||
beforeEach(function(done) {
|
||||
beforeEach(async function() {
|
||||
this.UserUpdater.promises.addAffiliationForNewUser.rejects()
|
||||
this.UserCreator.createNewUser(attributes, (error, createdUser) => {
|
||||
user = createdUser
|
||||
assert.ifError(error)
|
||||
done()
|
||||
})
|
||||
user = await this.UserCreator.promises.createNewUser(attributes)
|
||||
})
|
||||
|
||||
it('should flag that affiliation is unchecked', function() {
|
||||
user.emails[0].affiliationUnchecked.should.equal(true)
|
||||
})
|
||||
|
||||
it('should try to add affiliation to v1', function() {
|
||||
sinon.assert.calledOnce(
|
||||
this.UserUpdater.promises.addAffiliationForNewUser
|
||||
@@ -180,21 +165,53 @@ describe('UserCreator', function() {
|
||||
this.email
|
||||
)
|
||||
})
|
||||
it('should query for updated user data', function() {
|
||||
sinon.assert.calledOnce(this.UserGetter.promises.getUser)
|
||||
|
||||
it('should not query for updated user data', function() {
|
||||
sinon.assert.notCalled(this.UserGetter.promises.getUser)
|
||||
})
|
||||
|
||||
it('should log error', function() {
|
||||
sinon.assert.calledOnce(this.Logger.error)
|
||||
})
|
||||
})
|
||||
|
||||
describe('when v1 affiliations API returns an error and requireAffiliation=true', function() {
|
||||
beforeEach(async function() {
|
||||
this.UserUpdater.promises.addAffiliationForNewUser.rejects()
|
||||
user = await this.UserCreator.promises.createNewUser(attributes)
|
||||
})
|
||||
|
||||
it('should flag that affiliation is unchecked', function() {
|
||||
user.emails[0].affiliationUnchecked.should.equal(true)
|
||||
})
|
||||
|
||||
it('should try to add affiliation to v1', function() {
|
||||
sinon.assert.calledOnce(
|
||||
this.UserUpdater.promises.addAffiliationForNewUser
|
||||
)
|
||||
sinon.assert.calledWithMatch(
|
||||
this.UserUpdater.promises.addAffiliationForNewUser,
|
||||
user._id,
|
||||
this.email
|
||||
)
|
||||
})
|
||||
|
||||
it('should not query for updated user data', function() {
|
||||
sinon.assert.notCalled(this.UserGetter.promises.getUser)
|
||||
})
|
||||
|
||||
it('should log error', function() {
|
||||
sinon.assert.calledOnce(this.Logger.error)
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
it('should not add affiliation when without affiliation feature', function(done) {
|
||||
it('should not add affiliation when without affiliation feature', async function() {
|
||||
const attributes = { email: this.email }
|
||||
this.UserCreator.createNewUser(attributes, (err, user) => {
|
||||
assert.ifError(err)
|
||||
sinon.assert.notCalled(
|
||||
this.UserUpdater.promises.addAffiliationForNewUser
|
||||
)
|
||||
done()
|
||||
})
|
||||
await this.UserCreator.promises.createNewUser(attributes)
|
||||
sinon.assert.notCalled(
|
||||
this.UserUpdater.promises.addAffiliationForNewUser
|
||||
)
|
||||
})
|
||||
})
|
||||
|
||||
|
||||
@@ -29,7 +29,7 @@ describe('UserRegistrationHandler', function() {
|
||||
this.User = { update: sinon.stub().callsArgWith(2) }
|
||||
this.UserGetter = { getUserByAnyEmail: sinon.stub() }
|
||||
this.UserCreator = {
|
||||
createNewUser: sinon.stub().callsArgWith(1, null, this.user)
|
||||
createNewUser: sinon.stub().callsArgWith(2, null, this.user)
|
||||
}
|
||||
this.AuthenticationManager = {
|
||||
validateEmail: sinon.stub().returns(null),
|
||||
|
||||
Reference in New Issue
Block a user