Dan Brown c724bfe4d3
Copied over work from user_permissions branch
Only that relevant to the additional testing work.
2023-01-21 11:08:34 +00:00

102 lines
3.8 KiB

namespace Tests\Auth;
use BookStack\Auth\User;
use BookStack\Notifications\ResetPassword;
use Illuminate\Support\Facades\Notification;
use Tests\TestCase;
class ResetPasswordTest extends TestCase
public function test_reset_flow()
$resp = $this->get('/login');
$this->withHtml($resp)->assertElementContains('a[href="' . url('/password/email') . '"]', 'Forgot Password?');
$resp = $this->get('/password/email');
$this->withHtml($resp)->assertElementContains('form[action="' . url('/password/email') . '"]', 'Send Reset Link');
$resp = $this->post('/password/email', [
'email' => '',
$resp = $this->get('/password/email');
$resp->assertSee('A password reset link will be sent to if that email address is found in the system.');
$this->assertDatabaseHas('password_resets', [
'email' => '',
/** @var User $user */
$user = User::query()->where('email', '=', '')->first();
Notification::assertSentTo($user, ResetPassword::class);
$n = Notification::sent($user, ResetPassword::class);
$this->get('/password/reset/' . $n->first()->token)
->assertSee('Reset Password');
$resp = $this->post('/password/reset', [
'email' => '',
'password' => 'randompass',
'password_confirmation' => 'randompass',
'token' => $n->first()->token,
$this->get('/')->assertSee('Your password has been successfully reset');
public function test_reset_flow_shows_success_message_even_if_wrong_password_to_prevent_user_discovery()
$resp = $this->followingRedirects()->post('/password/email', [
'email' => '',
$resp->assertSee('A password reset link will be sent to if that email address is found in the system.');
$resp->assertDontSee('We can\'t find a user');
$this->get('/password/reset/arandometokenvalue')->assertSee('Reset Password');
$resp = $this->post('/password/reset', [
'email' => '',
'password' => 'randompass',
'password_confirmation' => 'randompass',
'token' => 'arandometokenvalue',
->assertDontSee('We can\'t find a user')
->assertSee('The password reset token is invalid for this email address.');
public function test_reset_page_shows_sign_links()
$this->setSettings(['registration-enabled' => 'true']);
$resp = $this->get('/password/email');
$this->withHtml($resp)->assertElementContains('a', 'Log in')
->assertElementContains('a', 'Sign up');
public function test_reset_request_is_throttled()
$editor = $this->users->editor();
$this->followingRedirects()->post('/password/email', [
'email' => $editor->email,
$resp = $this->followingRedirects()->post('/password/email', [
'email' => $editor->email,
Notification::assertTimesSent(1, ResetPassword::class);
$resp->assertSee('A password reset link will be sent to ' . $editor->email . ' if that email address is found in the system.');