Search moodle.org's
Developer Documentation

See Release Notes

  • Bug fixes for general core bugs in 3.10.x will end 8 November 2021 (12 months).
  • Bug fixes for security issues in 3.10.x will end 9 May 2022 (18 months).
  • PHP version: minimum PHP 7.2.0 Note: minimum PHP version has increased since Moodle 3.8. PHP 7.3.x and 7.4.x are supported too.

Differences Between: [Versions 39 and 310]

   1  <?php
   2  // This file is part of Moodle - http://moodle.org/
   3  //
   4  // Moodle is free software: you can redistribute it and/or modify
   5  // it under the terms of the GNU General Public License as published by
   6  // the Free Software Foundation, either version 3 of the License, or
   7  // (at your option) any later version.
   8  //
   9  // Moodle is distributed in the hope that it will be useful,
  10  // but WITHOUT ANY WARRANTY; without even the implied warranty of
  11  // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  12  // GNU General Public License for more details.
  13  //
  14  // You should have received a copy of the GNU General Public License
  15  // along with Moodle.  If not, see <http://www.gnu.org/licenses/>.
  16  
  17  /**
  18   * Data provider tests.
  19   *
  20   * @package    core_webservice
  21   * @category   test
  22   * @copyright  2018 Frédéric Massart
  23   * @author     Frédéric Massart <fred@branchup.tech>
  24   * @license    http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
  25   */
  26  
  27  defined('MOODLE_INTERNAL') || die();
  28  global $CFG;
  29  
  30  use core_privacy\tests\provider_testcase;
  31  use core_privacy\local\request\approved_contextlist;
  32  use core_privacy\local\request\transform;
  33  use core_privacy\local\request\writer;
  34  use core_webservice\privacy\provider;
  35  use core_privacy\local\request\approved_userlist;
  36  
  37  require_once($CFG->dirroot . '/webservice/lib.php');
  38  
  39  /**
  40   * Data provider testcase class.
  41   *
  42   * @package    core_webservice
  43   * @category   test
  44   * @copyright  2018 Frédéric Massart
  45   * @author     Frédéric Massart <fred@branchup.tech>
  46   * @license    http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
  47   */
  48  class core_webservice_privacy_testcase extends provider_testcase {
  49  
  50      public function setUp(): void {
  51          $this->resetAfterTest();
  52      }
  53  
  54      public function test_get_contexts_for_userid() {
  55          $dg = $this->getDataGenerator();
  56          $u1 = $dg->create_user();
  57          $u2 = $dg->create_user();
  58          $u3 = $dg->create_user();
  59          $u4 = $dg->create_user();
  60          $u5 = $dg->create_user();
  61          $u1ctx = context_user::instance($u1->id);
  62          $u2ctx = context_user::instance($u2->id);
  63          $u3ctx = context_user::instance($u3->id);
  64          $u5ctx = context_user::instance($u5->id);
  65  
  66          $s = $this->create_service();
  67          $this->create_token(['userid' => $u1->id]);
  68          $this->create_token(['userid' => $u1->id]);
  69          $this->create_token(['userid' => $u2->id, 'creatorid' => $u3->id]);
  70          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u5->id]);
  71  
  72          $contextids = provider::get_contexts_for_userid($u1->id)->get_contextids();
  73          $this->assertCount(1, $contextids);
  74          $this->assertTrue(in_array($u1ctx->id, $contextids));
  75  
  76          $contextids = provider::get_contexts_for_userid($u2->id)->get_contextids();
  77          $this->assertCount(1, $contextids);
  78          $this->assertTrue(in_array($u2ctx->id, $contextids));
  79  
  80          $contextids = provider::get_contexts_for_userid($u3->id)->get_contextids();
  81          $this->assertCount(1, $contextids);
  82          $this->assertTrue(in_array($u2ctx->id, $contextids));
  83  
  84          $contextids = provider::get_contexts_for_userid($u4->id)->get_contextids();
  85          $this->assertCount(0, $contextids);
  86  
  87          $contextids = provider::get_contexts_for_userid($u5->id)->get_contextids();
  88          $this->assertCount(1, $contextids);
  89          $this->assertTrue(in_array($u5ctx->id, $contextids));
  90      }
  91  
  92      public function test_delete_data_for_user() {
  93          global $DB;
  94  
  95          $dg = $this->getDataGenerator();
  96          $u1 = $dg->create_user();
  97          $u2 = $dg->create_user();
  98          $u1ctx = context_user::instance($u1->id);
  99          $u2ctx = context_user::instance($u2->id);
 100  
 101          $s = $this->create_service();
 102          $this->create_token(['userid' => $u1->id, 'creatorid' => $u2->id]);
 103          $this->create_token(['userid' => $u1->id]);
 104          $this->create_token(['userid' => $u2->id]);
 105          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u1->id]);
 106          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u2->id]);
 107  
 108          $this->assertEquals(2, $DB->count_records('external_tokens', ['userid' => $u1->id]));
 109          $this->assertEquals(1, $DB->count_records('external_tokens', ['userid' => $u2->id]));
 110          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u1->id]));
 111          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u2->id]));
 112  
 113          // Delete in another context, nothing happens.
 114          provider::delete_data_for_user(new approved_contextlist($u2, 'core_webservice', [$u1ctx->id]));
 115          $this->assertEquals(2, $DB->count_records('external_tokens', ['userid' => $u1->id]));
 116          $this->assertEquals(1, $DB->count_records('external_tokens', ['userid' => $u2->id]));
 117          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u1->id]));
 118          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u2->id]));
 119  
 120          // Delete in my context.
 121          provider::delete_data_for_user(new approved_contextlist($u2, 'core_webservice', [$u2ctx->id]));
 122          $this->assertEquals(2, $DB->count_records('external_tokens', ['userid' => $u1->id]));
 123          $this->assertEquals(0, $DB->count_records('external_tokens', ['userid' => $u2->id]));
 124          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u1->id]));
 125          $this->assertFalse($DB->record_exists('external_services_users', ['userid' => $u2->id]));
 126      }
 127  
 128      public function test_delete_data_for_all_users_in_context() {
 129          global $DB;
 130  
 131          $dg = $this->getDataGenerator();
 132          $u1 = $dg->create_user();
 133          $u2 = $dg->create_user();
 134          $u1ctx = context_user::instance($u1->id);
 135          $u2ctx = context_user::instance($u2->id);
 136  
 137          $s = $this->create_service();
 138          $this->create_token(['userid' => $u1->id, 'creatorid' => $u2->id]);
 139          $this->create_token(['userid' => $u1->id]);
 140          $this->create_token(['userid' => $u2->id]);
 141          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u1->id]);
 142          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u2->id]);
 143  
 144          $this->assertEquals(2, $DB->count_records('external_tokens', ['userid' => $u1->id]));
 145          $this->assertEquals(1, $DB->count_records('external_tokens', ['userid' => $u2->id]));
 146          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u1->id]));
 147          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u2->id]));
 148  
 149          provider::delete_data_for_all_users_in_context($u2ctx);
 150          $this->assertEquals(2, $DB->count_records('external_tokens', ['userid' => $u1->id]));
 151          $this->assertEquals(0, $DB->count_records('external_tokens', ['userid' => $u2->id]));
 152          $this->assertTrue($DB->record_exists('external_services_users', ['userid' => $u1->id]));
 153          $this->assertFalse($DB->record_exists('external_services_users', ['userid' => $u2->id]));
 154  
 155          provider::delete_data_for_all_users_in_context($u1ctx);
 156          $this->assertEquals(0, $DB->count_records('external_tokens', ['userid' => $u1->id]));
 157          $this->assertEquals(0, $DB->count_records('external_tokens', ['userid' => $u2->id]));
 158          $this->assertFalse($DB->record_exists('external_services_users', ['userid' => $u1->id]));
 159          $this->assertFalse($DB->record_exists('external_services_users', ['userid' => $u2->id]));
 160  
 161      }
 162  
 163      public function test_export_data_for_user() {
 164          global $DB;
 165  
 166          $dg = $this->getDataGenerator();
 167          $u1 = $dg->create_user();
 168          $u2 = $dg->create_user();
 169          $u1ctx = context_user::instance($u1->id);
 170          $u2ctx = context_user::instance($u2->id);
 171  
 172          $path = [get_string('webservices', 'core_webservice')];
 173          $yearago = time() - YEARSECS;
 174          $hourago = time() - HOURSECS;
 175  
 176          $s = $this->create_service(['name' => 'Party time!']);
 177          $this->create_token(['userid' => $u1->id, 'timecreated' => $yearago]);
 178          $this->create_token(['userid' => $u1->id, 'creatorid' => $u2->id, 'iprestriction' => '127.0.0.1',
 179              'lastaccess' => $hourago]);
 180          $this->create_token(['userid' => $u2->id, 'iprestriction' => '192.168.1.0/24', 'lastaccess' => $yearago,
 181              'externalserviceid' => $s->id]);
 182          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u2->id]);
 183  
 184          // User 1 exporting user 2 context does not give anything.
 185          writer::reset();
 186          provider::export_user_data(new approved_contextlist($u1, 'core_webservice', [$u2ctx->id]));
 187          $data = writer::with_context($u1ctx)->get_data($path);
 188          $this->assertEmpty($data);
 189          $data = writer::with_context($u1ctx)->get_related_data($path, 'created_by_you');
 190          $this->assertEmpty($data);
 191          $data = writer::with_context($u2ctx)->get_data($path);
 192          $this->assertEmpty($data);
 193          $data = writer::with_context($u2ctx)->get_related_data($path, 'created_by_you');
 194          $this->assertEmpty($data);
 195  
 196          // User 1 exporting their context.
 197          writer::reset();
 198          provider::export_user_data(new approved_contextlist($u1, 'core_webservice', [$u1ctx->id, $u2ctx->id]));
 199          $data = writer::with_context($u1ctx)->get_data($path);
 200          $this->assertFalse(isset($data->services_user));
 201          $this->assertCount(2, $data->tokens);
 202          $this->assertEquals(transform::datetime($yearago), $data->tokens[0]['created_on']);
 203          $this->assertEquals(null, $data->tokens[0]['ip_restriction']);
 204          $this->assertEquals(transform::datetime($hourago), $data->tokens[1]['last_access']);
 205          $this->assertEquals('127.0.0.1', $data->tokens[1]['ip_restriction']);
 206          $data = writer::with_context($u1ctx)->get_related_data($path, 'created_by_you');
 207          $this->assertEmpty($data);
 208          $data = writer::with_context($u2ctx)->get_data($path);
 209          $this->assertEmpty($data);
 210          $data = writer::with_context($u2ctx)->get_related_data($path, 'created_by_you');
 211          $this->assertEmpty($data);
 212  
 213          // User 2 exporting their context.
 214          writer::reset();
 215          provider::export_user_data(new approved_contextlist($u2, 'core_webservice', [$u1ctx->id, $u2ctx->id]));
 216          $data = writer::with_context($u2ctx)->get_data($path);
 217          $this->assertCount(1, $data->tokens);
 218          $this->assertEquals('Party time!', $data->tokens[0]['external_service']);
 219          $this->assertEquals(transform::datetime($yearago), $data->tokens[0]['last_access']);
 220          $this->assertEquals('192.168.1.0/24', $data->tokens[0]['ip_restriction']);
 221          $this->assertCount(1, $data->services_user);
 222          $this->assertEquals('Party time!', $data->services_user[0]['external_service']);
 223          $data = writer::with_context($u1ctx)->get_related_data($path, 'created_by_you');
 224          $this->assertCount(1, $data->tokens);
 225          $this->assertEquals(transform::datetime($hourago), $data->tokens[0]['last_access']);
 226          $this->assertEquals('127.0.0.1', $data->tokens[0]['ip_restriction']);
 227          $data = writer::with_context($u1ctx)->get_data($path);
 228          $this->assertEmpty($data);
 229          $data = writer::with_context($u2ctx)->get_related_data($path, 'created_by_you');
 230          $this->assertEmpty($data);
 231      }
 232  
 233      /**
 234       * Test that only users with a user context are fetched.
 235       */
 236      public function test_get_users_in_context() {
 237  
 238          $component = 'core_webservice';
 239          // Create user u1.
 240          $u1 = $this->getDataGenerator()->create_user();
 241          $u1ctx = context_user::instance($u1->id);
 242          // Create user u2.
 243          $u2 = $this->getDataGenerator()->create_user();
 244          $u2ctx = context_user::instance($u2->id);
 245          // Create user u3.
 246          $u3 = $this->getDataGenerator()->create_user();
 247          $u3ctx = context_user::instance($u3->id);
 248          // Create user u4.
 249          $u4 = $this->getDataGenerator()->create_user();
 250          $u4ctx = context_user::instance($u4->id);
 251          // Create user u5.
 252          $u5 = $this->getDataGenerator()->create_user();
 253          $u5ctx = context_user::instance($u5->id);
 254  
 255          // The lists of users for each user context ($u1ctx, $u2ctx, etc.) should be empty.
 256          // Related user data have not been created yet.
 257          $userlist1 = new \core_privacy\local\request\userlist($u1ctx, $component);
 258          provider::get_users_in_context($userlist1);
 259          $this->assertCount(0, $userlist1);
 260          $userlist2 = new \core_privacy\local\request\userlist($u2ctx, $component);
 261          provider::get_users_in_context($userlist2);
 262          $this->assertCount(0, $userlist2);
 263          $userlist3 = new \core_privacy\local\request\userlist($u3ctx, $component);
 264          provider::get_users_in_context($userlist3);
 265          $this->assertCount(0, $userlist3);
 266          $userlist4 = new \core_privacy\local\request\userlist($u4ctx, $component);
 267          provider::get_users_in_context($userlist4);
 268          $this->assertCount(0, $userlist4);
 269          $userlist5 = new \core_privacy\local\request\userlist($u5ctx, $component);
 270          provider::get_users_in_context($userlist5);
 271          $this->assertCount(0, $userlist5);
 272  
 273          // Create a webservice.
 274          $s = $this->create_service();
 275          // Create a ws token for u1.
 276          $this->create_token(['userid' => $u1->id]);
 277          // Create a ws token for u2, and u3 as the creator of the token.
 278          $this->create_token(['userid' => $u2->id, 'creatorid' => $u3->id]);
 279          // Create a service user (u4).
 280          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u4->id]);
 281  
 282          // The list of users for userlist1 should return one user (u1).
 283          provider::get_users_in_context($userlist1);
 284          $this->assertCount(1, $userlist1);
 285          $expected = [$u1->id];
 286          $actual = $userlist1->get_userids();
 287          $this->assertEquals($expected, $actual);
 288          // The list of users for userlist2 should return one user (u2).
 289          provider::get_users_in_context($userlist2);
 290          $this->assertCount(1, $userlist2);
 291          $expected = [$u2->id];
 292          $actual = $userlist2->get_userids();
 293          $this->assertEquals($expected, $actual);
 294          // The list of users for userlist3 should return one user (u3).
 295          provider::get_users_in_context($userlist3);
 296          $this->assertCount(1, $userlist3);
 297          $expected = [$u3->id];
 298          $actual = $userlist3->get_userids();
 299          $this->assertEquals($expected, $actual);
 300          // The list of users for userlist4 should return one user (u4).
 301          provider::get_users_in_context($userlist4);
 302          $this->assertCount(1, $userlist4);
 303          $expected = [$u4->id];
 304          $actual = $userlist4->get_userids();
 305          $this->assertEquals($expected, $actual);
 306          // The list of users for userlist5 should not return any users.
 307          provider::get_users_in_context($userlist5);
 308          $this->assertCount(0, $userlist5);
 309  
 310          // The list of users should only return users in the user context.
 311          $systemcontext = context_system::instance();
 312          $userlist6 = new \core_privacy\local\request\userlist($systemcontext, $component);
 313          provider::get_users_in_context($userlist6);
 314          $this->assertCount(0, $userlist6);
 315      }
 316  
 317      /**
 318       * Test that data for users in approved userlist is deleted.
 319       */
 320      public function test_delete_data_for_users() {
 321  
 322          $component = 'core_webservice';
 323          // Create user u1.
 324          $u1 = $this->getDataGenerator()->create_user();
 325          $u1ctx = context_user::instance($u1->id);
 326          // Create user u2.
 327          $u2 = $this->getDataGenerator()->create_user();
 328          $u2ctx = context_user::instance($u2->id);
 329          // Create user u3.
 330          $u3 = $this->getDataGenerator()->create_user();
 331          $u3ctx = context_user::instance($u3->id);
 332          // Create user u4.
 333          $u4 = $this->getDataGenerator()->create_user();
 334          $u4ctx = context_user::instance($u4->id);
 335          // Create user u5.
 336          $u5 = $this->getDataGenerator()->create_user();
 337          $u5ctx = context_user::instance($u5->id);
 338  
 339          // Create a webservice.
 340          $s = $this->create_service();
 341          // Create a ws token for u1.
 342          $this->create_token(['userid' => $u1->id]);
 343          // Create a ws token for u2, and u3 as the creator of the token.
 344          $this->create_token(['userid' => $u2->id, 'creatorid' => $u3->id]);
 345          // Create a service user (u4).
 346          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u4->id]);
 347          // Create a service user (u5).
 348          $this->create_service_user(['externalserviceid' => $s->id, 'userid' => $u5->id]);
 349  
 350          // The list of users for u1ctx should return one user (u1).
 351          $userlist1 = new \core_privacy\local\request\userlist($u1ctx, $component);
 352          provider::get_users_in_context($userlist1);
 353          $this->assertCount(1, $userlist1);
 354          // The list of users for u2ctx should return one user (u2).
 355          $userlist2 = new \core_privacy\local\request\userlist($u2ctx, $component);
 356          provider::get_users_in_context($userlist2);
 357          $this->assertCount(1, $userlist2);
 358          // The list of users for u3ctx should return one user (u3).
 359          $userlist3 = new \core_privacy\local\request\userlist($u3ctx, $component);
 360          provider::get_users_in_context($userlist3);
 361          $this->assertCount(1, $userlist3);
 362          // The list of users for u4ctx should return one user (u4).
 363          $userlist4 = new \core_privacy\local\request\userlist($u4ctx, $component);
 364          provider::get_users_in_context($userlist4);
 365          $this->assertCount(1, $userlist4);
 366  
 367          $approvedlist = new approved_userlist($u1ctx, $component, $userlist1->get_userids());
 368          // Delete using delete_data_for_user.
 369          provider::delete_data_for_users($approvedlist);
 370          // Re-fetch users in u1ctx - the user data should now be empty.
 371          $userlist1 = new \core_privacy\local\request\userlist($u1ctx, $component);
 372          provider::get_users_in_context($userlist1);
 373          $this->assertCount(0, $userlist1);
 374  
 375          $approvedlist = new approved_userlist($u2ctx, $component, $userlist2->get_userids());
 376          // Delete using delete_data_for_user.
 377          provider::delete_data_for_users($approvedlist);
 378          // Re-fetch users in u2ctx - the user data should now be empty.
 379          $userlist2 = new \core_privacy\local\request\userlist($u2ctx, $component);
 380          provider::get_users_in_context($userlist2);
 381          $this->assertCount(0, $userlist2);
 382  
 383          $approvedlist = new approved_userlist($u3ctx, $component, $userlist3->get_userids());
 384          // Delete using delete_data_for_user.
 385          provider::delete_data_for_users($approvedlist);
 386          // Re-fetch users in u3ctx - the user data should now be empty.
 387          $userlist3 = new \core_privacy\local\request\userlist($u3ctx, $component);
 388          provider::get_users_in_context($userlist3);
 389          $this->assertCount(0, $userlist3);
 390  
 391          $approvedlist = new approved_userlist($u4ctx, $component, $userlist3->get_userids());
 392          // Delete using delete_data_for_user.
 393          provider::delete_data_for_users($approvedlist);
 394          // Re-fetch users in u4ctx - the user data should now be empty.
 395          $userlist4 = new \core_privacy\local\request\userlist($u4ctx, $component);
 396          provider::get_users_in_context($userlist4);
 397          $this->assertCount(0, $userlist4);
 398  
 399          // The list of users for u5ctx should still return one user (u5).
 400          $userlist5 = new \core_privacy\local\request\userlist($u5ctx, $component);
 401          provider::get_users_in_context($userlist5);
 402          $this->assertCount(1, $userlist5);
 403  
 404          // User data should only be removed in the user context.
 405          $systemcontext = context_system::instance();
 406          $approvedlist = new approved_userlist($systemcontext, $component, $userlist5->get_userids());
 407          // Delete using delete_data_for_user.
 408          provider::delete_data_for_users($approvedlist);
 409          // Re-fetch users in u5ctx - the user data should still be present.
 410          $userlist5 = new \core_privacy\local\request\userlist($u5ctx, $component);
 411          provider::get_users_in_context($userlist5);
 412          $this->assertCount(1, $userlist5);
 413      }
 414  
 415      /**
 416       * Create a service.
 417       *
 418       * @param array $params The params.
 419       * @return stdClass
 420       */
 421      protected function create_service(array $params = []) {
 422          global $DB;
 423          static $i = 0;
 424          $record = (object) array_merge([
 425              'name' => 'Some service',
 426              'enabled' => '1',
 427              'requiredcapability' => '',
 428              'restrictedusers' => '0',
 429              'component' => 'core_webservice',
 430              'timecreated' => time(),
 431              'timemodified' => time(),
 432              'shortname' => 'service' . $i,
 433              'downloadfiles' => '1',
 434              'uploadfiles' => '1',
 435          ], $params);
 436          $record->id = $DB->insert_record('external_services', $record);
 437          return $record;
 438      }
 439  
 440      /**
 441       * Create a service user.
 442       *
 443       * @param array $params The params.
 444       * @return stdClass
 445       */
 446      protected function create_service_user(array $params) {
 447          global $DB, $USER;
 448          static $i = 0;
 449          $record = (object) array_merge([
 450              'externalserviceid' => null,
 451              'userid' => $USER->id,
 452              'validuntil' => time() + YEARSECS,
 453              'iprestriction' => '',
 454              'timecreated' => time(),
 455          ], $params);
 456          $record->id = $DB->insert_record('external_services_users', $record);
 457          return $record;
 458      }
 459  
 460      /**
 461       * Create a token.
 462       *
 463       * @param array $params The params.
 464       * @return stdClass
 465       */
 466      protected function create_token(array $params) {
 467          global $DB, $USER;
 468          $service = $DB->get_record('external_services', ['shortname' => MOODLE_OFFICIAL_MOBILE_SERVICE]);
 469          $record = (object) array_merge([
 470              'token' => random_string(64),
 471              'privatetoken' => random_string(64),
 472              'tokentype' => EXTERNAL_TOKEN_PERMANENT,
 473              'contextid' => SYSCONTEXTID,
 474              'externalserviceid' => $service->id,
 475              'userid' => $USER->id,
 476              'validuntil' => time() + YEARSECS,
 477              'iprestriction' => null,
 478              'sid' => null,
 479              'timecreated' => time(),
 480              'lastaccess' => time(),
 481              'creatorid' => $USER->id,
 482          ], $params);
 483          $record->id = $DB->insert_record('external_tokens', $record);
 484          return $record;
 485      }
 486  }