test_attachments_api.py 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287
  1. import os
  2. from PIL import Image
  3. from django.urls import reverse
  4. from django.utils import six
  5. from misago.acl.models import Role
  6. from misago.acl.testutils import override_acl
  7. from misago.conf import settings
  8. from misago.threads.models import Attachment, AttachmentType
  9. from misago.users.testutils import AuthenticatedUserTestCase
  10. TESTFILES_DIR = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'testfiles')
  11. TEST_DOCUMENT_PATH = os.path.join(TESTFILES_DIR, 'document.pdf')
  12. TEST_LARGEPNG_PATH = os.path.join(TESTFILES_DIR, 'large.png')
  13. TEST_SMALLJPG_PATH = os.path.join(TESTFILES_DIR, 'small.jpg')
  14. TEST_ANIMATEDGIF_PATH = os.path.join(TESTFILES_DIR, 'animated.gif')
  15. TEST_CORRUPTEDIMG_PATH = os.path.join(TESTFILES_DIR, 'corrupted.gif')
  16. class AttachmentsApiTestCase(AuthenticatedUserTestCase):
  17. def setUp(self):
  18. super(AttachmentsApiTestCase, self).setUp()
  19. AttachmentType.objects.all().delete()
  20. self.api_link = reverse('misago:api:attachment-list')
  21. def override_acl(self, new_acl=None):
  22. if new_acl:
  23. acl = self.user.acl_cache.copy()
  24. acl.update(new_acl)
  25. override_acl(self.user, acl)
  26. def test_anonymous(self):
  27. """user has to be authenticated to be able to upload files"""
  28. self.logout_user()
  29. response = self.client.post(self.api_link)
  30. self.assertEqual(response.status_code, 403)
  31. def test_no_permission(self):
  32. """user needs permission to upload files"""
  33. self.override_acl({'max_attachment_size': 0})
  34. response = self.client.post(self.api_link)
  35. self.assertContains(response, "don't have permission to upload new files", status_code=403)
  36. def test_no_file_uploaded(self):
  37. """no file uploaded scenario is handled"""
  38. response = self.client.post(self.api_link)
  39. self.assertContains(response, "No file has been uploaded.", status_code=400)
  40. def test_invalid_extension(self):
  41. """uploaded file's extension is rejected as invalid"""
  42. AttachmentType.objects.create(name="Test extension", extensions='jpg,jpeg', mimetypes=None)
  43. with open(TEST_DOCUMENT_PATH, 'rb') as upload:
  44. response = self.client.post(self.api_link, data={'upload': upload})
  45. self.assertContains(response, "You can't upload files of this type.", status_code=400)
  46. def test_invalid_mime(self):
  47. """uploaded file's mimetype is rejected as invalid"""
  48. AttachmentType.objects.create(
  49. name="Test extension", extensions='png', mimetypes='loremipsum'
  50. )
  51. with open(TEST_DOCUMENT_PATH, 'rb') as upload:
  52. response = self.client.post(self.api_link, data={'upload': upload})
  53. self.assertContains(response, "You can't upload files of this type.", status_code=400)
  54. def test_no_perm_to_type(self):
  55. """user needs permission to upload files of this type"""
  56. attachment_type = AttachmentType.objects.create(
  57. name="Test extension", extensions='png', mimetypes='application/pdf'
  58. )
  59. user_roles = (r.pk for r in self.user.get_roles())
  60. attachment_type.limit_uploads_to.set(Role.objects.exclude(id__in=user_roles))
  61. with open(TEST_DOCUMENT_PATH, 'rb') as upload:
  62. response = self.client.post(self.api_link, data={'upload': upload})
  63. self.assertContains(response, "You can't upload files of this type.", status_code=400)
  64. def test_type_is_locked(self):
  65. """new uploads for this filetype are locked"""
  66. AttachmentType.objects.create(
  67. name="Test extension",
  68. extensions='png',
  69. mimetypes='application/pdf',
  70. status=AttachmentType.LOCKED
  71. )
  72. with open(TEST_DOCUMENT_PATH, 'rb') as upload:
  73. response = self.client.post(self.api_link, data={'upload': upload})
  74. self.assertContains(response, "You can't upload files of this type.", status_code=400)
  75. def test_type_is_disabled(self):
  76. """new uploads for this filetype are disabled"""
  77. AttachmentType.objects.create(
  78. name="Test extension",
  79. extensions='png',
  80. mimetypes='application/pdf',
  81. status=AttachmentType.DISABLED
  82. )
  83. with open(TEST_DOCUMENT_PATH, 'rb') as upload:
  84. response = self.client.post(self.api_link, data={'upload': upload})
  85. self.assertContains(response, "You can't upload files of this type.", status_code=400)
  86. def test_upload_too_big_for_type(self):
  87. """too big uploads are rejected"""
  88. AttachmentType.objects.create(
  89. name="Test extension", extensions='png', mimetypes='image/png', size_limit=100
  90. )
  91. with open(TEST_LARGEPNG_PATH, 'rb') as upload:
  92. response = self.client.post(self.api_link, data={'upload': upload})
  93. self.assertContains(
  94. response, "can't upload files of this type larger than", status_code=400
  95. )
  96. def test_upload_too_big_for_user(self):
  97. """too big uploads are rejected"""
  98. self.override_acl({'max_attachment_size': 100})
  99. AttachmentType.objects.create(
  100. name="Test extension", extensions='png', mimetypes='image/png'
  101. )
  102. with open(TEST_LARGEPNG_PATH, 'rb') as upload:
  103. response = self.client.post(self.api_link, data={'upload': upload})
  104. self.assertContains(response, "can't upload files larger than", status_code=400)
  105. def test_corrupted_image_upload(self):
  106. """corrupted image upload is handled"""
  107. AttachmentType.objects.create(name="Test extension", extensions='gif')
  108. with open(TEST_CORRUPTEDIMG_PATH, 'rb') as upload:
  109. response = self.client.post(self.api_link, data={'upload': upload})
  110. self.assertContains(response, "Uploaded image was corrupted or invalid.", status_code=400)
  111. def test_document_upload(self):
  112. """successful upload creates orphan attachment"""
  113. AttachmentType.objects.create(
  114. name="Test extension", extensions='pdf', mimetypes='application/pdf'
  115. )
  116. with open(TEST_DOCUMENT_PATH, 'rb') as upload:
  117. response = self.client.post(self.api_link, data={'upload': upload})
  118. self.assertEqual(response.status_code, 200)
  119. response_json = response.json()
  120. attachment = Attachment.objects.get(id=response_json['id'])
  121. self.assertEqual(attachment.filename, 'document.pdf')
  122. self.assertTrue(attachment.is_file)
  123. self.assertFalse(attachment.is_image)
  124. self.assertIsNotNone(attachment.file)
  125. self.assertTrue(not attachment.image)
  126. self.assertTrue(not attachment.thumbnail)
  127. self.assertTrue(six.text_type(attachment.file).endswith('document.pdf'))
  128. self.assertIsNone(response_json['post'])
  129. self.assertEqual(response_json['uploader_name'], self.user.username)
  130. self.assertEqual(response_json['url']['index'], attachment.get_absolute_url())
  131. self.assertIsNone(response_json['url']['thumb'])
  132. self.assertEqual(response_json['url']['uploader'], self.user.get_absolute_url())
  133. # files associated with attachment are deleted on its deletion
  134. file_path = attachment.file.path
  135. self.assertTrue(os.path.exists(file_path))
  136. attachment.delete()
  137. self.assertFalse(os.path.exists(file_path))
  138. def test_small_image_upload(self):
  139. """successful small image upload creates orphan attachment without thumbnail"""
  140. AttachmentType.objects.create(
  141. name="Test extension", extensions='jpeg,jpg', mimetypes='image/jpeg'
  142. )
  143. with open(TEST_SMALLJPG_PATH, 'rb') as upload:
  144. response = self.client.post(self.api_link, data={'upload': upload})
  145. self.assertEqual(response.status_code, 200)
  146. response_json = response.json()
  147. attachment = Attachment.objects.get(id=response_json['id'])
  148. self.assertEqual(attachment.filename, 'small.jpg')
  149. self.assertFalse(attachment.is_file)
  150. self.assertTrue(attachment.is_image)
  151. self.assertTrue(not attachment.file)
  152. self.assertIsNotNone(attachment.image)
  153. self.assertTrue(not attachment.thumbnail)
  154. self.assertTrue(six.text_type(attachment.image).endswith('small.jpg'))
  155. self.assertIsNone(response_json['post'])
  156. self.assertEqual(response_json['uploader_name'], self.user.username)
  157. self.assertEqual(response_json['url']['index'], attachment.get_absolute_url())
  158. self.assertIsNone(response_json['url']['thumb'])
  159. self.assertEqual(response_json['url']['uploader'], self.user.get_absolute_url())
  160. def test_large_image_upload(self):
  161. """successful large image upload creates orphan attachment with thumbnail"""
  162. self.override_acl({'max_attachment_size': 10 * 1024})
  163. AttachmentType.objects.create(
  164. name="Test extension", extensions='png', mimetypes='image/png'
  165. )
  166. with open(TEST_LARGEPNG_PATH, 'rb') as upload:
  167. response = self.client.post(self.api_link, data={'upload': upload})
  168. self.assertEqual(response.status_code, 200)
  169. response_json = response.json()
  170. attachment = Attachment.objects.get(id=response_json['id'])
  171. self.assertEqual(attachment.filename, 'large.png')
  172. self.assertFalse(attachment.is_file)
  173. self.assertTrue(attachment.is_image)
  174. self.assertTrue(not attachment.file)
  175. self.assertIsNotNone(attachment.image)
  176. self.assertIsNotNone(attachment.thumbnail)
  177. self.assertTrue(six.text_type(attachment.image).endswith('large.png'))
  178. self.assertTrue(six.text_type(attachment.thumbnail).endswith('large.png'))
  179. self.assertIsNone(response_json['post'])
  180. self.assertEqual(response_json['uploader_name'], self.user.username)
  181. self.assertEqual(response_json['url']['index'], attachment.get_absolute_url())
  182. self.assertEqual(response_json['url']['thumb'], attachment.get_thumbnail_url())
  183. self.assertEqual(response_json['url']['uploader'], self.user.get_absolute_url())
  184. # thumbnail was scaled down
  185. thumbnail = Image.open(attachment.thumbnail.path)
  186. self.assertEqual(thumbnail.size[0], settings.MISAGO_ATTACHMENT_IMAGE_SIZE_LIMIT[0])
  187. self.assertLess(thumbnail.size[1], settings.MISAGO_ATTACHMENT_IMAGE_SIZE_LIMIT[1])
  188. # files associated with attachment are deleted on its deletion
  189. image_path = attachment.image.path
  190. thumbnail_path = attachment.thumbnail.path
  191. self.assertTrue(os.path.exists(image_path))
  192. self.assertTrue(os.path.exists(thumbnail_path))
  193. attachment.delete()
  194. self.assertFalse(os.path.exists(image_path))
  195. self.assertFalse(os.path.exists(thumbnail_path))
  196. def test_animated_image_upload(self):
  197. """successful gif upload creates orphan attachment with thumbnail"""
  198. AttachmentType.objects.create(
  199. name="Test extension", extensions='gif', mimetypes='image/gif'
  200. )
  201. with open(TEST_ANIMATEDGIF_PATH, 'rb') as upload:
  202. response = self.client.post(self.api_link, data={'upload': upload})
  203. self.assertEqual(response.status_code, 200)
  204. response_json = response.json()
  205. attachment = Attachment.objects.get(id=response_json['id'])
  206. self.assertEqual(attachment.filename, 'animated.gif')
  207. self.assertFalse(attachment.is_file)
  208. self.assertTrue(attachment.is_image)
  209. self.assertTrue(not attachment.file)
  210. self.assertIsNotNone(attachment.image)
  211. self.assertIsNotNone(attachment.thumbnail)
  212. self.assertTrue(six.text_type(attachment.image).endswith('animated.gif'))
  213. self.assertTrue(six.text_type(attachment.thumbnail).endswith('animated.gif'))
  214. self.assertIsNone(response_json['post'])
  215. self.assertEqual(response_json['uploader_name'], self.user.username)
  216. self.assertEqual(response_json['url']['index'], attachment.get_absolute_url())
  217. self.assertEqual(response_json['url']['thumb'], attachment.get_thumbnail_url())
  218. self.assertEqual(response_json['url']['uploader'], self.user.get_absolute_url())