admin.spec.ts 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327
  1. import { isExcludedBySharding, startWith } from './helpers/config'
  2. import {
  3. activateUser,
  4. createMongoUser,
  5. ensureUserExists,
  6. login,
  7. } from './helpers/login'
  8. import { v4 as uuid } from 'uuid'
  9. import { createProject } from './helpers/project'
  10. import { beforeWithReRunOnTestRetry } from './helpers/beforeWithReRunOnTestRetry'
  11. import { openEmail } from './helpers/email'
  12. describe('admin panel', function () {
  13. function registrationTests() {
  14. it('via GUI and opening URL manually', () => {
  15. const user = `${uuid()}@example.com`
  16. cy.get('input[name="email"]').type(user + '{enter}')
  17. cy.get('td')
  18. .contains(/\/user\/activate/)
  19. .then($td => {
  20. const url = $td.text().trim()
  21. activateUser(url)
  22. })
  23. })
  24. it('via GUI and email', () => {
  25. const user = `${uuid()}@example.com`
  26. cy.get('input[name="email"]').type(user + '{enter}')
  27. let url: string
  28. cy.get('td')
  29. .contains(/\/user\/activate/)
  30. .then($td => {
  31. url = $td.text().trim()
  32. })
  33. cy.then(() => {
  34. openEmail(
  35. 'Activate your Overleaf Community Edition Account',
  36. (frame, { url }) => {
  37. frame.contains('Set password').then(el => {
  38. expect(el.attr('href')!).to.equal(url)
  39. })
  40. },
  41. { url }
  42. )
  43. // Run activateUser in the main origin instead of inside openEmail. See docs on openEmail.
  44. activateUser(url)
  45. })
  46. })
  47. it('via script and opening URL manually', () => {
  48. const user = `${uuid()}@example.com`
  49. let url: string
  50. cy.then(async () => {
  51. ;({ url } = await createMongoUser({ email: user }))
  52. })
  53. cy.then(() => {
  54. activateUser(url)
  55. })
  56. })
  57. it('via script and email', () => {
  58. const user = `${uuid()}@example.com`
  59. let url: string
  60. cy.then(async () => {
  61. ;({ url } = await createMongoUser({ email: user }))
  62. })
  63. cy.then(() => {
  64. openEmail(
  65. 'Activate your Overleaf Community Edition Account',
  66. (frame, { url }) => {
  67. frame.contains('Set password').then(el => {
  68. expect(el.attr('href')!).to.equal(url)
  69. })
  70. },
  71. { url }
  72. )
  73. // Run activateUser in the main origin instead of inside openEmail. See docs on openEmail.
  74. activateUser(url)
  75. })
  76. })
  77. }
  78. describe('in CE', () => {
  79. if (isExcludedBySharding('CE_DEFAULT')) return
  80. startWith({ pro: false, version: 'latest' })
  81. const admin = 'admin@example.com'
  82. const user = `user+${uuid()}@example.com`
  83. ensureUserExists({ email: admin, isAdmin: true })
  84. ensureUserExists({ email: user })
  85. describe('create users', () => {
  86. beforeEach(() => {
  87. login(admin)
  88. cy.visit('/project')
  89. cy.get('nav').findByText('Admin').click()
  90. cy.get('nav').findByText('Manage Users').click()
  91. })
  92. registrationTests()
  93. })
  94. })
  95. describe('in server pro', () => {
  96. const admin = 'admin@example.com'
  97. const user1 = 'user@example.com'
  98. const user2 = 'user2@example.com'
  99. let testProjectName = ''
  100. let testProjectId = ''
  101. let deletedProjectName = ''
  102. let projectToDeleteId = ''
  103. const findProjectRow = (projectName: string) => {
  104. cy.log('find project row')
  105. return cy.findByText(projectName).parent().parent()
  106. }
  107. if (isExcludedBySharding('PRO_DEFAULT_2')) return
  108. startWith({
  109. pro: true,
  110. })
  111. ensureUserExists({ email: admin, isAdmin: true })
  112. ensureUserExists({ email: user1 })
  113. ensureUserExists({ email: user2 })
  114. beforeWithReRunOnTestRetry(() => {
  115. testProjectName = `project-${uuid()}`
  116. deletedProjectName = `deleted-project-${uuid()}`
  117. login(user1)
  118. createProject(testProjectName, { open: false }).then(
  119. id => (testProjectId = id)
  120. )
  121. createProject(deletedProjectName, { open: false }).then(
  122. id => (projectToDeleteId = id)
  123. )
  124. })
  125. describe('manage site', () => {
  126. beforeEach(() => {
  127. login(admin)
  128. cy.visit('/project')
  129. cy.get('nav').findByText('Admin').click()
  130. cy.get('nav').findByText('Manage Site').click()
  131. })
  132. it('publish and clear admin messages', () => {
  133. const message = 'Admin Message ' + uuid()
  134. cy.log('create system message')
  135. cy.get('[role="tab"]').contains('System Messages').click()
  136. cy.get('input[name="content"]').type(message)
  137. cy.get('button').contains('Post Message').click()
  138. cy.findByText(message)
  139. login(user1)
  140. cy.visit('/project')
  141. cy.findByText(message)
  142. cy.log('clear system messages')
  143. login(admin)
  144. cy.visit('/project')
  145. cy.get('nav').findByText('Admin').click()
  146. cy.get('nav').findByText('Manage Site').click()
  147. cy.get('[role="tab"]').contains('System Messages').click()
  148. cy.get('button').contains('Clear all messages').click()
  149. cy.log('verify system messages are no longer displayed')
  150. login(user1)
  151. cy.visit('/project')
  152. cy.findByText(message).should('not.exist')
  153. })
  154. })
  155. describe('manage users', () => {
  156. beforeEach(() => {
  157. login(admin)
  158. cy.visit('/project')
  159. cy.get('nav').findByText('Admin').click()
  160. cy.get('nav').findByText('Manage Users').click()
  161. })
  162. describe('create users', () => {
  163. beforeEach(() => {
  164. cy.get('a').contains('New User').click()
  165. })
  166. registrationTests()
  167. })
  168. it('user list RegExp search', () => {
  169. cy.get('input[name="isRegExpSearch"]').click()
  170. cy.get('input[name="email"]').type('user[0-9]{enter}')
  171. cy.findByText(user2)
  172. cy.findByText(user1).should('not.exist')
  173. })
  174. })
  175. describe('user page', () => {
  176. beforeEach(() => {
  177. login(admin)
  178. cy.visit('/project')
  179. cy.get('nav').findByText('Admin').click()
  180. cy.get('nav').findByText('Manage Users').click()
  181. cy.get('input[name="email"]').type(user1 + '{enter}')
  182. cy.findByText(user1).click()
  183. cy.url().should('match', /\/admin\/user\/[a-fA-F0-9]{24}/)
  184. })
  185. it('displays expected tabs', () => {
  186. const tabs = [
  187. 'User Info',
  188. 'Projects',
  189. 'Deleted Projects',
  190. 'Audit Log',
  191. 'Sessions',
  192. ]
  193. cy.get('[role="tab"]').each((el, index) => {
  194. cy.wrap(el).findByText(tabs[index]).click()
  195. })
  196. cy.get('[role="tab"]').should('have.length', tabs.length)
  197. })
  198. describe('user info tab', () => {
  199. beforeEach(() => {
  200. cy.get('[role="tab"]').contains('User Info').click()
  201. })
  202. it('displays required sections', () => {
  203. // not exhaustive list, checks the tab content is rendered
  204. cy.findByText('Profile')
  205. cy.findByText('Editor Settings')
  206. })
  207. it('should not display SaaS-only sections', () => {
  208. cy.findByText('Referred User Count').should('not.exist')
  209. cy.findByText('Split Test Assignments').should('not.exist')
  210. cy.findByText('Experimental Features').should('not.exist')
  211. cy.findByText('Service Integration').should('not.exist')
  212. cy.findByText('SSO Integrations').should('not.exist')
  213. cy.findByText('Security').should('not.exist')
  214. })
  215. })
  216. it('transfer project ownership', () => {
  217. cy.log("access project admin through owners' project list")
  218. cy.get('[role="tab"]').contains('Projects').click()
  219. cy.get(`a[href="/admin/project/${testProjectId}"]`).click()
  220. cy.findByText('Transfer Ownership').click()
  221. cy.get('button[type="submit"]').should('be.disabled')
  222. cy.get('input[name="user_id"]').type(user2)
  223. cy.get('button[type="submit"]').should('not.be.disabled')
  224. cy.get('button[type="submit"]').click()
  225. cy.findByText('Transfer project to this user?')
  226. cy.get('button').contains('Confirm').click()
  227. cy.log('check the project is displayed in the new owner projects tab')
  228. cy.get('input[name="email"]').type(user2 + '{enter}')
  229. cy.findByText(user2).click()
  230. cy.get('[role="tab"]').contains('Projects').click()
  231. cy.get(`a[href="/admin/project/${testProjectId}"]`)
  232. })
  233. })
  234. describe('project page', () => {
  235. beforeEach(() => {
  236. login(admin)
  237. cy.visit(`/admin/project/${testProjectId}`)
  238. })
  239. it('displays expected tabs', () => {
  240. const tabs = ['Project Info', 'Deleted Docs', 'Audit Log']
  241. cy.get('[role="tab"]').each((el, index) => {
  242. cy.wrap(el).findByText(tabs[index]).click()
  243. })
  244. cy.get('[role="tab"]').should('have.length', tabs.length)
  245. })
  246. })
  247. it('restore deleted projects', () => {
  248. login(user1)
  249. cy.visit('/project')
  250. cy.log('select project to delete')
  251. findProjectRow(deletedProjectName).within(() =>
  252. cy.get('input[type="checkbox"]').first().check()
  253. )
  254. cy.log('delete project')
  255. findProjectRow(deletedProjectName).within(() =>
  256. cy.findByRole('button', { name: 'Trash' }).click()
  257. )
  258. cy.get('button').contains('Confirm').click()
  259. cy.findByText(deletedProjectName).should('not.exist')
  260. cy.log('navigate to thrashed projects and delete the project')
  261. cy.get('.project-list-sidebar-scroll').within(() => {
  262. cy.findByText('Trashed Projects').click()
  263. })
  264. findProjectRow(deletedProjectName).within(() =>
  265. cy.findByRole('button', { name: 'Delete' }).click()
  266. )
  267. cy.get('button').contains('Confirm').click()
  268. cy.findByText(deletedProjectName).should('not.exist')
  269. cy.log('login as an admin and navigate to the deleted project')
  270. login(admin)
  271. cy.visit('/admin/user')
  272. cy.get('input[name="email"]').type(user1 + '{enter}')
  273. cy.get('a').contains(user1).click()
  274. cy.findByText('Deleted Projects').click()
  275. cy.get('a').contains(deletedProjectName).click()
  276. cy.log('undelete the project')
  277. cy.findByText('Undelete').click()
  278. cy.findByText('Undelete').should('not.exist')
  279. cy.url().should('contain', `/admin/project/${projectToDeleteId}`)
  280. cy.log('login as the user and verify the project is restored')
  281. login(user1)
  282. cy.visit('/project')
  283. cy.get('.project-list-sidebar-scroll').within(() => {
  284. cy.findByText('Trashed Projects').click()
  285. })
  286. cy.findByText(`${deletedProjectName} (Restored)`)
  287. })
  288. })
  289. })