admin.spec.ts 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310
  1. import { isExcludedBySharding, startWith } from './helpers/config'
  2. import {
  3. activateUser,
  4. createMongoUser,
  5. ensureUserExists,
  6. login,
  7. } from './helpers/login'
  8. import { v4 as uuid } from 'uuid'
  9. import { createProject } from './helpers/project'
  10. import { beforeWithReRunOnTestRetry } from './helpers/beforeWithReRunOnTestRetry'
  11. import { openEmail } from './helpers/email'
  12. describe('admin panel', function () {
  13. function registrationTests() {
  14. it('via GUI and opening URL manually', () => {
  15. const user = `${uuid()}@example.com`
  16. cy.get('input[name="email"]').type(user + '{enter}')
  17. cy.get('td')
  18. .contains(/\/user\/activate/)
  19. .then($td => {
  20. const url = $td.text().trim()
  21. activateUser(url)
  22. })
  23. })
  24. it('via GUI and email', () => {
  25. const user = `${uuid()}@example.com`
  26. cy.get('input[name="email"]').type(user + '{enter}')
  27. let url: string
  28. cy.get('td')
  29. .contains(/\/user\/activate/)
  30. .then($td => {
  31. url = $td.text().trim()
  32. })
  33. cy.then(() => {
  34. openEmail(
  35. 'Activate your Overleaf Community Edition Account',
  36. (frame, { url }) => {
  37. frame.contains('Set password').then(el => {
  38. expect(el.attr('href')!).to.equal(url)
  39. })
  40. },
  41. { url }
  42. )
  43. // Run activateUser in the main origin instead of inside openEmail. See docs on openEmail.
  44. activateUser(url)
  45. })
  46. })
  47. it('via script and opening URL manually', () => {
  48. const user = `${uuid()}@example.com`
  49. let url: string
  50. cy.then(async () => {
  51. ;({ url } = await createMongoUser({ email: user }))
  52. })
  53. cy.then(() => {
  54. activateUser(url)
  55. })
  56. })
  57. it('via script and email', () => {
  58. const user = `${uuid()}@example.com`
  59. let url: string
  60. cy.then(async () => {
  61. ;({ url } = await createMongoUser({ email: user }))
  62. })
  63. cy.then(() => {
  64. openEmail(
  65. 'Activate your Overleaf Community Edition Account',
  66. (frame, { url }) => {
  67. frame.contains('Set password').then(el => {
  68. expect(el.attr('href')!).to.equal(url)
  69. })
  70. },
  71. { url }
  72. )
  73. // Run activateUser in the main origin instead of inside openEmail. See docs on openEmail.
  74. activateUser(url)
  75. })
  76. })
  77. }
  78. describe('in CE', () => {
  79. if (isExcludedBySharding('CE_DEFAULT')) return
  80. startWith({ pro: false, version: 'latest' })
  81. const admin = 'admin@example.com'
  82. const user = `user+${uuid()}@example.com`
  83. ensureUserExists({ email: admin, isAdmin: true })
  84. ensureUserExists({ email: user })
  85. describe('create users', () => {
  86. beforeEach(() => {
  87. login(admin)
  88. cy.visit('/project')
  89. cy.get('nav').findByText('Admin').click()
  90. cy.get('nav').findByText('Manage Users').click()
  91. })
  92. registrationTests()
  93. })
  94. })
  95. describe('in server pro', () => {
  96. const admin = 'admin@example.com'
  97. const user1 = 'user@example.com'
  98. const user2 = 'user2@example.com'
  99. let testProjectName = ''
  100. let testProjectId = ''
  101. let deletedProjectName = ''
  102. let projectToDeleteId = ''
  103. const findProjectRow = (projectName: string) => {
  104. cy.log('find project row')
  105. return cy.findByText(projectName).parent().parent()
  106. }
  107. if (isExcludedBySharding('PRO_DEFAULT_2')) return
  108. startWith({
  109. pro: true,
  110. })
  111. ensureUserExists({ email: admin, isAdmin: true })
  112. ensureUserExists({ email: user1 })
  113. ensureUserExists({ email: user2 })
  114. beforeWithReRunOnTestRetry(() => {
  115. testProjectName = `project-${uuid()}`
  116. deletedProjectName = `deleted-project-${uuid()}`
  117. login(user1)
  118. cy.visit('/project')
  119. createProject(testProjectName).then(id => (testProjectId = id))
  120. cy.visit('/project')
  121. createProject(deletedProjectName).then(id => (projectToDeleteId = id))
  122. })
  123. describe('manage site', () => {
  124. beforeEach(() => {
  125. login(admin)
  126. cy.visit('/project')
  127. cy.get('nav').findByText('Admin').click()
  128. cy.get('nav').findByText('Manage Site').click()
  129. })
  130. it('publish and clear admin messages', () => {
  131. const message = 'Admin Message ' + uuid()
  132. cy.log('create system message')
  133. cy.get('[role="tab"]').contains('System Messages').click()
  134. cy.get('input[name="content"]').type(message)
  135. cy.get('button').contains('Post Message').click()
  136. cy.findByText(message)
  137. login(user1)
  138. cy.visit('/project')
  139. cy.findByText(message)
  140. cy.log('clear system messages')
  141. login(admin)
  142. cy.visit('/project')
  143. cy.get('nav').findByText('Admin').click()
  144. cy.get('nav').findByText('Manage Site').click()
  145. cy.get('[role="tab"]').contains('System Messages').click()
  146. cy.get('button').contains('Clear all messages').click()
  147. cy.log('verify system messages are no longer displayed')
  148. login(user1)
  149. cy.visit('/project')
  150. cy.findByText(message).should('not.exist')
  151. })
  152. })
  153. describe('manage users', () => {
  154. beforeEach(() => {
  155. login(admin)
  156. cy.visit('/project')
  157. cy.get('nav').findByText('Admin').click()
  158. cy.get('nav').findByText('Manage Users').click()
  159. })
  160. describe('create users', () => {
  161. beforeEach(() => {
  162. cy.get('a').contains('New User').click()
  163. })
  164. registrationTests()
  165. })
  166. it('user list RegExp search', () => {
  167. cy.get('input[name="isRegExpSearch"]').click()
  168. cy.get('input[name="email"]').type('user[0-9]{enter}')
  169. cy.findByText(user2)
  170. cy.findByText(user1).should('not.exist')
  171. })
  172. })
  173. describe('user page', () => {
  174. beforeEach(() => {
  175. login(admin)
  176. cy.visit('/project')
  177. cy.get('nav').findByText('Admin').click()
  178. cy.get('nav').findByText('Manage Users').click()
  179. cy.get('input[name="email"]').type(user1 + '{enter}')
  180. cy.findByText(user1).click()
  181. cy.url().should('match', /\/admin\/user\/[a-fA-F0-9]{24}/)
  182. })
  183. it('displays expected tabs', () => {
  184. const tabs = [
  185. 'User Info',
  186. 'Projects',
  187. 'Deleted Projects',
  188. 'Audit Log',
  189. 'Sessions',
  190. ]
  191. cy.get('[role="tab"]').each((el, index) => {
  192. cy.wrap(el).findByText(tabs[index]).click()
  193. })
  194. })
  195. describe('user info tab', () => {
  196. beforeEach(() => {
  197. cy.get('[role="tab"]').contains('User Info').click()
  198. })
  199. it('displays required sections', () => {
  200. // not exhaustive list, checks the tab content is rendered
  201. cy.findByText('Profile')
  202. cy.findByText('Editor Settings')
  203. })
  204. it('should not display SaaS-only sections', () => {
  205. cy.findByText('Referred User Count').should('not.exist')
  206. cy.findByText('Split Test Assignments').should('not.exist')
  207. cy.findByText('Experimental Features').should('not.exist')
  208. cy.findByText('Service Integration').should('not.exist')
  209. cy.findByText('SSO Integrations').should('not.exist')
  210. cy.findByText('Security').should('not.exist')
  211. })
  212. })
  213. it('transfer project ownership', () => {
  214. cy.log("access project admin through owners' project list")
  215. cy.get('[role="tab"]').contains('Projects').click()
  216. cy.get(`a[href="/admin/project/${testProjectId}"]`).click()
  217. cy.findByText('Transfer Ownership').click()
  218. cy.get('button[type="submit"]').should('be.disabled')
  219. cy.get('input[name="user_id"]').type(user2)
  220. cy.get('button[type="submit"]').should('not.be.disabled')
  221. cy.get('button[type="submit"]').click()
  222. cy.findByText('Transfer project to this user?')
  223. cy.get('button').contains('Confirm').click()
  224. cy.log('check the project is displayed in the new owner projects tab')
  225. cy.get('input[name="email"]').type(user2 + '{enter}')
  226. cy.findByText(user2).click()
  227. cy.get('[role="tab"]').contains('Projects').click()
  228. cy.get(`a[href="/admin/project/${testProjectId}"]`)
  229. })
  230. })
  231. // eslint-disable-next-line mocha/no-skipped-tests
  232. it.skip('restore deleted projects', () => {
  233. login(user1)
  234. cy.visit('/project')
  235. cy.log('select project to delete')
  236. findProjectRow(deletedProjectName).within(() =>
  237. cy.get('input[type="checkbox"]').first().check()
  238. )
  239. cy.log('delete project')
  240. findProjectRow(deletedProjectName).within(() =>
  241. cy.contains('Trash').click()
  242. )
  243. cy.get('button').contains('Confirm').click()
  244. cy.findByText(deletedProjectName).should('not.exist')
  245. cy.log('navigate to thrashed projects and delete the project')
  246. cy.get('.project-list-sidebar-react').within(() => {
  247. cy.findByText('Trashed Projects').click()
  248. })
  249. findProjectRow(deletedProjectName).within(() =>
  250. cy.contains('Delete').click()
  251. )
  252. cy.get('button').contains('Confirm').click()
  253. cy.findByText(deletedProjectName).should('not.exist')
  254. cy.log('login as an admin and navigate to the deleted project')
  255. login(admin)
  256. cy.visit('/admin/user')
  257. cy.get('input[name="email"]').type(user1 + '{enter}')
  258. cy.get('a').contains(user1).click()
  259. cy.findByText('Deleted Projects').click()
  260. cy.get('a').contains(deletedProjectName).click()
  261. cy.log('undelete the project')
  262. cy.findByText('undelete').click()
  263. cy.findByText('undelete').should('not.exist')
  264. cy.url().should('contain', `/admin/project/${projectToDeleteId}`)
  265. cy.log('login as the user and verify the project is restored')
  266. login(user1)
  267. cy.visit('/project')
  268. cy.get('.project-list-sidebar-react').within(() => {
  269. cy.findByText('Trashed Projects').click()
  270. })
  271. cy.findByText(`${deletedProjectName} (Restored)`)
  272. })
  273. })
  274. })