Skip to content
InlineBlockPrivateFilesTest.php 7.45 KiB
Newer Older

namespace Drupal\Tests\layout_builder\FunctionalJavascript;

use Drupal\file\Entity\File;
use Drupal\file\FileInterface;
use Drupal\node\Entity\Node;
use Drupal\Tests\file\Functional\FileFieldCreationTrait;
use Drupal\Tests\TestFileCreationTrait;

 * Test access to private files in block fields on the Layout Builder.
 * @group layout_builder
class InlineBlockPrivateFilesTest extends InlineBlockTestBase {

  use FileFieldCreationTrait;
  use TestFileCreationTrait;

   * {@inheritdoc}
  public static $modules = [

   * The file system service.
   * @var \Drupal\Core\File\FileSystemInterface
  protected $fileSystem;

   * {@inheritdoc}
  protected function setUp() {
    $field_settings = [
      'file_extensions' => 'txt',
      'uri_scheme' => 'private',
    $this->createFileField('field_file', 'block_content', 'basic', $field_settings);
    $this->fileSystem = $this->container->get('file_system');

   * Test access to private files added via inline blocks in the layout builder.
  public function testPrivateFiles() {
    $assert_session = $this->assertSession();
      'access contextual links',
      'configure any layout',
      'administer node display',
      'administer node fields',

    // Enable layout builder and overrides.
      static::FIELD_UI_PREFIX . '/display/default',
      ['layout[enabled]' => TRUE, 'layout[allow_custom]' => TRUE],

    // Log in as user you can only configure layouts and access content.
      'access contextual links',
      'configure any layout',
      'access content',
    $file = $this->createPrivateFile('drupal.txt');

    $file_real_path = $this->fileSystem->realpath($file->getFileUri());
    $this->addInlineFileBlockToLayout('The file', $file);

    $private_href1 = $this->assertFileAccessibleOnNode($file);


    // Try to access file directly after it has been removed.
    $assert_session->pageTextContains('You are not authorized to access this page');

    $file2 = $this->createPrivateFile('2ndFile.txt');

    $this->addInlineFileBlockToLayout('Number2', $file2);

    $private_href2 = $this->assertFileAccessibleOnNode($file2);

    $node = Node::load(1);
    $node->setTitle('Update node');

    $file3 = $this->createPrivateFile('3rdFile.txt');

    $private_href3 = $this->assertFileAccessibleOnNode($file3);

    $assert_session->pageTextContains('You are not authorized to access this page');

    $assert_session->pageTextContains('You are not authorized to access this page');
    $assert_session->pageTextContains('You are not authorized to access this page');

   * Replaces the file in the block with another one.
   * @param \Drupal\file\FileInterface $file
   *   The file entity.
  protected function replaceFileInBlock(FileInterface $file) {
    $assert_session = $this->assertSession();
    $page = $this->getSession()->getPage();
    $this->clickContextualLink(static::INLINE_BLOCK_LOCATOR, 'Configure');
    $this->assertDialogClosedAndTextVisible($file->label(), static::INLINE_BLOCK_LOCATOR);

   * Adds an entity block with a file.
   * @param string $title
   *   The title field value.
   * @param \Drupal\file\Entity\File $file
   *   The file entity.
  protected function addInlineFileBlockToLayout($title, File $file) {
    $assert_session = $this->assertSession();
    $page = $this->getSession()->getPage();
    $page->clickLink('Add Block');
    $this->assertNotEmpty($assert_session->waitForElementVisible('css', '.block-categories details:contains(Create new block)'));
    $this->clickLink('Basic block');
    $assert_session->fieldValueEquals('Title', '');
    $page->pressButton('Add Block');
    $this->assertDialogClosedAndTextVisible($file->label(), static::INLINE_BLOCK_LOCATOR);

   * Creates a private file.
   * @param string $file_name
   *   The file name.
   * @return \Drupal\Core\Entity\EntityInterface|\Drupal\file\Entity\File
   *   The file entity.
  protected function createPrivateFile($file_name) {
    // Create a new file entity.
    $file = File::create([
      'uid' => 1,
      'filename' => $file_name,
      'uri' => "private://$file_name",
      'filemime' => 'text/plain',
      'status' => FILE_STATUS_PERMANENT,
    file_put_contents($file->getFileUri(), $this->getFileSecret($file));
    return $file;

   * Asserts a file is accessible on the page.
   * @param \Drupal\file\FileInterface $file
   *   The file entity.
   * @return string
   *   The file href.
  protected function assertFileAccessibleOnNode(FileInterface $file) {
    $assert_session = $this->assertSession();
    $page = $this->getSession()->getPage();
    $private_href = $page->findLink($file->label())->getAttribute('href');

    // Access file directly.
    return $private_href;

   * Gets the text secret for a file.
   * @param \Drupal\file\FileInterface $file
   *   The file entity.
   * @return string
   *   The text secret.
  protected function getFileSecret(FileInterface $file) {
    return "The secret in {$file->label()}";

   * Attaches a file to the block edit form.
   * @param \Drupal\file\FileInterface $file
   *   The file to be attached.
  protected function attachFileToBlockForm(FileInterface $file) {
    $assert_session = $this->assertSession();
    $page = $this->getSession()->getPage();
    $page->attachFileToField("files[settings_block_form_field_file_0]", $this->fileSystem->realpath($file->getFileUri()));
