Newer
Older
<?php
/**
* @file
* Definition of Drupal\image\Tests\ImageStylesPathAndUrlTest.
*/
namespace Drupal\image\Tests;
use Drupal\simpletest\WebTestBase;
use Symfony\Component\HttpFoundation\Request;
/**
* Tests the functions for generating paths and URLs for image styles.
*
* @group image
*/
class ImageStylesPathAndUrlTest extends WebTestBase {
/**
* Modules to enable.
*
* @var array
*/
public static $modules = array('image', 'image_module_test');
Alex Pott
committed
/**
* @var \Drupal\image\ImageStyleInterface
*/
protected $style;
Alex Pott
committed
protected function setUp() {
parent::setUp();
Alex Pott
committed
$this->style = entity_create('image_style', array('name' => 'style_foo', 'label' => $this->randomString()));
$this->style->save();
Alex Pott
committed
* Tests \Drupal\image\ImageStyleInterface::buildUri().
*/
function testImageStylePath() {
$scheme = 'public';
Alex Pott
committed
$actual = $this->style->buildUri("$scheme://foo/bar.gif");
$expected = "$scheme://styles/" . $this->style->id() . "/$scheme/foo/bar.gif";
Dries Buytaert
committed
$this->assertEqual($actual, $expected, 'Got the path for a file URI.');
Alex Pott
committed
$actual = $this->style->buildUri('foo/bar.gif');
$expected = "$scheme://styles/" . $this->style->id() . "/$scheme/foo/bar.gif";
Dries Buytaert
committed
$this->assertEqual($actual, $expected, 'Got the path for a relative file path.');
Alex Pott
committed
* Tests an image style URL using the "public://" scheme.
*/
function testImageStyleUrlAndPathPublic() {
Alex Pott
committed
$this->doImageStyleUrlAndPathTests('public');
Alex Pott
committed
* Tests an image style URL using the "private://" scheme.
*/
function testImageStyleUrlAndPathPrivate() {
Alex Pott
committed
$this->doImageStyleUrlAndPathTests('private');
Alex Pott
committed
* Tests an image style URL with the "public://" scheme and unclean URLs.
Alex Pott
committed
function testImageStyleUrlAndPathPublicUnclean() {
$this->doImageStyleUrlAndPathTests('public', FALSE);
Alex Pott
committed
* Tests an image style URL with the "private://" schema and unclean URLs.
*/
function testImageStyleUrlAndPathPrivateUnclean() {
Alex Pott
committed
$this->doImageStyleUrlAndPathTests('private', FALSE);
Alex Pott
committed
* Tests an image style URL with a file URL that has an extra slash in it.
Angie Byron
committed
function testImageStyleUrlExtraSlash() {
Alex Pott
committed
$this->doImageStyleUrlAndPathTests('public', TRUE, TRUE);
Angie Byron
committed
}
/**
* Tests that an invalid source image returns a 404.
*/
function testImageStyleUrlForMissingSourceImage() {
$non_existent_uri = 'public://foo.png';
Alex Pott
committed
$generated_url = $this->style->buildUrl($non_existent_uri);
$this->drupalGet($generated_url);
$this->assertResponse(404, 'Accessing an image style URL with a source image that does not exist provides a 404 error response.');
}
Angie Byron
committed
/**
Alex Pott
committed
* Tests building an image style URL.
Angie Byron
committed
*/
Alex Pott
committed
function doImageStyleUrlAndPathTests($scheme, $clean_url = TRUE, $extra_slash = FALSE) {
$this->prepareRequestForGenerator($clean_url);
// Make the default scheme neither "public" nor "private" to verify the
// functions work for other than the default scheme.
$this->config('system.file')->set('default_scheme', 'temporary')->save();
// Create the directories for the styles.
Alex Pott
committed
$directory = $scheme . '://styles/' . $this->style->id();
$status = file_prepare_directory($directory, FILE_CREATE_DIRECTORY);
Dries Buytaert
committed
$this->assertNotIdentical(FALSE, $status, 'Created the directory for the generated images for the test style.');
// Create a working copy of the file.
$files = $this->drupalGetTestFiles('image');
Angie Byron
committed
$file = array_shift($files);
$original_uri = file_unmanaged_copy($file->uri, $scheme . '://', FILE_EXISTS_RENAME);
// Let the image_module_test module know about this file, so it can claim
// ownership in hook_file_download().
\Drupal::state()->set('image.test_file_download', $original_uri);
Dries Buytaert
committed
$this->assertNotIdentical(FALSE, $original_uri, 'Created the generated image file.');
// Get the URL of a file that has not been generated and try to create it.
Alex Pott
committed
$generated_uri = $this->style->buildUri($original_uri);
Dries Buytaert
committed
$this->assertFalse(file_exists($generated_uri), 'Generated file does not exist.');
Alex Pott
committed
$generate_url = $this->style->buildUrl($original_uri, $clean_url);
Angie Byron
committed
// Ensure that the tests still pass when the file is generated by accessing
// a poorly constructed (but still valid) file URL that has an extra slash
// in it.
if ($extra_slash) {
$modified_uri = str_replace('://', ':///', $original_uri);
$this->assertNotEqual($original_uri, $modified_uri, 'An extra slash was added to the generated file URI.');
Alex Pott
committed
$generate_url = $this->style->buildUrl($modified_uri, $clean_url);
Angie Byron
committed
}
if (!$clean_url) {
$this->assertTrue(strpos($generate_url, 'index.php/') !== FALSE, 'When using non-clean URLS, the system path contains the script name.');
Angie Byron
committed
// Add some extra chars to the token.
$this->drupalGet(str_replace(IMAGE_DERIVATIVE_TOKEN . '=', IMAGE_DERIVATIVE_TOKEN . '=Zo', $generate_url));
Jennifer Hodgdon
committed
$this->assertResponse(403, 'Image was inaccessible at the URL with an invalid token.');
Angie Byron
committed
// Change the parameter name so the token is missing.
$this->drupalGet(str_replace(IMAGE_DERIVATIVE_TOKEN . '=', 'wrongparam=', $generate_url));
Jennifer Hodgdon
committed
$this->assertResponse(403, 'Image was inaccessible at the URL with a missing token.');
// Check that the generated URL is the same when we pass in a relative path
// rather than a URI. We need to temporarily switch the default scheme to
// match the desired scheme before testing this, then switch it back to the
// "temporary" scheme used throughout this test afterwards.
$this->config('system.file')->set('default_scheme', $scheme)->save();
$relative_path = file_uri_target($original_uri);
$generate_url_from_relative_path = $this->style->buildUrl($relative_path, $clean_url);
$this->assertEqual($generate_url, $generate_url_from_relative_path);
$this->config('system.file')->set('default_scheme', 'temporary')->save();
// Fetch the URL that generates the file.
$this->drupalGet($generate_url);
Dries Buytaert
committed
$this->assertResponse(200, 'Image was generated at the URL.');
$this->assertTrue(file_exists($generated_uri), 'Generated file does exist after we accessed it.');
$this->assertRaw(file_get_contents($generated_uri), 'URL returns expected file.');
$image = $this->container->get('image.factory')->get($generated_uri);
$this->assertEqual($this->drupalGetHeader('Content-Type'), $image->getMimeType(), 'Expected Content-Type was reported.');
$this->assertEqual($this->drupalGetHeader('Content-Length'), $image->getFileSize(), 'Expected Content-Length was reported.');
if ($scheme == 'private') {
Dries Buytaert
committed
$this->assertEqual($this->drupalGetHeader('Expires'), 'Sun, 19 Nov 1978 05:00:00 GMT', 'Expires header was sent.');
Angie Byron
committed
$this->assertNotEqual(strpos($this->drupalGetHeader('Cache-Control'), 'no-cache'), FALSE, 'Cache-Control header contains \'no-cache\' to prevent caching.');
Dries Buytaert
committed
$this->assertEqual($this->drupalGetHeader('X-Image-Owned-By'), 'image_module_test', 'Expected custom header has been added.');
Angie Byron
committed
Alex Pott
committed
// Make sure that a second request to the already existing derivative
// works too.
Angie Byron
committed
$this->drupalGet($generate_url);
Dries Buytaert
committed
$this->assertResponse(200, 'Image was generated at the URL.');
Angie Byron
committed
Angie Byron
committed
// Make sure that access is denied for existing style files if we do not
// have access.
\Drupal::state()->delete('image.test_file_download');
Angie Byron
committed
$this->drupalGet($generate_url);
$this->assertResponse(403, 'Confirmed that access is denied for the private image style.');
Angie Byron
committed
// Repeat this with a different file that we do not have access to and
// make sure that access is denied.
$file_noaccess = array_shift($files);
$original_uri_noaccess = file_unmanaged_copy($file_noaccess->uri, $scheme . '://', FILE_EXISTS_RENAME);
Alex Pott
committed
$generated_uri_noaccess = $scheme . '://styles/' . $this->style->id() . '/' . $scheme . '/'. drupal_basename($original_uri_noaccess);
Dries Buytaert
committed
$this->assertFalse(file_exists($generated_uri_noaccess), 'Generated file does not exist.');
Alex Pott
committed
$generate_url_noaccess = $this->style->buildUrl($original_uri_noaccess);
Angie Byron
committed
$this->drupalGet($generate_url_noaccess);
Dries Buytaert
committed
$this->assertResponse(403, 'Confirmed that access is denied for the private image style.');
Angie Byron
committed
// Verify that images are not appended to the response. Currently this test only uses PNG images.
if (strpos($generate_url, '.png') === FALSE ) {
$this->fail('Confirming that private image styles are not appended require PNG file.');
}
else {
// Check for PNG-Signature (cf. http://www.libpng.org/pub/png/book/chapter08.html#png.ch08.div.2) in the
// response body.
$this->assertNoRaw( chr(137) . chr(80) . chr(78) . chr(71) . chr(13) . chr(10) . chr(26) . chr(10), 'No PNG signature found in the response body.');
}
elseif ($clean_url) {
Angie Byron
committed
// Add some extra chars to the token.
$this->drupalGet(str_replace(IMAGE_DERIVATIVE_TOKEN . '=', IMAGE_DERIVATIVE_TOKEN . '=Zo', $generate_url));
Jennifer Hodgdon
committed
$this->assertResponse(200, 'Existing image was accessible at the URL with an invalid token.');
Angie Byron
committed
}
Dries Buytaert
committed
// Allow insecure image derivatives to be created for the remainder of this
// test.
$this->config('image.settings')->set('allow_insecure_derivatives', TRUE)->save();
Dries Buytaert
committed
// Create another working copy of the file.
$files = $this->drupalGetTestFiles('image');
$file = array_shift($files);
$original_uri = file_unmanaged_copy($file->uri, $scheme . '://', FILE_EXISTS_RENAME);
// Let the image_module_test module know about this file, so it can claim
// ownership in hook_file_download().
\Drupal::state()->set('image.test_file_download', $original_uri);
Dries Buytaert
committed
// Suppress the security token in the URL, then get the URL of a file that
// has not been created and try to create it. Check that the security token
// is not present in the URL but that the image is still accessible.
$this->config('image.settings')->set('suppress_itok_output', TRUE)->save();
Alex Pott
committed
$generated_uri = $this->style->buildUri($original_uri);
Dries Buytaert
committed
$this->assertFalse(file_exists($generated_uri), 'Generated file does not exist.');
Alex Pott
committed
$generate_url = $this->style->buildUrl($original_uri, $clean_url);
Dries Buytaert
committed
$this->assertIdentical(strpos($generate_url, IMAGE_DERIVATIVE_TOKEN . '='), FALSE, 'The security token does not appear in the image style URL.');
$this->drupalGet($generate_url);
$this->assertResponse(200, 'Image was accessible at the URL with a missing token.');
Alex Pott
committed