3 namespace Drupal\Tests\filter\Functional;
5 use Drupal\Component\Utility\Html;
6 use Drupal\Component\Utility\Unicode;
7 use Drupal\filter\Entity\FilterFormat;
8 use Drupal\node\Entity\Node;
9 use Drupal\node\Entity\NodeType;
10 use Drupal\Tests\BrowserTestBase;
11 use Drupal\user\RoleInterface;
14 * Thoroughly test the administrative interface of the filter module.
18 class FilterAdminTest extends BrowserTestBase {
23 public static $modules = ['block', 'filter', 'node', 'filter_test_plugin', 'dblog'];
26 * An user with administration permissions.
28 * @var \Drupal\user\UserInterface
33 * An user with permissions to create pages.
35 * @var \Drupal\user\UserInterface
42 protected function setUp() {
45 $this->drupalCreateContentType(['type' => 'page', 'name' => 'Basic page']);
47 // Set up the filter formats used by this test.
48 $basic_html_format = FilterFormat::create([
49 'format' => 'basic_html',
50 'name' => 'Basic HTML',
55 'allowed_html' => '<p> <br> <strong> <a> <em>',
60 $basic_html_format->save();
61 $restricted_html_format = FilterFormat::create([
62 'format' => 'restricted_html',
63 'name' => 'Restricted HTML',
69 'allowed_html' => '<p> <br> <strong> <a> <em> <h4>',
80 'filter_htmlcorrector' => [
86 $restricted_html_format->save();
87 $full_html_format = FilterFormat::create([
88 'format' => 'full_html',
89 'name' => 'Full HTML',
93 $full_html_format->save();
95 $this->adminUser = $this->drupalCreateUser([
97 $basic_html_format->getPermissionName(),
98 $restricted_html_format->getPermissionName(),
99 $full_html_format->getPermissionName(),
100 'access site reports',
103 $this->webUser = $this->drupalCreateUser(['create page content', 'edit own page content']);
104 user_role_grant_permissions('authenticated', [$basic_html_format->getPermissionName()]);
105 user_role_grant_permissions('anonymous', [$restricted_html_format->getPermissionName()]);
106 $this->drupalLogin($this->adminUser);
107 $this->drupalPlaceBlock('local_actions_block');
111 * Tests the format administration functionality.
113 public function testFormatAdmin() {
115 $this->drupalGet('admin/config/content/formats');
116 $this->clickLink('Add text format');
117 $format_id = Unicode::strtolower($this->randomMachineName());
118 $name = $this->randomMachineName();
120 'format' => $format_id,
123 $this->drupalPostForm(NULL, $edit, t('Save configuration'));
125 // Verify default weight of the text format.
126 $this->drupalGet('admin/config/content/formats');
127 $this->assertFieldByName("formats[$format_id][weight]", 0, 'Text format weight was saved.');
129 // Change the weight of the text format.
131 "formats[$format_id][weight]" => 5,
133 $this->drupalPostForm('admin/config/content/formats', $edit, t('Save'));
134 $this->assertFieldByName("formats[$format_id][weight]", 5, 'Text format weight was saved.');
137 $this->drupalGet('admin/config/content/formats');
138 // Cannot use the assertNoLinkByHref method as it does partial url matching
139 // and 'admin/config/content/formats/manage/' . $format_id . '/disable'
141 // @todo: See https://www.drupal.org/node/2031223 for the above.
142 $edit_link = $this->xpath('//a[@href=:href]', [
143 ':href' => \Drupal::url('entity.filter_format.edit_form', ['filter_format' => $format_id])
145 $this->assertNotEmpty($edit_link, format_string('Link href %href found.',
146 ['%href' => 'admin/config/content/formats/manage/' . $format_id]
148 $this->drupalGet('admin/config/content/formats/manage/' . $format_id);
149 $this->drupalPostForm(NULL, [], t('Save configuration'));
151 // Verify that the custom weight of the text format has been retained.
152 $this->drupalGet('admin/config/content/formats');
153 $this->assertFieldByName("formats[$format_id][weight]", 5, 'Text format weight was retained.');
155 // Disable text format.
156 $this->assertLinkByHref('admin/config/content/formats/manage/' . $format_id . '/disable');
157 $this->drupalGet('admin/config/content/formats/manage/' . $format_id . '/disable');
158 $this->drupalPostForm(NULL, [], t('Disable'));
160 // Verify that disabled text format no longer exists.
161 $this->drupalGet('admin/config/content/formats/manage/' . $format_id);
162 $this->assertResponse(404, 'Disabled text format no longer exists.');
164 // Attempt to create a format of the same machine name as the disabled
165 // format but with a different human readable name.
167 'format' => $format_id,
168 'name' => 'New format',
170 $this->drupalPostForm('admin/config/content/formats/add', $edit, t('Save configuration'));
171 $this->assertText('The machine-readable name is already in use. It must be unique.');
173 // Attempt to create a format of the same human readable name as the
174 // disabled format but with a different machine name.
176 'format' => 'new_format',
179 $this->drupalPostForm('admin/config/content/formats/add', $edit, t('Save configuration'));
180 $this->assertRaw(t('Text format names must be unique. A format named %name already exists.', [
186 * Tests filter administration functionality.
188 public function testFilterAdmin() {
189 $first_filter = 'filter_autop';
190 $second_filter = 'filter_url';
192 $basic = 'basic_html';
193 $restricted = 'restricted_html';
195 $plain = 'plain_text';
197 // Check that the fallback format exists and cannot be disabled.
198 $this->assertTrue($plain == filter_fallback_format(), 'The fallback format is set to plain text.');
199 $this->drupalGet('admin/config/content/formats');
200 $this->assertNoRaw('admin/config/content/formats/manage/' . $plain . '/disable', 'Disable link for the fallback format not found.');
201 $this->drupalGet('admin/config/content/formats/manage/' . $plain . '/disable');
202 $this->assertResponse(403, 'The fallback format cannot be disabled.');
204 // Verify access permissions to Full HTML format.
205 $full_format = FilterFormat::load($full);
206 $this->assertTrue($full_format->access('use', $this->adminUser), 'Admin user may use Full HTML.');
207 $this->assertFalse($full_format->access('use', $this->webUser), 'Web user may not use Full HTML.');
209 // Add an additional tag and extra spaces and returns.
211 $edit['filters[filter_html][settings][allowed_html]'] = "<a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>\r\n<quote>";
212 $this->drupalPostForm('admin/config/content/formats/manage/' . $restricted, $edit, t('Save configuration'));
213 $this->assertUrl('admin/config/content/formats');
214 $this->drupalGet('admin/config/content/formats/manage/' . $restricted);
215 $this->assertFieldByName('filters[filter_html][settings][allowed_html]', "<a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <quote>", 'Allowed HTML tag added.');
217 $elements = $this->xpath('//select[@name=:first]/following::select[@name=:second]', [
218 ':first' => 'filters[' . $first_filter . '][weight]',
219 ':second' => 'filters[' . $second_filter . '][weight]',
221 $this->assertNotEmpty($elements, 'Order confirmed in admin interface.');
225 $edit['filters[' . $second_filter . '][weight]'] = 1;
226 $edit['filters[' . $first_filter . '][weight]'] = 2;
227 $this->drupalPostForm(NULL, $edit, t('Save configuration'));
228 $this->assertUrl('admin/config/content/formats');
229 $this->drupalGet('admin/config/content/formats/manage/' . $restricted);
230 $this->assertFieldByName('filters[' . $second_filter . '][weight]', 1, 'Order saved successfully.');
231 $this->assertFieldByName('filters[' . $first_filter . '][weight]', 2, 'Order saved successfully.');
233 $elements = $this->xpath('//select[@name=:first]/following::select[@name=:second]', [
234 ':first' => 'filters[' . $second_filter . '][weight]',
235 ':second' => 'filters[' . $first_filter . '][weight]',
237 $this->assertNotEmpty($elements, 'Reorder confirmed in admin interface.');
239 $filter_format = FilterFormat::load($restricted);
240 foreach ($filter_format->filters() as $filter_name => $filter) {
241 if ($filter_name == $second_filter || $filter_name == $first_filter) {
242 $filters[] = $filter_name;
245 // Ensure that the second filter is now before the first filter.
246 $this->assertEqual($filter_format->filters($second_filter)->weight + 1, $filter_format->filters($first_filter)->weight, 'Order confirmed in configuration.');
250 $edit['format'] = Unicode::strtolower($this->randomMachineName());
251 $edit['name'] = $this->randomMachineName();
252 $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'] = 1;
253 $edit['filters[' . $second_filter . '][status]'] = TRUE;
254 $edit['filters[' . $first_filter . '][status]'] = TRUE;
255 $this->drupalPostForm('admin/config/content/formats/add', $edit, t('Save configuration'));
256 $this->assertUrl('admin/config/content/formats');
257 $this->assertRaw(t('Added text format %format.', ['%format' => $edit['name']]), 'New filter created.');
259 filter_formats_reset();
260 $format = FilterFormat::load($edit['format']);
261 $this->assertNotNull($format, 'Format found in database.');
262 $this->drupalGet('admin/config/content/formats/manage/' . $format->id());
263 $this->assertSession()->checkboxChecked('roles[' . RoleInterface::AUTHENTICATED_ID . ']');
264 $this->assertSession()->checkboxChecked('filters[' . $second_filter . '][status]');
265 $this->assertSession()->checkboxChecked('filters[' . $first_filter . '][status]');
267 // Disable new filter.
268 $this->drupalPostForm('admin/config/content/formats/manage/' . $format->id() . '/disable', [], t('Disable'));
269 $this->assertUrl('admin/config/content/formats');
270 $this->assertRaw(t('Disabled text format %format.', ['%format' => $edit['name']]), 'Format successfully disabled.');
272 // Allow authenticated users on full HTML.
273 $format = FilterFormat::load($full);
275 $edit['roles[' . RoleInterface::ANONYMOUS_ID . ']'] = 0;
276 $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'] = 1;
277 $this->drupalPostForm('admin/config/content/formats/manage/' . $full, $edit, t('Save configuration'));
278 $this->assertUrl('admin/config/content/formats');
279 $this->assertRaw(t('The text format %format has been updated.', ['%format' => $format->label()]), 'Full HTML format successfully updated.');
282 $this->drupalLogin($this->webUser);
284 $this->drupalGet('node/add/page');
285 $this->assertRaw('<option value="' . $full . '">Full HTML</option>', 'Full HTML filter accessible.');
287 // Use basic HTML and see if it removes tags that are not allowed.
288 $body = '<em>' . $this->randomMachineName() . '</em>';
289 $extra_text = 'text';
290 $text = $body . '<random>' . $extra_text . '</random>';
293 $edit['title[0][value]'] = $this->randomMachineName();
294 $edit['body[0][value]'] = $text;
295 $edit['body[0][format]'] = $basic;
296 $this->drupalPostForm('node/add/page', $edit, t('Save'));
297 $this->assertText(t('Basic page @title has been created.', ['@title' => $edit['title[0][value]']]), 'Filtered node created.');
299 // Verify that the creation message contains a link to a node.
300 $view_link = $this->xpath('//div[contains(@class, "messages")]//a[contains(@href, :href)]', [':href' => 'node/']);
301 $this->assertNotEmpty($view_link, 'The message area contains a link to a node');
303 $node = $this->drupalGetNodeByTitle($edit['title[0][value]']);
304 $this->assertTrue($node, 'Node found in database.');
306 $this->drupalGet('node/' . $node->id());
307 $this->assertRaw($body . $extra_text, 'Filter removed invalid tag.');
309 // Use plain text and see if it escapes all tags, whether allowed or not.
310 // In order to test plain text, we have to enable the hidden variable for
311 // "show_fallback_format", which displays plain text in the format list.
312 $this->config('filter.settings')
313 ->set('always_show_fallback_choice', TRUE)
316 $edit['body[0][format]'] = $plain;
317 $this->drupalPostForm('node/' . $node->id() . '/edit', $edit, t('Save'));
318 $this->drupalGet('node/' . $node->id());
319 $this->assertEscaped($text, 'The "Plain text" text format escapes all HTML tags.');
320 $this->config('filter.settings')
321 ->set('always_show_fallback_choice', FALSE)
325 $this->drupalLogin($this->adminUser);
330 $edit['filters[filter_html][settings][allowed_html]'] = '<a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>';
331 $this->drupalPostForm('admin/config/content/formats/manage/' . $basic, $edit, t('Save configuration'));
332 $this->assertUrl('admin/config/content/formats');
333 $this->drupalGet('admin/config/content/formats/manage/' . $basic);
334 $this->assertFieldByName('filters[filter_html][settings][allowed_html]', $edit['filters[filter_html][settings][allowed_html]'], 'Changes reverted.');
338 $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'] = FALSE;
339 $this->drupalPostForm('admin/config/content/formats/manage/' . $full, $edit, t('Save configuration'));
340 $this->assertUrl('admin/config/content/formats');
341 $this->assertRaw(t('The text format %format has been updated.', ['%format' => $format->label()]), 'Full HTML format successfully reverted.');
342 $this->drupalGet('admin/config/content/formats/manage/' . $full);
343 $this->assertFieldByName('roles[' . RoleInterface::AUTHENTICATED_ID . ']', $edit['roles[' . RoleInterface::AUTHENTICATED_ID . ']'], 'Changes reverted.');
347 $edit['filters[' . $second_filter . '][weight]'] = 2;
348 $edit['filters[' . $first_filter . '][weight]'] = 1;
349 $this->drupalPostForm('admin/config/content/formats/manage/' . $basic, $edit, t('Save configuration'));
350 $this->assertUrl('admin/config/content/formats');
351 $this->drupalGet('admin/config/content/formats/manage/' . $basic);
352 $this->assertFieldByName('filters[' . $second_filter . '][weight]', $edit['filters[' . $second_filter . '][weight]'], 'Changes reverted.');
353 $this->assertFieldByName('filters[' . $first_filter . '][weight]', $edit['filters[' . $first_filter . '][weight]'], 'Changes reverted.');
357 * Tests the URL filter settings form is properly validated.
359 public function testUrlFilterAdmin() {
360 // The form does not save with an invalid filter URL length.
362 'filters[filter_url][settings][filter_url_length]' => $this->randomMachineName(4),
364 $this->drupalPostForm('admin/config/content/formats/manage/basic_html', $edit, t('Save configuration'));
365 $this->assertNoRaw(t('The text format %format has been updated.', ['%format' => 'Basic HTML']));
369 * Tests whether filter tips page is not HTML escaped.
371 public function testFilterTipHtmlEscape() {
372 $this->drupalLogin($this->adminUser);
375 $site_name_with_markup = 'Filter test <script>alert(\'here\');</script> site name';
376 $this->config('system.site')->set('name', $site_name_with_markup)->save();
378 // It is not possible to test the whole filter tip page.
379 // Therefore we test only some parts.
380 $link = '<a href="' . $base_url . '">' . Html::escape($site_name_with_markup) . '</a>';
381 $ampersand = '&';
382 $link_as_code = '<code>' . Html::escape($link) . '</code>';
383 $ampersand_as_code = '<code>' . Html::escape($ampersand) . '</code>';
385 $this->drupalGet('filter/tips');
387 $this->assertRaw('<td class="type">' . $link_as_code . '</td>');
388 $this->assertRaw('<td class="get">' . $link . '</td>');
389 $this->assertRaw('<td class="type">' . $ampersand_as_code . '</td>');
390 $this->assertRaw('<td class="get">' . $ampersand . '</td>');
394 * Tests whether a field using a disabled format is rendered.
396 public function testDisabledFormat() {
397 // Create a node type and add a standard body field.
398 $node_type = NodeType::create(['type' => Unicode::strtolower($this->randomMachineName())]);
400 node_add_body_field($node_type, $this->randomString());
402 // Create a text format with a filter that returns a static string.
403 $format = FilterFormat::create([
404 'name' => $this->randomString(),
405 'format' => $format_id = Unicode::strtolower($this->randomMachineName()),
407 $format->setFilterConfig('filter_static_text', ['status' => TRUE]);
410 // Create a new node of the new node type.
411 $node = Node::create([
412 'type' => $node_type->id(),
413 'title' => $this->randomString(),
415 $body_value = $this->randomString();
416 $node->body->value = $body_value;
417 $node->body->format = $format_id;
420 // The format is used and we should see the static text instead of the body
422 $this->drupalGet($node->urlInfo());
423 $this->assertText('filtered text');
425 // Disable the format.
426 $format->disable()->save();
428 $this->drupalGet($node->urlInfo());
430 // The format is not used anymore.
431 $this->assertNoText('filtered text');
432 // The text is not displayed unfiltered or escaped.
433 $this->assertNoRaw($body_value);
434 $this->assertNoEscaped($body_value);
436 // Visit the dblog report page.
437 $this->drupalLogin($this->adminUser);
438 $this->drupalGet('admin/reports/dblog');
439 // The correct message has been logged.
440 $this->assertRaw(sprintf('Disabled text format: %s.', $format_id));
442 // Programmatically change the text format to something random so we trigger
443 // the missing text format message.
444 $format_id = $this->randomMachineName();
445 $node->body->format = $format_id;
447 $this->drupalGet($node->urlInfo());
448 // The text is not displayed unfiltered or escaped.
449 $this->assertNoRaw($body_value);
450 $this->assertNoEscaped($body_value);
452 // Visit the dblog report page.
453 $this->drupalGet('admin/reports/dblog');
454 // The missing text format message has been logged.
455 $this->assertRaw(sprintf('Missing text format: %s.', $format_id));