You are here

ParagraphsAccessTest.php in Paragraphs 8


View source

namespace Drupal\Tests\paragraphs\Functional\WidgetStable;

use Drupal\Core\Entity\Entity\EntityFormDisplay;
use Drupal\filter\Entity\FilterFormat;
use Drupal\image\Entity\ImageStyle;
use Drupal\language\Entity\ConfigurableLanguage;
use Drupal\Tests\field_ui\Traits\FieldUiTestTrait;
use Drupal\user\RoleInterface;
use Drupal\user\Entity\Role;

 * Tests the access check of paragraphs.
 * @group paragraphs
class ParagraphsAccessTest extends ParagraphsTestBase {
  use FieldUiTestTrait;

   * Modules to enable.
   * @var array
  public static $modules = array(

   * {@inheritdoc}
  protected function setUp() : void {
      'id' => 'de',
      'label' => '1German',
      'id' => 'fr',
      'label' => '2French',
      ->addParagraphedContentType('paragraphed_content_demo', 'field_paragraphs_demo');
      'administer site configuration',
      'administer content translation',
      'administer languages',
      ->addParagraphsField('nested_paragraph', 'field_paragraphs_demo', 'paragraph');
    static::fieldUIAddNewField('admin/structure/paragraphs_type/images', 'images_demo', 'Images', 'image', [
      'cardinality' => -1,
    ], [
      'settings[alt_field]' => FALSE,
    static::fieldUIAddNewField('admin/structure/paragraphs_type/text_image', 'image_demo', 'Images', 'image', [
      'cardinality' => -1,
    ], [
      'settings[alt_field]' => FALSE,
    static::fieldUIAddNewField('admin/structure/paragraphs_type/text_image', 'text_demo', 'Text', 'text_long', [], []);
    static::fieldUIAddExistingField('admin/structure/paragraphs_type/text', 'field_text_demo', 'Text', []);
    $edit = [
      'entity_types[node]' => TRUE,
      'entity_types[paragraph]' => TRUE,
      'settings[node][paragraphed_content_demo][translatable]' => TRUE,
      'settings[node][paragraphed_content_demo][fields][field_paragraphs_demo]' => FALSE,
      'settings[paragraph][images][translatable]' => TRUE,
      'settings[paragraph][text_image][translatable]' => TRUE,
      'settings[paragraph][text][translatable]' => TRUE,
      'settings[paragraph][nested_paragraph][translatable]' => TRUE,
      'settings[paragraph][nested_paragraph][fields][field_paragraphs_demo]' => FALSE,
      'settings[paragraph][nested_paragraph][settings][language][language_alterable]' => TRUE,
      'settings[paragraph][images][fields][field_images_demo]' => TRUE,
      'settings[paragraph][text_image][fields][field_image_demo]' => TRUE,
      'settings[paragraph][text_image][fields][field_text_demo]' => TRUE,
      'settings[node][paragraphed_content_demo][settings][language][language_alterable]' => TRUE,
      ->submitForm($edit, 'Save configuration');
    $view_display = \Drupal::service('entity_display.repository')
      ->getViewDisplay('paragraph', 'images');
      ->setComponent('field_images_demo', [
      'settings' => [
        'image_style' => 'medium',

   * Tests the Paragraph access and permissions.
  public function testParagraphAccessCheck() {
    $permissions = [
      'administer site configuration',
      'administer node display',
      'administer paragraph display',
      'create paragraphed_content_demo content',
      'edit any paragraphed_content_demo content',

    // Remove the "access content" for anonymous users. That results in
    // anonymous users not being able to "view" the host entity.

    /* @var Role $role */
    $role = \Drupal::entityTypeManager()
      ->revokePermission('access content');

    // Set field_images from demo to private file storage.
    $edit = array(
      'settings[uri_scheme]' => 'private',
      ->submitForm($edit, 'Save field settings');

    // Use the stable widget.
    $form_display = EntityFormDisplay::load('node.paragraphed_content_demo.default')
      ->setComponent('field_paragraphs_demo', [
      'type' => 'paragraphs',

    // Create a new demo node.

    // Add a new Paragraphs images item.
      ->submitForm([], 'Add images');
    $images = $this

    // Create a file, upload it.
    $file_system = \Drupal::service('file_system');
      ->copy($images[0]->uri, 'temporary://privateImage.jpg');
    $file_path = $this->container

    // Create a file, upload it.
      ->copy($images[1]->uri, 'temporary://privateImage2.jpg');
    $file_path_2 = $this->container
    $edit = array(
      'title[0][value]' => 'Security test node',
      'files[field_paragraphs_demo_0_subform_field_images_demo_0][]' => $file_path,
      ->submitForm($edit, 'Upload');
    $edit = array(
      'files[field_paragraphs_demo_0_subform_field_images_demo_1][]' => $file_path_2,
      ->submitForm($edit, 'Upload');
      ->submitForm([], 'Preview');
    $image_style = ImageStyle::load('medium');
    $img1_url = $image_style
      ->buildUrl('private://' . date('Y-m') . '/privateImage.jpg');
    $image_url = file_url_transform_relative($img1_url);
      ->clickLink('Back to content editing');
      ->submitForm([], 'Save');
    $node = $this
      ->drupalGetNodeByTitle('Security test node');
      ->drupalGet('node/' . $node

    // Check the text and image after publish.

    // Logout to become anonymous.

    // @todo Requesting the same $img_url again triggers a caching problem on
    // test bot, thus we request a different file here.
    $img_url = $image_style
      ->buildUrl('private://' . date('Y-m') . '/privateImage2.jpg');
    $image_url = file_url_transform_relative($img_url);

    // Check the text and image after publish. Anonymous should not see content.

    // Login as admin with no delete permissions.

    // Create a new demo node.
      ->submitForm([], 'Add text');
    $edit = [
      'title[0][value]' => 'delete_permissions',
      'field_paragraphs_demo[0][subform][field_text_demo][0][value]' => 'Test',
      ->submitForm($edit, 'Save');

    // Edit the node.

    // Check the remove button is present.

    // Delete the Paragraph and save.
      ->submitForm([], 'field_paragraphs_demo_0_remove');
      ->submitForm([], 'Save');
    $node = $this
      ->addressEquals('node/' . $node

    // Create an unpublished Paragraph and assert if it is displayed for the
    // user.
    $permissions = [
      'create paragraphed_content_demo content',
      'edit any paragraphed_content_demo content',
      'view unpublished paragraphs',
      'administer paragraph form display',
    $edit = [
      'fields[status][region]' => 'content',
      'fields[status][type]' => 'boolean_checkbox',
      ->submitForm($edit, 'Save');
      ->submitForm([], 'Add text');
    $edit = [
      'title[0][value]' => 'unpublished_permissions',
      'field_paragraphs_demo[0][subform][field_text_demo][0][value]' => 'recognizable_test',
      'field_paragraphs_demo[0][subform][status][value]' => FALSE,
      ->submitForm($edit, 'Save');
    $node = $this

    // Login as an user without the view unpublished Paragraph permission.
    $user = $this
      'administer nodes',
      'edit any paragraphed_content_demo content',

    // Assert that the Paragraph is not displayed.
      ->drupalGet('node/' . $node

    // Grant to the user the view unpublished Paragraph permission.
      ->grantPermissions(Role::load(Role::AUTHENTICATED_ID), [
      'view unpublished paragraphs',

    // Assert that the Paragraph is displayed.
      ->drupalGet('node/' . $node

    // Grant to the user the administer Paragraphs settings permission.
      ->grantPermissions(Role::load(Role::AUTHENTICATED_ID), [
      'administer paragraphs settings',

    // Disable the show unpublished Paragraphs setting.
      'show_unpublished' => FALSE,
    ], 'Save configuration');

    // Assert that the Paragraph is not displayed even if the user has the
    // permission to do so.
      ->drupalGet('node/' . $node

    // Enable the show unpublished Paragraphs setting.
      'show_unpublished' => TRUE,
    ], 'Save configuration');

    // Assert that the Paragraph is displayed when the user has the permission
    // to do so.
      ->drupalGet('node/' . $node

   * Tests the Paragraph validation with filter access.
  public function testParagraphsTextFormatValidation() {
    $filtered_html_format = FilterFormat::create([
      'format' => 'filtered_html',
      'name' => 'Filtered HTML',
    $permissions = [
      'create paragraphed_content_demo content',
      'edit any paragraphed_content_demo content',

    // Create a node with a Text Paragraph using the filtered html format.
      ->submitForm([], 'Add text');
    $edit = [
      'title[0][value]' => 'access_validation_test',
      'field_paragraphs_demo[0][subform][field_text_demo][0][value]' => 'Test',
      ->submitForm($edit, 'Save');
      ->pageTextContains('paragraphed_content_demo access_validation_test has been created.');

    // Login as an user without the Text Format permission.
    $user = $this
      'administer nodes',
      'edit any paragraphed_content_demo content',
    $node = $this
      ->drupalGet('node/' . $node
      ->id() . '/edit');
      ->submitForm([], 'Save');
      ->pageTextContains('paragraphed_content_demo access_validation_test has been updated.');
      ->drupalGet('node/' . $node
      ->id() . '/edit');
      ->submitForm([], 'field_paragraphs_demo_0_collapse');
      ->submitForm([], 'Save');
      ->pageTextContains('paragraphed_content_demo access_validation_test has been updated.');
      ->pageTextNotContains('The value you selected is not a valid choice.');



Namesort descending Description
ParagraphsAccessTest Tests the access check of paragraphs.