 * @file
 * Contains \Drupal\file\Tests\FileFieldWidgetTest.
namespace Drupal\file\Tests;

use Drupal\comment\Entity\Comment;
use Drupal\comment\Tests\CommentTestTrait;
use Drupal\Component\Utility\Unicode;
use Drupal\field\Entity\FieldConfig;
use Drupal\field\Entity\FieldStorageConfig;
use Drupal\field_ui\Tests\FieldUiTestTrait;
use Drupal\user\RoleInterface;
use Drupal\file\Entity\File;

 * Tests the file field widget, single and multi-valued, with and without AJAX,
 * with public and private files.
 * @group file
class FileFieldWidgetTest extends FileFieldTestBase {
  use CommentTestTrait;
  use FieldUiTestTrait;

   * {@inheritdoc}
  protected function setUp() {

   * Modules to enable.
   * @var array
  public static $modules = array(

   * Tests upload and remove buttons for a single-valued File field.
  function testSingleValuedWidget() {
    $node_storage = $this->container
    $type_name = 'article';
    $field_name = strtolower($this
      ->createFileField($field_name, 'node', $type_name);
    $test_file = $this
    foreach (array(
    ) as $type) {

      // Create a new node with the uploaded file and ensure it got uploaded
      // successfully.
      // @todo This only tests a 'nojs' submission, because drupalPostAjaxForm()
      //   does not yet support file uploads.
      $nid = $this
        ->uploadNodeFile($test_file, $field_name, $type_name);
      $node = $node_storage
      $node_file = File::load($node->{$field_name}->target_id);
        ->assertFileExists($node_file, 'New file saved to disk on node creation.');

      // Ensure the file can be downloaded.
        ->assertResponse(200, 'Confirmed that the generated URL is correct by downloading the shipped file.');

      // Ensure the edit page has a remove button instead of an upload button.
        ->assertNoFieldByXPath('//input[@type="submit"]', t('Upload'), 'Node with file does not display the "Upload" button.');
        ->assertFieldByXpath('//input[@type="submit"]', t('Remove'), 'Node with file displays the "Remove" button.');

      // "Click" the remove button (emulating either a nojs or js submission).
      switch ($type) {
        case 'nojs':
            ->drupalPostForm(NULL, array(), t('Remove'));
        case 'js':
          $button = $this
            ->xpath('//input[@type="submit" and @value="' . t('Remove') . '"]');
            ->drupalPostAjaxForm(NULL, array(), array(
            (string) $button[0]['name'] => (string) $button[0]['value'],

      // Ensure the page now has an upload button instead of a remove button.
        ->assertNoFieldByXPath('//input[@type="submit"]', t('Remove'), 'After clicking the "Remove" button, it is no longer displayed.');
        ->assertFieldByXpath('//input[@type="submit"]', t('Upload'), 'After clicking the "Remove" button, the "Upload" button is displayed.');

      // Test label has correct 'for' attribute.
      $input = $this
        ->xpath('//input[@name="files[' . $field_name . '_0]"]');
      $label = $this
        ->xpath('//label[@for="' . (string) $input[0]['id'] . '"]');
        ->assertTrue(isset($label[0]), 'Label for upload found.');

      // Save the node and ensure it does not have the file.
        ->drupalPostForm(NULL, array(), t('Save and keep published'));
      $node = $node_storage
        ->assertTrue(empty($node->{$field_name}->target_id), 'File was successfully removed from the node.');

   * Tests upload and remove buttons for multiple multi-valued File fields.
  function testMultiValuedWidget() {
    $node_storage = $this->container
    $type_name = 'article';

    // Use explicit names instead of random names for those fields, because of a
    // bug in drupalPostForm() with multiple file uploads in one form, where the
    // order of uploads depends on the order in which the upload elements are
    // added to the $form (which, in the current implementation of
    // FileStorage::listAll(), comes down to the alphabetical order on field
    // names).
    $field_name = 'test_file_field_1';
    $field_name2 = 'test_file_field_2';
    $cardinality = 3;
      ->createFileField($field_name, 'node', $type_name, array(
      'cardinality' => $cardinality,
      ->createFileField($field_name2, 'node', $type_name, array(
      'cardinality' => $cardinality,
    $test_file = $this
    foreach (array(
    ) as $type) {

      // Visit the node creation form, and upload 3 files for each field. Since
      // the field has cardinality of 3, ensure the "Upload" button is displayed
      // until after the 3rd file, and after that, isn't displayed. Because
      // SimpleTest triggers the last button with a given name, so upload to the
      // second field first.
      // @todo This is only testing a non-Ajax upload, because drupalPostAjaxForm()
      //   does not yet emulate jQuery's file upload.
      foreach (array(
      ) as $each_field_name) {
        for ($delta = 0; $delta < 3; $delta++) {
          $edit = array(
            'files[' . $each_field_name . '_' . $delta . '][]' => drupal_realpath($test_file

          // If the Upload button doesn't exist, drupalPostForm() will automatically
          // fail with an assertion message.
            ->drupalPostForm(NULL, $edit, t('Upload'));
        ->assertNoFieldByXpath('//input[@type="submit"]', t('Upload'), 'After uploading 3 files for each field, the "Upload" button is no longer displayed.');
      $num_expected_remove_buttons = 6;
      foreach (array(
      ) as $current_field_name) {

        // How many uploaded files for the current field are remaining.
        $remaining = 3;

        // Test clicking each "Remove" button. For extra robustness, test them out
        // of sequential order. They are 0-indexed, and get renumbered after each
        // iteration, so array(1, 1, 0) means:
        // - First remove the 2nd file.
        // - Then remove what is then the 2nd file (was originally the 3rd file).
        // - Then remove the first file.
        foreach (array(
        ) as $delta) {

          // Ensure we have the expected number of Remove buttons, and that they
          // are numbered sequentially.
          $buttons = $this
            ->xpath('//input[@type="submit" and @value="Remove"]');
            ->assertTrue(is_array($buttons) && count($buttons) === $num_expected_remove_buttons, format_string('There are %n "Remove" buttons displayed (JSMode=%type).', array(
            '%n' => $num_expected_remove_buttons,
            '%type' => $type,
          foreach ($buttons as $i => $button) {
            $key = $i >= $remaining ? $i - $remaining : $i;
            $check_field_name = $field_name2;
            if ($current_field_name == $field_name && $i < $remaining) {
              $check_field_name = $field_name;
              ->assertIdentical((string) $button['name'], $check_field_name . '_' . $key . '_remove_button');

          // "Click" the remove button (emulating either a nojs or js submission).
          $button_name = $current_field_name . '_' . $delta . '_remove_button';
          switch ($type) {
            case 'nojs':

              // drupalPostForm() takes a $submit parameter that is the value of the
              // button whose click we want to emulate. Since we have multiple
              // buttons with the value "Remove", and want to control which one we
              // use, we change the value of the other ones to something else.
              // Since non-clicked buttons aren't included in the submitted POST
              // data, and since drupalPostForm() will result in $this being updated
              // with a newly rebuilt form, this doesn't cause problems.
              foreach ($buttons as $button) {
                if ($button['name'] != $button_name) {
                  $button['value'] = 'DUMMY';
                ->drupalPostForm(NULL, array(), t('Remove'));
            case 'js':

              // drupalPostAjaxForm() lets us target the button precisely, so we don't
              // require the workaround used above for nojs.
                ->drupalPostAjaxForm(NULL, array(), array(
                $button_name => t('Remove'),

          // Ensure an "Upload" button for the current field is displayed with the
          // correct name.
          $upload_button_name = $current_field_name . '_' . $remaining . '_upload_button';
          $buttons = $this
            ->xpath('//input[@type="submit" and @value="Upload" and @name=:name]', array(
            ':name' => $upload_button_name,
            ->assertTrue(is_array($buttons) && count($buttons) == 1, format_string('The upload button is displayed with the correct name (JSMode=%type).', array(
            '%type' => $type,

          // Ensure only at most one button per field is displayed.
          $buttons = $this
            ->xpath('//input[@type="submit" and @value="Upload"]');
          $expected = $current_field_name == $field_name ? 1 : 2;
            ->assertTrue(is_array($buttons) && count($buttons) == $expected, format_string('After removing a file, only one "Upload" button for each possible field is displayed (JSMode=%type).', array(
            '%type' => $type,

      // Ensure the page now has no Remove buttons.
        ->assertNoFieldByXPath('//input[@type="submit"]', t('Remove'), format_string('After removing all files, there is no "Remove" button displayed (JSMode=%type).', array(
        '%type' => $type,

      // Save the node and ensure it does not have any files.
        ->drupalPostForm(NULL, array(
        'title[0][value]' => $this
      ), t('Save and publish'));
      $matches = array();
      preg_match('/node\\/([0-9]+)/', $this
        ->getUrl(), $matches);
      $nid = $matches[1];
      $node = $node_storage
        ->assertTrue(empty($node->{$field_name}->target_id), 'Node was successfully saved without any files.');
    $upload_files = array(

    // Try to upload multiple files, but fewer than the maximum.
    $nid = $this
      ->uploadNodeFiles($upload_files, $field_name, $type_name);
    $node = $node_storage
      ->assertEqual(count($node->{$field_name}), count($upload_files), 'Node was successfully saved with mulitple files.');

    // Try to upload more files than allowed on revision.
      ->uploadNodeFiles($upload_files, $field_name, $nid, 1);
    $args = array(
      '%field' => $field_name,
      '@count' => $cardinality,
      ->assertRaw(t('%field: this field cannot hold more than @count values.', $args));
    $node = $node_storage
      ->assertEqual(count($node->{$field_name}), count($upload_files), 'More files than allowed could not be saved to node.');

    // Try to upload exactly the allowed number of files on revision.
      ->uploadNodeFile($test_file, $field_name, $nid, 1);
    $node = $node_storage
      ->assertEqual(count($node->{$field_name}), $cardinality, 'Node was successfully revised to maximum number of files.');

    // Try to upload exactly the allowed number of files, new node.
    $upload_files[] = $test_file;
    $nid = $this
      ->uploadNodeFiles($upload_files, $field_name, $type_name);
    $node = $node_storage
      ->assertEqual(count($node->{$field_name}), $cardinality, 'Node was successfully saved with maximum number of files.');

    // Try to upload more files than allowed, new node.
    $upload_files[] = $test_file;
      ->uploadNodeFiles($upload_files, $field_name, $type_name);
    $args = [
      '%field' => $field_name,
      '@max' => $cardinality,
      '@count' => count($upload_files),
      '%list' => $test_file
      ->assertRaw(t('Field %field can only hold @max values but there were @count uploaded. The following files have been omitted as a result: %list.', $args));

   * Tests a file field with a "Private files" upload destination setting.
  function testPrivateFileSetting() {
    $node_storage = $this->container

    // Grant the admin user required permissions.
    user_role_grant_permissions($this->adminUser->roles[0]->target_id, array(
      'administer node fields',
    $type_name = 'article';
    $field_name = strtolower($this
      ->createFileField($field_name, 'node', $type_name);
    $field = FieldConfig::loadByName('node', $type_name, $field_name);
    $field_id = $field
    $test_file = $this

    // Change the field setting to make its files private, and upload a file.
    $edit = array(
      'settings[uri_scheme]' => 'private',
      ->drupalPostForm("admin/structure/types/manage/{$type_name}/fields/{$field_id}/storage", $edit, t('Save field settings'));
    $nid = $this
      ->uploadNodeFile($test_file, $field_name, $type_name);
    $node = $node_storage
    $node_file = File::load($node->{$field_name}->target_id);
      ->assertFileExists($node_file, 'New file saved to disk on node creation.');

    // Ensure the private file is available to the user who uploaded it.
      ->assertResponse(200, 'Confirmed that the generated URL is correct by downloading the shipped file.');

    // Ensure we can't change 'uri_scheme' field settings while there are some
    // entities with uploaded files.
      ->assertFieldByXpath('//input[@id="edit-settings-uri-scheme-public" and @disabled="disabled"]', 'public', 'Upload destination setting disabled.');

    // Delete node and confirm that setting could be changed.
      ->assertFieldByXpath('//input[@id="edit-settings-uri-scheme-public" and not(@disabled)]', 'public', 'Upload destination setting enabled.');

   * Tests that download restrictions on private files work on comments.
  function testPrivateFileComment() {
    $user = $this
      'access comments',

    // Grant the admin user required comment permissions.
    $roles = $this->adminUser
    user_role_grant_permissions($roles[1], array(
      'administer comment fields',
      'administer comments',

    // Revoke access comments permission from anon user, grant post to
    // authenticated.
    user_role_revoke_permissions(RoleInterface::ANONYMOUS_ID, array(
      'access comments',
    user_role_grant_permissions(RoleInterface::AUTHENTICATED_ID, array(
      'post comments',
      'skip comment approval',

    // Create a new field.
      ->addDefaultCommentField('node', 'article');
    $name = strtolower($this
    $label = $this
    $storage_edit = array(
      'settings[uri_scheme]' => 'private',
      ->fieldUIAddNewField('admin/structure/comment/manage/comment', $name, $label, 'file', $storage_edit);

    // Manually clear cache on the tester side.

    // Create node.
    $edit = array(
      'title[0][value]' => $this
      ->drupalPostForm('node/add/article', $edit, t('Save and publish'));
    $node = $this

    // Add a comment with a file.
    $text_file = $this
    $edit = array(
      'files[field_' . $name . '_' . 0 . ']' => drupal_realpath($text_file
      'comment_body[0][value]' => $comment_body = $this
      ->drupalPostForm('node/' . $node
      ->id(), $edit, t('Save'));

    // Get the comment ID.
    preg_match('/comment-([0-9]+)/', $this
      ->getUrl(), $matches);
    $cid = $matches[1];

    // Log in as normal user.
    $comment = Comment::load($cid);
    $comment_file = $comment->{'field_' . $name}->entity;
      ->assertFileExists($comment_file, 'New file saved to disk on node creation.');

    // Test authenticated file download.
    $url = file_create_url($comment_file
      ->assertNotEqual($url, NULL, 'Confirmed that the URL is valid');
      ->assertResponse(200, 'Confirmed that the generated URL is correct by downloading the shipped file.');

    // Test anonymous file download.
      ->assertResponse(403, 'Confirmed that access is denied for the file without the needed permission.');

    // Unpublishes node.
      ->drupalPostForm('node/' . $node
      ->id() . '/edit', array(), t('Save and unpublish'));

    // Ensures normal user can no longer download the file.
      ->assertResponse(403, 'Confirmed that access is denied for the file without the needed permission.');

   * Tests validation with the Upload button.
  function testWidgetValidation() {
    $type_name = 'article';
    $field_name = strtolower($this
      ->createFileField($field_name, 'node', $type_name);
      ->updateFileField($field_name, $type_name, array(
      'file_extensions' => 'txt',
    foreach (array(
    ) as $type) {

      // Create node and prepare files for upload.
      $node = $this
        'type' => 'article',
      $nid = $node
      $test_file_text = $this
      $test_file_image = $this
      $name = 'files[' . $field_name . '_0]';

      // Upload file with incorrect extension, check for validation error.
      $edit[$name] = drupal_realpath($test_file_image
      switch ($type) {
        case 'nojs':
            ->drupalPostForm(NULL, $edit, t('Upload'));
        case 'js':
          $button = $this
            ->xpath('//input[@type="submit" and @value="' . t('Upload') . '"]');
            ->drupalPostAjaxForm(NULL, $edit, array(
            (string) $button[0]['name'] => (string) $button[0]['value'],
      $error_message = t('Only files with the following extensions are allowed: %files-allowed.', array(
        '%files-allowed' => 'txt',
        ->assertRaw($error_message, t('Validation error when file with wrong extension uploaded (JSMode=%type).', array(
        '%type' => $type,

      // Upload file with correct extension, check that error message is removed.
      $edit[$name] = drupal_realpath($test_file_text
      switch ($type) {
        case 'nojs':
            ->drupalPostForm(NULL, $edit, t('Upload'));
        case 'js':
          $button = $this
            ->xpath('//input[@type="submit" and @value="' . t('Upload') . '"]');
            ->drupalPostAjaxForm(NULL, $edit, array(
            (string) $button[0]['name'] => (string) $button[0]['value'],
        ->assertNoRaw($error_message, t('Validation error removed when file with correct extension uploaded (JSMode=%type).', array(
        '%type' => $type,

   * Tests file widget element.
  public function testWidgetElement() {
    $field_name = Unicode::strtolower($this
    $html_name = str_replace('_', '-', $field_name);
      ->createFileField($field_name, 'node', 'article', [
      'cardinality' => FieldStorageConfig::CARDINALITY_UNLIMITED,
    $file = $this
    $xpath = "//details[@data-drupal-selector='edit-{$html_name}']/div[@class='details-wrapper']/table";
    $elements = $this

    // If the field has no item, the table should not be visible.
      ->assertIdentical(count($elements), 0);

    // Upload a file.
    $edit['files[' . $field_name . '_0][]'] = $this->container
      ->drupalPostAjaxForm(NULL, $edit, "{$field_name}_0_upload_button");
    $elements = $this

    // If the field has at least a item, the table should be visible.
      ->assertIdentical(count($elements), 1);



