function CsrfRequestHeaderAccessCheckTest::testChecksAttachedToRoutes

Same name and namespace in other branches
  1. 11.x core/tests/Drupal/KernelTests/Core/Access/CsrfRequestHeaderAccessCheckTest.php \Drupal\KernelTests\Core\Access\CsrfRequestHeaderAccessCheckTest::testChecksAttachedToRoutes()

Tests which routes the access check is attached to.

The check is registered against the '_csrf_request_header_token' requirement, so it is attached regardless of the methods a route allows. There is no need to filter out read-only routes when building the route collection, because CsrfRequestHeaderAccessCheck::access() allows read-only requests.

Attributes

#[TestWith([ 'csrf_test.protected', TRUE, ], 'write method')] #[TestWith([ 'csrf_test.protected_read_only', TRUE, ], 'read-only method')] #[TestWith([ 'csrf_test.route_with_csrf_token', FALSE, ], 'no requirement')]

Parameters

string $route_name: The name of the route to check.

bool $expected: Whether the access check is expected to be attached to the route.

File

core/tests/Drupal/KernelTests/Core/Access/CsrfRequestHeaderAccessCheckTest.php, line 41

Class

CsrfRequestHeaderAccessCheckTest
Tests that the CSRF request header access check is attached to routes.

Namespace

Drupal\KernelTests\Core\Access

Code

public function testChecksAttachedToRoutes(string $route_name, bool $expected) : void {
  $route = $this->container
    ->get('router.route_provider')
    ->getRouteByName($route_name);
  $access_checks = $route->getOption('_access_checks') ?? [];
  if ($expected) {
    $this->assertContains('access_check.header.csrf', $access_checks);
  }
  else {
    $this->assertNotContains('access_check.header.csrf', $access_checks);
  }
}

Buggy or inaccurate documentation? Please file an issue. Need support? Need help programming? Connect with the Drupal community.