mattermost-mobile/app/queries/servers/system.test.ts
Elias Nahum 44eb76bed7
feat(iOS): Add Microsoft Intune MAM integration with multi-server support (#9312)
* refactor: implement custom ExpoImage wrapper for cache control

Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app

* refactor(ios): convert Gekidou to CocoaPods

Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0

* npm audit

* update fastlane

* feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection

Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository

* fix tests by mocking @mattermost/intune

* feat: implement Intune MAM integration with comprehensive security enforcement

Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls

* fix alerts when no server database is present

* Unify cache strategy

* fix emit config changed after it was stored in the db

* Handle Mid-Session Enrollment Detection

* fix ADALLogOverrideDisabled missing in Fastfile

* fix flow for initial enrollment

* fix and add unit tests

* enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release

* Update intune submodule with addressed feedback

* fix validate-intune-clean workflow

* feat(intune): add comprehensive error handling and SAML+Entra support

Add production-ready error handling for native Entra authentication with
user-friendly i18n messages, comprehensive test coverage, and support for
Entra login when server requires SAML.

* update i18n

* update intune submodule

* update build-pr token

* fix race condition between server auth and intune enrollment

* fix CI workflow to build with intune

* use deploy key for intune submodule

* set the config directly in the submodule .git

* debug injection

* try setting GIT_SSH_COMMAND

* remove action debug

* fix server url input

* match pod cache with intune hash

* Fastfile and envs

* have workflows check for intune/.git

* have ci cache intune frameworks as well

* update Fastlane to set no-cache to artifacts uploaded

* fix s3 upload

* fix pblist template

* Attempt to remove the cache control for PR uploads to s3

* use hash from commit for S3 path

* Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain

* Fix surface errors from intune login

* fix postinstall scripts

* use cacheKey for draft md images

* remove unnecessary double await during test

* Have isMinimumLicenseTier accept valid license sku tier as target

* Add missing Auth error messages

* remove the last period for intune errors in i18n

* do not call unenroll with wipe on manual logout

* Fix tests and Intune error messages

* do not filter any SSO type regardless of which is used for Intune

* fix 412 to not retry

* fix tests, app logs sharing and share_extension avatar cache

* apply setScreenCapturePolicy on license change

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* re-apply screen capture on enrollment

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* use userData from intunr login and prevent getMe

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>

* Check for Biometrics and Jailbreak as we used to

---------

Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
2025-12-10 13:07:28 +02:00

197 lines
7.2 KiB
TypeScript

// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
import {Platform} from 'react-native';
import {License} from '@constants';
import {SYSTEM_IDENTIFIERS} from '@constants/database';
import DatabaseManager from '@database/manager';
import {observeIsMinimumLicenseTier, observeReportAProblemMetadata} from './system';
import type ServerDataOperator from '@database/operator/server_data_operator';
import type {Database} from '@nozbe/watermelondb';
jest.mock('expo-application', () => {
return {
nativeApplicationVersion: '1.2.3',
nativeBuildVersion: '456',
};
});
describe('observeReportAProblemMetadata', () => {
const serverUrl = 'baseHandler.test.com';
let database: Database;
let operator: ServerDataOperator;
let originalPlatform: typeof Platform.OS;
beforeEach(async () => {
await DatabaseManager.init([serverUrl]);
const serverDatabaseAndOperator = DatabaseManager.getServerDatabaseAndOperator(serverUrl);
database = serverDatabaseAndOperator.database;
operator = serverDatabaseAndOperator.operator;
originalPlatform = Platform.OS;
// @ts-expect-error Platform.OS is mocked
Platform.OS = 'somePlatform';
});
afterEach(async () => {
await DatabaseManager.destroyServerDatabase(serverUrl);
Platform.OS = originalPlatform;
});
it('should return correct metadata', (done) => {
operator.handleConfigs({
configs: [
{id: 'Version', value: '7.8.0'},
{id: 'BuildNumber', value: '123'},
],
prepareRecordsOnly: false,
configsToDelete: [],
}).then(() => {
operator.handleSystem({
systems: [
{id: SYSTEM_IDENTIFIERS.LICENSE, value: {IsLicensed: 'true', Compliance: 'true'}},
{id: SYSTEM_IDENTIFIERS.CURRENT_USER_ID, value: 'user1'},
{id: SYSTEM_IDENTIFIERS.CURRENT_TEAM_ID, value: 'team1'},
],
prepareRecordsOnly: false,
}).then(() => {
observeReportAProblemMetadata(database).subscribe((data) => {
expect(data).toEqual({
currentUserId: 'user1',
currentTeamId: 'team1',
serverVersion: '7.8.0 (Build 123)',
appVersion: '1.2.3 (Build 456)',
appPlatform: 'somePlatform',
});
done();
});
});
});
});
it('should handle empty or undefined values', (done) => {
observeReportAProblemMetadata(database).subscribe((data) => {
expect(data).toEqual({
currentUserId: '',
currentTeamId: '',
serverVersion: 'Unknown (Build Unknown)',
appVersion: '1.2.3 (Build 456)',
appPlatform: 'somePlatform',
});
done();
});
});
});
describe('observeIsMinimumLicenseTier', () => {
const serverUrl = 'baseHandler.test.com';
let database: Database;
let operator: ServerDataOperator;
beforeEach(async () => {
await DatabaseManager.init([serverUrl]);
const serverDatabaseAndOperator = DatabaseManager.getServerDatabaseAndOperator(serverUrl);
database = serverDatabaseAndOperator.database;
operator = serverDatabaseAndOperator.operator;
});
afterEach(async () => {
await DatabaseManager.destroyServerDatabase(serverUrl);
});
it('should return false if no license is present', (done) => {
operator.handleConfigs({configs: [
{id: 'BuildEnterpriseReady', value: 'true'},
],
prepareRecordsOnly: false,
configsToDelete: []}).then(() => {
observeIsMinimumLicenseTier(database, License.SKU_SHORT_NAME.Professional).subscribe((isMinimumTier) => {
expect(isMinimumTier).toBe(false);
done();
});
});
});
it('should return false if license tier is below the required tier', (done) => {
operator.handleConfigs({configs: [
{id: 'BuildEnterpriseReady', value: 'true'},
],
prepareRecordsOnly: false,
configsToDelete: []}).then(() => {
operator.handleSystem({
systems: [
{id: SYSTEM_IDENTIFIERS.LICENSE, value: {IsLicensed: 'true', SkuShortName: License.SKU_SHORT_NAME.Starter}},
],
prepareRecordsOnly: false,
}).then(() => {
observeIsMinimumLicenseTier(database, License.SKU_SHORT_NAME.Professional).subscribe((isMinimumTier) => {
expect(isMinimumTier).toBe(false);
done();
});
});
});
});
it('should return true if license tier matches the required tier', (done) => {
operator.handleConfigs({configs: [
{id: 'BuildEnterpriseReady', value: 'true'},
],
prepareRecordsOnly: false,
configsToDelete: []}).then(() => {
operator.handleSystem({
systems: [
{id: SYSTEM_IDENTIFIERS.LICENSE, value: {IsLicensed: 'true', SkuShortName: License.SKU_SHORT_NAME.Professional}},
],
prepareRecordsOnly: false,
}).then(() => {
observeIsMinimumLicenseTier(database, License.SKU_SHORT_NAME.Professional).subscribe((isMinimumTier) => {
expect(isMinimumTier).toBe(true);
done();
});
});
});
});
it('should return true if license tier is above the required tier', (done) => {
operator.handleConfigs({configs: [
{id: 'BuildEnterpriseReady', value: 'true'},
],
prepareRecordsOnly: false,
configsToDelete: []}).then(() => {
operator.handleSystem({
systems: [
{id: SYSTEM_IDENTIFIERS.LICENSE, value: {IsLicensed: 'true', SkuShortName: License.SKU_SHORT_NAME.Enterprise}},
],
prepareRecordsOnly: false,
}).then(() => {
observeIsMinimumLicenseTier(database, License.SKU_SHORT_NAME.Professional).subscribe((isMinimumTier) => {
expect(isMinimumTier).toBe(true);
done();
});
});
});
});
it('should return false if BuildEnterpriseReady is false', (done) => {
operator.handleConfigs({
configs: [
{id: 'BuildEnterpriseReady', value: 'false'},
],
prepareRecordsOnly: false,
configsToDelete: [],
}).then(() => {
operator.handleSystem({
systems: [
{id: SYSTEM_IDENTIFIERS.LICENSE, value: {IsLicensed: 'true', SkuShortName: 'professional'}},
],
prepareRecordsOnly: false,
}).then(() => {
observeIsMinimumLicenseTier(database, 'professional').subscribe((isMinimumTier) => {
expect(isMinimumTier).toBe(false);
done();
});
});
});
});
});