SecureUnserializerTest.php 1.92 KB
Newer Older
Ketan's avatar
Ketan committed
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65
<?php
/**
 * Copyright © Magento, Inc. All rights reserved.
 * See COPYING.txt for license details.
 */
namespace Magento\Framework\Unserialize\Test\Unit;

/**
 * Tests \Magento\Framework\Unserialize\SecureUnserializer.
 */
class SecureUnserializerTest extends \PHPUnit_Framework_TestCase
{
    /**
     * @var \Magento\Framework\Unserialize\SecureUnserializer
     */
    protected $unserializer;

    /**
     * @inheritdoc
     */
    protected function setUp()
    {
        $this->unserializer = new \Magento\Framework\Unserialize\SecureUnserializer();
    }

    /**
     * @return void
     */
    public function testUnserializeArray()
    {
        $array = ['foo' => 'bar', 1, 4];
        $this->assertEquals($array, $this->unserializer->unserialize(serialize($array)));
    }

    /**
     * @param string $serialized The string containing serialized object
     * @return void
     *
     * @expectedException \InvalidArgumentException
     * @expectedExceptionMessage Data contains serialized object and cannot be unserialized
     * @dataProvider serializedObjectDataProvider
     */
    public function testUnserializeObject($serialized)
    {
        $this->assertFalse($this->unserializer->unserialize($serialized));
    }

    /**
     * @return array
     */
    public function serializedObjectDataProvider()
    {
        return [
            // Upper and lower case serialized object indicators, nested in array
            ['a:2:{i:0;s:3:"foo";i:1;O:6:"Object":1:{s:11:"Objectvar";i:123;}}'],
            ['a:2:{i:0;s:3:"foo";i:1;o:6:"Object":1:{s:11:"Objectvar";i:123;}}'],
            ['a:2:{i:0;s:3:"foo";i:1;c:6:"Object":1:{s:11:"Objectvar";i:123;}}'],
            ['a:2:{i:0;s:3:"foo";i:1;C:6:"Object":1:{s:11:"Objectvar";i:123;}}'],

            // Positive, negative signs on object length, non-nested
            ['o:+6:"Object":1:{s:11:"Objectvar";i:123;}'],
            ['o:-6:"Object":1:{s:11:"Objectvar";i:123;}'],
        ];
    }
}