diff --git a/admin/tool/behat/tests/behat/edit_permissions.feature b/admin/tool/behat/tests/behat/edit_permissions.feature index a4cfc450fbb..99ec96e532c 100644 --- a/admin/tool/behat/tests/behat/edit_permissions.feature +++ b/admin/tool/behat/tests/behat/edit_permissions.feature @@ -21,12 +21,15 @@ Feature: Edit capabilities Scenario: Default system capabilities modification Given I log in as "admin" - And I set the following system permissions of "Teacher" role: + And I navigate to "Users > Permissions > Define roles" in site administration + And I click on "Edit Teacher role" "link" + And I fill the capabilities form with the following permissions: | capability | permission | | block/mnet_hosts:myaddinstance | Allow | | moodle/site:messageanyuser | Inherit | | moodle/grade:managesharedforms | Prevent | | moodle/course:request | Prohibit | + And I press "Save changes" When I follow "Edit Teacher role" Then "block/mnet_hosts:myaddinstance" capability has "Allow" permission And "moodle/site:messageanyuser" capability has "Not set" permission diff --git a/admin/tool/lp/tests/behat/plan_workflow.feature b/admin/tool/lp/tests/behat/plan_workflow.feature index 1923882699c..e4a5406b72a 100644 --- a/admin/tool/lp/tests/behat/plan_workflow.feature +++ b/admin/tool/lp/tests/behat/plan_workflow.feature @@ -15,6 +15,17 @@ Feature: Manage plan workflow | usermanageowndraftplan | User manage own draft plan role | user | | usermanageownplan | User manage own plan role | user | | manageplan | Manager all plans role | manager | + And the following "role capabilities" exist: + | role | moodle/competency:planmanageowndraft | moodle/competency:planmanageown | + | usermanageowndraftplan | allow | | + | usermanageownplan | allow | allow | + | manageplan | allow | allow | + And the following "role capability" exists: + | role | manageplan | + | moodle/competency:planmanage | allow | + | moodle/competency:planview | allow | + | moodle/competency:planreview | allow | + | moodle/competency:planrequestreview | allow | And the following "role assigns" exist: | user | role | contextlevel | reference | | user1 | usermanageowndraftplan | System | | @@ -37,23 +48,9 @@ Feature: Manage plan workflow | Test-Plan1 | Test-Comp2 | | Test-Plan2 | Test-Comp1 | | Test-Plan2 | Test-Comp2 | - And I log in as "admin" - And I set the following system permissions of "User manage own draft plan role" role: - | capability | permission | - | moodle/competency:planmanageowndraft | Allow | - And I set the following system permissions of "User manage own plan role" role: - | capability | permission | - | moodle/competency:planmanageowndraft | Allow | - | moodle/competency:planmanageown | Allow | - And I set the following system permissions of "Manager all plans role" role: - | capability | permission | - | moodle/competency:planmanage | Allow | - | moodle/competency:planmanagedraft | Allow | - | moodle/competency:planmanageowndraft | Allow | - | moodle/competency:planview | Allow | - | moodle/competency:planreview | Allow | - | moodle/competency:planrequestreview | Allow | - And I log out + And the following "blocks" exist: + | blockname | contextlevel | reference | pagetypepattern | defaultregion | + | lp | System | 1 | my-index | content | Scenario: User can manages his own plan draft Given I log in as "user1" diff --git a/admin/tool/monitor/tests/behat/subscription.feature b/admin/tool/monitor/tests/behat/subscription.feature index c91d45a6951..7182ce26866 100644 --- a/admin/tool/monitor/tests/behat/subscription.feature +++ b/admin/tool/monitor/tests/behat/subscription.feature @@ -168,10 +168,9 @@ Feature: tool_monitor_subscriptions And I should not see "You can manage rules the from the Event monitoring rules page." Scenario: No manage rules link when user does not have permission - Given I log in as "admin" - And I set the following system permissions of "Non-editing teacher" role: - | tool/monitor:managerules | Prohibit | - And I log out + Given the following "role capability" exists: + | role | teacher | + | tool/monitor:managerules | prohibit | And I log in as "teacher1" And I follow "Preferences" in the user menu And I follow "Event monitoring" diff --git a/admin/tool/policy/tests/behat/acceptances.feature b/admin/tool/policy/tests/behat/acceptances.feature index 562c27e80fd..8df506a54a0 100644 --- a/admin/tool/policy/tests/behat/acceptances.feature +++ b/admin/tool/policy/tests/behat/acceptances.feature @@ -48,11 +48,9 @@ Feature: Viewing acceptances reports and accepting on behalf of other users And "Pending" "text" should exist in the "User Two" "table_row" Scenario: Agree on behalf of another user as a manager, single policy, javascript off - Given I log in as "admin" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | - And I log out + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | When I log in as "manager" And I press "Next" And I set the field "I agree to the This site policy" to "1" @@ -73,11 +71,9 @@ Feature: Viewing acceptances reports and accepting on behalf of other users @javascript Scenario: Agree on behalf of another user as a manager, single policy, javascript on - Given I log in as "admin" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | - And I log out + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | When I log in as "manager" And I press "Next" And I set the field "I agree to the This site policy" to "1" @@ -135,13 +131,13 @@ Feature: Viewing acceptances reports and accepting on behalf of other users And "Pending" "text" should exist in the "This privacy policy" "table_row" Scenario: Agree on behalf of another user as a manager, multiple policies, javascript off - Given I log in as "admin" + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | + And I log in as "admin" And I navigate to "Users > Privacy and policies > Manage policies" in site administration And I click on "Set status to \"Active\"" "link" in the "This privacy policy" "table_row" And I press "Continue" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | And I log out When I log in as "manager" And I press "Next" @@ -167,14 +163,14 @@ Feature: Viewing acceptances reports and accepting on behalf of other users @javascript Scenario: Agree on behalf of another user as a manager, multiple policies, javascript on - Given I log in as "admin" + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | + And I log in as "admin" And I navigate to "Users > Privacy and policies > Manage policies" in site administration And I click on "Actions" "link_or_button" in the "This privacy policy" "table_row" And I click on "Set status to \"Active\"" "link" in the "This privacy policy" "table_row" And I press "Activate" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | And I log out When I log in as "manager" And I press "Next" @@ -215,11 +211,9 @@ Feature: Viewing acceptances reports and accepting on behalf of other users And I should not see "Policies and agreements" Scenario: Policies and agreements profile link visible also for users who can access on behalf of others - Given I log in as "admin" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | - And I log out + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | And I log in as "manager" And I press "Next" And I set the field "I agree to the This site policy" to "1" @@ -231,11 +225,9 @@ Feature: Viewing acceptances reports and accepting on behalf of other users Then I should see "Policies and agreements" Scenario: Agree on behalf of another user as an admin who is logged in as a manager - Given I log in as "admin" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | - And I log out + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | When I log in as "manager" And I press "Next" And I set the field "I agree to the This site policy" to "1" @@ -261,14 +253,14 @@ Feature: Viewing acceptances reports and accepting on behalf of other users @javascript Scenario: Bulk agree on behalf of another users as a manager, multiple policies, javascript on - Given I log in as "admin" + Given the following "role capability" exists: + | role | manager | + | tool/policy:acceptbehalf | allow | + And I log in as "admin" And I navigate to "Users > Privacy and policies > Manage policies" in site administration And I click on "Actions" "link_or_button" in the "This privacy policy" "table_row" And I click on "Set status to \"Active\"" "link" in the "This privacy policy" "table_row" And I press "Activate" - And I set the following system permissions of "Manager" role: - | capability | permission | - | tool/policy:acceptbehalf | Allow | And I log out When I log in as "manager" And I press "Next" diff --git a/blocks/navigation/tests/behat/participants_link.feature b/blocks/navigation/tests/behat/participants_link.feature index b83a6291753..63088c4feb3 100644 --- a/blocks/navigation/tests/behat/participants_link.feature +++ b/blocks/navigation/tests/behat/participants_link.feature @@ -52,10 +52,9 @@ Feature: Displaying the link to the Participants page And I am on the "Test forum name" "forum activity" page And I should not see "Participants" in the "Navigation" "block" And I log out - And I log in as "admin" - And I set the following system permissions of "Guest" role: - | capability | permission | - | moodle/course:viewparticipants | Allow | + And the following "role capability" exists: + | role | guest | + | moodle/course:viewparticipants | allow | And I am on the "Course1" course page logged in as guest And I should see "Participants" in the "Navigation" "block" And I am on the "Test forum name" "forum activity" page diff --git a/blocks/tests/behat/restrict_available_blocks.feature b/blocks/tests/behat/restrict_available_blocks.feature index 581d0f84f77..2885dd241e7 100644 --- a/blocks/tests/behat/restrict_available_blocks.feature +++ b/blocks/tests/behat/restrict_available_blocks.feature @@ -24,9 +24,10 @@ Feature: Allowed blocks controls And I should see "Course completion status" in the "Course completion status" "block" Scenario: Blocks can not be added when the admin restricts the permissions - Given I log in as "admin" - And I set the following system permissions of "Teacher" role: - | block/activity_modules:addinstance | Prohibit | + Given the following "role capability" exists: + | role | editingteacher | + | block/activity_modules:addinstance | prohibit | + And I log in as "admin" And I am on "Course 1" course homepage And I navigate to "Users > Permissions" in current page administration And I override the system permissions of "Teacher" role with: diff --git a/course/format/singleactivity/tests/behat/create_course.feature b/course/format/singleactivity/tests/behat/create_course.feature index 6eee07ff1cf..abce67e9eca 100644 --- a/course/format/singleactivity/tests/behat/create_course.feature +++ b/course/format/singleactivity/tests/behat/create_course.feature @@ -14,19 +14,17 @@ Feature: Courses can be created in Single Activity mode And the following "system role assigns" exist: | user | role | contextlevel | | kevin | creator | System | - And I log in as "admin" - And I set the following system permissions of "Creator" role: - | capability | permission | - | moodle/course:create | Allow | - | moodle/course:update | Allow | - | moodle/course:manageactivities | Allow | - | moodle/course:viewparticipants | Allow | - | moodle/role:assign | Allow | - | mod/quiz:addinstance | Allow | - And I log out - And I log in as "kevin" + And the following "role capability" exists: + | role | creator | + | moodle/course:create | allow | + | moodle/course:update | allow | + | moodle/course:manageactivities | allow | + | moodle/course:viewparticipants | allow | + | moodle/role:assign | allow | + | mod/quiz:addinstance | allow | + When I log in as "kevin" And I am on site homepage - When I press "Add a new course" + And I press "Add a new course" And I set the following fields to these values: | Course full name | My first course | | Course short name | myfirstcourse | diff --git a/course/tests/behat/course_browsing.feature b/course/tests/behat/course_browsing.feature index 4993d076e20..4bf22ab9113 100644 --- a/course/tests/behat/course_browsing.feature +++ b/course/tests/behat/course_browsing.feature @@ -17,24 +17,20 @@ Feature: Restricting access to course lists | English Y1 | ENG1 | ENG | | English Y2 | ENG2 | ENG | | Humanities Y1 | HUM2 | MISC | - Given the following "users" exist: + And the following "users" exist: | username | firstname | lastname | email | | user0 | User | Z | user0@example.com | | userb | User | B | userb@example.com | | usere | User | E | usere@example.com | - Given the following "roles" exist: + And the following "roles" exist: | name | shortname | description | archetype | | Category viewer | coursebrowse | My custom role 1 | | + And the following "role capability" exist: + | role | moodle/category:viewcourselist | + | user | prevent | + | guest | prevent | + | coursebrowse | allow | Given I log in as "admin" - And I set the following system permissions of "Authenticated user" role: - | capability | permission | - | moodle/category:viewcourselist | Prevent | - And I set the following system permissions of "Guest" role: - | capability | permission | - | moodle/category:viewcourselist | Prevent | - And I set the following system permissions of "Category viewer" role: - | capability | permission | - | moodle/category:viewcourselist | Allow | And I am on site homepage And I turn editing mode on And I add the "Navigation" block if not present diff --git a/course/tests/behat/course_creation.feature b/course/tests/behat/course_creation.feature index 72eaf945e05..965fe16c39b 100644 --- a/course/tests/behat/course_creation.feature +++ b/course/tests/behat/course_creation.feature @@ -76,13 +76,11 @@ Feature: Managers can create courses And the following "system role assigns" exist: | user | role | contextlevel | | kevin | creator | System | - And I log in as "admin" - And I set the following system permissions of "Creator" role: - | capability | permission | - | moodle/course:create | Allow | - | moodle/course:manageactivities | Allow | - | moodle/course:viewparticipants | Allow | - And I log out + And the following "role capability" exists: + | role | creator | + | moodle/course:create | allow | + | moodle/course:manageactivities | allow | + | moodle/course:viewparticipants | allow | And I log in as "kevin" And I am on site homepage When I press "Add a new course" diff --git a/course/tests/behat/course_download_content_permissions.feature b/course/tests/behat/course_download_content_permissions.feature index 7ec66482833..b5f2110b411 100644 --- a/course/tests/behat/course_download_content_permissions.feature +++ b/course/tests/behat/course_download_content_permissions.feature @@ -16,10 +16,8 @@ Feature: Access to downloading course content can be controlled | user | course | role | | teacher1 | C1 | editingteacher | | student1 | C1 | student | - And I log in as "admin" And the following config values are set as admin: - | downloadcoursecontentallowed | 1 | - And I log out + | downloadcoursecontentallowed | 1 | Scenario: Site admins can remove the download course content feature Given I log in as "admin" @@ -60,25 +58,20 @@ Feature: Access to downloading course content can be controlled And "Download course content" "link" should not exist in current page administration Scenario: Teachers require a capability to access the download course content feature or modify its availability in a course - Given I log in as "admin" - And I navigate to "Courses > Course default settings" in site administration - And I set the field "Enable download course content" to "Yes" - And I press "Save changes" - And I log out + Given the following config values are set as admin: + | config | value | plugin | + | downloadcontentsitedefault | 1 | moodlecourse | # Check teacher can see download option and enable dropdown. And I log in as "teacher1" And I am on "Hockey 101" course homepage And "Download course content" "link" should exist in current page administration And I navigate to "Edit settings" in current page administration And "Enable download course content" "select" should exist - And I log out # Remove teacher's capabilities for download course content. - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | moodle/course:downloadcoursecontent | Prohibit | - | moodle/course:configuredownloadcontent | Prohibit | - And I log out + And the following "role capability" exists: + | role | editingteacher | + | moodle/course:downloadcoursecontent | prohibit | + | moodle/course:configuredownloadcontent | prohibit | # Check teacher can no longer see download option, and that enable value is visible, but dropdown no longer available. When I log in as "teacher1" And I am on "Hockey 101" course homepage @@ -99,13 +92,10 @@ Feature: Access to downloading course content can be controlled And I log in as "student1" And I am on "Hockey 101" course homepage And "Download course content" "button" should exist - And I log out - And I log in as "admin" # Remove student's capability for download course content. - When I set the following system permissions of "Student" role: - | capability | permission | - | moodle/course:downloadcoursecontent | Prohibit | - And I log out + When the following "role capability" exists: + | role | student | + | moodle/course:downloadcoursecontent | prohibit | # Check student can no longer see download button. And I log in as "student1" And I am on "Hockey 101" course homepage diff --git a/course/tests/behat/course_request.feature b/course/tests/behat/course_request.feature index 19fa9534ea2..2aa4a4ec352 100644 --- a/course/tests/behat/course_request.feature +++ b/course/tests/behat/course_request.feature @@ -17,11 +17,9 @@ Feature: Users can request and approve courses | user2 | Acceptance test site | manager | And the following config values are set as admin: | lockrequestcategory | 1 | - Given I log in as "admin" - And I set the following system permissions of "Authenticated user" role: - | capability | permission | - | moodle/course:request | Allow | - And I log out + And the following "role capability" exists: + | role | user | + | moodle/course:request | allow | When I log in as "user1" And I am on course index And I press "Request a course" @@ -67,11 +65,9 @@ Feature: Users can request and approve courses | user1 | courserequestor | Category | ENG | | user2 | manager | Category | SCI | | user3 | manager | Category | ENG | - Given I log in as "admin" - And I set the following system permissions of "Course requestor" role: - | capability | permission | - | moodle/course:request | Allow | - And I log out + And the following "role capability" exists: + | role | courserequestor | + | moodle/course:request | allow | And I log in as "user1" And I am on course index And I follow "English category" diff --git a/course/tests/behat/coursetags.feature b/course/tests/behat/coursetags.feature index 35068933a37..affbf37592c 100644 --- a/course/tests/behat/coursetags.feature +++ b/course/tests/behat/coursetags.feature @@ -66,10 +66,9 @@ Feature: Tagging courses And I log out Scenario: User can set course tags using separate form - Given I log in as "admin" - And I set the following system permissions of "Non-editing teacher" role: - | moodle/course:tag | Allow | - And I log out + Given the following "role capability" exists: + | role | teacher | + | moodle/course:tag | allow | When I log in as "teacher2" And I am on "Course 1" course homepage And I navigate to "Course tags" in current page administration diff --git a/course/tests/behat/keyholder.feature b/course/tests/behat/keyholder.feature index 604f8940479..e5ceb9a08d2 100644 --- a/course/tests/behat/keyholder.feature +++ b/course/tests/behat/keyholder.feature @@ -1,62 +1,54 @@ -@core @core_course @javascript +@core @core_course Feature: Keyholder role is listed as course contact As a student I need to know who the keyholder is to enrol in a course Background: - Given I log in as "admin" - And I am on site homepage + Given the following "role" exists: + | shortname | keyholder | + | name | Keyholder | + | context_coursecat | 1 | + | context_course | 1 | + | enrol/self:holdkey | allow | And the following "categories" exist: | name | category | idnumber | | Cat 1 | 0 | CAT1 | - And I navigate to "Users > Permissions > Define roles" in site administration - And I click on "Add a new role" "button" - And I click on "Continue" "button" - And I set the following fields to these values: - | Short name | keyholder | - | Custom full name | Keyholder | - | contextlevel40 | 1 | - | contextlevel50 | 1 | - | enrol/self:holdkey | 1 | - And I click on "Create this role" "button" - And I navigate to "Appearance > Courses" in site administration - And I click on "Keyholder" "checkbox" - And I press "Save changes" And the following "users" exist: - | username | firstname | lastname | email | - | teacher1 | Teacher | 1 | teacher1@example.com | - | keyholder1 | Keyholder | 1 | keyholder1@example.com | - | student1 | Student | 1 | teacher1@example.com | + | username | firstname | lastname | email | + | teacher1 | Teacher | 1 | teacher1@example.com | + | keyholder1 | Keyholder | 1 | keyholder1@example.com | + | student1 | Student | 1 | teacher1@example.com | And the following "courses" exist: | fullname | shortname | format | coursedisplay | numsections | category | - | Course 1 | C1 | topics | 0 | 5 | CAT1 | + | Course 1 | C1 | topics | 0 | 5 | CAT1 | + And I log in as "admin" And I am on "Course 1" course homepage And I add "Self enrolment" enrolment method with: | Custom instance name | Test student enrolment | | Enrolment key | letmein | + And I navigate to "Appearance > Courses" in site administration + And I set the following fields to these values: + | Keyholder | 1 | + And I press "Save changes" And I log out Scenario: Keyholder assigned to a course - When I log in as "admin" - And the following "course enrolments" exist: - | user | course | role | - | teacher1 | C1 | editingteacher | - | keyholder1 | C1 | keyholder | - And I log out - And I log in as "student1" + Given the following "course enrolments" exist: + | user | course | role | + | teacher1 | C1 | editingteacher | + | keyholder1 | C1 | keyholder | + When I log in as "student1" And I am on site homepage And I follow "Course 1" Then I should see "Keyholder 1" Scenario: Keyholder assigned to a category - When I log in as "admin" - And the following "role assigns" exist: - | user | role | contextlevel | reference | - | keyholder1 | keyholder | Category | CAT1 | + Given the following "role assigns" exist: + | user | role | contextlevel | reference | + | keyholder1 | keyholder | Category | CAT1 | And the following "course enrolments" exist: - | user | course | role | - | teacher1 | C1 | editingteacher | - And I log out - And I log in as "student1" + | user | course | role | + | teacher1 | C1 | editingteacher | + When I log in as "student1" And I am on site homepage And I follow "Course 1" Then I should see "Keyholder 1" diff --git a/course/tests/behat/navigate_course_list.feature b/course/tests/behat/navigate_course_list.feature index 4f7be585d40..69e94db5760 100644 --- a/course/tests/behat/navigate_course_list.feature +++ b/course/tests/behat/navigate_course_list.feature @@ -60,11 +60,9 @@ Feature: Browse course list and return back from enrolment page And the following "activities" exist: | activity | name | intro | course | idnumber | | choice | Test choice | Test choice description | C1 | choice1 | - And I log in as "admin" - And I set the following system permissions of "Non-enrolled" role: - | capability | permission | - | moodle/course:view | Allow | - And I log out + And the following "role capability" exists: + | role | custom1 | + | moodle/course:view | allow | When I log in as "user1" And I am on course index And I follow "Miscellaneous" diff --git a/course/tests/behat/restrict_available_activities.feature b/course/tests/behat/restrict_available_activities.feature index d0b7d9a7ab5..a71ea70bf32 100644 --- a/course/tests/behat/restrict_available_activities.feature +++ b/course/tests/behat/restrict_available_activities.feature @@ -30,9 +30,10 @@ Feature: Restrict activities availability @javascript @skip_chrome_zerosize Scenario: Activities can not be added when the admin restricts the permissions - Given I log in as "admin" - And I set the following system permissions of "Teacher" role: - | mod/chat:addinstance | Prohibit | + Given the following "role capability" exists: + | role | editingteacher | + | mod/chat:addinstance | prohibit | + And I log in as "admin" And I am on "Course 1" course homepage And I navigate to "Users > Permissions" in current page administration And I override the system permissions of "Teacher" role with: diff --git a/course/tests/behat/role_renaming.feature b/course/tests/behat/role_renaming.feature index b3aac3dae3e..bd66cd9c994 100644 --- a/course/tests/behat/role_renaming.feature +++ b/course/tests/behat/role_renaming.feature @@ -39,11 +39,9 @@ Feature: Rename roles in a course And I should not see "Learner (Student)" in the "Student 1" "table_row" Scenario: Ability to rename roles can be prevented - Given I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | moodle/course:renameroles | Inherit | - And I follow "Log out" + Given the following "role capability" exists: + | role | editingteacher | + | moodle/course:renameroles | inherit | When I log in as "teacher1" And I am on "Course 1" course homepage And I navigate to "Edit settings" in current page administration diff --git a/enrol/self/tests/behat/key_holder.feature b/enrol/self/tests/behat/key_holder.feature index eae9dd415f7..56d41c6f11e 100644 --- a/enrol/self/tests/behat/key_holder.feature +++ b/enrol/self/tests/behat/key_holder.feature @@ -5,23 +5,17 @@ Feature: Users can be defined as key holders in courses where self enrolment is I need to auto enrol me in courses Background: - Given the following "users" exist: + Given the following "roles" exist: + | shortname | name | context_course | enrol/self:holdkey | + | keyholder | Key holder | 1 | allow | + And the following "users" exist: | username | firstname | lastname | email | | manager1 | Manager | 1 | manager1@example.com | | student1 | Student | 1 | student1@example.com | And the following "courses" exist: | fullname | shortname | format | - | Course 1 | C1 | topics | + | Course 1 | C1 | topics | And I log in as "admin" - And I navigate to "Users > Permissions > Define roles" in site administration - And I click on "Add a new role" "button" - And I click on "Continue" "button" - And I set the following fields to these values: - | Short name | keyholder | - | Custom full name | Key holder | - | contextlevel50 | 1 | - | enrol/self:holdkey | 1 | - And I click on "Create this role" "button" And I navigate to "Appearance > Courses" in site administration And I set the following fields to these values: | Key holder | 1 | diff --git a/grade/report/grader/tests/behat/switch_views.feature b/grade/report/grader/tests/behat/switch_views.feature index 5e9af733f98..7e307d311a3 100644 --- a/grade/report/grader/tests/behat/switch_views.feature +++ b/grade/report/grader/tests/behat/switch_views.feature @@ -69,19 +69,15 @@ Feature: We can change what we are viewing on the grader report @javascript @skip_chrome_zerosize Scenario: Minimise the grader report containing hidden activities without the 'moodle/grade:viewhidden' capability - When I am on "Course 1" course homepage with editing mode on + Given I am on "Course 1" course homepage with editing mode on And I open "Test assignment name 2" actions menu And I click on "Hide" "link" in the "Test assignment name 2" activity - And I log out - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | moodle/grade:viewhidden | Prevent | - And I log out - And I log in as "teacher1" - And I am on "Course 1" course homepage + And the following "role capability" exists: + | role | editingteacher | + | moodle/grade:viewhidden | prevent | + And I am on the "C1" "course" page logged in as "teacher1" And I navigate to "View > Grader report" in the course gradebook - And I should see "Test assignment name 1" in the "user-grades" "table" + Then I should see "Test assignment name 1" in the "user-grades" "table" And I should see "Test assignment name 2" in the "user-grades" "table" And I should see "Manual grade" And I should see "Course total" diff --git a/grade/report/user/tests/behat/user_view.feature b/grade/report/user/tests/behat/user_view.feature index eb9bef2d334..5a8f4f7ed4e 100644 --- a/grade/report/user/tests/behat/user_view.feature +++ b/grade/report/user/tests/behat/user_view.feature @@ -175,14 +175,10 @@ Feature: View the user report as the student will see it | Test assignment six | Scenario: View the report as the student from both the teachers and students perspective when the student can view hidden - Given I log out - And I log in as "admin" - And I set the following system permissions of "Student" role: - | capability | permission | - | moodle/grade:viewhidden | Allow | - And I log out - And I log in as "teacher1" - And I am on "Course 1" course homepage + Given the following "role capability" exists: + | role | student | + | moodle/grade:viewhidden | allow | + And I am on the "C1" "Course" page logged in as "teacher1" And I navigate to "Setup > Course grade settings" in the course gradebook And I set the field with xpath "//select[@name='report_user_showtotalsifcontainhidden']" to "Show totals excluding hidden items" And I press "Save changes" diff --git a/group/tests/behat/auto_creation.feature b/group/tests/behat/auto_creation.feature index 9d8c4deeb49..1cd919c6f6c 100644 --- a/group/tests/behat/auto_creation.feature +++ b/group/tests/behat/auto_creation.feature @@ -165,11 +165,9 @@ Feature: Automatic creation of groups Scenario: Do not display 'Include only active enrolments' if user does not have the 'moodle/course:viewsuspendedusers' capability Given I log out - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | moodle/course:viewsuspendedusers | Prevent | - And I log out + And the following "role capability" exists: + | role | editingteacher | + | moodle/course:viewsuspendedusers | prevent | And I log in as "teacher1" And I am on "Course 1" course homepage And I navigate to "Users > Groups" in current page administration diff --git a/group/tests/behat/create_groups.feature b/group/tests/behat/create_groups.feature index 2b4a65a271c..5d579090a0f 100644 --- a/group/tests/behat/create_groups.feature +++ b/group/tests/behat/create_groups.feature @@ -101,10 +101,9 @@ Feature: Organize students into groups And the following "course enrolments" exist: | user | course | role | | teacher1 | C1 | editingteacher | - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | moodle/course:changeidnumber | Prevent | - And I log out + And the following "role capability" exists: + | role | editingteacher | + | moodle/course:changeidnumber | prevent | And I log in as "teacher1" And I am on "Course 1" course homepage And I navigate to "Users > Groups" in current page administration diff --git a/group/tests/behat/delete_groups.feature b/group/tests/behat/delete_groups.feature index 380b7f4b648..44a21f0f3c5 100644 --- a/group/tests/behat/delete_groups.feature +++ b/group/tests/behat/delete_groups.feature @@ -58,11 +58,9 @@ Feature: Automatic deletion of groups and groupings @javascript @skip_chrome_zerosize Scenario: Delete groups and groupings with and without ID numbers without the 'moodle/course:changeidnumber' capability - Given I log out - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | moodle/course:changeidnumber | Prevent | - And I log out + Given the following "role capability" exists: + | role | editingteacher | + | moodle/course:changeidnumber | prevent | And I log in as "teacher1" And I am on "Course 1" course homepage And I navigate to "Users > Groups" in current page administration diff --git a/group/tests/behat/update_groups.feature b/group/tests/behat/update_groups.feature index 51ffb45c6cb..9c5b4de0c2d 100644 --- a/group/tests/behat/update_groups.feature +++ b/group/tests/behat/update_groups.feature @@ -65,11 +65,9 @@ Feature: Automatic updating of groups and groupings @javascript @skip_chrome_zerosize Scenario: Update groups and groupings with ID numbers without the 'moodle/course:changeidnumber' capability - Given I log out - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | moodle/course:changeidnumber | Prevent | - And I log out + Given the following "role capability" exists: + | role | editingteacher | + | moodle/course:changeidnumber | prevent | And I log in as "teacher1" And I am on "Course 1" course homepage And I navigate to "Users > Groups" in current page administration diff --git a/lib/behat/classes/behat_core_generator.php b/lib/behat/classes/behat_core_generator.php index 75e7860ef2c..dbbd67f8185 100644 --- a/lib/behat/classes/behat_core_generator.php +++ b/lib/behat/classes/behat_core_generator.php @@ -156,6 +156,12 @@ class behat_core_generator extends behat_generator_base { 'datagenerator' => 'role', 'required' => ['shortname'], ], + 'role capabilities' => [ + 'singular' => 'role capability', + 'datagenerator' => 'role_capability', + 'required' => ['role'], + 'switchids' => ['role' => 'roleid'], + ], 'grade categories' => [ 'singular' => 'grade category', 'datagenerator' => 'grade_category', @@ -709,6 +715,23 @@ class behat_core_generator extends behat_generator_base { $this->datagenerator->create_role($data); } + /** + * Assign capabilities to a role. + * + * @param array $data + */ + protected function process_role_capability($data): void { + // We require the user to fill the role shortname. + if (empty($data['roleid'])) { + throw new Exception('\'role capability\' requires the field \'roleid\' to be specified'); + } + + $roleid = $data['roleid']; + unset($data['roleid']); + + $this->datagenerator->create_role_capability($roleid, $data, \context_system::instance()); + } + /** * Adds members to cohorts * diff --git a/lib/testing/generator/data_generator.php b/lib/testing/generator/data_generator.php index 15e63390617..bebd837b002 100644 --- a/lib/testing/generator/data_generator.php +++ b/lib/testing/generator/data_generator.php @@ -789,7 +789,20 @@ EOD; // If no archetype was specified we allow it to be added to all contexts, // otherwise we allow it in the archetype contexts. if (!$record['archetype']) { - $contextlevels = array_keys(context_helper::get_all_levels()); + $contextlevels = []; + $usefallback = true; + foreach (context_helper::get_all_levels() as $level => $title) { + if (array_key_exists($title, $record)) { + $usefallback = false; + if (!empty($record[$title])) { + $contextlevels[] = $level; + } + } + } + + if ($usefallback) { + $contextlevels = array_keys(context_helper::get_all_levels()); + } } else { // Copying from the archetype default rol. $archetyperoleid = $DB->get_field( @@ -802,7 +815,6 @@ EOD; set_role_contextlevels($newroleid, $contextlevels); if ($record['archetype']) { - // We copy all the roles the archetype can assign, override, switch to and view. if ($record['archetype']) { $types = array('assign', 'override', 'switch', 'view'); @@ -820,9 +832,76 @@ EOD; role_cap_duplicate($sourcerole, $newroleid); } + $allcapabilities = get_all_capabilities(); + $foundcapabilities = array_intersect(array_keys($allcapabilities), array_keys($record)); + $systemcontext = \context_system::instance(); + + $allpermissions = [ + 'inherit' => CAP_INHERIT, + 'allow' => CAP_ALLOW, + 'prevent' => CAP_PREVENT, + 'prohibit' => CAP_PROHIBIT, + ]; + + foreach ($foundcapabilities as $capability) { + $permission = $record[$capability]; + if (!array_key_exists($permission, $allpermissions)) { + throw new \coding_exception("Unknown capability permissions '{$permission}'"); + } + assign_capability( + $capability, + $allpermissions[$permission], + $newroleid, + $systemcontext->id, + true + ); + } + return $newroleid; } + /** + * Set role capabilities for the specified role. + * + * @param int $roleid The Role to set capabilities for + * @param array $rolecapabilities The list of capability =>permission to set for this role + * @param null|context $context The context to apply this capability to + */ + public function create_role_capability(int $roleid, array $rolecapabilities, context $context = null): void { + // Map the capabilities into human-readable names. + $allpermissions = [ + 'inherit' => CAP_INHERIT, + 'allow' => CAP_ALLOW, + 'prevent' => CAP_PREVENT, + 'prohibit' => CAP_PROHIBIT, + ]; + + // Fetch all capabilities to check that they exist. + $allcapabilities = get_all_capabilities(); + foreach ($rolecapabilities as $capability => $permission) { + if ($permission === '') { + // Allow items to be skipped. + continue; + } + + if (!array_key_exists($capability, $allcapabilities)) { + throw new \coding_exception("Unknown capability '{$capability}'"); + } + + if (!array_key_exists($permission, $allpermissions)) { + throw new \coding_exception("Unknown capability permissions '{$permission}'"); + } + + assign_capability( + $capability, + $allpermissions[$permission], + $roleid, + $context->id, + true + ); + } + } + /** * Create a tag. * diff --git a/lib/tests/behat/behat_data_generators.php b/lib/tests/behat/behat_data_generators.php index 9c44aad388f..c95b24b6f3f 100644 --- a/lib/tests/behat/behat_data_generators.php +++ b/lib/tests/behat/behat_data_generators.php @@ -93,7 +93,35 @@ class behat_data_generators extends behat_base { } /** - * Creates the specified element. + * Create multiple entities of one entity type. + * + * @Given :count :entitytype exist with the following data: + * + * @param string $entitytype The name of the type entity to add + * @param int $count + * @param TableNode $data + */ + public function the_following_repeated_entities_exist(string $entitytype, int $count, TableNode $data): void { + $rows = $data->getRowsHash(); + + $tabledata = [array_keys($rows)]; + for ($current = 1; $current < $count + 1; $current++) { + $rowdata = []; + foreach ($rows as $fieldname => $fieldtemplate) { + $rowdata[$fieldname] = str_replace('[count]', $current, $fieldtemplate); + } + $tabledata[] = $rowdata; + } + + if (isset($this->movedentitytypes[$entitytype])) { + $entitytype = $this->movedentitytypes[$entitytype]; + } + list($component, $entity) = $this->parse_entity_type($entitytype); + $this->get_instance_for_component($component)->generate_items($entity, new TableNode($tabledata), false); + } + + /** + * Creates the specified (singular) element. * * See the class comment for an overview. * diff --git a/lib/tests/behat/behat_permissions.php b/lib/tests/behat/behat_permissions.php index 155ad85d001..119be436d7d 100644 --- a/lib/tests/behat/behat_permissions.php +++ b/lib/tests/behat/behat_permissions.php @@ -47,22 +47,47 @@ class behat_permissions extends behat_base { * @param TableNode $table */ public function i_set_the_following_system_permissions_of_role($rolename, $table) { + // Applied in the System context. + $context = \context_system::instance(); - $parentnodes = get_string('users', 'admin') . ' > ' . - get_string('permissions', 'role'); + // Translate the specified rolename into a role. + $rolenames = role_get_names($context); + $matched = array_filter($rolenames, function($role) use ($rolename) { + return ($role->localname === $rolename) || ($role->shortname === $rolename) || ($role->description === $rolename); + }); - // Go to home page. - $this->execute("behat_general::i_am_on_homepage"); + if (count($matched) === 0) { + throw new ExpectationException("Unable to find a role with name '{$rolename}'", $this->getSession()); + } else if (count($matched) > 1) { + throw new ExpectationException("Multiple roles matched '{$rolename}'", $this->getSession()); + } - // Navigate to course management page via navigation block. - $this->execute("behat_navigation::i_navigate_to_in_site_administration", - array($parentnodes . ' > ' . get_string('defineroles', 'role')) + $role = reset($matched); + + $permissionmap = [ + get_string('inherit', 'role') => 'inherit', + get_string('allow', 'role') => 'allow', + get_string('prevent', 'role') => 'prevent', + get_string('prohibit', 'role') => 'prohibit', + ]; + + $columns = ['role']; + $newtabledata = [$role->shortname]; + foreach ($table as $data) { + $columns[] = $data['capability']; + $newtabledata[] = $permissionmap[$data['permission']]; + } + + $this->execute( + 'behat_data_generators::the_following_entities_exist', + [ + 'role capabilities', + new TableNode([ + 0 => $columns, + 1 => $newtabledata, + ]) + ] ); - - $this->execute("behat_general::click_link", "Edit " . $this->escape($rolename) . " role"); - $this->execute("behat_permissions::i_fill_the_capabilities_form_with_the_following_permissions", $table); - - $this->execute('behat_forms::press_button', get_string('savechanges')); } /** diff --git a/mod/assign/tests/behat/bulk_remove_submissions.feature b/mod/assign/tests/behat/bulk_remove_submissions.feature index 76a09b95420..1ee90f43886 100644 --- a/mod/assign/tests/behat/bulk_remove_submissions.feature +++ b/mod/assign/tests/behat/bulk_remove_submissions.feature @@ -35,12 +35,9 @@ Feature: Bulk remove submissions | assign | user | onlinetext | | Test assignment name | student1 | I'm the student1 submission | | Test assignment name | student2 | I'm the student2 submission | - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | mod/assign:editothersubmission | Allow | - And I log out - + And the following "role capability" exists: + | role | editingteacher | + | mod/assign:editothersubmission | allow | And I am on the "Test assignment name" Activity page logged in as teacher1 And I navigate to "View all submissions" in current page administration And I should see "I'm the student1 submission" @@ -96,13 +93,9 @@ Feature: Bulk remove submissions | assign | user | onlinetext | | Test assignment name | student1 | I'm the student1 submission | | Test assignment name | student2 | I'm the student2 submission | - - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | mod/assign:editothersubmission | Allow | - And I log out - + And the following "role capability" exists: + | role | editingteacher | + | mod/assign:editothersubmission | allow | And I am on the "Test assignment name" Activity page logged in as teacher1 And I navigate to "View all submissions" in current page administration And I should see "I'm the student1 submission" @@ -135,12 +128,9 @@ Feature: Bulk remove submissions | assign | user | onlinetext | | Test assignment name | student1 | I'm the student1 submission | | Test assignment name | student2 | I'm the student2 submission | - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | mod/assign:editothersubmission | Allow | - And I log out - + And the following "role capability" exists: + | role | editingteacher | + | mod/assign:editothersubmission | allow | And I am on the "Test assignment name" Activity page logged in as teacher1 And I navigate to "View all submissions" in current page administration And I should see "I'm the student1 submission" diff --git a/mod/assign/tests/behat/remove_submission.feature b/mod/assign/tests/behat/remove_submission.feature index 1a98e2a1993..d40dc69f87d 100644 --- a/mod/assign/tests/behat/remove_submission.feature +++ b/mod/assign/tests/behat/remove_submission.feature @@ -5,11 +5,8 @@ Feature: Remove a submission I need to remove a student submission at any time Background: - Given I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | mod/assign:editothersubmission | Allow | - And I log out + Given the following config values are set as admin: + | enabletimelimit | 1 | assign | And the following "courses" exist: | fullname | shortname | category | groupmode | | Course 1 | C1 | 0 | 0 | @@ -23,6 +20,9 @@ Feature: Remove a submission | teacher1 | C1 | editingteacher | | student1 | C1 | student | | student2 | C1 | student | + And the following "role capability" exists: + | role | editingteacher | + | mod/assign:editothersubmission | allow | And the following "groups" exist: | name | course | idnumber | | Group 1 | C1 | G1 | diff --git a/mod/feedback/tests/behat/anonymous.feature b/mod/feedback/tests/behat/anonymous.feature index b01c03541c8..2303cd92af4 100644 --- a/mod/feedback/tests/behat/anonymous.feature +++ b/mod/feedback/tests/behat/anonymous.feature @@ -62,11 +62,9 @@ Feature: Anonymous feedback @javascript Scenario: Complete anonymous feedback and view analysis on the front page as an authenticated user - And I log in as "admin" - And I set the following system permissions of "Authenticated user on frontpage" role: - | capability | permission | - | mod/feedback:viewanalysepage | Allow | - And I log out + Given the following "role capability" exists: + | role | frontpage | + | mod/feedback:viewanalysepage | allow | And I log in as "user1" And I am on site homepage When I follow "Site feedback" @@ -128,11 +126,9 @@ Feature: Anonymous feedback Scenario: Complete fully anonymous feedback and view analyze on the front page as a guest Given the following config values are set as admin: | feedback_allowfullanonymous | 1 | - And I log in as "admin" - And I set the following system permissions of "Guest" role: - | capability | permission | - | mod/feedback:viewanalysepage | Allow | - And I log out + And the following "role capability" exists: + | role | guest | + | mod/feedback:viewanalysepage | allow | When I follow "Site feedback" And I follow "Preview" And I should see "Do you like our site?" diff --git a/mod/feedback/tests/behat/non_anonymous.feature b/mod/feedback/tests/behat/non_anonymous.feature index b360de1ab7e..1916b7acd9d 100644 --- a/mod/feedback/tests/behat/non_anonymous.feature +++ b/mod/feedback/tests/behat/non_anonymous.feature @@ -62,14 +62,10 @@ Feature: Non anonymous feedback @javascript Scenario: Complete non anonymous feedback and view analysis on the front page as an authenticated user - And I log in as "admin" - And I set the following system permissions of "Authenticated user on frontpage" role: - | capability | permission | - | mod/feedback:viewanalysepage | Allow | - And I log out - And I log in as "user1" - And I am on site homepage - When I follow "Site feedback" + Given the following "role capability" exists: + | role | frontpage | + | mod/feedback:viewanalysepage | allow | + When I am on the "Site feedback" "feedback activity" page logged in as user1 And I follow "Answer the questions" And I should see "Do you like our site?" And I set the following fields to these values: diff --git a/mod/forum/tests/behat/separate_group_discussions.feature b/mod/forum/tests/behat/separate_group_discussions.feature index c30b6c1120c..f6cc0f0a9ed 100644 --- a/mod/forum/tests/behat/separate_group_discussions.feature +++ b/mod/forum/tests/behat/separate_group_discussions.feature @@ -226,9 +226,6 @@ Feature: Posting to all groups in a separate group discussion is restricted to u And I should not see "Student -> A" Scenario: Teacher in all groups but without accessallgroups can only post in their groups - And I log in as "admin" - And I set the following system permissions of "Non-editing teacher" role: - | moodle/site:accessallgroups | Prohibit | Given I am on the "Standard forum name" "forum activity" page logged in as noneditor1 When I click on "Add a new discussion topic" "link" And I click on "Advanced" "button" @@ -238,9 +235,6 @@ Feature: Posting to all groups in a separate group discussion is restricted to u And I should see "Post a copy to all groups" Scenario: Teacher in some groups and without accessallgroups can only post in their groups - And I log in as "admin" - And I set the following system permissions of "Non-editing teacher" role: - | moodle/site:accessallgroups | Prohibit | Given I am on the "Standard forum name" "forum activity" page logged in as noneditor1 When I click on "Add a new discussion topic" "link" And I click on "Advanced" "button" diff --git a/mod/lesson/tests/behat/link_to_gradebook.feature b/mod/lesson/tests/behat/link_to_gradebook.feature index 87bd60f913a..28f552ec527 100644 --- a/mod/lesson/tests/behat/link_to_gradebook.feature +++ b/mod/lesson/tests/behat/link_to_gradebook.feature @@ -82,10 +82,9 @@ Feature: link to gradebook on the end of lesson page And I should not see "View grades" Scenario: No link to gradebook if no gradereport/user:view capability - Given I log in as "admin" - And I set the following system permissions of "Student" role: - | capability | permission | - | gradereport/user:view | Prevent | + Given the following "role capability" exists: + | role | student | + | gradereport/user:view | prevent | When I am on the "Test lesson" "lesson activity" page logged in as student1 And I press "Next page" And I press "Next page" diff --git a/my/tests/behat/reset_all_pages.feature b/my/tests/behat/reset_all_pages.feature index c762b73957b..d1471f2e097 100644 --- a/my/tests/behat/reset_all_pages.feature +++ b/my/tests/behat/reset_all_pages.feature @@ -10,11 +10,10 @@ Feature: Reset all personalised pages to default | student1 | Student | 1 | student1@example.com | | student2 | Student | 2 | student2@example.com | | student3 | Student | 3 | student3@example.com | - And I log in as "admin" - And I set the following system permissions of "Authenticated user" role: - | block/myprofile:addinstance | Allow | - | moodle/block:edit | Allow | - And I log out + And the following "role capability" exists: + | role | user | + | moodle/block:edit | allow | + | block/myprofile:addinstance | allow | And I log in as "student1" And I follow "Dashboard" in the user menu diff --git a/my/tests/behat/restrict_available_blocks.feature b/my/tests/behat/restrict_available_blocks.feature index abe88f0c9c1..e1a03a979aa 100644 --- a/my/tests/behat/restrict_available_blocks.feature +++ b/my/tests/behat/restrict_available_blocks.feature @@ -25,13 +25,12 @@ Feature: Restrict which blocks can be added to Dashboard And the add block selector should contain "Tags" block Scenario: Remove the ability to add the comments block to Dashboard - When I log in as "admin" - And I set the following system permissions of "Authenticated user" role: - | block/comments:myaddinstance | Prohibit | - | block/course_list:myaddinstance | Prohibit | - | block/html:myaddinstance | Prohibit | - And I log out - And I log in as "student1" + Given the following "role capability" exists: + | role | user | + | block/comments:myaddinstance | prohibit | + | block/course_list:myaddinstance | prohibit | + | block/html:myaddinstance | prohibit | + When I log in as "student1" And I press "Customise this page" Then the add block selector should not contain "Comments" block And the add block selector should not contain "Courses" block diff --git a/tag/tests/behat/edit_tag.feature b/tag/tests/behat/edit_tag.feature index c3bc35e51ec..b563ec8a045 100644 --- a/tag/tests/behat/edit_tag.feature +++ b/tag/tests/behat/edit_tag.feature @@ -23,13 +23,11 @@ Feature: Users can edit tags to add description or rename @javascript Scenario: User with tag editing capability can change tag description - Given I log in as "admin" - And I set the following system permissions of "Tag editor" role: - | capability | permission | - | moodle/tag:edit | Allow | - | moodle/site:viewparticipants | Allow | - | moodle/user:viewdetails | Allow | - And I log out + Given the following "role capability" exists: + | role | tageditor | + | moodle/tag:edit | allow | + | moodle/site:viewparticipants | allow | + | moodle/user:viewdetails | allow | When I log in as "editor1" And I press "Customise this page" # TODO MDL-57120 site "Tags" link not accessible without navigation block. diff --git a/tag/tests/behat/flag_tags.feature b/tag/tests/behat/flag_tags.feature index 7eda63891eb..e634137c6df 100644 --- a/tag/tests/behat/flag_tags.feature +++ b/tag/tests/behat/flag_tags.feature @@ -17,12 +17,10 @@ Feature: Users can flag tags and manager can reset flags And the following "tags" exist: | name | isstandard | | Neverusedtag | 1 | - And I log in as "admin" - And I set the following system permissions of "Authenticated user" role: - | capability | permission | - | moodle/site:viewparticipants | Allow | - | moodle/user:viewdetails | Allow | - And I log out + And the following "role capability" exists: + | role | user | + | moodle/site:viewparticipants | allow | + | moodle/user:viewdetails | allow | And I log in as "user2" And I press "Customise this page" # TODO MDL-57120 site "Tags" link not accessible without navigation block. diff --git a/user/tests/behat/enrol_cohort_list.feature b/user/tests/behat/enrol_cohort_list.feature index fe32af431f6..3f09a38415e 100644 --- a/user/tests/behat/enrol_cohort_list.feature +++ b/user/tests/behat/enrol_cohort_list.feature @@ -21,11 +21,10 @@ Feature: Viewing the list of cohorts to enrol in a course | name | Test cohort name | | idnumber | 1337 | | description | Test cohort description | - And I log in as "admin" - And I set the following system permissions of "Teacher" role: - | capability | permission | - | moodle/cohort:manage | Prohibit | - | moodle/cohort:view | Prohibit | + And the following "role capability" exists: + | role | editingteacher | + | moodle/cohort:manage | prohibit | + | moodle/cohort:view | prohibit | And I log out And I am on the "Course 1" course page logged in as teacher1 And I navigate to course participants diff --git a/user/tests/behat/filter_participants.feature b/user/tests/behat/filter_participants.feature index ea9aa6dd5ef..e3cb2d437d2 100644 --- a/user/tests/behat/filter_participants.feature +++ b/user/tests/behat/filter_participants.feature @@ -732,9 +732,10 @@ Feature: Course participants can be filtered @javascript @skip_chrome_zerosize Scenario: Filter by user identity fields when cannot see the field data - Given I log in as "admin" - And I set the following system permissions of "Teacher" role: - | moodle/site:viewuseridentity | Prevent | + Given the following "role capability" exists: + | role | editingteacher | + | moodle/site:viewuseridentity | prevent | + And I log in as "admin" And the following config values are set as admin: | showuseridentity | idnumber,email,city,country | And I log out diff --git a/user/tests/behat/user_grade_navigation.feature b/user/tests/behat/user_grade_navigation.feature index 7eaee807efd..0a20f48ebbb 100644 --- a/user/tests/behat/user_grade_navigation.feature +++ b/user/tests/behat/user_grade_navigation.feature @@ -60,22 +60,18 @@ Feature: The student can navigate to their grades page and user grade report. Then I should see "My badges from Acceptance test site web site" Scenario: Log in as a parent and view a childs grades. + Given the following "role" exists: + | shortname | Parent | + | name | Parent | + | context_user | 1 | + | moodle/user:editprofile | allow | + | moodle/user:viewalldetails | allow | + | moodle/user:viewuseractivitiesreport | allow | + | moodle/user:viewdetails | allow | When I log in as "admin" And I am on site homepage And I turn editing mode on And I add the "Mentees" block - And I navigate to "Users > Permissions > Define roles" in site administration - And I click on "Add a new role" "button" - And I click on "Continue" "button" - And I set the following fields to these values: - | Short name | Parent | - | Custom full name | Parent | - | contextlevel30 | 1 | - | moodle/user:editprofile | 1 | - | moodle/user:viewalldetails | 1 | - | moodle/user:viewuseractivitiesreport | 1 | - | moodle/user:viewdetails | 1 | - And I click on "Create this role" "button" And I am on the "student1" "user > profile" page And I click on "Preferences" "link" in the ".profile_tree" "css_element" And I follow "Assign roles relative to this user" diff --git a/user/tests/behat/view_full_profile.feature b/user/tests/behat/view_full_profile.feature index 59549fdea27..bacf77660a3 100644 --- a/user/tests/behat/view_full_profile.feature +++ b/user/tests/behat/view_full_profile.feature @@ -55,10 +55,9 @@ Feature: Access to full profiles of users Then I should see "First access to site" Scenario: Viewing full profiles with global permission - Given I log in as "admin" - And I set the following system permissions of "Authenticated user" role: - | moodle/user:viewdetails | Allow | - And I log out + Given the following "role capability" exists: + | role | user | + | moodle/user:viewdetails | allow | When I log in as "student1" And I am on "Course 1" course homepage And I navigate to course participants diff --git a/user/tests/behat/view_preferences_page.feature b/user/tests/behat/view_preferences_page.feature index 9e452536e3f..18fa6489ced 100644 --- a/user/tests/behat/view_preferences_page.feature +++ b/user/tests/behat/view_preferences_page.feature @@ -52,22 +52,18 @@ Feature: Access to preferences page Then I should see "Preferences" in the "region-main" "region" Scenario: A user with the appropriate permissions can view another user's permissions page. - Given I log in as "admin" + Given the following "role" exists: + | shortname | Parent | + | name | Parent | + | context_user | 1 | + | moodle/user:editprofile | allow | + | moodle/user:viewalldetails | allow | + | moodle/user:viewuseractivitiesreport | allow | + | moodle/user:viewdetails | allow | + When I log in as "admin" And I am on site homepage And I follow "Turn editing on" And I add the "Mentees" block - And I navigate to "Users > Permissions > Define roles" in site administration - And I click on "Add a new role" "button" - And I click on "Continue" "button" - And I set the following fields to these values: - | Short name | Parent | - | Custom full name | Parent | - | contextlevel30 | 1 | - | moodle/user:editprofile | 1 | - | moodle/user:viewalldetails | 1 | - | moodle/user:viewuseractivitiesreport | 1 | - | moodle/user:viewdetails | 1 | - And I click on "Create this role" "button" And I am on the "student1" "user > profile" page And I click on "Preferences" "link" in the ".profile_tree" "css_element" And I follow "Assign roles relative to this user"