60 行
2.4 KiB
Ruby
60 行
2.4 KiB
Ruby
require 'rails_helper'
|
|
|
|
RSpec.describe 'Wiki creation freeze', type: :request do
|
|
include TagGroupRecords
|
|
include WikiRecords
|
|
|
|
let!(:user) { create_member_user! }
|
|
let(:headers) { { 'X-Transfer-Code' => user.inheritance_code } }
|
|
|
|
it 'updates an independent group without implicitly creating a legacy page' do
|
|
id = seed_group(name: 'independent', description: 'before')
|
|
expect do
|
|
put "/tag_groups/#{ id }", params: {
|
|
name: 'independent', description: 'after', members: [], placements: [] },
|
|
headers:, as: :json
|
|
end.to change(WikiPage, :count).by(0)
|
|
.and change(WikiRevision, :count).by(0)
|
|
.and change(WikiVersion, :count).by(0)
|
|
expect(response).to have_http_status(:ok)
|
|
expect(TagGroup.find(id).description).to eq('after')
|
|
end
|
|
|
|
context 'existing description write protection' do
|
|
let!(:tag) { create(:tag, primary_name: 'protected_description') }
|
|
let!(:page) do
|
|
seed_wiki_page(tag_name: tag.tag_name('ja'), body: 'before', created_by_user: user)
|
|
end
|
|
|
|
[nil, :guest, :banned].each do |role|
|
|
it "rejects #{ role || 'anonymous' } without changing either history" do
|
|
actor = role && create(:user, role == :banned ? :member : role)
|
|
actor.update!(banned_at: Time.current) if role == :banned
|
|
request_headers = actor ? { 'X-Transfer-Code' => actor.inheritance_code } : { }
|
|
before_state = group_state
|
|
put "/wiki/#{ page.id }", params: { title: tag.name('ja'), body: 'after' },
|
|
headers: request_headers
|
|
expect(response).to have_http_status(role ? :forbidden : :unauthorized)
|
|
expect(group_state).to eq(before_state)
|
|
end
|
|
end
|
|
|
|
it 'rejects banned IPs without writes' do
|
|
IpAddress.create!(ip_address: IPAddr.new('127.0.0.1').hton, banned_at: Time.current)
|
|
before_state = group_state
|
|
put "/wiki/#{ page.id }", params: { title: tag.name('ja'), body: 'after' }, headers: headers
|
|
expect(response).to have_http_status(:forbidden)
|
|
expect(group_state).to eq(before_state)
|
|
end
|
|
|
|
['', "\r\n\r\n"].each do |body|
|
|
it "rejects invalid description body #{ body.inspect } atomically" do
|
|
before_state = group_state
|
|
put "/wiki/#{ page.id }", params: { title: tag.name('ja'), body: }, headers: headers
|
|
expect(response).to have_http_status(:unprocessable_entity)
|
|
expect(group_state).to eq(before_state)
|
|
end
|
|
end
|
|
end
|
|
end
|