diff options
author | Robert Schilling <rschilling@student.tugraz.at> | 2016-04-13 12:10:12 +0200 |
---|---|---|
committer | Robert Schilling <rschilling@student.tugraz.at> | 2016-04-13 12:10:12 +0200 |
commit | 4cd04443f5f69665ce1139726751af678e0e55c3 (patch) | |
tree | 1cba028dc6553034cde35be345ac3835944e2686 | |
parent | ca40479c512f327c12adf51b47be46d75e4e333c (diff) | |
download | gitlab-ce-4cd04443f5f69665ce1139726751af678e0e55c3.tar.gz |
Fix group_member_spec to not leak information
-rw-r--r-- | spec/requests/api/group_members_spec.rb | 12 |
1 files changed, 7 insertions, 5 deletions
diff --git a/spec/requests/api/group_members_spec.rb b/spec/requests/api/group_members_spec.rb index 3e8b4aa1f88..96d89e69209 100644 --- a/spec/requests/api/group_members_spec.rb +++ b/spec/requests/api/group_members_spec.rb @@ -42,9 +42,10 @@ describe API::API, api: true do end end - it "users not part of the group should get access error" do + it 'users not part of the group should get access error' do get api("/groups/#{group_with_members.id}/members", stranger) - expect(response.status).to eq(403) + + expect(response.status).to eq(404) end end end @@ -165,12 +166,13 @@ describe API::API, api: true do end end - describe "DELETE /groups/:id/members/:user_id" do - context "when not a member of the group" do + describe 'DELETE /groups/:id/members/:user_id' do + context 'when not a member of the group' do it "should not delete guest's membership of group_with_members" do random_user = create(:user) delete api("/groups/#{group_with_members.id}/members/#{owner.id}", random_user) - expect(response.status).to eq(403) + + expect(response.status).to eq(404) end end |