diff options
author | Douglas Barbosa Alexandre <dbalexandre@gmail.com> | 2016-06-22 17:44:24 -0300 |
---|---|---|
committer | Douglas Barbosa Alexandre <dbalexandre@gmail.com> | 2016-06-22 17:44:24 -0300 |
commit | 8f9b64c720d55ee40066d5a6b1017ab95dbd9781 (patch) | |
tree | f7550c3a2353946f7524065ac2919a59ee6867f2 /spec/services/search | |
parent | 1d9bbb0b8ef4d67833fc99a5c6ffcdafa43a38d6 (diff) | |
download | gitlab-ce-8f9b64c720d55ee40066d5a6b1017ab95dbd9781.tar.gz |
Fix internal snippets can be searched by anyone
Diffstat (limited to 'spec/services/search')
-rw-r--r-- | spec/services/search/snippet_service_spec.rb | 37 |
1 files changed, 37 insertions, 0 deletions
diff --git a/spec/services/search/snippet_service_spec.rb b/spec/services/search/snippet_service_spec.rb new file mode 100644 index 00000000000..85721b61cff --- /dev/null +++ b/spec/services/search/snippet_service_spec.rb @@ -0,0 +1,37 @@ +require 'spec_helper' + +describe Search::SnippetService, services: true do + let(:author) { create(:author) } + let(:internal_user) { create(:user) } + + let!(:public_snippet) { create(:snippet, :public, content: 'password: XXX') } + let!(:internal_snippet) { create(:snippet, :internal, content: 'password: XXX') } + let!(:private_snippet) { create(:snippet, :private, content: 'password: XXX', author: author) } + + describe '#execute' do + context 'unauthenticated' do + it 'should return public snippets only' do + search = described_class.new(nil, search: 'password') + results = search.execute + + expect(results.objects('snippet_blobs')).to match_array [public_snippet] + end + end + + context 'authenticated' do + it 'should return only public & internal snippets' do + search = described_class.new(internal_user, search: 'password') + results = search.execute + + expect(results.objects('snippet_blobs')).to match_array [public_snippet, internal_snippet] + end + + it 'should return public, internal and private snippets for author' do + search = described_class.new(author, search: 'password') + results = search.execute + + expect(results.objects('snippet_blobs')).to match_array [public_snippet, internal_snippet, private_snippet] + end + end + end +end |