From 8f9b64c720d55ee40066d5a6b1017ab95dbd9781 Mon Sep 17 00:00:00 2001 From: Douglas Barbosa Alexandre Date: Wed, 22 Jun 2016 17:44:24 -0300 Subject: Fix internal snippets can be searched by anyone --- spec/models/snippet_spec.rb | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) (limited to 'spec/models') diff --git a/spec/models/snippet_spec.rb b/spec/models/snippet_spec.rb index 789816bf2c7..57365571a7b 100644 --- a/spec/models/snippet_spec.rb +++ b/spec/models/snippet_spec.rb @@ -72,7 +72,7 @@ describe Snippet, models: true do end end - describe '#search_code' do + describe '.search_code' do let(:snippet) { create(:snippet, content: 'class Foo; end') } it 'returns snippets with matching content' do @@ -88,6 +88,26 @@ describe Snippet, models: true do end end + describe '.accessible_to' do + let(:author) { create(:author) } + let(:user) { create(:user) } + let!(:public_snippet) { create(:snippet, :public) } + let!(:internal_snippet) { create(:snippet, :internal) } + let!(:private_snippet) { create(:snippet, :private, author: author) } + + it 'returns only public snippets when user is nil' do + expect(described_class.accessible_to(nil)).to eq [public_snippet] + end + + it 'returns only public, and internal snippets when user is not nil' do + expect(described_class.accessible_to(user)).to match_array [public_snippet, internal_snippet] + end + + it 'returns snippets where the user is the author' do + expect(described_class.accessible_to(author)).to match_array [public_snippet, internal_snippet, private_snippet] + end + end + describe '#participants' do let(:project) { create(:project, :public) } let(:snippet) { create(:snippet, content: 'foo', project: project) } -- cgit v1.2.1 From 256cd8e498edfcbb8199abfb2b54d2d2905f030e Mon Sep 17 00:00:00 2001 From: Douglas Barbosa Alexandre Date: Wed, 22 Jun 2016 19:29:40 -0300 Subject: Fix visibility of private project snippets for members when searching --- spec/models/snippet_spec.rb | 36 ++++++++++++++++++++++++++++-------- 1 file changed, 28 insertions(+), 8 deletions(-) (limited to 'spec/models') diff --git a/spec/models/snippet_spec.rb b/spec/models/snippet_spec.rb index 57365571a7b..0621c6a06ce 100644 --- a/spec/models/snippet_spec.rb +++ b/spec/models/snippet_spec.rb @@ -89,22 +89,42 @@ describe Snippet, models: true do end describe '.accessible_to' do - let(:author) { create(:author) } - let(:user) { create(:user) } + let(:author) { create(:author) } + let(:project) { create(:empty_project) } + let!(:public_snippet) { create(:snippet, :public) } let!(:internal_snippet) { create(:snippet, :internal) } let!(:private_snippet) { create(:snippet, :private, author: author) } - it 'returns only public snippets when user is nil' do - expect(described_class.accessible_to(nil)).to eq [public_snippet] + let!(:project_public_snippet) { create(:snippet, :public, project: project) } + let!(:project_internal_snippet) { create(:snippet, :internal, project: project) } + let!(:project_private_snippet) { create(:snippet, :private, project: project) } + + it 'returns only public snippets when user is blank' do + expect(described_class.accessible_to(nil)).to match_array [public_snippet, project_public_snippet] + end + + it 'returns only public, and internal snippets for regular users' do + user = create(:user) + + expect(described_class.accessible_to(user)).to match_array [public_snippet, internal_snippet, project_public_snippet, project_internal_snippet] end - it 'returns only public, and internal snippets when user is not nil' do - expect(described_class.accessible_to(user)).to match_array [public_snippet, internal_snippet] + it 'returns public, internal snippets and project private snippets for project members' do + member = create(:user) + project.team << [member, :developer] + + expect(described_class.accessible_to(member)).to match_array [public_snippet, internal_snippet, project_public_snippet, project_internal_snippet, project_private_snippet] end - it 'returns snippets where the user is the author' do - expect(described_class.accessible_to(author)).to match_array [public_snippet, internal_snippet, private_snippet] + it 'returns private snippets where the user is the author' do + expect(described_class.accessible_to(author)).to match_array [public_snippet, internal_snippet, private_snippet, project_public_snippet, project_internal_snippet] + end + + it 'returns all snippets when for admins' do + admin = create(:admin) + + expect(described_class.accessible_to(admin)).to match_array [public_snippet, internal_snippet, private_snippet, project_public_snippet, project_internal_snippet, project_private_snippet] end end -- cgit v1.2.1