From 08a8aa66ef41708976c27734587fc06e489a134f Mon Sep 17 00:00:00 2001 From: GitLab Bot Date: Wed, 10 Feb 2021 23:15:38 +0000 Subject: Add latest changes from gitlab-org/security/gitlab@13-8-stable-ee --- .../requests/api/merge_requests_shared_examples.rb | 23 ++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 spec/support/shared_examples/requests/api/merge_requests_shared_examples.rb (limited to 'spec/support') diff --git a/spec/support/shared_examples/requests/api/merge_requests_shared_examples.rb b/spec/support/shared_examples/requests/api/merge_requests_shared_examples.rb new file mode 100644 index 00000000000..e6f9e5a434c --- /dev/null +++ b/spec/support/shared_examples/requests/api/merge_requests_shared_examples.rb @@ -0,0 +1,23 @@ +# frozen_string_literal: true + +RSpec.shared_examples 'rejects user from accessing merge request info' do + let(:project) { create(:project, :private) } + let(:merge_request) do + create(:merge_request, + author: user, + source_project: project, + target_project: project + ) + end + + before do + project.add_guest(user) + end + + it 'returns a 404 error' do + get api(url, user) + + expect(response).to have_gitlab_http_status(:not_found) + expect(json_response['message']).to eq('404 Merge Request Not Found') + end +end -- cgit v1.2.1