summaryrefslogtreecommitdiff
path: root/spec/policies/releases/source_policy_spec.rb
blob: 1bc6d5415d306abfd6f845a2764e2ee2acd8dfa6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
# frozen_string_literal: true

require 'spec_helper'

describe Releases::SourcePolicy do
  using RSpec::Parameterized::TableSyntax

  let(:policy) { described_class.new(user, source) }

  let_it_be(:public_user) { create(:user) }
  let_it_be(:guest) { create(:user) }
  let_it_be(:reporter) { create(:user) }

  let(:release) { create(:release, project: project) }
  let(:source) { release.sources.first }

  shared_examples 'source code access' do
    it "allows access a release's source code" do
      expect(policy).to be_allowed(:read_release_sources)
    end
  end

  shared_examples 'no source code access' do
    it "does not allow access a release's source code" do
      expect(policy).to be_disallowed(:read_release_sources)
    end
  end

  context 'a private project' do
    let_it_be(:project) { create(:project, :private) }

    context 'accessed by a public user' do
      let(:user) { public_user }

      it_behaves_like 'no source code access'
    end

    context 'accessed by a user with Guest permissions' do
      let(:user) { guest }

      before do
        project.add_guest(user)
      end

      it_behaves_like 'no source code access'
    end

    context 'accessed by a user with Reporter permissions' do
      let(:user) { reporter }

      before do
        project.add_reporter(user)
      end

      it_behaves_like 'source code access'
    end
  end

  context 'a public project' do
    let_it_be(:project) { create(:project, :public) }

    context 'accessed by a public user' do
      let(:user) { public_user }

      it_behaves_like 'source code access'
    end

    context 'accessed by a user with Guest permissions' do
      let(:user) { guest }

      before do
        project.add_guest(user)
      end

      it_behaves_like 'source code access'
    end

    context 'accessed by a user with Reporter permissions' do
      let(:user) { reporter }

      before do
        project.add_reporter(user)
      end

      it_behaves_like 'source code access'
    end
  end
end