summaryrefslogtreecommitdiff
path: root/spec/requests/api/pages/public_access_spec.rb
blob: 882ca26ac51bcf33c5571e6052d759e4771ae132 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
require 'spec_helper'

describe "Public Project Pages Access"  do
  using RSpec::Parameterized::TableSyntax
  include AccessMatchers

  set(:group) { create(:group) }
  set(:project) { create(:project, :public, pages_access_level: ProjectFeature::ENABLED, namespace: group) }

  set(:admin) { create(:admin) }
  set(:owner) { create(:user) }
  set(:master) { create(:user) }
  set(:developer) { create(:user) }
  set(:reporter) { create(:user) }
  set(:guest) { create(:user) }
  set(:user) { create(:user) }

  before do
    allow(Gitlab.config.pages).to receive(:access_control).and_return(true)
    group.add_owner(owner)
    project.add_master(master)
    project.add_developer(developer)
    project.add_reporter(reporter)
    project.add_guest(guest)
  end

  describe "Project should be public" do
    describe '#public?' do
      subject { project.public? }
      it { is_expected.to be_truthy }
    end
  end

  describe "GET /projects/:id/pages_access" do
    context 'access depends on the level' do
      where(:pages_access_level, :with_user, :expected_result) do
        ProjectFeature::DISABLED   |   "admin"     |  403
        ProjectFeature::DISABLED   |   "owner"     |  403
        ProjectFeature::DISABLED   |   "master"    |  403
        ProjectFeature::DISABLED   |   "developer" |  403
        ProjectFeature::DISABLED   |   "reporter"  |  403
        ProjectFeature::DISABLED   |   "guest"     |  403
        ProjectFeature::DISABLED   |   "user"      |  403
        ProjectFeature::DISABLED   |   nil         |  403
        ProjectFeature::PUBLIC     |   "admin"     |  200
        ProjectFeature::PUBLIC     |   "owner"     |  200
        ProjectFeature::PUBLIC     |   "master"    |  200
        ProjectFeature::PUBLIC     |   "developer" |  200
        ProjectFeature::PUBLIC     |   "reporter"  |  200
        ProjectFeature::PUBLIC     |   "guest"     |  200
        ProjectFeature::PUBLIC     |   "user"      |  200
        ProjectFeature::PUBLIC     |   nil         |  200
        ProjectFeature::ENABLED    |   "admin"     |  200
        ProjectFeature::ENABLED    |   "owner"     |  200
        ProjectFeature::ENABLED    |   "master"    |  200
        ProjectFeature::ENABLED    |   "developer" |  200
        ProjectFeature::ENABLED    |   "reporter"  |  200
        ProjectFeature::ENABLED    |   "guest"     |  200
        ProjectFeature::ENABLED    |   "user"      |  200
        ProjectFeature::ENABLED    |   nil         |  200
        ProjectFeature::PRIVATE    |   "admin"     |  200
        ProjectFeature::PRIVATE    |   "owner"     |  200
        ProjectFeature::PRIVATE    |   "master"    |  200
        ProjectFeature::PRIVATE    |   "developer" |  200
        ProjectFeature::PRIVATE    |   "reporter"  |  200
        ProjectFeature::PRIVATE    |   "guest"     |  200
        ProjectFeature::PRIVATE    |   "user"      |  403
        ProjectFeature::PRIVATE    |   nil         |  403
      end

      with_them do
        before do
          project.project_feature.update(pages_access_level: pages_access_level)
        end
        it "correct return value" do
          if !with_user.nil?
            user = public_send(with_user)
            get api("/projects/#{project.id}/pages_access", user)
          else
            get api("/projects/#{project.id}/pages_access")
          end

          expect(response).to have_gitlab_http_status(expected_result)
        end
      end
    end
  end
end