* spelling: access Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: additional Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: administrative Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: aggregate Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: assigns Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: attributes Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: autocomplete Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: because Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: between Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: bootstrap Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: calculating Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: captcha Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: character Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: chosen Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: commenter Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: competitor Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: componentize Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: contrast Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: corresponding Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: description Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: destroyed Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: destroys Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: discussion Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: episode Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: escaped Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: evaluates Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: expired Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: explicitly Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: facebook Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: fragment Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: functionality Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: improper Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: incentive Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: interfere Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: latest Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: message Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: minimum Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: moderator Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: mouseover Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: mutual Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: nonexistent Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: notification Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: occasionally Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: occurrence Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: occurs Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: octokit Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: offset Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: omitted Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: opacity Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: organization Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: organizations Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: overridden Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: override Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: overriding Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: prefill Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: previous Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: profile Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: recycling Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: registered Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: repositories Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: rescuing Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: response Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: returns Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: second Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: separator Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: services Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: subscriber Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: subscription Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: success Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: successful Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: successfully Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: suppress Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: test Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: thought Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: uniqueness Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: unknown Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: unproductive Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: unreachable Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: unsuccessful Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: utilities Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: utility Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: valid Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: voluntarily Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: vomited Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: website Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> * spelling: withholding Signed-off-by: Josh Soref <jsoref@users.noreply.github.com> Co-authored-by: Josh Soref <jsoref@users.noreply.github.com>
204 lines
5.9 KiB
Ruby
204 lines
5.9 KiB
Ruby
require "rails_helper"
|
|
|
|
RSpec.describe "Authenticating with Twitter" do
|
|
let(:sign_in_link) { "Continue with Twitter" }
|
|
|
|
before do
|
|
omniauth_mock_twitter_payload
|
|
allow(Settings::Authentication).to receive(:providers).and_return(Authentication::Providers.available)
|
|
end
|
|
|
|
context "when a user is new" do
|
|
context "when using valid credentials" do
|
|
it "creates a new user" do
|
|
expect do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
end.to change(User, :count).by(1)
|
|
end
|
|
|
|
it "logs in and redirects to the onboarding" do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
expect(page).to have_current_path("/onboarding?referrer=none")
|
|
expect(page.html).to include("onboarding-container")
|
|
end
|
|
|
|
it "remembers the user" do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
user = User.last
|
|
|
|
expect(user.remember_token).to be_present
|
|
expect(user.remember_created_at).to be_present
|
|
end
|
|
end
|
|
|
|
context "when trying to register with an already existing username" do
|
|
it "creates a new user with a temporary username" do
|
|
username = OmniAuth.config.mock_auth[:twitter].extra.raw_info.username
|
|
user = create(:user, username: username.delete("."))
|
|
|
|
expect do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
end.to change(User, :count).by(1)
|
|
|
|
expect(page).to have_current_path("/onboarding?referrer=none")
|
|
expect(User.last.username).to include(user.username)
|
|
end
|
|
end
|
|
|
|
context "when using invalid credentials" do
|
|
before do
|
|
omniauth_setup_invalid_credentials(:twitter)
|
|
|
|
allow(ForemStatsClient).to receive(:increment)
|
|
end
|
|
|
|
after do
|
|
OmniAuth.config.on_failure = OmniauthHelpers.const_get("OMNIAUTH_DEFAULT_FAILURE_HANDLER")
|
|
end
|
|
|
|
it "does not create a new user" do
|
|
expect do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
end.not_to change(User, :count)
|
|
end
|
|
|
|
it "does not log in" do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
expect(page).to have_current_path("/users/sign_in")
|
|
expect(page).to have_button(sign_in_link)
|
|
end
|
|
|
|
it "notifies Datadog about a callback error" do
|
|
error = OmniAuth::Strategies::OAuth2::CallbackError.new(
|
|
"Callback error", "Error reason", "https://example.com/error"
|
|
)
|
|
|
|
omniauth_setup_authentication_error(error)
|
|
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
args = omniauth_failure_args(error, "twitter", "{}")
|
|
expect(ForemStatsClient).to have_received(:increment).with(
|
|
"omniauth.failure", *args
|
|
)
|
|
end
|
|
|
|
it "notifies Datadog about an OAuth unauthorized error" do
|
|
request = double
|
|
allow(request).to receive(:code).and_return(401)
|
|
allow(request).to receive(:message).and_return("unauthorized")
|
|
error = OAuth::Unauthorized.new(request)
|
|
omniauth_setup_authentication_error(error)
|
|
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
args = omniauth_failure_args(error, "twitter", "{}")
|
|
expect(ForemStatsClient).to have_received(:increment).with(
|
|
"omniauth.failure", *args
|
|
)
|
|
end
|
|
|
|
it "notifies Datadog even with no OmniAuth error present" do
|
|
error = nil
|
|
omniauth_setup_authentication_error(error)
|
|
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
args = omniauth_failure_args(error, "twitter", "{}")
|
|
expect(ForemStatsClient).to have_received(:increment).with(
|
|
"omniauth.failure", *args
|
|
)
|
|
end
|
|
end
|
|
|
|
context "when a validation failure occurs" do
|
|
before do
|
|
# A User is invalid if their name is more than 100 chars long
|
|
OmniAuth.config.mock_auth[:twitter].extra.raw_info.name = "X" * 101
|
|
end
|
|
|
|
it "does not create a new user" do
|
|
expect do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
end.not_to change(User, :count)
|
|
end
|
|
|
|
it "redirects to the registration page" do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
expect(page).to have_current_path("/users/sign_up")
|
|
end
|
|
|
|
it "reports errors" do
|
|
allow(Honeybadger).to receive(:notify)
|
|
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
expect(Honeybadger).to have_received(:notify)
|
|
end
|
|
end
|
|
end
|
|
|
|
context "when a user already exists" do
|
|
let!(:auth_payload) { OmniAuth.config.mock_auth[:twitter] }
|
|
let(:user) { create(:user, :with_identity, identities: [:twitter]) }
|
|
|
|
before do
|
|
auth_payload.info.email = user.email
|
|
end
|
|
|
|
context "when using valid credentials" do
|
|
it "logs in" do
|
|
visit sign_up_path
|
|
click_on(sign_in_link, match: :first)
|
|
|
|
expect(page).to have_current_path("/?signin=true")
|
|
end
|
|
end
|
|
|
|
context "when already signed in" do
|
|
it "redirects to the feed" do
|
|
sign_in user
|
|
visit user_twitter_omniauth_authorize_path
|
|
|
|
expect(page).to have_current_path("/?signin=true")
|
|
end
|
|
|
|
it "renders the twitter icon on the profile" do
|
|
sign_in user
|
|
visit user_twitter_omniauth_authorize_path
|
|
|
|
visit user_profile_path(user.username)
|
|
|
|
expect(page).to have_css("svg.crayons-icon.shrink-0", text: "twitter website")
|
|
end
|
|
end
|
|
end
|
|
|
|
context "when community is in invite-only mode" do
|
|
before do
|
|
allow(ForemInstance).to receive(:invitation_only?).and_return(true)
|
|
end
|
|
|
|
it "doesn't present the authentication option" do
|
|
visit sign_up_path(state: "new-user")
|
|
expect(page).not_to have_text(sign_in_link)
|
|
expect(page).to have_text("invite only")
|
|
end
|
|
end
|
|
end
|