* Test with Grid layout * Use Flexbox * Replace with utility classes * Wire up Tools -> Emails * Stash: will rebase with a better commit message * Fix transition between Email and Tools component * Refactor Verify Email Ownership button a bit * Use respond_to for verify_email_ownership * Wrap the Preact Snackbar controller in Stimulus and use it from users/tools/email_controller * Add HTML5 validation to EmailComponent * Validation and cleanup * Add Email history list and fix styling * Additional styling cleanups * Add error handling * Close panel after email operations * Actually use <local-time> GitHub time element correctly * Add specs for Tools component and controller * Email to Emails * Add tests for Admin::Users::Tools::EmailsComponent * Fix bug with ToolsComponent instantiation in ToolsController * Add notes to show page * Add ToolsComponent css * Use Rails UJS instead of manual Stimulus to connect remote helpers * Make Notes section come alive by adding its code * Make Credits section come alive by adding its code * Go back to vertical flex * Finalize small restructuring of credits code * Simplify ToolsComponent instantiation * Add basic Add user to org functionality * Make update user permissions form work * Make remove user from org work * Use generic Stimulus AjaxController to cleanup code * Use Stimulus AjaxController for NotesComponent * Use Stimulus AjaxController for CreditsComponent * Use Stimulus AjaxController for OrganizationsController * Add Admin::Users::Tools::ReportsComponent * Do not display snackbar message if there is no message * Add Admin::Users::Tools::ReactionsComponent * Fix EmailsComponent spec * Add CreditsComponent tests * Fix quotes * Add OrganizationsComponent specs * Add ReportsComponent spec * Add ReactionsComponent spec * Fix rubocop violation * Fix ToolsComponent specs * Remove unused variable * More tests * Use keyword argument for ToolsComponent * Fill in Tools requests specs * Use Rspec shared_examples for ToolsController and EmailsController * Add tests for Admin::Users::Tools::CreditsController * Add tests for Admin::Users::Tools::NotesController * Add tests for Admin::Users::Tools::OrganizationsController * Add tests for Admin::Users::Tools::ReactionsController and ReportsController * Fix bugs and add tests to Admin::OrganizationMembershipsController * Add comments to deprecated sections of the UsersController * Fix bugs and add tests to Admin::UsersController #send_email and #verify_email_ownership * Add User model tests * Feature flag fixes * Add Cypress Tools - Emails tests * Add Cypress Tools - Notes tests * Add Cypress Tools - Credits tests * Add Cypress Tools - Organizations tests * Add Cypress Tools - Reports and Reactions tests * Mark the replace target as a polite region * Update view_component gem * Tiny fixes * Fix spec * Wrap component rendering in render_component * Move user.related_negative_reactions to a Reaction scope * Move user.reports to a FeedbackMessage scope * Move user.last_verification_date as EmailAuthorization class method * Revert encapsulation to private * Fix boxes backlinks names * Add keyboard focus styling to boxes * Remove duplicate styling * Remove duplicated header element * Improve heading hiearchy * Fix <legend> and labels * Backlink should be Tools not Users * Announce section change to screen reader and fix focus * Fix specs * Add focus style for backlinks * Enable email sending in e2e mode * Use Settings instead of env variable
98 lines
3.6 KiB
Ruby
98 lines
3.6 KiB
Ruby
RSpec.shared_examples "GET /api/analytics/:endpoint authorization examples" do |endpoint, params|
|
|
let(:user) { create(:user) }
|
|
let(:api_token) { create(:api_secret, user: user) }
|
|
let(:org_member) { create(:user, :org_member) }
|
|
let(:org_member_token) { create(:api_secret, user: org_member) }
|
|
let(:org) { org_member.organizations.first }
|
|
let(:article) { create(:article, user: user) }
|
|
let(:user_article) { create(:article, user: user) }
|
|
let(:org_article) { create(:article, user: user, organization: org) }
|
|
|
|
context "when an invalid token is given" do
|
|
before { get "/api/analytics/#{endpoint}?#{params}", headers: { "api-key" => "abadskajdlsak" } }
|
|
|
|
it "renders an error message: 'unauthorized' in JSON" do
|
|
expect(response.parsed_body).to include("error" => "unauthorized")
|
|
end
|
|
|
|
it "has a status 401" do
|
|
expect(response).to have_http_status(:unauthorized)
|
|
end
|
|
end
|
|
|
|
context "when a valid token is given" do
|
|
before { get "/api/analytics/#{endpoint}?#{params}", headers: { "api-key" => api_token.secret } }
|
|
|
|
it "renders JSON as the content type" do
|
|
expect(response.media_type).to eq "application/json"
|
|
end
|
|
end
|
|
|
|
context "when attempting to view organization analytics without belonging to the organization" do
|
|
before do
|
|
headers = { "api-key" => api_token.secret }
|
|
get "/api/analytics/#{endpoint}?organization_id=#{org.id}#{params}", headers: headers
|
|
end
|
|
|
|
it "renders an error message: 'unauthorized' in JSON" do
|
|
expect(response.parsed_body).to include("error" => "unauthorized")
|
|
end
|
|
|
|
it "has a status 401" do
|
|
expect(response).to have_http_status(:unauthorized)
|
|
end
|
|
end
|
|
|
|
context "when attempting to view organization analytics and being a member of the organization" do
|
|
before do
|
|
path = "/api/analytics/#{endpoint}?organization_id=#{org_member.organization_ids.first}#{params}"
|
|
get path, headers: { "api-key" => org_member_token.secret }
|
|
end
|
|
|
|
it "renders JSON as the content type" do
|
|
expect(response.media_type).to eq "application/json"
|
|
end
|
|
end
|
|
|
|
context "when attempting to view another organization analytics and not belonging to that organization" do
|
|
it "responds with status 401 unauthorized" do
|
|
org = create(:organization)
|
|
headers = { "api-key" => org_member_token.secret }
|
|
get "/api/analytics/#{endpoint}?organization_id=#{org.id}#{params}", headers: headers
|
|
expect(response).to have_http_status(:unauthorized)
|
|
end
|
|
end
|
|
|
|
context "when attempting to view someone else's article analytics" do
|
|
it "responds with status 401 unauthorized" do
|
|
get "/api/analytics/#{endpoint}?article_id=#{article.id}#{params}"
|
|
expect(response).to have_http_status(:unauthorized)
|
|
end
|
|
end
|
|
|
|
context "when viewing as current user" do
|
|
it "responds with status 200 OK" do
|
|
sign_in user
|
|
get "/api/analytics/#{endpoint}?#{params}"
|
|
expect(response).to have_http_status(:ok)
|
|
end
|
|
end
|
|
|
|
context "when viewing your own single article's analytics" do
|
|
it "responds with status 200 OK" do
|
|
sign_in user
|
|
get "/api/analytics/#{endpoint}?article_id=#{user_article.id}#{params}"
|
|
expect(response).to have_http_status(:ok)
|
|
end
|
|
end
|
|
|
|
context "when viewing your own organizaiton's single article's analytics" do
|
|
it "responds with status 200 OK" do
|
|
org_param = "&organization_id=#{org_article.organization.id}"
|
|
|
|
sign_in org_member
|
|
get "/api/analytics/#{endpoint}?article_id=#{org_article.id}#{params}#{org_param}"
|
|
expect(response).to have_http_status(:ok)
|
|
end
|
|
end
|
|
end
|