docbrown/spec/support/shared_examples/api_analytics.rb
rhymes 7ff882b8ce
Refactor Admin Member Detail view - Tools section (#14283)
* Test with Grid layout

* Use Flexbox

* Replace with utility classes

* Wire up Tools -> Emails

* Stash: will rebase with a better commit message

* Fix transition between Email and Tools component

* Refactor Verify Email Ownership button a bit

* Use respond_to for verify_email_ownership

* Wrap the Preact Snackbar controller in Stimulus and use it from users/tools/email_controller

* Add HTML5 validation to EmailComponent

* Validation and cleanup

* Add Email history list and fix styling

* Additional styling cleanups

* Add error handling

* Close panel after email operations

* Actually use <local-time> GitHub time element correctly

* Add specs for Tools component and controller

* Email to Emails

* Add tests for Admin::Users::Tools::EmailsComponent

* Fix bug with ToolsComponent instantiation in ToolsController

* Add notes to show page

* Add ToolsComponent css

* Use Rails UJS instead of manual Stimulus to connect remote helpers

* Make Notes section come alive by adding its code

* Make Credits section come alive by adding its code

* Go back to vertical flex

* Finalize small restructuring of credits code

* Simplify ToolsComponent instantiation

* Add basic Add user to org functionality

* Make update user permissions form work

* Make remove user from org work

* Use generic Stimulus AjaxController to cleanup code

* Use Stimulus AjaxController for NotesComponent

* Use Stimulus AjaxController for CreditsComponent

* Use Stimulus AjaxController for OrganizationsController

* Add Admin::Users::Tools::ReportsComponent

* Do not display snackbar message if there is no message

* Add Admin::Users::Tools::ReactionsComponent

* Fix EmailsComponent spec

* Add CreditsComponent tests

* Fix quotes

* Add OrganizationsComponent specs

* Add ReportsComponent spec

* Add ReactionsComponent spec

* Fix rubocop violation

* Fix ToolsComponent specs

* Remove unused variable

* More tests

* Use keyword argument for ToolsComponent

* Fill in Tools requests specs

* Use Rspec shared_examples for ToolsController and EmailsController

* Add tests for Admin::Users::Tools::CreditsController

* Add tests for Admin::Users::Tools::NotesController

* Add tests for Admin::Users::Tools::OrganizationsController

* Add tests for Admin::Users::Tools::ReactionsController and ReportsController

* Fix bugs and add tests to Admin::OrganizationMembershipsController

* Add comments to deprecated sections of the UsersController

* Fix bugs and add tests to Admin::UsersController #send_email and #verify_email_ownership

* Add User model tests

* Feature flag fixes

* Add Cypress Tools - Emails tests

* Add Cypress Tools - Notes tests

* Add Cypress Tools - Credits tests

* Add Cypress Tools - Organizations tests

* Add Cypress Tools - Reports and Reactions tests

* Mark the replace target as a polite region

* Update view_component gem

* Tiny fixes

* Fix spec

* Wrap component rendering in render_component

* Move user.related_negative_reactions to a Reaction scope

* Move user.reports to a FeedbackMessage scope

* Move user.last_verification_date as EmailAuthorization class method

* Revert encapsulation to private

* Fix boxes backlinks names

* Add keyboard focus styling to boxes

* Remove duplicate styling

* Remove duplicated header element

* Improve heading hiearchy

* Fix <legend> and labels

* Backlink should be Tools not Users

* Announce section change to screen reader and fix focus

* Fix specs

* Add focus style for backlinks

* Enable email sending in e2e mode

* Use Settings instead of env variable
2021-08-17 18:55:53 +02:00

98 lines
3.6 KiB
Ruby

RSpec.shared_examples "GET /api/analytics/:endpoint authorization examples" do |endpoint, params|
let(:user) { create(:user) }
let(:api_token) { create(:api_secret, user: user) }
let(:org_member) { create(:user, :org_member) }
let(:org_member_token) { create(:api_secret, user: org_member) }
let(:org) { org_member.organizations.first }
let(:article) { create(:article, user: user) }
let(:user_article) { create(:article, user: user) }
let(:org_article) { create(:article, user: user, organization: org) }
context "when an invalid token is given" do
before { get "/api/analytics/#{endpoint}?#{params}", headers: { "api-key" => "abadskajdlsak" } }
it "renders an error message: 'unauthorized' in JSON" do
expect(response.parsed_body).to include("error" => "unauthorized")
end
it "has a status 401" do
expect(response).to have_http_status(:unauthorized)
end
end
context "when a valid token is given" do
before { get "/api/analytics/#{endpoint}?#{params}", headers: { "api-key" => api_token.secret } }
it "renders JSON as the content type" do
expect(response.media_type).to eq "application/json"
end
end
context "when attempting to view organization analytics without belonging to the organization" do
before do
headers = { "api-key" => api_token.secret }
get "/api/analytics/#{endpoint}?organization_id=#{org.id}#{params}", headers: headers
end
it "renders an error message: 'unauthorized' in JSON" do
expect(response.parsed_body).to include("error" => "unauthorized")
end
it "has a status 401" do
expect(response).to have_http_status(:unauthorized)
end
end
context "when attempting to view organization analytics and being a member of the organization" do
before do
path = "/api/analytics/#{endpoint}?organization_id=#{org_member.organization_ids.first}#{params}"
get path, headers: { "api-key" => org_member_token.secret }
end
it "renders JSON as the content type" do
expect(response.media_type).to eq "application/json"
end
end
context "when attempting to view another organization analytics and not belonging to that organization" do
it "responds with status 401 unauthorized" do
org = create(:organization)
headers = { "api-key" => org_member_token.secret }
get "/api/analytics/#{endpoint}?organization_id=#{org.id}#{params}", headers: headers
expect(response).to have_http_status(:unauthorized)
end
end
context "when attempting to view someone else's article analytics" do
it "responds with status 401 unauthorized" do
get "/api/analytics/#{endpoint}?article_id=#{article.id}#{params}"
expect(response).to have_http_status(:unauthorized)
end
end
context "when viewing as current user" do
it "responds with status 200 OK" do
sign_in user
get "/api/analytics/#{endpoint}?#{params}"
expect(response).to have_http_status(:ok)
end
end
context "when viewing your own single article's analytics" do
it "responds with status 200 OK" do
sign_in user
get "/api/analytics/#{endpoint}?article_id=#{user_article.id}#{params}"
expect(response).to have_http_status(:ok)
end
end
context "when viewing your own organizaiton's single article's analytics" do
it "responds with status 200 OK" do
org_param = "&organization_id=#{org_article.organization.id}"
sign_in org_member
get "/api/analytics/#{endpoint}?article_id=#{org_article.id}#{params}#{org_param}"
expect(response).to have_http_status(:ok)
end
end
end