* added organization policy + spec * user specs for is_org_admin? * added authroize to organization controller * admin policy + specs * deleted enforce admin due to pundit policy redundancy * applied admin policy to entire admin namespace * refactoring analytics controller WIP - wanna test codeship * Add protection against reactions to unpublished articles (#473) * Add chat channel policy and spec (#474) * Add comment policy and specs (#475) * Fix edge case with apostrophes * Add comment policy and specs * Add login for deleting comment spec * Change test to raise pundit error instead of 404 * Clean up comment destroy request specs * Remove redundant raise * Whitelist columns on to_json call (#477) * Add pundit policy for several controllers (#476) * Add pundit policy for several controllers * Adjust video spec * Fix tag request specs * Add proper twilio tokens request specs * Remove puts statements * Add a couple basic request specs (#478) * Add a few tests and fix user tag color bug (#482) * Refactor handle_tag_index in stories_controller (#481) * Modify valid_request_origin? (#483) * Add misc specs and remove banned attribute from user model (#484) * Fix missing Cloudinary tags and misc specs (#486) * removing current_user_is_admin? to use .is_admin? method * added missing org policy routes * Add comment for all public controllers * Fix edge case for test * Authorize mod controller and add specs * Refactor methods via inheritance and use only super_admin role * Create policy method for analytics via article_policy and refactor * Capitalize all buttons in dashboard page * Fix org tests and remove old admin test * Use only happy path for analytics * Fix tests to use Pundit error * Update org_policy spec
47 lines
1.2 KiB
Ruby
47 lines
1.2 KiB
Ruby
require "rails_helper"
|
|
|
|
RSpec.describe OrganizationPolicy do
|
|
subject { described_class.new(user, organization) }
|
|
|
|
let(:organization) { build(:organization) }
|
|
|
|
context "when user is not signed-in" do
|
|
let(:user) { nil }
|
|
|
|
it { within_block_is_expected.to raise_error(Pundit::NotAuthorizedError) }
|
|
end
|
|
|
|
context "when a non-org user" do
|
|
let(:user) { build(:user) }
|
|
|
|
it { is_expected.to forbid_action(:update) }
|
|
it { is_expected.to permit_action(:create) }
|
|
end
|
|
|
|
context "when user is banned" do
|
|
let(:user) { build(:user, :banned) }
|
|
|
|
it { is_expected.to forbid_actions(%i[create update]) }
|
|
end
|
|
|
|
context "when user is an org admin of an org" do
|
|
let(:user) { build(:user) }
|
|
|
|
before { user.update(organization: organization, org_admin: true) }
|
|
|
|
it "allows the user to update their own org" do
|
|
is_expected.to permit_action(:update)
|
|
end
|
|
end
|
|
|
|
context "when user is an org admin of another org" do
|
|
let(:user) { build(:user) }
|
|
let(:new_org) { build(:organization) }
|
|
|
|
before { user.update(organization: new_org, org_admin: true) }
|
|
|
|
it "does not allow the user to update another org" do
|
|
is_expected.to forbid_action(:update)
|
|
end
|
|
end
|
|
end
|