docbrown/spec
Jeremy Friesen 4509e81dd5
Ensuring the same policies for analytics (#16997)
Prior to this commit the following situation existed:

> The path /dashboard/analytics/org/:id requires user
> authentication (e.g. signed in). However, it does not enforce
> authorization. Anyone can see this page. The page, however, uses
> javascript to populate the data. So no information, aside from the org
> name associated with the :id leaks out. The javascript API end point
> enforces organization membership.
>
> I would expect that the authorization in the HTML rendering would be
> the same as the javascript API end point.

This commit ensures that the dashboards#analytics end point uses the
same policy logic as the API analytics end points.  Further, it keeps
folks who aren't org members out of the base HTML page for other orgs.

Closes forem/forem/#16985
2022-03-25 14:57:01 -04:00
..
controllers/concerns 15 minute fix: Add default argument to JsonApiSortParam (#13369) 2021-04-14 10:32:07 +07:00
decorators Routine Rubocop fixes (#16838) 2022-03-09 09:32:50 -05:00
factories Always show the browse section of podcasts regardless of featured (#16329) 2022-03-22 12:56:54 -04:00
fixtures Remove duplicated work display from header / profile work (#14210) 2021-07-30 12:28:40 +02:00
forms Routine Rubocop fixes (#16838) 2022-03-09 09:32:50 -05:00
generator Add service generator (#11265) 2020-11-10 09:09:35 +07:00
helpers Routine Rubocop fixes (#16838) 2022-03-09 09:32:50 -05:00
initializers A suspended user returns 403 instead of 500 (#16408) 2022-02-04 09:42:23 -05:00
lib Remove fastly http purge feature flag and conditional behavior (#16903) 2022-03-18 09:10:43 -05:00
liquid_tags youtube tag timestamp format fix (#16873) 2022-03-22 08:55:45 -06:00
mailers "Reply to" and "From" Email addresses for SMTP Configurations (#16499) 2022-02-16 16:14:54 +02:00
models Fix redundant slack notifications when article was published (#16977) 2022-03-24 09:59:01 +03:00
policies Ensuring the same policies for analytics (#16997) 2022-03-25 14:57:01 -04:00
queries Fixes a name conflict in Rpush models (#15978) 2022-01-07 09:38:16 -06:00
refinements Update data exporter to handle admin send (#10274) 2020-10-26 18:00:56 -04:00
requests Ensuring the same policies for analytics (#16997) 2022-03-25 14:57:01 -04:00
routing Scoping the :listing routes to feature (#16406) 2022-02-04 10:13:56 -05:00
sanitizers Don't sanitize anchor elements with no href (#16667) 2022-02-22 11:27:38 -06:00
serializers Refactoring to add helper method (#16064) 2022-01-12 11:21:44 -05:00
services Match error class using case instead of if/elsif/else (#16952) 2022-03-21 15:34:49 -05:00
support Fix embed link validation failures (#16920) 2022-03-18 14:45:43 -04:00
system Always show the browse section of podcasts regardless of featured (#16329) 2022-03-22 12:56:54 -04:00
tasks Make home link an admin-customisable navigation link (#16268) 2022-02-01 09:27:09 +00:00
uploaders Remove Remaining logo_svg Code (#16291) 2022-02-22 12:05:16 -07:00
validators Don't raise error when empty community emoji setting submitted (#15723) 2021-12-17 09:29:55 -06:00
view_objects Patching ERB rendering of the data-info JSON (#16067) 2022-01-14 08:30:49 -05:00
views Always show the browse section of podcasts regardless of featured (#16329) 2022-03-22 12:56:54 -04:00
workers Limit per-user feed import fanout to users with feed urls set (#16831) 2022-03-09 08:51:00 -06:00
i18n_spec.rb Show missing translation keys when test fails (#16637) 2022-02-17 16:21:29 -06:00
rails_helper.rb Removing a JS message about connect (#16982) 2022-03-23 12:30:59 -04:00
spec_helper.rb Theme data update script, remove theme choices from UI (#15225) 2021-11-08 08:38:43 -05:00