docbrown/spec/requests/api_secrets_create_spec.rb
Andy Zhao b2e18aeb72 Use Redis for session storage (#4004) [deploy]
* WIP use redis-session-store for sessions

* Use Redis as session storage

* Add redis-server to Travis

* Use integer for SESSION_EXPIRY_SECONDS env variable

Co-Authored-By: rhymes <rhymesete@gmail.com>

* Remove sessions b/c no custom sessions logic

* Use ApplicationConfig instead

* Rename default value

* Remove rememberable module

* Persist the user for the test

* Remove remember_me related tests

* Revert 'undo remember_me' commits

* Add redis to procfile

* Cleanup devise configuration

* Move REDIS configuration in the basic configuration section

* Make sure the expiration time can't zero

* Restore old order and remove useless comment line

* Delete legacy session cookie after login

Once deployed the server will start using the new session cookie, this makes sure the legacy one is deleted on the user's browser

* Remove redis from Procfile

* Add signed, secure and httponly to the Redis session cookie
2019-11-12 10:10:34 -06:00

44 lines
1.4 KiB
Ruby

require "rails_helper"
RSpec.describe "ApiSecretsCreate", type: :request do
let(:user) { create(:user) }
before { sign_in user }
describe "POST /users/api_secrets" do
context "when create succeeds" do
let(:valid_params) { { description: "My Test 3rd Party App" } }
it "creates an ApiSecret for the user" do
expect { post "/users/api_secrets", params: { api_secret: valid_params } }.
to change { user.api_secrets.count }.by 1
end
it "sets the description" do
post "/users/api_secrets", params: { api_secret: valid_params }
expect(user.api_secrets.last.description).to eq valid_params[:description]
end
it "flashes a message containing the token" do
post "/users/api_secrets", params: { api_secret: valid_params }
expect(flash[:notice]).to include(ApiSecret.last.secret)
expect(flash[:error]).to be_nil
end
end
context "when create fails" do
let(:invalid_params) { { description: nil } } # Force model validation error
it "does not create the ApiSecret" do
expect { post "/users/api_secrets", params: { api_secret: invalid_params } }.
not_to(change { user.api_secrets.count })
end
it "flashes an error message" do
post "/users/api_secrets", params: { api_secret: invalid_params }
expect(flash[:error]).to be_truthy
expect(flash[:notice]).to be_nil
end
end
end
end