Skip to content

Commit 5504508

Browse files
committed
test(contributors_controller): cover unauthorized plan access
Add specs for the contributors index and new endpoints to ensure unauthorized plans are denied access.
1 parent 22c392d commit 5504508

1 file changed

Lines changed: 39 additions & 12 deletions

File tree

‎spec/controllers/contributors_controller_spec.rb‎

Lines changed: 39 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
@scheme = create(:identifier_scheme, name: 'orcid')
88
@org = create(:org, managed: true)
99
@plan = create(:plan, :creator, org: @org)
10+
@unauthorized_plan = create(:plan)
1011
@user = @plan.owner
1112
@contributor = create(:contributor, plan: @plan, org: @org)
1213

@@ -36,20 +37,46 @@
3637
sign_in(@user)
3738
end
3839

39-
it 'GET plans/:plan_id/contributors (:index)' do
40-
get :index, params: { plan_id: @plan.id }
41-
expect(response).to render_template(:index)
42-
expect(assigns(:plan)).to eql(@plan)
43-
expect(assigns(:contributors).length).to eql(1)
44-
expect(assigns(:contributors).first).to eql(@contributor)
40+
describe 'GET plans/:plan_id/contributors (:index)' do
41+
it 'renders the index' do
42+
get :index, params: { plan_id: @plan.id }
43+
expect(response).to render_template(:index)
44+
expect(assigns(:plan)).to eql(@plan)
45+
expect(assigns(:contributors).length).to eql(1)
46+
expect(assigns(:contributors).first).to eql(@contributor)
47+
end
48+
49+
it 'denies access to an unauthorized plan' do
50+
get :index, params: { plan_id: @unauthorized_plan.id }
51+
52+
expect(response).not_to render_template(:index)
53+
expect(assigns(:contributors)).to eql(nil)
54+
55+
expect(response).to have_http_status(:redirect)
56+
expect(response).to redirect_to(plans_url)
57+
expect(flash[:alert]).to eq('You are not authorized to perform this action.')
58+
end
4559
end
4660

47-
it 'GET plans/:plan_id/contributors/new (:new)' do
48-
get :new, params: { plan_id: @plan.id }
49-
expect(response).to render_template(:new)
50-
expect(assigns(:plan)).to eql(@plan)
51-
expect(assigns(:contributor).new_record?).to eql(true)
52-
expect(assigns(:contributor).plan).to eql(@plan)
61+
describe 'GET plans/:plan_id/contributors/new (:new)' do
62+
it 'renders the new form' do
63+
get :new, params: { plan_id: @plan.id }
64+
expect(response).to render_template(:new)
65+
expect(assigns(:plan)).to eql(@plan)
66+
expect(assigns(:contributor).new_record?).to eql(true)
67+
expect(assigns(:contributor).plan).to eql(@plan)
68+
end
69+
70+
it 'denies access to an unauthorized plan' do
71+
get :new, params: { plan_id: @unauthorized_plan.id }
72+
73+
expect(response).not_to render_template(:new)
74+
expect(assigns(:contributor)).to eql(nil)
75+
76+
expect(response).to have_http_status(:redirect)
77+
expect(response).to redirect_to(plans_url)
78+
expect(flash[:alert]).to eq('You are not authorized to perform this action.')
79+
end
5380
end
5481

5582
it 'GET plans/:plan_id/contributors/:id/edit (:edit)' do

0 commit comments

Comments
 (0)