debian-mirror-gitlab/spec/requests/api/notes_spec.rb

193 lines
6.4 KiB
Ruby
Raw Normal View History

2014-09-02 18:07:02 +05:30
require 'spec_helper'
2017-08-17 22:00:37 +05:30
describe API::Notes do
2014-09-02 18:07:02 +05:30
let(:user) { create(:user) }
2017-09-10 17:25:29 +05:30
let!(:project) { create(:project, :public, namespace: user.namespace) }
2019-03-02 22:35:43 +05:30
let(:private_user) { create(:user) }
2017-09-10 17:25:29 +05:30
before do
2018-03-17 18:26:18 +05:30
project.add_reporter(user)
2017-09-10 17:25:29 +05:30
end
2014-09-02 18:07:02 +05:30
2019-12-04 20:38:33 +05:30
context 'when there are cross-reference system notes' do
let(:url) { "/projects/#{project.id}/merge_requests/#{merge_request.iid}/notes" }
let(:notes_in_response) { json_response }
it_behaves_like 'with cross-reference system notes'
end
2018-03-27 19:54:05 +05:30
context "when noteable is an Issue" do
let!(:issue) { create(:issue, project: project, author: user) }
let!(:issue_note) { create(:note, noteable: issue, project: project, author: user) }
2018-03-17 18:26:18 +05:30
2018-03-27 19:54:05 +05:30
it_behaves_like "noteable API", 'projects', 'issues', 'iid' do
let(:parent) { project }
let(:noteable) { issue }
let(:note) { issue_note }
end
2018-03-17 18:26:18 +05:30
2018-03-27 19:54:05 +05:30
context 'when user does not have access to create noteable' do
let(:private_issue) { create(:issue, project: create(:project, :private)) }
2018-03-17 18:26:18 +05:30
2018-03-27 19:54:05 +05:30
##
# We are posting to project user has access to, but we use issue id
# from a different project, see #15577
#
before do
post api("/projects/#{private_issue.project.id}/issues/#{private_issue.iid}/notes", user),
2019-02-15 15:39:39 +05:30
params: { body: 'Hi!' }
2018-03-27 19:54:05 +05:30
end
2018-03-17 18:26:18 +05:30
2018-03-27 19:54:05 +05:30
it 'responds with resource not found error' do
expect(response.status).to eq 404
2018-03-17 18:26:18 +05:30
end
2018-03-27 19:54:05 +05:30
it 'does not create new note' do
expect(private_issue.notes.reload).to be_empty
end
end
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
context "when referencing other project" do
# For testing the cross-reference of a private issue in a public project
let(:private_project) do
create(:project, namespace: private_user.namespace)
2018-11-18 11:00:15 +05:30
.tap { |p| p.add_maintainer(private_user) }
2014-09-02 18:07:02 +05:30
end
2019-03-02 22:35:43 +05:30
let(:private_issue) { create(:issue, project: private_project) }
2014-09-02 18:07:02 +05:30
2018-03-27 19:54:05 +05:30
let(:ext_proj) { create(:project, :public) }
let(:ext_issue) { create(:issue, project: ext_proj) }
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
let!(:cross_reference_note) do
create :note,
noteable: ext_issue, project: ext_proj,
note: "mentioned in issue #{private_issue.to_reference(ext_proj)}",
system: true
2014-09-02 18:07:02 +05:30
end
2018-03-27 19:54:05 +05:30
describe "GET /projects/:id/noteable/:noteable_id/notes" do
context "current user cannot view the notes" do
it "returns an empty array" do
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes", user)
2018-03-27 19:54:05 +05:30
expect(response).to have_gitlab_http_status(200)
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
expect(json_response).to be_empty
2017-09-10 17:25:29 +05:30
end
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
context "issue is confidential" do
before do
2018-11-18 11:00:15 +05:30
ext_issue.update(confidential: true)
2018-03-27 19:54:05 +05:30
end
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
it "returns 404" do
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes", user)
expect(response).to have_gitlab_http_status(404)
end
2016-06-02 11:05:42 +05:30
end
end
2018-03-27 19:54:05 +05:30
context "current user can view the note" do
2016-09-13 17:45:13 +05:30
it "returns an empty array" do
2017-08-17 22:00:37 +05:30
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes", private_user)
2016-06-02 11:05:42 +05:30
2018-03-17 18:26:18 +05:30
expect(response).to have_gitlab_http_status(200)
2017-08-17 22:00:37 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
expect(json_response.first['body']).to eq(cross_reference_note.note)
end
end
end
2018-03-17 18:26:18 +05:30
2018-03-27 19:54:05 +05:30
describe "GET /projects/:id/noteable/:noteable_id/notes/:note_id" do
context "current user cannot view the notes" do
it "returns a 404 error" do
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes/#{cross_reference_note.id}", user)
2018-03-17 18:26:18 +05:30
2018-03-27 19:54:05 +05:30
expect(response).to have_gitlab_http_status(404)
2017-09-10 17:25:29 +05:30
end
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
context "when issue is confidential" do
before do
2018-11-18 11:00:15 +05:30
issue.update(confidential: true)
2018-03-27 19:54:05 +05:30
end
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
it "returns 404" do
get api("/projects/#{project.id}/issues/#{issue.iid}/notes/#{issue_note.id}", private_user)
expect(response).to have_gitlab_http_status(404)
end
2016-06-02 11:05:42 +05:30
end
end
2018-03-27 19:54:05 +05:30
context "current user can view the note" do
2016-09-13 17:45:13 +05:30
it "returns an issue note by id" do
2017-08-17 22:00:37 +05:30
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes/#{cross_reference_note.id}", private_user)
2016-06-02 11:05:42 +05:30
2018-03-17 18:26:18 +05:30
expect(response).to have_gitlab_http_status(200)
expect(json_response['body']).to eq(cross_reference_note.note)
end
end
end
2014-09-02 18:07:02 +05:30
end
end
2018-03-27 19:54:05 +05:30
context "when noteable is a Snippet" do
let!(:snippet) { create(:project_snippet, project: project, author: user) }
let!(:snippet_note) { create(:note, noteable: snippet, project: project, author: user) }
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
it_behaves_like "noteable API", 'projects', 'snippets', 'id' do
let(:parent) { project }
let(:noteable) { snippet }
let(:note) { snippet_note }
2014-09-02 18:07:02 +05:30
end
2018-03-27 19:54:05 +05:30
end
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
context "when noteable is a Merge Request" do
let!(:merge_request) { create(:merge_request, source_project: project, target_project: project, author: user) }
let!(:merge_request_note) { create(:note, noteable: merge_request, project: project, author: user) }
2016-06-02 11:05:42 +05:30
2018-03-27 19:54:05 +05:30
it_behaves_like "noteable API", 'projects', 'merge_requests', 'iid' do
let(:parent) { project }
let(:noteable) { merge_request }
let(:note) { merge_request_note }
2016-06-02 11:05:42 +05:30
end
2018-03-17 18:26:18 +05:30
context 'when the merge request discussion is locked' do
before do
merge_request.update_attribute(:discussion_locked, true)
end
context 'when a user is a team member' do
2019-02-15 15:39:39 +05:30
subject { post api("/projects/#{project.id}/merge_requests/#{merge_request.iid}/notes", user), params: { body: 'Hi!' } }
2018-03-17 18:26:18 +05:30
it 'returns 200 status' do
subject
expect(response).to have_gitlab_http_status(201)
end
it 'creates a new note' do
expect { subject }.to change { Note.count }.by(1)
end
end
context 'when a user is not a team member' do
2019-02-15 15:39:39 +05:30
subject { post api("/projects/#{project.id}/merge_requests/#{merge_request.iid}/notes", private_user), params: { body: 'Hi!' } }
2018-03-17 18:26:18 +05:30
it 'returns 403 status' do
subject
expect(response).to have_gitlab_http_status(403)
end
it 'does not create a new note' do
expect { subject }.not_to change { Note.count }
end
end
end
2014-09-02 18:07:02 +05:30
end
end