debian-mirror-gitlab/spec/services/groups/group_links/create_service_spec.rb

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

179 lines
5.3 KiB
Ruby
Raw Normal View History

2019-12-26 22:10:19 +05:30
# frozen_string_literal: true
require 'spec_helper'
2020-07-28 23:09:34 +05:30
RSpec.describe Groups::GroupLinks::CreateService, '#execute' do
2022-07-16 23:28:13 +05:30
let_it_be(:shared_with_group_parent) { create(:group, :private) }
let_it_be(:shared_with_group) { create(:group, :private, parent: shared_with_group_parent) }
let_it_be(:shared_with_group_child) { create(:group, :private, parent: shared_with_group) }
2019-12-26 22:10:19 +05:30
let_it_be(:group_parent) { create(:group, :private) }
2022-07-16 23:28:13 +05:30
let(:group) { create(:group, :private, parent: group_parent) }
2019-12-26 22:10:19 +05:30
let(:opts) do
{
shared_group_access: Gitlab::Access::DEVELOPER,
expires_at: nil
}
end
2020-10-24 23:57:45 +05:30
2022-07-16 23:28:13 +05:30
subject { described_class.new(group, shared_with_group, user, opts) }
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
shared_examples_for 'not shareable' do
it 'does not share and returns an error' do
expect do
result = subject.execute
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
expect(result[:status]).to eq(:error)
expect(result[:http_status]).to eq(404)
end.not_to change { group.shared_with_group_links.count }
end
2019-12-26 22:10:19 +05:30
end
2022-07-16 23:28:13 +05:30
shared_examples_for 'shareable' do
it 'adds group to another group' do
expect do
result = subject.execute
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
expect(result[:status]).to eq(:success)
end.to change { group.shared_with_group_links.count }.from(0).to(1)
end
2019-12-26 22:10:19 +05:30
end
2022-07-16 23:28:13 +05:30
context 'when user has proper membership to share a group' do
let_it_be(:group_user) { create(:user) }
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
let(:user) { group_user }
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
before do
shared_with_group.add_guest(group_user)
group.add_owner(group_user)
2019-12-26 22:10:19 +05:30
end
2022-07-16 23:28:13 +05:30
it_behaves_like 'shareable'
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
context 'when sharing outside the hierarchy is disabled' do
let_it_be(:group_parent) do
create(:group,
namespace_settings: create(:namespace_settings, prevent_sharing_groups_outside_hierarchy: true))
end
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
it_behaves_like 'not shareable'
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
context 'when group is inside hierarchy' do
let(:shared_with_group) { create(:group, :private, parent: group_parent) }
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
it_behaves_like 'shareable'
end
2019-12-26 22:10:19 +05:30
end
2022-07-16 23:28:13 +05:30
context 'project authorizations based on group hierarchies' do
let_it_be(:child_group_user) { create(:user) }
let_it_be(:parent_group_user) { create(:user) }
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
before do
shared_with_group_parent.add_owner(parent_group_user)
shared_with_group.add_owner(group_user)
shared_with_group_child.add_owner(child_group_user)
2019-12-26 22:10:19 +05:30
end
2022-07-16 23:28:13 +05:30
context 'project authorizations refresh' do
it 'is executed only for the direct members of the group' do
expect(UserProjectAccessChangedService).to receive(:new).with(contain_exactly(group_user.id))
.and_call_original
2019-12-26 22:10:19 +05:30
2021-09-04 01:27:46 +05:30
subject.execute
2021-04-17 20:07:23 +05:30
end
2019-12-26 22:10:19 +05:30
end
2022-07-16 23:28:13 +05:30
context 'project authorizations' do
let(:group_child) { create(:group, :private, parent: group) }
let(:project_parent) { create(:project, group: group_parent) }
let(:project) { create(:project, group: group) }
let(:project_child) { create(:project, group: group_child) }
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
context 'group user' do
let(:user) { group_user }
it 'create proper authorizations' do
subject.execute
2021-04-17 20:07:23 +05:30
2022-07-16 23:28:13 +05:30
expect(Ability.allowed?(user, :read_project, project_parent)).to be_falsey
expect(Ability.allowed?(user, :read_project, project)).to be_truthy
expect(Ability.allowed?(user, :read_project, project_child)).to be_truthy
end
2021-04-17 20:07:23 +05:30
end
2022-07-16 23:28:13 +05:30
context 'parent group user' do
let(:user) { parent_group_user }
2021-04-17 20:07:23 +05:30
2022-07-16 23:28:13 +05:30
it 'create proper authorizations' do
subject.execute
expect(Ability.allowed?(user, :read_project, project_parent)).to be_falsey
expect(Ability.allowed?(user, :read_project, project)).to be_falsey
expect(Ability.allowed?(user, :read_project, project_child)).to be_falsey
end
end
2019-12-26 22:10:19 +05:30
2022-07-16 23:28:13 +05:30
context 'child group user' do
let(:user) { child_group_user }
it 'create proper authorizations' do
subject.execute
expect(Ability.allowed?(user, :read_project, project_parent)).to be_falsey
expect(Ability.allowed?(user, :read_project, project)).to be_falsey
expect(Ability.allowed?(user, :read_project, project_child)).to be_falsey
end
2021-04-17 20:07:23 +05:30
end
2019-12-26 22:10:19 +05:30
end
end
end
2021-09-04 01:27:46 +05:30
2022-07-16 23:28:13 +05:30
context 'user does not have access to group' do
let(:user) { create(:user) }
2021-09-04 01:27:46 +05:30
2022-07-16 23:28:13 +05:30
before do
group.add_owner(user)
end
2021-09-04 01:27:46 +05:30
2022-07-16 23:28:13 +05:30
it_behaves_like 'not shareable'
end
context 'user does not have admin access to shared group' do
let(:user) { create(:user) }
before do
shared_with_group.add_guest(user)
group.add_developer(user)
2021-09-04 01:27:46 +05:30
end
2022-07-16 23:28:13 +05:30
it_behaves_like 'not shareable'
end
context 'when group is blank' do
let(:group_user) { create(:user) }
let(:user) { group_user }
let(:group) { nil }
2021-09-04 01:27:46 +05:30
2022-07-16 23:28:13 +05:30
it 'does not share and returns an error' do
expect do
result = subject.execute
2021-09-04 01:27:46 +05:30
2022-07-16 23:28:13 +05:30
expect(result[:status]).to eq(:error)
expect(result[:http_status]).to eq(404)
end.not_to change { shared_with_group.shared_group_links.count }
2021-09-04 01:27:46 +05:30
end
end
2022-07-16 23:28:13 +05:30
context 'when shared_with_group is blank' do
let(:group_user) { create(:user) }
let(:user) { group_user }
let(:shared_with_group) { nil }
it_behaves_like 'not shareable'
end
2019-12-26 22:10:19 +05:30
end