2019-02-15 15:39:39 +05:30
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2020-07-28 23:09:34 +05:30
|
|
|
require 'fast_spec_helper'
|
2019-02-15 15:39:39 +05:30
|
|
|
require_relative '../../../rubocop/cop/safe_params'
|
|
|
|
|
2021-03-08 18:12:59 +05:30
|
|
|
RSpec.describe RuboCop::Cop::SafeParams do
|
2019-02-15 15:39:39 +05:30
|
|
|
subject(:cop) { described_class.new }
|
|
|
|
|
|
|
|
it 'flags the params as an argument of url_for' do
|
|
|
|
expect_offense(<<~SOURCE)
|
|
|
|
url_for(params)
|
|
|
|
^^^^^^^^^^^^^^^ Use `safe_params` instead of `params` in url_for.
|
|
|
|
SOURCE
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'flags the merged params as an argument of url_for' do
|
|
|
|
expect_offense(<<~SOURCE)
|
|
|
|
url_for(params.merge(additional_params))
|
|
|
|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Use `safe_params` instead of `params` in url_for.
|
|
|
|
SOURCE
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'flags the merged params arg as an argument of url_for' do
|
|
|
|
expect_offense(<<~SOURCE)
|
|
|
|
url_for(something.merge(additional).merge(params))
|
|
|
|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Use `safe_params` instead of `params` in url_for.
|
|
|
|
SOURCE
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'does not flag other argument of url_for' do
|
|
|
|
expect_no_offenses(<<~SOURCE)
|
|
|
|
url_for(something)
|
|
|
|
SOURCE
|
|
|
|
end
|
|
|
|
end
|