debian-mirror-gitlab/spec/controllers/projects/project_members_controller_spec.rb

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

530 lines
16 KiB
Ruby
Raw Normal View History

2019-07-31 22:56:46 +05:30
# frozen_string_literal: true
2016-06-02 11:05:42 +05:30
require('spec_helper')
2020-06-23 00:09:42 +05:30
RSpec.describe Projects::ProjectMembersController do
2021-09-04 01:27:46 +05:30
let_it_be(:user) { create(:user) }
let_it_be(:group) { create(:group, :public) }
let_it_be(:project, reload: true) { create(:project, :public) }
2021-04-29 21:17:54 +05:30
before do
travel_to DateTime.new(2019, 4, 1)
end
after do
travel_back
2021-02-11 23:33:58 +05:30
end
2017-08-17 22:00:37 +05:30
describe 'GET index' do
2019-07-07 11:18:12 +05:30
it 'has the project_members address with a 200 status code' do
2019-02-15 15:39:39 +05:30
get :index, params: { namespace_id: project.namespace, project_id: project }
2020-03-13 15:44:24 +05:30
expect(response).to have_gitlab_http_status(:ok)
2016-06-02 11:05:42 +05:30
end
2020-01-01 13:55:28 +05:30
2021-03-08 18:12:59 +05:30
context 'project members' do
context 'when project belongs to group' do
2021-09-04 01:27:46 +05:30
let_it_be(:user_in_group) { create(:user) }
let_it_be(:project_in_group) { create(:project, :public, group: group) }
2021-03-08 18:12:59 +05:30
before do
group.add_owner(user_in_group)
project_in_group.add_maintainer(user)
sign_in(user)
end
it 'lists inherited project members by default' do
get :index, params: { namespace_id: project_in_group.namespace, project_id: project_in_group }
expect(assigns(:project_members).map(&:user_id)).to contain_exactly(user.id, user_in_group.id)
end
it 'lists direct project members only' do
get :index, params: { namespace_id: project_in_group.namespace, project_id: project_in_group, with_inherited_permissions: 'exclude' }
expect(assigns(:project_members).map(&:user_id)).to contain_exactly(user.id)
end
it 'lists inherited project members only' do
get :index, params: { namespace_id: project_in_group.namespace, project_id: project_in_group, with_inherited_permissions: 'only' }
expect(assigns(:project_members).map(&:user_id)).to contain_exactly(user_in_group.id)
end
end
context 'when invited members are present' do
let!(:invited_member) { create(:project_member, :invited, project: project) }
before do
project.add_maintainer(user)
sign_in(user)
end
it 'excludes the invited members from project members list' do
get :index, params: { namespace_id: project.namespace, project_id: project }
expect(assigns(:project_members).map(&:invite_email)).not_to contain_exactly(invited_member.invite_email)
end
end
end
context 'invited members' do
2021-09-04 01:27:46 +05:30
let_it_be(:invited_member) { create(:project_member, :invited, project: project) }
2020-01-01 13:55:28 +05:30
before do
sign_in(user)
end
2021-03-08 18:12:59 +05:30
context 'when user has `admin_project_member` permissions' do
before do
2021-10-27 15:23:28 +05:30
project.add_maintainer(user)
2021-03-08 18:12:59 +05:30
end
it 'lists invited members' do
get :index, params: { namespace_id: project.namespace, project_id: project }
expect(assigns(:invited_members).map(&:invite_email)).to contain_exactly(invited_member.invite_email)
end
end
context 'when user does not have `admin_project_member` permissions' do
it 'does not list invited members' do
get :index, params: { namespace_id: project.namespace, project_id: project }
expect(assigns(:invited_members)).to be_nil
end
2020-01-01 13:55:28 +05:30
end
2021-03-08 18:12:59 +05:30
end
2020-01-01 13:55:28 +05:30
2021-03-08 18:12:59 +05:30
context 'access requests' do
2021-09-04 01:27:46 +05:30
let_it_be(:access_requester_user) { create(:user) }
2020-01-01 13:55:28 +05:30
2021-03-08 18:12:59 +05:30
before do
project.request_access(access_requester_user)
sign_in(user)
2020-01-01 13:55:28 +05:30
end
2021-03-08 18:12:59 +05:30
context 'when user has `admin_project_member` permissions' do
before do
2021-10-27 15:23:28 +05:30
project.add_maintainer(user)
2021-03-08 18:12:59 +05:30
end
it 'lists access requests' do
get :index, params: { namespace_id: project.namespace, project_id: project }
expect(assigns(:requesters).map(&:user_id)).to contain_exactly(access_requester_user.id)
end
end
context 'when user does not have `admin_project_member` permissions' do
it 'does not list access requests' do
get :index, params: { namespace_id: project.namespace, project_id: project }
2020-01-01 13:55:28 +05:30
2021-03-08 18:12:59 +05:30
expect(assigns(:requesters)).to be_nil
end
2020-01-01 13:55:28 +05:30
end
end
2017-08-17 22:00:37 +05:30
end
2016-06-02 11:05:42 +05:30
2018-03-17 18:26:18 +05:30
describe 'PUT update' do
2021-09-04 01:27:46 +05:30
let_it_be(:requester) { create(:project_member, :access_request, project: project) }
2018-03-17 18:26:18 +05:30
before do
2018-11-18 11:00:15 +05:30
project.add_maintainer(user)
2018-03-17 18:26:18 +05:30
sign_in(user)
end
2020-10-04 03:57:07 +05:30
context 'access level' do
Gitlab::Access.options.each do |label, value|
it "can change the access level to #{label}" do
params = {
project_member: { access_level: value },
namespace_id: project.namespace,
project_id: project,
id: requester
}
put :update, params: params, xhr: true
2018-03-17 18:26:18 +05:30
2020-10-04 03:57:07 +05:30
expect(requester.reload.human_access).to eq(label)
end
end
2022-07-23 23:45:48 +05:30
describe 'managing project direct owners' do
context 'when a Maintainer tries to elevate another user to OWNER' do
it 'does not allow the operation' do
params = {
project_member: { access_level: Gitlab::Access::OWNER },
namespace_id: project.namespace,
project_id: project,
id: requester
}
put :update, params: params, xhr: true
expect(response).to have_gitlab_http_status(:forbidden)
end
end
context 'when a user with OWNER access tries to elevate another user to OWNER' do
# inherited owner role via personal project association
let(:user) { project.first_owner }
before do
sign_in(user)
end
it 'returns success' do
params = {
project_member: { access_level: Gitlab::Access::OWNER },
namespace_id: project.namespace,
project_id: project,
id: requester
}
put :update, params: params, xhr: true
expect(response).to have_gitlab_http_status(:ok)
expect(requester.reload.access_level).to eq(Gitlab::Access::OWNER)
end
end
end
2020-10-04 03:57:07 +05:30
end
context 'access expiry date' do
subject do
put :update, xhr: true, params: {
project_member: {
expires_at: expires_at
},
namespace_id: project.namespace,
project_id: project,
id: requester
}
end
context 'when set to a date in the past' do
let(:expires_at) { 2.days.ago }
it 'does not update the member' do
subject
expect(requester.reload.expires_at).not_to eq(expires_at.to_date)
end
2021-03-11 19:13:27 +05:30
it 'returns error status' do
subject
expect(response).to have_gitlab_http_status(:unprocessable_entity)
end
it 'returns error message' do
subject
expect(json_response).to eq({ 'message' => 'Expires at cannot be a date in the past' })
end
2020-10-04 03:57:07 +05:30
end
context 'when set to a date in the future' do
let(:expires_at) { 5.days.from_now }
it 'updates the member' do
subject
expect(requester.reload.expires_at).to eq(expires_at.to_date)
end
2018-03-17 18:26:18 +05:30
end
end
2021-01-03 14:25:43 +05:30
context 'expiration date' do
let(:expiry_date) { 1.month.from_now.to_date }
before do
travel_to Time.now.utc.beginning_of_day
put(
:update,
params: {
project_member: { expires_at: expiry_date },
namespace_id: project.namespace,
project_id: project,
id: requester
},
format: :json
)
end
context 'when `expires_at` is set' do
it 'returns correct json response' do
expect(json_response).to eq({
"expires_soon" => false,
"expires_at_formatted" => expiry_date.to_time.in_time_zone.to_s(:medium)
})
end
end
context 'when `expires_at` is not set' do
let(:expiry_date) { nil }
it 'returns empty json response' do
expect(json_response).to be_empty
end
end
end
2018-03-17 18:26:18 +05:30
end
2017-08-17 22:00:37 +05:30
describe 'DELETE destroy' do
2021-09-04 01:27:46 +05:30
let_it_be(:member) { create(:project_member, :developer, project: project) }
2017-08-17 22:00:37 +05:30
2017-09-10 17:25:29 +05:30
before do
sign_in(user)
end
context 'when member is not found' do
it 'returns 404' do
2019-02-15 15:39:39 +05:30
delete :destroy, params: {
namespace_id: project.namespace,
project_id: project,
id: 42
}
2020-03-13 15:44:24 +05:30
expect(response).to have_gitlab_http_status(:not_found)
end
end
context 'when member is found' do
context 'when user does not have enough rights' do
2022-07-23 23:45:48 +05:30
context 'when user does not have rights to manage other members' do
before do
project.add_developer(user)
end
it 'returns 404', :aggregate_failures do
delete :destroy, params: {
namespace_id: project.namespace,
project_id: project,
id: member
}
expect(response).to have_gitlab_http_status(:not_found)
expect(project.members).to include member
end
2017-09-10 17:25:29 +05:30
end
2022-07-23 23:45:48 +05:30
context 'when user does not have rights to manage Owner members' do
let_it_be(:member) { create(:project_member, project: project, access_level: Gitlab::Access::OWNER) }
2022-07-23 23:45:48 +05:30
before do
project.add_maintainer(user)
end
it 'returns 403', :aggregate_failures do
delete :destroy, params: {
namespace_id: project.namespace,
project_id: project,
id: member
}
expect(response).to have_gitlab_http_status(:forbidden)
expect(project.members).to include member
end
end
end
context 'when user has enough rights' do
2017-09-10 17:25:29 +05:30
before do
2018-11-18 11:00:15 +05:30
project.add_maintainer(user)
2017-09-10 17:25:29 +05:30
end
2021-09-04 01:27:46 +05:30
it '[HTML] removes user from members', :aggregate_failures do
2019-02-15 15:39:39 +05:30
delete :destroy, params: {
namespace_id: project.namespace,
project_id: project,
id: member
}
expect(response).to redirect_to(
2017-09-10 17:25:29 +05:30
project_project_members_path(project)
)
2017-08-17 22:00:37 +05:30
expect(project.members).not_to include member
end
2021-09-04 01:27:46 +05:30
it '[JS] removes user from members', :aggregate_failures do
2019-02-15 15:39:39 +05:30
delete :destroy, params: {
namespace_id: project.namespace,
project_id: project,
id: member
}, xhr: true
2019-12-04 20:38:33 +05:30
expect(response).to be_successful
2017-08-17 22:00:37 +05:30
expect(project.members).not_to include member
end
end
end
end
2017-08-17 22:00:37 +05:30
describe 'DELETE leave' do
2017-09-10 17:25:29 +05:30
before do
sign_in(user)
end
context 'when member is not found' do
2016-11-03 12:29:30 +05:30
it 'returns 404' do
2019-02-15 15:39:39 +05:30
delete :leave, params: {
namespace_id: project.namespace,
project_id: project
}
2020-03-13 15:44:24 +05:30
expect(response).to have_gitlab_http_status(:not_found)
end
end
context 'when member is found' do
context 'and is not an owner' do
2017-09-10 17:25:29 +05:30
before do
2018-03-17 18:26:18 +05:30
project.add_developer(user)
2017-09-10 17:25:29 +05:30
end
2021-09-04 01:27:46 +05:30
it 'removes user from members', :aggregate_failures do
2019-02-15 15:39:39 +05:30
delete :leave, params: {
namespace_id: project.namespace,
project_id: project
}
2021-06-08 01:23:25 +05:30
expect(controller).to set_flash.to "You left the \"#{project.human_name}\" project."
expect(response).to redirect_to(dashboard_projects_path)
expect(project.users).not_to include user
end
end
context 'and is an owner' do
2017-09-10 17:25:29 +05:30
let(:project) { create(:project, namespace: user.namespace) }
2017-08-17 22:00:37 +05:30
2017-09-10 17:25:29 +05:30
before do
2018-11-18 11:00:15 +05:30
project.add_maintainer(user)
2017-09-10 17:25:29 +05:30
end
2018-11-08 19:23:39 +05:30
it 'cannot remove themselves from the project' do
2019-02-15 15:39:39 +05:30
delete :leave, params: {
namespace_id: project.namespace,
project_id: project
}
2020-03-13 15:44:24 +05:30
expect(response).to have_gitlab_http_status(:forbidden)
end
end
context 'and is a requester' do
2017-09-10 17:25:29 +05:30
before do
project.request_access(user)
end
2021-09-04 01:27:46 +05:30
it 'removes user from members', :aggregate_failures do
2019-02-15 15:39:39 +05:30
delete :leave, params: {
namespace_id: project.namespace,
project_id: project
}
2021-06-08 01:23:25 +05:30
expect(controller).to set_flash.to 'Your access request to the project has been withdrawn.'
2017-09-10 17:25:29 +05:30
expect(response).to redirect_to(project_path(project))
2016-08-24 12:49:21 +05:30
expect(project.requesters).to be_empty
expect(project.users).not_to include user
end
end
end
end
2017-08-17 22:00:37 +05:30
describe 'POST request_access' do
2017-09-10 17:25:29 +05:30
before do
sign_in(user)
end
2021-09-04 01:27:46 +05:30
it 'creates a new ProjectMember that is not a team member', :aggregate_failures do
2019-02-15 15:39:39 +05:30
post :request_access, params: {
namespace_id: project.namespace,
project_id: project
}
2021-06-08 01:23:25 +05:30
expect(controller).to set_flash.to 'Your request for access has been queued for review.'
expect(response).to redirect_to(
2017-09-10 17:25:29 +05:30
project_path(project)
)
2016-08-24 12:49:21 +05:30
expect(project.requesters.exists?(user_id: user)).to be_truthy
expect(project.users).not_to include user
end
end
2017-08-17 22:00:37 +05:30
describe 'POST approve' do
2021-09-04 01:27:46 +05:30
let_it_be(:member) { create(:project_member, :access_request, project: project) }
2017-08-17 22:00:37 +05:30
2017-09-10 17:25:29 +05:30
before do
sign_in(user)
end
context 'when member is not found' do
it 'returns 404' do
2019-02-15 15:39:39 +05:30
post :approve_access_request, params: {
namespace_id: project.namespace,
project_id: project,
id: 42
}
2020-03-13 15:44:24 +05:30
expect(response).to have_gitlab_http_status(:not_found)
end
end
context 'when member is found' do
2022-07-23 23:45:48 +05:30
context 'when user does not have rights to manage other members' do
2017-09-10 17:25:29 +05:30
before do
2018-03-17 18:26:18 +05:30
project.add_developer(user)
2017-09-10 17:25:29 +05:30
end
2021-09-04 01:27:46 +05:30
it 'returns 404', :aggregate_failures do
2019-02-15 15:39:39 +05:30
post :approve_access_request, params: {
namespace_id: project.namespace,
project_id: project,
id: member
}
2020-03-13 15:44:24 +05:30
expect(response).to have_gitlab_http_status(:not_found)
2017-08-17 22:00:37 +05:30
expect(project.members).not_to include member
end
end
context 'when user has enough rights' do
2017-09-10 17:25:29 +05:30
before do
2018-11-18 11:00:15 +05:30
project.add_maintainer(user)
2017-09-10 17:25:29 +05:30
end
2021-09-04 01:27:46 +05:30
it 'adds user to members', :aggregate_failures do
2019-02-15 15:39:39 +05:30
post :approve_access_request, params: {
namespace_id: project.namespace,
project_id: project,
id: member
}
expect(response).to redirect_to(
2017-09-10 17:25:29 +05:30
project_project_members_path(project)
)
2017-08-17 22:00:37 +05:30
expect(project.members).to include member
end
end
end
end
2016-11-03 12:29:30 +05:30
2021-01-03 14:25:43 +05:30
describe 'POST resend_invite' do
2021-09-04 01:27:46 +05:30
let_it_be(:member) { create(:project_member, project: project) }
2021-01-03 14:25:43 +05:30
before do
project.add_maintainer(user)
sign_in(user)
end
it 'is successful' do
post :resend_invite, params: { namespace_id: project.namespace, project_id: project, id: member }
expect(response).to have_gitlab_http_status(:found)
end
end
2016-06-02 11:05:42 +05:30
end