debian-mirror-gitlab/spec/requests/api/members_spec.rb

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

881 lines
34 KiB
Ruby
Raw Normal View History

2019-12-26 22:10:19 +05:30
# frozen_string_literal: true
2016-09-13 17:45:13 +05:30
require 'spec_helper'
2023-03-04 22:38:38 +05:30
RSpec.describe API::Members, feature_category: :subgroups do
2022-08-27 11:52:29 +05:30
let_it_be(:maintainer) { create(:user, username: 'maintainer_user') }
let_it_be(:maintainer2) { create(:user, username: 'user-with-maintainer-role') }
let_it_be(:developer) { create(:user) }
let_it_be(:access_requester) { create(:user) }
let_it_be(:stranger) { create(:user) }
let_it_be(:user_with_minimal_access) { create(:user) }
let_it_be(:project, refind: true) do
2022-07-23 23:45:48 +05:30
create(:project, :public, creator_id: maintainer.id, group: create(:group, :public)) do |project|
2018-11-18 11:00:15 +05:30
project.add_maintainer(maintainer)
2022-06-21 17:19:12 +05:30
project.add_developer(developer, current_user: maintainer)
2017-08-17 22:00:37 +05:30
project.request_access(access_requester)
end
2016-09-13 17:45:13 +05:30
end
2022-08-27 11:52:29 +05:30
let_it_be(:group, refind: true) do
2019-12-21 20:55:43 +05:30
create(:group, :public) do |group|
2018-11-18 11:00:15 +05:30
group.add_owner(maintainer)
2022-06-21 17:19:12 +05:30
group.add_developer(developer, maintainer)
2021-01-29 00:20:46 +05:30
create(:group_member, :minimal_access, source: group, user: user_with_minimal_access)
2017-08-17 22:00:37 +05:30
group.request_access(access_requester)
end
2016-09-13 17:45:13 +05:30
end
2018-11-18 11:00:15 +05:30
shared_examples 'GET /:source_type/:id/members/(all)' do |source_type, all|
let(:members_url) do
2019-12-26 22:10:19 +05:30
(+"/#{source_type.pluralize}/#{source.id}/members").tap do |url|
2018-11-18 11:00:15 +05:30
url << "/all" if all
end
end
context "with :source_type == #{source_type.pluralize}" do
2016-09-13 17:45:13 +05:30
it_behaves_like 'a 404 response when source is private' do
2018-11-18 11:00:15 +05:30
let(:route) { get api(members_url, stranger) }
2016-09-13 17:45:13 +05:30
end
2018-11-18 11:00:15 +05:30
%i[maintainer developer access_requester stranger].each do |type|
2016-09-29 09:46:39 +05:30
context "when authenticated as a #{type}" do
it 'returns 200' do
user = public_send(type)
2017-08-17 22:00:37 +05:30
2018-11-18 11:00:15 +05:30
get api(members_url, user)
2016-09-29 09:46:39 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2017-08-17 22:00:37 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
2016-09-29 09:46:39 +05:30
expect(json_response.size).to eq(2)
2018-11-18 11:00:15 +05:30
expect(json_response.map { |u| u['id'] }).to match_array [maintainer.id, developer.id]
2022-06-21 17:19:12 +05:30
expect(json_response).to contain_exactly(
a_hash_including('created_by' => a_hash_including('id' => maintainer.id)),
hash_not_including('created_by')
)
2016-09-13 17:45:13 +05:30
end
end
end
2018-03-17 18:26:18 +05:30
it 'avoids N+1 queries' do
# Establish baseline
2018-11-18 11:00:15 +05:30
get api(members_url, maintainer)
2018-03-17 18:26:18 +05:30
control = ActiveRecord::QueryRecorder.new do
2018-11-18 11:00:15 +05:30
get api(members_url, maintainer)
2018-03-17 18:26:18 +05:30
end
project.add_developer(create(:user))
expect do
2018-11-18 11:00:15 +05:30
get api(members_url, maintainer)
2018-03-17 18:26:18 +05:30
end.not_to exceed_query_limit(control)
end
2016-09-29 09:46:39 +05:30
it 'does not return invitees' do
create(:"#{source_type}_member", invite_token: '123', invite_email: 'test@abc.com', source: source, user: nil)
2018-11-18 11:00:15 +05:30
get api(members_url, developer)
2016-09-29 09:46:39 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2017-08-17 22:00:37 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
2016-09-29 09:46:39 +05:30
expect(json_response.size).to eq(2)
2018-11-18 11:00:15 +05:30
expect(json_response.map { |u| u['id'] }).to match_array [maintainer.id, developer.id]
2016-09-29 09:46:39 +05:30
end
2021-12-11 22:18:48 +05:30
context 'with cross db check disabled' do
around do |example|
allow_cross_joins_across_databases(url: 'https://gitlab.com/gitlab-org/gitlab/-/issues/343305') do
example.run
end
end
2016-09-13 17:45:13 +05:30
2021-12-11 22:18:48 +05:30
it 'finds members with query string' do
get api(members_url, developer), params: { query: maintainer.username }
expect(response).to have_gitlab_http_status(:ok)
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
expect(json_response.count).to eq(1)
expect(json_response.first['username']).to eq(maintainer.username)
end
2016-09-13 17:45:13 +05:30
end
2018-03-17 18:26:18 +05:30
2019-12-21 20:55:43 +05:30
it 'finds members with the given user_ids' do
get api(members_url, developer), params: { user_ids: [maintainer.id, developer.id, stranger.id] }
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2019-12-21 20:55:43 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
expect(json_response.map { |u| u['id'] }).to contain_exactly(maintainer.id, developer.id)
end
2018-03-17 18:26:18 +05:30
it 'finds all members with no query specified' do
2019-02-15 15:39:39 +05:30
get api(members_url, developer), params: { query: '' }
2018-03-17 18:26:18 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2018-03-17 18:26:18 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
expect(json_response.count).to eq(2)
2018-11-18 11:00:15 +05:30
expect(json_response.map { |u| u['id'] }).to match_array [maintainer.id, developer.id]
2018-03-17 18:26:18 +05:30
end
2016-09-13 17:45:13 +05:30
end
end
2019-10-12 21:52:04 +05:30
describe 'GET /:source_type/:id/members/all' do
2018-11-18 11:00:15 +05:30
let(:nested_user) { create(:user) }
let(:project_user) { create(:user) }
let(:linked_group_user) { create(:user) }
let!(:project_group_link) { create(:project_group_link, project: project, group: linked_group) }
2023-07-09 08:55:56 +05:30
let(:invited_group_developer) { create(:user, username: 'invited_group_developer') }
let(:invited_group) { create(:group) { |group| group.add_developer(invited_group_developer) } }
2018-11-18 11:00:15 +05:30
let(:project) do
create(:project, :public, group: nested_group) do |project|
project.add_developer(project_user)
end
end
let(:linked_group) do
create(:group) do |linked_group|
linked_group.add_developer(linked_group_user)
end
end
let(:nested_group) do
create(:group, parent: group) do |nested_group|
nested_group.add_developer(nested_user)
2023-07-09 08:55:56 +05:30
create(:group_group_link, :guest, shared_with_group: invited_group, shared_group: nested_group)
2018-11-18 11:00:15 +05:30
end
end
2023-07-09 08:55:56 +05:30
it 'finds all project members including inherited members and members shared into ancestor groups' do
2018-11-18 11:00:15 +05:30
get api("/projects/#{project.id}/members/all", developer)
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2018-11-18 11:00:15 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
2023-07-09 08:55:56 +05:30
expected_user_ids = [maintainer.id, developer.id, nested_user.id, project_user.id, linked_group_user.id, invited_group_developer.id]
expect(json_response.map { |u| u['id'] }).to match_array expected_user_ids
2018-11-18 11:00:15 +05:30
end
2023-07-09 08:55:56 +05:30
it 'returns only one member for each user without returning duplicated members with correct access levels' do
2019-09-04 21:01:54 +05:30
linked_group.add_developer(developer)
get api("/projects/#{project.id}/members/all", developer)
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2019-09-04 21:01:54 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
2019-12-26 22:10:19 +05:30
expected_users_and_access_levels = [
[developer.id, Gitlab::Access::DEVELOPER],
[maintainer.id, Gitlab::Access::OWNER],
[nested_user.id, Gitlab::Access::DEVELOPER],
[project_user.id, Gitlab::Access::DEVELOPER],
2023-07-09 08:55:56 +05:30
[linked_group_user.id, Gitlab::Access::DEVELOPER],
[invited_group_developer.id, Gitlab::Access::GUEST]
2019-12-26 22:10:19 +05:30
]
expect(json_response.map { |u| [u['id'], u['access_level']] }).to match_array(expected_users_and_access_levels)
2019-09-04 21:01:54 +05:30
end
2018-11-18 11:00:15 +05:30
it 'finds all group members including inherited members' do
get api("/groups/#{nested_group.id}/members/all", developer)
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2018-11-18 11:00:15 +05:30
expect(response).to include_pagination_headers
expect(json_response).to be_an Array
2023-07-09 08:55:56 +05:30
expected_user_ids = [maintainer.id, developer.id, nested_user.id, invited_group_developer.id]
expect(json_response.map { |u| u['id'] }).to match_array expected_user_ids
2018-11-18 11:00:15 +05:30
end
2022-06-02 21:05:25 +05:30
context 'with a subgroup' do
2022-08-27 11:52:29 +05:30
let(:group) { create(:group, :private) }
let(:subgroup) { create(:group, :private, parent: group) }
2022-06-02 21:05:25 +05:30
let(:project) { create(:project, group: subgroup) }
before do
subgroup.add_developer(developer)
end
it 'subgroup member cannot get parent group members list' do
get api("/groups/#{group.id}/members/all", developer)
expect(response).to have_gitlab_http_status(:forbidden)
end
end
2018-11-18 11:00:15 +05:30
end
2019-12-21 20:55:43 +05:30
shared_examples 'GET /:source_type/:id/members/(all/):user_id' do |source_type, all|
context "with :source_type == #{source_type.pluralize} and all == #{all}" do
2016-09-13 17:45:13 +05:30
it_behaves_like 'a 404 response when source is private' do
2019-12-21 20:55:43 +05:30
let(:route) { get api("/#{source_type.pluralize}/#{source.id}/members/#{all ? 'all/' : ''}#{developer.id}", stranger) }
2016-09-13 17:45:13 +05:30
end
context 'when authenticated as a non-member' do
%i[access_requester stranger].each do |type|
context "as a #{type}" do
it 'returns 200' do
user = public_send(type)
2019-12-21 20:55:43 +05:30
get api("/#{source_type.pluralize}/#{source.id}/members/#{all ? 'all/' : ''}#{developer.id}", user)
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:ok)
2016-09-13 17:45:13 +05:30
# User attributes
expect(json_response['id']).to eq(developer.id)
expect(json_response['name']).to eq(developer.name)
expect(json_response['username']).to eq(developer.username)
expect(json_response['state']).to eq(developer.state)
expect(json_response['avatar_url']).to eq(developer.avatar_url)
expect(json_response['web_url']).to eq(Gitlab::Routing.url_helpers.user_url(developer))
# Member attributes
expect(json_response['access_level']).to eq(Member::DEVELOPER)
2021-11-11 11:23:49 +05:30
expect(json_response['created_at'].to_time).to be_present
2016-09-13 17:45:13 +05:30
end
end
end
end
2022-08-27 11:52:29 +05:30
context 'with ancestral membership' do
shared_examples 'response with correct access levels' do
it do
get api("/#{source_type.pluralize}/#{source.id}/members/#{all ? 'all/' : ''}#{developer.id}", developer)
expect(response).to have_gitlab_http_status(:ok)
expect(json_response['access_level']).to eq(Member::MAINTAINER)
end
end
before do
source.add_maintainer(developer)
end
include_examples 'response with correct access levels'
context 'having email invite' do
before do
Member
.find_by(source: group, user: developer)
.update!(invite_email: 'email@email.com')
end
include_examples 'response with correct access levels'
end
end
2016-09-13 17:45:13 +05:30
end
end
2018-11-18 11:00:15 +05:30
shared_examples 'POST /:source_type/:id/members' do |source_type|
context "with :source_type == #{source_type.pluralize}" do
2016-09-13 17:45:13 +05:30
it_behaves_like 'a 404 response when source is private' do
2016-11-03 12:29:30 +05:30
let(:route) do
post api("/#{source_type.pluralize}/#{source.id}/members", stranger),
2019-02-15 15:39:39 +05:30
params: { user_id: access_requester.id, access_level: Member::MAINTAINER }
2016-11-03 12:29:30 +05:30
end
2016-09-13 17:45:13 +05:30
end
2023-01-13 00:05:48 +05:30
context 'when authenticated as a non-member or member with insufficient membership management rights' do
context 'when the user does not have rights to manage members' do
%i[access_requester stranger developer].each do |type|
context "as a #{type}" do
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
post api("/#{source_type.pluralize}/#{source.id}/members", public_send(type)),
params: { user_id: access_requester.id, access_level: Member::MAINTAINER }
end
end
2016-09-13 17:45:13 +05:30
end
end
2023-01-13 00:05:48 +05:30
end
2022-07-23 23:45:48 +05:30
2023-01-13 00:05:48 +05:30
context 'when the user has the rights to manage members but tries to manage members with a higher access level' do
# the other 'maintainer' is in fact an owner of the group!
let(:maintainer) { maintainer2 }
2022-07-23 23:45:48 +05:30
2023-01-13 00:05:48 +05:30
before do
source.add_maintainer(maintainer)
end
2022-07-23 23:45:48 +05:30
2023-01-13 00:05:48 +05:30
context 'when an access requester is added as OWNER' do
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: access_requester.id, access_level: Member::OWNER }
2022-07-23 23:45:48 +05:30
end
end
2023-01-13 00:05:48 +05:30
end
2022-07-23 23:45:48 +05:30
2023-01-13 00:05:48 +05:30
context 'when a totally new user is added as OWNER' do
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2022-07-23 23:45:48 +05:30
params: { user_id: stranger.id, access_level: Member::OWNER }
end
end
end
2016-09-13 17:45:13 +05:30
end
end
2022-07-23 23:45:48 +05:30
context 'when authenticated as a member with membership management rights' do
2016-09-13 17:45:13 +05:30
context 'and new member is already a requester' do
2022-07-23 23:45:48 +05:30
context 'when the requester is of equal or lower access level' do
it 'transforms the requester into a proper member' do
expect do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: access_requester.id, access_level: Member::MAINTAINER }
expect(response).to have_gitlab_http_status(:created)
end.to change { source.members.count }.by(1)
expect(source.requesters.count).to eq(0)
expect(json_response['id']).to eq(access_requester.id)
expect(json_response['access_level']).to eq(Member::MAINTAINER)
end
2016-09-13 17:45:13 +05:30
end
end
it 'creates a new member' do
expect do
2018-11-18 11:00:15 +05:30
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2020-10-04 03:57:07 +05:30
params: { user_id: stranger.id, access_level: Member::DEVELOPER }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:created)
2016-09-13 17:45:13 +05:30
end.to change { source.members.count }.by(1)
expect(json_response['id']).to eq(stranger.id)
expect(json_response['access_level']).to eq(Member::DEVELOPER)
2021-01-03 14:25:43 +05:30
end
2021-09-04 01:27:46 +05:30
context 'with invite_source considerations', :snowplow do
let(:params) { { user_id: stranger.id, access_level: Member::DEVELOPER } }
it 'tracks the invite source as api' do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: params
expect_snowplow_event(
category: 'Members::CreateService',
action: 'create_member',
label: 'members-api',
property: 'existing_user',
user: maintainer
)
end
it 'tracks the invite source from params' do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: params.merge(invite_source: '_invite_source_')
expect_snowplow_event(
category: 'Members::CreateService',
action: 'create_member',
label: '_invite_source_',
property: 'existing_user',
user: maintainer
)
end
end
context 'when executing the Members::CreateService for multiple user_ids' do
let(:user_ids) { [stranger.id, access_requester.id].join(',') }
2021-01-03 14:25:43 +05:30
it 'returns success when it successfully create all members' do
expect do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: user_ids, access_level: Member::DEVELOPER }
expect(response).to have_gitlab_http_status(:created)
end.to change { source.members.count }.by(2)
expect(json_response['status']).to eq('success')
end
it 'returns the error message if there was an error adding members to group' do
error_message = 'Unable to find User ID'
allow_next_instance_of(::Members::CreateService) do |service|
2021-04-29 21:17:54 +05:30
expect(service).to receive(:execute).and_return({ status: :error, message: error_message })
2021-01-03 14:25:43 +05:30
end
expect do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: user_ids, access_level: Member::DEVELOPER }
end.not_to change { source.members.count }
expect(json_response['status']).to eq('error')
expect(json_response['message']).to eq(error_message)
end
2016-09-13 17:45:13 +05:30
end
end
2019-02-15 15:39:39 +05:30
context 'access levels' do
2019-10-12 21:52:04 +05:30
it 'does not create the member if group level is higher' do
2019-02-15 15:39:39 +05:30
parent = create(:group)
2020-11-24 15:15:51 +05:30
group.update!(parent: parent)
project.update!(group: group)
2019-02-15 15:39:39 +05:30
parent.add_developer(stranger)
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: stranger.id, access_level: Member::REPORTER }
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:bad_request)
2019-07-07 11:18:12 +05:30
expect(json_response['message']['access_level']).to eq(["should be greater than or equal to Developer inherited membership from group #{parent.name}"])
2019-02-15 15:39:39 +05:30
end
2019-10-12 21:52:04 +05:30
it 'creates the member if group level is lower' do
2019-02-15 15:39:39 +05:30
parent = create(:group)
2020-11-24 15:15:51 +05:30
group.update!(parent: parent)
project.update!(group: group)
2019-02-15 15:39:39 +05:30
parent.add_developer(stranger)
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: stranger.id, access_level: Member::MAINTAINER }
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:created)
2019-02-15 15:39:39 +05:30
expect(json_response['id']).to eq(stranger.id)
expect(json_response['access_level']).to eq(Member::MAINTAINER)
end
end
2020-10-04 03:57:07 +05:30
context 'access expiry date' do
subject do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: stranger.id, access_level: Member::DEVELOPER, expires_at: expires_at }
end
context 'when set to a date in the past' do
let(:expires_at) { 2.days.ago.to_date }
it 'does not create a member' do
expect do
subject
end.not_to change { source.members.count }
expect(response).to have_gitlab_http_status(:bad_request)
expect(json_response['message']).to eq({ 'expires_at' => ['cannot be a date in the past'] })
end
end
context 'when set to a date in the future' do
let(:expires_at) { 2.days.from_now.to_date }
it 'creates a member' do
expect do
subject
end.to change { source.members.count }.by(1)
expect(response).to have_gitlab_http_status(:created)
expect(json_response['id']).to eq(stranger.id)
expect(json_response['expires_at']).to eq(expires_at.to_s)
end
end
end
2021-12-11 22:18:48 +05:30
context 'with tasks_to_be_done and tasks_project_id in the params' do
let(:project_id) { source_type == 'project' ? source.id : create(:project, namespace: source).id }
context 'when there is 1 user to add' do
it 'creates a member_task with the correct attributes' do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: stranger.id, access_level: Member::DEVELOPER, tasks_to_be_done: %w(code ci), tasks_project_id: project_id }
member = source.members.find_by(user_id: stranger.id)
expect(member.tasks_to_be_done).to match_array([:code, :ci])
expect(member.member_task.project_id).to eq(project_id)
end
end
context 'when there are multiple users to add' do
it 'creates a member_task with the correct attributes' do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: [developer.id, stranger.id].join(','), access_level: Member::DEVELOPER, tasks_to_be_done: %w(code ci), tasks_project_id: project_id }
members = source.members.where(user_id: [developer.id, stranger.id])
members.each do |member|
expect(member.tasks_to_be_done).to match_array([:code, :ci])
expect(member.member_task.project_id).to eq(project_id)
end
end
end
end
2017-08-17 22:00:37 +05:30
it "returns 409 if member already exists" do
2022-04-04 11:22:00 +05:30
source.add_guest(stranger)
2018-11-18 11:00:15 +05:30
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2019-02-15 15:39:39 +05:30
params: { user_id: maintainer.id, access_level: Member::MAINTAINER }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:conflict)
2016-09-13 17:45:13 +05:30
end
2018-11-18 11:00:15 +05:30
it 'returns 404 when the user_id is not valid' do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2022-07-23 23:45:48 +05:30
params: { user_id: non_existing_record_id, access_level: Member::MAINTAINER }
2018-11-18 11:00:15 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:not_found)
2018-11-18 11:00:15 +05:30
expect(json_response['message']).to eq('404 User Not Found')
end
2016-09-13 17:45:13 +05:30
it 'returns 400 when user_id is not given' do
2018-11-18 11:00:15 +05:30
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2019-02-15 15:39:39 +05:30
params: { access_level: Member::MAINTAINER }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:bad_request)
2016-09-13 17:45:13 +05:30
end
it 'returns 400 when access_level is not given' do
2018-11-18 11:00:15 +05:30
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2019-02-15 15:39:39 +05:30
params: { user_id: stranger.id }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:bad_request)
2016-09-13 17:45:13 +05:30
end
2020-04-22 19:07:51 +05:30
it 'returns 400 when access_level is not valid' do
2018-11-18 11:00:15 +05:30
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
2020-04-22 19:07:51 +05:30
params: { user_id: stranger.id, access_level: non_existing_record_access_level }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:bad_request)
2016-09-13 17:45:13 +05:30
end
end
2020-07-28 23:09:34 +05:30
context 'adding project bot' do
let_it_be(:project_bot) { create(:user, :project_bot) }
before do
unrelated_project = create(:project)
unrelated_project.add_maintainer(project_bot)
end
it 'returns 400' do
expect do
post api("/#{source_type.pluralize}/#{source.id}/members", maintainer),
params: { user_id: project_bot.id, access_level: Member::DEVELOPER }
expect(response).to have_gitlab_http_status(:bad_request)
expect(json_response['message']['user_id']).to(
include('project bots cannot be added to other groups / projects'))
end.not_to change { project.members.count }
end
end
2016-09-13 17:45:13 +05:30
end
2018-11-18 11:00:15 +05:30
shared_examples 'PUT /:source_type/:id/members/:user_id' do |source_type|
context "with :source_type == #{source_type.pluralize}" do
2016-09-13 17:45:13 +05:30
it_behaves_like 'a 404 response when source is private' do
2016-11-03 12:29:30 +05:30
let(:route) do
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", stranger),
2019-02-15 15:39:39 +05:30
params: { access_level: Member::MAINTAINER }
2016-11-03 12:29:30 +05:30
end
2016-09-13 17:45:13 +05:30
end
context 'when authenticated as a non-member or member with insufficient rights' do
%i[access_requester stranger developer].each do |type|
context "as a #{type}" do
2023-01-13 00:05:48 +05:30
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", public_send(type)),
params: { access_level: Member::MAINTAINER }
end
2016-09-13 17:45:13 +05:30
end
end
end
2022-07-23 23:45:48 +05:30
context 'as a maintainer updating a member to one with higher access level than themselves' do
2023-01-13 00:05:48 +05:30
# the other 'maintainer' is in fact an owner of the group!
let(:maintainer) { maintainer2 }
2022-07-23 23:45:48 +05:30
before do
# the other 'maintainer' is in fact an owner of the group!
source.add_maintainer(maintainer2)
end
2023-01-13 00:05:48 +05:30
context 'updating a member to OWNER' do
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer),
params: { access_level: Member::OWNER }
end
end
2022-07-23 23:45:48 +05:30
end
end
2016-09-13 17:45:13 +05:30
end
2018-11-18 11:00:15 +05:30
context 'when authenticated as a maintainer/owner' do
2022-07-23 23:45:48 +05:30
context 'when updating a member with the same or lower access level' do
it 'updates the member' do
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer),
params: { access_level: Member::MAINTAINER }
2016-09-13 17:45:13 +05:30
2022-07-23 23:45:48 +05:30
expect(response).to have_gitlab_http_status(:ok)
expect(json_response['id']).to eq(developer.id)
expect(json_response['access_level']).to eq(Member::MAINTAINER)
end
end
context 'when updating a member with higher access level' do
let(:owner) { create(:user) }
2023-01-13 00:05:48 +05:30
# the other 'maintainer' is in fact an owner of the group!
let(:maintainer) { maintainer2 }
2022-07-23 23:45:48 +05:30
before do
source.add_owner(owner)
2023-01-13 00:05:48 +05:30
source.add_maintainer(maintainer)
2022-07-23 23:45:48 +05:30
end
2023-01-13 00:05:48 +05:30
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
put api("/#{source_type.pluralize}/#{source.id}/members/#{owner.id}", maintainer),
params: { access_level: Member::OWNER }
end
2022-07-23 23:45:48 +05:30
end
2020-10-04 03:57:07 +05:30
end
end
context 'access expiry date' do
subject do
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer),
params: { expires_at: expires_at, access_level: Member::MAINTAINER }
end
context 'when set to a date in the past' do
let(:expires_at) { 2.days.ago.to_date }
it 'does not update the member' do
subject
expect(response).to have_gitlab_http_status(:bad_request)
expect(json_response['message']).to eq({ 'expires_at' => ['cannot be a date in the past'] })
end
end
context 'when set to a date in the future' do
let(:expires_at) { 2.days.from_now.to_date }
it 'updates the member' do
subject
expect(response).to have_gitlab_http_status(:ok)
expect(json_response['expires_at']).to eq(expires_at.to_s)
end
2016-09-13 17:45:13 +05:30
end
end
it 'returns 409 if member does not exist' do
2022-07-16 23:28:13 +05:30
put api("/#{source_type.pluralize}/#{source.id}/members/#{non_existing_record_id}", maintainer),
2019-02-15 15:39:39 +05:30
params: { access_level: Member::MAINTAINER }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:not_found)
2016-09-13 17:45:13 +05:30
end
it 'returns 400 when access_level is not given' do
2018-11-18 11:00:15 +05:30
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer)
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:bad_request)
2016-09-13 17:45:13 +05:30
end
2020-04-22 19:07:51 +05:30
it 'returns 400 when access level is not valid' do
2018-11-18 11:00:15 +05:30
put api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer),
2020-04-22 19:07:51 +05:30
params: { access_level: non_existing_record_access_level }
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:bad_request)
2016-09-13 17:45:13 +05:30
end
end
end
2018-11-18 11:00:15 +05:30
shared_examples 'DELETE /:source_type/:id/members/:user_id' do |source_type|
context "with :source_type == #{source_type.pluralize}" do
2016-09-13 17:45:13 +05:30
it_behaves_like 'a 404 response when source is private' do
let(:route) { delete api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", stranger) }
end
context 'when authenticated as a non-member or member with insufficient rights' do
%i[access_requester stranger].each do |type|
context "as a #{type}" do
2023-01-13 00:05:48 +05:30
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
delete api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", public_send(type))
end
2016-09-13 17:45:13 +05:30
end
end
end
end
context 'when authenticated as a member and deleting themself' do
it 'deletes the member' do
expect do
delete api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", developer)
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:no_content)
2016-09-13 17:45:13 +05:30
end.to change { source.members.count }.by(-1)
end
end
2018-11-18 11:00:15 +05:30
context 'when authenticated as a maintainer/owner' do
2016-09-13 17:45:13 +05:30
context 'and member is a requester' do
2017-08-17 22:00:37 +05:30
it 'returns 404' do
2016-09-13 17:45:13 +05:30
expect do
2018-11-18 11:00:15 +05:30
delete api("/#{source_type.pluralize}/#{source.id}/members/#{access_requester.id}", maintainer)
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:not_found)
2016-09-13 17:45:13 +05:30
end.not_to change { source.requesters.count }
end
end
2022-07-23 23:45:48 +05:30
context 'when attempting to delete a member with higher access level' do
let(:owner) { create(:user) }
2023-01-13 00:05:48 +05:30
# the other 'maintainer' is in fact an owner of the group!
let(:maintainer) { maintainer2 }
2022-07-23 23:45:48 +05:30
before do
source.add_owner(owner)
2023-01-13 00:05:48 +05:30
source.add_maintainer(maintainer)
2022-07-23 23:45:48 +05:30
end
2023-01-13 00:05:48 +05:30
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
delete api("/#{source_type.pluralize}/#{source.id}/members/#{owner.id}", maintainer)
end
2022-07-23 23:45:48 +05:30
end
end
2016-09-13 17:45:13 +05:30
it 'deletes the member' do
expect do
2018-11-18 11:00:15 +05:30
delete api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer)
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:no_content)
2016-09-13 17:45:13 +05:30
end.to change { source.members.count }.by(-1)
end
2018-03-17 18:26:18 +05:30
2023-07-09 08:55:56 +05:30
it_behaves_like 'rate limited endpoint', rate_limit_key: :member_delete do
let(:current_user) { maintainer }
let(:another_member) { create(:user) }
before do
source.add_developer(another_member)
end
# We rate limit scoped by the group / project
let(:delete_paths) do
[
api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer),
api("/#{source_type.pluralize}/#{source.id}/members/#{another_member.id}", maintainer)
]
end
def request
delete_member_path = delete_paths.shift
delete delete_member_path
end
end
2018-03-17 18:26:18 +05:30
it_behaves_like '412 response' do
2018-11-18 11:00:15 +05:30
let(:request) { api("/#{source_type.pluralize}/#{source.id}/members/#{developer.id}", maintainer) }
2018-03-17 18:26:18 +05:30
end
2016-09-13 17:45:13 +05:30
end
2017-08-17 22:00:37 +05:30
it 'returns 404 if member does not exist' do
2022-07-16 23:28:13 +05:30
delete api("/#{source_type.pluralize}/#{source.id}/members/#{non_existing_record_id}", maintainer)
2016-09-13 17:45:13 +05:30
2020-04-08 14:13:33 +05:30
expect(response).to have_gitlab_http_status(:not_found)
2016-09-13 17:45:13 +05:30
end
end
end
2021-04-29 21:17:54 +05:30
describe 'DELETE /groups/:id/members/:user_id' do
let(:other_user) { create(:user) }
let(:nested_group) { create(:group, parent: group) }
before do
nested_group.add_developer(developer)
nested_group.add_developer(other_user)
end
it 'deletes only the member with skip_subresources=true' do
expect do
delete api("/groups/#{group.id}/members/#{developer.id}", maintainer), params: { skip_subresources: true }
expect(response).to have_gitlab_http_status(:no_content)
end.to change { group.members.count }.by(-1)
.and change { nested_group.members.count }.by(0)
end
it 'deletes member and its sub memberships with skip_subresources=false' do
expect do
delete api("/groups/#{group.id}/members/#{developer.id}", maintainer), params: { skip_subresources: false }
expect(response).to have_gitlab_http_status(:no_content)
end.to change { group.members.count }.by(-1)
.and change { nested_group.members.count }.by(-1)
end
end
2018-11-18 11:00:15 +05:30
[false, true].each do |all|
it_behaves_like 'GET /:source_type/:id/members/(all)', 'project', all do
let(:source) { project }
end
2016-09-13 17:45:13 +05:30
2018-11-18 11:00:15 +05:30
it_behaves_like 'GET /:source_type/:id/members/(all)', 'group', all do
let(:source) { group }
end
2016-09-13 17:45:13 +05:30
end
2019-12-21 20:55:43 +05:30
[false, true].each do |all|
it_behaves_like 'GET /:source_type/:id/members/(all/):user_id', 'project', all do
let(:source) { all ? create(:project, :public, group: group) : project }
end
2016-09-13 17:45:13 +05:30
2019-12-21 20:55:43 +05:30
it_behaves_like 'GET /:source_type/:id/members/(all/):user_id', 'group', all do
let(:source) { all ? create(:group, parent: group) : group }
end
2016-09-13 17:45:13 +05:30
end
2020-07-28 23:09:34 +05:30
describe 'POST /projects/:id/members' do
it_behaves_like 'POST /:source_type/:id/members', 'project' do
let(:source) { project }
end
context 'adding owner to project' do
2023-01-13 00:05:48 +05:30
it_behaves_like 'a 403 response when user does not have rights to manage members of a specific access level' do
let(:route) do
post api("/projects/#{project.id}/members", maintainer),
params: { user_id: access_requester.id, access_level: Member::OWNER }
end
2020-07-28 23:09:34 +05:30
end
end
context 'remove bot from project' do
it 'returns a 403 forbidden' do
project_bot = create(:user, :project_bot)
create(:project_member, project: project, user: project_bot)
expect do
delete api("/projects/#{project.id}/members/#{project_bot.id}", maintainer)
expect(response).to have_gitlab_http_status(:forbidden)
end.not_to change { project.members.count }
end
end
2016-09-13 17:45:13 +05:30
end
2018-11-18 11:00:15 +05:30
it_behaves_like 'POST /:source_type/:id/members', 'group' do
2016-09-13 17:45:13 +05:30
let(:source) { group }
end
2018-11-18 11:00:15 +05:30
it_behaves_like 'PUT /:source_type/:id/members/:user_id', 'project' do
2016-09-13 17:45:13 +05:30
let(:source) { project }
end
2018-11-18 11:00:15 +05:30
it_behaves_like 'PUT /:source_type/:id/members/:user_id', 'group' do
2016-09-13 17:45:13 +05:30
let(:source) { group }
end
2018-11-18 11:00:15 +05:30
it_behaves_like 'DELETE /:source_type/:id/members/:user_id', 'project' do
2016-09-13 17:45:13 +05:30
let(:source) { project }
end
2018-11-18 11:00:15 +05:30
it_behaves_like 'DELETE /:source_type/:id/members/:user_id', 'group' do
2016-09-13 17:45:13 +05:30
let(:source) { group }
end
end