Skip to content

Commit 3326c79

Browse files
committed
test(contributors_controller): cover unauthorized plan access
Add specs for the contributors index and new endpoints to ensure unauthorized plans are denied access.
1 parent 0d56007 commit 3326c79

1 file changed

Lines changed: 38 additions & 12 deletions

File tree

‎spec/controllers/contributors_controller_spec.rb‎

Lines changed: 38 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -36,20 +36,46 @@
3636
sign_in(@user)
3737
end
3838

39-
it 'GET plans/:plan_id/contributors (:index)' do
40-
get :index, params: { plan_id: @plan.id }
41-
expect(response).to render_template(:index)
42-
expect(assigns(:plan)).to eql(@plan)
43-
expect(assigns(:contributors).length).to eql(1)
44-
expect(assigns(:contributors).first).to eql(@contributor)
39+
describe 'GET plans/:plan_id/contributors (:index)' do
40+
it 'renders the index' do
41+
get :index, params: { plan_id: @plan.id }
42+
expect(response).to render_template(:index)
43+
expect(assigns(:plan)).to eql(@plan)
44+
expect(assigns(:contributors).length).to eql(1)
45+
expect(assigns(:contributors).first).to eql(@contributor)
46+
end
47+
48+
it 'denies access to an unauthorized plan' do
49+
get :index, params: { plan_id: @unauthorized_plan.id }
50+
51+
expect(response).not_to render_template(:index)
52+
expect(assigns(:contributors)).to eql(nil)
53+
54+
expect(response).to have_http_status(:redirect)
55+
expect(response).to redirect_to(plans_url)
56+
expect(flash[:alert]).to eq('You are not authorized to perform this action.')
57+
end
4558
end
4659

47-
it 'GET plans/:plan_id/contributors/new (:new)' do
48-
get :new, params: { plan_id: @plan.id }
49-
expect(response).to render_template(:new)
50-
expect(assigns(:plan)).to eql(@plan)
51-
expect(assigns(:contributor).new_record?).to eql(true)
52-
expect(assigns(:contributor).plan).to eql(@plan)
60+
describe 'GET plans/:plan_id/contributors/new (:new)' do
61+
it 'renders the new form' do
62+
get :new, params: { plan_id: @plan.id }
63+
expect(response).to render_template(:new)
64+
expect(assigns(:plan)).to eql(@plan)
65+
expect(assigns(:contributor).new_record?).to eql(true)
66+
expect(assigns(:contributor).plan).to eql(@plan)
67+
end
68+
69+
it 'denies access to an unauthorized plan' do
70+
get :new, params: { plan_id: @unauthorized_plan.id }
71+
72+
expect(response).not_to render_template(:new)
73+
expect(assigns(:contributor)).to eql(nil)
74+
75+
expect(response).to have_http_status(:redirect)
76+
expect(response).to redirect_to(plans_url)
77+
expect(flash[:alert]).to eq('You are not authorized to perform this action.')
78+
end
5379
end
5480

5581
it 'GET plans/:plan_id/contributors/:id/edit (:edit)' do

0 commit comments

Comments
 (0)