2018-12-19 19:23:09 -08:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
|
|
|
require 'rails_helper'
|
|
|
|
require 'pundit/rspec'
|
|
|
|
|
|
|
|
RSpec.describe InvitePolicy do
|
2023-07-27 20:54:40 -07:00
|
|
|
subject { described_class }
|
|
|
|
|
2022-07-04 17:41:40 -07:00
|
|
|
let(:admin) { Fabricate(:user, role: UserRole.find_by(name: 'Admin')).account }
|
|
|
|
let(:john) { Fabricate(:user).account }
|
2018-12-19 19:23:09 -08:00
|
|
|
|
|
|
|
permissions :index? do
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when staff?' do
|
2018-12-19 19:23:09 -08:00
|
|
|
it 'permits' do
|
|
|
|
expect(subject).to permit(admin, Invite)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
permissions :create? do
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'with privilege' do
|
2022-07-04 17:41:40 -07:00
|
|
|
before do
|
|
|
|
UserRole.everyone.update(permissions: UserRole::FLAGS[:invite_users])
|
|
|
|
end
|
|
|
|
|
2018-12-19 19:23:09 -08:00
|
|
|
it 'permits' do
|
|
|
|
expect(subject).to permit(john, Invite)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when does not have privilege' do
|
2022-07-04 17:41:40 -07:00
|
|
|
before do
|
|
|
|
UserRole.everyone.update(permissions: UserRole::Flags::NONE)
|
|
|
|
end
|
|
|
|
|
2018-12-19 19:23:09 -08:00
|
|
|
it 'denies' do
|
|
|
|
expect(subject).to_not permit(john, Invite)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
permissions :deactivate_all? do
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when admin?' do
|
2018-12-19 19:23:09 -08:00
|
|
|
it 'permits' do
|
|
|
|
expect(subject).to permit(admin, Invite)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when not admin?' do
|
2018-12-19 19:23:09 -08:00
|
|
|
it 'denies' do
|
|
|
|
expect(subject).to_not permit(john, Invite)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
permissions :destroy? do
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when owner?' do
|
2018-12-19 19:23:09 -08:00
|
|
|
it 'permits' do
|
|
|
|
expect(subject).to permit(john, Fabricate(:invite, user: john.user))
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when not owner?' do
|
|
|
|
context 'when admin?' do
|
2022-07-04 17:41:40 -07:00
|
|
|
it 'permits' do
|
|
|
|
expect(subject).to permit(admin, Fabricate(:invite))
|
2018-12-19 19:23:09 -08:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2023-07-27 20:54:40 -07:00
|
|
|
context 'when not admin?' do
|
2022-07-04 17:41:40 -07:00
|
|
|
it 'denies' do
|
|
|
|
expect(subject).to_not permit(john, Fabricate(:invite))
|
2018-12-19 19:23:09 -08:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|