]> source.dussan.org Git - redmine.git/commitdiff
Merged r22066 from trunk to 5.0-stable (#38063).
authorGo MAEDA <maeda@farend.jp>
Fri, 20 Jan 2023 03:32:40 +0000 (03:32 +0000)
committerGo MAEDA <maeda@farend.jp>
Fri, 20 Jan 2023 03:32:40 +0000 (03:32 +0000)
git-svn-id: https://svn.redmine.org/redmine/branches/5.0-stable@22067 e93f8b46-1217-0410-a6f0-8f06a7374b81

app/controllers/application_controller.rb
test/functional/news_controller_test.rb
test/integration/application_test.rb

index d400bdca84a4456718fa6084ea4ed7731aac4900..2c070ed67d2f8c17e94ee924a94e796484fcb3b9 100644 (file)
@@ -354,9 +354,12 @@ class ApplicationController < ActionController::Base
   # and authorize the user for the requested action
   def find_optional_project
     if params[:project_id].present?
-      find_project(params[:project_id])
+      @project = Project.find(params[:project_id])
     end
     authorize_global
+  rescue ActiveRecord::RecordNotFound
+    User.current.logged? ? render_404 : require_login
+    false
   end
 
   # Finds and sets @project based on @object.project
index 0d62b8f196321d95c0c3ea2a5723dc81b970f074..12e815350a2e5db9cbbc8c1e94c554e46210f30e 100644 (file)
@@ -40,11 +40,21 @@ class NewsControllerTest < Redmine::ControllerTest
     assert_select 'h3 a', :text => 'eCookbook first release !'
   end
 
-  def test_index_with_invalid_project_should_respond_with_404
+  def test_index_with_invalid_project_should_respond_with_404_for_logged_users
+    @request.session[:user_id] = 2
+
     get(:index, :params => {:project_id => 999})
     assert_response 404
   end
 
+  def test_index_with_invalid_project_should_respond_with_302_for_anonymous
+    Role.anonymous.remove_permission! :view_news
+    with_settings :login_required => '0' do
+      get(:index, :params => {:project_id => 999})
+      assert_response 302
+    end
+  end
+
   def test_index_without_permission_should_fail
     Role.all.each {|r| r.remove_permission! :view_news}
     @request.session[:user_id] = 2
index f7abae80b7f892e1162b68d73abbcbfd2056dd5f..1b8c091a04ada9ac89fcb0cc315aa6cec1729edc 100644 (file)
@@ -96,4 +96,19 @@ class ApplicationTest < Redmine::IntegrationTest
       assert_response 302
     end
   end
+
+  def test_find_optional_project_should_not_error
+    Role.anonymous.remove_permission! :view_gantt
+    with_settings :login_required => '0' do
+      get '/projects/nonexistingproject/issues/gantt'
+      assert_response 302
+    end
+  end
+
+  def test_find_optional_project_should_render_404_for_logged_users
+    log_user('jsmith', 'jsmith')
+
+    get '/projects/nonexistingproject/issues/gantt'
+    assert_response 404
+  end
 end