123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305 |
- # frozen_string_literal: true
-
- # Redmine - project management software
- # Copyright (C) 2006-2021 Jean-Philippe Lang
- #
- # This program is free software; you can redistribute it and/or
- # modify it under the terms of the GNU General Public License
- # as published by the Free Software Foundation; either version 2
- # of the License, or (at your option) any later version.
- #
- # This program is distributed in the hope that it will be useful,
- # but WITHOUT ANY WARRANTY; without even the implied warranty of
- # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- # GNU General Public License for more details.
- #
- # You should have received a copy of the GNU General Public License
- # along with this program; if not, write to the Free Software
- # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
-
- require File.expand_path('../../test_helper', __FILE__)
-
- class EmailAddressesControllerTest < Redmine::ControllerTest
- fixtures :users, :email_addresses
-
- def setup
- User.current = nil
- end
-
- def test_index_with_no_additional_emails
- @request.session[:user_id] = 2
- get(:index, :params => {:user_id => 2})
- assert_response :success
- end
-
- def test_index_with_additional_emails
- @request.session[:user_id] = 2
- EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- get(:index, :params => {:user_id => 2})
- assert_response :success
- assert_select '.email', :text => 'another@somenet.foo'
- end
-
- def test_index_with_additional_emails_as_js
- @request.session[:user_id] = 2
- EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- get(:index, :params => {:user_id => 2}, :xhr => true)
- assert_response :success
- assert_include 'another@somenet.foo', response.body
- end
-
- def test_index_by_admin_should_be_allowed
- @request.session[:user_id] = 1
- get(:index, :params => {:user_id => 2})
- assert_response :success
- end
-
- def test_index_by_another_user_should_be_denied
- @request.session[:user_id] = 3
- get(:index, :params => {:user_id => 2})
- assert_response 403
- end
-
- def test_create
- @request.session[:user_id] = 2
- assert_difference 'EmailAddress.count' do
- post(
- :create,
- :params => {
- :user_id => 2,
- :email_address => {
- :address => 'another@somenet.foo'
- }
- }
- )
- assert_response 302
- assert_redirected_to '/users/2/email_addresses'
- end
- email = EmailAddress.order('id DESC').first
- assert_equal 2, email.user_id
- assert_equal 'another@somenet.foo', email.address
- end
-
- def test_create_as_js
- @request.session[:user_id] = 2
- assert_difference 'EmailAddress.count' do
- post(
- :create,
- :params => {
- :user_id => 2,
- :email_address => {
- :address => 'another@somenet.foo'
- }
- },
- :xhr => true
- )
- assert_response 200
- end
- end
-
- def test_create_with_failure
- @request.session[:user_id] = 2
- assert_no_difference 'EmailAddress.count' do
- post(
- :create,
- :params => {
- :user_id => 2,
- :email_address => {
- :address => 'invalid'
- }
- }
- )
- assert_response :success
- assert_select_error /email is invalid/i
- end
- end
-
- def test_create_with_disallowed_domain_should_fail
- @request.session[:user_id] = 2
-
- with_settings :email_domains_denied => 'black.example' do
- assert_no_difference 'EmailAddress.count' do
- post(
- :create,
- :params => {
- :user_id => 2,
- :email_address => {
- :address => 'another@black.example'
- }
- }
- )
- assert_response :success
- assert_select_error 'Email is invalid'
- end
- end
-
- with_settings :email_domains_allowed => 'white.example' do
- assert_no_difference 'EmailAddress.count' do
- post(
- :create,
- :params => {
- :user_id => 2,
- :email_address => {
- :address => 'something@example.fr'
- }
- }
- )
- assert_response :success
- assert_select_error 'Email is invalid'
- end
- end
- end
-
- def test_create_should_send_security_notification
- @request.session[:user_id] = 2
- ActionMailer::Base.deliveries.clear
- post(
- :create,
- :params => {
- :user_id => 2,
- :email_address => {
- :address => 'something@example.fr'
- }
- }
- )
- mail = ActionMailer::Base.deliveries.last
- assert_not_nil mail
- assert_mail_body_match '0.0.0.0', mail
- assert_mail_body_match I18n.t(:mail_body_security_notification_add, field: I18n.t(:field_mail), value: 'something@example.fr'), mail
- assert_select_email do
- assert_select 'a[href^=?]', 'http://localhost:3000/my/account', :text => 'My account'
- end
- # The old email address should be notified about a new address for security purposes
- assert mail.to.include?(User.find(2).mail)
- assert mail.to.include?('something@example.fr')
- end
-
- def test_update
- @request.session[:user_id] = 2
- email = EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- put(
- :update,
- :params => {
- :user_id => 2,
- :id => email.id,
- :notify => '0'
- }
- )
- assert_response 302
-
- assert_equal false, email.reload.notify
- end
-
- def test_update_as_js
- @request.session[:user_id] = 2
- email = EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- put(
- :update,
- :params => {
- :user_id => 2,
- :id => email.id,
- :notify => '0'
- },
- :xhr => true
- )
- assert_response 200
-
- assert_equal false, email.reload.notify
- end
-
- def test_update_should_send_security_notification
- @request.session[:user_id] = 2
- email = EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- ActionMailer::Base.deliveries.clear
- put(
- :update,
- :params => {
- :user_id => 2,
- :id => email.id,
- :notify => '0'
- },
- :xhr => true
- )
- mail = ActionMailer::Base.deliveries.last
- assert_not_nil mail
- assert_mail_body_match I18n.t(:mail_body_security_notification_notify_disabled, value: 'another@somenet.foo'), mail
-
- # The changed address should be notified for security purposes
- assert mail.to.include?('another@somenet.foo')
- end
-
- def test_destroy
- @request.session[:user_id] = 2
- email = EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- assert_difference 'EmailAddress.count', -1 do
- delete(
- :destroy,
- :params => {
- :user_id => 2,
- :id => email.id
- }
- )
- assert_response 302
- assert_redirected_to '/users/2/email_addresses'
- end
- end
-
- def test_destroy_as_js
- @request.session[:user_id] = 2
- email = EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- assert_difference 'EmailAddress.count', -1 do
- delete(
- :destroy,
- :params => {
- :user_id => 2,
- :id => email.id
- },
- :xhr => true
- )
- assert_response 200
- end
- end
-
- def test_should_not_destroy_default
- @request.session[:user_id] = 2
-
- assert_no_difference 'EmailAddress.count' do
- delete(
- :destroy,
- :params => {
- :user_id => 2,
- :id => User.find(2).email_address.id
- }
- )
- assert_response 404
- end
- end
-
- def test_destroy_should_send_security_notification
- @request.session[:user_id] = 2
- email = EmailAddress.create!(:user_id => 2, :address => 'another@somenet.foo')
-
- ActionMailer::Base.deliveries.clear
- delete(
- :destroy,
- :params => {
- :user_id => 2,
- :id => email.id
- },
- :xhr => true
- )
- mail = ActionMailer::Base.deliveries.last
- assert_not_nil mail
- assert_mail_body_match I18n.t(:mail_body_security_notification_remove, field: I18n.t(:field_mail), value: 'another@somenet.foo'), mail
-
- # The removed address should be notified for security purposes
- assert mail.to.include?('another@somenet.foo')
- end
- end
|