e2e/edit_test.go

00033f022fed6fe0b36e1d7a1e2b3f1df6139ccd
gitbay/e2e/edit_test.go history · blame · raw

110 lines · 4546 bytes

  1package e2e
  2
  3import (
  4	"encoding/json"
  5	"net/url"
  6	"os"
  7	"path/filepath"
  8	"strings"
  9	"testing"
 10)
 11
 12func TestIssueMREditing(t *testing.T) {
 13	inst := startInstanceWith(t, "[web]\nmode = \"accounts\"\n")
 14	aliceKey := inst.newKey(t, "alice")
 15	bobKey := inst.newKey(t, "bob")
 16	eveKey := inst.newKey(t, "eve")
 17	inst.admin(t, "admin", "user", "create", "alice",
 18		"--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
 19	inst.admin(t, "admin", "user", "create", "bob", "--key", bobKey+".pub")
 20	inst.admin(t, "admin", "user", "create", "eve", "--key", eveKey+".pub")
 21
 22	if _, _, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/app"); code != 0 {
 23		t.Fatal("repo create failed")
 24	}
 25	// bob authors an issue (no write access); eve is an outsider.
 26	if _, _, code := inst.ssh(t, bobKey, "", "issue", "create", "alice/app", "--title", "'typo titel'", "--body", "'first'"); code != 0 {
 27		t.Fatal("issue create failed")
 28	}
 29
 30	// SSH edit: the author may fix it; an outsider may not; empty titles
 31	// are refused; write access (alice) may edit someone else's.
 32	if _, errOut, code := inst.ssh(t, bobKey, "", "issue", "edit", "alice/app", "1", "--title", "'typo title'"); code != 0 {
 33		t.Fatalf("author edit: %s", errOut)
 34	}
 35	if _, _, code := inst.ssh(t, eveKey, "", "issue", "edit", "alice/app", "1", "--title", "'hax'"); code != 4 {
 36		t.Fatal("outsider edited an issue")
 37	}
 38	if _, _, code := inst.ssh(t, bobKey, "", "issue", "edit", "alice/app", "1", "--title", "''"); code != 2 {
 39		t.Fatal("empty title accepted")
 40	}
 41	if _, _, code := inst.ssh(t, aliceKey, "", "issue", "edit", "alice/app", "1", "--body", "'rewritten'"); code != 0 {
 42		t.Fatal("write-access edit failed")
 43	}
 44	out, _, _ := inst.ssh(t, aliceKey, "", "issue", "show", "alice/app", "1", "--json")
 45	if !strings.Contains(out, "typo title") || !strings.Contains(out, "rewritten") {
 46		t.Fatalf("edits not applied: %s", out)
 47	}
 48
 49	// MR edit over SSH.
 50	work := t.TempDir()
 51	env := inst.gitEnv(aliceKey)
 52	mustGit(t, work, env, "clone", inst.sshURL("alice/app"), "w")
 53	dir := filepath.Join(work, "w")
 54	os.WriteFile(filepath.Join(dir, "a.txt"), []byte("a\n"), 0o644)
 55	mustGit(t, dir, env, "checkout", "-q", "-b", "main")
 56	mustGit(t, dir, env, "add", ".")
 57	mustGit(t, dir, env, "commit", "-q", "-m", "base")
 58	mustGit(t, dir, env, "push", "-q", "origin", "main")
 59	mustGit(t, dir, env, "checkout", "-q", "-b", "feat")
 60	os.WriteFile(filepath.Join(dir, "b.txt"), []byte("b\n"), 0o644)
 61	mustGit(t, dir, env, "add", ".")
 62	mustGit(t, dir, env, "commit", "-q", "-m", "feat")
 63	mustGit(t, dir, env, "push", "-q", "origin", "feat")
 64	if _, _, code := inst.ssh(t, aliceKey, "", "mr", "create", "alice/app",
 65		"--source", "feat", "--target", "main", "--title", "'draft'"); code != 0 {
 66		t.Fatal("mr create failed")
 67	}
 68	if _, _, code := inst.ssh(t, aliceKey, "", "mr", "edit", "alice/app", "1", "--title", "'ready'"); code != 0 {
 69		t.Fatal("mr edit failed")
 70	}
 71	if out, _, _ := inst.ssh(t, aliceKey, "", "mr", "show", "alice/app", "1", "--json"); !strings.Contains(out, "ready") {
 72		t.Fatalf("mr edit not applied: %s", out)
 73	}
 74
 75	// Web edit: form appears for the authorized viewer, POST applies, and
 76	// with write access the label set is replaced.
 77	out, _, code := inst.ssh(t, aliceKey, "", "web", "login", "--json")
 78	if code != 0 {
 79		t.Fatal("web login failed")
 80	}
 81	var env2 struct {
 82		Data struct {
 83			URL string `json:"url"`
 84		} `json:"data"`
 85	}
 86	json.Unmarshal([]byte(out), &env2)
 87	browser := newBrowser(t)
 88	browserGet(t, browser, inst.base()+env2.Data.URL[strings.Index(env2.Data.URL, "/login"):])
 89	_, body := browserGet(t, browser, inst.base()+"/alice/app/issues/1")
 90	if !strings.Contains(body, "/alice/app/issues/1/edit") {
 91		t.Fatal("edit form missing for authorized viewer")
 92	}
 93	if status, _ := browserPost(t, browser, inst.base()+"/alice/app/issues/1/edit",
 94		url.Values{"title": {"web-edited"}, "body": {"web body"}, "labels": {"bug"}}); status != 200 {
 95		t.Fatal("web issue edit failed")
 96	}
 97	out, _, _ = inst.ssh(t, aliceKey, "", "issue", "show", "alice/app", "1", "--json")
 98	if !strings.Contains(out, "web-edited") || !strings.Contains(out, `"labels":["bug"]`) {
 99		t.Fatalf("web edit not applied: %s", out)
100	}
101	if status, _ := browserPost(t, browser, inst.base()+"/alice/app/mrs/1/edit",
102		url.Values{"title": {"web-mr"}, "body": {"mb"}}); status != 200 {
103		t.Fatal("web mr edit failed")
104	}
105	// Anonymous view shows no edit affordance.
106	_, body = inst.get(t, "/alice/app/issues/1")
107	if strings.Contains(body, "/issues/1/edit") {
108		t.Fatal("edit form leaked to anonymous viewer")
109	}
110}