e2e/webwrites_test.go
73 lines · 2927 bytes
1package e2e
2
3import (
4 "encoding/json"
5 "net/url"
6 "strings"
7 "testing"
8)
9
10// Web writes dispatch the command the CLI runs, so a rule the command
11// layer enforces holds from a browser too. Repo create used to call the
12// store directly and skip the per-account quota; issue comments skipped
13// the archived check (#93).
14func TestWebWritesGoThroughRegistry(t *testing.T) {
15 t.Parallel()
16 inst := startInstanceWith(t, "[web]\nmode = \"accounts\"\n[limits]\nmax_repos_per_user = 1\n")
17 aliceKey := inst.newKey(t, "alice")
18 inst.admin(t, "admin", "user", "create", "alice",
19 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
20 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/first"); code != 0 {
21 t.Fatalf("repo create: %s", errOut)
22 }
23 if _, errOut, code := inst.ssh(t, aliceKey, "", "issue", "create", "alice/first", "--title", "one"); code != 0 {
24 t.Fatalf("issue create: %s", errOut)
25 }
26
27 out, errOut, code := inst.ssh(t, aliceKey, "", "web", "login", "--json")
28 if code != 0 {
29 t.Fatalf("web login: %s", errOut)
30 }
31 var env struct {
32 Data struct {
33 URL string `json:"url"`
34 } `json:"data"`
35 }
36 if err := json.Unmarshal([]byte(out), &env); err != nil {
37 t.Fatalf("web login JSON: %v\n%s", err, out)
38 }
39 browser := newBrowser(t)
40 if status, _ := browserGet(t, browser, inst.base()+env.Data.URL[strings.Index(env.Data.URL, "/login"):]); status != 200 {
41 t.Fatalf("login: %d", status)
42 }
43
44 // The quota holds on the web: the form comes back with the refusal and
45 // no repository exists.
46 status, body := browserPost(t, browser, inst.base()+"/new", url.Values{"name": {"second"}, "visibility": {"public"}})
47 if status != 200 || !strings.Contains(body, "role=\"alert\"") {
48 t.Fatalf("second repo over quota was not refused on the form: %d\n%s", status, body)
49 }
50 if _, _, code := inst.ssh(t, aliceKey, "", "repo", "show", "alice/second"); code != 3 {
51 t.Fatalf("repo created past the quota from the web: exit %d, want 3", code)
52 }
53
54 // A form action on an issue that does not exist is the 404 page, not a
55 // redirect carrying a message (#106).
56 if status, _ := browserPost(t, browser, inst.base()+"/alice/first/issues/999/state", url.Values{"action": {"close"}}); status != 404 {
57 t.Fatalf("closing a missing issue from the web: %d, want 404", status)
58 }
59
60 // An archived repository refuses a comment from the web as it does
61 // over ssh.
62 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "archive", "alice/first"); code != 0 {
63 t.Fatalf("repo archive: %s", errOut)
64 }
65 status, _ = browserPost(t, browser, inst.base()+"/alice/first/issues/1/comment", url.Values{"body": {"late"}})
66 if status/100 != 4 {
67 t.Fatalf("comment on an archived repo from the web: %d, want 4xx", status)
68 }
69 show, _, _ := inst.ssh(t, aliceKey, "", "issue", "show", "alice/first", "1")
70 if strings.Contains(show, "late") {
71 t.Fatalf("archived repo took a web comment:\n%s", show)
72 }
73}