e2e/edit_test.go
110 lines · 4546 bytes
1package e2e
2
3import (
4 "encoding/json"
5 "net/url"
6 "os"
7 "path/filepath"
8 "strings"
9 "testing"
10)
11
12func TestIssueMREditing(t *testing.T) {
13 inst := startInstanceWith(t, "[web]\nmode = \"accounts\"\n")
14 aliceKey := inst.newKey(t, "alice")
15 bobKey := inst.newKey(t, "bob")
16 eveKey := inst.newKey(t, "eve")
17 inst.admin(t, "admin", "user", "create", "alice",
18 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
19 inst.admin(t, "admin", "user", "create", "bob", "--key", bobKey+".pub")
20 inst.admin(t, "admin", "user", "create", "eve", "--key", eveKey+".pub")
21
22 if _, _, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/app"); code != 0 {
23 t.Fatal("repo create failed")
24 }
25 // bob authors an issue (no write access); eve is an outsider.
26 if _, _, code := inst.ssh(t, bobKey, "", "issue", "create", "alice/app", "--title", "'typo titel'", "--body", "'first'"); code != 0 {
27 t.Fatal("issue create failed")
28 }
29
30 // SSH edit: the author may fix it; an outsider may not; empty titles
31 // are refused; write access (alice) may edit someone else's.
32 if _, errOut, code := inst.ssh(t, bobKey, "", "issue", "edit", "alice/app", "1", "--title", "'typo title'"); code != 0 {
33 t.Fatalf("author edit: %s", errOut)
34 }
35 if _, _, code := inst.ssh(t, eveKey, "", "issue", "edit", "alice/app", "1", "--title", "'hax'"); code != 4 {
36 t.Fatal("outsider edited an issue")
37 }
38 if _, _, code := inst.ssh(t, bobKey, "", "issue", "edit", "alice/app", "1", "--title", "''"); code != 2 {
39 t.Fatal("empty title accepted")
40 }
41 if _, _, code := inst.ssh(t, aliceKey, "", "issue", "edit", "alice/app", "1", "--body", "'rewritten'"); code != 0 {
42 t.Fatal("write-access edit failed")
43 }
44 out, _, _ := inst.ssh(t, aliceKey, "", "issue", "show", "alice/app", "1", "--json")
45 if !strings.Contains(out, "typo title") || !strings.Contains(out, "rewritten") {
46 t.Fatalf("edits not applied: %s", out)
47 }
48
49 // MR edit over SSH.
50 work := t.TempDir()
51 env := inst.gitEnv(aliceKey)
52 mustGit(t, work, env, "clone", inst.sshURL("alice/app"), "w")
53 dir := filepath.Join(work, "w")
54 os.WriteFile(filepath.Join(dir, "a.txt"), []byte("a\n"), 0o644)
55 mustGit(t, dir, env, "checkout", "-q", "-b", "main")
56 mustGit(t, dir, env, "add", ".")
57 mustGit(t, dir, env, "commit", "-q", "-m", "base")
58 mustGit(t, dir, env, "push", "-q", "origin", "main")
59 mustGit(t, dir, env, "checkout", "-q", "-b", "feat")
60 os.WriteFile(filepath.Join(dir, "b.txt"), []byte("b\n"), 0o644)
61 mustGit(t, dir, env, "add", ".")
62 mustGit(t, dir, env, "commit", "-q", "-m", "feat")
63 mustGit(t, dir, env, "push", "-q", "origin", "feat")
64 if _, _, code := inst.ssh(t, aliceKey, "", "mr", "create", "alice/app",
65 "--source", "feat", "--target", "main", "--title", "'draft'"); code != 0 {
66 t.Fatal("mr create failed")
67 }
68 if _, _, code := inst.ssh(t, aliceKey, "", "mr", "edit", "alice/app", "1", "--title", "'ready'"); code != 0 {
69 t.Fatal("mr edit failed")
70 }
71 if out, _, _ := inst.ssh(t, aliceKey, "", "mr", "show", "alice/app", "1", "--json"); !strings.Contains(out, "ready") {
72 t.Fatalf("mr edit not applied: %s", out)
73 }
74
75 // Web edit: form appears for the authorized viewer, POST applies, and
76 // with write access the label set is replaced.
77 out, _, code := inst.ssh(t, aliceKey, "", "web", "login", "--json")
78 if code != 0 {
79 t.Fatal("web login failed")
80 }
81 var env2 struct {
82 Data struct {
83 URL string `json:"url"`
84 } `json:"data"`
85 }
86 json.Unmarshal([]byte(out), &env2)
87 browser := newBrowser(t)
88 browserGet(t, browser, inst.base()+env2.Data.URL[strings.Index(env2.Data.URL, "/login"):])
89 _, body := browserGet(t, browser, inst.base()+"/alice/app/issues/1")
90 if !strings.Contains(body, "/alice/app/issues/1/edit") {
91 t.Fatal("edit form missing for authorized viewer")
92 }
93 if status, _ := browserPost(t, browser, inst.base()+"/alice/app/issues/1/edit",
94 url.Values{"title": {"web-edited"}, "body": {"web body"}, "labels": {"bug"}}); status != 200 {
95 t.Fatal("web issue edit failed")
96 }
97 out, _, _ = inst.ssh(t, aliceKey, "", "issue", "show", "alice/app", "1", "--json")
98 if !strings.Contains(out, "web-edited") || !strings.Contains(out, `"labels":["bug"]`) {
99 t.Fatalf("web edit not applied: %s", out)
100 }
101 if status, _ := browserPost(t, browser, inst.base()+"/alice/app/mrs/1/edit",
102 url.Values{"title": {"web-mr"}, "body": {"mb"}}); status != 200 {
103 t.Fatal("web mr edit failed")
104 }
105 // Anonymous view shows no edit affordance.
106 _, body = inst.get(t, "/alice/app/issues/1")
107 if strings.Contains(body, "/issues/1/edit") {
108 t.Fatal("edit form leaked to anonymous viewer")
109 }
110}