b93e14ae88f05c6e01d25ab41d2ecb7456d769b3 / internal/web/profile_test.go · 1859 bytes · raw
package web
import (
"net/http"
"strings"
"testing"
)
func TestProfileAnonymousListsPublicOnly(t *testing.T) {
httpServer, _, _ := newTestServer(t)
loggedIn := newLoggedInClient(t, httpServer)
createRepo(t, loggedIn, httpServer, "pub", "public")
createRepo(t, loggedIn, httpServer, "sec", "private")
resp, err := (&http.Client{}).Get(httpServer.URL + "/josie")
if err != nil {
t.Fatalf("GET /josie: %v", err)
}
body := readAll(t, resp)
if resp.StatusCode != http.StatusOK {
t.Fatalf("status = %d, want 200: %q", resp.StatusCode, body)
}
if !strings.Contains(body, "/josie/pub") {
t.Error("public repo missing from profile")
}
if strings.Contains(body, "/josie/sec") {
t.Error("private repo leaked to anonymous profile")
}
if strings.Contains(body, "sign out") {
t.Error("anonymous profile shows account actions")
}
}
func TestProfileOwnerShowsAccountActions(t *testing.T) {
httpServer, _, _ := newTestServer(t)
loggedIn := newLoggedInClient(t, httpServer)
createRepo(t, loggedIn, httpServer, "sec", "private")
resp, err := loggedIn.Get(httpServer.URL + "/josie")
if err != nil {
t.Fatalf("GET /josie: %v", err)
}
body := readAll(t, resp)
if resp.StatusCode != http.StatusOK {
t.Fatalf("status = %d, want 200: %q", resp.StatusCode, body)
}
if !strings.Contains(body, "/josie/sec") {
t.Error("owner profile missing private repo")
}
if !strings.Contains(body, "sign out") || !strings.Contains(body, `href="/settings"`) {
t.Errorf("owner profile lacks sign out/settings: %q", body)
}
}
func TestProfileUnknownUser(t *testing.T) {
httpServer, _, _ := newTestServer(t)
resp, err := (&http.Client{}).Get(httpServer.URL + "/nobody")
if err != nil {
t.Fatalf("GET /nobody: %v", err)
}
readAll(t, resp)
if resp.StatusCode != http.StatusNotFound {
t.Errorf("status = %d, want 404", resp.StatusCode)
}
}