package web import ( "net/http" "strings" "testing" ) func TestProfileAnonymousListsPublicOnly(t *testing.T) { httpServer, _, _ := newTestServer(t) loggedIn := newLoggedInClient(t, httpServer) createRepo(t, loggedIn, httpServer, "pub", "public") createRepo(t, loggedIn, httpServer, "sec", "private") resp, err := (&http.Client{}).Get(httpServer.URL + "/josie") if err != nil { t.Fatalf("GET /josie: %v", err) } body := readAll(t, resp) if resp.StatusCode != http.StatusOK { t.Fatalf("status = %d, want 200: %q", resp.StatusCode, body) } if !strings.Contains(body, "/josie/pub") { t.Error("public repo missing from profile") } if strings.Contains(body, "/josie/sec") { t.Error("private repo leaked to anonymous profile") } if strings.Contains(body, "sign out") { t.Error("anonymous profile shows account actions") } } func TestProfileOwnerShowsAccountActions(t *testing.T) { httpServer, _, _ := newTestServer(t) loggedIn := newLoggedInClient(t, httpServer) createRepo(t, loggedIn, httpServer, "sec", "private") resp, err := loggedIn.Get(httpServer.URL + "/josie") if err != nil { t.Fatalf("GET /josie: %v", err) } body := readAll(t, resp) if resp.StatusCode != http.StatusOK { t.Fatalf("status = %d, want 200: %q", resp.StatusCode, body) } if !strings.Contains(body, "/josie/sec") { t.Error("owner profile missing private repo") } if !strings.Contains(body, "sign out") || !strings.Contains(body, `href="/settings"`) { t.Errorf("owner profile lacks sign out/settings: %q", body) } } func TestProfileUnknownUser(t *testing.T) { httpServer, _, _ := newTestServer(t) resp, err := (&http.Client{}).Get(httpServer.URL + "/nobody") if err != nil { t.Fatalf("GET /nobody: %v", err) } readAll(t, resp) if resp.StatusCode != http.StatusNotFound { t.Errorf("status = %d, want 404", resp.StatusCode) } }