data:image/s3,"s3://crabby-images/7cd25/7cd25c32e50a87def7b33b7a6c50d83d0059d5bb" alt="Yarden Shoham"
We need to make sure a user can't confirm the existence of a user with private visibility * Follow up on #21533 ### Before #### User data:image/s3,"s3://crabby-images/99114/991146edef092798e60a0dc0c36d5743db06cd32" alt="image" #### Admin data:image/s3,"s3://crabby-images/d9c4b/d9c4bea57e2db350f498699e2914830cfeb738d2" alt="image" ### After #### User data:image/s3,"s3://crabby-images/39532/39532c65e6d049dcf8a272215dc1636a58106591" alt="image" #### Admin data:image/s3,"s3://crabby-images/56fec/56fecb8e3c133357b5a8ac8b96a48e1a7475835a" alt="image" Signed-off-by: Yarden Shoham <hrsi88@gmail.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
53 lines
1.9 KiB
Go
53 lines
1.9 KiB
Go
// Copyright 2022 The Gitea Authors. All rights reserved.
|
|
// Use of this source code is governed by a MIT-style
|
|
// license that can be found in the LICENSE file.
|
|
|
|
package markup
|
|
|
|
import (
|
|
"context"
|
|
"net/http"
|
|
"testing"
|
|
|
|
"code.gitea.io/gitea/models/db"
|
|
"code.gitea.io/gitea/models/unittest"
|
|
"code.gitea.io/gitea/models/user"
|
|
gitea_context "code.gitea.io/gitea/modules/context"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestProcessorHelper(t *testing.T) {
|
|
assert.NoError(t, unittest.PrepareTestDatabase())
|
|
|
|
userPublic := "user1"
|
|
userPrivate := "user31"
|
|
userLimited := "user33"
|
|
userNoSuch := "no-such-user"
|
|
|
|
unittest.AssertCount(t, &user.User{Name: userPublic}, 1)
|
|
unittest.AssertCount(t, &user.User{Name: userPrivate}, 1)
|
|
unittest.AssertCount(t, &user.User{Name: userLimited}, 1)
|
|
unittest.AssertCount(t, &user.User{Name: userNoSuch}, 0)
|
|
|
|
// when using general context, use user's visibility to check
|
|
assert.True(t, ProcessorHelper().IsUsernameMentionable(context.Background(), userPublic))
|
|
assert.False(t, ProcessorHelper().IsUsernameMentionable(context.Background(), userLimited))
|
|
assert.False(t, ProcessorHelper().IsUsernameMentionable(context.Background(), userPrivate))
|
|
assert.False(t, ProcessorHelper().IsUsernameMentionable(context.Background(), userNoSuch))
|
|
|
|
// when using web context, use user.IsUserVisibleToViewer to check
|
|
var err error
|
|
giteaCtx := &gitea_context.Context{}
|
|
giteaCtx.Req, err = http.NewRequest("GET", "/", nil)
|
|
assert.NoError(t, err)
|
|
|
|
giteaCtx.Doer = nil
|
|
assert.True(t, ProcessorHelper().IsUsernameMentionable(giteaCtx, userPublic))
|
|
assert.False(t, ProcessorHelper().IsUsernameMentionable(giteaCtx, userPrivate))
|
|
|
|
giteaCtx.Doer, err = user.GetUserByName(db.DefaultContext, userPrivate)
|
|
assert.NoError(t, err)
|
|
assert.True(t, ProcessorHelper().IsUsernameMentionable(giteaCtx, userPublic))
|
|
assert.True(t, ProcessorHelper().IsUsernameMentionable(giteaCtx, userPrivate))
|
|
}
|