2019-10-28 20:06:10 -04:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2012-11-27 14:43:39 -05:00
|
|
|
require 'spec_helper'
|
|
|
|
|
2020-06-24 02:09:01 -04:00
|
|
|
RSpec.describe API::Notes do
|
2020-03-23 08:09:47 -04:00
|
|
|
let!(:user) { create(:user) }
|
|
|
|
let!(:project) { create(:project, :public) }
|
2019-01-16 07:09:29 -05:00
|
|
|
let(:private_user) { create(:user) }
|
2016-01-13 13:42:36 -05:00
|
|
|
|
2017-06-14 14:18:56 -04:00
|
|
|
before do
|
2017-12-22 03:18:28 -05:00
|
|
|
project.add_reporter(user)
|
2017-06-14 14:18:56 -04:00
|
|
|
end
|
2012-11-27 14:43:39 -05:00
|
|
|
|
2019-08-22 03:19:44 -04:00
|
|
|
context 'when there are cross-reference system notes' do
|
|
|
|
let(:url) { "/projects/#{project.id}/merge_requests/#{merge_request.iid}/notes" }
|
|
|
|
let(:notes_in_response) { json_response }
|
|
|
|
|
|
|
|
it_behaves_like 'with cross-reference system notes'
|
|
|
|
end
|
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "when noteable is an Issue" do
|
|
|
|
let!(:issue) { create(:issue, project: project, author: user) }
|
|
|
|
let!(:issue_note) { create(:note, noteable: issue, project: project, author: user) }
|
2017-11-29 11:22:22 -05:00
|
|
|
|
2022-04-08 14:08:29 -04:00
|
|
|
it_behaves_like "noteable API with confidential notes", 'projects', 'issues', 'iid' do
|
2018-02-28 02:48:23 -05:00
|
|
|
let(:parent) { project }
|
|
|
|
let(:noteable) { issue }
|
|
|
|
let(:note) { issue_note }
|
|
|
|
end
|
2017-11-29 11:22:22 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context 'when user does not have access to create noteable' do
|
|
|
|
let(:private_issue) { create(:issue, project: create(:project, :private)) }
|
2017-11-29 11:22:22 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
##
|
|
|
|
# We are posting to project user has access to, but we use issue id
|
|
|
|
# from a different project, see #15577
|
|
|
|
#
|
|
|
|
before do
|
|
|
|
post api("/projects/#{private_issue.project.id}/issues/#{private_issue.iid}/notes", user),
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { body: 'Hi!' }
|
2018-02-28 02:48:23 -05:00
|
|
|
end
|
2017-11-29 11:22:22 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
it 'responds with resource not found error' do
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:not_found)
|
2017-11-29 11:22:22 -05:00
|
|
|
end
|
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
it 'does not create new note' do
|
|
|
|
expect(private_issue.notes.reload).to be_empty
|
|
|
|
end
|
|
|
|
end
|
2016-05-10 15:06:02 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "when referencing other project" do
|
|
|
|
# For testing the cross-reference of a private issue in a public project
|
|
|
|
let(:private_project) do
|
|
|
|
create(:project, namespace: private_user.namespace)
|
2018-07-11 10:36:08 -04:00
|
|
|
.tap { |p| p.add_maintainer(private_user) }
|
2012-11-27 14:43:39 -05:00
|
|
|
end
|
2020-08-10 23:11:00 -04:00
|
|
|
|
2019-01-16 07:09:29 -05:00
|
|
|
let(:private_issue) { create(:issue, project: private_project) }
|
2013-02-06 10:34:06 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
let(:ext_proj) { create(:project, :public) }
|
|
|
|
let(:ext_issue) { create(:issue, project: ext_proj) }
|
2016-05-10 15:06:02 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
let!(:cross_reference_note) do
|
|
|
|
create :note,
|
|
|
|
noteable: ext_issue, project: ext_proj,
|
|
|
|
note: "mentioned in issue #{private_issue.to_reference(ext_proj)}",
|
|
|
|
system: true
|
2013-02-06 10:34:06 -05:00
|
|
|
end
|
2016-01-13 13:42:36 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
describe "GET /projects/:id/noteable/:noteable_id/notes" do
|
|
|
|
context "current user cannot view the notes" do
|
|
|
|
it "returns an empty array" do
|
|
|
|
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes", user)
|
2016-01-13 13:42:36 -05:00
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:ok)
|
2018-02-28 02:48:23 -05:00
|
|
|
expect(response).to include_pagination_headers
|
|
|
|
expect(json_response).to be_an Array
|
|
|
|
expect(json_response).to be_empty
|
2017-06-14 14:18:56 -04:00
|
|
|
end
|
2016-05-09 18:35:37 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "issue is confidential" do
|
|
|
|
before do
|
2020-09-08 05:08:31 -04:00
|
|
|
ext_issue.update!(confidential: true)
|
2018-02-28 02:48:23 -05:00
|
|
|
end
|
2016-05-10 15:06:02 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
it "returns 404" do
|
|
|
|
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes", user)
|
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:not_found)
|
2018-02-28 02:48:23 -05:00
|
|
|
end
|
2016-05-09 18:35:37 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "current user can view the note" do
|
2019-12-10 02:53:40 -05:00
|
|
|
it "returns a non-empty array" do
|
2017-03-27 09:01:45 -04:00
|
|
|
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes", private_user)
|
2016-05-10 15:06:02 -04:00
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:ok)
|
2017-01-24 15:49:10 -05:00
|
|
|
expect(response).to include_pagination_headers
|
2016-01-13 13:42:36 -05:00
|
|
|
expect(json_response).to be_an Array
|
|
|
|
expect(json_response.first['body']).to eq(cross_reference_note.note)
|
|
|
|
end
|
2020-01-03 04:07:33 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
context "activity filters" do
|
|
|
|
let!(:user_reference_note) do
|
|
|
|
create :note,
|
|
|
|
noteable: ext_issue, project: ext_proj,
|
|
|
|
note: "Hello there general!",
|
|
|
|
system: false
|
|
|
|
end
|
|
|
|
|
2022-07-29 14:08:58 -04:00
|
|
|
let(:test_url) { "/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes" }
|
2020-01-03 04:07:33 -05:00
|
|
|
|
|
|
|
shared_examples 'a notes request' do
|
|
|
|
it 'is a note array response' do
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:ok)
|
2020-01-03 04:07:33 -05:00
|
|
|
expect(response).to include_pagination_headers
|
|
|
|
expect(json_response).to be_an Array
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context "when not provided" do
|
|
|
|
let(:count) { 2 }
|
|
|
|
|
|
|
|
before do
|
|
|
|
get api(test_url, private_user)
|
|
|
|
end
|
|
|
|
|
|
|
|
it_behaves_like 'a notes request'
|
|
|
|
|
|
|
|
it 'returns all the notes' do
|
|
|
|
expect(json_response.count).to eq(count)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context "when all_notes provided" do
|
|
|
|
let(:count) { 2 }
|
|
|
|
|
|
|
|
before do
|
|
|
|
get api(test_url + "?activity_filter=all_notes", private_user)
|
|
|
|
end
|
|
|
|
|
|
|
|
it_behaves_like 'a notes request'
|
|
|
|
|
|
|
|
it 'returns all the notes' do
|
|
|
|
expect(json_response.count).to eq(count)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context "when provided" do
|
|
|
|
using RSpec::Parameterized::TableSyntax
|
|
|
|
|
|
|
|
where(:filter, :count, :system_notable) do
|
|
|
|
"only_comments" | 1 | false
|
|
|
|
"only_activity" | 1 | true
|
|
|
|
end
|
|
|
|
|
|
|
|
with_them do
|
|
|
|
before do
|
|
|
|
get api(test_url + "?activity_filter=#{filter}", private_user)
|
|
|
|
end
|
|
|
|
|
|
|
|
it_behaves_like 'a notes request'
|
|
|
|
|
|
|
|
it "properly filters the returned notables" do
|
|
|
|
expect(json_response.count).to eq(count)
|
|
|
|
expect(json_response.first["system"]).to be system_notable
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2016-01-13 13:42:36 -05:00
|
|
|
end
|
|
|
|
end
|
2017-11-29 11:22:22 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
describe "GET /projects/:id/noteable/:noteable_id/notes/:note_id" do
|
|
|
|
context "current user cannot view the notes" do
|
|
|
|
it "returns a 404 error" do
|
|
|
|
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes/#{cross_reference_note.id}", user)
|
2017-11-29 11:22:22 -05:00
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:not_found)
|
2017-06-14 14:18:56 -04:00
|
|
|
end
|
2016-05-16 15:43:19 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "when issue is confidential" do
|
|
|
|
before do
|
2020-09-08 05:08:31 -04:00
|
|
|
issue.update!(confidential: true)
|
2018-02-28 02:48:23 -05:00
|
|
|
end
|
2016-05-16 15:43:19 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
it "returns 404" do
|
|
|
|
get api("/projects/#{project.id}/issues/#{issue.iid}/notes/#{issue_note.id}", private_user)
|
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:not_found)
|
2018-02-28 02:48:23 -05:00
|
|
|
end
|
2016-05-16 15:43:19 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "current user can view the note" do
|
2016-08-01 11:00:44 -04:00
|
|
|
it "returns an issue note by id" do
|
2017-03-27 09:01:45 -04:00
|
|
|
get api("/projects/#{ext_proj.id}/issues/#{ext_issue.iid}/notes/#{cross_reference_note.id}", private_user)
|
2016-05-10 15:06:02 -04:00
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:ok)
|
2016-01-13 13:42:36 -05:00
|
|
|
expect(json_response['body']).to eq(cross_reference_note.note)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2012-11-29 14:33:41 -05:00
|
|
|
end
|
|
|
|
end
|
2012-11-29 15:06:24 -05:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "when noteable is a Snippet" do
|
|
|
|
let!(:snippet) { create(:project_snippet, project: project, author: user) }
|
|
|
|
let!(:snippet_note) { create(:note, noteable: snippet, project: project, author: user) }
|
2016-05-10 15:06:02 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
it_behaves_like "noteable API", 'projects', 'snippets', 'id' do
|
|
|
|
let(:parent) { project }
|
|
|
|
let(:noteable) { snippet }
|
|
|
|
let(:note) { snippet_note }
|
2013-02-20 16:17:05 -05:00
|
|
|
end
|
2018-02-28 02:48:23 -05:00
|
|
|
end
|
2016-04-26 12:55:38 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
context "when noteable is a Merge Request" do
|
|
|
|
let!(:merge_request) { create(:merge_request, source_project: project, target_project: project, author: user) }
|
|
|
|
let!(:merge_request_note) { create(:note, noteable: merge_request, project: project, author: user) }
|
2016-04-26 12:55:38 -04:00
|
|
|
|
2018-02-28 02:48:23 -05:00
|
|
|
it_behaves_like "noteable API", 'projects', 'merge_requests', 'iid' do
|
|
|
|
let(:parent) { project }
|
|
|
|
let(:noteable) { merge_request }
|
|
|
|
let(:note) { merge_request_note }
|
2016-04-26 12:55:38 -04:00
|
|
|
end
|
2017-09-01 08:03:57 -04:00
|
|
|
|
2020-03-23 08:09:47 -04:00
|
|
|
let(:request_body) { 'Hi!' }
|
2022-03-15 05:07:33 -04:00
|
|
|
let(:params) { { body: request_body } }
|
2020-03-23 08:09:47 -04:00
|
|
|
let(:request_path) { "/projects/#{project.id}/merge_requests/#{merge_request.iid}/notes" }
|
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
subject { post api(request_path, user), params: params }
|
2020-03-23 08:09:47 -04:00
|
|
|
|
|
|
|
context 'a command only note' do
|
2022-03-15 05:07:33 -04:00
|
|
|
context '/spend' do
|
|
|
|
let(:request_body) { "/spend 1h" }
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
before do
|
|
|
|
project.add_developer(user)
|
|
|
|
end
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
it 'returns 202 Accepted status' do
|
|
|
|
subject
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:accepted)
|
|
|
|
end
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
it 'does not actually create a new note' do
|
|
|
|
expect { subject }.not_to change { Note.where(system: false).count }
|
|
|
|
end
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
it 'does however create a system note about the change', :sidekiq_inline do
|
|
|
|
expect { subject }.to change { Note.system.count }.by(1)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'applies the commands' do
|
|
|
|
expect { subject }.to change { merge_request.reset.total_time_spent }
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'reports the changes' do
|
|
|
|
subject
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
expect(json_response).to include(
|
|
|
|
'commands_changes' => include(
|
|
|
|
'spend_time' => include('duration' => 3600)
|
|
|
|
),
|
|
|
|
'summary' => include('Added 1h spent time.')
|
|
|
|
)
|
|
|
|
end
|
2020-03-23 08:09:47 -04:00
|
|
|
end
|
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
context '/merge' do
|
|
|
|
let(:request_body) { "/merge" }
|
|
|
|
let(:project) { create(:project, :public, :repository) }
|
|
|
|
let(:merge_request) { create(:merge_request_with_multiple_diffs, source_project: project, target_project: project, author: user) }
|
|
|
|
let(:params) { { body: request_body, merge_request_diff_head_sha: merge_request.diff_head_sha } }
|
|
|
|
|
|
|
|
before do
|
|
|
|
project.add_developer(user)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'returns 202 Accepted status' do
|
|
|
|
subject
|
|
|
|
|
|
|
|
expect(response).to have_gitlab_http_status(:accepted)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'does not actually create a new note' do
|
|
|
|
expect { subject }.not_to change { Note.where(system: false).count }
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'applies the commands' do
|
|
|
|
expect { subject }.to change { merge_request.reload.merge_jid.present? }.from(false).to(true)
|
|
|
|
end
|
2020-03-23 08:09:47 -04:00
|
|
|
|
2022-03-15 05:07:33 -04:00
|
|
|
it 'reports the changes' do
|
|
|
|
subject
|
|
|
|
|
|
|
|
expect(json_response).to include(
|
|
|
|
'commands_changes' => include(
|
|
|
|
'merge' => merge_request.diff_head_sha
|
|
|
|
),
|
|
|
|
'summary' => ['Merged this merge request.']
|
|
|
|
)
|
|
|
|
end
|
2020-03-23 08:09:47 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-09-01 08:03:57 -04:00
|
|
|
context 'when the merge request discussion is locked' do
|
|
|
|
before do
|
|
|
|
merge_request.update_attribute(:discussion_locked, true)
|
|
|
|
end
|
|
|
|
|
|
|
|
context 'when a user is a team member' do
|
|
|
|
it 'returns 200 status' do
|
|
|
|
subject
|
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:created)
|
2017-09-01 08:03:57 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it 'creates a new note' do
|
|
|
|
expect { subject }.to change { Note.count }.by(1)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context 'when a user is not a team member' do
|
2018-12-17 17:52:17 -05:00
|
|
|
subject { post api("/projects/#{project.id}/merge_requests/#{merge_request.iid}/notes", private_user), params: { body: 'Hi!' } }
|
2017-09-01 08:03:57 -04:00
|
|
|
|
|
|
|
it 'returns 403 status' do
|
|
|
|
subject
|
|
|
|
|
2020-02-26 10:08:56 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:forbidden)
|
2017-09-01 08:03:57 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it 'does not create a new note' do
|
|
|
|
expect { subject }.not_to change { Note.count }
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2012-11-29 15:06:24 -05:00
|
|
|
end
|
2012-11-27 14:43:39 -05:00
|
|
|
end
|