2019-04-15 06:17:05 -04:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2017-06-06 11:39:54 -04:00
|
|
|
require('spec_helper')
|
|
|
|
|
2020-06-03 14:08:28 -04:00
|
|
|
RSpec.describe ProfilesController, :request_store do
|
2021-09-29 08:11:22 -04:00
|
|
|
let(:password) { 'longsecret987!' }
|
|
|
|
let(:user) { create(:user, password: password) }
|
2017-10-17 06:12:24 -04:00
|
|
|
|
2018-05-04 13:24:55 -04:00
|
|
|
describe 'POST update' do
|
|
|
|
it 'does not update password' do
|
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
expect do
|
|
|
|
post :update,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { password: 'hello12345', password_confirmation: 'hello12345' } }
|
2018-05-04 13:24:55 -04:00
|
|
|
end.not_to change { user.reload.encrypted_password }
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2018-05-04 13:24:55 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-10-17 06:12:24 -04:00
|
|
|
describe 'PUT update' do
|
|
|
|
it 'allows an email update from a user without an external email address' do
|
2017-06-06 11:39:54 -04:00
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
put :update,
|
2021-09-29 08:11:22 -04:00
|
|
|
params: { user: { email: "john@gmail.com", name: "John", validation_password: password } }
|
2017-06-06 11:39:54 -04:00
|
|
|
|
|
|
|
user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2017-06-06 11:39:54 -04:00
|
|
|
expect(user.unconfirmed_email).to eq('john@gmail.com')
|
|
|
|
end
|
|
|
|
|
2017-09-18 13:00:38 -04:00
|
|
|
it "allows an email update without confirmation if existing verified email" do
|
|
|
|
user = create(:user)
|
2017-09-24 13:52:49 -04:00
|
|
|
create(:email, :confirmed, user: user, email: 'john@gmail.com')
|
2017-09-18 13:00:38 -04:00
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
put :update,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { email: "john@gmail.com", name: "John" } }
|
2017-09-18 13:00:38 -04:00
|
|
|
|
|
|
|
user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2017-09-18 13:00:38 -04:00
|
|
|
expect(user.unconfirmed_email).to eq nil
|
|
|
|
end
|
|
|
|
|
2017-10-17 06:12:24 -04:00
|
|
|
it 'ignores an email update from a user with an external email address' do
|
2017-08-29 04:57:41 -04:00
|
|
|
stub_omniauth_setting(sync_profile_from_provider: ['ldap'])
|
|
|
|
stub_omniauth_setting(sync_profile_attributes: true)
|
|
|
|
|
|
|
|
ldap_user = create(:omniauth_user)
|
|
|
|
ldap_user.create_user_synced_attributes_metadata(provider: 'ldap', name_synced: true, email_synced: true)
|
2017-06-06 11:39:54 -04:00
|
|
|
sign_in(ldap_user)
|
|
|
|
|
|
|
|
put :update,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { email: "john@gmail.com", name: "John" } }
|
2017-06-06 11:39:54 -04:00
|
|
|
|
|
|
|
ldap_user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2017-06-06 11:39:54 -04:00
|
|
|
expect(ldap_user.unconfirmed_email).not_to eq('john@gmail.com')
|
|
|
|
end
|
2017-08-29 04:57:41 -04:00
|
|
|
|
2017-10-17 06:12:24 -04:00
|
|
|
it 'ignores an email and name update but allows a location update from a user with external email and name, but not external location' do
|
2017-08-29 04:57:41 -04:00
|
|
|
stub_omniauth_setting(sync_profile_from_provider: ['ldap'])
|
|
|
|
stub_omniauth_setting(sync_profile_attributes: true)
|
|
|
|
|
|
|
|
ldap_user = create(:omniauth_user, name: 'Alex')
|
|
|
|
ldap_user.create_user_synced_attributes_metadata(provider: 'ldap', name_synced: true, email_synced: true, location_synced: false)
|
|
|
|
sign_in(ldap_user)
|
|
|
|
|
|
|
|
put :update,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { email: "john@gmail.com", name: "John", location: "City, Country" } }
|
2017-08-29 04:57:41 -04:00
|
|
|
|
|
|
|
ldap_user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2017-08-29 04:57:41 -04:00
|
|
|
expect(ldap_user.unconfirmed_email).not_to eq('john@gmail.com')
|
|
|
|
expect(ldap_user.name).not_to eq('John')
|
|
|
|
expect(ldap_user.location).to eq('City, Country')
|
|
|
|
end
|
2018-07-13 11:52:31 -04:00
|
|
|
|
|
|
|
it 'allows setting a user status' do
|
|
|
|
sign_in(user)
|
|
|
|
|
2020-10-29 14:09:11 -04:00
|
|
|
put :update, params: { user: { status: { message: 'Working hard!', availability: 'busy' } } }
|
2018-07-13 11:52:31 -04:00
|
|
|
|
|
|
|
expect(user.reload.status.message).to eq('Working hard!')
|
2020-10-29 14:09:11 -04:00
|
|
|
expect(user.reload.status.availability).to eq('busy')
|
2020-01-27 07:08:35 -05:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2018-07-13 11:52:31 -04:00
|
|
|
end
|
2020-03-03 04:07:54 -05:00
|
|
|
|
|
|
|
it 'allows updating user specified job title' do
|
|
|
|
title = 'Marketing Executive'
|
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
put :update, params: { user: { job_title: title } }
|
|
|
|
|
|
|
|
expect(user.reload.job_title).to eq(title)
|
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
|
|
|
end
|
2021-06-07 17:10:00 -04:00
|
|
|
|
|
|
|
it 'allows updating user specified pronouns', :aggregate_failures do
|
|
|
|
pronouns = 'they/them'
|
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
put :update, params: { user: { pronouns: pronouns } }
|
|
|
|
|
|
|
|
expect(user.reload.pronouns).to eq(pronouns)
|
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
|
|
|
end
|
2021-08-04 02:09:49 -04:00
|
|
|
|
|
|
|
it 'allows updating user specified pronunciation', :aggregate_failures do
|
|
|
|
user = create(:user, name: 'Example')
|
|
|
|
pronunciation = 'uhg-zaam-pl'
|
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
put :update, params: { user: { pronunciation: pronunciation } }
|
|
|
|
|
|
|
|
expect(user.reload.pronunciation).to eq(pronunciation)
|
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
|
|
|
end
|
2017-06-06 11:39:54 -04:00
|
|
|
end
|
2017-10-17 06:12:24 -04:00
|
|
|
|
2020-10-15 08:09:06 -04:00
|
|
|
describe 'GET audit_log' do
|
2021-11-15 01:10:30 -05:00
|
|
|
let(:auth_event) { create(:authentication_event, user: user) }
|
|
|
|
|
2020-10-15 08:09:06 -04:00
|
|
|
it 'tracks search event', :snowplow do
|
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
get :audit_log
|
|
|
|
|
|
|
|
expect_snowplow_event(
|
|
|
|
category: 'ProfilesController',
|
2021-06-01 23:09:51 -04:00
|
|
|
action: 'search_audit_event',
|
|
|
|
user: user
|
2020-10-15 08:09:06 -04:00
|
|
|
)
|
|
|
|
end
|
2021-11-15 01:10:30 -05:00
|
|
|
|
|
|
|
it 'loads page correctly' do
|
|
|
|
sign_in(user)
|
|
|
|
|
|
|
|
get :audit_log
|
|
|
|
|
|
|
|
expect(response).to have_gitlab_http_status(:success)
|
|
|
|
end
|
2020-10-15 08:09:06 -04:00
|
|
|
end
|
|
|
|
|
2017-10-17 06:12:24 -04:00
|
|
|
describe 'PUT update_username' do
|
|
|
|
let(:namespace) { user.namespace }
|
|
|
|
let(:gitlab_shell) { Gitlab::Shell.new }
|
2017-12-01 08:58:49 -05:00
|
|
|
let(:new_username) { generate(:username) }
|
2017-10-17 06:12:24 -04:00
|
|
|
|
2022-01-05 19:15:57 -05:00
|
|
|
before do
|
2017-10-17 06:12:24 -04:00
|
|
|
sign_in(user)
|
2022-01-05 19:15:57 -05:00
|
|
|
allow(::Gitlab::ApplicationRateLimiter).to receive(:throttled?).and_return(false)
|
|
|
|
end
|
2017-10-17 06:12:24 -04:00
|
|
|
|
2022-01-05 19:15:57 -05:00
|
|
|
it 'allows username change' do
|
2017-10-17 06:12:24 -04:00
|
|
|
put :update_username,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { username: new_username } }
|
2017-10-17 06:12:24 -04:00
|
|
|
|
|
|
|
user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2017-10-17 06:12:24 -04:00
|
|
|
expect(user.username).to eq(new_username)
|
|
|
|
end
|
|
|
|
|
2018-04-06 05:36:22 -04:00
|
|
|
it 'updates a username using JSON request' do
|
|
|
|
put :update_username,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: {
|
|
|
|
user: { username: new_username }
|
|
|
|
},
|
2018-04-06 05:36:22 -04:00
|
|
|
format: :json
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:ok)
|
2019-12-12 07:07:33 -05:00
|
|
|
expect(json_response['message']).to eq(s_('Profiles|Username successfully changed'))
|
2018-04-06 05:36:22 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it 'renders an error message when the username was not updated' do
|
|
|
|
put :update_username,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: {
|
|
|
|
user: { username: 'invalid username.git' }
|
|
|
|
},
|
2018-04-06 05:36:22 -04:00
|
|
|
format: :json
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:unprocessable_entity)
|
2018-04-06 05:36:22 -04:00
|
|
|
expect(json_response['message']).to match(/Username change failed/)
|
|
|
|
end
|
|
|
|
|
2018-04-04 03:59:35 -04:00
|
|
|
it 'raises a correct error when the username is missing' do
|
2018-12-17 17:52:17 -05:00
|
|
|
expect { put :update_username, params: { user: { gandalf: 'you shall not pass' } } }
|
2018-04-04 03:59:35 -04:00
|
|
|
.to raise_error(ActionController::ParameterMissing)
|
|
|
|
end
|
|
|
|
|
2017-12-01 08:58:49 -05:00
|
|
|
context 'with legacy storage' do
|
|
|
|
it 'moves dependent projects to new namespace' do
|
|
|
|
project = create(:project_empty_repo, :legacy_storage, namespace: namespace)
|
2017-10-17 06:12:24 -04:00
|
|
|
|
2017-12-01 08:58:49 -05:00
|
|
|
put :update_username,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { username: new_username } }
|
2017-10-17 06:12:24 -04:00
|
|
|
|
2017-12-01 08:58:49 -05:00
|
|
|
user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2019-10-09 05:06:19 -04:00
|
|
|
expect(gitlab_shell.repository_exists?(project.repository_storage, "#{new_username}/#{project.path}.git")).to be_truthy
|
2017-12-01 08:58:49 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context 'with hashed storage' do
|
|
|
|
it 'keeps repository location unchanged on disk' do
|
|
|
|
project = create(:project_empty_repo, namespace: namespace)
|
|
|
|
|
|
|
|
before_disk_path = project.disk_path
|
|
|
|
|
|
|
|
put :update_username,
|
2018-12-17 17:52:17 -05:00
|
|
|
params: { user: { username: new_username } }
|
2017-12-01 08:58:49 -05:00
|
|
|
|
|
|
|
user.reload
|
|
|
|
|
2020-03-31 17:08:05 -04:00
|
|
|
expect(response).to have_gitlab_http_status(:found)
|
2019-10-09 05:06:19 -04:00
|
|
|
expect(gitlab_shell.repository_exists?(project.repository_storage, "#{project.disk_path}.git")).to be_truthy
|
2017-12-01 08:58:49 -05:00
|
|
|
expect(before_disk_path).to eq(project.disk_path)
|
|
|
|
end
|
2017-10-17 06:12:24 -04:00
|
|
|
end
|
2022-01-05 19:15:57 -05:00
|
|
|
|
|
|
|
context 'when the rate limit is reached' do
|
|
|
|
it 'does not update the username and returns status 429 Too Many Requests' do
|
|
|
|
expect(::Gitlab::ApplicationRateLimiter).to receive(:throttled?).with(:profile_update_username, scope: user).and_return(true)
|
|
|
|
|
|
|
|
expect do
|
|
|
|
put :update_username,
|
|
|
|
params: { user: { username: new_username } }
|
|
|
|
end.not_to change { user.reload.username }
|
|
|
|
|
|
|
|
expect(response).to have_gitlab_http_status(:too_many_requests)
|
|
|
|
end
|
|
|
|
end
|
2017-10-17 06:12:24 -04:00
|
|
|
end
|
2017-06-06 11:39:54 -04:00
|
|
|
end
|