2016-08-23 19:19:36 -04:00
|
|
|
require 'spec_helper'
|
|
|
|
|
2017-07-10 10:24:02 -04:00
|
|
|
describe ProjectPolicy do
|
2017-09-22 03:13:31 -04:00
|
|
|
set(:guest) { create(:user) }
|
|
|
|
set(:reporter) { create(:user) }
|
|
|
|
set(:developer) { create(:user) }
|
2018-07-11 10:36:08 -04:00
|
|
|
set(:maintainer) { create(:user) }
|
2017-09-22 03:13:31 -04:00
|
|
|
set(:owner) { create(:user) }
|
|
|
|
set(:admin) { create(:admin) }
|
2017-08-02 15:55:11 -04:00
|
|
|
let(:project) { create(:project, :public, namespace: owner.namespace) }
|
2016-08-23 19:19:36 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
let(:base_guest_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[
|
2018-04-02 11:14:20 -04:00
|
|
|
read_project read_board read_list read_wiki read_issue
|
|
|
|
read_project_for_iids read_issue_iid read_merge_request_iid read_label
|
|
|
|
read_milestone read_project_snippet read_project_member read_note
|
2018-04-06 08:18:58 -04:00
|
|
|
create_project create_issue create_note upload_file create_merge_request_in
|
2018-12-13 06:08:53 -05:00
|
|
|
award_emoji read_release
|
2016-09-21 01:09:31 -04:00
|
|
|
]
|
2016-08-23 19:19:36 -04:00
|
|
|
end
|
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
let(:base_reporter_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[
|
|
|
|
download_code fork_project create_project_snippet update_issue
|
|
|
|
admin_issue admin_label admin_list read_commit_status read_build
|
|
|
|
read_container_image read_pipeline read_environment read_deployment
|
|
|
|
read_merge_request download_wiki_code
|
2016-09-21 01:09:31 -04:00
|
|
|
]
|
|
|
|
end
|
|
|
|
|
|
|
|
let(:team_member_reporter_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[build_download_code build_read_container_image]
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
let(:developer_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[
|
2017-09-13 16:32:58 -04:00
|
|
|
admin_milestone admin_merge_request update_merge_request create_commit_status
|
2017-02-06 18:19:37 -05:00
|
|
|
update_commit_status create_build update_build create_pipeline
|
2018-04-06 08:18:58 -04:00
|
|
|
update_pipeline create_merge_request_from create_wiki push_code
|
2017-02-06 18:19:37 -05:00
|
|
|
resolve_note create_container_image update_container_image
|
2018-12-13 06:08:53 -05:00
|
|
|
create_environment create_deployment create_release update_release
|
2016-09-21 01:09:31 -04:00
|
|
|
]
|
|
|
|
end
|
|
|
|
|
2018-07-11 10:36:08 -04:00
|
|
|
let(:base_maintainer_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[
|
2018-04-02 12:30:49 -04:00
|
|
|
push_to_delete_protected_branch update_project_snippet update_environment
|
2017-09-13 16:32:58 -04:00
|
|
|
update_deployment admin_project_snippet
|
2017-02-06 18:19:37 -05:00
|
|
|
admin_project_member admin_note admin_wiki admin_project
|
|
|
|
admin_commit_status admin_build admin_container_image
|
2018-12-25 04:48:26 -05:00
|
|
|
admin_pipeline admin_environment admin_deployment destroy_release add_cluster
|
2016-09-21 01:09:31 -04:00
|
|
|
]
|
|
|
|
end
|
|
|
|
|
|
|
|
let(:public_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[
|
|
|
|
download_code fork_project read_commit_status read_pipeline
|
|
|
|
read_container_image build_download_code build_read_container_image
|
2018-12-13 06:08:53 -05:00
|
|
|
download_wiki_code read_release
|
2016-09-21 01:09:31 -04:00
|
|
|
]
|
|
|
|
end
|
|
|
|
|
|
|
|
let(:owner_permissions) do
|
2017-02-06 18:19:37 -05:00
|
|
|
%i[
|
|
|
|
change_namespace change_visibility_level rename_project remove_project
|
|
|
|
archive_project remove_fork_project destroy_merge_request destroy_issue
|
2018-08-22 08:10:54 -04:00
|
|
|
set_issue_iid set_issue_created_at set_note_created_at
|
2016-09-21 01:09:31 -04:00
|
|
|
]
|
2016-08-23 19:19:36 -04:00
|
|
|
end
|
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
# Used in EE specs
|
|
|
|
let(:additional_guest_permissions) { [] }
|
|
|
|
let(:additional_reporter_permissions) { [] }
|
2018-07-11 10:36:08 -04:00
|
|
|
let(:additional_maintainer_permissions) { [] }
|
2017-09-22 03:13:31 -04:00
|
|
|
|
|
|
|
let(:guest_permissions) { base_guest_permissions + additional_guest_permissions }
|
|
|
|
let(:reporter_permissions) { base_reporter_permissions + additional_reporter_permissions }
|
2018-07-11 10:36:08 -04:00
|
|
|
let(:maintainer_permissions) { base_maintainer_permissions + additional_maintainer_permissions }
|
2017-09-22 03:13:31 -04:00
|
|
|
|
2016-08-23 19:19:36 -04:00
|
|
|
before do
|
2017-09-22 03:13:31 -04:00
|
|
|
project.add_guest(guest)
|
2018-07-11 10:36:08 -04:00
|
|
|
project.add_maintainer(maintainer)
|
2017-09-22 03:13:31 -04:00
|
|
|
project.add_developer(developer)
|
|
|
|
project.add_reporter(reporter)
|
2016-08-23 19:19:36 -04:00
|
|
|
end
|
2016-09-19 16:21:58 -04:00
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
def expect_allowed(*permissions)
|
|
|
|
permissions.each { |p| is_expected.to be_allowed(p) }
|
|
|
|
end
|
|
|
|
|
|
|
|
def expect_disallowed(*permissions)
|
|
|
|
permissions.each { |p| is_expected.not_to be_allowed(p) }
|
|
|
|
end
|
|
|
|
|
2016-09-19 16:21:58 -04:00
|
|
|
it 'does not include the read_issue permission when the issue author is not a member of the private project' do
|
2017-08-02 15:55:11 -04:00
|
|
|
project = create(:project, :private)
|
2017-08-04 13:14:04 -04:00
|
|
|
issue = create(:issue, project: project, author: create(:user))
|
2016-09-19 16:21:58 -04:00
|
|
|
user = issue.author
|
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
expect(project.team.member?(issue.author)).to be false
|
2016-09-19 16:21:58 -04:00
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
expect(Ability).not_to be_allowed(user, :read_issue, project)
|
2016-09-19 16:21:58 -04:00
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
context 'when the feature is disabled' do
|
|
|
|
subject { described_class.new(owner, project) }
|
2016-11-29 14:30:14 -05:00
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
before do
|
|
|
|
project.project_feature.update_attribute(:wiki_access_level, ProjectFeature::DISABLED)
|
|
|
|
end
|
2016-11-29 14:30:14 -05:00
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
it 'does not include the wiki permissions' do
|
|
|
|
expect_disallowed :read_wiki, :create_wiki, :update_wiki, :admin_wiki, :download_wiki_code
|
|
|
|
end
|
2016-11-29 14:30:14 -05:00
|
|
|
end
|
|
|
|
|
2017-06-13 04:25:25 -04:00
|
|
|
context 'issues feature' do
|
|
|
|
subject { described_class.new(owner, project) }
|
|
|
|
|
|
|
|
context 'when the feature is disabled' do
|
|
|
|
it 'does not include the issues permissions' do
|
|
|
|
project.issues_enabled = false
|
|
|
|
project.save!
|
|
|
|
|
2018-04-02 11:14:20 -04:00
|
|
|
expect_disallowed :read_issue, :read_issue_iid, :create_issue, :update_issue, :admin_issue
|
2017-06-13 04:25:25 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context 'when the feature is disabled and external tracker configured' do
|
|
|
|
it 'does not include the issues permissions' do
|
|
|
|
create(:jira_service, project: project)
|
|
|
|
|
|
|
|
project.issues_enabled = false
|
|
|
|
project.save!
|
|
|
|
|
2018-04-02 11:14:20 -04:00
|
|
|
expect_disallowed :read_issue, :read_issue_iid, :create_issue, :update_issue, :admin_issue
|
2017-06-13 04:25:25 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2018-04-06 06:47:52 -04:00
|
|
|
context 'merge requests feature' do
|
|
|
|
subject { described_class.new(owner, project) }
|
|
|
|
|
|
|
|
it 'disallows all permissions when the feature is disabled' do
|
|
|
|
project.project_feature.update(merge_requests_access_level: ProjectFeature::DISABLED)
|
|
|
|
|
2018-04-06 08:18:58 -04:00
|
|
|
mr_permissions = [:create_merge_request_from, :read_merge_request,
|
2018-04-06 06:47:52 -04:00
|
|
|
:update_merge_request, :admin_merge_request,
|
2018-04-06 08:18:58 -04:00
|
|
|
:create_merge_request_in]
|
2018-04-06 06:47:52 -04:00
|
|
|
|
|
|
|
expect_disallowed(*mr_permissions)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2018-06-14 06:34:09 -04:00
|
|
|
context 'builds feature' do
|
|
|
|
subject { described_class.new(owner, project) }
|
|
|
|
|
|
|
|
it 'disallows all permissions when the feature is disabled' do
|
|
|
|
project.project_feature.update(builds_access_level: ProjectFeature::DISABLED)
|
|
|
|
|
|
|
|
builds_permissions = [
|
|
|
|
:create_pipeline, :update_pipeline, :admin_pipeline, :destroy_pipeline,
|
|
|
|
:create_build, :read_build, :update_build, :admin_build, :destroy_build,
|
|
|
|
:create_pipeline_schedule, :read_pipeline_schedule, :update_pipeline_schedule, :admin_pipeline_schedule, :destroy_pipeline_schedule,
|
|
|
|
:create_environment, :read_environment, :update_environment, :admin_environment, :destroy_environment,
|
2018-10-14 20:42:02 -04:00
|
|
|
:create_cluster, :read_cluster, :update_cluster, :admin_cluster,
|
2018-06-14 06:34:09 -04:00
|
|
|
:create_deployment, :read_deployment, :update_deployment, :admin_deployment, :destroy_deployment
|
|
|
|
]
|
|
|
|
|
|
|
|
expect_disallowed(*builds_permissions)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
context 'repository feature' do
|
|
|
|
subject { described_class.new(owner, project) }
|
|
|
|
|
|
|
|
it 'disallows all permissions when the feature is disabled' do
|
|
|
|
project.project_feature.update(repository_access_level: ProjectFeature::DISABLED)
|
|
|
|
|
|
|
|
repository_permissions = [
|
|
|
|
:create_pipeline, :update_pipeline, :admin_pipeline, :destroy_pipeline,
|
|
|
|
:create_build, :read_build, :update_build, :admin_build, :destroy_build,
|
|
|
|
:create_pipeline_schedule, :read_pipeline_schedule, :update_pipeline_schedule, :admin_pipeline_schedule, :destroy_pipeline_schedule,
|
|
|
|
:create_environment, :read_environment, :update_environment, :admin_environment, :destroy_environment,
|
2018-10-14 20:42:02 -04:00
|
|
|
:create_cluster, :read_cluster, :update_cluster, :admin_cluster,
|
2018-12-13 06:08:53 -05:00
|
|
|
:create_deployment, :read_deployment, :update_deployment, :admin_deployment, :destroy_deployment,
|
2018-12-25 04:48:26 -05:00
|
|
|
:destroy_release
|
2018-06-14 06:34:09 -04:00
|
|
|
]
|
|
|
|
|
|
|
|
expect_disallowed(*repository_permissions)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2018-04-02 14:38:47 -04:00
|
|
|
shared_examples 'archived project policies' do
|
|
|
|
let(:feature_write_abilities) do
|
|
|
|
described_class::READONLY_FEATURES_WHEN_ARCHIVED.flat_map do |feature|
|
|
|
|
described_class.create_update_admin_destroy(feature)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
let(:other_write_abilities) do
|
|
|
|
%i[
|
2018-04-06 08:18:58 -04:00
|
|
|
create_merge_request_in
|
|
|
|
create_merge_request_from
|
2018-04-02 14:38:47 -04:00
|
|
|
push_to_delete_protected_branch
|
|
|
|
push_code
|
|
|
|
request_access
|
|
|
|
upload_file
|
|
|
|
resolve_note
|
2018-04-06 14:19:37 -04:00
|
|
|
award_emoji
|
2018-04-02 14:38:47 -04:00
|
|
|
]
|
|
|
|
end
|
|
|
|
|
|
|
|
context 'when the project is archived' do
|
|
|
|
before do
|
|
|
|
project.archived = true
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'disables write actions on all relevant project features' do
|
|
|
|
expect_disallowed(*feature_write_abilities)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'disables some other important write actions' do
|
|
|
|
expect_disallowed(*other_write_abilities)
|
|
|
|
end
|
|
|
|
|
2018-11-19 09:08:23 -05:00
|
|
|
it 'does not disable other abilities' do
|
2018-04-02 14:38:47 -04:00
|
|
|
expect_allowed(*(regular_abilities - feature_write_abilities - other_write_abilities))
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
shared_examples 'project policies as anonymous' do
|
|
|
|
context 'abilities for public projects' do
|
|
|
|
context 'when a project has pending invites' do
|
|
|
|
let(:group) { create(:group, :public) }
|
|
|
|
let(:project) { create(:project, :public, namespace: group) }
|
2018-04-06 14:19:37 -04:00
|
|
|
let(:user_permissions) { [:create_merge_request_in, :create_project, :create_issue, :create_note, :upload_file, :award_emoji] }
|
2018-04-02 14:38:47 -04:00
|
|
|
let(:anonymous_permissions) { guest_permissions - user_permissions }
|
2017-07-24 06:35:54 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
subject { described_class.new(nil, project) }
|
2017-07-24 06:35:54 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
before do
|
|
|
|
create(:group_member, :invited, group: group)
|
|
|
|
end
|
2017-07-24 06:35:54 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
it 'does not grant owner access' do
|
|
|
|
expect_allowed(*anonymous_permissions)
|
|
|
|
expect_disallowed(*user_permissions)
|
|
|
|
end
|
2018-04-02 14:38:47 -04:00
|
|
|
|
|
|
|
it_behaves_like 'archived project policies' do
|
|
|
|
let(:regular_abilities) { anonymous_permissions }
|
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
2017-07-24 06:35:54 -04:00
|
|
|
end
|
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
subject { described_class.new(nil, project) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-04-06 17:09:58 -04:00
|
|
|
it { is_expected.to be_banned }
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
shared_examples 'project policies as guest' do
|
|
|
|
subject { described_class.new(guest, project) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
2016-11-29 07:43:58 -05:00
|
|
|
let(:reporter_public_build_permissions) do
|
|
|
|
reporter_permissions - [:read_build, :read_pipeline]
|
|
|
|
end
|
|
|
|
|
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_disallowed(*reporter_public_build_permissions)
|
|
|
|
expect_disallowed(*team_member_reporter_permissions)
|
|
|
|
expect_disallowed(*developer_permissions)
|
2018-07-11 10:36:08 -04:00
|
|
|
expect_disallowed(*maintainer_permissions)
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_disallowed(*owner_permissions)
|
2016-11-29 07:43:58 -05:00
|
|
|
end
|
2016-10-13 03:38:03 -04:00
|
|
|
|
2018-04-02 14:38:47 -04:00
|
|
|
it_behaves_like 'archived project policies' do
|
|
|
|
let(:regular_abilities) { guest_permissions }
|
|
|
|
end
|
|
|
|
|
2016-11-29 07:43:58 -05:00
|
|
|
context 'public builds enabled' do
|
2016-10-13 03:38:03 -04:00
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_allowed(:read_build, :read_pipeline)
|
2016-10-13 03:38:03 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
context 'when public builds disabled' do
|
2016-10-13 03:38:03 -04:00
|
|
|
before do
|
2016-11-29 07:43:58 -05:00
|
|
|
project.update(public_builds: false)
|
2016-10-13 03:38:03 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_disallowed(:read_build, :read_pipeline)
|
2016-10-13 03:38:03 -04:00
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2017-06-07 06:32:16 -04:00
|
|
|
|
|
|
|
context 'when builds are disabled' do
|
|
|
|
before do
|
2017-09-22 03:13:31 -04:00
|
|
|
project.project_feature.update(builds_access_level: ProjectFeature::DISABLED)
|
2017-06-07 06:32:16 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it do
|
2017-04-06 17:06:42 -04:00
|
|
|
expect_disallowed(:read_build)
|
|
|
|
expect_allowed(:read_pipeline)
|
2017-06-07 06:32:16 -04:00
|
|
|
end
|
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
shared_examples 'project policies as reporter' do
|
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
subject { described_class.new(reporter, project) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_allowed(*reporter_permissions)
|
|
|
|
expect_allowed(*team_member_reporter_permissions)
|
|
|
|
expect_disallowed(*developer_permissions)
|
2018-07-11 10:36:08 -04:00
|
|
|
expect_disallowed(*maintainer_permissions)
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_disallowed(*owner_permissions)
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2018-04-02 14:38:47 -04:00
|
|
|
|
|
|
|
it_behaves_like 'archived project policies' do
|
|
|
|
let(:regular_abilities) { reporter_permissions }
|
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
shared_examples 'project policies as developer' do
|
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
|
|
|
|
|
|
|
subject { described_class.new(developer, project) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_allowed(*reporter_permissions)
|
|
|
|
expect_allowed(*team_member_reporter_permissions)
|
|
|
|
expect_allowed(*developer_permissions)
|
2018-07-11 10:36:08 -04:00
|
|
|
expect_disallowed(*maintainer_permissions)
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_disallowed(*owner_permissions)
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2018-04-02 14:38:47 -04:00
|
|
|
|
|
|
|
it_behaves_like 'archived project policies' do
|
|
|
|
let(:regular_abilities) { developer_permissions }
|
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
|
|
|
|
2018-07-11 10:36:08 -04:00
|
|
|
shared_examples 'project policies as maintainer' do
|
2017-09-22 03:13:31 -04:00
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2018-07-11 10:36:08 -04:00
|
|
|
subject { described_class.new(maintainer, project) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_allowed(*reporter_permissions)
|
|
|
|
expect_allowed(*team_member_reporter_permissions)
|
|
|
|
expect_allowed(*developer_permissions)
|
2018-07-11 10:36:08 -04:00
|
|
|
expect_allowed(*maintainer_permissions)
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_disallowed(*owner_permissions)
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2018-04-02 14:38:47 -04:00
|
|
|
|
|
|
|
it_behaves_like 'archived project policies' do
|
2018-07-11 10:36:08 -04:00
|
|
|
let(:regular_abilities) { maintainer_permissions }
|
2018-04-02 14:38:47 -04:00
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
shared_examples 'project policies as owner' do
|
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
subject { described_class.new(owner, project) }
|
2016-09-21 01:09:31 -04:00
|
|
|
|
2016-10-17 11:23:51 -04:00
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_allowed(*reporter_permissions)
|
|
|
|
expect_allowed(*team_member_reporter_permissions)
|
|
|
|
expect_allowed(*developer_permissions)
|
2018-07-11 10:36:08 -04:00
|
|
|
expect_allowed(*maintainer_permissions)
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*owner_permissions)
|
2016-10-17 11:23:51 -04:00
|
|
|
end
|
2018-04-02 14:38:47 -04:00
|
|
|
|
|
|
|
it_behaves_like 'archived project policies' do
|
|
|
|
let(:regular_abilities) { owner_permissions }
|
|
|
|
end
|
2016-10-17 11:23:51 -04:00
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
end
|
2016-10-17 11:23:51 -04:00
|
|
|
|
2017-09-22 03:13:31 -04:00
|
|
|
shared_examples 'project policies as admin' do
|
|
|
|
context 'abilities for non-public projects' do
|
|
|
|
let(:project) { create(:project, namespace: owner.namespace) }
|
|
|
|
|
|
|
|
subject { described_class.new(admin, project) }
|
2016-10-17 11:23:51 -04:00
|
|
|
|
2016-09-21 01:09:31 -04:00
|
|
|
it do
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*guest_permissions)
|
|
|
|
expect_allowed(*reporter_permissions)
|
|
|
|
expect_disallowed(*team_member_reporter_permissions)
|
|
|
|
expect_allowed(*developer_permissions)
|
2018-07-11 10:36:08 -04:00
|
|
|
expect_allowed(*maintainer_permissions)
|
2017-04-06 17:09:58 -04:00
|
|
|
expect_allowed(*owner_permissions)
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
2018-04-02 14:38:47 -04:00
|
|
|
|
|
|
|
it_behaves_like 'archived project policies' do
|
|
|
|
let(:regular_abilities) { owner_permissions }
|
|
|
|
end
|
2016-09-21 01:09:31 -04:00
|
|
|
end
|
|
|
|
end
|
2017-09-22 03:13:31 -04:00
|
|
|
|
|
|
|
it_behaves_like 'project policies as anonymous'
|
|
|
|
it_behaves_like 'project policies as guest'
|
|
|
|
it_behaves_like 'project policies as reporter'
|
|
|
|
it_behaves_like 'project policies as developer'
|
2018-07-11 10:36:08 -04:00
|
|
|
it_behaves_like 'project policies as maintainer'
|
2017-09-22 03:13:31 -04:00
|
|
|
it_behaves_like 'project policies as owner'
|
|
|
|
it_behaves_like 'project policies as admin'
|
2018-02-26 07:32:42 -05:00
|
|
|
|
|
|
|
context 'when a public project has merge requests allowing access' do
|
|
|
|
include ProjectForksHelper
|
|
|
|
let(:user) { create(:user) }
|
|
|
|
let(:target_project) { create(:project, :public) }
|
|
|
|
let(:project) { fork_project(target_project) }
|
|
|
|
let!(:merge_request) do
|
|
|
|
create(
|
|
|
|
:merge_request,
|
|
|
|
target_project: target_project,
|
|
|
|
source_project: project,
|
2018-05-22 21:54:57 -04:00
|
|
|
allow_collaboration: true
|
2018-02-26 07:32:42 -05:00
|
|
|
)
|
|
|
|
end
|
|
|
|
let(:maintainer_abilities) do
|
2018-05-15 04:18:22 -04:00
|
|
|
%w(create_build create_pipeline)
|
2018-02-26 07:32:42 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
subject { described_class.new(user, project) }
|
|
|
|
|
|
|
|
it 'does not allow pushing code' do
|
|
|
|
expect_disallowed(*maintainer_abilities)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'allows pushing if the user is a member with push access to the target project' do
|
|
|
|
target_project.add_developer(user)
|
|
|
|
|
|
|
|
expect_allowed(*maintainer_abilities)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'dissallows abilities to a maintainer if the merge request was closed' do
|
|
|
|
target_project.add_developer(user)
|
|
|
|
merge_request.close!
|
|
|
|
|
|
|
|
expect_disallowed(*maintainer_abilities)
|
|
|
|
end
|
|
|
|
end
|
2018-12-04 16:38:15 -05:00
|
|
|
|
|
|
|
it_behaves_like 'clusterable policies' do
|
|
|
|
let(:clusterable) { create(:project, :repository) }
|
|
|
|
let(:cluster) do
|
|
|
|
create(:cluster,
|
|
|
|
:provided_by_gcp,
|
|
|
|
:project,
|
|
|
|
projects: [clusterable])
|
|
|
|
end
|
|
|
|
end
|
2016-08-23 19:19:36 -04:00
|
|
|
end
|